SB nº AN-5 : Key Length Terminal Checking Requirements Clarification (Clarification)

v1.0 Specification Bulletins

Application Note Bulletin no. 05 June, 2002 Key Length Terminal Checking Requirements Clarification EMV 2000 Version 4.0 allows the Issuer Public Key length to be equal to or less than the CA Public Key length. It also allows the ICC Public Key length to be equal to or less than the Issuer Public Key length up to a maximum of 248 bytes. The ICC PIN Encipherment Public Key length requirements match the ICC Public Key requirements. EMV '96 Version 3.1.1 states that for EMV 3.1.1 cards the Issuer Public length is less than the CA Public Key length and that the ICC Public Key length is less than the Issuer Public Key length with a maximum length of 128 bytes. The ICC PIN Encipherment Public Key requirements match the ICC Public Key requirements. EMV '96 Version 3.1.1 does not specify any requirement for terminals to check the sizes of the keys recovered from certificates stored on the card or any requirement to take any action should the keys not be equal. Terminals shall not terminate processing or fail Offline Data Authentication or Offline Enciphered PIN based on the sizes of the keys from the card. Because terminals are being built, tested and approved to EMV 3.1.1 until March 2004, this clarification is being published to ensure that the EMV 3.1.1 terminal functionality in this regard is consistent with EMV 4.0 key length options. This bulletin is a clarification of the current EMV '96 3.1.1 specification. This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2002