Primus S2-Series HSM (CH-HSM)
for SIC and SECOM Operations
Challenge
Securing the Swiss financial market and ensuring that funds are placed properly pose significant challenges. The IT infrastructure of the Swiss financial marketplace must adhere to the highest security standards to combat ever-growing threats. SIX Interbank Clearing manages the SIC interbank payment system, handling transactions worth around CHF 100 billion daily, along with the settlement of the SIX exchange.
Solution
To address these challenges, Primus S2-Series HSM has been specifically designed for the Swiss Interbank Clearing System operated by SIX SIC under the supervision of the Swiss National Bank.
These models are engineered to accommodate technological advancements and increased security and performance needs, crucial for the Swiss payment system. Primus S2-Series HSMs feature market-leading encryption and authentication performance, along with cryptographic algorithms that are secure against post-quantum computing threats. With this, Securosys and SIX underscore their dedication to fortifying the security and efficiency of Switzerland’s financial system.
There are three different models available:
- The S4 Model for entry level performance requirements but without multi-tenant support
- The S6 Model for medium level performance requirements and with multi-tenant support
- The S6P Model for high level performance requirements and with multi-tenant support
All models are PQC ready and can be managed by the Decanus Remote Access Management Device.
IMPORTANT INFORMATION REGARDING THE S500 HSM DEVICES
Please note, that the Primus S500 HSMs are no longer available for purchase and need to be exchanged to the current models until June 30, 2026. For detailed Information please refer to the SIC Extranet (Login required).
Key Benefits
SIX-tailored Security
Engineered specifically for SIX, the backbone of the Swiss Interbank Clearing System, the Securosys Primus HSM S2-Series delivers tailored security solutions for Swiss interbank clearing and settlement operations, alongside safeguarding SECOM, the Swiss stock exchange.
Swiss Made
Crafted entirely in Switzerland, Securosys Primus HSMs embody unmatched quality and reliability. Free from external influences, our Swiss-made HSMs guarantee the highest standards from development to production, ensuring unparalleled security solutions.
Use Cases
Securing Swiss Financial Transactions
The Primus HSM S2-Series offers industry-leading performance tailored for securing financial transactions. It is ideal for critical operations such as SIC, eSIC, and SECOM transactions, providing robust security through key generation, management, authentication, and encryption tasks.
The Securosys HSMs that have been in use since 2016, will be replaced by the latest generation of HSMs, offering enhanced performance and protection against Post-Quantum Cryptography (PQC) threats.
Technical Specifications
- Multi-barrier software and hardware architecture with supervision mechanism
Authentication (extract)
- 128/192/256-Bit AES
with GCM-, CTR-, ECB-, CBC-, MAC Mode - Camellia, ChaCha20-Poly1305, ECIES
- RSA 1024-8192, DSA 1024-8192
- ECDSA 224-521, GF(P) arbitrary curves (NIST, Brainpool, ...)
- ED25519, Curve25519
- Diffie-Hellman 1024, 2048, 4096, ECDH
- SHA-2/SHA-3 (224 - 512), SHA-1, RIPEMED-160, Keccak
- HMAC, CMAC, GMAC, Poly 1305
- Post-Quantum Cryptographic (PQC) algorithms CRYSTALS-Dilithium, CRYSTALS-Kyber, SPHINCS+
- Two hardware true random number generators (TNRG)
- NIST SP800-90 compatible random number generator
- Key capacity: up to 12 GB
- 1 partitions @ 240 MB secure storage upgradeable to max. partitions:
S6P 50 S6 10 S4 1
- Number of client connections not restricted
- Several sensors to detect unauthorized access
- Active destruction of key material and sensitive data on tamper
- Transport and multi-year storage tamper protection by digital seal
- Cryptographic evidence of audit relevant parameters (keys, configuration, hardware, states, logs, time-stamping)
- Multiple security officers (m out of n)
- Identification based on smart card and PIN
- JCE/JCA provider
- IPv4/IPv6
- Interface bonding (LACP or active/backup)
- Active clustering of multiple units for load-balancing and fail-over
- Monitoring and log streaming (SNMPv2, syslog/TLS)
- Local configuration (GUI, console)
- Remote administration (Decanus Terminal)
- Local and remote firmware update
- Network attached storage data transfer (WebDAV option)
- Secure log and audit
- Enhanced diagnostic functions
(transactions per second)
Model | RSA 4096 |
RSA 3072 |
ECC 521 |
ECC 384 |
S6P | 1000 | 2000 | 800 | 2000 |
S6 | 500 | 1000 | 400 | 1000 |
S4 | 25 | 50 | 25 | 50 |
- Two redundant power supplies, hot pluggable 100 ... 240 V AC, 50 ... 60 Hz
- Power dissipation: 60 W (typ), 100 W (max)
- Ultra capacitors for data retention
- Backup lithium battery: Lithium Thionyl Chloride 0.65g Li, IEC 60086-4, UL 1642, 3.6V
- 4 Ethernet RJ-45 ports with 1 Gbps (rear)
- 2 SFP+ slots for optical 10Gbps Ethernet modules (rear)
- 2 Console ports (RJ45, front/rear)
- 2 USB-A management ports (front/rear)
- 1 USB-C management port (rear)
- 3 Smart card slots
- 3 slots for Securosys Security smart cards
- 4 LEDs for system and interface status (multicolor)
- Touch screen for configuration
- Console interface
- Optional Decanus Terminal for remote administration
- EMV/EMC: EN 55022, EN 55024, FCC Part 15 Class B
- Safety: IEC 62386-1
- Temperature ranges (IEC 60068-2-1 Ad, IEC 60068-2-2 Bd): storage -20...+60 °C; operation 0...+35 °C
- Humidity (IEC 60068-2-78 Cab):
40 °C, 93% RH, non-condensing - MTBF (RIAC-HDBU-217Plus) at tamb=25 °C: >100 000 h
- Dimensions (w×h×d) 417×44×365 mm
(1U 19" EIA standard rack) - Weight 7.5 kg
- CE, FCC, UL