Chrysalis-ITS K3 Cryptographic Engine
Chrysalis-ITS K3 Cryptographic Engine, from SafeNet, Inc., holds FIPS 140-2 certificate #436 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Certificate
| Certificate number | 436 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-chip embedded |
| Vendor | SafeNet, Inc. · website |
| Hardware versions | 2.0, 3.0 and 4.0 |
| Firmware versions | 4.1.0 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The K3 Chrysalis-ITS Cryptographic Engine is a hardware cryptographic module in the form of a PCI card that resides within a secured generalpurpose computing appliance. It is contained in its own secure enclosure that provides physical resistance to tampering and zeroization in the event the enclosure is opened. The cryptographic boundary of the module is defined to encompass all components inside the secure enclosure on the PCI card.
Security level exceptions
- Physical Security: Level 3
- EMI/EMC: Level 3
- Design Assurance: Level 3
- Cryptographic Key Management: Level 3
- Self-Tests: Level 3
- Mitigation of Other Attacks: Level 3
Approved algorithms (7)
| Algorithm | CAVP certificates |
|---|---|
| AES | 41 |
| DSA | 51 |
| HMAC-SHA-1 | vendor affirmed |
| RSA | vendor affirmed |
| SHA-1 | 64 |
| Triple-DES | 73 |
| Triple-DES MAC | vendor affirmed |
Other algorithms
DES (Cert. #32); DES MAC (Cert. #32, vendor affirmed); RC2; RC4; RC5; CAST; CAST3; CAST5; SEED; MD2; MD5; Diffie-Hellman 1024 (non-compliant); CAST MAC; CAST3 MAC; CAST5 MAC; SSL3-MD5 MAC; SSL3-SHA-1 MAC; HMAC-MD5; KCDSA; PBE-MD2-DES; PBE-MD5-DES; PBE-MD5-CAST; PBE-MD5-CAST3; PBE-SHA-1-CAST5; AES MAC; RC2 MAC; RC5 MAC
Validation history
| Date | Type | Lab |
|---|---|---|
| 2004-06-10 | Initial | DOMUS |
| 2004-10-18 | Update | |
| 2005-12-22 | Update |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2004-06-10, 2004-10-18, 2005-12-22