Cryptographic Module for Intel® Converged Security and Manageability Engine (CSME)

Certificate #4158

Webpage information

Status active
Validation dates 17.02.2022 , 21.08.2023
Sunset date 21-09-2026
Standard FIPS 140-2
Security level 1
Type Firmware-Hybrid
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode
Description The Cryptographic Module for Intel® Converged Security and Manageability Engine(CSME) (hereafter referred to as 'the module') is classified as a multiple-chip standalone firmware-hybrid module for FIPS 140-2 purpose. The module consists of both hardware and firmware. The hardware portion is the Converged Security Engine (CSE) and the firmware portion is the crypto driver process of the Manageability Engine (ME). The two portions form the logical cryptographic boundary and they combine as Converged Security and Manageability Engine (CSME) to perform cryptographic functions within the Cannon Point PCH applications executing on the CSME.
Version (Hardware) 3.0
Version (Firmware) 2.5 and 2.6
Tested configurations
  • embedded IA-32 dedicated to support the functionality of the CSME firmware version 12.0.70.1652 running on Cannon Point PCH with Intel Whiskey Lake with device firmware version 12.0.70.1652
  • embedded IA-32 dedicated to support the functionality of the CSME firmware version 12.0.70.1652 running on Intel Cannon Point PCH with Intel Coffee Lake with device firmware version 12.0.70.1652
Vendor Intel Corporation
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-256, RC4, TDEA, SM4, HMAC, HMAC-SHA-256, HMAC-SHA-512, CMAC
Asymmetric Algorithms
RSA-OAEP, ECDH, ECDSA, ECC, Diffie-Hellman, DH
Hash functions
SHA-1, SHA-256, SHA-224, SHA-384, SHA-512, MD5, PBKDF
Schemes
MAC, Key Agreement
Randomness
TRNG, DRBG
Elliptic Curves
P-256, P-384, P-224, P-521, NIST P-224
Block cipher modes
ECB, CBC, CTR, OFB, GCM

JavaCard API constants
SM2

Security level
Level 1, level 1
Side-channel analysis
timing attack, timing attacks

Standards
FIPS 140-2, FIPS PUB 140-2, FIPS 197, FIPS 180-4, FIPS 198-1, FIPS 186-4, FIPS 186-2, FIPS140-2, FIPS180-4, FIPS186-4, FIPS197, FIPS198-1, SP 800-90A, SP 800-108, SP 800-56B, SP 800-132, SP 800-90B, PKCS#1

File metadata

Title FIPS 140-2 Non-Proprietary Security Policy
Author Richard Fant
Creation date D:20230710181745+00'00'
Modification date D:20230710181745+00'00'
Pages 28
Creator Microsoft Word

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4158,
  "dgst": "aae49ea590f262f6",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC#C1770",
        "ECDSA#C1770",
        "ECDSA#C1769",
        "SHS#C1769",
        "RSA#C1770",
        "CVL#C1770",
        "AES#C1769",
        "KBKDF#C1769",
        "DRBG#C1769",
        "HMAC#C1769",
        "KBKDF#C1770",
        "DRBG#C1770",
        "KAS-SSC#A688",
        "SHS#C1770",
        "RSA#C1769",
        "AES#C1770",
        "CVL#C1769"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3.0",
        "2.6",
        "2.5"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 5
          },
          "ECDH": {
            "ECDH": 3
          },
          "ECDSA": {
            "ECDSA": 23
          }
        },
        "FF": {
          "DH": {
            "DH": 1,
            "Diffie-Hellman": 8
          }
        },
        "RSA": {
          "RSA-OAEP": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "CTR": {
          "CTR": 4
        },
        "ECB": {
          "ECB": 4
        },
        "GCM": {
          "GCM": 1
        },
        "OFB": {
          "OFB": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 6
        },
        "MAC": {
          "MAC": 5
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "NIST P-224": 1,
          "P-224": 3,
          "P-256": 10,
          "P-384": 8,
          "P-521": 4
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 30
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES 128": 1,
          "AES 256": 1,
          "AES-256": 2,
          "HMAC 128": 2,
          "HMAC- SHA-256": 1,
          "HMAC-SHA-1": 10,
          "HMAC-SHA-256": 6,
          "HMAC-SHA-512": 4,
          "PKCS#1": 16,
          "SHA-1": 8,
          "SHA-224": 8,
          "SHA-256": 15,
          "SHA-384": 8,
          "SHA-512": 8,
          "SHA2-256": 1,
          "SHA2-384": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 4,
          "level 1": 1
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 8
          }
        },
        "PBKDF": {
          "PBKDF": 5
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 8
          },
          "SHA2": {
            "SHA-224": 8,
            "SHA-256": 15,
            "SHA-384": 8,
            "SHA-512": 8
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {
        "curves": {
          "SM2": 4
        }
      },
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 12
        },
        "TRNG": {
          "TRNG": 2
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "timing attack": 1,
          "timing attacks": 1
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 43,
          "FIPS 180-4": 1,
          "FIPS 186-2": 1,
          "FIPS 186-4": 5,
          "FIPS 197": 1,
          "FIPS 198-1": 1,
          "FIPS PUB 140-2": 2,
          "FIPS140-2": 1,
          "FIPS180-4": 1,
          "FIPS186-4": 1,
          "FIPS197": 1,
          "FIPS198-1": 1
        },
        "NIST": {
          "SP 800-108": 1,
          "SP 800-132": 2,
          "SP 800-56B": 3,
          "SP 800-90A": 3,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS#1": 8
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 23,
            "AES-256": 2
          },
          "RC": {
            "RC4": 2
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 18,
            "HMAC-SHA-256": 3,
            "HMAC-SHA-512": 2
          }
        },
        "miscellaneous": {
          "SM4": {
            "SM4": 2
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Richard Fant",
      "/CreationDate": "D:20230710181745+00\u002700\u0027",
      "/Creator": "Microsoft Word",
      "/ModDate": "D:20230710181745+00\u002700\u0027",
      "/Title": "FIPS 140-2 Non-Proprietary Security Policy",
      "pdf_file_size_bytes": 611387,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-56b.pdf",
          "https://platformsw.intel.com/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 28
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "4b0fb0ed8154ed1da2eb798d6db3986662a35d7e7ce08815c5ff1c4a6ca0987d",
    "policy_txt_hash": "fea13655d938d42ffd4fb1ffc91d18bdf64dfe0e070668eca893d3deb4b8422f"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/February 2022_010322_0121_Signed.pdf",
    "date_sunset": "2026-09-21",
    "description": "The Cryptographic Module for Intel\u00ae Converged Security and Manageability Engine(CSME) (hereafter referred to as \u0027the module\u0027) is classified as a multiple-chip standalone firmware-hybrid module for FIPS 140-2 purpose. The module consists of both hardware and firmware. The hardware portion is the Converged Security Engine (CSE) and the firmware portion is the crypto driver process of the Manageability Engine (ME). The two portions form the logical cryptographic boundary and they combine as Converged Security and Manageability Engine (CSME) to perform cryptographic functions within the Cannon Point PCH applications executing on the CSME.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": null,
    "fw_versions": "2.5 and 2.6",
    "historical_reason": null,
    "hw_versions": "3.0",
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Cryptographic Module for Intel\u00ae Converged Security and Manageability Engine (CSME)",
    "module_type": "Firmware-Hybrid",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": null,
    "tested_conf": [
      "embedded IA-32 dedicated to support the functionality of the CSME firmware version 12.0.70.1652 running on Cannon Point PCH with Intel Whiskey Lake with device firmware version 12.0.70.1652",
      "embedded IA-32 dedicated to support the functionality of the CSME firmware version 12.0.70.1652 running on Intel Cannon Point PCH with Intel Coffee Lake with device firmware version 12.0.70.1652"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2022-02-17",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2023-08-21",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      }
    ],
    "vendor": "Intel Corporation",
    "vendor_url": "http://www.intel.com"
  }
}