Hardware Security Module (HSM)
E3. Technology, digitalization and smart shippingDefinition
Dedicated crypto device used in eBL/PKI.
A hardware security module is a tamper-resistant physical device that generates, stores, and uses cryptographic keys inside a hardened boundary, so private keys never leave in plaintext. In shipping it underpins public-key infrastructure (PKI) for electronic bills of lading and the SSAS, and signs or verifies X.509 certificates and digital signatures. HSMs are validated against FIPS 140-2/140-3 (NIST) or Common Criteria, and they perform key operations at a rate suited to certificate authorities and transaction signing without exposing the key material.
Source: NIST FIPS 140-3, Security Requirements for Cryptographic Modules