SB nº SU-70 : Selectable Kernel Configurations (Spec Change)
Specification Update No. 70 Third Edition August 2011 Selectable Kernel Configurations Allows terminals to support different capabilities for different types of transactions. This Third Edition removes the EMV-defined selection criteria.
Effective Date
This bulletin is effective from November 2011, at which time any affected or new type approval testing will also come into effect.
Applicability
This Specification Update Bulletin applies to:
- EMV Integrated Circuit Card Specifications for Payment Systems Version 4.2 Book 4 Cardholder, Attendant, and Acquirer Interface Requirements
Related Documents
None. Changes from Second Edition This Third Edition removes the EMV-defined selection criteria.
Description
Selectable Kernel Configurations In order to enable more flexible adjustment of terminal functionality to satisfy particular business requirements of the payments market, terminals will be allowed to support certain capabilities for some types of transactions and different capabilities for other types of transactions. For example, a terminal might support the ‘No CVM Required’ CVM for low value transactions and might support ‘Offline PIN’ for higher value transactions. To accomplish this functionality, terminals will now be allowed to dynamically invoke appropriate type-approved kernel configurations, which support the required terminal capabilities on a transaction-by-transaction basis. The determination of the kernel configuration to be invoked is based on certain characteristics of the transaction and card (the selection criteria). Basic Rules The following data objects are now allowed to vary on a transaction by transaction basis: Terminal Capabilities Additional Terminal Capabilities Terminal Type Transaction by transaction variation means that for each transaction, the terminal may invoke a particular type approved EMV kernel configuration based on the selection criteria. Only those kernel configurations which have been type-approved by EMVCo may be invoked. Each kernel configuration that may be invoked by the terminal must be EMVCo type-approved according to its related ICS. The selection of the kernel configuration to be used for a particular transaction must occur before the terminal issues the GET PROCESSING OPTIONS command. This specification update modifies Book 4 to allow variation of this data on a transaction by transaction basis. Specification Change Notice Please replace sections 10 and 10.1 of the EMV Integrated Circuit Card Specifications for Payment Systems Version 4.2 Book 4 Cardholder, Attendant, and Acquirer Interface Requirements with the following:
10 Data Management The data elements listed in this section shall be initialised in the terminal or obtainable at the time of a transaction. (Definitions for these data are in Book 3.) Additional data elements may be required for initialisation, such as those currently used for magnetic stripe processing. Whenever a data element is initialised or updated, data integrity shall be assured. Data elements resident in the terminal shall be under the control of one of the following parties:
- Terminal manufacturer: For example, IFD Serial Number
- Acquirer (or its agent): For example, Merchant Category Code
- Merchant: For example, Local Date and Local Time (these may be controlled by either the merchant or acquirer) The terminal should be constructed in such a way that the data which is under control of the acquirer is only initialised and updated by the acquirer (or its agent).
10.1 Application Independent Data The terminal resident application independent data elements identified in this section shall be initialised in and obtainable from the terminal prior to the issuance of the GET PROCESSING OPTIONS command in the Initiate Application Processing function described in Book 3 section 10.1. The data shall not change during the transaction. Any data sent in the authorisation request message shall have the same value as that provided to the card as listed in the PDOL (if present) and CDOL1, including Local Date and Local Time if appropriate.
10.1.1 Terminal Related Data The following data elements are application independent and shall be unique to the terminal (see section 5.3 for different terminal configurations):
- IFD Serial Number
- Local Date
- Local Time
- Terminal Country Code
- Transaction Sequence Counter The terminal shall have parameters initialised so that it can identify what language(s) are supported to process the card’s Language Preference (see section 11.1).
10.1.2 Transaction Related Data The following data elements are application independent and may be specific to each device constituting the terminal, such as a host concentrating a cluster of devices (see Figure 2 for an example):
- Additional Terminal Capabilities
- Terminal Capabilities
- Terminal Type The terminal shall be constructed in such a way that these data objects cannot be modified unintentionally or by unauthorised access. These data objects may be varied on a transaction by transaction basis which means that for each transaction, the terminal may invoke a different value for these data objects based on certain characteristics and parameters of the transaction (selection criteria). Support of this functionality is optional for the terminal. The implementation of this functionality is left to the discretion of the terminal manufacturer and is outside the scope of EMV.