All modules
CMVP Validated Module · FIPS 140-3 Security Policy

X5 Postal Security Device (PSD)

Certificate#4933StandardFIPS 140-3Level3TypeHardwareEmbodimentSingle ChipStatusActiveVendorPitney Bowes, Inc.
High review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 19 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level3
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date12/23/2029
CaveatInterim Validation; When operated in approved mode; No assurance of the minimum strength of generated SSPs (e.g., keys).
VendorPitney Bowes, Inc.

Approved Algorithms (13)

AlgorithmACVP Cert
AES-CBCA2435
AES-ECBA2435
AES-KWA2435
ECDSA KeyGen (FIPS186-4)A2437
ECDSA SigGen (FIPS186-4)A2437
ECDSA SigVer (FIPS186-4)A2437
Hash DRBGA2436
HMAC-SHA2-256A2438
KAS-ECC-SSC Sp800-56Ar3A2439
KDA OneStep Sp800-56Cr1A2439
RSA SigVer (FIPS186-4)A2440
SHA2-224A2441
SHA2-256A2441

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for X5 Postal Security Device (PSD)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>Rollback<br/>recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>bootloader<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for X5 Postal Security Device (PSD)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>Rollback<br/>recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>bootloader<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Pitney Bowes, Inc. X5 Postal Security Device (PSD) Version 1.0 This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 2
Table of Contents
#SectionPage
Page 3

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Hardware8
Table 3: Modes List and Description9
Table 4: Approved Algorithms9
Table 5: Vendor-Affirmed Algorithms11
Table 6 – FIPS Non-Approved, Not Allowed Algorithms11
Table 7: Security Function Implementations12
Table 8: Ports and Interfaces14
Table 9: Authentication Methods15
Table 10: Roles15
Table 11: Approved Services16
Table 12 - Non-Approved Services23
Table 13: Mechanisms and Actions Required25
Table 14: EFP/EFT Information25
Table 15: Hardness Testing Temperatures25
Table 16: Storage Areas26
Table 17: SSP Input-Output Methods26
Table 18: SSP Zeroization Methods27
Table 19: SSP Table 128
Table 20: SSP Table 229
Table 21: Pre-Operational Self-Tests32
Table 22: Conditional Self-Tests32
Table 23: Pre-Operational Periodic Information34
Table 24: Conditional Periodic Information34
Table 25: Error States35
Page 5
List of Figures
ItemPage
Figure 1 – X5 Postal Security Device (PSD)7
Figure 2: Block Diagram8
Page 6
SectionTitleSecurity Level
1General3
2Cryptographic Module Specification3
3Cryptographic Module Interfaces3
4Roles, Services, and Authentication3
5Software/Firmware Security3
6Operational EnvironmentN/A
7Physical Security3
8Non-Invasive SecurityN/A
9Sensitive Security Parameter Management3
10Self-Tests3
11Life-Cycle Assurance3
12Mitigation of Other AttacksN/A
Overall Level3
1.1 OVERVIEW

This document defines the Security Policy for the Pitney Bowes, Inc. (PB) X5 Postal Security Device (PSD) cryptographic module, hereafter “the module”. The physical form of the module is depicted in Figure 1. The module is a single-chip embodiment as defined by FIPS 140-3 and conforms to Security Level 3.

1.2 SECURITY LEVELS

The module meets the overall requirements of FIPS 140-3 Security Level 3. Table 1: Security Levels

2.1 DESCRIPTION

The X5 Postal Security Device (PSD) is a single-chip (hardware) cryptographic module designed by PB to conform with FIPS 140-3 Security Level 3 requirements. The module provides cryptographic services to a host device (i.e., Digital Postage Meter), to support postage evidence in the form of an indicium. A PSD provides protection that includes ensuring the secrecy of critical security parameters (CSPs) such as cryptographic keys and providing data This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 7

integrity protection for funds relevant data items (FRDIs 1) such as accounting data. CSPs and FRDIs reside inside the strong physical protection of the PSD. Figure 1 – X5 Postal Security Device (PSD) Purpose and Use: The module is designed to function as a postal security device. Postal security devices act as the core security component within postage evidencing systems (PES). Module Type: The module is defined as hardware module (refer to ISO/IEC 19790, Section 7.2.2). Module Embodiment: The module is defined as a single-chip cryptographic module. Module Characteristics: The critical components within the module are encapsulated within a single, integrated circuit. Cryptographic Boundary: The module’s cryptographic boundary is defined as the IC package that comprises the Maxim Integrated MAX32590 DeepCover Secure Microcontroller.

1 FRDIs are not applicable to FIPS 140-3 and are not CSPs. The FRDIs’ authenticity and integrity are critical for

postal functionality, and they should never be zeroized. This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 8
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
X5 Postal Security Device (PSD)Maxim Integrated MAX32590 DeepCover Secure Microcontroller - Revision B4PSD Application: 22.01.000D & 22.01.000F Device Abstraction Layer (DAL): 02.01.000F & 02.01.0013Maxim Integrated MAX32590 DeepCover Secure MicrocontrollerARM926EJ-S™ Processor Core with 16KB Data Cache and 32KB Instruction Cache
2.2 TESTED AND VENDOR AFFIRMED MODULE VERSION AND IDENTIFICATION

The module is designed to meet the requirements of FIPS 140-3 Security Level 3 (refer to Table 1). The module is available in the following configuration (refer to Table 2): Tested Module Identification

Page 9
Mode NameDescriptionTypeStatus Indicator
Approved ModeOnly Approved services are supportedApprovedApproved Mode Status Flag returns ‘0’.
Non-Approved ModeNon-Approved ConfigurationNon-ApprovedApproved Mode Status Flag returns ‘1’.
AlgorithmCAVP CertPropertiesReference
AES-CBCCert. #A2435Direction: Encrypt, Decrypt Key Length: 2562FIPS 197, NIST SP 800- 38A

N/A for this module. Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module.

2.3 EXCLUDED COMPONENTS
2.4 MODES OF OPERATION

Modes List and Description: The module only supports an Approved and non-Approved mode of operation. The module provides an explicit mode of operation indicator: the ‘Approved mode status flag’ is returned in every response from the module. The Approved Mode Status Flag is set to zero when a service utilizes an approved cryptographic algorithm, security function or process in an approved manner or to one for non-Approved cryptographic algorithms, security functions or process in a non-approved manner. The module’s mode of operation can only be configured within manufacturing. Once configured, the module does not have the ability to change modes. Table 3: Modes List and Description

2.5 ALGORITHMS

The module supports the approved cryptographic algorithms shown in Table 4. Approved Algorithms: The module supports the following approved cryptographic algorithms. Table 4: Approved Algorithms

2 Key sizes 128 and 192 are included in the algorithm certificate, but are not used in Approved mode.

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 10
AlgorithmCAVP CertPropertiesReference
AES-ECBCert. #A2435Direction: Encrypt, Decrypt Key Length: 2563FIPS 197, NIST SP 800- 38A
AES KWCert. #A2435Direction: Wrap, Unwrap Key Length: 2564NIST SP 800-38F
ECDSA Key GenerationCert. #A2437Curves: P-224, P-256 SHA Size: 224, 256FIPS 186-4
ECDSA Signature GenerationCert. #A2437Curves: P-224, P-256 SHA Size: 224, 256FIPS 186-4
ECDSA Signature VerificationCert. #A2437Curves: P-224, P-256 SHA Size: 224, 256FIPS 186-4
Hash DRBGCert. #A2436Function: Hash_DRBGNIST SP 800-90A Rev. 1
HMAC-SHA2-256Cert. #A2438Function: Generate Message Authentication Codes SHA Size: 256FIPS 198-1
KAS-ECC-SSC NIST SP 800-56Ar3Cert. #A2439Scheme: Ephemeral Unified Model C (2e, 0s, ECC CDH) Curve: P-256NIST SP 800-56A Rev. 3
KDA OneStep NIST SP 800-56Cr1Cert. #A2439Function: One-Step KDF (Session Key) SHA Size: 256NIST SP 800-56C Rev. 2
KTSCert. #A2435Function: Wrap, Unwrap Key Length: 256NIST SP 800-38F
KTSCert. #A2435 Cert. #A2438AES Function: Encrypt, Decrypt HMAC Function: Generate HMAC Key Length: 256 SHA Size: 256NIST SP 800-38F; FIPS 197; FIPS 198-1
RSA Signature VerificationCert. #A24405Function: Signature Verification (PKCS PSS) Key Length: 2048 SHA Size: 256FIPS 186-4
SHA2-224Cert. #A2441SHA Size: 224FIPS 180-4

3 Key sizes 128 and 192 are included in the algorithm certificate, but are not used in Approved mode.

4 Key sizes 128 and 192 are included in the algorithm certificate, but are not used in Approved mode.

5 RSA PKCS1 v1.5 and ANSI X9.31 are not used by the module in Approved mode. Only the modulus size of

2048 is supported by the module in Approved mode.

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 11
AlgorithmCAVP CertPropertiesReference
SHA2-256Cert. #A2441SHA Size: 256FIPS 180-4
NamePropertiesImplementationReference
CKG - AsymmetricKey Type: AsymmetricN/ANIST SP 800-133r2 Section 4 and Section 5.1 - The unmodified output of the DRBG is used for generation of asymmetric keys.
CKG - SymmetricKey Type: SymmetricN/ANIST SP 800-133r2 Section 4 and Section 6.1 - The unmodified output of the DRBG is used for generation of symmetric keys.
CKG - EstablishmentKey Type: AsymmetricN/ANIST SP 800-133r2 Section 4 and Section 5.2 - The unmodified output of the DRBG is used for key pair generation for key establishment.
AlgorithmUse/Function
KAS (non-compliant)FFC KAS used to establish a Triple DES session key.
DSA (non-compliant)Used to generate key pairs and generate/verify digital signatures.
ECDSA (non-compliant)Used to generate key pairs and generate/verify digital signatures.
HMAC (non-compliant)Secondary security mechanism on Canada Indicia.
RSA (non-compliant)Used to generate keys and digital signatures.
SHS (non-compliant)Hashing for digital signatures and key derivation.
Triple-DES (non-compliant)Data encryption and decryption.
Triple-DES MAC (non-compliant)Used to generate Message Authentication Codes (MACs).

Vendor-Affirmed Algorithms: The module supports the following vendor affirmed algorithms in accordance with IG D.H (refer to Table 5). Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: The following cryptographic algorithms are used solely in a non-Approved mode of operation (this includes specified CAVP-validated algorithms). There exists no mechanism to allow the use of these algorithms in an Approved mode of operation. Table 6 – FIPS Non-Approved, Not Allowed Algorithms This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 12
NameTypeDescriptionPropertiesAlgorithms
DRBG Generate FunctionDRBGNIST SP 800-90A CTR_DRBG generate function for delivering random bits on demandReturned Bits:1024Hash DRBG/A2436
ECDSA Key GenerationAsymKeyPair- KeyGen CKGFIPS 186-4 ECDSA P- 224/P-256 Key GenerationCurve:P-224 Curve:P-256ECDSA KeyGen (FIPS186-4) Curves: P-224, P256 Secret Generation Mode: Testing Candidates CKG - Asymmetric Key Type: Asymmetric
ECDSA Signature GenerationDigSig-SigGenFIPS 186-4 ECDSA P- 224/P-256 digital signature generation of postal relevant dataCurve:P-224 Curve:P-256ECDSA SigGen (FIPS186-4) Curves: P-224, P-256 SHA2-224, SHA2-256
ECDSA Signature VerificationDigSig-SigVerFIPS 186-4 ECDSA P- 224/P-256 digital signature verificationCurve:P-224 Curve:P-256ECDSA SigVer (FIPS186-4) Curves: P-224, P256 SHA2-224, SHA2-256
Hash FunctionSHASHA2-224 and SHA2-256 data integrity for ECDSA digital signaturesSHA2-224, SHA2- 256SHA2-224 and SHA2-256 Message Length Min: 8 bits Message Length Max: 51200 bits
KASKASNIST SP 800-56Ar3 KAS-SSC Per IG D.F Scenario 2 path (2)ECC P-256 providing strength of 128 bitsKAS-ECC-SSC SP800-56Ar3/A2439 KDA OneStep SP800-56Cr1/A2439
KTS_1KTSNIST SP 800-38F key wrapping and unwrapping per IG D.G256-bit key providing strength of 256 bitsAES-KW/A2435
KTS_2KTSNIST SP 800-38F key wrapping and unwrapping per IG D.G256-bit key providing strength of 256 bitsAES-CBC/A2435 HMAC-SHA2-256/A2438
Message AuthenticationMACHMAC-SHA-256 used for authentication for secure sessionsKey: 256-bitHMAC-SHA2-256 Key Length Min: 128-bit Key Length Max: 512-bit
RSA Signature Verification (Auth)DigSig-SigVerFIPS 186-4 RSA 2048 digital signature verificationKey:2048-bitRSA SigVer (FIPS186-4) Signature Type: PKCS PSS Modulo: 2048 SHA2-256
2.6 SECURITY FUNCTION IMPLEMENTATIONS

Table 7: Security Function Implementations This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 13
Seed DRBGDRBGInstantiate the DRBGLength: 1024 bitsHash DRBG/A2436
SSP AuthenticationMACMessage authentication code applied to stored SSPsKey: 256-bitHMAC-SHA2-256 Key Length: 128-bit
SSP DecryptionBC-UnAuthSSP Decryption in NVRAMKey:256-bitAES-CBC Key Size: 128-bit
SSP EncryptionBC-UnAuthSSP encryption in NVRAMKey:256-bitAES-CBC Key Size: 128-bit
Symmetric Key GenerationCKGSymmetric Key GenerationKey: 256-bitCKG Key Type: Symmetric

The module utilizes only approved algorithms that are tested and validated under the Cryptographic Algorithm Validation Program (CAVP).

2.7 RBG AND ENTROPY

The module incorporates a NIST SP 800-90A Hash-DRBG (Cert. #A2436) that is seeded with 512 bits of entropy and a 512-bit nonce from an external source during manufacturing of the module. The unmodified output of the DRBG is used for generating cryptographic key material or random nonces. Given that the entropy is imported from outside the device, there is no assurance of the minimum strength of generated SSPs. The module generates symmetric cryptographic keys in conformance with NIST SP 800-133r2 using a NIST SP 80090A conforming DRBG (Cert. #A5176) for the encryption and protection of data and cryptographic keys. The module generates asymmetric cryptographic key pairs in conformance with FIPS 186-5 for the verification of digital signatures, or for the facilitation of key agreement in conformance with NIST SP 800-56ar3.

2.9 KEY ESTABLISHMENT

The module supports the establishment of cryptographic keys using elliptic curve cryptography (ECC) in conformance with NIST SP 800-56ar3 and IG D.F – Scenario #2. The module implements KAS-ECC-SSC per NIST SP 800-56A Rev3 (Cert. #A2439), used in conjunction with KDA per NIST SP 800-56Cr1 (Cert. #A2439). Key establishment methodology provides at least 128 bits of encryption strength. This is used to establish secure communication sessions. The module also incorporates KTS in conformance with NIST SP 800-38F using AES-KW (Cert. #A2435), or when using AES-CBC (Cert. #A2435) with HMAC-SHA2-256 (Cert. #A2438).

2.10 INDUSTRY PROTOCOLS

The module relies upon the standard USB and other serial protocols for communication with general purpose computer (GPC) systems. This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 14
Physical PortLogical Interface(s)Data That Passes
G13, J5, J13, K5, K13Control InputReset Input, RTC, Commands.
B7, F13, F14, R10, R11, R12, R13, T10, T11, T12, T13, U10, U11, U12, U13, V10, V11, V12, V13Control Input Data InputSerial UART and USB interfaces for inputting postal relevant data items, configuration or sensitive security parameters (SSPs).
A7, F13, F14, P4, P6, P7, P8, P9, P10, P11, P13, P14, P15, P16, P17, P18, R10, R11, R12, R13, R14, R15, R16, R17, R18, T10, T11, T12, T13, T15, T16, T17, T18, U10, U11, U12, U13, U16, U17, U18, V10, V11, V12, V13, V16, V17, V18Data Output, Status OutputSerial UART and USB interfaces for outputting postal relevant data items, sensitive security parameters (SSPs), error codes and module status.
G5, H13, M4, N14, N17, N18Status OutputUSB Detect, Reset Output, module status.
C3, D3, F6, F7, F8, F9, F10, F11, F12, G6, G12, H5, H6, H12, J6, J12, K6, K12, L6, L12, M6, M12, N6, N7, N8, N9, N10, N11, N12PowerPower input.

The module incorporates physical ports and logical interfaces. The MAX32590 is supplied in a 324-pin Ball Grid Array (BGA) package where all power input, data input, data output, control input, and status output interfaces are supported. The module does not support a control output interface. The physical ports are defined within Table 8 below: Table 8: Ports and Interfaces This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 15
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Cryptographic Officer (CO)Identity-based. Allows the Cryptographic Officer to authenticate themselves. Sets up a remote session with CO.ECDSA P-256 SigVer (FIPS 186-4) (A2437)128 bitsThe module can execute at most 17.85 ECDSA verifications per second. Therefore, the probability of a successful random attempt in a one- minute period is 1 in 3.2 x 10^35 for ECDSA, which is far less than 1 in 100,000.
UserIdentity-based. Allows the User to authenticate to the module.Challenge response mechanism.128 bitsThe module can execute at most 40 password authentication attempts per minute. Therefore, the probability of a successful random attempt in a one- minute period is 1 in 8.5 x 10^36, which is far less than 1 in 100,000.
NameTypeOperator TypeAuthentication Methods
Cryptographic Officer (CO)IdentityCryptographic OfficerDigital Signature (ECDSA P-256, authenticated with Vendor, Download or Certificate Keys)
UserIdentityUserUniquely Assigned ID in conjunction with 128-bit password
UnauthenticatedN/AUnauthenticatedNone
4 ROLES, SERVICES, AND AUTHENTICATION

separate authentication methods as indicated in Table 9.

4.2 ROLES

Table 10: Roles The module does not support concurrent operators. Only one operator is allowed to access the device at any time. Operator authentication does not persist beyond power-cycling the module. The selection of roles is implicit. This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 16
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Generate PSD KeyInstructs the PSD to generate its Unique ECDSA P-256 Operation Key pair or the Unique ECDSA P-256 Debit Key pair.Approved Service ID, Success or Error IDCommand Block:0x203F00BD + Signed Key Record with the parameters for use in the generation of the private and public key values.PSD Certificate Request block after the key has been generated or an error condition has been detectedECDSA P-256/P- 224 KeyGen, Hash-DRBG, AES 256, HMAC-SHA- 256, CKGCryptographic Officer - Operation Private/Public Keys: G - Or Debit Private/Public Keys: G - DRBG Working State: E, G - Vendor Key: E - KEK: E - KAK: E
Generate Session KeyInstructs the PSD to generate an AES 256-bit and a HMAC 256-bit session key via NIST SP 800-56A and NIST SP 800-56C.Approved Service ID, Success or Error IDCommand Block:0x203F00C3 + Signed Key Block with an ECDH key for generating the shared secret key.Status bits, Session KeyHash-DRBG, NIST SP 800-56A KAS- SSC, NIST SP 800- 56C KDA, ECDSA P-256 SigVer, AES KW 256, HMAC- SHA-256 Or AES 256, CKGCryptographic Officer - DRBG Working State: E, G - Shared Secret: G, E - ECC-CDH PSD KAS Private Key: G, E - Operation Private Key: E, Session - Authentication Key: G, E - Or Session Privacy Key: G, E - KEK: E, KAK: E - Certificate Key: E, ECC-CDH - Infrastructure KAS Public Key: E - ECC-CDH PSD KAS Public Key: G, E, R
Load Certificate KeyInstructs the PSD to load the (ECDSA P-256) Certificate Key.Approved Service ID, Success or Error IDCommand Block: 0x203F00BA + Certificate KeyStatus bits (Success or Error ID)HMAC-SHA-256, ECDSA P-256 SigVerCryptographic Officer - KAK: E, Vendor Key: E - Certificate Key: W
Load CRLLoads the Certificate Revocation List and the CRL version.Approved Service ID, Success or Error IDCommand Block: 0x203F00B8 + CRLStatus bits (Success or Error ID)ECDSA P-256 SigVerCryptographic Officer - Download Key: E
Load Download KeyInstructs the PSD to load the (ECDSA P-256) Download Key Certificate.Approved Service ID, Success or Error IDCommand Block:0x203F00BB + Download KeyStatus bits (Success or Error ID)HMAC-SHA-256 ECDSA P-256 SigVerCryptographic Officer - KAK: E - Certificate Key: E - Download Key: W
4.3 APPROVED SERVICES
Page 17
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Load Encrypted KeyThe Crypto Officer instructs the PSD to load a signed key record containing an encrypted symmetric or private key.Approved Service ID, Success or Error IDCommand Block:0x203F00AD + Encrypted Secret KeyStatus bits (Success or Error ID)HMAC-SHA-256 AES KW 256 AES 256 ECDSA P-256 SigVerCryptographic Officer - Debit Secret Key: W - Session Privacy Key: E - KEK: E - KAK: E - Certificate Key: E
Load Key AcknowledgementAcknowledge that the generated PSD Key has been successfully registered and that the PSD can activate that key.Approved Service ID, Success or Error IDCommand Block: 0x203F00AE + Affirmation from server with Key AcknowledgementN/AECDSA P-256 SigVerCryptographic Officer - Certificate Key: E
Load Parameters: Transition to Operational StateCauses the PSD to transition to the PSD Operational lifecycle state.Approved Service ID, Success or Error IDCommand Block:0x203F00B5 + parameter valueStatus bits (Success or Error ID)ECDSA P-256 Sig VerCryptographic Officer - Certificate Key: E
Load Parameters: Transition to Base StateTransitions the PSD from its Manufacturing lifecycle state to Base lifecycle state.Approved Service ID, Success or Error IDCommand Block:0x203F00B5 + parameter valueStatus bits (Success or Error ID)ECDSA P-256 Sig VerCryptographic Officer - Certificate Key: E
Load Parameters: Disable PSDPlaces the PSD in the Disabled lifecycle state. In the Disabled lifecycle state, further financial functions are prohibited.Approved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x203F00B5 + parameter valueStatus bits (Success or Error ID)ECDSA P-256 Sig VerCryptographic Officer - Certificate Key: E
Load Parameters: Enable PSDTransition the PSD from Disabled lifecycle state to Operational lifecycle state.Approved Service ID, Success or Error IDCommand Block:0x203F00B5 + parameter valueStatus bits (Success or Error ID)ECDSA P-256 Sig VerCryptographic Officer - Certificate Key: E
Load Parameters: Reinitialize PSDCauses PSD to zeroize all plaintext cryptographic keys and CSPs, and then invalidates the PSD Application.Approved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x203F00B5 + parameter valueStatus bits (Success or Error ID)ECDSA P-256 Sig VerCryptographic Officer - Certificate Key: E

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 18
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Load Parameters: Software UpdateUpdate utility that allows start of firmware download.Approved Service ID, Success or Error IDCommand Block:0x203F00B5 + parameter valueStatus bits (Success or Error ID)ECDSA P-256 Sig VerCryptographic Officer - SWAK: E - Certificate Key: E
Load Parameters: Transaction Start (Commit, Rollback)Triggers event to have the PSD prepare for a multi-message transaction that must be completed successfully as a unit (atomic transaction).Approved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x203F00B5 + parameter valueStatus bits (Success or Error ID)ECDSA P-256 Sig VerCryptographic Officer - Certificate Key: E
Wipe PSDCauses PSD to zeroize all plaintext cryptographic keys and CSPs.Approved Service ID, Success or Error IDNoneStatus bits (Success or Error ID)ECDSA P-256 Sig VerCryptographic Officer - KEK: Z - Certificate Key: E
Load Vendor KeyInstructs the PSD to load the (ECDSA-P256) Vendor Key Certificate.Approved Service ID, Success or Error IDCommand Block:0x203F00BC + Vendor KeyStatus bits (Success or Error ID)HMAC-SHA-256, ECDSA P-256 SigVerCryptographic Officer - KAK: E - Manufacturing Key: E - Vendor Key: W
Process Audit ResponseInstructs the PSD to process the Horizon Audit Response Block returned from the Pitney Bowes infrastructure.Approved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x203F00B2 + Audit Response BlockStatus BitsECDSA P-256 Sig VerCryptographic Officer - Certificate Key: E
Process Postage Value DownloadInstructs the PSD to perform a postage value download operation.Approved Service ID, Success or Error IDCommand Block:0x203F00B9Status bits (Success or Error ID)ECDSA P-256 Sig VerCryptographic Officer - Certificate Key: E
Process Withdraw ResponseInstructs the PSD to complete the withdraw process.Approved Service ID, Success or Error IDCommand Block:0x203F00B0Status BitsECDSA P-256/P- 224 Sig VerCryptographic Officer - Debit Private Key: E - Certificate Key: E
Audit RequestInstructs the PSD to prepare a signed Audit Request Block.Approved Service ID, Success or Error IDCommand Block:0x204E0007 - initiates an Audit RequestAudit blockHash-DRBG, AES- 256, ECDSA P-256 SigGenUser - DRBG Working State: E, G - KEK:E - Operation Key: E

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 19
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Clear Upload IntervalInstructs the PSD to clear the Upload Interval Timer.Approved Service ID, Success or Error IDCommand Block: 0x204E0032 - clears the upload intervalStatus bits (Success or Error ID)NoneUser - None
Create Debit CertificateInstructs the PSD to create a debit certificate in the format defined by the Flex Debit Certificate Template.Approved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x204E0029 + Postal data for signingStatus bits, Signed data blockDRBG, AES 256, ECDSA P-256/P- 224 SigGen or HMAC-SHA-256User - DRBG Working State: E, G - KEK: E - Debit Secret Key: E, or Debit Private Key: E or Mail Piece Key: E
Create PVD RequestInstructs the PSD to create a Postage Value Download Request Block.Approved Service ID, Success or Error IDCommand Block:0x204E0033 - initiates an PVD RequestStatus bits (Success or Error ID)Hash-DRBG, AES 256, ECDSA P-256 SigGenUser - DRBG Working State: E, G - KEK: E - Operation Key: E
Finalize DebitPerforms post-debit housekeeping and prepare for the next Debit operation by precomputing the ‘r’ signature parameter if necessaryApproved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x204E0008 + data to perform a debit transactionStatus BitsNoneUser - None
Log PermitLogs the permit and the data capture recovery information.Approved Service ID, Success or Error IDCommand Block:0x204E002BStatus Bits and Register ValuesNoneUser - None
Login RequestAuthenticates the User with the PSD. If the authentication is successful, the PSD allows debit operations.Approved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x204E002F + Login dataStatus Bits with login success or failureAES 256User - KEK: E - Password: E

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 20
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Precompute r for DebitPre-computes the ‘r’ signature component for the PSD Key signature (ECDSA). This message is used for countries whose debit certificate is signed by an ECDSA key.Approved Service ID, Success or Error IDCommand Block:0x204E0009Status bits (Success or Error ID)Hash-DRBG, AES- 256User - DRBG Working State: E, G - KEK: E
Process Flex Debit BlockLoads a flex debit template into the PSD. The flex debit template defines the indicia content for debit operations.Approved Service ID, Success or Error IDCommand Block:0x203F00B4 + debit template dataStatus bits (Success or Error ID)ECDSA P-256 SigVerUser - Download Key: E
Sign Transaction DataGenerates a signature on the included hash.Approved Service ID, Success or Error IDCommand Block:0x204E0030 + Data to be hashedDigital SignatureHash-DRBG, AES 256, ECDSA P-256 SigGenUser - DRBG Working State: E, G - KEK: E - Operation Key: E
Verify Hash BlockValidates the included hash.Approved Service ID, Success or Error IDCommand Block:0x203F00B3 + data and hash to be verifiedStatus bits (Success or Error ID)ECDSA P-256 SigVerUser - Download Key: E
Verify Mail Piece DataVerifies the hash of the transaction data for a mail piece.Approved Service ID, Success or Error IDCommand Block:0x204E0031 + Data to be verifiedStatus bits (Success or Error ID)HMAC-SHA-256User - MailPiece Key: E
Withdraw RequestInstructs the PSD to initiate a Withdrawal operation.Approved Service ID, Success or Error IDCommand Block:0x204E000AStatus bits (Success or Error ID)ECDSA P-256 SigGenUser - Operation Key: E
Get ChallengeReturns an 8-byte nonce (random number) from the DRBG.Approved Service ID, Success or Error IDCommand Block:0x204E0003Nonce (8 bytes from DRBG)Hash-DRBG, AES- 256Unauthenticated - DRBG Working State: E, G - KEK: E

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 21
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Get Clock OffsetsReturns the drift and GMT offset values.Approved Service ID, Success or Error IDCommand Block:0x204E0020Status bits, + value of offsetsNoneUnauthenticated - None
Get Flex Debit TemplateReturns the loaded flex debit template.Approved Service ID, Success or Error IDCommand Block:0x204E002EStatus bits + Debit TemplateNoneUnauthenticated - None
Get GMT TimeReturns the real time clock value with only the drift correction applied.Approved Service ID, Success or Error IDCommand Block:0x204E001CTime YYYYMMDDhhmmssNoneUnauthenticated - None
Get Key ListReturns a list of all active keys stored in the PSD.Approved Service ID, Success or Error IDCommand Block:0x204E0004Key ListNoneUnauthenticated - None
Get Local TimeReturns the real time clock with drift and GMT offsets applied.Approved Service ID, Success or Error IDCommand Block:0x204E001ETime YYYYMMDDhhmmssNoneUnauthenticated - None
Get ML AttributesReturns device versions and unique device serial number.Approved Service ID, Success or Error IDCommand Block:0x204E002DDAL Layer versionsNoneUnauthenticated - None
Get ParametersReturns parameter values stored in the PSD. The Host can request individual parameter IDs or all the Parameters in the PSD.Approved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x204E0005Status bits + parameter informationNoneUnauthenticated - None
Get PSD AttributesReturns PSD attribute data, including firmware and hardware versions.Approved Service ID, Success or Error IDCommand Block:0x204E0021PSD versioning informationNoneUnauthenticated - None

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 22
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Get PSD StatusReturns PSD status information that includes the module’s mode of operation indicator.Approved Service ID, Success or Error IDCommand Block:0x204E0022Status of the PSDNoneUnauthenticated - None
Get PSD VersionsRetrieves the versions of the hardware, software and cryptographic libraries.Approved Service ID, Success or Error IDCommand Block:0x204E0037PSD Versioning information (includes HW ID and FW versions)NoneUnauthenticated - None
Get Withdraw CertificateRetrieves the Withdraw Certificate created at the successful completion of the Withdraw process.Approved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x204E0034Signed withdrawal certificateNoneUnauthenticated - None
Perform Diagnostic TestThe User sends this message to request that the PSD perform a diagnostic test.Approved Service ID, Success or Error IDCommand Block:0x204E0026Status bits (Success or Error IDNoneUnauthenticated - None
Perform Full DiagnosticsThe User sends this command to request the PSD perform its diagnostic processing.Approved Service ID, Success or Error IDCommand Block:0x204E0024Status bits (Success or Error IDNoneUnauthenticated - None
Read Log FileReturns Log Data stored in the PSD.Approved Service ID, Success or Error IDCommand Block:0x204E0028Log dataNoneUnauthenticated - None
Reboot PSDRestarts the PSD application. The PSD will run its power up tests.Approved Service ID, Success or Error IDCommand Block:0x204E0006N/ANoneUnauthenticated - None
Set ClockSets the real time clock in the PSD. The real time clock can only be set when the PSD is in manufacturing state.Approved Service ID, Success or Error IDApproved Service ID, Success or Error IDCommand Block:0x204E0002 + clock data YYYYMMDDhhmmssStatus bits (Success or Error IDNoneUnauthenticated - None

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 23
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Set GMT OffsetSets the GMT offset in the PSD. The GMT offset is a combination of time zone offset and daylight savings time offset (if applicable).Approved Service ID, Success or Error IDCommand Block:0x204E001D + 4-byte offsetTime with offsetNoneUnauthenticated - None
NameDescriptionAlgorithms AccessedRole
General Postal ServicesPostal services for countries that utilize non-approved algorithms (e.g. France, Germany, etc.)DSA, ECDSA, HMAC, KAS, RSA, SHS, Triple- DESCO/User

The non-Approved Mode of the module implements the same roles and services as the Approved Mode of operations, but this mode also allows the use of the algorithms specified in Section 2.10. This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 24
4.5 EXTERNAL SOFTWARE/FIRMWARE LOADED

There is no complete image replacement process. New firmware may be downloaded by the module for the country-specific postal application. The postal application firmware is signed by PB, with an ECDSA P-256 digital signature. On downloading, the device verifies the firmware digital signature.

5 SOFTWARE/FIRMWARE SECURITY
5.1 INTEGRITY TECHNIQUES

The module includes the following firmware components that include separate firmware integrity tests: − Bootloader: RSA 2048 Digital Signature Verification (RSA, Cert. #A2440) − Postal Application Firmware: ECDSA P-256 Digital Signature Verification (ECDSA, Cert. #A2437) The module will transition to its error state upon the failure of either firmware integrity test.

5.2 INITIATE ON DEMAND

Self-tests may be initiated on demand by power cycling the module (‘Reboot PSD’) or invoking the ‘Perform Diagnostic Test’ or ‘Perform Full Diagnostics’ services.

6 OPERATIONAL ENVIRONMENT
6.1 OPERATIONAL ENVIRONMENT TYPE AND REQUIREMENTS

Type of Operational Environment: Limited How Requirements are Satisfied: The module does not contain a modifiable operational environment. The module’s operational environment is limited. The module includes a firmware load service to support necessary updates. Firmware versions validated through the FIPS 140-3 CMVP will be explicitly identified on a validation certificate. Any firmware not identified in this Security Policy does not constitute the module defined by this Security Policy or covered by this validation. This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 25
MechanismInspection FrequencyInspection Guidance
Tamper EvidenceDuring installation, re-installation, decommissioning, and servicing.Inspect device for obvious damage or other evidence of tamper.
Tamper DetectionEvery 30 daysThe module HW status flag is submitted every 30 days to the PB servers to check for tamper.
Temp/Voltage TypeTemperature or VoltageEFP or EFTResult
Low Temperature-65°CEFPZeroization
High Temperature117°CEFPZeroization
Low Voltage2.9VEFPZeroization
High Voltage3.6VEFPZeroization
Temperature TypeTemperature
Low Temperature-65°C
High Temperature150°C
7 PHYSICAL SECURITY
7.1 MECHANISMS AND ACTIONS REQUIRED

The device includes automatic tamper detection and response. CSPs are zeroized automatically and immediately upon a tamper event being detected. On detection of a tamper event, the device is to be returned to PB. Table 13: Mechanisms and Actions Required extremes (refer to Table 14). Table 14: EFP/EFT Information

7.3 HARDNESS TESTING TEMPERATURE RANGES

The module has been tested at the operational, storage and distribution temperatures listed in Table 15. The module’s epoxy hardness is assured within these ranges. Table 15: Hardness Testing Temperatures This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 26
Storage Area NameDescriptionPersistence Type
Battery Backed RAM Register (BBREG)On-chip memory that is zeroized on tamper detection.Static
NVRAMOn-chip memory that is zeroized on tamper detection.Static
SRAMVolatile memoryDynamic
FLASHPersistent long-term storageStatic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Input (Encrypted)Outside the ModuleNVRAMEncryptedAutomatedElectronicKey Transport
Output (Encrypted)NVRAMOutside the ModuleEncryptedAutomatedElectronicKey Transport
Input (Plaintext)Outside the ModuleSRAMPlaintextAutomatedElectronicKAS (dhEphem C(2e, 0s, FFC DH))
Output (Plaintext)SRAMOutside the ModulePlaintextAutomatedElectronicKAS (dhEphem C(2e, 0s, FFC DH))
8 NON-INVASIVE SECURITY
8.1 MITIGATION TECHNIQUES

The module does not provide protections against non-invasive security methods.

9 SENSITIVE SECURITY PARAMETERS MANAGEMENT
9.1 STORAGE AREAS

The module supports both volatile and persistent storage of SSPs. Table 16: Storage Areas

9.2 SSP INPUT-OUTPUT METHODS

Table 17: SSP Input-Output Methods

9.3 SSP ZEROIZATION METHODS

The zeroization methods described within Table 18 are supported by the module. Zeroization services explicitly overwrite SSPs with zero values. This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 27
Zeroization MethodDescriptionRationaleOperator Initiation
Reinitialize PSDServiceForces a zeroization of the KEK (Key Encryption Key) and NVRAM memory components. N.B. This process is irreversible.Host device calls the service
Wipe PSDServiceForces a zeroization of the KEK (Key Encryption Key) and NVRAM memory components. N.B. This process is irreversible.Host device calls the service
End of sessionAutomaticFirmware programmed zeroization of ephemeral SSPs used in secure sessionN/A
Removal of Battery/TamperPhysicalForces a zeroization of the KEK (Key Encryption Key) and removal of power from battery-backed memory.Removal of battery power or a tamper event
AutomaticallyAutomaticImmediately after use.N/A

Table 18: SSP Zeroization Methods This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 28
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
KEK (Key Encryption Key)Protect all keys stored internally or in NVM256-bitSymmetric Key - CSPGenerated Internally by DRBG (during manufacturing)N/ASSP Encryption SSP Decryption
KEK’ (Backup Key Encryption Key)Backup KEK256-bitSymmetric Key - CSPGenerated Internally by DRBG (during manufacturing)N/ASSP Encryption SSP Decryption
KAK (Key Authentication Key)Authenticate keys externally stored in NVM256-bitSymmetric Key - CSPGenerated Internally by DRBG (during manufacturing)N/ASSP Authentication
Debit Private KeyDigitally sign debit records (indicia data)112-bit or 128-bitAsymmetric Private Key - CSPGenerated Internally by DRBGN/AECDSA Signature Generation
Debit Secret KeyDigitally authenticate debit records (indicia data)256-bitSymmetric Key - CSPExternallyN/AMessage Authentication
Operation Private KeyAuthenticate to the communicating infrastructure128-bitAsymmetric Private Key - CSPGenerated Internally by DRBGN/AECDSA Signature Generation
Session Authentication KeyUsed to authenticate messages sent between the Host and the PSD256-bitSymmetric Key - CSPN/AKAS (dhEphem C(2e, 0s, FFC DH))Message Authentication
Session Privacy KeyEncrypt data or wrap keys transported to infrastructure256-bitSymmetric Key - CSPN/AKAS (dhEphem C(2e, 0s, FFC DH))KTS_1 KTS_2
ECC-CDH PSD KAS KeyEphemeral ECC-CDH private key used in KAS256-bitAsymmetric Private Key - CSPGenerated Internally by DRBGN/AKAS
Shared SecretUsed to derive session keys256 bitsShared Secret - CSPN/AKAS (dhEphem C(2e, 0s, FFC DH))KAS
Entropy InputInstantiate the DRBG512 bitsEntropy - CSPExternallyN/ADRBG Generate
DRBG SeedSeeding the DRBG1024 bitsEntropy - CSPGenerated Internally by DRBG (during manufacturing)N/ADRBG Generate
9.4 SSPS

Table 19: SSP Table 1 This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 29
DRBG Working StateInternal working state of the DRBGN/AN/A - CSPGenerated Internally by DRBGN/ADRBG Generate
Mail Piece KeyAuthenticate stored mail piece data256-bitSymmetric Key - CSPGenerated Internally by DRBGN/AMessage Authentication
PasswordAuthenticate User Role128-bitN/A - CSPExternallyN/A
SWAK (Software Authentication Key)Used to verify loaded application code128-bitAsymmetric Public Key - PSPExternallyN/AECDSA Signature Verification
Manufacturing KeyValidates Vendor Certificate128-bitAsymmetric Public Key - PSPExternallyN/AECDSA Signature Verification
Vendor KeyAuthenticates CO role128-bitAsymmetric Public Key - PSPExternallyN/AECDSA Signature Verification
Certificate KeyAuthenticates CO role. Validates Authority Data, including other public keys128-bitAsymmetric Public Key - PSPExternallyN/AECDSA Signature Verification
Download KeyAuthenticates CO role128-bitAsymmetric Public Key - PSPExternallyN/AECDSA Signature Verification
ECC-CDH Infrastructure KAS Public KeyECDH public counterpart received as part of tKAS128-bitAsymmetric Public Key - PSPExternallyN/AKAS
ECC-CDH PSD KAS Public KeyECDH public key transmitted as part of KAS128-bitAsymmetric Public Key - PSPGenerated Internally by DRBGN/AKAS
Debit Public KeyOutput to the CO. Used to allow the CO to authenticate the debit records112-bit or 128-bitN/A - PSPGenerated Internally by DRBGN/AKTS_1, KTS_2
Operation Public KeyOutput to the CO. Used to allow the CO to authenticate the PSD128-bitAsymmetric Public Key - PSPGenerated Internally by DRBGN/AKTS_1, KTS_2
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
KEK (Key Encryption Key)N/ANVRAM: PlaintextN/AZeroization, Tamper or removal of all powerDRBG Working State: Generated from

Table 20: SSP Table 2 This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 30
KEK’ (Backup Key Encryption Key)N/ANVRAM: EncryptedN/AZeroization, Tamper or removal of all powerDRBG Working State: Generated from KEK (Key Encryption Key): Encrypted by
KAK (Key Authentication Key)N/ANVRAM: EncryptedN/AZeroization, Tamper or removal of all powerDRBG Working State: Generated from KEK (Key Encryption Key): Encrypted by
Debit Private KeyN/ANVRAM: EncryptedN/AZeroization, Tamper or removal of all powerDRBG Working State: Generated from Debit Public Key: Paired with KEK (Key Encryption Key): Encrypted by
Debit Secret KeyInput (Encrypted)NVRAM: EncryptedN/AZeroization, Tamper or removal of all powerKEK (Key Encryption Key): Encrypted by
Operation Private KeyN/ANVRAM: EncryptedN/AZeroization, Tamper or removal of all powerDRBG Working State: Generated from Operation Public Key: Paired with KEK (Key Encryption Key): Encrypted by
Session Authentication KeyN/ASRAM: PlaintextFor the life of the Secure SessionZeroization, Tamper or removal of all powerShared Secret (Z): Derived from
Session Privacy KeyN/ASRAM: PlaintextFor the life of the Secure SessionZeroization, Tamper or removal of all powerShared Secret (Z): Derived from
ECC-CDH PSD KAS KeyN/ASRAM: PlaintextUntil UseImmediately after useECC-CDH PSD KAS Public Key: Paired with DRBG Working State: Generated from Shared Secret (Z): Derives
Shared Secret (Z)N/ASRAM: PlaintextUntil UseImmediately after useSession Authentication Key: Derives Session Privacy Key: Derives ECC-CDH Infrastructure KAS Public Key: Derived From ECC-CDH PSD KAS Key: Derived From
Entropy InputN/ASRAM: PlaintextUntil UseImmediately after useDRBG Working State: Derives
DRBG SeedN/ASRAM: PlaintextUntil UseImmediately after useDRBG Working State: Derives
DRBG Working StateN/ANVRAM: EncryptedN/AZeroization, Tamper or removal of all powerEntropy Input: Derived from KEK (Key Encryption Key): Encrypted by
Mail Piece KeyN/ANVRAM: EncryptedN/AZeroization, Tamper or removal of all powerKEK (Key Encryption Key): Encrypted by
PasswordN/ANVRAM: EncryptedN/AZeroization, Tamper or removal of all powerKEK (Key Encryption Key): Encrypted by
SWAK (Software Authentication Key)N/APlaintextN/AN/AN/A
Manufacturing KeyN/ANVRAM: EncryptedN/AZeroization, Tamper or removal of all powerKEK (Key Encryption Key): Encrypted by
Vendor KeyInput (Encrypted)NVRAM: EncryptedN/AZeroization, Tamper or removal of all powerKEK (Key Encryption Key): Encrypted by

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 31
Certificate KeyInput (Encrypted)NVRAM: EncryptedN/AZeroization, Tamper or removal of all powerKEK (Key Encryption Key): Encrypted by
Download KeyInput (Encrypted)NVRAM: EncryptedN/AZeroization, Tamper or removal of all powerKEK (Key Encryption Key): Encrypted by
ECC-CDH Infrastructure KAS Public KeyInput (Plaintext)SRAM: PlaintextUntil UseZeroization, Tamper or removal of all powerShared Secret (Z): Derives
ECC-CDH PSD KAS Public KeyOutput (Plaintext)SRAM: PlaintextUntil UseZeroization, Tamper or removal of all powerECC-CDH PSD KAS Key: Paired with DRBG Working State: Generated from
Debit Public KeyOutput (Encrypted)NVRAM: EncryptedN/AZeroization, Tamper or removal of all powerDRBG Working State: Generated from Debit Private Key: Paired With KEK (Key Encryption Key): Encrypted by
Operation Public KeyOutput (Encrypted)NVRAM: EncryptedN/AZeroization, Tamper or removal of all powerDRBG Working State: Generated from Operation Private Key: Paired with KEK (Key Encryption Key): Encrypted by

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 32
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Firmware Integrity of BootloaderRSA 2048 (Cert. #A2440)RSA Signature VerificationSW/FW IntegritySuccess: No Error Code; Failure: Error CodeRSA 2048 Digital Signature Verification
Firmware Integrity of FirmwareECDSA P-256 (Cert. #A2437)ECDSA Signature VerificationSW/FW IntegritySuccess: No Error Code; Failure: Error CodeECDSA P-256 Digital Signature Verification
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (Cert. #A2435)256-bitKATCASTSuccess: No Error Code; Failure: Error CodeEncrypt and Decrypt KATsPower-up, Periodically & on-demand
AES-KW (Cert. #A2435)256-bitKATCASTSuccess: No Error Code; Failure: Error CodeEncrypt and Decrypt KATsPower-up, Periodically & on-demand
ECDSA (Cert. #A2437)P-256KATCASTSuccess: No Error Code; Failure: Error CodeSignature Generation and Verification KATsPower-up, Periodically & on-demand
Hash DRBG (Cert. #A2436)N/AKATCASTSuccess: No Error Code; Failure: Error CodeInstantiate and Generate KATPower-up, Periodically & on-demand
10 SELF-TESTS
10.1 PRE-OPERATIONAL SELF -TESTS

The following pre-operational tests are performed upon power-up, on-demand and periodically. Prior to the PreOperational firmware integrity self-tests being performed, the module performs the required known answer test (KAT) on the implementation. Table 21: Pre-Operational Self-Tests The module also includes critical function tests that test the real time clock (RTC) and BRAM.

10.2 CONDITIONAL SELF-TESTS

The following conditional tests are performed upon power-up, on-demand and periodically. Table 22: Conditional Self-Tests This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 33
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC (Cert. #A2438)256-bitKATCASTSuccess: No Error Code; Failure: Error CodeHMAC-SHA-256 KATPower-up, Periodically & on-demand
KAS-ECC-SSC SP800-56Ar3 (Cert. #A2439)P-256KATCASTSuccess: No Error Code; Failure: Error CodeKAS-ECC Shared Secret Computation KAT per IG D. FPower-up, Periodically & on-demand
KDA OneStep SP800-56Cr1 (Cert. #A2439)256-bitKATCASTSuccess: No Error Code; Failure: Error CodeKDA KATPower-up, Periodically & on-demand
RSA (Cert. #A2440)2048-bitKATCASTSuccess: No Error Code; Failure: Error CodeSignature Verification KATPower-up, Periodically & on-demand
Firmware Load TestECDSA P- 256Digital Signature VerificationSW/FW LoadSuccess: No Error Code; Failure: Error CodeFirmware load test occurs during 'Load Parameters Software Update' serviceDuring Firmware Updates
Public Key ValidationP-256N/ACritical FunctionSuccess: No Error Code; Failure: Error CodeOccurs during KAS upon receipt of the connected host application public keyDuring key agreement
ECC Pairwise Consistency TestP-256PCTPCTSuccess: No Error Code; Failure: Error CodePairwise consistency testDuring key agreement
ECDSA Key GenerationP-256PCTPCTSuccess: No Error Code; Failure: Error CodePairwise consistency testAfter key pair generation

This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 34
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Firmware Integrity of BootloaderRSA Signature VerificationSW/FW IntegrityEvery Power- OnAutomatic invocation of self- test service
Firmware Integrity of FirmwareECDSA Signature VerificationSW/FW IntegrityEvery Power- OnAutomatic invocation of self- test service
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (Cert. #A2435)KATCAST24 hoursAutomatic invocation of self- test service
AES-KW (Cert. #A2435)KATCAST24 hoursAutomatic invocation of self- test service
ECDSA (Cert. #A2437)KATCAST24 hoursAutomatic invocation of self- test service
Hash DRBG (Cert. #A2436)KATCAST24 hoursAutomatic invocation of self- test service
HMAC (Cert. #A2438)KATCAST24 hoursAutomatic invocation of self- test service
KAS-ECC-SSC NIST SP 800-56Ar3 (Cert. #A2439)KATCAST24 hoursAutomatic invocation of self- test service
KDA OneStep NIST SP 800-56Cr1 (Cert. #A2439)KATCAST24 hoursAutomatic invocation of self- test service
RSA (Cert. #A2440)KATCAST24 hoursAutomatic invocation of self- test service

The pre-operational and conditional algorithm self-tests are also automatically run on a periodic basis every 24 hrs. Table 23: Pre-Operational Periodic Information Table 24: Conditional Periodic Information This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 35
NameDescriptionConditionsRecovery MethodIndicator
TamperedOccurs in the event of a physical tamper event e.g. removal of battery power, physical breach.Tamper EventNoneError Code
Hard ErrorAn error condition that is not recoverable.Self-Test FailureNoneError Code
Soft ErrorNon-critical, recoverable errors that allow the module to transition back to operation.Non-Critical Error OccurrencesAutomated or Power-CycleError Code

ERROR STATES The module incorporates a single error state (refer to Table 25). Table 25: Error States

10.4 OPERATOR INITIATION OF SELF-TESTS

Self-tests may be triggered by the user on demand by power cycling the module (‘Reboot PSD’) or invoking the ‘Perform Diagnostic Test’ or ‘Perform Full Diagnostics’ services, which allows either individual or all tests to be run.

11 LIFE-CYCLE ASSURANCE

There are no specific maintenance requirements.

11.1 INSTALLATION, INITIALIZATION, AND STARTUP PROCEDURES

The module is initialized within PB manufacturing and installed into a PB manufactured PES. The PES is authorized and shipped to an end customer.

11.2 ADMINISTRATOR GUIDANCE

The device will only be provided to or retrieved from PB customers as part of a postage evidencing system. Administration guidance, in the form of API definitions, exists for PB engineers involved in the development of PES equipment.

11.3 NON-ADMINISTRATOR GUIDANCE

The device will only be provided to customers as part of a postage meter. Any user guidance will be provided as part of that equipment.

11.4 DESIGN AND RULES

The following security rules are enforced by the cryptographic module to ensure the FIPS 140-3 security requirements are met. This document may be freely reproduced and distributed, but only in its entirety and without modification.

Page 36
  1. The module must support an Approved and non-Approved mode of operation. The Approved mode indicator must be returned to the end user.
  2. The module must not allow unauthenticated operators to have any access to the module’s cryptographic services.
  3. The module must inhibit data output during self-tests, firmware load, zeroization and error states.
  4. The module must logically disconnect data output from the processes performing zeroization and key generation.
  5. The module must enforce identity-based authentication.
  6. The module must not retain the authentication of an operator following power-off or reboot.
  7. The module must support the following roles: Cryptographic Officer and User.
  8. The module must not permit the input or output of plaintext cryptographic keys or other CSPs.
  9. The module must not support a bypass mode or maintenance mode.
  10. The module must not support the following logically distinct interfaces: − Data input interface − Data output interface − Control input interface − Status output interface − Power interface.
  11. The module must protect critical security parameters from unauthorized disclosure, modification and substitution.
  12. The module must perform power-on, on-demand and periodic self-testing.
  13. The module must log errors whenever an error state is entered.
  14. The module must not perform any cryptographic functions while in an error state.
  15. The module must not support multiple concurrent operators.
11.5 END OF LIFE

Once a module is no longer needed by a customer, they will walk through a process called withdrawal and return the PSD to PB where an operator will perform the “re-initialize” operation, zeroizing the KEK. Once a module has been zeroized, it must be returned to the factory for software loading and parameterizing prior to being usable by a customer.

12 MITIGATION OF OTHER ATTACKS

The module is not purposefully designed to mitigate any attacks beyond the scope of FIPS 140-3 requirements. This document may be freely reproduced and distributed, but only in its entirety and without modification.