SB nº AN-31 : Coding of the length field of BER-TLV coded data objects not sent over the card-terminal interface (Clarification)
Application Note N° 31 First Edition November 2006 Coding of the length field of BER-TLV coded data objects not sent over the card-terminal interface The length field of BER-TLV coded data objects not sent over the card-terminal interface may be coded on more than two bytes (with special reference to Issuer Script Templates)
Applicability
This Application Note applies to:
- EMV Integrated Circuit Card Specifications for Payment Systems Book 3 Version 4.1 Annex B, May 2004
- EMV Integrated Circuit Card Specifications for Payment Systems Book 4 Version 4.1 May 2004 Section 6.3.9
Related Documents
- EMV Integrated Circuit Card Specifications for Payment Systems Book 3 Version 4.0 Annex B, December 2000 For BER-TLV Data Objects, EMV Version 4.1 Book 3 Annex B states that:
- The length field (L) consists of one or more consecutive bytes. It indicates the length of the following field. The length field of the data objects described in this specification is coded on one or two bytes. This restriction only applies to data objects that are transmitted over the cardterminal interface by means of command-response pairs, as defined in Book 3, section 6.1. For data objects not transmitted over the card-terminal interface, such as Issuer Script Templates, this restriction is not applicable. EMV Version 4.1 Book 3 section 10.10 defines the format of Issuer Script Templates. Issuer Script Commands are transmitted in Issuer Script Templates (tags ‘71’ or ‘72’) and each Issuer Script Command is encapsulated in a tag ‘86’ having a value field with length variable up to 261 bytes. If the value field of the Issuer Script Template exceeds 255 bytes, then the length of the Issuer Script Template shall be encoded using three length bytes. If the value field of the Issuer Script Command (tag ‘86’) exceeds 255 bytes, then the length of the Issuer Script Command shall be encoded using three length bytes. Since more than one Issuer Script Command may be present in an Issuer Script Template, the total length of the Issuer Script Template is variable with no theoretical upper limit. In practice the length is restricted by network and terminal limitations, and it should be noted that, currently, Issuer Script Templates longer than 128 bytes are not guaranteed to be processed correctly. EMV Version 4.1 Book 4 Section 6.3.9 states that: ‘The terminal shall be able to support one or more Issuer Scripts in each authorisation or financial transaction response it receives, where the total length of all Issuer Script Templates in the response shall be less than or equal to 128 bytes.’ When the above restriction is applied to the Issuer Script Template, the maximum length of the actual Issuer Script Command is limited as a result. For example, if a Case 3 command is sent in an Issuer Script Template, this restriction will yield the following maximum length for the actual script command (Note that in this example there is only one Issuer Script Command in the Issuer Script Template and no Script ID used): Example for a Case 3 command: Issuer Script Template – 128 bytes max (see Book, 4, section 6.3.9) Issuer Script Command – 126 bytes max Actual script command (Case 3) – 124 bytes max ‘71’ L ‘86’ L CLA INS P1 P2 Lc Command data or ‘72’ 1 1 1 1 1 1 1 1 1 byte byte byte byte byte byte byte byte byte 119 bytes Note that the length of the useable command data may be further reduced by the use of secure messaging Specification Clarification Notice In the next release of the EMV specification, the following clarifications will be applied to the text shown in:
- EMV Integrated Circuit Card Specifications for Payment Systems Book 3 Version 4.1 May 2004 Annex B The second sentence of the second bullet will be modified to read: The length field of the data objects described in this specification which are transmitted over the card-terminal interface is coded on one or two length bytes. After the second bullet in the introductory paragraph of Annex B, the following note will be added: Note: Three length bytes may be used if needed for templates '71' and '72' and tag '86' (to express length greater than 255 bytes), as they are not transferred over the card-terminal interface.
- EMV Integrated Circuit Card Specifications for Payment Systems Book 4 Version 4.1 May 2004 Section 6.3.9 After the first paragraph, the following note will be added: Note: In this case and when only one Issuer Script (tag ‘71’ or ‘72’) is sent, and no Issuer Script Identifier is used, the maximum length of the Issuer Script Command (tag ‘86’) is limited to 124 bytes. This implies that the maximum available useful command data (Lc) is limited to 119 bytes for a Case 3 command.