March 28, 2019
EMVCo, the industry body responsible for advancing the use of EMV and its specifications, has announced that it is working to promote confidence and consistency in the deployment of the consumer device cardholder verification method by identifying and addressing specific security, functional and performance needs for CDCVM.
Cardholder verification has traditionally been performed through consumer authentication on the merchant system — for instance, via a PIN entered into a merchant device. However, the growing use of mobile devices for payment transactions has resulted in consumer authentication more often being performed on the consumer’s own device, a type of authentication known as CDCVM. (When multiple payment applications on the device share the same CDCVM and associated result, it is referred to as Shared CDCVM.)
As CDCVM is very different to traditional CVM, EMVCo has developed a dedicated process to evaluate the security of CDCVM solutions and has defined industry best practices to address functional and performance considerations. These include:
As part of its ongoing collaboration with the Fido Alliance, EMVCo shared a number of CDCVM use-cases for payment which the FIDO Alliance took into consideration in developing its specification. CDCVM solution providers are encouraged to evaluate the performance of their solutions using the FIDO Alliance Biometric Certification program.
Learn more about CDCVM.