808bits

DIGIPASS FX Crypto Module

FIPS 140-3 certificate #5048 · OneSpan NV · data as of 2026-08-28
Active. Sunset date 2029-03-10, 924 days away.
Caveat: When installed, initialized and configured as specified in Section 11 of the Security Policy.

Certificate

Certificate number5048
StandardFIPS 140-3
Statusactive
Sunset date2029-03-10
Overall level3
Module typeHardware
EmbodimentSingle Chip
VendorOneSpan NV
Hardware versionsN7122 A1
Firmware versions[Platform ID J3R6000373181200 and ROM ID B3375FE9B5508BC4 and Patch ID 0000000000000000 and NXP IoT applet v7.2.22 and NXP SEMS Lite applet v2.0.2.11]

Module description

The DIGIPASS FX Crypto module validated to FIPS 140-3 overall Level 3, is a single chip module implementing the GlobalPlatform operational environment (Card Manager (ISD/SSD)) and the applications to perform cryptographic calculations.

Security level exceptions

  • Operational environment: N/A
  • Physical security: Level 4

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2713
AES-CCMA2713
AES-CMACA2713
AES-CTRA2713
AES-ECBA2713
AES-GCMA2714
AES-GMACA2714
AES-KWA2714
Counter DRBGA2713
ECDSA KeyGen (FIPS186-4)A2713
ECDSA SigGen (FIPS186-4)A2713
ECDSA SigVer (FIPS186-4)A2713
HMAC-SHA-1A2713
HMAC-SHA2-256A2713
HMAC-SHA2-384A2713
HMAC-SHA2-512A2713
KAS-ECC-SSC Sp800-56Ar3A2713
KDA HKDF Sp800-56Cr1A2713
KDA OneStep Sp800-56Cr1A2714
KDA OneStep Sp800-56Cr1A2715
KDF SP800-108A2713
KDF SP800-108A2713
KDF TLSA2714
PBKDFA2714
RSA Decryption PrimitiveA2713
RSA KeyGen (FIPS186-4)A2713
RSA SigGen (FIPS186-4)A2713
RSA Signature PrimitiveA2713
RSA SigVer (FIPS186-4)A2713
SHA-1A2713
SHA2-224A2713
SHA2-256A2713
SHA2-384A2713
SHA2-512A2713

Allowed algorithms

AES (Cert. #A2713, key unwrapping; key establishment methodology provides between 128 and 256 bits of encryption strength Per IG D.G; Symmetric key unwrapping (according to RFC3394) );AES (Cert. #A2713, key unwrapping; key establishment methodology provides 128 bits of encryption strength Per IG D.G; Symmetric key unwrapping (according to GlobalPlatform Amendment-I));ECDSA with non-NIST recommended curves (Provides between 112 and 256 bits of encryption strength Per IG C.A; Signature Generation/Verification using non-NIST curves [Brainpool224r1, Brainpool256r1, Brainpool320r, Brainpool384r1, Brainpool512r1, Secp224k1, Secp256k1 with strengths ]112, 128, 192 and 256 bits]);EC Diffie-Hellman with non-NIST recommended curves (Provides between 112 and 256 bits of encryption strength Per IGs D.F and C.A; Shared secret computation using non-NIST curves [Brainpool224r1, Brainpool256r1, Brainpool320r, Brainpool384r1, Brainpool512r1, Secp224k1, Secp256k1 with strengths ]112, 128, 192 and 256 bits])

Tested configurations

  • N/A

Validation history

DateTypeLab
2025-07-25InitialUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2025-07-25

Source documents