- 23 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
Key backup
- Mis à jour le 23 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
Customers can use the KMU to backup the HSM-level DPX transport key and the HSM-level BLOB storage key for further usage (key replication for multiple HSM architectures, recovery after crash, etc.)
With the procedures outlined in Sections OneSpan customer procedure and OneSpan procedure customers can back up the HSM-level DPX transport key. The procedure for the HSM-level BLOB storage key backup is identical except that the key needs to be created with the Exportable property set to TRUE.
Exporting keys does not necessarily require a key encrypting key. You can export the keys to smart cards with multiple card shares. This option is more secure because the shared secrets do not appear in clear text.
For more information about the key backup operations, refer to the ProtectToolkit C - Key Managment Utility User Guide included in the Thales ProtectServer HSM documentation.