MULTOS
A high-security, multi-application smart card platform designed by banks for banks. An on-chip virtual machine and a public-key security scheme let several applications coexist safely on one device. It is not test equipment: it is a card platform on the device under test.
What MULTOS is
A security technology for smart cards and connected devices. Applications as varied as payment, authentication, digital identity, loyalty and access control run on MULTOS chips, deployed in cards, wearables and connected devices of many kinds. In payments it is described as the only high-security multi-application platform designed by banks, built on the safe coexistence of several applications.
| Item | Detail |
|---|---|
| Category | Smart card operating system (card platform) |
| Memory | Up to 160 k |
| Cryptography | RSA / ECC / 3DES / AES / SHA-1 / SHA-2 |
| Security certification | Common Criteria EAL6+ High, with the virtual machine at EAL7 |
| Supported protocols | ISO 7816 / ISO 14443 Type A / Type B |
| Track record | More than 25 years in secure smart cards |
| Form | Cards, passive wristbands, contactless tags and active contactless devices |
Architecture
MULTOS is built from two technologies: an on-chip virtual machine that runs the applications, and the MULTOS security scheme that protects the chip, the application code and the application data.
| Element | Detail |
|---|---|
| Development language | C and Java, or low-level assembly language |
| Execution format | Compiled to MEL, MULTOS Executable Language, bytecode and run by the virtual machine |
| Runtime checking | The virtual machine rejects invalid instructions and memory accesses, halting the application |
| Application separation | One application cannot access the data of another on the same card |
| Compatibility | A standard virtual machine and a standard set of primitive functions make applications fully compatible across MULTOS and MULTOS step/one products from different vendors |
| Quality assurance | Every product undergoes type approval for conformance to the specification and for implementation security |
Secure loading with the ALU
What distinguishes the MULTOS security architecture is that applications and data can be loaded securely even in an insecure environment. This suits instant issuance, mobile payment and post-issuance updates.
| Steps | Detail |
|---|---|
| 1 | Each device holds its own RSA key pair, generated and certified by the Key Management Authority and loaded securely when the device is activated |
| 2 | Using the public key, data preparation software encrypts the Application Load Unit in a secure environment such as a personalisation bureau |
| 3 | The ALU contains both the application code and the personalisation data |
| 4 | Only the intended MULTOS device can decrypt the ALU |
| 5 | All cryptographic processing takes place inside the device, so neither external cryptographic equipment nor a secure channel is required |
Because the scheme uses public keys, no symmetric key has to be shared. The issuer controls the whole lifecycle, which strengthens supply chain control and lowers total cost of ownership.
EMV payment support
EMV solutions are available for the major payment networks — Mastercard, Visa, American Express, Discover and JCB — across contact, contactless and dual interface.
| Application | Detail |
|---|---|
| MICA | The Mastercard Integrated Card Application. It supports Mastercard Pre-Authorised, CAP (Chip Authentication Programme) and AA4C (Advanced Authentication For Chip). Combined with a contactless platform it supports PayPass and mass transit |
| VSDC for MULTOS | Conforms to the latest VIS specification, supporting Visa payWave on contactless and dual-interface cards |
| MULTOS step/one | For rolling out an EMV programme quickly using static data authentication, as a low-cost starting point |
Domestic schemes and additional applications
Domestic payment applications can be carried alongside the off-the-shelf international scheme applications, with features such as a PIN shared across every application.
| Region | Application |
|---|---|
| Japan | JBA |
| Canada | Interac |
| Saudi Arabia | SPAN |
| Korea | K-Cash / TMoney |
| Taiwan | FISC |
| France | B0’ / Moneo |
| Brazil | Banricompras |
It also suits mass transit, where a transit application and an EMV payment application coexist on a single contactless or dual-interface card. Further applications such as loyalty, coupons, secure data storage and online banking tools can be deployed on the same card.
Other card formats
| Form | Detail |
|---|---|
| Dynamic CVV cards | A dynamic security code on the card strengthens fraud prevention in e-commerce and card-not-present transactions |
| Biometric cards | The biometric template is held on the card for one-to-one matching without a database connection, completing the comparison on the card itself |
| Materials | From sustainable materials such as recycled plastic and wood through to metal cards |
| Contactless devices | Passive wristbands, contactless tags and active contactless payment devices |
Where this sits on this site
Most of the products on this site are test equipment used to verify things. MULTOS is on the side being verified — the device under test. Like the Alcinéo EMV kernels, it sits on a separate axis.
| Axis | Vendors | Role |
|---|---|---|
| Test equipment | KEOLABS/ICC Solutions/Barnes/B2 | Verifying cards and terminals |
| Embedded runtime | Alcinéo | EMV kernels embedded in the terminal |
| Card platform | MULTOS (this page) | The operating system on the card |
| Test laboratories | Bureau Veritas ICTK | performs testing and prepares the test report |
Used with Barnes P3
Barnes P3 in an instant issuance configuration, the MULTOS card serves as the platform on the card side. Because ALU loading works even in an insecure environment, it suits issuance in a branch or store. Barnes Smart Solutions is a member of the MULTOS Consortium.
| Element | Role |
|---|---|
| Barnes P3 | Securely manages and generates cryptographic keys and EMV data |
| Card printer | Writes the name, number and secure chip data to the card |
| MULTOS card | EMV card platform |
To verify this device under test
To verify a MULTOS card itself, or the applications carried on it, consider the following products according to the stage of the process.
| What you want to verify | Product |
|---|---|
| Whether the issuance data and personalisation are correct | Barnes CPT 3000v3/CPT 3000v3CL |
| The behaviour of bespoke and multi-application cards | Barnes CAT 3000v3 (Tcl script development) |
| Pre-certification before submission to the scheme | Barnes certification test modules |
| RF characteristics and protocol conformance (contactless) | ProxiLAB Quest/ProxiSPY Quest |
| Analysis of the contact protocol | ContactLAB/SPY 3000 |
| Certification (test laboratory) | Bureau Veritas ICTK |
Points to note
This page summarises the card platform based on information published by the manufacturer at multos.com. For procurement of MULTOS cards, supported chips, application development, licence terms and KMA operation, we advise individually once we understand your use case. MULTOS is run as a consortium whose members include Mastercard, Discover, Infineon, STMicroelectronics, Thales, IDEMIA, G+D, Entrust, Fiserv, FIS and Barnes Smart Solutions. For detail, see multos.com.
