HSM Hardware Security Module- 1.Signing Per Second - 1200 TPS, 2. Key Generation - 2 Keys Per Second. 3. Keys should always stored securely in Hardware Security Module only and never stored in software in any form. Complete hardware based storage of key material for entire Life cycle.2Certification- Standards FIPS 140-2 Level 3, CC EAL4,ROHS, FCC part 15 Class B. 4.Key Exchange Symmetric Algorithm- AES, DES, Triple DES, RC2, RC4, RC5, SEED. 5.Random Number Generation FIPS 140-2 approved DRBG SP 800-90 CTR mode. 6.Enhanced Audit Log Facility Error logs managed by separate audit role. Log entries should originate from HSM which should include, when, who, what and result of logging. Audit log entries are ensured against any truncation, modification, deletion, addition. Critical events like tamper, decommissioning, zeroization,SO creation audit role creation should be logged automatically and unconditionally. Logs should be sent to the server before rewriting them.
Other Specifications Download Specification | |
---|---|
SSL VPN Support | Client based Keys are always stored securely in Hardware and never stored in software in any form. Complete hardware based storage of key material for entire Life cycle. Key Length Supported (1024 to 4096) |
Concurrent SSL VPN Users | 3000 Numbers |
SSL VPN Users Scalability | Available |
If Available, Then Scalable Without Changing Hardware Up To | 3000 Numbers |
Network Interface Ports | Dual Gigabit Ethernet Ports |
SSL Throughput (Maximum) | 10 Gbps |
Hardware Based SSL Acceleration | Yes |
SSL Virtual Portals | NA Numbers |
Device With Multicore CPU Support | Yes |
Internal Storage | Not-Available |
If Available, Then Capacity Of Internal Storage | NA GB |
RAM | 128 GB |
Application Support | Should have minimum 20 unique partitions with 100 Client Licenses per HSM with each partition having its own unique serial number. Should support minimum 1000 transactions/second per HSM with RSA 2048. Should support complete use of ECC curves using the same curve without need of any additional licenses. Support for various cryptographic algorithms:- Asymmetric Key with Diffie-Hellman, RSA-2048, RSA-3072 |
Single Sign On (SSO) Feature | Yes |
Secure Access (from Laptops, Desktop, Android, IPhone & Other Smart Devices) | Yes |
URL Masking Feature | Yes |
SSL VPN With ActiveX And JAVA Support | Yes |
Authentication | All |
User Based Access Control | All |
Device Redundancy | 1:1 device Hardware |
Clustering (active-standby / Active-active) Upto Appliances | Enhanced Audit Log Facility & Error logs managed by separate audit role. Log entries should originate from HSM, which should include, when, who, what and result of logging. Audit log entries are ensured against any truncation, modification, deletion, addition. Critical events like tamper, decommissioning, zeroization, SO creation audit role creation should be logged automatically and unconditionally. Logs should be sent to the server before rewriting them |
Support SNMP | Yes |
Support Both IPv4 And IPv6 | Yes |
Interfaces For Device Configuration And Management | Multiple HSMs to be configurable in HA Mode and Full Remote Administration Supported |
Input-Output Port | USB, Serial, etc. Optional |
Power Supply | Dual |
Power Consumption | 110 Watt |
Operating Temperature Range | 0 to 35 Degree C |
Storage Temperature Range | -20 to 60 Degree C |
Operating Humidity (RH) | 5 to 95 % |
Compliance Certificates | PKCS#11, Java (JCA/JCE), Microsoft CAPI And CNG, OpenSSL, REST |
Availability Of Type Tests Reports From A Central Govt. Lab OR International Laboratory Accreditation Cooperation (ILAC)or Their Worldwide Affiliated/ Recognized Labs OR NABL Approved Lab Showing Conformity To The Specifications. | Yes |
Name Of The Lab | NA |
Address Of The Lab | NA |
Test Report No. And Date | NA |
Dimensions (H X W X D) | 48.26 X 53.34 X 4.38 cm x cm x cm |
Weight | 12.7 Kg |
Warranty | 1 |