payShield 10K Installation and User Guide
© Thales Group
Page 21
All Rights Reserved
1.11 Trusted Management Device (TMD)
1.11.1 Introduction
This section provides an outline of the Trusted Management Device (TMD) provided by Thales to securely manage
key components to meet the latest standards from PCI. The TMD replaces the Thales Key Management Device
(KMD) which is end of sale.
For further detailed information on the TMD please refer to the TMD User Guide.
1.11.2 Background
Secure key management is crucial to the security of the system in which the payShield 10K is used. One particular
area of importance is the exchange of symmetric encryption keys between parties in the payment network (such as
an Acquirer and a Switch) who need to exchange data securely. There is a large number of such keys, and these
need to be refreshed regularly, and so there is a frequent need to exchange working keys between parties. In order
to protect these keys while they are being exchanged electronically, the working keys are encrypted by a master key
(such as a Zone Master Key, or ZMK).
The master key still needs to be provided by one party to the other, and this transfer also has to be secured.
However, master keys need to be transferred only infrequently, and so a less automated mechanism is acceptable.
In general the institution providing the master key will issue it in the form of a number (typically 3) of components to
different officers in the receiving institution, and these officers will come together and enter their components
individually into a secure system.
In the past it has been acceptable to enter the components directly into the payment HSM such as the payShield
10K using the Console interface. However the latest PCI standards require use of a Secure Cryptographic Device
(SCD) such as the Thales Trusted Management Device (TMD). This replaces the Thales Key Management Device
(KMD) which is end of life.
1.11.3 Description
The TMD offers secure, flexible and efficient key management for payment HSMs. It is a compact,
intuitive, self-contained secure cryptographic device (SCD) that enables you to perform symmetric key
management tasks including securely forming keys from separate components or splitting existing keys
retrospectively into new components. The TMD generates and shares keys in a manner that is
compliant with relevant security standards, including X9 TR-31, ANSI X9.24-1 and PCI PIN Security.
Unlike traditional approaches, these critical key management tasks can be carried out without any
physical connection to a production HSM, providing greater operational flexibility without compromising
security. For example, a single payShield TMD can form keys for multiple payment HSMs distributed
across multiple data centers, enabling large payment processors to create and distribute thousands of
Key Encrypting Keys (KEKs) or Zone Master Keys (ZMKs) in a timely and secure manner while
eliminating data entry errors.
Each TMD shares one or more Master ZMKs (MZMKs) with the HSMs to facilitate secure exchange of
key material. The TMD does not require access to the Local Master Keys (LMKs) used by the production
HSMs. Keys exchanged between TMD and an HSM are encrypted under the appropriate MZMK.