Auto Light Dark
Auto Light Dark

Introduction

Azure Key Vault Managed HSM (HYOK) allows organizations to protect highly sensitive data while keeping full control of their encryption keys. In this approach, encryption keys are stored and managed only within the organization’s own environment and are not stored in the cloud.

When Azure Key Vault Managed HSM (HYOK) is integrated with Enterprise Secure Key Manager (ESKM), ESKM is used to securely create, store, and manage the encryption keys. With Azure Key Vault Managed HSM (HYOK), the encryption key used to protect data in Azure services (the Key Encryption Key, or KEK) is kept entirely outside Microsoft’s infrastructure, while cryptographic operations are performed by Azure Managed HSM (MHSM) through its integration with ESKM.

About This Guide

This guide explains how to integrate Azure Key Vault Managed HSM (HYOK) with Enterprise Secure Key Manager (ESKM).

Target Audience

This guide is intended for Utimaco ESKM and Azure Key Vault Managed HSM (HYOK) administrators.

Purpose of the Integration

The purpose of this integration is to enable Azure Key Vault Managed HSM to use encryption keys that are managed externally in Utimaco ESKM. This approach allows organizations to maintain control of key material while integrating with Azure services that support external key management.

Abbreviations

Abbreviation

Meaning

HSM

Hardware Security Module

EKM

External Key Management

ESKM

Enterprise Secure Key Manager

KEK

Key Encryption Key

HYOK

Hold Your Own Key

CA

Certificate Authority

CLI

Command-Line Interface

URL

Uniform Resource Locator

CN

Common Name

DEK

Data Encryption Key

GUI

Graphical User Interface

CMK

Customer-Managed Key

MHSM

Managed Hardware Security Module

REST

Representational State Transfer

SSL

Secure Sockets Layer

Abbreviations

Document Conventions

The following conventions are used in this guide:

Convention

Use

Example

Bold

Items of the Graphical User Interface (GUI), e.g., menu options

Press OK 

Monospaced

Code that is given for explanation or as an example, file paths

chsm-create

Italic

References and important terms

See Sample Chapter in the CryptoServer - Sample Manual

Document conventions

We use special icons to highlight the most important notes and information.

Here you will find important safety information that should be followed.

Here you will find additional notes or supplementary information.

This message indicates the expected result after the successful execution of an instruction.