808bits

Thales Luna K7 Cryptographic Module

FIPS 140-3 certificate #4684 · Thales · data as of 2026-09-15

Thales Luna K7 Cryptographic Module, from Thales, holds FIPS 140-3 certificate #4684 at overall level 3. The validation is active, with a sunset date of 2029-04-01. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2029-04-01, 928 days away.
Caveat: When operated in approved mode

Certificate

Certificate number4684
StandardFIPS 140-3
Statusactive
Sunset date2029-04-01
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorThales · website
Hardware versions808-000048-002, 808-000048-003, 808-000066-001, 808-000073-001, 808-000073-002
Firmware versions7.8.4 with bootloader version 1.1.1, 1.1.2, 1.1.4 or 1.1.5; 7.8.5 with bootloader version 1.1.1, 1.1.2, 1.1.4 or 1.1.5

Module description

Quoted from the NIST CMVP entry for this certificate.

The Thales Luna K7 Cryptographic Module is a multi-chip embedded hardware cryptographic module in the form of a PCIe card which typically resides within a custom computing or secure communications appliance.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (59)

AlgorithmCAVP certificates
AES-CBCC1707
AES-CFB128C1707
AES-CFB8C1707
AES-CMACC1707
AES-CTRC1707
AES-ECBC1707
AES-GCMC1707
AES-KWC1707, C1718
AES-KWPC1707, C1718
AES-OFBC1707
AES-XTSC1707
Counter DRBGC1707
DSA KeyGen (FIPS186-4)C1707, C1718
DSA PQGGen (FIPS186-4)C1707, C1718
DSA SigGen (FIPS186-4)C1707
DSA SigVer (FIPS186-4)C1707
ECDSA KeyGen (FIPS186-4)C1707, C1718
ECDSA SigGen (FIPS186-4)C1707, C1718
ECDSA SigVer (FIPS186-4)C1707, C1718
HMAC-SHA-1C1707
HMAC-SHA2-224C1707
HMAC-SHA2-256C1707, C1718
HMAC-SHA2-384C1707
HMAC-SHA2-512C1707
HMAC-SHA3-224C1707
HMAC-SHA3-256C1707
HMAC-SHA3-384C1707
HMAC-SHA3-512C1707
KAS-ECC Sp800-56Ar3A480
KAS-ECC-SSC Sp800-56Ar3A478, A480
KAS-FFC-SSC Sp800-56Ar3A478, A480
KAS-IFCA478, A479, A480, A481
KDA OneStep Sp800-56Cr1A480
KDA OneStep SP800-56Cr2A480
KDF ANS 9.42A480
KDF ANS 9.63A480
KDF SP800-108C1707
KTS-IFCA478, A479, A480, A481
PBKDFA480
RSA KeyGen (FIPS186-4)A478, A479, A480, A481, C1707, C1717, C1718, C1719
RSA SigGen (FIPS186-4)A480, A481, C1707, C1717
RSA SigVer (FIPS186-4)A480, A481, A3164, C1707, C1717
SHA-1C1701, C1707
SHA2-224C1707
SHA2-256C1707, C1718
SHA2-384C1701, C1707
SHA2-512C1707, C1718
SHA3-224C1707
SHA3-256C1707
SHA3-384C1707
SHA3-512C1707
SHAKE-128C1707
SHAKE-256C1707
TDES-CBCC1707
TDES-CFB64C1707
TDES-CFB8C1707
TDES-CTRC1707
TDES-ECBC1707
TDES-OFBC1707

Allowed algorithms

AES Cert. #C1707 (Key unwrapping; SSP establishment methodology provides between 128 and 256 bits of encryption strength; Clone partition objects between partitions, Clone SMK between partitions, Import secret or private key using key wrapping.);Triple-DES Cert #C1707 (Key unwrapping; SSP establishment methodology provides 112 bits of encryption strength; Import secret or private key using key wrapping.);KAS-ECC-SSC Cert. #A480 (Key establishment methodology provides between 112 and 256-bits of encryption strength.; Derive key from existing partition secret or private key object.);KAS-ECC-SSC Cert. #A478 (Key establishment methodology provides between 112 and 256-bits of encryption strength.; Derive key from existing partition secret or private key object.)

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-04-02InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2025-07-07UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-04-02

Source documents