ISO 9564-4:2016
Financial services — Personal Identification Number (PIN) management and security — Part 4: Requirements for PIN handling in eCommerce for Payment Transactions
Financial services — Personal Identification Number (PIN) management and security — Part 4: Requirements for PIN handling in eCommerce for Payment Transactions
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 14
- Дата публикации:
- 9 марта 2016 г.
- Издание:
- ISO IS 9564 edition 1 version 1
- ICS:
- 35.240.40
ISO 9564-4:2016 provides requirements for the use of personal identification numbers (PIN) in eCommerce. The PINs in scope are the same cardholder PINs used as a means of cardholder verification in card-based financial transactions; notably, automated teller machine (ATM) systems, point-of-sale (POS) terminals, automated fuel dispensers, and vending machines. It is applicable to financial card-originated transactions requiring verification of the PIN and to those organizations responsible for implementing techniques for the management of the PIN in eCommerce. The provisions of this part of ISO 9564 are not intended to cover - passwords, passcodes, pass phrases and other shared secrets used for customer authentication in online banking, telephone banking, digital wallets, mobile payment, etc., - management of cardholder PINs for use as a means of cardholder verification in retail banking systems in, notably, automated teller machine (ATM) systems, point-of-sale (POS) terminals, automated fuel dispensers, vending machines, banking kiosks and PIN selection/change systems, which are covered in ISO 9564‑1, - card proxies such as mobile phones or key fobs, - approved algorithms for PIN encipherment, which are covered in ISO 9564‑2, - the protection of the PIN against loss or intentional misuse by the customer or authorized employees of the issuer, - privacy of non-PIN transaction data, - protection of transaction messages against alteration or substitution, e.g. an online authorization response, - protection against replay of the transaction, - functionality of devices used for PIN entry which is related to issuer functions other than PIN entry, - specific key management techniques, and - access to, and storage of, card data other than the PIN by applications such as wallets.
Abstract
Overview
ISO 9564-4:2016 - "Financial services - PIN management and security - Part 4: Requirements for PIN handling in eCommerce for Payment Transactions" defines minimum security requirements and practices for using cardholder Personal Identification Numbers (PINs) in eCommerce. It addresses scenarios where the cardholder, merchant and payment device are separated across an open network and specifies acceptable device types and handling methods to protect cardholder PINs used for card-based verification. This part is one element of the ISO 9564 series (see Related Standards).
Key topics and technical requirements
- Prohibition on NAD PIN entry: PINs must not be entered into a Network Access Device (NAD) such as a personal computer, mobile phone or other general-purpose device connected to an open network.
- Approved device types:
- PED (PIN Entry Device) compliant with ISO 9564‑1 (traditional secure PIN entry devices).
- FSPED (Functionally Secure PIN Entry Device) - a limited-function device with a contact IC reader, numeric keypad and display used exclusively with IC cards to generate a One-Time Token (OTT).
- ICCPED (Integrated Circuit Card PIN Entry Device) - self-powered IC cards with integrated keypad/display that generate an OTT after PIN entry.
- One-Time Token (OTT) model: The IC card generates a cryptographic value after PIN entry; the OTT (possibly formatted by the FSPED) is entered or transferred into the NAD and sent to the issuer for verification.
- FSPED technical controls (selected requirements from the standard):
- Tamper-resistant physical design - modifications require physical penetration and are likely visible to the user.
- Device must not disclose PIN values (no visual/auditory leaks).
- Single unit containing reader, processor, keypad, display and memory.
- Immediate erasure of PIN from device memory after submission to the IC card.
- Cryptographically authenticated software updates applied in sequence.
- No forwarding of externally originated PIN verification commands.
- FSPED does not contribute cryptographically to the OTT (may only encipher PIN to the IC card).
- Cardholder guidance: Issuers should instruct cardholders not to use FSPEDs from untrusted sources, to remove the card after use, and to stop using devices that appear tampered or damaged.
Practical applications - who uses this standard
ISO 9564-4 is used by:
- Card issuers and their agents implementing PIN-based eCommerce verification.
- Payment scheme operators, acquirers and PSPs designing secure online payment flows that involve cardholder PIN verification.
- Device manufacturers and integrators developing FSPEDs, ICCPEDs or PEDs for eCommerce OTT generation.
- Security architects and compliance teams who must ensure PIN handling in eCommerce meets minimum international requirements.
Use cases include secure remote PIN verification for card‑originated eCommerce transactions where the PIN cannot be entered into insecure NADs and an OTT-based workflow is required.
Related standards
- ISO 9564‑1 - Basic principles and requirements for PINs in card-based systems (PED requirements).
- ISO 9564‑2 - Approved algorithms for PIN encipherment.
- ISO/IEC 7816 - Integrated circuit cards standards (referenced for ICC definitions).
Keywords: ISO 9564-4, PIN handling in eCommerce, FSPED, ICCPED, OTT, PIN security, cardholder PIN, NAD, eCommerce payments.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 9564-4:2016
Похожие стандарты
Стандарты, упомянутые в описании
ISO 9564-2:2014
ОтменёнFinancial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorith…
Overview ISO 9564-2:2014 defines the approved algorithms for the encipherment of Personal Identification Numbers (PINs) used in financial services. This part of the ISO 9564 series focuses exclusivel…
ISO 9564-1:2017
ДействующийFinancial services — Personal Identification Number (PIN) management and security — Part 1: Basic principles…
Overview ISO 9564-1:2017 - Financial services - Personal Identification Number (PIN) management and security - Part 1 defines the basic principles and minimum security requirements for effective PIN…
ISO/IEC 7816-15:2016
ДействующийIdentification cards — Integrated circuit cards — Part 15: Cryptographic information application
Overview ISO/IEC 7816-15:2016 - "Identification cards - Integrated circuit cards - Part 15: Cryptographic information application" defines a standardized, platform-neutral application for storing, or…