Module Name
SafeNet USB Hardware Security Module
Validation Dates
06/27/2018
Caveat
When operated in FIPS mode and initialized to Overall Level 3 per Security Policy
Embodiment
Multi-Chip Stand Alone
Description
The SafeNet USB Hardware Security Module delivers key management in a portable appliance. All key materials are maintained exclusively within the confines of the hardware. The small form-factor and on-board key storage sets the product apart, making it especially attractive to customers who need to physically remove and store the small appliance holding PKI root keys. The appliance directly connects the HSM to the application server via a USB interface.
FIPS Algorithms
AES |
Certs. #4849 and #5012 |
CKG |
vendor affirmed |
CVL |
Cert. #1562 |
DRBG |
Cert. #1704 |
DSA |
Certs. #1298 and #1315 |
ECDSA |
Certs. #1242 and #1278 |
HMAC |
Certs. #3306 and #3330 |
KAS |
Cert. #154 |
KBKDF |
Cert. #164 |
KTS |
AES Cert. #5012; key establishment methodology provides between 128 and 256 bits of encryption strength |
RSA |
Certs. #2691 and #2704 |
SHS |
Certs. #3988 and #4075 |
Triple-DES |
Certs. #2552 and #2585 |
Triple-DES MAC |
Triple-DES Certs. #2552 and #2585, vendor affirmed |
Allowed Algorithms
AES (Certs. #4849 and #5012, key unwrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); Diffie-Hellman (key agreement; key establishment methodology provides 112 or 128 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength); Triple-DES (Certs. #2552 and #2585, key unwrapping; key establishment methodology provides 112 bits of encryption strength)
Hardware Versions
LTK-03, Version Code 0102 [1, 2] and LTK-03, Version Code 0103 [1, 2]
Firmware Versions
6.24.6 [1] and 6.24.7 [2]