ENFORCER R1
Certificate
| Certificate number | 3932 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 4 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Private Machines Inc. · website |
| Hardware versions | (ENFORCER.R1.A2SDi.1.0.0, ENFORCER.R1.X10SDV.1.0.0, ENFORCER.R1.M11SDV.1.0.0 or ENFORCER.R1.X11SDV.1.0.0) and other excluded components identified in Security Policy Section 1.4 |
| Firmware versions | Security Anchor Firmware 1.2.0, Libdrbg 1.0.2, and Libucl 2.5.13 |
Module description
The ENFORCER R1 provides a physically secure, Level 4 enclosure protecting CSPs and cryptographic data. A physical tamper event on the enclosure immediately zeroizes module CSPs. It provides a KMIP (Key Management Interoperability Protocol) service for key management to external users. It also provides additional services for module management, module configuration, and for building higher-level application scenarios such as integration into cloud and data center environments.
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 5073, C1028 |
| CKG | vendor affirmed |
| CVL | 1633, 1634, 1635 |
| DRBG | C558 |
| DSA | 1336 |
| ECDSA | 1316 |
| HMAC | 3385 |
| KAS-SSC | vendor affirmed |
| KTS | |
| RSA | 2751 |
| SHS | 4131 |
Allowed algorithms
NDRNG; RSA (CVL Cert. #1635, key wrapping; key establishment methodology provides between 112 and 149 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-05-24 | Initial | Penumbra Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2021-05-24