9F76

Unprotected Data Envelope 2

Unprotected Data Envelope 2 is one of a small family of free-form fields Kernel 2 makes available on the card for scheme- or issuer-defined data that doesn't need cryptographic integrity protection to be useful - the unprotected in its name is a deliberate design statement, not an oversight: some data (loyalty identifiers, marketing flags, non-security configuration) simply doesn't need the same guarantees as a cryptogram or a certificate, and giving it its own lightweight envelope avoids overloading the security-critical fields with content that was never meant to be trusted the same way. It sits in the middle of the numbered envelope family, related to both its neighbours (9F75 and 9F77), which is itself informative about its place in that sequence compared to a more peripheral member of the family. Being a Mastercard PayPass (Kernel 2) tag, and being explicitly unprotected, a terminal or host consuming its contents has to apply its own application-layer trust decisions - this envelope carries no inherent guarantee that its bytes haven't been altered in transit, which is precisely the tradeoff its name is warning the reader about. See EMV Contactless Book C-2.

Interactive decoder

Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.

Binary (3): 010203

This tag is not a bitmap; the decoder shows a format-based interpretation.

Decoded example

Example value: 010203

Related tags

Properties

Tag9F76
NameUnprotected Data Envelope 2
FormatBinary
Lengthvariable
SourceCard (ICC)
Templates
BooksEMV Contactless Book C-2

Frequently asked questions

What is EMV tag 9F76?
Unprotected Data Envelope 2 is one of a small family of free-form fields Kernel 2 makes available on the card for scheme- or issuer-defined data that doesn't need cryptographic integrity protection to be useful - the unprotected in its name is a deliberate design statement, not an oversight: some data (loyalty identifiers, marketing flags, non-security configuration) simply doesn't need the same guarantees as a cryptogram or a certificate, and giving it its own lightweight envelope avoids overloading the security-critical fields with content that was never meant to be trusted the same way. It sits in the middle of the numbered envelope family, related to both its neighbours (9F75 and 9F77), which is itself informative about its place in that sequence compared to a more peripheral member of the family. Being a Mastercard PayPass (Kernel 2) tag, and being explicitly unprotected, a terminal or host consuming its contents has to apply its own application-layer trust decisions - this envelope carries no inherent guarantee that its bytes haven't been altered in transit, which is precisely the tradeoff its name is warning the reader about. See EMV Contactless Book C-2.
What format and length does EMV tag 9F76 use?
Tag 9F76 uses the Binary format and is normally variable long.
Is tag 9F76 provided by the card or the terminal?
Tag 9F76 (Unprotected Data Envelope 2) is provided by the Card (ICC).

Sources

  • C-2-Kernel-2-V2.11-Final-June-2023, p. 434

Receive site updates

Subscribe to receive site updates directly to your email

We won't send spam. You can unsubscribe at any time.