1.11.5 Example Sequence of Steps to Set-Up and Transfer Keys
This section shows a typical sequence of steps that are used to set up the keys required. Please note:
•
From the payShield 10K perspective, the MZMK is a standard ZMK.
•
The TMD has comprehensive facilities to manage TMD Administrators and Operators using smart cards and
these are set up when the first MZMK is installed – see the TMD User Guide
Note:
•
The host application in the description below is the customer's payment application.
The main steps are:
1. Sharing MZMK between the payShield 10K and the TMD:
a) Use payShield 10K Console Command GS to generate MZMK components on HSM smart cards and to
display the MZMK encrypted under the LMK.
b) Install MZMK in the TMD from the components on smart card generated above.
c) Enter MZMK encrypted under the LMK into the host application database for subsequent use.
2. Sharing ZMK with third party.
a) Use TMD to import ZMK in component form from third party and display ZMK encrypted under the MZMK.
b) Enter ZMK encrypted under the MZMK into the host application.
c) Host application uses host command A6 (or BY) to translate the ZMK from encryption under the MZMK to
encryption under the LMK and stores in the host application for subsequent use.
Note: Instead of using a host command in step c), Console Command IK can be used with the payShield
Manager Virtual Console (or the standard Console) to translate the ZMK from encryption under the MZMK to
encryption under the LMK. This can then be entered into the host application for subsequent use.
3. Sharing Application or Session Keys with Third Party
a) Application or Session keys (e.g. ZPK, PVK) received from the 3rd party encrypted under a ZMK are
translated to encryption under an LMK using host command A6.
b) Host application exports Application or Session keys (e.g. ZPK, PVK) to 3rd party by translating from
encryption under a LMK to encryption under the ZMK using host command A8.
4. Option - Sharing Application Keys with in Component Form with Third Party
a) Use TMD to import the application key (e.g. PVK, CVK) in component form and output key encrypted under
the MZMK on the display.
b) Enter key encrypted under the MZMK into the payment application
c) Host application uses host command A6 to translate the key encrypted under the MZMK to encryption under
the LMK and stores in the host application.
© Thales Group
All Rights Reserved
payShield 10K Installation and User Guide
Page 23
Need help?
Do you have a question about the payShield 10K and is the answer not in the manual?
Questions and answers
how to clear error alert in Thales HSM 9000?
To clear an error alert in Thales payShield 10K:
1. Navigate to Status > Maintenance in the system interface.
2. Click On to activate maintenance mode.
3. The handle light on payShield 10K should turn blue, indicating maintenance mode is active.
Additionally, if the security setting "Allow Error light to be extinguished when viewing Error Log?" is set to YES, viewing the error log may also clear the error light.
This answer is automatically generated