A financial enterprise is deploying specialized infrastructure across regional offices to process centralized database transaction encryption. The security team requires a dedicated hardware-based solution capable of performing high-throughput cryptographic operations while securely storing master keys. The device must ensure keys cannot be extracted even if an adversary gains root access to the host operating system or opens the chassis physical casing. Which of the following hardware security controls best meets these requirements?
- Hardware Security Module (HSM)Cevap
- BTrusted Platform Module (TPM)
- CSelf-Encrypting Drive (SED)
- DAsymmetric software key vault service
Cevap
A Hardware Security Module (HSM) is the appropriate control because it provides physical tamper-responsive protection and isolated cryptographic processing for master keys independent of host operating system security.
A Hardware Security Module (HSM) is a hardened, plug-in or external device dedicated to safeguarding digital keys and accelerating cryptographic operations. HSMs feature specialized physical security measures (such as tamper-detecting covers and zeroization circuits) that protect stored keys against both physical access and host system compromise.
Adım Adım Çözüm
Anahtar Kavram
Hardware Security Module (HSM) functionality and tamper protection