{"templateId":"markdown","versions":[{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/deployment/integrate-kms/overview","default":true,"active":true,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/deployment/integrate-kms/overview","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/deployment/integrate-kms/overview","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/deployment/integrate-kms/overview","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/deployment/integrate-kms/overview","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/deployment/integrate-kms/overview","default":false,"active":false,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Integrate a key management system (KMS)","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"integrate-a-key-management-system-kms","__idx":0},"children":["Integrate a key management system (KMS)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This section provides integration guides for all key management systems (KMSs) supported by ","Ripple Custody",". Choose the KMS that best fits your security requirements, infrastructure, and operational capabilities."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Before you begin:"]}," Review ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/planning/key-management"},"children":["Key management planning"]}," to understand the differences between HSM and MPC approaches and choose the right option for your organization."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"s390x support"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Starting in version 1.34, ","Ripple Custody"," supports s390x (IBM) architecture for secure components only, including the notary and vault. Non-secure components are not supported on s390x architecture. Contact your Ripple liaison if you have an existing deployment that includes non-secure components on s390x architecture."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"supported-key-management-systems","__idx":1},"children":["Supported key management systems"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Ripple Custody"," supports the following KMS platforms:"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"cloud-hsm","__idx":2},"children":["Cloud HSM"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Platform"},"children":["Platform"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"FIPS Level"},"children":["FIPS Level"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Guide"},"children":["Guide"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["AWS CloudHSM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["AWS-managed cloud HSM with FIPS 140-2 Level 3 validation. Deployed in your AWS VPC with Nitro Enclave isolation."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/cloud-hsm/aws-cloudhsm"},"children":["AWS CloudHSM integration"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Securosys CloudHSM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Securosys-hosted CloudHSM option available through the Securosys/Ripple partnership."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Documentation in progress. Contact your Ripple account team."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"on-premise-hsm","__idx":3},"children":["On-premise HSM"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Platform"},"children":["Platform"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"FIPS Level"},"children":["FIPS Level"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Guide"},"children":["Guide"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["BlockSafe HSM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Blockchain-optimized on-premises HSM with PKCS#11 interface."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/on-premise-hsm/blocksafe"},"children":["BlockSafe HSM integration"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["IBM LinuxONE"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 4"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["On-premises HSM on LinuxONE with GREP11 API for vault and notary components. Non-secure components are not supported on s390x architecture from version 1.34 onward."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/on-premise-hsm/ibm-linuxone"},"children":["IBM LinuxONE integration"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Securosys Primus HSM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["On-premises HSM with scalable key storage (SKS), SLIP10 key derivation, and clustering and HA support."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/on-premise-hsm/securosys-primus"},"children":["Securosys Primus HSM integration"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Thales Luna HSM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["On-premises HSM with scalable key storage (SKS), BIP32/SLIP10 key derivation, and HA group support. Available as Luna Network HSM 7 appliance or Luna PCIe HSM 7 (A700) card."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/on-premise-hsm/thales-luna"},"children":["Thales Luna HSM integration"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"multi-party-computation-mpc","__idx":4},"children":["Multi-party computation (MPC)"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Platform"},"children":["Platform"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Guide"},"children":["Guide"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MPC"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Distributed key management using 3-of-4 threshold signing. Keys are split across 4 nodes (2 Ripple + 2 customer). Customer MPC nodes can be deployed in supported cloud environments, including AWS and Azure."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/integrate-kms/mpc/overview"},"children":["MPC integration"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"hsm-hardware-compatibility","__idx":5},"children":["HSM hardware compatibility"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following table lists the HSM hardware that ","Ripple Custody"," is validated against, and the minimum compatibility requirements for each vendor. The ","Ripple Custody"," KMS providers rely on vendor-specific key-derivation extensions, so the supported hardware for each vendor is the family that exposes those extensions."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Vendor"},"children":["Vendor"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"KMS provider"},"children":["KMS provider"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Supported hardware"},"children":["Supported hardware"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Minimum requirements"},"children":["Minimum requirements"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Certification"},"children":["Certification"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["IBM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ibm"]}," (GREP11 — EP11 over gRPC)"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["IBM Crypto Express (CEX) adapters running EP11/XCP firmware: CEX8S (IBM 4770) and CEX7S (IBM 4769). Older CEX6S (IBM 4768) and CEX5S (IBM 4767) adapters are also compatible."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Firmware with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CKM_IBM_BTC_DERIVE"]}," extension."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["FIPS 140-2 Level 4"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Thales"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["luna"]}," (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["libCryptoki2.so"]},")"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Thales Luna 7 generation: Luna Network HSM 7 models A700/A750/A790 and S700/S750/S790."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["SLIP-10 derivation (secp256k1, ed25519, P-256) requires firmware 7.8.7 or later and Luna client 10.7.1 or later."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["FIPS 140-2 and 140-3 Level 3"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Securosys"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["primus"]}," (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["libprimusP11.so"]},")"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Primus HSM X-Series and E-Series, and the Securosys CloudHSM service. All share one firmware line that exposes the required extensions."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Firmware exposing ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["C_DeriveKeyPair"]}," and persistent-external-object support."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["FIPS 140-2 Level 3, Common Criteria EAL4+"]}]}]}]}]}]},"headings":[{"value":"Integrate a key management system (KMS)","id":"integrate-a-key-management-system-kms","depth":1},{"value":"Supported key management systems","id":"supported-key-management-systems","depth":2},{"value":"Cloud HSM","id":"cloud-hsm","depth":3},{"value":"On-premise HSM","id":"on-premise-hsm","depth":3},{"value":"Multi-party computation (MPC)","id":"multi-party-computation-mpc","depth":3},{"value":"HSM hardware compatibility","id":"hsm-hardware-compatibility","depth":2}],"frontmatter":{"seo":{"title":"Integrate a key management system (KMS)"}},"lastModified":"2026-08-04T20:25:11.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/deployment/integrate-kms/overview","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}