DUKPT + P2PE PIN Protection

Per-transaction key derivation and PIN translation from the pad to the HSM

DUKPT + P2PE PIN Protection Per-transaction key derivation and PIN translation from the pad to the HSM enter PIN cleartext never leaves the pad PIN block + KSN fresh DUKPT key; P2PE tunnel translate PIN PIN under ZMK re-derive from KSN, then re-encrypt auth request approve / decline auth response show result Capture + encrypt Translate + authorize Response Cardholder · secure PIN pad · Sequence participant Cardholder secure PIN pad Terminal · POI / SRED · Sequence participant Terminal POI / SRED Acquirer · payment host · Sequence participant Acquirer payment host HSM · key + PIN block · Sequence participant HSM key + PIN block Issuer · auth decision · Sequence participant Issuer auth decision Legend request return security async trace

Key per transaction

  • • DUKPT derives a fresh key from the KSN counter every time
  • • A captured key exposes at most one PIN block
  • • The base derivation key stays inside the HSM

P2PE scope

  • • The PIN block is encrypted inside the tamper pad
  • • The merchant and acquirer host see only ciphertext
  • • Decryption happens only inside the HSM boundary

Translation

  • • HSM re-derives the terminal key from the KSN
  • • It re-encrypts the PIN block under the next zone key
  • • Cleartext PIN exists only transiently inside the module