9F2F

Integrated Circuit Card (ICC) PIN Encipherment Public Key Remainder

ICC PIN Encipherment Public Key Remainder is the overflow field for 9F2D, playing exactly the same structural role that 9F48 plays for the general ICC certificate (9F46) and that 92 plays for the Issuer Public Key Certificate (90): whatever part of the PIN-encipherment key's modulus doesn't fit inside its certificate spills into this separate field, to be concatenated back on by the terminal before the key is complete and usable. It's the third instance of the exact same pattern in this dictionary - modulus-in-certificate plus optional remainder - which is worth recognising as a pattern rather than three unrelated fields to memorise separately: any card whose keys happen to be short enough needs none of the three remainder fields (92, 9F48, 9F2F) at all, and their absence is normal, not an error condition. A terminal implementation that handles the general PK Remainder (9F48) correctly but mishandles 9F2F specifically has almost certainly special-cased one code path instead of sharing the same concatenation logic across all three certificate types. See EMV 4.4 Book 2.

Interactive decoder

Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.

Binary (8): 3344334433443344

This tag is not a bitmap; the decoder shows a format-based interpretation.

Decoded example

Example value: 3344334433443344

Related tags

Properties

Tag9F2F
NameIntegrated Circuit Card (ICC) PIN Encipherment Public Key Remainder
FormatBinary
Lengthvariable
SourceCard (ICC)
Templates70, 77
BooksEMV 4.4 Book 2

Frequently asked questions

What is EMV tag 9F2F?
ICC PIN Encipherment Public Key Remainder is the overflow field for 9F2D, playing exactly the same structural role that 9F48 plays for the general ICC certificate (9F46) and that 92 plays for the Issuer Public Key Certificate (90): whatever part of the PIN-encipherment key's modulus doesn't fit inside its certificate spills into this separate field, to be concatenated back on by the terminal before the key is complete and usable. It's the third instance of the exact same pattern in this dictionary - modulus-in-certificate plus optional remainder - which is worth recognising as a pattern rather than three unrelated fields to memorise separately: any card whose keys happen to be short enough needs none of the three remainder fields (92, 9F48, 9F2F) at all, and their absence is normal, not an error condition. A terminal implementation that handles the general PK Remainder (9F48) correctly but mishandles 9F2F specifically has almost certainly special-cased one code path instead of sharing the same concatenation logic across all three certificate types. See EMV 4.4 Book 2.
What format and length does EMV tag 9F2F use?
Tag 9F2F uses the Binary format and is normally variable long.
Is tag 9F2F provided by the card or the terminal?
Tag 9F2F (Integrated Circuit Card (ICC) PIN Encipherment Public Key Remainder) is provided by the Card (ICC).

Sources

  • EMV_v4.4_Book_2_Security_and_Key_Management, p. 79

Receive site updates

Subscribe to receive site updates directly to your email

We won't send spam. You can unsubscribe at any time.