All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Atalla Cryptographic Subsystem (ACS)

Certificate#4992StandardFIPS 140-3Level3TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorUtimaco Inc.
Low review priority  ·  exposes firmware-update authentication  ·  last validated 10 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date3/24/2027
CaveatInterim validation. When installed, initialized and configured as specified in Section 11 of the Security Policy
VendorUtimaco Inc.

Approved Algorithms (7)

AlgorithmACVP Cert
AES-CBCAES 4600
AES-CCMA2606
Conditioning Component Block Cipher Derivation Function SP800-90BA2606
Counter DRBGA2606
ECDSA SigVer (FIPS186-4)A2606
RSA SigVer (FIPS186-4)A2606
SHA2-512SHS 3776

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Atalla Cryptographic Subsystem (ACS)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Firmware Load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Unauthenticated<br/>Self-test<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Atalla Cryptographic Subsystem (ACS)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Firmware Load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Unauthenticated<br/>Self-test<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Atalla Cryptographic Subsystem (ACS) Hardware Version: C9B60-2108A, C9B60-2108B and C9B60-2108C, C9B60-2108D, C9B60-2108E Firmware Version: Loader Version 1.24; PSMCU Version 1.0.1 or 1.0.3; CMS-OCT Version 0.95,1.0.0, or 1.0.3; CMS-NTX Version 1.0.0; Loader Stage 1 Version 1.10; Loader Stage 2 Version 1.20; Boot Version 1.23 FIPS 140-3 Document Version 1.78 May 13, 2025 © 2025 Utimaco Inc This document may be freely reproduced in its original entirety. i

Page 2

Atalla Cryptographic Subsystem Contents © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. ii

Page 3

Introduction The Atalla Cryptographic Subsystem (ACS), hereafter referred as ACS, is a secure cryptographic coprocessor designed for use in a variety of high security applications. This document specifies the ACS security rules, including the services offered by the cryptographic module, the roles supported, and all keys and CSPs employed by the module. The ACS module is designed to comply with FIPS 140-3 Level 3 Security requirements. Related Documents

[1]“Security Requirements for Cryptographic Modules,” FIPS PUB 140-3, Information Technology Laboratory, National Institute of Standards and Technology. March 22, 2019. https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
[2]"Secure Hash Standard," FIPS Pub 180-4, Aug 2015 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
[3]“Advanced Encryption Standard (AES)”, FIPS PUB 197, Nov 26 2001. http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.197.pdf
[4]“Digital Signature Standard (DSS)”, FIPS PUB 186-4, July 2013. http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
[5]“Recommendation for Block Cipher Modes of Operation: The CCM Mode for Authentication and Confidentiality,” Morris Dworkin, NIST Special Publication 800-38C, July 2007 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
[6]“Recommendation for Random Number Generation Using Deterministic Random Bit Generators”, Elaine Barker and John Kelsey, NIST Special Publication 800-90A, June 2015.http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
[7]“Recommendation for Block Cipher Modes of Operation: Methods and Techniques.”Dworkin, Morris, NIST Special Publication 800-38A, December 2001. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf
[8]“Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping.” Dworkin, Morris, NIST Special Publication 800-38F, December 2012. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
[9]“Recommendation for Cryptographic Key Generation.” Elaine Barker, Allen Roginsky, and Richard Davis, NIST Special Publication 800-133 Revision 2, June 2020. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
[10]"Recommendation for Random Bit Generator (RBG) Constructions.” Elaine Barker, John Kelsey, Kerry McKay, Allen Roginsky, and Meltem Sönmez Turan, NIST SP 800-90C 3pd, September 2022. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90C.3pd.pdf
[11]“Recommendation for the Entropy Sources Used for Random Bit Generation.” Meltem Sönmez Turan (NIST), Elaine Barker (NIST), John Kelsey (NIST), Kerry McKay (NIST), Mary Baish (NSA), Michael Boyle (NSA), NIST Special Bulletin 800-90B, January 2018. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf

© 2025 Utimaco Inc This document may be freely reproduced in its original entirety. 3

Page 4

Atalla Cryptographic Subsystem Glossary Term Definition ACS Atalla Cryptographic Subsystem, also called Icarus Adapter AES Advanced Encryption Standard symmetric encryption algorithm that uses a 128-bit block and a key size of 128,

192 or 256 bits.

CBC Cipher Block Chaining

Page 5

Atalla Cryptographic Subsystem Term Definition EC or ECC Elliptic Curve Cryptography algorithm

Page 6
ISO/IEC 24759 Section 6 [Number Below]FIPS 140-3 Section TitleSecurity Level
1General3
2Cryptographic Module Specification3
3Cryptographic Module Interfaces3
4Roles, Services, and Authentication3
5Software/Firmware Security3
6Operational EnvironmentN/A
7Physical Security3
8Non-invasive SecurityN/A
9Sensitive Security Parameter Management3
10Self-Tests3
11Life-Cycle Assurance3
12Mitigation of Other AttacksN/A

Atalla Cryptographic Subsystem Product Overview The ACS module is designed to comply with FIPS 140-3 overall Level 3 Security requirements. The ACS is a multi-chip embedded cryptographic module. It consists of a secure hardware platform, a firmware secure loader, and three separate microcontrollers, collectively called the Physical Security Monitoring Control Unit (or PSMCU) The purpose of the cryptographic module is to load Approved (RSA and ECDSA signed) application programs, called “personalities,” in a secure manner. The module is in an Approved mode of operation until a personality is loaded and started, at which point the module enters a non-compliant state. Verification that the module is in Approved mode can be observed by running the “getstatus” and “version” commands. This security policy addresses only the hardware and the firmware secure loader; the personality is not included in the current FIPS validation. But, the PCI-HSM version of the personality, as well as the Loader are included in the PCI-HSM validation. This approach creates a common secure platform with the ability to load trusted code (the personality). Once control passes from the loader to a personality, the module enters a non-compliant state. Note that the PSMCU is always running and no personality, no matter what its FIPS 140-3 validation level, will have access to the module’s secret keys and CSPs. © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 6

Page 7
ModelHardware (Part Number & Version)Firmware VersionDistinguishing Features
ACSC9B60-2108ALoader: 1.24 PSMCU: 1.0.1 CMS-OCT: 1.0.0 CMS-NTX: 1.0.0 Loader Stage 1: 1.10 Loader Stage 2: 1.20 Boot: 1.23N/A
ACSC9B60-2108BLoader: 1.24 PSMCU: 1.0.1 CMS-OCT: 1.0.0 CMS-NTX: N/A Loader Stage 1: 1.10 Loader Stage 2: 1.20 Boot: 1.23N/A
ACSC9B60-2108CLoader: 1.24 PSMCU: 1.0.1, 1.0.3 CMS-OCT: 1.0.0, 1.0.3 CMS-NTX: N/A Loader Stage 1: 1.10 Loader Stage 2: 1.20 Boot: 1.23N/A
ACSC9B60-2108DLoader: 1.24 PSMCU: 1.0.3 CMS-OCT: 1.0.3 CMS-NTX: N/A Loader Stage 1: 1.10 Loader Stage 2: 1.20 Boot: 1.23N/A
ACSC9B60-2108ELoader: 1.24 PSMCU: 1.0.3 CMS-OCT: 1.0.3 CMS-NTX: N/A Loader Stage 1: 1.10 Loader Stage 2: 1.20 Boot: 1.23N/A

Atalla Cryptographic Subsystem The cryptographic boundary of the ACS for the FIPS 140-3 Level 3 validation is the outer perimeter of the secure metal enclosure that encompasses all critical security components. Table 3 Cryptographic Module Tested Configuration The hardware features of the ACS include: • Tamper penetration detection grid © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 7

Page 8
CAVP CertAlgorithm and StandardMode/MethodDescription/Key Size(s)/Key Strength(s)Use/Function
A2606AES-CCM [SP 800-38C]AES-CCM256-bitEncrypt, Decrypt
A2606Conditioning Component Block Cipher Derivation Function [SP 800-90B]Conditioning Component Block Cipher Derivation Function SP800-90B256-bitVetted conditioner for ENT (P)
A2606Counter DRBG [SP 800- 90Arev1]Counter DRBGAES 256-bit with derivation function and no prediction resistanceSymmetric Key Generation
A2606ECDSA SigVer [FIPS 186-4]ECDSA SigVerNIST P-521 with SHA2-512Authentication, Signature Verification, and Integrity Testing
A2606RSA SigVer [FIPS 186-4]RSA SigVerPKCS#1.5 with 2048-bit and 4096-bit modulus and SHA2-512Authentication, Signature Verification, and Integrity testing
AES 4600AES-CBC [SP 800-38A]AES-CBC256-bitEncrypt, Decrypt
AES-CCM A2606KTS [SP 800-38F]SP800-38C and SP800- 38F. KTS (key unwrapping) per IG D.G.256-bit keys providing 256 bits of encryption strengthEstablish keys
N/AENT (P) [SP 800-90B]ENT (P)SP800-90B Entropy SourceEntropy source for Counter DRBG
SHS 3776SHA2-512 [FIPS 180-4]SHA2-512SHA2-512Hashing

Atalla Cryptographic Subsystem

Page 9

Vendor Affirmed

CKG [SP 800- 133rev2]

Section 6.1

Cryptographic Key Generation; SP 800- 133rev2 and IG. D.H.

Symmetric Key Generation

Atalla Cryptographic Subsystem Table 4 Approved Algorithms Note: The module does not implement any non-approved algorithms allowed in the approved mode of operation, non-approved algorithms allowed in the approved mode of operation with no security claimed or non-approved algorithms not allowed in the approved mode of operation.

2.1 Product Photo

The cryptographic boundary of the module is the outer perimeter of the secure metal enclosure that encompasses all critical security components. The red line around the outer metallic enclosure, as shown in Figure below, represents the cryptographic boundary. Note: There is no visibly discernable difference between hardware versions other than the part number. Figure 1: Front and back side of the Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 9

Page 10

Atalla Cryptographic Subsystem 3. Cryptographic Module Interfaces

3.1 External Ports

There are four physical data paths into and out of the ACS.

Page 11
GroupLED #DescriptionNormal State
NICNICNot currently usedOff
Octeon1LED_SYSTEM_READY – Icarus Banking Personality is running (Pulsing Green)Off

Atalla Cryptographic Subsystem Left Right NIC RJ45 Connector

14 12

1 9

10 9

11 8

1 2

3 16

14 12

12 10

4 9

5 1 2

14 12

1 2

Figure 2 Status LED Layout © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 11

Page 12
2LED_LOADER_READY – Icarus Loader is running (Pulsing Green)Off
3LED_SYSTEM_ERROR – Self-test, catastrophic or DRBG error has occurredOff
4LED_BANKING_OK – Indicates the system can process banking commandsOn
5LED_IMAGE_UPDATE – Image update in progress (Pulsing Green)Off
6/7LED_SECURE/TAMPER – Indicates Secure state (Solid Green), Tamper state (Flashing Red) or Test state (slow blinking Green)Solid Green
8LED_ACCESS_TYPE – Indicates HSM Enrolled in an Association (Solid Green)Off
9LED_CATASTROPHIC – Fatal error during Personality normal operationOff
10LED_DRBG_ERROR – Failure during continuous DRBG self- testOff
11LED_SELF_TEST_ERROR – Loader or Personality diagnostic self-test errorOff
12Not usedOff
13/14BATTERY_LIFE (Good = Green, Replace = Red/Green, Critical = Red, Expired = Flashing Red)Solid Green
15/16CPU_BUSY (0% = Solid Green, 100% = Flashing Red)Solid Green
PSMCU15/16 Left EdgePSMCU General/Loader Status – Indicates in Loader and not Enrolled (Off), in Loader and Personality is Enrolled (Flashing Green), in Personality (Solid Green), or PSMCU fault (Flashing Red)Off or Solid Green
1T1 – State of Top Serpentine Trace 1On
2T2 – State of Top Serpentine Trace 2On
3TP – State of Top Penetration LayerOn
4B1 – State of Bottom Serpentine Trace 1On
5B2 – State of Bottom Serpentine Trace 2On
6BP – State of Bottom Penetration LayerOn
7FA – State of Picket Fence Trace AOn
8FB – State of Picket Fence Trace BOn
9FC – State of Picket Fence Trace COn
10FD – State of Picket Fence Trace DOn
11FE – State of Picket Fence Trace EOn
12Board Removal – Solid Green if good, Flashing Green if notOn
13Vbat – State of the Vbat supplyOn
14THERMAL_STATUS_LEDOn
CMS- OCT1DDR0_2V5_STATUS – State of 2.5V supply for DDR bank 0On

Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 12

Page 13
2DDR0_1V2_STATUS – State of 1.2V supply for DDR bank 0On
3DDR0_0V6_STATUS – State of 0.6V supply for DDR bank 0On
4UnusedOff
5HOST_12V_STATUS – State of the host 12V supplyOn
6HOST_3V3_STATUS – State of the host 3.3V supplyOn
7VDD_1V5_STATUS – State of the Octeon 1.5V supply used for PCIeOn
8VDD_1V5lp_STATUS – State of the Octeon 1.5V aux supplyOn
9CORE_5V0_STATUS – State of the 5.0V supply used in the CORE regulatorOn
10CORE_0V9_STATUS – State of the Octeon core 0.9V supplyOn
11PLL_DC_OK_STATUS – State of the PLL_DC_OK line to the OcteonOn
12CHIP_RESET_STATUS – State of the CHIP_RESET line to the OcteonOn
13TEMPERATURE_STATUS – State of the Octeon temperature readingOff
14DDR1_0V6_STATUS – State of 0.6V supply for DDR bank 1On
15DDR1_1V2_STATUS – State of 1.2V supply for DDR bank 1On
16DDR1_2V5_STATUS – State of 2.5V supply for DDR bank 1On
CMS- NTX1NTX_CLOCK_STATUSOn
2NTX_E_LOCK_STATUSOn for first
3NTX_S_LOCK_STATUSminute after
4NTX_Z_LOCK_STATUSHOST power
5NTX_5V0_STATUSon, off after
6NTX_0V9_STATUSunless Nitrox
7NTX_1V8_STATUSIs activated
8NTX_1V8_VPH_STATUSby the Octeon
9NTX_1V8_VPTX_STATUSduring normal
10NTX_RESET_Loperation
11NTX_DC_OKof the system
12NTX_ZEROOff
13UnusedOff
14UnusedOff
15NTX_HOST_3V3_GOOD_LEDOn
16NTX_HOST_12V_GOOD_LEDOn

Atalla Cryptographic Subsystem Table 5 Status LED Meanings © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 13

Page 14
Physical PortLogical InterfaceData that passes over port/interface
LEDs 0-63Status OutputSecondary status output and informational data
Serial InterfaceData Input, Control Input, Status OutputAlternate interface for communication channel
PCIeData Input, Control Input, Status OutputPrimary Interface for communication

Atalla Cryptographic Subsystem

3.2 Power

Primary main system power is derived from the 3.3V pins on the PCIe connector. The supplies derived from the 3.3V pins are

Page 15
RoleServiceInputOutput
Crypto OfficerFirmware Loadprepdnld and writeimage“ok” upon success “fail” upon failure
UnauthenticatedStatus InformationGetStatusStatus information
UnauthenticatedVersionVersionVersion numbers of loader, boot, psmcu, cms-oct, cms-ntx (if applicable)
UnauthenticatedHelpHelpList of available commands
UnauthenticatedGet TimeGettimeTime in yymmddhhmmss and “ok” upon success
UnauthenticatedGet Serial NumberGetsnSerial number and “ok” upon success
UnauthenticatedEcho TestEcho along with testing textTesting text is returned upon success

Atalla Cryptographic Subsystem

4.1 Roles

An unauthenticated role has access to services as specified in Table 9. These services fall under Exception “e” (show status, show version, and self-tests) or Additional Comment 5 (zeroization) from FIPS 140-3 IG 4.1.A. A Crypto Officer is responsible for the overall security of the module. Only an operator in the Crypto Officer role can load a personality into the ACS.

4.1.3 User Role

A User can perform a limited number of the services available on the module as indicated in the following section.

4.2 Service Inputs and Outputs

© 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 15

Page 16
UnauthenticatedRSA Signature TestTest_sig_rsa“ok” upon success, “fail” upon test failure
UnauthenticatedECDSA Signature TestTest_sig_ecdsa“ok” upon success, “fail” upon test failure
UnauthenticatedSHA TestTest_sha“ok” upon success, “fail” upon test failure
UnauthenticatedAES TestTest_aes“ok” upon success, “fail” upon test failure
UnauthenticatedRBG TestTest_rng“ok” upon success, “fail” upon test failure
UnauthenticatedDRBG TestTest_drbg“ok” upon success, “fail” upon test failure
UnauthenticatedEntropy TestTest_entropy“ok” upon success, “fail” upon test failure
UnauthenticatedCCM TestTest_ccm“ok” upon success, “fail” upon test failure
UnauthenticatedCRC TestTest_crc“ok” upon success, “fail” upon test failure
Crypto OfficerPersonality Loadprepdnld and writeimage“ok” upon success, “fail” upon failure
UnauthenticatedZeroizeN/AALARM or TAMPER state
UserStart Personality “go”“go”, “go-pci”, “go- fips”“ok” when personality is valid and ready to start

Atalla Cryptographic Subsystem Table 7 Roles, Service Commands, Input and Output

4.3 Authentication

The ACS supports identity-based authentication of operators. The operator’s identity is represented by public key stored on behalf of the respective operator. Signing with the corresponding private key authenticates the operator. Note that the module is only able to store four operator identities – one capable of assuming the Crypto Officer (CO) and the other three capable of assuming the User role for one of the three different personality modes. The Crypto Officer role is far more security relevant than the User role from the FIPS perspective, so authentication for a Crypto Officer requires a significantly longer key. A Crypto Officer is required to be properly authenticated and its authentication mechanism is controlled by the PSK (private key) and PECSK (private key), which are used to sign personality images, and the LSK (private key) and LECSK (private key) (not SSP’s), which are used to sign the Loader firmware. A CO uses his knowledge of the PSK (private key) and PECSK (private key) to create signed personality images for download to the unit. Similarly, the CO uses his knowledge of the LSK (private © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 16

Page 17
RoleAuthentication MethodAuthentication Strength
Crypto OfficerSingle-Factor Cryptographic Device Authenticators256 bits; (RSA) Authentication is performed using RSA 4096 /w SHA-512 signatures (provides 152 bits of strength). The probability that a random attempt will succeed, or a false acceptance will occur, is approximately 1 in 2^152, which is less than 1 in 1,000,000. The command authentication takes approximately 1 second to complete. Therefore a maximum of 60 authentication attempts can be made per minute. Based on this maximum rate, the probability that a random attempt will succeed in a one-minute period is approximately 60 in 2^152, which is less than 1 in 100,000. (ECDSA) Authentication is performed using ECDSA P-521 /w SHA- 512 signatures (provides 256 bits of strength). The probability that a random attempt will succeed, or a false acceptance will occur, is approximately 1 in 2^256, which is less than 1 in 1,000,000. The command authentication takes approximately 1 second to complete. Therefore a maximum of 60 authentication attempts can be made per minute. Based on this maximum rate, the probability that a random attempt will succeed in a one-minute period is approximately 60 in 2^256, which is less than 1 in 100,000.
UserSingle-Factor Cryptographic Device Authenticators112 bits; Authentication is performed using RSA 2048 /w SHA-512 signatures (provides 112 bits of strength). The probability that a random attempt will succeed, or a false acceptance will occur, is approximately 1 in 2^112, which is less than 1 in 1,000,000. The command authentication takes approximately 1 second to complete. Therefore a maximum of 60 authentication attempts can be made per minute. Based on this maximum rate, the probability that a random attempt will succeed in a one-minute period is approximately 60 in 2^112, which is less than 1 in 100,000.

Atalla Cryptographic Subsystem key) and LECSK (private key) to create signed loader images. A 4096-bit RSA key and a P-521 ECDSA private key shall be used for the authentication process. A User is required to be properly authenticated and his authentication mechanism is controlled by the GSK (private key), which is used to sign the ‘go’ command for each of the three personality types. A User uses his knowledge of the GSK (private key) to sign either the ‘go’ command, the ‘go-pci’ command, or the ‘go-fips” command which allows the Loader to exit and start a personality of the same designated type. The User’s authentication key is a 2048-bit RSA key. Table 8 Roles and Authentication © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 17

Page 18
ServiceDescriptionApprove d Security Function sKeys and/or SSPsRolesAccess rights to Keys and/o r SSPsIndicator
Firmware LoadFirmware Load service is to update the Loader firmware. Two commands are required to perform this service: prepdnld and writeimage. The former prepares the module to receive an image download and the latter is used to load the firmware to the module. New firmware versions within the scope of this validation must be validated through the FIPS 140-3 CMVP. Any other firmware loaded into this module isAES- CCM, AES-CBC, RSA SigVer, ECDSA SigVer, KTSIMFK, PSK, PECSK, FFKCrypto OfficerE, E, E, GWEThe successful completio n of a service is an implicit indicator for the use of an approved service
4.4 Approved Services

following legend applies: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 18

Page 19
out of the scope of this validation and requires a separate FIPS 140- 3 validation. This service is authenticated as described below
Status Informatio nLimited status information shall always be available. This command is used to read and display the status of the module. The status includes tamper information, personality application load status, mode of operation (Approved vs. non-compliant state), etc. Approved vs. non- compliant state of operation is indicated by the combination of status, software version information, and hardware serial number given in the output of the command. The status output is broken into three parts: basic status, which customers can use for simple problemN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service

Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 19

Page 20
diagnosis; extended status, which is used by Atalla for problem analysis; and event status, which is a date- and-time stamped record of all events which have taken place with the ACS, also for use by Atalla for problem analysis. There is an optional parameter for basic getstatus service to display the other status information. None of the status information can compromise the security of the module in any way. Note, this corresponds to the “Show Status” mandatory service.
VersionThe version command is used to retrieve the loader name, product type, software version, and build date and time. Note, this corresponds to the “Show module’s versioningN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service

Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 20

Page 21
information” mandatory service.
HelpThe help command simply returns a list of the available commands. Help is context sensitive; i.e., it shows only the commands valid at the current time, so the responses are different in normal, error, and tamper states. It does not provide any syntax help.N/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
Get TimeThis command is used to read the contents of the real time clock. The date and time are a 12-character formatted ASCII string with the format: YYMMDDHHMMS S (year-month- day-hour-minute- second).N/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
Get Serial NumberThis command reads the value of the serial number field stored in the EEROM. If the serial number has not been set, an error is returned. The serial numberN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an

Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 21

Page 22
is at most a 15- character ASCII string.approved service
Echo TestThe echo command is used to test the I/O connection to the Loader.N/AN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
RSA Signature TestThis command performs a known-answer test of the RSA 4096-bit modulus signature computation algorithm using test vectors published on NIST CAVP website.RSA SigVerN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
ECDSA Signature TestThis command performs a known-answer test of the ECDSA P-521 curve signature computation algorithm using test vectors published on NIST CAVP website.ECDSA SigVerN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
SHA TestThis command does a test of the SHA-512 cryptographic engine using theSHA2- 512N/AUnauthenticate dN/AThe successful completio n of a service is

Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 22

Page 23
test vectors contained in [2].an implicit indicator for the use of an approved service
AES TestThis command does a test of the AES cryptographic engine using the test vectors contained in [3].AES-CBCN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
RBG TestThis command does a known- answer test of the SP800-90C RBG draft construction.N/AN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
DRBG TestThis command does a known- answer test of the SP800-90Arev1 DRBG using known answer test values contained in [6].Counter DRBGN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
Entropy TestThis command does a self-test of the SP800-90B Entropy Source generating 4096ENT (P)N/AUnauthenticate dN/AThe successful completio n of a service is

Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 23

Page 24
entropy samples with continuous health-tests enabled.an implicit indicator for the use of an approved service
CCM TestThis command does a test of the CCM mode of operation of the AES algorithm using test vectors published on NIST CAVP website.AES-CCMN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
CRC TestThis command does a test of the CRC-32 cyclical redundancy check algorithm using known answer test.N/AN/AUnauthenticate dN/AThe successful completio n of a service is an implicit indicator for the use of an approved service
Personality LoadPersonality Load service is to download personalities. Personality load instructions, when successful, result in updating the flash memory. This service is authenticated as described below.AES- CCM, AES-CBC, RSA SigVer, ECDSA SigVer, CKG, Counter DRBG, KTSIMFK, PSK, PECSK, PDEK, IDFK, FFK, DRBG Seed, DRBG Key, DRBG V, Entropy input stringCrypto OfficerE, E, E, E, EZ, GWE, GWE, GWE, GWE, GWEThe successful completio n of a service is an implicit indicator for the use of an approved service
ZeroizeThe zeroize service is not a command. ItN/AALLUnauthenticate dZThe successful completio

Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 24

Page 25
occurs automatically following any tamper event. A user can choose to invoke this service by the physical removal of the batteries. This results in the battery low event, which zeroizes non-volatile RAM, and forces the unit into the ALARM state. The time required for the PSMCU to perform the zeroization is less than 500 microseconds from the time of detection. The first half of this time, less than 250 microseconds, is used for the primary CSP erasure, while the second half is used for extended CSP erasure. Note, this corresponds to the “Perform zeroization” mandatory service.n of a service is an implicit indicator for the use of an approved service
Start Personality “go”The start personality service passes control from the loader to theAES- CCM, AES-CBC, RSAIMFK, GSK, PSK, PECSK, FFKUserE, E, E, E, EThe successful completio n of a service is

Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 25

Page 26

personality in one of 3 different types (A PCI-HSM validated personality mode, a FIPS validated personality mode, and a mode for personalities that have not been PCI-HSM or FIPS validated). This service must be authenticated by an operator in the User role by verifying a signature of the “go” command for the specified personality type (i.e. go, go-pci, or go-fips), which must also match the type of the personality stored in flash. If the PSMCU active “type” value has not been selected (i.e. type = “General”), any of the 3 personality types can be loaded. If the PSMCU active “type” value has already been selected (i.e. type != “General”) by a previous personality load, then only that same type of personality can be

SigVer, KTS

an implicit indicator for the use of an approved service

Atalla Cryptographic Subsystem © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 26

Page 27

loaded, without resetting the PSMCU “type” value. Once the PSMCU “type” value has been selected and the personality has been enrolled in an association, it will require the personality to be reset to factory state and then be server power- cycled or rebooted. If the personality is loaded and not enrolled into an association yet, it will automatically reset the “type” to “General” on the next power cycle or reboot.

Atalla Cryptographic Subsystem Table 9 Approved Services Note: The services that correspond to the “Perform self-tests” mandatory service include RSA Signature Test, ECDSA Signature Test, SHA Test, AES Test, RBG Test, DRBG Test, Entropy Test, CCM Test, and CRC Test. The self-tests can also be invoked on-demand by power cycling the module. Note: All services that specify an approved security function correspond to the “Perform approved security functions” mandatory service. The module does not support any Non-Approved services. 5. Software/Firmware Security The integrity of the module’s executable firmware is verified using CRC-32 (EDC), a 64-bit EDC, and approved integrity techniques for the following firmware components:

Page 28
Physical Security MechanismRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Tamper ResponseThis is constantly maintained by the moduleTamper response will automatically occur if a tamper event is detected. No actions necessary.
ZeroizationThis is constantly maintained by the moduleZeroization will occur after any tamper event. A user can choose to invoke this

Atalla Cryptographic Subsystem • RSA SigVer (FIPS 186-4) (Cert. #A2606) using 4096-bit modulus with PKCS #1.5 padding and SHA2-512, ECDSA SigVer (FIPS 186-4) (Cert. #A2606) using P-521 and SHA2-512 – Loader The firmware integrity tests can be invoked on-demand by power-cycling the module. The required CASTs are executed for the RSA and ECDSA approved integrity techniques prior to the execution of the firmware integrity test. Please refer to Section 2.10 of this document for more information.

  1. Operational Environment Not Applicable. The module has a limited operational environment and is validated with Physical Security Level
  2. The embodiment of the ACS is of a multi-chip embedded module. The Physical Security and Security Control Unit (PSMCU) within the ACS continually monitors the physical security of the module for attempts to physically penetrate the cryptographic boundary. Depending on states of (PSMCU) two major events are generated within the secured boundary of the
  3. A "reset event" is one that forces the module to become temporarily inoperable. This is a noncatastrophic event. When the conditions that cause the "reset event" are removed the unit will operate.
  4. A "tamper event" is one that forces the module to become permanently disabled. This is a catastrophic event. In the disabled state all critical security parameters are erased and the module can only provide status information to users. Any physical penetration results in a “tamper event”. This event causes active zeroization of all cleartext CSPs. The following table specifies the required actions required by the operator to ensure the physical © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 28
Page 29
service by physical removal of the batteries.
AlarmThese automatically occur following a tamper attempt, or failure of critical function or self-testsAlarm state will be entered automatically, and the unit will become non-operational
Temperature or Voltage MeasurementSpecify EFP or EFTSpecify if this condition results in a shutdown or zeroization
Low Temperature (reset)+5℃EFPShutdown
Low Temperature (tamper)-20℃EFPZeroization
High Temperature (reset)+63℃EFPShutdown
High Temperature (tamper)+100℃EFPZeroization
Low Voltage (on host power)12V= <9.6V 3V= <2.5VEFPShutdown
High Voltage (on host power)12V= >14.4V 3V= >4.13VEFPShutdown
Low Voltage (NOT on host power)Battery voltage = <8VEFPZeroization
Hardness tested temperature measurement
Low Temperature-20 ℃
High Temperature+100 ℃

Atalla Cryptographic Subsystem Table 10 Physical Security Inspection Guidelines In addition to physical penetration monitoring, the module supports Environment Failure Protection Table 11 EFP/EFT The following table specifies the temperature range that the hardness of the module’s enclosure was tested at. Table 12 Hardness Testing Temperature Ranges

7.1 Events

For FIPS 140-3 validation the EFP/EFT functionality was tested in order to meet the Security Level 3 requirements. © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 29

Page 30

Atalla Cryptographic Subsystem Events are signals that are generated by hardware circuits that monitor the physical environment. There are no actions required by the operator to enable the monitoring of the physical environment. There is no method for the operator to disable the monitoring of the physical environment. When events have occurred, the unit becomes non-operational either by going into the permanent ALARM state or the temporary RESET state. The detected events are:

Page 31
Key/S SP Name /TypeStreng thSecurit y Functio n and Cert. Numbe rGenerati onImport/ ExportEstablishm entStorageZeroizati onUse & related keys
IMFK (CSP)256 bitsAES- CCM Cert #A2606CKG (Vendor Affirmed )N/AN/APSMCU, plaintex tZeroized actively by tamper event, and passively by battery failureEncrypting and decrypting all other CSPs
PDEK (CSP)256 bitsAES- CCM Cert. #A2606 ; KTS (AES- CCM Cert. #A2606 )Factory pre- loading of a keyN/AN/AFlash ROM, encrypt edZeroized when the IMFK is zeroizedPerforms encryption and decryption of the CCM envelope
IDFK (CSP)256 bitsAES- CBC Cert #AES 4600ExternalInput encrypted and authentica ted by the PDEK using AES-CCMKTS (AES- CCM Cert. #A2606)SDRAM, plaintex tZeroized after image downloa d is complet e orUsed in CBC mode to decrypt the downloade d personality application
  1. Non-invasive Security This section is not applicable due to no requirements currently being defined in SP 800-140F.
  2. Sensitive Security Parameters Management The following table specifies the SSPs utilized by the module. The module supports the zeroization of all SSPs. r ) © 2025 Utimaco Inc This document may be freely reproduced in its original entirety. 31
Page 32
interrupt ed
FFK (CSP)256 bitsAES- CBC Cert #AES 4600CKG (Vendor Affirmed )N/AFlash ROM, encrypt edZeroized when the IMFK is zeroizedUsed in CBC mode to decrypt the personality
Entro py Input String (CSP)322 bitsCounte r DRBG Cert. #A2606 ; CKG (Vendo r Affirme dENT (P)N/AVolatile Memor y, plaintex tZeroized with any loss of powerEntropy
DRBG Seed (CSP)322 bitsCounte r DRBG Cert. #A2606 ; CKG (Vendo r Affirme d)ENT (P)N/AVolatile Memor y, plaintex tZeroized with any loss of powerEntropy Input, Nonce, Personalizat ion String
DRBG Key (CSP)256 bitsCounte r DRBG Cert. #A2606 ; CKG (Vendo r Affirme d)Generat ed per SP 800- 90Arev1N/AVolatile Memor y, plaintex tZeroized actively by tamper event, passively by battery failure, or by any power failureDRBG Internal State
DRBG V (CSP)128 bitsCounte r DRBG Cert. #A2606 ;Generat ed per SP 800- 90Arev1N/AVolatile Memor y, plaintex tZeroized actively by tamper event,DRBG Internal State

Atalla Cryptographic Subsystem r d r d) © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 32

Page 33
CKG (Vendo r Affirme d)passively by battery failure, or by any power failure
GSK (PSP)112 bitsRSA SigVer Cert. #A2606Factory pre- loading of a keyN/AKTS (AES- CCM Cert. #A2606) as part of Loader image.Stored Encrypt ed by the IMFKZeroized when the IMFK is zeroizedSignature verification public key for Go Command
PSK (PSP)152 bitsRSA SigVer Cert. #A2606Factory pre- loading of a keyN/AN/AStored Encrypt ed by the IMFKZeroized when the IMFK is zeroizedUsed for image validation for the personality application. Note, this is not an SSP.
PECSK (PSP)256 bitsECDSA SigVer Cert. #A2606Factory pre- loading of a keyN/AN/AStored Encrypt ed under the IMFKZeroized when the IMFK is zeroizedUsed for image validation for the personality application. Note, this is not an SSP.
Entropy SourcesMinimum Number of Bits of EntropyDetails
SP800-90B Entropy Source322-bitsThe DRBG requests 1024-bits of output from the entropy source. The entropy source provides 0.31515540348 bits of entropy per bit of output from the vetted Conditioning Component Block Cipher Derivation Function SP 800-90B (A2606). Therefore the DRBG is seeded with at least 322 bits of entropy before generating keys.

Atalla Cryptographic Subsystem Table 13 SSPs The following table specifies the module’s only entropy source, which is internal to the module’s cryptographic boundary. Table 14 Non-Deterministic Random Number Generation Specification © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 33

Page 34

Atalla Cryptographic Subsystem 10.Self-Tests The following self-tests are performed automatically by the module without requiring operator intervention.

  1. Pre-operational self-tests a. Pre-operational software/firmware integrity test: i. Firmware Integrity Test: The integrity of the Loader is verified at startup by checking a 4096-bit RSA signature and ECDSA P-521 signature.Stage 1, Stage 2, and Boot are verified by CRC-32. PSMCU, CMS-OCT, and CMS-NTX are verified by a 64-bit EDC. All must be verified successfully to continue b. Pre-operational critical functions test: i. Memory: Done during DDR RAM initialization ii. Key Integrity Check: All Loader keys are stored encrypted using CCM. The key CCM MAC is used to verify integrity before these keys are used. All PSMCU CSPs are stored within the PSMCU in cleartext form use leftmost 16-bytes of SHA-512 hash as the check digits. The check digits are used to verify integrity before these keys are used.
  2. Conditional self-tests a. Conditional cryptographic algorithm test i. SHA2-512 hash - Known answer test ii. AES-ECB 256-bit Encrypt – Known answer test (ECB is only used for self-tests) iii. AES-ECB 256-bit Decrypt – Known answer test (ECB is only used for self-tests) iv. AES-CBC 256-bit Encrypt – Known answer test v. AES-CBC 256-bit Decrypt – Known answer test vi. RSA SigVer (FIPS 186-4) 4096-bit modulus with SHA2-512 - Known answer test vii. ECDSA SigVer (FIPS 186-4) P-521 with SHA2-512 - Known answer test viii. SP800-90Arev1 Counter DRBG (instantiate/generate/reseed) – Known answer test ix. SP800-90B ENT (P) Self-Test- 4096 entropy samples generated with continuous health-tests (APT and RCT) enabled. x. AES -CCM 256-bit Encrypt – Known Answer Test xi. AES -CCM 256-bit Decrypt – Known Answer Test xii. Continuous SP800-90B ENT (P) Health Tests (APT and RCT). xiii. Continuous SP800-90Arev1 DRBG periodic self-tests (Instantiate/Generate/Reseed). b. Conditional software/firmware load test: i. Firmware Load Test: This is a series of tests used to validate the integrity of the Loader firmware or personality when loaded into the module. These tests include CCM for secure and authenticated key transport, Signature test (RSA 4096-bit modulus and ECDSA P-521 curve both with SHA-512), AES-256 file decryption, and CRC-32 for simple integrity check. © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 34
Page 35

Atalla Cryptographic Subsystem c. Conditional critical functions test: i. “go” command personality start validation: The “go” command is authenticated using a 2048-bit signature. Following this, the personality integrity is validated with CRC-32, then decrypted using AES-256, then validated again by verifying its signatures (RSA 4096-bit modulus and ECDSA P-521 curve both with SHA-512), prior to passing control to it. Failure of any of the above tests results in an error state. Recovery from the error state requires power cycling. When an error state occurs, cryptographic operations (like “go”, personality load, etc.) are disabled until the error state has been rectified. Since the module is only powered-on for short periods of time (30-60 seconds to start a personality, 3-

4 minutes to update flash) self-tests are periodically performed by nature of the design (i.e. power-on

self-tests, conditional self-tests, and signature tests on every start of the card). The only time the loader remains active for more than a couple minutes is if the ACS card has tampered or entered test state, in which case it is prevented from doing any cryptographic or security-related operations, permanently, so there is no need for periodic self-tests, in this case. In addition to the automatic self-tests, the module supports cryptographic algorithm self-test services (<algorithm> Test). These services allow the user to request on-demand invocation of any specific test. Additionally, the user can invoke all of the self-tests on demand by power-cycling the module. 11.Life-cycle Assurance The module is always in an Approved mode of operation until a personality is loaded and started, at which point the module enters a non-compliant state. The ACS loads and generates its initial keys randomly in manufacturing in the factory, during the process of entering into secure state. Once secure state has been entered, the physical security monitoring of external penetration, and voltage/thermal operating conditions are continuously maintained by the PSMCU, which is battery and system powered. The monitoring is maintained for the entire ACS life cycle. During normal operational use of the cryptographic operations, any failed startup test or self-test will enter a state that does not allow any cryptographic operations to be completed without cycling the power to the ACS. If an event is detected that results in the ACS security boundary being compromised, all keys are erased immediately and the ACS enters Tampered State, which renders the device cryptographic operations unusable, ending the ACS life cycle. There is no means to recover from this state, without irreversible damage. HSM lifecycle is documented and located within the HSM security directory and available upon request. 12.Mitigation of Other Attacks The module does not implement any additional attack mitigation techniques. © 2025 Utimaco Inc. This document may be freely reproduced in its original entirety. 35