EMVCo Letter of Approval - Terminal Level 2



Similar documents
EMVCo Letter of Approval - Contact Terminal Level 2

EMVCo Letter of Approval - Contact Terminal Level 2

Re: EMVCo Letter of Approval - Contact Terminal Level 2

JCB Terminal Requirements

Fundamentals of EMV. Guy Berg Senior Managing Consultant MasterCard Advisors

A Guide to EMV. Version 1.0 May Copyright 2011 EMVCo, LLC. All rights reserved.

Requirements for an EMVCo Common Contactless Application (CCA)

MasterCard PayPass. M/Chip, Acquirer Implementation Requirements. v.1-a4 6/06

M/Chip Functional Architecture for Debit and Credit

implementing American Express EMV acceptance on a Terminal

EMV 96 Integrated Circuit Card Terminal Specification for Payment Systems

Acquirer Device Validation Toolkit (ADVT)

Chip and PIN Programme. Guideline G18. Configuring Integrated Systems

Chip & PIN is definitely broken. Credit Card skimming and PIN harvesting in an EMV world

PayPass M/Chip Requirements. 10 April 2014

PayPass - M/Chip Requirements. 5 December 2011

Chip & PIN is definitely broken v1.4. Credit Card skimming and PIN harvesting in an EMV world

U.S. EMV Debit Implementation Guidelines for POS Acquirers

A Guide to EMV Version 1.0 May 2011

Using EMV Cards to Protect E-commerce Transactions

The EMV Readiness. Collis America. Guy Berg President, Collis America

CONTACTLESS PAYMENTS. Joeri de Ruiter. University of Birmingham. (some slides borrowed from Tom Chothia)

How To Protect A Smart Card From Being Hacked

EMV (Chip-and-PIN) Protocol

EPC SEPA CARDS STANDARDISATION (SCS) "VOLUME" BOOK 2

EMV: A to Z (Terms and Definitions)

EMV: Integrated Circuit Card Specifications for Payment Systems

Extending EMV payment smart cards with biometric on-card verification

Formal models of bank cards for free

The Canadian Migration to EMV. Prepared By:

EMV Acquiring at the ATM: Early Planning for Credit Unions

MasterCard Contactless Reader v3.0. INTRODUCTION TO MASTERCARD CONTACTLESS READER v3.0

Electronic Payments Part 1

EMV Frequently Asked Questions for Merchants May, 2014

EMV : Frequently Asked Questions for Merchants

EMV DEBIT ROUTING VERIFONE.COM

Master Thesis Towards an Improved EMV Credit Card Certification

Secure Remote Photo Identification With ID card

First Data s Program on EMV

EMV (Chip and PIN) Project. EMV card

Securing Card-Not-Present Transactions through EMV Authentication. Matthew Carter and Brienne Douglas December 18, 2015

Formal Analysis of the EMV Protocol Suite

SMARTCARD FRAUD DETECTION USING SECURE ONETIME RANDOM MOBILE PASSWORD

Payment Card Industry (PCI) Data Security Standard. PCI DSS Applicability in an EMV Environment A Guidance Document Version 1

Payments and Withdrawals with Cards in SEPA Applicable Standards and Certification Process

Formal analysis of EMV

FD40 User Guide. Version 16.0 June 2015

Introductions 1 min 4

Visa Recommended Practices for EMV Chip Implementation in the U.S.

Chip Card Acceptance Device

Smart Cards for Payment Systems

Balance Inquiry (Food Stamp or Cash Account) Use this function to obtain a cardholder s Account balance. Touch EBT. Touch desired option.

White Paper. EMV Key Management Explained

FUTURE PROOF TERMINAL QUICK REFERENCE GUIDE. Review this Quick Reference Guide to. learn how to run a sale, settle your batch

Mobile MasterCard PayPass UI Application Requirements. February Version 1.4

EMV Integrated Circuit Card Specifications for Payment Systems

EMV mobile Point of Sale (mpos) Initial Considerations

Card Payments Roadmap in the United States: How Will EMV Impact the Future Payments Infrastructure?

Overview of Contactless Payment Cards. Peter Fillmore. July 20, 2015

Maintenance Manual Version 1.02

Using Your Terminal for UnionPay Cards (05/15)

Securing Mobile Payment Protocol. based on EMV Standard

Heartland Secure. By: Michael English. A Heartland Payment Systems White Paper Executive Director, Product Development

EMV and Small Merchants:

Euronet s EMV Chip Solutions Superior Protection with Enhanced Security against Fraud

Preparing for EMV chip card acceptance

Payment systems. Tuomas Aura T Information security technology

Moneris HiSpeed 6200 OPERATING MANUAL For Credit, Chip and Debit Card Processing

Beyond Cards and Terminals: Considerations for Testing Host-to-Host EMV Processing

Quick IWL255 Merchant Operator Guide

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

Mobile and Contactless Payment Security

A typical 3D Secure transaction using TrustMarque s hosted MPI

VX 680 USER GUIDE. 001 Rev 1. VeriFone

American Express Contactless Payments

Full Dial Download to a Terminal with NO Existing Applications (The terminal will display DOWNLOAD NEEDED/*GO FILE NOT FOUND )

EMV's Role in reducing Payment Risks: a Multi-Layered Approach

Ingenico QUICK REFERENCE GUIDE

THE FIVE Ws OF EMV BY DAVE EWALD GLOBAL EMV CONSULTANT AND MANAGER DATACARD GROUP

INTRODUCTION AND HISTORY

EMV and Restaurants What you need to know! November 19, 2014

Visa Smart Debit/Credit Certificate Authority Public Keys

TS V1.3.1 ( )

What Merchants Need to Know About EMV

DPS POS Integration Certification Request and Test Scripts

EMV FAQs. Contact us at: Visit us online: VancoPayments.com

Ecommerce Setup Wizard Site Setup Wizards

What Issuers Need to Know Top 25 Questions on EMV Chip Cards and Personalization

What is EMV? What is different?

THE APPEAL FOR CONTACTLESS PAYMENT 3 AVAILABLE CONTACTLESS TECHNOLOGIES 3 USING ISO BASED TECHNOLOGY FOR PAYMENT 4

Card Payments Roadmap in the United States: How Will EMV Impact the Future Payments Infrastructure?

How Secure are Contactless Payment Systems?

Pima Federal Visa Credit Cards Frequently Asked Questions (FAQs)

Merchant Agreement for MasterCard, Maestro, Visa, Visa Electron, V PAY, JCB, China UnionPay and American Express. Business Procedures

EMV and Restaurants: What you need to know. Mike English. October Executive Director, Product Development Heartland Payment Systems

JCharge White Paper. Merchant, Acquirer, Bank, Authorization Network

MasterCard. Terminal Implementation Requirements. PayPass

Redwood Merchant Services. Merchant Processing Terminology

mobile payment acceptance Solutions Visa security best practices version 3.0

Chip and PIN is Broken a view to card payment infrastructure and security

Transcription:

April 06, 2011 Lorraine LEPINE France Telecom Direction Publiphonie (FT/OPF/MHGP/DMP/PUB) Orange Village, 1 avenue Nelson Mandela 94745 ARCUEIL France Re: EMV Application Kernel: Approval Number(s): EMVCo Letter of Approval - Terminal Level 2 Palier EP1 EMV V12.04 2-02026-1-1S-CBA-0411-4.2.b 2-02026-1-1P-CBA-0411-4.2.b 2-02026-1-1OS-CBA-0411-4.2.b The EMV Application Kernel has been tested on the following terminal Terminal: PF16-2 PinPad: 1P = Payphone PF16-2, PF16-2 Palier EP1 EMV V12.04 Checksum: 84000000 Operating System: 1OS = XEC86 Private Version V2 Report ID Session 1: ELITT/LABO/L2/2010-0528 - ELITT Approved Configurations: Config Vendor Config ID Terminal Checksum 1S SK 24 84000000 Page 1 of 6

Renewal Date: 06-Apr-2014 Dear Lorraine LEPINE: EMVCo, LLC ("EMVCo"), a Delaware limited liability company, has received your request for Level 2 terminal type approval for the EMV Application Kernel (hereafter refered to as Application) identified above. In connection with your request, we have reviewed all test file number(s) listed above. After assessing such file(s), EMVCo has found reasonable evidence that the submitted samples of the above referenced Application Kernel sufficiently conform to EMV Integrated Circuit Card Specifications for Payment Systems, Version 4.2 of June 2008. EMVCo hereby (a) grants your Application EMVCo Type Approval for Terminal Level 2, based on the requirements stated in the EMV 4.2 Specifications, and (b) agrees to include your Application Kernel in EMVCo's approved Application list. EMVCo's grant to your Application Kernel is subject to and specifically incorporates (i) the General Terms and Conditions to the Letter of Approval enclosed as Exhibit A, and (ii) the Specific Terms and Conditions to the Letter of Approval attached hereto as Attachment 1. Because EMVCo's grant is subject to such limitations, including certain events of termination, you and any third parties should confirm that such approval is current and has not been terminated by referring to the list of approved Application Kernels published on the EMVCo website (www.emvco.com). France Telecom This Letter of Approval is effective on dispatch from EMVCo. EMVCo, LLC, a Delaware limited liability company By: Name: Title: Arnaud du Chéné EMVCo Terminal Type Approval Page 2 of 6

Terminal Capabilities Card Data Input Capability Manual Key Entry Magnetic Stripe IC with Contacts CVM Capability Plaintext PIN for ICC Verification Enciphered PIN for online Verification Signature (Paper) Enciphered PIN for offline Verification CVM Required Security Capability Static Data Authentication and Dynamic Data Authentication Card Capture Combined Dynamic Data Authentication / Application Cryptogram Generation Transaction Type Capability Cash Goods Services Cash Back Inquiry Transfer Payment Administrative Cash Deposit Terminal Data Input Capability Does terminal have keypad Numeric Keys Alphabetic and Special Character Keys Command Keys Function Keys Terminal Data Output Capability Print, Attendant (Mandatory for terminals supporting signature) Print, Cardholder Display, Attendant (Mandatory for Attended terminals) Display Cardholder Code Table 10 Code Table 9 Code Table 8 Code Table 7 Code Table 6 Code Table 5 Code Table 4 Code Table 3 Code Table 2 Code Table 1 Value Supported Page 3 of 6

Terminal Capabilities Application Selection Support PSE selection Method Support Cardholder Confirmation Does Terminal have a preferred order of displaying applications Does terminal perfom partial AID selection Does the terminal have multi language support Does the terminal support the EMV Language Selection method Does the terminal support the Common Character Set as defined in Annex B table 20 Book 4 Selectable Kernel Configurations Does Terminal support Selectable Kernel Configurations according to EMVCo's defined Selection Criteria Does Terminal support Amount Selection Criteria X Does Terminal support Amount Selection Criteria X and Y Does Terminal support Amount Selection Criteria X per AID Does Terminal support Amount Selection Criteria X and Y per AID Data Authentication What is the maximun supported Certificate Authority Public Key Size (Mandatory for terminals supporting Data Authentication with minimal support for 248 bytes) What exponents does the terminal support (Mandatory for terminals supporting Data Authentication, 3 and 2^16+1) During data authentication does the terminal check validity for revocation of Issuer Public Key Certificate When supporting certificate revocation, what is the Certificate Revocation List format? Does the terminal contain a default DDOL (Mandatory for terminals supporting DDA) Is operator action required when loading CA Public Key fails CA Public Key verified with CA Public Key Check Sum Cardholder Verification Method Terminal supports bypass PIN Entry Terminal supports Subsequent bypass PIN Entry Terminal supports Get Data for PIN Try Counter Terminal supports Fail CVM Are amounts known before CVM processing Terminal Risk Management Floor Limit Checking (Mandatory for offline only terminals and offline terminals with online capability) Random Transaction Selection (Mandatory for offline terminals with online capability, except when cardholder controlled) Velocity Checking (Mandatory for offline only terminals and offline terminals with online capability) Transaction Log Exception File Performance of Terminal Risk Management irrespective of AIP setting (expected behavior) Value Supported n/a 0 ne Page 4 of 6

Terminal Capabilities Terminal Action Analysis Does the terminal support Terminal Action Codes Can the values of the Terminal Action Codes be changed Can the Terminal Action Codes be deleted or disabled? If yes what are the default TAC values supported? (according to Book 3 Section 10.7) Does Offline Only Terminal process Default Action Codes prior to First Generate AC Does Offline Only Terminal process Default Action Codes after First Generate AC Does Online Only Terminal skip processing TAC/IAC-Default and automatically request an AAC when unable to go online Does Online Only Terminal process TAC/IAC-Default as normal when unable to go online Device capable of detecting CDA failure before Terminal Action Analysis Mode 1: Req. CDA on ARQC + Req. CDA on 2nd GenAC after approved Online Mode 2: Req. CDA on ARQC + Req. CDA on 2nd GenAC after approved Online Mode 3: Req. CDA on ARQC + Req. CDA on 2nd GenAC after approved Online Mode 4: Req. CDA on ARQC + Req. CDA on 2nd GenAC after approved Online Completion Processing Transaction Forced Online Capability Transaction Forced Acceptance Capability Does terminal Support advices Does the terminal support Issuer initiated Voice Referrals Does the terminal support Batch Data Capture Does the terminal support Online Data Capture Does the terminal support a Default TDOL Exception Handling What is the POS Entry Mode value when IC cannot be read and the transaction falls back using Magstripe (Mandatory for attended terminals) Miscellaneous Is the terminal equipped with a PIN Pad Is the amount and PIN entered at the same keypad Is the ICC/Magstripe Reader combined If Combined ICC/Magstripe reader is supported, is Magstripe read first Does the terminal support account type selection Does the terminal support 'on fly' script processing (not recommended behavior) Is the Issuer Script device limit greater than 128 bytes If the Issuer Script device limit is greater than 128 bytes, what is the value supported Does the terminal support Internal Date Management TAC Denial: TAC Online: TAC Default: Value Supported n/a ne n/a ne Page 5 of 6

Attachment 1 Specific Terms and Conditions to the Letter of Approval Restriction: ne Page 6 of 6