808bits

Thales Luna USB Hardware Security Module

FIPS 140-2 certificate #3210 · Thales · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and initialized to Overall Level 2 per Security Policy

Certificate

Certificate number3210
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorThales · website
Hardware versionsLTK-03, Version Code 0102 [1, 2] and LTK-03, Version Code 0103 [1, 2]
Firmware versions6.24.6 [1] and 6.24.7 [2]

Module description

The Thales Luna USB HSM delivers key management in a portable appliance. All key materials are maintained exclusively within the confines of the hardware. The small form-factor and on-board key storage sets the product apart, making it especially attractive to customers who need to physically remove and store the small appliance holding PKI root keys. The appliance directly connects the HSM to the application server via a USB interface.

Security level exceptions

  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3

Approved algorithms

AlgorithmCAVP certificate
AES4849, 5012
CKGvendor affirmed
CVL1562
DRBG1704
DSA1298, 1315
ECDSA1242, 1278
HMAC3306, 3330
KAS154
KBKDF164
KTS
RSA2691, 2704
SHS3988, 4075
Triple-DES2552, 2585
Triple-DES MACvendor affirmed

Allowed algorithms

AES (Certs. #4849 and #5012, key unwrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); Diffie-Hellman (key agreement; key establishment methodology provides 112 or 128 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength); Triple-DES (Certs. #2552 and #2585, key unwrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2018-06-27InitialEWA - Canada
2021-08-31UpdateEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-06-27, 2021-08-31

Source documents