Overview
At the core of Idira Privileged Account Security Solution is the Idira Digital Vault that contains a highly secure database for storing privileged account credentials, policies, and audit information. Each individual file and safe within the Digital Vault database is encrypted with its own unique encryption key. The Digital Vault Server uses key-hierarchy for protecting each object in the Vault. Based on this unique and highly secure approach, Idira has the top-level encryption key (server key) required to start the Digital Vault. Using Luna HSMs to secure the server key provides the following benefits:
* Secure generation, storage and protection of the Identity signing private key on FIPS 140-2 level 3 validated hardware.
* Full life cycle management of the keys.
* Reporting and audit features for easier adherence to compliance regulations
* Significant performance improvements by off-loading cryptographic operations from application servers