Key Management Service

⚠️

This service is currently in Private Beta

The Blahaj Cloud Key Management Service allows you to securely manage cryptographic keys for your Blahaj Cloud and external workloads.

Key Storage Options

There are different key storage options available in Blahaj Cloud KMS. They differ in performance, security and cost.

SoftwareHSM ExternalHSM Internal
Hardware CertificationNoneCC EAL4+
FIPS 140-2 level 3
FIPS 140-3 level 3
CC EAL4+
FIPS 140-2 level 3
FIPS 140-3 level 3
Configuration CertificationNoneFIPS 140-2 level 3
FIPS 140-3 level 3
FIPS 140-2 level 3
FIPS 140-3 level 3
SecurityLowerHighHighest
PerformanceHighestMedium-HighHigh
CostLowestMediumHigh
Secure Backup of Key MaterialYesYesOptional

Software keys are stored in a secure key management software.

HSM External keys are stored on encrypted hard drives, but encrypted and protected by a HSM's cryptography. Cryptographic operations are only carried out on a HSM to which the key is temporarily transferred for use. The plain text key is never available outside the HSM.

HSM Internal keys are stored in the HSM's internal memory.

HSM External and HSM Internal keys provide the same overall security, with the exception of physical tamper safety in case of advanced attacks. In case of a physical attack, the tamper protection of the HSM will erase the internal key store, but not the external key store. However, the HSM internal key material will be deleted by the tamper detection as well, making the externally stored keys unusable until a secure offline backup of the key material is recovered. Internally stored keys are also backed up by default, however this can be turned off on a per-key basis.


Did this page help you?