9F48
Integrated Circuit Card (ICC) Public Key RemainderICC Public Key Remainder is the card-level counterpart to the Issuer Public Key Remainder (92): whatever part of the card's own RSA modulus doesn't fit inside the ICC Public Key Certificate (9F46) spills into this separate field, to be concatenated back on by the terminal before the card's public key is actually complete. Like its issuer-side sibling, it's optional in practice - a card whose modulus fits entirely within 9F46 simply has no need for it, and a terminal shouldn't treat its absence as anything other than normal. It's the last piece needed, alongside the Exponent (9F47), before the terminal has a fully reconstructed, trusted ICC public key ready to verify whatever the card signs dynamically - most directly, the Signed Dynamic Application Data (9F4B) that DDA and CDA depend on. A terminal that gets the concatenation order of 9F46 and 9F48 wrong reconstructs a modulus that looks superficially plausible but is cryptographically meaningless, which fails DDA/CDA verification in a way that's easy to misdiagnose as a card or issuer problem instead of a terminal parsing bug. See EMV Contactless Book C-8.
Interactive decoder
Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.
Binary (8): EEEEEEEEEEEEEEEE
This tag is not a bitmap; the decoder shows a format-based interpretation.
Decoded example
Example value: EEEEEEEEEEEEEEEE
Properties
| Tag | 9F48 |
|---|---|
| Name | Integrated Circuit Card (ICC) Public Key Remainder |
| Format | Binary |
| Length | variable |
| Source | Card (ICC) |
| Templates | — |
| Books | EMV Contactless Book C-8 |
Frequently asked questions
- What is EMV tag 9F48?
- ICC Public Key Remainder is the card-level counterpart to the Issuer Public Key Remainder (92): whatever part of the card's own RSA modulus doesn't fit inside the ICC Public Key Certificate (9F46) spills into this separate field, to be concatenated back on by the terminal before the card's public key is actually complete. Like its issuer-side sibling, it's optional in practice - a card whose modulus fits entirely within 9F46 simply has no need for it, and a terminal shouldn't treat its absence as anything other than normal. It's the last piece needed, alongside the Exponent (9F47), before the terminal has a fully reconstructed, trusted ICC public key ready to verify whatever the card signs dynamically - most directly, the Signed Dynamic Application Data (9F4B) that DDA and CDA depend on. A terminal that gets the concatenation order of 9F46 and 9F48 wrong reconstructs a modulus that looks superficially plausible but is cryptographically meaningless, which fails DDA/CDA verification in a way that's easy to misdiagnose as a card or issuer problem instead of a terminal parsing bug. See EMV Contactless Book C-8.
- What format and length does EMV tag 9F48 use?
- Tag 9F48 uses the Binary format and is normally variable long.
- Is tag 9F48 provided by the card or the terminal?
- Tag 9F48 (Integrated Circuit Card (ICC) Public Key Remainder) is provided by the Card (ICC).
Sources
- C-8_Kernel_8_v1.1, p. 260
Receive site updates
Subscribe to receive site updates directly to your email
We won't send spam. You can unsubscribe at any time.