ID-One PIV (Type B)
ID-One PIV (Type B), from Oberthur Technologies, holds FIPS 140-2 certificate #1416 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Certificate
| Certificate number | 1416 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Single-chip |
| Vendor | Oberthur Technologies · website |
| Hardware versions | P/Ns BF [1, 2] and C0 [3, 4] |
| Firmware versions | 0801 (with op-codes (071621 and 070534) [1], (071621 and 071891) [2], (071631 and 070544) [3] or (071631 and 071901) [4]) with ID-One PIV Applet Suite V2.3.2 [*] or V2.3.2-a [**] |
Module description
Quoted from the NIST CMVP entry for this certificate.
This new generation PIV Card addresses current & future needs of both Federal and Corporate customers with built-in support for all the cryptographic algorithms defined in SP800-78-2 including TDEA, AES, RSA, ECDSA, & ECDH with all possible key sizes as well as key history for over 20 retired decryption keys. It offers Identity proofing (storage of personal data), User authentication, Card authentication, digital signature, encryption, & secure post issuance management in the PIV system. Its fingerprint match-on-card has been validated in the MINEX II PIV Biometric interoperability program.
Security level exceptions
- Roles, Services, and Authentication: Level 3
- Physical Security: Level 3
- EMI/EMC: Level 3
- Design Assurance: Level 3
Approved algorithms (8)
| Algorithm | CAVP certificates |
|---|---|
| AES | 978 |
| CVL | 4, 216, 221 |
| ECDSA | 120 |
| RNG | 555 |
| RSA | 471 |
| SHS | 949 |
| Triple-DES | 770 |
| Triple-DES MAC | vendor affirmed |
Other algorithms
Triple-DES (Triple-DES Cert. #770, key wrapping; key establishment methodology provides 80 bits of encryption strength; non-compliant); AES (AES Cert. #978, key wrapping; key establishment methodology provides 128 bits of encryption strength); AES MAC (AES Cert. #978; non-compliant); RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2010-10-06 | Initial | UL Verification Services, Inc. |
| 2010-11-24 | Update | |
| 2010-12-21 | Update | |
| 2011-02-10 | Update | UL Verification Services, Inc. |
| 2011-07-05 | Update | |
| 2011-10-04 | Update | UL Verification Services, Inc. |
| 2014-02-06 | Update |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2010-10-06, 2010-11-24, 2010-12-21, 2011-02-10, 2011-07-05, 2011-10-04, 2014-02-06