>_ Skip to main content
Menu
Search
Post-Quantum Security

Crypto4A QASM Earns FIPS 140-3 Level 3 Validation


Canadian company Crypto4A has achieved FIPS 140-3 Level 3 validation for its QASM hardware security module (HSM). Crypto4A states that this module supports all NIST-approved post-quantum cryptography (PQC) algorithms, claiming it as a world-first at this level. This certification applies to the module itself, not as proof that its algorithms are impervious to quantum computers.

Validation details

Hardware security modules are designed to store and manage cryptographic keys. They are utilized by banks, government agencies, and infrastructure operators to safeguard banking transactions, digital identities, and secure communications. The QASM module serves this purpose.

According to the August 20 press release, FIPS 140-3 is a joint US and Canadian government standard for cryptographic modules. Level 3 validation assesses physical tamper resistance, identity-based authentication, and the internal handling of keys. Achieving this means an accredited laboratory has verified these properties and confirmed the module meets the stringent requirements.

It’s crucial to distinguish this validation from another claim. Though the QASM module supports NIST’s PQC algorithms, and it holds a FIPS 140-3 Level 3 certificate, these are two separate aspects. The certificate pertains to the module’s construction and key management, not an independent verification that the post-quantum algorithms it executes will withstand quantum attacks. The security of these algorithms relies on NIST’s own standardized work, which Crypto4A implements.

Crypto4A asserts that its module is the first globally at Level 3 to support all NIST-approved PQC algorithms. This claim of being a “world first” originates from the company.

Perspectives from stakeholders

The press release includes a quote from DigiCert CEO Amit Sinha, who praises the achievement. Bruno Couillard, CEO and co-founder of Crypto4A, frames this milestone as a significant step for Canadian cybersecurity. The company positions itself among Canadian firms developing sovereign security technology, a narrative often aimed at government buyers prioritizing domestic suppliers.

The wider context is significant. Governments are beginning the transition from current encryption methods to new standards designed to resist future quantum computer attacks. This transition requires both new algorithms and the hardware capable of managing them over time. With NIST having finalized its initial post-quantum standards in 2024, procurement efforts are now shifting towards products that implement these new technologies.

What the announcement omits is also noteworthy. There’s no mention of pricing, no named customer deployments, and no performance data for the module in a production environment. This is a certification milestone for a commercially available product, which is vital for buyers with such requirements, but it doesn’t showcase the module’s performance in real-world scenarios.