# Security and PIN Model

The Pinpad Getnet application employs a robust security architecture to protect sensitive cardholder data. This model is built upon three core pillars: RSA asymmetric encryption for messaging data, DUKPT key management for secure PIN and PAN encryption, and the specialized **PinEntryActivity** module to manage the secure keyboard lifecycle. For the complete encryption model, see [Pinpad Encryption](https://docs.globalgetnet.com/en/products/in-store-payments/host-to-host?doc=h2h-pinpad-encryption).

## RSA encryption for sensitive data

The terminal uses an RSA public key, provided by the Host System in the `Y19` requirement, to encrypt sensitive card information before it is transmitted. This ensures that even if serial communication is intercepted, the underlying data remains unreadable without the corresponding private key. The encryption applies to the sensitive data returned in the responses of the `Y19` (for contactless) and `Y02` (for chip/stripe) commands.

The following data elements are encrypted using the RSA key:

* **Track I and Track II data**.
* **Security Code (CDS)**.
* **EMV data**.

<Callout type="warning">

The **PAN (card number)** is **not** encrypted with RSA. It is encrypted separately with 3DES DUKPT — returned as `ENC-PAN` with its own `KSN-PAN` — and the PAN inside the RSA-encrypted tracks is masked with zeros. See [Pinpad Encryption](https://docs.globalgetnet.com/en/products/in-store-payments/host-to-host?doc=h2h-pinpad-encryption).

</Callout>

The Host System generates the key pair and passes the modulus and exponent in the `Y19` fields `RSA` and `EXP`. For the procedure, see [Generate and Inject Encryption Keys](https://docs.globalgetnet.com/en/products/in-store-payments/host-to-host?doc=h2h-generate-and-inject-keys).

## DUKPT key management

The terminal uses **DUKPT** (Derived Unique Key Per Transaction) to encrypt both the **PIN** and the **PAN**. Every transaction derives a unique key from a base key, building the **PINBLOCK** and **KSN** (PIN) and the **`ENC-PAN`** and **`KSN-PAN`** (PAN) sent in `Y19` and `Y02` responses. The PIN and PAN use independent KSN counters. See [Pinpad Encryption](https://docs.globalgetnet.com/en/products/in-store-payments/host-to-host?doc=h2h-pinpad-encryption) for key slots and the `ENC` and `PMK` parameters.

The base keys are not generated by the Host. They are injected into the Pinpad's secure memory in a controlled environment — **Slot 3** for the PIN, and **Slot 4** for the PAN on dual-key terminals — and the Pinpad never exposes them in clear. If a command references a key slot that holds no key, the operation ends immediately with an error. For the injection procedure, see [Generate and Inject Encryption Keys](https://docs.globalgetnet.com/en/products/in-store-payments/host-to-host?doc=h2h-generate-and-inject-keys).

## PIN handling and verification

The **PinEntryActivity** manages the secure keyboard UI, capturing user input safely within the terminal's secure area.

* **UI Behavior**: The keyboard allows a maximum of six digits. Every digit entered is masked on the screen specifically with an **asterisk (\*)**.
* **Timeout**: The secure keyboard has a fixed **10-second timeout**. If no action is taken within this window, the entry process expires.

### PIN verification methods

The method used is determined by the card's profile and reported back to the Host:

* **PIN Online**: The captured PIN is encrypted using DUKPT and sent to the Host System for remote validation.
* **PIN Offline**: The PIN is validated locally by the card's chip without additional encryption. For CHIP transactions, the field **Y02.PVF** indicates if an Offline PIN was successfully verified.
* **PIN Offline Cifrado (Encrypted)**: The PIN is validated by the card but travels encrypted from the secure keyboard to the chip using a key provided by the card itself.

## Security behavior rules

* **Command Blocking and Y06**: To prevent the interruption of a secure entry, the Pinpad ignores all commands while the secure keyboard is active. This specifically includes the **Y06 (Cancel)** command.
* **PIN Bypass**: For specific issuers, such as **American Express**, the user can skip PIN entry by pressing "Confirm" without entering digits. The transaction will proceed as if no PIN was required.
* **Validation Failures**: If the DUKPT key slot index provided in the command does not correspond to a loaded key in the terminal's memory, the operation is finalized immediately with an error.

## Related resources

1. [**Generate and Inject Encryption Keys**](https://docs.globalgetnet.com/en/products/in-store-payments/host-to-host?doc=h2h-generate-and-inject-keys): produce the RSA pair and load the DUKPT keys into the terminal.
2. [**Process Card Payments**](https://docs.globalgetnet.com/en/products/in-store-payments/host-to-host?doc=h2h-process-card-payments\&section=kei2fli2gqggbwgaddtl3xb7): follow the step-by-step transaction flows.
3. [**API Commands**](https://docs.globalgetnet.com/en/products/in-store-payments/host-to-host?doc=h2h-api-commands\&section=g7b851vgbt737kwul1fmgve2): review the low-level structure of the `Y19` and `Y02` commands to correctly populate RSA and DUKPT fields.