Contact Us (02) 9388 1741
    Hardware Security Modules

    Entrust nShield 5s: Hardware Security for the Post-Quantum Era

    Deliver high-assurance cryptographic key services with a dedicated PCIe HSM designed for crypto-agility, native hardware-accelerated post-quantum algorithm support, and long-term cryptographic resilience.

    PKIGuard Products
    nShield 5s
    nShield 5s
    #nShield5s
    Our Price: Request a Quote

    Details that matter

    nShield 5s

    Entrust nShield 5s HSMs

    nShield 5s HSMs are PCIe cards that perform encryption, digital signing, and key generation for an extensive range of commercial and custom-built applications, including certificate authorities, code signing, and more. With their comprehensive capabilities and quantum crypto-agility, they are 100% compatible with existing nShield HSM deployments and APIs, and they are highly secure, with FIPS 140-3 Level 3 certification*.

    Models

    The nShield 5s HSM series includes the new high-performance nShield 5s High, which offers superior asymmetric and symmetric performance and best-in-class elliptic curve cryptography (ECC) transaction rates.

    nShield 5s
    Powerful Architecture

    Powerful Architecture

    Our Security World architecture integrates nShield HSMs into a unified ecosystem, delivering scalability, load balancing, and more.

    Post-Quantum Ready

    Post-Quantum Ready

    Prepare for quantum-era threats with native firmware support for hardware-accelerated, NIST-standardized post-quantum algorithms.

    Protection of Sensitive Business and Application Logic

    Protection of Sensitive Business and Application Logic

    Execute code within nShield boundaries, protecting your applications and the data they process.

    Technical Specifications

    Full specifications for nShield 5s

    Specification Details
    Safety and Environmental Standards Compliance UL, CE, FCC, Canada ICES, KC, VCCI, RCM, UKCA RoHS, WEEE, REACH
    Security Compliance
    • FIPS 140-3 Level 3 eIDAS and Common Criteria EAL4 + AVA_VAN.5 and ALC_FLR.2 certification against EN 419 221-5 Protection Profile, under the Dutch NSCIB schemeCan form the basis of an EN 419 241-2 certified remote signing system for eIDASCompliant with BSI AIS 31 for true and deterministic random number generation
    • Validated progress toward quantum-safe cryptography: Entrust nShield HSM implementations of ML-DSA, ML-KEM, and SLH-DSA have achieved validation through NIST’s Cryptographic Algorithm Validation Program
    Supported APIs PKCS#11, OpenSSL
    Supported Cryptographic Algorithms
    • Post-quantum cryptography: Native firmware support for NIST-standardized post-quantum algorithms, including ML-DSA, ML-KEM, and SLH-DSA, with a crypto-agile architecture designed to support future algorithm updates through firmware
    • Full NIST Suite B implementation
    • Asymmetric algorithms: RSA, Diffie-Hellman, ECMQV, DSA, El- Gamal, KCDSA, ECDSA (including NIST, Brainpool & secp256k1 curves), ECDH, Edwards (Ed25519
    Ed25519ph)
    • Symmetric algorithms: AES, AES-GCM, Arcfour, ARIA, Camellia, MD5 HMAC, RIPEMD160 HMAC, SEED, SHA-1 HMAC, SHA-224 HMAC, SHA-256 HMAC, SHA-384 HMAC, SHA-512 HMAC, Tiger HMAC, 3DES
    • Hash/message digest: MD5, SHA-1, SHA-2 (224, 256, 384, 512 bit), HAS-160, RIPEMD160, SHA-3 (224, 256, 384, 512 bit)
    • Elliptic Curve Key Agreement (ECKA) available via Java API and nCore APIs
    • Elliptic Curve Integrated Encryption Scheme (ECIES) available via Java API
    PKCS#11 and nCore APIs TUAK & MILENAGE algorithm support for mutual authentication and key generation (3GPP), Supported Platforms
    Specifications nShield 5s HSM: 1,702,841 hours, nShield 5s modelsBaseMidHighML-DSA signing performance (tps) for NIST standardized PQC schemesML-DSA443407902,780ML-DSA652407901,920ML-DSA872107901,570RSA signing performance (tps) for NIST recommended key lengths2048 bit6703,94913,6144096 bit1358142,2008192 bit19115309ECC prime curve signing performance (tps) for NIST recommended key lengths256 bit2,0857,55321,826512 bit1,0105,97716,164Key generation (key/sec)RSA 2048 bit72023ECDSA P-256 bit1,0403,5803,494ECDSA P-521 bit5182,4802,724Key agreement performance (transaction/sec)ECDH P-256 bit2,0857,55021,436
    Discover More

    Similar Products

    Explore other configurations and models that might suit your needs.

    Call a Specialist
    Today!

    Our team of experts is ready to help you find the perfect solution for your business needs. Get personalized advice and competitive quotes.

    Monday - Friday: 9:00 AM - 6:00 PM AEST
    Sydney, Australia

    Speak to an Expert

    We're here to help with any questions

    Call us now
    (02) 9388 1741