02.02.2013 Views

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Europe Region<br />

8.4 PIN and Key Management Security Requirements<br />

If the Transaction is processed via a different network or processing<br />

arrangement than the Interchange System (including bilateral and on-us<br />

processing), the Acquirer must ensure that corresponding data elements contain<br />

values that allow issuers to clearly identify the Transaction as a <strong>Maestro</strong> PayPass<br />

Transaction.<br />

Regardless of processing arrangement, all Customers using the PayPass<br />

technology must have been granted the appropriate PayPass licenses as<br />

required in Chapter 21 of this rulebook.<br />

8.4 PIN and Key Management Security Requirements<br />

8.4.1 PIN Verification<br />

In addition to the <strong>Rules</strong> in Chapter 8, “Security,” Rule 8.4.1 in part 1 of this<br />

rulebook, the following apply:<br />

Refer to the Authorization Manual, Chapter 12, “PIN Processing for Europe<br />

Region Customers” for information about PIN validation by the Dual Message<br />

System in the Europe region.<br />

8.4.2 Stand-In Authorization<br />

If authorization is done by the Dual Message System on behalf of the Issuer,<br />

the identification of the Cardholder is based on a cryptographic transformation<br />

performed in the <strong>MasterCard</strong> Host Security Module of data encoded on ISO<br />

track 2 in combination with the PIN entered by the Cardholder. The algorithm<br />

produces a PIN Verification Value (PVV) that is to be compared with the value<br />

obtained from the Card. Positive identification is achieved if both values are<br />

identical.<br />

To verify a PIN, the following Card data must be present:<br />

1. PAN; and<br />

2. expiration year and month.<br />

8.9 Account Data Compromise Events<br />

8.9.4 Corporation Determination of ADC Event or Potential<br />

ADC Event<br />

8.9.4.2 Potential Reduction of Financial Responsibility<br />

In addition to the <strong>Rules</strong> in Chapter 8, “Security,” Rule 8.9.4.2 in part 1 of this<br />

rulebook, the following applies:<br />

©1993–2012 <strong>MasterCard</strong>. Proprietary. All rights reserved.<br />

17-48 9 November 2012 • <strong>Maestro</strong> <strong>Global</strong> <strong>Rules</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!