Ceremonies Design for PKI's Hardware Security Modules

Jean Everson MartinaRicardo Felipe CustódioTúlio Cícero Salvaro de Souza

Ceremonies are a useful tool to HSMs in PKI environments. They state operational procedures and usage scenarios. Their correct construction can lead to a safer operation. This paper presents basic ceremony procedures to manage the life cycle of cryptographic keys and ideas of requirements needed to assure security throughout the usage of ceremonies in the context of an HSM implementing the OpenHSM protocols. It presents ceremonies to make the OpenHSM protocol operational establishing basic building blocks that can be used by any PKI application based in an HSM. Our main contributions are the re-usage of ceremony phases and a survey on formal methods to verify them.

