|
|
|
This project investigates the usability of recently developed Cryptech HSM modules for various usecases we have in T&I in eduGAIN, eduroam, eduTEAMS, InAcademia and generally for federation operations. The goal of the CrypTech project is to create an open-source hardware cryptographic engine that can be built by anyone from public hardware specifications and open-source firmware and operated without fees of any kind. The team working on the project is a loose international collective of engineers trying to improve assurance and privacy on the Internet. Several GEANT participating NRENs are principle investors and participants in this project. In this phase we set up the devices to allow for testing and we collect the initial usecase we want to test and the people who will be testing. |
In this activity we gather requirements for HSM usage in GEANT services and the broader R&E community. We investigate the usability of the Cryptech devices technically and functionally. We discuss our findings with the community and the Cryptech project team. We set up a testbed so service owners may test specific requirements against the devices. The testing itself is likely being done in a followup activity. |
Top-down scheme of interests/work areas:
|
In many of the T&I services in the R&E sector, the services from GEANT included, we need to securely store sensitive data like key material. Currently it is very rarely done using HSMs, even though it is well understood such a solution is significantly more secure. Access to and cost of HSM technology is typically cited as the barriers for adoption of HSMs. The Cryptech project offers a relatively low cost HSM solution, with seemingly similar characteristics as compared to generally available commercial offerings. |
This activity does not deal with personal data directly. However use of HSM technologies may in various use case improve the security of the encryption used to store and process personal data. |
The activity is successfully finished when:
|
The HSM devices may be use in followup Incubator activities. |
Please provide pointers to completed and intermediary results of this activity |
Date | Activity | Owner | Minutes |
---|---|---|---|
February 19, 2019 | Kickoff meeting | HSM kick off.pdf | |
HSM Use case and Requirements Matrix
Cryptech HSM - Service Use Cases