Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

ADD A NEW IDEA

Crypto HW

Showing 43

Coordinated change master keys and key storage from TKE workstation

[Request] Create consistent Key Set function from TKE workstation to Domain Group on Linux only environment. [Issue]-Inconsistent master key “SET” operation from TKE workstation on z/Linux only environment-Cannot use “Set, immediate”, because this...
over 7 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 3 Future consideration

Cipher Text Translate to suport ASYM<-->SYMMETRIC translations

3rd party clients are using ASYM PKCS11 encrypt/decrypt to send for example CC numbers to us. Vice Versa as well. Local DB2 database stores the CC numbers using a symmetric key.Would like a enhancement to CIPHER text translate or new function to p...
about 8 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 10 Not under consideration

Heart beat for crypto in non-secure data centers

This requirement is for machines that exist in non-secure data centers.This is a request for a way to shut down the crypto card under conditions when a heartbeat from the customer ceases – or maybe allow admin. functions but nothing else at that p...
over 9 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 5 Not under consideration

Add the ability to generate an AES DUKPT DATA encryption key similar to the K1DATA derived key for DES DUKPT

This would allow the user to be able to perform encryption operations on DATA that has been encrypted using AES-DUKPT derived keys.
5 months ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Functionality already exists

No support of TR31 Block D K1 keys with dual mode of use

ICSF does not support TR31 K1 keys of type D with mode of use B(for encrypt and decrypt). CSNBT31I service ends with cc8/rsn7e0 (incorrect rule array parameter content). This makes ICSF CCA incompatible with authorities that do not separate KEKs a...
about 1 year ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 0 Future consideration

The Symmetric Algorithm Decipher callable service does not provide support to handle JWE Compact Serialization and none of the other callable services have support for this functionality.

The Symmetric Algorithm Decipher callable service does not provide support to handle JWE Compact Serialization and none of the other callable services have support for this functionality.
over 1 year ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Future consideration

Formatting Method PKOAEP2 in callable service CSNDPKE

Implement the PKOAEP2 formatting method (RSA DSI PKCS #1 v2.1 RSAES-OAEP) in the callable service CSNDPKE (PKA Encrypt). Currently PKOAEP2 is available in the callable services CSNDSYX and CSNDSYI2.
about 2 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Planned for future release

simplify repair actions of broken crypto cards

If a crypto card has broken in zHW, it is very complex to bring a replaced card in production again. Two or more people has to be at TKE to do that. Usually, this people are not at standby, so it could last a couple of days to be fully redundant a...
about 2 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Not under consideration

Enable the exchange of MDK keys to Visa using TR-31 Key Block Version B, mode of use=N

We are unable to send MDK keys to Visa using TR-31 Key Block Version B as they use Thales payShield HSMs which only support Mode of Use=N whereas IBM only supports Mode of Use=X.
about 2 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 3 Planned for future release

CMT#AB6351

When Correctable Error(CE) occurs in the CPU L3 cache in LinuxONE, db2sysc/gskit issues KMC instruction,After recovering Correctable Error (CE), HW recovery failed because KMC instruction could not rerun that original data was already encripted.IP...
almost 4 years ago in IBM Z and LinuxONE Systems Hardware / Crypto HW 2 Future consideration