• Ask A Question

    Ask us a question







    Please enter correct format as below:
    If AMERICA: yyy-yyy-yyyy ext123
    If Other: +yy-yyy-yyyyy ext123








    Captcha Code

  • Newsletter

Thales nShield Solo

Get certified

Thales training courses provides customers, partners, and developers with an overview of the nCipher product line key management and acceleration server based hardware.
Learn More »

 

Benefits

  • Cost-effective dedicated HSM for servers
  • Protects cryptographic keys and data of sensitive applications in secure hardware
  • Enables easy automated key backup with secure recovery
  • Enhances security and cryptographic acceleration for OEM appliances
  • Reduces cost through remote management
  • Lowers TCO with Security World management
  • Avoids bottlenecks through premium performance
  • Readily integrates with third-party applications
  • Protects data in hostile environments with CodeSafe technology
  • Delivers FIPS and Common Criteria compliance
 

Thales nShield Solo is a family of embedded, general-purpose HSMs for servers and appliances that safeguard encryption and digital signing keys and that can optionally run custom applications on the module to protect data in use.

Previously known simply as "nShield", nShield Solo protects encryption and signing keys on servers in a highly secure, tamper-resistant hardware module. It is compatible with platforms offering PCI, PCI-X and PCI Express interfaces.

Built to meet demands for high cryptographic performance, the nShield Solo family frees computing resources for your applications. It is commonly used as a cost-effective solution for standalone or clustered servers, and appliances that don't warrant the scalability of a network-attached HSM, such as nShield Connect.

The security boundary of the nShield Solo family is validated for FIPS 140-2 Level 3 and Common Criteria EAL4+. All models are also available at a lower price as a FIPS 140-2 Level 2 variant.

Thales Application Security Video

Click Here to View Webinar

See features >>

 

Hardware security for applications
nShield Solo enables enterprises to add hardware protection to critical applications such as public key infrastructures (PKIs), databases, web and application servers. Using standard cryptographic interfaces, nShield Solo nShield Assortmentintegrates readily with Microsoft Certificate Services (PKI), Entrust Authority Security Manager, RSA Certificate Manager, Oracle Database, Microsoft SQL Server, and many other applications. nShield Solo modules are available as tamper-resistant PCI and PCI Express expansion cards; the PCI variant is also compatible with PCI-X interfaces.

Cost-effective for stand-alone servers
When protecting cryptographic keys on one or only a few stand-alone servers, nShield Solo is the most cost-effective solution. However, organizations requiring scalability should consider nShield Connect, a network-attached HSM that can manage keys for up to 100 clients. nShield Solo and nShield Connect are fully compatible with each other and can therefore be managed as part of the same Security World infrastructure.

Security and acceleration for OEM appliances
Hardware vendors can benefit from enhanced security for their appliances by using nShield Solo, which delivers FIPS and Common Criteria compliance for their key management. Due to nShield Solo's hardware acceleration, they also take advantage of performance increases for cryptographic operations, such as SSL sessions or RSA signatures.

Enhanced security for integrated systems
Some integrated systems leverage hardware security modules for more than one security task. Here are some examples:  

  • Government agencies use Thales HSMs to protect its public key infrastructure (PKI) with hardware security. Another agency uses nShield Solo to digitally sign electronic documents; it then uses the Time Stamping Option Pack on the same HSM to apply a time stamp to the document to ensure that the document retains its validity after the signing certificate expires. Thales HSMs also safeguards the keys in issuing systems to protect digital identities for passports and national ID cards. (Read government case study about Certicamara in Columbia, the Finnish Passport project, the French Ministry of Defense, and the Irish Department of Defense.)
  • Banks and financial services use payShield Cardholder Authentication for nShield to enable log-on to its online banking site using EMV-based authentication and reduce card-not-present fraud with 3-D-Secure. They use the same HSM to secure SSL private keys and accelerate SSL sessions on the webserver. (Read banking case studies about bgc in Sweden, BACS in the UK, and Alpha Bank.)
  • Technology companies protect their PKIs with Thales HSMs to generate certificates for users, laptops, servers, and other devices. High tech manufacturing companies also use certificates and the CodeSafe technology to safeguard against counterfeiting, knock-offs, and grey markets. Thales HSMs also protect the intellectual property of technology companies on production lines in untrusted locations. (Read case studies from the technology sector about Exostar and Microsoft.)
  • Retailers who need to comply with the Payment Card  Industry Data Security Standard (PCI DSS) use Thales HSMs to reduce the chance of a credit card data breach and to lower their key management costs. (Read retail case study about Follett.)
  • Telecommunication companies use nShield Solo modules to decrypt information from their customer databases to collect data for electronic invoices and then digitally sign them using the same HSM. (Read telecommunications case study about si.mobil Vodafone.)

Remote management reduces costs
In situations where nShield Solo or nShield Connect HSMs are deployed at a remote site or in a lights-out data center, Remote Operator can be used with an nShield Solo card in the operator's machine to remotely provide credentials. This accelerates security administration and reduces travel costs.

Load balancing and high availability enable business continuity
nShield Solo can be deployed with clustered servers to enable load balancing and high availability. If used within the same Security World management infrastructure, updated key material is simultaneously made available to all modules.

Rack-mountable card readers for data centers 
For customers deploying one or more nShield Solo modules in a 19" rack, the optional nShield SmartCard Reader Rackmount provides a practical and tidy solution to attach card readers in the data center.

nShield Card Reader Rack Mount Front with nShield Solo and Smart Cards

Security World management lowers TCO
The Security World management software enables central management of nShield Solo, nShield Connect and netHSM to reduce setup and administration time. Security World enables remote operation of HSMs in lights-out data centers, disaster recovery even for total hardware replacements, and key sharing across HSMs and geographies. Keys and meta information can be automatically backed up without requiring additional hardware or on-site presence, reducing the total cost of operations.

Premium performance avoids bottlenecks
nShield Solo offers hardware acceleration for cryptographic operations, making it the world’s fastest HSMs with up to 6,000 signing transactions per second (TPS) with 1,024 RSA keys. Using RSA 2,048 bit keys, which the National Institute of Standards and Technology (NIST) recommends from 2010, nShield Solo excels with up to 3,100 TPS. Web servers, such as Microsoft IIS and Apache, can increase SSL throughput by off-loading handshake operations to the nShield Solo.

Elliptic curve cryptography is becoming increasingly popular. All nShield Solo cards can process elliptic curves inside the HSM, which requires the Elliptic Curve (ECC) Activation. nShield 500 offers especially good performance because it features hardware acceleration of elliptic curve operations.

Readily integrates with third-party applications
nShield Solo integrates with applications through standard interfaces including PKCS#11, Java Cryptography Extension (JCE), Microsoft CAPI and CNG.

Thales HSMs of the nCipher Product Line integrate with business applications through Microsoft CryptoAPI / CNG, PKCS#11, Java JCE, OpenSSL and nCore

nShield Solo is compatible with nShield Connect and netHSM products and can be upgraded to support additional features using various option packs. nShield Solo supports a broad range of operating systems, including Windows 2008/2003/Vista/XP, Linux Solaris, AIX and HP-UX. 

CodeSafe protects data in hostile environments
All HSMs can protect key material against breaches, but most cannot actually protect your valuable data while it is in use. Data breaches have shown that Trojans or rogue administrators still have access to sensitive information on the host system after it has been decrypted by the HSM. The Thales CodeSafe technology enables you to process sensitive information inside the HSM so that it is never exposed on the host system. This enables you to run critical processes in hostile environments, for example:

  • Where facilities cannot be physically secured
  • Where you need to protect against rogue individuals with access to the host system
  • Where host systems may be hacked or become infected by Trojans 

Thales offers off-the-shelf CodeSafe applications as well as CodeSafe Developer Software to create custom applications. You must use nShield Solo variants complying with FIPS 140-2 Level 3 to run CodeSafe applications.

Delivers FIPS and Common Criteria
nShield Solo supports a broad range of public-key and symmetric algorithms, including a full Suite B implementation with optional, fully licensed elliptic curve cryptography (ECC). nShield Solo's security boundary is validated to FIPS 140-2 Level 3 and Common Criteria EAL 4+. nShield Solo modules are also available in FIPS 140-2 Level 2 variants at a lower price. Following security best practice and to enable compliance, it separates administrative and operational duties with two-factor authentication and dual control. These operator groups can segregate access to keys by application, role, division, or geography.

Ensure project success with Thales deployment services 
Thales offers professional services to ensure a best practice implementation of Thales HSMs. Organizations can benefit from developer support to integrate Thales HSMs with custom applications or to develop custom applications to be executed on the HSM to process sensitive data.

Watch how easy it is to set up nShield Solo modules
nShield Solo Setup Demo Watch this video to see how to set up nShield Solo on a server. Specifically, you will learn how to:

  • Generate a new Security World with nShield Solo
  • Create the Administrator Card Set (ACS)
  • Generate an Operator Card Set (OCS) using the CSP Install Wizard
  • Verify that the installation was successful

Duration: 13:44 minutes

The video does not cover the integration of the actual application because the process differs by application.

See specifications >>

 

Model overview

nShield Solo is available in several different variants:

Model  Interface  FIPS
140-2 
Common
Criteria
CodeSafe-
ready
nShield 500 F2 PCI/PCI-X Level 2 EAL 4+ No
nShield 500 F3 PCI/PCI-X Level 3 EAL 4+ Yes
nShield 500e F2 PCI Express  Level 2  EAL 4+ 

No 

nShield 500e F3 PCI Express  Level 3 EAL 4+ Yes
nShield 2000 F2 PCI/PCI-X Level 2 EAL 4+ No
nShield 2000 F3 PCI/PCI-X Level 3 EAL 4+ Yes
nShield 4000 F2 PCI/PCI-X Level 2 EAL 4+ No
nShield 4000 F3 PCI/PCI-X Level 3 EAL 4+ Yes
nShield 6000e F2 PCI Express Level 2 EAL 4+ No
nShield 6000e F3 PCI Express Level 3 EAL 4+ Yes


General specifications

PCI modules: nShield 2000 F2, 2000 F3, 4000 F2, 4000 F3

  • nShield Solo PCIFull-height PCI, 174.6 mm length
  • 33/66 MHz, 32/64 bits
  • PCI 2.3 compliant
  • PCI 2.1, 2.2, PCI-X compatible
  • Maximum power consumption: 10 watts
  • Operating temperature: 10-35 degrees Celsius
  • Relative Humidity: 10%-85% non-condensing


PCI modules: Thales nShield 500 F2, 500 F3

  • Full-height PCI, 127.9 mm length
  • 33/66 MHz, 32 bits
  • PCI 2.3 compliant
  • PCI 2.1, 2.2, PCI-X compatible
  • Maximum power consumption: 5 watts
  • Operating temperature: 10-35 degrees Celsius
  • Relative Humidity: 10%-85% non-condensing


PCI Express modules: Thales nShield 500e F2, 500e F3, 6000e F2, 6000e F3

  • nShield Solo PCI ExpressPCI low-profile PCI Express, 167.65 mm length
  • PCI Express, single lane
  • PCI Express 1.1 and 2.0 compatible
  • Maximum power consumption: 10 watts
  • Operating temperature: 10-35 degrees Celsius
  • Relative Humidity: 10%-85% non-condensing


Performance

Performance numbers are provided in signing transactions per second (TPS). Performance may vary depending on operating system, application, and other factors.

Model  TPS @
RSA 1k
TPS @
RSA 2k
TPS @
RSA 4k
ECC HW
Acceleration
nShield 500 F2 460 81 12 Yes
nShield 500 F3 460 81 12 Yes
nShield 500e F2 540 145 67 No
nShield 500e F3 540 145 67 No
nShield 2000 F2 2000 300 20 No
nShield 2000 F3 2000 300 20 No
nShield 4000 F2 4400 575 40 No
nShield 4000 F3 4400 575 40 No
nShield 6000e F2 6000 3100 550 No
nShield 6000e F3 6000 3100 550 No


Hardware Options

nShield SmartCard Reader Rackmount Front


Optional features


Algorithms

  • Public key algorithms: RSA, Diffie-Hellman, DSA, El-Gamal, KCDSA, ECDSA, ECDH
  • Symmetric algorithms: AES, ARIA, Camellia, CAST, DES, RIPEMD160 HMAC, SEED, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, Triple DES

Note: Not all algorithms are available in FIPS 140-2 Level 3 mode.


Certified for Windows Server 2008 R2Platforms

  • Windows 2008 R2/2008/2003/Vista/XP
  • Solaris
  • HP-UX
  • AIX
  • Linux


Application interfaces

  • PKCS #11
  • Microsoft CryptoAPI / CNG
  • Java JCE
  • OpenSSL
  • nCore


Third-party applications
For more information on vendors providing applications compatible with nShield Solo, please visit the Thales Partners section.

Certifications


Questions? Contact a Thales representative

 

Related Resources

White Papers


  • Secure Execution Engine
    The Secure Execution Engine runs application software in a proven, certified hardware environment. It protects data, processes, and intellectual property that would otherwise be at risk.

Solution Sheets


  • DNSSEC Solution Brief
    The domain name system (DNS) is a critical network infrastructure component responsible for the routing of both intranet and Internet connections.

Related Products


  • Thales nShield Connect
    Thales nShield Connect is a network-attached, general-purpose hardware security module that is optimized for business continuity and scalability.

Related Data Sheets


  • Thales nShield Solo
    An embedded hardware security module in a PCI/PCIe card form factor, Thales nShield Solo, part of the nCipher product line, provides physical and logical protection for encryption keys and sensitive application code.


  • nShield Family Brochure
    The Thales nShield family of general purpose hardware security modules (HSMs) enhances the security and performance of server-based applications that handle your most sensitive data.

Webinars & Videos


  • Application Security - Video
    Our webinar overviews Thales nShield hardware security modules (HSM) and Time Stamp Server (TSS) technology to help customers protect sensitive data and protect critical IT infrastructure and business applications like PKI, ID management, database encryption, web portals & data processing solutions and more.