Chapter 5
Developing and Administering Financial Services
125
Key Management Overview
To meet the strict key management requirements of financial institutions, the Sun
Crypto Accelerator 6000 board adheres to the following essential financial key
management principles.
Key Separation and Compartmentalization of Risk
Keys must be used for specifically defined functions only. This requirement limits
potential damage from a key compromise. To meet this requirement, functional key
type information is associated with each financial key. The board allows generating
and importing the types of keys defined in the following list, and enforces the keys
use for specific operations only.
The following types of financial keys are supported:
■
Master file key (MFK)
The Sun Crypto Accelerator 6000 board is a dedicated hardware security
module (HSM). The MFK never leaves the secure HSM and encrypts other
operational keys when they leave the HSM. An MFK can be used only on the
encrypting HSM. MFKs are entered into the board in component form with the
direct input device.
■
Key encryption key (KEK)
Encrypts other keys for key exchange operations. The KEKs are entered into
the board in component form with the direct input device.
■
PIN encryption key (PEK)
Encrypts PINs. There are two types of supported PEKs:
■
Terminal PIN Key (TPK) – Encrypts PINs on the terminal side of the
transaction (ATM, POS device).
■
Zone Working Key (ZWK) – Encrypts PINS when transferring between
different financial institutions.
■
PIN verification key (PVK)
Verifies PIN operations.
■
Card verification key (CVK)
Verifies card operations.
Summary of Contents for Crypto Accelerator 6000 Board
Page 1: ...Sun Crypto Accelerator 6000 Board Version 1 1 User s Guide Part No E39851 01 February 2013...
Page 16: ...xvi Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 18: ...xviii Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 21: ...Preface xxi...
Page 22: ...xxii Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 54: ...32 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 118: ...96 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 210: ...188 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 228: ...206 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 242: ...220 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 256: ...234 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 260: ...238 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...
Page 266: ...244 Sun Crypto Accelerator 6000 Board User s Guide for Version 1 1 February 2013...