Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #4523

Details

Module Name
AWS Key Management Service HSM
Standard
FIPS 140-2
Status
Active
Sunset Date
9/21/2026
Overall Level
3
Caveat
When installed, initialized and configured as specified in Section 3 of the Security Policy
Security Level Exceptions
  • Mitigation of Other Attacks: N/A
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
The Amazon AWS Key Management Service HSM is a multi-chip standalone hardware cryptographic appliance designed to provide dedicated cryptographic functions to meet the security and scalability requirements of the AWS Key Management Service (KMS). The cryptographic boundary is defined as the secure chassis of the appliance. All key materials are maintained exclusively in volatile memory in the appliance and are erased immediately upon detection of physical tampering.
Tested Configuration(s)
  • N/A
Approved Algorithms
AES Certs. #A1791 and #A1908
CKG vendor affirmed
CVL Cert. #A1908
DRBG Certs. #A1791 and #A1908
ECDSA Cert. #A1908
ENT P
HMAC Cert. #A1908
KAS Cert. #A1908; key establishment methodology provides 192 bits of encryption strength
KBKDF Cert. #A1910
KDA Cert. #A1908
KTS AES Cert. #A1908
KTS-RSA Cert. #A1908; key establishment methodology provides between 112 and 150 bits of encryption strength
RSA Cert. #A1908
SHS Cert. #A1908
Allowed Algorithms
RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)
Hardware Versions
3.0
Firmware Versions
1.7.100, 1.7.102 and 1.7.103

Vendor

Amazon Web Services, Inc.
410 Terry Ave N
Ste 1200
Seattle, WA 98109-5210
USA

Kelvin Yiu
kelvinyi@amazon.com
Ken Beer
kenbeer@amazon.com

Validation History

Date Type Lab
5/19/2023 Initial ACUMEN SECURITY, LLC