ISO 9564

ISO 9564 is an international standard for personal identification number (PIN) management and security in financial services.

The PIN is used to verify the identity of a customer (the user of a bank card) within an electronic funds transfer system, and (typically) to authorize the transfer or withdrawal of funds. Therefore, it is important to protect PINs against unauthorized disclosure or misuse. Modern banking systems require interoperability between a variety of PIN entry devices, smart cards, card readers, card issuers, acquiring banks and retailers – including transmission of PINs between those entities – so a common set of rules for handling and securing PINs is required, to ensure both technical compatibility and a mutually agreed level of security. ISO 9564 provides principles and techniques to meet these requirements.

ISO 9564 comprises three parts,[Note 1] under the general title of Financial services — Personal Identification Number (PIN) management and security.

Part 1: Basic principles and requirements for PINs in card-based systems

ISO 9564-1:2011[1] specifies the basic principles and techniques of secure PIN management. It includes both general principles and specific requirements.

Basic principles

The basic principles of PIN management include:

  • PIN management functions shall be implemented in software and hardware in such a way that the functionality cannot be modified without detection, and that the data cannot be obtained or misused.
  • Encrypting the same PIN with the same key but for a different bank account shall not predictably give the same cipher text.
  • Security of the PIN encryption shall depend on secrecy of the key, not secrecy of the algorithm.
  • The PIN must always be stored encrypted or physically secured.
  • Only the customer (i.e. the user of a card) and/or authorized card issuer staff shall be involved with PIN selection or issuing. Where card issuer staff are involved, appropriate strictly enforced procedures shall be used.
  • A stored encrypted PIN shall be protected from substitution.
  • A PIN shall be revoked if it is compromised, or suspected to be.
  • The card issuer shall be responsible for PIN verification.
  • The customer shall be advised of the importance of keeping the PIN secret.

PIN entry devices

The standard specifies some characteristics required or recommended of PIN entry devices (also known as PIN pads), i.e. the device into which the customer enters the PIN, including:

  • All PIN entry devices shall allow entry of the digits zero to nine. Numeric keys may also have letters printed on them, e.g. as per E.161. These letters are only for the customers' convenience; internally, the PIN entry device only handles digits. (E.g. the standard does not support multi-tap or similar.) The standard also recommends that customers should be warned that not all devices may have letters.
  • The PIN entry device shall be physically secured so that it is not feasible to modify its operation or extract PINs or encryption keys from it.
  • The PIN entry device should be designed or installed so as to prevent other people from observing the PIN as it is entered.
  • The keyboard layout should be standardized, with consistent and unambiguous labels for function keys, such as "enter", "clear" (this entry) and "cancel" (the transaction). The standard also recommends specific colours for function keys: green for "enter", yellow for "clear", red for "cancel".

Smart card readers

A PIN may be stored in a secure smart card, and verified offline by that card. The PIN entry device and the reader used for the card that will verify the PIN may be integrated into a single physically secure unit, but they do not need to be.

Additional requirements that apply to smart card readers include:

  • The card reader should be constructed in such a way as to prevent someone monitoring the communications to the card by inserting a monitoring device into the card slot.
  • If the PIN entry device and the card reader are not both part of an integrated secure unit, then the PIN shall be encrypted while it is transmitted from the PIN entry device to the card reader.

Other specific PIN control requirements

Other specific requirements include:

  • All hardware and software used for PIN processing shall be implemented such that:
    • Their correct functioning can be assured.
    • They cannot be modified or accessed without detection.
    • The data cannot be inappropriately accessed, modified or misused.
    • The PIN cannot be determined by a brute-force search.
  • The PIN shall not be communicated verbally. In particular bank personnel shall never ask the customer to disclose the PIN, nor recommend a PIN value.
  • PIN encryption keys should not be used for any other purpose.

PIN length

The standard specifies that PINs shall be from four to twelve digits long, noting that longer PINs are more secure but harder to use. It also suggests that the issuer should not assign PINs longer than six digits.

PIN selection

There are three accepted methods of selecting or generating a PIN:

assigned derived PIN
The card issuer generates the PIN by applying some cryptographic function to the account number or other value associated with the customer.
assigned random PIN
The card issuer generates a PIN value using a random number generator.
customer selected PIN
The customer selects the PIN value.

PIN issuance and delivery

The standard includes requirements for keeping the PIN secret while transmitting it, after generation, from the issuer to the customer. These include:

  • The PIN is never available to the card issuing staff.
  • The PIN can only be displayed or printed for the customer in an appropriately secure manner. One method is a PIN mailer, an envelope designed so that it can be printed without the PIN being visible (even at printing time) until the envelope is opened. A PIN mailer must also be constructed so that any prior opening will be obvious to the customer, who will then be aware that the PIN may have been disclosed.
  • The PIN shall never appear where it can be associated with a customer's account. For example, a PIN mailer must not include the account number, but only sufficient information for its physical delivery (e.g. name and address). The PIN and the associated card shall not be mailed together, nor at the same time.

PIN encryption

To protect the PIN during transmission from the PIN entry device to the verifier, the standard requires that the PIN be encrypted, and specifies several formats that may be used. In each case, the PIN is encoded into a PIN block, which is then encrypted by an "approved algorithm", according to part 2 of the standard).

The PIN block formats are:

Format 0

The PIN block is constructed by XOR-ing two 64-bit fields: the plain text PIN field and the account number field, both of which comprise 16 four-bit nibbles.

The plain text PIN field is:

  • one nibble with the value of 0, which identifies this as a format 0 block
  • one nibble encoding the length N of the PIN
  • N nibbles, each encoding one PIN digit
  • 14−N nibbles, each holding the "fill" value 15 (i.e. 11112)

The account number field is:

Format 1

This format should be used where no PAN is available. The PIN block is constructed by concatenating the PIN with a transaction number thus:

  • one nibble with the value of 1, which identifies this as a format 1 block
  • one nibble encoding the length N of the PIN
  • N nibbles, each encoding one PIN digit
  • 14−N nibbles encoding a unique value, which may be a transaction sequence number, time stamp or random number
Format 2

Format 2 is for local use with off-line systems only, e.g. smart cards. The PIN block is constructed by concatenating the PIN with a filler value thus:

  • one nibble with the value of 2, which identifies this as a format 2 block
  • one nibble encoding the length N of the PIN
  • N nibbles, each encoding one PIN digit
  • 14−N nibbles, each holding the "fill" value 15 (i.e. 11112)

(Except for the format value in the first nibble, this is identical to the plain text PIN field of format 0.)

Format 3

Format 3 is the same as format 0, except that the "fill" digits are random values from 10 to 15, and the first nibble (which identifies the block format) has the value 3.

Extended PIN blocks

Formats 0 to 3 are all suitable for use with the Triple Data Encryption Algorithm, as they correspond to its 64-bit block size. However the standard allows for other encryption algorithms with larger block sizes, e.g. the Advanced Encryption Standard has a block size of 128 bits. In such cases the PIN must be encoding into an extended PIN block, the format of which is defined in a 2015 amendment to ISO 9564-1.[2]

Part 2: Approved algorithms for PIN encipherment

ISO 9564-2:2014[3] specifies which encryption algorithms may be used for encrypting PINs. The approved algorithms are:

Part 3 (withdrawn)

ISO 9564-3 Part 3: Requirements for offline PIN handling in ATM and POS systems,[4] most recently published in 2003, was withdrawn in 2011 and its contents merged into part 1.

Part 4: Requirements for PIN handling in eCommerce for Payment Transactions

ISO 9564-4:2016[5] defines minimum security requirements and practices for the use of PINs and PIN entry devices in electronic commerce.

Notes

  1. ^ Parts 1, 2 and 4. Part 3 was withdrawn in 2011.

References

Read other articles:

Nell FranzenFranzen ca. 1922Lahir(1889-11-17)17 November 1889[1]Portland, Oregon, A.S.Meninggal21 Agustus 1973(1973-08-21) (umur 83)Orange, California, A.S.MakamForest Lawn Memorial Park, Glendale, California34°07′31″N 118°14′37″E / 34.1252°N 118.2437°E / 34.1252; 118.2437PekerjaanAktrisTahun aktif1913–1924 Nell W. Franzen (17 November 1889 – 21 Agustus 1973) adalah seorang aktris film dan panggung Amerika dari era bisu....

 

Tampak atas Meja Kehormatan di aula kebesaran Merton College, Universitas Oxford. Meja bawah yang memiliki campuran tempat duduk kursi dan bangku diduduki oleh mahasiswa. Meja kehormatan (dikenal dalam Inggris: High Tablecode: en is deprecated ) adalah meja khusus yang digunakan oleh fellow (anggota Senior Common Room) dan tamunya di aula kebesaran kolese dalam budaya Anglo-Saxon, di mana para mahasiswa makan di ruang utama aula pada waktu yang bersamaan. Konsep ini tetap menjadi norma di uni...

 

Bram MoersasCover Album K'edananLahirR. H. Bramantio W.(1965-05-08)8 Mei 1965Tegal, Jawa Tengah, IndonesiaMeninggal21 Februari 2009(2009-02-21) (umur 43)Batang, Jawa TengahPekerjaanpenyanyi, pencipta laguKarier musikGenrePopInstrumenGitarTahun aktif1978 - 2009Artis terkaitChossy Pratama Harvey MalaiholoDewi GitaAnggota-Mantan anggota- R. H. Bramantio W. (8 Mei 1965 – 21 Februari 2009) adalah seorang musisi dan pencipta lagu berkebangsaan Indonesia. Ia mulai dikenal sejak...

Untuk surat kawat, lihat Telegram. Telegram Tangkapan layar Telegram berjalan di Android, tangkapan layar diambil pada tahun 2023TipePengirim pesan instan, perangkat lunak bebas, aplikasi seluler, aplikasi, situs web, perusahaan internet, aplikasi web dan komunitas daring Versi pertamaAgustus 2013 (2013-08)Versi stabilDaftarperamban web: 1.9.6 (24 September 2023)Android: 10.10.1 (1r April 2024)iOS, iPadOS: 10.10 (31 Maret 2024)macOS: 10.10.2 (3 April 2024)Linux, macOS, Microsoft Windows:...

 

العلاقات المكسيكية الكندية   كندا   المكسيك تعديل مصدري - تعديل   العلاقات المكسيكية الكندية هي العلاقات التي تجمع بين كندا والولايات المتحدة المكسيكية. تغيرت العلاقات بين المكسيك وكندا بشكل إيجابي في السنوات الأخيرة، وذلك على الرغم من خمول العلاقات التاريخي...

 

Pour les articles homonymes, voir Roman. Si ce bandeau n'est plus pertinent, retirez-le. Cliquez ici pour en savoir plus. Cet article ne cite pas suffisamment ses sources (septembre 2020). Si vous disposez d'ouvrages ou d'articles de référence ou si vous connaissez des sites web de qualité traitant du thème abordé ici, merci de compléter l'article en donnant les références utiles à sa vérifiabilité et en les liant à la section « Notes et références ». En pratique...

Содержание 1 Флаги 2 Геральдика 3 Гимн 4 Культура 5 Флора и фауна 6 Еда и напитки 7 См. также 8 Примечания Флаги Основная статья: Список шотландских флагов Флаг Шотландии представляет собой Андреевский крест на синем полотнище. Флаг существует с IX века и является старейшим на�...

 

Синелобый амазон Научная классификация Домен:ЭукариотыЦарство:ЖивотныеПодцарство:ЭуметазоиБез ранга:Двусторонне-симметричныеБез ранга:ВторичноротыеТип:ХордовыеПодтип:ПозвоночныеИнфратип:ЧелюстноротыеНадкласс:ЧетвероногиеКлада:АмниотыКлада:ЗавропсидыКласс:Пт�...

 

追晉陸軍二級上將趙家驤將軍个人资料出生1910年 大清河南省衛輝府汲縣逝世1958年8月23日(1958歲—08—23)(47—48歲) † 中華民國福建省金門縣国籍 中華民國政党 中國國民黨获奖 青天白日勳章(追贈)军事背景效忠 中華民國服役 國民革命軍 中華民國陸軍服役时间1924年-1958年军衔 二級上將 (追晉)部队四十七師指挥東北剿匪總司令部參謀長陸軍�...

This article does not cite any sources. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: There's Always Woodstock – news · newspapers · books · scholar · JSTOR (July 2014) (Learn how and when to remove this message) 2014 American filmThere's Always WoodstockDirected byRita MersonWritten byRita MersonProduced byPeter SchaferStarring Allison Miller Jason Ritter Britta...

 

Francesco MontenegroKardinal, Uskup Agung AgrigentoMontenegro pada tahun 2015.GerejaGereja Katolik RomaKeuskupan agungAgrigentoTakhtaAgrigentoMasa jabatan23 Februari 2008 - sekarangPendahuluCarmelo FerraroJabatan lainKardinal-Imam Santi Andrea a Gregorio al Monte CelioImamatTahbisan imam8 Agustus 1969oleh Francesco FasolaTahbisan uskup18 Maret 2000oleh Giovanni MarraPelantikan kardinal14 Februari 2015oleh Paus FransiskusPeringkatKardinal-ImamInformasi pribadiLahir22 Mei 1946 (umur&#...

 

First commercial computer Ferranti Mark 1Ferranti Mark 1 Star, c. 1953Also known asManchester Electronic ComputerManchester FerrantiProduct familyManchester computersPredecessorManchester Mark 1 The Ferranti Mark 1, also known as the Manchester Electronic Computer in its sales literature,[1] and thus sometimes called the Manchester Ferranti, was produced by British electrical engineering firm Ferranti Ltd. It was the world's first commercially available electronic general-purpose stor...

Ishirō HondaIshirō Honda pada tahun 1954Nama asal本多 猪四郎Lahir(1911-05-07)7 Mei 1911Yamagata, JepangMeninggal28 Februari 1993(1993-02-28) (umur 81)Tokyo, JepangSebab meninggalKegagalan PernapasanPekerjaansutradara, Produser film, penulis naskah, penyunting filmSitus webhttp://www.ishirohonda.org/ Ishirō Honda (本多猪四郎 Honda Ishirō|7 Mei 1911 – 28 Februari 1993), atau namanya sering salah ditulis sebagai Inoshiro Honda ketika filmnya dirilis ...

 

Prasasti Blanjong adalah suatu bagian dari tugu yang ditemukan di Sanur pada tahun 1932. Arca Airlangga dalam perwujudan Vishnu menunggangi Garuda, ditemukan di Candi Belahan, sekarang disimpan di Museum Trowulan, Jawa Timur. Wangsa (dinasti) Warmadewa adalah keluarga bangsawan yang pernah berkuasa di Pulau Bali. Pendiri dinasti ini adalah Sri Kesari Warmadewa, menurut riwayat lisan turun-temurun, yang berkuasa sejak abad ke-10. Namanya disebut-sebut dalam prasasti Blanjong di Sanur dan menja...

 

Battaglia di Mentanaparte della Campagna dell'Agro romano per la liberazione di RomaData3 novembre 1867 LuogoMentana EsitoVittoria franco-pontificia Schieramenti Italia(volontari italiani) Stato Pontificio Francia Comandanti Giuseppe Garibaldi Hermann Kanzler Balthazar Alban Gabriel de Polhes EffettiviIncerti: 4.000[1]; 8.100[2]; 10.000[3]Incerti: 5.000[1][3]; 5.500[4]; 22.000[5] Perdite1.100 tra morti e feriti[3]tra 80...

Sebuah jalinan liar semak belukar Tadasu no Mori (糺の森code: ja is deprecated ), secara harfiah berarti Hutan Koreksi, adalah suatu hutan larangan yang terkait dengan kompleks tempat suci Shinto penting yang dikenal di Jepang sebagai Kamo-jinja, terletak di dekat tepi Sungai Kamo tepat di utara di mana Sungai Takano bergabung dengan Sungai Kamo di timur laut kota Kyoto Jepang. Istilah Kamo-jinja dalam bahasa Jepang merupakan referensi umum untuk Kuil Shimogamo dan Kuil Kamigamo, kuil-kuil...

 

Reflection nebula in the constellation Cygnus IC 5146Reflection nebulaemission nebulaOptical image of IC 5146Observation data: J2000 epochRight ascension21h 53m 28.7sDeclination+47° 16′ 01″Distance2500±100[1] ly   (780±30 pc)Apparent magnitude (V)+7.2Apparent dimensions (V)12′ConstellationCygnusPhysical characteristicsRadius7.5 lyDesignationsCocoon Nebula, Caldwell 19, Sh 2-125, Cr 470See also: Lists of nebulae IC 5146 (also...

 

この記事の主題はウィキペディアにおける独立記事作成の目安を満たしていないおそれがあります。 目安に適合することを証明するために、記事の主題についての信頼できる二次資料を求めています。なお、適合することが証明できない場合には、記事は統合されるか、リダイレクトに置き換えられるか、さもなくば削除される可能性があります。出典検索?: チェ�...

Abadía de Bobbio LocalizaciónPaís ItaliaDivisión BobbioCoordenadas 44°46′00″N 9°23′13″E / 44.7667, 9.387Información religiosaCulto catolicismoDiócesis Diócesis de Piacenza-Bobbio, Adadía Territorial de San Colombano, diócesis de Bobbio y Archidiócesis de Génova-BobbioOrden Orden de San BenitoFundación siglo VIIDatos arquitectónicosEstilo arquitectura del RenacimientoMapa de localización Abadía de Bobbio Ubicación en Emilia-Romaña.Sitio web ofici...

 

Off-beat musical rhythm For other uses of the same name, see Syncopation (disambiguation). Audio playback is not supported in your browser. You can download the audio file.Syncopation (sfz) in Beethoven's String Quartet in A major, Op. 18, No. 5, 3rd movement, mm. 24–25 Audio playback is not supported in your browser. You can download the audio file.Vertical hemiola (the ratio 3:2) In music, syncopation is a variety of rhythms played together to make a piece of music, making part or all of ...