KL Bulletin nº28: EMVCo Annual RSA Key Lengths Assessment
Notice Bulletin No. 28 July 2024 EMV SWG NN73r4 EMVCo Annual RSA Key Lengths Assessment EMVCo, LLC (“EMVCo”) has completed its annual review of the Certification Authority Public Key lengths and expiry dates and makes the following recommendations to EMV®-based payment systems:
- 1408-bit keys are recommended to have an expiry date of 31 December 2024.
- 1984-bit keys are recommended to have an anticipated lifetime to at least 31 December 2034. EMVCo does not project beyond a 10-year horizon.
- No certificate should be issued that expires later than the expiry date of the CA key. Payment systems will decide individually whether to adopt the recommendations made in this Bulletin and will notify their members of their final decision. ECC Keys As noted in Book 2 v4.4 and Book E, ECC keys may be introduced into terminals. EMVCo makes the following recommendations to EMV®-based payment systems regarding new ECC payment system keys:
- 256-bit and 521-bit ECC keys are recommended to have an anticipated lifetime beyond 31 December 2034. Although EMVCo does not project beyond a 10-year horizon, in general 256-bit ECC keys are considered much more robust than 1984-bit RSA keys.
- No certificate should be issued that expires later than the expiry date of the CA key. Furthermore, it is expected that 521-bit ECC keys will be used for contingency only. Payment systems will decide individually whether to adopt the recommendations made in this Bulletin and will notify their members of their final decision. © 1994-2024 EMVCo, LLC. All rights reserved. Any and all uses of the EMV Specifications shall be permitted only pursuant to the terms and conditions of the license agreement between the user and EMVCo found at www.emvco.com. EMV® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries.