BS ISO IEC 7816-4-2020 + A1-2023 PDF
Name in English:
STB BS ISO IEC 7816-4-2020 + A1-2023
Name in Russian:
СТБ BS ISO IEC 7816-4-2020 + A1-2023
Original standard BS ISO IEC 7816-4-2020 + A1-2023 in PDF full version. Additional info + preview on request
Full title and description
STB BS ISO IEC 7816-4:2020 + A1:2023 — Identification cards — Integrated circuit cards — Part 4: Organization, security and commands for interchange (Edition 4, 2020) with Amendment 1 (2023) adding support for multiple logical security devices. This combined product page covers the international ISO/IEC base standard and its 2023 amendment as published by ISO/IEC (and commonly released/adopted by national bodies under prefixes such as BS and STB).
Abstract
Specifies the organization, security architecture and command-response mechanisms (APDU structure and semantics) used for interchange with integrated circuit cards (smart cards). It defines file and application structures visible at the interface, data object encodings (TLV), access methods to files and on-card algorithms, application identification and addressing, secure messaging and access rights. The amendment (A1:2023) introduces support for multiple logical security devices. The document is interface-technology independent and applies to contact, close-coupling and radio-frequency cards.
General information
- Status: Published (international standard and published amendment).
- Publication date: ISO/IEC 7816-4: May 2020; Amendment 1 (A1:2023): October 2023 (national adoptions such as BS ISO/IEC 7816-4:2020+A1:2023 were published by some bodies in late 2023).
- Publisher: International Organization for Standardization (ISO) in cooperation with the International Electrotechnical Commission (IEC), developed by ISO/IEC JTC 1/SC 17 (Cards and security devices for personal identification).
- ICS / categories: 35.240.15 (Identification cards; chip cards; biometrics / security devices).
- Edition / version: Edition 4 (2020) with Amendment 1 (2023).
- Number of pages: Base standard: 176 pages; Amendment A1:2023: 3 pages. (Some national consolidated publications that combine the base text and amendment may show slightly different total page counts when re-published as a single document.)
Scope
Defines the command-response syntax and semantics (APDUs), data object formats and TLV encodings, file and application structures visible at the card interface, methods for accessing files and on-card algorithms, an on-card security architecture including access rights and secure messaging, and mechanisms for identifying and addressing applications. It applies to integrated circuit cards accessed by contacts, close coupling or radio frequency and does not prescribe internal card implementations or the concrete cryptographic algorithms. The 2023 amendment extends the standard to support multiple logical security devices.
Key topics and requirements
- APDU structure and command-response pairs: class byte, instruction byte, parameters, data field handling, and status words.
- Data objects and TLV encodings (SIMPLE-TLV and BER-TLV) and rules for primitive vs constructed objects.
- File and application structures at the interface level (file control information, life-cycle status, instance identification).
- Access methods to files and data and defined security attributes for file access.
- Security architecture for access rights, authentication, and secure messaging (secure channel protocols are referenced but crypto algorithms are not specified).
- Application identification and addressing (AIDs) and application life-cycle management.
- Support for multiple logical security devices (added by Amendment A1:2023).
- Requirements for chaining/fragmentation of large data exchanges and status word semantics for error and processing conditions.
Typical use and users
Used by smart-card manufacturers, payment scheme architects, mobile SIM and eSIM developers, government eID and e-passport implementers, access control and transport-card integrators, system integrators, software developers implementing client readers and middleware, test and certification laboratories, and standards/QA teams seeking compliance with international smart-card interchange behaviour.
Related standards
Part of the ISO/IEC 7816 series — related parts include (non-exhaustive): ISO/IEC 7816-1 (physical characteristics), -2 (cards with contacts — dimensions and location of contacts), -3 (electrical interface and transmission protocols), -8 (commands and mechanisms for security operations), -9 (commands for card and reader interactions), -11 (biometric verification), and other parts of the 7816 family. It also interoperates in practice with contactless standards such as ISO/IEC 14443 where APDU-level semantics are required.
Keywords
Integrated circuit cards, smart cards, APDU, command-response, TLV, data objects, file structure, application identifier (AID), secure messaging, access rights, logical security device, ISO/IEC 7816-4, amendment A1:2023.
FAQ
Q: What is this standard?
A: ISO/IEC 7816-4:2020 is Part 4 of the ISO/IEC 7816 series covering organization, security and commands for interchange with integrated circuit (smart) cards. Amendment A1:2023 adds support for multiple logical security devices.
Q: What does it cover?
A: It covers APDU formats and behaviours, data object encodings (TLV), file and application structures visible at the card interface, access methods, an on-card security architecture, application addressing and secure messaging. It does not specify internal implementations or specific cryptographic algorithms.
Q: Who typically uses it?
A: Card manufacturers, payment system vendors, mobile network operators (SIM/eSIM), eID and government document authorities, access-control integrators, reader/middleware developers, conformity testing labs and certification bodies.
Q: Is it current or superseded?
A: The Edition 4 document dated May 2020 is the current base standard; Amendment 1 was published in October 2023. Earlier editions (for example the 2013 edition) have been withdrawn and replaced by the 2020 edition. Check national bodies for consolidated/adopted national publications (e.g., BS editions) for exact national status.
Q: Is it part of a series?
A: Yes — it is one part of the ISO/IEC 7816 series (identification cards — integrated circuit cards), which includes multiple parts addressing physical interfaces, commands, security operations, biometrics and other topics.
Q: What are the key keywords?
A: APDU, smart card, integrated circuit card, TLV, AID, secure messaging, file structure, access rights, logical security device, ISO/IEC 7816-4, amendment A1:2023.