9F4A

Static Data Authentication Tag List

Static Data Authentication Tag List is a short, usually single-entry list that names exactly which other data element's value is included, alongside the fixed static data, in what the Signed Static Application Data (93) actually signs - in nearly all real cards, that single named tag is the Data Authentication Code (9F45). Without 9F4A, 93 is a signature with an ambiguous scope: the terminal wouldn't know which of the card's data elements to feed into its own hash computation to check the signature against. It's a small field with an outsized role, because a terminal that gets the tag list wrong, or hardcodes an assumption about what it names instead of actually reading it, will compute the wrong hash and have every SDA verification fail - a bug that looks like a card or issuer signing problem but is actually the terminal not honouring what 9F4A explicitly told it to include. See EMV Contactless Book C-2.

Interactive decoder

Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.

Binary (2): 9F45

This tag is not a bitmap; the decoder shows a format-based interpretation.

Decoded example

Example value: 9F45

Related tags

Properties

Tag9F4A
NameStatic Data Authentication Tag List
FormatBinary
Lengthvariable
SourceCard (ICC)
Templates70, 77
BooksEMV Contactless Book C-2

Frequently asked questions

What is EMV tag 9F4A?
Static Data Authentication Tag List is a short, usually single-entry list that names exactly which other data element's value is included, alongside the fixed static data, in what the Signed Static Application Data (93) actually signs - in nearly all real cards, that single named tag is the Data Authentication Code (9F45). Without 9F4A, 93 is a signature with an ambiguous scope: the terminal wouldn't know which of the card's data elements to feed into its own hash computation to check the signature against. It's a small field with an outsized role, because a terminal that gets the tag list wrong, or hardcodes an assumption about what it names instead of actually reading it, will compute the wrong hash and have every SDA verification fail - a bug that looks like a card or issuer signing problem but is actually the terminal not honouring what 9F4A explicitly told it to include. See EMV Contactless Book C-2.
What format and length does EMV tag 9F4A use?
Tag 9F4A uses the Binary format and is normally variable long.
Is tag 9F4A provided by the card or the terminal?
Tag 9F4A (Static Data Authentication Tag List) is provided by the Card (ICC).

Sources

  • C-2-Kernel-2-V2.11-Final-June-2023, p. 417

Receive site updates

Subscribe to receive site updates directly to your email

We won't send spam. You can unsubscribe at any time.