Title: What is EKMI
1What is EKMI?
- Enterprise Key Management Infrastructure
- Take the tour
2Enterprise Key Management Infrastructure or EKMI
is a collection of technology, policies, and
procedures for managing all cryptographic keys in
the enterprise.
3EKMI is
A Single place to manage all keys
A Standard Protocol
Platform and Application Independent
Always available, even during network failure
Scalable to millions of clients
...and of course, extremely secure
4EKMI is comprised of
Public Key Infrastructure, or PKI
This is used for digital certificate
management, strong-autentication, secure storage,
and transport of symmetric encryption keys
Symetric Key Management System, or SKMS
SKS Server - for symmetric key management SKCL -
for client interactions with SKS Server
PKI
SKMS
EKMI
5Lets See How This All Works Together...
6Client
Server
Application Server
Application
Network
DB Server
SKCL
Crypto Module
Client Application makes a request for a
symmetric key
SKCL makes a digitally signed request to the SKS
SKS verifies SKCL request, generates, encrypts,
digitally signs escrows Key in the Database
Crypto HSM provides security for RSA Signing
Encryption Keys of SKS
SKS responds to SKCL with a signed and encrypted
symmetric key
SKCL verifies response, decrypts key and hands it
to the Client Application
7Since the Keys are generated and Leased at the
application level, data remains encrypted and
secure, not only at rest on the server, but also
through transit.
What does this mean in practical application...
8The Financial Solution
Bank Branch
Financial Institution
SKS Server
Bank Teller
ATM
Network
Central Database
Retail
Information can now be sent encrypted securely
over standard lines, and be decrypted at the
application level.
9The Helthcare Solution
Doctors Office
Hospital
Records
SKS Server
ER Application and Database
Doctors Tablet
Network
Patient Registration
EMT
ER Nurse
Patient Information can be shared securely and
quickly for efficient care.
EMT in Field
10Solutions to Symmetric Key Barriers
Slow
Multi-Core PCs
Complex
Higher Level APIs
Design Standards
Education
Expensive
Open Source
OASIS EKMI-TC
Lack of Standards
11But its not too late!
12OASIS EKMI-TC is driving new key-management
standards that cuts across platforms,
applications and industries.
Get involved!