All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Canon MFP Security Chip

Certificate#4785StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorCanon Inc.
Medium review priority  ·  no TCB surface named  ·  last validated 22 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date9/2/2029
CaveatWhen installed, initialized and configured as specified in Section 11 of the Security Policy. When entropy is externally loaded, no assurance of the minimum strength of generated SSPs (e.g., keys)
VendorCanon Inc.

Approved Algorithms (4)

AlgorithmACVP Cert
AES-XTSC217
Hash DRBGDRBG 2300
RSA SigVer (FIPS186-4)RSA 3059
SHA2-256SHS 4547

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Canon MFP Security Chip
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-test<br/>Status Output</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3 clue;
  class I2,I3 infer;
  class R2,R3 risk;
  class E2,E3 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Canon MFP Security Chip
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-test<br/>Status Output</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3 clueLow;

Security Policy, page by page

Page 1

Date of Issue: 2024/8/22 Canon MFP Security Chip FIPS140-3 Security Policy Version 1.27 2024/8/22 Canon Inc.

Page 2

Date of Issue: 2024/8/22 Contents Trademark Notice ・ Canon and the Canon logo are trademarks of Canon Inc. ・ All names of companies and products contained herein are trademarks or registered trademarks of the respective companies.

Page 3
Term/abbreviationDescription
AESAdvanced Encryption Standard
XTSXEX encryption mode with tweak and ciphertext stealing
ENT (P)Physical entropy source compliant with NIST SP 800-90B.
COCrypto Officer
CSPCritical Security Parameter
PSPPublic Security Parameter
SSPSensitive Security Parameter
FIPSFederal Information Processing Standards
Canon MFP/printerA general term that refers to a Canon brand multifunction peripheral or printer.
Serial ATA (SATA)A standard for connecting storage devices, based on serial transmission technology.
Storage deviceRefers to the storage device on the Canon MFP/printer such as HDD/SSD.

Date of Issue: 2024/8/22 This security policy (hereinafter referred to as SP) is the security policy for the hardware cryptographic module developed by Canon called the Canon MFP Security Chip. This document describes how the Canon MFP Security Chip meets the FIPS140-3 Level 2 security requirements. This SP is a nonproprietary document.

1.1 Reference

This section provides basic information about this SP. Title Canon MFP Security Chip FIPS140-3 Security Policy Version 1.27 Issuer Canon Inc. Date of issue 2024/8/22

1.2 Terms and Abbreviations

The following terms and abbreviations are used throughout this SP. Table 1 Terms and abbreviations

1.3 Security Level

The Canon MFP Security Chip is a cryptographic module designed and implemented to meet the FIPS140-3 Level 2 security requirements. Table2 shows the security level met by the Canon MFP Security Chip for each of the specified areas. The overall level is level 2.

Page 4
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A

Date of Issue: 2024/8/22 Table 2 Security Levels

1.4 Certificate Caveat

When installed, initialized and configured as specified in Section 11 of the Security Policy. When entropy is externally loaded1, no assurance of the minimum strength of generated SSPs (e.g., keys).

1 “externally loaded” caveat is only applicable when “Input secret information” service is used.

Page 5
ModelHardware VersionFirmware Version
Canon MFP Security Chip3.03.00, 3.00(V05L00), 3.00(V05L01)
2 Cryptographic Module Specification
2.1 Cryptographic Module Overview

The Canon MFP Security Chip handles cryptography for the storage device of the Canon MFP/printer. The Canon MFP Security Chip realizes high-speed data encryption/decryption through a serial ATA interface, using XTS-AES mode. This allows the Canon MFP/printer's storage device to be protected against the risk of information leakage, without compromising objectives such as extensibility, flexibility, usability, and high performance. The Canon MFP Security Chip is a “Multiple-chip embedded cryptographic module” and the cryptographic boundary is the surface of the package. The following table shows the hardware and firmware comprising the Canon MFP Security Chip (As described in Section 2.2, all elements of the module are enclosed in a single package). The firmware includes the boot loader. Table 3 Cryptographic Module Tested Configuration Figure1 and Figure2 show the appearance of the Canon MFP Security Chip. The physical perimeter of the Canon MFP Security Chip is the surface of the package. Figure 1 Appearance of the Canon MFP Security Chip GPIO SATA-I/F non-security relevant signal Figure 2 Appearance of Canon MFP Security Chip (Bottom view)

Page 6
ComponentRole
RAMVolatile memory that stores data and programs.
CPUExecutes programs stored in memory.
Flash memoryNon-volatile memory that stores the firmware controlling the Canon MFP Security Chip as well as CSPs.
SATA-Device I/FInterface to process SATA I/O for the Canon MFP
2.2 Cryptographic Module Description

DEVICE interface. Figure 3 shows an example of configuration for cryptographic module operation. The red line in the figure shows the cryptographic boundary. Cryptographic boundary Cryptographic SATA engine RAM HDD I/F I/F (AES) SATA-Host SATA GPIO CPU HDD I/F Reset Clock H Block Host System Power Supply F Block Power Supply PCIe Other Controller relevant I Block relevant signal signal Figure 3 Example of operational configuration of Canon MFP Security Chip The Canon MFP Security Chip is located between the host system and storage device. The host system is a system to use the services provided by the Canon MFP Security Chip, while the storage Security Chip also has a mirroring function thus it is possible to connect two storage devices. However, the second storage device is optional, and it is possible to operate with only one storage device. Serial ATA is used as the interface between the host system and Canon MFP Security Chip, and between The Canon MFP Security Chip consists of three blocks: H block for the main process of the cryptographic module; F block where flash memory is mounted; and I block not related to the services provided by the cryptographic module. The Canon MFP Security Chip consists of two dies: H and I blocks sit on one die, and F block, on the other. All these elements are enclosed in a single package, making up the cryptographic chip. All the security services of the cryptographic module are implemented in H block and F block. Firmware and CSP data to be executed in H block are stored in the flash memory in F block. I block does not have any physical I/F with H and F blocks, including the power supply. Therefore, it is not possible to access SSPs from I block and there is no impact on input/output of the cryptographic module. I block has no impact on the security of the Canon MFP Security Chip and thus explicitly excluded from the FIPS140-3 requirements. The following shows the role of each component of H and F blocks: Table 4 Roles of components of the Canon MFP Security Chip

Page 7
SATA-Host I/FSecurity Chip.
Cryptographic engineHandles AES encryption and decryption.
2.3 Mode of Operation

The Canon MFP Security Chip supports Approved mode, which implements security features approved by CMVP, and non-Compliant state, which is considered outside the scope of this certification. The Canon MFP Security Chip operates in non-Compliant state when installed. It becomes validated one by using the Initialization operation described in Section 11 and is always in Approved mode. If “Sanitization” service is used in Approved mode, the module will transition to non-Compliant state.

Page 8
CAVP CertAlgorithm and StandardMode/ MethodDescription / Key Size(s) / Key Strength(s)Use / Function
#C217AES2 FIPS PUB 197 SP 800-38EXTS Encryption/ DecryptionKey Strength: 128 bits, 256 bits Length: 128 bits, 256 bitsUsed in encryption/decryption of data stored in storage device.
#4547SHS FIPS PUB 180-4SHA-256Size: 256 bitsUsed in Hash_DRBG random bit generation, response generation for Device Identification and Authentication, and RSA digital signature verification.
#3059RSA FIPS PUB 186-4 PKCS#1Signature VerificationModulus: 2048 bitsUsed for firmware verification.
#2300Hash_DRBG SP 800-90A Rev.1N/ASHA-256Used in cryptographic key generation, and challenge generation for Device Identification and Authentication.
ENT(P)Entropy Source SP 800-90BN/AUsed in generating the seed value for approved DRBG
Vendor AffirmedCKG SP 800-133rev2N/AUsed in cryptographic key generation. As per SP 800-133rev2 Section 4.

Date of Issue: 2024/8/22 The Canon MFP Security Chip provides the following approved algorithms in Approved mode. Table 5 Approved algorithms The Canon MFP Security Chip does not implement any non-Approved algorithms.

2 #C217 includes AES-ECB as validated algorithm. This is used as a prerequisite for XTS-AES

Page 9
Physical portLogical interfaceData that passes over port/interface
SATA-DeviceControl Input- Non-data portion of the ATA command
Status Output- Non-data portion of the response to the ATA command
Data Input- Plaintext user data - "Authentication ID" (plaintext) - "CO authentication information" (plaintext) - Challenge for device authentication - Response for host authentication - New firmware image for Update firmware service - "Key seed" (plaintext)
Data Output- "Key seed" (plaintext) - Challenge for host authentication - Response for device authentication
SATA-HostData Input Data Output- Ciphertext user data
Power supplyPower supplyNone
GPIOStatus Output- Module status output (indicating a status, such as SSD access)
ResetControl Input- Reset signal
ClockControl Input- Clock signal
3 Cryptographic Module Interfaces

This section describes the physical ports of the Canon MFP Security Chip, and how they relate to the Security Chip operates upon ATA commands that are input from the host system. Each ATA command is associated with a different interface, namely Data Input, Data Output, Control Input, and Table 6 Ports and Interfaces There is no control output in the Canon MFP Security Chip.

Page 10
RoleServiceInputOutput
CO (USER)AES encryption DMA*2Plaintext user data, ATA command (WRITE DMA)Result*1, Ciphertext user data
CO (USER)AES encryption MULTIPLE*2Plaintext user data, ATA command (WRITE MULTIPLE)Result*1, Ciphertext user data
CO (USER)AES encryption SECTOR(S) *2Plaintext user data, ATA command (WRITE SECTOR(S))Result*1, Ciphertext user data
CO (USER)AES encryption DMA EXT*2Plaintext user data, ATA command (WRITE DMA EXT)Result*1, Ciphertext user data
CO (USER)AES encryption MULTIPLE EXT*2Plaintext user data, ATA command (WRITE MULTIPLE EXT)Result*1, Ciphertext user data
CO (USER)AES encryption SECTOR(S) EXT*2Plaintext user data, ATA command (WRITE SECTOR(S) EXT)Result*1, Ciphertext user data
CO (USER)AES decryption DMA*2Ciphertext user data, ATA command (READ DMA)Result*1, Plaintext user data
CO (USER)AES decryption MULTIPLE*2Ciphertext user data, ATA command (READ MULTIPLE)Result*1, Plaintext user data
CO (USER)AES decryption SECTOR(S) *2Ciphertext user data, ATA command (READ SECTOR(S))Result*1, Plaintext user data
CO (USER)AES decryption DMA EXT*2Ciphertext user data, ATA command (READ DMA EXT)Result*1, Plaintext user data
CO (USER)AES decryption MULTIPLE EXT*2Ciphertext user data, ATA command (READ MULTIPLE EXT)Result*1, Plaintext user data
CO (USER)AES decryption SECTOR(S) EXT*2Ciphertext user data, ATA command (READ SECTOR(S) EXT)Result*1, Plaintext user data
COConfigure secret informationAuthentication ID, CO authentication information, extended ATA command (INSTALL SECRET INFO)Result*1
COOutput secret informationextended ATA command*4 (EXPORT CSP)Result*1, Key seed
COInput secret informationKey seed, extended ATA command*4 (IMPORT CSP)Result*1
COChange CO authentication informationCO authentication information, extended ATA command*4 (CONFIG SECRET INFO)Result*1
COUpdate firmwareNew firmware image, extended ATA command*4 (UPDATE BUILD IN FW)Result*1
NoneProcess ATA command services*3ATA command (General feature set/ Power Management feature set/ 48-bit Address feature set/ SMART feature set/ General Purpose Logging feature set/ Security feature set/ Long Logical Sector (LLS) feature set/Result*1
4 Roles, Services, and Authentication
4.1 Roles, Service Commands, Input and Output

This section describes the roles with corresponding service with input and output provided by the Canon MFP Security Chip. Table 7 Roles, Service Commands, Input and Output

Page 11
Trusted Computing feature set/ Sanitize Device feature set/ Software Setting Preservation (SSP) feature set)
NoneReconfigurationPower onNone
NoneZeroize AES keyPower offNone
NoneInitialize Settingsextended ATA command*4 (INITIALIZE SETTINGS)Result*1
NoneTo Configextended ATA command*4 (TO CONFIG)Result*1
NoneSetup Mirroringextended ATA command*4 (SETUP MIRRORING)Result*1
NoneChange Modeextended ATA command*4 (CHANGE MODE)Result*1
NoneSelf-resetextended ATA command*4 (SELF RESET)Result*1
NoneShow statusextended ATA command*4 (GET STATUS)Result*1, current status and the error factor if an error occurs
NoneGet FW Version Infoextended ATA command*4 (GET VERSION INFO)Result*1, version of the Firmware module
NoneGet HW Version Infoextended ATA command*4 (CHECK CHIP VERSION)Result*1, version of the Hardware module
NoneZeroize secret informationextended ATA command*4 (ERASE SECRET INFO)Result*1
NoneSanitizationextended ATA command*4 (CHANGE TO NONFIPS)Result*1
NonePrepare Sanitizationextended ATA command*4 (PREPARE CHANGE TO NONFIPS)Result*1
NoneSend challenge for Device Identification and AuthenticationChallenge, extended ATA command*4 (SEND CHA1)Result*1
NoneRequest response for Device Identification and Authenticationextended ATA command*4 (REQUEST RES1)Result*1, Response
NoneRequest challenge for Device Identification and Authenticationextended ATA command*4 (REQUEST CHA2)Result*1, Challenge
NoneDevice Identification and AuthenticationResponse, extended ATA command*4 (SEND RES2)Result*1
NoneRequest challenge for C1 authenticationextended ATA command*4 (REQUEST CHA C1)Result*1, Challenge
NoneC1 authenticationResponse, extended ATA command*4 (SEND RES C1)Result*1
NoneRequest challenge for C3 authenticationextended ATA command*4 (REQUEST CHA C3)Result*1, Challenge
NoneC3 authenticationResponse, extended ATA command*4 (SEND RES C3)Result*1
NoneRequest challenge for C4 authenticationextended ATA command*4 (REQUEST CHA C4)Result*1, Challenge
NoneC4 authenticationResponse, extended ATAResult*1
Page 12
command*4 (SEND RES C4)
NoneRequest challenge for C5 authenticationextended ATA command*4 (REQUEST CHA C5)Result*1, Challenge
NoneC5 authenticationResponse, extended ATA command*4 (SEND RES C5)Result*1
NoneRequest challenge for C6 authenticationextended ATA command*4 (REQUEST CHA C6)Result*1, Challenge
NoneC6 authenticationResponse, extended ATA command*4 (SEND RES C6)Result*1
NoneSelf-testPower onNone
RoleAuthentication MethodAuthentication Strength
CO (USER)CO(USER) is authenticated by “Device Identification and Authentication” service. The method is role-based authentication by shared secret. See Section 4.3 for more information.32-byte
COCO is authenticated by C1, C3, C4, C5, or C6 authentication service. The method is role-based authentication by shared secret. It is possible to set different authentication information for C1, C3, C4, C5, and C6. The authentication method and specification of each authentication information are the same and are referred to as CO authentication. See Section 4.3 for more information.32-byte

Date of Issue: 2024/8/22 *2 AES encryption/decryption services perform different methods of data transfer to the storage device according to the ATA command (i.e., write a single block or multiple blocks, etc.). No matter which command is executed, the module provides same function (data encryption/decryption). *3 The Process ATA Command services sends non-cryptographic-related ATA commands (as defined in the ANSI INCITS 452 standard document (ATA 8)) received from a host to storage, and sends a response from storage to the host. The Canon MFP Security Chip has a service corresponding to services. *4 The extended ATA command is proprietary to the Canon MFP Security Chip.

4.2 Roles

The Canon MFP Security Chip supports two distinct operator roles, CO(USER) and CO. These roles are the "Crypto Officer Role" specified in ISO/IEC 19790 Section 7.4.2. The Canon MFP Security Chip has no "User Role". CO(USER) serves to allow connection to the Host. CO (USER) is allowed use of the AES encryption/decryption services as described in Table 10. CO (USER) is a role that undertakes information, and C6 can update the firmware of the Canon MFP Security Chip, respectively. The following table shows the authentication method of each role. The Canon MFP Security Chip does not provide the maintenance service, so no MAINTENANCE role is supported. It does not support concurrent use by multiple operators or bypass function. Table 9 Roles and Authentication

Page 13
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
AES encryption DMAEncrypts and writes data to the storage device(s).AES EncryptionAES cryptographic keysCO (USER)Ecommand response
AES encryption MULTIPLEEncrypts and writes data to the storage device(s).AES EncryptionAES cryptographic keysCO (USER)Ecommand response
4.3 Operator Authentication

Before providing any of the services associated with CO(USER) and CO respectively, the Canon MFP Security Chip performs role-based authentication by shared secret. The authentication mechanism differs for each role, as follows. Uses challenge-response authentication based on Authentication ID defined in 9.1. CO(USER) authentication is referred to as “Device Identification and Authentication” service. In Device Identification and Authentication, the challenge generated from the DRBG and a response value derived from the challenge and the Authentication ID, are used to mutually identify/authenticate the host system and the Canon MFP Security Chip. Response value is calculated by concatenating challenge and authentication ID, and then calculating hash values. ・ CO authentication Uses challenge-response authentication based on CO authentication information defined in section 9.1. The Canon MFP Security Chip generates challenge from DRBG and performs CO authentication using the response value notified by the host system. Response value is calculated by concatenating challenge and CO authentication information, and then calculating hash values. The hash algorithm used in CO (USER) and CO authentication is SHS as described in # 4547 of Table 5, and SHA-256 is used to calculate the hash value. For the shared secret, both CO authentication and CO(USER) authentication use a 32-byte random number, so the probability that a random attempt will succeed is 1/2 256, which is less than the objective of 1/1,000,000. The module can perform CO authentication every 60 milliseconds, and CO(USER) authentication, every 120 milliseconds. Therefore, the probability that multiple consecutive random authentication attempts will be successful during a one-minute period is 1000/2256 and 500/2256 respectively, both of which are less than the objective of 1/100,000.

4.4 Services

This section describes the cryptographic services provided by the Canon MFP Security Chip. The Access rights shown in the table mean the access rights to Keys and/or SSPs and are defined as follows: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. Zeroisation of SSP is performed by overwriting the area where corresponding SSP is stored with 0 or 1. See Table 9 for the method used for authentication to each operator role. Table 10 Approved Services

Page 14
AES encryption SECTOR(S)Encrypts and writes data to the storage device(s).AES EncryptionAES cryptographic keysCO (USER)Ecommand response
AES encryption DMA EXTEncrypts and writes data to the storage device(s).AES EncryptionAES cryptographic keysCO (USER)Ecommand response
AES encryption MULTIPLE EXTEncrypts and writes data to the storage device(s).AES EncryptionAES cryptographic keysCO (USER)Ecommand response
AES encryption SECTOR(S) EXTEncrypts and writes data to the storage device(s).AES EncryptionAES cryptographic keysCO (USER)Ecommand response
AES decryption DMAReads data from the storage device and decrypts.AES DecryptionAES cryptographic keysCO (USER)Ecommand response
AES decryption MULTIPLEReads data from the storage device and decrypts.AES DecryptionAES cryptographic keysCO (USER)Ecommand response
AES decryption SECTOR(S)Reads data from the storage device and decrypts.AES DecryptionAES cryptographic keysCO (USER)Ecommand response
AES decryption DMA EXTReads data from the storage device and decrypts.AES DecryptionAES cryptographic keysCO (USER)Ecommand response
AES decryption MULTIPLE EXTReads data from the storage device and decrypts.AES DecryptionAES cryptographic keysCO (USER)Ecommand response
AES decryption SECTOR(S) EXTReads data from the storage device and decrypts.AES DecryptionAES cryptographic keysCO (USER)Ecommand response
Configure secret informationConfigures the authentication ID and CO authentication information and generates the key seed for AES cryptographic key generation. Writes the Host- originated CSPs to Flash memory.Hash_DRBG CKGAuthentication ID, CO authentication informationCOWcommand response
AES cryptographic keysG
Key seedG/E
DRBG seedG/E/Z
DRBG internal stateE/G
Output secret informationKey seed is output in plaintext form from the cryptographic module.-Key seedCORcommand response
Input secret informationReplaces the key seed, with the secret information received from the host system in plaintext form.-Key seedCOE/Wcommand response
AES cryptographic keysG
Change CO authentication informationModifies CO authentication information.-CO authentication informationCOW/Zcommand response
Update firmwareUpdates firmware of the cryptographic module except for the boot loader. See section 5.RSA SHA-256Vendor public keyCOEcommand response
CO authentication information, key seed, authentication ID, DRBG internal state, AES cryptographicZ
Page 15
keys
Process ATA command servicesSends non-encryption- related ATA commands received from the host to the storage and sends a response from the storage to the host.-N/ANoneN/Acommand response
Reconfiguratio nInitializes the Canon MFP Security Chip. The cryptographic key is calculated using the key seed and stored in work memory within the module.Hash_DRBG CKG RSA SHA-256AES cryptographic keysNoneGShow status
Key seedE
DRBG seedG/E/Z
DRBG internal stateG
Vendor public keyE
Zeroize AES keyClears the cryptographic key stored in volatile memory.-AES cryptographic keysNoneZThe module is powered- off.
Initialize SettingsInitializes the non- security relevant settings of the Canon MFP Security Chip. After initializing, the module automatically resets.Hash_DRBG CKG RSA SHA-256AES cryptographic keysNoneGcommand response
Key seedE
DRBG seedG/E/Z
DRBG internal stateG
Vendor public keyE
To ConfigClears the CO(USER) authentication state and transitions to the Config state.-N/ANoneN/Acommand response
Setup MirroringConfigures the behavior settings of the Canon MFP Security Chip for mirroring mode.-N/ANoneN/Acommand response
Change modeConfigures the behavior settings of the Canon MFP Security Chip for mirroring mode.-N/ANoneN/Acommand response
Self-resetPerforms self-reset and self-tests.Hash_DRBG CKG RSA SHA-256AES cryptographic keysNoneGShow status
Key seedE
DRBG seedG/E/Z
DRBG internal stateG
Vendor public keyE
Show statusShows the current status of the module, including status indicators in response to request of some services. If the service resulted in an error, the cause of the error is also shown.-N/ANoneN/Acommand response
Get FW Version InfoShows the version of the cryptographic Firmware module.-N/ANoneN/Acommand response
Get HW Version InfoShows the version of the cryptographic Hardware module.-N/ANoneN/Acommand response
Zeroize secret informationClears (zeroizes) secret information.-Key seed, authentication ID,NoneZcommand response
Page 16
AES cryptographic keys
SanitizationClears (zeroizes) all CSPs and transitions to non-Compliant state.-CO authentication information, key seed, Authentication ID, DRBG internal state, AES cryptographic keysNoneZcommand response
Prepare SanitizationPrepares to use “Sanitization” service.-NoneNoneN/Acommand response
Send challenge for Device Identification and AuthenticationProvides a challenge value for Device Identification and Authentication from the host system to the module.-Challenge- responseNoneWcommand response
Request response for Device Identification and AuthenticationProvides a response value for Device Identification and Authentication from the module to the host system.SHA-256Authentication IDNoneEcommand response
Challenge- responseG/Z/R
Request challenge for Device Identification and AuthenticationProvides a challenge value for Device Identification and Authentication from the module to the host system.Hash_DRB GDRBG internal stateNoneE/Wcommand response
Challenge- responseG/W/R
Device Identification and AuthenticationUses challenge-response authentication to identify/authenticate that the connection is with the correct host system. The Canon MFP Security Chip provides services such as encryption/decryption, only when authentication succeeds.SHA-256Authentication IDNoneEcommand response
Challenge- responseZ/W
Request challenge for C1 authenticationProvides a challenge value for C1 authentication from the module to the host system.Hash_DRB GDRBG internal stateNoneE/Wcommand response
Challenge- responseG/R
C1 authenticationPerforms C1 authentication with challenge-response authentication. The Canon MFP Security Chip provides services to CO only when authentication succeeds.SHA-256CO authentication informationNoneEcommand response
Challenge- responseZ/W
Request challenge for C3 authenticationProvides a challenge value for C3 authentication from the module to the host system.Hash_DRB GDRBG internal stateNoneE/Wcommand response
Challenge- responseG/R
Page 17
C3 authenticationPerforms C3 authentication with challenge-response authentication. The Canon MFP Security Chip provides services to CO only when authentication succeeds.SHA-256CO authentication information Challenge- responseNoneE Z/Wcommand response
Request challenge for C4 authenticationProvides a challenge value for C4 authentication from the module to the host system.Hash_DRB GDRBG internal stateNoneE/Wcommand response
Challenge- responseG/R
C4 authenticationPerforms C4 authentication with challenge-response authentication. The Canon MFP Security Chip provides services to CO only when authentication succeeds.SHA-256CO authentication informationNoneEcommand response
Challenge- responseZ/W
Request challenge for C5 authenticationProvides a challenge value for C5 authentication from the module to the host system.Hash_DRB GDRBG internal stateNoneE/Wcommand response
Challenge- responseG/R
C5 authenticationPerforms C5 authentication with challenge-response authentication. The Canon MFP Security Chip provides services to CO only when authentication succeeds.SHA-256CO authentication informationNoneEcommand response
Challenge- responseZ/W
Request challenge for C6 authenticationProvides a challenge value for C6 authentication from the module to the host system.Hash_DRB GDRBG internal stateNoneE/Wcommand response
Challenge- responseG/R
C6 authenticationPerforms C6 authentication with challenge-response authentication. The Canon MFP Security Chip provides services to CO only when authentication succeeds.SHA-256CO authentication informationNoneEcommand response
Challenge- responseZ/W
Self-testPerforms self-tests.Hash_DRBG CKG RSA SHA-256AES cryptographic keysNoneGShow status
Key seedE
DRBG seedG/E/Z
DRBG internal stateG
Vendor public keyE
Page 18
Physical Security MechanismRecommended Frequency of Inspection/TestInspection/Test Guidance Details
All components are enclosed in a package and sealed by opaque plastic mold (coating).Before useThe administrator shall inspect the coating for any signs of tampering. If the administrator discovers tamper evidence, the Canon MFP Security Chip should not be used.
5 Software/Firmware Security

At the start-up, the Canon MFP Security Chip perform the boot loader integrity test using 32-bit CRC and an integrity test of the firmware (ELF format) using digital signature of RSA 2048-bit. By resetting the Canon MFP Security Chip, it is possible to perform an on-demand integrity test of the firmware. It is also possible for CO to update the firmware except for the boot loader by completely replacing it using Update firmware service. For firmware update, the new firmware image for firmware updating is stored to the non-running firmware storage space of the two storage spaces. After receiving all the firmware data, the Canon MFP Security Chip verifies the received digital signature of RSA 2048-bit by public key that is embedded in the current firmware. In case the verification succeeds, the Canon MFP Security Chip zeroizes CSPs, returns a success status and switches to non-Compliant state. Then, the next start-up, the Canon MFP Security Chip starts with the new firmware. The new firmware launches for the first time after the device is reset. After the new firmware becomes effective, the module becomes another one, and new validation is needed. If verification fails, the Canon MFP Security Chip discards the new firmware, returns an error, and quits the firmware update. In that case, the Canon MFP Security Chip will continue to operate with the pre-update firmware. The CO can verify the updated firmware version by Get FW Version Info service. The firmware version is displayed, consisting of the updated part and the unupdated boot loader.

6 Operational Environment

The Canon MFP Security Chip operates in limited operational environment. It has a function to update firmware but the firmware to be updated has to be the one approved by CMVP. In case other firmware is loaded, it is considered outside of the scope of this certification. The firmware will be completely replaced by the update function. of the Canon MFP Security Chip, it is necessary to remove at least a part of the plastic mold thus tamper evidence will be left if an attempt to remove the mold is made. Table 11 Physical Security Inspection Guidelines

8 Non-invasive Security

The Canon MFP Security Chip does not implement a non-invasive security technology to protect SSPs from non-invasive attacks.

Page 19
Key/SSP Name/ TypeStrengthSecurity Function and Cert. Number*GenerationImport/ExportEstablish mentStorageZeroisationUse & related keys
AES cryptograp hic keys (CSP)128 bits, 256 bitsXTS-AESGenerated by using CKG shown in Table 5.N/AN/APlaintext in RAM“Zeroize AES key”, “Zeroize secret information”, “Update firmware” and “Sanitization ” “Zeroize AES key” implicitly performs zeroisation. Other services explicitly perform zeroisation.“Symmetric Key” for encryption/de cryption
Key seed (CSP)256 bitsHash_DR BGGenerated by the instantiation function of Hash_DRBG in Table 5 by “Configure secret information” in CO Role, that uses DRBG seed described below.Import/Export: Input from the Host System by “Input secret information” in CO Role. The importing Key seed requires to have 256 bits of strength. The “Input secret information” service assumes that the Key seed output by the “Output secret information” service from this module is input.N/APlaintext in Flash“Zeroize secret information”, “Update firmware” and “Sanitization ” All services explicitly perform zeroisation.Used in AES Cryptographic key generation
Authentica tion ID (CSP)Refer to Section 4.3 of [SP].N/AN/AImport: Set by “Configure secret information” service.N/APlaintext in Flash“Zeroize secret information”, “Update firmware” and “Sanitization ” All servicesUsed for mutually authenticating the Canon MFP Security Chip and the host system, for Device Identification and
9 Sensitive Security Parameters Management
9.1 Definition of Sensitive Security Parameters (SSPs)

authentication ID and CO authentication information are collectively called “secret information”. There are no cryptographic algorithms and its parameters with an expiration date in this module. Since the establishment method does not apply to all CSPs, the description is omitted. Table 12 SSPs ”

Page 20
explicitly perform zeroisation.Authentication .
CO authentica tion informatio n (CSP)Refer to Section 4.3 of [SP].N/AN/AImport: Set by “Configure secret information” service and “Change CO authentication information” service. It is possible to set different authentication information for each service and the cryptographic module can retain multiple sets of authentication information.N/APlaintext in Flash“Sanitization ”, “Change CO authenticati on information” and “Update firmware” All services explicitly perform zeroisation.Information for CO authentication .
DRBG internal state (CSP)256 bitsN/AIt is generated by the instantiation function of Hash_DRBG in Table 5, that uses DRBG seed described below.N/AN/APlaintext in RAM“Sanitization ”, “Zeroize AES key” and “Update firmware” "Zeroize AES key" implicitly performs zeroisation. Other services explicitly perform zeroisation.Used for challenge generation, for “Device Identification and Authentication ”, “C1 Authentication ”, “C3 authentication ”, “C4 authentication ”, “C5 authentication ” and “C6 authentication ” services. And it is updated whenever the generation function of Hash_DRBG is called.
DRBG seed (CSP)256 bitsN/ADRBG seed is generated by combining random numbers from Chapter 3.4 ENT (P) that are generated as Entropy Input or Nonce.N/AN/APlaintext in RAM“Configure secret information” and “Reconfigur ation” All services implicitly perform zeroisation.Used for key seed generation. Used for DRBG internal state generation.
Challenge- response (PSP)N/AHash_DR BG SHSChallenge is generated for “Device Identification and Authentication ” and “CO authentication ”. Response isImport: a challenge code is input into the module at "Send challenge for Device Identification and Authentication" service, and response codes are input into the moduleN/APlaintext in RAM. Tempora rily stored during “Device Identifica tion and Authenti“Device Identification and Authenticati on”, “C1 authenticati on”, “C3 authenticati on”, “C4 authenticatiUsed for “CO authentication ” and “Device Identification and Authentication ”.
Page 21
generated for “Device Identification and Authentication ”.at "C1 authentication”, “C3 authentication” service, “C4 authentication” service, “C5 authentication” service, “C6 authentication” service, and "Device Identification and Authentication" service. Export: a response code is output from the module at "Request response for Device Identification and Authentication" service, and challenge codes are output from the module at "Request challenge for Device Identification and Authentication" service, "Request challenge for C1 authentication" service, "Request challenge for C3 authentication" service, "Request challenge for C4 authentication" service, "Request challenge for C5 authentication" service and "Request challenge for C6 authentication" service.cation”, “C1 authentic ation”, “C3 authentic ation”, “C4 authentic ation”, “C5 authentic ation” and “C6 authentic ation”on”, “C5 authenticati on”, “C6 authenticati on” and “Request response for Device Identification and Authenticati on” All services implicitly perform zeroisation
Vendor public key (PSP)[Strength] 112 bits [Length] 2048 bitsRSAStored when manufacturing the Canon MFP Security Chip.Import: Set by “Update firmware” service.N/APlaintext in FlashN/AUsed for verification of firmware.
Entropy sourcesMinimum number of bits of entropyDetails
ENT (P) ring oscillator embedded in the Canon MFP Security Chip5 bits per 8 bitsMinimum entropy provided by the ENT (P) is 5 bits per 8 bits. Total 896 bits random data is provided by ENT (P) to Hash_DRBG for key generation, and it includes 560 bits (=896 bits x 5 bits/8 bits) entropy.

Date of Issue: 2024/8/22 * See Table 5 for algorithm Certification number. The RBG entropy source is ENT (P). ENT (P) is used in generating the seed value for approved Hash_DRBG shown in Table 5. The Table shows entropy source specification. Table 15 Non-Deterministic Random Number Generation Specification

Page 22

Date of Issue: 2024/8/22 If the entropy source deteriorates to the point that it can no longer guarantee the generation of a sufficient amount of entropy, the Canon MFP Security Chip transitions to an error state as the result of the Conditional Self-test shown in 11.2. To recover from the error condition, it is necessary to contact the vendor to repair the Canon MFP security chip.

Page 23
Test itemTest methodTest typeParameterCondition
Firmware Integrity TestFirmware integrity test uses RSA 2048- bit digital signature to verify the firmware except for the boot loaderPre-operational (software/firmware integrity test)public key, 2048-bit RSA digital signatureperformed automatically when the power is turned on
Boot Loader Integrity TestBoot Loader integrity test using CRC Check(32bit)Pre-operational (software/firmware integrity test)CRCsame as above
AES EncryptionKnown answer test (XTS)Conditional (Cryptographic algorithm test)256-bit keysame as above
AES DecryptionKnown answer test (XTS)Conditional (Cryptographic algorithm test)256-bit keysame as above
Hash_DRBGKnown answer test (instantiate/generate)Conditional (Cryptographic algorithm testNonesame as above
SHA-256Known answer testConditional (Cryptographic algorithm test)Nonesame as above
RSA signatureKnown answer test using 2048-bit RSA digital signatureConditional (Cryptographic algorithm test)2048-bit RSA digital signaturesame as above
Hash_DRBGContinuous random bit generator testConditional (Cryptographic algorithm test)Noneperformed before using Hash_DRBG
Entropy Source TestPerform the Repetition Count Test and Adaptive Proportion Test as "Start-up health tests" and "Continuous health tests" as specified in SP 800-90B.Conditional (Cryptographic algorithm test)Noneperformed automatically when the power is turned on
Conditional (Cryptographic algorithm test)Noneperformed before seed generation
CSP Integrity TestSecret information integrity test using CRC Check (32 bits)Conditional (Critical functions test)CRCperformed when secret information is read
Firmware Load TestFirmware verification with 2048-bit RSA digital signature when loading firmwareConditional (software/firmware load test)public key, 2048-bit RSA digital signatureperformed when updating the firmware
10 Self-Tests

The Canon MFP Security Chip has pre-operational self-test and conditional self-test functions. Table

16 shows tests to be performed in self-test.
Page 24

Date of Issue: 2024/8/22 automatically. It performs the firmware integrity test shown in Table 16 as the pre-operational self-test. Cryptographic algorithm tests are also conducted since the firmware integrity test uses RSA signature verification and SHA-256. In case the result of the firmware integrity test and cryptographic algorithm tests is an error, the Canon MFP Security Chip transitions to an error state immediately, and after that, no data can be written to, or read from, the storage device(s). Status of the error state can be obtained by Show status service. In order to recover from an error state, it is necessary to contact the vendor to repair the cryptographic module. On-demand pre-operational self-test can be performed by resetting the Canon MFP Security Chip.

10.2 Conditional Self-test

The Canon MFP Security Chip provides cryptographic algorithm tests, Hash_DRBG continuous random bit generator test, entropy source test, CSP integrity test, and test for firmware loading as the conditional self-test shown in Table 16. The cryptographic algorithm tests are conducted at the same time as the pre-operational self-test, as described in 11.1. Hash_DRBG continuous random bit generator test is conducted every time before using the Hash_DRBG pseudo-random number generator. Entropy source tests are conducted as conditional cryptographic algorithm tests when performing start-up (i.e., as start-up health tests) and seed generation (i.e., as continuous health tests). The Canon MFP Security Chip also provides a management function of secret information as a critical function. It implements CSP integrity test shown in Table 16 as critical functions test. In CSP integrity test, each time secret information stored in the flash memory is read, the integrity of the secret information is confirmed by using 32-bit CRC. The Canon MFP Security Chip has the update firmware function and the firmware load test shown in Table 16 is performed when updating the firmware. In case the result of one of the cryptographic algorithm tests is an error, the Canon MFP Security Chip immediately transitions to an error state, and after that, no data can be written to, or read from, the storage device(s). The status of the error state can be obtained by using Show status service. In order to recover from an error state, it is necessary to contact the vender to repair the Canon MFP Security Chip. In case the transition to the error state is made as a result of the conditional self-test except the cryptographic algorithm tests and firmware load test, it is possible to recover from an error state by transitioning to non-Compliant state using “Sanitization” service. The status of the error state can be obtained by using Show status service. If the Firmware load test fails, the Canon MFP Security Chip will terminate the firmware update and continue to work with the existing firmware. The result can be obtained by using Show status service. No bypass test is implemented because the Canon MFP Security Chip does not have a bypass function.

11 Life-cycle Assurance
11.1 Initial Set-Up

The Canon MFP Security Chip operates in non-Compliant state when installed. In this state, the SSPs are not in the Canon MFP Security Chip and no security functions can be performed. To use the Canon MFP Security Chip in Approved mode, the CO shall perform the following. The CO first runs "Initialization operation" by the [PREPARE INSTALL] extended ATA command in non-Compliant state, and the Canon MFP Security Chip transitions to Approved mode after conducting pre-operational tests and cryptographic algorithm tests described in Section 10. Then, the CO uses the “Configure secret information” service, to set secret information to the Canon MFP Security Chip.

Page 25

Date of Issue: 2024/8/22 The Canon MFP Security Chip, in its initial state, does not have default CO authentication information and default authentication ID. In the service, the CO should set both CO authentication information and authentication ID at the same time. The 32 Byte value which is written in the specified position of the setting command is set as the CO authentication information. It should not be easily guessed. Upon receiving a request for this service, the Canon MFP Security Chip writes the authentication ID and CO authentication information to flash memory, and generates the key seed for AES cryptographic key generation. The Canon MFP Security Chip specifies the key size by the [INSTALL SECRET INFO] extended ATA command in the “Configure secret information” service. “Show status” service by the [GET STATUS] extended ATA command can be used to determine the current operating mode. In response, the operator receives status information from the Canon MFP Security Chip indicating whether it is on Approved mode or non-Compliant state. The administrator shall periodically perform tamper evidence inspection of the Canon MFP Security Chip. Physical access to the contents of the module cannot be gained without removing at least one part of the coating that covers the cryptographic chip. The administrator shall inspect the coating for any signs of tampering. If the administrator discovers tamper evidence, the Canon MFP Security Chip should not be used. Although it cannot be switched, key sizes can be re-set after erasing CSPs by the [ERASE SECRET INFO] command. In this case, user data will not be migrated.

11.2 Sanitization

The Canon MFP Security Chip zeroizes all CSPs and switches to non-Compliant state by using the “Sanitization” service.

11.3 Guidance Documents

Provide the following private document as Administrator guidance and non-Administrator guidance. - Canon MFP Security Chip Firmware specification

12 Mitigation of Other Attacks

The Canon MFP Security Chip does not implement functions to mitigate the impact of other types of attacks. END