Skip to content

KeyNub USB-C Hardware Security Module

89,95 

A USB-C hardware security module for PKCS#11 and PKI. RSA to 4096 and ECC to P-521 generated inside an EAL6+ certified smart card and never extractable, driverless on Windows, Linux and macOS, with secure boot, signed firmware updates and attestation.

SKU: AB-KN-HSM Category:

Contact us for more information.

Download the datasheet (PDF, one page) — specifications, security architecture and measured performance.

What it is

The KeyNub hardware security module (HSM) is a USB-C device for keys that must never be copyable. Every private key is generated inside the smart card fitted in the device and is non-extractable, so there is no export path to misuse and nothing on the host worth stealing. It is the sibling of the KeyNub license dongle: that one proves a licence is present, this one protects the keys your business runs on.

Keys generated on a certified platform

RSA up to 4096 bits and elliptic curves up to P-521, generated in hardware inside a Common Criteria EAL6+ certified smart card. Measured through the device: an ECDSA P-256 signature in 39 ms, RSA-2048 in 113 ms and RSA-4096 in 1.04 s; key generation takes 1.1 s for EC P-256, 2.6 s for RSA-2048 and 40 to 100 s for RSA-4096.

Driverless on Windows, Linux and macOS

The device presents the standard USB smart-card reader class, so every operating system binds its own built-in driver. There is no driver to install, no INF file and no kernel module. Your PKCS#11 tooling drives it directly: OpenSC, the Windows minidriver into CryptoAPI and CNG, EJBCA, XCA, OpenSSL and Java via SunPKCS11.

You hold every credential

The card ships uninitialised. You set the SO-PIN, the user PIN and the encrypted backup domain yourself, so no KeyNub-held credential exists and nobody but you can ever administer your keys. Encrypted key backup is built in: at initialisation you choose how many shares the device key encryption key is split into, and you hold all of them.

More than a card reader

Most USB devices in this class are a bridge chip in front of a smart card. This one adds the things a bridge cannot:

  • Secure boot — the controller ROM verifies an ECDSA signature over the firmware before it runs, enforced by one-time-programmable fuses, and debug access is permanently disabled.
  • An isolated attack surface — the USB stack and every parser the host can reach run in a separate Arm TrustZone world, unable to address the card, the device identity or storage.
  • Signed firmware updates with automatic rollback — an update that fails its self-test reverts unaided, so an update cannot leave you with a brick.
  • Attestation — a fresh challenge returns a signed report of the firmware version, the configuration and the identity of the card inside.

Practical details

USB-C, USB 2.0 Full Speed, bus powered, in a compact sealed housing with status and fault indicators. Developed and supported in Germany, and shipped from Munich. See the hardware security module page for the full specification.

Need your own branded version?

The KeyNub HSM is available as an OEM platform: your own enclosure, logo, USB VID/PID and custom firmware, with volume manufacturing, under a separate agreement.