NIST CMVP VALIDATION RECORD

ActiveFIPS 140-3Overall Level 3

Certificate #5331

Trusted Key Token Cryptographic Module - a Hardware, MultiChipEmbed module validated with firmware V1.3.02.

CMVPNIST Certificate5331

Initial validation
16 June 2026

Sunset
27 January 2031

VALIDATION FACTS

A complete online record for sales, engineering, procurement and audit.

The official NIST source remains authoritative. This page organizes the public facts and links each claim to its boundary.

Certificate
NIST CMVP #5331
Standard
FIPS 140-3
Status
Active
Overall level
3
Module type
Hardware
Embodiment
MultiChipEmbed
Part number
Trusted-Key
Validated firmware
V1.3.02
Initial validation
16 June 2026
Sunset date
27 January 2031
Laboratory
EWA - Canada
Security Policy
Version 1.1 - 1 April 2026

SECURITY-LEVEL MATRIX

Overall Level 3 is supported by the applicable security areas.

The matrix is reproduced as a navigational summary. The official Security Policy is the source for complete requirements and implementation details.

FIPS 140-3 areaLevel
General3
Cryptographic Module Specification3
Cryptographic Module Interfaces3
Roles, Services and Authentication3
Software/Firmware Security3
Operational EnvironmentN/A
Physical Security3
Non-Invasive SecurityN/A
Sensitive Security Parameter Management3
Self-Tests3
Life-Cycle Assurance3
Mitigation of Other AttacksN/A

TESTED MODULE IDENTIFICATION

Exact model, hardware and firmware scope.

The operator can correlate module identity and version information using the administrator guidance referenced by the Security Policy.

Model / part numberHardwareFirmwareProcessorForm
A2V1.2V1.3.02HSC32K2 with PAAWithout button
K9V1.0V1.3.02HSC32K2 with PAAWith button
K40V1.0V1.3.02HSC32K2 with PAAWith button
A4BV1.0V1.3.02HSC32K2 with PAAWith button
K49V1.0V1.3.02HSC32K2 with PAAWith button
K50V1.0V1.3.02HSC32K2 with PAAWith button
K28V1.0V1.3.02HSC32K2 with PAAWith button

VALIDATED SECURITY CHARACTERISTICS

What the public Security Policy documents.

Physical security

Production-grade enclosure and opaque, tamper-resistant epoxy over critical cryptographic components, with visible tamper evidence expectations.

Roles & authentication

Distinct Cryptographic Officer and User roles with identity-based authentication and no cryptographic service access before authorization.

Approved mode

One approved operating mode entered after power-up, with status indication.

SSP controls

Defined access modes, zeroization procedures and controls that prohibit plaintext CSP entry, output and storage.

Self-tests

Pre-operational and conditional self-tests, output inhibition during tests and error handling.

Lifecycle assurance

Secure manufacturing setup, delivery verification, administrator guidance and authenticated termination at end of life.

CERTIFICATE CAVEAT

Entropy and externally loaded SSP conditions remain part of the claim.

The certificate caveat states that generated SSP strengths are affected by available entropy and that no minimum security assurance is made for externally loaded SSPs or SSPs established with externally loaded SSPs.

CONTROLLED USE

Map the certificate to the exact product and deployment manifest.

Procurement and acceptance should verify certificate status, model, hardware version, firmware, approved mode, middleware and application compatibility.