Key features
The following keys are part of the Protegrity Key Management solution:- Key Encryption Key (KEK): A cryptographic key that protects other keys. The following keys are types of KEKs:
- Master Key: Protects the Data Store Keys and ESA Repository Key. In the ESA, only one active Master Key is present at a time.
- ESA Repository Key: Protects policy information in the ESA. In the ESA, only one active ESA Repository Key is present at a time.
- Data Store Key: Encrypts the audit logs on the protection endpoint. In the ESA, multiple active Data Store Keys can be present at a time.
- Data Encryption Key (DEK): A cryptographic key that encrypts the sensitive data for the customers.
- Codebooks: The lookup tables that tokenize the sensitive data.

