DESFire Applet on Apex

Any chance to get a DESFire Applet made for Java? Could Claude handle it?

1 Like

Im not sure, but that would be very cool!

1 Like

I mean kind of? But also not really. The question is way too open-ended and there would be a lot of qualifying information necessary to know if it would be even remotely possible to do what you’re trying to do.

What are you trying to do?

2 Likes

I’m fairly close with the Head of IT at our Company. He is responsible for the Technical Security department, and they’re trying to enable the ApexRing for my badge, but through reading online they either have to enable CSN and let me enroll by using my UID (not very secure and not their preference), or they need to write my credentials to a DESFire chip. Just wondering if it’s even possible. Claude seemed to think it could write the script for provisioning but that I needed the manufacturers passkeys to allow a new applet to be deployed.

It’s possible but you’d need to know the intimate details of the enrollment process (how data is stored on chip, instructions used to create the AIDs (files), keys used, etc.

Try on a j3r180 test card first.

What access control system is it?

1 Like

Hey Amal,

I looked into it and we’re running a Gallagher system (DESFire Probably EV2/EV3 but maybe EV1). It looks like a nightmare to emulate.

Here’s the gist of what I found, could definitely use the expertise.

The readers don’t just read a standard credential file. They’re hunting for a custom CAD (AID 0x…) to verify the “Facility Code” or Site Code? first

They use 128-bit AES, but with a custom private tweak on the standard key diversification.

Basically, a generic DESFire applet won’t handshake with it. We’ll see I’m hopeful my IT department will share the site keys to provision a custom applet onto my ring.

Seems like a dead otherwise though end unless you know a workaround for Gallagher setups. What do you think?

8 Likes

All hail @amal - :raising_hands: that was an incredible explanation! I actually understand now haha. Very interesting. So assuming the Apex smart card is in the category of not being configured on the ROM for DESFire? Is there an Apex 2.0 that could have that? I’ll keep digging on the other front and super appreciate your explanation.

1 Like

Correct…

Actually…

4 Likes

I’ll be the first to buy it if it does everything the Apex does and then some!

1 Like

@amal @Pilgrimsmaster ready to help me make this a reality? Or at least try? Gallagher is very interested. My company is also extremely supportive and will enable CSN/UID in the meantime.

4 Likes

Very cool :slight_smile: I’m all ears. If Apex can release a ghalleger applet for smart cards we’d put in the effort to develop it in partnership with ghalleger to ensure compliance and business goals are aligned.

3 Likes

Sounds great, I’ll send an invite. Want me to use your Vivokey or DT email?

VivoKey :slight_smile:

2 Likes

Just making sure you are aware, Amal is in in Seattle Pacific Daylight Time for your planning.

I’m currently in Korea, but you dont need me anyway.

Gallagher, as I am sure you are aware have offices around the world, with the Global headquarters in NZ, and at least 2 offices in the USA.

If you get stuck, I have some contacts in Gallagher I can connect you with, but I wont have access to their info for another couple of weeks.

4 Likes

Thanks pilgrim. Hopefully we make progress. Been a busy week but will send invites tomorrow and keep y’all posted.

2 Likes

Quick Update, today we met with the big G and I’ll let @amal chime in with his two cents, but overall I think it went really well. They seem very interested (technologically and economically). There’s a large market for something like this and I felt they saw the utility. No doubt they’re interested in the economics of it, but they see the writing on the wall and they don’t want to be left be-(HI)n(D) like others…

Interestingly they don’t seem to use unique credentials? (I’d be a little surprised if this was completely accurate, Amal fact check me please!).

More to come soon.

Yes it was a very good call. Now we dive into the technical. I did ask them to confirm their business model and the answer seemed strange, but maybe only because they did not elaborate. Many access control companies turn the credential purchase itself into a locked-down revenue stream (use the RFID transponder’s security features against the customer). Clearly they have other methods of making money in mind, they just didn’t explain what those were. :person_shrugging:

I’m getting together documentation now and we’ll see where this goes.

2 Likes