U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

This is an archive
(replace .gov by .rip)

Cryptographic Module Validation Program CMVP

Certificate #3617

Details

Module Name
AWS Key Management Service HSM
Standard
FIPS 140-2
Status
Active
Sunset Date
2/18/2025
Validation Dates
02/19/2020;06/08/2020
Overall Level
2
Caveat
When installed, initialized and configured as specified in Section 3 of the Security Policy
Security Level Exceptions
  • Cryptographic Module Specification: Level 3
  • Roles, Services, and Authentication: Level 3
  • Physical Security: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
The Amazon AWS Key Management Service HSM is a multi-chip standalone hardware cryptographic appliance designed to provide dedicated cryptographic functions to meet the security and scalability requirements of the AWS Key Management Service (KMS). The cryptographic boundary is defined as the secure chassis of the appliance. All key materials are maintained exclusively in volatile memory in the appliance and are erased immediately upon detection of physical tampering.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Cert. #4527
CKG vendor affirmed
CVL Certs. #1208 and #1209
DRBG Cert. #1487
ECDSA Cert. #1102
HMAC Cert. #2987
KAS Cert. #122
KBKDF Cert. #133
KTS AES Cert. #4527
KTS vendor affirmed
RSA Cert. #2464
SHS Cert. #3708
Allowed Algorithms
EC Diffie-Hellman (CVL Cert. #1209, key agreement; key establishment methodology provides 192 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)
Hardware Versions
2.0
Firmware Versions
1.5.135 and 1.5.138

Vendor

Amazon Web Services, Inc.
410 Terry Ave N
Ste 1200
Seattle, WA 98109-5210
USA

Kelvin Yiu
kelvinyi@amazon.com
Phone: n/a
Fax: n/a
Ken Beer
kenbeer@amazon.com
Phone: n/a
Fax: n/a

Lab

ACUMEN SECURITY, LLC
NVLAP Code: 201029-0