{"id":4908,"date":"2021-10-15T10:11:04","date_gmt":"2021-10-15T02:11:04","guid":{"rendered":"https:\/\/www.progreso.com.sg\/newsite\/?post_type=all_news&#038;p=4908"},"modified":"2021-10-15T11:54:03","modified_gmt":"2021-10-15T03:54:03","slug":"common-criteria-hardware-security-modules-hsms","status":"publish","type":"all_news","link":"https:\/\/www.progreso.com.sg\/newsite\/all_news\/common-criteria-hardware-security-modules-hsms\/","title":{"rendered":"What are the Common Criteria for Hardware Security Modules (HSMs)?"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"4908\" class=\"elementor elementor-4908\" data-elementor-settings=\"[]\">\n\t\t\t<div class=\"elementor-inner\">\n\t\t\t\t<div class=\"elementor-section-wrap\">\n\t\t\t\t\t\t\t<section class=\"elementor-element elementor-element-b159609 elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-top-section\" data-id=\"b159609\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8306bad elementor-column elementor-col-50 elementor-top-column\" data-id=\"8306bad\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-51de727 elementor-widget elementor-widget-text-editor\" data-id=\"51de727\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p>All the critical banking and payment systems incorporate Hardware Security Modules (HSMs) for the protection of user information and business transactions. HSMs deliver secure management of crypto keys along with encryption\/decryption, digital signatures and authentication mechanisms which are frequently used for the security of corporate business applications.\u00a0<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d869e00 elementor-column elementor-col-50 elementor-top-column\" data-id=\"d869e00\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-bbecf2d elementor-widget elementor-widget-image\" data-id=\"bbecf2d\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image\">\n\t\t\t\t\t\t\t\t\t\t<img width=\"1024\" height=\"316\" src=\"https:\/\/www.progreso.com.sg\/newsite\/wp-content\/uploads\/2021\/10\/commoncriteria_logo_original-1024x316.gif\" class=\"attachment-large size-large\" alt=\"\" loading=\"lazy\" srcset=\"https:\/\/www.progreso.com.sg\/newsite\/wp-content\/uploads\/2021\/10\/commoncriteria_logo_original-1024x316.gif 1024w, https:\/\/www.progreso.com.sg\/newsite\/wp-content\/uploads\/2021\/10\/commoncriteria_logo_original-300x93.gif 300w, https:\/\/www.progreso.com.sg\/newsite\/wp-content\/uploads\/2021\/10\/commoncriteria_logo_original-768x237.gif 768w, https:\/\/www.progreso.com.sg\/newsite\/wp-content\/uploads\/2021\/10\/commoncriteria_logo_original-600x185.gif 600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-element elementor-element-4aec452 elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-top-section\" data-id=\"4aec452\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-c7ae2e5 elementor-column elementor-col-100 elementor-top-column\" data-id=\"c7ae2e5\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a8480c4 elementor-widget elementor-widget-text-editor\" data-id=\"a8480c4\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><h3>1. Different types of hardware security modules and their importance<\/h3><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<section class=\"elementor-element elementor-element-90e6982 elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-inner-section\" data-id=\"90e6982\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1bf4022 elementor-column elementor-col-100 elementor-inner-column\" data-id=\"1bf4022\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ee97565 elementor-widget elementor-widget-text-editor\" data-id=\"ee97565\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p>Hardware Security Modules (HSMs) are a very critical component of business application because they are responsible for the security of confidential information and transactions. They are either a dedicated hardware machine or a cluster of multiple devices with embedded processors which can swiftly carry on cryptographic operations. HSMs or \u201cSecure Cryptographic Devices\u201d are available in several sizes\/types and different security levels such as TPMs\/ embedded HSMs, software tokens, PCI Cards, Smart Cards, USB tokens, and network-attached HSMs. Every HSM types offer features (performance, standalone\/network-attached) as per the requirements of corporate applications.<\/p><p>HSMs not only provide different levels of logical but also physical protection to crypto keying material against unauthorized access by adversaries consequentially acting as security backbone of your business architecture.<\/p><p>So HSMs provide accelerated crypto operations on one end and curtails\/lessens the business risks on the other end. The incorporation of HSM in business provides the following plus points.<\/p><ul><li style=\"list-style-type: none;\"><ul><li>Enhanced Security<\/li><li>Centralized Policy<\/li><li>Enforcement<\/li><li>Augmented Business Efficiency<\/li><li>Decrease Operational Cost\/Complexity<\/li><li>Legal and Regulatory Compliance<\/li><\/ul><\/li><\/ul><p>Banking and corporate sectors have a huge clientele and have to serve a large user base securely and efficiently. The risk of failover and downtime is very critical in such organizations and can lead to the huge amount of business loss. Hence, the HSMs are deployed in cluster\/redundancy, HA (High Availability) and load-balancing mode to guarantee contingency and ensure business continuity.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-element elementor-element-62df5f9 elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-inner-section\" data-id=\"62df5f9\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-caabe08 elementor-column elementor-col-100 elementor-inner-column\" data-id=\"caabe08\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-0a3bc1f elementor-widget elementor-widget-text-editor\" data-id=\"0a3bc1f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><h3>2. Advantage of CC certified HSMs<\/h3><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-element elementor-element-b80df7d elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-inner-section\" data-id=\"b80df7d\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-47feaab elementor-column elementor-col-100 elementor-inner-column\" data-id=\"47feaab\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-67c469d elementor-widget elementor-widget-text-editor\" data-id=\"67c469d\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p>A certification is an immediate and documented benchmark about the features and functionalities of an HSM based on standardized testing procedures. International and globally recognized certifications assure the trust\/confidence of all the stakeholders (managers, designers, clients\/end users and evaluators etc.) of an architecture. The core intention behind the initiative of Common Criteria was to assure the trust and global acceptance to the security products sold in the international market so that they don\u2019t need to be re-evaluated by each buying client\/country.<\/p><p>International and corporate organizations\/clients always prefer\/recommend HSMs and crypto devices having Common Criteria certifications. Federal Agencies of USA have made it mandatory to procure IT products which are Common Criteria certified. Common Criteria enlists all the\u00a0<a href=\"https:\/\/www.commoncriteriaportal.org\/products\/\" rel=\" noopener\">certified products<\/a>\u00a0on their website. As a whole, the following advantages are offered by a certification:<\/p><ul><li>Competitive benefit among vendors<\/li><li>Trust among stakeholders<\/li><li>Interoperability<\/li><li>Legal\/Regulatory bindings<\/li><\/ul><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-element elementor-element-1153391 elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-inner-section\" data-id=\"1153391\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-356ce7b elementor-column elementor-col-100 elementor-inner-column\" data-id=\"356ce7b\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f2b9721 elementor-widget elementor-widget-text-editor\" data-id=\"f2b9721\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><h3>3. Common Criteria Certification<\/h3><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-element elementor-element-cdbaf40 elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-inner-section\" data-id=\"cdbaf40\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5a48168 elementor-column elementor-col-100 elementor-inner-column\" data-id=\"5a48168\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-080a334 elementor-widget elementor-widget-text-editor\" data-id=\"080a334\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p>Common Criteria (CC) is a globally recognized standard\/certification (ISO\/IEC 15408) which helps in choosing maximum security and assurance levels of HSMs. It is a joint effort of six (06) countries: US, UK, Canada, France, Germany &amp; Netherlands. It is the cutting edge feature for the procurements of HSM among the competitor vendors and a core requirement of security aware corporations. The latest version (v3.1) was released in April 2017.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-element elementor-element-9c69d6e elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-inner-section\" data-id=\"9c69d6e\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-828ddbc elementor-column elementor-col-100 elementor-inner-column\" data-id=\"828ddbc\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-c0729fa elementor-widget elementor-widget-text-editor\" data-id=\"c0729fa\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><h3>4. Common Criteria evaluation of HSMs<\/h3><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<div class=\"elementor-element elementor-element-ca411b9 elementor-widget elementor-widget-text-editor\" data-id=\"ca411b9\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p>Common Criteria Evaluation of an HSM involves the validation that the HSM or crypto module fulfills a particular set of security objectives and requirements. The HSM or crypto module which has to be evaluated is referred to as TOE (Target of Evaluation) and the security requirements are referred to as ST (Security Target). After the evaluation process, an EAL (Evaluation Assurance Level) is assigned to the product. The EAL ranges from 1 (minimum) to 7 (maximum). EAL rating is basically a rating of testing, not the security. Hence it means that if an HSM has a higher EAL rating then it does not mean that it is more secure, it only means that the HSM has been thoroughly tested and evaluated based on the standards. It is highly recommended to procure\/deploy HSMs which have an EAL rating of 4 or higher.<\/p>\n<p>Source<br><a href=\"https:\/\/hsm.utimaco.com\/blog\/what-are-the-common-criteria-for-hardware-security-modules-hsms\/\" target=\"_blank\">Utimaco:&nbsp;What are the common criteria for hardware security modules (HSMs)?<\/a><br><\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>All the critical banking and payment systems incorporate Hardware Security Modules (HSMs) for the protection of user information and business transactions. HSMs deliver secure management of crypto keys along with encryption\/decryption, digital signatures and authentication mechanisms which are frequently used for the security of corporate business applications.\u00a0 1. Different types of hardware security modules and [&hellip;]<\/p>\n","protected":false},"featured_media":0,"template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news\/4908"}],"collection":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news"}],"about":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/types\/all_news"}],"version-history":[{"count":5,"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news\/4908\/revisions"}],"predecessor-version":[{"id":4914,"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news\/4908\/revisions\/4914"}],"wp:attachment":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/media?parent=4908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}