Introduction

This paper provides an integration guide explaining how to integrate a Hardware Security Module (HSM) -- SafeGuard® CryptoServer with OpenTrust PKI on a Linux operating system platform.

Concepts

OpenTrust PKI is an open, modular and highly scalable solution designed to address more advanced security solutions to combat high level risks. This innovative and market-proven solution is one of OpenTrust’s core products for building a trusted ecosystem. OpenTrust PKI creates, issues and manages the digital identities of users or devices within a Public Key Infrastructure. It oversees the complete credential management for Public Key certificates in IT infrastructures, encompassing any kind of smart card or token that embeds an X.509 certificate and a key pair.

The modular architecture of OpenTrust PKI allows support for singular or multiple applications, management of certificates and keys locally or centrally, and can be implemented within a centralized or decentralized architecture. In its basic and lighter structural design, the public-key operations (PKO) centre forms an integral component of OpenTrust PKI. OpenTrust PKI supports full local or centralized certificate and key life cycle management for all entities (such as users, devices and applications) and multiple CAs for singular or multiple applications.

The SafeGuard® CryptoServer is a hardware security module developed by Utimaco IS, i.e. a physically protected specialized computer unit designed to perform sensitive cryptographic tasks and to securely manage cryptographic keys and data. In a SafeGuard® CryptoServer security system security relevant actions can be executed, and security relevant information can be stored. It can be used as a universal, independent security component for heterogeneous computer systems.