FEITIAN MFA Cryptographic Module

Certificate #4422

Webpage information

Status active
Validation dates 23.01.2023
Sunset date 21-09-2026
Standard FIPS 140-2
Security level 2
Type Hardware
Embodiment Single Chip
Caveat When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Exceptions
  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Description The Module is a single chip embodiment implementing the JavaCard and Global Platform operational environment with a Card Manager, that is also considered an Issuer Security Domain (ISD), and five Applets. The Module meets FIPS 140-2 overall Level 2 requirements.
Version (Hardware) SLE78CLUFX5000PH
Version (Firmware) 7.04
Vendor FEITIAN Technologies US, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, HMAC, HMAC-SHA-256, CMAC
Asymmetric Algorithms
RSA-2048, ECDH, ECDSA, ECC
Hash functions
SHA-1, SHA-224, SHA-384, SHA-256, SHA-512, SHA-3
Schemes
Key agreement, Key Agreement
Randomness
DRBG
Elliptic Curves
P-224, P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR, GCM, CCM

Trusted Execution Environments
SSC
Vendor
Feitian

Security level
Level 2, Level 3

Standards
FIPS 140-2, FIPS186-4, FIPS140-2, FIPS PUB 140-2, FIPS PUB 202, PKCS#1

File metadata

Subject FIPS 140-2 Security Policy Template
Author QiuYL
Creation date D:20230104153617-08'00'
Modification date D:20230104153706-08'00'
Pages 26
Creator Acrobat PDFMaker 22 for Word
Producer Adobe PDF Library 22.3.58

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4422,
  "dgst": "dc99de4709eb45d5",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "KAS#A2406",
        "ECDSA#A2406",
        "HMAC#A2406",
        "AES#A2406",
        "KDA#A2406",
        "RSA#A2406",
        "CVL#A2406",
        "DRBG#A2406",
        "KTS#A2406",
        "RSA#A2408",
        "KAS-SSC#A2406",
        "SHS#A2406"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "7.04"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 17
          },
          "ECDH": {
            "ECDH": 2
          },
          "ECDSA": {
            "ECDSA": 13
          }
        },
        "RSA": {
          "RSA-2048": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CCM": {
          "CCM": 1
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 4
        },
        "GCM": {
          "GCM": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2,
          "Key agreement": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 6,
          "P-256": 12,
          "P-384": 6,
          "P-521": 6
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES-128": 1,
          "AES[197": 1,
          "HMAC SHA-1": 1,
          "HMAC SHA-256": 6,
          "HMAC [198": 1,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-256": 4,
          "HMAC-SHA256": 4,
          "PKCS#1": 14,
          "SHA(224": 6,
          "SHA-1": 5,
          "SHA-224": 1,
          "SHA-256": 11,
          "SHA-3": 1,
          "SHA-384": 1,
          "SHA-512": 2,
          "SHS [180": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 1,
          "Level 3": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 5
          },
          "SHA2": {
            "SHA-224": 2,
            "SHA-256": 10,
            "SHA-384": 2,
            "SHA-512": 1
          },
          "SHA3": {
            "SHA-3": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 32
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 33,
          "FIPS PUB 140-2": 1,
          "FIPS PUB 202": 1,
          "FIPS140-2": 1,
          "FIPS186-4": 1
        },
        "PKCS": {
          "PKCS#1": 7
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 15,
            "AES-128": 1
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 3,
            "HMAC": 15,
            "HMAC-SHA-256": 2
          }
        }
      },
      "tee_name": {
        "IBM": {
          "SSC": 1
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "Feitian": {
          "Feitian": 25
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "QiuYL",
      "/Company": "Microsoft",
      "/CreationDate": "D:20230104153617-08\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 22 for Word",
      "/ICV": "135D15AC2349477DB37F128B0B117933",
      "/KSOProductBuildVer": "2052-11.1.0.11744",
      "/ModDate": "D:20230104153706-08\u002700\u0027",
      "/Producer": "Adobe PDF Library 22.3.58",
      "/SourceModified": "D:20230104233557",
      "/Subject": "FIPS 140-2 Security Policy Template",
      "pdf_file_size_bytes": 689098,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 26
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_garbage": false,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_pdf_hash": "f644869c16642f1e138ea0c66ad5f038d11ce04dfc6336ad4fd2043ad49ae619",
    "policy_txt_hash": "c309144dcafebb627309f6dc486ca26ee7468b13d05f9690feb3672406a5e634"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/January 2023_010223_0657_signed.pdf",
    "date_sunset": "2026-09-21",
    "description": "The Module is a single chip embodiment implementing the JavaCard and Global Platform operational environment with a Card Manager, that is also considered an Issuer Security Domain (ISD), and five Applets. The Module meets FIPS 140-2 overall Level 2 requirements.",
    "embodiment": "Single Chip",
    "exceptions": [
      "Physical Security: Level 3",
      "EMI/EMC: Level 3",
      "Design Assurance: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "7.04",
    "historical_reason": null,
    "hw_versions": "SLE78CLUFX5000PH",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "FEITIAN MFA Cryptographic Module",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2023-01-23",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "FEITIAN Technologies US, Inc.",
    "vendor_url": "http://www.ftsafe.com"
  }
}