OneSpan procedure
  • 23 Jan 2025
  • 1 Minute à lire
  • Sombre
    Lumière
  • PDF

OneSpan procedure

  • Sombre
    Lumière
  • PDF

The content is currently unavailable in French. You are viewing the default English version.
Résumé de l’article

When the HSM-level DPX transport key and the KEK custodians arrive, OneSpan proceeds to a key import ceremony. The OneSpan key management procedure, which does not require any customer activity, involves the following steps:

  • Import the customer’s KEK with custodians import
  • Import the HSM-level DPX transport key wrapped by the KEK

Customers may use this procedure to restore the HSM-level DPX transport key in their own HSM (for example, after failure).

Import the customer’s KEK with custodians import

To import the customer’s KEK

  1. In the Key Managment Utility window, from the menu, select Options > Create > Enter Key from Components.
  2. Select the Mechanism: Double DES, Triple DES, AES with key size 128 bits or AESwith key size 256 bits.

    Figure: Import the customer’s KEK (1)

With these settings, KEK backup is not possible. To allow backup, set the Exportable option to TRUE.

  1. Specify the number of components to enter.

    Figure: Import the customer’s KEK (2)

  2. Enter the KEK components.

    Figure: Import the customer’s KEK (3)

    Figure: Import the customer’s KEK (4)

Import the HSM-level DPX transport key wrapped by the KEK

To import the HSM-level DPX transport key

  1. In the Key Managment Utility window, from the menu, select Options > Import Key(s).
  2. Select the Import encrypted parts and Single Partoptions.

    Figure: Import the HSM-level DPX transport key (1)

    Figure:  Import the HSM-level DPX transport key (2)

  3. Select the Mechanism: Double DES, Triple DES, AES with key size 128 bits or AES with key size 256 bits.

With these settings, backup or export of the HSM-level DPX transport key is not possible. To allow backup, the set the Exportable option to TRUE.

  1. Enter the wrapped transport key value.

    Figure: Import the HSM-level DPX transport key (3)

  2. Check the KCV value.

    Figure: Import the HSM-level DPX transport key (4)

OneSpan is now able to use this HSM-level DPX transport key to double-encrypt the DPX file(s) for the customer.


Cet article vous a-t-il été utile ?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Ozzy, facilitant la découverte de connaissances grâce à l’intelligence conversationnelle