Skip to main content
Applies to:
Cockpit v2Securosys Primus / CloudsHSMFIPS 140-2 Level 3 · CC EAL4+

Overview​

Securosys is DuoKey's lead HSM partner. The backend connects to a Securosys Primus HSM (on-premise) or CloudsHSM (managed) through the Transaction Security Broker (TSB) REST API. It is the most fully-featured backend and one of only two that support post-quantum cryptography, performed in the HSM hardware.

PropertyValue
Vault typesecurosys_primus
TransportTSB REST API v1 over TLS
CertificationSwiss-made HSM — FIPS 140-2 Level 3, Common Criteria EAL4+ (vendor certifications)
Post-quantumYes — ML-KEM, ML-DSA, SLH-DSA in hardware

Configuration​

FieldPurpose
HostnameTSB base URL
bearer_tokenTSB API bearer token (encrypted at rest, zeroized in memory)
TLS validationControlled by the vault\'s host-validation flag; mTLS is available as optional transport authentication
Tip

Use the vault test-connection action to validate TSB connectivity and the bearer token before binding apps to the vault.

Supported keys and algorithms​

FamilyDetail
SymmetricAES-128 / AES-256 (GCM, 128-bit tag)
RSARSA-2048 / RSA-4096 — signing and OAEP-SHA256 encryption
ECCEC-P256 / EC-P384
MACHMAC-SHA256
Post-quantumML-KEM-512/768/1024, ML-DSA-44/65/87, SLH-DSA-128f/128s

Keys are created with hardware attributes — non-extractable and marked sensitive by default — and per-key toggles for encrypt/decrypt, sign/verify and wrap/unwrap.

Operations​

Securosys exposes the richest operation set of any backend:

Core crypto

Create, delete, get-public-key, encrypt / decrypt (AES-GCM and RSA-OAEP), sign / verify.

HMAC & key wrapping

Hardware HMAC, plus wrap / unwrap for secure key export and import between HSM keys.

Certificates

Generate a CSR, self-sign, and import certificates directly against HSM-held keys.

Entropy & introspection

Hardware TRNG random generation, plus license, version, HSM info and keystore statistics.

Signing covers RSA (PKCS#1 v1.5 and PSS with SHA-256), ECDSA (SHA-256), HMAC-SHA256, and the post-quantum ML-DSA / SLH-DSA families. The backend handles differences between Securosys sandbox and production environments transparently.

PQC certificate signing

Because Securosys signs post-quantum and hybrid algorithms in hardware, it can back a post-quantum PKI. Bind a PQC or hybrid CA to a Securosys vault to keep the signing key in the HSM — see Post-Quantum PKI.