Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

Crypto HW

Showing 25

ICSF TR-34 support

In order to comply with PCI 3 (Payment Cards Industry) requirements for elimination of the usage of SHA-1 in RSA cryptography, as well as the requirement for "key bundling", NCR has elected to implement support the following "technical recommendat...
over 7 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 8 Delivered

Diffie-Hellman (DH/DHE) Hardware Support in Crypto Express/ICSF

Add support in hardware (CPACF or more likely, Crypto Express 6S/7S) for Diffie Hellman operations performed as part of DH/DHE/ECDH/ECDHE key exchanges and make the necessary coordinating changes in ICSF to expose this support to the software stac...
over 4 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 4 Delivered

Support additional TR-31 export options

We are working with third parties who have specific TR-31 key block requirements. Specifically, two of our partners need the mode of use on exported P0 key blocks to be set to "B". Currently, ICSF only allows exported P0 key blocks to have a mode ...
almost 5 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 7 Delivered

Support additional TR-31 key blocks

Our system uses ICSF, and we are working with third parties to import and export TR-31 key blocks. At least one third party so far has provided TR-31 key block examples that cannot be imported using ICSF. We would like IBM to consider relaxing som...
almost 6 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 6 Delivered

Support of RSASSA-PSS signature paddings in CCA

The padding schemes for signatures called RSASSA-PSS from PKCS#1 v2.2 are not so easy to implement and should therefore be implemented as an option to the CCA signature/verify verbs similar to the PKCS 1.5 options.The padding might be used togethe...
over 9 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 3 Delivered

User defined exponent in RSA key generation EKMF / CCA

The exponent for RSA key pair generation should be user selectable / definable in EKMF.Currently common values are 3 and 65537 as well as random.For specific use cases we will need 17 as an option.A more general approach would be a user definable ...
over 9 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 3 Delivered

Support of ECC curve 25519

The ECC curve 25519 will be needed for future projects to sign data structures.Furthermore it was selected as a future option for TLS and therefore might become in widespread use for ECDHE usages.The crypto card and all software stacks like ICSF C...
over 9 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 4 Delivered

Add support for updated EMV card personalization data format

There is a need to support a slightly different EMV DDA format as returned by the CSNDPKT service from the keywords
almost 7 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 5 Delivered

Using CPACF with HW "built-In" instructions - Linux on z

SV likes to use HW Crypto support of CPACF (see Principles of Operation) in their applications running on Linux for z Systems (LinuxONE) As of requiremts of their architecture and as of performance reasons, they want to use the CPACF instructions ...
over 8 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 5 Delivered

Secure logging

Logging of security significant events in the HSM (keys, access control info, admin commands)Logged info must be protected so it can not be modified or deleted by unauthorized peopleLog in HSM, OS, etc
about 10 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 5 Delivered