Hardware Security Modules What they are and why it's likely that - - PowerPoint PPT Presentation

hardware security modules
SMART_READER_LITE
LIVE PREVIEW

Hardware Security Modules What they are and why it's likely that - - PowerPoint PPT Presentation

Hardware Security Modules What they are and why it's likely that you've (indirectly) used one today Insert Your Name Insert Your Title Insert Date RWC 2015 Paul Hampton 8 th January 2015 What Am I Going to Talk About? What Is A Where Will


slide-1
SLIDE 1

Insert Your Name Insert Your Title Insert Date

Hardware Security Modules

What they are and why it's likely that you've (indirectly) used one today

RWC 2015 Paul Hampton 8th January 2015

slide-2
SLIDE 2

What Am I Going to Talk About?

What Is A HSM? Where Will I Find One?

slide-3
SLIDE 3

A Hardware Security Module is…

…a dedicated crypto processor… …designed for the protection of keys throughout their lifecycle… …validated as secure by third parties… …a Trust Anchor…

slide-4
SLIDE 4

A Hardware Security Module is…

…a source of high quality random numbers… …a vault for holding cryptographic keys…

…Cryptographic Acceleration Hardware…

…a hardware solution that implements the cryptographic algorithms you want to use…

slide-5
SLIDE 5

How is a HSM deployed?

Application Servers

Application Crypto Services Key Management Services Key Vault Services

Tamper Resistance/Response Separation of Duties MFA with M of N Controls PKCS #11 CAPI / CNG Java CSP OpenSSL XML-DIGSIG Backup/Restore Access Controls Export Controls EKM Interface Policy Def’n and Enforcement FIPS 140-2 Level 3 Common Criteria EAL4+

Offload Multiple Partitions

Availability and Load Balancing

Cryptographic Processing

Security Officer Application Owner Auditor IT Admin

Role Separation Certifications

slide-6
SLIDE 6

Certifications

  • Provide independent verification of the security of a HSM

6

Common Criteria

slide-7
SLIDE 7

Physical Security Features

Features of a Validated HSM Appliance

Intrusion detection Tamper Resistant Fasteners Tamper Resistant Fan Mounts Tamper Resistant I/O Mounts Serialised Tamper Evident Labelling Internal Baffles to Prevent Probing Protected Electronics

slide-8
SLIDE 8

HSM Form Factors

slide-9
SLIDE 9

So What Do HSMs Get Used For?

  • 1. Secure Documents
slide-10
SLIDE 10

HS HSMs secur ure e passpor

  • rt

t issuance uance

slide-11
SLIDE 11

HSM SMs secur ure e documents ents for governm nment ents, s, hospitals, itals, and the cour urt system tem

slide-12
SLIDE 12

Secure Manufacturing

slide-13
SLIDE 13

HSM SMs secur ure e enter ertai ainmen ment t devices, ices, includin cluding g video eogam game e consoles soles and Person sonal al Video eo Recor

  • rder

ers

slide-14
SLIDE 14

HSM SMs secur ure e Sm Smart Meteri ering g Sy System ems s and the deliver ivery y of Meter er messages ages in our homes s to H Head d End Utility ility systems ems

slide-15
SLIDE 15

Banking and Payments

slide-16
SLIDE 16

HSM SMs secur ure e mobile le money y paymen ments ts and verbal bal banking king transac nsactio tions s made by teleph ephone

  • ne
slide-17
SLIDE 17

HSM SMs secur ure e card data and the deliver ivery y of Personal

  • nal Identific

ificatio ation n Number ers s (P (PINs) s)

slide-18
SLIDE 18

HSM SMs secur ure e the production uction of credit edit and debit it cards ds and mobile le phone SI SIM cards. ds.

slide-19
SLIDE 19

And Yet More Payments Use Cases…

slide-20
SLIDE 20

HSM SMs secur ure e SS SSL for the websit sites es we use every y day

slide-21
SLIDE 21

Transport and Infrastructure

slide-22
SLIDE 22

HSM SMs secur ure e Devic vice e Manufacturing ufacturing in the deliver livery y of Trust usted ed Devic vice e Identities ities we used Ever ery y Day

slide-23
SLIDE 23

Railway lway signalli nalling g infras rastruct tructur ure e is secur ured ed by Hardwar ware e Se Security urity Modules les

slide-24
SLIDE 24

HSM SMs are used to p protec ect t the communication unication protocols

  • cols for large

ge industri strial al equipm pment ent

slide-25
SLIDE 25

HSM SMs secur ure e the softwar are e and physical sical component nents s of safety ety critica itical l systems tems

slide-26
SLIDE 26

HSM HSM HSM HSM HSM HSM HSM HSM

slide-27
SLIDE 27

HSM SMs secur ure e automated ated toll l booth passes es

slide-28
SLIDE 28

Online Content

slide-29
SLIDE 29

HSM SMs secur ure e the deliver ivery y of streamin eaming g media

slide-30
SLIDE 30

Thank You!