EMVCo Statement – Consumer Device Cardholder Verification Method (CDCVM)
EMVCo Statement – Consumer Device Cardholder Verification Method (CDCVM) The deployment of Consumer Device Cardholder Verification Method (CDCVM) solutions across the payments ecosystem is increasing. EMVCo is therefore working to promote confidence and consistency by identifying and addressing specific security, functional and performance needs. With traditional Cardholder Verification Methods (CVM), consumer authentication is performed on the merchant system (a PIN entered into a merchant device, for example). The growing use of mobile devices for payment transactions has enabled consumer authentication to be performed specifically on the consumer’s own device, via passcodes, passwords and patterns, as well as through biometrics such as fingerprint, iris, voice and facial recognition. This type of authentication on a consumer device is known as CDCVM. Additionally, when multiple payment applications on the device share the same CDCVM and the associated result, it is referred to as Shared CDCVM. As CDCVM is very different to traditional CVM, EMVCo has developed a dedicated process to evaluate the security of CDCVM solutions, defined industry best-practices to address functional and performance considerations and is creating a central mechanism to enable issuers and other participants to identify CDCVM solutions.
- EMV<sup>®</sup> CDCVM Security Requirements and Security Evaluation Process To help promote protection from fraud across the consumer and wider payments ecosystem, it is imperative that CDCVM solution assets (such as a user’s biometric or password) be adequately secured. Also, the delivery of a CDCVM result must not be manipulated, falsified or exploited, and the CDCVM solution must not be maliciously abused, disabled or bypassed. To support these objectives, EMVCo has published CDCVM Security Requirements and has established a Security Evaluation Process to help ensure CDCVM solutions maintain certain minimum levels of security, including mechanisms and protections designed to withstand known attacks.
- EMV CDCVM Best Practices Current CDCVM solutions have varying functional and performance behaviours. © 2019 EMVCo, LLC. All rights reserved. EMVCo has therefore published an EMV CDCVM Best Practices document, which defines guidelines for functional and performance behaviours to promote a consistent user experience and global interoperability. EMVCo has incorporated high-level biometric performance objectives into the document, including False Acceptance Rate (FAR), False Rejection Rate (FRR) and Imposter Attack Presentation Match Rate (IAPMR). EMVCo has also been collaborating with the FIDO Alliance since 2016 focusing on how FIDO authentication standards can support EMV payment use cases across all areas of EMVCo activity. EMVCo continues to liaise with the FIDO Alliance to ensure that the FIDO Alliance Biometric Certification programme covers the EMVCo high-level performance objectives. CDCVM solution providers are encouraged to evaluate the performance of their solutions using the FIDO Alliance Biometric Certification programme.
- EMV CDCVM Solution ID and Database EMVCo is creating an EMV CDCVM solutions database in which each registered CDCVM solution is assigned a unique, short identifier known as an EMV CDCVM Solution ID, together with a set of related metadata of the CDCVM solutions being entered and maintained in the database. This will allow a single value to be communicated to issuers, enabling them (or a service provider acting on their behalf) to access the CDCVM solution-related metadata to potentially help build a more accurate risk profile and authorise transactions with increased confidence. *** EMVCo actively engages the payment community in developing, enhancing, and evolving future specifications and related testing processes. EMVCo has an established Associates Programme that is open to industry stakeholders. Input is received from Associates at both a technical and business level, as well as Subscribers, to support global interoperability and security. EMVCo encourages new participants who are interested in contributing to EMVCo’s initiatives to join the EMVCo Associates Programme or become an EMVCo Subscriber. * EMV<sup>®</sup> is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo, LLC. © 2019 EMVCo, LLC. All rights reserved.