9F74

Protected Data Envelope 5

Protected Data Envelope 5 belongs to the opposite half of Kernel 2's data-storage design from the Unprotected Data Envelopes already covered in this dictionary (9F76, 9F79): where those carry free-read data with no integrity guarantee, the Protected family - of which 9F74 is one member, related to 9F71 through 9F73 as siblings in the same numbered sequence - has its write access guarded, meaning the card itself controls who can modify it rather than leaving it open the way an unprotected envelope is. This is a genuine, meaningful design distinction worth not glossing over: protected here is specifically about write-access control on the card's own data storage, not about the cryptographic integrity signing gives to fields like the Signed Static Application Data (93) - a protected envelope can still be read freely; what's restricted is who can change it. Scoped to Mastercard's Kernel 2 data-storage feature, a terminal integrating loyalty or issuer-specific programs against this envelope needs to consult Mastercard's own data-storage documentation for what 9F74 actually contains, since, like the Terminal Risk Management Data (9F1D) covered earlier, its payload isn't standardised by the core EMV spec. See EMV Contactless Book C-2.

Interactive decoder

Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.

Binary (2): AB01

This tag is not a bitmap; the decoder shows a format-based interpretation.

Decoded example

Example value: AB01

Related tags

Properties

Tag9F74
NameProtected Data Envelope 5
FormatBinary
Lengthvariable
SourceCard (ICC)
Templates
BooksEMV Contactless Book C-2

Frequently asked questions

What is EMV tag 9F74?
Protected Data Envelope 5 belongs to the opposite half of Kernel 2's data-storage design from the Unprotected Data Envelopes already covered in this dictionary (9F76, 9F79): where those carry free-read data with no integrity guarantee, the Protected family - of which 9F74 is one member, related to 9F71 through 9F73 as siblings in the same numbered sequence - has its write access guarded, meaning the card itself controls who can modify it rather than leaving it open the way an unprotected envelope is. This is a genuine, meaningful design distinction worth not glossing over: protected here is specifically about write-access control on the card's own data storage, not about the cryptographic integrity signing gives to fields like the Signed Static Application Data (93) - a protected envelope can still be read freely; what's restricted is who can change it. Scoped to Mastercard's Kernel 2 data-storage feature, a terminal integrating loyalty or issuer-specific programs against this envelope needs to consult Mastercard's own data-storage documentation for what 9F74 actually contains, since, like the Terminal Risk Management Data (9F1D) covered earlier, its payload isn't standardised by the core EMV spec. See EMV Contactless Book C-2.
What format and length does EMV tag 9F74 use?
Tag 9F74 uses the Binary format and is normally variable long.
Is tag 9F74 provided by the card or the terminal?
Tag 9F74 (Protected Data Envelope 5) is provided by the Card (ICC).

Sources

  • C-2-Kernel-2-V2.11-Final-June-2023, p. 410

Receive site updates

Subscribe to receive site updates directly to your email

We won't send spam. You can unsubscribe at any time.