Key Management Service
The Blahaj Cloud Key Management Service allows you to securely manage cryptographic keys for your Blahaj Cloud and external workloads.
Key Storage Options
There are different key storage options available in Blahaj Cloud KMS. They differ in performance, security and cost.
| Software | HSM External | HSM Internal | |
|---|---|---|---|
| Hardware Certification | None | CC EAL4+ FIPS 140-2 level 3 FIPS 140-3 level 3 | CC EAL4+ FIPS 140-2 level 3 FIPS 140-3 level 3 |
| Configuration Certification | None | FIPS 140-2 level 3 FIPS 140-3 level 3 | FIPS 140-2 level 3 FIPS 140-3 level 3 |
| Security | Lower | High | Highest |
| Performance | Highest | Medium-High | High |
| Cost | Lowest | Medium | High |
| Secure Backup of Key Material | Yes | Yes | Optional |
Software keys are stored in a secure key management software.
HSM External keys are stored on encrypted hard drives, but encrypted and protected by a HSM's cryptography. Cryptographic operations are only carried out on a HSM to which the key is temporarily transferred for use. The plain text key is never available outside the HSM.
HSM Internal keys are stored in the HSM's internal memory.
HSM External and HSM Internal keys provide the same overall security, with the exception of physical tamper safety in case of advanced attacks. In case of a physical attack, the tamper protection of the HSM will erase the internal key store, but not the external key store. However, the HSM internal key material will be deleted by the tamper detection as well, making the externally stored keys unusable until a secure offline backup of the key material is recovered. Internally stored keys are also backed up by default, however this can be turned off on a per-key basis.
Updated about 1 month ago