Skip to main content

Why DuoKey Software-Defined HSM?

Enterprise Key Management

DuoKey Software-Defined HSM

A Software-Defined HSM delivers the same security guarantees as a traditional Hardware Security Module — but entirely in software, powered by Multi-Party Computation (MPC). Instead of locking keys inside a single physical appliance, DuoKey distributes AES key shares across multiple independent nodes so the complete key never exists in any single location.

< 5msLatency
99.99%SLA Uptime
3+Regions
10K+Ops/sec/node

Deployment Options

Software-Defined HSM

Default

Distributed AES key management using MPC across multiple cloud regions or data centers. No hardware required, deploy in hours.

HSM-backed

Optional

Integrates with Securosys HSM (Swiss vendor, FIPS 140-2 Level 3 & 4), Atos TrustWay, Fortanix, and Utimaco.

Supported Vault Backends

DuoKey MPC

DuoKey MPC

Multi-Party Computation

FIPS-approved
DuoKey SD-HSM

DuoKey SD-HSM

Software-Defined HSM

MPC Cluster
Securosys CloudHSM

Securosys CloudHSM

Swiss Cloud HSM

EU Residency
HashiCorp Vault

HashiCorp Vault

Secrets Engine

Native
OpenBao

OpenBao

Open-Source Vault

Vault-Compatible
Azure Key Vault

Azure Key Vault

Microsoft Azure

Managed HSM
AWS KMS

AWS KMS

Amazon Web Services

CloudHSM
Google Cloud KMS

Google Cloud KMS

Google Cloud

Multi-Region
Fortanix SDKMS

Fortanix SDKMS

Confidential Computing

Intel SGX
Atos TrustWay HSM

Atos TrustWay HSM

Hardware HSM

ANSSI Qualified
Crypto4A QxHSM

Crypto4A QxHSM

PQC-Ready HSM

Quantum-Safe
Utimaco HSM

Utimaco HSM

Hardware HSM

EAL5+

Software-Defined HSM Architecture

Client ApplicationAES Encrypt / Decrypt
HTTPS / TLS 1.2+
DuoKey CockpitAPI Gateway & Load Balancer
MPC Protocol — Parallel Distribution to All Nodes
United States · AWS us-east-1
Docker Node 1Key Share 1/3Admin Team A
European Union · Azure eu-west-1
Docker Node 2Key Share 2/3Admin Team B
Switzerland · Swiss Data Center
Docker Node 3Key Share 3/3Admin Team C

Cryptographic keys distributed across 3 sovereign regions — never complete anywhere

Zero-KnowledgeComplete key never reconstructed
Admin SegregationDifferent teams per region
Sub-5ms LatencyParallel MPC computation
Data SovereigntyComply with local regulations

No Single Point of Failure

  • Keys never exist in complete form
  • Operations distributed across 3+ nodes
  • One compromised node ≠ compromised keys
  • Multi-cloud provider distribution

Software-Based Security

  • No expensive HSM hardware
  • Lower total cost of ownership
  • Faster deployment and scaling
  • Cloud-native architecture

High Availability

  • Active-active across regions
  • Automatic failover (< 1s)
  • Horizontal scaling on-demand
  • Sub-millisecond operations

Geographic Distribution

  • Deploy across AWS, Azure, GCP
  • Resilient to regional outages
  • Data residency compliance
  • Global load balancing

Traditional HSM vs Software-Defined HSM

Traditional HSM vs Software-Defined HSM

12 criteria
FeatureTraditional HSMDuoKey Software-Defined HSM
Security ModelHardware-based Cryptographically distributed
Single Point of FailureYes (HSM device) No (distributed keys)
Geographic DistributionLimited Native multi-region
CostHigh ($$$$) Low ($)
Deployment TimeWeeks Hours
ScalingVertical (buy more HSMs) Horizontal (add nodes)
Cloud NativeNo Yes
Disaster RecoveryComplex Automatic
PerformanceLimited by hardware Software-optimized
ComplianceFIPS 140-2 Level 3 Cryptographically equivalent
Vendor Lock-inHigh None
Multi-CloudDifficult Native

How the Software-Defined HSM Works

Cryptographic keys are never stored or reconstructed in a single location

  1. Key Generation

    Keys are generated in a distributed manner across multiple nodes simultaneously

  2. Key Shares

    Each node holds only a "share" of the key — never the complete key

  3. AES Encrypt/Decrypt

    Distributed AES encryption and decryption operations across nodes

  4. Zero-Knowledge

    No single node ever sees, stores, or can reconstruct the complete key

  5. Geographic Distribution

    Nodes deployed across different cloud providers and sovereign regions

Deployment Architecture

Cloud Deployment

Recommended
  • 3 Docker images across 3 cloud providers (AWS, Azure, GCP)
  • Automatic failover and load balancing
  • Geographic redundancy out of the box
  • Managed infrastructure

On-Premises Deployment

  • 3 Docker images across 3 separate data centers
  • Administrative segregation (different admin teams per DC)
  • Physical separation — no single point of compromise
  • Full control over infrastructure

Hybrid Deployment

  • Mix of cloud and on-premises nodes
  • Example: AWS + Azure + On-Prem DC
  • Maximum flexibility for compliance requirements
Key Requirements
Minimum 3 separate locations
Administrative segregation per node
HTTPS / TLS 1.2+ between nodes
Docker or Kubernetes runtime
No shared storage or dependencies

Security Guarantees

Distributed Security

  • Keys split across multiple independent nodes
  • Compromise of a single node does not expose the key
  • Significantly increases attack difficulty vs single HSM
✓ Node 1
✓ Node 2
Node 3
System remains secure even if one node is compromised

Information-Theoretic Security

  • Individual key shares reveal zero information about the key
  • Even with unlimited computing power, a single share is useless
  • Security based on mathematical principles, not computational hardness
1 Share
=
Zero Knowledge

Use Cases Across DuoKey Products

Transparent Data Encryption

Oracle TDE
  • MPC-protected master keys
  • Auto-login (no manual ops)
  • Geographic HA redundancy
Learn more →
SQL Server EKM
  • TDE with MPC-protected keys
  • DBA/security separation of duties
  • Centralized multi-DB management
Learn more →

Cloud Key Management

AWS XKS Proxy
  • External Key Store for AWS KMS
  • Double encryption: AWS + MPC
  • Full key control in AWS
Learn more →
Salesforce BYOK
  • Shield Platform Encryption
  • Customer-controlled tenant secrets
  • Data sovereignty & revocation
Learn more →

Secrets Management

HashiCorp Vault
  • MPC backend storage
  • Auto-unseal with distributed trust
  • No single key compromise point
Learn more →
OpenBao
  • Open-source Vault alternative
  • MPC-backed secrets engine
  • Community-driven development
Learn more →

Data Security & Compliance

Varonis DSPM
  • Data classification + MPC encryption
  • Privacy-preserving analytics
  • GDPR, CCPA compliance
Learn more →
Netwrix DLP
  • DLP with MPC keys
  • Sensitive data protection
  • Insider threat prevention
Learn more →

Contact Center & Digital Signatures

Genesys LKM
  • Call recording encryption
  • PCI DSS compliance
  • Real-time encrypt/decrypt
Learn more →
PDF Sign & PKI/SSL
  • Qualified e-signatures (eIDAS)
  • Private CA with MPC keys
  • Certificate lifecycle management
Learn more →

Benefits: Software-Defined HSM vs Traditional HSM

Total Cost of Ownership

Traditional HSM
  • Hardware purchase + maintenance contracts
  • Specialized HSM administrators & consultants
  • Professional services for setup, updates
  • Data center space, power, cooling
  • Complex multi-site redundancy (2-3x cost)
  • Manual processes, no IaC support
  • Limited DevOps/CI-CD integration
DuoKey Software-Defined HSM
  • No hardware purchase or maintenance
  • Self-service management via API
  • Full IaC support (Terraform, Ansible)
  • Native DevOps/CI-CD integration
  • Multi-region by default, auto failover
  • Zero professional services for routine ops
  • Elastic, pay-as-you-grow scaling
Key Differentiator: While licensing costs may be similar, DuoKey Software-Defined HSM significantly reduces operational overhead, eliminates specialized personnel, and provides modern DevOps capabilities that HSMs cannot match.

Deployment Speed

Traditional HSM
  • Procurement: 4-8 weeks
  • Hardware setup: 1-2 weeks
  • Configuration: 1-2 weeks
  • Testing & validation: 2-4 weeks
  • Total: 2-4 months
DuoKey Software-Defined HSM
  • Cloud deployment: 1-2 hours
  • Configuration: 4-8 hours
  • Integration testing: 1-2 days
  • Total: 2-5 days
  • 20-40x faster deployment

Geographic Resilience

Traditional HSM
  • Single data center deployment
  • Complex replication setup
  • Manual failover procedures
  • Limited geographic distribution
DuoKey Software-Defined HSM
  • Multi-region by default
  • Automatic failover (sub-second)
  • Active-active architecture
  • 99.99% vs 99.9% (10x fewer outages)

Scalability

Traditional HSM
  • Fixed capacity per device
  • Vertical scaling (buy more HSMs)
  • Limited to physical constraints
  • Complex capacity planning
DuoKey Software-Defined HSM
  • Horizontal scaling on-demand
  • Auto-scaling based on load
  • Unlimited capacity potential
  • Linear cost growth

Enterprise Features

Centralized Management

Unified Dashboard
  • Manage all keys across products
  • Single pane of glass
  • Role-based access control (RBAC)
  • Multi-tenant architecture
API-Driven Automation
  • RESTful APIs for all operations
  • Infrastructure as Code (IaC)
  • CI/CD integration
  • GitOps compatible

Compliance & Audit

Regulatory alignment
  • PCI DSS
  • HIPAA/HITECH
  • GDPR Article 32
  • SOC 2
  • ISO 27001
Monitoring
  • Complete audit trail
  • Tamper-evident logs
  • Real-time alerting
  • SIEM integration

Security Controls

Access
  • Multi-factor authentication
  • SSO via SAML/OIDC
  • Time-based restrictions
  • IP allowlisting
Key Lifecycle
  • Automated key rotation
  • Key versioning
  • Soft delete with recovery
  • Cryptographic shredding

Representative Scenarios

Financial Services

Major bank needed to encrypt 500+ Oracle databases while maintaining 99.99% availability

Solution

DuoKey Software-Defined HSM for Oracle TDE — deployed across 3 cloud regions (AWS, Azure, GCP) with distributed AES key operations and automated 90-day key rotation.

  • ✓ High availability across multiple regions
  • ✓ Lower TCO than dedicated HSM hardware
  • ✓ Supports PCI DSS compliance programs
  • ✓ Deploys in days, not months
Healthcare

Hospital network needed HIPAA-compliant encryption for patient data across Salesforce

Solution

DuoKey Software-Defined HSM for Salesforce BYOK — patient records encrypted with customer-controlled keys and key revocation for breach response.

  • ✓ Supports HIPAA compliance
  • ✓ Streamlined audit evidence
  • ✓ Data sovereignty maintained
  • ✓ MPC design: keys never reconstructed
Technology / SaaS

SaaS provider needed per-tenant encryption keys for 10,000+ customers

Solution

DuoKey Software-Defined HSM multi-tenant architecture — unique key per tenant with horizontal scaling and sub-millisecond operations.

  • ✓ Scales to thousands of tenants
  • ✓ Low-latency key operations
  • ✓ Per-tenant key isolation
  • ✓ Clear competitive differentiator

Illustrative deployment scenarios based on typical customer profiles — not specific named customers or measured results.

Getting Started

1

Assessment

  • Current KMS solution review
  • Compliance requirements
  • Performance & budget needs
  • Timeline planning
2

Proof of Concept

  • Free 30-day trial
  • Technical support included
  • Integration assistance
  • Performance benchmarking
3

Deployment

  • Phased migration plan
  • Training & documentation
  • Ongoing support
  • Success metrics tracking
4

Optimization

  • Performance monitoring
  • Cost optimization
  • Feature adoption
  • Regular reviews

Technical Specifications

Performance

Latency (p50)< 2ms
Latency (p99)< 10ms
Throughput10,000+ ops/sec/node
Availability99.99% SLA
Distribution3+ regions

Supported Algorithms

Symmetric Encryption (AES)

AES-128AES-192AES-256

Compliance Alignment

Designed to support your compliance programs (framework alignment, not DuoKey certifications):

PCI DSSSOC 2HIPAA/HITECHGDPR Art. 32ISO 27001

Performance and availability figures on this page (latency, throughput, SLA) are indicative design targets, not independently benchmarked guarantees.

Frequently Asked Questions

Ready to Modernize Your Key Management?

Replace costly HSM infrastructure with DuoKey's Software-Defined HSM.

Support & Resources​

Documentation​

Professional Services​

  • Architecture design and review
  • Migration from HSM or other KMS
  • Performance optimization
  • Compliance assistance

Support Channels​

Training​

  • Self-paced online courses
  • Live webinars
  • On-site training
  • Certification program