★ PayShield 10K 소개자료

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 14

payShield 10K

Adding a payShield 10K to your existing


payShield 9000 estate

Thales © 2019 All rights reserved


Adding payShield 10K will help with the following situations

You need to support new payments applications


Only payShield 10K supports hardware-based ECC - fundamental for 3D-Secure 2.x &
EMV 2nd Generation
You need to keep pace with the latest security standards & mandates
Only payShield 10K provides the future-proofing you need based on its more stringent
PCI HSM v3 certification
You need more cryptographic processing capacity quickly
payShield 10K offers much higher performance than payShield 9000, reducing the
space required in your data center racks

2 Thales © 2019 All rights reserved


Operating a mixed HSM estate is simple due to backwards compatibility
No impact on your software
Host applications
Operating system independence
Custom HSM software easily ported to new platform
No impact on your configuration and management processes
Keep your existing LMKs (and re-use existing smart cards)
payShield Manager and payShield Monitor work with both products
Multiple LMKs for cryptographic isolation available on both products
No impact on your compliance status
Audit compliance – both products satisfy all your current requirements
Testing procedure – your existing test software can validate the new
payShield 10K HSMs
Existing HSM utilization – enables you to maximize your past
investments in Thales payment HSM hardware

3 Thales © 2019 All rights reserved


Enhanced rackmount design

Reduced costs
Less space needed in rack (1U v 2U)
Lower power consumption (60W v 100W)
Higher reliability (14x MTBF improvement)
Simplified connectivity
Standard power connectors
Easy access to ports
Power on/off switch
Improved indicators
Minimalist front panel
Health status easily validated
New maintenance light (on front and rear)

4 Thales © 2019 All rights reserved


Connecting to your host system

Standard Ethernet ports on the rear panel


Dual host ports for resilience
Dedicated management port for payShield Manager
Multi-purpose auxiliary port – best used with payShield Monitor

A4665271570Q

Management & AUX


Ethernet Ports

Host Ethernet
Ports 1 & 2

5 Thales © 2019 All rights reserved


Running compatible software on both platforms

Packages and licenses


Performance on payShield 10K linked to package rather than hardware
- payShield 10K offers higher performance across all models
- See payShield 10K Product Options document for guidance
Fewer optional licenses for selection
- More bundling in packages, no functionality removed
May be slight differences in latest base software between platforms
- payShield 10K base will be much more feature-rich over time
- Bug fixes on payShield 9000 software now only provided on V3.x base
Custom software
Existing payShield 9000 custom software can be ported to payShield 10K
- Latest base release will be used
A friendly reminder …
No new payShield 9000 base software releases after 30th June 2020
Not all new features on payShield 10K are available on payShield 9000
31st December 2022 – EOL for support purposes on payShield 9000
6 Thales © 2019 All rights reserved
Leveraging existing smart cards

LMK Component payShield Manager Remote HSM Manager Customer Trust Authority

payShield 9000 smart cards payShield 9000 smart cards Remote HSM Manager smart Smart cards containing Trust
can be used on payShield 10K can be used on payShield 10K cards used to hold LMK components created on
and vice versa and vice versa components are not payShield 9000 using
compatible with payShield 10K payShield Manager can be
6 blank LMK Component smart Additional packs of 6, 30 and used on payShield 10K
cards are no longer supplied 100 payShield Manager smart payShield 9000 supports
free of charge with the HSMs cards can be ordered migration of smart cards in Smart cards created
question to payShield Manager containing Trust components
These are the only type of Existing smart card readers in on payShield 9000 using
smart cards that are use with payShield Manager Remote HSM Manager is not Remote HSM Manager are not
compatible with the Console for payShield 9000 are supported on payShield 9000 compatible with payShield 10K
interface compatible with payShield 10K V3.x software or with any
payShield 10K configuration payShield 9000 supports
migration of the smart cards in
question to payShield Manager

payShield 9000 cards storing security, command or PIN Block configuration cannot be used on the payShield 10K or vice versa

7 Thales © 2019 All rights reserved


Enhanced security configuration

No need to change security processes


Same steps to configure security
Additional features supported in payShield 10K
Minor (but critical difference in security design)
payShield 9000 is always recoverable after a tamper event
payShield 10K has a ‘high tamper’ mode
- Cannot be disabled
- When activated device cannot be recovered
High tamper is triggered by
Tampering of TASP module
Extreme temperature
Loss of battery power
Extreme power spikes and fluctuations

8 Thales © 2019 All rights reserved


Comparing security audit compliance

Ongoing certification work payShield 9000 payShield 10K


payShield 10K v1.0c software certified to
PCI HSM v3
PCI HSM v3 certificate
PCI HSM v1 certificate expired
All major future payShield 10K software PCI HSM
30th April 2019
awarded July 2019
(expires 30th April 2016)
releases will undergo PCI HSM certification
Both products will help you meet HSM
mandates linked to: FIPS 140-2
FIPS 140-2 Level 3 for TSPP FIPS 140-2 Level 3 for TASP
active since 22nd June 2010 In progress
- PCI PIN Security
- PCI P2PE
- PCI TSP APCA/AusPay Active since September 2011 In progress

- PCI 3DS
- PCI SPoC
MEPS Active since August 2013 In progress

9 Thales © 2019 All rights reserved


Future considerations you may need to address

Reducing your data center footprint Migrating to longer key lengths


Lowering your power consumption Supporting ECC algorithm

Ongoing Crypto
cost requirements
reduction for new use
cases

Passing Moving to
security hybrid
audits cloud

Complying with new Simplifying Sharing keys with new service providers
security standards operations Hosting your HSMs in a third party cloud
e.g. PCI HSM v3 Offloading some crypto processing to a
cloud-based HSM

Optimizing HSM management


& monitoring activities

10 Thales © 2019 All rights reserved


Standardizing on payShield 10K will help
Lower running costs
Less space & less power consumption
Latest functionality
Latest payment brand applications & services
- Card, mobile & IoT applications
- Card digitization service support
- EMV payment tokenization support
New use cases requiring ECC algorithm support
- 3-D Secure 2.x
- 2nd Generation EMV
- Software-based PIN Entry on COTS Device (SPoC)
Greater future flexibility
Higher maximum performance
- Ability to support more applications or tenants
Superior service architecture
- Ability to support cloud-based environments

11 Thales © 2019 All rights reserved


payShield HSM feature comparison
Feature payShield 9000 payShield 10K
Base software options Choice of four packages for different usage profiles Choice of two packages for different usage profiles

Code loading mechanism FTP interface or USB stick HTTPS via payShield Manager or the secure
“UPLOAD” Console command using USB-A port
Security sub-system Thales Secure Processing Platform (TSPP) Thales Advanced Security Platform (TASP)
FIPS 140-2 Level 3 & PCI HSM v1 certifications PCI HSM v3 certification
FIPS 140-2 Level 3 (in progress)
PIN block translate (tps) Choice of 20, 50, 150, 220, 800 & 1500 Choice of 25, 60, 250, 1000 & 2500

2048–bit RSA Key Gen / sec 1 80


Power supply options Dual Stationary Dual Hot Swappable
Fan options Stationary Dual Hot Swappable
Management port connection Six USB-A ports USB-C port on front panel
Ethernet for local & remote management USB-A port on rear panel
Ethernet for local & remote management
Ethernet for AUX (payShield Monitor)
Host interface connectivity Dual 10/100/1000 Mbps Ethernet host ports Dual 10/100/1000 Mbps Ethernet host ports
FICON (via optional PCIe adapter card) PCIe slot for FICON (future support planned)
Async Async no longer supported

12 Thales © 2019 All rights reserved


Further information

Presentation slide decks


payShield 10K - Product overview

Supporting documents
payShield 10K datasheet
payShield 9000 / payShield 10K compatibility guide
payShield 10K Product Options

13 Thales © 2019 All rights reserved


Thales © 2019 All rights reserved

You might also like