All modules
CMVP Validated Module · FIPS 140-3 Security Policy

IBM DataPower FIPS Provider

Certificate#4789StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorIBM
Medium review priority  ·  no TCB surface named  ·  last validated 22 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date9/5/2026
CaveatInterim validation. When operated in approved mode.
VendorIBM

Approved Algorithms (236)

AlgorithmACVP Cert
AES-CBCA4357
AES-CBCA4358
AES-CBCA4359
AES-CBC-CS1A4357
AES-CBC-CS1A4358
AES-CBC-CS1A4359
AES-CBC-CS2A4357
AES-CBC-CS2A4358
AES-CBC-CS2A4359
AES-CBC-CS3A4357
AES-CBC-CS3A4358
AES-CBC-CS3A4359
AES-CCMA4357
AES-CCMA4358
AES-CCMA4359
AES-CFB1A4357
AES-CFB1A4358
AES-CFB1A4359
AES-CFB128A4357
AES-CFB128A4358
AES-CFB128A4359
AES-CFB8A4357
AES-CFB8A4358
AES-CFB8A4359
AES-CMACA4357
AES-CMACA4358
AES-CMACA4359
AES-CTRA4357
AES-CTRA4358
AES-CTRA4359
AES-ECBA4357
AES-ECBA4358
AES-ECBA4359
AES-ECBA4370
AES-ECBA4377
AES-ECBA4378
AES-ECBA4379
AES-ECBA4380
AES-GCMA4360
AES-GCMA4363
AES-GCMA4364
AES-GCMA4371
AES-GCMA4372
AES-GCMA4373
AES-GCMA4374
AES-GCMA4375
AES-GCMA4376
AES-GMACA4360
AES-GMACA4363
AES-GMACA4364
AES-GMACA4371
AES-GMACA4372
AES-GMACA4373
AES-GMACA4374
AES-GMACA4375
AES-GMACA4376
AES-KWA4357
AES-KWA4358
AES-KWA4359
AES-KWPA4357
AES-KWPA4358
AES-KWPA4359
AES-OFBA4357
AES-OFBA4358
AES-OFBA4359
AES-XTS Testing Revision 2.0A4357
AES-XTS Testing Revision 2.0A4358
AES-XTS Testing Revision 2.0A4359
Counter DRBGA4356
ECDSA KeyGen (FIPS186-5)A4361
ECDSA KeyGen (FIPS186-5)A4365
ECDSA KeyGen (FIPS186-5)A4366
ECDSA KeyGen (FIPS186-5)A4367
ECDSA KeyGen (FIPS186-5)A4368
ECDSA KeyVer (FIPS186-5)A4361
ECDSA KeyVer (FIPS186-5)A4365
ECDSA KeyVer (FIPS186-5)A4366
ECDSA KeyVer (FIPS186-5)A4367
ECDSA KeyVer (FIPS186-5)A4368
ECDSA SigGen (FIPS186-5)A4361
ECDSA SigGen (FIPS186-5)A4362
ECDSA SigGen (FIPS186-5)A4365
ECDSA SigGen (FIPS186-5)A4366
ECDSA SigGen (FIPS186-5)A4367
ECDSA SigGen (FIPS186-5)A4368
ECDSA SigVer (FIPS186-5)A4361
ECDSA SigVer (FIPS186-5)A4362
ECDSA SigVer (FIPS186-5)A4365
ECDSA SigVer (FIPS186-5)A4366
ECDSA SigVer (FIPS186-5)A4367
ECDSA SigVer (FIPS186-5)A4368
Hash DRBGA4356
HMAC DRBGA4356
HMAC-SHA-1A4361
HMAC-SHA-1A4365
HMAC-SHA-1A4366
HMAC-SHA-1A4367
HMAC-SHA-1A4368
HMAC-SHA2-224A4361
HMAC-SHA2-224A4365
HMAC-SHA2-224A4366
HMAC-SHA2-224A4367
HMAC-SHA2-224A4368
HMAC-SHA2-256A4361
HMAC-SHA2-256A4365
HMAC-SHA2-256A4366
HMAC-SHA2-256A4367
HMAC-SHA2-256A4368
HMAC-SHA2-384A4361
HMAC-SHA2-384A4365
HMAC-SHA2-384A4366
HMAC-SHA2-384A4367
HMAC-SHA2-384A4368
HMAC-SHA2-512A4361
HMAC-SHA2-512A4365
HMAC-SHA2-512A4366
HMAC-SHA2-512A4367
HMAC-SHA2-512A4368
HMAC-SHA2-512/224A4361
HMAC-SHA2-512/224A4365
HMAC-SHA2-512/224A4366
HMAC-SHA2-512/224A4367
HMAC-SHA2-512/224A4368
HMAC-SHA2-512/256A4361
HMAC-SHA2-512/256A4365
HMAC-SHA2-512/256A4366
HMAC-SHA2-512/256A4367
HMAC-SHA2-512/256A4368
HMAC-SHA3-224A4362
HMAC-SHA3-256A4362
HMAC-SHA3-384A4362
HMAC-SHA3-512A4362
KAS-ECC-SSC Sp800-56Ar3A4361
KAS-ECC-SSC Sp800-56Ar3A4365
KAS-ECC-SSC Sp800-56Ar3A4366
KAS-ECC-SSC Sp800-56Ar3A4367
KAS-ECC-SSC Sp800-56Ar3A4368
KAS-FFC-SSC Sp800-56Ar3A4383
KDA HKDF Sp800-56Cr1A4355
KDA OneStep SP800-56Cr2A4382
KDA TwoStep SP800-56Cr2A4382
KDF ANS 9.42A4361
KDF ANS 9.42A4362
KDF ANS 9.42A4365
KDF ANS 9.42A4366
KDF ANS 9.42A4367
KDF ANS 9.42A4368
KDF ANS 9.63A4361
KDF ANS 9.63A4362
KDF ANS 9.63A4365
KDF ANS 9.63A4366
KDF ANS 9.63A4367
KDF ANS 9.63A4368
KDF SP800-108A4381
KDF SSHA4370
KDF SSHA4377
KDF SSHA4378
KDF SSHA4379
KDF SSHA4380
PBKDFA4361
PBKDFA4362
PBKDFA4365
PBKDFA4366
PBKDFA4367
PBKDFA4368
RSA KeyGen (FIPS186-5)A4361
RSA KeyGen (FIPS186-5)A4365
RSA KeyGen (FIPS186-5)A4366
RSA KeyGen (FIPS186-5)A4367
RSA KeyGen (FIPS186-5)A4368
RSA SigGen (FIPS186-5)A4361
RSA SigGen (FIPS186-5)A4362
RSA SigGen (FIPS186-5)A4365
RSA SigGen (FIPS186-5)A4366
RSA SigGen (FIPS186-5)A4367
RSA SigGen (FIPS186-5)A4368
RSA SigVer (FIPS186-4)A4361
RSA SigVer (FIPS186-4)A4365
RSA SigVer (FIPS186-4)A4366
RSA SigVer (FIPS186-4)A4367
RSA SigVer (FIPS186-4)A4368
RSA SigVer (FIPS186-5)A4361
RSA SigVer (FIPS186-5)A4362
RSA SigVer (FIPS186-5)A4365
RSA SigVer (FIPS186-5)A4366
RSA SigVer (FIPS186-5)A4367
RSA SigVer (FIPS186-5)A4368
Safe Primes Key GenerationA4383
Safe Primes Key VerificationA4383
SHA-1A4361
SHA-1A4365
SHA-1A4366
SHA-1A4367
SHA-1A4368
SHA2-224A4361
SHA2-224A4365
SHA2-224A4366
SHA2-224A4367
SHA2-224A4368
SHA2-256A4361
SHA2-256A4365
SHA2-256A4366
SHA2-256A4367
SHA2-256A4368
SHA2-384A4361
SHA2-384A4365
SHA2-384A4366
SHA2-384A4367
SHA2-384A4368
SHA2-512A4361
SHA2-512A4365
SHA2-512A4366
SHA2-512A4367
SHA2-512A4368
SHA2-512/224A4361
SHA2-512/224A4365
SHA2-512/224A4366
SHA2-512/224A4367
SHA2-512/224A4368
SHA2-512/256A4361
SHA2-512/256A4365
SHA2-512/256A4366
SHA2-512/256A4367
SHA2-512/256A4368
SHA3-224A4362
SHA3-256A4362
SHA3-384A4362
SHA3-512A4362
SHAKE-128A4362
SHAKE-256A4362
TLS v1.2 KDF RFC7627A4361
TLS v1.2 KDF RFC7627A4365
TLS v1.2 KDF RFC7627A4366
TLS v1.2 KDF RFC7627A4367
TLS v1.2 KDF RFC7627A4368
TLS v1.3 KDFA4355

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for IBM DataPower FIPS Provider
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>linux<br/>kernel<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for IBM DataPower FIPS Provider
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>linux<br/>kernel<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

IBM IBM DataPower FIPS Provider Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com © 2024 IBM Corporation/ atsec information security.

Page 2
Table of Contents
#SectionPage
Page 3

© 2024 IBM Corporation/ atsec information security.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)7
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Modes List and Description8
Table 5: Approved Algorithms24
Table 6: Vendor-Affirmed Algorithms24
Table 7: Non-Approved, Not Allowed Algorithms25
Table 8: Security Function Implementations44
Table 9: Entropy Certificates45
Table 10: Entropy Sources46
Table 11: Ports and Interfaces48
Table 12: Roles49
Table 13: Approved Services54
Table 14: Non-Approved Services55
Table 15: Storage Areas61
Table 16: SSP Input-Output Methods61
Table 17: SSP Zeroization Methods61
Table 18: SSP Table 164
Table 19: SSP Table 266
Table 20: Pre-Operational Self-Tests67
Table 21: Conditional Self-Tests76
Table 22: Pre-Operational Periodic Information76
Table 23: Conditional Periodic Information81
Table 24: Error States82
Figure 1: Block Diagram7
Page 5
SectionSecurity Level
11
21
31
41
51
61
7N/A
8N/A
91
101
111
121
1 General
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 3.0.9B3346E1D91BA83B7BAB52F472F3E6A0D of the IBM DataPower FIPS Provider. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. intact and including this notice. Other documentation is proprietary to their authors.

1.2 Security Levels
11
21
31
41
51
61
7N/A
8N/A
91

Table 1: Security Levels © 2024 IBM Corporation/ atsec information security.

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The IBM DataPower FIPS Provider (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. It provides a C language application program interface (API) for use by other applications that require cryptographic functionality. The module consists of one software component, the “FIPS provider”, which implements the FIPS requirements and the cryptographic functionality provided to the operator. Module Type: Software Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: The cryptographic boundary of the module is defined as the fips.so shared library, which contains the compiled code implementing the FIPS provider. Figure 1 shows a block diagram that represents the design of the module when the module is operational and providing services to other user space applications. In this diagram, the physical perimeter of the operational environment (a general-purpose computer on which the module is installed) is indicated by a purple dashed line. The cryptographic boundary is represented by the component painted in orange, which consists only of the shared library implementing the FIPS provider (fips.so). Green lines indicate the flow of data between the cryptographic module and its operator application, through the logical interfaces defined in Section 3. Components in white are only included in the diagram for informational purposes. They are not included in the cryptographic boundary (and therefore not part of the module’s validation). For example, the kernel is responsible for managing system calls issued by the module itself, as well as other applications using the module for cryptographic services. © 2024 IBM Corporation/ atsec information security.

Page 7

Package or File Name fips.so

Software/ Firmware Version 3.0.9- B3346E1D91BA83B7BAB52F472F3E6A0 D

Features

Integrity Test HMAC-SHA2- 256

Figure 1: Block Diagram Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed.

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 8

Operati ng System CentOS Stream 8 CentOS Stream 8

Hardwa re Platfor m IBM DataPow er Gateway X3 IBM DataPow er Gateway X3

Process ors Intel Xeon Gold 6326 Intel Xeon Gold 6326

PAA/ PAI Yes No

Hypervis or or Host OS

Version(s) 3.0.9- B3346E1D91BA83B7BAB52F472F 3E6A0D 3.0.9- B3346E1D91BA83B7BAB52F472F 3E6A0D

Table NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service
Non- approved modeAutomatically entered whenever a non-approved service is requestedNon- ApprovedEquivalent to the indicator of the requested service

N/A for this module. Tested Operational Environments - Software, Firmware, Hybrid: m Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module.

2.3 Excluded Components

There are no components excluded from the requirements of the FIPS 140-3 standard.

2.4 Modes of Operation

Modes List and Description: Table 4: Modes List and Description After passing all pre-operational self-tests and cryptographic algorithm self-tests executed on start-up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. In the operational state, the module accepts service requests from calling applications through its logical interfaces. At any point in the operational state, a calling application can end its process, thus causing the module to end its operation. Mode Change Instructions and Status: © 2024 IBM Corporation/ atsec information security.

Page 9
AlgorithmCAVP CertPropertiesReference
KDA HKDF Sp800- 56Cr1A4355Derived Key Length: 2048 Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384SP 800-56C Rev. 2
TLS v1.3 KDF (CVL)A4355HMAC Algorithm: SHA2-256, SHA2- 384 KDF Running Modes: DHE, PSK, PSK-DHESP 800-135 Rev. 1
Counter DRBGA4356Prediction Resistance: Yes, No Supports Reseed Mode: AES-128, AES-192, AES-256 Derivation Function Enabled: Yes, NoSP 800-90A Rev. 1
Hash DRBGA4356Prediction Resistance: Yes, No Supports Reseed Mode: SHA-1, SHA2-256, SHA2- 512SP 800-90A Rev. 1
HMAC DRBGA4356Prediction Resistance: Yes, No Supports Reseed Mode: SHA-1, SHA2-256, SHA2- 512SP 800-90A Rev. 1
AES-CBCA4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CBC-CS1A4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CBC-CS2A4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CBC-CS3A4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CCMA4357Key Length: 128, 192, 256 Tag Length: 32, 48, 64, 80, 96, 112, 128 IV Length: 56, 64, 72, 80, 88, 96, 104SP 800-38C
AES-CFB1A4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CFB128A4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CFB8A4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CMACA4357Direction: Generation, VerificationSP 800-38B

The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. The status indicator of the mode of operation is equivalent to the indicator of the service that was requested.

2.5 Algorithms

Approved Algorithms: © 2024 IBM Corporation/ atsec information security.

Page 10
AlgorithmCAVP CertProperties Key Length: 128, 192, 256 MAC Length: 128Reference
AES-CTRA4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-ECBA4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-KWA4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38F
AES-KWPA4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38F
AES-OFBA4357Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A4357Direction: Decrypt, Encrypt Key Length: 128, 256 Tweak Mode: Hex Data Unit Length Matches PayloadSP 800-38E
AES-CBCA4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CBC-CS1A4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CBC-CS2A4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CBC-CS3A4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CCMA4358Key Length: 128, 192, 256 Tag Length: 32, 48, 64, 80, 96, 112, 128 IV Length: 56, 64, 72, 80, 88, 96, 104SP 800-38C
AES-CFB1A4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CFB128A4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CFB8A4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CMACA4358Direction: Generation, Verification Key Length: 128, 192, 256 MAC Length: 128SP 800-38B
AES-CTRA4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-ECBA4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-KWA4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38F
AES-KWPA4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38F
AES-OFBA4358Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A4358Direction: Decrypt, Encrypt Key Length: 128, 256 Tweak Mode: Hex Data Unit Length Matches PayloadSP 800-38E
AES-CBCA4359Direction: Decrypt, EncryptSP 800-38A

© 2024 IBM Corporation/ atsec information security.

Page 11
AlgorithmCAVP CertProperties Key Length: 128, 192, 256Reference
AES-CBC-CS1A4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CBC-CS2A4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CBC-CS3A4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CCMA4359Key Length: 128, 192, 256 Tag Length: 32, 48, 64, 80, 96, 112, 128 IV Length: 56, 64, 72, 80, 88, 96, 104SP 800-38C
AES-CFB1A4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CFB128A4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CFB8A4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-CMACA4359Direction: Generation, Verification Key Length: 128, 192, 256 MAC Length: 128SP 800-38B
AES-CTRA4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-ECBA4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-KWA4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38F
AES-KWPA4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38F
AES-OFBA4359Direction: Decrypt, Encrypt Key Length: 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A4359Direction: Decrypt, Encrypt Key Length: 128, 256 Tweak Mode: Hex Data Unit Length Matches PayloadSP 800-38E
AES-GCMA4360Direction: Decrypt, Encrypt IV Generation: External, Internal IV Generation Mode: 8.2.2 Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96, 128SP 800-38D
AES-GMACA4360Direction: Decrypt, Encrypt IV Generation: External Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96SP 800-38D
ECDSA KeyGen (FIPS186-5)A4361Curve: P-224, P-256, P-384, P-521 Secret Generation Mode: testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4361Curve: P-224, P-256, P-384, P-521FIPS 186-5

© 2024 IBM Corporation/ atsec information security.

Page 12
AlgorithmCAVP CertPropertiesReference
ECDSA SigGen (FIPS186-5)A4361Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256FIPS 186-5
ECDSA SigVer (FIPS186-5)A4361Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256FIPS 186-5
HMAC-SHA-1A4361MAC: 160 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4361MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4361MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4361MAC: 384 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4361MAC: 512 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/224A4361MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4361MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4361P-224, P-256, P-384, P-521 Scheme: ephemeralUnified KAS Role: initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A4361Hash Algorithm: SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 zz Length: 8-4096 Increment 8 Key Data Length: 8-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A4361Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Shared Info Length: 0-1024 Increment 8 Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA4361Iteration Count: 1000-10000 Increment 1 HMAC Algorithm: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256 Password Length: 8-128 Increment 1 Salt Length: 128-4096 Increment 8SP 800-132

© 2024 IBM Corporation/ atsec information security.

Page 13
AlgorithmCAVP CertProperties Key Data Length: 128-4096 Increment 8Reference
RSA KeyGen (FIPS186-5)A4361Key Generation Mode: probableWithProbableAux Modulo: 2048, 3072, 4096 Private Key Format: standard Public Exponent Mode: randomFIPS 186-5
RSA SigGen (FIPS186-5)A4361Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-4)A4361Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 1024 Signature Type: pkcs1v1.5, pssFIPS 186-4
RSA SigVer (FIPS186-5)A4361Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
SHA-1A4361-FIPS 180-4
SHA2-224A4361-FIPS 180-4
SHA2-256A4361-FIPS 180-4
SHA2-384A4361-FIPS 180-4
SHA2-512A4361-FIPS 180-4
SHA2-512/224A4361-FIPS 180-4
SHA2-512/256A4361-FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4361Hash Algorithm: SHA2-256, SHA2- 384, SHA2-512 Key Block Length: 1024SP 800-135 Rev. 1
ECDSA SigGen (FIPS186-5)A4362Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA3-224, SHA3- 256, SHA3-384, SHA3-512FIPS 186-5
ECDSA SigVer (FIPS186-5)A4362Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA3-224, SHA3- 256, SHA3-384, SHA3-512FIPS 186-5
HMAC-SHA3-224A4362MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A4362MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A4362MAC: 384 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A4362MAC: 512 Key Length: 112-524288 Increment 8FIPS 198-1
KDF ANS 9.42 (CVL)A4362Hash Algorithm: SHA3-224, SHA3- 256, SHA3-384, SHA3-512 zz Length: 8-4096 Increment 8SP 800-135 Rev. 1

© 2024 IBM Corporation/ atsec information security.

Page 14
AlgorithmCAVP CertProperties Key Data Length: 8-4096 Increment 8Reference
KDF ANS 9.63 (CVL)A4362Hash Algorithm: SHA3-224, SHA3- 256, SHA3-384, SHA3-512 Shared Info Length: 0-1024 Increment 8 Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA4362Iteration Count: 1000-10000 Increment 1 HMAC Algorithm: SHA3-224, SHA3- 256, SHA3-384, SHA3-512 Password Length: 8-128 Increment 1 Salt Length: 128-4096 Increment 8 Key Data Length: 128-4096 Increment 8SP 800-132
RSA SigGen (FIPS186-5)A4362Hash Algorithm: SHA3-224, SHA3- 256, SHA3-384, SHA3-512 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-5)A4362Hash Algorithm: SHA3-224, SHA3- 256, SHA3-384, SHA3-512 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
SHA3-224A4362-FIPS 202
SHA3-256A4362-FIPS 202
SHA3-384A4362-FIPS 202
SHA3-512A4362-FIPS 202
SHAKE-128A4362-FIPS 202
SHAKE-256A4362-FIPS 202
AES-GCMA4363Direction: Decrypt, Encrypt IV Generation: External, Internal IV Generation Mode: 8.2.2 Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96, 128SP 800-38D
AES-GMACA4363Direction: Decrypt, Encrypt IV Generation: External Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96SP 800-38D
AES-GCMA4364Direction: Decrypt, Encrypt IV Generation: External, Internal IV Generation Mode: 8.2.2 Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96, 128SP 800-38D
AES-GMACA4364Direction: Decrypt, Encrypt IV Generation: ExternalSP 800-38D

© 2024 IBM Corporation/ atsec information security.

Page 15
AlgorithmCAVP CertProperties Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96Reference
ECDSA KeyGen (FIPS186-5)A4365Curve: P-224, P-256, P-384, P-521 Secret Generation Mode: testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4365Curve: P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4365Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256FIPS 186-5
ECDSA SigVer (FIPS186-5)A4365Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256FIPS 186-5
HMAC-SHA-1A4365MAC: 160 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4365MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4365MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4365MAC: 384 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4365MAC: 512 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/224A4365MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4365MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4365P-224, P-256, P-384, P-521 Scheme: ephemeralUnified KAS Role: initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A4365Hash Algorithm: SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 zz Length: 8-4096 Increment 8 Key Data Length: 8-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A4365Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Shared Info Length: 0-1024 Increment 8 Key Data Length: 128-4096SP 800-135 Rev. 1

© 2024 IBM Corporation/ atsec information security.

Page 16
AlgorithmCAVP CertProperties Increment 8Reference
PBKDFA4365Iteration Count: 1000-10000 Increment 1 HMAC Algorithm: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256 Password Length: 8-128 Increment 1 Salt Length: 128-4096 Increment 8 Key Data Length: 128-4096 Increment 8SP 800-132
RSA KeyGen (FIPS186-5)A4365Key Generation Mode: probableWithProbableAux Modulo: 2048, 3072, 4096 Private Key Format: standard Public Exponent Mode: randomFIPS 186-5
RSA SigGen (FIPS186-5)A4365Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-4)A4365Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 1024 Signature Type: pkcs1v1.5, pssFIPS 186-4
RSA SigVer (FIPS186-5)A4365Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
SHA-1A4365-FIPS 180-4
SHA2-224A4365-FIPS 180-4
SHA2-256A4365-FIPS 180-4
SHA2-384A4365-FIPS 180-4
SHA2-512A4365-FIPS 180-4
SHA2-512/224A4365-FIPS 180-4
SHA2-512/256A4365-FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4365Hash Algorithm: SHA2-256, SHA2- 384, SHA2-512 Key Block Length: 1024SP 800-135 Rev. 1
ECDSA KeyGen (FIPS186-5)A4366Curve: P-224, P-256, P-384, P-521 Secret Generation Mode: testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4366Curve: P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4366Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256FIPS 186-5
ECDSA SigVer (FIPS186-5)A4366Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-FIPS 186-5

© 2024 IBM Corporation/ atsec information security.

Page 17
AlgorithmCAVP CertProperties 512/224, SHA2-512/256Reference
HMAC-SHA-1A4366MAC: 160 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4366MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4366MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4366MAC: 384 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4366MAC: 512 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/224A4366MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4366MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4366P-224, P-256, P-384, P-521 Scheme: ephemeralUnified KAS Role: initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A4366Hash Algorithm: SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 zz Length: 8-4096 Increment 8 Key Data Length: 8-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A4366Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Shared Info Length: 0-1024 Increment 8 Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA4366Iteration Count: 1000-10000 Increment 1 HMAC Algorithm: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256 Password Length: 8-128 Increment 1 Salt Length: 128-4096 Increment 8 Key Data Length: 128-4096 Increment 8SP 800-132
RSA KeyGen (FIPS186-5)A4366Key Generation Mode: probableWithProbableAux Modulo: 2048, 3072, 4096 Private Key Format: standard Public Exponent Mode: randomFIPS 186-5

© 2024 IBM Corporation/ atsec information security.

Page 18
AlgorithmCAVP CertPropertiesReference
RSA SigGen (FIPS186-5)A4366Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-4)A4366Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 1024 Signature Type: pkcs1v1.5, pssFIPS 186-4
RSA SigVer (FIPS186-5)A4366Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
SHA-1A4366-FIPS 180-4
SHA2-224A4366-FIPS 180-4
SHA2-256A4366-FIPS 180-4
SHA2-384A4366-FIPS 180-4
SHA2-512A4366-FIPS 180-4
SHA2-512/224A4366-FIPS 180-4
SHA2-512/256A4366-FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4366Hash Algorithm: SHA2-256, SHA2- 384, SHA2-512 Key Block Length: 1024SP 800-135 Rev. 1
ECDSA KeyGen (FIPS186-5)A4367Curve: P-224, P-256, P-384, P-521 Secret Generation Mode: testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4367Curve: P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4367Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256FIPS 186-5
ECDSA SigVer (FIPS186-5)A4367Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256FIPS 186-5
HMAC-SHA-1A4367MAC: 160 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4367MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4367MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4367MAC: 384 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4367MAC: 512 Key Length: 112-524288 Increment 8FIPS 198-1

© 2024 IBM Corporation/ atsec information security.

Page 19
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2-512/224A4367MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4367MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4367P-224, P-256, P-384, P-521 Scheme: ephemeralUnified KAS Role: initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A4367Hash Algorithm: SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 zz Length: 8-4096 Increment 8 Key Data Length: 8-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A4367Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Shared Info Length: 0-1024 Increment 8 Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA4367Iteration Count: 1000-10000 Increment 1 HMAC Algorithm: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256 Password Length: 8-128 Increment 1 Salt Length: 128-4096 Increment 8 Key Data Length: 128-4096 Increment 8SP 800-132
RSA KeyGen (FIPS186-5)A4367Key Generation Mode: probableWithProbableAux Modulo: 2048, 3072, 4096 Private Key Format: standard Public Exponent Mode: randomFIPS 186-5
RSA SigGen (FIPS186-5)A4367Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-4)A4367Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 1024 Signature Type: pkcs1v1.5, pssFIPS 186-4
RSA SigVer (FIPS186-5)A4367Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
SHA-1A4367-FIPS 180-4

© 2024 IBM Corporation/ atsec information security.

Page 20
AlgorithmCAVP CertPropertiesReference
SHA2-224A4367-FIPS 180-4
SHA2-256A4367-FIPS 180-4
SHA2-384A4367-FIPS 180-4
SHA2-512A4367-FIPS 180-4
SHA2-512/224A4367-FIPS 180-4
SHA2-512/256A4367-FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4367Hash Algorithm: SHA2-256, SHA2- 384, SHA2-512 Key Block Length: 1024SP 800-135 Rev. 1
ECDSA KeyGen (FIPS186-5)A4368Curve: P-224, P-256, P-384, P-521 Secret Generation Mode: testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4368Curve: P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4368Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256FIPS 186-5
ECDSA SigVer (FIPS186-5)A4368Curve: P-224, P-256, P-384, P-521 Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256FIPS 186-5
HMAC-SHA-1A4368MAC: 160 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4368MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4368MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4368MAC: 384 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4368MAC: 512 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/224A4368MAC: 224 Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4368MAC: 256 Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4368P-224, P-256, P-384, P-521 Scheme: ephemeralUnified KAS Role: initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A4368Hash Algorithm: SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 zz Length: 8-4096 Increment 8 Key Data Length: 8-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A4368Hash Algorithm: SHA2-224, SHA2-SP 800-135 Rev.

© 2024 IBM Corporation/ atsec information security.

Page 21
AlgorithmCAVP CertProperties 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Shared Info Length: 0-1024 Increment 8 Key Data Length: 128-4096 Increment 8Reference 1
PBKDFA4368Iteration Count: 1000-10000 Increment 1 HMAC Algorithm: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256 Password Length: 8-128 Increment 1 Salt Length: 128-4096 Increment 8 Key Data Length: 128-4096 Increment 8SP 800-132
RSA KeyGen (FIPS186-5)A4368Key Generation Mode: probableWithProbableAux Modulo: 2048, 3072, 4096 Private Key Format: standard Public Exponent Mode: randomFIPS 186-5
RSA SigGen (FIPS186-5)A4368Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-4)A4368Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 1024 Signature Type: pkcs1v1.5, pssFIPS 186-4
RSA SigVer (FIPS186-5)A4368Hash Algorithm: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256 Modulo: 2048, 3072, 4096 Signature Type: pkcs1v1.5, pssFIPS 186-5
SHA-1A4368-FIPS 180-4
SHA2-224A4368-FIPS 180-4
SHA2-256A4368-FIPS 180-4
SHA2-384A4368-FIPS 180-4
SHA2-512A4368-FIPS 180-4
SHA2-512/224A4368-FIPS 180-4
SHA2-512/256A4368-FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4368Hash Algorithm: SHA2-256, SHA2- 384, SHA2-512 Key Block Length: 1024SP 800-135 Rev. 1
KDF SSH (CVL)A4370Hash Algorithm: SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
AES-GCMA4371Direction: Decrypt, Encrypt IV Generation: External, Internal IV Generation Mode: 8.2.2 Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112,SP 800-38D

© 2024 IBM Corporation/ atsec information security.

Page 22
AlgorithmCAVP CertProperties 120, 128 IV Length: 96, 128Reference
AES-GMACA4371Direction: Decrypt, Encrypt IV Generation: External Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96SP 800-38D
AES-GCMA4372Direction: Decrypt, Encrypt IV Generation: External, Internal IV Generation Mode: 8.2.2 Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96, 128SP 800-38D
AES-GMACA4372Direction: Decrypt, Encrypt IV Generation: External Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96SP 800-38D
AES-GCMA4373Direction: Decrypt, Encrypt IV Generation: External, Internal IV Generation Mode: 8.2.2 Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96, 128SP 800-38D
AES-GMACA4373Direction: Decrypt, Encrypt IV Generation: External Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96SP 800-38D
AES-GCMA4374Direction: Decrypt, Encrypt IV Generation: External, Internal IV Generation Mode: 8.2.2 Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96, 128SP 800-38D
AES-GMACA4374Direction: Decrypt, Encrypt IV Generation: External Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96SP 800-38D
AES-GCMA4375Direction: Decrypt, Encrypt IV Generation: External, Internal IV Generation Mode: 8.2.2 Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128SP 800-38D

© 2024 IBM Corporation/ atsec information security.

Page 23
AlgorithmCAVP CertProperties IV Length: 96, 128Reference
AES-GMACA4375Direction: Decrypt, Encrypt IV Generation: External Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96SP 800-38D
AES-GCMA4376Direction: Decrypt, Encrypt IV Generation: External, Internal IV Generation Mode: 8.2.2 Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96, 128SP 800-38D
AES-GMACA4376Direction: Decrypt, Encrypt IV Generation: External Key Length: 128, 192, 256 Tag Length: 32, 64, 96, 104, 112, 120, 128 IV Length: 96SP 800-38D
KDF SSH (CVL)A4377Hash Algorithm: SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF SSH (CVL)A4378Hash Algorithm: SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF SSH (CVL)A4379Hash Algorithm: SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF SSH (CVL)A4380Hash Algorithm: SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF SP800-108A4381KDF Mode: Counter, Feedback MAC Mode: HMAC-SHA-1, HMAC- SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, HMAC-SHA2-512/224, HMAC- SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512, CMAC-AES128, CMAC-AES192, CMAC-AES256 Supported Lengths: 8, 72, 128, 776, 3456, 4096 Fixed Data Order: Before Fixed Data Counter Length: 32SP 800-108 Rev. 1
KDA OneStep SP800- 56Cr2A4382Auxiliary Function: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512, HMAC- SHA-1, HMAC-SHA2-224, HMAC- SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, HMAC-SHA2- 512/224, HMAC-SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512SP 800-56C Rev. 2

© 2024 IBM Corporation/ atsec information security.

Page 24
AlgorithmCAVP CertProperties Derived Key Length: 2048 Shared Secret Length: 224-2048 Increment 8Reference
KDA TwoStep SP800- 56Cr2A4382KDF Mode: feedback MAC Modes: HMAC-SHA-1, HMAC- SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, HMAC-SHA2-512/224, HMAC- SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384 Derived Key Length: 2048 Shared Secret Length: 224-2048 Increment 8SP 800-56C Rev. 2
KAS-FFC-SSC Sp800- 56Ar3A4383ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme: dhEphem KAS Role: initiator, responderSP 800-56A Rev. 3
Safe Primes Key GenerationA4383ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
Safe Primes Key VerificationA4383ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
NamePropertiesImplementationReference
CKGKey Type:AsymmetricN/ASP 800-133r2, Section 4, example 1
NameUse and Function
AES GCM (external IV)Encryption
HMAC (< 112-bit keys)Message authentication

Table 5: Approved Algorithms Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: © 2024 IBM Corporation/ atsec information security.

Page 25
NameUse and Function
KBKDF, KDA OneStep, KDA TwoStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF (< 112-bit input or output keys)Key derivation
KDA OneStep, KDA TwoStep (SHAKE128, SHAKE256)Key derivation
ANS X9.42 KDF (SHAKE128, SHAKE256)Key derivation
ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256)Key derivation
SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256)Key derivation
TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA-3)Key derivation
TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3)Key derivation
PBKDF2 (short password; short salt; insufficient iterations; < 112-bit output keys)Password-based key derivation
KAS-IFC-SSC (KAS1 and KAS2 schemes)Shared secret computation
RSA and ECDSA (pre-hashed message)Signature generation; Signature verification
RSA-PSS (invalid salt length)Signature generation; Signature verification
RSA-OAEPAsymmetric encryption; Asymmetric decryption

Name Random number generation

Type DRBG

Description Random number generation

Properties

Algorithm s Counter DRBG HMAC DRBG Hash DRBG AES-ECB AES-ECB AES-ECB HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-224

Table 7: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

s © 2024 IBM Corporation/ atsec information security.

Page 26

Name

Type

Description

Properties

Algorithm s HMAC- SHA2-224 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256

s © 2024 IBM Corporation/ atsec information security.

Page 27

Name

Type

Description

Properties

Algorithm s HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA3-224 HMAC- SHA3-256 HMAC- SHA3-384 HMAC- SHA3-512 SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2-

s © 2024 IBM Corporation/ atsec information security.

Page 28

Name Encryption/ Decryption

Type BC-UnAuth BC-Auth KTS-Wrap

Description Encryption/ Decryption

Properties

Algorithm s 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA3-224 SHA3-256 SHA3-384 SHA3-512 AES-CBC AES-CBC AES-CBC AES-CBC- CS1 AES-CBC- CS1 AES-CBC- CS1 AES-CBC- CS2 AES-CBC- CS2 AES-CBC- CS2 AES-CBC- CS3 AES-CBC- CS3 AES-CBC- CS3 AES-CCM AES-CCM AES-CCM AES-CFB1 AES-CFB1 AES-CFB1 AES- CFB128 AES- CFB128 AES- CFB128 AES-CFB8 AES-CFB8 AES-CFB8 AES-CTR AES-CTR AES-CTR AES-ECB

s © 2024 IBM Corporation/ atsec information security.

Page 29

Name Message authentication

Type MAC

Description Message authentication

Properties

Algorithm s AES-ECB AES-ECB AES-KW AES-KW AES-KW AES-KWP AES-KWP AES-KWP AES-OFB AES-OFB AES-OFB AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-CMAC AES-CMAC AES-CMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC-

s 2.0 2.0 2.0 © 2024 IBM Corporation/ atsec information security.

Page 30

Name

Type

Description

Properties

Algorithm s SHA-1 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224

s © 2024 IBM Corporation/ atsec information security.

Page 31

Name

Type

Description

Properties

Algorithm s HMAC- SHA2- 512/224 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA3-224 HMAC- SHA3-256 HMAC- SHA3-384 HMAC- SHA3-512 SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2- 512/224

s © 2024 IBM Corporation/ atsec information security.

Page 32

Name Signature generation

Type DigSig- SigGen

Description Signature generation

Properties

Algorithm s SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA3-224 SHA3-256 SHA3-384 SHA3-512 ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5) SHA2-224

s © 2024 IBM Corporation/ atsec information security.

Page 33

Name Signature verification

Type DigSig- SigVer

Description Signature verification

Properties

Algorithm s SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA3-224 SHA3-256 SHA3-384 SHA3-512 ECDSA SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5) ECDSA

s © 2024 IBM Corporation/ atsec information security.

Page 34

Name

Type

Description

Properties

Algorithm s SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-5) SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-512 SHA2-512 SHA2-512

s © 2024 IBM Corporation/ atsec information security.

Page 35
NameTypeDescriptionPropertiesAlgorithm s SHA2-512 SHA2-512 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA3-224 SHA3-256 SHA3-384 SHA3-512
Shared secret computationKAS-SSCShared secret computationKAS-ECC-SSC Strength:112 -256 bits KAS-ECC-FFC Strength:112 -200 bitsKAS-ECC- SSC Sp800- 56Ar3 KAS-ECC- SSC Sp800- 56Ar3 KAS-ECC- SSC Sp800- 56Ar3 KAS-ECC- SSC Sp800- 56Ar3 KAS-ECC- SSC Sp800- 56Ar3 KAS-FFC- SSC Sp800- 56Ar3
Key derivationKAS-135KDF KAS-56CKDF KBKDFKey derivationKDF ANS 9.42 KDF ANS 9.42 KDF ANS 9.42 KDF ANS 9.42 KDF ANS

s © 2024 IBM Corporation/ atsec information security.

Page 36

Name

Type

Description

Properties

Algorithm s 9.42 KDF ANS 9.42 KDF ANS 9.63 KDF ANS 9.63 KDF ANS 9.63 KDF ANS 9.63 KDF ANS 9.63 KDF ANS 9.63 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 KDF SSH KDF SSH KDF SSH KDF SSH KDF SSH KDF SP800- 108 KDA OneStep SP800- 56Cr2 KDA TwoStep SP800- 56Cr2 KDA HKDF Sp800- 56Cr1 TLS v1.3 KDF AES-CMAC AES-CMAC AES-CMAC

s © 2024 IBM Corporation/ atsec information security.

Page 37

Name

Type

Description

Properties

Algorithm s HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2- 512/224

s © 2024 IBM Corporation/ atsec information security.

Page 38

Name

Type

Description

Properties

Algorithm s HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA3-224 HMAC- SHA3-256 HMAC- SHA3-384 HMAC- SHA3-512 SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-384 SHA2-384 SHA2-384

s © 2024 IBM Corporation/ atsec information security.

Page 39

Name Password-based key derivation

Type PBKDF

Description Password-based key derivation

Properties

Algorithm s SHA2-384 SHA2-384 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA3-224 SHA3-256 SHA3-384 SHA3-512 PBKDF PBKDF PBKDF PBKDF PBKDF PBKDF HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA-1 HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-224

s © 2024 IBM Corporation/ atsec information security.

Page 40

Name

Type

Description

Properties

Algorithm s HMAC- SHA2-224 HMAC- SHA2-224 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-256 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-384 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2-512 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/224 HMAC- SHA2- 512/256 HMAC-

s © 2024 IBM Corporation/ atsec information security.

Page 41

Name

Type

Description

Properties

Algorithm s SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA2- 512/256 HMAC- SHA3-224 HMAC- SHA3-256 HMAC- SHA3-384 HMAC- SHA3-512 SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2-

s © 2024 IBM Corporation/ atsec information security.

Page 42

Name Key pair generation Key pair verification

Type AsymKeyPair -KeyGen AsymKeyPair -SafePri AsymKeyPair -KeyVer AsymKeyPair -SafePri

Description Key pair generation Key pair verification

Properties

Algorithm s 512/224 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA2- 512/256 SHA3-224 SHA3-256 SHA3-384 SHA3-512 ECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) Safe Primes Key Generation ECDSA KeyVer (FIPS186-5) ECDSA KeyVer

s © 2024 IBM Corporation/ atsec information security.

Page 43

Name Message digest

Type SHA

Description Message digest

Properties

Algorithm s (FIPS186-5) ECDSA KeyVer (FIPS186-5) ECDSA KeyVer (FIPS186-5) ECDSA KeyVer (FIPS186-5) Safe Primes Key Verification SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/224 SHA2- 512/256 SHA2- 512/256 SHA2-

s © 2024 IBM Corporation/ atsec information security.

Page 44

Name XOF

Type XOF

Description XOF

Properties

Algorithm s 512/256 SHA2- 512/256 SHA2- 512/256 SHA3-224 SHA3-256 SHA3-384 SHA3-512 SHAKE-128 SHAKE-256

s Table 8: Security Function Implementations

2.7 Algorithm Specific Information

AES-GCM: For TLS 1.2, the module offers the AES-GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. OpenSSL 3 is compliant with SP 800-52r2 Section 3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446. The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established. Alternatively, the Crypto Officer can use the module’s API to perform AES-GCM encryption using internal IV generation. These IVs are always 96 bits and generated using the approved DRBG internal to the module’s boundary, compliant to Scenario 2 of FIPS 140-3 IG C.H. The module also provides a non-approved AES-GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the EVP_EncryptInit_ex2 API function with a non-NULL iv value. When this is the case, the API will set a non-approved service indicator as described in Section 4.3. Finally, for TLS 1.3, the AES-GCM implementation uses the context of Scenario 5 of FIPS 140-

3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of

August 2018, using the cipher-suites that explicitly select AES-GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES-GCM cipher suites from Section 3.3.1 of SP800-52r2. TLS 1.3 employs separate 64-bit sequence numbers, one for protocol records that are received, and one for protocol records that are sent to a peer. These sequence numbers are set at zero at the beginning of a TLS

1.3 connection and each time when the AES-GCM key is changed. After reading or writing a

record, the respective sequence number is incremented by one. The protocol specification determines that the sequence number should not wrap, and if this condition is observed, then the protocol implementation must either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection. AES-XTS: The length of a single data unit encrypted or decrypted with AES-XTS shall not exceed 2 20 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. © 2024 IBM Corporation/ atsec information security.

Page 45
Cert NumberVendor Name
E91IBM Corporation

The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit. PBKDF2: The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:  Derived keys shall only be used in storage applications. The MK shall not be used for other purposes. The length of the MK or DPK shall be 112 bits or more.  Passwords or passphrases, used as an input for the PBKDF2, shall not be used as cryptographic keys.  The length of the password or passphrase shall be at least 8 characters, and shall consist of lowercase, uppercase, and numeric characters. The probability of guessing the value is estimated to be at most 1/628 = 4 x 10-15. Combined with the minimum iteration count as described below, this provides an acceptable trade-off between user experience and security against brute-force attacks.  A portion of the salt, with a length of at least 128 bits, shall be generated randomly using the SP 800-90Ar1 DRBG provided by the module.  The iteration count shall be selected as large as possible, as long as the time required to generate the key using the entered password is acceptable for the users. The minimum value is 1000. If any of these requirements is not met, the requested service is non-approved. RSA: For RSA key pair generation, signature generation, and signature verification, the module supports any modulus size between 2048 and 16384 bits. Additionally, the module supports a modulus size of 1024 bits for RSA signature verification. Only modulus sizes 1024, 2048, 3072, and 4096 bits have been CAVP tested. Any other modulus size is untested. SP 800-56Ar3 assurances: To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the operator must use the module together with an application that implements the TLS protocol. Additionally, the module’s approved key pair generation service must be used to generate ephemeral Diffie-Hellman or EC Diffie-Hellman key pairs, or the key pairs must be obtained from another FIPS-validated module. As part of this service, the module will internally perform the full public key validation of the generated public key. The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 80056Ar3. Legacy use: Digital Signature Verification using RSA with a 1024-bit modulus is allowed for legacy use only.

2.8 RBG and Entropy

Table 9: Entropy Certificates © 2024 IBM Corporation/ atsec information security.

Page 46
NameTypeOperational EnvironmentSample SizeEntrop y per SampleConditioning Component
Entropy Source for the IBM DataPower FIPS ProviderNon- PhysicalIBM DataPower Gateway X3256 bits256 bitsSHA3-256 (A4294); AES-256 CTR DRBG (A4294); AES-256 CTR DRBG (A4356)

Table 10: Entropy Sources The module employs two Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1. These DRBGs are used internally by the module (e.g. to generate seeds for asymmetric key pairs and random numbers for security functions). They can also be accessed using the specified API functions. The following parameters are used:

  1. Private DRBG: AES-256 CTR_DRBG with derivation function. This DRBG is used to generate secret random values (e.g. during asymmetric key pair generation). It can be accessed using the RAND_priv_bytes API function.
  2. Public DRBG: AES-256 CTR_DRBG with derivation function. This DRBG is used to generate general purpose random values that do not need to remain secret (e.g. initialization vectors). It can be accessed using the RAND_bytes API function. The DRBGs are seeded with 384 bits of seed material (corresponding to 384 bits of entropy) obtained from an SP 800-90B compliant entropy source. During reseeding, the DRBGs obtain

256 bits of seed material (corresponding to 256 bits of entropy). These DRBGs will always

employ prediction resistance. More information regarding the configuration and design of these DRBGs can be found in the module’s manual pages. The module complies with the Public Use Document for ESV certificate E91 seeding the aforementioned DRBGs using the EVP_RAND_generate function, which corresponds to the GetEntropy() function. The operational environment of the module is identical to the one listed on the ESV certificate. There are no maintenance requirements for the entropy source.

2.9 Key Generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800-133r2. When random values are required, they are obtained from the SP 80090Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2. The following methods are implemented:  Safe primes key pair generation: compliant with SP 800-133r2, Section 5.2, which maps to SP 800-56Ar3. The method described in Section 5.6.1.1.4 of SP 800-56Ar3 (“Testing Candidates”) is used.  RSA key pair generation: compliant with SP 800-133r2, Section 5.1, which maps to FIPS 186-5. The method described in Appendix A.1.6 of FIPS 186-5 (“Probable Primes with Conditions Based on Auxiliary Probable Primes”) is used.  ECDSA key pair generation: compliant with SP 800-133r2, Section 5.1, which maps to FIPS 186-5. The method described in Appendix B.2.2 of FIPS 186-5 (“Rejection Sampling”) is used. Note that this generation method is also used to generate ECDH key pairs. Intermediate key generation values are not output from the module and are explicitly zeroized after processing the service. Additionally, the module implements the following key derivation methods, with a security strength of 112-256 bits:  KBKDF: compliant with SP 800-108r1. This implementation can be used to derive secret keys from a pre-existing key-derivation-key. © 2024 IBM Corporation/ atsec information security.

Page 47

 KDA OneStep, KDA TwoStep, HKDF: compliant with SP 800-56Cr2. These implementations shall only be used to derive secret keys in the context of an SP 80056Ar3 key agreement scheme.  ANS X9.42 KDF, ANS X9.63 KDF: compliant with SP 800-135r1. These implementations shall only be used to derive secret keys in the context of an ANS X9.42-2001 resp. ANS X9.63- 2001 key agreement scheme.  SSH KDF, TLS 1.2 KDF, TLS 1.3 KDF: compliant with SP 800-135r1 and RFC 8446. These implementations shall only be used to derive secret keys in the context of the SSH, TLS 1.2, or TLS 1.3 protocols, respectively.  PBKDF2: compliant with option 1a of SP 800-132. This implementation shall only be used to derive keys for use in storage applications.

2.10 Key Establishment

The module implements SSP agreement and SSP transport methods as listed in the SFI table.

2.11 Industry Protocols

The module implements the SSH key derivation function for use in the SSH protocol (RFC

4253 and RFC 6668).

GCM with internal IV generation in the approved mode is compliant with versions 1.2 and 1.3 of the TLS protocol (RFC 5288 and 8446) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the TLS 1.2 and TLS 1.3 key derivation functions for use in the TLS protocol. For Diffie-Hellman, the module supports the use of the following safe primes:  IKE (RFC 3526): MODP-2048 (ID = 14), MODP-3072 (ID = 15), MODP-4096 (ID = 16), MODP-6144 (ID = 17), MODP-8192 (ID = 18)  TLS (RFC 7919): ffdhe2048 (ID = 256), ffdhe3072 (ID = 257), ffdhe4096 (ID = 258), ffdhe6144 (ID = 259), ffdhe8192 (ID = 260) No parts of the SSH, TLS, or IKE protocols, other than those mentioned above, have been tested by the CAVP or CMVP. © 2024 IBM Corporation/ atsec information security.

Page 48
Physical PortLogical Interface(s)Data That Passes
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data InputAPI input parameters
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data OutputAPI output parameters
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Control InputAPI function calls
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Status OutputAPI return codes, error queue
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. © 2024 IBM Corporation/ atsec information security.

Page 49
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescr iptionIndicatorInput sOutp utsSecurity FunctionsSSP Acces s
Messag e digestComp ute a messa ge digestEVP_DigestFinal_ex returns 1Mess ageDiges t valueMessage digestCrypto Officer
XOFComp ute the output of an XOFEVP_DigestFinalXOF returns 1Mess age, outpu t lengt hDiges t valueXOFCrypto Officer
Encrypt ionEncryp t a plainte xtEVP_EncryptFinal_ex returns 1Plaint ext, IV, AES keyCiphe rtextEncryption/ DecryptionCrypto Officer - AES key: W,E
Decryp tionDecry pt a cipher textEVP_DecryptFinal_ex returns 1Ciphe rtext, IV, AES keyPlaint extEncryption/ DecryptionCrypto Officer - AES key: W,E
Authen ticated encrypt ionEncryp t a plainte xtAES GCM: EVP_CIPHER_DATAPOWER_FIPS_ INDICATOR_APPROVED; Others: EVP_EncryptFinal_ex returns 1Plaint ext, IV, AES keyCiphe rtext, MAC tagEncryption/ DecryptionCrypto Officer - AES key: W,E
Authen ticated decrypt ionDecry pt a cipher textAES GCM: EVP_CIPHER_DATAPOWER_FIPS_ INDICATOR_APPROVED; Others: EVP_DecryptFinal_ex returns 1Ciphe rtext, IV, AES key,Plaint ext or failEncryption/ DecryptionCrypto Officer - AES key: W,E
4 Roles, Services, and Authentication
4.2 Roles

Table 12: Roles No support is provided for multiple concurrent operators.

4.3 Approved Services

s © 2024 IBM Corporation/ atsec information security.

Page 50
NameDescr iptionIndicatorInput s MAC tagOutp utsSecurity FunctionsSSP Acces s
Messag e authen ticationComp ute a MAC tagHMAC: EVP_MAC_DATAPOWER_FIPS_IN DICATOR_APPROVED; Others: EVP_MAC_final returns 1Mess age, keyMAC tagMessage authenticati onCrypto Officer - AES key: W,E - HMAC key: W,E
Key derivati onDerive a key from a key- deriva tion key or a shared secretEVP_KDF_DATAPOWER_FIPS_IN DICATOR_APPROVEDKey- deriv ation key or share d secre t, outpu t lengt hDeriv ed keyKey derivationCrypto Officer - Key- deriva tion key: W,E - Share d secret: W,E - Derive d key: G,R
Passwo rd- based key derivati onDerive a key from a passw ordEVP_KDF_DATAPOWER_FIPS_IN DICATOR_APPROVEDPass word, salt, iterati on count , outpu t lengt hDeriv ed keyPassword- based key derivationCrypto Officer - Passw ord: W,E - Derive d key: G,R
Rando m numbe r genera tionGener ate rando m bytesRAND_bytes, RAND_priv_bytes, RAND_bytes_ex, RAND_priv_bytes_ex returns 1Outp ut lengt hRand om bytesRandom number generationCrypto Officer - Entrop y input: W,E,Z - DRBG seed: G,E,Z - DRBG intern

s W,E W,E h G,R , h W,E,Z G,E,Z © 2024 IBM Corporation/ atsec information security.

Page 51
Name Shared secret comput ationDescr iption Comp ute a shared secretIndicator EVP_PKEY_derive returns 1Input s Owne r privat e key, peer public keyOutp utsSecurity Functions Shared secret computatio nSSP Acces s al state (V, Key): G,E - DRBG intern al state (V, C): G,E Crypto Officer - DH public key: W,E - DH privat e key: W,E - EC public key: W,E - EC privat e key: W,E - Share d secret: G,R
Signatu re genera tionGener ate a signat ureRSA: OSSL_DP_FIPSINDICATOR_APPR OVED and EVP_SIGNATURE_DATAPOWER_F IPS_INDICATOR_APPROVED; ECDSA: OSSL_DP_FIPSINDICATOR_APPR OVEDMess age, privat e keySigna tureSignature generationCrypto Officer - EC privat e key: W,E - RSA privat e key: W,E
Signatu re verifica tionVerify a signat ureRSA: OSSL_DP_FIPSINDICATOR_APPR OVED and EVP_SIGNATURE_DATAPOWER_F IPS_INDICATOR_APPROVED; ECDSA: OSSL_DP_FIPSINDICATOR_APPRMess age, public key, signa turePass/ failSignature verificationCrypto Officer - EC public key: W,E - RSA

s (V, G,E (V, C): G,E W,E W,E W,E d G,R W,E © 2024 IBM Corporation/ atsec information security.

Page 52
NameDescr iptionIndicator OVEDInput sOutp utsSecurity FunctionsSSP Acces s public key: W,E
Key pair genera tionGener ate a key pairEVP_PKEY_generate returns 1Grou p, curve , or modu lus sizeKey pairKey pair generationCrypto Officer - DH public key: G,R - DH privat e key: G,R - EC public key: G,R - EC privat e key: G,R - RSA public key: G,R - RSA privat e key: G,R - Interm ediate key gener ation value: G,E,Z
Key pair verifica tionVerify a key pairSuccessful execution and non- approved indicator is not presentKey pairPass/ failKey pair verificationCrypto Officer - DH public key: W,E - DH privat e key: W,E - EC public key: W,E - EC

s W,E G,R G,R G,R G,R G,R G,E,Z W,E W,E W,E © 2024 IBM Corporation/ atsec information security.

Page 53
NameDescr iptionIndicatorInput sOutp utsSecurity FunctionsSSP Acces s privat e key: W,E
Show versionReturn the name and versio n inform ationNoneNoneModu le name and versi onNoneCrypto Officer
Show statusReturn the modul e statusNoneNoneModu le statu sNoneCrypto Officer
Self- testPerfor m the CASTs and integri ty testNoneNonePass/ failNoneCrypto Officer
Zeroiza tionZeroiz e any SSPNoneAny SSPNoneNoneCrypto Officer - AES key: Z - HMAC key: Z - Key- deriva tion key: Z - Share d secret: Z - Passw ord: Z - Derive d key: Z - DRBG intern al state (V, Key):

s W,E e s d Z Z (V, © 2024 IBM Corporation/ atsec information security.

Page 54

Name

Descr iption

Indicator

Input s

Outp uts

Security Functions

SSP Acces s Z - DRBG intern al state (V, C): Z - DH public key: Z - DH privat e key: Z - EC public key: Z - EC privat e key: Z - RSA public key: Z - RSA privat e key: Z

ContextService Indicator
EVP_CIPHER_CTXOSSL_CIPHER_PARAM_DATAPOWER_FIPS_INDICATOR
EVP_MAC_CTXOSSL_MAC_PARAM_DATAPOWER_FIPS_INDICATOR
EVP_KDF_CTXOSSL_KDF_PARAM_DATAPOWER_FIPS_INDICATOR

s Z (V, C): Z Z Z Z Table 13: Approved Services The following convention is used to specify access rights to SSPs:  Generate (G): The module generates or derives the SSP.  Read (R): The SSP is read from the module (e.g. the SSP is output).  Write (W): The SSP is updated, imported, or written to the module.  Execute (E): The module uses the SSP in performing a cryptographic operation.  Zeroize (Z): The module zeroizes the SSP.  N/A: The module does not access any SSP or key during its operation. To interact with the module, a calling application must use the EVP API layer provided by OpenSSL. This layer will delegate the request to the FIPS provider, which will in turn perform the requested service. Additionally, this EVP API layer can be used to retrieve the approved service indicator for the module. The datapower_ossl_query_fipsindicator API function indicates whether an EVP API function is approved. After a cryptographic service was performed by the module, the API context associated with this request can contain a parameter which represents the approved service indicator. The contexts and parameters are listed in the table below. © 2024 IBM Corporation/ atsec information security.

Page 55
EVP_PKEY_CTXOSSL_SIGNATURE_PARAM_DATAPOWER_FIPS_INDICATOR
EVP_PKEY_CTXOSSL_ASYM_CIPHER_PARAM_DATAPOWER_FIPS_INDICATOR
EVP_PKEY_CTXOSSL_KEM_PARAM_DATAPOWER_FIPS_INDICATOR
NameDescriptionAlgorithmsRole
EncryptionEncrypt a plaintextAES GCM (external IV)Crypto Officer
Message authenticationCompute a MAC tagHMAC (< 112-bit keys)Crypto Officer
Key derivationDerive a key from a key-derivation key or a shared secretKBKDF, KDA OneStep, KDA TwoStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF (< 112-bit input or output keys) KDA OneStep, KDA TwoStep (SHAKE128, SHAKE256) ANS X9.42 KDF (SHAKE128, SHAKE256) ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256) SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256) TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA-3) TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3)Crypto Officer
Password-based key derivationDerive a key from a passwordPBKDF2 (short password; short salt; insufficient iterations; < 112- bit output keys)Crypto Officer
Shared secret computationCompute a shared secretKAS-IFC-SSC (KAS1 and KAS2 schemes)Crypto Officer
Signature generationGenerate a signatureRSA and ECDSA (pre-hashed message) RSA-PSS (invalid salt length)Crypto Officer
Signature verificationVerify a signatureRSA and ECDSA (pre-hashed message) RSA-PSS (invalid salt length)Crypto Officer
Asymmetric encryptionEncrypt a plaintextRSA-OAEPCrypto Officer
Asymmetric decryptionDecrypt a ciphertextRSA-OAEPCrypto Officer

The details to use these functions and parameters are described in the module’s manual pages.

4.4 Non-Approved Services

Table 14: Non-Approved Services

4.5 External Software/Firmware Loaded

© 2024 IBM Corporation/ atsec information security.

Page 56

The module does not load external software or firmware. © 2024 IBM Corporation/ atsec information security.

Page 57
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC-SHA2-256 value calculated at run time with the HMAC-SHA2-256 value embedded in the fips.so file that was computed at build time.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity test may be invoked on-demand by resetting the module, or by calling the OSSL_PROVIDER_self_test API function. This will perform (among others) the software integrity test. © 2024 IBM Corporation/ atsec information security.

Page 58
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: Any SSPs contained within the module are protected by the process isolation and memory separation mechanisms provided by the Linux kernel, and only the module has control over these SSPs.

6.2 Configuration Settings and Restrictions

Instrumentation tools like the ptrace system call, gdb and strace, user space live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2024 IBM Corporation/ atsec information security.

Page 59
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. © 2024 IBM Corporation/ atsec information security.

Page 60
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2024 IBM Corporation/ atsec information security.

Page 61
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service executionDynamic

Name API input parameters API output parameters

From Operator calling application (TOEPP) RAM

To RAM Operator calling application (TOEPP)

Format Type Plaintext Plaintext

Distributio n Type Manual Manual

Entry Type Electronic Electronic

SFI or Algorithm

Zeroization MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the cipher handleMemory occupied by SSPs is overwritten with zeroes and then it is released, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the appropriate zeroization API functions
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievableN/A
Module resetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when the module is unloadedBy unloading the module
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas Table 16: SSP Input-Output Methods Table 17: SSP Zeroization Methods © 2024 IBM Corporation/ atsec information security.

Page 62

Name AES key HMAC key Key- derivation key Shared secret Password Derived key Entropy input

Descripti on AES key used for encryptio n, decryptio n, and computin g MAC tags HMAC key used computin g MAC tags Key- derivation key used for: Key derivation Shared secret generate d by (EC) Diffie- Hellman Password used to derive symmetri c keys Symmetri c key derived from a key- derivation key, shared secret, or password Entropy input used to seed the

Size - Strength XTS: 256, 512 bits; Other modes: 128, 192, 256 bits - XTS: 128, 256 bits; Other modes: 128, 192, 256 bits 112- 524288 bits - 112- 256 bits 112-4096 bits - 112- 256 bits 224-8192 bits - 112- 256 bits 8-128 characters - N/A 8-4096 bits - 112- 256 bits 128-384 bits - 128- 384 bits

Type - Categor y Symmetri c key - CSP Symmetri c key - CSP Symmetri c key - CSP Shared secret - CSP Password - CSP Symmetri c key - CSP Entropy input - CSP

Generat ed By Key derivatio n Passwor d-based key derivatio n Random number generati on

Establish ed By Shared secret computati on

Used By Encryption/ Decryption Message authentication Message authentication Key derivation Key derivation Password-based key derivation

All data output is inhibited during zeroization.

9.4 SSPs

y © 2024 IBM Corporation/ atsec information security.

Page 63

Name DRBG seed DRBG internal state (V, Key) DRBG internal state (V, C) DH public key DH private key

Descripti on DRBG DRBG seed derived from entropy input Internal state of CTR_DRB G and HMAC_DR BG instances Internal state of Hash_DR BG instances Public key used for Diffie- Hellman Private key used for Diffie-

Size - Strength CTR_DRB G: 256, 320, 348 bits; Hash_DRB G: 440, 888 bits; HMAC_DR BG: 160, 256, 512 bits - CTR_DRB G: 128, 192, 256 bits; Hash_DRB G: 128, 256 bits; HMAC_DR BG: 128, 256 bits CTR_DRB G: 256, 320, 348 bits HMAC_DR BG: 320, 512, 1024 bits - CTR_DRB G: 128, 192, 256 bits; HMAC_DR BG: 128, 256 bits Hash_DRB G: 880, 1776 bits - Hash_DRB G: 128, 256 bits 2048- 8192 bits - 112-200 bits 2048- 8192 bits - 112-200

Type - Categor y Seed - CSP Internal state - CSP Internal state - CSP Public key - PSP Private key - CSP

Generat ed By Random number generati on Random number generati on Random number generati on Key pair generati on Key pair generati on

Establish ed By

Used By Random number generation Random number generation Random number generation Shared secret computation Key pair verification Shared secret computation Key pair

y © 2024 IBM Corporation/ atsec information security.

Page 64

Name EC public key EC private key RSA public key RSA private key Intermedi ate key generatio n value

Descripti on Hellman Public key used for ECDH and ECDSA Private key used for ECDH and ECDSA Public key used for: Signature verificatio n, Key pair generatio n; Related keys: RSA private key Private key used RSA signature verificatio n Temporar y value generate d during key pair generatio n services

Size - Strength bits P-224, P-256, P-384, P-521 - 112-256 bits P-224, P-256, P-384, P-521 - 112-256 bits Signature verificatio n: 1024 and 2048- 16384 bits; Key pair generatio n: 2048- 16384 bits - Signature verificatio n: 80 and 112-256 bits; Key pair generatio n: 112- 256 bits 2048- 16384 bits - 112- 256 bits 2048- 16384 bits - 112- 256 bits

Type - Categor y Public key - PSP Private key - CSP Public key - PSP Private key - CSP Intermedi ate value - CSP

Generat ed By Key pair generati on Key pair generati on Key pair generati on Key pair generati on Key pair generati on

Establish ed By

Used By verification Signature verification Shared secret computation Key pair verification Signature generation Shared secret computation Key pair verification Signature verification Signature generation Key pair generation

y n Table 18: SSP Table 1 © 2024 IBM Corporation/ atsec information security.

Page 65
Name AES key HMAC key Key- derivation key Shared secret PasswordInput - Output API input parameter s API input parameter s API input parameter s API input parameter s API output parameter s API input parameter sStorage RAM:Plaintex t RAM:Plaintex t RAM:Plaintex t RAM:Plaintex t RAM:Plaintex tStorage Duration Until the cipher handle is freed Until the cipher handle is freed Until the cipher handle is freed Until the cipher handle is freed Until the cipher handle is freedZeroizatio n Free cipher handle Module reset Free cipher handle Module reset Free cipher handle Module reset Free cipher handle Module reset Free cipher handle Module resetRelated SSPs
Derived keyAPI output parameter sRAM:Plaintex tUntil the cipher handle is freedFree cipher handle Module resetKey-derivation key:Derived From Shared secret:Derived From Password:Derive d From
Entropy inputRAM:Plaintex tFrom generation until DRBG seed is createdAutomatic Module reset
DRBG seedRAM:Plaintex tWhile the DRBG is being instantiate dAutomatic Module resetEntropy input:Derived From
DRBG internal state (V, Key)RAM:Plaintex tUntil the cipher handle is freedFree cipher handle Module resetDRBG seed:Derived From
DRBG internal state (V, C)RAM:Plaintex tUntil the cipher handle is freedFree cipher handle Module resetDRBG seed:Derived From
DH public keyAPI input parameter sRAM:Plaintex tUntil the cipher handle isFree cipher handle ModuleDH private key:Paired With

s d © 2024 IBM Corporation/ atsec information security.

Page 66
NameInput - Output API output parameter sStorageStorage Duration freedZeroizatio n resetRelated SSPs
DH private keyAPI input parameter s API output parameter sRAM:Plaintex tUntil the cipher handle is freedFree cipher handle Module resetDH public key:Paired With
EC public keyAPI input parameter s API output parameter sRAM:Plaintex tUntil the cipher handle is freedFree cipher handle Module resetEC private key:Paired With
EC private keyAPI input parameter s API output parameter sRAM:Plaintex tUntil the cipher handle is freedFree cipher handle Module resetEC public key:Paired With
RSA public keyAPI input parameter s API output parameter sRAM:Plaintex tUntil the cipher handle is freedFree cipher handle Module resetRSA private key:Paired With
RSA private keyAPI input parameter s API output parameter sRAM:Plaintex tUntil the cipher handle is freedFree cipher handle Module resetRSA public key:Paired With
Intermediat e key generation valueRAM:Plaintex tFrom service invocation to service completionAutomatic
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2030. © 2024 IBM Corporation/ atsec information security.

Page 67
Algorith m or TestTest Propertie sTest MethodTest TypeIndicatorDetail s
HMAC- SHA2-256 (A4365)256-bit keyMessage authenticatio nSW/FW Integrit yOSSL_PROV_PARAM_STATU S is set to 1Used for fips.so
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A4361)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A4365)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A4366)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A4367)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A4368)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A4361)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A4365)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the
10 Self-Tests

While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module does not return control to the calling application until the tests are completed.

10.1 Pre-Operational Self-Tests

s Table 20: Pre-Operational Self-Tests The pre-operational software integrity tests are performed automatically when the module is initialized, before the module transitions into the operational state. The module transitions to the operational state only after the pre-operational self-tests are passed successfully.

10.2 Conditional Self-Tests

© 2024 IBM Corporation/ atsec information security.

Page 68
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions integrity test
SHA2-512 (A4366)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A4367)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A4368)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA3-256 (A4362)32-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA3-256 (A4362)32-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
AES-GCM (A4360)Encryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4363)Encryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4364)Encryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4371)Encryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4372)Encryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4373)Encryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4374)Encryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4375)Encryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the

© 2024 IBM Corporation/ atsec information security.

Page 69
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions integrity test
AES-GCM (A4376)Encryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4360)Decryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4363)Decryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4364)Decryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4371)Decryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4372)Decryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4373)Decryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4374)Decryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4375)Decryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4376)Decryption with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A4357)Decryption with 128-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A4358)Decryption with 128-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A4359)Decryption with 128-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the

© 2024 IBM Corporation/ atsec information security.

Page 70
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions integrity test
KDF SP800- 108 (A4381)Counter mode, HMAC-SHA2- 256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDA OneStep SP800- 56Cr2 (A4382)SHA2-224KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDA HKDF Sp800- 56Cr1 (A4355)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A4361)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A4362)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A4365)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A4366)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A4367)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A4368)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A4361)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A4362)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A4365)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.63SHA2-256KATCASTModule becomesKey derivationTest runs at power-on

© 2024 IBM Corporation/ atsec information security.

Page 71
Algorithm or Test (A4366)Test PropertiesTest MethodTest TypeIndicator operationalDetailsConditions before the integrity test
KDF ANS 9.63 (A4367)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A4368)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF SSH (A4370)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF SSH (A4377)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF SSH (A4378)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF SSH (A4379)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
KDF SSH (A4380)SHA-1KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A4361)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A4365)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A4366)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A4367)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A4368)SHA2-256KATCASTModule becomes operationalKey derivationTest runs at power-on before the integrity test
TLS v1.3 KDFSHA2-256, extract andKATCASTModule becomesKey derivationTest runs at power-on

© 2024 IBM Corporation/ atsec information security.

Page 72
Algorithm or Test (A4355)Test Properties expandTest MethodTest TypeIndicator operationalDetailsConditions before the integrity test
PBKDF (A4361)SHA2-256, 24-character password, 288-bit salt, iteration count: 4096KATCASTModule becomes operationalPassword- based key derivationTest runs at power-on before the integrity test
PBKDF (A4362)SHA2-256, 24-character password, 288-bit salt, iteration count: 4096KATCASTModule becomes operationalPassword- based key derivationTest runs at power-on before the integrity test
PBKDF (A4365)SHA2-256, 24-character password, 288-bit salt, iteration count: 4096KATCASTModule becomes operationalPassword- based key derivationTest runs at power-on before the integrity test
PBKDF (A4366)SHA2-256, 24-character password, 288-bit salt, iteration count: 4096KATCASTModule becomes operationalPassword- based key derivationTest runs at power-on before the integrity test
PBKDF (A4367)SHA2-256, 24-character password, 288-bit salt, iteration count: 4096KATCASTModule becomes operationalPassword- based key derivationTest runs at power-on before the integrity test
PBKDF (A4368)SHA2-256, 24-character password, 288-bit salt, iteration count: 4096KATCASTModule becomes operationalPassword- based key derivationTest runs at power-on before the integrity test
Counter DRBG (A4356)AES-128KATCASTModule becomes operationalInstantiate, generate, reseed, generate (compliant with SP 800- 90Ar1)Test runs at power-on before the integrity test
Hash DRBG (A4356)SHA2-256KATCASTModule becomes operationalInstantiate, generate, reseed, generate (compliant with SP 800- 90Ar1)Test runs at power-on before the integrity test

© 2024 IBM Corporation/ atsec information security.

Page 73
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC DRBG (A4356)HMAC-SHA2- 256KATCASTModule becomes operationalInstantiate, generate, reseed, generate (compliant with SP 800- 90Ar1)Test runs at power-on before the integrity test
KAS-FFC- SSC Sp800- 56Ar3 (A4383)ffdhe2048KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC- SSC Sp800- 56Ar3 (A4361)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC- SSC Sp800- 56Ar3 (A4365)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC- SSC Sp800- 56Ar3 (A4366)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC- SSC Sp800- 56Ar3 (A4367)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC- SSC Sp800- 56Ar3 (A4368)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A4361)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A4362)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A4365)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A4366)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A4367)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGenPKCS#1 v1.5KATCASTModuleDigitalTest runs at

© 2024 IBM Corporation/ atsec information security.

Page 74
Algorithm or Test (FIPS186-5) (A4368)Test Properties with 2048 bit key and SHA2-256Test MethodTest TypeIndicator becomes operationalDetails signature generationConditions power-on before the integrity test
RSA SigVer (FIPS186-5) (A4361)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A4362)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A4365)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A4366)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A4367)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A4368)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A4361)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A4362)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A4365)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A4366)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A4367)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test

© 2024 IBM Corporation/ atsec information security.

Page 75
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigGen (FIPS186-5) (A4368)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A4361)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A4362)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A4365)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A4366)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A4367)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A4368)P-224, P-256, P-384, and P-521 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
Safe Primes Key Generation (A4383)N/APCTPCTSuccessful key pair generationSP 800-56Ar3 Section 5.6.2.1.4Key pair generation
ECDSA KeyGen (FIPS186-5) (A4361)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A4365)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A4366)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSASHA2-256PCTPCTSuccessfulSignatureKey pair

© 2024 IBM Corporation/ atsec information security.

Page 76
Algorithm or Test KeyGen (FIPS186-5) (A4367)Test PropertiesTest MethodTest TypeIndicator key pair generationDetails generation & verificationConditions generation
ECDSA KeyGen (FIPS186-5) (A4368)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A4361)PKCS#1 v1.5 with SHA2- 256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A4365)PKCS#1 v1.5 with SHA2- 256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A4366)PKCS#1 v1.5 with SHA2- 256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A4367)PKCS#1 v1.5 with SHA2- 256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A4368)PKCS#1 v1.5 with SHA2- 256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 256 (A4365)Message authenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 (A4361)KATCASTOn demandManually
SHA-1 (A4365)KATCASTOn demandManually
SHA-1 (A4366)KATCASTOn demandManually
SHA-1 (A4367)KATCASTOn demandManually
SHA-1 (A4368)KATCASTOn demandManually

Table 21: Conditional Self-Tests Upon generation of a DH, RSA or EC key pair, the module will perform a pair-wise consistency test (PCT) as shown in the table above, which provides some assurance that the generated key pair is well formed. For DH key pairs, this tests consists of the PCT described in Section 5.6.2.1.4 of SP 800-56Ar3. For RSA and EC key pairs, this test consists of a

10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2024 IBM Corporation/ atsec information security.

Page 77
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-512 (A4361)KATCASTOn demandManually
SHA2-512 (A4365)KATCASTOn demandManually
SHA2-512 (A4366)KATCASTOn demandManually
SHA2-512 (A4367)KATCASTOn demandManually
SHA2-512 (A4368)KATCASTOn demandManually
SHA3-256 (A4362)KATCASTOn demandManually
SHA3-256 (A4362)KATCASTOn demandManually
AES-GCM (A4360)KATCASTOn demandManually
AES-GCM (A4363)KATCASTOn demandManually
AES-GCM (A4364)KATCASTOn demandManually
AES-GCM (A4371)KATCASTOn demandManually
AES-GCM (A4372)KATCASTOn demandManually
AES-GCM (A4373)KATCASTOn demandManually
AES-GCM (A4374)KATCASTOn demandManually
AES-GCM (A4375)KATCASTOn demandManually
AES-GCM (A4376)KATCASTOn demandManually
AES-GCM (A4360)KATCASTOn demandManually
AES-GCM (A4363)KATCASTOn demandManually
AES-GCM (A4364)KATCASTOn demandManually
AES-GCM (A4371)KATCASTOn demandManually
AES-GCM (A4372)KATCASTOn demandManually
AES-GCM (A4373)KATCASTOn demandManually
AES-GCM (A4374)KATCASTOn demandManually
AES-GCM (A4375)KATCASTOn demandManually
AES-GCM (A4376)KATCASTOn demandManually
AES-ECB (A4357)KATCASTOn demandManually

© 2024 IBM Corporation/ atsec information security.

Page 78
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A4358)KATCASTOn demandManually
AES-ECB (A4359)KATCASTOn demandManually
KDF SP800-108 (A4381)KATCASTOn demandManually
KDA OneStep SP800-56Cr2 (A4382)KATCASTOn demandManually
KDA HKDF Sp800-56Cr1 (A4355)KATCASTOn demandManually
KDF ANS 9.42 (A4361)KATCASTOn demandManually
KDF ANS 9.42 (A4362)KATCASTOn demandManually
KDF ANS 9.42 (A4365)KATCASTOn demandManually
KDF ANS 9.42 (A4366)KATCASTOn demandManually
KDF ANS 9.42 (A4367)KATCASTOn demandManually
KDF ANS 9.42 (A4368)KATCASTOn demandManually
KDF ANS 9.63 (A4361)KATCASTOn demandManually
KDF ANS 9.63 (A4362)KATCASTOn demandManually
KDF ANS 9.63 (A4365)KATCASTOn demandManually
KDF ANS 9.63 (A4366)KATCASTOn demandManually
KDF ANS 9.63 (A4367)KATCASTOn demandManually
KDF ANS 9.63 (A4368)KATCASTOn demandManually
KDF SSH (A4370)KATCASTOn demandManually
KDF SSH (A4377)KATCASTOn demandManually
KDF SSH (A4378)KATCASTOn demandManually
KDF SSH (A4379)KATCASTOn demandManually
KDF SSH (A4380)KATCASTOn demandManually
TLS v1.2 KDF RFC7627 (A4361)KATCASTOn demandManually
TLS v1.2 KDF RFC7627 (A4365)KATCASTOn demandManually

© 2024 IBM Corporation/ atsec information security.

Page 79
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
TLS v1.2 KDF RFC7627 (A4366)KATCASTOn demandManually
TLS v1.2 KDF RFC7627 (A4367)KATCASTOn demandManually
TLS v1.2 KDF RFC7627 (A4368)KATCASTOn demandManually
TLS v1.3 KDF (A4355)KATCASTOn demandManually
PBKDF (A4361)KATCASTOn demandManually
PBKDF (A4362)KATCASTOn demandManually
PBKDF (A4365)KATCASTOn demandManually
PBKDF (A4366)KATCASTOn demandManually
PBKDF (A4367)KATCASTOn demandManually
PBKDF (A4368)KATCASTOn demandManually
Counter DRBG (A4356)KATCASTOn demandManually
Hash DRBG (A4356)KATCASTOn demandManually
HMAC DRBG (A4356)KATCASTOn demandManually
KAS-FFC-SSC Sp800-56Ar3 (A4383)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A4361)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A4365)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A4366)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A4367)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A4368)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A4361)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A4362)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A4365)KATCASTOn demandManually
RSA SigGen (FIPS186-5)KATCASTOn demandManually

© 2024 IBM Corporation/ atsec information security.

Page 80
Algorithm or Test (A4366)Test MethodTest TypePeriodPeriodic Method
RSA SigGen (FIPS186-5) (A4367)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A4368)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A4361)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A4362)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A4365)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A4366)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A4367)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A4368)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A4361)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A4362)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A4365)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A4366)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A4367)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A4368)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A4361)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A4362)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A4365)KATCASTOn demandManually

© 2024 IBM Corporation/ atsec information security.

Page 81
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA SigVer (FIPS186-5) (A4366)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A4367)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A4368)KATCASTOn demandManually
Safe Primes Key Generation (A4383)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A4361)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A4365)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A4366)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A4367)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A4368)PCTPCTOn demandManually
RSA KeyGen (FIPS186-5) (A4361)PCTPCTOn demandManually
RSA KeyGen (FIPS186-5) (A4365)PCTPCTOn demandManually
RSA KeyGen (FIPS186-5) (A4366)PCTPCTOn demandManually
RSA KeyGen (FIPS186-5) (A4367)PCTPCTOn demandManually
RSA KeyGen (FIPS186-5) (A4368)PCTPCTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
ErrorThe module immediately stops functioningSoftware integrity test failureModule resetOSSL_PROV_PARAM_STATUS is set to 0 or Module is aborted

Table 23: Conditional Periodic Information

10.4 Error States

© 2024 IBM Corporation/ atsec information security.

Page 82

Name

Description

Conditions CAST failure PCT failure

Recovery Method

Indicator

Table 24: Error States In the error state, the module immediately stops functioning and ends the application process. Consequently, the data output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running).

10.5 Operator Initiation of Self-Tests

The software integrity tests and cryptographic algorithm self-tests can be invoked on demand by resetting the module. The pair-wise consistency tests can be invoked on demand by requesting the key pair generation service. © 2024 IBM Corporation/ atsec information security.

Page 83
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The IBM DataPower security appliance ships with signed firmware which contains the module embedded in it. No additional steps are required to install or initialize the module.

11.2 Administrator Guidance

After delivery of the DataPower security appliance, the module name and version can be verified by executing the “openssl list -providers” command. The FIPS provider will be listed in the output as follows: fips name: IBM DataPower FIPS Provider version: 3.0.9-B3346E1D91BA83B7BAB52F472F3E6A0D status: active The cryptographic boundary consists only of the FIPS provider as listed. If any other OpenSSL or third-party provider is invoked, the user is not interacting with the module specified in this Security Policy.

11.3 Non-Administrator Guidance

There is no non-administrator guidance.

11.6 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. © 2024 IBM Corporation/ atsec information security.

Page 84
12 Mitigation of Other Attacks

Certain cryptographic subroutines and algorithms are vulnerable to timing analysis. The module mitigates this vulnerability by using constant-time implementations. This includes, but is not limited to:  Big number operations: computing GCDs, modular inversion, multiplication, division, and modular exponentiation (using Montgomery multiplication)  Elliptic curve point arithmetic: addition and multiplication (using the Montgomery ladder)  Vector-based AES implementations In addition, RSA, ECDSA, ECDH, and DH employ blinding techniques to further impede timing and power analysis. No configuration is needed to enable the aforementioned countermeasures. © 2024 IBM Corporation/ atsec information security.

Page 85
Table, extracted as text (did not parse into structured rows)
Appendix A. Glossary and abbreviations AES         Advanced Encryption Standard AES-NI      Advanced Encryption Standard New Instructions API         Application Programming Interface CAST        Cryptographic Algorithm Self-Test CAVP        Cryptographic Algorithm Validation Program CBC         Cipher Block Chaining CCM         Counter with Cipher Block Chaining-Message Authentication Code CFB         Cipher Feedback CKG         Cryptographic Key Generation CMAC        Cipher-based Message Authentication Code CMVP        Cryptographic Module Validation Program CPACF       CP Assist for Cryptographic Functions CSP         Critical Security Parameter CTR         Counter CTS         Ciphertext Stealing DH          Diffie-Hellman DRBG        Deterministic Random Bit Generator ECB         Electronic Code Book ECC         Elliptic Curve Cryptography ECDH        Elliptic Curve Diffie-Hellman ECDSA       Elliptic Curve Digital Signature Algorithm EVP         Envelope FFC         Finite Field Cryptography FIPS        Federal Information Processing Standards GCM         Galois Counter Mode GMAC        Galois Counter Mode Message Authentication Code HKDF        HMAC-based Key Derivation Function HMAC        Keyed-Hash Message Authentication Code IKE         Internet Key Exchange KAS         Key Agreement Scheme KAT         Known Answer Test KBKDF       Key-based Key Derivation Function KW          Key Wrap KWP         Key Wrap with Padding MAC         Message Authentication Code NIST        National Institute of Science and Technology OAEP        Optimal Asymmetric Encryption Padding OFB         Output Feedback PAA         Processor Algorithm Acceleration PCT         Pair-wise Consistency Test PBKDF2      Password-based Key Derivation Function v2 PKCS        Public-Key Cryptography Standards PSP         Public Security Parameter PSS         Probabilistic Signature Scheme RSA         Rivest, Shamir, Addleman SHA         Secure Hash Algorithm SSC         Shared Secret Computation SSH         Secure Shell SSP         Sensitive Security Parameter TLS         Transport Layer Security XOF         Extendable Output Function © 2024 IBM Corporation/ atsec information security.
Page 86

XTS XEX-based Tweaked-codebook mode with cipher text Stealing Glossary and abbreviations © 2024 IBM Corporation/ atsec information security.

Page 87
ANS X9.42-Public Key Cryptography for the Financial Services Industry:
2001Agreement of Symmetric Keys Using Discrete Logarithm Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9422001
ANS X9.63-Public Key Cryptography for the Financial Services Industry, Key
2001Agreement and Key Transport Using Elliptic Curve Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9632001
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/ fips-140-3-ig-announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-4Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS 186-5Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
FIPS 197Advanced Encryption Standard November 2001 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.197-upd1.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt
RFC 3526More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt © 2024 IBM Corporation/ atsec information security.
Page 88
RFC 5288AES Galois Counter Mode (GCM) Cipher Suites for TLS August 2008 https://www.ietf.org/rfc/rfc5288.txt
RFC 7919Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://www.ietf.org/rfc/rfc7919.txt
RFC 8446The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://www.ietf.org/rfc/rfc8446.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP 800-38ARecommendation for Block Cipher Modes of Operation: Three
AddendumVariants of Ciphertext Stealing for CBC Mode October 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a- add.pdf
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800- 38c.pdf
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP 800-38ERecommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP 800-38FRecommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP 800-52r2Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf
SP 800-56Ar3Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf © 2024 IBM Corporation/ atsec information security.
Page 89
SP 800-56Cr2Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf
SP 800-90Ar1Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP 800-90BRecommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP 800-108r1NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
SP 800-Transitioning the Use of Cryptographic Algorithms and Key
131Ar2Lengths March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800- 131Ar2.pdf
SP 800-132Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf
SP 800-133r2Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP 800-135r1Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800- 135r1.pdf
SP 800-CMVP Security Policy Requirements
140Br1November 2023 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800- 140Br1.pdf © 2024 IBM Corporation/ atsec information security.