All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Edge Security Cryptographic Module

Certificate#4963StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorUltra Intelligence and Communications
Low review priority  ·  exposes firmware-update authentication  ·  last validated 17 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date2/9/2030
CaveatNone
VendorUltra Intelligence and Communications

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Edge Security Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load<br/>Update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Edge Security Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load<br/>Update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Ultra Intelligence and Communications Edge Security Cryptographic Module

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware6
Table 3: Modes List and Description7
Table 4: Approved Algorithms9
Table 5: Vendor-Affirmed Algorithms9
Table 6: Security Function Implementations12
Table 7: Entropy Certificates14
Table 8: Entropy Sources14
Table 9: Ports and Interfaces15
Table 10: Authentication Methods17
Table 11: Roles17
Table 12: Approved Services42
Table 13: Mechanisms and Actions Required44
Table 14: Storage Areas45
Table 15: SSP Input-Output Methods46
Table 16: SSP Zeroization Methods46
Table 17: SSP Table 151
Table 18: SSP Table 256
Table 19: Pre-Operational Self-Tests56
Table 20: Conditional Self-Tests59
Table 21: Pre-Operational Periodic Information60
Table 22: Conditional Periodic Information62
Table 23: Error States62
Page 5
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication3
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level2
1.1 Overview

This is a non-proprietary cryptographic module security policy for the Ultra Intelligence & Communications Edge Security Cryptographic Module with firmware version 1.0 (hereinafter called ESM or the Module). The module is validated at the FIPS 140-3 overall level 2.

1.2 Security Levels
2.1 Description

Purpose and Use: The module primarily acts as a network boundary protection device by using IPsec VPN or VLAN encryption services. Furthermore, it employs firewall and industrial control protocol packet inspection to provide defense-in-depth capabilities to prevent malicious attacks. The module offers Web GUI management via HTTPS using TLS v1.2 or TLS v1.3. Module Type: Hardware Module Embodiment: MultiChipEmbed Module Characteristics: Cryptographic Boundary: The cryptographic boundary is defined as the entire chassis unit’s physical perimeter encompassing the "top," "front," "left," "right," “rear” and "bottom" surfaces of the case and shown in the figures below.

Page 6
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
Edge Security Model (ESM-110)1.01.0Marvell CN9130N/A

Figure 1: ESM Module Bottom J4 Connector (Ethernet Port 1) J3 Connector (Ethernet Port Figure 2: ESM Module Top

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

The exposed electronic components (C16, R45, U11, C15, R46, R47, C18, C20, C21, C22, C23, C24, C27, R39, R40, R41, R44, R54 and TP4) in Figure 2 above are either capacitors or

Page 7
Mode NameDescriptionTypeStatus Indicator
Approved ModeThe module is only operated in Approved mode of operation.ApprovedN/A
AlgorithmCAVP CertPropertiesReference
AES-CBCA3316Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA3318Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3316Key Length - 128, 192, 256SP 800-38C
AES-CCMA3318Key Length - 128, 192, 256SP 800-38C
AES-ECBA3316Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA3316Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3318Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
Counter DRBGA3316Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A3316Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA SigGen (FIPS186-4)A3316Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512, SHA3-256, SHA3-384, SHA3-512FIPS 186-4

resistors associated with the power supply circuitry. They are excluded from the physical security requirements as they are only power supply circuitry related (non-security relevant). Modes List and Description: Table 3: Modes List and Description approve mode or non-complaint state mode.

2.5 Algorithms
Page 8
AlgorithmCAVP CertPropertiesReference
ECDSA SigVer (FIPS186-4)A3316Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
HMAC-SHA-1A3316Key Length - Key Length: 128FIPS 198-1
HMAC-SHA2- 256A3316Key Length - Key Length: 128FIPS 198-1
HMAC-SHA2- 256A3318Key Length - Key Length: 128FIPS 198-1
HMAC-SHA2- 384A3316Key Length - Key Length: 192FIPS 198-1
HMAC-SHA2- 384A3318Key Length - Key Length: 192FIPS 198-1
HMAC-SHA2- 512A3316Key Length - Key Length: 256FIPS 198-1
HMAC-SHA2- 512A3318Key Length - Key Length: 256FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A3316Domain Parameter Generation Methods - P-256 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A3316Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, MODP-2048 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF IKEv2 (CVL)A3316Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 224-8192 Increment 8 Derived Keying Material Length - Derived Keying Material Length: 1024-16384 Increment 8, Derived Keying Material Length: 384-16384 Increment 8 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512SP 800-135 Rev. 1
KDF SNMP (CVL)A3316Password Length - Password Length: 64, 8192SP 800-135 Rev. 1
RSA KeyGen (FIPS186-4)A3316Key Generation Mode - B.3.3 Modulo - 2048, 3072 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A3316Signature Type - PKCS 1.5 Modulo - 2048, 3072FIPS 186-4
RSA SigVer (FIPS186-4)A3316Signature Type - PKCS 1.5 Modulo - 1024, 2048, 3072FIPS 186-4
Safe Primes Key GenerationA3316Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, MODP-2048SP 800-56A Rev. 3
Page 9
AlgorithmCAVP CertPropertiesReference
SHA-1A3316Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A3316Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A3318Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A3316Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A3318Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A3316Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A3318Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A3316Hash Algorithm - SHA2-256, SHA2-384SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A3316HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHESP 800-135 Rev. 1
NamePropertiesImplementationReference
CKGKey Type:AsymmetricUltra I&C OpenSSLThe cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys as per sections 4 and 5 in SP800-133rev2 (vendor affirmed) and FIPS 140-3 IG D.H. A seed (i.e., the random value) used in asymmetric key generation is a direct output from SP800-90Arev1 CTR_DRBG

Table 4: Approved Algorithms Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: Non-Approved, Allowed Algorithms with No Security Claimed: Non-Approved, Not Allowed Algorithms:

Page 10
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC- KeyGenKAS-KeyGenKAS-ECC keypair generationCounter DRBG
KAS-FFC- KeyGenKAS-KeyGenKAS-FFC keypair generationCounter DRBG Safe Primes Key Generation
TLS KAS (ECC)KAS-135KDFKAS with TLSv1.2 KDF or TLSv1.3 KDFBit-strength Caveat:providing between 128 and 256 bits of encryption strengthKAS-ECC- SSC Sp800- 56Ar3 TLS v1.2 KDF RFC7627 TLS v1.3 KDF
TLS-KTS (AES- GCM)KTS-WrapKTS wrap with AES- GCMBit-strength Caveat:providing between 128 and 256 bits of encryption strengthAES-GCM
TLS-KTS (AES and HMAC)KTS-WrapKTS wrap with AES and HMACBit-strength Caveat:providing between 128 and 256 bits of encryption strengthAES-CBC HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 SHA2-256 SHA2-384 SHA2-512
TLS RSA KeyGenAsymKeyPair- KeyGenRSA key genRSA KeyGen (FIPS186-4) keysize: 2048, 3072 Counter DRBG
TLS RSA SigGenDigSig- SigGenRSA SigGenRSA SigGen (FIPS186-4) Keysize: 2048, 3072
TLS RSA SigVerDigSig-SigVerRSA SigVerRSA SigVer (FIPS186-4) Keysize: 2048, 3072
IPSec/IKE KAS (ECC)KAS-135KDFKAS with IKEv2 KDFBit-strength Caveat:Providing between 128KAS-ECC- SSC Sp800-
2.6 Security Function Implementations
Page 11
NameTypeDescriptionPropertiesAlgorithms
and 256 bits of encryption strength56Ar3 KDF IKEv2
IPSec/IKE KAS (FFC)KAS-135KDFKAS with IKEv2 KDFBit-strength Caveat:Providing 112 bits of encryption strengthKAS-FFC-SSC Sp800-56Ar3 KDF IKEv2
IPSec/IKE ECDSA KeyGenAsymKeyPair- KeyGenECDSA KeyGenECDSA KeyGen (FIPS186-4) Counter DRBG
IPSec/IKE ECDSA SigGenDigSig- SigGenECDSA SigGenECDSA SigGen (FIPS186-4)
IPSec/IKE ECDSA SigVerDigSig-SigVerECDSA SigVerECDSA SigVer (FIPS186-4)
IPSec/IKE RSA KeyGenAsymKeyPair- KeyGenRSA KeyGenRSA KeyGen (FIPS186-4) Keysize: 2048, 3072 Counter DRBG
IPSec/IKE RSA SigGenDigSig- SigGenRSA SigGenRSA SigGen (FIPS186-4) Keysize: 2048, 3072
IPSec/IKE RSA SigVerDigSig-SigVerRSA SigVerRSA SigVer (FIPS186-4) keysize: 2048, 3072
IPSec Session Encrypt/DecryptBC-Auth BC-UnAuthIPSec/IKEv2 session protectionAES-CBC AES-CCM AES-GCM AES-CBC AES-CCM AES-GCM
IPSec Session AuthenticationMACIPSec Session AuthenticationHMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 SHA2-256
Page 12
NameTypeDescriptionPropertiesAlgorithms
SHA2-384 SHA2-512 SHA2-256 SHA2-384 SHA2-512
SNMP Session Encrypt/DecryptBC-UnAuthSNMPv3 Encryption/DecryptionAES-CBC
SNMP Session AuthenticationMACSNMPv3 authenticationHMAC-SHA-1
VLAN Session Encrypt/DecryptBC-Auth BC-UnAuthVLAN session encryption/decryptionAES-CBC AES-CCM AES-ECB
VLAN Session AuthenticationMACVLAN session authenticationHMAC-SHA-1 HMAC-SHA2- 256 SHA-1 SHA2-256
Firmware LoadAsymKeyPair- KeyVerFirmware load testRSA SigVer (FIPS186-4) keysize: 4096 SHA2-256
TLS Session Encrypt/DecryptBC-Auth BC-UnAuthTLSv1.2/v1.3 Encryption/DecryptionAES-CBC AES-GCM
TLS Session AuthenticationMACTLSv1.2/v1.3 session authenticationHMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 SHA2-256 SHA2-384 SHA2-512
TLS Keying Materials DevelopmentKAS-135KDFTLS session keying materials, used to derive TLS session keysTLS v1.2 KDF RFC7627 TLS v1.3 KDF
IPSec/IKE Keying Materials DevelopmentKAS-135KDFIPSec/IKE session keying materials, used to derive IPSec/IKE session keysKDF IKEv2
SNMP Keying Materials DevelopmentKAS-135KDFSNMP session keying materials, used to derive SNMP session keysKDF SNMP
DRBG FunctionDRBGDRBG generationCounter DRBG

Table 6: Security Function Implementations

Page 13
2.7 Algorithm Specific Information

There are some algorithm modes that were tested but not implemented by the module. Only the algorithms, modes, and key sizes that are implemented by the module are shown in section 2.5. Notes: • No parts of the TLS, SNMP and IKE protocols, other than the KDFs, have been tested by the CAVP and CMVP.

For TLSv1.2, the module’s AES-GCM implementation conforms to FIPS 140-3 IG C.H scenario #1 following RFC 5288 for TLS. The module is compatible with TLSv1.2 and provides support for the acceptable GCM cipher suites from SP800-52 Rev1, Section 3.3.1. The operations of one of the two parties involved in the TLS key establishment scheme were performed entirely within the cryptographic boundary of the module being validated. The counter portion of the IV is set by the module within its cryptographic boundary. When the IV exhausts the maximum number of possible values for a given session key, the first party, client or server, to encounter this condition will trigger a handshake to establish a new encryption key. The keys for the client and server negotiated in the TLSv1.2 handshake process (client_write_key and server_write_key) are compared and the module aborts the session if the key values are identical. In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption shall be established.
For TLS 1.3, the module offers the AES-GCM implementation and uses the context of Scenario #5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the ciphersuites that explicitly select AES-GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES-GCM ciphersuites from Section 3.3.1 of SP800-52rev2. The module implements, within its boundary, an IV generation unit for TLS 1.3 that keeps control of the 64-bit counter value within the AES-GCM IV. If the exhaustion condition is observed, the module will return an error indication to the calling application, who will then need to either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection.
In the event the module’s power is lost and restored, the consuming application must ensure that new AES-GCM keys encryption or decryption under this scenario are established. TLS 1.3 provides session resumption, but the resumption procedure derives new AES-GCM encryption keys.
The module uses RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AES GCM encryption keys are derived. The operations of one of the two parties involved in the IKE key establishment scheme shall be performed entirely within the cryptographic boundary of the module being validated. When the IV exhausts the maximum number of possible values for a given session key, the first party, client or server, to encounter this condition will trigger a handshake to establish a new encryption key. Two keys established by IKEv2 for one security association (one key for encryption in each direction between the parties) are not identical and abort the session if they are. In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption shall be established.
2.8 RBG and Entropy
Page 14
Cert NumberVendor Name
E109Ultra Intelligence & Communications
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Ultra I&C Edge Security Module Entropy SourcePhysicalMarvel 9130 CPU8 bits6.682SHA2-256 (A3318)

Table 7: Entropy Certificates Table 8: Entropy Sources

2.9 Key Generation

The module generates RSA, ECDSA, EC Diffie-Hellman, and Diffie-Hellman asymmetric key pairs compliant with FIPS 186-4, using a NIST SP 800-90Ar1 CTR DRBG for random number generation. In accordance with FIPS 140-3 IG D.H, the cryptographic module performs CKG for asymmetric keys as per section 5.1 of NIST SP 800-133rev2 (vendor affirmed) by obtaining a random bit string directly from an approved DRBG. The random bit string supports the required security strength requested by the calling application (without any V, as described in Additional Comments 2 of IG D.H).

2.10 Key Establishment

The module provides the following key/SSP establishment services in the approved mode of operation:

2.11 Industry Protocols

The module supports TLS 1.2/1.3, SNMPv3 and IPsec/IKEv2. The module also supports VLAN encryption. The encryption uses AES ECB/CBC with HMAC, or AES-CCM with key size of 128 or 256 bits. Please refer to SSPs Table for more information.

Page 15
Physical PortLogical Interface(s)Data That Passes
Ethernet Port 1, Ethernet Port 2Data InputData input into the module for all the services defined in Tables 8-11, including TLSv1.2, TLSv1.3, IPsec/IKEv2 and VLAN Encryption services data
Ethernet Port 1, Ethernet Port 2Data OutputData input into the module for all the services defined in Tables 8-11, including TLSv1.2, TLSv1.3, IPsec/IKEv2 and VLAN Encryption services data
Ethernet Port 1, Ethernet Port 2 and RESET PINControl InputControl data input into the module for all the services defined in Tables 8-11, including TLSv1.2, TLSv1.3, IPsec/IKEv2 and VLAN Encryption services data. RESET Pin is used to send the control signal to reset the module
Ethernet Port 1, Ethernet Port 2 and GPIO status PINStatus OutputStatus Information output from the module
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Password- based AuthenticationThe minimum length is eight (8) characters (94 possible characters). The probability that a random attempt will succeed or a false acceptance will occur is 1/(94^8) which is less than 1/1,000,000. As the module supports at most ten failed attempts to authenticate in a one- minute period, the probability of successfullyPassword BasedThe probability that a random attempt will succeed or a false acceptance will occur is 1/(94^8). Please refer to Description section in this table for more detailsThe probability of successfully authenticating to the module within one minute is 10/(94^8). Please refer to Description section in this table for more details
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 9: Ports and Interfaces

4.1 Authentication Methods
Page 16
Method NameDescription authenticating to the module within one minute is 10/(94^8), which is less than 1/100,000. This calculation is based on the assumption that the typical standard American QWERTY computer keyboard has 10 Integer digits, 52 alphabetic characters, and 32 special characters providing 94 characters to choose from in total.Security MechanismStrength Each AttemptStrength per Minute
RSA-based AuthenticationThe modules support RSA public-key based authentication mechanism using a minimum of RSA 2048 bits, which provides 112 bits of security strength. The probability that a random attempt will succeed is 1/(2^112) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one-minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112), which is less than 1/100,000.RSA SigVer (FIPS186-4) (A3316)The probability that a random attempt will succeed is 1/(2^112). Please refer to Description section in this table for more detailsthe probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112). Please refer to Description section in this table for more details
Page 17
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
ECDSA- based AuthenticationThe modules support ECDSA public-key based authentication mechanism using a minimum of curve P- 256, which provides 128 bits of security strength. The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one-minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128), which is less than 1/100,000.ECDSA SigVer (FIPS186-4) (A3316)The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. Please refer to Description section in this table for more detailsthe probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128). Please refer to Description section in this table for more details
NameTypeOperator TypeAuthentication Methods
3e-LocalIdentityCrypto OfficerPassword-based Authentication
3e-CryptoOfficerIdentityCrypto OfficerPassword-based Authentication
3e-AdministratorIdentityUserPassword-based Authentication
End UserIdentityUserRSA-based Authentication ECDSA-based Authentication
4.2 Roles
Page 18
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Create User AccountCreate User AccountsN/ACommand s to create the other role’s accountStatus of the completion of account statusNone3e-Local - 3e-Local Password: W,Z - 3e- CryptoOffic er Password: W,Z - 3e- Administrat or Password: W,Z
Configure NetworkCommand s to configure the networkN/ACommand s to configure the networkStatus of the completion of network configurati on statusNone3e-Local 3e- CryptoOffic er 3e- Administrat or

The module supports Identity-based authentication mechanism. Each entity is authenticated by the module upon initial access to the module. There are four roles supported by the module: 3eLocal (Role: Crypto Officer), 3e-CyrptoOfficer (Role: Crypto Officer), 3e-Administrator (Role: User) and End User (Role: User), as detailed below. 3e-Local: This role is defined as a Crypto Officer role and performs all security functions provided by the module. This role performs cryptographic initialization and management functions (e.g., module initialization, input/output of cryptographic keys, audit functions and Operator account management). 3e-Local Role is responsible for managing (creating, deleting) 3e-CryptoOfficer role and 3e-Administrator role. 3e-CryptoOfficer: This role is defined as a Crypto Officer role and inherits all 3e-Local privileges except the ability to create and manage users locally. 3e-Administrator: This role is defined as a User role performs general module configuration. No security management functions are available to the Administrator. The Administrator can also reboot the module if deemed necessary. The Administrator authenticates to the module using a username and password. All Administrators are identical, i.e., they have the same set of services available. End User: This role is defined as a User role and sets up VPN tunnel using IKEv2 to the module and send or receive data to and from the module. End User Role can only use the cryptographic service but cannot configure the device. The End User role is authenticated via its digital certificate and its knowledge of the corresponding private key. The module does not support concurrent operator service.

4.3 Approved Services
Page 19
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Show StatusCommand used to show Module’s StatusN/ACommand used to show Module’s StatusModule’s operational statusNone3e-Local 3e- CryptoOffic er 3e- Administrat or
Show VersionShow module’s ID and versioning informationN/ACommand to show Module's ID and versionModule’s ID and versioning informationNone3e-Local 3e- CryptoOffic er 3e- Administrat or
3e-Local Authenticat ion3e-Local role authenticat ionN/A3e-Local authenticat ion requestStatus of the 3e- Local authenticat ionNone3e-Local - 3e-Local Password: W - 3e-Local Password: Z
3e- CryptoOffic er Authenticat ion3e- CryptoOffic er role authenticat ionN/A3e- CryptoOffic er authenticat ion requestStatus of the 3e- CryptoOffic er authenticat ionNone3e- CryptoOffic er - 3e- CryptoOffic er Password: W,Z
3e- Administrat or Authenticat ion3e- Administrat or role authenticat ionN/A3e- Administrat or authenticat ion requestStatus of the 3e- Administrat or authenticat ionNone3e- Administrat or - 3e- Administrat or Password: W,Z
End User Authenticat ionEnd User role authenticat ionN/AEnd User authenticat ion requestStatus of the End User authenticat ionNoneEnd User - IPSec/IKE Pre-shared Secret: W,Z
Perform ZeroizationZeroize all SSPsN/ACommand to zeroize the moduleStatus of the SSPs zeroizationNone3e-Local - DRBG Entropy Input: Z - DRBG
Page 20
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Seed: Z - DRBG Internal State V Value: Z - DRBG Key: Z - 3e-Local Password: Z - 3e- CryptoOffic er Password: Z - 3e- Administrat or Password: Z - Firmware Load Test Key: Z - TLS ECDH Private Key: Z - TLS ECDH Public Key: Z - TLS Peer ECDH Public Key: Z - TLS ECDH Shared Secret: Z - TLS RSA Private Key: Z - TLS RSA Public Key: Z - TLS Master Secret: Z - TLS
Page 21
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Encryption Key: Z - TLS Authenticat ion Key: Z - IPsec/IKE DH Private Key: Z - IPSec/IKE DH Public Key: Z - IPSec/IKE Peer DH Public Key: Z - IPSec/IKE DH Shared Secret: Z - IPSec/IKE ECDH Private Key: Z - IPSec/IKE ECDH Public Key: Z - IPSec/IKE Peer ECDH Public Key: Z - IPSec/IKE ECDH Shared Secret: Z - IPSec/IKE ECDSA Private Key: Z - IPSec/IKE
Page 22
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
ECDSA Public Key: Z - IPSec/IKE RSA Private Key: Z - IPSec/IKE RSA Public Key: Z - IPSec/IKE Pre-shared Secret: Z - SKEYSEE D: Z - IPSec/IKE Encryption Key: Z - IPSec/IKE Authenticat ion Key: Z - SNMPv3 Shared Secret: Z - SNMPv3 Encryption Key: Z - SNMPv3 Authenticat ion Key: Z - VLAN Encryption Key: Z - VLAN Authenticat ion Key: Z 3e- CryptoOffic er - DRBG Entropy Input: Z - DRBG
Page 23
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Seed: Z - DRBG Internal State V Value: Z - DRBG Key: Z - 3e-Local Password: Z - 3e- CryptoOffic er Password: Z - 3e- Administrat or Password: Z - Firmware Load Test Key: Z - TLS ECDH Private Key: Z - TLS ECDH Public Key: Z - TLS Peer ECDH Public Key: Z - TLS ECDH Shared Secret: Z - TLS RSA Private Key: Z - TLS RSA Public Key: Z - TLS Master Secret: Z - TLS
Page 24
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Encryption Key: Z - TLS Authenticat ion Key: Z - IPsec/IKE DH Private Key: Z - IPSec/IKE DH Public Key: Z - IPSec/IKE Peer DH Public Key: Z - IPSec/IKE DH Shared Secret: Z - IPSec/IKE ECDH Private Key: Z - IPSec/IKE ECDH Public Key: Z - IPSec/IKE Peer ECDH Public Key: Z - IPSec/IKE ECDH Shared Secret: Z - IPSec/IKE ECDSA Private Key: Z - IPSec/IKE
Page 25
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
ECDSA Public Key: Z - IPSec/IKE RSA Private Key: Z - IPSec/IKE RSA Public Key: Z - IPSec/IKE Pre-shared Secret: Z - SKEYSEE D: Z - IPSec/IKE Encryption Key: Z - IPSec/IKE Authenticat ion Key: Z - SNMPv3 Shared Secret: Z - SNMPv3 Encryption Key: Z - SNMPv3 Authenticat ion Key: Z - VLAN Encryption Key: Z - VLAN Authenticat ion Key: Z
Perform Self-TestPerform self-testsSelf-Test service completio n statusCommand to trigger self-testsStatus of the self- tests resultsNone3e-Local 3e- CryptoOffic er
Firmware UpdatePerform firmware updateFirmware update serviceCommand to triggerStatus of the updatedFirmware Load3e-Local - Firmware Load Test
Page 26
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
completio n statusfirmware updatefirmware installationKey: R,E 3e- CryptoOffic er - Firmware Load Test Key: R,E
Configure TLS (v1.2/v1.3) FunctionTLS configurati on completio n statusCommand s to configure TLS (v1.2/v1.3)Status of the completion of TLS (v1.2/v1.3) configurati onKAS-ECC- KeyGen TLS KAS (ECC) TLS-KTS (AES-GCM) TLS-KTS (AES and HMAC) TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer TLS Session Encrypt/Dec rypt TLS Session Authenticati on TLS Keying Materials Developmen t DRBG Function3e-Local - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Key: W,Z - TLS ECDH Private Key: W,Z - TLS ECDH Public Key: W,Z - TLS Peer ECDH Public Key: W,Z - TLS ECDH Shared Secret: W,Z - TLS RSA Private Key: W,Z - TLS RSA Public Key: W,Z - TLS
Page 27
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Master Secret: W,Z - TLS Encryption Key: W,Z - TLS Authenticat ion Key: W,Z 3e- CryptoOffic er - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Key: W,Z - TLS ECDH Private Key: W,Z - TLS ECDH Public Key: W,Z - TLS Peer ECDH Public Key: W,Z - TLS ECDH Shared Secret: W,Z - TLS RSA Private
Page 28
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key: W,Z - TLS RSA Public Key: W,Z - TLS Master Secret: W,Z - TLS Encryption Key: W,Z - TLS Authenticat ion Key: W,Z
Configure SNMPv3 FunctionSNMPv3 configurati on completio n statusCommand s to configure SNMPv3Status of the completion of SNMPv3 configurati onSNMP Session Encrypt/Dec rypt SNMP Session Authenticati on SNMP Keying Materials Developmen t3e-Local - SNMPv3 Shared Secret: W,Z - SNMPv3 Encryption Key: W,Z - SNMPv3 Authenticat ion Key: W,Z 3e- CryptoOffic er - SNMPv3 Shared Secret: W,Z - SNMPv3 Encryption Key: W,Z - SNMPv3 Authenticat ion Key: W,Z
Configure IPsec/IKEv 2 FunctionIPsec/IKE v2 configurati on completio n statusCommand s to configure IPsec/IKEv 2Status of the completion of IPsec/IKEv 2 configurati onKAS-ECC- KeyGen KAS-FFC- KeyGen IPSec/IKE KAS (ECC) IPSec/IKE KAS (FFC)3e-Local - IPsec/IKE DH Private Key: W,Z - IPSec/IKE DH Public Key: W,Z
Page 29
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
IPSec/IKE ECDSA KeyGen IPSec/IKE ECDSA SigGen IPSec/IKE ECDSA SigVer IPSec/IKE RSA KeyGen IPSec/IKE RSA SigGen IPSec/IKE RSA SigVer IPSec Session Encrypt/Dec rypt IPSec Session Authenticati on IPSec/IKE Keying Materials Developmen t DRBG Function- IPSec/IKE Peer DH Public Key: W,Z - IPSec/IKE DH Shared Secret: W,Z - IPSec/IKE ECDH Private Key: W,Z - IPSec/IKE ECDH Public Key: W,Z - IPSec/IKE Peer ECDH Public Key: W,Z - IPSec/IKE ECDH Shared Secret: W,Z - IPSec/IKE ECDSA Private Key: W,Z - IPSec/IKE ECDSA Public Key: W,Z - IPSec/IKE RSA Private Key: W,Z - IPSec/IKE
Page 30
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
RSA Public Key: W,Z - IPSec/IKE Pre-shared Secret: W,Z - SKEYSEE D: W,Z - IPSec/IKE Encryption Key: W,Z - IPSec/IKE Authenticat ion Key: W,Z - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Key: W,Z 3e- CryptoOffic er - IPsec/IKE DH Private Key: W,Z - IPSec/IKE DH Public Key: W,Z - IPSec/IKE Peer DH Public Key: W,Z - IPSec/IKE DH Shared Secret:
Page 31
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
W,Z - IPSec/IKE ECDH Private Key: W,Z - IPSec/IKE ECDH Public Key: W,Z - IPSec/IKE Peer ECDH Public Key: W,Z - IPSec/IKE ECDH Shared Secret: W,Z - IPSec/IKE ECDSA Private Key: W,Z - IPSec/IKE ECDSA Public Key: W,Z - IPSec/IKE RSA Private Key: W,Z - IPSec/IKE RSA Public Key: W,Z - IPSec/IKE Pre-shared Secret: W,Z - SKEYSEE
Page 32
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
D: W,Z - IPSec/IKE Encryption Key: W,Z - IPSec/IKE Authenticat ion Key: W,Z - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Key: W,Z
Configure VLAN EncryptionVLAN Encryptio n configurati on completio n statusCommand s to configure VLAN EncryptionStatus of the completion of VLAN Encryption configurati onVLAN Session Encrypt/Dec rypt VLAN Session Authenticati on3e-Local - VLAN Encryption Key: W,Z - VLAN Encryption Key: W,Z 3e- CryptoOffic er - VLAN Encryption Key: W,Z - VLAN Encryption Key: W,Z
Run TLS (v1.2/v1.3) FunctionTLSv1.2/1 .3 service completio n statusInitiate TLSv1.2 tunnel establishm ent requestStatus of TLSv1.2 tunnel establishm entKAS-ECC- KeyGen TLS KAS (ECC) TLS-KTS (AES-GCM) TLS-KTS (AES and HMAC) TLS RSA KeyGen TLS RSA3e-Local - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Seed: W,Z
Page 33
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
SigGen TLS RSA SigVer TLS Session Encrypt/Dec rypt TLS Session Authenticati on TLS Keying Materials Developmen t DRBG Function- DRBG Internal State V Value: W,Z - DRBG Key: W,Z - TLS ECDH Private Key: W,Z - TLS ECDH Public Key: W,Z - TLS Peer ECDH Public Key: W,Z - TLS ECDH Shared Secret: W,Z - TLS RSA Private Key: W,Z - TLS RSA Public Key: W,Z - TLS Master Secret: W,Z - TLS Encryption Key: W,Z - TLS Authenticat ion Key: W,Z 3e- CryptoOffic er - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG
Page 34
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Internal State V Value: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Key: W,Z - TLS ECDH Private Key: W,Z - TLS ECDH Public Key: W,Z - TLS Peer ECDH Public Key: W,Z - TLS ECDH Shared Secret: W,Z - TLS RSA Private Key: W,Z - TLS RSA Public Key: W,Z - TLS Master Secret: W,Z - TLS Encryption Key: W,Z - TLS Authenticat ion Key: W,Z 3e- Administrat or - DRBG
Page 35
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Key: W,Z - TLS ECDH Private Key: W,Z - TLS ECDH Public Key: W,Z - TLS Peer ECDH Public Key: W,Z - TLS ECDH Shared Secret: W,Z - TLS RSA Private Key: W,Z - TLS RSA Public Key: W,Z - TLS Master Secret: W,Z - TLS Encryption Key: W,Z - TLS Authenticat ion Key: W,Z
Run SNMPv3 FunctionSNMPv3 serviceInitiate SNMPv3 tunnelStatus of SNMPv3 tunnelSNMP Session Encrypt/Dec3e-Local - SNMPv3 Shared
Page 36
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
completio n statusestablishm ent requestestablishm entrypt SNMP Session Authenticati on SNMP Keying Materials Developmen tSecret: W,Z - SNMPv3 Encryption Key: W,Z - SNMPv3 Authenticat ion Key: W,Z 3e- CryptoOffic er - SNMPv3 Shared Secret: W,Z - SNMPv3 Encryption Key: W,Z - SNMPv3 Authenticat ion Key: W,Z 3e- Administrat or - SNMPv3 Shared Secret: W,Z - SNMPv3 Encryption Key: W,Z - SNMPv3 Authenticat ion Key: W,Z
Run IPsec/IKEv 2 FunctionIPsec/IKE v2 service completio n statusInitiate IPsec/IKEv 2 tunnel establishm ent requestStatus of IPSec/IKE v2 tunnel establishm entKAS-ECC- KeyGen KAS-FFC- KeyGen IPSec/IKE KAS (ECC) IPSec/IKE KAS (FFC) IPSec/IKE ECDSA KeyGen IPSec/IKE3e-Local - IPsec/IKE DH Private Key: W,Z - IPSec/IKE DH Public Key: W,Z - IPSec/IKE Peer DH Public Key:
Page 37
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
ECDSA SigGen IPSec/IKE ECDSA SigVer IPSec/IKE RSA KeyGen IPSec/IKE RSA SigGen IPSec/IKE RSA SigVer IPSec Session Encrypt/Dec rypt IPSec Session Authenticati on IPSec/IKE Keying Materials Developmen t DRBG FunctionW,Z - IPSec/IKE DH Shared Secret: W,Z - IPSec/IKE ECDH Private Key: W,Z - IPSec/IKE ECDH Public Key: W,Z - IPSec/IKE Peer ECDH Public Key: W,Z - IPSec/IKE ECDH Shared Secret: W,Z - IPSec/IKE ECDSA Private Key: W,Z - IPSec/IKE ECDSA Public Key: W,Z - IPSec/IKE RSA Private Key: W,Z - IPSec/IKE RSA Public Key: W,Z - IPSec/IKE
Page 38
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Pre-shared Secret: W,Z - SKEYSEE D: W,Z - IPSec/IKE Encryption Key: W,Z - IPSec/IKE Authenticat ion Key: W,Z - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Key: W,Z 3e- CryptoOffic er - IPsec/IKE DH Private Key: W,Z - IPSec/IKE DH Public Key: W,Z - IPSec/IKE Peer DH Public Key: W,Z - IPSec/IKE DH Shared Secret: W,Z - IPSec/IKE ECDH
Page 39
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Private Key: W,Z - IPSec/IKE ECDH Public Key: W,Z - IPSec/IKE Peer ECDH Public Key: W,Z - IPSec/IKE ECDH Shared Secret: W,Z - IPSec/IKE ECDSA Private Key: W,Z - IPSec/IKE ECDSA Public Key: W,Z - IPSec/IKE RSA Private Key: W,Z - IPSec/IKE RSA Public Key: W,Z - IPSec/IKE Pre-shared Secret: W,Z - SKEYSEE D: W,Z - IPSec/IKE Encryption
Page 40
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key: W,Z - IPSec/IKE Authenticat ion Key: W,Z - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Key: W,Z 3e- Administrat or - IPsec/IKE DH Private Key: W,Z - IPSec/IKE DH Public Key: W,Z - IPSec/IKE Peer DH Public Key: W,Z - IPSec/IKE DH Shared Secret: W,Z - IPSec/IKE ECDH Private Key: W,Z - IPSec/IKE ECDH Public Key: W,Z - IPSec/IKE
Page 41
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Peer ECDH Public Key: W,Z - IPSec/IKE ECDH Shared Secret: W,Z - IPSec/IKE ECDSA Private Key: W,Z - IPSec/IKE ECDSA Public Key: W,Z - IPSec/IKE RSA Private Key: W,Z - IPSec/IKE RSA Public Key: W,Z - IPSec/IKE Pre-shared Secret: W,Z - SKEYSEE D: W,Z - IPSec/IKE Encryption Key: W,Z - IPSec/IKE Authenticat ion Key: W,Z - DRBG Entropy Input: W,Z
Page 42
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- DRBG Seed: W,Z - DRBG Internal State V Value: W,Z - DRBG Key: W,Z
Run VLAN EncryptionVLAN Encryptio n service completio n statusInitiate VLAN Encryption tunnel establishm ent requestStatus of VLAN Encryption tunnel establishm entVLAN Session Encrypt/Dec rypt VLAN Session Authenticati on3e-Local - VLAN Encryption Key: W,Z - VLAN Encryption Key: W,Z 3e- CryptoOffic er - VLAN Encryption Key: W,Z - VLAN Encryption Key: W,Z 3e- Administrat or - VLAN Encryption Key: W,Z - VLAN Encryption Key: W,Z
4.5 External Software/Firmware Loaded

The module also supports the firmware load test by using RSA 4096 bits with SHA2-256 (RSA Cert. #A3316) for the new validated firmware to be uploaded into the module. A Firmware Load Test Key was preloaded to the module’s binary at the factory and used for firmware load test. In order to load new firmware, the Crypto Officer must authenticate to the module before loading the firmware. This ensures that unauthorized access and use of the module is not performed. The module will load the new update upon reboot. The update attempt will be rejected if the verification fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation.

Page 43
MechanismInspection FrequencyInspection Guidance
Tamper Evidence Seals90 daysTamper evidence tapes should be checked for nicks and scratches that make the metal case visible through the nicked or scratched seal. Tamper Evidence Label (TEL) may show any of the following as evidence of tampering or removal: TEL is not preset in the positions prescribed (as shown above); TEL has been cut; TEL is not stuck down well, or is loose; Self- destruction of the TEL (broken bits or shreds) present as from
4.6 Additional Information

The module supports Unauthenticated service, where the unauthenticated users can run the self-test service by power-cycling the module.

5 Software/Firmware Security
5.1 Integrity Techniques

The module is provided in the form of binary executable code (Module’s binary file name?). To ensure the software security, the module is digitally signed with RSA 4096 bits with SHA2-256 (RSA Cert. #3316) during the Pre-Operational Self-Test. A Firmware Integrity Test Key (nonSSP) was preloaded to the module’s binary at the factory and used for firmware integrity test only at the pre-operational self-test. The module uses the RSA 4096 bits modulus public key to verify the digital signature. If the firmware integrity test fails, the module would enter to an Error state with all crypto functionality inhibited.

5.2 Initiate on Demand

Integrity test is performed as part of the Pre-Operational Self-Tests. It is automatically executed at power-on. The authorized operator can initiate the firmware integrity test on-demand via Web GUI’s reboot command or power cycling.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited Not Applicable as the module is operated in a limited modifiable operational environments and the physical security (section 7) is level 2. The module’s Operational Environment is limited as the module implements the firmware load service to support necessary updates.

7 Physical Security
7.1 Mechanisms and Actions Required
Page 44

Mechanism

Inspection Frequency

Inspection Guidance an attempt of removal; Tracking numbers do not match those recorded. In addition, Please note that the TELs are not orderable. Please contact support@ultra-3eti.com for more information.

Table 13: Mechanisms and Actions Required

7.2 User Placed Tamper Seals

Two tamper evidence labels (TELs) are applied at Vendor’s factory, one on each side of the Number: 2 Placement: Please refer to the TELs placement below.

Page 45
Storage Area NameDescriptionPersistence Type
RAMVolatile memoryDynamic
FlashNon-Volatile memoryStatic
Name Module Public Key Output Peer Public Key InputFrom Module External (Outside the Module’s Boundary )To External (Outside the Module’s Boundary ) ModuleFormat Type Plaintext PlaintextDistributio n Type Automated AutomatedEntry Type Electroni c Electroni cSFI or Algorith m
Password/Secre t Input encrypted by GCMExternal (Outside theModuleEncrypte dAutomatedElectroni cTLS-KTS (AES- GCM)

Surface Preparation: N/A Operator Responsible for Securing Unused Seals: N/A Part Numbers: N/A 3e-CryptoOfficer is responsible for checking the integrity of the label by following the guidance listed above. In case of notification of tamper evidence, the 3e-CryptoOfficer shall not power on this module and shall contact 3eTI for factory repair. Any deviation of the TELs placement by unauthorized operators such as tearing, misconfiguration, removal, change, replacement or any other change in the TELs from its original configuration shall mean the module is no longer in the Approved mode of operation.

8 Non-Invasive Security

The module claims no non-invasive security techniques.

9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods
Page 46
NameFrom Module’s Boundary )ToFormat TypeDistributio n TypeEntry TypeSFI or Algorith m
Password/Secre t Input encrypted by AES and HMACExternal (Outside the Module’s Boundary )ModuleEncrypte dAutomatedElectroni cTLS-KTS (AES and HMAC)
VLAN SSPs Input via TLS- KTS (GCM)External (Outside the Module’s Boundary )ModuleEncrypte dAutomatedElectroni cTLS-KTS (AES- GCM)
VLAN SSPs Input via TLS- KTS (AES and HMAC)External (Outside the Module’s Boundary )ModuleEncrypte dAutomatedElectroni cTLS-KTS (AES and HMAC)
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroization commandCO issues zeroization service: "Factory Default" to zeroize all SSPsThe zeroization command will erase all SSPs stored in the RAM or in the Flash of the module.Module Reboot
N/AZeroization requirements are not applicableSSPs used solely for self-test purposes in module's self-test need not meet zeroization requirementsN/A

m ) ) ) ) Table 15: SSP Input-Output Methods

9.3 SSP Zeroization Methods

Table 16: SSP Zeroization Methods

  1. The zeroization operations shall be performed under the control of the Crypto Officer role (3e-Local Role or 3e-CyrptoOfficer role).
  2. To initiate zeroization, see Section End of Life / Sanitization in this document for more details.
  3. The zeroized SSPs cannot be retrieved or reused. Once the command is initiated, the SSPs are overwritten with 0s.
Page 47
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
DRBG Entropy InputUsed to seed the DRBG384 bits - At least 256 bitsEntropy Inputs - CSPDRBG Function
DRBG SeedUsed DRBG generation256 bits - 256 bitsDRBG Seed - CSPDRBG Function
DRBG Internal State V ValueUsed for DRBG generation256 bits - 256 bitsDRBG Internal State V Value - CSPDRBG Function
DRBG KeyUsed for DRBG generation256 bits - 256 bitsDRBG Key - CSPDRBG Function
3e-Local PasswordUsed for 3e-Local authenticati on8-30 characte rs - N/AAuthenticati on Data - CSP
3e- CryptoOffic er PasswordUsed for 3e-Local authenticati on8-30 characte rs - N/AAuthenticati on Data - CSP
3e- Administrat or PasswordUsed for 3e- Administrat or authenticati on8-30 characte rs - N/AAuthenticati on Data - CSP
Firmware Load Test KeyUsed for firmware load test4096 bits - 152 bitsPublic Key - PSPFirmware Load
TLS ECDH Private KeyTLS ECDH private keyCurves: P-256, P-384, P-512 - 128-256 bitsPrivate Key - CSPKAS- ECC- KeyGenTLS KAS (ECC)
TLS ECDH Public KeyTLS ECDH public keyCurves: P-256, P-384, P-512 - 128-256 bitsPublic Key - PSPKAS-ECC- KeyGenTLS KAS (ECC)
TLS Peer ECDH Public KeyUsed to derive TLS ECDHCurves: P-256, P-384,Public Key - PSPTLS KAS (ECC)
Page 48
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
Shared SecretP-512 - N/A
TLS ECDH Shared SecretTLS ECDH shared secretCurves: P-256, P-384, P-512 - 128-256 bitsShared Secret - CSPTLS KAS (ECC)TLS KAS (ECC)
TLS RSA Private KeyUsed for TLS peer authenticati onModulus : 2048 or 3072 bits - 112 or 128 bitsPrivate Key - CSPTLS RSA KeyGenTLS RSA SigGen
TLS RSA Public KeyUsed for TLS peer authenticati onModulus : 2048 or 3072 bits - 112 or 128 bitsPublic Key - PSPTLS RSA KeyGenTLS RSA SigVer
TLS Master SecretUsed to derive TLS Session keys384 bits - 384 bitsTLS Master Secret - CSPTLS Keying Materials Developm entTLS Session Encrypt/Decr ypt TLS Session Authenticatio n
TLS Encryption KeyUsed to protect TLS traffic confidentiali ty.128-256 bits - 128-256 bitsEncryption Key - CSPTLS Keying Materials Developm entTLS Session Encrypt/Decr ypt
TLS Authenticati on KeyUsed to protect traffic confidentiali ty.at least 112 bits - at least 112 bitsAuthenticati on Key - CSPTLS Keying Materials Developm entTLS Session Authenticatio n
IPsec/IKE DH Private KeyUsed to derive IKE DH Shared SecretMODP- 2048 bits - 112 bitsPrivate Key - CSPKAS- FFC- KeyGenIPSec/IKE KAS (FFC)
IPSec/IKE DH Public KeyUsed to derive IKE DH Shared SecretMODP- 2048 bits - 112 bitsPublic Key - PSPKAS-FFC- KeyGenIPSec/IKE KAS (FFC)
IPSec/IKE Peer DH Public KeyUsed to derive IKEMODP- 2048 - 112 bitsPublic Key - PSPIPSec/IKE KAS (FFC)
Page 49
NameDescriptio n DH Shared SecretSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
IPSec/IKE DH Shared SecretUsed to derive IPSec/IKE Session Encryption Key and IPSec/IKE Authenticati on KeyMODP- 2048 bits - 112 bitsShared Secret - CSPIPSec/IKE KAS (FFC)IPSec/IKE KAS (FFC)
IPSec/IKE ECDH Private KeyUsed to derive IKE ECDH Shared SecretCurves: P-256, P-384, P-521 - 128-256 bitsPrivate Key - CSPKAS- ECC- KeyGenIPSec/IKE KAS (ECC)
IPSec/IKE ECDH Public KeyUsed to derive IKE ECDH Shared SecretCurves: P-256, P-384, P-512 - 128-256 bitsPublic Key - PSPKAS-ECC- KeyGenIPSec/IKE KAS (ECC)
IPSec/IKE Peer ECDH Public KeyUsed to derive IKE ECDH Shared SecretCurves: P-256, P-384, P-521 - 128-256 bitsPublic Key - PSPIPSec/IKE KAS (ECC)
IPSec/IKE ECDH Shared SecretUsed to derive IKE ECDH Session Encryption Key and IPSec/IKE Authenticati on KeyCurves: P-256, P-384, P-521 - 128-256 bitsShared Secret - CSPIPSec/IKE KAS (ECC)IPSec/IKE KAS (ECC)
IPSec/IKE ECDSA Private KeyUsed for IPSec/IKE peer authenticati onCurves: P-256, P-384, P-512 - 128-256 bitsPrivate Key - CSPIPSec/IK E ECDSA KeyGenIPSec/IKE ECDSA SigGen
IPSec/IKE ECDSA Public KeyUsed for IPSec/IKE peerCurves: P-256, P-384,Public Key - PSPKAS-ECC- KeyGenIPSec/IKE ECDSA SigVer
Page 50
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
authenticati onP-512 - 128-256 bits
IPSec/IKE RSA Private KeyUsed for IPSec/IKE peer authenticati onModulus : 2048 or 3072 bits - 112 or 128 bitsPrivate Key - CSPIPSec/IK E RSA KeyGenIPSec/IKE RSA SigGen
IPSec/IKE RSA Public KeyUsed for IPSec/IKE peer authenticati onModulus : 2048 or 3072 bits - 112 or 128 bitsPublic Key - PSPKAS-FFC- KeyGenIPSec/IKE RSA SigGen
IPSec/IKE Pre-shared SecretUsed for IPSec/IKE peer authenticati on16-32 bytes characte rs - N/AShared Secret - CSP
SKEYSEEDKeying material used to derive the IPSec/IKE Session Encryption Key and IPSec/IKE Authenticati on Key160 bits - N/AKeying Material - CSPIPSec/IKE Keying Materials Developm entIPSec Session Encrypt/Decr ypt IPSec Session Authenticatio n
IPSec/IKE Encryption KeyUsed to secure IPSec/IKEv 2 traffic confidentiali ty128-256 bits - 128-256 bitsEncryption Key - CSPIPSec/IKE Keying Materials Developm entIPSec Session Encrypt/Decr ypt
IPSec/IKE Authenticati on KeyUsed to secure IPSec/IKEv 2 traffic integrityAt least 112 bits - At least 112 bitsAuthenticati on Key - CSPIPSec/IKE Keying Materials Developm entIPSec Session Authenticatio n
SNMPv3 Shared SecretUsed for SNMPv3 User authenticati on8-32 characte rs - N/AAuthenticati on Secret - CSP
Page 51
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
SNMPv3 Encryption KeyUsed to protect SNMPv3 traffic confidentiali ty128 bits - 128 bitsEncryption Key - CSPSNMP Keying Materials Developm entSNMP Session Encrypt/Decr ypt
SNMPv3 Authenticati on KeyUsed to secure SNMPv3 traffic integrityAt least 112 bits - At least 112 bitsAuthenticati on Key - CSPSNMP Keying Materials Developm entSNMP Session Authenticatio n
VLAN Encryption KeyUsed to protect VLAN data privacy128 or 256 bits - 128 or 256 bitsEncryption Key - CSPVLAN Session Encrypt/Decr ypt
VLAN Authenticati on KeyUsed to protect VLAN data integrityAt least 112 bits - At least 112 bitsAuthenticati on Key - CSPVLAN Session Authenticatio n
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
DRBG Entropy InputRAM:PlaintextUntil RebootZeroizatio n commandDRBG Seed:Used With DRBG Internal State V Value:Used With DRBG Key:Used With
DRBG SeedRAM:PlaintextUntil RebootZeroizatio n commandDRBG Entropy Input:Used With DRBG Internal State V Value:Used With DRBG Key:Used With
DRBG Internal State V ValueRAM:PlaintextUntil RebootZeroizatio n commandDRBG Entropy Input:Used With DRBG Seed:Used With DRBG Key:Used With
DRBG KeyRAM:PlaintextUntil RebootZeroizatio n commandDRBG Entropy Input:Used With DRBG Seed:Used With
Page 52
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs DRBG Internal State V Value:Used With
3e-Local PasswordPassword/Sec ret Input encrypted by GCM Password/Sec ret Input encrypted by AES and HMACFlash:Encrypt edUntil RebootZeroizatio n command
3e- CryptoOffice r PasswordPassword/Sec ret Input encrypted by GCM Password/Sec ret Input encrypted by AES and HMACFlash:Encrypt edUntil RebootZeroizatio n command
3e- Administrato r PasswordPassword/Sec ret Input encrypted by GCM Password/Sec ret Input encrypted by AES and HMACFlash:Encrypt edUntil RebootZeroizatio n command
Firmware Load Test KeyFlash:Plaintex tUntil RebootN/A
TLS ECDH Private KeyRAM:Plaintextwhile TLS tunnel is onZeroizatio n commandTLS ECDH Public Key:Paired With TLS Peer ECDH Public Key:Used With
TLS ECDH Public KeyModule Public Key OutputRAM:Plaintextwhile TLS tunnel is onZeroizatio n commandTLS ECDH Private Key:Paired With
TLS Peer ECDH Public KeyPeer Public Key InputRAM:Plaintextwhile TLS tunnel is onZeroizatio n commandTLS ECDH Private Key:Used With
TLS ECDH Shared SecretRAM:Plaintextwhile TLS tunnel is onZeroizatio n commandTLS ECDH Private Key:Derived From TLS Peer ECDH
Page 53
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs Public Key:Derived From
TLS RSA Private KeyFlash:Plaintex twhile TLS tunnel is onZeroizatio n commandTLS RSA Public Key:Paired With TLS Peer RSA Public Key:Used With
TLS RSA Public KeyModule Public Key OutputFlash:Plaintex twhile TLS tunnel is onZeroizatio n commandTLS RSA Private Key:Paired With
TLS Master SecretRAM:Plaintextwhile TLS tunnel is onZeroizatio n commandTLS ECDH Shared Secret:Derived From
TLS Encryption KeyRAM:Plaintextwhile TLS tunnel is onZeroizatio n commandTLS Authentication Key:Used With
TLS Authenticati on KeyRAM:Plaintextwhile TLS tunnel is onZeroizatio n commandTLS Encryption Key:Used With
IPsec/IKE DH Private KeyRAM:Plaintextwhile IPSec/IKE tunnel is onZeroizatio n commandIPSec/IKE DH Public Key:Paired With
IPSec/IKE DH Public KeyModule Public Key OutputRAM:Plaintextwhile IPSec/IKE tunnel is onZeroizatio n commandIPsec/IKE DH Private Key:Paired With
IPSec/IKE Peer DH Public KeyPeer Public Key InputRAM:Plaintextwhile IPSec/IKE tunnel is onZeroizatio n commandIPsec/IKE DH Private Key:Used With
IPSec/IKE DH Shared SecretRAM:Plaintextwhile IPSec/IKE tunnel is onZeroizatio n commandSKEYSEED:Deriv e to
IPSec/IKE ECDH Private KeyRAM:Plaintextwhile IPSec/IKE tunnel is onZeroizatio n commandIPSec/IKE ECDH Public Key:Paired With IPSec/IKE Peer ECDH Public Key:Used With
IPSec/IKE ECDH Public KeyModule Public Key OutputRAM:Plaintextwhile IPSec/IKE tunnel is onZeroizatio n commandIPSec/IKE ECDH Private Key:Paired With
Page 54
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
IPSec/IKE Peer ECDH Public KeyPeer Public Key InputRAM:Plaintextwhile IPSec/IKE tunnel is onZeroizatio n commandIPSec/IKE ECDH Private Key:Used With
IPSec/IKE ECDH Shared SecretRAM:Plaintextwhile IPSec/IKE tunnel is onZeroizatio n commandSKEYSEED:Used With IPSec/IKE Encryption Key:Derived to IPSec/IKE Authentication Key:Derived to
IPSec/IKE ECDSA Private KeyFlash:Plaintex twhile IPSec/IKE tunnel is onZeroizatio n commandIPSec/IKE ECDSA Public Key:Paired With IPSec/IKE Peer ECDSA Public Key:Used With
IPSec/IKE ECDSA Public KeyModule Public Key OutputFlash:Plaintex twhile IPSec/IKE tunnel is onZeroizatio n commandIPSec/IKE ECDSA Private Key:Paired With
IPSec/IKE RSA Private KeyFlash:Plaintex twhile IPSec/IKE tunnel is onZeroizatio n commandIPSec/IKE RSA Public Key:Paired With
IPSec/IKE RSA Public KeyModule Public Key OutputFlash:Plaintex twhile IPSec/IKE tunnel is onZeroizatio n commandIPSec/IKE RSA Private Key:Paired With
IPSec/IKE Pre-shared SecretPassword/Sec ret Input encrypted by GCM Password/Sec ret Input encrypted by AES and HMACFlash:Plaintex twhile IPSec/IKE v2 tunnel is onZeroizatio n commandSKEYSEED:Deriv ed to
SKEYSEEDRAM:Plaintextwhile IPSec/IKE v2 tunnel is onZeroizatio n commandTLS ECDH Shared Secret:Derived From IPSec/IKE DH Shared Secret:Derived From
Page 55
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
IPSec/IKE Encryption KeyRAM:Plaintextwhile IPSec/IKE v2 tunnel is onZeroizatio n commandIPSec/IKE DH Shared Secret:Derived From IPSec/IKE ECDH Shared Secret:Derived From
IPSec/IKE Authenticati on KeyRAM:Plaintextwhile IPSec/IKE v2 tunnel is onZeroizatio n commandIPSec/IKE DH Shared Secret:Derived From IPSec/IKE ECDH Shared Secret:Derived From
SNMPv3 Shared SecretPassword/Sec ret Input encrypted by GCM Password/Sec ret Input encrypted by AES and HMACFlash:Plaintex twhile SNMPv3 tunnel is onZeroizatio n commandSNMPv3 Encryption Key:Derive to SNMPv3 Authentication Key:Derive to
SNMPv3 Encryption KeyRAM:Plaintextwhile SNMPv3 tunnel is onZeroizatio n commandSNMPv3 Shared Secret:Derived From SNMPv3 Authentication Key:Used With
SNMPv3 Authenticati on KeyRAM:Plaintextwhile SNMPv3 tunnel is onZeroizatio n commandSNMPv3 Shared Secret:Derived From SNMPv3 Encryption Key:Used With
VLAN Encryption KeyVLAN SSPs Input via TLS- KTS (GCM) VLAN SSPs Input via TLS- KTS (AES and HMAC)Flash:Plaintex twhile VLAN tunnel is onZeroizatio n commandVLAN Authentication Key:Used With
VLAN Authenticati on KeyVLAN SSPs Input via TLS- KTS (GCM) VLAN SSPsFlash:Plaintex twhile VLAN tunnel is onZeroizatio n commandVLAN Encryption Key:Used With
Page 56

Name

Input - Output Input via TLS- KTS (AES and HMAC)

Storage

Storage Duration

Zeroizatio n

Related SSPs

Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
RSA SigVer (FIPS186-4) (A3316)Modulus: 4096 bits with SHA2- 256KATSW/FW IntegrityModule is in normal stateModule conducts RSA SigVer KAT prior to firmware integrity test
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A3316)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateEncryptPower up
AES-CBC (A3316)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateDecryptPower up
AES-CCM (A3316)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticated EncryptionPower up
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 19: Pre-Operational Self-Tests The module also performs the following Cryptographic Algorithm Self-Tests (CASTs), which can be initiated by rebooting the module. All self-tests run without operator intervention. In the event that a self-test fails, the module will enter an error state until the issue is resolved. Upon self-test failure, the module will go into the SYS_HALT status. Entropy start-up tests per SP800-90B section 4.2 including Repetition Count Test and Adaptive Proportion Test are performed at device power-on and it will run continuously. Any entropy test failures will cause SYS_HALT.

10.2 Conditional Self-Tests
Page 57
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CCM (A3316)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticated DecryptionPower up
AES-GCM (A3316)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticated EncryptionPower up
AES-GCM (A3316)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticated DecryptionPower up
Counter DRBG (A3316)AES-256Known Answer Test (KAT)CASTModule is in normal stateCTR_DRBG InstantiatePower up
Counter DRBG (A3316)AES-256Known Answer Test (KAT)CASTModule is in normal stateCTR_DRBG GeneratePower up
Counter DRBG (A3316)AES-256Known Answer Test (KAT)CASTModule is in normal stateCTR_DRBG ReseedPower up
ECDSA SigGen (FIPS186- 4) (A3316)P-256 with SHA2-256Known Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186- 4) (A3316)P-256 with SHA2-256Known Answer Test (KAT)CASTModule is in normal stateN/APower up
KAS-ECC- SSC Sp800- 56Ar3 (A3316)P-256 with SHA2-256Known Answer Test (KAT)CASTModule is in normal stateKAS-ECC- SSC Primitive ZPower up
KAS-FFC- SSC Sp800- 56Ar3 (A3316)MODP- 2048Known Answer Test (KAT)CASTModule is in normal stateKAS-FFC- SSC Primitive ZPower up
HMAC- SHA-1 (A3316)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC- SHA2-256 (A3316)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC- SHA2-384 (A3316)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC- SHA2-512 (A3316)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
Page 58
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigGen (FIPS186- 4) (A3316)2048 bitsKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
RSA SigVer (FIPS186- 4) (A3316)2048 bitsKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA-1 (A3316)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
KDF IKEv2 (A3316)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
KDF SNMP (A3316)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
TLS v1.2 KDF RFC7627 (A3316)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
TLS v1.3 KDF (A3316)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
AES-CBC (A3318)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateEncryptionPower up
AES-CBC (A3318)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateDecryptionPower up
AES-CCM (A3318)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticated EncryptionPower up
AES-CCM (A3318)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticated DecryptionPower up
AES-GCM (A3318)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticated EncryptionPower up
AES-GCM (A3318)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticated DecryptionPower up
HMAC- SHA-1 (A3318)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC- SHA2-256 (A3318)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
Page 59
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-384 (A3318)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC- SHA2-512 (A3318)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA-1 (A3318)N/AKnown Answer Test (KAT)CASTModule is in normal stateSHA-1Power up
KAS (A3316)P-256 with SHA2-256KAS-ECC Pairwise Consistency Test (PCT)PCTModule is in normal stateN/ABefore the first operational use
KAS (A3316)MODP- 2048KAS-FFC Pairwise Consistency Test (PCT)PCTModule is in normal stateN/ABefore the first operational use
ECDSA KeyGen (FIPS186- 4) (A3316)P-256 with SHA2-256ECDSA Pairwise Consistency Test (PCT)PCTModule is in normal stateECDSABefore the first operational use
RSA KeyGen (FIPS186- 4) (A3316)2048 bitsRSA Pairwise Consistency Test (PCT)PCTModule is in normal stateRSABefore the first operational use
RSA SigVer (FIPS186- 4) (A3316)RSA 4096 bits with SHA2-256Firmware Load TestSW/FW LoadModule is in normal stateRSAwhile doing the firmware upload test

Table 20: Conditional Self-Tests The module also performs the following Entropy start-up tests per SP800-90B section 4.2 including Repetition Count Test and Adaptive Proportion Test are performed at device power-on and it will run continuously. Any entropy test failures will cause SYS_HALT.

256 (RSA Cert. #A3316) for the new validated firmware to be uploaded into the module. A

Firmware Load Test Key was preloaded to the module’s binary at the factory and used for firmware load test. In order to load new firmware, the Crypto Officer must authenticate to the

Page 60
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigVer (FIPS186-4) (A3316)KATSW/FW IntegrityRecommend every 60 daysModule Reboot
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-CBC (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-CCM (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-CCM (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-GCM (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-GCM (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
Counter DRBG (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
Counter DRBG (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
Counter DRBG (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
ECDSA SigGen (FIPS186-4) (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
ECDSA SigVer (FIPS186-4) (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
KAS-ECC-SSC Sp800-56Ar3 (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
KAS-FFC-SSC Sp800-56Ar3 (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysReModule Reboot
HMAC-SHA-1 (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
HMAC-SHA2- 256 (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot

module before loading the firmware. This ensures that unauthorized access and use of the module is not performed. The module will load the new update upon reboot. The update attempt will be rejected if the verification fails.

10.3 Periodic Self-Test Information

Table 21: Pre-Operational Periodic Information

Page 61
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 384 (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
HMAC-SHA2- 512 (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
RSA SigGen (FIPS186-4) (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
RSA SigVer (FIPS186-4) (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
SHA-1 (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
KDF IKEv2 (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
KDF SNMP (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
TLS v1.2 KDF RFC7627 (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
TLS v1.3 KDF (A3316)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-CBC (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-CBC (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-CCM (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-CCM (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-GCM (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
AES-GCM (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
HMAC-SHA-1 (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
HMAC-SHA2- 256 (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
HMAC-SHA2- 384 (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
HMAC-SHA2- 512 (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
SHA-1 (A3318)Known Answer Test (KAT)CASTRecommend every 60 daysModule Reboot
KAS (A3316)KAS-ECC Pairwise Consistency Test (PCT)PCTN/ANew KAS ECC Keypair generation
Page 62
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS (A3316)KAS-FFC Pairwise Consistency Test (PCT)PCTN/ANew KAS FFC Keypair generation
ECDSA KeyGen (FIPS186-4) (A3316)ECDSA Pairwise Consistency Test (PCT)PCTN/ANew ECDSA Keypair generation
RSA KeyGen (FIPS186-4) (A3316)RSA Pairwise Consistency Test (PCT)PCTN/ANew RSA Keypair generation
RSA SigVer (FIPS186-4) (A3316)Firmware Load TestSW/FW LoadN/AN/A
NameDescriptionConditionsRecovery MethodIndicator
Error StateIf self-test tests fail, the module is put into an error stateSelf-tests failureReboot the moduleSystem Halt

Table 22: Conditional Periodic Information The module performs on-demand self-tests initiated by the operator, by power cycling to the module. The full suite of self-tests is then executed. The same procedure may be employed by the operator to perform periodic self-tests. In addition, the Crypto Officer shall perform the periodic test on demand no less than every 90 days to ensure all components are functioning correctly.

10.4 Error States

Table 23: Error States If any of the above-mentioned self-tests fail, the module reports the cause of the error and enters the Error state. In the Error State, no cryptographic services are provided, and data output is prohibited. The only method to recover from the error state is to reboot the module and perform the self-tests, including the pre-operational firmware integrity test and the conditional CASTs. The module will only enter into the operational state after successfully passing the preoperational firmware integrity test and the conditional CASTs.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module operates in the approved mode of operation at all times. The 3e-Local shall properly configure the module following the steps listed below:

  1. Log in the module over HTTPS and change the default password (if this is the first time of use).
  2. Configure the Management VPN tunnel with proper CSPs, such as certificate, private key, trust anchor and key expiration time.
Page 63
  1. If the external authentication server is employed, please use TLS v1.2 or TLS v1.3 or IPSec/IKEv2 to protect the traffic between the authentication server and the module.
  2. Configure the Data VPN tunnel with proper SSPs, such as certificate, private key, trust anchor and key expiration time. Or configure the VLAN encryption services with VLAN tag, authentication key and encryption key.
  3. Verify that the module is in the approved mode of operation from the Web GUI. After configuration of the above items, reboot the device and the device will come back in full approved mode of operation. Security Rules: The module meets all the Level 2 requirements for FIPS 140-3. Follow the secure operations provided below to place the module in the approved mode. Operating this module without maintaining the following settings will remove the module from the approved mode of operation. The module runs firmware version 1.0. This is the only allowable firmware image (cn9130-cffips.ipsec.6.0.0.00.6.bin) for this current approved mode of operation. The 3e-Local shall load the CMVP FIPS 140-3 validated firmware only to maintain validation. The following module security rules must be followed by the operator to ensure secure operation:
  4. The 3e-Local shall not share any SSPs used by the module with any other operator or entity.
  5. The 3e-Local is responsible for inspecting the tamper evidence tapes. Other signs of tamper include wrinkles, tears and marks on or around the tape.
  6. The 3e-Local shall change the default password (default username: CryptoOfficer; default password: CryptoFIPS) when configuring the module for the first time. Please note that the module firmware enforces the password change upon the 3e-Local first log in.
  7. The 3e-Local shall login to make sure CSPs and keys are configured and applied in the module.
11.2 Administrator Guidance

No specific Administrator guidance.

11.3 Non-Administrator Guidance

No specific non-Administrator guidance.

11.6 End of Life

Crypto Officer (3e-Local Role and 3e-CyrptoOfficer role) should follow the steps below for the secure destruction of the module: Note: This process will cause the module to no longer function after it has wiped all configurations and keys.

  1. Access the module via HTTPS over TLS v1.2 or TLS v1.3
  2. Authenticate to the module as the CO by using the proper credentials
  3. Execute zeroization service: “Factory Default” a. Confirm command
Page 64

4. Module will begin zeroization process and wipe all security parameters and configurations

12 Mitigation of Other Attacks

Not Applicable as the module does not claim mitigation of other attacks.