HSM (Hardware Security Module)
Definition
HSM Certifications: to be qualified under the eIDAS regulation, an HSM must meet strict standards — FIPS 140-2 level 3 or FIPS 140-3 level 3+ (NIST American standard), and/or Common Criteria EAL4+ (European standard). Common Criteria certified HSMs are eligible to host qualified signature (QES) keys and qualified timestamping keys. The European Trusted List references authorized HSMs for each qualified provider.
Cloud HSM vs Physical HSM: historically HSMs were dedicated appliances installed in private datacenters. Cloud providers now offer shared or dedicated HSMs as SaaS — AWS CloudHSM, Azure Dedicated HSM, Google Cloud HSM, but also national HSMs operated by European QTSPs. The eIDAS 2.0 regulation explicitly recognizes cloud HSMs for remote qualified signatures.
HSM and encryption ("HSM encryption"): beyond signatures, HSMs protect database encryption keys, disk encryption keys (BitLocker, FileVault, LUKS), internal PKI root keys, and application secrets. Key rotation, backup and revocation are managed via PKCS#11 or proprietary interfaces.
Certyneo implementation: the cryptographic keys for remote signing are hosted in Common Criteria EAL4+ HSMs operated by our qualified trust service provider (QTSP). No private key is ever accessible to Certyneo or its hosting provider — each signing operation goes through strong authentication of the signatory and an API call to the HSM, which returns the signature without exposing the key. See also QSCD and cloud signature.
Frequently asked questions
What is an HSM (Hardware Security Module)?
An HSM is a dedicated and tamper-proof hardware device that generates, stores and uses cryptographic keys within certified hardware. Private keys never leave the module in clear text, making HSMs the trust foundation for qualified electronic signatures and seals.
What is an HSM used for?
Within a signing platform, the HSM hosts the signing keys and performs the cryptographic operation itself: the key material is never exposed to the application server. HSMs are also used to protect TLS keys, PKI certification authorities, payments and database encryption.
What is the difference between an HSM and software key storage?
A software key store keeps keys in memory or on a server''s disk, where a single compromise allows them to be copied. An HSM keeps keys in certified and tamper-proof hardware (FIPS 140-2/3, Common Criteria EAL4+) and only exposes signing or decryption operations, never the keys themselves.
Is an HSM mandatory for a qualified electronic signature (eIDAS)?
Yes. According to the eIDAS regulation, a qualified electronic signature must be created using a qualified signature creation device (QSCD). In practice, this QSCD is a certified HSM operated by the qualified trust service provider, which protects the signer''s key at the highest level required by the regulation.
What is a cloud HSM?
A cloud HSM is a certified hardware module provided as a managed service: the organization benefits from HSM-level key protection without operating the hardware itself. Remote qualified signature relies on cloud HSMs owned by the trust service provider.
Related guides
Related terms
Ready to put these concepts into practice?
Certyneo allows you to create eIDAS-compliant signature envelopes in just a few clicks, with no installation required.
