Skip to main content

Key Management Definitions

Applies to:
TenantsOrganization UnitsVaultsKey States

Tenant​

A tenant is the top-level container for managing cryptographic keys. It typically represents an entire organization rather than an individual. Each key, vault, and application in DuoKey belongs to exactly one tenant. Tenants are completely isolated from each other.

Important

Keys, vaults, and applications cannot be moved between tenants. Multiple tenants are possible if you're certain that objects won't need to be shared or moved across them.

Organization Unit​

An Organization Unit in DuoKey corresponds to a business unit or department within a tenant. It represents a subdivision of an organization and is not tied to any specific user. Each vault belongs to one organization unit. Like tenants, organizations are isolated from each other.

Tip

Unlike tenants, vaults and applications can be reassigned between different organization units. Therefore, you can create multiple organizations within a tenant more flexibly.

Users​

Users are identified by their email addresses. A single user can belong to one or more organization units within a tenant.

For example, an employee may belong to:

  • A production organization unit
  • A testing organization unit
  • A personal development account

Depending on the user's role and assigned permissions, they can:

  • Manage users and vaults
  • Create keys
  • Modify key properties
  • Review activity logs
Note

Users cannot perform cryptographic operations themselves—only registered applications can execute those operations.

Roles​

DuoKey comes with a set of predefined roles per tenant, which can be customized independently to suit organizational needs:

RoleDescription
DKE-ServicesUsed by the DKE Web Service (e.g., Microsoft 365 Office Applications) to perform cryptographic operations. Limited to operational use and cannot perform administrative tasks.
DuoKey – HostReserved for DuoKey personnel responsible for tenant-level administration and support.
DuoKey – Tenant AdminCustomer administrator with administrative rights within the tenant. Can access DuoKey DKE Cockpit, create DKE Keys and Web Services, and manage users and groups.
DuoKey – AuditorA read-only role with access to view keys, services, and audit/activity logs. Ideal for compliance or monitoring purposes.

Keys​

A Key is stored within a DuoKey MPC Partition (Vault) and represents either a symmetric key or an asymmetric key pair. For asymmetric keys, both the private and public components are stored together in a single Key object.

Each Key belongs to exactly one Vault. Access to a Key is governed by the permissions assigned to the Vault it resides in. Users and applications that have access to the Vault can view and operate on its Keys.

Note

Users or applications not assigned to the Vault cannot see or interact with its Keys. For more details, see the Authorization section.

Key States​

The key states conform to NIST SP800-57 - Recommendation for Key Management - Chapter 7 Key States and Transitions

StateDescription
PreActiveKey is generated on the HSM but is not yet active. If an Activation time constraint is given, the key will automatically become Active when that time is reached.
ActiveThe key can be used for cryptographic operations and is the default state.
DeactivatedKey cannot be used for new encrypt operations but still needed to decrypt (e.g. old encrypted files)
CompromisedKey known or suspected to be compromised. This key should never be used again.
Warning

Keys that are in Deactivated or Compromised state cannot be re-activated!

Reference: NIST SP 800-57 Part 1 Rev 5 - Chapter 7 Key States and Transitions

Vaults​

A Vault is a logical container for grouping related Keys. All Keys in a Vault inherit the same Access Policies and Approval Policies, which are defined at the Vault level.

Multi-User Access

Multiple users and applications can be granted access

Security Boundary

Vaults serve as the security boundary for key access

Default Setup

At least one dedicated vault per Tenant

If more vaults are needed, please contact your sales representative, or open a request on the DuoKey Support Portal.

Apps (DKE Web Service)​

An Application refers to a non-human client—such as a service, daemon, or background process—that interacts with DuoKey. Applications (Microsoft 365 Office applications) authenticate to DuoKey using an API key (secret token).

Depending on assigned permissions, applications can:

  • Create keys
  • Modify key properties
  • Perform cryptographic operations using keys
Caution

Applications cannot perform administrative tasks such as managing users or assigning access to Vaults.

An application can be assigned to one or more Vaults. Once assigned, it gains permission to operate on all Keys within those Vaults.

Conditional Access Policy (Authorization)​

Conditional Access Policy enables fine-grained authorization for operations on entities such as Vaults, Keys, and Applications (Apps).

When an App interacts with a Vault or Key, the following security controls apply:

ControlDescription
Quorum ControlAllows enforcement of multi-party approvals (coming soon)
Role-Based Access Control (RBAC)App permissions are defined via roles assigned to it
Conditional Access PoliciesFine-tuned rules that govern what the App can do
Status ControlApps can be explicitly enabled or disabled

Commonly Applied Policies​

MFA Requirements

  • Require MFA for administrative roles
  • Enforce MFA for high-impact operations

Device Trust

  • Block access from unregistered devices
  • Require managed device compliance

Location Control

  • Require access from trusted network locations
  • Restrict or allow by geographic location

Risk-Based

  • Block risky sign-in behaviors
  • Detect impossible travel or anonymized IPs