Jump to content

EMV: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
No edit summary
Rescuing 3 sources, flagging 0 as dead, and archiving 44 sources. (Peachy 2.0 (alpha 8))
Line 200: Line 200:
Conversation capturing is the form of attack that was reported to have taken place against [[Royal Dutch Shell|Shell]] terminals in May 2006, when they were forced to disable all EMV authentication in their [[filling station]]s after more than £1 million was stolen from customers.<ref>{{cite news |url=http://news.bbc.co.uk/2/hi/uk_news/england/4980190.stm |title=Petrol firm suspends chip-and-pin |publisher=BBC News |date=6 May 2006 |accessdate=13 March 2015}}</ref>
Conversation capturing is the form of attack that was reported to have taken place against [[Royal Dutch Shell|Shell]] terminals in May 2006, when they were forced to disable all EMV authentication in their [[filling station]]s after more than £1 million was stolen from customers.<ref>{{cite news |url=http://news.bbc.co.uk/2/hi/uk_news/england/4980190.stm |title=Petrol firm suspends chip-and-pin |publisher=BBC News |date=6 May 2006 |accessdate=13 March 2015}}</ref>


In October 2008 it was reported that hundreds of EMV card readers for use in Britain, Ireland, the Netherlands, Denmark, and Belgium had been expertly tampered with in China during or shortly after manufacture so that details and PINs of credit and debit cards were sent during the 9 months before over [[mobile phone]] networks to criminals in [[Lahore]], Pakistan. United States National Counterintelligence Executive Joel Brenner said, "Previously only a [[nation state]]'s [[intelligence agency]] would have been capable of pulling off this type of operation. It's scary." Data were typically used a couple of months after the card transactions to make it harder for investigators to pin down the vulnerability. After the fraud was discovered it was found that tampered-with terminals could be identified as the additional circuitry increased their weight by about 100&nbsp;g. Tens of millions of pounds sterling are believed to have been stolen.<ref>{{cite news |title=Organized crime tampers with European card swipe devices |publisher=The Register |date=10 October 2008 |url=http://www.theregister.co.uk/2008/10/10/organized_crime_doctors_chip_and_pin_machines/}}</ref> This vulnerability spurred efforts to implement better control of electronic POS devices over their entire life cycle, a practice endorsed by electronic payment security standards like those being developed by the Secure POS Vendor Alliance (SPVA).<ref>{{cite web |title=Technical Working Groups, Secure POS Vendor Alliance |year=2009 |url=http://www.spva.org/technicalWorking.aspx/}}{{dead link |date=May 2015}}</ref>
In October 2008 it was reported that hundreds of EMV card readers for use in Britain, Ireland, the Netherlands, Denmark, and Belgium had been expertly tampered with in China during or shortly after manufacture so that details and PINs of credit and debit cards were sent during the 9 months before over [[mobile phone]] networks to criminals in [[Lahore]], Pakistan. United States National Counterintelligence Executive Joel Brenner said, "Previously only a [[nation state]]'s [[intelligence agency]] would have been capable of pulling off this type of operation. It's scary." Data were typically used a couple of months after the card transactions to make it harder for investigators to pin down the vulnerability. After the fraud was discovered it was found that tampered-with terminals could be identified as the additional circuitry increased their weight by about 100&nbsp;g. Tens of millions of pounds sterling are believed to have been stolen.<ref>{{cite news |title=Organized crime tampers with European card swipe devices |publisher=The Register |date=10 October 2008 |url=http://www.theregister.co.uk/2008/10/10/organized_crime_doctors_chip_and_pin_machines/}}</ref> This vulnerability spurred efforts to implement better control of electronic POS devices over their entire life cycle, a practice endorsed by electronic payment security standards like those being developed by the Secure POS Vendor Alliance (SPVA).<ref>{{cite web|title=Technical Working Groups, Secure POS Vendor Alliance |year=2009 |url=http://www.spva.org/technicalWorking.aspx/ |deadurl=yes |archiveurl=https://web.archive.org/20100415180123/http://www.spva.org:80/technicalWorking.aspx |archivedate=15 April 2010 }}</ref>


==== Demonstration of PIN harvesting and stripe cloning ====
==== Demonstration of PIN harvesting and stripe cloning ====
Line 239: Line 239:


===Africa===
===Africa===
*MasterCard's liability shift among countries within this region took place on 1 January 2006.<ref name="Chargeback Guide">{{cite web |url=http://www.mastercard.com/ca/merchant/fr/getstarted/support/Chargeback_manual.pdf |title=Chargeback Guide |date=3 November 2010 |publisher=MasterCard Worldwide |accessdate=May 10, 2015}}</ref> By 1 October 2010, a liability shift had occurred for all point of sale transactions.<ref name="corporate.visa.com">{{cite web |url=http://corporate.visa.com/_media/visa-international-operating-regulations.pdf |publisher=Visa International |title=Operating Regulations}}{{dead link|date=May 2015}}</ref>
*MasterCard's liability shift among countries within this region took place on 1 January 2006.<ref name="Chargeback Guide">{{cite web |url=http://www.mastercard.com/ca/merchant/fr/getstarted/support/Chargeback_manual.pdf |title=Chargeback Guide |date=3 November 2010 |publisher=MasterCard Worldwide |accessdate=May 10, 2015}}</ref> By 1 October 2010, a liability shift had occurred for all point of sale transactions.<ref name="corporate.visa.com">{{cite web|url=http://corporate.visa.com/_media/visa-international-operating-regulations.pdf |publisher=Visa International |title=Operating Regulations |deadurl=yes |archiveurl=https://web.archive.org/20130303213731/http://corporate.visa.com/_media/visa-international-operating-regulations.pdf |archivedate=3 March 2013 }}</ref>
*Visa's liability shift for points of sale took place on 1 January 2006. For ATMs, the liability shift took place on 1 January 2008.<ref name="The Journey To Dynamic Data">{{cite web |url=http://www.visa-asia.com/securitysummits2011/pdf/dubai/Case_Study_Europes_Journey_to_Dynamic_Data_VDias.pdf |title=The Journey To Dynamic Data |publisher=Visa}}{{dead link|date=May 2015}}</ref>
*Visa's liability shift for points of sale took place on 1 January 2006. For ATMs, the liability shift took place on 1 January 2008.<ref name="The Journey To Dynamic Data">{{cite web |url=http://www.visa-asia.com/securitysummits2011/pdf/dubai/Case_Study_Europes_Journey_to_Dynamic_Data_VDias.pdf |title=The Journey To Dynamic Data |publisher=Visa}}{{dead link|date=May 2015}}</ref>


Line 254: Line 254:


===Canada===
===Canada===
*American Express implemented a liability shift on 31 October 2012.<ref name="Chip Liability Shift">{{cite web |url=https://www.globalpaymentsinc.com/Canada/customerSupport/industryInit/chip_shift.html |title=Chip Liability Shift |publisher=globalpayments}}{{dead link|date=May 2015}}</ref>
*American Express implemented a liability shift on 31 October 2012.<ref name="Chip Liability Shift">{{cite web|url=https://www.globalpaymentsinc.com/Canada/customerSupport/industryInit/chip_shift.html |title=Chip Liability Shift |publisher=globalpayments |deadurl=yes |archiveurl=https://web.archive.org/20130730014206/http://www.globalpaymentsinc.com:80/Canada/customerSupport/industryInit/chip_shift.html |archivedate=30 July 2013 }}</ref>
*Discover implemented a liability shift on 1 October 2015. For pay at the pump at gas stations, the liability shift is 1 October 2017.<ref name="finextra.com">{{cite press release |date=12 November 2012 |url=http://www.finextra.com/news/announcement.aspx?pressreleaseid=47300 |title=Discover to enforce EMV liability shift by 2015 |publisher=Finextra Research |accessdate=10 May 2015}}</ref>
*Discover implemented a liability shift on 1 October 2015. For pay at the pump at gas stations, the liability shift is 1 October 2017.<ref name="finextra.com">{{cite press release |date=12 November 2012 |url=http://www.finextra.com/news/announcement.aspx?pressreleaseid=47300 |title=Discover to enforce EMV liability shift by 2015 |publisher=Finextra Research |accessdate=10 May 2015}}</ref>
*Interac (Canada's debit card network) stopped processing non-EMV transactions at ATMs on 31 December 2012, and will no longer process non-EMV transactions at point of sale terminals on 31 December 2015.<ref name="Chip Liability Shift"/>
*Interac (Canada's debit card network) stopped processing non-EMV transactions at ATMs on 31 December 2012, and will no longer process non-EMV transactions at point of sale terminals on 31 December 2015.<ref name="Chip Liability Shift"/>

Revision as of 07:49, 19 October 2015

A credit card issued by Japan Airlines and Visa, showing the square, gold-colored chip used by EMV cards.

EMV is a technical standard for smart payment cards and for payment terminals and automated teller machines that can accept them. EMV cards are smart cards (also called chip cards or IC cards) which store their data on integrated circuits rather than magnetic stripes, although many EMV cards also have stripes for backward compatibility. They can be contact cards that must be physically inserted (or "dipped") into a reader, or contactless cards that can be read over a short distance using radio-frequency identification technology. Payment cards that comply with the EMV standard are often called chip-and-PIN or chip-and-signature cards, depending on the exact authentication methods required to use them.

EMV stands for Europay, MasterCard, and Visa, the three companies that originally created the standard. The standard is now managed by EMVCo, a consortium with control split equally among Visa, Mastercard, JCB, American Express, China UnionPay, and Discover.[1]

There are standards based on ISO/IEC 7816 for contact cards, and standards based on ISO/IEC 14443 for contactless cards (PayPass, PayWave, ExpressPay).

The most widely known chip card implementations of EMV standard are:

  • VIS – Visa
  • M/Chip – MasterCard
  • AEIPS – American Express
  • UICS - China Union Pay
  • J Smart – JCB
  • D-PAS – Discover/Diners Club International.

Visa and MasterCard have also developed standards for using EMV cards in devices to support card not present transactions over the telephone and Internet. MasterCard has the Chip Authentication Program (CAP) for secure e-commerce. Its implementation is known as EMV-CAP and supports a number of modes. Visa has the Dynamic Passcode Authentication (DPA) scheme, which is their implementation of CAP using different default values.

In February 2010, computer scientists from Cambridge University demonstrated that an implementation of EMV PIN entry is vulnerable to a man-in-the-middle attack; however, the way PINs are processed depends on the capabilities of the card and the terminal.

History

Until the introduction of chip and PIN, all face-to-face credit or Debit card transactions used a magnetic stripe or mechanical imprint to read and record account data, and a signature for verification. Under that system, the customer hands their card to the clerk at the point of sale, who either "swipes" the card through a magnetic reader or makes an imprint from the raised text of the card. In the former case, the system verifies account details and prints a slip for the customer to sign. In the case of a mechanical imprint, the transaction details are filled in and the customer signs the imprinted slip. In either case, the clerk verifies that the customer's signature matches that on the back of the card to authenticate the transaction. (The signature is not intended for having clerks attempt to match handwriting, although widely seen as the reason for the signature. A signed card indicates the signatory agrees to abide by all terms with the credit card issuer, although It is acceptable to have an unsigned card signed by the owner right before a transaction. The signature on the printed slip is agreement to pay the posted charges as printed.)

This system has a number of security flaws, including the ability to steal a card in the post,[citation needed] or to learn to forge the signature on the card. More recently,[clarification needed] technology has become available on the black market for both reading and writing the magnetic stripes, making cards easy to clone and use without the owner's knowledge.

The first standard for smart payment cards was the Carte Bancaire M4 from Bull-CP8 deployed in France in 1986, followed by the B4B0' (compatible with the M4) deployed in 1989. Geldkarte in Germany also predates EMV. EMV was designed to allow cards and terminals to be backwardly compatible with these standards. France has since migrated all its card and terminal infrastructure to EMV.

The EMV standard was initially written in 1993 and 1994.[2] JCB joined the consortium in February 2009, China UnionPay in May 2013,[3] and Discover in September 2013.[4]

Differences and benefits of EMV

There are two major benefits to moving to smart-card-based credit card payment systems: improved security (with associated fraud reduction), and the possibility for finer control of "offline" credit-card transaction approvals. One of the original goals of EMV was to allow for multiple applications to be held on a card: for a credit and debit card application or an e-purse. With current processing regulations in the United States, new issue debit cards contain two applications — a card association (Visa, MasterCard etc.) application, and a common debit application. The common debit application ID is somewhat of a misnomer as each "common" debit application actually uses the resident card association application.

EMV chip card transactions improve security against fraud compared to magnetic stripe card transactions that rely on the holder's signature and visual inspection of the card to check for features such as hologram. The use of a PIN and cryptographic algorithms such as Triple DES, RSA and SHA provide authentication of the card to the processing terminal and the card issuer's host system. The processing time is comparable to online transactions, in which communications delay accounts for the majority of the time, while cryptographic operations take comparatively little time. The supposed increased protection from fraud has allowed banks and credit card issuers to push through a "liability shift" such that merchants are now liable (as of 1 January 2005 in the EU region) for any fraud that results from transactions on systems that are not EMV capable.[5]

Although not the only possible method, the majority of implementations of EMV cards and terminals confirm the identity of the cardholder by requiring the entry of a personal identification number (PIN) rather than signing a paper receipt. Whether or not PIN authentication takes place depends upon the capabilities of the terminal and programming of the card. For more details of this (specifically, the system being implemented in the UK) see Chip and PIN, below.

Under the old system, a customer typically had to hand their card to a sales clerk to pay for a transaction. When credit cards were first introduced, merchants used mechanical (rather than magnetic) offline portable card imprinters, sometimes referred to as "knucklebusters." They did not connect to the card issuer, and the card never left the customer's sight. The merchant had to verify transactions over a certain limit by telephoning the card issuer.

Later, equipment electronically contacted the card issuer, using information from the magnetic stripe to verify the card and authorise the transaction. This was much faster, but had to be in a fixed location. Consequently, if the transaction did not take place near a terminal (in a restaurant, for example) the clerk or waiter had to take the card away from the customer to the card machine. It was easily possible at any time for a dishonest employee to swipe the card surreptitiously through a cheap machine that instantly recorded the information on the card and stripe; in fact, even at the terminal, the criminal could bend down in front of the customer and swipe the card on a hidden reader. This made illegal cloning of cards easy, and a common occurrence.

Since the introduction of chip and PIN, cloning of the chip is not feasible; only the magnetic stripe can be copied, and a copied card cannot be used on a PIN terminal. The introduction of chip and PIN coincided with wireless data transmission technology becoming inexpensive and widespread. Merchant personnel can now bring wireless PIN pads to the customer, so the card is never out of the cardholder's sight. (This would have been possible with magnetic stripe cards had the technology been available.) Chip and PIN and wireless together reduce the risk of cloning of cards by surreptitious swiping.

Chip and PIN versus chip and signature

As of 2015, chip and signature cards are more common in the United States, Mexico, the Philippines and some European countries (such as Germany and Austria), whereas chip and PIN cards are more common in other European countries (e.g., the UK, Ireland, France, Finland and the Netherlands) as well as in Canada, Australia and New Zealand.[6]

Online, phone, and mail order transactions

While EMV technology has helped reduce crime at the point of sale, fraudulent transactions have shifted to more vulnerable telephone, Internet, and mail order transactions — known in the industry as card-not-present or CNP transactions. as of May 2009 CNP transactions made up more than 50% of all credit card fraud.[7] Because of physical distance, it is not possible for the merchant to present a keypad to the customer in these cases, so alternatives have been devised, including:

  • Software approaches for online transactions that involve interaction with the card-issuing bank or network's web site, such as Verified by Visa and MasterCard SecureCode (implementations of Visa's 3-D Secure protocol).
  • Additional hardware with keypad and screen that can produce a one-time password, such as the Chip Authentication Program.
  • Keypad and screen integrated into the card to produce a one-time password. Since 2008, VISA has been running pilot projects using the Emue card,[8] where the generated number replaces the code printed on the back of standard cards.[9]

Commands

ISO/IEC 7816-3 defines the transmission protocol between chip cards and readers. Using this protocol, data is exchanged in application protocol data units (APDUs). This comprises sending a command to a card, the card processing it, and sending a response. EMV uses the following commands:

  • application block
  • application unblock
  • card block
  • external authenticate (7816-4)
  • generate application cryptogram
  • get data (7816-4)
  • get processing options
  • internal authenticate (7816-4)
  • PIN change / unblock
  • read record (7816-4)
  • select (7816-4)
  • verify (7816-4).

Commands followed by "7816-4" are defined in ISO/IEC 7816-4 and are interindustry commands used for many chip card applications such as GSM SIM cards.

Transaction flow

An EMV transaction has the following steps:[10]

Application selection

ISO/IEC 7816 defines a process for application selection. The intent of application selection was to allow cards to contain completely different applications, for example GSM and EMV. EMV however took application selection to be a way of identifying the type of product, so that all product issuers (Visa, MasterCard, etc.) have to have their own application. The way application selection as prescribed in EMV is a frequent source of interoperability problems between cards and terminals. Book 1 of the EMV standard devotes 15 pages to describing the application selection process.

An application identifier (AID) is used to address an application in the card. An AID consists of a registered application provider identifier (RID) of five bytes, which is issued by the ISO/IEC 7816-5 registration authority. This is followed by a proprietary application identifier extension (PIX), which enables the application provider to differentiate among the different applications offered. The AID is printed on all EMV cardholder receipts.

Initiate application processing

The terminal sends the get processing options command to the card. When issuing this command, the terminal supplies the card with any data elements requested by the card in the processing options data objects list (PDOL). The PDOL (a list of tags and lengths of data elements) is optionally provided by the card to the terminal during application selection. The card responds with the application interchange profile (AIP), a list of functions to be performed in processing the transaction. The card also provides the application file locator (AFL), a list of files and records that the terminal needs to read from the card.

Read application data

Smart cards store data in files. The AFL contains the files that contain EMV data. These all need to be read using the read record command. EMV does not specify which files data is stored in, so all the files need to be read. Data in these files is stored in BER TLV format. EMV defines tag values for all data used in card processing.

Processing restrictions

The purpose of the processing restrictions is to see if the card should be used. Three data elements read in the previous step are checked.

  • Application version number
  • Application usage control (This shows whether the card is only for domestic use, etc.)
  • Application effective/expiration dates checking.

If any of these checks fails, the card is not necessarily declined. The terminal sets the appropriate bit in the terminal verification results (TVR), the components of which form the basis of an accept/decline decision later in the transaction flow. This feature allows, for example, card issuers to permit their cardholders to continue to use expired cards after their expiry date, but for all transactions made with an expired card to be performed on-line.

Offline data authentication

Offline data authentication is a cryptographic check to validate the card using public-key cryptography. There are three different processes that can be undertaken depending on the card:

  • Static data authentication (SDA) ensures data read from the card has been signed by the card issuer. This prevents modification of data, but does not prevent cloning.
  • Dynamic data authentication (DDA) provides protection against modification of data and cloning.
  • Combined DDA/generate application cryptogram (CDA) combines DDA with the generation of a card's application cryptogram to assure card validity. Support of CDA in devices may be needed, as this process has been implemented in specific markets. This process is not mandatory in terminals and can only be carried out where both card and terminal support it.

Cardholder verification

Cardholder verification is used to evaluate whether the person presenting the card is the legitimate cardholder. There are many cardholder verification methods (CVMs) supported in EMV. They are:

  • Signature
  • Offline plaintext PIN
  • Offline enciphered PIN
  • Offline plaintext PIN and signature
  • Offline enciphered PIN and signature
  • Online PIN
  • No CVM required
  • Fail CVM processing.

The terminal uses a CVM list read from the card to determine the type of verification to be performed. The CVM list establishes a priority of CVMs to be used relative to the capabilities of the terminal. Different terminals support different CVMs. ATMs generally support online PIN. POS terminals vary in their support of CVM depending on their type and in which country they are located.

Chip and PIN vs. chip and signature

According to issuer preference, some EMV cards are "chip and PIN" cards that require the customer to supply a four-to-six-digit personal identification number (PIN) when making a purchase at PIN-capable terminals. The chips in these cards feature "PIN" ranked first in the list of possible cardholder verification methods (CVM), but with signature allowed as a fall-back option (or PIN verification at unattended terminals).

Other EMV cards are either signature-only or prefer signature over PIN in their CVM list (i.e., signature at the POS, but PIN at unattended terminals or ATMs). These are often called "chip and signature" cards.[11]

Signature-only cards will not work at points of sale that allow no CVM other than PIN, such as some unattended ticket kiosks in Europe,[11] whereas signature-preferring cards might work. Attended POS, which are staffed by merchant personnel, are required by the credit card agreement to accept magnetic stripe cards as well as chip and signature cards.[11] Chip and PIN cards have not been adopted in the United States as of October 2015 for a variety of reasons, including lack of PIN management features in ATMs.[11]

Terminal risk management

Terminal risk management is only performed in devices where there is a decision to be made whether a transaction should be authorised on-line or offline. If transactions are always carried out on-line (e.g., ATMs) or always off-line, this step can be missed. Terminal risk management checks the transaction amount against an offline ceiling limit (above which transactions should be processed on-line). It is also possible to have a 1 in an online counter, and a check against a hot card list (which is only necessary for off-line transactions). If the result of any of these tests is positive, the terminal sets the appropriate bit in the terminal verification results (TVR).

Terminal action analysis

The results of previous processing steps are used to determine whether a transaction should be approved offline, sent online for authorization, or declined offline. This is done using a combination of Terminal action codes (TACs) held in the terminal and Issuer action codes (IACs) read from the card.

An online-only device such as an ATM always attempts to go on-line with the authorization request, unless declined off-line due to Issuer action codes—Denial settings. During IAC—Denial and TAC—Denial processing, for an online only device, the only relevant Terminal verification results bit is "Service not allowed".

When an online-only device performs IAC—Online and TAC—Online processing the only relevant TVR bit is "Transaction value exceeds the floor limit". Because the floor limit is set to zero, the transaction should always go online and all other values in TAC—Online or IAC—Online are irrelevant.

Online-only devices do not need to perform IAC-default processing.

First card action analysis

One of the data objects read from the card in the Read application data stage is CDOL1 (Card Data object List). This object is a list of tags that the card wants to be sent to it to make a decision on whether to approve or decline a transaction (including transaction amount, but many other data objects too). The terminal sends this data and requests a cryptogram using the generate application cryptogram command. Depending on the terminal′s decision (offline, online, decline), the terminal requests one of the following cryptograms from the card:

  • Transaction certificate (TC)—Offline approval
  • Authorization Request Cryptogram (ARQC)—Online authorization
  • Application Authentication Cryptogram (AAC)—Offline decline.

This step gives the card the opportunity to accept the terminal's action analysis or to decline a transaction or force a transaction on-line. The card cannot return a TC when an ARQC has been asked for, but can return an ARQC when a TC has been asked for.

Online transaction authorization

Transactions go online when an ARQC has been requested. The ARQC is sent in the authorisation message. The card generates the ARQC. Its format depends on the card application. EMV does not specify the contents of the ARQC. The ARQC created by the card application is a digital signature of the transaction details which can be checked in real time by the card issuer. This provides a strong cryptographic check that the card is genuine. The issuer responds to an authorisation request with a response code (accepting or declining the transaction), an authorisation response cryptogram (ARPC) and optionally an issuer script (a string of commands to be sent to the card).

Second card action analysis

CDOL2 (Card data object list) contains a list of tags that the card wants to be sent after online transaction authorisation (response code, ARPC, etc.). Even if for any reason the terminal could not go online (e.g., communication failure), the terminal should send this data to the card again using the generate authorisation cryptogram command. This lets the card know the issuer's response. The card application may then reset offline usage limits.

Issuer script processing

If a card issuer wants to update a card post issuance it can send commands to the card using issuer script processing. Issuer scripts are encrypted between the card and the issuer, so are meaningless to the terminal. Issuer script can be used to block cards, or change card parameters.

Control of the EMV standard

The first version of EMV standard was published in 1995. Now the standard is defined and managed by the privately owned corporation EMVCo LLC. The current members of EMVCo are JCB International, American Express, MasterCard, China UnionPay, Discover Financial and Visa Inc. Each of these organizations owns an equal share of EMVCo and has representatives in the EMVCo organization and EMVCo working groups.

Recognition of compliance with the EMV standard (i.e., device certification) is issued by EMVCo following submission of results of testing performed by an accredited testing house.

EMV Compliance testing has two levels: EMV Level 1, which covers physical, electrical and transport level interfaces, and EMV Level 2, which covers payment application selection and credit financial transaction processing.

After passing common EMVCo tests, the software must be certified by payment brands to comply with proprietary EMV implementations such as Visa VSDC, American Express AEIPS, MasterCard MChip, JCB JSmart, or EMV-compliant implementations of non-EMVCo members such as LINK in the UK, or Interac in Canada.

The EMVCo standards have been integrated into the broader electronic payment security standards being developed by the Secure POS Vendor Alliance, with a specific effort to develop a common interpretation of EMVCo's place relative to, and interactions with, other existing security standards, such as Payment Card Industry Data Security Standard (PCI-DSS).[12]

List of EMV documents and standards

Since version 4.0, the official EMV standard documents that define all the components in an EMV payment system are published as four "books" and some additional documents:

Versions

First EMV standard came into view in 1995 as EMV 2.0. This was upgraded to EMV 3.0 in 1996 (sometimes referred to as EMV '96) with later amendments to EMV 3.1.1 in 1998. This was further amended to version 4.0 in December 2000 (sometimes referred to as EMV 2000).

  • Version 4.0 became effective in June 2004
  • Version 4.1 became effective in June 2007
  • Version 4.2 is in effect since June 2008
  • Version 4.3 is in effect since November 2011.[13]

Vulnerabilities

Opportunities to harvest PINs and clone magnetic stripes

In addition to the track-two data on the magnetic stripe, EMV cards generally have identical data encoded on the chip, which is read as part of the normal EMV transaction process. If an EMV reader is compromised to the extent that the conversation between the card and the terminal is intercepted, then the attacker may be able to recover both the track-two data and the PIN, allowing construction of a magnetic stripe card, which, while not usable in a chip and PIN terminal, can be used, for example, in terminal devices that permit fallback to magstripe processing for foreign customers without chip cards, and defective cards. This attack is possible only where (a) the offline PIN is presented in plaintext by the PIN entry device to the card, where (b) magstripe fallback is permitted by the card issuer and (c) where geographic and behavioural checking may not be carried out by the card issuer. It was claimed[weasel words] that changes specified to the protocol (specifying different card verification values between the chip and magnetic stripe – the iCVV) rendered this attack ineffective. APACS (the UK payments association) stated that such measures would be in place from January 2008, although tests on cards in February 2008 indicated this may have been delayed.[14]

Successful attacks

Conversation capturing is the form of attack that was reported to have taken place against Shell terminals in May 2006, when they were forced to disable all EMV authentication in their filling stations after more than £1 million was stolen from customers.[15]

In October 2008 it was reported that hundreds of EMV card readers for use in Britain, Ireland, the Netherlands, Denmark, and Belgium had been expertly tampered with in China during or shortly after manufacture so that details and PINs of credit and debit cards were sent during the 9 months before over mobile phone networks to criminals in Lahore, Pakistan. United States National Counterintelligence Executive Joel Brenner said, "Previously only a nation state's intelligence agency would have been capable of pulling off this type of operation. It's scary." Data were typically used a couple of months after the card transactions to make it harder for investigators to pin down the vulnerability. After the fraud was discovered it was found that tampered-with terminals could be identified as the additional circuitry increased their weight by about 100 g. Tens of millions of pounds sterling are believed to have been stolen.[16] This vulnerability spurred efforts to implement better control of electronic POS devices over their entire life cycle, a practice endorsed by electronic payment security standards like those being developed by the Secure POS Vendor Alliance (SPVA).[17]

Demonstration of PIN harvesting and stripe cloning

Cambridge University researchers Steven Murdoch and Saar Drimer demonstrated in a February 2008 BBC Newsnight programme one example attack, to illustrate that chip and PIN is not secure enough to justify passing the liability to prove fraud from the banks onto customers.[18][19] The Cambridge University exploit allowed the experimenters to obtain both card data to create a magnetic stripe and the PIN.

APACS, the UK payments association, disagreed with the majority of the report, saying: "The types of attack on PIN entry devices detailed in this report are difficult to undertake and not currently economically viable for a fraudster to carry out."[20] They also said that changes to the protocol (specifying different card verification values between the chip and magnetic stripe – the iCVV) would make this attack ineffective from January 2008. The fraud reported in October 2008 to have operated for 9 months (see above) was probably in operation at the time, but was not discovered for many months.

2010: Hidden hardware disables PIN checking on stolen card

On 11 February 2010 Murdoch and Drimer's team at Cambridge University announced that they had found "a flaw in chip and PIN so serious they think it shows that the whole system needs a re-write" that was "so simple that it shocked them".[21][22] A stolen card is connected to an electronic circuit and to a fake card that is inserted into the terminal ("man-in-the-middle attack"). Any 4 digits are typed in and accepted as a valid PIN. A team from the BBC's Newsnight programme visited a Cambridge University cafeteria (with permission) with the system, and were able to pay using their own cards (a thief would use stolen cards) connected to the circuit, inserting a fake card and typing in "0000" as the PIN. The transactions were registered as normal, and were not picked up by banks' security systems. A member of the research team said, "Even small-scale criminal systems have better equipment than we have. The amount of technical sophistication needed to carry out this attack is really quite low." The announcement of the vulnerability said, "The expertise that is required is not high (undergraduate level electronics) ... We dispute the assertion by the banking industry that criminals are not sophisticated enough, because they have already demonstrated a far higher level of skill than is necessary for this attack in their miniaturized PIN entry device skimmers." It is not known if this vulnerability has been exploited.

EMVCo disagreed and published a response saying that, while such an attack might be theoretically possible, it would be extremely difficult and expensive to carry out successfully, that current compensating controls are likely to detect or limit the fraud, and that the possible financial gain from the attack is minimal while the risk of a declined transaction or exposure of the fraudster is significant.[23]

When approached for comment, several banks[which?] each said that this was an industry-wide issue, and referred the Newsnight team to the banking trade association for further comment. According to Phil Jones of the Consumers' Association, chip and PIN has helped to bring down instances of card crime, but many cases remain unexplained "What we do know is that we do have cases that are brought forward from individuals which seem quite persuasive."

Because the submission of the PIN is suppressed, this is the exact equivalent of a merchant performing a PIN bypass transaction; such transactions will never succeed offline, as a card will never generate an offline authorisation without a successful PIN entry. As a result of this, the transaction ARQC must be submitted online to the issuer who will know that the ARQC was generated without a successful PIN submission (since this information is included in the encrypted ARQC) and hence would be very likely to decline the transaction if it were for a high value, out of character, or otherwise outside of the typical risk management parameters set by the issuer.

Originally, bank customers had to prove that they had not been negligent with their PIN before getting redress, but UK regulations in force from 1 November 2009 placed the onus firmly on the banks to prove that a customer has been negligent in any dispute, with the customer given 13 months to make a claim.[24] Murdoch said that "[the banks] should look back at previous transactions where the customer said their PIN had not been used and the bank record showed it has, and consider refunding these customers because it could be they are victim of this type of fraud."

2011: CVM downgrade allows arbitrary PIN harvest

At the CanSecWest conference in March 2011, Andrea Barisani and Daniele Bianco presented research uncovering a vulnerability in EMV that would allow arbitrary PIN harvesting despite the cardholder verification configuration of the card, even when the supported CVMs data is signed.[25]

The PIN harvesting can be performed with a chip skimmer. In essence, a CVM list that has been modified to downgrade the CVM to Offline PIN is still honoured by POS terminals, despite its signature being invalid.[26]

Implementation

In many countries of the world, debit card and/or credit card payment networks have implemented liability shifts. Normally, the card issuer is liable for fraudulent transactions. However, after a liability shift is implemented, if the ATM or merchant's point of sale terminal does not support EMV, then the ATM owner or merchant will be liable for the fraudulent transaction.

Africa

  • MasterCard's liability shift among countries within this region took place on 1 January 2006.[27] By 1 October 2010, a liability shift had occurred for all point of sale transactions.[28]
  • Visa's liability shift for points of sale took place on 1 January 2006. For ATMs, the liability shift took place on 1 January 2008.[29]

South Africa

  • MasterCard's liability shift took place on 1 January 2005.[27]

Asian/Pacific countries

  • MasterCard's liability shift among countries within this region took place on 1 January 2006.[27] By 1 October 2010, a liability shift had occurred for all point of sale transactions, except for domestic transactions in China and Japan.[28]
  • Visa's liability shift for points of sale took place on 1 October 2010.[29] For ATMs, the liability shift date took place on 1 October 2015, except in China, India, Japan, and Thailand, where the liability shift will be 1 October 2017.[30] Domestic ATM transactions in China are not currently not subject to a liability shift deadline.

Australia

  • MasterCard required all point of sale terminals to be EMV capable by April 2013. For ATMs, the liability shift took place in April 2012. ATMs are required to be EMV compliant by the end of 2015[31]
  • Visa's liability shift for ATMs took place 1 April 2013.[29]

Canada

  • American Express implemented a liability shift on 31 October 2012.[32]
  • Discover implemented a liability shift on 1 October 2015. For pay at the pump at gas stations, the liability shift is 1 October 2017.[33]
  • Interac (Canada's debit card network) stopped processing non-EMV transactions at ATMs on 31 December 2012, and will no longer process non-EMV transactions at point of sale terminals on 31 December 2015.[32]
  • MasterCard implemented domestic transaction liability shift on 31 March 2011, and international liability shift on 15 April 2011. For pay at the pump at gas stations, the liability shift was implemented 31 December 2012.[32]
  • Visa implemented domestic transaction liability shift on 31 March 2011, and international liability shift on 31 October 2010. For pay at the pump at gas stations, the liability shift was implemented 31 December 2012.[32]

Europe

  • MasterCard's liability shift took place on 1 January 2005.[27]
  • Visa's liability shift for points of sale took place on 1 January 2006. For ATMs, the liability shift took place on 1 January 2008.[29]
  • France has cut card fraud by more than 80% since its introduction in 1992 (see: Carte Bleue).

United Kingdom

Green rectangle containing a row of four white asterisks in black squares; the outline of a hand points to and obscures the second asterisk.
Chip and PIN UK logo

Chip and PIN was trialled in Northampton, England from May 2003,[34] and as a result was rolled out nationwide in the United Kingdom on 14 February 2006[35] with advertisements in the press and national television touting the "Safety in Numbers" slogan. During the first stages of deployment, if a fraudulent magnetic swipe card transaction was deemed to have occurred, the retailer was refunded by the issuing bank, as was the case prior to the introduction of chip and PIN. On January 1, 2005, the liability for such transactions was shifted to the retailer; this acted as an incentive for retailers to upgrade their Point of sale (PoS) systems, and most major high-street chains upgraded on time for the EMV deadline. Many smaller businesses were initially reluctant to upgrade their equipment, as it required a completely new PoS system—a significant investment.

New cards featuring both magnetic strips and chips are now issued by all major banks. The replacement of pre-chip and PIN cards was a major issue, as banks simply stated that consumers would receive their new cards "when their old card expires" — despite many people having had cards with expiry dates as late as 2007. The card issuer Switch lost a major contract with HBOS to VISA, as they were not ready to issue the new cards as early as the bank wanted. The Republic of Ireland has required chip and PIN enabled cards since 17 March 2007.

The chip and PIN implementation was criticised as designed to reduce the liability of banks in cases of claimed card fraud by requiring the customer to prove that they had acted "with reasonable care" to protect their PIN and card, rather than on the bank having to prove that the signature matched. Before chip and PIN, if a customer's signature was forged, the banks were legally liable and had to reimburse the customer. Until 1 November 2009 there was no such law protecting consumers from fraudulent use of their chip and PIN transactions, only the voluntary Banking Code. While this code stated that the burden of proof is on the bank to prove negligence or fraud rather than the cardholder having to prove innocence,[36] there were many reports that banks refused to reimburse victims of fraudulent card use, claiming that their systems could not fail under the circumstances reported, despite several documented successful large-scale attacks.

The Financial Services Authority (FSA) Payment Services Regulations 2009 came into force on 1 November 2009[37] and shifted the onus onto the banks to prove, rather than assume, that the cardholder is at fault.[24] The Financial Services Authority said "It is for the bank, building society or credit card company to show that the transaction was made by you, and there was no breakdown in procedures or technical difficulty" before refusing liability.

Latin America and the Caribbean

  • MasterCard's liability shift among countries within this region took place on 1 January 2005.[27]
  • Visa's liability shift for points of sale took place on 1 October 2012, for any countries in this region that had not already implemented a liability shift. For ATMs, the liability shift took place on 1 October 2014, for any countries in this region that had not already implemented a liability shift.[29]

Brazil

  • MasterCard's liability shift took place on 1 March 2008.[27]
  • Visa's liability shift for points of sale took place on 1 April 2011. For ATMs, the liability shift took place on 1 October 2012.[29]

Colombia

  • MasterCard's liability shift took place on 1 October 2008.[27]

Mexico

  • Discover implemented a liability shift on 1 October 2015. For pay at the pump at gas stations, the liability shift is 1 October 2017.[33]
  • Visa's liability shift for points of sale took place on 1 April 2011. For ATMs, the liability shift took place on 1 October 2012.[29]

Venezuela

  • MasterCard's liability shift took place on 1 July 2009.[27]

Middle East

  • MasterCard's liability shift among countries within this region took place on 1 January 2006.[27] By 1 October 2010, a liability shift had occurred for all point of sale transactions.[28]
  • Visa's liability shift for points of sale took place on 1 January 2006. For ATMs, the liability shift took place on 1 January 2008.[29]

New Zealand

  • MasterCard required all point of sale terminals to be EMV compliant by 1 July 2011. For ATMs, the liability shift took place in April 2012. ATMs are required to be EMV compliant by the end of 2015.[31]
  • Visa's liability shift for ATMs was 1 April 2013.[29]

United States

Visa,[38] MasterCard[39] and Discover[40] in March 2012 – and American Express[41] in June 2012 – announced their EMV migration plans for the United States. In spite of these announcements, doubts remain over the willingness of smaller merchants to develop the capability to support EMV.[42] Since the announcement, multiple banks and card issuers have announced cards with EMV chip-and-signature technology, including American Express, Bank of America, Citibank, Wells Fargo,[43] JPMorgan Chase, U.S. Bank, and several credit unions.[44] JPMorgan was the first major bank to introduce a card with EMV technology, namely its Palladium card, in mid-2012.[44]

  • American Express implemented its liability shift for point of sale terminals on 1 October 2015.[45] For pay at the pump, at gas stations, the liability shift is 1 October 2017.
  • Discover implemented its liability shift on 1 October 2015. For pay at the pump at gas stations, the liability shift is 1 October 2017.[33]
  • Maestro implemented its liability shift of 19 April 2013, for international cards used in the United States.[46]
  • MasterCard implemented its liability shift for point of sale terminals in 1 October 2015.[45] For pay at the pump, at gas stations, the liability shift is 1 October 2017. For ATMs, the liability shift date is in 1 October 2016.[47][48]
  • Visa implemented its liability shift for point of sale terminals on 1 October 2015. For pay at the pump, at gas stations, the liability shift is 1 October 2017.[49] For ATMs, the liability shift date is 1 October 2017.[30]

In May 2010, a press release from Gemalto (a global EMV card producer) indicated that United Nations Federal Credit Union in New York would become the first EMV card issuer in the United States, offering an EMV Visa credit card to its customers.[50]

Chip and PIN systems can cause problems for travellers from countries that do not issue chip and PIN cards (most notably, the United States) as some retailers may refuse to accept their chipless cards.[51] While most terminals still accept a magnetic strip card, and the major credit card brands require vendors to accept them,[52] some staff may refuse to take the card, under the belief that they are held liable for any fraud if the card cannot verify a PIN. Non-chip-and-PIN cards may also not work in some unattended vending machines at, for example, train stations, or self-service check-out tills at supermarkets.[53]

In 2010, a number of companies began issuing pre-paid debit cards that incorporate chip and PIN and allow Americans to load cash as euros or pound sterling.[54] United Nations Federal Credit Union was the first United States issuer to offer chip and PIN credit cards.[55]

See also

References

  1. ^ "EMVCo Members". EMVCo. Retrieved 10 May 2015.
  2. ^ Kitten, Tracy (7 March 2011). "EMV Roots Go Deep in Europe: Global Shifts, New Headaches for U.S. Issuers". BankInfoSecurity. Retrieved 7 June 2015.
  3. ^ "China UnionPay joins EMVCo" (Press release). Finextra Research. 20 May 2013. Retrieved 10 May 2015.
  4. ^ "Discover Joins EMVCo to Help Advance Global EMV Standards". Discover Network News. 3 September 2013. Retrieved 10 May 2015.
  5. ^ "Shift of liability for fraudulent transactions". The UK Cards Association. Retrieved 10 May 2015.
  6. ^ "Chip-and-PIN vs. Chip-and-Signature", CardHub.com, retrieved 31 July 2012.
  7. ^ "BBC NEWS - Technology - Credit card code to combat fraud". bbc.co.uk.
  8. ^ "... a revolution in authentication". emue.com.
  9. ^ "Visa tests cards with built in PIN machine". IT PRO.
  10. ^ "How EMV (Chip & PIN) Works - Transaction Flow Chart". Creditcall Ltd. Retrieved 10 May 2015.
  11. ^ a b c d John Kiernan. "Chip-and-PIN vs. Chip-and-Signature". Evolution Finance, Inc. Retrieved 31 July 2012.
  12. ^ "SPVA Launch Presentation". Secure POS Vendor Alliance. 2009.[dead link]
  13. ^ "Integrated Circuit Card Specifications for Payment Systems". EMVCo. Retrieved 26 March 2012.
  14. ^ Saar Drimer; Steven J. Murdoch; Ross Anderson. "PIN Entry Device (PED) vulnerabilities". University of Cambridge Computer Laboratory. Retrieved 10 May 2015.
  15. ^ "Petrol firm suspends chip-and-pin". BBC News. 6 May 2006. Retrieved 13 March 2015.
  16. ^ "Organized crime tampers with European card swipe devices". The Register. 10 October 2008.
  17. ^ "Technical Working Groups, Secure POS Vendor Alliance". 2009. Archived from the original on 15 April 2010. {{cite web}}: Unknown parameter |deadurl= ignored (|url-status= suggested) (help)
  18. ^ "Is Chip and Pin really secure?". BBC News. 26 February 2008. Retrieved 2 May 2010.
  19. ^ "Chip and pin". 6 February 2007. Archived from the original on 5 July 2007.
  20. ^ John Leyden (27 February 2008). "Paper clip attack skewers Chip and PIN". The Channel. Retrieved 10 May 2015.
  21. ^ Steven J. Murdoch; Saar Drimer; Ross Anderson; Mike Bond. "EMV PIN verification "wedge" vulnerability". Computer Laboratory, University of Cambridge. Retrieved 12 February 2010.
  22. ^ Susan Watts (11 February 2010). "New flaws in chip and pin system revealed". BBC News. Retrieved May 2015. {{cite news}}: Check date values in: |accessdate= (help)
  23. ^ "Response from EMVCo to the Cambridge University Report on Chip and PIN vulnerabilities ('Chip and PIN is Broken' – February 2010)" (PDF). EMVCo. Retrieved 26 March 2010.
  24. ^ a b Richard Evans (15 October 2009). "Card fraud: banks now have to prove your guilt". The Telegraph. Retrieved 10 May 2015. Cite error: The named reference "bankliable" was defined multiple times with different content (see the help page).
  25. ^ Andrea Barisani; Daniele Bianco; Adam Laurie; Zac Franken (2011). "Chip & PIN is definitely broken" (PDF). Aperture Labs. Retrieved 10 May 2015.
  26. ^ Adam Laurie; Zac Franken; Andrea Barisani; Daniele Bianco. "EMV - Chip & Pin CVM Downgrade Attack". Aperture Labs and Inverse Path. Retrieved 10 May 2015.
  27. ^ a b c d e f g h i "Chargeback Guide" (PDF). MasterCard Worldwide. 3 November 2010. Retrieved 10 May 2015.
  28. ^ a b c "Operating Regulations" (PDF). Visa International. Archived from the original (PDF) on 3 March 2013. {{cite web}}: Unknown parameter |deadurl= ignored (|url-status= suggested) (help)
  29. ^ a b c d e f g h i "The Journey To Dynamic Data" (PDF). Visa.[dead link]
  30. ^ a b "Visa Expands U.S. Roadmap for EMV Chip Adoption to Include ATM and a Common Debit Solution" (Press release). Foster City, Calif.: Visa. 4 February 2013. Retrieved 10 May 2015.
  31. ^ a b "MasterCard Announces Five Year Plan to Change the Face of the Payments Industry in Australia". Mastercard Australia.[dead link]
  32. ^ a b c d "Chip Liability Shift". globalpayments. Archived from the original on 30 July 2013. {{cite web}}: Unknown parameter |deadurl= ignored (|url-status= suggested) (help)
  33. ^ a b c "Discover to enforce EMV liability shift by 2015" (Press release). Finextra Research. 12 November 2012. Retrieved 10 May 2015.
  34. ^ "Anti-fraud credit cards on trial". BBC Business News. 11 April 2003. Retrieved 27 May 2015.
  35. ^ The UK Cards Association. "The chip and PIN guide" (PDF). Retrieved 27 May 2015.
  36. ^ "Is chip and PIN safe?". This is MONEY. 3 November 2004. Retrieved 27 May 2015.
  37. ^ FSA: Payment Services Regulations 2009, in force from 1 November 2009
  38. ^ "Visa update for EMV Chip implementation in the U.S." Creditcall Ltd. 17 January 2012. Retrieved 10 May 2015.
  39. ^ "MasterCard aligns with Visa's U.S. EMV migration plans by publishing its own EMV implementation roadmap". Creditcall Ltd. 1 February 2012. Retrieved 10 May 2015.
  40. ^ "Discover Implements EMV Mandate for U.S., Canada and Mexico".[dead link]
  41. ^ "American Express Announces U.S. EMV Roadmap to Advance Contact, Contactless and Mobile Payments" (Press release). New York: American Express. 29 June 2012. Retrieved 10 May 2015.
  42. ^ "EMV's Uncertain Fate in the US". Protean Payment. Retrieved 22 September 2012.[dead link]
  43. ^ Camhi, Jonathan (3 August 2012). "Wells Fargo Introduces New EMV Card for Consumers". Bank Systems & Technology. Retrieved 10 May 2015.
  44. ^ a b Paul Riegler (25 July 2013). "Chip-and-Pin and Chip-and-Signature Credit Card Primer for 2013". Frequent Business Traveler. Retrieved 10 May 2015.
  45. ^ a b Cathy Medich (July 2012). "EMV Migration – Driven by Payment Brand Milestones". Retrieved 10 May 2015.
  46. ^ David Heun (10 September 2012). "MasterCard Brings EMV Chip-Card Liability Policy to U.S. ATMs". SourceMedia. Retrieved 10 May 2015.
  47. ^ Beth Kitchener (10 September 2012). "MasterCard Extends U.S. EMV Migration Roadmap to ATM Channel" (Press release). Purchase, N.Y.: Mastercard. Retrieved 10 May 2015.
  48. ^ EMV For U.S. Acquirers: Seven Guiding Principles for EMV Readiness
  49. ^ "Visa Announces U.S. Participation in Global Point-of-Sale Counterfeit Liability Shift" (PDF) (Press release). Visa. 9 August 2011. Retrieved 10 May 2015.
  50. ^ Ray Wizbowski (13 May 2010). "United Nations Federal Credit Union Selects Gemalto for First U.S. Issued Globally Compliant Payment Card" (Press release). Austin, Texas: Gemalto. Retrieved 10 May 2015.
  51. ^ "US credit cards outdated, less useful abroad, as 'chip and PIN' cards catch on". creditcards.com.
  52. ^ "Visa Australia". visa-asia.com.
  53. ^ For Americans, Plastic Buys Less Abroad
  54. ^ "Travelex Offers America's First Chip & PIN Enabled Prepaid Foreign Currency Card". Business Wire. Business Wire. 1 December 2010. Retrieved 6 February 2014.
  55. ^ "UNFCU to be first issuer in the US to offer credit cards with a high security chip". United Nations Federal Credit Union.