ISO 13492:2019
Financial services — Key-management-related data element — Application and usage of ISO 8583-1 data elements for encryption
Financial services — Key-management-related data element — Application and usage of ISO 8583-1 data elements for encryption
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 14
- Дата публикации:
- 25 октября 2019 г.
- Издание:
- ISO IS 13492 edition 3 version 1
- ICS:
- 35.240.40
This document describes a data element related to key management which can be transmitted either in transaction messages to convey information about cryptographic keys used to secure the current transaction, or in cryptographic service messages to convey information about cryptographic keys to be used to secure future transactions. This document addresses the requirements for the use of the data element related to key management within ISO 8583-1, using the following two ISO 8583-1 data elements for DEA and TDEA: — security related control information (data element 53); — key management data (data element 96). The data element related to key management for DEA and TDEA is constructed from the concatenation of two ISO 8583-1 message elements, data element 53 — security related control information, and data element 96 — key management data. It conveys information about the associated transaction's cryptographic key(s) and is divided into subfields including a control field, a key-set identifier and additional optional information. For AES implementations, the data elements are summarized in one field. This document is applicable to either symmetric or asymmetric cipher systems.
Abstract
Overview
ISO 13492:2019 specifies a standardized data element for key management in financial messaging. It defines how information about cryptographic keys is conveyed within ISO 8583-1 interchange messages - either in transaction messages (to indicate the key used to secure the current transaction) or in cryptographic service messages (to convey keys for future use). The standard supports legacy algorithms (DEA, TDEA) and modern AES usage, and is applicable to both symmetric and asymmetric cipher systems.
Key topics and requirements
- Data element construction: For DEA/TDEA the key-management data element is constructed by concatenating ISO 8583-1 data element 53 (security related control information) and data element 96 (key management data). For AES implementations the relevant data can be summarized into a single field (fields 50, 110 or 111 depending on implementation).
- Subfield structure: The data element is divided into subfields such as a control field, key‑set identifier, and optional fields for algorithm, key length, key protection method, padding, and encrypted data format.
- Control field role: Identifies the key management scheme and the structure of the remainder of the data element (e.g., static key vs. unique key per transaction like DUKPT/UKPT).
- Key-set identifiers: Provide a standardized way to uniquely identify the institution and specific key-set affected by an operation (load, use, rotate).
- Data representation and encoding: Supports data set, TLV or bitmap (composite data element) structures per ISO 8583-1 and uses ASN.1/BER rules where referenced.
- AES support: Recognizes that ISO 8583-1 fields historically sized for DEA/TDEA are too short for AES; ISO 13492 provides mechanisms to accommodate AES key and encrypted-data lengths.
- Scope exclusions: Does not cover ICC (chip card) internal key management; related key management procedures are referenced in other standards.
Applications and who uses it
ISO 13492:2019 is used by:
- Payment processors, card issuers and acquirers to indicate which cryptographic keys protect a transaction.
- POS and terminal vendors integrating encryption with ISO 8583-1 messaging.
- HSM (Hardware Security Module) and key‑management system vendors for interoperable key loading and rotation.
- Security architects and compliance teams implementing standardized key identifiers and protections across payment flows.
Practical uses include conveying which key-set an encrypted PIN or MAC uses, transporting key material in cryptographic service messages, and enabling AES adoption in existing ISO 8583 transaction infrastructures.
Related standards
- ISO 8583-1 - Messages, data elements and code values (interchange messaging)
- ISO 11568 - Key management procedures (referenced for key lifecycle)
- ISO/IEC 8825-1 - ASN.1 encoding rules (BER/CER/DER)
- ISO 9564 and ISO 16609 - Related security data (PIN and MAC handling)
Keywords: ISO 13492:2019, ISO 8583-1, key management, AES, DEA, TDEA, data element 53, data element 96, payment security, key-set identifier.
Технические детали
- Технический комитет
- ISO/TC 68/SC 2 - Financial Services, security
- SKU
- ISO 13492:2019
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO 13492:2019
ДействующийFinancial services. Key-management-related data element. Application and usage of ISO 8583-1 data elements fo…
ISO 8583-2:1998
ОтменёнFinancial transaction card originated messages — Interchange message specifications — Part 2: Application and…
Overview ISO 8583-2:1998 specifies the application and registration procedures for Institution Identification Codes (IIC) used in financial transaction card originated message interchange. Part of th…
BS ISO 11568:2023
ДействующийFinancial services. Key management (retail).
ISO/IEC 8825-1:2015
ОтменёнInformation technology — ASN.1 encoding rules: Specification of Basic Encoding Rules (BER), Canonical Encodin…
ISO 9564-2:2014
ОтменёнFinancial services — Personal Identification Number (PIN) management and security — Part 2: Approved algorith…
Overview ISO 9564-2:2014 defines the approved algorithms for the encipherment of Personal Identification Numbers (PINs) used in financial services. This part of the ISO 9564 series focuses exclusivel…