Certificate 2263 - SafeGuard CryptoServer Se
intCertNum 2263
strVendorName Utimaco IS GmbH
strURL http://hsm.utimaco.de
strAddress1 Germanusstraße 4
strAddress2
strAddress3
strCity Aachen
strStateProv
strPostalCode 52080
strCountry 52080
strContact Dr. Gesa Ott
strEmail hsm@utimaco.de
strPhone +49 241-1696-200
strFax +49 241-1696-190
strContact2
strEmail2
strFax2
strPhone2
intCertNum 2263
strModuleName SafeGuard CryptoServer Se
strPartNumber Hardware Versions: P/N CryptoServer Se, Version 3.00.3.1;
Firmware Version: 3.0.2.0
memModuleNotes When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
str140Version 140-2
_sp_ Security Policy   [pdf][html][txt]
_cert_ Certificate   [pdf]
strPURL
strModuleType Hardware
strValidationDate 10/07/2014;05/04/2016
intOverallLevel 3
memIndividualLevelNotes
strFIPSAlgorithms AES (Cert. #2739);
DRBG (Cert. #459);
ECDSA (Cert. #840);
HMAC (Cert. #1717);
RSA (Certs. #1435 and #1436);
SHS (Certs. #2308, #2309 and #2310);
Triple-DES (Cert. #1649);
Triple-DES MAC (Triple-DES Cert. #1649, vendor affirmed);
CVL (Cert. #749)
strOtherAlgorithms NDRNG;
RSA (key wrapping;
key establishment methodology provides between 112 and 150 bits of encryption strength;
non-compliant less than 112 bits of encryption strength);
AES (Cert. #2739, key wrapping;
key establishment methodology provides between 128 and 256 bits of encryption strength);
Triple-DES (Cert. #1649, key wrapping;
key establishment methodology provides 112 bits of encryption strength);
Diffie-Hellman (key agreement: key establishment methodology provides 112 bits of encryption strength;
non-compliant less than 112 bits of encryption strength);
EC Diffie-Hellman (key agreement);
RSA (non-compliant);
ECIES;
MD5;
MDC-2;
RIPEMD-160;
DES;
Retail-TDES MAC;
AES MAC (AES Cert. #2739;
non-compliant);
PIN generation/PIN verification (e.g., VISA/MasterCard);
KDF_ENC_DATA;
KDF_HASH;
KDF_ECDH;
KDF_DH;
KDF_XOR_BASE_AND_DATA;
KDF_CAT_BASE_AND_KEY;
KDF_CAT_BASE_AND_DATA;
KDF_CAT_DATA_AND_BASE;
KDF_EXTRACT_KEY_FROM_KEY
strConfiguration Multi-chip embedded
memModuleDescription SafeGuard CryptoServer Se is an encapsulated, tamper-protected hardware security module which provides secure cryptographic services like encryption or decryption, hashing, signing and verification of data, random number generation, on-board secure key generation, key storage and further key management functions.
intModuleCount 1
memAdditionalNotes Updated FW for minor bug fix in ECDSA implementation.
strFirstValidtionDate 10/07/14 00:00:00
strLabName InfoGard
strValidationYear 2014