SVMK generation
To generate the Server master Key in an M of N scheme, the following is required:
- Definition of parameter N: the total number of cards that will be generated and distributed. This number can be between 2 and 16.
- definition of parameter M: the number of cards, out of the N generated, that will be requested to activate the HSM. This number must be between 2 and the number defined for N.
- N cards. If these already contain a Server master Key, the local console will request confirmation to overwrite it.
The parameters N and M must be provided; the maximum value for M displayed by the local console will depend on N.
Each Server Master Key generation is a unique process, as the output of the HSM's DRBG is used. There is no way for the operator to generate two identical Server Master Keys.
Warning
Immediately after generating the M of N set with the Server Master Key, try to make a copy(Copy Set) in a second set for security and to guarantee business continuity if the original set is lost or damaged. See Smart Card Management.
Based on the defined number of cards that will be part of the M of N scheme, the console will initiate prompts for card insertion and PIN entry for each card to generate the shared secret on each card (known as a shadow). The requested order is for reference and ease of use only; there is no defined order for presenting the cards during activation. At the end of the process, a notification message will confirm successful completion.
If the process is interrupted before the end, the console will issue an invalid set warning and inform you that the process must be restarted. In this case, the set should not be used to activate the HSM.
Dinamo - Local Management Console
┌──────────┤ M of N scheme ├──────────┐
│ │
│ │
│ Please, choose a value for 'N' │
│ │
│ N: ____ │
│ │
│ │
│ ┌────┐ │
│ │ OK │ │
│ └────┘ │
│ │
│ │
└─────────────────────────────────────┘
Service stopped Replication Domain: <none>
Dinamo - Local Management Console
┌───────────────┤ ├────────────────┐
│ │
│ Please, insert a valid smart card │
│ for shadow #1 of 2... │
│ │
│ ┌────┐ │
│ │ OK │ │
│ └────┘ │
│ │
│ │
└───────────────────────────────────┘
Service stopped Replication Domain: <none>
Dinamo - Local Management Console
┌─┤ You can provide a card label (optional) ├─┐
│ │
│ │
│ │
│ _________________________________ │
│ │
│ ┌────┐ ┌──────┐ │
│ │ OK │ │ Skip │ │
│ └────┘ └──────┘ │
│ │
└──────────────────────────────────────────────┘
Service stopped Replication Domain: <none>
Dinamo - Local Management Console
┌───────────────┤ ├────────────────┐
│ │
│ │
│ Server Master Key succesfully │
│ created with Scheme '2 of 2' │
│ │
│ │
│ ┌────┐ │
│ │ OK │ │
│ └────┘ │
│ │
│ │
└───────────────────────────────────┘
Service stopped Replication Domain: <none>