Import Key (IK)
Command:
IK
Function:
To import a key from encryption under a ZMK to encryption under an LMK.
If the key imported does not have odd parity a warning will be issued and
odd parity will be forced on the key before encryption under the specified
LMK.
Authorization:
The HSM must either be in the Authorized State, or the activity
command.ik.console must be authorized.
For AES LMKs, keys can only be exported in Thales Key Block format.
• LMK Identifier: 00-99.
Inputs:
• Key Type: See the Key Type
Table in the Host Programmer's
Manual.
• Key Scheme (LMK).
• ZMK to be used to decrypt the
key.
• Key/Key Block to be imported.
• Key encrypted under an
Outputs:
appropriate variant of the selected
LMK.
• Key Check Value.
• For legacy reasons, the import of a ZMK or DEK from encryption under a
Notes:
ZMK (in variant/X9.17 format) to encryption under a key block LMK will not
be permitted. Specifically, such import of keys with key usage = "K0",
"52", "D0", "21" or "22" will be prohibited.
• Use of this command will always create an entry in the Audit Log.
• If the option "Enforce Atalla variant match to Thales key type" is set to YES
in the CS console command, the following matchings between Atalla
variant and Thales variant key types will be enforced:
Key Type
©Thales Group
All Rights Reserved
payShield 10K Installation and User Guide
Variant LMK
Atalla
Variant
Variant
Online
Offline
Authorization: Required
Activity: command.ik.console
Key Block LMK
• LMK Identifier: 00-99.
• Key Scheme (LMK).
• ZMK to be used to decrypt the key.
• Key/Key Block to be imported.
For import from Variant/X9.17:
• Key Usage: See the Key Usage Table
in the payShield 10K Host
Programmer's Manual.
• Mode of Use: See the Mode of Use
Table in the payShield 10K Host
Programmer's Manual.
• Key Version Number: 00-99.
• Exportability: See the Exportability
Table in the payShield 10K Host
Programmer's Manual.
• Optional Block data.
For import from a key block format:
• Modified Key Usage
• Optional Block data.
• Key Block containing the key
encrypted under the selected LMK.
• Key Check Value.
Thales Variant (*)
Key Block
Secure
∅
Thales Variant (
)
Page 378
Need help?
Do you have a question about the payShield 10K and is the answer not in the manual?
Questions and answers
how to clear error alert in Thales HSM 9000?
To clear an error alert in Thales payShield 10K:
1. Navigate to Status > Maintenance in the system interface.
2. Click On to activate maintenance mode.
3. The handle light on payShield 10K should turn blue, indicating maintenance mode is active.
Additionally, if the security setting "Allow Error light to be extinguished when viewing Error Log?" is set to YES, viewing the error log may also clear the error light.
This answer is automatically generated