99

Transaction Personal Identification Number (PIN) Data

Transaction Personal Identification Number Data is the vehicle that actually carries a PIN from the terminal to the card during offline PIN verification - either in the clear, for the plaintext offline PIN CVM method flagged in Terminal Capabilities (9F33, covered earlier), or encrypted, using the ICC PIN Encipherment Public Key Certificate chain (9F2D/9F2E/9F2F, all covered in this dictionary) for the enciphered offline PIN method. Related to the PIN Try Counter (9F17) the card decrements on a failed verification, this field only ever exists transiently as part of the VERIFY command's data - it is never stored, logged, or retained anywhere in the transaction record the way nearly every other tag in this dictionary is, which is precisely why it deserves the strictest handling discipline of any field covered here: any terminal implementation that logs, caches, or displays tag 99's contents for debugging purposes has created a PIN-exposure vulnerability, not a convenience. See EMV 4.4 Book 3.

Interactive decoder

Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.

Binary (8): 24FFFFFFFFFFFFFF

This tag is not a bitmap; the decoder shows a format-based interpretation.

Decoded example

Example value: 24FFFFFFFFFFFFFF

Related tags

Properties

Tag99
NameTransaction Personal Identification Number (PIN) Data
FormatBinary
Lengthvariable
SourceTerminal
Templates
BooksEMV 4.4 Book 3

Frequently asked questions

What is EMV tag 99?
Transaction Personal Identification Number Data is the vehicle that actually carries a PIN from the terminal to the card during offline PIN verification - either in the clear, for the plaintext offline PIN CVM method flagged in Terminal Capabilities (9F33, covered earlier), or encrypted, using the ICC PIN Encipherment Public Key Certificate chain (9F2D/9F2E/9F2F, all covered in this dictionary) for the enciphered offline PIN method. Related to the PIN Try Counter (9F17) the card decrements on a failed verification, this field only ever exists transiently as part of the VERIFY command's data - it is never stored, logged, or retained anywhere in the transaction record the way nearly every other tag in this dictionary is, which is precisely why it deserves the strictest handling discipline of any field covered here: any terminal implementation that logs, caches, or displays tag 99's contents for debugging purposes has created a PIN-exposure vulnerability, not a convenience. See EMV 4.4 Book 3.
What format and length does EMV tag 99 use?
Tag 99 uses the Binary format and is normally variable long.
Is tag 99 provided by the card or the terminal?
Tag 99 (Transaction Personal Identification Number (PIN) Data) is provided by the Terminal.

Sources

  • EMV_v4.4_Book_3_Application_Specification, p. 159

Receive site updates

Subscribe to receive site updates directly to your email

We won't send spam. You can unsubscribe at any time.