Master key store
Key Material
Where the issuer's master keys (from which per-credential keys are derived) are physically held. Best-practice is hardware-backed (HSM) with database-side keys wrapped by an external KMS. Wavelynx documents an HSM-rooted, KMS-wrapped, no-plaintext-at-rest pipeline; HID's public docs are silent on the equivalent — depth lives in NDA partner material.
What other systems call it
Per-vendor / per-standard terminology for this same concept.
| System | Term / Notes |
|---|---|
| HSM-rooted, KMS-wrapped Cloud SQL storage |