payShield 10K Installation and User Guide
payShield 10K Installation and User Guide
© Thales Group
Page 128
All Rights Reserved
8.8.1 Local Master Keys
Note:
Each LMK has its own security setting.
LMKs are used to encrypt operational keys used for encryption, MACing, digital signing, etc. LMKs are secret,
internal to the HSM, and do not exist outside of the HSM except as components or shares held in Smart Cards. Each
HSM can have a unique LMK, or an organization can install the same LMKs on multiple HSMs within a logical
system.
LMKs provide separation between different types of keys to ensure that keys can be used only for their intended
purpose. The payShield 10K supports two types of LMK, both of which provide key separation:
•
Variant LMKs
. These are double- or triple-length Triple-DES keys and provide key separation by encrypting
different types of key with different variants of the LMK. Double-length Variant LMKs have been in use for
many years, and are the most widely used type of LMK. Triple-length Variant LMKs were introduced for later
versions of the payShield.
•
Key Block LMKs
. These are either triple-length Triple-DES keys, or 256-bit AES keys, and key separation
is provided by parameters in the key block which govern characteristics such as usage and exportability of
the protected key.
Key Block LMKs are newer technology than Variant LMKs and so are still less widely used, but provide
security benefits.
This tab provides a table that shows and allows the management of all loaded LMKs stored in the tamper-proof area
of memory in the HSM.
The LMK holders become what are called the “
trusted officers
” because they hold components or shares of the
Master Key that encrypts all other keys as well as two of the (up to 9 possible component holders). They also
become “
authorizing officers
” (not to be confused with the administrators) and can authorize key management
functions such as generating, importing or exporting keys. They can also authorize changes to configuration settings
and other sensitive functions.
8.8.1.1 Generate LMK - create trusted officer
Prerequisite: Your Smart Card has already been commissioned, i.e., it already has the Security Domain stored on it.
To determine your status, navigate to
Summary > Local Master Key
. In the example below, you see that there are
no LMKs listed.