SB nº SU-47 : Support for Proprietary Authentication Data in CCD (Spec Change)
Specification Update Bulletin No. 47 First Edition April 2006 Support for Proprietary Authentication Data in CCD This specification update removes the restriction on the length for Proprietary Authentication Data sent to a CCD-compliant card. This Bulletin takes effect April 30, 2006. Products will be tested against the requirements of this bulletin commencing with the availability of CCD card type approval.
Applicability
This Specification Update Bulletin applies to:
- EMV Integrated Circuit Card Specifications for Payment Systems Version 4.1 Book 2 Security and Key Management
- EMV Integrated Circuit Card Specifications for Payment Systems Version 4.1 Book 3 Application Specification
Related Documents
This Specification Update Bulletin should be read in conjunction with:
- Specification Update Bulletin SU_46 Replacement of EMV Session Key Derivation Method
Description
This specification update removes the restriction on the length of Proprietary Authentication Data that may be sent to a CCD-compliant application. A CCD card is allowed to receive Proprietary Authentication Data as part of the Issuer Authentication Data sent in the online response to the card.
- If Proprietary Authentication Data is included in generation of the ARPC sent to the card, a new ‘Proprietary Authentication Data Included’ bit in the CSU will be set to 1b. If Proprietary Authentication Data is not included in generation of the ARPC sent to the card, the new ‘Proprietary Authentication Data Included’ bit in the CSU will be set to 0b.
- If the card receives Issuer Authentication Data of length in the range from 8 to 16 bytes with the new ‘Proprietary Authentication Data Included’ bit in the CSU set to 0b, then the card validates the ARPC using a Proprietary Authentication Data of length 0 bytes. Note: This allows the CDOL2 sent to the terminal to be configured to request Issuer Authentication Data with a length that allows for inclusion of Proprietary Authentication Data. If the Issuer Authentication Data in the online response sent to the terminal does not include Proprietary Authentication Data from the issuer (for example, the issuer does not use the functionality associated with the Proprietary Authentication Data, or the Issuer Authentication Data is generated by a proxy for the issuer), the terminal will zero-fill the Proprietary Authentication Data portion of the Issuer Authentication Data sent to the card. The card will be able to validate the ARPC in the Issuer Authentication Data that is received.
- If the card receives Issuer Authentication Data of length in the range from 8-16 bytes, with the new ‘Proprietary Authentication Data Included’ bit in the CSU set to 1b, then the card uses the Proprietary Authentication Data (if any) received as input to validation of the ARPC. This specification update also clarifies that the default value for issuer-discretionary data in the Issuer Authentication Data is zero. Specification Change Notice Please make the following changes to EMV 4.1 Book 2 Security and Key Management: In Section 8.2.2, delete Footnote 32. Replace CCD Section 8.2.2 with the following:
8.2.2 ARPC Method 2 For a cryptogram defined by the Common Core Definitions with a Cryptogram Version of ‘5’, the Card Status Update (CSU) data element shall be coded according to Annex C8 in the CCD part of Book 3. The default value for Proprietary Authentication Data is zero. If the ‘Proprietary Authentication Data Included’ bit in the CSU has the value 0b, then the length of Proprietary Authentication Data included in generation and validation of the ARPC shall be 0 bytes. Note: If the ‘Proprietary Authentication Data Included’ bit in the CSU has the value 0b, the Proprietary Authentication Data is not protected by Issuer Authentication. The card should not take action based on the settings of any Proprietary Authentication Data that is not protected by Issuer Authentication. If the ‘Proprietary Authentication Data Included’ bit in the CSU has the value 1b, then the Proprietary Authentication Data included in the Issuer Authentication Data shall be used in generation and validation of the ARPC. Please make the following changes to EMV Integrated Circuit Card Specifications for Payment Systems Version 4.1 Book 3. In Annex A Table 33, delete Footnote 17 on
1.
In CCD Section 6.5.5.3, delete the sentence: "In the Common Core
Definitions
Version 4.1, the length of the Issuer Authentication Data element shall be 8 bytes (as specified in section 8.2.2 of Book 2)." In CCD Section C8, Table CCD 11, replace the table for CSU Byte 1 with the following: b8 b7 b6 b5 b4 b3 b2 b1 Meaning 1 Proprietary Authentication Data Included 0 0 0 RFU x x x x PIN Try Counter In CCD Section C8, after Table CCD 11, add the following: The default value for issuer-discretionary data in the CSU is zero.