Crypto Module for Intel® Alder Point PCH Converged Security and Manageability Engine (CSME)

Certificate #5365

Webpage information

Status active
Validation dates 06.07.2026
Sunset date 01-08-2029
Standard FIPS 140-3
Security level 2
Type Firmware-Hybrid
Embodiment SingleChip
Caveat When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
Description The Cryptographic Module for Intel® Converged Security and Manageability Engine(CSME) is a firmware-hybrid module. The module consists of both hardware and firmware. The hardware portion is the Converged Security Engine (CSE) and the firmware portion is the crypto driver process of the Manageability Engine (ME). The two portions form the cryptographic boundary and they combine as Converged Security and Manageability Engine (CSME) to perform cryptographic functions within the Alder Point PCH applications executing on the CSME OS.
Vendor Intel Corporation
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-256, AES-, CAST, SM4, HMAC, HMAC-SHA-256, HMAC-SHA-384, CBC-MAC
Asymmetric Algorithms
RSA-OAEP, ECDHE, ECDH, ECDSA, ECC, Diffie-Hellman
Hash functions
SHA-1, SHA-384, SHA-224, SHA-256, SHA-512, MD5
Schemes
MAC, Key Agreement
Randomness
DRBG, RBG
Elliptic Curves
P-256, P-384, secp256k1
Block cipher modes
ECB, CTR, GCM

JavaCard API constants
SM2
Trusted Execution Environments
PSP

Security level
Level 2, Level 1, level 2
Side-channel analysis
DPA, timing attacks

File metadata

Author Nathan Glass
Creation date D:20260424140150-04'00'
Modification date D:20260424140242-04'00'
Pages 41
Creator Acrobat PDFMaker 25 for Word
Producer Adobe PDF Library 25.1.40

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5365,
  "dgst": "dd5c332e8ce67a7c",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": []
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 29
          },
          "ECDH": {
            "ECDH": 5,
            "ECDHE": 5
          },
          "ECDSA": {
            "ECDSA": 49
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 2
          }
        },
        "RSA": {
          "RSA-OAEP": 4
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "MAC": {
          "MAC": 23
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 24,
          "P-384": 18,
          "secp256k1": 3
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 42
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 2,
          "AES-256": 2,
          "HMAC- SHA-384": 1,
          "HMAC-SHA- 256": 2,
          "HMAC-SHA- 512": 2,
          "HMAC-SHA-1": 16,
          "HMAC-SHA-256": 4,
          "HMAC-SHA-384": 2,
          "HMAC-SHA256": 2,
          "PKCS 1": 2,
          "PKCS#1": 4,
          "RSA 1": 3,
          "SHA- 256": 2,
          "SHA-1": 14,
          "SHA-224": 1,
          "SHA-256": 3,
          "SHA-384": 2,
          "SHA-512": 1,
          "SHA2-224": 4,
          "SHA2-256": 8,
          "SHA2-384": 5,
          "SHA2-512": 6
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 2": 3,
          "level 2": 1
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 15
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 14
          },
          "SHA2": {
            "SHA-224": 1,
            "SHA-256": 3,
            "SHA-384": 2,
            "SHA-512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {
        "curves": {
          "SM2": 7
        }
      },
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 30
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "DPA": 2,
          "timing attacks": 2
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 51,
          "FIPS 180-4": 5,
          "FIPS 186-4": 9,
          "FIPS 186-5": 1,
          "FIPS 198-1": 5,
          "FIPS PUB 140-3": 1,
          "FIPS186-4": 21
        },
        "NIST": {
          "SP 800-108": 1,
          "SP 800-38A": 5,
          "SP 800-38B": 1,
          "SP 800-38D": 1,
          "SP 800-56A": 1,
          "SP 800-56B": 1,
          "SP 800-56C": 5,
          "SP 800-90A": 1,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS 1": 2,
          "PKCS#1": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 30,
            "AES-": 1,
            "AES-256": 2
          },
          "CAST": {
            "CAST": 36
          }
        },
        "constructions": {
          "MAC": {
            "CBC-MAC": 1,
            "HMAC": 17,
            "HMAC-SHA-256": 2,
            "HMAC-SHA-384": 1
          }
        },
        "miscellaneous": {
          "SM4": {
            "SM4": 3
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 3
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Nathan Glass",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20260424140150-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/ModDate": "D:20260424140242-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.40",
      "/SourceModified": "D:20260424180134",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 656737,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://platformsw.intel.com/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 41
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "088f68c134b3f8bb28fdadcaf9f88916d21db7eafa40acd9e2f4d43dac35d6dc",
      "txt_hash": "39221bdd44b45353632bb86b3a83f5feecbd17f3483076c61164e269206bfc89"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf",
    "date_sunset": "2029-08-01",
    "description": "The Cryptographic Module for Intel\u00ae Converged Security and Manageability Engine(CSME) is a firmware-hybrid module. The module consists of both hardware and firmware. The hardware portion is the Converged Security Engine (CSE) and the firmware portion is the crypto driver process of the Manageability Engine (ME). The two portions form the cryptographic boundary and they combine as Converged Security and Manageability Engine (CSME) to perform cryptographic functions within the Alder Point PCH applications executing on the CSME OS.",
    "embodiment": "SingleChip",
    "exceptions": [
      "Operational environment: N/A",
      "Non-invasive security: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Crypto Module for Intel\u00ae Alder Point PCH Converged Security and Manageability Engine (CSME)",
    "module_type": "Firmware-Hybrid",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-07-06",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Intel Corporation",
    "vendor_url": "http://www.intel.com"
  }
}