Entrust nShield Edge

Entrust nShield Edge is a portable hardware HSM module that can be integrated with root certification authorities (CAs), registration authorities (RAs) and data signing applications. The device is a hybrid of a full-featured secure hardware HSM module with a cryptographic card reader in one compact form factor, while having the functionality of secure storage of protected data.

The device has a USB interface that allows it to work with laptops and virtual machines, and is also fully compatible with Entrust’s older HSM modules, including the nShield Solo and newer HSMs in the nShield Connect line.

Main features of the device:

  • Cryptographic keys are securely stored in a hardware module.
  • Support for laptops and virtual machines.
  • Secure archiving of keys.
  • Works with all nShield HSM modules.
  • Ideal solution for offline Certification Authorities (CA).
  • Ability to work remotely with nShield HSM.
  • Simplifies the design of applications that use HSM modules.
  • Ability to install the device in branch offices of companies that need a local HSM.
  • Fast integration with third-party applications.
  • FIPS compliance.

Datasheet

Performance

Performance is measured in transactions/signatures per second (TPS):

EntrustnShieldEdge1
nShield Edge12 - 1024 bit (key generation time 0:06)
2 - 2048 bit (key generation time 1:00)
0.2 - 4096 bit (key generation time 8:00)
Note: performance may depend on the operating system, applications and other factors.
Supported cryptographic algorithms
Symmetric algorithmsAES, Arcfour, ARIA, Camellia, CAST, DES, MD5 HMAC, RIPEMD160 HMAC, SEED, SHA-1 HMAC, SHA-224 HMAC, SHA-256 HMAC, SHA-384 HMAC, SHA-512 HMAC, Tiger HMAC, 3DES
Asymmetric algorithmsRSA, Diffie-Hellman, ECMQV, DSA, El-Gamal, KCDSA, ECDSA, ECDH, Edwards (X25519, Ed25519ph)
HASH algorithmsMD5, SHA-1, SHA-2 (224, 256, 384, 512 bit), HAS-160, RIPEMD160
Technical specification
Physical characteristicsDimensions with stand open: 120 x 118 x 27mm (4.7 x 4.6 x 1in)
Weight: 340g (0.8lb)
Integrated smart card reader
Kensington lock
Power consumption: 700 mW
Input voltage: 5v DC powered by USB host device
Interface Mini USB
USB Type A/Mini USB
USB 1.x and 2.x
Supported OS*Microsoft Windows 7 x64, 10 x64, Windows Server, 2012 R2 x64, 2016 x64, 2019 x64
Red Hat Enterprise Linux AS/ES 6 x64, x86 and 7 x64; SUSE Enterprise Linux 11 x64 SP2, 12 x64, 15.1 x64
Oracle Enterprise Linux 6.10 x64, 7.6 x64
API
PKCS#11, OpenSSL, Java (JCE), Microsoft CAPI and CNG
OptionCipherTools, Remote Operator, Elliptic Curve (ECC) Activation, KCDSA Activation
Supported virtual OSVMWare Server
VMWare Workstation
Microsoft Hyper-V dla Windows Server 2008 R2
Microsoft Virtual PC dla Windows 7
Certifications &CompliancesFIPS 140-2 level 2 and level 3
UL, CE, FCC, RCM, and Canada ICES RoHS2, WEEE
* Contact us in order to obtain detailed information regarding support for a specific OS version.