FAQ: Consumer Device Cardholder Verification Method (CDCVM) – General & Technical Questions

FAQs
Mobile NFC Consumer Device

Consumer Device Cardholder Verification Method (CDCVM) Frequently Asked Questions (FAQ) 1. What is Consumer Device Cardholder Verification Method (CDCVM)? With traditional Cardholder Verification Methods (CVM), consumer authentication is performed on the merchant system (a PIN entered into a merchant device, for example). The growing use of mobile devices for payment transactions has enabled consumer authentication to be performed specifically on the consumer’s own device, via passcodes, passwords and patterns, as well as through biometrics such as fingerprint, iris, voice and facial recognition. This type of authentication on a consumer device is known as CDCVM. Additionally, when multiple payment applications on the device share the same CDCVM and the associated result, it is referred to as Shared CDCVM. 2. Why is EMVCo involved in this area and what activity is it undertaking? CDCVM solutions offer convenience, simplicity and familiarity to consumers. As CDCVM is very different to traditional CVM, there are specific security, functional and performance needs. EMVCo:

  • has developed a process to evaluate the security of CDCVM,
  • has defined industry best-practices to address functional and performance considerations, and
  • is creating a central mechanism to identify a CDCVM solution. As a result, consumers and issuers stand to benefit from increased confidence, a more consistent experience and enhanced global interoperability for CDCVM solutions. 3. Is EMVCo working with any other industry bodies in this area? Yes. EMVCo has been collaborating with the FIDO Alliance since 2016 focusing on how FIDO authentication standards can support EMV<sup>®</sup> payment use cases across all areas of EMVCo activity. EMVCo continues to liaise with the FIDO Alliance to ensure the FIDO Biometric Certification programme covers EMVCo’s performance requirements. 4. What is the difference between security, performance and functional characteristics of a CDCVM? © 2019 EMVCo, LLC. All rights reserved.
  • Security - The security properties of a CDCVM Solution relate to the security of: o the environment in which verification data is captured, o the storage of the reference data and o the environment in which the captured verification data is compared with the reference data. These security properties also extend to data related to the prolonged or persistent nature of a CDCVM, as well as data related to parameters such as CDCVM retry counters.
  • Performance - The performance characteristics of a CDCVM relate to how well a biometric CDCVM solution performs in correctly capturing a biometric and matching it with a reference value. This includes metrics such as the False Acceptance Rate (FAR) and False Rejection Rate (FRR).
  • Functional - The functional characteristics of a CDCVM system are those which the CDCVM system performs supporting authentication of a consumer, excluding the security and performance characteristics. These include, restricting the number or velocity of attempts to authenticate and ensuring that reference data is of sufficient quality. 5. How is EMVCo advancing security for CDCVM solutions? EMVCo has published CDCVM Security Requirements and has established a Security Evaluation Process to help ensure CDCVM solutions maintain certain minimum levels of security, including mechanisms and protections designed to withstand known attacks. 6. How is EMVCo working to promote consistency? Current CDCVM solutions have varying functional, performance and security behaviours, so EMVCo has taken the following steps to improve consistency between these solutions.
  • EMVCo has published an EMV CDCVM Best Practices document which sets forth the guidelines to promote consistent user experience and global interoperability. This includes, for example, the length of passwords and passcodes, capture points for patterns and risk controls for incorrect attempts.
  • EMVCo has also incorporated high-level biometric performance objectives into the document, including:
  • False Acceptance Rate (FAR) - proportion of verification transactions with wrongful claims of identity that are incorrectly confirmed. © 2019 EMVCo, LLC. All rights reserved.
  • False Rejection Rate (FRR) - proportion of verification transactions with truthful claims of identity that are incorrectly denied.
  • Imposter Attack Presentation Match Rate (IAPMR) - percentage of artefacts, such as a fake fingerprint, that are incorrectly accepted.
  • EMVCo has also published EMV CDCVM Security Requirements and established a Security Evaluation Process. 7. Will EMVCo be offering a supportive testing and certification infrastructure to evaluate the performance of biometric CDCVM solutions? At this time, EMVCo is not developing its own biometrics performance evaluation program. EMVCo has liaised with the FIDO Alliance to ensure that the FIDO Alliance Biometric Certification programme covers the EMVCo high-level performance objectives. EMVCo encourages CDCVM solution providers to evaluate the performance of their solutions using the FIDO Alliance Biometric Certification programme. 8. Why is EMVCo creating an EMV CDCVM solution database? CDCVM introduces more complexity and variability than traditional CVM, which can make it difficult for issuers to identify the exact CDCVM used for a particular payment transaction. Unlike an online PIN, a CDCVM is not seen by the issuer. CDCVM solutions can use varying components on a device, encompass multiple modalities, and can be used across a large range of consumer devices manufactured by different OEMs for various markets and users. To address this challenge, EMVCo is creating an EMV CDCVM Solutions database in which each registered CDCVM solution is assigned a unique, short identifier known as an EMV CDCVM Solution ID, together with a set of related metadata of the CDCVM solutions being entered and maintained in the database. This will allow a single value to be communicated to issuers, enabling them (or a service provider acting on their behalf) to access the CDCVM solution-related metadata to potentially help build a more accurate risk profile and authorise transactions with increased confidence. 9. How can other industry stakeholders get involved? EMVCo actively engages the payment community in developing, enhancing, and evolving future specifications and related testing processes. © 2019 EMVCo, LLC. All rights reserved. EMVCo has an established Associates Programme that is open to industry stakeholders. Input is received from Associates at both technical and business levels, as well as from Subscribers, to support global interoperability and security. EMVCo encourages new participants who are interested in contributing to EMVCo’s initiatives to join the EMVCo Associates Programme or become an EMVCo Subscriber. * EMV<sup>®</sup> is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo, LLC. © 2019 EMVCo, LLC. All rights reserved.