| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | Single Chip |
| Status | Active |
| Sunset date | 9/30/2029 |
| Caveat | None |
| Vendor | Advanced Micro Devices, Inc. (AMD) |
flowchart LR
%% Deterministic review-risk graph for AMD Pensando PenTrust Security Module
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for AMD Pensando PenTrust Security Module
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;Advanced Micro Devices, Inc. (AMD) AMD Pensando PenTrust Security Module
Disclaimer AMD, the AMD Arrow logo, Pensando and combinations thereof are trademarks of Advanced Micro Devices, Inc. This Security Policy document may be reproduced only in its original entirety (without revision).
| # | Section | Page |
|---|
| Item | Page |
|---|---|
| Table 1: Security Levels | 6 |
| Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) | 8 |
| Table 3: Tested Module Identification – Hybrid Disjoint Hardware | 8 |
| Table 4: Tested Operational Environments - Software, Firmware, Hybrid | 8 |
| Table 5: Modes List and Description | 9 |
| Table 6: Approved Algorithms | 9 |
| Table 7: Security Function Implementations | 10 |
| Table 8: Ports and Interfaces | 11 |
| Table 9: Roles | 12 |
| Table 10: Approved Services | 15 |
| Table 11: Storage Areas | 17 |
| Table 12: SSP Input-Output Methods | 17 |
| Table 13: SSP Zeroization Methods | 18 |
| Table 14: SSP Table 1 | 19 |
| Table 15: SSP Table 2 | 19 |
| Table 16: Pre-Operational Self-Tests | 19 |
| Table 17: Conditional Self-Tests | 21 |
| Table 18: Pre-Operational Periodic Information | 21 |
| Table 19: Conditional Periodic Information | 22 |
| Table 20: Error States | 22 |
| Figure 1: Block Diagram | 7 |
| Section | Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic module specification | 1 |
| 3 | Cryptographic module interfaces | 1 |
| 4 | Roles, services, and authentication | 1 |
| 5 | Software/Firmware security | 1 |
| 6 | Operational environment | 1 |
| 7 | Physical security | N/A |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle assurance | 1 |
| 12 | Mitigation of other attacks | N/A |
| Overall Level | 1 |
This document defines the Security Policy for AMD Pensando PenTrust Security Module, hereafter referred to as the Module. The Module meets FIPS 140-3 overall Level 1 requirements, with security levels as described in section 1.2 below.
Purpose and Use: The Module is a software-hybrid module intended for use by customers seeking to implement approved cryptography. Module Type: Software-hybrid Module Embodiment: SingleChip Module Characteristics: Module is not a Sub-chip and there are no special characteristics. Cryptographic Boundary: The Module is a software hybrid Module that comprises of software and hardware components. The software component of the Module can only support cryptographic algorithms by utilizing the Processor Algorithm Implementations (PAI), which are enabled by software and process
service requests from the consuming application (outside of the cryptographic boundary) via the Mailbox API. The cryptographic boundary of the Module is defined by the pentrustfw.img. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP is the physical perimeter of the AMD Pensando DPU 08-0010-01. The Module executes from the ARM Cortex M0 CPU, a single-threaded CPU, with no underlying OS. The consuming application (outside of the cryptographic boundary) executes from GPC Hardware outside of the boundary (e.g. A72 ARM Processor). Figure 1: Block Diagram
Tested Module Identification – Hardware:
| Package or File Name | Software/ Firmware Version | Features | Integrity Test | ||
|---|---|---|---|---|---|
| pentrustfw.img | 5.0.0 | ECDSA P-384 with SHA2-384 digital signature verification |
| Model and/or Part Number | Hardware Version | Firmware Version | Processors | Features | |
|---|---|---|---|---|---|
| AMD Pensando DPU 08- 0010-01 | version 01 | ARM Cortex M0 CPU with PAI |
| Operating System | Hardware Platform | Processors | PAA/PAI | Hypervisor or Host OS | Version(s) | |
|---|---|---|---|---|---|---|
| N/A | AMD Pensando DPU 08- 0010-01, version 01 | ARM Cortex M0 | Yes | 5.0.0 |
N/A for this module. Tested Module Identification
The Module does not support excluded components.
Modes List and Description:
| Mode Name | Description | Type | Status Indicator | ||||
|---|---|---|---|---|---|---|---|
| Approved mode of operation | Invoke approved services of the module | Approved | Global Indicator as per FIPS 140-3 IG 2.4.C. Module only supports approved services. |
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-CBC | A4453 | Direction - Decrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CTR | A4453 | Direction - Decrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-ECB | A4453 | Direction - Decrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-GCM | A4453 | Direction - Decrypt IV Generation - External Key Length - 128, 192, 256 | SP 800-38D |
| AES-GMAC | A4453 | Direction - Decrypt IV Generation - External Key Length - 128, 192, 256 | SP 800-38D |
| ECDSA SigVer (FIPS186-4) | A4453 | Component - No Curve - P-384 Hash Algorithm - SHA2-384 | FIPS 186-4 |
| RSA SigVer (FIPS186-4) | A4453 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 4096 | FIPS 186-4 |
| SHA2-256 | A4453 | Message Length - Message Length: 0- 65536 Increment 8 | FIPS 180-4 |
| SHA2-384 | A4453 | Message Length - Message Length: 0- 65536 Increment 8 | FIPS 180-4 |
| SHA2-512 | A4453 | Message Length - Message Length: 0- 65536 Increment 8 | FIPS 180-4 |
Table 5: Modes List and Description The Module does not support degraded mode.
Approved Algorithms: Table 6: Approved Algorithms Vendor-Affirmed Algorithms: N/A for this module.
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| Digital Signature | DigSig-SigVer | Verify signatures | ECDSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) SHA2-256 SHA2-384 SHA2-512 | |
| Secure Hash | SHA | Hash Messages | SHA2-256 SHA2-384 SHA2-512 | |
| Block Cipher | BC-UnAuth | Decrypt messages | AES-CBC AES-CTR AES-ECB | |
| Authenticated Block Cipher | BC-Auth | Decrypt and authenticate messages | AES-GCM AES-GMAC |
Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.
Table 7: Security Function Implementations
There are no additional requirements for documentation of the algorithms supported by the Module.
N/A for this module. N/A for this module.
| Physical Port | Logical Interface(s) | Data That Passes |
|---|---|---|
| Mailbox API | Data Input Data Output Control Input Status Output | All data being input or output to/from the module, control information and parameters passed via the module`s API, and status output returned from the API. All information travels through the module’s API; with the module’s process memory being physically in SRAM and executing on the platform’s CPU. No information is transmitted by the module over a physical port on the platform. |
| DMA | Data Input Data Output | Data input or output resulting from Mailbox API request. |
The Module does not support industry protocols.
Table 8: Ports and Interfaces
The Module does not support a Trusted Channel.
| Name | Type | Operator Type | Authentication Methods | ||
|---|---|---|---|---|---|
| Crypto Officer | Role | CO |
| Name | Description | Indica tor | Inputs | Outputs | Security Function s | SSP Access |
|---|---|---|---|---|---|---|
| HASH | SHA2-256 SHA2- 384 SHA2-512 | DataIn size, DataIn | Digest | Secure Hash | Crypto Officer | |
| HASH_FIRST | SHA2-256 SHA2- 384 SHA2-512 | DataIn size, DataIn | StateOut | Secure Hash | Crypto Officer | |
| HASH_UPD | SHA2-256 SHA2- 384 SHA2-512 | DataIn size, StateIn, DataIn | StateOut | Secure Hash | Crypto Officer | |
| HASH_FINISH | SHA2-256 SHA2- 384 SHA2-512 | DataIn size, StateIn, DataIn | DataIn size, StateIn, DataIn | Secure Hash | Crypto Officer | |
| VERIFY | RSA: algorithms RSA2048 /SHA2- 256 and RSA4096/SHA2- 512, Padding PKCS and PSS ECDSA: Curve P-384, Hash | Algorithm : RSA or ECDSA, Padding type, Hash algorithm , Key Size, | Success or Failure | Digital Signature | Crypto Officer - API RSA Key: W,E,Z - API ECDSA Key: |
Table 9: Roles As per FIPS 140-3, the Module supports the Crypto Officer (CO) operator role implicitly. The role is implicitly assumed by the service requested. The Module does not support authentication. The Module does not support multiple concurrent operators, a maintenance role or bypass capability.
Please see below for the Approved Services supported by the Module. As per FIPS 140-3 IG, Section 2.4.C, a global indicator applies to this Module as it only supports Approved Services in an approved manner. An implicit indication via the successful completion of a service is the global indicator of the Module. Please note that columns for “Input” and “Output” below are documented from the standpoint of the API parameters. It is important to note that independent of the parameters, module supports a status indicator per service to indicate success or failure. All service inputs result in a service output. s
Name FIPS_GET_MO DULE_VERSIO N CMD_FIPS_ZE ROIZE BOOT_SUCCES S DIAG_GET_STA TUS DIAG_READPU BKEYBOOT
Description Algorithm SHA2- 384 Returns the module version information. This is the show module version service required by FIPS 140-3. Zeroises long lived SSPs Used for the A72 to signal to PenTrust that boot is successful Reads the boot status from PenTrust. Includes which PenTrust image (0 or 1) was loaded, and which A72 image (0 or 1) was loaded Used to read out the public key material for SM Public Key or CM Public Key
Indica tor
Inputs Message Size, Public Key, Message , Signature DMA pointer to store result
Outputs Data containin g the version informati on for the module FaultStat us, Boot status info Key (public key of system authentic ation algorithm type)
Security Function s
SSP Access W,E,Z - SM Public Key: E Crypto Officer Crypto Officer - CM Public Key: Z - SM Public Key: Z Crypto Officer Crypto Officer Crypto Officer - CM Public Key: R - SM Public Key: R
| Name DIAG_SERIAL_ NUMBER DIAG_SET_UP GRADE_FLAG REVOKE_PUB_ KEY_BOOT | Description Used to read out the PenTrust serial number Sets an internal PenTrust flag that will make it re-evaluate which image to boot at the next reset Used to revoke the CM Public Key or SM Public Key stored by the consuming application in GPC hardware outside the boundary | Indica tor | Inputs Key index (select which key is being revoked), Certificat e from manufact urer, Signature of the comman d (based on system authentic ation algorithm ) | Outputs Serial number (128-bit) | Security Function s | SSP Access Crypto Officer Crypto Officer Crypto Officer - CM Public Key: E - SM Public Key: E |
|---|---|---|---|---|---|---|
| GCM_DECR | AES 128/192/256 decrypt in GCM and GMAC modes, GMAC generation and verification | Key metadata , AAD size, Ciphertex t size, Key, IV, AAD, Ciphertex t, MAC | Plaintext, MAC | Authentic ated Block Cipher | Crypto Officer - API AES Key: W,E,Z | |
| DECRYPT | AES 128/192/256 decrypt in ECB, CBC, CTR | Key metadata , Ciphertex t size, Key, IV or | Plaintext, Context | Block Cipher | Crypto Officer - API AES Key: W,E,Z |
Name READ_CHIP_C ERT SHOW_STATU S SELF_TEST
Description Reads and outputs the X.509 chip certificate (binary blob) which is outside of the boundary and not an SSP. This is a helper function. This is the Show Status service required by FIPS 140-3. The service is provided by the module`s API and will automatically report status of the module during Self-Tests and the Error State. See Section 10 for more information. This is the Self- Tests service required by FIPS 140-3. The service is provided automatically by the module upon power-cycle, reset, or reboot. All Self-Tests are executed by the module during power-on.
Indica tor
Inputs context, Ciphertex t
Outputs Chip Certificat e See Section 10 for more informati on See Section 10 for more informati on
Security Function s
SSP Access Crypto Officer Crypto Officer Crypto Officer - CM Public Key: E - SW image authentic ation public key: E
The Module does not support a software load test. The Module is a hybrid software module and the loaded software image is a complete image replacement of the disjoint software component.
The Module does not support Bypass Actions.
The Module does not support self-initiated cryptographic output capability.
The Module uses ECDSA P-384 with SHA2-384 Signature Verification (ECDSA Cert. #A4453) as the approved integrity technique. The Module executes an ECDSA P-384 with SHA2-384 Signature Verification Known Answer Test (KAT) prior to the software integrity test.
To initiate the integrity test on demand the operator can power-cycle, reset, reboot the Module as per FIPS 140-3 IG 2.4.C.
The Module is not Open-Source.
Type of Operational Environment: Modifiable The Module supports a modifiable Operational Environment. How Requirements are Satisfied: The modifiable Operational Environment supports a single threaded CPU where the only process that can execute at any point in time is the AMD Pensando PenTrust Security Module.
| Storage Area Name | Description | Persistence Type | |
|---|---|---|---|
| SRAM | Volatile in SRAM only | Dynamic |
| Name | From | To | Format Type | Distribution Type | Entry Type | SFI or Algorithm |
|---|---|---|---|---|---|---|
| API SSP input | Entered via Mailbox API from outside the boundary | SRAM inside the boundary | Plaintext | Automated | Electronic | |
| PSP output | SRAM inside the boundary | Outside the boundary via Mailbox API | Plaintext | Automated | Electronic |
Zeroization Method CMD_FIPS_ZEROIZE
Description Service available to the consuming application to Zeroise Long lived SSPs.
Rationale
Operator Initiation API
No other processes can run concurrently with the Module, and there can be only one instance of the Module. The modifiable Operational Environment does not support an operating system. Hence, the Module has control over its own SSPs, does not support uncontrolled access nor modifications to SSPs, and does not require restrictions or configurations of the operational environment for the Module to operate in an approved mode.
The Module does not support Non-Invasive Security. As per SP 800-140F, no additional requirements are applicable.
Table 11: Storage Areas Table 12: SSP Input-Output Methods
| Zeroization Method | Description | Rationale | Operator Initiation | |
|---|---|---|---|---|
| In-line zeroise | In-line zeroisation performed automatically by the module upon completion of the service. | Automatic |
| Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By |
|---|---|---|---|---|---|---|
| CM Public Key | ECDSA P-384 Public Key used to verify SW image authentication public key | 384 bits - 192 bits | Public - PSP | ECDSA SigVer (FIPS186- 4) (A4453) | ||
| SW image authentication public key | ECDSA P-384 Public Key used for the software integrity test. | 384 bits - 192 bits | public - PSP | ECDSA SigVer (FIPS186- 4) (A4453) | ||
| SM Public Key | ECDSA P-384 Public Key used to verify external A72 image. | 384 bits - 192 bits | Public - PSP | ECDSA SigVer (FIPS186- 4) (A4453) | ||
| API AES Key | Keys provided by the users of the API from outside the cryptographic boundary. Modes supported are: ECB, CBC, CTR, GCM, GMAC | 128 bits, 192 bits, 256 bits - 128 bits, 192 bits, 256 bits | Symmetric Key - CSP | AES-CBC (A4453) AES-CTR (A4453) AES-ECB (A4453) AES- GCM (A4453) AES- GMAC (A4453) | ||
| API RSA Key | Keys provided by the users of the API from outside the cryptographic boundary for Signature Verification Services. | 2048 bits, 4096 bits - 112 bits, 128 bits | Public - PSP | RSA SigVer (FIPS186- 4) (A4453) |
Table 13: SSP Zeroization Methods
| Name | Description Signature types supported are: PKCS 1.5, PKCSPSS | Size - Strength | Type - Category | Generated By | Established By | Used By | ||
|---|---|---|---|---|---|---|---|---|
| API ECDSA Key | Keys provided by the users of the API from outside the cryptographic boundary for Signature Verification Services | 384 bits - 192 bits | Public - PSP | ECDSA SigVer (FIPS186- 4) (A4453) |
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs |
|---|---|---|---|---|---|
| CM Public Key | PSP output | SRAM:Plaintext | While in use | CMD_FIPS_ZEROIZE | |
| SW image authentication public key | SRAM:Plaintext | While in use | N/A | ||
| SM Public Key | PSP output | SRAM:Plaintext | While in use | CMD_FIPS_ZEROIZE | |
| API AES Key | API SSP input | SRAM:Plaintext | While in use | In-line zeroise | |
| API RSA Key | API SSP input | SRAM:Plaintext | While in use | In-line zeroise | |
| API ECDSA Key | API SSP input | SRAM:Plaintext | While in use | In-line zeroise |
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | |||
|---|---|---|---|---|---|---|---|---|
| ECDSA | P-384 with SHA2-384 | SW Integrity | SW/FW Integrity | Image self-test: Passed or Image self-test: FAILED | Verify |
Table 14: SSP Table 1 Table 15: SSP Table 2
Table 16: Pre-Operational Self-Tests
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| SHA2-256 | 256 bits hash | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Hash | Before first use |
| SHA2-512 | 512 bits hash | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Hash | Before first use |
| RSA- PKCSPSS- 2048 | 2048 bits key with SHA2- 256 and Signature Type PKCSPSS | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Verify | Before first use |
| RSA-PKCS 1.5-2048 | 2048 bits key with SHA2- 256 and Signature Type PKCS 1.5 | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Verify | Before first use |
| RSA- PKCSPSS- 4096 | 4096 bits key with SHA2- 512 and Signature Type PKCSPSS | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Verify | Before first use |
| RSA-PKCS 1.5-4096 | 4096 bits key with SHA2- 512 and Signature Type PKCS 1.5 | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Verify | Before first use |
| ECDSA | P-384 with SHA2-384 | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Verify | Before first use |
| AES-GCM | 256 bit key size, GCM mode | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Decrypt | Before first use |
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| AES-CTR | 128 bit key size, CTR mode | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Decrypt | Before first use |
| AES-CBC | 128 bit key size, CBC mode | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Decrypt | Before first use |
| AES-ECB | 256 bit key size, ECB mode | KAT | CAST | KATS: algorithm_name DONE or KATS: algorithm_name FAILED | Decrypt | Before first use |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method | ||
|---|---|---|---|---|---|---|
| ECDSA | SW Integrity | SW/FW Integrity | Automatically on power on | Power cycle |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| SHA2-256 | KAT | CAST | Automatically on power on | Power cycle |
| SHA2-512 | KAT | CAST | Automatically on power on | Power cycle |
| RSA-PKCSPSS- 2048 | KAT | CAST | Automatically on power on | Power cycle |
| RSA-PKCS 1.5- 2048 | KAT | CAST | Automatically on power on | Power cycle |
| RSA-PKCSPSS- 4096 | KAT | CAST | Automatically on power on | Power cycle |
| RSA-PKCS 1.5- 4096 | KAT | CAST | Automatically on power on | Power cycle |
| ECDSA | KAT | CAST | Automatically on power on | Power cycle |
| AES-GCM | KAT | CAST | Automatically on power on | Power cycle |
| AES-CTR | KAT | CAST | Automatically on power on | Power cycle |
Table 17: Conditional Self-Tests
Table 18: Pre-Operational Periodic Information
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| AES-CBC | KAT | CAST | Automatically on power on | Power cycle |
| AES-ECB | KAT | CAST | Automatically on power on | Power cycle |
| Name | Description | Conditions | Recovery Method | Indicator | |
|---|---|---|---|---|---|
| Error State | Module has failed a Self-Test. FIPS approved services are not provided by the module when it is in this state and data output is inhibited. | Pre- Operational Self-Tests Conditional Self-Tests | Power cycle | Image self-test: FAILED or KATS: algorithm_name FAILED |
Table 19: Conditional Periodic Information
To initiate the Self-Tests on demand the operator can power-cycle, reset, reboot the Module as per FIPS 140-3 IG 2.4.C. The Module executes all Self-Tests during power-on.
The Module is included inside the AMD DPU ASIC, which will be assembled together with other parts by manufacturing (AMD) into a larger product for the end user. There are no specific installation procedures or initialization procedures required for the end user.
The startup procedures of the module are:
The security parameters, physical ports, and logical interfaces for the Administrator (Crypto Officer) are defined via this Security Policy. Given the Module does not support authentication, the Crypto Officer role is implicitly assumed by invoking the services of the Module. The Crypto Officer is responsible for taking the following security rules into consideration:
The Module does not support a Non-Administrator.
Please see section 11.2 for security rules.
The Module does not support Maintenance.
If the Crypto Officer would like to render the Module as no longer operable (end of life), the Crypto Officer must securely sanitize the Module by issuing the CMD_FIPS_ZEROIZE service followed by a power-cycle. Any private and public key records stored outside of the cryptographic boundary shall also be destroyed by the Crypto Officer.