<img alt="" src="https://secure.weed6tape.com/193471.png" style="display:none;">
Join us at SUDC 2026 – Discover the latest in cybersecurity, cryptography, and digital trust. Secure your place.

Register now

About
About
Learn more about our mission, explore career opportunities, and access our resources. Discover how we’re shaping the future of cybersecurity and how you can be part of it.
Contact us
  • There are no suggestions because the search field is empty.

Why do modern applications need secure transaction orchestration?

Modern financial and digital asset applications require more than basic key usage. They increasingly depend on fine-grained policies and complex workflows.

Implementing these workflows directly inside each application is complex. They require state management, authorization collection, and reliable coordination, while ensuring that all security-critical checks remain inside the HSM.

How does Transaction Security Broker (TSB) work?

The Securosys Transaction Security Broker (TSB) simplifies the implementation of advanced authorization and key-usage workflows and how applications interact with the Primus HSM. TSB is a Java-based service that communicates with the HSM over JCE while exposing a language-agnostic REST API that applications can use without installing client-side libraries. All cryptographic operations and security-critical checks remain inside the HSM, while TSB orchestrates request handling, approval logic, and workflow state.

Approvals can be provided using signing keys held on crypto tokens, in software, or through the Securosys Authorization App. The Securosys Authorization App provides approvers with a simple interface to receive notifications, review requests, and submit approvals. TSB manages communication with the app and collects approvals before forwarding authorized operations to the HSM.

TSB supports two usage modes. In its basic mode, it acts as a REST translation layer, enabling applications to perform signing, decryption, and key management operations through REST calls. In its workflow mode, TSB manages Smart Key Attribute (SKA) approval processes by collecting authorizations, coordinating multi-step workflows, and forwarding completed authorization data to the HSM. This separation ensures that all the approvals required by the SKA policy have been gathered together by TSB outside the HSM, while only the HSM itself enforces all policies

 

Why do organizations choose Transaction Security Broker (TSB)?

API-circle-b&w
Simple REST API Integration
TSB provides a language-agnostic REST API to access Primus HSM functionality without client-side libraries. This simplifies integration with modern applications and services.
key-circle-people-b&w
Streamlined SKA Workflow Orchestration
TSB manages approval collection and workflow state for SKA-enabled keys, reducing complexity for applications while ensuring that all authorization checks remain inside the HSM.
locket-circle-blocks-b&w
Scalable Deployment Options
TSB can run as multiple container instances connected to the same HSM partition, enabling horizontal scaling and integration with high-availability HSM clusters.
vault-b&w
Consistent Hardware-Based Security
All cryptographic operations and SKA policy validations occur inside the secure physical boundary of the Primus HSM, ensuring key protection with tamper-resistant hardware at every stage.
blocks-lock-b&w
Flexible Deployment Inside or Outside the HSM
TSB can be deployed on external platforms or within the HSM as VaultContainers, offering architectural flexibility based on operational and regulatory needs.

Why TSB vs. Multi-signature?

  • Works with all supported crypto assets — independent of blockchain signature formats
  • Lower fees and better privacy due to single-signature on-chain addresses
  • Decouples key ownership from key usage for operational and regulatory flexibility
  • Supports advanced policy models including time-restrictions

Why TSB vs. Multi-Party Computation (MPC)?

  • Supports time-based workflows
  • Key material stays hardware-protected
  • Redundant deployment without increasing key-exposure risk
  • Simpler lifecycle management and operational model

 

Approval Process with SKA — How It Works

The approval process applies when using Smart Key Attributes with TSB.

To support SKA workflows, the Securosys Authorization App enables approvers to receive notifications, review pending tasks, and provide approvals directly from their devices. The app integrates with TSB, which orchestrates the workflow while the HSM performs all policy enforcement.

Step 1
Request Approval
A business application requests a key operation (e.g., signing) via TSB.
Step 2
Policy Retrieval
The HSM returns the SKA policy associated with the key, with a signed timestamp.
Step 3
Broadcast Request
The application fetches the approval request from TSB and broadcasts it to approvers.
Step 4
Collect Approvals
TSB collects approvals until the key’s SKA rules are met.
Step 5
Authorization Validation
TSB forwards the payload and collected approvals to the HSM.The HSM validates authorization data according to SKA attributes.
Step 6
Final Signature
If all conditions are met, the HSM signs the payload and returns the signature to TSB.

What is Transaction Security Broker (TSB) used for?

colourful-background-patterns-13 Multi-Quorum Transaction Approval Enable m-of-n or multi-layer approval flows for high-value financial transactions, ensuring controlled and verifiable authorization.
colourful-background-patterns-11 Time-Locked Transaction Security Enforce time-based policies to delay or restrict key operations, reducing operational risk.
colourful-background-patterns-14 Hybrid Approval Systems Combine device-based approvals, user roles, or multi-device workflows with HSM-based key protection.
colourful-background-patterns-8 Policy-Driven Key Usage Control Define complex, granular SKA policies for key usage and enforce them through TSB for digital assets, financial operations, and regulated environments.

FAQ

What is Transaction Security Broker (TSB)?
Transaction Security Broker (TSB) is a middleware service that provides a REST API for interacting with Securosys Primus HSMs. It simplifies application integration while orchestrating approval workflows, authorization collection, and key management without exposing cryptographic keys. All security-critical operations remain inside the HSM. 
How does Transaction Security Broker (TSB) work?
TSB sits between business applications and the Primus HSM. Applications communicate with TSB through a REST API, while TSB securely communicates with the HSM over JCE. It manages workflow state, collects approvals, and forwards authorized requests to the HSM, where all cryptographic operations and policy enforcement take place.
Why use Transaction Security Broker instead of integrating directly with an HSM?
Direct HSM integration often requires proprietary APIs and custom workflow management. TSB provides a language-agnostic REST API and built-in workflow orchestration, reducing development effort while keeping all cryptographic operations protected by the HSM. 
Does TSB support multi-authorization workflows?
Yes. TSB orchestrates Smart Key Attribute (SKA) workflows by collecting approvals from multiple users or systems before submitting the authorized request to the HSM. The HSM then validates the policy and performs the requested cryptographic operation. 
Does TSB perform cryptographic operations?
No. TSB manages communication, workflow orchestration, and approval collection, but all cryptographic operations—including signing, encryption, decryption, and policy validation—are executed inside the Securosys Primus HSM.
Which applications can integrate with TSB?
Any application capable of communicating over HTTPS can integrate with TSB through its REST API. This allows organizations to connect web applications, cloud services, enterprise platforms, blockchain applications, and financial systems without installing proprietary HSM client libraries.
Can TSB be deployed in cloud and on-premises environments?
Yes. TSB is delivered as a containerized application that can run on Docker or Kubernetes, or directly inside a Primus HSM using VaultContainers. This provides flexibility for on-premises, hybrid, and cloud deployments.
How does TSB improve security?

TSB centralizes approval workflows and key usage orchestration while ensuring that private keys never leave the HSM. Security policies, authorization rules, and cryptographic operations are enforced within the HSM, reducing the attack surface and supporting regulatory compliance.

How is TSB different from Multi-signature or MPC solutions?
Unlike blockchain-specific multi-signature approaches or Multi-Party Computation (MPC), TSB provides policy-based authorization that is independent of blockchain signature formats. It supports quorum approvals, time-based restrictions, hardware-backed key protection, and flexible deployment models while keeping cryptographic keys inside certified HSMs.