All Tools
Tools/DUKPT Key Derivation
🗝️
CryptographyAvailable
DUKPT Key Derivation
Derive IPEK and session keys from a Base Derivation Key (BDK) and Key Serial Number (KSN) per ANSI X9.24-1 (Triple-DES DUKPT).
Use test data only. All calculations run locally in your browser — PayProbe never sees, transmits, or stores your PAN, CVV, keys, PINs, or cryptographic inputs. How we handle data →
How DUKPT derives a unique key per transaction
Derived Unique Key Per Transaction: every transaction uses a fresh key derived from a device-specific initial key, so compromising one transaction never exposes past or future ones (forward & backward security).
1 / 7
🗝️
BDKissuer master key📥
Initial Key🌳
Future Keys🔢
KSN Counter⚙️
Transaction Key🎭
Variant Mask🔒
Encrypt1BDK
Base Derivation Key
The Base Derivation Key is held only in the issuer/acquirer HSM. It never leaves it and is shared across a whole fleet of devices — individual devices never see the BDK.
0/16 B
0/10 B