Azure Key Vault Managed HSM (HYOK) allows organizations to protect highly sensitive data while keeping full control of their encryption keys. In this approach, encryption keys are stored and managed only within the organization’s own environment and are not stored in the cloud.
When Azure Key Vault Managed HSM (HYOK) is integrated with Enterprise Secure Key Manager (ESKM), ESKM is used to securely create, store, and manage the encryption keys. With Azure Key Vault Managed HSM (HYOK), the encryption key used to protect data in Azure services (the Key Encryption Key, or KEK) is kept entirely outside Microsoft’s infrastructure, while cryptographic operations are performed by Azure Managed HSM (MHSM) through its integration with ESKM.
About This Guide
This guide explains how to integrate Azure Key Vault Managed HSM (HYOK) with Enterprise Secure Key Manager (ESKM).
Target Audience
This guide is intended for Utimaco ESKM and Azure Key Vault Managed HSM (HYOK) administrators.
Purpose of the Integration
The purpose of this integration is to enable Azure Key Vault Managed HSM to use encryption keys that are managed externally in Utimaco ESKM. This approach allows organizations to maintain control of key material while integrating with Azure services that support external key management.
Abbreviations
|
Abbreviation |
Meaning |
|---|---|
|
HSM |
Hardware Security Module |
|
EKM |
External Key Management |
|
ESKM |
Enterprise Secure Key Manager |
|
KEK |
Key Encryption Key |
|
HYOK |
Hold Your Own Key |
|
CA |
Certificate Authority |
|
CLI |
Command-Line Interface |
|
URL |
Uniform Resource Locator |
|
CN |
Common Name |
|
DEK |
Data Encryption Key |
|
GUI |
Graphical User Interface |
|
CMK |
Customer-Managed Key |
|
MHSM |
Managed Hardware Security Module |
|
REST |
Representational State Transfer |
|
SSL |
Secure Sockets Layer |
Abbreviations
Document Conventions
The following conventions are used in this guide:
|
Convention |
Use |
Example |
|---|---|---|
|
Bold |
Items of the Graphical User Interface (GUI), e.g., menu options |
Press OK |
|
|
Code that is given for explanation or as an example, file paths |
|
|
Italic |
References and important terms |
See Sample Chapter in the CryptoServer - Sample Manual |
Document conventions
We use special icons to highlight the most important notes and information.
Here you will find important safety information that should be followed.
Here you will find additional notes or supplementary information.
This message indicates the expected result after the successful execution of an instruction.