EMVCo Common Payment Application Level 1 & Level 2 Implementation Conformance Statement
Export Form Data Import Form Data EMVCo Common Payment Application Level 1 & Level 2 Implementation Conformance Statement Version 1.0o ICS Reference Number and Validity Period (for EMVCo administrative use only) ICS Reference Number: Valid from: Valid to: Notice: This ICS form shall be completed for card products submitted for CPA Level 1 & Level 2 Functional evaluations. The form shall be completed in its entirety. All Yes and No questions shall be answered. If a feature/option is NOT supported, i.e. a question is answered “No,” the sub-questions for that feature/question shall be left blank. A
- Administrative Product Provider Identification A.1.1
- Company Legal Name: (As listed on the Letter of Registration) A.1.2 – EMVCo Registration Number: Level 1 Protocol Laboratory Identification A.1.3
- Company Legal Name: A.1.4 – EMVCo Registration Number: Level 2 Laboratory Identification A.1.5
- Company Legal Name: A.1.6 – EMVCo Registration Number: ICS Submission Type A.2.1
- Select submission type A.2.2
- For any submission except Initial, please provide the EMVCo letter of approval reference number of the previously approved product A.2.3
- Is this ICS a replacement of a previously accepted ICS? Yes No A.2.4
- If Yes. please provide the reference number of the previously accepted ICS A.2.5
- If Yes, please provide the reason for replacing the ICS A.2.6
- If Yes, please provide details of ICS replacement 19 Product Specification
References
Name Version Number Release Date Released by A.3.1
- EMV Specification EMV Integrated Circuit 4.4 Card Specifications for Payment Systems Level 1 Specifications 1.0 for Payment Systems
- EMV Contact Interface Specification A.3.5
- Other Specification(s) for Operating System A.3.6
- Other Specification(s) for non CPA application(s) A.3.7
- CPA Specification EMV Integrated Circuit 1.0 Card Specifications for Payment Systems: Common Payment Application Specification A.3.9
- EMV Card EMV 2.0 Personalization Specification (if applicable) Card Personalisation Specification Oct 2022 Oct 2022 Dec 2005 Aug 2021 Audit Report Tracking Number 19 Product and Chip Descriptions A.5.1 – Product Name: Product Version: (This is the name that will appear on the Approved Products List) A.5.2 – Who is the Card Manufacturer who will be producing the test cards being submitted for testing: A.5.3
- Chip Provider: A.5.4
- Chip Type or Identifier: A.5.5
- EMVCo IC Compliance Certificate reference number: Date: A.5.8
- Operating System Type: A.5.9
- Operating System Name and Version Number: Chip Feature
Description
A.5.10 – RAM size (Kbytes) A.5.11 – ROM size (Kbytes) A.5.12 – Total EEPROM or Flash size (Kbytes) A.5.13 – Available EEPROM or Flash size (Kbytes)* A.5.14 – CPU (8, 16 or 32 bit etc.) A.5.15 – Crypto coprocessor present? A.5.16 – RSA implementation supported by the card Name: Version Number: Yes No * Free EEPROM or Flash size available for initialization and personalization of the application(s) listed in Section A.6.1 (excluding any memory utilized for the card operating system).
19
Applications on the Card A.6.1 – CPA Application(s) and CCD Application(s) if applicable* Name Version Developer Functional Description AID(s) of all card images submitted for testing except for B7(A1a), B9(A1b), B10(A1c), B51a, and A11.x Code Loaded A.6.2 – Other Application(s) if applicable Name Version Developer Functional Description AID(s) or File ID(s) of the actual application Code Loaded * Note: For testing purposes multiple application is defined by several instances of the same or different CCD (resp CPA) application code with each instance having its own independent application life cycle – please list the AIDs for all instances of the application under the AID column. Multiple AIDs that share the same instance are not considered as multiple applications – in such a case please list only one AID for each instance of the application under the AID column. Please also specify the number of AIDs listed here in L2.3.1.
19
Applications Interaction with the CPA application A.7.1 - Do any other applications interact with the CPA application? Yes No A.7.2 - If yes, describe how each of the other applications interact with the CPA application (Data shared, functions shared). Please provide details below. Limitation on simultaneous personalization and activation of all applications listed in section A.6 A.7.3 - Is there any limitation that precludes submitting card images for testing with all applications personalized and activated simultaneously? (e.g. restriction on EEPROM size, other application selected by default, etc.) Yes No A.7.4 - If yes, please describe the limitation below. Please also list in A.7.5 and A.7.6 the original and additional multi-application configurations that will be submitted for testing. A.7.5 - Original multi-application configuration (submitted on all card images for testing): A.7.6 - Additional multi-application configurations (submitted on card images listed in the latest Card Approval Communication N°70 for non-regression testing): Additional Functionality included in the CPA application A.8.1a - Does the CPA application include any additional functionality? (e.g. additional functionality in EMV and CPA defined commands, or other examples of additional functionality in Section 19 of the CPA specification) Yes No A.8.1b - If the answer to A.8.1a is ‘Yes’ is this additional functionality activated for testing? Yes No A.8.2 - If A.8.1.a is “Yes”, please describe the additional functionality included in the CPA application. Please provide details below.
19
EMV Level 1 Electrical Characteristics L1E.1 – Sample information L1E.1.1 – EMV Contact protocol type(s) supported? L1E.2 – Card Class L1E.2.1 - Class A Supported? L1E.2.2 - Class B Supported? L1E.2.3 - Class C Supported? T=0 T=1 Yes No Yes No Yes No EMV Level 1 Protocol Characteristics L1P.1 – Answer to Reset (ATR) L1P.1.1 - Hex values (with no space and no wildcard ‘XX’) returned by the ICC in response to cold reset: (Provide the longest historical byte string the card can support) Note: Products that are exactly the same except for the ATR historical bytes may benefit from the ICS and LoA of the product tested L1P.1.1.1 – Is TA2 returned with b5 = 0 (specific mode, parameters defined by the interface bytes) in the Cold ATR? Yes No L1P.1.1.2 – Is the Cold ATR EMV Compatible? Yes No An ATR is EMV compatible when it shall be accepted by at least one generation of EMV terminals. L1P.1.1.3 – Is the Cold ATR EMV Compliant? Yes No L1P.1.2 - Hex values returned by the ICC in response to warm reset: (Provide the longest historical byte string the card can support) Transport Protocol L1P.2 – T = 0 supported? Yes No L1P.2.1 - Can the card issue procedure byte ‘60’ to request a Work Waiting Time extension? Yes No L1P.2.1.1 - If yes, can the card issue procedure byte ‘60’ to request a Work Waiting Time extension, during any command & response exchange of the payment application? Yes No L1P.2.1.1 - If Yes, describe how and where in the transaction this will occur. Please provide details below. L1P.2.1.2 - If yes, does the card issue procedure byte ‘60’ to request Yes No a Work Waiting Time extension, during ICC L1 testing?
19
L1P.3 – T = 1 supported? Yes No L1P.3.1 - Can the card issue a waiting time extension request, S (WTX request) block? Yes No L1P.3.1.1 – If yes, can the card issue a waiting time extension request, S (WTX request) block, during any command & response exchange of the payment application? Yes No L1P.3.1.1.1 - If Yes, describe how and where in the transaction this will occur. Please provide details below: L1P.3.1.2 - If yes, does the card issue a waiting time extension request, S (WTX request) block, during ICC L1 testing? Yes No L1P.3.2 - Value of IFSC L1P.3.3 - Can the ICC initiate chaining? Yes No L1P.3.3.1 - If yes, can the card initiate chaining, during any command & response exchange of the payment application? Yes No L1P.3.3.1.1 - If Yes, describe how and where in the transaction this is initiated? Please provide details below: L1P.3.3.2 - If yes, does the card initiate chaining, during ICC L1 testing? Yes No L1P.3.4 - Can the ICC by means of chaining receive a C-APDU command Yes No of length > IFSC? L1P.3.4.1 – If yes, can the ICC by means of chaining receive a C- Yes No APDU command of length > IFSC, during any command & response exchange of the payment application? L1P.3.4.1.1 - If yes, specify such C-APDU command and its response. Please provide details below: L1P.3.4.2 - If yes, does the ICC by means of chaining receive a CAPDU command of length > IFSC, during ICC L1 testing? L1P.4 – Dynamic Calculations L1P.4.1 - Can the ATR timings be impacted by any dynamic computation during the card reset? If Yes, please submit card(s) which display different timings. L1P.4.1.1 - If Yes, please provide details below: Yes No Yes No
19
Level 2 Additional Information for preparation of Level 1 test tool L1L2.1 – PSE supported? Yes No L1L2.1.1 - FCI Data: returned by card L1.L2.1.2 – List of READ RECORD Commands and Responses: Command Response L1L2.1.3 - SFI of Directory File and Record Number L1L2.2 – Direct Select supported? Yes No L1L2.2.1 - EMV Application Name: L1L2.2.2 – Is there any dynamic Yes No computations or internal check that could make variable the duration of the SELECT command? L1L2.2.2.1 - If yes, describe the worst case L1L2.2.3 –Is this EMV application implicitly selected by Cold Reset? Yes No L1L2.2.3.1 - If no, please state ADF or Name of the application implicitly selected by Cold Reset, if any: L1L2.2.4 –Is this EMV application implicitly selected by Warm Reset? Yes No L1L2.2.4.1 - If no, please state ADF or Name of the application implicitly selected by Warm Reset, if any: L1L2.3 – DYNAMIC DATA AUTHENTICATION supported? L1L2.4 – Enciphered PIN supported? Yes No Yes No L1L2.4.1- if yes, what is the max length of the private key?
19
L1L2.5 – 1st GENERATE AC L1L2.5.1 - 1st GAC Command L1L2.5.2 - Maximum Response size (depending if CDA is supported) L1L2.6 – 2nd GENERATE AC L1L2.6.1 - 2nd GAC Command L1L2.6.2 - Maximum Response size (depending if CDA is supported)
19
L2 - EMV Level 2 L2.0 - Implementer Options L2.0.1 - Is EMV CPS Personalization supported? L2.0.1a – Is SCP02 supported? L2.0.1b – Is SCP03 supported? L2.0.1b.1 – Is S8 variant supported? L2.0.1b.2 – Is S16 variant supported? L2.0.1b.3 – Are 16-bytes AES keys supported? L2.0.1b.4 – Are 32-bytes AES keys supported? L2.0.1b.5 – Is R-MAC supported? L2.0.1b.6 – Is R-ENCRYPTION supported? L2.0.2 - Is Dynamic RSA supported? L2.0.3 - Is VLP supported? L2.0.4 - Is Profile Selection Using Card Data supported? L2.0.5 - If Yes, provide a list of AIDs and specify which AID is linked to which GPO Parameter for card image B51a. (What is the value of x for DF0x in template BF3E that is associated with each AID?) Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes AID No No No No No No No No No No No No x in DF0x Note: Please define the AIDs as specified in Card Image B51a. L2.0.6 - Are Application Security Counters Yes No supported? L2.0.7 - Application Control ‘Allow Retrieval of Yes No Offline Values and Limits’ bit is significant (see note of CPA req. 12.7) L2.0.8 – Cryptogram Version supported <ct> Version & Cryptogram Confirmation L2.1 - MAC longer than 4 supported? L2.1.1 - Is MAC with length equal to 5 supported? L2.1.2 - Is MAC with length equal to 6 supported? L2.1.3 - Is MAC with length equal to 7 supported? L2.1.4 - Is MAC with length equal to 8 supported? Yes No Yes No Yes No Yes No Yes No
19
Application Selection L2.2 – PSE supported? SELECT Command L2.2.1 - FCI Maximum Length READ RECORD Command L2.2.2 - SFI value(s) for the Directory Elementary File L2.2.3 - Number of Records supported L2.2.4 - Maximum Record size (bytes per record) L2.2.5 - Minimum Record size (bytes per record) L2.2.6 - How many template ‘61’ can be loaded in Records? L2.3 – ADF L2.3.1 – How many CPA/CCD application AIDs are supported? SELECT Command L2.3.2 – FCI Maximum Length Read Application Data L2.5 – READ RECORD COMMAND L2.5.1 - [SFI 11 to 20] range supported L2.5.2 - [SFI 21 to 30] range supported L2.5.3 -List the SFI value(s) supported (all ranges) L2.5.4 - Number of Records supported L2.5.5 - Maximum Record size (bytes per record) L2.5.6 - Minimum Record size (bytes per record) Yes No Yes No Yes No
19
Public Keys (to be completed when answer to question L2.0.2 is ‘Yes’) L2.6 – Public Keys L2.6.1 - Maximum CA Public Key length L2.6.2 - Maximum Issuer Public Key length L2.6.3 - If Maximum CA key size is different from the pre-determined EMVCo test keys please provide CA public key value for testing L2.6.4 - If Maximum Issuer key size is different from the pre-determined EMVCo test keys please provide Issuer public key value for testing L2.8 – DDA L2.8.1 - Maximum ICC Public Key Length L2.8.2 - If Maximum key size is different from the pre-determined EMVCo test keys please provide ICC public key value for testing L2.8.3 - Odd Key Length supported? Modulus: Exponent: Yes No L2.9 – CDA L2.9.1 - Maximum ICC Public Key length L2.9.2 - If Maximum key size is different from the pre-determined EMVCo test keys please provide ICC public key value for testing L2.9.3 - Odd Key Length supported? L2.11 – Enciphered PIN L2.11.1 - Can the ICC Public key be different for Enciphered PIN and DDA/CDA? L2.11.2 - Can the ICC Public key be the same for Enciphered PIN and DDA/CDA? L2.11.3 - Maximum ICC Public Key length L2.11.4 - If Maximum key size is different from the pre-determined EMVCo test keys please provide ICC public key value for testing L2.11.5 - Odd Key Length supported? Modulus: Exponent: Yes No Yes No Yes No Yes No Modulus: Exponent: Yes No
19
Issuer Scripts EMV defined script commands supported by the application but not specified by CPA L2.14 – Application Block Command L2.14.1 - Supported before 2nd GEN AC? Yes No L2.14.2 - Supported after 2nd GEN AC? Yes No L2.14.3 - Second nibble range of the CLA byte (with first nibble is ‘8’) supported (different from ‘C’) L2.16 – Card Block Command L2.16.1 - Supported before 2nd GEN AC? Yes No L2.16.2 - Supported after 2nd GEN AC? Yes No L2.16.3 - Second nibble range of the CLA byte (with first nibble is ‘8’) supported (different from ‘C’) L2.18 – Additional SCRIPT Command without Secure Messaging for Confidentiality (without tag ‘87’) If the additional Issuer Script commands supported are different from those defined in CPA specification, you are required to fill in L2.18 as well as A8.2. To be CPA compliant, UPDATE RECORD and PUT DATA should not be listed. L2.18.1 – L2.18.2 - L2.18.3 - L2.18.4 - L2.18.5 - L2.18.6 List of script commands Supported before 2nd Supported after 2nd Second nibble Additional SCRIPT Can a tag that is part of a supported by the GEN AC? GEN AC? range of Command previously application as the CLA with tag personalized additional byte (with ‘81’ template be functionality first nibble supported? deleted later? is ‘8’) supported (different from ‘C’) Yes Yes Yes Yes No No No No Yes Yes Yes Yes No No No No Yes Yes Yes Yes No No No No Note: If there are more than 3 Additional SCRIPT Command without Secure Messaging for Confidentiality (without tag ‘87’), list them here and provide the information appropriate for L2.18.2, L2.18.3, L2.18.4, L2.18.5, and L2.18.6.
19
L2.19 – Additional SCRIPT Command with Secure Messaging for Confidentiality (with tag ‘87’) L2.19.1 – L2.19.2 - L2.19.3 - L2.19.4 - L2.19.5 List of script commands supported by the application Supported before 2nd Supported after 2nd Second nibble range of the Can a tag that is part of a as additional functionality GEN AC? GEN AC? CLA byte (with previously first nibble is personalized ‘8’) supported template be (different from deleted later? ‘C’) Yes Yes Yes No No No Yes Yes Yes No No No Yes Yes Yes No No No Note: If there are more than 3 Additional SCRIPT Command with Secure Messaging for Confidentiality (with tag ‘87’), list them here and provide the information appropriate for L2.19.2, L2.19.3, L2.19.4 and L2.19.5. Log L2.22 – LOG File L2.22.1a - SFI value(s) supported for the Log File (in the range 21 to 30) L2.22.1b - SFI value used in personalized cards L2.22.2a - Maximum number of records supported for each SFI indicated in L2.22.1a. (A value should be specified for each SFI supported) L2.22.2b - Maximum number of records in total supported for the Log File L2.22.3 - List the different Log Entry(s) supported and respective card image(s) other than those defined for card image A1 and B1. L2.22.4 - List the different Log Format(s) supported and respective card image(s) other than those defined for card image A1 and B1. 21 22 23 24 25 26 27 28 29 30 SFI value(s) Maximum number of records supported Log Entry(s) Card Image(s) Log Format(s) Card Image(s)
19
Specific Data L2.23 – Currency Code X L2.23.1 - What is the Currency Code X whose transactions are counted in Counter 1 for the relevant CCD card images? L2.24 – Currency Code Y L2.24.1 - What is the Currency Code Y whose amounts are cumulated in Accumulator 1 for the relevant CCD card images? L2.25 – Reference Day 0 L2.25.1 – What is the reference day 0 used (only if different from December 31, 1999)? L2.26 – SFI value for Profile Selection File L2.26.1 –SFI value(s) supported for the Profile Selection File in the range (21 to 30)? L2.26.2 – SFI value used in personalized cards L2.27 – Issuer Country Code L2.27.1 – What is the Country Code that is personalized on the cards submitted for testing? L2.28 – Currency Code for Accumulator 2 L2.28.1 – What is the Currency Code whose amounts are accumulated in Accumulator 2? 21 22 23 24 25 26 27 28 29 30 Other CCD compliant related functions L2.29 – Proprietary Authentication Data (greater than zero) supported L2.29.1 - What is (are) the length(s) supported? L2.29.2 - Can it be included in the ARPC calculation (CSU Byte 1 bit 8 supported)? L2.29.3 - What is (are) the Proprietary Authentication Data Value(s), or how it is calculated? L2.30 – Non EMV Commands L2.30.1 - Does the CPA Application support Non EMV Commands? (other than Proprietary Script Commands) L2.30.2 - Please list all supported pairs of CLA/INS L2.31 – VERIFY Command L2.31.1 - NON CPA P2 byte value(s) supported (different from ‘80’ and ‘88’) Yes No Yes No Yes No
19
Maximum Number of Profiles supported L2.40 – PROFILES L2.40.1 - How many Profiles can be supported (Maximum number of Profile Control entries in template BF3F)? L2.40.2 – How many Profiles can be supported when each profile is configured according to the rules for the default card image configuration B1, each N = minimum number/length required to be supported in the CCD/CPA Specifications, and all the data is shared between instances if multiple instances are supported? Maximum Allocated Size (higher than the Minimum defined in the CPA specification) L2.41 – Maximum Allocated Size L2.41.1 - Single Additional Check Table L2.41.1a - Single Additional Check Table length in bytes bytes L2.41.1b – Additional Check Table Comparison Data Length in bytes L2.41.1c – Number of Comparison Blocks for an Additional Check Table (with Comparison Data Length equal to ‘01’) L2.41.2 - Single Currency Conversion Table in number of currencies bytes Blocks currencies L2.41.3 - Number of AIP/AFL Entries L2.41.4 - GPO Input Data Length in bytes entries bytes L2.41.5 - Profile Selection Entry Comparison L2.41.5a - Profile Selection Entry Comparison Block Length in bytes L2.41.5b – Maximum number of comparison blocks for one Profile Selection Entry (Number of blocks without Bit Mask) L2.41.6 - Profile Selection File record number with each (Profile Selection Entry) record length greater than 30 bytes L2.41.7 - First GENERATE AC Extension Data length in bytes bytes Blocks records bytes L2.41.8 - First GEN AC Unchanging Log Data Table number of Data Entries L2.41.9 – Length of data extracted from First GEN AC command data for Transaction Logging using First GEN AC Unchanging Log Data Table (byte 2 of a Data Entry) L2.41.10 - First GEN AC Log Data Table number of Data Entries entries bytes entries L2.41.11 - Length of data extracted from First GEN AC command data for Transaction Logging using First GEN AC Log Data Table (byte 2 of a Data Entry) bytes
19
L2.41.12 - Second GEN AC Log Data Table number of Data Entries L2.41.13 - Length of data extracted from Second GEN AC command data for Transaction Logging using Second GEN AC Log Data Table (byte 2 of a Data Entry) L2.41.14 - Second GENERATE AC Extension Data in bytes L2.41.15 - Total size in bytes of all EMV Records L2.41.16 - Number of EMV Records L2.41.17 - Number of Log Records L2.41.18 - Number of AIDs supported for a single CPA application entries bytes bytes bytes records records AIDs Specific Data Elements L2.42 – Can These Data be not personalized? L2.42.1 - Accumulator 2 and Counter 2/3, Cyclic Accumulator 2, Additional Check Table 2 (CPA req. 21.12) Yes (personalization may omit one or more of these data) No (personalization must include all of these data, even if the condition in Table 21-9 is not met) L2.43 – Does the card Application allow personalization without these data? L2.43.1 - GPO Parameter 1 Yes No L2.43.2 - Profile Control template Yes No L2.43.3 - Application Control Yes No L2.43.4 - CIACs Entries template Yes No L2.43.5 - Accumulator Controls template Yes No L2.43.6 - Accumulator 1 Control Yes No L2.43.7 - Accumulator Profile Controls template Yes No L2.43.8 - Counter Controls template Yes No L2.43.9 - Counter Profile Controls template Yes No L2.43.10 - Cyclic Accumulator Controls template Yes No L2.43.11 - Cyclic Accumulator 1 Control Yes No L2.43.12 - Cyclic Accumulator Profile Controls template Yes No L2.43.13 - Issuer Country Code Yes No
19
L2.43.14 - Application Currency Code L2.43.15 - Additional Check Table template L2.43.16 - Number of Days Offline Limit L2.43.17 - AIP/AFL Entries template L2.43.18 - Issuer Options Profile Controls template L2.43.19 - MTA Profile Controls template L2.43.20 - Accumulator 1 Limit Set 1 L2.43.21 - Counter 1 Limit Set 1 L2.43.22 - Limit Entries template L2.43.23 - Currency Conversion Tables template L2.43.24 - Currency Conversion Table entry 1 L2.43.25 – Counter 1 Control L2.43.26 – Additional Check Table 1 Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No EMV CPS personalization (to be completed when answer to question L2.0.1 is ‘Yes’) L2.44 – KMC keys L2.44.1 - Can the Card support multiple KMC keys? Yes No L2.45 – DGIs L2.45.1 - CPA recommended DGI supported? L2.45.2 - Can the DGIs be loaded in any order? Yes No Yes No L2.45.3 - If not please define for each DGI that can not be loaded in any order:
- the DGI
- any DGI’s that must be loaded prior
- any DGI’s that must be loaded later L2.46 - Does the CPA Application support Non CPS Commands (before personalization)? L2.46.1 - Please list all supported pairs of CLA/INS (when CLA byte has one of the following values: ‘00’, ’04, ‘08’, ‘0C’, ‘80’, ‘84’ ‘88’, ‘8C’, ‘9x’ or ‘Ex’) Yes No Issuer Options L2.47 – Proprietary format of IAD byte 19-32 supported Yes No 19 Digital Signatures Product Provider I agree and understand that the cards submitted for Functional Level 1, Functional Level 2 and Security Evaluation testing are exactly the same. Also if an issue requires a change to the code of the card or the addition of a patch or new executable code to the card, EMVCo must be notified. In case of such change, new cards must be submitted for Functional Level 1 and Functional Level 2 and Security Evaluation testing. I hereby declare that the above referenced product currently is and will remain in compliance with the above referenced EMV specification for all mandatory and supported optional requirements. Comments Signature Level 1 Laboratory I hereby declare that this ICS document has been reviewed, and that all product information is consistent throughout the ICS. Comments Signature Level 2 Laboratory I hereby declare that this ICS document has been reviewed, and that all product information is consistent throughout the ICS. Comments Signature EMVCo Approval Secretariat Signature 19