KMS9000 Features

Centralized secure device for managing and tracking the use of cryptographic keys.

All keys managed from one central location.

PKI functionality for remote key.

KMS9000 Benefits

Easy to use reporting that meets ANSI requirements.

Improved security, ability to backup and manageability.

Eliminates travel related expenses.

Products Abide by:

  
  
  
KMS9000 - Key Management Server for ATM Networks

The ExcryptTM KMS9000 Key Management Server for POS Remote Key Solution is a complete ANSI and PCI DSS compliant hardware based key management solution. It provides a full range of encryption key management functions including key generation, distribution, injection, deletion and tracking. The solution securely injects encryption keys into the Encrypting PIN Pad (EPP) of Hypercom POS devices over an IP network.

As a centralized key management solution, all keys are secured under a device Master File Key (MFK), which is protected using a Tamper Resistant Security Module (TRSM) and application level controls such as dual control and split knowledge, as required by the governing standards. The TRSM is a FIPS 140-2 Level 3 compliant device with battery backed memory to prevent loss of the MFK.

The solution is composed of a server and the ExcryptTM Key Manager application consisting of firmware and software. The following are features of the Excrypt Key Manager application provided as part of the solution.

  • Key group management (logical grouping of keys assigned to a POS device/serial number for loading);


  • Support for Master Session and DUKPT keys for POS devices;


  • Batch device import (imports a list of device serial numbers);
  • CA certificate hierarchies support (chained CA assignments for KMS and POS devices);


  • Web administrative access;


  • Audit trace logging of all activities (exportable and searchable);


  • Futurex POS Remote Key Transfer protocol (for key loading);


  • Multi-user grouping for access restriction;


  • Host/Network key assignment (for key exchange with network/processors); and


  • Audit and system reporting abilities



Learn more about SKI Series - Secure Key Injection for PIN Entry Devices (PEDs)
Learn more about KLD7000 – Handheld Key Loader and Configuration Tool


Talk to Sales
Schedule a Presentation
Newsletter Signup
Request Literature
Contact Us