All modules
CMVP Validated Module · FIPS 140-3 Security Policy

AWS Key Management Service HSM

Certificate#4884StandardFIPS 140-3Level3TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorAmazon Web Services, Inc.
High review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 20 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date11/17/2026
CaveatInterim validation. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorAmazon Web Services, Inc.

Approved Algorithms (30)

AlgorithmACVP Cert
AES-CBCA1908
AES-CTRA1908
AES-ECBA1908
AES-GCMA1908
AES-KWPA1908
Conditioning Component AES-CBC-MAC SP800-90BA1791
Counter DRBGA1908
ECDSA KeyGen (FIPS186-4)A1908
ECDSA KeyVer (FIPS186-4)A1908
ECDSA SigGen (FIPS186-4)A1908
ECDSA SigGen (FIPS186-4)A1908
ECDSA SigVer (FIPS186-4)A1908
HMAC-SHA-1A1908
HMAC-SHA2-256A1908
HMAC-SHA2-384A1908
HMAC-SHA2-512A1908
KAS-ECC Sp800-56Ar3A1908
KAS-ECC Sp800-56Ar3A1908
KDA OneStep Sp800-56Cr1A1908
KDF SP800-108A1910
KTS-IFCA1908
RSA Decryption PrimitiveA1908
RSA KeyGen (FIPS186-4)A1908
RSA SigGen (FIPS186-4)A1908
RSA Signature PrimitiveA1908
RSA SigVer (FIPS186-4)A1908
SHA-1A1908
SHA2-256A1908
SHA2-384A1908
SHA2-512A1908

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for AWS Key Management Service HSM
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>status output<br/>self-test</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for AWS Key Management Service HSM
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>status output<br/>self-test</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

AWS Key Management Service HSM Hardware version 3.0, firmware version 1.8.104 Document Version 0.35 October 25, 2024

Page 2
Table of Contents
#SectionPage
Page 3
List of Tables
ItemPage
Table 1 – Security Levels4
Table 2 - Cryptographic Module Tested Configuration5
Table 3 –Approved Algorithms9
Table 4 – Non-Approved Algorithms Allowed in the Approved Mode of Operation9
Table 5 - Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed10
Table 6 – Ports and Interfaces12
Table 7 – Roles and Authentication13
Table 8 – Roles, Service Commands, Input and Output22
Table 9 – Approved Services42
Table 10 – Physical Security Inspection Guidelines46
Table 11 – EFP/EFT46
Table 12 – Hardness Testing Temperature Ranges46
Table 13 – SSPs64
Table 14 – Non-Deterministic Random Number Generator Specification65
Figure 1 – Cryptographic Module Boundary (Front)11
Figure 2 - Cryptographic Module Boundary (Back)11
Page 4
ISO/IEC 24759 Section 6FIPS 140-3 Section TitleSecurity Level
1General3
2Cryptographic module specification3
3Cryptographic module interfaces3
4Roles, services, and authentication3
5Software/Firmware security3
6Operational environmentN/A
7Physical security3
8Non-invasive securityN/A
9Sensitive security parameter management3
10Self-tests3
11Life-cycle assurance3
12Mitigation of other attacksN/A

Amazon Web Services, Inc. The module meets the FIPS 140-3 overall Level 3 requirements. Table 1 lists the security level of for each area in the FIPS 140-3 validation: Table 1 – Security Levels

Page 5
ModelHardware [Part Number and Ver- sion]Firmware VersionDistinguishing Features
AWS Key Management Service HSM3.01.8.104DC power input. No maintenance cover
CAVP Cert1 AWS Key Management Service Cryptographic LibraryAlgorithm and StandardMode/MethodSDescription / Key Size(s) / Key trength(s)Use / Function
A1908AES FIPS 197, SP 800-38AECB, CBC, CTRDirection: Decrypt, Encrypt Key Length: 128, 256Encryption, Decryption
A1908GCM2 SP 800-38DAESGCM: Direction: Decrypt, Encrypt IV Generation: External3 IV Generation Mode: 8.2.2 Key Length: 128, 256 Tag Length: 96, 128 IV Length: 96 Payload Length: 64, 128, 192 AAD Length: 128, 256Generation, Authentica- tion, Encryption, Decryption
  1. Cryptographic Module Specification The AWS Key Management Service HSM is used exclusively by AWS as a component of the AWS Key Management Service (KMS). The module is not directly accessible to customers of KMS. The cryptographic functions of the module are used to fulfill requests under specific public AWS KMS APIs. The module runs firmware versions 1.8.104 on hardware version 3.0 and is classified as a Hardware module with a multi-chip standalone embodiment. The cryptographic boundary is defined as the module case, and the module runs on a non-modifiable operating environment. The module follows the initialization/installation requirements found in Section
  2. Table 2 - Cryptographic Module Tested Configuration The AWS Key Management Service HSM operates only in an Approved mode of operation. The module does not support any non-approved algorithms not allowed in the Approved mode of operation. The module’s cryptographic algorithm implementations have received the following certificate numbers from the Cryptographic Algorithm Validation Program (CAVP). Although additional modes and key lengths were included in the CAVP algorithm testing, the table below represents the actual modes and key lengths used by the services of the module. Standard Strength(s) There are algorithms, modes, and key/moduli sizes that have been CAVP-tested but are not used by any approved service of the module. Only the algorithms, modes/methods, and key lengths/curves/moduli shown in this table are used by an approved service of the module. Per IG C.H (Scenario 2), IVs are internally generated using an approved DRBG, with length of 96 bits (per SP 800-38D). The IV generation is internal to the module, but external to the algorithm boundary
Page 6
CAVP Cert1Algorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A1908KTS SP 800-38F per IG D.GAES KWPDirection: Decrypt, Encrypt Cipher: Cipher Key Length: 256 Payload Length: 128, 192, 512Key Transport using AES KWP
A1908KTS SP 800-38D and SP 800-38F per IG D.GAES GCMDirection: Decrypt, Encrypt Cipher: Cipher Key Length: 256 Payload Length: 160, 256, 384, 512, 2048, 3072, 4096Key Transport using AES GCM
A1908DRBG SP 800-90ACTR DRBGCapabilities: Mode: AES-256 Derivation Function Enabled: Yes Additional Input: 384 Entropy Input: 384 Nonce: 384 Personalization String Length: 384 Returned Bits: 512Random Bit Generation
A1908ECDSA FIPS 186-4KeyGenCurve: P-256, P-384, P-521 Secret Generation Mode: Extra Bits, Testing CandidatesKey Pair Generation
KeyVerCurve: P-256, P-384, P-521Public Key Validation
SigGen ComponentCurve: P-256, P-384, P-521 Hash Algorithm: SHA2-256, SHA2-384, SHA2-512Signature Generation Component
SigGenCurve: P-256, P-384, P-521 Hash Algorithm: SHA2-256, SHA2-384, SHA2-512Signature Generation
SigVerCurve: P-256, P-384, P-521 Hash Algorithm: SHA2-256, SHA2-384, SHA2-512Signature Verification
A1908HMAC FIPS 198-1SHA-1MAC: 80-160 Increment 8 Key Length: 160Generation, Authentica- tion
SHA2-256MAC: 128-256 Increment 8 Key Length: 256
SHA2-384MAC: 192-384 Increment 8 Key Length: 384
SHA2-512MAC: 256-512 Increment 8 Key Length: 512
Page 7
CAVP Cert1Algorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A1908RSA FIPS 186-4KeyGenCapabilities: Key Generation Mode: B.3.3 Properties: Modulo: 2048, 3072, 4096 Primality Tests: Table C.2 Properties: Modulo: 2048, 3072, 4096 Primality Tests: Table C.3 Public Exponent Mode: Random Private Key Format: Chinese Remainder TheoremKey Pair Generation
SigGenSignature Type: PKCSPSS Properties: Modulo: 2048, 3072, 4096 (Note: All supported modulus sizes have been algorithm tested according to IG C.F) Hash Pair: Hash Algorithm: SHA2-256 Salt Length: 0 Hash Pair: Hash Algorithm: SHA2-384 Salt Length: 0 Hash Pair: Hash Algorithm: SHA2-512 Salt Length: 0Signature Generation
SigVerSignature Type: PKCSPSS Properties: Modulo: 2048, 3072, 4096 (Note: All supported modulus sizes have been algorithm tested according to IG C.F) Hash Pair: Hash Algorithm: SHA2-256 Salt Length: 0 Hash Pair: Hash Algorithm: SHA2-384 Salt Length: 0 Hash Pair: Hash Algorithm: SHA2-512 Salt Length: 0Signature Verification
Decryption PrimitiveModulo Length: 2048Component Test
Signature PrimitivePrivate Key Format: standard Public Exponent Mode: randomSignature Generation Component
Page 8
CAVP Cert1Algorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A1908SHS FIPS 180-4SHA-1Message Length: 0-65536 Increment 8non-Digital Signature Applications
SHA2-256Message Length: 0-65536 Increment 8Digital Signature Gener- ation and Verification
SHA2-384Message Length: 0-65536 Increment 8Digital Signature Gener- ation and Verification
SHA2-512Message Length: 0-65536 Increment 8Digital Signature Gener- ation and Verification
A1908KTS-IFC SP 800-56Brev2 per IG D.GRSA-OAEP without key confirmation Key sizes: 2048, 3072, and 4096 bits Hybrid Key-Transport scheme incorporating KTS-OAEP and SP 800- 38FModulo: 2048, 3072, 4096 Key Generation Methods: rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme: KTS-OAEP-basic: Key Transport Method: Hash Algorithms: SHA-1, SHA2-256 Supports Null Associated Data Associated Data Encoding: concatenation KAS Role: initiator, responder Key Length: 1024 SSP establishment methodology provides between 112 and 150 bits of en- cryption strengthKey Transport, Optional RSA encapsula- tion schemes for protecting keys that cus- tomers import into AWS KMS
A1908KAS SP 800-56Arev3 per IG D.F Sce- nario 2, path (2)KAS-ECC (Cofactor) Ephemeral Unified scheme with key confirmationP-384 curve providing 192 bits of encryp- tion strengthKey Agreement
A1908KAS SP 800-56Arev3 per IG D.F Sce- nario 2, path (2)KAS-ECC (Cofactor) One-Pass Dif- fie-Hellman scheme with key confirmationP-384 curve providing 192 bits of encryp- tion strengthKey Agreement
A1908KDA SP 800-56Crev1[SP 800-56Crev1] One-step key derivationAuxiliary Function Methods: Auxiliary Function Name: SHA2-256 MAC Salting Methods: default, random Auxiliary Function Methods: Auxiliary Function Name: SHA2-384 MAC Salting Methods: default, randomKey Derivation
Page 9
CAVP Cert1Algorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
Vendor Affirmed IG D.H AWS Key Management Service Key Derivation Function LibraryCKG SP 800-133rev2[SP 800-133rev2, Section 4] Seeding for asymmetric key generation uses un- modified DRBG output [SP 800-133rev2, Section 6.1] Symmetric key genera- tion uses unmodified DRBG output [SP 800-133rev2, Section 6.2] Symmetric keys can be derivedN/AKey Generation
A1910 Entropy SourceKBKDF SP 800-108Counter Mode HMAC-based KDF with SHA2-256Capabilities: KDF Mode: Counter MAC Mode: HMAC-SHA2-256 Supported Lengths: 8-4096 Increment 8 Fixed Data Or- der: Before Fixed Data Counter Length: 32 Supports Empty IV Custom Key In Length: 0Key Derivation
N/AENT (P) SP 800-90BEntropy source384 bitsProvides seeding mate- rial for the DRBG
A1791Conditioning ComponentsAES-ECB AES-CBC-MAC Counter DRBGKey Length: 128 Payload Length: 128Provides seeding mate- rial for the DRBG
AlgorithmCaveatUse / Function
ECDSA secp256k1key agreement; key establishment methodol- ogy provides 128 bits of encryption strength[IG C.A] Curves: secp256k1 may only be used in block- chain related applications
AlgorithmCaveatUse / Function
HMAC-SHA1 (non-com- pliant)No security claimedUsed as defined by the IPMI specification on the Baseboard Management Controller (BMC) which operates completely independently from the rest of the module’s functionality
HMAC-SHA1-96 (non- compliant)No security claimedUsed as defined by the IPMI specification on the Baseboard Management Controller (BMC) which operates completely independently from the rest of the module’s functionality

6.1] 6.2] Table 3 –Approved Algorithms Table 4 – Non-Approved Algorithms Allowed in the Approved Mode of Operation

Page 10
AlgorithmCaveatUse / Function
HMAC-MD5No security claimedUsed as defined by the IPMI specification on the Baseboard Management Controller (BMC) which operates completely independently from the rest of the module’s functionality
HMAC-SHA2-256-128 (non-compliant)No security claimedUsed as defined by the IPMI specification on the Baseboard Management Controller (BMC) which operates completely independently from the rest of the module’s functionality
AES-CBC-128 (non- compliant)No security claimedUsed as defined by the IPMI specification on the Baseboard Management Controller (BMC) which operates completely independently from the rest of the module’s functionality

Table 5 - Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed

Page 11

The cryptographic boundary consists of the entire module as shown in Figures 1 and 2. Figure 1 – Cryptographic Module Boundary (Front) Figure 2 - Cryptographic Module Boundary (Back)

Page 12
Physical portLogical inter- faceData that passes over port/interface
25 Gigabit Ethernet PortData InputMain session interface for cryptographic services
25 Gigabit Ethernet PortData OutputMain session interface for cryptographic services
25 Gigabit Ethernet PortControl InputMain session interface for cryptographic services
IPMI / Gigabit Ethernet PortControl InputProvides serial console access, query power on / off
25 Gigabit Ethernet PortStatus OutputMain session interface for cryptographic services
IPMI / Gigabit Ethernet PortStatus OutputProvides serial console access, query power on / off
PowerPowerN/A

3. Cryptographic Module Interfaces The module provides a number of physical and logical interfaces to the device, and the physical interfaces provided by the module are mapped to four FIPS 140-3 defined logical interfaces: data input, data output, control input, and status output. The control output interface is not applicable. The logical interfaces and their mapping are provided in the following table: Table 6 – Ports and Interfaces

Page 13
RoleAuthentication MethodAuthentication Strength
KMS Front End Role (KMS-FE)Identity based authentication. Com- mands are signed using the operator’s RSA 2048, 3072, 4096 or ECDSA P384 key112 to 192 bits of security
KMS Coordinator Role (KMS-C)Identity based authentication. Com- mands are signed using the operator’s RSA 2048, 3072, 4096 or ECDSA P384 key112 to 192 bits of security
Administrator Role (Admin)Identity based authentication. Com- mands are signed using the operator’s RSA 2048, 3072, 4096 or ECDSA P384 key112 to 192 bits of security
  1. Roles, Services, and Authentication Operators of the module may assume the following three roles implicitly: KMS Front End Role (KMS-FE) - The KMS front end hosts perform actions on behalf of customers of AWS KMS. KMS Coordinator Role (KMS-C) - Non-public facing KMS hosts perform actions on behalf of KMS administrators in Administrator Role (Admin) - Employees of AWS who are authorized to manage the module. For FIPS 140-3 purposes, the KMS Coordinator and Administrator roles serve as the Cryptographic Officer role per FIPS 140-3 requirements. The KMS-Front End role serves as the User role per FIPS 140-3 requirements. The module supports only identity-based authentication and requires RSA or ECDSA signatures using RSA with 2048bit, 3072-bit, or 4096-bit keys, or ECDSA with P-384. Operators of the module are identified by unique Operator Signature Public Key (QOS). The list of operator keys and the role of each operator are configured using either the Initialize or InitializeAndCreateDomain service. Operators interact with the module by submitting digitally signed commands to the module. The module authenticates operators by verifying the digitally signed commands submitted to the module. Table 7 – Roles and Authentication The list of services supported by the module are listed in Table
  2. Unless otherwise specified, access to services can be configured to require one or more members of one or more roles listed in Table
  3. These services are used only by components of KMS to fulfill requests under specific public AWS KMS APIs and cannot be used directly by KMS customers. See http://docs.aws.amazon.com/kms/latest/APIReference/Welcome.html for a list of the current public AWS KMS APIs. Authentication to the module requires RSA (2048 or 4096-bit) or ECDSA (P-384) signature verification. These authentication methods are cryptographically strong and provide between 112 to 192 bits of security. The possibility of a single random authentication attempt succeeding is 2-112 which is far less than the required minimum of less than 1/1,000,000.
Page 14

Assuming an upper bound of 232 authentication requests per second, the possibility of a random authentication succeeding within a one-minute period is (60*232)/2112 = 15/278 which is significantly less than 1/100,000. The cryptographic strengths of the digital signatures used for authentication create such difficulty in achieving a successful random authentication attempt that even the theoretical maximum bandwidth of the 25 Gb/second Ethernet port is not significant enough to allow enough attempts in a one-minute period.

Page 15
RoleServiceInputOutput
Cryptographic Services
KMS-FE, KMS-C, AdminCreateNoneA HSM Backing Key encrypted with the active Do- main Key (DKn), or An Import Wrapping Key Pair (dIWK, QIWK) The IWK private key is encrypted with the active Do- main Key (DKn) The IWK public key
KMS-FE, KMS-C, AdminImportKeyThe private key of an Import Wrapping Key Pair (IWK) encrypted with the active or a recent iter- ation of domain key (DKn or DKn-1) Customer Supplied Key (CSK), encrypted with the public key of the Import Wrapping Key. This may use the wrapping methods as defined in section 9.2 or 9.3 of SP 800-56B, using the ephemeral Import Wrapping Envelope Key (IWEK)The Customer Supplied Key, encrypted with the cur- rent active domain key (DKn)
KMS-FE, KMS-C, AdminRefreshKeyHBK or CSK encrypted with a recent iteration of a Domain Key (DKn-1)HBK or CSK encrypted with the active domain key (DKn)
KMS-FE, KMS-C, AdminEncryptA HBK or CSK encrypted with the active or a re- cent iteration of domain key (DKn or DKn-1)N/A (encrypted ciphertext)
KMS-FE, KMS-C, AdminDecryptA HBK or CSK encrypted with a Domain Key (DKn) Ciphertext or encrypted Customer Data Key (CDK) Customer Data Encryption Public Key (QCDEK)Arbitrary data or CDK encrypted using the HOSK
Page 16
RoleServiceInputOutput
KMS-FE, KMS-C, AdminReEncryptA HBK or CSK encrypted with the active or a re- cent iteration of domain key (DKn or DKn-1) used to decrypt the provided ciphertext A HBK or CSK encrypted with the active or a re- cent iteration of domain key (DKn or DKn-1) used to encrypt the resulting plaintext Ciphertext or encrypted Customer Data Key (CDK)N/A (encrypted ciphertext)
KMS-FE, KMS-C, AdminSignHBK or CSK encrypted with the active domain key (DKn)None (signature)
KMS-FE, KMS-C, AdminVerifyHBK or CSK encrypted with the active domain key (DKn) (signature to be verified)None
KMS-FE, KMS-C, AdminEncryptRandomBytesHBK or CSK encrypted by the active domain key (DKn)A number of random bytes that may be used as Cus- tomer Data Keys (CDK) encrypted by the HBK or CSK
KMS-FE, KMS-C, AdminGenerateAndEncryptRandomBytesHBK or CSK encrypted by the active domain key (DKn) Customer Data Encryption Public Key (QCDEK)A number of random bytes that may be used as Cus- tomer Data Keys (CDK) encrypted by the HOSK A number of random bytes that may be used as Cus- tomer Data Keys (CDK) encrypted by the HBK or CSK
KMS-FE, KMS-C, AdminGenerateDataKeyPairHBK or CSK encrypted by the active domain key (DKn) Customer Data Encryption Public Key (QCDEK)An asymmetric Customer Data Key (CDK) private key encrypted by the HOSK An asymmetric Customer Data Key (CDK) private key encrypted by the HBK or CSK
KMS-FE, KMS-C, AdminGenerateDataKeyPairWithoutPlaintextHBK or CSK encrypted by the active domain key (DKn)An asymmetric Customer Data Key (CDK) private key encrypted by the HBK or CSK
KMS-FE, KMS-C, AdminGenerateCustomer Data Encryption Public Key (QCDEK)None
Page 17
RoleServiceInputOutput
KMS-FE, KMS-C, AdminGetParametersForReplicationNonePublic Replication Agreement Key (QRAK ) 1 Private Replication Agreement Key (dRAK ) en- 1 crypted by the active domain key (DKn)
KMS-FE, KMS-C, AdminWrapKeyForReplicationPublic Replication Agreement Key (QRAK ) 1 HBK encrypted by the active domain key (DKn) Replication Agreement Key Pair (dRAK , QRAK ) 2 2Public Replication Agreement Key (QRAK ) 2 Customer Replicated Key (CRK) encrypted by the Replication Wrapping Key (RWK)
KMS-FE, KMS-C, Admin Configuration ServicesImportReplicatedKeyPrivate Replication Agreement Key (dRAK ) en- 1 crypted by the active domain key (DKn) Public Replication Agreement Key (QRAK ) 2 Customer Supplied Key (CSK) encrypted by the Replication Wrapping Key (RWK)HBK encrypted by the active domain key (DKn) Customer Replication Key (CRK)
KMS-FE, KMS-C, AdminCreateDomainList of Operator Signature Public Keys (QOS)A Domain Token containing: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Initial Domain Key (DK0) • Encrypted Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSK0) • Public Replication Signing Key (QRSK0)
Page 18
RoleServiceInputOutput
KMS-FE, KMS-C, AdminIngestDomainA Domain Token containing the following CSPs: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DKn) • Encrypted Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSKn) Public Replication Signing Key (QRSKn)The unmodified input Domain Token
KMS-FE, KMS-C, AdminForgetDomainA Domain Token containing the following CSPs: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DKn) • Encrypted Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSKn) Public Replication Signing Key (QRSKn)The unmodified input Domain Token
KMS-FE, KMS-C, AdminGetDomainNoneA Domain Token containing: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DKn) • Encrypted Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSKn) Public Replication Signing Key (QRSKn)
Page 19
RoleServiceInputOutput
KMS-FE, KMS-C, AdminChangeDomainA Domain Token containing: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DKn) • Encrypted Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSKn) • Public Replication Signing Key (QRSKn) HSM Signature Public Keys (QHSK) and HSM Key Agreement Public Keys (QHAK) of the domain members to be added (optional) List of Operator Signature Public Keys (QOS) (optional) List of Public Replication Signing Keys (QRSKm, …, QRSKn) (optional)An updated Domain Token containing the following CSPs: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DKn) • Encrypted Domain Key Encryption Key (DKEK) Encrypted Private Replication Signing Key (dRSKn) Public Replication Signing Key (QRSKn)
KMS-FE, KMS-C, AdminInitializeOne or more Domain Tokens. Each Domain To- ken contains: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DKn) • Encrypted Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSKn) Public Replication Signing Key (QRSKn)None
Page 20
RoleServiceInputOutput
All (un- authenti cated)InitializeAndCreateDomainList of Operator Signature Public Keys (QOS)A Domain Token containing: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Initial Domain Key (DK0) • Encrypted Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSKn) Public Replication Signing Key (QRSKn)
KMS-FE, KMS-C, AdminAttestHSM Signature Key Pair (dHSK, QHSK) Host Agreement Public Key (QHAK) Operator Signature Public Key(s) (QOS) HSM Session Key Encryption Key (HSKEK) HSM-to-Operator Session Key (HOSK)HSM Signature Public Key (QHSK) HSM Agreement Public Key (QHAK)
KMS-FE, KMS-C, AdminGetAttestationChallengeNoneNone
KMS-FE, KMS-C, AdminGetAttestationIdentityNoneNone
All (un- authenti cated)WipeNoneNone
All (un- authenti cated)GetInitialDomainNameNoneNone
All (un- authenti cated)DeactivateAndRebootNoneNone
Page 21
RoleServiceInputOutput
One member from any roleNegotiateSessionKeyOperator Ephemeral Agreement Public Key (QOEAK)Encrypted HSM-Operator Session Key (HOSK) en- crypted with the Domain Key (DKn) or HSM Session Key Encryption Key (HSKEK) HSM-Operator Session Key (HOSK) encrypted with a 256-bit key derived from the shared secret estab- lished using elliptic curve Diffie Hellman key exchange (NIST-P384) using the HSM Ephemeral Agreement Public Key (QE) and the Operator Ephem- eral Agreement Public Key (QOEAK) HSM Ephemeral Agreement Public Key (QE)
KMS-FE, KMS-C, Admin Audit Log ServicesUpdateHostConfigurationNoneNone
KMS-FE, KMS-C, AdminListLogsNoneNone
KMS-FE, KMS-C, AdminGetLogNoneNone
KMS-FE, KMS-C, Admin Other ServicesDeleteLogNoneNone
All (un- authenti cated)PingNoneReturns “healthy” if the module is operating in Ap- proved mode. Returns “failure” if the module is not operating in Approved mode.
All (un- authenti cated)ApprovedNoneReturns “healthy” if the module is operating in Ap- proved mode. Returns “failure” if the module is not operating in Approved mode.
All (un- authenti cated)VersionNoneModule name, hardware version and firmware ver- sion
Page 22
RoleServiceInputOutput
All (un- authenti cated)Hardware monitoringNoneHardware sensor data
All (un- authenti cated)Power managementNoneNone
All (un- authenti cated)Serial over LAN (SOL)NoneNone
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
CreateGenerates and en- crypts either an HSM Backing Key (HBK) or an Import Wrapping Key Pair (dIWK, QIWK) pri- vate keyCTR DRBG AES GCM KBKDF RSA (keygen) ECDSA (keygen) CKGHSM Backing Key IWK public and private keys Active Domain Key (DK ) n HSM-to-Operator Session Key (HOSK) DRBG (CTR AES) V and AES keyKMS-FE, KMS-C, AdminGenerate Read Execute Zeroize“healthy”

Table 8 – Roles, Service Commands, Input and Output Each approved service provides an indicator when the service utilizes an approved cryptographic algorithm, security function, or process in an approved manner. Per IG 2.4.C, the module implements a global indicator via the “Approved” service which is a persistent indicator that only returns healthy if the module is running in its approved mode of operation where approved services are executing. Approved Services Approved services supported by the module are listed in Table 9. Access rights Description Approved Functions Indicator Service Security SSPs Roles and/or SSPs

Page 23
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
ImportKeyDecrypts a Cus- tomer Supplied Key (CSK) and re-en- crypts it with the active Domain Key (DK ) nAES GCM KBKDF KTS-IFC (RSA-OAEP)The private key of an Import Wrapping Key Pair (dIWK, QIWK) Customer Supplied Key (CSK) Active Domain Key (DK ) n HSM-to-Operator Session Key (HOSK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
RefreshKeyRe-encrypts an HSM Backing Key (HBK) key or Cus- tomer Supplied Key (CSK) encrypted with a recent itera- tion of the domain key (DK ) with the n-1 active domain key (DK ) nAES GCM KBKDFHBK or CSK encrypted with a recent itera- tion of a Domain Key (DKn or DKn-1) Active or a recent iteration of Domain Key (DKn or DKn-1) HSM-to-Operator Session Key (HOSK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
EncryptEncrypt an arbitrary set of bytes using the DEK derived from the provided HBK or CSKAES GCMA HBK or CSK encrypted with the active or a recent iteration of domain key (DKn or DKn-1) Active or a recent iteration of Domain Key (DKn or DKn-1) HSM-to-Operator Session Key (HOSK) Data Encryption Key (DEK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                Indicator to Keys Service                                                        Security                   SSPs                                       Roles         and/or SSPs
Page 24
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
DecryptDecrypts ciphertext using the DEK de- rived from the provided HBK or CSKAES GCMA HBK or CSK encrypted with a Domain Key (DK ) n Ciphertext or encrypted Customer Data Key (CDK) Arbitrary data or CDK encrypted using the HOSK Active or a recent iteration of domain key (DK or DK ) n n-1 HSM-to-Operator Session Key (HOSK) Data Encryption Key (DEK) Customer Data Encryption Public Key (QCDEK) Customer Data Encryption Symmetric Key (SCDEK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write Generate“healthy”
ReEncryptDecrypts ciphertext using the DEK de- rived from the provided HBK or CSK, then re-en- crypts the resulting plaintext under the DEK from a sepa- rately provided HBK or CSK This operation does not expose the plaintextAES GCMA HBK or CSK encrypted with the active or a recent iteration of domain key (DK or n DK ) used to decrypt the provided cipher- n-1 text A HBK or CSK encrypted with the active or a recent iteration of domain key (DK or n DK ) used to encrypt the resulting n-1 plaintext Ciphertext or encrypted Customer Data Key (CDK) Active or a recent iteration of Domain Key (DK or DK ) n n-1 HSM-to-Operator Session Key (HOSK) Data Encryption Key (DEK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Keys and/or Description               Approved              Functions                                                                                 Indicator to Keys Service                                                        Security                   SSPs                                        Roles         and/or SSPs (DKn or DKn-1) (DKn or DKn-1)
Page 25
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
SignPerforms an ECDSA or RSA sign opera- tion, or HMAC operation using the provided HBK or CSKCTR DRBG AES GCM RSA ECDSA SHS HMACHBK or CSK encrypted with the active do- main key (DKn) Domain Key (DKn or DKn-1) HSM-to-Operator Session Key (HOSK) DRBG (CTR AES) V and AES keyKMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
VerifyPerforms an ECDSA or RSA verify, or HMAC operation using the provided HBK or CSKAES GCM RSA ECDSA SHS HMACHBK or CSK encrypted with the active do- main key (DKn) Domain Key (DKn or DKn-1) HSM-to-Operator Session Key (HOSK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
EncryptRan- domBytesGenerate a number of random bytes and encrypt it using the DEK derived from the specified HBK or CSK The random bytes may be used as cryptographic key material as Cus- tomer Data Keys (CDK)CTR DRBG AES GCM CKGHBK or CSK encrypted with the active do- main key (DKn) A number of random bytes that may be used as Customer Data Keys (CDK) en- crypted by the HBK or CSK Domain Key (DKn or DKn-1) HSM-to-Operator Session Key (HOSK) DRBG (CTR AES) V and AES key Data Encryption Key (DEK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                              Indicator Service                                                        Security                   SSPs                                     Roles         and/or SSPs
Page 26
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
GenerateAndEn- cryptRandomBytesGenerate a number of random bytes for use and encrypt it using the DEK de- rived from the specified HBK or CSK The random bytes may be used as cryptographic key material as Cus- tomer Data Keys (CDK) Note that the Gen- erateAndEncryptRa ndomBytes API will return encrypted versions of the ran- dom bytes in 2 formsCTR DRBG AES GCM CKGHBK or CSK encrypted with the active do- main key (DKn) A number of random bytes that may be used as Customer Data Keys (CDK) en- crypted by the HBK or CSK A number of random bytes that may be used as Customer Data Keys (CDK) en- crypted by the HOSK Domain Key (DKn or DKn-1) HSM-to-Operator Session Key (HOSK) DRBG (CTR AES) V and AES key Data Encryption Key (DEK) Customer Data Encryption Public Key (QCDEK) Customer Data Encryption Symmetric Key (SCDEK)KMS-FE, KMS-C, AdminGenerate Read Execute Zeroize Write“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                              Indicator Service                                                        Security                   SSPs                                     Roles         and/or SSPs
Page 27
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
GenerateDataKey- PairGenerate an asym- metric key pair and encrypt it with the specified HBK or CSK The asymmet- ric key pair will be used as crypto- graphic key material as Cus- tomer Data Keys (CDK) Note that the Gen- erateDataKeyPair API will return en- crypted versions of the CDK in 2 formsCTR DRBG RSA (keygen) ECDSA (keygen) AES GCM CKGHBK or CSK encrypted by the active do- main key (DK ) n An asymmetric Customer Data Key (CDK) private key encrypted by the HOSK An asymmetric Customer Data Key (CDK) private key encrypted by the HBK or CSK Active or a recent iteration of domain key (DK or DK ) n n-1 HSM-to-Operator Session Key (HOSK) DRBG (CTR AES) V and AES key Customer Data Encryption Public Key (QCDEK) Customer Data Encryption Symmetric Key (SCDEK)KMS-FE, KMS-C, AdminGenerate Read Execute Zeroize Write“healthy”
GenerateDataKey- PairWithoutPlainte xtGenerate an asym- metric key pair and encrypt it with the specified HBK or CSK The asymmet- ric key pair will be used as crypto- graphic key material as Cus- tomer Data Keys (CDK)CTR DRBG RSA (keygen) ECDSA (keygen) AES GCM CKGHBK or CSK encrypted by the active do- main key (DK ) n An asymmetric Customer Data Key (CDK) private key encrypted by the HBK or CSK Active or a recent iteration of domain key (DK or DK ) n n-1 HSM-to-Operator Session Key (HOSK) DRBG (CTR AES) V and AES keyKMS-FE, KMS-C, AdminGenerate Read Execute Zeroize Write“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                Indicator Service                                                        Security                   SSPs                                       Roles         and/or SSPs (DKn or DKn-1)
Page 28
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
GenerateGenerate a speci- fied number of random bytes, up to 1024 bytesCTR DRBG AES GCM CKGHSM-to-Operator Session Key (HOSK) DRBG (CTR AES) V and AES key Customer Data Encryption Public Key (QCDEK) Customer Data Encryption Symmetric Key (SCDEK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
GetParameters- ForReplicationThis API generates a new Replication Agreement Key Pair (dRAK , QRAK ) 1 1 The Private Replica- tion Agreement Key (dRAK ) is en- 1 crypted with the domain key (DK ) n The API also signs all output with the Private Replication Signing Key (dRSK n or dRSK ) n-1CTR DRBG ECDSA (keygen) AES GCM CKGPublic Replication Agreement Key (QRAK ) 1 Private Replication Agreement Key (dRAK ) 1 encrypted by the active domain key (DK ) n Replication Agreement Key Pair (dRAK , 1 QRAK ) 1 HSM-to-Operator Session Key (HOSK) Active or a recent iteration of domain key (DK or DK ) n n-1 Active or a recent iteration of a Private Replication Signing Key (dRSK or dRSK ) n n-1 DRBG (CTR AES) V and AES keyKMS-FE, KMS-C, AdminGenerate Read Execute Zeroize“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                Indicator to Keys Service                                                        Security                   SSPs                                       Roles         and/or SSPs (dRAK1, QRAK1) or dRSKn-1)
Page 29
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
WrapKeyForRepli- cationThis API takes an in- put a public Replication Agree- ment Key (QRAK ) 1 generated from an HSM, and gener- ates a new Replication Agree- ment Key pair (dRAK , QRAK ) 2 2 QRAK and dRAK 1 2 are combined using the Diffie-Hellmann key exchange to produce a shared secret and derive a symmetric secret key (the Replication Wrapping Key, RWK) The RWK is then used to encrypt an HBK, resulting in a Customer Repli- cated Key (CRK)KAS (ECCDH) KDA (one-step KDF SHA2) AES GCM ECDSAPublic Replication Agreement Key (QRAK ) 1 HBK encrypted by the active domain key (DK ) n Replication Agreement Key Pair (dRAK , 2 QRAK ) 2 Public Replication Agreement Key (QRAK ) 2 Customer Replicated Key (CRK) encrypted by the Replication Wrapping Key (RWK) HSM-to-Operator Session Key (HOSK) Active or a recent iteration of domain key (DK or DK ) n n-1 Active or a recent iteration of the Private Replication Signing Key (dRSK or dRSK ) n n-1 Active or a recent iteration of the Public Replication Singing Key (QRSK or QRSK ) n n-1 Replication Agreement RWK Shared Secret Z (RRZ) Customer Replication Key (CRK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                 Indicator to Keys Service                                                        Security                    SSPs                                       Roles         and/or SSPs ECDSA                              QRAK2)
Page 30
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
ImportReplicat- edKeyThis API combines two Replication Agreement Key (dRAK and QRAK ) 1 2 using the Diffie- Hellmann key ex- change to produce a shared secret and derive a Replication Wrapping Key (RWK) The RWK is used to decrypt the Cus- tomer Replicated Key (CRK), obtain- ing an HBK, which is then re-encrypted using the Domain Key (DK ) n The API also vali- dates input using the Public Replica- tion Signing Key (QRSK or QRSK ) n n-1KAS (ECCDH) KDA (one-step KDF SHA2) AES GCM ECDSA SHSPrivate Replication Agreement Key (dRAK ) 1 encrypted by the active domain key (DK ) n Public Replication Agreement Key (QRAK ) 2 Customer Supplied Key (CSK) encrypted by the Replication Wrapping Key (RWK) HBK encrypted by the active domain key (DK ) n HSM-to-Operator Session Key (HOSK) Active or a recent iteration of domain key (DK or DK ) n n-1 Active or a recent iteration of the Public Replication Singing Key (QRSK or QRSK ) n n-1 Replication Agreement RWK Shared Secret Z (RRZ) Customer Replication Key (CRK)KMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                Indicator to Keys Service                                                        Security                   SSPs                                       Roles         and/or SSPs (dRAK1 and QRAK2) Key (DKn) (QRSKn or QRSKn-1)
Page 31
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
CreateDomainCreates a new do- main token for a new domain, but does not join the HSM to the domain yetCTR DRBG KAS (ECCDH) KDA (one-step KDF SHA2) AES GCM ECDSA RSA SHSList of Operator Signature Public Keys (QOS) HSM Signature Key Pair (dHSK, QHSK) HSM Agreement Key Pair (dHAK, QHAK) HSM Agreement DKEK Shared Secret Z (HDKZ) HSM Agreement DKEK Wrapping Key (HDWK) Initial Domain Key (DK) 0 Replication Signing Key (dRSK , QRSK ) 0 0 A Domain Token containing: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Initial Domain Key (DK ) 0 • Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSK ) 0 • Public Replication Signing Key (QRSK ) 0 • DRBG (CTR AES) V and AES keyKMS-FE, KMS-C, AdminGenerate Read Execute Zeroize“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                Indicator Service                                                        Security                   SSPs                                       Roles         and/or SSPs Key (dRSK0)
Page 32
IngestDomainJoins a domain or receive an updated domain tokenCTR DRBG KAS (ECCDH) (one-step KDF SHA2) AES GCM ECDSA RSA SHA2A Domain Token containing the following CSPs: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DKn) • Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSKn) • Public Replication Signing Key (QRSKn) HSM Signature Public Key (QHSK) of a known member of the domain HSM Agreement Private Key (dHAK) HSM Agreement DKEK Shared Secret Z (HDKZ) HSM Agreement DKEK Wrapping Key (HDWK) Operator Signature Public Keys (QOS) Domain Key (DKn) Operator Signature Public Keys (QOS) HSM Signature Public Keys (QHSK) of all members of the domain HSM Key Agreement Public Keys (QHAK) of all members of the domain Encrypted Private Replication Signing Key (dRSKn) Public Replication Signing Key (QRSKn) DRBG (CTR AES) V and AES keyKMS-FE, KMS-C, AdminRead Execute Zeroize Write“healthy”
ForgetDomainDeletes domain in- formation as it pertains to aECDSA RSAA Domain Token containing the following CSPs:KMS-FE, KMS-C, AdminRead Execute“healthy”
Page 33
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
particular domain on the module in- cluding all Domain Keys (DK , DK ), n n-1 effectively leaving the domainSHA2• List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DK ) n • Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSK ) n • Public Replication Signing Key (QRSK ) n Domain Key (DK ) n Operator Signature Public Keys (QOS) HSM Signature Public Keys (QHSK) of all members of the domain HSM Key Agreement Public Keys (QHAK) of all members of the domainZeroize
GetDomainRetrieves the cur- rent version of the domain token for a specified domainECDSA RSA SHA2A Domain Token containing: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DK ) n • Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSK ) n • Public Replication Signing Key (QRSK ) n Domain Key (DK ) n Operator Signature Public Keys (QOS)KMS-FE, KMS-C, AdminRead Execute Zeroize“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Keys and/or Description               Approved              Functions                                                                                Indicator to Keys Service                                                        Security                   SSPs                                       Roles         and/or SSPs Key (dRSKn) Key (dRSKn)
Page 34
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
ChangeDomainModifies the cur- rent state of an operational domainCTR DRBG KAS (ECCDH) (one-step KDF SHA2) AES GCM ECDSA RSA SHA2A Domain Token containing: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DK ) n • Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSK ) n • Public Replication Signing Key (QRSK ) n HSM Signature Public Keys (QHSK) and HSM Key Agreement Public Keys (QHAK) of the domain members to be added (op- tional) List of Operator Signature Public Keys (QOS) (optional) List of Public Replication Signing Keys (QRSK , …, QRSK ) (optional) m n Domain Key Encrypting Key (DKEK) Domain Key (DK ) n HSM Ephemeral Agreement Key Pair (dE, QE) HSM Agreement Key (HAK) HSM Signature Key (HSK) DRBG (CTR AES) V and AES keyKMS-FE, KMS-C, AdminGenerate Read Execute Zeroize Write“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                Indicator Service                                                        Security                    SSPs                                      Roles         and/or SSPs Key (dRSKn) (QRSKm, …, QRSKn) (optional)
Page 35
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
InitializeInitializes the HSM by generating the HSM Signature Key and HSM Agree- ment Key and configuring the HSM’s operator and access control using a domain token from another HSM The Initialize API is only used during the module setup and initialization process If the HSM is already initialized by a call to either the Initialize or Ini- tializeAndCreateDo main API, the Ini- tialize API will return an error as the HSM cannot be Initialized again without a rebootCTR DRBG ECDSA (keygen, sign) KAS (EC CDH) (one-step KDF SHA2) AES GCM CKGOne or more Domain Tokens. Each Domain Token contains: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Domain Keys (DK ) n • Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSK ) n • Public Replication Signing Key (QRSK ) n HSM Signature Key (HSK) HSM Agreement Key (HAK) HSM Agreement HSKEK Shared Secret Z (HHKZ) HSM Session Key Encryption Key (HSKEK) Operator Signature Public Keys (QOS) DRBG (CTR AES) V and AES key DRBG (CTR AES) Seed Entropy Input StringAll / unauthenti- catedGenerate Read Execute Zeroize“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                      Indicator Service                                                        Security                   SSPs                                       Roles               and/or SSPs
Page 36
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
InitializeAndCre- ateDomainInitializes the HSM by generating the HSM Signature Key and HSM Agree- ment Key, configuring the list of operators, roles and the quorum- based access con- trol ruleset for all services / APIs The Initialize- AndCreateDomain API is only used during the module setup and initializa- tion process If the HSM is al- ready initialized by a call to either the Initialize or Initializ- eAndCreateDomain API, the Initialize- AndCreateDomain API will return an error as the HSM cannot be Initial- ized again without a rebootCTR DRBG ECDSA (keygen, sign) KAS (EC-CDH) (one-step KDF SHA2) AES GCM CKGList of Operator Signature Public Keys (QOS) HSM Signature Key Pair (dHSK, QHSK) HSM Agreement Key Pair (dHAK, QHAK) HSM Agreement DKEK Shared Secret Z (HDKZ) HSM Agreement DKEK Wrapping Key (HDWK) HSM Agreement HSKEK Shared Secret Z (HHKZ) HSM Session Key Encryption Key (HSKEK) Initial Domain Key (DK) 0 A Domain Token containing: • List of Operator Signature Public Keys (QOS) • List of HSM Signature Public Keys (QHSK) of all members of the domain • List of HSM Key Agreement Public Keys (QHAK) of all members of the domain • Encrypted Initial Domain Key (DK ) 0 • Domain Key Encryption Key (DKEK) • Encrypted Private Replication Signing Key (dRSK ) n • Public Replication Signing Key (QRSK ) n DRBG (CTR AES) V and AES keyAll / unauthenti- catedGenerate Read Execute Zeroize“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                      Indicator Service                                                        Security                   SSPs                                       Roles               and/or SSPs
Page 37
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
AttestThe Attest API is used by operators to attest an initial- ized HSM to ensure that the system is running the correct software, and to obtain an authentic copy of its creden- tials prior to being added to a domainCTR DRBG ECDSA (verify) SHA2 AES GCMHSM Signature Public Key (QHSK) HSM Agreement Public Key (QHAK) HSM Signature Key Pair (dHSK, QHSK) Operator Signature Public Key(s) (QOS) HSM Agreement HSKEK Shared Secret Z (HHKZ) HSM Session Key Encryption Key (HSKEK) HSM-to-Operator Session Key (HOSK) DRBG (CTR AES) V and AES keyKMS-FE, KMS-C, AdminRead Execute Zeroize“healthy”
GetAttestationChal- lengeThe GetAttestation- Challenge API is used by operators to retrieve a token that can be used to validate the identity of another HSMAES GCMActive or a recent iteration of Domain Key (DKn or DKn-1) HSM-to-Operator Session Key (HOSK)KMS-FE, KMS-C, AdminRead Execute Zeroize“healthy”
GetAttestationIden- tityThe GetAttesta- tionIdentity API is used by operators to retrieve infor- mation to attest the identity of the HSMAES GCMActive or a recent iteration of Domain Key (DKn or DKn-1) HSM-to-Operator Session Key (HOSK)KMS-FE, KMS-C, AdminRead Execute Zeroize“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                Indicator to Keys Service                                                        Security                   SSPs                                       Roles         and/or SSPs
Page 38
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
WipeThe Wipe API will delete the HSM Sig- nature Key and HSM Agreement Key from volatile memory The Wipe API will fail unless all previ- ously created domains in the module have been deleted using the ForgetDomain APIN/AHSM Signature Key Pair (dHSK, QHSK) HSM Agreement Key Pair (dHAK, QHAK) HSM Session Key Encryption Key (HSKEK)All / unauthenti- catedZeroize“healthy”
GetInitialDomain- NameRetrieves the initial domain name from an initialized HSM that is used as part of the domain crea- tion bootstrap processN/AN/AAll / unauthenti- catedN/A“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Keys and/or Description               Approved              Functions                                                                                  Indicator to Keys Service                                                        Security                     SSPs                                 Roles               and/or SSPs
Page 39
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
DeactivateAndRe- bootThe Deactivate- AndReboot API returns the HSM to the factory state and reboots after verifying the HSM Signature Key and HSM Agreement Key have been de- leted by the Wipe API (The module will perform self-tests after during reboot process)N/AN/AAll / unauthenti- catedN/A“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Keys and/or Description               Approved              Functions                                                                                Indicator to Keys Service                                                        Security                     SSPs                               Roles               and/or SSPs
Page 40
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
NegotiateSes- sionKeyUses a set of iden- tity keys to securely negotiate a session key that can be used between a KMS host and any HSM in the domain The NegotiateSes- sionKey API will return encrypted versions of the HSM-Operator Ses- sion Key (HOSK) in 2 formsCTR DRBG RSA (verify) ECDSA (verify) SHA2 KAS (ECCDH) (one-step KDF SHA2) AES GCMOperator Ephemeral Agreement Public Key (QOEAK) HSM Ephemeral Agreement Key Pair (dE, QE) HSM-Operator Session Key (HOSK) Encrypted HSM-Operator Session Key (HOSK) encrypted with the Domain Key (DKn) or HSM Session Key Encryption Key (HSKEK) HSM-Operator Session Key (HOSK) en- crypted with a 256 bit key derived from the shared secret established using elliptic curve Diffie Hellman key exchange (NIST- P384) using the HSM Ephemeral Agree- ment Key (QE) and the Operator Ephemeral Agreement Public Key (QOEAK) HSM Ephemeral Agreement Public Key (QE) Operator Signature Public Key (QOS) HSM Signature Key (dHSK) DRBG (CTR AES) V and AES keyOne member from any roleGenerate Read Execute Zeroize“healthy”
UpdateHostConfig- urationAllows updates of non-security-rele- vant host configurationRSA (verify) ECDSA (verify) SHA2Operator Signature Public Key (QOS)KMS-FE, KMS-C, AdminExecute“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Description               Approved              Functions                                                                                      Indicator Service                                                        Security                    SSPs                                        Roles             and/or SSPs
Page 41
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
ListLogsReturns a list of au- dit log file namesRSA (verify) ECDSA (verify) SHA2Operator Signature Public Key (QOS)KMS-FE, KMS-C, AdminExecute“healthy”
GetLogRetrieves specified audit log filesRSA (verify) ECDSA (verify) SHA2Operator Signature Public Key (QOS)KMS-FE, KMS-C, AdminExecute“healthy”
DeleteLogDeletes specified audit log fileRSA (verify) ECDSA (verify) SHA2Operator Signature Public Key (QOS)KMS-FE, KMS-C, AdminExecute“healthy”
PingReturns “healthy” if the module is ini- tialized and has ingested a domain Returns “failure” otherwiseN/AN/AAll / unauthenti- catedNone“healthy”
ApprovedApproved mode in- dicator that apply to approved ser- vices on the 25G Ethernet port Returns “healthy” if the module is oper- ating in Approved mode Returns “failure” if the module is not operating in Ap- proved modeN/AN/AAll / unauthenti- catedNone“healthy”
Table, extracted as text (did not parse into structured rows)
Access rights Keys and/or Description               Approved              Functions                                                                                Indicator to Keys Service                                                        Security                     SSPs                               Roles               and/or SSPs
Page 42
e c iv r e Sn o it p ir c s e Dd e v o r p p Ay t ir u c e Ss n o it c n u Fr o / d n a s y e Ks P S Ss e lo Rs t h g ir s s e c c As y e K o ts P S S r o / d n ar o t a c id n I
VersionReturns the module name, hardware version and firm- ware versionN/AN/AAll / unauthenti- catedNoneN/A
Hardware monitor- ingProvide access via IPMI to hardware sensor data to monitor tempera- tures, fan speed, etcNoneN/AAll / unauthenti- catedNoneSuccessful comple- tion of service
Power manage- mentTurns on and off the module via IPMINoneN/AAll / unauthenti- catedNoneSuccessful comple- tion of service
Serial over LAN (SOL)Provides access to the module’s con- sole before the module enters Ap- proved mode via IPMI In Approved mode, the SOL link is ac- tive but the module firmware blocks all input commands and status output to the consoleNoneN/AAll / unauthenti- catedNoneSuccessful comple- tion of service
Table, extracted as text (did not parse into structured rows)
Access rights Keys and/or Description               Approved              Functions                                                                                Indicator to Keys Service                                                        Security                     SSPs                               Roles               and/or SSPs Table 9 – Approved Services G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output).
Page 43

W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP.

Page 44

5. Software/Firmware Security The module performs integrity check on all firmware components using a 256-bit error detection code (EDC) on all module components. The integrity check is performed upon the initialization of the module and does not require operator intervention to run. If the check fails, the module will enter into an error state. The module does not support firmware loading. The operator can run the integrity test on demand by rebooting the module using the DeactivateAndReboot API.

Page 45

6. Operational Environment The module has a non-modifiable operational environment and does not allow loading of any additional firmware while the module is operating in Approved mode.

Page 46
Physical Security MechanismRecommended Frequency of Inspec- tion/TestInspection/Test Guidance Details
Tamper-evident physical enclosure with no removable coverInspect when the module unexpectedly re- boots or becomes unresponsiveInspect the physical enclosure for evidence of tampering, such as dents, signs of drilling or prying, cracks in the hard plastic portion of the enclosure
Temperature or voltageSpecify EFP orSpecify if this condition results in a shutdown or
measurementEFTzeroisation
Low Temperature- 8 °CEFPShutdown
High Temperature54 °CEFPShutdown
Low Voltage10 VEFPShutdown
High Voltage14 VEFPShutdown
Hardness tested temperature measurement
Low Temperature- 8 °C
High Temperature52 °C

The module is a hardware module with a multiple-chip standalone embodiment and conforms to the Level 3 requirements for physical security. The module’s production-grade enclosure is made of hard metal, and the enclosure does not provide a removable cover. The baffles installed by AWS satisfy FIPS 140-3 requirements for module opacity and probing. The module supports environments failure protection and shuts down if the temperature or voltage is outside of the values described in Table 11. Table 11

Page 47

8. Non-invasive Security This section is not applicable. The module does not implement non-invasive attack mitigation techniques.

Page 48
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
HSM Backing Key (HBK) CSP/PSP256 bits (AES) 160-256 bits (HMAC) 112 – 128 bits (RSA 2048, 3072 or 4096 bits) 128 – 256 bits (ECDSA P-256, P-384, P-521, or secp256k1)AES GCM RSA ECDSA HMAC (A1908) CKGInternally using DRBG or im- ported from another mem- ber of a DomainInput: En- crypted with the Domain Key us- ing AES GCM (electronically) Output: En- crypted with the Domain Key us- ing AES GCM (electronically)N/AVolatile memoryOverwrite with all zerosUsed as input to a SP 800-108 KBKDF to derive the DEK
Table, extracted as text (did not parse into structured rows)
9.            Sensitive Security Parameters Management Table 13 provides a complete list of Critical Security Parameters used within the module. All keys and SSPs are zeroized by powering off the module. Establishment Security FuncUse & related Key/SSP Generation                                                                        Zeroisation tion and Cert. Strength Import / Name/Type                                   Number                                      Export                                     Storage                           keys
Page 49

Customer Data Key (CDK) CSP/PSP

For symmetric keys, random bits length spec- ified by customer (in the range of 8 bits to 65536 bits) 112

AES RSA ECDSA (A1908) CKG

Internally using DRBG or im- ported from another mem- ber of a Domain

Input: En- crypted using AES GCM with the DEK derived from an HBK or CSK (electroni- cally) Output: En- crypted in 2 forms by the GenerateAndEn- cryptRandomBy tes and Gener- ateDataKeyPair APIs:

  1. Encrypted with the DEK derived from an HBK or CSK; and
  2. Encrypted with the HOSK to provide se- cure transport to the request- ing service operator/role EncryptRan- domBytes and Generate- DataKeyPairWit houtPlaintext APIs export the CDK encrypted with the DEK from an HBK or CSK (electroni- cally)

N/A

Volatile memory

Overwriting with all zeros

Used outside of the module

Page 50
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Data Encryption Key (DEK) CSP256 bits (AES)AES GCM (A1908)Derived inter- nally using SP 800-108 KBKDFInput: N/A Output: N/AN/AVolatile memoryOverwriting with all zerosThe DEK is de- rived from either the HBK or CSK and is used to encrypt the CDK
HSM Agreement Key Pair (dHAK, QHAK) CSP/PSP192 bits (ECDH P384)KAS (A1908) CKGInternally using DRBGInput: N/A Output: The public key (QHAK) is ex- ported in plaintext (elec- tronically)N/AVolatile memoryOverwriting with all zerosThe dHAK/QHAK are used in key agreement oper- ations to encrypt the DKEK
HSM Ephemeral Agreement Key Pair (dE, QE) CSP/PSP192 bits (ECDH P384)KAS (A1908)Internally using DRBGInput: N/A Output: The public key (QE) is exported in plaintext (elec- tronically)N/AVolatile memoryOverwriting with all zerosThe dE/QE is used in key agreement oper- ations to encrypt the DKEK
HSM Agreement DKEK Shared Se- cret Z (HDKZ) CSP192 bits (ECDH P384)KAS (A1908)N/AN/AKAS (SP 800- 56Arev3) (Cofactor) One- Pass Diffie-Hell- man (ECC CDH) scheme with key confirma- tionVolatile memoryOverwriting with all zerosThe HDKZ is the shared secret value Z com- puted using the HSM Agreement Key (dHAK) and the HSM Ephem- eral Agreement Key (QE) The HDKZ is used to derive the HDWK

Establishment Security FuncUse & related Key/SSP Generation Zeroisation Strength Import / Name/Type Number Export Storage keys

Page 51
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
HSM Agreement DKEK Wrapping Key (HDWK) CSP256 bits (One-Step KDF SHA2-256)KDA (A1908)N/AN/AKAS (SP 800- 56Arev3) (Cofactor) One- Pass Diffie-Hell- man (ECC CDH) scheme with key confirma- tionVolatile memoryOverwriting with all zerosThe HDWK is de- rived from the HDKZ and is used to wrap the DKEK

Establishment Security FuncUse & related Key/SSP Generation Zeroisation Strength Import / Name/Type Number Export Storage keys

Page 52
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Domain Key En- cryption Key (DKEK) CSP256 bits (AES)AES GCM (A1908)Internally using DRBG or im- ported from another mem- ber of a DomainInput: The DKEK is encrypted with the HDWK derived using the shared se- cret (HDKZ) generated from the HSM’s Key Agreement Key (QHAK) and an- other HSM’s Ephemeral Key Agreement Key (dE) (electroni- cally) Output: The DKEK is en- crypted with the HDWK derived using the shared secret (HDKZ) generated from the HSM’s Key Agreement Key (dHAK) and an- other HSM’s Ephemeral Key Agreement Key (QE) (electroni- cally)KAS (SP 800- 56Arev3) (Cofactor) One- Pass Diffie-Hell- man (ECC CDH) scheme with key confirma- tion KTS (SP 800- 38F)Volatile memoryOverwriting with all zerosThe DKEK is used to encrypt the DKn when im- ported to other members of a Domain

Establishment Security FuncUse & related Key/SSP Generation Zeroisation Strength Import / Name/Type Number Export Storage keys

Page 53
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Domain Key (DKn) CSP256 bits (AES)AES GCM (A1908) KBKDF (A1910)Internally using DRBG or im- ported from another mem- ber of a DomainInput: DKn en- crypted with the DKEK and may be imported from other members of a Domain (elec- tronically) Output: DKn en- crypted with the DKEK and may be exported to other members of a Domain (electronically)N/AVolatile memoryOverwriting with all zerosKeys derived from the DKn are used to encrypt HBKs and CSKs
HSM Agreement HSKEK Shared Secret Z (HHKZ) CSP192 bits (ECDH P384)KAS (A1908)N/AN/AKAS (SP 800- 56Arev3) (Cofactor) One- Pass Diffie-Hell- man (ECC CDH) scheme with key confirma- tionVolatile memoryOverwriting with all zerosThe HHKZ is the shared secret value Z com- puted using the HSM Agreement Key (dHAK) and the Operator Ephemeral Agreement Pub- lic Key (QOEAK) The HHKZ is used to derive the HSKEK

Establishment Security FuncUse & related Key/SSP Generation Zeroisation Strength Import / Name/Type Number Export Storage keys

Page 54
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
HSM Session Key Encryption Key (HSKEK) CSP256 bits (AES)AES GCM (A1908)Internally using DRBGInput: N/A Output: N/AKAS (SP 800- 56Arev3) (Cofactor) One- Pass Diffie-Hell- man (ECC CDH) scheme with key confirma- tionVolatile memoryOverwriting with all zerosThe HSKEK en- crypts the HSM- Operator Session Key (HOSK) for the following op- erations: Initialize, Ini- tializeAndCreate Domain, Attest, GetAttesta- tionIdentity, and Wipe
HSM Signature Key Pair (dHSK, QHSK) CSP/PSP192 bits (ECDSA P384)ECDSA (A1908) CKGInternally using DRBGInput: N/A Output: The public key (QHSK) is ex- ported in plaintext (elec- tronically)N/AVolatile memoryOverwriting with all zerosThe dHSK is used to sign data cre- ated on the HSM

Establishment Security FuncUse & related Key/SSP Generation Zeroisation Strength Import / Name/Type Number Export Storage keys

Page 55

HSM-Operator Session Key (HOSK) CSP

256 bits (AES)

AES GCM (A1908)

Internally using DRBG, or im- ported from an HSM that is a member of the same domain

Input: The HOSK is input en- crypted with the domain key (DKn) (electroni- cally) Output: The HOSK is en- crypted in two forms to be out- put The first form is encrypted with either the Do- main Key (DKn) or the HSM Ses- sion Key Encryption Key (HSKEK) using AES GCM (elec- tronically) The second form is en- crypted using AES GCM with a 256-bit key de- rived from the shared secret established us- ing elliptic curve Diffie-Hellman key exchange (NIST-P384) us- ing the HSM Ephemeral Agreement Key Pair (dE,QE) and the Operator Ephemeral Agreement Pub- lic Key (dOEAK,

KAS (SP 800- 56Arev3) (Cofactor) One- Pass Diffie-Hell- man (ECC CDH) scheme with key confirma- tion KTS (SP 800- 38F)

Volatile memory

Overwriting with all zeros

The HOSK is used to encrypt communications between a user and HSMs in the same Domain

Page 56
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
QOEAK) (elec- tronically)
Import Wrap- ping Key Pair (dIWK, QIWK) CSP/PSP112 – 128 bits (RSA 2048, 3072 or 4096 bits)KTS (RSA-OAEP) (A1908)Internally using DRBG or im- ported from another mem- ber of a DomainInput: The pri- vate key (dIWK) is encrypted with the Do- main Key (DKn) using AES-GCM for input (elec- tronically) Output: the pri- vate key (dIWK) is encrypted with the Do- main Key (DKn) using AES-GCM. The public key (QIWK) is ex- ported in plaintext (elec- tronically)N/AVolatile memoryOverwriting with all zerosThe public key is used by custom- ers of KMS to wrap their CSK for import via the public AWS KMS API

Establishment Security FuncUse & related Key/SSP Generation Zeroisation tion and Cert. Strength Name/Type Number Export Storage keys

Page 57
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Import Wrap- ping Envelope Key (IWEK) CSP256 bits (AES)AES KWP (A1908)Externally by AWS KMS cus- tomersInput: IWEK is encrypted using the Import Wrapping Key (QIWK) when used with the ImportKey API when the cus- tomer imports a CSK into the AWS KMS sys- tem (electronically) Output: N/AKTS-RSAVolatile memoryOverwriting with all zerosThis key is gener- ated by a customer exter- nal to the AWS KMS system and is used to en- crypt CSKs for the ImportKey API when AES- KWP is used per SP 800-56B

Establishment Security FuncUse & related Key/SSP Generation Zeroisation tion and Cert. Strength Name/Type Number Export Storage keys

Page 58
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Customer Sup- plied Key (CSK) CSP/PSP256 bits (AES) 160-256 bits (HMAC) 112 – 128 bits (RSA 2048, 3072 or 4096 bits) 128 – 256 bits (ECDSA P-256, P-384, P-521, or secp256k1)AES GCM HMAC RSA ECDSA (A1908)Externally by AWS KMS cus- tomersInput: CSK is en- crypted using Import Wrap- ping Key (QIWK) (and, optionally, the ephemeral Import Wrap- ping Envelope Key (IWEK)) when used with the ImportKey API when the customer im- ports the key into the AWS KMS system After import, the CSK is en- crypted with the Domain Key us- ing AES GCM (electronically) Output: CSK en- crypted by a Domain Key (DKn) (electroni- cally)KTS-OAEP with- out key confirmation KTS-RSA Hybrid Key-Transport scheme incorpo- rating KTS-OAEP and SP 800-38FVolatile memoryOverwriting with all zerosThis key is gener- ated by a customer of KMS outside the AWS KMS system to sign or encrypt plaintext It can also be used to encrypt CDKs
Entropy Input String CSP384 bitsRandom Num- ber Generation ENT (P)Internal entropy sourceInput: N/A Output: N/AN/AVolatile memoryOverwriting with all zerosRandom Num- ber Generation

Establishment Security FuncUse & related Key/SSP Generation Zeroisation tion and Cert. Strength Name/Type Number Export Storage keys

Page 59
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
DRBG (CTR AES) V and AES key CSPSP 800-90A CTR DRBG V (128 bits) AES key (256 bits)DRBG AES CTR AES-ECB (A1908)Internal entropy sourceInput:N/A Output: N/AN/AVolatile memoryOverwriting with all zerosEntropy input (length depend- ent on security strength)
DRBG (CTR AES) Seed CSP256 bitsDRBG AES CTR AES-ECB (A1908)Internal entropy sourceInput: N/A Output: N/AN/AVolatile memoryOverwriting with all zerosSeeding mate- rial for the DRBG. Used to derive the DRBG (AES CTR) V and AES key
Replication Sign- ing Key Pair (dRSKn, QRSKn) CSP/PSP192 bits (ECDSA P384)ECDSA (A1908)Internally using DRBG or im- ported from another mem- ber of a DomainInput: dRSK en- n crypted with the DKEK may be imported from other members of a Domain; QRSK may be n imported by an operator (elec- tronically) Output: dRKS n encrypted with the DKEK may be exported to other members of a Domain; QRSK may be n exported in plaintext (elec- tronically)N/AVolatile memoryOverwriting with all zerosThe private key (dRSK ) is used n to sign the out- puts of GetParameters- ForReplication and Wrap- KeyForReplicatio n APIs The public key (QRSK ) is used n to verify the in- put of WrapKeyForRep- lication and ImportReplicat- edKey APIs

Establishment Security FuncUse & related Key/SSP Generation Zeroisation tion and Cert. Import / Name/Type Number Export Storage keys

Page 60
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Replication Agreement Key (dRAK, QRAK) k k CSP/PSP192 bits (ECDH P384)ECDH (A1908) CKGInternally using DRBG or im- ported from a member of a different Do- mainInput: QRAK k may be im- ported in plaintext from another HSM; dRAK may be k imported en- crypted with the domain key (DK ) from an- n other HSM (electronically) Output: QRAK k may be ex- ported in plaintext; dRAK k may be ex- ported encrypted with the domain key (DK ) (electroni- n cally)N/AVolatile memoryOverwriting with all zerosKeys used for key agreement to derive a Repli- cation Wrapping Key (RWK)

Establishment Security FuncUse & related Key/SSP Generation Zeroisation tion and Cert. Strength Import / Name/Type Number Export Storage keys Output: QRAKk plaintext; dRAKk (DKn) (electroni-

Page 61
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Replication Agreement RWK Shared Secret Z (RRZ) CSP192 bits (ECDH P384)KAS (A1908)N/AN/AKAS (SP 800- 56Arev3) (Cofactor) One- Pass Diffie-Hell- man (ECC CDH) scheme with key confirma- tionVolatile memoryOverwriting with all zerosThe RRZ is the shared secret value Z com- puted using the private portion of a region’s Replication Agreement Key (dRAK) and the k public portion of another region’s Replication Agreement Key (QRAK) k The RRZ is used to derive the RWK
Replication Wrapping Key (RWK) CSP256 bits (AES)AES GCM (A1908)Internally de- rived from a Public Replica- tion Agreement Key (QRAK ) and 1 a Private Repli- cation Agreement Key (dRAK ) 2Input: N/A Output: N/AKAS (SP 800- 56Arev3) (Cofactor) One- Pass Diffie-Hell- man (ECC CDH) scheme with key confirma- tionVolatile memoryOverwriting with all zerosThe RWK is used to encrypt an HBK. It is derived from a key agreement oper- ation between the QRAK from k an HSM in an- other security domain and the dRAK in the lo- k cal HSM security domain

Establishment Security FuncUse & related Key/SSP Generation Zeroisation Strength Import / Name/Type Number Export Storage keys (QRAKk)

Page 62
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Customer Repli- cation Key (CRK) CSP/PSP256 bits (AES, HMAC) 112 to 128 bits (RSA: 2048, 3072, or 4096 bits) 128 to 256 bits (ECDSA: P256, P384, P521, or secp256k1)AES GCM HMAC RSA ECDSA (A1908)Internally from an HBK en- crypted with a domain key (DKn)Input: CRK may be imported by decrypting an HBK using a do- main key (DK ) n and re-encrypt- ing it using a Replication Wrapping Key (RWK) (elec- tronically) Output: CRK is exported en- crypted with a Replication Wrapping Key (RWK) (elec- tronically)KAS (SP 800- 56Arev3) (Cofactor) One- Pass Diffie-Hell- man (ECC CDH) scheme with key confirma- tionVolatile memoryOverwriting with all zerosThe CRK is the customer key that is being transmitted be- tween two HSMs CRKs are wrapped with the RWK
Operator Ephemeral Agreement Pub- lic Key (QOEAK) PSP192 bits (ECDH P384)ECDH (A1908)Externally by the module op- eratorInput: When an operator calls the NegotiateS- essionKey service (elec- tronically) Output: N/AN/AVolatile memoryOverwriting with all zerosThe QOEAK is provided by an operator to es- tablish a session key (HOSK) It is used with the HSM ephem- eral agreement key (dE) using ECC CDH

Establishment Security FuncUse & related Key/SSP Generation Zeroisation Strength Import / Name/Type Number Export Storage keys

Page 63
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Operator Signa- ture Public Key (QOS) PSP192 bits (ECDSA P384) 112 to 128 bits (RSA: 2048, 3072, or 4096 bits)ECDSA RSA (A1908)Externally by the module op- eratorInput: The pub- lic key (QOS) is imported in plaintext when an administra- tor calls InitializeAndCre- ateDomain, CreateDomain, and ChangeDo- main They are also imported by APIs that accept a Domain Token (electronically) Output: The public keys are exported from the HSM in plaintext by APIs that export a Domain Token (electronically)N/AVolatile memoryOverwriting with all zerosThe QOS is used by the HSM to authenticate op- erators

Establishment Security FuncUse & related Key/SSP Generation Zeroisation tion and Cert. Strength Import / Name/Type Number Export Storage keys

Page 64
P S S / y e Ke p y T / e m a Nh t g n e r t S- c n u F y t ir u c e S.t r e C d n a n o itr e b m u Nn o it a r e n e G/ t r o p m It r o p x Et n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Zd e t a le r & e s Us y e k
Customer Data Encryption Pub- lic Key (QCDEK) PSP112 to 128 bits (RSA: 2048, 3072, or 4096 bits)RSA (A1908)Externally by the module op- eratorInput: The pub- lic key (QCDEK) is optionally provided when an operator calls Generate, GenerateAndEn- cryptRandomBy tes, Generate- DataKeyPair, and Decrypt (electronically) Output: N/AN/AVolatile memoryOverwriting with all zerosThe QCDEK is provided by an operator or cus- tomer to encrypt the SCDEK, which encrypts customer data
Customer Data Encryption Sym- metric Key (SCDEK) PSP128 bits, 256 bits (AES)AES GCM AES CBC (A1908)Internally using DRBGInput: N/A Output: En- crypted by QCDEK (elec- tronically)N/AVolatile memoryOverwriting with all zerosThe SCDEK en- crypts customer plaintext data. If a QCDEK is op- tionally provided for Generate, GenerateAndEn- cryptRandomByt es, Generate- DataKeyPair, or Decrypt, a SCDEK will be gener- ated within the module to en- crypt the resulting cus- tomer plaintext data.

Establishment Security FuncUse & related Key/SSP Generation Zeroisation tion and Cert. Strength Import / Name/Type Number Export Storage keys Table 13 – SSPs

Page 65
Entropy sourcesMinimum number of bits of entropyDetails
Intel Deterministic Random Number Generator384 bits of seed material is requested from the entropy source which provides full entropyUsed only to seed the DRBG in the module. 512 bits of entropy data with 0.7 bits of min entropy per bit is provided to the vetted conditioning function, 128-bit AES-CBC-MAC. The conditioning function is called three times for the 384-bit entropy input into the DRBG.

Table 14 – Non-Deterministic Random Number Generator Specification

Page 66

10. Self-Tests FIPS 140-3 requires the module to perform self-tests to ensure the integrity of the module and the correctness of the cryptographic functionality at start up. Some functions require conditional tests during normal operation of the module. All of these tests are listed and described in this section. In the event of a self-test error, the module will log the error and enter the error state. Once in the error state, all SSPs are zeroized and the module becomes unusable. Pre-Operational Self-Tests Pre-operational self-tests are run upon the initialization of the module and do not require operator intervention to run. If any of the tests fail, the module will not initialize. The module will enter an error state and no services can be accessed by the operator. The module implements the following pre-operational self-tests: Integrity Check 256-bit error detection code (EDC) on all module components The module performs all pre-operational self-tests automatically when the module is initialized. All pre-operational self-tests must be passed before a Crypto Officer can perform services. The pre-operational self-tests can be run on demand by rebooting the module. Conditional Self-Tests The module performs all conditional self-tests automatically when the module is initialized. All conditional self-tests must be passed before a Crypto Officer can perform services.. If any of these tests fail, the module will enter an error state, where no services can be accessed by the operators. The module can be re-initialized to clear the error and resume Approved mode of operation. Each module performs the following conditional self-tests: Cryptographic Algorithm Self Tests

Page 67
Page 68
  1. Life-cycle Assurance Delivery and Operation The AWS Key Management Service HSM is designed to be mounted in a rack only. Before mounting onto a rack, the module should be inspected for signs of physical tampering. Connect the power interface to the power connector in the rack. Power up the module. The module will start up in the approved mode of operation. No other configuration is necessary. End of Life To prepare a module for disposal:
  2. Remove all domain information on the module using the ForgetDomain API
  3. Delete the HSM Signature Key and HSM Agreement Key from the HSM using the Wipe API
  4. Return the HSM to the factory state using the DeactivateAndReboot API. This step also zeroizes volatile memory as part of the reboot process
  5. Power down the module by disconnecting the module from the power source To securely destroy a module:
  6. To open the chassis, drill though all fasteners that secure the cover to the chassis and remove the cover.
  7. Remove and destroy the solid state drive and memory modules in accordance with NIST SP 800-88rev1.
Page 69

12. Mitigation of Other Attacks Not Applicable.

Page 70

AES

Advanced Encryption Standard

Table, extracted as text (did not parse into structured rows)
Appendix A - Acronyms ANSI         American National Standards Institute API          Application Programming Interface AWS          Amazon Web Services CBC          Cipher Block Chaining CDK          Customer Data Key CMK          Customer Managed Key CMVP         Cryptographic Module Validation Program CO           Crypto Officer CSE          Communications Security Establishment Canada CSK          Customer Supplied Key CSP          Critical Security Parameter CTR          Counter DH           Diffie-Hellman DKn          Domain Key DKEK         Domain Key Encryption Key DRBG         Deterministic Random Bit Generator ECB          Electronic Codebook EC           Elliptic Curve ECDSA        Elliptic Curve Digital Signature Algorithm EMC          Electromagnetic Compatibility EMI          Electromagnetic Interference FCC          Federal Communications Commission FIPS         Federal Information Processing Standard GCM          Galois/Counter Mode HBK          HSM Backing Key HMAC         (Keyed-) Hash Message Authentication Code HOSK         HSM-to-Operator Session Key HSK          HSM Signature Key Pair HSKEK        HSM Session Key Encryption Key HSM          Hardware Security Module IPMI         Intelligent Platform Management Interface KAS          Key Agreement Scheme KAT          Known Answer Test KBKDF        Key Based Key Derivation Function KDF          Key Derivation Function KMS          Key Management Service KTS          Key Transport Scheme
Page 71
Table, extracted as text (did not parse into structured rows)
MAC   Message Authentication Code MD    Message Digest NIST  National Institute of Standards and Technology NMI   Non-Maskable Interrupt OAEP  Optimal Asymmetric Encryption Padding PKCS  Public-Key Cryptography Standards PSS   Probabilistic Signature Scheme QOEAK Operator Ephemeral Agreement Public Key QOS   Operator Signature Public Key RNG   Random Number Generator RSA   Rivest, Shamir, and Adleman SHA   Secure Hash Algorithm SP    Special Publication SSP   Sensitive Security Parameter