All modules
CMVP Validated Module · FIPS 140-3 Security Policy

AWS-LC Cryptographic Module (static)

Certificate#4816StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorAmazon Web Services Inc.
Medium review priority  ·  no TCB surface named  ·  last validated 21 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date9/30/2029
CaveatWhen operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
VendorAmazon Web Services Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for AWS-LC Cryptographic Module (static)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery<br/>upgrade</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for AWS-LC Cryptographic Module (static)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery<br/>upgrade</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Amazon Web Services Inc. AWS-LC Cryptographic Module (static) Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 www.atsec.com

2024 Amazon Web Services, Inc., atsec information security.
Page 2
Table of Contents
#SectionPage
Page 3
2024 Amazon Web Services, Inc., atsec information security.
Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)7
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Modes List and Description8
Table 5: Approved Algorithms23
Table 6: Vendor-Affirmed Algorithms24
Table 7: Non-Approved, Allowed Algorithms with No Security Claimed24
Table 8: Non-Approved, Not Allowed Algorithms25
Table 9: Security Function Implementations32
Table 10: Ports and Interfaces36
Table 11: Roles37
Table 12: Approved Services42
Table 13: Non-Approved Services43
Table 14: EFP/EFT Information46
Table 15: Hardness Testing Temperatures46
Table 16: Storage Areas48
Table 17: SSP Input-Output Methods48
Table 18: SSP Zeroization Methods48
Table 19: SSP Table 151
Table 20: SSP Table 252
Table 21: Pre-Operational Self-Tests54
Table 22: Conditional Self-Tests55
Table 23: Pre-Operational Periodic Information56
Table 24: Conditional Periodic Information56
Table 25: Error States57
Figure 1: Block Diagram6
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version AWS-LC FIPS

2.0.0 of the AWS-LC Cryptographic Module (static). It contains the security rules under which

the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for

1.2 Security Levels
1.3 Additional Information

This Security Policy describes the features and design of the module named AWS-LC Cryptographic Module (static) using the terminology contained in the FIPS 140-3 specification. The FIPS 140-3 Security Requirements for Cryptographic Module specifies the security requirements that will be satisfied by a cryptographic module utilized within a security system protecting sensitive but unclassified information. The NIST/CCCS Cryptographic Module Validation Program (CMVP) validates cryptographic module to FIPS 140-3. Validated products are accepted by the Federal agencies of both the USA and Canada for the protection of sensitive or designated information. intact and including this notice. Other documentation is proprietary to their authors. In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing.

2024 Amazon Web Services, Inc., atsec information security.
Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The AWS-LC Cryptographic Module (static) (hereafter referred to as “the module”) provides cryptographic services to applications running in the user space of the underlying operating system through a C language Application Program Interface (API). Module Type: Software Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: The block diagram in Figure 1 shows the cryptographic boundary of the module, its interfaces with the operational environment and the flow of information between the module and operator (depicted through the arrows). The cryptographic boundary is defined as the AWS-LC Cryptographic Module (static) which is a cryptographic library consisting of the bcm.o file (version AWS-LC FIPS 2.0.0). This file is statically linked to the userspace application during the compilation process. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP is the general-purpose computer on which the module is installed. Figure 1: Block Diagram

2024 Amazon Web Services, Inc., atsec information security.
Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
bcm.o on Amazon Linux 2 with Intel ®Xeon ® Platinum 8275CLAWS-LC FIPS 2.0.0N/AHMAC-SHA2-256
bcm.o on Amazon Linux 2023 with Intel ®Xeon ® Platinum 8275CLAWS-LC FIPS 2.0.0N/AHMAC-SHA2-256
bcm.o on Ubuntu 22.04 with Intel ®Xeon ® Platinum 8275CLAWS-LC FIPS 2.0.0N/AHMAC-SHA2-256
bcm.o on Amazon Linux 2 with Gravition3AWS-LC FIPS 2.0.0N/AHMAC-SHA2-256
bcm.o on Amazon Linux 2023 with Gravition3AWS-LC FIPS 2.0.0N/AHMAC-SHA2-256
bcm.o on Ubuntu 22.04 with Gravition3AWS-LC FIPS 2.0.0N/AHMAC-SHA2-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Amazon Linux 2Amazon EC2 c5.metal with 192 GiB system memory and Elastic Block Store (EBS) 200 GiBIntel® Xeon® Platinum 8275CLYesN/AAWS-LC FIPS 2.0.0
Amazon Linux 2023Amazon EC2 c5.metal with 192 GiB system memory and Elastic Block Store (EBS) 200 GiBIntel® Xeon® Platinum 8275CLYesN/AAWS-LC FIPS 2.0.0
Ubuntu 22.04Amazon EC2 c5.metal with 192 GiB system memory and Elastic Block Store (EBS) 200 GiBIntel® Xeon® Platinum 8275CLYesN/AAWS-LC FIPS 2.0.0
Amazon Linux 2Amazon EC2 c7g.metal with 128 GiB system memory and Elastic Block Store (EBS) 200 GiBGraviton3YesN/AAWS-LC FIPS 2.0.0
2.2 Tested and Vendor Affirmed Module Version and

Identification Tested Module Identification

2024 Amazon Web Services, Inc., atsec information security.
Page 8
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Amazon Linux 2023Amazon EC2 c7g.metal with 128 GiB system memory and Elastic Block Store (EBS) 200 GiBGraviton3YesN/AAWS-LC FIPS 2.0.0
Ubuntu 22.04Amazon EC2 c7g.metal with 128 GiB system memory and Elastic Block Store (EBS) 200 GiBGraviton3YesN/AAWS-LC FIPS 2.0.0
Mode NameDescriptionTypeStatus Indicator
Approved ModeAutomatically entered whenever an approved service is requested.ApprovedEquivalent to the indicator of the requested service.
Non-approved ModeAutomatically entered whenever a non- approved service is requested.Non- ApprovedEquivalent to the indicator of the requested service.

Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module. CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

The module does not claim any excluded components.

2.4 Modes of Operation

Modes List and Description: Table 4: Modes List and Description When the module starts up successfully, after passing the pre-operational self-test and the cryptographic algorithms self-tests (CASTs), the module is operating in the approved mode of operation by default and can only be transitioned into the non-approved mode by calling one of the non-approved services listed in the Non-Approved Services table. The module will transition back to approved mode when approved service is called. Section 4 provides details on the service indicator implemented by the module. The service indicator identifies The module does not implement a degraded mode of operation.

2024 Amazon Web Services, Inc., atsec information security.
Page 9
AlgorithmCAVP CertPropertiesReference
ECDSA KeyGen (FIPS186-5)A4509Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4509Curve - P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4509Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A4509Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A4509Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-5
HMAC-SHA-1A4509Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4509Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4509Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4509Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4509Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4509Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4509Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800- 56Cr1A4509Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-56C Rev. 2
KDF SSH (CVL)A4509Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF TLS (CVL)A4509TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
PBKDFA4509Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 14-128 Increment 1SP 800-132
RSA KeyGen (FIPS186- 5)A4509Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5
2.5 Algorithms
2024 Amazon Web Services, Inc., atsec information security.
Page 10
AlgorithmCAVP CertPropertiesReference
RSA SigGen (FIPS186- 5)A4509Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186- 4)A4509Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 5)A4509Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A4509Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4509Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4509Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4509Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4509Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4509Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
AES-CBCA4510Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4510Key Length - 128SP 800-38C
AES-CMACA4510Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CTRA4510Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4510Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA4510Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA4510Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-XTS Testing Revision 2.0A4510Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
Counter DRBGA4510Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
AES-ECBA4511Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4511Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4511Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
2024 Amazon Web Services, Inc., atsec information security.
Page 11
AlgorithmCAVP CertPropertiesReference
AES-ECBA4512Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4512Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4512Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-CBCA4513Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4513Key Length - 128SP 800-38C
AES-CMACA4513Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CTRA4513Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4513Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA4513Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA4513Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-XTS Testing Revision 2.0A4513Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
Counter DRBGA4513Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
AES-ECBA4514Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4514Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4514Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-CBCA4515Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4515Key Length - 128SP 800-38C
AES-CMACA4515Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CTRA4515Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4515Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA4515Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA4515Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
2024 Amazon Web Services, Inc., atsec information security.
Page 12
AlgorithmCAVP CertPropertiesReference
AES-XTS Testing Revision 2.0A4515Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
Counter DRBGA4515Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
AES-ECBA4516Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4516Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4516Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
ECDSA KeyGen (FIPS186-5)A4517Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4517Curve - P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4517Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A4517Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A4517Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-5
HMAC-SHA-1A4517Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4517Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4517Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4517Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4517Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4517Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4517Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800- 56Cr1A4517Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-56C Rev. 2
2024 Amazon Web Services, Inc., atsec information security.
Page 13
AlgorithmCAVP CertPropertiesReference
KDF SSH (CVL)A4517Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF TLS (CVL)A4517TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
PBKDFA4517Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 14-128 Increment 1SP 800-132
RSA KeyGen (FIPS186- 5)A4517Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186- 5)A4517Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186- 4)A4517Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 5)A4517Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A4517Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4517Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4517Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4517Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4517Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4517Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
ECDSA KeyGen (FIPS186-5)A4518Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4518Curve - P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4518Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A4518Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A4518Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-5
HMAC-SHA-1A4518Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
2024 Amazon Web Services, Inc., atsec information security.
Page 14
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2-224A4518Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4518Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4518Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4518Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4518Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4518Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800- 56Cr1A4518Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-56C Rev. 2
KDF SSH (CVL)A4518Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF TLS (CVL)A4518TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
PBKDFA4518Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 14-128 Increment 1SP 800-132
RSA KeyGen (FIPS186- 5)A4518Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186- 5)A4518Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186- 4)A4518Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 5)A4518Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A4518Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4518Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4518Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4518Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
2024 Amazon Web Services, Inc., atsec information security.
Page 15
AlgorithmCAVP CertPropertiesReference
SHA2-512A4518Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4518Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
AES-CBCA4519Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4519Key Length - 128SP 800-38C
AES-CMACA4519Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CTRA4519Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4519Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA4519Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA4519Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-XTS Testing Revision 2.0A4519Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
Counter DRBGA4519Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
AES-ECBA4520Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4520Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4520Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-ECBA4521Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4521Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4521Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-ECBA4522Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4522Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4522Direction - Decrypt, Encrypt IV Generation - External, InternalSP 800-38D
2024 Amazon Web Services, Inc., atsec information security.
Page 16
AlgorithmCAVP CertProperties IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256Reference
AES-CBCA4523Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4523Key Length - 128SP 800-38C
AES-CMACA4523Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CTRA4523Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4523Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA4523Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA4523Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-XTS Testing Revision 2.0A4523Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
Counter DRBGA4523Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
AES-ECBA4524Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4524Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4524Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-ECBA4525Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4525Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4525Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-ECBA4526Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4526Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4526Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-CBCA4527Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
2024 Amazon Web Services, Inc., atsec information security.
Page 17
AlgorithmCAVP CertPropertiesReference
AES-CCMA4527Key Length - 128SP 800-38C
AES-CMACA4527Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CTRA4527Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4527Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA4527Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA4527Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-XTS Testing Revision 2.0A4527Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
Counter DRBGA4527Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
AES-ECBA4528Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4528Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4528Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-ECBA4529Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4529Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4529Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-ECBA4530Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4530Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
AES-GMACA4530Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 256SP 800-38D
ECDSA KeyGen (FIPS186-5)A4531Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4531Curve - P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4531Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-FIPS 186-5
2024 Amazon Web Services, Inc., atsec information security.
Page 18
AlgorithmCAVP CertProperties 384, SHA2-512 Component - NoReference
ECDSA SigVer (FIPS186-4)A4531Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A4531Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-5
HMAC-SHA-1A4531Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4531Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4531Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4531Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4531Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4531Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4531Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800- 56Cr1A4531Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-56C Rev. 2
KDF SSH (CVL)A4531Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF TLS (CVL)A4531TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
PBKDFA4531Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 14-128 Increment 1SP 800-132
RSA KeyGen (FIPS186- 5)A4531Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186- 5)A4531Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186- 4)A4531Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 5)A4531Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A4531Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
2024 Amazon Web Services, Inc., atsec information security.
Page 19
AlgorithmCAVP CertPropertiesReference
SHA2-224A4531Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4531Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4531Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4531Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4531Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
ECDSA KeyGen (FIPS186-5)A4532Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4532Curve - P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4532Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A4532Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A4532Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-5
HMAC-SHA-1A4532Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4532Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4532Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4532Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4532Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4532Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4532Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800- 56Cr1A4532Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-56C Rev. 2
2024 Amazon Web Services, Inc., atsec information security.
Page 20
AlgorithmCAVP CertPropertiesReference
KDF SSH (CVL)A4532Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF TLS (CVL)A4532TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
PBKDFA4532Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 14-128 Increment 1SP 800-132
RSA KeyGen (FIPS186- 5)A4532Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186- 5)A4532Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186- 4)A4532Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 5)A4532Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A4532Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4532Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4532Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4532Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4532Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4532Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
ECDSA KeyGen (FIPS186-5)A4533Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4533Curve - P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4533Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A4533Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A4533Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-5
HMAC-SHA-1A4533Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
2024 Amazon Web Services, Inc., atsec information security.
Page 21
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2-224A4533Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4533Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4533Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4533Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4533Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4533Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800- 56Cr1A4533Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-56C Rev. 2
KDF SSH (CVL)A4533Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF TLS (CVL)A4533TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
PBKDFA4533Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 14-128 Increment 1SP 800-132
RSA KeyGen (FIPS186- 5)A4533Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186- 5)A4533Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186- 4)A4533Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 5)A4533Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A4533Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4533Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4533Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4533Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
2024 Amazon Web Services, Inc., atsec information security.
Page 22
AlgorithmCAVP CertPropertiesReference
SHA2-512A4533Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4533Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
ECDSA KeyGen (FIPS186-5)A4534Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4534Curve - P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4534Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A4534Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A4534Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-5
HMAC-SHA-1A4534Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4534Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4534Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4534Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4534Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512/256A4534Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4534Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800- 56Cr1A4534Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-56C Rev. 2
KDF SSH (CVL)A4534Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF TLS (CVL)A4534TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
PBKDFA4534Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 14-128 Increment 1SP 800-132
RSA KeyGen (FIPS186- 5)A4534Key Generation Mode - probable Modulo - 2048, 3072, 4096FIPS 186-5
2024 Amazon Web Services, Inc., atsec information security.
Page 23
AlgorithmCAVP CertProperties Primality Tests - 2powSecStr Private Key Format - standardReference
RSA SigGen (FIPS186- 5)A4534Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186- 4)A4534Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 5)A4534Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A4534Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4534Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4534Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4534Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4534Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4534Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
NamePropertiesImplementationReference
Cryptographic Key Generation (CKG)RSA (FIPS 186-5):2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. EC (FIPS 186-5):P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strengthAWS-LC Cryptographic Module (static build) (SHA_ASM)SP 800-133Rev2 section 5.1 and 5.2
Cryptographic Key Generation (CKG)RSA (FIPS 186-5):2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. EC (FIPS 186-5):P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength.AWS-LC Cryptographic Module (static build) (SHA_CE)SP 800-133Rev2 section 5.1 and 5.2
Cryptographic Key Generation (CKG)RSA (FIPS 186-5):2048, 3072, 4096 bits with 112, 128, 149 bits of key strength EC (FIPS 186-5):P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength.AWS-LC Cryptographic Module (static build) (NEON)SP 800-133Rev2 section 5.1 and 5.2
Cryptographic Key Generation (CKG)RSA (FIPS 186-5):2048, 3072, 4096 bits with 112, 128, 149 bits of key strength.AWS-LC Cryptographic Module (static build) (SHA_SHANI)SP 800-133Rev2 section 5.1 and 5.2

Table 5: Approved Algorithms Vendor-Affirmed Algorithms:

2024 Amazon Web Services, Inc., atsec information security.
Page 24
NameProperties EC (FIPS 186-5):P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength.ImplementationReference
Cryptographic Key Generation (CKG)RSA (FIPS 186-5):2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. EC (FIPS 186-5):P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength.AWS-LC Cryptographic Module (static build) (SHA_AVX2)SP 800-133Rev2 section 5.1 and 5.2
Cryptographic Key Generation (CKG)RSA (FIPS 186-5):2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. EC (FIPS 186-5):P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength.AWS-LC Cryptographic Module (static build) (SHA_AVX)SP 800-133Rev2 section 5.1 and 5.2
Cryptographic Key Generation (CKG)RSA (FIPS 186-5):2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. EC (FIPS 186-5):P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength.AWS-LC Cryptographic Module (static build) (SHA_SSSE3)SP 800-133Rev2 section 5.1 and 5.2
NameCaveatUse and Function
MD5Allowed per IG 2.4.AMessage Digest used in TLS 1.0/1.1 KDF only
NameUse and Function
AES with OFB or CFB1, CFB8 modesEncryption, Decryption
AES GCM, GCM, GMAC, XTS with keys not listed in Table 5Encryption, Decryption
AES using aes_*_generic functionEncryption, Decryption
AES GMAC using aes_*_genericMessage Authentication Generation
Curve secp256k1Signature Generation, Signature Verification, Shared Secret Computation
Diffie HellmanShared Secret Computation
HMAC-MD4, HMAC-MD5, HMAC-SHA1, HMAC-SHA-3, HMAC- RIPEMD-160Message Authentication Generation
MD4Message Digest

Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. The module does not implement non-approved algorithms that are allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: Table 7: Non-Approved, Allowed Algorithms with No Security Claimed Non-Approved, Not Allowed Algorithms:

2024 Amazon Web Services, Inc., atsec information security.
Page 25
NameUse and Function
MD5 (outside of TLS)Message Digest
RSA using RSA_generate_key_exKey Generation
ECDSA using EC_KEY_generate_keyKey Generation
RSA using keys less than 2048 bitsSignature Generation
RSA using keys less than 1024 bitsSignature Verification
RSA without hashingSign/Verify primitive operations
RSA encryption primitive with PKCS#1 v1.5 and OAEP paddingEncryption
SHA-1, SHA-3Signature Generation
SHAKE, RIPEMD-160, SHA-3Message Digest
TLS KDF using any SHA algorithms other than SHA2-256, SHA2-384, SHA2-512; or TLS KDF using non-extended master secretKey Derivation
RSAKey Encapsulation/Un-encapsulation
NameTypeDescriptionPropertiesAlgorithms
Shared Secret Computation with EC Diffie-HellmanKAS-SSCShared secret computation per SP 800-56ARev3Curves:P-224, P-256, P-384, P-521 elliptic curves with 112-256 bits of key strength Compliance:Compliant with IG D.F scenario 2(1)KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3
Key Wrapping/Unwrapping with AES KW, AES- KWPKTS-WrapKey wrapping, key unwrapping using AES KW/KWPKeys:128, 192, 256 bits with 128-256 bits of key strength Compliance:Compliant with IG D.GAES-KW AES-KWP AES-KW AES-KWP AES-KW AES-KWP AES-KW AES-KWP AES-KW AES-KWP AES-KW AES-KWP
Key Wrapping/Unwrapping with AES GCMKTS-WrapKey wrapping, key unwrapping using AES GCMKeys:128 and 256 bits with 128 and 256 bits of key strength Compliance: Compliant with IG D.GAES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM

Table 8: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations
2024 Amazon Web Services, Inc., atsec information security.
Page 26
NameTypeDescriptionPropertiesAlgorithms AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM
Key Wrapping/Unwrapping with AES CCMKTS-WrapKey wrapping, key unwrapping using AES CCMKeys:128 bits with 128 bits of key strength Compliance:Compliant with IG D.GAES-CCM AES-CCM AES-CCM AES-CCM AES-CCM AES-CCM
Encryption/Decryption with AESBC-UnAuthEncryption, decryption using AESKeys:128, 192, 256 bits keys with 128- 256 of key strengthAES-CBC AES-CTR AES-ECB AES-XTS Testing Revision 2.0 AES-ECB AES-ECB AES-CBC AES-CTR AES-ECB AES-XTS Testing Revision 2.0 AES-ECB AES-CBC AES-CTR AES-ECB AES-XTS Testing Revision 2.0 AES-ECB AES-CBC AES-CTR AES-ECB AES-XTS Testing Revision 2.0 AES-ECB AES-ECB AES-ECB AES-CBC AES-CTR AES-ECB AES-XTS Testing Revision 2.0 AES-ECB AES-ECB AES-ECB AES-CBC AES-CTR AES-ECB AES-XTS Testing Revision 2.0 AES-ECB AES-ECB AES-ECB
Signature Generation with RSADigSig-SigGenDigital signature generation using RSAKeys:2048, 3072, 4096 bits with 112- 150 bits of strengthRSA SigGen (FIPS186-5) RSA SigGen
2024 Amazon Web Services, Inc., atsec information security.
Page 27
NameTypeDescriptionPropertiesAlgorithms (FIPS186-5) RSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5) RSA SigGen (FIPS186-5)
Signature Generation with ECDSADigSig-SigGenDigital signature generation using ECDSACurves:P-224, P-256, P-384, P-521 with 112-256 bits of key strengthECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5) ECDSA SigGen (FIPS186-5)
Key Generation with RSAAsymKeyPair- KeyGenKey generation using RSAKeys:2048, 3072, 4096 bits key with 112-150 bits of strengthRSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5) RSA KeyGen (FIPS186-5)
Key Generation with ECDSAAsymKeyPair- KeyGenKey generation using ECDSACurves:P-224, P-256, P-384, P-521 with 112-256 bits of strengthECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5) ECDSA KeyGen (FIPS186-5)
Signature Verification with ECDSADigSig-SigVerSignature verification using ECDSACurves:P-224, P-256, P-384, P-521 with 112-256 bits of strengthECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4)
2024 Amazon Web Services, Inc., atsec information security.
Page 28
NameTypeDescriptionPropertiesAlgorithms ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5) ECDSA SigVer (FIPS186-5)
Signature Verification with RSADigSig-SigVerSignature verification using RSAKeys:1024, 2048, 3072, 4096 bits with 80-150 bits of strengthRSA SigVer (FIPS186-4) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-5) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-5)
Key Verification with ECDSAAsymKeyPair- KeyVerKey verification using ECDSACurves:P-224, P-256, P-384, P-521 with 112-256 bits of strengthECDSA KeyVer (FIPS186-5) ECDSA KeyVer (FIPS186-5) ECDSA KeyVer (FIPS186-5)
2024 Amazon Web Services, Inc., atsec information security.
Page 29
NameTypeDescriptionPropertiesAlgorithms ECDSA KeyVer (FIPS186-5) ECDSA KeyVer (FIPS186-5) ECDSA KeyVer (FIPS186-5) ECDSA KeyVer (FIPS186-5)
Key Derivation with TLS KDFKAS-135KDFKey derivation using TLS KDFDerived keys:112 to 256 bitsKDF TLS KDF TLS KDF TLS KDF TLS KDF TLS KDF TLS KDF TLS
Key Derivation with SSH KDFKAS-135KDFKey derivation using SSH KDFSSH Derived keys:112 to 256 bitsKDF SSH KDF SSH KDF SSH KDF SSH KDF SSH KDF SSH KDF SSH
Key Derivation with KDA HKDFKAS-56CKDFKey derivation using KDA HKDFDerived keys:112 to 256 bitsKDA HKDF Sp800- 56Cr1 KDA HKDF Sp800- 56Cr1 KDA HKDF Sp800- 56Cr1 KDA HKDF Sp800- 56Cr1 KDA HKDF Sp800- 56Cr1 KDA HKDF Sp800- 56Cr1 KDA HKDF Sp800- 56Cr1
Key Derivation with PBKDFPBKDFKey derivation using PBKDFDerived keys:112 to 256 bitsPBKDF PBKDF PBKDF PBKDF PBKDF PBKDF PBKDF
Message Digest with SHASHAMessage digest using SHASHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA2-512/256 SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA2-512/256 SHA-1 SHA2-224
2024 Amazon Web Services, Inc., atsec information security.
Page 30
NameTypeDescriptionPropertiesAlgorithms SHA2-256 SHA2-384 SHA2-512 SHA2-512/256 SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA2-512/256 SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA2-512/256 SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA2-512/256 SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA2-512/256
Random Number Generation with DRBGDRBGRandom number generation using DRBGCompliance:Compliant with SP800-90ARev1Counter DRBG Counter DRBG Counter DRBG Counter DRBG Counter DRBG Counter DRBG
Message Authentication Generation with HMACMACMessage authentication generation using HMACSHA algorithm:SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2- 512/256 HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2- 512/256 HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2- 512/256 HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256
2024 Amazon Web Services, Inc., atsec information security.
Page 31
NameTypeDescriptionPropertiesAlgorithms HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2- 512/256 HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2- 512/256 HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2- 512/256 HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2- 512/256
Message Authentication Generation with AESMACMessage authentication generation using AES CMAC/GMACKeys:128 or 256 bits with 128 or 256 bits of strengthAES-CMAC AES-GMAC AES-GMAC AES-CMAC AES-GMAC AES-CMAC AES-GMAC AES-CMAC AES-GMAC AES-GMAC AES-GMAC AES-CMAC AES-GMAC AES-GMAC AES-GMAC AES-CMAC AES-GMAC AES-GMAC AES-GMAC
Authenticated Encryption/Decryption with AES CCMBC-AuthAuthenticated encryption and decryption using AES CCMKeys:128 bits with 128 bits of strengthAES-CCM AES-CCM AES-CCM AES-CCM AES-CCM AES-CCM
Authenticated Encryption/Decryption with AES GCMBC-AuthAuthenticated encryption and decryption using AES GCMKeys:128 or 256 bits with 128 or 256 bits of strength Authenticated Encryption:Internal IV Mode 8.2.2 Authenticated Decryption:External IVAES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM
2024 Amazon Web Services, Inc., atsec information security.
Page 32

Name

Type

Description

Properties

Algorithms AES-GCM AES-GCM AES-GCM AES-GCM

Table 9: Security Function Implementations

2.7 Algorithm Specific Information

GCM IV The module offers three AES GCM implementations. The GCM IV generation for these implementations complies respectively with IG C.H under Scenario 1, Scenario 2, and Scenario 5. The GCM shall only be used in the context of the AES-GCM encryption executing under each scenario, and using the referenced APIs explained next. Scenario 1, TLS 1.2 For TLS 1.2, the module offers the GCM implementation via the functions EVP_aead_aes_128_gcm_tls12() and EVP_aead_aes_256_gcm_tls12(), and uses the context of Scenario 1 of IG C.H. The module is compliant with SP800-52rev2 and the mechanism for IV generation is compliant with RFC5288. The module supports acceptable AES-GCM ciphersuites from Section 3.3.1 of SP800-52rev2. The module explicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values of 2^{64-1} for a given session key. If this exhaustion condition is observed, the module returns an error indication to the calling application, which will then need to either abort the connection, or trigger a handshake to establish a new encryption key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established. Scenario 2, Random IV In this implementation, the module offers the interfaces EVP_aead_aes_128_gcm_randnonce() and EVP_aead_aes_256_gcm_randnonce() for compliance with Scenario 2 of IG C.H and SP800-38D Section 8.2.2. The AES-GCM IV is generated randomly internal to the module using module’s approved DRBG. The DRBG seeds itself from the entropy source. The GCM IV is 96 bits in length. Per Section 9, this 96bit IV contains 96 bits of entropy. Scenario 5, TLS 1.3 August 2018, using the ciphersuites that explicitly select AES-GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES-GCM ciphersuites from Section 3.3.1 of SP800-52rev2. The module implements, within its boundary, an IV generation unit for TLS 1.3 that keeps control of the 64-bit counter value within the AES-GCM IV. If the exhaustion condition is observed, the module will return an error indication to the calling application, who will then need to either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection.

2024 Amazon Web Services, Inc., atsec information security.
Page 33

In the event the module’s power is lost and restored, the consuming application must ensure that new AES-GCM keys encryption or decryption under this scenario are established. TLS

1.3 provides session resumption, but the resumption procedure derives new AES-GCM

encryption keys. AES XTS The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit. Key Derivation using SP 800-132 PBKDF2 The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:

2024 Amazon Web Services, Inc., atsec information security.
Page 34
2.8 RBG and Entropy

N/A for this module. N/A for this module. The module provides an SP800-90Arev1-compliant Deterministic Random Bit Generator (DRBG) using CTR_DRBG mechanism with AES-256 for generation of key components of asymmetric keys, and random number generation. The DRBG is seeded with 256-bit of entropy input provided from an external entity to the module. This corresponds to scenario 2 (b) of IG 9.3.A i.e., the DRBG that receives a LOAD command with entropy obtained from inside the physical perimeter of the operational environment but outside of module's cryptographic boundary. The calling application shall use an entropy source that meets the security strength required for the CTR_DRBG as shown in NIST SP 800-90Arev1, Table 3 and should return an error if minimum strength cannot be met. Per the IG 9.3.A requirement, the module includes the caveat "No assurance of the minimum strength of generated keys".

2.9 Key Generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800-133Rev2. When random values are required, they are obtained from the SP 800-90ARev1 approved DRBG, compliant with Section 4 of SP 800-133Rev2. The following methods are implemented: ECDSA (FIPS 186-5, A.2.2 Rejection Sampling): P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength. RSA (FIPS 186-5, A.1.3 Random Probable Primes): 2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. Additionally, the module implements the following key derivation methods per SP800133Rev2 section 6.2: KDA HKDF (SP 800-56CRev1): 112-256 bits of key strength, using (HMAC) SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512. PBKDF (SP 800-133Rev2, option 1a): 112-256 bits of key strength, using (HMAC) SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512. SSH KDF (SP 800-135Rev1): 112-256 bits of key strength, using AES-128, AES-192, AES-256 with SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512. KDF TLS (SP 800-135Rev1): 112-256 bits of key strength, using SHA2-256, SHA2-384, SHA2512.

2.10 Key Establishment

The module implements SSP agreement and SSP transport methods as listed in the Security Function Implementations table.

2.11 Industry Protocols

The module implements the SSH key derivation function for use in the SSH protocol (RFC

4253 and RFC 6668).
2024 Amazon Web Services, Inc., atsec information security.
Page 35

GCM with internal IV generation in the approved mode is compliant with versions 1.2 and 1.3 of the TLS protocol (RFC 5288 and 8446) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the TLS 1.2 and TLS 1.3 key derivation functions for use in the TLS protocol. No parts of the SSH, TLS, other than those mentioned above, have been tested by the CAVP and CMVP.

2024 Amazon Web Services, Inc., atsec information security.
Page 36
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters for data.
N/AData OutputAPI output parameters for data.
N/AControl InputAPI function calls.
N/AStatus OutputAPI return codes, error message.
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 10: Ports and Interfaces As a Software module, the module interfaces are defined as Software or Firmware Module Interfaces (SMFI), and there are no physical ports. The module does not implement a control

2024 Amazon Web Services, Inc., atsec information security.
Page 37
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
EncryptionEncryptionReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()AES key, plaintextCiphertextEncryption/Decrypt ion with AESCrypto Officer - AES Key: W,E
DecryptionDecryptionReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()AES key, ciphertextPlaintextEncryption/Decrypt ion with AESCrypto Officer - AES Key: W,E
Authenticate d EncryptionAuthenticated EncryptionReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()AES key, plaintextCiphertextAuthenticated Encryption/Decrypt ion with AES CCM Authenticated Encryption/Decrypt ion with AES GCMCrypto Officer - AES Key: W,E
Authenticate d DecryptionAuthenticated DecryptionReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()AES key, ciphertextPlaintextAuthenticated Encryption/Decrypt ion with AES CCM Authenticated Encryption/Decrypt ion with AES GCMCrypto Officer - AES Key: W,E
Key WrappingEncrypting a keyReturn value 1 from the function: FIPS_ service_AES key wrapping key, KeyWrapped keyKey Wrapping/Unwrapp ing with AES KW, AES-KWPCrypto Officer - AES Key: W,E
4 Roles, Services, and Authentication

N/A for this module. The module does not support authentication.

4.2 Roles

Table 11: Roles The module does not support concurrent operators.

4.3 Approved Services
2024 Amazon Web Services, Inc., atsec information security.
Page 38
NameDescriptionIndicator indicator_ check_approve d()Inputs to be wrappedOutputsSecurity Functions Key Wrapping/Unwrapp ing with AES GCM Key Wrapping/Unwrapp ing with AES CCMSSP Access
Key unwrappingDecrypting a keyReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()AES key unwrappi ng key, Key to be unwrappe dUnwrappe d keyKey Wrapping/Unwrapp ing with AES KW, AES-KWP Key Wrapping/Unwrapp ing with AES GCM Key Wrapping/Unwrapp ing with AES CCMCrypto Officer - AES Key: W,E
Message Authenticati on GenerationMAC computationReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()AES key or HMAC key, messageMAC tagMessage Authentication Generation with HMAC Message Authentication Generation with AESCrypto Officer - HMAC Key: W,E
Message DigestGenerating message digestReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()MessageMessage digestMessage Digest with SHACrypto Officer
Random Number GenerationGenerating random numbersReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()Output lengthRandom bytesRandom Number Generation with DRBGCrypto Officer - Entropy Input: W,E - DRBG Seed: G,E - DRBG Internal State (V, Key): G,W,E
Key GenerationGenerating a key pairReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()Modulus size / CurveRSA public key, RSA private key / EC public key, EC private keyKey Generation with RSA Key Generation with ECDSACrypto Officer - RSA Public Key : G,R - RSA Private Key: G,R - EC Public Key: G,R - EC Private Key: G,R
2024 Amazon Web Services, Inc., atsec information security.
Page 39
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Key VerificationVerifying the public keyReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()Public keySuccess/ errorKey Verification with ECDSACrypto Officer - EC Public Key: W,E
Signature GenerationGenerating signatureReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()Message, EC private key or RSA private keyDigital signatureSignature Generation with RSA Signature Generation with ECDSACrypto Officer - RSA Private Key: W,E - EC Private Key: W,E
Signature VerificationVerifying signatureReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d(Signature, EC public key or RSA public keyDigital signature verificatio n resultSignature Verification with ECDSA Signature Verification with RSACrypto Officer - RSA Public Key : W,E - EC Public Key: W,E
Shared Secret ComputationCalculating the Shared SecretReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()EC public key, EC private keyShared SecretShared Secret Computation with EC Diffie-HellmanCrypto Officer - EC Public Key: W,E - EC Private Key: W,E - Shared Secret: G,R
Key Derivation with TLS KDFDeriving KeysReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()TLS Pre- Master Secret / TLS Master SecretTLS Master secret / TLS Derived Key (AES/HMA C)Key Derivation with TLS KDFCrypto Officer - TLS Pre- Master Secret: W,E - TLS Master Secret : G,W,E - TLS Derived Key (AES/HMAC ): G
Key Derivation with PBKDFDeriving KeysReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()Password, salt, iteration countPBKDF Derived KeyKey Derivation with PBKDFCrypto Officer - PBKDF Derived Key: G,R - Password: W,E
2024 Amazon Web Services, Inc., atsec information security.
Page 40
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Key Derivation with KDA HKDFDeriving KeysReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()Shared Secret, Key Length, DigestKDA Derived KeyKey Derivation with KDA HKDFCrypto Officer - KDA Derived Key: G,R - Shared Secret: W,E
Key Derivation with SSH KDFDeriving KeysReturn value 1 from the function: FIPS_ service_ indicator_ check_approve d()Shared Secret, Key LengthSSH Derived KeyKey Derivation with SSH KDFCrypto Officer - SSH Derived Key: G,R - Shared Secret: W,E
ZeroizationZeroize SSP in volatile memoryN/ASSPN/ANoneCrypto Officer - AES Key: Z - HMAC Key: Z - Entropy Input: Z - DRBG Seed: Z - DRBG Internal State (V, Key): Z - RSA Public Key : Z - RSA Private Key: Z - RSA Private Key: Z - EC Public Key: Z - EC Private Key: Z - Shared Secret: Z - TLS Pre- Master Secret: Z - TLS Master Secret : Z - TLS Derived Key (AES/HMAC ): Z
2024 Amazon Web Services, Inc., atsec information security.
Page 41
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - TLS Derived Key (AES/HMAC ): Z - Password: Z - Intermedia te Key Generation Value: Z
On-Demand Self-testInitiate power-on self-tests by resetN/AN/APass or failShared Secret Computation with EC Diffie-Hellman Key Wrapping/Unwrapp ing with AES KW, AES-KWP Key Wrapping/Unwrapp ing with AES GCM Key Wrapping/Unwrapp ing with AES CCM Encryption/Decrypt ion with AES Signature Generation with RSA Signature Generation with ECDSA Key Generation with RSA Key Generation with ECDSA Key Generation with RSA Signature Verification with ECDSA Signature Verification with RSA Key Verification with ECDSA Key Derivation with TLS KDF Key Derivation with SSH KDF Key Derivation with KDA HKDF Key Derivation with PBKDF Message DigestCrypto Officer
2024 Amazon Web Services, Inc., atsec information security.
Page 42
NameDescriptionIndicatorInputsOutputsSecurity Functions with SHA Random Number Generation with DRBG Message Authentication Generation with HMAC Message Authentication Generation with AES Authenticated Encryption/Decrypt ion with AES CCM Authenticated Encryption/Decrypt ion with AES GCMSSP Access
On-Demand Integrity TestInitiate integrity test on-demandN/AN/APass or failMessage Authentication Generation with HMACCrypto Officer
Show StatusShow status of the module stateN/AN/AModule statusNoneCrypto Officer
Show VersionShow the version of the module using awslc_version_stri ngN/AN/AModule name and versionNoneCrypto Officer

Table 12: Approved Services For the above table, the convention below applies when specifying the access permissions (types) that the service has for each SSP.

2024 Amazon Web Services, Inc., atsec information security.
Page 43
NameDescriptionAlgorithmsRole
EncryptionEncryptionAES with OFB or CFB1, CFB8 modes AES GCM, GCM, GMAC, XTS with keys not listed in Table 5 AES using aes_*_generic function AES GMAC using aes_*_generic RSA encryption primitive with PKCS#1 v1.5 and OAEP paddingCO
DecryptionDecryptionAES with OFB or CFB1, CFB8 modes AES GCM, GCM, GMAC, XTS with keys not listed in Table 5 AES using aes_*_generic function AES GMAC using aes_*_genericCO
Message Authentication GenerationMAC computationAES GMAC using aes_*_generic HMAC-MD4, HMAC-MD5, HMAC-SHA1, HMAC-SHA-3, HMAC-RIPEMD-160CO
Message DigestGenerating message digestMD4 MD5 (outside of TLS) SHAKE, RIPEMD-160, SHA-3CO
Signature GenerationGenerating signaturesRSA using keys less than 2048 bits RSA without hashing SHA-1, SHA-3CO
Signature VerificationVerifying signaturesRSA using keys less than 1024 bits RSA without hashingCO
Key GenerationGenerating key pairRSA using RSA_generate_key_ex ECDSA using EC_KEY_generate_keyCO
Shared Secret ComputationCalculating shared secretCurve secp256k1 Diffie HellmanCO
Key DerivationDeriving TLS keysTLS KDF using any SHA algorithms other than SHA2- 256, SHA2-384, SHA2-512; or TLS KDF using non- extended master secretCO
Key EncapsulationEncrypting a keyRSACO
Key Un- encapsulationDecrypting a keyRSACO

int after = FIPS_service_indicator_after_call(); • STEP 4: Return value 1 indicates approved service was invoked. int ret = FIPS_service_indicator_check_approved(before, after); Alternatively, all the above steps can be done by using a single call using the function CALL_SERVICE_AND_CHECK_APPROVED(approved, func).

4.4 Non-Approved Services

Table 13: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not support loading of external software or firmware.

2024 Amazon Web Services, Inc., atsec information security.
Page 44
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC value calculated at run time on the bcm.o file, with the HMAC-SHA2-256 value stored within the module that was computed at build time.

5.2 Initiate on Demand

The module provides on-demand integrity test. The integrity test can be performed on demand by reloading the module. Additionally, the integrity test can be performed using the On-Demand Integrity Test service, which calls the BORINGSSL_integrity_test function.

2024 Amazon Web Services, Inc., atsec information security.
Page 45
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module should be compiled and installed as stated in section 11. The user should confirm that the module is installed correctly by following steps 4 and 5 listed in section 11.

6.2 Configuration Settings and Restrictions

Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment.

2024 Amazon Web Services, Inc., atsec information security.
Page 46

Temp/Voltage Type LowTemperature HighTemperature LowVoltage HighVoltage

Temperature or Voltage

EFP or EFT

Result

Temperature Type LowTemperature HighTemperature

Temperature

7 Physical Security
7.1 Mechanisms and Actions Required

N/A for this module. The module is comprised of software only and therefore this section is not applicable.

7.4 Fault Induction Mitigation

Table 14: EFP/EFT Information

7.6 Hardness Testing Temperature Ranges

Table 15: Hardness Testing Temperatures

2024 Amazon Web Services, Inc., atsec information security.
Page 47
8 Non-Invasive Security
8.1 Mitigation Techniques

The module claims no non-invasive security techniques.

2024 Amazon Web Services, Inc., atsec information security.
Page 48
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPsDynamic

Name API input parameters API output parameters

From Operator calling application (TOEPP) Cryptographic module

To Cryptographic module Operator calling application (TOEPP)

Format Type Plaintext Plaintext

Distribution Type Manual Manual

Entry Type Electronic Electronic

SFI or Algorithm

Zeroization MethodDescriptionRationaleOperator Initiation
Free Cipher HandleZeroizes the SSPs contained within the cipher handle.Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.By calling the appropriate zeroization functions: OpenSSL_cleanse, EVP_CIPHER_CTX_cleanup, EVP_AEAD_CTX_zero, HMAC_CTX_cleanup, CTR_DRBG_clear, RSA_free, EC_KEY_free
Module ResetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed.By unloading and reloading the module.
AutomaticallyAutomatically zeroized when no longer neededMemory occupied by SSPs is overwritten with zeros, which renders the SSP values irretrievable.N/A
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 16: Storage Areas Table 17: SSP Input-Output Methods operational environment. The SSPs are provided to the module via API input parameters in the calling application running on the same operational environment. Table 18: SSP Zeroization Methods

2024 Amazon Web Services, Inc., atsec information security.
Page 49

Name AES Key HMAC Key Entropy Input DRBG Seed DRBG Internal State (V, Key) RSA Public Key RSA Private Key

Description AES key used for encryption, decryption, and computing MAC tags HMAC key for Message Authenticatio n Generation Entropy input used to seed the DRBGs DRBG seed derived from entropy input as defined in SP 800-90Ar1 Internal state of CTR_DRBG RSA public key used for RSA key generation, signature verification RSA private key used for RSA key generation, signature generation

Size - Strengt h 128-256 bits - 128-256 bits 112- 524288 bits - 112-256 bits 256 bits - 256 bits 256 bits - 256 bits 256 bits - 256 bits 1024, 2048, 3072, 4096 bits - 80-150 bits 2048, 3072, 4096 bits - 112-150 bits

Type - Category Symmetric key - CSP Authenticatio n key - CSP Entropy - CSP DRBG seed - CSP Internal state - CSP Public key - PSP Private key - CSP

Generate d By Random Number Generation with DRBG Random Number Generation with DRBG Key Generation with RSA Key Generation with RSA

Establishe d By

Used By Key Wrapping/Unwrappin g with AES KW, AES- KWP Key Wrapping/Unwrappin g with AES GCM Key Wrapping/Unwrappin g with AES CCM Encryption/Decryptio n with AES Message Authentication Generation with AES Authenticated Encryption/Decryptio n with AES CCM Authenticated Encryption/Decryptio n with AES GCM Message Authentication Generation with HMAC Random Number Generation with DRBG Random Number Generation with DRBG Random Number Generation with DRBG Key Generation with RSA Signature Verification with RSA Signature Generation with RSA Key Generation with RSA

9.4 SSPs
2024 Amazon Web Services, Inc., atsec information security.
Page 50

Name EC Public Key EC Private Key Shared Secret TLS Pre- Master Secret TLS Master Secret TLS Derived Key (AES/HMAC) KDA Derived Key

Description EC public key used for EC key generation, key verification, signature verification, shared secret computation EC private key used for EC key generation, key verification, signature generation, shared secret computation Shared Secret generated by KAS-ECC-SSC TLS Pre- Master secret used for deriving the TLS Master Secret TLS Master secret used for deriving the TLS Derived Key TLS Derived Key from TLS Master Secret KDA HKDF derived key

Size - Strengt h P-224, P- 256, P- 384, P- 521 - 112-256 bits P-224, P- 256, P- 384, P- 521 - 112-256 bits P-224, P- 256, P- 384, P- 521 - 112-256 bits 112-256 bits - N/A 384 bits - N/A AES: 128- 256 bits HMAC: 112 to 256 bits - AES: 128-256 bits HMAC: 112 to 256 bits 112 to 256 bits - N/A

Type - Category Public key - PSP Private key - CSP Shard secret - CSP TLS pre- master secret - CSP TLS master secret - CSP Symmetric key - CSP Symmetric key - CSP

Generate d By Key Generation with ECDSA Key Generation with ECDSA Key Derivation with TLS KDF Key Derivation with KDA HKDF Key Derivation with TLS KDF Key Derivation with KDA HKDF

Establishe d By Shared Secret Computation with EC Diffie- Hellman

Used By Shared Secret Computation with EC Diffie-Hellman Key Generation with ECDSA Signature Verification with ECDSA Shared Secret Computation with EC Diffie-Hellman Signature Generation with ECDSA Key Generation with ECDSA Key Derivation with TLS KDF Key Derivation with SSH KDF Key Derivation with KDA HKDF Key Derivation with TLS KDF Key Derivation with KDA HKDF Key Derivation with TLS KDF Key Derivation with KDA HKDF Key Derivation with TLS KDF Key Derivation with KDA HKDF

2024 Amazon Web Services, Inc., atsec information security.
Page 51

Name SSH Derived Key PBKDF Derived Key Password Intermediat e Key Generation Value

Description SSH KDF derived key PBKDF derived key Password for PBKDF Intermediate key generation value

Size - Strengt h 112 to 256 bits - N/A 112 to 256 bits - N/A 112- 524288 bits - N/A 224-4096 bits - 112-256 bits

Type - Category Symmetric key - CSP Symmetric key - CSP Password - CSP Intermediate value - CSP

Generate d By Key Derivation with SSH KDF Key Derivation with PBKDF Key Generation with RSA Key Generation with ECDSA

Establishe d By

Used By Key Derivation with SSH KDF Key Derivation with PBKDF Key Derivation with PBKDF Key Generation with ECDSA Key Generation with RSA

Name AES Key HMAC KeyInput - Output API input parameters API output parameters API input parameters API output parametersStorage RAM:Plaintext RAM:PlaintextStorage Duration From service invocation to service completion From service invocation to service completionZeroization Free Cipher Handle Module Reset Free Cipher Handle Module ResetRelated SSPs
Entropy InputAPI input parametersRAM:Plaintextfrom service invocation to service completionAutomaticallyDRBG Seed:Generation Of
DRBG SeedRAM:Plaintextfrom service invocation to service completionAutomaticallyEntropy Input:Derived From
DRBG Internal State (V, Key)from service invocation to service completionAutomaticallyDRBG Seed:Derived From
RSA Public KeyAPI input parameters API output parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetRSA Private Key:Paired With
RSA Private KeyAPI input parameters API output parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetRSA Public Key :Paired With
EC Public KeyAPI input parametersRAM:Plaintextfrom service invocation toFree Cipher Handle Module ResetEC Private Key:Paired With
2024 Amazon Web Services, Inc., atsec information security.
Page 52
NameInput - Output API output parametersStorageStorage Duration service completionZeroizationRelated SSPs Shared Secret:Generation Of
EC Private KeyAPI input parameters API output parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetEC Public Key:Paired With Shared Secret:Generation Of
Shared SecretAPI output parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetEC Public Key:Derived From EC Private Key:Derived From
TLS Pre-Master SecretAPI input parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetTLS Master Secret :Derivation Of
TLS Master SecretRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetTLS Pre-Master Secret:Derived From
TLS Derived Key (AES/HMAC)API output parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetTLS Master Secret :Derived From
KDA Derived KeyAPI output parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetShared Secret:Derived From
SSH Derived KeyAPI output parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetShared Secret:Derived From
PBKDF Derived KeyAPI output parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetPassword:Derived From
PasswordAPI input parametersRAM:Plaintextfrom service invocation to service completionFree Cipher Handle Module ResetDerived Key:Derivation Of
Intermediate Key Generation Valuefrom service invocation to service completionAutomaticallyRSA Public Key :Generation Of RSA Private Key:Generation Of EC Public Key:Generation Of EC Private Key:Generation Of
2024 Amazon Web Services, Inc., atsec information security.
Page 53
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2030.

2024 Amazon Web Services, Inc., atsec information security.
Page 54
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-256 (A4509)SHA2-256Message AuthenticationSW/FW IntegrityModule becomes operationalIntegrity test for bcm.o
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A4513)128-bit AES keyEncrypt KATCASTModule is operationalEncryptPower up
AES-CBC (A4510)128-bit AES keyDecrypt KATCASTModule is operationalDecryptPower up
AES-GCM (A4511)128-bit AES keyEncrypt KATCASTModule is operationalEncryptPower up
AES-GCM (A4511)128-bit AES keyDecrypt KATCASTModule is operationalDecryptPower up
SHA-1 (A4509)N/ASHA-1 KATCASTModule is operationalMessage digestPower up
SHA2-256 (A4509)N/ASHA2-256 KATCASTModule is operationalMessage digestPower up
SHA2-512 (A4509)N/ASHA2-512 KATCASTModule is operationalMessage digestPower up
HMAC-SHA2- 256 (A4509)SHA2-256HMAC KATCASTModule is operationalMessage authenticationPower up
Counter DRBG (A4513)AES 256CTR_DRBG KATCASTModule is operationalSeed GenerationPower up
Counter DRBG (A4513)N/ASP800-90Ar1 Section 11.3 Health TestCASTModule is operationalSeed GenerationPower up
ECDSA SigGen (FIPS186-5) (A4509)P-256 Curve and SHA2-256Sign KATCASTModule is operationalSignSignature Generation or Key Generation service request
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 21: Pre-Operational Self-Tests The module performs the pre-operational self-test automatically when the module is loaded into memory; the pre-operational self-test is the software integrity test that ensures that the module is not corrupted. While the module is executing the pre-operational self-test, services are not available, and input and output are inhibited. The software integrity test is performed after a set of conditional cryptographic algorithm self-tests (CASTs). The set of CASTs executed before the software integrity test consists of HMAC-SHA2-256 KAT, which is used in the pre-operational self-test, and the SHA2-256 KAT.

10.2 Conditional Self-Tests
2024 Amazon Web Services, Inc., atsec information security.
Page 55
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigVer (FIPS186-4) (A4509)P-256 Curve and SHA2-256Verify KATCASTModule is operationalVerifySignature verification or Key Generation service request
KAS-ECC-SSC Sp800-56Ar3 (A4509)P-256 CurveZ computationCASTModule is operationalShared secret computationShared secret computation request
ECDSA KeyGen (FIPS186-5) (A4509)Respective Curve and SHA2-256Signature generation and verificationPCTModule is operationalSign and VerifyKey generation
KDF TLS (A4509)SHA2-256TLS 1.2 KATCASTModule is operationalKey derivationPower up
KDA HKDF Sp800-56Cr1 (A4509)HMAC-SHA2- 256KDA HKDF KATCASTModule is operationalKey derivationPower up
PBKDF (A4509)HMAC-SHA2- 256PBKDF2 KATCASTModule is operationalKey derivationPower up
RSA SigGen (FIPS186-5) (A4509)PKCS#1 v1.5 with 2048 bit key and SHA2- 256Sign KATCASTModule is operationalSignSignature Generation or Key Generation service request
RSA SigVer (FIPS186-4) (A4509)PKCS#1 v1.5 with 2048 bit key and SHA2- 256Verify KATCASTModule is operationalVerifySignature Verification or Key Generation service request
RSA KeyGen (FIPS186-5) (A4509)SHA2-256 and respective keysSignature generation and verificationPCTModule is operationalSign and VerifyKey generation

Table 22: Conditional Self-Tests Conditional Cryptographic Algorithm Tests The module performs self-tests on approved cryptographic algorithms, using the tests shown in Table 22. Data output through the data output interface is inhibited during the selftests. The CASTs are performed in the form of Known Answer Tests (KATs), in which the calculated output is compared with the expected known answer (that are hard-coded in the module). A failed match causes a failure of the self-test. If any of these self-tests fails, the module transitions to error state. Conditional Pair-Wise Consistency Tests pairwise consistency test (PCT) using sign and verify functions when the keys are generated (Table 22). If any of these self-tests fails, the module transitions to error state and is aborted.

2024 Amazon Web Services, Inc., atsec information security.
Page 56
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A4509)Message AuthenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A4513)Encrypt KATCASTOn demandManually
AES-CBC (A4510)Decrypt KATCASTOn demandManually
AES-GCM (A4511)Encrypt KATCASTOn demandManually
AES-GCM (A4511)Decrypt KATCASTOn demandManually
SHA-1 (A4509)SHA-1 KATCASTOn demandManually
SHA2-256 (A4509)SHA2-256 KATCASTOn demandManually
SHA2-512 (A4509)SHA2-512 KATCASTOn demandManually
HMAC-SHA2-256 (A4509)HMAC KATCASTOn demandManually
Counter DRBG (A4513)CTR_DRBG KATCASTOn demandManually
Counter DRBG (A4513)SP800-90Ar1 Section 11.3 Health TestCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A4509)Sign KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4509)Verify KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A4509)Z computationCASTOn demandManually
ECDSA KeyGen (FIPS186-5) (A4509)Signature generation and verificationPCTOn demandManually
KDF TLS (A4509)TLS 1.2 KATCASTOn demandManually
KDA HKDF Sp800- 56Cr1 (A4509)KDA HKDF KATCASTOn demandManually
PBKDF (A4509)PBKDF2 KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A4509)Sign KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4509)Verify KATCASTOn demandManually
RSA KeyGen (FIPS186-5) (A4509)Signature generation and verificationPCTOn demandManually
10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information Table 24: Conditional Periodic Information The module does not support periodic self-tests.

2024 Amazon Web Services, Inc., atsec information security.
Page 57
NameDescriptionConditionsRecovery MethodIndicator
ErrorThe library is aborted with SIGABRT signal. Module is no longer operational the data output interface is inhibitedPre- operational test failureModule resetError message is output on the stderr and then the module is aborted.
PCT ErrorThe library is aborted with SIGABRT signal. Module is no longer operational the data output interface is inhibitedConditional test failureModule resetFor CAST failure, an error message is output on the stderr and then the module is aborted. For PCT failure, an error message is output in the error queue and then the module generates new key, If the PCT still does not pass, eventually the module will be aborted after 5 tries.
10.4 Error States

Table 25: Error States If the module fails any of the self-tests, the module enters an error state. To recover from any error state, the module must be rebooted.

10.5 Operator Initiation of Self-Tests

The software integrity tests and the CASTs for AES, SHS, DRBG, HMAC, KAS-ECC-SSC, TLS KDF, KDA HKDF, PBKDF2 can be invoked by unloading and subsequently re-initializing the module. The CASTs for ECDSA and RSA can be invoked by requesting the corresponding Key Generation or Digital Signature services. Additionally, all the CASTs can be invoked by calling the BORINGSSL_self_test function. The PCTs can be invoked on demand by requesting the Key Generation service.

10.6 Additional Information
2024 Amazon Web Services, Inc., atsec information security.
Page 58
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module bcm.o is embedded into the usersapce application which can be obtained by building the source code at the following location [1]. The set of files specified in the archive constitutes the complete set of source files of the validated module. There shall be no additions, deletions, or alterations of this set as used during module build. [1] https://github.com/aws/aws-lc/archive/refs/tags/AWS-LC-FIPS-2.0.0.zip The downloaded zip file can be verified by issuing the “sha256sum AWS-LC-FIPS-2.0.0.zip” command. The expected SHA2-256 digest value is: 6241EC2F13A5F80224EE9CD8592ED66A97D426481066FEAA4EFC6F24E60BBC96 After the zip file is extracted, the instructions listed below will compile the module. The compilation instructions must be executed separately on platforms that have different processors and/or operating systems. Due to six possible combinations of OS/processor, the module count is six (i.e., there are six separate binaries generated, one for each entry listed in the Tested Operational Environments table). Amazon Linux 2 and Amazon Linux 2023: 1. s u d o y u m g r o u p i n s t a l l " De v e l o p me n t To o l s "

2 . s u d o y u m i n s t a l l c ma k e 3 g o l a n g

3 . c d a ws - l c - f i p s - 2 0 2 2 - 1 1 - 0 2 /

4 . mk d i r b u i l d

6 . c ma k e 3 - DFI PS=1 . .

7 . ma k e

Ubuntu 22.04: 1. s udo a pt - ge t i ns t a l l bui l d- e s s e nt i a l

2 . s u d o a p t - g e t i n s t a l l c ma k e

3 . Ge t l a t e s t Go l a n g a r c h i v e f o r y o u r a r c h i t e c t u r e

4. s udo t a r - C / us r / l oc a l - xz f go*. t a r . gz

5 . c d a ws - l c - f i p s - 2 0 2 2 - 1 1 - 0 2 /

6 . mk d i r b u i l d

8 . c ma k e - DFI PS=1 - DGO_ EXECUTABLE=/ u s r / l o c a l / g o / b i n / g o . .

9 . ma k e

Upon completion of the build process, the module’s status can be verified by the command below. If the value obtained is “1” then the module has been installed and configured to operate in FIPS compliant manner. . / t ool / bs s l i s f i ps

2024 Amazon Web Services, Inc., atsec information security.
Page 59

Lastly, the user can call the “show version” service using awslc_version_string function and the expected output is “AWS-LC FIPS 2.0.0” which is the module version. This will confirm that the module is in the operational mode. Additionally, the “AWS-LC FIPS” also acts as the module identifier and the verification of the "static" part can be done using following command with an application that was used for static linking. The "T" in the output confirms that the module is statically linked. Command: nm <application_name> | grep awslc_version_string Example Output: 0000000000a5bdff T awslc_version_string

11.2 Administrator Guidance

When the module is at end of life, for the GitHub repo, the README will be modified to mark the library as deprecated. After a 6-month window, more restrictive branch permissions will be added such that only administrators can read from the FIPS branch. The module does not possess persistent storage of SSPs. The SSP value only exists in volatile memory and that value vanishes when the module is powered off. So as a first step for the secure sanitization, the module needs to be powered off. Then for actual deprecation, the module will be upgraded to newer version that is approved. This upgrade process will uninstall/remove the old/terminated module and provide a new replacement.

2024 Amazon Web Services, Inc., atsec information security.
Page 60
12 Mitigation of Other Attacks
12.1 Attack List
12.2 Mitigation Effectiveness

RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack. The module provides the mechanism to use the blinding for RSA. When the blinding is on, the module generates a random value to form a blinding factor in the RSA key before the RSA key is used in the RSA cryptographic operations.

2024 Amazon Web Services, Inc., atsec information security.