Knuckle Cryptographic Module
Certificate
| Certificate number | 5474 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-08-10 |
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | SingleChip |
| Vendor | Google, Inc. · website |
Module description
The Knuckle Cryptographic Module is defined as a sub-chip cryptographic subsystem within a single-chip physical embodiment. The module is the primary component of a PCIe-based NVMe controller which provides AES-XTS encryption of data-at-rest and key management functionality per Trusted Computing Group (TCG) Opal specifications. The NVMe controller also includes a Google Titan chip for providing a Root of Trust (RoT) and boot security. The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated storage devices. The Module is intended to be used in a storage system.
Security level exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-08-11 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2026-08-11