<img alt="" src="https://secure.weed6tape.com/193471.png" style="display:none;">
Join us at SUDC 2026 – Discover the latest in cybersecurity, cryptography, and digital trust. Secure your place.

Register now

About
About
Learn more about our mission, explore career opportunities, and access our resources. Discover how we’re shaping the future of cybersecurity and how you can be part of it.
Contact us
  • There are no suggestions because the search field is empty.
Home Blog Securosys and DFNS Enable Secure Digital Asset Infrastructure with Hardware-Enforced Key Protection

By combining DFNS, the core banking platform for digital assets, with hardware-backed key protection from Securosys HSMs, organizations can manage digital asset keys and transaction authorization within certified cryptographic environments while maintaining flexibility across on-premises HSM and CloudHSM deployments. The integration builds on the same HSM technology that is already trusted to protect critical financial infrastructures.

Consistent Security Across Deployment Environments

DFNS integrates with both on-premises Securosys Primus HSM environments and Securosys CloudHSM services, allowing organizations to choose the deployment model that best fits their operational and regulatory requirements.


The same integration approach can be used across local, cloud, or hybrid infrastructures while maintaining consistent cryptographic controls and governance processes.

 

Standardized Integration Through PKCS#11

The integration leverages the industry-standard PKCS#11 interface supported by Securosys Primus HSMs, enabling direct communication between the DFNS platform and the HSM.
Within this architecture:

  • Securosys HSMs handle cryptographic operations, key generation, and secure key storage.

  • DFNS provides the core banking platform above the hardware: accounts and wallets, transaction lifecycle management, treasury, and the policy and governance engines that authorize every operation before it reaches the HSM. 


This separation enables organizations to integrate blockchain infrastructures while keeping critical cryptographic operations within secure hardware boundaries.

 

Hardware-Enforced Key Protection and Governance

Through this integration, organizations can leverage several advanced security capabilities available within Securosys Primus HSM and CloudHSM environments.

Secure Key Lifecycle Management

Private keys remain protected within the HSM throughout their lifecycle. Using AES-GCM key wrapping mechanisms, keys can be securely wrapped inside the HSM before external storage or orchestration processes are applied, without exposing raw key material.

True Multi-Tenant Isolation

Securosys Primus HSMs support high partition density, enabling isolated cryptographic environments for different applications, business units, or customers within the same infrastructure.

Validation Gate: A Final Checkpoint Under Customer Control

For HSM-based deployments, DFNS provides Validation Gate: a validation step enforced inside the HSM driver running in the customer’s own environment. Every signing and key export request must receive approval from an endpoint the customer operates before a signature is produced. Configuration lives at the driver level, with no API through which it could be disabled, so the final decision on whether the hardware signs always remains with the organization.

Certified Security and Post-Quantum Readiness

Securosys Primus HSMs are certified to FIPS 140-3 Level 3, and Common Criteria EAL4+ augmented with AVA_VAN.5, the highest level of penetration testing.


The latest Primus CyberVault generation also introduces support for Post-Quantum Cryptography (PQC), including ML-DSA, ML-KEM, and SLH-DSA, enabling hybrid classical and PQC operations.


This allows organizations to begin preparing for the transition to post-quantum cryptography without disrupting existing infrastructures or workflows.

Supporting the Next Generation of Digital Asset Operations

The integration between DFNS and Securosys demonstrates how secure digital asset infrastructures can leverage the same trusted cryptographic foundations already used for critical financial systems.

By combining the DFNS core banking platform with Securosys hardware-enforced key protection, organizations can build blockchain and digital asset services while maintaining strong governance, compliance alignment, and operational flexibility.

As digital asset adoption continues to evolve, institutions increasingly require infrastructures that integrate securely into existing operational and regulatory frameworks. The collaboration between DFNS and Securosys helps address these requirements by extending trusted HSM-backed security controls into modern blockchain environments.

 

About DFNS

DFNS is a core banking platform for digital assets. We equip fintechs, institutions and businesses with secure, programmable infrastructure to build and operate financial services onchain. The platform brings together wallet interfaces, key management, node connectivity, transaction lifecycle processing, treasury capabilities, workflow orchestration, policy enforcement, governance, and compliance into a single system across more than 100 blockchains and third-party integrations.

DFNS is trusted by over 400 financial institutions and fintechs, including Standard Chartered Bank, First Abu Dhabi Bank, IBM, Broadridge, Apex Group, Stripe, Kraken, Circle, and Susquehanna. The company was founded in 2020 and is headquartered in Paris, France with offices in the US, the UAE, Switzerland, Singapore and Hong Kong.

Key Metrics: 400+ clients | Over €100B secured | Over $10B in monthly transactions | 0 security breach
Certifications: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018 (KPMG).

Learn more at dfns.co.