Intel® Offload and Crypto Subsystem (OCS)
Caveat: None
Certificate
| Certificate number | 4025 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-08 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Vendor | Intel Corporation · website |
| Hardware versions | 4.0 |
| Firmware versions | 4.0[1], 4.1[2], 4.2[3] and 4.3[4] |
Module description
The Intel® Offload and Crypto Subsystem (OCS) is classified as a single-chip hardware cryptographic module for FIPS 140-2 purpose.
Approved algorithms
Tested configurations
- Lakemont 3.7 embedded in Intel Elkhart Lake with Lakemont 3.7 with CSME OS running firmware version 15.40.10.2204 [4]
- Lakemont 3.7 embedded in Intel Rocket Lake-S with Lakemont 3.7 with CSME OS running firmware version 15.0.22.1571 [2]
- Lakemont 3.7 embedded in Intel Tiger Lake-H with Lakemont 3.7 with CSME OS running firmware version 15.0.30.1716 [3]
- Lakemont 3.7 embedded in Intel Tiger Lake-U with CSME OS running firmware version 15.0.20.1648 [1]
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-09-09 | Initial | atsec information security corporation |
| 2022-08-23 | Update | atsec information security corporation |
| 2023-04-19 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2021-09-09, 2022-08-23, 2023-04-19