4 ms·
The PKCS#11 standard, which is implemented by most HSMs defines two attributes that control this: - Marking a key as “sensitive” means that the raw key materia
by nmadden 3y ago
The PKCS#11 standard, which is implemented by most HSMs defines two attributes that control this:
- Marking a key as “sensitive” means that the raw key material cannot be exported, except in encrypted (“wrapped”) form. Such an encrypted key can then be unwrapped to install it on another HSM. This key-wrapping facility is largely to allow backup or replication (but see below).
- Marking a key as “non-extractable” also means that it cannot be exported even in encrypted/wrapped form.
You generally configure a policy on the HSM to say that all private keys must be sensitive etc. It is pretty common (in my experience, dealing with banks primarily) to enable a policy that enforces all private keys to be sensitive and non-extractable. Proprietary mechanisms are then used to replication and backup of those keys (that effectively ignore those attributes/work at a lower level).