SELANGOR, MALAYSIA – Total SE Solutions Sdn. Bhd., a sovereign digital defense architect and core entity of the Zchwantech Group, announces that its flagship KeyVault Hardware Security Module (kvHSM 2.0) has officially been awarded certification under Malaysia’s Produk Kriptografi Terpercaya Negara (PKTN) evaluation scheme.
Awarded PKTN Level 4 (Secret) classification, kvHSM 2.0 is among the Malaysian cryptographic products certified at this high-assurance security level. PKTN Level 4 (Secret) represents one of the highest certification levels currently achieved by cryptographic products in Malaysia. This certification demonstrates that kvHSM 2.0 has successfully met the PKTN evaluation requirements for deployment in environments requiring high-assurance cryptographic protection, including applications supporting National Critical Information Infrastructure (NCII).
Managed by CyberSecurity Malaysia (CSM) in alignment with the National Cryptography Policy (NCP), the PKTN framework serves as the national evaluation benchmark to validate the safety, integrity, and resilience of cryptographic technologies before deployment in critical national assets.
To achieve Level 4 (Secret) status, kvHSM 2.0 underwent rigorous multi-stage evaluations. The Secret classification indicates that kvHSM 2.0 meets the cryptographic and physical security requirements evaluated under the PKTN framework for high-assurance applications.
Unlike traditional standalone encryption devices that rely on external wiring or software-level protections, kvHSM 2.0 delivers high-assurance hardware key governance directly at the silicon layer:
Features an embedded secure core with dedicated Simple/Differential Power Analysis (SPA/DPA) countermeasures to defeat side-channel attacks and physical probing.
The entire key lifecycle—including key generation, storage, distribution, and destruction—remains strictly inside the physical hardware boundary. Plaintext keys are designed to remain within the secure hardware boundary.
Designed in an embedded PCIe form factor that eliminates external cabling failure points and communicates directly via the host server bus for microsecond latency.
Capable of executing up to 10,000 ECDSA signatures per second and achieving 1.6 GB/s encryption throughput under AES-256 XTS mode.
Protected by a physical data protection shell that automatically triggers key zeroization upon any physical breach or intrusion attempt.
As threats shift toward "Harvest Now, Decrypt Later" strategy—where adversaries capture encrypted data today to decrypt once quantum processing matures—kvHSM 2.0 provides the physical Root of Trust for Post-Quantum Cryptography (PQC).
TSE PQC X86 supports next-generation NIST-standardized algorithms (including ML-KEM and ML-DSA), helping organizations strengthen resilience against future quantum threats.
Classified communications requiring high-assurance, quantum-resistant encryption with PKTN Level 4 (Secret) certified key management.
Protecting high-value transactions, crypto-exchange private keys, and sensitive records against future quantum decryption threats.
Securing site-to-site and client-to-site IPsec VPN tunnels for distributed workforces accessing classified data.
Hardening operational technology (OT) networks and Industrial Control Systems (ICS) against advanced persistent threats and quantum-era adversaries.