SB nº SU-27 : ARPC Generation Option (Spec Change)
Specification Update: Bulletin No. 27 April 2004 First Edition ARPC Generation Option This bulletin applies to EMV 2000 Integrated Circuit Card Specifications for Payment Systems Version 4.0 Book 2, Section 8.2 Issuer Authentication and Book 3, Annex A. It provides a new option for generating a 4-byte Authorisation Response Cryptogram (ARPC) and including it in an 8-byte Issuer Authentication Data. This method is not mandatory but instead provides a second optional method for generating the ARPC. Please make the following change to EMV 2000 Integrated Circuit Card Specifications for Payment Systems Version 4.0, Book 2, Section 8.2 Issuer Authentication: Add the following at the beginning of the section: Two methods are supported for generation of the Authorisation Response Cryptogram (ARPC) used for issuer authentication:
8.2.1 ARPC Method 1 In the first sentence of the first paragraph, change "The method" to "ARPC Method 1" Add the following at the end of the section:
8.2.2 ARPC Method 2 ARPC Method 2 for the generation of a 4-byte ARPC consists of applying the MAC algorithm as specified in Annex A1.2 to - the 8-byte ARQC (generated by the ICC as described in section 8.1) - the 4-byte binary Card Status Update (CSU)1 - the 0-8 byte binary Proprietary Authentication Data2 using the 16-byte Application Cryptogram Session Key SKAC (see section 8.1) in the following way: 1. Concatenate the ARQC, the CSU and the Proprietary Authentication Data. Y: = ARQC || CSU || Proprietary Authentication Data. 1 See Annex A of Book 3 for a definition of this data item. 2 For a cryptogram defined by the Common Core Definitions with a Cryptogram Version of '4', the Proprietary Authentication Data element shall be 0 bytes long. The only Cryptogram Version currently defined for the Common Core Definitions is '4'. This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2004
2. Generate a MAC over the data by applying the MAC algorithm specified in Annex A1.2 to the data defined above using the 16-byte Application Cryptogram Session Key derived when computing the ARQC. For this application of the MAC algorithm, the MAC is computed according to ISO/IEC 9797-1 Algorithm 3, and the parameter s is set to 4 thereby yielding a 4-byte MAC. ARPC: = MAC: = MAC algorithm (SKAC)[Y]. 3. The Issuer Authentication Data (tag ‘91’) is formed by concatenating the resulting 4byte ARPC, the 4-byte CSU, and the Proprietary Authentication Data. Issuer Authentication Data: = ARPC || CSU || Proprietary Authentication Data Please add the following to EMV 2000 Integrated Circuit Card Specifications for Payment Systems Version 4.0, Book 3. The following data elements are added to Table A-1. Name Card Status Update (CSU) Proprietary Authentication Data Authorisation Response Cryptogram (ARPC)
Description
Contains data sent to the ICC to indicate whether the issuer approves or declines the transaction, and to initiate actions specified by the issuer. Transmitted to the card in Issuer Authentication Data. Contains issuer data for transmission to the card in the Issuer Authentication Data of an online transaction.3 Cryptogram generated by the issuer and used by the card to verify that the response came from the issuer. Source Format Issuer b Issuer b Issuer b Template -- --- Tag Length -- 4 -- Var up to 8 -- 4 or 8 3 For a cryptogram defined by the Common Core Definitions with a Cryptogram Version of '4', the Proprietary Authentication Data element shall be 0 bytes long. The only Cryptogram Version currently defined for the Common Core Definitions is '4'. This document contains proprietary and confidential information of EMVCo LLC. Copyright © EMVCo LLC 2004