EZPES Centralized Security Module (CSM)

Certificate #4433

Webpage information ?

Status active
Validation dates 09.02.2023
Sunset date 21-09-2026
Standard FIPS 140-2
Security level 3
Type Hardware
Embodiment Multi-Chip Embedded
Caveat When operated in FIPS mode
Exceptions
  • Physical Security: Level 4
Description The EasyPost Centralized Security Module (CSM) acts as the core security module of a United States Postal Service (USPS) Intelligent Mail Indicia Performance Criteria (IMI PC) conformant online postage evidencing system (PES). Its primary purpose is to perform secure postal financial transactions.
Version (Hardware) CryptoServer CSe-Series 4.00.5.1
Version (Firmware) CryptoServer CSe-Series 4.32.0.5; App version: 3.0.0.0
Vendor EasyPost
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy ?

Symmetric Algorithms
AES, DES, Triple-DES, TDES, HMAC, HMAC-SHA-256, CMAC
Asymmetric Algorithms
RSA 2048, RSA 4096, RSA 1024, ECDH, ECDSA, ECC, DH, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA-224, SHA-384, SHA-512, SHA-256, SHA-2, SHA3-256, SHA3-384, SHA3-512, SHA3-224, SHA-3, SHA3
Schemes
MAC, Key agreement, Key Agreement
Protocols
TLS, TLS v1.2, TLS 1.2
Randomness
DRBG, RNG
Elliptic Curves
P-224, P-256, P-384, P-521, P-192, K-233, K-283, K-409, K-571, B-233, B-283, B-409, B-571, K-163, B-163, NIST P-521, secp256k1, brainpoolP224r1, brainpoolP224t1, brainpoolP256r1, brainpoolP256t1, brainpoolP320r1, brainpoolP320t1, brainpoolP384r1, brainpoolP384t1, brainpoolP512r1, brainpoolP512t1, FRP256v1
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM

Trusted Execution Environments
PSP, SSC

Security level
Level 3, Level 4, Level 1
Side-channel analysis
DPA, SPA, timing attacks

Standards
FIPS 140-2, FIPS140-2, FIPS 197, FIPS 186-4, FIPS 186-2, FIPS 198-1, FIPS 202, FIPS 180-4, FIPS PUB 140-2, FIPS186-2, FIPS186-4, SP 800-38A, SP 800-38C, SP 800-38F, SP 800-38B, SP 800-38D, SP 800-135, SP 800-90A, SP 800-90B, SP 800-56A, SP 800-108, SP 800-56C, SP 800-56B, SP 800-67, SP 800-133, NIST SP 800-56A, PKCS 1, PKCS#11, PKCS#1, PKCS#3, RFC 7748

File metadata

Author Aryeh
Creation date D:20221230090736-08'00'
Modification date D:20221230090806-08'00'
Pages 39
Creator Acrobat PDFMaker 22 for Word
Producer Adobe PDF Library 22.3.58

References

Outgoing
  • 3886 - active - CryptoServer CSe-Series

Heuristics ?

No heuristics are available for this certificate.

References ?

Updates ?

  • 12.03.2023 The certificate data changed.
    Certificate changed

    The web extraction data was updated.

    • The certificate_pdf_url property was set to https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/February 2023_010323_0649.pdf.
  • 09.02.2023 The certificate was first processed.
    New certificate

    A new FIPS 140 certificate with the product name was processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4433,
  "dgst": "8c059aad9e8b1f53",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHS#A1067",
        "KAS-SSC#A2227",
        "AES#C1140",
        "AES#C1246",
        "CVL#C1141",
        "KAS#A2369",
        "AES#C1138",
        "KAS-SSC#A2369",
        "KAS#A1016",
        "KTS-RSA#A2370",
        "Triple-DES#C1128",
        "KDA#A1016",
        "SHS#C1124",
        "KAS#A2417",
        "KDA#A2417",
        "AES#C1137",
        "ECDSA#C1196",
        "RSA#C1197",
        "KTS#C1140",
        "KAS-SSC#A2368",
        "KAS#A2368",
        "ECDSA#A2367",
        "SHS#C1126",
        "KTS#C1122",
        "AES#C1122",
        "DSA#C1195",
        "CVL#C1165",
        "SHA-3#C1125",
        "CVL#A1016",
        "KBKDF#C1164",
        "DRBG#A1068",
        "HMAC#C1142"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "4.32.0.5",
        "3.0.0.0",
        "4.00.5.1"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3886"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3886"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "3886"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 2
          },
          "ECDH": {
            "ECDH": 7
          },
          "ECDSA": {
            "ECDSA": 15
          }
        },
        "FF": {
          "DH": {
            "DH": 2,
            "Diffie-Hellman": 2
          },
          "DSA": {
            "DSA": 29
          }
        },
        "RSA": {
          "RSA 1024": 1,
          "RSA 2048": 1,
          "RSA 4096": 2
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 27
        },
        "CCM": {
          "CCM": 4
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 6
        },
        "GCM": {
          "GCM": 6
        },
        "OFB": {
          "OFB": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "TLS": {
            "TLS": 2,
            "TLS 1.2": 1,
            "TLS v1.2": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 5,
          "Key agreement": 2
        },
        "MAC": {
          "MAC": 9
        }
      },
      "device_model": {},
      "ecc_curve": {
        "ANSSI": {
          "FRP256v1": 2
        },
        "Brainpool": {
          "brainpoolP224r1": 1,
          "brainpoolP224t1": 1,
          "brainpoolP256r1": 1,
          "brainpoolP256t1": 1,
          "brainpoolP320r1": 1,
          "brainpoolP320t1": 1,
          "brainpoolP384r1": 1,
          "brainpoolP384t1": 1,
          "brainpoolP512r1": 1,
          "brainpoolP512t1": 1
        },
        "NIST": {
          "B-163": 2,
          "B-233": 3,
          "B-283": 3,
          "B-409": 3,
          "B-571": 3,
          "K-163": 3,
          "K-233": 3,
          "K-283": 3,
          "K-409": 3,
          "K-571": 3,
          "NIST P-521": 2,
          "P-192": 4,
          "P-224": 6,
          "P-256": 8,
          "P-384": 6,
          "P-521": 14,
          "secp256k1": 2
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#3886": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 256": 1,
          "AES CBC 16": 1,
          "AES CBC 32": 1,
          "HMAC-SHA-256": 4,
          "PKCS 1": 4,
          "PKCS#1": 2,
          "PKCS#11": 12,
          "PKCS#3": 2,
          "RSA 1024": 1,
          "RSA 2048": 1,
          "RSA 4096": 2,
          "RSA16": 1,
          "SHA- 256": 9,
          "SHA- 384": 2,
          "SHA-1": 7,
          "SHA-14": 1,
          "SHA-17": 1,
          "SHA-2": 1,
          "SHA-224": 12,
          "SHA-2243": 2,
          "SHA-256": 7,
          "SHA-3": 5,
          "SHA-384": 12,
          "SHA-512": 17,
          "SHA-512 128": 1,
          "SHA-5128": 1,
          "SHA3": 1,
          "SHA3- 224": 1,
          "SHA3-224": 8,
          "SHA3-256": 5,
          "SHA3-384": 10,
          "SHA3-512": 7
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 3": 4,
          "Level 4": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 7
          },
          "SHA2": {
            "SHA-2": 1,
            "SHA-224": 12,
            "SHA-256": 7,
            "SHA-384": 12,
            "SHA-512": 18
          },
          "SHA3": {
            "SHA-3": 5,
            "SHA3": 1,
            "SHA3-224": 8,
            "SHA3-256": 5,
            "SHA3-384": 10,
            "SHA3-512": 7
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 27
        },
        "RNG": {
          "RNG": 4
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "DPA": 1,
          "SPA": 1,
          "timing attacks": 2
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 9,
          "FIPS 180-4": 3,
          "FIPS 186-2": 5,
          "FIPS 186-4": 11,
          "FIPS 197": 2,
          "FIPS 198-1": 1,
          "FIPS 202": 1,
          "FIPS PUB 140-2": 1,
          "FIPS140-2": 4,
          "FIPS186-2": 1,
          "FIPS186-4": 1
        },
        "NIST": {
          "NIST SP 800-56A": 2,
          "SP 800-108": 3,
          "SP 800-133": 1,
          "SP 800-135": 5,
          "SP 800-38A": 3,
          "SP 800-38B": 2,
          "SP 800-38C": 1,
          "SP 800-38D": 1,
          "SP 800-38F": 5,
          "SP 800-56A": 5,
          "SP 800-56B": 1,
          "SP 800-56C": 2,
          "SP 800-67": 1,
          "SP 800-90A": 1,
          "SP 800-90B": 5
        },
        "PKCS": {
          "PKCS 1": 2,
          "PKCS#1": 1,
          "PKCS#11": 6,
          "PKCS#3": 1
        },
        "RFC": {
          "RFC 7748": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 73
          }
        },
        "DES": {
          "3DES": {
            "TDES": 1,
            "Triple-DES": 13
          },
          "DES": {
            "DES": 4
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 23,
            "HMAC": 13,
            "HMAC-SHA-256": 2
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 2
        },
        "IBM": {
          "SSC": 3
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Aryeh",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20221230090736-08\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 22 for Word",
      "/Keywords": "",
      "/ModDate": "D:20221230090806-08\u002700\u0027",
      "/Producer": "Adobe PDF Library 22.3.58",
      "/SourceModified": "D:20221230161300",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 875775,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://tools.ietf.org/html/rfc5639",
          "http://www.rsa.com/rsalabs/node.asp?id=2133",
          "http://www.rsa.com/rsalabs/node.asp?id=2125",
          "https://www.legifrance.gouv.fr/affichTexte.do?cidTexte=JORFTEXT000024668816",
          "http://www.rsa.com/rsalabs/node.asp?id=2126"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 39
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_garbage": false,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_pdf_hash": "81dbd43428080482ebf3d1c63ea815ed9993bcb621eb7281a1f3cb6f97cbaf88",
    "policy_txt_hash": "b477490cad207f08b4048927d074c931d0645653581c8ff712edf9c096df8cfe"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/February 2023_010323_0649.pdf",
    "date_sunset": "2026-09-21",
    "description": "The EasyPost Centralized Security Module (CSM) acts as the core security module of a United States Postal Service (USPS) Intelligent Mail Indicia Performance Criteria (IMI PC) conformant online postage evidencing system (PES). Its primary purpose is to perform secure postal financial transactions.",
    "embodiment": "Multi-Chip Embedded",
    "exceptions": [
      "Physical Security: Level 4"
    ],
    "fw_versions": "CryptoServer CSe-Series 4.32.0.5; App version: 3.0.0.0",
    "historical_reason": null,
    "hw_versions": "CryptoServer CSe-Series 4.00.5.1",
    "level": 3,
    "mentioned_certs": {},
    "module_name": "EZPES Centralized Security Module (CSM)",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2023-02-09",
        "lab": "PENUMBRA SECURITY",
        "validation_type": "Initial"
      }
    ],
    "vendor": "EasyPost",
    "vendor_url": "http://www.easypost.com"
  }
}