SB nº 239: Update for EMV® Book C-2 – IDS & Torn Transactions

v1.0 Specification Bulletins
Contactless Acceptance Device

EMV<sup>®</sup> Specification Bulletin No. 239 First Edition February 2020 Update for EMV Book C-2 (Version 2.8) – IDS & Torn Transactions This Specification Bulletin specifies IDS and Torn Transaction Recovery as an implementation option.

Applicability

This Specification Bulletin applies to:

  • EMV Contactless Specifications for Payment Systems, Book C-2, Kernel 2 Specification, Version 2.8, March 2019 Related Documents [CDA] EMV Specification Bulletin No. 237 – Update for EMV Book C-2 (Version 2.8) – CDA

Effective Date

April 1st, 2020

Description

This Specification Bulletin specifies IDS and Torn Transaction Recovery as an implementation option. With this implementation option the implementer has the possibility to build Kernel 2 without support for IDS and Torn Transaction Recovery.

countries.

Proposed Specification Changes Implementation Option An implementation option allows the vendor to select whether the software behind the option will be implemented in a particular installation. An implementation option, when chosen by the vendor, reduces the number of execution paths supported by the software, changes the software itself, and impacts all the AIDs that rely on this software. The following sections list the functionality that must not be implemented if the IDS and Torn Transaction Recovery implementation option is not implemented. DOL Handling The special processing for DSDOL does not have to be implemented. List Handling The Torn Record list does not have to be implemented. Torn Transaction Log The Torn Transaction Log does not have to be implemented. Configuration Data The following data objects listed in Table 4.3 do not have to be configured with a default value:

  • Max Lifetime of Torn Transaction Log Record
  • Max Number of Torn Transaction Log Records Discretionary Data The Discretionary Data in Table 4.9 is as follows: Table 4.9—Discretionary Data for an EMV Mode Transaction Data Object Application Capabilities Information Application Currency Code Balance Read After Gen AC Balance Read Before Gen AC Error Indication Post-Gen AC Put Data Status Pre-Gen AC Put Data Status Third Party Data C-APDU Commands The RECOVER AC command does not have to be implemented. countries. State 1 – Idle State 1 Flow Diagram in Figure 6.2 is changed as follows: S1 s1 - idle 1 ACT 2 STOP 7 Parse FCI Template and add transaction data to TLV Database OK 9 Initialize EMV data objects 3 OUT (end application) NOK 8 OUT (select next) 1 Exit kernel countries. S1 2 16 Initialize EMV/DE data objects 21 Missing PDOL Data Flag No set? Yes 22 DEK 23 Start Timer s2 – waiting for PDOL data s3 – waiting for GPO response Symbols S1.4, S1.5, S1.6, S1.17, S1.18, S1.19 and S1.20 do not have to be implemented. In S1.16 IDS Status, DS

Summary

Status and DS Digest H do not have to be initialized.

countries.

States 3,R1 – Common Processing State 3,R1 Flow Diagram in Figure 6.6 is changed as follows: S3R1 6 14 Add known data listed in Tags To Read Yet to Data To Send 19 Set CDA Flag 15 Data Needed not empty OR (Data To Send not empty AND Tags To Read Yet empty)? No Yes 16 DEK 17 Card and Yes Kernel support CDA? No 20 Set ODA not performed in TVR 8 Symbols S3R1.10, S3R1.11, S3R1.12, S3R1.13 and S3R1.18 do not have to be implemented.

countries.

State 4 – Waiting for EMV Read Record Response State 4 Flow Diagram in Figure 6.7 is changed as follows: S4 4 34 CDA Flag set AND Signed Flag set? No Yes 35 Include record in Static Data To Be Authenticated A S456 Symbols S4.30, S4.31, S4.32 and S4.33 do not have to be implemented.

countries.

State 4, 5 and 6 – Common Processing State 4, 5 and 6 Flow Diagram in Figure 6.11 is changed as follows: S456 3 Yes 15 OUT (select next) Exit kernel 12 Amount Authorized present and not empty? Yes 14 Max Trans Amount Limit exceeded? No 16 Mandatory data objects present? Yes 4 No 13 OUT (end application) Exit kernel No 17.1 Prepare UI Request (Other Card) 17.2 OUT (end application) Exit kernel

countries.

S456 4 21 Add known data listed in Tags To Read Yet to Data To Send 22 Data To Send Yes empty? No 23 DEK 24 CDA Flag? No Yes 25 Check mandatory data objects for CDA Update TVR 7 8

countries.

S456 11 No 45 Prepare GENERATE AC 46 CA (GENERATE AC) 42 Pre GEN AC PUT DATA? Yes 50 Prepare PUT DATA Update Tags To Write Yet Before Gen AC 51 CA (PUT DATA) s9 - waiting for generate AC response - 1 s12 - waiting for put data response before generate AC Symbols S456.18, S456.19, S456.20.1, S456.20.2, S456.43, S456.44, S456.47, S456.48 and S456.49 do not have to be implemented.

countries.

State 9 – Waiting for Generate AC Response – 1 State 9 Flow Diagram in Figure 6.15 is changed as follows: S9 s9 – waiting for generate AC response - 1 1 L1RSP 2 RA 3 STOP 4 DET 9 Prepare UI Request (Try Again) 10 OUT (end application) Exit kernel 2 s9 – waiting for generate AC response - 1 Symbols S9.5, S9.6, S9.7, S9.8, S9.11, S9.13, S9.14 and S9.15 do not have to be implemented.

countries.

State 10 – Waiting for Recover AC Response State 10 does not have to be implemented. States 9 and 10 – Common Processing State 9 and 10 Flow Diagram in Figure 6.16 is changed as follows: S910 CDA A 1 Retrieve NOK Issuer Public Key and ICC Public Key OK F Yes 4.1 Verify SDAD, retrieve AC and check relay data 2.1 RRP performed? No 4 Verify SDAD and retrieve AC 6 Yes OK? No E F Valid response

countries.

S910 No CDA B 30 AC No present? Yes 31 Error Indication:= CARD DATA MISSING Yes C Invalid response - 1 No 35 AAC requested? Yes Yes 36 CDA No requested? Yes 37 Error Indication:= CARD DATA ERROR 32 AAC? No 34 CDA requested? No E Valid response C 6 Invalid response - 1

countries.

S910 Invalid response - 1 C 50 Prepare UI Request (Other Card) 53 OUT (end application) Exit kernel Symbols S910.2, S910.2.2, S910.3, S910.3.1, S910.5, S910.8, S910.9, S910.10, S910.11, S910.12, S910.13, S910.14, S910.15, S910.16, S910.17, S910.18, S910.19, S910.33, S910.51, S910.52, S910.61 and S910.62 do not have to be implemented. State 11 – Waiting for Generate AC Response – 2 State 11 does not have to be implemented.

countries.

State 12 – Waiting for Put Data Response Before Generate AC State 12 Flow Diagram in Figure 6.19 is changed as follows: S12 2 15 Prepare GENERATE AC 16 CA (GENERATE AC) s9 - waiting for generate AC response - 1 Symbols S12.13, S12.14, S12.17, S12.18 and S12.19 do not have to be implemented.

countries.

Procedure – Prepare Generate AC Command The Flow Diagram Prepare Generate AC Command in Figure 7.6 is changed as follows: GAC Prepare GENERATE AC 20 No CDA Flag set? Yes 21 CDA failed in No TVR set? Yes 22 On device No cardholder verification supported? Yes 23 AC Type:= AAC 26 Set AC Type in Ref Control Param Do not request CDA in Ref Control Param 24 AC Type = AAC? No Yes 25 CDA supported over TC, ARQC and Yes AAC? No 27 Set AC Type in Ref Control Param Request CDA in Ref Control Param 3

countries.

GAC 3 29 Create Generate AC command with CDOL1 Related Data Symbols GAC.1, GAC.2, GAC.3, GAC.4, GAC.5, GAC.6, GAC.7, GAC.8, GAC.9, GAC.10, GAC.11, GAC.12, GAC.13, GAC.40, GAC.41, GAC.42, GAC.43, GAC.44, GAC.45, GAC.47 and GAC.48 do not have to be implemented.

countries.

Security Algorithms OWHF2 and OWHF2AES do not have to be implemented. Data Dictionary The following data objects do not have to be implemented in the TLV Database. The data objects are unknown. DRDOL Data Object DRDOL Related Data DS AC Type DS Digest H DSDOL DS ID DS Input (Card) DS Input (Term) DS ODS Card DS ODS Info DS ODS Info For Reader DS ODS Term DS Requested Operator ID DS Slot Availability DS Slot Management Control DS Summary 1 DS Summary 2 DS Summary 3 DS Summary Status DS Unpredictable Number DSVN Term IDS Status Torn Entry Torn Record Torn Temp Record

countries.

Legal Notice

Unless the user has an applicable separate agreement with EMVCo or with the applicable payment system, any and all uses of these Specifications is subject to the terms and conditions of the EMVCo Terms of Use agreement available at www.emvco.com and the following supplemental terms and conditions. Except as otherwise may be expressly provided in a separate agreement with EMVCo, the license granted in the EMVCo Terms of Use specifically excludes (a) the right to disclose, distribute or publicly display these Specifications or otherwise make these Specifications available to any third party, and (b) the right to make, use, sell, offer for sale, or import any software or hardware that practices, in whole or in part, these Specifications. Further, EMVCo does not grant any right to use the Kernel Specifications to develop contactless payment applications designed for use on a Card (or components of such applications). As used in these supplemental terms and conditions, the term "Card" means a proximity integrated circuit card or other device containing an integrated circuit chip designed to facilitate contactless payment transactions. Additionally, a Card may include a contact interface and/or magnetic stripe used to facilitate payment transactions. To use the Specifications to develop contactless payment applications designed for use on a Card (or components of such applications), please contact the applicable payment system. To use the Specifications to develop or manufacture products, or in any other manner not provided in the EMVCo Terms of Use, please contact EMVCo. These Specifications are provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of these Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of these Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with these Specifications.

countries.