---
sourceDocument: Xanadu Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/platform-security

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Cryptographic module overview

# Cryptographic module overview {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Cryptographic modules are the centerpiece of (KMF). They define the specific cryptographic mechanisms used for cryptographic operations for a given use case.
A cryptographic module applies the cryptographic mechanism of your choice to a use case that you define. For example, if you wanted to secure the data in your HR application with an AES-CBC with a 256-bit symmetric key, you can
create a module for that purpose.

Cryptographic modules also support key life-cycle management. You can create and rotate your cryptographic keys, and define your encryption method. Cryptographic modules are composed of the following components:  

Cryptographic specification
:   Defines aspects of your module, including its cryptographic purpose and which algorithms to use.

Cryptographic keys
:   The key your module uses to encode or decode cryptographic data. This can be a key generated by your instance, or a customer-supplied key you create and upload.

Module access policies
:   Module access policies are the access control mechanisms that place limits on whether data can be encrypted or decrypted.

Module policy exceptions
:   A control mechanism to define exceptions to a module access policy.

The following screen shows these high-level components in a cryptographic module:  
Figure 1. Cryptographic module components

For details on creating cryptographic modules, see [Create a cryptographic module](https://www.servicenow.com/docs/e7uHtVZdOrcU_PA0G4aFtg "Create a cryptographic module to define the mechanisms used for cryptographic operations. After you create the module, you create a cryptographic specification, where you define an algorithm for encryption and generates a key.").
**Related concepts**   

* [Module access policy overview](https://www.servicenow.com/docs/5sr41ReBxS5vVeECDWx8pA "Module access policies (MAPs) are access controls that you apply to your cryptographic modules. Use these access policies to decide which users and scripts can access data encrypted by a cryptographic module.")
* [Cryptographic specification](https://www.servicenow.com/docs/rd3B_Us3bL~uh19AqWTukQ "The Cryptographic specification is the component that defines aspects of your cryptographic module, including its cryptographic purpose and which encryption algorithm to use.")
* [Module access policy visualization](https://www.servicenow.com/docs/_4H5c1YzVJ4b4TJT~tFhKA "Use module access policy visualization to view all relevant cryptographic module information on a single UI page.")
* [Module access policy debugger](https://www.servicenow.com/docs/BX4vU083pXpDKfxxMfBBUw "Use the module access policy debugger to review logging information and understand why your users are or aren’t granted access to an encryption context.")  
**Related tasks**   

* [Configure field encryption settings to select key type](https://www.servicenow.com/docs/Oj3GdjNfBdasVv1lnh3fqQ "Configure your field encryption settings to use ServiceNow supplied keys or your own customer-supplied keys (CSK) for encryption on the ServiceNow AI Platform.")
* [Create a cryptographic module](https://www.servicenow.com/docs/e7uHtVZdOrcU_PA0G4aFtg "Create a cryptographic module to define the mechanisms used for cryptographic operations. After you create the module, you create a cryptographic specification, where you define an algorithm for encryption and generates a key.")
* [Create a module access policy](https://www.servicenow.com/docs/TLgW1ph7I9G8pGSRDbEj5A "Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.")
* [Create a cryptographic module life-cycle policy](https://www.servicenow.com/docs/BGWhczFujOviSej229y4Bw "Create a cryptographic module life-cycle policy to place limits on cryptographic modules, such as how long the key is good for. Create policies to safeguard cryptographic modules by limiting their exposure.")  
**Related reference**   

* [Instance level keys in the Key Management Framework](https://www.servicenow.com/docs/hxut9EJ6UvwBhFbH8eQk9w "The Key Management Framework (KMF) architecture introduces a key structure built with security in mind. Using a Hardware Security Module (HSM), KMF uses envelope encryption to ensure that all platform keys under KMF management are protected through a chain of keys. Customer Data Encryption Keys (CDEKs) created by KMF are also included.")
* [Key Management Framework key lifecycle states](https://www.servicenow.com/docs/hhFxgSjjVZpHdqOk2R~LOg "KMF supports several cryptographic key lifecycle states through the enforcement of specific allowable actions. For example, only keys that are in the active state can be used fully for their intended cryptographic purpose. The following table provides further detail on the varying key lifecycle states.")
* [Roles installed with Key Management Framework](https://www.servicenow.com/docs/AuUBbnZrrf0p1AfCaARBtA#kmf-roles "The Key Management Framework (KMF) introduces specific roles for cryptographic module and key management-related configurations.")

