This page was not yet optimized for use on mobile devices.
Datacryptor® 100M Ethernet
Certificate details
| Certificate ID | #3042 |
|---|---|
| Status | historical |
| Historical reason | SP 800-56Arev3 transition |
| Validation dates | 11.10.2017 |
| Standard | FIPS 140-2 |
| Security level | 3 |
| Type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Caveat | When configured as indicated in Section 1 of the Security Policy with the Point-Point license |
| Exceptions |
|
| Description | The Datacryptor® 100 Mbps Ethernet Layer 2 is rack-mountable multi-chip standalone cryptographic modules which facilitate secure data transmission across public Ethernet Layer 2 networks. The Datacryptor® uses 100BaseT ports to connect the host and public sides of the network. The Datacryptor® offers user verification services via ECDSA enabled X.509 v.3 certificates, key management based on a Elliptic Curve Diffie-Hellman key agreement scheme, and AES encryption of data passing over public networks. Management of the Datacryptor® is performed via a remote management interface. |
| Version (Hardware) | 1600x439, Rev. 01 and 1600x439, Rev. 02 |
| Version (Firmware) | 5.0 and 5.1 |
| Vendor | Thales e-Security Inc. |
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES-256, AES, CMACAsymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-HellmanHash functions
SHA-384Schemes
MAC, Key AgreementRandomness
PRNG, DRBG, RNG, RBGElliptic Curves
P-384Vendor
ThalesSecurity level
level 3, Level 3Side-channel analysis
physical probingCross-references
IncomingAutomated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
Loading...
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 3042,
"dgst": "81d566fb189d5318",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"SHS#1808",
"SHS#1764",
"DRBG#188",
"AES#2014",
"ECDSA#304",
"KBKDF#1",
"AES#2062",
"KAS#34",
"AES#2030",
"ECDSA#289"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"5.1",
"5.0"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": {
"_type": "Set",
"elements": [
"2484",
"2472",
"2471"
]
},
"directly_referencing": null,
"indirectly_referenced_by": {
"_type": "Set",
"elements": [
"2472",
"2471",
"3099",
"2484",
"2549"
]
},
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 1
},
"ECDH": {
"ECDH": 14
},
"ECDSA": {
"ECDSA": 17
}
},
"FF": {
"DH": {
"Diffie-Hellman": 12
}
}
},
"certification_process": {},
"cipher_mode": {},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {
"KA": {
"Key Agreement": 1
},
"MAC": {
"MAC": 3
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-384": 8
}
},
"eval_facility": {},
"fips_cert_id": {
"Cert": {
"# 188": 1,
"#1": 1,
"#1764": 1,
"#1808": 1,
"#188": 5,
"#2014": 1,
"#2030": 1,
"#2062": 1,
"#289": 1,
"#304": 1,
"#34": 1
}
},
"fips_certlike": {
"Certlike": {
"AES #2014": 1,
"AES #2030": 1,
"AES #2062": 1,
"AES (256": 5,
"AES-256": 5,
"DRBG #188": 1,
"DRBG (cert # 188": 1,
"DRBG (cert #188": 4,
"SHA-384": 4,
"SHS #1764": 1,
"SHS #1808": 1
}
},
"fips_security_level": {
"Level": {
"Level 3": 2,
"level 3": 1
}
},
"hash_function": {
"SHA": {
"SHA2": {
"SHA-384": 4
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 16,
"PRNG": 1
},
"RNG": {
"RBG": 1,
"RNG": 3
}
},
"side_channel_analysis": {
"SCA": {
"physical probing": 1
}
},
"standard_id": {
"FIPS": {
"FIPS 140-2": 14,
"FIPS140-2": 1
},
"X509": {
"X.509": 9
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 11,
"AES-256": 5
}
},
"constructions": {
"MAC": {
"CMAC": 3
}
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"Thales": {
"Thales": 9
}
},
"vulnerability": {}
},
"policy_metadata": {
"/Author": "",
"/CreationDate": "D:20171004135404-04\u002700\u0027",
"/Creator": "Acrobat PDFMaker 11 for Word",
"/Keywords": "",
"/ModDate": "D:20171004135437-04\u002700\u0027",
"/Producer": "Adobe PDF Library 11.0",
"/SourceModified": "D:20171004174612",
"/Subject": "",
"/Title": "",
"pdf_file_size_bytes": 287749,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"http://iss.thalesgroup.com/",
"http://www.nist.gov/cvmp",
"http://www.nist.gov/cmvp"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 25
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "afa8622946463fe0e5a7ca6e4d3e1dd708831ad1e8c11c875f100b6092c78106",
"txt_hash": "9d99580f898b936c202f42edd56ca8f32ec04afdb412374797936c1495702cbe"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When configured as indicated in Section 1 of the Security Policy with the Point-Point license",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertOct2017.pdf",
"date_sunset": null,
"description": "The Datacryptor\u00ae 100 Mbps Ethernet Layer 2 is rack-mountable multi-chip standalone cryptographic modules which facilitate secure data transmission across public Ethernet Layer 2 networks. The Datacryptor\u00ae uses 100BaseT ports to connect the host and public sides of the network. The Datacryptor\u00ae offers user verification services via ECDSA enabled X.509 v.3 certificates, key management based on a Elliptic Curve Diffie-Hellman key agreement scheme, and AES encryption of data passing over public networks. Management of the Datacryptor\u00ae is performed via a remote management interface.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Mitigation of Other Attacks: N/A"
],
"fw_versions": "5.0 and 5.1",
"historical_reason": "SP 800-56Arev3 transition",
"hw_versions": "1600x439, Rev. 01 and 1600x439, Rev. 02",
"level": 3,
"mentioned_certs": {},
"module_name": "Datacryptor\u00ae 100M Ethernet",
"module_type": "Hardware",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "historical",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2017-10-11",
"lab": "COACT INC CAFE LAB",
"validation_type": "Initial"
}
],
"vendor": "Thales e-Security Inc.",
"vendor_url": "http://www.thalesesecurity.com"
}
}