Universal secure data exchange for cryptographic modules

An anonymous secure messaging method and system for securely exchanging information between a host computer system (105) and a functionally connected cryptographic module (75). The invention comprises a Host Security Manager application (110) in processing communications with a security executive program installed inside the cryptographic module (75). An SSL-like communications pathway is established between the host computer system (105) and the cryptographic module (75). The initial session keys are generated by the host and securely exchanged using a PKI key pair (210, 210') associated with the cryptographic module (75). The secure communications pathway allows presentation of critical security parameter (CSP) without clear text disclosure of the CSP and further allows use of the generated session keys as temporary substitutes of the CSP for the session in which the session keys were created.