Back to glossary

Hardware security module (HSM)

1 min read

A hardware security module is a dedicated device that generates and stores cryptographic keys and performs operations with them, built so that the key material cannot be exported in the clear. Applications send data to be signed or decrypted and receive a result, never the key itself.

July 29, 2026
Compartir:

What is being bought is a boundary and an assurance about it. The boundary means a compromise of the application server yields the ability to use a key while that access lasts, not a copy of the key that keeps working afterwards. The assurance comes from independent validation, which is why procurement documents refer to the FIPS 140 validation levels and, in Europe, to Common Criteria evaluation and to the requirements that apply to devices used for qualified electronic signatures.

Where it appears in a Spanish context is fairly predictable: as the root of a public key infrastructure, in payment environments where the card standards require it, in the higher category levels of the national security scheme, and wherever an electronic signature has to carry legal weight. A managed KMS in a public cloud covers most other cases at a fraction of the operational cost, and the providers offer a dedicated single tenant option where a validated boundary is specifically required.

The observation worth making is that a device of this kind protects the key and not the authorisation to use it. If any application identity can call the sign operation without constraint, an attacker who reaches that identity gets everything they need without ever touching the key. What we look at is who can invoke each operation, whether those calls are logged, and whether anyone reviews them, because that is where the boundary is actually decided.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.