What Is an HSM (Hardware Security Module)?

A hardware security module (HSM) is a dedicated, tamper-resistant device that creates, stores and uses cryptographic keys inside secure hardware. Applications send data to the HSM to be signed, encrypted or decrypted, and the private keys never leave the device in readable form.

Why keys need special protection

Whoever holds a private key can act as its owner. They can sign software, issue certificates or read encrypted data. A key stored as a file on a server can be copied by malware or by an insider.

An HSM keeps the key inside hardware that is built to resist and detect tampering. Copying the server does not copy the key.

What an HSM does

  • Generates keys with a strong random number generator
  • Stores keys, or wraps them with a master key that never leaves the HSM
  • Signs, encrypts, decrypts and wraps keys inside the device
  • Enforces roles and quorum rules (for example, 3 of 5 key holders), so no single administrator can act alone
  • Logs operations for audit
  • Supports secure backup and clustering for high availability

Types of HSM

  • Network appliances: shared by many applications over the network
  • PCIe cards: installed inside one server
  • USB or portable HSMs: often used for offline root CAs
  • Cloud HSM services: dedicated HSMs run by a cloud provider
  • Payment HSMs: built for card and PIN processing, with their own standard (PCI PTS HSM)

Cloud key management services (KMS) are different. They are shared, managed services, often backed by HSMs, and give the customer less direct control.

How applications talk to an HSM

  • PKCS#11: a widely used standard interface, published by OASIS and used by most CA and timestamping software
  • Java JCE/JCA providers for Java applications
  • Microsoft CNG for Windows services, including Microsoft’s CA
  • KMIP: an OASIS protocol for key management
  • Vendor REST APIs

Security certifications

  • FIPS 140-3 (NIST, used in the United States and Canada): four security levels. Level 3 is common for CA keys. FIPS 140-3 replaced FIPS 140-2, so for a new system, look for a current FIPS 140-3 validation.
  • Common Criteria (ISO/IEC 15408): for EU trust services, HSMs are often certified against the protection profile EN 419 221-5.
  • PCI PTS HSM: for payment HSMs.

Always check that the exact model and firmware version appear on the certificate.

Where HSMs are required or expected

  • Public certificate authorities: the CA/Browser Forum Baseline Requirements say a CA must protect its private key in a device validated to at least FIPS 140-2 or FIPS 140-3 Level 3, or to a suitable Common Criteria protection profile or security target at EAL 4 or higher.
  • Code signing: since June 1, 2023, the CA/Browser Forum code signing requirements say the private keys of publicly trusted code signing certificates must be generated, stored and used in a hardware crypto module.
  • eIDAS qualified trust services: Article 24 of the eIDAS Regulation requires qualified providers to use trustworthy systems and products that are protected against modification. See what a qualified trust service provider is.
  • Payments: PIN processing and card issuing.
  • Good practice: timestamping keys, document signing keys and the master keys for database encryption.

HSMs and post-quantum cryptography

NIST published its first post-quantum standards (FIPS 203, 204 and 205) in August 2024. Support for these algorithms depends on the HSM model and firmware. Check each vendor’s roadmap before you plan a migration.

How DictaLabs helps

The DictaLabs PKI consulting and HSM engineering team helps select the right HSM and design a secure architecture. Keys are generated, stored, rotated and retired following industry best practices. HSMs are connected to applications through PKCS#11, JCE and REST APIs, with high availability and disaster recovery.

DictaLabs CA integrates over PKCS#11 with Thales Luna, Entrust nShield, Utimaco CryptoServer, AWS CloudHSM, and Azure Key Vault or Managed HSM. It also supports software keystores for development and testing.

For application teams, the DictaLabs cryptographic APIs (crypto service) provide a REST-based layer for encryption, signing, hashing and key wrapping, so applications do not handle keys directly. The service connects to on-premises and cloud HSMs through PKCS#11, JCE and vendor-specific integrations, with high availability and failover.

Next step

Choosing or integrating an HSM? Talk to a DictaLabs expert.

Related