Skip to main content

Luna PCIe HSM

Thales Luna PCIe Hardware Security Module (HSM) can be directly embedded into devices or application servers, providing an easy-to-integrate and cost-effective solution for cryptographic acceleration and security. The highly secure hardware design of Thales Luna PCIe HSM ensures that cryptographic keys are protected for integrity throughout their entire lifecycle, and all digital signature and verification operations are performed inside the HSM to improve performance and maintain security.


Core Capabilities

Full Key Lifecycle Management:

  • Provides secure generation, secure storage, secure use, backup and recovery of keys, ensuring keys are fully protected at the hardware level.

High-Performance Cryptographic Operations:

  • Supports multiple cryptographic algorithms (symmetric algorithms, asymmetric algorithms, hash algorithms, etc.), with low data transmission latency, suitable for large-volume encryption tasks.

Digital Signature and Verification:

  • Creates non-repudiable digital signatures for core business data and verifies received digital signatures to ensure data integrity and authenticity.

True Random Number Generation:

  • Built-in true random number generator based on physical phenomena, providing a high-quality source of randomness for critical security functions such as key generation, initialization vectors (IV), and challenge-response mechanisms.

Application Scenarios

Thales PCIe HSM serves as the most trusted security cornerstone in the entire IT architecture, providing underlying cryptographic services for various sensitive applications:

  • Cloud-based digital Certificate Authority (CA) and Public Key Infrastructure (PKI)
  • SSL/TLS termination acceleration and key protection
  • Blockchain and digital assets
  • Code and document signing
  • Database encryption (TDE)
  • Smart card issuance and management
  • Email encryption
  • DNSSEC
  • Identity and permission management
  • Key management
  • Cryptographic acceleration
  • Timestamping
  • Secure manufacturing
  • Internet of Things (IoT)

Advantages

Highest Level of Security and Root of Trust

  1. FIPS 140-2 Level 3 certified, with physical tamper resistance and reliable random number generation capabilities.
  2. Keys always remain in FIPS-validated tamper-resistant hardware.
  3. Supports multi-factor authentication and access control to prevent misuse or accidental operations.

Outstanding Performance and Low Latency in PCIe Form Factor

  1. One of the fastest high-speed cryptographic modules (HSM) on the market.
  2. The PCIe interface provides high data transmission bandwidth, achieving extremely high throughput.
  3. Plugs directly into the server motherboard and communicates with the main CPU via the high-speed PCIe bus, ensuring ultra-low latency.

Customizable Function Modules

  1. Supports flexible expansion of native HSM capabilities.
  2. Allows development and deployment of custom code within the HSM's secure environment.

Strong Compliance and Audit Support

  1. Meets global high-standard compliance requirements, conforming to international standards such as FIPS 140-2/3 Level 3, Common Criteria EAL4+, and eIDAS QSCD.
  2. Provides detailed security audit logging.

Mature Ecosystem and Integration Convenience

  1. Supports both Windows and Linux operating systems.
  2. Provides API interfaces including PKCS#11, Java JCA/JCE, OpenSSL, and more.
  3. Offers extensive software support.

Benefits

  • Balanced Security and High Performance: No trade-off required between security and performance; low latency improves efficiency, supporting faster business processing, higher throughput, and better user experience.
  • Reduced Total Cost of Ownership: Simplifies deployment and maintenance, provides high reliability, system stability, and a simple architecture, easing operational burdens.
  • Separation of Duties for Multiple Roles: Supports multiple roles to enforce strong separation of duties, enhancing internal controls.
  • Core Digital Asset Protection: As the ultimate solution for protecting cryptographic keys, it serves as the cornerstone for passing audits and establishing secure trust.