Overview
ISO 11568:2023 - Financial services - Key management (retail) defines requirements and guidance for managing symmetric and asymmetric cryptographic keys used to protect sensitive information in retail payment environments. The standard covers the full key life cycle (generation, distribution, utilization, archiving, replacement and destruction), for connections such as card-accepting device ↔ Acquirer, Acquirer ↔ Issuer, and ICC ↔ terminal. It addresses both manual and automated key management, logging and auditing, and requirements for hardware used to manage keys.
Key topics and technical requirements
- Key life‑cycle management: policies and procedures for creation, storage, backup, archiving, replacement and secure destruction of keying material.
- Symmetric and asymmetric keys: requirements for secure generation, distribution and check values for both key types.
- Transaction key techniques: methods such as master keys, transaction keys and Derived Unique Key Per Transaction (DUKPT); the 2023 edition introduces AES DUKPT and removes fixed keys as a permissible method.
- Secure cryptographic devices (SCDs): device-level requirements, including additional controls when used with SKDAT (symmetric key distribution using asymmetric techniques).
- Dual control and split knowledge: mandatory controls to prevent single-person compromise of secret/private keys.
- Key attributes and key blocks: standardized packaging, integrity protection and attribute tagging for key transport and storage.
- Logging, auditing and compromise handling: explicit guidance for event logging, audit trails, synchronization and steps on key compromise.
- Cryptographic strength and separation: guidance for algorithm strength, single-purpose key usage, substitution prevention and clear key location controls.
- Hardware requirements: normative criteria for devices (e.g., HSMs/SCDs) used to create, store or distribute keys.
Practical applications and users
ISO 11568:2023 is applicable to organizations involved in retail payment security, including:
- Card issuers and acquirers
- Payment processors and payment service providers
- POS and terminal manufacturers, secure cryptographic device vendors and HSM integrators
- Security architects, key management teams, compliance and audit functions
- Payment gateway operators and host-to-host service providers
Use cases include secure key injection and distribution to terminals, derivation of per-transaction keys (DUKPT/AES DUKPT), HSM configuration and key rotation policies, and procedures for key compromise response and audit compliance.
Related standards
ISO 11568:2023 complements industry payment and cryptographic guidance such as EMV specifications, PCI PIN/PCI DSS requirements and other ISO/IEC and national cryptographic standards and algorithm guidance. Implementers should align ISO 11568 controls with applicable payment scheme rules and local regulations.
Keywords: ISO 11568:2023, key management (retail), retail payments, cryptographic key lifecycle, DUKPT, AES DUKPT, secure cryptographic device, HSM, key distribution, key rotation, key compromise, payment security.