Skip to content

This section provides integration guides for all key management systems (KMSs) supported by Ripple Custody. Choose the KMS that best fits your security requirements, infrastructure, and operational capabilities.

Before you begin: Review Key management planning to understand the differences between HSM and MPC approaches and choose the right option for your organization.

s390x support

Starting in version 1.34, Ripple Custody supports s390x (IBM) architecture for secure components only, including the notary and vault. Non-secure components are not supported on s390x architecture. Contact your Ripple liaison if you have an existing deployment that includes non-secure components on s390x architecture.


Supported key management systems

Ripple Custody supports the following KMS platforms:

Cloud HSM

PlatformFIPS LevelDescriptionGuide
AWS CloudHSMLevel 3AWS-managed cloud HSM with FIPS 140-2 Level 3 validation. Deployed in your AWS VPC with Nitro Enclave isolation.AWS CloudHSM integration

On-premise HSM

PlatformFIPS LevelDescriptionGuide
BlockSafe HSMLevel 3Blockchain-optimized on-premises HSM with PKCS#11 interface.BlockSafe HSM integration
IBM LinuxONELevel 4On-premises HSM on LinuxONE with GREP11 API (for vault and notary components only). Highest FIPS certification level. Non-secure components are not supported on s390x architecture from version 1.34 onward.IBM LinuxONE integration
Securosys Primus HSMLevel 3On-premises HSM with scalable key storage (SKS), SLIP10 key derivation, and clustering and HA support.Securosys Primus HSM integration
Thales Luna HSMLevel 3On-premises HSM with scalable key storage (SKS), BIP32/SLIP10 key derivation, and HA group support.Thales Luna HSM integration

Multi-party computation (MPC)

PlatformDescriptionGuide
MPCDistributed key management using 3-of-4 threshold signing. Keys are split across 4 nodes (2 Ripple + 2 customer). No single point of failure.MPC integration