
BEKO 300TR Security Policy V1.5
All information contained in this document is property of Arçelik A.Ş..
This document can't be used, copied, disclosed or divulged in whole or in part for any purpose by any person without the
written approval of Arçelik A.Ş..
Device doesn't have any default key at the beginning. Acquirer has to generate and
inject all transaction keys before deploying. Each key should be used for specified
purpose, and refused to export by any way.
Any violation will invalidate the approval of this device.
8.4 Key Loading Method
The device does not propose manual cryptographic key entry and remote key
injection. The key loading device which is complied with PCI PTS requirement shall be
placed in a secure environment and used for initial key injection.
The initial keys defined as below,
KBPK (Key Block Protection Key)
All initial keys shall be loaded into the device by the trustee using the authentic key
loading device in secure environment.
The key loading method for application is TR31 (Binding Method) specified in
document [4].
8.5 Key Replacement
Any keys should be replaced with a new key value whenever the compromise of the
original key is known or suspected, and whenever the time deemed feasible to
determine that the key by exhaustive attack elapses.
Kommentare zu diesen Handbüchern