ISO 9564-2:2014
Financial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorithms for PIN encipherment
Financial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorithms for PIN encipherment
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 2
- Дата публикации:
- 22 июля 2014 г.
- Издание:
- ISO IS 9564 edition 3 version 1
- ICS:
- 35.240.40
ISO 9564-2:2014 specifies approved algorithms for the encipherment of Personal Identification Numbers (PINs).
Abstract
Overview
ISO 9564-2:2014 defines the approved algorithms for the encipherment of Personal Identification Numbers (PINs) used in financial services. This part of the ISO 9564 series focuses exclusively on the cryptographic methods authorized for PIN protection and references related ISO/IEC standards for algorithm definitions and modes of operation.
Approved algorithms listed in the standard:
- Triple Data Encryption Algorithm (TDEA)
- RSA encryption algorithm (RSA)
- Advanced Encryption Standard (AES)
The document is published by ISO/TC 68 (Financial services), SC 2 (Financial services security) and forms Part 2 of the ISO 9564 family addressing PIN management and security.
Key Topics
-
Algorithm definitions and references: ISO 9564-2 relies on ISO/IEC documents (ISO/IEC 18033-2, ISO/IEC 18033-3) for formal algorithm definitions and ISO/IEC 10116 for modes of operation.
-
TDEA (Triple DES):
- Definition as per ISO/IEC 18033-3.
- Approved encipherment mode: Electronic Code Book (ECB) with block size n = 64.
- Approved for use with PIN block formats 0, 1, and 3.
-
RSA:
- Definition as per ISO/IEC 18033-2.
- Approved use limited to encipherment of offline PINs submitted to integrated circuit cards (ICCs) and is applicable only to PIN block format 2.
-
AES:
- Definition as per ISO/IEC 18033-3.
- Approved encipherment mode: Electronic Code Book (ECB) with block size n = 128.
- Approved for use with PIN block format 4.
Applications
ISO 9564-2:2014 provides practical guidance for organizations that implement PIN encipherment in card-based and offline payment contexts. Key applications and benefits include:
- Secure PIN transmission and storage: By prescribing approved algorithms and modes, the standard supports secure handling of PIN blocks within payment systems.
- Interoperability and compliance: Implementers can rely on the listed algorithms to meet industry expectations for PIN protection and to align with related ISO requirements.
- Clear scope for offline and card-present scenarios: RSA is explicitly approved for offline PIN submission to ICCs, while block-cipher algorithms (TDEA, AES) are tied to specific PIN block formats.
Related Standards
- ISO 9564-1 - Basic principles and requirements for PINs in card-based systems (normative reference).
- ISO/IEC 10116 - Modes of operation for block ciphers (normative reference for ECB mode usage).
- ISO/IEC 18033-2 - Definitions for asymmetric ciphers (RSA)
- ISO/IEC 18033-3 - Definitions for block ciphers (TDEA, AES)
- ISO 9564-4 - Requirements for PIN handling in eCommerce (related part of the series)
Adopting ISO 9564-2:2014 helps security architects and payment system operators select approved cryptographic algorithms and modes for protecting PIN data in compliance with internationally recognized practices.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 9564-2:2014
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 18033-2:2006
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 2: Asymmetric ciphers
Overview ISO/IEC 18033-2:2006 - Information technology - Security techniques - Encryption algorithms - Part 2: Asymmetric ciphers - specifies functional interfaces, correct usage, and ciphertext form…
ISO/IEC 18033-3:2010
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 3: Block ciphers
Overview ISO/IEC 18033-3:2010 - "Information technology - Security techniques - Encryption algorithms - Part 3: Block ciphers" is the international standard that specifies a set of block cipher algor…
BS ISO/IEC 10116:2017+A1:2021
ДействующийInformation technology. Security techniques. Modes of operation for an n-bit block cipher.
ISO 9564-1:2017
ДействующийFinancial services — Personal Identification Number (PIN) management and security — Part 1: Basic principles…
Overview ISO 9564-1:2017 - Financial services - Personal Identification Number (PIN) management and security - Part 1 defines the basic principles and minimum security requirements for effective PIN…
ISO 9564-4:2016
ОтменёнFinancial services — Personal Identification Number (PIN) management and security — Part 4: Requirements for…
Overview ISO 9564-4:2016 - "Financial services - PIN management and security - Part 4: Requirements for PIN handling in eCommerce for Payment Transactions" defines minimum security requirements and p…