Solutions Overview
Total Page:16
File Type:pdf, Size:1020Kb
GEOBRIDGE KeyBRIDGE Platform Solutions Overview GEOBRIDGE Corporation – 20110 Ashbrook Place, Suite #125, Ashburn, Virginia 20147 www.GEOBRIDGE.net INTRODUCTION The KeyBRIDGE platform is a turnkey solution that serves as a centralized key management solution for the secure storage and exchange of cryptographic keys. KeyBRIDGE provides local and remote key delivery capabilities and integrates with third party Host Security Modules (HSMs), providing valuable key generation, import and export functions while providing full key lifecycle tracking with rich automated audit features. KeyBRIDGE supports compliant key management and stringent dual control features while offering an easy to use graphical interface. Built as a TRSM, leveraging an internal FIPS 140-2 Level 3 HSM, KeyBRIDGE utilizes true hardware-based encryption and random number generation. It is a complete, secure and compliant key management solution. GEOBRIDGE Corporation – 20110 Ashbrook Place, Suite #125, Ashburn, Virginia 20147 www.GEOBRIDGE.net 2 KEY PRODUCT FEATURES . Easy to navigate Graphical User Interface for local console access. Simple JSON Schema RESTful API (ARCK™) – API for Remote Central Key Management. Remote administration using a set of ARCK commands. Enforcement of key separation through the use of dedicated key custodian groups. Key management support for all TR-31 Key Usage types and optional custom key types and attributes. Key Import and Export available with third party Host Security Module (HSM) master key and/or ZMK encryption. Secure key entry, with optional SCD component entry. Using the SCD, components may be entered and managed remotely, allowing components to be securely entered by authorized key custodians without requiring physical access to the appliance. Symmetric key support: generation, import, export and storage of double and triple- length TDES keys, as well as AES 128, 192 and 256-bit keys. Asymmetric key support: generation, import, export and storage of RSA and ECC key pairs; CSR generation and certificate storage. Integrated key bundling - import and export of keys in commonly-adopted key block formats. TDES/AES DUKPT and Master/Session key-loading support for over 350 unique payment devices, including key erasure. Detailed Key Inventory – Track generation, import, export, termination details and optional key expiration dates. Full life-cycle key management tracks all instances of imported and exported keys; key history is maintained even if the key has been terminated and removed from the system. Hierarchical user administration. Dual-control required for all sensitive operations. GEOBRIDGE Corporation – 20110 Ashbrook Place, Suite #125, Ashburn, Virginia 20147 www.GEOBRIDGE.net 3 . Extensive audit logging tracks all functional key management activities and access. Customizable interface for Remote Key Delivery (RKD) capabilities. Secure secret data storage provided a “virtual safe” for sensitive data like passwords, combinations, key components, and door codes. Configurable network settings enable access to shared network storage for secure file storage and access. Configurable automated daily backup function. Designed to ensure compliance with: o ANS X9.24 -2017: Parts 1, 2, & 3 (AES DUKPT) o ANS X9 TR-31 2018: Interoperable Secure Key Exchange Key Block Specification for Symmetric Algorithms. Supports Version “D” key blocks, with symmetric and asymmetric keys. o ANS X9 TR-34 Asymmetric Distribution of Keys o Payment Card Industry PIN 2.0 Key Management Security Requirements o ANS/X9.TR.39-2009: TG-3 Retail Financial Services Compliance Guideline Part 1: PIN Security and Key Management o ANS X9.97-2009: Financial Services – Secure Cryptographic Devices (Retail) Part 1: Concepts, Requirements and Evaluation Methods o NIST SP 800-67 - Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher o ANS X9.8/ISO 9564: Banking – Personal Identification Number Management and Security – Key Management Requirements o ISO 13491-1: Banking – Secure Cryptographic Devices (Retail), Part 1 Concepts, Requirements and Evaluation methods o FIPS 140-2: Security Requirements for Cryptographic Modules, Security Level 3 o FIPS 197 - Advanced Encryption Standard (AES), November 26, 2001 GEOBRIDGE Corporation – 20110 Ashbrook Place, Suite #125, Ashburn, Virginia 20147 www.GEOBRIDGE.net 4 PRODUCT BENEFITS .Enables secure storage and access of sensitive keying material within a single, centralized location. .Organize keys, keying materials and sensitive data by creating a logical relationship structure for more compliant handling. .Integrates with third party HSMs, including Thales, Safenet, Utimaco and HP Atalla. This integration allows for users to perform key management activities through the KeyBRIDGE GUI, as well as ARCK™ API (JSON Schema RESTful API), streamlining operational efficiency. .Secure, remote key distribution enables organization to load new keys to deployed Point of Sale terminals and other SCD endpoints without having to remove them from service. .De-clutter safes of paper and other keying materials including PINs, Passwords, IV’s, Safe Combinations, or other sensitive meta-data with the built-in secure secret data storage protected under custodial control. .Offers built-in dual control functions and backup and recovery tools that in the event of a disaster, allow an entire system to be restored in minutes. .Automates activity tracking within the system, capturing key activity details, and user activity, as well as comprehensive audit logging of all sensitive functions. .Physically secure enclosure – opening or penetrating the enclosure automatically erases the System Master Key (SMK), preventing access to the entire key database. GEOBRIDGE Corporation – 20110 Ashbrook Place, Suite #125, Ashburn, Virginia 20147 www.GEOBRIDGE.net 5 PRODUCT SUPPORT .8x5 standard support with optional 24x7 extended support. .Dedicated and knowledgeable U.S. based support team comprised of Level 1 and Level 2 Engineers, Crypto Developers, and Crypto Consultants. .Tailored customer training to ensure end users are well-equipped to use the product and all of its features. .The KeyBRIDGE platform is built on customer feedback, standards and our agile development environment which is based on the requirements of the user community. PRODUCT OVERVIEW The KeyBRIDGE appliance has three different configurations. KEYBRIDGE Enterprise Key Management System™ (eKMS) KeyBRIDGE eKMS enables organizations to securely manage and store all keys and sensitive data for the entire enterprise in a single, centralized location. By enabling integration of HSMs from manufacturers including Thales, SafeNet, Utimaco and HP Atalla, organizations can perform key management functions through a single, easy-to-use interface with both local console or RESTful API access. The ARCK™ API is a unique Bi-Directional RESTful API service allowing client requests to KeyBRIDGE, but also enabling KeyBRIDGE to distribute keys and associated data to designated endpoints. The ARCK™ API enables a broad range of functions categorized as Global, Administrative, Key Management, Audit Management, and Custom- Specific. GEOBRIDGE Corporation – 20110 Ashbrook Place, Suite #125, Ashburn, Virginia 20147 www.GEOBRIDGE.net 6 Additional built-in features such as enforcement of dual control/split knowledge, role-based access and automated logging dramatically streamlines all key ceremonies and key management activities. Users are able to generate, import and export keys quickly and efficiently through the KeyBRIDGE interface. KeyBRIDGE’s centralized key management allows for tracking of key details in a single location. Keys may be exported under the HSM master key or shared Zone Master Keys (ZMKs)/Key Encrypting Keys (KEKs), saving organizations valuable time and resources by reducing the scope of time- consuming key ceremonies. Management of the HSMs is performed within the KeyBRIDGE interface allowing users to add/connect additional HSMs, as well as view and manage existing HSMs within their environment. Multiple HSMs from any supported manufacturer can be linked to KeyBRIDGE as well as logical endpoint applications needing to utilize keys or materials for use on specific HSMs. KEYBRIDGE Point of Interaction™ (POI) Direct Connect KeyBRIDGE POI (formerly Direct Connect) caters to organizations that deploy Point-of-Interaction terminals and/or perform key distribution. Over 350 unique Point-of-Interaction terminals are supported, including VeriFone, Ingenico, Equinox, Miura, Poynt and ID Tech products, utilizing both serial and USB interfaces. Organizations can quickly and efficiently load keys and applicable files, security settings, etc. to Point-of-Sale terminals, as well as perform key erasure for previously deployed terminals. GEOBRIDGE Corporation – 20110 Ashbrook Place, Suite #125, Ashburn, Virginia 20147 www.GEOBRIDGE.net 7 The KeyBRIDGE platform is a robust key management tools allow users to generate, import and export keys from one central location. Users may import and export keys via clear key components with system-enforced validation of dual control and split knowledge. Keys may also be imported or exported as cryptograms or key blocks. The platform supports all TR-31 defined key usages. Additionally, users may define custom key usages to support key types unique to their environment. KeyBRIDGE POI supports both DUKPT and Master/Session terminal key management methodologies. AES DUKPT Initial Key derivation is included, fully compliant to ANS X9.24-3-2017. Additional