What cryptography actually protects
In a payment chain, cryptography serves three separate goals, and none of them guarantees the other two. Confidentiality makes data unreadable to anyone who intercepts it; integrity makes any tampering with a message detectable; authentication proves where a message came from and that the card is genuine. A single mechanism often does all three at once.
HSMs and the key hierarchy
An HSM (Hardware Security Module) is a tamper-resistant hardware vault in which keys are generated and used without ever leaving it in the clear. Banks, acquirers, and certificate authorities all use them, and they are also available in the cloud (CloudHSM). Models used in payments are certified to FIPS 140-2 / 140-3 Level 3 and PCI HSM / PCI PIN.
The keys in a payment system are organized in a tiered hierarchy. A local master key (LMK) protects every other key stored outside the HSM. Below it sit zone exchange keys, PIN keys, card verification keys, and so on. No key ever travels in the clear: each one is sent encrypted under the key one tier above it.
LMK (Local Master Key) -- never leaves the HSM, protects everything else
|
+-- ZMK (Zone Master Key) -- key shared with a partner bank
| |
| +-- ZPK (Zone PIN Key) -- encrypts PIN blocks exchanged within the zone
| +-- ZAK (Zone Auth Key) -- authenticates messages (MAC)
|
+-- TMK (Terminal Master Key) -- protects keys downloaded to a terminal
|
+-- PVK (PIN Verification Key) -- verifies the PIN (IBM 3624 / VISA PVV method)
+-- CVK (Card Verification Key) -- calculates and verifies the CVV / CVCDUKPT and P2PE: one key per transaction
DUKPT (Derived Unique Key Per Transaction) is a key derivation scheme in which every transaction from a terminal is encrypted under a unique derived key that is erased after use. A POS terminal must not reuse the same key to encrypt the PIN and card data, because if that key leaked, every past transaction could be decrypted. With DUKPT, compromising one encrypted transaction exposes neither the ones before it nor the ones after.
P2PE (Point-to-Point Encryption) encrypts card data the moment it is read, inside a hardened terminal with SRED (Secure Reading and Exchange of Data). The data only becomes readable again in the provider’s decryption environment, outside the merchant’s systems. The merchant therefore never handles any cleartext data, which sharply reduces its PCI scope (SAQ P2PE).
EMV cryptograms: the ARQC as proof of authenticity
Application cryptograms are values the EMV chip calculates for every payment, using a session key derived from its master key (MDK) and the transaction data. The cryptogram proves to the issuer that the card is genuine and that the data has not been altered. This mechanism has made card counterfeiting nearly impossible, because copying the visible data does not reproduce the key locked inside the chip.
| Acronym | Name | Role |
|---|---|---|
| ARQC | Authorization Request Cryptogram | Generated by the card and sent to the issuer to request online authorization |
| ARPC | Authorization Response Cryptogram | The issuer’s cryptographic response, verified by the card |
| TC | Transaction Certificate | Final approval cryptogram (transaction approved and completed) |
| AAC | Application Authentication Cryptogram | Decline cryptogram (transaction declined) |
The same principle underpins the printed CVV / CVC and the dynamic CVV used in tokenization. In both cases, a verification code is calculated cryptographically from the PAN, the expiration date, and a secret key (CVK). Without that key, a fraudster cannot generate a valid code for a given card number. The static code therefore still has value, despite its weakness in e-commerce, where it is sent with every payment.
Encryption in transit and the post-quantum threat
On open networks, PCI DSS Requirement 4 mandates strong encryption in transit, which in practice means TLS 1.2 or 1.3 with robust cipher suites and forward secrecy. SSL and early TLS have been banned since June 30, 2018. A server that still accepts these protocols is out of compliance and exposes its sessions to the known decryption attacks against those versions.
A sufficiently powerful quantum computer running Shor’s algorithm would break today’s asymmetric cryptography (RSA, elliptic curves), which protects TLS and certificates. No machine that powerful exists yet. The risk is already real, though, in the form of “harvest now, decrypt later”: an attacker captures encrypted traffic today and decrypts it once the capability arrives.
NIST finalized its first post-quantum standards on August 13, 2024: FIPS 203 (ML-KEM) for key exchange, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for signatures. EMVCo and the PCI SSC are tracking the issue. Crypto-agility means designing systems so that a cryptographic algorithm can be swapped out without rebuilding the whole chain. The payments industry’s migration to these standards will stretch across the 2030s.