2
www.thales-esecurity.com Thales e-Security payShield 9000 Key Benefits Delivers comprehensive, certified security specially designed for cards and mobile secure elements Provides off-the-shelf support for all major payment applications Maximizes business continuity with high resilience features Reduces the cost of compliance with a choice of software options tailored for issuers, processors, and acquirers Offers a range of scalable, high-performance models The Thales payShield 9000 is a payment hardware security module (HSM) that provides the cryptographic protection needed for Automated Teller Machine (ATM) and Point of Sale (POS) credit and debit card issuance and transactions. The cryptographic functionality and management features meet or exceed the card application and security audit requirements of the major international card schemes, including American Express, Discover, JCB, MasterCard, UnionPay and Visa. It is deployed as an external peripheral for mainframes and servers running card issuing, mobile provisioning and payment processing software applications for the electronic payments industry. THE HARDWARE SECURITY MODULE THAT SECURES THE WORLD’S PAYMENTS

Thales e-Security payShield 9000 - asiapeak.com

  • Upload
    others

  • View
    4

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Thales e-Security payShield 9000 - asiapeak.com

w w w . t h a l e s - e s e c u r i t y . c o m

Thales e-Security

payShield 9000

Key Benefits• Delivers comprehensive, certified security specially designed for

cards and mobile secure elements• Provides off-the-shelf support for all major payment applications• Maximizes business continuity with high resilience features• Reduces the cost of compliance with a choice of software options

tailored for issuers, processors, and acquirers• Offers a range of scalable, high-performance models

The Thales payShield 9000 is a payment hardware security module (HSM) that provides the cryptographic protection needed for Automated Teller Machine (ATM) and Point of Sale (POS) credit and debit card issuance and transactions. The cryptographic functionality and management features meet or exceed the card application and security audit requirements of the major international card schemes, including American Express, Discover, JCB, MasterCard, UnionPay and Visa. It is deployed as an external peripheral for mainframes and servers running card issuing, mobile provisioning and payment processing software applications for the electronic payments industry.

The hardware securiTy module ThaT secures The world’s paymenTs

Page 2: Thales e-Security payShield 9000 - asiapeak.com

Card payments support • american express/mastercard/Visa pin and card Verificationfunctions

• EMV3.Xand4.Xtransactionsandmessaging(inc.PINChange)• RemoteKeyLoadingtoNCR,DieboldandWincor-NixdorfATMs• MasterCardOn-behalfKeyManagement(OBKM)• Integrationwithallmajorpaymentauthorizationandswitchingapplications

Management facilities • GraphicalUserInterface(GUI)optionforstandardPChardwareoverEthernet-localandremotemodessupported

• KeyManagementDevice(KMD)optiontoformkeysfromcomponents

• Consoleinterfacefor“dumb”terminals• ClusteringusingThalesSecurityResourceManager(SRM)application

• snmp • Utilizationstatistics,healthcheckdiagnosticsanderrorlogs

Security features • Multiplemasterkeysoptionenablingcryptographicisolation• Two-FactorAuthenticationofsecurityofficersusingsmartcards• Dualphysicallocksand/orsmartcardscontrolauthorizationlevels• Tamper-resistanceexceedingrequirementsofPCIHSMandFIPS140-2Level3

• Detectionofcoverremovalinadditiontoalarmtriggersformotion,voltageandtemperature

• Device‘hardening’-abilitytodisablefunctionsnotrequired bythehostapplication

• Audittrails

Physical characteristics • FormFactor:2U19”rackmount• Height:85mm(3.35”)• Width:478mm(18.82”)• Depth:417mm(16.42”)• Weight:7.3kg(16lb)withsinglePSU, 7.5kg(16.5lb)withdualPSU• ElectricalSupply:100to240VACUniversalinput,47to63Hz.Dualpowersupplyoptiononallmodelsforresilience

• PowerConsumption:100W(maximum)• OperatingTemperature:0degCto40deg• Humidity:10%to90%(non-condensing)

Key management standards supported • ThalesKeyBlocksupport(compliantwithANSIX9.24; supersetofX9TR-31)

• X9TR-31KeyBlocksupport• RSARemoteKeyTransport• DUKPT• Master/SessionKeyScheme• RacalTransactionKeyScheme• AS2805support

Cryptographic algorithms supported • DESandTriple-DESkeylengths112bit,168bit• AESkeylengths128bit,192bit,256bit• RSA(upto2048bits)• FIPS198-1,MD5,SHA-1,SHA-2

Performance options • Rangeofperformanceoptionsupto1500Triple-DESPINblocktranslates/secondusingkeyblocks

• Multi-threadingtooptimizeperformance

Host connectivity • Asynchronous(v.24,RS-232)• TCP/IP&UDP(10/100/1000Base-T)–dualportsforresilience• FICON

Certifications / validations • CryptographicmodulecertifiedtoFIPS: 140-2Level3,46,81,180-3,186-3,198

• pci hsm*• apca • meps • NISTSP800-20,SP800-90(A)

Financial services standards supported • ISO:9564,10118,11568,13491,16609• ANSI:X3.92,X9.8,X9.9,X9.17,X9.19,X9.24,X9.31, X9.52,X9.97

• X9TR-31,X9TG-3/TR-39,APACS40&70,AS2805Pt14©Thales-May2013•LHP1036

Americas – Thales e-Security Inc. 900 South Pine Island Road, Suite 710, Plantation, FL 33324 USA • Tel:+1 888 744 4976 or +1 954 888 6200 • Fax:+1 954 888 6211 • E-mail: [email protected] Pacific – Unit 4101 41/F 248, Queen’s Road East, Wanchai, Hong Kong, PRC • Tel:+852 2815 8633 • Fax:+852 2815 8141 • E-mail: [email protected], Middle East, Africa – Meadow View House, Long Crendon, Aylesbury, Buckinghamshire HP18 9EQ • Tel:+44 (0)1844 201800 • Fax:+44 (0)1844 208550 • E-mail: [email protected]

payShield9000Technical SpecificaTionS

Follow us on:

*CustomersmustexplicitlyspecifyaPCIHSMcompliantproductatthetimeoforder.Specialsoftware,deliveryandconfigurationconditionsapplywhenorderingaPCIHSMcompliantproduct.