Module Name
AWS Key Management Service HSM
Historical Reason
SP 800-56Arev3 transition
Caveat
When installed, initialized and configured as specified in Section 3 of the Security Policy
Security Level Exceptions
- Cryptographic Module Specification: Level 3
- Roles, Services, and Authentication: Level 3
- Physical Security: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
The Amazon AWS Key Management Service HSM is a multi-chip standalone hardware cryptographic appliance designed to provide dedicated cryptographic functions to meet the security and scalability requirements of the AWS Key Management Service (KMS). The cryptographic boundary is defined as the secure chassis of the appliance. All key materials are maintained exclusively in volatile memory in the appliance and are erased immediately upon detection of physical tampering.
Approved Algorithms
AES |
Cert. #4527 |
CVL |
Certs. #1208 and #1209 |
DRBG |
Cert. #1487 |
ECDSA |
Cert. #1102 |
HMAC |
Cert. #2987 |
KAS |
Cert. #122 |
KBKDF |
Cert. #133 |
KTS |
AES Cert. #4527, key establishment methodology provides 256 bits of encryption strength |
KTS |
SP 800-56B, vendor affirmed |
RSA |
Cert. #2464 |
SHS |
Cert. #3708 |
Allowed Algorithms
EC Diffie-Hellman (CVL Cert. #1209, key agreement; key establishment methodology provides 192 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)