All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Nuvoton Cryptographic Library 2.3

Certificate#4954StandardFIPS 140-3Level1TypeHardwareEmbodimentSingle ChipStatusActiveVendorNuvoton Technology Corporation
Medium review priority  ·  no TCB surface named  ·  last validated 18 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date1/27/2030
CaveatNo assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorNuvoton Technology Corporation

Approved Algorithms (25)

AlgorithmACVP Cert
AES-CBCA4133
AES-CCMA4133
AES-CFB128A4133
AES-CMACA4133
AES-CTRA4133
AES-ECBA4133
AES-GCMA4133
AES-GMACA4133
AES-OFBA4133
ECDSA KeyGen (FIPS186-4)A4133
ECDSA KeyVer (FIPS186-4)A4133
ECDSA SigGen (FIPS186-4)A4133
ECDSA SigVer (FIPS186-4)A4133
Hash DRBGA4133
HMAC-SHA2-256A4133
HMAC-SHA2-384A4133
HMAC-SHA2-512A4133
KAS-ECC-SSC Sp800-56Ar3A4133
KDF SP800-108A4133
KTS-IFCA4133
RSA SigGen (FIPS186-4)A4133
RSA SigVer (FIPS186-4)A4133
SHA2-256A4133
SHA2-384A4133
SHA2-512A4133

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Nuvoton Cryptographic Library 2.3
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Firmware Load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>status output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Nuvoton Cryptographic Library 2.3
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Firmware Load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>status output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Nuvoton Cryptographic Library 2.3 Hardware Version 2.3.8 Version 1.2 Last update: 2025-01-07 Prepared by: atsec information security corporation

9130 Jollyville Road, Suite 260

Austin, TX 78759 www.atsec.com © 2024 Nuvoton Technology Corporation / atsec information security.

Page 2
1 Table of Contents

© 2024 Nuvoton Technology Corporation / atsec information security.

2 of 31

Page 3
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware SecurityNot Applicable
6Operational Environment1
7Physical Security1
8Non-invasive SecurityNot Applicable
9Sensitive Security Parameter Management1
10Self-tests1
11Life-cycle Assurance1
12Mitigation of Other AttacksNot Applicable
Overall Level1

This document is the non-proprietary FIPS 140-3 Security Policy for Hardware version 2.3.8 of the Nuvoton Cryptographic Library 2.3. It has a one-to-one mapping to the [SP 800-140B] starting with section B.2.1 named “General” that maps to section 1 in this document and ending with section B.2.12 named “Mitigation of other attacks” that maps to section 12 in this document. This document also contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for a Security Level 1 module. Table 1 describes the individual security areas of FIPS 140-3, as well as the Security Levels of those individual areas: Table 1 - Security Levels © 2024 Nuvoton Technology Corporation / atsec information security.

3 of 31

Page 4
Model/Part Number(s)Hardware Version(s)Firmware Version(s)Processor(s)Non-Security Relevant Distinguishing Features
Nuvoton NPCM8mnx Arbel Baseboard Management Controller (BMC)2.3.8N/AARM Cortex -M4 CoreN/A
CAVP CertAlgorithm and StandardMode / MethodDescription / Key / Curve / Modulus Size(s)Use / Function
A4133AESCBCECB128, 192, 256 bitsAESEncryption and AES Decryption
[SP 800-38 A] [SP 800-38 C]CFB128CCMOFB
AES [SP 800-38 A]CTR128, 192, 256 bits
AES [SP 800-38 D]GCM128, 192, 256 bits
AESCMAC128, 192, 256 bitsCMAC Message Authentication Code
[SP 800-38 B]Generation and CMAC Message Authentication Code Verification
2 Cryptographic Module Specification

The Nuvoton Cryptographic Library 2.3 cryptographic module (hereafter referred to as “the module”) is a Hardware single-chip cryptographic module. More specifically, the module is considered a sub-chip cryptographic subsystem as defined in IG 2.3.B. The module has been tested by atsec CST lab on the following platforms: Table 2 - Cryptographic Module Tested Configuration

2.1 Mode of Operation

The module only supports approved mode of operation. There are no non-approved but allowed algorithms used in approved mode. There are no non-approved algorithms used in the approved mode with no security claimed. There are no non-approved algorithms used in a non-approved

2.2 Security Functions

The Table 3 below lists all security functions of the module, including specific key strengths employed for approved services, and implemented modes of operation. © 2024 Nuvoton Technology Corporation / atsec information security.

4 of 31

Page 5

CAVP Cert

Algorithm and Standard AES [SP 800-38 D] HMAC [FIPS 198-1] RSA [FIPS 186-4] KBKDF [SP800-108] KTS-IFC [SP800-56Brev2] ECDSA [FIPS 186-4] SHS [FIPS 180-4] KAS-ECC-SSC [SP800-56Arev3]

Mode / Method GMAC HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 RSA-PSS using SHA2-256, SHA2-384 or SHA2-512 RSA-PKCS#1 v1.5 using SHA2-256, SHA2-384 or SHA2-512 KDF Modes: Counter, Feedback, Double pipeline iteration MAC Modes: HMAC-SHA2- 256, HMAC-SHA2-384, HMAC-SHA2-512 KTS-OAEP-basic B.4.2 Testing Candidates NA SHA2-256, SHA2-384, SHA2-512 N/A SHA2-256 SHA2-384 SHA2-512 ephemeralUnified

Description / Key / Curve / Modulus Size(s) 128, 192, 256 bits 256, 384, 512 bits 2048 or 3072 modulus 256, 384, 512 bits 2048 or 3072 modulus P-256, P-384, P-521 curves P-256, P-384, P-521 curves P-256, P-384, P-521 curves P-256, P-384, P-521 curves N/A P-256, P-384, P-521 curves

Use / Function GMAC Message Authentication Code Generation and GMAC Message Authentication Code Verification HMAC Message Authentication Code Generation RSA Signature Generation, RSA Signature Verification Key Derivation Function RSA Key Transport (key wrapping and un-wrapping) ECDSA Key Generation ECDSA Key Verification ECDSA Signature Generation, ECDSA Signature Verification ECDSA Signature Generation Component Message Digest Generation EC Diffie-Hellman Shared Secret Computation (complete)

© 2024 Nuvoton Technology Corporation / atsec information security.

5 of 31

Page 6
CAVP CertAlgorithm and Standard Hash_DRBG [SP800-90A]Mode / Method SHA2-512Description / Key / Curve / Modulus Size(s) 512Use / Function Random Number Generation
VendorCKG (Cryptographic KeySP800-133rev2 SectionN/AECDSA Key Generation
AffirmedGeneration)5.1 and FIPS 186-4: direct
[SP800-133rev2]output U from approved DRBG; no XOR, no post-
[FIPS 186-4]processing
E94ESVN/AUsed to seed theRandom Number Generation
[SP800-90B]SP800-90Arev1 DRBG
2.3 Module Overview

Figure 1 depicts the module’s block diagram with a red outline indicating the Tested Operational Environment’s Physical Perimeter (TOEPP) of the NPCM8mnx and the blue dotted outline depicting the cryptographic boundary of the sub-chip embedded within the physical perimeter. Figure 1 - [Block Diagram] © 2024 Nuvoton Technology Corporation / atsec information security.

6 of 31

Page 7

Figure 2 shows a picture of the NPCM8mnx (BMC) in which the sub-chip module is embedded. Figure 2: Nuvoton NPCM8mnx © 2024 Nuvoton Technology Corporation / atsec information security.

7 of 31

Page 8
Physical InterfaceLogical Interface1Data that passes over port/interface
I/O PortsData InputData inputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers
I/O PortsData OutputData outputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers
I/O PortsControl InputControl inputs which control the operation of the module are provided through dedicated parameters.
I/O PortsStatus OutputStatus output is provided in return codes and through messages. Documentation for each API lists possible return codes. A complete list of all return codes returned by the C language APIs within the module is provided in the header files and the API documentation. Messages are documented also in the API documentation.
Power PortPower InterfacePower interface is provided internally by TEOPP in which the cryptographic module is embedded.

Table 4 - Ports and Interfaces © 2024 Nuvoton Technology Corporation / atsec information security.

8 of 31

Page 9
ServiceDescriptionInputsOutputsApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
AES EncryptionData EncryptionAES key and plain textcipher textAES-CBC AES-ECB AES-CCM AES-OFB AES-CFB128 AES-CTR AES-GCMAES keyUserW, ENCL_STATUS_OK
AES DecryptionData DecryptionAES key and cipher textplain textAES-CBC AES-ECB AES-CCM AES-OFB AES-CFB128 AES-CTR AES-GCMAES keyUserW, ENCL_STATUS_OK
CMAC Message Authenticatio n Code GenerationMessage Authentication Code GenerationAES key and message MMACAES-CMACAES keyUserW, ENCL_STATUS_OK

The module supports two authorized roles: A Crypto Officer Role and a User Role. No support is provided for a Maintenance operator. The module does not implement a bypass mode nor concurrent operators. The Crypto Officer is implicitly assumed. Crypto Officer may be used to facilitate the module's audit functions by invoking the "Get Module Description" or "Show-Status" services. The User can perform any of the other services mentioned in Table 5. The Users of the module are software applications that implicitly assume the User Role when requesting any cryptographic services provided by the module. FIPS 140-3 does not require authentication mechanism for level 1 modules. Therefore, the module does not implement an authentication mechanism. The module only implements Approved security functions in an Approved mode. Table 5 below lists services available. The module provides an approved service indicator by receiving a return code of “NCL_STATUS_OK to indicate that the service executed an approved security function. NOTE: The module does not implement any non-Approved Algorithms (neither with nor without security claim). The abbreviations of the access rights to keys and SSPs have the following interpretation: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. © 2024 Nuvoton Technology Corporation / atsec information security.

9 of 31

Page 10
ServiceDescriptionInputsOutputsApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
CMAC Message Authenticatio n Code VerificationMessage Authentication Code VerificationMAC and Message“VALID” or “INVALID”AES-CMACAES keyUserW, ENCL_STATUS_OK
GMAC Message Authenticatio n Code GenerationMessage Authentication Code GenerationAES key, AADauthenticat ion tagAES-GMACAES keyUserW, ENCL_STATUS_OK
GMAC Message Authenticatio n Code VerificationMessage Authentication Code VerificationAES key, AAD, IV, authentic ation tag“PASS” or “FAIL”AES-GMACAES keyUserW, ENCL_STATUS_OK
HMAC Message Authenticatio n Code GenerationMessage Authentication Code GenerationHMAC key and messageMACHMAC-SHA2- 256 HMAC- SHA2-384 HMAC-SHA2- 512HMAC keyUserW, ENCL_STATUS_OK
Message Digest GenerationSHS Message Digest Generationmessagedigest (hash value)SHA2-256 SHA2-384 SHA2-512noneUserN/ANCL_STATUS_OK
RSA Key Transport (encapsulatio n)Key encapsulation using KTS- OAEP-basicRSA public key and key to be encapsul atedencapsulat ed keyKTS-IFCRSA public keyUserW, ENCL_STATUS_OK
RSA Key Transport (un- encapsulation )Key Un- encapsulation using KTS- OAEP-basicRSA private key and key to be un- encapsul atedplaintext keyKTS-IFCRSA private keyUserW, ENCL_STATUS_OK
RSA Digital Signature GenerationDigital Signature GenerationRSA private key, message and hash algorithmsignatureRSA-PSS, RSA-PKCS#1 v1.5 Signature Generation, Hash_DRBGRSA private keyUserW, ENCL_STATUS_OK
RSA Digital Signature VerificationDigital Signature VerificationRSA public key, signature and hash algorithmTrue or FalseRSA-PSS, RSA-PKCS#1 v1.5 Signature VerificationRSA public keyUserW, ENCL_STATUS_OK

© 2024 Nuvoton Technology Corporation / atsec information security.

10 of 31

Page 11
ServiceDescriptionInputsOutputsApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
ECDSA Digital Signature GenerationDigital Signature GenerationECDSA private key, message and hash algorithmsignatureECDSA Digital Signature Generation, Hash_DRBGECDSA private keyUserW, ENCL_STATUS_OK
ECDSA Digital Signature Generation ComponentDigital Signature Generation ComponentECDSA private key and message digestsignatureECDSA Digital Signature Generation Component, Hash_DRBGECDSA private keyUserW, ENCL_STATUS_OK
ECDSA Digital Signature VerificationDigital Signature VerificationECDSA public key, signature and hash algorithmTrue or FalseECDSA Digital Signature VerificationECDSA public keyUserW, ENCL_STATUS_OK
ECDSA Key GenerationAsymmetric Key Pair GenerationCurve sizegenerated private and public keysECDSA Key Generation, Hash_DRBG, CKGECDSA Key pairUserG, RNCL_STATUS_OK
EC Diffie- Hellman Shared Secret ComputationShared Secret Computation using Elliptic Curve Cryptographyreceived public key and possesse d private keyshared secretKAS-ECC-SSCECDH public keyUserW, ENCL_STATUS_OK
ECDH private keyE
shared secretG, R
Key derivationPerform key derivationKey materialDerived keyKBKDFDerived keyUserG, R, ENCL_STATUS_OK
Random Number GenerationDeterministic Random Number Generationnumber of bitsrandom numbersHash_DRBGEntropy input string, nonceUserWNCL_STATUS_OK
seed, V, and CG
Get Module DescriptionOutputs Module Name + Version NumberNoneModule Name + Module Version NumberN/ANoneCON/AN/A

© 2024 Nuvoton Technology Corporation / atsec information security.

11 of 31

Page 12
ServiceDescriptionInputsOutputsApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
SSP Zeroisationzeroizes crypto function context and releases memory spacehandle of crypto function contextzeroized and released memory spaceN/AAll Keys / SSPsUserZN/A
Show-StatusOutputs Operational/ Error status of the moduleNoneOperational /Error statusN/ANoneCON/AN/A
Self-test2Executes on- demand self- test and outputs Pass/Fail statusNonePass/Fail statusHMAC-SHA2- 512HMAC KeyUserENCL_STATUS_OK
SHA2-256N/A
AES-CCMAES Key
AES-CBCAES Key
RSA PKCS#1 v1.5 Signature GenerationRSA Private Key
RSA PKCS#1 v1.5 Signature VerificationRSA Public Key
KBKDFKey Derivati on Key, Derived Key
KTS-IFC (encapsulation)RSA Key Pair, Encapsu lated key
ECDSA Signature GenerationECDSA Private Key
ECDSA Signature VerificationECDSA Public Key

2Keys and SSPs used in this service are hard-coded in the module and used exclusively for self-tests. © 2024 Nuvoton Technology Corporation / atsec information security.

12 of 31

Page 13

Service

Description

Inputs

Outputs

Approved Security Functions KAS-ECC-SSC Hash_DRBG

Keys and/or SSPs ECDH Key Pair, Shared Secret Seed

Roles

Access rights to Keys and/or SSPs

Indicator

Table 5 - Approved Services © 2024 Nuvoton Technology Corporation / atsec information security.

13 of 31

Page 14
5 Software/Firmware Security
5.1 Software/Firmware Integrity Technique

The module’s executable code is programmed in a masked ROM which is a type of Read-Only Memory (ROM) where content is programmed by the integrated circuit manufacturer during the silicon manufacturing (rather than by the Operator of the module). The memory technology is non reconfigurable memory as defined in IG 5.A, which will not have any change or degradation of data for a minimum of 10 years after manufactured date. As such, it is considered a hardware only module with a non-modifiable operational environment. The requirements of this area are not applicable to the module. © 2024 Nuvoton Technology Corporation / atsec information security.

14 of 31

Page 15
6 Operational Environment

The Nuvoton Cryptographic Library 2.3 operates in a non-modifiable operational environment. The module is programmed by the manufacturer during the silicon manufacturing (rather than by the user). It maintains its own memory region which can only be accessed by the module. There is no additional application present within the operating environment. The module does not spawn any cryptographic processes. The operational environments in which the module was tested are listed in Table 2. © 2024 Nuvoton Technology Corporation / atsec information security.

15 of 31

Page 16
7 Physical Security

The Nuvoton Cryptographic Library 2.3 cryptographic module is a Hardware cryptographic module in a single-chip embodiment. More specifically, the module is considered a sub-chip cryptographic subsystem. The module consists of production-grade components that include standard passivation techniques (e.g., a conformal coating applied over the module’s circuitry to protect against environmental or other physical damage). The module does not implement a maintenance role and has no maintenance access interface. © 2024 Nuvoton Technology Corporation / atsec information security.

16 of 31

Page 17
8 Non-invasive Security

Currently, the non-invasive security is not required by FIPS 140-3 (see NIST SP 800-140F). The requirements of this area are not applicable to the module. © 2024 Nuvoton Technology Corporation / atsec information security.

17 of 31

Page 18
Key/SSP Name/ TypeStreng thSecurit y Functi on and Cert. Numb erGenerati onImport /ExportEstablishm entStora geZeroizati onUse & related keys
AES key128, 192, 256 - bits of security strengthAES CAVP Cert. #A4133Not Applicable. The key is entered via API parameterEntry: The key is entered into the module within the TOEPP3 via API input parameters in plaintext. Output: N/AN/AVolatile memor yautomatic zeroization when structure is deallocated or when the system is powered down.Use: AES Data Encryption and Decryption Related Keys: N/A
RSA private and public key112 to 128 bits of security strengthKTS-IFC CAVP Cert. #A4133Not Applicable. The key is entered via API parameterEntry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within the TOEPP via API output parameters in plaintextN/AVolatile memor yautomatic zeroization when structure is deallocated or when the system is powered down.Use: Key Encapsulati on and Un- encapsulati on Related Keys: Used to establish Encapsulat ed key
Encapsulat ed key112 to 128 bits of security strengthKTS-IFC CAVP Cert. #A4133N/AEntry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within theEstablished by KTS-IFCVolatile memor yautomatic zeroization when structure is deallocated or when the system is powered down.Use: Established by KTS-IFC Related Keys: Established using RSA private and public keys
9 Sensitive Security Parameter Management

The following table summarizes the keys and Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module. Modification of PSPs by unauthorized operators is prohibited.

3 TOEPP - Tested Operational Environment’s Physical Perimeter

© 2024 Nuvoton Technology Corporation / atsec information security.

18 of 31

Page 19
Key/SSP Name/ TypeStreng thSecurit y Functi on and Cert. Numb erGenerati onImport /Export TOEPP via API output parameters in plaintextEstablishm entStora geZeroizati onUse & related keys
RSA private and public key pair112 to 128 bits of security strengthRSA CAVP Cert. #A4133Not Applicable. The key is entered via API parameterEntry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within the TOEPP via API output parameters in plaintextN/AVolatile memor yautomatic zeroization when structure is deallocated or when the system is powered down.Use: Signature Generation and Verification Related Keys: N/A
ECDSA private and public key pair128 to 256 bits of security strengthECDSA CAVP Cert. #A4133The private keys can be generated using FIPS186-4 Key Generation method, and the random value used in the key generation is generated using SP800- 90Arev1 DRBGEntry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within the TOEPP via API output parameters in plaintextN/AVolatile memor yautomatic zeroization when structure is deallocated or when the system is powered down.Use: Key Generation and Verification, Signature Generation and Verification Related Keys: Generated using DRBG internal state
HMAC key112 or greater bits of security strengthHMAC CAVP Cert. #A4133Not Applicable. The key is entered via API parameterEntry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: N/AN/AVolatile memor yautomatic zeroization when structure is deallocated or when the system is powered down.Use: Hashed Message Authenticati on Code Generation Related Keys: N/A

© 2024 Nuvoton Technology Corporation / atsec information security.

19 of 31

Page 20
Key/SSP Name/ TypeStreng thSecurit y Functi on and Cert. Numb erGenerati onImport /ExportEstablishm entStora geZeroizati onUse & related keys
ECDH key pair (including intermedia te key generation values)128 to 256-bits of security strengthEC keygen CAVP Cert. #A4133The private keys are generated using FIPS186-4 Key Generation method, and the random value used in the key generation is generated using SP800- 90Arev1 DRBGEntry: The public key is entered into the module within the TOEPP via API input parameters in plaintext. Output: The key is output from the module within the TOEPP via API output parameters in plaintextN/AVolatile memor yautomatic zeroization when structure is deallocated or when the system is powered down.Use: ECDH Shared Secret Computatio n Related Keys: Generated using DRBG internal state, Used to establish EC Diffie- Hellman Shared Secret
ECC Shared SecretKAS- ECC-SSC CAVP Cert. #A4133N/AEntry: N/A Output: The key is output from the module within the TOEPP via API output parameters in plaintextEstablished by KAS-ECC-SSCUse: ECDH Shared Secret Computatio n Related Keys: Established from ECDH key pair
Derived key256, 384, 512 bitsKBKDF CAVP Cert. #A4133Derived by SP 800-108 KBKDFEntry: N/A Output: The key is output from the module within the TOEPP via API output parameters in plaintextN/AUse: Key derivation Related Keys: Derived from Key Derivation Key
Key Derivation Key256, 384, 512 bitsKBKDF CAVP Cert. #A4133The key can be entered via API parameter s, or generated using SP800- 90Arev1 DRBGEntry: The key is entered into the module within the TOEPP via API input parameters in plaintext. Output: N/AN/AUse: Key derivation Related Keys: Used to derive Derived key

© 2024 Nuvoton Technology Corporation / atsec information security.

20 of 31

Page 21
Key/SSP Name/ TypeStreng thSecurit y Functi on and Cert. Numb erGenerati onImport /ExportEstablishm entStora geZeroizati onUse & related keys
Entropy Input String + Nonce256-bits of security strengthEntropy Source ESV Cert. E94N/AEntry: N/A Output: N/AN/AUse: Random Number Generation Related Keys: DRBG internal state, Seed
DRBG internal state (i.e., Hash_DRB G V and C values), Seed256-bits of security strengthHash DRBG CAVP Cert. #A4133Derived from entropy input string as defined by SP800- 90Arev1Entry: N/A Output: N/AN/AUse: Random Number Generation Related Keys: Entropy Input String + Nonce
Entropy SourceMinimum number of bits of entropyDetails
E94256-bits strengthThe module includes SP800-90B compliant entropy source based on Ring Oscillators implemented in hardware TRNG. When output is requested from the entropy source, the entropy source fills a 1024-bit buffer with random bits obtained with a single request for entropy data. All 1024-bits are then provided as output from the entropy source.

Table 6 - SSPs The module employs a Hash_DRBG using a SHA-512 PRF. Per section 10.1.1.1 of [SP800-90A], the seeded with 1024-bits of entropy input thereby providing 256-bits of entropy during initialization values used by approved security functions, SSP generation, or SSP establishment method are Table 7 - Non-Deterministic Random Number Generation Specification The module generates Keys and SSPs in accordance with FIPS 140-3 IG D.H. The cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys as per [SP800© 2024 Nuvoton Technology Corporation / atsec information security.

21 of 31

Page 22

133rev2] (vendor affirmed), compliant with [FIPS186-4] and using DRBG compliant with [SP80090Arev1]. A seed (i.e., the random value) used in asymmetric key generation is obtained from [SP800-90Arev1] DRBG as described in Section 4 of [SP800-133rev2]. The key generation service for ECDSA, as well as the [SP 800-90Arev1] DRBG have been ACVT tested with algorithm certificates found in Table 3.

9.3 Key/SSP Establishment

The module provides the following key/SSP establishment services:

  1. The module implements a key-based key derivation method compliant with SP800-108.
  2. The module implements KAS-ECC-SSC EC Diffie-Hellman Shared Secret Computation compliant to [SP800-56Arev3] and IG D.F Scenario (2) path (1). o The shared secret computation provides between 128 and 256 bits of encryption strength.
  3. Within the TOEPP, the module offers RSA key wrapping and unwrapping using KTS-OAEPbasic scheme. The implementation supports 2048 and 3072 modulus size, with both key encapsulation and un-encapsulation supported. The module does not implement key confirmation. See section 11.2 for operator guidance details. o The SSP establishment methodology provides 112 or 128 bits of encryption strength.
9.4 Key/SSP Entry and Output

Keys/SSPs entered or output the module are electronically entered in plaintext form from the invoking User firmware running on the same device. No Keys/SSPs are entered or output from the module to outside the TOEPP. According to IG 2.3.B, Transferring SSPs including the entropy input between a sub-chip cryptographic subsystem and an intervening functional subsystem for Security Levels 1 and 2 on the same single chip is considered as not having Sensitive Security Parameter Establishment crossing the HMI of the sub-chip module per IG 9.5.A.

9.5 Key/SSP Storage

The module does not provide persistent storage for keys/SSPs. Keys/SSPs are stored in volatile memory only and are received for use by the module only at the request of the User firmware.

9.6 Key/SSP Zeroization

The module includes different methods for zeroization:

22 of 31

Page 23
AlgorithmTest
HMACHMAC-SHA2-512 MAC Generation KAT using 160-bit key
SHASHA2-256 Message Digest KAT
KBKDFCounter mode using HMAC-SHA2-256 using 160-bit key
AESAES-CCM Encryption KAT using 128-bit key AES-CBC Decryption KAT using 128-bit key
KTS-IFCKTS-OAEP-basic Encryption KAT with 2048 -bit key and SHA2-256 KTS-OAEP-basic Decryption KAT with 2048 -bit key and SHA2-256
10 Self-tests

Self-tests ensure that the module is not corrupted and that the cryptographic algorithms work as expected. While the module is executing the self-test, no services are available, and input and output are inhibited. The module will boot only after successfully passing the SHA2-256, HMACSHA2-512 and KBKDF-HMAC-SHA2-256 CASTs. If an error is detected in any self-test, the module will enter the Error State.

10.1 Pre-Operational Self-Tests

The module is solely implemented in hardware (i.e., only contains executable code that is stored in non- reconfigurable masked ROM4). As such, the module does not perform any pre-operational software/firmware integrity test, but instead performs a Cryptographic Algorithm Self-Test on the SHA2-256, HMAC-SHA2-512 and KBKDF-HMAC-SHA2-256 algorithms when the module is powered on. The module does not implement a pre-operational bypass test nor pre-operational critical functions test.

10.2 Conditional Self-Tests

The module performs a conditional self-test when the conditions specified for the following tests occur: Conditional Cryptographic Algorithm Self-Test Conditional Pair-Wise Consistency Test The module does not implement a Software/Firmware Load Test, Manual Entry Test, Conditional Bypass Test nor Conditional Critical Functions Test.

10.2.1 Conditional Cryptographic Algorithm Self-Tests

The module conducts conditional cryptographic algorithm self-test prior to the first operational use of each cryptographic algorithm (with the exception of KBKDF, HMAC and SHA CASTs, which are performed at power on). The table below describe the conditional tests supported by the module.

4 A masked ROM is a type of Read-Only Memory (ROM) where content is programmed by the integrated circuit

manufacturer during the silicon manufacturing. © 2024 Nuvoton Technology Corporation / atsec information security.

23 of 31

Page 24
AlgorithmTest
RSAPKCS#1 v1.5 Signature Generation KAT with 2048 -bit key and SHA2-256 PKCS#1 v1.5 Signature Verification KAT with 2048 -bit key and SHA2-256
ECDSAECDSA Signature Generation KAT with P-256 curve and SHA2-256 ECDSA Signature Verification KAT with P-256 curve and SHA2-256
KAS-ECC-SSC• ECDH shared secret computation KAT with P-256 curve
Hash_DRBG• Hash_DRBG random number generation KAT using predefined seed.
ENT• RCT (Repetition Count Test) • APT (Adaptive Proportion Test) • Startup self-tests with 1024-bit samples (Same process as the two continuous tests shown above)
Cause of ErrorStatus Indicator
failure in conditional self-test (conditional CAST or conditional PCT)NCL_STATUS_FAIL
10.2.2 Conditional Pair-Wise Consistency Test

The module performs a pair-wise consistency test on when a new ECDSA key pair is generated. The pair-wise consistency test is performed by calculating a digital signature and then verifying it. If the signature cannot be verified, the pair-wise consistency test will fail.

10.2.3 Periodic Self-Test

During runtime, operators can initiate the conditional self-tests on demand by calling NCL_MISC_SelfTest and passing the algorithm as an argument. The module’s entropy source is powered on only momentarily to seed the module’s SP80090Arev1 DRBG. The module performs ENT health tests defined in Section 4 of SP800-90B on the generated output prior to seeding the SP800-90Arev1 DRBG. After completing its execution, the entropy source powers down. For any of the conditional self-tests, the module enters an error state upon failing the self-test. A of the ENT health tests will result in an “ENTROPY_SRC_ERROR” status returned to the user. When in the error state, no cryptographic services are provided. The control and data output interfaces are prohibited while in the error state. The only method to clear this error state is to power cycle the device and then successfully pass the conditional self-tests. © 2024 Nuvoton Technology Corporation / atsec information security.

24 of 31

Page 25
Cause of ErrorStatus Indicator
failure of the ENT health testENTROPY_SRC_ERROR

Table 9 - Error States © 2024 Nuvoton Technology Corporation / atsec information security.

25 of 31

Page 26
11 Life-cycle assurance
11.1 Delivery and Operation

As explained in Section 10.1.1, the module is placed in a masked ROM by manufacturer during the silicon manufacturing. The module is delivered as part of the Nuvoton NPCM8mnx platform (listed in Table 2). During manufacturing

11.2 Crypto Officer Guidance
11.2.1 Configuration

The module is configured to be operational by default. If the device starts up successfully and has successfully passed the SHA2-256, HMAC-SHA2-512 and KBKDF-HMAC-SHA2-256 CASTs, it is operating correctly and can begin servicing User requests.

11.2.2 End of Life

Once the module reaches its end-of-life stage (End of Life (EOL) date for the Nuvoton device is 10 years from manufacturing date) or sanitation is initiated by the module’s Operator, it is the Operator’s responsibility to clear all existing SSPs from the module. This can be achieved by either performing a full device reset, or by explicitly invoking the following sequence of APIs to clear the data from all modules:

11.2.3 AES-GCM

The module’s AES-GCM implementation conforms to IG C.H scenario 2. The module uses the approved Hash_DRBG to generate the IV with a length of 96-bits. The entropy source producing the DRBG seed is located inside the module’s cryptographic boundary. © 2024 Nuvoton Technology Corporation / atsec information security.

26 of 31

Page 27
11.2.4 RSA Key Wrapping

To comply with SP800-56Brev2 assurances found in its Section 6 (specifically SP800-56Brev2 Section 6.4 Required Assurances) The entity using the IUT must obtain required assurances listed in section 6.4 of SP 800-56BRev2 by performing the following steps:

  1. The entity requesting the RSA key unwrapping (un-encapsulation) service from the module, shall only use an RSA private key that was generated by an active FIPS validated module that implements FIPS 186-4 compliant RSA key generation service and performs the key pair validity and the pairwise consistency as stated in section 6.4.1.1 of the SP 80056BRev2. Additionally, the entity shall renew these assurances over time by using any method described in section 6.4.1.5 of the SP 800-56BRev2.
  2. For use of an RSA key wrapping (encapsulation) service in the context of key transport per IG D.G, the entity using the module, shall verify the validity of the peer's public key using any method specified in section 6.4.2.1 of the SP 800-56BRev2.
  3. The entity using the module, shall confirm the peer's possession of private key by using any method specified in section 6.4.2.3 of the SP 800-56BRev2. © 2024 Nuvoton Technology Corporation / atsec information security.

27 of 31

Page 28
12 Mitigation of other attacks

The module does not implement security mechanisms to mitigate other attacks. © 2024 Nuvoton Technology Corporation / atsec information security.

28 of 31

Page 29
Table, extracted as text (did not parse into structured rows)
Appendix A. Glossary and Abbreviations AES                 Advanced Encryption Standard ACVP                Algorithm Certification Validation Program CBC                 Cipher Block Chaining CAST                Cryptographic Algorithm Self-Test CCM                 Counter with Cipher Block Chaining-Message Authentication Code CFB                 Cipher Feedback CMAC                Cipher-based Message Authentication Code CMVP                Cryptographic Module Validation Program CSP                 Critical Security Parameter CTR                 Counter Mode DRBG                Deterministic Random Bit Generator ECB                 Electronic Code Book ECC                 Elliptic Curve Cryptography ESV                 Entropy Source Validation EOL                 End Of Life FIPS                Federal Information Processing Standards Publication GCM                 Galois Counter Mode HMAC                Hash Message Authentication Code KAS                 Key Agreement Scheme KAT                 Known Answer Test MAC                 Message Authentication Code NIST                National Institute of Science and Technology OFB                 Output Feedback PSS                 Probabilistic Signature Scheme RSA                 Rivest, Shamir, Addleman SHA                 Secure Hash Algorithm SHS                 Secure Hash Standard SSC                 Shared Secret Computation TOEPP               Tested Operational Environment’s Physical Perimeter © 2024 Nuvoton Technology Corporation / atsec information security.

29 of 31

Page 30
FIPS140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3
FIPS140-3_IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program November 2023 https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validation-program/documents/fips 140-3/FIPS 140-3 IG.pdf
FIPS180-4Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS186-4Digital Signature Standard (DSS) July 2013 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS197Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt
RFC3394Advanced Encryption Standard (AES) Key Wrap Algorithm September 2002 http://www.ietf.org/rfc/rfc3394.txt
RFC5649Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm September 2009 http://www.ietf.org/rfc/rfc5649.txt
SP800-38ANIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP800-38BNIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP800-38CNIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf © 2024 Nuvoton Technology Corporation / atsec information security. 30 of 31
Page 31
SP800-38DNIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP800-38FNIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP800-56Arev3NIST Special Publication 800-56A Revision 3 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf
SP800-56Brev2Recommendation for Pair-Wise Key Establishment Schemes Using Integer Factorization Cryptography March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Br2.pdf
SP800-90Arev1NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP800-90BNIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP800-133rev2NIST Special Publication 800-133 - Recommendation for Cryptographic Key Generation December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP800-140BNIST Special Publication 800-140B - CMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf © 2024 Nuvoton Technology Corporation / atsec information security. 31 of 31