All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Cradlepoint Cryptographic Module

Certificate#4770StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorEricsson Enterprise Wireless Solutions, Inc.
Low review priority  ·  no TCB surface named  ·  last validated 4 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date8/19/2026
CaveatInterim Validation, No assurance of the minimum strength of generated keys
VendorEricsson Enterprise Wireless Solutions, Inc.

Approved Algorithms (33)

AlgorithmACVP Cert
AES-CBCA2584
AES-CTRA2584
AES-ECBA2584
Counter DRBGA2584
DSA KeyGen (FIPS186-4)A2584
DSA PQGGen (FIPS186-4)A2584
DSA PQGVer (FIPS186-4)A2584
DSA SigGen (FIPS186-4)A2584
DSA SigVer (FIPS186-4)A2584
ECDSA KeyGen (FIPS186-4)A2584
ECDSA KeyVer (FIPS186-4)A2584
ECDSA SigGen (FIPS186-4)A2584
ECDSA SigVer (FIPS186-4)A2584
HMAC-SHA-1A2584
HMAC-SHA2-224A2584
HMAC-SHA2-256A2584
HMAC-SHA2-384A2584
HMAC-SHA2-512A2584
KAS-ECC-SSC Sp800-56Ar3A2584
KAS-FFC-SSC Sp800-56Ar3A2584
PBKDFA2584
RSA KeyGen (FIPS186-4)A2584
RSA SigGen (FIPS186-4)A2584
RSA SigVer (FIPS186-4)A2584
Safe Primes Key GenerationA2584
SHA-1A2584
SHA2-224A2584
SHA2-256A2584
SHA2-384A2584
SHA2-512A2584
TDES-CBCA2584
TDES-ECBA2584
TLS v1.2 KDF RFC7627A2584

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Cradlepoint Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>HTTPS<br/>library named: openssl</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C3,C5,C6 clue;
  class I3,I5,I6 infer;
  class R3,R5,R6 risk;
  class E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Cradlepoint Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>HTTPS<br/>library named: openssl</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Ericsson Enterprise Wireless Solutions, Inc. Ericsson Cradlepoint Cryptographic Module Software Version: 1.0 FIPS Security Level: 1 Document Version: 0.6 Prepared for: Prepared by: Ericsson Enterprise Wireless Corsec Security, Inc. Solutions, Inc.

1100 W. Idaho Street, Suite 800 12600 Fair Lakes Circle, Suite 210

Boise, ID 83702-5389 Fairfax, VA 22033 United States United States of America Phone: +1 855 813 3385 Phone: +1 703 267 6050 www.cradlepoint.com www.corsec.com

Page 2

Abstract This is a non-proprietary Cryptographic Module Security Policy for the Ericsson Cradlepoint Cryptographic Module (version: 1.0) from Ericsson Enterprise Wireless Solutions, Inc. (Ericsson). This Security Policy describes how the Ericsson Cradlepoint Cryptographic Module meets the security requirements of Federal Information Processing Standards (FIPS) Publication 140-3, which details the U.S. and Canadian government requirements for cryptographic modules. More information about the FIPS 140-3 standard and validation program is available on the National Institute of Standards and Technology (NIST) and the Canadian Centre for Cyber Security (CCCS) Cryptographic Module Validation Program (CMVP) website at http://csrc.nist.gov/groups/STM/cmvp. This document also describes how to run the module in its Approved mode of operation. This policy was prepared as part of the Level 1 FIPS 140-3 validation of the module. The Ericsson Cradlepoint Cryptographic Module is referred to in this document as Cradlepoint Cryptographic Module or the module. References This document deals only with operations and capabilities of the module in the technical terms of a FIPS 140-3 cryptographic module security policy. More information is available on the module from the following sources:

Page 3
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1 – Security Level per FIPS 140-3 Section5
Table 2 – Tested Operational Environments6
Table 3 – Vendor-Affirmed Operational Environments6
Table 4 – Approved Algorithm Validation Certificates7
Table 5 – Non-Approved Algorithms Allowed in the Approved Mode of Operation10
Table 6 – Ports and Interfaces13
Table 7 – Roles, Service Commands, Input and Output14
Table 8 – Approved Services15
Table 9 – Keys21
Table 10 – Other SSPs22
Table 11 – Acronyms and Abbreviations30
Figure 1 – GPC Block Diagram11
Figure 2 – Module Block Diagram (with Cryptographic Boundary)12
Page 5
’s NetCloud™
platform and cellular routers deliver a pervasive, secure, and software-defined Wireless WAN1 edge to connect
people, places, and things – anywhere. More than 28,500 businesses and government agencies worldwide,
including many Global 2000 organizations and top public sector agencies, rely on sites, points of commerce, field forces, vehicles, and IoT2 devices always connectedto keep mission-critical
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical SecurityN/A
8Non-Invasive SecurityN/A
9Sensitive Security Parameter Management1
10Self-tests1
11Life-Cycle Assurance1
12Mitigation of Other AttacksN/A

Ericsson is a global leader in cloud-delivered 4G and 5G wireless network edge solutions. Ericsson’s NetCloud™ Ericsson’s NetCloud for Branch makes it easy to accelerate connecting to the Internet and critical applications from anywhere. Designed for traditional medium branches or locations requiring flexible connectivity, reliable performance, and simplified management, this all-in-one, compact endpoint includes full-featured routing, security, and Wi-Fi without needing extra hardware or complicated configurations. The Ericsson Cradlepoint Cryptographic Module version 1.0 is a cryptographic library as part of the NetCloud operating system (OS) kernel that provides cryptographic services for Ericsson endpoints. The module offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and SSP establishment functions to secure dataat-rest/data-in-flight and to support secure communications protocols (including TLS 3 1.2). The Ericsson Cradlepoint Cryptographic Module is validated at the FIPS 140-3 section levels shown in Table 1. The module has an overall security level of 1.

1 WAN – Wide Area Network

2 IoT – Internet of Things

3 TLS – Transport Layer Security

Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 6
#Operating SystemHardware PlatformProcessorPAA/Acceleration
1NetCloud OS 7Cradlepoint E3000ARM Cortex-A (ARMv8-A)With
2NetCloud OS 7Cradlepoint E3000ARM Cortex-A (ARMv8-A)Without
#Operating SystemHardware Platform
1NetCloud OS 7Ericsson Cradlepoint R920
2NetCloud OS 7Ericsson Cradlepoint R2105/R2155
3NetCloud OS 7Ericsson Cradlepoint R1900
4NetCloud OS 7Ericsson Cradlepoint E300
5NetCloud OS 7Ericsson Cradlepoint S700/S750
6NetCloud OS 7Ericsson Cradlepoint R980
7NetCloud OS 7Ericsson Cradlepoint E400
8NetCloud OS 7Ericsson Cradlepoint S400/S450
9NetCloud OS 7Ericsson Cradlepoint R2400

2. Cryptographic Module Specification The Ericsson Cradlepoint Cryptographic Module (version 1.0) is a software module with a multi-chip standalone embodiment. The module is designed to operate within a modifiable operational environment.

2.1 Operational Environments

The module was tested and found to be compliant with FIPS 140-3 requirements on the environment listed in Table

  1. Table 2 – Tested Operational Environments Each test environment includes a Qualcomm 802.11ax SoC 4 with four ARM Cortex-A processing cores. These processing cores support the ARMv8 Cryptography Extensions. The Cryptography Extensions include A64, A32, and T32 instructions for accelerating AES and SHA implementations. The module is designed to utilize the extended instruction sets when available. The vendor affirms the module’s continued validation compliance when operating on the environments listed in Table
  2. Table 3 – Vendor-Affirmed Operational Environments The cryptographic module maintains validation compliance when operating on any general-purpose computer (GPC) provided that the GPC uses any single-user operating system/mode specified on the validation certificate,

4 SoC – System on a Chip

Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 7
CAVP Certificate5Algorithm and StandardMode / MethodDescription / Key Size(s) / Key StrengthsUse / Function
A2584AES FIPS PUB6 197 NIST SP 800-38ACBC7, CTR8, ECB9128, 192, 256Encryption/decryption
Vendor AffirmedCKG10 NIST SP 800-133rev2--Cryptographic key generation
A2584CVL11 NIST SP 800-135rev1TLS12 1.2 KDF-Key derivation13
A2584CVL RFC 7627TLS 1.2 KDF RFC7627-Key derivation14
A2584DRBG15 NIST SP 800-90Arev1Counter-basedAES-128, AES-192, AES- 256Deterministic random bit generation
A2584DSA16 FIPS PUB 186-4-2048/224, 2048/256Key pair generation
SHA2-2562048/224, 2048/256Domain parameter generation
SHA2-2562048/224, 2048/256Domain parameter verification
SHA2-2562048/224, 2048/256Digital signature generation
SHA-1, SHA2-2561024/160, 2048/224, 2048/256Digital signature verification
A2584ECDSA17 FIPS PUB 186-4Secret generation method: Testing candidatesP-224, P-256, P-384Key pair generation

or another compatible single-user operating system. The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when ported to an operational environment not listed on the validation certificate. The sections below describe the module boundary, modes of operation, and algorithm implementations.

2.2 Algorithm Implementations

Validation certificates for each Approved security function are listed in Table 4 below. Table 4 – Approved Algorithm Validation Certificates

5 This table includes vendor-affirmed algorithms that are approved but CAVP testing is not yet available.

6 PUB – Publication

7 CBC – Cipher Block Chaining

8 CTR – Counter

9 ECB – Electronic Code Book

11 CVL – Component Validation List

12 TLS – Transport Layer Security

No part of the TLS protocol, other than the KDF, has been tested by the CAVP and CMVP.

14 No part of the TLS protocol, other than the KDF, has been tested by the CAVP and CMVP.

15 DRBG – Deterministic Random Bit Generator

17 ECDSA – Elliptic Curve Digital Signature Algorithm

Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 8
CAVP Certificate5Algorithm and StandardMode / Method - - -Description / Key Size(s) / Key Strengths P-224, P-256, P-384 (SHA2-256, SHA2-384, SHA2-512) P-224, P-256, P-384 (SHA2-256, SHA2-384, SHA2-512) P-224, P-256, P-384 (SHA- 1, SHA2-224, SHA2-256, SHA2-384, SHA2-512)Use / Function Public key verification Digital signature generation Digital signature verification
A2584HMAC FIPS PUB 198-1SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512112 (minimum)Message authentication
A2584KAS18 NIST SP 800-56Arev3 NIST SP 800-135rev1 RFC 7627KAS-ECC-SSC with TLS 1.2 KDF RFC7627P-224, P-256, P-384Key agreement19 SSP establishment methodology provides between 112 and 256 bits of encryption strength.
KAS-FFC-SSC with TLS 1.2 KDF RFC7627FB, FC, MODP-2048, MODP-3072, MODP-4096Key agreement20 SSP establishment methodology provides 112 bits of encryption strength.
A2584KAS-ECC-SSC21 NIST SP 800-56Arev3EphemeralUnifiedP-224, P-256, P-384Shared secret computation
A2584KAS-FFC-SSC22 NIST SP 800-56Arev3dhEphemFB, FC, MODP-2048, MODP-3072, MODP-4096Shared secret computation
A2584KTS23 FIPS PUB 197 FIPS PUB 198-1AES with HMAC128, 192, 256Key wrap/unwrap (encryption//decryption with message authentication)24 SSP establishment methodology provides 112 bits of encryption strength.
A2584KTS NIST SP 800-67rev2 FIPS PUB 198-1Triple-DES25 with HMAC168 (KO1)Key unwrap (decryption with message authentication)26 SSP establishment methodology provides 168 bits of encryption strength.
A2584PBKDF227 NIST SP 800-132Section 5.4, option 1aSHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512Password-based key derivation

18 KAS – Key Agreement Scheme

19 Key agreement method complies with FIPS 140-3 Implementation Guidance D.F, scenario 2(1).

20 Key agreement method complies with FIPS 140-3 Implementation Guidance D.F, scenario 2(1).

21 KAS-ECC-SSC – Key Agreement Scheme - Elliptic Curve Cryptography - Shared Secret Computation

22 KAS-FFC-SSC – Key Agreement Scheme - Finite Field Cryptography - Shared Secret Computation

KTS – Key Transport Scheme

24 Per FIPS 140-3 Implementation Guidance D.G, AES in any Approved mode with HMAC is an Approved key transport technique.

25 DES – Data Encryption Standard

26 Per FIPS 140-3 Implementation Guidance D.G, Triple DES in any Approved mode with HMAC is an Approved key transport technique.

Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 9
CAVP Certificate5Algorithm and StandardMode / MethodDescription / Key Size(s) / Key StrengthsUse / Function
A2584RSA28 FIPS PUB 186-4Key generation mode: B.3.32048, 3072, 4096Key pair generation
ANSI X9.312048, 3072, 4096 (SHA2- 256, SHA2-384, SHA2-512)Digital signature generation
1024, 2048, 3072, 4096 (SHA-1, SHA2-256, SHA2- 384, SHA2-512)Digital signature verification
PKCS#1 v1.52048, 3072, 4096 (SHA2- 224, SHA2-256, SHA2-384, SHA2-512)Digital signature generation
1024, 2048, 3072, 4096 (SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512)Digital signature verification
PSS292048, 3072, 4096 (SHA2- 224, SHA2-256, SHA2-384, SHA2-512)Digital signature generation
1024, 2048, 3072, 4096 (SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512)Digital signature verification
A2584Safe Primes NIST SP 800-56Arev3, Appendix D-MODP-2048, MODP-3072, MODP-4096Key generation
A2584SHS30 FIPS PUB 180-4SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512-Message digest
A2584Triple-DES NIST SP 800-67rev2 NIST SP 800-38ACBC, ECB168 (KO1)Encryption/decryption The encrypt function is used only to support self-testing. During operation, it is not available in the Approved mode.

The vendor affirms the following cryptographic security methods:

28 RSA – Rivest Shamir Adleman

29 PSS – Probabilistic Signature Scheme

30 SHS – Secure Hash Standard

Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 10
AlgorithmCaveatUse / Function
AES (Cert. A2584)SSP establishment methodology provides between 128 and 256 bits of encryption strength.Key unwrapping (using any approved mode)
Triple-DES (Cert. A2584)SSP establishment methodology provides between 112 and 168 bits of encryption strength.Key unwrapping (using any approved mode with two-key or three-key)

Table 5 – Non-Approved Algorithms Allowed in the Approved Mode of Operation The module does not implement any non-Approved algorithms allowed in the Approved mode of operation for which no security is claimed. The module does not implement any non-Approved algorithms not allowed in the Approved mode of operation.

2.3 Cryptographic Boundary

As a software cryptographic module, the module has no physical components. Therefore, the physical perimeter of the cryptographic module is defined by each host device on which the module is installed. Figure 1 below illustrates a block diagram of a typical general-purpose computer (GPC) and the module’s physical perimeter. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 11
Table, extracted as text (did not parse into structured rows)
Hardware                               Network                           DVD RAM Management                              Interface HDD Clock                                                         SCSI/SATA Generator                                                      Controller LEDs/LCD CPU                                                                              Serial I/O Hub Audio Cache                 PCI/PCIe Slots                                                       USB BIOS Power               Graphics                                             PCI/PCIe Interface             Controller                                            Slots External Power Supply KEY: BIOS – Basic Input/Output System               PCIe – PCI express Plaintext Data             CPU – Central Processing Unit                  HDD – Hard Disk Drive Encrypted Data             SATA – Serial Advanced Technology Attachment   DVD – Digital Video Disc Control Input              SCSI – Small Computer System Interface         USB – Universal Serial Bus Status Output              PCI – Peripheral Component Interconnect        RAM – Random Access Memory Physical Perimeter         LED – Light Emitting Diode                     LCD – Liquid Crystal Display Figure 1 – GPC Block Diagram The module’s cryptographic boundary consists of all functionalities contained within the module’s compiled source code. This comprises: •    libcrypto.so (cryptographic primitives library file) •    libssl.so (TLS protocol library file) •    libcrypto.hmac (an HMAC 31 digest file for libcrypto integrity checking) •    libssl.hmac (an HMAC digest file for libssl integrity checking) The cryptographic boundary is the contiguous perimeter that surrounds all memory-mapped functionality provided by the module when loaded and stored in the host device’s memory. The module is entirely contained within the physical perimeter. Figure 2 shows the logical block diagram of the module executing in memory, its location with respect to the operating system and other supporting applications, and its interactions with surrounding software components, as well as the host platform’s physical perimeter and module’s cryptographic boundary .

31 HMAC – Keyed-Hash Message Authentication Code

Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 12
Table, extracted as text (did not parse into structured rows)
libssl               libssl.hmac Calling Application KEY:                                                       libcrypto            libcrypto.hmac Cryptographic Boundary Physical Perimeter Operating System Data Input Data Output Control Input Control Output Status Output                          CPU           Memory            Storage            Ports System Calls Host Device Figure 2 – Module Block Diagram (with Cryptographic Boundary)
2.4 Modes of Operation

The module only implements one mode of operation, the Approved mode, in which the Approved and allowed cryptographic functions are available. The module transitions to the Approved mode of operation automatically after the module completes its pre-operational self-tests. No configuration is necessary for the module to operate and remain in the Approved mode. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 13
Physical PortLogical InterfaceData That Passes Over Port/Interface
Physical data input port(s) of the tested platformsData Input • API input arguments that provide input data for processing• Data to be encrypted, decrypted, signed, verified, or hashed • Keys to be used in cryptographic services • Random seed material for the module’s DRBG • Keying material to be used as input to key establishment services
Physical data output port(s) of the tested platformsData Output • API output arguments that return generated or processed data back to the caller• Data that has been encrypted, decrypted, or verified • Digital signatures • Hashes • Random values generated by the module’s DRBG • Keys established using module’s key establishment methods
Physical control input port(s) of the tested platformsControl Input • API input arguments that are used to initialize and control the operation of the module• API commands invoking cryptographic services • Modes, key sizes, etc. used with cryptographic services
Physical status output port(s) of the tested platformsStatus Output • API call return values• Status information regarding the module • Status information regarding the invoked service/operation

FIPS 140-3 defines the following logical interfaces for cryptographic modules: As a software library, the cryptographic module has no direct access to any of the host platform’s physical ports, as it communicates only to the calling application via its well-defined API. A mapping of the FIPS-defined interfaces and the module’s interfaces can be found in Table 6. Note that the module does not output control information, Table 6 – Ports and Interfaces Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 14
RoleServiceInputOutput
COShow StatusAPI callCurrent operational status
COPerform self-tests on-demandRe-instantiate module; API call parametersStatus
COZeroizeRestart calling application; reboot or power-cycle host platformNone
COShow versioning informationAPI call parametersModule name, version
UserPerform symmetric encryptionAPI call parameters, key, plaintextStatus, ciphertext
UserPerform symmetric decryptionAPI call parameters, key, ciphertextStatus, plaintext
UserGenerate random numberAPI call parameters, entropy inputStatus, random bits
UserPerform keyed hash operationsAPI call parameters, key, messageStatus, MAC32
UserPerform hash operationAPI call parameters, messageStatus, hash
UserGenerate DSA domain parametersAPI call parametersStatus, domain parameters
UserVerify DSA domain parametersAPI call parametersStatus, domain parameters
UserGenerate asymmetric key pairAPI call parametersStatus, key pair
UserVerify ECDSA public keyAPI call parameters, keyStatus
UserGenerate digital signatureAPI call parameters, key, messageStatus, signature
UserVerify digital signatureAPI call parameters, key, signature, messageStatus

4. Roles, Services, and Authentication The sections below describe the module’s authorized roles, services, and operator authentication methods.

4.1 Authorized Roles

The module supports a Crypto Officer that authorized operators can assume. The CO role performs cryptographic initialization or management functions and general security services. The module also supports the following role(s):

32 MAC – Message Authentication Code

Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 15
RoleServiceInputOutput
UserPerform key wrapAPI call parameters, wrapping key, plaintext keyStatus, encrypted key
UserPerform key unwrapAPI call parameters, wrapping key, wrapped keyStatus, decrypted key
UserCompute shared secretAPI call parametersStatus, shared secret
UserDerive TLS keysAPI call parameters, TLS pre- master secretStatus, TLS keys
UserDerive key via PBKDF2API call parameters, passwordStatus, key
ServiceDescriptionApproved Security Function(s)Keys and/or SSPsRolesAccess Rights to Keys and/or SSPsIndicator
Show statusReturn mode statusNoneNoneCON/AN/A
Perform self-tests on-demandPerform pre- operational self- testsHMAC (Cert. A2584) SHA2-256 (Cert. A2584)NoneCON/AAPI return value
ZeroizeZeroize and de- allocate memory containing sensitive dataNoneAll SSPsCOAll SSPs – ZN/A
4.2 Authentication Methods

The module does not support authentication methods; operators implicitly assume an authorized role based on the service selected.

4.3 Services

Descriptions of the Approved services available to the authorized roles are provided in Table 8 below. The module is an integrated component of Ericsson’s NetCloud OS and offers crypto functions to applications installed on the Cradlepoint devices. While the module includes implementations of non-Approved security functions that can be called by other Ericsson modules, all such invocations will return failure codes to the caller. This effectively limits the service offerings to Approved services only. As allowed for this scenario per section C.H of FIPS 140-3 Implementation Guidance, the module provides indicators for the use of Approved services through a combination of an explicit indication (via a global FIPS mode indicator) and an implicit indication (via the API return value of the service). The keys and Sensitive Security Parameters (SSPs) listed in the table indicate the type of access required using the following notation:

Page 16
ServiceDescriptionApproved Security Function(s)Keys and/or SSPsRolesAccess Rights to Keys and/or SSPsIndicator
Show versioning informationReturn module versioning informationNoneNoneCON/AN/A
Perform symmetric encryptionEncrypt plaintext dataAES (Cert. A2584)AES keyUserAES key – WEAPI return value
Perform symmetric decryptionDecrypt ciphertext dataAES (Cert. A2584) Triple-DES (Cert. A2584)AES key Triple-DES keyUserAES key – WE Triple-DES key – WEAPI return value
Generate random numberGenerate random bits using DRBGDRBG (Cert. A2584)DRBG entropy input DRBG seed DRBG ‘V’ value DRBG ‘Key’ valueUserDRBG entropy input – WE DRBG seed – GE DRBG ‘V’ value – GE DRBG ‘Key’ value – GEAPI return value
Perform keyed hash operationsCompute a message authentication codeHMAC (Cert. A2584) SHS (Cert. A2584)HMAC keyUserHMAC key – WEAPI return value
Perform hash operationCompute a message digestSHS (Cert. A2584)NoneUserN/AAPI return value
Generate DSA domain parametersGenerate DSA domain parametersDSA (Cert. A2584)NoneUserN/AAPI return value
Verify DSA domain parametersVerify DSA domain parametersDSA (Cert. A2584)NoneUserN/AAPI return value
Generate asymmetric key pairGenerate a public/private key pairCKG DSA (Cert. A2584) ECDSA (Cert. A2584) RSA (Cert. A2584) Safe Primes (Cert. A2584)DSA public key DSA private key ECDSA public key ECDSA private key RSA public key RSA private keyUserDSA public key – GR DSA private key – GR ECDSA public key – GR ECDSA private key – GR RSA public key – GR RSA private key – GRAPI return value
Verify ECDSA public keyVerify an ECDSA public keyECDSA (Cert. A2584)ECDSA public keyUserECDSA public key – WAPI return value
Generate digital signatureGenerate a digital signatureDSA (Cert. A2584) ECDSA (Cert. A2584) RSA (Cert. A2584) SHS (Cert. A2584)DSA private key ECDSA private key RSA private keyUserDSA private key – WE ECDSA private key – WE RSA private key – WEAPI return value
Verify digital signatureVerify a digital signatureDSA (Cert. A2584) ECDSA (Cert. A2584) RSA (Cert. A2584) SHS (Cert. A2584)DSA public key ECDSA public key RSA public keyUserDSA public key – WE ECDSA public key – WE RSA public key – WEAPI return value
Perform key wrapPerform key wrapKTS (Cert. A2584)AES key HMAC keyUserAES key – WE HMAC key – WEAPI return value
Perform key unwrapPerform key unwrapKTS (Cert. A2584)AES key HMAC key Triple-DES keyUserAES key – WE HMAC key – WE Triple-DES key – WEAPI return value
Compute shared secretCompute DH/ECDH shared secret suitable for use as input to an internal TLS KDF or an external IKE KDFKAS-ECC-SSC (Cert. A2584) KAS-FFC-SSC (Cert. A2584)DH public component DH private component ECDH public component ECDH private component TLS pre-master secret IKE shared secretUserDH public component – WE DH private component – WE ECDH public component – WE ECDH private component – WE TLS pre-master secret – GE IKE shared secret – GRAPI return value
Derive keys via TLS KDFDerive TLS session and integrity keysKDF (TLS) (Cert. A2584)TLS pre-master secret TLS master secret AES key HMAC keyUserTLS pre-master secret – WE TLS master secret – GE AES key – GR HMAC key – GRAPI return value
Derive key via PBKDF2Derive key from PBKDF2PBKDF (Cert. A2584)Password AES keyUserPassword – WE AES key – GRAPI return value

*Per FIPS 140-3 Implementation Guidance 2.4.C, the Show Status, Zeroize, and Show Versioning Information services do not require a service indicator. The module does not support a non-Approved mode of operation and offers no non-Approved services. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 17

5. Software/Firmware Security All software components within the cryptographic boundary are verified using an Approved integrity technique implemented within the cryptographic module itself. The module implements an HMAC SHA2-256 for the integrity test of each library file; failure of the integrity check for either library file will cause the module to enter a critical error state. The module’s integrity check is performed automatically at module instantiation (i.e., when the module is loaded into memory for execution) without action from the module operator. The CO can initiate the pre-operational tests and conditional CASTs on demand by re-instantiating the module or issuing the FIPS_selftest() API command. The Ericsson Cradlepoint Cryptographic Module is not delivered to end-users as a standalone offering. Rather, it is a pre-built integrated component of Ericsson’s solutions. Ericsson does not provide end-users with any mechanisms to directly access the module, its source code, its APIs, or any information sent to/from the module. Thus, end-users have no ability to independently load the module onto target platforms. No configuration steps are required to be performed by end-users, and no end-user action is required to initialize the module for operation. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 18

6. Operational Environment The Ericsson Cradlepoint Cryptographic Module comprises a software cryptographic library that executes in a modifiable operational environment. The cryptographic module has control over its own SSPs. The process and memory management functionality of the host device’s OS prevents unauthorized access to plaintext private and secret keys, intermediate key generation values and other SSPs by external processes during module execution. The module only allows access to SSPs through its well-defined API. The operational environment provides the capability to separate individual application processes from each other by preventing uncontrolled access to CSPs and uncontrolled modifications of SSPs regardless of whether this data is in the process memory or stored on persistent storage within the operational environment. Processes that are spawned by the module are owned by the module and are not owned by external processes/operators. Please refer to section 2.1 of this document for a list/description of the applicable operational environments. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 19

7. Physical Security The cryptographic module is software module and does not include physical security mechanisms. Therefore, per ISO/IEC 19790:2021 section 7.7.1, requirements for physical security are not applicable. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 20

8. Non-Invasive Security This section is not applicable. There are currently no approved non-invasive mitigation techniques referenced in ISO/IEC 19790:2021 Annex F. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 21
Key/SSP Name/TypeStrengthSecurity Function and Cert. NumberGenerationImport / ExportEstablishmentStorageZeroizationUse & Related Keys
AES key (CSP)Between 128 and 256 bitsAES (CBC, CTR, ECB) (Cert. A2584) KTS (Cert. A2584)-Imported in plaintext via API parameter Never exportedDerived via TLS KDFNot persistently stored by the moduleUnload module; Remove powerSymmetric encryption, decryption
Triple-DES key (CSP)-Triple-DES (Cert. A2584) KTS (Cert. A2584)-Imported in plaintext via API parameter Never exported-Not persistently stored by the moduleUnload module; Remove powerSymmetric decryption
HMAC key (CSP)160 bits (minimum)HMAC (Cert. A2584) KTS (Cert. A2584)-Imported in plaintext via API parameter Never exportedDerived via TLS KDFNot persistently stored by the moduleUnload module; Remove powerKeyed hash
DSA private key (CSP)112 or 128 bitsDSA (Cert. A2584)Generated internally via Approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerDigital signature generation
DSA public key (PSP)112 or 128 bitsDSA (Cert. A2584)Generated internally via approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerDigital signature verification
ECDSA private key (CSP)Between 112 and 256 bitsECDSA (Cert. A2584)Generated internally via approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerDigital signature generation
ECDSA public key (PSP)Between 112 and 256 bitsECDSA (Cert. A2584)Generated internally via approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerDigital signature verification
9.1 Keys and Other SSPs

The module supports the keys and other SSPs listed Table 9 and Table 10 below. Table 9 – Keys Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 22
Key/SSP Name/TypeStrengthSecurity Function and Cert. NumberGenerationImport / ExportEstablishmentStorageZeroizationUse & Related Keys
RSA private key (CSP)Between 80 and 150 bitsRSA (Cert. A2584)Generated internally via approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerDigital signature generation
RSA public key (PSP)Between 80 and 150 bitsRSA (Cert. A2584)Generated internally via approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerDigital signature verification
DH private component (CSP)112 bitsKAS-FFC-SSC (Cert. A2584)Generated internally via approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerDH shared secret computation
DH public component (PSP)112 bitsKAS-FFC-SSC (Cert. A2584)Generated internally via approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerDH shared secret computation
ECDH private component (CSP)Between 112 and 256 bitsKAS-ECC-SSC (Cert. A2584)Generated internally via approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerECDH shared secret computation
ECDH public component (PSP)Between 112 and 256 bitsKAS-ECC-SSC (Cert. A2584)Generated internally via approved DRBGImported in plaintext via API parameter Exported in plaintext via API parameter-Not persistently stored by the moduleUnload module; Remove powerECDH shared secret computation
Key/SSP Name/TypeStrengthSecurity Function and Cert. NumberGenerationImport / ExportEstablishmentStorageZeroizationUse & Related Keys
Passphrase (PSP)-PBKDF (Cert. A2584)-Imported in plaintext via API parameter Never exported-Not persistently stored by the moduleUnload module; Remove powerInput to PBKDF for key derivation
IKE shared secret (CSP)-KAS-FFC-SSC (Cert. A2584)-Never imported Exported in plaintext via API parameterDerived internally via DH shared secret computationNot persistently stored by the moduleUnload module; Remove powerKeying material suitable for use as input to an external IKE KDF
TLS pre-master secret (CSP)-KDF (TLS) (Cert. A2584)-Imported in plaintext via API parameter Never exported-Not persistently stored by the moduleUnload module; Remove powerDerivation of the TLS master secret

Table 10 – Other SSPs Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 23
Key/SSP Name/TypeStrengthSecurity Function and Cert. NumberGenerationImport / ExportEstablishmentStorageZeroizationUse & Related Keys
TLS master secret (CSP)-KDF (TLS) (Cert. A2584)-Never imported Never exportedDerived internally using the TLS pre- master secret via TLS KDFNot persistently stored by the moduleUnload module; Remove powerDerivation of the AES/AES- GCM key and HMAC key used for securing TLS connections
DRBG entropy input (CSP)-DRBG (Cert. A2584)-Imported in plaintext via API parameter33; Never exported-Not persistently stored by the moduleUnload module; Remove powerEntropy material for DRBG
DRBG seed (CSP)-DRBG (Cert. A2584)Generated internally using nonce along with DRBG entropy inputNever imported Never exported-Not persistently stored by the moduleUnload module; Remove powerSeeding material for DRBG
DRBG ‘V’ value (CSP)-DRBG (Cert. A2584)Generated internallyNever imported Never exported-Not persistently stored by the moduleUnload module; Remove powerState value for DRBG
DRBG ‘Key’ value (CSP)-DRBG (Cert. A2584)Generated internallyNever imported Never exported-Not persistently stored by the moduleUnload module; Remove powerState value for DRBG
9.2 DRBGs

The module implements the following Approved DRBG:

Page 24
9.4 SSP Zeroization Methods

As a software cryptographic module, there is no mechanism within the module boundary for the persistent storage of keys and CSPs. Maintenance, including protection and zeroization, of any keys and CSPs that exist outside the module’s cryptographic boundary are the responsibility of the end-user. For the zeroization of keys in volatile memory, module operators can unload the module from memory or reboot/power-cycle the host device.

9.5 RGB Entropy Sources

The cryptographic module’s entropy scheme follows the scenario given in FIPS 140-3 Implementation Guidance 9.3.A, section 2(b). The module invokes a GET command to obtain entropy for random number generation (the module requests 256 bits of entropy from the calling application per request), and then passively receives entropy from the calling application while having no knowledge of the entropy source and exercising no control over the amount or the quality of the obtained entropy. The calling application and its entropy sources are located within the physical perimeter of the module’s operational environment but outside its cryptographic boundary. Thus, there is no assurance of the minimum strength of the generated SSPs. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 25

10. Self-Tests Both pre-operational and conditional self-tests are performed by the module. Pre-operational tests are performed between the time the cryptographic module is instantiated and before the module transitions to the operational state. Conditional self-tests are performed by the module during module operation when certain conditions exist. The following sections list the self-tests performed by the module, their expected error status, and the error resolutions.

10.1 Pre-Operational Self-Tests

The module performs the following pre-operational self-test(s):

10.2 Conditional Self-Tests

The module performs the following conditional self-tests:

34 KAT – Known Answer Test

Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 26

To ensure all CASTs are performed prior to the first operational use of the associated algorithm, all CASTs are performed during the module’s initial power-up sequence. The SHA and HMAC KATs are performed prior to the pre-operational software integrity test; all other CASTs are executed after the successful completion of the software integrity test.

10.3 Self-Test Failure Handling

The module reaches the critical error state when any self-test fails. Upon test failure, the module immediately terminates the calling application’s API call with a returned error code and sets an internal flag, signaling the error condition. For any subsequent request made by the calling application for cryptographic services, the module will return a failure indicator, thereby disabling all access to its cryptographic functions, sensitive security parameters (SSPs), and data output services while the error condition persists. To recover, the module must be re-instantiated by the calling application. If the pre-operational self-tests complete successfully, then the module can resume normal operations. If the module continues to experience self-test failures after reinitializing, then the module will not be able to resume normal operations, and the CO should contact Ericsson Enterprise Wireless Solutions, Inc. for assistance. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 27

11. Life-Cycle Assurance The sections below describe how to ensure the module is operating in its validated configuration, including the following:

11.1 Secure Installation

The module is distributed as a package containing the binaries and HMAC digest files that the Crypto Officer is to install onto a target platform specified in section 6 or one where portability is maintained.

11.2 Initialization

This module is designed to support vendor applications, and these applications are the sole consumers of the cryptographic services provided by the module. No end-user action is required to initialize the module for operation; the calling application performs any actions required to initialize the module. The pre-operational integrity test and cryptographic algorithm self-tests are performed automatically via a DEP when the module is loaded for execution, without any specific action from the calling application or the end-user. End-users have no means to short-circuit or bypass these actions. Failure of any of the initialization actions will result in a failure of the module to load for execution.

11.3 Startup

No startup steps are required to be performed by end-users.

11.4 Administrator Guidance

There are no specific management activities required of the CO role to ensure that the module runs securely. However, if any irregular activity is noticed or the module is consistently reporting errors, then Ericsson Customer Support should be contacted. The following list provides additional guidance for the CO: • The fips_post_status() API can be used to determine the module’s operational status. A non-zero return value indicates that the module has passed all pre-operational self-tests and is currently in the Approved mode. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 28
11.5 Non-Administrator Guidance

The following list provides additional policies for non-administrators:

Page 29

12. Mitigation of Other Attacks This section is not applicable. The module does not claim to mitigate any attacks beyond the FIPS 140-3 Level 1 requirements for this validation. Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 30
TermDefinition
AESAdvanced Encryption Standard
ANSIAmerican National Standards Institute
APIApplication Programming Interface
CASTCryptographic Algorithm Self-Test
CBCCipher Block Chaining
CCCSCanadian Centre for Cyber Security
CCMCounter withCipher Block Chaining - Message Authentication Code
CFBCipher Feedback
CKGCryptographic Key Generation
CMACCipher-Based Message Authentication Code
CMVPCryptographic Module Validation Program
COCryptographic Officer
CPUCentral Processing Unit
CSP CTRCritical Security Parameter Counter
CVLComponent Validation List
DEPDefault Entry Point
DESData Encryption Standard
DHDiffie-Hellman
DRBGDeterministic Random Bit Generator
DSADigital Signature Algorithm
ECBElectronic Code Book
ECCElliptic Curve Cryptography
CDHElliptic Curve Cryptography Cofactor Diffie-Hellman
ECDHElliptic Curve Diffie-Hellman
ECDSAElliptic Curve Digital Signature Algorithm
EMI/EMCElectromagnetic Interference /Electromagnetic Compatibility
FFCFinite Field Cryptography
FIPSFederal Information Processing Standard
GCMGalois/Counter Mode

Appendix A. Acronyms and Abbreviations Table 11 provides definitions for the acronyms and abbreviations used in this document. Table 11 – Acronyms and Abbreviations Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 31
TermDefinition
GMACGalois Message Authentication Code
GPCGeneral-Purpose Computer
HMAC(keyed-) Hash Message Authentication Code
KASKey Agreement Scheme
KATKnown Answer Test
KTSKey Transport Scheme
KWKey Wrap
KWPKey Wrap with Padding
MDMessage Digest
NISTNational Institute of Standards and Technology
OCBOffset Codebook
OFBOutput Feedback
OSOperating System
PBKDFPassword-Based Key Derivation Function
PCTPairwise Consistency Test
PKCSPublic Key Cryptography Standard
PSSProbabilistic Signature Scheme
PUBPublication
RCRivest Cipher
RNG RSARandom Number Generator Rivest Shamir Adleman
SHAKESecure Hash Algorithm KECCAK
SHASecure Hash Algorithm
SHSSecure Hash Standard
SPSpecial Publication
SSCShared Secret Computation
TDESTriple Data Encryption Standard
TLSTransport Layer Security
XEXXOR Encrypt XOR
XTSXEX-Based Tweaked-Codebook Mode with Ciphertext Stealing

Ericsson Cradlepoint Cryptographic Module ©2026 Ericsson Enterprise Wireless Solutions, Inc.

Page 32

Prepared by: Corsec Security, Inc.

12600 Fair Lakes Circle, Suite 210

Fairfax, VA 22033 United States of America Phone: +1 703 267 6050 Email: info@corsec.com Web: www.corsec.com