Creation of the customer encryption key
During the creation of your corporate Connected account, the system makes a request to Connected Key Management Server (CMX-KMS) to create a customer encryption key. Connected stores the encrypted customer key on its servers for use in encrypting user-specific keys. The following figure illustrates the creation of the customer encryption key.
- Connected requests an encrypted customer key from CMX-KMS.
- CMX-KMS creates a key and sends it to the hardware security module (HSM) for encryption by the site's master encryption key.
- The HSM encrypts the key with the master key and returns the encrypted key to CMX-KMS.
- CMX-KMS returns the encrypted key to Connected, which stores it for future use.