← Payment Systems: Magstripe, Tokenization, NFC and EMV
Level 4 · Researcher120 min
The authorisation leg: from cryptogram to decision
The card signs an amount it cannot verify, and the message that carries it restates that amount in a second place nobody signed. Following one cryptogram out through field 55 to the issuer and back as an ARPC — and a real message that admits nineteen different readings.
Enrolment required
Module 1 of this course is free to read. The rest needs an enrolment — and so does nothing else on this site: the workbench, the APDU decoder and the whole capture corpus stay open to everyone, signed in or not.
What this module covers
- 01The round trip, end to end
- 02The twenty-nine bytes the card signed
- 03Field 55: where EMV crosses into ISO 8583
- 04The amount travels twice
- 05The issuer's answer, and what proves it
- 06The card's last word
- 07Matching, and the identifier that does not exist
- 08Authorising is not paying
- 09Stand-in: when the issuer never sees it
- 10Reversals, repeats, and the idempotency problem
- 11The dialect problem, demonstrated
- 12What to actually test
- 13Where this stops being settled