AWS Nitro Card Security Engine
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 3739 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Firmware-Hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Amazon Web Services, Inc. · website |
| Hardware versions | AL5+ |
| Firmware versions | HAL-rel-3.2-uemu-fips |
Module description
The AWS Nitro Card Security Engine is a multi-chip standalone firmware-hybrid module. The Approved cryptographic services provided by the module are: - Data encryption / decryption utilizing symmetric ciphers, i.e. AES algorithms. - Computation of hash values, i.e. SHA-256, SHA-512. - Message authentication utilizing HMAC-SHA256, HMAC-SHA512, hashing algorithms.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms
Tested configurations
- Carbon Linux (Linux kernel 4.9.32) running on Cortex ARMv8 with AL5+
Validation history
| Date | Type | Lab |
|---|---|---|
| 2020-10-29 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2020-10-29