Overview
Luna G5 delivers industry leading key management in a portable appliance with an USB interface. All key materials are maintained exclusively within the confines of the hardware.
The small form-factor and on-board key storage sets the product apart, making it especially attractive to customers who need to physically remove and store the small appliance holding PKI root keys.
Crytographic Capabilities
Luna G5 supports a broad range of asymmetric key encryption and key exchange capabilities, as well as support for all standard symmetric encryption algorithms. It also supports all standard hashing algorithms and message authentication codes (MAC). The Luna G5 has a hardware implemented random number generator (AES-DRBG) compliant with NIST SP 800-90.
Enhancing the previous generation HSM’s support of factory generated digital IDs based on RSA key pairs, the Luna G5 also supports ECC key pairs for use in Suite B applications that require a permanent, factory generated digital ID.
Features & Benefits
Sample Applications:
- PKI key generation & key
- Storage (online CA keys & offline CA keys)
- Certificate validation & signing
- Document signing
- Transaction processing
- Database encryption
- Smart card issuance
Security at a Glance:
- Keys in hardware
- Remote Management
- Secure transport mode for high-assurance delivery
- Multi-level access control
- Multi-part splits for all access control keys
- Intrusion-resistant, tamper evident hardware
- Secure Audit Logging
- Strongest cryptographic algorithms
- Suite B algorithm support
- Secure decommission
Features:
- Intrusion-resistant, tamper-evident hardware
- Field Serviceable Components
- Software upgradable
- Multiple Roles for Administration
- Strong Separation of Duties
- Load Balancing and Scalability
- Specification
Operating System Support
OS Support : Windows, Linux
Cryptographic Support
Cryptography – Full Suite B support
– Asymmetric: RSA (1024-8192), DSA (1024-3072), Diffie-Hellman, KCDSA, Elliptic Curve Cryptography (ECDSA, ECDH, ECIES) with named, user-defined and Brainpool curves
– Symmetric: AES, RC2, RC4, RC5, CAST, DES, Triple DES, ARIA, SEED
– Hash/Message Digest/HMAC: SHA-1, SHA-2 (224-512), SSL3-MD5-MAC, SSL3-SHA-1-MAC
– Random Number Generation: FIPS 140-2 approved DRBG (SP 800-90 CTR mode)
Crytographic APIs PKCS#11, Java (JCA/JCE), Microsoft CAPI and CNG, OpenSSL
Physical Characteristics
Dimensions : 8.5″ x 6.675″ x 1.7″ (215.9mm x 169.545mm x 43.18mm)
Weight : 3.3lb (1.5kg)
Input Voltage : 100-240V, 50-60Hz
Power Consumption : 26W maximum, 20W typical
Temperature : Operating 0°C – 35°C, storage -20°C – 70°C
Relative Humidity : 20% to 95% (38°C) non-condensing
Host Interface : USB 2.0
Security Certifications
Certifications – FIPS 140-2 Level 2 and Level 3
– BAC & EAC ePassport Support
Safety and Environmental Compliance
Compliance – UL, CSA, CE
– FCC, KC Mark, VCCI, CE
– RoHS, WEEE
Management, Logging, and Monitoring
Management : M of N support for division of command