SB n° SB-84 : CPA Specification Update (Spec Change)
Specification Bulletin No. 84 First Edition December 2010 CPA Specification Update This specification update clarifies the sequence of checking performed by a CPA compliant card in performing Offline Enciphered PIN.
Applicability
This Specification Update Bulletin applies to:
- EMV Integrated Circuit Card Specifications for Payment Systems Common Payment Application Specification Version 1.0
Description
EMV Book 2 Security and Key Management Section 7.2 defines the sequence of checking to be performed for Offline Enciphered PIN. The CPA specification is less clear on this sequence, and the related flow chart is incorrect. The purpose of this Specification Bulletin is to clarify this checking in the CPA specification and to correct the flow chart. Although this bulletin is immediately applicable it has no impact on functional testing. Specification Change Notice In the CPA specification, Section 12.7.2.2 please replace the text shown on the following page with the label 'Original text' with the text shown below with the label 'Replacement text':
http://www.emvco.com/.
Original text: Req 12.30 (Check format of recovered data): After deciphering the Transaction PIN Data, if the recovered data does not meet both of the following conditions:
- the recovered ICC Unpredictable Number matches the ICC Unpredictable Number sent in the response to the GET CHALLENGE command immediately preceding the VERIFY command,
- and the recovered Data Header has the value '7F', then the application:
- shall fail PIN Verification
- shall set the ‘Offline PIN Verification Performed and PIN Not Successfully Verified’ bit in the CVR to the value 1b.
- shall discontinue processing the VERIFY command, shall respond with an SW1 SW2 that indicates an error, and should respond with SW1 SW2 = '6984' (Command not allowed; referenced data invalidated). Otherwise the application shall continue with verification of the recovered PIN Block. Replacement text: Req 12.30 (Check format of recovered data): After deciphering the Transaction PIN Data, the application shall check that the recovered ICC Unpredictable Number matches the ICC Unpredictable Number sent in the response to the GET CHALLENGE command immediately preceding the VERIFY command. If the recovered ICC Unpredictable Number does not match the ICC Unpredictable Number sent in the GET CHALLENGE response, then the application shall not check the value of the recovered Data Header. Otherwise, the application shall check the value of the recovered Data Header. The application shall continue with verification of the recovered PIN block only if both of the following are true:
- the recovered ICC Unpredictable Number matches the ICC Unpredictable Number sent in the GET CHALLENGE response immediately preceding the VERIFY command,
- and the recovered Data Header has the value '7F'. Otherwise the application:
- shall fail PIN Verification
- shall set the ‘Offline PIN Verification Performed and PIN Not Successfully Verified’ bit in the CVR to the value 1b.
- shall discontinue processing the VERIFY command, shall respond with an SW1 SW2 that indicates an error, and should respond with SW1 SW2 = '6984' (Command not allowed; referenced data invalidated). http://www.emvco.com/. The lower section of the flow diagram on CPA -23 (shown below) shows the checking process in a different order from what EMV Book 2 requires. Please replace this section of this original flow diagram with the replacement flow diagram section shown on the following page. Original section of flow diagram on -23: http://www.emvco.com/. Replacement section of flow diagram: 12.7.2.2. decipher PIN data 12.7.2.2. Recovered data [10-17] (challenge) = ICC Unpredictable Y Number sent in GET CHALLENGE response? 12.7.2.2. Recovered data [1] (header) = '7F'? N N 12.7.2.2. Set ‘Offline PIN Verification Performed and PIN Not Successfully Verified’ in CVR to 1b sw12 = '6984' Y sw12 = '6984' PIN check http://www.emvco.com/.