Skip to main content

Storage Calculator

How much storage do 300 AES keys require? 10'000 ML-DSA key pairs? 27'500 RSA SKA key pairs?

This calculator helps you estimate the amount of storage you need for your Partitions. On-premise Primus HSM starts at 120 MB, CloudHSM starts at 10 MB. The maximum Partition size is 30 GB (varies by model/service type).

CountKey typeSKAKMIPSize
4.00 KB
Total keys/key pairs1
Total storage required4.00 KB
estimation

This calculator gives an estimate of the keystore size. Actual size varies depending on additional factors (such as size of key attributes) and may be higher. Additionally, in CloudHSM 5 MB are reserved for audit logs. The maximum storage size depends on device model and licensing.

Frequently Asked Questions​

Why does a single key pair need so much space?

It may seem surprising that, for example, a single EC P-256 key pair requires 4096 bytes of space, even though the private key material itself is only 256 bits / 32 bytes. The reasons for this are the following:

  1. Primus HSM stores attributes alongside each key.
  2. The internal block alignment is 1024 bytes. It is needed to speed up storage accesses.
  3. The private key and public key are stored as two separate objects. They are block-aligned separately.
Do invalidated keys count towards the storage quota?

Yes, invalidated keys also count towards the storage quota of a Partition. To free up space, delete the invalidated keys or disable key invalidation.

What effect does SKA have on object size?

When a key pair uses Smart Key Attributes (SKA), a policy is attached to it. The size of this policy depends on different factors, such as the number of approvers and whether the approvers are specified as raw public keys or as certificates. The approver key/certificate type also matters (EC, ML-DSA, ...).

This calculator uses 4 KB as an estimate for an average SKA policy.

What effect does KMIP have on object size?

Objects that are created via the Securosys KMIP Server have additional, KMIP-specific metadata attached to them. For example, they have a "State" (activated, archived, deactivate, ...).

This calculator uses 4 KB as an estimate for average KMIP metadata.

Feedback
Need help?