nShield Solo Options and Accessories
QUICK LINKS
Form Factors
The nShield Solo is available in PCI and PCIe form factors.
Performance
The nShield Solo is available in multiple performance variants: the 500, 2000, 4000, and 6000, which indicate their signing transactions per second for 1024 bit RSA. Additionally, model PCIe 6000+ is optimized for high performance elliptic curve cryptography (ECC). Please consult the nShield Solo data sheet for additional performance data.
Certification
The nShield Solo is available in FIPS 140-2 Level 2 and FIPS 140-2 Level 3 variants.
CipherTools Developer Toolkit
With the CipherTools Developer Toolkit, you can take full advantage of the advanced capabilities offered by the nShield HSM family as you integrate HSMs with your applications. It includes detailed tutorials and reference documentation, sample programs written in a range of high level languages, and additional versions of libraries to expand capabilities for integration with business applications beyond those that can be achieved by the standard application program interfaces (APIs).
CodeSafe
CodeSafe enables application developers to write programs that are securely loaded within the certified environment of an nShield HSM, protecting them from insider attacks, malware and Trojans on host systems. CodeSafe provides a “glass box” setting where code can be checked in a virtual secure execution environment. Because the security depends on access control rather than secrecy of operation, it is possible to debug application code without destroying its integrity. The secure execution capability provides additional security features to enable fine-grained access control and authorization for the use of security critical resources that are protected on the device, such as private keys, non-volatile user memory, and hardware-secured time. Examples include digital meters, authentication agents, time-stamps, audit loggers, digital signature agents, and custom encryption processes. CodeSafe is available for nShield Solo FIPS 140-2 Level 3 certified HSMs only (not for nShield Solo FIPS 140-2 Level 2 certified HSMs).
| |
|
|
| |
CodeSafe
Activation |
Organizations wishing to leverage the power of CodeSafe will need one license of CodeSafe Developer Software per developer and one CodeSafe Activation license for each HSM executing the code. |
| |
CodeSafe SSL
Activation |
An optional CodeSafe SSL Activation feature enables nShield Solo units to terminate encrypted SSL sessions within the HSM and then re-encrypt the data for applications running in the HSM, so that clear text data is never exposed on the host server. Unlike typical SSL host-based termination, which exposes sensitive clear text data, CodeSafe SSL enables sensitive personal account numbers (PANs) and personal identification numbers (PINs) that are vital for electronic commerce transactions to be distributed across systems with full end-to-end encryption. |
Elliptic Curve Cryptography (ECC) Activation
nShield HSMs offer a large number of cryptographic algorithms as part of the standard feature set, including AES, DSA and RSA. For organizations wishing to use elliptic curve cryptography (ECC), an ECC Activation license is available. The optional activation license enables ECC operation on all nShield Solo and Connect models. For organizations that require significantly accelerated ECC, two additional nShield models are also available. The nShield Solo PCIe 6000+ and nShield Connect 6000+ deliver hardware-optimized ECC performance and come bundled with the ECC Activation license.
Database Security Option Pack
Databases often contain an organization's most sensitive data. As a result, the large database vendors have implemented native encryption in their database server products. Database Security Option Pack adds support for Microsoft’s Extensible Key Management (EKM). It enables organizations to better protect keys that protect sensitive data in Microsoft SQL Server 2008, manage keys across databases and systems, and separate security and database administration. Users of Oracle 11g can take advantage of these features without requiring an option pack.
Time Stamp Option Pack
Secure time stamps help organizations verify that certain data existed at a certain point in time and has not been manipulated since that time. This is critical for applications including digital archives, public key infrastructures, code signing, notary services, patent applications, lottery, as well as betting and gaming. The Time Stamp Server from Thales is a turnkey solution for organizations that want a ready-to-use time stamping solution. For organizations looking for an OEM solution or who want to combine time stamping with other HSM functionality, the Time Stamp Option Pack enhances nShield Solo 500 to support standardized time stamps. The Time Stamp Option Pack is available for nShield Solo FIPS 140-2 Level 3 certified HSMs only (not for nShield Solo FIPS 140-2 Level 2 certified HSMs). Organizations looking to add time-stamping features in custom applications can benefit from the Time Stamping Developer Software.
| |
|
|
| |
Time Stamping Developer Toolkit |
Time Stamping Developer Toolkit is an easy-to-use API that enables applications to request and verify time stamps from the Time Stamp Server or a server featuring an nShield HSM and the Time Stamping Option Pack. It is available for nShield Solo FIPS 140-2 Level 3 certified HSMs only (not for nShield Solo FIPS 140-2 Level 2 certified HSMs). |
payShield Cardholder Authentication for nShield
To protect against credit card and online banking fraud, many financial institutions have implemented additional security measures for card-not-present transactions. payShield Cardholder Authentication for nShield complements other Thales payments products by enabling organizations to authenticate the cardholder through various means, such as Chip and PIN (CAP) authentication for online banking transactions and 3-D Secure, also known as Verified by Visa and MasterCard SecureCode. This option integrates with cardholder authentication solutions including ActivIdentity, Arcot, Bell ID, and Gemalto. Organizations with advanced requirements can also use the payShield Developer Software to produce custom solutions. payShield Cardholder Authentication for nShield is available for nShield Solo FIPS 140-2 Level 3 certified HSMs only (not for nShield Solo FIPS 140-2 Level 2 certified HSMs).
| |
|
|
| |
Key Loading Device |
Keys are typically generated inside an HSM to ensure that the key has never left the secure platform. However, some organizations receive tamper-proof envelopes containing keys from partners they are doing business with, or need to securely exchange sensitive data between systems from different vendors. The Key Loading Device enables organizations to load symmetric encryption key fragments into nShield HSMs by entering them on a PIN pad and loading them onto smart cards that can be read by nShield HSMs. The Key Loading Device requires the use of payShield Cardholder Authentication for nShield. |
Remote Operator
HSMs typically run in physically secure, lights-out data centers, often in several, redundant sites. Many organizations therefore find it impractical to gain physical access to the HSM for day-to-day operations. Remote Operator saves time and reduces travel costs by enabling users to present credentials to a remote HSM in a secure manner directly from their workstation.
KCDSA Activation
Highly sensitive areas of government and enterprises with a strong interest in national security sometimes prefer to use proprietary, national cryptographic algorithms to protect their most sensitive information. Given these security concerns, it is advantageous to run such algorithms on a secure HSM platform. The KCDSA Activation enables South Korean agencies to use the Korean Certificate-based Digital Signature Algorithm (KCDSA) on an nShield HSM. Thales recommends CodeSafe technology to organizations that wish to implement their own national algorithms on the protected HSM platform.
Smart Card Reader Rackmount
For organizations deploying one or more nShield Solo modules in a 19" rack, the optional nShield Smart Card Reader Rackmount provides a practical and tidy solution to attach card readers in the data center. The nShield Smart Card Reader Rackmount is 1U in height and can be equipped with up to four smart card readers, which are shipped as standard with nShield Solo cards. Each unit is shipped with three blanking plates to cover any unused slots.
Compatibility Overview
S = standard; O = optional
*No more than one of these CodeSafe applications can be run on a single HSM.