Securosys HSM
DuoKey's lead hardware security module — Primus / CloudsHSM over the Transaction Security Broker, with post-quantum support in hardware.
Overview
Securosys is DuoKey's lead HSM partner. The backend connects to a Securosys Primus HSM (on-premise) or CloudsHSM (managed) through the Transaction Security Broker (TSB) REST API. It is the most fully-featured backend and one of only two that support post-quantum cryptography, performed in the HSM hardware.
| Property | Value |
|---|---|
| Vault type | securosys_primus |
| Transport | TSB REST API v1 over TLS |
| Certification | Swiss-made HSM — FIPS 140-2 Level 3, Common Criteria EAL4+ (vendor certifications) |
| Post-quantum | Yes — ML-KEM, ML-DSA, SLH-DSA in hardware |
Configuration
| Field | Purpose |
|---|---|
| Hostname | TSB base URL |
bearer_token | TSB API bearer token (encrypted at rest, zeroized in memory) |
| TLS validation | Controlled by the vault\'s host-validation flag; mTLS is available as optional transport authentication |
Use the vault test-connection action to validate TSB connectivity and the bearer token before binding apps to the vault.
Supported keys and algorithms
| Family | Detail |
|---|---|
| Symmetric | AES-128 / AES-256 (GCM, 128-bit tag) |
| RSA | RSA-2048 / RSA-4096 — signing and OAEP-SHA256 encryption |
| ECC | EC-P256 / EC-P384 |
| MAC | HMAC-SHA256 |
| Post-quantum | ML-KEM-512/768/1024, ML-DSA-44/65/87, SLH-DSA-128f/128s |
Keys are created with hardware attributes — non-extractable and marked sensitive by default — and per-key toggles for encrypt/decrypt, sign/verify and wrap/unwrap.
Operations
Securosys exposes the richest operation set of any backend:
Core crypto
Create, delete, get-public-key, encrypt / decrypt (AES-GCM and RSA-OAEP), sign / verify.
HMAC & key wrapping
Hardware HMAC, plus wrap / unwrap for secure key export and import between HSM keys.
Certificates
Generate a CSR, self-sign, and import certificates directly against HSM-held keys.
Entropy & introspection
Hardware TRNG random generation, plus license, version, HSM info and keystore statistics.
Signing covers RSA (PKCS#1 v1.5 and PSS with SHA-256), ECDSA (SHA-256), HMAC-SHA256, and the post-quantum ML-DSA / SLH-DSA families. The backend handles differences between Securosys sandbox and production environments transparently.
Because Securosys signs post-quantum and hybrid algorithms in hardware, it can back a post-quantum PKI. Bind a PQC or hybrid CA to a Securosys vault to keep the signing key in the HSM — see Post-Quantum PKI.