>_ Skip to main content
Menu
Search
Post-Quantum Security

Thales Launches Post-Quantum Luna 8 Hardware Security Module

Thales has launched Luna 8, a hardware security module that uses post-quantum cryptography to protect keys, identities, applications, and digital transactions. It’s one of five security products that the company announced, alongside AI-focused tools and a Google Cloud collaboration for securing agentic AI. Thales calls it the fastest HSM it has built, a claim resting on a cryptographic processor the company designed in-house.

What Thales says Luna 8 does

According to the October 1 report, the module runs both traditional and post-quantum workloads on that custom chip, which Thales says delivers high throughput and low latency for high-volume jobs such as SSL/TLS key protection, code signing, digital-identity issuance, and similar work.

The company also claims Luna 8 draws about 20 times less energy per transaction than its previous generation. Both the speed and the efficiency figures are Thales’s own, and the announcement doesn’t include independent benchmarks.

Thales describes the platform as crypto-agile, meaning it’s designed to take on new algorithms and standards as requirements change, and says its software updates and internal security mechanisms have been made quantum-safe. The release doesn’t name which NIST-standardized algorithms (such as ML-KEM or ML-DSA) the module implements.

The security and operational features Thales lists include:

  • Keys that stay inside tamper-evident hardware
  • Protection against side-channel attacks on the processor
  • Secure audit logging, device attestation, quorum authorization and multi-factor authentication
  • A multi-tenant design with one or two independent crypto modules per appliance, each hosting up to 15 isolated HSM instances, for as many as 30 per device

Certification is a target, not yet a result

Thales says the hardware is designed for FIPS 140-3 Level 3 and Common Criteria certification. That’s a design goal rather than a completed validation, so buyers who need certified modules will want to confirm the status before they deploy. The company also cites support for GDPR, eIDAS, HIPAA and PCI DSS requirements, plus separation of duties and configurable security policies.

The other four launches center on AI. CipherTrust DSPM uses AI to find and protect sensitive data, Sentinel Envelope+ guards applications against AI-driven attacks, the AI Security Fabric offered with Google Cloud aims to protect AI agents and their data across the lifecycle, and a separate machine-speed security approach combines threat intelligence and expertise to counter automated attacks.