| name | performing-hardware-security-module-integration |
| description | Integrates Hardware Security Modules (HSMs) via the PKCS#11 interface using python-pkcs11, performing key generation, signing, encryption, verification, and token/slot queries against SoftHSM2, AWS CloudHSM, or YubiHSM2. Use when implementing HSM-backed key management or validating HSM configuration for FIPS 140-2/3 compliance. |
| domain | cybersecurity |
| subdomain | cryptography |
| tags | ["HSM","PKCS11","CloudHSM","YubiHSM2","key-management","cryptographic-operations","hardware-security"] |
| version | 1.0 |
| author | mahipal |
| license | Apache-2.0 |
| nist_ai_rmf | ["MEASURE-2.7","MAP-5.1","MANAGE-2.4"] |
| atlas_techniques | ["AML.T0070","AML.T0066","AML.T0082"] |
| nist_csf | ["PR.DS-01","PR.DS-02","PR.DS-10"] |
| mitre_attack | ["T1600","T1573","T1553","T1078.004","T1530"] |
Performing Hardware Security Module Integration
Overview
Hardware Security Modules (HSMs) provide tamper-resistant cryptographic key storage and operations. This skill covers integrating with HSMs via the PKCS#11 standard interface using python-pkcs11, performing key generation, signing, encryption, and verification operations, querying token and slot information, and validating HSM configuration for compliance with FIPS 140-2/3 requirements.
When to Use
- When conducting security assessments that involve performing hardware security module integration
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Prerequisites
- HSM device or software HSM (SoftHSM2 for testing)
- PKCS#11 shared library (.so/.dll) for the HSM vendor
- Python 3.9+ with
python-pkcs11
- Token initialized with SO PIN and user PIN
- For AWS CloudHSM:
cloudhsm-pkcs11 provider configured
Steps
- Load PKCS#11 library and enumerate available slots and tokens
- Open session and authenticate with user PIN
- Generate RSA 2048-bit or EC P-256 key pairs on the HSM
- Perform signing and verification using on-device keys
- List all objects (keys, certificates) stored on the token
- Query mechanism list to verify supported algorithms
- Generate compliance report with key inventory and algorithm audit
Expected Output
- JSON report listing HSM slots, tokens, stored keys, supported mechanisms, and compliance status
- Signing test results with key metadata and algorithm details