Book C-8 Kernel 8 Specification

v1.0 Specifications
Contactless Acceptance Device

EMV® Contactless Specifications for Payment Systems Book C-8 Kernel 8 Specification Version 1.0 October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0

Legal Notice

The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a licence to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications.

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1. 1. 1. 1. 1. 1. 1.5. 1.5. 1.5. 1. 2. 2. 2.2. 2.2. 2.2. 2.2. 2.2. 2.2. 2. 3. 3. 3. 3. 3.4. 3.4. 3.4. 3.4. 3. October 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec 1.0 3. 3. 3. 3. 4. 4.1. 4.1. 4.1. 4.1. 4. 4. 4. 4. 4. 4. 4.7. 4.7. 4. 5. 5. 5.2. 5.2. 5.2. 5.2. 5. 5.3. 5.3. 5.3. 5.3. 5. 5.4.

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0 Contents 5.4.2 5.4.3 5.4. 5. 5.5. 5.5. 5.5. 5.5. 5. 5.6. 5.6. 5.6. 5.6. 5. 5.7. 5.7. 5.7. 5.7. 6. 6. 6. 6.3. 6.3. 6.3. 6.3.

6.3.5 State 21 – Waiting for Exchange Relay Resistance Data Response... 99 6.3. 6.3. 6.3. 6.3. 6.3. 6.3. 6.3. 6.3. October 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec 1.0 6.3.14 6.3.15 6.3.16 6.3.17 6.3.18 6.3. 6. 6.4. 6.4. 7. 7. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 7.2. 8 8.1 8.2 8.3 8.4 8.5 8. A. A.1.

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0 Contents A.1.2 A.1.3 A.1.4 A.1.5 A.1.6 A.1.7 A.1.8 A.1.9 A.1.10 A.1.11 A.1.12 A.1.13 A.1.14 A.1.15 A.1.16 A.1.17 A.1.18 A.1.19 A.1.20 A.1.21 A.1.22 A.1.23 A.1.24 A.1.25 A.1.26 A.1.27 A.1.28 A.1.29 A.1.30 A.1.31 A.1.32 A.1.33 A.1.34 A.1.35 A.1.36 A.1. October 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec 1.0 A.1.38 A.1.39 A.1.40 A.1.41 A.1.42 A.1.43 A.1.44 A.1.45 A.1.46 A.1.47 A.1.48 A.1.49 A.1.50 A.1.51 A.1.52 A.1.53 A.1.54 A.1.55 A.1.56 A.1.57 A.1.58 A.1.59 A.1.60 A.1.61 A.1.62 A.1.63 A.1.64 A.1.65 A.1.66 A.1.67 A.1.68 A.1.69 A.1.70 A.1.71 A.1.

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0 Contents A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. October 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec 1.0 A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0 Contents A. B. B. October 2022

countries.

Contents EMV Contactless Book C-8 Kernel 8 Spec 1.0

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0 1 Using This Manual 1.1

Purpose

This document, EMV Contactless Specifications for Payment Systems, Book C-8 – Kernel 8 Specification, should be read in conjunction with:

  • EMV Contactless Specifications for Payment Systems, Book A – Architecture and General Requirements, hereafter referred to as [EMV Book A], and
  • EMV Contactless Specifications for Payment Systems, Book B – Entry Point Specification, hereafter referred to as [EMV Book B]. This document defines the behaviour of the Kernel used in combination with cards having a Kernel Identifier indicating Kernel 8, as defined in [EMV Book B]. Note: While this kernel is compatible with any Entry Point version, payment systems may specify a minimum Entry Point version that they require. For example, if the Kernel Identifier–Terminal (tag '96') data object is to be used, then the minimum version of Entry Point is Version 2.10 with Specification Bulletin 268.

1.2 Audience This specification is intended for use by manufacturers of contactless readers and terminals. It may also be of interest to manufacturers of contactless cards and to financial institution staff responsible for implementing financial applications in contactless cards.

1.3 Related Information The following references are used in this document

It is noted that the latest version applies unless a publication date is explicitly stated. Reference [EMV Book 1] Document Title Integrated Circuit Card Specifications for Payment Systems – Book 1, Application Independent ICC to Terminal Interface Requirements, Version 4.3, November 2011

October 2022

countries.

1 Using This Manual 1.3 Related Information EMV Contactless Book C-8 Kernel 8 Spec 1.0 Reference [EMV Book 2] Document Title Integrated Circuit Card Specifications for Payment Systems – Book 2, Security and Key Management, Version 4.3, November 2011 [EMV Book 3] Integrated Circuit Card Specifications for Payment Systems – Book 3, Application Specification, Version 4.3, November 2011 [EMV Book 4] Integrated Circuit Card Specifications for Payment Systems – Book 4, Cardholder, Attendant, and Acquirer Interface Requirements, Version 4.3, November 2011 [EMV Book A] EMV Contactless Specifications for Payment Systems, Book A – Architecture and General Requirements, Version 2.10 [EMV Book B] EMV Contactless Specifications for Payment Systems, Book B – Entry Point Specification, Version 2.10 [EMV CL L1] EMV Level 1 Specifications for Payment Systems, EMV Contactless Interface Specification, Version 3.1 [ISO 639-1] Codes for the representation of names of languages – Part 1: Alpha-2 Code [ISO 3166-1] Codes for the representation of names of countries and their subdivisions – Part 1: Country codes [ISO 4217] Codes for the representation of currencies and funds [ISO/IEC 7813] Information technology — Identification cards — Financial transaction cards [ISO/IEC 7816-4] Identification cards — Integrated circuit(s) cards with contacts — Part 4: Organization, security and commands for interchange [ISO/IEC 7816-5] Registration of application providers [ISO 8583:1987] Financial transaction card originated messages – Interchange message specifications [ISO 8583:1993] Financial transaction card originated messages – Interchange message specifications

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0 1 Using This Manual 1.3 Related Information Reference [ISO/IEC 8825-1] Document Title Specification of Basic Encoding Rules (BER), Canonical Encoding Rules (CER) and Distinguished Encoding Rules (DER) [ISO/IEC 8859] Information technology – 8-bit single-byte coded graphic character sets [ISO/IEC 9797-1] Information technology – Security techniques – Message Authentication Codes (MACs) — Part 1: Mechanisms using a block cipher [ISO/IEC 10116] Information technology — Security techniques — Modes of operation for an n-bit block cipher [ISO/IEC 14888-3] Information technology — Security techniques — Digital signatures with appendix — Part 3: Discrete logarithm based mechanisms [ISO/IEC 18031:2005] Information technology – Security techniques – Random bit generation [NIST SP800-22A] A statistical test suite for random and pseudorandom number generators for cryptographic algorithms October 2022

countries.

1 Using This Manual 1.4 Terminology EMV Contactless Book C-8 Kernel 8 Spec 1.0 1.4 Terminology The following terms are used in this document, carrying specialised meanings as indicated. Card Term Table 1.1—Terminology

Description

Card, as used in these specifications, is a consumer device supporting contactless transactions. Combination Combination is the combination of an AID and a Kernel ID. Configuration Option A Configuration Option allows activation or deactivation of the Kernel software behind this option. The Configuration Option may change the execution path of the software but it does not change the software itself. A Configuration Option is set in the Kernel database per AID and Transaction Type. Implementation Option An Implementation Option allows the vendor to select whether the functionality behind the option will be implemented in a particular installation. Kernel The Kernel contains the interface routines, security and control functions, and logic to manage a set of commands and responses to retrieve all the necessary data from the Card to complete a transaction. The Kernel processing covers the interaction with the Card between the selection of the card application (excluded) and the processing of the transaction's outcome (excluded). POS System The POS System is the collective term given to the payment infrastructure present at the merchant. It is made up of the Terminal and Reader. Process A Process is a logical component within a Reader that has one or more Queues to receive Signals. The processing of Signals, in combination with the carried data, may then generate other Signals to be sent. Processing can continue until all the Queues of a Process are empty, or until the Process terminates.

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0 1 Using This Manual 1.5 Notations Term Queue Reader Signal Terminal Description A Queue is a buffer that stores events to be processed. The events are stored in the order received. The Reader is the device that supports the Kernel(s) and provides the contactless interface used by the Card. In this specification, the Reader is considered as a separate logical entity, although it can be an integral part of the POS System. A Signal is an asynchronous event that is placed in a Queue. A Signal can convey data as parameters, and the data provided in this way is used in the processing of the Signal. The Terminal is the device that connects to the authorisation and/or clearing network and that together with the Reader makes up the POS System. The Terminal and the Reader may exist in a single integrated device. However, in this specification, they are considered separate logical entities.

1.5 Notations 1.5.1 State Machine This document specifies the Kernel processing as a state machine that is triggered by Signals that cause state transitions. The application states of the Kernel are written in a specific format to distinguish them from the rest of the text: State Example: S22 – Waiting for Read Record Response The state machine of the Kernel is represented using a state diagram. Example: October 2022

countries.

1 Using This Manual 1.5 Notations EMV Contactless Book C-8 Kernel 8 Spec 1.0 Figure 1.1 depicts the transitions for state S26 – Waiting for Generate AC Response. Upon receiving the Signal RECORD DECRYPTED, the state machine remains in state S26 – Waiting for Generate AC Response. The state machine leaves state S26 – Waiting for Generate AC Response upon receiving an RA Signal. In this case, the state machine goes to S28 – Waiting for IAD MAC Results if Crypto Read Record Counter = 0 and to S27 – Waiting for Decrypted Records if Crypto Read Record Counter ≠ 0. Figure 1.1—Example of State Diagram Notation RECORD DECRYPTED S26 - Waiting for Generate AC Response RA/CRYPTO READ RECORD COUNTER != 0 RA/CRYPTO READ RECORD COUNTER = 0 S27 - Waiting for Decrypted Records S28 - Waiting for IAD MAC Results This document uses a combination of flow diagrams and textual description to describe the state transitions in the state machine of the Kernel. Figure 1.2 depicts the symbols used in the flow diagrams.

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0 1 Using This Manual 1.5 Notations Figure 1.2—Symbols Used in Flow Diagrams X - State State Procedure Procedure Start CALL Call Procedure () Label High-Level Action Description Label Detailed Action Description Action With Detailed Description as Described in Text Action With Detailed Description Included in the Flow Diagram Test ? Label TRUE FALSE Decision SIGNAL Signal Received Action Connectors SIGNAL Signal Sent Action NO YES Implementation Option Test October 2022

countries.

1 Using This Manual 1.5 Notations EMV Contactless Book C-8 Kernel 8 Spec 1.0 On the Kernel behaviour, the combination of the flow diagrams and the corresponding textual descriptions constitutes the requirements:

  • Each diagram in this specification has a unique label.
  • Each symbol in a diagram has a unique identifier that is the concatenation of the diagram label with the symbol number.
  • The textual description corresponding to a symbol may be included in the diagram or it may be a detailed textual description included in the text below the diagram. The flow diagrams are read from top to bottom and define the order of execution of the processing steps. The textual description specifies the behaviour of the individual steps but bears no information on the order of execution. An example of a flow diagram is given in Figure 1.3 in combination with the detailed textual description below. Figure 1.3—Example of Flow Diagram IsNotEmpty(TagOf(DF Name)) AND IsNotEmpty(TagOf(Card Qualifier)) AND 'Version' in Card Qualifier ≠ '00' ? 1.8 FALSE TRUE 1.10 Set Language Preference 1.9 'L2' in Error Indication:= CARD DATA MISSING 'Msg On Error' in Error Indication:= N/A October 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec 1.0 1 Using This Manual 1.5 Notations 1.10 If the Language Preference is returned from the Card, then copy it to 'Language Preference' in User Interface Request Data 1 and User Interface Request Data 2: IF [IsNotEmpty(TagOf(Language Preference))] THEN 'Language Preference' in User Interface Request Data 1:= Language Preference 'Language Preference' in User Interface Request Data 2:= Language Preference If the length of Language Preference is less than 8 bytes, then pad 'Language Preference' in User Interface Request Data 1 and User Interface Request Data 2 with trailing hexadecimal zeroes to 8 bytes. ENDIF Only symbol 1.10 has a detailed textual description. The textual descriptions of symbols 1.9 and 1.8 are included in the flow diagram. The requirements are related to the behaviour of the Kernel, while leaving flexibility in the actual implementation. The implementation must behave in a way that is indistinguishable from the behaviour specified in this document, in terms of that it creates the output as predicted by this specification for a given input. There is no requirement that the implementation realises the behaviour through a state machine as described in this document.

1.5.2 Data Object Notation Data objects used for this specification are capitalised: Data Object Name Example: Application File Locator To refer to a sub-element of a data object (i.e. a specific bit, set of bits, or byte of a multi-byte data object), the following notational convention is used:

  • If the sub-element is defined in the data dictionary (Annex A), with each possible value of the sub-element having a name, then the following conventions apply:
  • The reference to the sub-element is 'Name of Sub-element' in Data Object Name.
  • The reference to the value is VALUE OF SUB-ELEMENT. Examples:
  • 'CVM Limit exceeded' in Terminal Risk Management Data refers to bit 8 of byte 2 in Terminal Risk Management Data. October 2022 countries. 1 Using This Manual 1.5 Notations EMV Contactless Book C-8 Kernel 8 Spec 1.0
  • 'CVM' in Outcome Parameter Set:= ONLINE PIN means the same as bits 8 to 5 of byte 4 of Outcome Parameter Set are set to 0010b.
  • Alternatively, an index may be used to identify a sub-element of a data object. In this case the following notational conventions apply:
  • To refer to a specific byte of a multi-byte data object, a byte index is used within brackets (i.e. [ ]). The first byte (leftmost or most significant) of a data object has index 1. For example, Terminal Verification Results[2] represents byte 2 of Terminal Verification Results.
  • To refer to a specific bit of a single byte multi-bit data object, a bit index is used within brackets [ ]. The first bit (rightmost or least significant) of a data object has index 1. For example, Cryptogram Information Data[7] represents bit 7 of the Cryptogram Information Data.
  • To refer to a specific bit of a multi-byte data object, a byte index and a bit index are used within brackets (i.e. [ ][ ]). For example, Terminal Verification Results[2][4] represents bit 4 of byte 2 of the Terminal Verification Results.
  • Ranges of bytes are expressed using the x:y notational convention: For example, Terminal Verification Results[1:4] represents bytes 1, 2, 3, and 4 of the Terminal Verification Results.
  • Ranges of bits are expressed using the y:x notational convention: For example, Cryptogram Information Data[5:1] represents bits 5, 4, 3, 2, and 1 of the Cryptogram Information Data. October 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec 1.0 1 Using This Manual 1.5 Notations 1.5.3 Other Notational Conventions Notations for processing data and managing memory are described in Table 1.2. Table 1.2—Other Notational Conventions Notation '0' to '9' and 'A' to 'F' Meaning Hexadecimal notation. Values expressed in hexadecimal form are enclosed in straight single quotes. Example 27509 decimal is expressed in hexadecimal as '6B75'. 1001b Binary notation. Values expressed in binary form are followed by the letter b. '08' hexadecimal is expressed in binary as 00001000b. 340 Decimal notation. Values '0C' hexadecimal is expressed in expressed in decimal form decimal as 12. are not enclosed in single quotes. C-APDU C-APDUs are written in all caps to distinguish them from the text GET PROCESSING OPTIONS SET A specific bit in a data object SET 'Kernel 8 processing and TVR is set to the value 1b format' in Terminal Verification Results CLEAR A specific bit in a data object is set to the value 0b CLEAR 'Cardholder verification was not successful' in Terminal Verification Results:= A specific value is assigned 'Status' in Outcome Parameter Set to a data object or to a:= END APPLICATION sub-element of a data object OR This notation is used for both Bitwise AND and OR: the logical and bitwise OR operation. Its meaning is therefore context-specific. TVR:= (TVR AND Kernel Reserved TVR Mask) OR (Card TVR AND NOT(Kernel Reserved TVR Mask)) October 2022 countries. 1 Using This Manual 1.5 Notations EMV Contactless Book C-8 Kernel 8 Spec 1.0 Notation AND NOT || IF THEN ELSE ENDIF FOR EXIT loop Meaning This notation is used for both the logical and bitwise AND operation. Its meaning is therefore context-specific. Example Logical AND: IF [IsNotEmptyList(Data To Send) AND IsEmptyList(Tags To Read Yet)] This notation is used for both the logical and bitwise negation operation. Therefore, its meaning is context-specific. Logical NOT: IF [NOT ParseAndStoreCardResponse(TLV)] Two values are concatenated. A:= 'AB34' B:= A || 'FFFF' means that B is assigned the value 'AB34FFFF' This textual description is used to specify decision logic, using the following syntax: IF T THEN Logic 1 ELSE Logic 2 ENDIF where T is a statement resulting in true or false. IF [IsNotEmptyList(Data Envelopes To Write Yet)] THEN P2:= '80' ELSE P2:= '00' ENDIF This textual description is used to specify repetition control logic, using the following syntax: FOR every x in list { IF T THEN Action EXIT loop ENDIF } FOR every T in Extended SDA Tag List { IF [IsNotPresent(T) OR IsEmpty(T)] THEN Data objects referenced in Extended SDA Tag List present:= FALSE EXIT loop ENDIF } October 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec 1.0 1 Using This Manual 1.5 Notations Notation CALL A mod n A div n X ⊕ Y A:= ALG(K)[X] x
  • Y Meaning Functionality of a certain complexity and appearing more than once is implemented by means of a procedure. In the textual description, a procedure is referenced by means of the key word CALL. Example CALL Process Restrictions () The reduction of the integer A modulo the integer n, that is, the unique integer r, 0 ≤ r &lt; n, for which there exists an integer d such that A = dn + r 54 mod 16 = 6 The integer division of A by n, that is, the unique integer d for which there exists an integer r, 0 ≤ r < n, such that A = dn + r 54 div 16 = 3 The bit-wise exclusive-OR of the data blocks X and Y. 11001100b ⊕ 10101010b = 01100110b Encryption of a data block X with a block cipher (ALG) using a secret key K. Typical values for ALG are AES, DES, TDES, AES-1, DES-1, and TDES-1. T:= AES(K)[M] Scalar multiplication by x of the point of the elliptic curve Y Q:= d
  • G October 2022 countries. 1 Using This Manual 1.6 Version EMV Contactless Book C-8 Kernel 8 Spec 1.0 1.6 Version Kernel and Card both maintain a version number, coded as 'Version' in Kernel Qualifier and in Card Qualifier respectively. The lowest version number of the two determines the functionality that can be used for the transaction. Two versions are defined, VERSION 1 and VERSION 2, with details on the corresponding functionality provided in Table 1.3. A Kernel implementing this version of the specification must set ‘Version’ to VERSION 2 in the Kernel Qualifier and must support Cards that provide ‘Version’ with value VERSION 1 or VERSION 2 in the Card Qualifier. Table 1.3— Versions and Corresponding Functionality Version VERSION 1 VERSION 2 Functionality The generation of the Issuer Application Data MAC does not use the Issuer Application Data as input. The Issuer Application Data MAC is inserted in the Issuer Application Data before using the Issuer Application Data as input for the generation of the Enhanced Data Authentication MAC. The generation of the Issuer Application Data MAC uses the Issuer Application Data as input. The Issuer Application Data MAC is used as input for the generation of the Enhanced Data Authentication MAC. The Issuer Application Data MAC is (optionally) included in the Issuer Application Data by the Kernel before including the Issuer Application Data in the Data Record. October 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec 1.0 2 General Architecture 2.1

Introduction

As described in [EMV Book A], the general architecture of a POS System consists of a Terminal and a Reader, where the terms Terminal and Reader refer to a separation in responsibility and functionality between two logical entities. Figure 2.1 shows how the Reader functionality is allocated to different processes: Process M(ain), Process D(isplay), Process S(elect), Process P(CD), Process K(ernel) and Process C(rypto). Communication between different processes happens through Signals stored on Queues. A Signal is an asynchronous event that is placed on a Queue waiting to be processed. A Signal can convey data as parameters, and the data provided in this way is used in the processing of the Signal. Zooming in further on Process K, Figure 2.1 illustrates the two components of the Kernel: the Kernel software, modeled as a state machine, and the Kernel database, consisting of a number of separate datasets. Figure 2.1—General Architecture POS System Terminal Reader Process M Reader Management Reader Database Process D Message Display Process S Application and Kernel Selection Process P Card Interaction Process K Kernel Process C Crypto State 1 Kernel database State 2 State 3 State 4

October 2022

countries.

2 General Architecture 2.1 Introduction EMV Contactless Book C-8 Kernel 8 Spec 1.0 There is no requirement to create devices that use the architecture and the partitioning as laid out in this document, as equally there is no requirement in [EMV Book A] on the partitioning. The only requirements in this document apply to Process K and Process C, and these requirements define the externally-observable behaviour, independent of the internal organisation of the Reader.

October 2022

countries.

EMV Contactless Book C-8 Kernel 8 Spec 1.0 2 General Architecture 2.2 Reader Processes 2.2 Reader Processes In Figure 2.2, the Reader is modeled as a set of Processes and each Process runs independently of the other Processes. The role of the Reader database is explained in section 2.3. Figure 2.2—Reader Logical Architecture Reader Process D Message Display Process M Reader Management Process S Application and Kernel Selection Process P Card Card Interaction Reader database Process K Kernel Process C Crypto The different processes are listed in Table 2.1. Table 2.1—Reader Processes Process Process P(CD) Process D(isplay) Process S(election) Process K(ernel) Process M(ain) Process C(rypto) Responsibility Management of the contactless interface Management of the user interface Selection of the Card application and Kernel Interaction with the Card once the application has been selected, covering the transaction flow specific to Kernel 8 Overall control and sequencing of the different processes. The configuration and activation of the Kernel and the processing of its outcome are also part of this role. Processing of cryptographic material October 2022

countries.

2 General Architecture 2.2 Reader Processes EMV Contactless Book C-8 Kernel 8 Spec 1.0 2.2.1 Process P Process P implements the functionality described in [EMV CL L1] and [ISO/IEC 7816-4] and manages the access to the Card. Process K communicates with Process P through the CMD, RA and L1RSP Signals as shown in Table 2.2. Signal In CMD Table 2.2—Process P Signals Signal Out RA(R-APDU) Comment If there is no L1 error, the RA Signal contains the R-APDU sent back in response to a C-APDU. L1RSP(code) If there is an L1 error, L1RSP is returned with code as one of the following:

  • Error – Timeout: An L1 timeout has occurred
  • Error – Protocol: An L1 protocol error has occurred
  • Error – Transmission: Any other error Process P sends the C-APDU included in the CMD Signal to the Card and responds with either:
  • An RA Signal containing the R-APDU and status bytes returned by the Card, or
  • An L1RSP Signal including an L1 event such as a timeout, transmission error, or protocol error.

2.2.2 Process D Process D manages the User Interface Requests as defined in [EMV Book A] and displays a message and/or a status. A MSG Signal is used as a carrier of User Interface Request Data (UIRD). Process D may receive MSG Signals from any other Process. The MSG Signal is not acknowledged. For more information on UIRD, refer to section 7.1 of [EMV Book A] and to A.1.139 and A.1.140 for the definition of the UIRDs used in this specification. For displaying messages and/or indicating status, Process D needs the following configuration data:

  • Default language
  • The currency symbol to display for each currency code and the number of minor units for that currency code October 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec 1.0 2 General Architecture 2.2 Reader Processes
  • A number of message strings in the default language and potentially other languages The status identifiers and message identifiers are defined in section 9.2 and section 9.4 respectively of [EMV Book A].

2.2.3 Process S Process S manages the application and Kernel selection

It runs constantly, and it is waiting for an ACT Signal from Process M. After processing the ACT Signal, it returns the selected Combination of application and Kernel (AID and Kernel ID) and the File Control Information Template and status bytes returned by the Card in response to the final SELECT command in an OUT Signal. Refer to [EMV Book B] for the specification of an implementation of Process S that supports a multi-kernel architecture.

2.2.4 Process K The Reader may support multiple Kernels but only one Kernel will execute at a time. The Kernel that is activated depends on the information returned by Process S, which may in turn depend on data retrieved from the Card. For each transaction, Process K is configured with a Kernel-specific dataset. The values in the dataset depend on the AID and the Transaction Type. More information on the initialisation of the Kernel-specific dataset is provided in section 2.3. Once the Kernel is selected and configured, it executes as Process K. Process K manages the interaction with the Card application beyond application selection, using the services of Process P as an intermediary. Upon completion, Process K sends its results to Process M in an OUT Signal and then terminates. For the remainder of the document, it is assumed that Kernel 8 is selected. From the viewpoint of the Reader and depending on the Configuration Options, Kernel 8 can provide two services:

  • Through its interaction with the Card, it creates a transaction record for authorisation and/or clearing.
  • It can interact with the Terminal directly through the Data Exchange mechanism. Seen from the Terminal and depending on the Configuration Options, Kernel 8 allows reading and writing data from and to the Card. The different services are listed in Table 2.3, with the corresponding Signal to call the service indicated in the right column. Only Process M and the Terminal request these services from Process K. October 2022 countries. 2 General Architecture 2.2 Reader Processes EMV Contactless Book C-8 Kernel 8 Spec 1.0 Table 2.3—Services from Process K Service Return an authorisation or clearing record. Corresponding Signal ACT(Data) As a minimum, “Data” includes the File Control Information Template received from the Card in the response to the SELECT command. Request data from the Kernel database or from the Card. Write data to the Kernel database or to the Card. DET(Data) Process K responds to the incoming service request with an outgoing Signal as described in Table 2.4. Signal In ACT Table 2.4—Responses from Process K Signal Out OUT Comment The OUT Signal includes:
  • Outcome Parameter Set
  • Data Record – if any
  • Discretionary Data
  • User Interface Request Data 1 – if any
  • User Interface Request Data 2 – if any DET DEK or n/a The DEK Signal can be used to request additional data to be provided in a subsequent DET Signal, as well as n/a DEK to provide data that was requested via a configuration setting or a previous DET Signal. The DEK Signal contains:
  • The Data Needed data object, which is the list of tags of data items that the Kernel needs from the Terminal
  • The Data To Send data object, which is the list of data values that the Terminal has requested October 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec 1.0 2 General Architecture 2.2 Reader Processes Within a transaction, the Terminal can only send one or more DET Signals after it received a DEK Signal indicating that Process K is active. The DEK Signal is sent only if the Kernel has data for the Terminal or needs data from the Terminal. The DEK and DET Signals are exchanged as part of the Data Exchange mechanism and are only used if DE/DS implementation option is implemented. Process K implements a Timer that runs as a daemon parallel to Process K. If not stopped, the Timer places a TIMEOUT Signal on the queue of Process K at a pre-set time interval after the Timer is started.

2.2.5 Process M Process M is responsible for coordinating the other processes to perform a transaction. The overall process is illustrated as follows:

  • Process M receives the ACT Signal from the Terminal.
  • Process M starts Process P to start polling for Cards as described in [EMV CL L1].
  • Process M requests Process D to display the READY message.
  • When Process P indicates to Process M that a Card is detected, Process M activates Process S. When Process S completes successfully, it responds with an OUT Signal with the selected Combination {AID – Kernel ID}, the File Control Information Template of the selected Card application, and the status bytes returned by the Card.
  • Based on this information, Process M then configures Process K for the specific Transaction Type and AID, using a Kernel-specific dataset, and sends it an ACT Signal containing transactional data such as the Amount, Authorised (Numeric) and the File Control Information Template. When Process K has completed the transaction, it returns an OUT Signal to Process M, including the Outcome Parameter Set, Discretionary Data, Data Record (if any) and optionally one or two UIRDs.
  • Process M analyzes the 'Status' in Outcome Parameter Set and executes the instructions encoded in the other fields of the Outcome Parameter Set. As required, Process M instructs Process P to perform the removal sequence. Alternatively, it may instruct Process S to select the next application on the Card.
  • Process M passes a subset of the Outcome Parameter Set, the Data Record and the Discretionary Data to the Terminal.
  • If the transaction is processed online, the Reader receives a MSG Signal from the Terminal to indicate whether the transaction was approved or declined. October 2022 countries. 2 General Architecture 2.2 Reader Processes EMV Contactless Book C-8 Kernel 8 Spec 1.0 2.2.6 Process C Process C is the cryptographic process and only Process K communicates with Process C. Communication between Process K and Process C is described in terms of Signals. The specification presumes that Signals between Process C and Process K are managed on a dedicated Queue that is exclusively reserved for their interactions. Process C is designed to run in parallel with Process K, offloading the processing of cryptographic data to simplify Process K and speed up the processing transaction flow. It is an implementation decision as to how it is implemented; if a reader has very fast cryptographic processing and the implementer prefers not to implement parallel processing, then its functions may be executed sequentially with respect to Process K but it is presented in this specification as a parallel process. Process C handles the following tasks:
  • Secure channel and certificate algorithm suite negotiation.
  • Processing of the key related data in the GET PROCESSING OPTIONS response
  • Decryption of privacy protected (encrypted) record or READ DATA data
  • Local authentication including validation of the Card and issuer certificates and the blinding factor
  • Generation of the Issuer Application Data MAC and validation of the Enhanced Data Authentication MAC
  • Validation of MACs for READ DATA and WRITE DATA
  • Encryption of data for WRITE DATA for transmission to the Card It is invoked by Process K by means of Signals. The Signals that Process K sends to Process C are listed in Table 2.5. Process C will process Signals in the order they are sent to it by Process K. In response to these Signals, Process C will return a message for each message sent, subject to the exceptions shown as described in Table 2.5. October 2022 countries. EMV Contactless Book C-8 Kernel 8 Spec 1.0 2 General Architecture 2.2 Reader Processes Table 2.5—Process C Signals In response to INITIALISE PROCESS C GPO PRIVACY RECORD RECEIVED PROCESS ISSUER CERTIFICATE PROCESS ICC CERTIFICATE PROCESS EDA MAC PROCESS BLINDING FACTOR VALIDATE MESSAGE ENCRYPT MESSAGE PROCESS IAD MAC Process C will send Normal response Exception INIT PROCESS C OK INIT PROCESS C FAIL None DECRYPTION FAILED None(1) or DECRYPTION FAILED RECORD DECRYPTED ISSUER CERTIFICATE OK ISSUER CERTIFICATE FAIL ICC CERTIFICATE OK ICC CERTIFICATE FAIL EDA MAC OK BLINDING FACTOR OK EDA MAC FAIL BLINDING FACTOR FAIL MESSAGE OK ENCRYPTED MESSAGE IAD MAC OK MESSAGE FAIL ENCRYPTION FAILED IAD MAC FAIL (1) If a RECORD RECEIVED Signal contains a plaintext record, Process C will not return a message. Process K sends plaintext records to Process C as it is Process C that builds the Static Data To Be Authenticated. October 2022 countries. 2 General Architecture 2.3 The Reader Database EMV Contactless Book C-8 Kernel 8 Spec 1.0 2.3 The Reader Database The Reader maintains a database that is divided into different datasets held in persistent memory. An overview of the different persistent datasets is given in Figure 2.3, with additional details in Table 2.6. Figure 2.3—Reader Database – Persistent Datasets Process S One data set per supported transaction type Refund AID1 PurcAhIDa2se wit…h cas-hbaAcIkDn-1 Kernel 1 AID1√ AID2Purch…ase AIDn-1 KernKele1rnAeIlD21√

Shown in part. Read the original for the full text.