Datacryptor® 100M Ethernet

Certificate details

Certificate ID #3042
Status historical
Historical reason SP 800-56Arev3 transition
Validation dates 11.10.2017
Standard FIPS 140-2
Security level 3
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When configured as indicated in Section 1 of the Security Policy with the Point-Point license
Exceptions
  • Mitigation of Other Attacks: N/A
Description The Datacryptor® 100 Mbps Ethernet Layer 2 is rack-mountable multi-chip standalone cryptographic modules which facilitate secure data transmission across public Ethernet Layer 2 networks. The Datacryptor® uses 100BaseT ports to connect the host and public sides of the network. The Datacryptor® offers user verification services via ECDSA enabled X.509 v.3 certificates, key management based on a Elliptic Curve Diffie-Hellman key agreement scheme, and AES encryption of data passing over public networks. Management of the Datacryptor® is performed via a remote management interface.
Version (Hardware) 1600x439, Rev. 01 and 1600x439, Rev. 02
Version (Firmware) 5.0 and 5.1
Vendor Thales e-Security Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-256, AES, CMAC
Asymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-Hellman
Hash functions
SHA-384
Schemes
MAC, Key Agreement
Randomness
PRNG, DRBG, RNG, RBG
Elliptic Curves
P-384

Vendor
Thales

Security level
level 3, Level 3
Side-channel analysis
physical probing

Standards
FIPS140-2, FIPS 140-2, X.509

Cross-references

Incoming
  • 2471 - historical - SUSE Linux Enterprise Server 12 - OpenSSH Server Module
  • 2484 - historical - SUSE Linux Enterprise Server 12 - StrongSwan Cryptographic Module
  • 2472 - historical - SUSE Linux Enterprise Server 12 - OpenSSH Client Module

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

Loading...

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3042,
  "dgst": "81d566fb189d5318",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHS#1808",
        "SHS#1764",
        "DRBG#188",
        "AES#2014",
        "ECDSA#304",
        "KBKDF#1",
        "AES#2062",
        "KAS#34",
        "AES#2030",
        "ECDSA#289"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "5.1",
        "5.0"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2484",
          "2472",
          "2471"
        ]
      },
      "directly_referencing": null,
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2472",
          "2471",
          "3099",
          "2484",
          "2549"
        ]
      },
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDH": {
            "ECDH": 14
          },
          "ECDSA": {
            "ECDSA": 17
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 12
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1
        },
        "MAC": {
          "MAC": 3
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-384": 8
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "# 188": 1,
          "#1": 1,
          "#1764": 1,
          "#1808": 1,
          "#188": 5,
          "#2014": 1,
          "#2030": 1,
          "#2062": 1,
          "#289": 1,
          "#304": 1,
          "#34": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES #2014": 1,
          "AES #2030": 1,
          "AES #2062": 1,
          "AES (256": 5,
          "AES-256": 5,
          "DRBG #188": 1,
          "DRBG (cert # 188": 1,
          "DRBG (cert #188": 4,
          "SHA-384": 4,
          "SHS #1764": 1,
          "SHS #1808": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 3": 2,
          "level 3": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA2": {
            "SHA-384": 4
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 16,
          "PRNG": 1
        },
        "RNG": {
          "RBG": 1,
          "RNG": 3
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "physical probing": 1
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 14,
          "FIPS140-2": 1
        },
        "X509": {
          "X.509": 9
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 11,
            "AES-256": 5
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 3
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Thales": {
          "Thales": 9
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "",
      "/CreationDate": "D:20171004135404-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 11 for Word",
      "/Keywords": "",
      "/ModDate": "D:20171004135437-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 11.0",
      "/SourceModified": "D:20171004174612",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 287749,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://iss.thalesgroup.com/",
          "http://www.nist.gov/cvmp",
          "http://www.nist.gov/cmvp"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 25
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "afa8622946463fe0e5a7ca6e4d3e1dd708831ad1e8c11c875f100b6092c78106",
      "txt_hash": "9d99580f898b936c202f42edd56ca8f32ec04afdb412374797936c1495702cbe"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When configured as indicated in Section 1 of the Security Policy with the Point-Point license",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertOct2017.pdf",
    "date_sunset": null,
    "description": "The Datacryptor\u00ae 100 Mbps Ethernet Layer 2 is rack-mountable multi-chip standalone cryptographic modules which facilitate secure data transmission across public Ethernet Layer 2 networks. The Datacryptor\u00ae uses 100BaseT ports to connect the host and public sides of the network. The Datacryptor\u00ae offers user verification services via ECDSA enabled X.509 v.3 certificates, key management based on a Elliptic Curve Diffie-Hellman key agreement scheme, and AES encryption of data passing over public networks. Management of the Datacryptor\u00ae is performed via a remote management interface.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "5.0 and 5.1",
    "historical_reason": "SP 800-56Arev3 transition",
    "hw_versions": "1600x439, Rev. 01 and 1600x439, Rev. 02",
    "level": 3,
    "mentioned_certs": {},
    "module_name": "Datacryptor\u00ae 100M Ethernet",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-10-11",
        "lab": "COACT INC CAFE LAB",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Thales e-Security Inc.",
    "vendor_url": "http://www.thalesesecurity.com"
  }
}