Crypto4A Technologies Submits PQC-Compatible QASM for FIPS 140-3 Level 3 Certification

Crypto4A Technologies Announced FIPS 140-3 Submission



Crypto4A Technologies, a pioneer in quantum-safe and crypto-agile security solutions, has made headlines with its recent announcement regarding the submission of its QASM hardware cryptographic core and v5.0 firmware for FIPS 140-3 Level 3 certification under the Cryptographic Module Validation Program (CMVP) managed by the National Institute of Standards and Technology (NIST).

This submission marks a remarkable milestone; the QASM represents the first-ever hardware security module (HSM) submitted for certification that includes all NIST-certified permutations and variations of the NIST algorithms concerning Post-Quantum Cryptography (PQC), including FIPS 203, 204, 205, and LMS. This innovative effort ensures that organizations can effectively protect critical assets against the evolving threats posed by advancements in quantum computing, both now and in the future.

Crypto4A’s quantum-safe HSMs are already highly valued by major chip manufacturers, board and device manufacturers, cloud service providers, government agencies, and enterprise clients around the world. As new quantum-safe algorithms are introduced by NIST, Crypto4A clients will be able to access these updates seamlessly due to the company’s crypto-agile FPGA-based design and firmware update mechanism. Unlike traditional HSMs, which often lack robust defenses, Crypto4A’s solution guarantees that firmware updates are safeguarded against potential quantum computer attacks.

Dr. Jim Goodman, the CTO and co-founder of Crypto4A, expressed his excitement regarding the submission, stating, "We are thrilled to have submitted our QASM design with complete PQC algorithm support for the CMVP’s FIPS 140-3 Level 3 certification, setting a precedent for the HSM industry! Our PQC-enabled QASM serves as a fundamental component of our QxHSM and QxEDGE product lines, providing all our clients with a quantum-safe foundation for their journey toward PQC migration."

The collaboration with atsec information security has been crucial in achieving this certification milestone. The expertise and extensive knowledge from atsec have ensured that Crypto4A's implementation of the approved algorithms and the security of its devices meet and exceed the NIST FIPS standards. Swapneela Unkule, manager of the atsec Cryptographic Security Testing Laboratory, highlighted the fruitful partnership by stating, "Crypto4A is our first provider to receive algorithm certificates for all available PQC algorithms. Throughout the project, we were impressed by the professionalism, dedication, meticulousness, and understanding of FIPS requirements from the entire team, ensuring a smooth validation process. We look forward to many collaborations for future validations."

The industry recognizes this achievement as a significant step forward. Spencer Frye from CERTINext/eMudhra remarked, "Quantum security starts with hardware, and Crypto4A is at the forefront of executing this concept." Tim Hollebeek, Vice President of Industry Standards at DigiCert, noted, “The submission of the first quantum-safe HSM for FIPS 140-3 demonstrates a forward-thinking approach to securing a post-quantum future.”

As organizations brace for the impending transition to PQC, HSM providers play a critical role in this ecosystem. Tomas Gustavsson, Chief PKI Officer at Keyfactor, emphasized the necessity of collaborative efforts to support migration endeavors, stating, “Our partnership with Crypto4A has been pivotal in providing our customers with quantum-safe algorithms and enabling them to integrate comprehensive quantum-safe solutions seamlessly.”

The call for proposals for PQC algorithms by NIST began in 2016, leading to standard releases in 2024. Thus, Crypto4A’s pioneering efforts are well-timed and crucial amidst the growing threats organizations face today and tomorrow.

With over seven years of expertise in delivering quantum-safe HSMs, Crypto4A continues to lead the way in cryptographic security for the post-quantum era. The company extends its gratitude to the atsec team for their comprehensive certification knowledge and assistance in finalizing this submission.

For more information about Crypto4A’s quantum-safe solutions and their implications in the industry, visit www.crypto4a.com.

Topics Consumer Technology)

【About Using Articles】

You can freely use the title and article content by linking to the page where the article is posted.
※ Images cannot be used.

【About Links】

Links are free to use.