PayPass MChip Requirements 2013 PDF
PayPass MChip Requirements 2013 PDF
Requirements
3 July 2013
Notices
Following are policies pertaining to proprietary rights, trademarks, translations, and details about
the availability of additional information online.
Proprietary Rights
The information contained in this document is proprietary and confidential to MasterCard International
Incorporated, one or more of its affiliated entities (collectively “MasterCard”), or both.
This material may not be duplicated, published, or disclosed, in whole or in part, without the prior
written permission of MasterCard.
Trademarks
Trademark notices and symbols used in this document reflect the registration status of MasterCard
trademarks in the United States. Please consult with the Customer Operations Services team or the
MasterCard Law Department for the registration status of particular product, program, or service names
outside the United States.
All third-party product and service names are trademarks or registered trademarks of their respective
owners.
Disclaimer
MasterCard makes no representations or warranties of any kind, express or implied, with respect to
the contents of this document. Without limitation, MasterCard specifically disclaims all representations
and warranties with respect to this document and any intellectual property rights subsisting therein or
any part thereof, including but not limited to any and all implied warranties of title, non-infringement,
or suitability for any purpose (whether or not MasterCard has been advised, has reason to know, or is
otherwise in fact aware of any information) or achievement of any particular result. Without limitation,
MasterCard specifically disclaims all representations and warranties that any practice or implementation of
this document will not infringe any third party patents, copyrights, trade secrets or other rights.
Translation
A translation of any MasterCard manual, bulletin, release, or other MasterCard document into a language
other than English is intended solely as a convenience to MasterCard customers. MasterCard provides any
translated document to its customers “AS IS” and makes no representations or warranties of any kind
with respect to the translated document, including, but not limited to, its accuracy or reliability. In no
event shall MasterCard be liable for any damages resulting from reliance on any translated document.
The English version of any MasterCard document will take precedence over any translated version in
any legal proceeding.
Information Available Online
MasterCard provides details about the standards used for this document—including times expressed,
language use, and contact information—on the Publications Support page available on MasterCard
Connect™. Go to Publications Support for centralized information.
Purpose.......................................................................................................................................... 1-1
Scope ............................................................................................................................................. 1-1
Audience........................................................................................................................................ 1-2
Overview ....................................................................................................................................... 1-2
Language Use ................................................................................................................................ 1-3
Requirements and Best Practices ................................................................................................... 1-3
Terminology................................................................................................................................... 1-4
Reference Information ................................................................................................................... 1-5
Conventions................................................................................................................................... 1-6
Purpose
This document provides the MasterCard requirements and best practices
for issuers and acquirers when using contactless chip technology with their
MasterCard M/Chip™ products.
• Define the PayPass requirements that MasterCard has established for use
with MasterCard brands
• Propose recommendations that constitute best practices for PayPass
implementations
• Define when and how the functions must be used as a requirement or
should be used as a best practice
Scope
This document does not discuss general brand rules or requirements, except to
explain how certain rules are implemented in PayPass.
These requirements have been written for PayPass—M/Chip so also cover the
PayPass—Mag Stripe requirements.
This document does not introduce new technical requirements that are not
already included in the existing card and reader specifications. The following
products, services, or environments are not in the scope of this document
because they are already addressed in other dedicated documents:
Audience
This document is intended for use by MasterCard customers and product
vendors involved in PayPass implementation projects who already have a
general understanding of how the contactless chip product works.
Overview
This document supports issuers and acquirers implementing PayPass—M/Chip.
It details the requirements and best practices for effective deployment of
PayPass solutions.
Chapter Description
Chapter 1: Using this This chapter contains information that helps you understand
Manual and use this document.
Chapter 2: This chapter introduces the basic principles of PayPass.
Introduction
Chapter 3: Issuer This chapter details the requirements from an issuer
Requirements perspective including requirements for configuring cards
and devices.
Language Use
The spelling of English words in this manual follows the convention used for
U.S. English as defined in Webster’s New Collegiate Dictionary.
An exception to the above concerns the spelling of proper nouns. In this case,
we use the local English spelling.
Requirements are always expressed using the word must. Requirements are
contained in tables and are indicated by a capital R in the left column.
Best practices are MasterCard recommendations for the best ways to implement
different options. If customers choose not to follow them, their PayPass
implementation will still work but may not be as effective or efficient as it
could be.
Best practices are written using the word should. Best practices are formatted
in the same way as requirements but are preceded by the letters BP.
Terminology
PayPass Cards and Devices
PayPass devices can be issued in form factors other than that of a traditional
payment card, for example: mobile phones, key fobs, watches. Throughout
this document a reference to PayPass cards includes other devices unless
specifically excluded.
A dual interface card refers to a chip card that can perform both EMV contact
and contactless chip transactions.
A hybrid card refers to a card that has a magnetic stripe and a chip with a
contact interface. The chip carries an EMV payment application that supports
the same payment product that is encoded on the magnetic stripe.
A hybrid terminal refers to a payment device that can accept transactions using
both contact chip and magnetic stripe technologies.
Devices such as a mobile phone may allow the cardholder to verify themselves
to the device, for example by entering a PIN, either before or during a PayPass
transaction. When required, the device confirms to the terminal that cardholder
verification has been performed during the transaction processing. This is
known as On Device Cardholder Verification but is also referred to as "mobile
PIN" or "mPIN".
Reference Information
The following references are used in, or are relevant to, this document. The
latest version applies unless a publication date is explicitly stated.
• Chargeback Guide
• M/Chip Card Personalization Standard Profiles (Including PayPass)
• M/Chip Requirements
• MasterCard Contactless ATM Implementation Requirements
• Maestro Global Rules
• Maestro PayPass Branding Standards
• MasterCard PayPass Branding Standards
• MasterCard Rules
• PayPass—Mag Stripe Acquirer Implementation Requirements
• PayPass On-behalf Services Guide
• PayPass Personalization Data Specification
• M/Chip Advance Personalization Data Specifications
• PayPass Vendor Product Approval Process Guide (Cards and Devices)
• PayPass Vendor Product Approval Process Guide (Terminals)
• Mobile PayPass Issuer Implementation Guide
• PayPass—M/Chip Issuer Guide
• PayPass Mag Stripe Issuer Implementation Requirements
• Security Rules and Procedures
Conventions
A generic reference to PayPass includes all applicable products. The terms
MasterCard PayPass or Maestro PayPass is used to identify specific product
requirements.
Values expressed in hexadecimal form ('0' to '9' and 'A' to 'F') are enclosed
in single quotes. For example, a hexadecimal value of ABCD is indicated as
'ABCD'.
Values expressed in binary form are followed by a lower case b. For example,
1001b.
EMV Card commands are indicated in bold capitals, for example, GENERATE AC.
Specific byte/bit references within a data object are included in square brackets.
For example, [1][3] means the third bit of the first byte of the given data object.
Introduction
PayPass is the proximity payments program from MasterCard Worldwide.
Participation
To issue PayPass cards or acquire PayPass transactions customers must enroll
in the PayPass program.
All cards, devices and readers used for performing PayPass transactions must
have been approved and licensed by MasterCard. Customers must only
purchase and deploy cards and terminals from properly licensed vendors.
Detailed information about the type approval process can be found in the
PayPass Vendor Product Approval Process Guide (Cards and Devices) and the
PayPass Vendor Product Approval Process Guide (Terminals) documents.
Issuers and acquirers must start a project with the relevant MasterCard project
team in order to define and complete various certification steps that are required.
Unless otherwise stated within the Project Implementation Plan issuers will
complete Issuer NIV, CPV and Issuer End-to-end Demonstration and acquirers
will complete Acquirer NIV, TIP and Acquirer End-to-end Demonstration.
PayPass Cards
PayPass functionality may be:
All PayPass cardholder devices are valid for acceptance at PayPass terminals;
not just cards.
PayPass data should only be used for card present transactions. Electronic
commerce or Mail Order/Telephone Order transactions should not be
performed with PayPass data read through the contactless interface.
The contactless interface may be used for MasterCard Purchase with Cash Back
transactions based on the existing product rules. Cardholder verification is
always required for Purchase with Cash Back transactions.
Maestro PayPass must not be used for POS Unique Transactions, as defined
in the Maestro Global Rules.
PayPass Acceptance
PayPass cards may be accepted at attended and unattended POS terminals.
PayPass cards may be used at ATMs.
Card Checking
PayPass transactions are carried out by the cardholder; therefore, the card does
not need to be given to the merchant. Since the PayPass card may remain in
the hands of the cardholder, the merchant is exempt from the visual inspection
requirement to determine if the PayPass card is valid. The card only needs
to be given to the merchant after the contactless interaction is complete if
signature verification is to be performed.
Transaction Amount
Limits
Floor limits for PayPass are as for EMV contact chip (for PayPass—M/Chip) or
magnetic stripe (for PayPass—Mag Stripe) transactions. The floor limit may
vary per market.
Fallback
Technology Selection
Application Selection
If the cardholder has chosen to pay by PayPass, the terminal attempts to find
an application via the contactless interface to complete the transaction.
When the terminal detects more than one application that it supports on the
PayPass card, the terminal automatically selects the application with the highest
priority set by the issuer. Interactive cardholder selection or confirmation is not
supported for PayPass to improve the transaction speed.
If there are no available applications, given any relevant transaction limits, then
the PayPass transaction cannot proceed.
For MasterCard products, the same Application Identifiers (AID) are used
for PayPass transactions as for EMV contact chip transactions. There are no
PayPass specific AIDs.
Card Authentication
For all PayPass transactions the card being used is authenticated. For
PayPass—M/Chip transactions the card can be authenticated:
OR
• CDA
OR
• SDA1
While older cards may support SDA, the only offline card authentication
method allowed for new cards is CDA. All PayPass—M/Chip terminals support
CDA. PayPass does not support DDA.
1. SDA authenticates the card, but not the transaction data. New PayPass cards cannot be issued supporting
SDA. Newly deployed PayPass terminals do not support SDA, and are not configured to support SDA.
Cardholder Verification
• Online PIN
• Signature
• On Device Cardholder Verification
• Online PIN
• On Device Cardholder Verification
Online/Offline Authorization
If online PIN has been identified as the cardholder verification method for the
transaction, the PIN is verified as part of the online authorization request.
End of Transaction
A PayPass—M/Chip terminal ends the interaction with the card once the
response to the first GENERATE AC command is received by the terminal. A
PayPass—Mag Stripe terminal ends the interaction with the card once the
response to the COMPUTE CRYPTOGRAPHIC CHECKSUM command is received
by the terminal. This is not the end of the PayPass transaction.
OR
When the printing of a receipt is supported by the point of sale, for PayPass
transactions less than or equal to the chargeback protection amount, a receipt
must be available if requested by the cardholder. A receipt must be provided
for transactions above the chargeback protection amount if the terminal is
capable of producing a receipt. See MasterCard Rules and Maestro Global
Rules for exemptions.
Neither Issuer Authentication Data nor issuer scripts are returned to the card
during a PayPass—M/Chip transaction.
General Requirements
PayPass Enrollment
R ALL All customers who wish to issue PayPass must enroll in the PayPass
program.
Card Requirements
Various requirements and best practices exist for the PayPass card.
All PayPass cards issued are required by MasterCard to have MasterCard vendor
product approval. It is the issuer¢s responsibility to confirm all products have
received this approval. A full PayPass card Letter of Approval is only granted to
a card when it has successfully completed all of the following:
When ordering cards from a card manufacturer, the issuer must ensure that the
card manufacturer has a current PayPass Letter of Approval for the product
being purchased. The Letter of Approval is valid for the duration of the time
the cards are held in stock prior to being issued.
All PayPass products must have a valid PayPass Letter of Approval at the time
the product is issued.
R ALL Issuers must ensure that all PayPass cards are covered by a valid Letter
of Approval at the time they are issued.
For the brand standards and design elements required for PayPass cards, please
refer to the MasterCard PayPass Branding Standards and the Maestro PayPass
Branding Standards. Issuers must obtain approval from MasterCard Card
Design Management for their PayPass card design, even if a similar design has
already been approved for use on a non-PayPass card.
PayPass Cards
R ALL PayPass—M/Chip cards that are ISO 7816 compliant must be hybrid
cards supporting both magnetic stripe and EMV contact chip.
A MasterCard PayPass card that supports EMV contact chip transactions on the
contact interface normally also supports PayPass—M/Chip.
Non-card Devices
• Mobile phones
• Key fobs
• Watches
All PayPass non-card devices conduct PayPass transactions in the same way
as PayPass cards. They may support special functionality, such as On Device
Cardholder Verification.
Card Application
• M/Chip Advance
• PayPass—M/Chip 4
• Mobile PayPass
• PayPass—M/Chip Flex
ATM
Because not all ATMs validate the settings of the card, issuers should be aware
that they may receive transactions from ATMs even if:
BP ALL The Application Usage Control should indicate support for ATM
transactions.
To meet special market requirements MasterCard may approve cards that are
exclusively online or exclusively offline; however, issuers should be aware that
these cards do not work in some terminals.
Service Codes
A value for the service code may be found several times on a PayPass—M/Chip
card. For example:
If the issuer does use a different service code value on the contactless interface,
the value may be acted on by some terminals. In particular, terminals that
process the service code may reject international cards that have a service code
value starting with '5' (National use only).
BP ALL Issuers should use a value of the service code appropriate for the
product.
BP ALL Issuers should use the same value of the service code each time the
service code is used.
Expiry Dates
The expiry date of the card should be consistent across all technologies
supported.
BP ALL The expiry date in the PayPass application should be consistent with
the expiry date of the card.
Maestro cards must not support Purchase with Cash Back on the contactless
interface.
Debit MasterCard cards may support Purchase with Cash Back on the
contactless interface.
Purchase with Cash Back on the contactless interface may only be supported
by MasterCard credit cards in European markets.
Application Selection
Issuers must use the Application Priority Indicator in the PPSE to show the
preferred sequence of choice of all PayPass applications on the card. Issuers
must set a different priority for each application. Cardholder confirmation must
not be requested.
The AID value used for PayPass is the same AID used for the EMV contact chip
interface. There are no specific AIDs for PayPass.
• MasterCard ‘A0000000041010’
• Maestro ‘A0000000043060’
Identification of PayPass cards use the product AID without any extension, as
shown above. PIX extensions may be used by issuers and are considered as
a successful match by the terminal when partial AID matching is supported.
However, it is recommended not to use PIX extensions, as some legacy PayPass
terminals do not support partial AID matching.
If the same account is accessed through the contact and contactless interfaces,
the AID used on each interface might be different; the contact AID may contain
a PIX extension, but the contactless AID excludes this PIX extension.
The Application Label (tag '50') must be present in a PayPass card. This may
appear on any receipts.
Issuers may personalize the Application Preferred Name (tag '9F12') and Issuer
Code Table Index (tag '9F11'). The Application Preferred Name may be used
on receipts instead of the Application Label if the terminal supports the code
table indicated.
Card Authentication
• New cards issued in the Europe or U.S. regions must support CDA and
must not support SDA
• New cards issued outside of the Europe or U.S. regions that do not support
CDA must operate as online only. Cards must not support SDA. Cards that
do not support CDA may experience interoperability issues and may not
work with some merchants such as mass transit agencies.
Issuers of old cards that support SDA should note that SDA will not be
performed on PayPass readers that comply with EMVCo Book C-2 and therefore
all transactions at these readers will require online authorization.
All Maestro PayPass cards must support CDA and must not support SDA for
Maestro PayPass—M/Chip.
The payment system public keys for PayPass—M/Chip have the same values
and expiry dates as those used for MasterCard EMV contact chip transactions. It
is recommended to use the same Issuer Key pair for transactions on the contact
and contactless interface of a PayPass—M/Chip card; therefore, the same Issuer
Public Key certificate may be used.
It is recommended to use the same ICC Key pair for transactions on the contact
and contactless interface of a PayPass—M/Chip card. The ICC Public Key
Certificate cannot be shared between the contact and contactless interface
even if the same keys are used since some of the data elements signed in the
certificate are different.
BP ALL Issuers should use the same Issuer and ICC Public Keys across both
the contact and contactless interface.
Cardholder Verification
A signature or PIN is not required for a PayPass transaction less than or equal
to the chargeback protection amount. In this situation, no setting of the Service
Code for PayPass—Mag Stripe, or CVM List for PayPass—M/Chip, requires the
acquirer to obtain cardholder verification.
The issuer may elect for either Signature or Online PIN to be preferred and
personalize the CVM List accordingly. On Device Cardholder Verification is
performed above the chargeback protection amount if supported by the mobile
phone and the terminal.
If the issuer supports Maestro PayPass transactions above the ceiling limit, then:
CVM List entries should not make use of the X and Y values to influence the
availability of a particular CVM. This means that condition codes: '06', '07', '08'
or '09' should not be used.
R ALL All PayPass—M/Chip cards and mobile phones must support No CVM
in the CVM List read through the contactless interface.
R ALL PayPass—M/Chip cards and mobile phones must not support either
offline plain text PIN or offline enciphered PIN in the CVM List read
through the contactless interface.
R MC MasterCard PayPass—M/Chip cards must support Online PIN and
Signature in the CVM List read through the contactless interface.
R MC MasterCard PayPass—M/Chip mobile phones must support Signature
in the CVM List read through the contactless interface.
BP ALL Magnetic stripe based PVV methods should not be used for online PIN
verification if PIN change is supported.
The issuer should manage the offline counters and parameters for the contactless
interface during the authorization response to a contact chip transaction. They
cannot be managed during a PayPass transaction as the Issuer Authentication
Data from the authorization response is never delivered to the card.
Personalization Requirements
MasterCard prohibits encoding the cardholder name in the data read through the
contactless interface to prevent unauthorized disclosure. It is recommended to
use a space character followed by the surname separator “/” in the Track 1 Data.
Third Party Data may be used by a terminal for proprietary processing. Issuers
that intend to participate in a scheme utilizing this data object must request a
Unique Identifier from MasterCard. A sub-field of this data object is also used to
carry the Device Type. Refer to Data Requirements for more information.
R ALL CPV must be successfully completed for all PayPass cards issued.
R ALL The name of the cardholder must not be readable over the contactless
interface.
R ALL If the Third Party Data included in the PayPass card is intended to be
used to carry proprietary data, then the issuer must contact MasterCard
at [email protected] to obtain the Unique Identifier.
BP ALL Issuers should use ² /² for the cardholder name in the data read
through the contactless interface.
R ALL Non-card form factors must be personalized with the Device Type
present in the Third Party Data object.
R ALL Effective 18 October 2013, U.S. region issuers must ensure that each
newly issued or reissued PayPass-enabled card, access device, and
mobile payment device is personalized with the appropriate Device
Type value.
R ALL Effective 18 October 2014, Canada region issuers must ensure that
each newly issued or reissued PayPass-enabled card, access device,
and mobile payment device is personalized with the appropriate
Device Type value.
Data objects may be personalized in the card organized in the pre-defined file
structure detailed in the PayPass Personalization Data Specifications to allow
efficient data capture by the PayPass terminal resulting in a faster transaction.
R ALL If data objects are not organized according to the rules specified for
the pre-defined file structure, then the pre-defined values for the AFL
must not be used.
Some data elements are unique for the contactless interface and some are
shared with the contact interface.
For PayPass the issuer may operate in full chip grade, semi-grade or magnetic
stripe grade on the contact profile.
Issuers that have the capability to distinguish between chip-read and magnetic
stripe-read transactions must use a different value for Chip CVC on the
contactless interface to the CVC1 encoded on the magnetic stripe. This prevents
compromised PayPass data being used to fraudulently create valid counterfeit
magnetic stripe cards.
Maestro cards that do not have a CVC1 encoded on the magnetic stripe do not
need to include a Chip CVC.
R ALL Issuers that have the capability to distinguish between chip-read and
magnetic stripe-read transactions must support a Chip CVC in Track
2 Equivalent Data on the contactless interface that is different to the
CVC1 if present.
R ALL The genuine CVC1, as found on the physical magnetic stripe, must not
appear in any data element that can be read through the contactless
interface.
R MS Issuers of Maestro PayPass cards that do not have a Chip CVC in Track
2 Equivalent Data must ensure that the Track 2 data found on the
magnetic stripe cannot be reproduced from the PayPass data on the
chip. Some aspect of the magnetic stripe data must be unique to the
magnetic stripe, unpredictable and validated during the authorization.
If this option is chosen, the issuer must be aware of the requirements to return
the value of the embossed PAN in the response message for PayPass transit
transactions.
To protect critical data used in the transaction, if the card supports offline card
authentication then the data elements shown in the table below must be stored
in records that are signed.
1. If present
R ALL The data elements shown in the table above, if present, must all be
stored in records that are signed.
The first and only record of the file SFI 1 must include the data objects
necessary to perform the PayPass -Mag Stripe transactions.
The last digit of both Track 1 and Track 2 must not be used by the issuer as this
is used by the terminal to indicate the number of digits of the unpredictable
number (nUN). The length of the unpredictable number must not be fewer
than 2 digits.
The positions where the PayPass reader stores the ATC, UN, and CVC3 in the
discretionary data in Track 1 Data and Track 2 Data, should be filled with zeroes.
This is a requirement if PayPass On Behalf CVC validation services are used.
If the issuer intends to make use of MasterCard's On-behalf Service for dynamic
CVC3 verification, then the value of NATCTRACK1 and the value of NATCTRACK2
must be greater than or equal to 3 for the CVC3 Validation in Stand-in Service,
or greater than or equal to 2 for the dynamic CVC3 Pre-validation Service or the
PayPass Mapping Service (processing only option). In both cases, a value of at
least 4 for NATCTRACK1 and NATCTRACK2 is recommended.
Card Delivery
PayPass data can be read by any reader that can power the contactless chip
and send the correct commands.
Therefore, it is feasible that card data could be captured while the card is in
transit to the cardholder. Issuers should consider appropriate control methods
to reduce the risks and impact of card or data interception. This might be by
using a special envelope to shield card reading or by disabling the contactless
interface until the card has been activated by the cardholder.
BP ALL Issuers should ensure that contactless transactions are not possible
until the card has been activated by the cardholder.
Authorization Messages
PayPass issuers must ensure host systems are capable of correctly receiving
and processing authorization messages containing specific values for the data
element (DE) 22 (POS Entry Mode) and DE 61 (POS Data) that identify PayPass
transactions.
R ALL Issuers must support on their network interface and host system
PayPass transactions as described above.
Authorization Decisions
The issuer should take into account that bits that are not set in the TVR included
in the authorization request of a PayPass—M/Chip transaction may not always
reflect the final outcome of the terminal tests performed. An example of this is
when card authentication may have been completed after the GENERATE AC
command was issued to the card or after the TVR was signed.
As part of the authorization decision process, issuers should also consider the
number of transactions done without cardholder verification that have been
done consecutively.
BP ALL Issuers should always perform online CAM by checking that the ARQC
contained in a PayPass—M/Chip online authorization request is correct.
R ALL An authorization or clearing request may legitimately contain a TC in
DE 55 (Integrated Circuit Card [ICC] System-Related Data). Issuers must
not routinely decline transactions in this situation.
R ALL The transaction amount and the transaction date may be different in
DE 55 when compared with other fields in the authorization message.
The issuer must not routinely decline transactions in this situation.
R MC Issuers must always perform online CAM by checking that the CVC3
contained in a PayPass —Mag Stripe online authorization request is
correct.
R MC Issuers must be able to process PayPass—Mag Stripe transactions if
either Track 1 Data or Track 2 Data is present in the authorization
message.
BP ALL Issuers should manage the risk of PayPass transactions done without a
CVM that are approved consecutively.
BP ALL Issuers should adopt the authorization decision process when
appropriate for transit-based transactions.
The role of the ATC is to ensure that every cryptogram produced by a genuine
card is unique.
Issuers should not routinely decline transactions where the ATC is out of the
range that they have set or if the ATCs arrive out of sequence.
The issuer may wish to accept and process advice messages (0120) in order to
maintain up to date ATC values as part of ATC management.
Authorization Responses
Since the consumer remains in control of the PayPass card throughout the
transaction, the opportunity for merchants to pick up these cards is limited.
Issuers should not use a capture card authorization response to PayPass
transactions.
Refunds
Clearing Requirements
PayPass transactions are identified in clearing messages.
Clearing Messages
PayPass issuers must ensure host systems are capable of correctly receiving and
processing existing subfields within the clearing message containing specific
values of the data input capability and the data input profile, DE 22 (POS
Entry Code).
DE 22, subfield 7 identifies the card data input profile for this transaction and
must contain:
General Requirements
Overall general requirements for acquirers and merchants include PayPass
enrollment and acceptance.
PayPass Enrollment
R ALL Members that want to acquire PayPass transactions must enroll in the
PayPass program.
PayPass Acceptance
PayPass acceptance means that all cardholder devices are valid for acceptance
at terminals, not just PayPass cards.
• Must not accept Maestro in PayPass—Mag Stripe mode. The terminal may
support PayPass—Mag Stripe for MasterCard.
• Must support PayPass—M/Chip transactions
A terminal that supports magnetic stripe and EMV chip contact transactions
(hybrid terminal) that also supports PayPass should support PayPass—M/Chip.
An updated list of countries and merchant categories that are allowed to accept
PayPass only is maintained in the MasterCard Rules and Maestro Global Rules.
Terminals
Acquirers and merchants must only use approved PayPass terminals.
R ALL Acquirers must only deploy terminals that have successfully completed
the MasterCard PayPass vendor product approval process. Approvals
are only given to properly licensed vendors.
Reader Specifications
Terminal Branding
In order to give the cardholder clear information as to where to tap the PayPass
device on the PayPass terminal, acquirers must use the PayPass landing zone.
The landing zone must indicate with the contactless identifier where the
cardholder has to tap or hold the MasterCard PayPass card.
If space permits, MasterCard PayPass and other scheme branding may also be
placed on the landing zone as long as branding rules are maintained and the
contactless symbol is not obscured in any way. If space on the landing zone
does not allow room for scheme branding, then it should be placed elsewhere
at the point of interaction. It should not distract the customer from identifying
the contactless symbol and the landing zone.
When the interaction with the card is successfully completed, the reader
provides a visible and audible indication of a successful PayPass interaction to
the cardholder. The visible and audible cues confirm the card can be removed,
but not that transaction is approved or completed.
BP ALL The PayPass reader should be included in the PIN Entry Device to
minimize the terminal footprint.
BP ALL The payment amount should be made automatically available to the
PayPass terminal by the electronic cash register. The amount should
not have to be entered manually.
R ALL The terminal must use visible and audible cues to the cardholder that
the PayPass interaction has been successful and is complete.
Any automation of the above visual checks by the POS system, such as Swipe
and Verify checks, must be capable of being overridden or disabled for the
acceptance of PayPass transactions.
Transaction Types
Payment
Terminals may support cash back for MasterCard PayPass, according to the
product rules. Cardholder verification and online authorization are always
required for Purchase with Cash Back transactions.
Terminals must not support cash back for Maestro PayPass transactions.
Refunds
Acquirers must be able to process refund transactions initiated via the contactless
interface. A refund must be to the same account as the original transaction.
If card refunds are supported by a merchant that has deployed at least one
contactless terminal, then refunds initiated through the contactless interface
must be supported. Merchant support for PayPass refunds is recommended at a
minimum of one PayPass enabled terminal in a merchant location.
Gratuities
PayPass Limits
Transactions less than or equal to the Terminal CVM Required Limit do not
require cardholder verification and, unless specifically requested by the
cardholder, do not require a printed receipt. For PayPass transactions above
the Terminal CVM Required Limit, normal cardholder verification and receipt
printing procedures apply.
1. Acquirers should be aware that the transaction limits discussed here are managed and supported
differently in the different versions of the PayPass—M/Chip reader.
Transactions less than or equal to the Terminal CVM Required Limit do not
require cardholder verification.
Transactions greater than the Terminal CVM Required Limit require cardholder
verification.
For MasterCard PayPass, the Chargeback Guide lists the chargeback protection
amounts to be used in each market. The relevant value should be used to
configure the Terminal CVM Required Limit.
For Maestro PayPass, the Maestro Global Rules lists the ceiling limits to be used
in each market. The relevant value should be used to configure the Terminal
CVM Required Limit.
Terminals that allow transactions above the Terminal CVM Required Limit must
not support No CVM above this limit.
BP ALL Transactions greater than the Terminal Contactless Floor Limit should
be authorized online by the issuer.
For Maestro PayPass, in a given market, one of the following scenarios will
apply:
Details of the markets where transactions above the ceiling limit are allowed
are shown in the Maestro Global Rules.
If the cardholder chooses to use PayPass, and both the card and terminal
support PayPass—M/Chip, then this mode must be used to complete the
transaction.
Data Usage
PayPass acquirers must only use data read from the contactless interface for
PayPass transactions. Data obtained from the contactless interface must not be
used for another payment transaction type.
R ALL Data read from the contactless interface must not be used for payment
transactions other than PayPass. This restriction does not include
refunds and transit debt recovery.
Acquirers should also be aware that any merchant data written to a card during
a transaction may be retrieved later by a third party. The data stored must
therefore respect local privacy laws.
For PayPass—Mag Stripe transactions, some POS systems collect Track 1 data,
truncate it, and process it as Track 2. PayPass Track 1 and Track 2 data may be
different. For this reason, merchants and acquirers must make sure that Track 1
data is processed as Track 1 and Track 2 data is processed as Track 2. If data
from one track is presented as the other, this may cause the transaction to be
rejected by the card issuer as the dynamic CVC3 cannot be verified correctly.
R ALL Merchants and acquirers must make sure that Track 1 Data is processed
as Track 1 and Track 2 Data is processed as Track 2.
R ALL Track 2 Equivalent Data must be used in the authorization request
for PayPass—M/Chip transactions.
Service Codes
MasterCard PayPass issuers may choose to use service code values in the
PayPass data different from those typically used for magnetic stripe cards.
A service code read during the PayPass transaction that indicates the presence
of a chip card does not mean that the terminal must prompt for an EMV contact
chip transaction.
A service code read during the PayPass transaction indicating that PIN is
required does not mean that PIN is required for a PayPass transaction below
the chargeback protection amount.
A service code read during the PayPass transaction indicating that the
transaction must be processed online does not mean that the terminal must
seek online authorization for transactions below the appropriate floor limit.
R ALL Terminals must not prompt for an EMV contact chip transaction just
because the service code read during the PayPass transaction indicates
a chip is present on the card.
R ALL Terminals must not prompt for PIN for transactions less than or equal
to the chargeback protection amount just because the service code
read during the PayPass transaction indicates that a PIN is required.
R ALL Terminals must not seek online authorization just because the service
code read during the PayPass transaction indicates that the card is
online only.
Cardholder Name
PayPass cards must not include the cardholder name in the data read through
the contactless interface. POS systems that normally obtain and make use of the
cardholder name from Track 1 data obtained from a magnetic stripe read must
be able to accommodate this difference.
R ALL Terminals that process Track 1 data must be able to handle the data
without a fully populated cardholder name.
Application Selection
The AID value used for PayPass is the same AID used for the contact interface.
There are no specific AIDs for PayPass.
• MasterCard ‘A0000000041010’
• Maestro ‘A0000000043060’
The payment system public keys for PayPass—M/Chip are the same values and
may be shared with those used for MasterCard EMV contact chip transactions.
Terminals must contain all current keys and must be able to store up to six CA
Public Keys per RID.
The terminal must associate each key with the following key-related information
that is used with the key.
R ALL All offline capable PayPass—M/Chip terminals must hold all the active
and current MasterCard public keys.
R ALL Terminals must only accept keys that the terminal can authenticate as
originating from the genuine acquirer.
R ALL Acquirers must be able to verify that all the appropriate keys are loaded
into all terminals that generate transactions which they acquire.
R ALL Terminals must not hold test public keys that might be used for live
transactions.
This table shows the Payment System Public Keys that are currently in use.
Key lengths and expiration dates are reviewed annually. MasterCard notifies
members of any changes in the Global Security Bulletin.
There is no requirement to store the expiry date of keys in the terminal. Expired
keys must be removed from terminals within six months. Where keys are held
in the terminals with an expiry date, it is imperative that keys remain valid until
the published expiry date, as amended from time to time.
Cardholder Verification
Cardholder verification is not required for a PayPass transaction less than or
equal to the chargeback protection amount.
Maestro terminals that accept contactless transactions above the ceiling limit
with cardholder verification must not accept transactions above the ceiling
limit with no cardholder verification.
NOTE
There are some MCCs where no CVM has been part of the product proposition
above the chargeback protection amount up to a specific transaction limit:
tollways, parking, etc.
For Maestro PayPass, attended terminals that support transactions above the
ceiling limit:
• Online PIN
• On Device Cardholder Verification
Acquirers and merchants that currently support Online PIN should also support
On Device Cardholder Verification.
The use of No CVM must be positively identified by the EMV process. It does
not mean skip CVM processing.
PayPass terminals must not support offline PIN on the contactless interface.
Offline PIN may be supported at the same terminal but only for EMV contact
chip transactions. Terminals must ensure that offline PIN is never selected as
the CVM for a PayPass transaction.
CAT Level 1 terminals must support online PIN for all PayPass transactions, and
may also support On Device Cardholder Verification.
CAT Level 2 and CAT Level 3 terminals must use No CVM for all PayPass
transactions.
R ALL CAT Level 1 terminals must support online PIN and may also support
On Device Cardholder Verification.
R ALL CAT Level 2 and CAT Level 3 terminals must support only No CVM
for PayPass transactions.
When online PIN is used to verify the cardholder, if the authorization is declined
by the issuer because the PIN is incorrect, the transaction should be restarted
and the cardholder prompted to re-enter their PIN.
When online PIN is the chosen cardholder verification method for the
transaction, the PIN must be entered or the transaction will be terminated. This
is because PIN entry is canceled or the terminal has timed out.
R ALL While waiting for PIN entry, if PIN entry is canceled by the cardholder
or merchant or if the terminal times out, then the transaction must
be terminated.
PayPass terminals may perform a cumulative floor limit check by adding the
last transaction in the terminal log file, if present and if performed by the
same card, to the current transaction amount and comparing the total with
the Terminal Contactless Floor Limit.
The mandatory TACs used for PayPass purchase transactions are provided
in Data Requirements.
If the terminal supports EMV contact chip transactions, the terminal must
maintain the PayPass TACs independently.
R ALL The terminal must maintain TACs for use in PayPass transactions
independent of other interfaces.
Authorization Responses
If a response to an authorization is not received, transactions are approved
at the acquirer¢s risk.
Cardholder Receipts
For transactions less than or equal to the Terminal CVM Required Limit, a
PayPass merchant, card acceptor, must make a receipt available if requested by
the cardholder. This means the facility to produce receipts must be available
unless some special circumstances apply. Refer to MasterCard Rules and
Maestro Global Rules for exemptions.
Receipts may be offered at the end of a transaction, rather than the cardholder
or merchant needing to confirm if they would like a receipt before continuing.
Above the Terminal CVM Required Limit, a receipt must always be provided if
the terminal has that capability.
Any receipt should specifically identify PayPass transactions. The input method
should be shown as Contactless, CONTACTLESS, or RF for PayPass transactions.
R ALL A cardholder receipt must be available for transactions less than the
chargeback protection amount on cardholder request if the terminal
supports receipt printing.
R ALL A cardholder receipt must be provided for transactions above the
chargeback protection amount if the terminal supports receipt printing.
BP ALL Terminals should not routinely produce receipts for transactions less
than the chargeback protection amount.
BP ALL Cardholder receipts should identify contactless transactions by
indicating 'Contactless', 'CONTACTLESS' or 'RF'.
The new transaction may be attempted using a different card read method
supported by both the card and the terminal in the order of preference of:
Terminated Transactions
A terminal may allow a merchant to cancel a transaction:
OR
BP ALL The terminal should take appropriate measures to reduce the risks of
an attack using aborted transactions.
• For CAT Level 1 terminals, the CVM is either Online PIN or On Device
Cardholder Verification as offline PIN is not supported for PayPass and
signature is not possible at an unattended terminal
• For CAT Level 2, Level 3, and Level 4 terminals, it is recommended that the
Terminal CVM Required Limit and Terminal Contactless Transaction Limit
be set to the maximum allowed transaction value appropriate for these
devices, and where indicated in the Chargeback Guide
Vending Machines
PayPass-only payment acceptance is permitted on vending machines identified
with Merchant Category Code 5499.
Such vending machines can operate with one of two possible purchasing
processes:
Acquirers should note that only PayPass readers installed on vending machines
using a “select first” ordering and payment process will be capable of supporting
both online and offline authorization of contactless transactions. Such readers
may also behave as offline only or online only.
Data Elements
Acquirer databases must also identify the terminal as being PayPass capable.
This impacts DE 61 and DE 22 in authorization messages and DE 22 in clearing
messages. Other data elements contain the same data values as for existing
transactions.
OR
Authorization Performance
The benefits of MasterCard PayPass are maximized when used with high-speed
authorization lines.
Authorization Responses
Service Codes
MasterCard PayPass issuers may choose to use service code values in the
PayPass application different from those typically used for magnetic stripe
cards. For this reason acquirers need to ensure that all processing systems
support all service codes.
BP ALL Acquirers should ensure that processing systems support all service
codes that could be used in PayPass transactions.
Authorization Requirements
Specific values in existing subfields within the authorization message specify
the terminal capability, DE 61, and the profile of operation, DE 22.
Authorization Messages
Terminals and other parts of the acquirer system must be able to determine
when transaction data has been obtained using the contactless interface in
order to properly process and identify the transaction to the issuer.
Acquirers should capture the Device Type indicator where present on a PayPass
device and send this to the issuer in DE 48 (Additonal Data), subelement 23
(Payment Initiation Channel). The Device Type indicator may be included in
the Third Party Data.
R ALL Acquirers must process on their network interface and host system
PayPass transactions as described above.
R ALL Acquirers must be full grade.
BP ALL Acquirers should include the Device Type indicator, where present, in
the authorization message.
R ALL If the Device Type is retrieved in a PayPass transaction, U.S. region
acquirers must transmit it in DE 48 of authorization messages.
R ALL Effective 18 October 2014, if the Device Type is retrieved in a PayPass
transaction, Canada region acquirers must transmit it in DE 48 of
authorization messages.
Clearing Requirements
Clearing Messages
Specific values in existing subfields within the clearing message specify the
data input capability and the data input profile, DE 22. PayPass transactions
require new values in these subfields.
DE 22, subfield 7 identifies the card data input profile for this transaction and
must contain:
R ALL Acquirers must process on their clearing interface and host system
PayPass transactions as described above.
BP ALL If the Device Type is retrieved from the card during a transaction,
acquirers should include it in private data subelement (PDS) 0198 of
the First Presentment/1240 message.
Exception Processing
Acquirers do not need to fulfill a retrieval request for a transaction identified as
a PayPass transaction that is equal to or less than the chargeback protection
amount, except in certain transit situations.
On-behalf Services
MasterCard offers the PayPass Mapping Service—an optional service that helps
issuers process different PayPass account numbers by translating them into
primary account numbers that can be processed with minimal impact.
MasterCard and Maestro PayPass Terminal Action Codes for Online Capable Terminals
4 New Card 0 0 0
3–1 RFU 0 0 0
Byte 3 8 Cardholder verification failed (see 0 1 1
exception below)
7 Unrecognized CVM 0 0 0
6 UCOL exceeded 0 0 0
3–1 RFU 0 0 0
Byte 5 8 Default TDOL used 0 0 0
7 Issuer Authentication Unsuccessful 0 0 0
4–1 RFU 0 0 0
For Maestro PayPass in markets that support Online PIN for transactions greater
than the ceiling limit, the following settings must be used:
MasterCard and Maestro PayPass Terminal Action Codes for Offline Only Terminals
4 New Card 0 0 0
3–1 RFU 0 0 0
Byte 3 8 Cardholder verification failed 1 0 0
7 Unrecognized CVM 0 0 0
2–1 RFU 0 0 0
6 UCOL exceeded 0 0 0
3–1 RFU 0 0 0
Byte 5 8 Default TDOL used 0 0 0
7 Issuer Authentication Unsuccessful 0 0 0
4–1 RFU 0 0 0
All length indications are given in bytes. Data object formats are binary (b)
or alphanumeric (an).
Tag '9F6E'
Length 5–32
Format b
Descriptions The Third Party Data contains proprietary information from a third
party and is coded as shown below. If present in the PayPass card, the
Third Party Data is returned in the File Control Information Template.
The Device Type subfield is present when the most significant bit of
byte 1 of the Unique Identifier is set to 0b. In this case, the maximum
length of the Proprietary Data field is 26 bytes.
Third Party Data may be used to communicate the Device Type to the
terminal, even when there is no Proprietary Data being used. In this
case a static, default value of '0000' for the Unique Identifier is used.
Device Type
Device Value
Card 00 (NB ASCII value coded as
'3030')
Mobile Network Operator (MNO) or controlled 01
removable secure element (SIM or UICC)
personalized for use with a Mobile Phone or a
Smartphone1
Key Fob 02
Watch 03
Mobile Tag 04
Wristband 05
1. As removable secure elements (SE) may be moved from a mobile phone to a tablet or eBook by the
consumer, this value represent the initial intended use of this SE.
Device Value
Mobile Phone Case or Sleeve 06
Mobile Phone or Smartphone with a permanent 07
secure element controlled by the MNO, for
example CDMA
Removable secure element not controlled by the 08
MNO, for example SD Card personalized for use
with a Mobile Phone or Smartphone1
Mobile Phone or Smartphone with a permanent 09
secure element not controlled by the MNO
MNO controlled removable secure element (SIM 10
or UICC) personalized for use with a tablet or
eBook
Tablet or eBook with a permanent secure element 11
controlled by the MNO
Removable permanent element not controlled by 12
the MNO, for example SD Card personalized for
use with a tablet or eBook
Tablet or eBook with a permanent secure element 13
not controlled by the MNO
Reserved for future use 14–99
Tag '9F5D'
Length 3
Format b
Descriptions The Application Capabilities Information is an optional data
object included in the File Control Information Template of the
PayPass Card. It lists a number of card features beyond regular
payment and is coded as defined below.
b1 CDA Indicator
0: CDA SUPPORTED AS IN EMV
1: CDA SUPPORTED OVER TC, ARQC AND AAC
Byte 3 b8-1 SDS Scheme Indicator
00000000: Undefined SDS configuration
00000001: All 10 tags 32 bytes
Abbreviations................................................................................................................................. 6-1
Abbreviations
Abbreviation Description