Key management with HSM, cloud KMS, and PKCS#11
Analog Informatics Corporation (AIC) kits encrypt every stored secret and let you choose where the keys live: in software, in a hardware security module (HSM) through PKCS#11, or in a cloud key management service (KMS) key that you own. The same model works on premises, in the cloud, and in hybrid deployments. AIC Server uses AWS-LC as its default cryptographic library. AWS-LC holds a Federal Information Processing Standards (FIPS) 140-3 certificate.
These features are built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits.
Short answers
What cryptographic module does AIC use?
AWS-LC, which holds a FIPS 140-3 certificate. We share the certificate on request. FIPS mode is fixed at build time and cannot be turned off. If you use an HSM or a cloud KMS key, that device or service carries its own FIPS certification, and you confirm the certification of each one you configure.
Where can the keys live?
In the platform secret store (software), on an HSM through PKCS#11, or in a customer-owned key in AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS.
Can different zones of systems use different keys?
Yes. Each system group can have its own encryption key set, separate from the server default. A CUI enclave, a lab network, and business systems can each be protected by a different key, and each can be rekeyed on its own.
Can you rekey data that is already encrypted?
Yes. Rotate a key set, preview the change, and re-encrypt. Each stored value records which key protects it, so older data stays readable until re-encryption finishes. You can also move keys from software to an HSM, or from one HSM to a replacement, without downtime.
Which HSMs are supported?
Any HSM with a PKCS#11 library. The console includes profiles for Thales, SafeNet, Entrust nShield, Utimaco, Futurex, AWS CloudHSM, Azure Dedicated HSM, IBM Cloud HSM, YubiHSM, and open-source tokens.
Does AIC hold our cloud key?
No. You own the cloud KMS key and its access policy. AIC Server asks the key service to protect its data keys. If the cloud key cannot be reached or access is denied, AIC Server does not use it and raises a warning.
Deployment options
| Deployment | Key custody |
|---|---|
| On premises | Network or PCIe HSM through PKCS#11 |
| Cloud | AWS CloudHSM or Azure Dedicated HSM through PKCS#11 |
| Cloud | Customer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS key |
| Hybrid | Software and HSM engines live together while keys move between them, with no downtime |
| Hybrid | On-premises enclaves on an HSM and cloud enclaves on a cloud KMS key, with the same key model |
| Air-gapped | Local PKCS#11 HSM with no cloud connection |
| Any | Software key in the platform secret store, as the simple default |
Key sets, rotation, and re-encryption
Capability
- Server default key set plus named key sets per system group
- Rotate a key set
- Preview re-encryption (dry run)
- Re-encrypt all data, or one group's data
- Rewrap all secrets after an engine change, without re-encrypting content
- Move encryption keys from software to an HSM
- Replace an HSM token from a wrap-only backup
- Maximum key age with a rotation warning
- Two-person approval for sensitive key actions
- Smart card (PIV/CAC) sign-in required for key administrators
- Every key action audited to the audit log, Windows Event Log, and syslog
Supported HSM vendors
| Vendor | Products |
|---|---|
| Thales | Luna Network HSM, CipherTrust Cloud HSM |
| Thales (SafeNet) | SafeNet Network HSM, Data Protection On Demand |
| Entrust | nShield (formerly nCipher), KeyControl Cloud |
| Utimaco | CryptoServer, CloudHSM |
| Futurex | KMES, VirtuCrypt Cloud HSM |
| Amazon Web Services | AWS CloudHSM, AWS KMS |
| Microsoft | Azure Dedicated HSM, Azure Key Vault Managed HSM |
| Google Cloud KMS | |
| IBM | IBM Cloud HSM |
| Yubico | YubiHSM, through its PKCS#11 library |
| Open source | OpenSC, OpenHSM, and SoftHSM2 for testing |
Any other HSM that provides a PKCS#11 library can be registered as a new vendor.
FIPS 140-3
| Where the cryptography runs | Validation |
|---|---|
| Inside AIC Server | AWS-LC, which holds a FIPS 140-3 certificate. We share the certificate on request |
| On an HSM | The HSM's own FIPS certificate for its model and firmware. You confirm it for your configuration |
| In a cloud KMS | The provider's certificate for the service tier and region. You confirm it for your configuration |
Screenshots
Platforms and integrations
Hardware Security Modules
YubiHSM is also supported.
All logos and trademarks are the property of their respective owners. Their use does not imply endorsement.
Related References
- CMMC: Kits, Level 1, Level 2, Level 3, Defense contractors, C3PAO
- Defense contract requirements: SPRS score, DFARS 252.204-7012, DFARS 252.204-7021, NIST SP 800-171 self-assessment, CUI marking, CMMC Phase 2