This page was not yet optimized for use on mobile devices.
XSOC Cryptosystem
Certificate details
| Certificate ID | #4038 |
|---|---|
| Status | historical |
| Historical reason | SP 800-56Arev3 transition |
| Validation dates | 27.09.2021 |
| Standard | FIPS 140-2 |
| Security level | 1 |
| Type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Caveat | When operated in FIPS mode. No assurance of the minimum strength of generated keys. This validation entry is a non-security relevant modification to Cert. #3080 |
| Exceptions |
|
| Description | XSOC Cryptosystem ™ is a standards-based "Drop-in Compliance" cryptographic engine that enables the protection of data requiring absolute compliance with federal standards. The module delivers core cryptographic Suite-B functions to the layered architecture of XSOC's own proprietary security workflow and overall cryptosystem. Data that is enciphered or transformed by XSOC passes through XSOC Cryptosystem during every cycle of operation. XSOC Cryptosystem enables flexible modes of operation for encryption. |
| Tested configurations |
|
| Vendor | XSOC Corp http://www.xsoccorp.com |
| Lab | AEGISOLVE, Inc. |
| References | This certificate's webpage directly references 1 certificates, transitively this expands into 1 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES, AES-128, AES-192, AES-256, AES-, Twofish, Serpent, CAST5, RC4, RC2, DES, Triple-DES, TripleDES, TDEA, TDES, IDEA, Blowfish, Camellia, SEED, HMAC, HMAC-SHA-256, CMAC, CBC-MACAsymmetric Algorithms
RSA-OAEP, ECDSA, ECC, DH, Diffie-Hellman, DSAHash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-2, SHA-3, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, MD5, RIPEMD128, RIPEMD-160, RIPEMD256, RIPEMD320, RIPEMD, PBKDFSchemes
MAC, Key AgreementProtocols
SSH, TLS, TLS 1.2, IKEv2Randomness
PRNG, DRBG, RNGLibraries
OpenSSLElliptic Curves
P-224, P-256, P-384, P-521, K-233, K-283, K-409, B-283, B-409, B-571, K-571Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCMJavaCard packages
com.safelogic.cryptocomply.fipsVendor
MicrosoftSecurity level
Level 1Side-channel analysis
timing attacks, timing attackStandards
FIPS 140-2, FIPS 140, FIPS 197, FIPS 186-4, FIPS 198-1, FIPS 180-4, FIPS 202, FIPS 186-3, FIPS PUB 140-2, SP 800-38A, SP 800-38C, SP 800-38B, SP 800-38D, SP 800-90A, SP 800-56A, SP 800-135, SP 800-108, SP 800-38F, SP 800-67, SP 800-133, SP 800-132, SP 800-56B, SP 800-56C, SP 800-20, SP 800-89, PKCS #1, PKCS1, PKCS#12, PKCS#5, PKCS#1Cross-references
Outgoing- 100 - historical - NetFortress® 10
Automated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
Loading...
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 4038,
"dgst": "df4aa3c96e0fe9b0",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"KBKDF#145",
"SHA-3#24",
"CVL#1343",
"AES#4702",
"DSA#1244",
"CVL#1344",
"SHS#3849",
"KTS#2494",
"CVL#1342",
"HMAC#3114",
"Triple-DES#2494",
"DRBG#1600",
"CVL#1345",
"ECDSA#1160",
"RSA#2562"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"3080"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"3080"
]
}
},
"module_prunned_references": {
"_type": "Set",
"elements": [
"3080"
]
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"100"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"100"
]
}
},
"policy_prunned_references": {
"_type": "Set",
"elements": [
"100"
]
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 2
},
"ECDSA": {
"ECDSA": 12
}
},
"FF": {
"DH": {
"DH": 8,
"Diffie-Hellman": 5
},
"DSA": {
"DSA": 15
}
},
"RSA": {
"RSA-OAEP": 1
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 3
},
"CCM": {
"CCM": 4
},
"CFB": {
"CFB": 1
},
"CTR": {
"CTR": 6
},
"ECB": {
"ECB": 3
},
"GCM": {
"GCM": 11
},
"OFB": {
"OFB": 2
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 1
}
},
"crypto_protocol": {
"IKE": {
"IKEv2": 5
},
"SSH": {
"SSH": 5
},
"TLS": {
"TLS": {
"TLS": 14,
"TLS 1.2": 1
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 7
},
"MAC": {
"MAC": 4
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"B-283": 2,
"B-409": 2,
"B-571": 2,
"K-233": 1,
"K-283": 2,
"K-409": 2,
"K-571": 1,
"P-224": 6,
"P-256": 8,
"P-384": 6,
"P-521": 4
}
},
"eval_facility": {},
"fips_cert_id": {
"Cert": {
"#1": 1,
"#100": 1,
"#1342": 1,
"#1344": 1,
"#1600": 1,
"#3114": 1
}
},
"fips_certlike": {
"Certlike": {
"AES 128, 192": 2,
"AES-128": 1,
"AES-192": 1,
"AES-256": 1,
"CVL #1342": 1,
"CVL #1344": 1,
"DRBG #1600": 1,
"DRBG 112": 1,
"DSA3": 1,
"HMAC #3114": 2,
"HMAC SHA-512/224": 1,
"HMAC-SHA-256": 2,
"HMAC-SHA256": 2,
"PKCS #1": 2,
"PKCS#1": 4,
"PKCS#12": 4,
"PKCS#5": 4,
"PKCS1": 2,
"SHA- 1": 1,
"SHA- 224": 1,
"SHA-1": 8,
"SHA-2": 2,
"SHA-224": 5,
"SHA-256": 6,
"SHA-3": 3,
"SHA-384": 6,
"SHA-512": 6,
"SHA3-224": 2,
"SHA3-256": 2,
"SHA3-384": 2,
"SHA3-512": 2
}
},
"fips_security_level": {
"Level": {
"Level 1": 4
}
},
"hash_function": {
"MD": {
"MD5": {
"MD5": 4
}
},
"PBKDF": {
"PBKDF": 14
},
"RIPEMD": {
"RIPEMD": 1,
"RIPEMD-160": 1,
"RIPEMD128": 1,
"RIPEMD256": 1,
"RIPEMD320": 1
},
"SHA": {
"SHA1": {
"SHA-1": 8
},
"SHA2": {
"SHA-2": 2,
"SHA-224": 5,
"SHA-256": 6,
"SHA-384": 6,
"SHA-512": 6
},
"SHA3": {
"SHA-3": 3,
"SHA3-224": 2,
"SHA3-256": 2,
"SHA3-384": 2,
"SHA3-512": 2
}
},
"SHAKE": {
"SHAKE128": 2,
"SHAKE256": 2
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {
"com": {
"com.safelogic.cryptocomply.fips": 1
}
},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 23,
"PRNG": 1
},
"RNG": {
"RNG": 2
}
},
"side_channel_analysis": {
"SCA": {
"timing attack": 1,
"timing attacks": 1
}
},
"standard_id": {
"FIPS": {
"FIPS 140": 6,
"FIPS 140-2": 13,
"FIPS 180-4": 2,
"FIPS 186-3": 1,
"FIPS 186-4": 10,
"FIPS 197": 2,
"FIPS 198-1": 3,
"FIPS 202": 2,
"FIPS PUB 140-2": 1
},
"NIST": {
"SP 800-108": 6,
"SP 800-132": 5,
"SP 800-133": 1,
"SP 800-135": 7,
"SP 800-20": 1,
"SP 800-38A": 5,
"SP 800-38B": 2,
"SP 800-38C": 2,
"SP 800-38D": 5,
"SP 800-38F": 4,
"SP 800-56A": 5,
"SP 800-56B": 7,
"SP 800-56C": 3,
"SP 800-67": 5,
"SP 800-89": 1,
"SP 800-90A": 3
},
"PKCS": {
"PKCS #1": 1,
"PKCS#1": 2,
"PKCS#12": 2,
"PKCS#5": 2,
"PKCS1": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 29,
"AES-": 1,
"AES-128": 1,
"AES-192": 1,
"AES-256": 1
},
"CAST": {
"CAST5": 1
},
"RC": {
"RC2": 1,
"RC4": 1
},
"Serpent": {
"Serpent": 1
},
"Twofish": {
"Twofish": 1
}
},
"DES": {
"3DES": {
"TDEA": 6,
"TDES": 1,
"Triple-DES": 25,
"TripleDES": 1
},
"DES": {
"DES": 4
}
},
"constructions": {
"MAC": {
"CBC-MAC": 1,
"CMAC": 5,
"HMAC": 12,
"HMAC-SHA-256": 1
}
},
"miscellaneous": {
"Blowfish": {
"Blowfish": 1
},
"Camellia": {
"Camellia": 1
},
"IDEA": {
"IDEA": 1
},
"SEED": {
"SEED": 1
}
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {
"Microsoft": {
"Microsoft": 1
}
},
"vulnerability": {}
},
"policy_metadata": {
"/Author": "SafeLogic",
"/CreationDate": "D:20210827183700-07\u002700\u0027",
"/Creator": "Microsoft\u00ae Word for Microsoft 365",
"/ModDate": "D:20210827183700-07\u002700\u0027",
"/Producer": "Microsoft\u00ae Word for Microsoft 365",
"/Subject": "XSOC Cryptosystem",
"/Title": "Security Policy",
"pdf_file_size_bytes": 649130,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://www.safelogic.com/",
"http://www.xsoccorp.com/",
"http://csrc.nist.gov/groups/STM/cmvp/index.html"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 34
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "02b1603db9d33f2da654a6b8c148424fb6541d6b1219c991603cc538e2fd03c0",
"txt_hash": "b68b4c42f81aea7979c8346a39ac64f49f42a8ca1598e2d8044e4aaf7dfa7557"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in FIPS mode. No assurance of the minimum strength of generated keys. This validation entry is a non-security relevant modification to Cert. #3080",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/September 2021_011021_0714_Signed2.pdf",
"date_sunset": null,
"description": "XSOC Cryptosystem \u2122 is a standards-based \"Drop-in Compliance\" cryptographic engine that enables the protection of data requiring absolute compliance with federal standards. The module delivers core cryptographic Suite-B functions to the layered architecture of XSOC\u0027s own proprietary security workflow and overall cryptosystem. Data that is enciphered or transformed by XSOC passes through XSOC Cryptosystem during every cycle of operation. XSOC Cryptosystem enables flexible modes of operation for encryption.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Physical Security: N/A"
],
"fw_versions": null,
"historical_reason": "SP 800-56Arev3 transition",
"hw_versions": null,
"level": 1,
"mentioned_certs": {
"3080": 1
},
"module_name": "XSOC Cryptosystem",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "historical",
"sw_versions": "3.0.1",
"tested_conf": [
"CentOS 6 and OpenJDK 1.7 running on HP ProLiant DL360 G7 Server using an Intel Xeon X5670 (single-user mode)"
],
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2021-09-27",
"lab": "AEGISOLVE, Inc.",
"validation_type": "Initial"
}
],
"vendor": "XSOC Corp",
"vendor_url": "http://www.xsoccorp.com"
}
}