Update PIV Object Access Control Rules

Note: The information provided below is applicable only to devices belonging to the Crescendo 4000 family.

This command updates the Access Control Rules of a data object (BER-TLV buffer) in the PIV application. The update is allowed only when the object is not personalized (before its creation or after it is cleared).

Instance: PIV

Access Condition: Always; however, the buffer needs to be empty.

Command Message

Field Value

CLA

00

INS

DB

P1

3F

P2

00

Lc

Data field length

Data

See the table below

Le

Empty

Data Field for Access Control Rule Update

Byte Value

0

5C (Tag List Tag)

1

[01...03] (Tag List Length)

2-4

BER-TLV tag of the data object

5

A1 (Security Attribute Tag)

6

06 (Security Attribute Format Length)

7-8

Personalization (PUT DATA) Access Control Rule (see Access Control Rules)

9-10

Contact Usage (GET DATA) Access Control Rule (see Access Control Rules)

11-12

Contactless Usage (GET DATA) Access Control Rule (see Access Control Rules)

Response Message

Status Meaning

9000

Command executed successfully

6A80

Incorrect values in command data

6A84

Not enough memory

6A88

Referenced data object does not exist

6985

Conditions of use not satisfied (e.g. object is already personalized or not cleared)

Example

Update the Access Control Rules for a data object (e.g., CHUID):

Field Example Value

CLA

00

INS

DB

P1

3F

P2

00

Lc

0D

Data

5C 03 5F C1 02 A1 06 A5 00 A5 00 A5 00

(Access allowed always for all rules: personalization, contact read, contactless read)