| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Firmware |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 11/14/2026 |
| Caveat | Interim validation |
| Vendor | Broadcom Inc. |
flowchart LR
%% Deterministic review-risk graph for VMware’s VPN Crypto Module
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>self-test<br/>Show Status</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
end
subgraph Inference["Derived inference"]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C3,C5,C6 clue;
class I3,I5,I6 infer;
class R3,R5,R6 risk;
class E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for VMware’s VPN Crypto Module
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>self-test<br/>Show Status</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C3,C5,C6 clueLow;VMware’s VPN Crypto Module Firmware version: 21.11 Document version: 2.3
VMware’s VPN Crypto Module Security Policy Document Contents Security Levels 4 Overall security design and the rules of operation 7 Pre-Operational Self-Tests 12 Conditional Cryptographic Algorithm Tests 12 Distribution and Installation 13 Configuration 13 Initialization and Setup 13 Verification of the Module 13 Crypto Officer Guidance 13 Destruction and Zeroization 14 © 2024 Broadcom Inc.
VMware’s VPN Crypto Module Security Policy Document List of tables List of figures © 2024 Broadcom Inc.
| ISO/IEC 24759 Section 6 | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic Module Specification | 1 |
| 3 | Cryptographic Module Interfaces | 1 |
| 4 | Roles, Services, and Authentication | 1 |
| 5 | Software/Firmware Security | 1 |
| 6 | Operational Environment | 1 |
| 7 | Physical Security | 1 |
| 8 | Non-invasive Security | N/A |
| 9 | Sensitive Security Parameters | 1 |
VMware’s VPN Crypto Module Security Policy Document This is a non-proprietary Cryptographic Module Security Policy for VMware's VPN Cryptographic Module from Broadcom Inc. This Security Policy describes how VMware's VPN Cryptographic Module meets the security requirements of Federal Information Processing Standards (FIPS) Publication 140-3, which details the U.S. and Canadian Government requirements for cryptographic modules. More information about the FIPS 140-3 standard and validation program is available on the National Institute of Standards and Technology (NIST) and the Canadian Centre for Cyber Security (CCCS), a branch of the Communications Security Establishment (CSE), Cryptographic Module Validation Program (CMVP) website at https://csrc.nist.gov/projects/cryptographic-module-validation-program. This document has been written for the following audiences:
| 10 | Self-Tests | 1 | |
|---|---|---|---|
| 11 | Life-Cycle Assurance | 1 | |
| 12 | Mitigation of Other Attacks | N/A | |
| Overall Module validation level | 1 |
| # | Operating System | Hardware Platform | Processor | PAA/Acceleration | ||||
|---|---|---|---|---|---|---|---|---|
| 1 | Ubuntu 20.04 running on ESXi 8.0 | Dell PowerEdge R650 | Intel(R) Xeon(R) Gold 6330 | Yes | ||||
| 2 | Ubuntu 20.04 running on ESXi 8.0 | Dell PowerEdge R650 | Intel(R) Xeon(R) Gold 6330 | No |
| CAVP Cert | Algorithm and Standard | Mode/Method | Description/Key Size/Strengths | Use / Function |
|---|---|---|---|---|
| A4384 | AES (FIPS PUB 197) | CBC | Key Size: 128, 192, 256 bits | Symmetric key operation |
| A4384 | AES (SP800-38B) | CMAC | Key Size: 128 bits | Symmetric key operation |
| A4384 | AES (SP800-38C) | CCM | Key Size: 128 bits | Symmetric key operation |
| A4384 | AES (SP800-38D) | GCM, GMAC | Key Size: 128,192,256 bits | Symmetric key operation |
| A4385 | HMAC (FIPS PUB 198-1) | SHA2-256 | Strength:256 bits | Integrity test |
VMware’s VPN Crypto Module Security Policy Document
| A4384 | HMAC (FIPS PUB 198-1) | HMAC-SHA-1, HMAC-SHA2- 224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC- SHA2-512 | Strength:128 to 256 bits | Authentication, Integrity checks | |||||
|---|---|---|---|---|---|---|---|---|---|
| A4384 | SHS (FIPS 180-4) | SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 | N/A | Hashing | |||||
| A4385 | SHS (FIPS 180-4) | SHA2-256 | N/A | Hashing |
VMware’s VPN Crypto Module Security Policy Document The module does not use any allowed or non-approved algorithms and operates only in the Approved mode of operation. Figure 1 – Cryptographic boundary and physical perimeter Calling Application FIPS API Interface Librte_cryptodev.so.22.0 Librte_crypto_post.so.22.0 Librte_crypto_ipsec_mb.so.22.0 LibIPsec_mb.so.1.3.0 User Space Kernel Space Ubuntu OS VMware ESXi Hardware (GRPC) Cryptographic Boundary FIPS Interface calls Internal API calls Physical Perimeter © 2024 Broadcom Inc.
| Physical Port | Logical Interface | Data that Passes over port/interface |
|---|---|---|
| Host computer Network Port, USB port, serial port | Data Input | The module accepts data input through the input arguments of the API functions. |
| Host computer Network Port, USB | Data Output | The module produces data output through the |
| port, serial port | parameters of the API functions. | |
| Host computer Network Port, USB port, serial port, Power button | Control Input | The module accepts control input through the input arguments of the API functions used to control the module. |
| Host computer Network Port, USB port, serial port, LED status light | Status Output | The module produces status output through the return values for function calls and error messages. |
| Host computer Power Port | Power interface | N/A |
| Role | Services | Input | Output | |
|---|---|---|---|---|
| Crypto Officer | Initialization of the module | None | None | |
| Crypto Officer | Run self-tests | The self-tests may be run on demand by rebooting the OS or cycling host power. | Results of each self-test |
VMware’s VPN Crypto Module Security Policy Document Overall security design and the rules of operation When the operating system boots, the module is initialized by calling librte_crypto_post, which runs the firmware integrity test and the KATs. Once librte_crypto_post finishes the POST tests the module is loaded as a device driver in the operating system. Calling applications can access the application once it is loaded as a device driver.
| Crypto Officer | Show version | API command | The module version will be output to the log (“DPDK v21.11.2") | |
|---|---|---|---|---|
| Crypto Officer | Encryption | Key and plaintext input via API | Encrypted data | |
| Crypto Officer | Decryption | Key and ciphertext input via API | Plaintext data | |
| Crypto Officer | Hashing | Data input via API | Hash of the input data | |
| Crypto Officer | Message Authentication Code (MAC) Generation | Key input via API Data input via API | MAC of the input data | |
| Crypto Officer | Zeroize | None | None | |
| Crypto Officer | Show Status | None | Success: “Finished Self-test successfully” Error State: “Failed dpdk_init” |
| Service | Description | Approved Security Functions | Keys / SSPs | Access Rights and Keys/SSPs | Indicator | ||
|---|---|---|---|---|---|---|---|
| Initialization of the module | Initialization of the module | - | - | N/A | The module is running |
VMware’s VPN Crypto Module Security Policy Document The module is a Level 1 firmware module and does not implement any authentication. The calling application implicitly assumes the Crypto Officer role when accessing the module. G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroizes the SSP. Table 6 – Approved Services for Crypto Officer © 2024 Broadcom Inc.
| Run self-tests | The self-tests may be run on demand by rebooting the OS or cycling host power. | - | - | - | The self-test results are output in the log | |
|---|---|---|---|---|---|---|
| Show version | Show the module name and version | - | - | - | The module name and version are output in the log | |
| Show Status | Show the module is either operational or in an error state | - | - | - | In log messages: Success: “Finished Self-test successfully” Error State: “Failed dpdk_init” | |
| Zeroization | Zeroize unprotected SSPs and key components | - | All SSPs | All SSPs: Z | The module reboot and startup will be shown in the log. | |
| Encryption | Encrypt plaintext using supplied key and algorithm specification | AES modes: CBC, CCM, CMAC, GCM/GMAC | AES keys and IVs: 128-bit, 192-bit, 256-bit | All SSPs: WE | Return values indicate success. Null values or void pointers together with error logs indicate failures. | |
| Decryption | Decrypt ciphertext using supplied key and algorithm specification | AES modes: CBC, CCM, CMAC, GCM/GMAC | AES keys and IVs: 128-bit, 192-bit, 256-bit | All SSPs: WE | Return values indicate success. Null values or void pointers together with error logs indicate failures. |
VMware’s VPN Crypto Module Security Policy Document © 2024 Broadcom Inc.
| Hashing | Compute and return a message digest using SHA algorithm | SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2-512 | N/A | N/A | Return values indicate success. Null values or void pointers together with error logs indicate failures. |
|---|---|---|---|---|---|
| Message Authentication Code (MAC) Generation | Compute and return a hashed message authentication code | HMAC-SHA-1, HMAC-SHA2- 224, HMAC- SHA2-256, HMAC-SHA2- 384, HMAC- SHA2-512 | HMAC key, 128 to 256- bits | All SSPs: WE | Return values indicate success. Null values or void pointers together with error logs indicate failures. |
VMware’s VPN Crypto Module Security Policy Document There are no non-approved services for the Crypto Officer.
| SSPs | Mode and Strength | Generation | Import/ Export | Establishment | Storage | Zeroisation | Use and Related Keys |
|---|---|---|---|---|---|---|---|
| AES Key | 128, 192, 256-bit keys | N/A, the key is imported. | Imported only. The key is not exported from the module. | N/A | Random Access Memory (RAM) in plaintext | Reboot OS; Cycle host power | Encryption, Decryption |
| AES GCM/GMAC Key | 128, 192, 256-bit keys | N/A, the key is imported. | Imported only. The key is not exported from the module. | N/A | Random Access Memory (RAM) in plaintext | Reboot OS; Cycle host power | Encryption, Decryption |
| AES GCM/GMAC IV | 96-bit IV | N/A, the key is imported. | Imported only. The key is not exported from the module. | N/A | Random Access Memory (RAM) in plaintext | Reboot OS; Cycle host power | Encryption, Decryption |
| AES CCM Key | 128-bit key | N/A, the key is imported. | Imported only. The key is not exported from the module. | N/A | Random Access Memory (RAM) in plaintext | Reboot OS; Cycle host power | Encryption, Decryption |
VMware’s VPN Crypto Module Security Policy Document
| AES CMAC key | 128-bit key | N/A, the key is imported. | Imported only. The key is not exported from the module. | N/A | Random Access Memory (RAM) in plaintext | Reboot OS; Cycle host power | Authenticat ion |
|---|---|---|---|---|---|---|---|
| HMAC Key | 128-256 bits | N/A, the key is imported. | Imported only. The key is not exported from the module. | N/A | RAM in plaintext | Reboot OS; Cycle host power | Message Authenticat ion |
| Firmware Integrity Key – HMAC key (not an SSP) | 256-bit key | N/A | Does not enter or exit the module | N/A | Hardcoded in the module | No zeroization | Verifies integrity of the module upon initializatio n |
VMware’s VPN Crypto Module Security Policy Document n Symmetric keys are provided to the module by the calling process and are destroyed when released by the appropriate API function calls. The module does not perform persistent storage of keys. 10. Self-tests The self-tests are run automatically when the module powers on. The module does not allow any data output before the self-tests are completed successfully. If a KAT encryption or decryption result does not match the known answer, the test will fail. If the firmware Integrity test produces a result which does not match the Integrity MAC value, the test will fail. If a self-test fails, the module will enter an error state and the name of the failing self-test will be shown in the log. While in an error state, the module cannot perform cryptographic operations. To clear an error state, The self-tests may be run on demand by rebooting the OS or cycling host power. Pre-Operational Self-Tests Conditional Cryptographic Algorithm Tests • AES CBC Encryption KAT (128, 192, and 256-bit) © 2024 Broadcom Inc.
VMware’s VPN Crypto Module Security Policy Document
VMware’s VPN Crypto Module Security Policy Document Destruction and Zeroization The module will remain installed for the lifetime of the operating system. When the operating system is removed, the module will be erased. Any SSPs in the module will be erased at that time. 12. Mitigation of other attacks The module does not implement mitigation of other attacks. © 2024 Broadcom Inc.
| AES | Advanced Encryption Standard |
|---|---|
| API | Application Program Interface |
| CAST | Cryptographic Algorithm Self-Test |
| CBC | Cipher Block Chaining |
| CFB | Cipher Feedback |
| CO | Crypto-Officer |
| CSP | Critical Security Parameter |
| CTR | Counter |
| CVL | Component Validation List |
| DRBG | Deterministic Random Bit Generation |
| FIPS | Federal Information Processing Standard |
| HMAC | (Keyed-)Hash Messages Authentication Code |
| KAT | Known Answer Test |
| MAC | Message Authentication Code |
| NIST | National Institute of Standards and Technology |
| OE | Operational Environment |
| OS | Operation System |
| POST | Power-On Self-Test |
| SHA | Secure hash Standard |
| SSP | Sensitive Security Parameter |
| SP | Special Publication |
VMware’s VPN Crypto Module Security Policy Document Acronyms Table 8 - Acronyms © 2024 Broadcom Inc.
VMware’s VPN Crypto Module Security Policy Document © 2024 Broadcom Inc.