Plug-in security module for Raspberry Pi
Embedded version of ZYMKEY4 for customer integration
Secure, modular and ready to scale
ZYMKEY4 for RPI, Jetson |
HSM4 encapsulated module |
HSM6 hardware wallet |
SCM secure compute module |
SCN secure compute node |
|
---|---|---|---|---|---|
![]() |
![]() |
![]() |
COMPUTE RESOURCES |
ZYMKEY4 | HSM4 | HSM6 | SCM | SCN |
PiCM4 comprising: Broadcom BCM2711 quad-core Cortex-A72 (ARM v8) 64-bit SoC @ 1.5GHz H.265 (HEVC) (up to 4Kp60 decode), H.264 (up to 1080p60 decode, 1080p30 encode) OpenGL ES 3.1, Vulkan 1.0 Options for 1GB, 2GB, 4GB or 8GB LPDDR4-3200 SDRAM Options for 0GB (“Lite”), 8GB, 16GB or 32GB eMMC Flash memory Option for fully certified radio module: 2.4 GHz, 5.0 GHz IEEE 802.11 b/g/n/ac wireless; Bluetooth 5.0, BLE; On-board electronic switch to select either external or PCB trace antenna |
MOTHERBOARD |
ZYMKEY4 | HSM4 | HSM6 | SCM | SCN |
Tamper resistant enclosure | |||||
Power supply input | +12V, 2.5A, barrel jack +12V SATA PWR optional |
||||
PCIE | |||||
USB | |||||
HDMI | |||||
Tamper Switches | 4 | ||||
HDMI | |||||
HDMI | KEY STORAGE |
ZYMKEY4 | HSM4 | HSM6 | SCM | SCN |
Generate secure key pairs Private key never exposed |
|||||
Tamper resistant secure element key store | |||||
Private/public key pairs | 3 | 3 | 512 | 512 | 512 |
Foreign public keys | 128 | 128 | 128 | ||
Master key recovery | |||||
CRYPTOGRAPHIC PRIMITIVES |
ZYMKEY4 | HSM4 | HSM6 | ||
BIP 32/39/44 HD wallet | |||||
ECC KOBLITZ P-256 (secp256k1) | |||||
ED25519, X25519 | |||||
ECDH (FIPS SP800-56A) | |||||
TRNG (NIST SP800-22) | |||||
ECC NIST P-256 (secp256r1) | |||||
ECDSA (FIPS186-3) | |||||
AES-256 (FIPS 197) | |||||
TAMPER DETECTION SENSORS |
ZYMKEY4 | HSM4 | HSM6 | ||
Perimeter breach detection circuits – standard | 2 | 2 | |||
Perimeter breach detection circuits – enhanced | 2 | ||||
Accelerometer shock & orientation sensor | |||||
Power rail monitor | |||||
Temperature of security module | |||||
SOFTWARE API |
ZYMKEY4 | HSM4 | HSM6 | ||
Python | |||||
C++ | |||||
C | |||||
ELECTRO MECHANICAL INTERFACE |
ZYMKEY4 | HSM4 | HSM6 | ||
Format | MiniHat | Module | Module | ||
Connectors | GPIO: 10pin header Perim: 5pin microusb |
All: 30pin Hirose DF40HC |
All: 30pin Hirose DF40HC |
||
Communication | I2C | I2C | I2C | ||
Production mode lock | Cut Tab |
Software API | Software API | ||
DEVICE MULTI-FACTOR IDENTITY & AUTHENTICATION |
ZYMKEY4 | HSM4 | HSM6 | ||
Host hardware measurement | |||||
Custom authentication factors | |||||
Host code measurement | |||||
DATA ENCRYPTION & SIGNING |
ZYMKEY4 | HSM4 | HSM6 | ||
Encrypt root file system with dm-crypt LUKS key manager hook |
|||||
Encrypt data blobs with “zblock” function | |||||
Encrypt data in flight with OpenSSL integration | |||||
OTHER FEATURES |
ZYMKEY4 | HSM4 | HSM6 | ||
True Random Number Generator | |||||
Real Time Clock | |||||
Backup battery – for RTC and perimeter circuits | Onboard | Offboard | Offboard | ||
Backup battery monitor | |||||
Last Gasp battery removal detection | |||||
OEM Custom features | |||||
EXAMPLE CIPHER SUITES |
ZYMKEY4 | HSM4 | HSM6 | ||
AWS-IOT | TLS_ECDHE_ECDSA_AES256_SHA | |||||
MS-AZURE | TLS_ECDHE_ECDSA_AES_128_GCM_SHA256_P256 | |||||
ACCESSORIES |
ZYMKEY4 | HSM4 | HSM6 | ||
Developer Kits | |||||
Reference Designs | |||||
Custom Integrations | |||||
READY TO GET STARTED? |
ZYMKEY4 | HSM4 | HSM6 | ||
Learn more > | Learn more > | Learn more> | |||
BUY NOW | BUY NOW | BUY NOW | |||
= standard feature = OEM feature |
ZYMKEY4 for RPI, Jetson |
HSM4 encapsulated module |
HSM6 hardware wallet |
|
---|---|---|---|
![]() |
![]() |
![]() |
KEY STORAGE |
ZYMKEY4 | HSM4 | HSM6 |
Generate secure key pairs Private key never exposed |
|||
Tamper resistant secure element key store | |||
Private/public key pairs | 3 | 3 | 512 |
Foreign public keys | 128 | ||
Master key support | |||
CRYPTOGRAPHIC PRIMITIVES |
ZYMKEY4 | HSM4 | HSM6 |
BIP 32/39/44 HD wallet | |||
ECC KOBLITZ P-256 (secp256k1) | |||
ED25519, X25519 | |||
ECDH (FIPS SP800-56A) | |||
TRNG (NIST SP800-22) | |||
ECC NIST P-256 (secp256r1) | |||
ECDSA (FIPS186-3) | |||
AES-256 (FIPS 197) | |||
TAMPER DETECTION SENSORS |
ZYMKEY4 | HSM4 | HSM6 |
Perimeter breach detection circuits – standard | 2 | 2 | |
Perimeter breach detection circuits – enhanced | 2 | ||
Accelerometer shock & orientation sensor | |||
Power rail monitor | |||
Temperature of security module | |||
SOFTWARE API |
ZYMKEY4 | HSM4 | HSM6 |
Python | |||
C++ | |||
C | |||
ELECTRO MECHANICAL INTERFACE |
ZYMKEY4 | HSM4 | HSM6 |
Format | MiniHat | Module | Module |
Connectors | GPIO: 10pin header Perim: 5pin microusb |
All: 30pin Hirose DF40HC |
All: 30pin Hirose DF40HC |
Communication | I2C | I2C | I2C |
Production mode lock | Cut Tab |
Software API | Software API |
DEVICE MULTI-FACTOR IDENTITY & AUTHENTICATION |
ZYMKEY4 | HSM4 | HSM6 |
Host hardware measurement | |||
Custom authentication factors | |||
Host code measurement | |||
DATA ENCRYPTION & SIGNING |
ZYMKEY4 | HSM4 | HSM6 |
Encrypt root file system with dm-crypt LUKS key manager hook |
|||
Encrypt data blobs with “zblock” function | |||
Encrypt data in flight with OpenSSL integration | |||
OTHER FEATURES |
ZYMKEY4 | HSM4 | HSM6 |
True Random Number Generator | |||
Real Time Clock | |||
Backup battery – for RTC and perimeter circuits | Onboard | Offboard | Offboard |
Backup battery monitor | |||
Last Gasp battery removal detection | |||
OEM Custom features | |||
EXAMPLE CIPHER SUITES |
ZYMKEY4 | HSM4 | HSM6 |
AWS-IOT | TLS_ECDHE_ECDSA_AES256_SHA | |||
MS-AZURE | TLS_ECDHE_ECDSA_AES_128_GCM_SHA256_P256 | |||
ACCESSORIES |
ZYMKEY4 | HSM4 | HSM6 |
Developer Kits | |||
Reference Designs | |||
Custom Integrations | |||
READY TO GET STARTED? |
ZYMKEY4 | HSM4 | HSM6 |
Learn more > | Learn more > | Learn more> | |
BUY NOW | BUY NOW | BUY NOW | |
= standard feature = OEM feature |