On highly sensitive KNX Secure installations (strategic sites, defence buildings), the keyring keys can be stored in a Hardware Security Module (HSM) attached to ETS, guaranteeing that the keys never leave the secure hardware even during download operations.
True
An HSM is a certified hardware device (typically FIPS 140-2 level 3 or above) that stores cryptographic keys with several protections: true random key generation (TRNG), crypto operations executed in protected memory (the key is never in the clear in ETS RAM), tamper-evident audit logging and physical tamper detection. A USB HSM costs roughly 500-5000 euros and is reserved for high-security sites: banking, defence and critical infrastructure. It is standard practice in those sectors, exotic everywhere else.
The vast majority of KNX Secure installs do NOT need an HSM — the encrypted ETS keyring suffices in 99 % of cases. If you do deploy one, plan the PIN/recovery procedure before deployment: a lost HSM credential under FIPS 140-2 level 3 is genuinely unrecoverable, and you will lose access to the keyring permanently.
Keep going with the full KNX Advanced bank
Keep going with the full KNX Advanced bank: unlimited timed mock exams, detailed answers, history. From €19 (one-time payment).
See pricing — from €19 →See the 9 other KNX Advanced practice questions
Related questions
- What is the principle of Constant Light Control regulation in KNX?5. Lighting Control · Constant Light Control
- Tunable White control (variable colour temperature, e.g. 2700 K warm to 6500 K cool) over KNX typically uses two distinct DPTs: one for the overall intensity (DPT 5.001, %) and one for the colour temperature (DPT 7.600, K).5. Lighting Control · Tunable White
- A KNX presence detector configured with a 15-minute timeout keeps the lighting on for that duration after the last detection, then automatically switches it off.5. Lighting Control · Präsenzerkennung
- The emergency lighting of a building CANNOT be driven by KNX alone: it must comply with dedicated standards (NF EN 1838, EN 50172) that require a self-contained system with a backup battery.5. Lighting Control · Sicherheitsbeleuchtung
- A standard KNX end-of-works deliverable typically includes the .knxproj project file, printed documentation (topology, Group Address table, electrical schematics), functional-test reports, user training, and a separate .knxkeys keyring file when KNX Secure is used.13. Project best practices · Projektdokumentation