Technical Specifications
Algorithms
- RSA (512, 1024, 1152, 1408, 1536, 1976, 1984, 2048, 2304, 2502, 2816, 3072, 4096 or 8192 bits)
- ECDSA (128, 160, 192, 256, 384, and 521 bits)
- ECX EdDSA (Ed25519 and Ed448)
- ECDH (128, 160, 192, 256, 384, and 521 bits)
- XECDH (X25519 and X448)
- ML-DSA (NIST Categories 2,3,5) 1
- ML-KEM (NIST Categories 1,3,5) 1
- SLH-DSA (SHA-256/SHAKE-256/Small/Fast NIST Categories 1,3,5) 1
- DES
- 3DES (112 and 168 bits)
- AES (128, 192 and 256 bits)
- MD5
- SHA1
- SHA2 (224, 256, 384 and 512 bits)
- SHA3 (224, 256, 384 and 512 bits)
- HMAC based on SHA1, SHA2, and SHA3 hash algorithms.
Operating Modes
- Non Restrictec Mode(NRM)
- Restricted Mode 1(RM1)
- Restricted Mode 2(RM2)
APIs
- MS Crypto API
- Java JCA/JCE
- PKCS#11
- KMIP Protocol v1.4
- Native API (Cryptography and Management)
Operating Systems
- MS Windows
- Linux
- Others (upon request)
Cloud
- BYOK (Bring Your Own Key)
- Azure Cloud Services
- Amazon Web Services
Storage
- Key protection master (Server Master Key) on smart card
- User-based partition separation
- Different privilege levels
- Encrypted Backup
Management
- Local Console (trusted path)
- Remote Console (network)
Modules (Engines)
- Core Crypto
- State Manager
- EFT
- EFT Direct
- Blockchain
- OATH
- SPB
- XML DSig
- Pix
- SVault
- TSP
AAA
- Authentication: authentication by identity
- Authorization: granular authorization by permissions
- Accounting: internal audit trail
Communication
- Open channel (remote console/API)
- Encrypted channel – TLS (remote console/API)
- Simultaneous sessions (up to 1500 application server connections)
Auditing
- Persistent event logging
- Log retrieval
Monitoring
- Events
- CPU, memory, and active sessions
- Battery, memory, and controller diagnostics
Authentication
- Regular (remote console/API)
- TFA - Two Factor Authentication (remote console/API)
Connectivity
- Ethernet 10/100 Mpbs RJ-45
Certifications
Performance
| metric | Value |
|---|---|
| Signatures per second RSA@2048 | 60 |