> For the complete documentation index, see [llms.txt](https://sandbox-docs.verifone.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sandbox-docs.verifone.com/adk-5.0-programmers-guide/readme/modules/group___config.md).

# Config

[Macros](#define-members)

|         |                                                                                                                                                                                                                                                                    |
| ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Macros  |                                                                                                                                                                                                                                                                    |
| #define | [CFG\_ENTRY\_IV](#gab60d01dead9ae5dd41d7a0c50e37e231)   "IVType"                                                                                                                                                                                                   |
| #define | [CFG\_TOKEN\_IV\_NONE](#ga82bfec8916794526f55f323be2384cc9)   "NONE"                                                                                                                                                                                               |
|         | <p>value of CFG\_ENTRY\_IV default value <a href="#ga82bfec8916794526f55f323be2384cc9">More...</a><br></p>                                                                                                                                                         |
| #define | [CFG\_TOKEN\_IV\_ZERO](#ga40452c6a4635fa88638d637ffd08852e)   "ZERO"                                                                                                                                                                                               |
|         | <p>value of CFG\_ENTRY\_IV <a href="#ga40452c6a4635fa88638d637ffd08852e">More...</a><br></p>                                                                                                                                                                       |
| #define | [CFG\_TOKEN\_IV\_RAND](#ga1963b2d020f256b2bc8f686e8d79c878)   "RANDOM"                                                                                                                                                                                             |
|         | <p>value of CFG\_ENTRY\_IV <a href="#ga1963b2d020f256b2bc8f686e8d79c878">More...</a><br></p>                                                                                                                                                                       |
| #define | [CFG\_TOKEN\_IV\_USE\_INPUT](#gaa3f2a7cd9700eb6e094c491cba90f44b)   "USER\_DEFINED"                                                                                                                                                                                |
|         | <p>value of CFG\_ENTRY\_IV <a href="#gaa3f2a7cd9700eb6e094c491cba90f44b">More...</a><br></p>                                                                                                                                                                       |
| #define | [CFG\_ENTRY\_ENCMODE](#ga946270505efb931b3211312afa8d492c)   "encMode"                                                                                                                                                                                             |
| #define | [CFG\_TOKEN\_ENCMODE\_ECB](#gafd97668a7484ce5224a24c3c7a657b08)   "MODE\_ECB"                                                                                                                                                                                      |
|         | <p>value of CFG\_ENTRY\_ENCMODE, default value <a href="#gafd97668a7484ce5224a24c3c7a657b08">More...</a><br></p>                                                                                                                                                   |
| #define | [CFG\_TOKEN\_ENCMODE\_CBC](#gaebf52c0f1820c19768a164f88a27bc94)   "MODE\_CBC"                                                                                                                                                                                      |
|         | <p>value of CFG\_ENTRY\_ENCMODE <a href="#gaebf52c0f1820c19768a164f88a27bc94">More...</a><br></p>                                                                                                                                                                  |
| #define | [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc)   "padding"                                                                                                                                                                                             |
| #define | [CFG\_TOKEN\_PAD\_NONE](#ga5c10532bcee038e5914f6373eacb46a0)   "NONE"                                                                                                                                                                                              |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a>, default value <a href="#ga5c10532bcee038e5914f6373eacb46a0">More...</a><br></p>                                                                                                 |
| #define | [CFG\_TOKEN\_PAD\_PKCS7](#gade87be513aa2c1a1a5b5271f78147533)   "PKCS7"                                                                                                                                                                                            |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a> <a href="#gade87be513aa2c1a1a5b5271f78147533">More...</a><br></p>                                                                                                                |
| #define | [CFG\_TOKEN\_PAD\_X923](#ga48e6b29ddaa97bbbd1d270f6c2a0da12)   "X923"                                                                                                                                                                                              |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a> <a href="#ga48e6b29ddaa97bbbd1d270f6c2a0da12">More...</a><br></p>                                                                                                                |
| #define | [CFG\_TOKEN\_PAD\_ISO7816](#gac1440351c36ae311ae5268468a6f0da8)   "ISO7816"                                                                                                                                                                                        |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a> <a href="#gac1440351c36ae311ae5268468a6f0da8">More...</a><br></p>                                                                                                                |
| #define | [CFG\_TOKEN\_PAD\_ZERO](#gaf95a5567d68b9d300baef8e27a741f8d)   "ZERO"                                                                                                                                                                                              |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a> <a href="#gaf95a5567d68b9d300baef8e27a741f8d">More...</a><br></p>                                                                                                                |
| #define | [CFG\_TOKEN\_PAD\_FF](#ga0f0e7c3801fb3b722d4bf3e42743250d)   "FF"                                                                                                                                                                                                  |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a> <a href="#ga0f0e7c3801fb3b722d4bf3e42743250d">More...</a><br></p>                                                                                                                |
| #define | [CFG\_TOKEN\_PAD\_SPACE](#ga27203e3e9c85b785354155336c7cb83b)   "SPACE"                                                                                                                                                                                            |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a> <a href="#ga27203e3e9c85b785354155336c7cb83b">More...</a><br></p>                                                                                                                |
| #define | [CFG\_TOKEN\_PAD\_ISO10126](#gae7322759618c7331c57ddd6e1f3c88a2)   "ISO10126"                                                                                                                                                                                      |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a> <a href="#gae7322759618c7331c57ddd6e1f3c88a2">More...</a><br></p>                                                                                                                |
| #define | [CFG\_TOKEN\_PAD\_ISO9797\_1](#ga9d966f4258d3169c123770080d65e5ba)   "ISO9797\_1"                                                                                                                                                                                  |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a>, ADE/SRED specific padding <a href="#ga9d966f4258d3169c123770080d65e5ba">More...</a><br></p>                                                                                     |
| #define | [CFG\_TOKEN\_PAD\_ISO9797\_2](#gabada9ee23745697d8202500d8086b102)   "ISO9797\_2"                                                                                                                                                                                  |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a>, ADE/SRED specific padding <a href="#gabada9ee23745697d8202500d8086b102">More...</a><br></p>                                                                                     |
| #define | [CFG\_TOKEN\_RSA\_PAD\_PKCS1](#gac8dcc08d9e286bac750fea9e93d7ad73)   "PKCS1"                                                                                                                                                                                       |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a>, RSA specific padding <a href="#gac8dcc08d9e286bac750fea9e93d7ad73">More...</a><br></p>                                                                                          |
| #define | [CFG\_TOKEN\_RSA\_PAD\_PKCS1\_OAEP](#gaa4fb8e794160a33f923fe68ee7179bd3)   "PKCS1\_OAEP"                                                                                                                                                                           |
|         | <p>value of <a href="#gafe03108f84657a93a3f7e1a52feb53bc">CFG\_ENTRY\_PADDING</a>, RSA specific padding <a href="#gaa4fb8e794160a33f923fe68ee7179bd3">More...</a><br></p>                                                                                          |
| #define | [CFG\_ENTRY\_HASHTYPE](#ga86a1b2813b9c5f7cf27242fdbf775439)   "hashType"                                                                                                                                                                                           |
| #define | [CFG\_TOKEN\_HASHTYPE\_SHA1](#gadd90d36b31ab0a577378f7720c076439)   "SHA1"                                                                                                                                                                                         |
|         | <p>value of CFG\_ENTRY\_HASHTYPE <a href="#gadd90d36b31ab0a577378f7720c076439">More...</a><br></p>                                                                                                                                                                 |
| #define | [CFG\_TOKEN\_HASHTYPE\_SHA224](#ga898427bc525c8513e971d8198e8f43dd)   "SHA224"                                                                                                                                                                                     |
|         | <p>value of CFG\_ENTRY\_HASHTYPE <a href="#ga898427bc525c8513e971d8198e8f43dd">More...</a><br></p>                                                                                                                                                                 |
| #define | [CFG\_TOKEN\_HASHTYPE\_SHA256](#gaba0922b0c5f4bb2f104d7dc3cd9affb2)   "SHA256"                                                                                                                                                                                     |
|         | <p>value of CFG\_ENTRY\_HASHTYPE, default value in AES module <a href="#gaba0922b0c5f4bb2f104d7dc3cd9affb2">More...</a><br></p>                                                                                                                                    |
| #define | [CFG\_TOKEN\_HASHTYPE\_SHA384](#gaaacb946c9029654216868f58fe3d4eae)   "SHA384"                                                                                                                                                                                     |
|         | <p>value of CFG\_ENTRY\_HASHTYPE <a href="#gaaacb946c9029654216868f58fe3d4eae">More...</a><br></p>                                                                                                                                                                 |
| #define | [CFG\_TOKEN\_HASHTYPE\_SHA512](#ga0a15b7e427347133f38c9cd34a6441e3)   "SHA512"                                                                                                                                                                                     |
|         | <p>value of CFG\_ENTRY\_HASHTYPE <a href="#ga0a15b7e427347133f38c9cd34a6441e3">More...</a><br></p>                                                                                                                                                                 |
| #define | [CFG\_ENTRY\_RSA\_CALC\_HASH](#gad6cb616ebd3638d561f21650dc1466ad)   "calcHash"                                                                                                                                                                                    |
| #define | [CFG\_TOKEN\_RSA\_CALC\_HASH\_YES](#ga4b1f0e2242b9b4ecc89ee3bf6f548976)   "yes"                                                                                                                                                                                    |
|         | <p>value of <a href="#gad6cb616ebd3638d561f21650dc1466ad">CFG\_ENTRY\_RSA\_CALC\_HASH</a>, default value <a href="#ga4b1f0e2242b9b4ecc89ee3bf6f548976">More...</a><br></p>                                                                                         |
| #define | [CFG\_TOKEN\_RSA\_CALC\_HASH\_NO](#ga89545638866850d2cfaf499d4bbb2fb2)   "no"                                                                                                                                                                                      |
|         | <p>value of <a href="#gad6cb616ebd3638d561f21650dc1466ad">CFG\_ENTRY\_RSA\_CALC\_HASH</a> <a href="#ga89545638866850d2cfaf499d4bbb2fb2">More...</a><br></p>                                                                                                        |
| #define | [CFG\_ENTRY\_RSA\_GETKD\_FORMAT](#ga336a59e27b41607b81eb15f34cac894a)   "getKeyDataFormat"                                                                                                                                                                         |
| #define | [CFG\_TOKEN\_RSA\_GETKD\_PEM](#gadc53fdacbcb2c210a7672d3e9fea6e99)   "PEM"                                                                                                                                                                                         |
|         | <p>value of <a href="#ga336a59e27b41607b81eb15f34cac894a">CFG\_ENTRY\_RSA\_GETKD\_FORMAT</a> <a href="#gadc53fdacbcb2c210a7672d3e9fea6e99">More...</a><br></p>                                                                                                     |
| #define | [CFG\_TOKEN\_RSA\_GETKD\_DER](#gaa7a16f0472b900b454c6969c7d8720ee)   "DER"                                                                                                                                                                                         |
|         | <p>value of <a href="#ga336a59e27b41607b81eb15f34cac894a">CFG\_ENTRY\_RSA\_GETKD\_FORMAT</a> <a href="#gaa7a16f0472b900b454c6969c7d8720ee">More...</a><br></p>                                                                                                     |
| #define | [CFG\_TOKEN\_RSA\_GETKD\_PRT](#gaeaf542d1a2dbd450b6aa81839df10200)   "PRINT"                                                                                                                                                                                       |
|         | <p>value of <a href="#ga336a59e27b41607b81eb15f34cac894a">CFG\_ENTRY\_RSA\_GETKD\_FORMAT</a>, default value <a href="#gaeaf542d1a2dbd450b6aa81839df10200">More...</a><br></p>                                                                                      |
| #define | [CFG\_TOKEN\_RSA\_GETKD\_ORG](#ga8573171ef0704459dbdcd91b363db091)   "ORIGINAL"                                                                                                                                                                                    |
|         | <p>value of <a href="#ga336a59e27b41607b81eb15f34cac894a">CFG\_ENTRY\_RSA\_GETKD\_FORMAT</a> <a href="#ga8573171ef0704459dbdcd91b363db091">More...</a><br></p>                                                                                                     |
| #define | [CFG\_ENTRY\_DUKPT\_INC\_KSN](#ga86878ef55c861a78b3c0240703d1bedb)   "KSNincrementation"                                                                                                                                                                           |
| #define | [CFG\_TOKEN\_DUKPT\_BY\_OPERATION](#ga1038e59d5a70ded57d6fa4d4828a5d00)   "BY\_OPERATION"                                                                                                                                                                          |
|         | <p>value of <a href="#ga86878ef55c861a78b3c0240703d1bedb">CFG\_ENTRY\_DUKPT\_INC\_KSN</a> default value <a href="#ga1038e59d5a70ded57d6fa4d4828a5d00">More...</a><br></p>                                                                                          |
| #define | [CFG\_TOKEN\_DUKPT\_BY\_API](#gad3b7e6d29779eee52566da614317208b)   "BY\_API"                                                                                                                                                                                      |
|         | <p>value of <a href="#ga86878ef55c861a78b3c0240703d1bedb">CFG\_ENTRY\_DUKPT\_INC\_KSN</a> <a href="#gad3b7e6d29779eee52566da614317208b">More...</a><br></p>                                                                                                        |
| #define | [CFG\_ENTRY\_DUKPT\_KEY\_VARIANT](#ga053f55fa711f0286d30aa4e79207aa6d)   "keyVariant"                                                                                                                                                                              |
| #define | [CFG\_TOKEN\_DUKPT\_KEY\_VAR\_REQUEST](#ga6727ebc5a0cda870745972d4b55ab71c)   "request"                                                                                                                                                                            |
|         | <p>value of <a href="#ga053f55fa711f0286d30aa4e79207aa6d">CFG\_ENTRY\_DUKPT\_KEY\_VARIANT</a>, default value. In case of AES DUKPT - Data Encryption Encrypt / Message Authentication Generation <a href="#ga6727ebc5a0cda870745972d4b55ab71c">More...</a><br></p> |
| #define | [CFG\_TOKEN\_DUKPT\_KEY\_VAR\_RESPONSE](#ga34c5fb6b1b6b58c4d6a51f2da208479b)   "response"                                                                                                                                                                          |
|         | <p>value of <a href="#ga053f55fa711f0286d30aa4e79207aa6d">CFG\_ENTRY\_DUKPT\_KEY\_VARIANT</a>. In case of AES DUKPT - Data Encryption Decrypt / Message Authentication Verification <a href="#ga34c5fb6b1b6b58c4d6a51f2da208479b">More...</a><br></p>              |
| #define | [CFG\_TOKEN\_DUKPT\_KEY\_VAR\_BOTH](#ga397a6f6091a11718ed25027c3e41d92d)   "both"                                                                                                                                                                                  |
|         | <p>value of <a href="#ga053f55fa711f0286d30aa4e79207aa6d">CFG\_ENTRY\_DUKPT\_KEY\_VARIANT</a>. In case of AES DUKPT - Data Encryption Both Ways / Message Authentication Both Ways <a href="#ga397a6f6091a11718ed25027c3e41d92d">More...</a><br></p>               |
| #define | [CFG\_TOKEN\_SRED\_VARIANT\_X924\_MAC\_REQ\_BW](#gac10817d4961802bbf9da51825ed9a42f)   "X924\_MAC\_REQ\_BW"                                                                                                                                                        |
|         | <p>value of <a href="#ga053f55fa711f0286d30aa4e79207aa6d">CFG\_ENTRY\_DUKPT\_KEY\_VARIANT</a> <a href="#gac10817d4961802bbf9da51825ed9a42f">More...</a><br></p>                                                                                                    |
| #define | [CFG\_TOKEN\_SRED\_VARIANT\_X924\_MAC\_RESP](#gad736c699dfba417d61030f2e12ade24b)   "X924\_MAC\_RESP"                                                                                                                                                              |
|         | <p>value of <a href="#ga053f55fa711f0286d30aa4e79207aa6d">CFG\_ENTRY\_DUKPT\_KEY\_VARIANT</a> <a href="#gad736c699dfba417d61030f2e12ade24b">More...</a><br></p>                                                                                                    |
| #define | [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6)   "algo"                                                                                                                                                                                                   |
| #define | [CFG\_TOKEN\_SRED\_ALG\_1](#gafdd390e0c15cdc2eed87ca316d3bbb74)   "ALG\_9797\_MAC\_1"                                                                                                                                                                              |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a>, default value. SRED specific padding. No default value for AES module <a href="#gafdd390e0c15cdc2eed87ca316d3bbb74">More...</a><br></p>                                            |
| #define | [CFG\_TOKEN\_SRED\_ALG\_1A](#ga00432754611bf9d4d68928f46aacf7e1)   "ALG\_9797\_MAC\_1A"                                                                                                                                                                            |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a>, SRED specific padding <a href="#ga00432754611bf9d4d68928f46aacf7e1">More...</a><br></p>                                                                                            |
| #define | [CFG\_TOKEN\_SRED\_ALG\_2](#ga8c9674a4e3e987b05f9faa0d5e545833)   "ALG\_9797\_MAC\_2"                                                                                                                                                                              |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a>, SRED specific padding <a href="#ga8c9674a4e3e987b05f9faa0d5e545833">More...</a><br></p>                                                                                            |
| #define | [CFG\_TOKEN\_SRED\_ALG\_3](#gac239a169346e74784abe25141f702fa1)   "ALG\_9797\_MAC\_3"                                                                                                                                                                              |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a>, SRED specific padding <a href="#gac239a169346e74784abe25141f702fa1">More...</a><br></p>                                                                                            |
| #define | [CFG\_TOKEN\_SRED\_ALG\_4](#ga769d2b2a5b51bbc6e49b5b72abd45e6b)   "ALG\_9797\_MAC\_4"                                                                                                                                                                              |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a>, SRED specific padding <a href="#ga769d2b2a5b51bbc6e49b5b72abd45e6b">More...</a><br></p>                                                                                            |
| #define | [CFG\_TOKEN\_SRED\_ALG\_5](#ga999281312eeef703cef5cfe1449aaee0)   "ALG\_9797\_MAC\_5"                                                                                                                                                                              |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a>, SRED specific padding <a href="#ga999281312eeef703cef5cfe1449aaee0">More...</a><br></p>                                                                                            |
| #define | [CFG\_TOKEN\_SRED\_ALG\_5A](#gab5822349188eae06fa55634ea4d3bb49)   "ALG\_9797\_MAC\_5A"                                                                                                                                                                            |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a>, SRED specific padding <a href="#gab5822349188eae06fa55634ea4d3bb49">More...</a><br></p>                                                                                            |
| #define | [CFG\_TOKEN\_SRED\_ALG\_CMAC](#ga312073af7ce6f177d077f21fc164a897)   "ALG\_CMAC\_TDEA"                                                                                                                                                                             |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a>, SRED specific padding <a href="#ga312073af7ce6f177d077f21fc164a897">More...</a><br></p>                                                                                            |
| #define | [CFG\_TOKEN\_SRED\_ALG\_HMAC](#gac26c4068e2480cbb6fd967a551cf790c)   "ALG\_HMAC\_SHA256"                                                                                                                                                                           |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a>, SRED specific padding <a href="#gac26c4068e2480cbb6fd967a551cf790c">More...</a><br></p>                                                                                            |
| #define | [CFG\_TOKEN\_ALGO\_CMAC](#gaf79405974fcfbba042ef5c2cb40e08a7)   "CMAC"                                                                                                                                                                                             |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a> <a href="#gaf79405974fcfbba042ef5c2cb40e08a7">More...</a><br></p>                                                                                                                   |
| #define | [CFG\_TOKEN\_ALGO\_HMAC](#ga7e7c533e64c60c460623099a271839e6)   "HMAC"                                                                                                                                                                                             |
|         | <p>value of <a href="#gab479d306344dff2934da238f5e2c48c6">CFG\_ENTRY\_ALGO</a> <a href="#ga7e7c533e64c60c460623099a271839e6">More...</a><br></p>                                                                                                                   |
| #define | [CFG\_ENTRY\_IPP\_KEY\_MANAGEMENT](#ga9b4a8d263360a9fc49e056cd459c65b0)   "KeyManagementOption"                                                                                                                                                                    |
| #define | [CFG\_ENTRY\_KEY\_MANAGEMENT\_TYPE](#gace84acf3acd2546983b0ac7f34bccd82)   "KeyManagementType"                                                                                                                                                                     |
| #define | [CFG\_TOKEN\_KEY\_MAN\_TYPE\_MSK](#ga6cc85bd481d0e2068105c2ab52ed1c3c)   "MSK"                                                                                                                                                                                     |
|         | <p>value of CFG\_ENTRY\_KEY\_MANAGEMENT\_TYPE <a href="#ga6cc85bd481d0e2068105c2ab52ed1c3c">More...</a><br></p>                                                                                                                                                    |
| #define | [CFG\_TOKEN\_KEY\_MAN\_TYPE\_DUKPT](#gac61a347bdf88553e6014655dcf50cd96)   "DUKPT"                                                                                                                                                                                 |
|         | <p>value of CFG\_ENTRY\_KEY\_MANAGEMENT\_TYPE <a href="#gac61a347bdf88553e6014655dcf50cd96">More...</a><br></p>                                                                                                                                                    |
| #define | [CFG\_TOKEN\_KEY\_MAN\_TYPE\_AS2805](#ga24851e60ec98ee64e15d7d019a561c5e)   "AS2805"                                                                                                                                                                               |
|         | <p>value of CFG\_ENTRY\_KEY\_MANAGEMENT\_TYPE <a href="#ga24851e60ec98ee64e15d7d019a561c5e">More...</a><br></p>                                                                                                                                                    |
| #define | [CFG\_ENTRY\_TRANSPORT\_KEY](#ga89cd282e773cd9be0282720efb9bae94)   "transportKey"                                                                                                                                                                                 |

### DetailedDescription <a href="#detailed-description" id="detailed-description"></a>

## Security Module VSS <a href="#autotoc_md47" id="autotoc_md47"></a>

VSS provides two engines: VSS-MSK and VSS-DUKPT

Using VSS - API functions

* [secSetKSId()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a75edecb24f839e04debb1aa5e47b5714) - selects a Key Set Id between 1 and 8 (default value is 1) which addresses the macro MACRO\_SELECT\_KEY\_SET\_ID\_x (1 <= x <= 8)
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - loads a key in a VSS key slot. possible Key Types
  * for DUKPT:
    * KEY\_TYPE\_DUKPT
  * for MSK:
    * KEY\_TYPE\_PPK
    * KEY\_TYPE\_MGK
    * KEY\_TYPE\_DEK
    * KEY\_TYPE\_MVK
    * KEY\_TYPE\_DDK
    * KEY\_TYPE\_KEK
  * special handling for MSK (OS function replacement):
    * KEY\_TYPE\_DIRECT\_MK\_PLAIN - iPS\_LoadMasterClearKey replacement. Loads the security script's master key. The values are sent in the clear, but must all be loaded in the same session. Before loading the first key after a power cycle, all previously loaded keys (including the system keys) are erased. **This function should be used exclusively in a secure environment.** Data will be installed into the script referenced by host config (via handle) and key slot pointed by [secSetKSId()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a75edecb24f839e04debb1aa5e47b5714) (key slot=keySetId-1)
    * KEY\_TYPE\_DIRECT\_MK\_ENC - iPS\_LoadMasterEncKey replacement. Loads the security script's master key without deleting the keys already loaded. The key value must be encrypted with VSS\_KLK. Data will be installed into the script referenced by host config (via handle) and key slot pointed by [secSetKSId()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a75edecb24f839e04debb1aa5e47b5714) (key slot=keySetId-1)
    * KEY\_TYPE\_DIRECT\_SYSK\_PLAIN - iPS\_LoadSysClearKey replacement. Loads the VSS\_KLK (system key) in the clear. Before writing the new value of the key, all other keys in the terminal are erased. **This function should be used exclusively in a secure environment.** Handle and keySetId are not relevant in this case.
    * KEY\_TYPE\_DIRECT\_SYSK\_ENC - iPS\_LoadSysEncKey replacement. Loads the system key. The new values must be encrypted under the current value of VSS\_KLK. Handle and keySetId are not relevant in this case.
    * KEY\_TYPE\_DELETE\_ALL\_KEYS - This iPS\_DeleteKey replacement deletes all keys in the script referenced by host config (via handle)
    * KEY\_TYPE\_DELETE\_SYS\_KEY - This iPS\_DeleteKey replacement deletes System key (VSS\_KLK). Handle and keySetId are not relevant in this case.
    * KEY\_TYPE\_DIRECT\_AUTHEX\_ENC - rsaAuthexVssKeyInstall replacement for loading the VSS keys. The new VSS key slot values must be encrypted under AuthEx with PKCS1 v1.5 padding. Data length of the encrypted data should be 256 bytes. Data will be installed into the script referenced by host config (via handle) and first key slot, that must be filled with decrypted key value, is pointed by [secSetKSId()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a75edecb24f839e04debb1aa5e47b5714) (key slot=keySetId-1)
    * KEY\_TYPE\_DIRECT\_AUTHEX\_SYSK - rsaAuthexVssKeyInstall replacement for loading the VSS\_KLK key. The new 16 bytes key value must be encrypted under AuthEx with PKCS1 v1.5 padding. Data length of the encrypted data should be 256 bytes. Handle and keySetId are not relevant in this case.
    * KEY\_TYPE\_DELETE\_ALL\_CUST\_KEYS - special key type (replacement for iPS\_DeleteKey(DEL\_ALL)) is independent from host configuration and clears all OS-managed customer keys like VSS, IPP and ADE.
    * KEY\_TYPE\_DIRECT\_CUSTOM\_ASYM - similar to KEY\_TYPE\_DIRECT\_AUTHEX\_ENC but using Custom RSA key. Functionality is provided only by VOS2. Data will be installed into the script referenced by host config (via handle) and first key slot, that must be filled with decrypted key value, is pointed by [secSetKSId()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a75edecb24f839e04debb1aa5e47b5714) (key slot=keySetId-1). The key value must be encrypted under Custom RSA key with PKCS1 v1.5 padding. Cryptogram length must be equal to transport key modulus length. Custom RSA key must be loaded via VRK and referenced in host configuration setting by tag "transportKey".
    * KEY\_TYPE\_DIRECT\_CUSTOM\_ASYM\_SYSK - similar to KEY\_TYPE\_DIRECT\_AUTHEX\_SYSK for loading the VSS\_KLK key. Functionality is provided only by VOS2. The new 16 bytes key value must be encrypted under Custom RSA key with PKCS1 v1.5 padding. Cryptogram length must be equal to transport key modulus length. KeySetId is not relevant in this case. Custom RSA key must be loaded via VRK and referenced in host configuration setting by tag "transportKey" (see Custom VSS key loading configuration example below).
* [secIncrementKSN()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a77860b4cffed3ba159a5c124c8e2cde2) - increments the Key Serial Number and creates a new DUKPT key (for DUKTP only)
* [secSign()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a66a1992f617359f2e4a96f4980478f82) - generates a MAC or HMAC (a maximum size of 4096 bytes will be supported)
* [secVerify()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a5470ce89fa947abc445f251ae0b2387b) - verifies a MAC (a maximum size of 4096 bytes will be supported)
* [secEncryptData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#aa58bc1a6a2056aebd3edc92f3bfcce9d) - encrypts data
* [secDecryptData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a9cd679dc9763b06566dff28b3d3268c9) - decrypts data
* [secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) - delivers a JSON-formatted list of injected keys per Key Set Id (see section 'JSON-formatted outputs' below)
* [secRetrieveEncryptedPIN()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab3d26136c64019fd223aa9ccd120d4e0) - retrieves an encrypted PIN block

## Configuration in sccfg.json <a href="#autotoc_md48" id="autotoc_md48"></a>

Mandatory tags:

* scriptFileName
* scriptName
* KeyManagementType

Optional tags:

* KSNincrementation (only for VSS\_DUKPT)

### Example for VSS-MSK configuration <a href="#autotoc_md49" id="autotoc_md49"></a>

```cpp
{
  "name": "schemeVSSMSK",
  "scriptFileName": "TS020122.vso",
  "scriptName": "TS020122",
  "settings": {
   "KeyManagementType": "MSK"
  }
}
```

### Example for VSS-DUKPT configuration <a href="#autotoc_md50" id="autotoc_md50"></a>

```cpp
{
  "name": "schemeVSSDUKPT",
  "scriptFileName": "TS010322.vso",
  "scriptName": "TS010322",
  "settings": {
   "KeyManagementType": "DUKPT",
   "KSNincrementation": "BY_OPERATION"
}
}
```

### Example for Custom VSS key loading configuration <a href="#autotoc_md51" id="autotoc_md51"></a>

ADKSEC\_CustomVSS\_RKL.der - RSA private Key loaded via VRK

```cpp
{
  "name": "schemeVSSMSK",
  "scriptFileName": "TS020122.vso",
  "scriptName": "TS020122",
  "settings": {
   "transportKey": "generickeys/usr1/ADKSEC_CustomVSS_RKL.der"
  }
}
```

## JSON formatted outputs <a href="#autotoc_md52" id="autotoc_md52"></a>

[secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) delivers a JSON formatted output string with information about keys related to an opened Security Module.

### Example: Output for a host using module VSS-MSK (conditioned output) <a href="#autotoc_md53" id="autotoc_md53"></a>

```cpp
{
  "Keys":[
   {"DDK":{"injected":"yes"},"DEK":{"injected":"yes"},"KEK":{"injected":"yes"},"KeySet":1,"MGK":{"injected":"yes"},"MVK":{"injected":"yes"},"PPK":{"injected":"yes"},"TMK":{"injected":"yes"}},
   {"DDK":{"injected":"yes"},"DEK":{"injected":"yes"},"KEK":{"injected":"yes"},"KeySet":2,"MGK":{"injected":"yes"},"MVK":{"injected":"yes"},"PPK":{"injected":"yes"},"TMK":{"injected":"yes"}},
   {"DDK":{"injected":"yes"},"DEK":{"injected":"yes"},"KEK":{"injected":"yes"},"KeySet":3,"MGK":{"injected":"yes"},"MVK":{"injected":"yes"},"PPK":{"injected":"yes"},"TMK":{"injected":"yes"}},
   {"DDK":{"injected":"yes"},"DEK":{"injected":"yes"},"KEK":{"injected":"yes"},"KeySet":4,"MGK":{"injected":"yes"},"MVK":{"injected":"yes"},"PPK":{"injected":"yes"},"TMK":{"injected":"yes"}},
   {"DDK":{"injected":"yes"},"DEK":{"injected":"yes"},"KEK":{"injected":"yes"},"KeySet":5,"MGK":{"injected":"yes"},"MVK":{"injected":"yes"},"PPK":{"injected":"yes"},"TMK":{"injected":"yes"}},
   {"DDK":{"injected":"yes"},"DEK":{"injected":"yes"},"KEK":{"injected":"yes"},"KeySet":6,"MGK":{"injected":"yes"},"MVK":{"injected":"yes"},"PPK":{"injected":"yes"},"TMK":{"injected":"yes"}},
   {"DDK":{"injected":"yes"},"DEK":{"injected":"yes"},"KEK":{"injected":"yes"},"KeySet":7,"MGK":{"injected":"yes"},"MVK":{"injected":"yes"},"PPK":{"injected":"yes"},"TMK":{"injected":"yes"}},
   {"DDK":{"injected":"yes"},"DEK":{"injected":"yes"},"KEK":{"injected":"yes"},"KeySet":8,"MGK":{"injected":"yes"},"MVK":{"injected":"yes"},"PPK":{"injected":"yes"},"TMK":{"injected":"yes"}}
  ],
  "Status":{
   "SlotsInUse":[0,1,2,3,4,5,6,7,8,9,10,11,12,13,26,27,28,29,30,31,32,33,34,35,36,37,56,57,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,100,101,103]
  }
}
```

### Example: Output for a host using module VSS-DUKPT (conditioned output) <a href="#autotoc_md54" id="autotoc_md54"></a>

```cpp
{
  "Keys":[
   {"DUKPT":{"KSN":"FFFF9876543210E00002","injected":"yes"},"KeySet":1},
   {"DUKPT":{"KSN":"FFFF9876543210E00002","injected":"yes"},"KeySet":2},
   {"DUKPT":{"KSN":"FFFF9876543210E00002","injected":"yes"},"KeySet":3},
   {"DUKPT":{"KSN":"FFFF9876543210E00002","injected":"yes"},"KeySet":4}
  ],
  "Status":{
   "SlotsInUse":[2,3,4,5,6,7,8,9,10,102,103,106,107,108,109,110]
  }
}
```

## Module Bendigo <a href="#autotoc_md55" id="autotoc_md55"></a>

Module Bendigo enhances the VSS Module functionality to meet AS2805 requirements for usage in the project Boomer.

Functionality of Bendigo module:

The Bendigo scheme covers the following functionality:

* key loading, management and update of symmetric and RSA keys
* retrieving key information
* generating and verifying MAC
* encrypting and decrypting data
* retrieving PIN block

For details please see the relevant documentation.

The Bendigo Module provides additionally to the shared VSS Module API functions following functions with special effectiveness:

* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - load a key in a VSS key slot. Possible Key Types:

  * KEY\_TYPE\_PPK
  * KEY\_TYPE\_MGK
  * KEY\_TYPE\_DEK
  * KEY\_TYPE\_MVK
  * KEY\_TYPE\_DDK
  * KEY\_TYPE\_KEK
  * KEY\_TYPE\_DUKPT
  * KEY\_TYPE\_SPONSOR\_PK
  * KEY\_TYPE\_SPONSOR\_MK
  * KEY\_TYPE\_SPONSOR\_KI
  * KEY\_TYPE\_SEC\_ACQ\_KI
  * KEY\_TYPE\_ACQUIRER\_MK
  * KEY\_TYPE\_SEC\_ACQ\_MK
  * KEY\_TYPE\_ACQ\_SESSION\_KEYS

  KEK1 or KEK2 usage can be adjusted in Transaction Data by tag TagBendigoKEKFlag (=1 for KEK1, =2 for KEK2) for KEY\_TYPE\_ACQ\_SESSION\_KEYS.
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - rolls key KEK1 or KEK2 by setting tag TagAS2805Func in Transaction Data:

  * KEK1 roll: TagAS2805Func=2
  * KEK2 roll: TagAS2805Func=3

  All function parameters are obsolete in this case.
* getKeyData() - get dedicated information for the following key types:

  * KEY\_TYPE\_TCU\_PK
  * KEY\_TYPE\_ENC\_KI\_FMT\_0
  * KEY\_TYPE\_ENC\_KI\_FMT\_1
  * KEY\_TYPE\_ENC\_KI\_FMT\_2
  * KEY\_TYPE\_ENC\_PPID
  * KEY\_TYPE\_ENC\_PPASN
  * KEY\_TYPE\_KVC\_KIA (KVC of KIA)
  * KEY\_TYPE\_KVC\_KEK1 (KVC of KEK1)

  To get key information of KEK1 or KEK2 set indication in Transaction Data tag TagBendigoKEKFlag (=1 for KEK1, =2 for KEK2) for KEY\_TYPE\_ENC\_PPASN.
* getKeyInventory() - get indicator whether AS2805 keys are injected

## Configuration in sccfg.json <a href="#autotoc_md56" id="autotoc_md56"></a>

Mandatory tags:

* KeyManagementType - value: "AS2805"

### Example for configuration <a href="#autotoc_md57" id="autotoc_md57"></a>

```cpp
{
   "name": "schemeBendigo",
   "scriptFileName": "AU010222.vso",
   "scriptName": "AU010222",
   "settings": {
   "KeyManagementType": "AS2805"
   }
}
```

## JSON formatted outputs <a href="#autotoc_md58" id="autotoc_md58"></a>

[secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) delivers a JSON formatted output string with information about keys related to an opened Security Module.

### Example: Output for a host using module Bendigo (conditioned output) <a href="#autotoc_md59" id="autotoc_md59"></a>

```cpp
{
   "Keys": [
   {
   "AS2805": {
   "injected": "yes"
   },
   "KeySet": 1
   }
   ]
}
```

## Security Modules IPPmsk and IPPdukpt <a href="#autotoc_md60" id="autotoc_md60"></a>

Working with IPP on Verix is described in Verix eVo Volume I: Operating System Programmers Manual, VPN DOC00301. For V/OS, please refer to V/OS Programmers Manual, VPN DOC00501.

IPP provides two engines: IPP-MSK and IPP-DUKPT

Note: To utilize IPP a Master Key injection must be prepared outside the user application before. Master Key injection is not ADK-SEC IPP functionality.

### Using IPP-MSK - API functions <a href="#autotoc_md61" id="autotoc_md61"></a>

* [secSetKSId()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a75edecb24f839e04debb1aa5e47b5714) - selects Key Set Id. Master Key will be used for cryption operation from slot given by KeyAddressTable (see configuration). The default KSId value is 1
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - loads a Master Key in a IPP key slot given by KeyAddressTable (see configuration). KeyAddressTable can reference MK (slots 0-9) and IPP KLK (slot 15)
  * possible Key Types: KEY\_TYPE\_KEK
  * use GISKE input format for 'keyData'
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - loads a Session Key
  * possible Key Types: KEY\_TYPE\_PPK, KEY\_TYPE\_MGK
  * use GISKE input format for 'keyData'
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - KEY\_TYPE\_DELETE\_ALL\_KEYS - This iPS\_DeleteKey replacement deletes all IPP keys referenced by host config (via handle)
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - KEY\_TYPE\_DELETE\_ALL\_CUST\_KEYS - special key type (replacement for iPS\_DeleteKey(DEL\_ALL)) is independent from host configuration and clears all OS-managed customer keys like VSS, IPP and ADE.
* [secSign()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a66a1992f617359f2e4a96f4980478f82) - generates a MAC
  * use BIN input format for 'data'
  * output format is BIN
  * a maximum size of 4096 bytes will be supported
* [secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) - delivers a JSON-formatted list of injected keys per Key Set Id (Master Key address (0-9))
* [secRetrieveEncryptedPIN()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab3d26136c64019fd223aa9ccd120d4e0) - retrieves an encrypted PIN block
  * output format for 'pinBlk' is BIN

### Using IPP-DUKPT - API functions <a href="#autotoc_md62" id="autotoc_md62"></a>

* [secSetKSId()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a75edecb24f839e04debb1aa5e47b5714) - selects Key Set Id. DUKPT key will be used for crypto operation from given by KeyAddressTable (see configuation). The default KSId value is 1
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - loads DUKPT Initial Key and an Initial KSN in a IPP key slot given by KeyAddressTable (see configuration). KeyAddressTable can reference DUKPT key slots 0, 1 and 2
  * possible Key Types: KEY\_TYPE\_DUKPT
  * use BIN input format for 'keyData' and 'ksn'
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - KEY\_TYPE\_DELETE\_ALL\_KEYS - This iPS\_DeleteKey replacement deletes all IPP-DUKPT keys referenced by host config (via handle)
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - KEY\_TYPE\_DELETE\_ALL\_CUST\_KEYS - special key type (replacement for iPS\_DeleteKey(DEL\_ALL)) is independent from host configuration and clears all OS-managed customer keys like VSS, IPP and ADE.
* [secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) - delivers a JSON-formatted list of injected keys per Key Set Id (DUKPT Key address (0-2)) Key Serial Number (KSN) with suppressed leading Fs.
* [secRetrieveEncryptedPIN()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab3d26136c64019fd223aa9ccd120d4e0) - retrieves an encrypted PIN block
  * output format for 'pinBlk' and 'KSN' is BIN

## Configuration in sccfg.json <a href="#autotoc_md63" id="autotoc_md63"></a>

Mandatory tags:

* KeyManagementOption

Optional tags:

* KeyAddressTable

### Example for IPP-MSK configuration <a href="#autotoc_md64" id="autotoc_md64"></a>

```cpp
{
  "KeyManagementOption": "8A3",
  "KeyAddressTable": [
   {"description": "| 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 <- KeySetId"},
   {"sign": ["0", "1", "2", "3", "4", "5", "6", "7", "8", "9"]},
   {"retrieveEncPIN": ["0", "1", "2", "3", "4", "5", "6", "7", "8", "9"]},
   {"updateKey": ["0", "1", "2", "3", "4", "5", "6", "7", "8", "9", "15"]}
  ]
}
```

### Example for IPP-DUKPT configuration <a href="#autotoc_md65" id="autotoc_md65"></a>

```cpp
{
"name": "schemeIPPDUKPT",
"settings": {
  "KeyManagementOption": "0A0",
  "KeyAddressTable": [
   {"description": "| 1 | 2 | 3 | <- KeySetId (3 slots)"},
   {"retrieveEncPIN": ["0", "1", "2"]}
  ]
}
}
```

IPP Key Management Options \[KMM + DEMF] according IPP Packet 17 (see OS Programmers Manual) example "0A0".

## JSON formatted outputs <a href="#autotoc_md66" id="autotoc_md66"></a>

[secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) delivers a JSON formatted output string with information about keys related to an opened Security Module.

### Example: Output for a host using security module IPP-MSK (conditioned output) <a href="#autotoc_md67" id="autotoc_md67"></a>

```cpp
{
   "Keys":[
   {
   "KEK":{
   "Algorithm":"TDES [4]",
   "KeyAddress":1,
   "KeyLength":50,
   "KeyUsageAttribute":"key encryption or wrapping",
   "KeyVersion":"00",
   "ModeOfUseAttribute":"Decryption only [2]",
   "injected":"yes",
   "slot_id":0
   },
   "KeySet":1,
   "MGK":{ "injected":"no" },
   "PPK":{ "injected":"no" }
   },
   {
   "KEK":{
   "Algorithm":"TDES [4]",
   "KeyAddress":2,
   "KeyLength":50,
   "KeyUsageAttribute":"ISO 9797-1 MAC algorithm 1 (1-112 bits)",
   "KeyVersion":"00",
   "ModeOfUseAttribute":"MAC generate [5]",
   "injected":"yes",
   "slot_id":1
   },
   "MGK":{ "injected":"yes" },
   "PPK":{ "injected":"yes" },
   "KeySet":2
   },
   {
   "KEK":{ "injected":"no" },
   "KeySet":3
   },
   {
   "KEK":{ "injected":"no" },
   "KeySet":4
   },
   {
   "KEK":{ "injected":"no" },
   "KeySet":5
   },
   {
   "KEK":{ "injected":"no" },
   "KeySet":6
   },
   {
   "KEK":{ "injected":"no" },
   "KeySet":7
   },
   {
   "KEK":{ "injected":"no" },
   "KeySet":8
   },
   {
   "KEK":{ "injected":"no" },
   "KeySet":9
   },
   {
   "KEK":{ "injected":"no" },
   "KeySet":10
   }
   ]
}
```

### Example: Output for a host using security module IPP-DUKPT (conditioned output) <a href="#autotoc_md68" id="autotoc_md68"></a>

```cpp
{
   "Keys":[
   {
   "DUKPT":{
   "KSN":"9876543210E00002",
   "injected":"yes",
   "slot_id":0
   },
   "KeySet":1
   },
   {
   "DUKPT":{
   "KSN":"552AE6B6DF000000002",
   "injected":"yes",
   "slot_id":1
   },
   "KeySet":2
   },
   {
   "DUKPT":{
   "KSN":"552AE7B7DF000000002",
   "injected":"yes",
   "slot_id":2
   },
   "KeySet":3
   }
   ]
}
```

## Security Module ADE <a href="#autotoc_md69" id="autotoc_md69"></a>

ADE (Account Data Encryption) is an SRED solution and provides DUKPT based card data encryption using triple DES encryption with a double-length key.

Sensitive card data protected is:

* Application Primary Account Number (PAN) \[Card read or Manual]
* Track1 Data (MasterCard PayPass contactless only)
* Track 2 Data (MasterCard PayPass contactless only)
* Track 1 Discretionary Data
* Track 2 Discretionary Data
* Track 2 Equivalent Data
* Magstripe read Track 1, 2 and 3 data
* Manual CVV2

ADE DUKPT keys are injected using VRK, VTM or IPP. The keys are independent to IPP DUKPT keys.

### Functionality of ADE module <a href="#autotoc_md70" id="autotoc_md70"></a>

THe ADE module provides following functionality:

* get status of engine and ADE module in a JSON formatted output string
* load a DUKPT initial key and initial KSN (optional - key loading is usually not done by ADK-SEC). This functionality is not supported on Verix!
* encrypt card data

For card data encryption following parameters are configurable:

1. encryption mode
2. initialization vector (IV)
3. padding scheme
4. KeyAddressTable

ADE encryption modes of operation:

* MODE\_ECB
* MODE\_CBC

In CBC mode ADE uses a initialization vector (IV) per encryption (8-byte). If the IV is configured as 'Random' the random value will be generated by the OS and returned as output parameter.

SRED padding schemes:

* NONE (default value)
* PKCS7 Each padding byte equals the padding length. Example: XX XX XX XX 04 04 04 04
* X923 Final padding byte equals the padding length and all other padding bytes equal 0x00. Example: XX XX XX XX 00 00 00 04
* ISO7816 First padding byte equals 0x80 and all other padding bytes equal 0x00. Example: XX XX XX XX 80 00 00 00
* ISO9797\_1 Padding bytes are 0x00 if needed to fill block. Example: XX XX XX XX 00 00 00 00
* ISO9797\_2 First padding byte equals 0x80 and all other padding bytes equal 0x00. There must be at least one padding byte. Example: XX XX XX XX 80 00 00 00

Involved API functions:

* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - load an initial DUKPT key in a slot given by KeyAddressTable (see configuration) and the initial KSN (This function is not supported on Verix!)
* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) with key type KEY\_TYPE\_DELETE\_ALL\_CUST\_KEYS - special key type (replacement for iPS\_DeleteKey(DEL\_ALL)) is independent from host configuration and clears all OS-managed customer keys like VSS, IPP and ADE.
* [secEncryptData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#aa58bc1a6a2056aebd3edc92f3bfcce9d) - encrypt data
* [secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) - delivers a JSON-formatted list of injected keys per Key Set Id status of ADE engine (see section 'JSON-formatted outputs' below)

## Configuration in sccfg.json <a href="#autotoc_md71" id="autotoc_md71"></a>

Optional tags:

* encMode - possible values: 0 (= "MODE\_ECB"), 1 (= "MODE\_CBC")
* IVType - possible values: 0 (= "NOT\_USED"), 1 (= "ZERO"), 2 (= "RANDOM"), 3 (= "USER\_DEFINED")
* padding - possible values: 0 (= "NONE"), 1 (= "PKCS7"), 2 (= "X923"), 3 (= "ISO7816"), 4 (= "ISO9797\_1"), 5 (= "ISO9797\_2")
* KeyAddressTable - key slots can be assigned per function by setting a KeySetId

### Example for configuration <a href="#autotoc_md72" id="autotoc_md72"></a>

```cpp
{
  "name": "schemeADE",
  "settings": {
   "padding": "PKCS7",
   "encMode": "MODE_CBC",
   "IVType": "RANDOM",
   "KeyManagementType": "DUKPT",
   "KeyAddressTable": [
   {"description":"| 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | <- KeySetId (10 slots)"},
   {"encryptData": ["0", "1", "2", "3", "4", "5", "6", "7", "8", "9"]}
   ]
  }
}
```

## JSON formatted outputs <a href="#autotoc_md73" id="autotoc_md73"></a>

[secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) delivers a JSON formatted output string with information about keys related to an opened Security Module.

### Example: Output for a host using module ADE (conditioned output) <a href="#autotoc_md74" id="autotoc_md74"></a>

```cpp
{
   "Keys":[
   {
   "DUKPT":{
   "KSN":"FFFF9876543210E00001",
   "injected":"yes",
   "slot_id":0
   },
   "KeySet":1
   },
   {
   "DUKPT":{
   "KSN":"FFFF0013010000200005",
   "injected":"yes",
   "slot_id":1
   },
   "KeySet":2
   },
   {
   "DUKPT":{
   "KSN":"FFFF0013020000200002",
   "injected":"yes",
   "slot_id":2
   },
   "KeySet":3
   },
   {
   "DUKPT":{"injected":"no"},
   "KeySet":4
   },
   {
   "DUKPT":{"injected":"no"},
   "KeySet":5
   },
   {
   "DUKPT":{"injected":"no"},
   "KeySet":6
   },
   {
   "DUKPT":{"injected":"no"},
   "KeySet":7
   },
   {
   "DUKPT":{"injected":"no"},
   "KeySet":8
   },
   {
   "DUKPT":{"injected":"no"},
   "KeySet":9
   },
   {
   "DUKPT":{"injected":"no"},
   "KeySet":10
   }
   ],
   "Status":{
   "ADE active":"yes",
   "ADE enabled":"yes"
   }
}
```

## Security Module RSA <a href="#autotoc_md75" id="autotoc_md75"></a>

RSA is one of the first practical public-key crypto systems and is widely used for secure data transmission. In such a crypto system, the encryption key is public and differs from the decryption key which is kept secret.

Module is designed to work with two kind of keys, stored in system:

* RSA key is istalled in OS. It can be both Public and Private RSA key. E.g. AuthEx keys. All the keys can be used in crypto operations provided by ADK-SEC. The keys must be loaded only using OS functions like VRK.
* Certificate Tree + Working RSA keys stored in Certstore service. These RSA public key certificates can be loaded using ADK-SEC UpdateKey() in PEM format. A special key type KEY\_TYPE\_CERT must be used for Cert Tree installation. Loading/Update of Cert Tree occurs in PEM format that contains all certificates of the chain. Root Cert is mandatory.

Cert store is a service that:

* takes care about storing, validating the chain and protecting the root cert against updates using PEM file format
* support a new key type=KEY\_TYPE\_CERT that will allow to install/update intermediate certs via the already define APIs [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39)
* allow installation of X.509 public keys for the existing key types=Encrypt/Verify via the already define APIs [secSetKSId()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a75edecb24f839e04debb1aa5e47b5714), [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39)
* allow to reference the installed Public keys in existing [secEncryptData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#aa58bc1a6a2056aebd3edc92f3bfcce9d) and [secVerify()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a5470ce89fa947abc445f251ae0b2387b) commands

## Configuration <a href="#autotoc_md76" id="autotoc_md76"></a>

### Padding <a href="#autotoc_md77" id="autotoc_md77"></a>

* Required entry [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc)
* possible values are defined in [CFG\_TOKEN\_PAD\_NONE](#ga5c10532bcee038e5914f6373eacb46a0) [CFG\_TOKEN\_RSA\_PAD\_PKCS1](#gac8dcc08d9e286bac750fea9e93d7ad73) [CFG\_TOKEN\_RSA\_PAD\_PKCS1\_OAEP](#gaa4fb8e794160a33f923fe68ee7179bd3)

### hash type <a href="#autotoc_md78" id="autotoc_md78"></a>

* optional entry [CFG\_ENTRY\_HASHTYPE](#ga86a1b2813b9c5f7cf27242fdbf775439)
* effective for "sign" and "verify"
* possible values are defined in [CFG\_TOKEN\_HASHTYPE\_SHA1](#gadd90d36b31ab0a577378f7720c076439) [CFG\_TOKEN\_HASHTYPE\_SHA224](#ga898427bc525c8513e971d8198e8f43dd) [CFG\_TOKEN\_HASHTYPE\_SHA256](#gaba0922b0c5f4bb2f104d7dc3cd9affb2) [CFG\_TOKEN\_HASHTYPE\_SHA384](#gaaacb946c9029654216868f58fe3d4eae) [CFG\_TOKEN\_HASHTYPE\_SHA512](#ga0a15b7e427347133f38c9cd34a6441e3)
* default value: #CFG\_ENTRY\_RSA\_SHA256

### calcHash <a href="#autotoc_md79" id="autotoc_md79"></a>

* optional entry [CFG\_ENTRY\_RSA\_CALC\_HASH](#gad6cb616ebd3638d561f21650dc1466ad) - determines if a hash of the input data shall be calculated before performing the crypto operation
* effective for "sign" and "verify"
* possible values are defined in [CFG\_TOKEN\_RSA\_CALC\_HASH\_YES](#ga4b1f0e2242b9b4ecc89ee3bf6f548976) [CFG\_TOKEN\_RSA\_CALC\_HASH\_NO](#ga89545638866850d2cfaf499d4bbb2fb2)
* default value: [CFG\_TOKEN\_RSA\_CALC\_HASH\_YES](#ga4b1f0e2242b9b4ecc89ee3bf6f548976)

### secGetData format <a href="#autotoc_md80" id="autotoc_md80"></a>

* optional entry [CFG\_ENTRY\_RSA\_GETKD\_FORMAT](#ga336a59e27b41607b81eb15f34cac894a)
* effective for [secGetKeyData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#aff0a109c58ef5637c7bf3ffc0722c48d) command
* possible values are defined in [CFG\_TOKEN\_RSA\_GETKD\_PEM](#gadc53fdacbcb2c210a7672d3e9fea6e99) [CFG\_TOKEN\_RSA\_GETKD\_DER](#gaa7a16f0472b900b454c6969c7d8720ee) [CFG\_TOKEN\_RSA\_GETKD\_PRT](#gaeaf542d1a2dbd450b6aa81839df10200) [CFG\_TOKEN\_RSA\_GETKD\_ORG](#ga8573171ef0704459dbdcd91b363db091)
* default value: [CFG\_TOKEN\_RSA\_GETKD\_PRT](#gaeaf542d1a2dbd450b6aa81839df10200)

### KeyAddressTable <a href="#autotoc_md81" id="autotoc_md81"></a>

* Key-Slots are given as key-files relative to #RSA\_KEY\_PREFIX\_VOS resp. #RSA\_KEY\_PREFIX\_VOS, absolute path to the key file or "internal" for certstore usage. In case of "internal" the secUpdateKey can be used for certificate loading.
* For encrypt and verify this has to be a public key
* For decrypt and sign this has to be a private key, which is encrypted by vault-key

### example <a href="#autotoc_md82" id="autotoc_md82"></a>

```cpp
{
   "padding": "PKCS1",
   "hashType": "SHA256",
   "calcHash": "yes"
   "getKeyDataFormat": "PEM",
   "KeyAddressTable": [
   {"encryptData": ["rkeys/usr1/key0.crt"]},
   {"decryptData": ["rkeys/usr1/key0.der"]},
   {"sign": ["rkeys/usr1/key0.der"]},
   {"verify": ["rkeys/usr1/key0.crt"]}
   ]
}
```

## JSON formatted outputs <a href="#autotoc_md83" id="autotoc_md83"></a>

[secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) delivers a JSON formatted output string with information about keys related to an opened Security Module.

### Example: Output for a host using module RSA (conditioned output) <a href="#autotoc_md84" id="autotoc_md84"></a>

```cpp
{
   "Keys": [
   {
   "DDK": {
   "injected": "yes"
   },
   "DEK": {
   "info": {
   "key_id": 0,
   "status": 3,
   "ts": "20180110161432",
   "type": "R",
   "user_id": 1
   },
   "info_type": "RSA",
   "injected": "yes",
   "install_date": "12\/01\/2018 15:43:01",
   "name": "RSAOS10",
   "version": 1
   },
   "KeySet": 1,
   "MGK": {
   "injected": "yes"
   },
   "MVK": {
   "info": {
   "key_id": 0,
   "status": 3,
   "ts": "20180110161432",
   "type": "R",
   "user_id": 1
   },
   "info_type": "RSA",
   "injected": "yes",
   "install_date": "12\/01\/2018 15:43:01",
   "name": "RSAOS10",
   "version": 1
   }
   }
   ]
}
```

## Security Module SRED <a href="#autotoc_md85" id="autotoc_md85"></a>

Module SRED supports SRED MAC-ing and encryption using the MAC key variant and the same DUKPT future key as is used to encrypt.

Functionality of SRED module: THe SRED module provides following functionality:

* get status of module in a JSON formatted output string
* load a DUKPT initial key and initial KSN (optional - key loading is usually not done by ADK-SEC). This functionality is not supported on Verix!
* MAC generation/verification using ADE DUKPT keys

Involved API functions:

* [secSign()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a66a1992f617359f2e4a96f4980478f82)
* [secVerify()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a5470ce89fa947abc445f251ae0b2387b)

## Configuration in sccfg.json <a href="#autotoc_md86" id="autotoc_md86"></a>

Mandatory tags: none Optional tags:

* encMode MODE\_ECB - default value MODE\_CBC
* IVType NONE - default value ZERO RANDOM USER\_DEFINED
* keyVariant X924\_MAC\_REQ\_BW - default value X924\_MAC\_RESP X924\_DE\_REQ\_BW
* algo DES112 ALG\_9797\_MAC\_1 K is a single length key (K1) - default value

  ALG\_9797\_MAC\_1A K is a double length key (K1 and K2) ALG\_9797\_MAC\_2 K1 is a single length key (K1) K2 is a single length key (K2) ALG\_9797\_MAC\_3 K1 is a single length key (K1) K2 is a single length key (K2) ALG\_9797\_MAC\_4 K is a single length key (K1) K1 is a single length key (K1 XOR 0xF0F0F0F0F0F0F0F0) K2 is a single length key (K2) ALG\_9797\_MAC\_5 K1 is a single length key (K1) K2 is a single length key (K1 XOR 0xF0F0F0F0F0F0F0F0) ALG\_9797\_MAC\_5A K1 is a double length key (K1 and K2) K2 is a double length key (K1 XOR 0xF0F0F0F0F0F0F0F0) (K2 XOR 0xF0F0F0F0F0F0F0F0) ALG\_CMAC\_TDEA ALG\_HMAC\_SHA256
* padding NONE - default value PKCS7 Each padding byte equals the padding length. Example: XX XX XX XX 04 04 04 04 X923 Final padding byte equals the padding length and all other padding bytes equal 0x00. Example: XX XX XX XX 00 00 00 04 ISO7816 First padding byte equals 0x80 and all other padding bytes equal 0x00. Example: XX XX XX XX 80 00 00 00 ISO9797\_1 Padding bytes are 0x00 if needed to fill block. Example: XX XX XX XX 00 00 00 00 ISO9797\_2 First padding byte equals 0x80 and all other padding bytes equal 0x00. There must be at least one padding byte. Example: XX XX XX XX 80 00 00 00 \* \* - PKCS7
* KeyAddressTable - key slots can be assigned per function by setting a KeySetId

### Example for configuration <a href="#autotoc_md87" id="autotoc_md87"></a>

```cpp
{
  "name": "schemeSREDMAC",
  "settings": {
   "padding": "NONE",
   "IVType": "ZERO",
   "encMode": "MODE_ECB",
   "algo": "ALG_9797_MAC_1A"
   "KSNincrementation": "BY_OPERATION",
   "KeyManagementType": "DUKPT",
   "KeyAddressTable": [
   {"description": "| 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | <- KeySetId (10 slots)"},
   {"sign": ["0", "1", "2", "3", "4", "5", "6", "7", "8", "9"]},
   {"verify": ["0", "1", "2", "3", "4", "5", "6", "7", "8", "9"]}
   }
  }
}
```

## Security Module VisaDSP <a href="#autotoc_md88" id="autotoc_md88"></a>

VisaDSP provides two methods of Point-to-Point-Encryption for the following card data types: PAN, Cardholder Name, Track1, Track2. The two methods are:

* Standard Point-to-Point Encryption (P2PE)
* Format-Preserving Encryption (FPE)

Both methods use the same keys and the DES IPP-DUKPT or optional the ADE DUKPT key management scheme. Additionally to encryption the original card data are obfuscated if P2PE is used.

Functionality of module VisaDSP:

* handling of configuration data (key management type, encryption algorithm, ...)
* loading a DUKPT initial key and initial KSN (optional - key loading is not the task of ADK-SEC)
* handling of options and card data provided by TD (Transaction Data)
* encryption of card data of each type according to the configured encryption algorithm (data variant of the key is used)
* obfuscating card data in case of P2PE
* retrieving an encrypted PIN block (PIN variant of the key is used). This this possible only if IPP DUKPT key management scheme is used. Remark: PIN entry is not the task of ADK-SEC.
* delivering of information about keys (related to an opened Security Module)

Involved API functions:

* [secUpdateKey()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab249c77069e9fc9946745fd4c63d5e39) - load an initial DUKPT key and the initial KSN
* [secPutTransactionData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a6bc0d39e1739680282d33d3d68df84c9) - put options and card data to TD
* [secEncryptTransactionData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#aaed6fc175245ba31936547cffd988948) - perform a card data encryption (P2PE or FPE) and a card data obfuscation in case of P2PE
* [secGetTransactionValue()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a85ada2e35c1d1cbf60c05454b88b4b44) - get obfuscated card data if P2PE was used
* [secRetrieveEncryptedPIN()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab3d26136c64019fd223aa9ccd120d4e0) - retrieve encrypted PIN block
* [secClearTransactionData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ac31ab997e8dc434d72e427a5d841186a) - clear card data in TD
* [secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) - delivers a JSON-formatted list of injected keys per Key Set Id (see section 'JSON-formatted outputs' below)

### Example for getting obfuscated data <a href="#autotoc_md89" id="autotoc_md89"></a>

```cpp
{
  secError errCode = EsecOK;
  SecTransactionValue transDataOut;
  std::string obfCardDataType = CTransactionData::TagObfuscatedPAN;
  if ((errCode = secGetTransactionValue(handle, obfCardDataType, transDataOut)) != EsecOK)
  return ((int)errCode);
  std::vector<uint8_t> outData = transDataOut.getRaw();
}
```

## Configuration in sccfg.json <a href="#autotoc_md90" id="autotoc_md90"></a>

Mandatory tags:

* "module": "VisaDSP"
* "encryptionAlgo" - possible values: "P2PE" or "FPE"
* "KeyManagementOption" - in case of DUKPT IPP key management type
* "KeyAddressTable" - list Key Address Table of involved functions (key slots can be selected by setting Key Set Ids)

Optional tags:

* "permissions" - access rights for card data types (e.g.: 1=writable only)

### Example for configuration <a href="#autotoc_md91" id="autotoc_md91"></a>

```cpp
{
  "secSchemes": [
  {
   "name": "schemeVisaDSP",
   "settings": {
   "encryptionAlgo": "P2PE"
   }
  }
  . . .
  "hosts": [
  {
   "name": "VisaDSP_FPE_Host",
   "description": "IPP-DUKPT usage",
   "scheme": "schemeVisaDSP",
   "module": "VisaDSP",
   "settings": {
   "encryptionAlgo": "FPE",
   "KeyManagementOption": "0A3",
   "KeyAddressTable": [
   {"description": "| 1 | 2 | 3 | <- KeySetId (3 slots)"},
   {"updateKey": ["0", "1", "2"]},
   {"encryptData": ["0", "1", "2"]},
   {"retrieveEncPIN": ["0", "1", "2"]}
   ]
   },
   "permissions": {
   "TagPAN": 1,
   "TagCHName": 1,
   "TagTrack1": 1,
   "TagTrack2": 1
   }
  }
  . . .
}
```

## JSON formatted outputs <a href="#autotoc_md92" id="autotoc_md92"></a>

[secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) delivers a JSON formatted output string with information about keys related to an opened Security Module.

### Example: Output for a host using module VisaDSP (conditioned output) <a href="#autotoc_md93" id="autotoc_md93"></a>

```cpp
{
   "Keys":[
   {
   "DUKPT":{
   "KSN":"AFEECABC871200000003",
   "injected":"yes",
   "slot_id":0
   },
   "KeySet":1
   },
   {
   "DUKPT":{
   "KSN":"AFEECABC871200000003",
   "injected":"yes",
   "slot_id":1
   },
   "KeySet":2
   },
   {
   "DUKPT":{
   "KSN":"736081210E000004",
   "injected":"yes",
   "slot_id":2
   },
   "KeySet":3
   }
   ]
}
```

## Security Module CryptoRW <a href="#autotoc_md94" id="autotoc_md94"></a>

CryptoRW module is a replacement for deprecated OS function cryptoRead / cryptoWrite()

Use the Data Encryption feature to guarantee that the content is lost if the unit is tampered with. The data is encrypted with a key derived from the top-level key erased from the terminal in case of attack, making it impossible to recover the plain text data. The key is unique for each terminal and is not known outside the cryptographic unit of the terminal. This feature can be used, for instance, when tamper detection must cause the deletion of the transaction batch file.

In contrast to the deprecated cryptoRead() / cryptoWrite() APIs, the CryptoRW module will not work on file handles and only be used to encrypt or decrypt data with a terminal individual key.

### Functionality of CryptoRW module <a href="#autotoc_md95" id="autotoc_md95"></a>

The CryptoRW module provides following functionality:

* encrypt data - encrypts the input data with the terminal individual key.
* decrypt data - decrypts the input data with the terminal individual key. Encrypted data can be in old (legacy) or new format. Decryption will be done according host configuation flag "legacy\_decrypt" described below.
* get status of engine and CryptoRW module in a JSON formatted output string

Please be aware that the data encryption of this module will use a different format, then used with the deprecated cryptoRead() / cryptoWrite() APIs. For compatibility and migration of data stored in old format, the decrypt functionality can be configured to use the old (deprecated) or the new format (default), but data encryption always uses the new format, independent of the configuration.

The decrypt mode can be configured the following ways:

* host/schema configuration settings entry "legacy\_decrypt" : true/false (default value "false" if entry is not exists)
* transaction data entry td\[[CTransactionData::TagCryptoRWLegacyDecrypt](https://github.com/verifoneone/verifone-git-book-adk/tree/ADK5.0_staging/classcom__adksec__cmd_1_1_c_transaction_data.md#ab5aff0278f7b0482a946cf9008dacb7d)] = true/false (default value "false" if the tag is not exists)

If application does not need to decrypt files encrypted with old interface, please use in general "legacy\_decrypt" : false. Data encryption occurs only in new format.

Involved API functions:

* [secEncryptData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#aa58bc1a6a2056aebd3edc92f3bfcce9d) - encrypt data. Please note, that encrypted data are longer than input data due to some internal formatting during encryption.
* [secDecryptData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a9cd679dc9763b06566dff28b3d3268c9) - decrypt data. Decrypted data do not contain any internal formatting.

## Configuration in sccfg.json <a href="#autotoc_md96" id="autotoc_md96"></a>

Optional tags:

* legacy\_decrypt - possible values: true (= use legacy decryption), false (= data are in new format, default value)

### Example for configuration <a href="#autotoc_md97" id="autotoc_md97"></a>

```cpp
{
  "adksecconfig": {
   "serviceCfg":
   {
   "secSchemes": [
   {
   "name": "schemeCryptoReadWrite",
   "settings": {
   "legacy_decrypt": false
   }
   }
   ]
   }
   "hosts": [
   {
   "name": "hostSafeData",
   "scheme": "schemeCryptoReadWrite",
   "module": "CryptoRW"
   }
   ]
  }
}
```

### Example of usage <a href="#autotoc_md98" id="autotoc_md98"></a>

```cpp
{
   secHandle_t hdl = 0;
   std::vector<uint8_t> plainData;
   std::vector<uint8_t> encData;
   std::vector<uint8_t> decryptedData;
   std::vector<uint8_t> vdummy;
   secError reterr = EsecOK;
   secOpen("hostSafeData", hdl);
   plainData.clear();
   secGenerateRandom(plainData, 77 ); // 77 byte of data to be encrypted. It can be data from file
   reterr = secEncryptData(hdl, plainData, encData, vdummy, vdummy);
   if (EsecNotSupportedModule == reterr)
   {
   LOG("Skip test due to not supported OS functionality");
   secClose(hdl);
   return;
   }
   if (plainData.size()+64 != encData.size()) // header to protect encrypted data
   {
   // error handling
   }
   secDecryptData(hdl, encData, decryptedData, vdummy, vdummy));
   SEC_DBG_HEXDUMP_TRACE("plain data", plainData.data(), plainData.size());
   SEC_DBG_HEXDUMP_TRACE("encrypted data", encData.data(), encData.size());
   SEC_DBG_HEXDUMP_TRACE("decrypted data", decryptedData.data(), decryptedData.size());
   if (plainData.size() != decryptedData.size())
   {
   // error handling
   }
   secClose(hdl);
}
```

## Security Module AES <a href="#autotoc_md99" id="autotoc_md99"></a>

AES is a specification for the encryption of electronic data. The algorithm described by AES is a symmetric-key algorithm, meaning the same key is used for both encrypting and decrypting the data. It is a variant of Rijndael which has a fixed block size of 128 bits, and a key size of 128, 192, or 256 bits. By contrast, the Rijndael specification per se is specified with block and key sizes that may be any multiple of 32 bits, both with a minimum of 128 and a maximum of 256 bits.

The Security AES Module uses the AES DUKPT algorithm. Transaction key(s) of 128, 192 or 256 bit length are derived from an Initial Terminal DUKPT Key of the corresponding length based on a transaction number. A transaction number consists of an Initial Key-ID and the Transaction Counter. The Initial Key and Initial Key-ID is injected via VRK or VTM.

### Functionality of AES module <a href="#autotoc_md100" id="autotoc_md100"></a>

The AES module provides following functionality:

* CMAC calculation and verifying of data
* data encryption and decryption
* retrieval of an encrypted PIN block
* key inventory information in a JSON formatted output string

Involved API functions:

* [secSign()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a66a1992f617359f2e4a96f4980478f82) - generation CMAC
* [secVerify()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a5470ce89fa947abc445f251ae0b2387b) - verifying CMAC
* [secEncryptData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#aa58bc1a6a2056aebd3edc92f3bfcce9d) - encrypt data
* [secDecryptData()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a9cd679dc9763b06566dff28b3d3268c9) - decrypt data
* [secRetrieveEncryptedPIN()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#ab3d26136c64019fd223aa9ccd120d4e0) - retrieve the encrypted PIN block of a entered PIN
* [secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) - delivers status information about injected keys

## Configuration <a href="#autotoc_md101" id="autotoc_md101"></a>

### algorithm method <a href="#autotoc_md102" id="autotoc_md102"></a>

* Required entry #CFG\_ENTRY\_ALG
* possible values are defined in [CFG\_TOKEN\_ALGO\_CMAC](#gaf79405974fcfbba042ef5c2cb40e08a7)

### encryption mode <a href="#autotoc_md103" id="autotoc_md103"></a>

* required entry #CFG\_ENTRY\_AES\_ENCMODE
* possible values are defined in #CFG\_ENTRY\_AES\_MODE\_ECB, #CFG\_ENTRY\_AES\_MODE\_CBC
* default value is #CFG\_ENTRY\_AES\_MODE\_ECB

### padding <a href="#autotoc_md104" id="autotoc_md104"></a>

* Required entry #CFG\_ENTRY\_AES\_PAD
* possible values are defined in #CFG\_ENTRY\_AES\_PAD\_NONE, #CFG\_ENTRY\_AES\_PAD\_PKCS7
* default value is #CFG\_ENTRY\_AES\_PAD\_PKCS7

### KeyAddressTable <a href="#autotoc_md105" id="autotoc_md105"></a>

* Key files relative to #AES\_KEY\_PREFIX\_VOS resp. #AES\_KEY\_PREFIX\_VRX can be assigned per function by setting a KeySetId

### Example for configuration <a href="#autotoc_md106" id="autotoc_md106"></a>

```cpp
{
   "name": "schemeAESDUKPT",
   "settings": {
   "algo": "CMAC",
   "encMode": "MODE_CBC",
   "padding": "NONE",
   "KeyAddressTable": [
   {"sign": ["generickeys/usr1/key2.ses"]},
   {"verify": ["generickeys/usr1/key2.ses"]},
   {"encryptData": ["generickeys/usr1/key2.ses"]},
   {"decryptData": ["generickeys/usr1/key2.ses"]},
   {"retrieveEncPIN": ["generickeys/usr1/key2.ses"]}
   ]
   }
}
```

## JSON formatted outputs <a href="#autotoc_md107" id="autotoc_md107"></a>

[secGetKeyInventory()](/adk-5.0-programmers-guide/readme/modules/group__com__verifone__seccmd/namespacecom__verifone__seccmd.md#a79b00ea8a8aed3b7950800bf136a1944) delivers a JSON formatted output string with information about keys related to an opened Security Module.

### Example: Output for a host using module AES (conditioned output) <a href="#autotoc_md108" id="autotoc_md108"></a>

```cpp
{
   "Keys": [
   {
   "DDK": {
   "KSN": "123456789012345600000003",
   "KeyType": "aesdukpt192",
   "injected": "yes"
   },
   "DEK": {
   "KSN": "123456789012345600000002",
   "KeyType": "aesdukpt192",
   "injected": "yes"
   },
   "KeySet": 1,
   "MGK": {
   "KSN": "123456789012345600000004",
   "KeyType": "aesdukpt256",
   "injected": "yes"
   },
   "MVK": {
   "KSN": "123456789012345600000005",
   "KeyType": "aesdukpt256",
   "injected": "yes"
   },
   "PPK": {
   "KSN": "123456789012345600000002",
   "KeyType": "aesdukpt128",
   "injected": "yes"
   }
   },
   {
   "DDK": {
   "KSN": "123456789012345600000004",
   "KeyType": "aesdukpt128",
   "injected": "yes"
   },
   "DEK": {
   "KSN": "123456789012345600000003",
   "KeyType": "aesdukpt128",
   "injected": "yes"
   },
   "KeySet": 2,
   "MGK": {
   "injected": "no"
   },
   "MVK": {
   "injected": "no"
   },
   "PPK": {
   "injected": "no"
   }
   },
   {
   "DDK": {
   "KSN": "123456789012345600000007",
   "KeyType": "aesdukpt256",
   "injected": "yes"
   },
   "DEK": {
   "KSN": "123456789012345600000006",
   "KeyType": "aesdukpt256",
   "injected": "yes"
   },
   "KeySet": 3,
   "MGK": {
   "injected": "no"
   },
   "MVK": {
   "injected": "no"
   },
   "PPK": {
   "injected": "no"
   }
   }
   ]
}
```

### MacroDefinition Documentation <a href="#macro-definition-documentation" id="macro-definition-documentation"></a>

### CFG\_ENTRY\_ALGO <a href="#gab479d306344dff2934da238f5e2c48c6" id="gab479d306344dff2934da238f5e2c48c6"></a>

\#define CFG\_ENTRY\_ALGO   \\"algo\\"

### CFG\_ENTRY\_DUKPT\_INC\_KSN <a href="#ga86878ef55c861a78b3c0240703d1bedb" id="ga86878ef55c861a78b3c0240703d1bedb"></a>

\#define CFG\_ENTRY\_DUKPT\_INC\_KSN   \\"KSNincrementation\\"

### CFG\_ENTRY\_DUKPT\_KEY\_VARIANT <a href="#ga053f55fa711f0286d30aa4e79207aa6d" id="ga053f55fa711f0286d30aa4e79207aa6d"></a>

\#define CFG\_ENTRY\_DUKPT\_KEY\_VARIANT   \\"keyVariant\\"

### CFG\_ENTRY\_ENCMODE <a href="#ga946270505efb931b3211312afa8d492c" id="ga946270505efb931b3211312afa8d492c"></a>

\#define CFG\_ENTRY\_ENCMODE   \\"encMode\\"

### CFG\_ENTRY\_HASHTYPE <a href="#ga86a1b2813b9c5f7cf27242fdbf775439" id="ga86a1b2813b9c5f7cf27242fdbf775439"></a>

\#define CFG\_ENTRY\_HASHTYPE   \\"hashType\\"

### CFG\_ENTRY\_IPP\_KEY\_MANAGEMENT <a href="#ga9b4a8d263360a9fc49e056cd459c65b0" id="ga9b4a8d263360a9fc49e056cd459c65b0"></a>

\#define CFG\_ENTRY\_IPP\_KEY\_MANAGEMENT   \\"KeyManagementOption\\"

### CFG\_ENTRY\_IV <a href="#gab60d01dead9ae5dd41d7a0c50e37e231" id="gab60d01dead9ae5dd41d7a0c50e37e231"></a>

\#define CFG\_ENTRY\_IV   \\"IVType\\"

### CFG\_ENTRY\_KEY\_MANAGEMENT\_TYPE <a href="#gace84acf3acd2546983b0ac7f34bccd82" id="gace84acf3acd2546983b0ac7f34bccd82"></a>

\#define CFG\_ENTRY\_KEY\_MANAGEMENT\_TYPE   \\"KeyManagementType\\"

### CFG\_ENTRY\_PADDING <a href="#gafe03108f84657a93a3f7e1a52feb53bc" id="gafe03108f84657a93a3f7e1a52feb53bc"></a>

\#define CFG\_ENTRY\_PADDING   \\"padding\\"

### CFG\_ENTRY\_RSA\_CALC\_HASH <a href="#gad6cb616ebd3638d561f21650dc1466ad" id="gad6cb616ebd3638d561f21650dc1466ad"></a>

\#define CFG\_ENTRY\_RSA\_CALC\_HASH   \\"calcHash\\"

### CFG\_ENTRY\_RSA\_GETKD\_FORMAT <a href="#ga336a59e27b41607b81eb15f34cac894a" id="ga336a59e27b41607b81eb15f34cac894a"></a>

\#define CFG\_ENTRY\_RSA\_GETKD\_FORMAT   \\"getKeyDataFormat\\"

### CFG\_ENTRY\_TRANSPORT\_KEY <a href="#ga89cd282e773cd9be0282720efb9bae94" id="ga89cd282e773cd9be0282720efb9bae94"></a>

\#define CFG\_ENTRY\_TRANSPORT\_KEY   \\"transportKey\\"

### CFG\_TOKEN\_ALGO\_CMAC <a href="#gaf79405974fcfbba042ef5c2cb40e08a7" id="gaf79405974fcfbba042ef5c2cb40e08a7"></a>

\#define CFG\_TOKEN\_ALGO\_CMAC   \\"CMAC\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6)

### CFG\_TOKEN\_ALGO\_HMAC <a href="#ga7e7c533e64c60c460623099a271839e6" id="ga7e7c533e64c60c460623099a271839e6"></a>

\#define CFG\_TOKEN\_ALGO\_HMAC   \\"HMAC\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6)

### CFG\_TOKEN\_DUKPT\_BY\_API <a href="#gad3b7e6d29779eee52566da614317208b" id="gad3b7e6d29779eee52566da614317208b"></a>

\#define CFG\_TOKEN\_DUKPT\_BY\_API   \\"BY\_API\\"

value of [CFG\_ENTRY\_DUKPT\_INC\_KSN](#ga86878ef55c861a78b3c0240703d1bedb)

### CFG\_TOKEN\_DUKPT\_BY\_OPERATION <a href="#ga1038e59d5a70ded57d6fa4d4828a5d00" id="ga1038e59d5a70ded57d6fa4d4828a5d00"></a>

\#define CFG\_TOKEN\_DUKPT\_BY\_OPERATION   \\"BY\_OPERATION\\"

value of [CFG\_ENTRY\_DUKPT\_INC\_KSN](#ga86878ef55c861a78b3c0240703d1bedb) default value

### CFG\_TOKEN\_DUKPT\_KEY\_VAR\_BOTH <a href="#ga397a6f6091a11718ed25027c3e41d92d" id="ga397a6f6091a11718ed25027c3e41d92d"></a>

\#define CFG\_TOKEN\_DUKPT\_KEY\_VAR\_BOTH   \\"both\\"

value of [CFG\_ENTRY\_DUKPT\_KEY\_VARIANT](#ga053f55fa711f0286d30aa4e79207aa6d). In case of AES DUKPT - Data Encryption Both Ways / Message Authentication Both Ways

### CFG\_TOKEN\_DUKPT\_KEY\_VAR\_REQUEST <a href="#ga6727ebc5a0cda870745972d4b55ab71c" id="ga6727ebc5a0cda870745972d4b55ab71c"></a>

\#define CFG\_TOKEN\_DUKPT\_KEY\_VAR\_REQUEST   \\"request\\"

value of [CFG\_ENTRY\_DUKPT\_KEY\_VARIANT](#ga053f55fa711f0286d30aa4e79207aa6d), default value. In case of AES DUKPT - Data Encryption Encrypt / Message Authentication Generation

### CFG\_TOKEN\_DUKPT\_KEY\_VAR\_RESPONSE <a href="#ga34c5fb6b1b6b58c4d6a51f2da208479b" id="ga34c5fb6b1b6b58c4d6a51f2da208479b"></a>

\#define CFG\_TOKEN\_DUKPT\_KEY\_VAR\_RESPONSE   \\"response\\"

value of [CFG\_ENTRY\_DUKPT\_KEY\_VARIANT](#ga053f55fa711f0286d30aa4e79207aa6d). In case of AES DUKPT - Data Encryption Decrypt / Message Authentication Verification

### CFG\_TOKEN\_ENCMODE\_CBC <a href="#gaebf52c0f1820c19768a164f88a27bc94" id="gaebf52c0f1820c19768a164f88a27bc94"></a>

\#define CFG\_TOKEN\_ENCMODE\_CBC   \\"MODE\_CBC\\"

value of CFG\_ENTRY\_ENCMODE

### CFG\_TOKEN\_ENCMODE\_ECB <a href="#gafd97668a7484ce5224a24c3c7a657b08" id="gafd97668a7484ce5224a24c3c7a657b08"></a>

\#define CFG\_TOKEN\_ENCMODE\_ECB   \\"MODE\_ECB\\"

value of CFG\_ENTRY\_ENCMODE, default value

### CFG\_TOKEN\_HASHTYPE\_SHA1 <a href="#gadd90d36b31ab0a577378f7720c076439" id="gadd90d36b31ab0a577378f7720c076439"></a>

\#define CFG\_TOKEN\_HASHTYPE\_SHA1   \\"SHA1\\"

value of CFG\_ENTRY\_HASHTYPE

### CFG\_TOKEN\_HASHTYPE\_SHA224 <a href="#ga898427bc525c8513e971d8198e8f43dd" id="ga898427bc525c8513e971d8198e8f43dd"></a>

\#define CFG\_TOKEN\_HASHTYPE\_SHA224   \\"SHA224\\"

value of CFG\_ENTRY\_HASHTYPE

### CFG\_TOKEN\_HASHTYPE\_SHA256 <a href="#gaba0922b0c5f4bb2f104d7dc3cd9affb2" id="gaba0922b0c5f4bb2f104d7dc3cd9affb2"></a>

\#define CFG\_TOKEN\_HASHTYPE\_SHA256   \\"SHA256\\"

value of CFG\_ENTRY\_HASHTYPE, default value in AES module

### CFG\_TOKEN\_HASHTYPE\_SHA384 <a href="#gaaacb946c9029654216868f58fe3d4eae" id="gaaacb946c9029654216868f58fe3d4eae"></a>

\#define CFG\_TOKEN\_HASHTYPE\_SHA384   \\"SHA384\\"

value of CFG\_ENTRY\_HASHTYPE

### CFG\_TOKEN\_HASHTYPE\_SHA512 <a href="#ga0a15b7e427347133f38c9cd34a6441e3" id="ga0a15b7e427347133f38c9cd34a6441e3"></a>

\#define CFG\_TOKEN\_HASHTYPE\_SHA512   \\"SHA512\\"

value of CFG\_ENTRY\_HASHTYPE

### CFG\_TOKEN\_IV\_NONE <a href="#ga82bfec8916794526f55f323be2384cc9" id="ga82bfec8916794526f55f323be2384cc9"></a>

\#define CFG\_TOKEN\_IV\_NONE   \\"NONE\\"

value of CFG\_ENTRY\_IV default value

### CFG\_TOKEN\_IV\_RAND <a href="#ga1963b2d020f256b2bc8f686e8d79c878" id="ga1963b2d020f256b2bc8f686e8d79c878"></a>

\#define CFG\_TOKEN\_IV\_RAND   \\"RANDOM\\"

value of CFG\_ENTRY\_IV

### CFG\_TOKEN\_IV\_USE\_INPUT <a href="#gaa3f2a7cd9700eb6e094c491cba90f44b" id="gaa3f2a7cd9700eb6e094c491cba90f44b"></a>

\#define CFG\_TOKEN\_IV\_USE\_INPUT   \\"USER\_DEFINED\\"

value of CFG\_ENTRY\_IV

### CFG\_TOKEN\_IV\_ZERO <a href="#ga40452c6a4635fa88638d637ffd08852e" id="ga40452c6a4635fa88638d637ffd08852e"></a>

\#define CFG\_TOKEN\_IV\_ZERO   \\"ZERO\\"

value of CFG\_ENTRY\_IV

### CFG\_TOKEN\_KEY\_MAN\_TYPE\_AS2805 <a href="#ga24851e60ec98ee64e15d7d019a561c5e" id="ga24851e60ec98ee64e15d7d019a561c5e"></a>

\#define CFG\_TOKEN\_KEY\_MAN\_TYPE\_AS2805   \\"AS2805\\"

value of CFG\_ENTRY\_KEY\_MANAGEMENT\_TYPE

### CFG\_TOKEN\_KEY\_MAN\_TYPE\_DUKPT <a href="#gac61a347bdf88553e6014655dcf50cd96" id="gac61a347bdf88553e6014655dcf50cd96"></a>

\#define CFG\_TOKEN\_KEY\_MAN\_TYPE\_DUKPT   \\"DUKPT\\"

value of CFG\_ENTRY\_KEY\_MANAGEMENT\_TYPE

### CFG\_TOKEN\_KEY\_MAN\_TYPE\_MSK <a href="#ga6cc85bd481d0e2068105c2ab52ed1c3c" id="ga6cc85bd481d0e2068105c2ab52ed1c3c"></a>

\#define CFG\_TOKEN\_KEY\_MAN\_TYPE\_MSK   \\"MSK\\"

value of CFG\_ENTRY\_KEY\_MANAGEMENT\_TYPE

### CFG\_TOKEN\_PAD\_FF <a href="#ga0f0e7c3801fb3b722d4bf3e42743250d" id="ga0f0e7c3801fb3b722d4bf3e42743250d"></a>

\#define CFG\_TOKEN\_PAD\_FF   \\"FF\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc)

### CFG\_TOKEN\_PAD\_ISO10126 <a href="#gae7322759618c7331c57ddd6e1f3c88a2" id="gae7322759618c7331c57ddd6e1f3c88a2"></a>

\#define CFG\_TOKEN\_PAD\_ISO10126   \\"ISO10126\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc)

### CFG\_TOKEN\_PAD\_ISO7816 <a href="#gac1440351c36ae311ae5268468a6f0da8" id="gac1440351c36ae311ae5268468a6f0da8"></a>

\#define CFG\_TOKEN\_PAD\_ISO7816   \\"ISO7816\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc)

### CFG\_TOKEN\_PAD\_ISO9797\_1 <a href="#ga9d966f4258d3169c123770080d65e5ba" id="ga9d966f4258d3169c123770080d65e5ba"></a>

\#define CFG\_TOKEN\_PAD\_ISO9797\_1   \\"ISO9797\_1\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc), ADE/SRED specific padding

### CFG\_TOKEN\_PAD\_ISO9797\_2 <a href="#gabada9ee23745697d8202500d8086b102" id="gabada9ee23745697d8202500d8086b102"></a>

\#define CFG\_TOKEN\_PAD\_ISO9797\_2   \\"ISO9797\_2\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc), ADE/SRED specific padding

### CFG\_TOKEN\_PAD\_NONE <a href="#ga5c10532bcee038e5914f6373eacb46a0" id="ga5c10532bcee038e5914f6373eacb46a0"></a>

\#define CFG\_TOKEN\_PAD\_NONE   \\"NONE\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc), default value

### CFG\_TOKEN\_PAD\_PKCS7 <a href="#gade87be513aa2c1a1a5b5271f78147533" id="gade87be513aa2c1a1a5b5271f78147533"></a>

\#define CFG\_TOKEN\_PAD\_PKCS7   \\"PKCS7\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc)

### CFG\_TOKEN\_PAD\_SPACE <a href="#ga27203e3e9c85b785354155336c7cb83b" id="ga27203e3e9c85b785354155336c7cb83b"></a>

\#define CFG\_TOKEN\_PAD\_SPACE   \\"SPACE\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc)

### CFG\_TOKEN\_PAD\_X923 <a href="#ga48e6b29ddaa97bbbd1d270f6c2a0da12" id="ga48e6b29ddaa97bbbd1d270f6c2a0da12"></a>

\#define CFG\_TOKEN\_PAD\_X923   \\"X923\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc)

### CFG\_TOKEN\_PAD\_ZERO <a href="#gaf95a5567d68b9d300baef8e27a741f8d" id="gaf95a5567d68b9d300baef8e27a741f8d"></a>

\#define CFG\_TOKEN\_PAD\_ZERO   \\"ZERO\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc)

### CFG\_TOKEN\_RSA\_CALC\_HASH\_NO <a href="#ga89545638866850d2cfaf499d4bbb2fb2" id="ga89545638866850d2cfaf499d4bbb2fb2"></a>

\#define CFG\_TOKEN\_RSA\_CALC\_HASH\_NO   \\"no\\"

value of [CFG\_ENTRY\_RSA\_CALC\_HASH](#gad6cb616ebd3638d561f21650dc1466ad)

### CFG\_TOKEN\_RSA\_CALC\_HASH\_YES <a href="#ga4b1f0e2242b9b4ecc89ee3bf6f548976" id="ga4b1f0e2242b9b4ecc89ee3bf6f548976"></a>

\#define CFG\_TOKEN\_RSA\_CALC\_HASH\_YES   \\"yes\\"

value of [CFG\_ENTRY\_RSA\_CALC\_HASH](#gad6cb616ebd3638d561f21650dc1466ad), default value

### CFG\_TOKEN\_RSA\_GETKD\_DER <a href="#gaa7a16f0472b900b454c6969c7d8720ee" id="gaa7a16f0472b900b454c6969c7d8720ee"></a>

\#define CFG\_TOKEN\_RSA\_GETKD\_DER   \\"DER\\"

value of [CFG\_ENTRY\_RSA\_GETKD\_FORMAT](#ga336a59e27b41607b81eb15f34cac894a)

### CFG\_TOKEN\_RSA\_GETKD\_ORG <a href="#ga8573171ef0704459dbdcd91b363db091" id="ga8573171ef0704459dbdcd91b363db091"></a>

\#define CFG\_TOKEN\_RSA\_GETKD\_ORG   \\"ORIGINAL\\"

value of [CFG\_ENTRY\_RSA\_GETKD\_FORMAT](#ga336a59e27b41607b81eb15f34cac894a)

### CFG\_TOKEN\_RSA\_GETKD\_PEM <a href="#gadc53fdacbcb2c210a7672d3e9fea6e99" id="gadc53fdacbcb2c210a7672d3e9fea6e99"></a>

\#define CFG\_TOKEN\_RSA\_GETKD\_PEM   \\"PEM\\"

value of [CFG\_ENTRY\_RSA\_GETKD\_FORMAT](#ga336a59e27b41607b81eb15f34cac894a)

### CFG\_TOKEN\_RSA\_GETKD\_PRT <a href="#gaeaf542d1a2dbd450b6aa81839df10200" id="gaeaf542d1a2dbd450b6aa81839df10200"></a>

\#define CFG\_TOKEN\_RSA\_GETKD\_PRT   \\"PRINT\\"

value of [CFG\_ENTRY\_RSA\_GETKD\_FORMAT](#ga336a59e27b41607b81eb15f34cac894a), default value

### CFG\_TOKEN\_RSA\_PAD\_PKCS1 <a href="#gac8dcc08d9e286bac750fea9e93d7ad73" id="gac8dcc08d9e286bac750fea9e93d7ad73"></a>

\#define CFG\_TOKEN\_RSA\_PAD\_PKCS1   \\"PKCS1\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc), RSA specific padding

### CFG\_TOKEN\_RSA\_PAD\_PKCS1\_OAEP <a href="#gaa4fb8e794160a33f923fe68ee7179bd3" id="gaa4fb8e794160a33f923fe68ee7179bd3"></a>

\#define CFG\_TOKEN\_RSA\_PAD\_PKCS1\_OAEP   \\"PKCS1\_OAEP\\"

value of [CFG\_ENTRY\_PADDING](#gafe03108f84657a93a3f7e1a52feb53bc), RSA specific padding

### CFG\_TOKEN\_SRED\_ALG\_1 <a href="#gafdd390e0c15cdc2eed87ca316d3bbb74" id="gafdd390e0c15cdc2eed87ca316d3bbb74"></a>

\#define CFG\_TOKEN\_SRED\_ALG\_1   \\"ALG\_9797\_MAC\_1\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6), default value. SRED specific padding. No default value for AES module

### CFG\_TOKEN\_SRED\_ALG\_1A <a href="#ga00432754611bf9d4d68928f46aacf7e1" id="ga00432754611bf9d4d68928f46aacf7e1"></a>

\#define CFG\_TOKEN\_SRED\_ALG\_1A   \\"ALG\_9797\_MAC\_1A\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6), SRED specific padding

### CFG\_TOKEN\_SRED\_ALG\_2 <a href="#ga8c9674a4e3e987b05f9faa0d5e545833" id="ga8c9674a4e3e987b05f9faa0d5e545833"></a>

\#define CFG\_TOKEN\_SRED\_ALG\_2   \\"ALG\_9797\_MAC\_2\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6), SRED specific padding

### CFG\_TOKEN\_SRED\_ALG\_3 <a href="#gac239a169346e74784abe25141f702fa1" id="gac239a169346e74784abe25141f702fa1"></a>

\#define CFG\_TOKEN\_SRED\_ALG\_3   \\"ALG\_9797\_MAC\_3\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6), SRED specific padding

### CFG\_TOKEN\_SRED\_ALG\_4 <a href="#ga769d2b2a5b51bbc6e49b5b72abd45e6b" id="ga769d2b2a5b51bbc6e49b5b72abd45e6b"></a>

\#define CFG\_TOKEN\_SRED\_ALG\_4   \\"ALG\_9797\_MAC\_4\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6), SRED specific padding

### CFG\_TOKEN\_SRED\_ALG\_5 <a href="#ga999281312eeef703cef5cfe1449aaee0" id="ga999281312eeef703cef5cfe1449aaee0"></a>

\#define CFG\_TOKEN\_SRED\_ALG\_5   \\"ALG\_9797\_MAC\_5\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6), SRED specific padding

### CFG\_TOKEN\_SRED\_ALG\_5A <a href="#gab5822349188eae06fa55634ea4d3bb49" id="gab5822349188eae06fa55634ea4d3bb49"></a>

\#define CFG\_TOKEN\_SRED\_ALG\_5A   \\"ALG\_9797\_MAC\_5A\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6), SRED specific padding

### CFG\_TOKEN\_SRED\_ALG\_CMAC <a href="#ga312073af7ce6f177d077f21fc164a897" id="ga312073af7ce6f177d077f21fc164a897"></a>

\#define CFG\_TOKEN\_SRED\_ALG\_CMAC   \\"ALG\_CMAC\_TDEA\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6), SRED specific padding

### CFG\_TOKEN\_SRED\_ALG\_HMAC <a href="#gac26c4068e2480cbb6fd967a551cf790c" id="gac26c4068e2480cbb6fd967a551cf790c"></a>

\#define CFG\_TOKEN\_SRED\_ALG\_HMAC   \\"ALG\_HMAC\_SHA256\\"

value of [CFG\_ENTRY\_ALGO](#gab479d306344dff2934da238f5e2c48c6), SRED specific padding

### CFG\_TOKEN\_SRED\_VARIANT\_X924\_MAC\_REQ\_BW <a href="#gac10817d4961802bbf9da51825ed9a42f" id="gac10817d4961802bbf9da51825ed9a42f"></a>

\#define CFG\_TOKEN\_SRED\_VARIANT\_X924\_MAC\_REQ\_BW   \\"X924\_MAC\_REQ\_BW\\"

value of [CFG\_ENTRY\_DUKPT\_KEY\_VARIANT](#ga053f55fa711f0286d30aa4e79207aa6d)

### CFG\_TOKEN\_SRED\_VARIANT\_X924\_MAC\_RESP <a href="#gad736c699dfba417d61030f2e12ade24b" id="gad736c699dfba417d61030f2e12ade24b"></a>

\#define CFG\_TOKEN\_SRED\_VARIANT\_X924\_MAC\_RESP   \\"X924\_MAC\_RESP\\"

value of [CFG\_ENTRY\_DUKPT\_KEY\_VARIANT](#ga053f55fa711f0286d30aa4e79207aa6d)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://sandbox-docs.verifone.com/adk-5.0-programmers-guide/readme/modules/group___config.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
