The BlackVault HSM.RAS is a network attached general purpose FIPS 140-2 Level 3 Hardware Security Module with unique functionality making authentication, security, compliance, and ease of use paramount.
Public Key Cryptography for generating and protecting public and private keys.
Affordable Commercial Grade
The BlackVault HSM.RAS is an affordable commercial grade model with an integrated Smart Card reader that utilizes an extruded aluminum case that has flanged end plates for securely mounting: within a 1U shelf/locking drawer; on DIN rail or wall mount.
Its powerful features include a compact form factor, smart card reader, tamper reactive silicon die shield, long battery life, networked and off-line operation with Ethernet and USB ports, and much more.
BlackVault HSM.RAS utilizes an intuitive iconic graphical user interface. A structured menu system facilitates straight forward configuration via remote management. The user interface presents Crypto Officers with a sequence of dialog boxes that lead through a series of well-defined steps to initiate the HSM and provision cards and keys.
Is aPowerful, easy to use, PKCS#11 CLI tool able to perform many different cryptographic operations that comes with every BlackVault HSM and works on Windows/Linux/MacOS both physical and virtualized. Some of the functions are:
• Create Keys
• Delete Keys
• Key Import/Export Wrap/Unwrap
• Self-Signed Certificates
As Well as...
• Sign/Verify Files
• Encrypt/Decrypt Files
Able to utilize AES, RSA EC, and DSA key types. Sign using various hashes including but not limited to SHA256, SHA384, and SHA512.
Easy to Integrate BlackVault easily integrates into a variety of applications, supporting numerous crypto APIs including PKCS#11, Java (JCE) and Microsoft CAPI / CNG, across a variety of operating systems.
A SDK comes with a purchase of an HSM designed to help you integrate your application with the BlackVault through its PKCS#11 interface.
- Includes example code of Python and C++
Simple easy to use integration guides with step by step walkthroughs to get you up and running with a variety of applications including:
• Android Dev Studio
• Microsoft Active Directory Certificate Services
Portable / Embeddable Form Factor Its compact “hard drive” form-factor and redundant, battery-backed, solid state key storage allow BlackVaultHSM.RAS to be moved to a secure room or safe without loss or compromise of root keys or other cryptographic material. Its small form factor with USB connection and power also supports mounting BlackVaultHSM.RAS within application servers and other compact environments.
Trusted Path Authentication The integrated smart card reader facilitates two-factor authentication, and advanced “M of N” Quorum approval. This ensures that no single individual can authorize administrative or operational actions.
Real Time Audits Constantly updated configuration and operation information provide Security Administrators with the data to discover anomalous activity or failure of critical functions. Audit information can be sent to a trusted entity and is protected to prevent unauthorized access, modification, or deletion.
Military Grade Tamper Reactive BlackVaultHSM.RAS cryptographic boundary is within the silicon of its secure CPU. This silicon die shield has dynamic fault detection with real-time environmental and tamper detection circuitry. It also avoids inadvertent tamper, making the BlackVaultHSM.RAS safe to transport. When a tamper event is detected, the Cryptographic keys are zeroized (deleted).
Ideal for Many Applications The BlackVaultHSM.RAS is an independently certified standards based network attached hsm (hardware security module) that performs key management and cryptographic operations for enterprises, certificate authorities, government, and a growing list of organizations requiring strong security for PKI, digital certificates, code signing, document signing, cryptographic key storage, data encryption, key generation and regulatory compliance in cloud companion, networked and off-line (air-gap) operations.
Certificate Authority (online and off-line)
Smart Card Issuance
Intrusion Tamper Reactive Hardware (Level 3+)
Integrated Smart Card Reader
Network and USB Connectivity
Solid State Construction (“Transport Safe”)
Highly Secure Silicon Die Shield Crypto Boundary
Multiple Administrative Roles
"M of N" Multi-factor Authentication
Key Backup / Cloning
Full Suite B Cryptography
Secure Keys in Tamper Reactive Hardware
Generate, Store, Backup and Decommission Keys
Expedite Regulatory Compliance Audits
Securely Transport Keys, Certificates, Signatures, etc.