| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 7/10/2029 |
| Caveat | No assurance of the minimum strength of generated SSPs (e.g., keys). |
| Vendor | Musarubra US LLC |
flowchart LR
%% Deterministic review-risk graph for Trellix FIPS Provider
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Unauth<br/>Status Output</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>DTLS</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for Trellix FIPS Provider
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Unauth<br/>Status Output</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>DTLS</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;Musarubra US LLC Trellix FIPS Provider Document Version 1.2 September 23, 2025 Prepared for: Prepared by: Musarubra US LLC KeyPair Consulting Inc. 102#, 6000 Headquarters Dr. 987 Osos St. STE 300 San Luis Obispo, CA 93401 Plano, TX 75024 +1 805.316.5024 trellix.com keypair.us
FIPS 140-3 Security Policy Trellix FIPS Provider Table of Contents
FIPS 140-3 Security Policy Trellix FIPS Provider
FIPS 140-3 Security Policy Trellix FIPS Provider List of Tables List of Figures
| Section | Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic module specification | 1 |
| 3 | Cryptographic module interfaces | 1 |
| 4 | Roles, services, and authentication | 1 |
| 5 | Software/Firmware security | 1 |
| 6 | Operational environment | 1 |
| 7 | Physical security | N/A |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle assurance | 3 |
| 12 | Mitigation of other attacks | 1 |
| Overall Level | 1 |
FIPS 140-3 Security Policy Trellix FIPS Provider
Module. The Module meets FIPS 140-3 overall Level 1 requirements, with security levels as shown in Section 1.2. In accordance with AS02.05, ISO/IEC 19790:2012 §7.7 Physical Security is optional and does not apply to the Module.
Purpose and Use: The Module is a cryptographic software library, intended for use by US and Canadian Federal agencies and other markets that require FIPS 140-3 validated cryptographic functionality. The Module design corresponds to the Module security rules. Security rules enforced by the Module are described in the appropriate context of this document. Module Embodiment: Multi-Chip Standalone
FIPS 140-3 Security Policy Trellix FIPS Provider Cryptographic Boundary: Figure 1 depicts the Module operational environment, with the cryptographic boundary highlighted in red inclusive of all Module entry points (API calls). The Module is defined as a Software module per AS02.03. The pre-operational approved integrity test is performed over all components within the cryptographic boundary. Tested Operational Environment’s Physical Perimeter (TOEPP): The General Purpose Computer is the TOEPP. Figure 1: Block Diagram
| Package or File Name | Software/ Firmware Version | Features | Integrity Test |
|---|---|---|---|
| fips.so | 3.0.10 with KP_1.2 | N/A | HMAC-SHA2-256 #A6884 over the complete module file image |
Operating System Trellix OS (TRFEOS) 11.0 Trellix OS (TRFEOS) 11.0
Hardware Platform EX3600 EX3600
Processors Intel® Xeon® E-2334 (Rocket Lake) Intel® Xeon® E-2334 (Rocket Lake)
PAA/PAI Yes No
Hypervisor or Host OS
Version(s) 3.0.10 with KP_1.2 3.0.10 with KP_1.2
| Operating System | Hardware Platform |
|---|---|
| Trellix OS (TRFEOS) 11.0 | AX5600 Processor: Intel® Xeon® E-2334 (Rocket Lake) |
| Trellix OS (TRFEOS) 11.0 | CM4600 Processor: Intel® Xeon® E-2334 (Rocket Lake) |
| Trellix OS (TRFEOS) 11.0 | CM7600 Processor: Intel® Xeon® Silver 4314 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | CM9600 Processor: Intel® Xeon® Silver 4316 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | EX3600 Processor: Intel® Xeon® E-2334 (Rocket Lake) |
| Trellix OS (TRFEOS) 11.0 | EX5600 Processor: Intel® Xeon® Silver 4314 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | EX8600 Processor: Intel® Xeon® Silver 4316 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | FX6600 Processor: Intel® Xeon® Silver 4316 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | HX4600 Processor: Intel® Xeon® E-2378 (Rocket Lake) |
| Trellix OS (TRFEOS) 11.0 | IPSM4210 Processor: Intel® Xeon® Silver 4210 (Cascade Lake) |
FIPS 140-3 Security Policy Trellix FIPS Provider
Tested Module Identification
| Operating System | Hardware Platform |
|---|---|
| Trellix OS (TRFEOS) 11.0 | IPSM4210 Processor: Intel® Xeon® Silver 4114 (Skylake) |
| Trellix OS (TRFEOS) 11.0 | IPSM4510 Processor: Intel® Xeon® Silver 4510 (Sapphire Rapids) |
| Trellix OS (TRFEOS) 11.0 | NX2600 Processor: Intel® Xeon® E-2334 (Rocket Lake) |
| Trellix OS (TRFEOS) 11.0 | NX3600 Processor: Intel® Xeon® E-2378 (Rocket Lake) |
| Trellix OS (TRFEOS) 11.0 | NX4600 Processor: Intel® Xeon® Silver 4314 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | NX5600 Processor: Intel® Xeon® Silver 4314 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | NX6600 Processor: Intel® Xeon® Gold 6330 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | NX8600 Processor: Intel® Xeon® Platinum 8380 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | VX3200 Processor: Intel® Xeon® Silver 4210 (Cascade Lake) |
| Trellix OS (TRFEOS) 11.0 | VX3210 Processor: Intel® Xeon® Silver 4210 (Cascade Lake) |
| Trellix OS (TRFEOS) 11.0 | VX5600 Processor: Intel® Xeon® E-2334 (Rocket Lake) |
| Trellix OS (TRFEOS) 11.0 | VX6200 Processor: Intel® Xeon® Gold 6230 (Cascade Lake) |
| Trellix OS (TRFEOS) 11.0 | VX6210 Processor: Intel® Xeon® Gold 6230 (Cascade Lake) |
| Trellix OS (TRFEOS) 11.0 | VX12600 Processor: Intel® Xeon® Gold 6330 (Ice Lake) |
| Trellix OS (TRFEOS) 11.0 | CM1500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | CM2500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | CM4500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Operating System | Hardware Platform |
|---|---|
| Trellix OS (TRFEOS) 11.0 | CM7500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | CM9500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | EX5500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | EXIntgV Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | EXIvx2500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | FX2500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | HX2502V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | HX4502V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | HX4600V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | NX1500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | NX2500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | NX2550V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Operating System | Hardware Platform |
|---|---|
| Trellix OS (TRFEOS) 11.0 | NX4500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | NX6500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | NX7500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | NX8500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | NX10500V Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Trellix OS (TRFEOS) 11.0 | VXV Processor: Intel® Xeon® Gold 5418Y (Sapphire Rapids) Hypervisor: VMware vSphere ESXi 8.0 |
| Skyhigh Linux OS (SLOS) | c5.large/c5.xlarge/c5.2xlarge/c5.4xlarge/c5.9xlarge/c5.18xlarge Processor: Intel® Xeon® Platinum 8000 series processor (Skylake-SP) |
| Skyhigh Linux OS (SLOS) | c5.12xlarge/c5.24xlarge Processor: Intel® Xeon® Platinum 8000 series processor (Cascade Lake) |
| Skyhigh Linux OS (SLOS) | c5d.large/c5d.xlarge/c5d.2xlarge/c5d.4xlarge/c5d.9xlarge/c5d.18xlarge Processor: Intel® Xeon® Platinum 8000 series processor (Skylake-SP) |
| Skyhigh Linux OS (SLOS) | c5d.12xlarge/c5d.24xlarge Processor: Intel® Xeon® Platinum 8000 series processor (Cascade Lake) |
FIPS 140-3 Security Policy Trellix FIPS Provider Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the Module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.
Mode Name Nominal
Description Approved mode of operation
Type Approved
Status Indicator
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-CBC | A6884 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CBC-CS1 | A6884 | Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-512 Increment 8 | SP 800-38A |
| AES-CBC-CS2 | A6884 | Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-512 Increment 8 | SP 800-38A |
FIPS 140-3 Security Policy Trellix FIPS Provider Modes List and Description: Table 5: Modes List and Description The Module only supports an Approved mode of operation. The conditions for using the Module in the Approved mode of operation are:
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-CBC-CS3 | A6884 | Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 136-512 Increment 8 | SP 800-38A |
| AES-CCM | A6884 | Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56-104 Increment 8 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0-524288 Increment 8 | SP 800-38C |
| AES-CFB1 | A6884 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB128 | A6884 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB8 | A6884 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CMAC | A6884 | Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 0-524288 Increment 8 | SP 800-38B |
| AES-CTR | A6884 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - Yes | SP 800-38A |
| AES-ECB | A6884 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-GCM | A6884 | Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96-1024 Increment 8 Payload Length - Payload Length: 8-65536 Increment 8 AAD Length - AAD Length: 0-65536 Increment 8 | SP 800-38D |
| AES-GMAC | A6884 | Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 | SP 800-38D |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Algorithm | CAVP Cert | Properties IV Length - IV Length: 96 AAD Length - AAD Length: 0-65536 Increment 8 | Reference |
|---|---|---|---|
| AES-KW | A6884 | Direction - Decrypt, Encrypt Cipher - Cipher, Inverse Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128 | SP 800-38F |
| AES-KWP | A6884 | Direction - Decrypt, Encrypt Cipher - Cipher, Inverse Key Length - 128, 192, 256 Payload Length - Payload Length: 8-4096 Increment 8 | SP 800-38F |
| AES-OFB | A6884 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-XTS Testing Revision | A6884 | Direction - Decrypt, Encrypt | SP 800-38E |
| 2.0 | Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - Yes | ||
| Counter DRBG | A6884 | Prediction Resistance - Yes Supports Reseed - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes Additional Input - Additional Input: 0-256 Increment 256, Additional Input: 256, Additional Input: 320, Additional Input: 384 Entropy Input - Entropy Input: 128-256 Increment 128, Entropy Input: 256, Entropy Input: 256-512 Increment 128, Entropy Input: 320, Entropy Input: 384 Nonce - Nonce: 0, Nonce: 128 Personalization String Length - Personalization String Length: 0-256 Increment 256, Personalization String Length: 256, Personalization String Length: 320, Personalization String Length: 384 Returned Bits - 256 | SP 800-90A Rev. 1 |
| DSA KeyGen (FIPS186-4) | A6884 | L - 2048, 3072 N - 224, 256 | FIPS 186-4 |
| DSA PQGGen (FIPS186-4) | A6884 | P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 | FIPS 186-4 |
| DSA PQGVer (FIPS186-4) | A6884 | P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 1024, 2048, 3072 | FIPS 186-4 |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Algorithm | CAVP Cert | Properties N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 | Reference |
|---|---|---|---|
| DSA SigGen (FIPS186-4) | A6884 | L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 | FIPS 186-4 |
| DSA SigVer (FIPS186-4) | A6884 | L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 | FIPS 186-4 |
| ECDSA KeyGen (FIPS186- | A6884 | Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 | FIPS 186-4 |
| 4) | Secret Generation Mode - Testing Candidates | ||
| ECDSA KeyVer (FIPS186- 4) | A6884 | Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521 | FIPS 186-4 |
| ECDSA SigGen (FIPS186- | A6884 | Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 | FIPS 186-4 |
| 4) | Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 | ||
| ECDSA SigVer (FIPS186-4) | A6884 | Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 | FIPS 186-4 |
| EDDSA KeyGen | A6884 | Curve - ED-25519, ED-448 | FIPS 186-5 |
| EDDSA KeyVer | A6884 | Curve - ED-25519, ED-448 | FIPS 186-5 |
| EDDSA SigGen | A6884 | Curve - ED-25519, ED-448 Context Length - Context Length: 0-255 Increment 1 PreHash - No Pure - Yes | FIPS 186-5 |
| EDDSA SigVer | A6884 | Curve - ED-25519, ED-448 PreHash - No Pure - Yes | FIPS 186-5 |
| Hash DRBG | A6884 | Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Entropy Input - Entropy Input: 128-256 Increment 64, Entropy Input: 192-256 Increment 64, Entropy Input: 256- 320 Increment 64 Nonce - Nonce: 128-160 Increment 32, Nonce: 96-128 Increment 32 Personalization String Length - Personalization String Length: 0-256 Increment 128 Additional Input - Additional Input: 0-256 Increment 128 Returned Bits - 160, 224, 256, 384, 512 | SP 800-90A Rev. 1 |
| HMAC DRBG | A6884 | Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Entropy Input - Entropy Input: 160-256 Increment 32, Entropy Input: 192-256 Increment 64, Entropy Input: 256- | SP 800-90A Rev. 1 |
FIPS 140-3 Security Policy Trellix FIPS Provider 4)
| Algorithm | CAVP Cert | Properties 512 Increment 64, Entropy Input: 384-512 Increment 64, Entropy Input: 512-1024 Increment 64 Nonce - Nonce: 128, Nonce: 64, Nonce: 96 Personalization String Length - Personalization String Length: 0-192 Increment 64, Personalization String Length: 0-256 Increment 128 Additional Input - Additional Input: 0-256 Increment 128, Additional Input: 192 Returned Bits - 160, 224, 256, 384, 512 | Reference |
|---|---|---|---|
| HMAC-SHA-1 | A6884 | MAC - MAC: 32-160 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-224 | A6884 | MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-256 | A6884 | MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-384 | A6884 | MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512 | A6884 | MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512/224 | A6884 | MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512/256 | A6884 | MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-224 | A6884 | MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-256 | A6884 | MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-384 | A6884 | MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-512 | A6884 | MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 112-2048 Increment 8 | FIPS 198-1 |
| KAS-ECC CDH- Component SP800-56Ar3 (CVL) | A6884 | Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 | SP 800-56A Rev. 3 |
| KAS-ECC-SSC Sp800- | A6884 | Domain Parameter Generation Methods - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, | SP 800-56A Rev. 3 |
| 56Ar3 | P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder | ||
| KAS-FFC-SSC Sp800- | A6884 | Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, | SP 800-56A Rev. 3 |
| 56Ar3 | modp-2048, modp-3072, modp-4096, modp-6144, modp-8192 |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Algorithm | CAVP Cert | Properties Scheme - dhEphem - KAS Role - initiator, responder | Reference |
|---|---|---|---|
| KAS-IFC-SSC | A6884 | Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2- prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder Fixed Public Exponent - 010001 | SP 800-56A Rev. 3 |
| KDA HKDF SP800-56Cr2 | A6884 | Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Perform Multiple Expansion Tests - No Uses Hybrid Shared Secret - No | SP 800-56C Rev. 2 |
| KDA OneStep SP800- | A6884 | Auxiliary Function Methods - | SP 800-56C Rev. 2 |
| 56Cr2 | Auxiliary Function Name - SHA2-512 MAC Salting Methods - default, random Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 | ||
| KDA TwoStep SP800- | A6884 | MAC Salting Methods - default, random | SP 800-56C Rev. 2 |
| 56Cr2 | Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation KDF Mode - feedback MAC Modes - HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, HMAC- SHA2-512/224, HMAC-SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512 Fixed Data Order - after fixed data Counter Lengths - 8 The KDF supports an empty IV - Yes The KDF requires an empty IV - Yes Supported Lengths - Supported Lengths: 2048 Derived Key Length - 2048 |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Algorithm | CAVP Cert | Properties Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 Perform Multiple Expansion Tests - No Uses Hybrid Shared Secret - No | Reference |
|---|---|---|---|
| KDF ANS 9.42 (CVL) | A6884 | KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Other Info Length - Other Info Length: 0-4096 Increment 8 zz Length - zz Length: 8-4096 Increment 8 Key Data Length - Key Data Length: 8-4096 Increment 8 Supplemental Information Length - Supplemental Information Length: 0-120 Increment 8 OID - AES-128-KW, AES-192-KW, AES-256-KW | SP 800-135 Rev. 1 |
| KDF ANS 9.63 (CVL) | A6884 | Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Field Size - 224, 571 Shared Info Length - Shared Info Length: 0, 1024 Key Data Length - Key Data Length: 128, 4096 | SP 800-135 Rev. 1 |
| KDF SP800-108 | A6884 | KDF Mode - Counter, Feedback MAC Mode - CMAC-AES128, CMAC-AES192, CMAC-AES256, HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512 Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096 Fixed Data Order - Before Fixed Data Counter Length - 32 Supports Empty IV - No, Yes Custom Key In Length - 0 Requires Empty IV - Yes | SP 800-108 Rev. 1 |
| KDF SSH (CVL) | A6884 | Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 | SP 800-135 Rev. 1 |
| KMAC-128 | A6884 | Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8 Hex Customization - No Supports eXtendable-Output Functions - No, Yes | SP 800-185 |
| KMAC-256 | A6884 | Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8 Hex Customization - No Supports eXtendable-Output Functions - No, Yes | SP 800-185 |
| KTS-IFC | A6884 | Function - keyPairGen, partialVal IUT ID - CAFEFACE Modulo - 2048, 3072, 4096, 6144 | SP 800-56B Rev. 2 |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Algorithm | CAVP Cert | Properties Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2- prime-factor Fixed Public Exponent - 010001 Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Hash Algorithms - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512 Supports Null Associated Data - Yes Associated Data Encoding - concatenation Key Length - 1024 | Reference |
|---|---|---|---|
| PBKDF | A6884 | Iteration Count - Iteration Count: 1-10000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Password Length - Password Length: 8-128 Increment 8 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 112-4096 Increment 8 | SP 800-132 |
| RSA KeyGen (FIPS186-4) | A6884 | Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - Yes Public Exponent Mode - Random Private Key Format - Standard | FIPS 186-4 |
| RSA SigGen (FIPS186-4) | A6884 | Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-256 | FIPS 186-4 |
| RSA SigGen (FIPS186-5) | A6884 | Hash Pair - Hash Algorithm - SHA2-224 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss Mask Function - MGF1 | FIPS 186-5 |
| RSA Signature Primitive | A6884 | Private Key Format - crt | FIPS 186-4 |
| (CVL) | Public Exponent Mode - fixed Fixed Public Exponent - 010001 | ||
| RSA SigVer (FIPS186-4) | A6884 | Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096 Hash Pair - | FIPS 186-4 |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Algorithm | CAVP Cert | Properties Hash Algorithm - SHA-1 Public Exponent Mode - Random | Reference |
|---|---|---|---|
| RSA SigVer (FIPS186-5) | A6884 | Hash Pair - Hash Algorithm - SHA2-224 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss Mask Function - MGF1 Public Exponent Mode - random | FIPS 186-5 |
| Safe Primes Key | A6884 | Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, modp-2048, modp-3072, modp- | SP 800-56A Rev. 3 |
| Generation | 4096, modp-6144, modp-8192 | ||
| Safe Primes Key | A6884 | Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, modp-2048, modp-3072, modp- | SP 800-56A Rev. 3 |
| Verification | 4096, modp-6144, modp-8192 | ||
| SHA-1 | A6884 | Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-224 | A6884 | Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-256 | A6884 | Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-384 | A6884 | Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512 | A6884 | Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/224 | A6884 | Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/256 | A6884 | Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA3-224 | A6884 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-256 | A6884 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-384 | A6884 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-512 | A6884 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHAKE-128 | A6884 | Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 | FIPS 202 |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| SHAKE-256 | A6884 | Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 | FIPS 202 |
| TLS v1.2 KDF RFC7627 | A6884 | Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 | SP 800-135 Rev. 1 |
| (CVL) | Key Block Length - Key Block Length: 1024 | ||
| TLS v1.3 KDF (CVL) | A6884 | HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE | SP 800-135 Rev. 1 |
Name CKG Section 4 CKG Section 5 CKG Section 6.2 Hash DRBG with SHA3-256, SHA3-512 HMAC DRBG with SHA3-256, SHA3-512
Properties
Implementation KeyPair FIPS Provider for OpenSSL 3 KeyPair FIPS Provider for OpenSSL 3 KeyPair FIPS Provider for OpenSSL 3 KeyPair FIPS Provider for OpenSSL 3 KeyPair FIPS Provider for OpenSSL 3
Reference NIST, SP 800-133 Rev. 2 NIST, SP 800-133 Rev. 2 NIST, SP 800-133 Rev. 2 NIST, SP 800-90A Rev. 1 NIST, SP 800-90A Rev. 1
Name Cipher (Unauth)
Type BC-UnAuth
Description AES ciphers
Properties
Algorithms AES-CBC: (A6884) AES-CBC-CS1: (A6884) AES-CBC-CS2: (A6884) AES-CBC-CS3: (A6884) AES-CFB1: (A6884) AES-CFB128: (A6884) AES-CFB8: (A6884)
FIPS 140-3 Security Policy Trellix FIPS Provider Table 6: Approved Algorithms Vendor-Affirmed Algorithms: Table 7: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this Module. Non-Approved, Not Allowed Algorithms: N/A for this Module.
| Name Cipher (Auth) CKG Section 4 CKG Section 5 CKG Section 6.2 | Type BC-Auth CKG CKG CKG | Description Authenticated ciphers Using the Output of a Random Bit Generator Generation of Key Pairs for Asymmetric-Key Algorithms Derivation of Symmetric Keys | Properties | Algorithms AES-CTR: (A6884) AES-ECB: (A6884) AES-OFB: (A6884) AES-XTS Testing Revision 2.0: (A6884) AES-CCM: (A6884) AES-GCM: (A6884) AES-KW: (A6884) AES-KWP: (A6884) CKG Section 4: () CKG Section 5: () CKG Section 6.2: () |
|---|---|---|---|---|
| Key agreement | KAS-SSC | Key agreement | KAS:KAS-ECC-SSC provides between 112 and 256 bits of encryption strength; KAS-FFC- SSC provides between 112 and 200 bits of encryption strength; KAS-IFC-SSC provides between 112 and 200 bits of encryption strength | KAS-ECC CDH-Component SP800-56Ar3: (A6884) KAS-ECC-SSC Sp800-56Ar3: (A6884) KAS-FFC-SSC Sp800-56Ar3: (A6884) KAS-IFC-SSC: (A6884) |
| Key derivation | KAS-135KDF | KAS-KDF HKDF SP800-56Cr2: | ||
| KAS-56CKDF | (A6884) | |||
| KBKDF | KAS-KDF OneStep SP800-56Cr2: | |||
| PBKDF | (A6884) KAS-KDF TwoStep SP800-56Cr2: (A6884) KDF ANS 9.42: (A6884) KDF ANS 9.63: (A6884) KDF SP800-108: (A6884) KDF SSH: (A6884) PBKDF: (A6884) TLS v1.2 KDF RFC7627: (A6884) TLS v1.3 KDF: (A6884) | |||
| Key management ECC | AsymKeyPair-KeyGen | ECDSA KeyGen (FIPS186-4): | ||
| AsymKeyPair-KeyVer | (A6884) ECDSA KeyVer (FIPS186-4): (A6884) |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Name Key management Edwards Key management FFC Key management IFC Key transport | Type AsymKeyPair-KeyGen AsymKeyPair-KeyVer AsymKeyPair-KeyGen AsymKeyPair-KeyGen KTS-Encap | Description | Properties KTS:2048, 3072, 4096 or 6144- bit keys provide between 112 and 176 bits of encryption strength | Algorithms EDDSA KeyGen: (A6884) EDDSA KeyVer: (A6884) DSA KeyGen (FIPS186-4): (A6884) DSA PQGGen (FIPS186-4): (A6884) DSA PQGVer (FIPS186-4): (A6884) Safe Primes Key Generation: (A6884) Safe Primes Key Verification: (A6884) RSA KeyGen (FIPS186-4): (A6884) KTS-IFC: (A6884) |
|---|---|---|---|---|
| KTS (Cipher w/ CMAC, GMAC, HMAC, KMAC) | BC-Auth | SP 800-38F Section 3.1 Provisions | KTS:128, 192 or 256-bit keys provide between 128 and 256 bits of encryption strength | AES-CBC: (A6884) |
| BC-UnAuth | AES-CBC-CS1: (A6884) | |||
| MAC | AES-CBC-CS2: (A6884) AES-CBC-CS3: (A6884) AES-CFB1: (A6884) AES-CFB128: (A6884) AES-CFB8: (A6884) AES-CTR: (A6884) AES-ECB: (A6884) AES-OFB: (A6884) AES-CCM: (A6884) AES-GCM: (A6884) AES-GMAC: (A6884) AES-CMAC: (A6884) HMAC-SHA-1: (A6884) HMAC-SHA2-224: (A6884) HMAC-SHA2-256: (A6884) HMAC-SHA2-384: (A6884) HMAC-SHA2-512: (A6884) HMAC-SHA2-512/224: (A6884) HMAC-SHA2-512/256: (A6884) |
FIPS 140-3 Security Policy Trellix FIPS Provider
Name KTS (AES KW, KWP) MAC AES (CMAC, GMAC) MAC HMAC MAC KMAC (XOF) Message Digest Message Digest (XOF SHAKE)
Type BC-Auth MAC MAC XOF SHA XOF
Description
Properties KTS:128, 192 or 256-bit keys provide between 128 and 256 bits of encryption strength
Algorithms HMAC-SHA3-224: (A6884) HMAC-SHA3-256: (A6884) HMAC-SHA3-384: (A6884) HMAC-SHA3-512: (A6884) KMAC-128: (A6884) KMAC-256: (A6884) AES-KW: (A6884) AES-KWP: (A6884) AES-GMAC: (A6884) AES-CMAC: (A6884) HMAC-SHA-1: (A6884) HMAC-SHA2-224: (A6884) HMAC-SHA2-256: (A6884) HMAC-SHA2-384: (A6884) HMAC-SHA2-512: (A6884) HMAC-SHA2-512/224: (A6884) HMAC-SHA2-512/256: (A6884) HMAC-SHA3-224: (A6884) HMAC-SHA3-256: (A6884) HMAC-SHA3-384: (A6884) HMAC-SHA3-512: (A6884) KMAC-128: (A6884) KMAC-256: (A6884) SHA-1: (A6884) SHA2-224: (A6884) SHA2-256: (A6884) SHA2-384: (A6884) SHA2-512: (A6884) SHA2-512/224: (A6884) SHA2-512/256: (A6884) SHA3-224: (A6884) SHA3-256: (A6884) SHA3-384: (A6884) SHA3-512: (A6884) SHAKE-128: (A6884) SHAKE-256: (A6884)
FIPS 140-3 Security Policy Trellix FIPS Provider
Name Random Signature DSA Signature ECDSA Signature EDDSA Signature RSA
Type DRBG DigSig-SigGen DigSig-SigVer DigSig-SigGen DigSig-SigVer DigSig-SigGen DigSig-SigVer DigSig-SigGen DigSig-SigVer
Description
Properties
Algorithms Counter DRBG: (A6884) Hash DRBG: (A6884) HMAC DRBG: (A6884) DSA SigGen (FIPS186-4): (A6884) DSA SigVer (FIPS186-4): (A6884) ECDSA SigGen (FIPS186-4): (A6884) ECDSA SigVer (FIPS186-4): (A6884) EDDSA SigGen: (A6884) EDDSA SigVer: (A6884) RSA SigGen (FIPS186-4): (A6884) RSA SigGen (FIPS186-5): (A6884) RSA Signature Primitive: (A6884) RSA SigVer (FIPS186-4): (A6884) RSA SigVer (FIPS186-5): (A6884)
FIPS 140-3 Security Policy Trellix FIPS Provider Table 8: Security Function Implementations
AES-GCM: The Module supports internal IV generation using the Approved DRBG. The IV is at least 96 bits in length per SP 800-38D Section 8.2.2, and the Approved DRBG generates outputs such that the (key, IV) pair collision probability is less than 2-32 per SP 800-38D Section 8. AES-GCM IVs shall be used in compliance with FIPS 140-3 IG C.H scenario 1a (TLS/DTLS 1.2, per RFC 5288), 1d (SSHv2, per RFC 5647) and 5 (TLS 1.3, per RFC 8446). The Module is compatible with TLS/DTLS 1.2 protocol and provides the primitives to support the AES GCM ciphersuites from SP 800-52 Rev. 1 Section 3.3.1. The Module’s implementation of AES-GCM is used together with one or more applications outside the Module’s cryptographic boundary that implement the specified protocols; these protocols have not been reviewed or tested by the CAVP and CMVP. In each of the protocols, if the Module’s power is lost and then restored, the key used for the AES GCM encryption/decryption shall be re-distributed. This condition is not enforced by the Module but is met implicitly. The Module does not retain any state across reset or power-cycles: AES-GCM key/IVs are not stored in non-volatile persistent memory (i.e., disk), hence no re-connection can occur without a fresh key establishment operation and the associated SSPs. The Module explicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values of 264-1 for a given session key. If this exhaustion condition is observed, the Module returns an error indication to the calling application, which will then need to either abort the connection, or trigger a handshake to establish a new encryption key.
The strength of the Data Protection Key is based on the strength of the Password and/or Passphrase used in key derivation. SP 800-132 does not impose
any strictly defined requirements on the strength of a password. It says that “passwords should be strong enough so that it is infeasible for attackers to
get access by guessing a password.”
FIPS 140-3 Security Policy Trellix FIPS Provider XTS-AES: In accordance with SP 800-38E, the XTS-AES algorithm is to be used for confidentiality on storage devices. The Module complies with FIPS 140-3 IG C.I by:
FIPS 140-3 Security Policy Trellix FIPS Provider Integrators making use of PBKDF with this Module shall determine password policy and input length based on the intended output key size and strength, taking into consideration the probability of guessing KD_PW_PBKDF. The following examples are provided to guide parameter selection:
N/A for this Module. The calling application is responsible for use of a SP 800-90B compliant entropy source outside the Module boundary providing at least 256 bits of security strength. Entropy is supplied to the Module via callback functions. The following caveat applies per FIPS 140-3 IG 9.3.A: No assurance of the minimum strength of generated SSPs (e.g., keys).
| Physical Port | Logical Interface(s) | Data That Passes |
|---|---|---|
| N/A (API - input) | Control Input Data Input | API input: stack frame including non-sensitive parameters. |
| N/A (API - output) | Data Output Status Output | API output: output parameters and return value resulting from call execution. |
FIPS 140-3 Security Policy Trellix FIPS Provider
The Module:
The Module implements key agreement methods compliant with FIPS 140-3 IG D.F and key transport methods compliant with FIPS 140-3 IG D.G. Strengths are provided in Section 2.6.
The Module conforms to FIPS 140-3 IG D.C References to the Support of Industry Protocols: while it provides SP 800-56A Rev. 3 conformant schemes and API entry points oriented to TLS usage, the Module does not contain the full implementation of TLS. The following caveat is required: No parts of the TLS protocol, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP.
Table 9: Ports and Interfaces The Module does not interact with physical ports. The Control Output interface is not applicable, as the Module does not control other components.
Name CO
Type Role
Operator Type CO
Authentication Methods
| Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Cipher | Encrypt or decrypt data, | FIPS_OK | Encryption or decryption key; | Status return. Plaintext | Cipher (Unauth) Cipher (Auth) | CO |
| including AEAD modes (CCM, | plaintext or ciphertext data; flags. | or ciphertext data. | - SC_EDK_AES: W,E | |||
| GCM). | - SC_EDK_XTS: W,E | |||||
| Get capabilities | Reports information on the | FIPS_OK | Provider context, capability, callback pointer and arguments. | Description of | ||
| requested capabilities. | capabilities. | |||||
| Initialize | Module initialization, | FIPS_OK | Core handle, dispatch in and out, | Initialization status (1 = | Random MAC HMAC | CO |
| including instantiation of the | provider context. | pass, 0 = fail). | - DRBG_EI: W,E,Z | |||
| opaque (managed within the | - DRBG_Seed: G,E,Z | |||||
| module) Counter DRBG | - DRBG_Key: G,W,E | |||||
| instance. | - DRBG_V: G,W,E | |||||
| Key agreement | Perform key agreement | FIPS_OK | Key structs (key agreement keys); | Status return; key | CKG Section 5 Key agreement | CO |
| primitives on behalf of the | flags. | agreement shared | - KAS_Private_ECC: | |||
| calling process (does not | secret. | W,E | ||||
| establish keys into the | - KAS_Public_ECC: W,E | |||||
| module). | - KAS_Private_FFC: W,E - KAS_Public_FFC: W,E - KAS_Private_IFC: W,E - KAS_Public_IFC: W,E - KAS_SS_ECC: G,R - KAS_SS_FFC: G,R - KAS_SS_IFC: G,R |
FIPS 140-3 Security Policy Trellix FIPS Provider
Table 10: Roles The Module supports the mandatory Cryptographic Officer (CO) operational role only (implicitly identified), and does not support a maintenance role or a bypass capability. The Module does not provide an authentication or identification method of its own. The CO role is assumed by meeting the conditions of Section 11 of this document and in associated Guidance Documentation.
| Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Key derivation | Derive keying material from a | FIPS_OK | Key agreement shared secret; flags. | Status return; derived keying material. | Key derivation CKG Section 6.2 | CO |
| shared secret. | - KD_DKM_KDF: G,R - KD_PW_PBKDF: W,E - KD_DKM_PBKDF: G,R - KD_SK: W,E | |||||
| Key management | Generate asymmetric key | FIPS_OK | ECDSA, EdDSA: curve identifier. DSA, RSA: domain parameter targets. | Status return; general digital signature private and public keys. | Key management ECC Key management Edwards Key management FFC Key management IFC CKG Section 4 | CO |
| pairs. | - DRBG_C: G,W,E - DRBG_Key: W,G,E - DRBG_V: W,G,E - GKP_Private_ECC: G,R - GKP_Public_ECC: G,R - GKP_Private_Edwards: G,R - GKP_Public_Edwards: G,R - GKP_Private_FFC: G,R - GKP_Public_FFC: G,R - GKP_Private_IFC: G,R - GKP_Public_IFC: G,R | |||||
| Key transport | Encapsulate or decapsulate | FIPS_OK | Key encapsulation/decapsulation key or Key wrap/unwrap key. | Status return; key transport shared secret. | CKG Section 5 Key transport KTS (Cipher w/ CMAC, GMAC, HMAC, KMAC) KTS (AES KW, KWP) | CO |
| key material on behalf of the | - KTS_KDK_IFC: W,E | |||||
| calling process. | - KTS_KEK_IFC: W,E - KTS_SS_IFC: G,R | |||||
| Message authentication | Generate or verify data | FIPS_OK | Keyed hash key. | Status return; MAC output value. | MAC AES (CMAC, GMAC) MAC HMAC MAC KMAC (XOF) | CO |
| integrity. | - KH_Key_AES-CMAC: W,E - KH_Key_AES-GMAC: W,E - KH_Key_HMAC: W,E - KH_Key_KMAC: W,E | |||||
| Message digest | Generate a message digest. | FIPS_OK | Message; flags. | Status return; Hash output value. | Message Digest Message Digest (XOF SHAKE) |
FIPS 140-3 Security Policy Trellix FIPS Provider G,R W,E
| Name Query | Description Report available crypto operations. | Indicator FIPS_OK | Inputs Provider context, operation ID. | Outputs Array of available operations. | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Random | Generate random bits using | FIPS_OK | DRBG struct (RBG State); DRBG_Seed. | Status return; Random | Random CKG Section 4 | CO |
| the DRBG. | value. | - DRBG_C: W,E - DRBG_EI: W,E,Z - DRBG_Seed: G,E,Z - DRBG_Key: W,E - DRBG_V: W,E | ||||
| Self-test | Perform the self-test | FIPS_OK | Provider context. | Status (1 = pass, 0 = | ||
| sequence. | fail). | |||||
| Show module name and versioning information | Return module name and | FIPS_OK | Provider context, parameter types (array). | Parameter types | ||
| versioning information. | (array) with: Name, Version. | |||||
| Show status | OpenSSL core metadata | FIPS_OK | Provider context, parameter types (array). | Parameter types with: | ||
| (Gettable parameters; Get | BuildInfo, Status, | |||||
| parameters). | SecurityChecks; Status return. | |||||
| Signature | Generate or verify digital | FIPS_OK | Sign: signing key; message. Verify: signature value; flags; sizes. | Status return; | CKG Section 5 Signature DSA Signature ECDSA Signature EDDSA Signature RSA | CO |
| signatures. (SSPs are passed in | Signature value. | - DS_SGK_ECC: W,E | ||||
| by the calling process.) | - DS_SVK_ECC: W,E - DS_SGK_Edwards: W,E - DS_SVK_Edwards: W,E - DS_SGK_FFC: W,E - DS_SVK_FFC: W,E - DS_SGK_IFC: W,E - DS_SVK_IFC: W,E | |||||
| Teardown | Uninstantiate the module; | FIPS_OK | Provider context. | None. | CO | |
| zeroizes internal CTR DRBG | - DRBG_Key: Z | |||||
| state (DRBG_Key, DRBG_V). | - DRBG_V: Z | |||||
| Zeroize | Zeroization of allocated key | FIPS_OK | Memory pointer. | Void. | CO | |
| structures using | - DRBG_C: Z | |||||
| openssl_cleanse. | - DRBG_EI: Z - DRBG_Key: Z - DRBG_Seed: Z - DRBG_V: Z |
FIPS 140-3 Security Policy Trellix FIPS Provider W,E
Name
Description
Indicator
Inputs
Outputs
Security Functions
SSP Access - DS_SGK_ECC: Z - DS_SGK_Edwards: Z - DS_SGK_FFC: Z - DS_SGK_IFC: Z - DS_SVK_ECC: Z - DS_SVK_Edwards: Z - DS_SVK_FFC: Z - DS_SVK_IFC: Z - GKP_Private_ECC: Z - GKP_Private_Edwards: Z - GKP_Private_FFC: Z - GKP_Private_IFC: Z - GKP_Public_ECC: Z - GKP_Public_Edwards: Z - GKP_Public_FFC: Z - GKP_Public_IFC: Z - KAS_Private_ECC: Z - KAS_Private_FFC: Z - GKP_Private_ECC: Z - KAS_Private_IFC: Z - KAS_Public_ECC: Z - KAS_Public_FFC: Z - KAS_Public_IFC: Z - KAS_SS_ECC: Z - KD_DKM_KDF: Z - KD_DKM_PBKDF: Z - KD_SK: Z - KH_Key_AES-CMAC: Z - KH_Key_AES-GMAC: Z - KH_Key_HMAC: Z - KH_Key_KMAC: Z - KTS_KDK_IFC: Z - KTS_KEK_IFC: Z - KTS_SS_IFC: Z - KAS_SS_ECC: Z
FIPS 140-3 Security Policy Trellix FIPS Provider Z Z
Name
Description
Indicator
Inputs
Outputs
Security Functions
SSP Access - SC_EDK_AES: Z - SC_EDK_XTS: Z
FIPS 140-3 Security Policy Trellix FIPS Provider Table 11: Approved Services All services implemented by the Module correspond to the functionality described by the fips_query function, which returns available services based on an operation_id input. The fips_get_params function provides access to the current status of the Module as well as the name and version; this information correlates to the validation listing. A 1 value returned in status indicates the Module is running without error (FIPS_OK); a 0 return indicates an error (with additional error details indicated as described in the release specific API documentation). Services are only operational in the running state. Any attempts to access services in any other state will result in an error being returned. If the integrity test or any CAST fails then any attempt to access any service will result in an error being returned. The OpenSSL toolkit OSSL_PROVIDER_get_params function is used to invoke fips_get_params, when called with the Module’s global handle and a pointer to a parameter structure (initialized using provider_gettable_params or the equivalent). Regarding the Indicator of approved security services, the Module conforms to FIPS 140-3 IG 2.4.C Approved Security Service Indicator, similar to example 2. Each service provides context sensitive status responses as described in the OpenSSL 3 API manual pages; generally, functions of return type int return the value 1 for success with other error codes as appropriate for the call (described in API documentation). The Module’s name and version parameters (as cited in Section 2) along with the Module’s internal indicators of the security-check and conditional-errors settings are used to confirm the Module is the validated Module operating in the approved mode with only approved security services. Note that the caller provides the KAS_Private and KAS_Public keys for shared secret computation; the caller’s exchange and assurance of PSPs with the remote participant is outside the scope of the Module.
The Module uses HMAC-SHA2-256 as the approved integrity technique; the file fips.so.mac contains the integrity reference value. The Module is provided in an executable form (as fips.so shared object for use in Linux environments).
| Storage Area Name | Description | Persistence Type |
|---|---|---|
| RAM | R: Random access memory | Dynamic |
FIPS 140-3 Security Policy Trellix FIPS Provider
The operator can initiate the integrity test on demand by calling fips_self_test (invoked using OSSL_PROVIDER_self_test called with the Module’s global handle) or reloading the Module.
In accordance with ISO/IEC 19790:2012 Annex B, as the Module is open source, the tools used to build the Module as tested are:
Type of Operational Environment: Modifiable No operational environment restrictions are required for operation in the approved mode. All conditions for operation of the Module in the approved mode are given in Section 2.4. The Module conforms to FIPS 140-3 IG 2.3.C Processor Algorithm Accelerators (PAA) and Processor Algorithm Implementation (PAI). The AES-NI functions are identified by FIPS 140-3 IG 2.3.C as a known PAA.
Name I O
From Calling process Call stack (API) output parameters
To Call stack (API) input parameters Calling process
Format Type Plaintext Plaintext
Distribution Type Manual Manual
Entry Type Electronic Electronic
SFI or Algorithm
| Zeroization Method | Description | Rationale | Operator Initiation |
|---|---|---|---|
| C | C (Cleanse): Caller invocation of openssl_cleanse. | Overwrites with zeros | Caller invocation of openssl_cleanse |
| T | T (Teardown): Module unload - invokes cleanse internally. | Overwrites with zeros | Occurs when module is unloaded |
Name DRBG_C DRBG_EI DRBG_Key DRBG_Seed DRBG_V
Description Element of Hash DRBG state. Entropy input from an external source used for DRBG seeding. Element of CTR DRBG or HMAC DRBG state. Seed used for DRBG Instantiation and Reseed. Element of CTR, Hash or HMAC DRBG state.
Size - Strength Size: 440-888 - Strength: 160 = s = 256 Size: 128-2^35 - Strength: 128 = s = 256 Size: 128-256, 128-256 - Strength: 128 = s = 256, 160 = s = 256 Size: 128-256 - Strength: 128 = s = 256 Size: 128-256, 128-256, 128-256 - Strength: 128 = s = 256, 128 = s = 256, 128 = s = 256
Type - Category Hash_DRBG_C - CSP Other - CSP CTR_DRBG_Key, HMAC_DRBG_Key - CSP Other - CSP CTR_DRBG_Key, Hash_DRBG_Key, HMAC_DRBG_Key - CSP
Generated By Random Random Random Random
Established By
Used By Random Random Random Random Random
FIPS 140-3 Security Policy Trellix FIPS Provider
Table 13: SSP Input-Output Methods
Table 14: SSP Zeroization Methods All SSPs are zeroized (overwritten with 0s) when they are no longer needed:
Name DS_SGK_ECC DS_SGK_Edwards DS_SGK_FFC DS_SGK_IFC DS_SVK_ECC DS_SVK_Edwards DS_SVK_FFC DS_SVK_IFC GKP_Private_ECC
Description SigGen (private) key. SigGen (private) key. SigGen (private) key. SigGen (private) key. SigVer (public) key. SigVer (public) key. SigVer (public) key. SigVer (public) key. General ECDSA (private) key.
Size - Strength Size: 233, 283, 409, 571, 233, 283, 409, 571, 224, 256, 384, 521 - Strength: s = 112, s = 128, s = 192, s = 256, s = 112, s = 128, s = 192, s = 256, s = 112, s = 128, s = 192, s = 256 Size: 255, 448 - Strength: s = 128, s = 224 Size: 2048, 2048, 3072 - Strength: s = 112, s = 112, s = 128 Size: 2048, 3072, 4096, 6144, 8192 - Strength: s = 112, s = 128, s = 152, s = 176, s = 200 Size: 163, 233, 283, 409, 571, 163, 233, 283, 409, 571, 192, 224, 256, 384, 521 - Strength: s < 112, s = 112, s = 128, s = 192, s = 256, s < 112, s = 112, s = 128, s = 192, s = 256, s < 112, s = 112, s = 128, s = 192, s = 256 Size: 255, 448 - Strength: s = 128, s = 224 Size: 1024, 2048, 2048, 3072 - Strength: s < 112, s = 112, s = 112, s = 128 Size: 1024, 2048, 3072, 4096, 6144, 8192 - Strength: s = 112, s = 112, s = 128, s = 152, s = 176, s = 200 Size: 233, 283, 409, 571, 233, 283, 409, 571, 224, 256, 384, 521 - Strength: s = 112, s = 128, s = 192, s = 256, s = 112, s = 128, s =
Type - Category B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 - CSP Edwards25519, Edwards448 - CSP L=2048/N=224, L=2048/N=256, L=3072/N=256 - CSP k=2048, k=3072, k=4096, k=6144, k=8192 - CSP B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521 - PSP Edwards25519, Edwards448 - PSP L=1024/N=160, L=2048/N=224, L=2048/N=256, L=3072/N=256 - PSP k=1024, k=2048, k=3072, k=4096, k=6144, k=8192 - PSP B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 - CSP
Generated By Key management ECC
Established By
Used By Signature ECDSA Signature EDDSA Signature DSA Signature RSA Signature ECDSA Signature EDDSA Signature DSA Signature RSA Key management ECC
FIPS 140-3 Security Policy Trellix FIPS Provider
Name GKP_Private_Edwards GKP_Private_FFC GKP_Private_IFC GKP_Public_ECC GKP_Public_Edwards GKP_Public_FFC GKP_Public_IFC KAS_Private_ECC
Description General EdDSA (private) key. General FFC (private) key. General RSA (private) key. General ECDSA (public) key. General EdDSA (public) key. General FFC (public) key. General RSA (public) key. Key pair component used for shared secret generation.
Size - Strength 192, s = 256, s = 112, s = 128, s = 192, s = 256 Size: 255, 448 - Strength: s = 128, s = 224 Size: 2048, 2048, 3072 - Strength: s = 112, s = 112, s = 128 Size: 2048, 3072, 4096, 6144, 8192 - Strength: s = 112, s = 128, s = 152, s = 176, s = 200 Size: 233, 283, 409, 571, 233, 283, 409, 571, 224, 256, 384, 521 - Strength: s = 112, s = 128, s = 192, s = 256, s = 112, s = 128, s = 192, s = 256, s = 112, s = 128, s = 192, s = 256 Size: 255, 448 - Strength: s = 128, s = 224 Size: 2048, 2048, 3072 - Strength: s = 112, s = 112, s = 128 Size: 2048, 3072, 4096, 6144, 8192 - Strength: s = 112, s = 128, s = 152, s = 176, s = 200 Size: 233, 283, 409, 571, 233, 283, 409, 571, 224, 256, 384, 521 - Strength: s = 112, s = 128, s = 192, s = 256, s = 112, s = 128, s = 192, s = 256, s = 112, s = 128, s = 192, s = 256
Type - Category Edwards25519, Edwards448 - CSP L=2048/N=224, L=2048/N=256, L=3072/N=256 - CSP k=2048, k=3072, k=4096, k=6144, k=8192 - CSP B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 - PSP Edwards25519, Edwards448 - PSP L=2048/N=224, L=2048/N=256, L=3072/N=256 - PSP k=2048, k=3072, k=4096, k=6144, k=8192 - PSP B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 - CSP
Generated By Key management Edwards Key management FFC Key management IFC Key management ECC Key management Edwards Key management FFC Key management IFC
Established By
Used By Key management Edwards Key management FFC Key management IFC Key management ECC Key management Edwards Key management FFC Key management IFC Key agreement
FIPS 140-3 Security Policy Trellix FIPS Provider
Name KAS_Private_FFC KAS_Private_IFC KAS_Public_ECC KAS_Public_FFC KAS_Public_IFC KAS_SS_ECC KAS_SS_FFC KAS_SS_IFC KD_DKM_KDF KD_DKM_PBKDF
Description Key pair component used for shared secret generation. Key pair component used for shared secret generation. Peer key pair component used for shared secret generation. Peer key pair component used for shared secret generation. Peer key pair component used for shared secret generation. Shared secret calculation z output value (for KDF). Shared secret calculation z output value (for KDF). Shared secret calculation z output value (for KDF). Key derivation derived keying material. PBKDF derived key material
Size - Strength Size: 2048, 3072, 4096, 6144, 8192 - Strength: s = 112, 112 = s = 128, 112 = s = 152, 112 = s = 176, 112 = s = 200 Size: 2048, 3072, 4096, 6144, 8192 - Strength: s = 112, s = 128, s = 152, s = 176, s = 200 Size: 233, 283, 409, 571, 233, 283, 409, 571, 224, 256, 384, 521 - Strength: s = 112, s = 128, s = 192, s = 256, s = 112, s = 128, s = 192, s = 256, s = 112, s = 128, s = 192, s = 256 Size: 2048, 3072, 4096, 6144, 8192 - Strength: s = 112, 112 = s = 128, 112 = s = 152, 112 = s = 176, 112 = s = 200 Size: 2048, 3072, 4096, 6144, 8192 - Strength: s = 112, s = 128, s = 152, s = 176, s = 200 Size: 112 - 256 - Strength: 112 - 256 Size: 112 - 256 - Strength: 112 - 200 Size: 112 - 256 - Strength: 112 - 200 Size: 128 - 256 - Strength: 128 - 256 Size: 128 - Strength: 128
Type - Category ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 - CSP k=2048, k=3072, k=4096, k=6144, k=8192 - CSP B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 - PSP ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 - PSP k=2048, k=3072, k=4096, k=6144, k=8192 - PSP Other - CSP Other - CSP Other - CSP Other - CSP Other - CSP
Generated By Key derivation Key derivation
Established By Key agreement Key agreement Key agreement
Used By Key agreement Key agreement Key agreement Key agreement Key agreement Key agreement Key agreement Key agreement Key derivation Key derivation
FIPS 140-3 Security Policy Trellix FIPS Provider
Name KD_PW_PBKDF KD_SK KH_Key_AES-CMAC KH_Key_AES-GMAC KH_Key_HMAC KH_Key_KMAC KTS_KDK_IFC KTS_KEK_IFC KTS_SS_IFC SC_EDK_AES SC_EDK_XTS
Description PBKDF password input. Key derivation source key material. Keyed Hash key. Keyed Hash key. Keyed Hash key. Keyed Hash key. RSA key de- encapsulation Key (key transport). RSA key encapsulation Key (key transport). RSA key transport shared secret. Symmetric encryption and decryption. Symmetric encryption and decryption.
Size - Strength Size: 128 - Strength: 128 Size: 128 - 256 - Strength: 128 - 256 Size: 128, 192, 256 - Strength: s = 128, s = 192, s = 256 Size: 128, 192, 256 - Strength: s = 128, s = 192, s = 256 Size: 112 - 2048 - Strength: 112 - 256 Size: 128, 256 - Strength: 112 = s = 128, 112 = s = 256 Size: 2048, 3072, 4096, 6144 - Strength: s = 112, s = 128, s = 152, s = 176 Size: 2048, 3072, 4096, 6144 - Strength: s = 112, s = 128, s = 152, s = 176 Size: 112 - 256 - Strength: s = 112 - s = 176 Size: 128, 192, 256 - Strength: s = 128, s = 192, s = 256 Size: 256, 512 - Strength: s = 128, s = 256
Type - Category Other - CSP Other - CSP AES-128, AES-192, AES-256 - CSP AES-128, AES-192, AES-256 - CSP Other - CSP KMAC128, KMAC256 - CSP Other - CSP Other - PSP Other - CSP AES-128, AES-192, AES-256 - CSP XTS-128, XTS-256 - CSP
Generated By Key derivation
Established By Key transport
Used By Key derivation Key derivation MAC AES (CMAC, GMAC) MAC AES (CMAC, GMAC) MAC HMAC MAC KMAC (XOF) Key transport Key transport Key transport Cipher (Unauth) Cipher (Auth) Cipher (Unauth)
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs |
|---|---|---|---|---|---|
| DRBG_C | I | RAM:Plaintext | Call lifetime | C | DRBG_Seed:Derived From |
| O | DRBG_V:Used with | ||||
| DRBG_EI | I | RAM:Plaintext | Call lifetime | C | DRBG_Seed:Constituent |
| DRBG_Key | I | RAM:Plaintext | Call lifetime (module up time for internal DRBG) | C T | DRBG_Seed:Derived From |
| O | DRBG_V:Used with |
FIPS 140-3 Security Policy Trellix FIPS Provider Table 15: SSP Table 1
| Name DRBG_Seed | Input - Output | Storage RAM:Plaintext | Storage Duration Call lifetime | Zeroization C | Related SSPs DRBG_C:Derives DRBG_Key:Derives DRBG_V:Derives DRBG_EI:Incorporates |
|---|---|---|---|---|---|
| DRBG_V | I | RAM:Plaintext | Call lifetime (module up time for internal DRBG) | C T | DRBG_Seed:Derived From |
| O | DRBG_Key:Used with | ||||
| DS_SGK_ECC | I | RAM:Plaintext | Call lifetime | C | DS_SVK_ECC:Paired With |
| DS_SGK_Edwards | I | RAM:Plaintext | Call lifetime | C | DS_SVK_Edwards:Paired With |
| DS_SGK_FFC | I | RAM:Plaintext | Call lifetime | C | DS_SVK_FFC:Paired With |
| DS_SGK_IFC | I | RAM:Plaintext | Call lifetime | C | DS_SVK_IFC:Paired With |
| DS_SVK_ECC | I | RAM:Plaintext | Call lifetime | C | DS_SGK_ECC:Paired With |
| DS_SVK_Edwards | I | RAM:Plaintext | Call lifetime | C | DS_SGK_Edwards:Paired With |
| DS_SVK_FFC | I | RAM:Plaintext | Call lifetime | C | DS_SGK_FFC:Paired With |
| DS_SVK_IFC | I | RAM:Plaintext | Call lifetime | C | DS_SGK_IFC:Paired With |
| GKP_Private_ECC | O | RAM:Plaintext | Call lifetime | C | GKP_Public_ECC:Paired With |
| GKP_Private_Edwards | O | RAM:Plaintext | Call lifetime | C | GKP_Public_Edwards:Paired With |
| GKP_Private_FFC | O | RAM:Plaintext | Call lifetime | C | GKP_Public_FFC:Paired With |
| GKP_Private_IFC | O | RAM:Plaintext | Call lifetime | C | GKP_Public_IFC:Paired With |
| GKP_Public_ECC | O | RAM:Plaintext | Call lifetime | C | GKP_Private_ECC:Paired With |
| GKP_Public_Edwards | O | RAM:Plaintext | Call lifetime | C | GKP_Private_Edwards:Paired With |
| GKP_Public_FFC | O | RAM:Plaintext | Call lifetime | C | GKP_Private_FFC:Paired With |
| GKP_Public_IFC | O | RAM:Plaintext | Call lifetime | C | GKP_Private_IFC:Paired With |
| KAS_Private_ECC | I | RAM:Plaintext | Call lifetime | C | KAS_Public_ECC:Paired With |
| KAS_Private_FFC | I | RAM:Plaintext | Call lifetime | C | KAS_Public_FFC:Paired With |
| KAS_Private_IFC | I | RAM:Plaintext | Call lifetime | C | KAS_Public_IFC:Paired With |
| KAS_Public_ECC | I | RAM:Plaintext | Call lifetime | C | KAS_Private_ECC:Paired With |
| KAS_Public_FFC | I | RAM:Plaintext | Call lifetime | C | KAS_Private_FFC:Paired With |
| KAS_Public_IFC | I | RAM:Plaintext | Call lifetime | C | KAS_Private_IFC:Paired With |
| KAS_SS_ECC | O | RAM:Plaintext | Call lifetime | C | KAS_Private_ECC:Calculated From KAS_Public_ECC:Calculated From |
| KAS_SS_FFC | O | RAM:Plaintext | Call lifetime | C | KAS_Private_FFC:Calculated From KAS_Public_FFC:Calculated From |
| KAS_SS_IFC | O | RAM:Plaintext | Call lifetime | C | KAS_Private_IFC:Calculated From KAS_Public_IFC:Calculated From |
| KD_DKM_KDF | O | RAM:Plaintext | Call lifetime | C | KD_SK:Derived From |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs |
|---|---|---|---|---|---|
| KD_DKM_PBKDF | O | RAM:Plaintext | Call lifetime | C | KD_PW_PBKDF:Derived From |
| KD_PW_PBKDF | I | RAM:Plaintext | Call lifetime | C | KD_DKM_PBKDF:Derives |
| KD_SK | I | RAM:Plaintext | Call lifetime | C | KD_DKM_KDF:Derives |
| KH_Key_AES-CMAC | I | RAM:Plaintext | Call lifetime | C | |
| KH_Key_AES-GMAC | I | RAM:Plaintext | Call lifetime | C | |
| KH_Key_HMAC | I | RAM:Plaintext | Call lifetime | C | |
| KH_Key_KMAC | I | RAM:Plaintext | Call lifetime | C | |
| KTS_KDK_IFC | I | RAM:Plaintext | Call lifetime | C | KTS_SS_IFC:Unwraps |
| KTS_KEK_IFC | I | RAM:Plaintext | Call lifetime | C | KTS_SS_IFC:Wraps |
| KTS_SS_IFC | O | RAM:Plaintext | Call lifetime | C | KTS_KDK_IFC:Unwrapped By KTS_KEK_IFC:Wrapped By |
| SC_EDK_AES | I | RAM:Plaintext | Call lifetime | C | |
| SC_EDK_XTS | I | RAM:Plaintext | Call lifetime | C |
FIPS 140-3 Security Policy Trellix FIPS Provider Table 16: SSP Table 2 Keys used for CASTs and the temporary value used in the integrity test are not SSPs; however, the latter is deleted after use as required by AS05.10. The Module maintains only the Counter DRBG state used for key generation as a persistent CSP; this DRBG instance is used exclusively for approved services.
Key/Algorithm Type Equivalent Strengths: Reference sources for the strengths provided in SSP Table 1 are specified below. Equivalent strength is given for each key or algorithm type (as some algorithms do not use or produce keys). Block Cipher (and related functions): • AES (AES-128, AES-192, AES-256): SP 800-57 Part 1 Rev. 5 Table
Algorithm or Test SW Integrity
Test Properties HMAC-SHA2-256 #A6884
Test Method HMAC over the complete module file image
Test Type SW/FW Integrity
Indicator FIPS_OK or PROV_R_FIPS_MODULE_IN_ERROR_STATE
Details
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| AES-ECB | 128-bit | KAT | CAST | FIPS_OK | Encrypt | Performed on module load. |
| AES-ECB | 128-bit | KAT | CAST | FIPS_OK | Decrypt | Performed on module load. |
| AES-GCM | 256-bit | KAT | CAST | FIPS_OK | Encrypt | Performed on module load. |
| AES-GCM | 256-bit | KAT | CAST | FIPS_OK | Decrypt | Performed on module load. |
FIPS 140-3 Security Policy Trellix FIPS Provider In Digital Signature applications, security strength is primarily associated with the asymmetric key pair specification. The hash function used must have equivalent strength equal to or greater than the security strength of the associated key pair. Secure Hash (and related functions): • SHA-1, SHA2 (SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256): SP 800-107 Rev. 1 Table 1. • SHA3 (SHA3-224, SHA3-256, SHA3-384, SHA3-512): SP 800-57 Part 1 Rev. 5 Table 3. • SHAKE (SHAKE128, SHAKE256): SP 800-185 Section 8.1. Preimage resistance strength applies to hash algorithms used in DRBG, KDFs. Described also in SP 800-57 Part 1 Rev. 5 Table
Table 17: Pre-Operational Self-Tests
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| Counter DRBG | AES-128 with derivation function | KAT | CAST | FIPS_OK | Instantiate, Generate, Reseed | Performed on module load. |
| DSA SigGen (FIPS186-4) | 2048-bit with SHA2-384 | KAT | CAST | FIPS_OK | Sign | Performed on module load. |
| DSA SigVer (FIPS186-4) | 2048-bit with SHA2-384 | KAT | CAST | FIPS_OK | Verify | Performed on module load. |
| ECDSA SigGen (FIPS186-4) | P-224 with SHA2-512 | KAT | CAST | FIPS_OK | Sign | Performed on module load. |
| ECDSA SigVer (FIPS186-4) | P-224 with SHA2-512 | KAT | CAST | FIPS_OK | Verify | Performed on module load. |
| EDDSA ED448 SigGen | Edwards448 SigGen with SHA2- 256 | KAT | CAST | FIPS_OK | Sign | Performed on module load. |
| EDDSA ED448 SigVer | Edwards448 SigVer with SHA2- 256 | KAT | CAST | FIPS_OK | Verify | Performed on module load. |
| EDDSA ED25519 SigGen | Edwards25519 SigGen with SHA2-512 | KAT | CAST | FIPS_OK | Sign | Performed on module load. |
| EDDSA ED25519 SigVer | Edwards25519 SigVer with SHA2-512 | KAT | CAST | FIPS_OK | Verify | Performed on module load. |
| Hash DRBG | SHA2-256 | KAT | CAST | FIPS_OK | Instantiate, Generate, Reseed | Performed on module load. |
| HMAC DRBG | SHA-1 | KAT | CAST | FIPS_OK | Instantiate, Generate, Reseed | Performed on module load. |
| HMAC-SHA2-256 | SHA2-256 with a 256-bit key | KAT | CAST | FIPS_OK | Generate | Performed on module load. |
| KAS-ECC-SSC | P-256 | KAT | CAST | FIPS_OK | Ephemeral Unified Shared Secret | Performed on module load. |
| Sp800-56Ar3 | (Z) Computation | |||||
| KAS-FFC-SSC | L=2048/N=256 | KAT | CAST | FIPS_OK | dhEphem Shared Secret (Z) | Performed on module load. |
| Sp800-56Ar3 | Computation | |||||
| KAS-IFC-SSC | k=2048 | KAT | CAST | FIPS_OK | SP 800-56B Rev. 2 Section 8.2.2 RSA Primitive Computation | Performed on module load. |
| KAS-KDF | SHA2-224 | KAT | CAST | FIPS_OK | SP 800-56C Rev. 2 Section 4 | Performed on module load. |
| OneStep SP800- | OneStep KDF (AKA OpenSSL single- | |||||
| 56Cr2 | step or SS-KDF) | |||||
| KAS-KDF | SHA2-256 | KAT | CAST | FIPS_OK | SP 800-56C Rev. 2 Section 5 | Performed on module load. |
| TwoStep SP800- 56Cr2 | TwoStep KDF (HKDF variant) | |||||
| KDF ANS 9.42 | Fixed input KAT | KAT | CAST | FIPS_OK | SP 800-135 Rev. 1 Section 5.1 ANSI X9.42-2001 KDF KAT | Performed on module load. |
FIPS 140-3 Security Policy Trellix FIPS Provider
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| KDF ANS 9.63 | Fixed input KAT | KAT | CAST | FIPS_OK | SP 800-135 Rev. 1 Section 5.1 X9.63-2001 KDF KAT | Performed on module load. |
| KDF SP800-108 | HMAC-SHA2-256 | KAT | CAST | FIPS_OK | SP 800-108 Rev. 1 Section 4.1 KAT for a Counter Mode KDF | Performed on module load. |
| KDF SSH | Fixed input KAT | KAT | CAST | FIPS_OK | SP 800-135 Rev. 1 Section 5.2 SSHv2 KDF KAT | Performed on module load. |
| KTS-IFC | k=2048 | KAT | CAST | FIPS_OK | SP 800-56B Rev. 2 Decrypt for CRT | Performed on module load. |
| KTS-IFC | k=2048 | KAT | CAST | FIPS_OK | SP 800-56B Rev. 2 Encrypt for Basic | Performed on module load. |
| KTS-IFC | k=2048 | KAT | CAST | FIPS_OK | SP 800-56B Rev. 2 Decrypt for Basic | Performed on module load. |
| PBKDF | SHA2-256, 24-byte password, | KAT | CAST | FIPS_OK | SP 800-132 Section 5.3 KAT of | Performed on module load. |
| 36-byte salt, iteration count of 4096 | Master Key derivation | |||||
| RSA SigGen (FIPS186-4) | k=2048 with SHA2-256 | KAT | CAST | FIPS_OK | Sign | Performed on module load. |
| RSA SigVer (FIPS186-4) | k=2048 with SHA2-256 | KAT | CAST | FIPS_OK | Verify | Performed on module load. |
| SHA-1 | SHA-1 | KAT | CAST | FIPS_OK | Simple SHA KAT | Performed on module load. |
| SHA2-512 | SHA2-512 | KAT | CAST | FIPS_OK | Simple SHA KAT | Performed on module load. |
| SHA3-256 | SHA3-256 | KAT | CAST | FIPS_OK | Simple SHA KAT | Performed on module load. |
| TLS v1.2 KDF | Fixed input KAT | KAT | CAST | FIPS_OK | SP 800-135 Rev. 1 Section 4.2.2 TLS | Performed on module load. |
| RFC7627 | 1.2 KAT | |||||
| TLS v1.3 KDF | Fixed input KAT | KAT | CAST | FIPS_OK | RFC8446 Section 7.1 TLS v1.3 KDF KAT | Performed on module load. |
| DSA KeyGen | PCT performed using the | PCT | PCT | FIPS_OK | Sign, Verify | Performed on FFC (DSA, KAS-FFC-SSC) key pair |
| (FIPS186-4) | generated key pair | generation, prior to returning the key pair on conclusion of the call. | ||||
| ECDSA KeyGen | PCT performed using the | PCT | PCT | FIPS_OK | Sign, Verify | Performed on ECC (ECDSA) key pair generation, |
| (FIPS186-4) | generated key pair | prior to returning the key pair on conclusion of the call. | ||||
| EDDSA KeyGen | PCT performed using the | PCT | PCT | FIPS_OK | Sign, Verify | Performed on Edwards (EdDSA) key pair |
| generated key pair | generation, prior to returning the key pair on conclusion of the call. | |||||
| RSA KeyGen | PCT performed using the | PCT | PCT | FIPS_OK | Sign, Verify | Performed on IFC (RSA, KAS-IFC-SSC, KTS-IFC) key |
| (FIPS186-4) | generated key pair | pair generation, prior to returning the key pair on conclusion of the call. |
FIPS 140-3 Security Policy Trellix FIPS Provider Table 18: Conditional Self-Tests
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| SW Integrity | HMAC over the complete module file image | SW/FW Integrity | On demand | Module load |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| AES-ECB | KAT | CAST | On demand | On power on or reset |
| AES-ECB | KAT | CAST | On demand | On power on or reset |
| AES-GCM | KAT | CAST | On demand | On power on or reset |
| AES-GCM | KAT | CAST | On demand | On power on or reset |
| Counter DRBG | KAT | CAST | On demand | On power on or reset |
| DSA SigGen (FIPS186-4) | KAT | CAST | On demand | On power on or reset |
| DSA SigVer (FIPS186-4) | KAT | CAST | On demand | On power on or reset |
| ECDSA SigGen (FIPS186-4) | KAT | CAST | On demand | On power on or reset |
| ECDSA SigVer (FIPS186-4) | KAT | CAST | On demand | On power on or reset |
| EDDSA ED448 SigGen | KAT | CAST | On demand | On power on or reset |
| EDDSA ED448 SigVer | KAT | CAST | On demand | On power on or reset |
| EDDSA ED25519 SigGen | KAT | CAST | On demand | On power on or reset |
| EDDSA ED25519 SigVer | KAT | CAST | On demand | On power on or reset |
| Hash DRBG | KAT | CAST | On demand | On power on or reset |
| HMAC DRBG | KAT | CAST | On demand | On power on or reset |
| HMAC-SHA2-256 | KAT | CAST | On demand | On power on or reset |
| KAS-ECC-SSC Sp800-56Ar3 | KAT | CAST | On demand | On power on or reset |
| KAS-FFC-SSC Sp800-56Ar3 | KAT | CAST | On demand | On power on or reset |
| KAS-IFC-SSC | KAT | CAST | On demand | On power on or reset |
| KAS-KDF OneStep SP800-56Cr2 | KAT | CAST | On demand | On power on or reset |
| KAS-KDF TwoStep SP800-56Cr2 | KAT | CAST | On demand | On power on or reset |
| KDF ANS 9.42 | KAT | CAST | On demand | On power on or reset |
| KDF ANS 9.63 | KAT | CAST | On demand | On power on or reset |
| KDF SP800-108 | KAT | CAST | On demand | On power on or reset |
| KDF SSH | KAT | CAST | On demand | On power on or reset |
| KTS-IFC | KAT | CAST | On demand | On power on or reset |
| KTS-IFC | KAT | CAST | On demand | On power on or reset |
FIPS 140-3 Security Policy Trellix FIPS Provider The intended usage of asymmetric key pairs generated by the Module is not known at the time when the key pair is generated and the pairwise consistency test (PCT) is performed. In all cases, a sign and verify PCT is performed.
Table 19: Pre-Operational Periodic Information
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| KTS-IFC | KAT | CAST | On demand | On power on or reset |
| PBKDF | KAT | CAST | On demand | On power on or reset |
| RSA SigGen (FIPS186-4) | KAT | CAST | On demand | On power on or reset |
| RSA SigVer (FIPS186-4) | KAT | CAST | On demand | On power on or reset |
| SHA-1 | KAT | CAST | On demand | On power on or reset |
| SHA2-512 | KAT | CAST | On demand | On power on or reset |
| SHA3-256 | KAT | CAST | On demand | On power on or reset |
| TLS v1.2 KDF RFC7627 | KAT | CAST | On demand | On power on or reset |
| TLS v1.3 KDF | KAT | CAST | On demand | On power on or reset |
| DSA KeyGen (FIPS186-4) | PCT | PCT | On demand | On power on or reset |
| ECDSA KeyGen (FIPS186-4) | PCT | PCT | On demand | On power on or reset |
| EDDSA KeyGen | PCT | PCT | On demand | On power on or reset |
| RSA KeyGen (FIPS186-4) | PCT | PCT | On demand | On power on or reset |
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| Self-test | The self-test failure error | If one of the KATs fails or integrity test | Reload the Module into | PROV_R_FIPS_MODULE_IN_ERROR_STATE |
| failure | state | fails | memory |
FIPS 140-3 Security Policy Trellix FIPS Provider Table 20: Conditional Periodic Information
Each time the Module is powered up it tests that the cryptographic algorithms still operate correctly and that sensitive data has not been damaged. The pre-operational self-tests are available on demand by reloading the Module. On instantiation, the Module performs the pre-operational self-test and all CASTs. All KATs must complete successfully prior to any other use of cryptography by the Module. The fips_self_test function (inclusive of software integrity verification) can also be called on demand, fulfilling AS05.11.
FIPS 140-3 Security Policy Trellix FIPS Provider
During the manufacturing process, Musarubra US LLC executes the build and installation instructions for the Module. The Module is pre-installed and configured in supported Musarubra US LLC solutions. The approved mode is enabled by default. There are no additional installation, configuration, or usage instructions for operators intending to use the Module.
Guidance Documentation is inclusive of all information required per ISO/IEC 19790:2012 Section 7.11.9.
The inherent properties of the Module are:
The Module implements mitigations for constant-time implementations and blinding attacks.
Constant-time implementations protect cryptographic implementations in the Module against timing analysis since such attacks exploit differences in execution time depending on the cryptographic operation, and constant-time implementations ensure that the variations in execution time cannot be traced back to the key, CSP or secret data. Numeric blinding protects the RSA, DSA and ECDSA algorithms from timing attacks. These algorithms are vulnerable to such attacks since attackers can measure the time of signature operations or RSA decryption. To mitigate this, the Module generates a random blinding factor which is provided as an input to the decryption/signature operation and is discarded once the operation has completed and resulted in an output. This makes it difficult for attackers to attempt timing attacks on such operations without the knowledge of the blinding factor, and therefore the execution time cannot be correlated to the RSA/DSA/ECDSA key.
FIPS 140-3 Security Policy Trellix FIPS Provider
The mitigation mechanisms described in Section 12.2 are inherent within the validated algorithms. No other guidance or constraints are specified.