Cryptographic Module for Intel® Platforms' Security Engine Chipset
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in Sections 2.3 and 9.1 for of the Security Policy. When entropy is externally loaded, no assurance of the minimum strength of generated keys
Certificate
| Certificate number | 4648 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Firmware-Hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Intel Corporation · website |
| Hardware versions | 2.0 |
| Firmware versions | 3.1 |
Module description
The Cryptographic Module for Intel® CSE is a hardware-firmware hybrid module present on Intel® PCH platforms. The module performs crypto functions for CSE applications, including but are not limited to: PTT (Platform Trust Technology), AMT (Active Management Technology), and DAL (Dynamic Application Loader).
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C1463 |
| CKG | vendor affirmed |
| CVL | C1463 |
| DRBG | C1463 |
| ECDSA | C1463 |
| HMAC | C1463 |
| KBKDF | C1463 |
| KTS | |
| KTS | |
| KTS | |
| KTS | |
| KTS | |
| KTS | vendor affirmed |
| RSA | C1463 |
| SHS | C1463 |
Allowed algorithms
NDRNG
Tested configurations
- Embedded customized proprietary OS running firmware version 14.0.30.1115 on Intel Comet Point PCH with Lakemont processor 3.6
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-10-26 | Initial | UL Verification Services, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2023-10-26