All modules
CMVP Validated Module · FIPS 140-3 Security Policy

FIPS Applet on RookySE

Certificate#4827StandardFIPS 140-3Level3TypeHardwareEmbodimentSingle ChipStatusActiveVendorIDEMIA
High review priority  ·  exposes firmware-update authentication, HSM/SE firmware trust anchor  ·  last validated 21 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level3
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date10/10/2029
CaveatWhen installed, initialized and configured as specified in Section 11 of the Security Policy
VendorIDEMIA

Approved Algorithms (27)

AlgorithmACVP Cert
AES-CBCA2912
AES-CMACA2912
AES-ECBA2912
Counter DRBGA2912
ECDSA KeyGen (FIPS186-4)A2912
ECDSA KeyVer (FIPS186-4)A2912
ECDSA SigGen (FIPS186-4)A2912
ECDSA SigVer (FIPS186-4)A2912
HMAC-SHA-1A2912
HMAC-SHA2-256A2912
HMAC-SHA2-384A2912
HMAC-SHA2-512A2912
KAS-ECC Sp800-56Ar3A2912
KDF SP800-108A2912
RSA KeyGen (FIPS186-4)A2912
RSA SigGen (FIPS186-4)A2912
RSA Signature PrimitiveA2912
RSA SigVer (FIPS186-4)A2912
SHA-1A2912
SHA2-224A2912
SHA2-256A2912
SHA2-384A2912
SHA2-512A2912
SHA3-224A2912
SHA3-256A2912
SHA3-384A2912
SHA3-512A2912

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for FIPS Applet on RookySE
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load<br/>Update<br/>upgrade</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>unauthenticated<br/>Status output</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for FIPS Applet on RookySE
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load<br/>Update<br/>upgrade</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>unauthenticated<br/>Status output</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

FIPS Applet on RookySE FIPS Applet v1.6.1.4 on RookySE ‘097153’ FIPS 140-3 Non-Proprietary Cryptographic Module Security Policy Version: 1.2 Revision Date: 30/09/2024

Page 2

About IDEMIA OT-Morpho is now IDEMIA, the global leader in trusted identities for an increasingly digital world, with the ambition to empower citizens and consumers alike to interact, pay, connect, travel and vote in ways that are now possible in a connected environment. Securing our identity has become mission critical in the world we live in today. By standing for Augmented Identity, we reinvent the way we think, produce, use and protect this asset, whether for individuals or for objects. We ensure privacy and trust as well as guarantee secure, authenticated and verifiable transactions for international clients from Financial, Telecom, Identity, Security and IoT sectors. With close to €3bn in revenues, IDEMIA is the result of the merger between OT (Oberthur Technologies) and Safran Identity & Security (Morpho). This new company counts 14,000 employees of more than 80 nationalities and serves clients in 180 countries. | For more information, visit www.idemia.com / Follow @IdemiaGroup on Twitter Specifications and information are subject to change without notice. The products described in this document are subject to continuous development and improvement. All trademarks and service marks referred to herein, whether registered or not in specific countries, are the properties of their respective owners. - Printed versions of this document are uncontrolled 2/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 3

TABLE OF CONTENT 3/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.1

Page 4

4/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 5

TABLE OF ILLUSTRATIONS 5/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.1

Page 6

TABLE OF TABLES Table 4 Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed 14 Table 11 Approved Services - ISO19790:2012 7.4.3 Services, Non Security-Relevant Services, or Services Using 6/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 7
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General3
2Cryptographic module specification3
3Cryptographic module interfaces3
4Roles, services, and authentication3
5Software/Firmware security3
6Operational environmentN/A
7Physical security3
8Non-invasive securityN/A
9Sensitive security parameter management3
10Self-tests3
11Life-cycle assurance3
12Mitigation of other attacks3

This document defines the Security Policy for FIPS Applet on RookySE with firmware FIPS Applet v1.6.1.4 on RookySE ‘097153’ cryptographic module. FIPS Applet on RookySE is a Hardware Security Module made by Idemia, hereafter denoted the module. The module, validated to [NIST.FIPS.140-3] overall Level 3, meets security levels of following individual areas. FIPS Applet on RookySE is a cryptographic module intended to be used as hardware security module. It is designated for creating, storing, and operating keys with some cryptographic operations capabilities, and it relies on a secure element hardware with a tamper-protection.

2.1 Module Specifications
2.1.1 Module Type and Boundary

This cryptographic module, is a hardware module, and is a single chip. It is operated by embedded Global Platform OS with card manager capability for firmware (applet) loading, installation, or deletion. FIPS Applet is loaded at manufacturing and is part of the module. The module boundary is shown in red in the following picture: 7/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.1

Page 8

Figure 1 Module Boundary The below picture shows the FIPS Applet on RookySE Cryptographic Module in a single chip (Module count is 1) in VQFN32 form factor with dual interface (ISO 7816 T0 Contact Protocol and SPI Protocol): 8/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 9
Model/Part NumberHardware VersionFirmware VersionProcessors
SLC37ESA2M0Version: ‘29’Global Platform OS: RookySE ‘097153’ Javacard Application: FIPS Applet v1.6.1.432-bit ARM® SecurCore® SC300™

Figure 2 FIPS Applet on RookySE Chip

2.1.2 Module Components and Configuration

Below components are part of the module: Table 2 Cryptographic Module Tested Configuration The module can be in one of the two configurations below. The configuration is set in the manufacturing stage. FIPS Certified Product (FCP) This product configuration is intended to meet FIPS requirements and be validated by validation authority. This Security Policy describes this configuration. Non-FIPS Certified Product (NFCP) This product configuration is not intended to meet FIPS requirements and is out of scope of the FIPS evaluation. The module does not implement any Vendor Affirmed Operational Environments.

2.2 Modes of Operations

The module supports an applet instance that is running only in one mode of operation that is an approved mode. All services provided by the module when set in configuration FCP are approved services as specified in the section 4.3.2. A global indicator via FIPS Applet GET INFO service (unauthenticated service) is provided to show the status mode of operation.

2.2.1 Approved Mode of Operation

This mode means that the module is applying strictly rules of the FIPS requirements and the security policy is enforced. Access to some services is restricted and only approved services as specified in section 4.3.2 are available for users. 9/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 10

In this mode, customer is still allowed to load additional firmware but this is restricted to firmware (applet) that is already validated under [NIST.FIPS.140-3]. Any firmware (applet) that is not validated [NIST.FIPS.140-3] will cancel the FIPS status of the module. A procedure for firmware loading is described in [FQR 401 9097 Ed 4] section 3.4.2.

2.3 Security Functions

The module implements the ‘approved security functions’ and ‘non-approved but allowed security functions’ listed in Table 3 and Table 4 respectively.

2.3.1 Approved Security Functions

Note that the full cryptographic algorithm implementation capabilities were tested for the Approved cryptographic functions but only algorithms / mode / key sizes / functionalities identified in the Table 3 are implemented by the module. 10/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 11
Table, extracted as text (did not parse into structured rows)
Description / CAVP        Algorithm and       Mode/                       Key Size(s) /   Use Cert       Standard            Method                      Key             / Function Strength(s) AES A2912     [NIST.FIPS.197]      ECB, CBC                    128/192/256     Data encryption/decryption [NIST.SP.800-38A] AES                                                              MAC Generation/Verification, A2912                          CMAC                        128/192/256     SP800-108 KDF [NIST.SP.800-38B]
5.1 Key Pairs for Digital RSA 2048,
5.2 Key Pairs for Key RSA 4096,

Establishment ECC P-224, ECC P-256, ECC P-384, ECC P-521,

6.1 The “Direct TDES-64,
Table, extracted as text (did not parse into structured rows)
Generation” of              TDES-128, Symmetric Keys              TDES-192, CKG Vendor                          6.2.1 Symmetric Keys                        Key generation Affirmed [NIST.SP.800-       Generated Using Key-                        Symmetric and Asymmetric HMAC 64, 133.Rev2]           Agreement Schemes           HMAC 128,
6.2.2 Symmetric Keys HMAC 160,
Table, extracted as text (did not parse into structured rows)
Derived from a Pre-         HMAC 224, existing Key                HMAC 256, HMAC 320, HMAC 384, HMAC 512, AES 128, AES 192, AES 256 DRBG                                                            Deterministic Random Bit A2912      [NIST.SP.800-       CTR                         256             Generation 90A.Rev1] CKG using method in         P-224,          ECDSA Key Generation, ECDSA               section 4 and 5.1           P-256, A2912 [NIST.FIPS.186-4]   [NIST.SP.800-133.Rev2]      P-384, P-521 P-192,          ECDSA Key Verification P-224, ECDSA A2912                                                      P-256, [NIST.FIPS.186-4]                               P-384, P-521 SHA2-224,                   P-224,          ECDSA Signature ECDSA               SHA2-256,                   P-256,          Generation A2912 [NIST.FIPS.186-4]   SHA2-384,                   P-384, SHA2-512                    P-521 SHA-1,                      P-192,          ECDSA Signature SHA2-224,                   P-224,          Verification ECDSA A2912                          SHA2-256,                   P-256, [NIST.FIPS.186-4]   SHA2-384,                   P-384, SHA2-512                    P-521 11/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2
Page 12
Table, extracted as text (did not parse into structured rows)
Hardware True RNG used to seed the DRBG. The minimum number of bits of ENT (P)   Entropy Source        Physical                                       entropy is specified in the [NIST.SP.800-90B]                                                    Table 17 Non-Deterministic Random Number Generation Specification SHA2-256                                       Message Authentication; HMAC                                            Key strength : 112 A2912                          SHA2-384,                                      SP800-108 KDF [NIST.FIPS.198-1]                               (minimum) SHA2-512                                       MAC Generation SHA-1, HMAC                  SHA2-256,                 Key strength : 64    Message Authentication; A2912 [NIST.FIPS.198-1]     SHA2-384,                 (minimum)            MAC Verification SHA2-512 P-521       curve KAS-ECC                                         providing     256 with bilateral key                             KAS-ECC SP800-56Ar3 A2912    [NIST.SP.800-         confirmation              bits of encryption 56A.Rev3]                                       strength HMAC-64, HMAC-128, HMAC-160, HMAC-224, HMAC-256,            Key Derivation KDF                                             HMAC-320, A2912                          AES CMAC, HMAC            HMAC-384,            Symmetric Keys Derived [NIST.SP.800-108]                                                    from a Pre-existing Key HMAC-512 using KDF AES-128, AES-192, AES-256 KTS       (Secure                              256 bits keys SP 800-38F. KTS (key                           AES-CBC, AES-CMAC providing 256 bits A2912    Channel GP)           wrapping and of encryption [NIST.SP.800-38F]     unwrapping) per IG D.G. strength KTS       (Secure                              256 bits keys SP 800-38F. KTS (key                           AES-CBC, AES-CMAC providing 256 bits A2912    Session)              wrapping and of encryption [NIST.SP.800-38F]     unwrapping) per IG D.G. strength 128,192, 256 bits KTS        (Token    SP 800-38F. KTS (key      keys providing AES-CBC, AES-CMAC A2912    transport )           wrapping and              128,192, 256 bits [NIST.SP.800-38F]     unwrapping) per IG D.G.   of encryption strength A2912    RSA                   N/A 2048/3072/4096       RSA Key Generation [NIST.FIPS.186-4] SHA2-224, RSA Signature Generation A2912    RSA                   SHA2-256, 2048/3072/4096       using PCKS1 v1.5 and PSS [NIST.FIPS.186-4]     SHA2-384, Scheme SHA2-512 SHA-1,                                         RSA Signature Verification SHA2-224,                                      using PCKS1 v1.5 and PSS A2912    RSA                                             1024/2048/3072/4 SHA2-256,                                      Scheme [NIST.FIPS.186-4]                               096 SHA2-384,                                      (SHA-1 and module 1024 SHA2-512                                       allowed for legacy use) 12/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2
Page 13
2048 RSA Signature Generation
Table, extracted as text (did not parse into structured rows)
Primitive RSA (CVL)                                                The RSA SigGen (CVL) shall A2912 [NIST.FIPS.186-4]                                        only be used within the context of a FIPS 186-4 signature generation SHA3-224, SHA-3                 SHA3-256, A2912                                                   N/A      Message Digest [NIST.FIPS.202]       SHA3-384, SHA3-512 SHA-1, SHA2-224, SHS A2912                          SHA2-256,                N/A      Message Digest [NIST.FIPS.180-4]     SHA2-384, SHA2-512 Table 3 Approved Algorithms 13/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2
Page 14
Physical portLogical interfaceData that passes over port/interface
VCC, GNDPowerISO 7816: Supply voltage
RSTControl inputISO 7816: Reset
CLKControl inputISO 7816: Clock
I/OControl input, Status output Data input, Data outputISO 7816: Input / Output of Data ISO 7816: Status Word ISO 7816: Procedure Byte
Physical portLogical interfaceData that passes over port/interface
VCC, GNDPowerSupply voltage
2.3.2 Non-approved but Allowed Security Functions

These algorithms do not claim any security and are not used to meet [NIST.FIPS.140-3] requirements. Therefore, SSPs do not map to these algorithms. Algorithm Caveat Use / Function CSPs obfuscation with a nonCSPs obfuscation (no security claimed) Approved algorithm Table 4 Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed The module does not implement any Non-Approved Algorithms Allowed in the Approved Mode of Operation with security claimed.

3 CRYPTOGRAPHIC MODULE INTERFACES

The module provides a dual interface for communications that is available to all users: ISO7816 T0 Contact Protocol and Serial Peripheral Interface (SPI) Protocol. These two interfaces cannot be used simultaneously. Data output is inhibited during error states in any interface. The module acts as a slave device and does not

3.1.1 ISO7816 T0 Contact Protocol

In the ISO7816 T0 protocol, data output is inhibited during key generation, self-tests, and zeroisation except for procedure byte NULL ‘60’ transmission in order to keep the communication between module and the interface device still alive. Table 5 Ports and Interfaces in ISO7816 T0 Contact Protocol

3.1.2 Serial Peripheral Interface (SPI) Protocol

In the SPI protocol, data output is inhibited during key generation, self-tests, and zeroisation with exception for Check Alive SPI command. This command is used to check if the module is still alive or not. This command can temporarily interrupt the current execution of key generation, self-tests, or zeroisation. 14/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 15
RSTControl inputChip Reset
SPI_CLKControl inputClock
SPI_MISOControl input, Data inputMaster IN, Slave OUT
SPI_MOSIData output, Status outputMaster OUT, Slave IN
SPI_CSControl inputChip Select
SPI_IRQStatus outputA status signal to inform command completion
Role NameIDRole Description
Application AdministratorAA SUGP Administrator - This role is responsible for upgrading and loading the main firmware version of the system and additional customer applet (delete/load/install Applet). This role is authenticated using Global Platform Secure Channel Protocol ‘03’
AdministratorCO AUCrypto Officer Role 2 - Performing module initialization with the help SuperUser for its creation, global configuration, user management, and profile management for user and key
Key CustodiansKC URPerforming Splitting Knowledge Procedure in the Key Ceremony and hold secrets of Crypto Card Master Key (CCMK) This role is split into 3 different roles: KC1 – manage secret 1 of CCMK in the Splitting Knowledge Procedure KC2 – manage secret 2 of CCMK in the Splitting Knowledge Procedure KC3 – manage secret 3 of CCMK in the Splitting Knowledge Procedure

Table 6 Ports and Interfaces in Serial Peripheral Interface (SPI) Protocol

4 ROLES, SERVICES, AND AUTHENTICATION

The FIPS Applet on RookySE Cryptographic module supports following user roles: User Role – Performing general security services including Key Management and Cryptographic services The standard user’s role is configurable based on access control list in a profile that is set by ADMIN for a user. E.g a user can be a standard user A that have role to do Crypto functions but no role for key management 15/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 16
Role NameIDRole Description
Unauthenticated UserUUA role that does not require an authentication of an operator for the role to perform some services where CSPs and PSPs are not modified, disclosed [for CSPs only], or substituted

The module does not support a maintenance role. Additionally, any user is allowed to perform non-sensitive services such as requesting status information, without prior authentication. There are three types of authentication methods employed by the Module:

  1. Global Platform Secure Channel Protocol ‘03’ (GP SCP ‘03’) Authentication
  2. FIPS Applet Password-based Authentication
  3. FIPS Applet Smartcard-based Authentication In the FIPS applet implementation, the module does support authentication level up to two levels where the last authenticated user will override the access control of the first authenticated user. The active access control in the second level is based on second authenticated user’s profile. When this user logoff, the active access control is set back to the first authenticated user’s profile. This authentication level is only applicable for authentication number 2 and number 3 above that is designed for specific procedure such as Key Ceremony, System Reset, or System Unblock services.

4.2.1 Global Platform Secure Channel Protocol ‘03’ (GP SCP ‘03’) Authentication

The Secure Channel Protocol authentication method is provided by the Secure Channel service. The SDKENC and SD-KMAC keys are used to derive the SD-SENC and SD-SMAC keys, respectively. The off-card entity participating in the mutual authentication sends a 64-bit challenge to the Cryptographic Module. The Cryptographic Module generates its own challenge and computes a 64-bit cryptogram with SD-SMAC key and both challenges. The Cryptographic Module cryptogram and challenge are sent to the off-card entity which checks the Cryptographic Module’s cryptogram and creates its own 64-bit cryptogram with both challenges. A 64-bit message authentication code (MAC) is also computed on the command containing the off-card entity cryptogram with AES-CMAC and SD-SMAC key, the MAC is concatenated to the command, and the command is sent to Cryptographic Module. The Cryptographic Module checks the message authentication code and compares the received cryptogram to the calculated cryptogram. If all of this succeeds, the two participants are mutually authenticated (the external entity is authenticated to the Module in the AA role). GP Secure Channel Protocol establishment provides mutual authentication service as well as establishment of a secure channel to protect confidentiality and integrity of the transmitted data.

4.2.2 FIPS Applet Authentication Methods

The FIPS Applet uses identity-based operator authentication to enforce the separation of roles and allow corresponding services within each role. FIPS Applet Password-based Authentication The operator must enter its user name and its password for authentication process. The username is an alphanumeric string. The password is a binary string of a minimum of eight (8) characters. Key Agreement technique ((Cofactor) Full Unified Model, C(2e, 2s, ECC CDH) with bilateral key confirmation is used for mutual authentication and to derive session keys (H-SKAuthEnc, HSKAuthMac, H-SKAuthKC). H-SKAuthKC is used to calculate MAC of user credential (user token) for 16/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 17
RoleAuthentication MethodAuthentication Strength
Application AdministratorIdentity-based authentication using Global Platform Secure Channel Protocol ‘03’ Authentication• Single Attempt Probability The probability that a random attempt will succeed using this authentication method is: • 1/(2^128) = 2.9E-39 (MAC||cryptogram, using a 128-bit block for authentication) Multiple Attempts Probability The module enforces a “slowdown mechanism” that increases the response time between two authentications attempts following a failed authentication, such that no more than nine (9) attempts are possible in a one-minute period. The probability that a random attempt will succeed over a one-minute interval is: • 9/(2^128) = 2.6E-38 (MAC||cryptogram, using a 128-bit block for authentication)

authentication. If this mutual authentication process is success, the user can be verified via Key Confirmation using USER AUTH service employing user token. Other session keys, H-SKAuthEnc and H-SKAuthMac are used for protecting the message in Secure Channel. This scheme protects from eavesdropping and provides perfect forward secrecy. FIPS Applet Smartcard-based Authentication The operator must use smartcard that owns unique user EC-key pair used for Key Agreement ((Cofactor) Full Unified Model, C(2e, 2s, ECC CDH) with bilateral key confirmation). The static user key is different per user and stored inside the smartcard which is considered as secure enclave. The user must enter his pin for verification by the smartcard in order to use his static key and to perform key agreement. The rest of user authentication process is similar with the password-based method, except there is no password involved in the user token. Upon correct authentication, the role is selected based on current logged user’s profile. During authentication session keys are negotiated which are used to secure subsequent services request from operator. Since the session keys (and session ID) are stored in volatile memory all information about the authentication and session is lost if the module is powered down. 17/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 18
RoleAuthentication MethodAuthentication Strength
Administrator Key Custodians Super User Auditor Standard UserIdentity-based authentication using SmartcardSingle Attempt Probability The probability that a random attempt will succeed using this authentication method is: • 1/(2^128) = 2.9E-39 (128-bit long cryptogram computed with 256-bit long key) Multiple Attempts Probability The module enforces a “slowdown mechanism” that increases the response time between two authentications attempts following a failed authentication, such that no more than nine (9) attempts are possible in a one-minute period. The probability that a random attempt will succeed over a one-minute interval is: • 9/(2^128) = 2.6E-38 (128-bit long cryptogram computed with 256-bit long key)
Administrator Key Custodians Super User Auditor Standard UserIdentity-based authentication using PasswordSingle Attempt Probability The probability that a random attempt will succeed using this authentication method is: • 1/(2^128) = 2.9E-39 (128-bit long cryptogram computed with 256-bit long key) Multiple Attempts Probability The module enforces a “slowdown mechanism” that increases the response time between two authentications attempts following a failed authentication, such that no more than nine (9) attempts are possible in a one-minute period. The probability that a random attempt will succeed over a one-minute interval is: • 9/(2^128) = 2.6E-38 (128-bit long cryptogram computed with 256-bit long key)

Table 8 Role and Authentication

4.3 Services

All services implemented by the module are listed in the section 4.3.1 for each service description and its access for each Role. The module only provides approved services listed in the section 4.3.2 Approved 18/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 19
Role Global Platform ServicesServiceInputOutput
AAGP Secure ChannelKey Identifier, Host Challenge, Security Level Host Cryptogram, MACCard Challenge, Card Cryptogram, diversification data, and key information, Status Word of the command
AAGP Manage ContentLoaded package and stored data and key encrypted through GP SCP ‘03’ Security Level 3Status Word of the command
AAGP Get StatusApplication TypeList of application and its status, Status Word of the command
AAGP Get DataData TagCorresponding data based on input tag
AAGP Life CycleStatus type and State ControlStatus Word of the command
UUGP SelectApplication (applet) AIDStatus Word of the command
UUFirmware Upgrades Services - FIPS AppletSE ResetSignal Reset in port RSTAnswer-to-RESET (ATR)
AAInitialize UpdateKey Identifier and host challengeCard Challenge, Card Cryptogram, diversification data, and key information, Status Word of the command
AAExternal AuthenticateSecurity Level 3, Host Cryptogram and MACStatus Word of the command
AAFIPS Applet ServicesStore DataSensitive Data and Key encrypted through GP SCP ‘03’ Security Level 3Status Word of the command
UUGet InfoInformation typeSystem information as requested such as: Applet version, applet build type, single/multi SE configuration, life cycle status, storage size configuration, TC and sync status, current active user, and/or last executed frame id Return Status1
UUManage SessionSession typeReturn Status

Services. The module does not provide bypass or self-initiated output capabilities. Each service of the module returns completion status to indicate successful execution or specific error code.

4.3.1 Roles, Service Commands, Input and Ouput

The following table shows data input and output of each service employed by the module. Some services do not require an operator to assume an authorized role. In this case the associated role is marked with the role UU (Unauthenticated User) defined in Table 7 Completion Status that indicates execution status result (success or error with specific reason code) 19/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 20
RoleServiceInputOutput
UUMutual Authenticateusername, user/host public ephemeral key, selected authentication method, and host IDSystem's public ephemeral key and receipt for key confirmation Return Status
UUUser Authenticateuser token generated from MAC of user's credential using generated session key from Key Agreement process in Mutual AuthenticateAuthentication result Return Status
SU, CO, KC1, KC2, KC3, AU, URUser LogoutUsername informationReturn Status
SU, CO, KC1, KC2, KC3, AU, URSecure ChannelEncrypted data and its signatureEncrypted response data Return Status
AUCheck LogNumber of logs to be returnedActivity logs and Return Status
AURead LogNumber of logs to be read and deletedActivity logs and Return Status
AUDelete LogNumber of logs to be deletedReturn Status
AUExport Log (mode 01)Mode to export the logs (mode: deleted)All activity logs and Return Status
CO, AUExport Log (mode 02)Mode to export the logs (mode: kept)All activity logs and Return Status
COProfile CreateProfile name and the access controlReturn Status
COProfile DeleteProfile name and deletion optionReturn Status
COProfile ViewOnly input frame with no additional input datainformation of all profiles Return Status
COUser CreateUser information and credential dataReturn Status
SUUser Create ADMINAdmin's information and credential dataReturn Status
COUser DeleteUsername informationReturn Status
SU, COUser Change CredentialUsername and new user’s password or new user’s public keyReturn Status
COUser View (full)User Type (All Users)Information of all users Return Status
SU, COUser View (Admin only)User Type (Admin only)information about admin user Return Status
CO, KC1CCMK Import 1Secret data and its key check value to import CCMK using split knowledge procedureReturn Status

20/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 21
RoleServiceInputOutput
CO, KC2CCMK Import 2Secret data and its key check value to import CCMK using split knowledge procedureReturn Status
CO, KC3CCMK Import 3Secret data and its key check value to import CCMK using split knowledge procedureKey check value of CCMK Return Status
CO, KC1CCMK Export 1Only input frame with no additional input dataSecret data and its key check value of CCMK using split knowledge procedure Return Status
CO, KC2CCMK Export 2Only input frame with no additional input dataSecret data and its key check value of CCMK using split knowledge procedure Return Status
CO, KC3CCMK Export 3Only input frame with no additional input dataSecret data and its key check value of CCMK using split knowledge procedure Return Status
COSystem Set Config00 to keep FIPS Certified Product 01 to change to Non FIPS Certified ProductReturn Status
CO, URImport KeyImported key in key token form protected by protection key whose label specified in key token's propertiesImported key in key token form protected by CCMK of the module as protection key Return Status
CO, URExport KeyExported key label and protection key label where those key tokens shall be loaded to the module prior to this service via Load Key serviceExported key in key token form with protection key as configured in input frame Return Status
CO, URLoad KeyLoaded key in key token form protected by protection key whose label specified in key token's propertiesReturn Status
CO, URDiversify KeyKey token properties and diversification methodDiversified key in key token form protected by CCMK of the module as its protection key Return Status
CO, URGenerate KeyKey token propertiesGenerated key in key token form protected by CCMK of the module as its protection key Return Status
CO, URGenerate Key PairKey token propertiesGenerated key in key token form protected by CCMK of the module as protection key

21/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 22
RoleServiceInputOutput
Return Status
COGenerate Key (For Split Knowledge)Customer key propertiesReturn Status
CO, URCK Export 1Only input frame with no additional input dataCustomer key’s secret data, its KCV and properties Return Status
CO, URCK Export 2Only input frame with no additional input dataCustomer key’s secret data and its KCV Return Status
CO, URCK Export 3Only input frame with no additional input dataExported Customer key's properties, secret data, secret KCV, customer key KCV Return Status
CO, URCK Import 1Customer key's properties, secret data, and its KCV to import Customer Key using split knowledge procedureReturn Status
CO, URCK Import 2Customer key's secret data and its KCV to import Customer Key using split knowledge procedureReturn Status
CO, URCK Import 3Imported Customer key's properties, secret data, secret KCV, and customer key KCV to import Customer Key using split knowledge procedureCustomer Key Token protected by CCMK of the module as its protection key Return Status
COSet DateDate informationReturn Status
SU, COSystem ResetOnly input frame with no additional input dataReturn Status
SU, COGet DataRequested data such as: System, Host or Super User’s Ephemeral public keyRequested data Return Status
SU, COSystem Store DataData to be stored such as: : System, Host or Super User’s Authentication public key, System Authentication private key, System Sync Master Key, logging configurationReturn Status
SU, COSync Request TokenSync propertiesSync token data Return Status
SU, COSync Write TokenSync token dataSync result status
SU, COSync ReportSync result dataReturn Status
CO, URCrypto EncipherEncipher Key label, plain data and cipher configurationEncrypted data Return Status
CO, URCrypto DecipherDecipher Key label, encrypted data and decipher configurationDecrypted data Return Status

22/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 23
RoleServiceInputOutput
CO, URCrypto SignSignature Key label, data and signature configurationSignature of the data Return Status
CO, URCrypto VerifySignature Key label, data, signature of the data, and verification configurationSignature verification result Return Status
COUser UnblockUsername informationReturn Status
SUAdmin UnblockAdmin username informationReturn Status
SU, COSystem UnblockOnly input frame with no additional input dataReturn Status

Table 9 Roles, Service Commands, Input and Output 23/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 24
4.3.2 Approved Services

Services listed below are approved services: either FIPS-approved security services, [ISO/IEC 19790] 7.4.3 services, non security-relevant services, or services using non-approved algorithm but claiming no security. Those services are available when the module is running in approved mode of operation. 24/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.1

Page 25
ServiceDescriptionApproved Security FunctionKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
GP Secure ChannelEstablish a Global Platform secure communications channelGP SCP ‘03’ Authentication and Secure Messaging vendor affirmed CKG [NIST.SP.800-133.Rev2] A2912OS-DRBG-STATE SD-KENC SD-KMAC SD-SENC SD-SMAC SD-RMACAAG, E E E G, E G, E G, ECompletion Status2
GP Manage ContentLoad and install application packages and its associated keys and dataGP SCP ‘03’ Secure Messaging AES Encryption/Decryption A2912SD-KENC SD-KMAC SD-KDEK SD-SENC SD-SMAC SD-RMAC DAP-AESAAW W W E E E W, ECompletion Status
GP Life CycleSet GP life cycle-OS-MKEKAAZCompletion Status
SE ResetReset Warm/Cold-H-eAUTH_sk H-Zs H-Ze H-SKAuthEnc H-SKAuthMac H-SKAuthKC H-SKSyncEnc H-SKSyncMac H-eAUTH_pk H-eHOST_pk H-HostIDUUZ Z Z Z Z Z Z Z Z Z ZCompletion Status
Initialize UpdatePerforms initiation of a GP SCP ‘03’ Secure Channel SessionGP SCP ‘03’ Authentication vendor affirmed CKG [NIST.SP.800-133.Rev2] A2912SD-SENC SD-SMAC SD-RMACAAG, E G, E GCompletion Status
External AuthenticateAuthenticate the host and to determine the level of security required for all subsequent commandsGP SCP ‘03’ Authentication A2912SD-SENC SD-SMAC SD-RMACAAE E ECompletion Status

E Completion Status that indicates execution status result (success or error with specific reason code) 25/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 26
Store DataTransfer data to an Application in the GP secure channelGP SCP ‘03’ Secure Messaging AES Encryption/Decryption A2912H-sAUTH_sk H-Ksync H-sAUTH_pk H-sHOST_pk H-sUSER_pkAAW W W W WCompletion Status
Manage SessionFIPS Applet open session and close sessionN/AH-KT_ECDSA_PAIR H-KT_ECDSA_sk H-KT_AES H-KT_3DES H-KT_RSA_CRT_PAIR H-KT_RSA_SFM_PAIR H-KT_RSA_CRT_sk H-KT_RSA_SFM_sk H-KT_HMAC H-KT_ECDSA_pk H- KT_RSA_pkUUZ Z Z Z Z Z Z Z Z Z ZCompletion Status
Mutual AuthenticatePublic key exchange leads to key agreement between HOST’s operator and the moduleC(2s,2e, ECDH) Key Agreement using Curve P521 One Step Key Derivation Counter Mode using HMAC-SHA2-256 A2912 vendor affirmed CKG [NIST.SP.800-133.Rev2]H-sAUTH_sk H-eAUTH_sk H-eD H-Zs H-Ze H-SKAuthEnc H-SKAuthMac H-SKAuthKC H-sAUTH_pk H-sHOST_pk H-sUSER_pk H-eAUTH_pk H-eHOST_pk H-HsmID H-HostIDUUE G, E, Z E G, E, Z G, E, Z G G G, E E E E G, E, Z G, E, Z E W, ECompletion Status
User AuthenticateLogin on current open sessionKey Confirmation using AES-CMAC-256 A2912H-SKAuthEnc H-SKAuthMac H-SKAuthKC H-User_pwdUUZ Z E, Z ECompletion Status
Secure ChannelSecure Messaging for sensitive dataAES-256-CBC for Message Encryption & Decryption AES-256-CMAC for Message Authenticity A2912H-SKAuthEnc H-SKAuthMac H-SKAuthKCSU, CO, KC1, KC2, KC3, AU, URE, Z E, Z E, ZCompletion Status

26/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 27
CCMK Import 1Import secret based on user’s (KeyCustodian1) inputSplit knowledge procedure and 32 Bits for KCV A2912N/ACO, KC1N/ACompletion Status
CCMK Import 2Import secret based on user’s (KeyCustodian2) inputSplit knowledge procedure and 32 Bits for KCV A2912N/ACO, KC2N/ACompletion Status
CCMK Import 3Import secret based on user’s (KeyCustodian3) input. CCMK will be set in this sequenceSplit knowledge procedure and 32 Bits for KCV A2912 One Step Key Derivation Counter Mode: AES- CMAC-256 vendor affirmed CKG [NIST.SP.800-133.Rev2] A2912H-CCMK H-CCMKEnc H-CCMKMacCO, KC3W, Z G, Z G, ZCompletion Status
CCMK Export 1Export secret of KeyCustodian1 Secret is calculated by FIPS applet in this casevendor affirmed CKG (SP800-133 Rev2) Split knowledge procedure and 32 Bits for KCV A2912H-CCMKCO, KC1GCompletion Status
CCMK Export 2Export secret of KeyCustodian2. Secret is calculated by FIPS applet in this caseSplit knowledge procedure and 32 Bits for KCV A2912H-CCMKCO, KC2ECompletion Status
CCMK Export 3Export secret of KeyCustodian3. Secret is calculated by FIPS applet in this case. CCMK will be set in this sequenceSplit knowledge procedure and 32 Bits for KCV One Step Key Derivation Counter Mode: AES- CMAC-256 vendor affirmed CKG [NIST.SP.800-133.Rev2] A2912H-CCMK H-CCMKEnc H-CCMKMacCO, KC3E G GCompletion Status

27/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 28
Import KeyCreate new key with parameters totally based on user’s input.Key Protection using combination of approved encryption method and approved authentication method in section 2.3.1 A2912H-CCMKEnc H-CCMKMac H-KT_AES H-KT_3DES H-KT_HMAC H-KT_RSA_CRT_PAIR H-KT_RSA_SFM_PAIR H-KT_RSA_pk H-KT_RSA_CRT_sk H-KT_RSA_SFM_sk H-KT_ECDSA_PAIR H-KT_ECDSA_pk H-KT_ECDSA_skCO, URE E W, E W W W W W W W W W WCompletion Status
Export KeyExport existing key into key file with CCMK or other existing key protectionKey Protection using combination of approved encryption method and approved authentication method in section 2.3.1 A2912H-CCMKEnc H-CCMKMac H-KT_AES H-KT_3DES H-KT_HMAC H-KT_RSA_CRT_PAIR H-KT_RSA_SFM_PAIR H-KT_RSA_pk H-KT_RSA_CRT_sk H-KT_RSA_SFM_sk H-KT_ECDSA_PAIR H-KT_ECDSA_pk H-KT_ECDSA_skCO, URE E R, E R R R R R R R R R RCompletion Status
Load KeyLoad PERMANENT key from LKD or VOLATILE FOR STORAGE key from LKD_DP into FIPS appletKey Protection using combination of approved encryption method and approved authentication method in section 2.3.1 A2912H-CCMKEnc H-CCMKMac H-KT_AES H-KT_3DES H-KT_HMAC H-KT_RSA_CRT_PAIR H-KT_RSA_SFM_PAIR H-KT_RSA_pk H-KT_RSA_CRT_sk H-KT_RSA_SFM_sk H-KT_ECDSA_PAIR H-KT_ECDSA_pk H-KT_ECDSA_skCO, URE E W W W W W W W W W W WCompletion Status

28/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 29
Diversify KeyDiversify an existing key with user’s choice of methodUsing approved Key Derivation Function SP800-108 Key Protection using combination of approved encryption method and approved authentication method in section 2.3.1H-CCMKEnc H-CCMKMac H-KT_AES H-KT_3DES H-KT_HMACCO, URE E G, E G G, ECompletion Status
Generate KeyCreate a new key with user’s input algorithm Key value randomized by FIPS appletvendor affirmed CKG [NIST.SP.800-133.Rev2] Key Protection using combination of approved encryption method and approved authentication method in section 2.3.1 A2912H-CCMKEnc H-CCMKMac H-KT_AES H-KT_3DES H-KT_HMACCO, URE E G G GCompletion Status
Generate Key PairCreate a new asymmetric key User can freely choose the algorithm and curve Key value randomized by FIPS appletvendor affirmed CKG [NIST.SP.800-133.Rev2] Key Protection using combination of approved encryption method and approved authentication method in section 2.3.1 A2912H-CCMKEnc H-CCMKMac H-KT_RSA_CRT_PAIR H-KT_RSA_SFM_PAIR H-KT_ECDSA_PAIRCO, URE E G G GCompletion Status
Generate Key (for Split Knowledge)Customer key generation This service will determine the specification of key token output from the whole Customer Key Ceremony procedurevendor affirmed CKG [NIST.SP.800-133.Rev2]H-KT_AES H-KT_3DES H-KT_HMACCOG G GCompletion Status
CK Export 1Export a secret for customer key creation for KCP1Split knowledge procedure and 32 bits KCV A2912H-KT_AES H-KT_3DES H-KT_HMACCO, URE E ECompletion Status

29/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 30
CK Export 2Export a secret for customer key creation for KCP2Split knowledge procedure and 32 bits KCV A2912H-KT_AES H-KT_3DES H-KT_HMACCO, URE E ECompletion Status
CK Export 3Export a secret for customer key creation for KCP3 This sequence will return KCV of Secret and Key Token for CK Import procedure later onSplit knowledge procedure and 32 bits KCV AES-CMAC-256 for Key Authenticity A2912H-KT_AES H-KT_3DES H-KT_HMAC H-CCMKMacCO, URE E E ECompletion Status
CK Import 1Import secret based on user’s (KCP1) inputSplit knowledge procedure and 32 bits KCVN/ACO, URN/ACompletion Status
CK Import 2Import secret based on user’s (KCP2) inputSplit knowledge procedure and 32 bits KCVN/ACO, URN/ACompletion Status
CK Import 3Import secret and key token based on user’s (KCP3) input. This sequence will return a completed key token to be stored in LKD or LKD_DPSplit knowledge procedure and 32 bits KCV Key Protection using combination of approved encryption method and approved authentication method in section 2.3.1 A2912H-CCMKEnc H-CCMKMacCO, URE ECompletion Status
FIPS Applet Store DataThis service normally used to store SUPER_USER public key within FIPS Applet Initialization procedure after SUPER_USER change its smartcard’s PINECC CDH Key Agreement for Key Validation Message Digest SHA2-256 A2912H-sHOST_pk H-sUSER_pkSU, COW WCompletion Status

30/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 31
Sync Request TokenThis service is targeted to SE_MASTER to retrieve a sync token which will be referred on Sync Write Token serviceKey Derivation One Step Counter Mode : AES- CMAC-256 vendor affirmed CKG [NIST.SP.800-133.Rev2] Automated SSPs Establishment using approved method SP800- 38F SYNC Message Encryption: AES-256-CBC-M2 SYNC Message Authenticity: AES-256- CMAC A2912H-KSync H-SKSyncEnc H-SKSyncMacSU, COE G, E, Z G, E, ZCompletion Status
Sync Write TokenThis service will write sync token on SE_SLAVE. Sync token that is written in this service can be retrieved from Sync Request Token serviceKey Derivation One Step Counter Mode: AES- CMAC-256-M2 vendor affirmed CKG [NIST.SP.800-133.Rev2] Automated SSPs Establishment using approved method SP800- 38F SYNC Message Decryption & Encryption : AES-256- CBC SYNC Message Authenticity: AES-256- CMAC A2912H-KSync H-SKSyncEnc H-SKSyncMac H-KT_AES H-KT_3DES H-KT_HMAC H-KT_RSA_CRT_PAIR H-KT_RSA_SFM_PAIR H-KT_RSA_pk H-KT_RSA_CRT_sk H-KT_RSA_SFM_sk H-KT_ECDSA_PAIR H-KT_ECDSA_pk H-KT_ECDSA_skSU, COE G, E, Z G, E, Z Z Z Z Z Z Z Z Z Z Z ZCompletion Status
Sync ReportThis service purpose is to confirm that Sync Write Token had performed successfully. The target of this service is SE_MASTERSYNC Message Decryption: AES-256-CBC- M2 SYNC Message Authenticity: AES-256- CMAC A2912H-SKSyncEnc H-SKSyncMacSU, COE, Z E, ZCompletion Status

31/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 32
Crypto EncipherPerform encipher on the user’s input dataWhen used with an approved encryption algorithm in section 2.3.1 A2912H-KT_AESCO, URECompletion Status
Crypto DecipherPerform decipher on the user’s input dataWhen used with an approved decryption algorithm in section 2.3.1 A2912H-KT_AESCO, URECompletion Status
Crypto SignCreate signature based on the user’s input dataWhen used with an approved signature and MAC algorithm in section 2.3.1 A2912H-KT_HMAC H-KT_RSA_CRT_PAIR H-KT_RSA_SFM_PAIR H-KT_RSA_CRT_sk H-KT_RSA_SFM_sk H-KT_ECDSA_PAIR H-KT_ECDSA_skCO, URE E E E E E ECompletion Status
Crypto VerifyConfirm the verified status of the user’s signature dataWhen used with an approved verification and MAC algorithm in section 2.3.1 A2912H-KT_HMAC H-KT_RSA_CRT_PAIR H-KT_RSA_SFM_PAIR H-KT_RSA_pk H-KT_ECDSA_PAIR H-KT_ECDSA_pkCO, URE E E E E ECompletion Status
FIPS Applet Set ConfigSet FIPS applet configurationService that uses processes in approved mannerN/ACON/ACompletion Status
Profile CreateCreate new profileService that uses processes in approved mannerN/ACON/ACompletion Status
Profile DeleteDelete non-default profile based on profile name inputService that uses processes in approved mannerN/ACON/ACompletion Status
User CreateCreate new userService that uses processes in approved mannerH-User_pwd H-sUSER_pkCOW WCompletion Status
User Create ADMINAdmin creation. This is a step during FIPS Applet Initialization procedureService that uses processes in approved mannerH-User_pwd H-sUSER_pkSUW WCompletion Status

32/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 33
User DeleteDelete user based on user name inputService that uses processes in approved mannerH-User_pwd H-sUSER_pkCOZ ZCompletion Status
User Change CredentialChange user’s password or user’s public keyService that uses processes in approved mannerH-User_pwd H-sUSER_pkSU, COW WCompletion Status
User LogoutLogout the userN/AH-SKAuthEnc H-SKAuthMac H-SKAuthKCSU, CO, KC1, KC2, KC3, AU, URZ Z ZCompletion Status
System ResetReset admin user, applet life cycle, LKD, and LKD_DPN/AH-CCMK H-CCMKEnc H-CCMKMac H-User_pwd H-KT_ECDSA_PAIR H-KT_ECDSA_sk H-KT_AES H-KT_3DES H-KT_RSA_CRT_PAIR H-KT_RSA_SFM_PAIR H-KT_RSA_CRT_sk H-KT_RSA_SFM_sk H-KT_HMAC H-KT_ECDSA_pk H-KT_RSA_pk H-sUSER_pkSU, COZ Z Z Z Z Z Z Z Z Z Z Z Z Z Z ZCompletion Status

Table 10 Approved Security Services G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. - = Not accessed by the service 33/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 34
Service Global Platform ServicesApproved Service’s Rationale
GP Get StatusShow status service as specified in the [ISO/IEC 19790] section 7.4.3
GP Get DataShow module’s versioning information service as specified in the ISO19790:2012 section 7.4.3
GP Select FIPS Applet ServicesThere is no intervention to the security process nor access to defined SSP
Get InfoShow module’s versioning information and Show status service as specified in the [ISO/IEC 19790] section 7.4.3
Check LogThere is no intervention to the security process nor access to defined SSP
Read LogThere is no intervention to the security process nor access to defined SSP
Delete LogThere is no intervention to the security process nor access to defined SSP
Export Log (mode 01)There is no intervention to the security process nor access to defined SSP
Export Log (mode 02)There is no intervention to the security process nor access to defined SS.
Profile ViewThere is no intervention to the security process nor access to defined SSP
User View (full)There is no intervention to the security process nor access to defined SSP
User View (Admin only)There is no intervention to the security process nor access to defined SSP
Set DateThere is no intervention to the security process nor access to defined SSP
Get DataThere is no intervention to the security process nor access to defined SSP
User UnblockCrypto Officer management function service
Admin UnblockCrypto Officer management function service
System UnblockCrypto Officer management function service

Table 11 Approved Services - ISO19790:2012 7.4.3 Services, Non Security-Relevant Services, or Services Using NonApproved Algorithm but Claiming No security The module does not support any non-approved services.

4.3.3 Firmware Loading

The module employs GP APDU Commands i. e Load command and Install command as specified in [GPC_Specification_v2.3] as part of GP Manage Content Services for firmware loading. Due to I/O buffer size of the module, the firmware loading process utilizes several Load commands and Install command. Data output is inhibited in each APDU command execution and during Load Test. The module performs Load Test specified in the section 10.2.2 during firmware loading process. If the load test is failed, specific Status Word of the command is returned to indicate failure on firmware loading and the firmware cannot be used. New firmware version within the scope of this validation must be validated through the [NIST.FIPS.140-3] CMVP. Any other firmware loaded into this module is out of the scope of this validation and requires a separate [NIST.FIPS.140-3] validation. A procedure for firmware loading is described in [FQR 401 9097 Ed 4] section 3.4.2. 34/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.1

Page 35
ComponentSub ComponentsForm
OSNative ApplicationA binary code written in c and assembly language running on Hardware’s CPU
Built-in Card ManagerA binary code written in Java running on JCVM
FIPS AppletFIPS AppletA binary code written in Java running on JCVM
Rooky Common PackageA binary code written in Java running on JCVM
5 SOFTWARE AND FIRMWARE SECURITY

Initial firmware is loaded through a chip loader (referenced as Initial Flash Loader) and provided by Hardware Manufacturer. The loader is used to decrypt a RookySE firmware delivered in an encrypted firmware. Once full firmware is received and deciphered, a final checksum is sent to the Flash Loader to compare against the internal computed checksum. From the RookySE firmware, OS checksum can be verified through a GP GET DATA command on DGI DF6E. During this command, the checksum is recalculated on the OS memory range. In case of memory corruption, the card might trigger a security event. OS checksum is checked using a 16-bit EDC and compared against a stored value in NVM. Beside OS Firmware verification, the module also ensures the Applet Packages integrity by computing a CRC16 on each package, and comparing against stored values. The laters are computed during application loading and stored as references. Upon a failed checksum verification, the OS Firmware will trigger a security event. The operator can perform a warm or cold reset to check OS integrity and NVM (applet packages) integrity is valid or not as specified in section 10.1.1 integrity self test.

5.1 Form of Executable Code

The module consists of several components that have different forms of executable code. The following table shows the form of each component: Table 12 Form of Executable Code

5.2 Initiate on Demand

The module permits operators to initiate the pre-operational self-tests on demand by power cycling the module.

6 OPERATIONAL ENVIRONMENT

Not Applicable (Remarks. The module is designated as a limited operational environment under the [NIST.FIPS.140-3] definitions. The module includes a firmware load process (GP Manage Content service) to support necessary updates. New firmware versions within the scope of this validation must be validated through the [NIST.FIPS.140-3] CMVP. Any other firmware loaded into this module is out of the scope of this validation and requires a separate [NIST.FIPS.140-3] validation.) 35/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 36
Physical Security MechanismRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Tamper-evident coating on chip The module implements a secure wiring: all security critical wires are protected by special routing measures against probing. Additionally, the wires are embedded into shield lines and used as normal lines for operation to prevent successful probing Whenever a physical manipulation or physical probing attack is detected, the processing of the module is stopped, and the module enters a secure state (reset)Permanently active, the detection is automaticN/A
Memory Protection All memories present on the module (Flash, ROM, RAM) are encrypted, memory addresses are scrambled and data transferred over bus are masked. Furthermore, RAM, Flash and Cache integrity are protected with error detection mechanisms In case of security critical error, the module enters a secure state (reset)Permanently active, the detection is automaticN/A
Sensors The module is equipped with a temperature sensor, a voltage sensor, a frequency sensor and backside light detection. The module enters a secure state in case of range v iolation (reset)Permanently active, the detection is automaticN/A

The module is a single-chip implementation that meets commercial-grade specifications for power, temperature, reliability, and shock/vibrations. actions required by the operator(s) to ensure that the physical security is maintained: N/A violation (reset) Table 13 Physical Security Inspection Guidelines 36/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 37
Temperature or voltage measurementSpecify EFP11 or EFTSpecify if this condition results in a shutdown or zeroisation
Low Temperature-25°CEFTShutdown
High Temperature+85°CEFTShutdown
Low Voltage1.40V < Vcc < 1.62VEFTShutdown
High Voltage5.5V < Vcc < 7.9VEFTShutdown
Hardness tested temperature measurement
Low Temperature-25°C
High Temperature+85°C

The following table shows temperature and voltage measurement for EFP that is required for modules with physical Security Level 3: Table 14 EFP/EFT The following table shows hardness tested at the lowest and highest temperatures within the module's intended temperature range of operation: Table 15 Hardness Testing Temperature Range

8 NON-INVASIVE SECURITY

Not Applicable 37/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 38
Key/SSP Name/ Type CRITICAL SECURITY PARAMETERS – OSStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
OS-DRBG-SEED Entropy input and nonce provided by the ENT (P)N/AENT (P)Generated by a call to ENT when the DRBG is instantiated or when a reseed is requiredN/AN/APlaintext/ dynamic in RAM (Stack)Overwrite with all zeros value on power cycle or when no longer usedUsed to seed the Approved DRBG
OS-DRBG-STATE The current AES‐ 256 CTR_DRBG stateN/AN/AGenerated every time DRBG is generatedN/AN/APlaintext/dyna mic in RAM (Global)Overwrite with all zeros value on power cycle or when no longer usedStore the state of CTR_DRBG
SD-KENC Master Encryption Security Domain key AES Key Mode: N/A (only derivation)AES-256AES A2912N/AImported using APDU Command STORE DATA or PUT KEY through GP SCP ‘03’ at Manufacturing, and also later, IN USE phase I/O type: electronicN/APlaintext(obfus cated)/static in persistent memory of the Module at manufacturing stageOverwrite with all zeros value on: Personalization at Manufacturing by erasing all data in NVM APDU Command GP Delete KeyMaster key used to generate SD‐SENC
9 SENSITIVE SECURITY PARAMETER MANAGEMENT
9.1 SSP Management

38/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.1

Page 39
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
SD-KMAC Master MAC Security Domain key AES Key Mode: N/A (only derivation)AES-256AES A2912N/AImported using APDU Command STORE DATA or PUT KEY through GP SCP ‘03’ at Manufacturing I/O type: electronicN/APlaintext(obfus cated)/static in persistent memory of the Module at manufacturing stageOverwrite with all zeros value on: Personalization at Manufacturing by erasing all data in NVM APDU Command GP Delete KeyMaster key used to generate SD‐SMAC
SD-KDEK Master DEK Security Domain key AES Key Mode: N/A (only derivation)AES-256AES A2912N/AImported using APDU Command STORE DATA or PUT KEY through GP SCP ‘03’ at Manufacturing I/O type: electronicN/APlaintext(obfus cated)/static in persistent memory of the Module at manufacturing stageOverwrite with all zeros value on: Personalization at Manufacturing by erasing all data in NVM APDU Command GP Delete KeySensitive data decry ption key used to de crypt CSPs (SD- KENC, SD-KMAC, SD-KDEK, DAP- AES)
SD-SENC GP Secure Channel Session Encryption Key AES Key Mode: CBCAES-256CKG AES A2912N/AN/AGenerated during Secure Channel opening (in InitUpdate command) using approved key generation function (CKG)Plaintext/dyna mic as a volatile Native Key Object (RAM) inside the ModuleOverwrite with all zeros value on: Power_ON or applet selectionSession encryption k ey used to encrypt / decrypt secure chan nel data

39/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 40
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
SD-SMAC GP Secure Channel Session Command MAC Key AES Key, Mode: CMACAES-256CKG AES A2912N/AN/AGenerated during Secure Channel opening (in InitUpdate command) using approved key generation function (CKG)Plaintext/dyna mic as a volatile Native Key Object (RAM) inside the ModuleOverwrite with all zeros value on: Power_ON or applet selectionSession MAC key us ed to verify inbound secure channel data integrity
SD-RMAC GP Secure Channel Session Response MAC Key AES Key Mode: CMACAES-256CKG AES A2912N/AN/AGenerated during Secure Channel opening (in InitUpdate command) using approved key generation function (CKG)Plaintext/dyna mic as a volatile Native Key Object (RAM) inside the ModuleOverwrite with all zeros value on: Power_ON or applet selectionSession MAC key us ed to generate respo nse secure channel data MAC
DAP-AES Data Authentication Pattern AES Key AES Key Mode: CMAC CRITICAL SECURITY PARAMETERS – FIPS APPLET on RookySEAES-128AES A2912N/AImported using APDU Command PUT KEY through GP SCP ‘03’ at Manufacturing I/O type: electronicN/APlaintext/static as persistent JCVM Key Object owned by the ISD inside the ModuleOverwrite with all zeros value on: Personalization at Manufacturing by erasing all data in NVM APDU Command GP Delete KeyUsed to calculate signature (MAC) of loaded package for firmware loading
H-sAUTH_skCurve P-521KAS- ECCN/AImported using APDU Command ‘StoreN/APlaintext(obfus cated)/static asOverwrite with all zeros valueUsed in the Key Agreement together
Page 41
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
System Authentication Static Private Key EC Private KeyA2912Data’ that is authenticated and protected using GP SCP ‘03’ level 3 (Encrypted and MAC) on: Personalization at Manufacturing Firmware Loading process to upgrade version of new validated FIPS Applet I/O type: electronicJCVM Key Object owned by the FIPS Applet inside the Module as non-volatile dataon: Personalization at Manufacturing by erasing all data in NVM Firmware Loading Process using APDU Command Delete Package and Instancewith HOST Authentication Static Public Key (H- sHOST_pk) or User Authentication Static Public Key (H- sUSER_pk) to generate shared secret H-Z s
H-eAUTH_sk System Authentication Ephemeral Private Key EC Private KeyCurve P-521CKG KAS- ECC A2912Generated using ECDSA Key Pair Generation function (CKG) on Mutual Authenticate serviceN/AN/APlaintext/dyna mic as JCVM Key Object owned by the FIPS Applet inside the Module as volatile dataOverwrite with all zeros value on: Destroy on shared secret H- Z generation. e Any failure during mutual authentication On RESET (Warm/Cold)Used in the Key Agreement together with HOST Authentication Ephemeral Public Key (H-eHOST_pk) to generate shared secret H-Z e
Page 42
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
H-Z s Shared secret Zs 66 bytes of secret dataN/AKAS- ECC A2912N/AN/AEstablished in the Key Agreement (A2912) between H- sAUTH_sk and H-sUSER_pk if authentication method is smartcard- based or H- sHOST_pk if authentication method is password-based on Mutual Authenticate servicePlaintext/Dyna mic in transient byte array owned by FIPS Applet inside the moduleOverwrite with all zeros value on: After Key Derivation Any failure during authentication On RESET (Warm/Cold)Combined with H-Z e to construct secret Z used in Key Derivation to generate session keys H-SKAuthEnc, H-SKAuthMac, H- SKAuthKC on successful user authentication
H-Z e Shared secrets Ze 66 bytes of secret dataN/AKAS- ECC A2912N/AN/AEstablished in the Key Agreement (A2912) between H- eAUTH_sk and H-eHOST_pk on Mutual Authenticate servicePlaintext/dyna mic in transient byte array owned by FIPS Applet inside the moduleOverwrite with all zeros value on: After Key Derivation Any failure during authentication On RESET (Warm/Cold)Combined with H-Z s to construct secret Z used in Key Derivation to generate session keys H-SKAuthEnc, H-SKAuthMac, H- SKAuthKC on successful user authentication

42/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 43
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
H-SKAuthEnc Encryption Secure Channel Session Key AES Key Mode: CBCAES-256CKG AES A2912N/AN/AGenerated using approved key generation (CKG) using derivation from Key Agreement Scheme followed by One Step KDF in counter mode with (H-Z ||H- s Z ) as message e in the process on Mutual Authenticate servicePlaintext/dyna mic in transient byte array owned by FIPS Applet inside the moduleOverwrite with all zeros value on: Any failure during User authentication Error secure messaging in secure channel User logging out Close Session On RESET (Warm/Cold)Used to encrypt and decrypt the message for secure messaging in the Secure Channel
H-SKAuthMac MAC Secure Channel Session Key AES Key Mode: CMACAES-256CKG AES A2912N/AN/AGenerated using approved key generation (CKG) using derivation from Key Agreement Scheme followed by One Step KDF counter mode with (H-Z ||H- s Z ) as message e in the process on MutualPlaintext/dyna mic in transient byte array owned by FIPS Applet inside the moduleOverwrite with all zeros value on: Any failure during User authentication Error secure messaging in secure channel User logging out Close SessionUsed to calculate MAC of the message for secure messaging in the Secure Channel

with (H-Zs ||H43/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 44
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishment Authenticate serviceStorageZeroisation On RESET (Warm/Cold)Use & related keys
H-SKAuthKC Key Confirmation Secure Channel Session Key AES Key Mode: CMACAES-256CKG AES A2912N/AN/AGenerated using approved key generation (CKG) using derivation from Key Agreement Scheme followed by One Step KDF counter mode with (H-Z ||H- s Z ) as message e in the process on Mutual Authenticate servicePlaintext/dyna mic in transient byte array owned by FIPS Applet inside the moduleOverwrite with all zeros value on: Any failure during User authentication Error secure messaging in secure channel User logging out Close Session On RESET (Warm/Cold)Used for bilateral key confirmation including for generating UserToken from username, {H- User_pwd}, H- HsmID, H-HostID, H-eAUTH_pk , and H-eHOST_pk in the authentication process Used to generate IVs for Message Encryption / Decryption for secure messaging in Secure Channel
H-CCMK Crypto Card Master Key AES Key Mode: N/A (only derivation)AES-256CKG AES DRBG KDF A2912Generated internally using approved CKG (Direct Generation of Symmetric Key) and split into 3 secrets on Export CCMK servicesExported and encrypted through secure channel using split knowledge procedure on Export CCMK services Imported through secure channel usingEstablished from three different secrets from three different key custodians through secure channel on Import CCMK servicesPlaintext(obfus cated)/static as JCVM Key Object owned by the FIPS Applet inside the Module as non-volatile dataOverwrite with all zeros on: System Reset service Personalization at Manufacturing by erasing allUsed as master key to derrive H- CCMKEnc and H- CCMKMac
Page 45
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /Export split knowledge procedure on Import CCMK services I/O type: electronicEstablishmentStorageZeroisation data in NVM Firmware Loading Process using APDU Command Delete Package and InstanceUse & related keys
H-CCMKEnc Encryption Derived CCMK Key AES Key Mode : CBCAES-256CKG AES A2912N/AN/ADerived from pre-existing key H-CCMK using one step KDF counter mode on successful completion of 3 secrets export or importPlaintext(obfus cated)/static as JCVM Key Object owned by the FIPS Applet inside the Module as non-volatile dataOverwrite with all zeros on: System Reset service Personalization at Manufacturing by erasing all data in NVM Firmware Loading Process using APDU Command Delete Package and InstanceUsed to encrypt/decrypt key token for Key Protection
H-CCMKMac MAC Derived CCMK Key AES Key Mode : CMACAES-256CKG AES A2912N/AN/ADerived from pre-existing key H-CCMK using one step KDF counter mode on successful completion of 3Plaintext(obfus cated)/static as JCVM Key Object owned by the FIPS Applet inside the Module asOverwrite with all zeros on: System Reset service Personalization at ManufacturingUsed to calculate MAC of key token as part of token for Key Protection
Page 46
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishment secrets export or importStorage non-volatile dataZeroisation by erasing all data in NVM Firmware Loading Process using APDU Command Delete Package and InstanceUse & related keys
H-KSync Synchronization Master Key AES Key Mode: N/A (only derivation)AES-256KDF A2912N/AImported using APDU Command ‘Store Data’ that is authenticated and protected using GP SCP ‘03’ level 3 (Encrypted and MAC) on: Personalization at Manufacturing Firmware Loading process to upgrade version of new validated FIPS Applet I/O type: electronicN/APlaintext(obfus cated)/static in persistent byte array owned by FIPS Applet inside the moduleOverwrite with all zeros on: Personalization at Manufacturing by erasing all data in NVM Firmware Loading Process using APDU Command Delete Package and InstanceUsed as master key to derive H- SKSyncEnc and H- SKSyncMac for Synchronization Session Keys
H-SKSyncEnc Encryption Synchronization Session KeyAES-256CKG AES A2912N/AN/ADerived from pre-existing key H-KSync using one step KDF counter mode with incrementalPlaintext/dyna mic in transient byte array owned by FIPS Applet inside the moduleOverwrite with all zeros on: Any failure duringUsed to encrypt/decrypt SYNC Token using Automated SSP Establishment Key Transport in
Page 47
Key/SSP Name/ Type AES Key Mode: CBCStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishment SYNC session counter as part of the message on every synchronization initiation (SYNC Request Token service in System MASTER and SYNC Write Token service in System SLAVE)StorageZeroisation synchronization session After synchronization session completed On RESET (Warm/Cold)Use & related keys synchronization process
H-SKSyncMac MAC Synchronization Session Key AES Key Mode: CMACAES-256CKG AES A2912N/AN/ADerived from pre-existing key H-KSync using one step KDF counter mode with incremental SYNC session counter as part of the message on every synchronization initiation (SYNC Request Token service in System MASTER and SYNC Write Token service in System SLAVE)Plaintext/dyna mic in transient byte array owned by FIPS Applet inside the moduleOverwrite with all zeros on: Any failure during synchronization session After synchronization session completed On RESET (Warm/Cold)Used to calculate MAC of SYNC Token using Automated SSP Establishment Key Transport in synchronization process
H-User_pwdMaximum 16 charAESN/AImported along with username via UserN/APlaintext(obfus cated)/static inOverwrite with all zeros on:Used as part of credential data to

47/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 48
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
User’s password credential Maximum 16 charactersKAS- ECC A2912Create service through secure channel Updated the old password with new password via User Change Password service through secure channel I/O type: electronicpersistent byte array owned by FIPS Applet inside the moduleSystem Reset User deletion Synchronization Personalization at Manufacturing by erasing all data in NVM Firmware Loading Process using APDU Command Delete Package and Instancegenerate User Token using H- SKAuthKC
H-KT_ECDSA_PAIR Key Token ECDSA PAIR ECC Key PairCurve P-192 Curve P-224 Curve P-256 Curve P-384 Curve P-521CKG ECDSA A2912Generated using ECDSA Key Pair Generation function (CKG) on Generate Key serviceImported via Import Key service and Exported via Export Key service I/O type: electronicN/APlaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, and device reset (warm/cold). Also when the following services are executed: - System ResetH- KT_ECDSA_PAIR can be stored outside the System module protected by H-CCMKEnc and H- CCMKMac, or by approved symmetric key token (H- KT_AES) Public Key of this key token can be used to perform

48/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 49
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisation - Manage session - Sync write tokenUse & related keys Crypto operation via Crypto Verify service Private Key of this key token can be used to perform Crypto operation via Crypto Sign service H- KT_ECDSA_PAIR with Curve P-192 can only be used for signature verification and not for signature generation
H-KT_ECDSA_sk Key Token ECDSA PRIVATE ECC Private KeyCurve P-192 Curve P-224 Curve P-256 Curve P-384 Curve P-521ECDSA A2912N/AImported via Import Key service and Exported via Export Key service I/O type: electronicN/APlaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, and device reset (warm/cold). Also when the following services are executed: - System Reset - Manage sessionH-KT_ECDSA_sk can be stored outside the system module protected by H-CCMKEnc and H- CCMKMac, or by approved symmetric key token (H- KT_AES) All curves (except curve P-192) of this key token can be used to perform Crypto operation via Crypto Sign service

H49/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 50
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisation - Sync write tokenUse & related keys
H-KT_AES Key Token AES AES Key Mode: CBCAES-128 AES-192 AES-256CKG AES A2912Generated internally using approved Generate Key service (CKG) – Direct Generation of Symmetric KeyImported via Import Key service and Exported via Export Key service I/O type: electronicH-KT_AES also can be generated from Diversify Key service using KDF Counter mode with approved MasterKey (H- KT_AES or H- KT_HMAC)Plaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, and device reset (warm/cold). Also when the following services are executed: - System Reset - Manage session - Sync write tokenH-KT_AES can be stored outside the System module protected by H- CCMKEnc and H- CCMKMac, or by approved symmetric key token (H- KT_AES) H-KT_AES can be used to protect another key token for external key storage (outside of System Module). This key token can be used to perform Crypto operation via Crypto Cipher, Crypto Decipher service.
H-KT_RSA_CRT_PAIR Key Token RSA CRT PAIR RSA CRT Key Pair Mode: PSS or PKSC1RSA-1024 RSA-2048 RSA-3072 RSA-4096CKG RSA A2912Generated using RSA Key Pair Generation function (CKG) on approved Generate Key serviceImported via Import Key service and Exported via Export Key service I/O type: electronicN/APlaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, andH- KT_RSA_CRT_PAI R can be stored outside the System module protected by H-CCMKEnc and H- CCMKMac, or by

50/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 51
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisation device reset (warm/cold). Also when the following services are executed: - System Reset - Manage session - Sync write tokenUse & related keys approved symmetric key token (H- KT_AES) Public Key of this key token can be used to perform Crypto operation via Crypto Verify service. Private Key of this key token can be used to perform Crypto operation via Crypto Sign service. (Key Token RSA- 1024 can only be used for signature verification)
H- KT_RSA_SFM_PAIR Key Token RSA SFM PAIR RSA SFM Key Pair Mode: PSS or PKSC1RSA-1024 RSA-2048 RSA-3072 RSA-4096CKG RSA A2912Generated using RSA Key Pair Generation function (CKG) on approved Generate Key serviceImported via Import Key service and Exported via Export Key service. I/O type: electronicN/APlaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, and device reset (warm/cold). Also when the followingH- KT_RSA_SFM_PAI R can be stored outside the System module protected by H-CCMKEnc and H- CCMKMac, or by approved symmetric key token (H- KT_AES)

H51/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 52
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisation services are executed: - System Reset - Manage session - Sync write tokenUse & related keys Public Key of this key token can be used to perform Crypto operation via Crypto Verify service. Private Key of this key token can be used to perform Crypto operation via Crypto Sign service. (Key Token RSA- 1024 can only be used for signature verification)
H-KT_RSA_CRT_sk Key Token RSA CRT PRIVATE RSA CRT Private Key Mode: PSS or PKSC1RSA-1024 RSA-2048 RSA-3072 RSA-4096RSA A2912N/AImported via Import Key service and Exported via Export Key service I/O type: electronicN/APlaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, and device reset (warm/cold). Also when the following services are executed: - System ResetH- KT_RSA_CRT_sk can be stored outside the System module protected by H-CCMKEnc and H- CCMKMac, or by approved symmetric key token (H- KT_AES) Key Token RSA Private can be used to perform Crypto

52/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 53
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisation - Manage session - Sync write tokenUse & related keys operation via Crypto sign service (For Crypto sign, key token RSA Private 1024 is excluded)
H-KT_RSA_SFM_sk Key Token RSA SFM PRIVATE RSA SFM Private Key Mode: PSS or PKSC1RSA-1024 RSA-2048 RSA-3072 RSA-4096RSA A2912N/AImported via Import Key service and Exported via Export Key service I/O type: electronicN/APlaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, and device reset (warm/cold). Also when the following services are executed: - System Reset - Manage session - Sync write tokenH- KT_RSA_SFM_sk can be stored outside the System module protected by H-CCMKEnc and H- CCMKMac, or by approved symmetric key token (H- KT_AES) Key Token RSA Private can be used to perform Crypto operation via Crypto sign service. (For Crypto sign, key token RSA Private 1024 is excluded)
H-KT_HMACHMAC-64 HMAC-128 HMAC-160 HMAC-224CKG HMACGenerated internally using approved Generate KeyImported via Import Key service andH-KT_HMAC also can be generated fromPlaintext/dyna mic as a volatile dataKey token data will be zeroised when the user isH-KT_HMAC can be stored outside the System module

H53/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 54
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
Key Token HMAC HMAC Key PUBLIC SECURITY PARAMETERHMAC-256 HMAC-320 HMAC-384 HMAC-512A2912service (CKG) – Direct Generation of Symmetric KeyExported via Export Key service I/O type: electronicDiversify Key service using KDF Counter mode with approved MasterKey (H- KT_AES or H- KT_HMAC)inside the System moduleblocked, System is blocked or terminated, and device reset (warm/cold). Also when the following services are executed: - System Reset - Manage session - Sync write tokenprotected by H- CCMKEnc and H- CCMKMac, or by approved symmetric key token (H- KT_AES). This key token can be used to perform Crypto operation via Crypto Sign and Crypto Verify service; HMAC-64 is used only for verification (not HMAC generation)
H-KT_ECDSA_pk Key Token ECDSA PUBLIC ECC Public KeyCurve P-192 Curve P-224 Curve P-256 Curve P-384 Curve P-521ECDSA A2912N/AImported via Import Key service and Exported via Export Key service I/O type: electronicN/APlaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, and device reset (warm/cold). Also when the following services are executed: - System ResetH-KT_ECDSA_pk can be stored outside the System module protected by H-CCMKEnc and H- CCMKMac, or by approved symmetric key token (H- KT_AES) This key token can be used to perform Crypto operation Crypto Verify service

54/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 55
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisation - Manage session Sync write tokenUse & related keys
H-KT_RSA_pk Key Token RSA PUBLIC RSA Public Key Mode: PSS or PKSC1RSA-1024 RSA-2048 RSA-3072 RSA-4096RSA A2912N/AImported via Import Key service and Exported via Export Key service I/O type: electronicN/APlaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, and device reset (warm/cold). Also when the following services are executed: - System Reset - Manage session - Sync write tokenH-KT_RSA_pk can be stored outside the System module protected by H- CCMKEnc and H- CCMKMac, or by approved symmetric key token (H- KT_AES) Key Token RSA Public can be used to perform Crypto operation via Crypto Verify service. Key Token RSA- 1024 Public can only be used for signature verification
H-sAUTH_pk System Authentication Static Public Key EC Public KeyCurve P-521KAS- ECC A2912N/AImported using APDU Command ‘Store Data’ that is authenticated and protected using GP SCP ‘03’ level 3 (Encrypted and MAC) on:N/APlaintext(obfus cated)/static as JCVM Key Object owned by the FIPS Applet inside the Module as non-volatile dataOverwrite with all zeros value on: Personalization at Manufacturing by erasing all data in NVMUsed in the Key Agreement together with HOST Authentication Static Private Key or User Authentication Static Private Key to generate shared secret in H-Z in the s client side
Page 56
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /Export Personalization at Manufacturing Firmware Loading process to upgrade version of new validated FIPS Applet Exported using System Get Data Service through Secure Channel I/O type: electronicEstablishmentStorageZeroisation Firmware Loading Process using APDU Command Delete Package and InstanceUse & related keys
H-sHOST_pk HOST Authentication Static Public Key EC Public KeyCurve P-521KAS- ECC A2912N/AImported using APDU Command ‘Store Data’ that is authenticated and protected using GP SCP ‘03’ level 3 (Encrypted and MAC) on: Personalization at Manufacturing Firmware Loading process to upgrade version of new validated FIPS Applet Exported using System Get DataN/APlaintext/static as JCVM Key Object owned by the FIPS Applet inside the Module as non-volatile dataOverwrite with all zeros value on: Personalization at Manufacturing by erasing all data in NVM Firmware Loading Process using APDU Command Delete Package and InstanceUsed in the Key Agreement together with System Authentication Static Private Key (H- sAUTH_sk) to generate shared secret H-Z s
Page 57
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /Export Service through Secure Channel I/O type: electronicEstablishmentStorageZeroisationUse & related keys
H-sUSER_pk User Authentication Static Public Key EC Public KeyCurve P-521KAS- ECC A2912N/AImported via User Create service through secure channel (for all users except Super User) Personalized at Manufacturing through GP SCP ‘03’ level 3 (only applicable for Super User’s Public Key) Updated using System Store Data service through secure channel (only applicable for Super User’s Public Key) Exported using System Get Data Service through Secure Channel (only applicable for Super User’s Public Key) I/O type: electronicN/APlaintext(obfus cated)/static as JCVM Key Object owned by the FIPS Applet inside the Module as non-volatile dataOverwrite with all zeros on: System Reset User deletion Synchronization Personalization at Manufacturing by erasing all data in NVM Firmware Loading Process using APDU Command Delete Package and InstanceUsed in the Key Agreement together with System Authentication Static Private Key (H- sAUTH_sk) to generate shared secret H-Z s
Page 58
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
H-eAUTH_pk System Authentication Ephemeral Public Key EC Public KeyCurve P-521CKG ECDSA A2912Generated using ECDSA Key Pair Generation function (CKG) on Mutual Authenticate serviceReturned to the user as part of response data of Mutual Authenticate service I/O type: electronicN/APlaintext/dyna mic as JCVM Key Object owned by the FIPS Applet inside the Module as volatile dataOverwrite with all zeros value on: Any failure during mutual authentication Successful user authentication On RESET (Warm/Cold)Used in the Key Agreement together with HOST Authentication Ephemeral Private Key to generate shared secret in H- Z in the client side e
H-eHOST_pk HOST / SMA Authentication Ephemeral Public Key EC Public KeyCurve P-521KAS- ECC KDF A2912N/AImported through Mutual Authenticate service I/O type: electronicN/APlaintext/dyna mic as JCVM Key Object owned by the FIPS Applet inside the Module as volatile dataOverwrite with all zeros value on: Any failure during mutual authentication Successful user authentication On RESET (Warm/Cold)Used in the Key Agreement together with System Authentication Ephemeral Private Key (H-eAUTH_sk) to generate shared secret H-Z e
H-HsmID Predefined System Identification dataN/AKDF A2912N/APre-defined valueN/APlaintext/static in persistent byte array owned by theOverwrite with all zeros value on:Used as FixedInfo data in Key Confirmation and UserToken

58/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 59
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorage FIPS Applet inside the ModuleZeroisation Personalization at Manufacturing by erasing all data in NVM Firmware Loading Process using APDU Command Delete Package and InstanceUse & related keys
H-HostID HOST Identification dataOTHER PARAMETERS (not considered as SSPs but included here for completeness)N/AKDF A2912N/AImported as part of mutual authenticate service’s incoming data I/O type: electronicN/APlaintext/dyna mic in transient byte array owned by the FIPS Applet inside the ModuleOverwrite with all zeros value on: On RESET (Warm/Cold)Used as FixedInfo data in Key Confirmation and UserToken
H-KT_3DES Key Token DES DES KeyTDES-64 TDES-128 TDES-192CKGGenerated internally using approved CKG (Direct Generation of Symmetric Key) in Generate Key serviceImported via Import Key service and Exported via Export Key service I/O type: electronicH-KT_3DES also can be generated from Diversify Key service using KDF Counter mode with approved MasterKey (H- KT_AES or H- KT_HMAC)Plaintext/dyna mic as a volatile data inside the System moduleKey token data will be zeroised when the user is blocked, System is blocked or terminated, and device reset (warm/cold). Also when the following services are executed:Needed by some product outside the cryptographic module for compatibility purpose.

59/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 60
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisation - System Reset - Manage session - Sync write tokenUse & related keys
OS-MKEK Key Encryption Key AES Key (Not a SSP but list here for completeness)AES-128CKGGenerated using approved CKG (Direct Generation of Symmetric Key) function as described in SP800-90N/AN/APlaintext/static in persistent memory of the Module at manufacturing stageKey is erased upon Card Manager lifecycle switched to TERMINATED (Overwrite with all zeros)Master Key used to encrypt (obf uscate) storage of CSPs

Table 16 SSPs 60/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 61
Entropy sourcesMinimum number of bits of entropyDetails
Hardware-TRNGMinimum entropy of 2.800831 bits per byteThe Entropy Source is a hardware module inside the CM boundary. The Entropy Source supplies the DRBG with more than 92 bytes Since the entropy source provides a min entropy output of at least 2.800831 bits of min entropy per byte, this is sufficient to obtain 256 bits of security strength
9.2 SSPs Access

SSPs are securely stored in the Cryptographic Module, a secure element hardware that is considered as secure enclave. The SSPs stored in the module is associated and accessible only via approved services as you can see in this section. The approved services itself are associated and accessible to some specific roles as described in the table section 4.3.1.

9.3 Random Bit Generator (RBG)

The RBG source within this module is from entropy source with tittle “ENT (P)” in the Table Approved Algorithm. Table 17 Non-Deterministic Random Number Generation Specification described below:

  1. Generate random number for initial Nonce for key protection by CCMK during FIPS Applet Installation
  2. Generate key for CCMK in “CCMK Export 1” service
  3. Generate random numbers for Split procedure in “CCMK export” services and “Generate Key (for Split Knowledge)” service
  4. Generate key for Customer key in “Generate Key (for Split Knowledge)” service
  5. Generate key for Symmetric Key in “Generate Key” Service
  6. Generate key for Asymmetric Key (RSA and EC Key pair) in “Generate Key Pair” Service
  7. Ephemeral EC Key Generation during Key Agreement in the Mutual Authentication service
  8. Utilized in Cipher process of RSA PKCS and PSS
  9. Utilized in Signature Generation process using ECDSA
  10. Utilized to generate card challenge in GP Initialize Update command
  11. Utilized in GP Put Key Command
  12. Utilized in the creation of OS-MKEK The approved services that uses DRBG are listed in the section 4.3.2 with link to “DRBG”.
9.4 SSP Zeroization

For all SSP, an implicit indicator that the zeroization is completed is provided. This indicator is the successful completion of the requested service for SSP zeroized through a dedicated command (the command is indicated in column “zeroization” of Table 16 SSPs) or Answer-to-RESET (ATR) in case of module reset. For SSP that are automatically zeroized (e.g H-Zs and H-Ze), the implicit indicator is the completion of the command mentioned in Table 16 SSPs with a correct status or an error status. 61/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.1

Page 62
Test TargetDescription
NVM IntegrityCRC-16 performed over all executable (JavaCard packages) in NVM
ROM Code IntegrityCRC-16 performed over all ROM code
Test TargetDescription
CRC-16Computes CRC-16 from a fixed message and checks the result (a critical function test)
TRNGPerforms Hardware True Random Number Generator tests
DRBGPerforms a fixed input KAT of CTR_DRBG instantiate and generate functions
Algorith m or TestTest PropertiesTest methodTypeIndicatorDetailsCondition sCoverag eCoverag e NotesPeriodPeriodic Method
CRC-16CRC-16 bitKATCASTPass: Next test Fail: Module inCRCPower On--2.097.15 1On Deman d & Auto
10 SELF-TESTS

The module has several self-tests that are triggered at pre-operational (manufacturing stage, power on, or prior to its first use), on demand, conditionally, and periodically. If any self-test fails other than the pairwise consistency, manual entry test, and firmware load test in the conditional self-test, the module will enter in the Kill Card state and emit an error code that identifies the type of test that failed. No further communication with the module is possible until the module is reset (Power-On). If it happens several times and reaches the error limit, the module will be terminated.

10.1 Pre-Operational Self-Tests

This section describes pre-operational self-test executed at startup (power on).

10.1.1 Pre-Operational Software/Firmware Integrity Test

The software/firmware integrity is verified using a 16-bit EDC, referred to as CRC-16 hereafter. Table 18 Integrity Self-Test Target

10.1.2 Pre-Operational Critical Functions Test

This critical function self-test is performed in every power on before executing integrity self-test. Table 19 Critical Function Self-test

10.2 Conditional Self-Tests

The module will automatically trigger specific self-test in some conditions. There are several types of conditional self-tests that are employed by the module described in the following section.

10.2.1 Conditional Cryptographic Algorithm Test

The module employs Known Answer Test (KAT) to perform Cryptographic Algorithm Self-test. For performance concern, not all algorithm are executed in the startup (power on) but prior to its first use. 62/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 63
Algorith m or TestTest PropertiesTest methodTypeIndicator KillCar d StateDetailsCondition sCoverag eCoverag e NotesPeriodPeriodic Method
AES- CBCAES, 128- bit,Covered by CAST on KDF- CMACCASTPass: Next test Fail: Module in KillCar d StateEncryptPower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
AES- CBCAES, 128- bit,Covered by CAST on AES ECBCASTPass: Next test Fail: Module in KillCar d StateDecryptPower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
AES- ECBAES, 128- bit, ECBCovered by CAST on KDF- CMACCASTPass: Next test Fail: Module in KillCar d StateEncryptPower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
AES- ECBAES, 128- bit, ECBKATCASTPass: Next test Fail: Module in KillCar d StateDecryptPower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
DRBGCTR_DRB G AES 256KATCASTPass: Next test Fail: Module in KillCar d StateGeneratePower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
DRBGCTR_DRB G AES 256KATCASTPass: Next test Fail: Module in KillCar d StateInstantiatePower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
DRBGCTR_DRB G AES 256KATCASTPass: Next test Fail: Module in KillCar d StateReseedPower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
HMACHMAC SHA- 1, 128-bitKATCASTPass: Next test Fail: Module in KillCar d StateGeneratePower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
1 d&
1 d&
1 d&
1 d&
1 d&
1 d&
1 d&

63/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 64
Algorith m or TestTest PropertiesTest methodTypeIndicatorDetailsCondition sCoverag eCoverag e NotesPeriodPeriodic Method
SHA2- 224Covered by CAST on SHA2- 256 – bitCASTPass: Next test Fail: Module in KillCar d StateGeneratePower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
SHA2- 256SHA2-256 – bitKATCASTPass: Next test Fail: Module in KillCar d StateGeneratePower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
SHA2- 384Covered by CAST on SHA2- 512 – bitCASTPass: Next test Fail: Module in KillCar d StateGeneratePower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
SHA2- 512SHA2-512- bitKATCASTPass: Next test Fail: Module in KillCar d StateGeneratePower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
SHA-3SHA3-512- bitKATCASTPass: Next test Fail: Module in KillCar d StateGeneratePower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
KDFKDF, AES CMAC 128 -bitKATCASTPass: Next test Fail: Module in KillCar d StateGeneratePower OnCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
ECDSAP-224 curveKATCASTPass: Next test Fail: Module in KillCar d Statesignature generation ,First UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
ECDSAP-224 curveKATCASTPass: Next test Fail: Module in KillCar d StateSignature verificationFirst UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
RSA PSS2048-bit RSA-STD PSS with SHA2-256KATCASTPass: Next testsignature generation STDFirst UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
1 d&
1 d&
1 d&
1 d&

64/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 65
Algorith m or TestTest PropertiesTest methodTypeIndicator Fail: Module in KillCar d StateDetailsCondition sCoverag eCoverag e NotesPeriodPeriodic Method
RSA PSS2048-bit RSA-CRT PSS with SHA2-256KATCASTPass: Next test Fail: Module in KillCar d Statesignature generation CRTFirst UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
RSA PSS2048-bit RSA PSS with SHA2- 256KATCASTPass: Next test Fail: Module in KillCar d StateSignature verificationFirst UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
RSA PKCS 1 V1.52048-bit RSA-STD PSS with SHA2-256Covered by CAST on RSA- PSSCASTPass: Next test Fail: Module in KillCar d Statesignature generation STDFirst UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
RSA PKCS 1 V1.52048-bit RSA-CRT PSS with SHA2-256Covered by CAST on RSA- PSSCASTPass: Next test Fail: Module in KillCar d Statesignature generation CRTFirst UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
RSA PKCS 1 V1.52048-bit RSA-PSS with SHA2- 256Covered by CAST on RSA-PSSCASTPass: Next test Fail: Module in KillCar d stateSignature verificationFirst UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
KAS- ECCKDFCovered by CAST on ECDSA, KDF and AES CMAC 128 -bitCASTPass: Next test Fail: Module in KillCar d stateGenerateFirst UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
KTSAES-CBC & AES CMAC 128 -bitCovered by- CAST on AES- CBC and AES- CMAC.CASTPass: Next test Fail: Module in KillCar d state-First UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto
AES CMACAES CMAC 128 -bitCovered by CAST on KDFCASTPass: Next test Fail: Module inEncryption (Verify uses encryption )First UseCert #A2912IG 10.3.A2.097.15 1On Deman d & Auto

) 65/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 66

Algorith m or Test

Test Properties

Test method

Type

Indicator KillCar d state

Details

Condition s

Coverag e

Coverag e Notes

Period

Periodic Method

NameDescriptionConditionsRecovery MethodIndicator
KillCard State (Low-level Error State)A state that indicates the module is in security state. Module at this state can no longer communicate till a power reset (cold or warm) is performedPre-Operational Self- Tests Failure Conditional Cryptographic Algorithm Test FailurePower cycleMuted Device

Table 20 CM Conditional CAST

10.2.2 Conditional Software/Firmware Load Test

The module relies on DAP Verification specified in [GPC_Specification_v2.3] section 9.2.1. The employed DAP Verification for Load Test is using AES-CMAC as approved data authentication technique to verify the validity of the firmware that is loaded. The AES Key with 128 bits key length (DAP-AES) is loaded at manufacturing stage used as authentication key to calculate the MAC of the loaded firmware.

10.2.3 Conditional Pair-Wise Consistency Test

When the module generating RSA and ECC Key Pair via ‘Generate Key Pair’ service, the module performs pairwise consistency test using sign and verify of known value technique. If pairwise consistency test is failed the module returns error code value ‘D6’ indicating error in Generate Key Service with reason pair-wise consistency self-test is failed. On five consecutive errors, the module will enter blocked state. An exit procedure from this state is described in [FQR 401 9097 Ed 4] section 7.3.

10.2.4 Conditional Manual Entry Test

The module performs manual entry self-test on some services such as “CCMK Import” services done by each key custodian to enter each secret of CCMK and “CK Import” services done by each customer key custodian enter secrets of customer key. Those operators enter KCV along with its secret. The module performs manual entry self-test by comparing entered KCV and calculated KCV of given secret. If the entered KCV does not match with calculated KCV, the manual entry test is failed with error code ‘D7’. On five consecutive errors, the module enters blocked state. An exit procedure from this state is described in [FQR 401 9097 Ed 4] section 7.3. The module provides a periodic self-test that is executed in every certain number of FIPS Applet service execution. This number is configured on FIPS Applet installation with 2,097,151 as default value. This periodic self-test executes the self-test described in the section 10.1. Data output is inhibited during self-test execution. Only power reset, Hard-fault, procedure NULL (‘60’) byte in ISO7816 interface, and check alive command in SPI can interrupt the process. If it’s interrupted by the Hard-fault, the module enters error state of the hardware and requires power reset to exit from this state.

10.4 Operator Initiation of Self-Tests

The module permits operators to initiate the pre-operational self-tests on demand by power cycling the module.

10.5 Error States

66/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 67

Periodic Self-Test Failure

11 LIFE-CYCLE ASSURANCE
11.1 Installation, Initialization and Startup Procedure

The module is delivered as single chip to the customer where its life cycle state is in SYSTEM INITIALIAZATION state. The customer shall follow below procedures for secure installation, initialization, startup and operation of the module:

  1. The installation procedure of the module that supports two physical interface ISO7816 T0 protocol and SPI Protocol are described as follow: a. Each ISO7816 physical port defined in section 3.1.1 must be installed correctly by connecting each ISO port (VCC, GND, RST, CLK, IO) of the module to the corresponding ISO Reader’s port or terminal’s port. Electrical characteristics in each connected port, signal sequence in activation and deactivation, and transmission protocol shall follow [ISO/IEC 7816-3]. b. Each SPI physical port defined in section 3.1.2 must be installed correctly by connecting each SPI port (VCC, GND, RST, SPI_CLK, SPI_MISO, SPI_MOSI, SPI_CS) of the module to the corresponding SPI Reader’s port or SPI master device’s port. Electrical characteristics in each connected port and its transmission protocol shall follow chip manufacturer datasheet.
  2. All module components specified in section 2.1.2 are already installed in the manufacturing. The configuration is set to FIPS Certified Product (FCP).
  3. In the SYSTEM INITIALIZATION state: a. Super User shall create new credential and replace its default credential in the module. b. Then, Super User shall create new Administrator role in the module. When this procedure is successfully done, the module state is automatically changed to KEY CEREMONY state.
  4. In the KEY CEREMONY state: a. Administrator shall create new roles for Auditor and three Key Custodians role. b. Then, Administrator shall initiate KEY CEREMONY session together with three Key Custodians to import or export CCMK of the module using split knowledge procedure. c. After that Administrator shall confirm either to keep the configuration still in FIPS Certified Product (FCP) or not. Please note that if Administrator is answering no, then the module will loose its FIPS Certified status. Customer cannot revert to FIPS Certified status unless the module is returned at IDEMIA to be erased and personalized with new SSPs. It is recommended for customer to perform System Reset before returning the module to the IDEMIA. When this procedure is successfully done, the module state is automatically changed to System USER (operational) state.
  5. When the module is in operational state and configured as FIPS Certified Product (FCP): a. Only approved mode of operation is available for users. In this mode of operation, only approved services in section 4.3.2 is available for users. b. Only applet that is already validated under [NIST.FIPS.140-3] evaluation shall be loaded and installed in the module. Otherwise, the module will loose its FIPS certified status. This is not 67/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2
Page 68

automatically enforced by the module but must be obeyed by following procedure defined in [FQR 401 9097 Ed 4] section 3.4.2.

  1. The module does not support maintenance role.
  2. The Administrator shall update current date of the module. It is strongly recommended to update the current date of the module on daily basis.
  3. Detailed information about module life cycle state and procedures for initialization and operation of the module at customer side, and the procedure to keep the module still in FIPS are described in document [FQR 401 9097 Ed 4] for Crypto Officer Role and [FQR 401 9098 Ed 3] for User Role.
11.1.1 Components Version Number Retrieval Procedures

Hardware version can be retrieved with the following steps:

Page 69
11.2 Secure Sanitization and Destruction Procedure

Sanitization can be done by performing HSM Reset that is authorized by SUPER_USER and HSM Administrator credentials authenticated in Admin Session. HSM Reset service will perform zeroization that is created at customer side and set back module to Factory State like when the customer receives the module for the first time. For secure destruction procedure, it is recommended for customers to follow below step:

  1. Under role ‘’AA” (Application Administrator) to set card manager state to TERMINATED.
  2. Once, it is terminated, OS-MKEK that is used to encrypt all keys stored in the module is zeroised.
  3. Once OS-MKEK is zeroised, all keys stored in the module cannot be retrieved in plaintext form. Event encrypted form, it is difficult to those keys which are stored inside the flash on single chip component which are protected with hard tamper-evident coating on the chip.
12 MITIGATION OF OTHER ATTACKS

The Module implements defenses against:

Page 70
ReferenceDetail Reference
[NIST.FIPS.140-3]Security Requirements for Cryptographic Modules
[NIST.FIPS.180-4]Secure Hash Standard (SHS)
[NIST.FIPS.186-4]Digital Signature Standard (DSS)
[NIST.FIPS.197]Advanced Encryption Standard (AES)
[NIST.FIPS.198-1]The Keyed-Hash Message Authentication Code (HMAC)
[NIST.FIPS.202]SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions
[NIST.SP.800-38A]Recommendation for Block Cipher Modes of Operation: Methods and Techniques
[NIST.SP.800-38B]Recommendation for Block Cipher Modes of Operation: the CMAC Mode for Authentication
[NIST.SP.800-38F]Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping
[NIST.SP.800-56A.Rev3]Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography
[NIST.SP.800-56B.Rev2]Recommendation for Pair-Wise Key-Establishment Using Integer Factorization Cryptography
[NIST.SP.800-56C.Rev2]Recommendation for Key-Derivation Methods in Key-Establishment Schemes
[NIST.SP.800-63b]Digital Identity Guidelines
[NIST.SP.800-67.Rev2]Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher
[NIST.SP.800-90A.Rev1]Recommendation for Random Number Generation Using Deterministic Random Bit Generators
[NIST.SP.800-90B]Recommendation for the Entropy Sources Used for Random Bit Generation
[NIST.SP.800-108]Recommendation for Key Derivation Using Pseudorandom Functions (Revised)
[NIST.SP.800-131A.Rev2]Transitioning the Use of Cryptographic Algorithms and Key Lengths
[NIST.SP.800-133.Rev2]Recommendation for Cryptographic Key Generation
[NIST.SP.800-140A]CMVP Documentation Requirements: CMVP Validation Authority Updates to ISO/IEC 24759
[NIST.SP.800-140B]CMVP Security Policy Requirements
[NIST.SP.800-140E]CMVP Approved Authentication Mechanisms
ReferenceDetail Reference
[ISO/IEC 7816-3]“Identification cards - Integrated circuit cards - Part 3: Cards with contacts - Electrical signal and transmission protocols”. - 2006-11-01 - Third edition

70/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 71
REFERENCE NUMBER: ISO/IEC 7816-3:2006(E)
[ISO/IEC 7816-4]“Identification cards - Integrated circuit cards - Part 4: Organization, security and commands for interchange." - 2013-04-15 - Third edition REFERENCE NUMBER: ISO/IEC 7816-4:2013(E)
[ISO/IEC 19790]Information technology — Security techniques — Security requirements for cryptographic modules
[ISO/IEC 24759]Information technology — Security techniques — Test requirements for cryptographic modules
ReferenceDetail Reference
[GPC_Specification_v2.3]GlobalPlatform Card Specification Version 2.3.1 Public Release – March 2018 Document Reference: GPC_SPE_034
[GPC_CIC]GlobalPlatform Card - Common Implementation Configuration Version 2.1 Member Release – July 2018 Document Reference: GPC_GUI_080
[GPC_AMD_D]GlobalPlatform Card Technology - Secure Channel Protocol '03', Card Specification v2.2 – Amendment D Version 1.1.1 - Public Release July 2014 Document Reference: GPC_SPE_014
ReferenceDetail Reference
[FQR 401 9097 Ed 4]FQR 401 9097 Ed 4 - Rooky Crypto Officer Guidance
[FQR 401 9098 Ed 3]FQR 401 9098 Ed 3 - Rooky User Guidance
[FQR 401 9187 Ed 2]FQR 401 9187 Ed 2 - Rooky Delivery, Installation, and Destruction Guidance
[FQR 110 A0A1 Ed 1]FQR 110 A0A1 Ed 1 - SPI Application Note for ROOKY

A.3 Global Platform References A.4 FIPS Applet on RookySE References 71/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 72
AcronymDefinition
FIPSFederal Information Processing Standard
LKDLocal Key Database
LKD_DPLocal Key Database Data Preparation
KCVKey Check Value
CCMKCrypto Card Master Key
DGIData Grouping Identifier
APDUApplication Protocol Data Unit
SESecure Element
SPISerial Peripheral Interface
GPGlobal Platform
RAMRandom Access Memory
AdminAppAdmin Application
EncEncipher
DecDecipher
SigSignature
VerVerify
JCVMJava Card Virtual Machine

APPENDIX 2. ACRONYMS AND DEFINITIONS 72/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2

Page 73
DateChange
1.2- Update table 3 for CKG and KDF to update description/key size - Update table 16 to add CKG in some key and its used - Update table conditional self-test - Add new table for error states - Add new section 11.2 Secure Sanitization and Destruction Procedure
1.1Renaming some tables according SP800-140B; typographic errors corrections. Change applet version.
1.0Initial version
13 DOCUMENT REVISIONS

73/73 FIPS Applet on RookySE FIPS 140-3 Non-Proprietary Security Revision Date: 30/09/2024 Policy V1.2