UICC Configuration v1.0.1 10/50
Copyright
2008-2011 GlobalPlatform Inc. All Rights Reserved.
The technology provided or described herein is subject to updates, revisions, and extensions by GlobalPlatform. Use of this
information is governed by the GlobalPlatform license agreement and any use inconsistent with that agreement is strictly
prohibited.
• Global Delete
• Global Lock
• Global Registry
• Card Terminate
• Card Lock
3. Only the Issuer Security Domain can assign the Authorized Management and the Mandated DAP
privileges.
4. It shall only be possible to assign the Token Verification and Receipt Generation privileges to a
Security Domain with the Authorized Management privilege.
4.2 Issuer Security Domain
The Issuer Security Domain supports Secure Channel Protocol '80' (SCP80). When the Issuer Security
Domain receives a Remote Application Management command, the security policy as defined in ETSI TS
102 225 [1] shall be applied.
The Issuer Security Domain may support Secure Channel Protocol '02' (SCP02) option i = '55'.
The absence or presence of additional SCPs in Security Domains on the UICC is beyond the scope of this
document.
When the Issuer Security Domain is the selected Application, all commands besides those required to
setup a Secure Channel shall be processed within a Secure Channel session except the GET DATA
command, which may be processed outside of a Secure Channel session.
The level of security of the commands following the setup of the Secure Channel Session in SCP02 mode
is defined in section 2.2 of the GP CS v2.2 Mapping Guidelines [4].
Extradition of an Application or Load File to the Issuer Security Domain shall never succeed.
The Issuer Security Domain shall only accept deletion requests made by Security Domains within its
hierarchy with the Delegated Management privilege or a Security Domain with the Global Delete privilege.
4.3 Supplementary Security Domains
Support for Supplementary Security Domains is mandatory.
Supplementary Security Domains are installed with Secure Channel Protocol '80' option i = '00' and/or
Secure Channel Protocol '02' option i = '55'. As with the Issuer Security Domain, the absence or presence
of additional SCPs in Security Domains on the UICC is beyond the scope of this document.
Any Supplementary Security Domain has the option to reject or accept Applications being extradited to it
as defined by the GP CS v2.2 Mapping Guidelines [4] and in accordance with the configuration given
below in section 4.3.2.
The level of security of the commands following the setup of the Secure Channel Session in SCP02 mode
is defined in section 2.3 of the GP CS v2.2 Mapping Guidelines [4] as was previously stated for the ISD.
4.3.1 Security Domain Hierarchies
Security Domains are organized in hierarchies according to GP CS v2.2.1 [3]:
• The root of a new hierarchy is defined by extraditing a SD to itself (as described in [3])
• Within such a hierarchy, the following rules are enforced by OPEN: