YubiHSM 2 Cryptographic Module
Caveat: When operated in FIPS mode, installed, initialized, and configured as specified in Section 3 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.
Certificate
| Certificate number | 3916 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Vendor | Yubico, Inc. · website |
| Hardware versions | SLE78CLUFX3000PH and SLE78CLUFX5000PH |
| Firmware versions | 2.2.0 |
Module description
The YubiHSM 2 is a USB-based, multi-purpose cryptographic device that is primarily used in servers. It is optimized for a small form factor and low power requirements.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C1680 |
| CKG | vendor affirmed |
| CVL | C1680 |
| DRBG | C1680 |
| ECDSA | C1680 |
| HMAC | C1680 |
| KAS-SSC | vendor affirmed |
| KBKDF | C1680 |
| KTS | |
| KTS | |
| RSA | A985, C1680 |
| SHS | C1680 |
Allowed algorithms
EC Diffie-Hellman (shared secret computation provides between 128 and 256 bits of encryption strength); NDRNG; RSA (CVL Cert. #C1680, key unwrapping; key establishment provides between 112 and 150 bits of encryption strength); RSA (key unwrapping; key establishment provides between 112 and 150 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-05-03 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2021-05-03