Disclosure: As an Amazon Associate, CardWise earns from qualifying purchases at no additional cost to you. This does not affect our recommendations.

How to Visualize Contactless Payment Flow — EMV Contactless Transaction Flow

A contactless EMV payment happens in under 300ms, but it's a multi-step protocol exchange involving card detection, application selection, data retrieval, risk management, and cryptographic proof. This guide walks through every APDU exchanged during a Mastercard PayPass / Visa payWave / Amex ExpressPay transaction, with byte-level protocol traces.

1. The 7 Steps of a Contactless Payment

READER → CARD
[ISO 14443-3 Anti-Collision] REQA / ATQA, SELECT / SAK
Card is detected, UID is read. ATQA identifies chip family (MIFARE DESFire / JCOP for payment cards).
READER ➠ CARD (PPSE)
00 A4 04 00 0E 32 50 41 59 2E 53 59 53 2E 44 44 46 30 31 00
SELECT PPSE: "2PAY.SYS.DDF01". Returns list of supported payment AIDs.
READER ➠ CARD (SELECT AID)
00 A4 04 00 07 A0 00 00 00 04 10 10 00
SELECT Mastercard AID (or A0000000031010 for Visa). FCI response includes PDOL, application label, priority indicator.
READER ➠ CARD (GPO)
80 A8 00 00 02 83 00 00
GET PROCESSING OPTIONS with PDOL data. Response: AFL (which records to read) + AIP (card risk features).
READER ➠ CARD (READ RECORD × N)
00 B2 01 0C 00
Read each AFL entry (SFI + record range). Retrieves PAN, expiry, track 2 equivalent, CDOL1, CVM List, issuer data.
READER ➠ CARD (GENERATE AC)
80 AE 80 00 1D [CDOL1 data] 00
GENERATE AC request (ARQC). Card computes cryptogram over CDOL1 data. Response: CID + ATC + ARQC (8 bytes) + IAD.
CARD ➠ ISSUER → READER (Optional Online)
[Issuer validates ARQC, returns ARPC + authorization code]
Online authorization: ARQC sent to issuer host. Issuer returns ARPC + ARC (00=approved, 05=declined). Optional EXTERNAL AUTHENTICATE.

2. Step-by-Step APDU Trace (Real Mastercard PayPass)

=== Step 1: Anti-Collision ===
ATQA: 03 44 → DESFire/JCOP (ISO 14443-4)
SAK:  20    → ISO 14443-4 compliant, RATS required

=== Step 2: SELECT PPSE ===
>> 00 A4 04 00 0E 32 50 41 59 2E 53 59 53 2E 44 44 46 30 31 00
<< 6F 23 84 0E 32 50 41 59 2E 53 59 53 2E 44 44 46 30 31
    A5 11 BF 0C 0E 61 0C 4F 07 A0 00 00 00 04 10 10
    87 01 01 90 00
# FCI: PPSE DF name, directory entry for Mastercard AID (A0000000041010)
# Priority bit in 0x87: card supports this AID for contactless

=== Step 3: SELECT Mastercard AID ===
>> 00 A4 04 00 07 A0 00 00 00 04 10 10 00
<< 6F 43 84 07 A0 00 00 00 04 10 10
    A5 38 9F 38 18 9F 66 04 ... [PDOL: 9F66 04, 9F02 06, ...]
    5F 2D 04 65 6E 65 73 90 00  # Language preference: "enes"
# PDOL tells terminal what data to include in GPO

=== Step 4: GET PROCESSING OPTIONS (with PDOL data) ===
# PDOL data: TTQ (9F66) = 0x26000000, Amount (9F02) = 0x000000001000, ...
>> 80 A8 00 00 0C 83 0A 26 00 00 00 00 00 00 00 10 00 00
<< 77 18 82 02 02 00 94 08 08 01 01 00 10 02 03 00
    90 00
# AIP: 02 00 (Contactless MSD, no CDA)
# AFL: 08 01 01 00 10 02 03 00 → SFI 1: record 1, SFI 2: records 2-3

=== Step 5: READ RECORD (AFL entry 1) ===
>> 00 B2 01 0C 00  # SFI 1, Record 1, P2=0C (read record 1 from SFI 1)
<< 70 5A 9F 6C 02 00 01 ... [Track 2 equivalent, PAN masked]
    5A 08 54 13 12 34 56 78 90 00  # PAN (5A), 8 bytes
    5F 24 03 25 12 31  # Expiry: 12/25
    90 00

=== Step 6: GENERATE AC (ARQC) ===
# CDOL1 from card: 9F02 06, 9F03 06, 9F1A 02, 95 05, 5F2A 02, 9A 03, 9C 01, 9F37 04
# CDOL1 data assembled by terminal
>> 80 AE 80 00 1E [30 bytes CDOL1 data] 00
<< 80 00 B7 A1 34 2F C8 D6 89 12 45 E3  ... [IAD: 14 bytes]
    90 00
# CID=0x80 (ARQC), ATC=0x00B7 (183), ARQC=8 bytes, IAD=14 bytes
# Card requests online authorization

=== Step 7: Issuer validates ARQC, returns ARPC ===
# (Off-card step — terminal sends ARQC to acquirer/issuer)
# If online: EXTERNAL AUTHENTICATE with issuer ARPC
>> 00 82 00 00 08 [ARPC 8 bytes]
<< 90 00 → Card accepts issuer authentication

3. Contactless Kernel Differences

FeatureVisa VCPSMastercard PayPassAmex ExpressPayDiscover D-PAS
PPSERequiredRequiredRequiredRequired
CVMCDCVM, Online PIN, SignatureCDCVM, Online PINCDCVM, SignatureOnline PIN
fDDA (Fast DDA)Supported (fDDA)Supported (fDDA)Not usedSupported
Mag Stripe ModemsdCVN17 (legacy)MSD (legacy, sunset)N/AN/A
EMV ModeqVSDC (EMV contactless)M/Chip (EMV contactless)AEIPS (EMV contactless)D-PAS (EMV)

4. Contactless vs Contact Transaction

AspectContactContactless
Transaction time2-5 seconds<300 ms (pre-read before amount)
ATRFull ATR with historical bytesRATS + ATS (simplified)
fDDAFull DDA with ICC public key certFast DDA (pre-computed)
CVM preferenceOffline PIN → Online PIN → SignatureCDCVM → Online PIN → No CVM
AmountCan be any valueFloor limit (e.g., $100) for no CVM; above requires CDCVM
Test this yourself: Our Contactless Payment Flow Visualizer lets you step through each APDU exchange interactively — select card brand, enter amount, see every command and response with byte annotations.

Worried about contactless card skimming? The SaiTech RFID Blocking Cards (5-pack) slip into your wallet and shield all cards within range — Check Price on Amazon. For a complete solution, the Travelambo RFID Wallet combines physical card slots with built-in RFID blocking — Check Price on Amazon. If you prefer a premium option, the TUMI Delta RFID Wallet offers enterprise-grade RFID protection with leather construction — Check Price on Amazon.

Related Tools

Contactless Payment Flow Visualizer — Step-by-step APDU trace | EMV Cryptogram Visualizer — ARQC computation | EMV TLV Parser — Decode card data | CVM List Decoder — Cardholder verification methods | EMV Data Decoding Guide