Thales Luna Pcie HSM 7 PB

Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

cpl.thalesgroup.

com

Thales Luna PCIe HSM

Secure sensitive data and critical applications by storing, protecting


and managing cryptographic keys in Thales Luna PCIe HSMs–
high-assurance, tamper-resistant PCIe cards. Provide applications
with dedicated access to a purpose-built, high-performance
cryptographic processor. Quickly embed this cost-efficient solution
directly into servers and security appliances for FIPS 140-2
validated assurance.

Contact us to learn how Luna PCIe HSMs can help you ensure
the integrity and protection of your encryption keys throughout
their life cycle.

What you need to know:


Superior Performance & Usability Highest Security & Compliance
• Fastest HSM on the market with over 20,000 ECC and 10,000 • Keys always remain in FIPS-validated, tamper-evident hardware
RSA operations per second for high-performance use cases • Meet compliance needs for GDPR, eIDAS, HIPAA, PCI-DSS,
• Lower latency for improved efficiency and more
• Dedicated access for applications • Multiple roles for strong separation of duties
• Low profile PCIe card • Multi-person MofN with multi-factor authentication for
Functionality Modules increased security
• Secure audit logging
• Extend native HSM functionality • High-assurance delivery with secure transport mode
• Develop and deploy custom code within the secure confines of
the HSM
PKI
Certificate
Signing &
Validation
BYOK/HYOK IOT

5G TLS/SSL

Post-
Time- Quantum
stamping Crypto Agility

Document
Signing Blockchain
Luna PCIe HSMs

Database Code Signing


Encryption

Transaction eIDAS
Processing

Smart Card Secure


Issuance Manufacturing

Technical specifications
Supported Operating Systems • Qualified Signature or Seal Creation Device (QSCD)
listing for eIDAS compliance
• Windows, Linux
• Singapore NITES Common Criteria Scheme *
API Support
Physical Characteristics
• PKCS#11, Java (JCA/JCE), Microsoft CAPI and CNG,
OpenSSL • Low profile PCIe card
• Dimensions: 69.6mm x 167mm x 18.7mm
Cryptography (2.74” x 6.57” x 0.74”)
• Full Suite B support • Power Consumption: 18W maximum, 14W typical
• Asymmetric: RSA, DSA, Diffie-Hellman, Elliptic Curve • Heat Dissipation: 61.4 BTU/hr maximum,
Cryptography (ECDSA, ECDH, Ed25519, ECIES) with named, 47.8 BTU/hr typical
user-defined and Brainpool curves, KCDSA, • Temperature: operating 0°C–50°C, storage -20°C–60°C
and more • Relative Humidity: 5% to 95% (38°C) non-condensing
• Symmetric: AES, AES-GCM, Triple DES, DES, ARIA, SEED, RCS, Safety & Environmental Compliance
RC4, RC5, CAST, and more
• Hash/Message Digest/HMAC: SHA-1, SHA-2, SHA-3, SM2, • UL, CSA, CE
SM3, SM4 and more • FCC, CE, VCCI, C-TICK, KC MARK
• Key Derivation: SP800-108 Counter Mode • RoHS2, WEEE
• Key Wrapping: SP800-38F • TAA
• Random Number Generation: designed to comply with AIS Host Interface
20/31 to DRG.4 using HW based true noise source alongside
NIST 800-90A compliant CTR-DRBG • PCI-Express CEM 3.0, PCI, PCI Express Base 2.0
• Digital Wallet Encryption: BIP32 Reliability
Security Certifications • Backup/restore
• FIPS 140-2 Level 3—Password and Multi-Factor (PED) • High Availability (HA)
• Common Criteria EAL4+ (AVA_VAN.5 and ALC_FLR.2) • Mean Time Between Failure (MTBF) 997,508 hours
against the eIDAS Protection Profile EN 419 221-5 *in progress
Available models
Choose from two series of Luna PCIe HSMs, each one with 3 different models to fit your requirements.

Luna A Series:
Password Authentication for easy management.

Standard Performance Enterprise Performance Maximum Performance


A700 A750 A790
2 MB Memory 16 MB Memory 32 MB Memory
Performance: Performance: Performance:
RSA-2048: 1,000 tps RSA-2048: 5,000 tps RSA-2048: 10,000 tps
ECC P256: 2,000 tps ECC P256: 10,000 tps ECC P256: 22,000 tps
AES-GCM: 2,000 tps AES-GCM: 10,000 tps AES-GCM: 17,000 tps

Luna S Series:
Multi-factor (PED) Authentication for high assurance use cases.

Standard Performance Enterprise Performance Maximum Performance


S700 S750 S790
2 MB Memory 16 MB Memory 32 MB Memory
Performance: Performance: Performance:
RSA-2048: 1,000 tps RSA-2048: 5,000 tps RSA-2048: 10,000 tps
ECC P256: 2,000 tps ECC P256: 10,000 tps ECC P256: 22,000 tps
AES-GCM: 2,000 tps AES-GCM: 10,000 tps AES-GCM: 17,000 tps

tps = transactions per second

About Thales
The people you rely on to protect your privacy rely on Thales to
protect their data. When it comes to data security, organizations are
faced with an increasing number of decisive moments. Whether the
moment is building an encryption strategy, moving to the cloud, or
meeting compliance mandates, you can rely on Thales to secure
your digital transformation.

Decisive technology for decisive moments.

© Thales - August 2021•RMv32

> cpl.thalesgroup.com <


Contact us – For all office locations and contact information, please visit cpl.thalesgroup.com/contact-us

You might also like