+1 613 254 5456
adjust font size Increase Font Size Reset Font Size Decrease Font Size

ESS-07: Virtual Security Module

Software developers dealing with keys and other secrets often rely on basic protection of these values through simplistic mechanisms such as folder permissions. This leaves these credentials open to an easy hack. In some cases, secrets may have enough value (such as an RSA or ECC private key for e-commerce) that an expensive hardware security module (HSM) needs to be employed. For many applications however, a well-constructed software system designed to hide keys and secrets can be a cost-effective solution. Elliptic offers this capability through the ESS-07: Virtual Security Module (VSM).

Ellipsys-VSM is part of the Ellipsys Trust Framework which is Elliptic’s solution to help device manufactures and system providers protect their product from tampering, cloning, and other threats.

Ellipsys-VSM is a Virtual Security Module (VSM) that offers software based cryptographic services, similar to a Hardware Security Module (HSM), to support a range of solutions for digital identity and transactional security applications. It is a “software smart card” used to secure embedded secrets in software systems and has the capability to manage and protect sensitive information such as keys and credentials for system applications executing on embedded platforms.

Ellipsys-VSM supports a wide range of protected key management services such as secure key generation, storage, archiving, cloning, and secure migration of key material. The solution optionally provides acceleration for public-key operations via Elliptic (CLP-300: Public Key Accelerator) or third party hardware offload engines.


Ellipsys-VSM can work as a standalone solution or in tandem with other Ellipsys Trust Framework companions, such as Ellipsys-Secure Boot (SB) and Ellipsys-Certification Authority (CA).

 

Features

  • Management and protection of sensitive information like keys and certificates
  • Secure generation, storage , archiving, cloning and migration of key material
  • Highly configurable and flexible architecture
  • Supports industry standards and protocols
  • Support for hardware acceleration and CPU offload
  • Linux and ANSI-C based Builds on generic ARM, PPC, X86 platforms

 

Benefits

  • Highly configurable, flexible and reliable
  • NIST CAVP Certified
  • Optimized for size and performance
  • GPL-Free Code
  • Platform/OS agnostic
  • Significantly reduces development cycles
  • Optional support for hardware acceleration and offload for embedded processors

Applications

  • Anti-cloning and anti-counterfeiting
  • Anti-tampering
  • Key exchange (IPsec IKE)

Downloads

Public Key Accelerator

注目の製品

TEE(Trusted Execution Environments)内で堅固な安全性を実現し、確実に許可されたアプリケーションでのみ保存、処理、アクセスされるように重要情報の保護を強化する実績あるHDCPベースのコンテンツ保護ソリューションです。このソリューションは、信頼性が高く安全性が保証されたOS環境に安全性を重視するコンポーネンツが組み込まれたARM TrustZone™のようなフレームワーク内に、シームレスに統合されます。安全性の重要度が高くないコンポーネンツに関しては、AndroidのようなリッチOSで実行されます。
高度にプログラム可能な独自のSecurity Protocol Acceleratorは、特に超大容量ワイヤレス、ネットワーク・アプリケーション向けに開発されました。このエンジンは、4G LTE-最先端ワイヤレスセルラー・ベースのソリューションやフェムトセルのような異なるコンテキストで複数のアクティブ接続や非常に高いトラフィック負荷を扱うアプリケーションに最適です。