Skip to main content

DKE Key Management

Applies to:
DuoKey CockpitKey LifecycleMPC KeyStoreNIST SP 800-57

Overview​

With DuoKey - DKE, you can manage MPC-protected keys directly from the DuoKey Cockpit. This guide explains how to modify existing keys and the Double Key Encryption key lifecycle mechanisms.

Key Management Portal

1
Log in to DuoKey Cockpitcockpit.duokey.cloud
2
Open Key ManagementKeys tab

Vaults​

A Vault is a logical connection to a DuoKey MPC KeyStore (Partition).

Dedicated Space

Only you can access your keystore

Isolation

Complete separation from other tenants

Full Control

Manage your cryptographic keys

Learn more: Vaults

Key States​

The DKE-Key states follow the NIST SP 800-57 - Recommendation for Key Management, specifically Chapter 7: Key States and Transitions.

StateDescriptionAllowed Operations
Pre-ActiveKey generated but not yet in useCan be activated or deleted
ActiveKey is operational and can be usedEncrypt, Decrypt, can be deactivated
DeactivatedKey permanently disabledCannot be reactivated
CompromisedKey security has been breachedCannot be reactivated
Warning

Certain operations may permanently render the DKE-Key and any associated encrypted content inaccessible!

Creating a Key​

To create a key, follow the instructions under 1. Create Key and DKE Web Service.

Prerequisites

  • Generate an RSA-2048 key (the Microsoft DKE client does not support RSA-4096)
  • Set initial state to Pre-Active or Active
  • Set Usage to Decrypt
  • Set Enabled to True
Caution

Failure to configure these attributes correctly will prevent the key from being usable for decryption operations.

Blocking a Key (Usage)​

To block a key, click Actions next to the key you wish to block, then select Edit.

Blocking Options

Temporarily Block

Key can be unblocked later

Permanently Deactivate

Key cannot be unblocked

Temporarily Blocking a Key​

To temporarily prevent a key from being used for decryption operations, toggle the Enabled switch off.

Important

Do not change the Key State to Deactivated or Compromised if you only intend a temporary block.

Permanently Deactivating a Key​

To permanently block a key from use, change its Key State to either:

  • Deactivated, or
  • Compromised
Warning

Permanent Action: The key will not be deleted from the MPC — but once set to Deactivated or Compromised, it cannot be reactivated.

This operation is permanent and cannot be undone.

Any DKE-encrypted documents relying on this key may become permanently inaccessible!

Deleting a Key​

To delete a key, click Actions next to the key you want to delete, then select Delete.

This will permanently remove the key from the MPC.

Caution

A key can be deleted regardless of its state, but deletion is blocked while the key is still referenced by an active DKE 365 service — either as the service's current key, or as its previous key during the post-rotation overlap window. Disable or stop the service, or rotate it onto a different key, before deleting.

Key Storage and Key Attestation​

DuoKey MPC provides the capability to cryptographically verify the origin of cryptographic keys, ensuring they were generated and securely stored within a DuoKey MPC.

Note

By default, the DuoKey MPC cluster used in DuoKey is ECO-CH (located in Switzerland). If a different cluster is required to meet geographic or jurisdictional requirements, please contact DuoKey Support.

Generate Attestation​

1

Navigate to Key

In the DuoKey Cockpit, go to Key

2

Get Attestation Files

Select Get Attestation Files and Attestation Key

3

Download and Validate

Download the attestation files for validation

Attestation Proves

Origin

Key generated inside the MPC

Security

Key marked as non-exportable

The attestation can be reviewed and validated by the customer or an independent auditor to confirm compliance with security and operational policies.