HSM Software Option Packs
Entrust nShield Option Pack 设置简单、部署方便,可以帮助您将高度安全的 nShield HSM 集成到您的首选环境,并为集成提供所有相关支持。
Web 服务
Cloud-friendly, REST-like interface for nShield HSM software in high assurance environments.
Containerized Applications
Containerized applications integrated with high assurance FIPS certified nShield HSMs.
电子时间戳
Secure, accurate time stamping ensures the integrity and traceability of digital records, code signing, transactions, logs, and more.
云整合
Use your HSM software and nShield HSMs to generate, store, and manage the keys you count on to secure your sensitive cloud-hosted applications.
数据库安全
通过 Microsoft 可扩展密钥管理 (EKM) API 与 Microsoft SQL Server 相集成。
后量子
Enable post-quantum cryptographic applications for nShield HSMs and HSM software.
Web Services Option Pack (WSOP)
The nShield WSOP provides a REST-like API between applications requiring cryptographic key and data protection services and FIPS-certified nShield HSMs. nShield HSMs perform a variety of cryptographic functions, including encryption, signing, random number generation, and key generation.
Benefits include:
技术规格
nShield 兼容性
- Compatible with all current nShield models
- Must be installed onto a host running a supported version of the Linux OS, Windows Server, or Windows OS, and have the nShield Security World software installed
- 支持操作员卡套装和受软卡保护的密钥
- Compatible with the nShield Container Option Pack, allowing WSOP instantiations to be containerized
API Compatibility
- nShield HSMs can support applications using the Web Services API alongside applications using other supported APIs (e.g., PKCS#11, Java, CNG, etc.)
nShield Container Option Pack (nCOP)
Containerized applications can be hard to integrate with high assurance hardware security modules. When the time from staging to production is critical, you need a proven deployment model and scripts that reduce the overall development cycle. nCOP simplifies the process of building HSM support into containerized solutions and provides a template deployment model without the worry of HSM integration.
Benefits include:
技术规格
支持的操作系统
- 仅支持 Linux 发行版
支持的 HSM
- Compatible with nShield Connect XC and nShield 5c HSMs
- Compatible with nShield as a Service for cloud-hosted HSM deployments
可扩展性和许可
- nCOP supports any number of hardserver or application containers, and can work with any number of container hosts (physical or virtualized server instances)
- When used in conjunction with network-attached nShield HSMs, client licenses will be required depending on the scale of deployment. The option pack includes a weighting factor for calculating the number of client licenses required based on the maximum number of running application containers to be deployed. Refer to licensing options table below for guidelines on the number of client licenses required for different sized deployments
兼容性
- 具备与 Red Hat OpenShift 容器平台的认证集成
许可选项
| 每个 HSM 的客户端许可证数量 | Maximum Container Pods | Maximum Application Containers |
|---|---|---|
| 5 | 5 | 50 |
| 10 | 10 | 100 |
| 15 | 15 | 150 |
| 20 | 20 | 200 |
| > 25 | > 25 | > 2501 |
注 1: 建议购买企业版客户端许可证
nShield 时间戳 OPTION PACK
Digital time stamping is integral to an organization’s ability to verify data and code integrity, generate audit trails, and enforce non-repudiation for electronic signatures. Entrust delivers a secure, high assurance time-stamping solution protected by nShield Solo XC HSMs. This time stamping solution automates records processing and supports a diverse array of applications.
Benefits include:
技术规格
时间戳 API
- We offer a software API that enables developers to build applications requesting time stamps from a server equipped with nShield Solo XC HSM and the Time Stamping Option Pack
兼容性
- Compatible with Microsoft Windows servers
集中式时间源
- Depending on customer requirements, the Time Stamping Option Pack can generate time stamps based on a centralized time source or the UTC (Coordinated Universal Time) standard
nShield Cloud Integration Option Pack (CIOP)
The nShield CIOP allows cloud service user to generate keys in their own environment and export them for use in the cloud. Users can be confident that their keys have been generated securely using a strong entropy source, and that long-term storage of their keys is protected by a FIPS-certified HSM. Supported cloud services include Amazon Web Services (AWS), Google Compute Engine, Microsoft Azure, and Salesforce.
Benefits include:
技术规格
Compatibility and Requirements
- Supported on all current nShield HSM models
- Azure BYOK: Requires nShield Security World Software v12.60 and firmware v12.60 or later
- AWS and Google Compute Engine: Requires nShield Security World software v12.40 or later
- Salesforce: Requires nShield Security World software v12.70 and firmware v12.70 or later
支持的平台
This release has been tested for compatibility on a range of platforms, including:
- Microsoft Windows 11 x64
- Microsoft Windows Server 2022 x64
- Microsoft Windows Server 2022 Core x64
- Red Hat Enterprise Linux 8 x64
- Red Hat Enterprise Linux 9 x64
- Oracle Enterprise Linux 8 x64
nShield 数据库安全选项包
The nShield Database Security Option Pack enables seamless integration of nShield HSMs with Microsoft SQL Server. Encrypting data in your database protects it, but the encryption keys used to unlock the data must also be protected. Using an HSM safeguards encryption keys by storing them separately from the data on a secure, trusted platform.
Benefits include:
技术规格
SQL EKM Provider Capability
- The SQL EKM provider has been tested to support the Enterprise Editions of Microsoft SQL Server 2019, Microsoft SQL Server 2017, and Microsoft SQL Server 2016
支持的平台
- Microsoft Windows Server: 2019 R2 Standard (64-bit configuration) and 2016 (64-bit configuration)
支持的 Security World 软件和 nShield HSM
- The Database Security Option Pack for SQL Server is fully compatible with v12.40.2 or higher of the Security World Software and all current PCIe and network-attached HSMs
支持的数据库加密类型
From a security perspective, Microsoft SQL Server supports the use of cryptographic keys to protect its databases. These encryption keys can be used to perform two levels of encryption:
- Transparent Data Encryption (TDE): Encrypts entire databases without changing existing queries or applications. When SQL Server loads a TDE-encrypted database into memory from disk storage, it automatically decrypts it. This enables clients to query the database within the server environment without manual decryption. The database is re-encrypted when saved to disk storage. When using TDE, data is unprotected by encryption while in memory, and TDE supports one encryption key per database at a time.
- Cell-Level Encryption (CLE): Requires specifying data and encryption key(s) for encryption. CLE uses one or more keys to encrypt individual cells or columns, enabling fine-grained access policies for sensitive database data. Only specified data is encrypted: other data remains unencrypted. This minimizes exposure in database servers and client applications. CLE can also be applied to tables encrypted with TDE. 注意:CLE data is decrypted in memory as needed, and different encryption keys can encrypt separate data within the same table.
Supported Deployment Configurations
- 独立服务
- 使用 nShield Solo 或 nShield Connect 的数据库故障转移群集
nShield 后量子选项包
The nShield Post-Quantum Option Pack leverages the Entrust CodeSafe SDK and the liboqs open source library to provide quantum-resistant cryptographic algorithms to customers.
Benefits include:
立即开始
要求
- FIPS Level 3 nShield HSM
- Codesafe 开发人员工具包
- CodeSafe activation license
Learn more about Codesafe.
常见问题解答
What is a hardware security module?
A hardware security module (HSM) is a physical device designed to securely generate, store, and manage cryptographic keys that protect sensitive data. HSMs are critical tools for ensuring data security, providing secure storage for digital keys, and enabling cryptographic operations like encryption, decryption, and digital signing. Organizations use HSM devices to strengthen their cryptographic infrastructure and comply with security regulations such as PCI DSS.
What does an HSM do?
An HSM device performs key functions essential to data security, including:
- Key generation and management: Creating and securely storing cryptographic keys.
- Digital signing and encryption: Enabling operations like digital signatures to ensure data integrity and secure communication.
- Access control: Protecting sensitive data by limiting access to cryptographic operations and digital keys.
Why is HSM security important?
HSM security is critical because it protects the foundation of an organization's cryptographic infrastructure. HSMs securely store and manage keys, ensuring that sensitive data, such as encrypted information or digital signatures, remains protected from unauthorized access. HSM security also plays a vital role in compliance with regulatory frameworks like PCI DSS and helps organizations maintain trust in their cryptographic operations and data protection practices.
What is an HSM software option pack?
An HSM software option pack is a set of advanced features and tools that extend device functionality. These option packs enhance cryptographic capabilities, enabling organizations to perform specialized tasks like code signing, digital signatures, or secure communication more efficiently. Entrust’s HSM Software Option Packs provide tailored solutions to suit specific use cases, ensuring organizations can adapt their HSM operations to evolving security needs.
What features are enabled by Entrust Software Option Packs?
Entrust Software Option Packs enable advanced functionalities for various uses. 例如:
- nShield Web Services Option Pack: Provides secure APIs for cryptographic operations, allowing applications to interact with HSMs through web services.
- Cloud Integration Option Pack: Enables seamless integration with environments like Microsoft Azure and Google Cloud, supporting secure key management in hybrid architectures.
- Time Stamp Option Pack: Offers tamper-proof, trusted time stamps for documents and transactions, ensuring data integrity and compliance.
- Database Security Option Pack: Secures integration with databases, enabling encrypted data storage and operations.
- Post-Quantum Option Pack: Protects cryptographic keys and sensitive data from future quantum-based threats.
Can HSM software support compliance?
Yes, HSM software plays a big role in supporting compliance by enabling secure cryptographic operations and helping organizations meet regulatory requirements for data protection. Entrust’s Software Option Packs can:
- Ensure compliance with data integrity standards by providing tamper-proof time stamps.
- Secure sensitive data stored in databases, supporting standards like PCI DSS.
- Prepare organizations for future compliance requirements via post-quantum cryptography.
These solutions, combined with Entrust’s industry-leading nShield HSMs, ensure that organizations maintain robust security while adhering to best practices and regulatory mandates.
Reach out to an Entrust specialist and learn more about how our HSM Software Option Packs can help secure your organization.