SB nº SU-46 : Replacement of EMV® Session Key Derivation Method (Spec Change)
Specification Update Bulletin No. 46 First Edition October 2005 Replacement of EMV Session Key Derivation Method This specification update replaces the current EMV Session Key Derivation Method with a different method. This Bulletin has immediate effect.
Applicability
This Specification Update Bulletin applies to:
- EMV Integrated Circuit Card Specifications for Payment Systems Version 4.1 Book 2 Security and Key Management
- EMV Integrated Circuit Card Specifications for Payment Systems Version 4.1 Book 3 Application Specification
Related Documents
None
Description
This specification update replaces the optional method for deriving the DES3 session keys used in EMV processing with a different optional method. The new method derives session keys for each transaction from the ICC master keys. A session key is generated by enciphering a transaction-unique data string with the appropriate ICC master key:
- For the Application Cryptogram and the ARPC, this data string is the Application Transaction Counter (ATC) padded on the right with binary zeroes.
- For secure messaging, this data string is the Application Cryptogram returned in the response to the first GENERATE AC command. Specification Change Notice Please make the following changes to EMV 4.1 Book 2 Security and Key Management: In Section 4 remove the abbreviations for Grandparent Key (GP), Intermediate Key (IK), Initial Vector (IV), and Parent Key (P). Change the definition of SK from “Session Key for session key generation” to “Session Key”. In Section 8.2.2 delete Footnote 32. In Section 9.2.2 replace "from the ICC's unique 16-byte MAC Master Key and the 2-byte ATC" with "from the ICC's unique 16-byte MAC Master Key and card-controlled data unique to the transaction." In Section 9.3.2 replace "from the ICC's unique 16-byte Encipherment Master Key and the 2-byte ATC" with "from the ICC's unique 16-byte Encipherment Master Key and card-controlled data unique to the transaction." In Annex D3 delete "where the key 'tree' should only be navigated once" from the end of the second paragraph. In the first sentence of the first paragraph of CCD Section 8.1.1, change “a Cryptogram Version of ‘4’” to “a Cryptogram Version of ‘5’.” In CCD Section 8.1.2, replace the second paragraph and three bullets with: “For an application with a cryptogram defined by the Common Core Definitions with a Cryptogram Version of ‘5’, the AC Session Key shall be derived using the method specified in Annex A1.3.1.” In CCD Section 8.2.2, change “Cryptogram Version of ‘4’: ” to “Cryptogram Version of ‘5’:” In CCD Section 8.3, change “Cryptogram Version of ‘4’,” to “Cryptogram Version of ‘5’,” Replace CCD Section 9.2.2 with: “For an application with a cryptogram defined by the Common Core Definitions with a Cryptogram Version of ‘5’, the MAC Session Key shall be derived using the method specified in Annex A1.3.1.” Replace CCD Section 9.3.2 with: “For an application with a cryptogram defined by the Common Core Definitions with a Cryptogram Version of ‘5’, the Encipherment Session Key shall be derived using the method specified in Annex A1.3.1.” In CCD Section 9.4, change "Cryptogram Version of ‘4’ ” to “Cryptogram Version of ‘5’ ” Replace Section A1.3 including sub-sections A1.3.1 and A1.3.2 with the following: "A1.3 Session Key Derivation Session keys KS are derived from unique Master Keys KM using diversification data R as follows KS:= F(KM)[R]. To prevent replay attacks, the diversification data R should have a high probability of being different for each session key derivation. An important requirement for the diversification function F is that the number of possible outputs of the function is sufficiently large and uniformly distributed to prevent an exhaustive key search on the session key. Annex A1.3.1 specifies a method for the derivation of session keys for Application Cryptogram generation, issuer authentication, and secure messaging (see sections 8 and 9) from ICC Master Keys. This session key derivation method ensures that different transactions use different session keys Note that the session key derivation method provided in Annex A1.3.1 is not mandatory. Issuers may decide to adopt another method for this function. A1.3.1 Common Session Key Derivation Option The common session key derivation option generates a unique session key for each transaction performed by the application. It does this by enciphering an 8-byte diversification value with the 16byte ICC Master Key (MK) to produce a 16-byte ICC Session Key (SK). The 8-byte diversification value is represented as R = R0 || R1 || R2 || R3 || R4 || R5 || R6 || R7. The left part of the double-length session key is obtained by applying the DES3 algorithm using the double-length ICC Master Key (MK) to the 8-byte data block that results from replacing the third byte (R2) of the diversification value with 'F0': SKL:= DES3 (MK) [(R0 || R1 || 'F0' || R3 || R4 || R5 || R6 || R7)] The right part of the double-length session key is obtained by applying the DES3 algorithm using the double-length ICC Master Key (MK) to the 8-byte data block that results from replacing the third byte (R2) of the diversification value with '0F': SKR:= DES3 (MK) [(R0 || R1 || '0F' || R3 || R4 || R5 || R6 || R7)] The session key is the concatenation of the left and right parts: SK:= SKL || SKR For the session key used to generate and verify the Application Cryptogram and the ARPC, the diversification value is the ATC followed by six bytes of '00': R:= ATC || '00' || '00' || '00' || '00' || '00' || '00' For the session keys used for secure messaging, the diversification value is the Application Cryptogram returned in the response to the first GENERATE AC command: R: = Application Cryptogram The same session key is used for all commands in a single transaction." Please make the following changes to EMV Integrated Circuit Card Specifications for Payment Systems Version 4.1 Book 3. In Annex A Table 33, delete Footnote 17 on 1. In CCD Section C7.1 replace the text in the Meaning column of the last row with "CCD Version 4.1 Cryptogram Version (='5') ". In CCD Section C8, change the captions for Table CCD 11 to: “Table CCD 11: Card Status Update for Cryptogram Version ‘5’”.