808bits

IDPrime 3930 FIDO

FIPS 140-2 certificate #4517 · Thales · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: No assurance of the minimum strength of generated keys

Certificate

Certificate number4517
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level2
Module typeHardware
EmbodimentSingle Chip
VendorThales · website
Hardware versionsSLE78CLFX400VPH (A1714221) and SLE78CLFX400VPH (A1633310)
Firmware versionsIDCore3130 - Build 12G, IDPrime 3930 Applet V4.5.0F, MSPNP Applet V1.2, FIDO V2.0.4B Applet

Module description

IDPrime 3930 FIDO is a dual interface smartcard combining Minidriver enabled PKI application, offering all the necessary services (with either RSA up to 4096 key length or Elliptic curves algorithms) to secure an IT Security and ID access infrastructure, with FIDO2 application (CTAP2) offering passwordless access for cloud apps, network domains and all Azure AD-connected apps and services

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Physical Security: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3

Approved algorithms

AlgorithmCAVP certificate
AESA1930
CKGvendor affirmed
CVLA1930
DRBGA1930
ECDSAA1930
HMACA1930
KAS
KAS-SSCA1930
KBKDFA1930
KDAA1930
KTS
KTS-RSA
RSAA1930
SHSA1930
Triple-DESA1930

Allowed algorithms

RSA (key unwrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2023-05-09InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-05-09

Source documents