AES

Embed This Widget

Theme


      
    

Widget powered by . Free, no account required.

การเข้ารหัสลับ

Advanced Encryption Standard -- a symmetric block cipher standardized by NIST (FIPS 197) operating on 128-bit blocks with 128, 192, or 256-bit key lengths, widely used in smart card secure channels and data encryption.

Also known as: Advanced Encryption Standard AES-128 AES-256

What Is AES?

Advanced Encryption Standard (AES) is a symmetric block cipher standardized by NIST as FIPS 197, operating on 128-bit data blocks with key lengths of 128, 192, or 256 bits. AES is the dominant symmetric encryption algorithm in modern smart card systems, used for secure channel communication, data encryption at rest, session key derivation, and message authentication codes across payment, identity, and telecom applications.

AES replaced 3DES as the preferred symmetric cipher in smart card specifications starting in the mid-2000s, driven by its superior security margins, faster software performance, and efficient hardware implementation on constrained crypto coprocessors.

AES in Smart Card Protocols

AES is foundational to several core smart card protocols:

Protocol AES Usage
SCP03 Session encryption (AES-CBC) + integrity (AES-CMAC) for GlobalPlatform secure channels
EMV CSU Card session key derivation for issuer script processing
Secure Messaging APDU data encryption and MAC computation
MIFARE DESFire EV3 File-level encryption and mutual authentication
PACE Session key establishment in ePassport and eID

Hardware Implementation

Modern smart card chips include dedicated AES hardware accelerators as part of the crypto coprocessor. A hardware AES engine on a typical 32-bit smart card CPU can encrypt a 128-bit block in 10-50 clock cycles, compared to thousands of cycles for a software-only implementation. This is critical for maintaining acceptable transaction times, especially on contactless cards where the entire session (including authentication, data exchange, and MAC verification) must complete within 500 ms.

AES Modes Used in Smart Cards

Mode Purpose Smart Card Application
AES-CBC Bulk data encryption Secure messaging data field
AES-CMAC Message authentication SCP03 command/response MAC
AES-CCM Authenticated encryption MIFARE DESFire file access
AES-ECB Key derivation, key wrapping Key diversification

Key Length Selection

Smart card deployments choose AES key lengths based on the security certification target:

  • AES-128 -- sufficient for most commercial applications. Common Criteria certified cards widely use AES-128 for SCP03.
  • AES-256 -- required for government applications targeting FIPS 140 Level 3 and high-assurance EAL 5+ certified products. Also recommended for long- lived credentials (10+ year card lifetime).

Smart Card Fundamentals

เริ่มต้นใช้งาน

…data Crypto acceleration Crypto coprocessor RSA, ECC, AES offload I/O Contact pad / RF antenna Communicate with…

EMV Payment Card Architecture

มาตรฐานและโพรโทคอล

…TC for approved offline, AAC for declined) using 3DES or AES under a card-unique derived key — a key-derivation scheme…

GlobalPlatform Card Management

มาตรฐานและโพรโทคอล

…the current mandatory baseline for new deployments — uses AES-128 or AES-256. Protocol Algorithm Session keys MAC…

EMV Contactless Kernel Deep Dive

มาตรฐานและโพรโทคอล

…The 8-byte ARQC is computed on-card using 3DES (legacy) or AES (newer M/Chip 5 cards) with the issuer master key…

Secure Channel Protocols (SCP02/SCP03)

มาตรฐานและโพรโทคอล

…C-ENC + R-MAC SCP03 Architecture SCP03 replaces 3DES with AES-128 (or AES-256) and CMAC for integrity — a significant…

Smart Card Cryptography

ความปลอดภัย

…and latency budgets are tight. Symmetric Algorithms — AES and Legacy Secure element platforms support AES natively…

Side-Channel Attacks and Countermeasures

ความปลอดภัย

…about a small portion of the secret (e.g., one byte of an AES key), computes a statistical distinguisher…

Key Management for Smart Cards

ความปลอดภัย

…GlobalPlatform SCP02 3DES-CBC Legacy card management SCP03 AES-CMAC based Current card management NIST SP 800-108…

Frequently Asked Questions

The smart card glossary is a comprehensive reference of technical terms, acronyms, and concepts used in smart card technology. It covers protocols (APDU, T=0, T=1), security (Common Criteria, EAL, HSM), hardware (SE, EEPROM, contact pad), and applications (EMV, ePassport, eSIM). It serves developers, product managers, and engineers.

Yes. SmartCardFYI provides glossary definitions in 15 languages including English, Korean, Japanese, Chinese, Spanish, Portuguese, Hindi, Arabic, French, Russian, German, Turkish, Vietnamese, Indonesian, and Thai.