All Tools
Tools/DUKPT Key Derivation
🗝️
CryptographyAvailable

DUKPT Key Derivation

Derive IPEK and session keys from a Base Derivation Key (BDK) and Key Serial Number (KSN) per ANSI X9.24-1 (Triple-DES DUKPT).

Use test data only. All calculations run locally in your browser — PayProbe never sees, transmits, or stores your PAN, CVV, keys, PINs, or cryptographic inputs. How we handle data →

How DUKPT derives a unique key per transaction

Derived Unique Key Per Transaction: every transaction uses a fresh key derived from a device-specific initial key, so compromising one transaction never exposes past or future ones (forward & backward security).

1 / 7
🗝️
BDKissuer master key
📥
Initial Key
🌳
Future Keys
🔢
KSN Counter
⚙️
Transaction Key
🎭
Variant Mask
🔒
Encrypt

1BDK

Base Derivation Key

The Base Derivation Key is held only in the issuer/acquirer HSM. It never leaves it and is shared across a whole fleet of devices — individual devices never see the BDK.

0/16 B
0/10 B