Thales Key Block (payShield)

Reads and builds the key block a Thales payShield produces under a Key Block LMK: version ID "1", AES-protected, with the two header characters X9.143 leaves reserved carrying the LMK identifier, and a key usage table that adds Thales-only numeric codes such as 72 (ZPK) and 51 (TMK). Parse reads the header alone, Decode also decrypts the wrapped key and verifies the CMAC authenticator with the protection key, and Create wraps a clear key into a new version 1 block. Parse and Decode also accept X9.143/TR-31 versions A, B, C and D, so the same screen handles a block that left the HSM in either format.

Inputs

Tips

Standards: ANSI X9.143, ASC X9 TR-31:2018, ANSI X9.24-1, NIST SP 800-38B, PCI PIN Security Requirement 18, Thales payShield 10K Core Host Commands

Open the Thales Key Block (payShield) tool — free, runs entirely in your browser.

Related Key Management tools