Edit

Secure your Azure Payment HSM v2 deployment

Azure Payment HSM v2 is a highly available, single-tenant payment hardware security module (HSM) service that provides payment cryptography for real-time, critical payment transactions by using Utimaco Atalla Payment Module (APM) software. Because the service protects sensitive payment keys and cryptographic operations, strong security controls are essential to maintain the integrity and confidentiality of your payment infrastructure.

This article provides security recommendations to help protect your Azure Payment HSM v2 deployment.

The security recommendations in this article implement Zero Trust principles: "Verify explicitly", "Use least privilege access", and "Assume breach". For comprehensive Zero Trust guidance, see the Zero Trust Guidance Center.

Service-specific security

Azure Payment HSM v2 gives you exclusive administrative control of an isolated, single-tenant HSM cluster while Microsoft manages the underlying infrastructure. Clients authenticate to the management and application interfaces over mutual TLS, so the certificate trust model is the foundation of the service's security.

  • Establish mutual TLS trust with a self-signed root certification authority: Configure a trusted certification authority (CA) certificate for both the management interface and the application interface so that clients authenticate to Azure Payment HSM v2 over mutually authenticated TLS. Use a self-signed root CA whose certificate uses an elliptic curve (EC) public key on the NIST P-256 (prime256v1) curve. Azure Payment HSM v2 doesn't support intermediate CA certificates or other key types. For more information, see Client authentication with mutual TLS.

  • Use separate trust CAs for the management and application interfaces: Provide a distinct management-port trusted issuer and application-port trusted issuer at deployment so that administrative access and payment-application access rely on independent trust anchors. For more information, see Client authentication with mutual TLS.

  • Verify that mutual TLS is active before performing operations: Confirm the connection and lock indicators in the Secure Configuration Assistant (SCA) before you administer the cluster, so that you don't operate over an unauthenticated session. For more information, see How can I tell if mutual TLS is enabled?

Network security

Azure Payment HSM v2 keeps management and payment-application traffic on private IP addresses through Azure Private Link. Restrict all access to your private virtual network and approved hybrid connections.

  • Disable public network access and require private endpoints: Deploy the cluster with public network access disabled and register the AllowPrivateEndpoints feature so that all traffic reaches the HSM through private endpoints instead of the public internet. For more information, see Public network access.

  • Connect through separate management and application private endpoints: Create a private endpoint for the management subresource on port 7005 and the application subresource on port 2200, each in the appropriate client subnet, so that administrative traffic and payment data-plane traffic stay isolated on private IP addresses. For more information, see Private endpoint.

  • Restrict subnet traffic with network security group (NSG) rules: Add outbound NSG rules that permit traffic only to the private endpoint IP addresses on ports 7005 and 2200, and apply each rule to the client subnet that needs that interface. For more information, see NSG rules.

  • Resolve HSM hostnames with a private DNS zone: Configure a private DNS zone for privatelink.phsm.azure.net and link it to the virtual networks that contain your admin and application VMs, so that HSM hostnames resolve to private endpoint addresses rather than public endpoints. For more information, see Private DNS.

  • Secure on-premises and workstation connectivity with a VPN or SSH tunnel: Reach the management and application interfaces from outside the virtual network through a site-to-site VPN, a point-to-site VPN, or SSH port forwarding through a jump box, rather than exposing the HSM to the public internet. For more information, see On-premises connectivity.

  • Isolate HSM resources in a dedicated resource group: Place the Payment HSM v2 cluster in a separate resource group from the client virtual network and VMs to simplify access control and lifecycle management. For more information, see VM placement.

Identity and access management

Administrative access to the HSM relies on SCA credentials and smart cards, while Azure role-based access control governs access to the Azure resource itself. Protect both control planes.

  • Authenticate administration with the SCA and smart cards: Administer the cluster by using the Utimaco Secure Configuration Assistant (SCA) with administrator and backup smart cards and the C3 Key Loading Device (KLD), so that HSM management requires physical credential possession. For more information, see HSM administrator credentials.

  • Treat smart cards and the key loading device as administrative credentials: Safeguard the administrator and backup smart cards and the C3 KLD according to your organization's credential-management policies, because administrators use these credentials for HSM authentication, administration, backup, and key-loading operations. For more information, see Glossary of terms.

  • Apply least privilege through security associations and use policies: Initialize the HSM with security associations and define use policies in the SCA so that administrators and applications receive only the permissions their tasks require. For more information, see Perform Azure Payment HSM v2 operations.

  • Restrict Azure permissions to manage the HSM resource: Grant only trusted identities the Azure permissions needed to create and manage the paymentHsmClusters resource, private endpoints, private DNS zones, and subscription feature registration, and follow least privilege for those role assignments. For more information, see Azure access control.

Data protection

Payment keys are generated, stored, and used inside the HSM boundary. Manage the key hierarchy and key exchange so that key material never leaves the HSM in the clear.

  • Manage payment keys under the Master File Key: Load and manage the Master File Key (MFK) through the SCA and smart cards so that operational payment keys remain protected under the HSM's root key hierarchy. For more information, see Perform Azure Payment HSM v2 operations.

  • Exchange keys securely with TR-31 key blocks: Import and export working keys by using TR-31 key blocks and Atalla Key Blocks (AKBs) so that keys are cryptographically protected during transport rather than exchanged in clear form. For more information, see Key operations.

  • Distribute key components securely on smart cards: Send and manage key components through smart cards when distributing keys, so that key component handling stays within the supported SCA and smart-card workflow. For more information, see Perform Azure Payment HSM v2 operations.

  • Verify loaded Master File Keys before processing transactions: Check the loaded MFK and AES Master Key check digits in the SCA HSM Information page to confirm the correct keys are present before you run payment workloads. For more information, see How can I verify which Master File Keys are loaded?

Logging and monitoring

Azure Payment HSM v2 emits signed operation audit logs through Azure Monitor diagnostic settings. Enable logging and retain it for investigation and compliance.

  • Enable diagnostic settings for HSM operation logs: Create a diagnostic setting that sends the HsmOperations log category to a Log Analytics workspace and a storage account, so that HSM access and operations are recorded for accountability and traceability. For more information, see Enable diagnostic settings.

  • Query operation events for investigation: Use the CloudHsmHardwareOperationAuditLogs table in Azure Monitor Logs to review HSM operation events, detect unauthorized access, and investigate incidents. For more information, see Query operation event logs.

  • Retain audit logs in a storage account for compliance: Archive exported logs to a storage account so that operation records are preserved for regulatory audit and backup beyond the interactive query window. For more information, see Create a storage account to store HSM logs.

  • Monitor daily self-test entries for tamper evidence: Review the automated Daily self-tests passed entries that the APM generates to confirm HSM integrity, tamper protections, and cryptographic function checks remain in place. For more information, see Daily self-test log entries.

Compliance and governance

Azure Payment HSM v2 runs on security infrastructure certified to the standards payment workloads require, and its single-tenant model lets you incorporate it into your own validated PCI solution.

  • Deploy Azure Payment HSM v2 as a validated PCI component: Use the single-tenant, isolated HSM cluster as a validated component within your own PCI solution to simplify ongoing audit and compliance for payment workloads. For more information, see Enhanced security and compliance.

  • Verify the service certifications for your audit scope: Confirm that Azure Payment HSM v2 uses infrastructure certified to FIPS 140-3 Level 3, PCI DSS, PCI 3DS, and PCI PIN when documenting the certification landscape for your payment infrastructure. For more information, see Enhanced security and compliance.

Backup and recovery

Because Azure Payment HSM v2 is single-tenant and under your administrative control, you're responsible for maintaining sufficient capacity and key backups to meet your resilience targets.

  • Maintain enough active HSM capacity for resilience targets: Provision and keep enough active HSM capacity across the cluster to meet your backup, disaster recovery, and resilience requirements, because Microsoft doesn't manage this capacity on your behalf. For more information, see Administrative and single-tenant control.

  • Back up keys by using the SCA and backup smart cards: Regularly back up your Master File Key and payment keys through the SCA and backup smart cards so that you can recover cryptographic material after a failure. For more information, see Perform Azure Payment HSM v2 operations.