Primus HSM E-Series
Challenge
Acquiring an HSM solution that maintains stringent security standards while staying within budget can be challenging. HSMs are crucial for safeguarding sensitive cryptographic keys and performing critical security functions, but they often come with a significantly high price tag. Finding the right balance between the need for robust security and cost-efficiency is key.
Solution
Primus E-Series HSMs offer an optimal solution for moderate scale HSM requirements where cost sensitivity is paramount. Primus E-Series HSMs do not compromise in regards of performance capabilities, functionality or usability. The Primus E-Series HSM is built as network appliance level and can serve as a cost-effective alternative to traditional PCI-e card HSMs, without the need and headache of additional surrounding hardware and software operation causing additional points of failure and costs.
Primus E-Series HSMS are available in three performance classes and are capable of in-field upgrades to the next performance level without the need to acquire a higher performance level device.
Key Benefits
Unbeatable Price/ Performance ratio
The Primus E-Series HSM delivers the functionality of full network appliances at a price comparable to PCIe card HSMs, but without their limitations or drawbacks.
In-built Security
High availability, clustering, automatic failovers, and load balancing at local or in a worldwide set-up is in-built in the HSM and does NOT require the installation of any additional software outside the HSM.
Swiss Made
Crafted entirely in Switzerland, Securosys Primus HSMs embody unmatched quality and reliability. Free from external influences, our Swiss-made HSMs guarantee the highest standards from development to production, ensuring unparalleled security solutions.
Use Cases
Technical Specifications
- Multilevel security architecture
- Internal hardware supervision for error-free operations
Authentication (extract)
- 128/192/256-Bit AES
with GCM-, CTR-, ECB-, CBC-, MAC-mode - Camellia, 3DES (legacy), ChaCha20-Poly1305, ECIES
- RSA 1024-8192, DSA 1024-8192
- ECDSA 224-521, GF(P) arbitrary curves (NIST, Brainpool,...)
- ED25519, Curve25519
- Diffie-Hellman 1024-4096, ECDH
- SHA-2/SHA-3 (224-512), SHA-1, RIPEMD-160, Keccak
- HMAC, CMAC, GMAC, Poly1305
- Post-Quantum Cryptographic (PQC) algorithms option CRYSTALS-Dilithium, CRYSTALS-Kyber, SPINCS+
- Two hardware true random number generators (TNRG)
- NIST SP800-90 compatible random number generator
- Key capacity: up to 6 GB
- E150 up to 50 partitions @ 120 MB capacity
- E60/E20 up to 10 partitions @ 120 MB capacity
- Number of client connections not restricted
- Unlimited number of backups
- Several sensors to detect unauthorized access
- Active destruction of key material and sensitive data on tamper
- Transport and multi-year storage tamper protection by digital seal
- Cryptographic evidence of audit relevant parameters (keys, configuration, hardware, states, logs, time-stamping)
- Multiple security officers (m out of n)
- Identification based on smart card and PIN using Decanus Terminal, or through virtual smart card
- JCE/JCA provider
- PKCS#11 provider and OpenSSLv3 provider
- Microsoft CNG/KSP
- REST (TSB module)
- IPv4/IPv6
- Interface bonding (LACP or active/backup)
- Monitoring and log streaming (SNMPv2, syslog/TLS)
- Active clustering of multiple units for load-balancing and fail-over
- Local configuration (GUI, console)
- Remote administration (Decanus Terminal)
- Local and remote firmware update
- Network attached storage data transfer (WebDAV option)
- Secure log and audit
- Enhanced diagnostic functions
(transactions per second)
Model | RSA 4096 |
ECC 256 |
ECC 521 |
AES 256 |
E150 | 2000 | 1500 | 300 | 600 |
E60 | 60 | 700 | 120 | 600 |
E20 | 20 | 350 | 60 | 200 |
- Power supply: 100 ... 240 V AC, 50 ... 60 Hz
E150 with two redundant hot pluggable power supplies - Power dissipation: 30 W (typ), 50 W (max)
- Backup lithium battery: Lithium Thionyl Chloride 0.65g Li, IEC 60086-4, UL 1642, 3.6V
- 4 Ethernet RJ-45-ports with 1 Gbit/s (rear)
- 1 RS-232 management port (rear)
- 1 USB management port (rear)
- Console interface
- 4 LEDs for system and interface status (multicolor)
- Optional Decanus Terminal for remote administration
- EMV/EMC: EN 55022, EN 55024, FCC Part 15 Class B
- Safety: IEC 62386-1
- Temperature ranges (IEC 60068-2-1 Ad, IEC 60068-2-2 Bd): storage -25 ... +70 °C; operation 0 ... +40 °C,
recommended +1 ... +30 ̊C - Humidity (IEC 60068-2-78 Cab): 40 °C, 93% RH, non-condensing
- MTBF (RIAC-HDBU-217Plus) at tamb=25 °C: 80 000 h
- Dimensions (w×h×d) 417 x 44 x 365 mm (1U 19" EIA standard rack)
- Weight 5,8 kg
- FIPS140-3 Level 3 (in progress)
- CC EN 419221-5 eIDAS protection profile
- CE, FCC, UL