SB n° 292: Update to C-5 (Torn Transaction Recovery)

v1.0 Specification Bulletins
Contactless Acceptance Device

EMV® Specification Bulletin No.292 First Edition April 2023 Update for EMV Book C-5 Remove the feature of Torn Transaction Recovery

Applicability

This Specification Bulletin applies to:

  • EMV® Contactless Specifications for Payment Systems, Book C-5 – Kernel 5 Specification, Version 2.10, March 2021

Related Documents

  • None

Effective Date

  • 1 January 2024

Description

This bulletin is to remove the feature of Torn Transaction Recovery. Details of Changes (1) Remove the description of “Transaction Recovery” under the section 2.3 as follows. The purpose is to provide a summarised overview of the normal Reader processing and is not prescriptive. Note that specific processes like Transaction Recovery or Issuer Update are not represented in this figure which features only a nominal transaction flow. (2) Under the section 3.2, remove the section 3.2.1.1 and move forward the following section numbers accordingly. Requirement – Recovering from Torn EMV Transaction 3.2.1.1 If the Kernel internal variable ‘Recovering from Torn EMV Transaction’ has value TRUE, Then the Kernel shall proceed with Torn Transaction Recovery as described in section 3.13. Otherwise the Kernel shall proceed with Requirement 3.2.1.2. (3) Under the section 3.11.2, remove the section 3.11.2.1 and 3.11.2.2, and move forward the following section numbers accordingly.

countries.

Requirement – Communication Errors – First GENERATE AC 3.11.2.1 If a Transmission, Protocol, or Timeout error as defined in [EMV L1 Contactless] is reported to the Kernel during the first GENERATE APPLICATION CRYPTOGRAM command of a transaction in EMV Mode, Then the Kernel shall prepare the Recovery Context as follows:

  • Set indicator ‘Recovering from Torn EMV Transaction’ to value TRUE;
  • Store the card Track 2 Equivalent Data value (Tag ‘57’) into variable ‘Torn Track 2 Data’;
  • If CDA has been requested by the Kernel, concatenate in this order and store in variable ‘Torn CDA Hash Data Buffer’
  • The values of the data elements specified by, and in the order they appear in the PDOL, and sent by the Kernel in the GET PROCESSING OPTIONS command
  • The values of the data elements specified by, and in the order they appear in the CDOL1, and sent by the Kernel in the GENERATE AC command 3.11.2.2 The Reader shall retain the Recovery Context and make it available to the Kernel for the next Kernel Activation. The Kernel shall terminate the transaction and provide an End Application (with restart – Communication errors) Outcome as described in section 3.12.8. (4) Remove the whole of the section 3.13. (5) Remove “ECHO” APDU command from the Table 4-1. CLA INS Meaning Requirement ‘80’ ‘DF’ ECHO Mandatory ‘80’ ‘AE’ GENERATE APPLICATION CRYPTOGRAM Mandatory ‘80’ ‘A8’ GET PROCESSING OPTIONS Mandatory countries. CLA ‘00’ ‘00’ INS ‘B2’ ‘A4’ Meaning READ RECORD SELECT

Requirement

Mandatory Mandatory (6) Remove the whole of the section 4.1 and move forward the following sections. (7) Remove the description of the SW ‘6200’ under the “Processing State Returned in the Response Message” of the section “4.4 GET PROCESSING OPTIONS”.

  • ‘6200’ (warning) indicates a successful execution of the command during a torn transaction recovery. (8) Remove the following data elements from the Table B-1 as follows. - ‘Recovering from Torn EMV Transaction’ Flag - Recovery Context - Torn CDA Hash Data Buffer - Torn Track 2 Data countries. Name Description Source Presence Format Specified Tag Length READ RECORD Contains the contents of the record read. Response Message (Mandatory for SFIs 1-10. Response messages for ICC M Template SFIs 11-30 are outside the scope of EMV, but may use template ‘70’) ‘Recovering from Torn Internal Kernel variable (Boolean) set to TRUE EMV Transaction’ Flag when the Kernel attempts to recover from a torn Kernel 5 C transaction (EMV Mode only) A set of persistent Kernel parameters involved in the management of torn EMV transactions. It consists of: Recovery Context - ‘Recovering from Torn EMV Transaction’ Kernel 5 C Flag - ‘Torn Track 2 Data’ - ‘Torn CDA Hash Data Buffer’ Present if the Combination supports Issuer Update as Acquirer Option (EMV Mode only). Removal Timeout In case of Online Request with “Present and Hold” Configuration C outcome, this parameter corresponds to the time (AID) after which cardholder is asked to remove the card. Value is given in units of 100ms. Response Message Contains the data objects (without tags and lengths) ICC C Template Format 1 returned by the ICC in response to a command Response Message Contains the data objects (with tags and lengths) ICC M Template Format 2 returned by the ICC in response to a command var. EMV ‘70’ var. Up to 252 - Kernel 5 - - - Kernel 5 - - n 4 Kernel - 2 var. EMV ‘80’ var. var. EMV ‘77’ var. countries. Name Terminal Interchange Profile (static) Terminal Type Terminal Verification Results (TVR) Threshold Value for Biased Random Selection Token Requestor ID Torn CDA Hash Data Buffer Torn Track 2 Data Description Defines the Cardholder Verification Methods and other reader capabilities (online capability, contact EMV capability) for the Combination Indicates the environment of the terminal, its communications capability, and its operational control Status of the different functions as seen from the terminal Value used in terminal risk management for random transaction selection. Present if the Combination supports Random Transaction Selection (EMV Mode only) An 11-digit numeric value that identifies each unique combination of token requestor and token domain(s) for a given token service provider. A copy of the PDOL related data and CDOL1 related data sent to the card during a torn transaction in EMV Mode. This copy is used to verify the CDA signature during the subsequent transaction recovery process. A copy of the card Track 2 Equivalent Data, kept by the Kernel after a torn transaction in EMV Mode to ensure that the card presented for recovery is the same as for the torn transaction Source Configuration (AID) Configuration (POS) Kernel 5 Configuration (AID) ICC / Issuer Kernel 5 Kernel 5 Presence M M M C O C C Format b n 2 b n 12 n 11 b b Specified Tag Length Kernel 5 - 3 See A.5 EMV ‘9F35’ 1 EMV / ‘95’ 5 Kernel 5 EMV - 6 EMV ‘9F19’ 6 Kernel 5 - Var. up to 507 Kernel 5 - Var. up to 19 countries.

Legal Notice

The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications

countries.