diff --git a/README.md b/README.md index f29ae37..a8ab216 100644 --- a/README.md +++ b/README.md @@ -438,28 +438,6 @@ Delivery PoR (SPI2 `01`) is simpler — the card returns the PoR directly in the - ISO 9797-1: MAC algorithms - NIST SP 800-38B: CMAC -### Cards - -Stores saved card configurations (presets) in `localStorage`. A preset holds the cryptographic keys, SPI settings, TAR and replay counter for SCP80 operations, plus the **PSK identity / PSK key** pair used by the SCP81 HTTP OTA listener. Cards is a **top-level tab**. When the card is equipped its EF.ICCID is read and the preset with the same ICCID is selected automatically in both SCP80 views. - -| Field | Description | -|---|---| -| Name | Human-readable label (required) | -| ICCID | Optional card identifier | -| SPI1 / SPI2 | Security level and PoR settings | -| KIc / KID index | Key version number (required together with the keys) | -| KIc / KID key | Encryption and MAC key hex | -| TAR | Toolkit Application Reference (3 bytes) | -| Counter (CNTR) | 10-digit hex replay counter, auto-incremented after each successful SCP80 send | -| PSK identity | SCP81 HTTP OTA: the identity the card sends in the TLS handshake | -| PSK key | SCP81 HTTP OTA: 32 hex chars (16 bytes); the listener picks it by the identity the card presents | - -The **SCP81** column shows whether the preset supplies a usable PSK pair: **✓** (identity and key), **⚠** (only one of the two — the listener ignores such a preset), **—** (no PSK). Identity and key must be set together. - -**Add a card:** fill in the name, ICCID (optional — **From card** fills it from the equipped card's EF.ICCID), SPI1/SPI2, KIc/KID keys and indices, TAR, the SCP81 PSK pair (optional) and click **Add**. A duplicate ICCID (compared ignoring spaces and the raw-hex form) is refused, naming the conflicting preset. The card appears in the list and becomes available in the RAM tab's **Card preset** dropdown. - -**Edit / remove:** **Edit** loads a preset into the form (the Add button becomes **Save**; **Cancel** clears the form); **Remove** deletes the row from `localStorage`. A successful SCP80 send advances and stores the replay counter, and edits are pushed into a running SCP81 listener automatically. - ### RAM All RAM operations are delivered as SCP80 secured packets (ETSI TS 102 225) via SMS-PP-DOWNLOAD ENVELOPE. The card must support SCP03 (AES or 3DES) for secure transport. @@ -485,6 +463,30 @@ Delete confirms via a browser prompt before sending the GP `DELETE` command via --- +## Cards + +Stores saved card configurations (presets) in `localStorage`. A preset holds the cryptographic keys, SPI settings, TAR and replay counter for SCP80 operations, plus the **PSK identity / PSK key** pair used by the SCP81 HTTP OTA listener. Cards is a **top-level tab**. When the card is equipped its EF.ICCID is read and the preset with the same ICCID is selected automatically in both SCP80 views. + +| Field | Description | +|---|---| +| Name | Human-readable label (required) | +| ICCID | Optional card identifier | +| SPI1 / SPI2 | Security level and PoR settings | +| KIc / KID index | Key version number (required together with the keys) | +| KIc / KID key | Encryption and MAC key hex | +| TAR | Toolkit Application Reference (3 bytes) | +| Counter (CNTR) | 10-digit hex replay counter, auto-incremented after each successful SCP80 send | +| PSK identity | SCP81 HTTP OTA: the identity the card sends in the TLS handshake | +| PSK key | SCP81 HTTP OTA: 32 hex chars (16 bytes); the listener picks it by the identity the card presents | + +The **SCP81** column shows whether the preset supplies a usable PSK pair: **✓** (identity and key), **⚠** (only one of the two — the listener ignores such a preset), **—** (no PSK). Identity and key must be set together. + +**Add a card:** fill in the name, ICCID (optional — **From card** fills it from the equipped card's EF.ICCID), SPI1/SPI2, KIc/KID keys and indices, TAR, the SCP81 PSK pair (optional) and click **Add**. A duplicate ICCID (compared ignoring spaces and the raw-hex form) is refused, naming the conflicting preset. The card appears in the list and becomes available in the RAM tab's **Card preset** dropdown. + +**Edit / remove:** **Edit** loads a preset into the form (the Add button becomes **Save**; **Cancel** clears the form); **Remove** deletes the row from `localStorage`. A successful SCP80 send advances and stores the replay counter, and edits are pushed into a running SCP81 listener automatically. + +--- + ## Card Reader (pySim integration) Connects to the bundled [`pysim-simple-server`](pysim_simple_server/) for live card operations. @@ -696,20 +698,12 @@ pysim-simple-server --http-port 8080 See [docs/api.md](docs/api.md) for the full endpoint reference. -## Theme - -Dark theme is supported. The app follows the OS preference on first visit, and a manual toggle button (🌙/☀️) at the top-right corner persists the choice in `localStorage`. - -## Localisation - -The UI is in English with Russian language support. Language is detected from the browser's `navigator.language` preference. A manual toggle button (EN/RU) in the header persists the choice in `localStorage`. - ## Version compatibility | PWA (SIMple) | Server | Status | |-------------|--------|--------| -| 1.x.x | 1.x.x | ✅ Compatible | -| 1.x.x | 0.x.x | ❌ Outdated — update server | -| 1.x.x | 2.x.x+ | ⚠️ Server newer — update PWA | +| any | same major | ✅ Compatible | +| any | older major | ❌ Outdated — update server | +| any | newer major | ⚠️ Server newer — update PWA | -The PWA checks the server version on connect via `GET /api/version` and warns if versions are incompatible. +The PWA checks the server version on connect via `GET /api/version` and compares the major version (e.g. a 2.x PWA with a 2.x server; a 1.x server is flagged as outdated). diff --git a/README_RUS.md b/README_RUS.md index 19e810f..c7855e2 100644 --- a/README_RUS.md +++ b/README_RUS.md @@ -412,28 +412,6 @@ Delivery PoR (SPI2 `01`) проще — карта возвращает PoR на - ISO 9797-1 - NIST SP 800-38B (CMAC) -### Карты - -Хранит сохранённые конфигурации карт (пресеты) в `localStorage`. Пресет содержит криптографические ключи, настройки SPI, TAR и счётчик повторов для SCP80-операций, а также пару **PSK identity / PSK key** для слушателя SCP81 HTTP OTA. «Карты» — **верхнеуровневая вкладка**. При подключении карты читается её EF.ICCID, и пресет с тем же ICCID автоматически выбирается в обоих видах SCP80. - -| Поле | Описание | -|---|---| -| Name | Понятная метка (обязательна) | -| ICCID | Опциональный идентификатор карты; кнопка **С карты** подставляет EF.ICCID подключённой карты (активна, только когда ICCID читается) | -| SPI1 / SPI2 | Уровень безопасности и настройки PoR | -| Индекс KIc / KID | Номер версии ключа (задаётся вместе с ключами) | -| Ключ KIc / KID | Hex-ключи шифрования и MAC | -| TAR | Toolkit Application Reference (3 байта) | -| Счётчик (CNTR) | 10-значный hex-счётчик повторов, автоматически увеличивается после каждой успешной отправки SCP80 | -| PSK identity | SCP81 HTTP OTA: идентификатор, который карта присылает в TLS-рукопожатии | -| PSK key | SCP81 HTTP OTA: 32 hex-символа (16 байт); ключ выбирается по идентификатору, который предъявляет карта | - -Столбец **SCP81** показывает, задана ли в пресете рабочая пара PSK: **✓** (идентификатор и ключ), **⚠** (только одно из двух — слушатель такой пресет игнорирует), **—** (PSK нет). Идентификатор и ключ задаются вместе. - -**Добавить карту:** заполните имя, ICCID (опционально — кнопка **С карты** подставляет EF.ICCID подключённой карты), SPI1/SPI2, ключи и индексы KIc/KID, TAR, при необходимости пару PSK и нажмите **Add**. Дубликат ICCID (сравнение без пробелов и с учётом сырой hex-формы) отклоняется с указанием конфликтующего пресета. Карта появится в списке и станет доступна в выпадающем списке **Card preset** на вкладке RAM. - -**Изменить/удалить:** **Edit** загружает пресет в форму (кнопка Add становится **Save**; **Cancel** очищает форму); **Remove** удаляет строку из `localStorage`. Успешная отправка SCP80 увеличивает и сохраняет счётчик повторов, а изменения сразу передаются работающему слушателю SCP81. - ### RAM Все операции RAM отправляются как защищённые пакеты SCP80 (ETSI TS 102 225) через SMS-PP-DOWNLOAD ENVELOPE. Карта должна поддерживать SCP03 (AES или 3DES) для безопасной транспортировки. @@ -459,6 +437,30 @@ Delivery PoR (SPI2 `01`) проще — карта возвращает PoR на --- +## Карты + +Хранит сохранённые конфигурации карт (пресеты) в `localStorage`. Пресет содержит криптографические ключи, настройки SPI, TAR и счётчик повторов для SCP80-операций, а также пару **PSK identity / PSK key** для слушателя SCP81 HTTP OTA. «Карты» — **верхнеуровневая вкладка**. При подключении карты читается её EF.ICCID, и пресет с тем же ICCID автоматически выбирается в обоих видах SCP80. + +| Поле | Описание | +|---|---| +| Name | Понятная метка (обязательна) | +| ICCID | Опциональный идентификатор карты; кнопка **С карты** подставляет EF.ICCID подключённой карты (активна, только когда ICCID читается) | +| SPI1 / SPI2 | Уровень безопасности и настройки PoR | +| Индекс KIc / KID | Номер версии ключа (задаётся вместе с ключами) | +| Ключ KIc / KID | Hex-ключи шифрования и MAC | +| TAR | Toolkit Application Reference (3 байта) | +| Счётчик (CNTR) | 10-значный hex-счётчик повторов, автоматически увеличивается после каждой успешной отправки SCP80 | +| PSK identity | SCP81 HTTP OTA: идентификатор, который карта присылает в TLS-рукопожатии | +| PSK key | SCP81 HTTP OTA: 32 hex-символа (16 байт); ключ выбирается по идентификатору, который предъявляет карта | + +Столбец **SCP81** показывает, задана ли в пресете рабочая пара PSK: **✓** (идентификатор и ключ), **⚠** (только одно из двух — слушатель такой пресет игнорирует), **—** (PSK нет). Идентификатор и ключ задаются вместе. + +**Добавить карту:** заполните имя, ICCID (опционально — кнопка **С карты** подставляет EF.ICCID подключённой карты), SPI1/SPI2, ключи и индексы KIc/KID, TAR, при необходимости пару PSK и нажмите **Add**. Дубликат ICCID (сравнение без пробелов и с учётом сырой hex-формы) отклоняется с указанием конфликтующего пресета. Карта появится в списке и станет доступна в выпадающем списке **Card preset** на вкладке RAM. + +**Изменить/удалить:** **Edit** загружает пресет в форму (кнопка Add становится **Save**; **Cancel** очищает форму); **Remove** удаляет строку из `localStorage`. Успешная отправка SCP80 увеличивает и сохраняет счётчик повторов, а изменения сразу передаются работающему слушателю SCP81. + +--- + ## Card Reader (интеграция с pySim) Подключение к встроенному [`pysim-simple-server`](pysim_simple_server/) для работы с картой. @@ -612,11 +614,11 @@ SIMple — Progressive Web App. Можно установить для offline- | PWA (SIMple) | Сервер | Статус | |---|---|---| -| 1.x.x | 1.x.x | ✅ Совместимы | -| 1.x.x | 0.x.x | ❌ Сервер устарел | -| 1.x.x | 2.x.x+ | ⚠️ Сервер новее — обновите PWA | +| любая | та же мажорная | ✅ Совместимы | +| любая | старее мажорная | ❌ Сервер устарел — обновите сервер | +| любая | новее мажорная | ⚠️ Сервер новее — обновите PWA | -PWA проверяет версию сервера при подключении через `GET /api/version`. +PWA проверяет версию сервера при подключении через `GET /api/version` и сравнивает мажорную версию (например, PWA 2.x с сервером 2.x; сервер 1.x помечается как устаревший). --- diff --git a/docs/api.md b/docs/api.md index fcc63c1..e857e25 100644 --- a/docs/api.md +++ b/docs/api.md @@ -8,12 +8,13 @@ on the preflight), so the API is reachable from a separately-hosted PWA. | Server | PWA (SIMple) | Status | |--------|-------------|--------| -| 1.x.x | 1.x.x | ✅ Compatible | -| 0.x.x | 1.x.x | ❌ Outdated — update server | -| 2.x.x+ | 1.x.x | ⚠️ Server newer — update PWA | +| same major | any | ✅ Compatible | +| older major | any | ❌ Outdated — update server | +| newer major | any | ⚠️ Server newer — update PWA | The server reports its version via `GET /api/version`. The PWA checks this on -connect and warns if versions are incompatible. +connect and compares the major version (a 1.x server is flagged as outdated by +a 2.x PWA). ## Endpoints @@ -23,6 +24,7 @@ connect and warns if versions are incompatible. | `/api/status` | GET | Card reader + card info + current selection | | `/api/command` | POST | pySim command (equip, status, tree, etc.) | | `/api/commands` | GET | List available pySim commands | +| `/api/cardinfo` | GET | pySim `cardinfo` output | | `/api/tree` | POST | File tree browser for given FID/name | | `/api/select` | POST | Select a file by name or FID | | `/api/read` | POST | Read file content | @@ -87,6 +89,12 @@ with the same ICCID in both SCP80 views (Secured Packet and RAM). List all available shell commands for the current card profile. +### `GET /api/cardinfo` + +Runs pySim's `cardinfo` command and returns its output as `{"output": "..."}` +(card type, ATR, ICCID and other information pySim reports for the equipped +card). A shortcut for `POST /api/command` with `{"cmd": "cardinfo"}`. + ### `POST /api/command` Execute any pysim-shell command. diff --git a/docs/scp81-findings.md b/docs/scp81-findings.md index 93d0f39..80cfa2a 100644 --- a/docs/scp81-findings.md +++ b/docs/scp81-findings.md @@ -308,8 +308,7 @@ INSTALL [for install] -> registries. ## Next tests / work 1. **UI:** group the per-page R-APDUs under their logical command in the - SCP81 tab (page merging/decoding for ELF and application listings); - expose the framing options in the tab. + SCP81 tab (page merging/decoding for ELF and application listings). 2. **Load/store over SCP81:** implemented - `POST /api/scp81/gen-install` takes a `.cap`, expands it with the shared `_cap_apdu_sequence` helper (INSTALL [for load] -> 240-byte LOAD blocks -> INSTALL [for install]) and diff --git a/frontend/help-ru.html b/frontend/help-ru.html index 73e7d37..35c6d0f 100644 --- a/frontend/help-ru.html +++ b/frontend/help-ru.html @@ -19,7 +19,7 @@

SIMple Документация

1. Обзор

-

SIMple — Progressive Web App (PWA) для построения APDU-команд, сборки защищённых пакетов SCP80, просмотра меню SIM Toolkit (STK) и симуляции реальной сетевой среды для тестирования SIM/USIM/UICC-карт через PC/SC-ридер.

+

SIMple — инструментарий для специалистов по UICC/SIM-картам: автономный Progressive Web App (PWA), закрывающий весь цикл лабораторной работы — APDU-верстак (конструкторы SIM/USIM RFM и Expanded Script, команды GlobalPlatform RAM, парсер C-APDU/R-APDU и декодер ответов), OTA-лаборатория (защищённые пакеты SCP80 и установка Java Card RAM, а также терминальная сторона HTTP OTA — SCP81: эмуляция BIP-каналов, PSK-TLS-сервер администрирования и выполнение скриптов APDU), симулятор телефона (меню SIM Toolkit, proactive-команды и события, редактирование TERMINAL PROFILE, журнал C-AT-диалога) и профайлер карты (профили и неизменяемые снимки с таймингами, точное сравнение снимков, декодер FCP/FCI).

Приложение — один статический файл index.html. Все вычисления выполняются в браузере; доступ к карте — через локальный HTTP-сервер (pysim-simple-server), оборачивающий библиотеку pySim.

Браузер (SIMple PWA) → HTTP :8080 → pysim-simple-server → pySim → PC/SC → ридер → UICC/SIM

Стандарты, на которые опирается приложение:

@@ -542,12 +542,12 @@ pysim-simple-server --http-port 8080 - - - + + +
PWA (SIMple)СерверСтатус
1.x.x1.x.x✅ Совместимы
1.x.x0.x.x❌ Устарел — обновите сервер
1.x.x2.x.x+⚠️ Сервер новее — обновите PWA
любаята же мажорная✅ Совместимы
любаястарее мажорная❌ Устарел — обновите сервер
любаяновее мажорная⚠️ Сервер новее — обновите PWA
-

PWA проверяет версию сервера при подключении через GET /api/version и предупреждает о несовместимости.

+

PWA проверяет версию сервера при подключении через GET /api/version и сравнивает мажорную версию (например, PWA 2.x с сервером 2.x; сервер 1.x помечается как устаревший).

diff --git a/frontend/help.html b/frontend/help.html index 608d4fc..3c60511 100644 --- a/frontend/help.html +++ b/frontend/help.html @@ -19,7 +19,7 @@

SIMple Documentation

1. Overview

-

SIMple is a Progressive Web App (PWA) for building APDU commands, assembling SCP80 secured packets, browsing the SIM Toolkit (STK) menu, and simulating a real network environment against a SIM/USIM/UICC card via a PC/SC reader.

+

SIMple is a workbench for UICC/SIM card specialists: an offline Progressive Web App (PWA) covering the full lab cycle — an APDU workbench (SIM/USIM RFM and Expanded Script builders, GlobalPlatform RAM commands, a C-APDU/R-APDU parser and a response decoder), an OTA lab (SCP80 secured packets and Java Card RAM installation, plus the terminal side of HTTP OTA — SCP81: BIP channel emulation, a PSK TLS administration server and APDU script execution), a phone/CAT simulator (SIM Toolkit menu, proactive commands and events, TERMINAL PROFILE editing, the C-AT dialogue log) and a card profiler (profiles and immutable snapshots with timings, exact snapshot comparison, FCP/FCI decoding).

The application is a single static index.html file. All computation runs in the browser; the card is accessed through a local HTTP server (pysim-simple-server) that wraps the pySim library.

Browser (SIMple PWA) → HTTP :8080 → pysim-simple-server → pySim → PC/SC → card reader → UICC/SIM

Standards referenced across the application:

@@ -542,12 +542,12 @@ pysim-simple-server --http-port 8080 - - - + + +
PWA (SIMple)ServerStatus
1.x.x1.x.x✅ Compatible
1.x.x0.x.x❌ Outdated — update server
1.x.x2.x.x+⚠️ Server newer — update PWA
anysame major✅ Compatible
anyolder major❌ Outdated — update server
anynewer major⚠️ Server newer — update PWA
-

The PWA checks the server version on connect via GET /api/version and warns if versions are incompatible.

+

The PWA checks the server version on connect via GET /api/version and compares the major version (e.g. 2.x PWA with a 2.x server; a 1.x server is flagged as outdated).

diff --git a/frontend/index.html b/frontend/index.html index eae87fc..08f7e06 100644 --- a/frontend/index.html +++ b/frontend/index.html @@ -18,7 +18,7 @@
-

SIMple SIM OTA with a Human Face v2.3.0

+

SIMple

@@ -1302,6 +1302,12 @@