TR-31 Key Block: the need to comply with and successfully integrate the regulatory requirements

What is TR-31 Key Block and why has it gained relevance and momentum as 2024 unfolds?

In the webinar TR-31 Key Block: Unraveling regulatory compliance and expiration, held on May 8, with the support of three of our experts in cryptographic and integration matters, we delved into the concept of TR-31 Key Block, its phases and expiration as regulatory element, its challenges and integration times, as well as some of the success stories that we have consolidated in CLAI PAYMENTS® Technologies at the level of implementation in the region.

With Rafael Holguín, Cryptography Director; Sonia Solís, CRYPTGRID™ Specialist and Carlos Pravia, Technology Director of CLAI PAYMENTS® Technologies Costa Rica, we approached the mission of unraveling this regulatory element from the generic to the more specific aspects.

TR-31 Key Block is a regulatory element issued by NIST and, also, a secure encryption algorithm for exchanging symmetric (AES or DES) or asymmetric keys reliably and with key attributes. In the financial context, it has become a fundamental pillar for brands and franchises for the handling of sensitive data and information at the time of each transaction, mitigating risks and increasing security by having blocks of keys that include keys in themselves and have a single import code in each key exchange.

Despite the importance of this format in the financial industry, its relevance is mediated by one important aspect: implementation phases and their expiration. Although TR-31 Key Block has already had two phases of implementation, its third and last phase of full implementation, in external host of card brands in POS and ATMs, which must be applied before January 2025, so the need for companies to integrate it is vital to continue operating without any sanctions from the brands or franchises. 

But, how does the TR-31 Key Block key format work and what can be processed with it? Sonia Solis, our CRYPTGRID™ specialist, explains the general structure of TR-31 cryptograms, where there is a header, the encrypted information and the MAC (Message Authentication Code) and presents six key aspects where this regulatory element comes to mediate in financial companies: protection, key exchange, key derivation, PIN verification, 3D Secure for secure authentication of Internet purchases, and Tokenization.

The TR-31 concept is not only key exchange, it is not only cryptogram processing, it grants security breadth to the whole process, thus providing specific keys and cryptograms for a specific purpose of anything we want to process

If you have not yet implemented TR-31 Key Block in its phase three for your company, how can you start doing it and what are the points to consider when carrying out the process? Carlos Pravia, our Director of Technology for the Costa Rica regional office, points out the importance of time estimates during implementation in order to anticipate the process involved, considering the necessary elements, previous analysis, setup, programming, testing and commissioning in production. 

In CLAI PAYMENTS® Technologies we have the experience to work hand in hand with your company in the integration of TR-31 Key Block, incorporating new functions, interfaces, service programs, messaging adjustments, inter alia. By having a high performance solution such as CRYPTGRID™, your business will be compliant with the highest industry standards in cryptography. 

If you would like to learn more about CRYPTGRID™ or speak to our dedicated team, please fill in your details below and we will contact you:

16 May, 2024