All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Quadient Postal Security Device

Certificate#4909StandardFIPS 140-3Level3TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorQuadient Technologies
Medium review priority  ·  exposes firmware-update authentication  ·  last validated 19 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date12/2/2026
CaveatInterim Validation
VendorQuadient Technologies

Approved Algorithms (17)

AlgorithmACVP Cert
AES-CBCA728
AES-CBCA728
AES-CMACA760
Conditioning Component Block Cipher Derivation Function SP800-90BA3803
Counter DRBGA2930
DSA KeyGen (FIPS186-4)A767
ECDSA KeyGen (FIPS186-4)A2931
ECDSA SigGen (FIPS186-4)A2931
ECDSA SigVer (FIPS186-4)A2931
HMAC-SHA-1A729
HMAC-SHA2-256A729
HMAC-SHA2-256A729
KAS-FFC-SSC Sp800-56Ar3A2929
KDF TLSA761
RSA KeyGen (FIPS186-4)A765
SHA-1A730
SHA2-256A730

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Quadient Postal Security Device
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>status output<br/>Unauthenticated<br/>Self-test</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Quadient Postal Security Device
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>status output<br/>Unauthenticated<br/>Self-test</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Classification: External Quadient Postal Security Device Security Policy Valid from: 27/11/2024 Version No.: V 1.2 This document is non-proprietary. It may be reproduced or transmitted only in its entirety without revision. © Quadient

Page 2

Classification: External Document Name: Security Policy Content Page 2/28

Page 3

Classification: External Document Name: Security Policy Page 3/28

Page 4

Classification: External Document Name: Security Policy Figure list Table list Page 4/28

Page 5
ISO/IEC 24759 Section 6FIPS 140-3 Section TitleSecurity Level
1General3
2Cryptographic module specification3
3Cryptographic module interfaces3
4Roles, services, and authentication3
5Software/Firmware security3
6Operational environmentN/A
7Physical security3
8Non-invasive securityN/A
9Sensitive security parameter management3
10Self-tests3
11Life-cycle assurance3
12Mitigation of other attacks3
Overall Level3

Classification: External Document Name: Security Policy This document describes the security policy of the Quadient Technologies France (Quadient) Postal Security Device under the terms of FIPS 140-3 validation. This document contains a statement of the security rules under which the Quadient Postal Security Device operates. The Quadient Postal Security Device is designed to meet the overall requirements applicable for FIPS 140-3 Table 1: Security Levels Page 5/28

Page 6
ModelHardware Part NumberFirmware Part NumberFirmware Version
Quadient Postal Security DeviceA0014227-B and A0014227-CA0156569Aa31.05

Classification: External Document Name: Security Policy 2. Cryptographic module specification 2.1. Overview The Quadient Postal Security Device is a hardware cryptographic module embedded within Quadient postal franking machines. The Quadient Postal Security Device performs all franking machine’s cryptographic and postal security functions and protects the Critical Security Parameters (CSPs) and Postal Relevant Data from unauthorized access. Table 2: Cryptographic Module Tested Configuration The Quadient Postal Security Device (Figure 1) is a multi-chip standalone cryptographic module enclosed within a hard, opaque, plastic enclosure encapsulating the epoxy potted module which is wrapped in a tamper detection envelope with a tamper response mechanism. This enclosure constitutes the cryptographic module’s physical boundary. 2.2. Excluded Components The module does not exclude any components from the requirements of FIPS 140-3. 2.3. Modes of operation The module only supports an Approved mode of operation that is entered upon powering-on the module. The module does not support a degraded mode of operation. Page 6/28

Page 7
CAVP Cert.Algorithm and StandardModes/ MethodsDescription/ Key Size(s)/ Key Strength(s)Use/Function
Cert. #A728AES CBC FIPS 197 SP 800-38ACBC128Encryption/Decryption of: • CSPs for storage within the module • Data exchanged using TLS v1.2
Cert. #A760AES CMAC FIPS 197 SP 800-38BAES128Indicia Authentication
Cert. #A3803Conditioning Component Block Cipher SP 800-90BN/AN/AConditioning component of module’s entropy source.
Cert. #A2930CTR-DRBG SP 800-90AAES128Key generation
Cert. #A761CVL (KDF TLS) SP 800-135SHA-256TLS 1.2 KDF
Cert. #A767DSA FIPS 186-4KeyGen(2048, 224)Used for KAS-SSC
Cert. #A2931ECDSASHA-256P-224, P-256Key Generation, Digital Signature
FIPS 186-4Generation (Indicia Authentication)1
Cert. #A729HMAC-SHA-1,(Key Sizes160 256TLS messages authentication, Indicia AuthenticationTLS messages authentication,
HMAC-SHA-256Ranges Tested:Indicia Authentication
FIPS 198-1KS<BS)

Classification: External Document Name: Security Policy 2.4. Security industry protocols The cryptographic module implements the TLS v1.2 protocol and uses only one cipher suite (TLS-DHE-RSAWITH-AES-128-CBC-SHA256). The TLS protocol is composed of TLS Handshake protocol (used for mutual authentication and TLS pre-master secret establishment) and TLS Record protocol (used for application data confidentiality and integrity). 2.5. Security functions 2.5.1. Approved Algorithms The Quadient Postal Security Device supports the following approved security functions:

1 ECDSA P-244 Signature Verification is included on the algorithm certificate but not used by the module.

Page 8
CAVP Cert.Algorithm and StandardModes/ MethodsDescription/ Key Size(s)/ Key Strength(s)Use/Function
Cert. #A2929KAS-SSC SP 800-56A r3FFC DH112Key agreement used to establish TLS session keys C(2e, 0s, FFC DH), with DSA KeyGen (Cert. #A767) as a prerequisite, using loaded ffdhe2048 safe prime domain parameters. Provides 112 bits of encryption strength.
AES (Cert. #A728) HMAC (Cert. #A729)KTS SP 800-38FAES CBC HMAC-SHA-256128 bits 256 bitsTLS key transport scheme, using keys established with KAS-SSC and TLS KDF. Provides 112 bits of encryption strength.
Cert. #A765RSA FIPS 186-4SHA-256 PKCS1 v1.52048Key Generation Signature generation/Signature verification of X509 certificates used by TLS Handshake protocol, Signature verification of signed files imported into the module2
Cert. #A730SHS FIPS 180-4SHA-1, SHA-256N/AHashing algorithm used for: • HMAC Generation • Digital signatures
Algorithm and StandardModes/ MethodsDescription/ Key Size(s)/ Key Strength(s)Use/Function
CKG SP 800-133r2CKGPer Sections 4 and 5.2The unmodified output from SP 800-90A DRBG (128 bits)The unmodified output of the DRBG is
SP 800-133r2used for symmetric and asymmetric key generation
Algorithm and StandardModes/ MethodsDescription/ Key Size(s)/ Key Strength(s)Use/Function
N/AN/AN/AN/A
Table, extracted as text (did not parse into structured rows)
Classification:                  External Document Name:                   Security Policy Table 3: Approved Algorithms 2.5.2.         Vendor Affirmed Algorithms The module supports the following vendor affirmed algorithms. Table 4: Vendor Affirmed Algorithms 2.5.3.         Allowed Algorithms The module supports only approved algorithms. N/A                       N/A                          N/A                                   N/A Table 5: Allowed Algorithms

2 RSA Signature Verification to FIPS 186-2 with modulo 1536 is listed on the algorithm certificate but not utilized by the module.

Page 9
Algorithm and StandardModes/ MethodsDescription/ Key Size(s)/ Key Strength(s)Use/Function
N/AN/AN/AN/A
NameTypeDescriptionSF PropertiesAlgorithms / CAVP Cert.
KASKASNIST SP 800- 56Arev3 KAS-SSC Per IG D.F Scenario 2 path (2).FFC (2048, 224) Providing 112 bits of encryption strengthKAS-SSC (Cert. #A2929) CVL (Cert. #A761)
KTSKTSNIST SP 800-38F. KTS (key wrapping and unwrapping) per IG D.G.128-bit key providing 128 bits of encryption strengthAES-CBC (Cert. #A728) HMAC-SHA-256 (Cert. #A729)
Vendor NameCertificate Number
Quadient Technologies FranceE58

Classification: External Document Name: Security Policy 2.5.4. Non-Approved Algorithms The module supports only approved algorithms. N/A N/A N/A N/A Table 6: Non-Approved Algorithms 2.5.5. Security Function Implementations (SFI) (2). Table 7: Security Function Implementations 2.5.6. Entropy Sources The module includes an internal entropy source for the generation of the DRBG seed. Please refer to the entropy source validation (ESV) certificate E58. Table 8: Entropy Source Implementations The entropy source generates 384 bits of entropy input which is combined with a 64-bit nonce, 64-bit personalization string, and 128 bits of additional input. This input is used to instantiate (or reseed) the CTRDRBG. The entropy source has a rate of 88% and therefore provides the DRBG with a full 128-bit security 2.5.7. Key Establishment The module supports the establishment of cryptographic keys using finite field cryptography (FFC) in conformance with NIST SP 800-56A Rev3. The module implements KAS-FFC-SSC per NIST SP 800-56A Rev3 (Cert. #A2929), used in conjunction with TLS KDF per NIST SP 800-135 (Cert. #A761). Key establishment methodology provides at least 112 bits of encryption strength. This is used to establish TLS v1.2 Page 9/28

Page 10
Physical PortLogical InterfaceData that passes over port/interface
PIN 1: GroundN/AN/A
PIN 2: GroundN/AN/A
PIN 3: RXdata input/control inputPSD TLS Communication Certificate chain Indicia Authentication Secret Key
PIN 4: RXdata input/control inputPSD TLS Communication Certificate chain

Classification: External Document Name: Security Policy communication sessions in conformance with NIST SP 800-38F using AES (Cert. #A728) and HMAC (Cert. #A729). 2.6. Security Rules This section documents the security rules applied by the cryptographic module to implement the security requirements of a FIPS 140-3 level 3 module:

  1. The PSD shall process only one request at a time (single thread). The PSD will ignore all other inputs to the module while processing the request. The only output performed by the PSD is the response to the request.
  2. Quadient Postal Security Device shall employ identity-based authentication mechanism.
  3. All authenticated sessions shall end when the module is power cycled.
  4. All keys generated in the module shall have at least 112 bits of cryptographic security strength for an Approved mode of operation.
  5. The module shall not provide any bypass capability.
  6. The PSD shall not support a maintenance role.
  7. The PSD shall not support manual input or output of CSPs.
  8. The PSD shall perform pre-operational and conditional self-tests without external control or operator intervention either in approved or non-approved mode. The PSD shall pass into the error state if the test fails.
  9. The PSD shall automatically perform periodic self-tests without external input or control. The PSD shall enter the error state if the test fails.
  10. The PSD shall inhibit all data output interfaces when performing self-tests, firmware loading, zeroization or while in the error state.
  11. The module shall not output any CSP in plaintext form.
  12. The module shall not accept any CSP in plaintext form.
  13. The PSD shall test the accessibility and validity of all CSP values in nonvolatile memories at power up. If any are not accessible (i.e., device failure) or contain erroneous data (16-bit EDC fails) then the PSD shall enter in error state.
  14. The PSD shall enter in the Faulted state and zeroize all SSPs if physical cryptographic boundary is breached or if the temperature inside the module exceeds 84°C.
  15. Once the PSD has been zeroized, it must be returned to the factory for destruction.
  16. Cryptographic module interfaces To communicate with the franking machine’s base the cryptographic module provides a physical 10-pin serial connector with five logical interfaces: Page 10/28
Page 11
Indicia Authentication Secret Key
PIN 5: TXdata output/status outputPSD TLS Communication Certificate chain PSD DH Public Key Indicia Authentication Public Keys
PIN 6: TXdata output/status outputPSD TLS Communication Certificate chain PSD DH Public Key Indicia Authentication Public Keys
PIN 7: PowerpowerN/A
PIN 8: PowerpowerN/A
PIN 9: GroundN/AN/A
PIN 10: GroundN/AN/A

Classification: External Document Name: Security Policy Table 9: Ports and Interfaces The data output interface and cryptographic operations are inhibited during zeroization, key generation, self-tests, and error states. No plaintext CSPs are input or output from the module through this serial interface. 4. Roles, services, and authentication 4.1. Roles The Quadient Postal Security Device supports authorized roles for operators and corresponding services within each role. The Quadient Postal Security Device supports the following Crypto-Officer roles: Field Crypto-Officer and Postal Crypto-Officer. The Quadient Postal Security Device supports the following User roles: Base User, R&D Signer and Unauthenticated User. For each role, the Quadient Postal Security Device provides the following services and the corresponding input and outputs: Page 11/28

Page 12
RoleServiceInputOutput
Field Crypto-OfficerTLS HandshakeField Server TLS Communication Certificate chain, Field Server DH Public parameters (p, g, Y)Field Server TLS Communication Certificate chain,PSD TLS Communication Certificate chain,
Field Server DH Public parameters (p, g, Y)TLS DH Public Key (Y)
Generate PKI KeyN/APSD TLS Communication Certificate (self-signed)
Get PKI CertificateN/APSD TLS Communication Certificate chain
Set PKI CertificatePSD TLS Communication Certificate chainN/A
Postal Crypto-OfficerTLS HandshakePostal Server TLS Communication Certificate chain, Postal Server DH Public parameters (p, g, Y)PSD TLS Communication Certificate chain, TLS DH Public Key (Y)
Generate Stamp KeyExpiry dateIndicia Authentication Secret or Private and Public Keys
Set Stamp KeyIndicia Authentication Key (encrypted), expiry dateN/A
Software downloadUtility certificate, Root CertificateOk or error code
Postal services (set resetting value, get statistic)Postal dataPostal data, status
Read Status (Get Device Info service)N/APSD State
Read Part Number (Get Device Info service)N/APART_NUMBER (package/firmware)
Base UserTLS HandshakeBase TLS Communication Certificate chain, Base DH Public Key (Y)PSD TLS Communication Certificate chain, TLS DH Public parameters (p, g, Y)
Postal IndiciaIndicia input dataIndicia digital signature or MAC
Read Status (Status request)N/APSD State
Read Part Number (Get Device Info service)N/APART_NUMBER (package/firmware)
Self-testN/AOk or error message
Get Error LogN/AError log information, includes most recent error codes, date & time stamps

Classification: External Document Name: Security Policy Page 12/28

Page 13
RoleServiceInputOutput
R&D Signer UserVerify Files (Check File)Utility Certificate, Root Certificate, file’s signature & hashOk or error code
TLS HandshakeR&D Signer Communication Certificate chain R&D Signer User DH Public Key (Y)PSD TLS Communication Certificate chain, TLS DH Public parameters (p, g, Y)
Unauthenticated UserRead Status (Status request)N/APSD State
Read Part Number (Get Device Info service)N/APART_NUMBER (package/firmware)
Zeroize SSPN/AOk or error code

Classification: External Document Name: Security Policy Table 10: Roles, Service Commands, Input and Output Page 13/28

Page 14
RoleAuthentication MethodAuthentication Strength (bits)
Field Crypto-OfficerTLS 1.2 handshake, X509 certificates112
Postal Crypto-OfficerTLS 1.2 handshake, X509 certificates112
Base UserTLS 1.2 handshake, X509 certificates112
R&D Signer UserTLS 1.2 handshake, X509 certificates112
Unauthenticated UserN/AN/A

Classification: External Document Name: Security Policy To control access to the module the Quadient Postal Security Device employs identity-based authentication mechanism. For each role, the Quadient Postal Security Device provides the following authentication method: Table 11: Roles and Authentication Mutual authentication is based on the TLS v1.2 Handshake Protocol using the "TLS-DHE-RSA" cryptographic suite, with 2048 RSA key length for authentication.

Page 15
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to keys and/or SSPsIndicator
Generate PKI KeyAsk the module to generate its TLS communication key pairRSA 2048, DRBG, AES 128RSA 2048,PSD TLS Communication Private and Public Keys, DRBG entropy input (if needed), DRBG parameters – Key & V, Master Secret KeyField Crypto-Officer(G) PSD TLSAPPR_MODE
DRBG,Communication
AES 128Private Key, (G) PSD TLS Communication Public Key (X509 certificate), (G, E) DRBG entropy input (if needed), (G, E) DRBG parameters – Key & V, (E) Master Secret Key
Get PKI CertificateAsk the module to send its TLS communication certificateN/APSD TLS Communication Public Key (TLS Communication Certificate chain)Field Crypto-Officer(R) PSD TLS Communication Public Key (TLS Communication Certificate chain)APPR_MODE
Set PKI CertificateSet the TLS communication certificateRSA 2048, SHA-256PSD TLSField Crypto-Officer(W) PSD TLSAPPR_MODE
CommunicationCommunication
Public Key (TLSPublic Key (TLS
CommunicationCommunication
Certificate chain),Certificate chain),
Root Public Key,(E) Root Public Key,
Previous Root Public(E) Previous Root
KeyPublic Key

Classification: External Document Name: Security Policy 4.3. Services 4.3.1. Approved services Page 15/28

Page 16
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to keys and/or SSPsIndicator
Generate Stamp KeyAsk the module to generate Indicia Authentication Key(s) (Secret or Private/Public, depending on country configuration)HMAC-SHA-1 or HMAC-SHA-256 or CMAC AES 128 or ECDSA P-224 or ECDSA P-256, SHA-256, DRBG, CBC AES 128Indicia Authentication Secret or Private & Public Key, DRBG entropy input (if needed), DRBG parameters – Key & V, Master Secret KeyPostal Crypto-Officer(G) Indicia Authentication Secret Key or (G) Indicia Authentication Private and Public Keys, (G, E) DRBG entropy input (if needed), (G, E) DRBG parameters – Key & V, (E) Master Secret KeyAPPR_MODE
Postal IndiciaAsk the module to print the indiciaHMAC-SHA-1 or HMAC-SHA-256 or CMAC AES 128 or ECDSA P-224 or ECDSA P-256, SHA-256, DRBG, AES 128Indicia Authentication Secret Key, Indicia Authentication Private Key, Master Secret KeyBase User(E) Indicia Authentication Secret Key or (E) Indicia Authentication Private Key, (E) Master Secret KeyAPPR_MODE
Set Stamp KeyImport encrypted Indicia Secret keyAES 128 CMAC AES 128Indicia Authentication Secret Key, Master Secret KeyPostal Crypto-Officer(W) Indicia Authentication Secret Key, (E) Master Secret KeyAPPR_MODE
Read Status (Status)Show statusN/AN/APostal Crypto-Officer,N/AAPPR_MODE
Base User,(Get device info,
Unauthenticated UserStatus_rep)
Read Part NumberShow versionN/AN/APostal Crypto-Officer, Base User, Unauthenticated UserN/AAPPR_MODE (Get device info/ Part_Nb_Rep, Part_Nb_Soft_Rep)

Classification: External Document Name: Security Policy Page 16/28

Page 17
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to keys and/or SSPsIndicator
TLS HandshakeTLS handshake protocolRSA 2048, SHA-256, KAS-SSC (DH), KDF (CVL)RSA 2048, SHA-256,PSD TLS Communication Public Key, TLS DH Private Key (x), TLS DH Public parameters (p, g Y) or TLS DH Public Key (Y), TLS Communication Secret Keysets, TLS pre-master key, TLS master key, Field Server or Postal Server or Base or R&D Signer User Public Key, DRBG entropy input (if needed), DRBG parameters – Key & V, Master Secret KeyField Crypto-Officer, Postal Crypto-Officer, Base User, R&D Signer User(E) PSD TLSAPPR_MODE Status_REQ before and after TLS Handshake
KAS-SSC (DH), KDF (CVL)Communication Public Key (TLS Communication Certificate chain), (G) TLS DH Private Key (x), (G) TLS DH Public Key (Y) or (G) TLS DH Public parameters (p, g, Y), (G) TLS pre-master key, (G) TLS master key, (G) TLS communication secret keyset, (E) Field Server or Postal Server or Base or R&D Signer User Public Key, (G, E) DRBG entropy input (if needed), (G, E) DRBG parameters – Key & V, (E) Master Secret Key
Verify FilesVerify file’s signatureRSA 2048, SHA-256Utility Public Key (Utility Certificate), Root Public Key (Root Certificate)R&D Signer User(E) Utility Public Key (Utility Certificate), (E) Root Public Key (Root Certificate)APPR_MODE
Zeroize SSPZeroise all SSPsN/AAll SSPs listed in TableUnauthenticated User(Z) SSPs listed in TableAPPR_MODE and
1515Zeroization indicator

Classification: External Document Name: Security Policy Page 17/28

Page 18
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to keys and/or SSPsIndicator
Self-testAES (CBC 128), AES (CMAC 128), DRBG, ECDSA (P-224), ECDSA (P-256), HMAC (SHA-1), HMAC (SHA-256), KAS-SSC, TLS-KDF, RSA, SHA-1, SHA-256N/ABase UserN/AAPPR_MODE
Postal ServicesSet resetting value AuditN/AN/APostal Crypto-OfficerN/AN/A
Get Error LogGet the module’s most recent error codeN/AN/ABase UserN/AAPPR_MODE
Software DownloadFirmware updateRSA 2048, SHA-256Utility Public Key (Utility Certificate), Root Public Key (Root Certificate)Postal Crypto-Officer(E/W) Utility Public Key (Utility Certificate), (E) Root Public Key (Root Certificate)APPR_MODE

Classification: External Document Name: Security Policy Table 12: Approved Services G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. Page 18/28

Page 19
Physical Security MechanismRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Non-removable enclosureInspected for tampering each time the module is returned to Quadient manufacturing or for servicing.Visual inspection
Tamper detection and responseInspected for tampering each time the module is returned to Quadient manufacturing or for servicing.Verify log files

Classification: External Document Name: Security Policy 4.3.2. Non-approved services The module does not support any non-approved services.

  1. Software/Firmware security At power-up, the Quadient Postal Security Device tests the integrity of its firmware (binary file) by verifying the RSA 2048 PKCS1 v1.5 signature with SHA-256 hash function. If the signature verification fails, the PSD enters an error state. At any time, the operator can initiate the firmware integrity test on demand by either power-cycling the module or calling the ‘Self-Test’ service.
  2. Operational environment The cryptographic module’s operational environment is limited. The Quadient Postal Security Device is designed to meet FIPS 140-3 Level 3 Physical Security requirements. The Quadient Postal Security Device includes a non-removable enclosure that comprises a hard epoxy resin with an outer plastic casing. The outer plastic casing is defined as the cryptographic boundary of the cryptographic module. The Quadient Postal Security Device employs a tamper detection envelope designed to detect penetration attempts and a response mechanism that will zeroize all plaintext Sensitive Security Parameters. Table 13: Physical Security Inspection Guidelines Quadient Postal Security Device was designed to securely operate when voltage supplied to the module is between 9.6V and 15.6V and the environmental temperature is between -30°C and 84°C. The module mitigates environmental attacks by using a high temperature fuse so that when the temperature of the module exceeds 84°C the module zeroizes all plaintext SSPs. Page 19/28
Page 20
Temperature or voltage measurementEFP / EFTSpecify if this condition results in a shutdown or zeroisation
Low temperature-30°CEFTThe PSD ceases operation
High temperature+84°CEFPZeroization
Low voltage9.6VEFTUndervoltage protection (infinite while loop)
High voltage15.6VEFTOvervoltage protection

Classification: External Document Name: Security Policy Table 14: EFP/EFT The non-removable enclosure and epoxy resin maintain strength and hardness characteristics over the operating, storage and distribution temperature range of the PSD, i.e. -30°C and 84°C. 8. Non-invasive security The module does not provide protections against non-invasive security methods. Page 20/28

Page 21
Key/SSP Name/TypeStrengthSecurity Function and Cert. NumberGenerationImport/ ExportEstablishmentStorageZeroisationUse & related keys
Master Secret Key128AES CBC 128 bits (Cert. #A728)AES CBC 128 bitsInternally: DRBGN/AN/APlaintext in volatile memory protected by tamper response mechanism- Invocation of “ZeroizeInternally encrypt & decrypt PSDs critical security parameters.
(Cert. #A728)SSPs” service; - Breach of flex circuit triggers “Zeroize SSPs” service; - PSD temperature over 84C triggers “Zeroize SSPs” service (EFP measure);
DRBG entropy input128ESV (Cert. #E58)Internally: Entropy SourceN/AN/APlaintext in volatile memory protected by tamper response mechanismInvocation of “Zeroize SSPs” service; - Breach of flex circuit triggers “Zeroize SSPs” service; - PSD temperature over 84C triggers “Zeroize SSPs” service (EFP measure);Input to DRBG.
DRBG parameters – Key & V128CTR DRBG using AES 128 (Cert. #A2930)Internally: Entropy SourceN/AN/APlaintext in volatile memory protected by tamper response mechanismInvocation of “Zeroize SSPs” service; - Breach of flex circuit triggers “Zeroize SSPs” service; - PSD temperature over 84C triggers “Zeroize SSPs” service (EFP measure);Internal state of DRBG.
PSD TLS Communication Private Key112RSA PKCS #1 v1.5 2048 bits (Cert. #A765)Internally: FIPS186-4 KEYGENN/AN/AEncrypted (w/Master Secret)Rendered unusable by zeroization of “Master Secret”Authenticates messages and data output from the PSD during TLS Handshake protocol.

Classification: External Document Name: Security Policy 9. Sensitive security parameters management Page 21/28

Page 22
Key/SSP Name/TypeStrengthSecurity Function and Cert. NumberGenerationImport/ ExportEstablishmentStorageZeroisationUse & related keys
PSD TLS Communication Public Key112RSA PKCS #1 v1.5 2048 bits (Cert. #A765)RSA PKCS #1 v1.5Internally: FIPS186-4 KEYGENExportN/APlaintextInvocation of “Zeroize SSPs” service;The key resides in a signed X509
2048 bitscertificate used for
(Cert. #A765)authentication by the cryptographic module to the Base/Field server/Postal Server.
TLS DH Private Key112Diffie-Hellman 224 bitsInternally: DRBGN/AN/AN/AImmediately after use (i.e., TLS-pre-master key establishment)Diffie-Hellman private key used to agree TLS pre-master.
TLS DH Public Key and Public parameters112Diffie-Hellman 2048 bitsInternally: SP 800-56Ar3ExportSP 800-56Ar3N/AImmediately after use (i.e., TLS-pre-master key establishment)Diffie-Hellman Public Key (Y) and Public parameters (p, g, Y) used during TLS handshake to agree upon a TLS pre-master secret. DH Public Key is relevant when the module acts as an initiator whereas DH Public parameters are relevant when the module acts as a responder.
TLS pre-master key256 bytesKAS-SSC (Cert. #A2929)InternallyN/AKAS-SSCN/AImmediately after useTLS Private and Public Keys
TLS master key48 bytesTLS KDF (Cert. #A761)InternallyN/ATLS KDFN/ATLS session closureUsed to derive the keys used by TLS Record Protocol (TLS Communication Secret Keyset).
TLS Communication Secret Keyset128AES CBC: 2 x 128 bits (Cert. #A728); HMAC-SHA-256: 2 x 256 bits (Cert. #A730).InternallyN/ATLS KDFN/ATLS session closureEncrypt & Decrypt & Integrity TLS Communication.
Indicia Authentication Secret Key160 or 256 or 128HMAC-SHA-1 (160 bits key)3 (Cert. #A729)InternallyExportKTS andEncrypted (w/Master Secret)Rendered unusable by zeroization of “Master Secret”Indicia authentication (dependent on country configuration).

Classification: External Document Name: Security Policy

3 Netherlands
Page 23
Key/SSP Name/TypeStrengthSecurity Function and Cert. Number or HMAC-SHA-256 (256 bits key4) (Cert. #A729) or CMAC AES 1285 (Cert. #A760)GenerationImport/ ExportEstablishment TLS Communication Secret KeysetStorageZeroisationUse & related keys
Indicia Authentication Private Key112ECDSA P2246 or ECDSA P2567 (Cert. #A2931)Internally: DRBGN/AEncrypted (w/Master Secret)Rendered unusable by zeroization of “Master Secret”Indicia authentication (dependent on country configuration).
Indicia Authentication Public Key112ECDSA P224 or ECDSA P256 (Cert. #A2931)FIPS 186-4 ECDSA KEYGENExportPlaintextInvocation of “Zeroize SSPs” service;Indicia authentication (dependent on country configuration).
Root Public Key (Root Certificate)112RSA PKCS #1 v1.5 2048 bits (Cert. #A765)ExternallyImportN/APlaintextInvocation of “Zeroize SSPs” service;Signed X509 Certificate of the Current Root Public key used for the verification of authenticated messages input from the Field server/Postal server/Base.
Previous Root Public Key (Previous Root Certificate)112RSA PKCS #1 v1.5 2048 bits (Cert. #A765)ExternallyImportN/APlaintextInvocation of “Zeroize SSPs” service;Signed X509 Certificate of the Previous Root Public key used for the verification of authenticated messages input from the Field server/Postal server/Base.
Region Public Key (Region Certificate)112RSA PKCS #1 v1.5 2048 bits (Cert. #A765)ExternallyImportN/APlaintextInvocation of “Zeroize SSPs” service;Signed X509 Certificate of the current Region Public key used for the verification of authenticated messages input

Classification: External Document Name: Security Policy UK Belgium

6 USPS
7 Canada
Page 24
Key/SSP Name/TypeStrengthSecurity Function and Cert. NumberGenerationImport/ ExportEstablishmentStorageZeroisationUse & related keys from the Field server/Postal server/Base.
Utility Public Key (Utility certificate)112RSA PKCS #1 v1.5 2048 bits (Cert. #A765)ExternallyImportN/APlaintextInvocation of “Zeroize SSPs” service;Signed X509 Certificate of the R&D Signer User for authentication of files loaded into module.
Field Server Public Key (Field Server Certificate)112RSA PKCS #1 v1.5 2048 bits (Cert. #A765)ExternallyImportN/APlaintextInvocation of “Zeroize SSPs” service;Signed X509 Certificate of the Field Server used to authenticate the Field CO.
Postal Server Public112RSA PKCS #1 v1.5ExternallyImportN/APlaintextInvocation of “Zeroize SSPs” service;Signed X509 Certificate of the
Key (Postal Server2048 bitsPostal Server used to
Certificate)(Cert. #A765)authenticate the Postal CO
Base Public Key (Base Certificate)112RSA PKCS #1 v1.5 2048 bits (Cert. #A765)ExternallyImportN/APlaintextInvocation of “Zeroize SSPs” service;Signed X509 Certificate of the Base used to authenticate the Base User.
R&D Signer User Public Key (R&D Signer Certificate)112RSA PKCS #1 v1.5 2048 bits (Cert. #A765)ExternallyImportN/APlaintextInvocation of “Zeroize SSPs” service;Signed X509 Certificate of the R&D Signer used to authenticate the R&D Signer User.

Classification: External Document Name: Security Policy Table 15: SSPs Page 24/28

Page 25

Classification: External Document Name: Security Policy 10. Self-tests The Quadient Postal Security Device performs pre-operational (§10.1) and conditional self-tests (§10.20) without external control or operator intervention. The Quadient Postal Security Device inhibits the data output and control interfaces during self-tests. If a self-test fails, the Quadient Postal Security Device enters in error state and outputs an error indicator (error code). The Quadient Postal Security Device does not perform any cryptographic operations or output control and data via the control and data output interface while in an error state. The PSD must be repowered to exit the error state and if the error persists the module must be returned to Quadient. The Quadient Postal Security Device maintains a self-test error log that is accessible by an authorized operator of the module. 10.1. Pre-operational self-tests The Quadient Postal Security Device performs the following pre-operational self-tests at power-up:

Page 26

Classification: External Document Name: Security Policy 10.2. Conditional self-tests The Quadient Postal Security Device performs the following conditional self-tests:

Page 27

Classification: External Document Name: Security Policy execution date and time is stored in non-volatile memory. The periodic self-test execution failure is recorded in the error log. 11. Life-cycle assurance Quadient Technologies France is using a system configuration management tool (Windchill) to manage products configurations (including the cryptographic module). 11.1. Installation, Initialization, and Startup Procedures The module is initialized and configured for a specific country in manufacturing. The postal meter is then authorized and shipped to the end customer. 11.2. Administrator Guidance The PSD TLS Communication RSA key pair is generated at the customization center during manufacturing. The PSD TLS Communication key pair is generated internally, by the module itself. Once the key pair is available, the public key is immediately output for certification by the Manufacturing CA entity. After the certificate is available and downloaded into the module, all communication between the manufacturing environment and the module are mutually authenticated and encrypted via a TLStunnel. Once installed in the postage meter (at the customer site), the module first connects to the Postal Server via a mutually authenticated TLS session and sends its certificate for certification. A new certificate chain is downloaded into the module to be used for communication with Quadient infrastructure (Postal Server) to access available services, during the operational phase. 11.3. Non-Administrator Guidance The Quadient postage meters include detailed user guidance in its free online manuals: iX Range - KCMS (quadient.com). 11.4. Design and rules The cryptographic module’s firmware has been implemented using a high-level language (C), except for the limited use of assembly language where it was essential for performance. 11.5. End of life Upon end of life, the module is withdrawn from service and returned to manufacturing for decommissioning and scrapping. Page 27/28

Page 28
AbbreviationDescription
AESAdvanced Encryption Standard
CMACCipher-based Message Authentication Code
CSPCritical Security Parameter
DHDiffie-Hellman key exchange (DHE Diffie Hellman Ephemeral)
DRBGDeterministic Random Bit Generator
ECDSAElliptic Curve Digital Signature Algorithm
EDCError Detection Code
EFP/EFTEnvironmental Failure Protection /Testing
ESVEntropy Source Validation
FIPSFederal Information Processing Standards
HMACHashed Message Authentication Code
KASKey Agreement Scheme
KATKnown Answer Test
KDFKey Derivation Function
KTSKey Transport Scheme
NISTNational Institute of Standards and Technology
PSDPostal Security Device
PKIPublic Key Infrastructure
RSARivest Shamir Adleman
SFISecurity Function Implementation
SHASecure Hash Algorithm
SHSSecure Hash Standard
SPSpecial Publication
SSPSensitive Security Parameter
TLSTransport Layer Security

Classification: External Document Name: Security Policy

  1. Mitigation of other attacks The module employs a tamper detection envelope designed to detect penetration attempts and a response mechanism that immediately zeroizes all plaintext CSPs.
  2. Glossary Page 28/28