EMV® QR Code Self-Evaluation: Consumer Presented Test Cases
EMV<sup>®</sup> QR Code Self-Evaluation Consumer Presented Test Cases Version 1.2 November 2020 EMV<sup>®</sup> QR Code Self-Evaluation Consumer Presented - Test Cases v1.2
Legal Notice
This document summarizes EMVCo’s present plans for evaluation services and related policies and is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or non-infringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document. QR Code is a registered trademark of DENSO WAVE.
v1.2
QC1.002. QC1.003. QC1.004. QC1.005. QC1.006. QC1.007. QC1.008. QC1.009. QC1.010. QC2.001. QC2.002. QC2.003. QC2.004. QC2.005. QC2.006. QC2.007. QC2.008. QC2.009. QC2.010. QC2.011. QC2.012.
v1.2
QC2.012.01 QC2.013.00 QC2.014.00 QC2.015.00 QC2.016.00 QC2.017.00 QC2.018.00 QC2.019.00 QC2.020.00 QC2.021.00 QC2.022.00 QC2.023.00 QC2.024.00 QC2.025.00 QC2.026.00 QC2.027.00 QC2.028.00 QC2.029.00 QC2.030.00 QC2.031.00 QC2.032.00 QC2.033.00 QC2.034.00 QC2.035.00 QC2.036.00 QC2.037.00 QC2.038.00 QC2.039.00 QC2.040.00 QC2.041.00 QC2.042.00 QC2.043.00 QC2.044.00 QC2.045.00 QC2.046.00 QC2.047.01 QC2.047.02 QC2.047.03 QC2.047.04 QC2.047.05 QC2.047.06 QC2.048.
v1.2
QC3.001. QC3.002. QC3.003. QC3.004. QC3.005. QC3.006. QC3.007. QC3.008. QC3.009. QC3.010. QC3.011. QC3.012. QC3.013. QC3.014. QC3.014. QC3.015. QC3.016. QC3.017. QC3.018. QC3.019. QC3.020. QC3.021. QC3.022. QC3.023. QC3.024. QC3.025. QC3.026. QC3.027. QC3.028. QC3.029. QC4.001. QC4.002. QC4.003. QC4.004. QC4.005. QC4.006. QC4.007. QC4.008. QC4.009.
v1.2 Revision Log Version 1.2 – November 2020 The following changes have been made from version 1.1. Implements new bulletins:
- [SB 206]
- [SB 236] Changes:
Applicability
Options: Add "APPLICATION_SELECTION"
- QC1.004.00 – Correct the test pass criteria. Transparent data length
- QC2.006.00 – Correct the QR Code PAN instead of T2Eq
- QC2.007.00 – Correct the test name / QR Code Template 64
- Update Track 2 Equivalent Data Value:
- QC2.008.00
- QC2.009.00
- QC2.010.00
- QC2.011.00
- QC2.017.00
- QC2.018.00
- QC2.048.00
- QC4.002.00
- QC4.006.00
- Correct the non-matching AID – Replaced with 'A00000000F'
- QC2.012.00
- QC2.013.00
- QC2.014.00
- QC2.015.00
- QC2.024.00
- QC2.030.00
- QC2.014.00 – Correct the QR Code name
- QC2.015.00 – Correct the QR Code Template 62
- QC2.016.00 – Correct the Test objective / QR AID and PAN
- QC2.038.00 – Correct the QR Code name
- Correct the applicability typo
- QC2.039.00
- QC2.040.00
- QC2.041.00
- QC2.042.00
- QC2.043.00
- QC2.044.00
- QC2.045.00
- QC2.046.00
- QC2.047.00 – Remove test
- Add test (notable languages):
- QC2.047.01
- QC2.047.02
- QC2.047.03
- QC2.047.04
- QC2.047.05
- QC2.047.06
- QC3.006.00 – Correct the test objective / QR Code add 2nd template
- QC3.007.00 – Correct the test objective / QR Code add 2nd template
- QC3.009.00 – Correct the QR Code PAN v1.2
- QC3.010.00 – Correct the Test Conditions / QR Code name and PAN
- QC3.014.00 – Modified – Implement [SB 236]
- QC3.014.01 – Added – Implement [SB 236]
- QC3.016.00 – Correct the Test and QR Cardholder name
- QC3.017.00 – Correct the test – Case 1 Update PAN
- QC3.018.00 – Correct the test – Case 1 Update PAN
- QC3.021.00 – Correct the test – Case 1 Update PAN
- QC3.022.00 – Correct the test – Case 1 Update PAN
- QC3.022.00 – Correct the QR Code – Case 2 4F -> 5A
- QC3.026.00 – Correct the QR Code template 63 -> 62 and name
- QC3.027.00 – Correct the QR Code – template and PAN
- QC3.028.00 – Correct the QR Code – template and PAN
- QC4.002.00 – Correct the test – T2Eq pan and padding
- QC4.003.00 – Correct the test – Remove 57 in description
- QC4.004.00 – Correct the test – Update QR Code reference name
- QC4.007.00 – Correct the QR Code – Remove cardholder name
- QC4.008.00 – Correct the QR Code – Remove Application Label
- QC4.009.00 – Added – Implement [SB 206] Version 1.1 – July 2018 The following changes have been made from version 1.0. Few values inserted in this document were truncated (253 characters). Affected only the test description. "Issuer URL" updated for tests: - QC2.013.00 - QC2.026.00 - QC2.027.00 - QC2.028.00 - QC2.029.00 - QC2.030.00 "Transparent Data" updated for tests: - QC2.014.00 - QC2.015.00 - QC2.020.00 - QC2.021.00 - QC2.022.00 - QC2.023.00 - QC2.024.00 QR code image table was updated to correct the non-matching names. v1.2 1
Scope
The present document describes a set of test cases which when applied to the POI, are designed to determine whether the POI Application meets the requirements stated in [EMV QRCPS]. Test cases are defined for unitary tests that are performed with presence of a valid POI payment application. The tests focus on the following areas:
- EMV QR Code processing: the tests ensure the POI Application correctly interprets the Data Objects, performs the AID selection and builds the POI data and Transparent Data according to the specifications
- Transaction processing: the tests ensure the POI Application correctly builds the Output data to be transmitted to the network. POI displayed messages and receipts are also verified. If any special conditions are required for a specific test case, these conditions are described in the test case. The intended audience for this document is laboratories, POI application providers, acquiring members or merchants. Although acquiring members and merchants may reference this document, testing is oriented toward EMV POI application providers. v1.2 2 Referenced Documents [EMV QRCPS] [SB 206] [SB 236] [Guidelines] [ISO 18004] [ISO 8825] [ISO 8859-1] [ISO 13239] [RFC 4648] [RFC 2396] [RFC 3966] EMV® QR Code Specification for Payment Systems (EMV QRCPS) Consumer-Presented Mode - Version 1.0 - July 2017 EMV® Specification Bulletin No. 206 – First Edition July 2018 EMV® Specification Bulletin No. 236 – First Edition January 2020 Consumer Presented Test Plan Guidelines - v0.2 ISO/IEC 18004:2000. Information technology—Automatic identification and data capture techniques — QR Code bar code symbology specification ISO 8825: ASN.1 encoding rules: Specification of Basic Encoding Rules (BER), Canonical Encoding Rules (CER) and Distinguished Encoding Rules (DER) ISO/IEC 8859-1: 8-bit single-byte coded graphic character sets -- Part 1: Latin alphabet No. 1 ISO/IEC 13239: Information technology — Telecommunications and information exchange between systems — High-level data link control (HDLC) procedures IETF RFC 4648: The Base16, Base32, and Base64 Data Encodings IETF RFC 2396: Uniform Resource Identifiers (URI): Generic Syntax IETF RFC 3966: The tel URI for Telephone Numbers v1.2 3 Abbreviations and Notations BER ECI EMV ISO LEN PAN PAR T2Eq TLV TRID Basic Encoding Rules. Extended Channel Interpretation A term referring to certain technical specifications developed and maintained by EMVCo and/or technologies conforming to such specification International Organization for Standardization Length Payment Account Number Payment Account Reference Track 2 Equivalent Data Tag-Length-Value, a data structure described by BER encoding Token Requestor Identifier v1.2 4 Global Glossary Authorization- The process by which a properly appointed person or persons grants permission to perform some action on behalf of an organization. This process assesses transaction risk, confirms that a given transaction does not raise the account holder's debt above the account's credit limit, and reserves the specified amount of credit. (When a merchant obtains authorization, payment for the authorized amount is guaranteed - provided that the merchant followed the rules associated with the authorization process.) Basic Encoding Rules - The format for Basic Encoding Rules specifies a self-describing and selfdelimiting format for encoding ASN.1 data structure Byte - 8 bits. Cardholder - An authorized holder of a payment card supported by an issuer. EMVCo - The limited liability company organized to facilitate worldwide interoperability and acceptance of secure payment transactions. Extended Channel Interpretation – QR Code Parameter that allows the output data stream to have interpretations different from that of the default character set. Interoperability - The ability of the software and hardware from different interface module (IFM) providers to work together. Laboratory - A facility that performs type approval testing.. Magnetic Stripe - The stripe containing magnetically encoded information. Merchant - A seller of goods, services, and/or information who accepts payment for them electronically, and may provide selling services and/or electronic delivery of items for sale (e.g., information). Message - A string of bytes sent by the terminal to the card or vice versa, excluding transmissioncontrol characters. Network - A collection of communication and information processing systems that may be shared among several users. Nibble - The four most significant or least significant bits of a byte. Padding - Appending extra bits to either side of a data string. Payment System - For the purposes of this specification, American Express, Discover, JCB, MasterCard, UnionPay or Visa. Point Of Interaction (POI) – Terminal hosted by Merchant which provides several kinds of services like payment or fidelity. POI Application – Application developed by the POI application provider to process the base64 encoded QR Code payload defined in [EMV QRCPS]. Primary Account Number (PAN) - The assigned number that identifies the card issuer and cardholder. This account number is composed of an issuer identifier, an individual account number identification, and an accompanying check digit, as defined by ISO 7812-1985. QR Code – A type of matrix barcode (or two-dimensional barcode) known as a ‘QR Code.’ v1.2 Reference specification - A set of documents defining the requirements to which the interface module (IFM) shall comply. The reference specification consists of the current EMV Integrated Circuit Card Specification for Payment Systems and any additional documentation required to proceed with type approval. Self-Evaluation – Process which does not imply EMVCo nor accredited instances to ensure compliance of the System Under Test to the specification. System under test (SUT) - System, module, part, or component actually tested or to be tested (either a part of the terminal or the entire terminal) including the implementation under test (IUT). Template - Value field of a constructed data object, defined to give a logical grouping of data objects. Terminal - The device used in conjunction with the ICC at the point of transaction to perform a financial transaction. It incorporates the interface device and may also include other components and interfaces such as host communications. Test - Any activity that aims at verifying the conformance of a selected product or process to a given requirement under a given set of conditions. v1.2 5 Self-Testing Procedure Self-Testing EMVCo enables self-testing process for this test plan. As EMVCo is not involved in the testing process, it cannot guaranty any claimed compliance results and therefore does not provide any certification for [EMV QRCPS] implementations. This document specifies procedures and requirements as guidelines to be followed by the tester. In the context of self-testing they may be adapted or transformed, however, the tester is highly advised to follow the hereby recommendations. Testing Procedure The tester should ensure that the following rules are observed:
- The test environment complies with the pre-requisites described in section Test Environment
- Presented QR Codes images are the ones from this document in section QR Codes.
- Supported and unsupported Applicability Options described in Section Test Structure shall be provided by the POI App manufacturer.
- Run all the applicable tests listed in the section ‘Test Cases’, using the referenced QR images. Results Terminal configuration, test case results and logs of all tests executed should be stored. If applicable, the logs may include tester actions and observations, terminal output messages, ticket receipts, network messages, and verdict for each test case. v1.2 6 Test Environment Terminology Host: means real host or host simulator POI (point of interaction): in this document, the POI is considered to be the system under test, that is the POI Application Output data: Data that is sent by the POI to the Host (e.g.: POI data and Transparent data) Architecture The POI is hosting the POI App (under test) and read the QR Code data through a QR Code reader. POI is connected to a host (or host simulator) to exchange authorization messages. Figure 1: Testing Architecture POI Minimum Test Requirements The minimum requirements for the test cases defined in this document shall be the following: - the POI permits to observe the Output data (e.g.: POI data and Transparent data) or a host simulator with logging capabilities is used. - the POI is connected to a host (or host simulator) - the host (or host simulator) is able to return the response defined in the test cases v1.2 7 Test Settings POI application Tester shall configure the POI app so that the following settings are set by default. Terminal AID List shall only contain:
- ‘A0000000001010’
- ‘A0000000002010’
- ‘A00000000F’ Issuer To ease the verdict and assist tester, Issuer may be configured so that it detects a test failure. Any successful test will never provide to the network the following values:
- AID: ‘A0000000000000’
- PAN:
- ‘9999999999999995’
- ‘9999999999999987’
- Cardholder name: "TEST/ERROR"
- Application Label: "DO_NOT_SELECT"
- Application Version Number: ‘0011’
- Issuer URL e-mail: "mailto:testerror@tld.invalid"
- Issuer URL tel: "tel:+0-0000000000"
- Language preference: "af"
- Last four digits of PAN: ‘5678’
- Track 2 Equivalent Data: ‘9999999999999995D17072017654321F’
- Token Requestor ID: ‘000000000000’
- Payment Account Reference: ‘3030303030303030303030303030303030303030303030303030303030’
- Application Specific Transparent Template: ‘9F370405060708’ QR Code images Images should be presented by the tester to the QR Code reader. Tester should ensure that the QR Codes are displayed with sufficient quality so that the reader can decode the data. Printed images or digital screen can be used, as long as the DPI (Dot Per Inch) or PPI (Pixel Per Inch) parameters do not alter rendering. Laser printing technology or the use of a smartphone screen (AMOLED and higher technologies) is advised. Unless otherwise specified in each test case individually the following rules have been used when building the QR Code images listed in the section ‘QR Code Images’:
- All the described data are placed in the same order as they appear in the document.
- Primitive Data Objects are included in templates as described by the specification
- The following default values are implicitly used in the tests: ECI Charset 8859-1 (000003) Payload Format Indicator "CPV01" v1.2 8 Test Structure Test numbering and associated sub cases Test Numbers are structured as follow: QCx.yyy.zz Version: 1 Sub Case Number: 3 Where:
- QC stands for "QR Code Consumer Presented",
- x is the category of the test (see next section),
- yyy is the test number in the category,
- zz is test number extension, used when test needs to be added between two existing tests,
- Version: it is the version of the test case,
- Sub case number: is the number of the sub case associated to the related test.
- Numbering can start at zero, meaning no sub cases in the related test. When subcases are present, reference to a specific sub case in a test case can be seen as follow: QCx.yyy.zz.ss, where ss is the number of the sub case. Test Category The Test Cases listed in this document are categorized. This rule is not strictly followed however, as depending on the objective of the test, it may happen that a test listed in a specific category also covers functions listed in another category. Test Cases are divided into the following categories:
- QC1: QR Code and Base64 decoding: The intent of the test cases in this category is to verify the compliance of the QR Code reader and the base64 decoder.
- QC2: BER-TLV Data Objects: The intent of the test cases in this category is to verify the compliance of the BER-TLV and other Data Objects.
- QC3: Transaction Data: The intent of the test cases in this category is to verify the AID Selection, POI Data and Transparent Data
- QC4: Transaction Processing: The intent of the test cases in this category is to verify that the transaction is conducted until completion. Applicability Options The Test Cases listed in this document may not all be applicable to the System Under Test. Applicability options are defined in this document and shall be declared as supported ("Y") or unsupported ("N") prior to executing the test cases based on the optional features implemented in the POI app. The following list of options may be used in a test case. Whenever no applicability option is requested, a test is always applicable. Option Name RECEIPT SENDING_RECEIPT PRINTING_RECEIPT LAST_4_DIGITS_ON_RECEIPT RECEIPT_WITH_APPLICATION_LABEL RECEIPT_WITH_CARHOLDER_NAME LANGUAGE ENGLISH_LANGUAGE CHINESE_LANGUAGE GERMAN_LANGUAGE JAPANESE_LANGUAGE SPANISH_LANGUAGE APPLICATION_SELECTION Value
Description
Y/N Electronic receipt sending support Y/N Receipt printing support Y/N Four last digits of PAN on receipt display Y/N Application Label on receipt display Y/N Cardholder name on receipt display Y/N English language support Y/N Chinese language support Y/N German language support Y/N Japanese language support Y/N Spanish language support Y/N Manual selection of payment application support
v1.2
Test applicability example with binary logic: [RECEIPT_WITH_CARDHOLDER_NAME] OR [RECEIPT_WITH_APPLICATION_LABEL]
v1.2 9 Test Cases
v1.2
QC1.002.00 QR Code – Length 512 Test No: QC1.002.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the QR Code Reader shall support recovery of at least 512 bytes from the QR Code Reference: EMV QRCPS – Section 4.1 QR Code Payload - Requirement 4.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’, PAN (‘5A’) = ‘1234567890123452’ and Application Specific Transparent Data (‘63’) so that the total size of the QR Code Payload is 512 bytes.
- Host approves the transaction Action: Image QC1.002.00_QR_Size512 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported v1.2 QC1.003.00 Base64 Decoding Test No: QC1.003.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that if the data received from the QR Code Reader starts with "hQVDUFY", then the POI shall perform base64 decoding as defined in [RFC 4648] and shall subsequently parse the data. Reference: EMV QRCPS – Section 5.1.1 Decode the QR Code Data - Requirement 5.1.1.1 EMV QRCPS – Section 5.1.12 Data Processing – Requirement 5.1.1.12 POI NA Configuration: Conditions:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- Host approves the transaction Action: Image QC1.003.00_B64 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported v1.2 QC1.004.00 Base64 Decoding – All symbols Test No: QC1.004.00 - Revision 2 - Number of sub cases: 0 Objective: To ensure that the POI shall perform base64 decoding as defined in [RFC 4648] and shall subsequently parse the data, when every base64 symbol is present. Reference: EMV QRCPS – Section 5.1.1 Decode the QR Code Data - Requirement 5.1.1.1 EMV QRCPS – Section 5.1.12 Data Processing – Requirement 5.1.1.12 POI NA Configuration: Conditions:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’, one Application Specific Transparent Template ('63') and PAN (‘5A’) = ‘1234567890123452’
- All the following base64 symbols shall be present in TLV ‘9F37’ of Template ‘63’, once it is base64 encoded: "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz01234 56789+/"
- A ‘00’ byte may have to be introduced at the beginning of the template value to align the data with the base64 6-bits wording
- Application Specific Transparent Template (‘63’) = ‘9F37 {30,31} [00] 00108310518720928b30d38f41149351559761969b71d79f8218a39259a7a 29aabb2dbafc31cb3d35db7e39ebbf3dfbf’
- Host approves the transaction Action: Image QC1.004.00_B64_allSymb is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- Transparent Data = ‘9F37 {30,31} [00] 00108310518720928b30d38f41149351559761969b71d79f8218a3 9259a7a29aabb2dbafc31cb3d35db7e39ebbf3dfbf’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported v1.2 QC1.005.00 Base64 Decoding – Padding Test No: QC1.005.00 - Revision 1 - Number of sub cases: 3 Objective: To ensure that the POI shall perform base64 decoding as defined in [RFC 4648] and shall subsequently parse the data, when all cases of padding occur. Reference: EMV QRCPS – Section 5.1.1 Decode the QR Code Data - Requirement 5.1.1.1 EMV QRCPS – Section 5.1.12 Data Processing – Requirement 5.1.1.12 POI NA Configuration: Conditions: Action:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’, one Application Specific Transparent Template ('63') and PAN (‘5A’) = ‘1234567890123452’
- Case 1: Application Specific Transparent Template ('63') = ‘9F37 01 00’
- Case 2: Application Specific Transparent Template ('63') = ‘9F37 02 00 00’
- Case 3: Application Specific Transparent Template ('63') = ‘9F37 03 00 00 00’
- Host approves the transaction
- Case 1: Image QC1.005.00.01_B64_Pad-1 is presented to the reader.
- Case 2: Image QC1.005.00.02_B64_Pad-2 is presented to the reader.
- Case 3: Image QC1.005.00.03_B64_Pad-3 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- Case 1: Transparent Data = ‘9F37 01 00’
- Case 2: Transparent Data = ‘9F37 02 00 00’
- Case 3: Transparent Data = ‘9F37 03 00 00 00’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported v1.2 QC1.006.00 Base64 Decoding – Wrong Header Test No: QC1.006.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that if the data received from the QR Code Reader is not base64 encoded, subsequent processing is outside the scope of this specification. Reference: EMV QRCPS – Section 5.1.1 Decode the QR Code Data - Requirement 5.1.1.1 EMV QRCPS – Section 5.1.12 Data Processing – Requirement 5.1.1.12 POI NA Configuration: Conditions:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- Base64 encoded data is starting with "HQVDUFY" instead of "hQVDUFY" Action: Image QC1.006.00_B64_WrongHead is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria: POI shall indicate that an error has occurred. v1.2 QC1.007.00 Base64 decoding – Non Base64 Characters Test No: QC1.007.00 - Revision 1 - Number of sub cases: 3 Objective: To ensure that if the data received from the QR Code Reader is not base64 encoded and include extra characters, subsequent processing is outside the scope of this specification Reference: EMV QRCPS – Section 5.1.2 Verify EMV QR Code- Requirement 5.1.1.2 EMV QRCPS – Section 5.1.12 Data Processing – Requirement 5.1.1.12 POI NA Configuration: Conditions:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’, one Application Specific Transparent Template ('63') = ‘9F37 04 FF FF FF FF’ and PAN (‘5A’) = ‘1234567890123452’
- Case 1: After Base64 encoding, one character is replaced with an ASCII character "%" at the place of Tag ‘9F37’ value
- Case 2: After Base64 encoding, one character is replaced with an ASCII character NULL (‘00’) at the place of Tag ‘9F37’ value
- Case 3: After Base64 encoding, one character is replaced with an Extended ASCII character "é" (‘82’) at the place of Tag ‘9F37’ Value Action:
- Case 1: Image QC1.007.00.01_B64_XtraChar-1 is presented to the reader.
- Case 2: Image QC1.007.00.02_B64_XtraChar-2 is presented to the reader.
- Case 3: Image QC1.007.00.03_B64_XtraChar-3 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria: POI shall indicate that an error has occurred. v1.2 QC1.008.00 Base64 decoding – Not BER-TLV Test No: QC1.008.00 - Revision 1 - Number of sub cases: 2 Objective: To ensure that following base64 decoding, if the resulting binary data is not BER-TLV encoded subsequent processing is outside the scope of this specification Reference: EMV QRCPS – Section 5.1.2 Verify EMV QR Code - Requirement 5.1.1.2 EMV QRCPS – Section 5.1.12 Data Processing – Requirement 5.1.1.12 POI NA Configuration: Conditions: Action:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- Case 1: length field ("L") of Application Template (‘61’) is set to ‘82’
- Case 2: ‘A9’ is inserted before Application Template (‘61’)
- Image QC1.008.00.01_B64_NotTLV-1 is presented to the reader.
- Image QC1.008.00.02_B64_NotTLV-2 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria: POI shall indicate that an error has occurred. v1.2 QC1.009.00 Parsing and Format Validation (1) Test No: QC1.009.00 - Revision 1 - Number of sub cases: 2 Objective: To ensure that if the value of the Payload Format Indicator (tag '85') is not "CPV01" then the POI App shall indicate that an error has occurred. Reference: EMV QRCPS – Section 5.1.3 Parsing and Format Validation - Requirement 5.1.1.3 EMV QRCPS – Section 5.1.12 Data Processing – Requirement 5.1.1.12 POI NA Configuration: Conditions: Action:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- Case 1: Payload Format Indicator (‘85’) = "CPV02"
- Case 2: Payload Format Indicator (‘85’) = "EMV01"
- Case 1: Image QC1.009.00.01_B64_BadPFI-1 is presented to the reader.
- Case 2: Image QC1.009.00.02_B64_BadPFI-2 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria: POI shall indicate that an error has occurred. v1.2 QC1.010.00 Parsing and Format Validation (2) Test No: QC1.010.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that if the data does not contain a template with a tag of '61' (Application Template), then the POI App shall indicate that an error has occurred. Reference: EMV QRCPS – Section 5.1.3 Parsing and Format Validation - Requirement 5.1.1.3 EMV QRCPS – Section 5.1.12 Data Processing – Requirement 5.1.1.12 POI NA Configuration: Conditions: QR Code image only contains Payload Format indicator, and Common Data Template with AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘9999999999999995’ Action: Image QC1.010.00_B64_NoT61 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria: POI shall indicate that an error has occurred. v1.2 QC2.001.00 BER-TLV – Template ‘61’ Test No: QC2.001.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload with template ‘61’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- Host approves the transaction Action: Image QC2.001.00_TLV_T61 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported v1.2 QC2.002.00 BER-TLV – Two Templates ‘61’ Test No: QC2.002.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload with two templates ‘61’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains two Application Templates (‘61’):
- First one with a non-matching AID (‘4F’) = ‘A0FFFFFFFF1010’ and PAN (‘5A’) = ‘9999999999999995’
- Second one with a matching AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- Host approves the transaction Action: Image QC2.002.00_TLV_twoT61 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported v1.2 QC2.003.00 BER-TLV – Template ‘63’ Test No: QC2.003.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload with template ‘63’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’, PAN (‘5A’) = ‘1234567890123452’ and one Application Specific Transparent Template (‘63’)
- Application Specific Transparent Template (‘63’) = ‘9F370401020304’
- Host approves the transaction Action: Image QC2.003.00_TLV_T63 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- Transparent Data = ‘9F370401020304’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported. v1.2 QC2.004.00 BER-TLV – Two Templates ‘63’ Test No: QC2.004.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload with two templates ‘63’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains two Application Templates (‘61’):
- First one with a non-matching AID (‘4F’) = ‘A0FFFFFFFF1010’ and PAN (‘5A’) = ‘9999999999999995’
- Second one with a matching AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- Each Application Template (‘61’) contains one Application Specific Transparent Template (‘63’):
- First one = ‘9F370405060708’
- Second one = ‘9F370401020304’
- Host approves the transaction. Action: Image QC2.004.00_TLV_twoT63 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- Transparent Data = ‘9F370401020304’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported. v1.2 QC2.005.00 BER-TLV – Template ‘62’ Test No: QC2.005.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload with template ‘62’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains two Application Templates (‘61’):
- First one with a non-matching AID (‘4F’) = ‘A0FFFFFFFF1010’ and PAN (‘5A’) = ‘9999999999999995’
- Second one with a matching AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- QR Code image contains one Common Data Template (‘62’) with Cardholder Name (‘5F20’) = "EMVCO/TEST"
- Host approves the transaction. Action: Image QC2.005.00_TLV_T62 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- Cardholder Name = "EMVCO/TEST"
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported. v1.2 QC2.006.00 BER-TLV – Template ‘64’ Test No: QC2.006.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload with template ‘64’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains two Application Templates (‘61’):
- First one with a non-matching AID (‘4F’) = ‘A0FFFFFFFF1010’ and PAN (‘5A’) = ‘9999999999999995’
- Second one with a matching AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- QR Code image contains one Common Data Template (‘62’) with Cardholder Name (‘5F20’) = "EMVCO/TEST" and one Common Data Transparent Template (‘64’)
- Common Data Transparent Template (‘64’) = ‘8F0101’
- Host approves the transaction. Action: Image QC2.006.00_TLV_T64 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- Cardholder Name = "EMVCO/TEST"
- Transparent Data = ‘8F0101’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported. v1.2 QC2.007.00 BER-TLV – Other Template Test No: QC2.007.00 - Revision 2 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload with ‘other template’ ‘65’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains one Application Template (‘61’) with AID (‘4F’) = ‘A0000000001010’ and PAN (‘5A’) = ‘1234567890123452’
- QR Code image contains one unknown template = ‘65038F0101’
- Host approves the transaction. Action: Image QC2.007.00_TLV_TOther is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- PAN = ‘1234567890123452’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported. v1.2 QC2.008.00 BER-TLV – All Data Objects in Template 61 Test No: QC2.008.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload whenever all data objects from [EMV QRCPS] Annex A are in template ‘61’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 EMV QRCPS – Section 6.1.1 Perform Merchant Specific Processing – Requirement 6.1.1.6 POI NA Configuratio n: Conditions:
- QR Code image contains one Application Template (‘61’) with:
- AID (‘4F’) = ‘A0000000001010’
- Application Label (‘50’) = "EMV"
- PAN (‘5A’) = ‘1234567890123452’
- Application Version Number (‘9F08’) = ‘0010’
- Cardholder Name (‘5F20’) = "EMVCO/TEST"
- Issuer URL (‘5F50’) = ‘6d61696c746f3a6578616d706c6540656d76636f2e636f6d’
- Last 4 Digits of PAN (‘9F25’) = ‘1234’
- Language Preference (‘5F2D’) = "en"
- Track 2 Equivalent Data (‘57’) = ‘1234567890123452D49112011234567F’
- Token Requestor ID (‘9F19’) = ‘099901234567’
- PAR (‘9F24’) = ‘39393939313233344142434445464748494a4b4c4d4e4f50515253 5455’
- Application Specific Transparent Template (‘63’) = ‘9F370401020304’
- Host approves the transaction. Action: Image QC2.008.00_TLV_AllInT61 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- Application Label = "EMV"
- PAN = ‘1234567890123452’
- Application Version Number = ‘0010’
- Cardholder Name = "EMVCO/TEST" v1.2 QC2.008.00 BER-TLV – All Data Objects in Template 61
- Issuer URL = ‘6d61696c746f3a6578616d706c6540656d76636f2e636f6d’
- Last 4 Digits of PAN = ‘1234’
- Language Preference = "en"
- Track 2 Equivalent Data = ‘1234567890123452D49112011234567F’
- Token Requestor ID = ‘099901234567’
- PAR = ‘39393939313233344142434445464748494a4b4c4d4e4f50515253 5455’
- Transparent Data = ‘9F370401020304’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported. v1.2 QC2.009.00 BER-TLV – All Data Objects in two Templates 61 Test No: QC2.009.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload whenever all data objects from [EMV QRCPS] Annex A are in two templates ‘61’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains two Application Templates (‘61’).
- First Application Templates (‘61’) with:
- AID (‘4F’) = ‘A0FFFFFFFF1010’
- Application Label (‘50’) = "DO_NOT_SELECT"
- PAN (‘5A’) = ‘9999999999999995’
- Application Version Number (‘9F08’) = ‘0011’
- Cardholder Name (‘5F20’) = "TEST/ERROR"
- Issuer URL (‘5F50’) = ‘74656c3a2b302d30303030303030303030’
- Last 4 Digits of PAN (‘9F25’) = ‘5678’
- Language Preference (‘5F2D’) = "af"
- Track 2 Equivalent Data (‘57’) = ‘9999999999999995D17072017654321F’
- Token Requestor ID (‘9F19’) = ‘000000000000’
- PAR (‘9F24’) = ‘30303030303030303030303030303030303030303030303030303 03030’
- Application Specific Transparent Template (‘63’) = ‘9F370405060708’
- Second Application Templates (‘61’) with:
- AID (‘4F’) = ‘A0000000001010’
- Application Label (‘50’) = "EMV"
- PAN (‘5A’) = ‘1234567890123452’
- Application Version Number (‘9F08’) = ‘0010’
- Cardholder Name (‘5F20’) = "EMVCO/TEST"
- Issuer URL (‘5F50’) = ‘6d61696c746f3a6578616d706c6540656d76636f2e636f6d’
- Last 4 Digits of PAN (‘9F25’) = ‘1234’
- Language Preference (‘5F2D’) = "en"
- Track 2 Equivalent Data (‘57’) = ‘1234567890123452D49112011234567F’
- Token Requestor ID (‘9F19’) = ‘099901234567’ v1.2 QC2.009.00 BER-TLV – All Data Objects in two Templates 61
- PAR (‘9F24’) = ‘39393939313233344142434445464748494a4b4c4d4e4f5051525 35455’
- Application Specific Transparent Template (‘63’) = ‘9F370401020304’
- Host approves the transaction. Action: Image QC2.009.00_TLV_AllInTwoT61 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- Application Label = "EMV"
- PAN = ‘1234567890123452’
- Application Version Number = ‘0010’
- Cardholder Name = "EMVCO/TEST"
- Issuer URL = ‘6d61696c746f3a6578616d706c6540656d76636f2e636f6d’
- Last 4 Digits of PAN = ‘1234’
- Language Preference = "en"
- Track 2 Equivalent Data = ‘1234567890123452D49112011234567F’
- Token Requestor ID = ‘099901234567’
- PAR = ‘39393939313233344142434445464748494a4b4c4d4e4f5051525 35455’
- Transparent Data = ‘9F370401020304’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported. v1.2 QC2.010.00 BER-TLV – All Data Objects in Template 62 Test No: QC2.010.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload whenever all data objects from [EMV QRCPS] Annex A are in template ‘62’, except for data element ‘4F’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirement 3.1.1.1 POI NA Configuration: Conditions:
- QR Code image contains two Application Templates (‘61’):
- First one with a non-matching AID (‘4F’) = ‘A0FFFFFFFF1010’ and Application Specific Transparent Template (‘63’) = ‘9F370405060708’
- Second one with a matching AID (‘4F’) = ‘A0000000001010’ and Application Specific Transparent Template (‘63’) = ‘9F370401020304’
- QR Code image contains one Common Data Template (‘62’) with:
- Application Label (‘50’) = "EMV"
- PAN (‘5A’) = ‘1234567890123452’
- Application Version Number (‘9F08’) = ‘0010’
- Cardholder Name (‘5F20’) = "EMVCO/TEST"
- Issuer URL (‘5F50’) = ‘6d61696c746f3a6578616d706c6540656d76636f2e636f6d’
- Last 4 Digits of PAN (‘9F25’) = ‘1234’
- Language Preference (‘5F2D’) = "en"
- Track 2 Equivalent Data (‘57’) = ‘1234567890123452D49112011234567F’
- Token Requestor ID (‘9F19’) = ‘099901234567’
- PAR (‘9F24’) = ‘39393939313233344142434445464748494a4b4c4d4e4f5051525 35455’
- Common Data Transparent Template (‘64’) = ‘8F0101’
- Host approves the transaction. Action: Image QC2.010.00_TLV_AllInT62 is presented to the reader. Procedure: Transaction is processed by the POI. Pass Criteria:
- Outputted Data from POI shall contain:
- AID = ‘A0000000001010’
- Application Label = "EMV"
- PAN = ‘1234567890123452’ v1.2 QC2.010.00 BER-TLV – All Data Objects in Template 62
- Application Version Number = ‘0010’
- Cardholder Name = "EMVCO/TEST"
- Issuer URL = ‘6d61696c746f3a6578616d706c6540656d76636f2e636f6d’
- Last 4 Digits of PAN = ‘1234’
- Language Preference = "en"
- Track 2 Equivalent Data = ‘1234567890123452D49112011234567F’
- Token Requestor ID = ‘099901234567’
- PAR = ‘39393939313233344142434445464748494a4b4c4d4e4f5051525 35455’
- Transparent Data: ‘9F370401020304’ ‘8F0101’
- POI shall approve the transaction by providing: o display message if supported o and/or receipt printing or sending if supported. v1.2 QC2.011.00 BER-TLV – All Data Objects Mixed in Templates Test No: QC2.011.00 - Revision 1 - Number of sub cases: 0 Objective: To ensure that the POI correctly parses BER-TLV data of QR Code Payload whenever all data objects from [EMV QRCPS] Annex A mixed in two templates ‘61’ and one template ‘62’. Reference: EMV QRCPS – Section 3.1.1 QR Code Payload - Requirem
Shown in part. Read the original for the full text.