TryTRY
BuyBUY
  • newsletter
  • contact
  • corporate
  • careers
Utimaco
TRYour free HSM simulator
BUYget a quote
  • home
  • solutions
  • products
  • services
  • blog
  • downloads
  • partners
  • company

Utimaco Portal

Here you will find everything you need as a partner and customerLogin required

  • home
  • solutions
    • industries
      • banking and financial services
        • acquirer
        • card scheme
        • issuer
        • hsm-as-a-service
      • government
        • federal government
      • cloud
        • cloud-based innovation
        • multi-cloud agility
      • connected car (V2V)
      • automotive solutions
      • road infrastructure (V2I), toll collection & ITS
      • industrial IoT & manufacturing
      • energy & utilities
      • lottery & gaming
      • media & entertainment
      • telecommunications
    • applications
      • authentication
      • blockchain
      • code signing
      • database encryption
      • document signing
      • key injection
      • post-quantum crypto agility
      • public key infrastructure (PKI)
        • EJBCA
      • random number generator (RNG)
    • compliance
      • certifications & approvals
        • Common Criteria (CC)
        • FIPS 140-2
      • compliance & standardization
        • FISMA, FedRAMP, and FICAM
        • Certificate Policy of the Smart Metering PKI
        • eIDAS
        • GDPR
        • PCI DSS
        • Privacy Shield
  • products
    • general purpose HSM
      • SecurityServer Se Gen2
      • SecurityServer CSe
      • Block-safe
      • CryptoServer CP5 (eIDAS & CC)
      • CryptoServer Cloud
      • TimestampServer
      • Q-safe
    • payment HSM
      • Atalla AT1000
      • PaymentServer Se Gen2
      • PaymentServer CSe
      • Secure Configuration Assistance (SCA)
      • QuickStart Services
      • u.cloud – Atalla PaymentHSMaaS
      • u.trust 360
    • key management
      • Enterprise Key Management
    • Software Development Kit (SDK)
      • CryptoServer SDK
      • CryptoScript SDK
    • HSM simulators
      • Block-safe HSM simulator
      • CryptoServer CP5 simulator (eIDAS & CC)
      • SecurityServer simulator
      • Q-safe HSM simulator
    • form factor
      • LAN appliance
      • PCIe card
      • cloud, “HSM as a Service”
    • KeyBRIDGE
      • KeyBRIDGE POI
      • KeyBRIDGE RKD
      • KeyBRIDGE eKMS
      • TokenBRIDGE™
    • u.trust Anchor
      • u.trust Anchor CSAR
      • u.trust Anchor High Performance HSM
  • services
    • consultancy
      • PQC consultancy
    • support
    • managed services
      • Key Exchange & Escrow Service (KEES™)
    • professional services
    • Utimaco Academy
  • blog
  • downloads
    • brochures
    • data sheets
    • case studies
    • white papers
    • webinars
    • e-books
      • PQC for Dummies e-book
      • HSM for Dummies e-book
    • Utimaco Portal
      • integration guides
      • knowledge base
  • partners
    • Partner Program
      • technology partner
    • Partner Locator
  • company
    • about Utimaco
      • legal
      • terms & conditions
      • privacy
        • cookie-policy
    • locations
    • news
      • newsletter
    • events
    • contact
    • careers
    • investors
    • utimaco management
    • business ethics
    • memberships and certifications
    • engagement in research
  • home
  • solutions
    • industries
      • banking and financial services
        • acquirer
        • card scheme
        • issuer
        • hsm-as-a-service
      • government
        • federal government
      • cloud
        • cloud-based innovation
        • multi-cloud agility
      • connected car (V2V)
      • automotive solutions
      • road infrastructure (V2I), toll collection & ITS
      • industrial IoT & manufacturing
      • energy & utilities
      • lottery & gaming
      • media & entertainment
      • telecommunications
    • applications
      • authentication
      • blockchain
      • code signing
      • database encryption
      • document signing
      • key injection
      • post-quantum crypto agility
      • public key infrastructure (PKI)
        • EJBCA
      • random number generator (RNG)
    • compliance
      • certifications & approvals
        • Common Criteria (CC)
        • FIPS 140-2
      • compliance & standardization
        • FISMA, FedRAMP, and FICAM
        • Certificate Policy of the Smart Metering PKI
        • eIDAS
        • GDPR
        • PCI DSS
        • Privacy Shield
  • products
    • general purpose HSM
      • SecurityServer Se Gen2
      • SecurityServer CSe
      • Block-safe
      • CryptoServer CP5 (eIDAS & CC)
      • CryptoServer Cloud
      • TimestampServer
      • Q-safe
    • payment HSM
      • Atalla AT1000
      • PaymentServer Se Gen2
      • PaymentServer CSe
      • Secure Configuration Assistance (SCA)
      • QuickStart Services
      • u.cloud – Atalla PaymentHSMaaS
      • u.trust 360
    • key management
      • Enterprise Key Management
    • Software Development Kit (SDK)
      • CryptoServer SDK
      • CryptoScript SDK
    • HSM simulators
      • Block-safe HSM simulator
      • CryptoServer CP5 simulator (eIDAS & CC)
      • SecurityServer simulator
      • Q-safe HSM simulator
    • form factor
      • LAN appliance
      • PCIe card
      • cloud, “HSM as a Service”
    • KeyBRIDGE
      • KeyBRIDGE POI
      • KeyBRIDGE RKD
      • KeyBRIDGE eKMS
      • TokenBRIDGE™
    • u.trust Anchor
      • u.trust Anchor CSAR
      • u.trust Anchor High Performance HSM
  • services
    • consultancy
      • PQC consultancy
    • support
    • managed services
      • Key Exchange & Escrow Service (KEES™)
    • professional services
    • Utimaco Academy
  • blog
  • downloads
    • brochures
    • data sheets
    • case studies
    • white papers
    • webinars
    • e-books
      • PQC for Dummies e-book
      • HSM for Dummies e-book
    • Utimaco Portal
      • integration guides
      • knowledge base
  • partners
    • Partner Program
      • technology partner
    • Partner Locator
  • company
    • about Utimaco
      • legal
      • terms & conditions
      • privacy
        • cookie-policy
    • locations
    • news
      • newsletter
    • events
    • contact
    • careers
    • investors
    • utimaco management
    • business ethics
    • memberships and certifications
    • engagement in research

Home / Blogs / Key generation and distribution considerations for PCI DSS Compliance

Key generation and distribution considerations for PCI DSS Compliance

November 09, 2020

Payment Cards Industry Data Security Standard (PCI-DSS) compliance protects vulnerable customers who are unaware of the complex technologies behind the scenes.

New call-to-action

Financial institutions are obliged to comply with the regulations that enforce the protection of information for customers. All this protection is based on cryptography, which makes credit card data and users personal information unreadable in case of a security breach. The encryption keys that can unlock the data are the most important part of any cryptographic operation. These keys require strict protection and internal controls must authorize their access.

The PCI DSS has 12 requirements designed to serve as the basis for organizations to operate in an safe environment where cardholder information is not compromised. Today we will cover 3 requirements which specifically focus on the generation, distribution, and access control of cardholder data.

Requirement 3.6.1

Requirement 3.6.1 requires organizations to generate strong encryption keys. The standard does not address exactly how to achieve this and therefore makes this a daunting task. An auditor will examine whether an organization’s tools for generating its key have produced an random number that is almost impossible to estimate.

A pseudo-random number generator makes this possible. One of these is the question that an auditor wants to answer: How sure is the organization that the quality of the random numbers generated makes collisions unlikely and prevents an attacker from suspecting them?

The Federal Office for Information Security prescribes 4 characteristics for quality random numbers, with criteria 3 and 4 being the most preferred generators due to the complexity and limited probability that an attacker could guess any previous numbers in the sequence or any previous information.

In this process, the risk for an organization is in the case that they develop a routine compliance checklist  and use the wrong tools to ensure compliance, and then do not realize their error until after the auditor tests to verify these properties.

Requirement 3.6.2

Requirement 3.6.2 focuses on the secure distribution of cryptographic keys. The keys should be distributed as specified in the access list to the selected custodians, who should not be many. An auditor reviews ISO 27001 Annex A for reference values for control objectives and controls.

Requirement 9

Section 9  requires the management of privileged access rights and formal documentation is reviewed to determine the correct management of elevated rights. Once the analysis is complete, an auditor will review to see if the keys were distributed to the correct administrators.

Security mechanisms have often been weakened by the misuse of authority by privileged users. Permanent logging of the key management system must be carried out to ensure that only authorized users have access.

HSM devices facilitate many key management problems and are highly recommended. However, organizations should look to a vendor for clarity on issues such as the ability of devices to integrate with their current systems.

To manage plans for custodians leaving the company and hire new employees, an HSM can help manage and comply with regulations as long as the right equipment is purchased.  For some HSM devices, an administrator must create a group for the key custodians and manage all custodians entering and leaving that group.

Of the 12 requirements listed in the PCI DSS standards, these are the three most relevant to key generation and key distribution. To meet the standards and provide the highest level of data security, HSMs provide all the cryptographic functionality, user access, and in most cases, key management software needed for PCI DSS regulatory compliance.

Back to overview

Stay on top of our news
Don’t miss out on any Utimaco updates

Subscribe to Utimaco Newsletter

We will keep you posted with news from Utimaco and the industries we protect, as well as information on upcoming events and webinars.

Subscribe now

Partners

Utimaco HSM - InfoGuard Swiss Cyber Security Nexus - Utimaco Hardware Security Modules Partner Safesoft Kft. Encryption Consulting LLC MTG - Utimaco Hardware Security Modules Partner Real security d.o.o. Ascertia - Utimaco Hardware Security Modules Partner CEGA Security Thomas-Krenn.AG Cryptomathic A/S Komar Consulting Inc. - Utimaco Hardware Security Modules Partner IQuantics Corp EUROPEAN DYNAMICS SA. Skytech Computing Solutions Limited. - Utimaco Hardware Security Modules Partner Utimaco HSM - QuintessenceLabs Astel (UK) Ltd. - Utimaco Hardware Security Modules Partner AKEA S.A. - Utimaco Hardware Security Modules Partner Nexus - Utimaco Hardware Security Modules Partner Nexus Technology GmbH Abrantix AG cv cryptovision GmbH Rohde & Schwarz Cybersecurity GmbH Cryptomathic Inc. Perceptus-sp.-z-o.-o. MIcrosec CewTec S.A. Compumatica secure networks B.V. JJNet International Co., Limited - Utimaco Hardware Security Modules Partner Microexpert Limited E-Sign S.A. CertiSur S.A. CREA plus d.o.o. VAR Group SpA - Utimaco Hardware Security Modules Partner Synergy Computers (Pvt.) Ltd. - Utimaco Hardware Security Modules Partner Fortiedge Pte Ltd. Baas Control s.r.o. Versasec Cryptomathic GmbH SecureMetric Technology Sdn. Bhd. PKI Solutions Inc. Telegrupp AS Altacom UAB Utimaco HSM - PTESA_profesionales en transacciones electronicas PrimeKey Labs GmbH Throughwave (Thailand) Co.,Ltd - Utimaco Hardware Security Modules Partner Cogito Group Pty Ltd PETA (Thailand) Co., Ltd. Softline Solutions GmbH Cyber Armor Pte Ltd Envoy Data Corporation - Utimaco Hardware Security Modules Partner Fornetix - Utimaco Hardware Security Modules Partner Primekey Solutions AB Macroseguridad Clearkey Consulting - Utimaco Hardware Security Modules Partner Secure Source Distribution (M) Sdn Bhd - Utimaco Hardware Security Modules Partner ESYSCO Sp. z o.o. intarsys AG CREAplus Italia S.r.l Compumatica secure networks GmbH MALKOM D.Malińska i Wspólnicy s.j.
Find a partner

Share this page

EMEA

Utimaco IS GmbH
Germanusstraße 4
52080 Aachen
Germany
Phone: + 49 241 1696 200

Americas

Utimaco Inc.
900 E Hamilton Ave., Suite 400
Campbell, CA 95008
USA
Phone: +1 844 UTIMACO

APAC

Utimaco IS Pte Limited
80 Raffles Place,
#32-01, UOB Plaza
Singapore 048624
Phone: +65 6622 5347

Utimaco

  • support
  • corporate
  • careers
  • legal
  • terms & conditions
  • privacy
  • cookie-policy
© 2021
to top
  • home
  • solutions
    • industries
      • banking and financial services
        • acquirer
        • card scheme
        • issuer
        • hsm-as-a-service
      • government
        • federal government
      • cloud
        • cloud-based innovation
        • multi-cloud agility
      • connected car (V2V)
      • automotive solutions
      • road infrastructure (V2I), toll collection & ITS
      • industrial IoT & manufacturing
      • energy & utilities
      • lottery & gaming
      • media & entertainment
      • telecommunications
    • applications
      • authentication
      • blockchain
      • code signing
      • database encryption
      • document signing
      • key injection
      • post-quantum crypto agility
      • public key infrastructure (PKI)
        • EJBCA
      • random number generator (RNG)
    • compliance
      • certifications & approvals
        • Common Criteria (CC)
        • FIPS 140-2
      • compliance & standardization
        • FISMA, FedRAMP, and FICAM
        • Certificate Policy of the Smart Metering PKI
        • eIDAS
        • GDPR
        • PCI DSS
        • Privacy Shield
  • products
    • general purpose HSM
      • SecurityServer Se Gen2
      • SecurityServer CSe
      • Block-safe
      • CryptoServer CP5 (eIDAS & CC)
      • CryptoServer Cloud
      • TimestampServer
      • Q-safe
    • payment HSM
      • Atalla AT1000
      • PaymentServer Se Gen2
      • PaymentServer CSe
      • Secure Configuration Assistance (SCA)
      • QuickStart Services
      • u.cloud – Atalla PaymentHSMaaS
      • u.trust 360
    • key management
      • Enterprise Key Management
    • Software Development Kit (SDK)
      • CryptoServer SDK
      • CryptoScript SDK
    • HSM simulators
      • Block-safe HSM simulator
      • CryptoServer CP5 simulator (eIDAS & CC)
      • SecurityServer simulator
      • Q-safe HSM simulator
    • form factor
      • LAN appliance
      • PCIe card
      • cloud, “HSM as a Service”
    • KeyBRIDGE
      • KeyBRIDGE POI
      • KeyBRIDGE RKD
      • KeyBRIDGE eKMS
      • TokenBRIDGE™
    • u.trust Anchor
      • u.trust Anchor CSAR
      • u.trust Anchor High Performance HSM
  • services
    • consultancy
      • PQC consultancy
    • support
    • managed services
      • Key Exchange & Escrow Service (KEES™)
    • professional services
    • Utimaco Academy
  • blog
  • downloads
    • brochures
    • data sheets
    • case studies
    • white papers
    • webinars
    • e-books
      • PQC for Dummies e-book
      • HSM for Dummies e-book
    • Utimaco Portal
      • integration guides
      • knowledge base
  • partners
    • Partner Program
      • technology partner
    • Partner Locator
  • company
    • about Utimaco
      • legal
      • terms & conditions
      • privacy
        • cookie-policy
    • locations
    • news
      • newsletter
    • events
    • contact
    • careers
    • investors
    • utimaco management
    • business ethics
    • memberships and certifications
    • engagement in research