TECHNICAL SUMMARY FOR SIM CARD
SMARTJAC PART NUMBER: SMAOT100A234FF
Register | Value | Binary value stored on card |
GPIN | 1234, disabled | 31323334FFFFFFFF |
LPIN | 5678, enabled | 35363738FFFFFFFF |
Proprietary | MILENAGE | Proprietary |
ADM1 | 11111111 | 3131313131313131 |
ADM2 | 22222222 | 3232323232323232 |
Ki stored in: 6FFC (18 bytes, where Ki value is 16 bytes and Checksum value is 2 bytes) OPc stored in: 6FFD (104 bytes)
File 6FFC contains Ki key, and file 6FFD contains OPc key and rotation/constant parameters. Ki content: [Ki] [CH]
OPc content: 01 [OPc] [CH] 40002040600000000000000000000000000000000000000000000000000000000000000001000000000000000000000000
000000020000000000000000000000000000000400000000000000000000000000000008
File 6FFC contains Ki key, and file 6FFD contains OPc key and rotation/constant parameters.
Replace [Ki] with 16 byte Ki key & Replace [OPc] with 16 byte OPc key
[CH] is a 2 byte checksum based on the 16 byte Hex code. It has to be calculated both for Ki and OPc.
The checksum is a CRC calculation. More specifically a CRC-16 polynomial 0x1021 with input/initialization FFFF. Also called CRC-CCITT-FALSE Online sample calculations can be done here (for example to check that your own calculations are correct): https://www.lammertbies.nl/comm/info/crc-calculation.html (use the result of CRC-CCITT (0xFFFF) )
Sweden:
Tel.: +46-8-410 712 30
Fax.: +1 (484) 631 1399
Finland:
Tel: +358 (09) 2316 7020
USA:
Tel: +1-484-4019-980
Sweden: Smartjac AB Kanalvägen 1 A,
SE-194 61 Upplands Väsby,
USA: Smartjac Industries Inc. 411 West Miner St
PA-193 82 West Chester
Infineon SLE97 - IO266G ; SLE97CNFX1M50PE G11
OTA
OTA over SMS / AES ciphering
OTA over CAT-TP
OTA over HTTPs / GP2.2 AmdB
Authentication applications
4 logical channels
SIM, USIM
ISIM
Authentication algorithms
Comp128 2&3
Milenage
Cryptographic features for OTA
CRC16, CRC32
DES, 3DES, AES 128/256 bits
HTTPs OTA
Java Card™ Cryptographic APIs
CRC16, CRC32
DES, 3DES, AES 128/256 bits
User memory : 512 kB

32-bit CPU in 90 nm CMOS technology
Max frequency 44 Mhz
DES, AES, RSA, ECC Hardware accelerator
Supply voltages range: Class A,B,C
Memory Endurance : Up to 500,000 Cycles
Global Platform Am A,B,C,D,E
NFC/SWP Support
EAL 4+ PP USIM V2
EMVCo Certified
NFC Applications: MIFARE4MOBILE 2.1 ; MIFARE DESFire ™ ; Calypso o EMVO
Sweden:
Tel.: +46-8-410 712 30
Fax.: +1 (484) 631 1399
Finland:
Tel: +358 (09) 2316 7020
USA:
Tel: +1-484-4019-980
Sweden: Smartjac AB Kanalvägen 1 A,
SE-194 61 Upplands Väsby,
USA: Smartjac Industries Inc. 411 West Miner St
PA-193 82 West Chester
Standards reference | ||
Code | Release | Title |
SIM | ||
GSM 11.12 | V4.3.1 | Specification of the 3 Volt Subscriber Identity Module - Mobile Equipment (SIM - ME) interface |
GSM 11.18 | V7.0.1 | Specification of the 1.8 Volt Subscriber Identity Module - Mobile Equipment (SIM - ME) interface |
3GPP TS 23.048 | V5.9.0 | Security Mechanisms for the (U)SIM application toolkit; Stage 2 |
3GPP TS 42.019 | V5.1.0 | Subscriber Identity Module Application Programming Interface (SIM API); Stage 1 |
3GPP TS 43.019 | V6.0.0 | Subscriber Identity Module Application Programming Interface (SIM API); Stage 2 |
3GPP TS 51.011 | V4.15.0 | Specification of the Subscriber Identity Module - Mobile Equipment (SIM-ME) interface |
3GPP TS 51.013 | V5.0.1 | Test specification for Subscriber Identity Module (SIM) Application Programming Interface (API) for Java |
3GPP TS 51.014 | V4.5.0 | Specification of the SIM Application Toolkit for the Subscriber Identity Module - Mobile Equipment (SIM - ME) interface |
3GPP TS 51.017 | V4.2.0 | Subscriber Identity Module (SIM) test specification |
Security algorithms | ||
3GPP TS 35.205 | V11.0.0 | Specification of the MILENAGE Algorithm Set |
3GPP TS 35.206 | V11.0.0 | 3G Security; Specification of the MILENAGE algorithm set: An example algorithm Set for the 3GPP Authentication and Key Generation functions f1, f1*, f2, f3, f4, f5 and f5*; Document 2: Algorithm specification |
3GPP TS 35.207 | V11.0.0 | Document 3: Implementors’test data |
3GPP TS 35.208 | V11.0.0 | Document 4: Design conformance test data |
Sweden:
Tel.: +46-8-410 712 30
Fax.: +1 (484) 631 1399
Finland:
Tel: +358 (09) 2316 7020
USA:
Tel: +1-484-4019-980
Sweden: Smartjac AB Kanalvägen 1 A,
SE-194 61 Upplands Väsby,
USA: Smartjac Industries Inc. 411 West Miner St
PA-193 82 West Chester
3GPP PLATFORM | ||
3GPP TS 31.048 | V5.1.0 | Test of (U)SAT security |
3GPP TS 21.111 | V11.0.1 | USIM and IC card requirements |
3GPP TS 22.038 | V8.0.1 | USIM Application Toolkit (USAT) - Stage 1 |
3GPP TS 23.040 | V8.6.0 | Technical realization of the Short Message Service (SMS) |
3GPP TS 23.041 | V7.0.0 | Technical realization of Cell Broadcast Service (CBS) |
3GPP TS 31.101 | V9.1.2 | UICC-terminal interface; Physical and logical characteristics |
3GPP TS 31.102 | V8.17.0 | Security feature |
Sweden:
Tel.: +46-8-410 712 30
Fax.: +1 (484) 631 1399
Finland:
Tel: +358 (09) 2316 7020
USA:
Tel: +1-484-4019-980
Sweden: Smartjac AB Kanalvägen 1 A,
SE-194 61 Upplands Väsby,
USA: Smartjac Industries Inc. 411 West Miner St
PA-193 82 West Chester
Parametrics - chip | SLE 97CNFX1M50PE |
Ambient Temperature min max | -25 °C 85 °C |
Applications | SIM and UICC for mobile communication |
Asymmetric Cryptography | ECC up to 521-bit ; RSA up to 4096-bit |
CPU | 32-bit |
Certifications | CC EAL5+ high ; EMVCo |
Interfaces | ISO 7816 ; NRG™ (ISO/IEC 14443-3 type A with CRYPTO1) ; SWP |
Leading Technologies | NFC optimized ; SOLID FLASH™ |
NVM | 512 KBytes |
![]()
CHIP SPECIFICATIONS
Parametrics - chip | SLE 97CNFX1M50PE |
Package | VQFN-32 |
Product Description | 32-bit SWP SIM card security cryptocontroller |
RAM | 32 kByte |
Symmetric Cryptography | AES up to 256-bit ; DES, 3DES |