# Smart Card Glossary

## Protocol
- [APDU](https://smartcardfyi.com/glossary/apdu/): Application Protocol Data Unit -- the communication unit between a smart card and a reader defined b
- [ATR](https://smartcardfyi.com/glossary/atr/): Answer to Reset -- the initial response sent by a contact smart card after power-on, containing inte
- [T=0](https://smartcardfyi.com/glossary/t0/): Character-oriented transmission protocol for contact smart cards defined in ISO 7816-3.
- [T=1](https://smartcardfyi.com/glossary/t1/): Block-oriented transmission protocol for contact smart cards defined in ISO 7816-3.
- [AID](https://smartcardfyi.com/glossary/aid/): Application Identifier -- a unique identifier for applications on a smart card, consisting of a 5-by
- [PPS](https://smartcardfyi.com/glossary/pps/): Protocol and Parameter Selection -- negotiation between card and reader to select communication para
- [RID](https://smartcardfyi.com/glossary/rid/): Registered Application Provider Identifier -- the first 5 bytes of an AID identifying the applicatio
- [PIX](https://smartcardfyi.com/glossary/pix/): Proprietary Application Identifier Extension -- the variable-length suffix of an AID after the RID.
- [SWP](https://smartcardfyi.com/glossary/swp/): Single Wire Protocol -- a high-speed serial interface defined by ETSI TS 102 613 linking a SIM card 
- [APDU Response Codes](https://smartcardfyi.com/glossary/apdu-response-codes/): Two-byte status words (SW1-SW2) appended to every APDU response indicating success (9000), warnings,
- [Secure Messaging](https://smartcardfyi.com/glossary/secure-messaging/): An ISO 7816-4 mechanism that applies cryptographic integrity and confidentiality protection to indiv

## Security
- [Secure Element](https://smartcardfyi.com/glossary/secure-element/): A tamper-resistant hardware component that provides secure storage and execution environment for sen
- [Common Criteria](https://smartcardfyi.com/glossary/common-criteria/): An international standard (ISO/IEC 15408) for evaluating IT security products, used extensively for 
- [EAL](https://smartcardfyi.com/glossary/eal/): Evaluation Assurance Level -- a numerical rating (1-7) indicating the depth and rigor of a Common Cr
- [HSM](https://smartcardfyi.com/glossary/hsm/): Hardware Security Module -- a physical device for managing cryptographic keys, used in card personal
- [TEE](https://smartcardfyi.com/glossary/tee/): Trusted Execution Environment -- an isolated execution area in a processor providing security for co
- [Protection Profile](https://smartcardfyi.com/glossary/protection-profile/): A document specifying security requirements for a category of products in the Common Criteria framew
- [SPA/DPA](https://smartcardfyi.com/glossary/spa-dpa/): Simple/Differential Power Analysis -- side-channel attacks that analyze power consumption patterns t
- [Side-Channel Attack](https://smartcardfyi.com/glossary/side-channel/): An attack exploiting physical information leakage (power, timing, electromagnetic emissions) rather 
- [Fault Injection](https://smartcardfyi.com/glossary/fault-injection/): A physical attack technique that deliberately disturbs a smart card chip using voltage glitches, clo
- [Key Diversification](https://smartcardfyi.com/glossary/key-diversification/): A technique generating unique per-card keys from a master key and card-specific data (e.g., serial n
- [Card Verifiable Certificate](https://smartcardfyi.com/glossary/cvc/): A compact certificate format defined by BSI TR-03110 used in eID and ePassport applications, optimiz

## Hardware
- [Contact Pad](https://smartcardfyi.com/glossary/contact-pad/): The gold-plated electrical contacts on a smart card (C1-C8) defined by ISO 7816-2 for power, ground,
- [EEPROM](https://smartcardfyi.com/glossary/eeprom/): Electrically Erasable Programmable Read-Only Memory -- non-volatile memory used in smart cards for d
- [Flash Memory](https://smartcardfyi.com/glossary/flash-memory/): Non-volatile memory with faster write speeds than EEPROM, increasingly used in modern high-capacity 
- [Crypto Coprocessor](https://smartcardfyi.com/glossary/crypto-coprocessor/): Dedicated hardware accelerator for cryptographic operations (RSA, ECC, AES) on a smart card chip.
- [Dual-Interface Module](https://smartcardfyi.com/glossary/dual-interface-module/): A chip module that supports both ISO 7816 contact and ISO 14443 contactless interfaces on a single s
- [Card Body](https://smartcardfyi.com/glossary/card-body/): The physical plastic substrate of a smart card, typically made of PVC, PET, or polycarbonate layers 
- [Chip-on-Flex](https://smartcardfyi.com/glossary/chip-on-flex/): A packaging technique bonding a bare smart card die directly onto a flexible printed circuit, used i
- [ROM](https://smartcardfyi.com/glossary/rom/): Read-Only Memory -- mask-programmed memory on a smart card chip containing the permanent operating s

## Software
- [JavaCard](https://smartcardfyi.com/glossary/javacard/): A technology enabling Java-based applets to run on smart cards and secure elements, defined by Oracl
- [GlobalPlatform](https://smartcardfyi.com/glossary/globalplatform/): An industry standard for secure management of smart card applications, including applet installation
- [MULTOS](https://smartcardfyi.com/glossary/multos/): Multi-application Operating System for smart cards, providing high-security multi-application suppor
- [SCP03](https://smartcardfyi.com/glossary/scp03/): Secure Channel Protocol 03 -- GlobalPlatform protocol using AES for secure communication between car

## Application
- [EMV](https://smartcardfyi.com/glossary/emv/): Europay, Mastercard, and Visa -- the global standard for chip-based payment card transactions.
- [eSIM](https://smartcardfyi.com/glossary/esim/): Embedded SIM -- a programmable SIM chip soldered onto a device, allowing remote provisioning of mobi
- [SIM](https://smartcardfyi.com/glossary/sim/): Subscriber Identity Module -- a smart card used in mobile devices to authenticate subscribers on cel
- [iSIM](https://smartcardfyi.com/glossary/isim/): Integrated SIM -- SIM functionality built directly into a device SoC, eliminating the need for a sep
- [RSP](https://smartcardfyi.com/glossary/rsp/): Remote SIM Provisioning -- the process of downloading and managing SIM profiles over-the-air on eSIM
- [ePassport](https://smartcardfyi.com/glossary/epassport/): An electronic passport with an embedded contactless chip storing biometric data, defined by ICAO Doc
- [BAC](https://smartcardfyi.com/glossary/bac/): Basic Access Control -- a security mechanism for ePassports using MRZ data to establish encrypted co
- [PACE](https://smartcardfyi.com/glossary/pace/): Password Authenticated Connection Establishment -- a stronger alternative to BAC for ePassport and e
- [Loyalty Program Card](https://smartcardfyi.com/glossary/loyalty-card/): A smart card storing points, rewards balances, and member identifiers for retail loyalty schemes, us
- [Healthcare Smart Card](https://smartcardfyi.com/glossary/healthcare-card/): A patient identity card containing health insurance credentials, medical record references, and emer
- [Digital Tachograph](https://smartcardfyi.com/glossary/digital-tachograph/): A smart card system mandated by EU regulations for commercial vehicles that records driver hours, sp
- [Electronic Toll Collection](https://smartcardfyi.com/glossary/electronic-toll/): A contactless smart card or RFID-based system enabling automatic toll payment on highways and bridge

## Standard
- [ISO 7816](https://smartcardfyi.com/glossary/iso-7816/): The primary international standard for contact smart cards, covering physical characteristics, elect
- [ISO 14443](https://smartcardfyi.com/glossary/iso-14443/): International standard for proximity contactless smart cards operating at 13.56 MHz with a range up 
- [EMVCo](https://smartcardfyi.com/glossary/emvco/): The organization owned by major payment networks that manages the EMV specifications for chip-based 
- [FIDO2](https://smartcardfyi.com/glossary/fido2/): An authentication standard using public-key cryptography for passwordless login, implemented in smar

## Personalization
- [Electrical Personalization](https://smartcardfyi.com/glossary/electrical-personalization/): The process of writing data (keys, certificates, cardholder info) to a smart card chip during issuan
- [Graphical Personalization](https://smartcardfyi.com/glossary/graphical-personalization/): Printing cardholder photos, names, and other visual elements onto the card body.
- [OTA](https://smartcardfyi.com/glossary/ota/): Over-the-Air -- remote management of smart card content (especially SIM cards) via mobile network co

## Identity
- [eID](https://smartcardfyi.com/glossary/eid/): Electronic Identity Card -- a national identity document with an embedded smart card chip for digita
- [PIV](https://smartcardfyi.com/glossary/piv/): Personal Identity Verification -- US federal smart card standard (NIST SP 800-73) for employee ident
- [CAC](https://smartcardfyi.com/glossary/cac/): Common Access Card -- the US Department of Defense smart card for identification, authentication, an

## Biometric
- [Match-On-Card](https://smartcardfyi.com/glossary/moc/): Match-On-Card (MOC) is a biometric verification method where the fingerprint or other biometric temp
- [Biometric Template](https://smartcardfyi.com/glossary/biometric-template/): A compact mathematical representation of biometric features (fingerprint minutiae, iris code, or fac
- [FAR/FRR](https://smartcardfyi.com/glossary/far-frr/): False Accept Rate (FAR) and False Reject Rate (FRR) are complementary metrics measuring biometric sy
- [Liveness Detection](https://smartcardfyi.com/glossary/liveness-detection/): Anti-spoofing technology that verifies a biometric sample comes from a living person rather than a p
- [Fingerprint Sensor Module](https://smartcardfyi.com/glossary/fingerprint-sensor/): A compact capacitive or optical sensor embedded in or attached to a smart card for capturing fingerp
- [Biometric Enrollment](https://smartcardfyi.com/glossary/biometric-enrollment/): The process of capturing and storing a person's biometric data (fingerprint, iris, face) onto a smar
- [Iris Recognition](https://smartcardfyi.com/glossary/iris-recognition/): A biometric identification method that uses the unique patterns in the colored ring of the eye. In e
- [Biometric Payment Card](https://smartcardfyi.com/glossary/biometric-payment-card/): An EMV payment card with an integrated fingerprint sensor that enables cardholder verification via o
- [CBEFF](https://smartcardfyi.com/glossary/cbeff/): Common Biometric Exchange Formats Framework (CBEFF, ISO/IEC 19785) defines a standardized structure 

## Compliance
- [FIPS 140](https://smartcardfyi.com/glossary/fips-140/): Federal Information Processing Standard 140-2 (and successor 140-3) is a US/Canadian government stan
- [PCI PTS](https://smartcardfyi.com/glossary/pci-pts/): Payment Card Industry PIN Transaction Security is a set of security requirements for devices that ac
- [ITSEF](https://smartcardfyi.com/glossary/itsef/): Information Technology Security Evaluation Facility -- an accredited laboratory that performs Common
- [JIL](https://smartcardfyi.com/glossary/jil/): Joint Interpretation Library -- a set of guidelines developed by smart card certification bodies to 
- [EMVCo Type Approval](https://smartcardfyi.com/glossary/emvco-type-approval/): The certification process administered by EMVCo that validates smart card chips, payment terminals, 
- [GSMA SAS](https://smartcardfyi.com/glossary/gsma-sas/): GSMA Security Accreditation Scheme -- a certification program for SIM card manufacturers, eSIM platf
- [ETSI SAS](https://smartcardfyi.com/glossary/etsi-sas/): European Telecommunications Standards Institute Security Assurance Specification defines security re
- [FIPS 201](https://smartcardfyi.com/glossary/fips-201/): Federal Information Processing Standard 201 -- the US government standard specifying PIV card requir
- [ICAO 9303](https://smartcardfyi.com/glossary/icao-9303/): International Civil Aviation Organization Doc 9303 defines the specifications for Machine Readable T
- [PCI DSS](https://smartcardfyi.com/glossary/pci-dss/): Payment Card Industry Data Security Standard -- a set of security requirements for organizations tha

## Provisioning
- [eUICC](https://smartcardfyi.com/glossary/euicc/): Embedded Universal Integrated Circuit Card -- a reprogrammable SIM chip that can securely download a
- [SM-DP+](https://smartcardfyi.com/glossary/sm-dp-plus/): Subscription Manager - Data Preparation Plus is the server-side component in the GSMA RSP architectu
- [SM-SR](https://smartcardfyi.com/glossary/sm-sr/): Subscription Manager - Secure Routing is the network entity in the M2M RSP architecture that manages
- [LPA](https://smartcardfyi.com/glossary/lpa/): Local Profile Assistant is the device-side application that manages eSIM profile operations on consu
- [Subscription Profile](https://smartcardfyi.com/glossary/subscription-profile/): A downloadable software package containing all the data and applications needed to access a mobile n
- [M2M Provisioning](https://smartcardfyi.com/glossary/m2m-provisioning/): Machine-to-Machine provisioning is the GSMA-specified remote SIM provisioning architecture for IoT a

## Cryptography
- [AES](https://smartcardfyi.com/glossary/aes/): Advanced Encryption Standard -- a symmetric block cipher standardized by NIST (FIPS 197) operating o
- [RSA](https://smartcardfyi.com/glossary/rsa/): Rivest–Shamir–Adleman -- a public-key cryptosystem based on the difficulty of factoring large intege
- [ECC](https://smartcardfyi.com/glossary/ecc/): Elliptic Curve Cryptography -- public-key cryptography based on elliptic curves over finite fields, 
- [3DES](https://smartcardfyi.com/glossary/3des/): Triple Data Encryption Standard -- a symmetric cipher applying DES three times with different keys (
- [SHA](https://smartcardfyi.com/glossary/sha/): Secure Hash Algorithm -- a family of NIST-standardized one-way hash functions (SHA-1, SHA-256, SHA-3
- [Key Ceremony](https://smartcardfyi.com/glossary/key-ceremony/): A formal, audited procedure for generating or loading master cryptographic keys into an HSM or smart

## Manufacturing
- [Card Personalization Bureau](https://smartcardfyi.com/glossary/personalization-bureau/): A certified facility that performs both electrical and graphical personalization of smart cards at s
- [Pre-personalization](https://smartcardfyi.com/glossary/pre-personalization/): An initial manufacturing step loading transport keys, card serial numbers, and a basic file system o
- [Hot Stamping](https://smartcardfyi.com/glossary/hot-stamping/): A card finishing technique that applies metallic foil or holographic security features to the card s
- [Laser Engraving](https://smartcardfyi.com/glossary/laser-engraving/): A personalization technique using a focused laser to permanently engrave cardholder data (name, numb
- [Chip Embedding](https://smartcardfyi.com/glossary/chip-embedding/): The manufacturing step milling a cavity in the card body and bonding the chip module into it using a
- [Card Testing](https://smartcardfyi.com/glossary/card-testing/): The quality assurance process verifying that completed smart cards meet electrical, mechanical, and 
