by Eleanor Chan and Rita Beisel
Let's set the context. EMV stands for Europay, MasterCard and Visa, a global standard founded in 1994, with the purpose of creating an international standard for authenticating credit and debit card transactions. Today, the security and global interoperability of chip-based payment cards (any pocket-sized card with embedded integrated circuits such as smart cards, chip cards, integrated circuit cards (ICC)) and ICC-capable point of sale (POS) terminals and automated teller machines (ATMs) are paramount to reducing credit card fraud and gaining consumer confidence with any financial transaction.
Worldwide adoption of EMV has been steadily progressing for over a decade now and a surge of acceptance is expected this year in the United States of America. Some of the contributing factors include the increase in credit card fraud, the October 2015 'liability shift' milestone announced by the payment brands, and President Obama's BuySecure Initiative. The increase in contact-less payments and mobile transactions has also motivated the need for technology to secure 'card-present' financial transactions, transactions where the actual 'smart' card is present.
While ICSF Cryptographic Support for z/OS contains the necessary cryptographic services needed to implement the EMV standards, using these services to build EMV applications is a challenging task because of the architectural and terminology differences between IBM's Common Cryptographic Architecture (CCA) and EMV.
With the application of the PTFs for APAR OA47016, ICSF simplifies the development of EMV applications with the introduction of six new callable services designed in support of the EMV standard. Although these services are new, they call existing ICSF callable services internally and simplify EMV key derivation (issuer, ICC, and session keys), EMV transaction processing (ARQC/ARPC), and EMV scripting. The callable service descriptions use EMV terminology for ease of use.
The ICSF callable services that simplify EMV applications are:
- Generate Issuer Master Key (CSNBGIM)
This service helps with the initial steps of EMV setup by generating and storing the issuer master keys. The master keys are stored in the key data set and returned as either internal or external key tokens for key management.
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBKGN --> CSNBKRC2 --> (optionally) CSNBKIM or CSNBKEX.
- Derive ICC Master Key (CSNBDCM)
This service generates an ICC master key from an issuer master key. The ICC master keys are needed for ICC personalization, EMV transaction processing, and EMV scripting. The master keys are returned as either internal or external key tokens for key management.
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG --> (optionally) CSNBKEX.
- Derive Session Key (CSNBDSK)
This service generates a session key from either an issuer master key or an ICC master key. Session keys are used in EMV transaction processing and EMV scripting.
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG.
- EMV Transaction (ARQC/ARPC) service (CSNBEAC)
This service simplifies EMV ARQC and ARPC transaction processing.
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG --> CSNBMGN and/or CSNBMVR.
This service simplifies EMV scripting. Scripts may be encrypted for confidentiality, MAC'd for integrity, or both.
Secure Messaging with Integrity
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG --> CSNBMGN.
Secure Messaging with Confidentiality
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG --> CSNBENC.
Secure Messaging with Confidentiality for commands containing a PIN
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG --> CSNBSPN.
Secure Messaging with both Confidentiality and Integrity
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG --> CSNBENC --> CSNBMGN.
Secure Messaging with both Confidentiality and Inegrity for commands containing a PIN
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG --> CSNBMGN --> CSNBSPN.
Visa PIN change/unblocking as described in VISA Integrated Circuit Card Specification, v1.4.0
The ICSF callable service that is called internally from this service is CSNBPCU.
- EMV Verification Service (CSNBEVF)
This service provides additional functions used by MasterCard.
Verification of data authentication codes
The ICSF callable service that is called internally from this service is CSNBENC.
Verification of ICC dynamic numbers
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG --> CSNBENC.
Decryption of encrypted counters
The ICSF callable services that are called internally from this service are CSNBKTB --> CSNBDKG --> CSNBDEC.
This support is available for ICSF releases running on z/OS V1R13 thru z/OS V2R2. For additional information, see ftp://public.dhe.ibm.com/eserver/zseries/zos/icsf/pdf/oa47016.pdf
For information on EMV SmartCard personalization, see https://www-304.ibm.com/connections/wikis/home?lang=en-us#!/wiki/W54fdea979176_407e_8a6e_f9d8c4cf1e08/page/EMV%20SmartCard%20Personalization
(With thanks to Steve Hart)