ISO 9564-2:2025
Financial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorithms for PIN encipherment
Financial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorithms for PIN encipherment
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 13
- Дата публикации:
- 19 августа 2025 г.
- Издание:
- ISO IS 9564 edition 4 version 1
- ICS:
- 35.240.40
This document specifies approved algorithms for the encipherment of personal identification numbers (PINs).
Abstract
Overview
ISO 9564-2:2025 - part of the ISO 9564 series on PIN management and security - specifies the approved algorithms for encipherment of Personal Identification Numbers (PINs) in financial services. The standard defines which symmetric and asymmetric ciphers are permitted for different PIN block formats and use cases, and gives guidance on key encapsulation, key derivation and replay protection when using asymmetric techniques to transport ephemeral PIN encryption keys.
Key topics and requirements
- Approved algorithms: TDEA (Triple DES), RSA, AES, SM4, and ECIES (elliptic curve integrated encryption scheme).
- Modes and block sizes:
- TDEA: ECB mode, n = 64; keying option 1 or 2. Approved only for PIN block formats 0, 1 and 3. TDEA is increasingly considered unsafe and should be avoided in new implementations.
- AES and SM4: ECB mode, n = 128. Approved for PIN block format 4 only.
- RSA: Defined per ISO/IEC 18033‑2. Approved for offline PIN submission to ICCs (PIN block format 2) and for PIN issuance/change over open networks.
- ECIES: Hybrid (ECIES‑HC) using an ECIES‑KEM, a KDF (ISO/IEC 11770‑6 or KDF1/KDF2), and a DEM based on AES or SM4 with authenticated encryption per ISO/IEC 19772. Approved only for offline PINs to ICCs (format 2); not for direct online PIN encryption.
- Key management: All PIN keys and encapsulation mechanisms must comply with ISO 11568 (retail key management). Randomness must meet ISO/IEC 18031.
- Annex A guidance: Practical advice on using key encapsulation mechanisms (KEMs/RSA‑KEM/ECIES‑KEM) to transport ephemeral symmetric PIN keys, acceptable KDFs, replay protection techniques (nonces, transaction binding, MACs/signatures), and allowed PIN block formats when using encapsulated keys.
Practical applications and who uses this standard
- Financial institutions, acquirers, issuers and payment processors implementing secure PIN transport and storage.
- Vendors of PIN entry devices (PEDs), HSMs, POS terminals, and payment gateways integrating PIN encryption.
- Card manufacturers and IC (chip) card developers implementing offline PIN verification.
- Security architects, compliance teams and auditors who must ensure cryptographic choices meet industry and regulatory requirements. Use cases include online PIN transmission, offline PIN submission to IC cards, issuance/change of PINs over open networks, and secure key exchange to establish ephemeral PIN encryption keys.
Related standards (for implementation)
- ISO 9564-1 (PIN fundamentals and PIN block formats)
- ISO/IEC 18033-2 / 18033-3 (asymmetric and block cipher definitions)
- ISO/IEC 10116 (modes of operation for block ciphers)
- ISO 11568 (key management for retail)
- ISO/IEC 11770-6 (KDFs) and ISO/IEC 19772 (authenticated encryption)
- ISO/IEC 18031 (random bit generation)
Keywords: ISO 9564-2:2025, PIN encipherment, PIN management, TDEA, AES, SM4, RSA, ECIES, PIN block formats, key encapsulation, ISO 11568.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 9564-2:2025
Похожие стандарты
Стандарты, упомянутые в описании
ISO 9564-2:2014
ОтменёнFinancial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorith…
Overview ISO 9564-2:2014 defines the approved algorithms for the encipherment of Personal Identification Numbers (PINs) used in financial services. This part of the ISO 9564 series focuses exclusivel…
ISO/IEC 18033-2:2006
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 2: Asymmetric ciphers
Overview ISO/IEC 18033-2:2006 - Information technology - Security techniques - Encryption algorithms - Part 2: Asymmetric ciphers - specifies functional interfaces, correct usage, and ciphertext form…
BS ISO/IEC 19772:2020
ДействующийInformation security. Authenticated encryption.
BS ISO 11568:2023
ДействующийFinancial services. Key management (retail).
ISO/IEC 18031:2025
ДействующийInformation technology — Security techniques — Random bit generation
Overview ISO/IEC 18031:2025 - "Information technology - Security techniques - Random bit generation" defines a conceptual model and security requirements for random bit generators (RBGs) used for cry…
ISO 9564-1:2017
ДействующийFinancial services — Personal Identification Number (PIN) management and security — Part 1: Basic principles…
Overview ISO 9564-1:2017 - Financial services - Personal Identification Number (PIN) management and security - Part 1 defines the basic principles and minimum security requirements for effective PIN…