YubiKey 4 Cryptographic Module
Certificate
| Certificate number | 3204 |
|---|---|
| Standard | FIPS 140-2 |
| Status | revoked |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Vendor | Yubico, Inc. · website |
| Hardware versions | SLE78CLUFX3000PH |
| Firmware versions | 4.4.2, 4.4.4 |
Module description
The Yubikey 4 cryptographic module is a secure element that supports multiple protocols designed to be embedded in USB security tokens. The module can generate, store, and perform cryptographic operations for sensitive data and can be utilized via an external touch-button for Test of User Presence in addition to PIN for smart card authentication.The module implements five major functions - Yubico One Time Password (OTP), FIDO Universal 2nd Factor (U2F), PIV-compatible smart card, OpenPGP smart card and OATH OTP authentication.
Security level exceptions
- Physical Security: Level 3
- EMI/EMC: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 4712, 4713, 4714 |
| CKG | vendor affirmed |
| CVL | 1356, 1358, 1360, 1395 |
| DRBG | 1604 |
| ECDSA | 1165 |
| HMAC | 3133, 3134 |
| KTS | |
| RSA | 2569 |
| SHS | 3861, 3862 |
| Triple-DES | 2498 |
Allowed algorithms
EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2018-06-21 | Initial | UL Verification Services, Inc. |
| 2019-02-07 | Update | UL Verification Services, Inc. |
| 2019-04-30 | Update | UL Verification Services, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status revoked
- Validation dates on record: 2018-06-21, 2019-02-07, 2019-04-30