All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Arista Crypto Module

Certificate#5001StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorArista Networks, Inc.
Low review priority  ·  no TCB surface named  ·  last validated 5 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date4/16/2030
CaveatWhen operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys).
VendorArista Networks, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Arista Crypto Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Arista Crypto Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks, Inc. Arista Crypto Module August 8th, 2024 Document prepared by: http://www.lightshipsec.com Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 2

Arista Networks, Inc. FIPS 140-3 Security Policy Table of Contents Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 3

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 4

Arista Networks, Inc. FIPS 140-3 Security Policy List of Tables Table 3: Tested Module Identification

Page 5

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1

Arista Networks, Inc. FIPS 140-3 Security Policy

1.1 Overview

This non-proprietary FIPS 140-3 Security Policy for the Arista Cryptographic Module, v4.0 describes how the module meets the security requirements specified in FIPS 140-3 (Federal Information Processing Standard 140-3) for an overall security level 1 module and outlines the security rules and operating procedures required to maintain compliance.

1.2 Security Levels
2.1 Description

Purpose and Use: The module is a dynamic software library providing an application programming interface (API) intended to be used via OpenSSL interfaces to serve cryptographic functionalities for applications running in the user space of the underlying operating system. Module Embodiment: Multi-Chip Standalone Module Characteristics: Cryptographic Boundary: The module’s cryptographic boundary (represented by the red dotted line in Figure 1) consists of the entire Arista Cryptographic Module executable code. Tested Operational Environment’s Physical Perimeter (TOEPP): Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
fips.sov4.0RPM package containing module in executable formatHMAC-SHA2-256

Arista Networks, Inc. FIPS 140-3 Security Policy The module was tested on the Arista AWE-5510 router, running Arista’s EOS operating system. Figure 1: Block Diagram

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 8
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
EOSv4Arista AWE- 5510Intel® Xeon® Processor D-2798NX (Ice Lake)Yesv4.0
EOSv4Arista AWE- 5510Intel® Xeon® Processor D-2798NX (Ice Lake)Nov4.0
Operating SystemHardware Platform
EOSv4Arista 7289 with Intel Xeon CPU D-1548
EOSv4Arista 7300-SUP-D with Intel Xeon CPU @ 2.60GHz
EOSv4Arista 7368-SUP with Intel Xeon CPU D-1527
EOSv4Arista 7368-SUP-D with Intel Xeon CPU D-1527
EOSv4Arista 7388-SUP-D with Intel Xeon CPU D-1527
Linux 5.4Arista C-460 with ARM Cortex-A73
Linux 5.4Arista O-435 with ARM Cortex-A53
EOSv4Arista AWE-5310 with Intel Atom P5721
EOSv4Arista AWE-5310-2F-FLX with Intel Atom P5721
EOSv4Arista AWE-5510 with Intel Xeon D-2798NX CPU
EOSv4Arista AWE-5510-2F-FLX with Intel Xeon D-2798NX
EOSv4Arista AWE-7220RP-5TH-2S with Intel Atom CPU C3558R
EOSv4Arista AWE-7230R-4TX-4S-FLX with Intel Atom P5721
EOSv4Arista AWE-7250R-16S-FLX with Intel Xeon D-2798NX
EOSv4Arista CCS-710P-12 with AMD GX-412TC
EOSv4Arista CCS-710P-12-NA with AMD GX-412TC
EOSv4Arista CCS-710P-16P with AMD GX-412TC
EOSv4Arista CCS-710P-16P-NA with AMD GX-412TC
EOSv4Arista CCS-720DF-48Y with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DF-48Y-2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DF-48Y-DC with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DF-48Y-M-S-2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DP-24S with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DP-24S-2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DP-24S-M-S-2 with AMD Ryzen Embedded R1600

Arista Networks, Inc. FIPS 140-3 Security Policy Tested Module Identification

Page 9
Operating SystemHardware Platform
EOSv4Arista CCS-720DP-24ZS-2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DP-48S with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DP-48S-2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DP-48S-M-S-2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DP-48ZS with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DT-24S with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DT-24S-2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DT-24S-2R with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DT-24S-M-S-2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DT-48S with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720DT-48S-2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720XP-24Y6 with AMD Crowned Eagle GX- 224PC or AMD G-Series GX-224
EOSv4Arista CCS-720XP-24ZY4 with AMD Crowned Eagle GX- 224PC or AMD G-Series GX-224
EOSv4Arista CCS-720XP-48TXH-2C-S with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720XP-48Y6 with AMD Crowned Eagle GX- 224PC or AMD G-Series GX-224
EOSv4Arista CCS-720XP-48ZC2 with AMD Crowned Eagle GX- 224PC or AMD G-Series GX-224
EOSv4Arista CCS-720XP-48ZXC2 with AMD Ryzen Embedded R1600
EOSv4Arista CCS-720XP-96ZC2 with AMD R-Series RX-216 (Merlin Falcon)
EOSv4Arista CCS-720XP-96ZC2-M-S-4 with AMD Embedded R- Series RX-216TD
EOSv4Arista CCS-720XP-96ZC2-M-S with AMD Embedded R- Series RX-216TD
EOSv4Arista CCS-722XPM-48Y4 with AMD G-Series GX-224 (Crowned Eagle)
EOSv4Arista CCS-722XPM-48ZY8 with AMD G-Series GX-224 (Crowned Eagle)
EOSv4Arista CCS-750-SUP100 with Intel Xeon D-1527 (Broadwell)
EOSv4Arista CCS-750-SUP25 with Intel Xeon D-1527 (Broadwell)
CloudVision PortalAny general-purpose computer (GPC) with Any CPU
CloudVision Portal on VMware ESXi 6.7 on AlmaLinux 9Supermicro SYS-6029TP-HTR with Intel Xeon Gold 5218R

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 10
Operating SystemHardware Platform
CloudVision Portal on QEMU 2.12 on AlmaLinux 9Supermicro SYS-6029TP-HTR with Intel Xeon Silver 4316
CloudEOSv4Any general-purpose computer (GPC) with Any CPU
CloudEOSv4 on QEMU 2.0Supermicro SYS-1029U-TR-CTO with Intel Xeon Gold 6240R
EOSv4Arista DCS-7010T-48 with AMD eKabini GX-210HA or AMD Steppe Eagle GX-424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7010T-48-DC with AMD eKabini GX-210HA or AMD Steppe Eagle GX-424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7010TX-48 with AMD Crowned Eagle GE224PIXJ23JB
EOSv4Arista DCS-7010TX-48-DC with AMD Crowned Eagle GE224PIXJ23JB
EOSv4Arista DCS-7010TX-48C with AMD Ryzen Embedded R1600
EOSv4Arista DCS-7010TX-48C-DC-RV3 with AMD Ryzen Embedded R1600
EOSv4Arista DCS-7020SR-24C2 with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7020SR-32C2 with Intel Broadwell DE D1508
EOSv4Arista DCS-7020SRG-24C2 with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7020TR-48 with AMD Steppe Eagle GX-424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7020TRA-48 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7050CX3-32C with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7050CX3-32S with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7050CX3-32S-SSD with AMD GX-424CC SOC
EOSv4Arista DCS-7050CX3M-32S with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7050CX4-24D8 with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7050CX4-40D with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7050CX4-48D8 with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7050CX4M-48D8 with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7050DX4-32S with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7050DX4M-32S with AMD Snowy Owl SP4r2 3151
EOSv4Arista DCS-7050PX4-32S with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 11
Operating SystemHardware Platform
EOSv4Arista DCS-7050QX-32 with AMD Athlon NEO X2 N40L
EOSv4Arista DCS-7050QX-32S with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7050QX2-32S with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7050SDX4-48D8 with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7050SPX4-48D8 with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7050SX-128 with Intel "Gladden" Sandy Bridge
EOSv4Arista DCS-7050SX-64 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7050SX-72 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7050SX-72Q with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7050SX-96 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7050SX2-128 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7050SX2-72Q with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7050SX3-48C8 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7050SX3-48C8C with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7050SX3-48YC12 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7050SX3-48YC8 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7050SX3-48YC8C with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7050SX3-96YC8 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7050TX-128 with Intel "Gladden" Sandy Bridge
EOSv4Arista DCS-7050TX-48 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7050TX-64 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7050TX-72 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7050TX-72Q with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7050TX-96 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7050TX2-128 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 12
Operating SystemHardware Platform
EOSv4Arista DCS-7050TX3-48C8 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7060CX-32C with AMD GX-424PC SOC
EOSv4Arista DCS-7060CX-32S with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7060CX2-32S with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7060CX5-56D8 with AMD Ryzen Embedded V1500B
EOSv4Arista DCS-7060DX4-32 with Intel Broadwell-DE D1508
EOSv4Arista DCS-7060DX5-32 with AMD EPYC 3151 (4c or 8c)
EOSv4Arista DCS-7060DX5-64 with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7060DX5-64E with AMD EPYC Embedded 3151
EOSv4Arista DCS-7060DX5-64S with AMD EPYC Embedded 3151
EOSv4Arista DCS-7060PX4-32 with Intel Broadwell-DE D1508
EOSv4Arista DCS-7060PX5-64 with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7060PX5-64E with AMD EPYC Embedded 3151
EOSv4Arista DCS-7060PX5-64S with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7060SX2-48YC6 for AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7060X6-64PE with AMD EPYC 3151 (4c or 8c)
EOSv4Arista DCS-7130-16G3S with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130-48EHS with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130-48G3S with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130-48LAS with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130-48LBAS with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130-48LBS with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130-96LAS with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130-96LBAS with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130-96LBS with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130-96LS with Intel Atom® Processor C2558 (Rangeley)

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 13
Operating SystemHardware Platform
EOSv4Arista DCS-7130-96S with Intel Atom® Processor C2558 (Rangeley)
EOSv4Arista DCS-7130LBR-48S6QD with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7132LB-48Y4C with AMD EPYC 3251
EOSv4Arista DCS-7132LB-48Y4C-DC with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7132LN-48Y4C with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7135LB-48Y4C with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7148SX with AMD Athlon NEO X2 N40L
EOSv4Arista DCS-7150S-24-CL with AMD Athlon NEO X2 N40L
EOSv4Arista DCS-7150SC-24-CLD with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7150SC-64-CLD with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7160-32CQ with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7160-48TC6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7160-48YC6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7170-32C with Intel Broadwell-DE D1508
EOSv4Arista DCS-7170-32CD with Intel Broadwell-DE D1508
EOSv4Arista DCS-7170-64C with Intel Broadwell-DE D1508
EOSv4Arista DCS-7170B-64C with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7260CX-64 with Intel "Gladden" Sandy Bridge
EOSv4Arista DCS-7260CX3-64 with Intel Broadwell-DE D1508
EOSv4Arista DCS-7260CX3-64E with Intel Broadwell-DE D1508
EOSv4Arista DCS-7260CX3-64LQ with Intel Broadwell-DE D1508
EOSv4Arista DCS-7260QX-64 with Intel "Gladden" Sandy Bridge or AMD GX-424CC SOC
EOSv4Arista DCS-7280CR-48 with Intel "Gladden" Sandy Bridge
EOSv4Arista DCS-7280CR2-60 with Intel "Gladden" Sandy Bridge
EOSv4Arista DCS-7280CR2A-30 with Intel Broadwell-DE D1508
EOSv4Arista DCS-7280CR2A-60 with Intel "Gladden" Sandy Bridge
EOSv4Arista DCS-7280CR2K-30 with Intel Broadwell-DE D1508
EOSv4Arista DCS-7280CR2K-60 with Intel "Gladden" Sandy Bridge
EOSv4Arista DCS-7280CR2M-30 with Intel Broadwell-DE D1508
EOSv4Arista DCS-7280CR3-32D4 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 14
Operating SystemHardware Platform
EOSv4Arista DCS-7280CR3-32P4 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280CR3-36S with AMD Merlin Falcon R-series RX-421ND or AMD Merlin Falcon R-series RX-216TD
EOSv4Arista DCS-7280CR3-96 with AMD Merlin Falcon R-series RX-421ND or AMD Merlin Falcon R-series RX-216TD
EOSv4Arista DCS-7280CR3A-24D12 with AMD Snowy Owl SP4r2 3251
EOSv4Arista DCS-7280CR3A-32S with AMD EPYC 3251
EOSv4Arista DCS-7280CR3A-48D6 with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280CR3A-72 with AMD Snowy Owl SP4r2 3251
EOSv4Arista DCS-7280CR3AK-24D12 with AMD Snowy Owl SP4r2 3251
EOSv4Arista DCS-7280CR3AK-48D6 with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280CR3AK-72 with AMD Snowy Owl SP4r2 3251
EOSv4Arista DCS-7280CR3AM-24D12 with AMD Snowy Owl SP4r2 3251
EOSv4Arista DCS-7280CR3AM-32S with AMD EPYC 3251
EOSv4Arista DCS-7280CR3AM-48D6 with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280CR3AM-72 with AMD Snowy Owl SP4r2 3251
EOSv4Arista DCS-7280CR3E-36S with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280CR3K-32D4 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280CR3K-32D4A with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280CR3K-32P4 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280CR3K-32P4A with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280CR3K-36A with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280CR3K-36S with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280CR3K-96 with AMD Merlin Falcon R-series RX-421ND or AMD Merlin Falcon R-series RX-216TD

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 15
Operating SystemHardware Platform
EOSv4Arista DCS-7280CR3MK-32D4 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280CR3MK-32D4A-S with AMD EPYC 3251
EOSv4Arista DCS-7280CR3MK-32D4S with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280CR3MK-32P4 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280CR3MK-32P4S with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280DR3-24 with AMD Merlin Falcon R-series RX-421ND or AMD Merlin Falcon R-series RX-216TD
EOSv4Arista DCS-7280DR3A-36 with AMD EPYC Embedded 3251
EOSv4Arista DCS-7280DR3A-54 with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280DR3AK-36 with AMD EPYC Embedded 3251
EOSv4Arista DCS-7280DR3AK-36S with AMD EPYC 3251
EOSv4Arista DCS-7280DR3AK-54 with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280DR3AM-36 with AMD EPYC Embedded 3251
EOSv4Arista DCS-7280DR3AM-54 with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280DR3K-24 with AMD Merlin Falcon R-series RX-421ND or AMD Merlin Falcon R-series RX-216TD
EOSv4Arista DCS-7280PR3-24 with AMD Merlin Falcon R-series RX-421ND or AMD Merlin Falcon R-series RX-216TD
EOSv4Arista DCS-7280PR3K-24 with AMD Merlin Falcon R-series RX-421ND or AMD Merlin Falcon R-series RX-216TD
EOSv4Arista DCS-7280QR-C36 with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7280QR-C72 with Intel "Gladden" Sandy Bridge
EOSv4Arista DCS-7280QRA-C36S with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7280SE-64 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7280SE-68 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7280SE-72 with AMD eKabini GE420CIAJ44HM
EOSv4Arista DCS-7280SR-48C6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 16
Operating SystemHardware Platform
EOSv4Arista DCS-7280SR2-48YC6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7280SR2A-48YC6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7280SR2K-48C6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7280SR3-40YC6 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280SR3-48YC8 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280SR3A-48YC8 with AMD EPYC 3251
EOSv4Arista DCS-7280SR3AM-48YC8 with AMD EPYC 3251
EOSv4Arista DCS-7280SR3E-40YC6 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280SR3E-40YC6-M with AMD Merlin Falcon R-series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280SR3E-48YC8 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280SR3K-48YC8 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280SR3K-48YC8A with AMD Snowy Owl SP4r2 3151 or 3251 (4c or 8c)
EOSv4Arista DCS-7280SR3M-48YC8 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280SR3MK-48YC8A-S with AMD EPYC 3251
EOSv4Arista DCS-7280SRA-48C6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7280SRAM-48C6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7280SRM-40CX2 with AMD Steppe Eagle GE424CIXJ44JB
EOSv4Arista DCS-7280TR-48C6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7280TR3-40C6 with AMD Merlin Falcon R- series RX-421ND or AMD Merlin Falcon R-series RX- 216TD
EOSv4Arista DCS-7280TRA-48C6 with AMD Steppe Eagle GX- 424CC (GE424CIXJ44JB)
EOSv4Arista DCS-7289-SUP with Intel Xeon CPU D-1548
EOSv4Arista DCS-7289-SUP-S with Intel Xeon CPU D-1548
EOSv4Arista DCS-7300-SUP with Intel Xeon CPU @ 2.60GHz

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 17
Operating SystemHardware Platform
EOSv4Arista DCS-7300-SUP2-D with Intel Xeon CPU D-1528
EOSv4Arista DCS-7388-SUP with Intel Sandy Bridge Gladden AV8062701048500 or Intel Xeon CPU D-1527
EOSv4Arista DCS-7500-SUP2 with Intel Xeon CPU D-1528
EOSv4Arista DCS-7500-SUP2-D with Intel Xeon CPU D-1531
EOSv4Arista DCS-7516-SUP2 with Intel Xeon CPU D-1548
EOSv4Arista DCS-7800-SUP with Intel Xeon CPU D-1528
EOSv4Arista DCS-7800-SUP1A with Intel Broadwell DE D-1528
EOSv4Arista DCS-7800-SUP1S with Intel Broadwell DE D-1528
EOSv4Arista DCS-7800A-SUP1A with Intel Xeon CPU D-1528
EOSv4Arista DCS-7816-SUP with Intel Broadwell DE D-1548
EOSv4Arista DCS-7816-SUP1S with Intel Broadwell DE D-1548
EOSv4Arista ZTX-7250F-16S with Intel Xeon D-2798NX
EOSv4Arista ZTX-7250S-16S with Intel Xeon D-2798NX
EOSv4Arista DCS-7060X6-64DE
EOSv4Arista 7280CR3AK-32S
EOSv4Arista 7280SR3AK-48YC8
Linux 4.4Arista C-200
Linux 4.4Arista C-230
Linux 4.4Arista C-230E
Linux 4.4Arista C-260
Linux 4.4Arista C-330
Linux 4.4Arista C-360
Linux 5.4Arista C-460E
Linux 4.4Arista O-235
Linux 4.4Arista O-235E
Linux 4.4Arista W318
Linux 4.4Arista W318-RW
CloudVision-CUE on CloudVision Portal on any hypervisorAny general-purpose computer (GPC) with any CPU
EOSv4DCS-7020R4-48Y-8QC with AMD Ryzen Embedded V1500B
EOSv4DCS-7020R4M-48Y-8QC with AMD Ryzen Embedded V1500B
EOSv4DCS-7020R4-48Y-4QC with AMD Ryzen Embedded V1500B
EOSv4DCS-7020R4M-48Y-4QC with AMD Ryzen Embedded V1500B
EOSv4DCS-7020R4-48TX-4QC with AMD Ryzen Embedded V1500B
EOSv4DCS-7020R4M-48TX-4QC with AMD Ryzen Embedded V1500B
EOSv4CCS-710HXP-28TXH-4S
EOSv4CCS-710HXP-20TNH-4S
EOSv4DCS-7050CX4M-48D8 with AMD Ryzen Embedded V1500B
EOSv4CCS-720DP-24S with AMD Ryzen Embedded R1600

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 18
Operating SystemHardware Platform
EOSv4CCS-720DP-48S with AMD Ryzen Embedded R1600
EOSv4CCS-720DT-24S with AMD Ryzen Embedded R1600
EOSv4CCS-720DT-48S with AMD Ryzen Embedded R1600
EOSv47500R3K-48Y4D-LC
EOSv47500R3K-36CQ-LC
EOSv47500R3-48Y4D-LC
EOSv47500R3-36CQ-LC
EOSv47500R3-24P-LC
EOSv47500R3-24D-LC
EOSv47300X3-32C-LC
EOSv47300X3-48TC4-LC
EOSv47300X3-48YC4-LC
Linux 5.4Arista O-435E
Linux 5.4Arista C-400
Linux 5.4Arista C-430
Linux 5.4Arista C-460D
Linux 5.4Arista O-405
Linux 5.4Arista O-405E
EOSv4DCS-7060XE7-64PRS-RV3 with Intel Xeon D-1735TR
CloudVision ApplianceAny general-purpose computer (GPC) with any CPU
CloudVision as-a-Service (CVaaS)Any general-purpose computer (GPC) with any CPU
EOSv4DCS-7060X6-32PE with AMD Ryzen Embedded v3000
EOSv4CCS-710XP-12TH-2S with ARM Cortex-A55
EOSv4CCS-720XPM-48TH-6SY with AMD Ryzen Embedded R1600
EOSv4DCS-7050SX3-24YC4C-S with AMD Ryzen Embedded V1500B
EOSv4DCS-7280CR3AK-32S with AMD EPYC 3251
EOSv4DCS-7060DX4-32C-RV3 with Intel Pentium D1508
EOSv4DCS-7060DX4-32SB-RV3 with Intel Xeon D1527
Velocloud SD-WAN 7.0Edge 710-W with Intel Atom C1100
Velocloud SD-WAN 7.0Edge 710-5G with Intel Atom C1110
Velocloud SD-WAN 7.0Edge 720 with Intel Atom C1110
Velocloud SD-WAN 7.0Edge 740 with Intel Atom C1130
Velocloud SD-WAN 7.0Edge 4100 with Xeon D-2798NT
Velocloud SD-WAN 7.0Edge 5100 with Xeon Gold 6548N
Velocloud SD-WAN OS 7.0 on ESXi 8.0 and KVMIntel Xeon D and SP CPUs

Arista Networks, Inc. FIPS 140-3 Security Policy Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 19
Mode NameDescriptionTypeStatus Indicator
Approved ModeState in which the module is performing approved cryptographic servicesApproved1 (return code)
Non-Approved ModeState in which the module is performing non- approved cryptographic services (TDES)Non- Approved0 (return code)
AlgorithmCAVP CertPropertiesReference
AES-CBCA5259Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA5259Key Length - 128, 192, 256SP 800-38C
AES-CFB1A5259Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A5259Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A5259Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA5259Capabilities - Direction - Generation, Verification Key Length - 128SP 800-38B

Arista Networks, Inc. FIPS 140-3 Security Policy There are no components excluded from the module’s cryptographic boundary or the FIPS security requirements.

2.4 Modes of Operation

Modes List and Description: Table 5: Modes List and Description The module is able to alternate between the approved and non-approved mode of operation based on service invocation. In the non-approved mode of operation, the module can offer Triple-DES encryption and decryption. When the Triple-DES encrypt and decrypt services are called, the module transitions to the non-approved state and a static return code of ‘0’, representing the invocation of a non-approved service is returned from the module.

2.5 Algorithms

Approved Algorithms: The table below lists the approved cryptographic algorithms of the module and implemented modes of operation of the algorithms. Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 20
AlgorithmCAVP CertPropertiesReference
AES-CTRA5259Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5259Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA5259Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-KWA5259Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA5259Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-XTS Testing Revision 2.0A5259Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA5259Prediction Resistance - No, Yes Capabilities - Mode - AES-128 Derivation Function Enabled - NoSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A5259Curve - P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A5259Curve - P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A5259Capabilities - Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A5259Component - No Capabilities - Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-5)A5259Capabilities - Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-5
Hash DRBGA5259Prediction Resistance - No, Yes Capabilities - Mode - SHA-1SP 800-90A Rev. 1
HMAC DRBGA5259Prediction Resistance - No, Yes Capabilities - Mode - SHA-1SP 800-90A Rev. 1
HMAC-SHA-1A5259Key Length - Key Length: 112-2048 Increment 8FIPS 198-1

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 21
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 224A5259Key Length - Key Length: 112-2048 Increment 8FIPS 198-1
HMAC-SHA2- 256A5259Key Length - Key Length: 112-2048 Increment 8FIPS 198-1
HMAC-SHA2- 384A5259Key Length - Key Length: 112-2048 Increment 8FIPS 198-1
HMAC-SHA2- 512A5259Key Length - Key Length: 112-2048 Increment 8FIPS 198-1
HMAC-SHA3- 224A5259Key Length - Key Length: 112-2048 Increment 8FIPS 198-1
HMAC-SHA3- 256A5259Key Length - Key Length: 112-2048 Increment 8FIPS 198-1
HMAC-SHA3- 384A5259Key Length - Key Length: 112-2048 Increment 8FIPS 198-1
HMAC-SHA3- 512A5259Key Length - Key Length: 112-2048 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A5259Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A5259Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, MODP-2048, MODP-3072, MODP-4096, MODP- 6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF IKEv1 (CVL)A5259Capabilities - Authentication Method - Pre-shared Key Preshared Key Length - Preshared Key Length: 8- 8192 Increment 8 Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 1024-8192 Increment 1024 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF IKEv2 (CVL)A5259Capabilities - Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 1024-8192 Increment 1024 Derived Keying Material Length - Derived Keying Material Length: 256-2048 Increment 128 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF SP800- 108A5259Capabilities - KDF Mode - Counter Supported Lengths - Supported Lengths: 128SP 800-108 Rev. 1

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 22
AlgorithmCAVP CertPropertiesReference
KDF SSH (CVL)A5259Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KTS-IFCA5259Modulo - 2048, 3072, 4096 Key Generation Methods - rsakpg2-basic Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 512SP 800-56B Rev. 2
RSA KeyGen (FIPS186-5)A5259Capabilities - Key Generation Mode - probable Properties - Modulo - 2048 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186-5)A5259Capabilities - Properties - Modulo - 2048 Signature Type - pkcs1v1.5FIPS 186-5
RSA SigVer (FIPS186-4)A5259Capabilities - Signature Type - ANSI X9.31 Properties - Modulo - 1024FIPS 186-4
RSA SigVer (FIPS186-5)A5259Capabilities - Properties - Modulo - 2048 Signature Type - pkcs1v1.5FIPS 186-5
SHA-1A5259Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 4FIPS 180-4
SHA2-224A5259Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 4FIPS 180-4
SHA2-256A5259Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 4FIPS 180-4
SHA2-384A5259Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 4FIPS 180-4
SHA2-512A5259Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 4FIPS 180-4
SHA3-224A5259Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 4FIPS 202

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 23
AlgorithmCAVP CertPropertiesReference
SHA3-256A5259Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 4FIPS 202
SHA3-384A5259Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 4FIPS 202
SHA3-512A5259Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 4FIPS 202
TLS v1.2 KDF RFC7627 (CVL)A5259Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512SP 800-135 Rev. 1
NamePropertiesImplementationReference
CKG (Asymmetric)Key Type:AsymmetricArista Crypto ModuleNIST SP 800-133rev2, Section 4 (1), 5.1, 5.2
NameUse and Function
Triple-DESEncryption/decryption

Arista Networks, Inc. FIPS 140-3 Security Policy Table 6: Approved Algorithms Vendor-Affirmed Algorithms: The vendor affirms the approved implementation of the following security methods: Table 7: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. The module does not implement any non-approved algorithms allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. The module does not implement any non-approved algorithms, allowed in the approved mode of operation, with no security claimed. Non-Approved, Not Allowed Algorithms: Table 8: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 24
NameTypeDescriptionPropertiesAlgorithms
Data EncryptionBC-Auth BC-UnAuthSymmetric Encryptionkey size:128, 192, 256 bitsAES-CBC: (A5259) AES-CCM: (A5259) AES-CFB1: (A5259) AES-CFB128: (A5259) AES-CFB8: (A5259) AES-CTR: (A5259) AES-ECB: (A5259) AES-GCM: (A5259) AES-XTS Testing Revision 2.0: (A5259)
Data DecryptionBC-Auth BC-UnAuthSymmetric Encryptionkey size:128, 192, 256AES-CBC: (A5259) AES-CCM: (A5259) AES-CFB1: (A5259) AES-CFB128: (A5259) AES-CFB8: (A5259) AES-CTR: (A5259) AES-ECB: (A5259) AES-GCM: (A5259) AES-XTS Testing Revision 2.0: (A5259)
Key Derivation FunctionKAS-135KDF KBKDFKey Derivation FunctionKDF IKEv1: (A5259) KDF IKEv2: (A5259) KDF SSH: (A5259) TLS v1.2 KDF RFC7627: (A5259) KDF SP800- 108: (A5259)

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 25
NameTypeDescriptionPropertiesAlgorithms
Deterministic Random Bit GenerationDRBGDeterministic Random Bit GenerationCounter DRBG: (A5259) Hash DRBG: (A5259) HMAC DRBG: (A5259)
Digital SignatureDigSig-SigGen DigSig-SigVerRSA, ECDSA SigGen / SigVerECDSA SigGen (FIPS186-5): (A5259) ECDSA SigVer (FIPS186-4): (A5259) ECDSA SigVer (FIPS186-5): (A5259) RSA SigGen (FIPS186-5): (A5259) RSA SigVer (FIPS186-4): (A5259) RSA SigVer (FIPS186-5): (A5259)
Message AuthenticationMACGenerate or verify data integrityAES-CMAC: (A5259) HMAC-SHA-1: (A5259) HMAC-SHA2- 224: (A5259) HMAC-SHA2- 256: (A5259) HMAC-SHA2- 384: (A5259) HMAC-SHA2- 512: (A5259) HMAC-SHA3- 224: (A5259) HMAC-SHA3- 256: (A5259) HMAC-SHA3- 384: (A5259) HMAC-SHA3- 512: (A5259)
Key Agreement ECCKAS-SSCPerform key agreement primitives on behalf of the calling processSecurity Strength:Key establishment methodology providesKAS-ECC-SSC Sp800-56Ar3: (A5259)

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 26
NameTypeDescriptionPropertiesAlgorithms
(does not establish keys into the module)between 112 and 256 bits of encryption strength. Publication:NIST SP 800-56Arev3 IG:D.F - Scenario 2, Path (1)
Key Agreement FFCKAS-SSCPerform key agreement primitives on behalf of the calling process (does not establish keys into the module)Security Strength:Key establishment methodology provides between 112 and 200 bits of encryption strength. Publication:NIST SP 800-56Arev3 IG:D.F - Scenario 2, Path (1)KAS-FFC-SSC Sp800-56Ar3: (A5259)
Message digestSHAHashingSHA-1: (A5259) SHA2-224: (A5259) SHA2-256: (A5259) SHA2-384: (A5259) SHA2-512: (A5259) SHA3-224: (A5259) SHA3-256: (A5259) SHA3-384: (A5259) SHA3-512: (A5259)
Key GenerationAsymKeyPair- KeyGenKey Generation (asymmetric)Publication:NIST SP 800-133rev2 - Section 4 Publication:NIST SP 800-133rev2 - Section 5 Publication:NIST SP 800-133rev2 - Section 6.2.2ECDSA KeyGen (FIPS186-5): (A5259) ECDSA KeyVer (FIPS186-5): (A5259) KAS-ECC-SSC Sp800-56Ar3: (A5259)

Arista Networks, Inc. FIPS 140-3 Security Policy (1) (1) Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 27
NameTypeDescriptionPropertiesAlgorithms
KAS-FFC-SSC Sp800-56Ar3: (A5259) RSA KeyGen (FIPS186-5): (A5259) CKG (Asymmetric) : () Key Type: Asymmetric CKG: () Key Type: KBKDF Derived Key
Key TransportKTS-EncapKey Transport (encapsulation) using RSA- OAEPSecurity Strength:Key establishment methodology provides between 112 and 150 bits of encryption strength.KTS-IFC: (A5259)
Key WrappingKTS-WrapKey Wrapping using AES-KW or AES-KWPSecurity Strength:Key establishment methodology provides between 128 and 256 bits of encryption strength.AES-KW: (A5259) AES-KWP: (A5259)

Arista Networks, Inc. FIPS 140-3 Security Policy Table 9: Security Function Implementations

2.7 Algorithm Specific Information

The following algorithm specific information applies to algorithms used by the module in the approved mode of operation. SHA-1: Per NIST SP 800-131A rev3, usage of the SHA-1 service as part of digital signature generation is disallowed in the approved mode of operation. AES-GCM: Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 28

Arista Networks, Inc. FIPS 140-3 Security Policy Per FIPS 140-3 IG C.H, the module implements deterministic IV construction as described in NIST SP 800-38D, section 8.2.1. The IV is constructed internally, and deterministically, with a length of 96 bits. The module provides the AES-GCM service to the calling application in a manner compatible with the TLS v1.2 protocol per RFC5246 and using cipher suites listed in section 3.3.1 or NIST SP 800-52rev2. The module explicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values of 2^64-1 for a given session key. If this exhaustion condition is observed, the module returns an error indication to the calling application, which will then need to either abort the connection, or trigger a handshake to establish a new encryption key. In the event Module power is lost and restored the calling application must ensure that any AES GCM keys used for encryption or decryption are re-distributed. AES-XTS: Per NIST SP 800-38E, the module implements the AES-XTS algorithm. Per IG A.9, AES-XTS is to be used for storage applications only. The module performs the required key uniqueness check (Key_1 =/= Key_2) before processing data with the AES-XTS keys. The user shall enforce the length of the data unit used by any AES-XTS implementation does not exceed 2^20 blocks.

2.8 RBG and Entropy

N/A for this module. N/A for this module. The module’s entropy source is located within the TOEPP, but outside the cryptographic boundary of the module. The module passively receives entropy based on request by the calling applications and exercises no control over the amount of quality of the obtained entropy. As such, there is No assurance of the minimum strength of generated SSPs (e.g., keys). By default, the module requests 256 bits of entropy per request.

2.9 Key Generation

When generating asymmetric keys, the module uses the direct output of its approved DRBG to generate random numbers and seeding material, per the guidance in NIST SP 800-133rev2, Section 5.

2.10 Key Establishment

The module implements the following approved key agreement methods: Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 29
Physical PortLogical Interface(s)Data That Passes
N/AData InputThe module accepts data input through the input arguments of the API functions.
N/AData OutputThe module produces data output through the parameters of the API functions.
N/AControl InputThe module accepts control input through the input arguments of the API functions used to control the module.
N/AStatus OutputThe module produces status output through the return values from function calls and error messages.

Arista Networks, Inc. FIPS 140-3 Security Policy - KAS-ECC-SSC - NIST SP 800-56A Rev. 3 (FIPS 140-3 IG D.F, Scenario 2, Path (1) - KAS-FFC-SSC - NIST SP 800-56A Rev. 3 (FIPS 140-3 IG D.F, Scenario 2, Path (1) While the module implements the protocol-specific KDFs in support of key agreement operations, the module only offers cryptographic services at the API-level to calling applications and does not implement full key agreement within the module boundary. The module implements the following key transport method: - KTS-IFC – NIST SP 800-56B Rev. 2 (FIPS 140-3 IG D.G, Key Encapsulation/Unencapsulation) - AES Key wrapping using AES-KW and KWP (FIPS 140-3 IG D.G, Key Wrapping/Unwrapping)

2.11 Industry Protocols

The module implements approved cryptography to support the following industry-specific protocols: - IKEv1, IKEv2, SSH, TLS v1.2, MACsec However, the module only offers cryptographic services to calling applications and does not contain full implementations of industry protocols. No parts of the TLS protocol, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 10: Ports and Interfaces As a software cryptographic toolkit, all of the module’s interfaces are defined at the Software/Firmware Module Interface (SFMI). The FIPS-defined logical interfaces are mapped to specific calls via a well-defined API, with which the operator interacts. Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 30
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCrypto OfficerNone
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Data Encryption, DecryptionEncrypt or decrypt data1 (return code)Parameters , plaintext or ciphertext, keyStatus, ciphertext or plaintextData Encryption Data DecryptionCrypto Officer - AES Key: W,E - AES GCM Key: W,E
Key Derivation FunctionPerform key derivation using a key derivation function1 (return code)Parameters , key/passwo rdStatus, derived keyKey Derivation FunctionCrypto Officer - KDF Secret: G,R - TLS Pre- Master Secret: G,R - TLS

Arista Networks, Inc. FIPS 140-3 Security Policy The data output interface is inhibited when the module is performing self-tests, performing zeroisation, or while in an error state.

4 Roles, Services, and Authentication

N/A for this module. The module does not implement an authentication mechanism. The operator role of Crypto Officer is assumed implicitly.

4.2 Roles

Table 11: Roles The module only supports 1 role: Crypto Officer (CO). This role is assumed implicitly by the operator when performing an approved service.

4.3 Approved Services

The module performs the following approves services: W,E G,R Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 31
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Master Secret: G,R - KBKDF Key: G,R - KBKDF Derived Key: W,E - KDF Derived Key: W,E
Deterministi c Random Bit GenerationGenerate random numbers with SP800- 90A Rev 11 (return code)N/AStatus, random numberDeterministi c Random Bit GenerationCrypto Officer - Entropy Input: W,E,Z - DRBG 'V' Value: W,E - DRBG 'C' Value: W,E - DRBG Seed: G,E,Z - DRBG Key: W,E
Digital SignatureGenerate or verify RSA or ECDSA digital signatures1 (return code)Parameters , RSA / ECDSA keys, messageStatus, digital signatureDigital SignatureCrypto Officer - RSA Public Key: W,E - RSA Private Key: W,E - ECDSA

Arista Networks, Inc. FIPS 140-3 Security Policy G,R G,R W,E W,E 'V' W,E 'C' W,E G,E,Z W,E W,E Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 32
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Public Key: W,E - ECDSA Private Key: W,E
Message Authenticati onGenerate or verify data integrity1 (return code)Parameters , message, keyStatus, message authenticati on codeMessage Authenticati onCrypto Officer - AES GCM Key: W,E - AES CMAC Key: W,E - HMAC Key: W,E
Key AgreementPerform key agreement primitives on behalf of the calling process (does not establish keys into the module)1 (return code)Parameters , DH/ECDH keysStatus, shared secretKey Agreement ECC Key Agreement FFCCrypto Officer - DH Public Key: W,E - DH Private Key: W,E - DH Shared Secret: G - ECDH Public Key: W,E - ECDH Private Key: W,E - ECDH Shared Secret: G

Arista Networks, Inc. FIPS 140-3 Security Policy W,E W,E W,E W,E W,E G W,E W,E G Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 33
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Key GenerationGenerate and verify an asymmetri c keypair and DH parameter s1 (return code)ParametersStatus, keypairKey GenerationCrypto Officer - RSA Public Key: G,R - RSA Private Key: G,R - ECDSA Public Key: G,R - ECDSA Private Key: G,R - DH Public Key: G,R - DH Private Key: G,R - ECDH Public Key: G,R - ECDH Private Key: G,R
Key TransportTransport CSPs1 (return code)Parameters , plaintext or ciphertext key, transport key(s)Status, plaintext or ciphertext keyKey TransportCrypto Officer - Key Transpo rt Key: W,E
Key WrappingWrap CSPs for Transport1 (return code)Parameters , plaintext or ciphertext key,Status, plaintext or ciphertext keyKey WrappingCrypto Officer - AES Key: W,E

Arista Networks, Inc. FIPS 140-3 Security Policy G,R G,R G,R G,R G,R G,R G,R Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 34
NameDescripti onIndicatorInputs transport key(s)OutputsSecurity FunctionsSSP Access
Message digestGenerate a message digest1 (return code)Parameters , MessageStatus, Digest of the messageMessage digestCrypto Officer
ZeroizeZeroize all SSPs procedural ly by power cycling or unloading the moduleSuccessful completion (Procedur al)N/AN/ANoneCrypto Officer - AES Key: Z - AES GCM IV: Z - AES GCM Key: Z - AES CMAC Key: Z - HMAC Key: Z - Entropy Input: Z - DRBG 'C' Value: Z - DRBG 'V' Value: Z - DRBG Seed: Z - DRBG Key: Z - RSA Public Key: Z - RSA Private Key: Z - ECDSA Public Key: Z - ECDSA Private Key: Z

Arista Networks, Inc. FIPS 140-3 Security Policy 'C' 'V' Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 35
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
- DH Public Key: Z - DH Private Key: Z - DH Shared Secret: Z - ECDH Public Key: Z - ECDH Private Key: Z - ECDH Shared Secret: Z - Key Transpo rt Key: Z - KDF Secret: Z - KDF Derived Key: Z - TLS Pre- Master Secret: Z - TLS Master Secret: Z - KBKDF Key: Z - KBKDF Derived Key: Z
Perform Self-testsPerform the module1 (return code)N/AStatusNoneCrypto Officer

Arista Networks, Inc. FIPS 140-3 Security Policy Z Z Z Z Z Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 36
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
self-tests on demand
Show StatusCommand the module to output it's current status1 (return code)ParametersStatusNoneCrypto Officer
Show module's versioning informationCommand the module to output the module version1 (return code)ParametersStatusNoneCrypto Officer
NameDescriptionAlgorithmsRole
Data Encryption, Decryption (TDES)Encrypt or decrypt data using Triple-DES (Return code of '0' for non-approved service)Triple-DESCrypto Officer

Arista Networks, Inc. FIPS 140-3 Security Policy Table 12: Approved Services Table 13: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not support loading of external software.

5 Software/Firmware Security
5.1 Integrity Techniques

The module verifies the integrity of all software components within the cryptographic boundary using an HMAC-SHA2-256-based integrity technique. The module computes the HMAC digest of the entire software package that represents the module and compares the result against a stored pre-computed digest. The module’s pre-operational integrity check is performed automatically at module power-up. The module integrity check can be performed on demand by the module operator by rebooting Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 37
Storage Area NameDescriptionPersistence Type
RAMSystem MemoryDynamic
ExternalCalling ApplicationDynamic

Arista Networks, Inc. FIPS 140-3 Security Policy

5.3 Open-Source Parameters

The module is based on the open-source OpenSSL FIPS Provider, version 3.1.5. The module was built using the following open-source compiler: - GCC – Version 11.3.1 20221121 (Red Hat 11.3.1-4)

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The cryptographic module has control over its own SSPs. The EOSv4 operating system used by the module’s operational environment uses proper memory and process management to prevent unauthorized access to CSPs and uncontrolled modifications of SSPs while the module is in process space. The OS also ensures via process management that processes spawned by the module are owned by the module itself, and not by external processes/operators. The module does not persistently store SSPs.

7 Physical Security

The cryptographic module is a multi-chip standalone software module and does not include any physical components. Therefore, no physical security mechanisms or protections are implemented, and the section 7 requirements do not apply to the module.

8 Non-Invasive Security

The module does not claim any mitigations against non-invasive attacks. Additionally, there are no non-invasive attack mitigations outlined in Annex F of ISO/IEC 19790:2012. Therefore, the section 8 requirements do not apply to the module.

9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 14: Storage Areas Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 38
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
SSP InputExternalRAMPlaintextAutomatedElectronic
SSP OutputRAMExternalPlaintextAutomatedElectronic
SSP Output (Encrypted)RAMExternalEncryptedAutomatedElectronicKey Transport
SSP Input (Encrypted)ExternalRAMEncryptedAutomatedElectronicKey Transport
Zeroization MethodDescriptionRationaleOperator Initiation
Reboot HostRebootMemory is zeroized upon rebootOperator Initiated (Procedural)
Module UnloadModule UnloadModule unloaded from memoryOperator Initiated (Procedural)
API CallZeroize function runs automatically as part of services that temporarily store SSPsRuns cleanup routine, then frees all memory locations where SSPs are stored.Automatic (Part of other operator initiated services)

Arista Networks, Inc. FIPS 140-3 Security Policy The table above lists the SSP storage areas implemented by the module. The module does not implement persistent storage of SSPs, and only stores keys temporarily in RAM, within the process space of the module. Table 15: SSP Input-Output Methods The table above lists the SSP Input-Output methods implemented by the module. The module only inputs or outputs SSPs using automated, electronic means to and from within the module TEOPP. Table 16: SSP Zeroization Methods The module does not persistently store keys; therefore, all keys are held in the module’s process space in volatile memory and are effectively zeroized upon reboot of the host platform. The zeroize API function can be invoked by the calling application and zeroizes all SSPs in the module storage space. The module supports the keys and other SSPs listed in the table below: Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 39
NameDescriptionSize - Strengt hType - CategoryGenerate d ByEstablishe d ByUsed By
AES KeyAES Key (CBC, CFB, CTR, ECB)128,192, 256 - 128,192, 256Symmetric Key - CSPData Encryption Data Decryption
AES GCM IVAES-GCM Initialization Vector96 bits - -Key Componen t - CSPData Encryption Data Decryption
AES GCM KeyAES-GCM Key128,192, 256 - 128,192, 256Symmetric Key - CSPData Encryption Data Decryption
AES CMAC KeyCMAC Key128, 192, 256 - 128, 192, 256Symmetric Key - CSPData Encryption Data Decryption
HMAC KeyKey used for HMAC Operations≥ 112 bits - ≥ 112 bitsHMAC Key - CSPMessage Authenticatio n
Entropy InputExternally generated entropy used to seed the DRBG128 - 256 bits - 128 - 256 bitsEntropy - CSPDeterministic Random Bit Generation
DRBG 'C' ValueHash-DRBG State Value440 bits - -DRBG Internal State - CSPDeterministic Random Bit Generation
DRBG 'V' ValueDRBG Internal State Value128-256 bits - -DRBG Internal State - CSPDeterministic Random Bit Generation
DRBG SeedDRBG Internal State Value128 - 256 bits - 128 - 256 bitsDRBG Internal State - CSPDeterministic Random Bit Generation
DRBG KeyDRBG Internal State Value128 - 256 bits - 128 - 256 bitsDRBG Internal State - CSPDeterministic Random Bit Generation
RSA Public KeyPublic Key used for RSA operations≥ 1024 bits - 96 to 256 bitsRSA Keypair - PSPDigital SignatureDigital Signature
RSA Private KeyPrivate Key used for RSA operations≥ 2048 bits -RSA Keypair - CSPDigital SignatureDigital Signature

Arista Networks, Inc. FIPS 140-3 Security Policy h Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 40
NameDescriptionSize - Strengt hType - CategoryGenerate d ByEstablishe d ByUsed By
112 to 256 bits
ECDSA Public KeyPublic Key used for EC operations256 to 521 bits - 128 to 256 bitsEC Keypair - PSPDigital SignatureDigital Signature
ECDSA Private KeyPrivate Key used for EC operations256 to 521 bits - 128 to 256 bitsEC Keypair - CSPDigital SignatureDigital Signature
DH Public KeyDH Public Key2048 – 8192 bits - 112 to 200 bitsDH Keypair - PSPKey Agreemen t FFCKey Agreement FFC
DH Private KeyDH Private Key2048 – 8192 bits - 112 to 200 bitsDH Keypair - CSPKey Agreemen t FFCKey Agreement FFC
DH Shared SecretDH Shared Secret2048 – 8192 bits - 112 to 256 bitsDH Shared Secret - CSPKey Agreement FFCKey Agreement FFC
ECDH Public KeyECDH Public Key224 - 521 bits - 112 to 256 bitsECDH Keypair - PSPKey Agreemen t ECCKey Agreement ECC
ECDH Private KeyECDH Private Key224 - 521 bits - 112 to 256 bitsECDH Shared Secret - CSPKey Agreemen t ECCKey Agreement ECC
ECDH Shared SecretECDH Shared Secret112 to 256 bits - 112 to 256 bitsECDH Shared Secret - PSPKey Agreement ECCKey Agreement ECC
Key Transpor t KeyKey Transport Key128 to 256 bits - 128 to 256 bitsKey Transport - CSPKey Transport
KDF SecretSecret used for KDF operations≥ 112 bits - ≥ 112 bitsKDF Secret - CSPKey Derivation Function Key Agreemen t ECCKey Derivation Function

Arista Networks, Inc. FIPS 140-3 Security Policy h Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 41
NameDescriptionSize - Strengt hType - CategoryGenerate d By Key Agreemen t FFCEstablishe d ByUsed By
KDF Derived KeyKey resulting from the module’s SP 800-135rev1 KDFs≥ 112 bits - ≥ 112 bitsKDF Key - CSPKey Derivation FunctionKey Derivation Function
TLS Pre- Master SecretShared Secret used for TLS session establishmen t112 to 256 bits - 112 to 256 bitsKDF Secret - CSPKey Derivation Function
TLS Master SecretMaster Secret used for TLS session112 to 256 bits - 112 to 256 bitsKDF Secret - CSPKey Derivation Function
KBKDF KeyKey used for key based key derivation112 to 256 bits - 112 to 256 bitsKDF Key - CSPKey Derivation Function
KBKDF Derived KeyKey resulting from the module’s KBKDF≥ 112 bits - ≥ 112 bitsSymmetric Key - CSPKey Derivation FunctionKey Derivation Function
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API Call
AES GCM IVSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API Call
AES GCM KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallAES GCM IV:Derived From

Arista Networks, Inc. FIPS 140-3 Security Policy h t Table 17: SSP Table 1 Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 42
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES CMAC KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API Call
HMAC KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API Call
Entropy InputSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API Call
DRBG 'C' ValueSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallDRBG 'V' Value:Used With
DRBG 'V' ValueSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallDRBG 'C' Value:Used With
DRBG SeedSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API Call
DRBG KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API Call
RSA Public KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallRSA Private Key:Paired With
RSA Private KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallRSA Public Key:Paired With
ECDSA Public KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host ModuleECDSA Private Key:Paired With

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 43
NameInput - OutputStorageStorage DurationZeroization Unload API CallRelated SSPs
ECDSA Private KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallECDSA Public Key:Paired With
DH Public KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallDH Private Key:Paired With
DH Private KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallDH Public Key:Paired With
DH Shared SecretSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallDH Public Key:Used With DH Private Key:Used With
ECDH Public KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallECDH Private Key:Paired With
ECDH Private KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallECDH Public Key:Paired With
ECDH Shared SecretSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallECDH Public Key:Used With ECDH Private Key:Used With
Key Transport KeySSP Input SSP Output SSP Output (Encrypted) SSP Input (Encrypted)RAM:Plaintext RAM:Encrypted External:Plaintext External:EncryptedUntil RebootReboot Host Module Unload API Call
KDF SecretSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API Call

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 44
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
KDF Derived KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallKDF Secret:Derived From
TLS Pre- Master SecretSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallTLS Master Secret:Used With
TLS Master SecretSSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallTLS Pre-Master Secret:Derived From
KBKDF KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallKBKDF Derived Key:Used With
KBKDF Derived KeySSP Input SSP OutputRAM:Plaintext External:PlaintextUntil RebootReboot Host Module Unload API CallKBKDF Key:Derived From
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-256 (A5259)HMAC-SHA2- 256KATSW/FW Integritystatus output

Arista Networks, Inc. FIPS 140-3 Security Policy Table 18: SSP Table 2

10 Self-Tests
10.1 Pre-Operational Self-Tests

The module performs the following pre-operational self-test: Table 19: Pre-Operational Self-Tests The pre-operational integrity self-test is performed after the module is instantiated, but before the module transitions to the approved mode of operation. The HMAC-SHA2-256 CAST is performed conditionally, before the integrity test, and therefore before the first operational use of the algorithm. Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 45
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A5259)128 bitsKATCASTSuccessful initialization of the moduleEncryptModule Initialization
AES-ECB (A5259)128 bitsKATCASTSuccessful initialization of the moduleDecryptModule Initialization
KDF SP800-108 (A5259)KATCASTSuccessful initialization of the moduleKDF KATModule Initialization
KAS-FFC- SSC Sp800- 56Ar3 (A5259)p=2048, q=256KATCASTSuccessful initialization of the moduleComputation of shared secret 'Z' (dhEphem)Module Initialization
KAS-ECC- SSC Sp800- 56Ar3 (A5259)P-256KATCASTSuccessful initialization of the moduleComputation of shared secret 'Z' (Ephemeral Unified)Module Initialization
ECDSA KeyGen (FIPS186- 5) (A5259)P-256PCTPCTSuccess or failure of serviceSign and Verify PCTKeypair generation
RSA KeyGen (FIPS186- 5) (A5259)2048-bitPCTPCTSuccess or failure of serviceSign and Verify PCTKeypair generation
AES-XTS Testing Revision 2.0 (A5259)Check to confirm Key1 ≠ Key2Key CheckPCTSuccess or failure of serviceXTS Key Check Check to confirm Key1 ≠ Key2 Key check Critical Function Success or failure of service Per IG C.IXTS Key entry
SHA-1 (A5259)SHA-1KATCASTSuccessful initialization of the moduleHash and compare digestModule Initialization

Arista Networks, Inc. FIPS 140-3 Security Policy

10.2 Conditional Self-Tests

The module performs the following conditional self-tests: Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 46
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-256 (A5259)SHA2-256KATCASTSuccessful initialization of the moduleHash and compare digestModule Initialization
SHA2-512 (A5259)SHA2-512KATCASTSuccessful initialization of the moduleHash and compare digestModule Initialization
SHA3-256 (A5259)SHA3-256KATCASTSuccessful initialization of the moduleHash and compare digestModule Initialization
SHA3-512 (A5259)SHA3-512KATCASTSuccessful initialization of the moduleHash and compare digestModule Initialization
TLS v1.2 KDF RFC7627 (A5259)SHA2-256KATCASTSuccessful initialization of the moduleKDF KATModule Initialization
HMAC- SHA2-256 (A5259)HMAC- SHA2-256KATCASTSuccessful initialization of the moduleMAC KATModule Initialization
KDF IKEv1 (A5259)SHA2-256KATCASTSuccessful initialization of the moduleKDF KATModule Initialization
KDF IKEv2 (A5259)SHA2-256KATCASTSuccessful initialization of the moduleKDF KATModule Initialization
KDF SSH (A5259)AES-128, SHA2-256KATCASTSuccessful initialization of the moduleKDF KATModule Initialization
KTS-IFC (A5259)2048-bit, SHA2-256, Key Length 256-bitsKATCASTSuccessful initialization of the moduleKey encapsulation test per SP 800- 56Brev2 and IG 10.3.AModule Initialization
Counter DRBG (A5259)AES-128KATCASTSuccessful initialization of the moduleInstantiate, Reseed, and Generate - Combined KAT per IG 10.3.AModule Initialization

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 47
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Hash DRBG (A5259)SHA2-256KATCASTSuccessful initialization of the moduleInstantiate, Reseed, and Generate - Combined KAT per IG 10.3.AModule Initialization
HMAC DRBG (A5259)HMAC- SHA2-256KATCASTSuccessful initialization of the moduleInstantiate, Reseed, and Generate - Combined KAT per IG 10.3.AModule Initialization
ECDSA SigGen (FIPS186- 5) (A5259)P-256KATCASTSuccessful initialization of the moduleSign and Verify KATModule Initialization
RSA SigGen (FIPS186- 5) (A5259)2048-bitKATCASTSuccessful initialization of the moduleSign and Verify KATModule Initialization
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 256 (A5259)KATSW/FW IntegrityUser initiated module rebootOn demand self- test service
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A5259)KATCASTUser initiated module rebootPerform Self- tests service
AES-ECB (A5259)KATCASTUser initiated module rebootPerform Self- tests service
KDF SP800-108 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
KAS-FFC-SSC Sp800-56Ar3 (A5259)KATCASTUser initiated module rebootPerform Self- tests service

Arista Networks, Inc. FIPS 140-3 Security Policy Table 20: Conditional Self-Tests Conditional CASTs are performed at module initialization, after the module integrity test, and before the first operational use of the algorithms. Pairwise consistency tests are performed conditionally upon generation of an asymmetric keypair. guidance in IG 10.3.A, Resolution 7. Table 21: Pre-Operational Periodic Information Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 48
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-ECC-SSC Sp800-56Ar3 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
ECDSA KeyGen (FIPS186-5) (A5259)PCTPCTWhen ECDSA keypairs are generatedAs part of the Digital Signature Service
RSA KeyGen (FIPS186-5) (A5259)PCTPCTWhen RSA keypairs are generatedAs part of the Digital Signature Service
AES-XTS Testing Revision 2.0 (A5259)Key CheckPCTUser initiated module rebootPerform Self- tests service
SHA-1 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
HMAC-SHA2- 256 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
SHA2-512 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
SHA3-256 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
SHA3-512 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
TLS v1.2 KDF RFC7627 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
HMAC-SHA2- 256 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
KDF IKEv1 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
KDF IKEv2 (A5259)KATCASTUser initiated module rebootPerform Self- tests service
KDF SSH (A5259)KATCASTUser initiated module rebootPerform Self- tests service
KTS-IFC (A5259)KATCASTUser initiated module rebootPerform Self- tests service
Counter DRBG (A5259)KATCASTUser initiated module rebootPerform Self- tests service
Hash DRBG (A5259)KATCASTUser initiated module rebootPerform Self- tests service
HMAC DRBG (A5259)KATCASTUser initiated module rebootPerform Self- tests service
ECDSA SigGen (FIPS186-5) (A5259)KATCASTUser initiated module rebootPerform Self- tests service
RSA SigGen (FIPS186-5) (A5259)KATCASTUser initiated module rebootPerform Self- tests service

Arista Networks, Inc. FIPS 140-3 Security Policy Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 49
NameDescriptionConditionsRecovery MethodIndicator
ErrorThe module's error state.POST or CAST failureReload / Reboot Modulereturn code: "0x0"

Arista Networks, Inc. FIPS 140-3 Security Policy Table 22: Conditional Periodic Information The module can perform the periodic pre-operational, and conditional self-tests procedurally, on demand, by power cycling the host platform.

10.4 Error States

Table 23: Error States Failure of any module self-test will cause the module to set an internal flag and transition to the error state. In the error state, all cryptographic functions are inhibited. The data output interface is also inhibited when the module is in the error state. Any further requests to the module for cryptographic services will cause the module to return an error indicator. To recover from the error state, the host platform must be power cycled. Power cycling will cause the module to perform the pre-operational self-tests and transition to the approved mode of operation. Optional statement - If the module self-tests continue to fail after rebooting, the CO should contact Arista Networks, Inc. for assistance.

10.5 Operator Initiation of Self-Tests

The module operator can initiate the pre-operational and conditional self-tests by power cycling the host platform.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The cryptographic module is distributed as part of Arista products, in the images accessible through the Arista software downloads portal. Products bundle together the operating system, applications, OpenSSL, and fips.so. While there is no need for the module to be built by the user at any point in time, it can be verified as the correct one by checking an unique version identifier, embedded into the module during the build process. The version identifier can be checked by issuing the following command: objcopy --dump-section .rodata2=/dev/stdout $(openssl info -modulesdir)/fips.so && echo The output of the above command should be: e8271acdca4674621a29e55d83fdbfb8990fbeb56b1a6eaf34082e562e5261e1

11.2 Administrator Guidance

Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)

Page 50

Arista Networks, Inc. FIPS 140-3 Security Policy The module comes pre-configured on the Arista device and will perform approved services without any operator intervention.

11.3 Non-Administrator Guidance

The module only implements the crypto-officer role, which is implicitly assumed. Therefore, there is no separate guidance required for non-administrator usage of the module.

12 Mitigation of Other Attacks

The module implements mitigations against 2 types of timing attacks against digital signature services. Digital signature timing attacks involve measuring either the total processing time of digital signature and RSA operations, or the differences in execution times of processes during cryptographic operations. The module implements mitigations against 2 types of timing attacks. Constant-time implementations: Constant-time implementations regulate the execution time deltas between cryptographic operations to prevent an attacker from reverse-engineering sensitive data or cryptographic keys during processing. Numeric blinding: Numeric blinding uses random values during RSA processing. Those values act as a blinding factor preventing the attacker from determining which operation has been called and what processed data was via measuring the total execution time of the cryptographic operation. Arista Networks Inc. Public Material – May be reproduced only in its original entirety (without revision)