Cyber SecurityEncryptionHYOK

nCipher nShield – Host Your Own Key

nCipher nShield – Host Your Own Key

nCipher nShield - Host Your Own Key

Encrypting data at rest and in transit over the network is essential. Cryptographic keys provide the foundation of all encryption. These keys provide the cryptographic codes used to encrypt data, and the security and reputation of the keys supply the trust in the encryption process. The move to the cloud has not changed the need for strong encryption, nor the need for confidence in the cryptographic keys in use. Irrespective of where data resides and is used the need for strong encryption remains.

Some data is so sensitive that the regulations that govern its use and storage require that the cryptographic keys used to protect it are stored in a controlled security domain. This causes an issue when the IT systems and data are spread across both on-premise and public cloud providers.

Microsoft Azure Information Protection (AIP) is used to secure and protect data stored on Azure. It provides the ability to generate and store cryptographic keys. But what to do when data sensitivity or regulations require that the keys should be stored on-premise? The answer lies with nCipher's nShield hardware security modules (HSM). Microsoft AIP has an option called Hold Your Own Key (HYOK). This is enabled by having an on-premise component that provides key management. The nCipher HSM modules deliver this component and are fully integrated into Microsoft AIP to provide on-premise and hybrid cloud key management. Note that nShield as a Service cloud offering from nCipher can also securely host cryptographic keys outside of Azure. If that is an option that delivers on your HYOK security needs without having to deploy on-premise hardware.

Renaissance and nCipher can deliver solutions for all your cryptographic key needs. Contact us today to find out more. Read on for an overview of using nCipher HSMs for HYOK deployments.

Why Use nCipher HSMs with AIP for HYOK?

The core functionality of nCipher HSMs creates a controlled environment to manage cryptographic keys. This is true both for on-premise use and for use with AIP in the cloud. nShield is a hardware solution that manages keys independently from the software environment in use. As a result, there is complete control of the keys in use at all times.

When using Azure cloud services but with a need to hold keys within your security perimeter, the nCipher HSM will generate and store your key locally while integrating with cloud services via AIP. Giving the best of both worlds. This flexibility allows the use of AIP in a way that suits each organisation's security needs. All nCipher HSMs and use cases deliver:

  • Secure key generation and management within a FIPS 140-2 certified cryptographic boundary.
  • Robust access control mechanisms with enforced separation of duties, so the key is only used for its authorised purpose and by those who should have access.
  • Redundancy and resilience features to ensure that the keys are available when needed.
  • A hardened, tamper-proof key storage vault.
  • Compliance with regulatory requirements across all sectors and industries.
  • Store AIP generated keys on-premise if required.

nCipher nShield HSM options

The nCipher nShield HSMs are available in several configurations to match specific performance and budgetary needs:

  • nShield Connect - Rack-mountable HSMs that can provide cryptographic services to applications distributed across the network. Available in standard and high-performance models.
  • nShield Edge - USB connected HSM designed for use with desktop or laptop computers. Suitable for development workflows and standalone low volume key generation and management.
  • nShield Solo - A PCIe based card to insert in a PCI-Express slot within a PC or server. Ideal for use with existing hardware devices. Like Connect, the Solo card comes as a standard or a high-performance model.
  • nShield as a service - provides dedicated access to a nShield Connect HSM located in the cloud. It is licensed via a subscription model and can be self-managed or managed by nCipher as part of a managed service. This provides all the benefits of an HSM in the cloud and is ideal for cloud applications and organisations with a cloud-first deployment model.

Conclusion

nCipher nShield Hardware Security Modules are an ideal solution to generate and protect the crucial cryptographic keys used to secure data and other services. The integration with the Microsoft technology stack via Azure Information Protection make them the ideal choice to generate and store your own keys, or to store Azure generated keys on-premise if that's a requirement for your organisation.