Disposition of comments for C-8 Kernel 8 DRAFT
Draft Specification & Bulletin Industry Feedback Form Working Group: Contactless Kernel Task Force Document: EMV® Contactless Specifications for Payment Systems Book C-8 Kernel 8 Specification Version DRAFT1 February 2022 Company Name: Consolidated Comments and CKTF Feedback Primary Contact Name: EMVCo Contactless Kernel Task Force Date: 3 May 2022
countries.
CKTF Consolidated Responses – C-8 Kernel Specification DRAFT1 Comment Source1 EA/Sub Clause No./ Subclause No. / Annex Paragraph/ Figure/ Table/ Note Type of comment2 Comment (justification for change) Draft Specification & Bulletin Industry Feedback Form Proposed change Status Accept, Reject, In progress, Acknowledge EMVCo Use Only EMVCo observations on each comment submitted EA 3.9 EA 4.3 Table 3.3
ge Question: what is the background of the option to set/unset the Report local authentication failed in TVR. Would it make sense to clarify that in the document? Accept As this bit is set after the Generate AC command there may be an impact on the issuer host. With this configuration option it is possible to remove the impact. We will add a note below Table A.19 in Section A.1.73: 'Local authentication failed' bit in TVR is set after GENERATE AC command and may impact Application Cryptogram verification." ed I had to look up ASI in the glossary …. or an Algorithm Suite Indicator (ASI) Accept The change will be made. when it first appeared in the text in a list of ASIs. in 4.3. Perhaps it can be introduced like… 1 EA/Sub = EMVCo Associate or Subscriber company (enter a 2 -3 letter abbreviation for commenting) 2 Type of comment: ge = general te = technical ed = editorial – For technical comments, please indicate whether your comment is a MAJOR or MINOR technical comment.
countries. 05/04/2021
of 5
CKTF Consolidated Responses – C-8 Kernel Specification DRAFT1 Comment Source1 EA/Sub Clause No./ Subclause No. / Annex Paragraph/ Figure/ Table/ Note Type of comment2 Comment (justification for change) Draft Specification & Bulletin Industry Feedback Form Proposed change EA A.1.29
ge Would it make sense to explain the background of the difference between Card Qualifier version 1 vs. 2? I see the technical difference in processing the MAC, but it might help to explain it in human / business language. EA A.1.123 Table A.30 ed Might it help to explain the meaning of the CVM bits with the additional text “supported” like in the example at the right. There is always quite a bit of confusion about the TRMD with customers encountering it for the first time. EA 3.1 and Annex C te MAJOR Will the support of some algorithms suite (Like the Curves P521 and SM2-P256) be a configuration option ? If yes we suggest listed them in 3.1 Status Accept, Reject, In progress, Acknowledge EMVCo Use Only EMVCo observations on each comment submitted Accept Reject We will add a note below Table A.7: The difference between VERSION 1 and VERSION 2 is the algorithm used for the IAD MAC generation. In VERSION 1 the IAD is excluded as input to the generation of the IAD MAC, whereas in VERSION 2 it is included to the generation of the IAD MAC. The naming of the bits follows the same convention as other EMV data objects (e.g. Terminal Capabilities). Therefore, we will keep the current naming. Reject P-521 and SM2-P256 are not configuration options. They are not supported by Process C in the current version of the specification. 1 EA/Sub = EMVCo Associate or Subscriber company (enter a 2 -3 letter abbreviation for commenting) 2 Type of comment: ge = general te = technical ed = editorial – For technical comments, please indicate whether your comment is a MAJOR or MINOR technical comment.
countries. 05/04/2021
of 5
CKTF Consolidated Responses – C-8 Kernel Specification DRAFT1 Comment Source1 EA/Sub Clause No./ Subclause No. / Annex Paragraph/ Figure/ Table/ Note Type of comment2 Comment (justification for change) EA Sections Processing te 3.3 and between 6.3.14 to 6.3.16 states 27 and 28 Splitting the Gen AC into 2 parts will create complexity in the implementation, testing and resolving field issues. Draft Specification & Bulletin Industry Feedback Form Proposed change Status Accept, Reject, In progress, Acknowledge EMVCo Use Only EMVCo observations on each comment submitted Follow a standard EMV process over the contactless interface so the card makes the final decision before it leaves the interface and you always see the 1st Gen results from the card which are final. Reject This is probably a misunderstanding as there is only one GENERATE AC command. The GENERATE AC command is not split into 2 parts. Kernel risk management processing is split in 2 parts: before and after GENERATE AC. Therefore, the Kernel performs a second Terminal Action Analysis after the GENERATE AC command to take into account the outcome of risk management processing performed during and after the GENERATE AC command. 1 EA/Sub = EMVCo Associate or Subscriber company (enter a 2 -3 letter abbreviation for commenting) 2 Type of comment: ge = general te = technical ed = editorial – For technical comments, please indicate whether your comment is a MAJOR or MINOR technical comment.
countries. 05/04/2021
of 5
CKTF Consolidated Responses – C-8 Kernel Specification DRAFT1 Comment Source1 EA/Sub Clause No./ Subclause No. / Annex Paragraph/ Figure/ Table/ Note Type of comment2 Comment (justification for change) Draft Specification & Bulletin Industry Feedback Form Proposed change EA 4.1.3 Para 10 te Length GetLength(T) Returns NULL if the TLV Database does not include a data object with tag T. NULL cannot be returned since it is not return type of the function. In this condition the function should return Zero. EA 3.9 Table 3.3 ed EA Annex E Table E.1 ed Certificates is miss spelled as cerificates DS is missing in abbreviation table Fix the miss-spelling Add DS in abbreviations table Status Accept, Reject, In progress, Acknowledge EMVCo Use Only EMVCo observations on each comment submitted Reject Accept The function returns zero when the data object isEmpty. GetLength(T), when there is no data object in the TLV Database with tag T, should not return zero. We use NULL to signify there is no database entry, and zero to signify there is a database entry, but its length is zero. Note that this is a behavioral specification and does not follow strict source code-like syntax such as function prototypes or data type checking. The implementer may use any value that does not represent a valid length, like -1 for example. The correction will be made. Accept The change will be made. 1 EA/Sub = EMVCo Associate or Subscriber company (enter a 2 -3 letter abbreviation for commenting) 2 Type of comment: ge = general te = technical ed = editorial – For technical comments, please indicate whether your comment is a MAJOR or MINOR technical comment.
countries. 05/04/2021
of 5