Issuer Best Practice for Correct ATR Values

v1.0 Best Practices
ChipContact Acceptance DeviceCard

EMV<sup>®</sup> Interoperability Working Group Issuer Best Practice for Correct ATR Values Version1.0 October 2019

countries. Issuer Best Practice for Correct ATR Values

Legal Notice

This document summarizes EMVCo’s present plans for evaluation services and related policies and is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or non-infringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document. October 2019 v1.0

countries. Legal Notice Contents 1 Executive Summary 2 Best Practice Issuer Best Practice for Correct ATR Values Contents ii iii 1 2 October 2019 v1.0

countries. Issuer Best Practice for Correct ATR Values 1 Executive

Summary

EMVCo has identified a potential interoperability issue related to the acceptance of cards with ATR incorrectly set at very high speeds. It is important that the relevant issuers be alerted of this, and follow the best practices described below to prevent occurrence. Summary of the issue EMVCo has identified some instances of cards having their ATR set at

  • high speeds that are not supported by EMV or
  • some of the functional ATR parameters are different than the ones observed and passed under EMV Level 1 tests As an example of the non-supported speed on the ATRs, EMVCo has currently set the acceptable rate to 4x of the initial value of the speed, but some cards have been shipped to consumers with the value set as high as 32x. One of the reasons for the difference on ATR functional values is by personalisation bureaus in order to speed up the personalisation process, which are subsequently being shipped by issuers to cardholders without having the ATR set back to tested and passed values of the functional parameters. The other reason could be when the chip is delivered from the chip/module manufacturers for card production its initial ATR functional parameters may be at factory setting which may be different than the tested and passed ones. As a result, some EMV terminals are unable to process these cards with the different ATRs containing non EMV functional parameter values. The ATR values are checked as part of the payment system type approval program. Issuers are reminded to be diligent in ensuring the ATR is set to the approved values prior to the cards being shipped to the cardholder, by checking its compliance with the payment system approved values. This can be done by requesting the relevant product information from the vendor. Impacted Market Global *Should there be any actual interoperability issues reported from the field in the future, EMVCo will update the Interoperability Working Group Issues List. Severity Medium

Related Documents

None October 2019 vx.x

countries.. Issuer Best Practice for Correct ATR Values 2 Best Practice Entity Issuers Best Practice The ATR functional parameter values are critical to ensure interoperability and must be carefully configured. Issuers are reminded to be diligent in ensuring the ATR is set to the approved values prior to the cards being shipped to the cardholder, by checking its compliance with EMVCo approved values for CCD and CPA cards or with the payment system approved values for other card types. This can be done by requesting the relevant product information from the vendor. October 2019 v1.0

countries.