Many Cloud service providers allow users to bring their own cryptographic key material to the key management service. This is called Bring Your Own Key (BYOK). With the Cryptographic Security Platform Vault BYOK functionality, you can use CSP Vault to manage BYOK for your cloud providers.
When you use an HSM with BYOK, keys are never stored as plaintext.
- CSP Vault also encrypts (wraps) in-memory keys, except for software-protected keys in Azure.
- When a software-protected key has to be uploaded to Azure, CSP Vault unwraps it before upload.
- For other keys, including hardware-protected keys on Azure, when CSP Vault uploads them to the cloud, it encrypts (wraps) them in the HSM using the master key and the cloud provider's wrapping key before uploading the wrapped keys.
See below for managing BYOK.