|
|
|
This project investigates the usability of open-source and affordable Cryptech HSM modules for various use cases that exist within T&I services delivered via GEANT project (eduGAIN, eduroam, eduTEAMS and InAcademia) and generally for federation operations. The goal of the Cryptech project is to create an open-source hardware cryptographic engine that can be built by anyone from public hardware specifications and open-source firmware and operated without fees of any kind. The team working on the project is a loose international collective of engineers trying to improve assurance and privacy on the Internet. Several GEANT participating NRENs are principle investors and participants in this project. The goal is to set up the Cryptech devices to allow for testing and to identify the initial use cases and the service teams who will be participating in the testing. |
|
Top-down scheme of interests/work areas:
|
In many of the T&I services in the R&E sector, the services from GEANT included, we need to securely store sensitive data like key material. Currently it is very rarely done using HSMs, even though it is well understood such a solution is significantly more secure. Access to and cost of HSM technology is typically cited as the barriers for adoption of HSMs. The Cryptech project offers a relatively low cost HSM solution, with seemingly similar characteristics as compared to generally available commercial offerings. |
This activity does not deal with personal data directly. However use of HSM technologies may in various use case improve the security of the encryption used to store and process personal data. |
The activity is successfully finished when:
|
The HSM devices may be use in followup Incubator activities. |
The work could not be concluded as Diamondkey seased operations during the evaluation period. Resulting documents are provided below. |
Date | Activity | Owner | Minutes |
---|---|---|---|
February 19, 2019 | Kickoff meeting | HSM kick off.pdf | |
HSM Use case and Requirements Matrix
Cryptech HSM - Service Use Cases