Vectera Plus
General-purpose hardware security module
General-purpose hardware security module
The Vectera Plus is a hardware security module (HSM) designed for general-purpose encryption and key management. The Vectera Plus is capable of the industry’s fastest processing speeds and can integrate with a wide variety of host applications. It supports all major encryption algorithms and complies with strict international standards like FIPS 140-2 Level 3 and PCI PTS HSM. The Vectera Plus can even support payments processing, making it a highly scalable long-term solution.
Create dozens of virtual HSMs with hundreds of application partitions to expand functionality and use cryptographic resources more effectively.
Futurex solutions support all major encryption algorithms (symmetric and asymmetric), standard client libraries, and APIs for swift integration.
Load, test, and execute custom applications and code within the boundary of the Vectera Plus’s Secure Code Environment (SCE).
The Vectera Plus is ideally suited for general-purpose cryptography, from securing applications and databases to encrypting keys. It supports all common APIs for easy integration with host applications. Like all Futurex solutions, the Vectera Plus’s functionality and performance can be scaled according to need. It can be deployed on-premises, in the cloud, or in a hybrid configuration.
Click diagram to enlarge
Whether securing databases, protecting emails, or encrypting files in compliance with HIPAA, the Vectera Plus can fill nearly any cryptographic role.
The Vectera Plus can be controlled with an intuitive web interface or through APIs. Add the Excrypt Touch for point-and-click key loading and configuration.
Thanks to a shared code base, the Vectera Plus easily integrates with other Futurex HSMs, key management servers, and cryptographic management tools.
The Vectera Plus supports all major cryptographic algorithms. Continuous support for new algorithms ensures your infrastructure remains secure.
The Vectera’s SCE is a powerful tool for organizations to both protect and refine their host applications, custom code, and API extensions.
Futurex solutions comply with strict regulatory requirements like PCI HSM, FIPS 140-2 Level 3, ANSI X9.24 part 1 and 2 – TR-39, and FCC part 15 – class B.
Apache: HTTP Server and Tomcat
The Vectera Plus offers easy integration with Apache HTTP Server and Apache Tomcat web server software.
Axway
Use the Vectera Plus to validate digital certificates stored on CAC cards, PIV cards and in software, via Axway Validation Authority integration.
HashiCorp Vault: Seal Wrap & Entropy Augmentation and Managed Keys
The Vectera Plus integrates with two services offered by HashiCorp Vault: Seal Wrap & Entropy Augmentation and Managed Keys. Manage secure data vaults for certificates, tokens, credentials, and managed encryption keys.
BIND 9
Integrate with the flexible, open-source BIND 9 DNS software suite. Between the Vectera Plus’s support for numerous APIs and the full-featured BIND 9, integration options abound.
CyberArk Vault
Create and configure secure credential storage vaults with the Vectera Plus. Use the CyberArk Vault integration to protect and manage privileged access across your organization’s on-premises and cloud infrastructure.
EJBCA
Bring high-performance general purpose encryption of the Vectera Plus to your open-source CA and PKI functionality in EJBCA. The platform-independent flexibility of EJBCA matches the many vendor-agnostic APIs supported by the Vectera Plus.
ISC CertAgent
The Vectera Plus includes a range of vendor-neutral APIs which allow it to integrate with the customer-hosted and easy-to-use ISC CertAgent CA to issue X.509 certificates.
Java Jarsigner
Establish digital signing operations for Java JAR files to authenticate them with the Vectera Plus’s support for Java Jarsigner.
Microsoft SignTool
Digitally sign and verify signatures of files with Microsoft SignTool support.
Microsoft Windows Certificate Store
Store certificates on local computers using the Microsoft Windows Certificate Store via the Vectera Plus. Certificate stores can accept certificates from different CAs.
OpenSSL Engine
Easily integrate with OpenSSL to generate private keys and create CSRs with the Vectera Plus.
Protegrity
Connect the Vectera Plus encryption functionality to the data protection capabilities of Protegrity.
Microsoft AD CS
Securely support Microsoft AD CS in creation and management of client Public Key Infrastructure (PKI) certificates by centralizing private key storage in the Vectera Plus hardware security module. For more information on Futurex’s AD CS integration methods, visit our Microsoft AD CS Technology Solutions page, or download our informational brochure.
Oracle Database TDE
Establish a Root-of-Trust (ROT) for Oracle databases in the Vectera Plus HSM and provide critical protection to the wallet password. The Vectera Plus provides high-assurance security for the Transparent Data Encryption (TDE) process without disrupting existing features.
Microsoft SQL Server
Take advantage of the vast set of features and administrative functionality the Vectera Plus HSM provides by using it to offload Transparent Data Encryption (TDE) keys for Microsoft SQL Server. Effectively manage the full key lifecycle, securely generate and issue database encryption keys, and configure specific key management functions like key rotation and aging. Read more about data encryption with SQL Server & HSMs.
Versasec vSEC:CMS
vSEC:CMS is a credential lifecycle management system. When implemented through the Vectera Plus, users can create and manage user authentication credentials throughout their organization.
Java KeyTool
Seamlessly secure keys in the Vectera Plus HSM with Java KeyTool for use in a wide range of general-purpose applications.
Venafi Trust Protection Platform (TPP)
For effective key & certificate lifecycle management, integrate the Vectera Plus HSM with Venafi’s Trust Protection Platform. Visit the Venafi.com Marketplace to download the integration guide and get started.
Red Hat Certificate System
Manage user identities and secure private communications with integration for Red Hat Certificate System. Red Hat integration protects traffic from security risks by streamlining PKI.
Check Point Security Gateway
Integrate the Vectera Plus HSM into a Check Point Security environment to add an extra layer of security to the network. Configure the Check Point Security Gateway to effectively store cryptographic key pairs and distribute Certificate Authority (CA) certificates.
VirtuCrypt key management services are backed by HSMs with hardened, FIPS 140-2 Level 3 validated technology. Whether an organization requires complete infrastructure management or simply more functionality for existing Futurex infrastructure, VirtuCrypt offers a variety of service structures designed to meet security requirements.
General-purpose HSMs provide a high level of security for IT infrastructure, protecting it from unauthorized access or tampering. Being general-purpose, they support a wide range of cryptographic functions like symmetric and asymmetric encryption, key management, and digital signing. This makes them versatile and able to be used in a variety of applications. The level of physical and logical security of general-purpose HSMs enables them to meet industry standards for security and compliance, such as FIPS 140-2 and PCI HSM.
Futurex’s VirtuCrypt cloud cryptography platform offers the ability to deploy the Vectera Plus in the cloud. Cloud versions of the Vectera Plus run out of VirtuCrypt data centers located in every geographic region, providing high availability, low latency, and maximum compliance. Users can acquire licenses to enable different Vectera features through the cloud just as they would with an on-premises deployment. Overall, the cloud offers the same functionality as an on-premises general-purpose HSM, but with the immediacy and ease of the cloud.
The use cases fulfilled by HSMs tend to be oriented toward either general-purpose encryption or payment encryption. Both involve running cryptographic operations inside the HSM’s secure boundary, but there are some major differences. Payment HSMs are tailored toward the high-performance environments of the payment industry: payment processors, issuing and acquiring banks, and fintech companies. They carry out specialized use cases centered around encrypting and processing payment data. This type of data requires payment HSMs to meet specific compliance requirements, such as those of PCI. General-purpose HSMs, on the other hand, are geared more toward securing communications, managing or authenticating identities, and managing encryption keys. However, some general-purpose HSMs can manage payment keys, and can use many of the same algorithms of a payment HSM.
The types of client libraries and application programming interfaces (APIs) that an HSM supports depends on the manufacturer. Futurex HSMs are designed to support the widest range of APIs available, enabling easy integration between our HSMs and client applications. Futurex HSMs also feature the Excrypt API, a vendor-neutral interface that simplifies HSM-to-application communication. Futurex’s integration engineers have coded to the standards PKCS#11, Microsoft CNG, KMIP, and others, creating our own versions of these libraries. That way, if a client is using PKCS#11 commands, their application can send those commands to our library, which translates them into commands for our HSMs. This simplifies things for the customer, who doesn’t have to do any additional coding to make this happen.
A general-purpose HSM is a physically and logically secure device from which you can carry out cryptographic tasks. General-purpose HSMs are often used to encrypt data, issue digital certificates, and manage cryptographic keys. The descriptor “general-purpose” refers to the wide array of cryptographic use cases it is designed to handle. They can be integrated into a wide variety of different environments and customized for diverse use cases.