eIDAS Compliance

FIPS 140-2

The dominant certification for cryptographic module, issued by NIST.

FIPS 140-2 Certified HSMs
  • About FIPS 140-2
  • Solutions
  • Related Products
  • Resources
About FIPS 140-2

About FIPS 140-2

The Federal Information Processing Standard (FIPS) 140-2 is issued by the National Institute of Standards and Technology (NIST) and specifies security requirements for cryptographic modules. The requirements cover areas related to the secure design and implementation of a cryptographic module. These areas include:

  • Cryptographic Module Specification
  • Ports and Interfaces
  • Roles, Services, and Authentication
  • Finite State Model
  • Physical Security
  • Operational Environment
  • Key Management
  • EMI / EMC
  • Self-Tests
  • Design Assurance
  • Mitigation of Other Attacks

FIPS 140-2 Security Levels

Based on the security requirements in the above areas, FIPS 140-2 defines four levels of security:

  • Level 1 is the lowest security level that can be applied to both soft- and hardware. It is characterized by the sole fact that it uses a cryptographic function.
  • Level 2 already has temper evidence as an additional security feature. This means that an attack may have been successful, but at least the fact that the secret has been divulged is known.
  • Level 3 devices are measured on tamper detection and response, identity-based authentication and enhanced protection of secret and private keys.
  • Level 4 devices are tamper resistant and provide environmental failure protection (with regard to voltage or temperature).

Solutions for FIPS 140-2

FIPS 140-2 Certified Hardware Security Modules

All Utimaco Hardware Security Modules (HSMs) are FIPS 140-2 Level 3 certified, with one model offering physical security compliant with FIPS 140-2 Level 4. Each HSM has been independently tested and certified to support your compliance needs. Certification for FIPS 140-3 Levels 3 and 4 is currently in progress for the u.trust General Purpose HSM Se-Series.

Related Products

Resources

Ready to Secure Your Digital Future?

Contact Sales

Wie können wir Ihnen helfen?

Sprechen Sie mit einem unserer Spezialisten und erfahren Sie, wie Utimaco Sie unterstützen kann.
You have selected two different types of downloads, so you need to submit different forms which you can select via the two tabs.

Your download request(s):

    By submitting below form you will receive links for your selected downloads.

    Your download request(s):

      For this type of documents, your e-mail address needs to be verified. You will receive the links for your selected downloads via e-mail after submitting below form.

      About Utimaco's Downloads

      Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).

      For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.

      Download via e-mail

       

      A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.