808bits

FCAT Wallet Vault Cryptographic Module

FIPS 140-3 certificate #5153 · Fidelity Center for Applied Technology, LLC · data as of 2026-08-28
Active. Sunset date 2029-01-29, 884 days away.
Caveat: When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)

Certificate

Certificate number5153
StandardFIPS 140-3
Statusactive
Sunset date2029-01-29
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorFidelity Center for Applied Technology, LLC · website
Software versions1.0

Module description

The FCAT Wallet Vault Cryptographic Module is implemented within the secure context of the FCAT hardware wallet platform. The FACT Wallet is built atop the ProvenCore EAL7-certified secure OS developed by ProvenRun and operates in conjunction with a hardened version of the OpenSSL FIPS-compliant cryptographic library. The module offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, and message authentication; support for key establishment functions to secure data-at-rest and data-in-flight for the larger FCAT Wallet platform, which includes cryptographic functions supporting user-facing wallet GUI application.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA4978
AES-CCMA4978
AES-CFB1A4978
AES-CFB128A4978
AES-CFB8A4978
AES-CMACA4978
AES-CTRA4978
AES-ECBA4978
AES-GCMA4978
AES-GMACA4978
AES-KWA4978
AES-KWPA4978
AES-OFBA4978
AES-XTSA4978
Counter DRBGA4978
DSA KeyGen (FIPS186-4)A4978
DSA PQGGen (FIPS186-4)A4978
DSA PQGVer (FIPS186-4)A4978
DSA SigGen (FIPS186-4)A4978
DSA SigVer (FIPS186-4)A4978
ECDSA KeyGen (FIPS186-4)A4978
ECDSA KeyVer (FIPS186-4)A4978
ECDSA SigGen (FIPS186-4)A4978
ECDSA SigVer (FIPS186-4)A4978
HMAC-SHA-1A4978
HMAC-SHA2-224A4978
HMAC-SHA2-256A4978
HMAC-SHA2-384A4978
HMAC-SHA2-512A4978
HMAC-SHA3-224A4978
HMAC-SHA3-256A4978
HMAC-SHA3-384A4978
HMAC-SHA3-512A4978
KAS-ECC-SSC Sp800-56Ar3A4978
KAS-FFC-SSC Sp800-56Ar3A4978
KDA HKDF SP800-56Cr2A4978
KDF SSHA4978
KDF TLSA4978
PBKDFA4978
RSA KeyGen (FIPS186-4)A4978
RSA SigGen (FIPS186-4)A4978
RSA SigVer (FIPS186-4)A4978
SHA-1A4978
SHA2-224A4978
SHA2-256A4978
SHA2-384A4978
SHA2-512A4978
SHA3-224A4978
SHA3-256A4978
SHA3-384A4978
SHA3-512A4978
SHAKE-128A4978
SHAKE-256A4978
TDES-CBCA4978
TDES-CFB1A4978
TDES-CFB64A4978
TDES-CFB8A4978
TDES-CMACA4978
TDES-ECBA4978
TDES-OFBA4978
TLS v1.2 KDF RFC7627A4978
TLS v1.3 KDFA4979

Allowed algorithms

AES (Cert. A4978, key unwrapping. Per IG D.G.; Symmetric key unwrapping);RSA ( Cert. A4978, key unencapsulation. Per IG D.G.; Asymmetric key unencapsulation);SHA-1 ( Cert. A4978, secure hashing.; Digital signature generation in TLS v1.0/1.1);Triple-DES ( Cert. A4978, key unwrapping. Per IG D.G.; Symmetric key unwrapping)

Tested configurations

  • Debian 9 running on a Dell PowerEdge R440 with an Intel® Xeon Silver 4214R with PAA
  • Debian 9 running on a Dell PowerEdge R440 with an Intel® Xeon Silver 4214R without PAA

Validation history

DateTypeLab
2026-02-11InitialTeron Labs

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2026-02-11

Source documents