Skip to content
SMAcademy
Sign in
Payment Systems: Magstripe, Tokenization, NFC and EMV
Level 4 · Researcher120 min

The authorization leg: from cryptogram to decision

The card signs an amount it cannot verify, and the message that carries it restates that amount in a second place nobody signed. Following one cryptogram out through field 55 to the issuer and back as an ARPC, and a real message that admits nineteen different readings.

Enrollment required

Module 1 of this course is free to read. The rest needs an enrollment: one payment, access for life, updates and new research included. Nothing else on this site needs one: the workbench, the APDU decoder and the whole capture corpus stay open to everyone, signed in or not.

Sign inAbout enrollmentThe workbench and decoder are free

What this module covers

  1. 01The round trip, end to end
  2. 02The twenty-nine bytes the card signed
  3. 03Field 55: where EMV crosses into ISO 8583
  4. 04The amount travels twice
  5. 05The issuer's answer, and what proves it
  6. 06The card's last word
  7. 07Matching a response to its request
  8. 08Authorizing is not paying
  9. 09Stand-in: when the issuer never sees it
  10. 10Reversals and repeats
  11. 11The dialect problem, demonstrated
  12. 12What to actually test
  13. 13The open question