SB nº 112 : Combination Selection and Final Combination Selection (Spec Change)
Specification Bulletin No. 112 First Edition August 2012 Combination Selection and Final Combination Selection This Specification Bulletin describes changes to the EMV Contactless Specifications for Payment Systems, Book B, version 2.2.
Applicability
This Specification Bulletin applies to: EMV Contactless Specifications for Payment Systems, Book B, version 2.2 – June 2012. Related Documents None Effective Date November 2012
Description
This specification update bulletin aims to resolve two potential problems in Entry Point processing in Combination Selection and Final Combination Selection. The change to Combination Selection removes a check for international kernel while determining whether a Requested Kernel ID is supported for a reader Combination. The change to Final Combination Selection resolves a scenario where, after processing, there remain multiple Combinations in the Candidate List. This would happen for example in the following situations: Notations {x,y}c = a PPSE entry with x= ADF Name, y=kernel ID {x,-}c = a PPSE entry with x= ADF Name but no kernel ID {x,y}r = a reader combination with x=AID, y=kernel ID AID = an AID AID+ext = an AID with PIX Extension ext Example 1 Suppose the reader supports the following combinations, where the AID is a nonAmex/MasterCard/Visa AID: 1. {AID,K1}r 2. {AID,K2}r Now suppose the card has this entry in the PPSE: 1. {AID,-}c
Entry Point would add 2 Combinations to the Candidate List: {AID,-}c {AID,K1}r {AID,K2}r match match As these Combinations have been added to the Candidate List when processing the same PPSE entry, there is no specified way for the reader to choose any one of them (the priority and order of appearance in the PPSE are identical for these Combinations). Example 2 Suppose the reader supports the following combinations: 1. {AID,K1}r 2. {AID+ext1,K1}r 3. {AID+ext1+ext2,K1}r Now suppose the card has this entry in the PPSE: 1. { AID+ext1+ext2,K1}c Entry Point would add 3 Combinations to the Candidate List: {AID+ext1+ext2,K1}c {AID,K1}r {AID+ext1,K1}r match match {AID+ext1+ext2,K1}r match As these Combinations have been added to the Candidate List when processing the same PPSE entry, there is no specified way for the reader to choose any one of them (the priority and order of appearance in the PPSE are identical for these Combinations). The change to Final Combination Selection resolves the situations exemplified above. This change states that, after processing the Candidate List with regards to the priority of PPSE entries and order of PPSE entries, if there remain several Combinations, the reader may select any one of them.
Proposed Specification Changes 1. Requirement 3.3.2.5, first paragraph. Change: For each reader Combination {AID – Kernel ID} supported by the reader for which the ‘Contactless Application Not Allowed’ indicator is 0, Entry Point shall process each Directory Entry (Tag '61') from the FCI. When the Directory Entries have been processed for all supported reader Combinations, Entry Point shall proceed to Step 3. To the following: For each reader Combination {AID – Kernel ID} supported by the reader for which the ‘Contactless Application Not Allowed’ indicator is 0, Entry Point shall process each Directory Entry (Tag '61') from the FCI. When the Directory Entries have been processed for all supported reader Combinations, Entry Point shall proceed to Step 3. 2. Requirement 3.3.2.5, bullet D. Change: Entry Point shall examine whether the Requested Kernel ID is supported for the reader Combination.
- If the value of the Requested Kernel ID is non-zero, and the value of the Requested Kernel ID is equal to the value of the Kernel ID, then the kernel requested by the card is supported by the reader; otherwise Entry Point shall proceed with the next Directory Entry (bullet A).
- If the value of the Requested Kernel ID is zero, and the Kernel Identifier indicates an international kernel (byte 1, b8 of the Kernel Identifier has the value 0b), then the kernel requested by the card is supported by the reader (e.g. a JCB product will use the Kernel ID of an international kernel associated with the JCB AID); otherwise Entry Point shall return to bullet A and proceed with the next Directory Entry. To the following: Entry Point shall examine whether the Requested Kernel ID is supported for the reader Combination.
- If the value of the Requested Kernel ID is zero, then the kernel requested by the card is supported by the reader (e.g. a JCB product will use the Kernel ID of an international kernel associated with the JCB AID);
- If the value of the Requested Kernel ID is non-zero and the value of the Requested Kernel ID is equal to the value of the Kernel ID, then the kernel requested by the card is supported by the reader;
- Otherwise Entry Point shall return to bullet A and proceed with the next Directory Entry. 3. Requirement 3.3.2.5, bullet E. Change: Entry Point shall add a Combination to the Candidate List for final selection, consisting of: o the ADF Name o the Kernel ID o the Application Priority Indicator (if present) o the Extended Selection (if present) To the following: Entry Point shall add a Combination to the Candidate List for final selection, consisting of: o the ADF Name o the AID o the Kernel ID o the Application Priority Indicator (if present) o the Extended Selection (if present) 4. Requirement 3.3.3.2. Change: If there are multiple Combinations in the Candidate List, then Entry Point shall select the Combination as follows: Consider each Combination that has an Application Priority Indicator with a value of 0 or no Application Priority Indicator to be of equal lowest priority. If a single Combination has a higher priority than any other Combination in the Candidate List, select that Combination. If multiple Combinations in the Candidate List have the highest priority, then select the Combination that occurs first in the PPSE. To the following: If there are multiple Combinations in the Candidate List, then Entry Point shall select the Combination as follows: Consider each Combination that has an Application Priority Indicator with a value of 0 or no Application Priority Indicator to be of equal lowest priority. If a single Combination has a higher priority than any other Combination in the Candidate List, then select that Combination. Otherwise multiple Combinations in the Candidate List have the highest priority, and Entry Point shall select a Combination as follows: Determine14 the order of these Combinations’ ADF Names and Kernel IDs in the PPSE, where the order is the position in the PPSE, with the lowest order being the first. Select any one of the Combinations that have the lowest order. 14 Unless track of the position of the PPSE entry leading to the addition of each Combination in the Candidate List was kept (while processing Requirement 3.3.2.5), it will be necessary to reprocess Requirement 3.3.2.5 for each of these combinations, instead of the complete list of reader Combinations, to determine which one corresponds to the earliest entry in the PPSE. 5. Requirement 3.3.3.5. Change: If the response to the SELECT (AID) command includes an SW1 SW2 other than '9000', then Entry Point shall remove the selected Combination with this ADF Name from the Candidate List and shall return to Start C (Step 3 of Combination Selection (requirement 3.3.2.6)). To the following: If the response to the SELECT (AID) command includes an SW1 SW2 other than '9000', then Entry Point shall remove the selected Combination from the Candidate List and shall return to Start C (Step 3 of Combination Selection (requirement 3.3.2.6)). 6. Requirement 3.3.3.6, second bullet of the ‘then’ clause. Change: If Kernel 1 is not supported, then Entry Point shall remove the selected Combination associated with this ADF Name from the Candidate List and shall return to Start C (Step 3 of Combination Selection (requirement 3.3.2.6)). To the following: If Kernel 1 is not supported, then Entry Point shall remove the selected Combination from the Candidate List and shall return to Start C (Step 3 of Combination Selection (requirement 3.3.2.6)). 7. Requirement 3.5.1.4. Change: If the Outcome is Select Next, then Entry Point shall remove the selected Combination associated with this ADF Name from the Candidate List and shall return to Start C (Step 3 of Combination Selection (requirement 3.3.2.6)). To the following: If the Outcome is Select Next, then Entry Point shall remove the selected Combination from the Candidate List and shall return to Start C (Step 3 of Combination Selection (requirement 3.3.2.6)).