TTA Bulletin nº 31: Contact Terminal Level 2 – Unutilized Functions for EMV® Application Kernels

v6.0 Type Approval Bulletins
ChipContact Acceptance Device

EMV<sup>®</sup> Terminal Type Approval Bulletin No. 31 Sixth Edition, August 2018 Contact Terminal Level 2 Type Approval Unutilized Functions for EMV Application Kernels

Applicability

  • This Bulletin applies to all approved EMV Application Kernels

Related Documents

This Bulletin should be read in conjunction with:

  • EMVCo Type Approval Terminal Administrative Process
  • Type Approval Bulletin #11, Major and Minor Change

Definitions

Effective Date

  • Immediate

Description

This bulletin describes the concept of functions being unutilized or hidden. Vendors may utilize this process to hide specific functions of the kernel without altering the kernel or jeopardizing their EMVCo approval. Some functions defined by EMV specifications are reliant upon input that comes from outside the kernel. Such examples of these are inputting Cashback amounts or loading Exception Lists into the terminal. Without such input, specific processing by the EMV kernel will not occur during a transaction. If the vendor can effectively remove such input without changing the kernel, then the function specifically related to that input can be considered unutilized. In order for a vendor to utilize this process, the vendor must conform to the following requirements:

  • The EMV Application Kernel must have been approved by EMVCo with the new checksum requirement
  • The kernel and its checksum must not change when hiding a specific function. Hiding a function must occur outside of the kernel
  • A function can only be hidden. New functions cannot be added that were not identified in the original approved EMV Application Kernel.
  • Only the below functions will be recognized as being able to be hidden. countries. The following are functions/capabilities that a vendor may hide in an approved EMV Application Kernel or in an approved Contactless Product. If such functions are hidden following the requirements above, EMVCo will not require re-approval by vendor. As vendors are intimately familiar with their developed components, it is ultimately the vendor’s responsibility to make the determination whether a function, within the below list, may be hidden. EMV Application Kernel Terminal Capabilities
  • Cash – Cash transaction may be hidden by not allowing this transaction type in the terminal
  • Goods – Goods transaction may be hidden by not allowing this transaction type in the terminal
  • Services - Services transaction may be hidden by not allowing this transaction type in the terminal
  • Cashback - Cashback may be hidden by not allowing this transaction type in the terminal Application Selection
  • Preferred Order - This function may be hidden by loading an empty list into the terminal (provided the preferred order is stored in a list in the terminal) Data Authentication
  • Key Revocation Check – This function may be hidden by loading an empty key revocation list into the terminal Cardholder Verification Method
  • PIN Bypass – This function may be hidden by removing the prompt on the terminal that normally allows the merchant to bypass PIN entry Terminal Risk Management
  • Exception File – This function may be hidden by loading an empty exception file into the terminal
  • Transaction log – This function may be hidden if the number of transactions to be stored is a parameter with value starting from 0; when this value is set to 0, no transaction will be stored which means that transaction log is not supported. Terminal Action Analysis
  • Terminal Action Codes deletion – This function may be hidden by not allowing the deletion of the Terminal Action Codes. Completion Processing
  • Force Online – This function may be hidden by removing the prompt on the terminal that normally allows the merchant to force a transaction online
  • Force Acceptance - This function may be hidden by removing the prompt on the terminal that normally allows the merchant to force a transaction to be approved Miscellaneous
  • Receipts - This function may be hidden by not issuing receipts.
  • Declined transactions storage - This function may be hidden by not storing declined transactions. countries. Acquirer Interface
  • Advice Messages – This function may be hidden by not creating advice messages when ICC indicates in the CID that Advice is required and the advice function is supported by the terminal but not supported by the terminal-acquirer interface protocol. The terminal shall not terminate the transaction under the above circumstances and it’s the responsibility of the terminal vendor and/or acquirer to ensure this requirement is met.
  • Online Data Capture and Batch Data Capture – This function may be hidden when the following conditions are met: 1. A terminal that is type approved to support both Online Data Capture and Batch Data Capture in single configuration- features identified in the ICS (Implementation Conformance Statement). 2. Terminal is capable of activating both or unutilized (hide)-either data capture method without impacting the Kernel or transaction itself. 3. Functions of Online Data Capture and Batch Data Capture are supported within the Application Layer and not in the Kernel. Multi Language support
  • When present, this function may be hidden or removed. EMV Contactless Product Language Preference in the User Interface
  • When present, this function may be hidden or removed. Autorun Parameter
  • When present, this function may be activated or deactivated. Other functions may be added to the list as EMVCo conducts further review. countries.

Legal Notice

This document summarizes EMVCo’s present plans for evaluation services and related policies and is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or noninfringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document.

countries.