Key management with HSM, cloud KMS, and PKCS#11

Analog Informatics Corporation (AIC) kits encrypt every stored secret and let you choose where the keys live: in software, in a hardware security module (HSM) through PKCS#11, or in a cloud key management service (KMS) key that you own. The same model works on premises, in the cloud, and in hybrid deployments. AIC Server uses AWS-LC as its default cryptographic library. AWS-LC holds a Federal Information Processing Standards (FIPS) 140-3 certificate.

These features are built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits.

Short answers

What cryptographic module does AIC use?

AWS-LC, which holds a FIPS 140-3 certificate. We share the certificate on request. FIPS mode is fixed at build time and cannot be turned off. If you use an HSM or a cloud KMS key, that device or service carries its own FIPS certification, and you confirm the certification of each one you configure.

Where can the keys live?

In the platform secret store (software), on an HSM through PKCS#11, or in a customer-owned key in AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS.

Can different zones of systems use different keys?

Yes. Each system group can have its own encryption key set, separate from the server default. A CUI enclave, a lab network, and business systems can each be protected by a different key, and each can be rekeyed on its own.

Can you rekey data that is already encrypted?

Yes. Rotate a key set, preview the change, and re-encrypt. Each stored value records which key protects it, so older data stays readable until re-encryption finishes. You can also move keys from software to an HSM, or from one HSM to a replacement, without downtime.

Which HSMs are supported?

Any HSM with a PKCS#11 library. The console includes profiles for Thales, SafeNet, Entrust nShield, Utimaco, Futurex, AWS CloudHSM, Azure Dedicated HSM, IBM Cloud HSM, YubiHSM, and open-source tokens.

Does AIC hold our cloud key?

No. You own the cloud KMS key and its access policy. AIC Server asks the key service to protect its data keys. If the cloud key cannot be reached or access is denied, AIC Server does not use it and raises a warning.

Deployment options

DeploymentKey custody
On premisesNetwork or PCIe HSM through PKCS#11
CloudAWS CloudHSM or Azure Dedicated HSM through PKCS#11
CloudCustomer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS key
HybridSoftware and HSM engines live together while keys move between them, with no downtime
HybridOn-premises enclaves on an HSM and cloud enclaves on a cloud KMS key, with the same key model
Air-gappedLocal PKCS#11 HSM with no cloud connection
AnySoftware key in the platform secret store, as the simple default

Key sets, rotation, and re-encryption

Capability

  • Server default key set plus named key sets per system group
  • Rotate a key set
  • Preview re-encryption (dry run)
  • Re-encrypt all data, or one group's data
  • Rewrap all secrets after an engine change, without re-encrypting content
  • Move encryption keys from software to an HSM
  • Replace an HSM token from a wrap-only backup
  • Maximum key age with a rotation warning
  • Two-person approval for sensitive key actions
  • Smart card (PIV/CAC) sign-in required for key administrators
  • Every key action audited to the audit log, Windows Event Log, and syslog

Supported HSM vendors

VendorProducts
ThalesLuna Network HSM, CipherTrust Cloud HSM
Thales (SafeNet)SafeNet Network HSM, Data Protection On Demand
EntrustnShield (formerly nCipher), KeyControl Cloud
UtimacoCryptoServer, CloudHSM
FuturexKMES, VirtuCrypt Cloud HSM
Amazon Web ServicesAWS CloudHSM, AWS KMS
MicrosoftAzure Dedicated HSM, Azure Key Vault Managed HSM
GoogleGoogle Cloud KMS
IBMIBM Cloud HSM
YubicoYubiHSM, through its PKCS#11 library
Open sourceOpenSC, OpenHSM, and SoftHSM2 for testing

Any other HSM that provides a PKCS#11 library can be registered as a new vendor.

FIPS 140-3

Where the cryptography runsValidation
Inside AIC ServerAWS-LC, which holds a FIPS 140-3 certificate. We share the certificate on request
On an HSMThe HSM's own FIPS certificate for its model and firmware. You confirm it for your configuration
In a cloud KMSThe provider's certificate for the service tier and region. You confirm it for your configuration

Screenshots

Encryption runs in AWS-LC and can move to an HSM.
Each key set can be rotated, and stored data re-encrypted after a preview.
A separate key set can be created for each zone of systems and assigned to its system group.
Built-in PKCS#11 profiles cover on-premises and cloud HSMs from the major vendors.

Platforms and integrations

Hardware Security Modules

  • Thales
  • Entrust
  • Utimaco
  • Futurex
  • IBM Cloud HSM
  • PKCS#11

YubiHSM is also supported.

All logos and trademarks are the property of their respective owners. Their use does not imply endorsement.

See it on your use case

Request a demo