
I can confirm that there is no new code or hardware inside the "cryptographic boundary" as validated by FIPS compared to the most recent release of our PCI cards; all necessary changes to the HSM were put in before the last re-validation of the cards. The UI components themselves are outside the cryptographic boundary. That said, communication with the HSM thought the screen and input devices on the front panel does NOT pass through the computer inside the case but instead goes through a micro-controller and into the serial port on the PCI card HSM. This is analogous to the way things have always been with out smart card readers plugged into the HSM which themselves were not FIPS certified.

                Nicko van Someren
                CTO, nCipher

This looks like new packaging of an old/previously-announced product.

The NIST FIPS 140 site ( does not list this device as having undergone any FIPS validation. And from the pictures and specs, it looks like what they did was to put one of their FIPS validated PCI cards into a 1U rack-mount format box -- along with one or two 10/100 Ethernet connections, an LCD display, keyboard input, and some other buttons and knobs (all of which have not gone through a FIPS validation no doubt).


