Creating an AES Key

Unique per request

Generate a new AES-256 session key for every secure-data request.

Minimum strength

The AES key must be no smaller than 256 bits.

Client-side control

Keep the original AES session key on the cardholder device or secure client application.