Overview
ISO/TR 24374:2023 - Financial services - Security information for PKI in blockchain and DLT implementations provides guidance on managing cryptographic keys and public key infrastructure (PKI) considerations when deploying blockchain and distributed ledger technology (DLT) in the financial sector. The report focuses on the impact of different key management processes required for PKI in blockchain/DLT projects and addresses security, privacy, governance and operational activities relevant to financial services.
Key technical topics and requirements
- Key lifecycle and key management - Guidance on secure generation, storage, use and retirement of cryptographic keys in blockchain/DLT environments, recognizing differences from traditional centralized PKI.
- Private key storage and protection - Emphasis on strong key protection mechanisms such as Hardware Security Modules (HSMs) and secure elements, and the need to interface blockchain nodes with secure execution environments.
- PKI challenges and attacks - Discussion of threats to centralized Web PKI (e.g., CA compromise, revocation delays) and PKI-specific attack vectors relevant to blockchain systems.
- Security objectives and controls - Technical controls, cryptographic tool selection, and operational controls tailored to decentralized ledger architectures.
- Governance and operations - Roles, processes, risk analysis, legal risk considerations, and recommended organisational practices for managing PKI in DLT projects.
- Integration patterns - Summary of how asymmetric cryptography is used in blockchain networks and considerations for implementing blockchain-based PKI solutions.
- Standards references for crypto modules - Reference to secure cryptographic module standards (e.g., ISO/IEC 19790 for HSMs) and harmonisation with existing PKI practice.
Practical applications and users
Who will benefit:
- Financial institutions evaluating or operating blockchain/DLT solutions
- Security architects and PKI engineers designing key management for DLT
- Blockchain developers responsible for node security and wallet integrations
- Risk, compliance and legal teams assessing operational and legal risks of on‑chain keys
- Auditors and regulators reviewing cryptographic controls and governance
Typical uses:
- Designing secure key lifecycle management for token systems, payment rails, or settlement platforms built on DLT
- Choosing and deploying HSM-backed key storage and transaction signing infrastructure
- Performing risk assessments that account for irreversible, instantaneous exploitation of compromised keys
- Defining PKI governance, certificate issuance and revocation models adapted to decentralized ledgers
Related standards
- ISO 22739:2020 (DLT/blockchain vocabulary and concepts)
- ISO/IEC 19790 (cryptographic module security requirements - HSMs)
- ISO/TC 307 deliverables and ISO/DTR 23245 (related blockchain PKI work)
Keywords: ISO/TR 24374:2023, PKI, blockchain, DLT, financial services, key management, cryptographic keys, HSM, certificate authority, distributed ledger.