Hardware Security Module
13.1.6 Secure Auditing for HSM
Image 67: Secure auditing for HSM
To enable Secure Auditing for HSM, a Master Audit Keypair will have to be created on the HSM. This must be
performed before configuring IDENTIKEY ApplianceIDENTIKEY Appliance for Secure Auditing.
The public key from the Master Audit Keypair must be exported from the HSM to allow its use in verification.
IDENTIKEY ApplianceIDENTIKEY Appliance will request a signature from the HSM for each epoch, and this will be
used as an epoch ID. An epoch keypair will be generated, consisting of an epoch public key and an epoch private
key. Each Secure Audit entry will contain the epoch public key, the epoch ID and an cryptographic signature which
relates it to the previous and subsequent entries.
To verify the Secure Audit entry, the verification tool will require:
the epoch public key
the epoch ID (supplied on each secure audit line)
the master audit public key which has been exported to a
.pem
file.
The entire file will be verified with a
Yes (verification successful)
or
No (verification unsuccessful)
result provided
after verification.
IDENTIKEY Appliance Installation and Maintenance
105