| Standard | FIPS 140-3 |
|---|---|
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 6/23/2030 |
| Caveat | None |
| Vendor | Kingston Technology Company, Inc. |
| Algorithm | ACVP Cert |
|---|---|
| AES-CBC | A3268 |
| AES-ECB | A3268 |
| AES-KW | A3268 |
| AES-XTS Testing Revision 2.0 | A3268 |
| ECDSA KeyGen (FIPS186-5) | A3268 |
| ECDSA KeyVer (FIPS186-4) | A3268 |
| HMAC DRBG | A3268 |
| HMAC-SHA2-256 | A3268 |
| KAS-ECC-SSC Sp800-56Ar3 | A3268 |
| KDA TwoStep SP800-56Cr2 | A3268 |
| PBKDF | A3268 |
| RSA SigVer (FIPS186-4) | A3268 |
| SHA2-256 | A3268 |
flowchart LR
%% Deterministic review-risk graph for IronKey D500S Series USB Flash Drive
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>Self-test</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for IronKey D500S Series USB Flash Drive
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>Self-test</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;Kingston Technology Company, Inc. IronKey D500S Series USB Flash Drive Document Version 1.0 This document may be freely reproduced and distributed, but only in its entirety and without modification.
| # | Section | Page |
|---|
This document may be freely reproduced and distributed, but only in its entirety and without modification.
This document may be freely reproduced and distributed, but only in its entirety and without modification.
TABLE OF TABLES This document may be freely reproduced and distributed, but only in its entirety and without modification.
| ISO/IEC 24759 | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 3 |
| 2 | Cryptographic Module Specification | 3 |
| 3 | Cryptographic Module Interfaces | 3 |
| 4 | Roles, Services, and Authentication | 3 |
| 5 | Software/Firmware Security | 3 |
| 6 | Operational Environment | N/A |
| 7 | Physical Security | 3 |
| 8 | Non-Invasive Security | N/A |
| 9 | Sensitive Security Parameter Management | 3 |
| 10 | Self-Tests | 3 |
| 11 | Life-Cycle Assurance | 3 |
| 12 | Mitigation of Other Attacks | N/A |
| Overall Level: | 3 |
The Kingston Technology Company, Inc. (Kingston) IronKey D500S Series USB Flash Drive is a hardware cryptographic module designed to meet the overall requirements of FIPS 140-3 Security
The Kingston IronKey D500S Series USB Flash Drive (refer to Figure 1) is a hardware cryptographic module designed for organizations that require a secure way to store and transfer portable data. The stored data is secured by hardware‐based 256‐bit AES on‐the‐fly encryption to guard sensitive information in case the drive is lost or stolen. Its strong, durable, metal casing provides robust physical protection. Its strong password rules and lock‐down control protect against brute force attacks. Such advanced security features make the IronKey D500S Series USB Flash Drive ideal for corporations and service organizations that require employees to transport large digital files consisting of confidential documents. This document may be freely reproduced and distributed, but only in its entirety and without modification.
The module is a multi-chip standalone cryptographic module whose outer enclosure defines the cryptographic boundary and Tested Operational Environment’s Physical Perimeter (TOEPP) (refer to Figure 1). Figure 1 – Cryptographic Boundary
2.2 T ESTED AND V ENDOR A FFIRMED M ODULE V ERSION AND I DENTIFICATION
The IronKey D500S Series USB Flash Drive is a FIPS 140-3 Security Level 3 (refer to Table 1) multi‐ chip standalone cryptographic module (module) available in the following configurations: − IKD500S/xGB − IKD500SM/xGB x = 8, 16, 32, 64, 128, 256 and 512 (denotes module’s memory capacity)
The module’s operating environment is defined as the non-modifiable, Kingston PS2251-15 USB AES Micro-Controller. The FIPS 140-3 Security Level 3 validated versioning information is shown in Table 2. The hardware versions differ by memory capacity e.g., 16GB, 32GB, etc. The Kingston IronKey D500S Series USB Flash Drive is marketed as IronKey D500S or IronKey D500SM. There is no physical or logical difference between these two branded products. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Model/Part Number(s) | Hardware Version(s) | Firmware Version(s) | Processor(s) | Non-Security Relevant Distinguishing Features | |
|---|---|---|---|---|---|
| IronKey D500S Series USB Flash Drive | IronKey D500S Series USB Flash | IronKey D500S/8GB | 3.06 | Kingston PS2251-15 USB AES Micro- Controller | 8GB of user data storage |
| Drive | IronKey D500S/16GB | 16GB of user data storage | |||
| IronKey D500S/32GB | 32GB of user data storage | ||||
| IronKey D500S/64GB | 64GB of user data storage | ||||
| IronKey D500S/128GB | 128GB of user data storage | ||||
| IronKey D500S/256GB | 256GB of user data storage | ||||
| IronKey D500S/512GB | 512GB of user data storage | ||||
| IronKey D500SM/8GB | 8GB of user data storage | ||||
| IronKey D500SM/16GB | 16GB of user data storage | ||||
| IronKey D500SM/32GB | 32GB of user data storage | ||||
| IronKey D500SM/64GB | 64GB of user data storage | ||||
| IronKey D500SM/128GB | 128GB of user data storage | ||||
| IronKey D500SM/256GB | 256GB of user data storage | ||||
| IronKey D500SM/512GB | 512GB of user data storage |
Table 2 – Tested Module Identification - Hardware
The module does not exclude any components from the requirements of FIPS 140-3.
The module supports a single approved mode of operation that is entered by powering-on the module. There are no non-approved modes, degraded modes or non-approved services available to the module. The module’s firmware provides an indicator (i.e., “FIPS ACTIVE”) showing the approved configuration which can be queried. This global indicator will be used along with the successful return codes of each service to indicate the module has provided an approved security service. If the module reports “FIPS DEFAULT”, the module is awaiting a new password (CO Password) to be set. The module is always running in an approved mode when module reports either “FIPS DEFAULT” or “FIPS ACTIVE”. The approved mode cannot be exited. The module does not support a non-approved or degraded mode of operation. In case of critical error, the module will remain in an error state, until reset. While in its error state, the LED will blink rapidly until it is reset. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| CAVP Cert(s) | Algorithm | Standards | Modes/ Methods | Description / Key Sizes, Curves, or Moduli / Key Strengths | Use/Function | |
|---|---|---|---|---|---|---|
| A3268 | AES-CBC | FIPS 197 NIST SP 800-38A | CBC | Key Length: 256-bit Strength: 256 bits | Key Length: 256-bit | Prerequisite for KW |
| Strength: 256 bits | Data Encryption/Decryption | |||||
| A3268 | AES-ECB | FIPS 197 NIST SP 800-38A | ECB | Key Length: 256-bit Strength: 256 bits | Prerequisite for KW Data Encryption/Decryption | |
| A3268 | AES-KW | FIPS 197 | KW | Key Length: 256-bit | DEK_CO and DEK_U | |
| NIST SP 800-38F | Strength: 256 bits | Encryption/Decryption | ||||
| A3268 | AES-XTS1 | FIPS 197 NIST SP 800-38E | XTS | Key Length: 256-bit Strength: 256 bits | Mass-Storage Data Encryption/Decryption | |
| A3268 | ECDSA | FIPS 186-5 | Key Generation | Curve: P-256 | Key Generation of KAS | |
| KeyGen | Strength: 128 bits | keys | ||||
| A3268 | ECDSA KeyVer | FIPS 186-4 | Key Verification | Curve: P-256 Strength: 128 bits | Key Verification of KAS keys | |
| A3268 | HMAC-SHA2- | FIPS 198-1 | SHA2-256 | Key Length: 256-bit | Prerequisite for KDA Message Authentication | |
| 256 | Strength: 256 bits | |||||
| A3268 | HMAC DRBG | NIST SP 800-90A | HMAC-SHA2-256 | Security strength: 256 bits | Deterministic Random Bit Generation | |
| A3268 | KAS-ECC-SSC | NIST SP 800-56Ar3 | ECC CDH | Curve: P-256 | Key Agreement Shared Secret calculation | |
| C(2e, 0s) | Strength: 128 bits | |||||
| A3268 | KDA | NIST SP 800-56Cr2 | Two-Step KDF (HMAC-SHA2-256) | Derived Key Length: 256 bits Shared Secret Length: 256 bits | Key derivation as part of KAS | |
| A3268 | PBKDF2 | NIST SP 800-132 (option 2A) | HMAC-SHA2-256 | Password length: 8 to 136 bytes (refer to Section 4.1) Salt Length: 256-bit | Deriving KEK_CO, KEK_U, KEK_R | |
| A3268 | RSA SigVer (PKCS1 v1.5) | FIPS 186-4 | Digital Signature Verification | Modulo: 2048 Strength: 128 bits | Digital Signature Verification |
The module supports the following approved cryptographic algorithms. Table 3 – Approved Algorithms
1 AES XTS was designed for the cryptographic protection of data on storage devices per NIST SP 800-38E. It
was not designed for other purposes, such as the encryption of data in transit.
2 The module implements PBKDF in conformance with NIST SP 800132 and FIPS IG D.N. Specifically, the
module implements Option 2a from Section 5.4 to generate the Key Encryption Key (KEK) responsible for protecting the Data Encryption Key using AES KW (Cert. #3268). The module implements an iteration counter equal to 1024 bits which is greater than the minimum recommendation documented within NIST SP 800-132 - Section 5.2. This is also justified by the maximum limit enforced on password retry attempts (Max = 10). This document may be freely reproduced and distributed, but only in its entirety and without modification.
| CAVP Cert(s) | Algorithm | Standards | Modes/ Methods | Description / Key Sizes, Curves, or Moduli / Key Strengths | Use/Function | |
|---|---|---|---|---|---|---|
| A3268 | SHA2-256 | FIPS 180-4 | SHA2-256 | Strength: 128 bits | Prerequisite for HMAC Message Digest |
| Algorithm Name | Algorithm Properties | Implementation | Reference | |
|---|---|---|---|---|
| CKG | Key Type: Symmetric | Crypto Library FW v2.00 | NIST SP 800-133r2 Sections 4 5.1 and 6.1 |
| Algorithm Name | Algorithm Properties | Implementation | Reference |
|---|---|---|---|
| N/A | N/A | N/A | N/A |
| Algorithm | Caveat | Use/Function |
|---|---|---|
| N/A | N/A | N/A |
| Algorithm | Use/Function |
|---|---|
| N/A | N/A |
The module supports the following vendor affirmed algorithms. Table 4 - Vendor Affirmed Algorithms
The module does not support non-approved algorithms. Table 5 – Non-Approved, Allowed Algorithms N/A N/A N/A N/A
2.5.4 N ON -A PPROVED , A LLOWED A LGORITHMS WITH N O S ECURITY C LAIMED
The module does not support non-approved algorithms. Table 6 – Non-Approved, Allowed Algorithms with No Security Claimed N/A N/A N/A
The module does not support non-approved algorithms. Table 7 – Non-Approved, Not Allowed Algorithms N/A N/A This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Name | Type | Description | SF Properties | Algorithms / CAVP Cert | ||
|---|---|---|---|---|---|---|
| KAS | KAS-Full | NIST SP 800-56Arev3 per IG D.F Scenario 2 path (2) | NIST SP 800-56Arev3 | Standards: NIST SP | KAS-ECC-SSC: (A3268) | |
| per IG D.F Scenario 2 | 800-56Arev3, NIST | KDA: (A3268) | ||||
| path (2) | SP 800-56Crev2, | |||||
| FIPS 186-4 | ECDSA KeyVer: (A3268) | |||||
| KTS | KTS-Unwrap | Key unwrapping per | Standards: FIPS 197, FIPS 198-1, NIST SP 800-38A | Standards: FIPS 197, | AES-CBC: (A3268) | |
| NIST SP 800-38F Per | FIPS 198-1, NIST SP | |||||
| IG D.G. Used for the entry of the operator’s password. | 800-38A | HMAC-SHA2-256: (A3268) |
| Entropy Sources | Minimum Number of Bits of Entropy | Details | |
|---|---|---|---|
| Kingston Technology Company, Inc. Crypto Library FW v2.00 ESV Validation #E55 | The ESV source outputs 1024 bits with a minimum of 256 bits of entropy | The ESV source outputs | Based on the heuristic |
| 1024 bits with a | lower bound entropy | ||
| minimum of 256 bits of | estimate, the entropy | ||
| entropy | source has a rate of 1-bit per nibble or 25%. This means the entropy input required for the DRBG is 1024*0.25 = 256 bits. |
Table 8 - Security Function Implementations (SFI)
The module utilizes only approved algorithms (refer to Table 3) that are tested and validated under the Cryptographic Module Validation Program (CAVP).
The module includes an internal entropy source for the generation of the DRBG seed. Please refer to Table 9 - Non-Deterministic Random Number Generation Specification
The module generates cryptographic keys using a NIST SP 800-90A conforming DRBG (Cert. #A3268) for the encryption and protection of user data.
The module supports a NIST SP 800-56Ar3 conforming key agreement scheme for the establishment of AES 256 and HMAC-SHA2-256 keys to secure communication to / from the This document may be freely reproduced and distributed, but only in its entirety and without modification.
The module relies upon the standard USB protocol for communication with general purpose computer (GPC) systems. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Physical Port | Logical Interface | Data that Passes over Port/Interface |
|---|---|---|
| USB Port (Rx / Tx) | Data Input | The USB 3.0 port connects the module to the host computer. It is used to receive user data as well as API calls issued by the host via the USB protocol. The input is received by the module on the Rx line. |
| Data Output | The USB 3.0 port connects the module to the host computer. It is used to send user data as well as return codes upon completion of API calls issued by the host via the USB protocol. The input is received by the module on the Tx line. | |
| Control Input | The USB 3.0 port connects the module to the host computer. It is used to receive commands as well as API calls issued by the host via the USB protocol. The input is received by the module on the Rx line. | |
| Status Output | Error codes and other statuses are transmitted from the module to the host computer. | |
| LED | Status Output | Error codes and other statuses are transmitted by the LED: − Active data transfer with host computer: LED blinks at 3Hz − Error state: LED blinks rapidly at 16Hz − Pre-operational Self-test status output: LED blinks at 3Hz if all self- tests completed, LED blinks at 16Hz if failed − Continuous Self-test status output: LED blinks at 16Hz if failed − Periodic Self-test status output: LED blinks at 16Hz if failed |
| USB Port (VCC) | Power | The USB VBUS (+5VDC) powers the module. |
The module incorporates both physical and logical interfaces as described within Table 10. Table 10 - Ports and Interfaces
The module does not support a Trusted Channel. 4. ROLES, SERVICES, AND AUTHENTICATION
The module supports identity-based authentication in the form of a User ID and Password (Memorized Secret) in conformance with NIST SP 800-140E and SP 800-63B (refer to Section 5.1.1).
Per NIST SP 800-63B – Section 5.1.1, passwords must be a minimum of 8 bytes (enforced by the module). The password must contain three of the following four-character types: lowercase letters, uppercase letters, numeric characters and/or special characters. This greatly increases the passwords entropy. Assuming a mix of lowercase letters, uppercase letters, numeric characters, the This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Name | Description | Mechanism | Strength Each Attempt | Strength Per Minute | |||
|---|---|---|---|---|---|---|---|
| ID/Password | CO and User role | ID & Password combination used within a challenge/resp onse mechanism | ID & Password | The upper bound for the probability of having the password guessed at random is: 1 / (10 * 26 * 26 * 955) ~= 1/245 < 1/1,000,000 | The upper bound for the | The probability of the consecutive failed authentication attempts in one minute period is approximately 10/ 245 < 1/100,000 | The probability of the |
| authentication | combination | probability of having the | consecutive failed | ||||
| method. | used within a | password guessed at | authentication attempts in one | ||||
| The password is at | challenge/resp | random is: | minute period is | ||||
| onse | approximately 10/ 245 < | ||||||
| least 8 bytes in | 1 / (10 * 26 * 26 * 955) | ||||||
| mechanism | 1/100,000 | ||||||
| length and includes the numbers, the uppercase letters, the lowercase letters, and the special characters. | ~= 1/245 < 1/1,000,000 |
| Role | Service | Input | Output | |
|---|---|---|---|---|
| Crypto Officer (CO) | Change CO Password | Current CO Password and new CO Password | Current CO Password and | Status Out (success, session |
| new CO Password | invalid, wrong password) LED blinks at 16Hz if fatal error | |||
| Close Partition (Logout) | N/A | Status Out (success, session invalid, partition has been closed) LED blinks at 16Hz if fatal error | ||
| Decrypt | Disk accessing | Read partition data | ||
| Encrypt | Disk accessing | Write partition data | ||
| Initialize | CO Password | Status Out (success, | ||
| and the drive’s partition | configuration invalid) LED | |||
| configuration | blinks at 16Hz if fatal error | |||
| Open Partition (Login) | CO ID & Password, and the selected partition | Status Out (success, session invalid, partition has been opened, wrong password) LED blinks at 16Hz if fatal error, the partition is opened if success | ||
| Setup User Password | Current CO Password and new User Password | Status Out (success, session invalid, wrong password) LED blinks at 16Hz if fatal error |
(10 * 26 * 26 * 955) ~= 1/245, which is less than 1/1,000,000. The module only allows for ten (10) Table 11 – Authentication Methods
Table 12 lists the roles supported by the module with the respective services supported by that Table 12 – Roles, Service Commands, Input and Output This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Role | Service | Input | Output | |
|---|---|---|---|---|
| Setup Recovery Password | Current CO Password and new Recovery Password | Status Out (success, session invalid, wrong password) LED blinks at 16Hz if fatal error | ||
| User | Change User Password | Current User Password and new User Password | Status Out (success, session invalid, wrong password) LED blinks at 16Hz if fatal error | |
| Close Partition (Logout) | N/A | Status Out (success, session invalid, partition has been closed) LED blinks at 16Hz if fatal error | ||
| Decrypt | Disk accessing | Read partition data | ||
| Encrypt | Disk accessing | Write partition data | ||
| Open Partition (Login) | User ID & Password, and the selected partition | Status Out (success, session invalid, partition has been opened, wrong password) LED blinks at 16Hz if fatal error, the partition is opened if success | ||
| Setup User Password (Using Recovery Password) | Recovery Password and new User Password | Status Out (success, session invalid, wrong password, recovery password not created) LED blinks at 16Hz if fatal error | ||
| Unauthenticated | CD Update | API call with CD Image, Signature | Status Out (success, session invalid, signature verification failed) | |
| Perform Self-Tests | Power-on the module | LED blinks at 3Hz if all tests complete LED blinks at 16Hz if failed | ||
| Reset Drive | N/A | Status Out (success, session invalid) Internally zeroize all CSPs except the session keys and generate DEK_CO and configure to the single partition. LED blinks at 16Hz if fatal error | ||
| Show Module Version | N/A | Returns module ID and version information, in addition to the approved mode indicator to API call. | ||
| Show Error Status | N/A | Returns the error log to API call | ||
| Show Status | N/A | Reply the service status, the disk status, or the session establishment status to API call | ||
| Zeroization | N/A | Status Out (success) Internally zeroize all CSPs. LED blinks at 16Hz if fatal error |
The operator must perform that following initialization procedures to access the module for the first time.
| Role | Authentication Method | Authentication Strength | |||
|---|---|---|---|---|---|
| Strength Each Attempt | Strength Per Minute | ||||
| Crypto Officer (CO) | ID & Password | The upper bound for the probability of having the password guessed at random is: 1 / (10 * 26 * 26 * 955) ~= 1/245 < 1/1,000,000 | The upper bound for the | The probability of the consecutive failed authentication attempts in one minute period is approximately 10/ 245 < 1/100,000 | The probability of the |
| combination used | probability of having the | consecutive failed authentication | |||
| within a | password guessed at random is: | attempts in one minute period is | |||
| challenge/response | 1 / (10 * 26 * 26 * 955) ~= 1/245 | approximately 10/ 245 < | |||
| mechanism. The password must be at least 8 characters long and must contain at least one integer, one lower- case letter, and one upper-case letter. | < 1/1,000,000 | 1/100,000 | |||
| User | ID & Password combination used within a challenge/response mechanism. The password must be at least 8 characters long and must contain at least one integer, one lower- case letter, and one upper-case letter. | The upper bound for the probability of having the password guessed at random is: 1 / (10 * 26 * 26 * 955) ~= 1/245 < 1/1,000,000 | The probability of the consecutive failed authentication attempts in one minute period is approximately 10/ 245 < 1/100,000 |
Table 13 – Roles and Authentication This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Service | Description | Approved Security Functions | Keys & SSPs | Roles | Access Rights to Keys and / or SSPs | Indicator |
|---|---|---|---|---|---|---|
| (All CO/User | Secure | KAS-ECC-SSC & KDA | AES Session Key, | CO and User | Shared Secret (Z): G, E, Z | Return status via the API: |
| Services) | Communication | MAC Session Key | AES Session Key: G, E | 0x0000: success | ||
| Session | MAC Session Key: G, E Device ECDH Private Key: G, Z Device ECDH Public Key: G, R, Z Host ECDH Public Key: W, Z DRBG Internal State: G, E | 0x4002: session invalid | ||||
| CD Update | Load/Update CD | RSA (PKCS1 v1.5) | CD Update Public | Unauthenticated | CD Update Public Key: E | Return status via the API: |
| Image to the CD-ROM | Signature | Key | 0x0000: success | |||
| partition | Verification | 0x4002: session invalid 0x4006: signature verification failed | ||||
| Change CO | Create new CO | DRBG, PBKDF, SHA2- | KEK_CO, | CO | KEK_CO: G, E, Z | Return status via the API: |
| Password | password | 256 | CO Password, | CO Password: E, Z | 0x0000: success | |
| CO Password Hash | CO Password Hash: Z, G | 0x8102: configuration | ||||
| DRBG Internal State | DRBG Internal State: G, E | invalid |
SSP access rights are defined as follows:
| Service | Description | Approved Security Functions | Keys & SSPs | Roles | Access Rights to Keys and / or SSPs | Indicator |
|---|---|---|---|---|---|---|
| Change User | Create new User | DRBG, PBKDF, SHA2- | KEK_U | User | KEK_U: G, E, Z | Return status via the API: |
| Password | Password | 256 | User Password, | User Password: E, Z | 0x0000: success | |
| User Password Hash, | User Password Hash: Z, G | 0x8102: configuration | ||||
| DRBG Internal State | DRBG Internal State: G, E | invalid | ||||
| Close Partition (Logout) | Logout. Locks drive | N/A | DEK_CO or DEK_U | CO | DEK_CO: Z | Return status via the API: |
| AES Session Key: Z | 0x0000: success | |||||
| MAC Session Key: Z | 0x1602: session invalid | |||||
| User | DEK_U: Z AES Session Key: Z MAC Session Key: Z | 0x1604: partition has been closed | ||||
| Decrypt | Read partition data | AES-XTS | DEK_CO or DEK_U | CO | DEK_CO: E | Return status via the API: |
| User | DEK_U: E | 0x0000: success | ||||
| Encrypt | Write partition data | AES-XTS | DEK_CO or DEK_U | CO | DEK_CO: E | Return status via the API: |
| User | DEK_U: E | 0x0000: success | ||||
| Initialize | Create CO password | DRBG, PBKDF, SHA2- | DEK_CO, | CO | DEK_CO: Z, G | Return status via the API: |
| and generate DEK | 256, AES-KW | KEK_CO, | KEK_CO: G, E, Z | 0x0000: success | ||
| CO Password, | CO Password: W, E, Z | 0x8102: configuration | ||||
| CO Password Hash, | CO Password Hash: G | invalid | ||||
| Entropy Input, | Entropy Input: G, E | |||||
| DRBG Nonce, | DRBG Nonce: G, E | |||||
| DRBG Internal State | DRBG Internal State: G, E | |||||
| Open Partition | Authenticates either | PBKDF, SHA2-256, | CO Password | CO | CO Password: W, E, Z | Return status via the API: |
| (Login) | the CO or User to the | AES-KW | KEK_CO & DEK_CO | KEK_CO: G, E, Z | 0x0000: success | |
| module | DEK_CO: E | |||||
| or | 0x1402: session invalid | |||||
| User Password, | User | User Password: W, E, Z | 0x1404: partition has been | |||
| KEK_U & DEK_U | KEK_U: G, E, Z | opened | ||||
| DEK_U: E | 0x1406: wrong password | |||||
| Perform Self- | Perform Pre- | N/A | N/A | Unauthenticated | DRBG Internal State: G, E | LED Flashing |
| Tests | Operational and Conditional Self-Tests |
This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Service | Description | Approved Security Functions | Keys & SSPs | Roles | Access Rights to Keys and / or SSPs | Indicator |
|---|---|---|---|---|---|---|
| Reset Drive | Erase all files stored | N/A | DEK_CO, DEK_U, | Unauthenticated | DEK_CO: Z | Return status via the API: |
| on the module and | CO Password Hash, | DEK_U: Z | 0x0000: success | |||
| zeroizes all CSPs | User Password Hash, | CO Password Hash: Z | 0x8101: session invalid | |||
| Recovery Password | User Password Hash: Z | |||||
| Hash, DRBG Internal | Recovery Password Hash: Z | |||||
| State | DRBG Internal State: Z | |||||
| Setup User | Create new User | DRBG, PBKDF, SHA2- | DEK_U, KEK_U, | CO | DEK_U: G, Z | Return status via the API: |
| Password | password | 256 | User Password, User | KEK_U: G, E, Z | 0x0000: success | |
| Password Hash, | User Password: W, E, Z | 0x8102: configuration | ||||
| DRBG Internal State | User Password Hash: G DRBG Internal State: G, E | invalid | ||||
| Setup User | Create new User | DRBG, PBKDF, SHA2- | KEK_R, KEK_U | User | KEK_U: G, E, Z | Return status via the API: |
| Password | Password | 256 | Recovery Password, | KEK_R: G, E, Z | 0x0000: success | |
| (Using Recovery | Recovery Password | Recovery Password: E, Z | 0x8102: configuration | |||
| Password) | Hash, | Recovery Password Hash: Z | invalid | |||
| User Password, | User Password: W, E, Z | |||||
| User Password Hash, | User Password Hash: G | |||||
| DRBG Internal State | DRBG Internal State: G, E | |||||
| Setup Recovery | Create Recovery | DRBG, PBKDF, SHA2- | KEK_R, | CO | KEK_R: G, E, Z | Return status via the API: |
| Password | password | 256 | Recovery Password, | Recovery Password: W, E, Z | 0x0000: success | |
| Recovery Password | Recovery Password Hash: G | 0x8102: configuration | ||||
| Hash, DRBG Internal State | DRBG Internal State: G, E | invalid | ||||
| Show Module | Get module ID and | N/A | N/A | Unauthenticated | N/A | Return status via the API: |
| Version | version | 0x0000: success | ||||
| Show Error | Returns the most | N/A | N/A | Unauthenticated | N/A | Return status via the API: |
| Status | recent error details | 0x0000: success | ||||
| Show Status | Get the module’s status | N/A | N/A | Unauthenticated | N/A | Return status via the API: 0x0000: success |
This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Service | Description | Approved Security Functions | Keys & SSPs | Roles | Access Rights to Keys and / or SSPs | Indicator |
|---|---|---|---|---|---|---|
| Zeroization | Zeroize all keys and | N/A | N/A | Unauthenticated | DEK_CO: Z | Return status via the API: |
| CSPs | DEK_U: Z CO Password Hash: Z User Password Hash: Z Recovery Password Hash: Z DRBG Internal State: Z AES Session Key: Z MAC Session Key: Z | 0x0000: success |
This document may be freely reproduced and distributed, but only in its entirety and without modification.
The module does not support any non-approved services.
The module’s firmware is non-modifiable. It does not have the ability to support the external software / firmware loading.
The module supports the following authenticated roles: • Crypto Officer (CO) • User It enforces the separation of roles using identity-based authentication. The operator must perform that following initialization procedures to access the module for the first time.
The module incorporates an RSA 2048 PKCS1 v1.5 (Cert. #A3268) digital signature mechanism over its firmware. The digital signature provides integrity as well as authentication. All commands sent to and from the cryptographic module are protected with HMAC-SHA2-256.
The module loads the firmware image from non-volatile memory to on-chip RAM when powering on the module where it then performs the firmware integrity test using the module’s RSA-2048 ‘Firmware Integrity Public Key’. If the test fails, the module enters an error state, the data output interface is inhibited, and the module’s LED (status output) blinks at 16Hz. The firmware integrity test is a part of Pre-Operational Self-Tests. It is automatically executed at power-on or during the Periodic Self-Tests. It can also be invoked by power-cycling the module. 6. OPERATIONAL ENVIRONMENT
The operational environment is classified as non-modifiable. 7. PHYSICAL SECURITY The module is a multiple-chip standalone module and conforms to FIPS 140-3 Security Level 3 physical security requirements. The module is housed within a strong, non-removable, tamperevident enclosure. The enclosure is opaque within the visible spectrum. In addition, all components are protected with a hard epoxy coating that protects each component from being viewed or probed. Attempts at removing the epoxy will render the module inoperable.
The operator of the module should inspect the outer casing of the module each time prior to connecting the module to a computer. If tamper evidence is observed on the outer casing, the module should not be used. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Physical Security Mechanism | Recommended Frequency of Inspection / Test | Inspection/Test Guidance Details | ||
|---|---|---|---|---|
| Tamper Evidence | Each time the module is used | Upon each use of the module the operator should examine the module for evidence of tamper. |
| Low Temperature | High Temperature | |
|---|---|---|
| Normal Operation | 0°C | 60°C |
| Storage | -20°C | 85°C |
| Distribution | -20°C | 85°C |
| Environment | Temperature / Voltage Measurement | EFP / EFT | Shutdown, Zeroization, Undefined Failure, Known Error Sate or Continues to Operate Normally3 |
|---|---|---|---|
| Low Temperature | -100C | EFT | Continues to Operate Normally |
| High Temperature | +122C | EFT | Undefined Failure |
| Low Voltage | 3.2V | EFT | Shutdown |
| High Voltage | 10.1V | EFT | Undefined Failure |
| Hardness Tested Temperature Measurement | |
|---|---|
| Low Temperature | -20°C |
| High Temperature | 85°C |
Table 15 - Physical Security Inspection Guidelines The module supports the operation, storage and distribution temperatures listed in Table 16. Table 16
The module supports and has been tested at the operation, storage and distribution temperatures listed in Table 16. The module’s epoxy and outer enclosure hardness are assured within these ranges. Table 18 – Hardness Testing Temperature Ranges This document may be freely reproduced and distributed, but only in its entirety and without modification.
The module is designed to encrypt and store arbitrary data with XTS-AES within eMMC memory components. The module physically and logically protects static keys and CSPs. Please refer to Table 19 for additional information.
The module inputs CSPs encrypted with AES CBC and authenticated with HMAC-SHA2-256. The module does not output CSPs. PSPs are output in order to authenticate the module to the connected GPC. Please refer to Table 19 for additional information.
During normal operation, the module explicitly erases copies of CSPs in volatile memory (e.g., RAM) by overwriting with zeros after their use. For CSPs stored in non-volatile memory the module initiates its erase operation to zeroize. The following methods are used to zeroize the module’s CSPs during normal operation. − ‘Zeroization’ and ‘Reset Drive’ service: This service overwrites all CSPs with zeroes and returns the module to its factory default state. − After ten failed CO authentication attempts the respective CO and User DEKs are erased. − After ten failed User authentication attempts the respective User DEK is erased. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Key/CSP Name | Strength | Security Function & Cert. Number | Generation | Import / Export | Establishment | Storage | Zeroization | Use & related SSPs | ||
|---|---|---|---|---|---|---|---|---|---|---|
| DEK_CO (Data Encryption Key - CO) | 256 bits | AES-XTS (Cert. #A3268) | AES-XTS | Generated (via SP 800- 90A DRBG) | Entry: N/A Output: N/A | Entry: N/A | N/A | eMMC - Encrypted with KEK_CO | Zeroization of | Data Encryption / Decryption |
| (Cert. #A3268) | Output: N/A | the KEK_CO during ‘Close Partition’ service or disconnecting the drive. ‘Zeroization’ or ‘Reset Drive’ services. | ||||||||
| DEK_U (Data Encryption Key - User) | 256 bits | AES-XTS (Cert. #A3268) | Generated (via SP 800- 90A DRBG) | Entry: N/A Output: N/A | N/A | eMMC - Encrypted with KEK_U | Zeroization of the KEK_U during ‘Close Partition’ service or disconnecting the drive. ‘Zeroization’ or ‘Reset Drive’ services. | Data Encryption / Decryption | ||
| KEK_CO (Key Encryption Key - CO) | 256 bits | AES-KW (Cert. #A3268) | N/A | Entry: N/A Output: N/A | Derived from Crypto Officer Password | RAM (Plaintext) | Overwritten with zeros immediately after use | Encrypt / Decrypt DEK_CO | ||
| KEK_U (Key Encryption Key - User) | 256 bits | AES-KW (Cert. #A3268) | N/A | Entry: N/A Output: N/A | Derived from User Password | RAM (Plaintext) | Overwritten with zeros immediately after use | Encrypt / Decrypt DEK_U | ||
| KEK_R (Recovery KEK) | 256 bits | AES-KW (Cert. #A3268) | N/A | Entry: N/A Output: N/A | Derived from Recovery Password | RAM (Plaintext) | Overwritten with zeros immediately after use | Encrypt / Decrypt DEK_U |
The module incorporates SSPs as defined with Table 19. Table 19 – SSPs This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Key/CSP Name | Strength | Security Function & Cert. Number | Generation | Import / Export | Establishment | Storage | Zeroization | Use & related SSPs | |
|---|---|---|---|---|---|---|---|---|---|
| Crypto Officer Password | 8 ~ 136 bytes (refer to Section 4.1) | PBKDF (Cert. #A3268) | Created by Crypto Officer | Entry: AES Encrypted entry via host application Output: N/A | N/A | RAM (Plaintext) | Overwritten with zeros immediately after use | Used to generate the KEK_CO | |
| User Password | 8 ~ 136 bytes (refer to Section 4.1) | PBKDF (Cert. #A3268) | Created by User | Entry: AES Encrypted entry via host application Output: N/A | N/A | RAM (Plaintext) | Overwritten with zeros immediately after use | Used to generate the KEK_U | |
| Recovery Password | 8 ~ 136 bytes (refer to Section 4.1) | PBKDF (Cert. #A3268) | Created by Crypto Officer | Entry: AES Encrypted entry via host application Output: N/A | N/A | RAM (Plaintext) | Overwritten with zeros immediately after use | User to generate the KEK_R | |
| Crypto Officer Password Hash | 128-bits | SHA2-256 (Cert. #A3268) | Generated | Entry: N/A Output: N/A | N/A | eMMC Hashed with SHA2-256 | ‘Zeroization’ or | Used for Authentication | |
| from CO | ‘Reset Device’ | ||||||||
| Password | service | ||||||||
| User Password Hash | 128-bits | SHA2-256 (Cert. #A3268) | Generated from User Password | Entry: N/A Output: N/A | N/A | eMMC Hashed with SHA2-256 | ‘Zeroization’ or ‘Reset Device’ service | Used for Authentication | |
| Recovery Password Hash | 128-bits | SHA2-256 (Cert. #A3268) | Generated from Recovery Password | Entry: N/A Output: N/A | N/A | eMMC Hashed with SHA2-256 | ‘Zeroization’ or ‘Reset Device’ service | Used for Authentication | |
| Entropy Input | 1024 bits (Security strength is 256 bits) | Entropy Source (Cert. #E55) | Internally from SP 800-90B Entropy Source | Entry: N/A Output: N/A | N/A | RAM (Plaintext) | Overwritten with zeros immediately after use | Used as entropy input to the SP 800-90A DRBG | |
| DRBG Nonce | 512 bits (Security strength is 128 bits) | HMAC DRBG (Cert. #A3268) | Internally from SP 800-90B Entropy Source | Entry: N/A Output: N/A | N/A | RAM (plaintext) | Overwritten with zeros immediately after use | Used as nonce input to the SP 800-90A DRBG | |
| DRBG Internal State (V and Key) | N/A | HMAC DRBG (Cert. #A3268) | Internally from SP 800-90A DRBG | Entry: N/A Output: N/A | N/A | RAM (plaintext) | ‘Zeroization’ or ‘Reset Device’ service | The internal state of the SP 800-90A DRBG |
This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Key/CSP Name | Strength | Security Function & Cert. Number | Generation | Import / Export | Establishment | Storage | Zeroization | Use & related SSPs | ||
|---|---|---|---|---|---|---|---|---|---|---|
| Device ECDH Private Key | 256 bits | ECDSA Key Gen (Cert. #A3268) | ECDSA Key Gen | Internally | Entry: N/A Output: N/A | Entry: N/A | N/A | RAM (plaintext) | Overwritten | Used by the module |
| (Security | (Cert. #A3268) | from | Output: N/A | with zeros | for key agreement | |||||
| strength is | SP 800-90A | immediately | (KAS-ECC-SSC per | |||||||
| 256 bits) | DRBG | after use | SP 800-56Ar3) | |||||||
| Shared Secret (Z) | 256 bits (Security strength is 128 bits) | KDA (Cert. #A3268) | N/A | Entry: N/A Output: N/A | Shared Secret from KAS-ECC- SSC C(2e, 0s) ECC CDH | RAM (plaintext) | Overwritten with zeros immediately after use | Used to derive the Session Key Material | ||
| AES Session Key | 256 bits (Security strength is 128 bits) | AES-CBC (Cert. #A3268) | N/A | Entry: N/A Output: N/A | Derived by the KDA Two-Step Key Derivation Function | RAM (plaintext) | Overwritten with zeros immediately after secure session is terminated ‘Zeroization’ service | AES Session Key serves to encrypt data during the Secure Session. | ||
| MAC Session Key | 256 bits (Security strength is 128 bits) | HMAC-SHA2-256 (Cert. #A3268) | N/A | Entry: N/A Output: N/A | Derived by the KDK via KDA Two-Step Key Derivation Function | RAM (plaintext) | Overwritten with zeros immediately after secure session is terminated ‘Zeroization’ service | MAC Session Key serves to authenticate data during the Secure Session. | ||
| CD Update Public Key | RSA 2048 (112 bits) | RSA 2048 (Cert. #A3268) | N/A | Entry: Manufacturing Output: N/A | N/A | eMMC | N/A – protected with SHA2-2564 | Validates the CD ROM partition. | ||
| Device ECDH Public Key | P-256 (256 bits) | KAS-ECC-SSC (Cert. #A3268) | Generated internally from DRBG | Entry: N/A Output: Plaintext | N/A | RAM (plaintext) | Overwritten with zeros immediately after used | Used by the module for key agreement (KAS-ECC-SSC per SP 800-56Ar3) | ||
| Host ECDH Public Key | P-256 (256 bits) | KAS-ECC-SSC (Cert. #A3268) | N/A | Entry: Plaintext Output: N/A | N/A | RAM (plaintext) | Overwritten | Used by the module | ||
| with zeros | for key agreement | |||||||||
| immediately | (KAS-ECC-SSC per SP | |||||||||
| after used | 800-56Ar3) |
4 Per IG 9.6.A
This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Algorithm or Test | Test Properties | Test Method | Type | Indicator | Details | ||||
|---|---|---|---|---|---|---|---|---|---|
| Firmware Integrity Test | Firmware | RSA 2048 PKCS1 v1.5 Digital Signature Verification | RSA 2048 PKCS1 v1.5 Digital | RSA 2048 Digital Signature Verification | RSA 2048 Digital | SW / FW Integrity | SW / FW | Success: LED | Performed during module power-on, on-demand, and on a periodic basis |
| Integrity Test | Signature Verification | Signature Verification | Integrity | blinks at 3Hz Error: LED blinks at 16Hz |
| Algorithm or Test | Test Properties | Test Method | Type | Indicator | Details | Conditions for Performing Test |
|---|---|---|---|---|---|---|
| AES CBC | 256-bit | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Encrypt KAT Decrypt KAT | Power-on & Periodically (11 mins) |
| AES ECB | 256-bit | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Encrypt KAT Decrypt KAT | Power-on & Periodically (11 mins) |
| AES KW | 256-bit | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Key Wrap KAT Key Unwrap KAT | Power-on & Periodically (11 mins) |
| AES XTS | 256-bit | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Encrypt KAT Decrypt KAT | Power-on & Periodically (11 mins) |
| AES-XTS Key Gen (Ref: IG C.I) | XTS Key Validity | -- | -- | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Key1≠ Key2 | Generation of DEK_CO or DEK_U |
The module performs pre-operational self-tests and conditional self-tests (refer to Section 10.2). Both self-tests ensure that the module is not corrupted, and the cryptographic algorithms work as expected. During self-tests, data output (via the data output interface) is inhibited. The module services are not available until the self-tests have completed successfully. Table 20 – Pre-Operational Self-Tests For the above error case, the device can be powered cycle to reinitiate the power-up self-tests. Please note: An RSA signature verification known-answer test (KAT) is performed prior to the
Table 21 – Conditional Self-Tests This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Algorithm or Test | Test Properties | Test Method | Type | Indicator | Details | Conditions for Performing Test |
|---|---|---|---|---|---|---|
| DRBG | Instantiate, Generate and Reseed5 | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Instantiate KAT Generate KAT | Power-on & Periodically (11 mins) |
| ECC CDH P- 256 | ECC CDH P- 256 keypair pairwise consistency test. | PCT | PCT | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Performed immediately after key generation during key agreement | ECC CDH keypair generation during key agreement when ‘Open Partition’ service is called. |
| ECC CDH P- 256 | ECC CDH P- 256 Public Key Validation | PKV | PKV | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Full Public Key Validation of host public key | Part of key agreement when ‘Open Partition’ service is called. |
| Entropy Source | N/A | APT/RCT | APT | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Adaptive Proportion Test | Continuous |
| HMAC- SHA2-256 | 256-bit | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | HMAC KAT | Power-on & Periodically (11 mins) |
| KAS-ECC- SSC | Private | KAT | CAST | Success: LED blinks | Compares output with expected result | Power-on & Periodically (11 mins) |
| Key:256-bit | at 3Hz | |||||
| Public Key: | Error: LED blinks at | |||||
| 256-bit | 16Hz | |||||
| KDA | Shared Secret: 256-bit | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Compares output with expected result | Power-on & Periodically (11 mins) |
| PBKDF | Salt 256-bit, Password: 8- bytes | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Compares output with expected result | Power-on & Periodically (11 mins) |
| SHA2-256 | N/A | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | SHA2-256 KAT | Power-on & Periodically (11 mins) |
| RSA-2048 | RSA 2048 & SHA2-256 | KAT | CAST | Success: LED blinks at 3Hz Error: LED blinks at 16Hz | Signature Verification KAT | Power-on & Periodically (11 mins) |
The module performs all self-tests automatically (with no operator intervention) every 11 minutes after being powered-on.
This document may be freely reproduced and distributed, but only in its entirety and without modification.
| State Name | Description | Conditions | Recovery Mode | Indicator |
|---|---|---|---|---|
| Hard Error | Hard Error State | Transitions to this state | Power-Cycle | LED Blink Pattern, |
| for all self-test errors | Error Code. | |||
| Soft Error | Soft Error State | Transitions to this state | Automatic | LED Blink Pattern, |
| for all non-critical errors | Error Code. |
The module supports the following error states: Table 22 – Error States The module transitions into an error state when an error condition is encountered and provides an unambiguous error status indicator (i.e., blinking LED and error code). All data output is inhibited while the module is in the error state.
The operator can initiate the self-tests at any time by power-cycling the module or via the ‘Perform Self-Tests’ command. 11. LIFE-CYCLE ASSURANCE
The User must configure and enforce the following initialization procedures:
Upon receipt of the module an operator must follow the initialization procedure outlined in Section 11.1. This establishes the operator as the Cryptographic Officer (CO) with a valid ID and password. The module is designed to securely store authorized user’s data files using physical and logical security methods. A user may transfer files to the device via a compatible PC or similar device. Over the life of the device an operator may: − Initialize the device as a single operator (CO only). − Initialize the device for multiple operators (CO and User). − Transfer files to the device for secure storage. − Reset the device effectively erasing all data and security parameters. Services available to the CO role are listed in Table 12.
The cryptographic officer must establish access for additional operators. Additional operators will be assigned to the User role. An operator under the User role shall authenticate and transfer files to the device via a compatible PC or similar device. Services available to the User role are listed in Table 12.
In the approved mode of operation, the module shall adhere to the following rules:
Upon the need to decommission the module, the CO should perform a ‘Reset Drive’ operation to securely overwrite all security parameters which makes all stored data unrecoverable. The module can then be repurposed or physically scrapped. 12. MITIGATION OF OTHER ATTACKS This module is not designed to mitigate other attacks beyond the scope of FIPS 140-3 requirements. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Reference Number | Reference Title | Publishing Entity | Publication Date |
|---|---|---|---|
| 1 | ISO/IEC 19790 – Security requirements for cryptographic modules | ISO/IEC | 2015 |
| 2 | ISO/IEC 24759 – Test requirements for cryptographic modules | ISO | 2015 |
| 3 | FIPS 140-3 – Security requirements for cryptographic equipment | NIST | 2019 |
| 4 | SP 800-140 – FIPS 140-3 Derived Test Requirements (DTR) | NIST | 2020 |
| 5 | SP 800-140A – CMVP Documentation Requirements | NIST | 2020 |
| 6 | SP 800-140B – CMVP Security Policy Requirements | NIST | 2022 |
| 7 | SP 800-140C – CMVP Approved Security Functions | NIST | 2023 |
| 8 | SP 800-140D – CMVP Approved Sensitive Security Parameter Generation and Establishment Methods | NIST | 2023 |
| 9 | SP 800-140E – CMVP Approved Authentication Mechanisms | NIST | 2020 |
| 10 | SP 800-140F – CMVP Approved Non-Invasive Attack Mitigation Test Metrics | NIST | 2020 |
13. APPENDIX A: REFERENCES Table 23 – References This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Term | Definition |
|---|---|
| ANSI | American National Standards Institute |
| CMVP | Cryptographic Module Validation Program |
| CSEC | Communications Security Establishment of Canada |
| CSP | Critical Security Parameter |
| DRBG | Deterministic Random Bit Generator |
| DTR | Derived Test Requirements |
| ECB | Electronic Codebook |
| FIPS | Federal Information Processing Standards |
| GPC | General Purpose Computer |
| GUI | Graphical User Interface |
| HMAC | Hashed Message Authentication Code |
| KAT | Known Answer Test |
| NIST | National Institute of Standards and Technology |
| NVRAM | Non-Volatile Random Access Memory |
| PBKDF | Password-Based Key Derivation Function |
| RNG | Random Number Generator |
| RSA | Rivest Shamir Adelman |
| SHA | Secure Hash Algorithm |
| USB | Universal Serial Bus |
14. APPENDIX B: ABBREVIATIONS AND DEFINITIONS Table 24 – Abbreviations and Definitions This document may be freely reproduced and distributed, but only in its entirety and without modification.