DES Validation Lists

Last Update: August 10, 2004

The purpose of this document is to provide technical information about implementations that have been validated as conforming to the Data Encryption Algorithm, as specified in Federal Information Processing Standard Publication 46-3, Data Encryption Standard (DES). The implementations below may consist of software, firmware, hardware, and any combination thereof. The National Institute of Standards and Technology (NIST) has made every attempt to provide complete and accurate information about the implementations described in this document. However, due to the possibility of changes made within individual companies, NIST cannot guarantee that this document reflects the current status of each product. It is the responsibility of the vendor to notify NIST of any necessary changes to its entry in any of the following lists.

Questions regarding implementations/products on these lists should first be directed to the appropriate vendor.


DES Modes of Operation Validated Implementations

(May 1996 - present)

The list below describes DES implementations which have been validated using the tests found in NIST Special Publication 800-17, Modes of Operation Validation System (MOVS): Requirements and Procedures , beginning in May 1996. The implementations are validated in accordance with FIPS 46-3 and FIPS 81, DES Modes of Operation. This testing is performed by NVLAP accredited Cryptographic Module Testing (CMT) laboratories. As of January 7, 2002 the following caveat will be listed on all new DES certificates: "Permitted for legacy systems only".

This list is ordered in reverse numerical order, by certificate number. Thus, the more recent validations are located closer to the top of the list. Also indicated after the date of validation are the modes and states for which the implementation was validated. DES modes are abbreviated as follows: Electronic Codebook (ECB), Cipher Block Chaining (CBC), Cipher Feedback (CFB), and Output Feedback (OFB). The two possible states for each mode are encryption(e) and decryption(d). The certificate issued to the vendor also indicates 1) the CMT laboratory that tested the implementation, and 2) the operating environment used to test the implementation (if software or firmware).

DES Validated Implementations
Cert# Vendor Implementation Operational Environment Val.
Date
Modes/Description
265 Forum Systems  
45 West 10000 South ,
Suite 415 ,
Sandy ,  Utah
84070
USA

- Terry Wise
TEL: 801-313-4400
FAX: 801-313-4401

Forum FIA Software Libraries
Version 4.0
Intel Xeon w/ Forum OS Version 4.1 8/4/2004

CBC(e/d)

" Forum FIA Gateway provides the foundation infrastructure that drives a return on investment by enabling secure XML and Web services communications for mission critical applications. These are the software algorithm implemenations utilized by the Forum FIA Gateway. "

264 IBM Corporation  
2455 South Road ,
Poughkeepsie ,  NY
12601
USA

- Walter Von Dehsen
TEL: 845-435-7521
FAX: 845-435-9270

IBM zSeries Cryptographic Assist DES, TDES, SHA-1
Part # 1.0
N/A 7/1/2004

ECB(e/d) ; CBC(e/d)

" The IBM zSeries CP Assist feature provides processor-integrated hardware acceleration for DES, TDES and SHA-1 services. "

263 Realia Technologies S.L.  
Orense, 68 11th floor ,
Madrid
28020
Spain

- Sebasti? Mu?z
TEL: +34 91 449 03 30
FAX: N/A

Cryptosec2048
Version 01.04.0004
Part # Model 1.0
N/A 6/23/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" The Cryptosec2048 is a high-end PCI card that provides cryptographic services and secure storage of cryptographic keys. The module is built to perform general cryptographic processing (RSA, DES, SHA-1, MD5,...) and features a tamper-protective case to physically protect sensitive information contained within the card. "

262 Aruba Wireless Networks Inc.  
180 Great Oaks Boulevard, Suite B ,
San Jose ,  CA
95119
USA

- Kenneth Jensen - Dir of Prod Mgmt
TEL: (408) 227-4500
FAX: N/A

Aruba WLAN Switching Platform Software Cryptographic Implementation
Version 5000 Series
600 MHz Pentium-3 w/ RedHat Linux 7.3, kernel version 2.4.18-3 6/15/2004

CBC(e/d)

" Aruba Wireless Networks?WLAN switching platform is a purpose-built WLAN voice and data switching solution designed to specifically address the needs and reduce the cost of large scale Wi-Fi network deployments for Government agencies and large enterprise. The Aruba Wireless Networks WLAN switching platform is a highly scalable and redundant solution that provides centralized intelligence to secure and manage the corporate RF environment, enforce identity based user security policies, enable service creation and provide secure mobility management to thousands of simultaneously connected users. "

261 Prism Payment Technologies (Pty) Ltd  
PO Box 901 ,
Witkoppen ,  Gauteng
2068
South Africa

- Wayne Donnelly
TEL: +27 (0) 11 5481000
FAX: +27 (0) 11 4673424

Incognito TSM410
Version 1.1.0.0 (Firmware)
Pentium III 450MHz 6/7/2004

ECB(e/d) ; CBC(e/d)

" The Incognito TSM410 is a multi-chip embedded Tamper Responsive Security Module. Fitted on a PCI carrier card, the device offers high-performance, high-security services targeted at EFT switches and mCommerce applications. "

260 Broadcom Corporation  
1131 W. Warner Rd. ,
Tempe ,  AZ
85284
USA

- Joseph Wallace
TEL: 480-753-2279
FAX: 480-753-2380

BCM5841
Part # A0
N/A 6/3/2004

CBC(e/d)

" The BCM5841 is a second generation multi-gigabit cryptographic coprocessor for VPN IPSec applications. "

259 F-Secure Corporation  
Tammasaarenkatu 7 ,
PL 24 ,
Helsinki
00181
Finland

- Alexey Kirichenko
TEL: +358 9 2520 5548

F-Secure?Cryptographic Library for Linux
Version 1.1
Intel P4 1.8 GHz w/ RedHat Enterprise Linux 3 AS; 1 GHz UltraSPARC IIIi w/ Solaris 8.0 5/10/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" The F-Secure?Cryptographic Library?for Linux is a 140-2 Level 1 compliant software module, which provides an assortment of cryptographic services including symmetric and asymmetric encryption, hash and HMAC computation, digital signing, key exchange, and pseudorandom number generation. "

258 Open Source Software Institute  
Stennis Space Center ,
Mississippi Technology Transfer Center ,
Building 1103, Room 135 F ,
Oxford ,  MS
39529
USA

- Ben Laurie
TEL: 44 (20) 8735 0686

- John Weathersby
TEL: 662-236-1794

OpenSSL FIPS Cryptographic Module
Version 1.0
HP D Class 9000 w/ HP-UX Release B.11.11; Linux Kernel Version: 2.4.21 w/ SuSE Linux 9.0 (x86) 5/10/2004

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

" The OpenSSL FIPS Cryptographic Module is a validated source code component of the standard OpenSSL distribution that can be downloaded from the http://openssl.org/ website. "

257 F-Secure Corporation  
Tammasaarenkatu 7 ,
PL 24 ,
Helsinki
00181
Finland

- Alexey Kirichenko
TEL: +358 9 2520 5548

F-Secure?Cryptographic Library for Windows
Version 2.1
Intel P4 1.6 GHz w/ Windows 2000 5/10/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" The F-Secure?Cryptographic Library for Windows is a 140-2 Level 2 compliant software module, implemented as a 32-bit Windows compatible DLL. The Module provides an assortment of cryptographic services to client processes that attach instances of the module DLL. "

256 Bioscrypt Inc.  
5450 Explorer Drive ,
Suite 500 ,
Mississauga ,  ON
L4W 5M1
Canada

- Doug Copeland
TEL: (905) 624-7720
FAX: (905) 624-7742

Bioscrypt Cryptographic Library (6711 DSP)
Version 1.00 (Firmware)
Texas Instruments TMS320C6711 DSP 5/10/2004

CBC(e/d)

" The Bioscrypt Cryptographic Library is used by Bioscrypt to provide developers with FIPS certified DES and Triple-DES solutions. "

255 Bioscrypt Inc.  
5450 Explorer Drive ,
Suite 500 ,
Mississauga ,  ON
L4W 5M1
Canada

- Doug Copeland
TEL: (905) 624-7720
FAX: (905) 624-7742

Bioscrypt Cryptographic Library (PC)
Version 1.00
Intel P4-1.8 GHz w/ Windows 2000 with SP2 5/10/2004

CBC(e/d)

" The Bioscrypt Cryptographic Library is used by Bioscrypt to provide developers with FIPS certified DES and Triple-DES solutions. "

254 SSP Litronic  
17862 Cartwright Rd. ,
Irvine ,  CA
92614
USA

- Brian Manahan
TEL: 949-851-1085
FAX: 949-851-8588

ARGUS/300 Software
Version V2.5 (Firmware)
ARGUS/300 Software PCI Board, Smartcard Reader and PC 4/27/2004

ECB(e/d) ; CBC(e/d)

" FIPS 140-1, Level 3 NIST/CEFMS Approved Electronic Signature System "

253 E.F. Johnson  
299 Johnson Ave. ,
PO Box 1249 ,
Waseca ,  MN
56093-0514
USA

- John Oblak
TEL: 507-835-6276

Subscriber Encryption Module DES
Version 3.3 (Firmware)
E. F. Johnson Portable Radios 4/19/2004

ECB(e/d) ; CBC(e/d) ; CFB1(e/d) ; OFB(e/d)

" This is the E.F. Johnson implementation of the DES algorithm. The modes of operation for this implementation are OFB, ECB, CBC and DES 1 bit CFB with differential encoding and decoding. This algorithm is used in the E.F. Johnson mobile and portable radios which contain the FIPS 140-2 validated Subscriber Encyption Module (SEM). "

252 RSA Security, Inc.  
2955 Campus Drive ,
Suite 400 ,
San Mateo ,  CA
94403
USA

- Kathy Kriese
TEL: 650-295-7692
FAX: 650-295-7700

- David Finkelstein
TEL: 650-295-7535
FAX: 650-295-7700

RSA BSAFE Crypto-J Software Module
Version 3.5
Pentium IV 1.4 GHz w/ Microsoft Windows XP 4/13/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" There are two variants of the Crypto-J module, one which implements an RSA Security-specific API [jsafeFIPS] and the other which implements the Java Cryptographic Extensions (JCE) API [jsafeJCEFIPS]. "

251 SonicWALL, Inc.  
1143 Borregas Ave. ,
Sunnyvale ,  CA
94089-1306
USA

- Paal Tveit
TEL: 408-745-9600
FAX: 408-745-9300

TZ 170
Version 2.0 Enhanced (Firmware)
Part # 101-5000072-00 rev A
SonicOS v2.0 Enhanced 4/13/2004

CBC(e/d)

" The TZ 170 is an internet security appliance with WAN interface, a flexible Optional interface, and a LAN interface incorporating a 5-port Fast-Ethernet switch. The TZ 170 provides stateful packet inspection firewall services, accelerated IPSec VPN, and bandwidth management, and can be upgraded to offer ISP failover and traffic. "

250 Lucent Technologies, Inc.  
600 Mountain Ave. ,
Murray Hill ,  NJ
07974
USA

- Richard T. Fohl
TEL: (716) 691 - 2715
FAX: (716) 691 - 2714

Lucent Secure Solutions SW Cryptographic Implementation
Version 2.0
Processor: Intel Pentium Xeon 2.4GHz; OS: LVF 7.1.189 4/1/2004

ECB(e/d) ; CBC(e/d)

" Lucent SW Cryptographic Implementation is used in Lucent Bricks. The VPN Firewall Brick is a high-speed packet-processing appliance, oriented towards providing security functions. The Bricks are carrier-grade integrated firewall and virtual private network (VPN) gateway appliance specifically designed for web/application data center security, large-scale managed security services, and remote access VPN services. Called the Brick because of its rugged, reliable design, this is an ideal platform for service providers seeking wide scalability, ready manageability, and industry-leading performance. "

249 Giesecke & Devrient America, Inc.  
45925 Horseshoe Drive ,
Dulles ,  VA
20166
USA

- Won J Jun
TEL: (703) 480-2145
FAX: (703) 480-2067

- Hassan Tavassoli
TEL: 703-480-2165

Sm@rtCaf?Expert FIPS 64K
Part # HD65246C1A05NB (Firmware Version:CH463JC_IRNABFOP003901_V101)
N/A 3/10/2004

ECB(e/d) ; CBC(e/d)

" Giesecke & Devrient (G&D) Smart Card Chip Operating System Sm@rtCaf?Expert FIPS 64K is a Java Card 2.2 and Open Platform v2.0.1' compliant smart card module. It supports, at a minimum, Triple-DES, AES, DSA, and RSA algorithms with on-card key generation. The Sm@rtCaf?Expert FIPS 64K is suitable for government and corporate identification, payment and banking, health care, and Web applications "

248 E.F. Johnson  
299 Johnson Ave. ,
PO Box 1249 ,
Waseca ,  MN
56093-0514
USA

- John Oblak
TEL: 507-835-6276

Communication Cryptographic Library DES
Version 2.0
Intel Pentium 4 w/ Windows XP SP 1a 4/16/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" This algorithm is used in the E.F. Johnson PC Keyloader - Key Encryption Programmer application. "

247 Nokia  
313 Fairchild Drive ,
Mt View ,  CA
94043
USA

- Robert Kusters
TEL: (650) 625-2940

Nokia HW Cryptographic Implementation
Part # NBB3350000
N/A 2/18/2004

CBC(e/d)

" The Nokia IP350 and IP380 are full-featured enterprise systems designed for small to medium enterprises, with Service Provider flexibility and rapid serviceability option in a single rack space. When combined with Check Point VPN-1/FW-1, these platforms provide reliable, easy to manage distributed security and access. "

246 Oberthur Card Systems  
3150 E. Ana Street ,
Rancho Dominguez ,  CA
90221
USA

- Christophe Goyet
TEL: 310-884-7953
FAX: 310-884-7904

ID-One Cosmo 72K RSA D
Version 0xE302 (Firmware)
JMX64 2/4/2004

ECB(e/d) ; CBC(e/d)

" The Oberthur Card Systems CosmopolIC 72K RSA Java Card Platform is a single chip cryptographic micro-processor smart card specifically designed for identity and government market needs, with a large memory (72KB), a highly secure architecture and several services and default applications in ROM for ISO 7816 File System, Biometry and Authentication. "

245 SonicWALL, Inc.  
1143 Borregas Ave. ,
Sunnyvale ,  CA
94089-1306
USA

- Paal Tveit
TEL: 408-745-9600
FAX: 408-745-9300

SonicWALL PRO 3060/4060
Version 2.0 (Firmware)
SonicOS v2.0 2/4/2004

CBC(e/d)

" The PRO 4060 and PRO 3060 are internet security appliances offering stateful packet inspection firewall services, accelerated IPSec VPN, bandwidth management, and dual-WAN port support with ISP failover and load-balancing capabilities, all via six configurable 10/100 Ethernet interfaces. "

244 Layer N Networks, Inc.  
12401 Research Blvd. ,
Bldg 2, Suite 275 ,
Austin ,  TX
78759

- Rick Hall
TEL: 512-250-2129 x135

UltraLock Cryptographic Module
Part # A1
N/A 1/14/2004

CBC(e/d)

" "The UltraLock?Cryptographic Module performs all the cryptography required for SSL/TLS applications. This module is a common element of the LNN2010 and LNN2025 UltraLock Security Processors, the industry's first single-chip solutions for completely off-loading SSL/TLS processing from host systems. The innovative in-line architecture combines TCP/IP termination and high-speed cryptography to transparently process SSL/TLS traffic at wire speed without impacting host system performance. Industry-standard GMII Ethernet connectivity allows UltraLock processors to drop easily into common networking and security platforms without special software development or complex hardware redesign, greatly reducing time to market." "

243 Blue Ridge Networks  
14120 Parke Long Court ,
Chantilly ,  VA
20151
USA

- Tom Gilbert
TEL: 703-631-0700
FAX: 703-631-9588

BG4000 Cryptographic Module
Part # BG4000
N/A 12/18/2003

ECB(e/d) ; CBC(e/d)

" The BG4000 and BG3140 are network security appliances for the construction of secure Virtual Private Networks between Internet sites, and between Internet sites and individual remote users. "

242 Mindspeed Technologies, Inc.  
4000 Mac Arthur Blvd. ,
Newport Beach ,  CA
92660
USA

- Elie Massabki
TEL: 949-579-3411
FAX: 949-579-7314

M826xx
Version 1 (Firmware)
RTXC 12/8/2003

ECB(e/d) ; CBC(e/d)

" M826xx is Communications Convergence Processor for Voice over IP (VoIP) and Voice over ATM (VoATM) applications. "

241 M/A-COM, Inc.  
221 Jefferson Ridge Parkway ,
Lynchburg ,  VA
24501
USA

- Daryl Popowitch

P7100/M7100 DES Algorithm
Version R4A (Firmware)
TI c5416 processor running on a Jaguar M7100 radio 11/26/2003

OFB(e/d)

" Implementation Description "

240 Enterasys Networks  
50 Minuteman Road ,
Andover ,  MA
01810
USA

- Damon Hopley
TEL: 978-684-1083

Enterasys Cryptographic Hardware
Part # SafeNet 1140; HW: Version 1.0
N/A 11/7/2003

CBC(e/d)

" Hardware cryptographic algorithm implementations for the XSR product line. "

239 Enterasys Networks  
50 Minuteman Road ,
Andover ,  MA
01810
USA

- Damon Hopley
TEL: 978-684-1083

Enterasys IR Cryptographic Library
Version 1.0
200MHz IBM PowerPC 405 GP w/ VxWorks 11/7/2003

CBC(e/d)

" Software cryptographic algorithm implementations for the XSR product line. "

238 Enterasys Networks  
50 Minuteman Road ,
Andover ,  MA
01810
USA

- Damon Hopley
TEL: 978-684-1083

Enterasys SSH Cryptographic Library
Version 1.0
200MHz IBM PowerPC 405 GP w/ VxWorks 11/7/2003

CBC(e/d)

" Software cryptographic algorithm implementations for the XSR product line. "

237 IBM Corporation  
2455 South Road ,
Poughkeepsie ,  NY
12601
USA

- Tamas Visegrady
TEL: 845-435-8512
FAX: 845-435-1858

UltraCypher 2 Crytographic Engine
Part # 1.0
N/A 10/23/2003

CBC(e/d)

" The IBM UltraCypher 2 Cryptographic Engine is a flexible, high performance subsystem that provides fast, ultra-secure, hardware-based cryptographic functionality. "

236 Hifn, Inc.  
750 University Avenue ,
Los Gatos ,  CA
95032
USA

- Glenn Haley
TEL: (408) 399-3545

7956
Part # 7956; Version 1.0
N/A 10/20/2003

ECB(e/d) ; CBC(e/d)

" The Hifn 7955 and 7956 are advanced security processors designed for high-speed T3/OC3, ROBO/SME networking applications like VPN Broadband Routers, wireless access points, VPN Edge Routers/Gateways, Firewall/VPN Appliances and other Network and Customer Premise Equipment (CPE). "

235 Hifn, Inc.  
750 University Avenue ,
Los Gatos ,  CA
95032
USA

- Prasad Shroff
TEL: (408) 399-3586

7814-W
Part # 7814-W
N/A 10/20/2003

ECB(e/d) ; CBC(e/d)

" Hifn Intelligent Packet Processing chips are full-duplex T3 to full-duplex OC-12, Integrated public key, 3DES, Advanced Encryption Standard (AES), and compression - the latest chips from Hifn have it all in a single high-performance package. "

234 3Com Corporation  
5500 Great America Parkway ,
Santa Clara ,  CA
95052
USA

- Victoria Van Spyk
TEL: 408-326-1581

3Com's IPSec Offload Integrated Circuit
Part # 40-0728-001
N/A 10/10/2003

ECB(e/d) ; CBC(e/d)

" 3Com's IPSec Offload Integrated Circuit is hardware based crypto device that performs IPSec (DES, TDES, SHA-1, MD5 and HMAC) computations on 3Com's series of Secure Network Interface Cards and Embedded Firewall products. "

233 SafeNet, Inc.  
8029 Corporate Drive ,
Baltimore ,  MD
21236
USA

- Joel Rieger
TEL: 443-442-8199

SafeXcel 1141/1741
Part # 11
N/A 9/30/2003

CBC(e/d)

" The SafeXcel 1141/1741 ASICs are part of the SafeNet IPsec co-processor chip family. The devices consist of an IPsec Packet Engine that performs DES, TDES, AES, SHA-1, MD5, header/trailer and insertion/deletion operations, a Public Key Accelerator that performs RSA, DSA, and DH operations using long vector math up to 2048 bits, and a Random Number Generator that provides up to 2 Mbps of random data. "

232 IDT  
2975 Stender Way ,
Santa Clara ,  CA
95054
USA

- Alex Soohoo
TEL: 408-330-1714
FAX: 408-330-1748

RC32365
Part # ZA
N/A 9/16/2003

ECB(e/d) ; CBC(e/d)

" The Interprise Access RC32365 is an integrated communications processor that addresses the secure SOHO wired/wireless gateway and VPN/firewall appliance markets by incorporating a high-performance CPU, an on-chip security engine and key peripheral interfaces. "

231 F-Secure Corporation  
Tammasaarenkatu 7 ,
PL 24 ,
Helsinki
00181
Finland

- Alexey Kirichenko
TEL: +358 9 2520 5548

F-Secure(R) Cryptographic Library ?
Version 2.1
Intel P4 1.6 GHz w/ Windows 2000s 8/27/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" The F-Secure Cryptographic Library for Windows is a 140-2 Level 2 compliant software module, implemented as a 32-bit Windows compatible DLL. The module provies an assortment of cryptographic services to client processes that attach instances of the module DLL. "

230 Microsoft Corporation  
One Microsoft Way ,
Redmond ,  WA
98052-6399
USA

- Mike Lai

Windows 2003 Kernel Mode Cryptographic Module (fips.sys)
Version 5.2.3790.0
Athlon 800 Mhz w/ Windows 2003 .Net Server 8/19/2003

ECB(e/d) ; CBC(e/d)

" Kernel level .sys module exporting cryptographic functionality. "

229 Microsoft Corporation  
One Microsoft Way ,
Redmond ,  WA
98052-6399
USA

- Mike Lai

Windows 2003 Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH)
Version 5.2.3790.0
AMD Athlon 900Mhz w/ Windows 2003 8/5/2003

ECB(e/d) ; CBC(e/d)

" The Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider is a FIPS 140-2 compliant, software-based, cryptographic module.RSAENH encapsulates several different cryptographic algorithms (including SHA-1, DES, 3DES, DSA, SHA-1-based HMAC) in a cryptographic module accessible via the Microsoft CryptoAPI. "

228 Research in Motion  
295 Phillip Street ,
Waterloo ,  Ontario
N2L 3W8
Canada

- Ian Robertson
TEL: 519-888-7465
FAX: 519-883-4924

BlackBerry Cryptographic API
Version 3.6
ARM 7 Processor running BlackBerry OS 7/14/2003

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

" BlackBerry?is the leading wireless enterprise solution that allows users to stay connected with secure, wireless access to email, corporate data, phone, web and organizer features. BlackBerry?is a totally integrated package that includes hardware, software and service, providing a complete end-to-end solution. The BlackBerry?Cryptographic API provides advanced cryptographic functionality for the BlackBerry? "

227 Schlumberger  
8311 North FM 620 Rd. ,
Austin ,  TX
78726
USA

- Mike Neumann
TEL: 512-257-3848
FAX: 512-257-3881

Cyberflex Access 64K V2
Part # M516LACC2 Hardmask 1V1 Softmask 2V1
JavaCard 2.1.1 Runtime Environment 7/14/2003

ECB(e/d) ; CBC(e/d)

" The Cyberflex Access 64K V2 smart card can be employed in solutions which provide secure PKI (public key infrastructure) and digital signature technology. Cyberflex Access 64K V2 serves as a highly portable, secure token for enhancing the security network access and ensuring secure electronic communications. "

226 Microsoft Corporation  
One Microsoft Way ,
Redmond ,  WA
98052-6399
USA

- Mike Lai

Windows 2003 Enhanced Cryptographic Provider (RSAENH)
Version 5.2.3790.0
Intel Pentium 4 w/ Windows 2000 Professional 6/30/2003

ECB(e/d) ; CBC(e/d)

" The Microsoft Enhanced Cryptographic Provider is a FIPS 140-2 compliant, software-based, cryptographic module.RSAENH encapsulates several different cryptographic algorithms (including SHA-1, DES, 3DES, AES, RSA, SHA-1-based HMAC) in a cryptographic module accessible via the Microsoft CryptoAPI. "

225 Sun Microsystems  
4150 Network Circle ,
Santa Clara ,  CA
95054
USA

- Javier Lorenzo
TEL: (858) 625-6020

- Irfan Khan
TEL: 510.936.4840

Sun Crypto Accelerator 4000
Version 1.0 (Hardware)
Part # X4011A Sun Crypto Accelerator 4000 - Copper
N/A 6/25/2003

CBC(e/d)

" Cryptographic Acceleration Card "

224 IBM  
11400 Burnet Rd ,
Austin ,  TX
78758
USA

- Tom Benjamin
TEL: 512.436.1223
FAX: 512.436.8009

IBM Java JCE 140-2 Cryptographic Module
Version 1.0
PowerPC Power3 processor w/ AIX 5.2 6/19/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" The IBM?Java?JCE (Java Cryptographic Extension) FIPS provider (IBMJCEFIPS) for Multi-platforms is a scalable, multi-purpose cryptographic module that supports only FIPS approved cryptographic operations via the Java2 Application Programming Interfaces (APIs). "

223 Bluesocket, Inc.  
7 New England Executive Park ,
Burlington ,  MA
01803
USA

- Mike Puglia
TEL: (781) 328-0888
FAX: (781) 328-0899

Bluesocket Wireless Gateway IPSec
Version Broadcom BCM5823
Part # BCM5823KPB
N/A 6/10/2003

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

" The Bluesocket Wireless Gateway IPSec implementation performs IPSec security services for the Bluesocket Wireless Gateway. "

222 Pitney Bowes, Inc.  
35 Waterview Drive ,
Shelton ,  CT
06484
U.S.A.

- Douglas Clark
TEL: 203.924.3500
FAX: 203.924.3406

Pitney Bowes iButton Postal Security Device (PSD)
Part # DS1955B PB0 1.00c
N/A 6/6/2003

ECB(e/d)

" The Pitney Bowes iButton Postal Security Device (PSD) has been designed in compliance with the United States Postal Service (USPS), Information-Based Indicia Program (IBIP). It employs strong encryption, decryption, and digital signature techniques for the protection of customer funds and the production of postage meter indicia in a variety of Pitney Bowes Metering products. The PSD has been designed to support international postal markets and their evolving requirements for digital indicia. "

221 E.F. Johnson  
299 Johnson Ave. ,
PO Box 1249 ,
Waseca ,  MN
56093-0514
USA

- John Oblak
TEL: 507-835-6276

Subscriber Encryption Module
Version 1.0
EF Johnson Portable Radios 5/7/2003

ECB(e/d) ; CBC(e/d) ; CFB1(e/d) ; OFB(e/d)

" The Subscriber Encryption Module (SEM) is a cryptographic module which supports the AES, DES, DSA, and SHA-1 algorithms. The SEM is used in subscriber equipment such as the E.F. Johnson radios to provide secure, encrypted voice and data communication. "

220 IBM Zurich Research Laboratory  
Saeumerstrasse 4 ,
Rueschlikon ,  CH
8803
Switzerland

- Michael Osborne
TEL: (41) (1) 724 8458
FAX: (41) (1) 724 8953

IBM CryptoLite in C
Version 3.0 (FIPS140/Prod)
Pentium III w/ Windows 2000 Professional 4/18/2003

ECB(e/d) ; CBC(e/d)

" IBM CryptoLite is a C software package providing advanced Cryptographic services in a very small footprint. CryptoLite supports public key encryption, digital signatures, symmetric ciphers, hash functions, message authentication codes, and other cryptographic algorithms through a simple programming interface. There are no runtime dependencies and the code has been optimized for high performance. "

219 Nauticus Networks  
200 Crossing Boulevard ,
Framingham ,  MA
01702
USA

- Matt Rollender, Director of Marketing
TEL: 508.270.0500

N2000 Series Switch
Version 1.0
PowerPC 440 w/ OSE 4.4.1 4/7/2003

CBC(e/d)

" Nauticus Networks N2040 and N2120 are purpose built application switches that enable cost effective, reliable, deployment of intergrated network and security services, delivering gigabit scaled Layer 5-7 application switching, Layer 4 load balancing, and SSL acceleration to the most demanding enterprise and service provider environments. "

218 M/A-COM, Inc.  
221 Jefferson Ridge Parkway ,
Lynchburg ,  VA
24501
USA

- Mr. Stefan Backstrom
TEL: (434) 455-6600
FAX: (434) 455-6851

Orion C57
Version DSP R2B
N/A 4/2/2003

OFB(e/d)

" The Orion C57 is used with the EDACS ProVoice Orion Mobile with FIPS 140-2 security level 1 validation. Digital voice, conventional and trunked; system and scan front mounting. "

217 Hifn, Inc.  
750 University Avenue ,
Los Gatos ,  CA
95032
USA

- Prasad Shroff
TEL: (408) 399-3586

8154PB5
Version Rev 1.0
Part # 8154PB5
N/A 3/23/2003

ECB(e/d) ; CBC(e/d)

" Hifn Intelligent Packet Processing chips are full-duplex T3 to full-duplex OC-12, Integrated public key, 3DES, Advanced Encryption Standard (AES), and compression - these latest chips from Hifn have it all in a single high-performance package. "

216 IBM Corporation  
3901 S. Miami Blvd. ,
Durham ,  NC
27703
USA

- Mike Allen

IBM Crypto for C
Version 0.1
AMD Athlon 900 Mhz processor w/ Windows 2000 Professional 3/20/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" The ICC is a C language implementation of cryptographic functions which uses the cryptograhic library provided by the OpenSSL project. This enables IBM products to use an open source solution for cryptography and a FIPS 140-2 certificate cryptographic provider. "

215 Oracle Corporation  
500 Oracle Parkway ,
Redwood Shores ,  CA
94065
USA

- Lakshmi Kethana
TEL: (650) 506-9315

Oracle Crypto Library for SSL
Version 9.0.4
Sun Solaris 8.0 on Dual UltraSPARC 64-bit 300MHz CPU 3/6/2003

CBC(e/d)

" The Cryptographic Library for SSL is a generic module used in a variety of Oracle application suites. It provides support for cryptography, authentication, PKCS and certificate management for applications like the Oracle database (Server & Client), Oracle Applications Server, Oracle Internet Directory, Web Cache and Apache. "

214 LSI Logic Corporation  
1778 McCarthy Blvd. ,
Milpitas ,  CA
95035
USA

- Dan Watkins
TEL: 408-433-7105
FAX: 408-433-7447

SC2005 (DirecTV DES descrambler)
Part # Version F
N/A 3/6/2003

ECB(d only)

" The des module is part of LSI Logic's extensive line of Coreware modules for ASIC development. "

213 LSI Logic Corporation  
1778 McCarthy Blvd. ,
Milpitas ,  CA
95035
USA

- Dan Watkins
TEL: 408-433-7105
FAX: 408-433-7447

SC2005 (TDES/DES engine)
Part # Version F
N/A 3/6/2003

ECB(e/d)

" The DES and TDES modules are part of LSI Logic's extensive line of Coreware modules for ASIC development. "

212 Cisco Systems, Inc  
7025-6 Kit Creek Road ,
PO Box 14987 ,
Research Triangle Park ,  NC
27709-4987
USA

- Ray Potter
TEL: 919-392-6789

VPN Client
Version 3.6.3B
Pentium IV w/ Windows 2000 SP2 2/20/2003

CBC(e/d)

" The Cisco VPN Client enables you to establish secure, end-to-end encrypted tunnels. The client can be pre-configured for mass deployments and initial logins require very little user intervention. VPN access policies and configurations are downloaded from the central gateway and pushed to the client when a connection is established, allowing simple deployment and management, as well as high scalability. "

211 TANDBERG Telecom AS  
Philip Pedersens vei 22 ,
P.O. Box 92, 1325 ,
LYSAKER ,  NORWAY
NORWAY

- Tor Erik Pedersen
TEL: +47 67 125 125

TT_Encryption
Version 1.0
Pentium III w/ Windows 2000 2/20/2003

ECB(e/d)

" a software cryptographic service library, used by all TANDBERG Videoconferencing systems. This software library provides encryption of video, voice and data in point-to-point and multipoint calls, over circuit-switched (ISDN, H.320) and packet-based (IP, H.323) networks according to the ITU H.233 and H.235 standards. "

210 Cisco Systems, Inc  
7025-6 Kit Creek Road ,
PO Box 14987 ,
Research Triangle Park ,  NC
27709-4987
USA

- Ray Potter
TEL: 919-392-6789

VPN 3000 Concentrator Series
Version 3.6
Motorola PPC740, VPN3015, pSOS+ 2/13/2003

CBC(e/d)

" The Cisco VPN 3000 Concentrator Series is a best-of-breed, remote-access VPN solution for enterprise-class deployment. The validation includes hardware models 3005, 3015, 3030, 3060, 3080 and the 3002 hardware client. "

209 Colubris Networks Inc.  
420 Armand-Frappier (suite 200) ,
Laval ,  Quebec
H7V 4B4
Canada

- St?hane Laroche
TEL: (450) 680-1661 x123
FAX: (450) 680-1910

Libfips
Version 1.0
Motorola MPC855T PowerQUICC 2/4/2003

ECB(e/d) ; CBC(e/d)

" Colubris CN105x Secure Wireless LAN Router enables strong security for wireless enterprise networking, using embedded IPSec VPN and firewall functionalities. Lipfips is the User mode implementation in the CN1050 and CN1054 Wireless LAN Routers. "

208 IBM Zurich Research Laboratory  
Saeumerstrasse 4 ,
Rueschlikon ,  CH
8803
Switzerland

- Michael Osborne
TEL: (41) ( 1 ) 724 8458
FAX: (41) (1) 724 8953

IBM CryptoLite in Java
Version 3.0 (FIPS140/Prod)
Pentium III w/ Windows 2000 1/30/2003

ECB(e/d) ; CBC(e/d)

" IBM CryptoLite is a 100% Java software package providing advanced cryptographic services in a very small footprint. CryptoLite supports public key encryption, digital signatures, symmetric ciphers, hash functions, message authentication codes, and other cryptographic algorithms through a simple programming interface. There are no runtime dependencies and the code has been optimized for high performance. It runs on JDK 1.1 or higher. "

207 SSH Communications Security Corp  
Fredrikinkatu 42 ,
Helsinki
00100
Finland

- Markus Levlin
TEL: +358 20 500 7518
FAX: +358 20 500 7390

SSH CryptoLib
Version 1.0
Pentium III w/ Redhat Linux 7.3 1/30/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" The SSH Cryptographic Library is a standards-based shared library providing FIPS 140-2 certified cryptographic services for SSH Communications Security's security products. The library provides a rich API and a comprehensive set of state-of-the-art algorithms including AES, 3DES, SHA-1, HMAC, RSA and DSA. "

206 Hifn, Inc.  
750 University Avenue ,
Los Gatos ,  CA
95032
USA

- Prasad Shroff
TEL: (408) 399-3586

7814-WPB4
Version 1.0
Part # 7814-WPB4
N/A 1/17/2003

ECB(e/d) ; CBC(e/d)

" Hifn Intelligent Packet Processing chips are full-duplex T3 to full-duplex OC-12, Integrated public key, 3DES, Advanced Encryption Standard (AES), and compression - these latest chips from Hifn have it all in a single high-performance package. "

205 D'Crypt Pte Ltd  
20 Ayer Rajah Crescent ,
#08-08 Technopreneur Centre ,
Singapore
139964
Singapore

- Quek Gim Chye
TEL: (65)6776-9210

d'Cryptor QE Firmware
Version 2.0
D'Crypt Secure Micro O/S v3.0 1/17/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" The d'Cryptor QE is a multi-chip embedded security module designed for high security assurance applications. It comprises a secure high-performance cryptographic core, generous memory in the form of a Flash ROM and NVRAM, and implements physical security through an opaque, hard epoxy potting and a tamper detection and response mesh. The QE firmware builds in a wide range of cryptographic support and accepts a user-programmable external application. Cryptographic services are provided through a library and an API. All keys and cryptographic processing are isolated within this library and accessible only through the API. "

204 Hifn, Inc.  
750 University Avenue ,
Los Gatos ,  CA
95032
USA

- Prasad Shroff
TEL: (408) 399-3586

7854PB4/3
Version 3.0
Part # 7854PB4/3
N/A 1/17/2003

ECB(e/d) ; CBC(e/d)

" Hifn Intelligent Packet Processing chips are full-duplex T3 to full-duplex OC-12, Integrated public key, 3DES, Advanced Encryption Standard (AES), and compression - these latest chips from Hifn have it all in a single high-performance package. "

203 SonicWALL, Inc.  
1143 Borregas Ave. ,
Sunnyvale ,  CA
94089-1306
USA

- Paal Tveit
TEL: 408-745-9600
FAX: 408-745-9300

Cisco CSS Series 11000 Secure Content Accelerator/SonicWALL SSL-RX
Version 4.1 (firmware)
MaxOS v4.1 1/17/2003

CBC(e/d)

" The SCA2/SSL-RX is an SSL proxy device designed for SSL acceleration and offloading. The SCA2/SSL-RX provides the ability to both terminate and initiate SSL connections, converting cipher-text to clear-text, or clear-text to cipher-text. "

202 Cisco Systems, Inc  
7025-6 Kit Creek Road ,
PO Box 14987 ,
Research Triangle Park ,  NC
27709-4987
USA

- Ray Potter
TEL: 919-392-6789

Cisco IOS Encryption Software
Version 12.2
Cisco 172 Modular Access Router, Motorola MPC860P 1/17/2003

CBC(e/d)

" Cisco IOSR Software, the industry-leading and most widely deployed network system software, delivers intelligent network services on a flexible networking infrastructure that enables the rapid deployment of Internet applications. "

201 Broadcom Corporation  
1131 W. Warner Rd. ,
Tempe ,  AZ
85284
USA

- Joe Wallace
TEL: 480-753-2279

BCM5840
Part # B3
N/A 12/10/2002

CBC(e/d)

" The BCM5840 delivers multi-gigabit performance for IPSec VPN applications. "

200 Giesecke & Devrient America, Inc.  
45925 Horseshoe Drive ,
Dulles ,  VA
20166
USA

- Won J. Jun
TEL: (703) 480-2145
FAX: (703) 480-2067

STARCOS SPK 2.4 in ID-1 module
Part # CP5WxSPKI24-01-3-S V0310
N/A 12/2/2002

CBC(e/d)

" Giesecke & Devrient (G&D) Smart Card Chip Operating System Standard Version with Public Key Extension 2.4 (STARCOS SPK 2.4) is a scaleable multi-application operating system for smart cards and provides functionalities that are necessary for public key infrastructure. "

199 Aladdin Knowledge Systems, Ltd.  
15 Beit Oved Street ,
Tel Aviv
61110
Israel

- Leedor Agam
TEL: (972) 3 636 5124
FAX: (972) 3 537 5796

eToken Pro 32K (Cryptographic Engine)
Version 4.2
N/A 11/26/2002

ECB(e/d) ; CBC(e/d)

" The eToken PRO is a fully portable USB device the size of an average house key which offers a cost-effective method for authenticating users when accessing a network and for securing electronic business applications. The eToken PRO offers security needs such as secure network logon, secure VPN's, secure email, and strong PKI support. "

198 Aladdin Knowledge Systems, Ltd.  
15 Beit Oved Street ,
Tel Aviv
61110
Israel

- Leedor Agam
TEL: (972) 3 636 5124
FAX: (972) 3 537 5796

eToken Pro 16K (Cryptographic Engine)
Version 4.1
N/A 11/26/2002

ECB(e/d) ; CBC(e/d)

" The eToken PRO is a fully portable USB device the size of a house key which offers a cost-effective method for authenticating users when accessing a network and for securing electronic business applications. The eToken PRO offers security needs such as secure network logon, secure VPN's, secure email, and PKI support. "

197 IBM Zurich Research Laboratory  
Saeumerstrasse 4 ,
Rueschlikon ,  CH
8803
Switzerland

- Michael Osborne
TEL: (41) ( 1 ) 724 8458
FAX: (41) ( 1 ) 724 8953

JCOP21id 32K
Version JCOP21id Mask 20 (firmware)
Part # P8WE5033 AEV 1034 188i
Philips P8WE5033 11/14/2002

ECB(e/d) ; CBC(e/d)

" The JCOP21id is IBM's multi-application smart card, designed to the Java Card v2.1.1 and Global Platform v2.0.1 specifications. The smart card features IBM's PKCS#15 applet which provides standardized high-level security services including, 2048 bit key generation, DES, 3DES, SHA, RSA and AES. "

196 Wei Dai  
Groove Networks, Inc. ,
100 Cummings Center ,
Suite 535Q ,
Beverly ,  MA
01915
USA

- Wei Dai
TEL: (978)720-2173
FAX: (978)720-2001

Crypto++ Library
Version 5.01
Pentium III w/ Windows 2000 11/14/2002

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

" The Crypto++ Library is a free, open source C++ class library providing public key encryption, digital signatures, symmetric ciphers, hash functions, message authentication codes, and other cryptographic algorithms. The pre-compiled Win32 static library is FIPS 140-2 Level 1 validated. The library is also available in source code form. "

195 Phaos Technology Corporation  
11 Broadway ,
Suite 501 ,
New York ,  NY
10004
USA

- Darren Calman
TEL: (212) 514-6515
FAX: (212) 514-6528

Phaos Crypto
Version 3.0
Pentium III w/ Windows 2000 11/6/2002

ECB(e/d) ; CBC(e/d)

" Phaos Crypto provides a state-of-the-art set of core cryptography algorithms in Java. It includes a comprehensive cryptographic library supporting the most current algorithms like AES, RSA-OAEP, SHA-256/384/512, X.9-42 as well as legacy algorithms that are still used in corporate systems like 3DES, DES, MD2 etc.. Phaos Crypto allows developers to integrate cryptography into any Java application or applet. For high security deployments, Phaos Crypto provides transparent migration to cryptographic hardware without requiring any changes to existing applications. "

194 Stonesoft Corporation  
It?ahdenkatu 22A , ,  Helsinki
FIN-00210
Finland

- Klaus Majewski
TEL: (678) 259-3411

StoneGate High Availability Firewall and VPN implementation of SSH Toolkit Library
Version 4.1.1-22
Pentium III w/ GNU/Linux 10/31/2002

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

" StoneGate is a firewall and VPN solution. It features clustering, load balancing between multiple ISPs, encrypted VPN client connectivity and advanced central administration tools. "

193 Datakey, Inc.  
407 W. Travelers Trail ,
Burnsville ,  MN
55337-2554
USA

- Hazem Hassan
TEL: (952) 890-6850

Model 330J with JCCOS applet
Version 2.0
Philips P8WE5033 10/24/2002

ECB(e/d) ; CBC(e/d)

" The Model 330J is Datakey's multi-application smart card, designed to the JavaCard v2.1.1 and Global Platform v2.0.1 specifications. The smart card features Datakey's JCCOS applet. JCCOS is an advanced cryptographic applet that, when loaded onto a multi-application JavaCard provides high-level security services. "

192 SchlumbergerSema  
50 avenue Jean Jaures ,
Montrouge Cedex
92542
FRANCE

- Bruno Blanchard
TEL: +33 1 46007456

Cyberflex Access e-Gate 32K
Version M256LCAEG1_ST_62_02_03, SM3v1
Part # ST19XT34
N/A 10/24/2002

ECB(e/d) ; CBC(e/d)

" Cyberflex Access e-Gate 32K smart card serves as a highly portable, secure token for enhancing the security of network access and ensuring secure electronic communications, supporting on-card DES aND RSA algorithms with on-card key generation. "

191 IBM Corporation  
CC1A/502/K301 ,
4205 S. Miami Blvd. ,
Durham ,  NC
27703
USA

- Keith Medlin
TEL: +1-919-543-2014
FAX: +1-919-486-0675

IBM Everyplace Wireless Gateway Cryptographic Module
Version 1.5
Trusted Solaris 8, UltraSparc-II 400 MHz; Pentium III w/ Windows 2000 SP3 10/24/2002

ECB(e/d) ; CBC(e/d)

" The IBM Everyplace Wireless Gateway is a distributed, scalable, multipurpose communications platform that supports optimized, secure data access over a wide range of international wireless and wire line network technologies. The cryptographic module implements a variety of encryption services for the product. "

190 Entrust, Inc.  
1000 Innovation Drive ,
Ottawa ,  Ontario
K2K 3E7
Canada

- Pierre Boucher
TEL: 613-270-2599
FAX: 613-270-2504

Entrust Authority Toolkit for Java
Version 6.1
Intel Pentium II w/ Windows 2000 SP3 10/7/2002

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

" The Security Toolkit for Java takes advantage of the features of a Public Key Infrastructure (PKI) from a Java environment. The Toolkit provides the means to incorporate security features, such as encryption and digital signatures, into applications. "

189 Motorola  
200 North Point Center East ,
Suite 400 ,
Alpharetta ,  GA
30022
USA

- Alfred Adler
TEL: 770-521-5128
FAX: 770-521-8066

Encryption DLL Module
Version 3.0
Intel Pentium III w/ Windows NT 4.0 10/1/2002

ECB(e/d) ; CBC(e/d)

" The Encryption DLL Module is incorporated into the Motorola Messaging Server, an enterprise system for managing data between a corporate e-mail or database system and a wireless device, and the Motorola MyMail Desktop Plus, a personal application to manage e-mail between the desktop and a wireless device. "

188 Motorola  
200 North Point Center East ,
Suite 400 ,
Alpharetta ,  GA
30022
USA

- Christopher Yasko
TEL: (770)521-5150
FAX: (770)521-8067

Encryption Services Module
Version 5.3
Intel Pentium III w/ Windows 2000 Pro 10/1/2002

ECB(e/d) ; CBC(e/d)

" The Encryption Services Module is incorporated into the operating software of the Accompli 009 -- the first wireless communications device to incorporate tri-band GSM and GPRS protocols, phone functionality, Internet access, e-mail, Triple-DES encryption, WAP browser and short message service (SMS) with a full QWERTY keyboard and 256-color screen. "

187 ASN Technology Corp.  
3th Fl., No. 22, Lane 31, Sec. 1, Hyandung Rd. ,
744 Tainan Science-Based Industrial Park ,
Tainan
Taiwan

- Jeng-Yang Hwang (Eric Hwang)
TEL: 886-6-6009636 ext 200

ASN eShield Cryptor Encryption/Decryption Processor Chip
Part # TAD0704-a
N/A 9/17/2002

ECB(e/d)

" ASN eShield Cryptor Encryption/Decryption Processor (TAD0704-a) is a cryptographic chip designed for system flexibility to ease secure system implementations. It is a ciphering engine supporting the Advanced Encryption Standard (AES), Data Encryption Standard (DES) and Triple-DES encryption/decryption algorithms. The chip performs AES, DES and Triple-DES at 30 MHz with 16bits I/O interface. &