VeriFone MX800 series Programmer's Manual page 282

Hide thumbs Also See for MX800 series:
Table of Contents

Advertisement

IPP MS
DUKPT C
AND
OMMUNICATIONS
IPP7
Table 26
Key Management Switching Rules
Rules
b
From 1DES
(VISA)
a
From 1DES
(SPAIN)
c
From Mixed mode
d
From 3DES
a
From SM
Key Mode
1DES and 3DES Key Usage Rules
b
1DES only
c
Mixed mode
d
3DES only
a.
Spain and SM modes not supported in Verix V. Keys are erased as specified.
b.
Least secure mode.
c.
For transition period.
d.
Most secure mode.
e.
The key management register is set using
f.
All DUKPT related keys, counters, and registers are erased when the IPP KM switches between 1DES DUKPT and 3DES
DUKPT. Other MS related information remains untouched.
g.
Key attributes verified means that when a key stored in the IPP is used, the IPP must validate the content of all key
attributes. The attributes of the key are validated against the GISKE specification acceptable for that command.
h.
GISKE key block verified means that when receiving a key block, the IPP must validate both the key block binding method
of the key block and the content of the header. The header of the key is validated against a list of headers acceptable for
that command.
282
M
X
800 S
P
ERIES
ROGRAMMERS
P
ACKETS
To 1DES (VISA)
NC
E
1K
E
E
Load and use of 1DES MS keys allowed
Load KLK allowed
Load 3DES master keys allowed
Use of 3DES master keys not allowed
Load 3DES session keys not allowed
Use of 3DES session keys not allowed
g
Key attributes verified
, except key usage = 'AN' – ANY is allowed
h
GISKE key block verified
Load and use 1DES or 3DES MS keys allowed
Load KLK allowed
1DES master keys used for 1DES session keys
3DES master keys used for 1DES and 3DES keys
Key attributes verified, except: key usage = 'AN' – ANY is allowed
GISKE key block verified
Load and use 3DES MS keys allowed
Load KLK allowed
Load 1DES master keys not allowed
Use of 1DES master keys not allowed
Load 1DES session keys not allowed
Use of 1DES session keys not allowed
Key attributes verified; no exceptions allowed
GISKE key block verified
Packet 17: Set IPP7 Key Management
G
UIDE
a
To Mixed Mode
To 1DES (SPAIN)
E
NC
NC
E
E
NC
E
E
E
E
e
f
To 3DES
2/3K
E
2/3K
NC
E
Mode.
a
To SM
E
E
E
E
NC

Advertisement

Table of Contents
loading

Table of Contents