id: 447fbf24aa7646128896fd37cda6efad
parent_id: fb71e4c4c9b347f6ac6128fe6f01cd18
item_type: 1
item_id: 1fbaa70f2fb94ffcaabbeca7b39482da
item_updated_time: 1782900706969
title_diff: "[]"
body_diff: "[{\"diffs\":[[0,\"iew \"],[-1,\"(A→B→C→D) | 1946×391\"],[1,\"— **two-row flow** (both rows start left; A003 feeds Phase D) | 1712×538\"],[0,\" |\\\n|\"]],\"start1\":521,\"start2\":521,\"length1\":28,\"length2\":80},{\"diffs\":[[0,\"Phase A \"],[-1,\"— KDF3\"],[1,\"full\"],[0,\" (master\"]],\"start1\":623,\"start2\":623,\"length1\":22,\"length2\":20},{\"diffs\":[[0,\"ase-\"],[-1,\"b.puml` | Phase B — session keys (static → SES-*) | 690×1076\"],[1,\"a-1.puml` | Phase A 1/2 (subkeys + S-ENC) — slide | 906×704 |\\\n| `kdf-phase-a-2.puml` | Phase A 2/2 (S-MAC + S-DEK) — slide | 836×718 |\\\n| `kdf-phase-b.puml` | Phase B full (session keys) | 690×1076 |\\\n| `kdf-phase-b-1.puml` | Phase B 1/2 (subkeys + SES-ENC) — slide | 684×699 |\\\n| `kdf-phase-b-2.puml` | Phase B 2/2 (SES-MAC + SES-RMAC) — slide | 747×543\"],[0,\" |\\\n|\"]],\"start1\":685,\"start2\":685,\"length1\":68,\"length2\":359},{\"diffs\":[[0,\"s (card \"],[-1,\"verify \"],[0,\"gate + h\"]],\"start1\":1086,\"start2\":1086,\"length1\":23,\"length2\":16},{\"diffs\":[[0,\"ES-CBC +\"],[-1,\" handle\"],[0,\" cleanup\"]],\"start1\":1161,\"start2\":1161,\"length1\":23,\"length2\":16},{\"diffs\":[[0,\"nd (\"],[-1,\"one \"],[0,\"Word \"],[-1,\"page; tall portrait\"],[1,\"full-page\"],[0,\") | \"]],\"start1\":1234,\"start2\":1234,\"length1\":36,\"length2\":22},{\"diffs\":[[0,\"blishment (slide\"],[-1,\"-fit\"],[0,\", landscape) | 1\"]],\"start1\":1323,\"start2\":1323,\"length1\":36,\"length2\":32},{\"diffs\":[[0,\"e (slide\"],[-1,\"-fit, ~square\"],[0,\") | 967×\"]],\"start1\":1430,\"start2\":1430,\"length1\":29,\"length2\":16},{\"diffs\":[[0,\"\\\n\\\n> \"],[-1,\"The combined `flow-2b-kdf-nethsm.puml` (all KDF phases in one diagram) was\\\n> **removed** — the four phase diagrams + the overview cover it. For PPT use the\\\n> two **slide-fit** splits (`flow-2-provisioning-1/2`); the tall full diagram is\\\n> kept for a single Word full-page. Part 1 uses a **compact KDF block**; the full\\\n> per-phase detail lives in `kdf-phase-a/b/c/d.puml`\"],[1,\"**Layout notes.** `kdf-overview` is now a **two-row flow** (both rows start on the\\\n> left; end of row 1 wraps to the start of row 2), and **A003 now correctly feeds\\\n> Phase D** (not Phase A). Phases A and B are split into two **slide-fit** halves\\\n> each (`-1`/`-2`); the unsuffixed files are the full single-page (Word) versions.\\\n> The combined `flow-2b-kdf-nethsm.puml` was removed (covered by the four phase\\\n> diagrams + overview)\"],[0,\".\\\n\\\n#\"]],\"start1\":1452,\"start2\":1452,\"length1\":379,\"length2\":440},{\"diffs\":[[0,\"overview\"],[1,\" (two-row flow)\"],[0,\"\\\n\\\n```pla\"]],\"start1\":2367,\"start2\":2367,\"length1\":16,\"length2\":31},{\"diffs\":[[0,\"startuml\"],[1,\" kdf-overview\"],[0,\"\\\n' KLMS \"]],\"start1\":2405,\"start2\":2405,\"length1\":16,\"length2\":29},{\"diffs\":[[0,\"b). \"],[-1,\"For PPT/Word embedding\"],[1,\"Two-row flow for PPT.\\\n' Both rows start on the LEFT; end of row1 wraps to start of row2.\\\n' A003 (OEM private key) feeds Phase D, not Phase A\"],[0,\".\\\n\\\ns\"]],\"start1\":2472,\"start2\":2472,\"length1\":30,\"length2\":148},{\"diffs\":[[0,\"ECB\\\" as \"],[1,\"p\"],[0,\"A\\\ncard \\\"\"]],\"start1\":3198,\"start2\":3198,\"length1\":16,\"length2\":17},{\"diffs\":[[0,\"ECB\\\" as \"],[1,\"p\"],[0,\"B\\\ncard \\\"\"]],\"start1\":3270,\"start2\":3270,\"length1\":16,\"length2\":17},{\"diffs\":[[0,\"ECB\\\" as \"],[1,\"p\"],[0,\"C\\\ncard \\\"\"]],\"start1\":3340,\"start2\":3340,\"length1\":16,\"length2\":17},{\"diffs\":[[0,\"ECB\\\" as \"],[1,\"p\"],[0,\"D\\\n\"],[1,\"rectangle \\\"**Outputs to station**\\\\\nSES-* keys - host_cryptogram\\\\\n- A003 ciphertext (pre-encrypted)\\\" as Out #FFF8E1\\\n\\\n' ---- ROW 1: inputs -> Phase A -> Phase B ----\\\nInStation -down-> pA\\\npA -right-> pB : static keys\\\\\n(SE / SM / SD)\"],[0,\"\\\nnote bo\"]],\"start1\":3427,\"start2\":3427,\"length1\":18,\"length2\":248},{\"diffs\":[[0,\"ttom of \"],[1,\"p\"],[0,\"A\\\n  mast\"]],\"start1\":3675,\"start2\":3675,\"length1\":16,\"length2\":17},{\"diffs\":[[0,\"M / SD\\\nend note\\\n\"],[-1,\"\\\n\"],[0,\"note bottom of B\"]],\"start1\":3754,\"start2\":3754,\"length1\":33,\"length2\":32},{\"diffs\":[[0,\"ttom of \"],[1,\"p\"],[0,\"B\\\n  SE /\"]],\"start1\":3777,\"start2\":3777,\"length1\":16,\"length2\":17},{\"diffs\":[[0,\"te\\\n\\\n\"],[-1,\"note bottom of C\\\n  VERIFY card_cryptogram -> GATE\\\n  host_cryptogram\\\nend note\\\n\\\nnote bottom of D\\\n  AES-CBC(S-DEK) -> A003 (private key) ciphertext\\\n  Zeroize all static & session key material\\\nend note\\\n\\\nInStation -down-> A\\\nInOEM -right-> A\\\nA -right-> B : static keys\\\\\n(SE/SM/SD)\\\nB -right\"],[1,\"' ---- wrap: anchor row2 under row1's columns (C under A, D under B); arrow from end of row1 ----\\\npA -[hidden]down-> pC\\\npB -[hidden]down-> pD\\\npB -down\"],[0,\"-> \"],[1,\"p\"],[0,\"C : \"]],\"start1\":3872,\"start2\":3872,\"length1\":294,\"length2\":162},{\"diffs\":[[0,\"AC)\\\n\"],[-1,\"C .\"],[1,\"\\\n' ---- ROW 2: Phase C -> Phase D -> outputs ----\\\npC -\"],[0,\"right\"],[-1,\".\"],[1,\"-\"],[0,\"> \"],[1,\"p\"],[0,\"D : \"],[-1,\" \"],[1,\"authenticated + host_cryptogram\\\\\n\"],[0,\"secu\"]],\"start1\":4048,\"start2\":4048,\"length1\":24,\"length2\":108},{\"diffs\":[[0,\"sted\"],[-1,\"\\\\\n→\"],[1,\" ->\"],[0,\" proceed\"],[-1,\" to encrypt\\\n\\\nrectangle \\\"**Outputs to station**\\\\\nSES-* keys - host_cryptogram\\\\\n- A003 ciphertext (pre-encrypted)\\\" as Out #FFF8E1\\\nD -right-> Out\"],[1,\"\\\nInOEM -down-> pD : A003 private key (SD)\\\\\nIV = 0, AES-CBC\\\npD -right-> Out : pre-encrypted A003\\\nnote bottom of pC\\\n  VERIFY card_cryptogram -> GATE\\\n  then host_cryptogram\\\nend note\\\nnote bottom of pD\\\n  AES-CBC(S-DEK) -> A003 ciphertext\\\n  Zeroize all static & session key material\\\nend note\"],[0,\"\\\n\\\nno\"]],\"start1\":4170,\"start2\":4170,\"length1\":161,\"length2\":304},{\"diffs\":[[0,\" top of \"],[1,\"p\"],[0,\"A #FFEEE\"]],\"start1\":4476,\"start2\":4476,\"length1\":16,\"length2\":17},{\"diffs\":[[0,\" A: KDF3\"],[1,\" (full, Word page)\"],[0,\"\\\n\\\n```pla\"]],\"start1\":4668,\"start2\":4668,\"length1\":16,\"length2\":34},{\"diffs\":[[0,\"uml\\\n```\\\n\\\n* * *\\\n\\\n\"],[1,\"## kdf-phase-a-1.puml — Phase A (1/2): subkeys + S-ENC (slide)\\\n\\\n```plantuml\\\n@startuml kdf-phase-a-1\\\n' Phase A (1/2): master subkeys + S-ENC. Continues in kdf-phase-a-2.puml.\\\n' Splits the portrait Phase A into two landscape halves for PPT.\\\nautonumber\\\ntitle Phase A — KDF3 (1/2): master subkeys + S-ENC\\\nparticipant KLMS\\\nparticipant \\\"NetHSM\\\\\nMaster Key M\\\" as HSM\\\n\\\n== Master Subkeys (RFC 4493) ==\\\nKLMS -> HSM : ECB(M, 0^16)\\\nHSM --> KLMS : L_M\\\nKLMS -> KLMS : K1_M = dbl(L_M)\\\nKLMS -> KLMS : K2_M = dbl(K1_M)\\\nnote left of KLMS : **dbl** is the doubling that CMAC uses to derive its subkeys K1 and K2.\\\\\nFor a 16‑byte block X: dbl(X) = (X << 1)  XOR  (Rb if MSB(X)=1, else 0)\\\\\nwith Rb = 00^15 87 (i.e. 15 zero bytes + 0x87).\\\\\n**In plain terms**: shift the 128‑bit value left by one bit;\\\\\nif the top bit that was shifted out was a 1, XOR 0x87 into the last byte.\\\n\\\n== S-ENC (purpose 0x40, 10-B UID from station) ==\\\nKLMS -> KLMS : header = 00^11 ‖ 40 (purpose) ‖ 00 ‖ 0080 ‖ 01\\\nKLMS -> HSM : ECB(M, header)\\\nHSM --> KLMS : C1\\\nKLMS -> HSM : ECB(M, C1 ⊕ pad(UID, 16-B) ⊕ K2_M)\\\nHSM --> KLMS : C2 = **S-ENC**\\\nKLMS -> HSM : ImportKey(S-ENC)\\\nHSM --> KLMS : handle **SE**\\\n@enduml\\\n```\\\n\\\n* * *\\\n\\\n## kdf-phase-a-2.puml — Phase A (2/2): S-MAC + S-DEK (slide)\\\n\\\n```plantuml\\\n@startuml kdf-phase-a-2\\\n' Phase A (2/2): S-MAC + S-DEK. Continues from kdf-phase-a-1.puml.\\\nautonumber\\\ntitle Phase A — KDF3 (2/2): S-MAC + S-DEK\\\nparticipant KLMS\\\nparticipant \\\"NetHSM\\\\\nMaster Key M\\\" as HSM\\\nnote left of KLMS : (continues) K1_M / K2_M already derived from L_M (see 1/2).\\\n\\\n== S-MAC (purpose 0x60, 10-B UID from station) ==\\\nKLMS -> KLMS : header = 00^11 ‖ 60 (purpose) ‖ 00 ‖ 0080 ‖ 01\\\nKLMS -> HSM : ECB(M, header)\\\nHSM --> KLMS : C1\\\nKLMS -> HSM : ECB(M, C1 ⊕ pad(UID, 16-B) ⊕ K2_M)\\\nHSM --> KLMS : C2 = **S-MAC**\\\nKLMS -> HSM : ImportKey(S-MAC)\\\nHSM --> KLMS : handle **SM**\\\n\\\n== S-DEK (purpose 0x70, 10-B UID from station) ==\\\nKLMS -> KLMS : header = 00^11 ‖ 70 (purpose) ‖ 00 ‖ 0080 ‖ 01\\\nKLMS -> HSM : ECB(M, header)\\\nHSM --> KLMS : C1\\\nKLMS -> HSM : ECB(M, C1 ⊕ pad(UID, 16-B) ⊕ K2_M)\\\nHSM --> KLMS : C2 = **S-DEK**\\\nKLMS -> HSM : ImportKey(S-DEK)\\\nHSM --> KLMS : handle **SD**\\\n@enduml\\\n```\\\n\\\n* * *\\\n\\\n\"],[0,\"## kdf-phase-b.p\"]],\"start1\":6339,\"start2\":6339,\"length1\":32,\"length2\":2179},{\"diffs\":[[0,\"ion keys\"],[1,\" (full, Word page)\"],[0,\"\\\n\\\n```pla\"]],\"start1\":8537,\"start2\":8537,\"length1\":16,\"length2\":34},{\"diffs\":[[0,\"uml\\\n```\\\n\\\n* * *\\\n\\\n\"],[1,\"## kdf-phase-b-1.puml — Phase B (1/2): subkeys + SES-ENC (slide)\\\n\\\n```plantuml\\\n@startuml kdf-phase-b-1\\\n' Phase B (1/2): session subkeys + SES-ENC. Continues in kdf-phase-b-2.puml.\\\nautonumber\\\ntitle Phase B — Session keys (1/2): subkeys + SES-ENC\\\nparticipant KLMS\\\nparticipant \\\"NetHSM\\\" as HSM\\\n\\\n== session subkeys (RFC 4493) ==\\\nKLMS -> HSM : ECB(SE, 0^16)\\\nHSM --> KLMS : L_SE\\\nKLMS -> KLMS : K1_SE = dbl(L_SE)\\\nKLMS -> KLMS : K2_SE = dbl(K1_SE)\\\nKLMS -> HSM : ECB(SM, 0^16)\\\nHSM --> KLMS : L_SM\\\nKLMS -> KLMS : K1_SM = dbl(L_SM)\\\nKLMS -> KLMS : K2_SM = dbl(K1_SM)\\\nnote left of KLMS : session deriv data = 32 B = block1 ‖ block2\\\\\n(usage ‖ host_challenge ‖ card_challenge ‖ …)\\\\\nboth blocks full (16 B) -> last block XOR **K1**\\\\\n(K2 is used only for a *partial* last block, as in Phase A)\\\n\\\n== SES-ENC (usage 0x04) ==\\\nKLMS -> HSM : ECB(SE, block1)\\\nHSM --> KLMS : C1\\\nKLMS -> HSM : ECB(SE, C1 ⊕ block2 ⊕ K1_SE)\\\nHSM --> KLMS : C2 = **SES-ENC**  (-> station)\\\n@enduml\\\n```\\\n\\\n* * *\\\n\\\n## kdf-phase-b-2.puml — Phase B (2/2): SES-MAC + SES-RMAC (slide)\\\n\\\n```plantuml\\\n@startuml kdf-phase-b-2\\\n' Phase B (2/2): SES-MAC + SES-RMAC. Continues from kdf-phase-b-1.puml.\\\nautonumber\\\ntitle Phase B — Session keys (2/2): SES-MAC + SES-RMAC\\\nparticipant KLMS\\\nparticipant \\\"NetHSM\\\" as HSM\\\nnote left of KLMS : (continues) K1_SM / K2_SM already derived from L_SM (see 1/2).\\\n\\\n== SES-MAC (usage 0x06) ==\\\nKLMS -> HSM : ECB(SM, block1)\\\nHSM --> KLMS : C1\\\nKLMS -> HSM : ECB(SM, C1 ⊕ block2 ⊕ K1_SM)\\\nHSM --> KLMS : C2 = **SES-MAC**  (-> station)\\\nKLMS -> HSM : ImportKey(SES-MAC)\\\nHSM --> KLMS : handle **SESMAC**\\\n\\\n== SES-RMAC (usage 0x07, reuse K1_SM) ==\\\nKLMS -> HSM : ECB(SM, block1)\\\nHSM --> KLMS : C1\\\nKLMS -> HSM : ECB(SM, C1 ⊕ block2 ⊕ K1_SM)\\\nHSM --> KLMS : C2 = **SES-RMAC**  (-> station)\\\n@enduml\\\n```\\\n\\\n* * *\\\n\\\n\"],[0,\"## kdf-phase-c.p\"]],\"start1\":9847,\"start2\":9847,\"length1\":32,\"length2\":1792},{\"diffs\":[[0,\"o-end (Word \"],[-1,\"full-\"],[0,\"page)\\\n\\\n```pl\"]],\"start1\":13990,\"start2\":13990,\"length1\":29,\"length2\":24},{\"diffs\":[[0,\"lide\"],[-1,\"-fit, landscape\"],[0,\")\\\n\\\n`\"]],\"start1\":17579,\"start2\":17579,\"length1\":23,\"length2\":8},{\"diffs\":[[0,\"lide\"],[-1,\"-fit, ~square\"],[0,\")\\\n\\\n`\"]],\"start1\":19998,\"start2\":19998,\"length1\":21,\"length2\":8}]"
metadata_diff: {"new":{},"deleted":[]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-07-01T10:17:50.841Z
created_time: 2026-07-01T10:17:50.841Z
type_: 13