2
Collis Solutions & Markets
Consu
ltancy Test Tools
Training Courses Test Serv
ices
Finance
Governm
entTel
ecom
Transport
Card PaymentsSEPA
Financial Risk Mgmt
e-TicketingRoad PricingTachograph
SIM/HandsetNFC
Billing
e-DocumentsLaw & OrderPublic Admin
4
EMV Readiness in the U.S.
What is EMV Migration, What is Involved:Card – Contactless EMV– Contact EMV– US Contactless
Terminal
Acquirer
Issuer Host
Full EMV and Partial EMV
A New Look at US EMV Readiness
5
Acquirer
Terminal
Authorization System
Card ConfigurationsContactless
MasterCard PayPassVisa payWave
Card Eco‐System
ContactMCHIP, VSDCJ‐Smart
Contact EMVVSDC, MCHIP
Contact ReaderSupport
Transaction Processing
MSD EMVContactless EMV
Contactless MSD
EMVContact
MSDContactless
EMVContactless
Contactless(ISO 14443)
6
The Transaction
Host System
Adds Online Transaction SecurityAdds Offline Transaction SecurityCard Cloning Security
EMV Transaction Shift
Transaction Acceptance Rules
Risk Assessment
Transaction Authorization Rules
Risk Assessment
Mag Stripe CardsChip Cards
11
Contactless Card Types
Contactless Magstripe CardsMagstripe data placed on the chip
On‐line authorization
Dynamically created codeUnpredictable # from terminal
ATC (transaction counter)
A secret Key from the card
Replay attacks are countered by using this code in the authorisation message
Antenna
12
Contactless Card Types
Contactless EMV cards• Risk management
• Decision making
• Offline counters
• Transactions can be offline or online
• Application Cryptogram
• No cardholder verification required for Small Value transactions
Antenna
14
EMV Kernel.EXE
Payment Application
POS Terminal Architecture
Hardware Interfaces
.TXT
Operating System
.TXT .TXT .TXT
Contact Contactless
Contact Reader
Contactless Reader
Other EMV Other EMV
Contactless
MSD
EMV
EMV Level 1 Certification
EMV Level 2 Certification
Scheme LevelCertification
16
Application Changes for Full EMV
Transaction Flow
Configuration Data
Crypto Functions
Transaction Logging
Authorization Protocol
Data Capture Elements
Ticket Printing
Fallback Processing
17
Industry Terminal Status
Most Terminal Vendors:Have multiple Contactless EMV certified terminals
Can add Contactless readers to existing POS terminals and ECRs.
Have EMV certified PIN Pads to integrate EMV support
Contactless EMV application support can be downloaded to terminals
19
The Transaction
Host System
New Authorization Data
Transaction Acceptance Rules
Risk Assessment
Transaction Authorization Rules
Risk Assessment
EMV Transaction
ISO 8583 Message
HSM
FULL EMV
Acquirer System
20
New Authorisation Data Elements for EMV
Application Interchange Profile
Application Transaction Counter
ARQC (Application Request Cryptogram)
CVM Results (Card Validation Method)
Issuer Application Data
Terminal Capabilities
Terminal Type
TVR (Terminal Verification Results)
Unpredictable Number
24
Card
Processor Switch
Acquiring
bankIssuing
bank
Consumer Merchant
Issuer Acquirer
6
1
2
3
4
55412 3402 1103 1803
Standards
Standards
Not as Standardized
Acquirer SituationAcquirer Situation
26
International Retailers
Need to implement EMV to support stores in other countries:• Canada• Europe• South America• Mexico• Asia Pacific• Middle East
27
Acquirer Support for Intl Retailers
Acquirers need to support International Merchants• FDMS• Global Payments• Chase Paymentech• Moneris• eFunds/Fidelity• TSYS
Most Acquirers support EMV transaction capture on at least one of their platforms.
29
Issuer Auth System
Full verses Partial EMV
SDA/DDA/CDAAuthentication
Partial ImplementationStops at the terminal
Acquirer System
ARQC
ARPC
ARQC
ARPC
Full EMV
30
EMV Readiness – A different perspective
Contactless EMVUS contactless infrastructure can be leveraged for EMV Contactless
Contactless Cards in US Cards will be personalized to support contactless EMV in addition to Contactless MSD
Terminal Vendors All have certified EMV TerminalsProvide ability to add Contactless EMV support via PIN pads and terminal add‐ons.
International Retailers Need to support International locations
Many Acquirers Have implemented EMV support in at least one platform to support International retailers
Partial EMV Implementation Can happen at the Card & Terminal level
31
The Payment Technology Evolution
-- ???--
EmbossedCards
MagstripeCredit Cards
ContactlessCards
MagstripeDebit Cards
EMV ContactlessCards or NFC
32
Contact detailsCollis Global & EMEALeiden, the NetherlandsCall +31 71 581 3636 Email [email protected] www.collis.nl
Collis FranceParis, FranceCall +33 66 75 08 703 Email [email protected] www.collis.fr
Collis AmericaSt. Paul, MN, USACall +1 651 925 5410 Email [email protected] www.collisamerica.com
Collis AsiaSingaporeCall +65 68 90 64 40 Email [email protected] www.collisasia.com
Collis DubaiDubai, United Arab EmiratesCall + 971 50 674 2380 Email [email protected] www.collisdubai.com