IDMETRIX
← Secure Identity
Stage 2 · Data Preparation

IDmetrix® Key Management System (KMS)

Generates, stores and retires every key the programme depends on — inside the HSM.

The Key Management System, paired with a Hardware Security Module, manages the encryption and signature keys behind a secure document programme. In an issuance system it holds the keys for the CSCA, the Document Signer, the CVCA, the Document Verifier and chip encryption — the entire cryptographic basis of the documents the country issues.

FIPS 140-2/3 Level 3 key storage
Capabilities

Key functions

Key generation
Generation of RSA, ECC, AES and DES keys inside the HSM using true random number generation.
Secure storage
Private keys held inside the HSM at FIPS 140-2/3 Level 3, never exported in plaintext.
Key lifecycle management
The full lifecycle: creation, activation, use, deactivation, archival, destruction.
Key rotation
Periodic replacement, automatic or scheduled, to reduce compromise risk — with old versions retained so historical documents stay verifiable.
Certificate management
X.509 certificate creation, signing, reissuance and revocation (CRL/OCSP), with PKD publication.
Access control
Role-based access for key custodian, crypto officer and auditor, with multi-factor authentication and dual control on key operations.
Cryptographic operations
Signature, verification, encryption and decryption performed through the API without keys leaving the HSM.
Audit and logging
Complete logging of every key operation — who, when, what operation, what result — for compliance and investigations.
Backup and recovery
Secure encrypted backup under split knowledge, and recovery after failure.
Multi-HSM support
HSM clustering for failover and scale, active-active or active-passive.
PKI integration
Integration with CSCA and CVCA systems, the ICAO PKD for e-Passports, and national PKI registries.
Keys under management

CSCA — the country root keys that sign Document Signer certificates. Document Signer — the keys that sign the SOD on each passport or card chip. CVCA — the root keys for Extended Access Control, governing access to biometric data. Document Verifier — the keys behind border control terminal certificates. Chip encryption keys — used to encrypt fingerprints and iris data before chip writing.