Depending on its design, it may generate, store, use, wrap, unwrap, back up, or destroy keys and execute signing, decryption, message authentication, or other functions while keeping designated secret or private keys inside that boundary.
An HSM can be an appliance, an expansion card, an embedded component, or infrastructure exposed through a managed service. Applications call it through controlled interfaces, while authentication, roles, authorization rules, separation of duties, and audit records govern who can request sensitive operations.
Key points
Security boundaryDocument which hardware, firmware, software, interfaces, keys, and operations are inside the evaluated boundary, along with approved operating modes and physical protections.
Key lifecycleDefine generation, import, export restrictions, backup, recovery, rotation, revocation, deletion, and dual-control procedures without creating unmanaged copies of protected keys.
Integration and resilienceAuthenticate callers, restrict permitted operations, protect administration, monitor activity, and design capacity, redundancy, and recovery for applications that depend on the module.
Important limitationAn HSM protects specified cryptographic functions; it does not make the host, application, administrator, supply chain, or key policy trustworthy. Federal Information Processing Standard (FIPS) validation applies to an exact module version, configuration, and approved mode — not automatically to a wider product, deployment, or compliance program.