We use cookies to give you the best experience and to help improve our website
Find out what cookies we use and how to disable themThis document provides requirements and guidance for methods of Issuer PIN Management using AES. It additionally defines a method for generating and verifying Card Security Codes using AES.
The processes defined in this Standard (in order as presented) are:
— PIN Generation
— PIN Change
— PIN Verification
— Generation and Verification of Card Security Code
All AES key lengths (128 bits, 192 bits and 256 bits) are acceptable for this Standard
Within this document, references to CMAC refer to algorithm 5 in ISO/IEC 9797‑1 used with AES.
Assigned derived PINS, where PINs are derived from PANs and customer selection is supported by means of offsets, are not prohibited but are not recommended and so an AES-based method for this approach is not specified in this standard. One reason for not recommending this approach is that with this approach if a user PIN is discovered by a fraudster (along with non-secret PIN verification data) then to recover PIN security the card must be reissued with a new PAN.
You are now following this standard. Weekly digest emails will be sent to update you on the following activities:
You can manage your follow preferences from your Account. Please check your mailbox junk folder if you don't receive the weekly email.
You have successfully unsubscribed from weekly updates for this standard.
Comment on proposal
Required form fields are indicated by an asterisk (*) character.