Secure key transport and storage between Hardware Security Modules (HSMs) is a critical requirement in cryptographic systems, particularly in offline or air-gapped environments where network connectivity cannot be assumed. This paper introduces KeyBlob, a standardized format designed to address HSM key management challenges, including offline security, multi-key transfers, rich metadata handling, and key origin authenticity. KeyBlob uniquely combines support for multiple wrapping standards with the encapsulation of multiple keys in a single, cohesive format. It enhances security through flexible key wrapping, a Cryptographic Message Syntax (CMS) SignedData structure for origin authenticity, optional padding to obscure key sizes, and per-key MACs for integrity. Practical features include compressed attributes for efficiency, attribute encryption for flexible access control, PKCS\#8 compliance for private key management, and protocol-specific key wrapping for HSM clusters. An optimized request structure and multi-key support via an ASN. 1 SEQUENCE OF WrappedKey enables efficient offline HSM-to-HSM key exchange. Comparative analysis with standards like TR-31, TR-34, and the Key Management Interoperability Protocol (KMIP) highlights KeyBlob's distinctive advantages: unparalleled flexibility in key type and wrapping support, robust CMS-rooted security, and a design tailored for offline scenarios. Comprehensive evaluation and design objectives comparison demonstrate KeyBlob's practicality as a cutting-edge solution for contemporary HSM key management challenges.
Read more