808bits

Knuckle Cryptographic Module

FIPS 140-3 certificate #5474 · Google, Inc. · data as of 2026-08-28
Active. Sunset date 2031-08-10, 1807 days away.
Caveat: No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.

Certificate

Certificate number5474
StandardFIPS 140-3
Statusactive
Sunset date2031-08-10
Overall level1
Module typeHardware
EmbodimentSingleChip
VendorGoogle, Inc. · website

Module description

The Knuckle Cryptographic Module is defined as a sub-chip cryptographic subsystem within a single-chip physical embodiment. The module is the primary component of a PCIe-based NVMe controller which provides AES-XTS encryption of data-at-rest and key management functionality per Trusted Computing Group (TCG) Opal specifications. The NVMe controller also includes a Google Titan chip for providing a Root of Trust (RoT) and boot security. The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated storage devices. The Module is intended to be used in a storage system.

Security level exceptions

  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Validation history

DateTypeLab
2026-08-11InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2026-08-11

Source documents