All modules
CMVP Validated Module · FIPS 140-3 Security Policy

AWS-LC Cryptographic Module (dynamic)

Certificate#4759StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorAmazon Web Services Inc.
Medium review priority  ·  no TCB surface named  ·  last validated 23 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date8/13/2029
CaveatInterim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys)
VendorAmazon Web Services Inc.

Approved Algorithms (287)

AlgorithmACVP Cert
AES-CBCA4484
AES-CBCA4487
AES-CBCA4489
AES-CBCA4493
AES-CBCA4497
AES-CBCA4501
AES-CCMA4484
AES-CCMA4487
AES-CCMA4489
AES-CCMA4492
AES-CCMA4497
AES-CCMA4501
AES-CMACA4484
AES-CMACA4487
AES-CMACA4489
AES-CMACA4493
AES-CMACA4497
AES-CMACA4501
AES-CTRA4484
AES-CTRA4487
AES-CTRA4489
AES-CTRA4493
AES-CTRA4497
AES-CTRA4501
AES-ECBA4484
AES-ECBA4485
AES-ECBA4486
AES-ECBA4487
AES-ECBA4488
AES-ECBA4489
AES-ECBA4490
AES-ECBA4493
AES-ECBA4494
AES-ECBA4495
AES-ECBA4496
AES-ECBA4497
AES-ECBA4498
AES-ECBA4499
AES-ECBA4500
AES-ECBA4501
AES-ECBA4502
AES-ECBA4503
AES-ECBA4504
AES-GCMA4485
AES-GCMA4485
AES-GCMA4486
AES-GCMA4486
AES-GCMA4488
AES-GCMA4488
AES-GCMA4490
AES-GCMA4490
AES-GCMA4494
AES-GCMA4494
AES-GCMA4495
AES-GCMA4495
AES-GCMA4496
AES-GCMA4496
AES-GCMA4498
AES-GCMA4498
AES-GCMA4499
AES-GCMA4499
AES-GCMA4500
AES-GCMA4500
AES-GCMA4502
AES-GCMA4502
AES-GCMA4503
AES-GCMA4503
AES-GCMA4504
AES-GCMA4504
AES-GMACA4485
AES-GMACA4486
AES-GMACA4488
AES-GMACA4490
AES-GMACA4494
AES-GMACA4495
AES-GMACA4496
AES-GMACA4498
AES-GMACA4499
AES-GMACA4500
AES-GMACA4502
AES-GMACA4503
AES-GMACA4504
AES-KWA4484
AES-KWA4487
AES-KWA4489
AES-KWA4493
AES-KWA4497
AES-KWA4501
AES-KWPA4484
AES-KWPA4487
AES-KWPA4489
AES-KWPA4493
AES-KWPA4497
AES-KWPA4501
AES-XTS Testing Revision 2.0A4484
AES-XTS Testing Revision 2.0A4487
AES-XTS Testing Revision 2.0A4489
AES-XTS Testing Revision 2.0A4493
AES-XTS Testing Revision 2.0A4497
AES-XTS Testing Revision 2.0A4501
Counter DRBGA4484
Counter DRBGA4487
Counter DRBGA4489
Counter DRBGA4493
Counter DRBGA4497
Counter DRBGA4501
ECDSA KeyGen (FIPS186-5)A4483
ECDSA KeyGen (FIPS186-5)A4491
ECDSA KeyGen (FIPS186-5)A4492
ECDSA KeyGen (FIPS186-5)A4505
ECDSA KeyGen (FIPS186-5)A4506
ECDSA KeyGen (FIPS186-5)A4507
ECDSA KeyGen (FIPS186-5)A4508
ECDSA KeyVer (FIPS186-5)A4483
ECDSA KeyVer (FIPS186-5)A4491
ECDSA KeyVer (FIPS186-5)A4492
ECDSA KeyVer (FIPS186-5)A4505
ECDSA KeyVer (FIPS186-5)A4506
ECDSA KeyVer (FIPS186-5)A4507
ECDSA KeyVer (FIPS186-5)A4508
ECDSA SigGen (FIPS186-5)A4483
ECDSA SigGen (FIPS186-5)A4491
ECDSA SigGen (FIPS186-5)A4492
ECDSA SigGen (FIPS186-5)A4505
ECDSA SigGen (FIPS186-5)A4506
ECDSA SigGen (FIPS186-5)A4507
ECDSA SigGen (FIPS186-5)A4508
ECDSA SigVer (FIPS186-4)A4483
ECDSA SigVer (FIPS186-4)A4491
ECDSA SigVer (FIPS186-4)A4492
ECDSA SigVer (FIPS186-4)A4505
ECDSA SigVer (FIPS186-4)A4506
ECDSA SigVer (FIPS186-4)A4507
ECDSA SigVer (FIPS186-4)A4508
ECDSA SigVer (FIPS186-5)A4483
ECDSA SigVer (FIPS186-5)A4491
ECDSA SigVer (FIPS186-5)A4492
ECDSA SigVer (FIPS186-5)A4505
ECDSA SigVer (FIPS186-5)A4506
ECDSA SigVer (FIPS186-5)A4507
ECDSA SigVer (FIPS186-5)A4508
HMAC-SHA-1A4483
HMAC-SHA-1A4491
HMAC-SHA-1A4492
HMAC-SHA-1A4505
HMAC-SHA-1A4506
HMAC-SHA-1A4507
HMAC-SHA-1A4508
HMAC-SHA2-224A4483
HMAC-SHA2-224A4491
HMAC-SHA2-224A4492
HMAC-SHA2-224A4505
HMAC-SHA2-224A4506
HMAC-SHA2-224A4507
HMAC-SHA2-224A4508
HMAC-SHA2-256A4483
HMAC-SHA2-256A4491
HMAC-SHA2-256A4492
HMAC-SHA2-256A4505
HMAC-SHA2-256A4506
HMAC-SHA2-256A4507
HMAC-SHA2-256A4508
HMAC-SHA2-384A4483
HMAC-SHA2-384A4491
HMAC-SHA2-384A4492
HMAC-SHA2-384A4505
HMAC-SHA2-384A4506
HMAC-SHA2-384A4507
HMAC-SHA2-384A4508
HMAC-SHA2-512A4483
HMAC-SHA2-512A4491
HMAC-SHA2-512A4492
HMAC-SHA2-512A4505
HMAC-SHA2-512A4506
HMAC-SHA2-512A4507
HMAC-SHA2-512A4508
HMAC-SHA2-512/256A4483
HMAC-SHA2-512/256A4491
HMAC-SHA2-512/256A4492
HMAC-SHA2-512/256A4505
HMAC-SHA2-512/256A4506
HMAC-SHA2-512/256A4507
HMAC-SHA2-512/256A4508
KAS-ECC-SSC Sp800-56Ar3A4483
KAS-ECC-SSC Sp800-56Ar3A4491
KAS-ECC-SSC Sp800-56Ar3A4492
KAS-ECC-SSC Sp800-56Ar3A4505
KAS-ECC-SSC Sp800-56Ar3A4506
KAS-ECC-SSC Sp800-56Ar3A4507
KAS-ECC-SSC Sp800-56Ar3A4508
KDA HKDF Sp800-56Cr1A4483
KDA HKDF Sp800-56Cr1A4491
KDA HKDF Sp800-56Cr1A4492
KDA HKDF Sp800-56Cr1A4505
KDA HKDF Sp800-56Cr1A4506
KDA HKDF Sp800-56Cr1A4507
KDA HKDF Sp800-56Cr1A4508
KDF SSHA4483
KDF SSHA4491
KDF SSHA4492
KDF SSHA4505
KDF SSHA4506
KDF SSHA4507
KDF SSHA4508
KDF TLSA4483
KDF TLSA4491
KDF TLSA4492
KDF TLSA4505
KDF TLSA4506
KDF TLSA4507
KDF TLSA4508
PBKDFA4483
PBKDFA4491
PBKDFA4492
PBKDFA4505
PBKDFA4506
PBKDFA4507
PBKDFA4508
RSA KeyGen (FIPS186-5)A4483
RSA KeyGen (FIPS186-5)A4491
RSA KeyGen (FIPS186-5)A4492
RSA KeyGen (FIPS186-5)A4505
RSA KeyGen (FIPS186-5)A4506
RSA KeyGen (FIPS186-5)A4507
RSA KeyGen (FIPS186-5)A4508
RSA SigGen (FIPS186-5)A4483
RSA SigGen (FIPS186-5)A4491
RSA SigGen (FIPS186-5)A4492
RSA SigGen (FIPS186-5)A4505
RSA SigGen (FIPS186-5)A4506
RSA SigGen (FIPS186-5)A4507
RSA SigGen (FIPS186-5)A4508
RSA SigVer (FIPS186-4)A4483
RSA SigVer (FIPS186-4)A4491
RSA SigVer (FIPS186-4)A4492
RSA SigVer (FIPS186-4)A4505
RSA SigVer (FIPS186-4)A4506
RSA SigVer (FIPS186-4)A4507
RSA SigVer (FIPS186-5)A4483
RSA SigVer (FIPS186-5)A4491
RSA SigVer (FIPS186-5)A4492
RSA SigVer (FIPS186-5)A4505
RSA SigVer (FIPS186-5)A4506
RSA SigVer (FIPS186-5)A4507
RSA SigVer (FIPS186-5)A4508
SHA-1A4483
SHA-1A4491
SHA-1A4492
SHA-1A4505
SHA-1A4506
SHA-1A4507
SHA-1A4508
SHA2-224A4483
SHA2-224A4491
SHA2-224A4492
SHA2-224A4505
SHA2-224A4506
SHA2-224A4507
SHA2-224A4508
SHA2-256A4483
SHA2-256A4491
SHA2-256A4492
SHA2-256A4505
SHA2-256A4506
SHA2-256A4507
SHA2-256A4508
SHA2-384A4483
SHA2-384A4491
SHA2-384A4492
SHA2-384A4505
SHA2-384A4506
SHA2-384A4507
SHA2-384A4508
SHA2-512A4483
SHA2-512A4491
SHA2-512A4492
SHA2-512A4505
SHA2-512A4506
SHA2-512A4507
SHA2-512A4508
SHA2-512/256A4483
SHA2-512/256A4491
SHA2-512/256A4492
SHA2-512/256A4505
SHA2-512/256A4506
SHA2-512/256A4507
SHA2-512/256A4508

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for AWS-LC Cryptographic Module (dynamic)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery<br/>upgrade</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show Status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for AWS-LC Cryptographic Module (dynamic)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery<br/>upgrade</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show Status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

AWS-LC Cryptographic Module (dynamic) Module Version: AWS-LC FIPS 2.0.0 Document version: 1.0 Last update: 2024-08-13 Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 www.atsec.com © 2024 Amazon Web Services, Inc., atsec information security.

Page 2
1 Table of Contents

© 2024 Amazon Web Services, Inc., atsec information security.

2 of 44

Page 3

© 2024 Amazon Web Services, Inc., atsec information security.

3 of 44

Page 4
2 List of Tables

© 2024 Amazon Web Services, Inc., atsec information security.

4 of 44

Page 5
3 List of Figures

© 2024 Amazon Web Services, Inc., atsec information security.

5 of 44

Page 6

Amazon is a registered trademark of Amazon Web Services, Inc. or its affiliates. © 2024 Amazon Web Services, Inc., atsec information security.

6 of 44

Page 7
ISO/IEC 24759 Section 6. SubsectionsFIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical SecurityN/A
8Non-invasive SecurityN/A
9Sensitive Security Parameter Management1
10Self-tests1
11Life-cycle Assurance1
12Mitigation of Other Attacks1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version AWS-LC FIPS 2.0.0 of the AWS-LC Cryptographic Module (dynamic). It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security

1.2 Security Levels

Table 1 describes the individual security areas of FIPS 140-3, as well as the security levels of those individual areas. Table 1: Security Levels

1.3 Additional Information

This Security Policy describes the features and design of the module named AWS-LC Cryptographic Module (dynamic) using the terminology contained in the FIPS 140-3 specification. The FIPS 140-3 Security Requirements for Cryptographic Module specifies the security requirements that will be satisfied by a cryptographic module utilized within a security system protecting sensitive but unclassified information. The NIST/CCCS Cryptographic Module Validation Program (CMVP) validates cryptographic module to FIPS 140-3. Validated products are accepted by the Federal agencies of both the USA and Canada for the protection of sensitive or designated information. and including this notice. Other documentation is proprietary to their authors. © 2024 Amazon Web Services, Inc., atsec information security.

7 of 44

Page 8

was further consolidated into this document by atsec information security together with other vendor-supplied documentation. In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. © 2024 Amazon Web Services, Inc., atsec information security.

8 of 44

Page 9
Package/File NamesSoftware/ Firmware VersionIntegrity Test Implemented
bcm.oAWS-LC FIPS 2.0.0HMAC-SHA2-256
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The AWS-LC Cryptographic Module (dynamic) (hereafter referred to as “the module”) provides cryptographic services to applications running in the user space of the underlying operating system through a C language Application Program Interface (API). Module Type: Software Module Embodiment: Multi-chip standalone Module Characteristics: N/A Cryptographic Boundary: The block diagram in Figure 1 shows the cryptographic boundary of the module, its interfaces with the operational environment and the flow of information between the module and operator (depicted through the arrows). The module components consist of the bcm.o (AWS-LC FIPS 2.0.0), which is dynamically linked to the userspace application during the compilation process. Figure 1: Block diagram

2.2 Operating Environments

Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): Table 2: Tested Module Identification © 2024 Amazon Web Services, Inc., atsec information security.

9 of 44

Page 10
Operating SystemHardware PlatformProcessor(s)PAA/PAIHypervisor or Host OSVersion(s)
Amazon Linux 2 Amazon Linux 2023 Ubuntu 22.04Amazon EC2 c5.metal with 192 GiB system memory and Elastic Block Store (EBS) 200 GiBIntel ®Xeon ® Platinum 8275CLAES-NI and SHA extensions (PAA)N/AAWS-LC FIPS 2.0.0
Amazon Linux 2 Amazon Linux 2023 Ubuntu 22.04Amazon EC2 c5.metal with 192 GiB system memory and Elastic Block Store (EBS) 200 GiBIntel ®Xeon ® Platinum 8275CLNone
Amazon Linux 2 Amazon Linux 2023 Ubuntu 22.04Amazon EC2 c7g.metal with 128 GiB system memory and Elastic Block Store (EBS) 200 GiBGraviton3Neon and Crypto Extension (CE) (PAA)AWS-LC FIPS 2.0.0
Amazon Linux 2 Amazon Linux 2023 Ubuntu 22.04Amazon EC2 c7g.metal with 128 GiB system memory and Elastic Block Store (EBS) 200 GiBGraviton3None
NameDescriptionTypeStatus Indicator
Approved ModeAutomatically entered whenever an approved service is requested.ApprovedEquivalent to the indicator of the requested service.
Non-approved ModeAutomatically entered whenever a non- approved service is requested.Non-ApprovedEquivalent to the indicator of the requested service.

Tested Operational Environments - Software, Firmware, Hybrid: Table 3: Tested Operational Environments

2.3 Excluded Components

The module does not claim any excluded components.

2.4 Modes of Operation of the Module

Table 4: Modes of Operation of the Module Mode change instructions and status indicators: When the module starts up successfully, after passing a set of cryptographic algorithms self-tests (CASTs) and the pre-operational self-test, the module is operating in the approved mode of operation by default and can only be transitioned into the non-approved mode by calling one of the non-approved services listed in Table 15. The module will transition back to approved mode when approved service is called. Section 4 provides details on the service indicator implemented by the module. The service indicator identifies when an approved service is called. The module does not implement a degraded mode of operation. © 2024 Amazon Web Services, Inc., atsec information security.

10 of 44

Page 11
Algorithm NameCAVP Cert NumbersAlgorithm CapabilitiesOE (Implementation)Reference
AES-CBCA4489, A4493,Encryption,Amazon Linux 2023 on EC2 bare metal on AmazonFIPS 197,
A4501, A4484,Decryption usingGraviton3: AES_C, CE, VPAESSP800-38A
A4487, A44971 28,192,256 bits keyUbuntu on EC2 bare metal on Amazon Graviton3 AWS Graviton: AES_C, CE, VPAES Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM
AES-CCMA4489, A4493,AuthenticatedAmazon Linux 2023 on EC2 bare metal on AmazonFIPS 197,
A4501, A4484,Encryption,Graviton3: AES_C, BAES_CTASM, CE, VPAESSP800-38C, IG
A4487, A4497AuthenticatedUbuntu on EC2 bare metal on Amazon Graviton3D.G
Decryption, Key Wrapping, KeyAWS Graviton: AES_C, BAES_CTASM, CE, VPAES
Unwrapping using 128 bit keyAmazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM
AES-CMACA4489, A4493,MessageAmazon Linux 2023 on EC2 bare metal on AmazonFIPS 197,
A4501, A4487,AuthenticationGraviton3: AES_C, BAES_CTASM, CE, VPAESSP800-38B
A4497Generation 128- orUbuntu on EC2 bare metal on Amazon Graviton3
256-bits keyAWS Graviton: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM
2.5 Algorithms

Approved Algorithms: © 2024 Amazon Web Services, Inc., atsec information security.

11 of 44

Page 12
Algorithm NameCAVP Cert NumbersAlgorithm CapabilitiesOE (Implementation)Reference
AES-CTRA4489, A4493,Encryption,Amazon Linux 2023 on EC2 bare metal on AmazonFIPS 197, SP
A4501, A4484,DecryptionGraviton3: AES_C, BAES_CTASM, CE, VPAES800-38A
A4487, A44971 2 8 ,192,256 bits keyUbuntu on EC2 bare metal on Amazon Graviton3 AWS Graviton: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM
AES-ECBA4489, A4490,Encryption,Amazon Linux 2023 on EC2 bare metal on AmazonFIPS 197, SP
A4493, A4494,Decryption using 128,Graviton3: AES_C, AES_C_GCM, CE,800-38A
A4496, A4501,192, 256 bits keyCE_GCM_UNROLL8_EOR3, CE_GCM, VPAES, VPAES_GCM
A4502, A4503,Ubuntu on EC2 bare metal on Amazon Graviton3
A4504, A4484,AWS Graviton: AES_C, AES_C_GCM, CE,
A4485, A4486, A4487, A4488,CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES, VPAES_GCM Amazon Linux 2 on EC2 bare metal on Amazon
A4495, A4497,Graviton3: AES_C, AES_C_GCM, CE,
A4498, A4499, A4500CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES VPAES_GCM Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESNI_AVX, AESNI_ASM, AESASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESNI_AVX, AESNI_ASM, AESASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESNI_AVX, AESNI_ASM, AESASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM
AES-GCMA4490, A4494,AuthenticatedAmazon Linux 2023 on EC2 bare metal on AmazonFIPS 197,
A4496, A4502,Encryption (withGraviton3: AES_C, AES_C_GCM, CE_GCM_UNROLL8_EOR3,SP800-38D, IG
A4503, A4504,Internal IV ModeCE_GCM, VPAES_GCMD.G
A4485, A4486, A4488, A4495,8.2.2) and Key Wrapping using 128Ubuntu on EC2 bare metal on Amazon Graviton3 AWS Graviton: AES_C, AES_C_GCM,
A4498, A4499, A4500or 256 bits keyCE_GCM_UNROLL8_EOR3, CE_GCM, VPAES_GCM Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, AES_C_GCM, CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES_GCM
AES-GCMAuthenticatedFIPS 197,
Decryption (withAmazon Linux 2 on EC2 bare metal on Intel CascadeSP800-38D, IG
external IV) and Key Unwrapping using 128- or 256-bits keyLake Xeon Platinum 8275CL: ASENI_AVX, AESNI_ASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM,D.G

© 2024 Amazon Web Services, Inc., atsec information security.

12 of 44

Page 13
Algorithm Name AES-GMACCAVP Cert NumbersAlgorithm Capabilities Message Authentication Generation using 128- or 256-bits keyOE (Implementation) AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: ASENI_AVX, AESNI_ASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: ASENI_AVX, AESNI_ASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASMReference FIPS 197, SP800-38D
AES-KWA4489, A4493,Key Wrapping, KeyAmazon Linux 2023 on EC2 bare metal on AmazonFIPS 197, SP800-
A4501, A4484,Unwrapping usingGraviton3: AES_C, BAES_CTASM, CE, VPAES38F, IG D.G
AES-KWPA4487, A44971 28, 192, 256 bits keyUbuntu on EC2 bare metal on Amazon Graviton3 AWS Graviton: AES_C, BAES_CTASM, CE, VPAES
AES-XTSEncryption,FIPS 197, SP
Decryption using 256Amazon Linux 2 on EC2 bare metal on Amazon800-38E
bits keyGraviton3: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM
CTR_DRBGA4489, A4493,Random NumberAmazon Linux 2023 on EC2 bare metal on AmazonSP800-90Arev1
A4501, A4484,Generation using AESGraviton3: AES_C, CE, VPAES
A4487, A44972 5 6 bits withoutUbuntu on EC2 bare metal on Amazon Graviton3
derivation function or prediction resistance.AWS Graviton: AES_C, CE, VPAES Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM
ECDSAA4483, A4491,Key Generation usingAmazon Linux 2023 on EC2 bare metal on AmazonFIPS 186-5
A4492, A4505,P-224, P-256, P-384,Graviton3: SHA_ASM, SHA_CE, NEONA.2.2 FIPS 186-
A4506, A4507,P-521Ubuntu on EC2 bare metal on Amazon Graviton35 Rejection
A4508AWS Graviton: SHA_ASM, SHA_CE, NEONSampling; SP800-133rev2
Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: SHA_ASM, SHA_CE, NEON Amazon Linux 2 on EC2 bare metal on Intel Cascadesections 4, 5.1, 5.2
Key Verification usingLake Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2,FIPS 186-5 for
P-224, P-256, P-384,SHA_AVX, SHA_SSSE3all except FIPS
P-521Amazon Linux 2023 on EC2 bare metal on Intel186-4 for
Cascade Lake Xeon Platinum 8275CL: SHA_SHANI,signature
ECDSA withSignature GenerationSHA_AVX2, SHA_AVX, SHA_SSSE3verification with
SHA2-224,using P-224, P-256, P-SHA-1
SHA2-256,384, P-521Ubuntu on EC2 bare metal on Intel Cascade Lake
SHA2-384,Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2,
SHA2-512SHA_AVX, SHA_SSSE3
5.2 © 2024 Amazon Web Services, Inc., atsec information security.

13 of 44

Page 14
Algorithm Name ECDSA with SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2-512CAVP Cert NumbersAlgorithm Capabilities Signature Verification using P-224, P-256, P- 384, P-521OE (Implementation)Reference
HMAC-SHA-1,A4483, A4491,MessageAmazon Linux 2023 on EC2 bare metal on AmazonFIPS 198-1
HMAC-SHA2-A4492, A4505,AuthenticationGraviton3: SHA_ASM, SHA_CE, NEON
224,A4506, A4507,Generation using 112-Ubuntu on EC2 bare metal on Amazon Graviton3
HMAC-SHA2- 256,A4508524288 bits keyAWS Graviton: SHA_ASM, SHA_CE, NEON
HMAC-SHA2- 384,Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: SHA_ASM, SHA_CE, NEON
HMAC-SHA2-Amazon Linux 2 on EC2 bare metal on Intel Cascade
512,Lake Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2,
HMAC-SHA2-SHA_AVX, SHA_SSSE3
512/256Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: SHA_SHANI,
KAS-ECC-SSCA4483, A4491,Shared SecretSHA_AVX2, SHA_AVX, SHA_SSSE3SP800-56ARev3,
ECC EphemeralA4492, A4505,Computation using P-IG D.F scenario
Unified schemeA4506, A4507,224, P-256, P-384, P-Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2,2(1)
A4508521SHA_AVX, SHA_SSSE3
KDA HKDF withA4483, A4491,Key DerivationSP800-56Crev1;
HMAC-SHA-1,A4492, A4505,SP800-133rev2
HMAC-SHA2-A4506, A4507,Derived Key Length:section 6.2
224, HMAC- SHA-256,A45082048
HMAC-SHA2- 384, HMAC- SHA2-512Shared Secret Length: 224-2048 Increment 8
KDF TLS (CVL)A4483, A4491,Key DerivationSP800-135rev1;
TLS 1.0/1.1,A4492, A4505,SP800-133rev2
TLS 1.2 (RFCA4506, A4507,section 6.2
7627) with SHA2-256, SHA2-384, SHA2-512A4508
PBKDF withA4483, A4491,Password based keyAmazon Linux 2023 on EC2 bare metal on AmazonSP800-132
HMAC-SHA-1,A4492, A4505,derivation:Graviton3: SHA_ASM, SHA_CE, NEONOption 1a;
HMAC-SHA2-A4506, A4507,Iteration Count: 1000-Ubuntu on EC2 bare metal on Amazon Graviton3SP800-133rev2
224, HMAC-A450810000 Increment 1AWS Graviton: SHA_ASM, SHA_CE, NEONsection 6.2
SHA2-256,Password Length: 14-
HMAC-SHA2-128 Increment 1Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: SHA_ASM, SHA_CE, NEON
384, HMAC-Salt Length: 128-4096
SHA2-512Increment 8 Key Data Length: 128-4096 Increment 8Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 Amazon Linux 2023 on EC2 bare metal on Intel
RSAA4483, A4491,Key Generation usingCascade Lake Xeon Platinum 8275CL: SHA_SHANI,FIPS 186-5
A4492, A4505,2048,3072, 4096 bitsSHA_AVX2, SHA_AVX, SHA_SSSE3A.1.3 Random
A4506, A4507,keyUbuntu on EC2 bare metal on Intel Cascade LakeProbable
A4508Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3Primes; SP800- 133rev2 sections 4, 5.1

© 2024 Amazon Web Services, Inc., atsec information security.

14 of 44

Page 15

Algorithm Name RSA PKCS#1v1.5 with SHA2-224, SHA2-256, SHA2-384, SHA2-512 RSA PSS with SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256 RSA PKCS#1v1.5 with SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512; RSA PSS with SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256 SSH KDF (CVL) with AES-128, AES-192, AES- 256; SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256

CAVP Cert Numbers A4483, A4491, A4492, A4505, A4506, A4507, A4508 A4483, A4491, A4492, A4505, A4506, A4507, A4508

Algorithm Capabilities Signature Generation using 2048,3072, 4096 bits key Signature Verification using 1024, 2048, 3072, 4096 bits key. Key Derivation Message Digest

OE (Implementation)

Reference FIPS 186-5 except FIPS 186-4 for use of SHA-1 and 1024 bit key SP800-135rev1; SP800-133rev2 section 6.2 FIPS 180-4

Algorithm NameAlgorithm CapabilitiesOE (Implementation)References
CKG (ECDSA KeyGen)ECDSA KeyGen (FIPS 186-5): P- 224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strengthSoftware; OE same as in Table 3FIPS 186-5, A.2.2 Rejection Sampling; SP 800-133Rev2 section 4 and IG D.H comment 2 (without any V, as described in Additional Comments 2 of IG D.H)
CKG (RSA KeyGen)RSA KeyGen (FIPS 186-5): 2048, 3072, 4096 bits with 112, 128, 149 bits of key strength.FIPS 186-5, A.1.3 Random Probable Primes; SP 800- 133Rev2 section 4 and IG D.H comment 2 (without any V, as described in Additional Comments 2 of IG D.H)

Table 5: Approved Algorithms Vendor-Affirmed Algorithms: Table 6: Vendor Affirmed Algorithms © 2024 Amazon Web Services, Inc., atsec information security.

15 of 44

Page 16
AlgorithmCaveatUse/Function
MD5Allowed per IG 2.4.AMessage Digest used in TLS 1.0/1.1 KDF only
Algorithm/FunctionsUse/Function
AES with OFB or CFB1, CFB8 modesEncryption, Decryption
AES GCM, GCM, GMAC, XTS with keys not listed in Table 5Encryption, Decryption
AES using aes_*_generic functionEncryption, Decryption
AES GMAC using aes_*_genericMessage Authentication Generation
Curve secp256k1Signature Generation, Signature Verification, Shared Secret Computation
Diffie HellmanShared Secret Computation
HMAC-MD4, HMAC-MD5, HMAC-SHA1, HMAC-SHA-3, HMAC- RIPEMD-160Message Authentication Generation
MD4Message Digest
MD5Message Digest (outside of TLS)
RSA using RSA_generate_key_exKey Generation
ECDSA using EC_KEY_generate_keyKey Generation
RSA using keys less than 2048 bitsSignature Generation
RSA using keys less than 1024 bitsSignature Verification
RSAKey Encapsulation/Un-encapsulation, sign/verify primitive operations without hashing
RSA with PKCS#1 v1.5 and OAEP paddingEncryption primitive
SHA-1, SHA-3Signature Generation
SHAKE, RIPEMD-160, SHA-3Message Digest
TLS KDF using any SHA algorithms not listed in Table 5 or TLS KDF using non extended master secretKey Derivation
NameTypeDescriptionSF CapabilitiesAlgorithms
KAS-ECC-SSCKASSP800-56Ar3. KAS-ECC-SSC per IG D.F 2 path (1)Ephemeral Unified scheme Curves: P-224, P-256, P-384, P-521 elliptic curves with 112-256 bits of strengthKAS-ECC-SSC: A4483, A4491, A4492, A4505, A4506, A4507, A4508
AES KW, AES-KWPKTSSP 800-38F. KTS (Key Wrapping, Key Unwrapping) per IG D.G128, 192, 256 bits with 128-256 bits of key strengthAES: A4489, A4493, A4501, A4484, A4487, A4497

The module does not implement non-approved algorithms that are allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: Table 7: Non-Approved Allowed Algorithms with No Security Claimed

2.6 Security Function Implementation

© 2024 Amazon Web Services, Inc., atsec information security.

16 of 44

Page 17
AES GCM [SP 800- 38D]KTSSP800-38D. KTS (Key Wrapping, Key Unwrapping) per IG D.G128, 256 bits with 128 and 256 bits of key strengthAES: A4490, A4494, A4496, A4502, A4503, A4504, A4485, A4486, A4488, A4495, A4498, A4499, A4500
AES CCM [SP 800- 38C]KTSSP 800-38C. KTS (Key Wrapping, Key Unwrapping) per IG D.G128 bits with 128 bits of key strengthAES: A4489, A4493, A4501, A4484, A4487, A4497

Table 9: Security Function Implementation

2.7 Algorithm Specific Information
2.7.1 GCM IV

The module offers three AES GCM implementations. The GCM IV generation for these implementations complies respectively with IG C.H under Scenario 1, Scenario 2, and Scenario 5. The GCM shall only be used in the context of the AES-GCM encryption executing under each scenario, and using the referenced APIs explained next. Scenario 1, TLS 1.2 For TLS 1.2, the module offers the GCM implementation via the functions EVP_aead_aes_128_gcm_tls12() and EVP_aead_aes_256_gcm_tls12(), and uses the context of Scenario 1 of IG C.H. The module is compliant with SP800-52rev2 and the mechanism for IV generation is compliant with RFC5288. The module supports acceptable AES-GCM ciphersuites from Section 3.3.1 of SP800-52rev2. The module explicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values of 2^{64-1} for a given session key. If this exhaustion condition is observed, the module returns an error indication to the calling application, which will then need to either abort the connection, or trigger a handshake to establish a new encryption In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established. Scenario 2, Random IV In this implementation, the module offers the interfaces EVP_aead_aes_128_gcm_randnonce() and Section 8.2.2. The AES-GCM IV is generated randomly internal to the module using module’s approved DRGB. The DRBG receives a LOAD command with entropy obtained from inside the physical perimeter of the operational environment but outside of module's cryptographic boundary. The GCM IV is 96 bits in length and is expected to have 96 bits of entropy. Scenario 5, TLS 1.3 For TLS 1.3, the module offers the AES-GCM implementation via the functions EVP_aead_aes_128_gcm_tls13() and EVP_aead_aes_256_gcm_tls13(), and uses the context of Scenario 5 of IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the ciphersuites that explicitly select AES-GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES-GCM ciphersuites from Section 3.3.1 of SP800-52rev2. The module implements, within its boundary, an IV generation unit for TLS 1.3 that keeps control of the 64-bit counter value within the AES-GCM IV. If the exhaustion condition is observed, the module will return an error indication to the calling application, who will then need to either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection. © 2024 Amazon Web Services, Inc., atsec information security.

17 of 44

Page 18

In the event the module’s power is lost and restored, the consuming application must ensure that new AES-GCM keys encryption or decryption under this scenario are established. TLS 1.3 provides session resumption, but the resumption procedure derives new AES-GCM encryption keys.

2.7.2 AES XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 2 20 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 80038E. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical.

2.7.3 Key Derivation using SP 800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:

2.7.4 Compliance to SP 800-56ARev3 assurances

The module offers ECDH shared secret computation services compliant to the SP 800-56ARev3 and meeting IG D.F scenario 2 path (1). To meet the required assurances listed in section 5.6 of SP 800-56ARev3, the module shall be used together with an application that implements the “TLS protocol” and the following steps shall be performed.

18 of 44

Page 19
NameTypeProperties
ECDSACKGEC: P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength Method: FIPS 186-5 A.2.2 Rejection Sampling using a DRBG compliant with SP800-90Arev1, per SP800-133Rev2 section 4 (without any V, as described in Additional Comments 2 of IG D.H) and SP800-133Rev2 section 5.1 and 5.2
RSACKGRSA: 2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. Method: FIPS 186-5 A.1.3 Random Probable Primes using a DRBG compliant with SP800- 90Arev1, per SP800-133Rev2 section 4 (without any V, as described in Additional Comments 2 of IG D.H) and SP800-133Rev2 section 5.1
KDA HKDFKey DerivationKey type: Symmetric key; Security strength: 112-256 bits Method: SP 800-56Cr1; (HMAC) SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 per SP800-133Rev2 section 6.2
PBKDFKey DerivationKey type: Symmetric key; Security strength: 112-256 bits Method: option 1a of SP 800-132; (HMAC) SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 per SP800-133Rev2 section 6.2
SSH KDF (CVL)Key DerivationKey type: Symmetric key; Security strength: 112-256 bits Method: SP 800-135r1; AES-128, AES-192, AES-256 with SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512 per SP800-133Rev2 section 6.2
KDF TLS (CVL) TLS 1.0/1.1, TLS 1.2Key DerivationKey type: Symmetric key; Security strength: 112-256 bits Method: SP 800-135r1; MD5 (TLS 1.0/1.1 only), SHA2-256, SHA2-384, SHA2-512 per SP800-133Rev2 section 6.2
2.7.5 Approved Modulus Sizes for RSA Digital Signature

Following IG C.F, RSA SigGen (FIPS 186-5) and RSA SigVer (FIPS 186-4 and FIPS 186-5) have been CAVP tested with all supported approved RSA modulus lengths (i.e., 1024 (SigVer only), 2048, 3072, 4096). This is documented in the Approved Algorithms table. There are no modulus sizes available in approved services which have not been CAVP tested. The minimum number of the Miller-Rabin tests used in primality testing is consistent with Table B.1 in FIPS 186-5.

2.7.6 Legacy Algorithms

The cryptographic module implements the following cryptographic algorithms for legacy use: • RSA SigVer (FIPS 186-4) with 1024-bit keys.

2.8 RNG and Entropy

The module provides an SP800-90Arev1-compliant Deterministic Random Bit Generator (DRBG) components of asymmetric keys, and random number generation. The DRBG receives a LOAD command with entropy obtained from inside the physical perimeter of the operational environment but outside of module's cryptographic boundary. This corresponds to scenario 2 (b) of IG 9.3.A. The calling application shall use an entropy source that meets the security strength required for the CTR_DRBG as shown in NIST SP 800-90Arev1, Table 3 and should return an error if minimum strength cannot be met. Per the IG 9.3.A requirement, the module includes the caveat "No assurance of the minimum strength of generated keys".

2.9 Key Generation

© 2024 Amazon Web Services, Inc., atsec information security.

19 of 44

Page 20

(RFC 7627)

NameTypeProperties
KAS-ECC-SSC [SP800-56Arev3]KAS (Shared Secret Computation)Curves: P-224, P-256, P-384, P-521 elliptic curves with 112-256 bits of key strength Compliant with IG D.F scenario 2(1)
AES GCM [SP 800-38D]KTS (Key wrapping, Key unwrapping)128 and 256 bits with 128 and 256 bits of key strength Compliant with IG D.G
AES CCM [SP 800-38C]128 bits with 128 bits of key strength Compliant with IG D.G
AES KW, AES KWP [SP 800-38F]128, 192, 256 bits with 128-256 bits of key strength Compliant with IG D.G
2.10 Key Establishment
2.11 Industry Protocols

The module implements the SSH key derivation function for use in the SSH protocol (RFC 4253 and RFC 6668). GCM with internal IV generation in the approved mode is compliant with versions 1.2 and 1.3 of the TLS protocol (RFC 5288 and 8446) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the following key derivation functions for use in the TLS protocol:

20 of 44

Page 21
Logical InterfaceData that passes over port/interface
Data InputAPI input parameters for data.
Data OutputAPI output parameters for data.
Control InputAPI function calls.
Status OutputAPI return codes, error message.
3 Cryptographic Module Interfaces

As a Software module, the module interfaces are defined as Software or Firmware Module Interfaces (SMFI), and there are no physical ports. Table 12: Ports and Interfaces 1

1 The control output interface is omitted on purpose because the module does not implement it. The physical ports are not

applicable because the module is software only. © 2024 Amazon Web Services, Inc., atsec information security.

21 of 44

Page 22
NameTypeOperator TypeAuthentication
Crypto OfficerRoleCON/A (Implicitly assumed)
NameDescriptionIndicatorInputsOutputsSecurity FunctionsRolesSSP Access
EncryptionEncryptionReturn value 1 from the function: FIPS_ service_ indicator_ check_appr oved()AES key, plaintextCiphertextAES-CBC, AES- CTR, AES-ECB, AES-XTS listed in Table 5COAES Key: W, E
DecryptionDecryptionAES key, ciphertextPlaintext
Authenticated EncryptionAuthenticated EncryptionAES key, IV, plaintextCiphertext, MAC tagAES-CCM, AES-GCM listed in Table 5AES Key: W, E
Authenticated DecryptionAuthenticated DecryptionAES key, ciphertext, MAC tag, IVPlaintext
Key wrappingEncrypting a keyAES key wrapping key, Key to be wrappedWrapped keyAES-KW, AES- KWP, AES-CCM, AES-GCMAES key: W, E
Key unwrappingDecrypting a keyAES key unwrapping keyUnwrapped keyAES-KW, AES- KWP, AES-CCM, AES-GCMAES key: W, E
Message Authentication GenerationMAC computationAES key, messageMAC tagAES-CMAC, AES-GMACAES Key: W, E
HMAC key, messageHMACHMAC Key: W, E
Message DigestGenerating message digestMessageMessage digestSHAN/A
Random Number GenerationGenerating random numbersOutput lengthRandom bytesCTR_DRBGEntropy Input: W, E DRBG Seed: G, E DRBG Internal State (V, Key): G, E
Key GenerationGenerating key pairModulus sizeModule generated RSA public key, Module generated RSA private keyRSA listed in Table 5, CKGModule generated RSA Public Key: G, R Module generated RSA Private Key: G, R Intermediate Key Generation Value: G, E, Z
4 Roles, Services, and Authentication
4.1 Authentication Methods

The module does not support authentication. The module does not support concurrent operators.

4.3 Approved Services

Z © 2024 Amazon Web Services, Inc., atsec information security.

22 of 44

Page 23

Name Key Verification Signature Generation Signature Verification Shared Secret Computation Key Derivation Zeroization On-Demand Self-test On-Demand Integrity Test

Description Verifying the public key Generating signature Verifying signature Calculating the Shared Secret Deriving Keys Zeroize PSP in volatile memory Initiate power-on self-tests by reset Initiate integrity test on-demand

Indicator N/A

Inputs Curve EC Public key Message, EC private key or RSA private key Signature, EC public key or RSA public key EC public key, EC private key TLS Pre- Master Secret TLS Master Secret Password, salt, iteration count Shared Secret, Key Length, Digest Shared Secret, Key Length SSP N/A N/A

Outputs Module generated EC public key, Module generated EC private key Success/ error Digital signature Digital signature verification result Shared Secret TLS Master secret TLS Derived Key (AES/HMAC) PBKDF Derived Key KDA HKDF Derived Key SSH KDF Derived Key N/A Pass or fail

Security Functions ECDSA listed in Table 5, CKG ECDSA listed in Table 5 RSA, ECDSA listed in Table 5 RSA, ECDSA listed in Table 5 KAS-ECC-SSC TLS KDF (CVL) TLS 1.0/1.1, TLS 1.2 TLS KDF (CVL) TLS 1.0/1.1, TLS 1.2 (RFC 7627) PBKDF2 KDA HKDF SSH KDF None AES, HMAC, SHA, CTR_DRBG, RSA, ECDSA, KAS-ECC-SSC, TLS KDF (CVL) TLS 1.0/1.1, TLS 1.2, KDA HKDF, PBKDF2 HMAC-SHA2- 256

Roles

SSP Access Module generated EC Public Key: G, R Module generated EC Private Key: G, R Intermediate Key Generation Value: G, E, Z EC Public Key: W, E EC Private Key: W, E RSA Private Key: W, E EC Public Key: W, E RSA Public Key: W, E EC Public Key: W, E EC Private Key: W, E Shared Secret: G, R TLS Pre-Master Secret: W, E TLS Master Secret: G TLS Master Secret: E TLS Derived Key (AES/HMAC): G, R PBKDF Derived Key: G, R Password: W, E KDA HKDF Derived Key: G, R Shared Secret: W, E SSH KDF Derived Key: G, R Shared Secret: W, E All SSPs: Z N/A N/A

Z © 2024 Amazon Web Services, Inc., atsec information security.

23 of 44

Page 24

Name Show Status Show Version

Description Show status of the module state Show the version of the module using awslc_versi on_string

Indicator

Inputs N/A N/A

Outputs Module status Module name and version

Security Functions N/A N/A

Roles

SSP Access N/A N/A

ServiceDescriptionAlgorithms AccessedRoleIndicator
EncryptionEncryptionAES listed in Table 8COReturn value 0 from the function FIPS_ service_ indicator_ check_ approved()
DecryptionDecryption
Message Authentication GenerationMAC computationAES GMAC and HMAC listed in Table 8
Message DigestGenerating message digestMD4, MD5 outside TLS 1.0 usage, SHAKE, SHA-3, RIPEMD-160
Signature GenerationGenerating signatureUsing SHA-1, SHAKE, SHA-3

Table 14: Approved Services For the above table, the convention below applies when specifying the access permissions (types) that the service has for each SSP.

4.4 Non-Approved Services

© 2024 Amazon Web Services, Inc., atsec information security.

24 of 44

Page 25

Service Signature Verification Key Generation Shared Secret Computation Key Derivation Key Encapsulation Key Un-encapsulation Encryption Primitive

Description Verifying signature Generating key pair Calculating shared secret Deriving TLS keys Decrypting a key Encrypting a key Asymmetric encryption

Algorithms Accessed RSA listed in Table 8, Curve secp256k1 RSA listed in Table 8, Curve secp256k1 RSA or ECDSA listed in Table 8 Diffie-Hellman, Curve secp256k1 TLS KDF listed in Table 8 RSA RSA RSA with PKCS#1 v1.5 and OAEP padding

Role

Indicator

Table 15: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not support loading of external software or firmware. © 2024 Amazon Web Services, Inc., atsec information security.

25 of 44

Page 26
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC value calculated at run time on the bcm.o file, with the HMAC-SHA2-256 value stored within the module that was computed at build time.

5.2 Initiate On-Demand Integrity Test

The module provides on-demand integrity test. The integrity test can be performed on demand by reloading the module. Additionally, the integrity test can be performed using the On-Demand Integrity Test service, which calls the BORINGSSL_integrity_test function. © 2024 Amazon Web Services, Inc., atsec information security.

26 of 44

Page 27
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: The module operates in a modifiable operational environment. The module runs on a commercially available general-purpose operating system executing on the hardware specified in section

  1. How requirements are satisfied: The module should be compiled and installed as stated in section
  2. The user should confirm that the module is installed correctly by following steps 4 and
5 listed in section 11.
6.2 Configurable Settings and Restrictions

Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2024 Amazon Web Services, Inc., atsec information security.

27 of 44

Page 28
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. © 2024 Amazon Web Services, Inc., atsec information security.

28 of 44

Page 29
8 Non-Invasive Security

The module claims no non-invasive security techniques. © 2024 Amazon Web Services, Inc., atsec information security.

29 of 44

Page 30
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPsDynamic
NameFromToFormat TypeDistribution TypeEntry Type
API input parametersOperator calling application (TOEPP)Cryptographic modulePlaintextManual (MD)Electronic (EE)
API output parametersCryptographic moduleOperator calling application (TOEPP)PlaintextManual (MD)Electronic (EE)
Zeroization MethodDescriptionRationaleOperator Initiation
Free Cipher HandleZeroizes the SSPs contained within the cipher handle.Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.By calling the appropriate zeroization functions: OpenSSL_cleanse, EVP_CIPHER_CTX_cleanup, EVP_AEAD_CTX_zero, HMAC_CTX_cleanup, CTR_DRBG_clear, RSA_free, EC_KEY_free
Module ResetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed.By unloading and reloading the module.
NameDescriptionSizeStrengthTypeGenerationEstablished By
AES KeyAES key used for encryption, decryption, and computing MAC tags128, 192, 256 bits128-256 bits of strengthSymmetric keyN/AN/A
9 Sensitive Security Parameter Management
9.1 Storage Areas

Table 16: Storage Areas operational environment. The SSPs are provided to the module via API input parameters in the application running on the same operational environment.

9.3 Zeroization Methods

Table 18: Zeroization Methods © 2024 Amazon Web Services, Inc., atsec information security.

30 of 44

Page 31
NameDescriptionSizeStrengthTypeGenerationEstablished By
HMAC KeyHMAC key for Message Authentication Generation112-524288 bits112-256 bits of strengthAuthentication keyN/AN/A
Entropy Input (per IG D.L)Entropy input used to seed the DRBGs256 bits256 bits of strengthEntropyN/AN/A
DRBG Seed (per IG D.L)DRBG seed derived from entropy input as defined in SP 800-90Ar1256 bits256 bits of strengthDRBG seedCTR_DRBG (according to SP800- 90Arev1)N/A
DRBG Internal State (V, Key) (per IG D.L)Internal state of CTR_DRBG256 bits256 bits of strengthInternal stateCTR_DRBG (derived from DRBG seed according to SP800-90Ar1)N/A
RSA Public KeyRSA public key used for signature verification1024, 2048, 3072, 4096 bits80-150 bits of strengthPublic keyN/AN/A
RSA Private KeyRSA private key used for signature generation2048, 3072, 4096 bits112-150 bits of strengthPrivate keyN/A
Module generated RSA Public KeyRSA public key generated by the module112-50 bits of strengthPublic keyRSA (generated according to FIPS 186-5) DRBG (for generation of random values)
Module generated RSA Private KeyRSA private key generated by the module112-150 bits of strengthPrivate key
EC Public KeyEC public key used for key verification, signature verification, shared secret computationP-224, P-256, P-384, P-521112-256 bits of strengthPublic keyN/AN/A
EC Private KeyEC private key used for signature generation, shared secret computationPrivate keyN/A
Module generated EC Public KeyEC public key generated by the modulePublic keyECDSA (generated according to FIPS 186-5) DRBG (for generation of random values)N/A
Module generated EC Private KeyEC private key generated by the modulePrivate keyN/A
Shared SecretShared Secret generated by KAS- ECC-SSCShard secretN/AKAS-ECC-SSC (established according to SP800- 56Arev3)
TLS Pre-Master SecretTLS Pre-Master secret used for deriving the TLS Master SecretP-224, P-256, P-384, P-521112-256 bitsTLS pre-master secretN/AN/A
TLS Master SecretTLS Master secret used for deriving the TLS Derived Key384 bits112-256 bitsTLS master secretKDF TLS (CVL) TLS 1.0/1.1, TLS 1.2 (RFC 7627) (derivedN/A

© 2024 Amazon Web Services, Inc., atsec information security.

31 of 44

Page 32
NameDescriptionSizeStrengthTypeGenerationEstablished By
TLS Derived key (AES/HMAC)TLS Derived Key from TLS Master SecretAES: 128-256 bits HMAC: 112 to 256 bitsAES: 128-256 bits of strength HMAC: 112-256 bits of strengthSymmetric keyaccording to SP800- 135rev1)N/A
KDA HKDF derived keyKDA HKDF derived key112 to 2048 bits112-256 bits of strengthSymmetric keyKDA HKDF (derived according to SP800- 56Crev1)N/A
SSH KDF derived keySSH KDF derived key112 to 256 bitsSSH KDF (CVL) (derived according to SP800- 135rev1)
PBKDF derived keyPBKDF derived key112–4096 bitsPBKDF (derived according to SP800-132)
PasswordPassword for PBKDF112-1024 bitsN/APasswordN/AN/A
Intermediate Key Generation ValueIntermediate key generation value224-4096 bits112-256 bits of strengthIntermediate valueCKGN/A
NameUsed ByInputs/OutputsStorageZeroizationCategoryRelated SSPs
AES KeyEncryption, Decryption, Authenticated Encryption, Authentication Decryption, Key wrapping, Key unwrapping, Message Authentication GenerationAPI input parameters (input)RAMFree Cipher Handle, Module ResetCSPNone
HMAC KeyMessage Authentication GenerationAPI input parameters (input)CSPNone
Entropy Input (per IG D.L)Random Number GenerationAPI input parameters (input)AutomaticallyCSPDRBG Seed
DRBG Seed (per IG D.L)Random Number GenerationN/ACSPEntropy Input, DRBG Internal State (V, Key)
DRBG Internal State (V, Key) (per IG D.L)Random Number GenerationN/AFree Cipher Handle, Module ResetCSPDRBG Seed
RSA Public KeySignature VerificationAPI input parameters (input)PSPRSA Private Key
RSA Private KeySignature GenerationCSPRSA Public Key

Table 19: SSP Information First © 2024 Amazon Web Services, Inc., atsec information security.

32 of 44

Page 33

Name Module generated RSA Public Key Module generated RSA Private Key EC Public Key EC Private Key Module generated EC Public Key Module generated EC Private Key Shared Secret TLS Pre-Master Secret TLS Master Secret TLS Derived Key (AES/HMAC) KDA HKDF Derived Key SSH KDF Derived Key PBKDF Derived Key

Used By N/A N/A Key Verification, Signature Verification, Shared Secret Computation Signature Generation, Shared Secret Computation EC Public Key generated by the module EC Private Key generated by the module Key Derivation Key Derivation Key Derivation N/A

Inputs/Outputs API output parameters (output) API input parameters (input) API output parameters (output) API output parameters (output) API input parameters (input) N/A API output parameters (output)

Storage

Zeroization

Category PSP CSP PSP CSP PSP CSP CSP CSP CSP CSP CSP CSP CSP

Related SSPs Module generated RSA Private Key, Intermediate Key Generation Value Module generated RSA Public Key, Intermediate Key Generation Value EC Private Key, Shared Secret EC Public Key, Shared Secret Module generated EC Private Key, Intermediate Key Generation Value Module generated EC Public Key, Intermediate Key Generation Value EC Public Key, EC Private Key TLS Master Secret TLS Pre-Master Secret, TLS Derived Key (AES/HMAC) TLS Master Secret Shared Secret Shared Secret Password

© 2024 Amazon Web Services, Inc., atsec information security.

33 of 44

Page 34

Name Password Intermediate Key Generation Value

Used By Key Generation

Inputs/Outputs API input parameters (input) N/A

Storage

Zeroization Automatically

Category CSP CSP

Related SSPs PBKDF Derived Key Module generated RSA Private Key, Module generated RSA Public Key, Module generated EC Private Key, Module generated EC Public Key

Table 20: SSP Information Second

9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2030. © 2024 Amazon Web Services, Inc., atsec information security.

34 of 44

Page 35
AlgorithmImplementationTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-256SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3SHA2-256Message AuthenticationSoftware IntegrityModule becomes operationalN/A
Algorithm or TestTest PropertiesTest MethodTypeIndicatorDetailsConditionCoverageCoverage Notes
AES CBC AES GCM AES_C, AES_C_GCM, AESNI, AESNI_AVX, AESNI_ASM, AESAESM, AESASM_AVX, AESASM_CLMULNI, AESASM_ASM, CE, CE_GCM_UNROLL8_E OR3, CE_GCM, VPAES, VPAES_GCM, AESNI_CLMULNI, BAES_CTASM, BAES_CTASM_AVX, BAES_CTASM_CLMUL NI, BAES_CTASM_ASM128-bit AES keyEncrypt KAT for CBCCASTModule is operationalEncryptPower upSelfN/A
Decrypt KAT for CBCDecryptSelf and ECB, KW, KWP, XTS (all implementatio ns)IG 10.3.A, resolution 1.c
Encrypt KAT for GCMEncryptSelf and CCM, CMAC, CTR, ECB, GMAC, KW, KWP, XTS all implementatio ns)IG 10.3.A, resolution 1.d.(i)
Decrypt KAT for GCMDecryptSelfN/A
SHA-1 SHA2-256 SHA2-512 SHA_CE, SHA_ASM, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3N/ASHA-1 KATCASTMessage digestPower upSelfN/A
SHA2-256 KATSelf and SHA2- 224 all implementatio ns)IG 10.3.A, resolution 2
SSH KDF (all implementatio ns)IG 10.3.A, resolution 12, note 18
SHA2-512Self and SHA2-IG 10.3.A,

Table 21: Pre-Operational Self-Tests The module performs the pre-operational self-test automatically when the module is loaded into memory; the pre-operational self-test is the software integrity test that ensures that the module is not corrupted. While the module is executing the pre-operational self-test, services are not available, and input and output are inhibited. The software integrity test is performed after a set of conditional cryptographic algorithm selftests (CASTs). The set of CASTs includes the self-test for HMAC-SHA2-256 algorithm used in the

10.2 Conditional Self-Tests

© 2024 Amazon Web Services, Inc., atsec information security.

35 of 44

Page 36

Algorithm or Test HMAC SHA_CE, SHA_ASM, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 CTR_DRBG AES_C, AESNI, AESASM, AESASM_AVX, CE, VPAES, BAES_CTASM ECDSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 ECDSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 KAS-ECC-SSC C ECDSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 KDF TLS (CVL) SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 KDA HKDF SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 PBKDF2 SHA_ASM, SHA_CE,

Test Properties SHA2-256 AES 256 N/A P-256 Curve and SHA2- 256 P-256 Curve and SHA2- 256 P-256 Curve Respective Curve and SHA2-256 SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256

Test Method KAT HMAC KAT CTR_DRB G KAT SP800- 90Ar1 Section 11.3 Health Test Sign KAT Verify KAT Z computati on Signature generatio n and verificatio n TLS 1.2 KAT KAT KAT

Type CAST CAST CAST PCT CAST CAST CAST

Indicator

Details Message authenticati on Seed Generation Seed Generation Sign Verify Shared secret computation Sign and Verify Key derivation Key derivation Key derivation

Condition Power up Power up Power up Signature Generation or Key Generation service request Signature verification or Key Generation service request Shared secret computatio n request Key generation Power up Power up Power up

Coverage 384, SHA2- 512/256 (all implementatio ns) Self and HMAC-SHA-1, HMAC-SHA2- 224, HMAC-SHA2- 384, HMAC-SHA2- 512, HMAC-SHA2- 512/256 Self Self Self Self Self Self and KAS- ECC-SSC PCT Self Self Self

Coverage Notes resolution 2 IG 10.3.A resolution 5 N/A N/A N/A N/A N/A IG 10.3.A additional comment 1. N/A N/A N/A

© 2024 Amazon Web Services, Inc., atsec information security.

36 of 44

Page 37

Algorithm or Test NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 RSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 RSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 RSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3

Test Properties PKCS#1 v1.5 with 2048 bit key and SHA2-256 PKCS#1 v1.5 with 2048 bit key and SHA2-256 SHA2-256 and respective keys

Test Method Sign KAT Verify KAT Signature generatio n and verificatio n

Type CAST CAST PCT

Indicator

Details Sign Verify Sign and Verify

Condition Signature Generation or Key Generation service request Signature Verification or Key Generation service request Key generation

Coverage Self Self Self

Coverage Notes N/A N/A N/A

NameDescriptionConditionRecovery MethodStatus Indicator
ErrorThe library is aborted with SIGABRT signal. Module is no longer operational the data outputPre-operational test failureModule resetError message is output on the stderr and then the module is aborted.
Conditional test failureModule resetFor CAST failure, an error message is output on the stderr and then the module is aborted. For PCT failure, an error message is output in the error queue and then

Table 22: Conditional Self-Tests

10.2.1 Conditional Cryptographic Algorithm Tests

The module performs self-tests on approved cryptographic algorithms, using the tests shown in Table 22. Data output through the data output interface is inhibited during the self-tests. The CASTs are performed in the form of Known Answer Tests (KATs), in which the calculated output is compared with the expected known answer (that are hard coded in the module). A failed match causes a failure of the self-test. If any of these self-tests fails, the module transitions to error state.

10.2.2 Conditional Pair-Wise Consistency Tests

pairwise consistency test (PCT) using sign and verify functions when the keys are generated (Table 22). If any of these self-tests fails, the module transitions to error state and is aborted.

10.3 Periodic Self-Tests

The module does not support periodic self-tests.

10.4 Error States

© 2024 Amazon Web Services, Inc., atsec information security.

37 of 44

Page 38

Name

Description interface is inhibited

Condition

Recovery Method

Status Indicator the module generates new key, If the PCT still does not pass, eventually the module will be aborted after 5 tries.

Table 23: Error States If the module fails any of the self-tests, the module enters the error state. To recover from the Error state, the module needs to be rebooted.

10.5 Operator Initiation

The software integrity tests and the CASTs for AES, SHA, DRBG, KAS-ECC-SSC, TLS KDF, KDA HKDF, PBKDF2 can be invoked by unloading and subsequently re-initializing the module. The CASTs for ECDSA and RSA can be invoked by requesting the corresponding Key Generation or Digital Signature services. Additionally, all the CASTs can be invoked by calling the BORINGSSL_self_test function. The PCTs can be invoked on demand by requesting the Key Generation service. © 2024 Amazon Web Services, Inc., atsec information security.

38 of 44

Page 39
11 Life-Cycle Assurance
11.1 Installation, Initialization and Startup Procedures

The module bcm.o is embedded into the shared library libcrypto.so which can be obtained by building the source code at the following location [1]. The set of files specified in the archive constitutes the complete set of source files of the validated module. There shall be no additions, deletions, or alterations of this set as used during module build. [1] https://github.com/aws/aws-lc/archive/refs/tags/AWS-LC-FIPS-2.0.0.zip. The downloaded zip file can be verified by issuing the “sha256sum AWS-LC-FIPS-2.0.0.zip” command. The expected SHA2-256 digest value is: 6241EC2F13A5F80224EE9CD8592ED66A97D426481066FEAA4EFC6F24E60BBC96 After the zip file is extracted, the instructions listed below will compile the module. The compilation instructions must be executed separately on platforms that have different processors and/or operating systems. Due to six possible combinations of OS/processor, the module count is six (i.e., there are six separate binaries generated, one for each entry listed in Table 3). Amazon Linux 2 and Amazon Linux 2023: 1. sudo yum groupinstall "Development Tools" 2. sudo yum install cmake3 golang 3. cd aws-lc-fips-2022-11-02/ 4. mkdir build 5. cd build 6. cmake3 -DFIPS=1 -DCMAKE_BUILD_TYPE=Release -DBUILD_SHARED_LIBS=1 .. 7. make Ubuntu 22.04: 1. sudo apt-get install build-essential 2. sudo apt-get install cmake 3. Get latest Golang archive for your architecture 4. sudo tar -C /usr/local -xzf go*.tar.gz 5. cd aws-lc-fips-2022-11-02/ 6. mkdir build 7. cd build 8. cmake -DFIPS=1 -DCMAKE_BUILD_TYPE=Release -DBUILD_SHARED_LIBS=1 -DGO_EXECUTABLE=/usr/local/go/bin/go .. 9. make Upon completion of the build process, the module’s status can be verified by the command below. If the value obtained is “1” then the module has been installed and configured to operate in FIPS compliant manner. ./tool/bssl isfips © 2024 Amazon Web Services, Inc., atsec information security.

39 of 44

Page 40

Lastly, the user can call the “show version” service using awslc_version_string function and the expected output is “AWS-LC FIPS 2.0.0” which is the module version. This will confirm that the module is in the operational mode. Additionally, the “AWS-LC FIPS” also acts as the module identifier and the verification of the "dynamic" part can be done using following command with an application that was used for dynamic linking. The "U" in the output confirms that the module is dynamically linked. Command: nm <application_name> | grep awslc_version_string Example Output: “ U awslc_version_string”

11.2 Administrator Guidance

When the module is at end of life, for the GitHub repo, the README will be modified to mark the library as deprecated. After a 6-month window, more restrictive branch permissions will be added such that only administrators can read from the FIPS branch. The module does not possess persistent storage of SSPs. The SSP value only exists in volatile memory and that value vanishes when the module is powered off. So as a first step for the secure sanitization, the module needs to be powered off. Then for actual deprecation, the module will be upgraded to newer version that is approved. This upgrade process will uninstall/remove the old/terminated module and provide a new replacement. © 2024 Amazon Web Services, Inc., atsec information security.

40 of 44

Page 41
12 Mitigation of Other Attacks

RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack. The module provides the mechanism to use the blinding for RSA. When the blinding is on, the module generates a random value to form a blinding factor in the RSA key before the RSA key is used in the RSA cryptographic operations. © 2024 Amazon Web Services, Inc., atsec information security.

41 of 44

Page 42
13 Glossary and Abbreviations
Table, extracted as text (did not parse into structured rows)
AES                Advanced Encryption Standard AESNI              Advanced Encryption Standard New Instructions CAVP               Cryptographic Algorithm Validation Program CAST               Cryptographic Algorithm Self-Test CBC                Cipher Block Chaining CCM                Counter with Cipher Block Chaining-Message Authentication Code CFB                Cipher Feedback CMAC               Cipher-based Message Authentication Code CMVP               Cryptographic Module Validation Program CSP                Critical Security Parameter CTR                Counter Mode DRBG               Deterministic Random Bit Generator ECB                Electronic Code Book ECC                Elliptic Curve Cryptography FIPS               Federal Information Processing Standards Publication GCM                Galois Counter Mode HMAC               Hash Message Authentication Code KAT                Known Answer Test KW                 AES Key Wrap KWP                AES Key Wrap with Padding MAC                Message Authentication Code NIST               National Institute of Science and Technology OFB                Output Feedback OS                 Operating System PAA                Processor Algorithm Acceleration PCT                Pair-Wise Consistency Test PR                 Prediction Resistance PSP                Public Security Parameter PSS                Probabilistic Signature Scheme RNG                Random Number Generator RSA                Rivest, Shamir, Addleman SHA                Secure Hash Algorithm © 2024 Amazon Web Services, Inc., atsec information security.

42 of 44

Page 43
14 References

FIPS140-3 FIPS PUB 140-3 - Security Requirements for Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS140-3_IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program August 2023 https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips140-3-ig-announcements FIPS180-4 Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf FIPS186-4 Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf FIPS186-5 Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf FIPS197 Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf FIPS198-1 The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf PKCS#1 Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt SP800-38A Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf SP800-38B NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf SP800-38C NIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038c.pdf © 2024 Amazon Web Services, Inc., atsec information security.

43 of 44

Page 44

SP800-38D NIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf SP800-38F NIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf SP800-56Arev3 NIST Special Publication 800-56A Revision 2 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography May 2013 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar2.pdf SP800-90Arev1 NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf SP800-131Arev1 NIST Special Publication 800-131A Revision 1- Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths November 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar1.pdf SP800-133rev2 NIST Special Publication 800-133rev2 - Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf SP800-135rev1 NIST Special Publication 800-135 Revision 1 - Recommendation for Existing Application-Specific Key Derivation Functions December 2011 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800135r1.pdf © 2024 Amazon Web Services, Inc., atsec information security.

44 of 44