IDmetrix® Key Management System (KMS)
Generates, stores and retires every key the programme depends on — inside the HSM.
The Key Management System, paired with a Hardware Security Module, manages the encryption and signature keys behind a secure document programme. In an issuance system it holds the keys for the CSCA, the Document Signer, the CVCA, the Document Verifier and chip encryption — the entire cryptographic basis of the documents the country issues.
Key functions
- Key generation
- Generation of RSA, ECC, AES and DES keys inside the HSM using true random number generation.
- Secure storage
- Private keys held inside the HSM at FIPS 140-2/3 Level 3, never exported in plaintext.
- Key lifecycle management
- The full lifecycle: creation, activation, use, deactivation, archival, destruction.
- Key rotation
- Periodic replacement, automatic or scheduled, to reduce compromise risk — with old versions retained so historical documents stay verifiable.
- Certificate management
- X.509 certificate creation, signing, reissuance and revocation (CRL/OCSP), with PKD publication.
- Access control
- Role-based access for key custodian, crypto officer and auditor, with multi-factor authentication and dual control on key operations.
- Cryptographic operations
- Signature, verification, encryption and decryption performed through the API without keys leaving the HSM.
- Audit and logging
- Complete logging of every key operation — who, when, what operation, what result — for compliance and investigations.
- Backup and recovery
- Secure encrypted backup under split knowledge, and recovery after failure.
- Multi-HSM support
- HSM clustering for failover and scale, active-active or active-passive.
- PKI integration
- Integration with CSCA and CVCA systems, the ICAO PKD for e-Passports, and national PKI registries.
CSCA — the country root keys that sign Document Signer certificates. Document Signer — the keys that sign the SOD on each passport or card chip. CVCA — the root keys for Extended Access Control, governing access to biometric data. Document Verifier — the keys behind border control terminal certificates. Chip encryption keys — used to encrypt fingerprints and iris data before chip writing.
Also in Data Preparation
The other IDMS components at this stage of the lifecycle.
