SB nº 176: EMV® Book C-4, Version 2.5 (Spec Change)
EMV® Specification Bulletin No. 176 First Edition January 2016 EMV Book C-4, Version 2.5 This Specification Bulletin contains an update to EMV Book C-4, Version 2.5.
Effective Date
Requirements in this bulletin will be effective immediately, at which time any affected or new type approval testing will also come into effect.
Applicability
This Specification Bulletin applies to:
- [EMVC4] EMV Contactless Specifications for Payment Systems, Book C-4, Kernel 4 Specification, Version 2.5. March 2015.
Related Documents
- None
Summary
This Specification Bulletin lists a number of errata for EMV Book C-4, Version 2.5 [EMVC4]. The changes in this bulletin have been categorized by the functionality specified in the relevant sections found in [EMVC4]. Each specification change is defined by the content of the relevant part as is in the Version 2.5 specification, followed by the content to be in the updated specification. Any respective differences in the content to be have been underlined accordingly. A. Processing Restrictions A.1. Changes to 7.2.1 Apply Dynamic Transaction limits The comparison of the Amount, Authorised value against Reader Contactless Transaction Limit in the selected Dynamic Reader Limits needs to be updated to “greater than or equal to” to be aligned with EMV Book B. In addition, changes need to be made to ensure that both the card and the reader support an alternative interface before executing the Try Another Interface logic. As Is: If Amount, Authorised is greater than the Reader Contactless Transaction Limit in the selected Dynamic Reader Limits, then set ‘Contactless Application Not Allowed’ to 1.
countries.
… Requirements – Processing Restrictions: Update Indicators Using Dynamic Reader Limits 7.2.1.4a If a set of Dynamic Reader Limits has been selected, and this set contains a Reader Contactless Transaction Limit, and the value of Amount, Authorised is greater than this limit, then the Kernel shall set the ‘Contactless Application Not Allowed’ indicator to 1. … If the ‘Contactless Application Not Allowed’ indicator is set to 1 and the card supports an alternative interface, the Kernel shall return control to Entry Point with a Final Outcome Try Another Interface with the following parameter settings: … Requirements – Processing Restrictions: ‘Contactless Application Not Allowed’ indicator 7.2.1.7a If the ‘Contactless Application Not Allowed’ indicator is set to 1, and any of the following conditions are true:
- Card Interface and Payment Capabilities is not present,
- Card Interface and Payment Capabilities Byte 1 Bit 6 is set to 1b, ‘Contact EMV interface supported’, then the kernel returns control to Entry Point, passing a Final Outcome of Try Another Interface. countries. To Be: If Amount, Authorised is greater than or equal to the Reader Contactless Transaction Limit in the selected Dynamic Reader Limits, then set ‘Contactless Application Not Allowed’ to 1. … Requirements – Processing Restrictions: Update Indicators Using Dynamic Reader Limits 7.2.1.4a If a set of Dynamic Reader Limits has been selected, and this set contains a Reader Contactless Transaction Limit, and the value of Amount, Authorised is greater than or equal to this limit, then the Kernel shall set the ‘Contactless Application Not Allowed’ indicator to 1. … If the ‘Contactless Application Not Allowed’ indicator is set to 1 and the transaction is taking place in EMV mode and both the card and the reader supports an alternative (contact) interface, the Kernel shall return control to Entry Point with a Final Outcome Try Another Interface with the following parameter settings: … Requirements – Processing Restrictions: ‘Contactless Application Not Allowed’ indicator 7.2.1.7a If the ‘Contactless Application Not Allowed’ indicator is set to 1, and the transaction is taking place in EMV mode, and the reader supports and alternative (contact) interface, and any of the following conditions are true:
- Card Interface and Payment Capabilities is not present,
- Card Interface and Payment Capabilities Byte 1 Bit 6 is set to 1b, ‘Contact EMV interface supported’, then the kernel returns control to Entry Point, passing a Final Outcome of Try Another Interface. countries. B. 1st Card Action Analysis B.1. Changes to 11.2.1 Format of the Response to GENERATE AC Command The following excerpts need to be updated to ensure that both the card and the reader support an alternative interface before executing the Try Another Interface logic. As Is: If the response is in the incorrect format then the reader determines whether an alternative interface is supported as follows:
- If any of the following conditions are true:
- Card Interface and Payment Capabilities is not present.
- Card Interface and Payment Capabilities Byte 1 Bit 6 is set to 1b, ‘Contact EMV interface supported’. then the card and the reader support an alternative interface and the kernel returns control to Entry Point with a Final Outcome of Try Another Interface and parameters set as per Table 11-1. Else the card and the reader do not support an alternative interface, and the transaction shall be terminated. The kernel returns control to Entry Point with a Final Outcome of End Application and parameters set as per Table 11-2. To Be: If the response is in the incorrect format then the reader determines whether an alternative interface is supported as follows:
- If the transaction is taking place in EMV mode, and the reader supports and alternative (contact) interface, and any of the following conditions are true:
- Card Interface and Payment Capabilities is not present.
- Card Interface and Payment Capabilities Byte 1 Bit 6 is set to 1b, ‘Contact EMV interface supported’. then the card and the reader support an alternative interface and the kernel returns control to Entry Point with a Final Outcome of Try Another Interface and parameters set as per Table 11-1. Else the card and the reader do not support an alternative interface, and the transaction shall be terminated. The kernel returns control to Entry Point with a Final Outcome of End Application and parameters set as per Table 11-2. countries. C. Online Processing C.1. Changes to 12.2.2 Partial Online Processing Table 12-4 Partial Online – Parameter settings needs to be updated such that there is no restart on an Online Request final outcome, since the card has been removed from the field and no further risk management is performed. The reader should determine the transaction disposition from the online authorization response received and display it to the cardholder accordingly. As Is: Table 12-1: Partial Online - Parameter Settings Start Online Response Data CVM UI Request on Outcome Present UI Request on Restart Present Data Record Present Discretionary Data Present Alternate Interface Preference Receipt Field Off Request Removal Timeout D Any As determined in section 8.2, Cardholder Verification – Processing Requirements Yes
- Message Identifier: '1B' (“Authorising, Please Wait”)
- Status: Processing
- Hold Time: 0
- Language Preference No Yes No N/A N/A N/A Zero countries. To Be: Table 12-2: Partial Online - Parameter Settings Start Online Response Data CVM UI Request on Outcome Present UI Request on Restart Present Data Record Present Discretionary Data Present Alternate Interface Preference Receipt Field Off Request Removal Timeout N/A N/A As determined in section 8.2, Cardholder Verification – Processing Requirements Yes
- Message Identifier: '1B' (“Authorising, Please Wait”)
- Status: Processing
- Hold Time: 0
- Language Preference No Yes No N/A N/A N/A Zero countries.
Legal Notice
The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications.
countries.