Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
The Utimaco portal provides detailed connectivity, administration, validation, troubleshooting, and key management procedures. See the Configuring SCA TLS Certificates for Azure Payments HSM v2 Guide, the SCAW-User Guide v2.4, and the AT1000 HSM Command Reference Manual. You need an active Utimaco portal account and registration to access these documents. After you create a Payment HSM v2 and connect to it, use the guidance in these documents to perform the supported operational scenarios described in the following list:
- Run the Utimaco Secure Configuration Assistant (SCA) application. (See Run the SCA-W application on page 59 in the SCAW-User Guide v2.4.)
- Create and manage security associations and use policies. (See Initialize the HSM on page 70 in the SCAW-User Guide v2.4.)
- Create or load a Master File Key (MFK). (See Create an MFK key component on the smart card followed by Send key component to the HSM beginning on page 82 in the SCAW-User Guide v2.4.)
- Send or delete key components on the Azure Payment HSM v2. (See Managing Key Components on the smart card on page 134 in the SCAW-User Guide v2.4.)
Supported Payment HSM v2 operations
Azure Payment HSM v2 supports the following Utimaco Atalla command set. These commands provide the foundational capabilities required for payment HSM administration, key management, PIN processing, card authentication, secure transaction processing, and cryptographic operations. Together, these commands enable you to perform common payment workloads while evaluating Azure Payment HSM v2 and validating compatibility with existing payment applications.
Management operations
Management operations are administrative commands that you use to configure, initialize, monitor, and maintain the Payment HSM environment. These commands support HSM configuration, security policy management, MFK lifecycle operations, software version verification, compliance reporting, and general system health checks.
| Opcode | Description |
|---|---|
00 |
Echo Test Message |
9E |
Translate Working Key from Current MFK to Pending MFK |
9A |
Administrative Information Services (9A#ID#, 9A#INFO#, 9A#INFO#CLOUD#, 9A#MFK#, 9A#KEY#, 9A#SERIAL#) |
9F |
Replace the Current MFK with the Pending MFK |
101 |
Configure HSM Option |
108 |
Define Security Policy |
109 |
Confirm Security Policy |
1100 |
HSM Extended Software Version |
1101 |
HSM Software Version |
1120 |
HSM System Information |
1200 |
HSM Compliance Information |
1226 |
HSM Key Check Digits |
Key operations
Key operations provide the core cryptographic key management capabilities of the Payment HSM. These commands let you generate, import, export, verify, derive, and transport payment keys. Supported mechanisms include Atalla Key Blocks (AKBs), TR-31 key blocks, and Derived Unique Key Per Transaction (DUKPT) key management. These capabilities are fundamental to securing payment transactions and payment application integration.
| Opcode | Description |
|---|---|
10 |
Generate 3DES Working Key |
39A |
Generate AES and HMAC keys |
7E |
Generate 3DES Check Digits |
392 |
Generate AES Check Digits |
1A |
Export a 3DES key in non-AKB Format |
11B |
Import a 3DES key in non-AKB Format |
119 |
Import TR-31 Formatted Working Key, versions A, B, or C |
11A |
Export Working Key in TR-31 Format, versions A, B, or C |
310 |
Import TR-31 Formatted Working Key, version D (AES) |
311 |
Export Working Key in TR-31 Format, version D (AES) |
38E |
Derive Working Key Using AES DUKPT |
PIN processing
PIN processing commands support the secure handling of cardholder personal identification numbers (PINs). These operations allow payment systems to translate PIN blocks between formats and verify PIN values without exposing sensitive PIN data outside the HSM boundary.
| Opcode | Description |
|---|---|
31 |
Translate PIN |
3E |
Translate PIN, ISO PIN Blocks |
32 |
Verify PIN |
Card processing
Card processing commands provide the cryptographic functions required to support modern payment card authentication standards. These operations support Europay, Mastercard, and Visa (EMV) transactions, CVV/CVC validation, CSC verification, dynamic card verification values, and token validation. The operations also support other card-brand-specific security mechanisms used during payment authorization and fraud prevention.
| Opcode | Description |
|---|---|
5E |
Verify CVV/CVC |
35A |
Verify AMEX CSC |
35D |
Verify EMV ARQC |
352 |
Generate EMV MAC |
356 |
Validate CAP Token |
357 |
Verify dCVV and dCVV2 |
359 |
MasterCard dynamic CVC3 Verify and IVCVC3 Generate |
365 |
Verify Visa Cloud-Based Payments |
Secure transaction data
Secure transaction data commands provide encryption, decryption, message authentication, and integrity verification services for payment workloads. These capabilities help protect sensitive transaction data both in transit and at rest while supporting industry-standard payment security models based on 3DES, AES, DUKPT, and CMAC cryptography.
| Opcode | Description |
|---|---|
97 |
Encrypt/Decrypt Data using 3DES |
305 |
Generate MAC using CMAC |
348 |
Verify DUKPT MAC |
388 |
3DES DUKPT Encrypt/Decrypt Data |
390 |
Encrypt/Decrypt Data using AES |
RSA commands
These commands provide asymmetric cryptographic capabilities for payment key management, public key exchange, digital signatures, ATM key distribution, and EMV transaction processing. Supported functions include RSA key pair generation, public key import and validation, digital signature generation and verification, and public key protection by using Atalla Key Blocks (AKBs). The commands also support ATM master key distribution and EMV cryptographic operations for payment card authentication and secure transaction processing.
| Opcode | Description |
|---|---|
120 |
Generate Asymmetric Key Pair |
12A |
Generate AKB of Public Key |
123 |
Verify Public Key and Generate RSA-AKB |
124 |
Generate Digital Signature |
125 |
Verify Digital Signature |
12F |
Generate ATM Master Key and Encrypt with Public Key |
358 |
Generate ISO/IEC 9796-2 Digital Signature |
131 |
EMV Sign Data |
132 |
EMV Recover Data |
Glossary of terms
| Term | Definition |
|---|---|
| SCA | Atalla Secure Configuration Assistant. Administrators use SCA as the interface and smart cards as credentials for HSM authentication, administration, backup, and security operations. |
| C3 KLD | Key Loading Device. Atalla C3 is the current generation of loading device. |
| APM | Atalla Payment Module (Utimaco payment software) that provides the Atalla command set and payment-specific cryptographic functions such as PIN processing, EMV, and key management. |
| HSM | Hardware Security Module. |
| MFK | Master File Key (root key) used to protect and manage payment cryptographic keys within the HSM. |
| LMK | Local Master Key. The internal master key hierarchy used by the Atalla Payment Module (APM) to protect operational payment keys and cryptographic functions. Your applications typically work with keys protected under the LMK. Azure Payment HSM v2 currently supports a single LMK domain. |
| AKB | Atalla Key Block. |
| KEK | Key Encryption Key. |
| PIN | Personal Identification Number (numeric code) used to authenticate a cardholder during payment and ATM transactions. Payment HSMs perform PIN encryption, translation, and verification operations. |
| PIN block | A standardized, encrypted representation of a PIN used during transmission and processing. |
| TR-31 | ANSI X9 TR-31 Interoperable Secure Key Exchange Key Block Specification. An industry-standard key block format used for secure transport and exchange of payment keys. Azure Payment HSM v2 supports this format. |
| DUKPT | Derived Unique Key Per Transaction. A key management scheme commonly used in payment terminals and PIN processing. |
| EMV | Europay, Mastercard, and Visa standard for chip-based payment card transactions. Azure Payment HSM v2 supports EMV cryptographic functions such as ARQC validation, EMV MAC generation, and related payment processing commands. |
| Application port (ASCII) | Application interface that uses American Standard Code for Information Interchange (ASCII) encoding. Payment applications use this interface to communicate with the APM and execute payment cryptographic commands. |
| Management port | Administrative interface used by SCA and administrators to configure and manage the Payment HSM environment. |