All modules
CMVP Validated Module · FIPS 140-3 Security Policy

IOS Common Cryptographic Module (IC2M)

Certificate#4752StandardFIPS 140-3Level1TypeFirmwareEmbodimentMulti-Chip Stand AloneStatusHistoricalVendorCisco Systems, Inc.
Medium review priority  ·  no TCB surface named  ·  last validated 23 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeFirmware
EmbodimentMulti-Chip Stand Alone
StatusHistorical
CaveatInterim Validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
VendorCisco Systems, Inc.

Approved Algorithms (32)

AlgorithmACVP Cert
AES-CBCA4354
AES-CFB128A4354
AES-CMACA4354
AES-ECBA4354
AES-GCMA4354
AES-GMACA4354
AES-KWA4354
Counter DRBGA4354
ECDSA KeyGen (FIPS186-4)A4354
ECDSA KeyVer (FIPS186-4)A4354
ECDSA SigGen (FIPS186-4)A4354
ECDSA SigVer (FIPS186-4)A4354
HMAC-SHA-1A4354
HMAC-SHA2-256A4354
HMAC-SHA2-384A4354
HMAC-SHA2-512A4354
KAS-ECC-SSC Sp800-56Ar3A4354
KAS-FFC-SSC Sp800-56Ar3A4354
KDF IKEv2A4354
KDF SNMPA4354
KDF SRTPA4354
KDF SSHA4354
RSA KeyGen (FIPS186-4)A4354
RSA SigGen (FIPS186-4)A4354
RSA SigVer (FIPS186-4)A4354
Safe Primes Key GenerationA4354
SHA-1A4354
SHA2-256A4354
SHA2-384A4354
SHA2-512A4354
TLS v1.2 KDF RFC7627A4354
TLS v1.3 KDFA4354

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for IOS Common Cryptographic Module (IC2M)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status output<br/>Show status<br/>self-test</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C3,C5,C6 clue;
  class I3,I5,I6 infer;
  class R3,R5,R6 risk;
  class E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for IOS Common Cryptographic Module (IC2M)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status output<br/>Show status<br/>self-test</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

ISO/IEC 19790 and FIPS 140-3 for IOS Common Cryptographic Module (IC2M) Firmware Version: Rel5b Last Updated: August 6, 2024 Version 1.4 Americas Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA

Page 2
Table of Contents
#SectionPage
Page 3
List of Figures
ItemPage
FIGURE 1 – LOGICAL CRYPTOGRAPHIC BOUNDARY9
TABLE 1 - SECURITY LEVELS4
TABLE 2 – TESTED OPERATIONAL ENVIRONMENTS5
TABLE 3 - VENDOR AFFIRMED OPERATIONAL ENVIRONMENTS5
TABLE 4 - APPROVED ALGORITHMS6
TABLE 5 – NON-APPROVED ALGORITHMS NOT ALLOWED IN THE APPROVED MODE OF OPERATION9
TABLE 6 – PORTS AND INTERFACES10
TABLE 7 – ROLES, SERVICE COMMANDS, INPUT AND OUTPUT10
TABLE 8 - APPROVED SERVICES11
TABLE 9 - NON-APPROVED SERVICES14
TABLE 10 - SSPS15
TABLE 11 - NON-DETERMINISTIC RANDOM NUMBER GENERATION SPECIFICATION17
TABLE 12 - ACRONYMS AND TERMS22
Page 4
ISO/IEC 24759:2017 Section 6FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A

(IC2M) with firmware version Rel5b (herein referred to as “IC2Mrel5b” or the “module”). The following details how this module meets the security requirements of FIPS 1 140-3, NIST 2 SP 3 800-140, and ISO4/IEC5 19790 for a Security Level 1 Firmware cryptographic module. The security requirements cover areas related to the design and implementation of a cryptographic module. Table 1 below indicates the security level for each area of the module. Table 1 - Security Levels The overall security level of the module is 1. FIPS

Page 5
#Operating SystemsHardware PlatformProcessor (Acceleration)PAA/Acceleration
1IOS-XE 17.12Cisco Aggregated Services Router (ASR) 1001-HXIntel Xeon E3-1125C v2N/A15
#Operating SystemHardware Platform
1IOS-XE 17.12Catalyst 9200 Series Switches
2IOS-XE 17.12Catalyst 9300 Series Switches
3IOS-XE 17.12Catalyst 9400 Series Switches
4IOS-XE 17.12Catalyst 9500 Series Switches
5IOS-XE 17.12Catalyst 9600 Series Switches
6IOS-XE 17.12Cisco Embedded Services 3300 Series Switch
7IOS-XE 17.12Cisco Embedded Services 9300 Series Switch
8IOS-XE 17.12Cisco Catalyst Industrial Ethernet 3000 Series Switch
9IOS-XE 17.12Cisco Catalyst Industrial Ethernet 9300 Series Switch
10IOS-XE 17.12Cisco C8500, C8500L Series Edge Platforms
11IOS-XE 17.12Cisco C8200, C8200L, C8300 Series Edge Platforms
12IOS-XE 17.12Cisco Aggregation Services Router (ASR) 1000 series
13IOS-XE 17.12Cisco Integrated Services Router (ISR) 4000 series
14IOS-XE 17.12Cisco Integrated Services Router (ISR) 1000 series
15IOS-XE 17.12Cisco C8000V Edge Software Router
16IOS-XE 17.12Cisco IR 1100, 1800, 8100, 8300 Series Industrial Routers
2 Cryptographic module specification

IC2Mrel5b is a single binary object file (sub_crypto_ic2m_k9.o) and is classified as a multi-chip standalone firmware module. IC2Mrel5b is a cryptographic library that supports cryptographic operations executed by a calling application. The calling application leverages the module’s well-defined API6 to initialize the module and call cryptographic algorithms for encryption/decryption, key generation, signature generation/verification, and hashing. The cryptographic library does not implement any protocols, but does provide the cryptographic primitives for IPsec7/IKE8v2, SNMP9v3, SRTP10, SSH11v2, and TLS12 v1.2/v1.3. No SSP13s are stored within the cryptographic boundary of the module. The module is intended for use on any Cisco device that runs the IOS-XE OS14, so the physical perimeter of the module is the testing platform. The module’s operational environment is non-modifiable. Table 2 below lists the tested operational environments. Table 2

Page 6
CAVP16 CertAlgorithm/StandardMode/MethodDescription/Key Size(s)/Key strength(s)Use/Function
A4354AES17 [FIPS PUB18 197] [NIST SP 800-38A]AES-CBC19;Key Length: 128, 192, 256 bitsSymmetric encryption and decryption
A4354AES [FIPS PUB 197] [NIST SP 800-38A]AES-CFB20128;Key Length: 128, 192, 256 bitsSymmetric encryption and decryption
A4354AES [FIPS PUB 197] [NIST SP 800-38A]AES-ECB21Key Length: 128, 192, 256 bitsSymmetric encryption and decryption
A4354AES [FIPS PUB 197] [NIST SP 800-38B]AES-CMAC22Key Length: 128, 256 bitsAuthenticated symmetric encryption and decryption
A4354AES [FIPS PUB 197] [NIST SP 800-38D]AES-GCM23Key Length: 128, 192, 256 bitsAuthenticated symmetric encryption and decryption
A4354AES [FIPS PUB 197] [NIST SP 800-38D]AES-GMAC24Key Length: 128 bitsAuthenticated symmetric encryption and decryption
A4354AES [NIST SP 800-38F]AES-KW25 (encrypt/decrypt)Key Length: 128, 192, 256 bitsSymmetric encryption and decryption
A4354ECDSA [FIPS PUB 186-4]ECDSA KeyGenCurves: P-256, P-384, P- 521ECDSA keypair generation

The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when ported to an operational environment which is not listed on the validation certificate. Modes of operation The module supports both approved and non-approved mode of operation. The module will be in approved mode when all pre-operational self-tests have completed successfully and only approved algorithms/services are invoked. Table 4 and Table 7 below for a list of the supported approved/allowed algorithms/services. The non-approved mode is entered when a non-approved algorithm/non-approved service is invoked. See Table 5 and Table 9 below for a list of non-approved algorithms/non-approved services. The Approved mode of operation can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table 9 - Non-Approved Services. The following tables list all Approved or Vendor-affirmed security functions of the module, including specific key size(s) -in bits otherwise noted- employed for approved services, and implemented modes of operation. Table 4 - Approved Algorithms

17 19

CAVP

Page 7
CAVP16 CertAlgorithm/StandardMode/MethodDescription/Key Size(s)/Key strength(s)Use/Function
A4354ECDSA [FIPS PUB 186-4]ECDSA KeyVerCurves: P-256, P-384, P- 521ECDSA keypair verification
A4354ECDSA [FIPS PUB 186-4]ECDSA SigGenCurves: P-256, P-384, P- 521ECDSA signature generation
A4354ECDSA [FIPS PUB 186-4]ECDSA SigVerCurves: P-256, P-384, P- 521ECDSA signature verification
A4354RSA26 [FIPS PUB 186-4]RSA KeyGen: - Mode: B.3.4 - 2048/3072 bits with SHA2-256Modulus: 2048, 3072, 4096RSA keypair generation
A4354RSA [FIPS PUB 186-4]RSA SigGen: - PKCSv1.5 - 2048/3072 bits with SHA2-256/384/512Modulus: 2048, 3072, 4096RSA signature generation
A4354RSA [FIPS PUB 186-4]RSA SigVer: - PKCSv1.5 - 2048/3072 bits with SHA2-256/384/512Modulus: 2048, 3072, 4096RSA signature verification
A4354KAS27-ECC-SSC28 [NIST SP 800-56Arev3]KAS-ECC29-SSC Scheme: dhEphem: KAS Role: initiator, responderCurves: P-256, P-384, P- 521Key establishment methodology provides between 128 and 256 bits of encryption strength
A4354KAS-FFC-SSC [NIST SP 800-56Arev3]KAS-FFC30-SSC Scheme: dhEphem: KAS Role: initiator, responderMODP-2048, MODP-3072, MODP-4096Key establishment methodology provides between 112 and 152 bits of encryption strength
A4354Safe Primes Key Generation [NIST SP 800-56Arev3]KeyGen for DH31 (CKG using method in Sections 4 and 5.1 of SP 800- 133rev2)MODP-2048, MODP-3072, MODP-4096KAS-FFC Keypair domain parameters generation
A4354KDF IKEv2 [NIST SP800-135rev1] (CVL)KDF IKEv2N/AKey derivation function used in IKEv2
A4354KDF SNMP [NIST SP800-135rev1] (CVL)KDF SNMPN/AKey derivation function used in SNMPv3
A4354KDF SRTP [NIST SP800-135rev1] (CVL)KDF SRTPN/AKey derivation function used in SRTP
A4354KDF SSH [NIST SP800-135rev1] (CVL)KDF SSHN/AKey derivation function used in SSHv2

RSA

Page 8
CAVP16 CertAlgorithm/StandardMode/MethodDescription/Key Size(s)/Key strength(s)Use/Function
A4354TLSv1.2 KDF RFC7627 (CVL)TLSv1.2 KDF RFC7627N/AKey derivation in TLSv1.2 with RFC 7627 KDF with Extended Master Secret
A4354TLS v1.3 KDF [RFC 8446] (CVL)TLSv1.3 KDFN/AKey derivation function used in TLSv1.3
A4354HMAC [FIPS 198-1]HMAC-SHA-1Key Length: 112-bits or greaterKeyed hash
A4354HMAC [FIPS 198-1]HMAC-SHA2-256Key Length: 112-bits or greaterKeyed hash
A4354HMAC [FIPS 198-1]HMAC-SHA2-384Key Length: 112-bits or greaterKeyed hash
A4354HMAC [FIPS 198-1]HMAC-SHA2-512Key Length: 112-bits or greaterKeyed hash
A4354SHS [FIPS PUB 180-4]SHA-1N/AMessage digest Note: SHA-1 is not used for digital signature generation
A4354SHS [FIPS PUB 180-4]SHA2-256N/AMessage digest
A4354SHS [FIPS PUB 180-4]SHA2-384N/AMessage digest
A4354SHS [FIPS PUB 180-4]SHA2-512N/AMessage digest
A4354DRBG32 [NIST SP 800-90Arev1]CTR33_DRBG (AES- 256) Derivation Function Enabled: Yes256 bitsRandom number generation
Vendor AffirmedCKG [SP 800-133rev2]N/AN/ASymmetric and asymmetric key generation (Please refer to section “SSP Generation” in this document for more information)

NOTES:

Page 9
Algorithm/FunctionUse/Function
RSAKey establishment with PKCS1-v1.5 padding
MD5Message digest
Triple-DESEncryption/decryption
3 Cryptographic module interfaces

The module’s physical perimeter encompasses the case of the tested platform mentioned in section 2 above. No data passes in or out of these physical ports. The module provides logical interfaces via welldefined APIs. The logical interfaces provided by the module are mapped to the following FIPS 140-3 interfaces: © Cisco Systems, Inc. 9

Page 10
Physical PortLogical InterfaceData that passes over port/interface
N/AData InputAPI input parameters – plaintext and/or ciphertext data
N/AData OutputAPI output parameters – plaintext and/or ciphertext data
N/AControl InputAPI input parameters – function calls, or input arguments that specify commands and control data used to control the operation of the module
N/AControl OutputNot applicable
N/AStatus OutputAPI return codes- function return codes, error codes, or output arguments that receive status information used to indicate the status of the module
N/APowerNot applicable
RoleServiceInputOutput
COInitialize moduleNoneModule loaded
COShow statusAPI commandModule’s current status
COPerform self-testAPI commandOutput display on each algorithm running self-test and pass/fail indicator
COShow version informationAPI commandDisplays the module’s name/ID and versioning information
COSymmetric cipher operationAPI commands, key, and plaintext/ciphertext dataPlaintext or ciphertext
COAsymmetric cipher operationAPI commands, keys, and ciphertext/plaintext dataSignature and plaintext/ciphertext
COKey exchange/agreement component (NIST SP 800-56Arev3)API commands, asymmetric keysAsymmetric key or key agreement component
COKey wrapping (KW)API commands, wrapping key, keyWrapped key
COKey derivation functionIKEv2 (existing application specific): IKEv2 parametersKDF shared secret data
SNMPv3 (existing application specific): SNMPv3 parametersKDF shared secret data
SRTP (existing application specific): SRTP parametersKDF shared secret data

Table 6 below provides a description of data that passes through each logical interface. Table 6 – Ports and Interfaces

4 Roles, services, and authentication

The module supports the CO35 role. The module does not provide any authentication methods. The module does not allow concurrent operators. The CO role is implicitly assumed based on the service requested. The module provides the services in Table 8 below to the CO. Table 7 below provides roles, service commands, input, and output for the module. CO – Crypto Officer © Cisco Systems, Inc. 10

Page 11
RoleServiceInputOutput
SSH (existing application specific): SSH parametersKDF shared secret data
TLS (KDF, existing application specific): TLS parametersKDF shared secret data
COKeyed hashing functionAPI commands, HMAC key, plaintextMAC value
COMessage digestAPI commands, plaintextHash value
CORandom number generationAPI commandsRandom bits
COZeroizationAPI commandNone
ServiceDescriptionApproved Security FunctionKeys and/or SSPsRolesAccess RightsIndicator
Initialize moduleInitialization occurs when the module is loadedNoneNoneCORN/A
Show statusDisplay running status of the moduleN/ANoneCON/AN/A
Perform self-testPerform Self-Tests (Pre- operational self-tests and Conditional Self-Tests)AES-CBC; AES-CMAC; AES-GCM; CTR-DRBG; ECDSA SigGen; ECDSA SigVer; HMAC-SHA2-256; KAS-FFC-SSC; KAS-ECC-SSC; RSA SigGen; RSA SigVer; SHA-1; SHA2-256; SHA2-512; KDF IKEv2; KDF SNMP; KDF SRTP; KDF SSH; TLS v1.2 KDF with RFC7627; TLS v1.3 KDFFirmware integrity key (non-SSP)CORAPI return value
Show version informationProvide module’s name and version informationN/ANoneCON/AN/A
Symmetric cipher operationPerform encryption/decryption of dataCKG; DRBG; AES-CBC; AES-CFB128; AES-ECB;DRBG entropy input; DRBG seed;COG, R, W, EAPI return value

Table 8 below lists all approved services that can be used in the approved mode of operation. The abbreviations of the access rights to keys and SSPs have the following interpretation:

Page 12
ServiceDescriptionApproved Security FunctionKeys and/or SSPsRolesAccess RightsIndicator
AES-CMAC; AES-GMAC; AES-GCMDRBG internal state V value; DRBG key; AES EDK
Asymmetric cipher operationPerform signature generation/verification and key generationCKG; DRBG; RSA KeyGen; RSA SigGen; RSA SigVer; ECDSA KeyGen; ECDSA KeyVer; ECDSA SigGen; ECDSA SigVerDRBG entropy input; DRBG seed; DRBG internal state V value; DRBG key; RSA SGK; RSA SVK; ECDSA SGK; ECDSA SVKCOG, R, W, EAPI return value
Key exchange/agreement componentPerform key agreement primitives on behalf of the calling application (does not establish keys into the module)CKG; DRBG; KAS-ECC-SSC; KAS-FFC-SSC; Safe Primes Key GenerationDRBG entropy input; DRBG seed; DRBG internal state V value; DRBG key; DH public key; DH private key; ECDH public key; ECDH private keyCOG, R, W, EAPI return value
Key wrapping (KW)Encrypt a key value on behalf of the calling applicationCKG; DRBG; AES-KWDRBG entropy input; DRBG seed; DRBG internal state V value; DRBG key; AES KWKCOG, R, W, EAPI return value
KDF IKEv2 functionDerive keys for IKEv2 protocolKDF IKEv2IKEv2 KDF SecretCOG, R, W, EAPI return value
KDF SNMPv3 functionDerive keys for SNMPv3 protocolKDF SNMPSNMP KDF secretCOG, R, W, EAPI return value
KDF SRTP functionDerive keys for SRTP protocolKDF SRTPSRTP KDF secretCOG, R, W, EAPI return value
Page 13
ServiceDescriptionApproved Security FunctionKeys and/or SSPsRolesAccess RightsIndicator
KDF SSHv2 functionDerive keys for SSHv2 protocolKDF SSHSSH KDF secretCOG, R, W, EAPI return value
KDF TLS v1.2 functionDerive keys for TLS v1.2 protocolTLSv1.2 KDF RFC 7627TLS v1.2 KDF extended master secretCOG, R, W, EAPI return value
KDF TLS v1.3 functionDerive keys for TLS v1.3 protocolTLSv1.3 KDFTLS v1.3 KDF secretCOG, R, W, EAPI return value
Keyed hashing functionGenerate keyed hashCKG; DRBG; HMAC-SHA-1; HMAC-SHA2-256; HMAC-SHA2-384; HMAC-SHA2-512;DRBG entropy input; DRBG seed; DRBG internal state V value; DRBG key; HMAC keyCOG, R, W, EAPI return value
Message digestGenerate message digest (secure hashing function)SHA-1; SHA2-256; SHA2-384; SHA2-512;NoneCOG, R, W, EAPI return value
Random number generationProvide random data for key generationCTR-DRBGDRBG entropy input; DRBG seed; DRBG internal state V value; DRBG keyCOG, R, W, EAPI return value
ZeroizationZeroize all SSPs stored in allocated memory. Cleanup is the responsibility of the calling application.NoneAll SSPsCOZN/A
Page 14
ServiceDescriptionAlgorithm AccessedRoleIndicator
Message digestGenerate message digestMD5COAPI return value
Asymmetric cipher operationPerform signature generation/verificationRSA (PKCS1-v1.5 padding)COAPI return value
Symmetric cipher operationPerform decryption of ciphertext dataTriple-DESCOAPI return value

Table 9 below lists non-Approved services supported by the module. Table 9 - Non-Approved Services

5 Software/Firmware security

Integrity techniques The IC2Mrel5b cryptographic module is a binary file (sub_crypto_ic2m_k9.o) statically linked within the IOS-XE OS. To ensure firmware security, the module is protected by an HMAC-SHA2-256 (HMAC Cert. #A4354) algorithm. The firmware integrity test key (non-SSP) was preloaded to the module’s binary at the factory and used only for the pre-operational firmware integrity self-test. During initialization of the module, the integrity of the runtime executable is verified using an HMAC-SHA2-256 which is compared to a value computed at build time. If at load time the MAC does not match the stored, known MAC value, the module enters a critical error state where all crypto functionality inhibited. The module must be reloaded to attempt the integrity test again. Integrity test on-demand The integrity test is performed as part of the Pre-Operational Self-Tests. It is automatically executed at power-on. The operator can power-cycle or reboot the tested platform to initiate the integrity test ondemand.

6 Operational environment

The module is operated in a non-modifiable operational environment per ISO/IEC 19790, section 7.6, level

1 specifications. The module is delivered as part of the IOS-XE OS. The OS is restricted to a single

operator mode of operation (i.e., concurrent operators are explicitly excluded). The application that makes calls to the module is the single user of the module. The module’s firmware version running on each tested platform is Rel5b.

7 Physical security

Per ISO/IEC 19790, section 7.7, the module is defined as a multi-chip standalone firmware cryptographic module. The module runs on a host appliance made of production-grade components with standard passivation techniques.

8 Non-invasive security

At the time of publication of this Security Policy, non-invasive security is not required for FIPS 140-3 certification (see NIST SP 800-140F). The requirements of this area are not applicable to the module. © Cisco Systems, Inc. 14

Page 15
Keys/ SSP Name/TypeStrengthSecurity Function and Cert NumberGenerationImport/ ExportEstablish- mentStorageZeroizationUse and released keys
AES EDK (CSP)128-256 bitsCKG; DRBG; AES-CBC; AES-CFB128; AES-ECB; AES-CMAC; AES-GCM; AES-GMAC; Cert: A4354Internally generated conformant to NIST SP 800-133r2 (CKG), section 6 for Symmetric Key Generation method, and the random value used in key generation is generated using SP 800-90Arev1 DRBG.Import: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downSymmetric encryption/ decryption
AES KWK (CSP)128-256 bitsCKG; DRBG; AES-KW Cert: A4354Internally generated conformant to NIST SP 800-133r2 (CKG), section 6 for Symmetric Key Generation method, and the random value used in key generation is generated using SP 800-90Arev1 DRBG.Import: No Export: NoN/AStored outside the module in the host OSZeroized via API command outside the module; Power cycleKey wrapping
RSA SGK (CSP)112-152 bitsCKG; DRBG; RSA KeyGen; RSA SigVer Cert: A4354Internally generated conformant to NIST SP 800-133r2 (CKG) using FIPS 186-4 RSA key generation method, and the random value used in the key generation is generated using SP 800- 90Arev1 DRBG.Import: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downDigital signature generation
RSA SVK (PSP36)112-152 bitsRSA SigVer; Cert: A4354Internally derived conformant to FIPS 186-4 RSA key generation methodImport: No Export: Via module APIMD/EEN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downDigital signature verification
ECDSA SGK (CSP)128-192 bitsCKG; DRBG; ECDSA KeyGen; ECDSA KeyVer; ECDSA SigGen; Cert: A4354Internally generated conformant to NIST SP 800-133r2 (CKG) using FIPS 186- 4 ECDSA key generation method, and the random value used in key generation is generated using SP 800- 90Arev1 DRBGImport: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downDigital signature generation
ECDSA SVK (PSP)128-192 bitsECDSA SigVer; Cert: A4354Internally derived conformant to FIPS 186-4 ECDSA key generation methodImport: No Export: Via module APIMD/EEN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downDigital signature verification
DH public key (PSP)112-152 bitsKAS-FFC-SSC; Cert: A4354Internally derived conformant to SP 800- 56A rev3 DH key generation methodImport: No Export: NoN/AN/A: The module does not provide persistentAutomatic zeroization when the tested platform is powered downKey agreement
9 Sensitive security parameters management

Table 10 below provides information for the SSPs that are used by the cryptographic services Table 10 - SSPs © Cisco Systems, Inc. 15

Page 16
Keys/ SSP Name/TypeStrengthSecurity Function and Cert NumberGenerationImport/ ExportEstablish- mentStorage keys/SSPs storageZeroizationUse and released keys
DH private key (CSP)112-152 bitsCKG; DRBG; KAS-FFC-SSC Cert: A4354Internally generated conformant to NIST SP 800-133r2 (CKG) using SP 800-56Arev3 DH key generation method, and the random value used in the key generation is generated using SP 800-90Arev1 DRBGImport: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downKey agreement
ECDH public key (PSP)128-256 bitsKAS-ECC- SSC; Cert: A4354Internally derived conformant to SP 800- 56A rev3 EC Diffie- Hellman key generation methodImport: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downKey agreement
ECDH private key (CSP)128-256 bitsCKG; DRBG; KAS-ECC- SSC; Cert: A4354Internally generated conformant to NIST SP 800-133r2 (CKG) using SP 800-56Arev3 ECDH key generation method, and the random value used in the key generation is generated using SP 800-90Arev1 DRBGImport: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downKey agreement
HMAC key (CSP)112 bits or greaterCKG; DRBG; HMAC-SHA-1; HMAC-SHA2- 256; HMAC-SHA2- 384 Cert: A4354Internally generated conformant to NIST SP 800-133r2 (CKG), section 6 for Symmetric Key Generation method, and the random value used in key generation is generated using SP 800-90Arev1 DRBGImport: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downMAC generation
DRBG entropy input (CSP)112 bits or greaterN/AObtained from the Entropy Source within TOEPP (GPS INT PathwaysImport: Via module API Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downRandom number generation
DRBG seed, (CSP)384 bitsCTR_DRBG Cert: A4354Internally Derived from entropy input string as defined by NIST SP 800-90Arev1Import: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downRandom number generation
DRBG internal state V value, (CSP)384 bitsCTR_DRBG Cert: A4354Internally Derived from entropy input string as defined by NIST SP 800-90Arev1Import: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downRandom number generation
DRBG key (CSP)384 bitsCTR_DRBG Cert: A4354Internally Derived from entropy input string as defined by NIST SP 800-90Arev1Import: No Export: NoN/AN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downRandom number generation
IKEv2 KDF secret (CSP)112-256 bitsKDF IKEv2 Cert: A4354Internally derived per the KDF defined in NIST SP 800-135 KDF (IKEv2)Import: No Export:MD/EEN/A: The module does not provide persistentAutomatic zeroization when the tested platform is powered downKeying material used to derive other IPSec/IKEv2 keys
Page 17
Keys/ SSP Name/TypeStrengthSecurity Function and Cert NumberGenerationImport/ Export As part of agreement schemeEstablish- mentStorage keys/SSPs storageZeroizationUse and released keys
SNMPv3 KDF secret (CSP)112-256 bitsKDF SNMP Cert: A4354Internally derived per the KDF defined in NIST SP 800-135 KDF (SNMPv3)Import: No Export: As part of agreement schemeMD/EEN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downKeying material used to derive other SNMPv3 keys
SRTP KDF secret (CSP)112-256 bitsKDF SRTP Cert: A4354Internally derived per the KDF defined in NIST SP 800-135 KDF (SRTP)Import: No Export: As part of agreement schemeMD/EEN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downKeying material used to derive other SRTP keys
SSH KDF secret (CSP)112-256 bitsKDF SSH Cert: A4354Internally derived per the KDF defined in NIST SP 800-135 KDF (SSHv2)Import: No Export: As part of agreement schemeMD/EEN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downKeying material used to derive other SSHv2 keys
TLSv1.2 KDF extended master secret (CSP)112-256 bitsTLSv1.2 KDF with RFC 7627 Cert: A4354Internally derived per the KDF defined in NIST SP 800-135 KDF (TLSv1.2 with RFC 7627)Import: No Export: As part of agreement schemeMD/EEN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downKeying material used to derive other TLSv1.2 keys
TLSv1.3 KDF secret (CSP)112-256 bitsKDF TLSv1.3 Cert: A4354Internally derived per the KDF defined in NIST SP 800-135 KDF (TLSv1.3 with RFC 8446)Import: No Export: As part of agreement schemeMD/EEN/A: The module does not provide persistent keys/SSPs storageAutomatic zeroization when the tested platform is powered downKeying material used to derive other TLSv1.3 keys
Entropy sourcesMinimum number of bits of entropyDetails
The OS passively loads entropy within the TOEPP into the module to seed the NIST SP 800-90Arev1 DRBGAt least 112 bitsWhile in the approved mode of operation, the entropy and seeding material for the NIST SP 800-90Arev1 DRBG are provided by the external calling application (and not by the module) which is outside the module’s cryptographic boundary but contained within the module’s physical perimeter. The module receives a LOAD command with entropy obtained from the entropy source inside the TOEPP. The minimum effective strength of the NIST SP 800-90Arev1 DRBG seed is required to be at least 112-bits when used in an approved mode of operation; therefore the minimum number of bits of entropy requested when the Module makes a call to the NIST SP 800-90Arev1 DRBG is at least 112-bits. Per the IG 9.3.A Entropy Caveats, the following caveat applies: No assurance of the minimum strength of generated SSPs (e.g., keys).

Table 11 below specifies the modules entropy sources. Table 11 - Non-Deterministic Random Number Generation Specification © Cisco Systems, Inc. 17

Page 18

Random Number Generation The Approved DRBG for random number generation is a NIST SP 800-90Arev1 CTR_DRBG using AES-

256 with derivation function and without prediction resistance. The numbers used for key generation are

all generated by the CTR_DRBG within the module. Per NIST SP 800-90Arev1, section 10.2.1.1, the internal state is the values of V and Key. Refer to Table 4 above for the CAVP certificate of the validated DRBG algorithm. SSP Generation The module generates RSA, ECDSA, ECDH, and DH asymmetric key pairs compliant with FIPS 186-4, using a NIST SP 800-90Arev1 CTR_DRBG for random number generation. In accordance with FIPS 140-

3 IG D.H, the cryptographic module performs CKG for asymmetric keys as per section 5 of NIST SP 800-

133rev2 (vendor affirmed) by obtaining a random bit string directly from an approved DRBG. The random bit string supports the required security strength requested by the calling application (without any V, as described in Additional Comments 2 of IG D.H.). The module generates AES symmetric keys compliant with FIPS PUB 197 and HMAC key compliant with FIPS PUB 198. All symmetric key generation is performed using a NIST SP 800-90Arev1 CRT_DRBG for rando number generation. In accordance with FIPS 140-3 IG D.H, the cryptographic module performs CKG for symmetric keys as per section 6 of NIST SP 800-133rev2. SSP Entry and Output The module does not support manual SSP entry or intermediate key generation output. SSPs are not output through physical ports on the TOEPP. SSPs are input in plaintext form via API from the calling application to the module. SSPs are output in plaintext form from the module to the calling application within TOEPP. Per ISO/IEC 19790, section 7.9.5, the module performs two independent internal actions to prevent the inadvertent output of sensitive information:

  1. The module internally requests the random number generation service, confirming it executes successfully.
  2. Once keys are generated, the module performs the PCT to verify the keys are correctly generated. Once both actions are successfully completed, the module outputs the SSP to the calling application via the output API. SSP Storage The module does not provide persistent storage of SSPs. SSP storage is performed by the tested platform. Zeroization The module does not possess persistent storage of SSPs. The SSP value only exists in volatile memory of the host appliance and that value vanishes when the module is powered off. The procedure for secure sanitization of the module at the end of life is simply to power off the tested platform. © Cisco Systems, Inc. 18
Page 19
10 Self-tests

The module performs Pre-Operational Self-Tests and CASTs 37 before entering an approved mode of operation. The module is single threaded and will not return to the calling application until all self-tests are complete. If any of the pre-operational self-tests or conditional cryptographic algorithm self-tests fail, the module enters a critical error state and sends an error to the OS. The module supports two Error states, critical error state and soft error state. Following is an example of the error message displayed on the console of the host appliance in a critical error state: %CRYPTO-0-SELF_TEST_FAILURE: Encryption self-test failed (<failing test description>) In a critical error state no cryptographic operations are performed and data output is prohibited. The CO can clear the error state by restarting the module. If a PCT fails, the module enters a soft error state, deletes the key, logs an error, and returns to the approved mode of operation. In the approved mode of operation the service may be retried or a new service may be performed. Following is an example of the error message displayed on the console of the host appliance in a soft error state: %CRYPTO-3-RSA_SELFTEST_FAILED: Generated RSA key failed self test If the module fails to retrieve enough entropy, the module enters a soft error state. The module deletes the DRBG value, then reseeds and reinitializes the DRBG. Pre-operational self-tests: Pre-operational firmware integrity test:

Page 20
During system start-up, the is the default entry point for the module. The ic2m_init() function initiates all self-tests and does not returnOS will call module’s ic2m_init() function. The ic2m_init() function
to the operation. No other tasks are executed while the self-tests are performed so no data is passed and all cryptographic operations are prohibited. If a self-test fails, the module enters a critical error state and must be reloaded to clear the error state and retry the self-tests.IOS-XEOS until all self-tests are completed successfully and the module is in an approved mode of
11 Life-cycle assurance

The module meets all the Level 1 requirements for FIPS 140-3. The module is completely and permanently embedded into Host Device IOS-XE OS. There are no installation considerations besides the loading of the IOS-XE OS. The module cannot be modified, replaced, or upgraded except by loading a new Host Device IOS-XE version in its entirety. The module functions entirely within the process space of the process that invokes it, and thus satisfies the FIPS 140-3 requirement for a single user mode of operation. AES-GCM IV: The CO shall consider the following requirements and restrictions when using the module. • The AES-GCM IV is constructed in compliance with IG C.H, scenario 1 (TLS v1.2), scenario 2 (IPsec-v3), and scenario 5 (TLS v1.3). Users should consult IG C.H specific scenarios for all the © Cisco Systems, Inc. 20

Page 21

requirements using AES-GCM mode. The TLS and IPsec/IKE protocols have not been reviewed or tested by the CAVP and CMVP.

12 Mitigation of other attacks

The module does not support mitigation of other attacks as defined under ISO/IEC 19790, section 7.12. © Cisco Systems, Inc. 21

Page 22
Term/AcronymDefinition
AESAdvanced Encryption Standard
APIApplication Programming Interface
ASRAggregated Services Router
CASTCryptographic Algorithm Self-Tests
CAVPCryptographic Algorithm Validation Program
CBCCipher-Block Chaining
CFBCipher Feedback
CKGCryptographic Key Generation
CMACCipher-based Message Authentication Code
CMVPCryptographic Module Validation Program
COCrypto Officer
CSPCritical Security Parameter
CTRCounter
CVLComponent Validation List
DHDiffie-Hellman
DRBGDeterministic Random Bit Generator
ECBElectronic Codebook
ECCElliptic Curve Cryptography
ECDHElliptic Curve Diffie-Hellman
ECDSAElliptic Curve Digital Signature Algorithm
FFCFinite Field Cryptography
FIPSFederal Information Processing Standards
GCMGalois Counter Mode
GMACGalois Message Authentication Code
HMAC(keyed)-Hashed Message Authentication Code
IECInternational Electrotechnical Commission
IGImplementation Guidance
IKEInternet Key Exchange
IPsecIP Security
ISOInternational Organization of Standardization
KASKey Agreement Scheme
KATKnown Answer Test
KDFKey Derivation Function
N/ANot Applicable
NISTNational Institute of Standards and Technology
OSOperating System
PCTPairwise Consistency Test
PSPPublic Security Parameter
PUBPublication
RFCRequest for Comment
RSARivest, Shamir, and Adleman
SHASecure Hash Algorithm
SHSSecure Hash Standard
SSCShared Secret Computation
SSHSecure Shell
SNMPSimple Network Transfer Protocol
SPSpecial

Appendix A – Acronyms and Terms Table 12 below provides a list of acronyms and terms used throughout this Security Policy. Table 12 - Acronyms and Terms © Cisco Systems, Inc. 22

Page 23
Term/AcronymDefinition
SRTPSecure Real-time Protocol
SSPSensitive Security Parameters
TLSTransport Layer Security
TOEPPTested Operational Environment’s Physical Perimeter