安全代码
Develop and execute sensitive code within a FIPS 140-3 Level 3 certified nShield hardware security module.
最大限度地提升应用安全
CodeSafe is a runtime on the Entrust nShield HSM that allows third-party developers to run their own code within the secure boundary of the module. Using the CodeSafe Developer Kit, developers write their own CodeSafe Apps, cross-compile them, and package them to run on the HSM. While on the HSM, the CodeSafe App is segregated from the actual keys loaded onto the module, including the keys the App uses. This means that CodeSafe can be used without affecting the FIPS 140 validation of the module it runs on.
Example Use Cases For CodeSafe
Secure Manufacturing/IoT
Use CodeSafe as a secure root of trust and policy engine for manufacturing equipment and IoT devices, where firmware signing, device identity, and command authorization must remain safe even in a hostile factory or edge environment.
Cryptocurrency
Run wallet logic and transaction-approval flows within CodeSafe so that private keys and signing policies for digital assets never leave a tamper resistant environment.
令牌化
Use CodeSafe to implement the tokenization engine –PAN→token mapping, detokenization rules, and vault access – entirely inside the HSM.
金融服务业
Beyond basic key storage and protection, use CodeSafe to enforce complex financial controls – such as regulatory checks, per product rules, and conditional signing – at the cryptographic boundary.
Protecting Sensitive Business Logic
Move critical decision logic (risk checks, limits, foureyes rules, approval workflows) into a CodeSafe trusted agent so even a compromised OS or rogue admin cannot bypass it.
Emerging Cryptographic Algorithms
Use CodeSafe to implement, test, and run new or nonstandard cryptographic algorithms (for example, PQC, national algorithms, proprietary schemes) inside the HSM boundary, before or instead of native firmware support.
CodeSafe 的优势
安全敏感型应用程序保护
CodeSafe 可用于在防篡改 nShield HSM 中执行任何类型的应用程序。
防御攻击和恶意软件
在 HSM 的安全范围内执行敏感应用程序,确保程序免受内部和外部威胁,实现应用程序安全。
增强访问控制
CodeSafe 在加密进程和其密钥之间建立了强大的绑定关系。
Entrust nShield Post-Quantum Cryptography Option Pack
- 充分利用 CodeSafe 开发人员工具包
- 遵循新兴的 PQ 标准发展组织,并确保组织的后量子战略符合加密安全要求
- Use for emerging PQC algorithms not currently supported natively in nShield firmware
技术规格
CodeSafe 由两个部分组成: 一部分是用于编译应用程序并为将其导入 HSM 做准备的开发人员工具包,另一部分是保护使用中应用程序的运行时环境。 CodeSafe 不仅为执行安全敏感型应用程序提供了一处独立、受保护的空间,同时还在加密过程与其密钥之间建立了强大的绑定关系。
nShield HSM 兼容性
CodeSafe is available with all FIPS 140-3 Level 3 certified PCIe nShield 5s and network-attached nShield 5c HSMs.
支持的操作系统
支持 CodeSafe 开发的系统包括 Windows 和 RHEL 操作系统
HSM 开发环境
CodeSafe 可与下列编程应用程序兼容:
- C programming languages for embedded applications
- C and Java on host-server
听听我们客户的评价...