{"id":10240,"date":"2025-12-11T15:03:16","date_gmt":"2025-12-11T14:03:16","guid":{"rendered":"https:\/\/pcihispano.com\/?p=10240"},"modified":"2026-05-06T19:13:14","modified_gmt":"2026-05-06T17:13:14","slug":"la-importancia-de-los-modos-de-cifrado-en-la-criptografia","status":"publish","type":"post","link":"https:\/\/www.pcihispano.com\/en\/la-importancia-de-los-modos-de-cifrado-en-la-criptografia\/","title":{"rendered":"The Importance of Encryption Modes in Cryptography"},"content":{"rendered":"<p><span class=\"intro-text\">When using encryption, a robust algorithm and an acceptable key length is not enough. There are two other very important parameters that are often forgotten: the encryption mode and parameterization of the initialization vector (<em>Initialization Vector<\/em>, IV). These values are critical when protecting data with a fixed length, such as a personal identification number (<em>Personal Account Number<\/em> \u2013 PAN).<\/span><\/p>\n<h3>Data Encryption and the Problem with Pattern Generation<\/h3>\n<p>The algorithms of <a href=\"https:\/\/es.wikipedia.org\/wiki\/Cifrado_por_bloques\" target=\"_blank\" rel=\"noopener\">Block Encryption<\/a>\u00a0y <a href=\"https:\/\/es.wikipedia.org\/wiki\/Cifrado_de_flujo\" target=\"_blank\" rel=\"noopener\">Flow<\/a> (employees to encrypt fixed and variable length data, respectively) work in a very simple way: receive the data to be protected and the key to encrypt\/decrypt it, and employ a routine that changes the order of the data (encryption algorithm). This set is called a <a href=\"https:\/\/es.wikipedia.org\/wiki\/Criptosistema\" target=\"_blank\" rel=\"noopener\">cryptosystem<\/a>:<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-10241\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2025\/12\/Cifrado.png?resize=774%2C359&#038;ssl=1\" alt=\"\" width=\"774\" height=\"359\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/Cifrado.png?w=940&amp;ssl=1 940w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/Cifrado.png?resize=300%2C139&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/Cifrado.png?resize=768%2C356&amp;ssl=1 768w\" sizes=\"auto, (max-width: 774px) 100vw, 774px\" \/><\/p>\n<p>However, <span class=\"highlight\">This model has a critical vulnerability: when running encryption routines on a dataset limited in size and relatively similar, using the same algorithm and the same key, patterns can be generated<\/span> which can be used as part of an attack (<a href=\"https:\/\/es.wikipedia.org\/wiki\/Criptoan%C3%A1lisis\" target=\"_blank\" rel=\"noopener\">cryptanalysis<\/a>). In the following example, a <a href=\"https:\/\/tripledes.codethoi.com\/\" target=\"_blank\" rel=\"noopener\">encryption routine<\/a> of a block of five consecutive NAP numbers:<\/p>\n<ul>\n<li><strong>Algorithm:<\/strong> TripleDES<\/li>\n<li><strong>Key:<\/strong> 59c5b527f37ff7fbbd5b2478 (double length \u2013 128 bits including parity bits)<\/li>\n<li><strong>Encryption mode<\/strong>: ECB<\/li>\n<li><strong>Padding<\/strong>: None<\/li>\n<li><strong>Data to encrypt<\/strong>: 16 decimal characters = 53 bits<\/li>\n<li><strong>Cryptogram format<\/strong>: Hexadecimal<\/li>\n<\/ul>\n<div class=\"su-table su-table-alternate\">\n<table>\n<tbody>\n<tr>\n<td>4656543289876520<\/td>\n<td><span style=\"color: #ff0000\">3A70F5A513753CDE<\/span>9CE209796E5DD990<\/td>\n<\/tr>\n<tr>\n<td>4656543289876521<\/td>\n<td><span style=\"color: #ff0000\">3A70F5A513753CDE<\/span>41CBFF4CACA02930<\/td>\n<\/tr>\n<tr>\n<td>4656543289876522<\/td>\n<td><span style=\"color: #ff0000\">3A70F5A513753CDE<\/span>4906E893316D0F31<\/td>\n<\/tr>\n<tr>\n<td>4656543289876523<\/td>\n<td><span style=\"color: #ff0000\">3A70F5A513753CDE<\/span>9FEA240365279BFD<\/td>\n<\/tr>\n<tr>\n<td>4656543289876524<\/td>\n<td><span style=\"color: #ff0000\">3A70F5A513753CDE<\/span>353E392C6BEAE5CF<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>As can be seen, in this process a pattern is identified in the first half of the result, caused by the method that TripleDES uses to encrypt the data (divide the data to be encrypted into 64-bit blocks and then encrypt\/decrypt\/encrypt each block with the associated keys):<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"wp-image-612 aligncenter\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2022\/12\/TDEA1.png?resize=508%2C266&#038;ssl=1\" alt=\"\" width=\"508\" height=\"266\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/TDEA1.png?w=380&amp;ssl=1 380w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/TDEA1.png?resize=300%2C157&amp;ssl=1 300w\" sizes=\"auto, (max-width: 508px) 100vw, 508px\" \/><\/p>\n<p>In this case, when the data is limited, as in the case of a PAN (whose length is fixed \u2013 16 characters in most cases and its initial digits are widely known as they are associated with the payment marks: 4 for Visa, 5 for MasterCard, etc.) and the encryption key and algorithm are the same, this reuse of elements will affect the final cryptogram creating patterns, as demonstrated above, affecting the security provided by the encryption. Due to this problem (among many others), it was possible to break the encryption of the German machine <a href=\"https:\/\/es.wikipedia.org\/wiki\/The_Imitation_Game\" target=\"_blank\" rel=\"noopener\">ENIGMA<\/a>.<\/p>\n<h3>Encryption modes<\/h3>\n<p>The case explained above is the simplest of all: Clear text is taken, divided into several blocks of a fixed size and each block is encrypted with the key provided, <span style=\"text-decoration: underline;\">so two identical blocks of text will result in the same cryptogram<\/span>. This encryption mode is called <strong>Electronic Code Book<\/strong> (ECB):<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-10313\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB.png?resize=900%2C487&#038;ssl=1\" alt=\"\" width=\"900\" height=\"487\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB.png?w=1452&amp;ssl=1 1452w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB.png?resize=300%2C162&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB.png?resize=1024%2C554&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB.png?resize=768%2C416&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB.png?resize=1300%2C704&amp;ssl=1 1300w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/p>\n<p>To avoid this problem, an additional data was added to the encryption process called <strong>initialization vector<\/strong> (<a href=\"https:\/\/csrc.nist.gov\/glossary\/term\/IV\" target=\"_blank\" rel=\"noopener\"><em>Initialization Vector<\/em> \u2013 IV<\/a>). This new element is added to the cryptosystem to add a layer of randomness in the process, preventing two equal blocks of data from generating the same output. Obviously, the key to this process is to ensure that the IV is as random as possible and that it is not reused. In addition, it is important to clarify that the IV should not necessarily be a secret data.<\/p>\n<p>Depending on the format and time at which the IV is used, the NIST defined five (5) modes of encryption for block encryption algorithms, listed in the document. <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/38\/a\/final\" target=\"_blank\" rel=\"noopener\"><em>NIST SP 800-38A Recommendation for Block Cipher Modes of Operation: Methods and Techniques<\/em><\/a>:<\/p>\n<ol>\n<li><strong>Electronic Codebook (ECB)<\/strong>, in which each block of text is encrypted independently with the same key.<\/li>\n<li><strong>Cipher Block Chaining (CBC),<\/strong> in which a random IV is combined with the first block of clear text and its output is combined with the next block to encrypt.<\/li>\n<li><strong>Cipher Feedback (CFB),\u00a0<\/strong>in which the initialization vector is encrypted before being combined with the first block of text to encrypt and that output is combined with the next block to encrypt.<\/li>\n<li><strong>Output Feedback (OFB),<\/strong> similar to CFB, only that the encrypted IV is combined independently with each block of clear text before being encrypted.<\/li>\n<li><strong>Counter (CTR),\u00a0<\/strong>in which, instead of using a random IV, a counter is used that is increased during the encryption of each block.<\/li>\n<\/ol>\n<p>Below is a visual example of the CBC operation:<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-10315\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2025\/12\/CBC.png?resize=900%2C515&#038;ssl=1\" alt=\"\" width=\"900\" height=\"515\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/CBC.png?w=1432&amp;ssl=1 1432w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/CBC.png?resize=300%2C172&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/CBC.png?resize=1024%2C586&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/CBC.png?resize=768%2C439&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/CBC.png?resize=1300%2C744&amp;ssl=1 1300w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/p>\n<p>Indications for safe generation of IV are described in the <em>Appendix C: Generation of Initialization Vectors<\/em> from NIST document SP 800-38A.<\/p>\n<p>Using the initialization vector prevents the creation of patterns in the generated cryptograms, ensuring that each cryptogram is different regardless of whether the clear text blocks are the same:<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-10318\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB_vs_others.png?resize=900%2C381&#038;ssl=1\" alt=\"\" width=\"900\" height=\"381\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB_vs_others.png?w=929&amp;ssl=1 929w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB_vs_others.png?resize=300%2C127&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/ECB_vs_others.png?resize=768%2C325&amp;ssl=1 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/p>\n<p>If you repeat the encryption process of the block of five consecutive PAN numbers used previously, but this time using CBC and a different IV for each encryption operation, the following results are obtained:<\/p>\n<ul>\n<li><strong>Algorithm:<\/strong> TripleDES<\/li>\n<li><strong>Key:<\/strong> 59c5b527f37ff7fbbd5b2478 (double length \u2013 128 bits including parity bits)<\/li>\n<li><strong>Encryption mode<\/strong>: CBC<\/li>\n<li><strong>Padding<\/strong>: None<\/li>\n<li><strong>Data to encrypt<\/strong>: 16 decimal characters = 53 bits<\/li>\n<li><strong>Cryptogram format<\/strong>: Hexadecimal<\/li>\n<\/ul>\n<div class=\"su-table su-table-alternate\">\n<table>\n<tbody>\n<tr>\n<td>PAN<\/td>\n<td>IV<\/td>\n<td>Cryptogram<\/td>\n<\/tr>\n<tr>\n<td>4656543289876520<\/td>\n<td>671b89995b7be45b<\/td>\n<td>8bc804dd3c0e395601525f6103e75974<\/td>\n<\/tr>\n<tr>\n<td>4656543289876521<\/td>\n<td>309bf68859959c0c<\/td>\n<td>f2ff5fadd0cc5332453edc8743d19a1a<\/td>\n<\/tr>\n<tr>\n<td>4656543289876522<\/td>\n<td>b991e9fed507d479<\/td>\n<td>79b5cc461a4c883e124d93371bf13183<\/td>\n<\/tr>\n<tr>\n<td>4656543289876523<\/td>\n<td>8623008e355c4725<\/td>\n<td>b6e57d387f34c2673c805cac92f049bd<\/td>\n<\/tr>\n<tr>\n<td>4656543289876524<\/td>\n<td>661ee80ae9ad932a<\/td>\n<td>04ac1af1c9e221e8a06e0c555fe4ae99<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>As you can see, by using a random IV in each round of encryption, the resulting data (cryptogram) is different. Even if the same data is encrypted but with different IV, the result will vary, guaranteeing that there will be no patterns:<\/p>\n<div class=\"su-table su-table-alternate\">\n<table>\n<tbody>\n<tr>\n<td>PAN<\/td>\n<td>IV<\/td>\n<td>Cryptogram<\/td>\n<\/tr>\n<tr>\n<td>4656543289876520<\/td>\n<td>671b89995b7be45b<\/td>\n<td>8bc804dd3c0e395601525f6103e75974<\/td>\n<\/tr>\n<tr>\n<td>4656543289876520<\/td>\n<td>10b57a092c176687<\/td>\n<td>1884560ef41e4584d4a7baa5441a4ece<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h3>QSA recommendations<\/h3>\n<p>To ensure that the cryptography techniques used for the protection of sensitive data are secure, I recommend taking into account the following points:<\/p>\n<ul>\n<li><strong>Using a robust encryption algorithm with an acceptable key length<\/strong>, based on industry best practices. In this case, <a href=\"https:\/\/www.pcihispano.com\/en\/obsolescencia-de-triple-des-tdea-y-su-impacto-en-los-estandares-del-pci-ssc\/\" target=\"_blank\" rel=\"noopener\">avoid the use of TripleDES<\/a> and use AES for block encryption.<\/li>\n<li><strong>Use a secure encryption mode.<\/strong> As discussed above, the use of ECB can lead to the compromise of protected data due to the generation of patterns in cryptograms. However, other encryption modes have also been found to be vulnerable, such as: <a href=\"https:\/\/blog.ise.io\/blog\/the-dangers-of-cbc-mode\" target=\"_blank\" rel=\"noopener\">CBC<\/a>, engaged in attacks such as <a href=\"https:\/\/en.wikipedia.org\/wiki\/Padding_oracle_attack\" target=\"_blank\" rel=\"noopener\">Padding Oracle Attack<\/a>. For this reason, it is suggested to use more secure and recent modes, as is the case of <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/38\/d\/final\" target=\"_blank\" rel=\"noopener\">Galois\/Counter Mode (GCM)<\/a>.<\/li>\n<li><strong>Using Initialization Vectors (IV) Safely<\/strong>: For an IV to provide the expected level of security, it must be safely generated (as random as possible) and not reused. The reuse of the IV was what gave way to the commitment of <a href=\"https:\/\/www.startupdefense.io\/cyberattacks\/wep-cracking\" target=\"_blank\" rel=\"noopener\">Wired Equivalent Privacy<\/a>, a security protocol for the protection of wireless networks. In that case, a weak implementation of the encryption algorithm (RC4) was employed along with <a href=\"https:\/\/cwe.mitre.org\/data\/definitions\/1204.html\" target=\"_blank\" rel=\"noopener\">Short and reused IVs<\/a>.<\/li>\n<li>If there are repositories of sensitive data encrypted with algorithms considered weak and with ECB, it is recommended to proceed with the migration of such information to a robust algorithm with a strong encryption mode.<\/li>\n<\/ul>\n<p>Personally, I recommend the use of <a href=\"https:\/\/medium.com\/@pravallikayakkala123\/understanding-aes-encryption-and-aes-gcm-mode-an-in-depth-exploration-using-java-e03be85a3faa\" target=\"_blank\" rel=\"noopener\">256-bit AES in GCM mode<\/a>, using <a href=\"https:\/\/www.pcihispano.com\/en\/hardware-security-module-hsm-que-es-y-para-que-sirve\/\" target=\"_blank\" rel=\"noopener\">Hardware Security Modules (HSMs)<\/a> trustworthy.<\/p>","protected":false},"excerpt":{"rendered":"<p>When using encryption, a robust algorithm and an acceptable key length is not enough. There are two other very important parameters that are often forgotten: Encryption mode and initialization vector parameterization (Initialization Vector, IV). These [\u2026]<\/p>","protected":false},"author":2,"featured_media":10323,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1,329],"tags":[104,401,402,404,400,408,406,405,403,102,399,407],"class_list":["post-10240","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contenido","category-criptografia","tag-aes","tag-cbc","tag-cfb","tag-ctr","tag-ecb","tag-inicializacion","tag-iv","tag-modos","tag-ofb","tag-tdea","tag-tripledes","tag-vector"],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/encryption.png?fit=1918%2C1078&ssl=1","jetpack-related-posts":[{"id":1404,"url":"https:\/\/www.pcihispano.com\/en\/obsolescencia-de-triple-des-tdea-y-su-impacto-en-los-estandares-del-pci-ssc\/","url_meta":{"origin":10240,"position":0},"title":"Obsolescencia de Triple DES (TDEA) y su impacto en los est\u00e1ndares del PCI SSC","author":"David Acosta","date":"marzo 13, 2024","format":false,"excerpt":"El 1 de enero de 2024 marc\u00f3 un hito en la historia de la criptograf\u00eda moderna: El algoritmo Triple DES (3DES\/TDES o TDEA) fue catalogado como \"obsoleto\" por NIST. Esta noticia hace parte de los esfuerzos de la migraci\u00f3n hacia algoritmos m\u00e1s seguros en la carrera hacia la criptograf\u00eda post-cu\u00e1ntica\u2026","rel":"","context":"In &quot;Criptograf\u00eda&quot;","block_context":{"text":"Criptograf\u00eda","link":"https:\/\/www.pcihispano.com\/en\/category\/criptografia\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":5447,"url":"https:\/\/www.pcihispano.com\/en\/metodos-de-gestion-de-claves-criptograficas-clave-fija-mk-sk-y-dukpt\/","url_meta":{"origin":10240,"position":1},"title":"M\u00e9todos de gesti\u00f3n de claves criptogr\u00e1ficas: clave fija, MK\/SK y DUKPT","author":"David Acosta","date":"enero 29, 2025","format":false,"excerpt":"Cuando se emplean claves criptogr\u00e1ficas sim\u00e9tricas para la protecci\u00f3n de datos almacenados o transmitidos, es necesario establecer ciertos protocolos para su carga, transmisi\u00f3n, rotaci\u00f3n o bloqueo. En los est\u00e1ndares del PCI SSC (principalmente PCI PIN y P2PE), cuando los datos a proteger son datos de cuenta o datos de PIN\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":6439,"url":"https:\/\/www.pcihispano.com\/en\/hash-criptografico-con-clave-fundamentos-y-caracteristicas\/","url_meta":{"origin":10240,"position":2},"title":"Hash criptogr\u00e1fico con clave: fundamentos y caracter\u00edsticas","author":"David Acosta","date":"mayo 15, 2025","format":false,"excerpt":"Una de las mejoras significativas que incorpor\u00f3 el est\u00e1ndar PCI DSS en su versi\u00f3n 4.0 fue el uso de funciones de hash criptogr\u00e1fico con clave (keyed cryptographic hash) como remplazo de las funciones de hash tradicionales (non-keyed hash) que, hasta entonces, se empleaban en la protecci\u00f3n del PAN. Pero, \u00bfpor\u2026","rel":"","context":"In &quot;Criptograf\u00eda&quot;","block_context":{"text":"Criptograf\u00eda","link":"https:\/\/www.pcihispano.com\/en\/category\/criptografia\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/MAC.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/MAC.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/MAC.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/MAC.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/04\/MAC.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":11319,"url":"https:\/\/www.pcihispano.com\/en\/transparent-data-encryption-tde-cumplimiento-vs-seguridad\/","url_meta":{"origin":10240,"position":3},"title":"Transparent Data Encryption (TDE): \u00abcumplimiento\u00bb vs. \u00abseguridad\u00bb","author":"David Acosta","date":"febrero 19, 2026","format":false,"excerpt":"Transparent Data Encryption (TDE) es una tecnolog\u00eda que protege los datos sensibles en bases de datos durante su almacenamiento (data-at-rest). Sin embargo, su uso debe estar restringido a escenarios muy espec\u00edficos, fuera de los cuales el nivel de protecci\u00f3n que ofrece se reduce y puede dar lugar a una falsa\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2026\/02\/SQL.png?fit=1200%2C674&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":173,"url":"https:\/\/www.pcihispano.com\/en\/analisis-de-pci-dss-v4-0-parte-iii-requerimientos-3-y-4\/","url_meta":{"origin":10240,"position":4},"title":"An\u00e1lisis de PCI DSS v4.0 \u2013 Parte III: Requerimientos 3 y 4","author":"David Acosta","date":"agosto 18, 2022","format":false,"excerpt":"Continuando con el an\u00e1lisis a la versi\u00f3n 4.0 del est\u00e1ndar PCI DSS, en esta tercera parte de la serie se analizar\u00e1n los requerimientos 3 y 4 que hacen parte del grupo \u201cProtect Account Data\u201d, enfocados a la protecci\u00f3n de la confidencialidad y la integridad de los datos de tarjetas de\u2026","rel":"","context":"In &quot;An\u00e1lisis de PCI DSS v4.0&quot;","block_context":{"text":"An\u00e1lisis de PCI DSS v4.0","link":"https:\/\/www.pcihispano.com\/en\/category\/pci-dss-4-0\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte3.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte3.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte3.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte3.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte3.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":608,"url":"https:\/\/www.pcihispano.com\/en\/la-guia-definitiva-de-bloques-de-claves-criptograficas-key-blocks\/","url_meta":{"origin":10240,"position":5},"title":"La gu\u00eda definitiva de bloques de claves criptogr\u00e1ficas (Key Blocks)","author":"David Acosta","date":"diciembre 14, 2022","format":false,"excerpt":"Con la entrada en vigencia del est\u00e1ndar PCI PIN v2.0 en el a\u00f1o 2014, todas las claves sim\u00e9tricas cifradas (criptogramas) deben ser manejadas en estructuras denominadas key blocks, que permiten proteger de forma estandarizada la integridad de dichas claves criptogr\u00e1ficas y asociarlas de forma inequ\u00edvoca a un uso en particular\u2026","rel":"","context":"In &quot;Criptograf\u00eda&quot;","block_context":{"text":"Criptograf\u00eda","link":"https:\/\/www.pcihispano.com\/en\/category\/criptografia\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/key_blocks-1.png?fit=1200%2C674&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/key_blocks-1.png?fit=1200%2C674&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/key_blocks-1.png?fit=1200%2C674&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/key_blocks-1.png?fit=1200%2C674&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/key_blocks-1.png?fit=1200%2C674&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/10240","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/comments?post=10240"}],"version-history":[{"count":1,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/10240\/revisions"}],"predecessor-version":[{"id":11705,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/10240\/revisions\/11705"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media\/10323"}],"wp:attachment":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media?parent=10240"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/categories?post=10240"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/tags?post=10240"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}