808bits

Crypto Module for Intel® Core Ultra Series 1 (Meteor Lake) Converged Security and Manageability Engine (CSME)

FIPS 140-3 certificate #5546 · Intel Corporation · data as of 2026-10-09

Crypto Module for Intel® Core Ultra Series 1 (Meteor Lake) Converged Security and Manageability Engine (CSME), from Intel Corporation, holds FIPS 140-3 certificate #5546 at overall level 2. The validation is active, with a sunset date of 2031-10-06. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2031-10-06, 1822 days away.
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11.2 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs

Certificate

Certificate number5546
StandardFIPS 140-3
Statusactive
Sunset date2031-10-06
Overall level2
Module typeFirmware-hybrid
EmbodimentSingleChip
VendorIntel Corporation · website

Module description

Quoted from the NIST CMVP entry for this certificate.

The Crypto Module for Intel® Core Ultra Series 1 (Meteor Lake) Converged Security and Manageability Engine (CSME) is a firmware-hybrid module. The module consists of both hardware and firmware. The hardware portion is the Converged Security Engine (CSE) and the firmware portion is the crypto driver process of the Manageability Engine (ME). The two portions form the cryptographic boundary and they combine as Converged Security and Manageability Engine (CSME) to perform cryptographic functions within the Meteor Point PCH applications executing on the CSME OS.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A

Approved algorithms (31)

AlgorithmCAVP certificates
AES-CBCA5442
AES-CFB128A5442
AES-CMACA5442
AES-CTRA5442
AES-ECBA5442
AES-GCMA5442
AES-OFBA5442
Conditioning Component AES-CBC-MAC SP800-90BA5254
Counter DRBGA5254, A5442
ECDSA KeyGen (FIPS186-5)A5442
ECDSA KeyVer (FIPS186-5)A5442
ECDSA SigGen (FIPS186-5)A5442
ECDSA SigVer (FIPS186-5)A5442
HMAC-SHA-1A5442
HMAC-SHA2-224A5442
HMAC-SHA2-256A5442, A7742
HMAC-SHA2-384A5442
HMAC-SHA2-512A5442
KAS-ECC Sp800-56Ar3A5442
KDF SP800-108A5442
KTS-IFCA5442
RSA Decryption Primitive Sp800-56Br2A5442
RSA KeyGen (FIPS186-5)A5442
RSA SigGen (FIPS186-5)A5442
RSA Signature PrimitiveA5442
RSA SigVer (FIPS186-5)A5442
SHA-1A5442
SHA2-224A5442
SHA2-256A5442, A7742
SHA2-384A5442
SHA2-512A5442

Validation history

DateTypeLab
2026-10-07Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-10-09: first observed by this tracker, status active
  • Validation dates on record: 2026-10-07

Source documents