Skip to main content

Luna Cloud HSM

Luna Cloud HSM (Hardware Security Module) is a high-security cryptographic solution launched by Thales. It is designed to provide key management and data protection services for cloud and hybrid IT environments, seamlessly extending the robust security capabilities of traditional HSMs to the cloud. It delivers a fully managed, pay-as-you-go hardware security module service that meets strict compliance requirements across major public cloud environments.


Core Features

Full Key Lifecycle Management

  • Supports secure generation, storage, usage, backup, and recovery of keys.

High-Performance Cryptographic Operations

  • Supports multiple algorithms (RSA, ECC, AES, SHA, etc.), and high-performance models (such as the A790) can achieve up to 22,000 ECC operations per second.

Digital Signature and Verification

  • Provides non-repudiable digital signatures for core business data and verifies data integrity.

Cloud-Native and Hybrid Environment Integration

  • Integrates with native cloud platform services (such as AWS KMS and Azure Key Vault) as an External Key Store.
  • Provides standard API interfaces (PKCS#11, JCA/JCE, CNG, OpenSSL), enabling migration and use without modifying existing applications.

Application Scenarios

It primarily serves enterprises running sensitive workloads in public clouds that must meet the highest security standards and strict compliance requirements.

  • Cloud-based digital Certificate Authorities (CA) and Public Key Infrastructure (PKI)
  • Cloud-based code signing and document signing
  • Cloud key management services
  • Compliance enablement during cloud migration

Advantages

High Availability and Elastic Scaling

  1. Fully managed service: Thales is responsible for hardware maintenance, patching, and replacement.
  2. On-demand configuration: Quickly create HSM clusters via web or API, with flexible scaling.
  3. Built-in multi-AZ redundancy to avoid single points of failure.

Compliance and Audit Support

  1. Compliant with international standards including FIPS 140-2/3 Level 3, Common Criteria EAL4+, and eIDAS QSCD.
  2. Provides detailed audit log records.

Flexible Control and Deployment

  1. Supports virtual partitions (multi-tenant isolation) and granular permission management (with separation of roles such as partition officer and auditor).
  2. Supports migration of on-premises licenses to the cloud; customers retain full control over their keys, and neither cloud service providers nor Thales can access them.

Benefits

Reduced Operational Complexity and TCO

  • Eliminates hardware capital expenditure and physical maintenance costs. With pay-as-you-go pricing, it converts fixed costs into variable costs.

Accelerated Cloud Migration and Digital Transformation

  • Provides a cloud-based compliance foundation for high-security scenarios (such as payments, banking services, and digital identity), removing security bottlenecks.
  • Delivers minute-level deployment, improving business agility and the speed of response to innovation.