The ACOS6 Secure Access Module (SAM) is designed as a general cryptogram computation module or as a security authentication module for ACOS contact client cards - ACOS3, ACOS6, ACOS7 and ACOS10, and common contactless client cards - DESFire, DESFire EV1, Ultralight-C and Mifare Plus.

The ACOS6-SAM card securely stores cryptographic keys and uses these keys to compute cryptograms for other applications or smart cards. Using this, terminals need not know the master key(s) of an application, considering that the keys never leave the ACOS6-SAM.

The ACOS6-SAM card can perform:

  • Mutual Authentication: To guarantee the authenticity of the terminal and the client card
  • Secure Messaging: To ensure that the data transmission between the card and terminal/server is secured and not susceptible to eavesdropping, replay attack and unauthorized modification
  • Purse MAC Computation: To authenticate and ensure data integrity of data and commands that are transferred into the card and vice versa
  • Key Diversification: To enable diversified entry of keys without exposing the master key
  • Secure Key Injection: To ensure the key injection from SAM to client cards for contactless cards with protection of Encryption and Message Authentication Code, besides, key(s) may be changed after injection
  • Memory
    • Capacity: 64  KB
  • Contact Smart Card Interface
    • Compliant with ISO 7816 Parts 1, 2, 3 and 4
    • Supports T=0  Protocol
    • Supports baud up to 223.2 kbps
  • Cryptographic Features
    • AES: 128/192/256-bits (ECB, CBC)
    • DES/3DES: 56/112/168-bits (ECB, CBC)
    • Random Number Generation: FIPS 140-2 compliant hardware based RNG
  • File Security
    • Session key based on random numbers
    • Key pair for mutual authentication
    • Secure Messaging function for confidential and authenticated data transfers
    • Stores and performs all key operations for mutual authentication, encrypted PIN submission, secure messaging, and e-Purse commands
    • Multilevel secured access hierarchy
    • Anti-tearing capability
  • Secure Access Module Compatibility
    • ACOS3
    • ACOS6
    • ACOS7
    • ACOS10
    • MIFARE Ultralight® C
    • MIFARE® DESFire®
    • MIFARE® DESFire® EV1
    • MIFARE® DESFire® EV2
    • MIFARE® DESFire® Light
    • MIFARE Plus®