The purpose of this document is to provide technical information about implementations that have been validated as conforming to the Triple Data Encryption Algorithm (TDEA, a.k.a. "Triple DES"), as specified in Federal Information Processing Standard Publication 46-3, Data Encryption Standard (DES). For the complete specification of Triple DES, the standard ANSI X9.52-1998, Triple Data Encryption Algorithm Modes of Operation, must be used in conjunction with FIPS 46-3.
The list below describes Triple DES implementations which have been validated as correctly implementing the TDEA, using the tests found in NIST Special Publication 800-20, Modes of Operation Validation System for the Triple Data Encryption Algorithm (TMOVS): Requirements and Procedures. This testing is performed by NVLAP accredited Cryptographic Module Testing (CMT) laboratories.
The implementations below consist of software, firmware, hardware, and any combination thereof. The National Institute of Standards and Technology (NIST) has made every attempt to provide complete and accurate information about the implementations described in this document. However, due to the possibility of changes made within individual companies, NIST cannot guarantee that this document reflects the current status of each product. It is the responsibility of the vendor to notify NIST of any necessary changes to its entry in the following list. A validation certificate issued to each vendor also indicates 1) the CMT laboratory that tested the implementation, and 2) the operating environment used to test the implementation (if software or firmware).
This list is ordered in reverse numerical order, by certificate number. Thus, the more recent validations are located closer to the top of the list. Also indicated after the date of validation are the modes (e.g., TECB, TCFB, etc.), states ( encryption(e) and/or decryption(d) ), and keying options (KO) for which the implementation was validated:
| Triple DES Modes of Operation | Triple DES Keying Options (KO) |
|---|---|
| TECB = TDEA Electronic Codebook TCBC = TDEA Cipher Block Chaining TCBC-I = TDEA Cipher Block Chaining - Interleaved TCFB = TDEA Cipher Feedback TCFB-P = TDEA Cipher Feedback - Pipelined TOFB = TDEA Output Feedback TOFB-I = TDEA Output Feedback - Interleaved |
KO 1 = Three-key Triple DES KO 2 = Two-key Triple DES KO 3 = Single DES |
For TCFB and TCFB-P, the number of feedback bits is specified.
The following mode/keying option combinations are backwards compatible with their corresponding single DES modes: TECB (KO 3), TCBC (KO 3), TCFB (KO 3), TOFB (KO 3).
| Cert# | Vendor | Implementation | Operational Environment | Val. Date |
Modes/Keying Opts./ Description |
|---|---|---|---|---|---|
| 267 |
Forum Systems
45 West 10000 South , Suite 415 , Sandy , Utah 84070 USA -
Terry Wise
|
Forum FIA Software Libraries
Version 4.0 |
Intel Xeon w/ Forum OS Version 4.1 | 8/4/2004 | TCBC(e/d; KO 1,2,3) " Forum FIA Gateway provides the foundation infrastructure that drives a return on investment by enabling secure XML and Web services communications for mission critical applications. These are the software algorithm implemenations utilized by the Forum FIA Gateway. " |
| 266 |
Symantec Corporation
One Old Oyster Point Road , Suite 300 , Newport News , VA 23602 USA -
Cecilia C. Holmes-Addison
|
Symantec Cryptographic Module
Version 1.0 |
Dual Xenon 2.66 GHZ, Microsoft Windows XP Professional, SP1 | 7/15/2004 | TECB(e/d; KO 1,2,3) " The Symantec Cryptographic Module is a software library that contains FIPS-approved cryptographic algorithms. This module provides encryption functionality for selected Symantec products. " |
| 265 |
Kasten Chase Applied Research, Ltd.
5100 Orbitor Drive , Mississauga , Ontario L4W 4Z4 Canada -
Steve Demmery
|
KCCE Triple DES
Version 2.0 |
x86 Linux | 7/7/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " KCCE is an independent, executable cryptographic module that exists variously as a dynamic linked library (dll), a shared library and a driver. KCCE provides software designers with a comprehensive API that ensures secure cryptographic application development, for a wide range of operating systems, without undue complexity. " |
| 264 |
IBM Corporation
2455 South Road , Poughkeepsie , NY 12601 USA -
Walter Von Dehsen
|
IBM zSeries Cryptographic Assist DES, TDES, SHA-1
Part # 1.0 |
N/A | 7/1/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The IBM zSeries CP Assist feature provides processor-integrated hardware acceleration for DES, TDES and SHA-1 services. " |
| 263 |
V-ONE Corporation
20300 Century Blvd. , Suite 200 , Germantown , MD 20874 USA -
Chris Brook
|
SmartGate
Version 4.5 |
Sun Solaris 2.6 | 7/6/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3) " Client/server Virtual Private Network (VPN) software that provides enterprise-level security to network-based users for private information and private TCP/IP application services. SmartGate provides encryption, strong user authentication, authorization, management, accounting, key distribution, and proxy capabilities. " |
| 262 |
Realia Technologies S.L.
Orense, 68 11th floor , Madrid 28020 Spain -
Sebasti? Mu?z
|
Cryptosec2048
Version 01.04.0004 Part # Model 1.0 |
N/A | 6/23/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3) " The Cryptosec2048 is a high-end PCI card that provides cryptographic services and secure storage of cryptographic keys. The module is built to perform general cryptographic processing (RSA, DES, SHA-1, MD5,...) and features a tamper-protective case to physically protect sensitive information contained within the card. " |
| 261 |
Aruba Wireless Networks Inc.
180 Great Oaks Boulevard, Suite B , San Jose , CA 95119 USA -
Kenneth Jensen - Dir of Prod Mgmt
|
Aruba 5000 WLAN Switching Platform Hardware Cryptographic Implementation
Version CN1000-MC-Main-IPsec-1.0 Part # 1000199-01 |
N/A | 6/15/2004 | TCBC(e/d; KO 1,2,3) " Aruba Wireless Networks?WLAN switching platform is a purpose-built WLAN voice and data switching solution designed to specifically address the needs and reduce the cost of large scale Wi-Fi network deployments for Government agencies and large enterprise. The Aruba Wireless Networks WLAN switching platform is a highly scalable and redundant solution that provides centralized intelligence to secure and manage the corporate RF environment, enforce identity based user security policies, enable service creation and provide secure mobility management to thousands of simultaneously connected users. " |
| 260 |
Aruba Wireless Networks Inc.
180 Great Oaks Boulevard, Suite B , San Jose , CA 95119 USA -
Kenneth Jensen - Dir of Prod Mgmt
|
Aruba WLAN Switching Platform Software Cryptographic Implementation
Version 5000 Series |
600 MHz Pentium-3 w/ RedHat Linux 7.3, kernel version 2.4.18-3 | 6/15/2004 | TCBC(e/d; KO 1,2,3) " Aruba Wireless Networks?WLAN switching platform is a purpose-built WLAN voice and data switching solution designed to specifically address the needs and reduce the cost of large scale Wi-Fi network deployments for Government agencies and large enterprise. The Aruba Wireless Networks WLAN switching platform is a highly scalable and redundant solution that provides centralized intelligence to secure and manage the corporate RF environment, enforce identity based user security policies, enable service creation and provide secure mobility management to thousands of simultaneously connected users. " |
| 259 |
Prism Payment Technologies (Pty) Ltd
PO Box 901 , Witkoppen , Gauteng 2068 South Africa -
Wayne Donnelly
|
Incognito TSM410
Version 1.1.0.0 (Firmware) |
Pentium III 450MHz | 6/7/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The Incognito TSM410 is a multi-chip embedded Tamper Responsive Security Module. Fitted on a PCI carrier card, the device offers high-performance, high-security services targeted at EFT switches and mCommerce applications. " |
| 258 |
Broadcom Corporation
1131 W. Warner Rd. , Tempe , AZ 85284 USA -
Joseph Wallace
|
BCM5841
Part # A0 |
N/A | 6/3/2004 | TCBC(e/d; KO 1,2,3) " The BCM5841 is a second generation multi-gigabit cryptographic coprocessor for VPN IPSec applications. " |
| 257 |
F-Secure Corporation
Tammasaarenkatu 7 , PL 24 , Helsinki 00181 Finland -
Alexey Kirichenko
|
F-Secure?Cryptographic Library for Linux
Version 1.1 |
Intel P4 1.8 GHz w/ RedHat Enterprise Linux 3 AS; 1 GHz UltraSPARC IIIi w/ Solaris 8.0 | 5/10/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3); CTR(ext only; KO 1,2,3) " The F-Secure?Cryptographic Library?for Linux is a 140-2 Level 1 compliant software module, which provides an assortment of cryptographic services including symmetric and asymmetric encryption, hash and HMAC computation, digital signing, key exchange, and pseudorandom number generation. " |
| 256 |
Open Source Software Institute
Stennis Space Center , Mississippi Technology Transfer Center , Building 1103, Room 135 F , Oxford , MS 39529 USA -
Ben Laurie
-
John Weathersby
|
OpenSSL FIPS Cryptographic Module
Version 1.0 |
HP D Class 9000 w/ HP-UX Release B.11.11; Linux Kernel Version: 2.4.21 w/ SuSE Linux 9.0 (x86) | 5/10/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB8(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3) " The OpenSSL FIPS Cryptographic Module is a validated source code component of the standard OpenSSL distribution that can be downloaded from the http://openssl.org/ website. " |
| 255 |
F-Secure Corporation
Tammasaarenkatu 7 , PL 24 , Helsinki 00181 Finland -
Alexey Kirichenko
|
F-Secure?Cryptographic Library for Windows
Version 2.1 |
Intel P4 1.6 GHz w/ Windows 2000 | 5/10/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3); CTR(ext only; KO 1,2,3) " The F-Secure?Cryptographic Library for Windows is a 140-2 Level 2 compliant software module, implemented as a 32-bit Windows compatible DLL. The Module provides an assortment of cryptographic services to client processes that attach instances of the module DLL. " |
| 254 |
Bioscrypt Inc.
5450 Explorer Drive , Suite 500 , Mississauga , ON L4W 5M1 Canada -
Doug Copeland
|
Bioscrypt Cryptographic Library (6711 DSP)
Version 1.00 (Firmware) |
Texas Instruments TMS320C6711 DSP | 5/10/2004 | TCBC(e/d; KO 2,3) " The Bioscrypt Cryptographic Library is used by Bioscrypt to provide developers with FIPS certified DES and Triple-DES solutions. " |
| 253 |
Bioscrypt Inc.
5450 Explorer Drive , Suite 500 , Mississauga , ON L4W 5M1 Canada -
Doug Copeland
|
Bioscrypt Cryptographic Library (PC)
Version 1.00 |
Intel P4-1.8 GHz w/ Windows 2000 with SP2 | 5/10/2004 | TCBC(e/d; KO 2,3) " The Bioscrypt Cryptographic Library is used by Bioscrypt to provide developers with FIPS certified DES and Triple-DES solutions. " |
| 251 |
Thales e-Security
Sawgrass Technology Park , 1601 North Harrison Parkway , Building A, Suite 100 , Sunrise , FL 33323 USA -
Juan Asenjo
|
Datacryptor?2000
Version DHDES3_V1_81 |
Datacryptor?2000 hw device w/ Motorola Coldfire processor, part number XCF5206EFT | 4/27/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB8(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3) " The Datacryptor?2000 is a standalone multi-chip cryptographic module that secures communications using signed Diffie-Hellman key exchange and Triple-DES or AES encryption over point-to-point links X.25, Frame Relay, and IP networks. The unit also provides integrated secure unit management capability. " |
| 250 |
Bluesocket, Inc.
7 New England Executive Park , Burlington , MA 01803 USA -
Mike Puglia
|
Bluesocket Wireless Gateway TLS
Version OpenSSL Library 0.9.6 |
Pentium IV w/ Linux kernel version 2.4.18 | 4/16/2004 | TCBC(e/d; KO 1,2,3) " OpenSSL is an open source toolkit implementing the Transport Layer Security (TLS v1) protocols as well as a full-strength general-purpose cryptography library used to implement TLS for the Bluesocket Wireless Gateway. " |
| 249 |
RSA Security, Inc.
2955 Campus Drive , Suite 400 , San Mateo , CA 94403 USA -
Kathy Kriese
-
David Finkelstein
|
RSA BSAFE Crypto-J Software Module
Version 3.5 |
Pentium IV 1.4 GHz w/ Microsoft Windows XP | 4/13/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3) " There are two variants of the Crypto-J module, one which implements an RSA Security-specific API [jsafeFIPS] and the other which implements the Java Cryptographic Extensions (JCE) API [jsafeJCEFIPS]. " |
| 248 |
SonicWALL, Inc.
1143 Borregas Ave. , Sunnyvale , CA 94089-1306 USA -
Paal Tveit
|
TZ 170
Version 2.0 Enhanced (Firmware) Part # 101-5000072-00 rev A |
SonicOS v2.0 Enhanced | 4/13/2004 | TCBC(e/d; KO 1,2,3) " The TZ 170 is an internet security appliance with WAN interface, a flexible Optional interface, and a LAN interface incorporating a 5-port Fast-Ethernet switch. The TZ 170 provides stateful packet inspection firewall services, accelerated IPSec VPN, and bandwidth management, and can be upgraded to offer ISP failover and traffic. " |
| 247 |
ITServ Inc.
6 Montgomery Village Ave. , Suite 405 , Gaithersburg , MD 20879 USA -
Faydeana Huang
|
RideWay Station FGC
Version 5.0 |
Linux 2.2.17-21 w/ Transmeta Crusoe TM5400 (Intel x86-based) | 4/1/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " RideWay Station FGC is an integrated firewall, VPN and wireless gateway appliance for small to medium-sized organizations. Computers and servers (wired and/or wireless) in your networks will be protected from unauthorized accesses and attacks from the Internet. In addition, IPSec VPN (using 3DES encryption) enables workers in remote locations to securely access internal network resources. VPN can also be used to create a secure connection between two branch offices. " |
| 246 |
Corrent Corporation
1711 W. Greentree Dr. Suite 201 , Tempe , AZ 85284-2717 USA -
Richard Andelfinger
|
Corrent CR7120 Security Processor
Part # 220-0001-01 |
N/A | 3/30/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The Corrent CR7120 is industry's first complete full duplex 2.0 Gigabit + IPSec and SSL Security Processor on a chip, for Internet access equipment such as high-speed routers, VPN/Firewalls, Access concentrators, other Internet aggregation devices, layer 4 - 7 security appliances and SAN applications. " |
| 245 |
Lucent Technologies, Inc.
600 Mountain Ave. , Murray Hill , NJ 07974 USA -
Richard T. Fohl
|
Lucent Secure Solutions SW Cryptographic Implementation
Version 2.0 |
Processor: Intel Pentium Xeon 2.4GHz; OS: LVF 7.1.189 | 4/1/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " Lucent SW Cryptographic Implementation is used in Lucent Bricks. The VPN Firewall Brick is a high-speed packet-processing appliance, oriented towards providing security functions. The Bricks are carrier-grade integrated firewall and virtual private network (VPN) gateway appliance specifically designed for web/application data center security, large-scale managed security services, and remote access VPN services. Called the Brick because of its rugged, reliable design, this is an ideal platform for service providers seeking wide scalability, ready manageability, and industry-leading performance. " |
| 244 |
C4 Technology, Inc.
Meguro Tokyu Bldg., 5th Floor , 2-13-17 Kamiosaki Shinagawa-ku , , Tokyo 141-0021 Japan -
Hirohisa Ogawa
|
C4CS
Version 1.0.0 |
Intel Pentium M w/ Windows XP SP1 and Windows 2000 SP3 | 3/23/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " C4CS is a software cryptographic module providing symmetric/asymmetric ciphers, hash function, and secret sharing schemes. " |
| 243 |
iDirect Technologies, Inc.
10803 Parkridge Boulevard , Reston , VA 20191 USA -
Sasmith Reddi
|
Protocol Processor Cryptographic Chip
Part # 1.0 |
N/A | 3/18/2004 | TCBC(e/d; KO 1,2,3) " iDirect Technologies' broadband VSAT solutions enable enterprise IT application delivery when performance, bandwidth, and efficient capital costs are required. In a single turnkey solution, enterprises get fast, reliable, cost-effective, broadband IP connections for LAN-to-LAN connectivity and/or direct point-to-point links. " |
| 242 |
iDirect Technologies, Inc.
10803 Parkridge Boulevard , Reston , VA 20191 USA -
Sasmith Reddi
|
NetModem Cryptographic Chip
Part # 1.0 |
N/A | 3/18/2004 | TCBC(e/d; KO 1,2,3) " iDirect Technologies' broadband VSAT solutions enable enterprise IT application delivery when performance, bandwidth, and efficient capital costs are required. In a single turnkey solution, enterprises get fast, reliable, cost-effective, broadband IP connections for LAN-to-LAN connectivity and/or direct point-to-point links. " |
| 241 |
Vormetric, Inc.
3131 Jay Street , Santa Clara , CA 95054 USA -
Mukesh Nigam
|
CoreGuard Security Server
Version VN.3.0SP1 |
Linux 7.3, Intel Xeon processor | 3/18/2004 | TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3) " Vormetric CoreGuard is a comprehensive security solution that combines protection of data at rest and host protection. CoreGuard integrates a software module loaded on a server and FIPS compliant appliance with user-defined security policies allowing fine-grain data access control and encryption of stored data. " |
| 240 |
Good Technology
1032 Morse Ave , Sunnyvale , CA 94089 USA -
Prathaban Selvaraj
|
FipsCrypto on PocketPC
Version 20040220 |
Intel Strong ARM w/ WinCE4.2 | 3/18/2004 | TCBC(e/d; KO 1,2,3) " The FipsCrypto on Pocket PC is a FIPS 140-2 compliant software-based cryptographic module that implements the 3DES, AES, SHA-1 and HMAC-SHA-1 algorithms. " |
| 239 |
Giesecke & Devrient America, Inc.
45925 Horseshoe Drive , Dulles , VA 20166 USA -
Won J Jun
-
Hassan Tavassoli
|
Sm@rtCaf?Expert FIPS 64K
Part # HD65246C1A05NB (Firmware Version:CH463JC_IRNABFOP003901_V101) |
N/A | 3/10/2004 | TECB(e/d; KO 2,3); TCBC(e/d; KO 2,3) " Giesecke & Devrient (G&D) Smart Card Chip Operating System Sm@rtCaf?Expert FIPS 64K is a Java Card 2.2 and Open Platform v2.0.1' compliant smart card module. It supports, at a minimum, Triple-DES, AES, DSA, and RSA algorithms with on-card key generation. The Sm@rtCaf?Expert FIPS 64K is suitable for government and corporate identification, payment and banking, health care, and Web applications " |
| 238 |
TeamF1, Inc.
39159 Paseo Padre Parkway #121 , Fremont , CA 94538 USA -
Mukesh Lulla
|
Krypto-Lite Library
Version 2.0 |
pSOSystem on X86 family CPU | 3/4/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3) " TeamF1's Krypto-Lite Is a FIPS 140-2 compliant, standards-based flexible, high performance and modular software cryptographic algorithms library. It is available in "C" source code form and tailored for embedded use and for hardware acceleration. It includes symmetric and asymmetric ciphers as well as crypto hash algorithms with an interface that can be used with any network security application. " |
| 237 |
Fortinet Inc.
920 Stewart Drive , Sunnyvale , CA 94085 USA -
Alan Kaye
|
FortiOS Cryptographic Library
Version 1.0 |
FortiOS ASIC Running FortiOS V2.5 | 3/4/2004 | TCBC(e/d; KO 1,2,3) " The FortiGate modules are multiple chip, standalone cryptographic modules consisting of production grade components contained in a physically protected enclosure in accordance with FIPS 140-2 Level 2 requirements. " |
| 236 |
Datakey, Inc.
407 W. Travelers Trail , Burnsville , MN 55337-2554 USA -
Hazem Hassan
-
Datakey Sales
|
Model 330G2 Smart Card
Part # 1.0 (Firmware Version 2.0) |
N/A | 3/4/2004 | TECB(e/d; KO 2,3); TCBC(e/d; KO 2,3) " The 330G2 is an ISO 7816 and GSC-IS compliant cryptographic smart card that offers multiapplication secure storage and retrieval of digital credentials. Cryptographic services provided by the card include SHA-1, DES, 3DES, RSA and DSA with on board key generation including RSA 2048-bit key generation " |
| 235 |
Nokia
313 Fairchild Drive , Mt View , CA 94043 USA -
Robert Kusters
|
Nokia HW Cryptographic Implementation
Part # NBB3350000 |
N/A | 2/18/2004 | TCBC(e/d; KO 1,2,3) " The Nokia IP350 and IP380 are full-featured enterprise systems designed for small to medium enterprises, with Service Provider flexibility and rapid serviceability option in a single rack space. When combined with Check Point VPN-1/FW-1, these platforms provide reliable, easy to manage distributed security and access. " |
| 234 |
Nokia
313 Fairchild Drive , Mt View , CA 94043 USA -
Robert Kusters
|
Nokia IPSO Cryptographic SW Implementation
Version 3.7 |
Intel Pentium 3 w/Nokia IPSO-SB | 2/18/2004 | TCBC(e/d; KO 1,2,3) " The Nokia IP350 and IP380 are full-featured enterprise systems designed for small to medium enterprises, with Service Provider flexibility and rapid serviceability option in a single rack space. When combined with Check Point VPN-1/FW-1, these platforms provide reliable, easy to manage distributed security and access. " |
| 233 |
VCON Telecommunications
22 Maskit St. , Herzliya 46733 Israel -
Yair Shachar
|
Advanced Encryption Server
Version 3.5 |
Pentium 4 w/ Windows 2000 and XP | 2/4/2004 | TECB(e/d; KO 1,2,3) " An IP networking platform that dynamically creates a secure (fully encrypted) and private virtual LAN for videoconferences or any other data transmissions across public and/or private networks. " |
| 232 |
Oberthur Card Systems
3150 E. Ana Street , Rancho Dominguez , CA 90221 USA -
Christophe Goyet
|
ID-One Cosmo 72K RSA D
Version 0xE302 (Firmware) |
JMX64 | 2/4/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The Oberthur Card Systems CosmopolIC 72K RSA Java Card Platform is a single chip cryptographic micro-processor smart card specifically designed for identity and government market needs, with a large memory (72KB), a highly secure architecture and several services and default applications in ROM for ISO 7816 File System, Biometry and Authentication. " |
| 231 |
SonicWALL, Inc.
1143 Borregas Ave. , Sunnyvale , CA 94089-1306 USA -
Paal Tveit
|
SonicWALL PRO 3060/4060
Version 2.0 (Firmware) |
SonicOS v2.0 | 2/4/2004 | TCBC(e/d; KO 1,2,3) " The PRO 4060 and PRO 3060 are internet security appliances offering stateful packet inspection firewall services, accelerated IPSec VPN, bandwidth management, and dual-WAN port support with ISP failover and load-balancing capabilities, all via six configurable 10/100 Ethernet interfaces. " |
| 230 |
Layer N Networks, Inc.
12401 Research Blvd. , Bldg 2, Suite 275 , Austin , TX 78759 -
Rick Hall
|
UltraLock Cryptographic Module
Part # A1 |
N/A | 1/14/2004 | TCBC(e/d; KO 1,2,3) " "The UltraLock?Cryptographic Module performs all the cryptography required for SSL/TLS applications. This module is a common element of the LNN2010 and LNN2025 UltraLock Security Processors, the industry's first single-chip solutions for completely off-loading SSL/TLS processing from host systems. The innovative in-line architecture combines TCP/IP termination and high-speed cryptography to transparently process SSL/TLS traffic at wire speed without impacting host system performance. Industry-standard GMII Ethernet connectivity allows UltraLock processors to drop easily into common networking and security platforms without special software development or complex hardware redesign, greatly reducing time to market." " |
| 229 |
Credant Technologies, Inc.
15303 N Dallas Parkway , Suite 1420 , Addison , TX 75001 USA -
Chris Burchett
|
Credant Cryptographic Kernel
Version 1.0 |
Intel Pentium III w/ Win 2000 | 1/5/2004 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " CREDANT Cryptographic Kernel is a FIPs-140-2 compliant, software-based cryptography library that implements 3DES, AES and SHA-1 algorithms for the CREDANT Mobile Guardian product. CREDANT Mobile Guardian enables enterprise-wide control of security for mobile and wireless users of laptops, tablet PCs & PDAs. " |
| 228 |
Blue Ridge Networks
14120 Parke Long Court , Chantilly , VA 20151 USA -
Tom Gilbert
|
BG4000 Cryptographic Module
Version 6.2 (Firmware) |
Motorola MPC8260 | 12/18/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The BG4000 and BG3140 are network security appliances for the construction of secure Virtual Private Networks between Internet sites, and between Internet sites and individual remote users. " |
| 227 |
Blue Ridge Networks
14120 Parke Long Court , Chantilly , VA 20151 USA -
Tom Gilbert
|
BG4000 Cryptographic Module
Part # BG4000 |
N/A | 12/18/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The BG4000 and BG3140 are network security appliances for the construction of secure Virtual Private Networks between Internet sites, and between Internet sites and individual remote users. " |
| 226 |
PalmSource, Inc.
1240 Crossman Drive , Sunnyvale , CA 94089 USA -
Richard Levenberg
|
Cryptographic Provider Manager
Version 5.2.2 |
Palm OS(r) software v. 5.2.1 | 12/8/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB8(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3) " The CPM provides robust cryptographic functionality through a simple API that developers can use with very little cryptographic expertise. The FIPS certified algorithms, available through the CPM, include 3DES, AES and SHA1. SHA2, RC4, and RSA public operations are also supported. " |
| 225 |
Mindspeed Technologies, Inc.
4000 Mac Arthur Blvd. , Newport Beach , CA 92660 USA -
Elie Massabki
|
M826xx
Version 1 (Firmware) |
RTXC | 12/8/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " M826xx is Communications Convergence Processor for Voice over IP (VoIP) and Voice over ATM (VoATM) applications. " |
| 224 |
Chunghwa Telecom
12, Lane 551, Min-Tsu Road SEC.5 , Yang-Mei, Taoyuan , Tawian 326 Republic of China -
Yu-Ling Cheng
|
SafGuard 200 Cryptographic Library
Version 1.0 (Firmware) |
ARM 7 Processor running PSOS | 12/8/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " SafGuard200 is a multi-chip standalone cryptographic module that is used to provide highly-secure cryptographic services and key storage for PKI applications. (e.g., secure private key storage, high-speed math accelerator for 1024-4096 bit public key signatures, and hashing). The SafGuard 200 HSM provides secure identity-based challenge-response authentication using smart cards and data encryption using FIPS approved 3DES and AES encryption. " |
| 223 |
Mobile Armor, LLC
400 South Woods Mill Road , Suite 110 , Chesterfield , MO 63017-3407 USA -
Bryan Glancey
|
MA Crypto Module
Version 1.0 |
Intel Pentium IV processor w/ Windows 2000 Professional | 11/26/2003 | TECB(e/d; KO 1,2,3) " Mobile Armor's FIPS 140-2 certified cryptographic Module is for use in all products and all platforms including PocketPC, PalmOS, Windows, and Linux. This provides consistent protection on all platforms. Mobile Armor integrates this module into it's suite of Enterprise Security Solutions. " |
| 222 |
Real Time Logic, Inc.
1042 Elkton Dr. , Colorado Springs , CO 80907 USA -
Bela Szabo
|
RTL-TDEA
Version 1.0(Firmware) Part # RTL-P200006 |
RTL-TDEA | 11/13/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3) " RTL-TDEA Module is a multi-chip embedded cryptographic PCI card supporting TECB, TCBC, TCFB-64, TOFB-64, Encrypt and Decrypt FIPS modes. " |
| 221 |
Good Technology
1032 Morse Ave , Sunnyvale , CA 94089 USA -
Phil Peterson
|
GoodFipsCrypto.prc
Version 20031028 |
ARM-based processor w/ Palm 5 | 11/7/2003 | TCBC(e/d; KO 1,2,3) " The GoodFipsCrypto.prc is a FIPS 140-2 compliant software-based cryptographic module that implements the TDES, AES, SHA-1 and HMAC-SHA-1 algorithms. " |
| 220 |
Enterasys Networks
50 Minuteman Road , Andover , MA 01810 USA -
Damon Hopley
|
Enterasys Cryptographic Hardware
Part # SafeNet 1140; HW: Version 1.0 |
N/A | 11/7/2003 | TCBC(e/d; KO 1,2,3) " Hardware cryptographic algorithm implementations for the XSR product line. " |
| 219 |
Enterasys Networks
50 Minuteman Road , Andover , MA 01810 USA -
Damon Hopley
|
Enterasys IR Cryptographic Library
Version 1.0 |
200MHz IBM PowerPC 405 GP w/ VxWorks | 11/7/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " Software cryptographic algorithm implementations for the XSR product line. " |
| 218 |
Enterasys Networks
50 Minuteman Road , Andover , MA 01810 USA -
Damon Hopley
|
Enterasys SSH Cryptographic Library
Version 1.0 |
200MHz IBM PowerPC 405 GP w/ VxWorks | 11/7/2003 | TCBC(e/d; KO 1,2,3) " Software cryptographic algorithm implementations for the XSR product line. " |
| 217 |
Cavium Networks
2610 Augustine Dr. , Santa Clara , CA 95054 USA -
Mike Scruggs
|
NITROX Lite Security Macro Processors
Version CN1000-MC-Cryptomodule-1.1 Part # NITROX Lite CN1010 |
NITROX Lite CN1010 | 11/7/2003 | TCBC(e/d; KO 1,2,3) " The NITROX Lite CN1010 is one member of the NITROX-Lite line of award winning security processors from Cavium Networks. Based on common hardware processor core architecture, the NITROX-Lite family delivers 50Mbs to 1 Gbps of encryption bandwidth with 1 to 7K RSA/DH operations per second. NITROX processors and acceleration boards are being used by server-motherboard vendors and OEMs, in a wide range of equipment, to accelerate security protocols and algorithms. " |
| 216 |
Research in Motion
295 Phillip Street , Waterloo , Ontario N2L 3W8 Canada -
BlackBerry Security Team
|
BlackBerry Enterprise Server Cryptographic Library
Version 1.0 |
Pentium 4 w/ Windows 2000 SP3 | 11/13/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " BlackBerry is the leading wireless enterprise solution that allows users to stay connected with secure, wireless access to email, corporate data, phone, web and organizer features. BlackBerry is a totally integrated package that includes hardware, software and service, providing a complete end-to-end solution. The BlackBerry " |
| 215 |
IBM Corporation
2455 South Road , Poughkeepsie , NY 12601 USA -
Tamas Visegrady
|
UltraCypher 2 Crytographic Engine
Part # 1.0 |
N/A | 10/23/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The IBM UltraCypher 2 Cryptographic Engine is a flexible, high performance subsystem that provides fast, ultra-secure, hardware-based cryptographic functionality. " |
| 214 |
Hifn, Inc.
750 University Avenue , Los Gatos , CA 95032 USA -
Glenn Haley
|
7956
Part # 7956; Version 1.0 |
N/A | 10/20/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The Hifn 7955 and 7956 are advanced security processors designed for high-speed T3/OC3, ROBO/SME networking applications like VPN Broadband Routers, wireless access points, VPN Edge Routers/Gateways, Firewall/VPN Appliances and other Network and Customer Premise Equipment (CPE). " |
| 213 |
Hifn, Inc.
750 University Avenue , Los Gatos , CA 95032 USA -
Prasad Shroff
|
7814-W
Part # 7814-W |
N/A | 10/20/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " Hifn Intelligent Packet Processing chips are full-duplex T3 to full-duplex OC-12, Integrated public key, 3DES, Advanced Encryption Standard (AES), and compression - the latest chips from Hifn have it all in a single high-performance package. " |
| 212 |
3Com Corporation
5500 Great America Parkway , Santa Clara , CA 95052 USA -
Victoria Van Spyk
|
3Com's IPSec Offload Integrated Circuit
Part # 40-0728-001 |
N/A | 10/10/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " 3Com's IPSec Offload Integrated Circuit is hardware based crypto device that performs IPSec (DES, TDES, SHA-1, MD5 and HMAC) computations on 3Com's series of Secure Network Interface Cards and Embedded Firewall products. " |
| 211 |
Vindicator Technologies, Inc.
5307 Industrial Oaks Blvd. , Suite 130 , Austin , TX 78735 USA -
Daniel Skret
|
TDEA Option
Version 1.0 (Firmware) |
MC68HC000 and MC68HC11 processor | 10/10/2003 | TCFB8(e/d; KO 1,2,3) " TDEA Encryption option for UHS-net security monitoring and control equipment. " |
| 210 |
SafeNet, Inc.
8029 Corporate Drive , Baltimore , MD 21236 USA -
Joel Rieger
|
SafeXcel 1141/1741
Part # 11 |
N/A | 9/30/2003 | TCBC(e/d; KO 1,2,3) " The SafeXcel 1141/1741 ASICs are part of the SafeNet IPsec co-processor chip family. The devices consist of an IPsec Packet Engine that performs DES, TDES, AES, SHA-1, MD5, header/trailer and insertion/deletion operations, a Public Key Accelerator that performs RSA, DSA, and DH operations using long vector math up to 2048 bits, and a Random Number Generator that provides up to 2 Mbps of random data. " |
| 209 |
Good Technology
1032 Morse Ave , Sunnyvale , CA 94089 USA -
Phil Peterson
|
FipsCrypto
Version 1.9.3.7 |
ARM-based processor w/ eCos 1.3.1 | 9/30/2003 | TCBC(e/d; KO 1,2,3) " The FipsCrypto is a FIPS 140-2 compliant software-based cryptographic dll module that implements the 3DES, AES, SHA-1 and HMAC-SHA-1 algorithms. " |
| 208 |
Backbone Security.com
701 Main Street , Suite 300 , Stroudsburg , PA 18360 USA -
Marc Kurtz
|
Ribcage Kernel
Version 2.2 FIPS |
Linux kernel w/ Intel P3 (proprietary non-modifiable) | 9/22/2003 | TCBC(e/d; KO 1,2,3) " Ribcage is a secure IPSec Virtual Private Network that provides secure connectivity deployed on a shared infrastructure with the same privacy and performance as a leased network. Ribcage is a solution that is flexible as both a secure virtual private network and as a remote access device. " |
| 207 |
PGP Corporation
3460 West Bayshore , Palo Alto , CA 94303 USA -
Vinnie Moscaritolo
|
PGP Cryptographic SDK
Version 3.0.3 9/17/2003 only KO 3 was validated for TDES. On 9/30/2003, received validation of KO1 for the same modes for TDES. Updated database. |
Sony Notebook Computer PCG-8C6L, MS Win XP ProfessionalSP-1 | 9/17/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3) " The PGP SDK includes a wide range of field-tested and standards-based encryption, digital signature, and encoding algorithms as well as a variety of secure network protocol implementations. The PGP SDK offers developers the same core crypto that is at the heart of PGP products. " |
| 206 |
GE-Interlogix
791 Park of Commerce Blvd , Boca Raton , FL 33487 USA -
Khalil Yacoub
|
Triple DES C Module
Version 1.1 (Firmware) |
Windows 2000 Professional | 9/17/2003 | TECB(e/d; KO 1,2,3) " M/5PX-N, PXN2000, Picture Perfect, NX590E, OH Network Receiver, OH TCP/IP Line-card, ATS-1806, AL-1806, Simon/Concord TCP/IP Module, Premises Manager, DL900 " |
| 205 |
IDT
2975 Stender Way , Santa Clara , CA 95054 USA -
Alex Soohoo
|
RC32365
Part # ZA |
N/A | 9/16/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The Interprise Access RC32365 is an integrated communications processor that addresses the secure SOHO wired/wireless gateway and VPN/firewall appliance markets by incorporating a high-performance CPU, an on-chip security engine and key peripheral interfaces. " |
| 204 |
Cavium Networks
2610 Augustine Dr. , Santa Clara , CA 95054 USA -
Mike Scruggs
|
NITROX II In-line Security Processors
Version NITROX II (Firmware) Part # CN2130 |
CN2130 and Cavium Microcode | 8/27/2003 | TCBC(e/d; KO 1,2,3) " NITROX II In-Line Security Processors Product Description: The NITROX II CN2130 is one member of the Cavium Networks award winning NITROX, NITROX Lite, and NITROX II line of security processors. Based on a common hardware processor core, the NITROX families deliver 50Mbs to 10Gbps of encryption bandwidth with 1K to 40K RSA/DH operations per second. NITROX processors and acceleration boards are being used by server-motherboard vendors and OEMs in a wide range of networking equipment to accelerate security protocols and algorithms. " |
| 203 |
Cavium Networks
2610 Augustine Dr. , Santa Clara , CA 95054 USA -
Mike Scruggs
|
NITROX Security Macro Processor
Version CN1000-MC-CryptoModule-1.1(Firmware) Part # NITROX CN1120 |
NITROX CN1120 and associated firmware (microcode) | 8/27/2003 | TCBC(e/d; KO 1,2,3) " NITROX Security Macro Processor Product Description: The NITROX CN1120 is one member of the NITROX line of award winning security processors from Cavium Networks. Based on a common core hardware processor architecture, the NITROX family delivers 50Mbs to 10Gbps of encryption bandwidth with 1K to 40K RSA/DH operations per second. NITROX processors and acceleration boards are being used by server-motherboard vendors and OEMs, in a wide range of equipment, to accelerate security protocols and algorithms. " |
| 202 |
F-Secure Corporation
Tammasaarenkatu 7 , PL 24 , Helsinki 00181 Finland -
Alexey Kirichenko
|
F-Secure(R) Cryptographic Library ?
Version 2.1 |
Intel P4 1.6 GHz w/ Windows 2000s | 8/27/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3); CTR(ext only; KO 1,2,3) " The F-Secure Cryptographic Library for Windows is a 140-2 Level 2 compliant software module, implemented as a 32-bit Windows compatible DLL. The module provies an assortment of cryptographic services to client processes that attach instances of the module DLL. " |
| 201 |
Microsoft Corporation
One Microsoft Way , Redmond , WA 98052-6399 USA - Mike Lai |
Windows 2003 Kernel Mode Cryptographic Module (fips.sys)
Version 5.2.3790.0 |
Athlon 800 Mhz w/ Windows 2003 .Net Server | 8/19/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " Kernel level .sys module exporting cryptographic functionality. " |
| 200 |
Research in Motion
295 Phillip Street , Waterloo , Ontario N2L 3W8 Canada -
Ian Robertson
|
BlackBerry Cryptographic API
Version 3.6 |
ARM 7 Processor running BlackBerry OS | 8/14/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB8(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3) " BlackBerry?is the leading wireless enterprise solution that allows users to stay connected with secure, wireless access to email, corporate data, phone, web and organizer features. BlackBerry?is a totally integrated package that includes hardware, software and service, providing a complete end-to-end solution. The BlackBerry?Cryptographic API provides advanced cryptographic functionality for the BlackBerry? " |
| 199 |
Microsoft Corporation
One Microsoft Way , Redmond , WA 98052-6399 USA - Mike Lai |
Windows 2003 Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH)
Version 5.2.3790.0 |
AMD Athlon 900Mhz w/ Windows 2003 | 8/5/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider is a FIPS 140-2 compliant, software-based, cryptographic module.RSAENH encapsulates several different cryptographic algorithms (including SHA-1, DES, 3DES, DSA, SHA-1-based HMAC) in a cryptographic module accessible via the Microsoft CryptoAPI. " |
| 198 |
Wei Dai
Groove Networks, Inc. , 100 Cummings Center , Suite 535Q , Beverly , MA 01915 USA -
Wei Dai
|
Crypto++ Library
Version 5.0.4 |
Pentium III w/ Windows 2000 Prof SP1 | 7/30/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3); TCFB8(e/d; KO 1,2,3); TCFB64(e/d; KO 1,2,3); TOFB(e/d; KO 1,2,3); CTR(ext only; KO 1,2,3) " The Crypto++ Library is a free, open source C++ class, 32-bit dynamic link library (DLL) providing public key encryption, digital signatures, symmetric ciphers, hash functions, message authentication codes, and other cryptographic algorithms. " |
| 197 |
Airespace Inc.
110 Nortech Pkwy , San Jose , CA 95134 USA -
Scott Kelly
|
Airespace IPSec Crypto Module
Version 1.3 Part # 35-100680-000 (R1) |
Airespace 4000 Series | 7/29/2003 | TCBC(e/d; KO 1,2,3) " Airespace IPSec Crypto Module provides cryptographic services for the Airespace Wireless Enterprise Platform. Airespace offers a unique hierarchical architecture that centralizes network intelligence for cost effective deployment, dynamic RF operations, secure mobility management, service creation, and policy enforcement throughout an entire wireless network. " |
| 196 |
Airespace Inc.
110 Nortech Pkwy , San Jose , CA 95134 USA -
Scott Kelly
|
Airespace SSL Crypto Module
Version 1.3 Part # 35-100681-000 (R1) |
Airespace 4000 Series | 7/29/2003 | TCBC(e/d; KO 1,2,3) " Airespace SSL Crypto Module provides cryptographic services for the Airespace Wireless Enterprise Platform. Airespace offers a unique hierarchical architecture that centralizes network intelligence for cost effective deployment, dynamic RF operations, secure mobility management, service creation, and policy enforcement throughout an entire wireless network. " |
| 195 |
ADEMCO [d.b.a. Honeywell International, Inc.]
165 Eileen Way , Syosset , NY 11791 USA -
Harry Pashkoff
|
AC Communicator Module
Version WA-ACMDES3 Part # 472491D3 |
ADT Communications Module;OS:proprietary | 7/22/2003 | TCFB1(e/d; KO 1,2,3) " The AC Communicator Module (P/N 472491D3) is used to encrypt and transmit security system data over public telephone line, RS232 and DVAC to proprietary central station automation equipment. " |
| 194 |
Penta Security Systems, Inc.
9th Fl. Hana Securities Bldg. , 23-3 Yoido-dong, Youngdeungpo-ku , Seoul 150-709 Korea -
Yoon-sung Chong
-
Duk Soo Kim
|
CIS Crypto Library
Version 2.0 |
Pentium III 733MHz, Windows 2000 Professional | 7/22/2003 | TECB(e/d; KO 2,3); TCBC(e/d; KO 2,3); TCFB8(e/d; KO 2,3); TCFB64(e/d; KO 2,3); TOFB(e/d; KO 2,3) " The Penta Security CIS Crypto Library is a full set C software library providing high-performance implementations of various cipher algorithms (AES, DES, 3DES, SEED, IDEA, Blowfish, RC2, RC5, PACA, RSA, DSA, KCDSA, RC4, etc.), hash algorithms and message authentication codes. " |
| 193 |
Schlumberger
8311 North FM 620 Rd. , Austin , TX 78726 USA -
Mike Neumann
|
Cyberflex Access 64K V2
Part # M516LACC2 Hardmask 1V1 Softmask 2V1 |
JavaCard 2.1.1 Runtime Environment | 7/14/2003 | TECB(e/d; KO 2,3); TCBC(e/d; KO 2,3) " The Cyberflex Access 64K V2 smart card can be employed in solutions which provide secure PKI (public key infrastructure) and digital signature technology. Cyberflex Access 64K V2 serves as a highly portable, secure token for enhancing the security network access and ensuring secure electronic communications. " |
| 192 |
Microsoft Corporation
One Microsoft Way , Redmond , WA 98052-6399 USA - Mike Lai |
Windows 2003 Enhanced Cryptographic Provider (RSAENH)
Version 5.2.3790.0 |
Intel Pentium 4 w/ Windows 2000 Professional | 6/30/2003 | TECB(e/d; KO 1,2,3); TCBC(e/d; KO 1,2,3) " The Microsoft Enhanced Cryptographic Provider is a FIPS 140-2 compliant, software-based, cryptographic module.RSAENH encapsulates several different cryptographic algorithms (including SHA-1, DES, 3DES, AES, RSA, SHA-1-based HMAC) in a cryptographic module accessible via the Microsoft CryptoAPI. " |
| 191 |
INITECH Co. Ltd.
7F, Initech B/D, 559-5 Geoyo-dong , Songpa-Gu , Seoul |