Implementing Electronic Card Payment Systems (Artech House Computer Security Series)

4.1 Organization of the EMV ¢ specifications

This section presents the set of documents (Book 1 to Book 4) that form the specification known as the EMV 2000 ”Integrated Circuit Card Specification for Payment Systems [1 “4]. This set of documents replaces the set of documents referred to as the EMV'96 ”Integrated Circuit Card (Terminal, Application) Specification for Payment Systems [5 “7]. The EMV'96 was effective until December 2000 and served as the technical reference for implementations performed before this date. For the reader who is already familiar with the documents comprising the EMV'96 , we provide a mapping of their content into the new set of documents that form the EMV 2000 .

For a better understanding of the documents composing the EMV 2000 specification, the reader is referred to Figure 4.1. In this figure we outline the generic EMV ¢ communication protocol stack, which describes the interaction between the ICC and the terminal and between the terminal and the AH. We also show the user interfaces of the terminal towards the cardholder and the attendant.

Figure 4.1: The EMV ¢ protocol stack and its mapping to EMV 2000 .

The EMV 2000 consists of the following documents:

Book 1: Application Independent ICC to Terminal Interface Requirements [1]. This document is divided into two parts :

Book 2: Security and Key Management [2]. This document presents a detailed specification of the security mechanisms in the ICC and terminal:

The topics mentioned above are reconsidered from "Part IV ”Security Aspects" of the EMV'96 ”Integrated Circuit Card Specification for Payment Systems [5].

Certification Authority Public Key Management Principles and Policies is a new topic introduced in EMV 2000, Book 2 . The topic Terminal Security and Key Management Requirements can also be considered as newly introduced in EMV 2000, Book 2 . We make this statement since the terminal security was just briefly mentioned in "Section 4 ”Security Requirements", in Part I ”General Requirements of the EMV'96 ”Integrated Circuit Card Terminal Specification for Payment Systems [6].

Book 3: Application Specification [3] This document is divided into two parts:

Book 4: Cardholder, Attendant, and Acquirer Interface Requirements [4] This document reconsiders the content of the EMV ¢ '96 ”Integrated Circuit Card Terminal Specification for Payment Systems [6]. It is divided into three parts:

Категории