- 23 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
Key management procedure
- Mis à jour le 23 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
Figure: Key management diagram shows the key management as expected by OneSpan. The HSM-level BLOB storage key and the HSM-level DPX transport key perform a cryptographic operation so that authenticator application can be used with Authentication Suite Server SDK for HSM. It is important to securely transfer the HSM-level DPX transport key from the customer’s HSM to the OneSpan HSM. The KEK is used for this purpose (wrapping of the HSM-level DPX transport key on the customer’s HSM, unwrapping of the key on the OneSpan HSM). The different components of this KEK are known when the key is generated. With these components, the KEK is easily exportable from the customer’s HSM to the OneSpan HSM.
Each key custodian knows only one key component. Thus, the key remains secret.
In Figure: Key management diagram, the key encrypting key is split into two components. However, we strongly recommend that you split the KEK into three components.