Edit

Perform Azure Payment HSM v2 operations

The Utimaco portal provides detailed connectivity, administration, validation, troubleshooting, and key management procedures. See the Configuring SCA TLS Certificates for Azure Payments HSM v2 Guide, the SCAW-User Guide v2.4, and the AT1000 HSM Command Reference Manual. You need an active Utimaco portal account and registration to access these documents. After you create a Payment HSM v2 and connect to it, use the guidance in these documents to perform the supported operational scenarios described in the following list:

  • Run the Utimaco Secure Configuration Assistant (SCA) application. (See Run the SCA-W application on page 59 in the SCAW-User Guide v2.4.)
  • Create and manage security associations and use policies. (See Initialize the HSM on page 70 in the SCAW-User Guide v2.4.)
  • Create or load a Master File Key (MFK). (See Create an MFK key component on the smart card followed by Send key component to the HSM beginning on page 82 in the SCAW-User Guide v2.4.)
  • Send or delete key components on the Azure Payment HSM v2. (See Managing Key Components on the smart card on page 134 in the SCAW-User Guide v2.4.)

Supported Payment HSM v2 operations

Azure Payment HSM v2 supports the following Utimaco Atalla command set. These commands provide the foundational capabilities required for payment HSM administration, key management, PIN processing, card authentication, secure transaction processing, and cryptographic operations. Together, these commands enable you to perform common payment workloads while evaluating Azure Payment HSM v2 and validating compatibility with existing payment applications.

Management operations

Management operations are administrative commands that you use to configure, initialize, monitor, and maintain the Payment HSM environment. These commands support HSM configuration, security policy management, MFK lifecycle operations, software version verification, compliance reporting, and general system health checks.

Opcode Description
00 Echo Test Message
9E Translate Working Key from Current MFK to Pending MFK
9A Administrative Information Services (9A#ID#, 9A#INFO#, 9A#INFO#CLOUD#, 9A#MFK#, 9A#KEY#, 9A#SERIAL#)
9F Replace the Current MFK with the Pending MFK
101 Configure HSM Option
108 Define Security Policy
109 Confirm Security Policy
1100 HSM Extended Software Version
1101 HSM Software Version
1120 HSM System Information
1200 HSM Compliance Information
1226 HSM Key Check Digits

Key operations

Key operations provide the core cryptographic key management capabilities of the Payment HSM. These commands let you generate, import, export, verify, derive, and transport payment keys. Supported mechanisms include Atalla Key Blocks (AKBs), TR-31 key blocks, and Derived Unique Key Per Transaction (DUKPT) key management. These capabilities are fundamental to securing payment transactions and payment application integration.

Opcode Description
10 Generate 3DES Working Key
39A Generate AES and HMAC keys
7E Generate 3DES Check Digits
392 Generate AES Check Digits
1A Export a 3DES key in non-AKB Format
11B Import a 3DES key in non-AKB Format
119 Import TR-31 Formatted Working Key, versions A, B, or C
11A Export Working Key in TR-31 Format, versions A, B, or C
310 Import TR-31 Formatted Working Key, version D (AES)
311 Export Working Key in TR-31 Format, version D (AES)
38E Derive Working Key Using AES DUKPT

PIN processing

PIN processing commands support the secure handling of cardholder personal identification numbers (PINs). These operations allow payment systems to translate PIN blocks between formats and verify PIN values without exposing sensitive PIN data outside the HSM boundary.

Opcode Description
31 Translate PIN
3E Translate PIN, ISO PIN Blocks
32 Verify PIN

Card processing

Card processing commands provide the cryptographic functions required to support modern payment card authentication standards. These operations support Europay, Mastercard, and Visa (EMV) transactions, CVV/CVC validation, CSC verification, dynamic card verification values, and token validation. The operations also support other card-brand-specific security mechanisms used during payment authorization and fraud prevention.

Opcode Description
5E Verify CVV/CVC
35A Verify AMEX CSC
35D Verify EMV ARQC
352 Generate EMV MAC
356 Validate CAP Token
357 Verify dCVV and dCVV2
359 MasterCard dynamic CVC3 Verify and IVCVC3 Generate
365 Verify Visa Cloud-Based Payments

Secure transaction data

Secure transaction data commands provide encryption, decryption, message authentication, and integrity verification services for payment workloads. These capabilities help protect sensitive transaction data both in transit and at rest while supporting industry-standard payment security models based on 3DES, AES, DUKPT, and CMAC cryptography.

Opcode Description
97 Encrypt/Decrypt Data using 3DES
305 Generate MAC using CMAC
348 Verify DUKPT MAC
388 3DES DUKPT Encrypt/Decrypt Data
390 Encrypt/Decrypt Data using AES

RSA commands

These commands provide asymmetric cryptographic capabilities for payment key management, public key exchange, digital signatures, ATM key distribution, and EMV transaction processing. Supported functions include RSA key pair generation, public key import and validation, digital signature generation and verification, and public key protection by using Atalla Key Blocks (AKBs). The commands also support ATM master key distribution and EMV cryptographic operations for payment card authentication and secure transaction processing.

Opcode Description
120 Generate Asymmetric Key Pair
12A Generate AKB of Public Key
123 Verify Public Key and Generate RSA-AKB
124 Generate Digital Signature
125 Verify Digital Signature
12F Generate ATM Master Key and Encrypt with Public Key
358 Generate ISO/IEC 9796-2 Digital Signature
131 EMV Sign Data
132 EMV Recover Data

Glossary of terms

Term Definition
SCA Atalla Secure Configuration Assistant. Administrators use SCA as the interface and smart cards as credentials for HSM authentication, administration, backup, and security operations.
C3 KLD Key Loading Device. Atalla C3 is the current generation of loading device.
APM Atalla Payment Module (Utimaco payment software) that provides the Atalla command set and payment-specific cryptographic functions such as PIN processing, EMV, and key management.
HSM Hardware Security Module.
MFK Master File Key (root key) used to protect and manage payment cryptographic keys within the HSM.
LMK Local Master Key. The internal master key hierarchy used by the Atalla Payment Module (APM) to protect operational payment keys and cryptographic functions. Your applications typically work with keys protected under the LMK. Azure Payment HSM v2 currently supports a single LMK domain.
AKB Atalla Key Block.
KEK Key Encryption Key.
PIN Personal Identification Number (numeric code) used to authenticate a cardholder during payment and ATM transactions. Payment HSMs perform PIN encryption, translation, and verification operations.
PIN block A standardized, encrypted representation of a PIN used during transmission and processing.
TR-31 ANSI X9 TR-31 Interoperable Secure Key Exchange Key Block Specification. An industry-standard key block format used for secure transport and exchange of payment keys. Azure Payment HSM v2 supports this format.
DUKPT Derived Unique Key Per Transaction. A key management scheme commonly used in payment terminals and PIN processing.
EMV Europay, Mastercard, and Visa standard for chip-based payment card transactions. Azure Payment HSM v2 supports EMV cryptographic functions such as ARQC validation, EMV MAC generation, and related payment processing commands.
Application port (ASCII) Application interface that uses American Standard Code for Information Interchange (ASCII) encoding. Payment applications use this interface to communicate with the APM and execute payment cryptographic commands.
Management port Administrative interface used by SCA and administrators to configure and manage the Payment HSM environment.