CSCIP Module 5
Total Page:16
File Type:pdf, Size:1020Kb
Module 6/P: Smart Card Usage Models – Payments and Financial Transactions Smart Card Alliance Certified Smart Card Industry Professional Accreditation Program Smart Card Alliance © 2015 CSCIP Module 6/P - Payments and Financial Transactions FINAL – Version 2 – June 15, 2015 1 For CSCIP Applicant Use Only About the Smart Card Alliance The Smart Card Alliance is a not-for-profit, multi-industry association working to stimulate the understanding, adoption, use and widespread application of smart card technology. Through specific projects such as education programs, market research, advocacy, industry relations and open forums, the Alliance keeps its members connected to industry leaders and innovative thought. The Alliance is the single industry voice for smart cards, leading industry discussion on the impact and value of smart cards in the U.S. and Latin America. For more information please visit http://www.smartcardalliance.org. Important note: The CSCIP training modules are only available to LEAP members who have applied and paid for CSCIP certification. The modules are for CSCIP applicants ONLY for use in preparing for the CSCIP exam. These documents may be downloaded and printed by the CSCIP applicant. Further reproduction or distribution of these modules in any form is forbidden. Copyright © 2015 Smart Card Alliance, Inc. All rights reserved. Reproduction or distribution of this publication in any form is forbidden without prior permission from the Smart Card Alliance. The Smart Card Alliance has used best efforts to ensure, but cannot guarantee, that the information described in this report is accurate as of the publication date. The Smart Card Alliance disclaims all warranties as to the accuracy, completeness or adequacy of information in this report. Smart Card Alliance © 2015 CSCIP Module 6/P - Payments and Financial Transactions FINAL – Version 2 – June 15, 2015 2 For CSCIP Applicant Use Only TABLE OF CONTENTS 1 INTRODUCTION ................................................................................................................................. 6 2 SMART CARD MARKET DRIVERS AND BENEFITS FOR PAYMENTS AND FINANCIAL TRANSACTIONS ................................................................................................................................. 7 2.1 REDUCING FRAUD AND ENHANCING SECURITY .................................................................................8 2.2 ENHANCING CONSUMER CONVENIENCE AND CONFIDENCE ...............................................................8 2.3 ENHANCING THE BUSINESS CASE WITH MULTIPLE APPLICATIONS ....................................................8 2.4 IMPROVING EFFICIENCY AND INCREASING SALES VOLUME AT THE MERCHANT POS ........................9 2.5 SUPPORTING INNOVATION AND DIFFERENTIATION ............................................................................9 3 BANK CARD PAYMENTS ................................................................................................................ 10 3.1 BANK CARD TECHNOLOGY AND PROCESSING: MAGNETIC STRIPE CARDS ...................................... 11 3.2 BANK CARD TECHNOLOGY AND PROCESSING: SMART CARDS ........................................................ 12 3.2.1 EMV .................................................................................................................................. 13 3.2.2 Contactless Payments ....................................................................................................... 18 4 EMV ...................................................................................................................................................... 19 4.1 EMV SECURITY ............................................................................................................................... 20 4.1.1 Card Authentication Methods (CAM) ............................................................................... 20 4.1.2 Cardholder Verification Methods (CVM) ......................................................................... 21 4.1.3 Transaction Authorization ................................................................................................ 22 4.1.4 EMV Use of Symmetric and Asymmetric Cryptography ................................................... 23 4.2 EMV TRANSACTION FRAMEWORK .................................................................................................. 24 4.3 EMV CHIP SOFTWARE AND DATA ................................................................................................... 26 4.3.1 EMV Chip Applications and AIDs .................................................................................... 27 4.3.2 EMV Chip Data ................................................................................................................. 27 4.4 EMV CHANGES TO THE MESSAGING INFRASTRUCTURE .................................................................. 28 4.5 EMV MIGRATION OPTIONS ............................................................................................................. 30 4.5.1 Card Interface Options ..................................................................................................... 31 4.5.2 Card Authentication and Transaction Authorization Options .......................................... 32 4.5.3 Cardholder Verification .................................................................................................... 32 4.5.4 Hybrid Options .................................................................................................................. 32 4.5.5 EMV Infrastructure and Migration ................................................................................... 33 4.6 CARD ISSUER MIGRATION CONSIDERATIONS ................................................................................... 33 4.6.1 Card Interface ................................................................................................................... 33 4.6.2 Offline PIN vs. Online PIN................................................................................................ 33 4.6.3 Personalization System ..................................................................................................... 34 4.6.4 Host System ....................................................................................................................... 34 4.6.5 Transaction Authorization Process ................................................................................... 35 4.6.6 Summary ........................................................................................................................... 35 4.7 PAYMENTS ACQUIRER/PROCESSOR CONSIDERATIONS ..................................................................... 37 4.7.1 Contactless MSD ............................................................................................................... 37 4.7.2 Contactless EMV ............................................................................................................... 37 4.7.3 Contact EMV with Signature or PIN................................................................................. 38 4.7.4 Summary ........................................................................................................................... 38 4.8 POS TERMINAL AND MERCHANT POS SYSTEM CONSIDERATIONS .................................................. 39 4.8.1 Hardware Support............................................................................................................. 39 4.8.2 Software Support ............................................................................................................... 40 4.8.3 EMV and Brand Certification ........................................................................................... 41 4.8.4 Transaction Messaging Support ....................................................................................... 42 4.8.5 Terminal Upgrade Capabilities and Plans ....................................................................... 43 4.8.6 Summary ........................................................................................................................... 43 Smart Card Alliance © 2015 CSCIP Module 6/P - Payments and Financial Transactions FINAL – Version 2 – June 15, 2015 3 For CSCIP Applicant Use Only 4.9 U.S. EMV DEBIT ............................................................................................................................. 45 4.10 ATM CONSIDERATIONS ................................................................................................................... 46 4.10.1 ATM Hardware ................................................................................................................. 46 4.10.2 ATM Software ................................................................................................................... 46 4.10.3 Certifications ..................................................................................................................... 47 4.10.4 Terminal Upgrade Capabilities and Plans ....................................................................... 48 4.10.5 Summary ........................................................................................................................... 48 4.11 EMV AND NFC MOBILE CONTACTLESS PAYMENTS ........................................................................ 49 5 CONTACTLESS BANK CARD PAYMENT ..................................................................................