Microsoft is open-sourcing the Azure Integrated HSM, a tamper-resistant hardware security module built into every new Azure server. Engineered to meet FIPS 140-3 Level 3 standards, it brings hardware-enforced cryptographic key protection directly to the compute layer rather than relying solely on centralized services. The firmware, driver, and software stack are now available on GitHub, with an OCP workgroup planned to guide ongoing development. Keys are designed to never leave the hardware boundary, eliminating entire classes of memory-based key exfiltration attacks. The HSM supports TDISP for integration with confidential computing environments and will be available in Azure V7 VMs globally in the coming weeks.

5m read timeFrom azure.microsoft.com
Post cover image
Table of contents
Reinforcing transparency through trust with open-sourced designsA tiered approach to key managementSetting a new standard for server-local key protection at scaleAzure Security

Sort: