Overview of Paraview API Security Gateway
Paraview API Security Gateway is an enterprise API management and security platform that provides a centralized gateway for securing, managing, and controlling access to APIs and backend services. The platform enables secure HTTPS communication, policy enforcement, authentication and authorization, certificate management, traffic routing, and monitoring capabilities. Through its centralized management console, administrators can configure security settings and distribute configurations across gateway nodes, allowing organizations to manage API security consistently while ensuring secure and reliable API communications across distributed environments.
Overview of Utimaco u.trust GP HSM
Utimaco u.trust GP HSM is a hardware security module developed by Utimaco IS GmbH. It is a
physically protected, specialized computer unit designed to perform sensitive cryptographic
tasks and securely manage and store cryptographic keys and data. It can be used as a universal,
independent security component for heterogeneous computer systems.
With the Quantum Protect firmware loaded, the u.trust GP HSM provides post-quantum algorithms through three firmware modules:
|
Firmware module |
Capability |
|---|---|
|
a5 ML |
FIPS 204 ML-DSA / FIPS 203 ML-KEM |
|
a6 PQMI |
Post-quantum mechanism distribution |
|
a2 HBS |
Hash-based signatures (LMS / XMSS) |
Firmware modules
This integration uses ML-DSA-65 as provided by the a5 ML module.
Joint Value Proposition
The integration of Paraview API Security Gateway with the Utimaco u.trust GP HSM combines centralized API security and management with hardware-backed cryptographic key protection. By securing TLS private keys within the HSM, organizations can protect sensitive cryptographic assets from unauthorized access, strengthen the security of API communications, simplify certificate and key lifecycle management, and support compliance with security and regulatory requirements while maintaining reliable and scalable API services.
This integration replaces the origin of the server certificate's private key, and the algorithm it uses, with the HSM and its post-quantum firmware:
-
HSM connection settings are entered once in the management console and delivered to the gateway nodes that need them.
-
Certificates are created in the management console — either from an externally generated postquantum key pair, or generated directly inside the HSM — and are delivered to the gateway nodes bound to the same cluster.
-
The PKCS#11 client library required to talk to the HSM is either pre-installed on each node or uploaded once and delivered automatically.
Delivery happens over the product's own mutually authenticated configuration channel and takes effect without restarting a gateway node.