HSM Authentication Model with Two PED PINs

Here is a picture of a PED authenticated HSM, where two different PED Keys generate the same PinKey to unlock the HSM. The secrets contained on the PED Keys are different. The PED PINS used to make those secrets into the PinKey are different. The same model scales up to any number of PED Keys. You can have identical copies of blue PED Keys to unlock the HSM, or you can have different "copies" that still unlock that same HSM, so long as the combination of PED Key secret contained on any key and the PED PIN used with it are able to generate the same PinKey outcome.

An HSM being unlocked by two PED Key "copies" that carry different secrets and have different PED PINs, yet generate the same PinKey that the HSM needs.

 

This Help also has similar diagrams with:

   

See Also