6.5 Security functions 安全功能

6.5.1 General requirements

With the exception of DITK values, VendingKey and DecoderKey values shall only be generated by a device responsible for token generation, such as a POS that is certified as STS-compliant and which is subject to an STS-certified KeyManagementSystem (see Clause 9). This subclause describes the key generation methods used by such devices and is applicable to manufacturers of these devices.


6.5.2 Key attributes and key changes (Key属性和Key更改) Key change requirements (Key关键变更要求)

With the exception of DITK values, STS key values shall only be introduced or changed in a payment meter from a device responsible for key management, such as a POS that is certified as STS-compliant, and which is subject to STS key management. This subclause describes the STS key change method used between such devices and payment meters, and is applicable to manufacturers of these devices and payment meters.


An STS key change provides the mechanism for changing the DecoderKey present in a decoder from its current value to a new value. This process may be initiated by several events or circumstances, including the following:


 • a new or repaired payment meter that contains a manufacturer's DITK value shall be changed before leaving the manufacturing or repair premises to contain the appropriate value of manufacturer’s default (DDTK) or utility’s DecoderKey (DUTK or DCTK) depending on the SupplyGroup to which the payment meter has been allocated;

  • 包含制造商DITK值的新的或已修复的付款仪表应在离开制造或维修场所之前进行更改,以包含制造商默认值(DDTK)或公用工程解码器键(DUTK或DCTK)的适当值,具体取决于已分配付款仪表的供应组; 

 • a SupplyGroup's VendingKey has either expired or been compromised, and is replaced by a new VendingKey revision and, as a result, each DecoderKey within the SupplyGroup shall be changed from its current DecoderKey value to the DecoderKey value that corresponds to the new VendingKey value;

  • 供应组的VendingKey已过期或被泄露,并被新的VendingKey修订版本取代,因此,供应组内的每个DecoderKey应从其当前的DecoderKey值更改为与新的VendingKey值相对应的DecoderKey值;

 • a payment meter is re-allocated from one SupplyGroup to another SupplyGroup and, as a result, its DecoderKey shall be changed from its current value generated from the previous SupplyGroup VendingKey to the new value generated from its new SupplyGroup VendingKey; or

  • 付款计价器从一个供应组重新分配到另一个供应组,因此,其解码器键应从其从上一个供应组VendingKey生成的当前值更改为从其新的供应组VendingKey生成的新值;或 

 • the TI for a payment meter is changed and, as a result, its DecoderKey shall be changed from its current value (that corresponds to the previous TI) to the new value (that corresponds to the new TI).

  • 支付计价器的TI发生改变,其解码密钥应从当前值(对应于前一个TI)更改为新值(对应于新TI)。

The key change token set effects an STS key change. This meter-specific management token set transfers the following information from the POS to the payment meter, encrypted under the current DecoderKey:
• the value of the new DecoderKey;
• the KEN;
• the KRN;
• the KT;
• the SGC (only in the case of the three-token set and the four-token set);
• the TI.


  • 新DecoderKey的值;
  • KEN;
  • KRN;
  • KT;
  • SGC(仅适用于3个令牌集合和4个令牌集合);
  • TI

An STS key change process for a payment meter shall be initiated whenever any one of the following attributes of the VendingKey changes in value:
• the value of the VendingKey;
• the value of BDT;
• the value of the SGC;
• the value of the TI;
• the value of the KEN;
• the value of the KRN;
• the value of the KT;
• the value of the DKGA.


  • • VendingKey;
  • •BDT;
  • SGC;
  • TI;
  • KEN;
  • KRN;
  • KT;
  • DKGA.

 NOTE See 6.1 .1 for detailed specifications on the data elements in the APDU and 6.5.3 for DKGA requirements.


 A particular SGC may be associated with more than one VendingKey at the same time during its operational life, in which case each VendingKey shall be identified by its associated KRN.


Key change tokens shall not be generated in the case where the destination key's KEN relative to BDT is in the past (according to the system clock).


Key change tokens shall not be generated where the BaseDate associated with the destination VendingKey/DecoderKey is earlier than the BaseDate associated with the source VendingKey/DecoderKey.


A POS may optionally generate and issue key change tokens automatically or manually, but this shall be specified in the purchase agreement between the manufacturer and the utility.




