SB n° 306: Update to Book C-6
EMV® Specification Bulletin No. 306 First Edition June 2024 Updates to EMV® Contactless Book C-6 – Kernel 6 Specification This Specification Bulletin updates the Terminal Action Analysis flow in Book C-6.
Applicability
This Spec Bulletin applies to:
- EMV Contactless Specifications for Payment Systems, Book C-6 – Kernel 6 Specification, Version 2.10, March 2021
- EMV Contactless Specifications for Payment Systems, Book C-6 – Kernel 6 Specification, Version 2.11, June 2023
Related Documents
- None
Effective Date
- Immediate
Description
This specification bulletin updates the Terminal Action Analysis flow in Book C-6, Kernel 6 Specification, to always check the Terminal Verification Results Byte 1 bit 8 when offline data authentication is required. Updates are highlighted in blue. Removals are highlighted in red with a strikethrough. Proposed Specification Changes
countries.
In Book C-6 section 3.9, update the ‘No’ branch for step 3 in Figure 3-19 “Terminal Action Analysis Process (Validate Choice)” and in its actions-table as follow: Validate Choice (1) TTQ B2b8 = Yes (‘Online cryptogram required ? No (2) CID indicates TC? Yes No Declined Outcome (3) CID indicates Yes ARQC? No (4) Deferred Authorization Supported? Yes No Online Request Outcome (5) TVR B1b8 = (‘ODA was Yes performed No (6) TVR B1b3 = Yes (‘CDA Failed ? No Declined Outcome (7) Usage Control Checks Skipped set Yes to No Approved Outcome (offline authorization) # Description 1 Kernel shall verify if an online cryptogram is required [TTQ B2b8 = ‘1’ (Online Cryptogram required)]. If… Then… Yes Go to Step 2. No Go to Step 3.
countries.
# Description 2 Kernel shall verify if the CID indicates TC based on the CID setting [i.e., CID B1b8-7 to ‘01’ (01 = TC)].
- If the card has approved the transaction when the Kernel asked to go online (i.e., the CID indicates TC), the Kernel shall send a ‘Declined’ Outcome (End the Terminal Action Analysis).
- Else, go to Step 4. 3 Kernel shall verify if the card requests an online authorization (i.e., CID indicates ARQC, with CID B1b8-7 = ‘10’). If… Then… Yes Go to Step 4. No Go to Step 65. 4 Kernel shall verify if it is configured for Deferred Authorizations (true if Deferred Authorization Supported flag is present and set to ‘1’).
- If it is not configured for Deferred Authorizations, the Kernel shall send an ‘Online Request’ Outcome (End the Terminal Action Analysis).
- Else, go to Step 5. 5 Kernel shall verify that Offline Data Authentication (ODA) was performed (TVR B1b8 = ‘0’).
- If ODA was not performed, the Kernel shall send a ‘Declined’ Outcome (End the Terminal Action Analysis)
- Else, go to Step 6. 6 If the transaction is not sent online and the CDA check is not equal to ‘1` [(TVR B1b3 = ‘0’ (CDA did not fail)], the Kernel shall approve the transaction offline with ‘Approved’ Outcome, (End the Terminal Action Analysis). Else the Kernel shall decline the transaction with ‘Declined’ Outcome. 7 Kernel shall check if the application usage control checks were skipped (‘Usage Control Checks Skipped’ is set to ‘1’).
- If ‘Usage Control Checks Skipped’ is set to ‘1’, then the Kernel shall decline the transaction
- Else, the Kernel shall approve the transaction offline countries.
Legal Notice
The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications
countries.