Guideline for ECC Issuer Self-signed Public Key Certificates

v1.0 General Bulletin
ContactContactless

EMV SWG NK89r8 EMV® General Bulletin No. 55 First Edition August 2022 _____________________________________________________ Guideline for ECC Issuer Self-signed Public Key Certificates _____________________________________________________ This General Bulletin defines a recommended format for ECC Issuer self-signed public key certificates. Payment systems may decide individually whether to adopt the recommendation in this General Bulletin when processing Issuer certificate requests in the context of:

  • EMV Integrated Circuit Card Specifications for Payment Systems, Book 2 – Security and Key Management, Version 4.3, November 2011 as updated by Specification Bulletin 243. countries. EMV SWG NK89r8 Field Name Certificate Format Certificate Encoding Issuer Identifier Length (bytes) 1 1 5 Issuer Public 1 Key Algorithm Suite Indicator Certificate 4 Expiration Date RID Certification Authority Public Key Index Payment System Proprietary Identifier Tracking Number Issuer Public Key 5 1 4 4 NFIELD Issuer Public NSIG Key Certificate Signature

Description

Hex '28' Format b Hex '00' b Leftmost three to ten digits from the Primary Account Number (PAN), padded on the right with hex 'F's. Indicates the algorithms to be used with the Issuer Public Key that is used to verify ICC Public Key Certificates and this Issuer SelfSigned Public Key Certificate. Year, month, day (YYYYMMDD) after which this certificate is invalid. This field is also used to define the requested expiration date of the Issuer Public Key Certificate generated by the Payment System Certification Authority. Identifies the Payment System which is requested to sign the Issuer Public Key. When combined with the RID, uniquely identifies the Payment System key to be used to sign the Issuer Public Key and the associated algorithm suite. Proprietary Identifier whose usage is determined by the Payment System and whose value is assigned by Payment System or Issuer (e.g. for identifying a service). Proprietary Tracking Number whose value is assigned by Payment System or Issuer. Representation of Issuer Public Key (xcoordinate of Issuer public key point) on the curve identified by the Issuer Public Key Algorithm Suite Indicator. Output of digital signature ECC algorithm on concatenated first ten data objects using the Issuer private key on the elliptic curve identified by the Issuer Public Key Algorithm Suite Indicator. cn 10 b n 8 b b b n 8 b b

countries.

EMV SWG NK89r8

Legal Notice

This document is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or non-infringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, knowhow, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any

countries.

EMV SWG NK89r8 theory for any party's infringement of any intellectual property rights in connection with this document.

countries.