+ All Categories
Home > Documents > EMV - Europay,MasterCard,Visa

EMV - Europay,MasterCard,Visa

Date post: 18-Nov-2014
Category:
Upload: rajat-kumar
View: 168 times
Download: 0 times
Share this document with a friend
Description:
This document briefly talks about EMV Certification.
Popular Tags:
21
EUROPAY, MASTERCARD & VISA (EMV) VISA (EMV) Testing Procedures and Specifications By Rajat Kumar
Transcript
Page 1: EMV - Europay,MasterCard,Visa

EUROPAY, MASTERCARD & VISA (EMV)VISA (EMV)

Testing Procedures and Specifications

By Rajat Kumar

Page 2: EMV - Europay,MasterCard,Visa

Basic Terms

� Account Holder – Consumer using Integrated Circuit Card (ICC)

� Acquirer – Financial Institution that enlists merchant to use an application like VISAto use an application like VISA

� Issuer – Financial Institution which issues ICC to consumer

� Merchant – a store, restaurant, airline etc.

Page 3: EMV - Europay,MasterCard,Visa

Transaction Flow

CardholderMerchant Acquirer

Application Issuer

VISA/MASTERCARD

Page 4: EMV - Europay,MasterCard,Visa

Course of Presentation

� Common Payment Application(CPA) basics

� Terminal requirements

� Hardware

� Software� Software

� Test Procedure

� Level 1

� Level 2

� Contactless Specifications

Page 5: EMV - Europay,MasterCard,Visa

Common Payment Application- a process overview

� Application Selection

� Checking for offline verification

� Initiate Application Processing

� Read Application Data

Page 6: EMV - Europay,MasterCard,Visa

CPA – a process overview

� Offline Data Authentication

� Two methods

� Static Data Authentication(SDA)

� Dynamic Data Authentication(DDA)

� SDA verifies authenticity of personalized data

� Dynamic data authentication has two forms :

� In DDA, terminal decodes a cryptogram generated by card using dynamic data, thus verifying legitimacy of card

� In Combined DDA/ Generate AC, a dynamic signature is sent along with Application Cryptogram to terminal.

Page 7: EMV - Europay,MasterCard,Visa

CPA – a process overview

� Processing Restrictions

� Cardholder Verification

� Terminal Risk Management

� Terminal Action Analysis� Terminal Action Analysis

� Terminal decides on basis of results from offline data authentication, processing restrictions, terminal risk mgmt. and cardholder verification to approve transaction offline, sent online for verification or decline offline.

Page 8: EMV - Europay,MasterCard,Visa

POS Terminal Definition

� Terminal Type ‘22’

� Offline with online capability for carrying out transactions

� Operational Control is provided by merchant� Operational Control is provided by merchant

-- EMV v4.2 Book 4

Page 9: EMV - Europay,MasterCard,Visa

Terminal Requirements

� Mechanical Characteristics

� IFD must be ISI/IEC 7816-1,2

� Contact embossing should be ISO 7811 -1,3 compliant.

� Contact force on IC Card contacts must be in range of � Contact force on IC Card contacts must be in range of 0.2 to 0.6 Newton.

-- EMV v4.2 Book 1

Page 10: EMV - Europay,MasterCard,Visa

Terminal contact locations

Page 11: EMV - Europay,MasterCard,Visa

Terminal Requirements

� Electrical Characteristics

� All measurements must be with respect to GND over an ambience 5⁰ C to 40⁰ C

� Input/Output contact must limit current by +/-15mA

⁰ ⁰

� Rise and Fall times for signals as mentioned in Book-1

-- EMV v4.2 Book 1

Page 12: EMV - Europay,MasterCard,Visa

Terminal Requirements

� Software Characteristics

�Offline data authentication

� Personal Identification Number encipherment

� Secure messaging� Secure messaging

� Terminal security

Page 13: EMV - Europay,MasterCard,Visa

Test Procedure

� Multi level testing

� Level 1

� Electromechanical characteristics

� Logical interface

� Transmission protocol

� Level 2

� Compliance with debit/credit payment applications

Page 14: EMV - Europay,MasterCard,Visa

Test Procedure

� Level 1 Test Cases

� Card session test

� Answer to reset test

� Protocol test

Transport layer test� Transport layer test

-- Terminal Level-1 Test Cases

Page 15: EMV - Europay,MasterCard,Visa

Test Procedure

� Level 2 Test Cases

� Application selection

� Security aspects

� Cryptography algorithm

Functions in transaction processing� Functions in transaction processing

� Erroneous/missing data in ICC

-- Terminal Level-2 Test Cases

Page 16: EMV - Europay,MasterCard,Visa

Contactless Specifications

� Communication Protocol

� Electrical characteristics of interface

� Power requirements

�Modulation methods used

� Protocol layer sequence

� Proximity Coupling Device’s(PCD) polling mechanism

Page 17: EMV - Europay,MasterCard,Visa

Contactless Specifications

� Terminal Architecture

� Entry Point – An overlying layer above application kernels to support multiple legacy kernels.

� Application kernels such as Paypass MasterCard chip kernel lie in the next layer

�Once Entry Point finds a suitable kernel match with PICC it hands over communication to it.

Page 18: EMV - Europay,MasterCard,Visa

Contactless Specifications

Terminal Architecture

Page 19: EMV - Europay,MasterCard,Visa

Contactless Testing

� Level 1 is about compliance to EMV CL Communication Protocol Specification v2.0

� Entry Point Compliance Label is given after testing Entry Point using specified kernelsEntry Point using specified kernels

* Level 1 certification has been given to three terminals.

* No test cases mentioned for Level 1/Entry Point.

Page 20: EMV - Europay,MasterCard,Visa

References

� www.emvco.com

� www.visa.com

� Google Image & Web Search

Page 21: EMV - Europay,MasterCard,Visa

Thank You


Recommended