← Payment Systems: Magstripe, Tokenization, NFC and EMV
Level 4 · Researcher120 min
The authorization leg: from cryptogram to decision
The card signs an amount it cannot verify, and the message that carries it restates that amount in a second place nobody signed. Following one cryptogram out through field 55 to the issuer and back as an ARPC, and a real message that admits nineteen different readings.
Enrollment required
Module 1 of this course is free to read. The rest needs an enrollment: one payment, access for life, updates and new research included. Nothing else on this site needs one: the workbench, the APDU decoder and the whole capture corpus stay open to everyone, signed in or not.
What this module covers
- 01The round trip, end to end
- 02The twenty-nine bytes the card signed
- 03Field 55: where EMV crosses into ISO 8583
- 04The amount travels twice
- 05The issuer's answer, and what proves it
- 06The card's last word
- 07Matching a response to its request
- 08Authorizing is not paying
- 09Stand-in: when the issuer never sees it
- 10Reversals and repeats
- 11The dialect problem, demonstrated
- 12What to actually test
- 13The open question