SB nº 238: Update for EMV® Book C-2 – Mag-stripe Mode

v1.0 Specification Bulletins
Contactless Acceptance Device

EMV<sup>®</sup> Specification Bulletin No. 238 First Edition February 2020 Update for EMV Book C-2 (Version 2.8) – Mag-stripe Mode This Specification Bulletin specifies mag-stripe mode as an implementation option.

Applicability

This Specification Bulletin applies to:

  • EMV Contactless Specifications for Payment Systems, Book C-2, Kernel 2 Specification, Version 2.8, March 2019
  • EMV Specification Bulletin No. 237 – Update for EMV Book C-2 (Version 2.8) – CDA

Related Documents

  • None

Effective Date

April 1st, 2020

Description

This Specification Bulletin specifies mag-stripe mode as an implementation option. With this implementation option the implementer has the possibility to build Kernel 2 without support for magstripe mode.

countries.

Proposed Specification Changes Implementation Option An implementation option allows the vendor to select whether the software behind the option will be implemented in a particular installation. An implementation option, when chosen by the vendor, reduces the number of execution paths supported by the software, changes the software itself, and impacts all the AIDs that rely on this software. The following sections list the functionality that must not be implemented, if the mag-stripe mode implementation option is not implemented. Configuration Data The following data objects listed in Table 4.3 do not have to be configured with a default value:

  • Default UDOL
  • Mag-stripe Application Version Number (Reader)
  • Mag-stripe CVM Capability – CVM Required
  • Mag-stripe CVM Capability – No CVM Required Data Record The CreateMSDataRecord () method does not have to be implemented. Discretionary Data The CreateMSDiscretionaryData () method does not have to be implemented. C-APDU Commands The COMPUTE CRYPTOGRAPHIC CHECKSUM command does not have to be implemented. countries. State 3 – Waiting for GPO Response State 3 Flow Diagram in Figure 6.4 is changed as follows: S3 1 11 Parsing No OK? Yes 13 AFL, AIP No not empty? Yes 12 Error Indication:= PARSING ERROR 14 Error Indication:= CARD DATA MISSING 16 AIP indicates EMV mode? Yes No 18 Error Indication:= MAGSTRIPE NOT SUPPORTED A EMV mode C Invalid response countries. S3 EMV mode A 31 Set Active AFL to AFL No 34 Contactless Trx Limit:= Trx Limit without On-device CVM 33 On device cardholder verification supported? Yes 35 Contactless Trx Limit:= Trx Limit with On-device CVM 4 Symbols S3.15, S3.17, S3.30, S3.32, S3.70, S3.71, S3.72, S3.73, S3.74, S3.75, S3.76, S3.77, S3.78, S3.80 and S3.81 do not have to be implemented. countries. State 7 – Waiting for Mag-stripe Read Record Response State 7 does not have to be implemented. State 8 – Waiting for Mag-stripe First Write Flag State 8 does not have to be implemented. State 13 – Waiting for CCC Response – 1 State 13 does not have to be implemented. State 14 – Waiting for CCC Response – 2 State 14 does not have to be implemented. Data Dictionary The following data objects must not be implemented. The data objects are unknown. CVC3 (Track1) Data Object CVC3 (Track2) DD Card (Track1) DD Card (Track2) Default UDOL Failed MS Cntr Mag-stripe Application Version Number (Reader) Mag-stripe CVM Capability – CVM Required Mag-stripe CVM Capability – No CVM Required NATC(Track1) NATC(Track2) nUN PCVC3(Track1) PCVC3(Track2) PUNATC(Track1) PUNATC(Track2) Track 1 Data Track 2 Data UDOL Unpredictable Number (Numeric) countries. Kernel Configuration Bits b8 and b7 in Kernel Configuration are no longer applicable. Byte 1 b8-7 b6 b5 b4 b3-1 Kernel Configuration 00b (Not applicable) On device cardholder verification supported Relay resistance protocol supported Reserved for Payment System Each bit RFU countries.

Legal Notice

Unless the user has an applicable separate agreement with EMVCo or with the applicable payment system, any and all uses of these Specifications is subject to the terms and conditions of the EMVCo Terms of Use agreement available at www.emvco.com and the following supplemental terms and conditions. Except as otherwise may be expressly provided in a separate agreement with EMVCo, the license granted in the EMVCo Terms of Use specifically excludes (a) the right to disclose, distribute or publicly display these Specifications or otherwise make these Specifications available to any third party, and (b) the right to make, use, sell, offer for sale, or import any software or hardware that practices, in whole or in part, these Specifications. Further, EMVCo does not grant any right to use the Kernel Specifications to develop contactless payment applications designed for use on a Card (or components of such applications). As used in these supplemental terms and conditions, the term "Card" means a proximity integrated circuit card or other device containing an integrated circuit chip designed to facilitate contactless payment transactions. Additionally, a Card may include a contact interface and/or magnetic stripe used to facilitate payment transactions. To use the Specifications to develop contactless payment applications designed for use on a Card (or components of such applications), please contact the applicable payment system. To use the Specifications to develop or manufacture products, or in any other manner not provided in the EMVCo Terms of Use, please contact EMVCo. These Specifications are provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of these Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of these Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with these Specifications.

countries.