All modules
CMVP Validated Module · FIPS 140-3 Security Policy

VMware’s VPN Crypto Module

Certificate#4881StandardFIPS 140-3Level1TypeFirmwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorBroadcom Inc.
High review priority  ·  no TCB surface named  ·  last validated 20 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeFirmware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date11/14/2026
CaveatInterim validation
VendorBroadcom Inc.

Approved Algorithms (17)

AlgorithmACVP Cert
AES-CBCA4384
AES-CCMA4384
AES-CMACA4384
AES-GCMA4384
AES-GMACA4384
HMAC-SHA-1A4384
HMAC-SHA2-224A4384
HMAC-SHA2-256A4384
HMAC-SHA2-256A4385
HMAC-SHA2-384A4384
HMAC-SHA2-512A4384
SHA-1A4384
SHA2-224A4384
SHA2-256A4384
SHA2-256A4385
SHA2-384A4384
SHA2-512A4384

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for VMware’s VPN Crypto Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>self-test<br/>Show Status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C3,C5,C6 clue;
  class I3,I5,I6 infer;
  class R3,R5,R6 risk;
  class E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for VMware’s VPN Crypto Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>self-test<br/>Show Status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

VMware’s VPN Crypto Module Firmware version: 21.11 Document version: 2.3

Page 2
Table, extracted as text (did not parse into structured rows)
VMware’s VPN Crypto Module                                                                                                                                            Security Policy Document Contents Security Levels                                                                                                                                                                                                          4 Overall security design and the rules of operation                                                                                                                                                                       7 Pre-Operational Self-Tests                                                                                                                                                                                             12 Conditional Cryptographic Algorithm Tests                                                                                                                                                                              12 Distribution and Installation                                                                                                                                                                                          13 Configuration                                                                                                                                                                                                          13 Initialization and Setup                                                                                                                                                                                               13 Verification of the Module                                                                                                                                                                                             13 Crypto Officer Guidance                                                                                                                                                                                                13 Destruction and Zeroization                                                                                                                                                                                            14 © 2024 Broadcom Inc.
Page 3

VMware’s VPN Crypto Module Security Policy Document List of tables List of figures © 2024 Broadcom Inc.

Page 4
ISO/IEC 24759 Section 6FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical Security1
8Non-invasive SecurityN/A
9Sensitive Security Parameters1

VMware’s VPN Crypto Module Security Policy Document This is a non-proprietary Cryptographic Module Security Policy for VMware's VPN Cryptographic Module from Broadcom Inc. This Security Policy describes how VMware's VPN Cryptographic Module meets the security requirements of Federal Information Processing Standards (FIPS) Publication 140-3, which details the U.S. and Canadian Government requirements for cryptographic modules. More information about the FIPS 140-3 standard and validation program is available on the National Institute of Standards and Technology (NIST) and the Canadian Centre for Cyber Security (CCCS), a branch of the Communications Security Establishment (CSE), Cryptographic Module Validation Program (CMVP) website at https://csrc.nist.gov/projects/cryptographic-module-validation-program. This document has been written for the following audiences:

Page 5
10Self-Tests1
11Life-Cycle Assurance1
12Mitigation of Other AttacksN/A
Overall Module validation level1
#Operating SystemHardware PlatformProcessorPAA/Acceleration
1Ubuntu 20.04 running on ESXi 8.0Dell PowerEdge R650Intel(R) Xeon(R) Gold 6330Yes
2Ubuntu 20.04 running on ESXi 8.0Dell PowerEdge R650Intel(R) Xeon(R) Gold 6330No
CAVP CertAlgorithm and StandardMode/MethodDescription/Key Size/StrengthsUse / Function
A4384AES (FIPS PUB 197)CBCKey Size: 128, 192, 256 bitsSymmetric key operation
A4384AES (SP800-38B)CMACKey Size: 128 bitsSymmetric key operation
A4384AES (SP800-38C)CCMKey Size: 128 bitsSymmetric key operation
A4384AES (SP800-38D)GCM, GMACKey Size: 128,192,256 bitsSymmetric key operation
A4385HMAC (FIPS PUB 198-1)SHA2-256Strength:256 bitsIntegrity test

VMware’s VPN Crypto Module Security Policy Document

  1. Cryptographic Module Specification VMware's VPN Crypto Module is a firmware cryptographic module whose purpose is to provide FIPS 140-3 validated cryptographic functions to various applications utilizing VPN capabilities. The module was tested and found to be compliant with FIPS 140-3 security level 1 requirements on the operational environments (OE) listed in Table
  2. Table 2 - Tested Operational Environments Validation certificates for each Approved security function are listed in Table
  3. Table 3 - Approved Algorithms © 2024 Broadcom Inc.
Page 6
A4384HMAC (FIPS PUB 198-1)HMAC-SHA-1, HMAC-SHA2- 224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC- SHA2-512Strength:128 to 256 bitsAuthentication, Integrity checks
A4384SHS (FIPS 180-4)SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512N/AHashing
A4385SHS (FIPS 180-4)SHA2-256N/AHashing

VMware’s VPN Crypto Module Security Policy Document The module does not use any allowed or non-approved algorithms and operates only in the Approved mode of operation. Figure 1 – Cryptographic boundary and physical perimeter Calling Application FIPS API Interface Librte_cryptodev.so.22.0 Librte_crypto_post.so.22.0 Librte_crypto_ipsec_mb.so.22.0 LibIPsec_mb.so.1.3.0 User Space Kernel Space Ubuntu OS VMware ESXi Hardware (GRPC) Cryptographic Boundary FIPS Interface calls Internal API calls Physical Perimeter © 2024 Broadcom Inc.

Page 7
Physical PortLogical InterfaceData that Passes over port/interface
Host computer Network Port, USB port, serial portData InputThe module accepts data input through the input arguments of the API functions.
Host computer Network Port, USBData OutputThe module produces data output through the
port, serial portparameters of the API functions.
Host computer Network Port, USB port, serial port, Power buttonControl InputThe module accepts control input through the input arguments of the API functions used to control the module.
Host computer Network Port, USB port, serial port, LED status lightStatus OutputThe module produces status output through the return values for function calls and error messages.
Host computer Power PortPower interfaceN/A
RoleServicesInputOutput
Crypto OfficerInitialization of the moduleNoneNone
Crypto OfficerRun self-testsThe self-tests may be run on demand by rebooting the OS or cycling host power.Results of each self-test

VMware’s VPN Crypto Module Security Policy Document Overall security design and the rules of operation When the operating system boots, the module is initialized by calling librte_crypto_post, which runs the firmware integrity test and the KATs. Once librte_crypto_post finishes the POST tests the module is loaded as a device driver in the operating system. Calling applications can access the application once it is loaded as a device driver.

  1. Cryptographic Module Interfaces Table 4 - Ports and Interfaces
  2. Roles, Services, and Authentication Table 5 – Roles, Services and Command Input and Output © 2024 Broadcom Inc.
Page 8
Crypto OfficerShow versionAPI commandThe module version will be output to the log (“DPDK v21.11.2")
Crypto OfficerEncryptionKey and plaintext input via APIEncrypted data
Crypto OfficerDecryptionKey and ciphertext input via APIPlaintext data
Crypto OfficerHashingData input via APIHash of the input data
Crypto OfficerMessage Authentication Code (MAC) GenerationKey input via API Data input via APIMAC of the input data
Crypto OfficerZeroizeNoneNone
Crypto OfficerShow StatusNoneSuccess: “Finished Self-test successfully” Error State: “Failed dpdk_init”
ServiceDescriptionApproved Security FunctionsKeys / SSPsAccess Rights and Keys/SSPsIndicator
Initialization of the moduleInitialization of the module--N/AThe module is running

VMware’s VPN Crypto Module Security Policy Document The module is a Level 1 firmware module and does not implement any authentication. The calling application implicitly assumes the Crypto Officer role when accessing the module. G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroizes the SSP. Table 6 – Approved Services for Crypto Officer © 2024 Broadcom Inc.

Page 9
Run self-testsThe self-tests may be run on demand by rebooting the OS or cycling host power.---The self-test results are output in the log
Show versionShow the module name and version---The module name and version are output in the log
Show StatusShow the module is either operational or in an error state---In log messages: Success: “Finished Self-test successfully” Error State: “Failed dpdk_init”
ZeroizationZeroize unprotected SSPs and key components-All SSPsAll SSPs: ZThe module reboot and startup will be shown in the log.
EncryptionEncrypt plaintext using supplied key and algorithm specificationAES modes: CBC, CCM, CMAC, GCM/GMACAES keys and IVs: 128-bit, 192-bit, 256-bitAll SSPs: WEReturn values indicate success. Null values or void pointers together with error logs indicate failures.
DecryptionDecrypt ciphertext using supplied key and algorithm specificationAES modes: CBC, CCM, CMAC, GCM/GMACAES keys and IVs: 128-bit, 192-bit, 256-bitAll SSPs: WEReturn values indicate success. Null values or void pointers together with error logs indicate failures.

VMware’s VPN Crypto Module Security Policy Document © 2024 Broadcom Inc.

Page 10
HashingCompute and return a message digest using SHA algorithmSHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2-512N/AN/AReturn values indicate success. Null values or void pointers together with error logs indicate failures.
Message Authentication Code (MAC) GenerationCompute and return a hashed message authentication codeHMAC-SHA-1, HMAC-SHA2- 224, HMAC- SHA2-256, HMAC-SHA2- 384, HMAC- SHA2-512HMAC key, 128 to 256- bitsAll SSPs: WEReturn values indicate success. Null values or void pointers together with error logs indicate failures.

VMware’s VPN Crypto Module Security Policy Document There are no non-approved services for the Crypto Officer.

  1. Software/Firmware Security For the purposes of a FIPS 140-3 level 1 validation, the cryptographic module is a set of files, listed here: • librte_crypto_post.so.22.0 • librte_cryptodev.so.22.0 • libipsec_MB.so.1.3.0 • librte_crypto_ipsec_mb.so.22.0 The object code in the object module file is incorporated into the runtime executable application at the time the binary executable is generated. The module performs no communications other than with the consuming host application (the process that invokes the module services via the module’s API), which can be considered as the host for the module. The module runs a HMAC SHA2-256 integrity verification during initialization by the host application. The module also runs the self-test for HMAC SHA2-256 prior to running the integrity test. The temporary values generated during the integrity test of the module are zeroized upon the completion of the integrity test. The CO can reboot the OS or cycle host power to run the integrity test on demand.
  2. Operational Environment The operational environment is non-modifiable. The control plane Operating System (OS) is Linux, a multi-threaded operating system that supports memory protection between processes. Access to the underlying Linux implementation is not provided directly. © 2024 Broadcom Inc.
Page 11
SSPsMode and StrengthGenerationImport/ ExportEstablishmentStorageZeroisationUse and Related Keys
AES Key128, 192, 256-bit keysN/A, the key is imported.Imported only. The key is not exported from the module.N/ARandom Access Memory (RAM) in plaintextReboot OS; Cycle host powerEncryption, Decryption
AES GCM/GMAC Key128, 192, 256-bit keysN/A, the key is imported.Imported only. The key is not exported from the module.N/ARandom Access Memory (RAM) in plaintextReboot OS; Cycle host powerEncryption, Decryption
AES GCM/GMAC IV96-bit IVN/A, the key is imported.Imported only. The key is not exported from the module.N/ARandom Access Memory (RAM) in plaintextReboot OS; Cycle host powerEncryption, Decryption
AES CCM Key128-bit keyN/A, the key is imported.Imported only. The key is not exported from the module.N/ARandom Access Memory (RAM) in plaintextReboot OS; Cycle host powerEncryption, Decryption

VMware’s VPN Crypto Module Security Policy Document

  1. Physical Security The module is a firmware module with a multi-chip standalone cryptographic embodiment. The module's host platform provides production-grade components and chassis using standard passivation.
  2. Non-invasive Security The module does not implement any non-invasive security measures, so this section is not applicable.
  3. Sensitive Security Parameter Management Table 7 – Sensitive Security Parameters © 2024 Broadcom Inc.
Page 12
AES CMAC key128-bit keyN/A, the key is imported.Imported only. The key is not exported from the module.N/ARandom Access Memory (RAM) in plaintextReboot OS; Cycle host powerAuthenticat ion
HMAC Key128-256 bitsN/A, the key is imported.Imported only. The key is not exported from the module.N/ARAM in plaintextReboot OS; Cycle host powerMessage Authenticat ion
Firmware Integrity Key – HMAC key (not an SSP)256-bit keyN/ADoes not enter or exit the moduleN/AHardcoded in the moduleNo zeroizationVerifies integrity of the module upon initializatio n

VMware’s VPN Crypto Module Security Policy Document n Symmetric keys are provided to the module by the calling process and are destroyed when released by the appropriate API function calls. The module does not perform persistent storage of keys. 10. Self-tests The self-tests are run automatically when the module powers on. The module does not allow any data output before the self-tests are completed successfully. If a KAT encryption or decryption result does not match the known answer, the test will fail. If the firmware Integrity test produces a result which does not match the Integrity MAC value, the test will fail. If a self-test fails, the module will enter an error state and the name of the failing self-test will be shown in the log. While in an error state, the module cannot perform cryptographic operations. To clear an error state, The self-tests may be run on demand by rebooting the OS or cycling host power. Pre-Operational Self-Tests Conditional Cryptographic Algorithm Tests • AES CBC Encryption KAT (128, 192, and 256-bit) © 2024 Broadcom Inc.

Page 13

VMware’s VPN Crypto Module Security Policy Document

Page 14

VMware’s VPN Crypto Module Security Policy Document Destruction and Zeroization The module will remain installed for the lifetime of the operating system. When the operating system is removed, the module will be erased. Any SSPs in the module will be erased at that time. 12. Mitigation of other attacks The module does not implement mitigation of other attacks. © 2024 Broadcom Inc.

Page 15
AESAdvanced Encryption Standard
APIApplication Program Interface
CASTCryptographic Algorithm Self-Test
CBCCipher Block Chaining
CFBCipher Feedback
COCrypto-Officer
CSPCritical Security Parameter
CTRCounter
CVLComponent Validation List
DRBGDeterministic Random Bit Generation
FIPSFederal Information Processing Standard
HMAC(Keyed-)Hash Messages Authentication Code
KATKnown Answer Test
MACMessage Authentication Code
NISTNational Institute of Standards and Technology
OEOperational Environment
OSOperation System
POSTPower-On Self-Test
SHASecure hash Standard
SSPSensitive Security Parameter
SPSpecial Publication

VMware’s VPN Crypto Module Security Policy Document Acronyms Table 8 - Acronyms © 2024 Broadcom Inc.

Page 16

VMware’s VPN Crypto Module Security Policy Document © 2024 Broadcom Inc.