9F49
Dynamic Data Authentication Data Object List (DDOL)Dynamic Data Authentication Data Object List is the card's tag-and-length request list for the INTERNAL AUTHENTICATE command used in DDA - the same request-list mechanism as the PDOL and CDOLs already covered in this dictionary, this time defining what the terminal must supply so the card can sign it as part of proving it's genuinely present for this specific transaction. It's related to the terminal's Unpredictable Number (9F37), almost universally included in a DDOL for the same replay-resistance reason it's folded into the Application Cryptogram, and to the Signed Static Application Data (93) and Signed Dynamic Application Data (9F4B) that represent SDA's and DDA/CDA's respective proof outputs - 9F49 is specifically what shapes the DDA-side proof, defining the exact data the card's dynamic signature actually covers. A terminal that supplies data in a different order or length than 9F49 specifies produces a DDA verification failure that traces back to a request-formatting mismatch, not to any actual problem with the card's signing key or the terminal's cryptographic implementation. See EMV 4.4 Book 3.
Interactive decoder
Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.
Binary (3): 9F3704
This tag is not a bitmap; the decoder shows a format-based interpretation.
Decoded example
Example value: 9F3704
Properties
| Tag | 9F49 |
|---|---|
| Name | Dynamic Data Authentication Data Object List (DDOL) |
| Format | Binary |
| Length | variable |
| Source | Card (ICC) |
| Templates | 70, 77 |
| Books | EMV 4.4 Book 3 |
Frequently asked questions
- What is EMV tag 9F49?
- Dynamic Data Authentication Data Object List is the card's tag-and-length request list for the INTERNAL AUTHENTICATE command used in DDA - the same request-list mechanism as the PDOL and CDOLs already covered in this dictionary, this time defining what the terminal must supply so the card can sign it as part of proving it's genuinely present for this specific transaction. It's related to the terminal's Unpredictable Number (9F37), almost universally included in a DDOL for the same replay-resistance reason it's folded into the Application Cryptogram, and to the Signed Static Application Data (93) and Signed Dynamic Application Data (9F4B) that represent SDA's and DDA/CDA's respective proof outputs - 9F49 is specifically what shapes the DDA-side proof, defining the exact data the card's dynamic signature actually covers. A terminal that supplies data in a different order or length than 9F49 specifies produces a DDA verification failure that traces back to a request-formatting mismatch, not to any actual problem with the card's signing key or the terminal's cryptographic implementation. See EMV 4.4 Book 3.
- What format and length does EMV tag 9F49 use?
- Tag 9F49 uses the Binary format and is normally variable long.
- Is tag 9F49 provided by the card or the terminal?
- Tag 9F49 (Dynamic Data Authentication Data Object List (DDOL)) is provided by the Card (ICC).
Sources
- EMV_v4.4_Book_3_Application_Specification, p. 145
Receive site updates
Subscribe to receive site updates directly to your email
We won't send spam. You can unsubscribe at any time.