Running CCA verbs in PCI-HSM 2016 compliance mode

Starting with the Crypto Express6 feature (CEX6S), the IBM Z® cryptographic hardware offers the possibility to run CCA applications using keys that conform to the PIN Transaction Security (PTS) standards of the Payment Card Industry (PCI). This PCI PTS standard implemented on a hardware security module as of June 2016 is referred to in this documentation as PCI-HSM 2016 compliance mode.

When configured as a CCA coprocessor, CEX6C or later adapters are capable of running in PCI-HSM 2016 compliance mode. PCI-HSM compliant operation and the available compliance modes are explained in PCI-HSM 2016 compliance mode.

In order for the requirements of PCI-HSM 2016 to apply to a workload, the workload must be using compliant-tagged key tokens. Such a workload can be processed in the domain of a cryptographic coprocessor which is also switched into PCI-HSM 2016 compliance mode.

You can use a TKE V9.0 or higher to set a domain on the adapter to this PCI-HSM 2016 compliance mode. Then you can use the TKE to manually enter or create operational secure keys that have a compliance-tag, or you can create compliance-tagged keys directly from an application. Thus, the CCA applications that invoke services that use PCI-HSM 2016 compliant keys, also apply to the PTS standards of the Payment Card Industry (PCI).

Such a compliant-tagged key token is a key token that adheres to the requirements of the PCI-HSM 2016 compliance mode. Read Using verbs and applications in PCI-HSM 2016 compliance mode for more information.

For verbs that support PCI-HSM 2016 compliant-tagged key tokens, their description in CCA verbs contains a note that indicates this support. Also, Using verbs and applications in PCI-HSM 2016 compliance mode provides a compact list of these verbs.

Watch the TKE Demonstration Video to learn how to use a TKE V9.0 to set a domain on a crypto adapter to PCI-HSM 2016 compliance mode.

The PCI-HSM 2016 compliance mode places certain restrictions on the use of compliant-tagged key tokens. For more detail, see Impact of the PCI-HSM 2016 compliance mode on the callable verbs.

Existing applications prior to CCA release 6.0 that exploit verbs that are now PCI-HSM 2016 compliant, can be migrated to apply to PCI-HSM 2016 compliance mode. For more information, see Migrating applications to PCI-HSM 2016 compliance mode.