Skip to main content

Economy Certified (ECO CC)

CloudHSM Economy Certified (ECO CC) is tailored for those needing a specific HSM cluster operating in stringent Common Criteria mode and is certified according CC EN 419 221-5 which is relevant for eIDAS compliant qualified signatures. Each user space includes a designated storage capacity within a cluster of synchronized HSMs, with data mirrored to a secure backup data center for added protection.

Service Description

This service provides access to Securosys Cloud HSM Service partitions with the following attributes:

AttributeDescription
Client ConnectionsNot limited
Storage Capacity10MB (up to 200 RSA-4096 asymmetric key pairs, 5MB reserved for user audit logs). Additional Storage Capacity is available in increments of 100 MB
PerformanceUp to 600 operations (RSA-4096) per minutes. Additional performance is available in increments of 600 operations (RSA-4096) per minutes.
Key GenerationMax. 1 key per second
Cryptographic APIsPKCS#11, Java (JCA/JCE), Microsoft CNG or REST
Supported FunctionsSee the Supported Algorithms and Functions list
Operational ModeStrict FIPS mode and Common Criteria compliant operation

Service Options

In addition to the service description provided above, the following table outlines the available options and indicates whether they are currently enabled, disabled, or can be optionally selected:

OptionAvailability
Attestation and Partition AuditEnabled
Partition AdministrationOption. Requires purchase or rent of Decanus Terminal
Smart Key Attributes (SKA)Option
Transaction Security Broker (TSB)Option
CryptocurrenciesDisabled
Post-Quantum Cryptographic AlgorithmsDisabled
Timestamp Service (RFC3161 compliant)Option

Regions

ECO CC is accessible through either a Regional Swiss or US cluster, ensuring optimal reach and performance tailored to specific geographic needs. This distribution is detailed in the table below.

Service PackageData Center locationsActive DCBusiness Continuity DC
Economy Certified Mode (ECO CC), SwitzerlandSwitzerlandCH01, CH02CH03
Economy Certified Mode (ECO CC), USAUSA, SwitzerlandUS01, US02CH03
note

The active sites are located based on the configuration specified in the cluster definition. The business continuity site, designed for disaster recovery, is strategically located in Switzerland.

Partition Policy Settings

The following tables provide an overview of all partition policy settings, indicating whether they are enabled, disabled, or available for selection by the customer upon ordering and wether they can be modified afterwards.

API Settings

API ActivationAvailability
PKCS#11Included; can be enabled/disabled upon ordering
Java (JCA/JCE)Included; can be enabled/disabled upon ordering
Microsoft CNGIncluded; can be enabled/disabled upon ordering
RESTIncluded; can be enabled/disabled upon ordering
Client API AccessEnabled. Modifiable via Support Portal or Decanus Terminal via Partition Administration to take partition completely offline.

Partition Settings

PolicyAvailability
Key ImportSelectable upon ordering. Modifiable via Support Portal or Decanus Terminal via Partition Administration.
Key ExportSelectable upon ordering. Modifiable via Support Portal or Decanus Terminal via Partition Administration.
Key InvalidationSelectable upon ordering. Modifiable via Support Portal or Decanus Terminal via Partition Administration.
Partition R/ODisabled. Modifiable via Support Portal or Decanus Terminal via Partition Administration.
Session ObjectsEnabled
Object DestructionSelectable upon ordering. Modifiable via Support Portal or Decanus Terminal via Partition Administration.
Object UsageEnabled. Modifiable via Support Portal or Decanus Terminal via Partition Administration.

Service Management

The CloudHSM ECO CC partition offers versatile management options to make changes to the partition policy setting. Users can utilize the Decanus Terminal via Partition Administration or submit change requests on the Support Portal.