Per-transaction key derivation and PIN translation from the pad to the HSM
Guided views
Explore this system
Step through curated paths without changing the source diagram.
Beat
Next
ReadyChapter 01 / 01
Guided chapter
Diagram guideExplore this system
Inspecting compiled semantics
E ExportT ThemeS Style0 Reset+ Zoom in- Zoom outEsc Close
Find a node
⌕/
No matching nodes
Semantic passport
Verified source
Authored reach
Route probeChoose a start node
Pick two semantic nodes on the diagram
Choose the source, then the destination. Direction matters.
Semantic lensCompare system roles
Choose up to two semantic kinds. One reveals its real traffic; two compare only direct authored relationships.
Choose a kind to inspect its nodes and touching relationships.
Semantic radar
Building overview
Click nodeDrag to pan
Key per transaction
• DUKPT derives a fresh key from the KSN counter every time
• A captured key exposes at most one PIN block
• The base derivation key stays inside the HSM
P2PE scope
• The PIN block is encrypted inside the tamper pad
• The merchant and acquirer host see only ciphertext
• Decryption happens only inside the HSM boundary
Translation
• HSM re-derives the terminal key from the KSN
• It re-encrypts the PIN block under the next zone key
• Cleartext PIN exists only transiently inside the module
Sequence diagram • Built with Archify • Create yours ↗ • Hover to trace • R route • Click to focus • +/− zoom • M radar • [/] views • P play story • T theme • E export