SB nº SU-12 : Offline Data Authentication Processing (Spec Change)

v0.1 Specification Bulletins

Specification Update: Bulletin no. 12, July 2002 Revision 0.1 - October 2002 The contents of this bulletin have immediate effect. This is a revised edition of Bulletin no. 12. The revision adds a final paragraph that states explicitly the action to be taken by the terminal in the case that the conditions described in the bulletin are not met and clarifies when SFIs outside the range of 1-10 are within the scope of the EMV Specifications. Offline Data Authentication Processing This note applies to EMV ’96 Integrated Circuit Card Specification for Payment Systems Version 3.1.1 and EMV 2000 Integrated Circuit Card Specifications for Payment Systems Version 4.0. Records read by the EMV terminal application for offline data authentication are TLV encoded. To clarify that this must be the case the following additions to the text are applicable immediately. In EMV '96 Version 3.1.1 Card volume Section 7.3 and EMV 2000 Version 4.0 Book 3 Section 6.3, replace the paragraph starting "The data from each record to be included in the offline data authentication" with the following: The records read for offline data authentication must be TLV-coded with Tag equal to '70'. The data from each record to be included in the offline data authentication input depends upon the SFI of the file from which the record was read. ƒ For files with SFI in the range 1 to 10, the record tag (‘70’) and the record length are excluded from the offline data authentication process. All other data in the data field of the response to the READ RECORD command (excluding SW1 SW2) is included. ƒ For files with SFI in the range 11 to 30, the record tag ('70') and the record length are not excluded from the offline data authentication process. Thus all data in the data field of the response to the READ RECORD command (excluding SW1 SW2) is included. If the records read for offline data authentication are not TLV-coded with Tag equal to '70' then offline data authentication shall be considered to have been performed and to have failed; that is, the terminal shall set to ‘1’ the ‘Offline data authentication was performed’ bit in the TSI, and the appropriate ‘Offline static data authentication failed’ or ‘Offline dynamic authentication failed’ or ‘Combined DDA/AC Generation failed’ bit shall be set in the TVR.

In EMV '96 Version 3.1.1 Card volume Section 2.4.10.4 and EMV 2000 Version 4.0 Book 3 Section 2.5.11.4, replace the paragraph “The response message to READ RECORD for SFIs outside the range 1-10 is outside the scope of this specification.” with the following paragraph: The response message to READ RECORD for SFIs outside the range 1-10 is outside the scope of this specification, except as specified in Section 6.3.