Luna 8 brings post-quantum processing into hardware security

Luna 8 brings post-quantum processing into hardware security

Thales has launched Luna 8 for post-quantum security infrastructure deployment. The network appliance adds native algorithms, isolated instances, and an upgradeable hardware architecture.


IN Brief:

  • Luna 8 supports ML-KEM-768 and ML-DSA-65 using a Thales-designed cryptographic processor.
  • A two-module appliance can host up to 30 isolated hardware security module instances.
  • FIPS 140-3 Level 3 and Common Criteria certification assessments remain in progress.

Thales has launched Luna 8, a network hardware security module built around a company-designed cryptographic processor and an upgradeable architecture for existing and post-quantum workloads.

The system is the first product on Thales’s new HSM platform. It stores and operates on cryptographic keys inside tamper-evident hardware, supporting public-key infrastructure, certificate authorities, TLS key protection, code signing, digital identities, database encryption, and transaction signing.

Post-quantum migration increases the burden on that infrastructure. Organisations need to introduce new algorithms without abandoning current certificates, signatures, applications, and operational controls in one step. An HSM therefore needs more than a mathematical implementation: it must keep keys isolated, expose stable interfaces, enforce policy, and remain upgradeable as standards and deployment profiles evolve.

Luna 8 supports ML-KEM-768 for key establishment and ML-DSA-65 for digital signatures. Thales says its custom processor is optimised for high-volume post-quantum operations while retaining traditional cryptographic throughput. The company also claims the new generation is 20 times more energy efficient per transaction than its predecessor, although independent workload comparisons have not been published.

The appliance can contain one or two independent cryptographic modules. Each module can host up to 15 isolated HSM instances, giving a maximum of 30 instances in a two-module system. The density is intended for enterprises, service providers, and hyperscale environments that need separated cryptographic domains without assigning a physical appliance to every application or customer.

Isolation is accompanied by secure audit logging, device attestation, quorum authorisation, multi-factor authentication, and side-channel protection for the processor. The platform also supports an onboard dual entropy source, including a quantum random-number generator, alongside external entropy inputs.

Management has been pulled closer to normal infrastructure operations. Luna 8 provides APIs and command-line tools for administration and automation, integrations for monitoring, logging, and metrics, and out-of-band diagnostics. It can also run multiple firmware versions in secure containers on the same hardware, which is useful where application estates cannot migrate to new cryptographic mechanisms in lockstep.

Existing Luna 7 applications can continue through the Luna HSM Universal Client, and Thales says the migration path uses familiar interfaces and supports movement of existing key material. Backwards compatibility is essential: a post-quantum programme that demands immediate application replacement would shift cost and risk from the cryptographic layer into every dependent service.

Hardware roots of trust are already being designed around longer cryptographic lifecycles in embedded and accelerated-compute systems. Infineon’s quantum-resilient TPM work for Jetson Thor shows the same pressure at platform level, where secure boot, attestation, signed updates, and future algorithm support must survive the service life of deployed equipment.

Thales says Luna 8 has been designed for FIPS 140-3 Level 3 and Common Criteria certification, but those assessments remain in progress. Other listed approvals, including eIDAS 2 qualified signature or seal creation-device status and NATO-related certification, are also pending rather than completed.

Performance comparisons will need to account for more than peak operations per second. Post-quantum keys, ciphertexts, and signatures are larger than many current equivalents, which affects network traffic, application buffers, storage, and transaction latency. HSM throughput must therefore be assessed with the surrounding protocol and application path rather than as an isolated cryptographic benchmark.

Crypto agility will depend on how quickly new mechanisms can be introduced without weakening the certified boundary. Firmware updates, algorithm policy, key migration, and application compatibility all become part of the security case. The upgradeable architecture gives Thales room to respond to changing standards, but customers will still need controlled migration plans and evidence that mixed traditional and post-quantum environments behave as intended.

The network appliance is available now, with a future payShield 11K implementation planned for payment-security workloads. Its immediate test is operational rather than theoretical: whether organisations can introduce ML-KEM and ML-DSA at useful throughput while preserving the interfaces, controls, and audit evidence on which existing systems depend.


Stories for you