AWS Key Management Service HSM
Caveat: When installed, initialized and configured as specified in Section 3 of the Security Policy
Certificate
| Certificate number | 4177 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Amazon Web Services, Inc. · website |
| Hardware versions | 2.0 |
| Firmware versions | 1.6.109, 1.6.163 and 1.6.165 |
Module description
The Amazon AWS Key Management Service HSM is a multi-chip standalone hardware cryptographic appliance designed to provide dedicated cryptographic functions to meet the security and scalability requirements of the AWS Key Management Service (KMS). The cryptographic boundary is defined as the secure chassis of the appliance. All key materials are maintained exclusively in volatile memory in the appliance and are erased immediately upon detection of physical tampering.
Security level exceptions
- Cryptographic Module Specification: Level 3
- Roles, Services, and Authentication: Level 3
- Physical Security: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 4527 |
| CKG | vendor affirmed |
| CVL | 1208, 1209 |
| DRBG | 1487 |
| ECDSA | 1102 |
| HMAC | 2987 |
| KAS-SSC | vendor affirmed |
| KBKDF | 133 |
| KDA | vendor affirmed |
| KTS | |
| KTS | vendor affirmed |
| RSA | 2464 |
| SHS | 3708 |
Allowed algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-03-15 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-03-15