SAP Security Note
Low priority
SAP security note 633462, “Encrypting credit card data”, is a legal change note released on 08.10.2009. Below are the symptom, reason and prerequisites, SAP recommended solution and references.
Description
Symptom
For legal reasons, you must save payment card numbers to a database in encrypted form. Before you activate the encryption function, refer to the FAQ contained in Note 766703.
Solution
To activate encryption, your system must meet the following requirements:
- For Release 4.6C, you must import Support Package SAPKH46C46.
- Kernel 4.6D must have patch level 1329 (see Note 565111).
- For Release 470, you must import Support Package SAPKH47022.
- For Release ERP 500, you must import Support Package SAPKH50007.
- Download and install SAPCRYPTOLIB (see Note 662340). You must use the CCARD application when you use Transaction SSFA to set up encryption.
Activation steps:
- Start the SAPFACCG report once.
- Depending on the card type, use Transaction SM30 to activate encryption. Maintain the CCARDEC_V view.
- Use the CCARDEC_CHECK report to ensure that the encryption tool is working correctly. Only select the P_TOOLS checkbox and then execute the report on all application servers.
- If encryption works correctly (Process Encryption/Decryption passed), you can start to convert existing data. This is only necessary if you also want to encrypt legacy data. Two reports (first CCARDEC_TRANSFORM_SD and then CCARDEC_TRANSFORM_FI) are used to convert the data.
- Data conversion using the CCARDEC_TRANSFORM_SD report takes place in two steps: start the report and choose the action ‘Encrypt’ (the credit card number is encrypted and saved to the database), then start the report and choose the action ‘Check’ (the encrypted payment card number is checked and the original payment card number is masked). For testing purposes, you can carry out both steps without performing a database update (by setting the test indicator to ‘X’).
- Then carry out the same steps using the CCARDEC_TRANSFORM_FI report.
Reason and prerequisites
This is a legal requirement.
References
- 1105524 – Security when displaying credit card numbers
- 1034482 – FAQ: Credit card encryption in CRM
- 1029819 – Encryption of payment cards in SD and customer master
- 894022 – NAE: Credit Card Masking
- 813198 – Action ‘C4’ is missing for the VBAK_AAT authorization object
- 808313 – CCARDEC_CHECK report missing
- 791178 – Credit card encryption in AR backend
- 790161 – The customer number is missing in message V/005
- 779203 – Loss of data during payment card encryption
- 766703 – FAQ: Credit card encryption in R/3 systems
- 735071 – Payment cards: Coding report does not work
- 662340 – SSF Encryption Using the SAPCryptolib
- 597059 – License terms of SAP CommonCryptoLib
- 397175 – SAP Cryptographic software – export control
Full note on SAP: SAP Support Launchpad note 633462
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
