| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 8/13/2029 |
| Caveat | Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys) |
| Vendor | Amazon Web Services Inc. |
flowchart LR
%% Deterministic review-risk graph for AWS-LC Cryptographic Module (dynamic)
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery<br/>upgrade</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show Status</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for AWS-LC Cryptographic Module (dynamic)
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery<br/>upgrade</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show Status</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;AWS-LC Cryptographic Module (dynamic) Module Version: AWS-LC FIPS 2.0.0 Document version: 1.0 Last update: 2024-08-13 Prepared by: atsec information security corporation
4516 Seton Center Pkwy, Suite 250
Austin, TX 78759 www.atsec.com © 2024 Amazon Web Services, Inc., atsec information security.
© 2024 Amazon Web Services, Inc., atsec information security.
2 of 44
© 2024 Amazon Web Services, Inc., atsec information security.
3 of 44
© 2024 Amazon Web Services, Inc., atsec information security.
4 of 44
© 2024 Amazon Web Services, Inc., atsec information security.
5 of 44
Amazon is a registered trademark of Amazon Web Services, Inc. or its affiliates. © 2024 Amazon Web Services, Inc., atsec information security.
6 of 44
| ISO/IEC 24759 Section 6. Subsections | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic Module Specification | 1 |
| 3 | Cryptographic Module Interfaces | 1 |
| 4 | Roles, Services, and Authentication | 1 |
| 5 | Software/Firmware Security | 1 |
| 6 | Operational Environment | 1 |
| 7 | Physical Security | N/A |
| 8 | Non-invasive Security | N/A |
| 9 | Sensitive Security Parameter Management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle Assurance | 1 |
| 12 | Mitigation of Other Attacks | 1 |
This document is the non-proprietary FIPS 140-3 Security Policy for version AWS-LC FIPS 2.0.0 of the AWS-LC Cryptographic Module (dynamic). It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security
Table 1 describes the individual security areas of FIPS 140-3, as well as the security levels of those individual areas. Table 1: Security Levels
This Security Policy describes the features and design of the module named AWS-LC Cryptographic Module (dynamic) using the terminology contained in the FIPS 140-3 specification. The FIPS 140-3 Security Requirements for Cryptographic Module specifies the security requirements that will be satisfied by a cryptographic module utilized within a security system protecting sensitive but unclassified information. The NIST/CCCS Cryptographic Module Validation Program (CMVP) validates cryptographic module to FIPS 140-3. Validated products are accepted by the Federal agencies of both the USA and Canada for the protection of sensitive or designated information. and including this notice. Other documentation is proprietary to their authors. © 2024 Amazon Web Services, Inc., atsec information security.
7 of 44
was further consolidated into this document by atsec information security together with other vendor-supplied documentation. In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. © 2024 Amazon Web Services, Inc., atsec information security.
8 of 44
| Package/File Names | Software/ Firmware Version | Integrity Test Implemented | |||
|---|---|---|---|---|---|
| bcm.o | AWS-LC FIPS 2.0.0 | HMAC-SHA2-256 |
Purpose and Use: The AWS-LC Cryptographic Module (dynamic) (hereafter referred to as “the module”) provides cryptographic services to applications running in the user space of the underlying operating system through a C language Application Program Interface (API). Module Type: Software Module Embodiment: Multi-chip standalone Module Characteristics: N/A Cryptographic Boundary: The block diagram in Figure 1 shows the cryptographic boundary of the module, its interfaces with the operational environment and the flow of information between the module and operator (depicted through the arrows). The module components consist of the bcm.o (AWS-LC FIPS 2.0.0), which is dynamically linked to the userspace application during the compilation process. Figure 1: Block diagram
Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): Table 2: Tested Module Identification © 2024 Amazon Web Services, Inc., atsec information security.
9 of 44
| Operating System | Hardware Platform | Processor(s) | PAA/PAI | Hypervisor or Host OS | Version(s) | |
|---|---|---|---|---|---|---|
| Amazon Linux 2 Amazon Linux 2023 Ubuntu 22.04 | Amazon EC2 c5.metal with 192 GiB system memory and Elastic Block Store (EBS) 200 GiB | Intel ®Xeon ® Platinum 8275CL | AES-NI and SHA extensions (PAA) | N/A | AWS-LC FIPS 2.0.0 | |
| Amazon Linux 2 Amazon Linux 2023 Ubuntu 22.04 | Amazon EC2 c5.metal with 192 GiB system memory and Elastic Block Store (EBS) 200 GiB | Intel ®Xeon ® Platinum 8275CL | None | |||
| Amazon Linux 2 Amazon Linux 2023 Ubuntu 22.04 | Amazon EC2 c7g.metal with 128 GiB system memory and Elastic Block Store (EBS) 200 GiB | Graviton3 | Neon and Crypto Extension (CE) (PAA) | AWS-LC FIPS 2.0.0 | ||
| Amazon Linux 2 Amazon Linux 2023 Ubuntu 22.04 | Amazon EC2 c7g.metal with 128 GiB system memory and Elastic Block Store (EBS) 200 GiB | Graviton3 | None |
| Name | Description | Type | Status Indicator |
|---|---|---|---|
| Approved Mode | Automatically entered whenever an approved service is requested. | Approved | Equivalent to the indicator of the requested service. |
| Non-approved Mode | Automatically entered whenever a non- approved service is requested. | Non-Approved | Equivalent to the indicator of the requested service. |
Tested Operational Environments - Software, Firmware, Hybrid: Table 3: Tested Operational Environments
The module does not claim any excluded components.
Table 4: Modes of Operation of the Module Mode change instructions and status indicators: When the module starts up successfully, after passing a set of cryptographic algorithms self-tests (CASTs) and the pre-operational self-test, the module is operating in the approved mode of operation by default and can only be transitioned into the non-approved mode by calling one of the non-approved services listed in Table 15. The module will transition back to approved mode when approved service is called. Section 4 provides details on the service indicator implemented by the module. The service indicator identifies when an approved service is called. The module does not implement a degraded mode of operation. © 2024 Amazon Web Services, Inc., atsec information security.
10 of 44
| Algorithm Name | CAVP Cert Numbers | Algorithm Capabilities | OE (Implementation) | Reference |
|---|---|---|---|---|
| AES-CBC | A4489, A4493, | Encryption, | Amazon Linux 2023 on EC2 bare metal on Amazon | FIPS 197, |
| A4501, A4484, | Decryption using | Graviton3: AES_C, CE, VPAES | SP800-38A | |
| A4487, A4497 | 1 28,192,256 bits key | Ubuntu on EC2 bare metal on Amazon Graviton3 AWS Graviton: AES_C, CE, VPAES Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM | ||
| AES-CCM | A4489, A4493, | Authenticated | Amazon Linux 2023 on EC2 bare metal on Amazon | FIPS 197, |
| A4501, A4484, | Encryption, | Graviton3: AES_C, BAES_CTASM, CE, VPAES | SP800-38C, IG | |
| A4487, A4497 | Authenticated | Ubuntu on EC2 bare metal on Amazon Graviton3 | D.G | |
| Decryption, Key Wrapping, Key | AWS Graviton: AES_C, BAES_CTASM, CE, VPAES | |||
| Unwrapping using 128 bit key | Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM | |||
| AES-CMAC | A4489, A4493, | Message | Amazon Linux 2023 on EC2 bare metal on Amazon | FIPS 197, |
| A4501, A4487, | Authentication | Graviton3: AES_C, BAES_CTASM, CE, VPAES | SP800-38B | |
| A4497 | Generation 128- or | Ubuntu on EC2 bare metal on Amazon Graviton3 | ||
| 256-bits key | AWS Graviton: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM |
Approved Algorithms: © 2024 Amazon Web Services, Inc., atsec information security.
11 of 44
| Algorithm Name | CAVP Cert Numbers | Algorithm Capabilities | OE (Implementation) | Reference |
|---|---|---|---|---|
| AES-CTR | A4489, A4493, | Encryption, | Amazon Linux 2023 on EC2 bare metal on Amazon | FIPS 197, SP |
| A4501, A4484, | Decryption | Graviton3: AES_C, BAES_CTASM, CE, VPAES | 800-38A | |
| A4487, A4497 | 1 2 8 ,192,256 bits key | Ubuntu on EC2 bare metal on Amazon Graviton3 AWS Graviton: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM | ||
| AES-ECB | A4489, A4490, | Encryption, | Amazon Linux 2023 on EC2 bare metal on Amazon | FIPS 197, SP |
| A4493, A4494, | Decryption using 128, | Graviton3: AES_C, AES_C_GCM, CE, | 800-38A | |
| A4496, A4501, | 192, 256 bits key | CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES, VPAES_GCM | ||
| A4502, A4503, | Ubuntu on EC2 bare metal on Amazon Graviton3 | |||
| A4504, A4484, | AWS Graviton: AES_C, AES_C_GCM, CE, | |||
| A4485, A4486, A4487, A4488, | CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES, VPAES_GCM Amazon Linux 2 on EC2 bare metal on Amazon | |||
| A4495, A4497, | Graviton3: AES_C, AES_C_GCM, CE, | |||
| A4498, A4499, A4500 | CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES VPAES_GCM Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESNI_AVX, AESNI_ASM, AESASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESNI_AVX, AESNI_ASM, AESASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESNI_AVX, AESNI_ASM, AESASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM | |||
| AES-GCM | A4490, A4494, | Authenticated | Amazon Linux 2023 on EC2 bare metal on Amazon | FIPS 197, |
| A4496, A4502, | Encryption (with | Graviton3: AES_C, AES_C_GCM, CE_GCM_UNROLL8_EOR3, | SP800-38D, IG | |
| A4503, A4504, | Internal IV Mode | CE_GCM, VPAES_GCM | D.G | |
| A4485, A4486, A4488, A4495, | 8.2.2) and Key Wrapping using 128 | Ubuntu on EC2 bare metal on Amazon Graviton3 AWS Graviton: AES_C, AES_C_GCM, | ||
| A4498, A4499, A4500 | or 256 bits key | CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES_GCM Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, AES_C_GCM, CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES_GCM | ||
| AES-GCM | Authenticated | FIPS 197, | ||
| Decryption (with | Amazon Linux 2 on EC2 bare metal on Intel Cascade | SP800-38D, IG | ||
| external IV) and Key Unwrapping using 128- or 256-bits key | Lake Xeon Platinum 8275CL: ASENI_AVX, AESNI_ASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, | D.G |
© 2024 Amazon Web Services, Inc., atsec information security.
12 of 44
| Algorithm Name AES-GMAC | CAVP Cert Numbers | Algorithm Capabilities Message Authentication Generation using 128- or 256-bits key | OE (Implementation) AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: ASENI_AVX, AESNI_ASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: ASENI_AVX, AESNI_ASM, AESASM_AVX, AES_CLMULNI, AESASM_ASM, AESASM_CLMULNI, AESNI_CLMULNI, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM | Reference FIPS 197, SP800-38D |
|---|---|---|---|---|
| AES-KW | A4489, A4493, | Key Wrapping, Key | Amazon Linux 2023 on EC2 bare metal on Amazon | FIPS 197, SP800- |
| A4501, A4484, | Unwrapping using | Graviton3: AES_C, BAES_CTASM, CE, VPAES | 38F, IG D.G | |
| AES-KWP | A4487, A4497 | 1 28, 192, 256 bits key | Ubuntu on EC2 bare metal on Amazon Graviton3 AWS Graviton: AES_C, BAES_CTASM, CE, VPAES | |
| AES-XTS | Encryption, | FIPS 197, SP | ||
| Decryption using 256 | Amazon Linux 2 on EC2 bare metal on Amazon | 800-38E | ||
| bits key | Graviton3: AES_C, BAES_CTASM, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM | |||
| CTR_DRBG | A4489, A4493, | Random Number | Amazon Linux 2023 on EC2 bare metal on Amazon | SP800-90Arev1 |
| A4501, A4484, | Generation using AES | Graviton3: AES_C, CE, VPAES | ||
| A4487, A4497 | 2 5 6 bits without | Ubuntu on EC2 bare metal on Amazon Graviton3 | ||
| derivation function or prediction resistance. | AWS Graviton: AES_C, CE, VPAES Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: AES_C, CE, VPAES Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: AESNI, AESASM, BAES_CTASM | |||
| ECDSA | A4483, A4491, | Key Generation using | Amazon Linux 2023 on EC2 bare metal on Amazon | FIPS 186-5 |
| A4492, A4505, | P-224, P-256, P-384, | Graviton3: SHA_ASM, SHA_CE, NEON | A.2.2 FIPS 186- | |
| A4506, A4507, | P-521 | Ubuntu on EC2 bare metal on Amazon Graviton3 | 5 Rejection | |
| A4508 | AWS Graviton: SHA_ASM, SHA_CE, NEON | Sampling; SP800-133rev2 | ||
| Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: SHA_ASM, SHA_CE, NEON Amazon Linux 2 on EC2 bare metal on Intel Cascade | sections 4, 5.1, 5.2 | |||
| Key Verification using | Lake Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2, | FIPS 186-5 for | ||
| P-224, P-256, P-384, | SHA_AVX, SHA_SSSE3 | all except FIPS | ||
| P-521 | Amazon Linux 2023 on EC2 bare metal on Intel | 186-4 for | ||
| Cascade Lake Xeon Platinum 8275CL: SHA_SHANI, | signature | |||
| ECDSA with | Signature Generation | SHA_AVX2, SHA_AVX, SHA_SSSE3 | verification with | |
| SHA2-224, | using P-224, P-256, P- | SHA-1 | ||
| SHA2-256, | 384, P-521 | Ubuntu on EC2 bare metal on Intel Cascade Lake | ||
| SHA2-384, | Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2, | |||
| SHA2-512 | SHA_AVX, SHA_SSSE3 |
13 of 44
| Algorithm Name ECDSA with SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2-512 | CAVP Cert Numbers | Algorithm Capabilities Signature Verification using P-224, P-256, P- 384, P-521 | OE (Implementation) | Reference |
|---|---|---|---|---|
| HMAC-SHA-1, | A4483, A4491, | Message | Amazon Linux 2023 on EC2 bare metal on Amazon | FIPS 198-1 |
| HMAC-SHA2- | A4492, A4505, | Authentication | Graviton3: SHA_ASM, SHA_CE, NEON | |
| 224, | A4506, A4507, | Generation using 112- | Ubuntu on EC2 bare metal on Amazon Graviton3 | |
| HMAC-SHA2- 256, | A4508 | 524288 bits key | AWS Graviton: SHA_ASM, SHA_CE, NEON | |
| HMAC-SHA2- 384, | Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: SHA_ASM, SHA_CE, NEON | |||
| HMAC-SHA2- | Amazon Linux 2 on EC2 bare metal on Intel Cascade | |||
| 512, | Lake Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2, | |||
| HMAC-SHA2- | SHA_AVX, SHA_SSSE3 | |||
| 512/256 | Amazon Linux 2023 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: SHA_SHANI, | |||
| KAS-ECC-SSC | A4483, A4491, | Shared Secret | SHA_AVX2, SHA_AVX, SHA_SSSE3 | SP800-56ARev3, |
| ECC Ephemeral | A4492, A4505, | Computation using P- | IG D.F scenario | |
| Unified scheme | A4506, A4507, | 224, P-256, P-384, P- | Ubuntu on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2, | 2(1) |
| A4508 | 521 | SHA_AVX, SHA_SSSE3 | ||
| KDA HKDF with | A4483, A4491, | Key Derivation | SP800-56Crev1; | |
| HMAC-SHA-1, | A4492, A4505, | SP800-133rev2 | ||
| HMAC-SHA2- | A4506, A4507, | Derived Key Length: | section 6.2 | |
| 224, HMAC- SHA-256, | A4508 | 2048 | ||
| HMAC-SHA2- 384, HMAC- SHA2-512 | Shared Secret Length: 224-2048 Increment 8 | |||
| KDF TLS (CVL) | A4483, A4491, | Key Derivation | SP800-135rev1; | |
| TLS 1.0/1.1, | A4492, A4505, | SP800-133rev2 | ||
| TLS 1.2 (RFC | A4506, A4507, | section 6.2 | ||
| 7627) with SHA2-256, SHA2-384, SHA2-512 | A4508 | |||
| PBKDF with | A4483, A4491, | Password based key | Amazon Linux 2023 on EC2 bare metal on Amazon | SP800-132 |
| HMAC-SHA-1, | A4492, A4505, | derivation: | Graviton3: SHA_ASM, SHA_CE, NEON | Option 1a; |
| HMAC-SHA2- | A4506, A4507, | Iteration Count: 1000- | Ubuntu on EC2 bare metal on Amazon Graviton3 | SP800-133rev2 |
| 224, HMAC- | A4508 | 10000 Increment 1 | AWS Graviton: SHA_ASM, SHA_CE, NEON | section 6.2 |
| SHA2-256, | Password Length: 14- | |||
| HMAC-SHA2- | 128 Increment 1 | Amazon Linux 2 on EC2 bare metal on Amazon Graviton3: SHA_ASM, SHA_CE, NEON | ||
| 384, HMAC- | Salt Length: 128-4096 | |||
| SHA2-512 | Increment 8 Key Data Length: 128-4096 Increment 8 | Amazon Linux 2 on EC2 bare metal on Intel Cascade Lake Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 Amazon Linux 2023 on EC2 bare metal on Intel | ||
| RSA | A4483, A4491, | Key Generation using | Cascade Lake Xeon Platinum 8275CL: SHA_SHANI, | FIPS 186-5 |
| A4492, A4505, | 2048,3072, 4096 bits | SHA_AVX2, SHA_AVX, SHA_SSSE3 | A.1.3 Random | |
| A4506, A4507, | key | Ubuntu on EC2 bare metal on Intel Cascade Lake | Probable | |
| A4508 | Xeon Platinum 8275CL: SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 | Primes; SP800- 133rev2 sections 4, 5.1 |
© 2024 Amazon Web Services, Inc., atsec information security.
14 of 44
Algorithm Name RSA PKCS#1v1.5 with SHA2-224, SHA2-256, SHA2-384, SHA2-512 RSA PSS with SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256 RSA PKCS#1v1.5 with SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512; RSA PSS with SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256 SSH KDF (CVL) with AES-128, AES-192, AES- 256; SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256
CAVP Cert Numbers A4483, A4491, A4492, A4505, A4506, A4507, A4508 A4483, A4491, A4492, A4505, A4506, A4507, A4508
Algorithm Capabilities Signature Generation using 2048,3072, 4096 bits key Signature Verification using 1024, 2048, 3072, 4096 bits key. Key Derivation Message Digest
OE (Implementation)
Reference FIPS 186-5 except FIPS 186-4 for use of SHA-1 and 1024 bit key SP800-135rev1; SP800-133rev2 section 6.2 FIPS 180-4
| Algorithm Name | Algorithm Capabilities | OE (Implementation) | References | |
|---|---|---|---|---|
| CKG (ECDSA KeyGen) | ECDSA KeyGen (FIPS 186-5): P- 224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength | Software; OE same as in Table 3 | FIPS 186-5, A.2.2 Rejection Sampling; SP 800-133Rev2 section 4 and IG D.H comment 2 (without any V, as described in Additional Comments 2 of IG D.H) | |
| CKG (RSA KeyGen) | RSA KeyGen (FIPS 186-5): 2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. | FIPS 186-5, A.1.3 Random Probable Primes; SP 800- 133Rev2 section 4 and IG D.H comment 2 (without any V, as described in Additional Comments 2 of IG D.H) |
Table 5: Approved Algorithms Vendor-Affirmed Algorithms: Table 6: Vendor Affirmed Algorithms © 2024 Amazon Web Services, Inc., atsec information security.
15 of 44
| Algorithm | Caveat | Use/Function | ||
|---|---|---|---|---|
| MD5 | Allowed per IG 2.4.A | Message Digest used in TLS 1.0/1.1 KDF only |
| Algorithm/Functions | Use/Function |
|---|---|
| AES with OFB or CFB1, CFB8 modes | Encryption, Decryption |
| AES GCM, GCM, GMAC, XTS with keys not listed in Table 5 | Encryption, Decryption |
| AES using aes_*_generic function | Encryption, Decryption |
| AES GMAC using aes_*_generic | Message Authentication Generation |
| Curve secp256k1 | Signature Generation, Signature Verification, Shared Secret Computation |
| Diffie Hellman | Shared Secret Computation |
| HMAC-MD4, HMAC-MD5, HMAC-SHA1, HMAC-SHA-3, HMAC- RIPEMD-160 | Message Authentication Generation |
| MD4 | Message Digest |
| MD5 | Message Digest (outside of TLS) |
| RSA using RSA_generate_key_ex | Key Generation |
| ECDSA using EC_KEY_generate_key | Key Generation |
| RSA using keys less than 2048 bits | Signature Generation |
| RSA using keys less than 1024 bits | Signature Verification |
| RSA | Key Encapsulation/Un-encapsulation, sign/verify primitive operations without hashing |
| RSA with PKCS#1 v1.5 and OAEP padding | Encryption primitive |
| SHA-1, SHA-3 | Signature Generation |
| SHAKE, RIPEMD-160, SHA-3 | Message Digest |
| TLS KDF using any SHA algorithms not listed in Table 5 or TLS KDF using non extended master secret | Key Derivation |
| Name | Type | Description | SF Capabilities | Algorithms |
|---|---|---|---|---|
| KAS-ECC-SSC | KAS | SP800-56Ar3. KAS-ECC-SSC per IG D.F 2 path (1) | Ephemeral Unified scheme Curves: P-224, P-256, P-384, P-521 elliptic curves with 112-256 bits of strength | KAS-ECC-SSC: A4483, A4491, A4492, A4505, A4506, A4507, A4508 |
| AES KW, AES-KWP | KTS | SP 800-38F. KTS (Key Wrapping, Key Unwrapping) per IG D.G | 128, 192, 256 bits with 128-256 bits of key strength | AES: A4489, A4493, A4501, A4484, A4487, A4497 |
The module does not implement non-approved algorithms that are allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: Table 7: Non-Approved Allowed Algorithms with No Security Claimed
© 2024 Amazon Web Services, Inc., atsec information security.
16 of 44
| AES GCM [SP 800- 38D] | KTS | SP800-38D. KTS (Key Wrapping, Key Unwrapping) per IG D.G | 128, 256 bits with 128 and 256 bits of key strength | AES: A4490, A4494, A4496, A4502, A4503, A4504, A4485, A4486, A4488, A4495, A4498, A4499, A4500 |
|---|---|---|---|---|
| AES CCM [SP 800- 38C] | KTS | SP 800-38C. KTS (Key Wrapping, Key Unwrapping) per IG D.G | 128 bits with 128 bits of key strength | AES: A4489, A4493, A4501, A4484, A4487, A4497 |
Table 9: Security Function Implementation
The module offers three AES GCM implementations. The GCM IV generation for these implementations complies respectively with IG C.H under Scenario 1, Scenario 2, and Scenario 5. The GCM shall only be used in the context of the AES-GCM encryption executing under each scenario, and using the referenced APIs explained next. Scenario 1, TLS 1.2 For TLS 1.2, the module offers the GCM implementation via the functions EVP_aead_aes_128_gcm_tls12() and EVP_aead_aes_256_gcm_tls12(), and uses the context of Scenario 1 of IG C.H. The module is compliant with SP800-52rev2 and the mechanism for IV generation is compliant with RFC5288. The module supports acceptable AES-GCM ciphersuites from Section 3.3.1 of SP800-52rev2. The module explicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values of 2^{64-1} for a given session key. If this exhaustion condition is observed, the module returns an error indication to the calling application, which will then need to either abort the connection, or trigger a handshake to establish a new encryption In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established. Scenario 2, Random IV In this implementation, the module offers the interfaces EVP_aead_aes_128_gcm_randnonce() and Section 8.2.2. The AES-GCM IV is generated randomly internal to the module using module’s approved DRGB. The DRBG receives a LOAD command with entropy obtained from inside the physical perimeter of the operational environment but outside of module's cryptographic boundary. The GCM IV is 96 bits in length and is expected to have 96 bits of entropy. Scenario 5, TLS 1.3 For TLS 1.3, the module offers the AES-GCM implementation via the functions EVP_aead_aes_128_gcm_tls13() and EVP_aead_aes_256_gcm_tls13(), and uses the context of Scenario 5 of IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the ciphersuites that explicitly select AES-GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES-GCM ciphersuites from Section 3.3.1 of SP800-52rev2. The module implements, within its boundary, an IV generation unit for TLS 1.3 that keeps control of the 64-bit counter value within the AES-GCM IV. If the exhaustion condition is observed, the module will return an error indication to the calling application, who will then need to either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection. © 2024 Amazon Web Services, Inc., atsec information security.
17 of 44
In the event the module’s power is lost and restored, the consuming application must ensure that new AES-GCM keys encryption or decryption under this scenario are established. TLS 1.3 provides session resumption, but the resumption procedure derives new AES-GCM encryption keys.
The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 2 20 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 80038E. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical.
The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:
The module offers ECDH shared secret computation services compliant to the SP 800-56ARev3 and meeting IG D.F scenario 2 path (1). To meet the required assurances listed in section 5.6 of SP 800-56ARev3, the module shall be used together with an application that implements the “TLS protocol” and the following steps shall be performed.
18 of 44
| Name | Type | Properties |
|---|---|---|
| ECDSA | CKG | EC: P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength Method: FIPS 186-5 A.2.2 Rejection Sampling using a DRBG compliant with SP800-90Arev1, per SP800-133Rev2 section 4 (without any V, as described in Additional Comments 2 of IG D.H) and SP800-133Rev2 section 5.1 and 5.2 |
| RSA | CKG | RSA: 2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. Method: FIPS 186-5 A.1.3 Random Probable Primes using a DRBG compliant with SP800- 90Arev1, per SP800-133Rev2 section 4 (without any V, as described in Additional Comments 2 of IG D.H) and SP800-133Rev2 section 5.1 |
| KDA HKDF | Key Derivation | Key type: Symmetric key; Security strength: 112-256 bits Method: SP 800-56Cr1; (HMAC) SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 per SP800-133Rev2 section 6.2 |
| PBKDF | Key Derivation | Key type: Symmetric key; Security strength: 112-256 bits Method: option 1a of SP 800-132; (HMAC) SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 per SP800-133Rev2 section 6.2 |
| SSH KDF (CVL) | Key Derivation | Key type: Symmetric key; Security strength: 112-256 bits Method: SP 800-135r1; AES-128, AES-192, AES-256 with SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512 per SP800-133Rev2 section 6.2 |
| KDF TLS (CVL) TLS 1.0/1.1, TLS 1.2 | Key Derivation | Key type: Symmetric key; Security strength: 112-256 bits Method: SP 800-135r1; MD5 (TLS 1.0/1.1 only), SHA2-256, SHA2-384, SHA2-512 per SP800-133Rev2 section 6.2 |
Following IG C.F, RSA SigGen (FIPS 186-5) and RSA SigVer (FIPS 186-4 and FIPS 186-5) have been CAVP tested with all supported approved RSA modulus lengths (i.e., 1024 (SigVer only), 2048, 3072, 4096). This is documented in the Approved Algorithms table. There are no modulus sizes available in approved services which have not been CAVP tested. The minimum number of the Miller-Rabin tests used in primality testing is consistent with Table B.1 in FIPS 186-5.
The cryptographic module implements the following cryptographic algorithms for legacy use: • RSA SigVer (FIPS 186-4) with 1024-bit keys.
The module provides an SP800-90Arev1-compliant Deterministic Random Bit Generator (DRBG) components of asymmetric keys, and random number generation. The DRBG receives a LOAD command with entropy obtained from inside the physical perimeter of the operational environment but outside of module's cryptographic boundary. This corresponds to scenario 2 (b) of IG 9.3.A. The calling application shall use an entropy source that meets the security strength required for the CTR_DRBG as shown in NIST SP 800-90Arev1, Table 3 and should return an error if minimum strength cannot be met. Per the IG 9.3.A requirement, the module includes the caveat "No assurance of the minimum strength of generated keys".
© 2024 Amazon Web Services, Inc., atsec information security.
19 of 44
(RFC 7627)
| Name | Type | Properties | |
|---|---|---|---|
| KAS-ECC-SSC [SP800-56Arev3] | KAS (Shared Secret Computation) | Curves: P-224, P-256, P-384, P-521 elliptic curves with 112-256 bits of key strength Compliant with IG D.F scenario 2(1) | |
| AES GCM [SP 800-38D] | KTS (Key wrapping, Key unwrapping) | 128 and 256 bits with 128 and 256 bits of key strength Compliant with IG D.G | |
| AES CCM [SP 800-38C] | 128 bits with 128 bits of key strength Compliant with IG D.G | ||
| AES KW, AES KWP [SP 800-38F] | 128, 192, 256 bits with 128-256 bits of key strength Compliant with IG D.G |
The module implements the SSH key derivation function for use in the SSH protocol (RFC 4253 and RFC 6668). GCM with internal IV generation in the approved mode is compliant with versions 1.2 and 1.3 of the TLS protocol (RFC 5288 and 8446) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the following key derivation functions for use in the TLS protocol:
20 of 44
| Logical Interface | Data that passes over port/interface |
|---|---|
| Data Input | API input parameters for data. |
| Data Output | API output parameters for data. |
| Control Input | API function calls. |
| Status Output | API return codes, error message. |
As a Software module, the module interfaces are defined as Software or Firmware Module Interfaces (SMFI), and there are no physical ports. Table 12: Ports and Interfaces 1
1 The control output interface is omitted on purpose because the module does not implement it. The physical ports are not
applicable because the module is software only. © 2024 Amazon Web Services, Inc., atsec information security.
21 of 44
| Name | Type | Operator Type | Authentication | ||||
|---|---|---|---|---|---|---|---|
| Crypto Officer | Role | CO | N/A (Implicitly assumed) |
| Name | Description | Indicator | Inputs | Outputs | Security Functions | Roles | SSP Access |
|---|---|---|---|---|---|---|---|
| Encryption | Encryption | Return value 1 from the function: FIPS_ service_ indicator_ check_appr oved() | AES key, plaintext | Ciphertext | AES-CBC, AES- CTR, AES-ECB, AES-XTS listed in Table 5 | CO | AES Key: W, E |
| Decryption | Decryption | AES key, ciphertext | Plaintext | ||||
| Authenticated Encryption | Authenticated Encryption | AES key, IV, plaintext | Ciphertext, MAC tag | AES-CCM, AES-GCM listed in Table 5 | AES Key: W, E | ||
| Authenticated Decryption | Authenticated Decryption | AES key, ciphertext, MAC tag, IV | Plaintext | ||||
| Key wrapping | Encrypting a key | AES key wrapping key, Key to be wrapped | Wrapped key | AES-KW, AES- KWP, AES-CCM, AES-GCM | AES key: W, E | ||
| Key unwrapping | Decrypting a key | AES key unwrapping key | Unwrapped key | AES-KW, AES- KWP, AES-CCM, AES-GCM | AES key: W, E | ||
| Message Authentication Generation | MAC computation | AES key, message | MAC tag | AES-CMAC, AES-GMAC | AES Key: W, E | ||
| HMAC key, message | HMAC | HMAC Key: W, E | |||||
| Message Digest | Generating message digest | Message | Message digest | SHA | N/A | ||
| Random Number Generation | Generating random numbers | Output length | Random bytes | CTR_DRBG | Entropy Input: W, E DRBG Seed: G, E DRBG Internal State (V, Key): G, E | ||
| Key Generation | Generating key pair | Modulus size | Module generated RSA public key, Module generated RSA private key | RSA listed in Table 5, CKG | Module generated RSA Public Key: G, R Module generated RSA Private Key: G, R Intermediate Key Generation Value: G, E, Z |
The module does not support authentication. The module does not support concurrent operators.
Z © 2024 Amazon Web Services, Inc., atsec information security.
22 of 44
Name Key Verification Signature Generation Signature Verification Shared Secret Computation Key Derivation Zeroization On-Demand Self-test On-Demand Integrity Test
Description Verifying the public key Generating signature Verifying signature Calculating the Shared Secret Deriving Keys Zeroize PSP in volatile memory Initiate power-on self-tests by reset Initiate integrity test on-demand
Indicator N/A
Inputs Curve EC Public key Message, EC private key or RSA private key Signature, EC public key or RSA public key EC public key, EC private key TLS Pre- Master Secret TLS Master Secret Password, salt, iteration count Shared Secret, Key Length, Digest Shared Secret, Key Length SSP N/A N/A
Outputs Module generated EC public key, Module generated EC private key Success/ error Digital signature Digital signature verification result Shared Secret TLS Master secret TLS Derived Key (AES/HMAC) PBKDF Derived Key KDA HKDF Derived Key SSH KDF Derived Key N/A Pass or fail
Security Functions ECDSA listed in Table 5, CKG ECDSA listed in Table 5 RSA, ECDSA listed in Table 5 RSA, ECDSA listed in Table 5 KAS-ECC-SSC TLS KDF (CVL) TLS 1.0/1.1, TLS 1.2 TLS KDF (CVL) TLS 1.0/1.1, TLS 1.2 (RFC 7627) PBKDF2 KDA HKDF SSH KDF None AES, HMAC, SHA, CTR_DRBG, RSA, ECDSA, KAS-ECC-SSC, TLS KDF (CVL) TLS 1.0/1.1, TLS 1.2, KDA HKDF, PBKDF2 HMAC-SHA2- 256
Roles
SSP Access Module generated EC Public Key: G, R Module generated EC Private Key: G, R Intermediate Key Generation Value: G, E, Z EC Public Key: W, E EC Private Key: W, E RSA Private Key: W, E EC Public Key: W, E RSA Public Key: W, E EC Public Key: W, E EC Private Key: W, E Shared Secret: G, R TLS Pre-Master Secret: W, E TLS Master Secret: G TLS Master Secret: E TLS Derived Key (AES/HMAC): G, R PBKDF Derived Key: G, R Password: W, E KDA HKDF Derived Key: G, R Shared Secret: W, E SSH KDF Derived Key: G, R Shared Secret: W, E All SSPs: Z N/A N/A
Z © 2024 Amazon Web Services, Inc., atsec information security.
23 of 44
Name Show Status Show Version
Description Show status of the module state Show the version of the module using awslc_versi on_string
Indicator
Inputs N/A N/A
Outputs Module status Module name and version
Security Functions N/A N/A
Roles
SSP Access N/A N/A
| Service | Description | Algorithms Accessed | Role | Indicator |
|---|---|---|---|---|
| Encryption | Encryption | AES listed in Table 8 | CO | Return value 0 from the function FIPS_ service_ indicator_ check_ approved() |
| Decryption | Decryption | |||
| Message Authentication Generation | MAC computation | AES GMAC and HMAC listed in Table 8 | ||
| Message Digest | Generating message digest | MD4, MD5 outside TLS 1.0 usage, SHAKE, SHA-3, RIPEMD-160 | ||
| Signature Generation | Generating signature | Using SHA-1, SHAKE, SHA-3 |
Table 14: Approved Services For the above table, the convention below applies when specifying the access permissions (types) that the service has for each SSP.
© 2024 Amazon Web Services, Inc., atsec information security.
24 of 44
Service Signature Verification Key Generation Shared Secret Computation Key Derivation Key Encapsulation Key Un-encapsulation Encryption Primitive
Description Verifying signature Generating key pair Calculating shared secret Deriving TLS keys Decrypting a key Encrypting a key Asymmetric encryption
Algorithms Accessed RSA listed in Table 8, Curve secp256k1 RSA listed in Table 8, Curve secp256k1 RSA or ECDSA listed in Table 8 Diffie-Hellman, Curve secp256k1 TLS KDF listed in Table 8 RSA RSA RSA with PKCS#1 v1.5 and OAEP padding
Role
Indicator
Table 15: Non-Approved Services
The module does not support loading of external software or firmware. © 2024 Amazon Web Services, Inc., atsec information security.
25 of 44
The integrity of the module is verified by comparing a HMAC value calculated at run time on the bcm.o file, with the HMAC-SHA2-256 value stored within the module that was computed at build time.
The module provides on-demand integrity test. The integrity test can be performed on demand by reloading the module. Additionally, the integrity test can be performed using the On-Demand Integrity Test service, which calls the BORINGSSL_integrity_test function. © 2024 Amazon Web Services, Inc., atsec information security.
26 of 44
Type of Operational Environment: The module operates in a modifiable operational environment. The module runs on a commercially available general-purpose operating system executing on the hardware specified in section
Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2024 Amazon Web Services, Inc., atsec information security.
27 of 44
The module is comprised of software only and therefore this section is not applicable. © 2024 Amazon Web Services, Inc., atsec information security.
28 of 44
The module claims no non-invasive security techniques. © 2024 Amazon Web Services, Inc., atsec information security.
29 of 44
| Storage Area Name | Description | Persistence Type | |||
|---|---|---|---|---|---|
| RAM | Temporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPs | Dynamic |
| Name | From | To | Format Type | Distribution Type | Entry Type |
|---|---|---|---|---|---|
| API input parameters | Operator calling application (TOEPP) | Cryptographic module | Plaintext | Manual (MD) | Electronic (EE) |
| API output parameters | Cryptographic module | Operator calling application (TOEPP) | Plaintext | Manual (MD) | Electronic (EE) |
| Zeroization Method | Description | Rationale | Operator Initiation |
|---|---|---|---|
| Free Cipher Handle | Zeroizes the SSPs contained within the cipher handle. | Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. | By calling the appropriate zeroization functions: OpenSSL_cleanse, EVP_CIPHER_CTX_cleanup, EVP_AEAD_CTX_zero, HMAC_CTX_cleanup, CTR_DRBG_clear, RSA_free, EC_KEY_free |
| Module Reset | De-allocates the volatile memory used to store SSPs | Volatile memory used by the module is overwritten within nanoseconds when power is removed. | By unloading and reloading the module. |
| Name | Description | Size | Strength | Type | Generation | Established By |
|---|---|---|---|---|---|---|
| AES Key | AES key used for encryption, decryption, and computing MAC tags | 128, 192, 256 bits | 128-256 bits of strength | Symmetric key | N/A | N/A |
Table 16: Storage Areas operational environment. The SSPs are provided to the module via API input parameters in the application running on the same operational environment.
Table 18: Zeroization Methods © 2024 Amazon Web Services, Inc., atsec information security.
30 of 44
| Name | Description | Size | Strength | Type | Generation | Established By |
|---|---|---|---|---|---|---|
| HMAC Key | HMAC key for Message Authentication Generation | 112-524288 bits | 112-256 bits of strength | Authentication key | N/A | N/A |
| Entropy Input (per IG D.L) | Entropy input used to seed the DRBGs | 256 bits | 256 bits of strength | Entropy | N/A | N/A |
| DRBG Seed (per IG D.L) | DRBG seed derived from entropy input as defined in SP 800-90Ar1 | 256 bits | 256 bits of strength | DRBG seed | CTR_DRBG (according to SP800- 90Arev1) | N/A |
| DRBG Internal State (V, Key) (per IG D.L) | Internal state of CTR_DRBG | 256 bits | 256 bits of strength | Internal state | CTR_DRBG (derived from DRBG seed according to SP800-90Ar1) | N/A |
| RSA Public Key | RSA public key used for signature verification | 1024, 2048, 3072, 4096 bits | 80-150 bits of strength | Public key | N/A | N/A |
| RSA Private Key | RSA private key used for signature generation | 2048, 3072, 4096 bits | 112-150 bits of strength | Private key | N/A | |
| Module generated RSA Public Key | RSA public key generated by the module | 112-50 bits of strength | Public key | RSA (generated according to FIPS 186-5) DRBG (for generation of random values) | ||
| Module generated RSA Private Key | RSA private key generated by the module | 112-150 bits of strength | Private key | |||
| EC Public Key | EC public key used for key verification, signature verification, shared secret computation | P-224, P-256, P-384, P-521 | 112-256 bits of strength | Public key | N/A | N/A |
| EC Private Key | EC private key used for signature generation, shared secret computation | Private key | N/A | |||
| Module generated EC Public Key | EC public key generated by the module | Public key | ECDSA (generated according to FIPS 186-5) DRBG (for generation of random values) | N/A | ||
| Module generated EC Private Key | EC private key generated by the module | Private key | N/A | |||
| Shared Secret | Shared Secret generated by KAS- ECC-SSC | Shard secret | N/A | KAS-ECC-SSC (established according to SP800- 56Arev3) | ||
| TLS Pre-Master Secret | TLS Pre-Master secret used for deriving the TLS Master Secret | P-224, P-256, P-384, P-521 | 112-256 bits | TLS pre-master secret | N/A | N/A |
| TLS Master Secret | TLS Master secret used for deriving the TLS Derived Key | 384 bits | 112-256 bits | TLS master secret | KDF TLS (CVL) TLS 1.0/1.1, TLS 1.2 (RFC 7627) (derived | N/A |
© 2024 Amazon Web Services, Inc., atsec information security.
31 of 44
| Name | Description | Size | Strength | Type | Generation | Established By |
|---|---|---|---|---|---|---|
| TLS Derived key (AES/HMAC) | TLS Derived Key from TLS Master Secret | AES: 128-256 bits HMAC: 112 to 256 bits | AES: 128-256 bits of strength HMAC: 112-256 bits of strength | Symmetric key | according to SP800- 135rev1) | N/A |
| KDA HKDF derived key | KDA HKDF derived key | 112 to 2048 bits | 112-256 bits of strength | Symmetric key | KDA HKDF (derived according to SP800- 56Crev1) | N/A |
| SSH KDF derived key | SSH KDF derived key | 112 to 256 bits | SSH KDF (CVL) (derived according to SP800- 135rev1) | |||
| PBKDF derived key | PBKDF derived key | 112–4096 bits | PBKDF (derived according to SP800-132) | |||
| Password | Password for PBKDF | 112-1024 bits | N/A | Password | N/A | N/A |
| Intermediate Key Generation Value | Intermediate key generation value | 224-4096 bits | 112-256 bits of strength | Intermediate value | CKG | N/A |
| Name | Used By | Inputs/Outputs | Storage | Zeroization | Category | Related SSPs |
|---|---|---|---|---|---|---|
| AES Key | Encryption, Decryption, Authenticated Encryption, Authentication Decryption, Key wrapping, Key unwrapping, Message Authentication Generation | API input parameters (input) | RAM | Free Cipher Handle, Module Reset | CSP | None |
| HMAC Key | Message Authentication Generation | API input parameters (input) | CSP | None | ||
| Entropy Input (per IG D.L) | Random Number Generation | API input parameters (input) | Automatically | CSP | DRBG Seed | |
| DRBG Seed (per IG D.L) | Random Number Generation | N/A | CSP | Entropy Input, DRBG Internal State (V, Key) | ||
| DRBG Internal State (V, Key) (per IG D.L) | Random Number Generation | N/A | Free Cipher Handle, Module Reset | CSP | DRBG Seed | |
| RSA Public Key | Signature Verification | API input parameters (input) | PSP | RSA Private Key | ||
| RSA Private Key | Signature Generation | CSP | RSA Public Key |
Table 19: SSP Information First © 2024 Amazon Web Services, Inc., atsec information security.
32 of 44
Name Module generated RSA Public Key Module generated RSA Private Key EC Public Key EC Private Key Module generated EC Public Key Module generated EC Private Key Shared Secret TLS Pre-Master Secret TLS Master Secret TLS Derived Key (AES/HMAC) KDA HKDF Derived Key SSH KDF Derived Key PBKDF Derived Key
Used By N/A N/A Key Verification, Signature Verification, Shared Secret Computation Signature Generation, Shared Secret Computation EC Public Key generated by the module EC Private Key generated by the module Key Derivation Key Derivation Key Derivation N/A
Inputs/Outputs API output parameters (output) API input parameters (input) API output parameters (output) API output parameters (output) API input parameters (input) N/A API output parameters (output)
Storage
Zeroization
Category PSP CSP PSP CSP PSP CSP CSP CSP CSP CSP CSP CSP CSP
Related SSPs Module generated RSA Private Key, Intermediate Key Generation Value Module generated RSA Public Key, Intermediate Key Generation Value EC Private Key, Shared Secret EC Public Key, Shared Secret Module generated EC Private Key, Intermediate Key Generation Value Module generated EC Public Key, Intermediate Key Generation Value EC Public Key, EC Private Key TLS Master Secret TLS Pre-Master Secret, TLS Derived Key (AES/HMAC) TLS Master Secret Shared Secret Shared Secret Password
© 2024 Amazon Web Services, Inc., atsec information security.
33 of 44
Name Password Intermediate Key Generation Value
Used By Key Generation
Inputs/Outputs API input parameters (input) N/A
Storage
Zeroization Automatically
Category CSP CSP
Related SSPs PBKDF Derived Key Module generated RSA Private Key, Module generated RSA Public Key, Module generated EC Private Key, Module generated EC Public Key
Table 20: SSP Information Second
The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2030. © 2024 Amazon Web Services, Inc., atsec information security.
34 of 44
| Algorithm | Implementation | Test Properties | Test Method | Test Type | Indicator | Details |
|---|---|---|---|---|---|---|
| HMAC-SHA2-256 | SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 | SHA2-256 | Message Authentication | Software Integrity | Module becomes operational | N/A |
| Algorithm or Test | Test Properties | Test Method | Type | Indicator | Details | Condition | Coverage | Coverage Notes |
|---|---|---|---|---|---|---|---|---|
| AES CBC AES GCM AES_C, AES_C_GCM, AESNI, AESNI_AVX, AESNI_ASM, AESAESM, AESASM_AVX, AESASM_CLMULNI, AESASM_ASM, CE, CE_GCM_UNROLL8_E OR3, CE_GCM, VPAES, VPAES_GCM, AESNI_CLMULNI, BAES_CTASM, BAES_CTASM_AVX, BAES_CTASM_CLMUL NI, BAES_CTASM_ASM | 128-bit AES key | Encrypt KAT for CBC | CAST | Module is operational | Encrypt | Power up | Self | N/A |
| Decrypt KAT for CBC | Decrypt | Self and ECB, KW, KWP, XTS (all implementatio ns) | IG 10.3.A, resolution 1.c | |||||
| Encrypt KAT for GCM | Encrypt | Self and CCM, CMAC, CTR, ECB, GMAC, KW, KWP, XTS all implementatio ns) | IG 10.3.A, resolution 1.d.(i) | |||||
| Decrypt KAT for GCM | Decrypt | Self | N/A | |||||
| SHA-1 SHA2-256 SHA2-512 SHA_CE, SHA_ASM, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 | N/A | SHA-1 KAT | CAST | Message digest | Power up | Self | N/A | |
| SHA2-256 KAT | Self and SHA2- 224 all implementatio ns) | IG 10.3.A, resolution 2 | ||||||
| SSH KDF (all implementatio ns) | IG 10.3.A, resolution 12, note 18 | |||||||
| SHA2-512 | Self and SHA2- | IG 10.3.A, |
Table 21: Pre-Operational Self-Tests The module performs the pre-operational self-test automatically when the module is loaded into memory; the pre-operational self-test is the software integrity test that ensures that the module is not corrupted. While the module is executing the pre-operational self-test, services are not available, and input and output are inhibited. The software integrity test is performed after a set of conditional cryptographic algorithm selftests (CASTs). The set of CASTs includes the self-test for HMAC-SHA2-256 algorithm used in the
© 2024 Amazon Web Services, Inc., atsec information security.
35 of 44
Algorithm or Test HMAC SHA_CE, SHA_ASM, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 CTR_DRBG AES_C, AESNI, AESASM, AESASM_AVX, CE, VPAES, BAES_CTASM ECDSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 ECDSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 KAS-ECC-SSC C ECDSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 KDF TLS (CVL) SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 KDA HKDF SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 PBKDF2 SHA_ASM, SHA_CE,
Test Properties SHA2-256 AES 256 N/A P-256 Curve and SHA2- 256 P-256 Curve and SHA2- 256 P-256 Curve Respective Curve and SHA2-256 SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256
Test Method KAT HMAC KAT CTR_DRB G KAT SP800- 90Ar1 Section 11.3 Health Test Sign KAT Verify KAT Z computati on Signature generatio n and verificatio n TLS 1.2 KAT KAT KAT
Type CAST CAST CAST PCT CAST CAST CAST
Indicator
Details Message authenticati on Seed Generation Seed Generation Sign Verify Shared secret computation Sign and Verify Key derivation Key derivation Key derivation
Condition Power up Power up Power up Signature Generation or Key Generation service request Signature verification or Key Generation service request Shared secret computatio n request Key generation Power up Power up Power up
Coverage 384, SHA2- 512/256 (all implementatio ns) Self and HMAC-SHA-1, HMAC-SHA2- 224, HMAC-SHA2- 384, HMAC-SHA2- 512, HMAC-SHA2- 512/256 Self Self Self Self Self Self and KAS- ECC-SSC PCT Self Self Self
Coverage Notes resolution 2 IG 10.3.A resolution 5 N/A N/A N/A N/A N/A IG 10.3.A additional comment 1. N/A N/A N/A
© 2024 Amazon Web Services, Inc., atsec information security.
36 of 44
Algorithm or Test NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 RSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 RSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 RSA SHA_ASM, SHA_CE, NEON, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3
Test Properties PKCS#1 v1.5 with 2048 bit key and SHA2-256 PKCS#1 v1.5 with 2048 bit key and SHA2-256 SHA2-256 and respective keys
Test Method Sign KAT Verify KAT Signature generatio n and verificatio n
Type CAST CAST PCT
Indicator
Details Sign Verify Sign and Verify
Condition Signature Generation or Key Generation service request Signature Verification or Key Generation service request Key generation
Coverage Self Self Self
Coverage Notes N/A N/A N/A
| Name | Description | Condition | Recovery Method | Status Indicator |
|---|---|---|---|---|
| Error | The library is aborted with SIGABRT signal. Module is no longer operational the data output | Pre-operational test failure | Module reset | Error message is output on the stderr and then the module is aborted. |
| Conditional test failure | Module reset | For CAST failure, an error message is output on the stderr and then the module is aborted. For PCT failure, an error message is output in the error queue and then |
Table 22: Conditional Self-Tests
The module performs self-tests on approved cryptographic algorithms, using the tests shown in Table 22. Data output through the data output interface is inhibited during the self-tests. The CASTs are performed in the form of Known Answer Tests (KATs), in which the calculated output is compared with the expected known answer (that are hard coded in the module). A failed match causes a failure of the self-test. If any of these self-tests fails, the module transitions to error state.
pairwise consistency test (PCT) using sign and verify functions when the keys are generated (Table 22). If any of these self-tests fails, the module transitions to error state and is aborted.
The module does not support periodic self-tests.
© 2024 Amazon Web Services, Inc., atsec information security.
37 of 44
Name
Description interface is inhibited
Condition
Recovery Method
Status Indicator the module generates new key, If the PCT still does not pass, eventually the module will be aborted after 5 tries.
Table 23: Error States If the module fails any of the self-tests, the module enters the error state. To recover from the Error state, the module needs to be rebooted.
The software integrity tests and the CASTs for AES, SHA, DRBG, KAS-ECC-SSC, TLS KDF, KDA HKDF, PBKDF2 can be invoked by unloading and subsequently re-initializing the module. The CASTs for ECDSA and RSA can be invoked by requesting the corresponding Key Generation or Digital Signature services. Additionally, all the CASTs can be invoked by calling the BORINGSSL_self_test function. The PCTs can be invoked on demand by requesting the Key Generation service. © 2024 Amazon Web Services, Inc., atsec information security.
38 of 44
The module bcm.o is embedded into the shared library libcrypto.so which can be obtained by building the source code at the following location [1]. The set of files specified in the archive constitutes the complete set of source files of the validated module. There shall be no additions, deletions, or alterations of this set as used during module build. [1] https://github.com/aws/aws-lc/archive/refs/tags/AWS-LC-FIPS-2.0.0.zip. The downloaded zip file can be verified by issuing the “sha256sum AWS-LC-FIPS-2.0.0.zip” command. The expected SHA2-256 digest value is: 6241EC2F13A5F80224EE9CD8592ED66A97D426481066FEAA4EFC6F24E60BBC96 After the zip file is extracted, the instructions listed below will compile the module. The compilation instructions must be executed separately on platforms that have different processors and/or operating systems. Due to six possible combinations of OS/processor, the module count is six (i.e., there are six separate binaries generated, one for each entry listed in Table 3). Amazon Linux 2 and Amazon Linux 2023: 1. sudo yum groupinstall "Development Tools" 2. sudo yum install cmake3 golang 3. cd aws-lc-fips-2022-11-02/ 4. mkdir build 5. cd build 6. cmake3 -DFIPS=1 -DCMAKE_BUILD_TYPE=Release -DBUILD_SHARED_LIBS=1 .. 7. make Ubuntu 22.04: 1. sudo apt-get install build-essential 2. sudo apt-get install cmake 3. Get latest Golang archive for your architecture 4. sudo tar -C /usr/local -xzf go*.tar.gz 5. cd aws-lc-fips-2022-11-02/ 6. mkdir build 7. cd build 8. cmake -DFIPS=1 -DCMAKE_BUILD_TYPE=Release -DBUILD_SHARED_LIBS=1 -DGO_EXECUTABLE=/usr/local/go/bin/go .. 9. make Upon completion of the build process, the module’s status can be verified by the command below. If the value obtained is “1” then the module has been installed and configured to operate in FIPS compliant manner. ./tool/bssl isfips © 2024 Amazon Web Services, Inc., atsec information security.
39 of 44
Lastly, the user can call the “show version” service using awslc_version_string function and the expected output is “AWS-LC FIPS 2.0.0” which is the module version. This will confirm that the module is in the operational mode. Additionally, the “AWS-LC FIPS” also acts as the module identifier and the verification of the "dynamic" part can be done using following command with an application that was used for dynamic linking. The "U" in the output confirms that the module is dynamically linked. Command: nm <application_name> | grep awslc_version_string Example Output: “ U awslc_version_string”
When the module is at end of life, for the GitHub repo, the README will be modified to mark the library as deprecated. After a 6-month window, more restrictive branch permissions will be added such that only administrators can read from the FIPS branch. The module does not possess persistent storage of SSPs. The SSP value only exists in volatile memory and that value vanishes when the module is powered off. So as a first step for the secure sanitization, the module needs to be powered off. Then for actual deprecation, the module will be upgraded to newer version that is approved. This upgrade process will uninstall/remove the old/terminated module and provide a new replacement. © 2024 Amazon Web Services, Inc., atsec information security.
40 of 44
RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack. The module provides the mechanism to use the blinding for RSA. When the blinding is on, the module generates a random value to form a blinding factor in the RSA key before the RSA key is used in the RSA cryptographic operations. © 2024 Amazon Web Services, Inc., atsec information security.
41 of 44
AES Advanced Encryption Standard AESNI Advanced Encryption Standard New Instructions CAVP Cryptographic Algorithm Validation Program CAST Cryptographic Algorithm Self-Test CBC Cipher Block Chaining CCM Counter with Cipher Block Chaining-Message Authentication Code CFB Cipher Feedback CMAC Cipher-based Message Authentication Code CMVP Cryptographic Module Validation Program CSP Critical Security Parameter CTR Counter Mode DRBG Deterministic Random Bit Generator ECB Electronic Code Book ECC Elliptic Curve Cryptography FIPS Federal Information Processing Standards Publication GCM Galois Counter Mode HMAC Hash Message Authentication Code KAT Known Answer Test KW AES Key Wrap KWP AES Key Wrap with Padding MAC Message Authentication Code NIST National Institute of Science and Technology OFB Output Feedback OS Operating System PAA Processor Algorithm Acceleration PCT Pair-Wise Consistency Test PR Prediction Resistance PSP Public Security Parameter PSS Probabilistic Signature Scheme RNG Random Number Generator RSA Rivest, Shamir, Addleman SHA Secure Hash Algorithm © 2024 Amazon Web Services, Inc., atsec information security.
42 of 44
FIPS140-3 FIPS PUB 140-3 - Security Requirements for Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS140-3_IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program August 2023 https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips140-3-ig-announcements FIPS180-4 Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf FIPS186-4 Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf FIPS186-5 Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf FIPS197 Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf FIPS198-1 The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf PKCS#1 Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt SP800-38A Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf SP800-38B NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf SP800-38C NIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038c.pdf © 2024 Amazon Web Services, Inc., atsec information security.
43 of 44
SP800-38D NIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf SP800-38F NIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf SP800-56Arev3 NIST Special Publication 800-56A Revision 2 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography May 2013 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar2.pdf SP800-90Arev1 NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf SP800-131Arev1 NIST Special Publication 800-131A Revision 1- Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths November 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar1.pdf SP800-133rev2 NIST Special Publication 800-133rev2 - Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf SP800-135rev1 NIST Special Publication 800-135 Revision 1 - Recommendation for Existing Application-Specific Key Derivation Functions December 2011 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800135r1.pdf © 2024 Amazon Web Services, Inc., atsec information security.
44 of 44