
Payment HSM: nShield HSMi
Leverage a certified payment hardware security module (HSM) to deliver scalable cryptographic services for payment applications, including card production, payment credential issuance, and EMV chip card personalization.

Integral for integrated issuance
The nShield Hardware Security Module (HSMi) is FIPS 140-2 Level 3-certified hardware that delivers cryptographic services for Entrust’s secure issuance software. This tamper-resistant HSMi performs vital functions for financial and identification issuance, including EMV data preparation, key generation, and data protection.
nShield HSMi Benefits
Seamless Integration
Our Security World architecture integrates our HSMi with issuance software, ensuring seamless failover and maximum availability.
High Transaction Rates
Its support for high transaction rates makes it ideal for instant issuance and central issuance.
Remote Administration
The Remote Administration kit facilitates remote smart card presentation for firmware updates and more.
Tech Specs
Supported Cryptographic Algorithms
Asymmetric algorithms: RSA, Diffie-Hellman, ECMQV, DSA, El-Gamal, KCDSA, ECDSA (including NIST, Brainpool & secp256k1 curves), ECDH, Edwards (Ed25519, Ed25519ph)
Symmetric algorithms: AES, Arcfour, ARIA, Camellia, CAST, DES, MD5 HMAC, RIPEMD160 HMAC, SEED, SHA-1 HMAC, SHA-224, HMAC, SHA-256 HMAC, SHA384 HMAC, SHA-512 HMAC, Tiger HMAC, Triple DES
Hash/message digest: MD5, SHA-1, SHA-2 (224, 256, 384, 512 bit), HAS-160, RIPEMD160
Supported Issuer EMV Certificates
- American Express
- Discover
- Elo
- Interac
- Japan Credit Bureau (JCB)
- Jetco
- MasterCard
- NSICCS Indonesia
- Visa
- VCCS Vietnam
Security Compliance
- FIPS 140-2 Level 2 and Level 3 certified
Host Connectivity
- Dual Gigabit Ethernet ports (two network segments)
Safety and Environmental Standards Compliance
- UL, CE, FCC, C-TICK, Canada ICES RoHS2, WEEE
High Availability
- Field-serviceable fan tray components
- Dual hot-swap power supply
- HSM load balancing / Failover with Adaptive Issuance Key Manager
Management and Monitoring
- nShield Remote Administration — includes nShield Trusted Verification
- Device and remote administration smart cards
Physical Characteristics
- Standard 1U 19in. rack mount dimensions: 43.4 x 430 x 705mm (1.7 x 16.9 x 27.8in)
- Weight: 11.5kg (25.4lb)
- Input voltage: 100-240V AC auto switching 50-60Hz
- Power consumption: up to 2.0A at 110V AC, 60Hz | 1.0A at 220V AC, 50Hz
- Heat dissipation: 327.6 to 362.0 BTU/hr. (full load)
Frequently Asked Questions
What Is a Payment HSM?
A payment HSM is a specialized, high-assurance cryptographic device used to secure and manage sensitive payment-related data and processes. These devices are integral to the payment industry, where they protect data associated with financial transactions, such as PCI PIN codes, cardholder data, and cryptographic keys used in payment processing.
How Do I Use a Payment HSM?
Common use cases include:
- Card issuance: Encrypting data during the personalization of EMV chip cards
- Transaction security: Securing point-of-sale (POS) transactions through PIN encryption and verification
- Tokenization: Replacing sensitive data like credit card numbers with non-sensitive equivalents for storage and processing
- Payment security: Securing online payment gateway processes, including 3D Secure implementations
- ATM operations: Managing cryptographic processes for secure ATM withdrawals and PIN management
- Key management: Creating, storing, and distributing cryptographic keys used for securing payments across financial services
What’s the Difference Between a General Purpose HSM and a Payment HSM?
While both general-purpose HSMs and payment HSMs are designed to secure cryptographic keys and perform cryptographic operations, their use cases and compliance requirements differ significantly.
General-purpose HSMs are used in various industries beyond payments, such as healthcare, government, and cloud environments. They perform encryption, decryption, signing, and authentication for general data security applications.
Payment HSMs are tailored for the financial services industry. They protect financial transactions and manage sensitive data using payment cryptography, helping organizations comply with relevant standards like PCI DSS and PCI PIN. As specialized devices, they’re specifically designed to support card production, tokenization, and transaction security.
How Does a Payment HSM Work?
Consider a payment HSM as the secure foundation for your overall payment system, protecting sensitive data, enforcing cryptographic protocols, and ensuring compliance with industry regulations. With the right device, you can leverage several essential capabilities, such as:
- Secure key storage: Payment HSMs store cryptographic keys in tamper-resistant hardware, ensuring that sensitive assets are never exposed in plaintext.
- Transaction processing: They encrypt and decrypt data during credit and debit card payment transactions, such as customer PINs or account details.
- Compliance enforcement: HSMs enforce payment cryptography and other security measures required by standards like PCI DSS.
- Integration: They work seamlessly with banking systems, payment applications, and ATMs to secure payment operations from top to bottom.
Why Are Payment HSMs Important?
The Payment Card Industry Data Security Standard (PCI DSS) is a globally recognized framework for protecting cardholder data and ensuring secure payment processing. It applies to organizations that store, process, or transmit credit card information. In turn, covered entities must meet several requirements:
- Secure network infrastructure: Implement firewalls and encrypt sensitive data
- Access control: Limit access to cardholder data to authorized personnel
- Encryption: Use robust encryption methods for data transmission and storage
- Regular testing: Continuously monitor and test payment systems to identify vulnerabilities
- Policy implementation: Maintain a security policy that addresses information security
Payment HSMs play a crucial role in meeting PCI DSS requirements by:
- Securing cryptographic keys
- Encrypting payment data during transmission and storage
- Providing secure authentication methods for payment processes
Related Products

Resources
Fill out the form below, and an Entrust nShield HSMi specialist will be in touch soon.