# HSM (Hardware Security Module)

> An HSM (Hardware Security Module) in an automotive microcontroller is a separate, protected core with its own memory that stores cryptographic keys and runs crypto operations the application core cannot reach directly. It backs SecOC message authentication, secure boot, secure diagnostics and key storage. On AURIX it is the HSM core, and EVITA full, medium and light describe three capability levels. A bench test cannot see inside it, but it can test the diagnostic and bus behaviour that depends on it.

An automotive HSM is a protected core inside a microcontroller that stores keys and runs crypto for SecOC, secure boot and diagnostics. What a bench test can see.

Source: https://auto-st.com/glossary/hsm · Updated: 2026-10-07

## What is an HSM?

An HSM is a protected subsystem inside a modern automotive microcontroller: its own CPU core, its own RAM and flash, and a boundary that the main application core cannot cross. It holds cryptographic keys and performs operations with them, so the keys themselves never appear in the memory of the application software. The application asks the HSM to sign, verify, encrypt or derive, and gets back only the result.

On Infineon AURIX, for example, the HSM is a dedicated core alongside the TriCore application cores. The EVITA project defined three reference levels: full (asymmetric crypto for V2X), medium (symmetric crypto for in-vehicle communication) and light (minimal, close to SHE).

## Where is it defined?

There is no single HSM standard. The capability levels come from the EVITA project; the fixed-function cousin SHE comes from a HIS specification. AUTOSAR describes how software reaches these functions through the Crypto Service Manager and Crypto Driver. ISO/SAE 21434 does not mandate an HSM but treats key protection and hardware-based security as part of the engineering decisions in a security concept.

## What it means in practice

The HSM is the root of trust that SecOC, secure boot and secure diagnostics build on. If it is present and configured well, keys are hard to extract and message authentication and boot verification have a trustworthy base. If it is absent, misconfigured or bypassed, those functions rest on software that is easier to attack.

From the outside, a tester never sees the HSM directly. What a tester sees is the behaviour that depends on it: whether SecurityAccess uses a key that appears to be hardware-backed and random, whether diagnostics that should need a secure channel enforce it, whether authenticated messages are actually rejected when their MAC is wrong. Extracting or attacking keys inside the HSM is firmware reverse engineering and chip-level work, the domain of a penetration test, not an automated bench scan.

## How AutoST tests it

AutoST tests the diagnostic and bus-facing functions that an HSM supports, not the module itself. It checks SecurityAccess (`0x27`) for weak or constant seeds and computable keys, checks whether services that should require a secure or authenticated session enforce it, and records what the ECU exposes. It does not read keys, attack the HSM or verify its internal configuration; that is reverse engineering and penetration-test work.

## Common misunderstandings

Having an HSM is not the same as using it well. Keys can still be provisioned badly, functions can be left disabled and a seed/key scheme can be weak even on top of strong hardware. The hardware is a foundation, not a guarantee.

## FAQ

**What is the difference between an HSM and SHE?**

SHE (Secure Hardware Extension) is a smaller, fixed-function security block defined in a HIS specification, with a set number of key slots and AES. An HSM is a fuller programmable security core, often described by the EVITA light, medium and full levels, with more memory, asymmetric crypto and room for custom firmware.

**Can a security test read the keys in an HSM?**

No, and that is the point of the HSM. Keys are meant never to leave it. A bench test works from the outside: it checks whether the functions that rely on the HSM, such as SecurityAccess or secure diagnostics, behave correctly, not what is stored inside.

**Does every ECU have an HSM?**

No. Cost and function decide. Safety and security relevant ECUs and gateways often have one, simple body controllers often do not. The presence of an HSM does not by itself mean the security functions are configured or used correctly.

## Sources

- [ISO/SAE 21434:2021 Road vehicles, Cybersecurity engineering](https://www.iso.org/standard/70918.html)
- [AUTOSAR Classic Platform, Specification of Crypto Service Manager and Crypto Driver](https://www.autosar.org/standards)

## Related

- [SecOC (Secure Onboard Communication)](https://auto-st.com/glossary/secoc)
- [Secure Boot](https://auto-st.com/glossary/secure-boot)
- [ECU (Electronic Control Unit)](https://auto-st.com/glossary/ecu)
- [Does your seed/key actually hold?](https://auto-st.com/security-access-testing)

---
AutoST by Zyberum. Canonical page: https://auto-st.com/glossary/hsm
