Service Overview
payShield Cloud HSM is a ‘bare metal’ hosted HSM service from Thales delivered using payShield 10K HSMs, providing you with the secure real-time, cryptographic processing capabilities required by your payment workloads running in any of the major public clouds. The service addresses the needs of both existing users of payment HSMs and new payment entrants looking to leverage hardware-based security for the first time. Thales is offering its customers a choice of deployment model, namely on-prem, cloud or hybrid (when a mixture of on-prem and cloud HSMs are utilized). Whatever model is chosen, consistent HSM functionality is available with the highest levels of security compliance.
When the payShield cloud HSM variant is deployed, the separation of roles between the end user of the service (you) and the service provider (in this case Thales) differs from the on-prem configuration (where Thales is not directly involved). With the cloud HSM, the physical infrastructure is managed by Thales, and the HSMs are housed in datacenters under Thales control with high-speed links being available if required to connect to public clouds running the application workloads.
Thales allocates each single-tenant HSM to you (the end user) as a part of the subscription service. You therefore have complete administrative control and exclusive access to the HSMs assigned to you under the chosen subscription – importantly you can configure each HSM to support multiple distinct applications or use cases (through the multiple LMK capability) in the same way you would perform secure segregation today with Thales on-prem payShield 10K HSMs. Once the HSM is allocated to you, Thales has no access to any of your data, cryptographic keys, or audit logs. Likewise, when you decide that the HSM is no longer required, all data and keys, belonging to you, are securely erased to ensure complete security and privacy. The HSM is then free to be assigned by Thales to another subscriber as required.
The datacenters used to host the HSMs are PCI DSS certified. Also, the HSMs are PCI HSM v3 and FIPS certified, and the service will maintain ongoing compliance with PCI PIN audit requirements.
payShield Cloud HSM meets the stringent security requirements of the Payment Card Industry (PCI) and the individual payment brands and networks. It offers a high performance, low latency service that enables you to comply with the same payment security audits that apply to any on-prem HSM infrastructures you may be operating. In a hybrid scenario, you can use the same management and monitoring tools (payShield Manager and payShield TMD) and associated smart cards and readers for both on-prem and cloud HSMs.
This guide covers all the typical tasks that you will need to perform to enable your payment application to issue host commands to the HSM. The specific details of the host commands available for use are in the payShield 10K Core Host Commands Guide that you can download from the Customer Support Portal.