Physical-grade key protection and dedicated hardware HSM

Thales Luna HSM

In an era of data explosion and strict compliance, the confidentiality and integrity of digital information face increasingly serious challenges. Thales HSMs provide physical-level key protection and high-performance cryptographic operations, building a highly reliable security foundation for your core digital processes and keeping your keys safe. Whether your keys live on-premises or in hybrid environments, Thales' FIPS and Common Criteria certified solutions fully meet your requirements for root of trust, cryptographic agility and compliance.

Get a special offer Understand the application scenarios
HSM Node: Partition_01_Secure
FIPS 140-3 Physical Boundary Verification
Anti-side-channel Defense and Physical anti-disassembly verification
Hardware-level master key active zeroing mechanism

Thales HSM Product Portfolio Selection Matrix

The entire series has passed the authoritative FIPS certification and offers multiple deployment forms such as network, embedded, and portable. All functions are included and there are no additional charges.

Server embedded card

Luna PCIe encryption card

It adopts the PCIe interface form and is directly embedded in servers or dedicated devices, providing exclusive high-performance encryption processing capabilities for applications.

Embedded hardware expansion/inquiry
  • All digital signature and verification operations are completed in a closed loop within the card.
  • High-security hardware architecture ensures the integrity of keys throughout their entire life cycle.
  • Significantly enhance the local throughput of the system and maintain the highest security standards
  • Compact footprint that fits easily into server racks
  • 7*24 Expert technical service and architecture design support
  • Ecological Rights (Full Function Included)
  • Free inclusion of BYOK module
  • Free inclusion of advanced application interface integration license
Obtain technical specifications
Portable offline type

Luna USB HSM

The industry-leading portable key management device, with its compact design and offline storage, is particularly suitable for scenarios where core keys need to be protected in an isolated environment.

Portable physical hardware/Inquiry
  • Designed specifically for PKI root key protection and cold storage
  • All key materials are completely independently maintained within the hardware.
  • Supports plug-and-play functionality, facilitating Air-Gapped environments
  • Physical devices are stored offline and disconnected from the network to prevent remote network penetration.
  • 7*24 Expert technical service and architecture design support
  • Ecological Rights (Full Function Included)
  • It includes the standard root key issuance console software
Obtain technical specifications

How does an encrypted root of trust work?

Through hardware-level barriers, the key lifecycle is completely isolated from external systems to achieve high-performance ciphertext high-speed offloading communication.

1. Hardware isolation generation

By using a true random number generator (TRNG), the core master key is securely generated within the FIPS-certified physical hardware boundary, eliminating the risks of memory scanning and leakage in the software operating system environment.

2. Centralized state storage

The key is stored in a tamper-proof white porcelain shell lattice in a strongly encrypted state. Through partition isolation and Elastic Storage (SKS) technology, the policy consistency of distributed keys is uniformly monitored and automatically managed.

3. Dedicated hardware unloading operation

When the business system issues requests for encryption and decryption, digital signature or signature verification, the business message enters the HSM. The dedicated hardware chip takes over and offloads all encryption operations, processes and sends back the results in milliseconds, reducing the latency of the source station.

Hardware trust root


Thales HSM Core Advantage Matrix

Abandon the insecure pure software layer cryptographic solution and build a physical anti-breakable underlying foundation for core digital assets in financial payments, government and enterprise sectors, etc.

View version pricing

Hardware-level key full lifecycle management

The entire process of securely generating, storing, rotating and destroying encryption keys runs in FIPS 140-3 certified hardware, isolating software threats such as malicious process scanning.

Physical anti-disassembly active protection

Tamper-proof hardware housing and anti-physical side-channel attack design. Through CC EAL 4+ authentication, when fault injection or illegal disassembly is detected, the master key actively zeros within seconds.

High-performance encryption and tenant isolation

Dedicated hardware offloads cryptographic processing with industry-leading RSA/ECC performance. With scalable key storage (SKS), a single physical HSM can be flexibly partitioned into 100 independent virtual HSMs.

Forward-looking quantum-ready agility

Comprehensively and proactively support the upgrade of post-quantum cryptography (PQC) and traditional SM cryptographyand ECC algorithms. Algorithms can be flexibly replaced without the need to change hardware to deal with future computing threats.

Flexible Deployment Across Environments with 300+ Ecosystem Partners

Natively supports on-premises (Network/PCIe/USB), public cloud and heterogeneous hybrid cloud deployment, with keys migrating freely across environments to effectively avoid cloud vendor lock-in. Deep integrations with 300+ ecosystems including Microsoft PKI, IBM Cloud and Adobe Sign greatly reduce integration and development costs.

Core application scenarios of hardware security module

From digital assets, enterprise compliance audits to cross-cloud trust management, empower the modern information security foundation with physical-level advanced defense in one stop.

Digital Trust Foundation
High-density Data Security
Identity and Access Security
Payment and Transaction Protection
The integration of Cloud and Emerging technologies
Global authoritative security compliance
Thales_HSM_Core.sys
PKI: ROOT_SIGNATURE
TDE: ENCRYPTING_DATA
IAM: IDENTITY_VERIFIED
PAY: TOKENIZATION
KMS: MULTI_CLOUD_SYNC
FIPS: TAMPER_BLOCKED

Digital Trust Foundation

Covering enterprise PKI root certificate lifecycle management, network-wide SSL/TLS edge encryption, commercial code and document signing, and authoritative third-party timestamping, it provides a physically isolated, highly reliable root of trust—keeping the foundation of all digital credentials and seals pure and preventing root key exposure in software systems.

High-density Data Security

Deeply integrated for transparent database encryption (TDE) of core structured databases and end-to-end encryption of massive unstructured sensitive files and emails. Without sacrificing native throughput, it securely manages tokenization keys to make "data usable but not visible", effectively preventing insider data theft and external attacks.

Identity and Access Security

It issues and controls the full lifecycle of high-concurrency government and enterprise cloud digital identity authentication centers, privileged access management systems (PAM), and smart cards and hardware tokens, and outputs a physically isolated cryptographic computing space. Completely eliminate the vulnerabilities of digital identity forgery, crediting hijacking and unauthorized theft of privileged accounts from the root.

Payment and Financial Transaction Protection

Specifically designed for high-compliance clearing financial transaction processing, replacement of old HSMs in online banking backrooms, secure custody of blockchain digital asset wallets, and Tokenization of financial sensitive data, it provides millisecond-level, non-slowing concurrent ciphertext defense buffering, providing round-the-clock protection for extremely sensitive core fund transaction flows.

The integration of Cloud and Emerging technologies

Fits centralized key lifecycle management (KMS) in modern multi-cloud, multi-tenant heterogeneous environments, breaking free from single-cloud vendor lock-in. It also injects dedicated root-of-trust credentials into IoT devices at the factory and secures high-risk smart contract ledgers on decentralized blockchain nodes.

Global authoritative security compliance audit

The entire hardware architecture and key management lifecycle mechanism have passed the latest standard FIPS 140-3 Level 3 (including the strong encryption backup mechanism), Common Criteria EAL 4+, and the national commercial cryptography standard. Comprehensively assist multinational enterprises and government agencies in seamlessly crossing the most stringent international data privacy compliance thresholds such as PCI DSS, GDPR, and eIDAS.

Frequently Asked Questions

What is the essential difference between HSM and software encryption?

HSM locks all key generation, storage and operation in tamper-proof hardware. The plaintext of the key never leaves the device. Even if the server is invaded, the key cannot be exported. This is a physical-level protection that pure software solutions cannot provide.

What product forms does Thales HSM have?

It covers three forms: Luna network HSM (rack-mounted), PCIe encryption card (embedded in server), and USB portable HSM. A single machine supports 100 virtual partitions, with up to 32-node cluster high availability, and is suitable for all scenarios from R&D testing to financial production.

What compliance certification requirements must be met?

It has passed the dual certifications of FIPS 140-3 Level 3 and CC EAL4+, meeting the hard requirements for key management of PCI DSS, GDPR and Multi-Level Protection Scheme (MLPS), and is the compliance baseline for financial payment and government affairs systems.

How to deal with the threats of quantum computing in the future?

Thales HSM is embedded with the agile upgrade capability of post-quantum cryptography (PQC), supporting a smooth migration to NIST-standardized quantum-resistant algorithms and protecting current crypto assets from the threat of "store first, decrypt later".

Can it be quickly integrated with the existing business systems?

Deeply integrated with over 300 mainstream ecosystems (databases, PKI, cloud platforms, blockchain, etc.), it provides standard PKCS#11, JCE, CNG interfaces and BYOK cloud integration capabilities. Mainstream applications are basically ready to use out of the box.

From Manual Certificate Operations to Automation

From SSL/TLS certificate discovery, enrollment and deployment to continuous monitoring, alerting and automatic renewal, sslTrus helps enterprises build a unified certificate automation platform—reducing the operational burden of growing certificate inventories and shorter validity periods.

  • Overview
  • Certificate Requests
  • Certificate Deployment
  • Discovery Agents
  • Compliance & Alerts
  • Settings
Global Overview
Total Certificates
12,458
Pending
34
Expiring in 30 Days
15
Expired
2
Automated Deployments · 30 Days
Expiration Risk · Next 6 Months
Overall Compliance Rate
96%

Certificates Meet the Latest Security Baseline

Device & Cloud Asset Mix
Alibaba Cloud (40%)
AWS (25%)
Azure (15%)
F5 (10%)
Cisco (10%)