I am trying to give Change Key command for a new TDES Key (K1 != K2) after Standard Authentication (0x1A) of Key0. I am getting error 1E. The same authentication (0x1A) and functions (key block generation, CRC32, Enciphering etc.) were used for the Change Key command for new TDES Keys (K1=K2) and 3KTDES keys for different apps and they were successful. Yes, Session key generation were different. My question is do we need to do something different in case of 2KTDES. Following is the log of the steps followed on (PN7160, nci 2.0):
TX: 00 00 0B 90 CA 00 00 05 FF FF 02 0F 05 00
RX: 00 00 0A 80 F8 F0 76 D7 98 10 5E 91 00
#DesfireEV1
TX: 00 00 09 90 5A 00 00 03 FF FF 02 00
RX: 00 00 02 91 00
TX: 00 00 07 90 1A 00 00 01 00 00
RX: 00 00 0A 11 AB 8B 5F 37 F1 5D 15 91 AF
TX: 00 00 16 90 AF 00 00 10 42 8F EB 15 99 EF C2 9F 80 45 92 2C E8 6D EE 6B 00
RX: 00 00 0A 1E 08 BE 39 E9 06 42 7F 91 00
RndA matched and Session key was (RndA(0-3)RndB(0-3)RndA(4-7)RndB(4-7))
41 42 43 44 89 C0 AF 76 45 46 47 48 A5 ED 90 60
TX: 00 00 1F 90 C4 00 00 19 01 17 42 32 03 90 E4 2B 0C A9 E3 0F A8 0F 63 F5 30 BE F9 B4 E1 F1 2E AE CD 00
RX: 00 00 02 91 1E
As in the cases of C4 for TDES (k1=K2) and 3KTDES2 the C4 frame consists of (key-no (01), enciphered keyblock with Session key). Where keyblock = (new key XOR 00), Little Endian CRC32(C4, 01, (new key XOR 00)), Little Endian CRC32(new key XOR 00).
Could anybody help?
Thanks in advance.