PIN-Encrypting keys
A unique master key variant enciphers each type of key.
Note that the PIN block variant constant (PBVC) are not supported in this version of CCA.
Derived unique key per transaction algorithms
CCA supports ANSI X9.24 derived unique key per transaction algorithms to generate PIN-encrypting keys from user data.
CCA supports both single-length and double-length key generation. Keywords for single-length and double-length key generation cannot be mixed.
Encrypted PIN Translate
The UKPTIPIN, IPKTOPIN, and UKPTBOTH keywords will cause the verb to generate single-length keys. and DUKPT-IP, DKPT-OP, and DUKPT-BH are the respective keywords to generate double-length keys.
The input_PIN_profile and output_PIN_profile parameters must supply the current key serial number when these keywords are specified.
Encrypted PIN Verify
The UKPTIPIN keyword cause the verb to verify single-length keys. DUKPT-IP is the keyword for double-length key generation.
The input_PIN_profile parameter must supply the current key serial number when these keywords are specified.