Physical security
Production-grade enclosure and opaque, tamper-resistant epoxy over critical cryptographic components, with visible tamper evidence expectations.
NIST CMVP VALIDATION RECORD
Trusted Key Token Cryptographic Module - a Hardware, MultiChipEmbed module validated with firmware V1.3.02.
Initial validation
16 June 2026
Sunset
27 January 2031
VALIDATION FACTS
The official NIST source remains authoritative. This page organizes the public facts and links each claim to its boundary.
SECURITY-LEVEL MATRIX
The matrix is reproduced as a navigational summary. The official Security Policy is the source for complete requirements and implementation details.
| FIPS 140-3 area | Level |
|---|---|
| General | 3 |
| Cryptographic Module Specification | 3 |
| Cryptographic Module Interfaces | 3 |
| Roles, Services and Authentication | 3 |
| Software/Firmware Security | 3 |
| Operational Environment | N/A |
| Physical Security | 3 |
| Non-Invasive Security | N/A |
| Sensitive Security Parameter Management | 3 |
| Self-Tests | 3 |
| Life-Cycle Assurance | 3 |
| Mitigation of Other Attacks | N/A |
TESTED MODULE IDENTIFICATION
The operator can correlate module identity and version information using the administrator guidance referenced by the Security Policy.
| Model / part number | Hardware | Firmware | Processor | Form |
|---|---|---|---|---|
| A2 | V1.2 | V1.3.02 | HSC32K2 with PAA | Without button |
| K9 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| K40 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| A4B | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| K49 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| K50 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
| K28 | V1.0 | V1.3.02 | HSC32K2 with PAA | With button |
VALIDATED SECURITY CHARACTERISTICS
Production-grade enclosure and opaque, tamper-resistant epoxy over critical cryptographic components, with visible tamper evidence expectations.
Distinct Cryptographic Officer and User roles with identity-based authentication and no cryptographic service access before authorization.
One approved operating mode entered after power-up, with status indication.
Defined access modes, zeroization procedures and controls that prohibit plaintext CSP entry, output and storage.
Pre-operational and conditional self-tests, output inhibition during tests and error handling.
Secure manufacturing setup, delivery verification, administrator guidance and authenticated termination at end of life.
CERTIFICATE CAVEAT
The certificate caveat states that generated SSP strengths are affected by available entropy and that no minimum security assurance is made for externally loaded SSPs or SSPs established with externally loaded SSPs.
CONTROLLED USE
Procurement and acceptance should verify certificate status, model, hardware version, firmware, approved mode, middleware and application compatibility.