SB nº SU-23 : Corrections and Clarifications to EMV® Card Personalization Specification (Spec Change)
Specification Update: Bulletin no. 23 First edition October 2003 Corrections and Clarifications to EMV Card Personalization Specification This bulletin applies to EMV Card Personalization Specification Version 1.0, June 2003. The contents of this bulletin have immediate effect. The changes to the specification have been made in response to comments received following the publication of the specification on the EMVCo web site. 1. Abbreviations and Notations Insert the following paragraph above “Operators and Functions” on
: “Length Fields Length fields are “big-endian” encoded. For example if a two-byte length field has a hexadecimal value of 13F (319 in decimal), it is encoded as '013F'.” 2. Section 2.2 item 4 Add the following sentence to the end of the text in item 4: "For DGIs with the first byte equal to '01' through '1E', the first byte indicates the SFI in which the data is to be stored, and the second byte indicates the record number.” 3. Section 2.2 item 15 Replace the text of item 15 with: “The first two or three data bytes of any DGI in the range ('01xx' through '0Axx’) will consist of the record template tag ‘70’ and the length of the remaining record data”. 4. Section 2.6 Table 7 Entry 3d LMACDATA Remove the sentence: “If this field is ‘0C’, a single length MACkey has been used”.
5. Section 5.2 requirement 5.2.1.2 Replace the first paragraph with: “Session keys must be calculated using the triple DES algorithm presented in section 5.4.2.3 and the base keys KENC, KMAC, and KDEK to produce SKUENC, SKUMAC, and SKUDEK respectively”. 6. Section 5.3.3 requirement 5.3.3.1 Replace requirement 5.3.3.1 text with: “For each application the input to the MAC is the data within section 3 of the Table 7 excluding the fields MACkey and MACINP (LAPPL includes the length for fields MACkey and MACINP)”. 7. Section 3.2.5 Table 20 Replace the “Meaning” text of the second row (related to ‘6A80’) with: “Incorrect parameters in the data field”. 8. Annex A Append the following new Section A.4 after Table 19 of Section A.3: A.4 Common DGIs to Load/Update Secure Channel Static Keys The Data Grouping Identifiers ‘7F01’, ‘8F01’ and ‘00CF’ are recommended for use to load or update the secure channel static keys i.e. KENC, KMAC and KDEK. The condition of use is that the application allows load or update of the secure channel static keys after initialization of the card. These DGIs are defined to standardize any secure channel static keys update after initialization of the card.
Table 20 – Data Grouping Identifiers for Secure Channel Static Keys DGI Data Content Function Encrypt 7F01 Secure Channel DES keys Related data for No related data – Table 21 Load/Update personalization static keys KENC, KMAC and KDEK 8F01 Secure Channel DES Keys Load/Update Yes – Table 22 personalization static keys KENC, KMAC and KDEK 00CF Secure Channel DES Key Derivation data for No derivation data
- Table 23 Load/Update personalization static keys KENC, KMAC and KDEK External Access None None INTIALIZE
- UPDATE GET DATA (Tag ‘CF’) Table 21 – Data Content for DGI ‘7F01’ Req. Tag Data Element C N/A Current Key Version Number (‘00’ or ‘01’ to ‘6F’) New Key Version Number (‘01’ to ‘6F’) Key type (‘80’) Check value for new Key Identifier 1 Check value for new Key Identifier 2 Check value for new Key Identifier 3 Length 1 1 1 3 3 3 Encrypt N/A Table 22 – Data Content for DGI ‘8F01’ Req. Tag Data Element C N/A New Key Identifier 1 (encryption) New Key Identifier 2 (MAC) New Key Identifier 3 (DEK) Length 16 16 16 Encrypt SKUDEK Table 23 – Data Content for DGI ‘00CF’ Req. Tag Data Element C N/A New Key derivation data Length 10 Encrypt N/A