SCP03中16字节密钥生成APDU加密ICV的算法与模式问询
Question
I'm trying to understand the algorithm and mode used to generate the encrypted ICV for APDU data fields in SCP03. According to section 6.2.6 "Generation and Verification of APDU Command C-MAC and C-DECRYPTION" from Secure Channel Protocol '03' – Public Release v1.1.1:
When both command confidentiality (C-DECRYPTION) and integrity (C-MAC) are required, subsequent APDU commands within the secure channel must use secure messaging mechanisms such as C-MAC (integrity) and encryption (confidentiality). The off-card entity must increment an encryption counter for each APDU command sent within a secure channel session:
- The encryption counter is initialized to 1 for the first command after successful execution of the EXTERNAL AUTHENTICATE command;
- Left-pad the binary value of the encryption counter to form a complete block;
- Encrypt this block using S-ENC to generate the command encryption ICV.
The note mentions this scheme complies with the requirement for unpredictable ICVs under CBC mode in [NIST 800-38A].
My question is: When using a 16-byte key and a 16-byte input (the left-padded encryption counter, e.g., counter 1 becomes 00000000000000000000000000000001), which specific algorithm should be used?
Answer
Great question—let's break this down clearly based on SCP03 specs and the NIST reference you mentioned.
First, let's anchor this to the core of SCP03's design: it relies on symmetric cryptography, and the S-ENC primitive (used for encryption operations in the secure channel) maps directly to AES-128 in CBC mode for your 16-byte key/block scenario. Here's why this fits perfectly:
- Key & Block Size Alignment: AES-128 uses exactly 16-byte (128-bit) keys and operates on 16-byte blocks—this matches your input parameters perfectly. Longer AES variants (192/256) would require 24/32-byte keys, which aren't your case here.
- NIST 800-38A CBC Compliance: The note calls out CBC mode requirements for unpredictable ICVs. For this specific ICV generation step, the critical detail is that you'll use an all-zero IV when encrypting the padded counter block with AES-128-CBC. This is a defined implementation rule in SCP03 for this process, ensuring the ICV is unique and unpredictable as the counter increments per command.
- SCP03's S-ENC Definition: The S-ENC primitive in SCP03 is standardized to use AES for encryption/decryption operations. Since your key is 16 bytes, AES-128 is the mandatory choice here.
To make this concrete for your example (counter = 1, padded to 16 bytes):
- Start with the padded counter block:
00000000000000000000000000000001 - Initialize CBC mode with an IV of
00000000000000000000000000000000(16 bytes of zeros) - Encrypt this single block using AES-128 with your 16-byte S-ENC key
- The resulting 16-byte ciphertext is your command encryption ICV
This approach ensures the ICV meets both SCP03's secure messaging rules and NIST 800-38A's CBC mode requirements for unpredictability.
内容的提问来源于stack exchange,提问作者vion

