id: fb71e4c4c9b347f6ac6128fe6f01cd18
parent_id: 872a50fc87074c50a99c36bb0324fd57
item_type: 1
item_id: 1fbaa70f2fb94ffcaabbeca7b39482da
item_updated_time: 1782899780731
title_diff: "[]"
body_diff: "[{\"diffs\":[[0,\"tecture.\"],[-1,\"  \"],[0,\"\\\n> Files\"]],\"start1\":119,\"start2\":119,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"uml`\"],[-1,\". R\"],[1,\"; r\"],[0,\"endered \"],[-1,\"PNG/SVG\"],[1,\"**SVG** (scalable, for\\\n> PPT/Word) and **PNG**\"],[0,\" go \"]],\"start1\":174,\"start2\":174,\"length1\":26,\"length2\":65},{\"diffs\":[[0,\"ide \"],[-1,\" \\\n> them\"],[1,\"each source\"],[0,\". Co\"]],\"start1\":245,\"start2\":245,\"length1\":16,\"length2\":19},{\"diffs\":[[0,\"ions: **\"],[-1,\"\\\"\"],[0,\"Keyfob F\"]],\"start1\":268,\"start2\":268,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"b Flow 1\"],[-1,\"\\\"\"],[0,\"**,\"],[1,\"\\\n>\"],[0,\" **\"],[-1,\"\\\"\"],[0,\"Keyfob F\"]],\"start1\":281,\"start2\":281,\"length1\":24,\"length2\":24},{\"diffs\":[[0,\"ow 2\"],[-1,\"\\\"\"],[0,\"**\"],[1,\" (sequence detail)\"],[0,\", **\"],[-1,\"\\\"\"],[0,\"Keyf\"]],\"start1\":306,\"start2\":306,\"length1\":16,\"length2\":32},{\"diffs\":[[0,\"low 2b —\"],[-1,\"  \\\n>\"],[0,\" KLMS ↔ \"]],\"start1\":342,\"start2\":342,\"length1\":20,\"length2\":16},{\"diffs\":[[0,\"tHSM AES\"],[1,\"\\\n>\"],[0,\" Orchest\"]],\"start1\":360,\"start2\":360,\"length1\":16,\"length2\":18},{\"diffs\":[[0,\"stration\"],[-1,\"\\\"\"],[0,\"**\"],[1,\" (per-message AES-ECB table)\"],[0,\".\\\n\\\n## Di\"]],\"start1\":376,\"start2\":376,\"length1\":19,\"length2\":46},{\"diffs\":[[0,\" Shows |\"],[-1,\"\\\n\"],[1,\" SVG (px W×H) |\\\n| --- \"],[0,\"| --- | \"]],\"start1\":438,\"start2\":438,\"length1\":17,\"length2\":38},{\"diffs\":[[0,\"B→C→D) |\"],[1,\" 1946×391 |\"],[0,\"\\\n| `kdf-\"]],\"start1\":528,\"start2\":528,\"length1\":16,\"length2\":27},{\"diffs\":[[0,\" keys) |\"],[1,\" 915×1225 |\"],[0,\"\\\n| `kdf-\"]],\"start1\":606,\"start2\":606,\"length1\":16,\"length2\":27},{\"diffs\":[[0,\"SES-\"],[-1,\"\\\\\"],[0,\"*) |\"],[1,\" 690×1076 |\"],[0,\"\\\n| `\"]],\"start1\":682,\"start2\":682,\"length1\":13,\"length2\":23},{\"diffs\":[[0,\"st cg) |\"],[1,\" 885×983 |\"],[0,\"\\\n| `kdf-\"]],\"start1\":769,\"start2\":769,\"length1\":16,\"length2\":26},{\"diffs\":[[0,\"up |\"],[-1,\"\\\n| `flow-2b-kdf-nethsm.puml` | Combined KLMS↔NetHSM KDF\"],[1,\" 908×700 |\\\n| `flow-2-provisioning.puml` | Full end-to-end (one Word page; tall portrait) | 1384×2210 |\\\n| `flow-2-provisioning-1.puml` | Flow 2a — Session establishment (slide-fit, landscape) | 1639×1134 |\\\n| `flow-2-provisioning-2.puml` | Flow 2b — Personalize & finalize (slide-fit, ~square) | 967×1087 |\\\n\\\n> The combined `flow-2b-kdf-nethsm.puml`\"],[0,\" (all \"],[1,\"KDF \"],[0,\"phases\"],[-1,\",\"],[1,\" in\"],[0,\" one\"]],\"start1\":848,\"start2\":848,\"length1\":76,\"length2\":373},{\"diffs\":[[0,\"am) \"],[-1,\"|\\\n| `flow-2-provisioning.puml` | Key Fob ↔ Station ↔ KLMS (↔ NetHSM) end-to-end |\"],[1,\"was\\\n> **removed** — the four phase diagrams + the overview cover it. For PPT use the\\\n> two **slide-fit** splits (`flow-2-provisioning-1/2`); the tall full diagram is\\\n> kept for a single Word full-page. Part 1 uses a **compact KDF block**; the full\\\n> per-phase detail lives in `kdf-phase-a/b/c/d.puml`.\"],[0,\"\\\n\\\n##\"]],\"start1\":1227,\"start2\":1227,\"length1\":89,\"length2\":309},{\"diffs\":[[0,\"via \"],[-1,\"the \"],[0,\"deflate/\"],[-1,\"base64\"],[1,\"map6\"],[0,\" encoder\"],[1,\" (+ UA header)\"],[0,\"\\\npyt\"]],\"start1\":1669,\"start2\":1669,\"length1\":34,\"length2\":42},{\"diffs\":[[0,\"diagrams\"],[1,\"        # PNG always; SVG only if missing\\\npython3 ~/render_puml.py docs/diagrams --svg  # also (re)render SVG\"],[0,\"\\\n```\\\n\\\nFo\"]],\"start1\":1738,\"start2\":1738,\"length1\":16,\"length2\":125},{\"diffs\":[[0,\"PPT/Word\"],[-1,\",\"],[0,\" embed t\"]],\"start1\":1865,\"start2\":1865,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"ble)\"],[-1,\" or **PNG**\"],[0,\". Se\"]],\"start1\":1898,\"start2\":1898,\"length1\":19,\"length2\":8},{\"diffs\":[[0,\"ver \"],[-1,\"base \"],[0,\"URL:\"],[-1,\"  \"],[0,\"\\\n`ht\"]],\"start1\":1907,\"start2\":1907,\"length1\":19,\"length2\":12},{\"diffs\":[[0,\"startuml\"],[-1,\" kdf-overview\"],[0,\"\\\n' KLMS \"]],\"start1\":2033,\"start2\":2033,\"length1\":29,\"length2\":16},{\"diffs\":[[0,\"tion\"],[1,\" (from fob)\"],[0,\"**\\\\\n\"],[1,\"- \"],[0,\"UID\"],[-1,\" \"],[1,\"\\\\\n\"],[0,\"- ho\"]],\"start1\":2446,\"start2\":2446,\"length1\":16,\"length2\":30},{\"diffs\":[[0,\"hallenge\"],[-1,\" \"],[1,\"\\\\\n\"],[0,\"- card_c\"]],\"start1\":2480,\"start2\":2480,\"length1\":17,\"length2\":18},{\"diffs\":[[0,\"gram\"],[-1,\" (from fob\"],[1,\"\\\" as InStation #E8F5E9\\\nrectangle \\\"**Inputs from OEM key feed**\\\\\n- Private Key for Key Fob (A003\"],[0,\")\\\" as In\"],[1,\"OEM\"],[0,\" #E8\"]],\"start1\":2521,\"start2\":2521,\"length1\":26,\"length2\":114},{\"diffs\":[[0,\"ase D — A003\"],[1,\" (private key)\"],[0,\" CBC + clean\"]],\"start1\":2855,\"start2\":2855,\"length1\":24,\"length2\":38},{\"diffs\":[[0,\" as D\\\n\\\nnote \"],[-1,\"right\"],[1,\"bottom\"],[0,\" of A\\\n  mast\"]],\"start1\":2925,\"start2\":2925,\"length1\":29,\"length2\":30},{\"diffs\":[[0,\"ote \"],[-1,\"right\"],[1,\"bottom\"],[0,\" of B\\\n  \"],[1,\"SE / SM \"],[0,\"-> S\"]],\"start1\":3035,\"start2\":3035,\"length1\":21,\"length2\":30},{\"diffs\":[[0,\" note\\\n\\\nnote \"],[-1,\"right\"],[1,\"bottom\"],[0,\" of C\\\n  VERI\"]],\"start1\":3132,\"start2\":3132,\"length1\":29,\"length2\":30},{\"diffs\":[[0,\"ram \"],[-1,\" \"],[0,\"->\"],[-1,\" \"],[0,\" GATE\\\n  \"],[-1,\"then \"],[0,\"host\"]],\"start1\":3177,\"start2\":3177,\"length1\":25,\"length2\":18},{\"diffs\":[[0,\" note\\\n\\\nnote \"],[-1,\"right\"],[1,\"bottom\"],[0,\" of D\\\n  AES-\"]],\"start1\":3210,\"start2\":3210,\"length1\":29,\"length2\":30},{\"diffs\":[[0,\"003 \"],[-1,\"ciphertext\\\n  Destroy SE / SM / SD / SESMAC; zeroize RAM\"],[1,\"(private key) ciphertext\\\n  Zeroize all static & session key material\"],[0,\"\\\nend\"]],\"start1\":3255,\"start2\":3255,\"length1\":63,\"length2\":76},{\"diffs\":[[0,\"note\\\n\\\nIn\"],[1,\"Station\"],[0,\" -down->\"]],\"start1\":3332,\"start2\":3332,\"length1\":16,\"length2\":23},{\"diffs\":[[0,\"> A\\\n\"],[-1,\"A -down\"],[1,\"InOEM -right-> A\\\nA -right\"],[0,\"-> B\"]],\"start1\":3354,\"start2\":3354,\"length1\":15,\"length2\":33},{\"diffs\":[[0,\"tic keys\"],[-1,\" \"],[1,\"\\\\\n\"],[0,\"(SE/SM/S\"]],\"start1\":3393,\"start2\":3393,\"length1\":17,\"length2\":18},{\"diffs\":[[0,\"/SD)\\\nB -\"],[-1,\"down\"],[1,\"right\"],[0,\"-> C : S\"]],\"start1\":3409,\"start2\":3409,\"length1\":20,\"length2\":21},{\"diffs\":[[0,\" SES-MAC\"],[-1,\" \"],[1,\"\\\\\n\"],[0,\"(SESMAC)\"]],\"start1\":3428,\"start2\":3428,\"length1\":17,\"length2\":18},{\"diffs\":[[0,\")\\\nC \"],[-1,\"-down-> D : authenticated + host_cryptogram\"],[1,\".right.> D :  secure channel trusted\\\\\n→ proceed to encrypt\"],[0,\"\\\n\\\nre\"]],\"start1\":3445,\"start2\":3445,\"length1\":51,\"length2\":66},{\"diffs\":[[0,\"F8E1\\\nD -\"],[-1,\"down\"],[1,\"right\"],[0,\"-> Out\\\n\\\n\"]],\"start1\":3619,\"start2\":3619,\"length1\":20,\"length2\":21},{\"diffs\":[[0,\"ote \"],[-1,\"as N1\"],[1,\"top of A\"],[0,\" #FF\"]],\"start1\":3641,\"start2\":3641,\"length1\":13,\"length2\":16},{\"diffs\":[[0,\"ver \"],[-1,\"returned (0 bytes)\"],[1,\"exposed\"],[0,\".\\\n  \"]],\"start1\":3727,\"start2\":3727,\"length1\":26,\"length2\":15},{\"diffs\":[[0,\"ote\\\n\"],[-1,\"A .. N1\\\n\"],[0,\"@end\"]],\"start1\":3784,\"start2\":3784,\"length1\":16,\"length2\":8},{\"diffs\":[[0,\"startuml\"],[-1,\" kdf-phase-a\"],[0,\"\\\n' Phase\"]],\"start1\":3858,\"start2\":3858,\"length1\":28,\"length2\":16},{\"diffs\":[[0,\"tic keys\"],[1,\" (S-ENC/S-MAC/S-DEK)\"],[0,\"\\\n\\\npartic\"]],\"start1\":4004,\"start2\":4004,\"length1\":16,\"length2\":36},{\"diffs\":[[0,\"SM\\\\\n\"],[-1,\"(m\"],[1,\"M\"],[0,\"aster \"],[-1,\"M sealed)\"],[1,\"Key M\"],[0,\"\\\" as\"]],\"start1\":4068,\"start2\":4068,\"length1\":25,\"length2\":20},{\"diffs\":[[0,\"HSM\\\n\\\n== \"],[-1,\"m\"],[1,\"M\"],[0,\"aster \"],[-1,\"s\"],[1,\"S\"],[0,\"ubkeys (\"]],\"start1\":4089,\"start2\":4089,\"length1\":24,\"length2\":24},{\"diffs\":[[0,\"L_M\\\n\"],[-1,\"note right of KLMS : host\"],[1,\"KLMS -> KLMS \"],[0,\": K1\"]],\"start1\":4168,\"start2\":4168,\"length1\":33,\"length2\":21},{\"diffs\":[[0,\" K1_M = dbl(L_M)\"],[-1,\", \"],[1,\"\\\nKLMS -> KLMS :\"],[0,\" K2_M = dbl(K1_M\"]],\"start1\":4186,\"start2\":4186,\"length1\":34,\"length2\":47},{\"diffs\":[[0,\"bl(K1_M)\"],[1,\"\\\nnote left of KLMS : **dbl** is the doubling that CMAC uses to derive its subkeys K1 and K2.\\\\\nFor a 16‑byte block X: dbl(X) = (X << 1)  XOR  (Rb if MSB(X)=1, else 0)\\\\\nwith Rb = 00^15 87 (i.e. 15 zero bytes + 0x87).\\\\\n**In plain terms**: shift the 128‑bit value left by one bit;\\\\\nif the top bit that was shifted out was a 1, XOR 0x87 into the last byte.\"],[0,\"\\\n\\\n== S-E\"]],\"start1\":4226,\"start2\":4226,\"length1\":16,\"length2\":367},{\"diffs\":[[0,\"40, \"],[-1,\"26-B deriv data) ==\"],[1,\"10-B UID from station) ==\\\nKLMS -> KLMS : header = 00^11 ‖ 40 (purpose) ‖ 00 ‖ 0080 ‖ 01\"],[0,\"\\\nKLM\"]],\"start1\":4607,\"start2\":4607,\"length1\":27,\"length2\":95},{\"diffs\":[[0,\"-> HSM : ECB(M, \"],[-1,\"block1\"],[1,\"header\"],[0,\")\\\nHSM --> KLMS :\"]],\"start1\":4704,\"start2\":4704,\"length1\":38,\"length2\":38},{\"diffs\":[[0,\"SM : ECB(M, \"],[-1,\"pad(block2) ^\"],[1,\"C1 ⊕ pad(UID, 16-B) ⊕\"],[0,\" K2_M)\\\nHSM -\"]],\"start1\":4755,\"start2\":4755,\"length1\":37,\"length2\":45},{\"diffs\":[[0,\"ose 0x60\"],[-1,\") ==\"],[1,\", 10-B UID from station) ==\\\nKLMS -> KLMS : header = 00^11 ‖ 60 (purpose) ‖ 00 ‖ 0080 ‖ 01\"],[0,\"\\\nKLMS ->\"]],\"start1\":4900,\"start2\":4900,\"length1\":20,\"length2\":105},{\"diffs\":[[0,\"-> HSM : ECB(M, \"],[-1,\"block1\"],[1,\"header\"],[0,\")\\\nHSM --> KLMS :\"]],\"start1\":5003,\"start2\":5003,\"length1\":38,\"length2\":38},{\"diffs\":[[0,\"SM : ECB(M, \"],[-1,\"pad(block2) ^\"],[1,\"C1 ⊕ pad(UID, 16-B) ⊕\"],[0,\" K2_M)\\\nHSM -\"]],\"start1\":5054,\"start2\":5054,\"length1\":37,\"length2\":45},{\"diffs\":[[0,\"ose 0x70\"],[-1,\") ==\"],[1,\", 10-B UID from station) ==\\\nKLMS -> KLMS : header = 00^11 ‖ 70 (purpose) ‖ 00 ‖ 0080 ‖ 01\"],[0,\"\\\nKLMS ->\"]],\"start1\":5199,\"start2\":5199,\"length1\":20,\"length2\":105},{\"diffs\":[[0,\" ECB(M, \"],[-1,\"block1\"],[1,\"header\"],[0,\")\\\nHSM --\"]],\"start1\":5310,\"start2\":5310,\"length1\":22,\"length2\":22},{\"diffs\":[[0,\"SM : ECB(M, \"],[-1,\"pad(block2) ^\"],[1,\"C1 ⊕ pad(UID, 16-B) ⊕\"],[0,\" K2_M)\\\nHSM -\"]],\"start1\":5353,\"start2\":5353,\"length1\":37,\"length2\":45},{\"diffs\":[[0,\"**\\\n\\\n\"],[-1,\"note over HSM #FFEEEE : master M never returned (7 AES-ECB calls)\\\nnote over KLMS : block1 = 16-B header; block2 = raw 10-B UID (partial -> padded)\\\\\nlayouts: crates/kf-scp03/src/derive.rs (build_static_derivation_data)\\\n\"],[0,\"@end\"]],\"start1\":5480,\"start2\":5480,\"length1\":226,\"length2\":8},{\"diffs\":[[0,\"B CMAC.\\\n\"],[-1,\"\\\n\"],[0,\"autonumb\"]],\"start1\":5651,\"start2\":5651,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"> SES-*\\\n\"],[-1,\"\\\n\"],[0,\"particip\"]],\"start1\":5716,\"start2\":5716,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\" as HSM\\\n\"],[-1,\"\\\n\"],[0,\"== sessi\"]],\"start1\":5761,\"start2\":5761,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"_SE\\\n\"],[-1,\"note right of KLMS : host: K1_SE, K2_SE\\\nKLMS -> HSM : ECB(SM, 0^16)\\\nHSM --> KLMS : L_SM\"],[1,\"KLMS -> KLMS : K1_SE = dbl(L_SE)\\\nKLMS -> KLMS : K2_SE = dbl(K1_SE)\\\nKLMS -> HSM : ECB(SM, 0^16)\\\nHSM --> KLMS : L_SM\\\nKLMS -> KLMS : K1_SM = dbl(L_SM)\\\nKLMS -> KLMS : K2_SM = dbl(K1_SM)\"],[0,\"\\\nnote \"],[-1,\"righ\"],[1,\"lef\"],[0,\"t of\"]],\"start1\":5846,\"start2\":5846,\"length1\":105,\"length2\":198},{\"diffs\":[[0,\"S : \"],[-1,\"host: K1_SM, K2_SM\\\n\\\n== SES-ENC (const 0x04, 32-B deriv data\"],[1,\"session deriv data = 32 B = block1 ‖ block2\\\\\n(usage ‖ host_challenge ‖ card_challenge ‖ …)\\\\\nboth blocks full (16 B) -> last block XOR **K1**\\\\\n(K2 is used only for a *partial* last block, as in Phase A)\\\n== SES-ENC (usage 0x04\"],[0,\") ==\"]],\"start1\":6048,\"start2\":6048,\"length1\":67,\"length2\":232},{\"diffs\":[[0,\"SM : ECB(SE,\"],[1,\" C1 ⊕\"],[0,\" block2 \"],[-1,\"^\"],[1,\"⊕\"],[0,\" K1_SE)\\\nHSM \"]],\"start1\":6338,\"start2\":6338,\"length1\":33,\"length2\":38},{\"diffs\":[[0,\"tation)\\\n\"],[-1,\"\\\n\"],[0,\"== SES-M\"]],\"start1\":6410,\"start2\":6410,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"== SES-MAC (\"],[-1,\"const\"],[1,\"usage\"],[0,\" 0x06) ==\\\nKL\"]],\"start1\":6418,\"start2\":6418,\"length1\":29,\"length2\":29},{\"diffs\":[[0,\"SM : ECB(SM,\"],[1,\" C1 ⊕\"],[0,\" block2 \"],[-1,\"^\"],[1,\"⊕\"],[0,\" K1_SM)\\\nHSM \"]],\"start1\":6502,\"start2\":6502,\"length1\":33,\"length2\":38},{\"diffs\":[[0,\"ESMAC**\\\n\"],[-1,\"\\\n\"],[0,\"== SES-R\"]],\"start1\":6640,\"start2\":6640,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"S-RMAC (\"],[-1,\"const\"],[1,\"usage\"],[0,\" 0x07, r\"]],\"start1\":6653,\"start2\":6653,\"length1\":21,\"length2\":21},{\"diffs\":[[0,\"SM : ECB(SM,\"],[1,\" C1 ⊕\"],[0,\" block2 \"],[-1,\"^\"],[1,\"⊕\"],[0,\" K1_SM)\\\nHSM \"]],\"start1\":6746,\"start2\":6746,\"length1\":33,\"length2\":38},{\"diffs\":[[0,\"ion)\"],[-1,\"\\\n\\\nnote over HSM #FFEEEE : 8 AES-ECB calls; block2 is full -> XOR K1\\\nnote over KLMS : 32-B deriv data = 16-B header || host_challenge || card_challenge\\\\\n(crates/kf-scp03/src/derive.rs :: build_derivation_data)\"],[0,\"\\\n@en\"]],\"start1\":6822,\"start2\":6822,\"length1\":216,\"length2\":8},{\"diffs\":[[0,\"togram.\\\n\"],[-1,\"\\\n\"],[0,\"autonumb\"]],\"start1\":7006,\"start2\":7006,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"SESMAC)\\\n\"],[-1,\"\\\n\"],[0,\"particip\"]],\"start1\":7060,\"start2\":7060,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\" as HSM\\\n\"],[-1,\"\\\n\"],[0,\"== crypt\"]],\"start1\":7105,\"start2\":7105,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"-> KLMS : L\\\n\"],[1,\"KLMS -> KLMS : K1 = dbl(L)\\\nKLMS -> KLMS : K2 = dbl(K1)\\\n\"],[0,\"note \"],[-1,\"righ\"],[1,\"lef\"],[0,\"t of KLMS : \"]],\"start1\":7186,\"start2\":7186,\"length1\":33,\"length2\":87},{\"diffs\":[[0,\" KLMS : \"],[-1,\"host: K1, K2\\\n\"],[1,\"cryptogram deriv data = 32 B = block1 ‖ block2\\\\\n(const ‖ host_challenge ‖ card_challenge ‖ …)\\\\\nboth blocks full (16 B) -> last block XOR **K1**\\\\\ncryptogram = CMAC tag truncated to 8 B\\\\\n(crates/kf-scp03/src/derive.rs)\"],[0,\"\\\n== card\"]],\"start1\":7265,\"start2\":7265,\"length1\":29,\"length2\":232},{\"diffs\":[[0,\" ECB(SESMAC,\"],[1,\" C1 ⊕\"],[0,\" block2 \"],[-1,\"^\"],[1,\"⊕\"],[0,\" K1)\\\nHSM -->\"]],\"start1\":7604,\"start2\":7604,\"length1\":33,\"length2\":38},{\"diffs\":[[0,\"LMS : C2\"],[-1,\" -> truncate 8 B\"],[1,\"\\\nKLMS -> KLMS : card_crypto = C2[0:8]\"],[0,\"\\\nKLMS ->\"]],\"start1\":7644,\"start2\":7644,\"length1\":32,\"length2\":53},{\"diffs\":[[0,\"S : compare \"],[1,\"card_crypto \"],[0,\"== fob **car\"]],\"start1\":7701,\"start2\":7701,\"length1\":24,\"length2\":36},{\"diffs\":[[0,\"ogram**\\\n\"],[-1,\"\\\n\"],[0,\"alt matc\"]],\"start1\":7744,\"start2\":7744,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"ed)\\\n\"],[-1,\"  stop\\\n\"],[0,\"end\\\n\"],[-1,\"\\\n\"],[0,\"== h\"]],\"start1\":7897,\"start2\":7897,\"length1\":20,\"length2\":12},{\"diffs\":[[0,\" ECB(SESMAC,\"],[1,\" C1 ⊕\"],[0,\" block2 \"],[-1,\"^\"],[1,\"⊕\"],[0,\" K1)\\\nHSM -->\"]],\"start1\":8018,\"start2\":8018,\"length1\":33,\"length2\":38},{\"diffs\":[[0,\": C2\"],[-1,\" -> truncate 8 B = **host_cryptogram**  (-> station)\\\n\\\nnote over HSM #FFEEEE : 5 AES-ECB calls\\\nnote over KLMS : card/host cryptograms keyed by SES-MAC (crates/kf-scp03/src/derive.rs\"],[1,\"\\\nKLMS -> KLMS : host_crypto = C2[0:8] = **host_cryptogram**  (-> station\"],[0,\")\\\n@e\"]],\"start1\":8062,\"start2\":8062,\"length1\":188,\"length2\":80},{\"diffs\":[[0,\"leanup.\\\n\"],[-1,\"\\\n\"],[0,\"autonumb\"]],\"start1\":8316,\"start2\":8316,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"cleanup\\\n\"],[-1,\"\\\n\"],[0,\"particip\"]],\"start1\":8377,\"start2\":8377,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"HSM\\\" as HSM\\\n\"],[1,\"note left of KLMS : A003 encrypted with **S-DEK (SD)** — a static per-fob key,\\\\\nindependent of the session. IV = 0; host chains AES-CBC from\\\\\nsingle-block ECB (ISO 9797-1 Method 2 padding). SD never sent to station.\"],[0,\"\\\n== A003 enc\"]],\"start1\":8418,\"start2\":8418,\"length1\":24,\"length2\":239},{\"diffs\":[[0,\"SM : ECB(SD, P1 \"],[-1,\"^\"],[1,\"⊕\"],[0,\" IV)\\\nHSM --> KLM\"]],\"start1\":8756,\"start2\":8756,\"length1\":33,\"length2\":33},{\"diffs\":[[0,\"SM : ECB(SD, P2 \"],[-1,\"^\"],[1,\"⊕\"],[0,\" C1)\\\nHSM --> KLM\"]],\"start1\":8805,\"start2\":8805,\"length1\":33,\"length2\":33},{\"diffs\":[[0,\"SM : ECB(SD, P3 \"],[-1,\"^\"],[1,\"⊕\"],[0,\" C2)\\\nHSM --> KLM\"]],\"start1\":8854,\"start2\":8854,\"length1\":33,\"length2\":33},{\"diffs\":[[0,\"> KLMS : C3\\\n\"],[-1,\"note right of\"],[1,\"KLMS ->\"],[0,\" KLMS : A003\"]],\"start1\":8882,\"start2\":8882,\"length1\":37,\"length2\":31},{\"diffs\":[[0,\": A003 = C1 \"],[-1,\"||\"],[1,\"‖\"],[0,\" C2 \"],[-1,\"||\"],[1,\"‖\"],[0,\" C3  (-> sta\"]],\"start1\":8907,\"start2\":8907,\"length1\":32,\"length2\":30},{\"diffs\":[[0,\"rypted)\\\n\"],[-1,\"\\\n\"],[0,\"== Clean\"]],\"start1\":8950,\"start2\":8950,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"AM)\\\n\"],[-1,\"\\\nnote over HSM #FFEEEE : 3 AES-ECB calls; master M untouched\\\nnote over KLMS : CBC chained by host from single-block ECB; S-DEK never sent to station\\\n@enduml\\\n```\\\n\\\n* * *\\\n\\\n## flow-2b-kdf-nethsm.puml — combined KDF (all phases)\\\n\\\n```plantuml\\\n@startuml flow-2b-kdf-nethsm\\\n' Flow 2b -\"],[1,\"@enduml\\\n```\\\n\\\n* * *\\\n\\\n## flow-2-provisioning.puml — full end-to-end (Word full-page)\\\n\\\n```plantuml\\\n@startuml flow-2-provisioning\\\n' Flow 2 - Provisioning: Key Fob <-> Station <->\"],[0,\" KLMS \"],[-1,\"<\"],[1,\"(\"],[0,\"-> N\"]],\"start1\":9150,\"start2\":9150,\"length1\":292,\"length2\":189},{\"diffs\":[[0,\"tHSM\"],[-1,\" KDF orchestration (AES-ECB only).\\\n' Byte layouts: crates/kf-scp03/src/derive.rs\\\n\\\nautonumber\"],[1,\")\\\n' Station knows only the UID; FESN/SPID come back in the response.\\\n' KDF detail: kdf-phase-a/b/c/d.puml\"],[0,\"\\\ntit\"]],\"start1\":9340,\"start2\":9340,\"length1\":100,\"length2\":113},{\"diffs\":[[0,\"ow 2\"],[-1,\"b\"],[0,\" — \"],[-1,\"KLMS <-> NetHSM KDF Orchestration (AES-ECB only, per transac\"],[1,\"Provisioning: Key Fob <-> Station <-> KLMS\\\nactor       \\\"Key Fob\\\\\n(NCJ37x)\\\"   as Fob\\\nparticipant Station               as Sta\"],[0,\"tion\"],[-1,\")\\\n\"],[0,\"\\\npar\"]],\"start1\":9458,\"start2\":9458,\"length1\":78,\"length2\":139},{\"diffs\":[[0,\"participant KLMS\"],[1,\"                  as KLMS\"],[0,\"\\\nparticipant \\\"Ne\"]],\"start1\":9594,\"start2\":9594,\"length1\":32,\"length2\":57},{\"diffs\":[[0,\" key\"],[-1,\" sealed\"],[0,\")\\\" a\"]],\"start1\":9664,\"start2\":9664,\"length1\":15,\"length2\":8},{\"diffs\":[[0,\"HSM\\\n\"],[-1,\"\\\nnote over HSM\\\n  Handles:  M       = master \"],[1,\"== 1. SCP03 initial handsha\"],[0,\"ke\"],[-1,\"y\"],[0,\" (\"],[-1,\"permanent)\\\n            SE/SM/SD = static S-ENC/MAC/DEK (ephemeral, imported)\\\n            SESMAC  = session S-MAC (ephemeral, imported)\\\n  \\\"host:\\\" steps are pure KLMS logic (no HSM call)\\\nend note\\\n\\\n== Phase A — KDF3 (key = M, master key) ==\\\nKLMS -> HSM : ECB(M, 0^16)\\\nHSM --> KLMS : L_M\\\nnote right of KLMS : host: K1_M = dbl(L_M),  K2_M = dbl(K1_M)\\\n\\\ngroup S-ENC  (purpose 0x40, 26-B derivation data)\\\n  KLMS -> HSM : ECB(M, block1)\\\n  HSM --> KLMS : C1\\\n  KLMS -> HSM : ECB(M, pad(block2) ^ K2_M)\\\n  HSM --> KLMS : C2 = S-ENC\"],[1,\"station <-> fob) ==\\\nStation -> Fob : INITIALIZE UPDATE\\\\\n80 50 <KVN> 00 08 || host_challenge[8]\\\nFob --> Station : UID[10] || key_info || seq_counter[3]\\\\\n|| card_challenge[8] || card_cryptogram[8]\\\n== 2. Forward handshake to KLMS (DLL over mTLS) ==\\\nStation -> KLMS : establish session\\\\\n{ transaction_id, station_id,\\\\\n  fob{uid, key_version},\\\\\n  scp03{host_challenge, card_challenge,\\\\\n        sequence_counter, card_cryptogram} }\\\nKLMS -> KLMS : cache lookup **by UID**\\\\\n-> content + FESN + SPID (from Flow 1)\\\nalt no package for UID\"],[0,\"\\\n  KLMS \"],[1,\"-\"],[0,\"-> \"],[-1,\"HSM : ImportKey(S-ENC)\\\n  HSM --> KLMS : handle SE\\\nend\\\n\\\ngroup S-MAC  (purpose 0x60)\\\n  KLMS -> HSM : ECB(M, block1)\\\n  HSM --> KLMS : C1\\\n  KLMS -> HSM : ECB(M, pad(block2) ^ K2_M)\\\n  HSM --> KLMS : C2 = S-MAC\\\n  KLMS -> HSM : ImportKey(S-MAC)\\\n  HSM --> KLMS : handle SM\\\nend\\\n\\\ngroup S-DEK  (purpose 0x70)\\\n  KLMS -> HSM : ECB(M, block1)\\\n  HSM --> KLMS : C1\"],[1,\"Station : NoPackage  (watchdog priority-fetches the UID)\\\nend\\\n== 3. KLMS derives keys via NetHSM (AES-ECB only; detail: kdf-phase-a/b/c/d.puml) ==\\\nnote right of KLMS : ~23 AES-ECB + 4 Import + 4 Destroy\\\\\n(master subkeys cacheable across transactions)\\\ngroup Phase A — KDF3 (key = M) : 7 ECB\"],[0,\"\\\n  K\"]],\"start1\":9674,\"start2\":9674,\"length1\":934,\"length2\":866},{\"diffs\":[[0,\"SM :\"],[1,\" 7 x\"],[0,\" ECB(M\"],[-1,\", pad(block2) ^ K2_M)\\\n  HSM --> KLMS : C2 =\"],[1,\") -> S-ENC / S-MAC /\"],[0,\" S-D\"]],\"start1\":10548,\"start2\":10548,\"length1\":57,\"length2\":38},{\"diffs\":[[0,\"ImportKey(S-\"],[1,\"ENC/MAC/\"],[0,\"DEK)\\\n  HSM -\"]],\"start1\":10605,\"start2\":10605,\"length1\":24,\"length2\":32},{\"diffs\":[[0,\"ndle\"],[1,\"s SE / SM /\"],[0,\" SD\\\nend\\\n\"],[-1,\"\\\n==\"],[1,\"group\"],[0,\" Pha\"]],\"start1\":10649,\"start2\":10649,\"length1\":19,\"length2\":32},{\"diffs\":[[0,\"SM) \"],[-1,\"==\\\nKLMS -> HSM : ECB(SE, 0^16)\\\nHSM --> KLMS : L_SE\\\nnote right of KLMS : host: K1_SE, K2_SE\\\nKLMS -> HSM : ECB(SM, 0^16)\\\nHSM --> KLMS : L_SM\\\nnote right of KLMS : host: K1_SM, K2_SM\\\n\\\ngroup SES-ENC  (const 0x04, 32-B derivation data)\\\n  KLMS -> HSM : ECB(SE, block1)\\\n  HSM --> KLMS : C1\\\n  KLMS -> HSM : ECB(SE, block2 ^ K1_SE)\\\n  HSM --> KLMS : C2 = SES-ENC   (-> station)\\\nend\\\n\\\ngroup SES-MAC  (const 0x06)\\\n  KLMS -> HSM : ECB(SM, block1)\\\n  HSM --> KLMS : C1\\\n  KLMS -> HSM : ECB(SM, block2 ^ K1_SM)\\\n  HSM --> KLMS : C2 =\"],[1,\": 8 ECB\\\n  KLMS -> HSM : 8 x ECB -> SES-ENC / SES-MAC /\"],[0,\" SES-\"],[1,\"R\"],[0,\"MAC \"]],\"start1\":10713,\"start2\":10713,\"length1\":526,\"length2\":68},{\"diffs\":[[0,\"end\\\n\"],[-1,\"\\\n\"],[0,\"group \"],[-1,\"SES-RMAC  (const 0x07, reuses K1_SM)\\\n  KLMS -> HSM : ECB(SM, block1)\\\n  HSM --> KLMS : C1\\\n  KLMS -> HSM : ECB(SM, block2 ^ K1_SM)\\\n  HSM --> KLMS : C2 = SES-RMAC  (-> station)\\\nend\\\n\\\n== Phase C — cryptograms (key = SESMAC) ==\\\nKLMS -> HSM : ECB(SESMAC, 0^16)\\\nHSM --> KLMS : L\\\nnote right of KLMS : host: K1, K2\\\n\\\ngroup card cryptogram verify (const 0x00) — GATE\\\n  KLMS -> HSM : ECB(SESMAC, block1)\\\n  HSM --> KLMS : C1\"],[1,\"Phase C — cryptograms (key = SESMAC) : 5 ECB — GATE\\\n  KLMS -> HSM : ECB(SESMAC) -> card_cryptogram\\\n  KLMS -> KLMS : verify == fob card_cryptogram\\\n  KLMS -> HSM : ECB(SESMAC) -> host_cryptogram   (-> station)\\\nend\\\ngroup Phase D — A003 AES-CBC (key = SD) : 3 ECB\"],[0,\"\\\n  K\"]],\"start1\":10862,\"start2\":10862,\"length1\":425,\"length2\":273},{\"diffs\":[[0,\"SM :\"],[1,\" 3 x\"],[0,\" ECB(S\"],[-1,\"ESMAC, block2 ^ K1)\\\n  HSM --> KLMS : C2 -> truncate 8 B\\\n  KLMS \"],[1,\"D) -> A003 ciphertext\\\n  HSM -\"],[0,\"-> K\"]],\"start1\":11143,\"start2\":11143,\"length1\":77,\"length2\":47},{\"diffs\":[[0,\"S : \"],[-1,\"compare == fob card_cryptogram\\\nend\\\nnote right of KLMS #FFD0D0\\\n  mismatch => ABORT:\\\n  no session keys / container issued to the station\\\nend note\\\n\\\ngroup\"],[1,\"A003 ciphertext (pre-encrypted)\\\nend\\\n== 4. Container back to station ==\\\nKLMS --> Station : container\\\\\n{ fob{fesn, spid}, authenticated,\\\\\n  scp03{ses_enc, ses_mac, ses_rmac,\"],[0,\" host\"],[-1,\" \"],[1,\"_\"],[0,\"cryp\"]],\"start1\":11192,\"start2\":11192,\"length1\":164,\"length2\":185},{\"diffs\":[[0,\"gram\"],[-1,\" (const 0x01, reuses K1/K2)\\\n  KLMS -> HSM : ECB(SESMAC, block1)\\\n  HSM --> KLMS : C1\\\n  KLMS -> HSM : ECB(SESMAC, block2 ^ K1)\\\n  HSM --> KLMS : C2 -> truncate 8 B =\"],[1,\",\\\\\n       security_level},\\\\\n  content{A001..A006 (A003 pre-encrypted), post_perso},\\\\\n  expires_at (~5 s) }\\\nStation -> Station : Scp03Channel::establish_from_session_keys()\\\n== 5. Open secure channel (C-MAC) ==\\\nStation -> Fob : EXTERNAL AUTHENTICATE\\\\\n84 82 <level> 00 ||\"],[0,\" hos\"]],\"start1\":11379,\"start2\":11379,\"length1\":170,\"length2\":276},{\"diffs\":[[0,\"ram \"],[-1,\" (-> s\"],[1,\"|| MAC[8]\\\nFob --> S\"],[0,\"tation\"],[-1,\")\\\nend\\\n\\\n== Phase D — A003 AES-CBC (key = SD, IV = 0) ==\\\nKLMS -> KLMS : pad 32-B scalar -> 48 B (ISO 9797-1 Method 2)\\\nKLMS -> HSM : ECB(SD, P1 ^ IV)\\\nHSM --> KLMS : C1\\\nKLMS -> HSM : ECB(SD, P2 ^ C1)\\\nHSM --> KLMS : C2\\\nKLMS -> HSM : ECB(SD, P3 ^ C2)\\\nHSM --> KLMS : C3\\\nnote right of KLMS\"],[1,\" : 9000   (channel open)\\\n== 6. Personalize — STORE DATA loop ==\\\nloop over DGI blocks (<= 245 B each, each C-MAC'd)\\\n  Station -> Fob : STORE DATA\\\\\n84 E2 <P1> <P2> || DGI payload || MAC[8]\\\n  Fob --> Station : 9000\\\nend\\\n== 7. Lifecycle transition ==\\\nStation -> Fob : STORE DATA (last)\\\\\n84 E2 80 <P2> 00 || MAC[8]\\\nnote over Fob : UNPERSONALIZED -> FACTORY\\\nFob --> Station : 9000\\\n== 8. Post-personalization (raw, no secure messaging) ==\\\nStation -> Fob : 00 DB 00 00 03 0A 01 01   (enable UICC)\\\nStation -> Fob\"],[0,\" : \"],[-1,\"A\"],[0,\"00\"],[-1,\"3 = C1 || C2 || C3   (-> s\"],[1,\" DB 00 00 03 0B 01 01   (enable BLE)\\\nFob --> S\"],[0,\"tation\"],[-1,\")\\\n\\\n== Cleanup ==\\\nKLMS -> HSM : Destroy(SE)\\\nKLMS -> HSM : Destroy(SM)\\\nKLMS -> HSM : Destroy(SD)\\\nKLMS -> HSM : Destroy(SESMAC)\\\nKLMS -> KLMS : zeroize all derived keys (RAM)\\\n\\\nnote over HSM #FFEEEE\\\n  Master key M: 0 bytes ever returned.\\\n  Totals: 23 ECB + 4 ImportKey + 4 Destroy per\"],[1,\" : 9000\\\n== 9. Result + audit ==\\\nStation -> KLMS : provision result\\\\\n{ transaction_id, fesn, result,\\\\\n  stage_reached, apdu_count, timestamp }\\\nKLMS -> KLMS : audit + retire cached package\\\nStation -> Station : zeroize session keys\\\nnote over Station #E8FFE8\\\n  Station holds ONLY: ephemeral session keys\\\n  + pre-encrypted A003 (both zeroized after the\"],[0,\" tra\"]],\"start1\":11664,\"start2\":11664,\"length1\":618,\"length2\":939},{\"diffs\":[[0,\"tion\"],[1,\").\"],[0,\"\\\n  \"],[-1,\"(master subkeys cacheable across transactions).\\\nend note\\\n\"],[1,\"Never: master key, static keys, S-DEK.\\\nend note\\\nnote over HSM #FFEEEE : master key never leaves the NetHSM\"],[0,\"\\\n@en\"]],\"start1\":12607,\"start2\":12607,\"length1\":68,\"length2\":119},{\"diffs\":[[0,\"ning\"],[1,\"-1\"],[0,\".puml — \"],[-1,\"Key Fob ↔ Station ↔ KLMS\"],[1,\"Flow 2a: Session establishment (slide-fit, landscape)\"],[0,\"\\\n\\\n``\"]],\"start1\":12761,\"start2\":12761,\"length1\":40,\"length2\":71},{\"diffs\":[[0,\"w-2-provisioning\"],[1,\"-1\"],[0,\"\\\n' Flow 2 - Prov\"]],\"start1\":12855,\"start2\":12855,\"length1\":32,\"length2\":34},{\"diffs\":[[0,\"oning-1\\\n' Flow 2\"],[1,\"a\"],[0,\" - Provisioning:\"]],\"start1\":12866,\"start2\":12866,\"length1\":32,\"length2\":33},{\"diffs\":[[0,\"ning\"],[-1,\": Key Fob <-> Station <-> KLMS (-> NetHSM)\"],[1,\" (1/2): session establishment (slide-fit).\\\n' Compact KDF block here; full per-phase detail in kdf-phase-a/b/c/d.puml\\\n' and the full-page flow-2-provisioning.puml.\\\n' Continues in flow-2-provisioning-2.puml (personalize & finalize).\"],[0,\"\\\n' S\"]],\"start1\":12894,\"start2\":12894,\"length1\":50,\"length2\":238},{\"diffs\":[[0,\"se.\\\n\"],[-1,\"' KDF detail: flow-2b-kdf-nethsm.puml\\\n\\\n\"],[0,\"titl\"]],\"start1\":13192,\"start2\":13192,\"length1\":47,\"length2\":8},{\"diffs\":[[0,\"se.\\\ntitle Flow 2\"],[1,\"a\"],[0,\" — Provisioning:\"]],\"start1\":13192,\"start2\":13192,\"length1\":32,\"length2\":33},{\"diffs\":[[0,\"ning\"],[-1,\": Key Fob <-> Station <-> KLMS\\\n\"],[1,\" (1/2): Session establishment\"],[0,\"\\\nact\"]],\"start1\":13220,\"start2\":13220,\"length1\":39,\"length2\":37},{\"diffs\":[[0,\" as HSM\\\n\"],[-1,\"\\\n\"],[0,\"== 1. SC\"]],\"start1\":13416,\"start2\":13416,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"gram[8]\\\n\"],[-1,\"\\\n\"],[0,\"== 2. Fo\"]],\"start1\":13642,\"start2\":13642,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"hake to \"],[-1,\"Clypeum\"],[1,\"KLMS\"],[0,\" (DLL ov\"]],\"start1\":13669,\"start2\":13669,\"length1\":23,\"length2\":20},{\"diffs\":[[0,\"gram} }\\\n\"],[-1,\"\\\n\"],[0,\"KLMS -> \"]],\"start1\":13873,\"start2\":13873,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"Flow 1)\\\n\"],[-1,\"\\\n\"],[0,\"alt no p\"]],\"start1\":13952,\"start2\":13952,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"end\\\n\"],[-1,\"\\\n\"],[0,\"== 3. \"],[-1,\"Clypeum\"],[1,\"KLMS\"],[0,\" der\"]],\"start1\":14051,\"start2\":14051,\"length1\":22,\"length2\":18},{\"diffs\":[[0,\"SM (\"],[-1,\"detail: flow-2b-kdf-nethsm.puml) ==\\\ngroup KDF orchestration — 23 AES-ECB calls (keyed AES-ECB only)\\\n  \"],[1,\"AES-ECB only; detail: kdf-phase-a/b/c/d.puml) ==\\\nnote right of KLMS : ~23 AES-ECB + 4 Import + 4 Destroy per transaction\\\\\n(master subkeys cacheable across transactions)\\\n\"],[0,\"KLMS\"]],\"start1\":14087,\"start2\":14087,\"length1\":110,\"length2\":177},{\"diffs\":[[0,\": KDF3 (\"],[-1,\"master\"],[1,\"M\"],[0,\" + UID) \"]],\"start1\":14272,\"start2\":14272,\"length1\":22,\"length2\":17},{\"diffs\":[[0,\"-ENC\"],[-1,\"/MAC/\"],[1,\" / S-MAC / S-\"],[0,\"DEK\"],[-1,\"\\\n\"],[0,\"  \"],[-1,\"HSM --> KLMS : static keys\\\n  \"],[1,\" (Phase A)\\\n\"],[0,\"KLMS\"]],\"start1\":14293,\"start2\":14293,\"length1\":48,\"length2\":37},{\"diffs\":[[0,\"-ENC\"],[-1,\"/MAC/\"],[1,\" / SES-MAC / SES-\"],[0,\"RMAC\"],[-1,\"\\\n\"],[1,\" \"],[0,\"  \"],[1,\"(Phase B)\\\n\"],[0,\"KLMS\"]],\"start1\":14358,\"start2\":14358,\"length1\":20,\"length2\":42},{\"diffs\":[[0,\"ram (SES\"],[-1,\"-\"],[0,\"MAC)\"],[-1,\"\\\n  HSM\"],[0,\" \"],[-1,\"-\"],[0,\"->\"],[-1,\" KLMS :\"],[0,\" authent\"]],\"start1\":14429,\"start2\":14429,\"length1\":38,\"length2\":23},{\"diffs\":[[0,\"ted \"],[-1,\"= true\\\n  \"],[1,\"  (Phase C, GATE)\\\n\"],[0,\"KLMS\"]],\"start1\":14455,\"start2\":14455,\"length1\":17,\"length2\":26},{\"diffs\":[[0,\"> HSM : host\"],[-1,\" \"],[1,\"_\"],[0,\"cryptogram\\\n \"]],\"start1\":14483,\"start2\":14483,\"length1\":25,\"length2\":25},{\"diffs\":[[0,\"gram\"],[-1,\"\\\n\"],[0,\"  \"],[-1,\"HSM --> KLMS : host_cryptogram\\\n  \"],[1,\" (Phase C)\\\n\"],[0,\"KLMS\"]],\"start1\":14502,\"start2\":14502,\"length1\":44,\"length2\":21},{\"diffs\":[[0,\" HSM : AES-CBC(S\"],[-1,\"-DEK\"],[1,\"D\"],[0,\") -> A003 cipher\"]],\"start1\":14526,\"start2\":14526,\"length1\":36,\"length2\":33},{\"diffs\":[[0,\"text\"],[-1,\"\\\n  HSM --> KLMS : A003 ciphertext\\\nend\\\n\"],[1,\" (pre-encrypted)   (Phase D)\\\nnote right of HSM #FFEEEE : master key M never leaves the NetHSM\"],[0,\"\\\n== \"]],\"start1\":14559,\"start2\":14559,\"length1\":46,\"length2\":101},{\"diffs\":[[0,\"_cryptogram,\"],[-1,\"\\\\\n      \"],[0,\" security_le\"]],\"start1\":14797,\"start2\":14797,\"length1\":32,\"length2\":24},{\"diffs\":[[0,\"d), post_perso},\"],[-1,\"\\\\\n \"],[0,\" expires_at (~5 \"]],\"start1\":14867,\"start2\":14867,\"length1\":35,\"length2\":32},{\"diffs\":[[0,\"_keys()\\\n\"],[1,\"note over Station #E8FFE8\\\n  Station now holds ONLY: ephemeral session keys\\\n  + pre-encrypted A003 (both zeroized after the transaction).\\\n  Never: master key, static keys, S-DEK.\\\nend note\\\n@enduml\\\n```\\\n\\\n* * *\\\n\\\n## flow-2-provisioning-2.puml — Flow 2b: Personalize & finalize (slide-fit, ~square)\\\n\\\n```plantuml\\\n@startuml flow-2-provisioning-2\\\n' Flow 2b - Provisioning (2/2): personalize & finalize.\\\n' Continues from flow-2-provisioning-1.puml (session established).\\\ntitle Flow 2b — Provisioning (2/2): Personalize & finalize\\\nactor       \\\"Key Fob\\\\\n(NCJ37x)\\\"   as Fob\\\nparticipant Station               as Station\\\nparticipant KLMS                  as KLMS\\\nnote over Station : (continues from Flow 2a: holds session keys + pre-encrypted A003)\"],[0,\"\\\n== 5. O\"]],\"start1\":14961,\"start2\":14961,\"length1\":16,\"length2\":748},{\"diffs\":[[0,\"l open)\\\n\"],[-1,\"\\\n\"],[0,\"== 6. Pe\"]],\"start1\":15857,\"start2\":15857,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"000\\\nend\\\n\"],[-1,\"\\\n\"],[0,\"== 7. Li\"]],\"start1\":16048,\"start2\":16048,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\" : 9000\\\n\"],[-1,\"\\\n\"],[0,\"== 8. Po\"]],\"start1\":16206,\"start2\":16206,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\" : 9000\\\n\"],[-1,\"\\\n\"],[0,\"== 9. Re\"]],\"start1\":16399,\"start2\":16399,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"on keys\\\n\"],[-1,\"\\\n\"],[0,\"note ove\"]],\"start1\":16620,\"start2\":16620,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"FFE8\\\n  Station h\"],[-1,\"o\"],[1,\"e\"],[0,\"ld\"],[-1,\"s\"],[0,\" ONLY: ephemeral\"]],\"start1\":16649,\"start2\":16649,\"length1\":36,\"length2\":35},{\"diffs\":[[0,\"ote\\\n\"],[-1,\"note over HSM #FFEEEE : master key never leaves the NetHSM\\\n\\\n@enduml\\\n```\\\n\\\n* * *\\\n\\\n> **ASCII note:** the Joplin copies use ASCII (`^`, `||`, `->`, `0^16`) so they paste  \\\n> cleanly anywhere; the repo `.puml` files use the unicode glyphs (`⊕ ‖ ¹ →`) for  \\\n> nicer rendering. Either set renders identically in PlantUML.\"],[1,\"@enduml\\\n```\\\n\\\n* * *\\\n\"]],\"start1\":16806,\"start2\":16806,\"length1\":318,\"length2\":23}]"
metadata_diff: {"new":{},"deleted":[]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-07-01T09:57:51.512Z
created_time: 2026-07-01T09:57:51.512Z
type_: 13