Re: Support for the Montenegrin eID

Frank Morgner <[email protected]> Fri, 25 Apr 2025 22:52:45 +0200
Newsgroups gmane.comp.encryption.opensc.devel
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============5079078647639804652==
Content-Type: multipart/alternative;
 boundary="------------gBOK4DZFhMXgdStqMTdHpw70"

This is a multi-part message in MIME format.
--------------gBOK4DZFhMXgdStqMTdHpw70
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

The middleware is available on the bottom of this page
https://www.gov.me/clanak/preuzmite-software-i-uputstva

But I think you already know that. You analyzed that in 2024 already, 
didn't you?

Regards.

Am 22.04.25 um 14:44 schrieb dzeri96 via Opensc-devel:
> Hello everyone,
>
> I'm trying to kickstart support for the new Montenegrin eID 
> <https://www.gov.me/mup/elk>, or at least figure out how it works. 
> I've sent multiple requests for technical specs to the government, but 
> unless I take them to court, I doubt I'll get any useful information. 
> Therefore I'll just write down what I manage to figure out on my own, 
> and hopefully you can provide further insight. One thing about a 
> country as small as Montenegro, is that there is a very high 
> probability we didn't implement anything custom, as it's not 
> financially viable.
>
> Here's what I have so far:
>
>   * *ATR*:
>     3b:dc:96:ff:81:91:fe:1f:c3:80:73:c8:21:13:66:05:03:63:51:00:02:de.
>     It doesn't seem to comply with the ATR scheme in the IAS ECC
>     specification, even though the government says the card complies
>     with all EU ID regulations (unclear which ones).
>   * *EF.ATR raw data*: 80004301B946040400ECC24703940180
>     4F0BF0496173456363526F6F74E01002 020104020200E6020200E6020200E678
>     0806062B8122F8780282029000
>   * *EF.DIR raw data*: 61374F0EE828BD080FD25047656E6572
>     6963500743686970446F63731C300404 025031A004040250324F0EE828BD080F
>     D2504543432D654944610F4F07A00000 0247100150044943414F61184F0A4D4F
>     4E54454E4547524F500A4E6174696F6E 616C4944
>   * By deciphering the EF.DIR data, we can discover 4 applications:
>       o E828BD080FD25047656E65726963 - ECC Generic PKI / ChipDocs Applet
>       o E828BD080FD2504543432D654944 - ECC eID
>       o A0000002471001 - ICAO
>       o 4D4F4E54454E4547524F - Spells out MONTENEGRO in ASCII, label
>         is "NationalID". No idea what this could be... maybe something
>         related to healthcare?
>   * I managed to use npa-tool and read the MRZ stored on the card
>     using CAN-based PACE, but all other functions of the tool don't
>     work, not even PIN-based PACE. I'm just using it as an APDU
>     debugger with PACE support.
>   * The official middleware supplied by the government is Athena
>     IDProtect.
>   * The activation software is available here
>     <https://wapi.gov.me/download/e63b50c5-9ccc-4034-961f-5bb401a9b375?version=1.0>.
>     It's a java program developed by Mühlbauer
>     <https://www.muehlbauer.de/>. I decompiled it and saw that it's
>     accessing the ECC eID application. I managed to extract some APDUs
>     and get the activation status of the card (PIN change is required
>     on first use).
>   * iasecc-tool and pkcs15-tool say "Card is invalid or cannot be
>     handled" regardless of what I try.
>
> I've skimmed over hundreds of pages of standards, including the 
> ISO-7816 parts, the NXP ChipDoc v4 spec, the BSI TR-03110, the IAS ECC 
> spec, but I can barely find any concrete info on these applications. 
> Someone must know how to access them because there are vendor-provided 
> tools to do so.
>
> My goals are:
>
>  1. Get general knowledge about the card and build some PoC APDU
>     chains to read/set data.
>  2. Get the birthdate of the person via PIN-based auth and verify the
>     authenticity of the data.
>  3. Get the openSC suite of tools to work with the card.
>  4. Replace the closed-source middleware provided by the government.
>
>
> I would really appreciate any help here. Thanks!
>
>
> _______________________________________________
> Opensc-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/opensc-devel
--------------gBOK4DZFhMXgdStqMTdHpw70
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>The middleware is available on the bottom of this page<br>
      <a class="moz-txt-link-freetext" href="https://www.gov.me/clanak/preuzmite-software-i-uputstva">https://www.gov.me/clanak/preuzmite-software-i-uputstva</a></p>
    <p>But I think you already know that. You analyzed that in 2024
      already, didn't you?</p>
    <p>Regards.<br>
    </p>
    <div class="moz-cite-prefix">Am 22.04.25 um 14:44 schrieb dzeri96
      via Opensc-devel:<br>
    </div>
    <blockquote type="cite"
cite="mid:7OQr9mkal5ySpx5bNbxnwXFnLT5QAPGDGck7MG82BYisaIBIIVVg8RlzTPfs6njh-IiUcZ0n7wbdiRSYspWbXeeLYaHgE-rhtGfAMh91XpE=@proton.me">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div style="font-family: Arial, sans-serif; font-size: 14px;">Hello
        everyone,</div>
      <div style="font-family: Arial, sans-serif; font-size: 14px;"><br>
      </div>
      <div style="font-family: Arial, sans-serif; font-size: 14px;">I'm
        trying to kickstart support for the new <a
          title="Montenegrin eID" href="https://www.gov.me/mup/elk"
          target="_blank" rel="noreferrer nofollow noopener"
          moz-do-not-send="true">Montenegrin eID</a>, or at least figure
        out how it works. I've sent multiple requests for technical
        specs to the government, but unless I take them to court, I
        doubt I'll get any useful information. Therefore I'll just write
        down what I manage to figure out on my own, and hopefully you
        can provide further insight. One thing about a country as small
        as Montenegro, is that there is a very high probability we
        didn't implement anything custom, as it's not financially
        viable.</div>
      <div style="font-family: Arial, sans-serif; font-size: 14px;"><br>
      </div>
      <div style="font-family: Arial, sans-serif; font-size: 14px;"><span
          style="font-size: 13.5pt; line-height: normal;">Here's what I
          have so far:</span></div>
      <div style="font-family: Arial, sans-serif; font-size: 14px;">
        <ul
data-editing-info="{&quot;orderedStyleType&quot;:1,&quot;unorderedStyleType&quot;:1}"
          style="margin-top: 0px; margin-bottom: 0px;">
          <li style="list-style-type: disc;"><b>ATR</b>: <span>3b:dc:96:ff:81:91:fe:1f:c3:80:73:c8:21:13:66:05:03:63:51:00:02:de</span>.
            It doesn't seem to comply with the ATR scheme in the IAS ECC
            specification, even though the government says the card
            complies with all EU ID regulations (unclear which ones).</li>
          <li style="list-style-type: disc;"><b>EF.ATR raw data</b>:
            80004301B946040400ECC24703940180
            4F0BF0496173456363526F6F74E01002
            020104020200E6020200E6020200E678
            0806062B8122F8780282029000</li>
          <li style="list-style-type: disc;"><b>EF.DIR raw data</b>: <span>61374F0EE828BD080FD25047656E6572
              6963500743686970446F63731C300404
              025031A004040250324F0EE828BD080F</span>
            <div><span>D2504543432D654944610F4F07A00000
                0247100150044943414F61184F0A4D4F
                4E54454E4547524F500A4E6174696F6E </span><span>616C4944</span></div>
          </li>
          <li style="list-style-type: disc;">By deciphering the EF.DIR
            data, we can discover 4 applications:</li>
          <ul
style="margin-top: 0px; margin-bottom: 0px; list-style-type: circle;">
            <li style="font-size: 15px; font-family: &quot;Mono&quot;;"><span
style="font-size:15px;line-height:24px;letter-spacing:-0.08px;overflow-wrap:break-word"><kbd
style="display: inline; font-family: &quot;Mono&quot;; line-height: 1.71; background: rgba(247, 245, 240, 0.5); padding: 0px 4px; border-radius: 2px;">E828BD080FD25047656E65726963</kbd></span>
              - ECC Generic PKI / ChipDocs Applet</li>
            <li style="font-size: 15px; font-family: &quot;Mono&quot;;"><span
style="font-size:15px;line-height:24px;letter-spacing:-0.08px;overflow-wrap:break-word"><kbd
style="display: inline; font-family: &quot;Mono&quot;; line-height: 1.71; background: rgba(247, 245, 240, 0.5); padding: 0px 4px; border-radius: 2px;">E828BD080FD2504543432D654944</kbd></span>
              - ECC eID</li>
            <li style="font-size: 15px; font-family: &quot;Mono&quot;;"><span
style="font-size:15px;line-height:24px;letter-spacing:-0.08px;overflow-wrap:break-word"><kbd
style="display: inline; font-family: &quot;Mono&quot;; line-height: 1.71; background: rgba(247, 245, 240, 0.5); padding: 0px 4px; border-radius: 2px;">A0000002471001</kbd></span>
              - ICAO</li>
            <li style="">4D4F4E54454E4547524F - Spells out MONTENEGRO in
              ASCII, label is "NationalID". No idea what this could
              be... maybe something related to healthcare?</li>
          </ul>
          <li style="list-style-type: disc;">I managed to use npa-tool
            and read the MRZ stored on the card using CAN-based PACE,
            but all other functions of the tool don't work, not even
            PIN-based PACE. I'm just using it as an APDU debugger with
            PACE support.</li>
          <li style="list-style-type: disc;">The official middleware
            supplied by the government is Athena IDProtect.</li>
          <li style="list-style-type: disc;">The activation software is
            available <a
href="https://wapi.gov.me/download/e63b50c5-9ccc-4034-961f-5bb401a9b375?version=1.0"
              title="here" moz-do-not-send="true">here</a>. It's a java
            program developed by <a href="https://www.muehlbauer.de/"
              title="Mühlbauer" moz-do-not-send="true">Mühlbauer</a>. I
            decompiled it and saw that it's accessing the ECC eID
            application. I managed to extract some APDUs and get the
            activation status of the card (PIN change is required on
            first use).</li>
          <li style="list-style-type: disc;">iasecc-tool and pkcs15-tool
            say "Card is invalid or cannot be handled" regardless of
            what I try.</li>
        </ul>
        <div>I've skimmed over hundreds of pages of standards, including
          the ISO-7816 parts, the NXP ChipDoc v4 spec, the BSI TR-03110,
          the IAS ECC spec, but I can barely find any concrete info on
          these applications. Someone must know how to access them
          because there are vendor-provided tools to do so.</div>
        <div><br>
        </div>
        <div><span style="font-size: 13.5pt; line-height: normal;">My
            goals are:</span></div>
        <div>
          <ol
data-editing-info="{&quot;orderedStyleType&quot;:1,&quot;unorderedStyleType&quot;:1}"
            style="margin-top: 0px; margin-bottom: 0px;">
            <li
style="font-size: 10.5pt; list-style-type: &quot;1. &quot;;"><span
                style="font-size: 10.5pt; line-height: normal;">Get
                general knowledge about the card and build some PoC APDU
                chains to read/set data.</span></li>
            <li
style="font-size: 10.5pt; list-style-type: &quot;2. &quot;;"><span
                style="font-size: 10.5pt; line-height: normal;">Get the
                birthdate of the person via PIN-based auth and verify
                the authenticity of the data.</span></li>
            <li
style="font-size: 10.5pt; list-style-type: &quot;3. &quot;;">Get the
              openSC suite of tools to work with the card.</li>
            <li
style="font-size: 10.5pt; list-style-type: &quot;4. &quot;;">Replace the
              closed-source middleware provided by the government.</li>
          </ol>
          <div><br>
          </div>
          <div>I would really appreciate any help here. Thanks!</div>
        </div>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre wrap="" class="moz-quote-pre">_______________________________________________
Opensc-devel mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/opensc-devel">https://lists.sourceforge.net/lists/listinfo/opensc-devel</a>
</pre>
    </blockquote>
  </body>
</html>

--------------gBOK4DZFhMXgdStqMTdHpw70--


--===============5079078647639804652==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============5079078647639804652==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Opensc-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/opensc-devel

--===============5079078647639804652==--