track 1&2 encrypted
•
sessionID encrypted
•
track 1 hashed
•
track 2 hashed
•
track 3 hashed (optional)
•
DUKPT serial number
•
Non-ISO/ABA Data Output Format:
card encoding type
•
track status
•
track 1 length
•
track 2 length
•
track 3 length
•
track 1 data
•
track 2 data
•
track 3 data
•
10.5. DUKPT Level 3 Data Output Enhanced Format
This format is the standard encryption format but not yet the default encryption format.
This mode is used for the following reasons below:
When all tracks must be encrypted.
•
When encrypted OPOS support is required.
•
When the tracks must be encrypted separately.
•
When cards other than type 0 (ABA bank cards) must be encrypted.
•
When track 3 must be encrypted.
•
1. Encryption Output Format Setting:
Command:
53 85 01 <Encryption Format>
Encryption Format:
'00h': Original Encryption Format
'01h': Enhanced Encryption Format
2. Encryption Option Setting: (for enhanced encryption format only)
Command:
53 84 01 <Encryption Option>
Encryption Option: (default 08h)
bit0: 1 – track 1 force encrypt
SecureMag Encrypted MagStrip Reader User Manual
(AES/TDES encrypted data)
(AES/TDES encrypted data)
(20-bytes SHA1-Xor)
(20-bytes SHA1-Xor)
(20-bytes SHA1-Xor)
(10-bytes)
(1: AAMVA, 3: Others)
(bit 0,1,2:T1,2,3 decode, bit 3,4,5:T1,2,3 sampling)
(1-byte, 0 for no track1 data)
(1-byte, 0 for no track2 data)
(1-byte, 0 for no track3 data)
Page | 34