EMVCo Letter of Approval - Contact Terminal Level 2

Similar documents
EMVCo Letter of Approval - Terminal Level 2

EMVCo Letter of Approval - Contact Terminal Level 2

EMVCo Letter of Approval - Contact Terminal Level 2 - Renewal

EMVCo Letter of Approval - Contact Terminal Level 2

EMVCo Letter of Approval - Terminal Level 2

S-TUU a OS-TUU a

Re: EMVCo Letter of Approval - Contact Terminal Level 2

EMVS Kernel Capabilities

EMV Contactless Specifications for Payment Systems

EMV Contactless Specifications for Payment Systems

EMV2000 Integrated Circuit Card Specifications for Payment Systems

EMV Contactless Specifications for Payment Systems

CDA Modified Terminal Behaviour

EMV 96 Integrated Circuit Card Application Specification for Payment Systems

EMV ContactlessSpecifications for Payment Systems

PayPass M/Chip Application Note #17

PayPass M-TIP Test Case User Guide. July 2014

Acquirer JCB Dual Interface EMV Test Card Set

JR/T Translated English of Chinese Standard: JR/T

EMV Contactless Specifications for Payment Systems

Acquirer JCB EMV Test Card Set

Common Payment Application Contactless Extension CPACE. Functional Specification. Terminal Kernel

First Data U.S. Debit Test Card Set. Version 1.20

7. Best Practice. 7.1 Introduction. 7.2 Documentation. 7.3 Terminal Categories

Interac USA Interoperability EMV Test Card Set

First Data DCC Test Card Set. Version 1.30

First Data EMV Test Card Set. Version 1.30

First Data EMV Test Card Set. Version 2.00

EMV Integrated Circuit Card Specifications for Payment Systems

Common Payment Application Contactless Extension CPACE. Functional Specification. CPACE for Dual Interface Cards

EMV Integrated Circuit Card Specifications for Payment Systems

Visa paywave Implementation Overview and European Pilot Operating Principles Member Letter: VE 08/08 Type: General 16 April 2008

PayPass Testing Environment

First Data Dual Interface EMV Test Card Set. Version 1.20

PayPass M/Chip 4. Card Technical Specification

EMV Integrated Circuit Card Specifications for Payment Systems

UnionPay QuickPass Terminal Product Certification Rules

Chip Card Acceptance Device

Terminal Architecture for PSAM Applications (TAPA) Application Architecture Specification. Version 2.1. February 2001

M/Chip Advance V1.1 Personalization Guide

User Acceptance Test (UAT) ATM EMV Test Card Set Summary

Practical EMV PIN interception and fraud detection

AUTHORISATION AND SETTLEMENT TECHNICAL SPECIFICATIONS

MasterCard NFC Mobile Device Approval Guide v July 2015

USA Debit EMV Test Plan. Version 1.30

QR Code Specification for Payment Systems (EMV QRCPS)

Payment Card Industry (PCI) Data Security Standard

Q2. Why is there an Australian specific device approval process?

Payment Card Industry (PCI) PIN Transaction Security (PTS) Point of Interaction (POI) Modular Evaluation Vendor Questionnaire Version 3.

Security Requirements and Assessment Procedures for EMV 3-D Secure Core Components: ACS, DS, and 3DS Server

Payment Card Industry (PCI) Data Security Standard

Transaction Security. Mastercard M-TIP. Customer Guide. Oct 2016 v2.3

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) PIN Security. Requirements and Testing Procedures. Version 2.0. December 2014

EPC SEPA CARDS STANDARDISATION (SCS) VOLUME

Card Specification Amendment A March 2004

Presentation of the Interoperability specification for ICCs and Personal Computer Systems, Revision 2.0

CEPTEST Application Note

Payment Card Industry (PCI) Data Security Standard

MIFARE Security Evaluation Scheme

DynaPro Go. Secure PIN Entry Device PCI PTS POI Security Policy. September Document Number: D REGISTERED TO ISO 9001:2008

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

OSCAR POS INTEGRATION SPECIFICATION FOR SEPA COMPLIANT TERMINALS

Payment Card Industry (PCI) Data Security Standard

This document is a preview generated by EVS

Table of Contents. PCI Information Security Policy

Payment Card Industry (PCI) Data Security Standard

AMENDMENT FORM FOR AMERICAN EXPRESS CORPORATE GREEN CARD COMPANY CLIENTS POWER(S) OF ATTORNEY

SSL Certificates Certificate Policy (CP)

Clover Flex Security Policy

Payment Card Industry (PCI) Data Security Standard

Mobile MasterCard. PayPass User Interface Application Design Guide. User Experience, Use Cases, Screen Layouts and Design. Version 1.

Payment Card Industry (PCI) Data Security Standard

Creating your own payment card Joost Kremers MSc CEH

Payment Card Industry (PCI) Data Security Standard

PCI PA DSS. PBMUECR Implementation Guide

Payment Card Industry (PCI) Data Security Standard

SELF-CERTIFICATION USING THE UL STP

Software-Based PIN Entry on COTS. Jeremy King International Director PCI Security Standards Council

Payment Card Industry (PCI) Data Security Standard

Google Cloud Platform: Customer Responsibility Matrix. April 2017

IT Security Evaluation and Certification Scheme Document

Data Security Standard

Visa Chip Security Program Security Testing Process

ACOS 10 B/G PBOC 2.0 EDEP Card

Payment Card Industry (PCI) PIN Transaction Security (PTS) Hardware Security Module (HSM) Evaluation Vendor Questionnaire Version 2.

Version 2.3 March 2, WisePad 2 Security Policy

Payment Card Industry (PCI) PIN Transaction Security (PTS) Point of Interaction (POI) Modular Evaluation Vendor Questionnaire Version 4.

CB TEST PRODUCTS & SERVICES CATALOGUE

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

OSCAR POS INTEGRATION SPECIFICATION FOR SEPA COMPLIANT TERMINALS

CIPURSE V2 Certification Program

DPS SKP200 / SCR200 Common Criteria Security Target Lite

Google Cloud Platform: Customer Responsibility Matrix. December 2018

Payment Card Industry (PCI) Data Security Standard

American Express Online PIN & PIN Security Requirements

PA-DSS Implementation Guide for Sage MAS 90 and 200 ERP. and Sage MAS 90 and 200 Extended Enterprise Suite

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Transcription:

July 01, 2015 Kyoungtae Kang AIONBANK, Inc. Unit 502, Small and Medium Business DMC Tower, 189 Seongam-ro, Mapo-gu Seoul 121-904 S.KOREA Re: EMV Application Kernel: Approval Number(s): EMVCo Letter of Approval - Contact Terminal Level 2 AIONEMV Version 1.00 2-03209-1-1S-CEM-0715-4.3.d 2-03209-1-1OS-CEM-0715-4.3.d The EMV Application Kernel has been tested on the following terminal Terminal: A700 PinPad: n/a Operating System: 1OS = FreeRTOS Version 7.2.0 Renewal Date: 30-Jun-2018 Report ID Session 1: 2_AINO_K6080_15_02_CEM - CETECOM Limited Kernel Checksum: 252F22FB05D01807F4BC6D0BB1E9DDF30AFF5F49 Configuration Checksum: Config Vendor Config ID Terminal Checksum 1S 21 1E1D9FE795CB21EA40531DDE082D91D9A23D96A6 Page 1 of 6

Dear Kyoungtae Kang: EMVCo, LLC ("EMVCo"), a Delaware limited liability company, has received your request for Level 2 terminal type approval for the EMV Application Kernel identified above (hereafter refered to as the "Application"). In connection with your request, we have reviewed all test file number(s) listed above. After assessing such file(s), EMVCo has found reasonable evidence that the submitted samples of the above referenced Application sufficiently conform to EMV Integrated Circuit Card Specifications for Payment Systems, Version 4.3 of vember 2011. EMVCo hereby grants your Application EMVCo Type Approval for Terminal Level 2, based on the requirements stated in the EMV 4.3 Specifications. Please note that EMVCo may publish this letter and publicly identify your Application as an approved Application, including in EMVCo's published list of approved Applications. EMVCo's grant to your Application is subject to and specifically incorporates (i) the General Terms and Conditions to the Letter of Approval enclosed as Exhibit A, and (ii) the Specific Terms and Conditions to the Letter of Approval attached hereto as Attachment 1. Because EMVCo's grant is subject to such limitations, including certain events of termination, you and any third parties should confirm that such approval is current and has not been terminated by referring to the list of approved Applications published on the EMVCo website (www.emvco.com). Please note that EMVCo makes certain logos available for use in connection with an Application that has received EMVCo approval. To obtain permission to use the "EMV Approved" certification mark, please contact EMVCo to request a license agreement. AIONBANK, Inc. This Letter of Approval is valid while the approval number is posted on the EMVCo website. EMVCo, LLC, a Delaware limited liability company By: Name: Title: Arnaud du Chéné EMVCo Terminal Type Approval Page 2 of 6

Terminal Capabilities Card Data Input Capability Manual Key Entry Magnetic Stripe IC with Contacts CVM Capability Plaintext PIN for ICC Verification Enciphered PIN for online Verification Signature (Paper) Enciphered PIN for offline Verification CVM Required Security Capability Static Data Authentication and Dynamic Data Authentication Card Capture Combined Dynamic Data Authentication / Application Cryptogram Generation Transaction Type Capability Cash Goods Services Cash Back Inquiry Transfer Payment Administrative Cash Deposit Terminal Data Input Capability Does terminal have keypad Numeric Keys Alphabetic and Special Character Keys Command Keys Function Keys Terminal Data Output Capability Print, Attendant (Mandatory for terminals supporting signature) Print, Cardholder Display, Attendant (Mandatory for Attended terminals) Display Cardholder Code Table 10 Code Table 9 Code Table 8 Code Table 7 Code Table 6 Code Table 5 Code Table 4 Code Table 3 Code Table 2 Code Table 1 Value Supported Page 3 of 6

Terminal Capabilities Application Selection Support PSE selection Method Support Cardholder Confirmation Does Terminal have a preferred order of displaying applications Does terminal perfom partial AID selection Does the terminal have multi language support Does the terminal support the EMV Language Selection method Does the terminal support the Common Character Set as defined in Annex B table 20 Book 4 Selectable Kernel Configurations Is your Multi-Configuration Kernel capable of dynamically selecting a configuration at the time of transaction Data Authentication What is the maximun supported Certificate Authority Public Key Size (Mandatory for terminals supporting Data Authentication with minimal support for 248 bytes) What exponents does the terminal support (Mandatory for terminals supporting Data Authentication, 3 and 2^16+1) During data authentication does the terminal check validity for revocation of Issuer Public Key Certificate When supporting certificate revocation, what is the Certificate Revocation List format? Does the terminal contain a default DDOL (Mandatory for terminals supporting DDA) Is operator action required when loading CA Public Key fails CA Public Key verified with CA Public Key Check Sum Cardholder Verification Method Terminal supports bypass PIN Entry Terminal supports Subsequent bypass PIN Entry Terminal supports Get Data for PIN Try Counter Terminal supports Fail CVM Are amounts known before CVM processing Terminal Risk Management Floor Limit Checking (Mandatory for offline only terminals and offline terminals with online capability) Random Transaction Selection (Mandatory for offline terminals with online capability, except when cardholder controlled) Velocity Checking (Mandatory for offline only terminals and offline terminals with online capability) Transaction Log Exception File Performance of Terminal Risk Management irrespective of AIP setting (expected behavior) Value Supported N/A Page 4 of 6

Terminal Capabilities Terminal Action Analysis Does the terminal support Terminal Action Codes Can the values of the Terminal Action Codes be changed Can the Terminal Action Codes be deleted or disabled? If yes what are the default TAC values supported? (according to Book 3 Section 10.7) How does Offline Only Terminal process Default Action Codes prior to First Generate AC? (Offline Only Terminal shall support one option) How does online only terminal process TAC/IAC-Default when unable to go online? (Online Only Terminal shall support one option) Completion Processing Transaction Forced Online Capability Transaction Forced Acceptance Capability Does terminal Support advices Does the terminal support Issuer initiated Voice Referrals Does the terminal support Batch Data Capture Does the terminal support Online Data Capture Does the terminal support a Default TDOL Exception Handling What is the POS Entry Mode value when IC cannot be read and the transaction falls back using Magstripe (Mandatory for attended terminals) Miscellaneous Is the terminal equipped with a PIN Pad Is the amount and PIN entered at the same keypad Is the ICC/Magstripe Reader combined If Combined ICC/Magstripe reader is supported, is Magstripe read first Does the terminal support account type selection Does the terminal support 'on fly' script processing (not recommended behavior) Is the Issuer Script device limit greater than 128 bytes If the Issuer Script device limit is greater than 128 bytes, what is the value supported Does the terminal support Internal Date Management TAC Denial: TAC Online: TAC Default: Is the Level 2 Contact Kernel Random Generator using the algorithm described in SB144 If the Level 2 Contact Kernel Random Generator is not using the algorithm described in SB144, is this function PCI approved If the Level 2 Contact Kernel Random Generator is not using the algorithm described in SB144, describe the function (such as algorithm used, etc) Is the Level 2 Contact Kernel Software dependent on the Terminal Hardware If answer to previous question is, describe the function and the Hardware Are the Cryptographic functions (RSA, Hash, etc) of the Level 2 Contact Kernel Software dependent on the Terminal Hardware If answer to previous question is, describe the Hardware Is any other functions of the Level 2 Contact Kernel Software dependent on the Terminal Hardware If answer to previous question is, describe the functions and the Hardware Checksum Does the product comply with the Checksum rules as defined in Contact Terminal Level 2 administrative process This is an Initial submission or Subsequent submission or renewal of the original approved product prior to the effective date of checksum rules (cf Terminal Type Approval Bulletin. 134) Configuration Checksum (Static Kernel only) Value Supported Skip TAC/IAC and automatically request AAC 02 n/a 1E1D9FE795CB21EA40531DDE082D91D9A23D 96A6 Page 5 of 6

Attachment 1 Specific Terms and Conditions to the Letter of Approval Restriction: ne Page 6 of 6