EMV Cryptogram Exchange

Offline data authentication, ARQC generation, and issuer ARPC validation in one card-present transaction

EMV Cryptogram Exchange Offline data authentication, ARQC generation, and issuer ARPC validation in one card-present transaction SELECT AID read records + SDA/DDA data GENERATE AC (CDOL1) ARQC + ATC online auth request validate ARQC -> ARPC EXTERNAL AUTHENTICATE (ARPC) 2nd GENERATE AC -> TC Offline auth Cryptogram Online + ARPC Card · chip / ICC · Sequence participant Card chip / ICC Terminal · POS reader · Sequence participant Terminal POS reader Issuer · host + HSM · Sequence participant Issuer host + HSM Legend request return security async trace

Per-transaction proof

  • • The ATC counter guarantees every cryptogram is unique
  • • ARQC is a MAC over transaction data with a derived key
  • • Replaying a captured ARQC fails the next counter check

Offline authentication

  • • SDA verifies issuer-signed static data with a CA public key
  • • DDA/CDA add a fresh card-signed dynamic signature
  • • CDA binds the signature to the generated cryptogram

Issuer response

  • • Issuer recomputes the ARQC inside an HSM to validate it
  • • ARPC proves the response genuinely came from the issuer
  • • Final TC settles the transaction for clearing