{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "d1e915d03c28fd01", "cert_id": 5291, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "YubiKey 5 Cryptographic Module", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-05-22", "validation_type": "Initial", "lab": "Penumbra Security, Inc."}], "vendor_url": "http://www.yubico.com", "vendor": "Yubico, Inc.", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/May 2026_030626_0716.pdf", "module_type": "Hardware", "standard": "FIPS 140-3", "status": "active", "level": 2, "caveat": "When operated in approved mode; When installed, initialized and configured as specified in Section 11.1 of the Security Policy; No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.", "exceptions": ["Operational environment: N/A", "Physical security: Level 3", "Non-invasive security: N/A", "Mitigation of other attacks: N/A"], "embodiment": "SingleChip", "description": "The YubiKey 5 Cryptographic Module (the module) is a single-chip module validated at FIPS 140-3 Security Level 2. The module is a secure element that supports multiple protocols designed to be embedded in USB and/or NFC security tokens. The module can generate, store, and perform cryptographic operations for sensitive data and can be utilized via an external touch-button for Test of User Presence in addition to PIN for smart card authentication. The module implements several major functions - FIDO, PIV-compatible smart card, OpenPGP smart card, OATH authentication, Security Domain, and YubiHSM Auth.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2031-05-21", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {}, "fips_security_level": {"Level": {"Level 2": 5, "Level 1": 1}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 4, "HMAC-SHA1": 2, "SHA2-256": 7, "SHA2-384": 3, "SHA2- 512": 3, "SHA-1": 4, "SHA2-512": 3, "SHA1": 1, "SHA2- 256": 2, "RSA 2048": 2, "PKCS#1": 6, "AES-256": 1, "AES128": 1, "AES 128": 1, "DRBG 1216": 1}}, "vendor": {"Infineon": {"Infineon Technologies": 1, "Infineon Technologies AG": 1, "Infineon": 1}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-256": 1, "AES": 6, "AES128": 1}, "CAST": {"CAST": 30}}, "DES": {"DES": {"DES": 2}}, "constructions": {"MAC": {"HMAC": 11, "CMAC": 26}}}, "asymmetric_crypto": {"RSA": {"RSA 2048": 2}, "ECC": {"ECDH": {"ECDH": 4}, "ECDSA": {"ECDSA": 15}, "EdDSA": {"EdDSA": 1}, "ECC": {"ECC": 3}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 4, "SHA1": 1}}}, "crypto_scheme": {"MAC": {"MAC": 92}, "KA": {"Key Agreement": 1}}, "crypto_protocol": {}, "randomness": {"PRNG": {"DRBG": 62}, "RNG": {"RBG": 2}}, "cipher_mode": {"CCM": {"CCM": 3}}, "ecc_curve": {"NIST": {"P-224": 6, "P-256": 33, "P-384": 12, "P-521": 24, "curve P-256": 1}, "Edwards": {"Ed25519": 2}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 2}, "IBM": {"SSC": 7}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 8, "FIPS186-5": 23, "FIPS 186-5": 9, "FIPS 198-1": 4, "FIPS 186-4": 1, "FIPS 180-4": 4}, "NIST": {"SP 800-38A": 2, "SP 800-38C": 1, "SP 800-38B": 1, "SP 800-90A": 2, "SP 800-56A": 1, "SP 800-56C": 1, "SP 800-135": 1, "SP 800-108": 1, "SP 800-56B": 1, "NIST SP 800-90A": 1, "NIST SP 800-90B": 1, "NIST SP 800-140E": 1}, "PKCS": {"PKCS#1": 3}, "X509": {"X.509": 2}, "SCP": {"SCP11": 15, "SCP03": 9}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 685841, "pdf_is_encrypted": false, "pdf_number_of_pages": 67, "/Author": "", "/ClassificationContentMarkingHeaderFontProps": "#008000,10,Aptos", "/ClassificationContentMarkingHeaderShapeIds": "613e2a5b,7d2165eb,2aa81795", "/ClassificationContentMarkingHeaderText": "UNCLASSIFIED / NON CLASSIFI\u00c9//TLP:AMBER+STRICT", "/Comments": "", "/Company": "", "/ContentTypeId": "0x010100A83CF21AA0B8034899C5A76D1E900B4F", "/CreationDate": "D:20260520114139-04'00'", "/Creator": "Acrobat PDFMaker 26 for Word", "/Keywords": "", "/MSIP_Label_74f313cf-d20a-406f-9af7-e4526ef74d9f_ActionId": "82744f8f-1f48-4167-b734-a7b9572cc291", "/MSIP_Label_74f313cf-d20a-406f-9af7-e4526ef74d9f_ContentBits": "1", "/MSIP_Label_74f313cf-d20a-406f-9af7-e4526ef74d9f_Enabled": "true", "/MSIP_Label_74f313cf-d20a-406f-9af7-e4526ef74d9f_Method": "Privileged", "/MSIP_Label_74f313cf-d20a-406f-9af7-e4526ef74d9f_Name": "TLP-Amber_Strict", "/MSIP_Label_74f313cf-d20a-406f-9af7-e4526ef74d9f_SetDate": "2026-05-20T15:31:53Z", "/MSIP_Label_74f313cf-d20a-406f-9af7-e4526ef74d9f_SiteId": "da9cbe40-ec1e-4997-afb3-17d87574571a", "/MSIP_Label_74f313cf-d20a-406f-9af7-e4526ef74d9f_Tag": "10, 0, 1, 1", "/ModDate": "D:20260520114400-04'00'", "/Producer": "Adobe PDF Library 26.1.59", "/SourceModified": "", "/Subject": "", "/Title": "", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://docs.yubico.com/hardware/yubikey/yk-tech-manual/fips-140-3-nist-requirement.html"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["ECDSA SigGen (FIPS186-5)A5891", "EDDSA SigVerA5891", "SHA2-256A5891", "AES-CCMA5891", "RSA KeyGen (FIPS186-5)A5891", "SHA2-384A5891", "AES-CBCA5891", "SHA-1A5891", "KDF ANS 9.63A5891", "ECDSA KeyGen (FIPS186-5)A5891", "SHA2-512A5891", "Counter DRBGA5891", "HMAC-SHA2-384A5891", "ECDSA SigVer (FIPS186-5)A5891", "HMAC-SHA2-512A5891", "EDDSA SigGenA5891", "HMAC-SHA2-256A5891", "RSA Signature PrimitiveA5891", "KDF SP800-108A5891", "RSA SigVer (FIPS186-5)A5891", "AES-CMACA5891", "EDDSA KeyGenA5891", "AES-ECBA5891", "KDA HKDF SP800-56Cr2A5891", "KAS-ECC-SSC Sp800-56Ar3A5891", "RSA SigGen (FIPS186-5)A5891", "RSA Decryption Primitive Sp800-56Br2A5891", "HMAC-SHA-1A5891"]}, "extracted_versions": {"_type": "Set", "elements": ["5"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "a2a19cbe34ea950c05169aae9c90eb76cbb2c6fa4720fc5c2e381f006a4f3d90", "txt_hash": "509de0dd5b9f1a714622585d78443e7fe33f12993b115516e256785d4704b7d2", "json_hash": null}}}