Pitney Bowes iButton Postal Security Device (PSD)
Pitney Bowes iButton Postal Security Device (PSD), from Pitney Bowes, Inc., holds FIPS 140-2 certificate #2203 at overall level 3. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 2203 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-chip standalone |
| Vendor | Pitney Bowes, Inc. · website |
| Hardware versions | MAXQ1959B-F50# |
| Firmware versions | 09.02.00; Indicia Type: 0, 1, 2, 5, 7 and 8 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Pitney Bowes iButton Postal Security Device (PSD) has been designed in compliance with the United States Postal Service (USPS), Information-Based Indicia Program (IBIP), Royal Mail Mailmark and other international postal authorities' specification. It employs strong encryption, decryption, and digital signature techniques for the protection of customer funds in Pitney Bowes global digital metering products. The PSD has been designed to support international postal markets and their rapidly evolving requirements for digital indicia.
Security level exceptions
- Physical Security: Level 3 +EFP
- Mitigation of Other Attacks: N/A
Approved algorithms (5)
Other algorithms
Triple-DES MAC (Non-Compliant)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2014-07-09 | Initial | Penumbra Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2014-07-09