U.S. flag   An unofficial archive of your favorite United States government website
This is an archive
(replace .gov by .rip)

Cryptographic Module Validation Program CMVP

Certificate #3211

Details

Module Name
SafeNet USB Hardware Security Module
Standard
FIPS 140-2
Status
Active
Sunset Date
6/26/2023
Validation Dates
06/27/2018
Overall Level
3
Caveat
When operated in FIPS mode and initialized to Overall Level 3 per Security Policy
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
The SafeNet USB Hardware Security Module delivers key management in a portable appliance. All key materials are maintained exclusively within the confines of the hardware. The small form-factor and on-board key storage sets the product apart, making it especially attractive to customers who need to physically remove and store the small appliance holding PKI root keys. The appliance directly connects the HSM to the application server via a USB interface.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Certs. #4849 and #5012
CKG vendor affirmed
CVL Cert. #1562
DRBG Cert. #1704
DSA Certs. #1298 and #1315
ECDSA Certs. #1242 and #1278
HMAC Certs. #3306 and #3330
KAS Cert. #154
KBKDF Cert. #164
KTS AES Cert. #5012; key establishment methodology provides between 128 and 256 bits of encryption strength
RSA Certs. #2691 and #2704
SHS Certs. #3988 and #4075
Triple-DES Certs. #2552 and #2585
Triple-DES MAC Triple-DES Certs. #2552 and #2585, vendor affirmed
Allowed Algorithms
AES (Certs. #4849 and #5012, key unwrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); Diffie-Hellman (key agreement; key establishment methodology provides 112 or 128 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength); Triple-DES (Certs. #2552 and #2585, key unwrapping; key establishment methodology provides 112 bits of encryption strength)
Hardware Versions
LTK-03, Version Code 0102 [1, 2] and LTK-03, Version Code 0103 [1, 2]
Firmware Versions
6.24.6 [1] and 6.24.7 [2]

Vendor

Gemalto
20 Colonnade Road, Suite 200
Ottawa, ON K2E 7M6
Canada

Security & Certifications Team
SecurityCertifications@gemalto.com

Lab

EWA CANADA
NVLAP Code: 200556-0