All modules
CMVP Validated Module · FIPS 140-3 Security Policy

HID Global ActivID Applet 2.7.7 & 2.7.8 on Thales IDCore 3230 Platform

Certificate#5028StandardFIPS 140-3Level2TypeHardwareEmbodimentSingle ChipStatusActiveVendorHID Global
Medium review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 13 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date6/17/2030
CaveatNone
VendorHID Global

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for HID Global ActivID Applet 2.7.7 & 2.7.8 on Thales IDCore 3230 Platform
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>firmware load<br/>UPDATE</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>unauthenticated</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for HID Global ActivID Applet 2.7.7 & 2.7.8 on Thales IDCore 3230 Platform
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>firmware load<br/>UPDATE</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>unauthenticated</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

HID Global HID Global ActivID Applet 2.7.7 & 2.7.8 on Thales IDCore 3230 Platform HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 2
Table of Contents
#SectionPage
Page 3

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware8
Table 3: Modes List and Description9
Table 4: Approved Algorithms11
Table 5: Vendor-Affirmed Algorithms11
Table 6: Security Function Implementations13
Table 7: Entropy Certificates13
Table 8: Entropy Sources13
Table 9: Ports and Interfaces15
Table 10: Authentication Methods16
Table 11: Roles16
Table 12: Approved Services21
Table 13: Mechanisms and Actions Required22
Table 14: EFP/EFT Information23
Table 15: Hardness Testing Temperatures23
Table 16: Storage Areas24
Table 17: SSP Input-Output Methods24
Table 18: SSP Zeroization Methods24
Table 19: SSP Table 128
Table 20: SSP Table 232
Table 21: Pre-Operational Self-Tests32
Table 22: Conditional Self-Tests33
Table 23: Pre-Operational Periodic Information34
Table 24: Conditional Periodic Information34
Table 25: Error States35
Figure 1: Block Diagram6
Figure 2 : Tags for Tracking Data (Approved Mode)9
Figure 3 : Card Production Life Cycle Data9
Figure 4 : Versions and Operations Indicators10
Page 5
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication3
5Software/Firmware security2
6Operational environmentN/A
7Physical security3
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance3
12Mitigation of other attacksN/A
Overall Level2

WORLD Combi RLT module (SLC37GDA512) for 3230

Oblong punching Top View – Combi Plate

Oblong punching

Bottom View – Black Epoxy with RLT

Top View – Combi Plate

technology

1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for the HID Global ActivID Applet 2.7.7 &

2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module. This document may freely be reproduced

and distributed in its entirety. This Security Policy describes the security services provided by the module and describes how the module meets the requirements of FIPS 140-3 (Federal Information Processing Standards 140-3) for an overall Security Level 2 implementation.

1.2 Security Levels
2.1 Description

Purpose and Use: The Module is designed to be embedded into a plastic card body, USB key, secure element etc., with a contact plate connection and/or RF antenna. The physical form of the Module is depicted in following pictures (to scale). The cryptographic boundary is defined as the surfaces and edges of the packages. The Module relies on [ISO 7816] and/or [ISO 14443] card readers as input/output devices. Purpose and Use: HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 6

This document defines the Security Policy for the HID Global ActivID Applet 2.7.7 & 2.7.8 on the Thales IDCore

3230 Platform cryptographic module, herein denoted the Module. The Module, validated to FIPS 140-3 overall

Level 2, is a single-chip “contact and contactless” module implementing the Global Platform operational environment, with Card Manager and the HID Global ActivID Applet. The term platform herein is used to describe the chip and operational environment, not inclusive of the ActivID Applet. The Module has a limited operational environment. The Module includes a firmware load function to support necessary updates. New firmware versions within the scope of this Security Policy and certificate must be validated through the FIPS 140-3 CMVP. Any other firmware loaded onto this module is out of the scope of this validation and requires a separate FIPS 140-3 validation. The Module is designed to be embedded into a plastic card body, passport, USB key, secure element etc., with a contact plate connection and/or RF antenna. Module Type: Hardware Module Embodiment: SingleChip Module Characteristics: Cryptographic Boundary: Figure 1 below depicts the Module’s block diagram, with a red outline highlighting the cryptographic boundary. The cryptographic boundary encompasses all the components. included on the single chip. Figure 1: Block Diagram The Cryptographic Module (CM) is fully compliant with two major cards industry standards: Oracle Java Card

3.1.0 Classic Edition and GlobalPlatform (GP) Card Specification version 2.2.1.

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 7

The CM supports [ISO7816] T=0, T=1 and T=CL communication protocols. The CM provides an execution sandbox for Applets, performing the requested services as described in this security policy. Applets access module functionality via internal API entry points that are not exposed to external entities. External devices have access to CM services by sending APDU commands. The CM inhibits all data output via the data output interface while the module is in error state and during selftests. The JavaCard API (JCAPI) is an internal interface, available to applets. Only applet services are available at the card edge (the interfaces that cross the cryptographic boundary). The Javacard Runtime Environment (JCRE) implements the dispatcher, registry, loader, and logical channel functionalities. The Virtual Machine (VM) implements the byte code interpreter, firewall, exception management and byte code optimizer functionalities. The Card Manager is the card administration entity, allowing authorized users to manage the card content, keys, and life cycle states. The Card Manager behaves similarly to an applet, but is properly represented as a constituent of the platform. In case of delegated management (DM), the Supplementary Security Domain (SSD) behaves similarly to the Card Manager in term of card content, keys and life cycle states. The Memory Manager implements functions such as memory access, allocation, deletion and garbage collection. The Communication handler implements the ISO 7816 and ISO 14443 communications protocols in contactless mode and dual mode. The Cryptography Libraries implement the Approved services listed in Section 2.5. The HID Global ActivID Applet 2.7.7 & 2.7.8 comprises:

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification – Hardware: The Module is designed to be embedded into a plastic card body, passport, USB key, secure element etc., with a contact plate connection and/or RF antenna. The Module’s single chip is the SLC37GDA512. It is presented on one form factor: WORLD Combi RLT module (contact and contactless) HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 8
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
World Combi RLT module/ PN: A2848344SLC37GDA512 Mask number: G322Firmware: IDCore 3230-BUILD6.9; ActivID Applet 2.7.7 or ActivID Applet 2.7.8Infineon SLC37GDA512Java Card 3.1.0 GlobalPlatform (GP) 2.2.1 Interface: contact with protocol communication; T=0 and T=1; Contactless with protocol communication T=CL

Application Firmware: HID Global ActivID Applet 2.7.7 is comprised of

2.3 Excluded Components
2.4 Modes of Operation

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 9
Mode NameDescriptionTypeStatus Indicator
Approved modeThis is the module's only mode of operationApproved"8900" in byte 11-12 of tag 0103
FieldCLAINSP1-P2 (Tag)Le (Expected response length)Purpose
Value00CA9F-7F2DhGet CPLC data (tag 9F 7F)
01-031DhGet Identification data (tag 01 03)
01-2F10hGet Approved mode parameters (tag 01 2F):
IDCore 3230 – CPLC data (tag 9F7F)
ByteDescriptionValueValue meaning
1-2IC fabricator4090hInfineon
3-4IC type0039hSLC37GDA512
5-6Operating system identifier1291hThales
7-8Operating system release date (YDDD) – Y=Year, DDD=Day in the yearYDDDhOperating System release Date
9-10Operating system release level0100hV1.0
11-12IC fabrication datexxxxhFilled in during IC manufacturing
13-16IC serial numberxxxxxxxxhFilled in during IC manufacturing
17-18IC batch identifierxxxxhFilled in during IC manufacturing
19-20IC module fabricatorxxxxhFilled in during module manufacturing
21-22IC module packaging datexxxxhFilled in during module manufacturing
23-24ICC manufacturerxxxxhFilled in during module embedding
25-26IC embedding datexxxxhFilled in during module embedding
27-28IC pre-personalizerxxxxhFilled in during smartcard preperso
29-30IC pre-personalization datexxxxhFilled in during smartcard preperso
31-34IC pre-personalization equipment identifierxxxxxxxxhFilled in during smartcard preperso
35-36IC personalizerxxxxhFilled in during smartcard personalization
37-38IC personalization datexxxxhFilled in during smartcard personalization
39-42IC personalization equipment identifierxxxxxxxxhFilled in during smartcard personalization

Modes List and Description: Table 3: Modes List and Description The module is acting in an approved mode of operation when the module provides the services described in the Approved Services table. These services use the security functions listed in the Approved Algorithm table in an approved manner. The security service indicator provides confirmation that an approved service has been provided. Once the module has been delivered outside of the factory, the CM is always in Approved mode. The configuration cannot be changed outside the factory. The CM does not support a non-approved mode of To identify the CM, verify that a CM is in the approved mode of operation, select the Card Manager and send the GET DATA commands shown below: Figure 2 : Tags for Tracking Data (Approved Mode) The CM production life cycle data can be checked using GET DATA command with tag ‘9F7F’. The Module responds with 42 bytes composed of: Figure 3 : Card Production Life Cycle Data HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 10
IDCORE 3230 – Identification data (tag 0103)
ByteDescriptionValueValue meaning
1Thales Family NameB0Javacard
2Thales OS Name84IDCore family
3Thales Mask Number66G322
4Thales Product Name69IDCore3230
5Thales Version06Major Version
6Thales Version (Minor)09Minor Version
7-8Chip Manufacturer4090Infineon
9-10Chip Version7305SLC37GDA512
11-12Operational Mode8900Approved mode
13FIPS Level for product0202 = FIPS Level 2
14-15Specific chip ID32 3032 30 = Contact and Contactless
16-17HID Piv applet version02 7702 77 = ActivID Applet 2.7.7 02 78 = ActivID Applet 2.7.8
18-29RFUxx..xxhRFU
AlgorithmCAVP CertPropertiesReference
AES-CBCA2877Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA2877Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-ECBA2877Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
Counter DRBGA2877Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A2877Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - extra bitsFIPS 186-5

The CM identification data can be checked using GET DATA command with tag ‘0103’. The Module responds with 29 bytes composed of: Figure 4 : Versions and Operations Indicators The status of the Approved mode of operation can be checked using GET DATA command with tag ‘012F’. The Module responds with 16 bytes composed of:

2.5 Algorithms

Approved Algorithms: HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 11
AlgorithmCAVP CertPropertiesReference
KAS-ECC Sp800-56Ar3A2877Domain Parameter Generation Methods - P-256 Function - Partial Validation Scheme - onePassDh - KAS Role - Responder KDF Methods - oneStepKdf - Key Length - 512SP 800-56A Rev. 3
KDF SP800-108A2877KDF Mode - Counter Supported Lengths - Supported Lengths: 128-256 Increment 64SP 800-108 Rev. 1
KTS-IFCA2877Modulo - 2048, 3072, 4096 Key Generation Methods - rsakpg1-basic, rsakpg1-crt Scheme - KTS-OAEP-basic - KAS Role - responder Key Transport Method - Key Length - 512SP 800-56B Rev. 2
RSA KeyGen (FIPS186-5)A2877Key Generation Mode - probable Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Primality Tests - 2pow100 Modulo - 2048, 3072 Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186-5)A2877Modulo - 2048, 3072 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-5)A2877Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA2-224A2877Message Length - Message Length: 8-65536 Increment 8FIPS 180-4
SHA2-256A2877Message Length - Message Length: 8-65536 Increment 8FIPS 180-4
SHA2-384A2877Message Length - Message Length: 8-65536 Increment 8FIPS 180-4
SHA2-512A2877Message Length - Message Length: 8-65536 Increment 8FIPS 180-4
NamePropertiesImplementationReference
CKGKey Type:AsymmetricN/ASP800-133r2 Section 4, Example 1

Table 4: Approved Algorithms NOTE: Only the algorithms specified in the table above are supported by the module in approved mode of operation. Vendor-Affirmed Algorithms: Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 12
NameTypeDescriptionPropertiesAlgorithms
Digital Signature Generation RSADigSig-SigGenSignature GenerationRSA SigGen (FIPS186-5): (A2877)
Digital Signature Verification RSADigSig-SigVerSignature VerificationRSA SigVer (FIPS186- 5): (A2877)
Encryption - DecryptionBC-UnAuthBlock cipher unauthenticatedStrength:128, 192, 256 bitsAES-CBC: (A2877) Sizes: 128, 192, 256 bits AES-ECB: (A2877) Sizes: 128, 192, 256 bits
Generate Key Pair EC (CKG)AsymKeyPair-KeyGenDemonstrate ECC key generationECDSA KeyGen (FIPS186-5): (A2877) Counter DRBG: (A2877) CKG: () Key Type: Asymmetric
Generate Key Pair RSA (CKG)AsymKeyPair-KeyGenDemonstrate RSA key generationRSA KeyGen (FIPS186-5): (A2877) Counter DRBG: (A2877) CKG: () Key Type: Asymmetric
KDFKBKDFKey-Based Key DerivationAES-CMAC: (A2877) Sizes: 128,192, 256 KDF SP800-108: (A2877)
KTSKTS-WrapKey Transport using AES ECB or CBC for encryption and AES- CMAC for authenticationStrength:Key transport methodology providing between 128 and 256 bits of security strength Standard:SP 800-38F IG D.G:Approved method #2AES-CBC: (A2877) Sizes: 128,192, 256 AES-CMAC: (A2877) Sizes: 128,192, 256 AES-ECB: (A2877)
KTS-IFCKTS-EncapKey Transport EncapsulationStrength:Key establishment methodology providing between 112 and 128 bits of security strength Standard:SP 800- 56Br2 IG D.G:Approved method #1KTS-IFC: (A2877) Modulus: 2048, 3072
Message AuthenticationMACMessage AuthenticationAES-CMAC: (A2877) Sizes: 128,192, 256
Opacity Secure Channel (KAS)KAS-FullKey Agreement Scheme, SP800- 56Cr2 Key Derivation, Message Authentication for key confirmationIG:IG D.F Scenario 2, path 2 Key Derivation:SP 800-56Cr2 KDA (Tested as part of KASKAS-ECC Sp800- 56Ar3: (A2877) AES-CMAC: (A2877) Sizes: 128 Counter DRBG: (A2877)

Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 13
NameTypeDescriptionPropertiesAlgorithms
certificate) Key Confirmation:Yes
Secure HashSHACompute the hash valueSHA2-224: (A2877) SHA2-256: (A2877) SHA2-384: (A2877) SHA2-512: (A2877)
CertVendor
NumberName
E107Infineon
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
SLC37 32-bit Security ControllerPhysicalN/A32 bitsMin-entropy claimed: 13.376 bits per 32- bit blocks.N/A

Table 6: Security Function Implementations The table lists the security functions provided by the HID Global ActivID Applet 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module.

2.7 Algorithm Specific Information

SP 800-56Ar3 Assurances: The module is systematically checking the key in mode FULL VALIDATION at EC public key generation and key agreement, it implements assurances for SP800-56Ar3 section 5.6.2.3.3 for ECC full public key validation.

2.8 RBG and Entropy

Table 7: Entropy Certificates Table 8: Entropy Sources ESV certificate (#E107) has been procured for this entropy source. The output of the entropy source is used to directly feed the DRBG. The DRBG uses CTR_DRBG from [SP800-90Ar1] with Derivation Function (DF) enabled. 1024-bits of entropy at 13.376 bits per 32-bits minentropy are fed to the DF which accounts for 428.032 -bits of entropy which exceed the 256-bits required by CTR_DRBG to claim full entropy output of the DRBG. A separate nonce is created for the DRBG based on output from entropy source.

2.9 Key Generation

The module uses unmodified output from its Counter DRBG to generate seeds used for asymmetric key generation. The module supports the following CKG methodologies: - FIPS 186-5 RSA Key generation per SP 800-133r2, sections 4 and 5.1 - FIPS 186-5 and SP 800-56Ar3 ECC Key generation per SP 800-133r2, sections 4, 5.1 and 5.2 HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 14
Physical PortLogical Interface(s)Data That Passes
VCCPowerSupply Voltage
RSTControl InputReset Signal
CLKControl InputClock Signal
GNDPowerGround
I/OData Input Data Output Control Input Status OutputCommands and responses, protocol and control data
2.10 Key Establishment
2.10.1 Key Agreement

The module implements the following approved key agreement scheme as specified in FIPS 140-3 IG D.F, Scenario 2, path 2 which has been CAVP tested and validated: - SP 800-56Ar3 KAS-ECC with SP 800-56Cr2 OneStep KDA.

2.10.2 Key Transport

The module implements the following approved key transport methods as specified in FIPS 140-3 IG D.G, the underlying algorithms of which have been CAVP tested and validated: - SP 800-56Br2 KTS-IFC (Approved method #1 from IG D.G) - SP 800-38F Key Transport using AES ECB/CBC for encryption and AES-CMAC for authentication. (Approved method #2 from IG D.G)

2.11 Industry Protocols
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

The WORLD Combi RLT module has access to contact and contactless interfaces. VCC, RST, CLK, GND and IO are for contact interface. as specified into ISO7816 standard. When the contactless smart card is within the reader's electromagnetic field, the antenna receives the RF energy, which powers the IC chip via the LA and LB connections, enabling the chip to communicate with the reader in contactless. As specified into ISO14443 standard. HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 15
Physical PortLogical Interface(s)Data That Passes
LAData Input Data Output Control Input Status Output PowerSupply ,clock signal, commands and responses, protocol and control data
LBData Input Data Output Control Input Status Output PowerSupply ,clock signal, commands and responses, protocol and control data
ConditionsRange
Voltage1.8V, 3 V and 5.5 V DC
Frequency11MHz to 10MHz
ConditionsRange
Supported bit rate106 Kbits/s, 212 Kbits/s, 424 Kbits/s, 848 Kbits/s
Operating fieldBetween 1.5 A/m and 7.5 A/m rms
Frequency13.56 MHz +- 7kHz
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Secure Channel Protocol authentication methodIn accordance to SP 800-63B, this Authenticator type is best described as Single-Factor Cryptographic Software (Section 5.1.6). This authentication method employs AES CMAC used along with AES ECB/CBC as part of a challenge-response mechanism. This method is performed when the EXTERNAL AUTHENTICATEKTSThe strength of Global Platform mutual authentication relies on AES key length, and the probability that a random attempt at authentication will succeed is: (1/2^128) for AES 16-byte-long keys; (1/2^192) for AES 24-byte-long keys;The module enforces a maximum count of 15 consecutive failed authentication attempts. After 15 consecutive unsuccessful attempts, the secure channel authentication is permanently blocked

Table 9: Ports and Interfaces For contact interface operation, the Module conforms to [ISO 7816] part 1 and part

  1. The electrical signals and transmission protocols follow the [ISO 7816] part
  2. For contactless interface operation, the Module conforms to [ISO 14443] part 1 for physical connections, and to [ISO 14443] parts 2, 3 and 4 for radio frequencies and transmission protocols. Both contact and contactless interfaces share the same data storage, processing, SSPs, and services.
4 Roles, Services, and Authentication
4.1 Authentication Methods

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 16
Method NameDescription command is invoked after successful execution of the INITIALIZE UPDATE command.Security MechanismStrength Each Attempt (1/2^256) for AES 32- byte-long keysStrength per Minute
Symmetric Cryptographic Authentication methodIn accordance to SP 800-63B, this Authenticator type is best described as Single-Factor Cryptographic Software (Section 5.1.6). This authentication method decrypts (using ACA-SPAK) an encrypted challenge (128-bits) sent to the module by an external entity and compares the challenge to the expected value. This method is used to authenticate to the AA role.Encryption - DecryptionThe strength of Symmetric Cryptographic Authentication method relies on AES-CBC key length (128 bits), and the probability that a random attempt at authentication will succeed is: 1/(2^128)The execution of this authentication mechanism is rate limited - the module can perform no more than 2^16 attempts per minute. Therefore, the probability that a random attempt will succeed over a one minute period is (2^16)/(2^128) = 1.93E - 34
Secret Value authentication methodIn accordance to SP 800-63B, this Authenticator type is best described as Memorized Secrets (Section 5.1.1). This authentication method compares a value sent to the Module to the stored ACA-PIN value; if the two values are equal, the operator is authenticated.Encryption - DecryptionThe probability of false authentication of this authentication method is as follows: 1/(256^8) = 5.4E20Based on the [SP800-73- 4] defined maximum count of 15 for failed authentication attempts, the probability that a random attempt will succeed over a one minute period is: 15/(256^8) = 8.1E-19
NameTypeOperator TypeAuthentication Methods
COIdentityCrypto Officer.Secure Channel Protocol authentication method
AAIdentityApplication AdministratorSymmetric Cryptographic Authentication method
USRIdentityUserSecret Value authentication method

Table 10: Authentication Methods logical channel usage. Only one operator at a time is permitted on a channel. Applet deselection (including Card Manager), card reset or power down terminates the current authentication; re-authentication is required after any of these events for access to authenticated services. Applet reselection (except Card Manager that close systematically the GlobalPlatform secure channel) is leaving the secure channel unchanged and it is up to the applet policy to close it or not. The module clears previous authentications on each power cycle. It also supports Global Platform SCP logical channels, allowing concurrent operators in a limited fashion.

4.2 Roles

Table 11: Roles The Module does not support a maintenance role.

4.3 Approved Services

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 17
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
LifecycleModify the card or applet life cycle status. Performs zeroization.IND_1Set / Get Status : life cycle state to update/ emptyReturn Status Word / life cycle state and package listNoneCO - OS-DRBG-EI : Z - OS-DRBG-S : Z - OS-DRBG-V : Z - OS-DRBG-KEY : Z - OS-MKDK : Z - SD-KENC: Z - SD-KMAC: Z - SD-KDEK: Z - SD-SENC: Z - SD-SMAC: Z - DAP-SYM: Z - OPACITY-SENC : Z - OPACITY-SMAC: Z - OPACITY- SRMAC : Z - OPACITY- SCONFIRMATION: Z - ACA-PIN: Z - ACA-PUK: Z - ACA-PC: Z - SMA-OPRI: Z - PIV-RPAK: Z - PIV-RDSK: Z - PIV-RCAK: Z - PIV-RKDK: Z - PIV-RPAK-PUB: Z - PIV-RKDK-PUB: Z - SMA-OPRI-PUB: Z - ACA-SPAK: Z
Manage ContentLoad, install, and delete application packages and associated keys and dataIND_1Applications and associated dataReturn Status WordMessage AuthenticationCO - SD-SMAC: E - DAP-SYM: E - ACA-PIN: Z - ACA-PUK: Z - ACA-PC: Z - ACA-SPAK: Z - PIV-RPAK: Z - PIV-RDSK: Z - PIV-RCAK: Z - PIV-RKDK: Z - SMA-OPRI: Z - PIV-RPAK-PUB: Z - PIV-RDSK-PUB: Z - PIV-RCAK-PUB: Z - SMA-OPRI-PUB: Z

Z Z Z Z Z Z Z Z Z Z Z HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 18
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Module Info (Auth)Read module configuration or status information (privileged data objects). Shows module versioning and status information.IND_1Tags and module informationModule configuration status information return Status WordMessage AuthenticationCO - SD-SMAC: E
Secure ChannelEstablish and use a secure communications channelIND_1Random, diversification dataAuthentication data, return Status WordEncryption - Decryption KDF KTS Message AuthenticationCO - OS-DRBG-EI : G,E - OS-DRBG-S : G,E - OS-DRBG-V : G,E - OS-DRBG-KEY : G,E - SD-KENC: E - SD-KMAC: E - SD-KDEK: E - SD-SMAC: G,E - SD-SENC: G,E - SD-MDAP-KDEK: E - SD- MDAP - KENC: E - SD- MDAP - KMAC: E
Request for autotestPerforms self-tests. Sets a flag to see that a specific cryptographic KAT has been performed on demand via Module Reset.IND_1CAST bit fieldreturn Status WordNoneUnauthenticated
Generate HID Applet RSA 2048/3072 Key pair using the secure channel.Generate HID Applet RSA 2048/3072 Key pair using the secure channel. PIV Authentication RSA Key Pair Generation PIV Signature RSA Key Pair Generation PIV Card Authentication RSA Key Pair Generation HID Applet 2.7.7 supports 2048 RSA keypair generation. HID Applet 2.7.8 supports both 2048 and 3072 RSA Keypair generation.IND_1HID applet application parameters for generating RSA key pairThe response message contains the modulus corresponding to the private key generated in the card, and return Status WordGenerate Key Pair RSA (CKG) Message AuthenticationCO - PIV-RPAK: G,Z - PIV-RDSK: G,Z - PIV-RCAK: G,Z - PIV-RPAK-PUB: G - PIV-RDSK-PUB: G - PIV-RCAK-PUB: G - SD-SMAC: E
PUT Key (RSA)Put HID Applet RSA 2048/3072 Encryption Private Key using the secure channel Inject PIV Encryption RSA Private Key (put key)IND_1HID applet application parameters for injecting RSA PrivateReturn Status WordKTSCO - PIV-RKDK: W,Z - SD-KDEK: E - SD-SENC: E - SD-SMAC: E

G,E G,E E HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 19
NameDescription Inject Retired Encryption Private Key 1-5 (Put key) Private Key components wrapped with SD-KDEK HID Applet 2.7.7 supports 2048 RSA Private Key Put Key. HID Applet 2.7.8 support both 2048 and 3072 RSA Private Key Put KeyIndicatorInputs Key componentOutputsSecurity FunctionsSSP Access
PUT CertificatePut HID Applet RSA 2048/3072 Certificate using the secure channel Put PIV Authentication Certificate Put PIV Signature Certificate Put PIV Card Authentication Certificate Put PIV Encryption Certificate Put PIV Retired 1-5 Key Certificate HID Applet 2.7.7 supports Put RSA 2048 certificate service only. HID Applet 2.7.8 supports Put RSA 2048 and 3072 certificate serviceIND_1HID applet application parameters for putting certificate T/V dataReturn Status WordMessage AuthenticationCO - SD-SMAC: E - PIV-RPAK-PUB: W - PIV-RDSK-PUB: W - PIV-RCAK-PUB: W - PIV-RKDK-PUB: W
PUT AES 128 using Symmetric Cryptographic AuthenticationManage AES 128 using Symmetric Cryptographic Authentication Put AES 128 key used by ACA applet to authenticate the AA role (0-8 keys) Legacy use Key wrapped by SD- KDEKIND_1HID Applet application parametersReturn Status WordKTSCO - ACA-SPAK: W,Z - SD-KDEK: E - SD-SMAC: E
Manage Security valueManage Security value using the secure channel PIN, PUK, Pairing CodeIND_1HID Applet application parametersReturn Status WordKTSCO - ACA-PIN: W - ACA-PUK: W - ACA-PC: W - SD-SENC: E - SD-SMAC: E
OPACITY ECC Key Pair generationOPACITY ECC Key Pair generationIND_1HID Applet Application parametersReturn Status WordGenerate Key Pair EC (CKG) Message AuthenticationCO - SMA-OPRI: G - SD-SMAC: E - SMA-OPRI-PUB: G
Manage HID Applet ConfigurationRegister/Unregister applet instance, set its associated identifier, and relatedIND_1HID Applet Application ParametersHID Applet application response and status wordKDF Message AuthenticationCO - SD-SMAC: E

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 20
NameDescription ACR configuration in ACA, and Instance propertiesIndicatorInputsOutputsSecurity FunctionsSSP Access
Read HID Applet infoRetrieve applet instance properties, public ACR and associated properties, secure messaging certificate (CVC). ACR configuration defined which role is allowed to perform the service.IND_1HID Applet Application ParametersHID Applet application response and status wordNoneAA USR Unauthenticated
PIV AuthenticationAuthentication of the PIV application by an external system, Required PIN verificationIND_1Data to sign.Signature, return Status WordDigital Signature Verification RSAUSR - PIV-RPAK: E
PIV Card AuthenticationAuthentication by an external systemIND_1Data to signSignature, return Status WordDigital Signature Verification RSAUnauthenticated - PIV-RCAK: E
PIV Digital SignatureSign an externally generated Hash, Required PIN verificationIND_1Data to signSignature, return statusDigital Signature Generation RSAUSR - PIV-RDSK: E
PIV System Key serviceUnwrap a key provided by the host. The key is not established into or used by the module, Required PIN verificationIND_1Wrapped data to unwrapUnwrapped data, return statusKTS-IFCUSR - PIV-RKDK: E
PIV Read DataRead PIV Data objectsIND_1Specified in NIST.SP.800- 73-4PIV Data. Specified in NIST.SP.800- 73-4NoneUSR
VerifyVerify the PIN, Pairing Code, and PUKIND_1PIN, Pairing Code or PUKReturn Status WordEncryption - DecryptionUnauthenticated - OS-MKDK : E - ACA-PIN: E - ACA-PUK: E - ACA-PC: E
OPACITY Secure MessageEstablish OPACITY- ZKM secure messagingIND_1DataControl byte + nonce + cryptogram + cert return Status WordOpacity Secure Channel (KAS) Secure HashUnauthenticated - OS-DRBG-EI : G,E - OS-DRBG-S : G,E - OS-DRBG-V : G,E - OS-DRBG-KEY : G,E - OPACITY-SENC : G,E - OPACITY-SMAC: G,E - OPACITY- SRMAC : G,E - OPACITY- SCONFIRMATION:

G,E G,E G,E G,E HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 21
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access G,E,Z - SMA-OPRI: E - SMA-OPRI-PUB: R - OPACITY-Z: G,E,Z - ROE-PUB: E
Read CertificatesRead Certificate from a user card, that is configured as read always in ACA ACR configuration as SP- 800-73-4IND_1Input Data defined in SP- 800-73-4Certificate, data format defined in SP- 800-73-4NoneUnauthenticated - PIV-RPAK-PUB: R - PIV-RDSK-PUB: R - PIV-RCAK-PUB: R - PIV-RKDK-PUB: R
Symmetric Cryptographic AuthenticationUse of AES for encryptionIND_1HID Application ParameterEncrypted Data + Status WordEncryption - DecryptionAA - ACA-SPAK: E

G,E,Z R G,E,Z R R Table 12: Approved Services In the ‘Roles SSP Access’ column: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroize: The module zeroizes the SSP In the ‘Indicator Column’: IND_1: The status conditions for successfully completed execution is 90 00

4.4 Non-Approved Services
4.5 External Software/Firmware Loaded

The module has a limited operational environment. In the Approved mode of operation, the Cryptographic Officer (Crypto Officer) has access to the firmware load service. Only applets that are validated under FIPS 140-3 shall be loaded and installed. The firmware loading service relies on the DAP Verification specified in Global Platform Specification v2.3, whereby the DAP Verification (DAP-SYM) key uses AES-CMAC (Cert. #A2877) as the approved data authentication technique. The firmware load test verifies the validity of the firmware package to be loaded. HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 22
MechanismInspection FrequencyInspection Guidance
Single-Chip PackagingOn receipt of module following transport. Before each module use.In the event of any observed damage, photograph the card and contact Thales to confirm whether observed anomalies are to be expected or are confirmed signs of potential tampering
5 Software/Firmware Security
5.1 Integrity Techniques

The CM’s firmware integrity is checked on startup and when periodic self-test period is over. Periodic Self-Tests (PST) are performed and run the firmware integrity tests. The integrity technique is based on EDC (CRC-16), which is approved for a hardware module. The firmware image size covered by the integrity technique is roughly 200 KB. Failure of firmware integrity self-tests during Periodic Self-Tests (PST) will trigger a module halt. Recovery from this state will require the module to be restarted and for the detected fault to have cleared. Otherwise the module will re-halt during POST following restart. The module’s FIPS error log is updated regarding the encountered issue and the card goes into an error state.

5.2 Initiate on Demand

The integrity test can be triggered on demand by setting the specific flag with the proprietary command “Request for autotest”. Restarting the module will cause the integrity check to be rerun.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited How Requirements are Satisfied: The module includes a limited Operating Environment. Only authorized applets can be loaded at post-issuance under control of the Cryptographic Officer. Their execution is controlled by the CM operating system following its security policy rules.

7 Physical Security
7.1 Mechanisms and Actions Required

Table 13: Mechanisms and Actions Required The module is a hardware module claiming level 3 physical security and of embodiment single-chip. The module meets commercial-grade specifications for power, temperature, reliability, and shock/vibrations. The CM uses standard passivation techniques and is protected by passive shielding (metal layer coverings opaque HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 23
Temp/Voltage TypeTemperature or VoltageEFP or EFTResult
LowTemperature-45°CEFPshutdown
HighTemperature+130°CEFPshutdown
LowVoltage1.6 VEFPshutdown
HighVoltage5.5 VEFPshutdown
Temperature TypeTemperature
LowTemperature-25°C
HighTemperature85°C
Storage Area NameDescriptionPersistence Type
RAMRandom Access MemoryDynamic
FLASHElectronic non-volatile memory storageStatic

to the circuitry below) and active shielding (a grid of top metal layer wires with tamper response). A tamper event detected by the active shield places the Module permanently into the Card Is Killed error state. The Module is designed to be mounted in a plastic smartcard or similar package; physical inspection of the epoxy side of the Module is not practical after mounting. Table 14: EFP/EFT Information The module’s hardware is designed to sense and respond to out-of-range temperature conditions as well as outof-range voltage conditions. The temperature and voltage conditions are only monitored in the powered-on state. The module supports an EFP mechanism that will trigger module shutdown if low or high temperature extremes and out-of-range voltage conditions are detected whilst the module is active. In the event that the module senses an out-of-range temperature or over voltage the module will reset itself, clearing all working memory. The module can be reset and placed back into operation when in-bound operating conditions have been restored.

7.6 Hardness Testing Temperature Ranges

Table 15: Hardness Testing Temperatures

8 Non-Invasive Security
9 Sensitive Security Parameters Management
9.1 Storage Areas

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 24
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
PutKey or Writing with Secure Channel (contact)EnteredFLASHEncryptedManualElectronicKTS
PutKey or Writing with Secure Channel ( contactless)EnteredFLASHEncryptedWirelessElectronicKTS
PUT Key (RSA) (contact)EnteredFLASHEncryptedManualElectronicKTS
PUT Key (RSA) (contactless)EnteredFLASHEncryptedWirelessElectronicKTS
PUT Certificate (contact)EnteredFLASHEncryptedManualElectronicMessage Authentication
PUT Certificate (contactless)EnteredFLASHEncryptedWirelessElectronicMessage Authentication
PUT AES 128 (contact)EnteredFLASHEncryptedManualElectronicKTS
PUT AES 128 (contactless)EnteredFLASHEncryptedWirelessElectronicKTS
Manage Security value (contact)EnteredFLASHEncryptedManualElectronicKTS
Manage Security value(contactless)EnteredFLASHEncryptedWirelessElectronicKTS
OPACITY Secure Message input (contact)EnteredRAMPlaintextManualElectronicOpacity Secure Channel (KAS)
OPACITY Secure Message input (contactless)EnteredRAMPlaintextWirelessElectronicOpacity Secure Channel (KAS)
OPACITY Secure Message output (contact)FLASHOutputPlaintextManualElectronicOpacity Secure Channel (KAS)
OPACITY Secure Message output (contactless)FLASHOutputPlaintextWirelessElectronicOpacity Secure Channel (KAS)
Read Certificates (contact)FLASHOutputPlaintextManualElectronic
Read Certificates (contactless)FLASHOutputPlaintextWirelessElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Module entering TERMINATED stateUsing the Manage Content / Lifecycle service of the CO, the CM is able to enter the TERMINATED state, through the Set Status command, destroying the SSPs by overwriting with zero values.Overwrite with zero valuesyes
Power-cycling the moduleUsing the Module Reset service, the CM is able to destroy the SSPs by overwriting with zero values (in RAM memory).Overwrite with zero valuesYes
Closing SCP secure channelUsing the Secure Channel service of the CO, the CM is able to destroy the SSPs of this service, at the closing of SCP secure channel by overwriting with zero valuesOverwrite with zero valuesYes
Uninstallation of appletUsing the Manage Content / Delete service of the CO, the CM is able to destroy the SSPs of applet, through the Delete command (uninstall method).Overwrite with zero valuesYes
Zeroize after useZeroize immediately after useOverwrite with zero valuesNo

Table 16: Storage Areas All SSPs used by the CM are described in this section. All usages of these SSPs by the CM are described in the services. In addition, all keys stored in RAM are zeroized upon power-cycle of the CM.

9.2 SSP Input-Output Methods

Table 17: SSP Input-Output Methods ‘PutKey or Writing with Secure channel’ keys are encrypted by SD-KDEK; key identifier entity association during manufacturing. This command is only used only during manufacturing.

9.3 SSP Zeroization Methods

Table 18: SSP Zeroization Methods HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 25
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
OS-DRBG-EIEntropy Input 1024- bit random drawn by an external entropy source populated during CM initialization and used as entropy input for the [SP 800-90Ar1] DRBG implementation1024 bit - 256 bitsEntropy Input - CSPEntropy Source (E107)Generate Key Pair EC (CKG) Generate Key Pair RSA (CKG)
OS-DRBG-SSeed 48 bytes seed output from AES_DF used for instantiation of the [SP800-90Ar1] DRBG implementation768 bits - 256 bitsSeed - CSPEntropy Source (E107)Generate Key Pair EC (CKG) Generate Key Pair RSA (CKG)
OS-DRBG-VDRBG "V" value 16- byte AES state V used in the [SP 800- 90Ar1] CTR DRBG implementation128 bits - 128 bitsDRBG "V" Value - CSPCounter DRBG (A2877)Generate Key Pair EC (CKG) Generate Key Pair RSA (CKG)
OS-DRBG-KEYDRBG "Key" value 32-byte AES key used in the [SP 800- 90Ar1] CTR DRBG implementation256 bits - 256 bitsDRBG "Key" value - CSPCounter DRBG (A2877)Generate Key Pair EC (CKG) Generate Key Pair RSA (CKG)
OS-MKDKEncryption key128, 192, 256 bits - 128 bits, 192 bits, 256 bitsEncryption Symmetric Key - CSPEncryption - Decryption
SD-KENCDecryption Key AES- 128/192/256 master key128, 192, 256 bits - 128 bits, 192 bits, 256 bitsDecryption Symmetric Key - CSPKDF
SD-KMACSignature verification Key AES- 128/192/256 master key128, 192, 256 bits - 128 bits, 192 bits, 256 bitsMessage Authentication; Symmetric Key - CSPKDF
SD-KDEKEncryption decryption AES-128/192/256 key128, 192, 256 bits - 128 bits, 192 bits, 256 bitsEncryption / Decryption Symmetric Key - CSPEncryption - Decryption KDF
SD-SENCSession decryption key128, 192, 256 bits - 128 bits, 192 bits, 256 bitsDecryption Symmetric Key - CSPKDFEncryption - Decryption
SD-SMACSession Signature verification Key128, 192, 256 bits -Message AuthenticationKDFMessage Authentication

All SSPs stored in RAM are zeroized upon power-cycle of the CM.

9.4 SSPs

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 26
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
128 bits, 192 bits, 256 bitsSymmetric Key - CSP
SD-MDAP-KDEKEncryption decryption AES-128/192/256 key for SD with MDAP128, 192, 256 bits - 128 bits, 192 bits, 256 bitsEncryption / Decryption Symmetric Key - CSPEncryption - Decryption
SD- MDAP -KENCDecryption Key AES- 128/192/256 key for SD with MDAP128, 192, 256 bits - 128 bits, 192 bits, 256 bitsDecryption Symmetric Key - CSPEncryption - Decryption
SD- MDAP -KMACSignature verification Key AES- 128/192/256 key for SD with MDAP128, 192, 256 bits - 128 bits, 192 bits, 256 bitsMessage Authentication Symmetric Key - CSPMessage Authentication
DAP-SYMDAP verification key128, 192, 256 bits - 128 bits, 192 bits, 256 bitsSignature verification Symmetric Key - CSPMessage Authentication
OPACITY-SENCCard OPACITY Secure Messaging Session Encryption Key128, 256 bits - 128 bits, 256 bitsEncryption Symmetric Key - CSPOpacity Secure Channel (KAS)Encryption - Decryption
OPACITY-SMACCard OPACITY Secure Messaging Session MAC Key128, 256 bits - 128 bits, 256 bitsMessage Authentication Symmetric Key - CSPOpacity Secure Channel (KAS)Message Authentication
OPACITY-SRMACCard OPACITY Secure Messaging Session Response MAC Key128, 256 bits - 128 bits, 256 bitsSignature generation Symmetric Key - CSPOpacity Secure Channel (KAS)Message Authentication
OPACITY- SCONFIRMATIONCard OPACITY Secure Messaging Session Confirmation Key128, 256 bits - 128 bits, 256 bitsSignature generation confirmation Symmetric Key - CSPOpacity Secure Channel (KAS)Opacity Secure Channel (KAS)
OPACITY-ZShared secret generated during opacity secure channel establishment256 bits - 256 bitsShared secret - CSPOpacity Secure Channel (KAS)Opacity Secure Channel (KAS)
ACA-PINEnter by User. Use for USR Verification64 bits - 64 bitsPersonal Identification Number - CSP
ACA-PUKUse for USR PIN unlock64 bits - 64 bitsPIN Unblocking Key - CSP
ACA-PCPIV VCI Pairing Code Verification PIN64 bits - 64 bitsPairing Code - CSP
SMA-OPRICard OPACITY Secure Channel ECC KeypairP-256 - 256 bitsKey Agreement Asymmetric Key - CSPGenerate Key Pair EC (CKG)Opacity Secure Channel (KAS)
PIV-RPAKPIV-RPAK is Private Key performs Digital Signature PIV-RPAK: PIV AuthenticationApplet 2.7.8: 2048 bits , 3072 bits; AppletSignature generation Asymmetric Key - CSPGenerate Key Pair RSA (CKG)Digital Signature Verification RSA

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 27
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
(9A) RSA authentication Key2.7.7: 2048 bits - 112 bits, 128 bits
PIV-RDSKPrivate Key performs Digital Signature PIV- RDSK: PIV Card Authentication (9C) RSA Authentication KeyApplet 2.7.8: 2048 bits , 3072 bits; Applet 2.7.7: 2048 bits - 112 bits, 128 bitsSignature generation Asymmetric Key - CSPGenerate Key Pair RSA (CKG)Digital Signature Generation RSA
PIV-RCAKPrivate Key performs Digital Signature, PIV-RCAK: PIV Card Authentication (9E) RSA Authentication KeyApplet 2.7.8: 2048 bits , 3072 bits; Applet 2.7.7: 2048 bits - 112 bits, 128 bitsSignature generation Asymmetric Key - CSPGenerate Key Pair RSA (CKG)Digital Signature Verification RSA
PIV-RKDKPIV-RKDK: PIV Key Management (9D) RSA private decryption key and up to 5 copies of this key may be stored in retired key locations "82" thought "86"Applet 2.7.8: 2048 bits , 3072 bits; Applet 2.7.7: 2048 bits - 112 bits, 128 bitsDecryption - CSPKTS-IFC
PIV-RPAK-PUBPIV Digital Authentication (9A)'s RSA Public Key with certificate (No Private Key). The module stores the certificate, but does not perform Security Function with this certificate.Applet 2.7.8: 2048 bits , 3072 bits; Applet 2.7.7: 2048 bits - 112 bits, 128 bitsPublic - PSPGenerate Key Pair RSA (CKG)KTS-IFC
PIV-RDSK-PUBPIV Card Signature (9C)'s RSA Public Key with certificate (No Private Key). The module stores the certificate, but does not perform Security Function with this certificate.Applet 2.7.8: 2048 bits , 3072 bits; Applet 2.7.7: 2048 bits - 112 bits, 128 bitsPublic - PSPGenerate Key Pair RSA (CKG)
PIV-RCAK-PUBPIV Key Card Authentication (9E)'s RSA Public Key with certificate. The module stores the public certificate.Applet 2.7.8: 2048 bits , 3072 bits; Applet 2.7.7: 2048 bits - 112 bits, 128 bitsPublic - PSPGenerate Key Pair RSA (CKG)
PIV-RKDK-PUBPIV Key management (9D)'s RSA Public Key with certificate. TheApplet 2.7.8: 2048 bits , 3072 bits; Applet 2.7.7: 2048Public - PSPGenerate Key Pair RSA (CKG)

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 28
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
module stores public the certificatebits - 112 bits, 128 bits
SMA-OPRI-PUBHash of the certificate is one of parameters to generate session keys of OPACITY secure channel.2048 bits - P-256Public - PSPGenerate Key Pair EC (CKG)Opacity Secure Channel (KAS)
ACA-SPAKAES, Use for AA authentication128 bits - 128 bitsEncryption Symmetric Key - CSPEncryption - Decryption
ROE-PUBReader ephemeral public key used for opacityP-256 - 2048 bitsPublic - PSPOpacity Secure Channel (KAS)
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
OS-DRBG-EIRAM:PlaintextDuration of the module sessionModule entering TERMINATED stateOS-DRBG-V :Derives OS-DRBG-KEY :Derives
OS-DRBG-SRAM:PlaintextDuration of the module sessionModule entering TERMINATED state Power-cycling the moduleOS-DRBG-V :Derives OS-DRBG-KEY :Derives
OS-DRBG-VRAM:PlaintextDuration of the module sessionModule entering TERMINATED state Power-cycling the moduleOS-DRBG-EI :Derived From OS-DRBG-S :Derived From
OS-DRBG-KEYRAM:PlaintextDuration of the module sessionModule entering TERMINATED stateOS-DRBG-EI :Derived From OS-DRBG-S :Derived From
OS-MKDKPutKey or Writing with Secure Channel (contact) PutKey or Writing with Secure Channel ( contactless)FLASH:PlaintextModule entering TERMINATED stateACA-PIN:Encrypts
SD-KENCPutKey or Writing with Secure Channel (contact) PutKey or Writing with Secure Channel ( contactless)FLASH:PlaintextModule entering TERMINATED stateSD-SENC:Derives SD-KDEK:Wrapped by
SD-KMACPutKey or Writing with Secure Channel (contact) PutKey or Writing with SecureFLASH:PlaintextModule entering TERMINATED stateSD-KDEK:Wrapped by

Table 19: SSP Table 1 HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 29
Name SD-KDEKInput - Output Channel ( contactless) PutKey or Writing with Secure Channel (contact) PutKey or Writing with Secure Channel ( contactless)Storage FLASH:PlaintextStorage DurationZeroization Module entering TERMINATED stateRelated SSPs SD-KENC:Encrypts SD-KMAC:Encrypts SD-KDEK:Encrypts ACA-PIN:Encrypts ACA-PUK:Encrypts ACA-PC:Encrypts SMA-OPRI:Encrypts PIV-RPAK:Encrypts PIV-RDSK:Encrypts PIV-RCAK:Encrypts PIV-RKDK:Encrypts PIV-RPAK-PUB:Encrypts PIV-RDSK-PUB:Encrypts PIV-RCAK-PUB:Encrypts PIV-RKDK-PUB:Encrypts SMA-OPRI-PUB:Encrypts ACA-SPAK:Encrypts
SD-SENCRAM:PlaintextDuration of the SCP secure channelPower-cycling the module Closing SCP secure channelSD-KENC:Derived From
SD-SMACRAM:PlaintextDuration of the SCP secure channelPower-cycling the module Closing SCP secure channelSD-KMAC:Derived From
SD-MDAP-KDEKPutKey or Writing with Secure Channel (contact) PutKey or Writing with Secure Channel ( contactless)FLASH:PlaintextModule entering TERMINATED stateSD-MDAP-KDEK:Encrypts SD- MDAP - KENC:Encrypts SD- MDAP - KMAC:Encrypts DAP-SYM:Encrypts
SD- MDAP -KENCPutKey or Writing with Secure Channel (contact) PutKey or Writing with Secure Channel ( contactless)FLASH:PlaintextModule entering TERMINATED stateSD-MDAP-KDEK:Wrapped by
SD- MDAP -KMACPutKey or Writing with Secure Channel (contact) PutKey or Writing with Secure Channel ( contactless)FLASH:PlaintextModule entering TERMINATED stateSD-MDAP-KDEK:Wrapped by
DAP-SYMPutKey or Writing with Secure Channel (contact) PutKey or Writing with Secure Channel ( contactless)FLASH:PlaintextModule entering TERMINATED stateSD-MDAP-KDEK:Wrapped by

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 30
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
OPACITY-SENCRAM:PlaintextDuration of the SCP secure channelPower-cycling the module Closing SCP secure channelOPACITY-Z:Derived From
OPACITY-SMACRAM:PlaintextDuration of the SCP secure channelPower-cycling the module Closing SCP secure channelOPACITY-Z:Derived From
OPACITY-SRMACRAM:PlaintextDuration of the SCP secure channelPower-cycling the module Closing SCP secure channelOPACITY-Z:Derived From
OPACITY- SCONFIRMATIONRAM:PlaintextDuration of the SCP secure channel establishmentPower-cycling the module Closing SCP secure channelOPACITY-Z:Derived From
OPACITY-ZRAM:PlaintextDuration of the SCP secure channel establishmentZeroize after useSMA-OPRI:Derived From OPACITY-SENC :Derives OPACITY-SMAC:Derives OPACITY-SRMAC :Derives OPACITY- SCONFIRMATION:Derives
ACA-PINManage Security value (contact) Manage Security value(contactless)FLASH:PlaintextModule entering TERMINATED state Uninstallation of appletOS-MKDK :Wrapped by
ACA-PUKManage Security value (contact) Manage Security value(contactless)FLASH:PlaintextModule entering TERMINATED state Uninstallation of applet
ACA-PCManage Security value (contact) Manage Security value(contactless)FLASH:PlaintextModule entering TERMINATED state Uninstallation of applet
SMA-OPRIPutKey or Writing with Secure Channel (contact) PutKey or Writing with Secure Channel ( contactless)FLASH:PlaintextModule entering TERMINATED state Uninstallation of appletSMA-OPRI-PUB:Paired With OPACITY-Z:Derives
PIV-RPAKFLASH:PlaintextModule entering TERMINATED state Uninstallation of appletPIV-RPAK-PUB:Paired With

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 31

Name PIV-RDSK PIV-RCAK PIV-RKDK PIV-RPAK-PUB PIV-RDSK-PUB PIV-RCAK-PUB PIV-RKDK-PUB SMA-OPRI-PUB ACA-SPAK

Input - Output PUT Key (RSA) (contact) PUT Key (RSA) (contactless) PUT Certificate (contact) PUT Certificate (contactless) Read Certificates (contact) Read Certificates (contactless) PUT Certificate (contact) PUT Certificate (contactless) Read Certificates (contact) Read Certificates (contactless) PUT Certificate (contact) PUT Certificate (contactless) Read Certificates (contact) Read Certificates (contactless) PUT Certificate (contact) PUT Certificate (contactless) Read Certificates (contact) Read Certificates (contactless) OPACITY Secure Message output (contact) OPACITY Secure Message output (contactless) PUT AES 128 (contact)

Storage FLASH:Plaintext FLASH:Plaintext FLASH:Plaintext FLASH:Plaintext FLASH:Plaintext FLASH:Plaintext FLASH:Plaintext FLASH:Plaintext FLASH:Plaintext

Storage Duration

Zeroization Module entering TERMINATED state Uninstallation of applet Module entering TERMINATED state Uninstallation of applet Module entering TERMINATED state Uninstallation of applet Module entering TERMINATED state Uninstallation of applet Module entering TERMINATED state Uninstallation of applet Module entering TERMINATED state Uninstallation of applet Module entering TERMINATED state Uninstallation of applet Module entering TERMINATED state Uninstallation of applet Module entering TERMINATED

Related SSPs PIV-RDSK-PUB:Paired With PIV-RCAK:Paired With PIV-RKDK-PUB:Paired With PIV-RPAK:Paired With PIV-RDSK:Paired With PIV-RCAK:Paired With PIV-RKDK:Paired With SMA-OPRI:Paired With

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 32
NameInput - Output PUT AES 128 (contactless)StorageStorage DurationZeroization state Uninstallation of appletRelated SSPs
ROE-PUBOPACITY Secure Message input (contact) OPACITY Secure Message input (contactless)RAM:PlaintextDuration of the SCP secure channel establishmentZeroize after useOPACITY-Z:Derives
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Integrity testEDC (16-bit CRC)KATSW/FW IntegrityBit32 of flag set to 1Comparison with known value
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A2877)decrypt KAT using an AES 128-bit key in ECB mode.KATCASTBit 18 of flag set to 1decryptCOND_1
KDF SP800- 108 (A2877)generates AES-CMAC message performs a KDF AES-CMAC KAT using an AES 128-byte key and 32-byte derivation dataKATCASTBit 18 of flag set to 1encrypt signCOND_1

Table 20: SSP Table 2 The following table lists Sensitive Security Parameters (SSP) used to perform approved security function supported by the cryptographic module. The following notes should be observed when reading the table:

Keys with the “SD” prefix pertain to a Global Platform Security Domain key set. The module supports the Issuer Security Domain at minimum, and can be configured to support Supplemental Security Domains
The “PRI” suffix indicates that this is a private key
The “PUB” suffix indicates that this is a public key
The “SYM” suffix indicates that this is a symmetric key
The “ASYM” suffix indicates that this is an asymmetric key
The “ACA” prefix is used for the HID ACA Applet keys.
The “SMA” prefix is used for HID PIV Applet OPACITY keys
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 21: Pre-Operational Self-Tests On power-on or reset, the Module performs integrity testing using an EDC (16-bit CRC) performed over all code located in FLASH and EEPROM memory (for OS and Applets).

10.2 Conditional Self-Tests

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 33
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigGen (FIPS186-5) (A2877)Performs an RSA PKCS#1 v1.5 signature generation using an RSA 2048-bit private STD key implementationKATCASTBit 27 of flag set to 1SignCOND_1
RSA SigVer (FIPS186-5) (A2877)Performs an RSA PKCS#1 v1.5 signature verification using an RSA 2048-bit public STD keyKATCASTBit 26 of flag set to 1VerifyCOND_1
KAS-ECC Sp800-56Ar3 (A2877)Performs a Key Agreement Scheme Standalone Shared Secret ECC using an ECC P-224 keyKATCASTBit 29 of flag set to 1Key AgreementCOND_1
SHA2-256 (A2877)SHA2-256: hashes a 24-bytes messageKATCASTBit 21 of flag set to 1HashingCOND_1
SHA2-512 (A2877)SHA2-512: hashes a 24-bytes messageKATCASTBit 21 of flag set to 1HashingCOND_1
Counter DRBG (A2877)Gets a random value with specific nonce (48 bytes) and entropy (128 bytes) SP 800-90AR1 Tests 11.3 (11.3.1-11.3.3)KATCASTBit 3 of flag set to 1DRBGCOND_1
ECDSA KeyGen (FIPS186-5) (A2877)Sign a fixed pattern and verify with the public key in order to validate the key pairPCTPCTIND 3Sign, VerifyCOND_2
RSA KeyGen (FIPS186-5) (A2877)Performs signature generation and verification using the key pairPCTPCTIND 3Encrypt , DecryptCOND_2
SP 800-90B RCTEntropy error eventFault- Detection testCASTIND 2TRNG ErrorCOND_1
SP 800-90B APTStatistic error eventFault- Detection testCASTIND 2TRNG ErrorCOND_1
Firmware LoadMAC verification with AES CMAC (128-256 bit key)SignatureSW/FW LoadIND_4MAC verification with AES CMACCOND_3

Table 22: Conditional Self-Tests The module maintains a flag in RAM memory that stores the state (self-test passed or not) for each Cryptographic algorithm that is approved. This flag indicates if an algorithm has been already self-tested. The Module performs self-test of an algorithm prior the first operational use (corresponding flag is not set) and if the self-test succeeds, the corresponding flag is set otherwise the card logs the self-test error and entered into a Card Is Mute error state or Card is Killed error state, depending on number of failures. On each reset, all flags for cryptographic algorithm self-tests are cleared. IND_2: In case of error detection, the module enters into specific error states such as "Card Is Mute" or "Card is Killed." IND_3: If the test fails, the error is logged in error log of “Approved mode parameters” IND_4: An unsuccessful execution returns the status word: Security Conditions not satisfied In the ‘Condition Column’: HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 34
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Integrity testKATSW/FW IntegrityPeriodic counter valueCount of APDU received by the CM
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A2877)KATCASTPeriodic counter valueCount of APDU received by the CM
KDF SP800-108 (A2877)KATCASTPeriodic counter valueCount of APDU received by the CM
RSA SigGen (FIPS186-5) (A2877)KATCASTPeriodic counter valueCount of APDU received by the CM
RSA SigVer (FIPS186- 5) (A2877)KATCASTPeriodic counter valueCount of APDU received by the CM
KAS-ECC Sp800- 56Ar3 (A2877)KATCASTPeriodic counter valueCount of APDU received by the CM
SHA2-256 (A2877)KATCASTPeriodic counter valueCount of APDU received by the CM
SHA2-512 (A2877)KATCASTPeriodic counter valueCount of APDU received by the CM
Counter DRBG (A2877)KATCASTPeriodic counter valueCount of APDU received by the CM
ECDSA KeyGen (FIPS186-5) (A2877)PCTPCTN/AN/A
RSA KeyGen (FIPS186-5) (A2877)PCTPCTN/AN/A
SP 800-90B RCTFault-Detection testCASTN/AN/A
SP 800-90B APTFault-Detection testCASTN/AN/A
Firmware LoadSignatureSW/FW LoadN/AN/A

COND_1: The self-test is executed before the first operational use of the algorithm if the indicator is not set COND_2: The test is executed at each Key pair generation requested by the module COND_3: The test is executed on each APDU Command

10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information Table 24: Conditional Periodic Information strictly periodic but are triggered whenever the module calls on the services they depend on. The Module supports an internal counter and an associated maximum value. The counter is set to its maximum value on power on and it is decremented when receiving an APDU. When the counter reaches zero, the integrity test is executed (see 10.1), the counter is reset to its maximum value, and the flag for on-demand tests is reset so that at the next individual cryptographic algorithm usage, the CAST for that algorithm are executed again (see 10.2.1). No interruption to the module’s operation is expected while the CASTs are executed. The periodic counter is stored in RAM and defined during the init flow.

10.4 Error States

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024

Page 35
NameDescriptionConditionsRecovery MethodIndicator
Card is MuteThe module Resource Manager has shut downFault DetectedReset cardError log is stored
Card is killedThe module Resource Manager has shut down. It no longer responds to the command, serviceFault DetectedN/ANo answer from module
10.5 Operator Initiation of Self-Tests

The cryptographic KATs are executed automatically, in a mode named “on demand”, when a cryptographic Self-tests can be run by any operator using the “autotests management” APDU command, corresponding to the “Request for autotest” service. The operator can choose from the list of self-test executions by providing the appropriate self-test flag.

10.6 Additional Information

The module performs continuous health tests of the entropy using the repetition count test and the adaptative Proportion test. The cryptographic module performs a pair-wise consistency test for every generated public and private key pair. If this test fails, the error is logged into the error log. The module performs a validity check of the public static key and the ephemeral keys according to the SP 80056Ar3 specification. If this test fails, the error is logged into the error log. The module performs hardware fault detection tests (APT and RCT tests). If a fault is detected, the module will handle the error by entering entered into a “Card Is Mute” error state or “Card is Killed” error state. In case of failure, the module will handle the error by entering entered into a “Card Is Mute” error state or “Card is Killed” error state, depending on number of failures. If 8 consecutive failures occur, the module irreversibly In case of “Card Is Mute”, the crypto module provides an error log an error log that is accessible by an authorized operator of the module. Following are the details on specific ADPU return codes returned upon specific self-test failures:

Page 36
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Some additional documents (‘Delivery and Operation’, ‘Reference Manual’, ‘Card Initialization Specification’ documents) define and describe the steps necessary to deliver and operate the CM securely. Once the module has been delivered outside of the factory, the CM is always in Approved mode. The configuration cannot be changed outside the factory. Product documentation, technical notes are available on The Customer Support Portal https://supportportal.thalesgroup.com.

11.2 Administrator Guidance

The Guidance document provided with CM is intended to be the ‘Reference Manual’. This document includes guidance for secure operation of the CM by its users as defined in the Roles, Services, and Authentication chapter.

11.3 Non-Administrator Guidance

Please refer to section 11.2.

11.6 End of Life

When the module has reached end of life and is no longer deployed or intended for further use, it shall be placed in the TERMINATED state by the Crypto Officer. Following this, the module shall be taken to a suitable electronics recycling facility that assures physical destruction of electronic waste.

11.7 Additional Information

The Module implementation also enforces the following security rules:

Page 37
12 Mitigation of Other Attacks

HID Global ActivID Applet Suite 2.7.7 & 2.7.8 on the Thales IDCore 3230 Platform Cryptographic Module Non-Proprietary Security Policy 002-000482-001, Rev F, Sep 27, 2024