All Products

bRUID Kms

Key Management System

PCI-DSS & PCI-PIN Compliant

The vault that protects
every key in your payment chain.

bRUID Kms is a comprehensive Key Management System for payment HSMs. It manages the complete cryptographic lifecycle - master key ceremonies, issuer key management, PIN translation, MAC validation, certificate authority operations, and multi-HSM failover - all within a tamper-resistant environment with zero plaintext exposure.

8+

Card Network CAs

3-Part

Master Key Ceremony

Dual Control

Split-Knowledge

Zero Plain

No Plaintext Exposure

Key Management

Complete Key Lifecycle

From master key ceremonies to issuer key distribution - bRUID Kms manages every cryptographic key your payment infrastructure requires.

Master Key Ceremonies

Three-part LMK generation with dual-control and split-knowledge. Import, generate, and activate via KMS screens or Trusted Path with full ceremony logging.

Transport Keys

Import and generate ZMKs and transport keys in cleartext or via Trusted Path. Symmetric and asymmetric transport with security level enforcement.

PIN Management

Secure PIN translation and encryption within the tamper-resistant boundary. PEK lifecycle management with zero plaintext exposure at any point.

MAC Validation

Message Authentication Code generation and validation for transaction integrity. Cryptographically signed clearing files for secure settlement.

RSA & ECC Keys

Generate, import, and manage asymmetric keys. RSA key generation with modulus export (MULTOS), ECC keys across supported elliptic curve domains.

Key Cache & Buffering

Local and remote key buffering for high-throughput scenarios. Configurable key cache with server parameters for key generation and buffer management.

Certificate Management

Every Card Network.
Every Certificate.

bRUID Kms manages Certificate Authority public keys, issuer certificates, and X.509 certificate chains across all major card networks. Import, endorse, and manage the full PKI lifecycle.

V
Visa
M
Mastercard
A
Amex
J
JCB
G
GCB
I
INTERAC
C
CUP
D
DFS
M
MULTOS
N
NSPK
E
ERCA
M
MSCA

Certificate Operations

Import CA Public Key

Load root CA keys from Visa, MC, Amex, JCB, GCB, INTERAC, CUP, DFS, MULTOS, NSPK

Endorse CA Key

X.509 CA public key endorsement via KMS screens or Trusted Path

Manage Issuer Certificates

Banking, Visa, MCI, GCB, JCB, Amex, INTERAC, CUP, DFS, MULTOS, NSPK certificate management

X.509 Certificates

Import, chain, endorse X.509 issuer public key certificates with P10 format support

PKCS#10 Profiles

Configure certificate request profiles for automated certificate signing

Key Profiles Export

Export key profiles for auditing, compliance documentation, and backup

Infrastructure

Enterprise HSM Infrastructure

Multi-HSM Support

Connect and manage multiple HSM devices simultaneously with unified key management

Load Balancing

Distribute cryptographic operations across HSM pool for high availability and throughput

Failover

Automatic failover between HSM devices ensuring continuous cryptographic service availability

IP Filtering

Configurable IP-based access control for KMS server connections and HSM administration

Trusted Path

Secure alternative to KMS screens for key ceremonies - tamper-evident key entry with hardware tokens

RBAC & SO Roles

Security Officer roles (SO1, SO2, SO3) with password-protected access and special identities

Backup & Restore

Full KMS database backup and restore with configurable backup locations and integrity checks

Audit Logging

Key Administration and Server logs with function usage tracking, key usage activity, and remote log config

Ecosystem

Integrated with BNPRS Products

Ready to Secure Your Payment Keys?

Deploy bRUID Kms as your cryptographic foundation - PCI-DSS and PCI-PIN compliant key management with zero plaintext exposure.