SB nº SU-52 : Certification Revocation Lists (Spec Change)

v1.0 Specification Bulletins

Specification Update Bulletin No. 52 First Edition February 2007 Certification Revocation Lists This specification update defines Certification Revocation List requirements for terminals that support these lists.

Applicability

This Specification Update Bulletin applies to:

  • EMV Integrated Circuit Card Specifications for Payment Systems Version 4.1 Book 2 Security and Key Management

Related Documents

This Specification Update Bulletin should be read in conjunction with:

  • Type Approval Bulletin No 53: Terminal Level 2 Test Cases v4.1.b Update - Certification Revocation Lists

Description

This specification update defines requirements for Certification Revocation Lists (CRLs) for terminals that support these lists. A terminal considers certificates listed on the CRL to be invalid and fails offline data authentication and offline PIN encipherment when one of these certificates is encountered. This bulletin defines the required data in a CRL entry, the minimum number of entries to be supported in a CRL, and the requirement for updating the CRL. The method of checking the CRL and the required action when a certificate is on the CRL are already described in Step 10 of EMV 4.1 Book 2 Sections 5.3 and 6.3. The payment system decides whether to add a certificate to the CRL. The method of updating the CRL is determined by the terminal vendor and the acquirer. Specification Change Notice Please make the following changes to EMV Book 2 Security and Key Management: Add the following abbreviation Section 4: CRL Certificate Revocation List

Add the following section after Section 5.1.1:

5.1.2 Certification Revocation List The terminal may support a Certification Revocation List (CRL) that lists the Issuer Public Key Certificates that payment systems have revoked. If, during SDA, a concatenation of the RID and Certification Authority Public Key Index from the card and the Certificate Serial Number recovered from the Issuer Public Key Certificate is on this list, SDA fails as described in Section 5.3 Step 10 of this book. At a minimum each entry in the CRL shall contain the following data: Name Registered Application Provider Identifier (RID) Certification Authority Public Key Index Certificate Serial Number Additional Data Description Identifiers the application provider Format Length b 5 Identifies the public key in b 1 conjunction with the RID Number unique to this certificate b 3 assigned by the certification authority Optional terminal proprietary data, b var such as the date the certificate was added to the revocation list Additional data such as the date the certificate was added to the CRL may be included in the CRL entry. The terminal shall support at least thirty entries in the CRL for each RID for which the terminal has CA Public Keys. The device must be able to update the CRL as requested by the acquirer. The payment systems provide these updates to the acquirer. A reliable method of maintaining the CRL is defined by the terminal vendor and the acquirer and should meet the security requirements of the acquirer. It is the responsibility of the payment system to ensure that the number of revoked certificates does not exceed the maximum number of entries that terminals are required to support and the responsibility of the acquirer to ensure that appropriate entries are deleted in order to make way for new entries. Add the following sentence to the end of Footnote 7: This list is described in Section 5.1.2 Certification Revocation List. Add the following section after Section 6.1.1:

6.1.2 Certification Revocation List The terminal may support a Certification Revocation List (CRL) that lists the Issuer Public Key Certificates that payment systems have revoked. If, during dynamic data authentication (DDA or CDA), a concatenation of the RID and Certification Authority Public Key Index from the card and the Certificate Serial Number recovered from the Issuer Public Key Certificate is on this list, dynamic data authentication fails as described in Section 6.3 Step 10 of this book.

The requirements for the CRL are listed in Section 5.1.2 of this book. Add the following sentence at the end of Footnote 16: This list is described in Section 6.1.2 Certification Revocation List. Modify Step 3 on

, Section 7.1 as follows: 3. If the conditions under points 1 and 2 above are not satisfied or if as described in Section 6.1.2 for dynamic data authentication, the Issuer Public Key Certificate has been revoked, then PIN encipherment has failed and the Offline Enciphered PIN CVM has failed.