FAQ: EMVCo CDCVM Solution Database Pilot – General Questions

v1.0
Mobile

EMVCo CDCVM Solution Database Pilot FAQs This document provides FAQs for the EMVCo Solution Database Pilot. This information is current as of July 2020. Consumer Device Cardholder Verification Method (CDCVM) Overview 1. What is Consumer Device Cardholder Verification Method (CDCVM)? With traditional Cardholder Verification Methods (CVM), consumer authentication is performed on the merchant system (a PIN entered into a merchant device, for example). The growing use of mobile devices for payment transactions has enabled consumer authentication to be performed specifically on the consumer’s own device, via passcodes, passwords and patterns, as well as through biometrics such as fingerprint, iris, voice and facial recognition. This type of authentication on a consumer device is known as CDCVM. Additionally, when multiple payment applications on the device share the same CDCVM and the associated result, it is referred to as Shared CDCVM. 2. Why is EMVCo involved in this area and what activity is it undertaking? With the increased deployment of Consumer Device Cardholder Verification Method (CDCVM) solutions across the payments ecosystem, EMVCo is working to promote confidence and consistency by identifying and addressing specific security, functional and performance needs. EMVCo has already developed a process to evaluate the security of CDCVM, and also has proposed some industry best-practices to address functional and performance considerations. It is now piloting a central mechanism to enable issuers and other participants to identify CDCVM solutions – the EMV<sup>®</sup> CDCVM Solution ID and Database. 3. What specific challenge is the EMV CDCVM Solution ID and Database addressing? CDCVM comes with more complexity and variability than traditional CVM, which can make it more difficult for issuers to identify the precise CDCVM used for a particular payment transaction. Unlike an online PIN, a CDCVM is not seen by the issuer. CDCVM solutions can use varying components on a device, encompass multiple modalities, and can be used across a large range of consumer devices manufactured by different original equipment manufacturers (OEMs) for various markets and users. © 2020 EMVCo, LLC. All rights reserved

This challenge has highlighted the need to provide more information about a CDCVM solution used during a transaction to enable better-informed authorisation decisions for payments conducted on consumer devices. In response, EMVCo is piloting an EMV CDCVM Solutions database in which each registered CDCVM solution is assigned a unique, short identifier known as an EMV CDCVM Solution ID, together with a set of related metadata of the CDCVM solutions being entered and maintained in the database. 4. What are the industry benefits of the EMV CDCVM Solution ID and Database? By accessing the Solution Database, Solution ID users such as issuers, acquirers, merchants and token service providers (TSPs) can build more accurate risk profiles for use during transaction authorisations. This is because it is easier to identify and analyse the integrity of the precise CDCVM used for a particular payment transaction. It can also support innovation by Solution Providers such as device manufacturers, operating system (OS) / platform providers and mobile application providers to facilitate broader industry adoption of CDCVM solutions. Database Overview 5. What is the EMV CDCVM Solution Database? The EMV CDCVM Solution Database assigns each registered CDCVM Solution a unique, short identifier known as an EMV CDCVM Solution ID and a set of related metadata. This will allow a single value to be communicated to issuers, enabling them (or a service provider acting on their behalf) to access the CDCVM Solutionrelated metadata. 6. What type of information will be registered in the Database? Data Fields of the CDCVM Database include information such as CDCVM Solution Name, Solution Provider, Solution Type, Operating System and other metadata which may help to identify the CDCVM used during a transaction. 7. What are the use case scenarios of the Database? EMVCo has provided example use cases of how the CDCVM Solution ID Database entries may be used. The sample use cases cover various scenarios on Solution ID allocation, and use of Solution ID. Please refer to CDCVM Solution ID and Database Use Cases for further details on these use cases. © 2020 EMVCo, LLC. All rights reserved

8. Will implementation of the Database and registration of Solution ID be mandatory in the future? EMVCo does not mandate the use of the CDCVM Solution ID or the Database. However, EMVCo encourages Solution Providers to register their CDCVM Solutions so that the Solution Database can provide enhanced information to assist in identifying the CDCVM Solution used during a transaction. A CDCVM Solution ID data element may be included in future EMV Specifications. 9. In which part of the EMV Specification will this be included? EMVCo has defined the CDCVM Solution ID format and is currently establishing the need and viability for the Database through a pilot. There are no immediate plans to include the CDCVM Solution ID in EMV Specifications; however it is under consideration for inclusion where appropriate. 10. When is the launch of the Database? The Database is currently available to participants of the pilot. As part of the pilot, EMVCo will conduct surveys with the pilot participants to help determine if, or at what point, the live Database will launch. Pilot Overview 11. What is the purpose of the pilot? The purpose of the pilot is to validate the utility of the Database, the data recorded, the related processes, and to obtain stakeholder feedback. During this time, EMVCo may revise the processes and Database information. 12. What are the benefits to participating? Participating in the pilot provides the opportunity to test and provide input to the Database processes, integrate with the Database to test how it may be used in practice, and to refine the data which is collected in order to optimise its usefulness in risk analysis decisions. 13. How many issuers / OEM vendors are estimated to participate? At this time EMVCo has not put a limit on the number of participants in the pilot. 14. Are there any obligations for the participants during the pilot? The pilot participant must sign the relevant agreement in order to participate in the pilot. EMVCo will periodically send a survey to participants for feedback regarding the pilot. © 2020 EMVCo, LLC. All rights reserved

Pilot Registration 15. What is the duration of the pilot? The overall duration will be a maximum of two years, with checkpoints at six-month intervals to report progress and determine next steps. 16. Is there a registration fee for participating in a pilot? EMVCo welcomes participation in the pilot to register CDCVM Solutions and test the CDCVM Solution Database, and therefore will waive the relevant fees during the pilot phase. 17. What are the requirements for participation? The pilot is open only to selected EMVCo Associates and Subscribers. Following are the requirements for participation:

  • To register CDCVM solution or use the Database, a participant must be a company, a national or regional representative organisation, or a significant division of a parent company.
  • Solution Providers must currently provide one or more developed and commercially released CDCVM Solutions to become a registered vendor and register their CDCVM Solution in the database. Database Registration 18. What are the procedures for Database registration? See the CDCVM Solution Database Pilot Portal for detailed procedures to register as a Solution Provider or Database User. For more information, please contact the Secretariat at cdcvm_admin@emvco.com. 19. Is all information required for product registration? Not all Solution data fields are mandatory during Solution Registration. Solution Providers register information by following the required or optional field instructions on the Solution Registration web pages. Further information of the registered CDCVM Solution may be updated once the details are available. 20. Will other OEMs be able to access our product information? Yes. The Registered Solution information is intended to be made available to subscribed Database Users and other OEMs may register as a CDCVM Solution Database User. © 2020 EMVCo, LLC. All rights reserved Database Implementation 21. How can we download the Database information? To access the CDCVM Solution Database the user must first register as a CDCVM Solution Database User. You will then get access to the database and be able to search for information of registered CDCVM Solutions. Additional methods are provided for participants to download/export the registered solution details from the database. 22. How is the Database information utilised within a transaction? EMVCo offers the Solution Database service to enable the possibility of using the CDCVM Solution ID for various business needs including enabling better-informed authorisation decisions for payments conducted on consumer devices. However, implementation decisions impacting the actual use of the CDCVM Solution data and Solution ID is outside of EMVCo’s scope. Please refer to CDCVM Solution ID and Database Use Cases for examples of how information in the CDCVM Solution Database may be possibly utilised. 23. Is there a guideline document for implementation? How can we access the document? The actual use of the CDCVM Solution data and Solution ID is outside the scope of EMVCo. There is no current EMVCo implementation documentation. Pilot Feedback 24. What kind of feedback will we receive from EMVCo during/after the pilot? EMVCo will conduct evaluations of the pilot at six-month intervals after the pilot launch. Evaluation results will then be shared with EMVCo associates and pilot participants. 25. How can participants provide feedback during the pilot? As part of the pilot evaluation, EMVCo plans to send a survey to solicit participant feedback on various aspects of the Database pilot. Pilot participants are also welcome to provide feedback through EMVCo query system or contact the EMVCo Secretariat (cdcvm_admin@emvco.com). EMV<sup>®</sup> is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo, LLC. © 2020 EMVCo, LLC. All rights reserved