IDPrime 3930 FIDO
Caveat: No assurance of the minimum strength of generated keys
Certificate
| Certificate number | 4517 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Vendor | Thales · website |
| Hardware versions | SLE78CLFX400VPH (A1714221) and SLE78CLFX400VPH (A1633310) |
| Firmware versions | IDCore3130 - Build 12G, IDPrime 3930 Applet V4.5.0F, MSPNP Applet V1.2, FIDO V2.0.4B Applet |
Module description
IDPrime 3930 FIDO is a dual interface smartcard combining Minidriver enabled PKI application, offering all the necessary services (with either RSA up to 4096 key length or Elliptic curves algorithms) to secure an IT Security and ID access infrastructure, with FIDO2 application (CTAP2) offering passwordless access for cloud apps, network domains and all Azure AD-connected apps and services
Security level exceptions
- Roles, Services, and Authentication: Level 3
- Physical Security: Level 3
- EMI/EMC: Level 3
- Design Assurance: Level 3
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A1930 |
| CKG | vendor affirmed |
| CVL | A1930 |
| DRBG | A1930 |
| ECDSA | A1930 |
| HMAC | A1930 |
| KAS | |
| KAS-SSC | A1930 |
| KBKDF | A1930 |
| KDA | A1930 |
| KTS | |
| KTS-RSA | |
| RSA | A1930 |
| SHS | A1930 |
| Triple-DES | A1930 |
Allowed algorithms
RSA (key unwrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-05-09 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2023-05-09