Skip to content

Cryptography and keys

Key origin, custody, recovery and verification semantics.

availableAvailableReviewed 5 Sept 2026

Where are my cryptographic keys generated and stored?

Keys used for hardware-verified security are intended to be generated and protected in hardware-backed environments associated with the active form factor—card historically; SIM, eSIM or iSIM currently per company declaration. Exact generation location, custody model and export policy per deployment remain editorial tasks until engineering publishes confirmed details. This answer does not invent algorithms or key sizes.

unknownUnknownReviewed 5 Sept 2026

Can an organization control its own key infrastructure?

Organizational key control is a program design choice across enterprise, bank, government or telco custody models. Keyra documentation must state which models are supported, proposed or unavailable. Historical Cyber One workforce themes suggest enterprise relevance, but current supported custody options require confirmed product evidence before claiming full customer key control.

availableAvailableReviewed 5 Sept 2026

What happens if a device or key is compromised?

Compromise response should revoke or suspend affected credentials, rotate keys where supported, and re-enroll on a trustworthy form factor. Hardware-verified designs aim to contain software malware impact, but physical theft, insider misuse or flawed recovery can still create risk. Use only confirmed revocation channels.

availableAvailableReviewed 5 Sept 2026

How does recovery avoid bypassing the intended protection?

Safe recovery re-establishes hardware-backed credentials under policy instead of accepting a weak software-only bypass. Lost-device recovery should preserve the hardware trust boundary through identity checks, invalidating old keys and enrolling a new SIM, eSIM, iSIM or card instance—exact steps are product-specific.

availableAvailableReviewed 5 Sept 2026

What is a trust root in Keyra verification?

A trust root or trust anchor is the reference material a verifier uses to validate cryptographic evidence from a client or device. Public Keyra technology messaging describes SIM as a trust-anchor theme. Operational trust-store management belongs to platform operators and application publisher configuration.

plannedPlannedReviewed 5 Sept 2026

What distinguishes Keyra Vault Certified from Keyra Connected?

Keyra Vault Certified is framed as a target architecture for validated end-to-end hardware-rooted authorization unless later approved evidence establishes otherwise. Keyra Connected is a proposed capability with alternative authorization paths and must not inherit full Vault assurance claims. Wallet or network connectivity does not equal Vault Certified status.

availableAvailableReviewed 5 Sept 2026

Which certifications have actually been obtained?

This knowledge center does not invent certifications. Historical CyberONE public materials reference FIDO-oriented themes; that is not proof of a current Keyra certification listing. Until an approved certificate register is published, assume no independent certification claim beyond documented company declarations and public corroboration cited on each answer.

availableAvailableReviewed 5 Sept 2026

Does standards alignment equal certification?

No. Designing toward a standard or using standard vocabulary differs from holding an accredited certification for a specific product version and scope. Keyra answers may cite standards for education while keeping company declarations and independent assessments in separate provenance classes.

availableAvailableReviewed 5 Sept 2026

How should threat models mention SIM swap risks?

SIM-swap and subscription takeover risks matter for mobile identity. Hardware-verified security applications aim to raise the bar beyond SMS OTP, but recovery and operator processes still need hardening. Threat models should include device loss, insider misuse and flawed bypasses—without claiming systems are unhackable.

Cryptography and keys · Keyra FAQ