536
IBM z13s Technical Guide
exportable. The applet also creates two Advanced Encryption Standard (AES) symmetric
keys. One of these AES keys is known as the
key-encrypting key (KEK), which is retained on
the smart card. The KEK can also be exported. The other AES key becomes the
Flash
encryption key/authentication key
and is encrypted by the KEK.
A buffer is allocated containing the KEK-encrypted flash encryption key/authentication key
and the unique serial number of the SE. The buffer is padded per Public-Key Cryptography
Standards #1 (PKCS #1) and then encrypted by the smart card RSA public key. The
encrypted content is then written to a file on the SE hard disk.
This design defines a tight coupling of the file on the SE to the smart card. The coupling
ensures that any other SE is not able to share the file or the smart card that is associated with
an SE. It ensures that the encrypted files are unique and all such smart cards are uniquely
tied to their SEs.
All key generation, encryption, and decryption occur on the smart card. Keys are never in the
clear. The truly sensitive key, the flash encryption key/authentication key, is only in the file on
the SE until it is served to the firmware management of the Flash Express adapter.
Figure H-6 shows the cryptographic keys that are involved in creating this tight-coupling
design.
Figure H-6 Integrated Key Controller
The flash encryption key/authentication key can be served to the firmware management of
the Flash Express adapter. This process can be either upon request from the firmware at
initial microcode load (IML) time or from the SE as the result of a request to “change” or “roll”
the key.
Support Element (SE)
Integrated
Key
Controller
SE
Hard
Disk
Flash Encryption Key
/ Authentication Key
Support
Element
Serial Number
Keys Generated in the Smart Card
AES Key-Encrypting Key AES Flash Encryption Key /
Authentication Key
RSA Private Key
RSA Public Key
Содержание z13s
Страница 2: ......
Страница 3: ...International Technical Support Organization IBM z13s Technical Guide June 2016 SG24 8294 00 ...
Страница 24: ...THIS PAGE INTENTIONALLY LEFT BLANK ...
Страница 164: ...136 IBM z13s Technical Guide ...
Страница 226: ...198 IBM z13s Technical Guide ...
Страница 256: ...228 IBM z13s Technical Guide ...
Страница 414: ...386 IBM z13s Technical Guide ...
Страница 464: ...436 IBM z13s Technical Guide ...
Страница 476: ...448 IBM z13s Technical Guide ...
Страница 498: ...470 IBM z13s Technical Guide ...
Страница 502: ...474 IBM z13s Technical Guide ...
Страница 568: ...540 IBM z13s Technical Guide ...
Страница 578: ...550 IBM z13s Technical Guide ...
Страница 584: ...556 IBM z13s Technical Guide ...
Страница 585: ...ISBN 0738441678 SG24 8294 00 1 0 spine 0 875 1 498 460 788 pages IBM z13s Technical Guide ...
Страница 586: ......
Страница 587: ......
Страница 588: ...ibm com redbooks Printed in U S A Back cover ISBN 0738441678 SG24 8294 00 ...