Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #4933

Details

Module Name
X5 Postal Security Device (PSD)
Standard
FIPS 140-3
Status
Active
Sunset Date
12/23/2026
Overall Level
3
Caveat
Interim Validation; When operated in approved mode; No assurance of the minimum strength of generated SSPs (e.g., keys).
PIV Cert Number
N/A
Security Level Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
  • Documentation requirements: N/A
  • Cryptographic module security policy: N/A
Module Type
Hardware
Embodiment
Single Chip
Description
The X5 Postal Security Device (PSD) is a single-chip cryptographic module designed by Pitney Bowes, Inc. (PB) to conform with FIPS 140-3 Security Level 3 requirements. The device includes the Maxim Integrated MAX32590 DeepCover Secure Microcontroller hardware component. The PSD Application and DAL are compiled into a single firmware. The X5 Postal Security Device (PSD) provides cryptographic services to a host device (i.e., Digital Postage Meter), to support postage evidence in the form of an indicium. A PSD provides protection that includes ensuring the secrecy of sensitive security parameters (SSPs) such as cryptographic keys and providing data integrity protection for funds relevant data items (FRDIs) such as accounting data. SSPs and FRDIs reside inside the strong physical protections of the X5 Postal Security Device (PSD).
Tested Configuration(s)
  • N/A
Approved Algorithms
AES-CBC
AES-ECB
AES-KW
ECDSA KeyGen (FIPS186-4)
ECDSA SigGen (FIPS186-4)
ECDSA SigVer (FIPS186-4)
Hash DRBG
HMAC-SHA2-256
KAS-ECC-SSC Sp800-56Ar3
KDA OneStep Sp800-56Cr1
RSA SigVer (FIPS186-4)
SHA2-224
SHA2-256
Allowed Algorithms
N/A (N/A; N/A)
Hardware Versions
Maxim Integrated MAX32590 DeepCover Secure Microcontroller - Revision B4
Firmware Versions
PSD Application: 22.01.000D & 22.01.000F Device Abstraction Layer (DAL): 02.01.000F & 02.01.00013

Vendor

Pitney Bowes, Inc.
27 Waterview Drive
Shelton, CT 06484
USA

Brian Hannigan
brian.hannigan@pb.com
Phone: 203-796-3201
Fax: 203-749-7491

Related Files

Validation History

Date Type Lab
12/24/2024 Initial PENUMBRA SECURITY