SB nº SB-91 : AES Support in Common Core Definitions (CCD) (Spec Change)
Specification Bulletin No. 91 First Edition August 2011 AES Support in Common Core Definitions (CCD) This specification update defines how AES is to be supported in those Common Core Definitions (CCD) applications that support AES. AES support in CCD is optional, and CCD testing is not scheduled to include testing for any AES functionality in CCD applications.
Applicability
This Specification Bulletin applies to: EMV Integrated Circuit Card Specifications for Payment Systems Version 4.2 Book 2 Security and Key Management EMV Integrated Circuit Card Specifications for Payment Systems Version 4.2 Book 3 Application Specification
Related Documents
This Specification Bulletin should be read in conjunction with: EMV Specification Bulletin #74 AES in EMV Second Edition July 2010.
Description
This specification bulletin adds an option to CCD for the use of AES as the algorithm for online cryptography. Up to now, only Triple DES has been supported for CCD applications. This AES support is being defined at this time so that issuers who wish to implement AES to satisfy local requirements will do so in a consistent manner. It is anticipated that most CCD applications will continue to support Triple DES. Testing of the AES functionality will be the responsibility of those using this option since EMVCo has no current plans to test the option for AES. Specification Change Notice Please make the following changes to EMV Book 2 Security and Key Management Part IV Common Core Definitions: 1. Replace the first sentence of the first paragraph of CCD Section 8.1.1 Data Selection with the following: "Table CCD 3 lists the set of data elements to be included in the Application Cryptogram for a cryptogram defined by the Common Core Definitions with a Cryptogram Version of '5' (which uses Triple DES) or '6' (which uses AES)." 2. Replace all of CCD Section 8.1.2 Application Cryptogram Version Algorithm with the following: "The Application Cryptogram shall be 8-bytes. EMV-defined Application Cryptograms shall be generated using one of two methods: using the MAC algorithm specified in Annex A1.2.1 and ISO/IEC 9797-1 Algorithm 3 with DES, and s=8. This method shall be used for a Cryptogram Version of '5'. using the MAC algorithm specified in Annex A1.2.2 with AES and s=8. This method shall be used for a Cryptogram Version of '6'. For an application defined by the Common Core Definitions with a Cryptogram Version of '5' or '6', the AC Session Key shall be derived using the method specified in Annex A1.3.1." 3. In CCD Section 8.2.2 APRC Method 2 first paragraph first sentence, add "or '6' " after "with a Cryptogram Version of '5'." 4. In CCD Section 8.3 Key Management, add the following paragraph after the first paragraph: "For a cryptogram defined by the Common Core Definitions with a Cryptogram Version of '6', the ICC Master Key shall be derived using the Option C method described in Annex A1.4.3." 5. In CCD Section 9.2.2 MAC Session Key Derivation, add "or '6' " after "with a Cryptogram Version of '5'." 6. In CCD Section 9.2.3 MAC Computation, replace all of the third paragraph with the following:
"The MAC for Cryptogram Version '5' shall be generated using the MAC algorithm specified in Annex A1.2.1, Step 3, second bullet using DES as the block cipher. The MAC for Cryptogram Version '6' shall be generated using the MAC algorithm specified in Annex A1.2.2 using AES as the block cipher." 7. In Section 9.3.2 Encipherment Session Key Generation, add "or '6' " after "with a Cryptogram Version of '5'." 8. Replace Section 9.3.3 Encipherment/Decipherment with the following: "Encipherment/decipherment of the command data field shall use the Cipher Block Chaining (CBC) Mode described in Annex A1.1. For Cryptogram Version '5' the Triple DES algorithm specified in Annex B1.1 is used. For Cryptogram Version '6' the AES algorithm specified in Annex B1.2 is used. For both versions the Padding Indicator byte is set to the value '01' to indicate that padding is present." 9. Add the following paragraph to the end of Section 9.4 Key Management: "For an application with a cryptogram defined by the Common Core Definitions with a Cryptogram Version of '6', the ICC MAC and Encipherment Master Keys shall be derived using the Option C method described in Annex A1.4.3." Please make the following changes to EMV Book 3 Application Specification Part V Common Core Definitions: 10. Change Table CCD 8 in Section C7.1 Common Core Identifier: In the last row, change "(= '5')" to "(= '5' for Triple DES)." After the last row, add the following row: b8 b7 b6 b5 b4 b3 b2 b1 Meaning 0 1 1 0 CCD Ver sion 4.1 Cr ypt ogr a m Ver sion (= '6' for AE S) 11. Change the caption on Table CCD 11 in Section C8 Card Status Update for a Common Core Definitions-Compliant Application to "Card Status Update for Cryptogram Versions '5' and '6'." After the changes to EMV Book 2 are made, Part IV Common Core Definitions will have the following text. Deleted text is shown with strike-throughs and added text is underlined.
Common Core
Definitions
This Part describes an optional extension to this Book, to be used when implementing the Common Core Definitions (CCD). These Common Core Definitions specify a minimum common set of card application implementation options, card application behaviours, and data element definitions sufficient to accomplish an EMV transaction. Terminals certified to be compliant with the existing EMV specifications will, without change, accept cards implemented according to the Common Core Definitions, since the Common Core Definitions are supported within the existing EMV requirements. To be compliant with the Common Core Definitions, an implementation shall implement all the additional requirements in the Common Core Definitions Parts of all affected Books. Changed Sections Each section heading below refers to the section in this Book to which the additional requirements apply. The text defines requirements for a common core implementation, in addition to the requirements already specified in the referenced section of EMV. Part II – Security and Key Management Techniques 6 Offline Dynamic Data Authentication 6.5 Dynamic Data Authentication (DDA) 6.5.1 Dynamic Signature Generation An ICC that supports DDA shall contain a DDOL. The DDOL shall contain only the Unpredictable Number generated by the terminal (tag '9F37', 4 bytes binary).
6.6 Combined DDA/Application Cryptogram Generation (CDA) 6.6.1 Dynamic Signature Generation For a CCD-compliant application that supports CDA, the following requirements shall apply. The ICC response to the GENERATE AC command for a TC or ARQC shall contain only the data objects specified in Table CCD 1 (which, for CCD, supplants Table 20).
Tag '9F 27' '9F 36' '9F 4B' '9F 10' Length 1 2 N IC 32 Value Cr ypt ogr a m In for m a t ion Dat a Applica t ion Tr a nsa ct ion Cou n t er Sign ed Dyn a m ic Applica t ion Da t a Issu er Applica t ion Da t a Presence M M M M Table CCD 1: Data Objects in Response to GENERATE AC for TC or ARQC 3. If t h e ICC r espon ds wit h a n AAC, t h e ICC r espon se sh a ll be coded accor din g t o for m at 2 a s specified in sect ion 6.5.5.4 of Book 3 a n d sh a ll cont a in on ly t h e dat a elem en t s specified in Ta ble CCD 2 (wh ich, for CCD, su ppla n t s Ta ble 21). Tag '9F 27' '9F 36' '9F 26' '9F 10' Length 1 2 8 32 Value Cr ypt ogr a m In for m a t ion Dat a Applica t ion Tr a nsa ct ion Cou n t er Applica t ion Au t hen t icat ion Cr ypt ogr a m Issu er Applica t ion Da t a Presence M M M M Table CCD 2: Data Objects in Response to GENERATE AC for AAC
8 Application Cryptogram and Issuer Authentication 8.1 Application Cryptogram Generation 8.1.1 Data Selection Ta ble CCD 3 list s t h e set of da t a elem en t s t o be in cluded in t h e Applica t ion Cr ypt ogr am gen er a t ion for a cr ypt ogr a m defined by t h e Com m on Cor e Defin it ions wit h a Cr ypt ogr a m Ver sion of '5' (wh ich u ses Tr iple DE S) or '6' (wh ich u ses AE S). Th e dat a elem en t s sh a ll be in cluded in t he or der shown in Ta ble CCD 3 [wh ich, for CCD, su ppla nt s Ta ble 26]. Value Am ou n t, Au t h or ised (Nu m er ic) Am ou n t Ot h er (Num er ic) Ter m in a l Cou n t r y Code Ter m in a l Ver ifica t ion Resu lt s Tr a n sa ct ion Cu r r en cy Code Tr a n sa ct ion Da t e Tr a n sa ct ion Type Un pr edict a ble Num ber Applica t ion In t er ch a n ge P r ofile Applica t ion Tr a nsa ct ion Cou n t er Issu er Applica t ion Da t a Source Ter m in a l Ter m in a l Ter m in a l Ter m in a l Ter m in a l Ter m in a l Ter m in a l Ter m in a l ICC ICC ICC Table CCD 3: Data Elements for Application Cryptogram Generation 8.1.2 Application Cryptogram Algorithm Th e 8-byt e Applica t ion Cr ypt ogr a m sh all be 8-byt es. E MV-defin ed Applica t ion Cr ypt ogr a m s sh a ll be gen er a t ed usin g on e of t wo m et hods: u sin g t h e MAC a lgor it hm specified in An n ex A1.2.1 a n d ISO/IE C 9797-1 Algor it h m 3 wit h DE S a n d s=8. Th is m et h od sh a ll be used for a Cr ypt ogr a m Ver sion of '5'. u sin g t h e MAC a lgor it hm specified in An n ex A1.2.2 wit h AE S a n d s=8. Th is m et h od sh a ll be used for a Cr ypt ogr am Ver sion of '6'. F or a n applica t ion defined by t h e Com m on Cor e Defin it ion s wit h a Cr ypt ogr a m Ver sion of '5' or '6', t h e AC Session Key sh a ll be der ived u sin g t h e m et h od specified in An n ex A1.3.1.
8.2 Issuer Authentication Th e CCD-com plia n t a pplica t ion sh a ll su ppor t Issu er Au t h ent ica t ion accor din g t
- ARP C Met h od 2 specified in sect ion 8.2.2.
8.2.2 ARPC Method 2 F or a cr ypt ogr a m defin ed by t h e Com m on Cor e Definit ions wit h a Cr ypt ogr a m Ver sion of '5' or '6', t h e Ca r d St at u s Updat e (CSU) da t a elem en t sh a ll be coded a ccor din g t
- An n ex C8 in t h e CCD pa r t of Book 3. Th e defa u lt va lu e for P r opr iet ar y Au t h ent ica t ion Dat a is zer o. If t h e ‘P r opr iet a r y Au t hen t ica t ion Da t a In clu ded’ bit in t h e CSU h a s t he va lu e 0b, t h en t h e len gt h of P r opr iet a r y Au t h en t icat ion Dat a in clu ded in gener a t ion an d va lidat ion of t h e ARP C sh all be 0 byt es. N o te: If t h e ‘P r opr iet a r y Au t h en t ica t ion Da t a In clu ded’ bit in t h e CSU h a s t h e va lu e 0b, t h e P r opr iet a r y Au t h en t ica t ion Da t a is n ot pr ot ect ed by Issu er Au t h en t ica t ion. Th e ca r d sh ou ld n ot t a k e a ct ion ba sed on t h e set t in gs of a n y P r opr iet a r y Au t h en t ica t ion Da t a t h a t is n ot pr ot ect ed by Issu er Au t h en t ica t ion. If t h e ‘P r opr iet a r y Au t hen t ica t ion Da t a In clu ded’ bit in t h e CSU h a s t he va lu e 1b, t h en t h e P r opr iet a r y Au t hent ica t ion Da t a in clu ded in t h e Issu er Au t hen t icat ion Da t a sh a ll be u sed in gen er at ion an d va lidat ion of t h e ARP C.
8.3 Key Management F or a cr ypt ogr a m defin ed by t h e Com m on Cor e Definit ions wit h a Cr ypt ogr a m Ver sion of '5', t h e ICC Mast er Key sh a ll be der ived using t h e Opt ion B m et h od descr ibed in An n ex A1.4.2. F or a cr ypt ogr a m defin ed by t h e Com m on Cor e Definit ions wit h a Cr ypt ogr a m Ver sion of '6', t h e ICC Mast er Key sh a ll be der ived using t h e Opt ion C m et h od descr ibed in An n ex A1.4.3. 9 Secure Messaging 9.1 Secure Messaging Format All com m a n ds u sin g Secu r e Messa gin g sh a ll u se Secur e Messa gin g F or m a t 1 as descr ibed in t h is Book.
9.2 Secure Messaging for Integrity and Authentication 9.2.1 Command Data Field All com m a n ds u sin g Secu r e Messa gin g for in t egr it y a n d a u t h ent ica t ion: sh a ll use Secur e Messagin g F or m a t 1 as descr ibed in sect ion D2.1.1 sh a ll ch a in t h e MACs fr om on e com m a n d t o t h e n ext accor din g t o t h e m et h od r ecom m en ded in sect ion 9.2.3.1.
9.2.1.1 Format 1 All com m a n d dat a sh a ll be inclu ded in t h e com pu t a t ion of t he MAC.
Da t a en ciph er ed for confiden t ia lit y sh a ll be en ca psu la t ed wit h t a g '87'. Da t a n ot en ciph er ed for confiden t ia lit y sh a ll be en ca psu la t ed wit h t a g '81'. Th e CCD-com plia n t a pplica t ion sh a ll accept 4-byt e MACs, a n d t h e issu er ca n on ly r ely on suppor t of 4-byt e MACs.
9.2.2 MAC Session Key Derivation F or a n applica t ion wit h a cr ypt ogr a m defin ed by t h e Com m on Cor e Defin it ion s wit h a Cr ypt ogr a m Ver sion of '5' or '6', t h e MAC Session Key sh a ll be der ived u sin g t h e m et h od specified in An n ex A1.3.1.
9.2.3 MAC Computation Secu r e Messa gin g is a ccor din g t
- Secu r e Messagin g F or m a t 1. Th e CCD-com plia n t a pplica t ion sh a ll accept 4-byt e MACs, a n d t h e issu er ca n on ly r ely on suppor t of 4-byt e MACs. Th e MAC for Cr ypt ogr am Ver sion '5' sh a ll be gen er a t ed u sin g t h e MAC a lgor it h m specified in An n ex A1.2.1, St ep 3, secon d bu llet u sin g DE S as t h e block ciph er. Th e MAC for Cr ypt ogr am Ver sion '6' sh a ll be gen er a t ed u sin g t h e MAC a lgor it h m specified in An n ex A1.2.2 u sin g AE S a s t h e block ciph er.
9.3 Secure Messaging for Confidentiality 9.3.1 Command Data Field All com m a n ds u sin g secu r e m essa gin g for con fiden t ia lit y sh all use Secu r e Messa gin g F or m a t 1 as descr ibed in sect ion 9.3.1.1.
9.3.1.1 Format 1 Da t a en ciph er ed for confiden t ia lit y sh a ll be en ca psu la t ed wit h Ta g '87'. Da t a t h a t is en ciph er ed in t he Issu er S cr ipt Com m a n d dat a field sh a ll a lwa ys be pa dded befor e en ciph er m en t. Th e P a ddin g In dicat or byt e sh own in F igu r e 8 sha ll be in clu ded a n d sh all be set t o t h e va lu e '01' t o indica t e paddin g is pr esen t.
9.3.2 Encipherment Session Key Derivation F or a n applica t ion wit h a cr ypt ogr a m defin ed by t h e Com m on Cor e Defin it ion s wit h a Cr ypt ogr a m Ver sion of '5' or '6', t h e E nciph er m en t Session Key sh a ll be der ived usin g t h e m et h od specified in An n ex A1.3.1.
9.3.3 Encipherment/Decipherment E n ciph er m en t /deciph er m en t of t h e com m a nd da t a field sh a ll use t h e Ciph er Block Ch a in in g (CBC) Mode descr ibed in An n ex A1.1. F or Cr ypt ogr am Ver sion '5' wit h t h e Tr iple DE S a lgor it h m specified in An n ex B1.1 is used. F or Cr ypt ogr a m Ver sion '6' t h e AE S a lgor it hm specified in An n ex B1.2 is u sed. F or bot h ver sions, t h e P a ddin g In dica t or byt e is set t o t h e va lu e '01' t o in dica t e t h at paddin g is pr esen t.
9.4 Key Management F or a n applica t ion wit h a cr ypt ogr a m defin ed by t h e Com m on Cor e Defin it ion s wit h a Cr ypt ogr a m Ver sion of '5', t h e ICC MAC a n d En ciph er m en t Mast er Keys sh all be der ived u sin g t h e Opt ion B m et h od descr ibed in An n ex A1.4.2.
F or a n applica t ion wit h a cr ypt ogr a m defin ed by t h e Com m on Cor e Defin it ion s wit h a Cr ypt ogr a m Ver sion of '6', t h e ICC MAC a n d En ciph er m en t Mast er Keys sh all be der ived u sin g t h e Opt ion C m et h od descr ibed in An n ex A1.4.3.