MicroCloud X4

Certificate #2973

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 27.07.2017
Standard FIPS 140-2
Security level 2
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat No assurance of the minimum strength of generated keys.
Exceptions
  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Mitigation of Other Attacks: N/A
Description The Module is a Linux computer in a microSD form factor, providing hardware isolated cryptographic services to host devices into which it is inserted. Main functions of the Module are Cryptographic Support, User Data Protection, Security Management and Protection of the Security Functionality. The cryptographic boundary is SD bus interface of the microSD.
Version (Hardware) P/Ns MCX4-004, MCX4-008
Version (Firmware) X4 Linux 3.4.110.1, MicroCloud Manager 1.9
Vendor Bluechip Systems LLC
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-, SEED, HMAC
Asymmetric Algorithms
ECDSA
Hash functions
SHA-256, SHA256, PBKDF
Protocols
SSL
Randomness
DRBG, RNG
Libraries
OpenSSL
Elliptic Curves
P-256, P-384, NIST P-384
Block cipher modes
ECB, XTS

Trusted Execution Environments
SE

Security level
Level 2, Level 3
Certification process
out of scope, between the MicroCloud Manager and the user is done using a handset application that is out of scope of this document. Vault Service The Vault Service is an Android Service that runs on the Android

Standards
FIPS 140-2, FIPS 197, FIPS 186-4, FIPS 198-1, FIPS 180-4, FIPS140-2, SP 800-38A, SP 800-38E, SP 800-38F, SP 800-90A, SP 800-132, NIST SP 800-132

File metadata

Author Uri Kreisman
Creation date D:20170721090912-07'00'
Modification date D:20170721090922-07'00'
Pages 31
Creator Acrobat PDFMaker 17 for Word
Producer Adobe PDF Library 15.0

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2973,
  "dgst": "09cc2d87080e6edd",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "AES#4251",
        "SHS#3488",
        "KTS#4251",
        "SHS#3487",
        "ECDSA#991",
        "HMAC#2789",
        "AES#4250",
        "SHS#3489",
        "ECDSA#990",
        "DRBG#1329",
        "ECDSA#992"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3.4.110.1",
        "1.9"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 26
          }
        }
      },
      "certification_process": {
        "OutOfScope": {
          "between the MicroCloud Manager and the user is done using a handset application that is out of scope of this document. Vault Service The Vault Service is an Android Service that runs on the Android": 1,
          "out of scope": 1
        }
      },
      "cipher_mode": {
        "ECB": {
          "ECB": 3
        },
        "XTS": {
          "XTS": 5
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 14
        }
      },
      "crypto_protocol": {
        "TLS": {
          "SSL": {
            "SSL": 1
          }
        }
      },
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "NIST P-384": 3,
          "P-256": 22,
          "P-384": 19
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1329": 1,
          "#2789": 1,
          "#3487": 1,
          "#3488": 1,
          "#3489": 1,
          "#4250": 1,
          "#4251": 1,
          "#990": 1,
          "#991": 1,
          "#992": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES (Cert. #4250": 1,
          "AES (Cert. #4251": 1,
          "AES 256": 1,
          "AES, 256": 1,
          "Cert # AES": 1,
          "DRBG (Cert. #1329": 1,
          "HMAC (Cert. #2789": 1,
          "HMAC SHA-256": 1,
          "SHA- 256": 1,
          "SHA-256": 19,
          "SHA256": 3,
          "SHS (Cert. #3487": 1,
          "SHS (Cert. #3488": 1,
          "SHS (Cert. #3489": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 2,
          "Level 3": 1
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 10
        },
        "SHA": {
          "SHA2": {
            "SHA-256": 19,
            "SHA256": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 12
        },
        "RNG": {
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 9,
          "FIPS 180-4": 3,
          "FIPS 186-4": 3,
          "FIPS 197": 2,
          "FIPS 198-1": 1,
          "FIPS140-2": 1
        },
        "NIST": {
          "NIST SP 800-132": 1,
          "SP 800-132": 3,
          "SP 800-38A": 2,
          "SP 800-38E": 1,
          "SP 800-38F": 1,
          "SP 800-90A": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 20,
            "AES-": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 4
          }
        },
        "miscellaneous": {
          "SEED": {
            "SEED": 2
          }
        }
      },
      "tee_name": {
        "IBM": {
          "SE": 9
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Uri Kreisman",
      "/Company": "",
      "/CreationDate": "D:20170721090912-07\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 17 for Word",
      "/ModDate": "D:20170721090922-07\u002700\u0027",
      "/Producer": "Adobe PDF Library 15.0",
      "/SourceModified": "D:20170721160847",
      "pdf_file_size_bytes": 601658,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 31
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "ba74c30a3ca7ce0c7b566e5c990e673ce86d5b5cb6a9d2affe5dd8900d514562",
    "policy_txt_hash": "a9911c1c3ec31fb6a77b78f3bfba2fff5e231671ffcda937b6112af08f244060"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "No assurance of the minimum strength of generated keys.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertJuly2017.pdf",
    "date_sunset": null,
    "description": "The Module is a Linux computer in a microSD form factor, providing hardware isolated cryptographic services to host devices into which it is inserted. Main functions of the Module are Cryptographic Support, User Data Protection, Security Management and Protection of the Security Functionality. The cryptographic boundary is SD bus interface of the microSD.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: Level 3",
      "EMI/EMC: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "X4 Linux 3.4.110.1, MicroCloud Manager 1.9",
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": "P/Ns MCX4-004, MCX4-008",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "MicroCloud X4",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-07-27",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Bluechip Systems LLC",
    "vendor_url": "http://www.bluechipsys.com"
  }
}