Change Tracked C-8 Kernel 8 DRAFT

v2.0 Draft Specification
Contactless Acceptance Device

EMV® Contactless Specifications for Payment Systems Book C-8 Kernel 8 Specification Version DRAFT2 April 2022

countries.

April 2022

countries.

1. 1. 1. 1. 1. 1.5. 1.5. 1.5. 2. 2. 2.2. 2.2. 2.2. 2.2. 2.2. 2.2. 2. 3. 3. 3. 3. 3.4. 3.4. 3.4. 3.4. 3. 3. April 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 3. 3. 3. 4. 4.1. 4.1. 4.1. 4.1. 4. 4. 4. 4. 4. 4. 4.7. 4.7. 4. 5. 5. 5.2. 5.2. 5.2. 5.2. 5. 5.3. 5.3. 5.3. 5.3. 5. 5.4. 5.4.

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Contents 5.4.3 5.4. 5. 5.5. 5.5. 5.5. 5.5. 5. 5.6. 5.6. 5.6. 5.6. 5. 5.7. 5.7. 5.7. 5.7. 6. 6. 6. 6.3. 6.3. 6.3. 6.3.

6.3.5 State 21 – Waiting for Exchange Relay Resistance Data Response... 97 6.3. 6.3. 6.3. 6.3. 6.3. 6.3. 6.3. 6.3. 6.3. April 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 6.3.15 6.3.16 6.3.17 6.3.18 6.3. 6. 6.4. 6.4. 7. 7. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 8 8.1 8.2 8.3 8.4 8.5 8. A. A.1. A.1.

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Contents A.1.3 A.1.4 A.1.5 A.1.6 A.1.7 A.1.8 A.1.9 A.1.10 A.1.11 A.1.12 A.1.13 A.1.14 A.1.15 A.1.16 A.1.17 A.1.18 A.1.19 A.1.20 A.1.21 A.1.22 A.1.23 A.1.24 A.1.25 A.1.26 A.1.27 A.1.28 A.1.29 A.1.30 A.1.31 A.1.32 A.1.33 A.1.34 A.1.35 A.1.36 A.1.37 A.1. April 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 A.1.39 A.1.40 A.1.41 A.1.42 A.1.43 A.1.44 A.1.45 A.1.46 A.1.47 A.1.48 A.1.49 A.1.50 A.1.51 A.1.52 A.1.53 A.1.54 A.1.55 A.1.56 A.1.57 A.1.58 A.1.59 A.1.60 A.1.61 A.1.62 A.1.63 A.1.64 A.1.65 A.1.66 A.1.67 A.1.68 A.1.69 A.1.70 A.1.71 A.1.72 A.1.

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Contents A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. April 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A. A.

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Contents B. B. April 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec DRAFT2

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 1 Using This Manual 1.1

Purpose

This document, EMV Contactless Specifications for Payment Systems, Book C-8 – Kernel 8 Specification, should be read in conjunction with:

  • EMV Contactless Specifications for Payment Systems, Book A – Architecture and General Requirements, hereafter referred to as [EMV Book A], and
  • EMV Contactless Specifications for Payment Systems, Book B – Entry Point Specification, hereafter referred to as [EMV Book B]. This document defines the behaviour of the Kernel used in combination with cards having a Kernel Identifier indicating Kernel 8, as defined in [EMV Book B].

1.2 Audience This specification is intended for use by manufacturers of contactless readers and terminals. It may also be of interest to manufacturers of contactless cards and to financial institution staff responsible for implementing financial applications in contactless cards.

1.3 Related Information The following references are used in this document

It is noted that the latest version applies unless a publication date is explicitly stated. Reference [EMV Book 1] Document Title Integrated Circuit Card Specifications for Payment Systems – Book 1, Application Independent ICC to Terminal Interface Requirements, Version 4.3, November 2011 [EMV Book 2] Integrated Circuit Card Specifications for Payment Systems – Book 2, Security and Key Management, Version 4.3, November 2011 [EMV Book 3] Integrated Circuit Card Specifications for Payment Systems – Book 3, Application Specification, Version 4.3, November 2011

April 2022

countries.

1 Using This Manual 1.3 Related Information EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Reference [EMV Book 4] [EMV Book A] [EMV Book B] [EMV CL L1] [ISO 639-1] [ISO 3166-1] [ISO 4217] [ISO/IEC 7813] [ISO/IEC 7816-4] [ISO/IEC 7816-5] [ISO 8583:1987] [ISO 8583:1993] [ISO/IEC 8825-1] [ISO/IEC 8859] Document Title Integrated Circuit Card Specifications for Payment Systems – Book 4, Cardholder, Attendant, and Acquirer Interface Requirements, Version 4.3, November 2011 EMV Contactless Specifications for Payment Systems, Book A – Architecture and General Requirements, Version 2.10 EMV Contactless Specifications for Payment Systems, Book B – Entry Point Specification, Version 2.10 EMV Level 1 Specifications for Payment Systems, EMV Contactless Interface Specification, Version 3.1 Codes for the representation of names of languages – Part 1: Alpha-2 Code Codes for the representation of names of countries and their subdivisions – Part 1: Country codes Codes for the representation of currencies and funds Information technology — Identification cards — Financial transaction cards Identification cards — Integrated circuit(s) cards with contacts — Part 4: Organization, security and commands for interchange Registration of application providers Financial transaction card originated messages – Interchange message specifications Financial transaction card originated messages – Interchange message specifications Specification of Basic Encoding Rules (BER), Canonical Encoding Rules (CER) and Distinguished Encoding Rules (DER) Information technology – 8-bit single-byte coded graphic character sets

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 1 Using This Manual 1.4 Terminology Reference [ISO/IEC 9797-1] Document Title Information technology – Security techniques – Message Authentication Codes (MACs) — Part 1: Mechanisms using a block cipher [ISO/IEC 10116] Information technology — Security techniques — Modes of operation for an n-bit block cipher [ISO/IEC 14888-3] Information technology — Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms [ISO/IEC 18031:2005] Information technology – Security techniques – Random bit generation [NIST SP800-22A] A statistical test suite for random and pseudorandom number generators for cryptographic algorithms 1.4 Terminology The following terms are used in this document, carrying specialised meanings as indicated. Table 1.1—Terminology Card Term

Description

Card, as used in these specifications, is a consumer device supporting contactless transactions. Combination Combination is the combination of an AID and a Kernel ID. Configuration Option A Configuration Option allows activation or deactivation of the Kernel software behind this option. The Configuration Option may change the execution path of the software but it does not change the software itself. A Configuration Option is set in the Kernel database per AID and Transaction Type. Implementation Option An Implementation Option allows the vendor to select whether the functionality behind the option will be implemented in a particular installation. April 2022

countries.

1 Using This Manual 1.4 Terminology Term Kernel POS System Process Queue Reader Signal Terminal EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Description The Kernel contains the interface routines, security and control functions, and logic to manage a set of commands and responses to retrieve all the necessary data from the Card to complete a transaction. The Kernel processing covers the interaction with the Card between the selection of the card application (excluded) and the processing of the transaction's outcome (excluded). The POS System is the collective term given to the payment infrastructure present at the merchant. It is made up of the Terminal and Reader. A Process is a logical component within a Reader that has one or more Queues to receive Signals. The processing of Signals, in combination with the carried data, may then generate other Signals to be sent. Processing can continue until all the Queues of a Process are empty, or until the Process terminates. A Queue is a buffer that stores events to be processed. The events are stored in the order received. The Reader is the device that supports the Kernel(s) and provides the contactless interface used by the Card. In this specification, the Reader is considered as a separate logical entity, although it can be an integral part of the POS System. A Signal is an asynchronous event that is placed in a Queue. A Signal can convey data as parameters, and the data provided in this way is used in the processing of the Signal. The Terminal is the device that connects to the authorisation and/or clearing network and that together with the Reader makes up the POS System. The Terminal and the Reader may exist in a single integrated device. However, in this specification, they are considered separate logical entities.

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 1 Using This Manual 1.5 Notations 1.5 Notations 1.5.1 State Machine This document specifies the Kernel processing as a state machine that is triggered by Signals that cause state transitions. The application states of the Kernel are written in a specific format to distinguish them from the rest of the text: State Example: S22 – Waiting for Read Record Response The state machine of the Kernel is represented using a state diagram. Example: Figure 1.1 depicts the transitions for state S26 – Waiting for Generate AC Response. Upon receiving the Signal RECORD DECRYPTED, the state machine remains in state S26 – Waiting for Generate AC Response. The state machine leaves state S26 – Waiting for Generate AC Response upon receiving an RA Signal. In this case, the state machine goes to S28 – Waiting for IAD MAC Results if Crypto Read Record Counter = 0 and to S27 – Waiting for Decrypted Records if Crypto Read Record Counter ≠ 0. Figure 1.1—Example of State Diagram Notation RECORD DECRYPTED S26 - Waiting for Generate AC Response RA/CRYPTO READ RECORD COUNTER != 0 RA/CRYPTO READ RECORD COUNTER = 0 S27 - Waiting for Decrypted Records S28 - Waiting for IAD MAC Results This document uses a combination of flow diagrams and textual description to describe the state transitions in the state machine of the Kernel. Figure 1.2 depicts the symbols used in the flow diagrams. April 2022

countries.

1 Using This Manual 1.5 Notations EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Figure 1.2—Symbols Used in Flow Diagrams X - State State Procedure Procedure Start CALL Call Procedure () Label High-Level Action Description Label Detailed Action Description Action With Detailed Description as Described in Text Action With Detailed Description Included in the Flow Diagram Test ? Label TRUE FALSE Decision SIGNAL Signal Received Action Connectors SIGNAL Signal Sent Action NO YES Implementation Option Test

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 1 Using This Manual 1.5 Notations On the Kernel behaviour, the combination of the flow diagrams and the corresponding textual descriptions constitutes the requirements:

  • Each diagram in this specification has a unique label.
  • Each symbol in a diagram has a unique identifier that is the concatenation of the diagram label with the symbol number.
  • The textual description corresponding to a symbol may be included in the diagram or it may be a detailed textual description included in the text below the diagram. The flow diagrams are read from top to bottom and define the order of execution of the processing steps. The textual description specifies the behaviour of the individual steps but bears no information on the order of execution. An example of a flow diagram is given in Figure 1.3 in combination with the detailed textual description below. Figure 1.3—Example of Flow Diagram IsNotEmpty(TagOf(DF Name)) AND IsNotEmpty(TagOf(Card Qualifier)) AND 'Version' in Card Qualifier ≠ '00' ? 1.8 FALSE TRUE 1.10 Set Language Preference 1.9 'L2' in Error Indication:= CARD DATA MISSING 'Msg On Error' in Error Indication:= N/A April 2022 countries. 1 Using This Manual 1.5 Notations EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 1.10 If the Language Preference is returned from the Card, then copy it to 'Language Preference' in User Interface Request Data 1 and User Interface Request Data 2: IF [IsNotEmpty(TagOf(Language Preference))] THEN 'Language Preference' in User Interface Request Data 1:= Language Preference 'Language Preference' in User Interface Request Data 2:= Language Preference If the length of Language Preference is less than 8 bytes, then pad 'Language Preference' in User Interface Request Data 1 and User Interface Request Data 2 with trailing hexadecimal zeroes to 8 bytes. ENDIF Only symbol 1.10 has a detailed textual description. The textual descriptions of symbols 1.9 and 1.8 are included in the flow diagram. The requirements are related to the behaviour of the Kernel, while leaving flexibility in the actual implementation. The implementation must behave in a way that is indistinguishable from the behaviour specified in this document, in terms of that it creates the output as predicted by this specification for a given input. There is no requirement that the implementation realises the behaviour through a state machine as described in this document.

1.5.2 Data Object Notation Data objects used for this specification are capitalised: Data Object Name Example: Application File Locator To refer to a sub-element of a data object (i.e. a specific bit, set of bits, or byte of a multi-byte data object), the following notational convention is used:

  • If the sub-element is defined in the data dictionary (Annex A), with each possible value of the sub-element having a name, then the following conventions apply:
  • The reference to the sub-element is 'Name of Sub-element' in Data Object Name.
  • The reference to the value is VALUE OF SUB-ELEMENT. Examples:
  • 'CVM Limit exceeded' in Terminal Risk Management Data refers to bit 8 of byte 2 in Terminal Risk Management Data. April 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 1 Using This Manual 1.5 Notations
  • 'CVM' in Outcome Parameter Set:= ONLINE PIN means the same as bits 8 to 5 of byte 4 of Outcome Parameter Set are set to 0010b.
  • Alternatively, an index may be used to identify a sub-element of a data object. In this case the following notational conventions apply:
  • To refer to a specific byte of a multi-byte data object, a byte index is used within brackets (i.e. [ ]). The first byte (leftmost or most significant) of a data object has index 1. For example, Terminal Verification Results[2] represents byte 2 of Terminal Verification Results.
  • To refer to a specific bit of a single byte multi-bit data object, a bit index is used within brackets [ ]. The first bit (rightmost or least significant) of a data object has index 1. For example, Cryptogram Information Data[7] represents bit 7 of the Cryptogram Information Data.
  • To refer to a specific bit of a multi-byte data object, a byte index and a bit index are used within brackets (i.e. [ ][ ]). For example, Terminal Verification Results[2][4] represents bit 4 of byte 2 of the Terminal Verification Results.
  • Ranges of bytes are expressed using the x:y notational convention: For example, Terminal Verification Results[1:4] represents bytes 1, 2, 3, and 4 of the Terminal Verification Results.
  • Ranges of bits are expressed using the y:x notational convention: For example, Cryptogram Information Data[5:1] represents bits 5, 4, 3, 2, and 1 of the Cryptogram Information Data. April 2022 countries. 1 Using This Manual 1.5 Notations EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 1.5.3 Other Notational Conventions Notations for processing data and managing memory are described in Table 1.2. Table 1.2—Other Notational Conventions Notation '0' to '9' and 'A' to 'F' Meaning Hexadecimal notation. Values expressed in hexadecimal form are enclosed in straight single quotes. Example 27509 decimal is expressed in hexadecimal as '6B75'. 1001b Binary notation. Values expressed in binary form are followed by the letter b. '08' hexadecimal is expressed in binary as 00001000b. 340 Decimal notation. Values '0C' hexadecimal is expressed in expressed in decimal form decimal as 12. are not enclosed in single quotes. C-APDU C-APDUs are written in all caps to distinguish them from the text GET PROCESSING OPTIONS SET A specific bit in a data object SET 'Kernel 8 processing and TVR is set to the value 1b format' in Terminal Verification Results CLEAR A specific bit in a data object is set to the value 0b CLEAR 'Cardholder verification was not successful' in Terminal Verification Results:= A specific value is assigned 'Status' in Outcome Parameter Set to a data object or to a:= END APPLICATION sub-element of a data object OR This notation is used for both Bitwise AND and OR: the logical and bitwise OR TVR:= (TVR AND Kernel Reserved operation. Its meaning is TVR Mask) OR (Card TVR AND therefore context-specific. NOT(Kernel Reserved TVR Mask)) April 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 1 Using This Manual 1.5 Notations Notation AND NOT || IF THEN ELSE ENDIF FOR EXIT loop Meaning This notation is used for both the logical and bitwise AND operation. Its meaning is therefore context-specific. Example Logical AND: IF [IsNotEmptyList(Data To Send) AND IsEmptyList(Tags To Read Yet)] This notation is used for both the logical and bitwise negation operation. Therefore, its meaning is context-specific. Logical NOT: IF [NOT ParseAndStoreCardResponse(TLV)] Two values are concatenated. A:= 'AB34' B:= A || 'FFFF' means that B is assigned the value 'AB34FFFF' This textual description is used to specify decision logic, using the following syntax: IF T THEN Logic 1 ELSE Logic 2 ENDIF where T is a statement resulting in true or false. IF [IsNotEmptyList(Data Envelopes To Write Yet)] THEN P2:= '80' ELSE P2:= '00' ENDIF This textual description is used to specify repetition control logic, using the following syntax: FOR every x in list { IF T THEN Action EXIT loop ENDIF } FOR every T in Extended SDA Tag List { IF [IsNotPresent(T) OR IsEmpty(T)] THEN Data objects referenced in Extended SDA Tag List present:= FALSE EXIT loop ENDIF } April 2022 countries. 1 Using This Manual 1.5 Notations EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Notation CALL A mod n A div n X ⊕ Y A:= ALG(K)[X] x
  • Y Meaning Functionality of a certain complexity and appearing more than once is implemented by means of a procedure. In the textual description, a procedure is referenced by means of the key word CALL. Example CALL Process Restrictions () The reduction of the integer A modulo the integer n, that is, the unique integer r, 0 ≤ r &lt; n, for which there exists an integer d such that A = dn + r 54 mod 16 = 6 The integer division of A by n, that is, the unique integer d for which there exists an integer r, 0 ≤ r < n, such that A = dn + r 54 div 16 = 3 The bit-wise exclusive-OR of the data blocks X and Y. 11001100b ⊕ 10101010b = 01100110b Encryption of a data block X with a block cipher (ALG) using a secret key K. Typical values for ALG are AES, DES, TDES, AES-1, DES-1, and TDES-1. T:= AES(K)[M] Scalar multiplication by x of the point of the elliptic curve Y Q:= d
  • G April 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 2 General Architecture 2.1

Introduction

As described in [EMV Book A], the general architecture of a POS System consists of a Terminal and a Reader, where the terms Terminal and Reader refer to a separation in responsibility and functionality between two logical entities. Figure 2.1 shows how the Reader functionality is allocated to different processes: Process M(ain), Process D(isplay), Process S(elect), Process P(CD), Process K(ernel) and Process C(rypto). Communication between different processes happens through Signals stored on Queues. A Signal is an asynchronous event that is placed on a Queue waiting to be processed. A Signal can convey data as parameters, and the data provided in this way is used in the processing of the Signal. Zooming in further on Process K, Figure 2.1 illustrates the two components of the Kernel: the Kernel software, modeled as a state machine, and the Kernel database, consisting of a number of separate datasets. Figure 2.1—General Architecture POS System Terminal Reader Process M Reader Management Reader Database Process D Message Display Process S Application and Kernel Selection Process P Card Interaction Process K Kernel Process C Crypto State 1 Kernel database State 2 State 3 State 4

April 2022

countries.

2 General Architecture 2.1 Introduction EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 There is no requirement to create devices that use the architecture and the partitioning as laid out in this document, as equally there is no requirement in [EMV Book A] on the partitioning. The only requirements in this document apply to Process K and Process C, and these requirements define the externally-observable behaviour, independent of the internal organisation of the Reader.

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 2 General Architecture 2.2 Reader Processes 2.2 Reader Processes In Figure 2.2, the Reader is modeled as a set of Processes and each Process runs independently of the other Processes. The role of the Reader database is explained in section 2.3. Figure 2.2—Reader Logical Architecture Reader Process D Message Display Process M Reader Management Process S Application and Kernel Selection Process P Card Card Interaction Reader database Process K Kernel Process C Crypto The different processes are listed in Table 2.1. Table 2.1—Reader Processes Process Process P(CD) Process D(isplay) Process S(election) Process K(ernel) Process M(ain) Process C(rypto) Responsibility Management of the contactless interface Management of the user interface Selection of the Card application and Kernel Interaction with the Card once the application has been selected, covering the transaction flow specific to Kernel 8 Overall control and sequencing of the different processes. The configuration and activation of the Kernel and the processing of its outcome are also part of this role. Processing of cryptographic material April 2022

countries.

2 General Architecture 2.2 Reader Processes EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 2.2.1 Process P Process P implements the functionality described in [EMV CL L1] and [ISO/IEC 7816-4] and manages the access to the Card. Process K communicates with Process P through the CMDA, RA and L1RSP Signals as shown in Table 2.2. Signal In CMDA Table 2.2—Process P Signals Signal Out RA(R-APDU) Comment If there is no L1 error, the RA Signal contains the R-APDU sent back in response to a C-APDU. L1RSP(code) If there is an L1 error, L1RSP is returned with code as one of the following:

  • Error – Timeout: An L1 timeout has occurred
  • Error – Protocol: An L1 protocol error has occurred
  • Error – Transmission: Any other error Process P sends the C-APDU included in the CMDA Signal to the Card and responds with either:
  • An RA Signal containing the R-APDU and status bytes returned by the Card, or
  • An L1RSP Signal including an L1 event such as a timeout, transmission error, or protocol error.

2.2.2 Process D Process D manages the User Interface Requests as defined in [EMV Book A] and displays a message and/or a status. A MSG Signal is used as a carrier of User Interface Request Data (UIRD). Process D may receive MSG Signals from any other Process. The MSG Signal is not acknowledged. For more information on UIRD, refer to section 7.1 of [EMV Book A] and to A.1.137 and A.1.138 for the definition of the UIRDs used in this specification.

April 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 2 General Architecture 2.2 Reader Processes For displaying messages and/or indicating status, Process D needs the following configuration data:

  • Default language
  • The currency symbol to display for each currency code and the number of minor units for that currency code
  • A number of message strings in the default language and potentially other languages The status identifiers and message identifiers are defined in section 9.2 and section 9.4 respectively of [EMV Book A].

2.2.3 Process S Process S manages the application and Kernel selection

It runs constantly, and it is waiting for an ACT Signal from Process M. After processing the ACT Signal, it returns the selected Combination of application and Kernel (AID and Kernel ID) and the File Control Information Template and status bytes returned by the Card in response to the final SELECT command in an OUT Signal. Refer to [EMV Book B] for the specification of an implementation of Process S that supports a multi-kernel architecture.

2.2.4 Process K The Reader may support multiple Kernels but only one Kernel will execute at a time. The Kernel that is activated depends on the information returned by Process S, which may in turn depend on data retrieved from the Card. For each transaction, Process K is configured with a Kernel-specific dataset. The values in the dataset depend on the AID and the Transaction Type. More information on the initialisation of the Kernel-specific dataset is provided in section 2.3. Once the Kernel is selected and configured, it executes as Process K. Process K manages the interaction with the Card application beyond application selection, using the services of Process P as an intermediary. Upon completion, Process K sends its results to Process M in an OUT Signal and then terminates. For the remainder of the document, it is assumed that Kernel 8 is selected. From the viewpoint of the Reader and depending on the Configuration Options, Kernel 8 can provide two services:

  • Through its interaction with the Card, it creates a transaction record for authorisation and/or clearing.
  • It can interact with the Terminal directly through the Data Exchange mechanism. April 2022 countries. 2 General Architecture 2.2 Reader Processes EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Seen from the Terminal and depending on the Configuration Options, Kernel 8 allows reading and writing data from and to the Card. The different services are listed in Table 2.3, with the corresponding Signal to call the service indicated in the right column. Only Process M and the Terminal request these services from Process K. Table 2.3—Services from Process K Service Return an authorisation or clearing record. Corresponding Signal ACT(Data) As a minimum, “Data” includes the File Control Information Template received from the Card in the response to the SELECT command. Request data from the Kernel database or from the Card. Write data to the Kernel database or to the Card. DET(Data) Process K responds to the incoming service request with an outgoing Signal as described in Table 2.4. Signal In ACT Table 2.4—Responses from Process K Signal Out OUT Comment The OUT Signal includes
  • Outcome Parameter Set
  • Data Record – if any
  • Discretionary Data
  • User Interface Request Data 1 – if any
  • User Interface Request Data 2 – if any DET DEK or n/a April 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 2 General Architecture 2.2 Reader Processes Signal In n/a Signal Out DEK Comment The DEK Signal can be used to request additional data to be provided in a subsequent DET Signal, as well as to provide data that was requested via a configuration setting or a previous DET Signal. The DEK Signal contains:
  • The Data Needed data object, which is the list of tags of data items that the Kernel needs from the Terminal
  • The Data To Send data object, which is the list of data values that the Terminal has requested Within a transaction, the Terminal can only send one or more DET Signals after it received a DEK Signal indicating that Process K is active. The DEK Signal is sent only if the Kernel has data for the Terminal or needs data from the Terminal. The DEK and DET Signals are exchanged as part of the Data Exchange mechanism and are only used if DE/DS implementation option is implemented.

2.2.5 Process M Process M is responsible for coordinating the other processes to perform a transaction. The overall process is illustrated as follows:

  • Process M receives the ACT Signal from the Terminal.
  • Process M starts Process P to start polling for Cards as described in [EMV CL L1].
  • Process M requests Process D to display the READY message.
  • When Process P indicates to Process M that a Card is detected, Process M activates Process S. When Process S completes successfully, it responds with an OUT Signal with the selected Combination {AID – Kernel ID}, the File Control Information Template of the selected Card application, and the status bytes returned by the Card.
  • Based on this information, Process M then configures Process K for the specific Transaction Type and AID, using a Kernel-specific dataset, and sends it an ACT Signal containing transactional data such as the Amount, Authorised (Numeric) and the File Control Information Template. When Process K has completed the transaction, it returns an OUT Signal to Process M, including the Outcome Parameter Set, Discretionary Data, Data Record (if any) and optionally one or two UIRDs. April 2022 countries. 2 General Architecture 2.2 Reader Processes EMV Contactless Book C-8 Kernel 8 Spec DRAFT2
  • Process M analyzes the 'Status' in Outcome Parameter Set and executes the instructions encoded in the other fields of the Outcome Parameter Set. As required, Process M instructs Process P to perform the removal sequence. Alternatively, it may instruct Process S to select the next application on the Card.
  • Process M passes a subset of the Outcome Parameter Set, the Data Record and the Discretionary Data to the Terminal.
  • If the transaction is processed online, the Reader receives a MSG Signal from the Terminal to indicate whether the transaction was approved or declined.

2.2.6 Process C Process C is the cryptographic process and only Process K communicates with Process C. Communication between Process K and Process C is described in terms of Signals. The specification presumes that Signals between Process C and Process K are managed on a dedicated Queue that is exclusively reserved for their interactions. Process C is designed to run in parallel with Process K, offloading the processing of cryptographic data to simplify Process K and speed up the processing transaction flow. It is an implementation decision as to how it is implemented; if a reader has very fast cryptographic processing and the implementer prefers not to implement parallel processing, then its functions may be executed sequentially with respect to Process K but it is presented in this specification as a parallel process. Process C handles the following tasks:

  • Secure channel and certificate algorithm suite negotiation.
  • Processing of the key related data in the GET PROCESSING OPTIONS response
  • Decryption of privacy protected (encrypted) record or READ DATA data
  • Local authentication including validation of the Card and issuer certificates and the blinding factor
  • Generation of the Issuer Application Data MAC and validation of the Enhanced Data Authentication MAC
  • Validation of MACs for READ DATA and WRITE DATA
  • Encryption of data for WRITE DATA for transmission to the Card April 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 2 General Architecture 2.2 Reader Processes It is invoked by Process K by means of Signals. The Signals that Process K sends to Process C are listed in Table 2.5. Process C will process Signals in the order they are sent to it by Process K. In response to these Signals, Process C will return a message for each message sent, subject to the exceptions shown as described in Table 2.5. Table 2.5—Process C Signals In response to INITIALISE PROCESS C GPO PRIVACY RECORD RECEIVED PROCESS ISSUER CERTIFICATE PROCESS ICC CERTIFICATE PROCESS EDA MAC PROCESS BLINDING FACTOR VALIDATE MESSAGE ENCRYPT MESSAGE PROCESS IAD MAC Process C will send Normal response Exception INIT PROCESS C OK INIT PROCESS C FAIL None DECRYPTION FAILED None(1) or RECORD DECRYPTED DECRYPTION FAILED ISSUER CERTIFICATE OK ISSUER CERTIFICATE FAIL ICC CERTIFICATE OK ICC CERTIFICATE FAIL EDA MAC OK BLINDING FACTOR OK EDA MAC FAIL BLINDING FACTOR FAIL MESSAGE OK ENCRYPTED MESSAGE IAD MAC OK MESSAGE FAIL ENCRYPTION FAILED IAD MAC FAIL (1) If a RECORD RECEIVED Signal contains a plaintext record, Process C will not return a message. Process K sends plaintext records to Process C as it is Process C that builds the Sstatic Ddata Tto Bbe Aauthenticated. April 2022 countries. 2 General Architecture 2.3 The Reader Database EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 2.3 The Reader Database The Reader maintains a database that is divided into different datasets held in persistent memory. An overview of the different persistent datasets is given in Figure 2.3, with additional details in Table 2.6. Figure 2.3—Reader Database – Persistent Datasets April 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 2 General Architecture 2.3 The Reader Database Process Process M Process P Process D Process S Process K Table 2.6—Reader Database Data Sets One dataset, including generic data and the different transaction types supported. Examples of generic data are Interface Device Serial Number, Terminal Country Code, Transaction Currency Code and Transaction Currency Exponent. Examples of transaction types are purchase, purchase with cashback, and refund. One or more datasets, one for each protocol configuration setting. Each dataset contains (part of) the configuration settings as defined in Annex A of [EMV CL L1]. Multiple datasets for Process D, one for each supported language. Each dataset contains the message strings behind the message identifiers. Multiple datasets for Process S, one dataset per Transaction Type. Each dataset contains a list of Combinations {AID – Kernel ID}. Multiple Kernel-specific datasets for Process K. Each Kernel-specific dataset includes different subsets. For Kernel 8, see Table 2.7. If the transaction type has not been indicated by the Terminal in the ACT Signal, a configurable default transaction type is used. April 2022 countries. 2 General Architecture 2.3 The Reader Database EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 Subset Configuration Data Table 2.7—Persistent Dataset for Kernel 8 Purpose Contains the TLV-encoded persistent data objects relevant to a specific AID (used by Process S to identify the application during application selection) and Transaction Type. The values of the TLV-encoded data objects do not vary per transaction. Proprietary Tags Data objects with proprietary tags (i.e. data objects with tags not listed in Table A.38). A proprietary tag may have a zero length for data returned from the Card or a length different from zero for terminal sourced data. PS CA Public Key Database Information linked to the PS Certification Authority Public Keys, including the index, modulus, and exponent. Certification Authority PS Public Keys can be shared between AIDs that have the same RID and sharing can be done across Kernels. The Reader must be able to store the information for at least six RSA keys per RID and ten ECC keys per RID. Certification Revocation List A list of Issuer Public Key Certificates that payment systems have revoked for each RID supported by the Kernel. As for the CA Public Key Database, entries in the Certification Revocation List may be shared between Kernels where Kernels support the same RID. April 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 3 Overview of Kernel Functionality 3.1 Implementation Options Kernel 8 supports the Implementation Option listed in Table 3.1. Table 3.1—Kernel Implementation Options Implementation Option Data Exchange & Data Storage Description This Implementation Option gives the implementer the choice to build Kernel 8 with or without support for Data Exchange and Data Storage. This Implementation Option is further on referenced as DE/DS. This Implementation Option gives rise to the following two possible Kernel implementations:
  • DE/DS implemented
  • DE/DS not implemented April 2022 countries. 3 Overview of Kernel Functionality 3.2 The Kernel TLV Database EMV Contactless Book C-8 Kernel 8 Spec DRAFT2 3.2 The Kernel TLV Database When the Kernel process starts, the Kernel database, as introduced in section 2.3, is already initiated with the persistent dataset of Kernel 8 for a specific AID (or RID) and Transaction Type. This includes the Configuration Data, Proprietary Tags, CA Public Key Database and the Certification Revocation List (see Table 2.7). At the start of the Kernel, the Kernel instantiates a TLV Database including the tags defined in Table A.38. The

Shown in part. Read the original for the full text.