Offline data authentication, ARQC generation, and issuer ARPC validation in one card-present transaction
Guided views
Explore this system
Step through curated paths without changing the source diagram.
Beat
Next
ReadyChapter 01 / 01
Guided chapter
Diagram guideExplore this system
Inspecting compiled semantics
E ExportT ThemeS Style0 Reset+ Zoom in- Zoom outEsc Close
Find a node
⌕/
No matching nodes
Semantic passport
Verified source
Authored reach
Route probeChoose a start node
Pick two semantic nodes on the diagram
Choose the source, then the destination. Direction matters.
Semantic lensCompare system roles
Choose up to two semantic kinds. One reveals its real traffic; two compare only direct authored relationships.
Choose a kind to inspect its nodes and touching relationships.
Semantic radar
Building overview
Click nodeDrag to pan
Per-transaction proof
• The ATC counter guarantees every cryptogram is unique
• ARQC is a MAC over transaction data with a derived key
• Replaying a captured ARQC fails the next counter check
Offline authentication
• SDA verifies issuer-signed static data with a CA public key
• DDA/CDA add a fresh card-signed dynamic signature
• CDA binds the signature to the generated cryptogram
Issuer response
• Issuer recomputes the ARQC inside an HSM to validate it
• ARPC proves the response genuinely came from the issuer
• Final TC settles the transaction for clearing
Sequence diagram • Built with Archify • Create yours ↗ • Hover to trace • R route • Click to focus • +/− zoom • M radar • [/] views • P play story • T theme • E export