BlackVault HSM.TSA

BlackVault HSM.TSA

Product Image

Time Stamp Authority with Hardware Security Module

Overview

The BlackVault HSM.TSA is a Time Stamp Authority (TSA) product fully integrated with the network attached BlackVault HSM platform combining a cryptographically advanced HSM with creation and authenticity of timestamps. In response to the needs of customer with increasingly valuable digital signing practices and the need for enabling organizations to record when a digital item – ie. a document, piece of software or transaction – was signed. Time stamping is also crucial for stock trades, lottery ticket issuance and legal proceedings. In general time stamping is valuable for audit processes and record keeping as it provides proof whether the digital certificate was valid at the time it was used.

Secure Timestamping

The BlackVault HSM.TSA ensures the tamper proof creation and authenticity of the timestamped data for many applications. Verify at all times, if the timestamped data matches the exact same form at the point in time it was logged by the timestamp. The BlackVault HSM.TSA complies with the RFC 3161 timestamp protocol. Administration clients initialize and administer the BlackVault HSM.TSA via a web application interface. The BlackVault HSM..TSA is designed to easily integrate into an existing infrastructure. The system is easy to set up which means it is both time and cost-efficient. All keys are generated and managed by Hardware Security Modules (HSMs), which means they are never exposed and cannot be tampered with. Administrators must log on to the HSM using smart cards with two-factor authentication with an “M of N” Quorum. Optionally you can enable TLS for additional security. Key sizes are configurable and easy to change via the web application. Timestamp operation are backed by NTP servers that are also configurable.

 

Rack Mount Locking Drawer

Powerful Features

Its powerful features include a compact form factor, smart card reader, tamper reactive silicon die shield, long battery life, networked and off-line operation with Ethernet and USB ports, and much more. The TSA Server and the HSM PKCS#11 API have independent logins creating isolated access to their Signing Keys adding another layer of protection.

BVGUI

The BlackVault HSM.TSA utilizes an intuitive iconic graphical user interface. A structured menu system facilitates straight forward configuration via remote management. The user interface presents Crypto Officers with a sequence of dialog boxes that lead through a series of well-defined steps to initiate the HSM and provision cards and keys.

BV Tool

Is a Powerful, easy to use, PKCS#11 CLI tool able to perform many different cryptographic operations that comes with every BlackVault HSM and works on Windows/Linux/MacOS both physical and virtualized. Some of the functions are:

Key Management

• Create Keys

• Delete Keys

• Key Import/Export Wrap/Unwrap

Create Certificates

• CSRs

• Certificates

• Self-Signed Certificates

As Well as...

• Sign/Verify Files

• Encrypt/Decrypt Files

Able to utilize AES, RSA EC, and DSA key types. Sign using various hashes including but not limited to SHA256, SHA384, and SHA512.

Easy to Integrate

BlackVault easily integrates into a variety of applications, supporting numerous crypto APIs including PKCS#11, Java (JCE) and Microsoft CAPI / CNG, across a variety of operating systems. 

SDK comes with a purchase of an HSM designed to help you integrate your application with the BlackVault through its PKCS#11 interface.

- Includes example code of Python and C++

Simple easy to use integration guides with step by step walkthroughs to get you up and running with a variety of applications including: 

• Authenticode

• Eclipse

• Android Dev Studio

• Java

• Microsoft Active Directory Certificate Services 

Portable / Embeddable Form Factor

Its compact “hard drive” form-factor and redundant, battery-backed, solid state key storage allow BlackVault HSM.TSA  to be moved to a secure room or safe without loss or compromise of root keys or other cryptographic material. Its small form factor with USB connection and power also supports mounting BlackVault HSM.TSA  within application servers and other compact environments. 

Trusted Path Authentication

The integrated smart card reader facilitates two-factor authentication, and advanced “M of N” Quorum approval.  This ensures that no single individual can authorize administrative or operational actions. 

Real Time Audits

Constantly updated configuration and operation information provide Security Administrators with the data to discover anomalous activity or failure of critical functions. Audit information can be sent to a trusted entity and is protected to prevent unauthorized access, modification, or deletion. 

Military Grade Tamper Reactive

BlackVault HSM.TSA  cryptographic boundary is within the silicon of its secure CPU. This silicon die shield has dynamic fault detection with real-time environmental and tamper detection circuitry. It also avoids inadvertent tamper, making the BlackVault HSM.TSA  safe to transport. When a tamper event is detected, the Cryptographic keys are zeroized (deleted). 

Ideal for Many Applications

BlackVault HSM.TSA  is an independently certified standards based network attached hsm (hardware security module) that performs key management and cryptographic operations for enterprises, certificate authorities, government, and a growing list of organizations requiring strong security for PKI, digital certificates, code signing, document signing, cryptographic key storage, data encryption, key generation and regulatory compliance in cloud companion, networked and off-line (air-gap) operations.

Applications

Applications

  • Digital Signing Validation
  • Legal Document Proof and Validation
  • Stock Trades
  • Lottery Ticket Issuance 
  • Legal Proceedings
  • Software or transaction date and time keeping

Features

  • Intrusion Tamper Reactive Hardware (Level 3+)
  • Integrated Smart Card Reader
  • Network and USB Connectivity
  • Solid State Construction (“Transport Safe”)
  • Highly Secure Silicon Die Shield Crypto Boundary
  • Multiple Administrative Roles
  • "M of N" Multi-factor Authentication
  • Key Backup / Cloning
  • Full Suite B Cryptography
  • Software Upgradable 
  • Secure Timestamping

Benefits

  • Improve the integrity of crucial business operations with trusted time stamps
  • Save cost and remove inefficient paper-based processes
  • Minimize disputes and resolve them more easily
  • Maximize the value of your investment in digital signing solutions
  • Create a tamper-proof record of transactions
  • Streamline auditing and compliance
  • Secure Keys in Tamper Reactive Hardware
  • Generate, Store, Backup and Decommission Keys
  • Expedite Regulatory Compliance Audits
  • Securely Transport Keys, Certificates, Signatures, etc.
  • Single Platform has Network and USB Ports
  • Compact, Fits in Safe, Server Slot, Secure Room
  • Integrated Multi-factor Authentication (Trust Path)
  • Multi-level Access Control
  • Secure Audit Logging
  • Remote Management

Specifications

Cryptography
  • Full Suite B support with Elliptic Curve Cryptography (ECC)
  • Asymmetric: RSA (1024, 2048, 4096, 8192), Diffie-Hellman, DSA, Elliptic Curve Cryptography (ECDSA (NIST Curves: P-192, P-224, P-256, P-384, P-521, K-163, K-233, K-283, K-409, K-571, B-163, B-233, B-283, B-409, B-571), ECDH) [More info in HSM User Guide continued]
  • Symmetric: AES 256
  • Hash / Message Digest: SHA-1, SHA-2 (224, 256, 384, 512)
  • Hardware Random Number Generator: NIST SP 800-90
Operating Systems
  • Windows, Linux, Ubuntu, CentOS, RedHat
  • Virtual: VMware, Windows, Linux
Cryptographic APIs and Interfaces
  • PCKS#11, Java (JCE), Microsoft CAPI / CNG
  • RFC 3161 timestamp protocol
  • PKCS#10 and PKCS#7 for request and import of TimestampServer certificates
  • NTP Network Time Protocol for synchronization of TimestampServer with external time server
Host Connectivity
  • 10/100 Ethernet with Transport Layer Security (TLS) and Optional SFP
Additional Connectivity
  • Integrated Smart Card Reader
  • USB 2.0
Management
  • Graphical User Interface
  • Command Line Interface (CLI)
  • Syslog Logging
  • Enable TLS for additional Security
  • SNMPv3 Monitoring and Traps
  • Multi-level Access Control ("M of N")
  • Remote Management
Mounting
  • Desktop (Portable)
  • 19” rack mount (1U height)
  • Server Hard Drive Slot Embeddable
Physical
  • Dimensions: 4” x 6” x 1” (102 mm x 153 mm x 26 mm)
  • Weight: 1 lb. (454 g)
Power
  • Power Consumption: 4W
  • Input Range: 5 to 30 VDC
  • Lockable DB9 Connector
  • AC adaptor (order per country) 
Redundancy
  • Optional Dual Power, Hot Standby
Environmental
  • Operating Temperature: 0° to 50° C (32° to 122° F)
  • Storage Temperature: -20° to 60° C (-4° to 140° F)
  • Operating Humidity: Up to 90% (Non-Condensing)
  • Optional Extended Temperature Range Available on the BlackVault HSM.TAC
Certification
  • FIPS 140-2 Level 3

Regulatory
  • UL, CE, FCC, RoHS
  • Safety: IEC 60950
  • EMC: CFR 47 Part 15 Sub Part B: 2002, EN55022: 1994+A1&A2, EN55024, ICES-003 1997, CISPR22 Level A

So What’s Next?

WE’RE READY!

Engage logo 990000 rev 2.000
9565 Soquel Drive Dr,
Aptos, CA 95003
 
Telephone: +1-831-688-1021
Toll Free : +1-877-ENGAGE4
Designed, Fabricated, and Assembled
in America icon
Supported Worldwide