SB nº AN-8 : Issuer and ICC Public Key Length Restrictions (Clarification)

v1.0 Specification Bulletins

Application Note Bulletin no. 08, February 19th, 2003 Issuer and ICC Public Key Length Restrictions EMV2000 Version 4.0 allows the Issuer Public Key length to be equal to or less than the CA Public Key length up to a maximum of 248 bytes and allows the ICC Public Key and ICC PIN Encipherment Public Key lengths to be equal to or less than the Issuer Public Key length up to a maximum of 248 bytes (Book 2 Sections 5.1 & 6.1). However, Book 3 Section 3 states that records are limited to 254 bytes including tag and length and as a consequence, if an ICC public key pair is required, the Issuer and ICC key lengths must be less than the maximum of 248 bytes. Book 1 Section 5.4.1 says that the maximum number of data bytes that may be sent with a command is 255 and the maximum number of data bytes for a response is 256. If dynamically signed data is included in a response from the ICC, then the latter restriction limits the maximum length of the ICC keys. Issuer Public Key Restriction For card applications supporting Dynamic Data Authentication, Combined DDA/Application Cryptogram Generation, or Offline Enciphered PIN, the TLV encoded template containing the ICC Public Key Certificate needs to fit within the 254 byte record limit. To accommodate the tags and lengths of the certificate and the record template in the record containing this certificate, the maximum size of the ICC Public Key Certificate is restricted to 247 bytes, and consequently the Issuer Public Key, which is the same length as the certificate, is also restricted to 247 bytes. ICC Public Key Restrictions Combined Dynamic Data Authentication/Application Cryptogram Generation The following restriction applies for card applications supporting Combined Dynamic Data Authentication/Application Cryptogram Generation: To ensure that the GENERATE APPLICATION CRYPTOGRAM response data length (format 2) is within the 256 byte constraint, the value portion of the Signed Dynamic Application Data needs to be limited in accordance with the other data elements contained within the template. This is achieved by limiting the size of the ICC public key, since owing to the properties of the cryptographic calculation, signature results are the same length as the key. The lengths of the data in the GENERATE APPLICATION CRYPTOGRAM response are shown in the following table: This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2002

Response Template Cryptogram Information Data Application Transaction Counter Signed Dynamic Application Data Issuer Application Data (optional) Other optional data Tag 1 byte ('77') Length in Bytes Length Value 2 bytes -- Total Length 3 bytes 2 bytes ('9F27') 1 byte 1 byte 4 bytes 2 bytes ('9F36') 1 byte 2 bytes 5 bytes 2 bytes ('9F4B') 2 bytes 2 bytes ('9F10') 1 byte ?? ?? NICC bytes 0 to 32 bytes ?? NICC plus 4 bytes 0 to 35 bytes ?? The tag and length of the response template, together with the tags, lengths, and values of the Cryptogram Information Data and Application Transaction Counter, and the tag and length of the Signed Dynamic Application Data are fixed in size and occupy 16 bytes. Thus without Issuer Application Data, the maximum size of the Signed Dynamic Application Data and consequently the ICC Public Key is 240 bytes. If Issuer Application Data is included, then the maximum size of the Signed Dynamic Application Data needs to be reduced accordingly. Including Issuer Application Data of tag, length and 32 bytes of value (the maximum) results in a maximum size of 205 bytes for the Signed Dynamic Application Data and consequently the ICC Public Key. Note - If other optional data is appended in the response, then the length of this data and its associated tag and length field further restricts the length of the ICC Public Key. Dynamic Data Authentication The following restriction applies for card applications supporting INTERNAL AUTHENTICATE Format 2: To ensure the INTERNAL AUTHENTICATE response data length is within the 256 byte limit, the length of the Signed Dynamic Application Data plus the length of the TLV encoded optional data (if present) shall not exceed 249 bytes. The length of the ICC Public Key is the same as the Signed Dynamic Application Data. The additional 7 bytes in the response are used for the tags and lengths of the response template and the Signed Dynamic Application Data. This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2002

T=1 Chaining

Requirement

When using the T=1 transmission protocol, the card needs to support chaining if it is required to send more than 254 bytes (including SW1 & SW2) in response to a command, since the INF field of blocks is limited to 254 bytes. This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2002