| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Firmware |
| Embodiment | Multi-Chip Stand Alone |
| Status | Historical |
| Caveat | Interim Validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys) |
| Vendor | Cisco Systems, Inc. |
| Algorithm | ACVP Cert |
|---|---|
| AES-CBC | A4354 |
| AES-CFB128 | A4354 |
| AES-CMAC | A4354 |
| AES-ECB | A4354 |
| AES-GCM | A4354 |
| AES-GMAC | A4354 |
| AES-KW | A4354 |
| Counter DRBG | A4354 |
| ECDSA KeyGen (FIPS186-4) | A4354 |
| ECDSA KeyVer (FIPS186-4) | A4354 |
| ECDSA SigGen (FIPS186-4) | A4354 |
| ECDSA SigVer (FIPS186-4) | A4354 |
| HMAC-SHA-1 | A4354 |
| HMAC-SHA2-256 | A4354 |
| HMAC-SHA2-384 | A4354 |
| HMAC-SHA2-512 | A4354 |
| KAS-ECC-SSC Sp800-56Ar3 | A4354 |
| KAS-FFC-SSC Sp800-56Ar3 | A4354 |
| KDF IKEv2 | A4354 |
| KDF SNMP | A4354 |
| KDF SRTP | A4354 |
| KDF SSH | A4354 |
| RSA KeyGen (FIPS186-4) | A4354 |
| RSA SigGen (FIPS186-4) | A4354 |
| RSA SigVer (FIPS186-4) | A4354 |
| Safe Primes Key Generation | A4354 |
| SHA-1 | A4354 |
| SHA2-256 | A4354 |
| SHA2-384 | A4354 |
| SHA2-512 | A4354 |
| TLS v1.2 KDF RFC7627 | A4354 |
| TLS v1.3 KDF | A4354 |
flowchart LR
%% Deterministic review-risk graph for IOS Common Cryptographic Module (IC2M)
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status output<br/>Show status<br/>self-test</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
end
subgraph Inference["Derived inference"]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C3,C5,C6 clue;
class I3,I5,I6 infer;
class R3,R5,R6 risk;
class E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for IOS Common Cryptographic Module (IC2M)
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Status output<br/>Show status<br/>self-test</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C3,C5,C6 clueLow;ISO/IEC 19790 and FIPS 140-3 for IOS Common Cryptographic Module (IC2M) Firmware Version: Rel5b Last Updated: August 6, 2024 Version 1.4 Americas Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA
| # | Section | Page |
|---|
| Item | Page |
|---|---|
| FIGURE 1 – LOGICAL CRYPTOGRAPHIC BOUNDARY | 9 |
| TABLE 1 - SECURITY LEVELS | 4 |
| TABLE 2 – TESTED OPERATIONAL ENVIRONMENTS | 5 |
| TABLE 3 - VENDOR AFFIRMED OPERATIONAL ENVIRONMENTS | 5 |
| TABLE 4 - APPROVED ALGORITHMS | 6 |
| TABLE 5 – NON-APPROVED ALGORITHMS NOT ALLOWED IN THE APPROVED MODE OF OPERATION | 9 |
| TABLE 6 – PORTS AND INTERFACES | 10 |
| TABLE 7 – ROLES, SERVICE COMMANDS, INPUT AND OUTPUT | 10 |
| TABLE 8 - APPROVED SERVICES | 11 |
| TABLE 9 - NON-APPROVED SERVICES | 14 |
| TABLE 10 - SSPS | 15 |
| TABLE 11 - NON-DETERMINISTIC RANDOM NUMBER GENERATION SPECIFICATION | 17 |
| TABLE 12 - ACRONYMS AND TERMS | 22 |
| ISO/IEC 24759:2017 Section 6 | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic module specification | 1 |
| 3 | Cryptographic module interfaces | 1 |
| 4 | Roles, services, and authentication | 1 |
| 5 | Software/Firmware security | 1 |
| 6 | Operational environment | 1 |
| 7 | Physical security | 1 |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle assurance | 1 |
| 12 | Mitigation of other attacks | N/A |
(IC2M) with firmware version Rel5b (herein referred to as “IC2Mrel5b” or the “module”). The following details how this module meets the security requirements of FIPS 1 140-3, NIST 2 SP 3 800-140, and ISO4/IEC5 19790 for a Security Level 1 Firmware cryptographic module. The security requirements cover areas related to the design and implementation of a cryptographic module. Table 1 below indicates the security level for each area of the module. Table 1 - Security Levels The overall security level of the module is 1. FIPS
| # | Operating Systems | Hardware Platform | Processor (Acceleration) | PAA/Acceleration | |||||
|---|---|---|---|---|---|---|---|---|---|
| 1 | IOS-XE 17.12 | Cisco Aggregated Services Router (ASR) 1001-HX | Intel Xeon E3-1125C v2 | N/A15 |
| # | Operating System | Hardware Platform |
|---|---|---|
| 1 | IOS-XE 17.12 | Catalyst 9200 Series Switches |
| 2 | IOS-XE 17.12 | Catalyst 9300 Series Switches |
| 3 | IOS-XE 17.12 | Catalyst 9400 Series Switches |
| 4 | IOS-XE 17.12 | Catalyst 9500 Series Switches |
| 5 | IOS-XE 17.12 | Catalyst 9600 Series Switches |
| 6 | IOS-XE 17.12 | Cisco Embedded Services 3300 Series Switch |
| 7 | IOS-XE 17.12 | Cisco Embedded Services 9300 Series Switch |
| 8 | IOS-XE 17.12 | Cisco Catalyst Industrial Ethernet 3000 Series Switch |
| 9 | IOS-XE 17.12 | Cisco Catalyst Industrial Ethernet 9300 Series Switch |
| 10 | IOS-XE 17.12 | Cisco C8500, C8500L Series Edge Platforms |
| 11 | IOS-XE 17.12 | Cisco C8200, C8200L, C8300 Series Edge Platforms |
| 12 | IOS-XE 17.12 | Cisco Aggregation Services Router (ASR) 1000 series |
| 13 | IOS-XE 17.12 | Cisco Integrated Services Router (ISR) 4000 series |
| 14 | IOS-XE 17.12 | Cisco Integrated Services Router (ISR) 1000 series |
| 15 | IOS-XE 17.12 | Cisco C8000V Edge Software Router |
| 16 | IOS-XE 17.12 | Cisco IR 1100, 1800, 8100, 8300 Series Industrial Routers |
IC2Mrel5b is a single binary object file (sub_crypto_ic2m_k9.o) and is classified as a multi-chip standalone firmware module. IC2Mrel5b is a cryptographic library that supports cryptographic operations executed by a calling application. The calling application leverages the module’s well-defined API6 to initialize the module and call cryptographic algorithms for encryption/decryption, key generation, signature generation/verification, and hashing. The cryptographic library does not implement any protocols, but does provide the cryptographic primitives for IPsec7/IKE8v2, SNMP9v3, SRTP10, SSH11v2, and TLS12 v1.2/v1.3. No SSP13s are stored within the cryptographic boundary of the module. The module is intended for use on any Cisco device that runs the IOS-XE OS14, so the physical perimeter of the module is the testing platform. The module’s operational environment is non-modifiable. Table 2 below lists the tested operational environments. Table 2
| CAVP16 Cert | Algorithm/Standard | Mode/Method | Description/Key Size(s)/Key strength(s) | Use/Function |
|---|---|---|---|---|
| A4354 | AES17 [FIPS PUB18 197] [NIST SP 800-38A] | AES-CBC19; | Key Length: 128, 192, 256 bits | Symmetric encryption and decryption |
| A4354 | AES [FIPS PUB 197] [NIST SP 800-38A] | AES-CFB20128; | Key Length: 128, 192, 256 bits | Symmetric encryption and decryption |
| A4354 | AES [FIPS PUB 197] [NIST SP 800-38A] | AES-ECB21 | Key Length: 128, 192, 256 bits | Symmetric encryption and decryption |
| A4354 | AES [FIPS PUB 197] [NIST SP 800-38B] | AES-CMAC22 | Key Length: 128, 256 bits | Authenticated symmetric encryption and decryption |
| A4354 | AES [FIPS PUB 197] [NIST SP 800-38D] | AES-GCM23 | Key Length: 128, 192, 256 bits | Authenticated symmetric encryption and decryption |
| A4354 | AES [FIPS PUB 197] [NIST SP 800-38D] | AES-GMAC24 | Key Length: 128 bits | Authenticated symmetric encryption and decryption |
| A4354 | AES [NIST SP 800-38F] | AES-KW25 (encrypt/decrypt) | Key Length: 128, 192, 256 bits | Symmetric encryption and decryption |
| A4354 | ECDSA [FIPS PUB 186-4] | ECDSA KeyGen | Curves: P-256, P-384, P- 521 | ECDSA keypair generation |
The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when ported to an operational environment which is not listed on the validation certificate. Modes of operation The module supports both approved and non-approved mode of operation. The module will be in approved mode when all pre-operational self-tests have completed successfully and only approved algorithms/services are invoked. Table 4 and Table 7 below for a list of the supported approved/allowed algorithms/services. The non-approved mode is entered when a non-approved algorithm/non-approved service is invoked. See Table 5 and Table 9 below for a list of non-approved algorithms/non-approved services. The Approved mode of operation can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table 9 - Non-Approved Services. The following tables list all Approved or Vendor-affirmed security functions of the module, including specific key size(s) -in bits otherwise noted- employed for approved services, and implemented modes of operation. Table 4 - Approved Algorithms
17 19
CAVP
| CAVP16 Cert | Algorithm/Standard | Mode/Method | Description/Key Size(s)/Key strength(s) | Use/Function |
|---|---|---|---|---|
| A4354 | ECDSA [FIPS PUB 186-4] | ECDSA KeyVer | Curves: P-256, P-384, P- 521 | ECDSA keypair verification |
| A4354 | ECDSA [FIPS PUB 186-4] | ECDSA SigGen | Curves: P-256, P-384, P- 521 | ECDSA signature generation |
| A4354 | ECDSA [FIPS PUB 186-4] | ECDSA SigVer | Curves: P-256, P-384, P- 521 | ECDSA signature verification |
| A4354 | RSA26 [FIPS PUB 186-4] | RSA KeyGen: - Mode: B.3.4 - 2048/3072 bits with SHA2-256 | Modulus: 2048, 3072, 4096 | RSA keypair generation |
| A4354 | RSA [FIPS PUB 186-4] | RSA SigGen: - PKCSv1.5 - 2048/3072 bits with SHA2-256/384/512 | Modulus: 2048, 3072, 4096 | RSA signature generation |
| A4354 | RSA [FIPS PUB 186-4] | RSA SigVer: - PKCSv1.5 - 2048/3072 bits with SHA2-256/384/512 | Modulus: 2048, 3072, 4096 | RSA signature verification |
| A4354 | KAS27-ECC-SSC28 [NIST SP 800-56Arev3] | KAS-ECC29-SSC Scheme: dhEphem: KAS Role: initiator, responder | Curves: P-256, P-384, P- 521 | Key establishment methodology provides between 128 and 256 bits of encryption strength |
| A4354 | KAS-FFC-SSC [NIST SP 800-56Arev3] | KAS-FFC30-SSC Scheme: dhEphem: KAS Role: initiator, responder | MODP-2048, MODP-3072, MODP-4096 | Key establishment methodology provides between 112 and 152 bits of encryption strength |
| A4354 | Safe Primes Key Generation [NIST SP 800-56Arev3] | KeyGen for DH31 (CKG using method in Sections 4 and 5.1 of SP 800- 133rev2) | MODP-2048, MODP-3072, MODP-4096 | KAS-FFC Keypair domain parameters generation |
| A4354 | KDF IKEv2 [NIST SP800-135rev1] (CVL) | KDF IKEv2 | N/A | Key derivation function used in IKEv2 |
| A4354 | KDF SNMP [NIST SP800-135rev1] (CVL) | KDF SNMP | N/A | Key derivation function used in SNMPv3 |
| A4354 | KDF SRTP [NIST SP800-135rev1] (CVL) | KDF SRTP | N/A | Key derivation function used in SRTP |
| A4354 | KDF SSH [NIST SP800-135rev1] (CVL) | KDF SSH | N/A | Key derivation function used in SSHv2 |
RSA
| CAVP16 Cert | Algorithm/Standard | Mode/Method | Description/Key Size(s)/Key strength(s) | Use/Function |
|---|---|---|---|---|
| A4354 | TLSv1.2 KDF RFC7627 (CVL) | TLSv1.2 KDF RFC7627 | N/A | Key derivation in TLSv1.2 with RFC 7627 KDF with Extended Master Secret |
| A4354 | TLS v1.3 KDF [RFC 8446] (CVL) | TLSv1.3 KDF | N/A | Key derivation function used in TLSv1.3 |
| A4354 | HMAC [FIPS 198-1] | HMAC-SHA-1 | Key Length: 112-bits or greater | Keyed hash |
| A4354 | HMAC [FIPS 198-1] | HMAC-SHA2-256 | Key Length: 112-bits or greater | Keyed hash |
| A4354 | HMAC [FIPS 198-1] | HMAC-SHA2-384 | Key Length: 112-bits or greater | Keyed hash |
| A4354 | HMAC [FIPS 198-1] | HMAC-SHA2-512 | Key Length: 112-bits or greater | Keyed hash |
| A4354 | SHS [FIPS PUB 180-4] | SHA-1 | N/A | Message digest Note: SHA-1 is not used for digital signature generation |
| A4354 | SHS [FIPS PUB 180-4] | SHA2-256 | N/A | Message digest |
| A4354 | SHS [FIPS PUB 180-4] | SHA2-384 | N/A | Message digest |
| A4354 | SHS [FIPS PUB 180-4] | SHA2-512 | N/A | Message digest |
| A4354 | DRBG32 [NIST SP 800-90Arev1] | CTR33_DRBG (AES- 256) Derivation Function Enabled: Yes | 256 bits | Random number generation |
| Vendor Affirmed | CKG [SP 800-133rev2] | N/A | N/A | Symmetric and asymmetric key generation (Please refer to section “SSP Generation” in this document for more information) |
NOTES:
| Algorithm/Function | Use/Function |
|---|---|
| RSA | Key establishment with PKCS1-v1.5 padding |
| MD5 | Message digest |
| Triple-DES | Encryption/decryption |
The module’s physical perimeter encompasses the case of the tested platform mentioned in section 2 above. No data passes in or out of these physical ports. The module provides logical interfaces via welldefined APIs. The logical interfaces provided by the module are mapped to the following FIPS 140-3 interfaces: © Cisco Systems, Inc. 9
| Physical Port | Logical Interface | Data that passes over port/interface |
|---|---|---|
| N/A | Data Input | API input parameters – plaintext and/or ciphertext data |
| N/A | Data Output | API output parameters – plaintext and/or ciphertext data |
| N/A | Control Input | API input parameters – function calls, or input arguments that specify commands and control data used to control the operation of the module |
| N/A | Control Output | Not applicable |
| N/A | Status Output | API return codes- function return codes, error codes, or output arguments that receive status information used to indicate the status of the module |
| N/A | Power | Not applicable |
| Role | Service | Input | Output |
|---|---|---|---|
| CO | Initialize module | None | Module loaded |
| CO | Show status | API command | Module’s current status |
| CO | Perform self-test | API command | Output display on each algorithm running self-test and pass/fail indicator |
| CO | Show version information | API command | Displays the module’s name/ID and versioning information |
| CO | Symmetric cipher operation | API commands, key, and plaintext/ciphertext data | Plaintext or ciphertext |
| CO | Asymmetric cipher operation | API commands, keys, and ciphertext/plaintext data | Signature and plaintext/ciphertext |
| CO | Key exchange/agreement component (NIST SP 800-56Arev3) | API commands, asymmetric keys | Asymmetric key or key agreement component |
| CO | Key wrapping (KW) | API commands, wrapping key, key | Wrapped key |
| CO | Key derivation function | IKEv2 (existing application specific): IKEv2 parameters | KDF shared secret data |
| SNMPv3 (existing application specific): SNMPv3 parameters | KDF shared secret data | ||
| SRTP (existing application specific): SRTP parameters | KDF shared secret data |
Table 6 below provides a description of data that passes through each logical interface. Table 6 – Ports and Interfaces
The module supports the CO35 role. The module does not provide any authentication methods. The module does not allow concurrent operators. The CO role is implicitly assumed based on the service requested. The module provides the services in Table 8 below to the CO. Table 7 below provides roles, service commands, input, and output for the module. CO – Crypto Officer © Cisco Systems, Inc. 10
| Role | Service | Input | Output | ||
|---|---|---|---|---|---|
| SSH (existing application specific): SSH parameters | KDF shared secret data | ||||
| TLS (KDF, existing application specific): TLS parameters | KDF shared secret data | ||||
| CO | Keyed hashing function | API commands, HMAC key, plaintext | MAC value | ||
| CO | Message digest | API commands, plaintext | Hash value | ||
| CO | Random number generation | API commands | Random bits | ||
| CO | Zeroization | API command | None |
| Service | Description | Approved Security Function | Keys and/or SSPs | Roles | Access Rights | Indicator |
|---|---|---|---|---|---|---|
| Initialize module | Initialization occurs when the module is loaded | None | None | CO | R | N/A |
| Show status | Display running status of the module | N/A | None | CO | N/A | N/A |
| Perform self-test | Perform Self-Tests (Pre- operational self-tests and Conditional Self-Tests) | AES-CBC; AES-CMAC; AES-GCM; CTR-DRBG; ECDSA SigGen; ECDSA SigVer; HMAC-SHA2-256; KAS-FFC-SSC; KAS-ECC-SSC; RSA SigGen; RSA SigVer; SHA-1; SHA2-256; SHA2-512; KDF IKEv2; KDF SNMP; KDF SRTP; KDF SSH; TLS v1.2 KDF with RFC7627; TLS v1.3 KDF | Firmware integrity key (non-SSP) | CO | R | API return value |
| Show version information | Provide module’s name and version information | N/A | None | CO | N/A | N/A |
| Symmetric cipher operation | Perform encryption/decryption of data | CKG; DRBG; AES-CBC; AES-CFB128; AES-ECB; | DRBG entropy input; DRBG seed; | CO | G, R, W, E | API return value |
Table 8 below lists all approved services that can be used in the approved mode of operation. The abbreviations of the access rights to keys and SSPs have the following interpretation:
| Service | Description | Approved Security Function | Keys and/or SSPs | Roles | Access Rights | Indicator |
|---|---|---|---|---|---|---|
| AES-CMAC; AES-GMAC; AES-GCM | DRBG internal state V value; DRBG key; AES EDK | |||||
| Asymmetric cipher operation | Perform signature generation/verification and key generation | CKG; DRBG; RSA KeyGen; RSA SigGen; RSA SigVer; ECDSA KeyGen; ECDSA KeyVer; ECDSA SigGen; ECDSA SigVer | DRBG entropy input; DRBG seed; DRBG internal state V value; DRBG key; RSA SGK; RSA SVK; ECDSA SGK; ECDSA SVK | CO | G, R, W, E | API return value |
| Key exchange/agreement component | Perform key agreement primitives on behalf of the calling application (does not establish keys into the module) | CKG; DRBG; KAS-ECC-SSC; KAS-FFC-SSC; Safe Primes Key Generation | DRBG entropy input; DRBG seed; DRBG internal state V value; DRBG key; DH public key; DH private key; ECDH public key; ECDH private key | CO | G, R, W, E | API return value |
| Key wrapping (KW) | Encrypt a key value on behalf of the calling application | CKG; DRBG; AES-KW | DRBG entropy input; DRBG seed; DRBG internal state V value; DRBG key; AES KWK | CO | G, R, W, E | API return value |
| KDF IKEv2 function | Derive keys for IKEv2 protocol | KDF IKEv2 | IKEv2 KDF Secret | CO | G, R, W, E | API return value |
| KDF SNMPv3 function | Derive keys for SNMPv3 protocol | KDF SNMP | SNMP KDF secret | CO | G, R, W, E | API return value |
| KDF SRTP function | Derive keys for SRTP protocol | KDF SRTP | SRTP KDF secret | CO | G, R, W, E | API return value |
| Service | Description | Approved Security Function | Keys and/or SSPs | Roles | Access Rights | Indicator |
|---|---|---|---|---|---|---|
| KDF SSHv2 function | Derive keys for SSHv2 protocol | KDF SSH | SSH KDF secret | CO | G, R, W, E | API return value |
| KDF TLS v1.2 function | Derive keys for TLS v1.2 protocol | TLSv1.2 KDF RFC 7627 | TLS v1.2 KDF extended master secret | CO | G, R, W, E | API return value |
| KDF TLS v1.3 function | Derive keys for TLS v1.3 protocol | TLSv1.3 KDF | TLS v1.3 KDF secret | CO | G, R, W, E | API return value |
| Keyed hashing function | Generate keyed hash | CKG; DRBG; HMAC-SHA-1; HMAC-SHA2-256; HMAC-SHA2-384; HMAC-SHA2-512; | DRBG entropy input; DRBG seed; DRBG internal state V value; DRBG key; HMAC key | CO | G, R, W, E | API return value |
| Message digest | Generate message digest (secure hashing function) | SHA-1; SHA2-256; SHA2-384; SHA2-512; | None | CO | G, R, W, E | API return value |
| Random number generation | Provide random data for key generation | CTR-DRBG | DRBG entropy input; DRBG seed; DRBG internal state V value; DRBG key | CO | G, R, W, E | API return value |
| Zeroization | Zeroize all SSPs stored in allocated memory. Cleanup is the responsibility of the calling application. | None | All SSPs | CO | Z | N/A |
| Service | Description | Algorithm Accessed | Role | Indicator |
|---|---|---|---|---|
| Message digest | Generate message digest | MD5 | CO | API return value |
| Asymmetric cipher operation | Perform signature generation/verification | RSA (PKCS1-v1.5 padding) | CO | API return value |
| Symmetric cipher operation | Perform decryption of ciphertext data | Triple-DES | CO | API return value |
Table 9 below lists non-Approved services supported by the module. Table 9 - Non-Approved Services
Integrity techniques The IC2Mrel5b cryptographic module is a binary file (sub_crypto_ic2m_k9.o) statically linked within the IOS-XE OS. To ensure firmware security, the module is protected by an HMAC-SHA2-256 (HMAC Cert. #A4354) algorithm. The firmware integrity test key (non-SSP) was preloaded to the module’s binary at the factory and used only for the pre-operational firmware integrity self-test. During initialization of the module, the integrity of the runtime executable is verified using an HMAC-SHA2-256 which is compared to a value computed at build time. If at load time the MAC does not match the stored, known MAC value, the module enters a critical error state where all crypto functionality inhibited. The module must be reloaded to attempt the integrity test again. Integrity test on-demand The integrity test is performed as part of the Pre-Operational Self-Tests. It is automatically executed at power-on. The operator can power-cycle or reboot the tested platform to initiate the integrity test ondemand.
The module is operated in a non-modifiable operational environment per ISO/IEC 19790, section 7.6, level
1 specifications. The module is delivered as part of the IOS-XE OS. The OS is restricted to a single
operator mode of operation (i.e., concurrent operators are explicitly excluded). The application that makes calls to the module is the single user of the module. The module’s firmware version running on each tested platform is Rel5b.
Per ISO/IEC 19790, section 7.7, the module is defined as a multi-chip standalone firmware cryptographic module. The module runs on a host appliance made of production-grade components with standard passivation techniques.
At the time of publication of this Security Policy, non-invasive security is not required for FIPS 140-3 certification (see NIST SP 800-140F). The requirements of this area are not applicable to the module. © Cisco Systems, Inc. 14
| Keys/ SSP Name/Type | Strength | Security Function and Cert Number | Generation | Import/ Export | Establish- ment | Storage | Zeroization | Use and released keys |
|---|---|---|---|---|---|---|---|---|
| AES EDK (CSP) | 128-256 bits | CKG; DRBG; AES-CBC; AES-CFB128; AES-ECB; AES-CMAC; AES-GCM; AES-GMAC; Cert: A4354 | Internally generated conformant to NIST SP 800-133r2 (CKG), section 6 for Symmetric Key Generation method, and the random value used in key generation is generated using SP 800-90Arev1 DRBG. | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Symmetric encryption/ decryption |
| AES KWK (CSP) | 128-256 bits | CKG; DRBG; AES-KW Cert: A4354 | Internally generated conformant to NIST SP 800-133r2 (CKG), section 6 for Symmetric Key Generation method, and the random value used in key generation is generated using SP 800-90Arev1 DRBG. | Import: No Export: No | N/A | Stored outside the module in the host OS | Zeroized via API command outside the module; Power cycle | Key wrapping |
| RSA SGK (CSP) | 112-152 bits | CKG; DRBG; RSA KeyGen; RSA SigVer Cert: A4354 | Internally generated conformant to NIST SP 800-133r2 (CKG) using FIPS 186-4 RSA key generation method, and the random value used in the key generation is generated using SP 800- 90Arev1 DRBG. | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Digital signature generation |
| RSA SVK (PSP36) | 112-152 bits | RSA SigVer; Cert: A4354 | Internally derived conformant to FIPS 186-4 RSA key generation method | Import: No Export: Via module API | MD/EE | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Digital signature verification |
| ECDSA SGK (CSP) | 128-192 bits | CKG; DRBG; ECDSA KeyGen; ECDSA KeyVer; ECDSA SigGen; Cert: A4354 | Internally generated conformant to NIST SP 800-133r2 (CKG) using FIPS 186- 4 ECDSA key generation method, and the random value used in key generation is generated using SP 800- 90Arev1 DRBG | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Digital signature generation |
| ECDSA SVK (PSP) | 128-192 bits | ECDSA SigVer; Cert: A4354 | Internally derived conformant to FIPS 186-4 ECDSA key generation method | Import: No Export: Via module API | MD/EE | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Digital signature verification |
| DH public key (PSP) | 112-152 bits | KAS-FFC-SSC; Cert: A4354 | Internally derived conformant to SP 800- 56A rev3 DH key generation method | Import: No Export: No | N/A | N/A: The module does not provide persistent | Automatic zeroization when the tested platform is powered down | Key agreement |
Table 10 below provides information for the SSPs that are used by the cryptographic services Table 10 - SSPs © Cisco Systems, Inc. 15
| Keys/ SSP Name/Type | Strength | Security Function and Cert Number | Generation | Import/ Export | Establish- ment | Storage keys/SSPs storage | Zeroization | Use and released keys |
|---|---|---|---|---|---|---|---|---|
| DH private key (CSP) | 112-152 bits | CKG; DRBG; KAS-FFC-SSC Cert: A4354 | Internally generated conformant to NIST SP 800-133r2 (CKG) using SP 800-56Arev3 DH key generation method, and the random value used in the key generation is generated using SP 800-90Arev1 DRBG | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Key agreement |
| ECDH public key (PSP) | 128-256 bits | KAS-ECC- SSC; Cert: A4354 | Internally derived conformant to SP 800- 56A rev3 EC Diffie- Hellman key generation method | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Key agreement |
| ECDH private key (CSP) | 128-256 bits | CKG; DRBG; KAS-ECC- SSC; Cert: A4354 | Internally generated conformant to NIST SP 800-133r2 (CKG) using SP 800-56Arev3 ECDH key generation method, and the random value used in the key generation is generated using SP 800-90Arev1 DRBG | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Key agreement |
| HMAC key (CSP) | 112 bits or greater | CKG; DRBG; HMAC-SHA-1; HMAC-SHA2- 256; HMAC-SHA2- 384 Cert: A4354 | Internally generated conformant to NIST SP 800-133r2 (CKG), section 6 for Symmetric Key Generation method, and the random value used in key generation is generated using SP 800-90Arev1 DRBG | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | MAC generation |
| DRBG entropy input (CSP) | 112 bits or greater | N/A | Obtained from the Entropy Source within TOEPP (GPS INT Pathways | Import: Via module API Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Random number generation |
| DRBG seed, (CSP) | 384 bits | CTR_DRBG Cert: A4354 | Internally Derived from entropy input string as defined by NIST SP 800-90Arev1 | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Random number generation |
| DRBG internal state V value, (CSP) | 384 bits | CTR_DRBG Cert: A4354 | Internally Derived from entropy input string as defined by NIST SP 800-90Arev1 | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Random number generation |
| DRBG key (CSP) | 384 bits | CTR_DRBG Cert: A4354 | Internally Derived from entropy input string as defined by NIST SP 800-90Arev1 | Import: No Export: No | N/A | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Random number generation |
| IKEv2 KDF secret (CSP) | 112-256 bits | KDF IKEv2 Cert: A4354 | Internally derived per the KDF defined in NIST SP 800-135 KDF (IKEv2) | Import: No Export: | MD/EE | N/A: The module does not provide persistent | Automatic zeroization when the tested platform is powered down | Keying material used to derive other IPSec/IKEv2 keys |
| Keys/ SSP Name/Type | Strength | Security Function and Cert Number | Generation | Import/ Export As part of agreement scheme | Establish- ment | Storage keys/SSPs storage | Zeroization | Use and released keys |
|---|---|---|---|---|---|---|---|---|
| SNMPv3 KDF secret (CSP) | 112-256 bits | KDF SNMP Cert: A4354 | Internally derived per the KDF defined in NIST SP 800-135 KDF (SNMPv3) | Import: No Export: As part of agreement scheme | MD/EE | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Keying material used to derive other SNMPv3 keys |
| SRTP KDF secret (CSP) | 112-256 bits | KDF SRTP Cert: A4354 | Internally derived per the KDF defined in NIST SP 800-135 KDF (SRTP) | Import: No Export: As part of agreement scheme | MD/EE | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Keying material used to derive other SRTP keys |
| SSH KDF secret (CSP) | 112-256 bits | KDF SSH Cert: A4354 | Internally derived per the KDF defined in NIST SP 800-135 KDF (SSHv2) | Import: No Export: As part of agreement scheme | MD/EE | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Keying material used to derive other SSHv2 keys |
| TLSv1.2 KDF extended master secret (CSP) | 112-256 bits | TLSv1.2 KDF with RFC 7627 Cert: A4354 | Internally derived per the KDF defined in NIST SP 800-135 KDF (TLSv1.2 with RFC 7627) | Import: No Export: As part of agreement scheme | MD/EE | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Keying material used to derive other TLSv1.2 keys |
| TLSv1.3 KDF secret (CSP) | 112-256 bits | KDF TLSv1.3 Cert: A4354 | Internally derived per the KDF defined in NIST SP 800-135 KDF (TLSv1.3 with RFC 8446) | Import: No Export: As part of agreement scheme | MD/EE | N/A: The module does not provide persistent keys/SSPs storage | Automatic zeroization when the tested platform is powered down | Keying material used to derive other TLSv1.3 keys |
| Entropy sources | Minimum number of bits of entropy | Details | |
|---|---|---|---|
| The OS passively loads entropy within the TOEPP into the module to seed the NIST SP 800-90Arev1 DRBG | At least 112 bits | While in the approved mode of operation, the entropy and seeding material for the NIST SP 800-90Arev1 DRBG are provided by the external calling application (and not by the module) which is outside the module’s cryptographic boundary but contained within the module’s physical perimeter. The module receives a LOAD command with entropy obtained from the entropy source inside the TOEPP. The minimum effective strength of the NIST SP 800-90Arev1 DRBG seed is required to be at least 112-bits when used in an approved mode of operation; therefore the minimum number of bits of entropy requested when the Module makes a call to the NIST SP 800-90Arev1 DRBG is at least 112-bits. Per the IG 9.3.A Entropy Caveats, the following caveat applies: No assurance of the minimum strength of generated SSPs (e.g., keys). |
Table 11 below specifies the modules entropy sources. Table 11 - Non-Deterministic Random Number Generation Specification © Cisco Systems, Inc. 17
Random Number Generation The Approved DRBG for random number generation is a NIST SP 800-90Arev1 CTR_DRBG using AES-
256 with derivation function and without prediction resistance. The numbers used for key generation are
all generated by the CTR_DRBG within the module. Per NIST SP 800-90Arev1, section 10.2.1.1, the internal state is the values of V and Key. Refer to Table 4 above for the CAVP certificate of the validated DRBG algorithm. SSP Generation The module generates RSA, ECDSA, ECDH, and DH asymmetric key pairs compliant with FIPS 186-4, using a NIST SP 800-90Arev1 CTR_DRBG for random number generation. In accordance with FIPS 140-
3 IG D.H, the cryptographic module performs CKG for asymmetric keys as per section 5 of NIST SP 800-
133rev2 (vendor affirmed) by obtaining a random bit string directly from an approved DRBG. The random bit string supports the required security strength requested by the calling application (without any V, as described in Additional Comments 2 of IG D.H.). The module generates AES symmetric keys compliant with FIPS PUB 197 and HMAC key compliant with FIPS PUB 198. All symmetric key generation is performed using a NIST SP 800-90Arev1 CRT_DRBG for rando number generation. In accordance with FIPS 140-3 IG D.H, the cryptographic module performs CKG for symmetric keys as per section 6 of NIST SP 800-133rev2. SSP Entry and Output The module does not support manual SSP entry or intermediate key generation output. SSPs are not output through physical ports on the TOEPP. SSPs are input in plaintext form via API from the calling application to the module. SSPs are output in plaintext form from the module to the calling application within TOEPP. Per ISO/IEC 19790, section 7.9.5, the module performs two independent internal actions to prevent the inadvertent output of sensitive information:
The module performs Pre-Operational Self-Tests and CASTs 37 before entering an approved mode of operation. The module is single threaded and will not return to the calling application until all self-tests are complete. If any of the pre-operational self-tests or conditional cryptographic algorithm self-tests fail, the module enters a critical error state and sends an error to the OS. The module supports two Error states, critical error state and soft error state. Following is an example of the error message displayed on the console of the host appliance in a critical error state: %CRYPTO-0-SELF_TEST_FAILURE: Encryption self-test failed (<failing test description>) In a critical error state no cryptographic operations are performed and data output is prohibited. The CO can clear the error state by restarting the module. If a PCT fails, the module enters a soft error state, deletes the key, logs an error, and returns to the approved mode of operation. In the approved mode of operation the service may be retried or a new service may be performed. Following is an example of the error message displayed on the console of the host appliance in a soft error state: %CRYPTO-3-RSA_SELFTEST_FAILED: Generated RSA key failed self test If the module fails to retrieve enough entropy, the module enters a soft error state. The module deletes the DRBG value, then reseeds and reinitializes the DRBG. Pre-operational self-tests: Pre-operational firmware integrity test:
| During system start-up, the is the default entry point for the module. The ic2m_init() function initiates all self-tests and does not return | OS will call module’s ic2m_init() function. The ic2m_init() function | ||
|---|---|---|---|
| to the operation. No other tasks are executed while the self-tests are performed so no data is passed and all cryptographic operations are prohibited. If a self-test fails, the module enters a critical error state and must be reloaded to clear the error state and retry the self-tests. | IOS-XE | OS until all self-tests are completed successfully and the module is in an approved mode of |
The module meets all the Level 1 requirements for FIPS 140-3. The module is completely and permanently embedded into Host Device IOS-XE OS. There are no installation considerations besides the loading of the IOS-XE OS. The module cannot be modified, replaced, or upgraded except by loading a new Host Device IOS-XE version in its entirety. The module functions entirely within the process space of the process that invokes it, and thus satisfies the FIPS 140-3 requirement for a single user mode of operation. AES-GCM IV: The CO shall consider the following requirements and restrictions when using the module. • The AES-GCM IV is constructed in compliance with IG C.H, scenario 1 (TLS v1.2), scenario 2 (IPsec-v3), and scenario 5 (TLS v1.3). Users should consult IG C.H specific scenarios for all the © Cisco Systems, Inc. 20
requirements using AES-GCM mode. The TLS and IPsec/IKE protocols have not been reviewed or tested by the CAVP and CMVP.
The module does not support mitigation of other attacks as defined under ISO/IEC 19790, section 7.12. © Cisco Systems, Inc. 21
| Term/Acronym | Definition |
|---|---|
| AES | Advanced Encryption Standard |
| API | Application Programming Interface |
| ASR | Aggregated Services Router |
| CAST | Cryptographic Algorithm Self-Tests |
| CAVP | Cryptographic Algorithm Validation Program |
| CBC | Cipher-Block Chaining |
| CFB | Cipher Feedback |
| CKG | Cryptographic Key Generation |
| CMAC | Cipher-based Message Authentication Code |
| CMVP | Cryptographic Module Validation Program |
| CO | Crypto Officer |
| CSP | Critical Security Parameter |
| CTR | Counter |
| CVL | Component Validation List |
| DH | Diffie-Hellman |
| DRBG | Deterministic Random Bit Generator |
| ECB | Electronic Codebook |
| ECC | Elliptic Curve Cryptography |
| ECDH | Elliptic Curve Diffie-Hellman |
| ECDSA | Elliptic Curve Digital Signature Algorithm |
| FFC | Finite Field Cryptography |
| FIPS | Federal Information Processing Standards |
| GCM | Galois Counter Mode |
| GMAC | Galois Message Authentication Code |
| HMAC | (keyed)-Hashed Message Authentication Code |
| IEC | International Electrotechnical Commission |
| IG | Implementation Guidance |
| IKE | Internet Key Exchange |
| IPsec | IP Security |
| ISO | International Organization of Standardization |
| KAS | Key Agreement Scheme |
| KAT | Known Answer Test |
| KDF | Key Derivation Function |
| N/A | Not Applicable |
| NIST | National Institute of Standards and Technology |
| OS | Operating System |
| PCT | Pairwise Consistency Test |
| PSP | Public Security Parameter |
| PUB | Publication |
| RFC | Request for Comment |
| RSA | Rivest, Shamir, and Adleman |
| SHA | Secure Hash Algorithm |
| SHS | Secure Hash Standard |
| SSC | Shared Secret Computation |
| SSH | Secure Shell |
| SNMP | Simple Network Transfer Protocol |
| SP | Special |
Appendix A – Acronyms and Terms Table 12 below provides a list of acronyms and terms used throughout this Security Policy. Table 12 - Acronyms and Terms © Cisco Systems, Inc. 22
| Term/Acronym | Definition |
|---|---|
| SRTP | Secure Real-time Protocol |
| SSP | Sensitive Security Parameters |
| TLS | Transport Layer Security |
| TOEPP | Tested Operational Environment’s Physical Perimeter |