808bits

JCOP21id 32K

FIPS 140-2 certificate #363 · IBM® Corporation · data as of 2026-09-13

JCOP21id 32K, from IBM® Corporation, holds FIPS 140-2 certificate #363 at overall level 3. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number363
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentSingle-chip
VendorIBM® Corporation · website
Hardware versionsP8WE5033AEV/034188i
Firmware versionsMask 20, Applet Version 1.0

Module description

Quoted from the NIST CMVP entry for this certificate.

The JCOP21id is IBM's multi-application smart card, designed to the Java Card v2.1.1 and Global Platform v2.0.1 specifications. The smart card features IBM's PKCS#15 applet which provides standardized high-level security services including, 2048 bit key generation, DES, 3DES, SHA-1, RSA and AES. Additional features include biometric extensions as defined by the Java Card Forum and DAP/mandated DAP security for post issuance applets.

Approved algorithms (5)

AlgorithmCAVP certificates
AES44
RSAvendor affirmed
SHA-1135
Triple-DES150
Triple-DES MACvendor affirmed

Other algorithms

DES (Cert.# 197); DES MAC (Cert. #197, vendor affirmed); AES MAC

Validation history

DateTypeLab
2003-11-26InitialSAIC-VA

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2003-11-26

Source documents