9F2E
Integrated Circuit Card (ICC) PIN Encipherment Public Key ExponentICC PIN Encipherment Public Key Exponent is the third and final piece of the PIN-encipherment key chain already covered in this dictionary alongside the Certificate (9F2D) and the Remainder (9F2F): the exponent that, combined with the modulus recovered from those two, gives the terminal a complete, working public key it can use to encrypt an offline PIN before sending it to the card as Transaction PIN Data (99, also covered here). It follows the identical modulus-plus-exponent pattern already established for every other RSA key pair in this dictionary - the issuer key (90/92/9F32), the general ICC key (9F46/9F47/9F48), and now this PIN-specific ICC key - which is worth recognising as one recurring structure applied three times rather than three unrelated mechanisms. A terminal offering the enciphered-offline-PIN CVM method needs all three of 9F2D, 9F2E, and 9F2F handled correctly together; a bug isolated to just this exponent produces the same silent CVM failure or plaintext-PIN fallback already described for its sibling certificate field. See EMV 4.4 Book 3.
Interactive decoder
Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.
Binary (1): 03
This tag is not a bitmap; the decoder shows a format-based interpretation.
Decoded example
Example value: 03
Properties
| Tag | 9F2E |
|---|---|
| Name | Integrated Circuit Card (ICC) PIN Encipherment Public Key Exponent |
| Format | Binary |
| Length | 1 bytes |
| Source | Card (ICC) |
| Templates | 70, 77 |
| Books | EMV 4.4 Book 3 |
Frequently asked questions
- What is EMV tag 9F2E?
- ICC PIN Encipherment Public Key Exponent is the third and final piece of the PIN-encipherment key chain already covered in this dictionary alongside the Certificate (9F2D) and the Remainder (9F2F): the exponent that, combined with the modulus recovered from those two, gives the terminal a complete, working public key it can use to encrypt an offline PIN before sending it to the card as Transaction PIN Data (99, also covered here). It follows the identical modulus-plus-exponent pattern already established for every other RSA key pair in this dictionary - the issuer key (90/92/9F32), the general ICC key (9F46/9F47/9F48), and now this PIN-specific ICC key - which is worth recognising as one recurring structure applied three times rather than three unrelated mechanisms. A terminal offering the enciphered-offline-PIN CVM method needs all three of 9F2D, 9F2E, and 9F2F handled correctly together; a bug isolated to just this exponent produces the same silent CVM failure or plaintext-PIN fallback already described for its sibling certificate field. See EMV 4.4 Book 3.
- What format and length does EMV tag 9F2E use?
- Tag 9F2E uses the Binary format and is normally 1 bytes long.
- Is tag 9F2E provided by the card or the terminal?
- Tag 9F2E (Integrated Circuit Card (ICC) PIN Encipherment Public Key Exponent) is provided by the Card (ICC).
Sources
- EMV_v4.4_Book_3_Application_Specification, p. 147
Receive site updates
Subscribe to receive site updates directly to your email
We won't send spam. You can unsubscribe at any time.