SB nº SB-92 : Various Changes to Book 2 (Spec Change)
Specification Bulletin No. 92 September 2011 Various Changes to Book 2 This Specification Bulletin defines various changes to Book 2. These changes are either clarifications, corrections or additional best practices. The changes include recommendations to issuers on ARPC generation and recommendations to acquirers for managing payment system public keys and expiry dates. Effective Dates This bulletin is effective immediately but has no impact on type approval testing.
Applicability
This Specification Bulletin applies to: EMV Integrated Circuit Card Specifications for Payment Systems Version 4.2 Book 2 Security and Key Management Related Documents None
Description
This bulletin replaces references to NIST publications since the relevant algorithm in Book 2 is now specified in a revised ISO/IEC standard. (Note that the CMAC NIST reference had been inserted into version 4.2 of Book 2 by Specification Bulletin 74 (AES option)). This bulletin adds a recommendation on the management of payment system public keys in terminals. This bulletin adds a recommendation that issuers do not respond with an ARPC when ARQC validation fails. This bulletin makes various other clarifications. Specification Change Notice The following changes relate to Book 2. In section 2 „Normative References‟ remove the FIPS 180-2 reference remove the NIST SP38-B reference change “ISO/IEC 9796-2:2002” to “ISO/IEC 9796-2:2010”
http://www.emvco.com/.
change “ISO/IEC 9797-1” to “ISO/IEC 9797-1:2011”. In both section 8.2.1 „ARPC Method 1‟ and section 8.2.2 „ARPC Method 2‟ please delete „generated by the ICC‟ from the first bullet and add the following footnote at the end of each bullet: It is recommended that an ARPC is only returned if the ARQC verification is successful. However if an issuer still intends to return an ARPC when ARQC verification has failed, then the ARPC should not be calculated from the ARQC received from the network. In section 8.2.2 „ARPC Method 2‟ as updated by SB74, please change „NIST CMAC‟ to „CMAC‟. In section 10.2.5.2 „EMV Principles‟ please change the penultimate bullet as follows Ter m in a ls sh a ll pr ovide t h e a bilit y t o va lida t e Cer t ifica t ion Au t h or it y P u blic Key in t egr it y a nd sh ou ld do so per iodica lly. In section 11.2.4 „Certification Authority Public Key Withdrawal‟ please add the following paragraph after the first paragraph: It is recommended that acquirers do not implement expiry dates coded into the terminals but instead remove keys according to the expiry dates as indicated by the payment systems. In section A1.2.2 „MAC algorithms using a 16-byte block cipher‟ as updated by SB74 in the first paragraph, please replace “NIST CMAC” with “ISO/IEC 9797-1:2011 Algorithm 5 (CMAC)”. In Annex C „Informative References‟, please remove the version number and availability information for the EMV Issuer and Application Security Guidelines add a reference “5. EMV Acquirer and Terminal Security Guidelines”.
http://www.emvco.com/.