9F76
Unprotected Data Envelope 2Unprotected Data Envelope 2 is one of a small family of free-form fields Kernel 2 makes available on the card for scheme- or issuer-defined data that doesn't need cryptographic integrity protection to be useful - the unprotected in its name is a deliberate design statement, not an oversight: some data (loyalty identifiers, marketing flags, non-security configuration) simply doesn't need the same guarantees as a cryptogram or a certificate, and giving it its own lightweight envelope avoids overloading the security-critical fields with content that was never meant to be trusted the same way. It sits in the middle of the numbered envelope family, related to both its neighbours (9F75 and 9F77), which is itself informative about its place in that sequence compared to a more peripheral member of the family. Being a Mastercard PayPass (Kernel 2) tag, and being explicitly unprotected, a terminal or host consuming its contents has to apply its own application-layer trust decisions - this envelope carries no inherent guarantee that its bytes haven't been altered in transit, which is precisely the tradeoff its name is warning the reader about. See EMV Contactless Book C-2.
Interactive decoder
Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.
Binary (3): 010203
This tag is not a bitmap; the decoder shows a format-based interpretation.
Decoded example
Example value: 010203
Properties
| Tag | 9F76 |
|---|---|
| Name | Unprotected Data Envelope 2 |
| Format | Binary |
| Length | variable |
| Source | Card (ICC) |
| Templates | — |
| Books | EMV Contactless Book C-2 |
Frequently asked questions
- What is EMV tag 9F76?
- Unprotected Data Envelope 2 is one of a small family of free-form fields Kernel 2 makes available on the card for scheme- or issuer-defined data that doesn't need cryptographic integrity protection to be useful - the unprotected in its name is a deliberate design statement, not an oversight: some data (loyalty identifiers, marketing flags, non-security configuration) simply doesn't need the same guarantees as a cryptogram or a certificate, and giving it its own lightweight envelope avoids overloading the security-critical fields with content that was never meant to be trusted the same way. It sits in the middle of the numbered envelope family, related to both its neighbours (9F75 and 9F77), which is itself informative about its place in that sequence compared to a more peripheral member of the family. Being a Mastercard PayPass (Kernel 2) tag, and being explicitly unprotected, a terminal or host consuming its contents has to apply its own application-layer trust decisions - this envelope carries no inherent guarantee that its bytes haven't been altered in transit, which is precisely the tradeoff its name is warning the reader about. See EMV Contactless Book C-2.
- What format and length does EMV tag 9F76 use?
- Tag 9F76 uses the Binary format and is normally variable long.
- Is tag 9F76 provided by the card or the terminal?
- Tag 9F76 (Unprotected Data Envelope 2) is provided by the Card (ICC).
Sources
- C-2-Kernel-2-V2.11-Final-June-2023, p. 434
Receive site updates
Subscribe to receive site updates directly to your email
We won't send spam. You can unsubscribe at any time.