PINs
or Personal Identification
Numbers are typically
used with debit
card transactions
and some security
transactions.
The PIN increases
the security of
a transaction
by ensuring the
person making
the transaction
is authorized
by knowing a "secret" or
PIN. A person
finding a lost
card or otherwise
obtaining a card
or card number
by fraudulent
means would not
be able to complete
transactions without
knowing the PIN.
PINs
can be processed
at the point of
transaction or
transmitted to
the host for verification.
When the PIN is
processed locally,
it is processed
internal to the
transaction device
at the point of
sale in specially
secured hardware.
Any attempt to
access the algorithms
or encryption
keys in the device
will result in
destruction of
the information
inside.
When
PINs are transmitted
with the transaction
data, it is always
encrypted with
secret keys. These
keys are further
diversified from
the master key
so that the actual
key for each transaction
is different from
every other transaction.
Discovering the
key for one transaction
will not be useful
for decrypting
another transaction.
The encryption
and diversification
algorithms used
are those currently
approved for the
encryption of
PIN values for
financial transactions.
All
this means that
if you are capturing
transaction information,
the PIN may or
may not be in
the transaction
request. If the
PIN is there,
it will undoubtedly
be encrypted.
The PIN block
will appear as
a sequence of
random or unintelligible
characters. AALogic
products CANNOT
decrypt any data
in any transaction.
The
ADM and MLT products
are intended for
troubleshooting
and development
of modem communications
over standard
telephone lines.
The equipment
and software is
only capable of
capturing and
displaying the
transmitted data.
There is no capability
to apply protocol
rules for parsing
the data or decrypting
any data within
the messages.
Developers
and technical
support persons
needing to verify
that the encryption
and decryption
processes are
performing correctly
should be able
to capture the
data for test
transactions using
known test keys.
They can then
compare the encrypted
fields within
the transaction
to verify that
the data is correct.
AALogic
does not and will
not support efforts
to decrypt or
recover encrypted
data in any messages.
Back
to Top