Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #4962

Details

Module Name
Thales Luna G7 Cryptographic Module
Standard
FIPS 140-3
Status
Active
Sunset Date
2/6/2027
Overall Level
3
Caveat
Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11.2 of the Security Policy
Security Level Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
The Thales Luna G7 Cryptographic Module is a standalone hardware security module in the form of a USB device. The cryptographic module is contained in its own secure enclosure, which provides physical resistance.
Tested Configuration(s)
  • N/A
Approved Algorithms
AES-CBC
AES-CFB128
AES-CFB8
AES-CMAC
AES-CTR
AES-ECB
AES-GCM
AES-KW
AES-KWP
AES-OFB
DSA KeyGen (FIPS186-4)
DSA PQGGen (FIPS186-4)
DSA SigGen (FIPS186-4)
DSA SigVer (FIPS186-4)
ECDSA KeyGen (FIPS186-4)
ECDSA SigGen (FIPS186-4)
ECDSA SigGen (FIPS186-4)
ECDSA SigVer (FIPS186-4)
ECDSA SigVer (FIPS186-4)
Hash DRBG
HMAC-SHA-1
HMAC-SHA2-224
HMAC-SHA2-256
HMAC-SHA2-384
HMAC-SHA2-512
HMAC-SHA3-224
HMAC-SHA3-256
HMAC-SHA3-384
HMAC-SHA3-512
KAS-ECC Sp800-56Ar3
KAS-ECC-SSC Sp800-56Ar3
KAS-FFC-SSC Sp800-56Ar3
KAS-IFC
KDA OneStep Sp800-56Cr1
KDA OneStep SP800-56Cr2
KDF ANS 9.42
KDF ANS 9.63
KDF SP800-108
KTS-IFC
PBKDF
RSA KeyGen (FIPS186-4)
RSA KeyGen (FIPS186-4)
RSA SigGen (FIPS186-4)
RSA SigGen (FIPS186-4)
RSA SigVer (FIPS186-4)
RSA SigVer (FIPS186-4)
RSA SigVer (FIPS186-5)
SHA-1
SHA2-224
SHA2-256
SHA2-384
SHA2-384
SHA2-512
SHA3-224
SHA3-256
SHA3-384
SHA3-512
SHAKE-128
SHAKE-256
TDES-CBC
TDES-CFB64
TDES-CFB8
TDES-CMAC
TDES-CTR
TDES-ECB
TDES-OFB
Allowed Algorithms
KAS-ECC-SSC Cert #A2125 (ephemeralUnified, fullUnified, onePassDH When using Non-NIST curves and allowances from FIPS 140-3 IG C.A, Use of Non-approved elliptic curves.; Derive key from existing partition secret or private key object);KTS (AES Cert. #C2020) (Key unwrapping: key establishment methodology provides between 128 and 256 bits of encryption strength. Uses allowances in FIPS 140-3 IG D.G, Key transport methods, for key unwrapping using un-authenticated modes of encryption listed on Cert #C2020 without use of an additional approved hash function.; Clone SMK between partitions, Import secret or private key using key wrapping. Legacy Unwrapping);KTS (Triple-DES Cert #C2020) (Key unwrapping: key establishment methodology provides 112 bits of encryption strength. Uses allowances in FIPS 140-3 IG D.G, Key transport methods, for key unwrapping using un-authenticated modes of encryption listed on Cert #C2020 without use of an additional approved hash function.; Import secret or private key using key wrapping. Legacy Unwrapping)
Entropy
ENT (P)
Hardware Versions
808-000080-001, 808-000080-002, 808-000064-005, 808-000064-006
Firmware Versions
7.7.3 with bootloader versions 1.3.0, 1.5.0 and 1.6.0

Vendor

Thales
20 Colonnade Road
Suite 200
Ottawa, Ontario K2E 7M6
Canada

Security and Certifications Team
securitycertifications@thalesgroup.com
Phone: 33-0-1-57-77-80-00

Related Files

Validation History

Date Type Lab
2/7/2025 Initial LEIDOS CSTL