id: 4969b795be6b41c3bcae8117b1368d36
parent_id: b74c3f6cb4bc4fe18f2d1a99d6fd94ca
item_type: 1
item_id: 445891dba8674cae8b865a6fd2a3faf1
item_updated_time: 1786963123670
title_diff: "[]"
body_diff: "[{\"diffs\":[[0,\"e | \"],[-1,\"Industrial NFC reader via USB (CCID\"],[1,\"ACS ACR1281U-C1 (contactless PICC, CCID over USB\"],[0,\") |\\\n\"]],\"start1\":540,\"start2\":540,\"length1\":43,\"length2\":56},{\"diffs\":[[0,\"ioning plane\"],[-1,\")\"],[0,\",\"],[1,\" updated 2026-08-17),\\\n>\"],[0,\" **\\\"Keyfob S\"]],\"start1\":800,\"start2\":800,\"length1\":26,\"length2\":48},{\"diffs\":[[0,\" SCP03 /\"],[-1,\"\\\n>\"],[0,\" KLMS Fl\"]],\"start1\":856,\"start2\":856,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"oduction\"],[1,\"\\\n>\"],[0,\" summary\"]],\"start1\":906,\"start2\":906,\"length1\":16,\"length2\":18},{\"diffs\":[[0,\"mmary), \"],[-1,\"and\"],[1,\"**\\\"Keyfob Station — PlantUML Diagram Sources\\\"** (diagrams), and\\\n>\"],[0,\" **\\\"Keyf\"]],\"start1\":919,\"start2\":919,\"length1\":19,\"length2\":81},{\"diffs\":[[0,\" Station\"],[-1,\"\\\n>\"],[0,\" — Real \"]],\"start1\":1002,\"start2\":1002,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"trail).\\\n\"],[-1,\"\\\n---\"],[1,\"> Live open/closed items: **\\\"Keyfob Station — Code Audit Open Items\\\"** (in the\\\n> parent Key Fob Station notebook).\"],[0,\"\\\n\\\n## Two\"]],\"start1\":1067,\"start2\":1067,\"length1\":20,\"length2\":130},{\"diffs\":[[0,\"der)\"],[-1,\".\\\n- Uses the **development SCP03 static key set**; performs the **\"],[1,\" + **KLMS panel**.\\\n- Files mode: dev static keys (`dev_profiles.toml`), \"],[0,\"full \"],[1,\"SW \"],[0,\"KDF\"],[-1,\" in\\\n  software** (Phase 1 master+UID → S-ENC/MAC/DEK, Phase 2 → session keys).\\\n- Provisions from a per-fob container folder via `FileContainerSource`.\\\n- Today runs against the simulated JCOP applet (stub fob).\\\n\\\n### `kf-prod-station` — Production GUI\\\n- **Provisioning only** (no flashing).\\\n- **No KDF in the application.** After `INITIALIZE UPDATE` it forwards\\\n  `{uid, key_version, host_challenge, card_challenge, seq_counter, card_cryptogram}`\\\n  to Clypeum via a **DLL over mTLS** (`KlmsClient` trait) and receives back a\\\n  **container** with:\\\n  - the SCP03 **session keys** (SES-ENC/MAC/RMAC) + host cryptogram,\\\n  - the **pre-encrypted** personalization content (A003 already S-DEK-encrypted\\\n    by Clypeum via the NetHSM — the app never holds static/master/DEK keys).\\\n- `Scp03Channel::establish_from_session_keys` injects the container's keys.\\\n- `KlmsProvisioner` rejects any content item flagged `encrypt_with_dek=true`.\\\n- Today runs end-to-end against `MockKlmsClient` + the simulated fob\"],[1,\", per-fob container\\\n  folder via `FileContainerSource`.\\\n- **KLMS mode (the production flow, implemented here first):** REST over mTLS to\\\n  Clypeum — token auth, seed, `POST /cryptoContainers` (typeID/seedUUID/productSerial\\\n  + extra JSON), binary container parse/decrypt, session-key injection, auto-provision\\\n  on tap with retry classification. **HW-verified end-to-end 2026-08-17** (two fobs,\\\n  GA ECDSA signatures passing).\\\n\\\n### `kf-prod-station` — Production GUI\\\n- **Provisioning only** (no flashing).\\\n- Same session-key offload architecture, currently running against\\\n  `MockKlmsClient` — the proven REST client from kf-dev-station's KLMS panel is\\\n  the blueprint for its productionization.\\\n- `Scp03Channel::establish_from_session_keys` injects the container's keys;\\\n  card-ready A003 (S-DEK CBC+IV0+M2) is forwarded untouched — the app never holds\\\n  static/master/DEK keys\"],[0,\".\\\n\\\n#\"]],\"start1\":1407,\"start2\":1407,\"length1\":1075,\"length2\":969},{\"diffs\":[[0,\"aries.\\\n\\\n\"],[-1,\"---\\\n\\\n\"],[0,\"## Produ\"]],\"start1\":2671,\"start2\":2671,\"length1\":21,\"length2\":16},{\"diffs\":[[0,\"og**\"],[-1,\" keeps inventory,\"],[0,\" fet\"]],\"start1\":3118,\"start2\":3118,\"length1\":25,\"length2\":8},{\"diffs\":[[0,\" bundles\"],[-1,\",\"],[0,\" and has\"]],\"start1\":3130,\"start2\":3130,\"length1\":17,\"length2\":16},{\"diffs\":[[0,\"**NetHSM\"],[-1,\"\\\n \"],[0,\" decrypt\"]],\"start1\":3151,\"start2\":3151,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"them\"],[-1,\" → caches decrypted **packages** (≥ **2 weeks of production** stock)\"],[0,\".\\\n- \"]],\"start1\":3170,\"start2\":3170,\"length1\":76,\"length2\":8},{\"diffs\":[[0,\"ion \"],[-1,\"sends the fob UID + handshake to Clypeum (DLL/mTLS).\"],[1,\"identifies the fob, runs INITIALIZE UPDATE, and requests a container\\\n  via **REST/mTLS** (`POST /cryptoContainers`, seed-based on-demand generation).\\\n \"],[0,\" The\"]],\"start1\":3413,\"start2\":3413,\"length1\":60,\"length2\":159},{\"diffs\":[[0,\"n).\\\n  The **KLMS\"],[-1,\"\\\n \"],[0,\" orchestrates**:\"]],\"start1\":3563,\"start2\":3563,\"length1\":34,\"length2\":32},{\"diffs\":[[0,\"s**:\"],[-1,\" looks up cached content, uses the NetHSM to\"],[0,\" derive\"],[1,\"s\"],[0,\" **s\"]],\"start1\":3591,\"start2\":3591,\"length1\":59,\"length2\":16},{\"diffs\":[[0,\"tic keys\"],[-1,\"\\\n \"],[0,\" (KDF3, \"]],\"start1\":3609,\"start2\":3609,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"UID)** →\"],[1,\"\\\n \"],[0,\" **sessi\"]],\"start1\":3632,\"start2\":3632,\"length1\":16,\"length2\":18},{\"diffs\":[[0,\"K encryption\"],[1,\" (CBC, IV=0, M2)\"],[0,\".\\\n- Clypeum \"]],\"start1\":3685,\"start2\":3685,\"length1\":24,\"length2\":40},{\"diffs\":[[0,\"rns a **\"],[1,\"binary \"],[0,\"containe\"]],\"start1\":3729,\"start2\":3729,\"length1\":16,\"length2\":23},{\"diffs\":[[0,\"ontainer** (\"],[1,\"13 TLV fields: \"],[0,\"session keys\"]],\"start1\":3745,\"start2\":3745,\"length1\":24,\"length2\":39},{\"diffs\":[[0,\": session keys +\"],[1,\"\\\n \"],[0,\" pre-encrypted c\"]],\"start1\":3770,\"start2\":3770,\"length1\":32,\"length2\":34},{\"diffs\":[[0,\"nt); the\"],[-1,\"\\\n \"],[0,\" station\"]],\"start1\":3808,\"start2\":3808,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"to fob; \"],[-1,\"DLL\"],[1,\"REST\"],[0,\"/mTLS to\"]],\"start1\":4177,\"start2\":4177,\"length1\":19,\"length2\":20},{\"diffs\":[[0,\"pted\"],[-1,\"-\"],[1,\" \"],[0,\"content\"],[-1,\" cache (2-wk stock)\"],[0,\" | w\"]],\"start1\":4256,\"start2\":4256,\"length1\":35,\"length2\":16},{\"diffs\":[[0,\"(Flow 2)\"],[1,\"; generates containers on demand\"],[0,\" |\\\n| **N\"]],\"start1\":4309,\"start2\":4309,\"length1\":16,\"length2\":48},{\"diffs\":[[0,\"HSM)\"],[-1,\"; the watchdog keeps a 2-week cache\"],[0,\".\\\n- \"]],\"start1\":4998,\"start2\":4998,\"length1\":43,\"length2\":8},{\"diffs\":[[0,\"003.\"],[-1,\" The **Station↔Clypeum boundary\\\n  (`KlmsClient`) is unchanged.**\"],[0,\"\\\n\\\n--\"]],\"start1\":5128,\"start2\":5128,\"length1\":72,\"length2\":8},{\"diffs\":[[0,\"26-0\"],[-1,\"6-30\"],[1,\"8-17\"],[0,\", rev \"],[-1,\"7\"],[1,\"8\"],[0,\")\\\n\\\nA\"]],\"start1\":5167,\"start2\":5167,\"length1\":19,\"length2\":19},{\"diffs\":[[0,\"ce. \"],[-1,\"Everything runs **headless** — no hardware required —\\\nagainst a simulated JCOP applet + (for the prod path) a mock KLMS\"],[1,\"**Real hardware in the loop**: PC/SC reader + real\\\nNCJ37x fobs; KLMS REST flow verified end-to-end against the dev Clypeum\\\nenvironment\"],[0,\". **\"],[-1,\"86\"],[1,\"105\"],[0,\" tests\"],[-1,\"\\\n\"],[1,\" \"],[0,\"pass\"]],\"start1\":5209,\"start2\":5209,\"length1\":140,\"length2\":156},{\"diffs\":[[0,\"ean \"],[-1,\"(incl. `--features nitrokey`\"],[1,\"on all 3 build variants\\\n(full/test/minimal\"],[0,\"), `\"]],\"start1\":5390,\"start2\":5390,\"length1\":36,\"length2\":50},{\"diffs\":[[0,\"clean.**\"],[-1,\"\\\n\"],[1,\" \"],[0,\"Both GUI\"]],\"start1\":5445,\"start2\":5445,\"length1\":17,\"length2\":17},{\"diffs\":[[0,\"ifecycle\"],[-1,\" transition\"],[1,\", `select`\"],[0,\") | ✅ Do\"]],\"start1\":5818,\"start2\":5818,\"length1\":27,\"length2\":26},{\"diffs\":[[0,\"let`\"],[-1,\" (lifecycle states)\"],[1,\", **PC/SC transport**\"],[0,\" | ✅\"]],\"start1\":6080,\"start2\":6080,\"length1\":27,\"length2\":29},{\"diffs\":[[0,\"MS Lite)\"],[1,\" + **KLMS REST panel (HW-verified)**\"],[0,\" | ✅ Don\"]],\"start1\":6889,\"start2\":6889,\"length1\":16,\"length2\":52},{\"diffs\":[[0,\"only\"],[-1,\", DLL/mTLS to Clypeum, no KDF in app\"],[1,\"; mock KLMS for now (REST productionization pending)\"],[0,\" | ✅\"]],\"start1\":6994,\"start2\":6994,\"length1\":44,\"length2\":60},{\"diffs\":[[0,\"| ✅ Done\"],[1,\" (mock)\"],[0,\" |\\\n\\\n### \"]],\"start1\":7051,\"start2\":7051,\"length1\":16,\"length2\":23},{\"diffs\":[[0,\"tus\\\n\"],[-1,\"All **CRITICAL** and **WARNING** findings fixed across multiple review passes:\\\nDGI-tag \"],[1,\"Multiple full review passes through 2026-08; all CRITICAL/HIGH/MEDIUM f\"],[0,\"ind\"],[-1,\"ex\"],[0,\"ing\"],[-1,\" panic → validated; empty `personalization_items` → rejected;\\\naudit TX entries → redacted (no secrets in audit); applet auth bypass on empty\\\nSTORE DATA → closed; host-cryptogram compare → constant-time; host-challenge RNG\\\n→ fail-closed `Result`. Remaining items are dead-code cleanup or deferred to\\\nreal-card (below).\\\n\\\n### Stubbed Behind Traits (pending external decisions / hardware)\\\n- **DLL-backed `KlmsClient`** — trait + `MockKlmsClient` in place; the real DLL\\\n  links the station to Clypeum over mTLS\"],[1,\"s\\\nclosed (see the audit note's session log). Zero clippy warnings across all 3\\\nbuild variants; 105 tests.\\\n\\\n### Stubbed Behind Traits (pending external decisions / hardware)\\\n- **`report_usage`** — REST method defined; unwired pending KLMS status semantics.\\\n- **Container signature/checksum verification** — ready to wire pending signing-key\\\n  confirmation + checksum algorithm spec\"],[0,\".\\\n- \"]],\"start1\":7089,\"start2\":7089,\"length1\":608,\"length2\":465},{\"diffs\":[[0,\"hdog\"],[-1,\"/content cache\"],[0,\" (Fl\"]],\"start1\":7579,\"start2\":7579,\"length1\":22,\"length2\":8},{\"diffs\":[[0,\"stration\"],[-1,\"\\\n \"],[0,\" (Flow 2\"]],\"start1\":7609,\"start2\":7609,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"w 2) are\"],[1,\"\\\n \"],[0,\" **Clype\"]],\"start1\":7622,\"start2\":7622,\"length1\":16,\"length2\":18},{\"diffs\":[[0,\"nly.\"],[-1,\"\\\n- **Real `pcsc` transport** — `SmartcardTransport` trait ready; awaits NFC reader hardware.\"],[0,\"\\\n\\\n##\"]],\"start1\":7694,\"start2\":7694,\"length1\":100,\"length2\":8},{\"diffs\":[[0,\" clippy \"],[1,\"--workspace \"],[0,\"--all-ta\"]],\"start1\":7753,\"start2\":7753,\"length1\":16,\"length2\":28},{\"diffs\":[[0,\"\\\n1. \"],[-1,\"**DLL-backed `KlmsClient`** — bind the station→Clypeum link (mTLS) behind the trait\"],[1,\"~~DLL/REST binding~~ → **done** (REST client, HW-verified)\"],[0,\".\\\n2. \"],[-1,\"**\"],[1,\"~~\"],[0,\"Real\"]],\"start1\":8012,\"start2\":8012,\"length1\":98,\"length2\":73},{\"diffs\":[[0,\"port\"],[-1,\"** — wire real readers into both binaries\"],[1,\"~~ → **done**\"],[0,\".\\\n3. \"],[-1,\"**\"],[1,\"~~\"],[0,\"Real\"]],\"start1\":8098,\"start2\":8098,\"length1\":56,\"length2\":28},{\"diffs\":[[0,\"tion\"],[-1,\"** — run both paths against real NCJ37x samples.\\\n4. **Bundle/content-supply design** — bundle crypto, push/pull, 2-week sizing (Flow 1).\\\n5. **NetHSM product + primitive surface** — confirm YubiHSM 2 / Nitrokey / Utimaco\\\n      for master-key AES primitives + bundle decrypt (Flow 1+2)\"],[1,\"~~ → **done** (dev flow + KLMS flow, 2026-08-17).\\\n4. **Clypeum external items**: valid CA cert (C1), `cryptoDataContainerId`\\\n   header, signing-key confirmation, checksum spec, `report_usage` semantics.\\\n5. **kf-prod-station productionization** — port the verified REST flow\"],[0,\".\\\n6.\"]],\"start1\":8138,\"start2\":8138,\"length1\":291,\"length2\":281},{\"diffs\":[[0,\"ce. \"],[-1,\"Swap in official GP vectors / validate on a real\\\n  JCOP card with known static keys.\\\n- **Dead-code cleanup (low priority)** — orphaned `handle_set_status`/`ins::SET_STATUS`,\\\n  unused `lifecycle()`/`is_factory()` accessors.\"],[1,\"(Partially mitigated: the KLMS-delivered session\\\n  keys are now verified against a real card on every tap — the cryptogram gate.)\"],[0,\"\\\n\\\n--\"]],\"start1\":8972,\"start2\":8972,\"length1\":230,\"length2\":137},{\"diffs\":[[0,\"C(S-DEK,\"],[1,\" IV=0,\"],[0,\" M2 pad)\"]],\"start1\":9886,\"start2\":9886,\"length1\":16,\"length2\":22},{\"diffs\":[[0,\"ed**\"],[-1,\" in the\\\n> container (`encrypt_with_dek=false`); the app never holds S-DEK. The A003\\\n> plaintext + the other per-fob content come from the Flow 1 content cache\"],[1,\"\\\n> (card-ready, CBC+IV0+M2 — HW-verified 2026-08-17); the app never holds S-DEK\"],[0,\".\\\n\\\n#\"]],\"start1\":10346,\"start2\":10346,\"length1\":166,\"length2\":87},{\"diffs\":[[0,\"y Format\"],[1,\" (Files mode)\"],[0,\"\\\n\\\nEach f\"]],\"start1\":11581,\"start2\":11581,\"length1\":16,\"length2\":29},{\"diffs\":[[0,\"on (\"],[-1,\"`kf-prod-station`)** — no KDF in the app:\\\n1. Read fob UID + INITIALIZE UPDATE response.\\\n2. Forward `{uid, challenges, card_cryptogram}` to Clypeum via the DLL (mTLS)\"],[1,\"KLMS flow, currently in `kf-dev-station`'s KLMS panel)** — no KDF in the app:\\\n1. SELECT ISD + GET DATA (OEF + UID); INITIALIZE UPDATE.\\\n2. `POST /cryptoContainers` (REST/mTLS): typeID, seedUUID, productSerial + extra{handshake}\"],[0,\".\\\n3.\"]],\"start1\":13098,\"start2\":13098,\"length1\":173,\"length2\":234},{\"diffs\":[[0,\"pts A003\"],[-1,\".\\\n4.\"],[1,\" (CBC+IV0+M2).\\\n4. Station decrypts the binary container, verifies the card cryptogram locally,\\\n  \"],[0,\" `establ\"]],\"start1\":13440,\"start2\":13440,\"length1\":20,\"length2\":113},{\"diffs\":[[0,\"TA → lifecycle →\"],[1,\"\\\n   post-perso → validation (GA) →\"],[0,\" zeroize.\\\n\\\n**Dev\"]],\"start1\":13610,\"start2\":13610,\"length1\":32,\"length2\":66},{\"diffs\":[[0,\"opment (\"],[-1,\"`kf-dev-station`\"],[1,\"Files mode\"],[0,\")** — fu\"]],\"start1\":13678,\"start2\":13678,\"length1\":32,\"length2\":26},{\"diffs\":[[0,\"e.\\\n\\\n\"],[-1,\"### Key Design Decision: master key in the Clypeum NetHSM; content supplied as encrypted bundles\\\n\\\nThe architecture evolved from local Nitrokey KDF → KLMS-HSM session-key offload →\\\nthe current **two-flow split**:\\\n\\\n- The **NXP master key lives in the NetHSM** (Clypeum-side), imported from NXP,\\\n  never exported. The NetHSM does **AES primitives only** (AES-CMAC/AES-CBC); the\\\n  **KLMS orchestrates** SCP03 — KDF3 (Phase 1, master+UID → S-ENC/MAC/DEK, purpose\\\n  bytes 0x40/0x60/0x70, raw 10-byte UID), then Phase-2 session keys + cryptograms,\\\n  and A003 AES-CBC(S-DEK).\\\n- Per-fob **content** (FESN/SPID/certs/device key) is supplied **separately** by\\\n  Ford IVSS/GIVIS as encrypted **bundles** (keypair generated in the same NetHSM);\\\n  the watchdog keeps a 2-week cache. (See Flow 1.)\\\n\\\n**Net:** master key + static keys never leave the NetHSM; the station receives\\\nonly ephemeral session keys + pre-encrypted A003. The Station↔Clypeum boundary is\\\nunchanged.\\\n\\\n\"],[0,\"---\\\n\"]],\"start1\":13915,\"start2\":13915,\"length1\":965,\"length2\":8},{\"diffs\":[[0,\"ee=se)\\\n\\\n\"],[1,\"### Step 0: Identify\\\n- `00 A4 04 00 || A000000151000000` (SELECT ISD), then GET DATA → OEF ID + UID\\\n- **UID is NOT part of the INITIALIZE UPDATE response** (read here first)\\\n\\\n\"],[0,\"### Step\"]],\"start1\":14112,\"start2\":14112,\"length1\":16,\"length2\":191},{\"diffs\":[[0,\"se (\"],[-1,\"S8 mode\"],[1,\"as parsed by `parse_init_update`\"],[0,\"): `\"]],\"start1\":14384,\"start2\":14384,\"length1\":15,\"length2\":40},{\"diffs\":[[0,\"10) \"],[-1,\"||\"],[1,\"‖\"],[0,\" key_\"],[-1,\"info(1) || seq_counter(3) || KVN(2) ||\"],[1,\"version(1) ‖ scp_id(1) ‖ i_param(1) ‖\"],[0,\" car\"]],\"start1\":14428,\"start2\":14428,\"length1\":53,\"length2\":51},{\"diffs\":[[0,\"enge(8) \"],[-1,\"||\"],[1,\"‖\"],[0,\" card_cr\"]],\"start1\":14486,\"start2\":14486,\"length1\":18,\"length2\":17},{\"diffs\":[[0,\"ogram(8)\"],[1,\" ‖ seq_counter(3, tail)\"],[0,\"`\\\n\\\n### S\"]],\"start1\":14506,\"start2\":14506,\"length1\":16,\"length2\":39},{\"diffs\":[[0,\"s + \"],[-1,\"SeqCnt + RND.IC + RND.CC\"],[1,\"challenges\"],[0,\"\\\n- U\"]],\"start1\":14624,\"start2\":14624,\"length1\":32,\"length2\":18},{\"diffs\":[[0,\"S-CMAC(S\"],[1,\"ES\"],[0,\"-MAC, de\"]],\"start1\":14974,\"start2\":14974,\"length1\":16,\"length2\":18},{\"diffs\":[[0,\"ed with \"],[1,\"SE\"],[0,\"S-MAC ch\"]],\"start1\":15032,\"start2\":15032,\"length1\":16,\"length2\":18},{\"diffs\":[[0,\"hannel\\\n\\\n\"],[1,\"### Step 7: Validation\\\n- Cert read-back (KF/ICA/CMS), FESN/SPID read-back, GA ECDSA signature verify\\\n\\\n\"],[0,\"---\\\n\\\n## \"]],\"start1\":15603,\"start2\":15603,\"length1\":16,\"length2\":118},{\"diffs\":[[0,\"ports) |\"],[1,\"\\\n| `Validation` | Read-back + GA signature check |\"],[0,\"\\\n\\\n---\\\n\\\n#\"]],\"start1\":16240,\"start2\":16240,\"length1\":16,\"length2\":66},{\"diffs\":[[0,\"ihalopul\"],[-1,\"ou\"],[1,\"e\"],[0,\"s |\\\n| Pr\"]],\"start1\":16522,\"start2\":16522,\"length1\":18,\"length2\":17},{\"diffs\":[[0,\"hdog\"],[-1,\"/cache\"],[0,\" (Fl\"]],\"start1\":17148,\"start2\":17148,\"length1\":14,\"length2\":8},{\"diffs\":[[0,\"tation over \"],[1,\"REST/\"],[0,\"mTLS.\\\n\\\n---\\\n\\\n\"]],\"start1\":17217,\"start2\":17217,\"length1\":24,\"length2\":29},{\"diffs\":[[0,\"station`\"],[1,\" Files mode\"],[0,\" targets\"]],\"start1\":17587,\"start2\":17587,\"length1\":16,\"length2\":27},{\"diffs\":[[0,\"tent\"],[-1,\" cache +\"],[0,\" wat\"]],\"start1\":18126,\"start2\":18126,\"length1\":16,\"length2\":8},{\"diffs\":[[0,\" | (\"],[-1,\"YubiHSM2/Nitrokey/Utimaco, \"],[0,\"Clyp\"]],\"start1\":18150,\"start2\":18150,\"length1\":35,\"length2\":8},{\"diffs\":[[0,\"C pipe, \"],[-1,\"DLL\"],[1,\"REST\"],[0,\"/mTLS to\"]],\"start1\":18305,\"start2\":18305,\"length1\":19,\"length2\":20},{\"diffs\":[[0,\"s |\\\n\"],[-1,\"| `time` | ISO-8601 timestamps for audit records |\\\n\"],[0,\"| `g\"]],\"start1\":19404,\"start2\":19404,\"length1\":59,\"length2\":8},{\"diffs\":[[0,\"rrors |\\\n\"],[1,\"| `reqwest` | KLMS REST client (mTLS + bearer token) |\\\n| `pcsc` (via `pcsc-sys`) | PC/SC reader transport |\\\n\"],[0,\"| `crypt\"]],\"start1\":19799,\"start2\":19799,\"length1\":16,\"length2\":124},{\"diffs\":[[0,\"view. |\\\n\"],[1,\"| `6A 80` | Incorrect values in data field | Halt — bad DGI payload (e.g. wrong A003 cipher mode) |\\\n\"],[0,\"| `6A 86\"]],\"start1\":20186,\"start2\":20186,\"length1\":16,\"length2\":116},{\"diffs\":[[0,\"locked |\"],[1,\"\\\n| `69 FF` / `62 80` | GP auth counter exhausted (\\\"auth exceed\\\") | **Card permanently locked** — see the Locked-Fob incident note |\"],[0,\"\\\n\\\n---\\\n\\\n#\"]],\"start1\":20618,\"start2\":20618,\"length1\":16,\"length2\":147},{\"diffs\":[[0,\" **i\"],[-1,\"nterface de\"],[1,\"mplemented & HW-veri\"],[0,\"fi\"],[-1,\"n\"],[0,\"ed** \"],[-1,\"as the `KlmsClient` trait (`SessionRequest`/`SessionResponse`/`KlmsContent`); DLL implementation pending\\\n- [ ] **DLL interface** + **mTLS** details for the station↔Clypeum link\"],[1,\"(token auth, seed,\\\n      `POST /cryptoContainers` binary container)\"],[0,\"\\\n- [\"]],\"start1\":20834,\"start2\":20834,\"length1\":203,\"length2\":102},{\"diffs\":[[0,\"\\\n- [\"],[-1,\" ] **Bundle encryption scheme** (RSA-OAEP / ECIES / AES-KW) + push vs pull + signature (Flow 1)\\\n- [ ] **2-week stock sizing** + low-water mark (Flow 1)\\\n- [ ] **NetHSM product** (YubiHSM 2 / Nitrokey / Utimaco)\"],[1,\"x] ~~A003 card-ready cipher format~~ → AES-128-CBC, IV=0, M2 (2026-08-17)\\\n- [ ] **Valid CA certificate chain** (C1) — dev runs `accept_invalid_certs=true`\\\n- [ ] **`cryptoDataContainerId` header** — currently empty on success\\\n- [ ] **Container signing key** confirmation + **checksum algorithm** spec (0x00–0x03)\\\n- [ ] **`report_usage`** status values/payload semantics\\\n- [ ] **Bundle encryption scheme** (RSA-OAEP / ECIES / AES-KW) + push vs pull + signature (Flow 1)\\\n- [ ] **NetHSM product**\"],[0,\" + A\"]],\"start1\":21130,\"start2\":21130,\"length1\":217,\"length2\":500},{\"diffs\":[[0,\"[ ] \"],[-1,\"TTL on issued session key\"],[1,\"getVersions / getContainerType\"],[0,\"s \"],[-1,\"(\"],[0,\"re\"],[-1,\"commended: 5 seconds) + single-use\\\n- [ ] KLMS logging and audit trail capabilities\"],[1,\"turn empty — response shape or permissions?\"],[0,\"\\\n- [\"]],\"start1\":21793,\"start2\":21793,\"length1\":120,\"length2\":85},{\"diffs\":[[0,\"ge)\\\n\"],[-1,\"\\\n---\\\n\\\n*Source: Z.ai chat session (2025-06-08). \"],[1,\"- [x] ~~TTL on issued session keys~~ → dropped; the API enforces no TTL\\\n\\\n---\\\n\\\n*\"],[0,\"Upda\"]],\"start1\":22052,\"start2\":22052,\"length1\":55,\"length2\":87},{\"diffs\":[[0,\"26-0\"],[-1,\"6-30\"],[1,\"8-17\"],[0,\" rev \"],[-1,\"7: split production into two planes — **Flow 1** (content supply: Ford IVSS/GIVIS → encrypted bundles → NetHSM-decrypt → Clypeum watchdog cache) and **Flow 2** (provisioning: station forwards handshake via DLL/mTLS; Clypeum derives static+session keys using the NetHSM which holds the NXP master key; returns content+keys container). The master key is in the Clypeum NetHSM; bundles carry content only. 86 tests, clippy clean incl. nitrokey\"],[1,\"8: REST transport implemented and HW-verified (KLMS flow end-to-end, card-ready A003 CBC+M2); real PC/SC hardware in the loop; 105 tests, clippy clean on all 3 build variants. Earlier revs: 2026-06-30 rev 7 (two-flow split), 2025-06-08 initial\"],[0,\".*\"]],\"start1\":22145,\"start2\":22145,\"length1\":455,\"length2\":258}]"
metadata_diff: {"new":{},"deleted":[]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-08-17T10:39:07.803Z
created_time: 2026-08-17T10:39:07.803Z
is_locked: 0
type_: 13