
Transportation Key (KEK)

cl flag

I was studying about how to transport keys from one HSM environment to another and it came to me that I would need some sort of transportation key so the HSM keys would be double encrypted. How would this key be generated so it would be imported in both HSM securely? Coyld It be used RSA or EC? Since the key could be generated in the target HSM and in the source we would just import the public key which is the responsible for encryption?

Maarten Bodewes avatar
in flag
Usually smart card or multiple key parts. HSM's of a specific vendor may have ways of clustering them as well.
I sit in a Tesla and translated this thread with Ai:


Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.