Home Solutions Services About Us Discovery Contact Us

Strawinskylaan 411 1077XX,
Amsterdam, Netherlands

Wilhelmina van Pruisenweg 35,
2595 AN Den Haag

+31 6 11 10 62 26

[email protected]

CyberArk

Integration of CyberArk with HSM

The privileged accounts of organizations play an important role in today's cybersecurity ecosystem. Protecting these accounts and the critical resources they access has become crucial for organizations to manage, control, and audit all privileged account activities.

Estimated reading time: 5 minutes
By T.O. - Netsmart
 - 20 July 2020, Monday
In this blog post, we will explore how to strengthen the security of CyberArk by leveraging Hardware Security Modules (HSMs).

In this blog post, we will explore how to strengthen the security of CyberArk by leveraging Hardware Security Modules (HSMs).

The CyberArk Privileged Access Security solution facilitates the management of privileged accounts for organizations and establishes a secure structure. It enables the protection, monitoring, detection of activities, and intervention in events of privileged accounts from a single center. It manages the passwords of many privileged accounts, including Unix, Linux, and Windows-based systems, databases, virtual systems, network devices, SaaS, websites, and social media, and records, isolates, and controls sessions through RDP and SSH Proxies.

At the core of the CyberArk Privileged Account Security solution is the CyberArk Digital Vault, which securely stores privileged account credentials, access control policies, identity management policies, and audit information. CyberArk keeps all sensitive information in the Digital Vault, which is the heart of the CyberArk solution. It prevents the malicious use of privileged user accounts and ensures the organization and protection of privileged accounts. The Digital Vault controls access to these accounts according to the privileged account security policy, determining who can access which passwords and when, thus automating the process and eliminating errors and security risks associated with manual management of privileged accounts, ensuring compliance with audit and compliance requirements.

As sensitive data is transmitted between systems, it may be exposed to attackers listening in on the network. To prevent attackers from capturing privileged account credentials from intercepted traffic, CyberArk ensures that all data entering and leaving the Digital Vault is encrypted during transit. To protect both the Digital Vault database itself and the data stored within it, a multi-layered encryption hierarchy using FIPS 140-2 compliant cryptographic algorithms is designed. Symmetric encryption is completed using a unique AES-256 key, and asymmetric encryption is completed using a unique RSA-2048 key pair. When this level of encryption is applied, attackers within the network can see traffic flowing between CyberArk components, but the traffic is undetectable and therefore unusable for attackers.

Cyberark uses two external key groups in encrypting stored sensitive data. At the top of this key hierarchy is the Server Key. Safe Keys are encrypted using the Server Key. Data stored on the Cyberark Vault server is meaningless without the Server Key because the Server Key is required to start the decryption process. Recovery Keys are used to recover data when the Digital Vault is not operational. This key should be used only in very rare failure situations. The Recovery Key consists of a Public Recovery Key and a Private Recovery Key, forming an asymmetric key pair. The Cyberark key hierarchy is also illustrated below.

Since these keys provide access to the server and the data stored within it, it is recommended to store the Server Key on Hardware Security Modules (HSMs) that meet the FIPS 140-2 Level 3 standard to enhance the security of the Cyberark Privileged Access Security solution. Including a FIPS 140-2 certified HSM in the identity management solution maximizes the security of the entire infrastructure and ensures the confidentiality, integrity, and availability of critical corporate data.
Hardware Security Modules (HSMs) are specialized security hardware devices designed to store sensitive cryptographic keys in a physical environment and perform cryptographic operations in the most secure manner possible. These devices ensure that applications operate securely.

Integration of Cyberark with HSM prevents vulnerabilities in the key security layer. Since the Server Key acts as the key used to open a physical vault, the server requires the key every time it is started. Therefore, with Cyberark HSM integration, the Digital Vault can access the key via the HSM whenever needed, allowing the vault to start without the need for additional operational processes beyond storing the key in physical hardware. The position of the HSM in the topology of the Cyberark Privileged Access Security solution is illustrated below. All Vault servers in the Cyberark structure must be able to communicate with the HSM device.

An HSM can be integrated with the Cyberark solution in two ways: the existing Server Key can be loaded onto the relevant HSM device, or, for added security, a new Server Key can be generated on the HSM device.

  • If you are creating a new Server Key on the HSM, it must be a Network HSM, and access to this HSM is required for all Vault servers to obtain the key.
  • If you are loading the existing Server Key onto the HSM, each Vault server will require either a Network or Local HSM.

Integration of CyberArk Privileged Access Security Solution with HSMs;

  • It provides an additional layer of security to manage encryption keys used to access vaults or files.
  • It ensures the confidentiality, integrity, and availability of critical data.
  • It protects critical encryption keys used within the vault and hosted in a secure environment, reducing the risk of exposure or compromise.
  • It provides advanced key management, storage, and backup to ensure that keys are always accessible when needed.
  • It enhances operational efficiency by facilitating compliance with audit and data security regulations.

CyberArk can be integrated with any PKCS # 11 compliant HSM such as CyberArk Thales nShield, SafeNet Hardware Security Modules, and Utimaco CryptoServer.

Thanks for reading! Share this post if you found it helpful.

Post-Quantum Cryptography: A Strategic Roadmap for Cybersecurity

Thales

The rise of quantum computing introduces significant challenges to existing cryptographic systems.

More
In today’s post we’ll explain how to simulate Active Directory attacks using Splunk and various tools to improve an organization's security posture.

Simulation of Active Directory Attacks with Splunk

Splunk

In today’s post we’ll explain how to simulate Active Directory attacks using Splunk and various tools to improve an organization’s security posture.

More
In this blog post, we will cut through the confusion and explain the core differences between SIEM and SOAR, two essential security tools used to protect your organization.

SIEM vs. SOAR

Versus

In this blog post, we will cut through the confusion and explain the core differences between SIEM and SOAR, two essential security tools used to protect your organization.

More
In this blog post, we will explore how to strengthen the security of CyberArk by leveraging Hardware Security Modules (HSMs).

Integration of CyberArk with HSM

CyberArk

The privileged accounts of organizations play an important role in today’s cybersecurity ecosystem. Protecting these accounts and the critical resources they access has become crucial for organizations to manage, control, and audit all privileged account activities.

More