Home / Product / Technical Specifications

CQ1 MODULE

Technical Specifications

Full hardware, cryptographic, and interface specifications for evaluation and procurement.

Request Evaluation Unit

Cryptographic Algorithms

AlgorithmStandardKey SizesNotes
CRYSTALS-Kyber-1024NIST FIPS 203 (ML-KEM)1568 bytes public, 3168 bytes encapPrimary KEM — post-quantum key exchange
CRYSTALS-Dilithium-3NIST FIPS 204 (ML-DSA)1952 byte public, 3293 byte sigPost-quantum digital signatures
Hybrid X25519+Kyber-1024IETF draft-ietf-tls-hybrid-designCombined 64 + 1568 bytesTLS migration mode
ECDSA P-384NIST FIPS 186-5384-bitClassical fallback, backward compat
RSA-2048 / RSA-4096PKCS#1 v2.22048 or 4096 bitLegacy key storage and operations
AES-256-GCMNIST SP 800-38D256-bit key, 96-bit IVSymmetric encryption, authenticated
SHA-3 (Keccak-f1600)NIST FIPS 202256 / 384 / 512 outputHashing, internal KDF input

Performance

OperationThroughputP99 LatencyMeasurement Conditions
Kyber-1024 Key Encapsulation>18,000 ops/sec<0.8msSustained 10,000 ops/sec, 1500B payload
Kyber-1024 Key Decapsulation>18,000 ops/sec<0.8msSame conditions
Dilithium-3 Sign>12,000 ops/sec<1.2ms512-byte message
Dilithium-3 Verify>22,000 ops/sec<0.6ms512-byte message
AES-256-GCM Encrypt40 Gbps<0.1ms1500B blocks, hardware pipeline
RSA-4096 Sign800 ops/sec<3msLegacy key operations
ECDSA P-384 Sign6,000 ops/sec<1.5msStandard operations

Physical & Environmental

AttributeValue
Form factor1U rack-mount, 19" EIA-310
Depth448mm (17.6")
Weight4.8 kg (10.6 lb)
Power consumption65W typical, 90W max
Power input90–264 VAC, 47–63 Hz, dual PSU
CoolingDual counter-rotating fans, N+1
Operating temperature0°C to 50°C (32°F to 122°F)
Storage temperature−40°C to 70°C
Operating humidity5% to 95% non-condensing
Altitude0 to 3,000m operating
Security AttributeValue
Physical security targetDesigned for FIPS 140-3 Level 3
Tamper detectionAnti-tamper mesh, voltage/temp sensors
Zeroization time<100ms on breach detection
Key storageBattery-backed SRAM, encrypted at rest
Operator authDual-control smartcard + PIN
Audit logTamper-evident, 100,000 entry capacity
HSM managementTLS 1.3 + mutual cert auth, out-of-band
RNGDual DRBG (SP 800-90A/C), NIST tested

Interfaces & Connectivity

InterfaceTypeQuantityNotes
PKCS#11Software library (cryptoki)v3.0 compliant, 1x PKCS#11 DLL/SO
JCA/JCEJava Cryptography ProviderJava 11+ SPI, signed provider JAR
PCIeGen3 x4 host adapter1Included; supports x8/x16 slots
10GbESFP+ network2HA active-standby or load-balanced
Management port1GbE RJ451Out-of-band management, IPMI 2.0
USBUSB-A 3.2 Gen 12Smartcard reader, firmware update
Serial consoleDB9 RS-2321Recovery console access

Compliance & Standards

StandardStatusDetails
FIPS 140-3 Level 3Designed for validationPhysical + logical security requirements; CMVP submission in progress
NIST FIPS 203 (ML-KEM)ImplementedCRYSTALS-Kyber-1024 per final standard, August 2024
NIST FIPS 204 (ML-DSA)ImplementedCRYSTALS-Dilithium-3 per final standard, August 2024
PKCS#11 v3.0CompliantFull Cryptoki API including PQC mechanisms
Common Criteria EAL4+Evaluation plannedTarget: EAL4 augmented with ATE_DPT.2
PCI HSMEvaluation plannedFor Issuer and Acquirer transaction signing
FCC Part 15 Class ACertifiedEMI/EMC for data center environments
CE MarkCertifiedEU electromagnetic compatibility and safety
RoHS 3CompliantEU Directive 2011/65/EU

Compliance statuses reflect current state as of Q2 2026. FIPS 140-3 and Common Criteria evaluations are ongoing. Cryptrig does not claim certified status on any standard until formal validation body confirmation. Contact [email protected] for current evaluation timeline.

Specifications confirmed — request your evaluation unit