KMES Series 3
Encryption key management system
Encryption key management system
The Key Management Enterprise Server Series 3 is a powerful and scalable key management solution. It unites every possible encryption key use case – from root CA to PKI to BYOK – in a nexus of cryptographic utility. Automate and script key lifecycle routines. Secure private keys with a built-in FIPS 140-2 Level 3 validated HSM. Deploy it on-premises for tamper-proof control, or in the cloud for native integration with public cloud providers. The KMES Series 3 is the last word on encryption key management and is the cornerstone of enterprise cryptographic ecosystems around the world.
Manage encryption key lifecycles efficiently with sophisticated automation and scripting options. Reduce the manual effort involved with automated backups.
Establish a logically isolated cryptographic resource pool to be shared among different applications with the KMES Series 3’s segregated key containers.
Design a highly available network of Futurex devices which communicate via a common code base to synchronize encryption keys and certificates.
The KMES Series 3 stands alone among key management solutions. It is a dynamic, all-in-one key management tool with support for all common vendor-neutral APIs, flexible automation and scripting capabilities, and an embedded FIPS 140-2 Level 3 validated HSM.
This makes it fast to deploy, easy to integrate, and efficient to manage, all while adhering to the most rigorous physical and logical compliance requirements. With on-premises, cloud, and hybrid deployment options, your key management possibilities are virtually unlimited.
Click diagram to enlarge
Symmetric & asymmetric key management for 3DES DUKPT, X.509 v3, EMV and support for X9.17, AKB, and TR-31 (with custom fields).
Permission-based user access control enforces dual control and segregation of duties. Includes exportable user activity logs.
The intuitive user interface doesn’t require command-line tasks for initial setup, regular auditing, firmware upgrades, or maintenance.
The KMES supports mutual authentication under an offline root CA. It can generate and manage self-signed certificates to establish a trusted PKI.
Remotely distribute keys across ATMs and POS devices (including mobile POS) to reduce logistical and compliance burdens.
Automatically sign and send activity logs to a remote syslog server for internal and external audits.
Encryption is most effective when paired with smart encryption key management. But what makes for smart key management? At the end of the day, it comes down to finding a key management tool that centralizes management without compromising encrypted data.
Traditionally, organizations had to manage encryption keys using physical hardware security modules or some form of encryption key management software. Larger enterprises tend to have on-premises data security infrastructure to which they might add a physical key management server. But today, many organizations are migrating their applications to the cloud. This has led to a rise in cloud-based encryption key management systems as a cost-effective alternative to on-premises key management tools.
One of the main advantages of an efficient key management tool is centralization. By consolidating cryptographic operations into a single-vendor solution, it streamlines your ability to manage existing data security infrastructure and to deploy new encryption key management use cases, such as remote key loading (RKL), Bring-Your-Own-Key (BYOK), or external key management (EKM). It also allows enterprise organizations to integrate their systems with public cloud providers such as Amazon Web Services (AWS) or Google Cloud Platform (GCP).
With a trusted solution to manage cryptographic keys like the KMES Series 3, you don’t have to choose between maximal functionality or minimal cost. The inherent flexibility of the key management tool allows you to manage keys and encrypt data from a single hardware security module. It’s just one of many reasons why the KMES Series 3 is a true all-in-one encryption key lifecycle management solution.
VirtuCrypt key management services are backed by the KMES Series 3 with hardened, FIPS 140-2 Level 3 validated technology. Whether an organization requires complete infrastructure management or simply more functionality for existing Futurex infrastructure, VirtuCrypt offers a variety of service structures designed to meet security requirements.