SB nº SB-82 : Various Terminal Updates (Spec Change)

v1.0 Specification Bulletins

Specification Bulletin No. 82 First Edition February 2010 Various Terminal Updates This specification update defines various enhancements to terminal behaviour. These include a new requirement on terminal behaviour relating to data origin, revised Terminal Risk Management behaviour, and revised recommendations on Certificate Revocation Lists and Unpredictable Numbers Effective Dates The effective date for each change is specified in the description

Applicability

This Specification Bulletin applies to:

  • EMV Integrated Circuit Card Specifications for Payment Systems Version 4.2 Book 3 Application Specification
  • EMV Integrated Circuit Card Specifications for Payment Systems Version 4.2 Book 4 Cardholder, Attendant and Acquirer Interface Requirements

Related Documents

  • None Description 1. Terminal and issuer sourced data This bulletin clarifies that terminals must ignore data elements coming from the card which are designated in the data dictionary as terminal-sourced data or issuer-sourced. This terminal requirement is mandatory from November, 2010. 2. TRM behaviour The EMV specifications require terminals to perform Terminal Risk Management when the ‘Terminal Risk Management shall be performed’ bit in the AIP is set to ‘1’, and in addition allow terminals to perform Terminal Risk Management even when this AIP bit is set to ‘0’. The purpose of this bulletin change is to require, rather than allow, that offline capable terminals perform Terminal Risk Management regardless of the setting of the AIP bit in the card. This EMV requirement now aligns with existing payment system requirements. This requirement is immediately effective and will be tested from November, 2010. http://www.emvco.com/. 3. CRLs This bulletin changes the specifications so as to recommend that terminals supporting offline cryptography support certification revocation lists (CRLs). 4. Unpredictable Numbers This bulletin enhances the EMV recommendations for the generation of Unpredictable Numbers. Specification Change Notice 1. Terminal or issuer sourced data Please insert the following new paragraphs after paragraph 3 in Book 3 section 7.5: During a transaction the terminal shall ignore any data object coming from the ICC which is designated in the EMV data elements dictionary (Table 33 in Annex A) as terminal-sourced or issuer-sourced. The data elements dictionary defines data as being sourced from any of three places: the ICC, the terminal or the issuer. 2. TRM behaviour Please replace Book 3 section 10.6 ‘Conditions of Execution’ including the note with the following: Terminal risk management shall always be performed regardless of the setting of the ‘Terminal risk management is to be performed’ bit in the Application Interchange Profile. Random transaction selection need not be performed by a terminal with no online capability. 3. Certificate Revocation Lists Please append the following paragraph to section 6.3.2 of Book 4: Terminals supporting offline cryptography should support Certificate Revocation Lists (CRLs). If CRLs are supported, the support shall be in accordance with section 5.1.2 of Book 2. 4. Unpredictable Numbers Please replace the 2nd paragraph of Book 4 section 6.5.6 and associated footnote with the following: The Unpredictable Number could be generated by a dedicated hardware random number generator or could, for example, be a function of previous Application Cryptograms, the terminal Transaction Sequence Counter and other variable data (e.g. date/time). In the second example the function could be a hash function or more preferably a keyed encipherment function. http://www.emvco.com/.