HiKey - Flash and HiKey PKI Token
HiKey - Flash and HiKey PKI Token, from Chunghwa Telecom Co., Ltd., holds FIPS 140-2 certificate #1117 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 1117 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-chip standalone |
| Vendor | Chunghwa Telecom Co., Ltd. · website |
| Software versions | Card OS version 3.1 with GINA Applet: 1.0, PKI Applet: 2.0, FISC II Applet: 1.2 |
| Hardware versions | 1.5 and 1.8 |
| Firmware versions | 1.25 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The HiKey Flash and HiKey PKI Token modules are multi-chip standalone implementations of a cryptographic module. The Hikey - Flash and HiKey PKI Token modules are USB tokens that adhere to ISO/IEC specifications for Integrated Circuit Chip (ICC) based identification cards. The HiKey - Flash and HiKey PKI Token cryptographic modules contain an implementation of the Open Platform (OP) Version 2.0.1 specification defining a secure infrastructure for post-issuance programmable smart cards.
Security level exceptions
- Roles, Services, and Authentication: Level 3
- EMI/EMC: Level 3
- Design Assurance: Level 3
Approved algorithms (7)
Other algorithms
AES MAC (AES Cert. #896; non-compliant)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2009-07-07 | Initial | DOMUS |
| 2011-11-17 | Update |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2009-07-07, 2011-11-17