payShield 10K Installation and User Guide
©Thales Group
Page 446
All Rights Reserved
Import Key encrypted under KTK (KK)
Variant
Key Block
Online
Offline
Secure
Authorization:
Required
Activity:
command.kk.console
Command:
KK
Function:
To translate a key from encryption under a KTK to encryption under an LMK.
Authorization:
The HSM must either be in the Authorized State, or the activity
command.kk.console
must be authorized.
Inputs:
•
LMK Identifier
•
Key Type Code
•
Key Scheme (LMK)
•
KTK Identifier
•
Key encrypted under KTK
Outputs:
•
Key encrypted under LMK
Example 1:
This example demonstrates the use of the KK console command to import
a double-length DES ZMK (key type 000) from encryption under KTK Id 01
to encryption under LMK Id 02.
Online-AUTH>
KK
<Return>
Enter LMK id:
02
<Return>
Enter Key type:
000
<Return>
Enter Key Scheme (LMK):
U
<Return>
Enter KTK id:
01
<Return>
Enter key: U
XXXX XXXX XXXX XXXX XXXX XXXX XXXX XXXX
<Return>
LMK encrypted key: U YYYY YYYY YYYY YYYY YYYY YYYY YYYY
YYYY
Key check value: ZZZZZZ
Online-AUTH>