ISO 11568:2023
Financial services — Key management (retail)
Financial services — Key management (retail)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 115
- Дата публикации:
- 17 февраля 2023 г.
- Издание:
- ISO IS 11568 edition 1 version 1
- ICS:
- 35.240.40
This document describes the management of symmetric and asymmetric cryptographic keys that can be used to protect sensitive information in financial services related to retail payments. The document covers all aspects of retail financial services, including connections between a card-accepting device and an Acquirer, between an Acquirer and a card Issuer, and between an ICC and a card-accepting device. It covers all phases of the key life cycle, including the generation, distribution, utilization, archiving, replacement and destruction of the keying material. This document covers manual and automated management of keying material, and any combination thereof, used for retail financial services. It includes guidance and requirements related to key separation, substitution prevention, identification, synchronization, integrity, confidentiality and compromise, as well as logging and auditing of key management events. Requirements associated with hardware used to manage keys have also been included in this document.
Abstract
Overview
ISO 11568:2023 - Financial services - Key management (retail) defines requirements and guidance for managing symmetric and asymmetric cryptographic keys used to protect sensitive information in retail payment environments. The standard covers the full key life cycle (generation, distribution, utilization, archiving, replacement and destruction), for connections such as card-accepting device ↔ Acquirer, Acquirer ↔ Issuer, and ICC ↔ terminal. It addresses both manual and automated key management, logging and auditing, and requirements for hardware used to manage keys.
Key topics and technical requirements
- Key life‑cycle management: policies and procedures for creation, storage, backup, archiving, replacement and secure destruction of keying material.
- Symmetric and asymmetric keys: requirements for secure generation, distribution and check values for both key types.
- Transaction key techniques: methods such as master keys, transaction keys and Derived Unique Key Per Transaction (DUKPT); the 2023 edition introduces AES DUKPT and removes fixed keys as a permissible method.
- Secure cryptographic devices (SCDs): device-level requirements, including additional controls when used with SKDAT (symmetric key distribution using asymmetric techniques).
- Dual control and split knowledge: mandatory controls to prevent single-person compromise of secret/private keys.
- Key attributes and key blocks: standardized packaging, integrity protection and attribute tagging for key transport and storage.
- Logging, auditing and compromise handling: explicit guidance for event logging, audit trails, synchronization and steps on key compromise.
- Cryptographic strength and separation: guidance for algorithm strength, single-purpose key usage, substitution prevention and clear key location controls.
- Hardware requirements: normative criteria for devices (e.g., HSMs/SCDs) used to create, store or distribute keys.
Practical applications and users
ISO 11568:2023 is applicable to organizations involved in retail payment security, including:
- Card issuers and acquirers
- Payment processors and payment service providers
- POS and terminal manufacturers, secure cryptographic device vendors and HSM integrators
- Security architects, key management teams, compliance and audit functions
- Payment gateway operators and host-to-host service providers
Use cases include secure key injection and distribution to terminals, derivation of per-transaction keys (DUKPT/AES DUKPT), HSM configuration and key rotation policies, and procedures for key compromise response and audit compliance.
Related standards
ISO 11568:2023 complements industry payment and cryptographic guidance such as EMV specifications, PCI PIN/PCI DSS requirements and other ISO/IEC and national cryptographic standards and algorithm guidance. Implementers should align ISO 11568 controls with applicable payment scheme rules and local regulations.
Keywords: ISO 11568:2023, key management (retail), retail payments, cryptographic key lifecycle, DUKPT, AES DUKPT, secure cryptographic device, HSM, key distribution, key rotation, key compromise, payment security.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 11568:2023
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO 11568:2023
ДействующийFinancial services. Key management (retail).
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…