EMF Implementing EMV at The

Total Page:16

File Type:pdf, Size:1020Kb

EMF Implementing EMV at The Implementing EMV®at the ATM: Requirements and Recommendations for the U.S. ATM Community Version 2.0 Date: June 2015 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community About the EMV Migration Forum The EMV Migration Forum is a cross-industry body focused on supporting the EMV implementation steps required for global and regional payment networks, issuers, processors, merchants, and consumers to help ensure a successful introduction of more secure EMV chip technology in the United States. The focus of the Forum is to address topics that require some level of industry cooperation and/or coordination to migrate successfully to EMV technology in the United States. For more information on the EMV Migration Forum, please visit http://www.emv- connection.com/emv-migration-forum/. EMV is a trademark owned by EMVCo LLC. Copyright ©2015 EMV Migration Forum and Smart Card Alliance. All rights reserved. The EMV Migration Forum has used best efforts to ensure, but cannot guarantee, that the information described in this document is accurate as of the publication date. The EMV Migration Forum disclaims all warranties as to the accuracy, completeness or adequacy of information in this document. Comments or recommendations for edits or additions to this document should be submitted to: ATM- [email protected]. __________________________________________________________________________________ Page 2 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community TABLE OF CONTENTS 1 INTRODUCTION ............................................................................................................................................. 5 1.1 EXECUTIVE SUMMARY ........................................................................................................................................ 5 1.2 NOTES AND INFORMATION DISCLOSURE ................................................................................................................ 6 1.3 ASSUMPTIONS .................................................................................................................................................. 7 2 FUNDAMENTAL EMV CONCEPTS ................................................................................................................... 8 2.1 COMPARING A MAGNETIC STRIPE TRANSACTION WITH AN EMV TRANSACTION ............................................................ 8 2.2 EMV AND EMVCO ........................................................................................................................................... 8 2.3 ICC APPLICATIONS AND APPLICATION IDENTIFIERS ................................................................................................. 10 2.4 APPLICATION IDENTIFIERS USED BY NETWORKS ..................................................................................................... 12 2.5 EMV TAGS .................................................................................................................................................... 13 2.6 APPLICATION LABEL/APPLICATION PREFERRED NAME ............................................................................................ 14 2.7 ONLINE AND OFFLINE PIN ................................................................................................................................ 15 2.8 SERVICE CODES ............................................................................................................................................... 15 2.9 ISSUER SCRIPTS ............................................................................................................................................... 16 2.10 TERMINAL VERIFICATION RESULTS ...................................................................................................................... 18 3 BASIC EMV REQUIREMENTS FOR ATMS ....................................................................................................... 19 3.1 CARD READER ................................................................................................................................................ 19 3.2 OPERATING SYSTEM ........................................................................................................................................ 22 3.3 ATM SOFTWARE ............................................................................................................................................ 23 3.4 EMV SOFTWARE KERNEL ................................................................................................................................. 23 3.5 COMMUNICATIONS PROTOCOL .......................................................................................................................... 24 3.6 RECEIPTS ....................................................................................................................................................... 25 3.7 CONFIGURATION ............................................................................................................................................. 25 3.8 ENCRYPTION KEYS ........................................................................................................................................... 27 3.9 TESTING AND APPROVALS ................................................................................................................................. 27 4 MIGRATION PLANNING ............................................................................................................................... 29 4.1 GENERAL CONSIDERATIONS ............................................................................................................................... 29 4.2 UPGRADE OR REPLACE ..................................................................................................................................... 30 4.3 CERTIFICATION, TESTING, AND APPROVALS NEEDED .............................................................................................. 31 4.4 MIGRATION PLANNING TASKS ........................................................................................................................... 32 5 GENERAL CONSIDERATIONS ........................................................................................................................ 36 5.1 ROUTING ....................................................................................................................................................... 36 5.2 LIABILITY SHIFT ............................................................................................................................................... 36 5.3 TRANSACTION LOG .......................................................................................................................................... 37 5.4 ENCRYPTING PIN PAD REQUIREMENTS ................................................................................................................ 38 5.5 EXCEPTION CONDITIONS ................................................................................................................................... 38 5.6 CARD DATA IN ONLINE MESSAGE ....................................................................................................................... 39 5.7 TRANSACTION CHAINING .................................................................................................................................. 39 __________________________________________________________________________________ Page 3 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community 5.8 SERVICE LEVEL AGREEMENTS ............................................................................................................................. 41 5.9 ATM NON-CASH TRANSACTION TYPES ............................................................................................................... 41 5.10 NETWORK CONSIDERATIONS ............................................................................................................................. 44 6 RECOMMENDATIONS AND SUGGESTED BEST PRACTICES ............................................................................ 45 6.1 GENERAL RECOMMENDATIONS .......................................................................................................................... 45 6.2 TECHNICAL RECOMMENDATIONS ........................................................................................................................ 46 6.3 ENSURING A POSITIVE CUSTOMER EXPERIENCE ..................................................................................................... 48 7 ATM TRANSACTION PROCESSING WITH EMV .............................................................................................. 52 7.1 READING THE CHIP .......................................................................................................................................... 54 7.2 APPLICATION SELECTION ................................................................................................................................... 55 7.3 FINAL SELECTION ............................................................................................................................................ 57 7.4 LANGUAGE SELECTION ..................................................................................................................................... 59 7.5 OFFLINE DATA AUTHENTICATION ......................................................................................................................
Recommended publications
  • Milesaway Business Card
    BUSINESS CARD 14001 University Avenue • Clive, Iowa 50325-8258 Toll-free 1-888-400-5711 • Fax 1-800-704-9416 Cardholder Agreement Revised May 2020 This Cardholder Agreement (“Agreement”) and the application you signed or otherwise submitted (collectively, the “Cardholder Documents”) govern the use of your MilesAway MasterCard credit card account (“Account”) with us. The word “Card” means one or more cards or other access devices, such as account numbers, that we have issued to you to permit you to obtain credit under this Agreement. Your signature (including any electronic or digital signature) on your Card, on any application, on any accepted sales slip, or on any other document you sign in connection with the use of your Card or your Account is part of and incorporated into this Agreement. Please read and keep the Cardholder Documents for your records. In this Agreement and in your monthly Periodic Statement (as defned below), the words “you”, “your” and “yours” mean all persons responsible for complying with this Agreement, including but not limited to, the person who applied for the Account and the person to whom we address the periodic Statements, as well as any person who you authorize to use the Account. The words “we”, “us” and “our” refer to NCMIC Finance Corporation, an Iowa Corporation. 1. USE OF ACCOUNT. YOU AGREE TO USE THE ACCOUNT AND CARD(S) ISSUED FOR THE ACCOUNT TO MAKE PURCHASES OR LEASE GOODS OR SERVICES FOR COMMERCIAL OR BUSINESS PURPOSES ONLY (AND NOT FOR PERSONAL, FAMILY OR HOUSEHOLD USE) from any person who accepts the Card(s) (“Purchases”).
    [Show full text]
  • How Can Private Sector Systems Achieve Public Policy Goals?
    Faster Payments in the United States: How Can Private Sector Systems Achieve Public Policy Goals? Fumiko Hayashi June 2015 RWP 15-03 Faster Payments in the United States: How Can Private Sector Systems Achieve Public Policy Goals?∗ Fumiko Hayashi† June 2015 Abstract Consumers and businesses are increasingly expecting faster payments. While many countries have already developed or are in process of developing faster payments, the availability of these payments is fragmented in the United States. The recently released paper by the Federal Reserve encourages private sector participants to provide faster payment services. However, private- sector faster payments systems will face significant challenges in achieving public policy goals of ubiquity, safety, and efficiency unless system governance represents broad public interests. One way to better align private-sector interests with those of the public is for the Federal Reserve to influence governance of the private-sector systems through its leadership role. JEL Classification: L5; L88; M14 Keywords: Faster payments, System governance, Public interest ∗ The author thanks Kelly Edmiston and Richard J. Sullivan for valuable comments, and Elizabeth Cook for editorial suggestions. The views expressed herein are those of the author and do not necessarily reflect the views of the Federal Reserve Bank of Kansas City or the Federal Reserve System. † Fumiko Hayashi is a senior economist at the Federal Reserve Bank of Kansas City. E-mail: [email protected]. 1 1. Introduction In the wake of technological innovations such as high-speed data networks and sophisticated mobile computing devices, consumers and businesses have raised their expectations for faster payments. Payment users increasingly expect electronic payment products to be accessible through mobile and online channels at any time.
    [Show full text]
  • Consumer Credit Card Disclosure Effective October 1, 2017
    Consumer Credit Card Disclosure Effective October 1, 2017 VISA Platinum Tier I, Tier II, Tier III, Student VISA Free CU Rewards • No Annual Fee Important information about your credit card contract & your billing rights KEEP THIS NOTICE FOR FUTURE USE Visa Credit Card AGREEMENT & REGULATIONS These regulations are effective October 1, 2017, and are subject to change. In these regulations the words “you” and “your” mean each and all of those who applied for the card. “Card” means your VISA credit card issued by Altra Federal Credit Union. “We,” “us,” and “our” means Altra Federal Credit Union. 1. Responsibility. If you apply for and receive a personal card from us, you agree to these regulations and you agree to maintain membership in good standing at Altra Federal Credit Union. You agree to use the card for personal charges. You also agree to repay all debts, advances, and any Finance Charge or any other fees or charges arising from the use of the card and the card account. For example, you are responsible for charges made by yourself, your spouse, and minor children. You are also responsible for charges made by anyone else to whom you give the card, and this responsibility continues until you recover and return the card to us. Except to the extent allowed by law, you cannot disclaim responsibility by notifying us. Your responsibility continues even though an agreement, divorce decree, or other court judgment which we are not a party to may direct you or one of the other persons responsible to pay the account. Any person using the card shall be jointly responsible with you for charges he or she makes, and if that person signs the application and receives a copy of these regulations, he or she is also responsible for all charges on the account, including yours.
    [Show full text]
  • Public Bank Unionpay Lifestyle Debit Card Product Disclosure Sheet
    PRODUCT DISCLOSURE SHEET Public Bank Berhad (6463-H) Read this Product Disclosure Sheet before you PB Visa/MasterCard Lifestyle Debit – Generic decide to take up the PB Visa/MasterCard/Union Pay Lifestyle Debit. Be sure to also read the PB Visa/MasterCard Lifestyle Debit – Basic general terms and conditions. Savings Account/Basic Current Account PB UnionPay Lifestyle Debit – PB UnionPay Savings Account Date: 1. What is this product about? PB Visa/MasterCard/UnionPay Lifestyle Debit is a two-in-one card combining Visa/MasterCard/ UnionPay debit card and ATM functions. The card is linked to the Savings Account/Current Account/Basic Savings Account/Basic Current Account/PB UnionPay Savings Account (“Banking Account”) of the individual and any expenditure will be deducted directly from the Banking Account. This is a PB Visa/MasterCard/UnionPay Lifestyle Debit, a payment instrument which allows you to pay via a direct deduction of the cost for goods and services from your Banking Account at participating retail and service outlets. You are required to maintain a Banking Account with us, to be linked to your PB Visa/MasterCard/UnionPay Lifestyle Debit. If you close your Banking Account maintained with us, your PB Visa/MasterCard/UnionPay Lifestyle Debit will be automatically cancelled. 2. What are the fees and charges I have to pay? (i) Annual Fee x Generic/PB UnionPay Savings Account: RM8.00 x Basic Savings Account/Basic Current Account: Waived (subject to eight (8) ATM cash withdrawals and six (6) over-the-counter withdrawals per month*) *Note: Fee for exceeding the threshold will be RM1.00 per transaction.
    [Show full text]
  • Card Processing Guide Merchant Operating Instructions
    Card Processing Guide Merchant Operating Instructions © 2019 GPUK LLP. All Rights Reserved. CONTENTS SECTION PAGE Welcome 1 Global Payments 1 About This Document 1 An Introduction To Card Processing 3 The Anatomy Of A Card Payment 3 Transaction Types 4 Risk Awareness 4 Card Present (CP) Transactions 9 Cardholder Verified By PIN 9 Cardholder Verified By Signature 9 Cardholder Verified By PIN And Signature 9 Contactless Card Payments 10 Checking Cards 10 Examples Of Card Logos 13 Examples Of Cards And Card Features 14 Accepting Cards Using An Electronic Terminal 18 Authorisation 19 ‘Code 10’ Calls 24 Account Verification/Status Checks 25 Recovered Cards 25 Refunds 26 How To Submit Your Electronic Terminal Transactions 28 Using Fallback Paper Vouchers 29 Card Not Present (CNP) Transactions 32 Accepting Mail And Telephone Orders 32 Accepting Internet Orders 33 Authorisation Of CNP Transactions 35 Confirming CNP Orders 37 Delivering Goods 37 Collection Of Goods 38 Special Transaction Types 39 Bureau de Change 39 Dynamic Currency Conversion (DCC) 40 Foreign Currency Transactions 40 Gratuities 41 Hotel And Car Rental Transactions 41 Prepayments/Deposits/Instalments 43 Purchase With Cashback 43 Recurring Transactions 44 Card Processing Guide © 2019 GPUK LLP. All Rights Reserved. SECTION PAGE Global Iris 47 HomeCurrencyPay 49 An Introduction To HomeCurrencyPay 49 Card Present (CP) HomeCurrencyPay Transactions 50 Mail Order And Telephone Order (MOTO) HomeCurrencyPay Transactions 52 Ecommerce HomeCurrencyPay Transactions 55 Mastercard And Visa Regulations
    [Show full text]
  • (Automated Teller Machine) and Debit Cards Is Rising. ATM Cards Have A
    Consumer Decision Making Contest 2001-2002 Study Guide ATM/Debit Cards The popularity of ATM (automated teller machine) and debit cards is rising. ATM cards have a longer history than debit cards, but the National Consumers League estimates that two-thirds of American households are likely to have debit cards by the end of 2000. It is expected that debit cards will rival cash and checks as a form of payment. In the future, “smart cards” with embedded computer chips may replace ATM, debit and credit cards. Single-purpose smart cards can be used for one purpose, like making a phone call, or riding mass transit. The smart card keeps track of how much value is left on your card. Other smart cards have multiple functions - serve as an ATM card, a debit card, a credit card and an electronic cash card. While this Study Guide will not discuss smart cards, they are on the horizon. Future consumers who understand how to select and use ATM and debit cards will know how to evaluate the features and costs of smart cards. ATM and Debit Cards and How They Work Electronic banking transactions are now a part of the American landscape. ATM cards and debit cards play a major role in these transactions. While ATM cards allow us to withdraw cash to meet our needs, debit cards allow us to by-pass the use of cash in point-of-sale (POS) purchases. Debit cards can also be used to withdraw cash from ATM machines. Both types of plastic cards are tied to a basic transaction account, either a checking account or a savings account.
    [Show full text]
  • Personal On-Line Payments
    Kenneth N. Kuttner and James J. McAndrews Personal On-Line Payments • Personal on-line payment systems— he rapid growth of e-commerce and the Internet has led to Internet-based systems for making small retail Tthe development of new payment mechanisms capable payments—have recently emerged as an of tapping the Internet’s unique potential for speed and alternative to cash, checks, and credit cards. convenience. A recent and especially successful example of such a development is the personal on-line payment: • All these systems use the web to convey a mechanism that uses web and e-mail technologies to 1 payment information, but they differ in the facilitate transfers between individuals. type of accounts they access: In proprietary In a typical transaction of this type, the payer accesses the account systems, funds are transferred payment provider’s web site to initiate a funds transfer. The between special-purpose accounts payer enters information about the transfer along with maintained by a nonbank provider; in bank- payment delivery instructions. Notification of the transfer is sent to the payee by e-mail; confirmation by the payee also account-based systems, funds are transferred occurs via e-mail. The payment provider’s computer then between demand deposit accounts at banks. transfers the funds. The first on-line payment systems were created by dot-com Increased acceptance of this payment • start-ups in 1999, and their usefulness quickly became method will depend on effective risk control apparent in on-line auctions. These systems grew out of the and improved settlement arrangements limitations of retail payment instruments in meeting the needs among nonbank providers, a group that of auction participants.
    [Show full text]
  • Contactless Operating Mode Requirements Clarification Whitepaper
    Contactless Operating Mode Requirements Clarification Whitepaper Version 1.0 Publication Date: February 2020 U.S. Payments Forum ©2020 Page 1 About the U.S. Payments Forum The U.S. Payments Forum, formerly the EMV Migration Forum, is a cross-industry body focused on supporting the introduction and implementation of EMV chip and other new and emerging technologies that protect the security of, and enhance opportunities for payment transactions within the United States. The Forum is the only non-profit organization whose membership includes the entire payments ecosystem, ensuring that all stakeholders have the opportunity to coordinate, cooperate on, and have a voice in the future of the U.S. payments industry. Additional information can be found at http://www.uspaymentsforum.org. EMV ® is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo, LLC. Copyright ©2020 U.S. Payments Forum and Smart Card Alliance. All rights reserved. The U.S. Payments Forum has used best efforts to ensure, but cannot guarantee, that the information described in this document is accurate as of the publication date. The U.S. Payments Forum disclaims all warranties as to the accuracy, completeness or adequacy of information in this document. Comments or recommendations for edits or additions to this document should be submitted to: [email protected]. U.S. Payments Forum ©2020 Page 2 Table of Contents 1. Introduction .......................................................................................................................................... 4 2. Contactless Operating Modes ............................................................................................................... 5 2.1 Impact of Contactless Operating Mode on Debit Routing Options .............................................. 6 3. Contactless Issuance Requirements ..................................................................................................... 7 4.
    [Show full text]
  • Chip Cards and EMV: Coming Soon
    What are the benefits? Chip cards and Chip cards offer a more secure way to process card transactions. The secure microchip contains security EMV: coming soon data and software – because it is more difficult to fraudulently copy the details of the card, security is increased. Accepting chip cards therefore helps you reduce the risk of processing a counterfeit, lost or stolen card. And better card security means fewer disputed transactions. ADB3492 110908 We’re here to help You can find more information about EMV at www.commbank.com.au/emv If you have any further queries about EMV, you can email [email protected] or call our Merchant Help Desk on 1800 022 966, 24 hours, Important information about 7 days a week. your EFTPOS terminal inside What is EMV? What do you need to do? EMV (Europay MasterCard Visa) is the global All you need to do is leave your terminal switched ON electronic transaction standard named after the three overnight from 08 October, and we’ll do the rest. organisations that established it. The EMV standard enables EFTPOS terminals worldwide to process chip-based debit and credit cards. How do you know when To meet EMV standards, the Commonwealth Bank the upgrade is complete? is planning upgrades to its EFTPOS terminals so they can process chip cards. Once you swipe a card that has a chip, your EFTPOS Please note that after the upgrade, you will still be able terminal will prompt you to ‘insert card’ rather than to process cards using the magnetic strip, including ‘swipe card’.
    [Show full text]
  • Introduction: History
    Introduction: "Key to the global village", that is how the Smart Card has been described. Smart Cards will bring big changes to the way people provide and receive information and the way they spend money. They will have a profound impact on retailing and service delivery. A Smart Card is like an "electronic wallet". It is a standard credit card-sized plastic intelligent token within which a microchip has been embedded within its body and which makes it 'smart'. It provides not only memory capacity, but computational capability as well and thus the chip is capable of processing data. It has gold contacts that allow other devices to communicate with it. This chip holds a variety of information, from stored (monetary) value used for retail and vending machines to secure information and applications for higher-end operations such as medical/healthcare records. New information and applications can be added depending on the chip capabilities. Smart Cards can store several hundred times more data than a conventional card with a magnetic stripe and can be programmed to reveal only the relevant information. For example, it could tell a device in a store that there is sufficient balance in an account to pay for a transaction without revealing the balance amount. The marriage between a convenient plastic card and a microprocessor allows information to be stored, accessed and processed either online or offline. Therefore, unlike the read-only plastic card, the processing power of Smart Cards gives them the versatility needed to make payments, to configure your cell phones, TVs and video players and to connect to your computers via telephone, satellite or the Internet anytime, anywhere in the world.
    [Show full text]
  • Effects of Automated Teller Machine on the Performance of Nigerian Banks
    American Journal of Applied Mathematics and Statistics, 2014, Vol. 2, No. 1, 40-46 Available online at http://pubs.sciepub.com/ajams/2/1/7 © Science and Education Publishing DOI:10.12691/ajams-2-1-7 Effects of Automated Teller Machine on the Performance of Nigerian Banks Jegede C.A.* Department of Accounting and finance, Lagos State University, Ojo, Nigeria *Corresponding author: [email protected] Received August 07, 2013; Revised August 24, 2013; Accepted February 07, 2014 Abstract This study investigates the effects of ATM on the performance of Nigerian banks. Available studies have concentrated on the significant dimensions of ATM (automated teller machine) service quality and its effect on customer satisfaction with a bias against ATM producers. The study is motivated by the astronomical challenges confronting the proliferation of ATM infrastructure and attendant financial losss to banks which are often under- reported. Also, there are serious debate on the relevance of ATM technology as most countries in the world are moving away from the virus technology to the more secured chip cards free of credit and debit frauds. Questionnaire was used to collect the data from a convenience sample of 125 employees of five selected banks in Lagos State with interswitch network. Therefore, data collected through the questionnaire were analyzed statistically by using the Software Package for Social Science (SPSS Version 20.0 for Student Version) and chi-square technique. The results indicate that less than the benefits, the deployment of ATMs terminals have averagely improved the performance of Nigerian banks because of the alarming rate of ATM fraud.
    [Show full text]
  • AUTOMATED TELLER MACHINE (Athl) NETWORK EVOLUTION in AMERICAN RETAIL BANKING: WHAT DRIVES IT?
    AUTOMATED TELLER MACHINE (AThl) NETWORK EVOLUTION IN AMERICAN RETAIL BANKING: WHAT DRIVES IT? Robert J. Kauffiiian Leollard N.Stern School of Busivless New 'r'osk Universit,y Re\\. %sk, Net.\' York 10003 Mary Beth Tlieisen J,eorr;~rd n'. Stcr~iSchool of B~~sincss New \'orl; University New York, NY 10006 C'e~~terfor Rcseai.clt 011 Irlfor~i~ntion Systclns lnfoornlation Systen~sI)epar%ment 1,eojrarcl K.Stelm Sclrool of' Busir~ess New York ITuiversity Working Paper Series STERN IS-91-2 Center for Digital Economy Research Stem School of Business Working Paper IS-91-02 Center for Digital Economy Research Stem School of Business IVorking Paper IS-91-02 AUTOMATED TELLER MACHINE (ATM) NETWORK EVOLUTION IN AMERICAN RETAIL BANKING: WHAT DRIVES IT? ABSTRACT The organization of automated teller machine (ATM) and electronic banking services in the United States has undergone significant structural changes in the past two or three years that raise questions about the long term prospects for the retail banking industry, the nature of network competition, ATM service pricing, and what role ATMs will play in the development of an interstate banking system. In this paper we investigate ways that banks use ATM services and membership in ATM networks as strategic marketing tools. We also examine how the changes in the size, number, and ownership of ATM networks (from banks or groups of banks to independent operators) have impacted the structure of ATM deployment in the retail banking industry. Finally, we consider how movement toward market saturation is changing how the public values electronic banking services, and what this means for bankers.
    [Show full text]