808bits

SafeNet PCIe Hardware Security Module and SafeNet PCIe Hardware Security Module for SafeNet Network HSM

FIPS 140-2 certificate #3208 · Gemalto · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and initialized to Overall Level 2 per Security Policy

Certificate

Certificate number3208
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorGemalto · website
Hardware versionsVBD-05-0100 [1, 2], VBD-05-0101 [1, 2], VBD-05-0102 [1, 2] and VBD-05-0103 [1, 2]
Firmware versions6.24.6 [1] and 6.24.7 [2]

Module description

The SafeNet PCI-E Hardware Security Module is a multi-chip embedded hardware cryptographic module in the form of a PCI-Express card that typically resides within a custom computing or secure communications appliance. The cryptographic module is contained in its own secure enclosure that provides physical resistance to tampering. The cryptographic boundary of the module is defined to encompass all components inside the secure enclosure on the PCI-E card.

Security level exceptions

  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3

Approved algorithms

AlgorithmCAVP certificate
AES4849, 4960, 5021
CKGvendor affirmed
CVL1565
DRBG1704
DSA1298, 1316, 1317
ECDSA1242, 1280, 1281
HMAC3306, 3335
KAS155
KBKDF165
KTS
RSA2691, 2706
SHS3988, 4080
Triple-DES2552, 2573, 2588
Triple-DES MACvendor affirmed

Allowed algorithms

AES (Certs. #4849, #4960 and #5012, key unwrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); Diffie-Hellman (key agreement; key establishment methodology provides 112 or 128 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength); Triple-DES (Certs. #2552, #2573 and #2588, key unwrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2018-06-26InitialEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-06-26

Source documents