Cryptographic Module for Intel® Platforms' Security Engine Chipset
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in Sections 2.3 and 9.1 of the Security Policy. When entropy is externally loaded, no assurance of the minimum strength of generated keys.
Certificate
| Certificate number | 3838 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Firmware-Hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Intel Corporation · website |
| Hardware versions | 3.1 |
| Firmware versions | 3.0 |
Module description
The Cryptographic Module for Intel® CSME is a hardware-firmware hybrid module present on Intel® PCH platforms. The module performs crypto functions for CSME applications, including but are not limited to: PTT (Platform Trust Technology), AMT (Active Management Technology), and DAL (Dynamic Application Loader).
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C849 |
| CKG | vendor affirmed |
| CVL | C849 |
| DRBG | C849 |
| ECDSA | C849 |
| HMAC | C849 |
| KAS | C849 |
| KBKDF | C849 |
| KTS | |
| KTS | |
| KTS | |
| KTS | |
| KTS | |
| KTS | |
| KTS | vendor affirmed |
| RSA | C849 |
| SHS | C849 |
Allowed algorithms
NDRNG
Tested configurations
- Intel Ice Point PCH chipset with CSME device firmware version 13.0.0.1084
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-03-04 | Initial | UL Verification Services, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2021-03-04