{"id":5134,"date":"2022-03-16T15:47:25","date_gmt":"2022-03-16T07:47:25","guid":{"rendered":"https:\/\/www.progreso.com.sg\/newsite\/?post_type=all_news&#038;p=5134"},"modified":"2022-03-16T16:34:38","modified_gmt":"2022-03-16T08:34:38","slug":"hardware-security-modules-hsm-digital-identities","status":"publish","type":"all_news","link":"https:\/\/www.progreso.com.sg\/newsite\/all_news\/hardware-security-modules-hsm-digital-identities\/","title":{"rendered":"Blog: Understanding the Role of Hardware Security Modules in Digital Identities for Humans"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"5134\" class=\"elementor elementor-5134\" data-elementor-settings=\"[]\">\n\t\t\t<div class=\"elementor-inner\">\n\t\t\t\t<div class=\"elementor-section-wrap\">\n\t\t\t\t\t\t\t<section class=\"elementor-element elementor-element-d24df7d elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-top-section\" data-id=\"d24df7d\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1367e80 elementor-column elementor-col-100 elementor-top-column\" data-id=\"1367e80\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e796bd8 elementor-widget elementor-widget-text-editor\" data-id=\"e796bd8\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p>On 23 July 2014, the European Union established\u00a0<a href=\"https:\/\/www.utimaco.com\/compliance\/compliance-and-standardization\/eidas-compliance\" rel=\"noreferrer\">eIDAS<\/a>\u00a0(electronic IDentification, Authentication and trust Services) that regulates electronic transactions, electronic signatures, involved bodies, and their embedded processes. Having taken effect on 1 July 2016, eIDAS provides a safe way for users to perform actions such as electronic funds transfers or transactions with government agencies.<\/p><p>eIDAS created standards for trust services to ensure that digital identities, including those for humans remain secure with the presumption of integrity, and are exclusively linked to the individual, entity, or machine through cryptographic protections. Such strict eIDAS standards require the security that\u00a0<a title=\"Categories\" href=\"https:\/\/utimaco.com\/products\/categories\" data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"f926937f-376b-4c6d-8edf-be1a45b0f3ad\">hardware security modules (HSMs)<\/a>\u00a0offer. Here we will examine the role that HSMs play in securing digital identities for humans.<\/p><h2>Digital Identity with eIDAS<\/h2><p>One of the greatest things to come out of eIDAS is it has provided the means to facilitate secure and seamless electronic transactions across EU member state borders and ideally with non-EU countries. A digital identity opens the door for a person with an officially authenticated identity to conduct business electronically, including signing legal or financial documents. However, this means first securing an electronic identification.<\/p><p>As defined under eIDAS, an \u201celectronic identification&#8221; means the process of using person identification data in electronic form uniquely representing either a natural or legal person, or a natural person representing a legal person.<\/p><p>For an electronic identification to be performed, the process of authentication. According to eIDAS, this is \u201can electronic process that enables the electronic identification of a natural or legal person, or the origin and integrity of data in electronic form to be confirmed.\u201d This process is performed through a trust service provider (TSP). A TSP is an entity that provides and preserves digital certificates that are used to authenticate digital identities.<\/p><h2>Role of HSMs with Digital Identity<\/h2><p>The Common Criteria Protection Profile \u2013 Cryptographic Module for Trust Service Providers outlines the security requirements that TSPs must follow with their authentications services under eIDAS. A cryptographic module, such as an HSM is required to generate and\/or protect the secret keys and other sensitive data and control the use of such data for one or more cryptographic services to support TSP trust services.<\/p><p>An HSM that is Common Criteria-certified according to the eIDAS Protection Profile (PP) EN 419 221-5 \u201cCryptographic Module for Trust Services\u201d allows trust service providers to be in compliance with the policy and its security requirements. Such HSMs:<\/p><ul><li>Have key authorization functionalities that are suited for eIDAS-compliant issuance of qualified certificates.<\/li><li>Provide protection to keep cryptographic material protected and hidden at all times.<\/li><li>Run on a secure operating system.<\/li><li>Are resistant to hacking attempts because they are built with specialized and secure hardware.<\/li><li>Have limited access through a strictly-controlled network interface.<\/li><li>Offer an additional layer of security by storing decryption keys separately from encrypted data to ensure that if a data breach does occur, the encrypted data is kept secured.<\/li><li>Strengthen cryptographic encryption practices throughout the entire key lifecycle from generation to storage to distribution to disposal.<\/li><\/ul><p>Utimaco HSMs are\u00a0<a title=\"CryptoServer CP5\" href=\"https:\/\/utimaco.com\/products\/categories\/general-purpose-solutions\/cryptoserver-cp5\" data-entity-substitution=\"canonical\" data-entity-type=\"node\" data-entity-uuid=\"e58ce86c-16e1-4ae1-a9f4-17f4c5af3f85\">certified under eIDAS standards<\/a>\u00a0in order to achieve higher levels of data security and trust whilst also maintaining high service levels and business agility. They provide a scalable and FIPS-compliant compliant hardware solution for secure key storage and processing inside the boundary of the HSM.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>On 23 July 2014, the European Union established&nbsp;eIDAS&nbsp;(electronic IDentification, Authentication and trust Services) that regulates electronic transactions, electronic signatures, involved bodies, and their embedded processes. Having taken effect on 1 July 2016, eIDAS provides a safe way for users to perform actions such as electronic funds transfers or transactions with government agencies. eIDAS created standards [&hellip;]<\/p>\n","protected":false},"featured_media":0,"template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news\/5134"}],"collection":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news"}],"about":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/types\/all_news"}],"version-history":[{"count":3,"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news\/5134\/revisions"}],"predecessor-version":[{"id":5138,"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news\/5134\/revisions\/5138"}],"wp:attachment":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/media?parent=5134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}