SB nº AN-17 : Terminal Requirements regarding Status Words returned to an EXTERNAL AUTHENTICATE command (Clarification)

v1.0 Specification Bulletins

Application Note N°17 First Edition December 2003 Terminal Requirements regarding Status Words returned to an EXTERNAL AUTHENTICATE command

Applicability

This Application Note applies to:

  • EMV 2000 Integrated Circuit Card Specifications for Payment Systems, Version 4.0, Book 3

Related Documents

None When the terminal issues an EXTERNAL AUTHENTICATE command to the card, the card will normally return status word ‘9000’ indicating that Issuer Authentication was successful. However, under abnormal circumstances, the card may return other status words to the terminal – this Application Note clarifies the terminal requirements in this event. Status Word ‘6300’ In the EMV ’96 Integrated Circuit Card Specification for Payment Systems Version 3.1.1 section 2.2.5, the second note following Table II-8 stated that if status word ‘6300’ was returned to an EXTERNAL AUTHENTICATE command, then Issuer Authentication was unsuccessful. Unfortunately this definition was omitted from the EMV 2000 Integrated Circuit Card Specifications for Payment Systems Version 4.0, and it will be reintroduced. Terminal Requirements The terminal shall only issue an EXTERNAL AUTHENTICATE command to the card if the card indicates in byte 1 b3 of the AIP that it supports issuer authentication using the EXTERNAL AUTHENTICATE command. The terminal shall only issue one EXTERNAL AUTHENTICATE command to the card during a transaction. (There is a complementary card requirement to this which states that the card shall return status ‘6985’ – ‘Command Not This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2003

Supported’ - to the second and any subsequent EXTERNAL AUTHENTICATE commands received during the transaction – see Book 3 section 6.9). If in response the (first) EXTERNAL AUTHENTICATE command issued to the card, the terminal receives a status of:

  • ‘9000’, issuer authentication was successful and it shall continue with the transaction.
  • ‘6300’ or any other status except ‘6985’ and '9000', issuer authentication was unsuccessful. It shall set byte 5 b7 of the TVR (issuer authentication unsuccessful) to 1, and continue with the transaction.
  • ‘6985’, issuer authentication was unsuccessful and the card is in an error state (it has indicated in the AIP that it supports EXTERNAL AUTHENTICATE, but in the status returned that it does not). This condition should never occur; in the event that it does, the behaviour of the terminal is indeterminate and it shall either terminate the transaction OR set byte 5 b7 of the TVR (issuer authentication unsuccessful) to 1, and continue with the transaction. Specification Clarification Change Notice To reinstate the definition of the ‘6300’ status word, the following sentence will be added at the end of Book 3 section 2.5.4.5: ‘6300’ codes ‘issuer authentication unsuccessful’. This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2003