EMVCo Statement – EMVCo Security Evaluation Processes for IoT Products
EMVCo Statement – EMVCo Security Evaluation Processes for IoT Products In an increasingly connected world, use cases across various IoT verticals now require payment functionality. This includes retail and e-commerce, smart home and entertainment, consumer wearables and mobile payment applications, consumer electronic products, and multiple transportation solutions. EMVCo’s existing security evaluation methodologies and processes can support emerging IoT payment use cases. Device Hardware Security Assessments Device hardware evaluations play an important role with respect to IoT assessments across various IoT payment use cases, security frameworks and emerging compliance models. Since 2005, EMVCo has evaluated the security of EMV<sup>®</sup> Integrated Circuit (IC), Platform and Integrated Circuit Card (ICC) products, and more recently alternative hardware form factors, such as embedded Secure Elements (eSE) and System on Chips (SoC). EMV evaluations also consider post-issuance and personalisation to support the product lifecycle. EMVCo acts as a security certification entity for all these EMV products, and also develops and maintains security requirements and guidance for vendors. The EMVCo Security Evaluation Process reflects a collaboration with independent, recognised security laboratories around the world performing security evaluations, and supports the work of JIL Hardware Attacks Subgroup (JHAS) to facilitate industry alignment. As a result, the current EMVCo Security Evaluation Process can address various IoT hardware solutions and devices quickly and efficiently, except where devices are so constrained that they cannot provide an acceptable security baseline. Device Software Security Assessments In 2018, EMVCo established a Security Evaluation Process for Software-Based Mobile Payments (SBMP) to support the evaluation of payment applications, firmware, and software on mobile devices. This process supports security assessments of various interfaces and payment security functional requirements of IoT products. This includes on-device and off-device security services, such as pre- and post-personalisation services, attestation services relying on © 2019 EMVCo, LLC. All rights reserved.
device and consumer identity verification, and secure data transport providing payment data confidentiality and integrity. These services are important to the overall trust framework required for payment solutions, and are applicable to most IoT security assessment models emerging today. Flexible Security Evaluation Processes for IoT Products The EMVCo Security Evaluation Processes enable both ‘component’ and ‘integration’ evaluations. This allows components to be evaluated either independently or together in order to assess the security of the overall solution. This flexible process is ideal for emerging IoT verticals where both payment software and hardware certifications are needed. Please contact the EMVCo Security Evaluation Secretariat to express your interest in an EMVCo evaluation. *** As card-based payment solutions continue to emerge across various IoT verticals, EMVCo expects to support new use cases and functionalities. This may include further enhancements to security requirements and guidelines. In addition, EMVCo expects to liaise with other industry bodies and regulators as payment certifications emerge. EMVCo actively engages the payment community in developing, enhancing, and evolving future specifications and related testing processes. EMVCo encourages new participants who are interested in contributing to EMVCo’s initiatives to join the EMVCo Associates Programme or become an EMVCo Subscriber. – ENDS – EMV<sup>®</sup> is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo, LLC. © 2019 EMVCo, LLC. All rights reserved.