Share this article
Software-based key management requires protecting the computer system itself to prevent key compromise. HSM-based management protects the key at the device level, making it much harder to steal even if surrounding systems are compromised. For institutional custody, this architectural difference is fundamental. Regulatory examiners also tend to prefer HSM-based approaches because the physical security model is easier to assess than a software-only model.
An HSM vault is typically a physical location housing HSMs, with additional security measures such as biometric access, armed security, and environmental controls. HSM key management refers to the operational procedures for using HSMs, including key generation, rotation, and access control. Both are necessary. The vault protects the physical device. Key management procedures protect against misuse by authorised personnel.
Banks can use HSM-as-a-service for digital asset custody, but they must carefully evaluate the provider. Keys are stored on the provider’s HSM, so the bank’s security depends partly on the provider’s security practices. Large banks with significant digital asset positions typically operate on-premises HSMs to maintain direct control. Banks with smaller positions may use HSM-as-a-service to reduce operational complexity.
Banks typically rotate keys quarterly or semi-annually, depending on risk tolerance and regulatory requirements. Key rotation limits the window of exposure if a key is compromised. Rotation requires generating new keys, updating all systems to use them, and securely destroying the old keys. The process should be tested carefully to avoid lockout.