Translating IBM PVK using VISA ZCMK

Feb 24, 2015 at 9:10 AM

I am running with a project where VISA would verify card holder PINS during Issuer Offline. Now during testing with VISA , VISA has given a requirement where they want the clear PVK to be encrypted under VISA ZCMK in my HSM and to be provided to them.

I am not sure how to do this. I have HSM Thales 9000 and 8000 both. And we do IBM PVV offset method for Pin Validation.

Thanks in Advance to help.

Feb 24, 2015 at 9:16 AM
Hi Also

My VISA Test Clear ZCMK is

2034 E62C BC73 FBE6
A764 D3A4 7980 D680
B68C CD45 FB38 C7B3

XOR'ed = 31DC F8CD 3ECB EAD5

And Test IBM Clear 15EA 4CA2 0131 C2FD

My key Scheme Z
Feb 26, 2015 at 5:53 AM

You just need to form the Visa ZCMK using console of HSM, FK command and export PVK under formed ZCMK using KE command.

Mar 2, 2015 at 6:06 AM
Hi Manshtein

Thank you for your response it helped. Additionally i have a encrypted PVK , is there a way if i want to know what were the clear values?

Mar 2, 2015 at 11:07 AM

Sure. If you want to decrypt the key (eg. PVK) from under LMK, just use the ZMK key with known clear value to export PVK to under ZMK and decrypt the result using usual DES calculator, eg. EFT Calculator.

You can achieve this in few steps:
1) generate 1 clear ZMK component with console command GC;
2) form ZMK component into ZMK under LMK using FK console command;
3) export PVK under ZMK using scheme 'X';
4) the export result can be decrypted using plain ZMK component and EFT calculator.