Physical device for secure cryptographic key storage and operations, resistant to tampering.
A Hardware Security Module (HSM) is a dedicated physical device for secure cryptographic operations and key storage. HSMs generate, store, and manage cryptographic keys in tamper-resistant hardware—keys never leave the device in plaintext. HSMs are used for protecting certificate authority keys, payment system cryptography, and high-security applications. Cloud providers offer HSM-as-a-service. HSMs provide the highest level of key protection but add cost and complexity.
Why It Matters
The DSC Perspective:
HSMs provide the highest key security assurance. They're required for some compliance (payment processing) and valuable for protecting critical keys. Cloud HSM services make this capability more accessible.
