SB n° 249: EMV® Contactless Book A Update

v2.8 Specification Bulletins
Contactless Acceptance Device

EMV<sup>®</sup> Specification Bulletin No.249 First Edition October 2020 EMV Contactless Book A Update This Specification Bulletin describes latest changes and corrections to the EMV Contactless Specifications for Payment Systems Book A Version 2.8.

Applicability

This Specification Bulletin applies to:

  • EMV Contactless Specifications for Payment Systems, Book A Architecture and General Requirements, Version 2.8, April 2019

Related Documents

  • N/A

Effective Date

  • Specification: Effective immediately
  • Testing: 15 October 2020

Description

After Version 2.8 of the EMV Contactless Specifications for Payment Systems was published in April 2019, there have been comments and feedback received from the industry regarding Book A. Some of those issues reported have since been corrected by Version 2.9 of the EMV Contactless Specifications for Payment Systems which was published in March 2020. However, the associated new test plan and lab release for Version 2.9 won’t be formally available until early 2021. The purpose of this bulletin is to update Version 2.8 to incorporate some of those key changes both in the specification and in the test plan and lab process, to ensure that devices type approved to Version 2.8 include those key updates. Specification Changes

countries.

Book A In Section 6.1 Outcomes, content for ‘Try Another Interface’ and ‘End Application’ in Table 6-1 Outcomes is updated as shown below: Try Another Interface Any of the following:

  • The kernel is unable to complete the transaction with the selected contactless card application, but knows from the configuration data that another interface (e.g. contact or magnetic-stripe) is available. The kernel could indicate a preference for the alternate interface.
  • Entry Point was unable to identify a contactless card application that could complete the transaction and returns control to the POS System, which might attempt a different interface.
  • The issuer has requested to ‘Try Another Interface’ in the Authorisation Response Code after the transaction has gone online i.e. after the Online Request Outcome May create Outcome and pass it to Entry Point Either of the following:
  • Receives Outcome from kernel, processes selected Outcome parameters, and passes Outcome to reader as a Final Outcome
  • Under exception conditions, creates Outcome and passes it to reader Processes the Final Outcome countries. End Application Any of the following:
  • The kernel has completed processing and requires no further action.
  • The kernel wished to restart after the card has been removed. It is one way a kernel may handle a mobile device that requires a confirmation code to be entered.
  • The kernel experienced an application error, such as missing data, that will not resolve if the transaction is attempted again with the same selected contactless card application.
  • Entry Point was unable to identify a contactless card application that could complete the transaction with the current card and wants the POS System to direct the cardholder to present another card. May create Outcome and pass it to Entry Point Either of the following:
  • Receives Outcome from kernel, processes selected Outcome parameters, and passes Outcome to reader as a Final Outcome
  • Under exception conditions, creates Outcome and passes it to reader countries. In Section 6.3 Outcome Processing, update the 2nd Paragraph as shown below: Table 6-3 describes POS System processing for a first Final Outcome. Table 6-4 describes POS System processing for a second Final Outcome; that is, one that follows an Online Request Outcome. Table 6-5 describes POS System processing for a third Final Outcome following a Request Online PIN Outcome. In Section 6.3 Outcome Processing, content for ‘Try Another Interface’ and ‘Request Online PIN’ in Table 6-4 Second Final Outcome (Following an Online Request) is updated as shown below: Second Final Outcome POS System Processing Try Another Interface
  • The terminal allows the transaction to be attempted on another interface – contact chip or mag-stripe according to its capabilities. If a preference is indicated in the Outcome, then (depending on payment system rules) this might need to be taken into account.
  • The POS System advises the cardholder that another interface might be used. An initial message to the cardholder might have been displayed as a result of including a User Interface Request with the Outcome.
  • The terminal processes the transaction using the other interface and might use the ADF Name provided with the Outcome to seek to select the same application if the chip interface is used. Cardholder communication will be as per the normal processing for a chip or mag-stripe interface.
  • Once complete, continue with ‘Requirements – New Transaction Preparation and Start’ on 9. countries. Second Final Outcome Request Online PIN POS System Processing
  • The POS System advises the cardholder that an online transaction is in progress. An initial message to the cardholder might have been displayed as a result of the kernel including a User Interface Request with the Outcome. The issuer has determined in the Online Request that Online PIN CVM is required, therefore the message directs the cardholder to enter their PIN.
  • The terminal processes and submits the encrypted online PIN CVM. With the additional online PIN data result, the terminal initiates an online authorisation request, using the data record provided with the Outcome, which is the same data as the previous Online Request. The terminal receives the online response or might determine that the request was unable to go online.
  • If the Start parameter was any value other than `N/A', then: O The terminal makes available the transaction disposition in the online response together with all of the EMV TLV data elements present. O The reader reactivates Entry Point by continuing with `Requirements - Online Response - Restart' on 4.
  • The terminal determines the transaction disposition, based on the online response indication (with Unable To Go Online a decline).
  • The terminal advises the cardholder of the transaction outcome.
  • If a cardholder receipt is required, the terminal prints it or provides it electronically (e.g. email).
  • The terminal prepares a clearing record if transaction disposition is "approved".
  • Once complete, continue with `Requirements - New Transaction Preparation and Start' on 9. countries. In Section 8 POS System Requirements, add the following 8.1.1.24 Requirements – Request Online PIN - Restart to the end of the section: Requirements – Request Online PIN – Restart The following requirement applies if the Outcome is Request Online PIN and the retained Start parameter is any value other than ‘N/A’.

8.1.1.24 If either of the following is true:

  • the value of the Online Response Data parameter is ‘Any’,
  • or the value of the Outcome parameter Online Response Data is ‘EMV Data’ and at least one of the following data elements is present:
  • Issuer Authentication Data (Tag '91')
  • Issuer Script Template (Tag '71', '72') then the reader shall activate Entry Point at the Start indicated by the retained Start parameter. In Section B.4 Try Another Interface, the first paragraph is updated as shown below: The kernel, Entry Point, or the Issuer has determined that the transaction cannot be completed over the contactless interface and another interface such as contact chip or mag-stripe should be attempted. countries. In Section B.8 Request Online PIN, replace the whole section as shown below: B.8 Request Online PIN The kernel has determined that the Issuer is requesting that Online PIN entry is required.
  • Start: D
  • Online Response Data: Any
  • CVM: Online PIN
  • UI Request on Outcome Present: Yes
  • Message Identifier: '09' ("Please Enter Your PIN ")
  • Status: Processing
  • UI Request on Restart Present: No
  • Data Record Present: Yes
  • Discretionary Data Present: Yes or No
  • Alternate Interface Preference: N/A
  • Receipt: Yes or N/A
  • Field Off Request: N/A
  • Removal Timeout: set by kernel countries.

Legal Notice

The EMV<sup>®</sup> Specifications are provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV<sup>®</sup> Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV<sup>®</sup> Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV<sup>®</sup> Specifications

countries.