Tactical Key Management Device (TKMD)
Certificate
| Certificate number | 4157 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Christine Wireless, Inc. · website |
| Hardware versions | TKMD Spin 3 |
| Firmware versions | TKMD_FIPS_FINAL_11_01_20 |
Module description
The TKMD is a low-cost single unit that implements the TIA Project 25 Over-the-Air Rekey standard to provide a Key Management Facility (KMF) for 500 and up to 3000 Subscriber Radios. The TKMD can be utilized as a stand-alone KMF for use in a campus environment or can be utilized in a network environment where Subscriber Radio configurations can be securely shared between TKMDs. The networked TKMDs can also securely share collections of Cryptographic keys to allow periodic updating of Cryptographic keys. Control of the TKMD is accomplished with a secure (https) connection to a web browser.
Security level exceptions
- Roles, Services, and Authentication: Level 3
- Physical Security: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C1775 |
| CKG | vendor affirmed |
| CVL | C1775 |
| DRBG | C1775 |
| ECDSA | A881 |
| HMAC | C1775 |
| KAS-SSC | vendor affirmed |
| KBKDF | A862 |
| KTS | |
| RSA | C1775 |
| SHS | C1775 |
Allowed algorithms
AES MAC (AES Cert. #C1775, vendor affirmed; P25 AES OTAR); NDRNG
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-02-16 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-02-16