Status on UN

v1.0
Acceptance Device

EMVCo Status on UN 19th August 2015 EMV-SWG-NB00r6 This document provides status as at 19th August 2015 regarding EMVCo efforts to improve terminal Unpredictable Number (UN) generation. Communications On 24th February 2012 EMVCo added a position statement "EMV Unpredictable Number Vulnerability" (NA69r4) to the EMVCo Advisors' repository of Security Responses. This statement notes that "EMVCo will however enhance its terminal type approval process and will work with the payments industry to help ensure the quality and integrity of terminal UN generators." On 4th April 2012 EMVCo published Specification Bulletin No.103 that reminded Terminal vendors of the EMV requirements on UN generation and advised them that EMVCo will be introducing enhanced type approval testing for UNs. In June 2014 EMVCo published Specification Bulletin No. 144 specifying an EMV algorithm for generating UNs. Enhanced testing EMVCo introduced enhanced testing for terminal UN generation in November 2012. These tests (published as test cases 2cc.145.00 and 2cc.145.01) are designed to be practical for type approval laboratories to implement and yet good enough to detect most of the bad UN generators that have been seen in the field. These tests are statistical in nature and although they may detect a flawed or broken generator, they cannot substitute for a proper 'white box' evaluation of the design of the UN generator (see later). The Terminal Approval Implementation Conformance Statement has been updated to include questions regarding implementations of UN generators and whether they use a hardware random number generator and/or the EMV UN Algorithm. Guidance and Schema In May 2012 EMVCo published a new document called the EMV Acquirer and Terminal Security Guidelines. This document contained a section that provides additional guidance and recommendations on UN generation and provides a Schema for how UN generation might be implemented in software. The guidance notes that although a Random Number Generator (RNG) used for EMV Offline Enciphered PIN, and hence evaluated by PCI PTS, might produce UNs of an acceptable quality, it is preferable to apply conditioning to the RNG output before using as a UN and the UN Schema is given as an example of such conditioning. White-box security evaluation As already noted, any full evaluation of a terminal's UN generator involves 'white-box' security evaluation, i.e. evaluating the design rather than only its output. PCI PTS

security evaluators have the skills for such tasks (they must evaluate the RNG used for EMV Offline Enciphered PIN), however UN generation might also be influenced by the Payment Application and fall under PCI PA-DSS. EMVCo has collaborated with PCI SSC to include this type of security evaluation in the PCI SSC security evaluation programme. PCI PTS has now done this in their latest specifications. IWG investigations on deployed terminals The EMVCo IWG has worked with the vendors of identified kernels to correct the problem in deployed terminals. It should be noted however that in some circumstances the generation of UNs is performed in the application software and not in the EMV kernel and in these cases it is less clear what EMVCo and terminal vendors can achieve. UN Algorithm The EMV SWG has now designed an algorithm for generating UNs. This has been presented to the EMV Technical Associates and undergone external expert security evaluation. The algorithm has been published as Specification Bulletin 144 in June 2014. Other actions As noted above, it is not feasible for EMVCo and terminal vendors to address all deployed terminals. In many cases therefore it will require the intervention of acquirers, merchants and their service providers to correct weak UN generators. ----oo0oo----