SB n° 221: Entry Point Request Online PIN Outcome and Zero Amount in Offline Transactions

v1.0 Specification Bulletins
Contactless Acceptance Device

EMV<sup>®</sup> Specification Bulletin No. 221 First Edition June 2019 Entry Point Request Online PIN Outcome and Zero Amount in Offline Transactions This Specification Bulletin introduces a new outcome of Request Online PIN. The new outcome enables the issuer to request Online PIN after an Online Authorisation Request.

  • This Specification Bulletin also introduces a new pre-processing flag to allow zero amount to be used in offline transactions.

Applicability

This Specification Bulletin applies to:  EMV Contactless Specifications for Payment Systems: Book A, Version 2.7  EMV Contactless Specifications for Payment Systems: Book B, Version 2.7 Related Documents  EMV Contactless Specifications for Payment Systems: Book A, Version 2.8  EMV Contactless Specifications for Payment Systems: Book B, Version 2.8 Effective Date  Specification: Effective immediately  Testing: January 2020

Description

When a contactless card or mobile payment device performs a low value transaction with No CVM that goes online, the issuer may return a request for the Kernel to instruct the POS Application to request online PIN. The new request, "Request online PIN", is returned in the Authorisation Response. After Online PIN is performed, the POS Application presents again the same data from the previous authorisation along with the additional PIN data. In order to implement this functionality a new Final Outcome "Request Online PIN" is defined. The pre-processing requirements have also been updated for Zero value offline transactions.

countries.

countries.

Book A Architecture and General Requirements: Changes In 5.3 Logical Architecture, replace Figure 5-2: Logical Architecture, with the following diagram. Terminal Amount, Type of TX, Other TX data IAD, Issuer Scripts Online Authorisation Additional Processing ●CVM ●Online Auth ●…... Other Services: Exception files, Etc. Figure 5 2: Logical Architecture Reader New Transaction Restart Start Var Amount A Fixed Amount B C D Additional Functionalities: UN, Amount, Configuration Handling, UI, Removal Procedure Other Services: Field control, UI, etc. Request Processing Data Exchange Entry Point Pre-processing Protocol Activation Combination Selection Kernel Activation Kernel Processing Outcome Processing Final Outcome Functions in scope of EMV CL Specs Not in scope End Application Request Online PIN Try Another I/F Online Request Declined Approved Try Again Select Next

countries.

In 5.6.5 Kernel and Entry Point Configuration Data, replace Table 5-2: Entry Point Configuration Data per Combination with the following table. Table 5 2: Entry Point Configuration Data per Combination Status Check Support flag, if present Zero Amount Allowed flag, if present Zero Amount for Offline Allowed flag, if present Reader Contactless Transaction Limit, if present Reader Contactless Floor Limit, if present Terminal Floor Limit (Tag '9F1B'), if present Reader CVM Required Limit, if present Terminal Transaction Qualifiers, if present Extended Selection Support flag, if present In 5.7 Transaction Data change the following text as described. Existing text… 5.7 Transaction Data Entry Point uses the data sets described in section 5.6.5 during Pre-Processing to compute the Entry Point Pre-Processing Indicators for each combination, as defined in Table 5-3. The indicators are made available to the kernel selected by Entry Point. Entry Point temporarily stores the computed indicators to support selection of another combination for the same transaction or reactivation of a kernel after an Online Request Outcome. New text… 5.7 Transaction Data Entry Point uses the data sets described in section 5.6.5 during Pre-Processing to compute the Entry Point Pre-Processing Indicators for each combination, as defined in Table 5-3. The indicators are made available to the kernel selected by Entry Point. Entry Point temporarily stores the computed indicators to support selection of another combination for the same transaction or reactivation of a kernel after an Online Request Outcome or a Request online PIN Outcome.

countries.

In 6.1 Outcomes change the following text as described. Existing text… 6.1 Outcomes The following Outcomes are defined:  Select Next  Try Again  Approved  Declined  Online Request  Try Another Interface  End Application New text… 6.1 Outcomes The following Outcomes are defined:  Select Next  Try Again  Approved  Declined  Online Request  Request Online PIN  Try Another Interface  End Application

countries.

In 6.1 Outcomes replace Table 6-1: Outcomes, with the following new table. Outcome Select Next Try Again Table 6 1: Outcomes Description The kernel has determined that the selected Combination is unsuitable and the next Combination (if any) should be tried. Kernel Creates Outcome, passes to Entry Point The kernel wishes that a card be presented again; this may be a result of an error, such as tearing, that could resolve if the transaction is attempted again. It is one way a kernel may handle a mobile device that requires a confirmation code to be entered. Entry Point Processes Outcome Reader/ Terminal No processing

countries.

Outcome Approved Declined Online Request Request Online PIN Description The kernel is satisfied that the transaction is acceptable with the selected contactless card application and wants the transaction to be approved. This is the expected Outcome for a successful offline transaction. This might also occur following reactivation of a kernel after an online response. The kernel has found that the transaction is not acceptable with the selected contactless card application and wants the transaction to be declined. This might also occur following reactivation of a kernel after an online response. The transaction requires an online authorisation to determine the approved or declined status. If the kernel wishes to be restarted when the response has been received (e.g. to receive issuer update data), then this is indicated in the parameters. The issuer has requested Online PIN in the Authorisation Response Code after the transaction has gone online i.e. after the Online Request outcome. Kernel Creates Outcome, passes to Entry Point Entry Point  Processes selected Outcome parameters  Passes Outcome to reader as a Final Outcome Reader/ Terminal Processes the Final Outcome

countries.

Outcome Try Another Interface Description Either of the following:  The kernel is unable to complete the transaction with the selected contactless card application, but knows from the configuration data that another interface (e.g. contact or magnetic-stripe) is available. The kernel could indicate a preference for the alternate interface.  Entry Point was unable to identify a contactless card application that could complete the transaction and returns control to the POS System, which might attempt a different interface. Kernel May create Outcome and pass it to Entry Point Entry Point Either of the following:  Receives Outcome from kernel, processes selected Outcome parameters, and passes Outcome to reader as a Final Outcome  Under exception conditions, creates Outcome and passes it to reader Reader/ Terminal Processes the Final Outcome

countries.

Outcome End Application Description Any of the following:  The kernel has completed processing and requires no further action.  The kernel wished to restart after the card has been removed. It is one way a kernel may handle a mobile device that requires a confirmation code to be entered.  The kernel experienced an application error, such as missing data, that will not resolve if the transaction is attempted again with the same selected contactless card application.  Entry Point was unable to identify a contactless card application that could complete the transaction with the current card and wants the POS System to direct the cardholder to present another card. Kernel Entry Point Reader/ Terminal

countries.

In 6.2 Outcome Parameters, replace Table 6-2: Outcome Parameter with the following table. Outcome Parameter Start Description Indicates whether Entry Point should be restarted after the Outcome has been processed, and which Entry Point start location should be used. Typically used in conjunction with an online request and allows for issuer risk management via a variety of approaches, such as a "second presentment" or "present and hold". It may also be used to allow card removal to be confirmed, before a kernel is restarted. Values B C D N/A Meaning of Value Restart Entry Point from Protocol Activation. If the same card is present, the same kernel will be selected.  Used by Online Request for "two presentments".  Used by End Application to confirm card removal before restart.  Used by Try Again, which is processed by Entry Point. Restart Entry Point from Combination Selection. Currently only used by Select Next processed internally by Entry Point. Restart Entry Point from Kernel Activation. The same kernel will be selected. There will be no removal procedure and the field will stay on. Used by Online Request for "present and hold" and Request Online PIN for the second submission of online data after entry of online PIN. Do not restart Entry Point.

countries.

This page is BLANK

countries.

In 6.3 Outcome Processing, replace the Online Request section of Table 6-3: First Final Outcome, with the new table section. Existing table section… Table 6 3: First Final Outcome First Final Outcome Online Request POS System Processing  The POS System advises the cardholder that an online transaction is in progress. An initial message to the cardholder might have been displayed as a result of the kernel including a User Interface Request with the Outcome. If a PIN CVM is required, then the message directs the cardholder to enter the PIN.  The terminal initiates an online authorisation request, using the data record provided with the Outcome. If the CVM is online PIN, then the terminal processes and submits the encrypted online PIN.  The terminal receives the online response or might determine that the request was unable to go online.  If the Start parameter was any value other than ‘N/A’, then:  The terminal makes available the transaction disposition in the online response together with all of the EMV TLV data elements present.  The reader reactivates Entry Point by continuing with ‘Requirements – Online Response – Restart’ on

4.  The terminal determines the transaction disposition, based on the online response indication (with Unable To Go Online a decline).  The terminal advises the cardholder of the transaction outcome.  If a cardholder receipt is required, the terminal prints it or provides it electronically (e.g. email).  The terminal captures CVM signature or online PIN if requested.  The terminal prepares a clearing record if transaction disposition is "approved".  Once complete, continue with ‘Requirements – New Transaction Preparation and Start’ on

9.

countries.

New table section… Table 6 3: First Final Outcome First Final Outcome POS System Processing Online Request  The POS System advises the cardholder that an online transaction is in progress. An initial message to the cardholder might have been displayed as a result of the kernel including a User Interface Request with the Outcome. If a PIN CVM is required, then the message directs the cardholder to enter the PIN.  The terminal initiates an online authorisation request, using the data record provided with the Outcome. If the CVM is online PIN, then the terminal processes and submits the encrypted online PIN.  The terminal receives the online response or might determine that the request was unable to go online.  If the Start parameter was any value other than ‘N/A’, then:  The terminal makes available the transaction disposition in the online response together with all of the EMV TLV data elements present.  The reader reactivates Entry Point by continuing with ‘Requirements – Online Response – Restart’ on

1.  The terminal determines the transaction disposition, based on the online response indication (with Unable To Go Online a decline).  If the outcome is Approve or Decline, then:  The terminal advises the cardholder of the transaction outcome.  If a cardholder receipt is required, the terminal prints it or provides it electronically (e.g. email).  The terminal captures CVM signature or online PIN if requested.  The terminal prepares a clearing record if transaction disposition is "approved".  Once complete, continue with ‘Requirements – New Transaction Preparation and Start’ on

6.

countries.

In 6.3 Outcome Processing, replace Table 6-4: Second Final Outcome (Following an online Request), with the following new table. Table 6-4: Second Final Outcome (Following an Online Request) Second Final Outcome Approved Declined Online Request Try Another Interface POS System Processing  The terminal determines the transaction disposition as "approved".  The POS System advises the cardholder of the transaction outcome.  If a cardholder receipt is required, the terminal prints it or provides it electronically (e.g. email).  The terminal captures CVM signature if requested.  The terminal prepares a clearing record.  Once complete, continue with ‘Requirements – New Transaction Preparation and Start’ on

6.  The terminal determines the transaction disposition as "declined". (This overrules an "approved" in the online response).  The POS System advises the cardholder of the transaction outcome.  Once complete, continue with ‘Requirements – New Transaction Preparation and Start’ on

6. Not applicable. Not applicable.

countries.

Second Final Outcome Request Online PIN End Application POS System Processing  The POS System advises the cardholder that an online transaction is in progress. An initial message to the cardholder might have been displayed as a result of the kernel including a User Interface Request with the Outcome. The issuer has determined in the Online Request that Online PIN CVM is required, therefore the message directs the cardholder to enter their PIN.  The terminal processes and submits the encrypted online PIN CVM. With the additional online PIN data result, the terminal initiates an online authorisation request, using the data record provided with the Outcome, which is the same data as the previous Online Request. The terminal receives the online response or might determine that the request was unable to go online.  If the Start parameter was any value other than `N/A', then:  The terminal makes available the transaction disposition in the online response together with all of the EMV TLV data elements present.  The reader reactivates Entry Point by continuing with `Requirements

  • Online Response
  • Restart' on 4.  The terminal determines the transaction disposition, based on the online response indication (with Unable To Go Online a decline).  The terminal advises the cardholder of the transaction outcome.  If a cardholder receipt is required, the terminal prints it or provides it electronically (e.g. email).  The terminal prepares a clearing record if transaction disposition is "approved".  Once complete, continue with `Requirements
  • New Transaction Preparation and Start' on 9.  The terminal determines the transaction disposition according to the online response indication.  The POS System advises the cardholder of the situation.  The terminal continues according to its environment and acceptance rules.  Once complete, continue with ‘Requirements – New Transaction Preparation and Start’ on 6. countries. In 6.3 Outcome Processing, add the new Table 6-5: Third Final Outcome (Following a Request Online PIN). Table 6-5: Third Final Outcome (Following a Request Online PIN) Third Final Outcome Approved Declined Online Request Try Another Interface Request Online PIN End Application POS System Processing  The terminal determines the transaction disposition as "approved".  The POS System advises the cardholder of the transaction outcome.  If a cardholder receipt is required, the terminal prints it or provides it electronically (e.g. email).  The terminal captures CVM signature if requested.  The terminal prepares a clearing record.  Once complete, continue with ‘Requirements – New Transaction Preparation and Start’ on 6.  The terminal determines the transaction disposition as "declined". (This overrules an "approved" in the online response).  The POS System advises the cardholder of the transaction outcome.  Once complete, continue with ‘Requirements – New Transaction Preparation and Start’ on 6. Not applicable. Not applicable. Not applicable.  The terminal determines the transaction disposition according to the online response indication.  The POS System advises the cardholder of the situation.  The terminal continues according to its environment and acceptance rules.  Once complete, continue with ‘Requirements – New Transaction Preparation and Start’ on 6. countries. After appendix section B.7 Online Request (for "Present and Hold"), add the following section at B.8, and rename existing appendix sections B.8 through B.11 to new numbering of B.9 through B.12. B.8 Request Online PIN The kernel has determined that the Issuer is requesting that Online PIN entry is required.  Start: D  Online Response Data: Any  CVM: Online PIN  UI Request on Outcome Present: Yes
  • Message Identifier: '1B' ("Authorising, Please Wait")
  • Status: Processing  UI Request on Restart Present: Yes
  • Message Identifier: '16' ("Processing")
  • Status: Processing  Data Record Present: Yes  Discretionary Data Present: Yes or No  Alternate Interface Preference: N/A  Receipt: Yes or N/A  Field Off Request: N/A  Removal Timeout: set by kernel countries. Book B Entry Point Specification: Changes In Section 3 Entry Point Functionality in Table 3-1: Starting Points, update the row for Start D as follows. Existing table row… Start D Table 3 1: Starting Points Kernel Activation Activated by the reader to handle issuer responses after an Online Request Outcome with parameter Start = D. New table row… Start D Table 3 1: Starting Points Kernel Activation Activated by the reader to handle issuer responses after an Online Request or Request Online PIN Outcome with parameter Start = D. And replace the fourth paragraph following the table as described. Existing text… Entry Point activates the card and selects the appropriate kernel, which then conducts the contactless transaction with the card, until it finishes with an Outcome. Try Again and Select Next Outcomes are immediately processed by Entry Point, which re-starts at the appropriate point. All other Outcomes are considered to be Final Outcomes and processing reverts to the reader and terminal. In some cases, such as Approved or Declined Outcomes, the transaction is complete and no further processing from Entry Point and the kernel is required. In other cases, such as an Online Request Outcome, then after the reader and terminal have dealt with the expected functionality, if applicable, Entry Point will be started at the requested Start so that a kernel can complete the transaction. countries. New text… Entry Point activates the card and selects the appropriate kernel, which then conducts the contactless transaction with the card, until it finishes with an Outcome. Try Again and Select Next Outcomes are immediately processed by Entry Point, which re-starts at the appropriate point. All other Outcomes are considered to be Final Outcomes and processing reverts to the reader and terminal. In some cases, such as Approved or Declined Outcomes, the transaction is complete and no further processing from Entry Point and the kernel is required. In other cases, such as an Online Request or Request Online PIN Outcome, then after the reader and terminal have dealt with the expected functionality, if applicable, Entry Point will be started at the requested Start so that a kernel can complete the transaction. And replace Figure 3-1: Entry Point High Level Architecture with the following figure. Figure 3 1: Entry Point High Level Architecture Reader Card External Data Entry Point Start A Pre-processing B Protocol Activation C Combination Selection D Kernel Activation Kernel Processing Outcome Processing Select PPSE ADF Names + Kernel IDs Select AID FCI C-APDU R-APDU... End Application Request Online PIN Try Another I/F Online Request Declined Approved Try Again Select Next Final Outcome External Processing countries. In section 3.1 Pre-Processing – Start A, updated note 2 as follows. Existing text… 2 This is a payment system specific tag used by Kernel 3. New text… 2 This is a payment system specific tag used by Kernels 3, 6 and 7. In section 3.1.1 Pre-Processing Requirements replace requirement 3.1.1.4 as described. Existing text… 3.1.1.4 If the value of Amount, Authorised is zero, then:  If the Zero Amount Allowed flag is present and the Zero Amount Allowed flag is 0, then Entry Point shall set the ‘Contactless Application Not Allowed’ indicator for the Combination to 1.  Otherwise, Entry Point shall set the ‘Zero Amount’ indicator for the Combination to 1. New Text… 3.1.1.4 If the value of Amount, Authorised is zero, then:  If the Zero Amount for Offline Allowed flag is present and the Zero Amount for Offline Allowed flag is 1, then Entry Point shall proceed with next requirement 3.1.1.5.  Otherwise,
  • If the Zero Amount Allowed flag is present and the Zero Amount Allowed flag is 0, countries. then Entry Point shall set the ‘Contactless Application Not Allowed’ indicator for the Combination to 1.
  • Otherwise, Entry Point shall set the ‘Zero Amount’ indicator for the Combination to 1. In 3.5 Outcome Processing, change the following text as described. Existing text… 3.5 Outcome Processing Each kernel finishes its processing by providing an Outcome with parameters. Some Outcomes, such as Try Again and Select Next are processed immediately by Entry Point which re starts processing at the appropriate start. The rest, such as Approved and Online Request are passed to the reader as a Final Outcome together with the parameters and associated data. New text… 3.5 Outcome Processing Each kernel finishes its processing by providing an Outcome with parameters. Some Outcomes, such as Try Again and Select Next are processed immediately by Entry Point which re starts processing at the appropriate start. The rest, such as Approved, Online Request and Request Online PIN are passed to the reader as a Final Outcome together with the parameters and associated data. countries.

Legal Notice

The EMV<sup>®</sup> Specifications are provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV<sup>®</sup> Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV<sup>®</sup> Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV<sup>®</sup> Specifications

countries.