Urgent.News

What's breaking now, across thousands of outlets.

Tech

How to Load and Run a Java Card Applet on Real Hardware

Build a Java Card applet on real hardware. Working commands, a complete device-key demo, and the client bugs we mistook for a locked card.

How to Load and Run a Java Card Applet on Real Hardware

This article guides the reader through building and running a JavaCard applet called CollarMAC on real hardware. CollarMAC verifies a challenge by generating a message authentication code (MAC) using AES key material that remains in the chip. The process involves four main steps: development, hardware setup, building the applet, and running it on real hardware.

The prerequisites include a development card (NXP J3R150), a CCID smartcard reader ($10), Java 17+, Python 3 with the cryptography package, and a full day to complete the process. It's essential to verify the seller's documentation, including the ISD keyset and Java Card version, before purchasing a development card.

The article provides several tips for a successful build, such as checking the Java Card and GlobalPlatform versions, using the correct ISD keyset in hexadecimal, and ensuring the installation command returns 9000. The reader should also be aware of potential issues with certain readers, such as the Generic EMV reader on macOS, which may intermittently fail connections.

Before running the applet on actual hardware, the author recommends testing it in a simulator (jCardSim) to catch any bugs in the code. Running the applet in a simulator can save EEPROM write cycles and prevent costly mistakes. The article concludes by providing a step-by-step guide to installing and personalizing the CollarMAC applet on a real Java Card development card.

Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hackernoon.com →

More in Tech

Same Terabyte, $0 to $205: Cloudflare vs Azure for a Solo Developer

In my last post I described how Azure trapped a custom domain, a web app and an entire resource group in a state I couldn't delete, and how I ended up moving that project to Cloudflare Workers. A few people asked a fair question: was that just a bad afternoon, or is one platform actually a better deal?

More from Monday 28 September →