DKE Key Management
DKE Key Management
Manage MPC-protected keys and understand the Double Key Encryption key lifecycle
Overview
With DuoKey - DKE, you can manage MPC-protected keys directly from the DuoKey Cockpit. This guide explains how to modify existing keys and the Double Key Encryption key lifecycle mechanisms.
Key Management Portal
Vaults
A Vault is a logical connection to a DuoKey MPC KeyStore (Partition).
Dedicated Space
Only you can access your keystore
Isolation
Complete separation from other tenants
Full Control
Manage your cryptographic keys
Learn more: Vaults
Key States
The DKE-Key states follow the NIST SP 800-57 - Recommendation for Key Management, specifically Chapter 7: Key States and Transitions.
| State | Description | Allowed Operations |
|---|---|---|
| Pre-Active | Key generated but not yet in use | Can be activated or deleted |
| Active | Key is operational and can be used | Encrypt, Decrypt, can be deactivated |
| Deactivated | Key permanently disabled | Cannot be reactivated |
| Compromised | Key security has been breached | Cannot be reactivated |
Certain operations may permanently render the DKE-Key and any associated encrypted content inaccessible!
Creating a Key
To create a key, follow the instructions under 1. Create Key and DKE Web Service.
Prerequisites
- Generate an RSA-2048 key (the Microsoft DKE client does not support RSA-4096)
- Set initial state to Pre-Active or Active
- Set Usage to Decrypt
- Set Enabled to True
Failure to configure these attributes correctly will prevent the key from being usable for decryption operations.
Blocking a Key (Usage)
To block a key, click Actions next to the key you wish to block, then select Edit.
Blocking Options
Temporarily Block
Key can be unblocked later
Permanently Deactivate
Key cannot be unblocked
Temporarily Blocking a Key
To temporarily prevent a key from being used for decryption operations, toggle the Enabled switch off.
Do not change the Key State to Deactivated or Compromised if you only intend a temporary block.
Permanently Deactivating a Key
To permanently block a key from use, change its Key State to either:
Deactivated, orCompromised
Permanent Action: The key will not be deleted from the MPC — but once set to Deactivated or Compromised, it cannot be reactivated.
This operation is permanent and cannot be undone.
Any DKE-encrypted documents relying on this key may become permanently inaccessible!
Deleting a Key
To delete a key, click Actions next to the key you want to delete, then select Delete.
This will permanently remove the key from the MPC.
A key can be deleted regardless of its state, but deletion is blocked while the key is still referenced by an active DKE 365 service — either as the service's current key, or as its previous key during the post-rotation overlap window. Disable or stop the service, or rotate it onto a different key, before deleting.
Key Storage and Key Attestation
DuoKey MPC provides the capability to cryptographically verify the origin of cryptographic keys, ensuring they were generated and securely stored within a DuoKey MPC.
By default, the DuoKey MPC cluster used in DuoKey is ECO-CH (located in Switzerland). If a different cluster is required to meet geographic or jurisdictional requirements, please contact DuoKey Support.
Generate Attestation
Navigate to Key
In the DuoKey Cockpit, go to Key
Get Attestation Files
Select Get Attestation Files and Attestation Key
Download and Validate
Download the attestation files for validation
Attestation Proves
Origin
Key generated inside the MPC
Security
Key marked as non-exportable
The attestation can be reviewed and validated by the customer or an independent auditor to confirm compliance with security and operational policies.