FIPS 140-3 Highest Level Physical Trust anchor point

Entrust nShield HSM

Facing the dual challenges of quantum computing and cloud environments, Entrust nShield HSMs build a highly reliable physical root of trust with FIPS 140-3 Level 3 and Common Criteria EAL4+ certification. With NIST post-quantum algorithms and FPGA programmable architecture, the cryptographic system evolves seamlessly; the unique Security World hybrid cloud architecture connects on-premises HSMs with cloud-based nSaaS while preserving key sovereignty and meeting GDPR and MLPS compliance requirements—providing a future-ready cryptographic foundation for finance, 5G, blockchain and other highly sensitive scenarios.

Get a special offer Understand the application scenarios
Security World: nSaaS_Cloud_Active
FIPS 140-3 & CC EAL4+ Double Boundary Verification
Security World Infinite Key Ring Synchronization
NIST Field programmable post-quantum algorithm injection

Entrust nShield HSM Product Portfolio Selection Matrix

Based on the unique Security World elastic architecture, performance has soared by 40% compared to the previous generation, and the native nCore API grants maximum flexibility in all scenarios.

Embedded peripheral type

nShield 5s Encryption Card

A standard card form factor with outstanding physical longevity and ultra-low latency provides dedicated cryptographic offload for core devices.

PCIe interface embedded/Inquiry
  • It has an extremely long MTBF physical life of up to 1.7 million hours
  • Ultra-low hardware-level system latency (≤0.5ms), more immediate response
  • Fully support hardware-level physical access authorization for smart card racks
  • Suitable for: financial transaction terminals, edge computing devices, medical IoT
  • 7*24 Expert Technical Service and Worry-free Guarantee Plan
  • Core module (Empowered by Security World)
  • Firmware-level post-quantum cryptography:On-site upgrade does not require the elimination of hardware
Obtain technical parameters
HSM as a Service (nSaaS)

nShield nSaaS Cloud Service

A lightweight cloud-native subscription model that eliminates costly data center CAPEX while keeping full control of on-premises keys.

Cloud-based billing is based on the number of signatures
  • Strong Cross-Cloud Key Control (BYOK/HYOK)
  • Reduce the high physical maintenance and operation burden of the computer room by more than 50%
  • Elastic expansion option, second-level response to business sudden traffic peak encryption
  • Suitable for: Cloud migration compliance, GDPR data sovereignty, burst traffic encryption
  • 7*24 Expert Technical Service and Worry-free Guarantee Plan
  • Core module (Empowered by Security World)
  • Cloud-based Advanced disaster Recovery:Fully automated multi-data center hot backup
Obtain technical parameters

How does the Security World Cryptographic Foundation work?

Through an original hybrid cloud multi-terminal homogeneous trust architecture, a smooth closed loop from key generation, multiple protection backups to high-performance offloading is achieved.

1. Full life cycle management

The key is securely generated within a tamper-proof physical card that has passed the strict FIPS 140-3 certification. Eliminate the risks of software-level vulnerabilities such as memory interception and process scanning caused by keys remaining in the complex software environment of general-purpose servers from the source.

2. Simple Automatic Backup

With the unique patented architecture of Security World, the keys generated by the physical card are packaged and bound in a strongly encrypted state. The operations team can directly use the existing common file management processes to complete unlimited automated disaster recovery archiving at a more convenient application layer.

3. On-site high-performance decryption

When the application layer generates large concurrent encryption and decryption, 5G core network handshake, blockchain signature or timestamp verification, the dedicated hardware chip directly completes the operation in a closed loop within the physical boundary of the chassis through the nCore interface, releasing the results in milliseconds and significantly reducing network latency.

Entrust nShield


Entrust HSM Core Advantage Matrix

Taking physically isolated hardware as the core anchor point, the traditional zero-trust concept is solidly implemented, achieving agile evolution of enterprise cryptography with an extremely low total cost of ownership (TCO).

View version pricing

Global authoritative dual qualifications for compliance and security

Passed the top-of-the-line FIPS 140-3 Level 3 + CC EAL4+ + eIDAS QSCD certification, providing irrefutable legal evidence for the data sovereignty, GDPR and PCI DSS audits of multinational enterprises.

Key Control Sovereignty Always in Your Hands

Supports homogeneous integration across on-premises, private line and cloud environments. Through self-controlled BYOK/HYOK cryptographic mechanisms, it keeps enterprise key assets private across multi-cloud flows.

Zero-trust Remote high-efficiency operations Management

Implements the "never trust, always verify" principle. It fully supports zero-touch remote configuration without physical data center access, status monitoring and second-level disaster recovery—dramatically reducing travel costs.

Ten Years of worry-free quantum threat defense

The native firmware-level embedded and accelerated advanced network algorithms of post-quantum cryptography (PQC) issued by NIST endow the security foundation with forward-looking anti-cracking and anti-enemy capabilities.

An on-site upgradable encrypted agile architecture with wide ecosystem compatibility

A unique FPGA-based hardware foundation supports hot firmware upgrades for current and future cryptographic algorithms, breaking free from the depreciation cycle of legacy hardware and lowering TCO. It natively integrates with 300+ leading cloud vendors and cryptographic application systems, including AWS KMS, Microsoft Azure and Red Hat OpenStack.

Core application scenarios of hardware security module

From digital assets, enterprise compliance audits to cross-cloud trust management, empower the modern information security foundation with physical-level advanced defense in one stop.

Digital Trust Foundation
High-density Data Security
Identity and Access Security
Payment and Transaction Protection
The integration of Cloud and Emerging technologies
Global authoritative security compliance
Thales_HSM_Core.sys
PKI: ROOT_SIGNATURE
TDE: ENCRYPTING_DATA
IAM: IDENTITY_VERIFIED
PAY: TOKENIZATION
KMS: MULTI_CLOUD_SYNC
FIPS: TAMPER_BLOCKED

Digital Trust Foundation

Covering enterprise PKI root certificate lifecycle management, network-wide SSL/TLS edge encryption, commercial code and document signing, and authoritative third-party timestamping, it provides a physically isolated, highly reliable root of trust—keeping the foundation of all digital credentials and seals pure and preventing root key exposure in software systems.

High-density Data Security

Deeply integrated for transparent database encryption (TDE) of core structured databases and end-to-end encryption of massive unstructured sensitive files and emails. Without sacrificing native throughput, it securely manages tokenization keys to make "data usable but not visible", effectively preventing insider data theft and external attacks.

Identity and Access Security

It issues and controls the full lifecycle of high-concurrency government and enterprise cloud digital identity authentication centers, privileged access management systems (PAM), and smart cards and hardware tokens, and outputs a physically isolated cryptographic computing space. Completely eliminate the vulnerabilities of digital identity forgery, crediting hijacking and unauthorized theft of privileged accounts from the root.

Payment and Financial Transaction Protection

Specifically designed for high-compliance clearing financial transaction processing, replacement of old HSMs in online banking backrooms, secure custody of blockchain digital asset wallets, and Tokenization of financial sensitive data, it provides millisecond-level, non-slowing concurrent ciphertext defense buffering, providing round-the-clock protection for extremely sensitive core fund transaction flows.

The integration of Cloud and Emerging technologies

Fits centralized key lifecycle management (KMS) in modern multi-cloud, multi-tenant heterogeneous environments, breaking free from single-cloud vendor lock-in. It also injects dedicated root-of-trust credentials into IoT devices at the factory and secures high-risk smart contract ledgers on decentralized blockchain nodes.

Global authoritative security compliance audit

The entire hardware architecture and key management lifecycle mechanism have passed the latest standard FIPS 140-3 Level 3 (including the strong encryption backup mechanism), Common Criteria EAL 4+, and the national commercial cryptography standard. Comprehensively assist multinational enterprises and government agencies in seamlessly crossing the most stringent international data privacy compliance thresholds such as PCI DSS, GDPR, and eIDAS.

Frequently Asked Questions

What are the core advantages of Entrust nShield?

Original Security World security architecture, integrating local HSM with cloud-based nSaaS services. Keys are uniformly managed and sovereignty is not lost in a hybrid cloud environment. FPGA field programmable chips support flexible evolution of algorithms.

What product forms are available for selection?

It covers nShield 5c network HSM, 5s PCIe encryption card and nShield as a Service cloud subscription service, which can be flexibly combined according to performance, deployment mode and budget.

Does it support post-quantum cryptography (PQC)?

Support. After nShield is pre-installed with NIST quantum algorithms, it can be pre-tested in the existing system and smoothly migrated to quantum-resistant encryption, preparing for future quantum computing threats.

How to ensure key sovereignty and compliance?

It has passed the dual certifications of FIPS 140-3 Level 3 and CC EAL4+, supports the BYOK/HYOK key sovereignty mode, and the key is fully controlled by the enterprise independently, meeting the compliance requirements of GDPR and Multi-Level Protection Scheme (MLPS)for high-sensitivity scenarios such as finance, 5G, and blockchain.

From Manual Certificate Operations to Automation

From SSL/TLS certificate discovery, enrollment and deployment to continuous monitoring, alerting and automatic renewal, sslTrus helps enterprises build a unified certificate automation platform—reducing the operational burden of growing certificate inventories and shorter validity periods.

  • Overview
  • Certificate Requests
  • Certificate Deployment
  • Discovery Agents
  • Compliance & Alerts
  • Settings
Global Overview
Total Certificates
12,458
Pending
34
Expiring in 30 Days
15
Expired
2
Automated Deployments · 30 Days
Expiration Risk · Next 6 Months
Overall Compliance Rate
96%

Certificates Meet the Latest Security Baseline

Device & Cloud Asset Mix
Alibaba Cloud (40%)
AWS (25%)
Azure (15%)
F5 (10%)
Cisco (10%)