HiPKI SafGuard 2000 HSM

Certificate details

Certificate ID #5511
Status active
Validation dates 02.09.2026
Sunset date 01-09-2031
Standard FIPS 140-3
Security level 3
Type Hardware
Embodiment MultiChipStand
Caveat The tamper evident seals and external entropy source installed as indicated in the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys).
Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Chunghwa Telecom Laboratories HiPKI SafGuard 2000 HSM is a hardware cryptographic module provides FIPS 140-3 approved cryptographic services used in PKI system.
Vendor Chunghwa Telecom laboratories
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-128, CAST, HMAC
Asymmetric Algorithms
RSA 2048, RSA-2048, RSA-OAEP, ECDSA
Schemes
MAC
Randomness
DRBG, RBG
Elliptic Curves
P-224, P-256, P-384, P-521
Block cipher modes
ECB, CBC

JavaCard packages
com.tw
Trusted Execution Environments
PSP

Security level
Level 3, Level 1, level 3

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5511,
  "dgst": "8798b848ede7e47c",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "ECDSA SigGen (FIPS186-4)A2894",
        "HMAC-SHA2-256A2892",
        "AES-KWA2894",
        "AES-KWPA2894",
        "AES-ECBA2892",
        "ECDSA SigVer (FIPS186-4)A2894",
        "SHA2-256A2892",
        "AES-CBCA2892",
        "RSA KeyGen (FIPS186-4)A2894",
        "RSA SigGen (FIPS186-4)A2894",
        "ECDSA KeyVer (FIPS186-4)A2894",
        "KTS-IFCA2894",
        "ECDSA KeyGen (FIPS186-4)A2894",
        "RSA SigVer (FIPS186-4)A2894",
        "HMAC DRBGA2894"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "2000"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 24
          }
        },
        "RSA": {
          "RSA 2048": 3,
          "RSA-2048": 2,
          "RSA-OAEP": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "ECB": {
          "ECB": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 6,
          "P-256": 10,
          "P-384": 6,
          "P-521": 6
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "# A2892": 1,
          "- PKCS 1": 1,
          "AES 128": 1,
          "AES-128": 3,
          "DRBG 256": 1,
          "PKCS 1": 1,
          "RSA 2048": 3,
          "SHA2-256": 10
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 3": 2,
          "level 3": 2
        }
      },
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {
        "com": {
          "com.tw": 1
        }
      },
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 27
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 10,
          "FIPS 180-4": 1,
          "FIPS 186-4": 5,
          "FIPS 198-1": 1,
          "FIPS186-4": 35
        },
        "NIST": {
          "NIST SP 800-131A": 1,
          "SP 800-131A": 1,
          "SP 800-38A": 1,
          "SP 800-38D": 1,
          "SP 800-38F": 2,
          "SP 800-56B": 1,
          "SP 800-90A": 1
        },
        "PKCS": {
          "PKCS 1": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 10,
            "AES-128": 3
          },
          "CAST": {
            "CAST": 20
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 16
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 7
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/CreationDate": "D:20260828072151-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20260828072151-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 573260,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.chttl.com.tw/",
          "https://csrc.nist.gov/projects/cryptographic-module-validation-program"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 26
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "f3e0c6286e32033252d1372e6ca8ffb425e953b07cdca53cae1335ebea3b0855",
      "txt_hash": "07f1ac2c4a715c52bad8504807beb538af79a76c1e864519bb9c05c58175edeb"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "The tamper evident seals and external entropy source installed as indicated in the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys).",
    "certificate_pdf_url": null,
    "date_sunset": "2031-09-01",
    "description": "The Chunghwa Telecom Laboratories HiPKI SafGuard 2000 HSM is a hardware cryptographic module provides FIPS 140-3 approved cryptographic services used in PKI system.",
    "embodiment": "MultiChipStand",
    "exceptions": [
      "Operational environment: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 3,
    "mentioned_certs": {},
    "module_name": "HiPKI SafGuard 2000 HSM",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-09-02",
        "lab": "Asia Pacific IT Laboratory, TUV NORD",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Chunghwa Telecom laboratories",
    "vendor_url": "https://www.chttl.com.tw/en/index.html"
  }
}