Skip to main content
Test and simulation use only. Real payment systems keep clear PINs and keys inside a hardware security module (HSM). Use this module to generate test data and to check what your system under test produces, never to handle real cardholder PINs or production keys.

Installation

This installs the cryptography package.

PIN Blocks (ISO 9564-1)

Formats 0, 1 and 3 fit field 52 in every version (8 bytes). Format 4 is 16 bytes, which fits field 52 in the 1993 and 2003 versions.
Format 4 needs an AES key (128, 192 or 256 bits):
For clear (unencrypted) blocks in formats 0, 1 and 3, use encode_pin_block and decode_pin_block:
Decrypting with the wrong key raises SecurityError in every format, because the result fails the block’s structure checks. A wrong PAN is always caught in format 4, but only sometimes in formats 0 and 3: there the PAN is applied with a single XOR, so a different PAN can decode to a well-formed block with a different PIN. That is a property of those formats.

MACs (ISO 9797-1)

Padding method 1 (zeros, the default) and method 2 (0x80 then zeros) are supported.

Signing and verifying messages

build_with_mac builds a message and puts its MAC in the last field: field 64, or field 128 when the message has a secondary bitmap.
The MAC covers every character of the message before the MAC field, including the MTI and bitmap. Any change to the message makes verification fail.

Raw data

Pass length=4 to generate_mac for a 4-byte MAC. verify_mac takes the length from the MAC you give it.