Professional Documents
Culture Documents
Daniele Bianco
<andrea@inversepath.com>
<daniele@inversepath.com>
Adam Laurie
Zac Franken
<adam@aperturelabs.com>
<zac@aperturelabs.com>
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
What is EMV?
EMV stands for Europay, MasterCard and VISA, the global
standard for inter-operation of integrated circuit cards (IC cards
or "chip cards") and IC card capable point of sale (POS) terminals
and automated teller machines (ATMs), for authenticating credit
and debit card transactions.
IC card systems based on EMV are being phased in across the
world, under names such as "IC Credit" and "Chip and PIN".
Source: Wikipedia
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Why EMV?
ICC / smartcard
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Liability shift
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Liability shift
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
EMV adoption
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
EMV is broken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
ATM skimmers
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
EMV skimmers
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
EMV skimmer
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
EMV smartcards
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
2 |
3 |
4 |
5 |
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
The CVV (228) matches the magstripe one only for cards that do
not use iCVV (a different stored value to protect against this
attack, introduced in January 2008 but not present on all cards)
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Chip&PINisdefinitelybroken
Chip cloning
SDA cards can be cloned and used without PIN for offline
transactions only (Yes card)
DDA cards clone ineffective for offline and online transactions,
however a valid DDA card can be used to pass offline
authentication and perform fake offline transaction (not tied
to the authentication)
offline transactions are rare in EU
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Threats
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Cardholder verification
----------------------------------------------------------------------------------------------------------------------------Bits
8 7 6
0
0
1
0
0
0
0
0
0
0
0
0
0
1
1
1
Meaning
5 4 3 2 1
0
0
0
0
0
0
0
x
1
1
0
1
1
0
0
0
0
0
0
0
x
1
1
x
x
1
0
0
0
0
1
1
1
x
1
1
x
x
1
0
0
1
1
0
0
0
x
1
1
x
x
1
0
1
0
1
0
1
1
x
0
1
x
x
1
RFU
Fail cardholder verification if this CVM is unsuccessful
Apply succeeding CV rule if this CVM is unsuccessful
Fail CVM processing
Plaintext PIN verification performed by ICC
Enciphered PIN verified online
Plaintext PIN verification by ICC and signature (paper)
Enciphered PIN verification by ICC
Enciphered PIN verification by ICC and signature (paper)
Enciphered PIN verification by ICC and signature (paper)
Values in range 000110 011101 reserved for future use
Signature (paper)
No CVM required
Values in range 100000 101111 reserved for future use
Values in range 110000 111110 reserved for future use
Not available
Copyright2011InversePathS.r.l.
Value
N/A
N/A
N/A
00 or 40
01 or 41
02 or 42
03 or 43
04 or 44
05 or 45
05 or 45
06-1D/16-5D
1E or 5E
1F or 5F
20-2F/60-6F
30-3E/70-7E
3F or 7F
Chip&PINisdefinitelybroken
CVM List
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Action Codes
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Chip&PINisdefinitelybroken
Chip&PINisdefinitelybroken
0
1
0
x
x
x
x
x
x
x
x
x
x
0
0
1
x
x
x
x
x
x
x
0
1
0
x
x
x
x
x
x
x
x
x
x
1
x
x
x
x
x
x
x
x
x
x
1
x
x
x
x
x
x
x
x
x
x
1
x
x
x
x
x
x
x
x
x
x
1
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
1
x
x
x
x
1
x
x
x
x
1
x
x
x
x
1
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Backend detection
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Backend detection
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Summary
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
Recommendations
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken
http://www.inversepath.com
http://www.aperturelabs.com
sponsored by:
http://www.integra-group.it
Copyright2011InversePathS.r.l.
Chip&PINisdefinitelybroken