Enterprise Key Manager as a Service

Enterprise Key Manager as a Service

Utimaco’s Enterprise Key Manager as a Service is providing enhanced management and control over cryptographic keys based on converged KMS and HSM capabilities.

Free 30-Day Trial
  • Overview
  • Key Features
  • Description
  • Specifications
  • Resources
The fully managed service for holistic crypto key generation, management and storage

The fully managed service for holistic crypto key generation, management and storage

The Enterprise Key Manager aaS is a cloud-based service combining the capabilities of a Key Management System with those of a General Purpose Hardware Security Module.

It enables you to secure your environments through advanced multi-cloud or hybrid deployment, supporting BYOK, HYOK, KMIP, TDE, KMS, and REST.

  • Key Features

  • Description

  • Specifications

Enterprise Key Manager aaS combines KSM and GP HSM capabilities, enabling holistic generation, management and storage of cryptographic keys.

Secure your environments through advanced multi-cloud or hybrid deployment, supporting BYOK, HYOK, KMIP, TDE, KMS, and REST. Centralized key management ensures strict separation between your data and cryptographic material, while your exclusive-access Master Backup Key (MBK)—stored in HSMs—serves as your reliable Root of Trust.

image
Cryptographic Interfaces (APIs)
  • Certifications and compliance

  • Service benefits and capabilities

  • Supported use cases

  • Supported cryptographic interfaces

  • Supported cryptographic algorithms

Certifications and compliance

  • FIPS 140-2 Level 3 (for HSM)
  • FIPS 140-2 Level 1 (for KMS)
  • ISO 27001 Compliant
background image
image

Service benefits and capabilities

  • Multi-Cloud and Hybrid Cloud support (CSP independent)
  • Mix of Cloud and Customer Datacenter support (Hybrid deployments)
  • Key Management, with HSM root of trust
  • Customer has full control of Master Key
  • Support all Enterprise Key Management use cases from one service
background-image
image

Supported use cases

  • Cloud Key Management (BYOK/HYOK)
  • Multi-Cloud Key MgM
  • dB encryption (TDE)
  • Enterprise Key Management for Applications/VMs/dB (KMIP, KMS)
  • Converged Key MgM and GP HSMaaS service over REST API
background-image
image

Supported cryptographic interfaces

  • RESTful interface API
  • KMIP, OpenKMIP and PyKMIP
  • KMS
  • TDE
  • PKCS #11
  • Java Cryptography Extension (JCE)
  • Microsoft Crypto API (CSP), Cryptography Next Generation (CNG), and SQL
  • Extensible Key Management (SQLEKM)
  • Supports Azure, Google, and Amazon cloud integrations
background-image
image

Supported cryptographic algorithms

  • Symmetric algorithms: AES, Triple-DES, DES
  • Asymmetric algorithms: RSA, DSA, ECDSA with NIST and Brainpool curves, EdDSA
  • Elliptic Curves: DH, ECDH with NIST, Brainpool and Montgomery curves
  • Hashing algorithms: SHA-1, SHA-2, SHA-3, RIPEMD
  • MAC/sealing algorithms: MAC, CMAC, HMAC
  • Optional upgraded with blockchain-specific algorithms: BIP32/44 and SLIP-010
background-image
image
image

Certifications and Compliance

Enterprise Key Manager as a Service enables compliance to:

image

Resources

Ready to Secure Your Digital Future?

Contact Sales

Related Products

How can we help you?

Talk to one of our specialists and find out how Utimaco can support you today.
You have selected two different types of downloads, so you need to submit different forms which you can select via the two tabs.

Your download request(s):

    By submitting below form you will receive links for your selected downloads.

    Your download request(s):

      For this type of documents, your e-mail address needs to be verified. You will receive the links for your selected downloads via e-mail after submitting below form.

      About Utimaco's Downloads

      Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).

      For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.

      Download via e-mail

       

      A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.