Keep the key in hardware
The service sends a signing or decryption operation through the provider path; the HSM retains the private key.
Enterprise PKI · Digital Trust Engineering
SERVICE IDENTITIES & HSM
SYNRION x.ID connects accountable service identities, certificate lifecycle and policy with hardware-protected key paths for Utimaco, Thales Luna, Yubico YubiHSM 2 and Nitrokey NetHSM.
VALUE IN 30 SECONDS
The service sends a signing or decryption operation through the provider path; the HSM retains the private key.
Service, account, certificate, application, key provider and lifecycle state remain explicitly related.
The architecture distinguishes Windows CNG, provider KSP and HSM-specific paths instead of hiding them behind an undefined “HSM” label.
WINDOWS APPLICATION TO HARDWARE
The certificate can be visible to Windows while the private key remains non-exportable in hardware. Understanding the interfaces makes operation, troubleshooting and provider changes controllable.
A Windows service or .NET application requests TLS or mTLS with a selected certificate and identity context.
The Windows security stack resolves the certificate and requests the required cryptographic operation through the configured key provider path.
Windows identifies the private-key object through its Key Storage Provider instead of reading an exportable key file.
The appropriate Utimaco, Thales Luna, YubiHSM 2 or keyONE NetHSM provider path translates the Windows request for its hardware target.
Signing or decryption happens inside the protected hardware boundary and only the result returns to the application path.
The service, certificate, key location, provider and policy remain visible so renewal or migration does not become an undocumented manual handover.
THE ARCHITECTURE AT A GLANCE
TECHNICAL DEPTH
Using the precise terms prevents false assumptions during troubleshooting, migration and security review.
EVIDENCE & BOUNDARIES
Each HSM integration has its own provider, authentication and operating requirements. x.ID makes the shared lifecycle visible without pretending the providers are identical.
Windows CNG and the Utimaco KSP provide a concrete reference path from application request to hardware-protected private-key operation.
Thales Luna provider and partition concepts can participate in the same controlled certificate and service-identity lifecycle.
YubiHSM 2 can protect service and infrastructure keys through its supported provider and integration path.
Windows CNG → keyONE NetHSM CNG KSP → keyONE Agent → Nitrokey NetHSM.
RELATED PRODUCT
SYNRION x.ID combines verified primary identities, authentic hardware and independent policy enforcement into one reliable trust decision.
THE NEXT CONTROLLED STEP
We will map the Windows stack, provider, HSM, CA, service account, lifecycle and recovery path so every responsibility is visible.