HID Global ActivID Applet 2.7.7 & 2.7.8 on Thales IDCore 3230 Platform

Certificate details

Certificate ID #5028
Status active
Validation dates 18.06.2025
Sunset date 17-06-2030
Standard FIPS 140-3
Security level 2
Type Hardware
Embodiment Single Chip
Caveat None
Exceptions
  • Roles, services, and authentication: Level 3
  • Operational environment: N/A
  • Physical security: Level 3
  • Non-invasive security: N/A
  • Life-cycle assurance: Level 3
  • Mitigation of other attacks: N/A
Description HID Global ActivID Applet 2.7.7 & 2.7.8 on Thales IDCore 3230 Platform cryptographic module, validated to FIPS 140-3 overall Level 2, is a single-chip “contact and contactless” module implementing the Global Platform operational environment, with Card Manager as well as the ActivID Applet Suite.
Vendor HID Global http://www.hidglobal.com/
Lab Leidos Accredited Testing & Evaluation (AT&E) Lab
Algorithms
  • AES-CBCA2877
  • AES-CMACA2877
  • AES-ECBA2877
  • Counter DRBGA2877
  • ECDSA KeyGen (FIPS186-5)A2877
  • KAS-ECC Sp800-56Ar3A2877
  • KDF SP800-108A2877
  • KTS-IFCA2877
  • RSA KeyGen (FIPS186-5)A2877
  • RSA SigGen (FIPS186-5)A2877
  • RSA SigVer (FIPS186-5)A2877
  • SHA2-224A2877
  • SHA2-256A2877
  • SHA2-384A2877
  • SHA2-512A2877
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-256, AES, AES-, CAST, CMAC
Asymmetric Algorithms
RSA 2048, ECDSA, ECC, DH
Hash functions
SHA2
Schemes
MAC, Key Agreement
Randomness
TRNG, DRBG, RBG
Elliptic Curves
P-224, P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR

JavaCard versions
Java Card 3.1.0
Trusted Execution Environments
PSP
Vendor
Infineon, Thales

Security level
Level 2, level 3

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5028,
  "dgst": "95476eb48784279d",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256A2877",
        "KDF SP800-108A2877",
        "#A2877",
        "AES-CBCA2877",
        "AES-CMACA2877",
        "Counter DRBGA2877",
        "SHA2-384A2877",
        "ECDSA KeyGen (FIPS186-5)A2877",
        "AES-ECBA2877",
        "RSA SigVer (FIPS186-5)A2877",
        "RSA KeyGen (FIPS186-5)A2877",
        "SHA2-512A2877",
        "RSA SigGen (FIPS186-5)A2877",
        "KTS-IFCA2877",
        "SHA2-224A2877",
        "KAS-ECC Sp800-56Ar3A2877"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "2.7.8",
        "2.7.7"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 9
          },
          "ECDSA": {
            "ECDSA": 5
          }
        },
        "FF": {
          "DH": {
            "DH": 1
          }
        },
        "RSA": {
          "RSA 2048": 2
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 6
        },
        "MAC": {
          "MAC": 5
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 4,
          "P-256": 10,
          "P-384": 2,
          "P-521": 2
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 2,
          "#2": 2
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 128": 7,
          "AES- 128/192/256": 4,
          "AES-128/192/256": 1,
          "AES-128/192/256 key 128, 192": 1,
          "AES-256": 1,
          "PKCS#1": 2,
          "RSA 2048": 2,
          "RSA PKCS#1": 2,
          "SHA2 256": 1,
          "SHA2 512": 1,
          "SHA2-224": 2,
          "SHA2-256": 4,
          "SHA2-384": 2,
          "SHA2-512": 4
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 3,
          "level 3": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA2": {
            "SHA2": 2
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {
        "JavaCard": {
          "Java Card 3.1.0": 2
        }
      },
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 21
        },
        "RNG": {
          "RBG": 2
        },
        "TRNG": {
          "TRNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 10,
          "FIPS 180-4": 4,
          "FIPS 186-5": 4,
          "FIPS186-5": 17
        },
        "NIST": {
          "SP 800-108": 1,
          "SP 800-38A": 2,
          "SP 800-38B": 1,
          "SP 800-56A": 1,
          "SP 800-56B": 1,
          "SP 800-63B": 3,
          "SP 800-90A": 1,
          "SP 800-90B": 5
        },
        "PKCS": {
          "PKCS#1": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 24,
            "AES-": 5,
            "AES-256": 1
          },
          "CAST": {
            "CAST": 32
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 4
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 6
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "Infineon": {
          "Infineon": 4
        },
        "Thales": {
          "Thales": 49
        }
      },
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256A2877",
        "KDF SP800-108A2877",
        "AES-CBCA2877",
        "AES-CMACA2877",
        "Counter DRBGA2877",
        "SHA2-384A2877",
        "ECDSA KeyGen (FIPS186-5)A2877",
        "AES-ECBA2877",
        "RSA SigVer (FIPS186-5)A2877",
        "RSA KeyGen (FIPS186-5)A2877",
        "SHA2-512A2877",
        "RSA SigGen (FIPS186-5)A2877",
        "KTS-IFCA2877",
        "SHA2-224A2877",
        "KAS-ECC Sp800-56Ar3A2877"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A2877"
      ]
    },
    "policy_metadata": {
      "/Author": "Hawes, David J. (Fed)",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20250609082737-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_ActionId": "416e1c5e-846b-436e-b098-bf5bea59f662",
      "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_ContentBits": "0",
      "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_Enabled": "true",
      "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_Method": "Privileged",
      "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_Name": "Unrestricted",
      "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_SetDate": "2024-05-07T17:40:55Z",
      "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_SiteId": "b64da4ac-e800-4cfc-8931-e607f720a1b8",
      "/ModDate": "D:20250609082825-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.208",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 675729,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://supportportal.thalesgroup.com/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 37
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "57951ddfdfc100b22e866031382fa713041e8f8cfecae76b2b64b4cc340648e3",
      "source_hash": "87fe26f05c9ba8a1998fa244703f3d7ce10ed6dd92e5825a4d509638274ed459",
      "txt_hash": "7267f021614c883f66874dc0a636dbca04f61601be165ef38409ba1576fb925b"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "None",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/June 2025_080725_0749.pdf",
    "date_sunset": "2030-06-17",
    "description": "HID Global ActivID Applet 2.7.7 \u0026 2.7.8 on Thales IDCore 3230 Platform cryptographic module, validated to FIPS 140-3 overall Level 2, is a single-chip \u201ccontact and contactless\u201d module implementing the Global Platform operational environment, with Card Manager as well as the ActivID Applet Suite.",
    "embodiment": "Single Chip",
    "exceptions": [
      "Roles, services, and authentication: Level 3",
      "Operational environment: N/A",
      "Physical security: Level 3",
      "Non-invasive security: N/A",
      "Life-cycle assurance: Level 3",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 2,
    "mentioned_certs": {},
    "module_name": "HID Global ActivID Applet 2.7.7 \u0026 2.7.8 on Thales IDCore 3230 Platform",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-06-18",
        "lab": "Leidos Accredited Testing \u0026 Evaluation (AT\u0026E) Lab",
        "validation_type": "Initial"
      }
    ],
    "vendor": "HID Global",
    "vendor_url": "http://www.hidglobal.com/"
  }
}