PIN WORKING KEY

1,308 views
Skip to first unread message

queo1987

unread,
Feb 5, 2010, 4:42:32 AM2/5/10
to jpos-...@googlegroups.com

Dear all,
I have some problems follwing:

After input manual master key for ATM/POS:
- The master key is generate by HSM (from twos clear components)
- and the, PWK encrypted is send to ATM/POS, the ATM will decrypt PWK
Encrypted to get PWK clear.

Quest:
-What will POS/ATM do with PWK clear key?
-After input twos components clear to HSM, what will it do that?

Thank and regards.

-----
----Cheer :drunk: ---
mail: queo...@gmail.com
Yahoo: queo1987
--
View this message in context: http://old.nabble.com/PIN-WORKING-KEY-tp27465529p27465529.html
Sent from the jPOS - Users mailing list archive at Nabble.com.

Mark Salter

unread,
Feb 5, 2010, 5:09:35 AM2/5/10
to jpos-...@googlegroups.com
queo1987 wrote:

> I have some problems follwing:

Which really are Off-Topic on this mailing list. Please therefore tag
the subject as I have done - with "[OT]" on this reply.

This is not the first time I have asked you to do this, it will be the last.

>
> After input manual master key for ATM/POS:
> - The master key is generate by HSM (from twos clear components)
> - and the, PWK encrypted is send to ATM/POS, the ATM will decrypt PWK
> Encrypted to get PWK clear.
>
> Quest:
> -What will POS/ATM do with PWK clear key?

If it stands for "Pin Working Key", It will be used to produce the
encrypt the clear PIN block carrying the cardholder entered PIN from the
ATM to the Issuer for checking.

> -After input twos components clear to HSM, what will it do that?

As you stated it will "generate the master key" and likely return a
response code to indicate success. What this master key will be used
for is hard to tell, given the level of detail provided. I suspect
though that the detail you need is in the HSM or ATM documentation.

--
HSM 'simulating'
Mark

queo1987

unread,
Feb 5, 2010, 8:14:08 PM2/5/10
to jpos-...@googlegroups.com

Dear all,

I have some problems follwing:

After input manual master key for ATM/POS:


- The master key is generate by HSM (from twos clear components)
- and the, PWK encrypted is send to ATM/POS, the ATM will decrypt PWK
Encrypted to get PWK clear.

Quest:
-What will POS/ATM do with PWK clear key?

-After input twos components clear to HSM, what will it do that?

Thank and regards.

-----
----Cheer :drunk: ---
mail: queo...@gmail.com
Yahoo: queo1987
--

View this message in context: http://old.nabble.com/-OT-PIN-WORKING-KEY-tp27476199p27476199.html

Mark Salter

unread,
Feb 6, 2010, 4:14:45 AM2/6/10
to jpos-...@googlegroups.com
Please read all the way through responses, but thankyou for adding the
OT marker.

queo1987 wrote:
> I have some problems follwing:
>
> After input manual master key for ATM/POS:
> - The master key is generate by HSM (from twos clear components)
> - and the, PWK encrypted is send to ATM/POS, the ATM will decrypt PWK
> Encrypted to get PWK clear.
>
> Quest:
> -What will POS/ATM do with PWK clear key?

If it stands for "Pin Working Key", It will be used to produce the
encrypt the clear PIN block carrying the cardholder entered PIN from the
ATM to the Issuer for checking.

> -After input twos components clear to HSM, what will it do that?


As you stated it will "generate the master key" and likely return a
response code to indicate success. What this master key will be used
for is hard to tell, given the level of detail provided. I suspect
though that the detail you need is in the HSM or ATM documentation.

--
Mark

queo1987

unread,
Feb 8, 2010, 2:36:49 AM2/8/10
to jpos-...@googlegroups.com

Dear,
I have a problem about generating terminal pin key key at HSM.

which LMK Pair for Terminal Master key,Terminal PIN Key?
When gen key, if select input from many component clear (2-9), which LMK
Pair souble selected?
Thank and regards

> --
> You received this message because you are subscribed to the "jPOS Users"
> group.
> Please see http://jpos.org/wiki/JPOS_Mailing_List_Readme_first
> To post to this group, send email to jpos-...@googlegroups.com
> To unsubscribe, send email to jpos-users+...@googlegroups.com
> For more options, visit this group at
> http://groups.google.com/group/jpos-users
>
>


-----
----Cheer :drunk: ---
mail: queo...@gmail.com
Yahoo: queo1987
--

View this message in context: http://old.nabble.com/-OT-PIN-WORKING-KEY-tp27476199p27496282.html

Victor Salaman

unread,
Feb 8, 2010, 2:47:02 AM2/8/10
to jpos-...@googlegroups.com
Forgot the [OT] again?

Mark Salter

unread,
Feb 8, 2010, 6:11:08 AM2/8/10
to jpos-...@googlegroups.com
queo1987 wrote:

> I have a problem about generating terminal pin key key at HSM.
>
> which LMK Pair for Terminal Master key,Terminal PIN Key?

What does the HSM or ATM manual say?

> When gen key, if select input from many component clear (2-9), which LMK
> Pair souble selected?

I'm afraid your questions make very little sense.

Please check the manuals for your ATM and HSM, they will both provide
guidance on key selection.


--
Mark

queo1987

unread,
Feb 8, 2010, 9:03:07 PM2/8/10
to jpos-...@googlegroups.com

Dear,
I'm so sorry. I think this will last time.
When Terminal/POS recived TPK (TPK encryted by HSM), it will decrypt to TPK
Clear.
Quest:
- Dose Terminal use TPK clear or TPK ecrypted to encrypt pin block?
- Which relation between TPK and TMK at Terminal / POS before encrypt
pinblock.

Please reply my question.
Thank and regard.

>> jpos-users+...@googlegroups.com<jpos-users%2Bunsu...@googlegroups.com>


>> > For more options, visit this group at
>> > http://groups.google.com/group/jpos-users
>> >
>> >
>>
>>
>> -----
>> ----Cheer :drunk: ---
>> mail: queo...@gmail.com
>> Yahoo: queo1987
>> --
>> View this message in context:
>> http://old.nabble.com/-OT-PIN-WORKING-KEY-tp27476199p27496282.html
>> Sent from the jPOS - Users mailing list archive at Nabble.com.
>>
>> --
>> You received this message because you are subscribed to the "jPOS Users"
>> group.
>> Please see http://jpos.org/wiki/JPOS_Mailing_List_Readme_first
>> To post to this group, send email to jpos-...@googlegroups.com
>> To unsubscribe, send email to

>> jpos-users+...@googlegroups.com<jpos-users%2Bunsu...@googlegroups.com>


>> For more options, visit this group at
>> http://groups.google.com/group/jpos-users
>>
>
> --
> You received this message because you are subscribed to the "jPOS Users"
> group.
> Please see http://jpos.org/wiki/JPOS_Mailing_List_Readme_first
> To post to this group, send email to jpos-...@googlegroups.com
> To unsubscribe, send email to jpos-users+...@googlegroups.com
> For more options, visit this group at
> http://groups.google.com/group/jpos-users
>


-----
----Cheer :drunk: ---
mail: queo...@gmail.com
Yahoo: queo1987
--

View this message in context: http://old.nabble.com/-OT-PIN-WORKING-KEY-tp27476199p27509396.html

Mark Salter

unread,
Feb 9, 2010, 2:51:56 AM2/9/10
to jpos-...@googlegroups.com
Please subscribe to this directly if you want to ask or reply to questions.

As I indicated here :-

http://tinyurl.com/yfyet49

The use of a generic 'member' in your case 'nabble' for posting is not
acceptable.


queo1987 wrote:
> When Terminal/POS recived TPK (TPK encryted by HSM), it will decrypt to TPK
> Clear.

Perhaps, but more likely it will (inside it's 'HSM') translate the TPK
from under the transport key to under the TMK.

> Quest:
> - Dose Terminal use TPK clear or TPK ecrypted to encrypt pin block?

Clear.

> - Which relation between TPK and TMK at Terminal / POS before encrypt
> pinblock.

A above, I would hazard a guess that the TMK (Terminal Master Key?) is
the key under which the Terminal holds keys.

The TPK being the key to encrypt clear PIN blocks.

The terminal will likely store the TPK under the TMK.

The TMK is therefore the important key and will not be easily accessible.

>
> Please reply my question.
Please subscribe to this mailing list *direct*.

http://tinyurl.com/joinjposusers

--
Mark

chhil

unread,
Feb 9, 2010, 3:15:16 AM2/9/10
to jpos-users

TMK = Key Encryption Key. (parent key)
TPK = Pin Working Key.     (child of parentt key)

The TMK is loaded in the clear on the atm
The TPK is a key encrypted under the TMK obtained from the HSM (i.e. you ask hsm to generate a key under the the TMK).

TPK  is sent in a downline message to the atm, this key is encrypted under the TMK when sent to the atm.
So now the atm has the TMK (in the clear)  and encrypted TPK. Atm  can decrypt the TPK to get a clear TPK. It uses this clear TPK to encrypt the pin block and send it in the request from the atm.


-chhil


Mark

--
You received this message because you are subscribed to the  "jPOS Users" group.
Please see http://jpos.org/wiki/JPOS_Mailing_List_Readme_first
To post to this group, send email to jpos-...@googlegroups.com
To unsubscribe, send email to jpos-users+...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages