SB nº SU-40 : Additional Corrections and clarifications to EMV® Card Personalization Specification (Spec Change)

v1.0 Specification Bulletins

Specification Update: Bulletin no. 40 First edition February 2005 Additional Corrections and clarifications to EMV Card Personalization Specification This bulletin applies to EMV Card Personalization Specification Version 1.0, June 2003. The contents of this bulletin have immediate effect. The changes to the specification have been made in response to comments received following the publication of the specification on the EMVCo web site. 1. Normative

References

Insert the following Entry in the Normative References table on

: GlobalPlatform Card GlobalPlatform Card Specification – V2.1.1: 2003 Specification V2.1.1: 2003 2. Section 2.1.1 This text between the first set of parentheses in the last paragraph: “e.g. IIN left justified padded with 1111b per nibble” should be replaced with the following text: “e.g. IIN right justified and left padded with 1111b per nibble”. 3. Section 2.6 Table 8 This text between the second set of parentheses in the first row under Description of TKDATA: “the issuer BIN/IIN left justified and padded, if necessary, with 1111b per nibble” should be replaced with the following text: “the issuer BIN/IIN right justified and left padded, if necessary, with 1111b per nibble”. 4. Section 2.6 Table 9 This text between the second set of parentheses in the first row of entry #1 and entry #n under Description: “the issuer BIN/IIN left justified and padded, if necessary, with 1111b per nibble” should be replaced with the following text: “the issuer BIN/IIN right justified and left padded, if necessary, with 1111b per nibble”.

5. Section 3.2.3 Table 14 This text between the first set of parentheses in the first row under Field: “e.g. IIN/BIN left justified padded with 1111b per nibble” should be replaced with the following text: “e.g. IIN/BIN right justified and left padded with 1111b per nibble”. 6. Section 3.2.3 new requirement Add the requirement 3.2.3.7 with the following text: “If a secure channel is active and an INITIALIZE UPDATE command is received, the current secure channel shall be closed by the card”. 7. Section 3.2.4 new requirement Add the requirement 3.2.4.7 with the following text: “If an EXTERNAL AUTHENTICATE command is received and is not preceded by an INITIALIZE UPDATE command, the SW1 SW2 ‘6985’ shall be returned by the card.” 8. Section 3.2.4 Table 16 new Entry Add a new Entry in Table 16 as follows: SW1 ‘69’ SW2 '85' Meaning Conditions of use not satisfied 9. Section 3.2.6 requirement 3.2.6.1 Add the following sentence at the end: “If the conditions to transit the status of the application to “PERSONALIZED” are not satisfied as a result of missing DGIs or missing data element(s), the SW1 SW2 ‘6A86’ may be returned by the application”. 10. Section 3.2.6 new requirement Add the requirement 3.2.6.4 with the following text: “If required by the application and after successful completion of the personalization, the acceptance of the STORE DATA command may be disabled by the application”. 11. Section 3.2.5 requirement 3.2.5.16

Add the following text after the first sentence ending with “SKUENC”: “Note that the padding added to the data field to ensure that encryption takes place over a data size which is a multiple of 8-bytes becomes part of the data field and so further modification of Lc is required to reflect this”. 12. Section 3.2.5 requirement 3.2.5.17 The phrase: “the C-MAC must be saved to be used as initial chain vector (ICV) for the next C-MAC” should be replaced with the following phrase: “the C-MAC must be saved to be used for the computation of the next C-MAC”. 13. Section 4.1 requirement 4.1.1.9 The phrase: “The sequence counter to be returned in the response to the INITIALIZE UPDATE command must be initialized to ‘0001’” should be replaced with the following phrase: “The sequence counter to be returned in the response to the INITIALIZE UPDATE command must be initialized to ‘0000’”. 14. Section 4.2.3 new requirement Add the requirement 4.2.3.5 with the following text: “The secure channel described in this document is compliant with Secure Channel Protocol '02' - implementation option '15' as defined in Appendix E of the GlobalPlatform Card Specification V2.1.1:2003.” 15. Section 4.2.2 requirement 4.2.2.2 Replace the first sentence with: “Each secure channel key set must be associated with a sequence counter that can be returned in the response to the INITIALIZE UPDATE command”. 16. Section 5.3.2 requirement 5.3.2.2 Remove the following part of the text from item 4 between parentheses: “binary zeroes or”. The text becomes: “C-MAC from previous command”. 17. Section 6.18 This text between the first set of parentheses in the second paragraph: “left justified padded with 1111b per nibble” should be replaced with the following text: “right justified and left padded with 1111b per nibble”.

18. Annex A Table 1 of Section A.2: Remove “PUT DATA” from 5th Entry in 5th column. Table 2 of Section A.2: Replace “(MAC)” with “(MAC UDK)” and replace “(ENC)” with “(ENC UDK)”. The table becomes: Table 2 – Data Content for DGI ‘8000’ Req. Tag Data Element C N/A Unique Derivation Key (UDK) Message Authentication (MAC UDK) DEA Key Data Encipherment DEA Key (ENC UDK) Length 16 16 16 Encrypt SKUDEK 19. Annex B The following text in the box IC Card: ”Areas for card data storage Initial sequence counter 0001 KMCID FCI” should be replaced with the following text: “Areas for card data storage Initial sequence counter 0000 KMCID FCI”.