ID-One PIV 2.4 on Cosmo V8.2 NPIVP & CIV Configurations

Certificate #3863

Webpage information

Status active
Validation dates 24.03.2021
Sunset date 23-03-2026
Standard FIPS 140-2
Security level 2
Type Hardware
Embodiment Single Chip
Caveat When operated in FIPS mode and initialized to Overall Level 2 per Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy
Exceptions
  • Roles, Services, and Authentication: Level 3
  • Physical Security: Level 4
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
Description ID-One PIV 2.4 on Cosmo V8.2, is a dual interface smartcard chip (ISO 7816 & ISO 14443) that contains a Personal Identity Verification (PIV) application with On-Card-Fingerprints-Comparison that can be configured to strictly comply with NIST FIPS 201-2 Standard for US Government Federal Employees and Contractors (NPIVP configuration), or support enhanced functionalities (ANSI 504), and additional access conditions (SO_PIN), as well as stronger cryptography (ECC P521) while maintaining backward compatibility with NPIVP, to address Civilian markets worldwide (CIV configuration).
Version (Hardware) P/N ‘30’
Version (Firmware) ['6F01' with ID-One PIV Applet 2.4.2 NPIVP configuration] and ['6F01' with ID-One PIV Applet 2.4.2 CIV configuration]
Vendor IDEMIA
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, AES-256, AES-192, AES-, DES, TDEA, Triple-DES, HMAC, CMAC
Asymmetric Algorithms
RSA 2048, RSA-2048, RSA-CRT, ECDSA, ECC
Hash functions
SHA-256, SHA-384, SHA-224, SHA-512, SHA-3, SHA3-512
Schemes
MAC, Key Agreement
Randomness
DRBG, RNG
Elliptic Curves
P-224, P-384, P-256, P-521
Block cipher modes
ECB, CBC, CTR

JavaCard versions
Java Card 3.0.4
Vendor
IDEMIA, Microsoft

Security level
Level 2
Side-channel analysis
Side-channel, side-channel, DPA, SPA, DFA

Standards
FIPS 140-2, FIPS201-2, FIPS140-2, FIPS PUB 140-2, FIPS 113, FIPS 197, FIPS 186-4, FIPS 180-4, FIPS 198-1, FIPS 202, FIPS 201-2, PKCS#1, PKCS #1, AIS 31, ISO/IEC 24787: 2010

File metadata

Subject FIPS 140-2 Security Policy Template
Author sweymann
Creation date D:20201228163820-08'00'
Modification date D:20201228163835-08'00'
Pages 23
Creator Acrobat PDFMaker 17 for Word
Producer Adobe PDF Library 15.0

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3863,
  "dgst": "5c3d91e81ae54157",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "ECDSA#C990",
        "KTS#C989",
        "CVL#C984",
        "AES#C982",
        "KBKDF#C995",
        "SHS#C980",
        "CVL#C986",
        "RSA#C994",
        "DRBG#C987",
        "AES#C989",
        "Triple-DES#C981",
        "SHS#C978",
        "CVL#C991",
        "KTS#C982"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "8.2",
        "2.4",
        "2.4.2"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 18
          },
          "ECDSA": {
            "ECDSA": 4
          }
        },
        "RSA": {
          "RSA 2048": 6,
          "RSA-2048": 12,
          "RSA-CRT": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 6
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "MAC": {
          "MAC": 3
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 30,
          "P-256": 28,
          "P-384": 32,
          "P-521": 26
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES CMAC 128": 1,
          "AES- 128": 1,
          "AES- 256": 1,
          "AES-128": 11,
          "AES-192": 5,
          "AES-256": 14,
          "HMAC SHA-256": 1,
          "PKCS #1": 2,
          "PKCS#1": 2,
          "RSA 2048": 6,
          "SHA- 256": 2,
          "SHA- 512": 1,
          "SHA-224": 3,
          "SHA-256": 7,
          "SHA-3": 4,
          "SHA-384": 4,
          "SHA-512": 3,
          "SHA3-512": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 3
        }
      },
      "hash_function": {
        "SHA": {
          "SHA2": {
            "SHA-224": 3,
            "SHA-256": 7,
            "SHA-384": 4,
            "SHA-512": 3
          },
          "SHA3": {
            "SHA-3": 4,
            "SHA3-512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {
        "JavaCard": {
          "Java Card 3.0.4": 3
        }
      },
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 10
        },
        "RNG": {
          "RNG": 3
        }
      },
      "side_channel_analysis": {
        "FI": {
          "DFA": 1
        },
        "SCA": {
          "DPA": 1,
          "SPA": 1,
          "Side-channel": 1,
          "side-channel": 1
        }
      },
      "standard_id": {
        "BSI": {
          "AIS 31": 1
        },
        "FIPS": {
          "FIPS 113": 1,
          "FIPS 140-2": 10,
          "FIPS 180-4": 3,
          "FIPS 186-4": 5,
          "FIPS 197": 2,
          "FIPS 198-1": 2,
          "FIPS 201-2": 1,
          "FIPS 202": 2,
          "FIPS PUB 140-2": 1,
          "FIPS140-2": 2,
          "FIPS201-2": 1
        },
        "ISO": {
          "ISO/IEC 24787: 2010": 1
        },
        "PKCS": {
          "PKCS #1": 1,
          "PKCS#1": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 19,
            "AES-": 2,
            "AES-128": 11,
            "AES-192": 5,
            "AES-256": 14
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 3,
            "Triple-DES": 10
          },
          "DES": {
            "DES": 3
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 14,
            "HMAC": 6
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Idemia": {
          "IDEMIA": 27
        },
        "Microsoft": {
          "Microsoft": 1
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "sweymann",
      "/Company": "Microsoft",
      "/CreationDate": "D:20201228163820-08\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 17 for Word",
      "/Keywords": "",
      "/MSIP_Label_431684b1-a5da-4051-9fb4-5631703e02d5_ActionId": "b3153660-0f55-4fb7-ab75-96fe47c5a641",
      "/MSIP_Label_431684b1-a5da-4051-9fb4-5631703e02d5_Application": "Microsoft Azure Information Protection",
      "/MSIP_Label_431684b1-a5da-4051-9fb4-5631703e02d5_Enabled": "True",
      "/MSIP_Label_431684b1-a5da-4051-9fb4-5631703e02d5_Extended_MSFT_Method": "Automatic",
      "/MSIP_Label_431684b1-a5da-4051-9fb4-5631703e02d5_Name": "Public",
      "/MSIP_Label_431684b1-a5da-4051-9fb4-5631703e02d5_Owner": "[email protected]",
      "/MSIP_Label_431684b1-a5da-4051-9fb4-5631703e02d5_SetDate": "2019-08-30T14:58:24.1935855Z",
      "/MSIP_Label_431684b1-a5da-4051-9fb4-5631703e02d5_SiteId": "7694d41c-5504-43d9-9e40-cb254ad755ec",
      "/ModDate": "D:20201228163835-08\u002700\u0027",
      "/Producer": "Adobe PDF Library 15.0",
      "/SourceModified": "D:20201229003748",
      "/Subject": "FIPS 140-2 Security Policy Template",
      "/Title": "",
      "pdf_file_size_bytes": 609085,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31385",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31380",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31391",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31383",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31377",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31382",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31376",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31381",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31387",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31384",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31379",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31388",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31386",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31392",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31378",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31692",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31375"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 23
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "163bdeb8488b55c748c944394c9c789b8dd1151fae1b5ebe79e43e0a503c4b23",
    "policy_txt_hash": "960469ac89cf3eb4e953513779c8e28fd787fdcca6067740520889991154948f"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and initialized to Overall Level 2 per Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/March 2021_010421_0724_signed.pdf",
    "date_sunset": "2026-03-23",
    "description": "ID-One PIV 2.4 on Cosmo V8.2, is a dual interface smartcard chip (ISO 7816 \u0026 ISO 14443) that contains a Personal Identity Verification (PIV) application with On-Card-Fingerprints-Comparison that can be configured to strictly comply with NIST FIPS 201-2 Standard for US Government Federal Employees and Contractors (NPIVP configuration), or support enhanced functionalities (ANSI 504), and additional access conditions (SO_PIN), as well as stronger cryptography (ECC P521) while maintaining backward compatibility with NPIVP, to address Civilian markets worldwide (CIV configuration).",
    "embodiment": "Single Chip",
    "exceptions": [
      "Roles, Services, and Authentication: Level 3",
      "Physical Security: Level 4",
      "EMI/EMC: Level 3",
      "Design Assurance: Level 3"
    ],
    "fw_versions": "[\u00276F01\u0027 with ID-One PIV Applet 2.4.2 NPIVP configuration] and [\u00276F01\u0027 with ID-One PIV Applet 2.4.2 CIV configuration]",
    "historical_reason": null,
    "hw_versions": "P/N \u201830\u2019",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "ID-One PIV 2.4 on Cosmo V8.2 NPIVP \u0026 CIV Configurations",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-03-24",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "IDEMIA",
    "vendor_url": "http://www.idemia.com"
  }
}