X4i Hardware Security Module (HSM)

Certificate #4225

Webpage information

Status active
Validation dates 12.05.2022
Sunset date 21-09-2026
Standard FIPS 140-2
Security level 3
Type Hardware
Embodiment Single Chip
Caveat When operated in FIPS Mode. No assurance of the minimum strength of generated keys.
Description The X4i HSM is a single chip cryptographic module using the Maxim MAX32590 hardware. The central purpose of the module is as a physical computing device that safeguards and manages cryptographic keys and provides cryptographic services to connected host devices.
Version (Hardware) MAX32590 Secure Microcontroller Revision B4
Version (Firmware) PB Bootloader Version 00.00.0016, HSM Application Version 21.04.0008, and Device Abstraction Layer (DAL) Version 01.02.002F
Vendor Pitney Bowes, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-256, DES, Triple-DES, TDES, HMAC, HMAC-SHA-256
Asymmetric Algorithms
RSA 2048, ECDH, ECDSA, ECC, DH, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA-256, SHA-224
Schemes
MAC, Key Agreement
Randomness
TRNG, DRBG
Elliptic Curves
P-256, P-224, P-192, P-160
Block cipher modes
ECB, CBC

Trusted Execution Environments
PSP, SSC

Security level
Level 3, Level 1, Level 4

Standards
FIPS 140-2, FIPS 197, FIPS 186-4, FIPS 198-1, FIPS 180-4, FIPS PUB 186-4, FIPS PUB 197, FIPS PUB 198-1, FIPS PUB 180-4, FIPS PUB 140-2, SP 800-63B, SP 800-38A, SP 800-90A, SP 800-38F, PKCS 1

File metadata

Author Aryeh
Creation date D:20220428095848-07'00'
Modification date D:20220428095915-07'00'
Pages 24
Creator Acrobat PDFMaker 22 for Word
Producer Adobe PDF Library 22.1.149

References

Outgoing
  • 2900 - historical - SAP CommonCryptoLib Crypto Kernel

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4225,
  "dgst": "36a02b1565e32306",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC#C464",
        "DRBG#C472",
        "KTS#C464",
        "KAS-SSC#A1869",
        "RSA#C477",
        "KDA#A1869",
        "AES#5954",
        "KTS#5954",
        "ECDSA#C476",
        "SHS#C295",
        "KAS#A1869"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "00.00.0016",
        "21.04.0008",
        "01.02.002"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "2900"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "2900"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "2900"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 6
          },
          "ECDH": {
            "ECDH": 2
          },
          "ECDSA": {
            "ECDSA": 32
          }
        },
        "FF": {
          "DH": {
            "DH": 5,
            "Diffie-Hellman": 2
          },
          "DSA": {
            "DSA": 4
          }
        },
        "RSA": {
          "RSA 2048": 20
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "ECB": {
          "ECB": 4
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 3
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-160": 3,
          "P-192": 9,
          "P-224": 8,
          "P-256": 40
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#2900": 1,
          "#5954": 8
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES (Cert. #5954": 1,
          "AES 128/192/256": 15,
          "AES 256": 2,
          "AES CBC 128, 192": 1,
          "AES CBC 256": 2,
          "AES Cert. #5954": 2,
          "AES-256": 4,
          "HMAC-SHA- 2568": 2,
          "HMAC-SHA-1": 4,
          "HMAC-SHA-256": 62,
          "HMAC-SHA-256 256": 2,
          "PKCS 1": 10,
          "RSA 2048": 20,
          "SHA-1": 16,
          "SHA-224": 1,
          "SHA-256": 12
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 3": 6,
          "Level 4": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 16
          },
          "SHA2": {
            "SHA-224": 1,
            "SHA-256": 12
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 49
        },
        "TRNG": {
          "TRNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 9,
          "FIPS 180-4": 1,
          "FIPS 186-4": 2,
          "FIPS 197": 1,
          "FIPS 198-1": 1,
          "FIPS PUB 140-2": 11,
          "FIPS PUB 180-4": 1,
          "FIPS PUB 186-4": 1,
          "FIPS PUB 197": 1,
          "FIPS PUB 198-1": 1
        },
        "NIST": {
          "SP 800-38A": 1,
          "SP 800-38F": 3,
          "SP 800-63B": 1,
          "SP 800-90A": 1
        },
        "PKCS": {
          "PKCS 1": 5
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 50,
            "AES-256": 4
          }
        },
        "DES": {
          "3DES": {
            "TDES": 1,
            "Triple-DES": 2
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 15,
            "HMAC-SHA-256": 32
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 5
        },
        "IBM": {
          "SSC": 1
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Aryeh",
      "/Comments": "",
      "/Company": "",
      "/ContentTypeId": "0x010100F9FA04D8D4CFB14CB50F7594BF09F976",
      "/CreationDate": "D:20220428095848-07\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 22 for Word",
      "/Keywords": "",
      "/ModDate": "D:20220428095915-07\u002700\u0027",
      "/Producer": "Adobe PDF Library 22.1.149",
      "/SourceModified": "D:20220428165405",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 799130,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=10836",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=10823",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=10831",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=10347",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=10835",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=10655"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 24
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "aeafe9549b3feba9db7d7501bb814001117c8710b5499554524ff18bfa27a0a1",
    "policy_txt_hash": "21df1efd39c242610283d38e115429c817f98d9fa233bbcccee7c983cb0f029a"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS Mode. No assurance of the minimum strength of generated keys.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/May 2022_010622_0641_signed.pdf",
    "date_sunset": "2026-09-21",
    "description": "The X4i HSM is a single chip cryptographic module using the Maxim MAX32590 hardware. The central purpose of the module is as a physical computing device that safeguards and manages cryptographic keys and provides cryptographic services to connected host devices.",
    "embodiment": "Single Chip",
    "exceptions": null,
    "fw_versions": "PB Bootloader Version 00.00.0016, HSM Application Version 21.04.0008, and Device Abstraction Layer (DAL) Version 01.02.002F",
    "historical_reason": null,
    "hw_versions": "MAX32590 Secure Microcontroller Revision B4",
    "level": 3,
    "mentioned_certs": {},
    "module_name": "X4i Hardware Security Module (HSM)",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2022-05-12",
        "lab": "Penumbra Security, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Pitney Bowes, Inc.",
    "vendor_url": "http://www.pb.com"
  }
}