Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Review: Enterprise Key Management Software: Page 5 of 9

Decru also has an OpenKey Partner Program that offers third-party access to its API, but as of press time only Quantum and Symantec have signed on as charter members. It bears mentioning that Decru is an independent division of Network Appliance, and that might serve as a limiting factor for buy-in of the LKM platform from other storage vendors.

Like the KeyVault, the LKM appliance is focused on secure key administration, centralized policy management and long-term key archiving, but unlike NeoScale's model, keys are generated by individual DataFort encryption appliances. Each DataFort uses a FIPS 140-2 Level 3 certified SEP (Storage Encryption Processor) that contains a true random number generator; those numbers are then encrypted and sent to the LKM system for archiving. The question of where the key is generated doesn't seem to be as much of an issue as how securely those keys are archived and managed, and Decru's LKM system in a clustered configuration offers enterprise-class features for key archiving, role-based access, system recovery and failover as well as emergency key access using a smartcard and "M of N" authentication.

Ncipher Keyauthority

The keyAuthority application from nCipher is a software suite that consists of the keyAuthority Management Server, Management Console client and Provisioning Server modules. These modules were developed to provide key- and configuration-management capabilities to nCipher's line of Hardware Security Modules (HSMs). Targeted at providing security and key access for applications, transaction security and embedded systems, nCipher HSMs are available as sharable network-connected modules (netHSM), PCI expansion cards (nShield) and miniature modules for OEM integration (miniHSM). There's also a PayShield option that provides the additional security required for credit-card transaction processing.

In a keyAuthority infrastructure, all servers and endpoints are equipped with an HSM, and the Management Server system generates keys, enrolls endpoints and provides centralized management of security policies for all connected devices. Administration can be done through the use of a keyAuthority Management Console client, and the Provisioning Server module distributes keys to endpoints on request.