What Does the PrivateServer HSM Do?PrivateServer provides a wide range of cryptographic operations, such as data encryption and secure key storage, for application servers using TCP/IP. EMV Applications:
»
EMV card issuance. PrivateServer HSM is used within physical card issuing processes for performing the decryption of sensitive material coming from the issuer and re-encrpyting it before writing to the card. » EMV authorizations. PrivateServer-HSM can be used as part of the issuer application to verify transactions that were made using EMV cards. The ability of PrivateServer-HSM to handle large amount of EMV transaction is outstanding (5000 triple DES based transactions such as verify ARQC - per second). » EMV data preparation. PrivateServer HSM serves many roles in the Data Preparation processes within EMV card issuing centers, including: key generations, encryption of sensitive information, storage of issuer key and certificate, and more. » EMV-CAP authorization. PrivateServer-HSM can be used as part of the issuer application to verify transactions that were made using EMV cards. The ability of PrivateServer-HSM to handle large amount of EMV transaction is outstanding (5000 triple DES based transactions such as verify ARQC - per second). » PIN verification. These operations are used for both generating the personalized information that is put inside the magnetic strip such as CVV creation or PIN generation. Also, PrivateServer-HSM is capable of performing verification operations such as PIN verification, CVV verification etc. PKI Applications: » CA Signing Engine. PrivateServer can be used as a hardware-based signing engine for CA systems that use PKCS#11 or CAPI interface. For example, PrivateServer can be easily integrated with Microsoft CA running on Windows 2003 or Windows 2008 servers.
»
SSL Acceleration. In order to relieve the burden of cryptographic operations in Web servers, it is common practice to offload such operations to an externally-attached HSM such as PrivateServer.
» EKM Provider forMicrosoft SQL Server 2008.
PrivateServer has an Extensible Key Management (EKM) plug-in for Microsoft SQL Server 2008. This feature enables vendors to integrate with the database, encrypt sensitive data and store private keys in an external hardware device.
» Microsoft Certificate LifeCycle Management.ARX's PrivateServer hardware security module (HSM) can be easily integrated with Microsoft Identity Lifecycle Manager (ILM) application. With PrivateServer, an organization can enhance the overall security of the ILM solution by:
PrivateServer can be integrated with solutions based on smart cards from any vendor that has a minidriver that implements Microsoft Base CSP API. » General Purpose Cryptographic Appliance. PrivateServer offers a wide range of cryptographic algorithms through standard interfaces such as PKCS#11 and CAPI.
The combination of a dedicated cryptographic server and cryptographic enhancements delivers toplevel performance together with heightened security. For example, PrivateServer is capable of performing:
Advanced Features: » Module Development Kit. The PrivateServer MDK enables customers and partners to develop their own custom modules that will be executed within the secure environmet of the PrivateServer HSM. PrivateServer MDK takes full advantage of the .NET environment and development tools to develop code that access the functionality of the PrivateServer API and performs cryptographic operations, generates keys and runs numerous other applications. The code is based on programming languages and tools supported by .NET Framework 2.0. These include: C#, VB .NET, Microsoft Visual Studio 2005 and many others. » PINMailer Printing. PrivateServer enables customers to securely output a PIN Mailer to a printer that is attached to the PrivateServer HSM. It can be used to print advanced PIN Mailer designs that contain both text and graphics. PrivateServer supports a large variety of printer brands of both PostScript and PCL printer types, depending on organizational needs. The printer can be directly attached to the PrivateServer through a parallel interface, serial interface, or by using a dedicated Ethernet based network interface. How Does the HSM Work?Any application that requires a cryptographic-based process will access PrivateServer through the network using the PrivateServer client. All data transferred across the network is encrypted. The process then takes place in the server, which accesses relevant keys provided the connecting user has the necessary permissions to do so. The entire operation is performed by PrivateServer, which then replies back to the client application to enable the transaction. Back to TopPrivateServer HSM Benefits
Back to Top
Who is the Solution Aimed At?
PrivateServer is aimed at financial institutions, card issuers, and governmental organizations requiring security-related deployments such as the CA Signing Engine, EMV data preparation and card personalization, PIN verification, data encryption, and data signing.
CertificationFIPS 140-2 level 3 certification granted.
Back to TopSelected Customers
Back to TopTechnical Specifications
Ready to learn more about the benefits of using PrivateServer HSM (Host Security Module) for data encryption, key storage, and management? Get more information today or Contact us here and we’ll be happy to explain why this system is a must-have for secure key storage. Learn about CoSign’s digital signature solution or try the free CoSign demo online. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||







Back to Top