Thales Luna Backup HSM Cryptographic Module
Caveat: When operated in FIPS mode.
Certificate
| Certificate number | 4195 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Thales · website |
| Hardware versions | 808-000064-005, 808-000064-006 |
| Firmware versions | 7.7.1 and bootloader version 1.3.0 or 1.5.0 |
Module description
The Thales Luna Backup HSM Cryptographic Module is a multi-chip standalone hardware cryptographic module in the small form factor device that connects to a computer workstation or server via USB. The cryptographic module is contained in its own enclosure that provides physical resistance to tampering.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C2020 |
| CKG | vendor affirmed |
| CVL | C2020, C2021 |
| DRBG | C2020 |
| ECDSA | C2020 |
| HMAC | C2020 |
| KAS | A2125 |
| KAS-RSA | A2125 |
| KBKDF | C2020 |
| KDA | A2125 |
| KTS | |
| KTS-RSA | |
| PBKDF | A2125 |
| RSA | A674, A675, C2020, C2021, C2022 |
| SHS | C2020, C2022 |
Allowed algorithms
AES (Cert. #C2020, key unwrapping; key establishment methodology provides 256 bits of encryption strength); NDRNG; RSA (CVL Certs. #C2020 and #C2021, key unwrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-04-14 | Initial | EWA - Canada |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-04-14