2021 News

Cryptocards news and updates from 2021.

Nov. 30, 2021 | HSM CEX7S / 4769 | FIPS 140-2 Level 4 certification

As of November 30, 2021, the IBM CEX7S / 4769 hardware security module (HSM) is validated to FIPS PUB 140-2 Level 4. Level 4 is the highest level of certification currently achievable for commercial cryptographic devices. See FIPS certification number 4079 (link resides outside of Ibm.com) on the Computer Security Resource Center website for the certification.

Oct. 23, 2021 | HSM CEX7S | Product update of CCA for Linux on Z

A CCA product update for 7.3.28 is now available for CEX7S Linux on Z customers on IBM's CCA download site.

Details are available in the RPM/DEB package change logs.

Sep. 17, 2021 | FC EJ35 / EJ37 | CCA Release 7.x for IBM Power Systems™

As of September 17, 2021, CCA Release 7.3.30 includes support for IBM Power Systems with any of the following operating systems installed:
  • IBM AIX: Version 7.3 (32-bit and 64-bit)
  • IBM i: Version 7.3 (32-bit and 64-bit)
  • PowerLinux
    • RHEL Server 8.4 little endian, 64-bit
    • SLES 15 Service Pack 3 (little endian), 64-bit

CCA Release 7.3 is now available for download by all customers who use the IBM 4769 on these operating systems.

Aug. 13, 2021 | HSM 4769 | CCA Release 7.2.55 Toolkit

As of August 13, 2021, the Toolkit for CCA Release 7.2.55 is available. This is the first release of the Toolkit for the IBM 4769. The following major upgrades are in this Toolkit:
  1. Updates to the Toolkit samples to accommodate changes between the IBM 4767 and IBM 4769.
  2. A rewrite to the Outbound Authentication sample due to changes between the two adapters.
  3. A new ICATPFX debugger for the IBM 4769.

July 23, 2021 | HSM CEX7S / 4769 | PCI PTS HSM certification

The IBM 4769 Cryptographic Coprocessor, with CCA Support Program Releases 7.0, 7.1, 7.2, and 7.3 firmware, has achieved PCI PTS HSM certification (link resides outside of Ibm.com). CCA Release 7.3 is available for customers who use the IBM CEX7S on IBM Z, and CCA Release 7.2 is available for customers who use the 4769 on x64 systems. Refer to the CEX7S / 4769 overview page for additional information.

July 1, 2021 | HSM 4769 | CCA 7.3 Release for Linux on Z

CCA 7.3 is now available for CEX7S Linux on Z customers. CCA for Linux on Z details are available on the CEX7S / 4769 Linux on Z software page.

New format preserving algorithms FF1, FF2, F2.1, CSNBFFXE, CSNBFFXD, CSNBFFXT.

Multiple updates are applied to topic Chapter 20, “Key token formats,” on page 1053. For example, Koblitz elliptic curve cryptography is supported with CCA release 7.2.

The generation of an internal DATAM or DATAMV key results in a key token with a good double-length control vector (supported with CCA release 7.2).

The use of AES keys with derived unique key per transaction processing (AES DUKPT) has been introduced and can be requested for applicable verbs with the A-DUKPT keyword (supported with CCA release 7.2).

New enhanced key wrapping methods are provided and can be requested with the WRAPENH2 or WRAPENH3 keywords for applicable verbs. The WRAPENH2 method uses the SHA-256 hashing algorithm and is available for more verbs now than in previous releases. The WRAPENH3 method is supported with CCA release 7.3 and uses TDES CMAC and the SHA-256 hashing algorithm.

You can use the CSNBKYT2 service to return the key length of an AES or DES key in a secure key token. The information is returned in the verification_pattern parameter.

You can allow or prohibit exporting keys to CPACF protected key format for further applicable verbs now, besides CSNBKTB2.

CRYSTALS-Dilithium (8,7) keys are supported by applicable verbs.

May 28, 2021 | HSM 4769 | CCA Sample programs for the 4769

Sample programs for the IBM 4769-001 are available for use by customers on x64 systems. These samples include samples that are also available for the IBM 4767 as well as new samples. The samples are described on the Cryptocards sample code page and are available on the IBM CCA download site.

Note: To access this site, you must obtain and log in with an IBMid. This process is quick and easy. Instructions are on the download site.

May 6, 2021 | All HSMs with CCA | PCI PIN Security - first independently reviewed TDES key block

The IBM Common Cryptographic Architecture (CCA) is introducing the first proprietary TDES key block (also known as a key token) to be independently reviewed and confirmed to be compliant with Payment Card Industry (PCI) Security Standard Council (SSC) PIN Security key block requirements as updated 30-Sep-2020.

The new TDES key block is backwards compatible with existing applications and CKDS. The new TDES key block is implemented starting with z/OS level 2.4, ICSF 77D1 and APAR OA60318. The new TDES key block is available for the IBM z15 with driver D41C:S39a, offering support on the Crypto Express 5S with CCA, Crypto Express 6S with CCA and Crypto Express 7S with CCA.

The new TDES key block is implemented as a new TDES key token wrapping method known as "WRAPENH3". The wrapping method controls the cryptographic algorithms used to encrypt the clear key material within the boundary of the coprocessor, resulting in what we know as a “secure key” from an ICSF perspective. With OA60318, ICSF will offer a utility that can be used to migrate all existing TDES secure keys in a CKDS to the new wrapping method, or it can be done on a key-by-key basis using updated callable services. In addition, a new SAF resource will provide a way to override existing applications such that wherever a wrapping method is specified or defaulted, the wrapping method will be automatically updated to WRAPENH3. Migration topics and planning are covered in ICSF published materials for this release.

Please note that the independent review report is publicly available as required by PCI SSC PIN requirement 18-3. It is posted on the IBM Cryptocards public download site (PDF, 1.1 MB). Watch the Cryptocards news page for any updates.

Please note that ICSF toleration APAR OA60813 availability for legacy releases to tolerate the new WRAPENH3 method wrapped TDES keys. This prevents any use or management of the new TDES key tokens - since it is not possible - but allows legacy z/OS ICSF releases to skip over the keys that are not understood when reading the CKDS.

For any questions, please contact Crypto.

Apr. 30, 2021 | All HSMs | New site for most documentation

Many of the documents for CCA and EP11 for the IBM family of cryptographic adapters are now available on IBM's download site. Please see these links for each adapter:

IBM 4769 / CCA 7 download site

IBM 4768 / CCA 6 download site

IBM 4767 / CCA 5 download site

IBM 4765 / CCA 4 download site

IBM EP11 3.0 download site

IBM EP11 2.1 download site

Note: To access these sites, you must obtain and log in with an IBMid. This process is quick and easy. Instructions are on each download site.

Publicly-available IBM Cryptocards documentation is still available on IBM's public download site.

Apr. 20, 2021 | HSM 4769 | GBIC certification

On April 20, 2021, the German Banking Industry Committee (GBIC) confirmed that the IBM 4769-001 with CCA firmware versions 7.0, 7.1, or 7.2 meets the requirements of the GBIC and is compliant with GBIC's security requirements. Please contact Crypto if you have any questions.

Mar. 30, 2021 | HSM 4767 | Withdrawal from marketing

On March 30, 2021, IBM announced the withdrawal from marketing the MTM 4767-002. Please see the withdrawal notice for additional information. The replacement adapter is the MTM 4769-002, which is available for installation in x64 servers on RHEL 64-bit operating systems. See the Feb. 23, 2021 announcement below for more information.

Mar. 29, 2021 | HSM CEX7S / 4769 | PCI PTS HSM certification

The IBM 4769 Cryptographic Coprocessor, with CCA Support Program Releases 7.0, 7.1, and 7.2 firmware, has achieved PCI PTS HSM certification (link resides outside of Ibm.com). CCA Release 7.2 is available for customers who use the IBM CEX7S on IBM Z as well as customers who use the 4769 on x64 systems. Refer to the CEX7S / 4769 overview page for additional information.

Feb. 23, 2021 | HSM 4769 | New IBM 4769-001 and CCA release 7.2 for x64 servers

The IBM 4769 is now available as machine type-model (MTM) 4769-001 for installation in x64 servers. on RHEL 64-bit operating systems.

The IBM 4769 is the latest generation of IBM's HSMs. It is redesigned for improved performance and security rich services for your sensitive workloads, and to deliver high throughput for cryptographic functions. For a detailed summary of the capabilities and specifications of the 4769, refer to the IBM 4769 Data Sheet (PDF, 383 KB), the CEX7S / 4769 overview page, and the CEX7S / 4769 x64 releases page.

Feb. 16, 2021 | HSM CEX7S | Product update of CCA for Linux on Z

Product update CCA 7.1.35 is now available for CEX7S Linux on Z customers.

CCA for Linux on Z details are available on the CEX7S Linux on Z software page.

Jan. 4, 2021 | IBM Cryptocards | IBM Crypto Education Community

The IBM Cryptocards Newsletter has transitioned to the IBM Crypto Education Community. Click here to view or join the community, which features articles of interest about cryptography and IBM's cryptographic solutions.