GlobalPlatform

Embed This Widget

Theme


      
    

Widget powered by . Free, no account required.

ซอฟต์แวร์

An industry standard for secure management of smart card applications, including applet installation, deletion, and secure channels.

Also known as: GP

GlobalPlatform

GlobalPlatform (GP) is an industry standard that defines the infrastructure for managing applications on secure chip technology — smart cards, Secure Elements, and TEEs. It specifies how applications are securely loaded, installed, deleted, and managed on multi-application cards, providing the administrative framework that sits above the card operating system (typically JavaCard).

Key Concepts

GlobalPlatform organizes card management around Security Domains:

Component Description
Issuer Security Domain (ISD) The card issuer's master domain — controls card lifecycle and delegates privileges
Supplementary Security Domain (SSD) Additional domains for application providers with delegated management authority
CASD (Controlling Authority SD) Optional domain for certification authority token verification
Card Manager The on-card entity that routes APDUs and enforces lifecycle policies

Each Security Domain holds its own set of cryptographic keys for authenticating management operations. This key separation ensures that a payment network can manage its applets independently of the telecom operator's applets on the same card.

Secure Channel Protocols

All management operations (applet installation, key rotation, card locking) are protected by a secure channel:

Protocol Cipher Status
SCP01 3DES Deprecated
SCP02 3DES Legacy, still in SIM cards
SCP03 AES-128/192/256 Current standard
SCP11 ECC + AES For certificate-based mutual authentication

SCP03 is the current production standard, providing AES-based encryption and CMAC integrity protection. SCP11 enables PKI-based authentication, useful for IoT scenarios where pre-shared symmetric keys are impractical.

Card Lifecycle States

GlobalPlatform defines a card lifecycle with controlled transitions:

  1. OP_READY — Card manufactured, ready for personalization
  2. INITIALIZED — ISD keys loaded
  3. SECURED — Production keys set, card ready for deployment
  4. CARD_LOCKED — Card temporarily locked (security event)
  5. TERMINATED — Card permanently disabled

These states are enforced by the card hardware — once a card reaches TERMINATED, it cannot be recovered. This lifecycle model is critical for personalization bureaus managing the secure issuance pipeline.

GlobalPlatform Beyond Smart Cards

GlobalPlatform specifications extend beyond traditional cards to cover TEE management (GPD_SPE_021), eSIM profile management (in coordination with GSMA), and IoT device security. The GP Device Technology specifications define secure device enrollment, firmware update, and device attestation protocols.

Understanding ISO 7816

มาตรฐานและโพรโทคอล

…application management in a multi-application environment GP-aligned 15 Cryptographic information application Key…

GlobalPlatform Card Management

มาตรฐานและโพรโทคอล

GlobalPlatform Card Management GlobalPlatform is the industry consortium…

ISO 7816 Parts Guide

มาตรฐานและโพรโทคอล

…in a multi-application environment Superseded by GlobalPlatform in practice 7816-14 Conformance test plan Test cases for…

Secure Channel Protocols (SCP02/SCP03)

มาตรฐานและโพรโทคอล

Secure Channel Protocols (SCP02/SCP03) GlobalPlatform Secure Channel Protocols establish a mutually…

Smart Card Cryptography

ความปลอดภัย

…800-108 counter-mode KDF or EMV-style diversification. The GlobalPlatform specification governs how card-unique keys are structured…

Key Management for Smart Cards

ความปลอดภัย

…Domain EMV Visa / MasterCard 3DES + KCMVP Legacy payment GlobalPlatform SCP02 3DES-CBC Legacy card management SCP03 AES-CMAC based…

HSM Integration for Smart Cards

ความปลอดภัย

…personalisation key diversification Per-card derived keys GP SCP02/SCP03 PIN block generation / verification PVK, PEK…

TEE vs Secure Element

ความปลอดภัย

…Attestation (Android), Secure Enclave (iOS) Manufacturer + GlobalPlatform Replacement / provisioning OTA firmware update OTA profile…

Frequently Asked Questions

The smart card glossary is a comprehensive reference of technical terms, acronyms, and concepts used in smart card technology. It covers protocols (APDU, T=0, T=1), security (Common Criteria, EAL, HSM), hardware (SE, EEPROM, contact pad), and applications (EMV, ePassport, eSIM). It serves developers, product managers, and engineers.

Yes. SmartCardFYI provides glossary definitions in 15 languages including English, Korean, Japanese, Chinese, Spanish, Portuguese, Hindi, Arabic, French, Russian, German, Turkish, Vietnamese, Indonesian, and Thai.