{"id":608,"date":"2022-12-14T13:54:34","date_gmt":"2022-12-14T12:54:34","guid":{"rendered":"https:\/\/pcihispano.com\/?p=608"},"modified":"2026-05-06T19:16:34","modified_gmt":"2026-05-06T17:16:34","slug":"la-guia-definitiva-de-bloques-de-claves-criptograficas-key-blocks","status":"publish","type":"post","link":"https:\/\/www.pcihispano.com\/en\/la-guia-definitiva-de-bloques-de-claves-criptograficas-key-blocks\/","title":{"rendered":"The Ultimate Guide to Cryptographic Key Blocks"},"content":{"rendered":"<p><span class=\"intro-text\">With the entry into force of the PCI PIN v2.0 standard in 2014, all encrypted symmetric keys (cryptograms) must be handled in structures called <strong><em>key blocks<\/em><\/strong>, which allow the integrity of those cryptographic keys to be protected in a standardised manner and unequivocally associated with a particular use in order to avoid unauthorised modifications or substitutions. This article describes in a general way the history and the need for the use of <em>key blocks<\/em>, as well as the dates stipulated for the global implementation of this security mechanism.<\/span><\/p>\n<p><strong>Update January 2023<\/strong>: All references to <em>ASC X9 TR 31: Interoperable Secure Key Exchange Key Block Specification<\/em> have been replaced by <em>X9.143 Retail Financial Services: Interoperable Secure Key Block Specification.<\/em><\/p>\n<h3>Introduction<\/h3>\n<p>One of the encryption algorithms of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Block_cipher\">Block Encryption<\/a> that was most used in the financial field was the algorithm <em>Data Encryption Standard<\/em> (DES), also known as <em>Data Encryption Algorithm<\/em> (DEA). This algorithm was originally chosen as a FIPS standard in 1976 and is currently considered insecure, because the size of its key length (56 real key bits and 8 parity bits) is very short and can be easily compromised with current computational techniques (examples of which are the <a href=\"https:\/\/w2.eff.org\/Privacy\/Crypto\/Crypto_misc\/DESCracker\/HTML\/19980716_eff_des_faq.html\">DES Breaking Machine<\/a> of the EFF, <em>Cost-Optimized Parallel COde Breaker<\/em> (<a href=\"https:\/\/www.copacobana.org\">COPACABANA<\/a>) and\u00a0 <a href=\"http:\/\/crack.sh\/\">Crack.sh: The World\u2019s Fastest DES Cracker<\/a>, among others).<\/p>\n<div id=\"attachment_609\" style=\"width: 268px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-609\" class=\"size-full wp-image-609\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2022\/12\/DES_Image.png?resize=258%2C163&#038;ssl=1\" alt=\"\" width=\"258\" height=\"163\" \/><p id=\"caption-attachment-609\" class=\"wp-caption-text\">Figure 1. Structure of a DES key: 64 bits, of which the last bit of each octet is used as parity bit<\/p><\/div>\n<p>In response to this problem, two algorithms were used that used the same DES base but added new complexity to the process using iterations and additional keys:<\/p>\n<ul>\n<li><strong>Double-DES (2DES or 2DEA)<\/strong> uses two instances of DES in the same clear text block. In each instance it uses different encryption keys. Currently, this algorithm is obsolete.<\/li>\n<\/ul>\n<div id=\"attachment_610\" style=\"width: 390px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-610\" class=\"size-full wp-image-610\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2022\/12\/2DES_Image.png?resize=380%2C240&#038;ssl=1\" alt=\"\" width=\"380\" height=\"240\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/2DES_Image.png?w=380&amp;ssl=1 380w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/2DES_Image.png?resize=300%2C189&amp;ssl=1 300w\" sizes=\"auto, (max-width: 380px) 100vw, 380px\" \/><p id=\"caption-attachment-610\" class=\"wp-caption-text\">Figure 2. Double DES (K1 \u2260 K2)<\/p><\/div>\n<ul>\n<li><strong>Triple-DES (3DES or TDEA)<\/strong> uses three instances of DES in the same clear text, being able to use two keys (<em>Double-length TDEA<\/em>) or three different encryption keys (<em>Triple-length TDEA<\/em>).<\/li>\n<\/ul>\n<div id=\"attachment_612\" style=\"width: 390px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-612\" class=\"size-full wp-image-612\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2022\/12\/TDEA1.png?resize=380%2C199&#038;ssl=1\" alt=\"\" width=\"380\" height=\"199\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/TDEA1.png?w=380&amp;ssl=1 380w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/TDEA1.png?resize=300%2C157&amp;ssl=1 300w\" sizes=\"auto, (max-width: 380px) 100vw, 380px\" \/><p id=\"caption-attachment-612\" class=\"wp-caption-text\">Figure 3. Double-length TDEA (K1 \u2260 K2)<\/p><\/div>\n<div id=\"attachment_613\" style=\"width: 428px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-613\" class=\"wp-image-613 size-full\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2022\/12\/TDEA2.png?resize=418%2C229&#038;ssl=1\" alt=\"\" width=\"418\" height=\"229\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/TDEA2.png?w=418&amp;ssl=1 418w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/TDEA2.png?resize=300%2C164&amp;ssl=1 300w\" sizes=\"auto, (max-width: 418px) 100vw, 418px\" \/><p id=\"caption-attachment-613\" class=\"wp-caption-text\">Figure 4. Triple-length TDEA (K1 \u2260 K2 \u2260 K3)<\/p><\/div>\n<p>The set of keys used in 2DES and 3DES and their specific order is called <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-67r2.pdf\"><em>Key Bundle<\/em><\/a>, a concept introduced in the 1990s. As you can see, when making use of several keys must be established <u>the Order<\/u> of such keys or, otherwise, the decryption process will not be correct. Additionally, the use of <em>key bundles <\/em>helps protect against attacks from <a href=\"http:\/\/www.crypto-it.net\/eng\/attacks\/meet-in-the-middle.html\"><em>Meet-in-the-middle<\/em><\/a>, aimed at obtaining cryptographic keys in ciphers that use two or more keys in multiple rounds of encryption with the same algorithm.<\/p>\n<p>However, the use of <em>key bundles no <\/em>ensures the complete security of the cryptosystem. One of the main problems lies in the security during the process of exchanging and storing symmetric keys in hostile environments. These keys are usually shared or stored by encrypting them with another key (<em>key-encrypting key<\/em> \u2013 KEK). If a KEK is transmitted or stored without any attributes restricting its use to specific processes (encryption of another key), an attacker could exploit this vulnerability as part of an attack on the cryptosystem (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Cryptanalysis\">cryptanalysis<\/a>).<\/p>\n<p>One of the most widely used alternatives to manage this problem is through the use of variants (<a href=\"https:\/\/caffinc.github.io\/2018\/04\/key-variants\/\"><em>Key Variants<\/em><\/a>). Variants are created by combining a binary mask with the original key, depending on the type of implementation (<em>Atalla variant<\/em>, <em>Thales variant<\/em>, <em>IBM variant<\/em> o <em>Control Vectors<\/em>, etc.). However, this method does not provide any functionality for verifying the integrity or authentication of the key.<\/p>\n<p>To solve this problem, another additional concept of cryptographic protection for keys called <a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-38f\/final\"><em>Key Wrapping<\/em><\/a>, which can be used interchangeably for TDEA (<em>Triple DEA Key Wrap<\/em> \u2013 TKW) as for AES (<em>AES Key Wrap \u2013 AESKW or AES Key Wrap With Padding<\/em> \u2013 KWP). The purpose of the <em>key wrapping<\/em> is to unmistakably link the key (AES or all keys of a<em> Key Bundle<\/em> from TDEA) to additional information (<em>metadata<\/em>), establishing specific use policies for each key. Generally speaking, the use of<em> key wrapping <\/em>allows:<\/p>\n<ol>\n<li>Associate the type\/purpose of a cryptographic key to ensure that this key is not used for any purpose other than the designated one, for example, as a key encryption key (KEK) or as a PIN encryption key.<\/li>\n<li>Protect the integrity of the key, including the order of the parts of the key in the case of algorithms that require multiple keys, for example, TDEA.<\/li>\n<\/ol>\n<p>In this way, the functionalities provided by the <em>key bundles<\/em> and variants (<em>key variants<\/em>) can be deployed using only <em>key wrapping. <\/em>Technically, the concept of <em>key wrapping<\/em> gave rise to what is now known as <em>Key Blocks<\/em>.<\/p>\n<h3>Structure of the <em>Key Blocks<\/em><\/h3>\n<p>According to requirements 18-3 of PCI PIN v3.0 and P2PE v3.0, some of the acceptable methods for the implementation of <a href=\"https:\/\/www.cryptomathic.com\/news-events\/blog\/introduction-to-cryptographic-key-blocks-faqs\" target=\"_blank\" rel=\"noopener\"><em>key blocks<\/em><\/a> are:<\/p>\n<ul>\n<li>Using a MAC function (<em>Message Authentication Code<\/em>) applied on the concatenation of the attributes in clear text and the encrypted part of the <em>Key Block<\/em>, which includes the key (example: A<span id=\"page41R_mcid5\" class=\"markedContent\"><span dir=\"ltr\" role=\"presentation\">NSI X9.143 e <span id=\"page45R_mcid3\" class=\"markedContent\">ISO 20038<\/span>)<\/span><\/span>,<\/li>\n<li>A digital signature computed on all this data (example: <span id=\"page41R_mcid6\" class=\"markedContent\"><span dir=\"ltr\" role=\"presentation\">ASC X9 TR 34<\/span><\/span>), or<\/li>\n<li>An integrity check function that is an implicit part of the key encryption process such as the one used in the <em>key-wrapping<\/em> in AES keys, specified in ANSI X9.102.<\/li>\n<\/ul>\n<p>There are multiple proprietary implementations of these methods of <em>key blocks<\/em>, including <a href=\"https:\/\/www.cryptomathic.com\/news-events\/blog\/why-a-banking-key-management-system-must-support-atalla-key-blocks\">Atalla Key Blocks<\/a> (AKB) and <a href=\"https:\/\/www.cryptomathic.com\/news-events\/blog\/an-overview-of-the-different-key-block-formats\" target=\"_blank\" rel=\"noopener\">Thales Key Blocks<\/a> (TKB). In order to avoid compatibility issues and ensure consistency with ANSI X9.24, ANSI developed the technical report in 2017. <a href=\"https:\/\/webstore.ansi.org\/Standards\/ASCX9\/ASCX9TR312018\">ASC X9 TR-31:<\/a> <em>Interoperable Secure Key Exchange Key Block Specification.\u00a0<\/em> This report was updated in 2021 and finally renamed in 2022 to <a href=\"https:\/\/webstore.ansi.org\/standards\/ascx9\/ansix91432022\" target=\"_blank\" rel=\"noopener\">ANSI X9.143-2022<\/a>: <em>Retail Financial Services Interoperable Secure Key Block Specification<\/em> which, today, is the method <em>de facto <\/em>for the implementation of <em>key blocks<\/em>.<\/p>\n<p>In X9.143, each <em>key block<\/em> contains a protected key, the information of its limitations of use and other metadata that is protected by a mechanism of<em> key wrapping<\/em>, as follows:<\/p>\n<div id=\"attachment_624\" style=\"width: 762px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-624\" class=\"wp-image-624\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2022\/12\/Estructura_Key_Block.png?resize=752%2C279&#038;ssl=1\" alt=\"\" width=\"752\" height=\"279\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Estructura_Key_Block.png?w=1807&amp;ssl=1 1807w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Estructura_Key_Block.png?resize=300%2C111&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Estructura_Key_Block.png?resize=1024%2C380&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Estructura_Key_Block.png?resize=768%2C285&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Estructura_Key_Block.png?resize=1536%2C570&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Estructura_Key_Block.png?resize=500%2C185&amp;ssl=1 500w\" sizes=\"auto, (max-width: 752px) 100vw, 752px\" \/><p id=\"caption-attachment-624\" class=\"wp-caption-text\">Figure 5. Key Block Structure using ANSI X9.143<\/p><\/div>\n<p>This model involves the generation of a new encryption key (<strong><em>Key-Block Protection Key<\/em> \u2013 KBPK<\/strong>) from which two additional keys will be derived:<\/p>\n<ul>\n<li><strong><em>Key-Block Encryption Key (KBEK)<\/em><\/strong><em>,<\/em> used to encrypt the section containing the cryptogram of the key and its length; and<\/li>\n<li><em><strong>Key-Block Authentication Key (KBAK)<\/strong><\/em>, used to generate a message authentication code (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Message_authentication_code\"><em>Message Authentication Code<\/em><\/a> \u2013 MAC) of the entire content of the <em>Key Block<\/em>. This key is also known as <em><strong>Key-Block MAC Key (KBMK)<\/strong><\/em>.<\/li>\n<\/ul>\n<div id=\"attachment_625\" style=\"width: 761px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-625\" class=\"wp-image-625\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2022\/12\/Key_Block_Header_Structure.png?resize=751%2C542&#038;ssl=1\" alt=\"\" width=\"751\" height=\"542\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Key_Block_Header_Structure.png?w=1435&amp;ssl=1 1435w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Key_Block_Header_Structure.png?resize=300%2C216&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Key_Block_Header_Structure.png?resize=1024%2C739&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Key_Block_Header_Structure.png?resize=768%2C554&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/Key_Block_Header_Structure.png?resize=500%2C361&amp;ssl=1 500w\" sizes=\"auto, (max-width: 751px) 100vw, 751px\" \/><p id=\"caption-attachment-625\" class=\"wp-caption-text\">Key Block Header Structure (ANSI X9.143)<\/p><\/div>\n<p>By using these structures it is ensured that the change or replacement of any bit in the attributes or encryption key can be detected effectively.<\/p>\n<div id=\"attachment_616\" style=\"width: 715px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-616\" class=\"wp-image-616\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2022\/12\/BPTools.png?resize=705%2C500&#038;ssl=1\" alt=\"\" width=\"705\" height=\"500\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/BPTools.png?w=936&amp;ssl=1 936w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/BPTools.png?resize=300%2C213&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/BPTools.png?resize=768%2C545&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/BPTools.png?resize=500%2C355&amp;ssl=1 500w\" sizes=\"auto, (max-width: 705px) 100vw, 705px\" \/><p id=\"caption-attachment-616\" class=\"wp-caption-text\">Figure 6. Example of decoding a Key Block, including the description of the header, using EFTlab BP-Tools (https:\/\/www.eftlab.com\/bp-tools\/)<\/p><\/div>\n<h3>Using Key Blocks<\/h3>\n<p>Generally, encryption keys can be stored or transmitted by any of the following methods:<\/p>\n<ol>\n<li>At least in two <em>key shares<\/em> Separate or in components<\/li>\n<li>Contents within a secure cryptographic device (<em>Secure Cryptographic Device<\/em> \u2013 SCD)<\/li>\n<li>Encrypted with a key of equal or greater strength than the protected key<\/li>\n<\/ol>\n<p>Traditionally, when keys are stored or transmitted by encrypting them with other keys (called <em>Key-encrypting (encipherment or exchange) keys \u2013\u00a0 <\/em>KEK) cannot be guaranteed that the KEK can only be used for the encryption or decryption of other keys nor can its integrity be validated. In that case, the use of <em>Key Blocks<\/em> is indispensable and applicable at any time when a cryptographic key exists outside the boundaries of a cryptographic security device (SCD).<\/p>\n<h3>What kind of keys should be protected using <em>Key Blocks<\/em>?<\/h3>\n<p>The concept of <em>key wrapping<\/em> \/ <em>key blocks <\/em>is applicable to any encrypted symmetric key that has to be stored outside the security limits of an SCD or transferred to an external entity.<\/p>\n<p>From the perspective of PCI PIN and P2PE, the use of <em>key blocks<\/em> is mandatory for all symmetric keys exchanged or stored under another symmetric key under fixed key scenarios (<em>fixed key<\/em>) and <em>master key\/session key<\/em> (e.g. <em>Zone Master Keys<\/em> (ZMK), <em>Key-Encipherment Keys<\/em> (KEKs), <em>Terminal Master Keys<\/em> (TMKs) and <em>PIN-Encryption Keys<\/em> (PEKs)).<\/p>\n<p>Likewise, in the case of DUKPT, the use of <em>Key Blocks<\/em> is applicable to <em>Derivation Keys Base<\/em> (BDKs) and initial DUKPT keys (<em>initial DUKPT keys<\/em>).<\/p>\n<p>It is also important to note that all Hardware Security Modules (HSMs) certified as PCI HSM and all PIN acceptance devices (<em>Point-of-Interaction<\/em> \u2013 POI) from version 2 of PCI PTS POI (published in 2007) support TR-31 or equivalent methods.<\/p>\n<h3>Key Blocks Implementation Periods<\/h3>\n<p>In order to allow a coordinated and staggered migration towards the <em>Key Blocks<\/em>, in July 2020 (for <a href=\"https:\/\/www.pcisecuritystandards.org\/pdfs\/Key%20Block%20Implementation%20Revision%20Bulletin%20FINAL.pdf\">PCI PIN<\/a>) and in August 2020 (for <a href=\"https:\/\/www.pcisecuritystandards.org\/pdfs\/Key_Block_Implementation_Bulletin_P2PE_final.pdf\">P2PE<\/a>) the ICP SSC defined the following phases and their related dates (amended due to the impact of COVID-19):<\/p>\n<ul>\n<li><strong>Phase 1:<\/strong> Must be implemented <em>Key Blocks<\/em> for all internal connections and key storage within the Service Provider environment. This may include applications and databases connected to Hardware Security Modules (HSMs). Date of entry into force: <span style=\"color: #ff0000;\"><strong>1 June 2019<\/strong><\/span> (completed).<\/li>\n<li><strong>Phase 2<\/strong>: Must be implemented <em>Key Blocks <\/em>for external connections to associations and networks. Date of entry into force: <span style=\"color: #ff0000;\"><strong>1 January 2023<\/strong><\/span> (completed).<\/li>\n<li><strong>Phase 3<\/strong>: Extension of the implementation of <em>Key Blocks<\/em> to all merchant hosts, point-of-sale terminals and electronic tellers. Date of entry into force: <strong>1 January 2025<\/strong>.<\/li>\n<\/ul>\n<p>It's important to note that payment brands (mainly Visa entered your program) <a href=\"https:\/\/usa.visa.com\/content\/dam\/VCOM\/download\/security\/documents\/visa-pin-security-program-guide-public.pdf\" target=\"_blank\" rel=\"noopener\">Visa PIN<\/a>) have also emphasized migration to <a href=\"https:\/\/usa.visa.com\/content\/dam\/VCOM\/global\/partner-with-us\/documents\/visa-security-bulletin-key-block-dates-reminder.pdf\" target=\"_blank\" rel=\"noopener\"><em>Key Blocks<\/em><\/a><em>.<\/em><\/p>\n<h3>What needs to be done in each of the migration phases to meet Key Blocks deployment dates?<\/h3>\n<p>Migration from traditional keys to keys in key block format for transmission and storage requires planning and time, as well as support from external entities such as HSM manufacturers, manufacturers of interaction point devices (POIs) and companies with which there are connections with encrypted data from the entity (KIFs, issuers, etc.). The tasks to be performed in each of the phases are described in a general way below:<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Phase I: Internal connections and storage within the entity<\/strong><\/span><\/p>\n<ul>\n<li>All cryptographic repositories (cryptographic keys encrypted with other keys) that are outside the safe limits of an HSM must be migrated to <em>key blocks<\/em>. This includes cryptograms stored in databases, files, etc. Depending on the hierarchy of keys in the organization, keys outside of an HSM may be encrypted by the master key of the HSM (<em>Master File Key \/ Local Master Key<\/em>) or by other encryption keys (<em>Key-Encrypting Keys \u2013 KEK<\/em>), so these keys (MFK\/LMK\/KEK) must be migrated to generate <em>Key Block Protection Keys<\/em> (KBPK) and be able to encrypt other keys using <em>key blocks<\/em>.<\/li>\n<\/ul>\n<p><span style=\"text-decoration: underline;\"><strong>Phase II: External connections to associations and networks<\/strong><\/span><\/p>\n<ul>\n<li>All KEK (<em>Zone Master Keys<\/em> \u2013 ZMK) used for the transmission of PIN encryption keys with external entities (<em>Acquirer Working Key<\/em> (AWK), <em>Issuer Working Key<\/em> (IWK), etc.) should be replaced by KBPKs.<\/li>\n<li>This key migration affects not only the purchasing environment but also the issuing environment, so issuers and authorizing centers are required to migrate their keys. Similarly, if the entity shares keys with key injection services (<em>Key Injection Facilities<\/em> (KIF), CA\/RAs, etc.), transport keys must be migrated to format<em> key block<\/em>.<\/li>\n<\/ul>\n<p><span style=\"text-decoration: underline;\"><strong>Phase III: Hosts of merchants, point-of-sale terminals and electronic tellers<\/strong><\/span><\/p>\n<ul>\n<li>All KEK (<em>Terminal Master Key<\/em> \u2013 TMK) used for the transmission of PIN encryption keys on merchant hosts, point-of-sale terminals and ATMs (<em>Terminal PIN Key<\/em>TPK), <em>Initial PIN Encryption Key<\/em> (IPEK)) should be replaced by KBPKs.<\/li>\n<\/ul>\n<h3>How can you check if a cryptographic key is in key block format?<\/h3>\n<p>One of the advantages of standardization provided by key blocks (<em>key blocks<\/em>) is that it can be identified by simple direct observation whether a cryptographic key is in key block format or not.<em>header<\/em>) of a <em>key block <\/em>indicates the version used. There are four key block version identifiers:<\/p>\n<ul>\n<li><strong>Version A<\/strong>: <em>Key block<\/em> protected using <em>Key Variant Binding Method<\/em><\/li>\n<li><strong>Version B<\/strong>: <em>Key block<\/em> protected using <em>TDEA Key Derivation Binding Method<\/em><\/li>\n<li><strong>Version C<\/strong>: <em>Key block<\/em> protected using <em>TDEA Key Variant Binding Method<\/em><\/li>\n<li><strong>Version D<\/strong>: <em>Key block<\/em> protected using<em> AES Key Derivation Binding Method<\/em><\/li>\n<\/ul>\n<p>From the perspective of PCI PIN and PCI P2PE, <span class=\"highlight\">only versions B (TDEA) and D (AES) are acceptable<\/span>, since they use derivation instead of variants for key diversification. A variant is significantly weaker because it is reversible, while derivation is not. Using this criterion, below are two TDEA cryptographic keys protected by <em>key blocks<\/em>:<\/p>\n<p><em><span id=\"page60R_mcid5\" class=\"markedContent\"><span dir=\"ltr\" role=\"presentation\">A0136V0TN00S0200102CIBMC012400227E000341000000227E0003210000PB047F5787<\/span><span dir=\"ltr\" role=\"presentation\">857B413A01A880461CB19203B0F2D9E3E5326133B9D29036D35BEC873C95F22E81<\/span><\/span><span id=\"page60R_mcid6\" class=\"markedContent\"><\/span><span id=\"page60R_mcid7\" class=\"markedContent\"><\/span><\/em><\/p>\n<p><em><span id=\"page60R_mcid7\" class=\"markedContent\"><span dir=\"ltr\" role=\"presentation\">B0144P0TE00S0200102CIBMC012400247700034100000024770003210000PB04C71F19<\/span><span dir=\"ltr\" role=\"presentation\">9CC5A13FECEAAF94EC3CC4C3025787E70<\/span><span dir=\"ltr\" role=\"presentation\">9BC8101236F51736F93421D65CABAD5E97A7F<\/span><span dir=\"ltr\" role=\"presentation\">D11B<\/span><\/span><\/em><\/p>\n<p>Of these two keys, only the second (the one that uses the B identifier) is valid to be used in the PCI PIN\/PCI P2PE environment.<\/p>\n<h3>References<\/h3>\n<ul>\n<li><em>PCI Perspectives: <a href=\"https:\/\/blog.pcisecuritystandards.org\/key-blocks-101\">Key Blocks 101<\/a>, <a href=\"https:\/\/blog.pcisecuritystandards.org\/key-blocks-102\">Key Blocks 102<\/a>, <a href=\"https:\/\/blog.pcisecuritystandards.org\/key-blocks-103\">Key Blocks 103<\/a> y <a href=\"https:\/\/blog.pcisecuritystandards.org\/key-blocks-104\">Key Blocks 104<\/a><\/em><\/li>\n<li><em>PCI SSC <a href=\"https:\/\/www.pcisecuritystandards.org\/documents\/Cryptographic_Key_Blocks_Information_Supplement_June_2017.pdf\">Information Supplement: Cryptographic Key Blocks<\/a> (June 2017)<\/em><\/li>\n<li><em>PCI SSC <a href=\"https:\/\/docs-prv.pcisecuritystandards.org\/PIN\/Supporting%20Document\/PIN_Security_Rqmt_18-3_Key_Blocks_2022_v1.1.pdf\" target=\"_blank\" rel=\"noopener\">Information Supplement: PIN Security Requirement 18-3 -Key Blocks <\/a>(July 2022)<\/em><\/li>\n<li>\n<div class=\"newsroom-list-item\"><em>PCI SSC <a href=\"https:\/\/www.pcisecuritystandards.org\/wp-content\/uploads\/2020\/08\/Key_Block_Implementation_Bulletin_P2PE_final.pdf\" target=\"_blank\" rel=\"noopener\">PCI Security Standards Council Bulletin: Revisions to the Implementation Dates for PCI P2PE Security Requirement 18-3<\/a><\/em><\/div>\n<\/li>\n<li>\n<div class=\"newsroom-list-item\"><em>PCI SSC <a href=\"https:\/\/www.pcisecuritystandards.org\/wp-content\/uploads\/2020\/07\/Key-Block-Implementation-Revision-Bulletin-FINAL.pdf\" target=\"_blank\" rel=\"noopener\">PCI Security Standards Council Bulletin: Revisions to the Implementation Date for PCI PIN Security Requirement 18-3<\/a><\/em><\/div>\n<\/li>\n<li><em>Geobridge: <a href=\"https:\/\/www.geobridge.net\/guide-to-implementing-key-blocks\/\">Implementing Key Blocks Guide<\/a><\/em><\/li>\n<li><em>SANS: <a href=\"https:\/\/cyber-defense.sans.org\/resources\/papers\/gsec\/3des-secure-pin-based-electronic-transaction-processing-106500\">3DES and Secure PIN-based Electronic Transaction Processing<\/a><\/em><\/li>\n<li><em>Cryptomathic: Introduction to Cryptographic Key Blocks \u2013 FAQs <a href=\"https:\/\/www.cryptomathic.com\/news-events\/blog\/introduction-to-cryptographic-key-blocks-faqs\" target=\"_blank\" rel=\"noopener\">https:\/\/www.cryptomathic.com\/news-events\/blog\/introduction-to-cryptographic-key-blocks-faqs<\/a><\/em><\/li>\n<li><em>Cryptomathic: An Overview of the Different Key Block Formats <a href=\"https:\/\/www.cryptomathic.com\/news-events\/blog\/an-overview-of-the-different-key-block-formats\" target=\"_blank\" rel=\"noopener\">https:\/\/www.cryptomathic.com\/news-events\/blog\/an-overview-of-the-different-key-block-formats<\/a><\/em><\/li>\n<li><em>Utimaco: A Panorama of the key blocks <a href=\"https:\/\/utimaco.com\/current-topics\/blog\/panorama-key-blocks\" target=\"_blank\" rel=\"noopener\">https:\/\/utimaco.com\/current-topics\/blog\/panorama-key-blocks<\/a><\/em><\/li>\n<li><em>ANSI X9.24 Part 1-2009 Retail Financial Services Symmetric Key Management Part 1: Using Symmetric Techniques<\/em><\/li>\n<li><em>ANSI X9.24 Part 2-2006 Retail Financial Services Symmetric Key Management Part 2: Using Asymmetric Techniques for Distribution of Symmetric Keys<\/em><\/li>\n<li><em>ANSI X9 TR-31, Interoperable Secure Key Exchange Key Block Specification<\/em><\/li>\n<li><em><a href=\"https:\/\/webstore.ansi.org\/standards\/ascx9\/ansix91432022\" target=\"_blank\" rel=\"noopener\">ANSI ANSI X9.143-2022<\/a> Retail Financial Services Interoperable Secure Key Block Specification<\/em><\/li>\n<li><em>ISO 20038: Banking and related financial services \u2014 Key wrap using AES<code><\/code><\/em><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>With the entry into force of the PCI PIN v2.0 standard in 2014, all encrypted symmetric keys (cryptograms) must be handled in structures called key blocks, which allow to protect in a standardized way the integrity of said cryptographic keys [\u2026]<\/p>","protected":false},"author":2,"featured_media":630,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[329,54,330],"tags":[104,107,109,100,101,102,103,105,106,108],"class_list":["post-608","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-criptografia","category-noticias","category-pci-pin","tag-aes","tag-ansi","tag-key-block","tag-key-blocks","tag-key-wrapping","tag-tdea","tag-tdes","tag-tr-31","tag-tr-34","tag-x9-143"],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/12\/key_blocks-1.png?fit=1914%2C1075&ssl=1","jetpack-related-posts":[{"id":753,"url":"https:\/\/www.pcihispano.com\/en\/que-es-pci-pin\/","url_meta":{"origin":608,"position":0},"title":"\u00bfQu\u00e9 es PCI PIN?","author":"David Acosta","date":"enero 25, 2023","format":false,"excerpt":"En este nuevo art\u00edculo de la serie \u00bfQu\u00e9 es? se realizar\u00e1 una breve introducci\u00f3n al est\u00e1ndar Payment Card Industry (PCI) PIN Security (PCI PIN), focalizado en la protecci\u00f3n del n\u00famero de identificaci\u00f3n personal (PIN) en transacciones presenciales. Introducci\u00f3n El est\u00e1ndar Payment Card Industry (PCI) PIN Security (o PCI PIN) es\u2026","rel":"","context":"In &quot;PCI PIN&quot;","block_context":{"text":"PCI PIN","link":"https:\/\/www.pcihispano.com\/en\/category\/pci-pin\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/01\/PCI_PIN.png?fit=1200%2C674&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/01\/PCI_PIN.png?fit=1200%2C674&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/01\/PCI_PIN.png?fit=1200%2C674&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/01\/PCI_PIN.png?fit=1200%2C674&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/01\/PCI_PIN.png?fit=1200%2C674&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":288,"url":"https:\/\/www.pcihispano.com\/en\/fechas-importantes\/","url_meta":{"origin":608,"position":1},"title":"Fechas importantes","author":"David Acosta","date":"enero 24, 2023","format":"quote","excerpt":"Fechas importantes: Octubre 1, 2023: El programa Visa PIN ha sido retirado. Enero 1, 2024: Cambia el proceso de carga de claves por componentes en PCI PIN Marzo 31, 2024: El est\u00e1ndar PCI DSS v3.2.1 ser\u00e1 retirado y la versi\u00f3n 4.0 entrar\u00e1 totalmente en vigor. Enero 1, 2025: Fecha final\u2026","rel":"","context":"In &quot;Noticias&quot;","block_context":{"text":"Noticias","link":"https:\/\/www.pcihispano.com\/en\/category\/noticias\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/pexels-olya-kobruseva-5386754-scaled.jpg?fit=1200%2C801&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/pexels-olya-kobruseva-5386754-scaled.jpg?fit=1200%2C801&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/pexels-olya-kobruseva-5386754-scaled.jpg?fit=1200%2C801&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/pexels-olya-kobruseva-5386754-scaled.jpg?fit=1200%2C801&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/pexels-olya-kobruseva-5386754-scaled.jpg?fit=1200%2C801&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":1918,"url":"https:\/\/www.pcihispano.com\/en\/recordatorio-pci-pin-cambia-el-proceso-de-carga-de-claves-desde-el-1-de-enero-de-2024\/","url_meta":{"origin":608,"position":2},"title":"Recordatorio PCI PIN: Cambia el proceso de carga de claves desde el 1 de enero de 2024","author":"David Acosta","date":"diciembre 14, 2023","format":false,"excerpt":"De acuerdo con las Preguntas T\u00e9cnicas de Uso Frecuente de PCI PIN (PCI PTS PIN Security Requirements \u2212 Technical FAQs for use with Version 3), a partir del 1 de enero de 2024 el proceso de carga de claves en dispositivos HSM empleando componentes en texto claro cambia de forma\u2026","rel":"","context":"In &quot;Noticias&quot;","block_context":{"text":"Noticias","link":"https:\/\/www.pcihispano.com\/en\/category\/noticias\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/12\/PIN_Carga_Claves.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/12\/PIN_Carga_Claves.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/12\/PIN_Carga_Claves.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/12\/PIN_Carga_Claves.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2023\/12\/PIN_Carga_Claves.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":1404,"url":"https:\/\/www.pcihispano.com\/en\/obsolescencia-de-triple-des-tdea-y-su-impacto-en-los-estandares-del-pci-ssc\/","url_meta":{"origin":608,"position":3},"title":"Obsolescencia de Triple DES (TDEA) y su impacto en los est\u00e1ndares del PCI SSC","author":"David Acosta","date":"marzo 13, 2024","format":false,"excerpt":"El 1 de enero de 2024 marc\u00f3 un hito en la historia de la criptograf\u00eda moderna: El algoritmo Triple DES (3DES\/TDES o TDEA) fue catalogado como \"obsoleto\" por NIST. Esta noticia hace parte de los esfuerzos de la migraci\u00f3n hacia algoritmos m\u00e1s seguros en la carrera hacia la criptograf\u00eda post-cu\u00e1ntica\u2026","rel":"","context":"In &quot;Criptograf\u00eda&quot;","block_context":{"text":"Criptograf\u00eda","link":"https:\/\/www.pcihispano.com\/en\/category\/criptografia\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/03\/TDEA.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":6546,"url":"https:\/\/www.pcihispano.com\/en\/hardware-security-module-hsm-que-es-y-para-que-sirve\/","url_meta":{"origin":608,"position":4},"title":"Hardware Security Module (HSM): \u00bfQu\u00e9 es y para qu\u00e9 sirve?","author":"David Acosta","date":"julio 16, 2025","format":false,"excerpt":"Uno de los principales problemas derivados del uso de la criptograf\u00eda para la protecci\u00f3n de datos sensibles durante su almacenamiento y su transmisi\u00f3n es la complejidad en la gesti\u00f3n del ciclo de vida de las claves de encriptaci\u00f3n (generaci\u00f3n, almacenamiento, importaci\u00f3n\/exportaci\u00f3n, distribuci\u00f3n, rotaci\u00f3n, remplazo, copias de seguridad, revocaci\u00f3n, suspensi\u00f3n, destrucci\u00f3n,\u2026","rel":"","context":"In &quot;Criptograf\u00eda&quot;","block_context":{"text":"Criptograf\u00eda","link":"https:\/\/www.pcihispano.com\/en\/category\/criptografia\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/05\/HSM.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/05\/HSM.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/05\/HSM.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/05\/HSM.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/05\/HSM.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":5447,"url":"https:\/\/www.pcihispano.com\/en\/metodos-de-gestion-de-claves-criptograficas-clave-fija-mk-sk-y-dukpt\/","url_meta":{"origin":608,"position":5},"title":"M\u00e9todos de gesti\u00f3n de claves criptogr\u00e1ficas: clave fija, MK\/SK y DUKPT","author":"David Acosta","date":"enero 29, 2025","format":false,"excerpt":"Cuando se emplean claves criptogr\u00e1ficas sim\u00e9tricas para la protecci\u00f3n de datos almacenados o transmitidos, es necesario establecer ciertos protocolos para su carga, transmisi\u00f3n, rotaci\u00f3n o bloqueo. En los est\u00e1ndares del PCI SSC (principalmente PCI PIN y P2PE), cuando los datos a proteger son datos de cuenta o datos de PIN\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/01\/Encryption_Keys.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/comments?post=608"}],"version-history":[{"count":1,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/608\/revisions"}],"predecessor-version":[{"id":11742,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/608\/revisions\/11742"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media\/630"}],"wp:attachment":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media?parent=608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/categories?post=608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/tags?post=608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}