COMPARE EMV COMPATIBLE APPS

Tomcat

Professional
Messages
1,008
Reputation
3
Reaction score
149
Points
63
The purpose of this section is to compare the functionality, security, and implementation features of the most popular EMV-cob applications on the market . These applications primarily include applications of the leading payment systems VISA and MasterCard, known under the brands VSDC and M / Chip, respectively.

The previous version of the EMV standard (version 4.1, approved in May 2004) introduced the Common Core Definition (CCD) specification and introduced the concept of a CCD application (an application that meets the requirements of CCD).

The CCD specification defines the set and format of data used in the dialogue between the card and the issuer, as well as the set and format of commands sent by the terminal to the card for transferring the issuer's data to it. In addition, the CCD specification defines some features of transaction processing (for example, the exclusion of terminal velocity checking), and also unifies the method of exchanging chip data between the bank host and the payment network (according to CCD, the DE 55 field of the authorization request / answer).

An important example of a CCD-compliant application is the CPA (Common Payment Application) approved by EMVCo as a standard in December 2005. It is the only EMV application recognized by MasterCard, VISA, JCB and American Express as an alternative payment application to their own applications (M / Chip, VSDC, etc.). The latter means that each bank of the above-mentioned payment systems has the opportunity to use both its own unique application of this system and the universal CPA application.

EMVCo has developed procedures for certifying cards for compliance with CCD and CPA standards - the so-called Card Type Approval procedures. These procedures allow you to check the compliance of the physical parameters of the card with the EMV requirements, as well as the functionality of the card, including from the point of view of the correctness of the application performing functions that ensure the safety of card transactions.

To assess the security of a microcircuit and its operating system, a separate special procedure EMVCo Security Evaluation Process is used, which is applied to cards that support the CCD application and the CPA application.

Certification of cards and applications in accordance with the Card Type Approval and EMVCo Security Evaluation Process is performed by laboratories accredited by EMVCo for these tasks.

The intellectual property rights for the M / Chip Application are owned by MasterCard Worldwide. The M / Chip specification is confidential.

VISA International is the owner of the intellectual property rights for the VIS application. The VIS specification is confidential.

The owner of the intellectual property rights for the CPA specification is EMVCo, whose founders at the end of 2009 were MasterCard Worldwide, VISA International, JCB and American Express. The CPA specification is open source and anyone can download the specification from the EMVCo website at www.emvco.com. Any company can use the CPA specification for free to develop their own card product.

If a company-developer wishes to confirm the fact of compliance of the application developed by it with the CPA specification, it must be certified by EMVCo. The EMVCo website contains a list of laboratories accredited by EMVCo to perform this certification.

VISA and MasterCard payment systems require card suppliers with the CPA application to certify the card for compliance with the CPA standard, if the supplier intends to sell these cards to banks for use in the named payment systems.

This section compares the M / Chip 4, VSDC and CPA applications in terms of:
  • - the data objects and commands used by them;
  • - functionality;
  • - the security of transactions provided by the application;
  • - the complexity of implementation.
In the comparative analysis of applications, the following specifications were used:
  • - for VSDC application: Visa Integrated Circuit Card (ICC) Specification, v. 1.4.0, 31 October, 2001, Integrated Circuit Card Specification (VIS) Corrections, November 2003, and Technical Guide to Visa's Applet For Global Platform Cards, March 2007;
  • - for application M / Chip 4: M / Chip 4 Version 1.1 Card Application Specifications for Debit and Credit, October 2006;
  • - for the CPA application: Common Payment Application Specification, Version 1.0, December 2005, as well as CPA Specification vl Plus Bulletins, March 2008.
 
Top