8.3. nShield Solo XC physical security controls
The nShield Solo XC uses Tamper Resistance, Tamper Evident, Tamper Detection and
Response physical security controls to protect sensitive security parameters within the
unit:
The nShield Solo XC card is covered in an epoxy encapsulant to resist and provide
evidence of tamper attempts. A cosmetic metal lid covers the encapsulant and can be
removed for inspection purposes. See
required to maintain and manage tamper evident security controls.
The nShield Solo XC features tamper detection and response mechanisms that indicates
the following tamper events:
• Abnormal temperature
• Abnormal voltage
• Low battery voltage
• Sensor failure.
When one of the above tamper events is detected (i.e. a possible attempt to compromise
the system has been detected), the HSM will perform the following actions:
1. All non-protected secrets in the HSM will be erased
2. The HSM will enter its Error state
3. The particular tamper event is identified by flashing a morse (SOS) code error on the
LED indicator.
After a tamper event, the HSM and its environment should be examined for signs of
potential tamper/intrusion, and the tamper event recorded (in accordance with the
Customer's Security Incident and Response Policy). If the source of the tamper event can
be discovered and can be considered harmless, provided the Customer's Security
Incident and Response Policy allows, the HSM can be restarted to bring it back into
operation. If the tamper event has not been neutralized, the HSM will just reassert the
tamper event.
If the source of the tamper cannot be discovered, then the HSM should be considered to
be in a compromised state and will have to either be destroyed or returned to Entrust for
secure destruction. See
A list of nShield Solo XC of hard tamper events and their respective morse code error
messages is listed in the Appendices of the User Guide.
nShield® Security Manual
Tamper inspection
Decommission and Disposal
for procedural control guidance
for further information.
57 of 90
Need help?
Do you have a question about the nShield and is the answer not in the manual?