Economy Certified (ECO CC)
CloudHSM Economy Certified (ECO CC) is tailored for those needing a specific HSM cluster operating in stringent Common Criteria mode and is certified according CC EN 419 221-5 which is relevant for eIDAS compliant qualified signatures. Each user space includes a designated storage capacity within a cluster of synchronized HSMs, with data mirrored to a secure backup data center for added protection.
Service Description
This service provides access to Securosys Cloud HSM Service partitions with the following attributes:
Attribute | Description |
---|---|
Client Connections | Not limited |
Storage Capacity | 10MB (up to 200 RSA-4096 asymmetric key pairs, 5MB reserved for user audit logs). Additional Storage Capacity is available in increments of 100 MB |
Performance | Up to 600 operations (RSA-4096) per minutes. Additional performance is available in increments of 600 operations (RSA-4096) per minutes. |
Key Generation | Max. 1 key per second |
Cryptographic APIs | PKCS#11, Java (JCA/JCE), Microsoft CNG or REST |
Supported Functions | See the Supported Algorithms and Functions list |
Operational Mode | Strict FIPS mode and Common Criteria compliant operation |
Service Options
In addition to the service description provided above, the following table outlines the available options and indicates whether they are currently enabled, disabled, or can be optionally selected:
Option | Availability |
---|---|
Attestation and Partition Audit | Enabled |
Partition Administration | Option. Requires purchase or rent of Decanus Terminal |
Smart Key Attributes (SKA) | Option |
Transaction Security Broker (TSB) | Option |
Cryptocurrencies | Disabled |
Post-Quantum Cryptographic Algorithms | Disabled |
Timestamp Service (RFC3161 compliant) | Option |
Regions
ECO CC is accessible through either a Regional Swiss or US cluster, ensuring optimal reach and performance tailored to specific geographic needs. This distribution is detailed in the table below.
Service Package | Data Center locations | Active DC | Business Continuity DC |
---|---|---|---|
Economy Certified Mode (ECO CC), Switzerland | Switzerland | CH01, CH02 | CH03 |
Economy Certified Mode (ECO CC), USA | USA, Switzerland | US01, US02 | CH03 |
The active sites are located based on the configuration specified in the cluster definition. The business continuity site, designed for disaster recovery, is strategically located in Switzerland.
Partition Policy Settings
The following tables provide an overview of all partition policy settings, indicating whether they are enabled, disabled, or available for selection by the customer upon ordering and wether they can be modified afterwards.
API Settings
API Activation | Availability |
---|---|
PKCS#11 | Included; can be enabled/disabled upon ordering |
Java (JCA/JCE) | Included; can be enabled/disabled upon ordering |
Microsoft CNG | Included; can be enabled/disabled upon ordering |
REST | Included; can be enabled/disabled upon ordering |
Client API Access | Enabled. Modifiable via Support Portal or Decanus Terminal via Partition Administration to take partition completely offline. |
Partition Settings
Policy | Availability |
---|---|
Key Import | Selectable upon ordering. Modifiable via Support Portal or Decanus Terminal via Partition Administration. |
Key Export | Selectable upon ordering. Modifiable via Support Portal or Decanus Terminal via Partition Administration. |
Key Invalidation | Selectable upon ordering. Modifiable via Support Portal or Decanus Terminal via Partition Administration. |
Partition R/O | Disabled. Modifiable via Support Portal or Decanus Terminal via Partition Administration. |
Session Objects | Enabled |
Object Destruction | Selectable upon ordering. Modifiable via Support Portal or Decanus Terminal via Partition Administration. |
Object Usage | Enabled. Modifiable via Support Portal or Decanus Terminal via Partition Administration. |
Service Management
The CloudHSM ECO CC partition offers versatile management options to make changes to the partition policy setting. Users can utilize the Decanus Terminal via Partition Administration or submit change requests on the Support Portal.