All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Apple corecrypto Module v12 [Intel, User, Software]

Certificate#4951StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorApple, Inc.
Medium review priority  ·  no TCB surface named  ·  last validated 18 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date1/26/2027
CaveatInterim validation. When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorApple, Inc.

Approved Algorithms (152)

AlgorithmACVP Cert
AES-CBCA2812
AES-CBCA2813
AES-CBCA2814
AES-CBCA2815
AES-CBCA2819
AES-CBCA2820
AES-CCMA2814
AES-CCMA2815
AES-CCMA2820
AES-CCMA2821
AES-CCMA2822
AES-CFB128A2814
AES-CFB128A2815
AES-CFB128A2820
AES-CFB8A2814
AES-CFB8A2815
AES-CFB8A2820
AES-CMACA2820
AES-CTRA2814
AES-CTRA2815
AES-CTRA2820
AES-CTRA2821
AES-CTRA2822
AES-ECBA2812
AES-ECBA2813
AES-ECBA2814
AES-ECBA2815
AES-ECBA2820
AES-ECBA2821
AES-ECBA2822
AES-GCMA2814
AES-GCMA2815
AES-GCMA2820
AES-GCMA2821
AES-GCMA2822
AES-KWA2814
AES-KWA2815
AES-KWA2820
AES-OFBA2814
AES-OFBA2815
AES-OFBA2820
AES-XTS Testing Revision 2.0A2812
AES-XTS Testing Revision 2.0A2813
AES-XTS Testing Revision 2.0A2814
AES-XTS Testing Revision 2.0A2815
AES-XTS Testing Revision 2.0A2820
Counter DRBGA2814
Counter DRBGA2815
Counter DRBGA2820
Counter DRBGA2821
Counter DRBGA2822
ECDSA KeyGen (FIPS186-4)A2816
ECDSA KeyGen (FIPS186-4)A2817
ECDSA KeyGen (FIPS186-4)A2818
ECDSA KeyGen (FIPS186-4)A2820
ECDSA KeyVer (FIPS186-4)A2816
ECDSA KeyVer (FIPS186-4)A2817
ECDSA KeyVer (FIPS186-4)A2818
ECDSA KeyVer (FIPS186-4)A2820
ECDSA SigGen (FIPS186-4)A2816
ECDSA SigGen (FIPS186-4)A2817
ECDSA SigGen (FIPS186-4)A2818
ECDSA SigGen (FIPS186-4)A2820
ECDSA SigVer (FIPS186-4)A2816
ECDSA SigVer (FIPS186-4)A2817
ECDSA SigVer (FIPS186-4)A2818
ECDSA SigVer (FIPS186-4)A2820
HMAC DRBGA2816
HMAC DRBGA2817
HMAC DRBGA2818
HMAC DRBGA2820
HMAC-SHA-1A2816
HMAC-SHA-1A2817
HMAC-SHA-1A2818
HMAC-SHA-1A2820
HMAC-SHA-1A2823
HMAC-SHA2-224A2816
HMAC-SHA2-224A2817
HMAC-SHA2-224A2818
HMAC-SHA2-224A2820
HMAC-SHA2-224A2823
HMAC-SHA2-256A2816
HMAC-SHA2-256A2817
HMAC-SHA2-256A2818
HMAC-SHA2-256A2820
HMAC-SHA2-256A2823
HMAC-SHA2-384A2816
HMAC-SHA2-384A2817
HMAC-SHA2-384A2818
HMAC-SHA2-384A2820
HMAC-SHA2-384A2823
HMAC-SHA2-512A2816
HMAC-SHA2-512A2817
HMAC-SHA2-512A2818
HMAC-SHA2-512A2820
HMAC-SHA2-512A2823
HMAC-SHA2-512/256A2816
HMAC-SHA2-512/256A2817
HMAC-SHA2-512/256A2818
HMAC-SHA2-512/256A2820
KAS-ECC-SSC Sp800-56Ar3A2820
KAS-FFC-SSC Sp800-56Ar3A2820
KDF SP800-108A2816
KDF SP800-108A2817
KDF SP800-108A2818
KDF SP800-108A2820
PBKDFA2816
PBKDFA2817
PBKDFA2818
PBKDFA2820
RSA KeyGen (FIPS186-4)A2816
RSA KeyGen (FIPS186-4)A2817
RSA KeyGen (FIPS186-4)A2818
RSA KeyGen (FIPS186-4)A2820
RSA SigGen (FIPS186-4)A2816
RSA SigGen (FIPS186-4)A2817
RSA SigGen (FIPS186-4)A2818
RSA SigGen (FIPS186-4)A2820
RSA SigVer (FIPS186-4)A2816
RSA SigVer (FIPS186-4)A2817
RSA SigVer (FIPS186-4)A2818
RSA SigVer (FIPS186-4)A2820
Safe Primes Key GenerationA2820
SHA-1A2816
SHA-1A2817
SHA-1A2818
SHA-1A2820
SHA-1A2823
SHA2-224A2816
SHA2-224A2817
SHA2-224A2818
SHA2-224A2820
SHA2-224A2823
SHA2-256A2816
SHA2-256A2817
SHA2-256A2818
SHA2-256A2820
SHA2-256A2823
SHA2-384A2816
SHA2-384A2817
SHA2-384A2818
SHA2-384A2820
SHA2-384A2823
SHA2-512A2816
SHA2-512A2817
SHA2-512A2818
SHA2-512A2820
SHA2-512A2823
SHA2-512/256A2816
SHA2-512/256A2817
SHA2-512/256A2818
SHA2-512/256A2820

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Apple corecrypto Module v12 [Intel, User, Software]
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status output<br/>Self-test<br/>Show Status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IPSEC<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C3,C5,C6 clue;
  class I3,I5,I6 infer;
  class R3,R5,R6 risk;
  class E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Apple corecrypto Module v12 [Intel, User, Software]
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status output<br/>Self-test<br/>Show Status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IPSEC<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Apple Inc. Apple corecrypto Module v12 [Intel, User, Software] Document version: 1.0 January 15, 2025 Prepared by: www.acumensecurity.net This document may be reproduced and distributed only in its original entirely without revision

Page 2
Table of Contents
#SectionPage
Page 3

1. General Trademarks Apple’s trademarks applicable to this document are listed in https://www.apple.com/legal/intellectualproperty/trademark/appletmlist.html. Other company, product, and service names may be trademarks or service marks of others. This document is the non-proprietary FIPS 140-3 Security Policy for the Apple, Inc. corecrypto Module v12 [Intel, User, Software] cryptographic module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an Overall Security Level 1 module. This document provides all tables and diagrams (when applicable) required by NIST SP 800-140B. The column names of the tables follow the template tables provided in NIST SP 800-140B. Table 1 describes the individual security areas of FIPS 140-3, as well as the Security Levels of those individual areas. This document may be reproduced and distributed only in its original entirely without revision

Page 4
ISO/IEC 24759
Security
Section 6.FIPS 140-3 Section Title
[Number Below]Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical SecurityNot Applicable
8Non-invasive SecurityNot Applicable
9Sensitive Security Parameter Management1
10Self-tests1
11Life-cycle Assurance1
12Mitigation of Other AttacksNot Applicable

9 1

Table 1 – Security Levels The module claims an overall Security Level 1. This document may be reproduced and distributed only in its original entirely without revision

Page 5
#Operating SystemHardware PlatformProcessorPAA/Acceleration
1macOS Monterey 12MacBook AirIntel i5 (Amber Lake)AES-NI
2macOS Monterey 12MacBook AirIntel i5 (Amber Lake)N/A
3macOS Monterey 12iMacIntel i5 (Comet Lake)AES-NI
4macOS Monterey 12iMacIntel i5 (Comet Lake)N/A
5macOS Monterey 12MacBook AirIntel i7 (Ice Lake)AES-NI
6macOS Monterey 12MacBook AirIntel i7 (Ice Lake)N/A
7macOS Monterey 12MacBook ProIntel i7 (Coffee Lake)AES-NI
8macOS Monterey 12MacBook ProIntel i7 (Coffee Lake)N/A
9macOS Monterey 12iMacIntel i7 (Comet Lake)AES-NI
10macOS Monterey 12iMacIntel i7 (Comet Lake)N/A
11macOS Monterey 12MacBook ProIntel i9 (Coffee Lake)AES-NI
12macOS Monterey 12MacBook ProIntel i9 (Coffee Lake)N/A
13macOS Monterey 12iMac ProXeon W Sky LakeAES-NI
14macOS Monterey 12iMac ProXeon W Sky LakeN/A
15macOS Monterey 12Mac ProXeon W Cascade LakeAES-NI
16macOS Monterey 12Mac ProXeon W Cascade LakeN/A
  1. Cryptographic Module Specification The Apple corecrypto Module v12 [Intel, User, Software] cryptographic module (hereafter referred to as “the module”) is a software module running on a multi-chip standalone general-purpose computing platform. The version of module is 12, written as v12. The module provides implementations of low-level cryptographic primitives to the Host OS’s (macOS Monterey
  2. Security Framework and Common Crypto. The module has been tested by Acumen Security, LLC. CST lab on the following platforms with and without AES-NI: Table 2 – Tested Operational Environments This document may be reproduced and distributed only in its original entirely without revision
Page 6
#Operating SystemHardware Platform
1macOS Monterey 12MacBook Proi5 (Ice Lake)2020
2macOS Monterey 12MacBook Proi5 (Coffee Lake)2020, 2019, 2018
3macOS Monterey 12MacBook Proi7 (Amber Lake)2019, 2018
4macOS Monterey 12MacBook Proi7 (Coffee Lake)2020, 2019, 2018
5macOS Monterey 12MacBook Proi7 (Ice Lake)2020
6macOS Monterey 12MacBook Proi9 (Coffee Lake)2019, 2018
7macOS Monterey 12MacBook Airi5 (Ice Lake)2020
8macOS Monterey 12MacBook Airi7 (Ice Lake)2020
9macOS Monterey 12MacBook Airi5 (Amber Lake)2019, 2018
10macOS Monterey 12MacBook Airi7 (Amber Lake)2018
11macOS Monterey 12Mac minii5 (Coffee Lake)2018
12macOS Monterey 12Mac minii7 (Coffee Lake)2018
13macOS Monterey 12iMaci5 (Comet Lake)2020
14macOS Monterey 12iMaci7 (Comet Lake)2020
15macOS Monterey 12iMaci9 (Comet Lake)2020
16macOS Monterey 12iMaci5 (Coffee Lake)2019
17macOS Monterey 12iMaci7 (Coffee Lake)2019
18macOS Monterey 12iMaci9 (Coffee Lake)2019

In addition to the platforms listed in Table 2, Apple Inc. has also tested the module on the following platforms and claims vendor affirmation on them (the processor and year per platform have also been specified): Table 3 – Vendor Affirmed Operational Environments The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation This document may be reproduced and distributed only in its original entirely without revision

Page 7

certificate. The physical perimeter of the module which is also the Tested Operational Environment’s Physical Perimeter (TOEPP), is the physical perimeter of the macOS device that contains the module. Consequently, the embodiment of the module is a multi-chip standalone cryptographic module. (Figure 1) below depicts the following information:

Page 8
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
#A2821 (vng_asm) #A2820 (c_ltc) #A2815 (c_asm) #A2814 (c- aesni) #A2822 (vng_aesni)CTR_DRBG [SP800-90Ar1]AES-128, AES-256 Derivation Function Enabled128, 256 bitsRandom Number Generation
#A2820 (c_ltc) #A2817 (c_avx2) #A2816 (c_avx) #A2818 (c_ssse3)HMAC_DRBG [SP800-90Ar1]SHA-1, SHA-224, SHA-256, SHA-384, SHA-512112 bits or greaterRandom Number Generation
#A2820 (c_ltc) #A2817 (c_avx2) #A2816 (c_avx) #A2818 (c_ssse3)RSA [FIPS 186-4]Key GenerationDigital Signature and Asymmetric Key Generation
Key Generation2048, 3072,
(ANSI X9.31),4096
SignatureSignature
GenerationGeneration Modulus:
(PKCS#1 v1.5) and2048 (SHA-1
(PKCS PSS)(legacy), SHA2-
Signature224, SHA2-256,
VerificationSHA2-284,

is in the Approved mode of operation when the module utilizes the services that use the security functions listed in the table below. The module supports an Approved mode and a non-Approved mode of operation. The module does not support a degraded operation. The Approved mode of operation is configured in the system by default and can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table 10 - NonApproved Services. If the device starts up successfully, then the module has passed all self-tests and is operating in the Approved mode. This document may be reproduced and distributed only in its original entirely without revision

Page 9
CAVP CertAlgorithm and StandardMode/Method (PKCS#1 v1.5) and (PKCS PSS)Description / Key Size(s) / Key Strength(s) SHA2-512), 3072 (SHA-1 (legacy), SHA2- 224, SHA2-256, SHA2-284, SHA2-512), 4096 (SHA-1 (legacy), SHA2- 224, SHA2-256, SHA2-284, SHA2-512) Signature Verification Modulus: 1024 (SHA-1 (legacy), SHA2-224, SHA2-256, SHA2-284), 2048 (SHA-1 (legacy), SHA2- 224, SHA2-256, SHA2-284, SHA2-512), 3072 (SHA-1 (legacy), SHA2- 224, SHA2-256, SHA2-284, SHA2-512), 4096 (SHA-1 (legacy), SHA2- 224, SHA2-256, SHA2-284, SHA2-512)Use / Function
#A2820ECDSA ANSI X9.62 [FIPS 186-4]Key Pair Generation (PKG) Public Key Validation (PKV) Signature Generation Signature VerificationKey PairDigital Signature and Asymmetric Key Generation
(c_ltc)Generation
#A2817(PKG):
(c_avx2)P-224, P-256, P-
#A2816 (c_avx)384, P-521
#A2818Public Key
(c_ssse3)Validation (PKV):

This document may be reproduced and distributed only in its original entirely without revision

Page 10
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s) P-224, P-256, P- 384, P-521 Signature Generation: P-224, P-256, P- 384, P-521 SHA2-224, SHA2-256, SHA2-384, SHA2-512 Signature Verification: P-224, P-256, P- 384, P-521 SHA-1 (legacy), SHA2-224, SHA2-256, SHA2-384, SHA2-512Use / Function
#A2820 (c_ltc) #A2818 (c_ssse3) #A2823 (vng_Intel) #A2817 (c_avx2) #A2816 (c_avx)SHS [FIPS 180-4]SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/256 (except A2823)N/AMessage Digest
#A2820 (c_ltc)AES [FIPS 197] [SP 800-38 A] [SP 800-38 C] [SP 800-38 D] [SP 800-38 E] [SP 800-38 F]CBC, CCM, CFB128, CFB8, CMAC, CTR, ECB, GCM, KW, OFB, XTSKey Length: 128, 192, 256 CMAC :128 XTS (128 and 256-bits key size only)Symmetric Encryption and Decryption
#A2815 #A2814 (c_aesni)CBC, CCM, CFB128,Key Length:
CFB8, CTR, ECB,128, 192, 256
GCM, KW, OFB,XTS (128 and
XTS256-bits key size only)

This document may be reproduced and distributed only in its original entirely without revision

Page 11
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
#A2821 #A2822CCM, CTR, ECB, GCM
A2819 (c_glad)CBCKey Length: 128, 192, 256
#A2812 (asm_aesni) #A2813 (asm_x86)CBC, ECB, XTSKey Length: 128, 192, 256 XTS (128 and 256-bits key size only)
#A2823 (vng_Intel) #A2817 (c_avx2) #A2816 (c_avx) #A2820 (c_ltc) #A2818 (c_ssse3)HMAC [FIPS 198]SHA-1, SHA-224, SHA-256, SHA-384, SHA-512 SHA-512/256 (except A2823)112 bits or greaterKeyed Hash
#A2820 (c_Itc)KAS-FFC-SSC [SP800-56r3]Scheme: dhEphem: KAS Role: initiator, responderDomain Parameter Generation Methods: MODP-2048, MODP-4096, MODP-6144, MODP-8192Key Agreement Scheme – Shared Secret Computation
#A2820(c_Itc)KAS-ECC-SSC [SP800-56r3]Scheme: ephemeralUnified: KAS Role: initiator, responderDomain Parameter Generation Methods: P- 224, P-256, P- 384, P-Key Agreement Scheme – Shared Secret Computation

This document may be reproduced and distributed only in its original entirely without revision

Page 12
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
521
#A2820 (c_ltc ) #A2817 (c_avx2) A2816 (c_avx) #A2818 (c_ssse3)KBKDF [SP800-108]KDF Mode: Counter and Feedback MAC Mode: HMAC- SHA-1, HMAC-SHA2-224, HMAC-SHA2- 256, HMAC-SHA2- 384, HMAC-SHA2- 512 CMAC-AES128, CMAC-AES192, CMAC-AES256 (only #A2820)Supported Lengths: 8-4096 Increment 8 Fixed Data Order: Before Fixed Data Counter Length: 32Key Derivation
#A2820 (c_ltc ) #A2817 (c_avx2) #A2816 (c_avx) #A2818 (c_ssse3)PBKDF [SP800-132]HMAC with: SHA-1, SHA-224, SHA-256, SHA-384, SHA-512Password length: 8- 128 bytes Increment 1 Salt Length: 128-4096 Increment 8 Iteration Count: 10-1000 Increment 1Key Derivation
#A2820 (c_ltc )Key Generation forSafe Prime Groups: MODP- 2048, MODP-Key Generation
Safe Primes KeyDiffie-Hellman
generation(KAS-FFC-SSC)

) ) ) This document may be reproduced and distributed only in its original entirely without revision

Page 13
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
3072, MODP- 4096, MODP-6144, MODP- 8192
KAS-1 KAS-FFC-SSC Sp800- 56Ar3/A2820KASSP 800-56Arev3. KAS-FFC-SSC per IG D.F Scenario 2 path (1)2048, 4096, 6144, 8192-bit key providing 112, 152, 176, 200 bits of encryption strengthKey Agreement – Shared Secret Computation
KAS-2 KAS-ECC-SSC Sp800- 56Ar3/A2820KASSP 800-56Arev3. KAS-ECC-SSC per IG D.F Scenario 2 path (1)224 , 256, 384, 521-bit key providing 112, 128, 192, 256 bits of encryption strengthKey Agreement – Shared Secret Computation
KTS AES- KW/A2814 AES- KW/A2815 AES- KW/A2820KTSSP 800-38D and SP 800-38F; key wrapping per IG D.G128, 192, and 256- bit keys providing 128, 192, or 256 bits of encryption strengthKey Wrapping
Vendor AffirmedCryptographic Key Generation (CKG) [SP800-133r2]RSA Key Generation (ANSI X9.31), ECDSA Key Pair Generation (PKG), Sections 4, 5.1, 5.2, 6.2.2 and 6.2.3 per SP800-132r2RSA: Modulus: 2048, 3072, 4096 ECDSA: P-224, P-256, P- 384, P-521Key Generation

KAS-1

KAS-FFC-SSC

Sp800-

56Ar3/A2820

SP 800-56Arev3.

KAS-FFC-SSC per IG

D.F Scenario 2 path

KAS

KAS-2

KAS-ECC-SSC

Sp800-

56Ar3/A2820

SP 800-56Arev3.

KAS-ECC-SSC per IG

D.F Scenario 2 path

KAS

SP 800-38D and SP

800-38F; key

wrapping per IG D.G

KTS

(1) Table 4 – Approved Algorithms This module does not have non-Approved but Allowed Algorithms used in the Approved mode of operation. This document may be reproduced and distributed only in its original entirely without revision

Page 14
AlgorithmCaveatUse / Function
MD5no security claimedMessage Digest (used as part of the TLS key establishment scheme only), Digest Size: 128-bit
Algorithm/FunctionUse/Function
RSA Signature Generation / Signature Verification / Asymmetric Key GenerationANSI X9.31 Key Pair Generation Key Size < 2048 PKCS#1 v1.5 and PSS Signature Generation Key Size < 2048 PKCS#1 v1.5 and PSS Signature Verification Key Size< 1024
RSA Key WrappingOAEP, PKCS#1 v1.5 and -PSS schemes
Diffie-HellmanKey agreement scheme
EC Diffie-HellmanKey agreement scheme
Ed25519Key Agreement Sig(gen) Sig(ver)
ANSI X9.63 KDFHash based Key Derivation Function
RFC6637Key Derivation Function
HKDF [SP800-56Cr1]Key Derivation Function
DESEncryption / Decryption Key Size 56-bits
CASTEncryption / Decryption Key Sizes 40 to 128-bits in 8-bit increments
RC4Encryption / Decryption Key Sizes 8 to 4096-bits
RC2Encryption / Decryption Key Sizes 8 to 1024-bits
MD2Message Digest Digest size 128-bit
MD4Message Digest Digest size 128-bit
RIPEMDMessage Digest Digest size 160-bits
ECDSAPKG: Curve P-192 PKV: Curve P-192 Signature Generation: Curve P-192 Signature Verification: Curve P-192

The table below list non-Approved but Allowed security functions with no security claimed: Table 5 – Non-Approved Algorithms Not Allowed in the Approved Mode of Operation with No Security The table below lists Non-Approved security functions that are not Allowed in the Approved Mode of Operation: This document may be reproduced and distributed only in its original entirely without revision

Page 15
Key Pair Generation for compact point representation of points
Key Pair Generation for compact point representation of points
Integrated Encryption Scheme on elliptic curves (ECIES)Encryption / Decryption
BlowfishEncryption / Decryption
OMAC (One-Key CBC MAC)MAC generation
Triple-DES [SP 800-67]CBC, CTR, CFB64, ECB, CFB8, OFB

Table 6

Page 16
Logical interfaceData that passes over port/interface
Data input interfaceData inputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers
Data output interfaceData outputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers
Control input interfaceControl inputs which control the mode of the module are provided through dedicated parameters.
Status output interfaceStatus output is provided in return codes and through messages. Documentation for each API lists possible return codes. A complete list of all return codes returned by the C language APIs within the module is provided in the header files and the API documentation. Messages are also documented in the API documentation.

3. Cryptographic Module Interfaces As a software-only module, the module does not have physical ports. For the purpose of the FIPS 140-

3 validation, the physical ports are interpreted to be the physical ports of the hardware platform on

which it runs. The logical interfaces are the application program interface (API) through which applications request services and the Operating System calls that the module invokes. these interfaces are described in (Table 7): Table 7 – Ports and Interfaces The module is optimized for library use within the macOS User space and does not contain any terminating assertions or exceptions. It is implemented as a macOS dynamically loadable library. The dynamically loadable library is loaded into the macOS User and its cryptographic functions are made available to the macOS application. Any internal error detected by the module is reflected back to the caller with an appropriate return code. The calling macOS application must examine the return code and act accordingly. The module communicates any error status synchronously through the use of its documented return codes, thus indicating the module’s status. It is the responsibility of the caller to handle exceptional conditions in a FIPS 140-3 appropriate manner. Caller-induced or internal errors do not reveal any sensitive material to callers. Cryptographic bypass This document may be reproduced and distributed only in its original entirely without revision

Page 17

capability is not supported by the module. This document may be reproduced and distributed only in its original entirely without revision

Page 18
RoleServiceInputOutput
Crypto Officer (CO)AES Encryption / Decryption (Perform approved security functions)Input for Encryption: key and plain text Input for Decryption: key and cipher textOutput for Encryption: cipher text Output for Decryption: plain text
AES Key Wrapping (Perform approved security functions)key encryption key and key to be wrappedwrapped key
Secure Hash Generation (Perform approved security functions)MessageHash value
HMAC generation (Perform approved security functions)HMAC key and messagekeyed Hash value
RSA signature generation and verification (Perform approved security functions)Input for SigGen: RSA private key and message Input for SigVer: RSA public key and signatureOutput SigGen: signature Output for Sigver: True or False
ECDSA signature generation and verification (Perform approved security functions)Input for SigGen: ECDSA private key and message Input for SigVer: ECDSA public key and signatureOutput for SigGen: signature Output for SigVer: True or False
Random number generation (Perform approved security functions)Entropy input string, nonceRandom numbers
PBKDF (Perform approved security functions)passwordderived key
KBKDF (Perform approved security functions)key derivation keyDerived key
ECDSA (key pair generation) (Perform approved security functions)random numbersgenerated private and public key pair
RSA (key pair generation)random prime numbersgenerated private and public key pair

4. Roles, Services, and Authentication The module supports a single instance of one authorized role: The Crypto Officer. No support is provided for multiple concurrent operators or a Maintenance Operator. This document may be reproduced and distributed only in its original entirely without revision

Page 19
RoleServiceInputOutput
(Perform approved security functions)
Safe primes key generation (Perform approved security functions)key sizegenerated private and public key pair
Diffie-Hellman Key Shared Secret Computation (Perform approved security functions)domain parameter, received public key and possessed private keyshared secret
EC Diffie-Hellman Shared Secret Computation (Perform approved security functions)domain parameter, received public key and possessed private keyshared secret
Release all resources of symmetric crypto function context (Perform zeroisation)handler of symmetric crypto function contextzeroised and released memory space
Release all resources of hash context (Perform zeroisation)handler of hash contextreleased memory space
Release of all resources of Diffie-Hellman context for Diffie- Hellman and EC Diffie- Hellman (Perform zeroisation)handler of (EC) DiffieHellman contextzeroised and released memory space
Release of all resources of key derivation function context (Perform zeroisation)handler of key derivation function contextzeroised and released memory space
Release of all resources of asymmetric crypto function context (Perform zeroisation)handler of asymmetric crypto function contextzeroised and released memory space
Self-test (Perform self-tests)powerPass/Fail status
Show StatusAPI invocationOperational/Error status
Show Module Info (Show module’s versioning information)API invocationModule Base Name + Module Version Number

Table 8 – Roles, Service Commands, Input and Output This document may be reproduced and distributed only in its original entirely without revision

Page 20

FIPS 140-3 does not require an authentication mechanism for level 1 modules. Therefore, the module does not implement an authentication mechanism for Crypto Officer. The Crypto Officer role is authorized to access all services provided by the module (see Table 9 - Approved Services and Table

10 - Non-Approved Services below).

The module implements a dedicated API function to indicate if a requested service utilizes an approved security function. For services listed in Table 9 - Approved Services, the indicator function returns

  1. For services listed in Table 10 - Non-Approved Services, the indicator function returns
  2. The table below lists all approved services that can be used in the approved mode of operation. The abbreviations of the access rights to keys and SSPs have the following interpretation: This document may be reproduced and distributed only in its original entirely without revision
Page 21
ServicesDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
AES Encryption / Decryption (Perform approved security functions)Input for Encryption: key and plain text Output for Encryption: cipher text Input for Decryption: key and cipher text Output for Decryption: plain textSymmetric Encryption and Decryption AES-CBC (#A2820, #A2815, #A2814, A2819, #A2812, #A2813) AES-ECB (#A2820, #A2815, #A2814, #A2812, #A2813, #A2821, #A2822) AES-CCM (#A2820, #A2815, #A2814, #A2821, #A2822) AES-GCM (#A2820, #A2815, #A2814, #A2821, #A2822) AES- CFB128(#A2820, #A2815, #A2814) AES- CFB8(#A2820, #A2815, #A2814) AES-OFB (#A2820, #A2815, #A2814) AES-CTR (#A2820, #A2815, #A2814, #A2821, #A2822)AES keyCOW, E1

This document may be reproduced and distributed only in its original entirely without revision

Page 22
ServicesDescriptionApproved Security Functions AES-XTS (#A2820, #A2815, #A2814, #A2812, #A2813) CMAC (#A2820)Keys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
AES Key Wrapping (Perform approved security functions)I n p u t : key encryption key and key to be wrapped Output: wrapped keyKey Wrapping KW (#A2820, #A2815, #A2814)AES key, key to be wrapped, wrapped keyCOW, R, E1

This document may be reproduced and distributed only in its original entirely without revision

Page 23
ServicesDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Secure Hash Generation (Perform approved security functions)Input: message Output: Hash valueMessage Digest SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/256 (except for A2823) (#A2820, #A2818 #A2823, #A2817, #A2816)noneCON/A1
HMAC generation (Perform approved security functions)Input: HMAC key and message Output: keyed Hash valueKeyed Hash SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/256 (except for A2823) (#A2820, #A2823, #A2818 #A2817, #A2816)HMAC keyCOW, E1
RSA signature generation and verification (Perform approved security funct ions)Input for SigGen: RSA private key and message Output: signature Input for SigVer: RSA public key and signature Output: True or FalseDigital Signature Generation (PKCS#1 v1.5) and (PKCS PSS) Signature Verification (PKCS#1 v1.5) and (PKCS PSS) (#A2820, #A2817, #A2816, #A2818)RSA Key Pair (including intermediate keygen values)COW, E1

This document may be reproduced and distributed only in its original entirely without revision

Page 24
ServicesDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
ECDSA signature generation and verification (Perform approved security functions)Input for SigGen: ECDSA private key and message Output: signature Input for SigVer: ECDSA public key and signature Output: True or FalseDigital Signature Generation: P- 224, P-256, P- 384, P-521 Signature Verification: P- 224, P-256, P- 384, P-521 (#A2820, #A2817, #A2816, #A28 18)ECDSA Key Pair (including intermediate keygen values)COW, E1
Random number generation (Perform approved security functions)Input: Entropy input string, nonce Output: Random numbers (DRBG Output)Random number generation CTR_DRBG (AES-128, AES- 256) #A2820, #A2821, #A2815, #A2814, #A2822 HMAC_DRBG (SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512)Entropy Input String, Seed, DRBG V and DRBG Key, random numbers (DRBG Output)COG, R, W, E, Z1

#A2818) This document may be reproduced and distributed only in its original entirely without revision

Page 25
ServicesDescriptionApproved Security Functions #A2820, #A2817, #A2816, #A2818 #A2820, #A2817, #A2816, #A2818 CK GKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
PBKDF (Perform approved security functions)Input: password Output: derived keyKey Derivation PBKDF HMAC with: SHA-1, SHA-224, SHA-256, SHA- 384, SHA-512 #A2820, #A2817, #A2816, #A2818 CK GPBKDF Derived Keys (including password hash), PBKDF PasswordCOG, R, W, E1
KBKDF (Perform approved security functions)Input: key derivation key Output: derived keyKey Derivation KDF Mode: Counter and Feedback MAC Mode: HMAC- SHA-1, HMAC- SHA2-224, HMAC- SHA2- 256, HMAC-SHA2-384, HMAC-SHA2-512 Supported Lengths: 8-4096 Increment 8 Fixed Data Order: Before Fixed Data Counter Length: 32 KDF Mode:KBKDF Key Derivation Key, KBKDF Derived KeyCOG, R, W, E1

CKG CKG This document may be reproduced and distributed only in its original entirely without revision

Page 26
ServicesDescriptionApproved Security Functions Counter AES- CMAC based (for A2820 only) #A2820, #A2817, #A2816, #A2818 CK GKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
ECDSA (key pair generation) (Perform approved security functions)Input: random numbers Output: generated private and public key pairKey Pair Generation (PKG): P-224, P- 256, P-384, P-521 Public Key Validation (PKV): P-224, P-256, P- 384, P-521 #A2820, #A2817, #A2816, #A2818 CK GECDSA Key Pair (including intermediate keygen values)COG, R, E1
RSA (key pair generation) (Perform approved security functions)Input: random prime numbers Output: generated private and public key pairAsymmetric Key Generation Modulus 2048, 3072, 4096 #A2820, #A2817, #A2816, #A2818 CK GRSA Key Pair (including intermediate keygen values)COG, R, E1
Diffie- Hellman Key Shared Secret Computation (Perform approvedInput: domain parameter, received public key and possessed private key Output: shared secretKAS-FFC-SSC #A2820DH Key Pair (including intermediate keygen values)COG, R, W, E1

CKG CKG CKG This document may be reproduced and distributed only in its original entirely without revision

Page 27
Services security functions)DescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
EC Diffie- Hellman Shared Secret Computation (Perform approved security functions)Input: domain parameter, received public key and possessed private key Output: shared secretKAS-ECC-SSC #A2820ECC CDH Key Pair (including intermediate keygen values)COG, R, W, E1
Safe primes key generationInput: key size Output: generated private and public key pairSafe primes key pair generation #A2820 CKGDH Key Pair (including intermediate keygen values)COG, R, E1
Release all resources of symmetric crypto function context (Perform zeroisation)Input: handler of symmetric crypto function context Output: zeroised and released memory spaceN/AAES keyCOZ1
Release all resources of hash context (Perform zeroisation)Input: handler of hash context Output: released memory spaceN/AHMAC keyCOZ1
Release of all resources of Diffie- Hellman context for Diffie- Hellman andInput: handler of (EC) Diffie- Hellman context Output: zeroised and released memory spaceN/ADH Key Pair (including intermediate keygen values), ECC CDH Key Pair (including intermediateCOZ1

This document may be reproduced and distributed only in its original entirely without revision

Page 28
Services EC Diffie- Hellman (Perform zeroisation)DescriptionApproved Security FunctionsKeys and/or SSPs keygen values), DH Shared Secret, ECC CDH Shared SecretRolesAccess rights to Keys and/or SSPsIndicator
Release of all resources of key derivation function context (Perform zeroisation)Input: handler of key derivation function context Output: zeroised and released memory spaceN/AKBKDF Key Derivation Key, PBKDF Password, KBKDF Derived Key and PBKDF Derived KeyCOZ1
Release of all resources of asymmetric crypto function context (Perform zeroisation)Input: handler of asymmetric crypto function context Output: zeroised and released memory spaceN/ARSA/EC/DH keysCOZ1
Self-test (Perform Self-tests)Input: power Output: Pass/Fail statusAES-CCM (#A2820, #A2815, #A2814, #A2821, #A2822) AES-GCM (#A2820, #A2815, #A2814, #A2821, #A2822) AES-XTS (#A2820, #A2815, #A2814, #A2812, #A2813) AES-CBC (#A2820, #A2815, #A2814, A9819, #A2812, #A2813)All SSPsCOE1

N/A Z 1 This document may be reproduced and distributed only in its original entirely without revision

Page 29

Services

Description

Approved Security Functions AES-ECB (#A2820, #A2815, #A2814, #A2812, #A2813, #A2821, #A2822) HMAC_DRBG (#A2820, #A2817, #A2816, #A2818) CTR_DRBG, #A2820, #A2821, #A2815, #A2814, #A2822 HMAC (#A2820, #A2818 #A2823, #A2817, #A2816) RSA Signature Generation (#A2820, #A2817, #A2816, #A2818) RSA Signature Verification (#A2820, #A2817, #A2816, #A2818) ECDSA Signature Generation (#A2820, #A2817, #A2816, #A2818)

Keys and/or SSPs

Roles

Access rights to Keys and/or SSPs

Indicator

This document may be reproduced and distributed only in its original entirely without revision

Page 30
ServicesDescriptionApproved Security Functions ECDSA Signature Verification (#A2820, #A2817, #A2816, #A2818) DH and ECDH Z computation (#A2820) PBKDF (#A2820, #A2817, #A2816, #A2818) KBKDF (#A2820, #A2817, #A2816, #A28 18)Keys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Show StatusInput: API invocation Output: Operational/Error statusN/ANoneCON/AStatus returned
Show Module Info (Show module’s versioning information)Input: API invocation Output: Module Base NameN/ANoneCON/AVersioning information returned

G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. N/A= The service does not access any SSP during its operation This document may be reproduced and distributed only in its original entirely without revision

Page 31
ServiceDescriptionAlgorithms AccessedRoleIndicator
Triple-DES encryption / decryptionModule does not meet FIPS 140-3 IG C.G because it does not have a control over the number of blocks to be encrypted under the same Triple-DES key. Input for Encryption: key and plain text Output for Encryption: cipher text Input for Decryption: key and cipher text Output for Decryption: plain textTriple-DESCrypto Officer (CO)0
(other) symmetric encryption / decryptionThey are non-approved encryption algorithms. Input for Encryption: key and plain text Output for Encryption: cipher text Input for Decryption: key and cipher text Output for Decryption: plain textBlowfish, CAST5, DES, ECIES, RC2, RC4Crypto Officer (CO)0
RSA Key WrappingThe CAST does not perform the full KTS, only the raw RSA encrypt/decrypt Input: RSA public key and key to be wrapped Output: wrapped keyRSA encrypt/decryptCrypto Officer (CO)0

This document may be reproduced and distributed only in its original entirely without revision

Page 32
ServiceDescriptionAlgorithms AccessedRoleIndicator
RSA Signature Generation/Signature Verification/Key-pair GenerationANSI X9.31 Key Pair Generation Key Size < 2048 PKCS#1 v1.5 and PSS Signature Generation Key Size < 2048 PKCS#1 v1.5 and PSS Signature Verification Key Size < 1024RSA KeyGen RSA SigGen RSA SigVerCrypto Officer (CO)0
ECDSA PKG, PKV, Signature Generation/Signature VerificationECDSA keys with curve P-192ECDSA PKG, PKV, SigGen/SigVerCrypto Officer (CO)0
Ed25519 Key Generation, Signature Generation/Signature Verification256-bit keyEd25519 KeyGen Ed25519 SigGen Ed25519 SigVerCrypto Officer (CO)0
ANSI X9.63 Key DerivationSHA-1 hash-basedSHA-1Crypto Officer (CO)0
SP800-56Cr1 Key Derivation (HKDF)SHA-256 hash-basedSHA-256Crypto Officer (CO)0
RFC6637 Key DerivationSHA hash basedSHA-256, SHA- 512, AES-128, AES-256Crypto Officer (CO)0
OMAC Message Authentication Code Generation and VerificationOne-Key CBC MAC using 128-bit keyOMACCrypto Officer (CO)0
Message digest verificationInput: message Output: message digestMD2, MD4, RIPEMDCrypto Officer (CO)0
Diffie-HellmanKAS-FFC-SSC using key sizes < 2048KAS-FFC-SSCCrypto Officer (CO)0
EC Diffie-HellmanKAS-ECC-SSC using curves < P-224KAS-ECC-SSCCrypto Officer (CO)0
Ed25519 Key AgreementInput: peer public key, own private key Output: shared secretEd25519Crypto Officer (CO)0
Integrated Encryption Scheme on ellipticEncrypt: Input: peer public key, plaintext Output: public key,Integrated Encryption Scheme onCrypto Officer (CO)0

This document may be reproduced and distributed only in its original entirely without revision

Page 33
ServiceDescriptionAlgorithms AccessedRoleIndicator
curves (ECIES) Encryption/Decryptionciphertext (with authentication tag) Decrypt: Input: authentication tag, ciphertext, own private key Output: plaintext message or errorelliptic curves (ECIES)

Table 10 – Non-Approved Services This document may be reproduced and distributed only in its original entirely without revision

Page 34

5. Software/Firmware Security Integrity Techniques The Apple corecrypto Module v12 [Intel, User, Software] is in the form of binary executable code. A software integrity test is performed on the runtime image of the module. The HMAC-SHA2-256 implemented in the module is used as an approved algorithm for the integrity test. If the test fails, the module enters an error state where no cryptographic services are provided and data output is prohibited i.e. the module is not operational. The Software Integrity Key (HMAC-SHA2-256 with 256 bits of security strength), a non-SSP, is stored in the module binary computed during build. On-Demand Integrity Test The integrity test is also performed as part of the Pre-Operational Self-Tests. It is automatically executed at power-on. It can also be invoked by powering-off and reloading the module to meet the on-demand request for integrity test. In addition, the module provides the Self-Test service to perform self-tests, including integrity test and algorithm tests, on demand. Software Loading The module does not support loading of any additional software. This document may be reproduced and distributed only in its original entirely without revision

Page 35
  1. Operational Environment Applicability The Apple corecrypto Module v12 [Intel, User, Software] operates in a modifiable operational environment per FIPS 140-3 level 1 specifications. The module is supplied as part of macOS Monterey 12, a commercially available general-purpose operating system executing on the hardware specified in section
  2. Policy The operating system is restricted to a single operator (single-user mode; i.e. concurrent operators are explicitly excluded). When the operating system loads the module into memory, it invokes the Self-Test functionality, which in turn runs the mandatory self-tests. This document may be reproduced and distributed only in its original entirely without revision
Page 36

7. Physical Security The FIPS 140-3 physical security requirements do not apply to the Apple corecrypto Module v12 [Intel, User, Software] since it is a software module. This document may be reproduced and distributed only in its original entirely without revision

Page 37

8. Non-invasive Security Currently, the non-invasive security is not required by FIPS 140-3 (see NIST SP 800-140F). The requirements of this area are not applicable to the module. This document may be reproduced and distributed only in its original entirely without revision

Page 38
Key/SSP Name/T ypeStren gthSecurityGenerat ionImportEstablish mentStorag eZeroisat ionUse
Function/Expor tand
and Cert.related
Numberkeys
Table, extracted as text (did not parse into structured rows)
9. Sensitive Security Parameter Management The following table summarizes the keys and Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module: Symmetric Encryption Decryption AES-CBC (#A2820, #A2815, #A2814, A9819, #A2812, #A2813) AES-ECB (#A2820, #A2815,                                                              Automati Size:                                                                 N/A: #A2814,                                                                  c 128,                                                                 The #A2812,                                                             zeroisatio 192,                                  Import                       module #A2813,                                                               n when     Symmet
256                                     and                         does
#A2821,                                                              structure     ric Export                         not AES Key                #A2822)                                                                  is      Encrypti N/A           to            N/A         provide (CSP)                AES-CCM                                                              deallocat   on and Strengt                                 calling                      persist (#A2820,                                                               ed or     Decrypti h:                                  applicati                       ent #A2815,                                                             when the       on 128,                                     on                        keys/S #A2814,                                                             system is 192,                                                                 SPs #A2821,                                                              powered

256 storage

#A2822) down AES-GCM (#A2820, #A2815, #A2814, #A2821, #A2822) AESCFB128(#A2 820, #A2815, #A2814) AESCFB8(#A282 This document may be reproduced and distributed only in its original entirely without revision

Page 39
Key/SSP Name/T ypeStren gthSecurityGenerat ionImportEstablish mentStorag eZeroisat ionUse
Function/Expor tand
and Cert.related
0, #A2815, #A2814) AES-OFB (#A2820, #A2815, #A2814) AES-CTR (#A2820, #A2815, #A2814, #A2821, #A2822) AES-XTS (#A2820, #A2815, #A2814, #A2812, #A2813) CMAC (#A2 820)Numberkeys
HMAC Key (CSP)Min: 112 bitsHMAC generation SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 SHA2- 512/256 #A2820, #A2818 #A2823, #A2817, #A2816N/AKeyed Hash
Table, extracted as text (did not parse into structured rows)
ECDSA         The key ECDSA                    Keygen        pairs are                                                      Digital Key Pair     Curves                    generate                      N/A                              Signatu This document may be reproduced and distributed only in its original entirely without revision
Page 40
Key/SSP Name/T ypeStren gthSecurityGenerat ionImportEstablish mentStorag eZeroisat ionUse
Function/Expor tand
and Cert.related
Numberkeys
P-256, P-384, P-521 Strengt h: 112, 128, 192, 256#A2816, #A2818 CK Gnt to SP800- 133r2 (CKG) using FIPS186- 4 Key Generati on method, and the random value used in the key generatio n is generate d using SP800- 90Ar1 DRBG
RSA Key Pair (CSP)Modulu s: 2048, 3072, 4096 Strengt h: 112, 128, 152RSA Keygen #A2820, #A2817, #A2816, #A2818 CK GN/ADigital Signatu re
Entropy Input String (CSP)256 bitsObtained from the ENTImport from OS; No ExportN/ARandom Number Generat ion
Seed (CSP)256 bitsDerived from entropy input string as defined by SP 800- 90Ar1N/A

s: h: (CSP) #A2821, #A2815, #A2814, #A2822 HMAC_DRB Derived G (SHA-1, from SHA-224, entropy SHA-512) defined This document may be reproduced and distributed only in its original entirely without revision

Page 41
Key/SSP Name/T ypeStren gthSecurityGenerat ionImportEstablish mentStorag eZeroisat ionUse
Function/Expor tand
and Cert.related
Numberkeys
DRBG V (CSP)#A2816, #A2818Generate d Internally using the approved DRBGN/AN/AN/A: The module does not provide persist ent keys/S SPs storageAutomati c zeroisatio n when structure is deallocat ed or when the system is powered downGenerat ion
DRBG Key (CSP)Generate d Internally using the approved DRBGN/AN/AN/A: The module does not provide persist ent keys/S SPs storageAutomati c zeroisatio n when structure is deallocat ed or when the system is powered down
DRBG Output (CSP)CTR_DRBG (AES-128, AES-256) #A2820, #A2821, #A2815, #A2814, #A2822 HMAC_DRBG (SHA-1, SHA- 224, SHA- 256, SHA- 384, SHA- 512) #A2820,Generate d Internally using the approved DRBGN/AN/A

N/A: c N/A: c N/A: This document may be reproduced and distributed only in its original entirely without revision

Page 42
Key/SSP Name/T ypeStren gthSecurityGenerat ionImportEstablish mentStorag eZeroisat ionUse
Function/Expor tand
and Cert.related
Numberkeys
#A2817, #A2816, #A2818 CKGKey Derivati on
PBKDF Derived Keys (including password hash) (CSP)Min: 112 bitsPBKDF #A2820, #A2817, #A2816, #A2818 CK GInternally generate d via SP800- 132 PBKDF key derivatio n algorithmNo Import; Export to calling applicati onN/A
PBKDF Password (CSP)N/APBKDF #A2820, #A2817, #A2816, #A2818N/Aimporte d from calling applicati on, No ExportN/AKey Derivati on
KBKDF Key Derivatio n Key (CSP)Min: 112N/Aimporte dN/A
Table, extracted as text (did not parse into structured rows)
n Key                    Derivation Derivatio               KDF Mode:           N/A                       N/A (CSP)                   Feedback MAC Mode:       Internally HMAC-SHA-       generate 1, HMAC-          d via SHA2-224,        SP800KBKDF         Min:        HMAC-           108 HMAC-             n SHA2-512 This document may be reproduced and distributed only in its original entirely without revision
Page 43
Key/SSP Name/T ypeStren gthSecurityGenerat ionImportEstablish mentStorag eZeroisat ionUse
Function/Expor tand
and Cert.related
#A2816, #A2818 KBKDF CMAC based (for A2820 only) CKGNumberkeys
DH Key Pair (CSP)2048KAS-FFC- SSC #A2820 CKGGenerate d using Safe- prime groups MODP groups belongin g to (RFC 3526)Import from calling applicati on, No ExportN/AKAS- SSC FFC
DH Shared Secret (CSP)N/ANo Import; Export to calling applicati onComputed using SP800- 56Ar3 DH shared secret computatio n

d n This document may be reproduced and distributed only in its original entirely without revision

Page 44
Key/SSP Name/T ypeStren gthSecurityGenerat ionImportEstablish mentStorag eZeroisat ionUse
Function/Expor tand
and Cert.related
Numberkeys
ECC CDH Key Pair (CSP)Curves : P-224, P-256, P-384, P-521 Strengt h: 112, 128, 192, 256KAS-ECC- SSC #A2820 CKGGenerate d using FIPS 186-4 Key Generati on method, and the random value used in key generatio n is generate d using SP800- 90Ar1 DRBGImport from calling applicati on, No ExportN/AKAS- SSC ECC
ECC CDH Shared Secret (CSP)Curves : P-224, P-256, P-384, P-521 Strengt h: 112, 128, 192, 256KAS-ECC- SSC #A2820Internally generate d via SP800- 56Ar3 ECC CDH shared secret computat io nNo Import; Export to calling applicati onN/AKAS- SSC ECC

: Table 11 – SSPs The Software Integrity Key (HMAC-SHA2-256 with 256 bits of security strength), a non-SSP, is stored in the module binary computed during build. A NIST approved deterministic random bit generator based on a block cipher as specified in NIST [SP 800-90Ar1] is used. The default Approved DRBG used for random number generation is a CTR_DRBG This document may be reproduced and distributed only in its original entirely without revision

Page 45
Entropy sourcesMinimum number of bits of entropyDetails
NISP SP800-90B compliant ENT (P) ESV Cert. #E14256-bits per 256-bit output sampleThe seed is provided by an SP 800-90B compliant entropy source

using AES-256 with derivation function and without prediction resistance. The random numbers used for key generation are all generated by CTR_DRBG in this module. Per section 10.2.1.1 of [SP 800-90Ar1], the internal state of CTR_DRBG is the value V, Key and a reseed counter. The module also employs a HMAC_DRBG for random number generation. The HMAC_DRBG is only used at the early boot time of macOS User for memory randomization. The output of HMAC_DRBG is not used for key generation. Per section 10.1.2.1 of [SP 800-90Ar1], the internal state of HMAC_DRBG is the value V, Key and a reseed counter. The deterministic random bit generators are seeded by read_random. The read_random is the User Space interface that extracts random bits from the entropy pool. The output of entropy pool provides 256-bits of entropy to seed and reseed SP800-90B DRBG during initialization (seed) and reseeding (reseed). Table 12 – Non-Deterministic Random Number Generation Specification Key / SSP Generation The module generates Keys and SSPs in accordance with FIPS 140-3 IG D.H. The cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys as per sections 4, 5.1, 5.2, 6.2.2 and

6.2.3 [SP800-133r2] (vendor affirmed), compliant with [FIPS186-4], and using DRBG compliant with

[SP800-90Ar1]. A seed (i.e., the random value) used in asymmetric key pair generation is a direct output from [SP800-90Ar1] CTR_DRBG. The key generation service for RSA, Diffie-Hellman, and EC key pairs as well as the [SP 800-90Ar1] DRBG have been ACVT tested with algorithm certificates found in Table 4. Keys/SSPs Establishment The module provides the following key/SSP establishment services in the Approved mode:

Page 46

4.1 of [SP800-133r2] as indirect generation from DRBG. The derived keys may only be used in

storage applications. • KBKDF Key Derivation o The KBKDF is compliant to [SP800-108]. The module implements both Counter and Feedback modes with HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, or HMACSHA2-512 as the PRF. Keys/SSPs Import/Export All keys and SSPs that are entered from, or output to module, are entered from or output to the invoking application running on the same device. Keys/SSPs entered into the module are electronically entered in plain text form. Keys/SSPs are output from the module in plain text form if required by the calling application. The module allows the output of plaintext CSPs (i.e., EC/DH/RSA Key Pairs). To prevent inadvertent output of sensitive information, the module performs the following two independent internal actions:

  1. The module will internally request the random number generation service to obtain the random numbers and verify that the service completed without errors.
  2. Once the keys are generated the module will perform the pairwise consistency test and verify that the test is completed without errors. Only after successful completion of both actions, are the generated CSPs output via the KPI output parameter in plaintext. Keys/SSPs Storage The Apple corecrypto Module v12 [Intel, User, Software] stores ephemeral keys/SSPs in memory only. They are received for use or generated by the module only at the command of the calling application. The module does not provide persistent keys/SSPs storage. This document may be reproduced and distributed only in its original entirely without revision
Page 47

The module protects all keys/SSPs through the memory separation and protection mechanisms provided by the operating system. No process other than the module itself can access the keys/SSPs in its process’ memory. Keys/SSPs Zeroization Keys and SSPs are zeroised when the appropriate context object is destroyed or when the system is powered down. Input and output interfaces are inhibited while zeroisation is performed. This document may be reproduced and distributed only in its original entirely without revision

Page 48

10. Self-tests The module performs pre-operational self-tests automatically when the module is loaded into memory; the pre- operational self-tests triggered at power-on ensure that the module is not corrupted and that the cryptographic algorithms work as expected. FIPS 140-3 only requires that software/firmware integrity test(s) and the requisite cryptographic algorithm(s) be tested during power-up, but the Apple corecrypto Module v12 [Intel, User, Software] runs all Cryptographic Algorithm Tests (CASTs) during power-up as well. The following tests are performed each time the Apple corecrypto Module v12 [Intel, User, Software] starts. If any of the following tests fails the device (tested platform) fails to startup. To invoke the self-tests (pre-operational and CASTs) on demand (and periodically), the user may reboot the system. While the module is executing the self-tests, services are not available and input and output are inhibited. The self-tests are implemented for the following algorithms:

Page 49

 RSA 2048 bits SHA2-256 Signature Generation KAT  RSA 2048 bits SHA2-256 Verify KAT  ECDSA P-224 SHA2-224 Sig Gen KAT  ECDSA P-224 SHA2-224 Sig Ver KAT  KAS-FFC-SSC KAT  KAS-ECC-SSC KAT  PBKDF KAT  KBKDF counter KAT  NIST SP 800-90B Repetitive Count Test (RCT)  NIST SP 800-90B Adaptive Proportion Test (APT)

Page 50

prohibited. The only method to clear the error state is to power cycle the device. The module will only enter into the operational state after successfully passing the preoperational software integrity test and the Conditional CASTs. The module returns the “FAILED: fipspost_post_integrity” error indicator in case of a software integrity test failure, “FAILED: <algorithm>” in case of a CAST failure. Public Material – May be reproduced only in its original entirety (without revision).

Page 51

11. Life-cycle Assurance Delivery and Operation The module is built into macOS Monterey 12 and delivered with macOS. There is no standalone delivery of the module as a software library. The vendor’s internal development process guarantees that the correct version of module goes with its intended macOS version. For additional assurance, the module is digitally signed by vendor and it is verified during the integration into macOS. This digital signature-based integrity protection during the delivery/integration process is not to be confused with the HMAC-SHA2-256 based integrity check performed by the module itself as its pre-operational self-test. No additional maintenance requirements apply. Crypto Officer Guidance The Approved mode of operation is configured in the system by default and can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table 10 - Non-Approved Services. If the device starts up successfully, then the module has passed all self-tests and is operating in the Approved mode. A Crypto Officer Role Guide is provided by Apple which offers IT System Administrators with the necessary technical information to ensure FIPS 140-3 Compliance of macOS Monterey 12 systems. This guide walks the reader through the system’s assertion of cryptographic module integrity and the steps necessary if module integrity requires remediation. A link to the Guide can be found on the Product security, validations, and guidance page. Public Material – May be reproduced only in its original entirety (without revision).

Page 52

12. Mitigation of Other Attacks The module does not claim mitigation of other attacks. Public Material – May be reproduced only in its original entirety (without revision).