Update PIV Object Access Control Rules
This command updates the Access Control Rules of a data object (BER-TLV buffer) in the PIV application. The update is allowed only when the object is not personalized (before its creation or after it is cleared).
Instance: PIV
Access Condition: Always; however, the buffer needs to be empty.
Command Message
| Field | Value |
|---|---|
|
CLA |
00 |
|
INS |
DB |
|
P1 |
3F |
|
P2 |
00 |
|
Lc |
Data field length |
|
Data |
See the table below |
|
Le |
Empty |
Data Field for Access Control Rule Update
| Byte | Value |
|---|---|
|
0 |
5C (Tag List Tag) |
|
1 |
[01...03] (Tag List Length) |
|
2-4 |
BER-TLV tag of the data object |
|
5 |
A1 (Security Attribute Tag) |
|
6 |
06 (Security Attribute Format Length) |
|
7-8 |
Personalization (PUT DATA) Access Control Rule (see Access Control Rules) |
|
9-10 |
Contact Usage (GET DATA) Access Control Rule (see Access Control Rules) |
|
11-12 |
Contactless Usage (GET DATA) Access Control Rule (see Access Control Rules) |
Response Message
| Status | Meaning |
|---|---|
|
9000 |
Command executed successfully |
|
6A80 |
Incorrect values in command data |
|
6A84 |
Not enough memory |
|
6A88 |
Referenced data object does not exist |
|
6985 |
Conditions of use not satisfied (e.g. object is already personalized or not cleared) |
Example
Update the Access Control Rules for a data object (e.g., CHUID):
| Field | Example Value |
|---|---|
|
CLA |
00 |
|
INS |
DB |
|
P1 |
3F |
|
P2 |
00 |
|
Lc |
0D |
|
Data |
5C 03 5F C1 02 A1 06 A5 00 A5 00 A5 00 (Access allowed always for all rules: personalization, contact read, contactless read) |