A device that performs a set of key and metadata-management functions for at least one FCKMS and is associated with a cryptographic module. The device may be implemented as hardware, software, and/or firmware.
						                            Source(s):
						                            
								                            
                                                                
                                                                    NIST SP 800-152