27 November 2018

Green light for EBICS 3.0

As of today, the EBICS specification is valid in version 3.0. The new version primarily serves to create a uniform standard for Germany, France and Switzerland.

One standard for all countries

Up to EBICS version 2.5, a distinction was made between German, French and Swiss EBICS. This created barriers for banks, customers and manufacturers alike when different EBICS dialects had to be handled equally.

EBICS version 3.0 starts right here and with its universal standard offers the right solution for the whole of Europe.

EBICS 3.0 is valid from 27 November 2018. The date, when credit institutions offer the new standard is up to the individual countries. In Germany, for example, the version is mandatory from 22 November 2021.

What changes?

The innovations include several aspects that must be taken into consideration on the server side at the banks as well as by the users. The most important changes at a glance.

Banking transactions via BTFs instead of order types

EBICS V 3.0 replaces the use of banking order types (or file formats in French or Swiss EBICS) with the so-called Business Transaction Formats, or BTFs for short.

Up to EBICS version 2.5, the specification of an order type, e.g. CCT for standard SEPA transfers, was sufficient to determine the business transaction. A BTF, however, allows more values:

  • ServiceName
    Name of the service (mandatory), e.g. SCT
  • MsgName
    Name of the message (mandatory), e.g. pain.001
  • Scope
    Scope of validity (optional), e.g. CGI
  • ServiceOption
    Service option (optional), e.g. B2B
  • ContainerFlag
    Container property (optional), e.g. ZIP

While until now it was only up to the bank how the processing was carried out, under EBICS 2.5, with the help of the BTFs, the client side can now also take influence on the processing in the bank server.

BTFs are distinguished between Upload (BTU) and Download (BTD).

Electronic keys

The most important change for the keys concerns the use of certificates. As of EBICS 3.0, all keys must always be transferred as X.509 certificates.

In addition, the minimum length for the various key types has been increased to 2048 bits and the A004 format has been removed from the standard.

EDS for all countries

In Germany, the Electronic Distributed Signature (EDS) has been available since the introduction of EBICS. With the new version, the EDS can now also be used in all other countries.

Uniform customer protocol

The adapted version of the customer protocol HAC in XML format replaces previous text-based versions. The cumbersome and error-prone proprietary parsing of the protocol is eliminated.

Miscellaneous

Further changes of the protocol in version 3.0:

  • Use of TLS 1.2 with expandable cipher list,
  • Possibility to transmit additional order information, e.g. the file name,
  • Adaptation of the INI letter to display certificate information,
  • Replacement of order attributes (OrderAttributes OZHNN, DZHNN) by signature flag (SignatureFlag).

Products from Business-Logics for EBICS 3.0

All server products and test systems as well as various client products of the manufacturer Business-Logics from Hilden, Germany, are now available in an updated version for EBICS 3.0. As usual, customers with an active maintenance contract receive the update free of charge.

For decision-makers and employees of credit institutions, Business-Logics also offers training courses around the topic EBICS 3.0.