SB nº 177: Errata for EMV® Book C-2 (Version 2.5) (Spec Change)
EMV® Specification Bulletin No. 177 February 2016 Errata for EMV Book C-2 (Version 2.5) This Specification Bulletin contains modifications for EMV Book C-2.
Applicability
This Specification Bulletin applies to: EMV Contactless Specifications for Payment Systems, Book C-2, Kernel 2 Specification, Version 2.5, February 2015
Related Documents
None
Effective Date
This Specification Bulletin is effective immediately.
Summary
This Specification Bulletin describes the following changes to EMV Book C-2: 1- Added support for the Payment Account Reference data object (see EMV SB-167) 2- Added tags for RRP-related data objects in data dictionary 3- Added RRP Counter data object to the Torn Transaction Log Record 4- Corrected template for Static Data Authentication Data in the data dictionary 5- Removed steps S9.12 and S11.14 to avoid unnecessary duplication 6- Modified test on PAN length in RRP processing 7- Modified check on CVM List in CVM.7 8- Modified length of ICC Public Key Remainder in the data dictionary
countries.
1. Payment Account Reference The Payment Account Reference data object is described in EMVCo Specification Bulletin 167. It is added to the data dictionary of Book C-2 with the definition as shown here: A.1.118 Tag: Template: Length: Format: Update: Description: Payment Account Reference '9F24' '70' or '77' 29 an K/RA The Payment Account Reference is a data object associated with an Application PAN. It allows acquirers and merchants to link transactions, whether tokenised or not, that are associated to the same underlying Application PAN. Lower case alphabetic characters are not permitted for the Payment Account Reference, however the Kernel is not expected to check this. The Payment Account Reference data object is also added to the OUT signal in Table 4.7: Table 4.1—Data Record Detail for EMV Mode Transaction …………. Issuer Code Table Index Payment Account Reference Terminal Capabilities ……………… Data Object
countries.
2. Tags for Relay Resistance Protocol Data Objects The following data objects are assigned tags in the data dictionary as listed here: Tag 'DF8301' 'DF8302' 'DF8303' 'DF8304' 'DF8305' 'DF8306' 'DF8307' Data Object Terminal Relay Resistance Entropy Device Relay Resistance Entropy Min Time For Processing Relay Resistance APDU Max Time For Processing Relay Resistance APDU Device Estimated Transmission Time For Relay Resistance RAPDU Measured Relay Resistance Processing Time RRP Counter 3. Added RRP Counter data object to the Torn Transaction Log Record The RRP Counter is added to the list of data objects included in the Torn Transaction Log Record in Table 4.2: Table 4.2—Torn Transaction Log Record Data Object ……… Max Time For Processing Relay Resistance APDU Device Estimated Transmission Time For Relay Resistance R-APDU Measured Relay Resistance Processing Time RRP Counter
countries.
4. Corrected Static Data Authentication Tag List Template. The definition of the Static Data Authentication Tag List in the data dictionary is modified to reference template '77' as well as '70'. A.1.150 Tag: Template: Length: Format: Update: Description: Static Data Authentication Tag List '9F4A' '70' or '77' var. up to 250 b K/RA List of tags of primitive data objects defined in this specification for which the value fields must be included in the Signed Dynamic Application Data.
countries.
5. Removed steps S9.12 and S11.14 The processing steps S9.12 and S11.14 are removed to avoid duplication. S9.12 AddToList(GetTLV(TagOf(IDS Status)), Torn Temp Record) IF ['Read' in IDS Status is set] THEN AddToList(GetTLV(TagOf(DS Summary 1)), Torn Temp Record) ENDIF S9 1 11 Prepare new record for Torn Transaction Log 13 Insert new record in Torn Transaction Log 14 Prepare UI Request (Try Again) 15 OUT (end application) Exit kernel
countries.
S11.14 AddToList(GetTLV(TagOf(IDS Status)), Torn Temp Record) IF ['Read' in IDS Status is set] THEN AddToList(GetTLV(TagOf(DS Summary 1)), Torn Temp Record) ENDIF S11 1 11 IDS Write Flag in Torn Temp Record set ? Yes No 12 Remove Torn Entry from Torn Transaction Log 13 Prepare new record for Torn Transaction Log 15 Insert new record in Torn Transaction Log 16 Prepare UI Request (Try Again) 17 OUT (end application) Exit kernel
countries.
6. Modified test on PAN length in S910.39 As part of RRP processing, the discretionary part of the Track 2 Equivalent Data is populated with zeroes, subject to the length of the PAN. The test on the PAN length in processing step S910.39 is corrected to refer to the PAN in the track data instead of the Application PAN. S910.39 IF [IsNotEmpty(TagOf(Track 2 Equivalent Data))] THEN IF [GetLength(TagOf(Application PAN)) d 8] IF [Number of digits in 'Primary Account Number' in Track 2 Equivalent Data d 16] THEN ……. 7. Modified the check on CVM List Entry The check on the length of each entry in the CVM List is removed from processing step CVM.7 as it is redundant: CVM.7 IF [IsNotPresent(TagOf(CVM List)) OR IsEmpty(TagOf(CVM List)) OR (GetLength(TagOf(CVM List)) = 8)] THEN GOTO CVM.8 ELSE GOTO CVM.9 ENDIF
countries.
8. Length of ICC Public Key Remainder The length of the ICC Public Key Remainder in the data dictionary is modified as follows: A.1.79 Tag: Template: Length: Format: Update: Description: ICC Public Key Remainder '9F48' '70' or '77' NIC-NI + 42 var. b K/RA Remaining digits of the modulus of the ICC public key.
countries.
Legal Notice
The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications.
countries.