Unbound Tech EKM Cryptographic Module
Unbound Tech EKM Cryptographic Module, from Unbound Tech, holds FIPS 140-2 certificate #3453 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode with two additional Unbound Tech EKM Cryptographic Modules with each EKM Cryptographic Module running in Entry mode, Pair mode, and Auxiliary mode as specified in Section 3.1 of the Security Policy
This caveat mentions binding. A bound module inherits the earliest sunset of the modules it binds to, so the sunset date above can be optimistic.
Certificate
| Certificate number | 3453 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Unbound Tech · website |
| Software versions | 2.0 |
Module description
Quoted from the NIST CMVP entry for this certificate.
Unbound's Enterprise Key Management (EKM) lets you manage and control keys working with any application. This pure-software solution is easy to deploy and maintain, while giving you unmatched levels of security and control for your crypto keys in the cloud. Based on Unbound vHSM technology, the keys are guaranteed to never appear in the clear, not even when generated or while at use - ensuring your most sensitive keys are kept private at all times.
Security level exceptions
- Physical Security: N/A
- Design Assurance: Level 3
Approved algorithms (10)
| Algorithm | CAVP certificates |
|---|---|
| AES | 5443, 5444 |
| CKG | vendor affirmed |
| CVL | 1884, 1885, 1886, 1887, 1888, 1889 |
| DRBG | 2126 |
| ECDSA | 1447, 1448 |
| HMAC | 3600, 3601 |
| KAS | vendor affirmed |
| KTS | vendor affirmed |
| RSA | 2918, 2919 |
| SHS | 4362 |
Allowed algorithms
EC Diffie-Hellman (key agreement; key establishment methodology provides 128 bits of encryption strength); NDRNG; RSA (key unwrapping; key establishment methodology provides 128 bits of encryption strength)
Tested configurations
- Windows Server version 1803 (2016 version 10.0.17134) running on Intel® i3 on Gigabyte GA-6ISL with PAA (single-user mode)
- Windows Server version 1803 (2016 version 10.0.17134) running on Intel® i3 on Gigabyte GA-6ISL without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2019-05-07 | Initial | UL Verification Services, Inc. |
| 2020-04-24 | Update | UL Verification Services, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2019-05-07, 2020-04-24