IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  GKLM in compliance with PCI standards, Key Block requirement

    Posted Mon January 09, 2023 11:52 AM
    Hi Team, a prospect customer is asking: Is GKLM in compliance with PCI standards, especially the Key Block requirement? https://docs-prv.pcisecuritystandards.org/PIN/Supporting%20Document/PIN_Security_Rqmt_18-3_Key_Blocks_2022_v1.1.pdf
    Does the solution have Remote Key Loading? Any clue? Thanks in advance.

    ------------------------------
    David Vicenteño Sanchez
    ------------------------------


  • 2.  RE: GKLM in compliance with PCI standards, Key Block requirement
    Best Answer

    Posted Fri January 20, 2023 09:04 AM
    I don't believe this is applicable to the key serving use cases that GKLM (nee SKLM) is used for. The FAQ for Key Blocks includes this text:
    "must be used for all PIN security-relevant symmetric keys exchanged or stored under another symmetric key - for example, Zone Master Keys (ZMKs), .......... and PIN-Encryption Keys (PEKs)".

    GKLM is typically used to serve keys used for various types of platform encryption. Examples include self encrypting storage hardware (flash/disk/tape), platform encryption for database servers, platform encryption for ESXi virtual machines, and for virtual storage such as Spectrum Scale (nee GPFS). The keys served by GKLM are not used to authenticate or identify individual users. The example of self-encrypting storage is instructional: the storage hardware itself performs all encryption and decryption of data at wire speed, using the key served from GKLM. From outside that storage device, it appears as if the data on that storage device is not encrypted. The main benefit is to ensure that if flash/disk is retired or returned for maintenance, or if a tape is lost in transit, no one outside your organization will ever be able to read it. So there is no concept of individual user authentication using these keys.

    ------------------------------
    Carl Hovi
    IBM
    ------------------------------



  • 3.  RE: GKLM in compliance with PCI standards, Key Block requirement

    Posted Fri January 20, 2023 12:40 PM
    Got it, Thank you very much Carl.

    ------------------------------
    David Vicenteño Sanchez
    ------------------------------