DES Validation Lists

Last Update: July 7, 2004

The purpose of this document is to provide technical information about implementations that have been validated as conforming to the Data Encryption Algorithm, as specified in Federal Information Processing Standard Publication 46-3, Data Encryption Standard (DES). The implementations below may consist of software, firmware, hardware, and any combination thereof. The National Institute of Standards and Technology (NIST) has made every attempt to provide complete and accurate information about the implementations described in this document. However, due to the possibility of changes made within individual companies, NIST cannot guarantee that this document reflects the current status of each product. It is the responsibility of the vendor to notify NIST of any necessary changes to its entry in any of the following lists.

Questions regarding implementations/products on these lists should first be directed to the appropriate vendor.


DES Modes of Operation Validated Implementations

(May 1996 - present)

The list below describes DES implementations which have been validated using the tests found in NIST Special Publication 800-17, Modes of Operation Validation System (MOVS): Requirements and Procedures , beginning in May 1996. The implementations are validated in accordance with FIPS 46-3 and FIPS 81, DES Modes of Operation. This testing is performed by NVLAP accredited Cryptographic Module Testing (CMT) laboratories. As of January 7, 2002 the following caveat will be listed on all new DES certificates: "Permitted for legacy systems only".

This list is ordered in reverse numerical order, by certificate number. Thus, the more recent validations are located closer to the top of the list. Also indicated after the date of validation are the modes and states for which the implementation was validated. DES modes are abbreviated as follows: Electronic Codebook (ECB), Cipher Block Chaining (CBC), Cipher Feedback (CFB), and Output Feedback (OFB). The two possible states for each mode are encryption(e) and decryption(d). The certificate issued to the vendor also indicates 1) the CMT laboratory that tested the implementation, and 2) the operating environment used to test the implementation (if software or firmware).

DES Validated Implementations
Cert# Vendor Implementation Val.
Date
Modes/Description
264 IBM Corporation 
2455 South Road,
Poughkeepsie , NY
12601
USA

-Walter Von Dehsen
TEL: 845-435-7521
FAX: 845-435-9270

IBM zSeries Cryptographic Assist DES, TDES, SHA-1
Part #1.0
7/1/2004

ECB(e/d) ; CBC(e/d)

"The IBM zSeries CP Assist feature provides processor-integrated hardware acceleration for DES, TDES and SHA-1 services."

263 Realia Technologies S.L. 
Orense, 68 11th floor,
Madrid
28020
Spain

-Sebasti? Mu?z
TEL: +34 91 449 03 30
FAX: N/A

Cryptosec2048
Version 01.04.0004
Part #Model 1.0
6/23/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"The Cryptosec2048 is a high-end PCI card that provides cryptographic services and secure storage of cryptographic keys. The module is built to perform general cryptographic processing (RSA, DES, SHA-1, MD5,...) and features a tamper-protective case to physically protect sensitive information contained within the card."

262 Aruba Wireless Networks Inc. 
180 Great Oaks Boulevard, Suite B,
San Jose , CA
95119
USA

-Kenneth Jensen - Dir of Prod Mgmt
TEL: (408) 227-4500
FAX: N/A

Aruba WLAN Switching Platform Software Cryptographic Implementation
Version 5000 Series
6/15/2004

CBC(e/d)

"Aruba Wireless Networks?WLAN switching platform is a purpose-built WLAN voice and data switching solution designed to specifically address the needs and reduce the cost of large scale Wi-Fi network deployments for Government agencies and large enterprise. The Aruba Wireless Networks WLAN switching platform is a highly scalable and redundant solution that provides centralized intelligence to secure and manage the corporate RF environment, enforce identity based user security policies, enable service creation and provide secure mobility management to thousands of simultaneously connected users."

261 Prism Payment Technologies (Pty) Ltd 
PO Box 901,
Witkoppen , Gauteng
2068
South Africa

-Wayne Donnelly
TEL: +27 (0) 11 5481000
FAX: +27 (0) 11 4673424

Incognito TSM410
Version 1.1.0.0 (Firmware)
6/7/2004

ECB(e/d) ; CBC(e/d)

"The Incognito TSM410 is a multi-chip embedded Tamper Responsive Security Module. Fitted on a PCI carrier card, the device offers high-performance, high-security services targeted at EFT switches and mCommerce applications."

260 Broadcom Corporation 
1131 W. Warner Rd.,
Tempe , AZ
85284
USA

-Joseph Wallace
TEL: 480-753-2279
FAX: 480-753-2380

BCM5841
Part #A0
6/3/2004

CBC(e/d)

"The BCM5841 is a second generation multi-gigabit cryptographic coprocessor for VPN IPSec applications."

259 F-Secure Corporation 
Tammasaarenkatu 7,
PL 24,
Helsinki
00181
Finland

-Alexey Kirichenko
TEL: +358 9 2520 5548

F-Secure?Cryptographic Library for Linux
Version 1.1
5/10/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"The F-Secure?Cryptographic Library?for Linux is a 140-2 Level 1 compliant software module, which provides an assortment of cryptographic services including symmetric and asymmetric encryption, hash and HMAC computation, digital signing, key exchange, and pseudorandom number generation."

258 Open Source Software Institute 
Stennis Space Center,
Mississippi Technology Transfer Center,
Building 1103, Room 135 F,
Oxford , MS
39529
USA

-Ben Laurie
TEL: 44 (20) 8735 0686

-John Weathersby
TEL: 662-236-1794

OpenSSL FIPS Cryptographic Module
Version 1.0
5/10/2004

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

"The OpenSSL FIPS Cryptographic Module is a validated source code component of the standard OpenSSL distribution that can be downloaded from the http://openssl.org/ website."

257 F-Secure Corporation 
Tammasaarenkatu 7,
PL 24,
Helsinki
00181
Finland

-Alexey Kirichenko
TEL: +358 9 2520 5548

F-Secure?Cryptographic Library for Windows
Version 2.1
5/10/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"The F-Secure?Cryptographic Library for Windows is a 140-2 Level 2 compliant software module, implemented as a 32-bit Windows compatible DLL. The Module provides an assortment of cryptographic services to client processes that attach instances of the module DLL."

256 Bioscrypt Inc. 
5450 Explorer Drive,
Suite 500,
Mississauga , ON
L4W 5M1
Canada

-Doug Copeland
TEL: (905) 624-7720
FAX: (905) 624-7742

Bioscrypt Cryptographic Library (6711 DSP)
Version 1.00 (Firmware)
5/10/2004

CBC(e/d)

"The Bioscrypt Cryptographic Library is used by Bioscrypt to provide developers with FIPS certified DES and Triple-DES solutions."

255 Bioscrypt Inc. 
5450 Explorer Drive,
Suite 500,
Mississauga , ON
L4W 5M1
Canada

-Doug Copeland
TEL: (905) 624-7720
FAX: (905) 624-7742

Bioscrypt Cryptographic Library (PC)
Version 1.00
5/10/2004

CBC(e/d)

"The Bioscrypt Cryptographic Library is used by Bioscrypt to provide developers with FIPS certified DES and Triple-DES solutions."

254 SSP Litronic 
17862 Cartwright Rd.,
Irvine , CA
92614
USA

-Brian Manahan
TEL: 949-851-1085
FAX: 949-851-8588

ARGUS/300 Software
Version V2.5 (Firmware)
4/27/2004

ECB(e/d) ; CBC(e/d)

"FIPS 140-1, Level 3 NIST/CEFMS Approved Electronic Signature System"

253 E.F. Johnson 
299 Johnson Ave.,
PO Box 1249,
Waseca , MN
56093-0514
USA

-John Oblak
TEL: 507-835-6276

Subscriber Encryption Module DES
Version 3.3 (Firmware)
4/19/2004

ECB(e/d) ; CBC(e/d) ; CFB1(e/d) ; OFB(e/d)

"This is the E.F. Johnson implementation of the DES algorithm. The modes of operation for this implementation are OFB, ECB, CBC and DES 1 bit CFB with differential encoding and decoding. This algorithm is used in the E.F. Johnson mobile and portable radios which contain the FIPS 140-2 validated Subscriber Encyption Module (SEM)."

252 RSA Security, Inc. 
2955 Campus Drive,
Suite 400,
San Mateo , CA
94403
USA

-Kathy Kriese
TEL: 650-295-7692
FAX: 650-295-7700

-David Finkelstein
TEL: 650-295-7535
FAX: 650-295-7700

RSA BSAFE Crypto-J Software Module
Version 3.5
4/13/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"There are two variants of the Crypto-J module, one which implements an RSA Security-specific API [jsafeFIPS] and the other which implements the Java Cryptographic Extensions (JCE) API [jsafeJCEFIPS]."

251 SonicWALL, Inc. 
1143 Borregas Ave.,
Sunnyvale , CA
94089-1306
USA

-Paal Tveit
TEL: 408-745-9600
FAX: 408-745-9300

TZ 170
Version 2.0 Enhanced (Firmware)
Part #101-5000072-00 rev A
4/13/2004

CBC(e/d)

"The TZ 170 is an internet security appliance with WAN interface, a flexible Optional interface, and a LAN interface incorporating a 5-port Fast-Ethernet switch. The TZ 170 provides stateful packet inspection firewall services, accelerated IPSec VPN, and bandwidth management, and can be upgraded to offer ISP failover and traffic."

250 Lucent Technologies, Inc. 
600 Mountain Ave.,
Murray Hill , NJ
07974
USA

-Richard T. Fohl
TEL: (716) 691 - 2715
FAX: (716) 691 - 2714

Lucent Secure Solutions SW Cryptographic Implementation
Version 2.0
4/1/2004

ECB(e/d) ; CBC(e/d)

"Lucent SW Cryptographic Implementation is used in Lucent Bricks. The VPN Firewall Brick is a high-speed packet-processing appliance, oriented towards providing security functions. The Bricks are carrier-grade integrated firewall and virtual private network (VPN) gateway appliance specifically designed for web/application data center security, large-scale managed security services, and remote access VPN services. Called the Brick because of its rugged, reliable design, this is an ideal platform for service providers seeking wide scalability, ready manageability, and industry-leading performance."

249 Giesecke & Devrient America, Inc. 
45925 Horseshoe Drive,
Dulles , VA
20166
USA

-Won J Jun
TEL: (703) 480-2145
FAX: (703) 480-2067

-Hassan Tavassoli
TEL: 703-480-2165

Sm@rtCaf?Expert FIPS 64K
Part #HD65246C1A05NB (Firmware Version:CH463JC_IRNABFOP003901_V101)
3/10/2004

ECB(e/d) ; CBC(e/d)

"Giesecke & Devrient (G&D) Smart Card Chip Operating System Sm@rtCaf?Expert FIPS 64K is a Java Card 2.2 and Open Platform v2.0.1' compliant smart card module. It supports, at a minimum, Triple-DES, AES, DSA, and RSA algorithms with on-card key generation. The Sm@rtCaf?Expert FIPS 64K is suitable for government and corporate identification, payment and banking, health care, and Web applications"

248 E.F. Johnson 
299 Johnson Ave.,
PO Box 1249,
Waseca , MN
56093-0514
USA

-John Oblak
TEL: 507-835-6276

Communication Cryptographic Library DES
Version 2.0
4/16/2004

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"This algorithm is used in the E.F. Johnson PC Keyloader - Key Encryption Programmer application."

247 Nokia 
313 Fairchild Drive,
Mt View , CA
94043
USA

-Robert Kusters
TEL: (650) 625-2940

Nokia HW Cryptographic Implementation
Part #NBB3350000
2/18/2004

CBC(e/d)

"The Nokia IP350 and IP380 are full-featured enterprise systems designed for small to medium enterprises, with Service Provider flexibility and rapid serviceability option in a single rack space. When combined with Check Point VPN-1/FW-1, these platforms provide reliable, easy to manage distributed security and access."

246 Oberthur Card Systems 
3150 E. Ana Street,
Rancho Dominguez , CA
90221
USA

-Christophe Goyet
TEL: 310-884-7953
FAX: 310-884-7904

ID-One Cosmo 72K RSA D
Version 0xE302 (Firmware)
2/4/2004

ECB(e/d) ; CBC(e/d)

"The Oberthur Card Systems CosmopolIC 72K RSA Java Card Platform is a single chip cryptographic micro-processor smart card specifically designed for identity and government market needs, with a large memory (72KB), a highly secure architecture and several services and default applications in ROM for ISO 7816 File System, Biometry and Authentication."

245 SonicWALL, Inc. 
1143 Borregas Ave.,
Sunnyvale , CA
94089-1306
USA

-Paal Tveit
TEL: 408-745-9600
FAX: 408-745-9300

SonicWALL PRO 3060/4060
Version 2.0 (Firmware)
2/4/2004

CBC(e/d)

"The PRO 4060 and PRO 3060 are internet security appliances offering stateful packet inspection firewall services, accelerated IPSec VPN, bandwidth management, and dual-WAN port support with ISP failover and load-balancing capabilities, all via six configurable 10/100 Ethernet interfaces."

244 Layer N Networks, Inc. 
12401 Research Blvd.,
Bldg 2, Suite 275,
Austin , TX
78759

-Rick Hall
TEL: 512-250-2129 x135

UltraLock Cryptographic Module
Part #A1
1/14/2004

CBC(e/d)

""The UltraLock?Cryptographic Module performs all the cryptography required for SSL/TLS applications. This module is a common element of the LNN2010 and LNN2025 UltraLock Security Processors, the industry's first single-chip solutions for completely off-loading SSL/TLS processing from host systems. The innovative in-line architecture combines TCP/IP termination and high-speed cryptography to transparently process SSL/TLS traffic at wire speed without impacting host system performance. Industry-standard GMII Ethernet connectivity allows UltraLock processors to drop easily into common networking and security platforms without special software development or complex hardware redesign, greatly reducing time to market.""

243 Blue Ridge Networks 
14120 Parke Long Court,
Chantilly , VA
20151
USA

-Tom Gilbert
TEL: 703-631-0700
FAX: 703-631-9588

BG4000 Cryptographic Module
Part #BG4000
12/18/2003

ECB(e/d) ; CBC(e/d)

"The BG4000 and BG3140 are network security appliances for the construction of secure Virtual Private Networks between Internet sites, and between Internet sites and individual remote users."

242 Mindspeed Technologies, Inc. 
4000 Mac Arthur Blvd.,
Newport Beach , CA
92660
USA

-Elie Massabki
TEL: 949-579-3411
FAX: 949-579-7314

M826xx
Version 1 (Firmware)
12/8/2003

ECB(e/d) ; CBC(e/d)

"M826xx is Communications Convergence Processor for Voice over IP (VoIP) and Voice over ATM (VoATM) applications."

241 M/A-COM, Inc. 
221 Jefferson Ridge Parkway,
Lynchburg , VA
24501
USA

-Daryl Popowitch

P7100/M7100 DES Algorithm
Version R4A (Firmware)
11/26/2003

OFB(e/d)

"Implementation Description"

240 Enterasys Networks 
50 Minuteman Road,
Andover , MA
01810
USA

-Damon Hopley
TEL: 978-684-1083

Enterasys Cryptographic Hardware
Part #SafeNet 1140; HW: Version 1.0
11/7/2003

CBC(e/d)

"Hardware cryptographic algorithm implementations for the XSR product line."

239 Enterasys Networks 
50 Minuteman Road,
Andover , MA
01810
USA

-Damon Hopley
TEL: 978-684-1083

Enterasys IR Cryptographic Library
Version 1.0
11/7/2003

CBC(e/d)

"Software cryptographic algorithm implementations for the XSR product line."

238 Enterasys Networks 
50 Minuteman Road,
Andover , MA
01810
USA

-Damon Hopley
TEL: 978-684-1083

Enterasys SSH Cryptographic Library
Version 1.0
11/7/2003

CBC(e/d)

"Software cryptographic algorithm implementations for the XSR product line."

237 IBM Corporation 
2455 South Road,
Poughkeepsie , NY
12601
USA

-Tamas Visegrady
TEL: 845-435-8512
FAX: 845-435-1858

UltraCypher 2 Crytographic Engine
Part #1.0
10/23/2003

CBC(e/d)

"The IBM UltraCypher 2 Cryptographic Engine is a flexible, high performance subsystem that provides fast, ultra-secure, hardware-based cryptographic functionality."

236 Hifn, Inc. 
750 University Avenue,
Los Gatos , CA
95032
USA

-Glenn Haley
TEL: (408) 399-3545

7956
Part #7956; Version 1.0
10/20/2003

ECB(e/d) ; CBC(e/d)

"The Hifn 7955 and 7956 are advanced security processors designed for high-speed T3/OC3, ROBO/SME networking applications like VPN Broadband Routers, wireless access points, VPN Edge Routers/Gateways, Firewall/VPN Appliances and other Network and Customer Premise Equipment (CPE)."

235 Hifn, Inc. 
750 University Avenue,
Los Gatos , CA
95032
USA

-Prasad Shroff
TEL: (408) 399-3586

7814-W
Part #7814-W
10/20/2003

ECB(e/d) ; CBC(e/d)

"Hifn Intelligent Packet Processing chips are full-duplex T3 to full-duplex OC-12, Integrated public key, 3DES, Advanced Encryption Standard (AES), and compression - the latest chips from Hifn have it all in a single high-performance package."

234 3Com Corporation 
5500 Great America Parkway,
Santa Clara , CA
95052
USA

-Victoria Van Spyk
TEL: 408-326-1581

3Com's IPSec Offload Integrated Circuit
Part #40-0728-001
10/10/2003

ECB(e/d) ; CBC(e/d)

"3Com's IPSec Offload Integrated Circuit is hardware based crypto device that performs IPSec (DES, TDES, SHA-1, MD5 and HMAC) computations on 3Com's series of Secure Network Interface Cards and Embedded Firewall products."

233 SafeNet, Inc. 
8029 Corporate Drive,
Baltimore , MD
21236
USA

-Joel Rieger
TEL: 443-442-8199

SafeXcel 1141/1741
Part #11
9/30/2003

CBC(e/d)

"The SafeXcel 1141/1741 ASICs are part of the SafeNet IPsec co-processor chip family. The devices consist of an IPsec Packet Engine that performs DES, TDES, AES, SHA-1, MD5, header/trailer and insertion/deletion operations, a Public Key Accelerator that performs RSA, DSA, and DH operations using long vector math up to 2048 bits, and a Random Number Generator that provides up to 2 Mbps of random data."

232 IDT 
2975 Stender Way,
Santa Clara , CA
95054
USA

-Alex Soohoo
TEL: 408-330-1714
FAX: 408-330-1748

RC32365
Part #ZA
9/16/2003

ECB(e/d) ; CBC(e/d)

"The Interprise Access RC32365 is an integrated communications processor that addresses the secure SOHO wired/wireless gateway and VPN/firewall appliance markets by incorporating a high-performance CPU, an on-chip security engine and key peripheral interfaces."

231 F-Secure Corporation 
Tammasaarenkatu 7,
PL 24,
Helsinki
00181
Finland

-Alexey Kirichenko
TEL: +358 9 2520 5548

F-Secure(R) Cryptographic Library ?/B>
Version 2.1
8/27/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"The F-Secure Cryptographic Library for Windows is a 140-2 Level 2 compliant software module, implemented as a 32-bit Windows compatible DLL. The module provies an assortment of cryptographic services to client processes that attach instances of the module DLL."

230 Microsoft Corporation 
One Microsoft Way,
Redmond , WA
98052-6399
USA

-Mike Lai

Windows 2003 Kernel Mode Cryptographic Module (fips.sys)
Version 5.2.3790.0
8/19/2003

ECB(e/d) ; CBC(e/d)

"Kernel level .sys module exporting cryptographic functionality."

229 Microsoft Corporation 
One Microsoft Way,
Redmond , WA
98052-6399
USA

-Mike Lai

Windows 2003 Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH)
Version 5.2.3790.0
8/5/2003

ECB(e/d) ; CBC(e/d)

"The Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider is a FIPS 140-2 compliant, software-based, cryptographic module.RSAENH encapsulates several different cryptographic algorithms (including SHA-1, DES, 3DES, DSA, SHA-1-based HMAC) in a cryptographic module accessible via the Microsoft CryptoAPI."

228 Research in Motion 
295 Phillip Street,
Waterloo , Ontario
N2L 3W8
Canada

-Ian Robertson
TEL: 519-888-7465
FAX: 519-883-4924

BlackBerry Cryptographic API
Version 3.6
7/14/2003

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

"BlackBerry?is the leading wireless enterprise solution that allows users to stay connected with secure, wireless access to email, corporate data, phone, web and organizer features. BlackBerry?is a totally integrated package that includes hardware, software and service, providing a complete end-to-end solution. The BlackBerry?Cryptographic API provides advanced cryptographic functionality for the BlackBerry?"

227 Schlumberger 
8311 North FM 620 Rd.,
Austin , TX
78726
USA

-Mike Neumann
TEL: 512-257-3848
FAX: 512-257-3881

Cyberflex Access 64K V2
Part #M516LACC2 Hardmask 1V1 Softmask 2V1
7/14/2003

ECB(e/d) ; CBC(e/d)

"The Cyberflex Access 64K V2 smart card can be employed in solutions which provide secure PKI (public key infrastructure) and digital signature technology. Cyberflex Access 64K V2 serves as a highly portable, secure token for enhancing the security network access and ensuring secure electronic communications."

226 Microsoft Corporation 
One Microsoft Way,
Redmond , WA
98052-6399
USA

-Mike Lai

Windows 2003 Enhanced Cryptographic Provider (RSAENH)
Version 5.2.3790.0
6/30/2003

ECB(e/d) ; CBC(e/d)

"The Microsoft Enhanced Cryptographic Provider is a FIPS 140-2 compliant, software-based, cryptographic module.RSAENH encapsulates several different cryptographic algorithms (including SHA-1, DES, 3DES, AES, RSA, SHA-1-based HMAC) in a cryptographic module accessible via the Microsoft CryptoAPI."

225 Sun Microsystems 
4150 Network Circle,
Santa Clara , CA
95054
USA

-Javier Lorenzo
TEL: (858) 625-6020

-Irfan Khan
TEL: 510.936.4840

Sun Crypto Accelerator 4000
Version 1.0 (Hardware)
Part # X4011A Sun Crypto Accelerator 4000 - Copper
6/25/2003

CBC(e/d)

"Cryptographic Acceleration Card"

224 IBM 
11400 Burnet Rd,
Austin , TX
78758
USA

-Tom Benjamin
TEL: 512.436.1223
FAX: 512.436.8009

IBM Java JCE 140-2 Cryptographic Module
Version 1.0
6/19/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"The IBM?Java?JCE (Java Cryptographic Extension) FIPS provider (IBMJCEFIPS) for Multi-platforms is a scalable, multi-purpose cryptographic module that supports only FIPS approved cryptographic operations via the Java2 Application Programming Interfaces (APIs)."

223 Bluesocket, Inc. 
7 New England Executive Park,
Burlington , MA
01803
USA

-Mike Puglia
TEL: (781) 328-0888
FAX: (781) 328-0899

WG-2100 Wireless Gateway
Version Release 3
6/10/2003

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

"The Bluesocket WG-2100 Wireless Gateway provides a single scalable solution to the security, quality of service (QoS), and management issues facing institutions, enterprises, and service providers who deploy 802.11 and Bluetooth-based wireless networks."

222 Pitney Bowes, Inc. 
35 Waterview Drive,
Shelton , CT
06484
U.S.A.

-Douglas Clark
TEL: 203.924.3500
FAX: 203.924.3406

Pitney Bowes iButton Postal Security Device (PSD)
Part #DS1955B PB0 1.00c
6/6/2003

ECB(e/d)

"The Pitney Bowes iButton Postal Security Device (PSD) has been designed in compliance with the United States Postal Service (USPS), Information-Based Indicia Program (IBIP). It employs strong encryption, decryption, and digital signature techniques for the protection of customer funds and the production of postage meter indicia in a variety of Pitney Bowes Metering products. The PSD has been designed to support international postal markets and their evolving requirements for digital indicia."

221 E.F. Johnson 
299 Johnson Ave.,
PO Box 1249,
Waseca , MN
56093-0514
USA

-John Oblak
TEL: 507-835-6276

Subscriber Encryption Module
Version 1.0
5/7/2003

ECB(e/d) ; CBC(e/d) ; CFB1(e/d) ; OFB(e/d)

"The Subscriber Encryption Module (SEM) is a cryptographic module which supports the AES, DES, DSA, and SHA-1 algorithms. The SEM is used in subscriber equipment such as the E.F. Johnson radios to provide secure, encrypted voice and data communication."

220 IBM Zurich Research Laboratory 
Saeumerstrasse 4,
Rueschlikon , CH
8803
Switzerland

-Michael Osborne
TEL: (41) (1) 724 8458
FAX: (41) (1) 724 8953

IBM CryptoLite in C
Version 3.0 (FIPS140/Prod)
4/18/2003

ECB(e/d) ; CBC(e/d)

"IBM CryptoLite is a C software package providing advanced Cryptographic services in a very small footprint. CryptoLite supports public key encryption, digital signatures, symmetric ciphers, hash functions, message authentication codes, and other cryptographic algorithms through a simple programming interface. There are no runtime dependencies and the code has been optimized for high performance."

219 Nauticus Networks 
200 Crossing Boulevard,
Framingham , MA
01702
USA

-Matt Rollender, Director of Marketing
TEL: 508.270.0500

N2000 Series Switch
Version 1.0
4/7/2003

CBC(e/d)

"Nauticus Networks N2040 and N2120 are purpose built application switches that enable cost effective, reliable, deployment of intergrated network and security services, delivering gigabit scaled Layer 5-7 application switching, Layer 4 load balancing, and SSL acceleration to the most demanding enterprise and service provider environments."

218 M/A-COM, Inc. 
221 Jefferson Ridge Parkway,
Lynchburg , VA
24501
USA

-Mr. Stefan Backstrom
TEL: (434) 455-6600
FAX: (434) 455-6851

Orion C57
Version DSP R2B
4/2/2003

OFB(e/d)

"The Orion C57 is used with the EDACS ProVoice Orion Mobile with FIPS 140-2 security level 1 validation. Digital voice, conventional and trunked; system and scan front mounting."

217 Hifn, Inc. 
750 University Avenue,
Los Gatos , CA
95032
USA

-Prasad Shroff
TEL: (408) 399-3586

8154PB5
Version Rev 1.0
Part #8154PB5
3/23/2003

ECB(e/d) ; CBC(e/d)

"Hifn Intelligent Packet Processing chips are full-duplex T3 to full-duplex OC-12, Integrated public key, 3DES, Advanced Encryption Standard (AES), and compression - these latest chips from Hifn have it all in a single high-performance package."

216 IBM Corporation 
3901 S. Miami Blvd.,
Durham , NC
27703
USA

-Mike Allen

IBM Crypto for C
Version 0.1
3/20/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"The ICC is a C language implementation of cryptographic functions which uses the cryptograhic library provided by the OpenSSL project. This enables IBM products to use an open source solution for cryptography and a FIPS 140-2 certificate cryptographic provider."

215 Oracle Corporation 
500 Oracle Parkway,
Redwood Shores , CA
94065
USA

-Lakshmi Kethana
TEL: (650) 506-9315

Oracle Crypto Library for SSL
Version 9.0.4
3/6/2003

CBC(e/d)

"The Cryptographic Library for SSL is a generic module used in a variety of Oracle application suites. It provides support for cryptography, authentication, PKCS and certificate management for applications like the Oracle database (Server & Client), Oracle Applications Server, Oracle Internet Directory, Web Cache and Apache."

214 LSI Logic Corporation 
1778 McCarthy Blvd.,
Milpitas , CA
95035
USA

-Dan Watkins
TEL: 408-433-7105
FAX: 408-433-7447

SC2005 (DirecTV DES descrambler)
Part #Version F
3/6/2003

ECB(d only)

"The des module is part of LSI Logic's extensive line of Coreware modules for ASIC development."

213 LSI Logic Corporation 
1778 McCarthy Blvd.,
Milpitas , CA
95035
USA

-Dan Watkins
TEL: 408-433-7105
FAX: 408-433-7447

SC2005 (TDES/DES engine)
Part #Version F
3/6/2003

ECB(e/d)

"The DES and TDES modules are part of LSI Logic's extensive line of Coreware modules for ASIC development."

212 Cisco Systems, Inc 
7025-6 Kit Creek Road,
PO Box 14987,
Research Triangle Park , NC
27709-4987
USA

-Ray Potter
TEL: 919-392-6789

VPN Client
Version 3.6.3B
2/20/2003

CBC(e/d)

"The Cisco VPN Client enables you to establish secure, end-to-end encrypted tunnels. The client can be pre-configured for mass deployments and initial logins require very little user intervention. VPN access policies and configurations are downloaded from the central gateway and pushed to the client when a connection is established, allowing simple deployment and management, as well as high scalability."

211 TANDBERG Telecom AS 
Philip Pedersens vei 22,
P.O. Box 92, 1325,
LYSAKER , NORWAY
NORWAY

-Tor Erik Pedersen
TEL: +47 67 125 125

TT_Encryption
Version 1.0
2/20/2003

ECB(e/d)

"a software cryptographic service library, used by all TANDBERG Videoconferencing systems. This software library provides encryption of video, voice and data in point-to-point and multipoint calls, over circuit-switched (ISDN, H.320) and packet-based (IP, H.323) networks according to the ITU H.233 and H.235 standards."

210 Cisco Systems, Inc 
7025-6 Kit Creek Road,
PO Box 14987,
Research Triangle Park , NC
27709-4987
USA

-Ray Potter
TEL: 919-392-6789

VPN 3000 Concentrator Series
Version 3.6
2/13/2003

CBC(e/d)

"The Cisco VPN 3000 Concentrator Series is a best-of-breed, remote-access VPN solution for enterprise-class deployment. The validation includes hardware models 3005, 3015, 3030, 3060, 3080 and the 3002 hardware client."

209 Colubris Networks Inc. 
420 Armand-Frappier (suite 200),
Laval , Quebec
H7V 4B4
Canada

-St?hane Laroche
TEL: (450) 680-1661 x123
FAX: (450) 680-1910

Libfips
Version 1.0
2/4/2003

ECB(e/d) ; CBC(e/d)

"Colubris CN105x Secure Wireless LAN Router enables strong security for wireless enterprise networking, using embedded IPSec VPN and firewall functionalities. Lipfips is the User mode implementation in the CN1050 and CN1054 Wireless LAN Routers."

208 IBM Zurich Research Laboratory 
Saeumerstrasse 4,
Rueschlikon , CH
8803
Switzerland

-Michael Osborne
TEL: (41) ( 1 ) 724 8458
FAX: (41) (1) 724 8953

IBM CryptoLite in Java
Version 3.0 (FIPS140/Prod)
1/30/2003

ECB(e/d) ; CBC(e/d)

"IBM CryptoLite is a 100% Java software package providing advanced cryptographic services in a very small footprint. CryptoLite supports public key encryption, digital signatures, symmetric ciphers, hash functions, message authentication codes, and other cryptographic algorithms through a simple programming interface. There are no runtime dependencies and the code has been optimized for high performance. It runs on JDK 1.1 or higher."

207 SSH Communications Security Corp 
Fredrikinkatu 42,
Helsinki
00100
Finland

-Markus Levlin
TEL: +358 20 500 7518
FAX: +358 20 500 7390

SSH CryptoLib
Version 1.0
1/30/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"The SSH Cryptographic Library is a standards-based shared library providing FIPS 140-2 certified cryptographic services for SSH Communications Security's security products. The library provides a rich API and a comprehensive set of state-of-the-art algorithms including AES, 3DES, SHA-1, HMAC, RSA and DSA."

206 Hifn, Inc. 
750 University Avenue,
Los Gatos , CA
95032
USA

-Prasad Shroff
TEL: (408) 399-3586

7814-WPB4
Version 1.0
Part #7814-WPB4
1/17/2003

ECB(e/d) ; CBC(e/d)

"Hifn Intelligent Packet Processing chips are full-duplex T3 to full-duplex OC-12, Integrated public key, 3DES, Advanced Encryption Standard (AES), and compression - these latest chips from Hifn have it all in a single high-performance package."

205 D'Crypt Pte Ltd 
20 Ayer Rajah Crescent,
#08-08 Technopreneur Centre,
Singapore
139964
Singapore

-Quek Gim Chye
TEL: (65)6776-9210

d'Cryptor QE Firmware
Version 2.0
1/17/2003

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"The d'Cryptor QE is a multi-chip embedded security module designed for high security assurance applications. It comprises a secure high-performance cryptographic core, generous memory in the form of a Flash ROM and NVRAM, and implements physical security through an opaque, hard epoxy potting and a tamper detection and response mesh. The QE firmware builds in a wide range of cryptographic support and accepts a user-programmable external application. Cryptographic services are provided through a library and an API. All keys and cryptographic processing are isolated within this library and accessible only through the API."

204 Hifn, Inc. 
750 University Avenue,
Los Gatos , CA
95032
USA

-Prasad Shroff
TEL: (408) 399-3586

7854PB4/3
Version 3.0
Part #7854PB4/3
1/17/2003

ECB(e/d) ; CBC(e/d)

"Hifn Intelligent Packet Processing chips are full-duplex T3 to full-duplex OC-12, Integrated public key, 3DES, Advanced Encryption Standard (AES), and compression - these latest chips from Hifn have it all in a single high-performance package."

203 SonicWALL, Inc. 
1143 Borregas Ave.,
Sunnyvale , CA
94089-1306
USA

-Paal Tveit
TEL: 408-745-9600
FAX: 408-745-9300

Cisco CSS Series 11000 Secure Content Accelerator/SonicWALL SSL-RX
Version 4.1 (firmware)
1/17/2003

CBC(e/d)

"The SCA2/SSL-RX is an SSL proxy device designed for SSL acceleration and offloading. The SCA2/SSL-RX provides the ability to both terminate and initiate SSL connections, converting cipher-text to clear-text, or clear-text to cipher-text."

202 Cisco Systems, Inc 
7025-6 Kit Creek Road,
PO Box 14987,
Research Triangle Park , NC
27709-4987
USA

-Ray Potter
TEL: 919-392-6789

Cisco IOS Encryption Software
Version 12.2
1/17/2003

CBC(e/d)

"Cisco IOSR Software, the industry-leading and most widely deployed network system software, delivers intelligent network services on a flexible networking infrastructure that enables the rapid deployment of Internet applications."

201 Broadcom Corporation 
1131 W. Warner Rd.,
Tempe , AZ
85284
USA

-Joe Wallace
TEL: 480-753-2279

BCM5840
Part #B3
12/10/2002

CBC(e/d)

"The BCM5840 delivers multi-gigabit performance for IPSec VPN applications."

200 Giesecke & Devrient America, Inc. 
45925 Horseshoe Drive,
Dulles , VA
20166
USA

-Won J. Jun
TEL: (703) 480-2145
FAX: (703) 480-2067

STARCOS SPK 2.4 in ID-1 module
Part #CP5WxSPKI24-01-3-S V0310
12/2/2002

CBC(e/d)

"Giesecke & Devrient (G&D) Smart Card Chip Operating System Standard Version with Public Key Extension 2.4 (STARCOS SPK 2.4) is a scaleable multi-application operating system for smart cards and provides functionalities that are necessary for public key infrastructure."

199 Aladdin Knowledge Systems, Ltd. 
15 Beit Oved Street,
Tel Aviv
61110
Israel

-Leedor Agam
TEL: (972) 3 636 5124
FAX: (972) 3 537 5796

eToken Pro 32K (Cryptographic Engine)
Version 4.2
11/26/2002

ECB(e/d) ; CBC(e/d)

"The eToken PRO is a fully portable USB device the size of an average house key which offers a cost-effective method for authenticating users when accessing a network and for securing electronic business applications. The eToken PRO offers security needs such as secure network logon, secure VPN's, secure email, and strong PKI support."

198 Aladdin Knowledge Systems, Ltd. 
15 Beit Oved Street,
Tel Aviv
61110
Israel

-Leedor Agam
TEL: (972) 3 636 5124
FAX: (972) 3 537 5796

eToken Pro 16K (Cryptographic Engine)
Version 4.1
11/26/2002

ECB(e/d) ; CBC(e/d)

"The eToken PRO is a fully portable USB device the size of a house key which offers a cost-effective method for authenticating users when accessing a network and for securing electronic business applications. The eToken PRO offers security needs such as secure network logon, secure VPN's, secure email, and PKI support."

197 IBM Zurich Research Laboratory 
Saeumerstrasse 4,
Rueschlikon , CH
8803
Switzerland

-Michael Osborne
TEL: (41) ( 1 ) 724 8458
FAX: (41) ( 1 ) 724 8953

JCOP21id 32K
Version JCOP21id Mask 20 (firmware)
Part #P8WE5033 AEV 1034 188i
11/14/2002

ECB(e/d) ; CBC(e/d)

"The JCOP21id is IBM's multi-application smart card, designed to the Java Card v2.1.1 and Global Platform v2.0.1 specifications. The smart card features IBM's PKCS#15 applet which provides standardized high-level security services including, 2048 bit key generation, DES, 3DES, SHA, RSA and AES."

196 Wei Dai 
Groove Networks, Inc.,
100 Cummings Center,
Suite 535Q,
Beverly , MA
01915
USA

-Wei Dai
TEL: (978)720-2173
FAX: (978)720-2001

Crypto++ Library
Version 5.01
11/14/2002

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

"The Crypto++ Library is a free, open source C++ class library providing public key encryption, digital signatures, symmetric ciphers, hash functions, message authentication codes, and other cryptographic algorithms. The pre-compiled Win32 static library is FIPS 140-2 Level 1 validated. The library is also available in source code form."

195 Phaos Technology Corporation 
11 Broadway,
Suite 501,
New York , NY
10004
USA

-Darren Calman
TEL: (212) 514-6515
FAX: (212) 514-6528

Phaos Crypto
Version 3.0
11/6/2002

ECB(e/d) ; CBC(e/d)

"Phaos Crypto provides a state-of-the-art set of core cryptography algorithms in Java. It includes a comprehensive cryptographic library supporting the most current algorithms like AES, RSA-OAEP, SHA-256/384/512, X.9-42 as well as legacy algorithms that are still used in corporate systems like 3DES, DES, MD2 etc.. Phaos Crypto allows developers to integrate cryptography into any Java application or applet. For high security deployments, Phaos Crypto provides transparent migration to cryptographic hardware without requiring any changes to existing applications."

194 Stonesoft Corporation 
It?ahdenkatu 22A, , Helsinki
FIN-00210
Finland

-Klaus Majewski
TEL: (678) 259-3411

StoneGate High Availability Firewall and VPN implementation of SSH Toolkit Library
Version 4.1.1-22
10/31/2002

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d)

"StoneGate is a firewall and VPN solution. It features clustering, load balancing between multiple ISPs, encrypted VPN client connectivity and advanced central administration tools."

193 Datakey, Inc. 
407 W. Travelers Trail,
Burnsville , MN
55337-2554
USA

-Hazem Hassan
TEL: (952) 890-6850

Model 330J with JCCOS applet
Version 2.0
10/24/2002

ECB(e/d) ; CBC(e/d)

"The Model 330J is Datakey's multi-application smart card, designed to the JavaCard v2.1.1 and Global Platform v2.0.1 specifications. The smart card features Datakey's JCCOS applet. JCCOS is an advanced cryptographic applet that, when loaded onto a multi-application JavaCard provides high-level security services."

192 SchlumbergerSema 
50 avenue Jean Jaures,
Montrouge Cedex
92542
FRANCE

-Bruno Blanchard
TEL: +33 1 46007456

Cyberflex Access e-Gate 32K
Version M256LCAEG1_ST_62_02_03, SM3v1
Part #ST19XT34
10/24/2002

ECB(e/d) ; CBC(e/d)

"Cyberflex Access e-Gate 32K smart card serves as a highly portable, secure token for enhancing the security of network access and ensuring secure electronic communications, supporting on-card DES aND RSA algorithms with on-card key generation."

191 IBM Corporation 
CC1A/502/K301,
4205 S. Miami Blvd.,
Durham , NC
27703
USA

-Keith Medlin
TEL: +1-919-543-2014
FAX: +1-919-486-0675

IBM Everyplace Wireless Gateway Cryptographic Module
Version 1.5
10/24/2002

ECB(e/d) ; CBC(e/d)

"The IBM Everyplace Wireless Gateway is a distributed, scalable, multipurpose communications platform that supports optimized, secure data access over a wide range of international wireless and wire line network technologies. The cryptographic module implements a variety of encryption services for the product."

190 Entrust, Inc. 
1000 Innovation Drive,
Ottawa , Ontario
K2K 3E7
Canada

-Pierre Boucher
TEL: 613-270-2599
FAX: 613-270-2504

Entrust Authority Toolkit for Java
Version 6.1
10/7/2002

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

"The Security Toolkit for Java takes advantage of the features of a Public Key Infrastructure (PKI) from a Java environment. The Toolkit provides the means to incorporate security features, such as encryption and digital signatures, into applications."

189 Motorola 
200 North Point Center East,
Suite 400,
Alpharetta , GA
30022
USA

-Alfred Adler
TEL: 770-521-5128
FAX: 770-521-8066

Encryption DLL Module
Version 3.0
10/1/2002

ECB(e/d) ; CBC(e/d)

"The Encryption DLL Module is incorporated into the Motorola Messaging Server, an enterprise system for managing data between a corporate e-mail or database system and a wireless device, and the Motorola MyMail Desktop Plus, a personal application to manage e-mail between the desktop and a wireless device."

188 Motorola 
200 North Point Center East,
Suite 400,
Alpharetta , GA
30022
USA

-Christopher Yasko
TEL: (770)521-5150
FAX: (770)521-8067

Encryption Services Module
Version 5.3
10/1/2002

ECB(e/d) ; CBC(e/d)

"The Encryption Services Module is incorporated into the operating software of the Accompli 009 -- the first wireless communications device to incorporate tri-band GSM and GPRS protocols, phone functionality, Internet access, e-mail, Triple-DES encryption, WAP browser and short message service (SMS) with a full QWERTY keyboard and 256-color screen."

187 ASN Technology Corp. 
3th Fl., No. 22, Lane 31, Sec. 1, Hyandung Rd.,
744 Tainan Science-Based Industrial Park,
Tainan
Taiwan

-Jeng-Yang Hwang (Eric Hwang)
TEL: 886-6-6009636 ext 200

ASN eShield Cryptor Encryption/Decryption Processor Chip
Part #TAD0704-a
9/17/2002

ECB(e/d)

"ASN eShield Cryptor Encryption/Decryption Processor (TAD0704-a) is a cryptographic chip designed for system flexibility to ease secure system implementations. It is a ciphering engine supporting the Advanced Encryption Standard (AES), Data Encryption Standard (DES) and Triple-DES encryption/decryption algorithms. The chip performs AES, DES and Triple-DES at 30 MHz with 16bits I/O interface."

186 RSA Security, Inc. 
2955 Campus Drive,
Suite 400,
San Mateo , CA
94403
USA

-Bill Kennedy
TEL: (650) 295-7600 x512

RSA Crypto-C ME
Version 1.7
9/9/2002

ECB(e/d); CBC(e/d); CFB( 64 bits;e/d); OFB(e/d)

"The Crypto-C ME Module is RSA Security, Inc.'s cryptographic library designed for securing mobile devices like wireless phones and personal digital assistants. It contains assembly-level optimizations on key wireless processors while offering great flexibility and choice by allowing developers to select only the algorithms needed in reduced code sizes. Its functionality includes a wide range of data encryption and signing algorithms, including TDES, the high performing RC5, the RSA Public Key Cryptosystem, the DSA government signature algorithm, MD5 and SHA1 message digest routines, and more."

185 Columbitech 
Maria Bangatan 4A,
Box 381 73,
Stockholm
SE-100 64
Sweden

-David Broman
TEL: 46(0)8-55608119
FAX: 46(0)8-55608101

Airbeam Safe
Version 1.4
9/20/2002

CBC(e/d)

"WVPN software that enables strong encryption and roaming on Windows client, Pocket PC and DOS-devices. Focus on security, performance and convenience."

184 Netscreen Technologies, Inc. 
350 Oakmead Parkway,
Sunnyvale , CA
94085
USA

-Lee Klarich
TEL: (408)543-8209
FAX: 408-543-8200

GigaScreen-II ASIC
Version 4.0.0 (Firmware)
Part #T8F05TB-0002
9/9/2002

CBC(e/d)

"The core security processor within NS-5200 security system, which delivers firewall, VPN, and traffic management optimized for the most demanding environments such as high traffic e-business sites, co-location facilities, ASP/ISP data centers and enterprise central sites."

183 Broadcom Corporation 
1131 W. Warner Rd.,
Tempe , AZ
85284
USA

-Joe Wallace
TEL: 480-753-2279
FAX: 480-753-2380

BCM5805, BCM5820, BCM5821, BCM5822
Version B5, B0, A2, A2
9/9/2002

CBC(e/d)

"The BCM5805 delivers industry leading performance and security functions for eCommerce and VPN applications."

182 Mitsubishi 
5-1-1 Ofuna,
Kamakura
247-8501
Japan

-Tetsuo Nakakawaji
TEL: 81-0467-41-2186

TurboMisty
Version 2.0.1.1
8/22/2002

ECB(e/d); CBC(e/d)

"Encryption Accelerator Card"

181 Motorola, Inc - Semiconductor Products Sector 
6501 William Cannon Drive West,
MD: OE56,
Austin , TX
78735-8598
USA

-Geoff Waters
TEL: (512)933-6419

Cerberus, Rev 0
Part #PPC190VF
7/16/2002

ECB(e/d); CBC(e/d)

"The Cerberus PPC190 is a security co-processor, designed to accelerate encryption and authentication algorithms commonly used in networking and communications. The PPC190 connects to the host system via a PCI bus. See Technical Summary for additional details."

180 Certicom Corporation 
Certicom Corporate Headquarters,
5520 Explorer Drive, 4th Floor,
Mississauga , ON
L4W 5L1
Canada

-Mike Harvey (Product Manager)
TEL: (905) 507-4220
FAX: (905) 507-4230

-Certicom Eastern US Sales Office
TEL: (571)203-0700
FAX: (571)203-9653

Security Builder Government Solutions Edition
Version 1.0
6/26/2002

ECB(e/d); CBC(e/d); CFB( 64 bits;e/d); OFB(e/d)

"A standards-based cryptography toolkit that provides application developers with the sophisticated tools and flexibility needed to integrate encryption, digital signatures, and other security mechanisms into their applications. Security Builder GSE supports optimized Elliptic Curve Cryptography and the RSA algorithm."

179 SchlumbergerSema 
50 avenue Jean Jaures,
Montrouge Cedex
92542
FRANCE

-Renaud Presty
TEL: 33 1 47 46 61 83
FAX: 33 1 47 46 68 40

Cyberflex Access 64K
Version 01
Part #M512LACC1_SI_29_05_01
6/13/2002

ECB(e/d); CBC(e/d)

"The Cyberflex Access 64K smart card can be employed in solutions which provide secure PKI (public key infrastructure) and digital signature technology. Cyberflex Access 64K serves as a highly portable, secure token for enhancing the security of network access and ensuring secure electronic communications. Cyberflex Access 64K supports on-card Triple DES and 1024-bit RSA algorithms with on-card key generation. It is compliant to Java Card v2.1.1 and Open Platform v2.0.1. The Cyberflex Access 64K smart card is part of a range of SchlumbergerSema highly secure, Java-based smart cards for physical and logical access, e-transactions and other applications."

178 IBM Corporation 
2455 South Road,
Poughkeepsie , NY
12601
USA

-Barry K. Ward
TEL: 1-845-435-4881
FAX: 1-845-435-5540

IBM 4758 PCI Cryptographic Coprocessor CP/Q++
Version 2.41
5/30/2002

ECB(e/d); CBC(e/d)

"The IBM 4758 PCI Cryptographic Coprocessor provides a secured environment in which application programs can perform and carry out cryptographic functions."

177 Lipman Electronic Engineering Ltd. 
11 Haamal Street Park Afek,
Rosh Haayin
48092
Israel

-Mr. David Kaplan
TEL: 972 3 902 97 30
FAX: 972 3 902 97 31

NURIT 202 PIN Pad
Part #NURIT 0202-TR-M03-XXX

5/30/02 - Date certificate originally validated for ECB only; 12/16/02 - Date CBC validated - no reissuing of certificate - letter #51 received 5/31/02

12/16/2002

ECB(e/d) ; CBC(e only)

"Secure PIN Entry Device (PED) for EFT POS Terminals. **NOTE: "XXX" in P/N indicates plastic case colour.**"

176 Hifn, Inc. 
750 University Avenue,
Los Gatos , CA
95032
USA

-Glenn Young
TEL: 408-399-3500

HiFn 8065
Version R1
Part #8065-PBn/n
5/28/2002

ECB(e/d); CBC(e/d)

"The 8065 chip is used in network security products. Security algorithms include DES, TDES, AES, and SHA-1, which conform to NIST requirements."

175 Novell, Inc. 
1800 South Novell Place,
Provo , UT
84606
USA

-Gabriel Waters
TEL: 880-453-1267

Solaris NICI
Version 2.4.0
Part #870-000768-001
5/28/2002

CBC(e/d)

"Novell International Cryptographic Infrastructure for Solaris"

174 Netscreen Technologies, Inc. 
350 Oakmead Parkway,
Sunnyvale , CA
94085
USA

-Lee Klarich
TEL: 408-543-8209
FAX: 408-543-8200

NetScreen 204/208
Part #T8F59TB-0101
5/20/2002

CBC(e/d)

"NetScreen 204/208 are purpose-built internet security appliances that deliver firewall, VPN, and traffic shaping optimized for the most demanding environments such as high traffic e-business sites, co-location facilities, ASP/ISP data centers and enterprise central sites."

173 nCipher Inc. 
500 Unicorn Park Drive,
Woburn , MA
01801-3371
USA

-Marcus Streets
TEL: +1(781)994-4000

nCipher Algorithm Library
Version 2
5/9/2002

ECB(e/d); CBC(e/d)

"The nCipher algorithm library provides cryptographic functionality for nCipher's nForce 800/1600 secure e-commerce accelerators and nShield Hardware Security Modules."

172 BRECIS Communications 
2025 Gateway Place,
Suite 132,
San Jose , CA
95110
USA

-Raymond Tan
TEL: 408-437-9900 X5113
FAX: 408-437-1101

MSP2000
Version 1.0
5/9/2002

ECB(e/d); CBC(e/d); CFB( 64 bits;e/d)

"MSP2000 is Multi-Service Processor targeted at security appliances and business-class Ethernet-to-Ethernet routers where high-performance, secure communications is a key requirement."

171 Information Security Corporation 
1141 Lake Cook Road,
Suite D,
Deerfield , IL
60015
USA

-Michael J. Markowitz, VP R&D
TEL: (847)405-0500

ISC Cryptographic Development Kit (CDK)
Version 7.0
5/8/2002

ECB(e/d) ; CBC(e/d) ; CFB8(e/d) ; CFB64(e/d) ; OFB(e/d)

"A software development toolkit providing a comprehensive set of cryptographic primitives for use in any application. Includes RSA, DSA/Diffie-Hellman and elliptic curve algorithms, as well as a wide range of symmetric ciphers and hash functions."

170 Hifn, Inc. 
750 University Avenue,
Los Gatos , CA
95032
USA

-Glenn Young
TEL: (408)399-3500

HiFn 8165
Version R1
Part #8165-PBn/n
5/8/2002

ECB(e/d); CBC(e/d)

"The 8165 chip is used in network security products. Security algorithms include DES, TDES, AES, and SHA-1, which conform to NIST requirements."

169 Broadcom Corporation 
1131 W. Warner Rd.,
Tempe , AZ
85284
USA

-Joe Wallace
TEL: (480)753-2279
FAX: (480)753-2380

BCM5821
Part #Revision A1
4/29/2002

CBC(e/d)

"The BCM5821 delivers industry leading performance and security functions for eCommerce and VPN applications Systems with PCI"

168 RSA Security, Inc. 
2955 Campus Drive,
Suite 400,
San Mateo , CA
94403
USA

-Kathy Kriese
TEL: (650)295-7692

RSA Crypto-J
Version 3.3.3
4/24/2002

ECB(e/d); CBC(e/d); CFB( 8,64 bits;e/d); OFB(e/d)

"The Crypto-J Module is a Java-language software dvelopment kit that allows software and hardware developers to incorporate encryption technologies directly into their products."

167 Cylink Corporation - ATM Technology Centre 
951 Aviation Pkwy,
Suite 300,
Morrisville , NC
27560
USA

-Glenn Constable
TEL: (919)462-1900x212
FAX: (919)462-1933

Cylink ATM Encryptor Single Direction TDES Encryption ASIC
Part #247-001-001
4/24/2002

ECB(e/d)

"The ATM Encryptor is a stand alone hardware product which sets between the customer's premise and the public network. It encrypts ATM traffic departing the customer's premise and decrypts ATM traffic received at the customer's premise. The ATM Encryptor contains 3 basic sections. The first is the Media Interface section. The second is the Encryption/Decryption section. And the third is the Control or "Host" section. For purposes of FIPS, this submission covers the Encryption ASIC [Alcatraz] used in the Encryption/Decryption section."

166 Lucent Technologies 
101 Crawfords Corner Road,
4D-218,
Holmdel , NJ
07733
USA

-Steve Reustle
TEL: (732)332-6281

Brick 1000
Version 6.0.545
4/16/2002

CBC(e/d)

"The Brick 1000 is a carrier-grade integrated firewall and virtual private network (VPN) gateway appliance specifically designed for web/application data center security, large-scale managed security services, and remote access VPN services. Called the Brick because of its rugged, reliable design, this is an ideal platform for service providers seeking wide scalability, ready manageability, and industry-leading performance."

165 F-Secure Corporation 
Tammasaarenkatu 7,
PL 24,
Helsinki
00181
Finland

-Alexey Kirichenko
TEL: +358 9 2520 5548

F-Secure Pocket PC Cryptographic Library
Version 1.1
4/8/2002

ECB(e/d) ; CBC(e/d) ; CFB64(e/d) ; OFB(e/d) CTR

"The F-Secure Pocket PC Cryptographic Library is a 140-2 Level 1 compliant software module, implemented as a 32-bit Windows?CE compatible DLL for Pocket PC and Pocket PC 2002 platforms. The Module provides an assortment of cryptographic services to client processes that attach instances of the Module DLL."

164 Lucent Technologies 
101 Crawfords Corner Road,
Room 4G-218,
Holmdel , NJ
07733
USA

-Roberta Eggert
TEL: (732)332-6189

Access Point Operating System
Version 2.6
4/8/2002

CBC(e/d)

"The Access Point Operating System delivers IP services with multi-access routing, Quality of Service (QoS) with Class-Based Queuing (CBQ), secure Virtual Private Networks (VPN), firewall security, and policy management. And the service provider has the advantages of easy deployment to multi-size customer premises locations, and the implementation of flexible management facilities that can be both customer and/or service provider managed."

163 Motorola 
200 North Point Center East,
Suite 400,
Alpharetta , GA
30022
USA

-Christopher Yasko
TEL: (770)521-5150
FAX: (770)521-8067

Encryption Services Module
Version 5.3
10/1/2002

ECB(e/d) ; CBC(e/d)

"The Encryption Services Module is incorporated into the operating software of the Accompli 009 -- the first wireless communications device to incorporate tri-band GSM and GPRS protocols, phone functionality, Internet access, e-mail, Triple-DES encryption, WAP browser and short message service (SMS) with a full QWERTY keyboard and 256-color screen."

162 Motorola 
200 North Point Center East,
Suite 400,
Alpharetta , GA
30022
USA

-Alfred Adler
TEL: 770-521-5128
FAX: 770-521-8066

Encryption DLL Module
Version 3.0
10/1/2002

ECB(e/d) ; CBC(e/d)

"The Encryption DLL Module is incorporated into the Motorola Messaging Server, an enterprise system for managing data between a corporate e-mail or database system and a wireless device, and the Motorola MyMail Desktop Plus, a personal application to manage e-mail between the desktop and a wireless device."

161 CyberGuard Corporation 
2000 W. Commercial Blvd.,
Suite 200,
Ft. Lauderdale , FL
33309
USA

-Soheila Amiri
TEL: (954)958-3900 X3309

CyberGuard Firewall/VPN Appliance Family
Version 5.0PSU1 (Revision)
3/21/2002

CBC(e/d)

"The cyberguard Firewall/VPN is a packet-filtering and application proxy gateway, which allows or blocks the routing of specific network services between networks based on a set of administrator-defined rules. Packet-filtering rules provide administrative control over hosts, services allowed through the firewall, and direction of communication. The VPN feature of CyberGuard Firewall ensures that this communication takes place over secure virtual private networks by using cryptographic algorithms to protect the data while en-route."

160 Certicom Corporation 
Certicom Corporate Headquarters,
5520 Explorer Drive, 4th Floor,
Mississauga , ON
L4W 5L1
Canada

-Mike Harvey (Product Manager)
TEL: (905)507-4220
FAX: (905)507-4230

-Certicom Eastern US Sales Office
TEL: (571)203-0700
FAX: (571)203-9653

Security Builder?Government Solutions Edition (GSE)
Version 1.0
3/11/2002

ECB(e/d); CBC(e/d); CFB( 64 bits;e/d); OFB(e/d)

"Security Builder GSE is a standards-based cryptography toolkit that provides application developers with the sophisticated tools and flexibility needed to integrate encryption, digital signatures, and other security mechanisms into their applications. Security Builder provides the cryptographic core for a variety of Certicom products, including movianCrypt(c), movianVPN(c), SSL Plus(c), Trustpoint(c), PKI products, toolkits, certificates, and WTLS Plus(c). Security Builder is also licensed to third party companies."

159 V-ONE Corporation 
20300 Century Blvd.,
Suite 200,
Germantown , MD
20874
USA

-Paul Des Rivieres
TEL: 301-515-5200 x5417

SmartGate 4.3 server 3/6/2002

ECB(e/d) ; CBC(e/d) ; CFB64(e/d)

"V-ONE Corporations SmartGate is leading client/server Virtual Private Network (VPN) software that provides enterprise-level security to network-based users for private information and private TCP/IP application services. SmartGate provides encryption, strong user authentication, authorization, management, accounting, key distribution, and proxy capabilities. It consists of server (SmartGate) and client (SmartPass) software."

158 SchlumbergerSema 
50 avenue Jean Jaures,
Montrouge Cedex
92542
FRANCE

-Bruno Blanchard
TEL: +33 1 46007456
FAX: +33 1 46 00 6826

Cryptoflex 32K e-gate
Version 32K
Part #ST19XT34
2/7/2002

ECB(e/d)

"The Cryptoflex e-Gate card is a credit-card sized computer with a crypto-processor dedicated to security and implements security industry functions based on public key cryptography directly onto the card. Incorporates, apart from the conventional ISO 7816-3 interface, also the USB interface normally resident in the smartcard reader."

157 F-Secure Corporation 
Tammasaarenkatu 7,
PL 24,
Helsinki
00181
Finland

-Alexey Kirichenko
TEL: +358 9 2520 5548

F-Secure Kernel Mode Cryptographic Driver
Version 1.1
2/11/2002

ECB(e/d); CBC(e/d); CFB( 64 bits;e/d); OFB(e/d)

"The F-Secure Kernel Mode Cryptographic Driver is a 140-2 Level 1 compliant software module, implemented as a 32-bit Windows NT/2000/XP compatible export driver. When loaded into computing system memory, it resides at the Kernel Mode level of the Windows OS and provides an assortment of cryptographic services that are accessible by other kernel mode drivers through an Application Program Interface (API)."

156 Microsoft Corporation 
One Microsoft Way,
Redmond , WA
98052-6399
USA

-Mike Lai

Microsoft Enhanced Cryptographic Provider
Version 5.1.2518.0
2/5/2002

ECB(e/d); CBC(e/d)

"The Microsoft Enhanced Cryptographic Provider (RSAENH) is a FIPS 140-1 Level 1 compliant, general-purpose, software-based, cryptographic module. It encapsulates several different cryptographic algorithms (SHA-1, DES, 3DES, AES, RSA, SHA-1-based HMAC) in an easy-to-use cryptographic module accessible via the Microsoft CryptoAPI. Can be dynamically linked into applications to permit the use of general-purpose FIPS 140-1 Level 1 compliant cryptography."

155 Gemplus 
Avenue du Pic de Bertagne,
GEMENOS Cedex
BP100, 138
FRANCE

-Luc Astier, Product Line Manager
TEL: +33 (0) 4 42 36 50 00
FAX: n/a

Gemplus GemXpresso Pro E64 PK - FIPS with ActivCard Applet Suite
Version Hardware GP92 , Firmware GXP3-FIPS
1/25/2002

ECB(e/d); CBC(e/d)

"The "GemXpresso Pro E64 PK - FIPS with ActivCard Applet Suite" is based on a Gemplus Open OS Smart Card (Java Card 2.1.1, OP 2.0.1, 64K of EEPROM), and on platform-independent cryptographic applets developed by ActivCard (ID, PKI, and GC applets). The card and applets provide authentication and digital signature cryptographic services to end-users."

154 3S Group Incorporated 
125 Church St. NE,
Vienna , VA
22180
USA

-Satpal S Sahni
TEL: 703-281-5015

Type 2 Cryptographic Support Server
Part #T2CSS-208
1/7/2002

ECB(e/d); CBC(e/d); CFB( 8,64 bits;e/d); OFB(e/d)

"T2CSS is a multiple cryptoprocessor PCI board and cryptographic server. Provides high assurance security services; secure session/virtual token management; scalabel server performance(multiple boards); Government and commercial algorithms; FORTEZZA CI, PKCS #11, other APIs; and Windows NT/2000, Solaris and Linux support."

153 IP Dynamics, Inc. 
2880 Stevens Creek Boulevard,
3rd Floor,
San Jose , CA
95128
USA

-Hasan Alkhatib, Ph.D
TEL: 1-(866)-QUIK-VPN
FAX: (408)369-6904

VP3
Version 3.3
1/4/2002

CBC(e/d)

"A VPN software suite for intuitively configuring and deploying centrally managed secure networks."

152 Ceragon Networks 
24, Raoul Wallenberg St.,
Tel-Aviv
69719
Israel

-Shaul Shohat
TEL: +972-3-765-7001
FAX: +972-3-645-5559

FibeAir 1500-S, FibeAir 1528-S
Version 1.0
Part #15-IDU-S, 15-IDU-S-28
1/4/2002

OFB(e/d)

"Integrated into Ceragon Networks' FibeAir family, this unique wireless encryption solution allows encrypted 155Mbps+ wireless connectivity in licensed frequency bands. This solution enables the highest information security, without degrading the wireless link performance and all its features."

151 Motorola 
8220 E. Roosevelt St.,
Scottsdale , AZ
85257
USA

-Randy Morton
TEL: (480)441-4472
FAX: (480)441-358

Armor Cryptographic Processor ASIC
Version (SW: API R02.01, Alg R01.01)
Part #5185963A91
12/26/2001

ECB(e/d); CBC(e/d); CFB( 1 bit;e/d); OFB(e/d)

"(SW Version ASIC developed from: API R02,01,Alg R01.01) The Armor cryptographic processor is used in security modules embedded in Motorola's Astro family of radio system products. It provides secure voice and data capabilities as well as APCO Over-The-Air-Rekeying and advanced key management."

150 SecureLogix Corporation 
13750 San Pedro,
Suite 230,
San Antonio , TX
78232
USA

-Timothy J. Barton
TEL: (210)402-9669
FAX: n/a

ETM Platform
Version 3
12/18/2001

CFB( 64 bits;e/d)

"PBX-independent, easy-to-use management platform that supports telecommunications security, telephony, and management applications for real-time visibility, security, and control of telecommunications resources across the enterprise. Composed of ETM Management Server and TeleView Console, both written in Java and typically used in a distributed architecture across an enterprise LAN or WAN. Utilizes a common library of DES and TDES encryption routines to secure their network communications."

149 SecureLogix Corporation 
13750 San Pedro,
Suite 230,
San Antonio , TX
78232
USA

-Timothy J. Barton
TEL: (210)402-9669
FAX: n/a

ETM Appliance
Version 3
12/18/2001

CFB( 64 bits;e/d)

"PBX-independent, easy-to-use management platform that supports telecommunications security, telephony, and management applications for real-time visibility, security, and control of telecommunications resources across the enterprise. Primary components of the ETM Platform are the ETM Communications Appliances. Custom designed devices installed inline on the telecommunication system to monitor and control T1 CAS, analog, and ISDN PRI (both T1 and E1) telecommunications circuits. Uses a C library of DES and TDES encryption routines to secure their network communications to the ETM Management Server."

148 Oberthur Card Systems 
3150 E. Ana Street,
Rancho Dominguez , CA
90221
USA

-Antoine Kelman
TEL: (310)763-6378
FAX: N/A

CosmopolIC 2.1
Version V4
Part #006 181 381
12/3/2001

ECB(e/d); CBC(e/d)

"The CosmopolIC 2.1 V4 product is a highly secure and powerful multi-application Java Card platform for smart cards. The product is fully interoperable and complies with JavaCard 2.1.1 and Open Platform 2.0.1 standards. It supports both T=0 and T=1 protocols, DES, 3DES, SHA, RSA signature and key generation up to 2048 bits."

147 Cisco Systems, Inc 
7025-6 Kit Creek Road,
PO Box 14987,
Research Triangle Park , NC
27709-4987
USA

-Ray Potter
TEL: 919-392-6789

VPN 3000 Concentrator Series
Version 3.1 (Firmware Version FIPS )
11/27/2001

CBC(e/d)

"The Cisco VPN 3000 Concentrator Series is a best-of-breed, remote-access VPN solution for enterprise-class deployment. Includes Hardware Models 3005, 3015, 3030,3060,3080 3002 Hardware Client."

146 Pointsec Mobile Technologies 
1333 N. California Blvd.,
Suite 445,
Walnut Creek , CA
94596
USA

-Mr. Mikel Draghici
TEL: (732)416-1313
FAX: (730)416-1370

Pointsec Hard Disk Encryption Application
Version 4.1
11/20/2001

ECB(e/d)

"Employs hard disk encryption to guarantee that no users can access or manipulate information on an encrypted device, either from available files, erased files, or temporary files. Safeguards the operating system and the important system files (which often contain clues to passwords for Windows), shared devices, and the network."

145 Control Break International 
2338 Immokalee Road #172,
Naples , FL
34110
USA

-Dawn Cole
TEL: (941)596-8962

SafeBoot
Version 4.1
11/20/2001

CBC(e/d); CFB( 8 bits;e/d)

"SafeBoot is a high performance software solution that provides sector-level encryption of a PC's hard drive in a manner that is totally transparent to the user. In addition, the centralized SafeBoot management system provides robust recovery tools, administration, and implementation."

144 ValiCert, Inc. 
339 N. Bernardo Avenue,
Mountain View , CA
94043
USA

-Chini Krishnan
TEL: (650)567-5414
FAX: (650)254-2148

ALG DES
Version 1.0
11/20/2001

ECB(e/d); CBC(e/d)

"A module that will contain DES, TDES, and SHA-1 algorithms. The module willl be included in a variety of ValiCert products. E.g., Included in ValiCert Validation Authority (VA), ValiCert Transaction Authority (TA), ValiCert Secure Transport (ST)."

143 Enova® Technology Corporation 
Bldg. 53, #195-57, Sec.4,
Chung Hsing Road,
Chutung, Hsin-chu County , Taiwan
310
R.O.C.

-Thomas Chuang
TEL: 886-3-5910197
FAX: 886-3-5910204

X-Wall DX/SE-64
Version 1.0
10/30/2001

ECB(e/d)

"A real-time IDE crypto gateway, X-Wall DX/SE-64 sits between PCI south bridge and the device on the IDE interface. It intercepts, interprets, translates, and relays IDE command and data to and from the disk drive, encrypting entire disc content including boot sector and OS using DES 56 bits strength. Hardware Platform: ATA-5"

142 Check Point Software Technologies, Ltd. 
3 Lagoon Drive,
Redwood City , CA
94065
USA

-Scott Armstrong
TEL: (703)715-3028
FAX: (703)980-1552

-Mark Elliot
TEL: (310)364-5255
FAX: (916)716-1377

VPN-1 Gateway Next Generation FP-1 10/10/2001

CBC(e/d)

"Integrates access control, authentication and encryption to guarantee the security of corporate network connections, and the authenticity of local and remote users, satellite offices and key partners. It may be deployed on a wide range of platforms for maximum flexibility and scalability."

141 M/A-COM, Inc. 
221 Jefferson Ridge Parkway,
Lynchburg , VA
24501
USA

-Greg Farmer
TEL: (434)455-6600
FAX: (434)455-6851

800 MHz Jaguar J700P and J700Pi Portable Radios
Version Jaguar
Part #Model HA8ESX (scan) and HA8ETX (system)
10/5/2001

OFB(e/d)

"Jaguar handheld radio . System and scan versions. Aegis/ProVoice digital voice with DES encryption."

140 Communication Devices, Inc. 
#1 Forstmann Court,
Clifton , NJ
07011
USA

-Donald Snook
TEL: (973)772-6997

UniGuard
Version 7.15
Part #UG-V34
9/24/2001

CFB( 8 bits;e/d)

"Single Port Triple DES encryption modem (hardware)"

139 CTAM PTY, LTD. 
399 High Street,
Ashburton , Victoria
3147
Australia

-Peter Sim
TEL: +61 3 9886 0128

Crypto III
Version 1.0.0
Part #C1036A001
9/18/2001

CFB( 64 bits;e/d)

"FPGA implemenation of DES and TDES in CFB mode"

138 CTAM PTY, LTD. 
399 High Street,
Ashburton , Victoria
3147
Australia

-Peter Sim
TEL: +61 3 9886 0128

CTAM DES
Version 1.0.0
9/18/2001

CBC(e/d)

"Software implementation of DES in CBC mode"

137 Cisco Systems, Inc 
7025-6 Kit Creek Road,
PO Box 14987,
Research Triangle Park , NC
27709-4987
USA

-Ray Potter
TEL: 919-392-6789

Integrated Service Module
Version 1.1
Part #73-4201-07/Board Revision A0
9/17/2001

CBC(e/d)

"The ISM is a single-width service module. It provides high-performance, hardware-assisted tunneling and encryption services suitable for VPN remote access and site-to-site intranet/extranet applications while working with all services necessary for successful VPN deployments. The ISM off-loads IPSec and MPPE processing from the main processor of the Cisco 7100 series router, thus freeing resources on the processor engine."

136 Cisco Systems, Inc 
7025-6 Kit Creek Road,
PO Box 14987,
Research Triangle Park , NC
27709-4987
USA

-Ray Potter
TEL: 919-392-6789

Integrated Service Adapter
Version 1.0
Part #73-4201-06/ Board Revision B0
9/17/2001

CBC(e/d)

"The ISA is a single-width service adapter. It provides high-performance, hardware-assisted tunneling and encryption services suitable for VPN remote access and site-to-site intranet/extranet applications while working with all services necessary for successful VPN deployments. The ISA off-loads IPSec and MPPE processing from the main processor of the Cisco 7200 series router, thus freeing resources on the processor engine."

135 Hifn, Inc. 
750 University Avenue,
Los Gatos , CA
95032
USA

-Phil Papenfuss
TEL: (408)399-3500

HiFn 7851
Version R2
Part #7851-PB4/2
9/14/2001

ECB(e/d); CBC(e/d)

"Used in network security products. Security algorithms include DES, TDES, and SHA-1, which conform to NIST requirements."

134 Chrysalis-ITS, Inc. 
One Chrysalis Way,
Ottawa , ON
K2G 6P9
Canada

-Carlos Fox
TEL: (613) 723-5077
FAX: (613) 723-5078

Luna?XP plus
Version 3.9 (Firmware)
8/13/2001

ECB(e/d); CBC(e/d)

&quo