ISO 9564-5:2025
Financial services — Personal identification number (PIN) management and security — Part 5: Methods for the generation, change, and verification of PINs
Financial services — Personal identification number (PIN) management and security — Part 5: Methods for the generation, change, and verification of PINs
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 21
- Дата публикации:
- 24 октября 2025 г.
- Издание:
- ISO IS 9564 edition 1 version 1
- ICS:
- 35.240.40
This document specifies cryptographic methods for: — PIN generation; — reference PIN change; — transaction PIN verification. These PIN management functions can be implemented using: — encryption using an approved algorithm (see REF Table_tab_1 \r \h Table 1 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000C0000005400610062006C0065005F007400610062005F0031000000 ); — CMAC using an approved block cipher (see REF Table_tab_1 \r \h Table 1 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000C0000005400610062006C0065005F007400610062005F0031000000 ); — HMAC using an approved hash algorithm (see REF Table_tab_1 \r \h Table 1 08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000C0000005400610062006C0065005F007400610062005F0031000000 ). Refer to ISO 9564-1 for basic principles & requirements regarding PIN establishment.
Abstract
Overview
ISO 9564-5:2025 - Financial services - Personal identification number (PIN) management and security - Part 5 specifies cryptographic methods for PIN generation, PIN change and transaction PIN verification. The standard defines approved techniques using encryption, CMAC (block-cipher MAC) and HMAC (hash-based MAC), and references approved ciphers and hash algorithms (see the standard’s Table 1). It builds on the basic PIN principles in ISO 9564-1 and is intended to ensure secure, interoperable PIN management in card-based and payment systems.
Key topics and requirements
- PIN generation methods
- Random PIN generation and deterministic PIN generation (including PIN offset methods).
- Use of a PIN generation key (PGK) and clear rules for decimalization and base conversion.
- PIN change and management
- Authentication requirements for PIN change.
- Handling forgotten PINs and issuer-side update processes.
- HSMs must provide an atomic PIN change function to safely update reference PINs, PVVs or offsets.
- Transaction PIN verification
- PIN Verification Value (PVV) method (a 16‑byte block-cipher calculated PVV in this standard, distinct from legacy TDEA PVVs).
- Offset method and stored encrypted reference PIN approaches.
- Cryptographic building blocks
- Approved encryption algorithms and block ciphers (e.g., AES family as referenced).
- CMAC and HMAC mechanisms conforming to ISO/IEC 9797 and approved hash algorithms.
- Key management
- Keys must be managed per ISO 11568 (retail key management).
- Guidance on key rotation policies for PVV/PIN generation keys to allow for card life and reissuance.
Applications
ISO 9564-5:2025 is directly applicable to:
- Banks, card issuers and payment processors implementing secure PIN issuance, generation and verification workflows.
- HSM and security appliance vendors building PIN management functions, PVV calculation, CMAC/HMAC support and atomic update APIs.
- Security architects and compliance teams designing PIN lifecycle controls, cryptographic key rotation, and interoperability between issuer systems.
- Payment scheme operators and integrators ensuring consistent PIN verification across channels (ATM, POS, online wallet back-ends).
Practical benefits include improved security for PIN lifecycle operations, standardized PVV/offset techniques, and interoperability across issuer and acquirer systems.
Related standards
- ISO 9564-1 (Basic principles and requirements for PINs)
- ISO/IEC 9797-1 and 9797-2 (MAC algorithms - block-cipher and hash-based)
- ISO 11568 (Financial services - Key management)
- ISO/IEC 18031 and ISO/IEC 18033-3 (random generation and cipher references)
Keywords: ISO 9564-5:2025, PIN management, PIN generation, PVV, PIN verification, CMAC, HMAC, AES, HSM, financial services security.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 9564-5:2025
Похожие стандарты
Стандарты, упомянутые в описании
ISO 9564-1:2017
ДействующийFinancial services — Personal Identification Number (PIN) management and security — Part 1: Basic principles…
Overview ISO 9564-1:2017 - Financial services - Personal Identification Number (PIN) management and security - Part 1 defines the basic principles and minimum security requirements for effective PIN…
ISO/IEC 9797-3:2011
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 3: Mechanisms using…
Overview ISO/IEC 9797-3:2011 - "Information technology - Security techniques - Message Authentication Codes (MACs) - Part 3: Mechanisms using a universal hash-function" - specifies MAC algorithms tha…
BS ISO 11568:2023
ДействующийFinancial services. Key management (retail).
ISO/IEC 9797-1:2011
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 1: Mechanisms using…
Overview ISO/IEC 9797-1:2011 - Information technology - Security techniques - Message Authentication Codes (MACs) - Part 1: Mechanisms using a block cipher specifies six standardized MAC algorithms t…
ISO/IEC 18031:2025
ДействующийInformation technology — Security techniques — Random bit generation
Overview ISO/IEC 18031:2025 - "Information technology - Security techniques - Random bit generation" defines a conceptual model and security requirements for random bit generators (RBGs) used for cry…
ISO/IEC 18033-3:2010
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 3: Block ciphers
Overview ISO/IEC 18033-3:2010 - "Information technology - Security techniques - Encryption algorithms - Part 3: Block ciphers" is the international standard that specifies a set of block cipher algor…