SB nº 312: CPS DGIs for Block Cipher Key Personalisation
EMV® Specification Bulletin No. 312 First Edition May 2025 EMV® CPS DGIs for Block Cipher Key Personalisation
Applicability
This Specification Bulletin applies to:
- EMV Card Personalisation Specification (EMV CPS), v2.0, August 2021
Related Documents
- EMV Specification Bulletin No. 281 – EMV CPS DGIs for AES Key Personalisation, May 2023
Effective Date
- 1 January 2026
Description
This Specification Bulletin introduces new DGIs in the EMV CPS to avoid ambiguities inherent when applications rely on 8-byte boundaries to interpret symmetric algorithm key lengths during personalisation. Currently EMV personalisation structures need to be tightly coupled to their target EMV applications as regards cryptographic algorithms and key lengths. This addendum to EMV CPS enables recognition by an application of the algorithm and associated key length to be personalised into the application. The new DGIs unambiguously specify the key lengths and identify the matching symmetric algorithms. This can support the growing transition from DES to AES (all key lengths) and other 16-byte block ciphers, where different key length options for AES make it harder to determine what keys are personalised without explicitly identifying the length of each key. The EMV application does need to know the order in which multiple keys used for different functionality are personalised, as EMV applications might use symmetric block ciphers for:
- Application Cryptograms
- Secure Messaging for Integrity
- Secure Messaging for Confidentiality
- Other e.g. ICC Dynamic Number generation Typically, separate card level Master Keys are used for each of these functions, and different Master Keys might be used for the contact and contactless interfaces. The “Other” category recognises that some EMV applications might have additional symmetric block cipher requirements and consequently additional Master Keys would be personalised. Specification Changes Additions are identified using blue text. Modify the second requirement in section 3.2 Creation of Data Groupings as follows: CONFIDENTIAL. countries. 2. Except for DGI '8005' and DGI '8006', DES keys must be placed in a data grouping that consists of only DES keys. More than one data grouping of DES keys may be created. Except for DGI '8005' and DGI '8006', AES keys must be placed in a data grouping consisting only of AES keys. More than one data grouping of AES keys may be created. In Table A-1 in Annex A.2, insert the rows listed below: Table A-1 Data Grouping Identifiers for Payment Applications DGI '00C5' Data Content Meta Data For '8005' (Algorithm Identifier & Key Length pairs, in the order the keys are listed in '8005'). Algorithm Identifier is '80' for DES & '88' for AES. Key Length is a one-byte binary field specifying the length of the key in bytes. Function Descriptor Encrypt External Access No None '00C6' Meta Data For '8006' (Algorithm Descriptor No Identifier & Key Length pairs, in the order the keys are listed in '8006'). Algorithm Identifier is '80' for DES & '88' for AES. Key Length is a one-byte binary field specifying the length of the key in bytes. None '8000' Block cipher (DES/AES) keys – Table CAM* Yes A-2 / Issuer Auth/ Issuer Script None '8002' Block cipher (AES) keys – Table A-2a CAM* Yes / Issuer Auth/ Issuer Script None '8005' Block Cipher Keys Unpadded – Table CAM* Yes A-2b / Issuer Auth/ Issuer Script/ Other None '8006' Block Cipher Keys Padded – Table A- CAM* Yes 2c / Issuer Auth/ Issuer Script/ Other None '9000' Block cipher (DES/AES) Key Check Values – Table A-3 No None '9002' Block cipher (DES/AES) Key Check Values – Table A-3a No None '9005' Block Cipher Key Check Values according to '00C5'/'8005' – Table A3b No None countries. DGI '9006' Data Content Block Cipher Key Check Values according to '00C6'/'8006' – Table A-3c Function Encrypt External Access No None After Table A-2a, add the following new tables: Table A-2b Data Content for DGI '8005' Req. Tag Data Element Length Encrypt C N/A List of keys as indicated in DGI '00C5' 16, 32, 48, KDEK (without padding) … (SCP03) Key function and order are defined by each application and are outside the scope of this specification. Table A-2c Data Content for DGI '8006' Req. Tag Data Element Length Encrypt C N/A List of keys as indicated in DGI '00C6' 16, 32, 48, KDEK followed by 8 bytes of random padding … (SCP03) Key function and order are defined by each application and are outside the scope of this specification. After Table A-3a, add the following new tables: Table A-3b Data Content for DGI '9005' Req. Tag O N/A Data Element Key Check Values for card keys stored in DGI '8005', in the order the keys are listed in '8005' Length 3, 6, 9, … Encrypt N/A Req. Tag O N/A Table A-3c Data Content for DGI '9006' Data Element Key Check Values for card keys stored in DGI '8006', in the order the keys are listed in '8006' Length 3, 6, 9, … Encrypt N/A countries.
Legal Notice
The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications
countries.