Built for authorized development, certification, and performance testing support@isotran.com
EMV & payment cryptography

Test the payment data behind the transaction—not only the ISO fields around it.

IsoTran composes card, ICC, terminal, device, transaction, and cryptographic inputs to generate realistic test messages and support investigation of issuer-side EMV and security behavior.

TEST CARD PROFILE
5413 •••• •••• 0089ICC / CONTACT & CONTACTLESS
APPLICATION CRYPTOGRAM9F26A7 84 3C 9E 12 6F 80 D1
ARQCATCIADUN
The testing problem

EMV behavior depends on coordinated card, terminal, transaction, and key data.

Copying a static field 55 payload cannot fully exercise changes in cryptogram generation, counters, transaction context, card-risk data, terminal results, or issuer authentication. IsoTran builds the message from reusable profiles and dynamic execution inputs.

  • Generate transaction-specific EMV data instead of replaying a fixed payload
  • Keep card and device behavior explicit and reusable
  • Support CVN-aware cryptogram inputs and issuer response validation
  • Investigate the relationship between ISO 8583 fields, TLV data, and security outcomes
Profile-driven composition

Build the transaction from the same layers that influence EMV behavior

IsoTran combines reusable profiles with values created at execution time.

01

Card & account

PAN, expiry, service data, account context, programs, groups, and reusable card populations.

02

ICC application

AID, AIP, CID, IAD/CVR inputs, ATC behavior, CVN selection, session-key context, and cryptogram data.

03

Terminal & device

Terminal capabilities, TVR, country, currency, entry mode, reader behavior, type, location, and device groups.

04

Transaction

Amount, transaction type, message fields, unpredictable data, sequence values, and network-specific formatting.

COMPOSE
ISO 8583 message + EMV TLV + application cryptogram
SEND
Cryptogram-aware testing

Generate the request. Validate the issuer-authentication response.

Use card-profile inputs, transaction data, key material, and the applicable cryptogram method to produce the application cryptogram for a test transaction. When issuer authentication is expected, capture and validate the returned ARPC in the response workflow.

  • Application cryptogram input assembled by the configured CVN method
  • Dynamic ATC, amount, currency, date, transaction type, terminal country, TVR, and unpredictable-number context
  • Issuer Application Data and Cryptogram Information Data generated from reusable profiles
  • Response ARPC capture and validation where required by the simulated flow

Exact supported schemes, CVNs, algorithms, and HSM integration options depend on the licensed IsoTran release and customer configuration.

CARD SIMULATIONARQC9F26
AUTHORIZED TEST HOSTIssuer decisionISO 8583 response
ISOTRAN VALIDATIONARPCcaptured + verified
Cryptography Center

Purpose-built workspaces for payment-security testing

Keep sensitive test utilities inside the same permission-aware, on-premises platform as the transactions that use them.

PIN workflows

Create and inspect test PIN blocks, translation inputs, offsets, verification values, and related payment-security data.

Key management utilities

Manage test keys and metadata, calculate check values, apply supported transport and usage formats, and control export access.

MAC generation & verification

Configure MAC profiles, construct inputs, generate values, and verify response authentication behavior.

EMV cryptograms

Generate application cryptograms from configured card, terminal, transaction, and key inputs, then validate issuer authentication data.

Sensitive workflows remain local

Exercise security-dependent behavior without sending test assets to a public SaaS platform.

IsoTran is designed for installation within the customer environment. Access to cryptographic functions can be separated by role, while test data and execution remain under organizational controls.

  • Role- and permission-aware cryptography workspaces
  • Customer-managed deployment, storage, network access, and backup
  • Controlled key export and administrative functions
  • Intended for authorized test data and non-production environments
Go deeper than static field 55 data

Demonstrate your EMV and cryptographic transaction requirements in context.

Review scheme, CVN, card-profile, terminal, key, message-format, issuer-authentication, and response-validation needs with a payment specialist.