A method for a plurality of key cache managers for a plurality of
localities to share cryptographic key storage resources of a security
chip, includes: loading an application key into the key storage; and
saving a restoration data for the application key by a key cache manager,
where the restoration data can be used by the key cache manager to
re-load the application key into the key storage if the application key
is evicted from the key storage by another key cache manager. The method
allows each of a plurality of key cache managers to recognize that its
key had been removed from the security chip and to restore its key. The
method also allows each key cache manager to evict or destroy any key
currently loaded on the security chip without affecting the functionality
of other localities.