Contact | Support | View Cart
 
Overview | Data Sheet | Buy Now

Overview - Hardware Security Modules

Organisations are increasingly turning to cryptography to establish identity, provide data confidentiality, prove data integrity and build trust. The appropriate use of cryptography to encrypt information, digitally sign documents and enforce digital rights is well proven and effectively unbreakable.

But cryptography relies on the use of keys; failure to protect and manage these cryptographic keys risks shattering an entire layer of security. Many organizations make the mistake of relying on ‘soft security’, leaving keys unprotected on general purpose servers, vulnerable to attack. Wherever cryptography is used to protect sensitive data, organizations must deploy ‘hard security’ controls to manage risk. Central to strong cryptographic security is the protection of keys within a Hardware Security Module (HSM).

nCipher’s range of HSMs protects cryptographic keys in a highly secure hardware environment, enabling them to be effectively managed and safely stored. Every nCipher HSM has received an independent FIPS 140-2 security validation, the de facto security benchmark for cryptographic modules.

nCipher’s Hardware Security Modules

nCipher HSMs use a common key management framework, nCipher’s Security World. This means nCipher HSMs are completely compatible with each other, allowing them to be configured in any combination to meet an organization’s management, security and budgetary needs. nCipher conducts extensive interoperability testing to ensure straightforward HSM integration with leading Web server, application server, PKI and other third party software security products.

All nCipher HSMs feature specialized cryptographic processors to perform CPU-intensive cryptographic operations. Off-loading these tasks from the host server dramatically increases server capacity and optimizes the performance of secure services and applications.

Dedicated HSMs and shareable HSMs

nCipher’s HSMs are available in two distinct deployment configurations: dedicated, directly-connected cryptographic modules, each attached to individual servers; and network-connected HSMs that can be shared by multiple servers.

 
 
tel: 1.800.368.6971 © Copyright 2005. Envoy Data Corporation