Using A Session Key; Loading The Session Key; Master Key For Pin Encryption - VeriFone MX800 series Programmer's Manual

Hide thumbs Also See for MX800 series:
Table of Contents

Advertisement

Using a Session Key

NOTE

Loading the Session Key

3DES session keys are only loaded in GISKE cipher text under the protection of
the indexed master key, as long as that key has its attribute set to 'KEK' (key
usage attributes = "K0"). The master key must be 3DES. The version of the
incoming key is not checked or saved. The usage attribute of the incoming
working key is checked, but is not saved.
The GISKE key length decryption rule is applied. The length of the master key
must be greater or equal to the length of the working key.
1DES session keys in key-only format are loaded in cipher text under the
protection of the indexed master key, if that key has its attribute set to 'ANY' or
'KEK' (key usage attributes = "K0"). The master key can be a single-, double-, or
triple-length key.
1DES session keys in GISKE format are loaded in cipher text under the protection
of the indexed master key, if that key has its attribute set to 'KEK' (key usage
attributes = "K0"). The version of the incoming key is not checked or saved. The
usage attribute of the incoming working key is checked, but not saved. The master
key can be a single-, double-, or triple-length key.

Master Key for PIN Encryption

Where the PIN Entry zero session key method for 1DES is used, the current
master key must be tagged ANY or PIN ENCRYPTION.
Where the tagged zero GISKE session key method for 3DES is used, the current
master key must be tagged for the specified purpose – key usage =
'P0' - 'PIN ENCRYPTION'
Key Algorithm = 'T' -TDES for double or triple-length keys
'D' - DES for single-length key
'AN' – ANY
Zero GISKE session key for 3DES means all fields are zero in the GISKE key
block.
If zero GISKE support is disabled, the zero GISKE session key causes an error
response from the IPP. The zero session key support is enabled or disabled
through the KM flag. Zero GISKE session key support (PIN entry) is enabled or
disabled through the KM flag.
IPP MS
DUKPT C
AND
OMMUNICATIONS
X
M
800 S
P
ERIES
ROGRAMMERS
P
ACKETS
IPP7
283
G
UIDE

Advertisement

Table of Contents
loading

Table of Contents