payShield host commands

Key management

payShield A4 — Form a Key from Encrypted Components

answers with A5

Form a key by XORing 2-3 components — each an S… component key block from A2 (opened under the LMK), or clear hex from a printed slip

Fields

FieldWhat it holds
Key Type3 chars000 (ZMK), 001 (ZPK), 002 (TMK/TPK), 003 (PVK), 009 (MAC key)
Number of Components1 chars2 or 3
Component 132 or 48 or 97 or 129 charsS… component key block from A2, or 32/48 clear hex as printed
Component 232 or 48 or 97 or 129 charsS… component key block from A2, or 32/48 clear hex as printed
Component 332 or 48 or 97 or 129 charsS… component key block from A2, or 32/48 clear hex (optional)

Worked values

Example values for each field. The key blocks work against the Thales test LMK the simulator ships with.

From encrypted components (A2 output)
Key Type
000
Number of Components
2
Component 1
S10096K0TN00N0000686CB9D8340B3EC327B33C7350D7246B650CEB8E8099C2808A8C211BF0F3A23167F390EE389605F5
Component 2
S10096K0TN00N0000F856BB95F949241DA5D534A55D99B171F8C8DF0D632F6618F7E02484FF9F18A5272727314F29258F
From clear components (as printed)
Key Type
000
Number of Components
2
Component 1
0123456789ABCDEFFEDCBA9876543210
Component 2
89ABCDEF0123456789ABCDEF01234567
Open A4 in the simulator

Key management