Crypto Module for Intel® Alder Point PCH Converged Security and Manageability Engine (CSME)
Caveat: Interim Validation. When operated in approved mode. When initialized and configured as specified in Section 11 of the Security Policy.
Certificate
| Certificate number | 4749 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 2 |
| Module type | Firmware-hybrid |
| Embodiment | Single Chip |
| Vendor | Intel Corporation · website |
| Hardware versions | 4.6.0.0 |
| Firmware versions | 5.2.0.0 |
| Entropy | ENT (P) |
Module description
The Cryptographic Module for Intel® Converged Security and Manageability Engine(CSME) is a firmware-hybrid module. The module consists of both hardware and firmware. The hardware portion is the Converged Security Engine (CSE) and the firmware portion is the crypto driver process of the Manageability Engine (ME). The two portions form the cryptographic boundary and they combine as Converged Security and Manageability Engine (CSME) to perform cryptographic functions within the Alder Point PCH applications executing on the CSME OS.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A3362 |
| AES-CFB128 | A3362 |
| AES-CMAC | A3362 |
| AES-CTR | A3362 |
| AES-ECB | A3362 |
| AES-GCM | A3362 |
| AES-OFB | A3362 |
| Counter DRBG | A3362 |
| ECDSA KeyGen (FIPS186-4) | A3362 |
| ECDSA KeyVer (FIPS186-4) | A3362 |
| ECDSA SigGen (FIPS186-4) | A3362 |
| ECDSA SigVer (FIPS186-4) | A3362 |
| HMAC-SHA-1 | A3362 |
| HMAC-SHA2-224 | A3362 |
| HMAC-SHA2-256 | A3362 |
| HMAC-SHA2-384 | A3362 |
| HMAC-SHA2-512 | A3362 |
| KAS-ECC Sp800-56Ar3 | A3362 |
| KDF SP800-108 | A3362 |
| KTS-IFC | A3362 |
| KTS-IFC | A3362 |
| RSA Decryption Primitive | A3362 |
| RSA KeyGen (FIPS186-4) | A3362 |
| RSA SigGen (FIPS186-4) | A3362 |
| RSA Signature Primitive | A3362 |
| RSA SigVer (FIPS186-4) | A3362 |
| SHA-1 | A3362 |
| SHA2-224 | A3362 |
| SHA2-256 | A3362 |
| SHA2-384 | A3362 |
| SHA2-512 | A3362 |
Tested configurations
- CSME OS with firmware version 16.1.25.2124 running on Alder Point PCH-M/P with Alder Lake M CPU
- CSME OS with firmware version 16.1.25.2124 running on Alder Point PCH-M/P with Raptor Lake HX CPU
- CSME OS with firmware version 16.1.25.2124 running on Alder Point PCH-S with Alder Lake S CPU
- CSME OS with firmware version 16.1.25.2124 running on Alder Point PCH-S with Raptor Lake P CPU
- CSME OS with firmware version 16.1.25.2124 running on Alder Point PCH-S with Raptor Lake S CPU
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-08-02 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2024-08-02