Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #5153

Details

Module Name
FCAT Wallet Vault Cryptographic Module
Standard
FIPS 140-3
Status
Active
Sunset Date
1/29/2029
Overall Level
1
Caveat
When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
Security Level Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Module Type
Software
Embodiment
Multi-Chip Stand Alone
Description
The FCAT Wallet Vault Cryptographic Module is implemented within the secure context of the FCAT hardware wallet platform. The FACT Wallet is built atop the ProvenCore EAL7-certified secure OS developed by ProvenRun and operates in conjunction with a hardened version of the OpenSSL FIPS-compliant cryptographic library. The module offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, and message authentication; support for key establishment functions to secure data-at-rest and data-in-flight for the larger FCAT Wallet platform, which includes cryptographic functions supporting user-facing wallet GUI application.
Tested Configuration(s)
  • Debian 9 running on a Dell PowerEdge R440 with an Intel® Xeon Silver 4214R with PAA
  • Debian 9 running on a Dell PowerEdge R440 with an Intel® Xeon Silver 4214R without PAA
Approved Algorithms
AES-CBC
AES-CCM
AES-CFB1
AES-CFB128
AES-CFB8
AES-CMAC
AES-CTR
AES-ECB
AES-GCM
AES-GMAC
AES-KW
AES-KWP
AES-OFB
AES-XTS
Counter DRBG
DSA KeyGen (FIPS186-4)
DSA PQGGen (FIPS186-4)
DSA PQGVer (FIPS186-4)
DSA SigGen (FIPS186-4)
DSA SigVer (FIPS186-4)
ECDSA KeyGen (FIPS186-4)
ECDSA KeyVer (FIPS186-4)
ECDSA SigGen (FIPS186-4)
ECDSA SigVer (FIPS186-4)
HMAC-SHA-1
HMAC-SHA2-224
HMAC-SHA2-256
HMAC-SHA2-384
HMAC-SHA2-512
HMAC-SHA3-224
HMAC-SHA3-256
HMAC-SHA3-384
HMAC-SHA3-512
KAS-ECC-SSC Sp800-56Ar3
KAS-FFC-SSC Sp800-56Ar3
KDA HKDF SP800-56Cr2
KDF SSH
KDF TLS
PBKDF
RSA KeyGen (FIPS186-4)
RSA SigGen (FIPS186-4)
RSA SigVer (FIPS186-4)
SHA-1
SHA2-224
SHA2-256
SHA2-384
SHA2-512
SHA3-224
SHA3-256
SHA3-384
SHA3-512
SHAKE-128
SHAKE-256
TDES-CBC
TDES-CFB1
TDES-CFB64
TDES-CFB8
TDES-CMAC
TDES-ECB
TDES-OFB
TLS v1.2 KDF RFC7627
TLS v1.3 KDF
Allowed Algorithms
AES (Cert. A4978, key unwrapping. Per IG D.G.; Symmetric key unwrapping);RSA ( Cert. A4978, key unencapsulation. Per IG D.G.; Asymmetric key unencapsulation);SHA-1 ( Cert. A4978, secure hashing.; Digital signature generation in TLS v1.0/1.1);Triple-DES ( Cert. A4978, key unwrapping. Per IG D.G.; Symmetric key unwrapping)
Software Versions
1.0

Vendor

Fidelity Center for Applied Technology, LLC
245 Summer Street
Boston, Massachusetts 02210
USA

FCAT Wallet
[email protected]
Phone: 800-343-3548

Related Files

Validation History

Date Type Lab
2/11/2026 Initial Teron Labs