Getnet DocsGetnet Docs

Security and PIN Model

The Pinpad Getnet application employs a robust security architecture to protect sensitive cardholder data. This model is built upon three core pillars: RSA asymmetric encryption for messaging data, DUKPT key management for secure PIN and PAN encryption, and the specialized PinEntryActivity module to manage the secure keyboard lifecycle. For the complete encryption model, see Pinpad Encryption.

RSA encryption for sensitive data

The terminal uses an RSA public key, provided by the Host System in the Y19 requirement, to encrypt sensitive card information before it is transmitted. This ensures that even if serial communication is intercepted, the underlying data remains unreadable without the corresponding private key. The encryption applies to the sensitive data returned in the responses of the Y19 (for contactless) and Y02 (for chip/stripe) commands.

The following data elements are encrypted using the RSA key:

  • Track I and Track II data.
  • Security Code (CDS).
  • EMV data.

The PAN (card number) is not encrypted with RSA. It is encrypted separately with 3DES DUKPT — returned as ENC-PAN with its own KSN-PAN — and the PAN inside the RSA-encrypted tracks is masked with zeros. See Pinpad Encryption.

The Host System generates the key pair and passes the modulus and exponent in the Y19 fields RSA and EXP. For the procedure, see Generate and Inject Encryption Keys.

DUKPT key management

The terminal uses DUKPT (Derived Unique Key Per Transaction) to encrypt both the PIN and the PAN. Every transaction derives a unique key from a base key, building the PINBLOCK and KSN (PIN) and the ENC-PAN and KSN-PAN (PAN) sent in Y19 and Y02 responses. The PIN and PAN use independent KSN counters. See Pinpad Encryption for key slots and the ENC and PMK parameters.

The base keys are not generated by the Host. They are injected into the Pinpad’s secure memory in a controlled environment — Slot 3 for the PIN, and Slot 4 for the PAN on dual-key terminals — and the Pinpad never exposes them in clear. If a command references a key slot that holds no key, the operation ends immediately with an error. For the injection procedure, see Generate and Inject Encryption Keys.

PIN handling and verification

The PinEntryActivity manages the secure keyboard UI, capturing user input safely within the terminal’s secure area.

  • UI Behavior: The keyboard allows a maximum of six digits. Every digit entered is masked on the screen specifically with an asterisk (*).
  • Timeout: The secure keyboard has a fixed 10-second timeout. If no action is taken within this window, the entry process expires.

PIN verification methods

The method used is determined by the card’s profile and reported back to the Host:

  • PIN Online: The captured PIN is encrypted using DUKPT and sent to the Host System for remote validation.
  • PIN Offline: The PIN is validated locally by the card’s chip without additional encryption. For CHIP transactions, the field Y02.PVF indicates if an Offline PIN was successfully verified.
  • PIN Offline Cifrado (Encrypted): The PIN is validated by the card but travels encrypted from the secure keyboard to the chip using a key provided by the card itself.

Security behavior rules

  • Command Blocking and Y06: To prevent the interruption of a secure entry, the Pinpad ignores all commands while the secure keyboard is active. This specifically includes the Y06 (Cancel) command.
  • PIN Bypass: For specific issuers, such as American Express, the user can skip PIN entry by pressing “Confirm” without entering digits. The transaction will proceed as if no PIN was required.
  • Validation Failures: If the DUKPT key slot index provided in the command does not correspond to a loaded key in the terminal’s memory, the operation is finalized immediately with an error.
  1. Generate and Inject Encryption Keys: produce the RSA pair and load the DUKPT keys into the terminal.
  2. Process Card Payments: follow the step-by-step transaction flows.
  3. API Commands: review the low-level structure of the Y19 and Y02 commands to correctly populate RSA and DUKPT fields.