Glossary
- Account servicing entity (ASE)
- An entity that provides and maintains payment and/or cardholder accounts for its customers and is a regulated entity in the country/countries it operates
- Acquirer
The ASE or other financial institution that manages a merchant’s POS terminal
- Application file locator (AFL)
A data object in EMV cards and NFC payments that tells a POS terminal exactly which files and records to read to process a transaction
- Application interchange profile (AIP)
A 2-byte data object sent by an EMV card to the POS terminal during the GET PROCESSING OPTIONS step
- Application protocol data unit (APDU)
A communication unit exchanged between terminal and card, consisting of commands and responses
- Asymmetric key
- A cryptographic system that uses a mathematically linked pair of keys: a public key and a private key
- Base derivation key (BDK)
The root key from which a unique IPEK is derived for each device or terminal
- Card risk management data object list (CDOL)
- Specifies the data elements that the POS terminal must provide to the card during the first and second
GENERATE APPLICATION CRYPTOGRAMcommands. Exists as two different fields:CDOL1andCDOL2. A trusted organization that verifies identities and binds them to cryptographic keys by issuing digital certificates
A symmetric-key cryptographic algorithm used to ensure the integrity and authenticity of a message
- Country code
- A combination of letters and/or numbers that represent the names of countries, aligned with ISO 3166-1 alpha-2
- Data group identifier (DGI)
- A 2-byte identifier used during card personalization to group related data elements when loading data onto the card
- Derived unique key per transaction (DUKPT)
- A key management scheme used primarily in payment systems (for example, POS terminals) to ensure each transaction is encrypted with a unique key, dramatically reducing the risk of compromise. It’s defined by the ANSI X9.24-3 standard.
- Elliptic curve digital signature algorithm (ECDSA) P-256 key
- A 256-bit key used to generate digital signatures. It’s a public key used at the ASE to verify transactions signed by the card chip.
A 5- to 16-byte code used by POS terminals to identify and select the specific payment application on a chip card
A software engine that manages EMV protocol logic, data exchange, and cryptographic processing required to authorize a payment during a transaction between a POS terminal and an EMV chip card.
- Europay, Mastercard, Visa (EMV)
- A global security standard for chip-based credit and debit cards
- File control information (FCI)
Data returned from a card containing application configuration information
- GNU privacy guard (GPG)
An open source implementation of the OpenPGP standard (
RFC 4880) supporting signing, encryption, and key management
Physical device that provides secure key storage and cryptographic processing designed to protect sensitive data and perform secure operations
- Initial PIN encryption key (IPEK)
- Used to derive session keys for each transaction, ensuring that no two transactions share the same encryption key
- Integrated circuit card (ICC)
A plastic card with an embedded microchip, commonly known as a chip card or smart card; must be EMV-compliant with an Open Payments-enabled wallet address
- ILP extension
An open protocol stack designed to facilitate the transfer of value across different currencies, platforms, and payment networks. For more information, refer to the
Interledger specification.
- Issuer
The ASE or other financial institution that provides and manages cards for the customer
- Issuer Identification number (IIN)
The first eight or nine digits on a payment card which are tied to the ASE or other financial institution that issued the card. Ensures transactions are routed correctly and helps to verify the legitimacy of a card and its issuing organization.
- Issuer public key certificate
- A digitally signed document issued by a trusted CA that verifies the identity of the issuer and authenticates their public key
- Kernel
- The core software component in a POS terminal that manages the complex interaction between the payment card (the chip) and the terminal
- Key check value (KCV)
Short cryptographic value derived from a key, used to verify that the key was correctly transferred or entered without revealing the key itself
- Key serial number (KSN)
- Unique identifier for each POS device, used in key derivation
- Key wrapping
A cryptographic process that encrypts one or more cryptographic keys using another master key
- Know-your-business (KYB)
- A mandatory due-diligence process where companies verify the identities, legitimacy, and risk profiles of their corporate clients
- Local master key (LMK)
- Top-level encryption key used to secure and manage other keys in the HSM, playing a central role in the HSM’s key hierarchy
- Location
- A physical store, branch, or any logical site at which POS terminals can be deployed
- Message authentication code (MAC) key
- A shared secret cryptographic key used alongside an algorithm to authenticate and integrity-check a message, also known as an authentication tag
- Merchant
- A legal entity that accepts payments, owns locations and POS terminals, and manages POS trust RKI, IPEK lifecycle, and compliance)
A set of communication protocols that enables communication between two electronic device
- Open Payments
- An API standard and a set of APIs that allows clients to securely retrieve account information and authorize payments from a customer’s account with their consent. For more information, refer to the Open Payments documentation.
- Open Payments-enabled wallet address
- See wallet address
- Payment card industry (PCI)
- A set of global security guidelines established by major credit card networks to ensure that businesses accept, process, store, and transmit cardholder data securely
- Payment service provider (PSP)
A third-party company that acts as an intermediary, allowing businesses to securely accept electronic payments from customers
An EU regulation designed to make online payments more secure, increase competition, and drive open banking; mandates SCA to prevent fraud and requires banks to open customer data via APIs to authorized third-party providers
- Primary account number (PAN)
The 12- to 19-digit number embossed on the front of a credit, debit, or prepaid card that identifies the specific cardholder account
The device that initiates card-present payment transactions at a location and runs the EMV kernel and ILP extensions
- Pretty good privacy (PGP)
An encryption program that provides privacy and authentication for data communication, combining public-key and symmetric-key cryptography to ensure that messages remain confidential and can be verified for authenticity
A highly secure alphanumeric code used in cryptography to encrypt, decrypt, or digitally sign data
- Processing options data object list (PDOL)
Specifies the data elements that the POS terminal must provide to the card when initiating EMV processing using the
GET PROCESSING OPTIONScommand- Proprietary Application Identifier Extension (PIX)
The second half of an EMV application ID that identifies a card’s specific issuer
- Proximity payment system environment (PPSE)
- A contactless directory used to discover supported payment apps
An openly shared cryptographic code that allows anyone to securely encrypt messages or verify digital signatures intended for a specific recipient; operates as the foundational half of an asymmetric key pair, working exclusively alongside a corresponding private key.
- Public key certificate
- A secure digital document that binds a cryptographic public key to a specific entity; also known as a digital certificate
- Rafiki
- Open source software freely available to any licensed ASE that simplifies implementing ILP and Open Payments on end-users’ accounts
- Registered application provider identifier (RID)
The first half of an EMV application identifier that identifies a card’s scheme
- Remote key injection (RKI)
- A secure, over-the-network process used by merchants and processors to load cryptographic PIN encryption keys onto POS terminals
- Secure reading and exchange of data (SRED) encryption key
- The cryptographic key that’s stored inside secure hardware devices to encrypt sensitive card data before it ever reaches a network
- Session key
- Derived from the IPEK for encrypting a single transaction
- Signed dynamic application data (SDAD)
A unique, card-generated cryptographic signature used in EMV chip transactions that proves the card is authentic, actively participating in the transaction, and prevents skimming or cloning
- Signed static application data (SSAD)
A digital signature stored on a payment card to verify its authenticity during an offline transaction; acts as proof that critical financial data elements on the card were genuinely created by the card issuer and haven’t been altered since the card was printed
A regulatory requirement (PSD2) requiring two-factor authentication for payments
- Symmetric key
- A single, shared cryptographic secret used by both a sender and a receiver to encrypt and decrypt data. The identical symmetric key is used at the ASE to verify the transaction.
- Terminal master key (TMK)
- Used to secure the transmission of working keys (like PIN, SRED encryption keys, or MAC keys) between a terminal and the HSM
- TR-31 key block
- A standardized format used to securely exchange cryptographic keys between systems in financial environments involving HSMs
A secure, unique URL of a payment account that supports Open Payments. It acts as an entry point into the Open Payments APIs, facilitating interactions like sending and receiving payments.
- X.509 certificate signing request (CSR)
An encoded text block submitted to a CA to apply for an SSL/TLS certificate. It contains identity details and a public key, and is digitally signed by a corresponding private key to ensure authenticity
- Zone master key (ZMK)
Cryptographic key used to securely exchange other encryption keys between two systems or organizations, typically between two HSMs that are part of different cryptographic zones