Thales Luna G7 Cryptographic Module
Certificate
| Certificate number | 4962 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2027-02-06 |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Thales · website |
| Hardware versions | 808-000080-001, 808-000080-002, 808-000064-005, 808-000064-006 |
| Firmware versions | 7.7.3 with bootloader versions 1.3.0, 1.5.0 and 1.6.0 |
| Entropy | ENT (P) |
Module description
The Thales Luna G7 Cryptographic Module is a standalone hardware security module in the form of a USB device. The cryptographic module is contained in its own secure enclosure, which provides physical resistance.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | C2020 |
| AES-CFB128 | C2020 |
| AES-CFB8 | C2020 |
| AES-CMAC | C2020 |
| AES-CTR | C2020 |
| AES-ECB | C2020 |
| AES-GCM | C2020 |
| AES-KW | C2020 |
| AES-KWP | C2020 |
| AES-OFB | C2020 |
| DSA KeyGen (FIPS186-4) | C2020 |
| DSA PQGGen (FIPS186-4) | C2020 |
| DSA SigGen (FIPS186-4) | C2020 |
| DSA SigVer (FIPS186-4) | C2020 |
| ECDSA KeyGen (FIPS186-4) | C2020 |
| ECDSA SigGen (FIPS186-4) | A2125 |
| ECDSA SigGen (FIPS186-4) | C2020 |
| ECDSA SigVer (FIPS186-4) | A2125 |
| ECDSA SigVer (FIPS186-4) | C2020 |
| Hash DRBG | A2125 |
| HMAC-SHA-1 | C2020 |
| HMAC-SHA2-224 | C2020 |
| HMAC-SHA2-256 | C2020 |
| HMAC-SHA2-384 | C2020 |
| HMAC-SHA2-512 | C2020 |
| HMAC-SHA3-224 | C2020 |
| HMAC-SHA3-256 | C2020 |
| HMAC-SHA3-384 | C2020 |
| HMAC-SHA3-512 | C2020 |
| KAS-ECC Sp800-56Ar3 | A2125 |
| KAS-ECC-SSC Sp800-56Ar3 | A2125 |
| KAS-FFC-SSC Sp800-56Ar3 | A2125 |
| KAS-IFC | A2125 |
| KDA OneStep Sp800-56Cr1 | A2125 |
| KDA OneStep SP800-56Cr2 | A2125 |
| KDF ANS 9.42 | A2125 |
| KDF ANS 9.63 | A2125 |
| KDF SP800-108 | C2020 |
| KTS-IFC | A2125 |
| PBKDF | A2125 |
| RSA KeyGen (FIPS186-4) | A674 |
| RSA KeyGen (FIPS186-4) | C2020 |
| RSA SigGen (FIPS186-4) | A674 |
| RSA SigGen (FIPS186-4) | C2020 |
| RSA SigVer (FIPS186-4) | A674 |
| RSA SigVer (FIPS186-4) | C2020 |
| RSA SigVer (FIPS186-5) | A6549 |
| SHA-1 | C2020 |
| SHA2-224 | C2020 |
| SHA2-256 | C2020 |
| SHA2-384 | C2020 |
| SHA2-384 | C2022 |
| SHA2-512 | C2020 |
| SHA3-224 | C2020 |
| SHA3-256 | C2020 |
| SHA3-384 | C2020 |
| SHA3-512 | C2020 |
| SHAKE-128 | C2020 |
| SHAKE-256 | C2020 |
| TDES-CBC | C2020 |
| TDES-CFB64 | C2020 |
| TDES-CFB8 | C2020 |
| TDES-CMAC | C2020 |
| TDES-CTR | C2020 |
| TDES-ECB | C2020 |
| TDES-OFB | C2020 |
Allowed algorithms
KAS-ECC-SSC Cert #A2125 (ephemeralUnified, fullUnified, onePassDH When using Non-NIST curves and allowances from FIPS 140-3 IG C.A, Use of Non-approved elliptic curves.; Derive key from existing partition secret or private key object);KTS (AES Cert. #C2020) (Key unwrapping: key establishment methodology provides between 128 and 256 bits of encryption strength. Uses allowances in FIPS 140-3 IG D.G, Key transport methods, for key unwrapping using un-authenticated modes of encryption listed on Cert #C2020 without use of an additional approved hash function.; Clone SMK between partitions, Import secret or private key using key wrapping. Legacy Unwrapping);KTS (Triple-DES Cert #C2020) (Key unwrapping: key establishment methodology provides 112 bits of encryption strength. Uses allowances in FIPS 140-3 IG D.G, Key transport methods, for key unwrapping using un-authenticated modes of encryption listed on Cert #C2020 without use of an additional approved hash function.; Import secret or private key using key wrapping. Legacy Unwrapping)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2025-02-07 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2025-02-07