← All Verification IP
Smartcard / Contactless

ISO/IEC 7816

An independent clean-room ISO/IEC 7816 reader/IFD-side Bus Functional Model verifying the catalog’s iso7816_icc — an ICC/card-side responder…

Request this VIP →Browse all VIP
shippingGroup Smartcard / ContactlessStandard ISO/IEC 7816 (Contact Smart Cards)

Available now — real, tested verification collateral, not a roadmap placeholder.

Verification IP is not safety-rated. These are testbench components — no ASIL target, no FMEDA, no IP-XACT, no safety-mechanism interface. They exist to help you verify a design, not to carry a safety argument. The safety soft-IP catalog is over here.

The deliverable

What you get

Bus-functional model
An independent driver for the protocol, written clean-room from the public specification — not derived from our own RTL, so it is a genuine second source.
Passive protocol checker
A monitor that watches the bus and asserts the spec’s rules continuously, so a violation fails the run where it happens rather than downstream.
Self-checking interop testbench
A one-command testbench that drives the model against real RTL and hard-checks the result — reproduce every claim on day one.

An independent clean-room ISO/IEC 7816 reader/IFD-side Bus Functional Model verifying the catalog’s iso7816_icc — an ICC/card-side responder, analogous to how cxpi_node/smbus_slave are peripheral-role responders in this catalog. This BFM plays the reader role a real terminal implements: it owns and drives the RST contact (matching the real physical topology, where the READER controls RST, not the card) and the reader half of the modeled I/O contact, with bit-level TIMING mirrored off iso7816_icc‘s own proven-correct C++ interop reference (tb_iso7816_icc_interop.cpp‘s sendByte/recvByte, ETU_DIV=4/16x oversampling) — not derived from the DUT’s own internal RXE/TXE/card-FSM logic or either native testbench’s own BFM code. RECV_ATR captures the Answer-To-Reset (TS + body + optional hardware-computed TCK); DO_PPS drives a full PPS request (PPSS/PPS0/PPS1/PCK) and captures the card’s echoed negotiation response; SEND_T0_HEADER/RECV_PROC_BYTE/SEND_T0_DATA/RECV_T0_DATA/RECV_SW drive a T=0 byte-oriented APDU exchange (CLA/INS/P1/P2/P3, ACK/NULL procedure bytes, either data direction, SW1SW2); SEND_T1_IBLOCK/RECV_T1_BLOCK drive/capture T=1 block-oriented NAD/PCB/LEN/INF/EDC exchanges, with a bad_lrc argument for the deliberate-LRC-corruption negative test; SEND_BYTE‘s own bad_parity argument injects a corrupted parity bit on any byte. A passive protocol checker independently reconstructs every byte off the DUT’s real icc_rx/icc_tx pins with its own from-scratch oversampling/edge-detect (a level-based busy-wait for the card-driven icc_tx pin, since the card can begin responding within a couple of clock cycles of whatever provoked it — the same race every sibling OSS checker’s own header documents — vs. an edge-triggered sync for the reader-driven icc_rx pin, whose transitions this VIP’s own BFM creates deliberately and sequentially), logging every captured byte so a small set of TB-invoked structural checks can independently recompute each DUT-computed field from that log without ever re-driving or re-sampling the wire: the ATR’s hardware TCK (an XOR fold over the captured body), the PPS response’s PCK, the T=0 procedure byte’s ACK-echoes-INS correctness, and the T=1 EDC/LRC plus PCB-classification legality of every card-emitted block. Its rules are asymmetric, the same division of labor every sibling OSS checker’s own header draws: fields the CARD itself computes (its own byte parity/framing, the ATR TCK, the PPS PCK, the ACK echo, a card-emitted block’s own EDC/PCB) are unconditionally flagged as violations if wrong, while reader-driven, test-corruptible fields (a deliberately bad T=1 LRC, a deliberately corrupted byte parity bit) are independently recomputed and exposed as facts (rx_t1_lrc_ok/last_rx_par_ok) for the testbench to assert on in context, never auto-flagged. This second-source effort ran clean against iso7816_icc: 0 checker violations across a full ATR capture+parse, a PPS negotiation switching T=0->T=1, a T=0 full APDU round trip covering all three command shapes (case 3 host->card data, case 2 card->host data with a NULL wait procedure byte, case 1 SW-only), a T=1 I-block RX/TX round trip with LRC, a bad-LRC injection (the autonomous R-block NACK response independently confirmed legitimate, the reader’s own corrupted request independently confirmed bad but never auto-flagged), and a parity-error injection, with no false ASIL-B self-check trip (err_code 1/2/9) at any point. Explicitly out of scope, inherited directly from iso7816_icc‘s own v1 scope note (a VIP limitation only insofar as the paired DUT itself doesn’t implement these): T=1 block chaining (multi-block I-block sequences via the more-data M-bit) and CRC (vs. LRC), PPS2/PPS3 negotiation, ATR interface-byte (TAi/TBi/TCi/TDi) field reconstruction in hardware, and exact reconciliation of the ATR/PPS/T=0/T=1 byte-level behavior against the licensed ISO/IEC 7816-3/-4 text before real silicon integration.

Key Features

Standards & Compliance

ISO/IEC 7816 (Contact Smart Cards)

Pairs With

Built to lean against these catalog IPs during integration:

Interested in the ISO/IEC 7816 VIP?

Deliverables, the file manifest, and licensing terms are shared under a mutual NDA.

Talk to us →See related VIP

Verification IP is testbench collateral and is deliberately not safety-rated: no ASIL target, no FMEDA, and no IP-XACT descriptor. It carries no functional-safety claim.

circuit-design.space · +1-971-357-1400 · anovickis@circuit-design.space