Overview
ISO/IEC 24727-1:2014 defines the architecture for programming interfaces that enable interactions between integrated circuit cards (ICCs or smart cards) and applications on diverse computer platforms. Part 1 sets out system principles, conceptual service and data models, and the rationale for trusted operations that enable interoperability across multiple application domains while maintaining backward compatibility with pre-existing systems. The standard assumes ICC organization/operation conforming to ISO/IEC 7816-4.
Key topics and technical requirements
- System architecture & principles of operation: Partitioning of functionality between a client-application (host) and card-applications (on ICCs); definition of layers and interfaces required for a protocol stack.
- Interoperability mechanisms: Common architecture, common semantics, formally defined interfaces, discoverability, extensibility, backward compatibility and conformance testing.
- Service and data models: Conceptual models for services, named data sets, data elements and data structures for interoperability; access to data sets controlled by access control lists (ACLs).
- Interfaces and layers:
- Service access layer (SAL) and SAL-lite: APIs for client-applications (detailed in ISO/IEC 24727-3).
- Generic card interface: Definition of a generic card access layer (detailed in ISO/IEC 24727-2).
- Connectivity and trusted channel interfaces: Mechanisms for communication and secure channels (further specified in Parts 3 and 4).
- Protocol independence and formal descriptions: Interfaces are specified using ASN.1 (with XML subordinate descriptions) so implementations remain independent of underlying transport protocols.
- Capability description & discoverability: ICCs provide capability descriptions to support discovery of supported services and features.
- Proxy-agent mechanism: Splits stack element implementation between proxy and agent locations while preserving interoperability.
- Security rationale: Principles supporting trusted Identification, Authentication and Signature (IAS) operations.
Applications and who uses it
ISO/IEC 24727-1 is aimed at:
- Smart card system architects and solution designers building interoperable ICC ecosystems.
- Middleware and API vendors implementing SAL, generic card interfaces or SAL-lite components.
- Government, identity management and PKI projects requiring trusted IAS (identification, authentication, signature) services across platforms.
- Card manufacturers and integrators needing to expose capability descriptions and conform to ISO/IEC 7816-4 semantics.
- Test houses developing conformance testing per ISO/IEC 24727-5.
Practical applications include multi-application smart cards for eID, e-government, secure authentication, digital signatures and cross-platform middleware deployments.
Related standards
- ISO/IEC 24727 (complete series: Parts 2–6 cover generic card interface, application interface, API administration, testing, registration authority)
- ISO/IEC 7816-4 (ICC organization, security and APDUs)
- ISO/IEC 7498-1 / ITU-T X.200 (OSI reference model principles)
ISO/IEC 24727-1:2014 is essential reading for anyone designing interoperable smart-card programming interfaces, middleware, or trusted multi-domain ICC services.