Treasure Cryptographic Module

Certificate #3672

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 18.06.2020 , 26.06.2020 , 21.05.2021
Standard FIPS 140-2
Security level 1
Type Software-Hybrid
Embodiment Multi-Chip Stand Alone
Caveat When installed, initialized and configured as specified in Sections 5.2 and 11 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy
Exceptions
  • Mitigation of Other Attacks: N/A
Description The Treasure Cryptographic Module is the cryptographic component of Treasure's Treasure Vault product, which provides HSM-grade security for managing cryptographic keys and protecting sensitive data. This solution leverages on Intel ® SGX technology and allows enterprises to protect data at all states: at rest, in motion and in use
Version (Hardware) Intel Core i7-6600U
Tested configurations
  • Ubuntu 18.04 LTS running on a Lenovo Thinkpad T460s with an Intel Core i7-6600U (single-user mode)
Vendor Treasure Cloud Pte.Ltd
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, HMAC, HMAC-SHA-224, HMAC-SHA-256, HMAC-SHA-512
Asymmetric Algorithms
ECDSA, ECC
Hash functions
SHA-1, SHA-224, SHA-384, SHA-512, SHA-256, SHA-2
Schemes
MAC
Randomness
DRBG
Libraries
OpenSSL
Elliptic Curves
P-224, P-256, P-384, P-521, P-512
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM

Trusted Execution Environments
SGX, Intel SGX

Security level
level 1, Level 1

Standards
FIPS 140-2, FIPS 186-4, FIPS 186-2, FIPS 197, FIPS 198, FIPS 180-4, SP 800-38C, SP 800-38D, SP 800-90, SP 800-133, SP 800-90A

File metadata

Title Treasure Cryptographic Module FIPS 140-2 Security Policy
Subject Treasure Cloud Pte Ltd.
Author Prepared by jtsec Beyond IT Security S.L.
Creation date D:20210421104101+08'00'
Modification date D:20210421104101+08'00'
Pages 23
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3672,
  "dgst": "9e40f86360ba8c10",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "ECDSA#C608",
        "HMAC#C608",
        "AES#C608",
        "DRBG#C608",
        "SHS#C608",
        "RSA#C608"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 2
          },
          "ECDSA": {
            "ECDSA": 8
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "CCM": {
          "CCM": 2
        },
        "CFB": {
          "CFB": 2
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 3
        },
        "GCM": {
          "GCM": 3
        },
        "OFB": {
          "OFB": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 4
        }
      },
      "crypto_protocol": {},
      "crypto_scheme": {
        "MAC": {
          "MAC": 2
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 8,
          "P-256": 8,
          "P-384": 8,
          "P-512": 1,
          "P-521": 6
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "HMAC SHA-1": 1,
          "HMAC-SHA- 384": 2,
          "HMAC-SHA-1": 4,
          "HMAC-SHA-224": 2,
          "HMAC-SHA-256": 2,
          "HMAC-SHA-512": 2,
          "HMAC-SHA1": 2,
          "RSA2": 1,
          "SHA- 512": 4,
          "SHA-1": 6,
          "SHA-2": 1,
          "SHA-224": 13,
          "SHA-256": 13,
          "SHA-384": 14,
          "SHA-512": 11
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "level 1": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 6
          },
          "SHA2": {
            "SHA-2": 1,
            "SHA-224": 13,
            "SHA-256": 13,
            "SHA-384": 14,
            "SHA-512": 11
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 12
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 37,
          "FIPS 180-4": 1,
          "FIPS 186-2": 1,
          "FIPS 186-4": 2,
          "FIPS 197": 1,
          "FIPS 198": 1
        },
        "NIST": {
          "SP 800-133": 1,
          "SP 800-38C": 1,
          "SP 800-38D": 1,
          "SP 800-90": 1,
          "SP 800-90A": 5
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 14
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 10,
            "HMAC-SHA-224": 1,
            "HMAC-SHA-256": 1,
            "HMAC-SHA-512": 1
          }
        }
      },
      "tee_name": {
        "Intel": {
          "Intel SGX": 6,
          "SGX": 17
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Prepared by jtsec Beyond IT Security S.L.",
      "/CreationDate": "D:20210421104101+08\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20210421104101+08\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "/Subject": "Treasure Cloud Pte Ltd.",
      "/Title": "Treasure Cryptographic Module FIPS 140-2 Security Policy",
      "pdf_file_size_bytes": 596009,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://github.com/01org/linux-sgx",
          "http://www.boost.org/",
          "https://github.com/01org/linux-sgx-driver"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 23
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "8ef5948ed8ac9cad93b860cd952469e5236f278b9ce4c09145a1cd74bf42f203",
    "policy_txt_hash": "90597c2041b7206421e7e6f2d019f34e48bf64ca948f2b619821e09eaa903f6d"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When installed, initialized and configured as specified in Sections 5.2 and 11 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/June 2020_010720_0752.pdf",
    "date_sunset": null,
    "description": "The Treasure Cryptographic Module is the cryptographic component of Treasure\u0027s Treasure Vault product, which provides HSM-grade security for managing cryptographic keys and protecting sensitive data. This solution leverages on Intel \u00ae SGX technology and allows enterprises to protect data at all states: at rest, in motion and in use",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": "Intel Core i7-6600U",
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Treasure Cryptographic Module",
    "module_type": "Software-Hybrid",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "1.5",
    "tested_conf": [
      "Ubuntu 18.04 LTS running on a Lenovo Thinkpad T460s with an Intel Core i7-6600U (single-user mode)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-06-18",
        "lab": "EWA - Canada",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-06-26",
        "lab": "EWA - Canada",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-05-21",
        "lab": "EWA - Canada",
        "validation_type": "Update"
      }
    ],
    "vendor": "Treasure Cloud Pte.Ltd",
    "vendor_url": "https://www.anqlave.co"
  }
}