| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Status | Active |
| Sunset date | 1/27/2030 |
| Caveat | No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. |
| Vendor | Nuvoton Technology Corporation |
| Algorithm | ACVP Cert |
|---|---|
| AES-CBC | A4133 |
| AES-CCM | A4133 |
| AES-CFB128 | A4133 |
| AES-CMAC | A4133 |
| AES-CTR | A4133 |
| AES-ECB | A4133 |
| AES-GCM | A4133 |
| AES-GMAC | A4133 |
| AES-OFB | A4133 |
| ECDSA KeyGen (FIPS186-4) | A4133 |
| ECDSA KeyVer (FIPS186-4) | A4133 |
| ECDSA SigGen (FIPS186-4) | A4133 |
| ECDSA SigVer (FIPS186-4) | A4133 |
| Hash DRBG | A4133 |
| HMAC-SHA2-256 | A4133 |
| HMAC-SHA2-384 | A4133 |
| HMAC-SHA2-512 | A4133 |
| KAS-ECC-SSC Sp800-56Ar3 | A4133 |
| KDF SP800-108 | A4133 |
| KTS-IFC | A4133 |
| RSA SigGen (FIPS186-4) | A4133 |
| RSA SigVer (FIPS186-4) | A4133 |
| SHA2-256 | A4133 |
| SHA2-384 | A4133 |
| SHA2-512 | A4133 |
flowchart LR
%% Deterministic review-risk graph for Nuvoton Cryptographic Library 2.3
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Firmware Load</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>status output</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for Nuvoton Cryptographic Library 2.3
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Firmware Load</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>status output</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;Nuvoton Cryptographic Library 2.3 Hardware Version 2.3.8 Version 1.2 Last update: 2025-01-07 Prepared by: atsec information security corporation
9130 Jollyville Road, Suite 260
Austin, TX 78759 www.atsec.com © 2024 Nuvoton Technology Corporation / atsec information security.
© 2024 Nuvoton Technology Corporation / atsec information security.
2 of 31
| ISO/IEC 24759 Section 6. [Number Below] | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic Module Specification | 1 |
| 3 | Cryptographic Module Interfaces | 1 |
| 4 | Roles, Services, and Authentication | 1 |
| 5 | Software/Firmware Security | Not Applicable |
| 6 | Operational Environment | 1 |
| 7 | Physical Security | 1 |
| 8 | Non-invasive Security | Not Applicable |
| 9 | Sensitive Security Parameter Management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle Assurance | 1 |
| 12 | Mitigation of Other Attacks | Not Applicable |
| Overall Level | 1 |
This document is the non-proprietary FIPS 140-3 Security Policy for Hardware version 2.3.8 of the Nuvoton Cryptographic Library 2.3. It has a one-to-one mapping to the [SP 800-140B] starting with section B.2.1 named “General” that maps to section 1 in this document and ending with section B.2.12 named “Mitigation of other attacks” that maps to section 12 in this document. This document also contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for a Security Level 1 module. Table 1 describes the individual security areas of FIPS 140-3, as well as the Security Levels of those individual areas: Table 1 - Security Levels © 2024 Nuvoton Technology Corporation / atsec information security.
3 of 31
| Model/Part Number(s) | Hardware Version(s) | Firmware Version(s) | Processor(s) | Non-Security Relevant Distinguishing Features | |
|---|---|---|---|---|---|
| Nuvoton NPCM8mnx Arbel Baseboard Management Controller (BMC) | 2.3.8 | N/A | ARM Cortex -M4 Core | N/A |
| CAVP Cert | Algorithm and Standard | Mode / Method | Description / Key / Curve / Modulus Size(s) | Use / Function | ||||
|---|---|---|---|---|---|---|---|---|
| A4133 | AES | CBC | ECB | 128, 192, 256 bits | AES | E | ncryption and AES Decryption | |
| [SP 800-38 A] [SP 800-38 C] | CFB128 | CCM | OFB | |||||
| AES [SP 800-38 A] | CTR | 128, 192, 256 bits | ||||||
| AES [SP 800-38 D] | GCM | 128, 192, 256 bits | ||||||
| AES | CMAC | 128, 192, 256 bits | CMAC Message Authentication Code | |||||
| [SP 800-38 B] | Generation and CMAC Message Authentication Code Verification |
The Nuvoton Cryptographic Library 2.3 cryptographic module (hereafter referred to as “the module”) is a Hardware single-chip cryptographic module. More specifically, the module is considered a sub-chip cryptographic subsystem as defined in IG 2.3.B. The module has been tested by atsec CST lab on the following platforms: Table 2 - Cryptographic Module Tested Configuration
The module only supports approved mode of operation. There are no non-approved but allowed algorithms used in approved mode. There are no non-approved algorithms used in the approved mode with no security claimed. There are no non-approved algorithms used in a non-approved
The Table 3 below lists all security functions of the module, including specific key strengths employed for approved services, and implemented modes of operation. © 2024 Nuvoton Technology Corporation / atsec information security.
4 of 31
CAVP Cert
Algorithm and Standard AES [SP 800-38 D] HMAC [FIPS 198-1] RSA [FIPS 186-4] KBKDF [SP800-108] KTS-IFC [SP800-56Brev2] ECDSA [FIPS 186-4] SHS [FIPS 180-4] KAS-ECC-SSC [SP800-56Arev3]
Mode / Method GMAC HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 RSA-PSS using SHA2-256, SHA2-384 or SHA2-512 RSA-PKCS#1 v1.5 using SHA2-256, SHA2-384 or SHA2-512 KDF Modes: Counter, Feedback, Double pipeline iteration MAC Modes: HMAC-SHA2- 256, HMAC-SHA2-384, HMAC-SHA2-512 KTS-OAEP-basic B.4.2 Testing Candidates NA SHA2-256, SHA2-384, SHA2-512 N/A SHA2-256 SHA2-384 SHA2-512 ephemeralUnified
Description / Key / Curve / Modulus Size(s) 128, 192, 256 bits 256, 384, 512 bits 2048 or 3072 modulus 256, 384, 512 bits 2048 or 3072 modulus P-256, P-384, P-521 curves P-256, P-384, P-521 curves P-256, P-384, P-521 curves P-256, P-384, P-521 curves N/A P-256, P-384, P-521 curves
Use / Function GMAC Message Authentication Code Generation and GMAC Message Authentication Code Verification HMAC Message Authentication Code Generation RSA Signature Generation, RSA Signature Verification Key Derivation Function RSA Key Transport (key wrapping and un-wrapping) ECDSA Key Generation ECDSA Key Verification ECDSA Signature Generation, ECDSA Signature Verification ECDSA Signature Generation Component Message Digest Generation EC Diffie-Hellman Shared Secret Computation (complete)
© 2024 Nuvoton Technology Corporation / atsec information security.
5 of 31
| CAVP Cert | Algorithm and Standard Hash_DRBG [SP800-90A] | Mode / Method SHA2-512 | Description / Key / Curve / Modulus Size(s) 512 | Use / Function Random Number Generation |
|---|---|---|---|---|
| Vendor | CKG (Cryptographic Key | SP800-133rev2 Section | N/A | ECDSA Key Generation |
| Affirmed | Generation) | 5.1 and FIPS 186-4: direct | ||
| [SP800-133rev2] | output U from approved DRBG; no XOR, no post- | |||
| [FIPS 186-4] | processing | |||
| E94 | ESV | N/A | Used to seed the | Random Number Generation |
| [SP800-90B] | SP800-90Arev1 DRBG |
Figure 1 depicts the module’s block diagram with a red outline indicating the Tested Operational Environment’s Physical Perimeter (TOEPP) of the NPCM8mnx and the blue dotted outline depicting the cryptographic boundary of the sub-chip embedded within the physical perimeter. Figure 1 - [Block Diagram] © 2024 Nuvoton Technology Corporation / atsec information security.
6 of 31
Figure 2 shows a picture of the NPCM8mnx (BMC) in which the sub-chip module is embedded. Figure 2: Nuvoton NPCM8mnx © 2024 Nuvoton Technology Corporation / atsec information security.
7 of 31
| Physical Interface | Logical Interface1 | Data that passes over port/interface |
|---|---|---|
| I/O Ports | Data Input | Data inputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers |
| I/O Ports | Data Output | Data outputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers |
| I/O Ports | Control Input | Control inputs which control the operation of the module are provided through dedicated parameters. |
| I/O Ports | Status Output | Status output is provided in return codes and through messages. Documentation for each API lists possible return codes. A complete list of all return codes returned by the C language APIs within the module is provided in the header files and the API documentation. Messages are documented also in the API documentation. |
| Power Port | Power Interface | Power interface is provided internally by TEOPP in which the cryptographic module is embedded. |
Table 4 - Ports and Interfaces © 2024 Nuvoton Technology Corporation / atsec information security.
8 of 31
| Service | Description | Inputs | Outputs | Approved Security Functions | Keys and/or SSPs | Roles | Access rights to Keys and/or SSPs | Indicator |
|---|---|---|---|---|---|---|---|---|
| AES Encryption | Data Encryption | AES key and plain text | cipher text | AES-CBC AES-ECB AES-CCM AES-OFB AES-CFB128 AES-CTR AES-GCM | AES key | User | W, E | NCL_STATUS_OK |
| AES Decryption | Data Decryption | AES key and cipher text | plain text | AES-CBC AES-ECB AES-CCM AES-OFB AES-CFB128 AES-CTR AES-GCM | AES key | User | W, E | NCL_STATUS_OK |
| CMAC Message Authenticatio n Code Generation | Message Authentication Code Generation | AES key and message M | MAC | AES-CMAC | AES key | User | W, E | NCL_STATUS_OK |
The module supports two authorized roles: A Crypto Officer Role and a User Role. No support is provided for a Maintenance operator. The module does not implement a bypass mode nor concurrent operators. The Crypto Officer is implicitly assumed. Crypto Officer may be used to facilitate the module's audit functions by invoking the "Get Module Description" or "Show-Status" services. The User can perform any of the other services mentioned in Table 5. The Users of the module are software applications that implicitly assume the User Role when requesting any cryptographic services provided by the module. FIPS 140-3 does not require authentication mechanism for level 1 modules. Therefore, the module does not implement an authentication mechanism. The module only implements Approved security functions in an Approved mode. Table 5 below lists services available. The module provides an approved service indicator by receiving a return code of “NCL_STATUS_OK to indicate that the service executed an approved security function. NOTE: The module does not implement any non-Approved Algorithms (neither with nor without security claim). The abbreviations of the access rights to keys and SSPs have the following interpretation: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. © 2024 Nuvoton Technology Corporation / atsec information security.
9 of 31
| Service | Description | Inputs | Outputs | Approved Security Functions | Keys and/or SSPs | Roles | Access rights to Keys and/or SSPs | Indicator |
|---|---|---|---|---|---|---|---|---|
| CMAC Message Authenticatio n Code Verification | Message Authentication Code Verification | MAC and Message | “VALID” or “INVALID” | AES-CMAC | AES key | User | W, E | NCL_STATUS_OK |
| GMAC Message Authenticatio n Code Generation | Message Authentication Code Generation | AES key, AAD | authenticat ion tag | AES-GMAC | AES key | User | W, E | NCL_STATUS_OK |
| GMAC Message Authenticatio n Code Verification | Message Authentication Code Verification | AES key, AAD, IV, authentic ation tag | “PASS” or “FAIL” | AES-GMAC | AES key | User | W, E | NCL_STATUS_OK |
| HMAC Message Authenticatio n Code Generation | Message Authentication Code Generation | HMAC key and message | MAC | HMAC-SHA2- 256 HMAC- SHA2-384 HMAC-SHA2- 512 | HMAC key | User | W, E | NCL_STATUS_OK |
| Message Digest Generation | SHS Message Digest Generation | message | digest (hash value) | SHA2-256 SHA2-384 SHA2-512 | none | User | N/A | NCL_STATUS_OK |
| RSA Key Transport (encapsulatio n) | Key encapsulation using KTS- OAEP-basic | RSA public key and key to be encapsul ated | encapsulat ed key | KTS-IFC | RSA public key | User | W, E | NCL_STATUS_OK |
| RSA Key Transport (un- encapsulation ) | Key Un- encapsulation using KTS- OAEP-basic | RSA private key and key to be un- encapsul ated | plaintext key | KTS-IFC | RSA private key | User | W, E | NCL_STATUS_OK |
| RSA Digital Signature Generation | Digital Signature Generation | RSA private key, message and hash algorithm | signature | RSA-PSS, RSA-PKCS#1 v1.5 Signature Generation, Hash_DRBG | RSA private key | User | W, E | NCL_STATUS_OK |
| RSA Digital Signature Verification | Digital Signature Verification | RSA public key, signature and hash algorithm | True or False | RSA-PSS, RSA-PKCS#1 v1.5 Signature Verification | RSA public key | User | W, E | NCL_STATUS_OK |
© 2024 Nuvoton Technology Corporation / atsec information security.
10 of 31
| Service | Description | Inputs | Outputs | Approved Security Functions | Keys and/or SSPs | Roles | Access rights to Keys and/or SSPs | Indicator |
|---|---|---|---|---|---|---|---|---|
| ECDSA Digital Signature Generation | Digital Signature Generation | ECDSA private key, message and hash algorithm | signature | ECDSA Digital Signature Generation, Hash_DRBG | ECDSA private key | User | W, E | NCL_STATUS_OK |
| ECDSA Digital Signature Generation Component | Digital Signature Generation Component | ECDSA private key and message digest | signature | ECDSA Digital Signature Generation Component, Hash_DRBG | ECDSA private key | User | W, E | NCL_STATUS_OK |
| ECDSA Digital Signature Verification | Digital Signature Verification | ECDSA public key, signature and hash algorithm | True or False | ECDSA Digital Signature Verification | ECDSA public key | User | W, E | NCL_STATUS_OK |
| ECDSA Key Generation | Asymmetric Key Pair Generation | Curve size | generated private and public keys | ECDSA Key Generation, Hash_DRBG, CKG | ECDSA Key pair | User | G, R | NCL_STATUS_OK |
| EC Diffie- Hellman Shared Secret Computation | Shared Secret Computation using Elliptic Curve Cryptography | received public key and possesse d private key | shared secret | KAS-ECC-SSC | ECDH public key | User | W, E | NCL_STATUS_OK |
| ECDH private key | E | |||||||
| shared secret | G, R | |||||||
| Key derivation | Perform key derivation | Key material | Derived key | KBKDF | Derived key | User | G, R, E | NCL_STATUS_OK |
| Random Number Generation | Deterministic Random Number Generation | number of bits | random numbers | Hash_DRBG | Entropy input string, nonce | User | W | NCL_STATUS_OK |
| seed, V, and C | G | |||||||
| Get Module Description | Outputs Module Name + Version Number | None | Module Name + Module Version Number | N/A | None | CO | N/A | N/A |
© 2024 Nuvoton Technology Corporation / atsec information security.
11 of 31
| Service | Description | Inputs | Outputs | Approved Security Functions | Keys and/or SSPs | Roles | Access rights to Keys and/or SSPs | Indicator |
|---|---|---|---|---|---|---|---|---|
| SSP Zeroisation | zeroizes crypto function context and releases memory space | handle of crypto function context | zeroized and released memory space | N/A | All Keys / SSPs | User | Z | N/A |
| Show-Status | Outputs Operational/ Error status of the module | None | Operational /Error status | N/A | None | CO | N/A | N/A |
| Self-test2 | Executes on- demand self- test and outputs Pass/Fail status | None | Pass/Fail status | HMAC-SHA2- 512 | HMAC Key | User | E | NCL_STATUS_OK |
| SHA2-256 | N/A | |||||||
| AES-CCM | AES Key | |||||||
| AES-CBC | AES Key | |||||||
| RSA PKCS#1 v1.5 Signature Generation | RSA Private Key | |||||||
| RSA PKCS#1 v1.5 Signature Verification | RSA Public Key | |||||||
| KBKDF | Key Derivati on Key, Derived Key | |||||||
| KTS-IFC (encapsulation) | RSA Key Pair, Encapsu lated key | |||||||
| ECDSA Signature Generation | ECDSA Private Key | |||||||
| ECDSA Signature Verification | ECDSA Public Key |
2Keys and SSPs used in this service are hard-coded in the module and used exclusively for self-tests. © 2024 Nuvoton Technology Corporation / atsec information security.
12 of 31
Service
Description
Inputs
Outputs
Approved Security Functions KAS-ECC-SSC Hash_DRBG
Keys and/or SSPs ECDH Key Pair, Shared Secret Seed
Roles
Access rights to Keys and/or SSPs
Indicator
Table 5 - Approved Services © 2024 Nuvoton Technology Corporation / atsec information security.
13 of 31
The module’s executable code is programmed in a masked ROM which is a type of Read-Only Memory (ROM) where content is programmed by the integrated circuit manufacturer during the silicon manufacturing (rather than by the Operator of the module). The memory technology is non reconfigurable memory as defined in IG 5.A, which will not have any change or degradation of data for a minimum of 10 years after manufactured date. As such, it is considered a hardware only module with a non-modifiable operational environment. The requirements of this area are not applicable to the module. © 2024 Nuvoton Technology Corporation / atsec information security.
14 of 31
The Nuvoton Cryptographic Library 2.3 operates in a non-modifiable operational environment. The module is programmed by the manufacturer during the silicon manufacturing (rather than by the user). It maintains its own memory region which can only be accessed by the module. There is no additional application present within the operating environment. The module does not spawn any cryptographic processes. The operational environments in which the module was tested are listed in Table 2. © 2024 Nuvoton Technology Corporation / atsec information security.
15 of 31
The Nuvoton Cryptographic Library 2.3 cryptographic module is a Hardware cryptographic module in a single-chip embodiment. More specifically, the module is considered a sub-chip cryptographic subsystem. The module consists of production-grade components that include standard passivation techniques (e.g., a conformal coating applied over the module’s circuitry to protect against environmental or other physical damage). The module does not implement a maintenance role and has no maintenance access interface. © 2024 Nuvoton Technology Corporation / atsec information security.
16 of 31
Currently, the non-invasive security is not required by FIPS 140-3 (see NIST SP 800-140F). The requirements of this area are not applicable to the module. © 2024 Nuvoton Technology Corporation / atsec information security.
17 of 31
| Key/SSP Name/ Type | Streng th | Securit y Functi on and Cert. Numb er | Generati on | Import /Export | Establishm ent | Stora ge | Zeroizati on | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| AES key | 128, 192, 256 - bits of security strength | AES CAVP Cert. #A4133 | Not Applicable. The key is entered via API parameter | Entry: The key is entered into the module within the TOEPP3 via API input parameters in plaintext. Output: N/A | N/A | Volatile memor y | automatic zeroization when structure is deallocated or when the system is powered down. | Use: AES Data Encryption and Decryption Related Keys: N/A |
| RSA private and public key | 112 to 128 bits of security strength | KTS-IFC CAVP Cert. #A4133 | Not Applicable. The key is entered via API parameter | Entry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within the TOEPP via API output parameters in plaintext | N/A | Volatile memor y | automatic zeroization when structure is deallocated or when the system is powered down. | Use: Key Encapsulati on and Un- encapsulati on Related Keys: Used to establish Encapsulat ed key |
| Encapsulat ed key | 112 to 128 bits of security strength | KTS-IFC CAVP Cert. #A4133 | N/A | Entry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within the | Established by KTS-IFC | Volatile memor y | automatic zeroization when structure is deallocated or when the system is powered down. | Use: Established by KTS-IFC Related Keys: Established using RSA private and public keys |
The following table summarizes the keys and Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module. Modification of PSPs by unauthorized operators is prohibited.
3 TOEPP - Tested Operational Environment’s Physical Perimeter
© 2024 Nuvoton Technology Corporation / atsec information security.
18 of 31
| Key/SSP Name/ Type | Streng th | Securit y Functi on and Cert. Numb er | Generati on | Import /Export TOEPP via API output parameters in plaintext | Establishm ent | Stora ge | Zeroizati on | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| RSA private and public key pair | 112 to 128 bits of security strength | RSA CAVP Cert. #A4133 | Not Applicable. The key is entered via API parameter | Entry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within the TOEPP via API output parameters in plaintext | N/A | Volatile memor y | automatic zeroization when structure is deallocated or when the system is powered down. | Use: Signature Generation and Verification Related Keys: N/A |
| ECDSA private and public key pair | 128 to 256 bits of security strength | ECDSA CAVP Cert. #A4133 | The private keys can be generated using FIPS186-4 Key Generation method, and the random value used in the key generation is generated using SP800- 90Arev1 DRBG | Entry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within the TOEPP via API output parameters in plaintext | N/A | Volatile memor y | automatic zeroization when structure is deallocated or when the system is powered down. | Use: Key Generation and Verification, Signature Generation and Verification Related Keys: Generated using DRBG internal state |
| HMAC key | 112 or greater bits of security strength | HMAC CAVP Cert. #A4133 | Not Applicable. The key is entered via API parameter | Entry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: N/A | N/A | Volatile memor y | automatic zeroization when structure is deallocated or when the system is powered down. | Use: Hashed Message Authenticati on Code Generation Related Keys: N/A |
© 2024 Nuvoton Technology Corporation / atsec information security.
19 of 31
| Key/SSP Name/ Type | Streng th | Securit y Functi on and Cert. Numb er | Generati on | Import /Export | Establishm ent | Stora ge | Zeroizati on | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| ECDH key pair (including intermedia te key generation values) | 128 to 256-bits of security strength | EC keygen CAVP Cert. #A4133 | The private keys are generated using FIPS186-4 Key Generation method, and the random value used in the key generation is generated using SP800- 90Arev1 DRBG | Entry: The public key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within the TOEPP via API output parameters in plaintext | N/A | Volatile memor y | automatic zeroization when structure is deallocated or when the system is powered down. | Use: ECDH Shared Secret Computatio n Related Keys: Generated using DRBG internal state, Used to establish EC Diffie- Hellman Shared Secret |
| ECC Shared Secret | KAS- ECC-SSC CAVP Cert. #A4133 | N/A | Entry: N/A Output: The key is output from the module within the TOEPP via API output parameters in plaintext | Established by KAS-ECC-SSC | Use: ECDH Shared Secret Computatio n Related Keys: Established from ECDH key pair | |||
| Derived key | 256, 384, 512 bits | KBKDF CAVP Cert. #A4133 | Derived by SP 800-108 KBKDF | Entry: N/A Output: The key is output from the module within the TOEPP via API output parameters in plaintext | N/A | Use: Key derivation Related Keys: Derived from Key Derivation Key | ||
| Key Derivation Key | 256, 384, 512 bits | KBKDF CAVP Cert. #A4133 | The key can be entered via API parameter s, or generated using SP800- 90Arev1 DRBG | Entry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: N/A | N/A | Use: Key derivation Related Keys: Used to derive Derived key |
© 2024 Nuvoton Technology Corporation / atsec information security.
20 of 31
| Key/SSP Name/ Type | Streng th | Securit y Functi on and Cert. Numb er | Generati on | Import /Export | Establishm ent | Stora ge | Zeroizati on | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| Entropy Input String + Nonce | 256-bits of security strength | Entropy Source ESV Cert. E94 | N/A | Entry: N/A Output: N/A | N/A | Use: Random Number Generation Related Keys: DRBG internal state, Seed | ||
| DRBG internal state (i.e., Hash_DRB G V and C values), Seed | 256-bits of security strength | Hash DRBG CAVP Cert. #A4133 | Derived from entropy input string as defined by SP800- 90Arev1 | Entry: N/A Output: N/A | N/A | Use: Random Number Generation Related Keys: Entropy Input String + Nonce |
| Entropy Source | Minimum number of bits of entropy | Details | |
|---|---|---|---|
| E94 | 256-bits strength | The module includes SP800-90B compliant entropy source based on Ring Oscillators implemented in hardware TRNG. When output is requested from the entropy source, the entropy source fills a 1024-bit buffer with random bits obtained with a single request for entropy data. All 1024-bits are then provided as output from the entropy source. |
Table 6 - SSPs The module employs a Hash_DRBG using a SHA-512 PRF. Per section 10.1.1.1 of [SP800-90A], the seeded with 1024-bits of entropy input thereby providing 256-bits of entropy during initialization values used by approved security functions, SSP generation, or SSP establishment method are Table 7 - Non-Deterministic Random Number Generation Specification The module generates Keys and SSPs in accordance with FIPS 140-3 IG D.H. The cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys as per [SP800© 2024 Nuvoton Technology Corporation / atsec information security.
21 of 31
133rev2] (vendor affirmed), compliant with [FIPS186-4] and using DRBG compliant with [SP80090Arev1]. A seed (i.e., the random value) used in asymmetric key generation is obtained from [SP800-90Arev1] DRBG as described in Section 4 of [SP800-133rev2]. The key generation service for ECDSA, as well as the [SP 800-90Arev1] DRBG have been ACVT tested with algorithm certificates found in Table 3.
The module provides the following key/SSP establishment services:
Keys/SSPs entered or output the module are electronically entered in plaintext form from the invoking User firmware running on the same device. No Keys/SSPs are entered or output from the module to outside the TOEPP. According to IG 2.3.B, Transferring SSPs including the entropy input between a sub-chip cryptographic subsystem and an intervening functional subsystem for Security Levels 1 and 2 on the same single chip is considered as not having Sensitive Security Parameter Establishment crossing the HMI of the sub-chip module per IG 9.5.A.
The module does not provide persistent storage for keys/SSPs. Keys/SSPs are stored in volatile memory only and are received for use by the module only at the request of the User firmware.
The module includes different methods for zeroization:
22 of 31
| Algorithm | Test |
|---|---|
| HMAC | HMAC-SHA2-512 MAC Generation KAT using 160-bit key |
| SHA | SHA2-256 Message Digest KAT |
| KBKDF | Counter mode using HMAC-SHA2-256 using 160-bit key |
| AES | AES-CCM Encryption KAT using 128-bit key AES-CBC Decryption KAT using 128-bit key |
| KTS-IFC | KTS-OAEP-basic Encryption KAT with 2048 -bit key and SHA2-256 KTS-OAEP-basic Decryption KAT with 2048 -bit key and SHA2-256 |
Self-tests ensure that the module is not corrupted and that the cryptographic algorithms work as expected. While the module is executing the self-test, no services are available, and input and output are inhibited. The module will boot only after successfully passing the SHA2-256, HMACSHA2-512 and KBKDF-HMAC-SHA2-256 CASTs. If an error is detected in any self-test, the module will enter the Error State.
The module is solely implemented in hardware (i.e., only contains executable code that is stored in non- reconfigurable masked ROM4). As such, the module does not perform any pre-operational software/firmware integrity test, but instead performs a Cryptographic Algorithm Self-Test on the SHA2-256, HMAC-SHA2-512 and KBKDF-HMAC-SHA2-256 algorithms when the module is powered on. The module does not implement a pre-operational bypass test nor pre-operational critical functions test.
The module performs a conditional self-test when the conditions specified for the following tests occur: Conditional Cryptographic Algorithm Self-Test Conditional Pair-Wise Consistency Test The module does not implement a Software/Firmware Load Test, Manual Entry Test, Conditional Bypass Test nor Conditional Critical Functions Test.
The module conducts conditional cryptographic algorithm self-test prior to the first operational use of each cryptographic algorithm (with the exception of KBKDF, HMAC and SHA CASTs, which are performed at power on). The table below describe the conditional tests supported by the module.
4 A masked ROM is a type of Read-Only Memory (ROM) where content is programmed by the integrated circuit
manufacturer during the silicon manufacturing. © 2024 Nuvoton Technology Corporation / atsec information security.
23 of 31
| Algorithm | Test |
|---|---|
| RSA | PKCS#1 v1.5 Signature Generation KAT with 2048 -bit key and SHA2-256 PKCS#1 v1.5 Signature Verification KAT with 2048 -bit key and SHA2-256 |
| ECDSA | ECDSA Signature Generation KAT with P-256 curve and SHA2-256 ECDSA Signature Verification KAT with P-256 curve and SHA2-256 |
| KAS-ECC-SSC | • ECDH shared secret computation KAT with P-256 curve |
| Hash_DRBG | • Hash_DRBG random number generation KAT using predefined seed. |
| ENT | • RCT (Repetition Count Test) • APT (Adaptive Proportion Test) • Startup self-tests with 1024-bit samples (Same process as the two continuous tests shown above) |
| Cause of Error | Status Indicator |
|---|---|
| failure in conditional self-test (conditional CAST or conditional PCT) | NCL_STATUS_FAIL |
The module performs a pair-wise consistency test on when a new ECDSA key pair is generated. The pair-wise consistency test is performed by calculating a digital signature and then verifying it. If the signature cannot be verified, the pair-wise consistency test will fail.
During runtime, operators can initiate the conditional self-tests on demand by calling NCL_MISC_SelfTest and passing the algorithm as an argument. The module’s entropy source is powered on only momentarily to seed the module’s SP80090Arev1 DRBG. The module performs ENT health tests defined in Section 4 of SP800-90B on the generated output prior to seeding the SP800-90Arev1 DRBG. After completing its execution, the entropy source powers down. For any of the conditional self-tests, the module enters an error state upon failing the self-test. A of the ENT health tests will result in an “ENTROPY_SRC_ERROR” status returned to the user. When in the error state, no cryptographic services are provided. The control and data output interfaces are prohibited while in the error state. The only method to clear this error state is to power cycle the device and then successfully pass the conditional self-tests. © 2024 Nuvoton Technology Corporation / atsec information security.
24 of 31
| Cause of Error | Status Indicator |
|---|---|
| failure of the ENT health test | ENTROPY_SRC_ERROR |
Table 9 - Error States © 2024 Nuvoton Technology Corporation / atsec information security.
25 of 31
As explained in Section 10.1.1, the module is placed in a masked ROM by manufacturer during the silicon manufacturing. The module is delivered as part of the Nuvoton NPCM8mnx platform (listed in Table 2). During manufacturing
The module is configured to be operational by default. If the device starts up successfully and has successfully passed the SHA2-256, HMAC-SHA2-512 and KBKDF-HMAC-SHA2-256 CASTs, it is operating correctly and can begin servicing User requests.
Once the module reaches its end-of-life stage (End of Life (EOL) date for the Nuvoton device is 10 years from manufacturing date) or sanitation is initiated by the module’s Operator, it is the Operator’s responsibility to clear all existing SSPs from the module. This can be achieved by either performing a full device reset, or by explicitly invoking the following sequence of APIs to clear the data from all modules:
The module’s AES-GCM implementation conforms to IG C.H scenario 2. The module uses the approved Hash_DRBG to generate the IV with a length of 96-bits. The entropy source producing the DRBG seed is located inside the module’s cryptographic boundary. © 2024 Nuvoton Technology Corporation / atsec information security.
26 of 31
To comply with SP800-56Brev2 assurances found in its Section 6 (specifically SP800-56Brev2 Section 6.4 Required Assurances) The entity using the IUT must obtain required assurances listed in section 6.4 of SP 800-56BRev2 by performing the following steps:
27 of 31
The module does not implement security mechanisms to mitigate other attacks. © 2024 Nuvoton Technology Corporation / atsec information security.
28 of 31
Appendix A. Glossary and Abbreviations AES Advanced Encryption Standard ACVP Algorithm Certification Validation Program CBC Cipher Block Chaining CAST Cryptographic Algorithm Self-Test CCM Counter with Cipher Block Chaining-Message Authentication Code CFB Cipher Feedback CMAC Cipher-based Message Authentication Code CMVP Cryptographic Module Validation Program CSP Critical Security Parameter CTR Counter Mode DRBG Deterministic Random Bit Generator ECB Electronic Code Book ECC Elliptic Curve Cryptography ESV Entropy Source Validation EOL End Of Life FIPS Federal Information Processing Standards Publication GCM Galois Counter Mode HMAC Hash Message Authentication Code KAS Key Agreement Scheme KAT Known Answer Test MAC Message Authentication Code NIST National Institute of Science and Technology OFB Output Feedback PSS Probabilistic Signature Scheme RSA Rivest, Shamir, Addleman SHA Secure Hash Algorithm SHS Secure Hash Standard SSC Shared Secret Computation TOEPP Tested Operational Environment’s Physical Perimeter © 2024 Nuvoton Technology Corporation / atsec information security.
29 of 31
| FIPS140-3 | FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 |
| FIPS140-3_IG | Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program November 2023 https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validation-program/documents/fips 140-3/FIPS 140-3 IG.pdf |
| FIPS180-4 | Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf |
| FIPS186-4 | Digital Signature Standard (DSS) July 2013 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf |
| FIPS197 | Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf |
| FIPS198-1 | The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf |
| PKCS#1 | Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt |
| RFC3394 | Advanced Encryption Standard (AES) Key Wrap Algorithm September 2002 http://www.ietf.org/rfc/rfc3394.txt |
| RFC5649 | Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm September 2009 http://www.ietf.org/rfc/rfc5649.txt |
| SP800-38A | NIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf |
| SP800-38B | NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf |
| SP800-38C | NIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf © 2024 Nuvoton Technology Corporation / atsec information security. 30 of 31 |
| SP800-38D | NIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf |
| SP800-38F | NIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf |
| SP800-56Arev3 | NIST Special Publication 800-56A Revision 3 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf |
| SP800-56Brev2 | Recommendation for Pair-Wise Key Establishment Schemes Using Integer Factorization Cryptography March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Br2.pdf |
| SP800-90Arev1 | NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf |
| SP800-90B | NIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf |
| SP800-133rev2 | NIST Special Publication 800-133 - Recommendation for Cryptographic Key Generation December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf |
| SP800-140B | NIST Special Publication 800-140B - CMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf © 2024 Nuvoton Technology Corporation / atsec information security. 31 of 31 |