Z13S Cryptographic Support In Z/Os - IBM z13s Technical Manual

Table of Contents

Advertisement

Important: Products that include any of the cryptographic feature codes contain
cryptographic functions that are subject to special export licensing requirements by the
United States Department of Commerce. It is your responsibility to understand and adhere
to these regulations when you are moving, selling, or transferring these products.
To access and use the cryptographic hardware devices that are provided by z13s servers, the
application must use an application programming interface (API) provided by the operating
system. In z/OS, the Integrated Cryptographic Service Facility (ICSF) provides the APIs and
manages access to the cryptographic devices, as shown in Figure 6-3.
Figure 6-3 z13s cryptographic support in z/OS
ICSF is a software component of z/OS. ICSF works with the hardware cryptographic features
and the Security Server (IBM RACF® element) to provide secure, high-speed cryptographic
services in the z/OS environment. ICSF provides the APIs by which applications request the
cryptographic services, as well from the CPACF and Crypto Express5S features. ICSF
transparently routes application requests for cryptographic services to one of the integrated
cryptographic engines, either CPACF or a Crypto Express5S card, depending on
performance or requested cryptographic function. ICSF is also the means by which the
secure Crypto Express5S features are loaded with master key values, allowing the hardware
features to be used by applications. The cryptographic hardware installed in the z13s server
determines the cryptographic features and services available to the applications.
The users of the cryptographic services call the ICSF API. Some functions are performed by
the ICSF software without starting the cryptographic hardware features. Other functions result
in ICSF going into routines that contain proprietary z Systems crypto instructions. These
instructions are run by a CPU engine and result in a work request being generated for a
cryptographic hardware feature.
206
IBM z13s Technical Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents