Emvco Security Evaluation Process V5.1 Page 2 / 38
Total Page:16
File Type:pdf, Size:1020Kb
EMV® Security Guidelines EMVCo Security Evaluation Process Version 5.1 June 2016 © 2016 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo found at www.emvco.com . EMV ® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries. EMV Security Guidelines EMVCo Security Evaluation Process v5.1 Page 2 / 38 Legal Notice The EMV ® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON- INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV Specifications. © 2016 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo found at www.emvco.com . EMV ® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries. EMV Security Guidelines EMVCo Security Evaluation Process v5.1 Page 3 / 38 Version History Version Date Description v4.0 December 2010 Introduction of the Platform security evaluation process. v5.0 March 2015 This release clarifies the product renewal policy terms, and provides additional details on the initial and renewal registration, evaluation, and certification process. v5.1 June 2016 This release references the product certification policy and introduces the terms of the expired product extension process. It provides additional details on the certification process. © 2016 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo found at www.emvco.com . EMV ® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries. EMV Security Guidelines EMVCo Security Evaluation Process v5.1 Page 4 / 38 Contents 1 Scope ............................................................................................................................. 7 1.1 Audience ................................................................................................................ 7 1.2 Overview ................................................................................................................ 8 1.3 Related Information ................................................................................................ 8 1.4 Support ................................................................................................................. 10 2 Overview ...................................................................................................................... 11 2.1 Background .......................................................................................................... 11 2.2 EMVCo Security Evaluation .................................................................................. 12 2.2.1 The Role of EMVCo in the Security Evaluation Process ............................ 12 2.2.2 Development and Production Site Audit .................................................... 13 2.2.3 IC Security Evaluation ............................................................................... 13 2.2.4 Platform Security Evaluation ..................................................................... 14 2.2.5 ICC Security Evaluation ............................................................................ 15 2.3 Security Assurance............................................................................................... 16 2.4 Risk Management ................................................................................................ 18 2.5 Changes to Previously Approved Products ........................................................... 19 2.6 EMVCo Approval Renewal Date ........................................................................... 19 3 Security Evaluation Process ...................................................................................... 20 3.1 Security Evaluation Roles and Responsibilities .................................................... 21 3.1.1 Maintain Security Guidelines ..................................................................... 21 3.1.2 Design Product ......................................................................................... 21 3.1.3 Test Product ............................................................................................. 21 3.1.4 Certify Product .......................................................................................... 21 3.1.5 Security Monitoring ................................................................................... 22 3.2 Compliance Certificates ........................................................................................ 23 3.2.1 Certifiable Products ................................................................................... 23 3.2.2 Types of Certificates ................................................................................. 23 3.3 Security Evaluation Process ................................................................................. 24 3.3.1 Sign EMVCo Agreement ........................................................................... 25 3.3.2 Complete EMVCo Registration Questionnaire .......................................... 25 3.3.3 Initial Discussion ....................................................................................... 25 3.3.4 Product Design ......................................................................................... 25 3.3.5 Select Laboratory and Decide Evaluation Details ...................................... 26 3.3.6 Assess Product and Product Provider Infrastructure ................................. 26 3.3.7 Submit Reports to EMVCo Security Evaluation Secretariat ....................... 28 3.3.8 Validate Laboratory Evaluation Reports .................................................... 28 © 2016 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo found at www.emvco.com . EMV ® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries. EMV Security Guidelines EMVCo Security Evaluation Process v5.1 Page 5 / 38 3.3.9 Risk Analysis ............................................................................................ 29 3.3.10 Issue EMVCo Compliance Certificate ....................................................... 30 3.4 Certificate Renewal Process ................................................................................. 31 3.4.1 Send EMVCo Renewal Registration Questionnaire ................................... 31 3.4.2 Perform Renewal Evaluation with Laboratory ............................................ 31 3.4.3 Renew Product Certificate ........................................................................ 31 3.5 Certificate Update Process ................................................................................... 32 3.5.1 Send EMVCo Update Registration Questionnaire ..................................... 32 3.5.2 Perform Delta Evaluation with Laboratory ................................................. 32 3.5.3 Update Product Certificate ........................................................................ 32 3.6 Expired Product Extension Process ...................................................................... 33 3.6.1 Send EMVCo Extension Registration Questionnaire ................................. 33 3.6.2 Perform Extension Evaluation with Laboratory .......................................... 33 3.6.3 Extension Recognition Letter .................................................................... 33 Annex A Glossary .......................................................................................................... 34 © 2016 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo found at www.emvco.com . EMV ® is a registered trademark or trademark of EMVCo, LLC in the United States