All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Allegro Cryptographic Engine

Certificate#4944StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusHistoricalVendorAllegro Software Development Corporation
Medium review priority  ·  no TCB surface named  ·  last validated 18 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusHistorical
CaveatInterim validation. No assurance of the minimum strength of generated SSPs (e.g., keys)
VendorAllegro Software Development Corporation

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Allegro Cryptographic Engine
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Allegro Cryptographic Engine
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Allegro Software Development Corporation Allegro Cryptographic Engine Document Revision 1.1 September 2024

Page 2
Table of Contents
#SectionPage
Page 3

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)7
Table 3: Tested Operational Environments - Software, Firmware, Hybrid7
Table 4: Modes List and Description7
Table 5: Approved Algorithms - Cipher8
Table 6: Approved Algorithms - Message Authentication8
Table 7: Approved Algorithms - Symmetric Key Wrap8
Table 8: Approved Algorithms - Asymmetric Key Generation8
Table 9: Approved Algorithms - Asymmetric Key Verification9
Table 10: Approved Algorithms - Asymmetric Signature Generation9
Table 11: Approved Algorithms - Asymmetric Signature Verification9
Table 12: Approved Algorithms - Random Number Generation9
Table 13: Approved Algorithms - Shared Secret Computation9
Table 14: Approved Algorithms - Key Derivation10
Table 15: Approved Algorithms - Hash Function10
Table 16: Approved Algorithms - Safe Primes Generation10
Table 17: Approved Algorithms - Safe Primes Verification10
Table 18: Vendor-Affirmed Algorithms10
Table 19: Non-Approved, Allowed Algorithms11
Table 20: Non-Approved, Allowed Algorithms with No Security Claimed11
Table 21: Security Function Implementations13
Table 22: Ports and Interfaces16
Table 23: Roles16
Table 24: Approved Services25
Table 25: Storage Areas26
Table 26: SSP Input-Output Methods26
Table 27: SSP Zeroization Methods26
Table 28: SSP Table 129
Table 29: SSP Table 232
Table 30: Pre-Operational Self-Tests33
Table 31: Conditional Self-Tests36
Table 32: Pre-Operational Periodic Information36
Table 33: Conditional Periodic Information39
Table 34: Error States39
Figure 1: Block Diagram6
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is a non-proprietary cryptographic module security policy for the Allegro Cryptographic Engine (Software Version 6.50) from Allegro Software Development Corporation. This security policy contains specification of the security rules, under which the cryptographic module operates, including the security rules derived from the requirements of the FIPS 140-3 standard.

1.2 Security Levels
2.1 Description

Purpose and Use: The Allegro Cryptographic Engine (also informally referred to as “ACE,” and in this security policy as “the module”) is a software cryptographic module that runs on a general-purpose computer (GPC). It provides FIPS 140-3 approved cryptography that can be used by calling applications via a C language Application Programming Interface (API). The module meets the overall requirements applicable to a multi-chip stand-alone embodiment at FIPS 1403, Level 1. The module is a shared cryptographic library providing symmetric and asymmetric encryption and decryption, message digest, message authentication, random number generation, key generation, digital signature generation and verification, and other cryptographic functionality. As a software cryptographic module that executes on a general-purpose computer, the module depends upon the physical characteristics of the host platform. The module’s physical perimeter is defined by the enclosure around the host system on which it executes. The logical interface of the module is its Application Programming Interface, which a calling application must utilize to invoke the cryptographic services of the module, pass input data to the module and receive output data and status from the module. The module is packaged as a shared object for Linux 5.15 (Mint 21) and Windows 11 Pro. The module also includes a data file that is used for verifying the integrity of the module. The module has been validated on Linux

5.15 (Mint 21) and Windows 11 Pro.

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 6
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
Acelib.so (Linux 5.15) (Mint 21) (PAA Enabled)6.50PAA Enabled BinaryHMAC-SHA2-256 (AceLib.dat)
AceDll.dll (Windows 11 Pro) (PAA Enabled)6.50PAA Enabled BinaryHMAC-SHA2-256 (AceDll.dll.dat)

The module meets the overall requirements applicable at Level 1 security of FIPS 140-3. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The module’s cryptographic boundary is comprised of a single binary:

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
Acelib.so (Linux 5.15) (Mint 21) (PAA Disabled)6.50PAA Disabled BinaryHMAC-SHA2-256 (AceLib.dat)
AceDll.dll (Windows 11 Pro) (PAA Disabled)6.50PAA Disabled BinaryHMAC-SHA2-256 (AceDll.dll.dat)
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Linux 5.15 (Mint 21)Intel NUCIntel® Core™ i7-1260PNoN/A6.50
Linux 5.15 (Mint 21)Intel NUCIntel® Core™ i7-1260PYesN/A6.50
Windows 11 ProIntel NUCIntel® Core™ i7-1260PNoN/A6.50
Windows 11 ProIntel NUCIntel® Core™ i7-1260PYesN/A6.50
Mode NameDescriptionTypeStatus Indicator
Approved ModeMode of operation where only approved security functions and services can be utilizedApprovedPass
AlgorithmCAVP CertPropertiesReference
AES-CBCA3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3332Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) Tested Operational Environments - Software, Firmware, Hybrid: Table 3: Tested Operational Environments - Software, Firmware, Hybrid The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

There are no components excluded from the module. Modes List and Description: Table 4: Modes List and Description The module supports an approved mode of operation only.

2.5 Algorithms

Approved Algorithms: Cipher (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 8
AlgorithmCAVP CertPropertiesReference
AES-CTRA3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-FF1A3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38G
AES-GCMA3332Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-OFBA3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A3332Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AlgorithmCAVP CertPropertiesReference
AES-CMACA3332Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-GMACA3332Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
HMAC-SHA-1A3332Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2-224A3332Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2-256A3332Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2-384A3332Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA2-512A3332Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA3-224A3332Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA3-256A3332Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA3-384A3332Key Length - Key Length: 256-448 Increment 8FIPS 198-1
HMAC-SHA3-512A3332Key Length - Key Length: 256-448 Increment 8FIPS 198-1
AlgorithmCAVP CertPropertiesReference
AES-KWA3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3332Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AlgorithmCAVP CertPropertiesReference
ECDSA KeyGen (FIPS186-4)A3332Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
RSA KeyGen (FIPS186-4)A3332Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.3 Private Key Format - StandardFIPS 186-4

Table 5: Approved Algorithms - Cipher Message Authentication Table 6: Approved Algorithms - Message Authentication Symmetric Key Wrap Table 7: Approved Algorithms - Symmetric Key Wrap Table 8: Approved Algorithms - Asymmetric Key Generation (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 9
AlgorithmCAVP CertPropertiesReference
ECDSA KeyVer (FIPS186-4)A3332Curve - P-192, P-224, P-256, P-384, P-521FIPS 186-4
AlgorithmCAVP CertPropertiesReference
ECDSA SigGen (FIPS186-4)A3332Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
RSA SigGen (FIPS186-4)A3332Signature Type - ANSI X9.31, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
AlgorithmCAVP CertPropertiesReference
ECDSA SigVer (FIPS186-4)A3332Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
RSA SigVer (FIPS186-4)A3332Signature Type - ANSI X9.31, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
AlgorithmCAVP CertPropertiesReference
Hash DRBGA3332Mode - SHA2-256, SHA2-512SP 800-90A Rev. 1

Algorithm KAS-ECC-SSC Sp800- 56Ar3 KAS-FFC-SSC Sp800- 56Ar3

C C A3332 A3332

AVP ert

Properties Domain Parameter Generation Methods - P-224, P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder Domain Parameter Generation Methods - MODP- 2048, MODP-3072

Reference SP 800-56A Rev. 3 SP 800-56A Rev. 3

AlgorithmCAVP CertPropertiesReference
KDA HKDF Sp800- 56Cr1A3332Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA3-224, SHA3-256, SHA3-384, SHA3-512SP 800-56C Rev. 2
KDF SSH (CVL)A3332Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512SP 800-135 Rev. 1
PBKDFA3332Iteration Count - Iteration Count: 1000-100000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132

Asymmetric Key Verification Table 9: Approved Algorithms - Asymmetric Key Verification Table 10: Approved Algorithms - Asymmetric Signature Generation Asymmetric Signature Verification Table 11: Approved Algorithms - Asymmetric Signature Verification Random Number Generation Table 12: Approved Algorithms - Random Number Generation Table 13: Approved Algorithms - Shared Secret Computation Key Derivation (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 10
AlgorithmCAVP CertPropertiesReference
TLS v1.2 KDF RFC7627 (CVL)A3332Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A3332HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - PSK-DHESP 800-135 Rev. 1
AlgorithmCAVP CertPropertiesReference
SHA-1A3332Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-224A3332Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-256A3332Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-384A3332Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-512A3332Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA3-224A3332Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-256A3332Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-384A3332Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-512A3332Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHAKE-128A3332Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A3332Output Length - Output Length: 16-65536 Increment 8FIPS 202
AlgorithmCAVP CertPropertiesReference
Safe Primes Key GenerationA3332Safe Prime Groups - modp-2048, modp- 3072SP 800-56A Rev. 3
AlgorithmCAVP CertPropertiesReference
Safe Primes Key VerificationA3332Safe Prime Groups - modp-2048, modp- 3072SP 800-56A Rev. 3
NamePropertiesImplementationReference
CKG Section 4Key Type:SymmetricN/ANIST SP 800-133 Rev. 2 (Section 4)
CKG Section 4Key Type:Seed for Asymmetric KeyN/ANIST SP 800-133 Rev. 2 (Section 4)
CKG Section 6.1Key Type:SymmetricN/ANIST SP 800-133 Rev. 2 (Section 6.1)
NamePropertiesImplementationReference
Key UnwrapKey Type:SymmetricN/AIG D.G

Table 14: Approved Algorithms - Key Derivation Hash Function Table 15: Approved Algorithms - Hash Function Table 16: Approved Algorithms - Safe Primes Generation Table 17: Approved Algorithms - Safe Primes Verification The module’s approved algorithms are specified above. There are some algorithm modes that were tested but not implemented by the module. Only the algorithms, modes, and key sizes that are implemented by the module are shown in this table. Vendor-Affirmed Algorithms:

6.1 6.1)

Table 18: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 11
NameCaveatUse and Function
MD5Allowed in the approved mode with no security claimedUsed for TLS 1.2 interoperability
NameTypeDescriptionPropertiesAlgorithms
DRBGDRBGRandom Bit GenerationHash DRBG
Message DigestSHACreate Message DigestSHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA3-224 SHA3-256 SHA3-384 SHA3-512 SHAKE-128 SHAKE-256
Generate Digital SignatureDigSig-SigGenCreate Digital SignaturesECDSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4)
Verify Digital SignatureDigSig-SigVerVerify Digital SignatureECDSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4)
Generate Symmetric KeysCKG DRBGGenerate Symmetric KeysHash DRBG CKG Section 4 Key Type: Symmetric CKG Section 6.1 Key Type: Symmetric

Table 19: Non-Approved, Allowed Algorithms Caveats:

Page 12
NameTypeDescriptionPropertiesAlgorithms
Generate Asymmetric KeysAsymKeyPair- KeyGen CKGGeneration of Asymmetric KeysECDSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) Hash DRBG CKG Section 4 Key Type: Seed for Asymmetric Key
Shared Secret Computation (KAS- FFC-SSC)AsymKeyPair- SafePri KAS-SSCShared Secret Computation (KAS- FFC-SSC)Shared Secret Computation:Provides between 112 and 128 bits of encryption strengthKAS-FFC-SSC Sp800-56Ar3 Safe Primes Key Generation Safe Primes Key Verification
Shared Secret Computation (KAS- ECC-SSC)AsymKeyPair- DomPar AsymKeyPair- KeyGen AsymKeyPair- PubKeyVal DRBG KAS-SSCNIST SP 800-56Ar3 shared secret computation (KAS- ECC-SSC)Shared Secret Computation:Provides between 128 and 256 bits of encryption strengthKAS-ECC-SSC Sp800-56Ar3 ECDSA KeyGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigVer (FIPS186-4) Hash DRBG
Derive Key (HKDF)KAS-56CKDF SHAKey DerivationKDA HKDF Sp800- 56Cr1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA3-224 HMAC-SHA3-256 HMAC-SHA3-384 HMAC-SHA3-512
Derive Key (TLS 1.2)KAS-135KDF SHAKey Derivation for TLS 1.2 RFC 7627TLS v1.2 KDF RFC7627 SHA2-256 SHA2-384 SHA2-512
Derive Key (TLS 1.3)KAS-135KDF SHAKey Derivation for TLS 1.3TLS v1.3 KDF SHA2-256 SHA2-384
Derive Key (SSH)KAS-135KDF SHAKey Derivation for SSHKDF SSH SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512
Derive Key (PBKDF)MAC PBKDFPassword-Based Key DerivationPBKDF HMAC-SHA-1
Message AuthenticationMACMessage Authentication AlgorithmsHMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 13
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA3-224 HMAC-SHA3-256 HMAC-SHA3-384 HMAC-SHA3-512 AES-CMAC AES-GMAC Hash DRBG CKG Section 4 Key Type: Symmetric CKG Section 6.1 Key Type: Symmetric
Symmetric CipherBC-Auth BC-UnAuthEncryption & DecryptionAES-CBC AES-CCM AES-CFB1 AES-CFB128 AES-CFB8 AES-ECB AES-FF1 AES-GCM AES-KW AES-KWP AES-OFB AES-XTS Testing Revision 2.0 AES-CTR
Key WrappingKTS-WrapKey Wrapping Method (SP 800- 38F) (IG D.G)KTS:Key establishment methodology provides between 128 and 256 bits of encryption strengthAES-KW AES-KWP
Verify Asymmetric KeysAsymKeyPair- KeyVerVerify Asymmetric KeysECDSA KeyVer (FIPS186-4)
CKG Section 4CKGNIST SP 800-133 Rev. 2 (Section 4)CKG Section 4
CKG Section 6.1CKGNIST SP 800-133 Rev. 2 (Section 6.1)CKG Section 6.1

Table 21: Security Function Implementations

2.7 Algorithm Specific Information

SHA-3 & SHAKE (IG C.C) SHA-3 and SHAKE were tested and validated on all of the module’s operating environments. RSA (IG C.F) (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 14
Page 15

PBKDF2 (IG D.N) The Allegro Cryptographic Engine requires the password to be at least ten characters in length, the iteration count at least 1000, the salt at least 128 bits in length, and that the master key output from the PBKDF2 is at least 112 bits in length. Master keys may be used as Device Protection Keys (Option 1(a) from Section 5.4 of NIST SP 800132). Alternately, they may be used with a key derivation function to produce a Device Protection Key (Option 1(b) from Section 5.4 of NIST SP 800-132). Passwords passed to the PBKDF2 implemented shall have a length of at least 10 characters and shall consist of upper- and lower-case letters and numbers (52 letters) and digits (0-9) as well as characters from the set ~!@#$%^&*. There are 71 different characters that can be used, in any order. The probability of guessing this password at random is 7110 = 1: 3.3 * 1018. This provides a password search space of more than 60 bits. The length of the random salt used in PBKDF2 must be at least 128 bits. The iteration count used in PBKDF2 must be at least

1000 and should be as large as is tolerable by the calling application. The length of the master key generated by

PBKDF2 must be at least 112 bits. The calling application may use the master key, the Data Protection Key, or it may derive the Data Protection Key from the master key using a key derivation function. The Data Protection Key shall be used for storage purposes only and shall use only approved encryption algorithms.

2.8 RBG and Entropy

The entropy for seeding the SP 800-90Ar1 DRBG is determined by the user of the module, which is outside of the module’s cryptographic boundary. To be compliant, the target application shall supply at least 256 bits of entropy in order to meet the security strength required for the random number generation mechanism. Since entropy is loaded passively into the module, there is no assurance of the minimum strength of generated SSPs (e.g., keys).

2.9 Key Generation

SSPs that are generated internally by the module, are generated using the module's approved DRBG.

2.10 Key Establishment

The module is capable of performing key establishment when utilizing the implemented NIST SP 800-56Ar3 shared secret computation methods, with one of the approved key derivation functions. The module also supports key transport methods compliant with NIST SP 800-38F.

2.11 Industry Protocols

While the module does not implement the TLS or SSH protocols, it does implement the key derivation functions for both, per NIST SP 800-135r1.

2.12 Additional Information

Please see Section 11 for details regarding the preparation of the operational environments, and installation of the module.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 16
Physical PortLogical Interface(s)Data That Passes
N/AData InputInput data passed via API calls as function arguments or in memory buffers referenced by function arguments
N/AData OutputData returned by API calls using function arguments and related memory buffers
N/AControl InputAPI function calls that initialize and control the operation of the module
N/AStatus OutputValues returned from API calls
NameTypeOperator TypeAuthentication Methods
CORoleCrypto OfficerNone
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access
AcInit()Initialize the module for use in Approved modeSuccessf ul Invocatio n (Pass)N/AInvocation Success or Invocation FailureNoneCO
AcDeInit()Zeroize all keys and CSPs and disable crypto servicesSuccessf ul Invocatio n (Pass)N/AInvocation Success or Invocation FailureNoneCO
AcRunSelfTest()Run cryptographic self-tests on demandSuccessf ul Invocatio n (Pass)N/AInvocation Success or Invocation FailureDRBG Message Digest Generate DigitalCO

Table 22: Ports and Interfaces As a software cryptographic module, the module’s physical and electrical characteristics, manual controls and physical indicators are those of the host system. The host system provides physical ports that the operating system physical indicators of the GPC. The module does not support a control output interface. The module does not identify or authenticate the operator. The Crypto Officer role is assumed by the operator. Only one operator can operate the module at any time.

4.2 Roles

Table 23: Roles The Allegro Cryptographic Engine supports only one role, which is the Crypto Officer role. (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 17
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access
Signature Verify Digital Signature Generate Asymmetric Keys Shared Secret Computatio n (KAS- FFC-SSC) Shared Secret Computatio n (KAS- ECC-SSC) Derive Key (HKDF) Derive Key (TLS 1.2) Derive Key (TLS 1.3) Derive Key (SSH) Derive Key (PBKDF) Message Authenticati on Symmetric Cipher Verify Asymmetric Keys
AcAceLibraryInfo()Return the module name and versionSuccessf ul Invocatio n (Pass)N/AModule Name, Major Version, Minor Version, Build Number, Invocation Success or Invocation FailureNoneCO
AcGenerateRandomNumb ers()Generate random dataSuccessf ul Invocatio n (Pass)API call paramete rsRandom Number, Invocation Success or Invocation FailureDRBGCO

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 18
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access
AcDigest() AcDigestInit() AcDigestUpdate() AcDigestFinal()Create message digest from input dataSuccessf ul Invocatio n (Pass)API call paramete rsHash, Invocation Success or Invocation FailureMessage DigestCO
AcDigestClone()Duplicate a message digestSuccessf ul Invocatio n (Pass)API call paramete rsHash, Invocation Success or Invocation FailureNoneCO
AcKeyedDigestInit()Create a keyed message digest of input dataSuccessf ul Invocatio n (Pass)API call paramete rsDigest, Invocation Success or Invocation FailureMessage Digest Message Authenticati onCO - HMAC Key: R,E - AES GMAC Key: R,E - AES CMAC Key: R,E
AcSign() AcSignInit() AcSignUpdate() AcSignFinal()Create a Digital SignatureSuccessf ul Invocatio n (Pass)API call paramete rsSignature, Invocation Success or Invocation FailureGenerate Digital SignatureCO - RSA Private Key: R,E - ECDSA Private Key: R,E
AcSignDigestBuffer()Create a digital signature for a previously computed message digestSuccessf ul Invocatio n (Pass)API call paramete rsSignature, Invocation Success or Invocation FailureGenerate Digital SignatureCO - RSA Private Key: R,E - ECDSA Private Key: R,E
AcVerify() AcVerifyInit() AcVerifyUpdate() AcVerifyFinal()Verify a digital signatureSuccessf ul Invocatio n (Pass)API call paramete rsSignature, Invocation Success or Invocation FailureVerify Digital Signature Verify Asymmetric KeysCO - RSA Public Key: R,E - ECDSA Public Key: R,E
AcVerifyDigestBuffer()Verify a digital signature for a previously computed digestSuccessf ul Invocatio n (Pass)API call paramete rsSignature, Invocation Success or Invocation FailureVerify Digital Signature Verify Asymmetric KeysCO - RSA Public Key: R,E - ECDSA Public Key: R,E
AcEncryptInit()Encrypt or decrypt a block of dataSuccessf ul Invocatio n (Pass)API call paramete rsPlaintext, Ciphertext, Invocation Success or Invocation FailureSymmetric CipherCO - AES Key : R,E - AES GCM Key: R,E - AES GCM IV: R,E

R,E R,E (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 19
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access - AES CCM Key: R,E - AES-XTS Testing Revision 2.0 Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E
AcEncryptUpdate()Encrypt or decrypt a block of dataSuccessf ul Invocatio n (Pass)API call paramete rsPlaintext, Ciphertext, Invocation Success or Invocation FailureSymmetric CipherCO - AES Key : R,E - AES GCM Key: R,E - AES GCM IV: R,E - AES CCM Key: R,E - AES-XTS Testing Revision 2.0 Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E
AcEncryptFinal()Encrypt or decrypt a block of dataSuccessf ul Invocatio n (Pass)API call paramete rsPlaintext, Ciphertext, Invocation Success or Invocation FailureSymmetric CipherCO - AES Key : R,E - AES GCM Key: R,E - AES GCM IV: R,E - AES CCM Key: R,E - AES-XTS Testing Revision 2.0 Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E
AcGenerateKey()Generate symmetric keysSuccessf ul Invocatio n (Pass)API call paramete rsKey, Invocation Success or Invocation FailureGenerate Symmetric Keys CKG Section 4CO - AES Key : G,W - AES GCM Key: G,W

R,E R,E R,E (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 20
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access
CKG Section 6.1- AES CMAC Key: G,W - AES-XTS Testing Revision 2.0 Key: G,W - Key Encryption Key (KEK): G,W
AcGenerateKeyPair()Generate asymmetric key pairsSuccessf ul Invocatio n (Pass)API call paramete rsKeyPair, Invocation Success or Invocation FailureGenerate Asymmetric Keys CKG Section 4CO - RSA Private Key: G,W - RSA Public Key: G,W - ECDSA Private Key: G,W - ECDSA Public Key: G,W - ECDH Private Components : G,W - ECDH Public Components : G,W - DH Private Components : G,W - DH Public Components : G,W
AcBuildKeyPairFromPara ms()Generate asymmetric key pairs using specific key parametersSuccessf ul Invocatio n (Pass)API call paramete rsKeyPair, Invocation Success or Invocation FailureGenerate Asymmetric Keys Shared Secret Computatio n (KAS- FFC-SSC) Shared Secret Computatio n (KAS- ECC-SSC)CO - RSA Private Key: G,W - RSA Public Key: G,W - ECDSA Private Key: G,W - ECDSA Public Key: G,W - ECDH Private Components : G,W

G,W G,W G,W : G,W : G,W : G,W : G,W : G,W (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 21
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access - ECDH Public Components : G,W - DH Private Components : G,W - DH Public Components : G,W
AcExportKey()Wrap KeySuccessf ul Invocatio n (Pass)API call paramete rsKey/KeyPair, Invocation Success or Invocation FailureKey WrappingCO - Key Encryption Key (KEK): R,E
AcImportKey()Unwrap KeySuccessf ul Invocatio n (Pass)API call paramete rsKey/KeyPair, Invocation Success or Invocation FailureKey WrappingCO - Key Encryption Key (KEK): W,E
AcKeySize()Return the key size for a selected KeySuccessf ul Invocatio n (Pass)API call paramete rsKey Size, Invocation Success or Invocation FailureNoneCO
AcKeyExchange()Establish a shared secretSuccessf ul Invocatio n (Pass)API call paramete rsShared, Secret, Key, Invocation Success or Invocation FailureShared Secret Computatio n (KAS- FFC-SSC) Shared Secret Computatio n (KAS- ECC-SSC)CO - ECDH Private Components : R,E - ECDH Public Components : R,E - DH Private Components : R,E - DH Public Components : R,E
AcDeriveKey()Derive a keySuccessf ul Invocatio n (Pass)API call paramete rsKey, Invocation Success or Invocation FailureDerive Key (TLS 1.2) Derive Key (TLS 1.3) Derive Key (PBKDF)CO - TLS Session Key: G,W - PBKDF2 DPK: G,W - AES Key : G,W - TLS RSA Premaster Secret: G,W - TLS Master

: G,W : G,W : G,W : R,E : R,E G,W (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 22
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access Secret: G,W - TLS Integrity Key: G,W - PBKDF2 Password: G,W - TLS Extended Master Secret: G,W
AcReleaseHandle()Zeroize KeysSuccessf ul Invocatio n (Pass)API call paramete rsInvocation Success or Invocation FailureNoneCO - AES Key : Z - AES GCM Key: Z - AES GCM IV: Z - AES CCM Key: Z - AES-XTS Testing Revision 2.0 Key: Z - AES CMAC Key: Z - AES GMAC Key: Z - HMAC Key: Z - Key Encryption Key (KEK): Z - PBKDF2 DPK: Z - PBKDF2 Password: Z - RSA Private Key: Z - ECDSA Private Key: Z - ECDH Private Components : Z - TLS RSA Premaster Secret: Z - TLS Master

G,W G,W Z Z Z Z :Z (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 23
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access Secret: Z - TLS Session Key: Z - TLS Integrity Key: Z - DRBG Entropy: Z - DRBG Seed: Z - DRBG ‘C’ Value: Z - DRBG ‘V’ Value : Z - RSA Public Key: Z - ECDSA Public Key: Z - ECDH Public Components : Z - TLS Extended Master Secret: Z
AcAceLibraryStatus()Query whether library is in the soft error stateSuccessf ul Invocatio n (Pass)API call paramete rsInvocation Success or Invocation FailureNoneCO
AcKeyedDigest()Message authenticatio nSuccessf ul Invocatio n (Pass)API call paramete rsInvocation Success or Invocation FailureMessage Digest Message Authenticati onCO - HMAC Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E
AcDigestSize()Message authenticatio n digest sizeSuccessf ul Invocatio n (Pass)API call paramete rsInvocation Success or Invocation FailureNoneCO
AcEncrypt()Encrypt plaintextSuccessf ul Invocatio n (Pass)API call paramete rsCiphertext, Invocation Success or Invocation FailureMessage Authenticati on Symmetric CipherCO - AES Key : R,E - AES GCM Key: R,E - AES GCM IV: R,E

Z Z Z :Z R,E (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 24
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access - AES CCM Key: R,E - AES-XTS Testing Revision 2.0 Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E
AcEncryptBlockSize()Return size of ciphertextSuccessf ul Invocatio n (Pass)API call paramete rsInvocation Success or Invocation FailureNoneCO
AcSetOperationParameter ()Sets/Configur es non- security relevant operational parametersSuccessf ul Invocatio n (Pass)API call paramete rsInvocation Success or Invocation FailureNoneCO
AcGetVendorImplementati on()Returns the Module’s Algorithm capabilitiesSuccessf ul Invocatio n (Pass)API call paramete rsInvocation Success or Invocation FailureNoneCO
AcAESFpeEncrypt( )Encrypt plaintextSuccessf ul Invocatio n (Pass)API call paramete rsCiphertext, Invocation Success or Invocation FailureSymmetric CipherCO - AES Key : R,E
AsGetCryptoDataPtr()Get Data PointerSuccessf ul Invocatio n (Pass)API call paramete rsData Pointer, Invocation Success or Invocation FailureNoneCO
AcGetAceError()Get Error MessageSuccessf ul Invocatio n (Pass)API call paramete rsError Message, Invocation Success or Invocation FailureNoneCO
AcGatherSystemNoise()Gather Entropy InputSuccessf ul Invocatio n (Pass)API call paramete rsEntropy Input, Invocation Success or Invocation FailureNoneCO - DRBG Entropy: G,W,E - DRBG ‘V’ Value : G,W,E - DRBG ‘C’ Value: G,W,E

R,E G,W,E G,W,E (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 25
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access
AcGetPersonalizationData ()Get DRBG Personalizati on DataSuccessf ul Invocatio n (Pass)API call paramete rsPersonalizati on Data, Invocation Success or Invocation FailureNoneCO - DRBG Personalizati on String: R - DRBG Seed: G,W,E
AcEncryptClone()Duplicate an Encrypt OperationSuccessf ul Invocatio n (Pass)API call paramete rsEncrypt Operation, Invocation Success or Invocation FailureNoneCO
4.4 Non-Approved Services
4.5 External Software/Firmware Loaded

The module does not support the external loading of software or firmware.

5 Software/Firmware Security
5.1 Integrity Techniques

The module, which is made up of a single component, is provided in the form of binary executable code (Acelib.so for Linux and AceDll.dll for Windows). A software integrity test is performed on the runtime image of the module. The HMAC-SHA2-256 (Cert. #A3332) implemented in the module is used as an approved algorithm for the integrity test. If the test fails, the module enters an error state where no cryptographic services are provided, and data output is prohibited. (the module is not operational)

5.2 Initiate on Demand

The software integrity test is performed as part of the Pre-Operational self-tests. It is automatically executed at power-on. It can also be invoked by powering-off and reloading the module, or using the AcRunSelfTest() service.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module operates in a modifiable operational environment as described by the FIPS 140-3 definition. The operating systems on which the module was tested run user processes in logically separate process spaces. When (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 26
Storage Area NameDescriptionPersistence Type
RAMRandom Access MemoryDynamic
NameFromFormat TypeDistribution TypeEntry TypeSFI or Algorithm
InputCalling ProcessCall stack (API) input parametersPlaintextManualElectronic
OutputCall stack (API) output parametersCalling ProcessPlaintextManualElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Unload ModuleUnload module from memorySSPs no longer present in memory after unloadOperator unloads module
API CallAPI zeroize instructionSSPs no longer present in memory after API callAcDeInit() AcReleaseHandle()
Remove PowerPower removed from host GPCSSPs no longer present in memory after GPC power lossOperator powers off GPC

the module is present in memory, the operating system protects the module’s memory space from unauthorized access. The module functions entirely within the process space of the calling application.

7 Physical Security

The physical security requirements of FIPS 140-3 do not apply to software modules.

8 Non-Invasive Security

The module does not implement non-invasive attack mitigations.

9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 25: Storage Areas The module does not persistently store SSPs.

9.2 SSP Input-Output Methods

Table 26: SSP Input-Output Methods Note: To prevent the inadvertent output of sensitive information, two independent internal actions shall be required in order to output any plaintext CSP.

9.3 SSP Zeroization Methods

Table 27: SSP Zeroization Methods SSPs are implicitly zeroized when unloading the module or removing power, and explicitly zeroized when using AcDeInit() and AcReleaseHandle() where SSPs are overwritten with zeros. (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 27
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES KeyAES-ECB, AES-CBC, AES-CFB1, AES-CFB8, AES-CFB128, AES-CTR, AES-OFB, AES-FF1128, 192, 256 bits - 128, 192, 256 bitsSymmetric - CSPGenerate Symmetric KeysSymmetric Cipher
AES GCM KeyAES-GCM128, 192, 256 bits - 128, 192, 256 bitsSymmetric - CSPGenerate Symmetric KeysSymmetric Cipher
AES GCM IVAES-GCM96 bits - 96 bitsInitialization Vector - CSPDRBGSymmetric Cipher
AES CCM KeyAES-CCM128, 192, 256 bits - 128, 192, 256 bitsSymmetric - CSPGenerate Symmetric KeysSymmetric Cipher
AES-XTS Testing Revision 2.0 KeyAES-XTS Testing Revision 2.0128, 256 bits - 128, 256 bitsSymmetric - CSPGenerate Symmetric KeysSymmetric Cipher
AES CMAC KeyAES-CMAC128, 192, 256 bits - 128, 192, 256 bitsMessage Authentication - CSPGenerate Symmetric KeysMessage Authentication
AES GMAC KeyAES-GMAC128, 192, 256 bits - 128, 192, 256 bitsMessage Authentication - CSPGenerate Symmetric KeysMessage Authentication
HMAC KeyHMAC-SHA-1, HMAC-SHA2- 224, HMAC- SHA2-256, HMAC-SHA2- 384, HMAC- SHA2-512, HMAC-SHA3- 224, HMAC- SHA3-256, HMAC-SHA3- 384, HMAC- SHA3-512160, 224, 256, 384, 512 bits - 160, 224, 256, 384, 512 bitsMessage Authentication - CSPMessage AuthenticationMessage Authentication
Key Encryption Key (KEK)AES-KW, AES-KWP128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key Wrapping (KTS) - CSPGenerate Symmetric KeysKey Wrapping
PBKDF2 DPKPBKDF112 bits - 112 bitsData Protection Key - CSPDerive Key (PBKDF)Derive Key (PBKDF)
9.4 SSPs

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 28
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
PBKDF2 PasswordPBKDF PasswordGreater than or equal to 80 bits of data - Greater than or equal to 80 bits of dataPassword - CSPDerive Key (PBKDF)
RSA Private KeyRSA (186-4)2048, 3072, 4096 bits - 112, 128, 150 bitsAsymmetric Private Key - CSPGenerate Asymmetric KeysGenerate Digital Signature
ECDSA Private KeyECDSA (186- 4)P-224, P- 256, P- 384, P- 521 - 112, 128, 192, 256 bitsAsymmetric Private Key - CSPGenerate Asymmetric KeysGenerate Digital Signature
ECDH Private ComponentsKAS-ECC- SSC (NIST SP 800- 56Ar3)P-224, P- 256, P- 384, P- 521 - 112, 128, 192, 256 bitsAsymmetric Private Key - CSPGenerate Asymmetric KeysShared Secret Computation (KAS-ECC- SSC)
TLS RSA Premaster SecretUsed to derive the master secret384 bits - 384 bitsPremaster Secret - CSPDerive Key (TLS 1.2)
TLS Master SecretUsed to generate the session keys384 bits - 384 bitsMaster Secret - CSPDerive Key (TLS 1.2) Derive Key (TLS 1.3)Derive Key (TLS 1.2) Derive Key (TLS 1.3)
TLS Session KeyUsed for data encryption128 or 256 bits - 128 or 256 bitsSession Key - CSPDerive Key (TLS 1.2) Derive Key (TLS 1.3)Derive Key (TLS 1.2) Derive Key (TLS 1.3)
TLS Integrity KeyUsed for data integrity and authenticity160 bits - 160 bitsIntegrity Key - CSPDerive Key (TLS 1.2) Derive Key (TLS 1.3)Derive Key (TLS 1.2) Derive Key (TLS 1.3)
DRBG EntropyNIST SP 800- 90A DRBG Entropy Input256 bits - 256 bitsEntropy Input - CSPDRBG
DRBG SeedNIST SP 800- 90A DRBG Seed440-888 bits - 440- 888 bitsSeed - CSPDRBG

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 29
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
DRBG ‘C’ ValueNIST SP 800- 90A DRBG ‘C’ Value (IG D.L)440-888 bits - 440- 888 bitsInternal State Value - CSPDRBGDRBG
DRBG ‘V’ ValueNIST SP 800- 90A DRBG ‘V’ Value (IG D.L)440-888 bits - 440- 888 bitsInternal State Value - CSPDRBGDRBG
RSA Public KeyRSA Public Key2048, 3072, 4096 bits - 112, 128, 150 bitsAsymmetric Public Key - PSPGenerate Asymmetric KeysVerify Digital Signature
ECDSA Public KeyECDSA Public KeyP-224, P- 256, P- 384, P- 521 - 112, 128, 192, 256 bitsAsymmetric Public Key - PSPGenerate Asymmetric KeysVerify Digital Signature
ECDH Public ComponentsECDH Public ComponentsP-224, P- 256, P- 384, P- 521 - 112, 128, 192, 256 bitsKey Agreement Components - PSPGenerate Asymmetric KeysShared Secret Computation (KAS-ECC- SSC)
TLS Extended Master SecretBinds the master secret to a log of the full handshake384-bits - 384-bitsExtended Master Secret - CSPDerive Key (TLS 1.2)Derive Key (TLS 1.2)
DH Private ComponentsPrivate components for KAS-FFC- SSCMODP 2048, MODP 3072 - 112 bits, 128 bitsAsymmetric Private Key - CSPGenerate Asymmetric KeysShared Secret Computation (KAS-FFC- SSC)
DH Public ComponentsPublic components for KAS-FFC- SSCMODP 2048, MODP 3072 - 112 bits, 128 bitsAsymmetric Public Key - PSPGenerate Asymmetric KeysShared Secret Computation (KAS-FFC- SSC)
DRBG Personalization StringOptional input to the DRBG instantiate function128 to 256 bits - 128 to 256 bitsPersonalization String - NeitherDRBG
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES KeyInputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call

Table 28: SSP Table 1 (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 30
NameInput - OutputStorageStorage DurationZeroization Remove PowerRelated SSPs
AES GCM KeyInputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerAES GCM IV:Used With
AES GCM IVOutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerAES GCM Key:Used With
AES CCM KeyInputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
AES-XTS Testing Revision 2.0 KeyInputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
AES CMAC KeyInputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
AES GMAC KeyInputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
HMAC KeyInputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
Key Encryption Key (KEK)Input OutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
PBKDF2 DPKOutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerPBKDF2 Password:Derived From
PBKDF2 PasswordInputRAM:PlaintextIn volatile memory until zeroizedUnload Module Remove PowerPBKDF2 DPK:Used With

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 31
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
RSA Private KeyInput OutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerRSA Public Key:Paired With
ECDSA Private KeyInput OutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerECDSA Public Key:Paired With
ECDH Private ComponentsInput OutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerECDH Public Components:Paired With
TLS RSA Premaster SecretRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
TLS Master SecretRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerTLS RSA Premaster Secret:Derived From
TLS Session KeyRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerTLS Master Secret:Derived From
TLS Integrity KeyRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerTLS Master Secret:Derived From
DRBG EntropyInputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerDRBG Seed:Used With
DRBG SeedRAM:PlaintextIn volatile memory until zeroizedUnload Module Remove PowerDRBG Entropy:Derived From
DRBG ‘C’ ValueRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerDRBG Seed:Derived From

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 32
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
DRBG ‘V’ ValueRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerDRBG Seed:Derived From
RSA Public KeyInput OutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerRSA Private Key:Paired With
ECDSA Public KeyInput OutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerECDSA Private Key:Paired With
ECDH Public ComponentsInput OutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerECDH Private Components:Paired With
TLS Extended Master SecretRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove PowerTLS RSA Premaster Secret:Derived From
DH Private ComponentsInput OutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
DH Public ComponentsInput OutputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
DRBG Personalization StringInputRAM:PlaintextIn volatile memory until zeroizedUnload Module API Call Remove Power
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-256 (A3332)HMAC-SHA2- 256Software Integrity TestSW/FW IntegrityPassKeyed hash performed on Acelib.so or AceDll.dll
10 Self-Tests
10.1 Pre-Operational Self-Tests

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 33
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES-CBC (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On
AES-CCM (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES-CCM (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On
AES-CFB1 (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES-CFB1 (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On
AES- CFB128 (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES- CFB128 (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On
AES-CFB8 (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES-CFB8 (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On
AES-CMAC (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES-CMAC (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On
AES-CTR (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES-CTR (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On
AES-ECB (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES-ECB (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On
AES-FF1 (A3332)128 bit KeyKATCASTPassEncryptPower-On
AES-GCM (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES-GCM (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On
AES-OFB (A3332)128, 192, 256 bit KeyKATCASTPassEncryptPower-On
AES-OFB (A3332)128, 192, 256 bit KeyKATCASTPassDecryptPower-On

Table 30: Pre-Operational Self-Tests The module performs the pre-operational software integrity test automatically upon every instantiation. (A CAST for HMAC-SHA2-256 executes prior to the software integrity test.)

10.2 Conditional Self-Tests

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 34
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-XTS Testing Revision 2.0 (A3332)128, 256 bit KeyKATCASTPassEncryptPower-On
AES-XTS Testing Revision 2.0 (A3332)128, 256 bit KeyKATCASTPassDecryptPower-On
ECDSA SigGen (FIPS186-4) (A3332)P-384 CurveKATCASTPassSignPower-On
ECDSA SigVer (FIPS186-4) (A3332)P-384 CurveKATCASTPassVerifyPower-On
Hash DRBG (A3332)SHA2-256, SHA2-512 (NIST SP 800- 90A, Section 11.3 Health Tests)KATCASTPassHash_DRBG1. Power On 2. Instantiate: Any time that a new DRBG instance is created 3. Generate: When new random data is generated 4. Reseed: When the reseed counter has reached its pre- determined maximum value and the DRBG needs to be reseeded
HMAC- SHA-1 (A3332)160 bit HashKATCASTPassKeyed HashPower-On
HMAC- SHA2-224 (A3332)224 bit HashKATCASTPassKeyed HashPower-On
HMAC- SHA2-256 (A3332)256 bit HashKATCASTPassKeyed HashPower-On
HMAC- SHA2-384 (A3332)384 bit HashKATCASTPassKeyed HashPower-On
HMAC- SHA2-512 (A3332)512 bit HashKATCASTPassKeyed HashPower-On
HMAC- SHA3-224 (A3332)224 bit HashKATCASTPassKeyed HashPower-On
HMAC- SHA3-256 (A3332)256 bit HashKATCASTPassKeyed HashPower-On
HMAC- SHA3-384 (A3332)384 bit HashKATCASTPassKeyed HashPower-On

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 35
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA3-512 (A3332)512 bit HashKATCASTPassKeyed HashPower-On
KAS-ECC- SSC Sp800- 56Ar3 (A3332)P-384 CurveKATCASTPassPrimitive "Z"Power-On
KAS-FFC- SSC Sp800- 56Ar3 (A3332)MODP-2048, MODP-3072KATCASTPassPrimitive "Z"Power-On
KDA HKDF Sp800- 56Cr1 (A3332)SHA2-256KATCASTPassHashPower-On
KDF SSH (A3332)AES-128, AES-192, AES-256, SHA2-256KATCASTPassHashPower-On
PBKDF (A3332)160 bit Keyed HashKATCASTPassKeyed HashPower-On
RSA SigGen (FIPS186-4) (A3332)2048 bit KeyKATCASTPassSignPower-On
RSA SigVer (FIPS186-4) (A3332)2048 bit KeyKATCASTPassVerifyPower-On
SHA-1 (A3332)160 bit HashKATCASTPassHashPower-On
SHA2-224 (A3332)224 bit HashKATCASTPassHashPower-On
SHA2-256 (A3332)256 bit HashKATCASTPassHashPower-On
SHA2-384 (A3332)384 bit HashKATCASTPassHashPower-On
SHA2-512 (A3332)512 bit HashKATCASTPassHashPower-On
SHA3-224 (A3332)224 bit HashKATCASTPassHashPower-On
SHA3-256 (A3332)256 bit HashKATCASTPassHashPower-On
SHA3-384 (A3332)384 bit HashKATCASTPassHashPower-On
SHA3-512 (A3332)512 bit HashKATCASTPassHashPower-On
TLS v1.2 KDF RFC7627 (A3332)SHA2-256KATCASTPassHashPower-On

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 36
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
TLS v1.3 KDF (A3332)SHA2-256KATCASTPassHashPower-On
AES-XTS Testing Revision 2.0 (A3332)128, 256 bit keyKey_1 ≠ Key_2 (IG C.I)CASTPassCheckConditional upon first use of AES-XTS
KAS-ECC- SSC Sp800- 56Ar3 (A3332)P-224, P-256, P-384, P-521Public Key Assurance TestCASTPassCheckConditional upon ECDSA KeyPair Generation
ECDSA KeyGen (FIPS186-4) (A3332)P-384Pairwise Consistency TestPCTPassSign & VerifyConditional upon ECDSA KeyPair Generation
RSA KeyGen (FIPS186-4) (A3332)2048 bit keyPairwise Consistency TestPCTPassSign & VerifyConditional upon RSA KeyPair Generation
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A3332)Software Integrity TestSW/FW IntegrityOn DemandReload Module or AcRunSelfTest()
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CBC (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CCM (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CCM (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CFB1 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()

Table 31: Conditional Self-Tests Conditional CASTs are performed automatically upon every instantiation. The pairwise consistency tests are performed on the condition that an asymmetric keypair is requested, and the AES-XTS key validation test is performed prior to using the keys, per IG C.I. The DRBG health tests required by NIST SP 800-90A, Section 11.3 (instantiate, generate, reseed) execute upon instantiation of the module and also upon the following conditions:

  1. Instantiate: Any time that a new DRBG instance is created.
  2. Generate: When new random data is generated.
  3. Reseed: When the reseed counter has reached its pre-determined maximum value and the DRBG needs to be reseeded.
10.3 Periodic Self-Test Information

Table 32: Pre-Operational Periodic Information (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 37
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CFB1 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CFB128 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CFB128 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CFB8 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CFB8 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CMAC (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CMAC (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CTR (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-CTR (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-ECB (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-ECB (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-FF1 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-GCM (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-GCM (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-OFB (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-OFB (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-XTS Testing Revision 2.0 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
AES-XTS Testing Revision 2.0 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
ECDSA SigGen (FIPS186-4) (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
ECDSA SigVer (FIPS186-4) (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
Hash DRBG (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
HMAC-SHA-1 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
HMAC-SHA2-224 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
HMAC-SHA2-256 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 38
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-384 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
HMAC-SHA2-512 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
HMAC-SHA3-224 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
HMAC-SHA3-256 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
HMAC-SHA3-384 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
HMAC-SHA3-512 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
KAS-ECC-SSC Sp800-56Ar3 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
KAS-FFC-SSC Sp800-56Ar3 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
KDA HKDF Sp800- 56Cr1 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
KDF SSH (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
PBKDF (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
RSA SigGen (FIPS186-4) (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
RSA SigVer (FIPS186-4) (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
SHA-1 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
SHA2-224 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
SHA2-256 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
SHA2-384 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
SHA2-512 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
SHA3-224 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
SHA3-256 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
SHA3-384 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
SHA3-512 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
TLS v1.2 KDF RFC7627 (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()
TLS v1.3 KDF (A3332)KATCASTOn DemandReload Module or AcRunSelfTest()

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 39
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-XTS Testing Revision 2.0 (A3332)Key_1 ≠ Key_2 (IG C.I)CASTN/AN/A
KAS-ECC-SSC Sp800-56Ar3 (A3332)Public Key Assurance TestCASTN/AN/A
ECDSA KeyGen (FIPS186-4) (A3332)Pairwise Consistency TestPCTN/AN/A
RSA KeyGen (FIPS186-4) (A3332)Pairwise Consistency TestPCTN/AN/A
NameDescriptionConditionsRecovery MethodIndicator
Hard Error StateNon-recoverable error stateResult of pre-operational self-test failure Result of CAST failureReload module / Reinstall moduleFail
Soft Error StateRecoverable error stateResult of RSA pairwise consistency test failure Result of ECDSA pairwise consistency test failure Result of Key_1 ≠ Key_2 for AES- XTSAutomaticFail

Table 33: Conditional Periodic Information The pre-operational software integrity test and all conditional CASTs can be executed on-demand by calling the AcRunSelfTest() service.

10.4 Error States

Table 34: Error States The module implements two error states. A hard error state, whereby recovery may be attempted by restarting or reinstalling the module, and a software error state whereby conditional self-test failures such as the pairwise tests and the AES-XTS key validation test may be recovered. Self-tests in the module return an indication of whether the invocation passed or failed. If any self-test fails, the module’s data output interfaces will be inhibited, and only control input and status output commands will be allowed to execute. To correct an on-demand or conditional self-test error, the module must be restarted by calling the AllegroTaskInit() service after the module has been de-initialized. To correct a preoperational self-test error, the module must be reloaded into memory by terminating and restarting the host application. If the pre-operational self-test fails after restarting the host application, it will be necessary to re-install the module.

10.5 Operator Initiation of Self-Tests

The pre-operational software integrity test and all conditional CASTs can be executed by the operator using the API call AcRunSelfTest().

11 Life-Cycle Assurance

(Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).

Page 40
11.1 Installation, Initialization, and Startup Procedures

When built and executed, the module automatically operates in the approved mode. (Additional guidance is provided in Section 11.2.)

11.2 Administrator Guidance

Initial setup for the module consists of:

  1. Installing the host operating system: Linux 5.15 (Mint 21) or Windows 11 Pro.
  2. Creating a new user account on the Operating System (and providing that user account with a password). The host operating system will provide the operational environment required for the module to meet FIPS 140-3, Level 1 security specifications. The Crypto Officer will create a new admin account per the guidelines of the OS user manual. (The Crypto Officer shall refer to all administrative and guidance documents in order to create a new user account on the Operating System.) The Crypto Officer is in charge of the secure management and handling of the module. The Allegro Cryptographic Engine is shipped on a DVD and delivered via FedEx. A tracking number is provided to the Crypto Officer in order to track the progress of the shipment and ensure secure delivery of the module. The Crypto Officer shall sign for the DVD upon arrival and shall maintain control of the DVD throughout its lifetime. Following the secure delivery of the module, the Crypto Officer shall first follow the steps outlined above. After the operational environment has been prepared, the module can be built in any configuration specified in Table

2 of this security policy, by consulting the build instructions provided in Chapter 5 of the ACE™ Allegro

Cryptography Engine Programming Reference, Version 6.50, included on the DVD. During normal operation, the operator may check the status of the module by attempting to run a service. If the service executes and does not return an error, the module is operating in the approved mode.

11.3 Non-Administrator Guidance

The module supports the role of Crypto Officer only, which is an administrative role.

11.4 End of Life

The module may be sanitized by uninstalling the binary and power-cycling the host GPC.

11.5 Additional Information

The operator shall adhere to the guidelines of this Security Policy. Operators in the Crypto Officer role are able to use the approved services listed in this security policy. The operator is responsible for monitoring the module for any irregular activity.

12 Mitigation of Other Attacks

The module does not attempt to mitigate specific attacks. (Allegro Software Development Corporation. © 2024) Version 1.0 Public Material – May be reproduced only in its original entirety (without revision).