Virtual TPM
Caveat: When operated in FIPS mode with the modules Kernel Mode Cryptographic Primitives Library validated to FIPS 140-2 under Cert. #3196 operating in FIPS mode and Code Integrity validated to FIPS 140-2 under Cert. #3644 operating in FIPS mode or Secure Kernel Code Integrity validated to FIPS 140-2 under Cert. #3651 operating in FIPS mode
Certificate
| Certificate number | 3690 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Microsoft Corporation · website |
| Software versions | 10.0.17763 |
Module description
The Virtual Trusted Platform Module (Virtual TPM or VTPM) is a dynamically linked library, TPMEngUM.dll, that provides TPM 2.0 cryptographic services to virtual machines that are running in guest partitions on the host Windows operating system.
Security level exceptions
- Physical Security: N/A
- Design Assurance: Level 2
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C211, C350 |
| CKG | vendor affirmed |
| CVL | C348 |
| DRBG | C211, C350 |
| ECDSA | C348, C350 |
| HMAC | C350 |
| KAS | C350 |
| KBKDF | C350 |
| KTS | vendor affirmed |
| RSA | C211, C348, C350 |
| SHS | C211 |
Allowed algorithms
NDRNG
Tested configurations
- Windows 10 Education October 2018 Update (x64) running on a Microsoft Surface Laptop with an Intel Core i5 with PAA
- Windows 10 Enterprise October 2018 Update (x64) running on a Microsoft Surface Book 2 with an Intel Core i7 with PAA
- Windows 10 Enterprise October 2018 Update (x64) running on a Microsoft Surface Laptop with an Intel Core i5 with PAA
- Windows 10 Enterprise October 2018 Update (x64) running on a Microsoft Surface Pro LTE with an Intel Core i5 with PAA
- Windows 10 Enterprise October 2018 Update (x64) running on a Microsoft Surface Studio with an Intel Core i7 with PAA
- Windows 10 Enterprise October 2018 Update (x64) running on a Samsung Galaxy Book 12" with an Intel Core i5 with PAA
- Windows 10 Enterprise October 2018 Update (x64) running on an HP EliteBook x360 1030 G2 with an Intel Core i7 with PAA
- Windows 10 Pro October 2018 Update (x64) running on a Dell Latitude 5290 with an Intel Core i7 with PAA
- Windows 10 Pro October 2018 Update (x64) running on a Microsoft Surface Book 2 with an Intel Core i7 with PAA
- Windows 10 Pro October 2018 Update (x64) running on a Microsoft Surface Go with an Intel Pentium with PAA
- Windows 10 Pro October 2018 Update (x64) running on a Microsoft Surface Laptop with an Intel Core i5 with PAA
- Windows 10 Pro October 2018 Update (x64) running on a Microsoft Surface Pro LTE with an Intel Core i5 with PAA
- Windows 10 Pro October 2018 Update (x64) running on a Samsung Galaxy Book 10.6" with an Intel Core m3 with PAA
- Windows 10 Pro October 2018 Update (x64) running on an HP Elite x2 1013 G3 Tablet with an Intel Core i7 PAA
- Windows 10 Pro October 2018 Update (x64) running on an HP Slimline Desktop with an Intel Pentium with PAA
- Windows Server 2019 Core (x64) on Hyper-V on Windows Server 2016 running on a Dell PowerEdge R740 Server with an Intel Xeon Gold with PAA
- Windows Server 2019 Core (x64) on Hyper-V on Windows Server 2019 running on a Dell Precision Tower 5810MT with an Intel Xeon E5 with PAA
- Windows Server 2019 Core (x64) running on a Dell PowerEdge R740 Server with an Intel Xeon Gold with PAA
- Windows Server 2019 Datacenter Core (x64) on Hyper-V on Windows Server 2019 running on a Dell Precision Tower 5810MT with an Intel Xeon E5 with PAA (single-user mode)
- Windows Server 2019 Datacenter Core (x64) running on a Dell PowerEdge R740 Server with an Intel Xeon Gold with PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2020-07-27 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2020-07-27