Tamper-evident physical protection
Critical components are obscured and covered by black, opaque, tamper-resistant epoxy; penetration or removal is designed to leave visible damage or render the module unusable.
VALIDATED HARDWARE TRUST ANCHOR
A portable hardware cryptographic module recorded by NIST CMVP Certificate #5331 at Overall Level 3, with a public validation boundary, tested module identification and non-proprietary Security Policy.
FIPS module validation and PQC algorithm capability are governed as separate claims.
VALIDATION FACTSHEET
These facts are mapped to the NIST CMVP certificate and the non-proprietary Security Policy. Product quotations and deployments must preserve the identified model, firmware and approved-mode boundary.
HARDWARE CRYPTOGRAPHIC BOUNDARY
The module is a multi-chip embedded USB token containing Mobile-ID MIDCOS on an HSC32K2 with PAA integrated circuit. The diagram shows the security relationship rather than implying application compatibility.
WHAT LEVEL 3 MEANS HERE
Critical components are obscured and covered by black, opaque, tamper-resistant epoxy; penetration or removal is designed to leave visible damage or render the module unusable.
Distinct Cryptographic Officer and User roles control access to approved services. Previous authentication is cleared on power cycle.
The module has one operating mode—the FIPS Approved mode entered after power-up—with a visible status indicator.
SSP generation, access and zeroization are mapped to services. Data output is inhibited during key generation, zeroization, self-tests and error states.
Pre-operational and conditional tests run without operator action; operators can initiate power-up tests by resetting or power cycling the module.
Factory initialization, delivery verification and authenticated termination are defined; termination clears CSPs and disables services.
VALIDATED MODULE IDENTIFICATION
A2 is identified without a button; K9, K40, A4B, K49, K50 and K28 are identified with a button. Deployment must still match the complete NIST and Security Policy record.
| Model / part number | Hardware | Firmware | Processor | Form |
|---|---|---|---|---|
| A2 | V1.2 | V1.3.02 | HSC32K2 with PAA | Without button |
| K9 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| K40 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| A4B | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| K49 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| K50 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| K28 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
SECURITY-LEVEL MATRIX
Level 3 applies to the listed applicable sections. Operational Environment, Non-Invasive Security and Mitigation of Other Attacks are marked N/A in the certificate and Security Policy.
| FIPS 140-3 area | Level |
|---|---|
| General | 3 |
| Cryptographic Module Specification | 3 |
| Cryptographic Module Interfaces | 3 |
| Roles, Services and Authentication | 3 |
| Software/Firmware Security | 3 |
| Operational Environment | N/A |
| Physical Security | 3 |
| Non-Invasive Security | N/A |
| Sensitive Security Parameter Management | 3 |
| Self-Tests | 3 |
| Life-Cycle Assurance | 3 |
| Mitigation of Other Attacks | N/A |
APPROVED SERVICE FAMILIES
The public Security Policy includes approved service families such as AES, ECDSA, RSA, SHA-2/SHA-3, HMAC, key agreement, KDF and DRBG. Exact algorithms, curves, modes, key sizes and CAVP references must be read from the current policy.
PQC provider, firmware, parameter-set and algorithm-validation status must be disclosed through a separate capability and evidence record.
View the PQC capability matrix →OFFICIAL CAVEAT & PROCUREMENT USE
The NIST record states that generated SSP strength is affected by available entropy and provides no assurance of minimum security for externally loaded SSPs or SSPs established with externally loaded SSPs.
NEXT STEP
Confirm the exact token model, middleware, operating system, application version, key policy and acceptance evidence before production rollout.