IBM Brings BYOK Support and Enhanced Encryption to IBM i 7.6
IBM has rolled out significant encryption key management changes in its latest IBM i 7.6 release. One of the major updates is bring-your-own-key (BYOK) support via IBM Key Protect for IBM Cloud, which will cater to regulatory requirements.
The new feature allows customers to import their existing symmetric keys and manage them from a central location using hardware security modules (HSMs). This service supports servers and applications running in the IBM Cloud as well as custom applications on-prem, provided there's a connection to the IBM Cloud. There are two versions of Key Protect: a standard tier for multi-tenant systems and a dedicated tier for single-tenant environments.
According to Tim Mullenbach, IBM i security business architect, the new BYOK feature works by tying in with the IBM Cryptographic Services API. Customers can 'wrap' their existing IBM i encryption keys by creating a new key in Key Protect, which will be stored locally but only accessible if Key Protect unlocks it.
IBM has also bolstered master key protection, requiring customers to change the default setting for master keys whenever they're set or modified. Master keys are now stored encrypted on disk, with encryption done by the save/restore key. Customers can cache their save/restore keys in Platform Key Store (PKS), introduced over a year ago.
The new changes will make it more complicated to perform IPLs following DR events, but they meet regulatory requirements and boost security.