On Line Secure Elements: Deploying High Security Keystores and Personal HSMs

  • Pascal Urien

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper presents innovative approach to deploy secure elements providing cryptographic resources in TCP/IP environment. The main idea is to execute in secure element, TLS1.3 server, secured by 256 bits pre-shared-key. All cryptographic resources are protected by TLS-PSK sessions. In the user plane the secure element is a TLS server, what enables to define uniform resource identifier (URI) for embedded resources. The user is optionally equipped with access card (TLS identity module) that stores procedures working with PSK. The security level may be increased by the use of dedicated terminal, similar to payment terminal, which protects dual factor authentication. We present two open platforms: keystore devices hosting preconfigured TLS-SE secure elements, and personal HSM supporting on-demand TLS-SE applications. Finally we detail some performance elements.

Original languageEnglish
Title of host publication2023 International Conference on Computing, Networking and Communications, ICNC 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages450-455
Number of pages6
ISBN (Electronic)9781665457194
DOIs
Publication statusPublished - 1 Jan 2023
Event2023 International Conference on Computing, Networking and Communications, ICNC 2023 - Honolulu, United States
Duration: 20 Feb 202322 Feb 2023

Publication series

Name2023 International Conference on Computing, Networking and Communications, ICNC 2023

Conference

Conference2023 International Conference on Computing, Networking and Communications, ICNC 2023
Country/TerritoryUnited States
CityHonolulu
Period20/02/2322/02/23

Keywords

  • IOSE
  • Secure Element
  • Security
  • TLS

Fingerprint

Dive into the research topics of 'On Line Secure Elements: Deploying High Security Keystores and Personal HSMs'. Together they form a unique fingerprint.

Cite this