Primus HSM CyberVault Core


Challenge
For some enterprises, securing sensitive cryptographic keys and executing critical security functions requires an HSM that meets the highest security standards while aligning with their operational needs. Traditional enterprise-grade HSMs often come with significant costs and infrastructure requirements, making them difficult to implement for organizations with budget constraints.
Many enterprises also struggle with the complexity of integrating HSMs into their existing infrastructure, managing cryptographic operations efficiently, and ensuring seamless scalability. Finding a solution that delivers uncompromising security, high performance, and adaptability is essential
.webp?length=1920&name=Image%20(1).webp)
Solution
The Securosys Primus HSM CyberVault Core (E2-Series) addresses these challenges with an enterprise-grade security solution that combines high performance, cost efficiency, and ease of use. It provides a standalone network appliance design that eliminates PCIe-based limitations, a high-performance cryptographic engine with scalable in-field upgrades, comprehensive support for industry-standard APIs to ensure seamless integration, advanced security measures including active tamper and transport protection, and secure remote management capabilities for streamlined administration.
.webp?length=1920&name=Image%20(1).webp)
Key Benefits

Unbeatable Price/ Performance ratio
The CyberVault Core delivers full network appliance functionality at a PCIe card price level, eliminating embedded HSM limitations.
Comprehensive Cryptographic Support
Supports RSA, ECC, EdDSA, and optionally supports all NIST-selected post-quantum cryptographic algorithms, including ML-DSA, SLH-DSA, ML-KEM,HSS-LMS, and XMSS, ensuring future-proof encryption.
Swiss Made
Crafted entirely in Switzerland, Securosys Primus CyberVault Core embodies unmatched quality and reliability. Free from external influences, our Swiss-made HSMs guarantee the highest standards from development to production, ensuring unparalleled security solutions.
Technical Specifications
- Multi-barrier software and hardware architecture with supervision mechanisms
- Secure supply-chain
- Post-Quantum Cryptographic (PQC) algorithms (optional)
ML-DSA, SLH-DSA, ML-KEM, HSS-LMS, XMSS - RSA 1024-8192, DSA 1024-8192
- ECDSA 224-521, GF(P) arbitrary curves (NIST, Brainpool, ...)
- ED25519, Curve25519
- Diffie-Hellman 1024, 2048, 4096, ECDH
- SHA-3/SHA-2 (224 - 512), SHA-1, RIPEMED-160, Keccak
- HMAC, CMAC, GMAC, Poly 1305
- 128/192/256-Bit AES with GCM-, CTR-, ECB-, CBC-, MAC Mode
- Camellia, ChaCha20-Poly1305, ECIES
- Two hardware true random number generators (TNRG)
- NIST SP800-90 compatible random number generator
- 2 partitions and 240MB total storage, fixed
- Number of client connections not restricted
- Unlimited number of backups
- Several sensors to detect unauthorized access
- Active destruction of key material and sensitive data on tamper
- Transport and multi-year storage tamper protection by digital seal
- Cryptographic evidence of audit relevant parameters (keys, configuration, hardware, states, logs, time-stamping)
- Multiple security officers (m out of n)
- Identification based on smart card and PIN
- JCE/JCA provider
- PKCS#11 provider and OpenSSLv3
- Microsoft CNG/KSP provider
- RESTful API
- IPv4/IPv6
- Interface bonding (LACP or active/backup)
- Active clustering of multiple units for load-balancing and fail-over
- Monitoring and log streaming (SNMPv2, syslog/TLS)
- Local configuration (console)
- Remote administration (Decanus Terminal)
- Local and remote firmware update
- Secure log and audit
- Enhanced diagnostic functions
Signing | |
RSA 2048 - 8192 | 25 |
EC 256 | 250 |
ED 25519 | 250 |
AES | 250 |
ML-DSA-44 | 25 |
Key Creation | |
RSA 2048 | 6 |
- Two redundant power supplies, hot pluggable 100 ... 240 V AC, 50 ... 60 Hz
- Power dissipation: 65 W (typ.), 100 W (max.)
- Backup lithium battery: Lithium Thionyl Chloride 0.65g Li, IEC 60086-4, UL 1642, 3.6V
- 4 Ethernet RJ-45 ports with1 Gbps (rear)
- 2 SFP+ slots for optical 10Gbps Ethernet modules (rear; optional)
- 1 Console ports (RJ45, rear)
- 1 USB-A management ports (rear)
- 1 USB-C management port (rear)
- 4 LEDs for system and interface status (multicolor)
- Console interface
- Optional Decanus Terminal for remote administration
- EMV/EMC: EN 55022, EN 55024, FCC Part 15 Class B
- Safety: IEC 62368-1
- Temperature ranges (IEC 60068-2-1 Ad, IEC 60068-2-2 Bd): storage -20 ... +60 °C; operation 0 ... +35 °C
- Humidity (IEC 60068-2-78 Cab): 40 °C, 93% RH, non-condensing
- MTBF (RIAC-HDBU-217Plus) at tamb=25 °C: >100 000 h
- Dimensions (w×h×d) 417×44×365 mm (1U 19" EIA standard rack)
- Weight 7.5kg
- FIPS140-3 Level 3 (in progress)
- Common Criteria EAL4+ (in certification)
- CC EN 419221-5 eIDAS protection profile
-
CE, FCC, UL
Related Products


