All modules
CMVP Validated Module · FIPS 140-3 Security Policy

BCM58202B0

Certificate#5007StandardFIPS 140-3Level3TypeHardwareEmbodimentSingle ChipStatusActiveVendorBroadcom, Inc.
Medium review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 15 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level3
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date4/20/2030
CaveatNone
VendorBroadcom, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for BCM58202B0
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for BCM58202B0
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Broadcom, Inc. BCM58202B0 Document Version: 1.2 Date: April 09, 2025 Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 2
Table of Contents
#SectionPage
Page 3

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware7
Table 3: Modes List and Description7
Table 4: Approved Algorithms9
Table 5: Vendor-Affirmed Algorithms10
Table 6: Security Function Implementations13
Table 7: Entropy Certificates13
Table 8: Entropy Sources13
Table 9: Ports and Interfaces15
Table 10: Authentication Methods17
Table 11: Roles18
Table 12: Approved Services23
Table 13: Mechanisms and Actions Required26
Table 14: EFP/EFT Information26
Table 15: Hardness Testing Temperatures27
Table 16: Storage Areas29
Table 17: SSP Input-Output Methods29
Table 18: SSP Zeroization Methods29
Table 19: SSP Table 131
Table 20: SSP Table 232
Table 21: Pre-Operational Self-Tests33
Table 22: Conditional Self-Tests36
Table 23: Pre-Operational Periodic Information37
Table 24: Conditional Periodic Information38
Table 25: Error States39
Figure 1 – [Model 1]6
Page 5
SectionTitleSecurity Level
1General3
2Cryptographic module specification3
3Cryptographic module interfaces3
4Roles, services, and authentication3
5Software/Firmware security3
6Operational environmentN/A
7Physical security3
8Non-invasive securityN/A
9Sensitive security parameter management3
10Self-tests3
11Life-cycle assurance3
12Mitigation of other attacksN/A
Overall Level3

this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 3 module.

1.2 Security Levels

The FIPS 140-3 security levels for the Module are as follows from Table 1: Table 1: Security Levels

1.3 Additional Information

The Module is a highly integrated SoC (System on a Chip). It is marketed with part number BCM58202PB0KFBG10 and is ideally suited for end point security protection applications. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 6

2 – Cryptographic Module Specification

2.1 Description

Purpose and Use: The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated cryptographic based security systems to protect sensitive information, access, usage, of computer, telecommunication systems, and property. The Module is intended to be used in commercial personal computers, point of sales terminals, access control devices in physically or electronically access restricted areas. Module Type: Hardware Module Embodiment: SingleChip Cryptographic Boundary: The physical form of the Module is depicted in Figure 1. The Module is a single-chip embodiment. The cryptographic module is encapsulated in an opaque and tamper resistant package material. The cryptographic boundary is the outer perimeter of the IC packaging. Figure 1

Page 7
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
BCM58202B0BCM58202PB0KFBG10SBL Version: 1.1 SBI Version: 1.0 AAI Version: 2.1BCM58202B0BCM58202B0 single-chip SoC
Mode NameDescriptionTypeStatus Indicator
Approved ModeThe module only supports an Approved mode of operation.ApprovedRESET_OUT_L is high and UART prints the message, “The Device is running in FIPS operational mode: 0xFFFF
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

There were no components that were excluded from the cryptographic boundary. Modes List and Description: Table 3: Modes List and Description does not support a non-Approved mode of operation. The module cannot be configured to operate in a non-compliant state. The Cryptographic Officer (CO) can confirm the Approved Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 8
AlgorithmCAVP CertPropertiesReference
AES-CBCAES 5895Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMAES 5896Key Length - 128, 192, 256SP 800-38C
AES-CTRAES 5895Key Length - 128, 192, 256SP 800-38A
AES-ECBAES 5895Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
Counter DRBGA3753Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
DSA SigGen (FIPS186-4)A4437L - 2048 N - 256 Hash Algorithm - SHA2-256FIPS 186-4
DSA SigVer (FIPS186-4)A4437L - 2048 N - 256 Hash Algorithm - SHA2-256FIPS 186-4
ECDSA KeyGen (FIPS186- 4)A3751Curve - P-256 Secret Generation Mode - Extra BitsFIPS 186-4

In addition, the CO can confirm they are using the appropriate version of the module by consulting the output of the “Get info” service: Global Indicator (4) Global Indicator: 00 00 ff ff SBL Version (2) SBL Version: 01 01 SBI Version (2) SBI Version: 01 00 AAI Version (2) AAI Version: 02 01 CHIP Version: BCM58202PB0KFBG10 BCM58202B0 is configured during manufacturing to operate in the Approved mode. The CO is responsible for confirming the appropriate versions of the SBI and AAI are loaded; no additional configuration is required.

2.5 Algorithms

Approved Algorithms: The Module implements the Approved cryptographic algorithms listed in the table below. 4) Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 9
AlgorithmCAVP CertPropertiesReference
ECDSA KeyVer (FIPS186- 4)A3751Curve - P-256FIPS 186-4
ECDSA SigGen (FIPS186- 4)A3751Component - No Curve - P-256, P-384 Hash Algorithm - SHA2-256FIPS 186-4
ECDSA SigVer (FIPS186- 4)A3751Component - No Curve - P-256, P-384 Hash Algorithm - SHA2-256FIPS 186-4
HMAC-SHA2-256HMAC 3870-FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A3751Domain Parameter Generation Methods - P-256 Scheme - ephemeralUnified - KAS Role - responderSP 800-56A Rev. 3
KDA OneStepNoCounter SP800-56Cr2A3752Key Length - Key Length: 256SP 800-56C Rev. 2
RSA SigGen (FIPS186-4)A3750Signature Type - PKCS 1.5 Modulo - 2048, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A3750Signature Type - PKCS 1.5 Modulo - 2048, 4096FIPS 186-4
SHA2-256SHS 4646Message Length - Message Length: 0-51200 Increment 8FIPS 180-4
SHA3-224SHA-3 60-FIPS 202
SHA3-256SHA-3 60-FIPS 202
SHA3-384SHA-3 60-FIPS 202
SHA3-512SHA-3 60-FIPS 202

4) 4) 4) Table 4: Approved Algorithms KAS [56Ar3] - Per [IG] D.F Scenario 2 path (2), compliant key agreement scheme where testing is performed end-to-end for the shared secret computation and a KDA compliant with SP80056Cr2 without key confirmation. Vendor-Affirmed Algorithms: The Module implements the Vendor Affirmed cryptographic algorithms listed. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 10
NamePropertiesImplementationReference
CKG- SymCapabilities:Sections 4 and 6.1 Direct symmetric key generation using unmodified DRBG output; Section 6.2.1 Derivation of symmetric keys from a key agreement shared secretDRBG (A3753)SP800- 133r2, IG [D.H]
CKG- AsymCapabilities:Sections 4 and 5.1 Asymmetric signature key generation using unmodified DRBG output; Sections 4 and 5.2 Asymmetric key establishment key generation using unmodified DRBG outputECDSA KeyGen (A3751)SP800- 133r2, IG [D.H]
NameTypeDescriptionPropertiesAlgorithms
AKGAsymKeyPair- KeyGenAsymmetric Key-Pair GenerationPublications:FIPS 186-4, SP800-90A, IG C.A, IG C.ECKG-Asym Curve: P-256 ECDSA KeyGen (FIPS186-4) Counter DRBG
AKVAsymKeyPair- KeyVerAsymmetric Key-Pair VerificationPublications:FIPS 186-4, SP800-90A, IG C.A, IG C.EECDSA KeyVer (FIPS186-4) Curve: P-256
DPGAsymKeyPair- DomParDomain ParametersPublication:SP800- 56Ar3KAS-ECC-SSC Sp800-56Ar3 Curve: P-256 Counter DRBG

[D.H] Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 11
NameTypeDescriptionPropertiesAlgorithms
DRBGDRBGRandom Number GenerationPublication:SP800- 90ACounter DRBG Capabilities: AES- 256 w/ Derivation Function
ENCBC-UnAuthBlock CipherPublication:FIPS 197, SP800-38AAES-CBC Key Size: 128, 192, 256 AES-CTR Key Size: 128, 192, 256 AES-ECB Key Size: 128, 192, 256
ENC-AUTHBC-AuthAuthenticated Block CipherPublication:FIPS 197, SP800-38CAES-CCM Key Size: 128, 192, 256
CKG- SymmetricCKGSymmetric Key GenerationPublication:IG D.H, FIPS 197, SP800-133r2 Sections 4 and 6.1 Direct symmetric key generation using unmodified DRBG outputCounter DRBG Key Size: 128, 192, 256
SigGenDigSig-SigGenDigital Signature GenerationPublication:FIPS 186-4, SP800-90A, FIPS 180-4DSA SigGen (FIPS186-4) Key Size: 2048 ECDSA SigGen (FIPS186-4) Curve: P-256, P- 384 RSA SigGen (FIPS186-4) Key Size: 2048, 4096 SHA2-256 Counter DRBG
SigVerDigSig-SigVerDigital Signature VerificationPublication:FIPS 186-4, SP800-90A, FIPS 180-4DSA SigVer (FIPS186-4) Key Size: 2048 ECDSA SigVer (FIPS186-4) Curve: P-256, P- 384 RSA SigVer

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 12
NameTypeDescriptionPropertiesAlgorithms
(FIPS186-4) Key Size: 2048, 4096 SHA2-256 Counter DRBG
ESVENT-ESVEntropy SourcePublication:SP800- 90B, IG 9.3.A, IG D.J, IG D.OCounter DRBG Security Strength: 256
KASKAS-FullKey AgreementPublication:SP800- 56Ar3, SP800- 56Cr2 Caveat:Key establishment method provides 128 bits of encryption strengthKAS-ECC-SSC Sp800-56Ar3 Scheme: Ephemeral Unified (Responder) Curve: P-256 KDA OneStepNoCounter SP800-56Cr2 Auxiliary Function: SHA2- 256 Key Length: 128 Counter DRBG
KTSKTS-WrapKey Transport - WrappingPublication:FIPS 197, SP800-38F, IG D.G Caveat:Key establishment methodology provides 128 bits of encryption strengthAES-CCM Key Size: 128
MACMACMessage Authentication CodePublication:FIPS 198-1, FIPS 180-4, IG C.BHMAC-SHA2-256 Capabilities: Key size < Block size
SHSSHASecure Hash StandardPublication:FIPS 180-4, FIPS 202, IG C.B, IG C.CSHA2-256 Message Length: 0 - 51200 Increment 8 SHA3-224 Message Length: 0 - 51200 Increment 8 SHA3-256 Message Length: 0 - 51200 Increment

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 13
NameTypeDescriptionPropertiesAlgorithms
8 SHA3-384 Message Length: 0 - 51200 Increment 8 SHA3-512 Message Length: 0 - 51200 Increment 8
CertVendor
NumberName
E35broadcom
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
E35PhysicalBCM58202B032 bitsMinimum of 4 bitsN/A

Table 6: Security Function Implementations

2.7 Algorithm Specific Information

The module does not have any algorithm specific information.

2.8 RBG and Entropy

Table 7: Entropy Certificates The Module uses the following entropy sources: Table 8: Entropy Sources The entropy source produces 4 bits of entropy per 32 bit sample. When instantiating the DRBG, the module will collect a total of 3072 bits from the entropy source, which has a total of 384 bits of entropy. Per SP800-90Arev1, the module must provide security_strength bits of entropy (i.e., 256-bits) plus another security_strength/2 (i.e., 128-bits) to instantiate a CTR_DRBG to a security strength of 256 bits.

2.9 Key Generation

For Key Generation methods, see Section 2.6 Security Function Implementations above. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 14
2.10 Key Establishment

Key Agreement Information For Key Establishment methods, see Section 2.6 Security Function Implementations above. The module supports KAS-ECC per SP800-56Ar3 using the Ephemeral Unified scheme with the NISTrecommended curve P-256, as tested under CAVP Cert. #A3751. The module employs the SP 800-56Cr2 OneStepKDF, which was validated under CAVP Cert. #A3752. No key confirmation is supported. Key and seed generation is performed in compliance with NIST SP 800-133r2, Section 4, per 140-3 IG D.H without any post-processing. ECDSA Key Generation was tested under CAVP Cert. #A3751 using extra random bits, whereby an extra 64 bits are generated from the Approved DRBG (CAVP Cert. #A3753. Full public key validation is performed according to SP 800-56Ar3, Section 5.6.2.3.3, on both the generated public key, as well as any received public key. All temporary values used during the key agreement process are zeroized after the shared key is established. Key Transport Information For Key Transport methods, see Section 2.6 Security Function Implementations above.

2.11 Industry Protocols

The module does not implement any Industry Protocols> Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 15
Physical PortLogical Interface(s)Data That Passes
Clock groupControl Input Status OutputClock - 26MHz clock - 32KHz clock; Clock output - 26MHz clock output
Reset groupControl Input Status OutputOne reset input; Reset output: Indicates that system power supply is stable.
ZeroisationControl Input Status OutputZeroisation request input (MANU_DEBUG)
SPI groupData InputCode and data from SPI flash (clock, device select, and four data I/O). All Code/Data Input is authenticated by the module.
USB groupData Input Data Output Control Input Status OutputService request input; Service response output; (USB differential data bus); Device interface used by the CO to make service requests. Requests are authenticated via the KAS secure session.
UART groupStatus OutputStatus output (Four UART ports of four signals each.)
Power groupPowerOver 50 power and ground pins. Power is distributed to the chip using designated IO and core power pins that are completely separated from any signal pin groups. Power pins are only connected to the internal power planes of the silicon chip.
AlertData InputTamper, Voltage, or Temperature event
3 Cryptographic Module Interfaces

The Module’s ports and associated defined logical interface categories are listed below. below contains several BCM58202B0 pins. Unused Interface Groups will be marked as “Disabled” because they are disabled by the cryptographic module. The Module does not provide control output to other cryptographic modules or peripherals performing any cryptographic operations. Table 9: Ports and Interfaces Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 16

Note: The module does not support Control Output. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 17
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Signature VerificationThe CO role is authenticated by the verification of an ECDSA digital signature using a P-256 key.SigVerThe probability that a random attempt will succeed or a false acceptance will occur is 1/2^128 which is less than 1/1,000,000.Based on performance limitations, the probability of successfully authenticating to the module within one minute is 3,750/2^128 which is less than 1/100,000. The module will only allow one attempt to verify the CO – if that attempt fails, the module will be in an error state and must be rebooted to try and become operational again
4 Roles, Services, and Authentication
4.1 Authentication Methods

Authentication is accomplished via a 256-bit ECDSA-based signature verification process using KOP-PUB. During the manufacturing process, the ECDSA private key, KDI-EC-PRIV, is loaded into SOTP of the Module and the corresponding public key, KDI-EC-PUB, resides in SRAM. KDI-ECPUB is used to authenticate the module to the operator during the establishment of a secure session. session does not persist across power cycles. The Cryptographic Officer must be authenticated to establish a secure session before any cryptographic services are rendered. In addition to the CO, the Module supports services which do not require authentication, listed as UA in Approved Services table. The Module does not support a maintenance role or bypass capability. The Module does not support concurrent operators. The role of the CO is authenticated via the establishment of a mutually authenticated KAS session with ECDSA-based signatures. CO authentication is not carried over a terminated secure session or power cycle. A new secure session requires a complete CO authentication process. Table 10: Authentication Methods

4.2 Roles

The Module supports a single distinct operator role, the Cryptographic Officer (CO). Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 18
NameTypeOperator TypeAuthentication Methods
Cryptographic OfficerIdentityCOSignature Verification
NameDescrip tionIndicato rInputsOutputsSecuri ty Functi onsSSP Access
Get InfoShow module, versions , global indicato r informa“Succee ded”; “Failed”None=Return Module ID (ECDSA public key). Information returned to CO: Module Info Dump Global Indicator: (4)NoneCryptogra phic Officer - KDI-EC- PUB: R Unauthenti cated

The Roles Table below lists all operator roles supported by the Module. The Module does not support concurrent operators. The CO’s Public Key is installed in the SBI. It is protected with the SBI signature. SBI is also integrity protected with a CRC32 checksum. Only one CO public key is present in the SBI. The BCM58202B0 Cryptographic Module supports a single operator role: Cryptographic Officer. Only the authorized operator can establish a secure session with the cryptographic module. The cryptographic module implements identity-based operator authentication to allow only the authorized operator to Authentication is accomplished via a 256-bit ECDSA-based signature verification process. A single 256-bit ECDSA public key is embedded in the SBI. The 256-bit ECDSA public key is used to authenticate the CO during the establishment of a secure session between the module and the CO on the external host system. Table 11: Roles

4.3 Approved Services

All approved services implemented by the Module are listed in the table below: The SSPs modes of access shown in the table below are defined as:

G = Generate: The Module generates or derives the SSP.
R = Read: The SSP is read from the Module (e.g., the SSP is output).
W = Write: The SSP is updated, imported, or written to the Module (SSP is input).
E = Execute: The Module uses the SSP in performing a cryptographic operation.
Z = Zeroize: The Module zeroizes the SSP

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 19
NameDescrip tion tion and StatusIndicato rInputsOutputs Global Indicator: 00 00 ff ff SBL Version: (2) SBL Version: 01 01 SBI Version: (2) SBI Version: 01 00 AAI Version: (2) AAI Version: 02 01 CHIP Version: BCM58202PB0 KFBG10Securi ty Functi onsSSP Access - KDI-EC- PUB: R
Symmetric_encr yptSymmet ric encrypti on of plaintex t message“Succee ded”; “Failed”Input data, input size, key, key size, mode of operation Input : 128 bit blocks of plaintext Key size: 128, 192, 256 bit Modes: ECB, CBC, CTRReturn the ciphertext or an error statusENCCryptogra phic Officer - KAPP- AES: E
Symmetric_decr yptSymmet ric decrypti on of cipherte xt“Succee ded”; “Failed”Encrypte d input data, input size, key, key size, mode of operation Input : 128 bit blocks of ciphertexReturn the plaintext or an error statusENCCryptogra phic Officer - KAPP- AES: E

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 20
NameDescrip tionIndicato rInputs t Key size : 128, 192, 256 bit Modes : ECB, CBC, CTROutputsSecuri ty Functi onsSSP Access
Symmetric_key_ genGenerat e AES or HMAC key in selected key slot“Succee ded”; “Failed”Selection of AES or HMAC key slot for key genKey generation complete statusDRBG CKG- Symm etric ESVCryptogra phic Officer - DRBG- EI and Seed: G,E - DRBG- State: G,E - KAPP- AES: G - KAPP- HMAC: G
Symmetric_key_ importLoad AES or HMAC key in selected key slot“Succee ded”; “Failed”Selection of AES or HMAC key slot for key importLoad statusKTSCryptogra phic Officer - KAPP- AES: W - KAPP- HMAC: W - KKAS- SS: E
Asymmetric_sig _genGenerat e signatur e“Succee ded”; “Failed”Key/Cur ve size, private key, plaintext messageDigital signature of messageSigGenCryptogra phic Officer - KAPP- PRIV: E
Asymmetric_sig _verSignatur e verificat ion“Succee ded”; “Failed”Key/Cur ve size, public key, signatureStatus of signature verificationSigVerCryptogra phic Officer - KAPP- PUB: E

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 21
NameDescrip tionIndicato rInputsOutputsSecuri ty Functi onsSSP Access
Asymmetric_key _genGenerat e ECDSA P-256 Key Pair“Succee ded”; “Failed”Key slotKey generation complete statusAKG AKV DPG DRBG ESVCryptogra phic Officer - DRBG- EI and Seed: G,E - DRBG- State: G,E - KAPP- PRIV: G,E - KAPP- PUB: G,E
Asymmetric_key _importLoad RSA, ECDSA , DSA keys“Succee ded”; “Failed”Asymmet ric Public/Pr ivate KeysLoad statusKTSCryptogra phic Officer - KAPP- PRIV: W - KAPP- PUB: W - KKAS- SS: E
Secure_sessionEstablis h a secure session with the CO by generati ng a shared key“Succee ded”; “Failed”Public KeysModule’s KAS public keyAKG AKV DPG DRBG ENC- AUTH SigGen SigVer KASCryptogra phic Officer - KDI-EC- PRIV: E - KKAS- PRIV: G,E - KOP- PUB: E - KKAS- PUB: G,R - KKAS- OP-PUB: W,E - KSS: G,E - KKAS- SS: G,E - DRBG- State: G,E - DRBG-

ha PRIV: G,E Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 22
NameDescrip tionIndicato rInputsOutputsSecuri ty Functi onsSSP Access EI and Seed: G,E
ZeroiseDestroy all CSPsDevice Inoperati veNoneDevice InoperativeNoneCryptogra phic Officer - KDI-EC- PRIV: Z
HMAC-SHA2- 256Generat es MAC of input message“Succee ded”; “Failed”HMAC key, plaintext messageMAC of messageMACCryptogra phic Officer - KAPP- HMAC: E
SHA3 hashingGenerat es SHA3 digest“Succee ded”; “Failed”Digest size: 224, 256, 384, 512 bit Plaintext messageDigest of messageSHSCryptogra phic Officer
SHA2-256 hashingGenerat es SHA2- 256 digest“Succee ded”; “Failed”Digest size: 256 bit Plaintext messageDigest of messageSHSCryptogra phic Officer
Get Random NumberRequest a random number“Succee ded”; “Failed”NoneRandom numberDRBG ESVCryptogra phic Officer - DRBG- EI and Seed: G,E - DRBG- State: G,E
Get Error LogGet self-test error logThree latest self-test errors and CRC checksu m of error logNoneError Log: the last three detected errors and the CRC checksumNoneCryptogra phic Officer

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 23
NameDescrip tionIndicato rInputsOutputsSecuri ty Functi onsSSP Access
Firmware LoadLoad firmwar e from an external source at power- onNo error reported on service executio n; Module accepts CO requestsFirmware images, signature sSelf-test results from SBI execution.SigVerUnauthenti cated - KSBI: W,E - KAAI: W,E
4.4 Non-Approved Services

All approved services implemented by the Module are listed in the table below: NOTE: There are no Non-Approved services available.

4.5 External Software/Firmware Loaded

The module supports external firmware loads per IG 10.3.F, Additional Comment #3A. Both the Secure Boot Image (SBI) and Authenticated Application Image (AAI) are externally loaded into the module during initialization at every power-on. Each externally loaded image must have a valid ECDSA or RSA signature verified before the image is accepted. The hash of the public keys used to validate the candidate images are loaded prior to the firmware images themselves. The public keys are embedded in the SBI and AAI headers respectively. The hash of the embedded keys are validated against the preloaded hash values. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 24
5 Software/Firmware Security
5.1 Integrity Techniques

The Module is composed of the following firmware components:

5.2 Initiate on Demand

The operator can initiate the integrity test on demand by power cycling the Module. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 25
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited How Requirements are Satisfied: The Module has a limited operational environment under the FIPS 140-3 definitions. The Module includes a firmware load service using ECDSA and RSA to support necessary updates. Firmware versions validated to FIPS 140-3 will be explicitly identified on a validation certificate issued by the CMVP. Any firmware not identified in this Security Policy does not constitute the Module defined by this Security Policy or covered by this validation. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 26
MechanismInspection FrequencyInspection Guidance
Tamper-resistant IC packaging6 monthsReview for evidence of tamper. If tamper evidence is observed, zeroise the module.
Temp/Voltage TypeTemperature or VoltageEFP or EFTResult
LowTemperature-50CEFTShutdown
HighTemperature130CEFTShutdown
LowVoltage1.5VEFTShutdown
HighVoltage3.8VEFTShutdown
7 Physical Security
7.1 Mechanisms and Actions Required

The BCM58202B0 Cryptographic Module is a single chip device offering the following physical security mechanisms:

7.6 Hardness Testing Temperature Ranges

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 27
Temperature TypeTemperature
LowTemperature0C
HighTemperature70C

Table 15: Hardness Testing Temperatures Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 28
8 Non-Invasive Security

At present, SP800-140F does not define any non-invasive attack mitigation methods and as such, this section is not applicable. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 29
Storage Area NameDescriptionPersistence Type
RAMOnly stored in volatile memory (RAM).Dynamic
OTPStored in One-Time Programmable memoryStatic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
KAS-EntryOutsideRAMPlaintextAutomatedElectronicKAS
KTSOutsideRAMEncryptedAutomatedElectronicKTS
PT-EntryOutsideRAMPlaintextManualElectronic
PT-OutputRAMOutsidePlaintextManualElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Z1Zeroisation Service (MANU_DEBUG pin). Contents of OTP are overwritten with all ‘1’Permanently remove sensitive parameters by writing all ‘1’. No new data can be loaded.Asserting the MANU_DEBUG signal
Z2Zeroised by Power cycle or hard reset.Remove temporary or generated sensitive data from being carried over to the next operating session.Power cycle
Z3Zeroise after Secure Session is established.To prevent leakage of Secure Session secrets.No operator intervention is needed.
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 17: SSP Input-Output Methods

9.3 SSP Zeroization Methods

Table 18: SSP Zeroization Methods Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 30
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
DRBG-EI and SeedCTR_DRBG entropy input3072 - 256DRBG - CSPESVDRBG
DRBG- StateCTR_DRBG internal state (V and Key)256 - 256DRBG - CSPDRBGDRBG
KKAS- PRIVPrivate key for share secret generationP-256 - 128Asymmetric - CSPAKGKAS
KDI-EC- PRIVSigning key of messages during secure session establishmenP-256 - 128Asymmetric - CSPInstalled during manufacturing.SigGen
KAPP- AESEncryption/decryption operations128, 192, 256 - 128, 192, 256Symmetric - CSPCKG-SymmetricENC
KAPP- HMACIntegrity operations256 - 256Symmetric - CSPCKG-SymmetricMAC
KAPP- PRIVGeneral purpose key for sig-genDSA: 2048, RSA 2048, 4096; ECDSA: P-256, P- 384 - 112-192Asymmetric - CSPAKGSigGen
KKAS- SSAES-CCM secure session key.128 - 128Symmetric - CSPKASENC- AUTH KTS
KSSShared secret for session key derivation.256 - 256Symmetric - CSPKASKAS
KDI-EC- PUBUsed by the CO to mutually authenticate the secure session.P-256 - 128Asymmetric - PSPAKG
KKAS- PUBEphemeral public key from Module for shared secret establishmentP-256 - 128Asymmetric - PSPAKGKAS
9.4 SSPs

All usage of these SSPs by the Module are described in the services detailed in Section 4.3 Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 31
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
KKAS- OP-PUBEphemeral KAS public key of the CO used to establish a secure session.P-256 - 128Asymmetric - PSPKAS
KAPP- PUBGeneral purpose key for sig-ver.DSA: 2048, RSA 2048, 4096; ECDSA: P-256, P- 384 - 112-192Asymmetric - PSPAKGSigVer
KOP- PUBPublic key to authenticate the CO during secure session establishmentP-256 - 128Asymmetric - PSPSigVer
KSBIPublic Key. SBI signature verificationP-384 - 192Asymmetric - NeitherSigVer
KAAIPublic Key. AAI signature verification2048 - 112Asymmetric - NeitherSigVer

Name DRBG-EI and Seed DRBG-State

Input - Output

Storage RAM:Plaintext RAM:Plaintext

Storage Duration Until use completes Until use completes

Zeroization Z2 Z2

Related SSPs DRBG-State:Initializes DRBG-EI and Seed:Derived From KKAS-PRIV:Generates KKAS-PUB:Generates KAPP-AES:Generates KAPP-HMAC:Generates KAPP-PRIV:Generates KAPP-PUB:Generates

Table 19: SSP Table 1 Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 32
Name KKAS-PRIV KDI-EC-PRIVInput - OutputStorage RAM:Plaintext RAM:Plaintext OTP:PlaintextStorage Duration Until use completes Until use completesZeroization Z2 Z3 Z1Related SSPs KKAS-SS:Derives KKAS-PUB:Paired With DRBG-State:Generated from KDI-EC-PUB:Paired With
KAPP-AESKTSRAM:PlaintextUntil use completesZ2DRBG-State:Generated from
KAPP-HMACKTSRAM:PlaintextUntil use completesZ2DRBG-State:Generated from
KAPP-PRIVKTSRAM:PlaintextUntil use completesZ2KAPP-PUB:Paired With DRBG-State:Generated from
KKAS-SSRAM:PlaintextUntil use completesZ2KSS:Derived From
KSSRAM:PlaintextUntil use completesZ2 Z3KKAS-PRIV:Derived From KKAS-PUB:Derived From KKAS-OP-PUB:Derived From KKAS-SS:Derives
KDI-EC-PUBPT-OutputRAM:PlaintextUntil use completesZ2KDI-EC-PRIV:Paired With DRBG-State:Generated from
KKAS-PUBPT-OutputRAM:PlaintextUntil use completesZ2 Z3KKAS-PRIV:Paired With KKAS-SS:Derives DRBG-State:Generated from
KKAS-OP-PUBKAS-EntryRAM:PlaintextUntil use completesZ2 Z3KSS:Derives
KAPP-PUBKTSRAM:PlaintextUntil use completesZ2KAPP-PRIV:Paired With DRBG-State:Generated from
KOP-PUBPT-EntryRAM:PlaintextUntil use completesN/A
KSBIPT-EntryRAM:PlaintextUntil use completesN/A
KAAIPT-EntryRAM:PlaintextUntil use completesN/A

Table 20: SSP Table 2 Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 33
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Firmware IntegrityCRC-32EDCSW/FW IntegrityModule has not entered error state.A CRC-32 is checked on SBI and AAI respectively before SBI and AAI executes.
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (AES 5895)AES-128, 192 and 256 – CBC EncryptKATCASTTest name displayed and module does not enter ES1Encryption - Forward cipher functionPower-On
10 Self-Tests
10.1 Pre-Operational Self-Tests

The Module performs self-tests to ensure the proper operation of the Module. Per FIPS 140-3 these are categorized as either preoperational self-tests or conditional self-tests. Conditional self–tests are periodically performed by the Module every 10 minutes or by power cycling the Module. The Module accepts one service request at a time. The Module will postpone periodic self-testing while critical operations are in progress. The Module will process a service request after the periodic self-test in progress. The Module logs the latest three (3) self-test errors in the Module’s persistent registers, preserved across reset cycles. The CO can consult the error log by invoking Get Error Log service. The Module performs the following pre-operational self-tests in table below Table 21: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

The Module performs the following conditional self-tests in the table below Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 34
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CCM (AES 5896)AES-128 - CCM EncryptKATCASTTest name displayed and module does not enter ES1Authenticated encryptionPower-On
Counter DRBG (A3753)AES-256 CTR_DRBGKATCASTTest name displayed and module does not enter ES1AES-256 CTR_DRBG instantiate, generate, and reseed KATs.Power-On
DSA SigGen (FIPS186-4) (A4437)2048-bit Signature Generation with SHA2-256KATCASTTest name displayed and module does not enter ES1Signature GenerationPower-On
DSA SigVer (FIPS186-4) (A4437)2048-bit Signature Verification with SHA2-256KATCASTTest name displayed and module does not enter ES1Signature VerificationPower-On
ECDSA SigGen (FIPS186-4) (A3751)P-256 SHA2-256 and P-384 SHA2- 256KATCASTTest name displayed and module does not enter ES1Signature GenerationPower-On
ECDSA SigVer (FIPS186-4) (A3751)P-256 SHA2-256 and P-384 SHA2- 256KATCASTTest name displayed and module does not enter ES1Signature VerificationPower-On
KAS-ECC-SSC Sp800-56Ar3 (A3751)KAS-SSC Ephemeral Unified Model, C(2,0, ECC CDH). P-256KATCASTTest name displayed and module does not enter ES1KAS-SSC Shared Secret generation with P-256Power-On
ECDSA KeyGen (FIPS186-4) (A3751)P-256PCTPCTTest name displayed and module does not enter ES1ECDSA P-521 Key Generation Pairwise Consistency TestECDSA Key Generation Sign/Verify Pairwise Consistency TestECDSA Key Generation

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 35
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ENTSP800-90B Health TestAPT and RCTCASTTest name displayed and module does not enter ES1An RCT and APT as specified in [90B] section 4.4 are executed before generation of the DRBG entropy inputContinuous
Firmware LoadingECDSA P-384 with SHA2-256 or RSA 4096 with SHA2- 256Signature VerificationSW/FW LoadModule does not enter ES1. Self- Tests initiateSignature Verification using ECDSA P-384 (SBI) or RSA 4096 (AAI)Upon firmware load
HMAC-SHA2-256 (HMAC 3870)HMAC-SHA256 Key Sizes: λ = 32 bytesKATCASTTest name displayed and module does not enter ES1HMAC-SHA2-256 KAT – Inclusive to SHA2-256 testingPower-On
KDA OneStepNoCounter SP800-56Cr2 (A3752)One step KDA with SHA2-256 in no counter mode. SP800-56c-rev2 One-Step Key Derivation Function, Section 4.1, Option 1KATCASTTest name displayed and module does not enter ES1Generate 256-bits of keying materialPower-On
RSA SigGen (FIPS186-4) (A3750)2048-bit and 4096- bit with SHA2-256KATCASTTest name displayed and module does not enter ES12048-bit and 4096- bit RSA PKCSv1.5 with SHA2-256 Signature GenerationPower-On
RSA SigVer (FIPS186-4) (A3750)2048-bit and 4096- bit with SHA2-256KATCASTTest name displayed and module does not enter ES12048-bit and 4096- bit RSA PKCSv1.5 with SHA2-256 Signature VerificationPower-On

Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 36
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA2-256 (SHS 4646)SHA2-256KATCASTTest name displayed and module does not enter ES1SHA2-256Power-On
SHA3-224 (SHA-3 60)SHA3-224KATCASTTest name displayed and module does not enter ES1SHA3-224Power-On
SHA3-256 (SHA-3 60)SHA3-256KATCASTTest name displayed and module does not enter ES1SHA3-256Power-On
SHA3-384 (SHA-3 60)SHA3-384KATCASTTest name displayed and module does not enter ES1SHA3-384Power-On
SHA3-512 (SHA-3 60)SHA3-512KATCASTTest name displayed and module does not enter ES1SHA3-512Power-On
KAS Key GenerationKAC-ECC P-256. Ephemeral UnifiedPCTPCTSecure session establishment proceeds and module does not enter ES1Pairwise Consistency Test as defined by SP800- 56Ar3.KAS Key Generation
AES-CBC (AES 5895)AES-128, 192 and 256 – CBC DecryptKATCASTTest name displayed and module does not enter ES1Decryption - Inverse cipher functionPower-On
AES-CCM (AES 5896)AES-128 - CCM DecryptKATCASTTest name displayed and module does not enter ES1Authenticated decryption.Power-On

Table 22: Conditional Self-Tests Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 37
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Firmware IntegrityEDCSW/FW IntegrityPonwer-OnAutomatically
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (AES 5895)KATCAST10 minutesAutomatically
AES-CCM (AES 5896)KATCAST10 minutesAutomatically
Counter DRBG (A3753)KATCAST10 minutesAutomtically
DSA SigGen (FIPS186- 4) (A4437)KATCAST10 minutesAutomatically
DSA SigVer (FIPS186- 4) (A4437)KATCAST10 minutesAutomatically
ECDSA SigGen (FIPS186-4) (A3751)KATCAST10 minutesAutomatically
ECDSA SigVer (FIPS186-4) (A3751)KATCAST10 minutesAutomatically
KAS-ECC-SSC Sp800- 56Ar3 (A3751)KATCAST10 minutesAutomatically
ECDSA KeyGen (FIPS186-4) (A3751)PCTPCTN/AN/A
ENTAPT and RCTCASTContinuousAutomatically
Firmware LoadingSignature VerificationSW/FW LoadN/AN/A
HMAC-SHA2-256 (HMAC 3870)KATCAST10 minutesAutomtically
KDA OneStepNoCounter SP800-56Cr2 (A3752)KATCAST10 minutesAutomatically

Table 23: Pre-Operational Periodic Information Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 38
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigGen (FIPS186- 4) (A3750)KATCAST10 minutesAutomatically
RSA SigVer (FIPS186- 4) (A3750)KATCAST10 minutesAutomatically
SHA2-256 (SHS 4646)KATCAST10 minutesAutomatically
SHA3-224 (SHA-3 60)KATCAST10 minutesAutomatically
SHA3-256 (SHA-3 60)KATCAST10 minutesAutomatically
SHA3-384 (SHA-3 60)KATCAST10 minutesAutomatically
SHA3-512 (SHA-3 60)KATCAST10 minutesAutomatically
KAS Key GenerationPCTPCTN/AN/A
AES-CBC (AES 5895)KATCAST10 minutesAutomatically
AES-CCM (AES 5896)KATCAST10 minutesAutomatically

Table 24: Conditional Periodic Information Conditional self–tests are periodically performed by the Module every 10 minutes. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 39
NameDescriptionConditionsRecovery MethodIndicator
ESIThe Module fails a KAT, PCT, conditional or periodic self-test, FW integrity, critical function tests, DRBG self-tests.The Module enters the FIPS error stateReboot/Power cycle the moduleThe Module enters the FIPS error state and SBL fails to boot or continue operation, and enters a continuous reset loop.
10.4 Error States
10.5 Operator Initiation of Self-Tests

Self-tests can be initiated by power cycling or issuing a reset to the Module.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The Module is manufactured and fully tested in secure environments under authorized access control. The Module is installed in the final product with the companion external flash device in the manufacturing facility. The CO must ensure the appropriate versions of the SBI and AAI are loaded in the companion external flash device upon first power up of the Module using the “Get Info” service. The CO should also visually inspect the Module for tamper evidence. The Module is a single chip device that does not provide any maintenance service access. At the end of life of the Module, all CSPs shall be zeroised by setting MANU_DEBUG pin high and Installation and Initialization: The following steps must be performed in order to securely install, initialize, and start up the BCM58202B0 cryptographic module in the FIPS 140-3 Approved mode of operation: The Module should be installed in the final product with the companion external flash device in the manufacturing facility. The manufacturing process includes a Module customization step which installs SBI and AAI in the module, initializes the Module with per device unique AES and HMAC keys, binding the Module and the flash device. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 40

The CO must ensure the appropriate versions of the SBI and AAI are loaded in the companion external flash device upon first power up of the Module using the “Get Info” service. The CO should also visually inspect the Module for tamper evidence. Delivery: The CO must ensure the appropriate versions of the SBI and AAI are loaded in the companion external flash device upon first power up of the Module using the “Get Info” service. The CO should also visually inspect the Module for tamper evidence.

11.2 Administrator Guidance

Before the Module is installed in the end product, the module package should be inspected for integrity and to be free of any tamper evidence. The Module should be installed in the final product with the companion external flash device in a secure manufacturing facility. The manufacturing process includes a Module customization step which installs SBI and AAI in the module. To ensure the appropriate versions of the SBI and AAI are loaded in the companion external flash device, execute the “Get Info” service upon first power up of the Module. Verify the expected versions are reported. While the Module is in service in the end product, it is recommended to perform a visual inspection of the Module at least every 6 months to ensure that the Module package is still intact and void of any tamper evidence. “Get Info” service should be run to ensure that the correct SBI and AAI versions are in operation. Upon the termination of service of the Module, all critically sensitive parameters in the Module should be zeroized by setting the MANU_DEBUG pin high and power cycling the Module. Then, the Module can be disposed of responsibly.

11.3 Non-Administrator Guidance

Same as above for Administration Guidance.

11.4 Design and Rules

Rules of Operation

  1. The Module provides one distinct operator roles: Cryptographic Officer.
  2. The Module provides identity-based authentication.
  3. The Module clears previous authentications on power cycle. Broadcom Public Material – May be reproduced only in its original entirety (without revision).
Page 41
  1. An operator does not have access to any cryptographic services prior to assuming an authorized role.
  2. The Module allows the operator to initiate power-up self-tests by power cycling power or resetting the Module.
  3. All self-tests do not require any operator action.
  4. Data output is inhibited during key generation, self-tests, zeroization, and error states.
  5. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module.
  6. There are no restrictions on which keys or SSPs are zeroized by the zeroization service.
  7. The Module does not support concurrent operators.
  8. The Module does not support a maintenance interface or role.
  9. The Module does not support manual SSP establishment method.
  10. The Module does not have any proprietary external input/output devices used for entry/output of data.
  11. The Module does not enter or output plaintext CSPs.
  12. The Module does not output intermediate key values.
  13. The Module does not provide bypass services or ports/interfaces.
11.5 Maintenance Requirements

The Module is a single chip device that does not provide any maintenance service access.

11.6 End of Life

At the end of life of the Module, all CSPs shall be zeroised by setting MANU_DEBUG pin high and power cycling the Module.

12 Mitigation of Other Attacks

The Module does not implement any mitigation method against other attacks. References and Definitions The following standards are referred to in this Security Policy. Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 42
Abbreviation*Full Specification Name
[FIPS140-3]Security Requirements for Cryptographic Modules, March 22, 2019
[ISO19790]International Standard, ISO/IEC 19790, Information technology — Security techniques — Test requirements for cryptographic modules, Third edition, March 2017
[ISO24759]International Standard, ISO/IEC 24759, Information technology — Security techniques — Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015
[IG]Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, August 1, 2023
[108r1]NIST Special Publication 800-108, Recommendation for Key Derivation Using Pseudorandom Functions (Revised), August 2022
[133r2]NIST Special Publication 800-133, Recommendation for Cryptographic Key Generation, Revision 2, June 2020
[186]National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-4, July 2013.
[197]National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197, November 26, 2001
[198]National Institute of Standards and Technology, The Keyed-Hash Message Authentication Code (HMAC), Federal Information Processing Standards Publication 198-1, July, 2008
[180]National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August, 2015
[202]FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION, SHA-3 Standard: Permutation- Based Hash and Extendable-Output Functions, FIPS PUB 202, August 2015
[38A]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation, Methods and Techniques, Special Publication 800-38A, December 2001
[38C]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: The CCM Mode for Authentication and Confidentiality, Special Publication 800-38C, May 2004
[38F]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping, Special Publication 800-38F, December 2012
[56Ar3]NIST Special Publication 800-56A Revision 3, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, April 2018
[56Cr2]NIST Special Publication 800-56C Revision 2, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, August 2020
[90Ar1]National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A, Revision 1, June 2015.
[90B]National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018.

References Broadcom Public Material – May be reproduced only in its original entirety (without revision).

Page 43
Acronym*Definition
APTAdaptive Proportion Test
KATKnow Answer Test
RCTRepetition Count Test
SSPSensitive Security Parameter

Acronyms and Definitions Broadcom Public Material – May be reproduced only in its original entirety (without revision).