9F2D
Integrated Circuit Card (ICC) PIN Encipherment Public Key CertificateICC PIN Encipherment Public Key Certificate is a card-specific RSA key dedicated to exactly one purpose, distinct from the general ICC Public Key Certificate (9F46, referenced alongside it) used for DDA/CDA: encrypting a PIN the cardholder enters, so it can be verified offline by the card without ever crossing the terminal-to-card interface in the clear. The terminal recovers and validates this key using the same issuer-signature chain as 9F46, but the two keys serve genuinely different purposes and shouldn't be confused with each other even though they're structurally similar certificates issued by the same issuer for the same card. Like the general ICC certificate, its modulus may overflow into a companion Remainder field (9F2F) when it doesn't fit inside the certificate template alone. This is specifically the key involved in the enciphered-offline-PIN CVM method, one of the options in Terminal Capabilities (9F33) - a terminal offering that CVM method without correctly recovering and using 9F2D is either silently falling back to plaintext PIN or failing the CVM outright, neither of which looks like an obvious 9F2D-shaped error from the terminal's own logs. See EMV 4.4 Book 3 and Book 2.
Interactive decoder
Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.
Binary (8): 1122112211221122
This tag is not a bitmap; the decoder shows a format-based interpretation.
Decoded example
Example value: 1122112211221122
Properties
| Tag | 9F2D |
|---|---|
| Name | Integrated Circuit Card (ICC) PIN Encipherment Public Key Certificate |
| Format | Binary |
| Length | variable |
| Source | Card (ICC) |
| Templates | 70, 77 |
| Books | EMV 4.4 Book 3, EMV 4.4 Book 2 |
Frequently asked questions
- What is EMV tag 9F2D?
- ICC PIN Encipherment Public Key Certificate is a card-specific RSA key dedicated to exactly one purpose, distinct from the general ICC Public Key Certificate (9F46, referenced alongside it) used for DDA/CDA: encrypting a PIN the cardholder enters, so it can be verified offline by the card without ever crossing the terminal-to-card interface in the clear. The terminal recovers and validates this key using the same issuer-signature chain as 9F46, but the two keys serve genuinely different purposes and shouldn't be confused with each other even though they're structurally similar certificates issued by the same issuer for the same card. Like the general ICC certificate, its modulus may overflow into a companion Remainder field (9F2F) when it doesn't fit inside the certificate template alone. This is specifically the key involved in the enciphered-offline-PIN CVM method, one of the options in Terminal Capabilities (9F33) - a terminal offering that CVM method without correctly recovering and using 9F2D is either silently falling back to plaintext PIN or failing the CVM outright, neither of which looks like an obvious 9F2D-shaped error from the terminal's own logs. See EMV 4.4 Book 3 and Book 2.
- What format and length does EMV tag 9F2D use?
- Tag 9F2D uses the Binary format and is normally variable long.
- Is tag 9F2D provided by the card or the terminal?
- Tag 9F2D (Integrated Circuit Card (ICC) PIN Encipherment Public Key Certificate) is provided by the Card (ICC).
Sources
- EMV_v4.4_Book_3_Application_Specification, p. 146
- EMV_v4.4_Book_2_Security_and_Key_Management, p. 79
Receive site updates
Subscribe to receive site updates directly to your email
We won't send spam. You can unsubscribe at any time.