CP Assist for Cryptographic Functions

CP Assist for Cryptographic Functions (CPACF), supporting clear and protected key encryption, is activated using the no-charge enablement feature (#3863). It offers the following:

  • For data privacy and confidentially: Data Encryption Standard (DES), Triple Data Encryption Standard (TDES), Advanced Encryption Standard (AES) for 128-bit, 192-bit and 256-bit keys.
  • For data integrity: Secure Hash Algorithm-1 (SHA-1) 160-bit, and SHA-2 for 224-, 256-, 384-and 512-bit support. SHA-3 for 224-, 256- 384-, 512 bit support, and SHAKE for 128-, and 256 bit support. SHA-1, SHA-2 and SHA3 are shipped enabled and do not require the no-charge enablement feature.
  • For Key Generation: Pseudo Random Number Generation (PRNG), Deterministic Random Number Generation (DRNG), and True Random number generation (TRNG).
  • CPACF instructions for SHA-3 hashing, TRNG (True Random Number Generation), and Improved performance of AES GCM encryption.
  • The Elliptical Curve Cryptography (ECC) key import functions to control the enablement of digital signatures (KDSA instruction).