Kms Case Study - Mastercard: Centralized Key Management
Kms Case Study - Mastercard: Centralized Key Management
– MasterCard
unique administrative role and credentials. From here the operators can
update and configure the cryptographic keys on each individual Network
Security Platform (NSP) as well as enter new, shared network keys into all
boxes with just a click on a button.
MasterCard Europe
Jean Paul Boly
MasterCard Europe is a European banking organization which owns and MasterCard Europe
manages many of the most commonly used payment systems, includ- With the Key Management Centre we are able to reduce costs
ing Maestro, EC (EuroCheque), Cirrus, CLIP and Eurocard. MasterCard while increasing both network security and performance. We chose to
Europe is a subsidiary of Mastercard Corp. outsource the design and development of the KMC to Cryptomathic due
to their extensive knowledge and strong market position within e-Security
– especially cryptography. It was important to us that all relevant de facto
Managing the Keys and industry standards were followed to ensure interoperability through-
MasterCard Europe used to put much effort into maintaining the keys out the network and to guarantee our member banks a cost-efficient and
in their network. They had staff employed that would travel between highly secure infrastructure."
their hundreds of member banks and update the keys in their network
by entering them manually into each box in the distributed network. "The KMC is an extremely useful tool for updating and maintaining the
Today they manage this process centrally from their secured operations security in our networks – this is a good example of the efficiency that
venue with multiple and secure user authentication, each with their allows us to stay in the lead."
Strong User Authentication
KMC Clients
Secure Server Secure operations have been a design goal from the beginning of the
Room project. The KMC Server is located on a physically secured operations
KMC Secure
Client site to which only a limited number of system operators have access.
Smart cards are used in order to provide strong user authentication. All
sensitive operations must be performed within the secured area and
with the presence of multiple operators. All non-sensitive operations can
be carried out by auditors and operators who are not allowed on the
secured operations site.
KMC Server
HSM The first version of the KMC system was introduced in the spring of 2000.
Since then the system has been continuously extended and enhanced.
EPS-Net The KMC system allows a high degree of flexibility while preserving the
highest level of security for operating the Network Security Platforms.
Oracle Server
NSP NSP
Solution Overview
The KMC system is built around a three-tier architecture with an applica-
tion server (KMC Server), which provides services for a number of client
applications (KMC Client). An Oracle database server is used as reposi-
tory for the system. The KMC Server has a network interface to the NSPs
and uses a hardware security module to secure all keys.
The KMC system is primarily used for managing the system keys, e.g.:
CRYPTOMATHIC SIGNER
Cryptomathic Signer is an innovation in digitally signing and certifying
electronic documents, from emails through to pdf and any other docu-
ment type. The basis of the solution differs from other PKI implementa-
tions in that the user does not have to carry their private key around
with them or store it on their computer. Instead, they simply have to
authenticate themselves to the service and sign the relevant electronic
document within the server itself. This means that they are not only
signing exactly what they see but they also maintain the security of the
private signing key.
CRYPTOMATHIC AUTHENTICATOR
The Authenticator is an independent solution for a number of reasons.
Firstly, it is independent of token suppliers so customers are not tied
to any particular authentication vendors or technologies when choosing
the Authenticator. Secondly, the same level of independence applies to
HSMs, allowing the Authenticator to support the customer's preferred
HSM brands and models.
ABOUT CRYPTOMATHIC
Cryptomathic is a global provider of secure server solutions to business- market knowledge, with 2/3 of employees working in R&D, including an
es across a wide range of industry sectors, including banking, govern- international team of security experts and a number of world renowned
ment, technology manufacturing, cloud and mobile. With over 30 years' cryptographers. At the leading edge of security provision within its key
experience, we provide systems for Authentication & Signing, EMV, Key markets, Cryptomathic closely supports its global customer base with
Management and PKI & ID, through best-of-breed security solutions and many multinationals as longstanding clients.
services. We pride ourselves on strong technical expertise and unique