808bits

AWS Key Management Service HSM

FIPS 140-3 certificate #4884 · Amazon Web Services, Inc. · data as of 2026-08-28
Active. Sunset date 2026-11-17, 80 days away.
Caveat: Interim validation. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs

Certificate

Certificate number4884
StandardFIPS 140-3
Statusactive
Sunset date2026-11-17
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorAmazon Web Services, Inc. · website
Hardware versions3.0
Firmware versions1.8.104
EntropyENT (P)

Module description

The Amazon AWS Key Management Service HSM is a multi-chip standalone hardware cryptographic appliance designed to provide dedicated cryptographic functions to meet the security and scalability requirements of the AWS Key Management Service (KMS). The cryptographic boundary is defined as the secure chassis of the appliance. All key materials are maintained exclusively in volatile memory in the appliance and are erased immediately upon detection of physical tampering.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA1908
AES-CTRA1908
AES-ECBA1908
AES-GCMA1908
AES-KWPA1908
Conditioning Component AES-CBC-MAC SP800-90BA1791
Counter DRBGA1908
ECDSA KeyGen (FIPS186-4)A1908
ECDSA KeyVer (FIPS186-4)A1908
ECDSA SigGen (FIPS186-4)A1908
ECDSA SigGen (FIPS186-4)A1908
ECDSA SigVer (FIPS186-4)A1908
HMAC-SHA-1A1908
HMAC-SHA2-256A1908
HMAC-SHA2-384A1908
HMAC-SHA2-512A1908
KAS-ECC Sp800-56Ar3A1908
KAS-ECC Sp800-56Ar3A1908
KDA OneStep Sp800-56Cr1A1908
KDF SP800-108A1910
KTS-IFCA1908
RSA Decryption PrimitiveA1908
RSA KeyGen (FIPS186-4)A1908
RSA SigGen (FIPS186-4)A1908
RSA Signature PrimitiveA1908
RSA SigVer (FIPS186-4)A1908
SHA-1A1908
SHA2-256A1908
SHA2-384A1908
SHA2-512A1908

Allowed algorithms

ECDSA secp256k1 (key agreement; key establishment methodology provides 128 bits of encryption strength; [IG C.A] Curves: secp256k1 may only be used in block-chain related applications)

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-11-18InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-11-18

Source documents