Navigation

Get in touch
Logo
News

Services from OTOKO®

HSM: your keys. Your control.

OTOKO® advises on, supplies and integrates hardware security modules for PKI, code signing, payments and the protection of corporate data. We connect the right hardware or cloud service to your applications, including key management, commissioning, recovery and agreed support.

macro photography of black circuit board — illustrative image
HSM & Key Management · Planning and implementation by OTOKO®

Hardware security module · Simply explained

Protect the secret. Control its use.

Encryption helps little if the corresponding key sits unprotected next to the data. An HSM creates its own security boundary: applications can request approved key operations without receiving the private key as a file.

OTOKO® connects this protection to your processes. Who may sign? What happens in the event of a failure? How does older data remain readable after a key change? This is how the architecture takes shape, and only then the product selection.

  1. 01 / Application

    Submit request

    An authorized application submits the signing request via the supported interface.

  2. 02 / HSM

    Execute securely

    The module performs the permitted operation. The non-exportable private key stays within its security boundary.

  3. 03 / Result

    Continue processing

    The application receives the signature. Approvals, rights and logs secure the process outside the module.

The operating decision

Where should your keys work?

There is no operating model that is best for every application. Compare control, integration effort and failure dependencies together with cost.

Your own hardware

If you want to control devices, location and maintenance yourself.

What we clarify with you

Budget for a network HSM or PCIe card, redundancy, backup devices, administration and vendor support together.

Evaluate model

HSM as a service

If a suitable cloud or service interface fits your applications.

What we clarify with you

Review API, region, role distribution, ongoing costs and exit. Managed hardware does not replace permission planning.

Evaluate model

Hybrid

If applications and key tasks are distributed across several environments.

What we clarify with you

Map trust boundaries and network dependencies. Assess BYOK and external key management specifically for each service.

Evaluate model

From use case to product

Hardware that fits the task.

We assess product families based on required functions and supported integration. A vendor name, form factor or a certification logo alone is not enough for this decision.

6 specific services

How can we support you?

Do you want to secure a certificate authority, remove signing keys from a build pipeline or replace an existing HSM generation? Start with the specific use case. Our six services cover selection, integration and operation. You can order a single work package, or plan the implementation with us from current-state review to handover.

01

HSM architecture

An HSM must handle your real key operations and fit your applications, security requirements and operating structure. We translate these requirements into a well-founded device and architecture decision, before hardware is procured or you commit to a cloud service.

Service in detail
02

PKI & certificates

Certificates link identities to keys. We plan certificate hierarchies, protect CA and signing keys in the HSM and integrate issuance, renewal and revocation into your environment. For software releases, we develop a controlled signing process instead of freely available key files.

Service in detail
03

Payment HSM

In payments, key handovers, PIN processing and system changes must work together in a controlled way. We plan the technical HSM integration and the associated procedures with those responsible on your side. Roles, approvals and documented ceremonies are part of the implementation.

Service in detail
04

Key management

An HSM only protects your application once keys are correctly generated, used, renewed and backed up. We connect applications and key services and design the lifecycle so that operations and development can work with it reliably.

Service in detail
05

HSM as a Service

You need protected key operations but do not want to operate every infrastructure component yourself. We evaluate HSM services and cloud connections based on key control, access paths, locations and exit options, and integrate the suitable solution into your applications.

Service in detail
06

HSM operations

Protected keys must remain usable even during updates, device failures and staff changes. We take on agreed operating tasks for your HSM environment and prepare maintenance, recovery and hardware generation changes using documented procedures.

Service in detail
Meeting room at the OTOKO® Cologne office

Scoping the work properly

A clear starting point. A shared goal.

A device validation does not automatically confirm the security of an entire application. Requirements, product version, operating mode, permissions and organizational procedures must fit together. Availability and response times are explicitly agreed.

Bring your situation, the systems involved and the result you want. We clarify which service enables the next step and what preparation is required for it.

Discuss your situation

Before the first step

Your questions about HSM & Key Management.

What is a hardware security module and what does it do?

An HSM is a specialized hardware component for cryptographic keys and operations. It can generate keys within its security boundary and use them, for example, for signing, without releasing the private key to the application. Which operations, protection mechanisms and export rules apply depends on the specific module and its configuration.

When is an HSM worthwhile for a midsize company?

If the loss of a key or a misused signing key would have significant consequences, a structured review is worthwhile. Examples include software releases, an in-house PKI or keys for sensitive business data. Scope, integration effort and operations must match the risk. Not every application needs its own device; a suitable managed service can also be an option.

What is the difference between HSM, KMS and TPM?

An HSM provides a protected environment for key operations. A key management system (KMS) organizes keys, permissions, versions and lifecycles, and can use an HSM as a protection component. A Trusted Platform Module (TPM) is typically bound to a single platform, for example for its integrity and device-bound keys. These tasks overlap in part but are not interchangeable.

Which vendors can OTOKO® consider?

Our product range includes HSM solutions from Utimaco, Thales, Entrust, IBM, Futurex, Marvell and IDEMIA. For a project, we review the specific series, the supported applications and the required evidence. Naming a vendor does not mean that every model supports every interface or every use case.

What does an HSM project cost?

In addition to hardware or service fees, costs include client and feature licenses, redundancy, backup, integration, testing, training and ongoing support. A reliable quote is based on your operations, load peaks, locations and operating requirements. We separate one-time implementation costs from recurring costs and make the necessary options visible.

Does an HSM automatically mean compliance or suitability for VS-NfD?

No. Module validation or product certification has a defined scope. Deployment depends on factors such as the product version, operating mode, application, processes and the specific evidence required. Suitability for classified information is also reviewed separately and is not inferred from the term HSM.

Can an attacker trigger a signature despite an HSM?

An HSM can make it harder to extract a key. A compromised application with valid signing authorization can still submit unauthorized requests. This is why application identities, tightly limited rights, approval processes and monitoring are part of the solution. Key protection and control over key usage are planned together.

How does an HSM project with OTOKO® begin?

Bring an overview of your applications, existing devices and client versions, key types and your main operating requirements. Together, we scope the task. Depending on the assignment, we then deliver a selection decision, evidence of a working integration or a migration and operations plan with traceable acceptance criteria.

Your project

Which task would you like to solve?

Describe your situation and the desired result. The selected service will be included in the contact request.

Discuss your project

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.