808bits

Cryptographic Module for Intel® Platforms' Security Engine Chipset

FIPS 140-2 certificate #4648 · Intel Corporation · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in Sections 2.3 and 9.1 for of the Security Policy. When entropy is externally loaded, no assurance of the minimum strength of generated keys

Certificate

Certificate number4648
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeFirmware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIntel Corporation · website
Hardware versions2.0
Firmware versions3.1

Module description

The Cryptographic Module for Intel® CSE is a hardware-firmware hybrid module present on Intel® PCH platforms. The module performs crypto functions for CSE applications, including but are not limited to: PTT (Platform Trust Technology), AMT (Active Management Technology), and DAL (Dynamic Application Loader).

Approved algorithms

AlgorithmCAVP certificate
AESC1463
CKGvendor affirmed
CVLC1463
DRBGC1463
ECDSAC1463
HMACC1463
KBKDFC1463
KTS
KTS
KTS
KTS
KTS
KTSvendor affirmed
RSAC1463
SHSC1463

Allowed algorithms

NDRNG

Tested configurations

  • Embedded customized proprietary OS running firmware version 14.0.30.1115 on Intel Comet Point PCH with Lakemont processor 3.6

Validation history

DateTypeLab
2023-10-26InitialUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-10-26

Source documents