Security Hardware

Micro HSM

USB Micro HSM — personal cryptographic shield for developers and privileged access

USB Micro HSM · Personal Shield

Portable hardware security for developers, administrators, and privileged access.

In direct endpoint mode, connect via the dedicated SDK; high-assurance cryptographic operations run on the device without a central server. Keys never leave the chip.

Direct Endpoint

Local SDK connection — server-free crypto operations on a single workstation.

SSH · 2FA · PKCS#11

SSH key protection, two-factor authentication, and qualified digital signatures.

Physical Protection

A compact USB personal security shield for privileged accounts.

kHSM hardware security module — Kayten HSM in USB form factor

Product Showcase

USB Micro HSM

Keys never leave the chip

Key Features

High-Performance Cryptographic Acceleration

Hardware-accelerated AES-128 CBC, SHA-256, and ECDSA-256 — measured on TC375 with a 100 MHz HSM core: AES-128 CBC HW 4,065 op/s (1 KB), SHA-256 HW 19,230 op/s (1 KB), ECDSA-256 signing ~216 op/s.

Secure Key Generation & Storage

Hardware-based True Random Number Generator (TRNG) compliant with AIS 31 for cryptographically secure key generation and tamper-resistant key storage.

PKCS#11, PKCS#8 Support

PKCS#11 (Cryptoki) for signing, verification, AES/ECDSA/ECDH, and key management; PKCS#8 for secure key import/export. Integrates with OpenSSL and enterprise stacks — private keys never leave the hardware.

Secure Updater

Encrypted Secure Updater that can update itself as well as the application and the HSM — signed, tamper-protected update paths without insecure firmware delivery.

Technical Specifications

Cryptographic Algorithms & Functions

  • Symmetric cryptography: AES with 128/256-bit key lengths (CBC, GCM modes).
  • Asymmetric cryptography: RSA with 2048/4096-bit keys; ECC with NIST curve P-256.
  • Hash algorithms & MAC: SHA-256/384/512; HMAC-SHA256/384/512.
  • Random number generation: Hardware-based True Random Number Generator (TRNG) according to AIS 31.

Secure Updater

  • Update payloads are received and processed encrypted with AES-128.
  • Update integrity and authenticity are verified via asymmetric signature verification (e.g. ECDSA).
  • Supports secure self-update as well as application and HSM updates.

Performance Benchmarks

Detailed performance measurements of our cryptographic operations on embedded platforms.

SHA-256 (Hardware)

32 Byte 40,000 op/s
64 Byte 93,457 op/s
128 Byte 76,923 op/s
256 Byte 54,644 op/s
1 KB 19,230 op/s

AES-128 CBC (Hardware)

32 Byte 23,255 op/s
64 Byte 28,169 op/s
128 Byte 20,202 op/s
256 Byte 12,820 op/s
1 KB 4,065 op/s

ECDSA-256

Signature Generation

32 Byte 219 op/s
64–256 Byte 216 op/s
1 KB 210 op/s

Signature Verification

32–256 Byte 122 op/s
1 KB 120 op/s

ED25519

Signature Generation

32 Byte 119 op/s
64 Byte 114 op/s
128 Byte 111 op/s
256 Byte 105 op/s
1 KB 78 op/s

Signature Verification

32 Byte 144 op/s
64–128 Byte 140 op/s
256 Byte 136 op/s
1 KB 116 op/s

Lower Energy Use

than external HSM modules

On-chip integration removes the need for separate HSM hardware

Cost Advantage

over discrete HSMs

Integration replaces a dedicated hardware component

Parallel Processing

for cryptographic operations

Multiple crypto operations run concurrently without blocking the CPU

Measurement conditions (HSM Performance Report v0.3): TC375 host at 300 MHz, HSM core at 100 MHz, Saleae Logic at 500 MS/s. Figures are minimally optimized measured results. Total time = start + operation + response.

Use Cases

Industry & IoT

  • Protection of production data
  • Device authentication
  • Secure cloud connectivity
  • Compliance with industry standards

Defense

  • Classified information protection
  • High security communication
  • Hardware security modules
  • Certified security solutions

Other Critical Systems

  • Medical device security (MDR/IVDR compliance)
  • Energy infrastructure (Smart Grid, meters)
  • Aerospace & satellite communications
  • Secure payment terminals & kiosks