GB nº 31, EMV® Level 2

v4.0 General Bulletin

General Bulletin No. 31 First Edition July 2006 EMV Level 2 - Multiple Configuration Kernels with PIN Pad Change Testing Process

Related Documents

This General Bulletin should be read in conjunction with: z EMVCo Type Approval Terminal Level 2 Administrative Process, v 1.4

Introduction

EMVCo has recently expanded its level 2 procedures in order to test application kernels that support multiple configurations and multiple PIN pad. The configurable kernels are those capable of changing functional options without impacting the core application code. The multiple PIN pads are those that contain the EMV PIN functionality. This bulletin serves as an introduction to the requirements and procedures necessary to test configurable kernels that also support multiple PIN pads. When a Level 2 application kernel is now submitted for testing, the Implementation Conformance Statement (ICS) indicates what options are classed as configurable or fixed. The ICS shows the potential combinations of these options for each deployable configuration and the variety of PIN pads which contain EMV PIN functionality that may bind with the application kernel. There is no limit to the number of configurations and PIN pads that may be defined in a single type approval submission. EMVCo believes this approach continues to offer considerable savings to vendors who intend to support a configurable kernel with multiple PIN pads. The possible areas for savings are: z Time necessary to test a given number of deployable configurations and supported PIN pads z Cost savings in the test expense when considering the number of deployable configurations and PIN pads finally approved z Flexibility in which options and PIN pad are tested and approved, new option combinations and new PIN pads may be tested and approved as needed. z Single administrative approval process for a given number of deployable configurations and PIN pad combinations. Requirements for Submission EMVCo has specified a number of requirements that must be satisfied in order for a kernel to take advantages of the merging process of configurable kernel and PIN pad change process. Most importantly, in order to qualify for this process, the changing of options must not require any recompilation or linkage of the application kernel code. The EMV application kernel code residing within all submitted PIN pads must be confined to PIN processing functions. Changing of options must be clearly documented and easily reproducible by EMVCo recognized laboratories. All PIN pad functions must also be performed in a consistent and interchangeable manner, meaning each PIN pad must support an identical set of functions (offline plaintext PIN, offline enciphered PIN pads, etc.). No recompilation of the application kernel is permitted when changing PIN pads. This document contains proprietary and1confidential information of EMVCo LLC. Copyright © EMVCo LLC 2006

Finally, the kernel must be capable of outputting a unique checksum value for each deployable configuration and a unique secondary checksum associated with each PIN pad. The secondary checksum is derived from the application logic associated with the PIN processing. While the primary checksum is used to identify the configuration of the kernel, changing of the PIN pad must not impact the primary checksum. Submission Procedure All leve1 2 application kernel submissions will be accompanied by an ICS that describes what options are fixed or configurable. The ICS will also describe what the possible combinations of these options are. Multiple PIN pads, satisfying the above requirements, shall also be identified on the ICS. When requesting a test session, the vendor may also specify the baseline. The baseline is a deployable configuration with the primary PIN pad that will be fully tested against the EMVCo Level 2 test plan. Other supported PIN pads in combination with the baseline shall undergo a reduced set of PIN-related testing only. Other deployable subsequent configurations will receive limited incremental and regression testing. PIN pads in combination with each subsequent configuration are subject to reduced set of PIN-related testing. Vendors may choose not to specify the baseline, in this case the baseline defaults to be the configuration with the most activated options. During testing, failures may be discovered in the baseline, subsequent configuration or PIN pad. Depending on where the error occurs, the vendor may have a choice of how to continue. Errors found in the baseline will result in a rejection of entire kernel. Errors found in other deployable configuration-PIN pad combinations may either be eliminated from the testing process, repair the PIN pad and resume the regression process (only permitted if no change required for the core application kernel), or repair the core application kernel and restart the type approval process. A configurable kernel that encounters testing failure during configuration testing is not eligible for resubmission. Failures discovered during PIN Pad regression test have no impact on the other PIN pads already tested or PIN pads yet to be tested. EMVCo does not require any additional testing when a failure is isolated to a single PIN Pad. Resubmission Procedure A configurable kernel that has already been approved without test failures may be resubmitted for testing of subsequent deployable configurations and additional PIN pads, as defined by the vendor. Resubmission testing must be conducted on the original sample stored at the test laboratory whenever possible. In instances where the kernel is no longer available, or is otherwise inoperable, the vendor may supply an identical kernel after having signed a disclaimer attesting that no modifications have been made to that kernel since last tested by a laboratory. There is no need for a vendor to return to the original testing laboratory; however, the vendor is responsible for any shipping costs incurred in delivering the original kernel to the new laboratory. The kernel resubmission must be accompanied with a complete ICS, describing all configurable options and additional PIN pad components. The resubmitted kernel ICS must be reviewed by EMVCo before any testing may begin. EMVCo will compare the resubmitted ICS to the original and confirm there has been no change in options or supported values. Failures identified during resubmission are subject to the same process described above.

Conclusion

This document contains proprietary and2confidential information of EMVCo LLC. Copyright © EMVCo LLC 2006

Additional details regarding this policy can be found in the EMVCo Type Approval Level 2 Administrative Process, v1.4,. Testing for multiple configuration kernels with multiple PIN pads will be available on August 1st, 2006. Comments or queries regarding this policy change can be directed to EMVCo via the standard web page communication. This document contains proprietary and3confidential information of EMVCo LLC. Copyright © EMVCo LLC 2006