2
Chapter 2
Product overview
The SafeNet ProtectServer Network HSM
is a self-contained, security
-
hardened
server providing hardware based cryptographic functionality through a TCP/IP
network connection. The product is used, together with SafeNet high level application
programming interface (API) software, to implement cryptographic service providers
for a wide range of secure applications.
The SafeNet ProtectServer Network HSM is PC based. The enclosure is a heavy duty
steel case and common PC ports and controls are provided. The unit is delivered with
the necessary software components pre-installed on a Linux operating system, in a
“ready to operate” state. Network setting configuration is required, as described in this
document.
The full range of cryptographic services required by Public Key Infrastructure (PKI)
users is supported by using the SafeNet ProtectServer Network HSM’s dedicated
hardware cryptographic accelerator. These services include encryption, decryption,
signature generation and verification, and key management with a tamper resistant
and battery-backed key storage.
To implement a cryptographic service provider, use the SafeNet ProtectServer
Network HSM with one of SafeNet’s high level cryptographic APIs. The provider
types that can be implemented and the corresponding SafeNet high level
cryptographic API required are shown in the following table.
API
SafeNet Product Required
PKCS #11
ProtectToolkit C
JCA / JCE
ProtectToolkit J
Microsoft IIS and CA
ProtectToolkit M
To provide the highest level of security, these APIs interface directly with the
product’s FIPS 140-1 Level 3 certified core. High-speed DES and RSA hardware
based cryptographic processing is used. Key storage is tamper resistant and battery-
backed.
A smart card reader RS232 (V.24) serial port (male DB9 connector) is provided on the
processing module for the secure loading and backup of keys. One smart card reader
with smart cards is also supplied with the unit.
Front panel view
Figure 1 illustrates the front panel of the ProtectServer External 2 appliance.