All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Apple corecrypto Module v12.0 [Apple silicon, Secure Key Store, Hardware, SL2]

Certificate#5025StandardFIPS 140-3Level2TypeHardwareEmbodimentSingle ChipStatusActiveVendorApple Inc.
Low review priority  ·  no TCB surface named  ·  last validated 13 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date6/15/2030
CaveatWhen operated in approved mode
VendorApple Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Apple corecrypto Module v12.0 [Apple silicon, Secure Key Store, Hardware, SL2]
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Unauthenticated<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Apple corecrypto Module v12.0 [Apple silicon, Secure Key Store, Hardware, SL2]
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Unauthenticated<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Apple Inc. Apple corecrypto Module v12.0 [Apple silicon, Secure Key Store, Hardware, SL2] Prepared for: Apple Inc. One Apple Park Way Cupertino, CA 95014 Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com

Page 2

This document may be reproduced and distributed only in its original entirely without revision.

Page 3
Table of Contents
#SectionPage
Page 4

This document may be reproduced and distributed only in its original entirely without revision.

Page 5

List of Tables Table 3: Tested Module Identification – Software/Firmware/Hybrid (Executable Code Sets) .. Error! Bookmark not defined. defined. Bookmark not defined. defined. This document may be reproduced and distributed only in its original entirely without revision.

Page 6

List of Figures This document may be reproduced and distributed only in its original entirely without revision.

Page 7

Trademarks Apple’s trademarks applicable to this document are listed in https://www.apple.com/legal/intellectual-property/trademark/appletmlist.html. Other company, product, and service names may be trademarks or service marks of others. This document may be reproduced and distributed only in its original entirely without revision.

Page 8
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level2
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for Apple corecrypto Module v12.0 [Apple silicon, Secure Key Store, Hardware, SL2] cryptographic module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 2 module. This document provides all tables and diagrams (when applicable) required by NIST SP 800140Br1.

1.2 Security Levels

Table 1: Security Levels This document may be reproduced and distributed only in its original entirely without revision.

Page 9
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Apple corecrypto Module v12.0 [Apple silicon, Secure Key Store, Hardware, SL2] cryptographic module (hereafter referred to as “the module”) consists of both firmware and hardware components. The Secure Key Store (SKS) application is the module’s firmware which operates within the sepOS execution environment which is separate from the Device OS’ (iPadOS 15, iOS 15, tvOS 15, watchOS 8) execution environment. The firmware interface is defined as the API offered by the module's mailbox interface to callers from the Device OS execution environment. SKS has an API layer that provides consistent interfaces to the supported services and therefore the supported cryptographic algorithms. In addition, the module provides Inter-Process Communication (IPC) interfaces to other applications executing within the sepOS execution environment. The sepOS execution environment is driven by its own CPU and operates from a dedicated region of the device’s memory. Both the Device’s and sepOS’ execution environments are physically separated on the SoC and thus execute independently of each other. Module Type: Hardware Module Embodiment: SingleChip Module Characteristics: SubChip Cryptographic Boundary: The module cryptographic boundary is delineated by the dotted blue rectangle in the Figure 1. The cryptographic module boundary includes the following hardware components:

Hardware Random Number Generator composed of a SP800-90A Approved CTR_DRBG and a physical entropy source compliant to SP800-90B.
Hardware AES implementing AES-ECB and AES-CBC encryption and decryption.
Hardware Public Key Accelerator (PKA) used for generating asymmetric key pairs.
A volatile RAM for storing runtime SSPs.
A non-volatile Flash for storing an encrypted Class D key.

The physical perimeter is represented by the most exterior black line in the block diagram Figure 1. This document may be reproduced and distributed only in its original entirely without revision.

Page 10

Figure 1: Block Diagram Tested Operational Environment’s Physical Perimeter (TOEPP): A photograph of each hardware module is shown below: Figure 3: Apple Figure 4: Apple Figure 6: Apple Figure 2: Apple A9 Figure 5: Apple A9X A10 Fusion A11 Bionic A10X Fusion This document may be reproduced and distributed only in its original entirely without revision.

Page 11
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
iPad (5th generation) running sepOS distributed with iPadOS 152.012.0Apple A Series A9N/A
iPad Pro 9.7-inch running sepOS distributed with iPadOS 152.012.0Apple A Series A9XN/A
iPad (7th generation) running sepOS distributed with iPadOS 152.012.0Apple A Series A10 FusionN/A
iPad Pro 10.5 inch running sepOS distributed with iPadOS 152.012.0Apple A Series A10X FusionN/A
iPad mini (5th generation) running sepOS distributed with iPadOS 152.012.0Apple A Series A12 BionicN/A
iPad Pro 11-inch (1st generation) running sepOS distributed with iPadOS 152.012.0Apple A Series A12X BionicN/A
iPad Pro 11-inch (2nd generation) running sepOS distributed with iPadOS 152.012.0Apple A Series A12Z BionicN/A
iPhone 6S running sepOS distributed with iOS 152.012.0Apple A Series A9N/A

Figure 12: Apple Figure 13: Apple Figure 14: Apple S5 S6 S7

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification – Hardware: This document may be reproduced and distributed only in its original entirely without revision.

Page 12
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
iPhone 7 Plus running sepOS distributed with iOS 152.012.0Apple A Series A10 FusionN/A
iPhone X running sepOS distributed with iOS 152.012.0Apple A Series A11 BionicN/A
iPhone XS Max running sepOS distributed with iOS 152.012.0Apple A Series A12 BionicN/A
Apple Watch Series S3 running sepOS distributed with watchOS 82.012.0Apple S Series S3N/A
Apple Watch Series S4 running sepOS distributed with watchOS 82.012.0Apple S Series S4N/A
Apple Watch Series S5 running sepOS distributed with watchOS 82.012.0Apple S Series S5N/A
Apple Watch Series S6 running sepOS distributed with watchOS 82.012.0Apple S Series S6N/A
Apple Watch Series S7 running sepOS distributed with watchOS 82.012.0Apple S Series S7N/A
Apple TV 4K running sepOS distributed with tvOS 152.012.0Apple A Series A10X FusionN/A
Mode NameDescriptionTypeStatus Indicator
Approved modeApproved mode of operation is entered when the module utilizes the services that use the security functions listed in the Approved Algorithms Table and the Vendor Affirmed Algorithms Table.Approvedreturn a '0' from fips_allowed_mode() for block cipher functions and fips_allowed() for all other services to indicate the executed cryptographic algorithm was approved
2.3 Excluded Components

None for this module Modes List and Description: This document may be reproduced and distributed only in its original entirely without revision.

Page 13
Mode NameDescriptionTypeStatus Indicator
Non- Approved modeNon-Approved mode of operation is entered when the module utilizes non- approved security functions in the Table Non-Approved Algorithms Not Allowed in the Approved Mode of Operation.Non- Approvedreturn a non-zero value from fips_allowed_mode() for block cipher functions and fips_allowed() for all other services to indicate the executed cryptographic algorithm was non- approved
AlgorithmCAVP CertPropertiesReference
AES-CBCA2842Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA2843Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA2844Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA2845Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA510Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCC314Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-CBCC315Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-CBCC317Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-CBCC318Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-CBCC319Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A

This document may be reproduced and distributed only in its original entirely without revision.

Page 14
AlgorithmCAVP CertPropertiesReference
AES-CBCC320Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-CBCC322Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-CBCC326Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-CBCC358Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AlgorithmCAVP CertPropertiesReference
AES-ECBA2842Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA2843Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA2845Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA2847Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA501Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBA510Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBAES 5261Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBAES 5272Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBAES 5273Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBAES 5274Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBAES 5275Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBAES 5278Direction - Encrypt Key Length - 256SP 800-38A

Table 4: Approved Algorithms - AES-CBC This document may be reproduced and distributed only in its original entirely without revision.

Page 15
AlgorithmCAVP CertPropertiesReference
AES-ECBC314Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-ECBC315Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-ECBC317Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-ECBC318Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-ECBC319Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-ECBC320Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-ECBC322Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-ECBC323Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBC324Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBC326Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-ECBC331Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBC358Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AlgorithmCAVP CertPropertiesReference
AES-KWA2843Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWA2845Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWA2846Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F

Table 5: Approved Algorithms - AES-ECB Table 6: Approved Algorithms - AES-KW This document may be reproduced and distributed only in its original entirely without revision.

Page 16
AlgorithmCAVP CertPropertiesReference
Counter DRBGA501Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
Counter DRBGC323Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
Counter DRBGC324Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
Counter DRBGC331Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
Counter DRBGDRBG 2014Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
Counter DRBGDRBG 2022Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
Counter DRBGDRBG 2023Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
Counter DRBGDRBG 2024Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
Counter DRBGDRBG 2025Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
Counter DRBGDRBG 2028Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
AlgorithmCAVP CertPropertiesReference
HMAC-SHA-1A2845Key Length - Key Length: 8-262144 Increment 8FIPS 198-1

CTR_DRBG Table 7: Approved Algorithms - CTR_DRBG This document may be reproduced and distributed only in its original entirely without revision.

Page 17
AlgorithmCAVP CertPropertiesReference
HMAC-SHA-1A2848Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2-224A2845Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2-224A2848Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2-256A2845Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2-256A2848Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2-256A2849Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2-384A2845Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2-384A2848Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2-512A2845Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2-512A2848Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A2848Key Length - Key Length: 8-262144 Increment 8FIPS 198-1
AlgorithmCAVP CertPropertiesReference
SHA-1A2845Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA-1A2848Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA2-224A2845Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA2-224A2848Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA2-256A2845Message Length - Message Length: 0-32768 Increment 8FIPS 180-4

Table 8: Approved Algorithms - HMAC Message-Digest This document may be reproduced and distributed only in its original entirely without revision.

Page 18
AlgorithmCAVP CertPropertiesReference
SHA2-256A2848Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA2-256A2849Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA2-384A2845Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA2-384A2848Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA2-512A2845Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA2-512A2848Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
SHA2- 512/256A2848Message Length - Message Length: 0-32768 Increment 8FIPS 180-4
NamePropertiesImplementationReference
CKGKey Type:SymmetricN/ASP800-133 Rev2 Section 4, example 1
NameUse and Function
Ed25519 Key generationEdDSA signature scheme
Ed25519 shared secret generationEdDSA shared secret generation
Curve 25519 key generationkey generation
Curve 25519 shared secret generationshared secret generation
ECDH Key Pair GenerationElliptic Curve Integrated Encryption Scheme (ECIES) Key Generation
ECDH Shared Secret ComputationElliptic Curve Integrated Encryption Scheme (ECIES) Encryption/Decryption
ANSI X9.63 KDFElliptic Curve Integrated Encryption Scheme (ECIES) Encryption/Decryption

Table 9: Approved Algorithms - Message-Digest Vendor-Affirmed Algorithms: Table 10: Vendor-Affirmed Algorithms Non-Approved, Not Allowed Algorithms: This document may be reproduced and distributed only in its original entirely without revision.

Page 19
NameUse and Function
AES-GCMElliptic Curve Integrated Encryption Scheme (ECIES) Encryption/Decryption
HKDF RFC5869HMAC based Key Derivation Function
PBKDFKey Derivation
ECDSA implemented in FWKey generation as part of Ref key generation service and validation, Signature generation and verification as part of Device keybag service
ECDSA implemented in HW PKAKey generation as part of Ref key generation service Signature generation primitive
ECDH implemented in FWShared secret computation
ECDH implemented in HW PKAShared secret computation
AES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyKey wrapping and unwrapping
NameTypeDescriptionPropertiesAlgorithms
Unauthenticated Symmetric Encryption and DecryptionBC-UnAuthAES Encrypt/DecryptAES-CBC:128-, 192-, 256-bit keys AES-ECB:128-, 192-, 256-bit keysAES-CBC: (A2842, A2843, A2844, A2845, A510) Key Size/Strength: 128, 192, 256 AES-ECB: (A2842, A2843, A2845, A2847, A510) Key Size/Strength: 128, 192, 256 AES-ECB: (A501, AES 5261, AES 5272, AES 5273, AES 5274, AES 5275, AES 5278)

Table 11: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

This document may be reproduced and distributed only in its original entirely without revision.

Page 20
NameTypeDescriptionPropertiesAlgorithms
Key Size/Strength: 256 AES-ECB: (C314, C315, C317, C318, C319, C320, C322, C323, C324, C326, C331, C358) Key Size/Strength: 128, 256 AES-CBC: (C315, C317, C318, C319, C320, C322, C326, C358, C314) Key Size/Strength: 128, 256
key wrapping / key unwrappingKTS-WrapAES Key WrappingKTS (AES) [SP 800-38F]:AES- KWAES-KW: (A2843, A2845, A2846) Key Size/Strength: 128, 192, 256
Random Number GenerationDRBGRandom number generator using AES-256CTR_DRBG [SP800- 90ARev1]:AES- 256; No Derivation Function; Prediction Resistance EnabledCounter DRBG: (DRBG 2014, DRBG 2022, DRBG 2023, DRBG 2024, DRBG 2025, DRBG 2028, A501, C323, C324, C331) Key Size/Strength: 256
HMAC Message AuthenticationMACKey Length 8 - 262144 bits/ KeyHMAC [FIPS 198]:SHA-1,HMAC-SHA-1: (A2845, A2848)

This document may be reproduced and distributed only in its original entirely without revision.

Page 21
NameTypeDescriptionPropertiesAlgorithms
Strength: 112 to 256 bitsSHA-224, SHA- 256, SHA-384, SHA-512, SHA- 512/256HMAC-SHA2- 224: (A2845, A2848) HMAC-SHA2- 256: (A2845, A2848) HMAC-SHA2- 256: (A2849) SHA2-256: (for all SoCs but S3 that doesn't implement vng_neon) HMAC-SHA2- 384: (A2845, A2848) HMAC-SHA2- 512: (A2845, A2848) HMAC-SHA2- 512/256: (A2848)
Message DigestSHAHash functionSHS [FIPS 180- 4]:SHA-1, SHA- 224, SHA-256, SHA-384, SHA- 512, SHA- 512/256SHA-1: (A2845, A2848) SHA2-224: (A2845, A2848) SHA2-256: (A2845, A2848) SHA2-256: (A2849) SHA2-256: (for all SoCs but S3 that doesn't implement vng_neon) SHA2-384: (A2845, A2848) SHA2-512: (A2845, A2848) SHA2-512/256: (A2848)

This document may be reproduced and distributed only in its original entirely without revision.

Page 22
NameTypeDescriptionPropertiesAlgorithms
Symmetric Key GenerationCKGAES Key GenerationKey Length / Key Strength:256- bitsCKG: () AES key: Key Length/ Key Strength: 256
CertVendor
NumberName
E113Apple
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Apple corecrypto physical entropy sourcePhysicalSee Tested Operational Environment Table256 bitSHA-256 [ACVP cert. # C1223]

Table 12: Security Function Implementations

2.7 Algorithm Specific Information

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes except signature verification, starting January 1, 2030.

2.8 RBG and Entropy

Table 13: Entropy Certificates Table 14: Entropy Sources Entropy sources : The internal physical noise source consisting of ring oscillators. RBGs: The NIST [SP 800-90ARev1] approved deterministic random bit generators (DRBG) used for random number generation is a CTR_DRBG using AES-256 without derivation function and with prediction resistance. The module performs DRBG health tests according to [SP800-90ARev1 section 11.3]. The deterministic random bit generators are seeded by the physical noise source. RBG Output: The output of hardware entropy source provides 256-bits of security strength in instantiating and reseeding the module approved DRBGs. This document may be reproduced and distributed only in its original entirely without revision.

Page 23
2.9 Key Generation

See vendor affirmed algorithms (CKG) in section 2.5.

2.10 Key Establishment

The Module implements AES key wrapping and unwrapping as part of KTS in accordance with IG D.G method 2 and SP800-38F.

2.11 Industry Protocols

None for this module This document may be reproduced and distributed only in its original entirely without revision.

Page 24
Physical PortLogical Interface(s)Data That Passes
Mailbox Memory, IPC channelData Input Data OutputData inputs/outputs are provided through the memory used for mailbox and IPC
Mailbox Memory, IPC channelControl InputControl input which controls the module's operation is provided through the mailbox by the Device OS' kernel and to applications located within the sepOS execution environment through IPC.
Mailbox Memory, IPC channelStatus OutputStatus output is provided in return codes and through messages returned via the mailbox or the IPC. Documentation for each service invocation lists possible return codes. A complete list of all return codes returned by the C language APIs within the module is provided in the header files and the API documentation. Messages are also documented in the API documentation.
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 15: Ports and Interfaces This document may be reproduced and distributed only in its original entirely without revision.

Page 25
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
AES- KWUnwrapping functionkey wrapping / key unwrapping256-bits60,000,000 * 1 / 2^256
ImplicitImplicit role assumption for non-crypto servicesNoneN/AN/A
4 Roles, Services, and Authentication
4.1 Authentication Methods

Table 16: Authentication Methods Within the constraints of FIPS 140-3 overall security level 2 (with physical security at security level 3), the module implements a role-based authentication mechanism for authentication of the user role. The module implements authenticated encryption-based mechanism in the following way: to request an authenticated service from the module the user must provide the credential and a reference to the class C or A keys of the user keybag that is stored encrypted under SP800-38F AES Key Wrapping (AES-KW) within the module. The module performs obfuscation on the Operator provided credential. The resulting value -called REK (Root Encryption Key)- is used as the 256-bit AES key. Using this key, the module decrypts all the class C or A keys in the referenced user keybag with SP800-38F AES Key Unwrapping function (i.e., AES-KW-AD). As AES-KW is an authentication cipher, the decryption operation will only succeed if there is no authentication error. If the user keybag can be successfully decrypted, the user is authenticated to the module and the requested crypto service will then be proceeded with the decrypted user key. The failure of decrypting the user keybag is also a user authentication failure and the Operator will be denied access to the module. The User keybags are configured in the module during factory install. Each User keybag consists of set of class C, A and D keys. Specifically, class C keys include C key, CK key, CKU keys and the class A keys include A key, AK key, AKU key and APKU key. Only the class A or C keys are considered as approved. Any use of class D keys is considered as non-approved. The module maintains authenticated session from the time the User keybags are unwrapped until the power off. Upon power off, the unwrapped User keybags are zeroized and at the next power on the User credential needs to be provided again in order to unwrap the User keybag. All authentication data is provided electronically from the calling application/service and hence is not in visible form. The module does not support concurrent operators. This document may be reproduced and distributed only in its original entirely without revision.

Page 26
NameTypeOperator TypeAuthentication Methods
UserRoleAuthenticatedAES-KW
Crypto OfficerRoleNon- authenticatedImplicit
NameDescriptionIndicat orInputsOutputsSecurity FunctionsSSP Access
User Keybag Services via MailboxStep 1: The module receives User credential and the reference to the class C or A key from the User keybag; Step 2. Obfuscation is performed on the User provided credential resulting into a value called REK.; Step 3. REK is used as a key for the AES KW operation to unwrap the referenced class A or C keys in the user keybag stored in the module; Step 4. Status of unwrapping operation of class keys is returned viaSuccess returne d from API listed in the custom er proprie tary guidan ce docum entUser creden tial, referen ce to class C/A key from the user keybagstatus (success/e rror)Unauthenti cated Symmetric Encryption and Decryption key wrapping / key unwrappin gUser - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in User Keybag (AES keys): W,E - REK: W,E - Authentic ation Credential : W,E
4.2 Roles
4.3 Approved Services

This document may be reproduced and distributed only in its original entirely without revision.

Page 27
NameDescription mailbox interface and the REK is zeroized.Indicat orInputsOutputsSecurity FunctionsSSP Access
General Authentication serviceThe module invokes the User Keybag Services via Mailbox (i.e. #1 above)Success returne d from API listed in the custom er proprie tary guidan ce docum entUser creden tial, referen ce to class C/A key from the user keybagstatus (success/e rror)key wrapping / key unwrappin gUser - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in User Keybag (AES keys): W,E - REK: W,E - Authentic ation Credential : W,E
Generation of Data Encryption Key (DEK)Step 1: The module receives the reference to the class C or A key from the user keybag; Step 2: The module generates a new DEK using the DRBG; Step 3: Referenced class C or A key is used to wrap the DEK using AES-KW; Step 4: Wrapped DEK isSuccess returne d from API listed in the custom er proprie tary guidan ce docum entreferen ce to class C/A key from the User keybagwrapped DEKSymmetric Key GenerationUser - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in User Keybag (AES keys): W,E - Entropy input string: W,E - Data

: W,E This document may be reproduced and distributed only in its original entirely without revision.

Page 28
NameDescriptionIndicat orInputsOutputsSecurity FunctionsSSP Access
sent out of the moduleEncryptio n Key (DEK) (AES key): G,W,E
Keychain DEK service using AK/AKU/AKPU/ CK/CKU class keyStep 1. The module receives wrapped DEK (that was sent as part of service 3 above) and the pointer to class key AK/AKU/AKPU/ CK/CKU from the user keybag; Step 2. Using the referenced class key, the module unwraps the DEK using AES- KW. If the class key is not available, an error is returned; Step 3. plaintext DEK is sent out to the User. (AS09.16)Success returne d from API listed in the custom er proprie tary guidan ce docum entpointer to AK/AK U/ AKPU/ CK/ CKU class key, wrapp ed DEKunwrappe d DEKkey wrapping / key unwrappin gUser - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in User Keybag (AES keys): W,E - Data Encryptio n Key (DEK) (AES key): W,E
Backup keybag generationThe module generates new set of back up keybags using the DRBGSuccess returne d from API listed in the custom erN/Astatus (success/e rror)Random Number GenerationUser - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU

G,W,E This document may be reproduced and distributed only in its original entirely without revision.

Page 29
NameDescriptionIndicat orInputsOutputsSecurity FunctionsSSP Access
proprie tary guidan ce docum entin Backup Keybag (AES keys): G,E - Entropy input string: W,E - DRBG internal state: V vlaue, key, and seed material: W,E
Backup keybag serviceStep 1. The module receives wrapped DEK and the class key reference for C and A from the user keybag; 2. Using the referenced class key, the module unwraps the DEK using AES- KW. If the class key is not available, an error is returned; 3. The module generates a set of back up keybag using DRBG; 4. Unwrapped DEK is re-wrappedSuccess returne d from API listed in the custom er proprie tary guidan ce docum entwrapp ed DEK, referen ce to class C or A key from the user keybagwrapped DEKkey wrapping / key unwrappin gUser - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in User Keybag (AES keys): W,E - Data Encryptio n Key (DEK) (AES key): W,E - Entropy input string: W,E - DRBG internal state: V

W,E W,E This document may be reproduced and distributed only in its original entirely without revision.

Page 30
NameDescriptionIndicat orInputsOutputsSecurity FunctionsSSP Access
with back up keybag using AES-KW; 5. Wrapped DEK is sent out.vlaue, key, and seed material: W,E - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in Backup Keybag (AES keys): R,W,E
Escrow keybag creationThe module generates new set of escrow keybag using the DRBGSuccess returne d from API listed in the custom er proprie tary guidan ce docum entN/Astatus (success/e rror)Random Number GenerationUser - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in Escrow Keybag (AES keys): G,E - Entropy input string: W,E - DRBG internal state: V vlaue, key, and seed material: W,E

R,W,E W,E W,E This document may be reproduced and distributed only in its original entirely without revision.

Page 31
NameDescriptionIndicat orInputsOutputsSecurity FunctionsSSP Access
Export KeybagStep 1. The module receives reference to a keybag; Step 2: A HMAC key is taken as input based on the hardware specific data for the SKS; Step 3: HMAC value is calculated on the entire referenced keybag that includes encrypted keys; Step 4: HMAC is appended at the end of the keybag; Step 5: keybag with the appended HMAC is output to the UserSuccess returne d from API listed in the custom er proprie tary guidan ce docum entreferen ce to a keybag to be export edkeybag with HMAC tagHMAC Message Authenticat ion Message DigestUser - HMAC key: W,E - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in User Keybag (AES keys): R,E - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in Backup Keybag (AES keys): R,E - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in Escrow Keybag (AES keys): R,E
Device WipeErase all content (Factory Reset)Success returne d fromN/AN/ANoneCrypto Officer - Class A,

This document may be reproduced and distributed only in its original entirely without revision.

Page 32
NameDescriptionIndicat orInputsOutputsSecurity FunctionsSSP Access
API listed in the custom er proprie tary guidan ce docum entClass C, Class AK, Class AKU, Class CK, Class CKU in User Keybag (AES keys): Z - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in Backup Keybag (AES keys): Z - Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in Escrow Keybag (AES keys): Z - Data Encryptio n Key (DEK) (AES key): Z - Entropy input

Z This document may be reproduced and distributed only in its original entirely without revision.

Page 33
NameDescriptionIndicat orInputsOutputsSecurity FunctionsSSP Access
string: Z - DRBG internal state: V vlaue, key, and seed material: Z - HMAC key: Z - Authentic ation Credential : Z - REK: Z
Perform self testInitiate pre- operational self- test and CASTs by powering off/onN/Amodul e power- off/onresults of self-testUnauthenti cated Symmetric Encryption and Decryption key wrapping / key unwrappin g Random Number Generation HMAC Message Authenticat ion Message DigestCrypto Officer
Show StatusN/AN/AN/AstatusNoneCrypto Officer

Z :Z g This document may be reproduced and distributed only in its original entirely without revision.

Page 34
NameDescriptionIndicat orInputsOutputsSecurity FunctionsSSP Access
Show Module Version InformationN/AN/AModule name and versionNoneCrypto Officer
NameDescriptionAlgorithmsRole
Class D key File System Services to wrap or unwrap DEKWrapping of provided plaintext DEK or unwrapping of provided wrapped DEK using class D key from Backup keybag or Flash in SEPAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
Class D key service to encrypt or decrypt dataEncryption of provided plaintext or decryption of provided ciphertext using class D key from Device or iCloud KeybagAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
Class DK/DKU File System Services to wrap or unwrap keychainWrapping of provided plaintext keychain or unwrapping of provided wrapped keychain using class DK/DKU key from Backup keybag or User keybagAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVMCrypto Officer

Table 18: Approved Services The abbreviations of the access rights to SSPs have the following interpretation: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. N/A = The service does not access any SSP during its operation

4.4 Non-Approved Services

This document may be reproduced and distributed only in its original entirely without revision.

Page 35
NameDescriptionAlgorithmsRole
storage controller key
Class DK/DKU key service for data encrypt or decryptEncryption of provided plaintext or decryption of provided ciphertext using DK/DKU key from Device or iCloud keybagAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
Generate Ref-KeyKey GenerationEd25519 Key generation Curve 25519 key generation ECDH Key Pair GenerationCrypto Officer
Sign and verify using Ref-keySignature Generation and VerificationECDSA implemented in FW ECDSA implemented in HW PKACrypto Officer
Encryption and decryption using Ref- keyshared secret is generated using user provided key and existing ref key followed by HKDF is applied to derived a key which is used to encrypt the provided plaintext or decrypt the provided ciphertextAES-GCM HKDF RFC5869 ECDSA implemented in FW ECDSA implemented in HW PKA AES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
Generate Shared Secret using Ref-keyShared secret generationEd25519 shared secretCrypto Officer

This document may be reproduced and distributed only in its original entirely without revision.

Page 36
NameDescriptionAlgorithmsRole
generation Curve 25519 shared secret generation ECDH Shared Secret Computation ECDH implemented in FW ECDH implemented in HW PKA
Device Keybag service for data encrypt or decryptEncryption of provided plaintext or decryption of provided ciphertext using any key from Device KeybagAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
iCloud Keybag service for data encrypt or decryptEncryption of provided plaintext or decryption of provided ciphertext using any key from iCloud KeybagAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
Escrow keybag service for key wrapping and unwrappingWrapping of provided plaintext key or unwrapping of provided wrapped key using any key from Escrow KeybagAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
Encrypt or Decrypt service using Class Bshared secret is computed by generating new ephemeral keypair and existing Curve25519 key followed by HKDF isCurve 25519 key generation Curve 25519Crypto Officer

This document may be reproduced and distributed only in its original entirely without revision.

Page 37
NameDescriptionAlgorithmsRole
Curve 22519 key from any keybagapplied to derived a key which is used doe data encryption or decryption. During encryption operations, the wrapped key and the ephemeral public key is sent to the usershared secret generation HKDF RFC5869 AES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller key
Wrap or unwrap service for DEK or keychain using any Curve 22519 key from asymmetric keybagshared secret is computed by generating new ephemeral keypair and existing Curve25519 key followed by HKDF is applied to derived a key which is used to wrap and unwrap DEK or keychain. During wrapping operation, the wrapped key and the ephemeral public key is sent to the userCurve 25519 key generation Curve 25519 shared secret generation HKDF RFC5869 AES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
Asymmetric (Ed25519) backup keybag wrap and unwrapPointer to DK/DKU/CK/CKU/AK/AKU/AKPU key from asymmetric keybag, plaintext keychain during wrapping operation or wrapped keychain during unwrapping operationEd25519 Key generation Ed25519 shared secret generation HKDF RFC5869 AES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer

This document may be reproduced and distributed only in its original entirely without revision.

Page 38
NameDescriptionAlgorithmsRole
Wrap or unwrap service for keychain using DK/DKU/CK/ CKU/AK/AKU/AKPU Ed25519 key from asymmetric keybagshared secret is computed by generating new ephemeral keypair and existing Curve25519 key followed by HKDF is applied to derived a key which is used to wrap and unwrap. The wrapped key and the ephemeral public key is sent to the userEd25519 Key generation Ed25519 shared secret generation HKDF RFC5869 AES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
NVM Storage Controller Key Servicewrapping DEK using NVM storage controller keyAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
Elliptic Curve Integrated Encryption Scheme (ECIES) EncryptionEncryptionECDH Shared Secret Computation ANSI X9.63 KDF AES-GCMCrypto Officer
Elliptic Curve Integrated Encryption Scheme (ECIES) DecryptionDecryptionECDH Shared Secret Computation ANSI X9.63 KDF AES-GCMCrypto Officer
PBKDF Key DerivationHash-based Key DerivationPBKDFCrypto Officer
File system DEK serviceUnwrap the DEK using referenced class key and re-wrap using NVM storage controller keyAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVMCrypto Officer

This document may be reproduced and distributed only in its original entirely without revision.

Page 39
NameDescriptionAlgorithmsRole
storage controller key
Generation of DEK via IPC using class D keyRequesting generate DEK service via IPC Channel using class D keysAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer
Requesting backup keybag service via IPC using class D keyRequesting backup keybag service via IPC Channel using class D keysAES KW using class D key, keys from Device keybag, keys from iCloud keybag or NVM storage controller keyCrypto Officer

Table 19: Non-Approved Services

4.5 External Software/Firmware Loaded

N/A This document may be reproduced and distributed only in its original entirely without revision.

Page 40
5 Software/Firmware Security
5.1 Integrity Techniques

The Apple corecrypto Module v12.0 [Apple silicon, Secure Key Store, Hardware SL2] is in the form of binary executable code. A firmware integrity test is performed on the runtime image of the module. The HMAC-SHA256 implemented in the module is used as the approved algorithm for the integrity test. If the test fails, the module enters an error state where no cryptographic services are provided, and data output is prohibited i.e. the module is not operational. As the module is delivered built with the Device OS, there is no standalone delivery of the module. The vendor’s internal development process guarantees that the correct version of module goes with its intended Device OS version

5.2 Initiate on Demand

The module’s integrity test can be performed on demand by powering-off and reloading the module. The integrity test on demand is performed as part of the Pre-Operational Self-Tests, automatically executed at power-on. This document may be reproduced and distributed only in its original entirely without revision.

Page 41
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Non-Modifiable

6.2 Configuration Settings and Restrictions

The module operates within the sepOS execution environment which is separate from the Device OS execution environment. The SEP operating system provides memory isolation between all applications executing on it. The Device OS is unable to access the module's memory or observe the module's operation. This document may be reproduced and distributed only in its original entirely without revision.

Page 42
MechanismInspection FrequencyInspection Guidance
Production Grade Components that include standard passivationNo operator- performed testing is recommendedN/A
Tamper-Evident Coating or black hard coated material or metal coating, SoC is soldered in logic board from the Ball Grid Array (BGA) or SIP is embedded in hardened resin. The components listed above are opaque within the visible spectrum.No operator- performed testing is recommendedN/A
7 Physical Security

The defined physical boundary of the Apple corecrypto Module v12 [Apple silicon, Secure Key Store, Hardware, SL2] is the entire System-on-Chip (SoC) listed in the Tested Module Identification table. Consequently, the physical embodiment of each SoC is considered to be that of a single-chip cryptographic module. The hardware module conforms to the Level 2 requirements for physical security. The physical components that comprise the module are of production grade components with industry direct observation, probing, or manipulation of the single-chip as detailed in the Physical Security Mechanisms and Actions Required table.

7.1 Mechanisms and Actions Required

Table 20: Mechanisms and Actions Required This document may be reproduced and distributed only in its original entirely without revision.

Page 43
8 Non-Invasive Security
8.1 Mitigation Techniques

Per IG 12.A, until the requirements of NIST SP 800-140F are defined, non-invasive mechanisms fall under ISO/IEC 19790:2012 Section 7.12 Mitigation of other attacks. The requirements of this area are not applicable to the module. This document may be reproduced and distributed only in its original entirely without revision.

Page 44
Storage Area NameDescriptionPersistence Type
FlashPreloaded at factoryStatic
RAMVolatile memoryDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
User InputUserRAMPlaintextManualDirect
Export Keybag from FlashFlashOperating calling application (TOEPP)EncryptedAutomatedElectronickey wrapping / key unwrapping
Export Keybag from RAMRAMOperating calling application (TOEPP)EncryptedAutomatedElectronickey wrapping / key unwrapping
Obfuscation of User Input Authentication CredentialUserRAMPlaintextManualDirect
Obtained from ENT (P)ENT (P)RAMPlaintextAutomatedElectronicRandom Number Generation
Pre-loaded from FactoryFactory installFlashPlaintextAutomatedElectronic
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 22: SSP Input-Output Methods This document may be reproduced and distributed only in its original entirely without revision.

Page 45
Zeroization MethodDescriptionRationaleOperator Initiation
Context object destructionSSPs are zeroised when the appropriate context object is destroyedZeroization when structure is deallocatedN/A
Power DownSSPs are zeroised when the system is powered downPowering down forces context object destructionOperator can initiate a power down
Device WipeErase all content (factory reset)Factory reset zeroizes all SSPs, including those stored in FlashOperator can initiate a device wipe
NameDescriptio nSize - Strengt hType - CategoryGenerate d ByEstablishe d ByUsed By
Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in User Keybag (AES keys)AES keys in user keybag256- bits - 256- bitsSymmetric - CSPUnauthenticat ed Symmetric Encryption and Decryption key wrapping / key unwrapping
Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in Backup Keybag (AES keys)AES keys in backup keybag256- bits - 256- bitsSymmetric - CSPSymmetri c Key Generatio nkey wrapping / key unwrapping
Class A, Class C, Class AK, Class AKU, Class CK, Class CKU inAES keys in escrow keybag256- bits - 256- bitsSymmetric - CSPSymmetri c Key Generatio nkey wrapping / key unwrapping
9.3 SSP Zeroization Methods

Table 23: SSP Zeroization Methods Data output interfaces are inhibited while zeroisation is performed. h This document may be reproduced and distributed only in its original entirely without revision.

Page 46
Name Escrow Keybag (AES keys)Descriptio nSize - Strengt hType - CategoryGenerate d ByEstablishe d ByUsed By
Data Encryption Key (DEK) (AES key)AES keys in user keybag256- bits - 256- bitsSymmetric - CSPSymmetri c Key Generatio nkey wrapping / key unwrapping Random Number Generation
Entropy input stringEntropy input string256- bits - 256- bitsEntropy - CSPRandom Number Generatio nRandom Number Generation
DRBG internal state: V vlaue, key, and seed materialInternal state values associate d with CTR_DRB G256- bits - 256- bitsDRBG - CSPRandom Number Generatio nRandom Number Generation
HMAC keyHMAC key112- bits - 112- bitsMessage Authenticatio n Key - CSPSymmetri c Key Generatio nRandom Number Generation
Authenticatio n CredentialUser- provided credential sN/A - N/AUser- generated - CSPkey wrapping / key unwrapping
REKRoot Encryptio n Key256- bits - 256- bitsSymmetric - CSPkey wrapping / key unwrapping

h G s Table 24: SSP Table 1 This document may be reproduced and distributed only in its original entirely without revision.

Page 47
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in User Keybag (AES keys)Export Keybag from Flash Pre-loaded from FactoryFlash:Encrypte dFrom factory install to device- wipeDevice Wipe
Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in Backup Keybag (AES keys)Export Keybag from RAMRAM:Encrypte dFrom service invocatio n to service completio nContext object destructio n Power Down
Class A, Class C, Class AK, Class AKU, Class CK, Class CKU in Escrow Keybag (AES keys)Export Keybag from RAMRAM:Encrypte dFrom service invocatio n to service completio nContext object destructio n Power Down
Data Encryption Key (DEK) (AES key)Export Keybag from RAMRAM:Encrypte dFrom service invocatio n to service completio nContext object destructio n Power Down
Entropy input stringObtained from ENT (P)RAM:Encrypte dFrom service invocatio n to service completio nContext object destructio n Power DownDRBG internal state: V vlaue, key, and seed material:Used With

n n This document may be reproduced and distributed only in its original entirely without revision.

Page 48
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
DRBG internal state: V vlaue, key, and seed materialRAM:Encrypte dFrom service invocatio n to service completio nContext object destructio n Power DownEntropy input string:Derived From
HMAC keyRAM:Encrypte dFrom service invocatio n to service completio nContext object destructio n Power Down
Authenticati on CredentialUser InputRAM:Obfuscat edFrom service invocatio n to service completio nContext object destructio n Power DownREK:Derives
REKObfuscation of User Input Authenticati on CredentialRAM:PlaintextFrom service invocatio n to service completio nContext object destructio n Power DownAuthentication Credential:Obfuscati on from

n n n n Table 25: SSP Table 2 This document may be reproduced and distributed only in its original entirely without revision.

Page 49
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-256 (A2845)112-bit keyMessage AuthenticationSW/FW IntegrityIf the test fails, then the module enters an Error State.The HMAC value is pre- computed at build time and stored in the module. The HMAC value is recalculated during runtime and compared with the stored value.
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsCondition s
HMAC- SHA2-512 (A2845)SHA2-256KATCAS TModule becomes operationa lMessage authenticationTest runs at Power- on before the integrity test
AES-CBC (A2842)128-bit keyKATCAS TModule becomes operationa lEncryptionTest runs at Power- on before the integrity test
10 Self-Tests

While the module is executing the self-tests, services are not available, and input and output are inhibited.

10.1 Pre-Operational Self-Tests

The module performs a pre-operational firmware integrity automatically when the module is loaded into memory (i.e., at power on) before the module transitions to the operational state. A HMAC-SHA256 is used as an approved integrity technique. Prior to using HMAC-SHA-256, a Conditional Cryptographic Algorithm Self-Tests (CAST) KAT is performed on the HMAC Table 26: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

This document may be reproduced and distributed only in its original entirely without revision.

Page 50
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsCondition s
AES-ECB (A2842)128-bit keyKATCAS TModule becomes operationa lDecryptionTest runs at Power- on before the integrity test
AES-KW (A2843)128-bit keyKATCAS TModule becomes operationa lWrapping/Unwrappin gTest runs at Power- on before the integrity test
Counter DRBG (DRBG 2014)AES 128- bit keyKATCAS TModule becomes operationa lHealth test per SP800- 90ARev1 section 11.3Test runs at Power- on before the integrity test
ESV-RCT (Startup)Repetition Count Test performe d at entropy source startupfault- detectio n testCAS Tsuccessful seeding of SP 800- 90A DRBGSP 800-90B 4.4.1 Repetition Count Testupon startup of entropy source
ESV-RCT (Continuous )Repetition Count Test performe d every invocation of entropy source after startupfault- detectio n testCAS Tsuccessful seeding of SP 800- 90A DRBGSP 800-90B 4.4.1 Repetition Count Testupon seeding or reseeding SP 800- 90A DRBG

This document may be reproduced and distributed only in its original entirely without revision.

Page 51
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsCondition s
ESV-APT (Startup)Adaptive Proportio n Test performe d at etnropy source startupfault- detectio n testCAS Tsuccessful seeding of SP 800- 90A DRBGSP 800-90B 4.4.2 Adaptive Proportion Testupon startup of entropy source
ESV-APT (Continuous )Adaptive Proportio n Test performe d at every invocation of entropy source every invocation after startupfault- detectio n testCAS Tsuccessful seeding of SP 800- 90A DRBGSP 800-90B 4.4.2 Adaptive Proportion Testupon seeding or reseeding SP 800- 90A DRBG
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 256 (A2845)Message AuthenticationSW/FW IntegrityWhenever module is powered onUpon every power-on
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 512 (A2845)KATCASTOn DemandManually

Table 27: Conditional Self-Tests

10.3 Periodic Self-Test Information

Table 28: Pre-Operational Periodic Information This document may be reproduced and distributed only in its original entirely without revision.

Page 52
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A2842)KATCASTOn DemandManually
AES-ECB (A2842)KATCASTOn DemandManually
AES-KW (A2843)KATCASTOn DemandManually
Counter DRBG (DRBG 2014)KATCASTOn DemandManually
ESV-RCT (Startup)fault-detection testCASTOn demandManually
ESV-RCT (Continuous)fault-detection testCASTOn demandManually
ESV-APT (Startup)fault-detection testCASTOn demandManually
ESV-APT (Continuous)fault-detection testCASTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
Error stateThe HMAC-SHA-256 value computed over the module did not match the pre- computed value, OR the computed value in the invoked Conditional CAST did not match the known value. No cryptographic services are provided, and data output is prohibitedPre- operational Firmware Integrity Test failure OR Conditional CAST failurePower off/onfor Integrity: print statement "FAILED: fipspost_post_integrity" to stdout; for CAST: sprint statement "FAILED:<event>" to stdout (<event> refers to any of the cryptographic functions listed in the Conditional Self- test Table)
10.4 Error States

Table 30: Error States This document may be reproduced and distributed only in its original entirely without revision.

Page 53
10.5 Operator Initiation of Self-Tests

The module permits operators to initiate the pre-operational or conditional self-tests on demand for periodic testing of the module by reloading the module. This document may be reproduced and distributed only in its original entirely without revision.

Page 54
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Startup Procedures: As the module is delivered built with the Device OS, there is no standalone delivery of the module. Installation Process and Authentication Mechanisms: The vendor’s internal development process guarantees that the correct version of module goes with its intended Device OS version. For additional assurance, the module is digitally signed by vendor, and it is verified during the integration into Host Device OS. This digital signature-based integrity protection used during the delivery/integration process is not to be confused with the HMAC-256 based integrity check performed by the module itself as part of its pre-operational self- tests.

11.2 Administrator Guidance

The biometric authentication option provided by the underlying test platform shall be disabled in order to run the module in the FIPS validated manner. The Approved mode of operation is configured in the system by default and can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table - Non-Approved Services. If the device starts up successfully, then the module has passed all self-tests and is operating in the Approved mode. The ESV Public Use Document (PUD) reference for physical entropy source is: https://csrc.nist.gov/projects/cryptographic-module-validation-program/entropyvalidations/certificate/113 Apple Platform Certifications guide [platform certifications] and Apple Platform Security guide [SEC] are provided by Apple which offers IT System Administrators with the necessary technical information to ensure FIPS 140-3 Compliance of the deployed systems. This guide walks the reader through the system’s assertion of cryptographic module integrity and the steps necessary if module integrity requires remediation.

11.3 Non-Administrator Guidance

The User role is authenticated with the mechanism described in section 4. The User role can access the module via mailbox interface using the Device OS’s XNU kernel. The User role can perform subset of services from Table - Approved Algorithms. As stated in the Administrator Guidance section above, the Approved mode of operation is configured in the system by default and can only be transitioned into the non-Approved mode by calling one of the non-Approved services. This transition cannot be made by the User directly, as all non-approved services require an implicit transition into the Crypto-Officer role. Any calling of such services is therefore implicitly performed by the Crypto Officer. This document may be reproduced and distributed only in its original entirely without revision.

Page 55
11.4 End of Life

The Device Wipe service erases the module content. When performing a Device Wipe service to erase all content of the module, the procedure must be performed under the control of the Operator. This document may be reproduced and distributed only in its original entirely without revision.

Page 56
12 Mitigation of Other Attacks

The module does not claim mitigation of other attacks. This document may be reproduced and distributed only in its original entirely without revision.

Page 57
Table, extracted as text (did not parse into structured rows)
Appendix A.                   Glossary and Abbreviations AES                   Advanced Encryption Standard API                   Application Programming Interfaces APT                   Adaptive Proportion Test (SP800-90B health test) BGA                   Ball Grid Array (Physical Security) CAVP                  Cryptographic Algorithm Validation Program CBC                   Cipher Block Chaining CCM                   Counter with Cipher Block Chaining-Message Authentication Code CMVP                  Cryptographic Module Validation Program CST                   Cryptographic and Security Testing CTR                   Counter Mode DEK                   Data Encryption Key DRBG                  Deterministic Random Bit Generator ECB                   Electronic Code Book ECDSA                 DSA (Digital Signature Algorithm) based on Elliptic Curve Cryptography (ECC) EMI                   Electromagnetic Interference (Physical Security) ESV                   NIST entropy source validation program providing SP 800-90B compliant entropy validation certificate FIPS                  Federal Information Processing Standards Publication GCM                   Galois Counter Mode HMAC                  Hash Message Authentication Code IPC                   Inter-Process Communication IHS                   Integrated Heat Spreader (Physical Security) KAT                   Known Answer Test KDF                   Key Derivation Function KEK                   Key Encryption Key KW                    AES Key Wrap MAC                   Message Authentication Code NIST                  National Institute of Science and Technology NVM                   Non-Volatile Memory OFB                   Output Feedback OS                    Operating System PBKDF                 Password Based Key Derivation Function RCT                   Repetition Count Test (SP800-90B health test) SEP                   Secure Enclave Processor SHA                   Secure Hash Algorithm This document may be reproduced and distributed only in its original entirely without revision.
Page 58
Appendix B.References
FIPS140-3FIPS PUB 140-3 - Security Requirements for Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3
SP 800-140xCMVP FIPS 140-3 Related Reference https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-standards
FIPS140-3_IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program January 2024 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation- program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf
FIPS140-3_MMCMVP FIPS 140-3 Management Manual February 2024 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation- program/documents/fips%20140-3/FIPS-140-3-CMVP%20Management%20Manual%20v2.1%5B02-29- 2024%5D.pdf
SP 800-140FIPS 140-3 Derived Test Requirements (DTR) March 2020 https://csrc.nist.gov/publications/detail/sp/800-140/final
SP 800-140ACMVP Documentation Requirements March 2020 https://csrc.nist.gov/publications/detail/sp/800-140a/final
SP 800-140Br1CMVP Security Policy Requirements November 2023 https://doi.org/10.6028/NIST.SP.800-140Br1
SP 800-140CCMVP Approved Security Functions July 2023 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140Cr2.pdf
SP 800-140DCMVP Approved Sensitive Security Parameter Generation and Establishment Methods July 2023 https://doi.org/10.6028/NIST.SP.800-140Dr2
SP 800-140ECMVP Approved Authentication Mechanisms March 2020 https://csrc.nist.gov/publications/detail/sp/800-140e/final
SP 800-140FCMVP Approved Non-Invasive Attack Mitigation Test Metrics March 2020 https://csrc.nist.gov/publications/detail/sp/800-140f/final This document may be reproduced and distributed only in its original entirely without revision.
Page 59
FIPS180-4Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS186-5Digital Signature Standard (DSS) F3b 2023 https://doi.org/10.6028/NIST.FIPS.186-5
FIPS197Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt
RFC3394Advanced Encryption Standard (AES) Key Wrap Algorithm September 2002 http://www.ietf.org/rfc/rfc3394.txt
RFC5649Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm September 2009 http://www.ietf.org/rfc/rfc5649.txt
SP800-38ANIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP800-38CNIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
SP800-38DNIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP800-38ENIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 http://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP800-38FNIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf This document may be reproduced and distributed only in its original entirely without revision.
Page 60
SP800-56Cr2Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://doi.org/10.6028/NIST.SP.800-56Cr2
SP800-57NIST Special Publication 800-57 Part 1 Revision 5 - Recommendation for Key Management Part 1: General May 2020 https://doi.org/10.6028/NIST.SP.800-57pt1r5
SP800-67r2NIST Special Publication 800-67 Revision 1 - Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher January 2012 (withdrawn January 2014) https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-67r2.pdf
SP800-90Ar1NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://dx.doi.org/10.6028/NIST.SP.800-90Ar1
SP800-90BNIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://doi.org/10.6028/NIST.SP.800-90B
SP800-108r1NIST Special Publication 800-108r1 - Recommendation for Key Derivation Using Pseudorandom Functions Aug 2022 https://doi.org/10.6028/NIST.SP.800-108r1
SP800-131Ar2Transitioning the Use of Cryptographic Algorithms and Key Lengths March 2019 https://doi.org/10.6028/NIST.SP.800-131Ar2
SP800-133r2Recommendation for Cryptographic Key Generation June 2020 https://doi.org/10.6028/NIST.SP.800-133r2
SP800-135r1NIST Special Publication 800-135 Revision 1 - Recommendation for Existing Application-Specific Key Derivation Functions December 2011 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf
SECApple Platform Security https://support.apple.com/guide/security/welcome/web https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/apple-platform-security-guide.pdf