Book C-2 Kernel Specification

v2.11 Specifications
Contactless Acceptance Device

EMV® Contactless Specifications for Payment Systems Book C-2 Kernel 2 Specification Version 2.11 June 2023

Legal Notice

Unless the user has an applicable separate agreement with EMVCo or with the applicable payment system, any and all uses of these Specifications is subject to the terms and conditions of the EMVCo Terms of Use agreement available at www.emvco.com and the following supplemental terms and conditions. Except as otherwise may be expressly provided in a separate agreement with EMVCo, the license granted in the EMVCo Terms of Use specifically excludes (a) the right to disclose, distribute or publicly display these Specifications or otherwise make these Specifications available to any third party, and (b) the right to make, use, sell, offer for sale, or import any software or hardware that practices, in whole or in part, these Specifications. Further, EMVCo does not grant any right to use the Kernel Specifications to develop contactless payment applications designed for use on a Card (or components of such applications). As used in these supplemental terms and conditions, the term “Card” means a proximity integrated circuit card or other device containing an integrated circuit chip designed to facilitate contactless payment transactions. Additionally, a Card may include a contact interface and/or magnetic stripe used to facilitate payment transactions. To use the Specifications to develop contactless payment applications designed for use on a Card (or components of such applications), please contact the applicable payment system. To use the Specifications to develop or manufacture products, or in any other manner not provided in the EMVCo Terms of Use, please contact EMVCo. These Specifications are provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of these Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of these Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with these Specifications.

June 2023

EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Revision Log – Version 2.11 The following changes have been made to Book C-2 since the publication of Version 2.10. Incorporated changes described in the following Specification Bulletin:

  • Specification Bulletin No. 261 October 2021: Implementation Options for EMV Book C-2 V2.10 Other changes:
  • Simplified informative information in chapters 2 and 3 to reflect functional changes of SB261.
  • Removed the 'Value Qualifier', 'Value' and 'Currency Code' fields from User Interface Request Data and changed the length to 13 bytes.
  • Removed Offline Accumulator Balance from data retrievable with GET DATA command and from Data Dictionary
  • Added Token Requestor ID to Data Dictionary and Data Record June 2023 Contents EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Contents Revision Log – Version 2. 1 1. 1. 1. 1. 1. 1.5. 1.5. 1.5. 2 2. 2. 2.2. 2.2. 2.2. 2.2. 2.2. 2. 3 3. 3. 3. 3.3. 3.3. 3.3. 3. 3.4. 3.4. 3.4. 3.4. 3. 3.5. 3.5. 3.5. 3. June 2023 EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Contents 3.6. 3.6. 3.6. 3. 3.7. 3.7. 3. 3.8. 3.8. 3. 4 4. 4.1. 4.1. 4.1. 4.1. 4. 4. 4. 4.4. 4.4. 4.4. 4. 4.5. 4.5. 4.5. 4.5. 4. 4.6. 4.6. 4. 4. 5 5. 5. 5.2. 5.2. 5.2. June 2023 Contents EMV® Contactless Book C-2 Kernel 2 Spec v2.11 5.2. 5. 5.3. 5.3. 5.3. 5.3. 5. 5.4. 5.4. 5.4. 5.4. 5. 5.5. 5.5. 5.5. 5.5. 5. 5.6. 5.6. 5.6. 5.6. 5. 5.7. 5.7. 5.7. 5.7. 5. 5.8. 5.8. 5.8. 5.8. 6 6. 6. 6.2. 6.2. 6.2. 6. June 2023 EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Contents 6.3. 6.3. 6.3. 6. 6.4. 6.4. 6.4. 6. 6.5. 6.5. 6.5. 6. 6.6. 6.6. 6.6. 6. 6.7. 6.7. 6.7. 6. 6.8. 6.8. 6.8. 6. 6.9. 6.9. 6.9. 6. 6.10. 6.10. 6.10. 6. 6.11. 6.11. 6.11. 6. 6.12. 6.12. June 2023 Contents EMV® Contactless Book C-2 Kernel 2 Spec v2.11 6.12. 6. 6.13. 6.13. 6.13. 6. 6.14. 6.14. 6.14. 6. 6.15. 6.15. 6.15. 6. 6.16. 6.16. 6.16. 6. 6.17. 6.17. 6.17. 6. 6.18. 6.18. 6.18. 6. 6.19. 6.19. 6.19. 7 7. 7.1. 7.1. 7.1. 7. 7.2. 7.2. 7.2. June 2023 EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Contents 7. 7.3. 7.3. 7.3. 7. 7.4. 7.4. 7.4. 8 8. 8. 8. A. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. June 2023 Contents EMV® Contactless Book C-2 Kernel 2 Spec v2.11 A.1.25 A.1.26 A.1.27 A.1.28 A.1.29 A.1.30 A.1.31 A.1.32 A.1.33 A.1.34 A.1.35 A.1.36 A.1.37 A.1.38 A.1.39 A.1.40 A.1.41 A.1.42 A.1.43 A.1.44 A.1.45 A.1.46 A.1.47 A.1.48 A.1.49 A.1.50 A.1.51 A.1.52 A.1.53 A.1.54 A.1.55 A.1.56 A.1.57 A.1.58 A.1.59 A.1.60 A.1. June 2023 EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Contents A.1.62 A.1.63 A.1.64 A.1.65 A.1.66 A.1.67 A.1.68 A.1.69 A.1.70 A.1.71 A.1.72 A.1.73 A.1.74 A.1.75 A.1.76 A.1.77 A.1.78 A.1.79 A.1.80 A.1.81 A.1.82 A.1.83 A.1.84 A.1.85 A.1.86 A.1.87 A.1.88 A.1.89 A.1.90 A.1.91 A.1.92 A.1.93 A.1.94 A.1.95 A.1.96 A.1.97 A.1.98 A.1. June 2023 Contents EMV® Contactless Book C-2 Kernel 2 Spec v2.11 A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. June 2023 EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Contents A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1.157 Terminal Expected Transmission Time For Relay Resistance C-APDU 420 A.1.158 Terminal Expected Transmission Time For Relay Resistance R-APDU 420 A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. June 2023 Contents EMV® Contactless Book C-2 Kernel 2 Spec v2.11 A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A.1. A. B. B. June 2023 EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Figures Figures Figure 1. Figure 2. Figure 2. Figure 2. Figure 3. Figure 4. Figure 4. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 6. Figure 7. Figure 7. Figure 7. Figure 7. June 2023 Tables EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Tables Table 1. Table 1. Table 2. Table 2. Table 2. Table 2. Table 2. Table 2. Table 3. Table 3. Table 3. Table 4. Table 4. Table 4. Table 4. Table 4. Table 4. Table 4. Table 4. Table 4. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. June 2023 EMV® Contactless Book C-2 Kernel 2 Spec v2.11 Tables Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 5. Table 6. Table 6. Table 6. Table 6. Table 6. Table 6. Table 6. Table 6. June 2023 Tables EMV® Contactless Book C-2 Kernel 2 Spec v2.11 June 2023 EMV® Contactless Book C-2 Kernel 2 Spec v2.11 1 Using This Manual 1.1

Purpose

This document, EMV Contactless Specifications for Payment Systems, Book C-2 – Kernel 2 Specification, should be read in conjunction with:

  • EMV Contactless Specifications for Payment Systems, Book A – Architecture and General Requirements, hereafter referred to as [EMV Book A], and
  • EMV Contactless Specifications for Payment Systems, Book B – Entry Point Specification, hereafter referred to as [EMV Book B]. This document defines the behaviour of the Kernel used in combination with cards supporting a Mastercard brand or cards having a Kernel Identifier indicating Kernel 2, as defined in [EMV Book B]. The Kernel requirements cover both EMV mode and mag-stripe mode contactless transactions.

1.2 Audience This specification is intended for use by manufacturers of contactless readers and terminals. It may also be of interest to manufacturers of contactless cards and to financial institution staff responsible for implementing financial applications in contactless cards.

June 2023

1 Using This Manual 1.3 Related Information EMV® Contactless Book C-2 Kernel 2 Spec v2.11 1.3 Related Information The following references are used in this document. The latest version applies unless a publication date is explicitly stated. Reference [EMV Book 1] Document Title Integrated Circuit Card Specifications for Payment Systems – Book 1, Application Independent ICC to Terminal Interface Requirements, Version 4.4, October 2022 [EMV Book 2] Integrated Circuit Card Specifications for Payment Systems – Book 2, Security and Key Management, Version 4.4, October 2022 [EMV Book 3] Integrated Circuit Card Specifications for Payment Systems – Book 3, Application Specification, Version 4.4, October 2022 [EMV Book 4] Integrated Circuit Card Specifications for Payment Systems – Book 4, Cardholder, Attendant, and Acquirer Interface Requirements, Version 4.4, October 2022 [EMV Book A] EMV Contactless Specifications for Payment Systems, Book A – Architecture and General Requirements, Version 2.11 [EMV Book B] EMV Contactless Specifications for Payment Systems, Book B – Entry Point Specification, Version 2.11 [EMV CL L1] EMV Level 1 Specifications for Payment Systems, EMV Contactless Interface Specification, Version 3.2 [EMV Token] EMV Payment Tokenisation Specification, Technical Framework, Version 2.3, October 2021 [ISO 639-1] Codes for the representation of names of languages – Part 1: Alpha-2 Code [ISO 3166-1] Codes for the representation of names of countries and their subdivisions – Part 1: Country codes [ISO 4217] Codes for the representation of currencies and funds [ISO/IEC 7813] Information technology — Identification cards — Financial transaction cards

June 2023

EMV® Contactless Book C-2 Kernel 2 Spec v2.11 1 Using This Manual 1.3 Related Information Reference [ISO/IEC 7816-4] Document Title Identification cards — Integrated circuit(s) cards with contacts — Part 4: Organization, security and commands for interchange [ISO/IEC 7816-5] Registration of application providers [ISO 8583:1987] Financial transaction card originated messages – Interchange message specifications [ISO 8583:1993] Financial transaction card originated messages – Interchange message specifications [ISO/IEC 8825-1] Specification of Basic Encoding Rules (BER), Canonical Encoding Rules (CER) and Distinguished Encoding Rules (DER) [ISO/IEC 8859] Information technology – 8-bit single-byte coded graphic character sets [ISO 14443-4] Identification cards — Contactless integrated circuit(s) cards — Proximity cards — Part 4: Transmission protocol [ISO 18031:2005] Information technology – Security techniques – Random bit generation [NIST SP800-22A] A statistical test suite for random and pseudorandom number generators for cryptographic algorithms June 2023

1 Using This Manual 1.4 Terminology EMV® Contactless Book C-2 Kernel 2 Spec v2.11 1.4 Terminology The following terms are used in this document, carrying specialized meanings as indicated. Table 1.1—Terminology Card Term

Description

Card, as used in these specifications, is a consumer device supporting contactless transactions. Combination Combination is the combination of an AID and a Kernel ID. Configuration Option A Configuration Option allows activation or deactivation of the Kernel software behind this option. The Configuration Option may change the execution path of the software but it does not change the software itself. A Configuration Option is set in the Kernel database per AID and transaction type. EMV Mode Operating mode that indicates that the contactless payment transaction is validated based on EMV minimum data. Implementation Option An Implementation Option allows the vendor to select whether the functionality behind the option will be implemented in a particular installation. Kernel Mag-stripe Mode The Kernel contains the interface routines, security and control functions, and logic to manage a set of commands and responses to retrieve all the necessary data from the Card to complete a transaction. The Kernel processing covers the interaction with the Card between the selection of the card application (excluded) and the processing of the transaction's outcome (excluded). Mag-stripe Mode describes an operating mode of the POS System that indicates that this particular acceptance environment and acceptance rules support magnetic stripe infrastructure. It is typically used in conjunction with the term “transaction” (i.e. Mag-stripe Mode transaction) to indicate contactless payment based on Track 1 and/or Track 2 Data obtained from the Card.

June 2023

EMV® Contactless Book C-2 Kernel 2 Spec v2.11 1 Using This Manual 1.4 Terminology Term POS System Process Queue Reader Signal Terminal Description The POS System is the collective term given to the payment infrastructure present at the merchant. It is made up of the Terminal and Reader. A Process is a logical component within a Reader that has one or more Queues to receive Signals. The processing of Signals, in combination with the carried data, may then generate other Signals to be sent. Processing can continue until all the Queues of a Process are empty, or until the Process terminates. A Queue is a buffer that stores events to be processed. The events are stored in the order received. The Reader is the device that supports the Kernel(s) and provides the contactless interface used by the Card. In this specification, the Reader is considered as a separate logical entity, although it can be an integral part of the POS System. A Signal is an asynchronous event that is placed in a Queue. A Signal can convey data as parameters, and the data provided in this way is used in the processing of the Signal. The Terminal is the device that connects to the authorization and/or clearing network and that together with the Reader makes up the POS System. The Terminal and the Reader may exist in a single integrated device. However, in this specification, they are considered separate logical entities. June 2023

1 Using This Manual 1.5 Notations EMV® Contactless Book C-2 Kernel 2 Spec v2.11 1.5 Notations This section lists notational conventions used in this specification:

1.5.1 State Machine This document specifies the Kernel processing as a state machine that is triggered by Signals that cause state transitions. The application states of the Kernel are written in a specific format to distinguish them from the text: state Example: GOTO s4 – waiting for EMV read record response The state machine of the Kernel is represented by means of a state diagram (as shown in Figure B.1). This document uses a combination of flow diagrams and textual description in order to describe the state transitions in the state machine of the Kernel. Figure 1.1 shows the symbols used in the flow diagrams.

June 2023

EMV® Contactless Book C-2 Kernel 2 Spec v2.11 1 Using This Manual 1.5 Notations Figure 1.1—Symbols Used in Transaction Flow Diagrams Procedure Procedure start Procedure return Yes No decision task X X connectors complex task Yes No complex decision ACT signal received CA(GPO) signal sent procedure X – state state XYZ No Yes Implementation option test June 2023

1 Using This Manual 1.5 Notations EMV® Contactless Book C-2 Kernel 2 Spec v2.11 The combination of the flow diagrams and the corresponding textual descriptions constitute the requirements on the Kernel behaviour:

  • Each diagram in this specification has a unique label.
  • Each symbol in a diagram has a unique identifier that is the concatenation of the diagram label with the symbol number.
  • The textual description corresponding to the symbol in a diagram starts with the identifier of the symbol. The flow diagrams are read from top to bottom and define the order of execution of the processing steps. The textual description specifies the behaviour of the individual steps but bears no information on the order of execution. The requirements relate to the behaviour of the Kernel but leave flexibility in the actual implementation. The implementation must behave in a way that is indistinguishable from the behaviour specified in this document. Indistinguishable means that it creates the output as predicted by this specification for a given input. There is no requirement that the implementation realize the behaviour through a state machine as described in this document.

1.5.2 Data Object Notation Data objects used for this specification are written in a specific font to distinguish them from the text: Data Object Name Example: Application File Locator Pre-Gen AC Put Data Status To refer to a sub-element of a data object (i.e. a specific bit, set of bits, or byte of a multi-byte data object), the following notational convention is used:

  • If the sub-element is defined in the data dictionary (Annex A), with each possible value of the sub-element having a name, then the following conventions apply:
  • The reference to the sub-element is 'Name of Sub-element' in Data Object Name.
  • The reference to the value is VALUE OF SUB-ELEMENT. Examples:
  • 'OD-CVM verification successful' in POS Cardholder Interaction Information refers to bit 5 of byte 2 in POS Cardholder Interaction Information. June 2023 EMV® Contactless Book C-2 Kernel 2 Spec v2.11 1 Using This Manual 1.5 Notations
  • 'CVM' in Outcome Parameter Set:= ONLINE PIN means the same as “bits 4 to 1 of byte 4 of Outcome Parameter Set are set to 0010b”.
  • Alternatively, an index may be used to identify a sub-element of a data object. In this case the following notational conventions apply:
  • To refer to a specific byte of a multi-byte data object, a byte index is used within brackets (i.e. [ ]). For example, Terminal Verification Results[2] represents byte 2 of Terminal Verification Results. The first byte (leftmost or most significant) of a data object has index 1.
  • To refer to a specific bit of a single byte multi-bit data object, a bit index is used within brackets [ ]. For example, Cryptogram Information Data[7] represents the 7th bit of the Cryptogram Information Data. The first bit (rightmost or least significant) of a data object has index 1.
  • To refer to a specific bit of a multi-byte data object, a byte index and a bit index are used within brackets (i.e. [ ][ ]). For example, Terminal Verification Results[2][4] represents bit 4 of byte 2 of the Terminal Verification Results.
  • Ranges of bytes are expressed with the x:y notational convention: For example, Terminal Verification Results[1:4] represents bytes 1, 2, 3, and 4 of the Terminal Verification Results.
  • Ranges of bits are expressed with the y:x notational convention: For example, Cryptogram Information Data[5:1] represents bits 5, 4, 3, 2, and 1 of the Cryptogram Information Data. June 2023 1 Using This Manual 1.5 Notations EMV® Contactless Book C-2 Kernel 2 Spec v2.11 1.5.3 Other Notational Conventions Notations for processing data and managing memory are described in Table 1.2. Table 1.2—Other Notational Conventions Symbol '0' to '9' and 'A'

Shown in part. Read the original for the full text.