ExportAttributes - AWS Payment Cryptography Control Plane

ExportAttributes

The attributes for IPEK generation during export.

Contents

ExportDukptInitialKey

Parameter information for IPEK export.

Type: ExportDukptInitialKey object

Required: No

KeyCheckValueAlgorithm

The algorithm that AWS Payment Cryptography uses to calculate the key check value (KCV). It is used to validate the key integrity. Specify KCV for IPEK export only.

For TDES keys, the KCV is computed by encrypting 8 bytes, each with value of zero, with the key to be checked and retaining the 3 highest order bytes of the encrypted result. For AES keys, the KCV is computed using a CMAC algorithm where the input data is 16 bytes of zero and retaining the 3 highest order bytes of the encrypted result.

Type: String

Valid Values: CMAC | ANSI_X9_24

Required: No

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: