Thales Hardware Security Modules Achieve Common Criteria EAL4+ Certification
Peter Galvin, vice president strategy, Thales e-Security says:
鈥淭hales has long championed best practices and industry standards and this level of security certification demonstrates our commitment to achieving the highest standards and compliance requirements. The use of cryptography, whether it be encryption, strong authentication or digital signing, requires the strict management of cryptographic keys and enforcement of the management policies governing their use. It is vital that Thales customers have a high level of confidence in the products they buy and independent review of a product鈥檚 security properties is a powerful tool in building that confidence. Government agencies and private sector enterprises deploying Thales HSMs can be assured they are implementing the most secure solutions available.鈥
Thales nShield Connect, nShield Connect+, nShield Solo and nShield Solo+ have all been certified to EAL4+, which exceeds the highest level permitted by international mutual recognition arrangements, ensuring customers have the utmost confidence in Thales鈥檚 range of advanced cryptographic solutions. By way of this certification, Thales nShield HSMs are recognised as Secure Signature Creation Devices (SSCDs) which earns them eIDAS compliance (Article 51, Transitional Measures). Thales nShield HSMs are also certified to FIPS-140-2 level 3, a standard defined by the US National Institute of Standards and Technology and the most widely adopted security benchmark for cryptographic solutions in government and commercial enterprises.
Thales鈥檚 participation in the Common Criteria scheme complements FIPS validation by providing a broader scope for evaluation including further assurance that the product has been developed in accordance with internationally recognized best practice. Organismo di Certificazione della Sicurezza Informatica (OCSI), the Italian technical testing and evaluation standards organization, evaluated Thales nShield HSMs for Common Criteria certification.
For industry insight and views on the latest key management trends check out our blog
Follow Thales e-Security on @Thalesesecurity, , and
Thales e-Security is a leading global provider of digital trust management and data protection solutions that protect the world鈥檚 most sensitive applications and information. Thales solutions address identity and privacy related challenges with hardware and software-based encryption, digital signature, and management capabilities. In today鈥檚 increasingly connected world, our solutions help thwart today鈥檚 targeted attacks and reduce the risk of sensitive data exposure introduced by cloud computing and virtualization, consumer devices in the workplace, increased mobility, big data, and more. Thales e-Security has a worldwide support capability, with regional headquarters in the United States, United Kingdom, and Hong Kong.