{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "2c52330077a08ea7", "cert_id": 5153, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "FCAT Wallet Vault Cryptographic Module", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-02-11", "validation_type": "Initial", "lab": "Teron Labs"}], "vendor_url": "https://www.fcatalyst.com/", "vendor": "Fidelity Center for Applied Technology, LLC", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/February 2026_180326_0748-Signed.pdf", "module_type": "Software", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)", "exceptions": ["Physical security: N/A", "Non-invasive security: N/A", "Mitigation of other attacks: N/A"], "embodiment": "Multi-Chip Stand Alone", "description": "The FCAT Wallet Vault Cryptographic Module is implemented within the secure context of the FCAT hardware wallet platform. The FACT Wallet is built atop the ProvenCore EAL7-certified secure OS developed by ProvenRun and operates in conjunction with a hardened version of the OpenSSL FIPS-compliant cryptographic library. The module offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, and message authentication; support for key establishment functions to secure data-at-rest and data-in-flight for the larger FCAT Wallet platform, which includes cryptographic functions supporting user-facing wallet GUI application.", "tested_conf": ["Debian 9 running on a Dell PowerEdge R440 with an Intel\u00ae Xeon Silver 4214R with PAA", "Debian 9 running on a Dell PowerEdge R440 with an Intel\u00ae Xeon Silver 4214R without PAA"], "hw_versions": null, "fw_versions": null, "sw_versions": "1.0", "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2029-01-29", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"Certificate4": 4}}, "fips_security_level": {"Level": {"Level 1": 3, "Level 5": 1}}, "fips_certlike": {"Certlike": {"HMAC 128": 2, "SHA2-224": 14, "SHA2- 256": 7, "SHA2-384": 12, "SHA2-512": 12, "SHA-1": 13, "SHA2-256": 17, "SHA2- 512": 5, "SHA2- 384": 4, "SHA3-224": 3, "SHA3- 256": 1, "SHA3-384": 3, "SHA3- 512 112": 1, "SHA3-256": 4, "SHA3- 384": 1, "SHA3-512": 3, "SHA3- 224": 1, "SHA-3": 1, "SHS39": 1, "SHA-256": 1, "RSA36": 1, "PKCS#1": 6, "AES-GCM 128": 1, "AES-CMAC 128": 1, "AES GCM encrypt KAT46": 1, "DRBG24": 1, "DRBG 9": 1, "DSA25": 1, "CVL21": 1}}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 100}, "CAST": {"CAST": 4, "CAST5": 3}, "RC": {"RC4": 3, "RC5": 3, "RC2": 2}}, "DES": {"DES": {"DES": 8}, "3DES": {"Triple-DES": 20, "TDES": 1}}, "djb": {"ChaCha": {"ChaCha20": 3}, "Poly": {"Poly1305": 2}}, "miscellaneous": {"IDEA": {"IDEA": 3}, "Blowfish": {"Blowfish": 3}, "Camellia": {"Camellia": 3}, "ARIA": {"ARIA": 3}, "SM4": {"SM4": 3}, "SEED": {"SEED": 3}}, "constructions": {"MAC": {"HMAC": 28, "CMAC": 24}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 11}, "ECDSA": {"ECDSA": 27}, "EdDSA": {"EdDSA": 3}, "ECC": {"ECC": 3}}, "FF": {"DH": {"DH": 12, "Diffie-Hellman": 2}, "DSA": {"DSA": 27}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 13}, "SHA2": {"SHA-256": 1}, "SHA3": {"SHA3-224": 3, "SHA3-384": 3, "SHA3-256": 4, "SHA3-512": 3, "SHA-3": 1}}, "BLAKE": {"Blake2": 3}, "MD": {"MD4": {"MD4": 2}, "MD5": {"MD5": 2}}, "RIPEMD": {"RIPEMD": 2}, "PBKDF": {"PBKDF": 7, "PBKDF2": 5}}, "crypto_scheme": {"MAC": {"MAC": 11}, "KA": {"Key Agreement": 3, "Key agreement": 2}}, "crypto_protocol": {"SSH": {"SSH": 17}, "TLS": {"SSL": {"SSL": 3}, "TLS": {"TLS": 36, "TLS v1.2": 3, "TLS v1.3": 2, "TLS 1.2": 3, "TLS 1.3": 5}}}, "randomness": {"PRNG": {"DRBG": 46}, "RNG": {"RNG": 4, "RBG": 2}}, "cipher_mode": {"ECB": {"ECB": 10}, "CBC": {"CBC": 8}, "CTR": {"CTR": 5}, "CFB": {"CFB": 3}, "OFB": {"OFB": 8}, "GCM": {"GCM": 37}, "CCM": {"CCM": 3}, "XEX": {"XEX": 2}, "XTS": {"XTS": 4}}, "ecc_curve": {"NIST": {"P-224": 16, "P-256": 10, "P-384": 10, "P-521": 10, "P-192": 8, "B-233": 5, "B-283": 5, "B-409": 5, "B-571": 5, "K-233": 7, "K-283": 5, "K-409": 5, "K-571": 5, "B-163": 2, "K-163": 4}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {"OpenSSL": {"OpenSSL": 2}}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"ARM": {"ARM TrustZone": 1}, "AMD": {"PSP": 6}, "IBM": {"SSC": 1}, "other": {"TEE": 1}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 20, "FIPS PUB 186-4": 5, "FIPS PUB 198-1": 1, "FIPS PUB 197": 2, "FIPS PUB 202": 1, "FIPS PUB 180-4": 1}, "NIST": {"NIST SP 800-38A": 1, "NIST SP 800-38B": 2, "NIST SP 800-38C": 2, "NIST SP 800-38D": 6, "NIST SP 800-38E": 2, "NIST SP 800-38F": 2, "NIST SP 800-132": 2, "NIST SP 800-67": 2, "SP 800-38A": 1, "SP 800-38B": 1, "NIST SP 800-52": 1}, "PKCS": {"PKCS#1": 3}, "RFC": {"RFC23": 1, "RFC 8446": 1, "RFC 5288": 1, "RFC 5246": 1}, "ISO": {"ISO/IEC 19790": 6, "ISO/IEC 24579": 4, "ISO/IEC 19790:2012": 1, "ISO/IEC 19790:2021": 1}}, "javacard_version": {}, "javacard_api_const": {"curves": {"SM2": 2}}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 787114, "pdf_is_encrypted": false, "pdf_number_of_pages": 41, "/Author": "Corsec Security, Inc.", "/Company": "Corsec Security, Inc.", "/ContentTypeId": "0x0101008CEA64F1FB1D5A4F93ABC4EA3F4AF0B8", "/CreationDate": "D:20250713174533+10'00'", "/Creator": "Acrobat PDFMaker 25 for Word", "/MediaServiceImageTags": "", "/ModDate": "D:20250713174613+10'00'", "/Producer": "Adobe PDF Library 25.1.51", "/SourceModified": "", "/Title": "FIPS 140-3 Non-Proprietary Security Policy", "/_Copyright": "2025", "/_Document Date": "July 7, 2025", "/_Document Version": "0.2", "/_FIPS Security Level": "1", "/_Hardware/Software/Firmware": "software", "/_Module Name (first use)": "FCAT Wallet Vault Cryptographic Module", "/_Module Name (long)": "FCAT Wallet Vault Cryptographic Module", "/_Module Name (short)": "FCAT Wallet Vault Cryptographic Module", "/_Module Version Number": "1.0", "/_Vendor Name (long)": "Fidelity Center for Applied Technology LLC", "/_Vendor Name (short)": "Fidelity", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Validated-Modules/Search", "mailto:info@corsec.com", "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=37589", "http://www.fcatwallet.com/", "http://www.corsec.com/", "http://csrc.nist.gov/groups/STM/cmvp", "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=37588"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["KDF SSHA4978", "AES-GMACA4978", "Counter DRBGA4978", "DSA SigGen (FIPS186-4)A4978", "HMAC-SHA3-256A4978", "SHA2-256A4978", "DSA SigVer (FIPS186-4)A4978", "HMAC-SHA3-384A4978", "RSA KeyGen (FIPS186-4)A4978", "SHA3-224A4978", "ECDSA SigVer (FIPS186-4)A4978", "HMAC-SHA2-512A4978", "SHA3-384A4978", "KAS-FFC-SSC Sp800-56Ar3A4978", "ECDSA KeyGen (FIPS186-4)A4978", "TDES-OFBA4978", "AES-CFB1A4978", "AES-CFB128A4978", "AES-CCMA4978", "TDES-CFB64A4978", "TLS v1.3 KDFA4979", "AES-CFB8A4978", "SHA-1A4978", "ECDSA KeyVer (FIPS186-4)A4978", "SHA3-512A4978", "TDES-CFB8A4978", "KDA HKDF SP800-56Cr2A4978", "HMAC-SHA2-256A4978", "ECDSA SigGen (FIPS186-4)A4978", "SHAKE-128A4978", "HMAC-SHA2-384A4978", "HMAC-SHA3-224A4978", "AES-CBCA4978", "TLS v1.2 KDF RFC7627A4978", "DSA KeyGen (FIPS186-4)A4978", "SHAKE-256A4978", "AES-KWA4978", "AES-CMACA4978", "DSA PQGVer (FIPS186-4)A4978", "AES-GCMA4978", "DSA PQGGen (FIPS186-4)A4978", "HMAC-SHA3-512A4978", "SHA2-384A4978", "SHA2-224A4978", "TDES-ECBA4978", "AES-KWPA4978", "TDES-CFB1A4978", "KAS-ECC-SSC Sp800-56Ar3A4978", "TDES-CBCA4978", "AES-XTSA4978", "RSA SigVer (FIPS186-4)A4978", "AES-CTRA4978", "AES-ECBA4978", "HMAC-SHA-1A4978", "HMAC-SHA2-224A4978", "KDF TLSA4978", "SHA3-256A4978", "SHA2-512A4978", "PBKDFA4978", "AES-OFBA4978", "RSA SigGen (FIPS186-4)A4978", "TDES-CMACA4978"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "5198418629288a817f3db24a247fcc739bf48a416e7a8e39afde7a9cbb835d95", "txt_hash": "6ef3a8332c8473c23265dc4d667bc121a7bd7606582aedd9f5e58dbd842065f6", "json_hash": null}}}