GB nº 22, EMV® Level 2 Multiple Configuration Kernel Testing – Introduction to requirements and procedures
General Bulletin No. 22 First Edition September 2004 EMV Level 2 Multiple Configuration Kernel Testing
Related Documents
This General Bulletin should be read in conjunction with:
- EMVCo Type Approval Terminal Level 2 Administrative Process, v1.2
Introduction
EMVCo has recently expanded its level 2 procedures in order to test applications kernels that support multiple configurations. These configurable kernels are those capable of changing options without impacting the core application kernel code. This bulletin serves as an introduction to the requirements and procedures necessary to test configurable kernels. The EMVCo Type Approval Terminal Level 2 Administrative Process, v1.2 contains additional details on this procedure. When an EMV level 2 application kernel is now submitted for testing the Implementation Conformance Statement (ICS) will indicate what options are classed as configurable or fixed. The ICS will also show the potential combination of these options for each deployable configuration. These deployable configurations are those that will be tested and approved. There is no limit to the number of configurations that may be defined in a single type approval submission. EMVCo believes this approach will offer considerable savings to vendors who support a configurable kernel approach. The possible areas for savings are:
- Time necessary to test a given number of deployable configurations
- Cost savings in the test expense when considering the number of deployable configurations finally approved
- Flexibility for what options are tested and approved, new option combinations may be tested and approved as needed
- Single administrative approval process for a given number of deployable configurations This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2004 Requirements for Submission EMVCo has specified a number of requirements that must be satisfied in order for a kernel to take advantage of the configurable kernel process. Most importantly, in order to qualify for this process the changing of options must not require any recompilation or linkage of the application kernel code. Changing of options must be clearly documented and easily reproducible by EMVCo recognized laboratories. Finally, the kernel must be capable of outputting a unique checksum value for each deployable configuration. This value will be uniquely derived from active or inactive options for any given configuration. Submission Procedure All level 2 kernel submissions will be accompanied by an ICS that describes what options are fixed or configurable. The ICS will also describe what the possible combinations of these options are. A traditional static application kernel may also be submitted with this ICS, all options will simply be fixed and a single configuration will be described. When submitting the ICS the vendor may also specify the baseline. The baseline is the deployable configuration that will be fully tested against the EMVCo Level 2 test plan. Other deployable configurations will receive limited incremental and regression testing. A vendor may choose not to specify the baseline, in this case the baseline defaults to the configuration with the most options active. During test, failures may be discovered in either the baseline or subsequent configurations. Depending on where the error occurs the vendor may have a choice of how to continue. Errors found in the baseline will result in a rejection of the entire kernel. Errors found in a deployable configuration may either: be repaired and the kernel resubmitted for a full test cycle, submitted for baseline approval only, or the baseline and any error-free configurations submitted for type approval. Submission of a configurable kernel report that contained failures may result in additional testing for which the vendor is responsible. All failures detected during a Type Approval shall be reported directly to EMVCo regardless of the final approval request. A configurable kernel that encounters testing failures of any kind is not eligible for the resubmission procedure, see below. Resubmission Procedure A configurable kernel that has already been approved without test failures may be resubmitted for testing of additional deployable configurations, as defined by the vendor. Resubmission testing must be conducted on the original sample stored at the test laboratory whenever possible. In instances where the kernel is no longer available, or is otherwise inoperable, the vendor may supply an identical kernel after having signed a disclaimer attesting that no modifications have been made to that kernel since last tested by a laboratory. There is no need for a vendor to return to the original testing laboratory; This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2004 however, the vendor is responsible for any shipping costs incurred in delivering the original kernel to the new laboratory. The resubmitted kernel must be accompanied with a complete ICS, again describing all configurable options and deployable configurations. The resubmitted kernel ICS must be reviewed by EMVCo before any testing may begin. EMVCo will compare the resubmitted ICS to the original and confirm there has been no change in options defined as configurable or supported values. Variation in configurable options or supported values will result in the resubmission being classed as a new device and tested accordingly. Failures identified during resubmission of a configurable kernel will require review against previously approved configurations of the same kernel. There is a possibility that specific configurations may be removed from the approval. The vendor is responsible for any additional laboratory expense incurred for this additional testing.
Conclusion
Additional details for this policy are available in the EMVCo Type Approval Terminal Level 2 Administrative Process, v1.0.2. Testing for multiple configuration kernels will be available on September 15, 2004. Comments or queries regarding this policy change can be directed to EMVCo via the standard web page communication. This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2004