EMF Implementing EMV at The
Total Page:16
File Type:pdf, Size:1020Kb
Implementing EMV®at the ATM: Requirements and Recommendations for the U.S. ATM Community Version 2.0 Date: June 2015 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community About the EMV Migration Forum The EMV Migration Forum is a cross-industry body focused on supporting the EMV implementation steps required for global and regional payment networks, issuers, processors, merchants, and consumers to help ensure a successful introduction of more secure EMV chip technology in the United States. The focus of the Forum is to address topics that require some level of industry cooperation and/or coordination to migrate successfully to EMV technology in the United States. For more information on the EMV Migration Forum, please visit http://www.emv- connection.com/emv-migration-forum/. EMV is a trademark owned by EMVCo LLC. Copyright ©2015 EMV Migration Forum and Smart Card Alliance. All rights reserved. The EMV Migration Forum has used best efforts to ensure, but cannot guarantee, that the information described in this document is accurate as of the publication date. The EMV Migration Forum disclaims all warranties as to the accuracy, completeness or adequacy of information in this document. Comments or recommendations for edits or additions to this document should be submitted to: ATM- [email protected]. __________________________________________________________________________________ Page 2 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community TABLE OF CONTENTS 1 INTRODUCTION ............................................................................................................................................. 5 1.1 EXECUTIVE SUMMARY ........................................................................................................................................ 5 1.2 NOTES AND INFORMATION DISCLOSURE ................................................................................................................ 6 1.3 ASSUMPTIONS .................................................................................................................................................. 7 2 FUNDAMENTAL EMV CONCEPTS ................................................................................................................... 8 2.1 COMPARING A MAGNETIC STRIPE TRANSACTION WITH AN EMV TRANSACTION ............................................................ 8 2.2 EMV AND EMVCO ........................................................................................................................................... 8 2.3 ICC APPLICATIONS AND APPLICATION IDENTIFIERS ................................................................................................. 10 2.4 APPLICATION IDENTIFIERS USED BY NETWORKS ..................................................................................................... 12 2.5 EMV TAGS .................................................................................................................................................... 13 2.6 APPLICATION LABEL/APPLICATION PREFERRED NAME ............................................................................................ 14 2.7 ONLINE AND OFFLINE PIN ................................................................................................................................ 15 2.8 SERVICE CODES ............................................................................................................................................... 15 2.9 ISSUER SCRIPTS ............................................................................................................................................... 16 2.10 TERMINAL VERIFICATION RESULTS ...................................................................................................................... 18 3 BASIC EMV REQUIREMENTS FOR ATMS ....................................................................................................... 19 3.1 CARD READER ................................................................................................................................................ 19 3.2 OPERATING SYSTEM ........................................................................................................................................ 22 3.3 ATM SOFTWARE ............................................................................................................................................ 23 3.4 EMV SOFTWARE KERNEL ................................................................................................................................. 23 3.5 COMMUNICATIONS PROTOCOL .......................................................................................................................... 24 3.6 RECEIPTS ....................................................................................................................................................... 25 3.7 CONFIGURATION ............................................................................................................................................. 25 3.8 ENCRYPTION KEYS ........................................................................................................................................... 27 3.9 TESTING AND APPROVALS ................................................................................................................................. 27 4 MIGRATION PLANNING ............................................................................................................................... 29 4.1 GENERAL CONSIDERATIONS ............................................................................................................................... 29 4.2 UPGRADE OR REPLACE ..................................................................................................................................... 30 4.3 CERTIFICATION, TESTING, AND APPROVALS NEEDED .............................................................................................. 31 4.4 MIGRATION PLANNING TASKS ........................................................................................................................... 32 5 GENERAL CONSIDERATIONS ........................................................................................................................ 36 5.1 ROUTING ....................................................................................................................................................... 36 5.2 LIABILITY SHIFT ............................................................................................................................................... 36 5.3 TRANSACTION LOG .......................................................................................................................................... 37 5.4 ENCRYPTING PIN PAD REQUIREMENTS ................................................................................................................ 38 5.5 EXCEPTION CONDITIONS ................................................................................................................................... 38 5.6 CARD DATA IN ONLINE MESSAGE ....................................................................................................................... 39 5.7 TRANSACTION CHAINING .................................................................................................................................. 39 __________________________________________________________________________________ Page 3 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community 5.8 SERVICE LEVEL AGREEMENTS ............................................................................................................................. 41 5.9 ATM NON-CASH TRANSACTION TYPES ............................................................................................................... 41 5.10 NETWORK CONSIDERATIONS ............................................................................................................................. 44 6 RECOMMENDATIONS AND SUGGESTED BEST PRACTICES ............................................................................ 45 6.1 GENERAL RECOMMENDATIONS .......................................................................................................................... 45 6.2 TECHNICAL RECOMMENDATIONS ........................................................................................................................ 46 6.3 ENSURING A POSITIVE CUSTOMER EXPERIENCE ..................................................................................................... 48 7 ATM TRANSACTION PROCESSING WITH EMV .............................................................................................. 52 7.1 READING THE CHIP .......................................................................................................................................... 54 7.2 APPLICATION SELECTION ................................................................................................................................... 55 7.3 FINAL SELECTION ............................................................................................................................................ 57 7.4 LANGUAGE SELECTION ..................................................................................................................................... 59 7.5 OFFLINE DATA AUTHENTICATION ......................................................................................................................