Secure Key Box: FIPS 140-2 Level One Certification Now in Hand


If you work in government or financial services then you know the importance that industry regulators place on information security and with today’s reliance on mobile devices and platforms, this security protocol is not always an easy endeavor. In fact, according to the Identify Theft Resource Center Data Breach Report (PDF), as of December 23, 2014, there have been 42 data breaches in the financial services industry alone, representing 5.5 percent of all breaches and involving over 1 million records. Think that’s bad? In the government sector there were 90 data breaches in 2014, representing 7.6 percent of all breaches and involving 6.5 million records.

One of the ways these industries emphasize security is with the Federal Information Processing Standard (FIPS) 140-2 that validates security claims for products using cryptography through the National Institute of Standards and Technology (NIST). By law, U.S. government purchasing agents must purchase the product that is validated for FIPS 140-2 (or FIPS 140-1) over one that is not. FIPS 140-2 is also required by federal agencies in Canada and recognized in Europe and Australia.

The financial community uses FIPS 140-2 to measure the safety of products handling monetary transactions. Security Level 1 allows the software and firmware components of a cryptographic module to be executed on a general purpose computing system using an unevaluated operating system without any additional hardware security mechanism.

We’re excited to announce that our Secure Key Box 4.6.0 Crypto Module has received the FIPS 140-2 Level 1 certification from NIST. This certification assures that government, financial agencies, and resellers alike that our Secure Key Box module delivers the highest level of protection available for sensitive information.

Thorsten Held, our managing director, summed up our certification:

Investing in certifications like FIPS is important for our customers and demonstrates our commitment to offer best-in-class software security solutions to the industry. Our Secure Key Box is an innovative white-box protected crypto library that secures cryptographic keys in memory. With the FIPS certification we address the security concerns of government and financial agencies that can rest assured our solution has passed the most rigorous testing. And to date, we seem to be the only company that is offering a white-box crypto library that comes with FIPS 140-2 certification.

Our Cryptanium security solutions are available for popular platforms such as Android, iOS, Windows, OSX and Linux.