Skip to main content

SID-CRYPTO-01 — PKCS#11 HSM Key Protection

PropertyValue
Statusverified
Ownerplatform
Categorytechnical
CSF Functionprotect
GroupCryptography Controls

Description

Hardware Security Module integration via PKCS#11 for issuer key protection. Supports ECDSA (P-256/P-384/P-521) and RSA signing without key export. Keys never leave the HSM boundary. Multi-backend signer interface abstracts software keys, PKCS#11, and cloud KMS.

Components

  • VC Issuer/Verifier
  • WSCA / HSM

Source References

Audit Findings

FindingSeverityStatus
EN-S-2 — Partial asset classification and cryptographic documentationmediumin progress