DINAMO HSM provides a secure environment for managing the cryptographic keys lifecycle of your environment, as well as digital signature and certification. Our appliances guarantee authenticationality, confidentiality, integrity and inviolability of company’s information.
Our Hardware Security Modules reduce risk and operational costs by centralizing enterprise cryptographic key management. Multiple applications can have access to security and cryptographic functions in a dedicated and high performance equipment.
HSMs are built under strict international security standards and approved by the Institute of Information Technology (ITI) in Brazil, a federal agency linked to the Civil House of the Presidency of the Republic. The certifications recognise attests that DINAMO Networks appliances meet the protection requirements and standards, ICP-Brazil (Brazilian Public Key Infrastructure) Approval Level 3, which establishes national digital certification standards.
With the industry’s highest integration capabilities, our HSMs enable a growing number of technology partners to easily integrate with our security appliances.
ALGORITHMS
- RSA (1024, 1152, 1408,1984, 2048, 3072, 4096 e 8192 bits)
- ECDSA (128, 160, 192, 256, 384 e 521 bits)
- ECX EdDSA (Ed25519 e Ed448)
- XECDH (X25519 e X448)
- DES
- 3DES (128 e 192 bits)
- AES (128, 192 e 256 bits)
- MD5
- SHA1
- SHA2 (256, 384, 512 bits)
HOMOLOGATION
- ICP Brasil MCT-7 Security Homologation Level (NSH) 3
INTERFACE / APIS
- MS Crypto API
- PKCS#11
- API Native (encryption, management and monitoring)
- Java JCA/JCE
- API Native SPB – Brazilian Payment System
CONECTIVITY
- Two interfaces – Ethernet 10/100/1000 RJ-45
- Replication
OPERATION MODEL
- Non Restricted Mode
- Restricted Mode 1 (ICP-Br MCT-7, Brasil)
- Restricted Mode 2 (FIPS 140-3, EUA)
OBJECT STORAGE
- Master Key Protection (Server Master Key) in Smartcard
- Separation of partitions by users
- Diferent Privileges Levels
- 100% Encrypted Backup
MANAGEMENT
- Local Console (trusted path)
- Remote Console (network)
INTERN AND NATIVE MODULES
- State Manager
- XML DSig Engine
AUTHENTICATION
- Regular (remote console / API)
- Smart Card (local console)
- TFA – Two Factor Authentication (remote console / API)
COMMUNICATION WITH HSM – APPLICATION HOST
HMAC BASED ONE TIME PASSWORD (HOTP)
- Seed generation or import
- OTPs for time or event
AUDIT
- Persistent Events Log
- Records Recovery
MONITORING
- Events
- CPU, memory and active sessions
- Battery, memory and controller diagnostics
PERFORMANCE
RSA signature 2048 bits per second
- 1600 (HSM DINAMO CD)
- 4000 (HSM DINAMO XP)
- 10800 (HSM DINAMO ST)