All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Amazon Linux 2023 Libgcrypt Cryptographic Module

Certificate#4971StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorAmazon Web Services, Inc.
Low review priority  ·  no TCB surface named  ·  libgcrypt upstream has published 2 CVEs since this module's initial validation  ·  last validated 17 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date2/23/2030
CaveatWhen operated in approved mode and installed, initialized and configured as specified in Section 11 of the Security Policy.
VendorAmazon Web Services, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Amazon Linux 2023 Libgcrypt Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Amazon Linux 2023 Libgcrypt Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Amazon Web Services, Inc. Amazon Linux 2023 Libgcrypt Cryptographic Module Document Version 1.2 Last update: 2025-02-05 Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Page 2

www.atsec.com © 2025 Amazon Web Services, Inc./atsec information security.

Page 3
Table of Contents
#SectionPage
Page 4

© 2025 Amazon Web Services, Inc./atsec information security.

Page 5

© 2025 Amazon Web Services, Inc./atsec information security.

Page 6
List of Tables
ItemPage
Table : Security Levels8
Table : Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)11
Table : Tested Operational Environments - Software, Firmware, Hybrid11
Table : Modes List and Description12
Table : Approved Algorithms27
Table : Vendor-Affirmed Algorithms28
Table : Non-Approved, Not Allowed Algorithms29
Table : Security Function Implementations37
Table : Entropy Certificates38
Table : Entropy Sources38
Table : Ports and Interfaces40
Table : Roles41
Table : Approved Services47
Table : Non-Approved Services49
Table : Storage Areas54
Table : SSP Input-Output Methods54
Table : SSP Zeroization Methods55
Table : SSP Table 158
Table : SSP Table 259
Table : Pre-Operational Self-Tests61
Table : Conditional Self-Tests80
Table : Pre-Operational Periodic Information81
Table : Conditional Periodic Information89
Table : Error States89
Page 7
List of Figures
ItemPage
Figure 1: Block Diagram8
Page 8
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 1.10.2- 752a14d13e4ce9c0 of the Amazon Linux 2023 Libgcrypt Cryptographic Module. It has a one-to- one mapping to the SP 800-140Brev1 starting with Section B.2.1 named “General” that maps to Section 1 General in this document and ending with Section B.2.12 named “Mitigation of other attacks” that maps to Section 12 Mitigation of Other Attacks in this document.

1.2 Security Levels

Table 1: Security Levels © 2025 Amazon Web Services, Inc./atsec information security.

Page 9
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Amazon Linux 2023 Libgcrypt Cryptographic Module (hereafter referred to as “the module”) is a Software multi-chip standalone cryptographic module. The module is a software library implementing general purpose cryptographic algorithms. The module provides cryptographic services to applications running in the user space of the underlying operating system through an application program interface (API). Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The module is implemented as shared library / binary file; as shown in the diagram below, the shared library file constitutes the cryptographic boundary. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed on. © 2025 Amazon Web Services, Inc./atsec information security.

Page 10
Software/ Firmware
Package or File NameVersionFeaturesIntegrity Test
libgcrypt.so.20.4.2 on Amazon Linux 2023 with AWS Graviton31.10.2-e4ddf5ed7abe8d45N/AHMAC-SHA-256
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 11
Software/ Firmware
Package or File NameVersionFeaturesIntegrity Test
libgcrypt.so.20.4.2 on Amazon Linux 2023 with Intel Xeon Platinum 8375C1.10.2-e4ddf5ed7abe8d45N/AHMAC-SHA-256
libgcrypt.so.20.4.2 on SnowOS 1.0 with AMD EPYC 77021.10.2-e4ddf5ed7abe8d45N/AHMAC-SHA-256
HardwareHypervisor
Operating SystemProcessorsPAA/PAIVersion(s)
Platformor Host OS
Amazon Linux 2023EC2 c7g.metalAWS Graviton3YesN/A1.10.2- e4ddf5ed7abe8d45
Amazon Linux 2023EC2 c6i.metalIntel Xeon Platinum 8375CYesN/A1.10.2- e4ddf5ed7abe8d45
SnowOS 1.0AWS SnowballAMD EPYC 7702YesN/A1.10.2- e4ddf5ed7abe8d45

Table 2: Tested Module Identification

2.3 Excluded Components

There are no components excluded from the module. © 2025 Amazon Web Services, Inc./atsec information security.

Page 12
Mode NameDescriptionTypeStatus Indicator
Approved ModeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service
Non-approved modeAutomatically entered whenever a non- approved service is requestedNon- ApprovedEquivalent to the indicator of the requested service
CAVP
AlgorithmCertPropertiesReference
AES-CBCA4597Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4598Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4600Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4601Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
2.4 Modes of Operation

Modes List and Description: Table 4: Modes List and Description Mode Change Instructions and Status: When the module starts up successfully, after passing the pre-operational self-test and cryptographic algorithms self-tests, the module is operating in the approved mode of operation by default and can only be transitioned into the non-approved mode by calling one of the non-approved services listed in the table above. Refer to Section 4 Roles, Services, and Authentication for details on the service indicators provided by the module that identify when an approved service is called. The module does not implement a degraded mode of operation.

2.5 Algorithms

Approved Algorithms: © 2025 Amazon Web Services, Inc./atsec information security.

Page 13
CAVP
AlgorithmCertPropertiesReference
AES-CCMA4597Key Length - 128, 192, 256SP 800-38C
AES-CCMA4598Key Length - 128, 192, 256SP 800-38C
AES-CCMA4600Key Length - 128, 192, 256SP 800-38C
AES-CCMA4601Key Length - 128, 192, 256SP 800-38C
AES-CFB128A4597Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A4598Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A4600Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A4601Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4597Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4598Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4600Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4601Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA4597Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CMACA4598Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CMACA4600Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B

© 2025 Amazon Web Services, Inc./atsec information security.

Page 14
CAVP
AlgorithmCertPropertiesReference
AES-CMACA4601Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA4597Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA4598Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA4600Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA4601Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4597Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4598Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4600Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4601Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA4597Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWA4598Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWA4600Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWA4601Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA4597Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

© 2025 Amazon Web Services, Inc./atsec information security.

Page 15
CAVP
AlgorithmCertPropertiesReference
AES-OFBA4598Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-OFBA4600Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-OFBA4601Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A4597Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-XTS Testing Revision 2.0A4598Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-XTS Testing Revision 2.0A4600Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-XTS Testing Revision 2.0A4601Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA4597Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA4598Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA4600Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA4601Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A4597Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4

© 2025 Amazon Web Services, Inc./atsec information security.

Page 16
CAVP
AlgorithmCertPropertiesReference
ECDSA KeyGen (FIPS186-4)A4598Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A4600Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A4601Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A4602Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A4597Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4598Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4600Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4601Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4602Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4597Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
ECDSA SigGen (FIPS186-4)A4598Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
ECDSA SigGen (FIPS186-4)A4600Component - No Curve - P-224, P-256, P-384, P-521FIPS 186-4

© 2025 Amazon Web Services, Inc./atsec information security.

Page 17
CAVP
AlgorithmCertProperties Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512Reference
ECDSA SigGen (FIPS186-4)A4601Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
ECDSA SigGen (FIPS186-4)A4602Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4597Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4598Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4600Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4601Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4

© 2025 Amazon Web Services, Inc./atsec information security.

Page 18
CAVP
AlgorithmCertPropertiesReference
ECDSA SigVer (FIPS186-4)A4602Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
Hash DRBGA4597Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA4598Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA4600Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA4601Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA4602Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA4597Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA4598Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA4600Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA4601Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA4602Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC-SHA-1A4596Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

© 2025 Amazon Web Services, Inc./atsec information security.

Page 19
CAVP
AlgorithmCertPropertiesReference
HMAC-SHA-1A4599Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4600Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4601Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4600Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4601Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4600Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4601Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4600Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4601Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

© 2025 Amazon Web Services, Inc./atsec information security.

Page 20
CAVP
AlgorithmCertPropertiesReference
HMAC-SHA2-512A4600Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4601Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4600Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4601Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4600Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4601Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

© 2025 Amazon Web Services, Inc./atsec information security.

Page 21
CAVP
AlgorithmCertPropertiesReference
HMAC-SHA3-256A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A4597Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A4598Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A4602Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
PBKDFA4597Iteration Count - Iteration Count: 1000-10000000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
PBKDFA4598Iteration Count - Iteration Count: 1000-10000000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
PBKDFA4600Iteration Count - Iteration Count: 1000-10000000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
PBKDFA4601Iteration Count - Iteration Count: 1000-10000000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
PBKDFA4602Iteration Count - Iteration Count: 1000-10000000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A4597Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA KeyGen (FIPS186-4)A4598Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096FIPS 186-4

© 2025 Amazon Web Services, Inc./atsec information security.

Page 22
CAVP
AlgorithmCertProperties Primality Tests - Table C.2 Private Key Format - StandardReference
RSA KeyGen (FIPS186-4)A4600Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA KeyGen (FIPS186-4)A4601Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA KeyGen (FIPS186-4)A4602Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4597Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigGen (FIPS186-4)A4598Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigGen (FIPS186-4)A4600Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigGen (FIPS186-4)A4601Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigGen (FIPS186-4)A4602Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-2)A4597Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536FIPS 186-4
RSA SigVer (FIPS186-2)A4598Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536FIPS 186-4
RSA SigVer (FIPS186-2)A4600Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536FIPS 186-4

© 2025 Amazon Web Services, Inc./atsec information security.

Page 23
CAVP
AlgorithmCertPropertiesReference
RSA SigVer (FIPS186-2)A4601Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536FIPS 186-4
RSA SigVer (FIPS186-2)A4602Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536FIPS 186-4
RSA SigVer (FIPS186-4)A4597Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4598Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4600Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4601Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4602Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
SHA-1A4596Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4599Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4600Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4601Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4

© 2025 Amazon Web Services, Inc./atsec information security.

Page 24
CAVP
AlgorithmCertPropertiesReference
SHA2-224A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4600Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4601Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4600Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4601Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4600Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4601Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4

© 2025 Amazon Web Services, Inc./atsec information security.

Page 25
CAVP
AlgorithmCertPropertiesReference
SHA2-384A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4600Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4601Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4600Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4601Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4600Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4

© 2025 Amazon Web Services, Inc./atsec information security.

Page 26
CAVP
AlgorithmCertPropertiesReference
SHA2-512/256A4601Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA3-224A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-224A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-224A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A4597Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A4598Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A4602Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202

© 2025 Amazon Web Services, Inc./atsec information security.

Page 27
CAVP
AlgorithmCertPropertiesReference
SHAKE-128A4597Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-128A4598Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-128A4602Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A4597Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A4598Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A4602Output Length - Output Length: 16-65536 Increment 8FIPS 202
NamePropertiesImplementationReference
CKGCapabilities:Key generation RSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)Amazon Linux 2023 Libgcrypt Cryptographic Module (Full Acceleration)FIPS 186-4, SP 800- 133rev2 Section 5.1
CKGCapabilities:Key generation RSA:2048, 3072, 4096 (112, 128, 192 bits) ECDSA:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)Amazon Linux 2023 Libgcrypt Cryptographic Module (No Acceleration)FIPS 186-4, SP 800- 133rev2 Section 5.1
CKGCapabilities:Key generation RSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)Amazon Linux 2023 Libgcrypt Cryptographic Module (AESNI AVX)FIPS 186-4, SP 800- 133rev2 Section 5.1
CKGCapabilities:Key generation RSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)Amazon Linux 2023 Libgcrypt Cryptographic Module (SSSE3)FIPS 186-4, SP 800- 133rev2 Section 5.1

Table 5: Approved Algorithms Vendor-Affirmed Algorithms: © 2025 Amazon Web Services, Inc./atsec information security.

Page 28
NamePropertiesImplementationReference
CKGCapabilities:Key generation RSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)Amazon Linux 2023 Libgcrypt Cryptographic Module (SHLD)FIPS 186-4, SP 800- 133rev2 Section 5.1
NameUse and Function
MD5Message Digest
ECDHShared Secret Computation
AES-GCM, AES-GCM-SIV, AES- OCB, AES-EAXSymmetric encryption; Symmetric decryption
RSASignature generation primitives; Signature verification primitives; Encryption primitives; Decryption primitives
RSA with non-approved public key flagsKey generation; Signature generation; Signature verification
ECDSASignature generation primitives; Signature verification primitives
ECDSA with non-approved public key flagsKey generation; Signature generation; Signature verification

Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. The module does not implement non-approved algorithms that are allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. The module does not implement non-approved algorithms that are allowed in the approved mode of operation with no security claimed. Non-Approved, Not Allowed Algorithms: © 2025 Amazon Web Services, Inc./atsec information security.

Page 29
NameTypeDescriptionPropertiesAlgorithms
Key wrapping using AES CCMKTS-WrapKey wrapping using AES CCMKey:128, 192, 256 bits keys with 128, 192, 256 bits of key strength, respectivelyAES-CCM AES-CCM AES-CCM AES-CCM
Key unwrapping using AES CCMKTS-WrapKey unwrapping using AES CCMKey:128, 192, 256 bits keys with 128, 192, 256 bits of key strength, respectivelyAES-CCM AES-CCM AES-CCM AES-CCM
Key wrapping using AES KWKTS-WrapKey wrapping using AES KWKey:128, 192, 256 bits keys with 128, 192, 256 bits of key strength, respectivelyAES-KW AES-KW AES-KW AES-KW
Key unwrapping using AES KWKTS-WrapKey wrapping using AES KWKey:128, 192, 256 bits keys with 128, 192, 256 bits of key strength, respectivelyAES-KW AES-KW AES-KW AES-KW
Encryption with AESBC-UnAuthEncryption using AESXTS mode key sizes and strength:128, 256 bits keys with 128, 256 bits of key strength, respectively Other modes key sizes and strength:128, 192, 256 bits keys with 128, 192, 256 bits of key strength, respectivelyAES-CBC AES-CBC AES-CBC AES-CBC AES-OFB AES-OFB AES-OFB AES-OFB AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CTR

Table 7: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© 2025 Amazon Web Services, Inc./atsec information security.

Page 30
NameTypeDescriptionPropertiesAlgorithms AES-CTR AES-CTR AES-CTR AES-ECB AES-ECB AES-ECB AES-ECB AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0
Authenticated encryption with AESBC-AuthAuthenticated encryption using AESKey:128, 192, 256 bits keys with 128, 192, 256 bits of key strength, respectivelyAES-CCM AES-CCM AES-CCM AES-CCM AES-KW AES-KW AES-KW AES-KW
Decryption with AESBC-UnAuthDecryption using AESXTS mode key sizes and strength:128, 256 bits keys with 128, 256 bits of key strength, respectively Other modes key sizes and strength:128, 192, 256 bits keys with 128, 192, 256 bits of key strength, respectivelyAES-CBC AES-CBC AES-CBC AES-CBC AES-OFB AES-OFB AES-OFB AES-OFB AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CTR

© 2025 Amazon Web Services, Inc./atsec information security.

Page 31
NameTypeDescriptionPropertiesAlgorithms AES-CTR AES-CTR AES-CTR AES-ECB AES-ECB AES-ECB AES-ECB AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0
Authenticated decryption with AESBC-AuthAuthenticated decryption using AESKey:128, 192, 256 bits keys with 128, 192, 256 bits of key strength, respectivelyAES-CCM AES-CCM AES-CCM AES-CCM AES-KW AES-KW AES-KW AES-KW
Key Pair Generation with RSAAsymKeyPair- KeyGenKey pair generation for RSAMode:B.3.3. Random Probable Primes Modulus:2048, 3072, 4096 (112, 128, 149 bits)RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4)
Key Pair Generation with ECDSAAsymKeyPair- KeyGenKey pair generation for ECDSAMode:B.4.2 Testing Candidates Curves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4)

© 2025 Amazon Web Services, Inc./atsec information security.

Page 32
NameTypeDescriptionPropertiesAlgorithms ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4)
Public Key Verification with ECDSAAsymKeyPair- KeyVerVerify public key for ECDSACurves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4)
Signature Generation with RSADigSig-SigGenDigital signature generation using RSAPadding:PKCS#1 v1.5, PSS Keys:2048, 3072, 4096 bits (112, 128, 149 bits) Hashes:SHA-224, SHA-256, SHA-384, SHA-512, SHA- 512/224, SHA-512/256RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4)
Signature Verification with RSADigSig-SigVerDigital signature verification using RSAPadding:PKCS#1 v1.5, PSS Keys:1024, 1536, 2048, 3072, 4096 (80, 96, 112, 128, 149 bits) Hashes:SHA-224, SHA-256, SHA-384, SHA-512, SHA- 512/224, SHA-512/256RSA SigVer (FIPS186-2) RSA SigVer (FIPS186-2) RSA SigVer (FIPS186-2) RSA SigVer (FIPS186-2) RSA SigVer (FIPS186-2) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer

© 2025 Amazon Web Services, Inc./atsec information security.

Page 33
NameTypeDescriptionPropertiesAlgorithms (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4)
Signature Generation with ECDSADigSig-SigGenDigital signature generation using ECDSACurves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) Hashes:SHA-224, SHA-256, SHA-384, SHA-512, SHA- 512/224, SHA- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4)
Signature Verification with ECDSADigSig-SigVerDigital signature verification using ECDSACurves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) Hashes:SHA-224, SHA-256, SHA-384, SHA-512, SHA- 512/224, SHA- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4)
HashesSHACompute a message digest using Secure Hash AlgorithmsSHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-256 SHA2-256

© 2025 Amazon Web Services, Inc./atsec information security.

Page 34

Name Extendable Output Functions

Type XOF

Description Compute a message digest from XOFs

Properties

Algorithms SHA2-256 SHA2-256 SHA2-256 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512/224 SHA2-512/224 SHA2-512/224 SHA2-512/224 SHA2-512/224 SHA2-512/256 SHA2-512/256 SHA2-512/256 SHA2-512/256 SHA2-512/256 SHA3-224 SHA3-224 SHA3-224 SHA3-256 SHA3-256 SHA3-256 SHA3-384 SHA3-384 SHA3-384 SHA3-512 SHA3-512 SHA3-512 SHAKE-128 SHAKE-128 SHAKE-128 SHAKE-256 SHAKE-256 SHAKE-256

© 2025 Amazon Web Services, Inc./atsec information security.

Page 35
NameTypeDescriptionPropertiesAlgorithms
Message Authentication CodeMACCompute MAC tags using AES-based CMAC or HMACKeys:112-256 bitsHMAC-SHA-1 HMAC-SHA-1 HMAC-SHA-1 HMAC-SHA-1 HMAC-SHA-1 HMAC-SHA-1 HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/256 HMAC-SHA2- 512/256

© 2025 Amazon Web Services, Inc./atsec information security.

Page 36
NameTypeDescriptionPropertiesAlgorithms HMAC-SHA2- 512/256 HMAC-SHA2- 512/256 HMAC-SHA2- 512/256 HMAC-SHA3-224 HMAC-SHA3-224 HMAC-SHA3-224 HMAC-SHA3-256 HMAC-SHA3-256 HMAC-SHA3-256 HMAC-SHA3-384 HMAC-SHA3-384 HMAC-SHA3-384 HMAC-SHA3-512 HMAC-SHA3-512 HMAC-SHA3-512 AES-CMAC AES-CMAC AES-CMAC AES-CMAC
Random Number Generation with DRBGDRBGRandom number generation using DRBGCompliance:Compliant with SP 800-90Arev1Counter DRBG Counter DRBG Counter DRBG Counter DRBG Hash DRBG Hash DRBG Hash DRBG Hash DRBG Hash DRBG HMAC DRBG HMAC DRBG HMAC DRBG HMAC DRBG HMAC DRBG
Key Derivation with PBKDFPBKDFKey derivation using PBKDFDerived keys:112-256 bitsPBKDF PBKDF PBKDF

© 2025 Amazon Web Services, Inc./atsec information security.

Page 37

Name

Type

Description

Properties

Algorithms PBKDF PBKDF

Table 8: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES XTS

The AES algorithm in XTS mode can be only used for the cryptographic protection of data on storage devices, as specified in SP 800-38E. The length of a single data unit encrypted with the XTS-AES shall not exceed 2²⁰ AES blocks, that is 16MB of data. To meet the requirement stated in IG C.I, the module implements a check that ensures, before performing any cryptographic operation, that the two AES keys used in AES XTS mode are not identical. The AES-XTS mode shall only be used for the cryptographic protection of data on storage devices. The AESXTS shall not be used for other purposes, such as the encryption of data in transit.

2.7.2 Key Derivation using SP 800-132 PBKDF

The module provides password-based key derivation (PBKDF), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met.

Page 38
Cert
Vendor Name
Number
E124Amazon Web Services, Inc.
Entropy
SampleConditioning
NameTypeOperational Environmentper
SizeSampleComponent
Userspace CPU Time Jitter RNG Entropy Source version 3.4.0Non- PhysicalAmazon Linux 2023 on EC2 c7g.metal; Amazon Linux 2023 on EC2 c6i.metal; SnowOS 1.0 on AWS Snowball64 bitsFull entropySHA3-256 (A4551); HMAC_DRBG (A4551)
2.8 RBG and Entropy

Table 9: Entropy Certificates Table 10: Entropy Sources The module provides an SP 800-90Arev1-compliant Deterministic Random Bit Generator (DRBG) for creation of key components of asymmetric keys, and random number generation. This entropy source is located within the module’s physical perimeter but outside of the module’s cryptographic boundary. The module obtains 384 bits to seed the DRBG, and 256 bits to reseed it. The seeding (and automatic reseeding) of the DRBG is done with getrandom(). The DRBG supports the Hash_DRBG, HMAC_DRBG and CTR_DRBG mechanisms. The DRBG is initialized during module initialization; the module loads by default the DRBG using the HMAC_DRBG mechanism with SHA-256 and without prediction resistance. A different DRBG mechanism can be chosen by invoking the gcry_control(GCRYCTL_DRBG_REINIT) function. The module performs the DRBG health tests as defined in Section 11.3 of SP 800-90Arev1.

2.9 Key Generation

The module provides an SP 800-90Arev1-compliant Deterministic Random Bit Generator (DRBG) for the creation of key components of asymmetric keys, and random number generation. The Cryptographic Key Generation (CKG) methods implemented in the module for Approved services in the approved mode are compliant with Section 5.1 of SP 800-133rev2. For generating RSA and ECDSA keys the module implements asymmetric key generation services compliant with FIPS 186-4. A seed (i.e., the random value) used in asymmetric key generation is directly obtained from the SP 800-90Arev1 DRBG. © 2025 Amazon Web Services, Inc./atsec information security.

Page 39

Additionally, the module implements key derivation with PBKDF2 using option 1a, compliant with SP800-132.

2.10 Key Establishment

The module implements the SSP transport methods as specified in the Security Function Implementations table.

2.11 Industry Protocols

The module does not support any industry protocols listed within the publication of SP 800-135rev1. Therefore, this section is not applicable. © 2025 Amazon Web Services, Inc./atsec information security.

Page 40
Logical
Physical PortInterface(s)Data That Passes
As a software-only module, the module does not have physical ports. The operator can only interact with the module through the API provided by the module. Thus, the physical ports are interpreted to be the physical ports of the hardware platform on which the module runs.Data InputAPI input parameters for data
As a software-only module, the module does not have physical ports. The operator can only interact with the module through the API provided by the module. Thus, the physical ports are interpreted to be the physical ports of the hardware platform on which the module runs.Data OutputAPI output parameters for data
As a software-only module, the module does not have physical ports. The operator can only interact with the module through the API provided by the module. Thus, the physical ports are interpreted to be the physical ports of the hardware platform on which the module runs.Control InputAPI function calls, API input parameters for control input
As a software-only module, the module does not have physical ports. The operator can only interact with the module through the API provided by the module. Thus, the physical ports are interpreted to be the physical ports of the hardware platform on which the module runs.Status OutputAPI return codes, API output parameters for status output
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces All data output via data output interface is inhibited when the module is performing the pre-operational selftest, conditional self-tests, zeroization, or when the module enters an error state. The module does not © 2025 Amazon Web Services, Inc./atsec information security.

Page 41
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
DescriptiOutputSecuritySSP
NameIndicatorInputs
onsFunctionsAccess
Symmetri c encryptio nPerform AES encryptio ngcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_CIPHER, ...) returns GPG_ERR_NO_ERRORAES key, PlaintextCiphert extEncryptio n with AESCrypto Officer - AES keys: W,E
Symmetri c decryptio nPerform AES decryptio ngcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_CIPHER, ...) returns GPG_ERR_NO_ERRORAES key, CiphertextPlainte xtDecryptio n with AESCrypto Officer - AES keys: W,E
Authenti cated symmetri cPerform AES encryptio n andgcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_CIPHER, ...) returns GPG_ERR_NO_ERRORAES key, Plaintext, IVCiphert ext, MAC tagAuthentic ated encryptio n with AESCrypto Officer - AES keys: W,E
4 Roles, Services, and Authentication

N/A for this module. The module does not implement authentication methods.

4.2 Roles

Table 12: Roles The module supports the Crypto Officer role only. This sole role is implicitly assumed by the operator of the module when performing a service.

4.3 Approved Services

W,E W,E © 2025 Amazon Web Services, Inc./atsec information security.

Page 42
DescriptiOutputSecuritySSP
NameIndicatorInputs
onsFunctionsAccess
encryptio nauthentic ation
Authenti cated symmetri c decryptio nPerform AES decryptio n and authentic ationgcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_CIPHER, ...) returns GPG_ERR_NO_ERRORAES key, Ciphertext, MAC tagPlainte xt or failAuthentic ated decryptio n with AESCrypto Officer - AES keys: W,E
RSA Key generatio nGenerate RSA key pairsgcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_PK_FLAGS, ...) returns GPG_ERR_NO_ERRORKey sizeRSA public key, RSA private keyKey Pair Generatio n with RSACrypto Officer - RSA public keys: G,R - RSA private keys: G,R
ECDSA Key generatio nGenerate ECDSA key pairsgcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_PK_FLAGS, ...) returns GPG_ERR_NO_ERRORKey sizeECDSA public key, ECDSA private keyKey Pair Generatio n with ECDSACrypto Officer - ECDSA public keys: G,R - ECDSA private keys: G,R
ECDSA Digital signature generatio nECDSA signature generatio ngcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_PK_FLAGS, ...) and gcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_MD, ...) return GPG_ERR_NO_ERRORECDSA private key, message, hash algorithmSignatu reSignature Generatio n with ECDSACrypto Officer - ECDSA private keys: W,E

G,R G,R G,R W,E © 2025 Amazon Web Services, Inc./atsec information security.

Page 43
DescriptiOutputSecuritySSP
NameIndicatorInputs
onsFunctionsAccess
RSA Digital signature generatio nRSA signature generatio ngcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_PK_FLAGS, ...) and gcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_MD, ...) return GPG_ERR_NO_ERRORRSA private key, message, hash algorithmSignatu reSignature Generatio n with RSACrypto Officer - RSA private keys: W,E
ECDSA Digital signature verificati onECDSA signature verificati ongcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_PK_FLAGS, ...) and gcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_MD, ...) return GPG_ERR_NO_ERRORSignature, hash algorithm, ECDSA public keySignatu re verifica tion resultSignature Verificati on with ECDSACrypto Officer - ECDSA public keys: W,E
Digital signature verificati onRSA signature verificati ongcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_PK_FLAGS, ...) and gcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_MD, ...) return GPG_ERR_NO_ERRORSignature, hash algorithm, RSA public keySignatu re verifica tion resultSignature Verificati on with RSACrypto Officer - RSA public keys: W,E
Public key verificati onVerify ECDSA public keygcry_mpi_ec_curve_point() returns GPG_ERR_NO_ERRORECDSA public key, ECDSA private keyReturn codes/l og messag esPublic Key Verificati on with ECDSACrypto Officer - ECDSA public keys: W,E
Random number generatio nGenerate random bitstringsgcry_randomize(), gcry_random_bytes(), gcry_random_bytes_secure() return GPG_ERR_NO_ERRORSizeRando m numberRandom Number Generatio n with DRBGCrypto Officer - Entrop y input: W,E - DRBG seed: G,E

W,E W,E W,E W,E W,E G,E © 2025 Amazon Web Services, Inc./atsec information security.

Page 44
DescriptiOutputSecuritySSP
NameIndicatorInputs
onsFunctionsAccess - DRBG interna l state (V value, key): W,E - DRBG interna l state (V value, C value): W,E
Message digestCompute SHA hashesgcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_MD, ...) returns GPG_ERR_NO_ERRORMessageMessag e digestHashes Extendabl e Output FunctionsCrypto Officer
Message authentic ation code (MAC)Compute HMAC or AES- based CMACgcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_MAC, ...) returns GPG_ERR_NO_ERRORMessage, keyMAC tagMessage Authentic ation CodeCrypto Officer - HMAC keys: W,E - AES keys: W,E
Key wrappingPerform AES- based key wrappinggcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_CIPHER, ...) returns GPG_ERR_NO_ERRORKey wrapping key, key to be wrappedWrapp ed keyKey wrapping using AES CCM Key wrapping using AES KWCrypto Officer - AES keys: W,E

(V W,E (V C W,E W,E W,E © 2025 Amazon Web Services, Inc./atsec information security.

Page 45
DescriptiOutputSecuritySSP
NameIndicatorInputs
onsFunctionsAccess
Key unwrappi ngPerform AES- based unwrappi nggcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_CIPHER, ...) returns GPG_ERR_NO_ERRORWrapped key, key unwrapping keyUnwra pped keyKey unwrappi ng using AES CCM Key unwrappi ng using AES KWCrypto Officer - AES keys: W,E
Key derivatio nPerform key derivatio ngcry_control(GCRYCTL_FIPS_SERVICE_IND ICATOR_KDF, ...) returns GPG_ERR_NO_ERRORPassword/pass phrase; Derived keyDerive d keyKey Derivatio n with PBKDFCrypto Officer - Derive d key: G,R - Passwo rd or passphr ase: W,E
Show statusShow module statusN/ANoneCurrent status of the moduleNoneCrypto Officer
Zeroizati onZeroize SSPsN/AN/AN/ANoneCrypto Officer - AES keys: Z - HMAC keys: Z - RSA public keys: Z - RSA private keys: Z -

G,R W,E © 2025 Amazon Web Services, Inc./atsec information security.

Page 46
DescriptiOutputSecuritySSP
NameIndicatorInputs
onsFunctionsAccess ECDSA public keys: Z - ECDSA private keys: Z - Passwo rd or passphr ase: Z - Derive d key: Z - Entrop y input: Z - DRBG interna l state (V value, key): Z - DRBG interna l state (V value, C value): Z - DRBG seed: Z

Z y Z (V (V C Z © 2025 Amazon Web Services, Inc./atsec information security.

Page 47
DescriptiOutputSecuritySSP
NameIndicatorInputs
onsFunctionsAccess
Self-testsPerform self-testsN/APower on of the moduleN/ANoneCrypto Officer
Show module name and versionShow module name and versionN/AN/ADisplay module name and versionNoneCrypto Officer

Table 13: Approved Services The table above lists the approved services. For each service, the table lists the associated cryptographic algorithm(s), the role to perform the service, the cryptographic keys or CSPs involved, and their access type(s). The following convention is used to specify access rights to a CSP: • G = Generate: The module generates or derives the SSP. • R = Read: The SSP is read from the module (e.g., the SSP is output). • W = Write: The SSP is updated, imported, or written to the module. • E = Execute: The module uses the SSP in performing a cryptographic operation. • N/A: the calling application does not access any CSP or key during its operation. The details of the approved cryptographic algorithms including the CAVP certificate numbers can be found in the Approved Algorithms table in Section 2.5 Algorithms. In order to check whether it utilizes an approved security function or not, the operator is responsible to invoke the gcry_control() API along with dedicated controls in the form of API input parameters. The module implements the following controls depending on the requested service:

  1. GCRYCTL_FIPS_SERVICE_INDICATOR_CIPHER - For symmetric algorithms and the related modes.
  2. GCRYCTL_FIPS_SERVICE_INDICATOR_KDF - For KDF operations.
  3. GCRYCTL_FIPS_SERVICE_INDICATOR_PK_FLAGS - For asymmetric operations. 1
  4. GCRYCTL_FIPS_SERVICE_INDICATOR_MD - For digest operations.
  5. GCRYCTL_FIPS_SERVICE_INDICATOR_MAC - For MAC operations. 1The list of public key flags allowed in approved mode of operation is described in Appendix A. Approved Public Key Flags. © 2025 Amazon Web Services, Inc./atsec information security.
Page 48
NameDescriptionAlgorithmsRole
Symmetric encryptionAES encryption using non-approved AES modesAES-GCM, AES-GCM-SIV, AES-OCB, AES-EAXCO
Symmetric decryptionAES decryption using non-approved AES modesAES-GCM, AES-GCM-SIV, AES-OCB, AES-EAXCO
Message digestMessage digest using non-approved algorithmsMD5CO
Shared Secret ComputationECDH Shared Secret ComputationECDHCO
Key generationGenerate RSA/ECDSA key pairs with non- approved public key flagsRSA ECDSACO
Digital signature generationRSA/ECDSA signature generation with non- approved public key flagsRSA with non-approved public key flags ECDSA with non-approved public key flagsCO
Digital signature verificationRSA/ECDSA signature verification with non- approved public key flagsRSA with non-approved public key flags ECDSA with non-approved public key flagsCO
Asymmetric encryption primitivesRSA encryption primitivesRSACO

In addition to that, for the below-mentioned services, the approved service indicator corresponds to the GPG_ERR_NO_ERROR returned from listed functions in the indicator column below. They don’t use gcry_control() API:

  1. Random number generation service: gcry_randomize(), gcry_random_bytes(), gcry_random_bytes_secure().
  2. Public key validation service: gcry_mpi_ec_curve_point(). For all approved services, GPG_ERR_NO_ERROR (i.e., “0”) return code indicates the service is approved. In case the above-mentioned controls are used in conjunction, the operator is responsible to check that all the called functions return GPG_ERR_NO_ERROR (i.e., “0”). For all non-approved services, "non-zero" return code indicates the service is not approved. © 2025 Amazon Web Services, Inc./atsec information security.
Page 49
NameDescriptionAlgorithmsRole
Asymmetric decryption primitivesRSA decryption primitivesRSACO
Signature generation primitivesRSA/ECDSA signature generation primitivesRSA ECDSACO
Signature verification primitivesRSA/ECDSA signature verification primitivesRSA ECDSACO

Table 14: Non-Approved Services The table above lists the non-approved services. The details of the non-approved cryptographic algorithms not available in non-approved mode can be found in the Not Allowed, Non-Approved Algorithms table. For the services listed above, the module implements an additional service indicator in the form of a control named GCRYCTL_FIPS_SERVICE_INDICATOR_FUNCTION. The operator is responsible to invoke the gcry_control() API along with the following input parameters: GCRYCTL_FIPS_SERVICE_INDICATOR_FUNCTION control; the name of the API 2 representing the service.

4.5 External Software/Firmware Loaded

The module does not load any external software/firmware.

2 The list of APIs supported by the module can be found in the documentation included in the optional

libgcrypt-devel package. © 2025 Amazon Web Services, Inc./atsec information security.

Page 50
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing the HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the module’s ELF header that was computed at build time for each software component of the module. If the HMAC values do not match, the test fails, and the module enters the Error state.

5.2 Initiate on Demand

Integrity test is performed as part of the Pre-Operational Self-Test. The module provides the Self-Test service to perform self-tests on demand which includes the pre-operational self-test (i.e., integrity test) and cryptographic algorithm self-tests (CASTs). This service can be invoked relying on the gcry_control(GCRYCTL_SELFTEST) API function call or by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and no data output or input is possible. In order to verify whether the self-tests have succeeded and the module is in the Operational state, the calling application may invoke the gcry_control(GCRYCTL_OPERATIONAL_P). The function will return TRUE if the module is in the Operational state and FALSE if the module is in the Error state. © 2025 Amazon Web Services, Inc./atsec information security.

Page 51
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module shall be installed as stated in Section 11 Life-Cycle Assurance. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11 Life-Cycle Assurance. Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2025 Amazon Web Services, Inc./atsec information security.

Page 52
7 Physical Security

The module is comprised of software only, and therefore this section is not applicable. © 2025 Amazon Web Services, Inc./atsec information security.

Page 53
8 Non-Invasive Security

The module does not implement any non-invasive security mechanism, and therefore this section is not applicable. © 2025 Amazon Web Services, Inc./atsec information security.

Page 54
Storage
Persistence
Description
Area
Type
Name
RAMTemporary storage for SSPs used by the module as part of service executionDynamic
FormatDistributionEntrySFI or
NameFromTo
TypeTypeTypeAlgorithm
API input parametersOperator calling application (TOEPP)Cryptographic modulePlaintextManualElectronic
API output parametersCryptographic moduleOperator calling application (TOEPP)PlaintextManualElectronic
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in plaintext form. SSPs are provided to the module by the calling process and are destroyed when released by the appropriate zeroization function calls.

9.2 SSP Input-Output Methods

Table 16: SSP Input-Output Methods The module does not support manual SSP input or intermediate SSP generation output. The SSPs are provided form within the physical perimeter of the operational environment. This is allowed by FIPS 140-3 IG 9.5.A, according to the “CM Software to/from App via TOEPP Path” entry in the table above. © 2025 Amazon Web Services, Inc./atsec information security.

Page 55
Zeroization
MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the provided cipher handleMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of a zeroization routine will indicate that a zeroization procedure succeeded.By calling the appropriate zeroization functions: AES key: gcry_cipher_close HMAC key: gcry_mac_close, gcry_free Key-derivation key: gcry_free Derived key: gcry_free RSA keys: gcry_mpi_release, gcry_sexp_release, gcry_free EC keys: gcry_mpi_release, gcry_free, gcry_mpi_point_release, gcry_sexp_release, gcry_ctx_release Entropy input: gcry_ctrl(GCRYCTL_TERM_SECMEM) Internal state: gcry_ctrl(GCRYCTL_TERM_SECMEM)
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded.By unloading the module

Table 17: SSP Zeroization Methods The memory occupied by SSPs is allocated by regular memory allocation operating system calls. The application API and listed in the table above. Calling gcry_free() will zeroize the SSPs and also invoke the corresponding API functions listed in table to zeroize SSPs. The zeroization functions overwrite the memory occupied by SSPs with “zeros” and deallocate the memory with the regular memory deallocation operating system call. In case of abnormal termination, or swap in/out of a physical memory page of a process, the keys in physical memory are overwritten by the Linux kernel before the physical memory is allocated to another process. Data output via the The user must not call malloc/free to create/release space for keys, and must let libgcrypt manage space for keys, needs to be called before the process is terminated. © 2025 Amazon Web Services, Inc./atsec information security.

Page 56
Type -GeneratedEstablished
NameDescriptionSize - StrengthUsed By
CategoryByBy
AES keysAES key used for encryption, decryption, key wrapping, key unwrapping, and computing MAC tagsXTS: 256, 512 bits; Other modes: 128, 192, 256 bits - XTS: 128, 256 bits; Other modes; 128, 192, 256 bitsSymmetric key - CSPKey wrapping using AES CCM Key wrapping using AES KW Key unwrapping using AES CCM Key unwrapping using AES KW Encryption with AES Decryption with AES
HMAC keysHMAC key used for message authentication code112 to 256 bits - 112 to 256 bitsSymmetric key - CSPMessage Authentication Code
RSA public keysPublic key used for RSA signature verification1024, 1536, 2048, 3072, 4096 bits - 80, 96, 112, 128, 149 bitsPublic key - PSPKey Pair Generation with RSAKey Pair Generation with RSA Signature Verification with RSA
RSA private keysPrivate key used for RSA signature generation2048, 3072, 4096 bits - 112, 128, 149 bitsPrivate key - CSPKey Pair Generation with RSAKey Pair Generation with RSA Signature Generation with RSA
ECDSA public keysPublic key used for ECDSA signature verificationP-224, P-256, P-384, P- 521 - 112, 128, 192, 256 bitsPublic key - PSPKey Pair Generation with ECDSAKey Pair Generation with ECDSA Signature
9.4 SSPs

© 2025 Amazon Web Services, Inc./atsec information security.

Page 57
Type -GeneratedEstablished
NameDescriptionSize - StrengthUsed By
CategoryByByVerification with ECDSA
ECDSA private keysPrivate key used for ECDSA signature generationP-224, P-256, P-384, P- 521 - 112, 128, 192, 256 bitsPrivate key - CSPKey Pair Generation with ECDSAKey Pair Generation with ECDSA Signature Generation with ECDSA
Password or passphrasePBKDF2 passwordAt least 8 characters - N/APassword or passphrase - CSPKey Derivation with PBKDF
Derived keyPBKDF2 derived key112-256 bits - 112-256 bitsSymmetric key - CSPKey Derivation with PBKDFKey Derivation with PBKDF
Entropy inputEntropy input used to seed the DRBGs128-384 bits - 128-256 bitsEntropy input - CSPRandom Number Generation with DRBG
DRBG internal state (V value, key)Internal state of CTR_DRBG and HMAC_DRBGCTR_DRBG: 256, 320, 348 bits; HMAC_DRBG: 320, 512, 1024 bits - CTR_DRBG: 128, 192, 256 bits; HMAC_DRBG: 128, 256 bitsInternal state - CSPRandom Number Generation with DRBGRandom Number Generation with DRBG
DRBG internal state (V value, C value)Internal state of Hash_DRBG880, 1776 bits - 128, 256 bitsInternal state - CSPRandom Number Generation with DRBGRandom Number Generation with DRBG

© 2025 Amazon Web Services, Inc./atsec information security.

Page 58
Type -Generated ByEstablished
NameDescriptionSize - StrengthUsed By
CategoryBy
DRBG seedDRBG seed derived from entropy inputCTR_DRBG: 256, 320, 348 bits; Hash DRBG: 440, 888 bits; HMAC_DRBG: 160, 256, 512 bits - CTR_DRBG: 128, 192, 256 bits; Hash_DRBG: 128, 256 bits; HMAC_DRBG: 128, 256 bitsSeed - CSPRandom Number Generation with DRBGRandom Number Generation with DRBG
Input -Storage
NameStorageZeroizationRelated SSPs
OutputDuration
AES keysAPI input parametersRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the module
HMAC keysAPI input parametersRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the module
RSA public keysAPI input parameters API output parametersRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the moduleRSA private keys:Paired With
RSA private keysAPI input parameters API output parametersRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the moduleRSA public keys:Paired With
ECDSA public keysAPI input parameters API output parametersRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the moduleECDSA private keys:Paired With

Table 18: SSP Table 1 © 2025 Amazon Web Services, Inc./atsec information security.

Page 59
Input -Storage
NameStorageZeroizationRelated SSPs
OutputDuration
ECDSA private keysAPI input parameters API output parametersRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the moduleECDSA public keys:Paired With
Password or passphraseAPI input parametersRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the moduleDerived key:Derives
Derived keyAPI output parametersRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the modulePassword or passphrase:Derived From
Entropy inputRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the moduleDRBG seed:Generates
DRBG internal state (V value, key)RAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the moduleDRBG seed:Generated from
DRBG internal state (V value, C value)RAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the moduleDRBG seed:Generated from
DRBG seedRAM:PlaintextFor the duration of the serviceFree cipher handle Remove power from the moduleEntropy input:Generated from DRBG internal state (V value, key):Generates DRBG internal state (V value, C value):Generates

Table 19: SSP Table 2 © 2025 Amazon Web Services, Inc./atsec information security.

Page 60
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. The RSA and ECDSA algorithms as implemented by the module conform to FIPS 186-4, which has been superseded by FIPS 186-5. FIPS 186-4 has been withdrawn since February 3, 2024. © 2025 Amazon Web Services, Inc./atsec information security.

Page 61
Test
Algorithm or TestPropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-256 (A4597)Key size: 376 bitsMessage AuthenticationSW/FW IntegrityModule is operationalIntegrity test for libgcrypt.so.20.4.2
HMAC-SHA2-256 (A4598)Key size: 376 bitsMessage AuthenticationSW/FW IntegrityModule is operationalIntegrity test for libgcrypt.so.20.4.2
HMAC-SHA2-256 (A4600)Key size: 376 bitsMessage AuthenticationSW/FW IntegrityModule is operationalIntegrity test for libgcrypt.so.20.4.2
HMAC-SHA2-256 (A4601)Key size: 376 bitsMessage AuthenticationSW/FW IntegrityModule is operationalIntegrity test for libgcrypt.so.20.4.2
HMAC-SHA2-256 (A4602)Key size: 376 bitsMessage AuthenticationSW/FW IntegrityModule is operationalIntegrity test for libgcrypt.so.20.4.2
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodType
AES-ECB (A4597)AES ECB mode with 128, 192, 256-bit keys for encryptionKATCASTModule is operationalEncryptionModule initialization or on demand through API function call
AES-ECB (A4598)AES ECB mode with 128, 192, 256-bit keys for encryptionKATCASTModule is operationalEncryptionModule initialization or on demand
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests The details of integrity test are provided in Section 5.1 Integrity Techniques. Data output via the data output interface is inhibited during the execution of the pre-operational self-test.

10.2 Conditional Self-Tests

© 2025 Amazon Web Services, Inc./atsec information security.

Page 62
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypethrough API function call
AES-ECB (A4600)AES ECB mode with 128, 192, 256-bit keys for encryptionKATCASTModule is operationalEncryptionModule initialization or on demand through API function call
AES-ECB (A4601)AES ECB mode with 128, 192, 256-bit keys for encryptionKATCASTModule is operationalEncryptionModule initialization or on demand through API function call
AES-ECB (A4597)AES ECB mode with 128, 192, 256-bit keys for decryptionKATCASTModule is operationalDecryptionModule initialization or on demand through API function call
AES-ECB (A4598)AES ECB mode with 128, 192, 256-bit keys for decryptionKATCASTModule is operationalDecryptionModule initialization or on demand through API function call
AES-ECB (A4600)AES ECB mode with 128, 192, 256-bit keys for decryptionKATCASTModule is operationalDecryptionModule initialization or on demand through API function call
AES-ECB (A4601)AES ECB mode with 128, 192, 256-bit keys for decryptionKATCASTModule is operationalDecryptionModule initialization or on demand through API function call
AES-CMAC (A4597)AES CMAC with 128-bit key, MAC generationKATCASTModule is operationalMessage AuthenticationModule initialization or

© 2025 Amazon Web Services, Inc./atsec information security.

Page 63
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypeon demand through API function call
AES-CMAC (A4598)AES CMAC with 128-bit key, MAC generationKATCASTModule is operationalMessage AuthenticationModule initialization or on demand through API function call
AES-CMAC (A4600)AES CMAC with 128-bit key, MAC generationKATCASTModule is operationalMessage AuthenticationModule initialization or on demand through API function call
AES-CMAC (A4597)AES CMAC with 128-bit key, MAC generationKATCASTModule is operationalMessage AuthenticationModule initialization or on demand through API function call
Counter DRBG (A4597)CTR_DRBG with 129-bit key with DF, with and without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
Counter DRBG (A4598)CTR_DRBG with 129-bit key with DF, with and without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
Counter DRBG (A4600)CTR_DRBG with 129-bit key with DF, with and without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call

© 2025 Amazon Web Services, Inc./atsec information security.

Page 64
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodType
Counter DRBG (A4601)CTR_DRBG with 129-bit key with DF, with and without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
Hash DRBG (A4597)SHA-256 with and without PR; SHA-1 without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
Hash DRBG (A4598)SHA-256 with and without PR; SHA-1 without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
Hash DRBG (A4597)SHA-256 with and without PR; SHA-1 without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
Hash DRBG (A4597)SHA-256 with and without PR; SHA-1 without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
Hash DRBG (A4597)SHA-256 with and without PR; SHA-1 without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
HMAC DRBG (A4597)SHA-256 with and without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand

© 2025 Amazon Web Services, Inc./atsec information security.

Page 65
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypethrough API function call
HMAC DRBG (A4598)SHA-256 with and without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
HMAC DRBG (A4600)SHA-256 with and without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
HMAC DRBG (A4601)SHA-256 with and without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
HMAC DRBG (A4602)SHA-256 with and without PRKATCASTModule is operationalCompliant with section 11.3 of SP 800-90Ar1Module initialization or on demand through API function call
ECDSA SigGen (FIPS186-4) (A4597)ECDSA signature generation with P-256 and SHA-256KATCASTModule is operationalSignature generationModule initialization or on demand through API function call
ECDSA SigGen (FIPS186-4) (A4598)ECDSA signature generation with P-256 and SHA-256KATCASTModule is operationalSignature generationModule initialization or on demand through API function call
ECDSA SigGenECDSA signature generation with P-256 and SHA-256KATCASTModule is operationalSignature generationModule initialization or

© 2025 Amazon Web Services, Inc./atsec information security.

Page 66
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodType
(FIPS186-4) (A4600)on demand through API function call
ECDSA SigGen (FIPS186-4) (A4601)ECDSA signature generation with P-256 and SHA-256KATCASTModule is operationalSignature generationModule initialization or on demand through API function call
ECDSA SigGen (FIPS186-4) (A4602)ECDSA signature generation with P-256 and SHA-256KATCASTModule is operationalSignature generationModule initialization or on demand through API function call
ECDSA SigVer (FIPS186-4) (A4597)ECDSA signature verification with P-256 and SHA-256KATCASTModule is operationalSignature verificationModule initialization or on demand through API function call
ECDSA SigVer (FIPS186-4) (A4598)ECDSA signature verification with P-256 and SHA-256KATCASTModule is operationalSignature verificationModule initialization or on demand through API function call
ECDSA SigVer (FIPS186-4) (A4600)ECDSA signature verification with P-256 and SHA-256KATCASTModule is operationalSignature verificationModule initialization or on demand through API function call
ECDSA SigVer (FIPS186-4) (A4601)ECDSA signature verification with P-256 and SHA-256KATCASTModule is operationalSignature verificationModule initialization or on demand through API function call

© 2025 Amazon Web Services, Inc./atsec information security.

Page 67
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodType
ECDSA SigVer (FIPS186-4) (A4602)ECDSA signature verification with P-256 and SHA-256KATCASTModule is operationalSignature verificationModule initialization or on demand through API function call
HMAC- SHA-1 (A4596)HMAC-SHA-1KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA-1 (A4597)HMAC-SHA-1KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA-1 (A4598)HMAC-SHA-1KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA-1 (A4599)HMAC-SHA-1KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA-1 (A4600)HMAC-SHA-1KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA-1 (A4601)HMAC-SHA-1KATCASTModule is operationalMessage authenticationModule initialization or on demand

© 2025 Amazon Web Services, Inc./atsec information security.

Page 68
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypethrough API function call
HMAC- SHA-1 (A4602)HMAC-SHA-1KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-224 (A4597)HMAC-SHA-224KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-224 (A4598)HMAC-SHA-224KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-224 (A4600)HMAC-SHA-224KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-224 (A4601)HMAC-SHA-224KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-224 (A4602)HMAC-SHA-224KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call

© 2025 Amazon Web Services, Inc./atsec information security.

Page 69
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodType
HMAC- SHA2-256 (A4597)HMAC-SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-256 (A4598)HMAC-SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-256 (A4600)HMAC-SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-256 (A4601)HMAC-SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-256 (A4602)HMAC-SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-384 (A4597)HMAC-SHA-384KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-384 (A4598)HMAC-SHA-384KATCASTModule is operationalMessage authenticationModule initialization or on demand

© 2025 Amazon Web Services, Inc./atsec information security.

Page 70
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypethrough API function call
HMAC- SHA2-384 (A4600)HMAC-SHA-384KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-384 (A4601)HMAC-SHA-384KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-384 (A4602)HMAC-SHA-384KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-512 (A4597)HMAC-SHA-512KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-512 (A4598)HMAC-SHA-512KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-512 (A4600)HMAC-SHA-512KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call

© 2025 Amazon Web Services, Inc./atsec information security.

Page 71
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodType
HMAC- SHA2-512 (A4601)HMAC-SHA-512KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-512 (A4602)HMAC-SHA-512KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-224 (A4597)HMAC-SHA3-224KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-224 (A4597)HMAC-SHA3-224KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-224 (A4597)HMAC-SHA3-224KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-256 (A4597)HMAC-SHA3-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-256 (A4598)HMAC-SHA3-256KATCASTModule is operationalMessage authenticationModule initialization or on demand

© 2025 Amazon Web Services, Inc./atsec information security.

Page 72
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypethrough API function call
HMAC- SHA3-256 (A4602)HMAC-SHA3-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-384 (A4597)HMAC-SHA3-384KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-384 (A4598)HMAC-SHA3-384KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-384 (A4602)HMAC-SHA3-384KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-512 (A4597)HMAC-SHA3-512KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-512 (A4598)HMAC-SHA3-512KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call

© 2025 Amazon Web Services, Inc./atsec information security.

Page 73
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodType
HMAC- SHA3-512 (A4602)HMAC-SHA3-512KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4597)PKCS#1 v1.5 with 2048-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4598)PKCS#1 v1.5 with 2048-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4597)PKCS#1 v1.5 with 2048-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4601)PKCS#1 v1.5 with 2048-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4602)PKCS#1 v1.5 with 2048-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
RSA SigVer (FIPS186-4) (A4597)PKCS#1 v1.5 with 2084-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand

© 2025 Amazon Web Services, Inc./atsec information security.

Page 74
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypethrough API function call
RSA SigVer (FIPS186-4) (A4598)PKCS#1 v1.5 with 2084-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
RSA SigVer (FIPS186-4) (A4600)PKCS#1 v1.5 with 2084-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
RSA SigVer (FIPS186-4) (A4601)PKCS#1 v1.5 with 2084-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
RSA SigVer (FIPS186-4) (A4602)PKCS#1 v1.5 with 2084-bit key and SHA-256KATCASTModule is operationalMessage authenticationModule initialization or on demand through API function call
SHA-1 (A4596)SHA-1KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA-1 (A4597)SHA-1KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA-1 (A4598)SHA-1KATCASTModule is operationalMessage digestModule initialization or

© 2025 Amazon Web Services, Inc./atsec information security.

Page 75
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypeon demand through API function call
SHA-1 (A4600)SHA-1KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA-1 (A4601)SHA-1KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA-1 (A4602)SHA-1KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-224 (A4597)SHA-224KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-224 (A4598)SHA-224KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-224 (A4600)SHA-224KATCASTModule is operationalMessage digestModule initialization or on demand through API function call

© 2025 Amazon Web Services, Inc./atsec information security.

Page 76
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodType
SHA2-224 (A4601)SHA-224KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-224 (A4602)SHA-224KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-256 (A4597)SHA-256KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-256 (A4598)SHA-256KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-256 (A4600)SHA-256KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-256 (A4601)SHA-256KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-256 (A4602)SHA-256KATCASTModule is operationalMessage digestModule initialization or on demand

© 2025 Amazon Web Services, Inc./atsec information security.

Page 77
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypethrough API function call
SHA2-384 (A4597)SHA-384KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-384 (A4598)SHA-384KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-384 (A4600)SHA-384KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-384 (A4601)SHA-384KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-384 (A4602)SHA-384KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-512 (A4597)SHA-512KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-512 (A4598)SHA-512KATCASTModule is operationalMessage digestModule initialization or

© 2025 Amazon Web Services, Inc./atsec information security.

Page 78
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodTypeon demand through API function call
SHA2-512 (A4600)SHA-512KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-512 (A4601)SHA-512KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
SHA2-512 (A4602)SHA-512KATCASTModule is operationalMessage digestModule initialization or on demand through API function call
PBKDF (A4597)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA- 256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsKATCASTModule is operationalPassword-based key derivationModule initialization or on demand through API function call
PBKDF (A4598)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA- 256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsKATCASTModule is operationalPassword-based key derivationModule initialization or on demand through API function call

© 2025 Amazon Web Services, Inc./atsec information security.

Page 79
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or TestMethodType
PBKDF (A4600)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA- 256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsKATCASTModule is operationalPassword-based key derivationModule initialization or on demand through API function call
PBKDF (A4601)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA- 256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsKATCASTModule is operationalPassword-based key derivationModule initialization or on demand through API function call
PBKDF (A4602)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA- 256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsKATCASTModule is operationalPassword-based key derivationModule initialization or on demand through API function call
ECDSA KeyGen (FIPS186-4) (A4597)Signature generation and verification with SHA-256PCTPCTSuccessful key generationEC key pair generationKey generation
ECDSA KeyGen (FIPS186-4) (A4598)Signature generation and verification with SHA-256PCTPCTSuccessful key generationEC key pair generationKey generation
ECDSA KeyGenSignature generation and verification with SHA-256PCTPCTSuccessful key generationEC key pair generationKey generation

© 2025 Amazon Web Services, Inc./atsec information security.

Page 80
AlgorithmTestTest
Test PropertiesIndicatorDetailsConditions
or Test (FIPS186-4) (A4600)MethodType
ECDSA KeyGen (FIPS186-4) (A4601)Signature generation and verification with SHA-256PCTPCTSuccessful key generationEC key pair generationKey generation
ECDSA KeyGen (FIPS186-4) (A4602)Signature generation and verification with SHA-256PCTPCTSuccessful key generationEC key pair generationKey generation
RSA KeyGen (FIPS186-4) (A4597)Signature generation and verification with SHA-256PCTPCTSuccessful key generationRSA key pair generationKey generation
RSA KeyGen (FIPS186-4) (A4598)Signature generation and verification with SHA-256PCTPCTSuccessful key generationRSA key pair generationKey generation
RSA KeyGen (FIPS186-4) (A4600)Signature generation and verification with SHA-256PCTPCTSuccessful key generationRSA key pair generationKey generation
RSA KeyGen (FIPS186-4) (A4601)Signature generation and verification with SHA-256PCTPCTSuccessful key generationRSA key pair generationKey generation
RSA KeyGen (FIPS186-4) (A4602)Signature generation and verification with SHA-256PCTPCTSuccessful key generationRSA key pair generationKey generation

Table 21: Conditional Self-Tests The CASTs are run prior to performing the integrity test. Data output via the data output interface is inhibited during the execution of the conditional self-tests. © 2025 Amazon Web Services, Inc./atsec information security.

Page 81
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A4597)Message AuthenticationSW/FW IntegrityWhenever the module is powered onUpon every power on
HMAC-SHA2-256 (A4598)Message AuthenticationSW/FW IntegrityWhenever the module is powered onUpon every power on
HMAC-SHA2-256 (A4600)Message AuthenticationSW/FW IntegrityWhenever the module is powered onUpon every power on
HMAC-SHA2-256 (A4601)Message AuthenticationSW/FW IntegrityWhenever the module is powered onUpon every power on
HMAC-SHA2-256 (A4602)Message AuthenticationSW/FW IntegrityWhenever the module is powered onUpon every power on
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A4597)KATCASTOn demandManually
AES-ECB (A4598)KATCASTOn demandManually
AES-ECB (A4600)KATCASTOn demandManually
AES-ECB (A4601)KATCASTOn demandManually
AES-ECB (A4597)KATCASTOn demandManually
AES-ECB (A4598)KATCASTOn demandManually
AES-ECB (A4600)KATCASTOn demandManually
AES-ECB (A4601)KATCASTOn demandManually
10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2025 Amazon Web Services, Inc./atsec information security.

Page 82
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CMAC (A4597)KATCASTOn demandManually
AES-CMAC (A4598)KATCASTOn demandManually
AES-CMAC (A4600)KATCASTOn demandManually
AES-CMAC (A4597)KATCASTOn demandManually
Counter DRBG (A4597)KATCASTOn demandManually
Counter DRBG (A4598)KATCASTOn demandManually
Counter DRBG (A4600)KATCASTOn demandManually
Counter DRBG (A4601)KATCASTOn demandManually
Hash DRBG (A4597)KATCASTOn demandManually
Hash DRBG (A4598)KATCASTOn demandManually
Hash DRBG (A4597)KATCASTOn demandManually
Hash DRBG (A4597)KATCASTOn demandManually
Hash DRBG (A4597)KATCASTOn demandManually
HMAC DRBG (A4597)KATCASTOn demandManually
HMAC DRBG (A4598)KATCASTOn demandManually
HMAC DRBG (A4600)KATCASTOn demandManually
HMAC DRBG (A4601)KATCASTOn demandManually

© 2025 Amazon Web Services, Inc./atsec information security.

Page 83
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC DRBG (A4602)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4597)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4598)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4600)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4601)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4602)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4597)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4598)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4600)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4601)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4602)KATCASTOn demandManually
HMAC-SHA-1 (A4596)KATCASTOn demandManually
HMAC-SHA-1 (A4597)KATCASTOn demandManually
HMAC-SHA-1 (A4598)KATCASTOn demandManually

© 2025 Amazon Web Services, Inc./atsec information security.

Page 84
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA-1 (A4599)KATCASTOn demandManually
HMAC-SHA-1 (A4600)KATCASTOn demandManually
HMAC-SHA-1 (A4601)KATCASTOn demandManually
HMAC-SHA-1 (A4602)KATCASTOn demandManually
HMAC-SHA2-224 (A4597)KATCASTOn demandManually
HMAC-SHA2-224 (A4598)KATCASTOn demandManually
HMAC-SHA2-224 (A4600)KATCASTOn demandManually
HMAC-SHA2-224 (A4601)KATCASTOn demandManually
HMAC-SHA2-224 (A4602)KATCASTOn demandManually
HMAC-SHA2-256 (A4597)KATCASTOn demandManually
HMAC-SHA2-256 (A4598)KATCASTOn demandManually
HMAC-SHA2-256 (A4600)KATCASTOn demandManually
HMAC-SHA2-256 (A4601)KATCASTOn demandManually
HMAC-SHA2-256 (A4602)KATCASTOn demandManually

© 2025 Amazon Web Services, Inc./atsec information security.

Page 85
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-384 (A4597)KATCASTOn demandManually
HMAC-SHA2-384 (A4598)KATCASTOn demandManually
HMAC-SHA2-384 (A4600)KATCASTOn demandManually
HMAC-SHA2-384 (A4601)KATCASTOn demandManually
HMAC-SHA2-384 (A4602)KATCASTOn demandManually
HMAC-SHA2-512 (A4597)KATCASTOn demandManually
HMAC-SHA2-512 (A4598)KATCASTOn demandManually
HMAC-SHA2-512 (A4600)KATCASTOn demandManually
HMAC-SHA2-512 (A4601)KATCASTOn demandManually
HMAC-SHA2-512 (A4602)KATCASTOn demandManually
HMAC-SHA3-224 (A4597)KATCASTOn demandManually
HMAC-SHA3-224 (A4597)KATCASTOn demandManually
HMAC-SHA3-224 (A4597)KATCASTOn demandManually
HMAC-SHA3-256 (A4597)KATCASTOn demandManually

© 2025 Amazon Web Services, Inc./atsec information security.

Page 86
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA3-256 (A4598)KATCASTOn demandManually
HMAC-SHA3-256 (A4602)KATCASTOn demandManually
HMAC-SHA3-384 (A4597)KATCASTOn demandManually
HMAC-SHA3-384 (A4598)KATCASTOn demandManually
HMAC-SHA3-384 (A4602)KATCASTOn demandManually
HMAC-SHA3-512 (A4597)KATCASTOn demandManually
HMAC-SHA3-512 (A4598)KATCASTOn demandManually
HMAC-SHA3-512 (A4602)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4597)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4598)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4597)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4601)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4602)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4597)KATCASTOn demandManually

© 2025 Amazon Web Services, Inc./atsec information security.

Page 87
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigVer (FIPS186-4) (A4598)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4600)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4601)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4602)KATCASTOn demandManually
SHA-1 (A4596)KATCASTOn demandManually
SHA-1 (A4597)KATCASTOn demandManually
SHA-1 (A4598)KATCASTOn demandManually
SHA-1 (A4600)KATCASTOn demandManually
SHA-1 (A4601)KATCASTOn demandManually
SHA-1 (A4602)KATCASTOn demandManually
SHA2-224 (A4597)KATCASTOn demandManually
SHA2-224 (A4598)KATCASTOn demandManually
SHA2-224 (A4600)KATCASTOn demandManually
SHA2-224 (A4601)KATCASTOn demandManually
SHA2-224 (A4602)KATCASTOn demandManually
SHA2-256 (A4597)KATCASTOn demandManually
SHA2-256 (A4598)KATCASTOn demandManually
SHA2-256 (A4600)KATCASTOn demandManually
SHA2-256 (A4601)KATCASTOn demandManually

© 2025 Amazon Web Services, Inc./atsec information security.

Page 88
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-256 (A4602)KATCASTOn demandManually
SHA2-384 (A4597)KATCASTOn demandManually
SHA2-384 (A4598)KATCASTOn demandManually
SHA2-384 (A4600)KATCASTOn demandManually
SHA2-384 (A4601)KATCASTOn demandManually
SHA2-384 (A4602)KATCASTOn demandManually
SHA2-512 (A4597)KATCASTOn demandManually
SHA2-512 (A4598)KATCASTOn demandManually
SHA2-512 (A4600)KATCASTOn demandManually
SHA2-512 (A4601)KATCASTOn demandManually
SHA2-512 (A4602)KATCASTOn demandManually
PBKDF (A4597)KATCASTOn demandManually
PBKDF (A4598)KATCASTOn demandManually
PBKDF (A4600)KATCASTOn demandManually
PBKDF (A4601)KATCASTOn demandManually
PBKDF (A4602)KATCASTOn demandManually
ECDSA KeyGen (FIPS186-4) (A4597)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-4) (A4598)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-4) (A4600)PCTPCTOn demandManually

© 2025 Amazon Web Services, Inc./atsec information security.

Page 89
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA KeyGen (FIPS186-4) (A4601)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-4) (A4602)PCTPCTOn demandManually
RSA KeyGen (FIPS186-4) (A4597)PCTPCTOn demandManually
RSA KeyGen (FIPS186-4) (A4598)PCTPCTOn demandManually
RSA KeyGen (FIPS186-4) (A4600)PCTPCTOn demandManually
RSA KeyGen (FIPS186-4) (A4601)PCTPCTOn demandManually
RSA KeyGen (FIPS186-4) (A4602)PCTPCTOn demandManually
Recovery
NameDescriptionConditionsMethodIndicator
Error stateThe module immediately stops functioning due to a self-test failureSoftware integrity test failure CAST failure PCT failureRestart of the moduleModule will not load; Module stops functioning for PCT failure
Fatal Error stateThe module immediately halts all cryptographic operations and transits to shutdownRandom numbers are requested in the error state Cipher operations are requested on a deallocated handleRestart of the moduleModule is aborted and is not available for use

Table 23: Conditional Periodic Information

10.4 Error States

Table 24: Error States © 2025 Amazon Web Services, Inc./atsec information security.

Page 90

The table above shows the error states and the corresponding condition. The calling application can obtain the module state by calling the gcry_control(GCRYCTL_OPERATIONAL_P) API function. The function returns FALSE if the module is in the Error state, TRUE if the module is in the Operational state. When the module fails any pre-operational self-test or conditional self-tests, the module will return an error code to indicate the error and enter the Error state. If random numbers are requested in the Error state or cipher operations are requested on a deallocated handle, the module will enter the Fatal Error state. Any further cryptographic operation and all data output via the data output interface are inhibited in both error states. Recovering from the Error state includes performing self-tests and restarting the module. The only way to transition from the Fatal Error state to the Operational state is to restart the cryptographic module.

10.5 Operator Initiation of Self-Tests

The module provides the Self-Test service to perform self-tests as stated in Section 5.2 Initiate on Demand. During the execution of the on-demand self-tests, services are not available, and data output is not possible. Additionally, the PCTs can be invoked on demand by requesting the asymmetric key generation services. © 2025 Amazon Web Services, Inc./atsec information security.

Page 91
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The Crypto Officer can install the RPM package of the module as listed in Section 11.2 Administrator Guidance using standard tools recommended for the installation of RPM packages on an Amazon Linux 2023 or SnowOS

1.0 system (for example, dnf, rpm, and the RHN remote management tool). The integrity of the RPM package is

automatically verified during the installation, and the Crypto Officer shall not install the RPM package if there is any integrity error. Before the RPM package of the module is installed, the Amazon Linux 2023 and SnowOS 1.0 systems must operate in the FIPS validated configuration. This can be achieved by executing the fips-mode-setup --enable command and then restarting the system. More information can be found at the vendor documentation. The Crypto Officer must verify the Amazon Linux 2023 and SnowOS 1.0 system operates in the FIPS validated configuration by executing the fips-mode-setup --check command, which should output “FIPS mode is enabled.”

11.2 Administrator Guidance

The binaries of the module are contained in the RPM packages for delivery. The Crypto Officer shall follow Section 11.1 Installation, Initialization, and Startup Procedures to configure the operational environment and install the module to be operated as a FIPS 140-3 validated module. The following RPM packages contain the FIPS validated module:

Page 92
11.3 Non-Administrator Guidance

There is no non-administrator guidance. The administrator guidance is specified in section 11.2

11.4 Design and Rules

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the libgcrypt-1.10.2-1.amzn2023.0.2 RPM package can be uninstalled from the Amazon Linux 2023 and SnowOS 1.0 systems. © 2025 Amazon Web Services, Inc./atsec information security.

Page 93
12 Mitigation of Other Attacks
12.1 Attack List

RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack.

12.2 Mitigation Effectiveness

The module implements blinding against RSA Timing Attacks. By default, the module uses the following blinding technique: instead of using the RSA decryption directly, a blinded value y = x re mod n is decrypted and the unblinded value x' = y' r−1 mod n returned. The blinding value r is a random value with the size of the modulus n.

12.3 Guidance and Constraints
12.4 Additional Information

Not applicable. © 2025 Amazon Web Services, Inc./atsec information security.

Page 94
curveddataeecdsaflagssig-val
genkeyhashnnbitspkcs1private-keyvalue
psspublic-keyqrrawrsasalt-length
rsa-use-es

Below are listed the approved public key flags for an input s-expression: © 2025 Amazon Web Services, Inc./atsec information security.

Page 95
Table, extracted as text (did not parse into structured rows)
Appendix B. Glossary and Abbreviations AES                     Advanced Encryption Standard AES-NI                  Advanced Encryption Standard New Instructions CAVP                    Cryptographic Algorithm Validation Program CBC                     Cipher Block Chaining CCM                     Counter with Cipher Block Chaining-Message Authentication Code CFB                     Cipher Feedback CMAC                    Cipher-based Message Authentication Code CMVP                    Cryptographic Module Validation Program CSP                     Critical Security Parameter CTR                     Counter Mode DF                      Derivation Function DRBG                    Deterministic Random Bit Generator ECB                     Electronic Code Book FIPS                    Federal Information Processing Standards Publication GCM                     Galois Counter Mode HMAC                    Hash Message Authentication Code KAT                     Known Answer Test KW                      AES Key Wrap MAC                     Message Authentication Code NIST                    National Institute of Science and Technology OFB                     Output Feedback PAA                     Processor Algorithm Acceleration PAI                     Processor Algorithm Implementation PR                      Prediction Resistance PSP                     Public Security Parameter PSS                     Probabilistic Signature Scheme RNG                     Random Number Generator RSA                     Rivest, Shamir, Adleman SHA                     Secure Hash Algorithm © 2025 Amazon Web Services, Inc./atsec information security.
Page 96

SSP Sensitive Security Parameter XTS XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 Amazon Web Services, Inc./atsec information security.

Page 97

Appendix C. References FIPS140-3 FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS140-3_IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program January 2024 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validationprogram/documents/fips%20140-3/FIPS%20140-3%20IG.pdf FIPS180-4 Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf FIPS186-4 Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf FIPS186-5 Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf FIPS197 Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf FIPS198-1 The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf FIPS202 SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf SP800-38A NIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf SP800-38B NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/detail/sp/800-38b/final © 2025 Amazon Web Services, Inc./atsec information security.

Page 98

SP800-38C NIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf SP800-38E NIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf SP800-38F NIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf SP800-90Arev1 NIST Special Publication 800-90A