9F2D

Integrated Circuit Card (ICC) PIN Encipherment Public Key Certificate

ICC PIN Encipherment Public Key Certificate is a card-specific RSA key dedicated to exactly one purpose, distinct from the general ICC Public Key Certificate (9F46, referenced alongside it) used for DDA/CDA: encrypting a PIN the cardholder enters, so it can be verified offline by the card without ever crossing the terminal-to-card interface in the clear. The terminal recovers and validates this key using the same issuer-signature chain as 9F46, but the two keys serve genuinely different purposes and shouldn't be confused with each other even though they're structurally similar certificates issued by the same issuer for the same card. Like the general ICC certificate, its modulus may overflow into a companion Remainder field (9F2F) when it doesn't fit inside the certificate template alone. This is specifically the key involved in the enciphered-offline-PIN CVM method, one of the options in Terminal Capabilities (9F33) - a terminal offering that CVM method without correctly recovering and using 9F2D is either silently falling back to plaintext PIN or failing the CVM outright, neither of which looks like an obvious 9F2D-shaped error from the terminal's own logs. See EMV 4.4 Book 3 and Book 2.

Interactive decoder

Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.

Binary (8): 1122112211221122

This tag is not a bitmap; the decoder shows a format-based interpretation.

Decoded example

Example value: 1122112211221122

Related tags

Properties

Tag9F2D
NameIntegrated Circuit Card (ICC) PIN Encipherment Public Key Certificate
FormatBinary
Lengthvariable
SourceCard (ICC)
Templates70, 77
BooksEMV 4.4 Book 3, EMV 4.4 Book 2

Frequently asked questions

What is EMV tag 9F2D?
ICC PIN Encipherment Public Key Certificate is a card-specific RSA key dedicated to exactly one purpose, distinct from the general ICC Public Key Certificate (9F46, referenced alongside it) used for DDA/CDA: encrypting a PIN the cardholder enters, so it can be verified offline by the card without ever crossing the terminal-to-card interface in the clear. The terminal recovers and validates this key using the same issuer-signature chain as 9F46, but the two keys serve genuinely different purposes and shouldn't be confused with each other even though they're structurally similar certificates issued by the same issuer for the same card. Like the general ICC certificate, its modulus may overflow into a companion Remainder field (9F2F) when it doesn't fit inside the certificate template alone. This is specifically the key involved in the enciphered-offline-PIN CVM method, one of the options in Terminal Capabilities (9F33) - a terminal offering that CVM method without correctly recovering and using 9F2D is either silently falling back to plaintext PIN or failing the CVM outright, neither of which looks like an obvious 9F2D-shaped error from the terminal's own logs. See EMV 4.4 Book 3 and Book 2.
What format and length does EMV tag 9F2D use?
Tag 9F2D uses the Binary format and is normally variable long.
Is tag 9F2D provided by the card or the terminal?
Tag 9F2D (Integrated Circuit Card (ICC) PIN Encipherment Public Key Certificate) is provided by the Card (ICC).

Sources

  • EMV_v4.4_Book_3_Application_Specification, p. 146
  • EMV_v4.4_Book_2_Security_and_Key_Management, p. 79

Receive site updates

Subscribe to receive site updates directly to your email

We won't send spam. You can unsubscribe at any time.