IPEK export for injection into device.

Jun 12, 2014 at 6:33 AM
Edited Jun 12, 2014 at 6:50 AM
Hi all,
I'm trying to realize how to inject HSM generated IPEK into device.
I was able to generate BDK, generate IPEK, export IPEK under ZMK. I need to get 'clear' IPEK to inject into device. What is the right approach for that? HSM is payShield 9000
Thanks in advance.
Jun 12, 2014 at 11:12 AM
Edited Jun 12, 2014 at 3:40 PM

You can do that into few steps:

1) generate single ZMK component using GC console command and save it;
2) form ZMK from that component into a key using FK console command;
3) export IPEK under ZMK in Z (single), X (double), Y (triple) scheme;
4) decrypt the result of export with any freeware DES calculator using ZMK component. Thee result of decryption will be your plain IPEK.

The calculator you can use can be downloaded from Codeplex, too: https://eftcalculator.codeplex.com/

Marked as answer by 0xcafebabe on 6/12/2014 at 8:49 AM
Jun 12, 2014 at 4:47 PM
Edited Jun 12, 2014 at 4:49 PM
Thanks, Juris!

That what I was doing but probably confused with step 4 and used wrong decryption scheme. Really appreciate!

Jun 13, 2014 at 11:11 AM
Edited Jun 13, 2014 at 11:34 AM
Hi Vitaly!

Sorry, but i did not understand. Did you get ready with IPEK export?

Do you need any future assistance?

Jun 13, 2014 at 4:29 PM
Edited Jun 13, 2014 at 4:30 PM
Hi Juris.

I just wanted to say you thanks. Everything's working like a charm. No more assistance needed.