All modules
CMVP Validated Module · FIPS 140-3 Security Policy

CryptoComply 140-3 FIPS Provider

Certificate#5040StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorSafeLogic Inc.
Low review priority  ·  no TCB surface named  ·  last validated 12 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date8/26/2029
CaveatNo assurance of the minimum strength of generated SSPs (e.g., keys) and random strings. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorSafeLogic Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for CryptoComply 140-3 FIPS Provider
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for CryptoComply 140-3 FIPS Provider
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

SafeLogic Inc. CryptoComply 140-3 FIPS Provider Software Versions 3.0.0-FIPS 140-3, 3.0.1-FIPS 140-3 Document Version 1.3 July 3, 2025 SafeLogic Inc.

530 Lytton Ave, Suite 200

Palo Alto, CA 94301 www.safelogic.com

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)9
Table 3: Tested Operational Environments - Software, Firmware, Hybrid11
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid12
Table 5: Modes List and Description13
Table 6: Approved Algorithms26
Table 7: Vendor-Affirmed Algorithms27
Table 8: Non-Approved, Allowed Algorithms27
Table 9: Security Function Implementations35
Table 10: Ports and Interfaces41
Table 11: Roles42
Table 12: Approved Services56
Table 13: Storage Areas61
Table 14: SSP Input-Output Methods62
Table 15: SSP Zeroization Methods62
Table 16: SSP Table 170
Table 17: SSP Table 277
Table 18: Pre-Operational Self-Tests79
Table 19: Conditional Self-Tests94
Table 20: Pre-Operational Periodic Information95
Table 21: Conditional Periodic Information111
Table 22: Error States112
Figure 1: Block Diagram8
Page 5
1 General
1.1 Overview

This document provides a non-proprietary FIPS 140-3 Security Policy for CryptoComply 140-3 FIPS Provider. SafeLogic Inc.'s CryptoComply 140-3 FIPS Provider is designed to provide FIPS 140-3 validated cryptographic functionality and is available for licensing. For more information, visit www.safelogic.com/cryptocomply.

1.1.1 About FIPS 140

Federal Information Processing Standards Publication 140-3, Security Requirements for Cryptographic Modules, (FIPS 140-3) specifies the latest requirements for cryptographic modules utilized to protect sensitive but unclassified information. The National Institute of Standards and Technology (NIST) and Canadian Centre for Cyber Security (CCCS) collaborate to run the Cryptographic Module Validation Program (CMVP), which assesses conformance to FIPS 140. NIST (through NVLAP) accredits independent testing labs to perform FIPS 140 testing. The CMVP reviews and validates modules tested against FIPS

140 criteria. Validated is the term given to a module that has successfully gone through this FIPS 140

validation process. Validated modules receive a validation certificate that is posted on the CMVP’s website. More information is available on the CMVP website at: https://csrc.nist.gov/projects/cryptographic-module-validation-program.

1.1.2 About this Document

This non-proprietary cryptographic module Security Policy for CryptoComply 140-3 FIPS Provider from SafeLogic Inc. (SafeLogic) provides an overview of the product and a high-level description of how it meets the security requirements of FIPS 140-3. This document includes details on the module’s cryptographic capabilities, services, sensitive security parameters, and self-tests. This Security Policy also includes guidance on operating the module while maintaining compliance with FIPS 140-3. CryptoComply 140-3 FIPS Provider may also be referred to as the “module” in this document.

1.1.3 External Resources

The SafeLogic website (www.safelogic.com) contains information on SafeLogic services and products. The CMVP website maintains all FIPS 140 certificates for SafeLogic’s FIPS 140 validations. These certificates also include SafeLogic contact information.

Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1.4 Notices

This document may be freely reproduced and distributed, but only in its entirety and without modification.

1.2 Security Levels

The following table lists the module’s level of validation for each area in FIPS 140-3. Table 1: Security Levels

Page 7
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: CryptoComply 140-3 FIPS Provider is a standards-based “Drop-in Compliance™” cryptographic module. The module delivers core cryptographic functions to applications such as servers, personal computers, mobile devices, and appliances. The module features robust algorithm support, including CNSA algorithms. The module delivers cryptographic services to host applications through a C language Application Programming Interface (API). Module Type: Software Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: The module's cryptographic boundary is delimited by the module’s components, as well as the instantiation of the cryptographic module saved in memory and executed by the processor. The executable files that constitute the cryptographic module are listed in Security Policy Section 2.2 Tested and Vendor Affirmed Module Version and Identification. Additionally, the module’s integrity value is included inside the boundary. Refer to the block diagram in Figure 1 for additional detail. Tested Operational Environment’s Physical Perimeter (TOEPP): As a software cryptographic module, the module operates within the Tested Operational Environment’s Physical Perimeter (TOEPP). The TOEPP consists of the Operating System (OS) and the physical perimeter of the General Purpose Computer (GPC). This TOEPP comprises the Operational Environment (OE) that the module operates in, the module itself, and all other applications that operate within the OE, including the host application for the module. Refer to the block diagram in Figure 1 for additional detail.

Page 8

Figure 1: Block Diagram The module’s block diagram depicts the cryptographic boundary, TOEPP, and the components of each. Additionally, it depicts the data flow between these components. The module’s logical interfaces are defined by its API. These interfaces are used by the host application to interact with the module. All input to the module occurs through the data input interface or control input interface. All output from the module occurs through the data output interface or status output interface. Refer also to Security Policy Section 3 - Cryptographic Module Interfaces and Section 9.2 - SSP Input-Output Methods. The module executes within the operating environments specified in Security Policy Section 2.2 - Tested and Vendor Affirmed Module Version and Identification.

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification – Hardware: N/A for this module.

Page 9
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
fips.a3.0.1-FIPS 140-3Compiled as a static library, tested on iOS and iPadOSHMAC-SHA-256
fips.dll3.0.0-FIPS 140-3Compiled for WindowsHMAC-SHA-256
fips.dylib3.0.0-FIPS 140-3Compiled for MacOSHMAC-SHA-256
fips.so3.0.0-FIPS 140-3Compiled for Linux, Unix, AndroidHMAC-SHA-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
AlmaLinux 9Dell PowerEdge R830Intel Xeon E5-Yes3.0.0-FIPS
4667v4140-3
AlmaLinux 9Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
Android 13Google Pixel 7Google Tensor G2No3.0.0-FIPS 140-3
Debian 11Dell PowerEdge R830Intel Xeon E5- 4667v4Yes3.0.0-FIPS 140-3

Tested Module Identification

Page 10
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Debian 11Dell PowerEdgeIntel Xeon E5-No3.0.0-FIPS
R8304667v4140-3
FreeBSD 13Dell PowerEdge R830Intel Xeon E5- 4667v4Yes3.0.0-FIPS 140-3
FreeBSD 13Dell PowerEdgeIntel Xeon E5-No3.0.0-FIPS
R8304667v4140-3
iOS 16iPhone 13 MiniApple A15 BionicNo3.0.1-FIPS 140-3
iPadOS 16iPad Air (2022)Apple M1No3.0.1-FIPS 140-3
macOS 13 (Ventura)Mac Mini M2Apple M2No3.0.0-FIPS 140-3
Oracle Solaris 11.4Dell PowerEdgeIntel Xeon E5-Yes3.0.0-FIPS
R8304667v4140-3
Oracle Solaris 11.4Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
Red Hat Enterprise Linux 9Dell PowerEdgeIntel Xeon E5-Yes3.0.0-FIPS
R8304667v4140-3
Red Hat Enterprise Linux 9Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
Rocky Linux 9Dell PowerEdgeIntel Xeon E5-Yes3.0.0-FIPS
R8304667v4140-3
Rocky Linux 9Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
SUSE Linux EnterpriseDell PowerEdgeIntel Xeon E5-Yes3.0.0-FIPS
Server 15R8304667v4140-3
SUSE Linux Enterprise Server 15Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
Ubuntu 22.04Dell PowerEdgeIntel Xeon E5-Yes3.0.0-FIPS
R8304667v4140-3
Page 11
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Ubuntu 22.04Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
Windows 10Dell PowerEdgeIntel Xeon E5-Yes3.0.0-FIPS
R8304667v4140-3
Windows 10Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
Windows 11Dell PowerEdgeIntel Xeon E5-Yes3.0.0-FIPS
R8304667v4140-3
Windows 11Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
Windows Server 2019Dell PowerEdgeIntel Xeon E5-Yes3.0.0-FIPS
R8304667v4140-3
Windows Server 2019Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
Windows Server 2022Dell PowerEdgeIntel Xeon E5-Yes3.0.0-FIPS
R8304667v4140-3
Windows Server 2022Dell PowerEdge R830Intel Xeon E5- 4667v4No3.0.0-FIPS 140-3
Operating SystemHardware Platform
AlmaLinux 9Any general-purpose platform that supports this OS
Android 13Any general-purpose platform that supports this OS
Debian 11Any general-purpose platform that supports this OS
FreeBSD 13Any general-purpose platform that supports this OS
iOS 16Any general-purpose platform that supports this OS

Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: The module, when compiled from the same unmodified source code, is vendor affirmed to be FIPS 140-3 compliant when compiled as a static library for the tested operating environments listed above for which the module was tested as a shared object or dynamically loaded library.

Page 12
Operating SystemHardware Platform
iPadOS 16Any general-purpose platform that supports this OS
macOS 13 (Ventura)Any general-purpose platform that supports this OS
Oracle Solaris 11.4Any general-purpose platform that supports this OS
Red Hat Enterprise Linux 9Any general-purpose platform that supports this OS
Rocky Linux 9Any general-purpose platform that supports this OS
SUSE Linux Enterprise Server 15Any general-purpose platform that supports this OS
Ubuntu 22.04Any general-purpose platform that supports this OS
Windows 10Any general-purpose platform that supports this OS
Windows 11Any general-purpose platform that supports this OS
Windows Server 2019Any general-purpose platform that supports this OS
Windows Server 2022Any general-purpose platform that supports this OS

Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid Porting guidance is defined in the FIPS 140-3 CMVP Management Manual Section 7.9. FIPS 140-3 validation compliance can be maintained when the following requirements are met:

2.3 Excluded Components
2.4 Modes of Operation

Modes List and Description:

Page 13
Mode NameDescriptionTypeStatus Indicator
Approved ModeApprovedSingle approved mode of operation. No non- approved mode is implemented in the module.ApprovedIn alignment with IG 2.4.C example scenario 2, the module
Modeonly provides approved services. The module provides a global indicator that services are approved. Additionally, the module provides a status code indicating the completion of each service, as indicated in Security Policy Section 4.3 - Approved Services. The successful completion of a service is an implicit indicator for the use of an approved service.
AlgorithmCAVP CertPropertiesReference
AES-CBCA4593Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5173Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A4593Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A

Table 5: Modes List and Description Mode Change Instructions and Status: No instructions are needed to invoke the Approved mode in the module. The module only supports this mode of operation and will operate in this mode once the module is powered on. To confirm that the module is operating in Approved mode, the operator should: • Obtain the global indicator by calling EVP_default_properties_is_fips_enabled() and confirming that this returns as true.

2.5 Algorithms
2.5.1 Approved Algorithms

Approved Algorithms: The module implements the following approved algorithms that have been tested by the Cryptographic Algorithm Validation Program (CAVP).

Page 14
AlgorithmCAVP CertPropertiesReference
AES-CBC-CS1A5173Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A4593Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A5173Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A4593Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A5173Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4593Key Length - 128, 192, 256SP 800-38C
AES-CCMA5173Key Length - 128, 192, 256SP 800-38C
AES-CFB1A4593Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB1A5173Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A4593Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A5173Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4593Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A5173Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA4593Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CMACA5173Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA4593Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
Page 15
AlgorithmCAVP CertPropertiesReference
AES-CTRA5173Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4593Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5173Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4593Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5173Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GMACA4593Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GMACA5173Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-KWA4593Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWA5173Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA4593Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA5173Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA4593Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
Page 16
AlgorithmCAVP CertPropertiesReference
AES-OFBA5173Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS TestingA4593Direction - Decrypt, EncryptSP 800-38E
Revision 2.0Key Length - 128, 256
AES-XTS Testing Revision 2.0A5173Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA4593Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5173Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
DSA KeyGenA4593L - 2048FIPS 186-4
(FIPS186-4)N - 224, 256
DSA KeyGen (FIPS186-4)A5173L - 2048 N - 224, 256FIPS 186-4
DSA PQGGen (FIPS186-4)A4593L - 2048 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
DSA PQGGen (FIPS186-4)A5173L - 2048 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
DSA PQGVer (FIPS186-4)A4593L - 1024, 2048 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256FIPS 186-4
DSA PQGVer (FIPS186-4)A5173L - 1024, 2048 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256FIPS 186-4
DSA SigVer (FIPS186-4)A4593L - 1024, 2048, 3072 N - 160, 224, 256FIPS 186-4
Page 17
AlgorithmCAVP CertPropertiesReference
Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-
512, SHA2-512/224, SHA2-512/256
DSA SigVer (FIPS186-4)A5173L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA KeyGen (FIPS186-4)A4593Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A5173Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVerA4593Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-FIPS 186-4
(FIPS186-4)409, K-571, P-192, P-224, P-256, P-384, P-521
ECDSA KeyVer (FIPS186-4)A5173Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K- 409, K-571, P-192, P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4593Component - No Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigGen (FIPS186-4)A5173Component - No Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4593Component - No Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K- 409, K-571, P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
Page 18
AlgorithmCAVP CertPropertiesReference
ECDSA SigVer (FIPS186-4)A5173Component - No Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K- 409, K-571, P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
EDDSA KeyGenA4593Curve - ED-25519, ED-448FIPS 186-5
EDDSA KeyGenA5173Curve - ED-25519, ED-448FIPS 186-5
EDDSA KeyVerA4593Curve - ED-25519, ED-448FIPS 186-5
EDDSA KeyVerA5173Curve - ED-25519, ED-448FIPS 186-5
EDDSA SigGenA4593Curve - ED-25519, ED-448 PreHash - YesFIPS 186-5
EDDSA SigGenA5173Curve - ED-25519, ED-448 PreHash - YesFIPS 186-5
EDDSA SigVerA4593Curve - ED-25519, ED-448 PreHash - No Pure - YesFIPS 186-5
EDDSA SigVerA5173Curve - ED-25519, ED-448 PreHash - No Pure - YesFIPS 186-5
Hash DRBGA4593Prediction Resistance - YesSP 800-90A
Mode - SHA-1, SHA2-256, SHA2-512Rev. 1
Hash DRBGA5173Prediction Resistance - Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA4593Prediction Resistance - YesSP 800-90A
Mode - SHA-1, SHA2-256, SHA2-512Rev. 1
HMAC DRBGA5173Prediction Resistance - Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC-SHA-1A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA-1A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
Page 19
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 224A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3- 224A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3- 224A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3- 256A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
Page 20
AlgorithmCAVP CertPropertiesReference
HMAC-SHA3- 256A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3- 384A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3- 384A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3- 512A4593Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3- 512A5173Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4593Domain Parameter Generation Methods - B-233, B-283, B-409, B- 571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-ECC-SSC Sp800-56Ar3A5173Domain Parameter Generation Methods - B-233, B-283, B-409, B- 571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A4593Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A5173Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-IFC-SSCA4593Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1- prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme -SP 800-56A Rev. 3
Page 21
AlgorithmCAVP CertPropertiesReference
KAS1 -
KAS Role - initiator, responder
KAS2 -
KAS Role - initiator, responder
KAS-IFC-SSCA5173Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1- prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF SP800-56Cr2A4593Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512SP 800-56C Rev. 2
KDA HKDF SP800-56Cr2A5173Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512SP 800-56C Rev. 2
KDA OneStep SP800-56Cr2A4593Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDA OneStep SP800-56Cr2A5173Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDA TwoStep SP800-56Cr2A4593MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDA TwoStep SP800-56Cr2A5173MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048SP 800-56C Rev. 2
Page 22
AlgorithmCAVP CertProperties Shared Secret Length - Shared Secret Length: 224-8192 Increment 8Reference
KDF ANS 9.42 (CVL)A4593KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.42 (CVL)A5173KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63A4593Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135
(CVL)Key Data Length - Key Data Length: 128, 4096Rev. 1
KDF ANS 9.63 (CVL)A5173Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Key Data Length - Key Data Length: 128, 4096SP 800-135 Rev. 1
KDF KMACA4593Derived Key Length - Derived Key Length: 112-4096 Increment 8SP 800-108
Sp800-108r1Rev. 1
KDF KMAC Sp800-108r1A5173Derived Key Length - Derived Key Length: 112-4096 Increment 8SP 800-108 Rev. 1
KDF SP800-108A4593KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096SP 800-108 Rev. 1
KDF SP800-108A5173KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096SP 800-108 Rev. 1
KDF SSH (CVL)A4593Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512SP 800-135 Rev. 1
KDF SSH (CVL)A5173Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512SP 800-135 Rev. 1
KMAC-128A4593Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
Page 23
AlgorithmCAVP CertPropertiesReference
KMAC-128A5173Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KMAC-256A4593Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KMAC-256A5173Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KTS-IFCA4593Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1- prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024SP 800-56B Rev. 2
KTS-IFCA5173Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1- prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024SP 800-56B Rev. 2
PBKDFA4593Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8SP 800-132
PBKDFA5173Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8SP 800-132
RSA KeyGen (FIPS186-4)A4593Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA KeyGen (FIPS186-4)A5173Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
Page 24
AlgorithmCAVP CertPropertiesReference
RSA SigGenA4593Signature Type - PKCS 1.5, PKCSPSSFIPS 186-4
(FIPS186-4)Modulo - 2048, 3072, 4096
RSA SigGen (FIPS186-4)A5173Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVerA4593Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSSFIPS 186-4
(FIPS186-4)Modulo - 1024, 2048, 3072, 4096
RSA SigVer (FIPS186-4)A5173Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
Safe Primes Key GenerationA4593Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
Safe Primes Key GenerationA5173Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
Safe Primes Key VerificationA4593Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
Safe Primes Key VerificationA5173Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
SHA-1A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
Page 25
AlgorithmCAVP CertPropertiesReference
SHA2-384A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512/224A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512/256A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA3-224A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-224A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-256A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-384A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-512A4593Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
Page 26
AlgorithmCAVP CertPropertiesReference
SHA3-512A5173Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHAKE-128A4593Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-128A5173Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A4593Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A5173Output Length - Output Length: 16-65536 Increment 8FIPS 202
TDES-CBCA4593Direction - DecryptSP 800-67 Rev. 2
TDES-CBCA5173Direction - DecryptSP 800-67 Rev. 2
TDES-ECBA4593Direction - DecryptSP 800-67 Rev. 2
TDES-ECBA5173Direction - DecryptSP 800-67 Rev. 2
TLS v1.2 KDFA4593Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135
RFC7627 (CVL)Rev. 1
TLS v1.2 KDF RFC7627 (CVL)A5173Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
TLS v1.3 KDFA4593HMAC Algorithm - SHA2-256, SHA2-384SP 800-135
(CVL)KDF Running Modes - DHE, PSK, PSK-DHERev. 1
TLS v1.3 KDF (CVL)A5173HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHESP 800-135 Rev. 1
2.5.2 Vendor-Affirmed Algorithms

Vendor-Affirmed Algorithms: The module implements the following vendor affirmed algorithms that are approved for use in Approved mode.

Page 27
NamePropertiesImplementationReference
CKGKey Type:Symmetric and AsymmetricN/ASP 800-133r2 and IG D.H: Per Section 4, example 1
CKG (XTS)Key Type:SymmetricN/ASP 800-133r2 and IG D.H: Per Section 6.3, approved method 1. Applicable to AES-XTS compliant to IG C.I because Key_1 and Key_2 are concatenated prior to usage.
NamePropertiesImplementationReference
EC Diffie-Hellman with non-NIST recommended curvesEC Diffie-HellmanCurves: brainpoolP224r1 (strength 112CryptoComply 140-3 FIPS ProviderCryptoComplyAllowed per IG D.F, scenario 3 (per IG C.A, category 1a and SP 800-186 Appendix H.1)Allowed per IG D.F,
with non-NISTbits) brainpoolP256r1 (strength 128 bits)140-3 FIPSscenario 3 (per IG
recommendedbrainpoolP320r1 (strength 160 bits)ProviderC.A, category 1a and
curvesbrainpoolP384r1 (strength 192 bits)SP 800-186 Appendix
brainpoolP512r1 (strength 256 bits) : SSP AgreementH.1)
ECDSA with non- NIST recommended curvesCurves: brainpoolP224r1 (strength 112 bits) brainpoolP256r1 (strength 128 bits) brainpoolP320r1 (strength 160 bits) brainpoolP384r1 (strength 192 bits) brainpoolP512r1 (strength 256 bits) : Signature Generation, Signature Verification, Key Generation, Key VerificationCryptoComply 140-3 FIPS ProviderAllowed per IG C.A, category 1a (per SP 800-186 Appendix H.1)

Table 7: Vendor-Affirmed Algorithms The module implements the following algorithms that are allowed for use in Approved mode.

2.5.4 Non-Approved, Allowed Algorithms with No Security Claimed

Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. The module does not implement any non-approved algorithms with no security claimed.

Page 28
NameTypeDescriptionPropertiesAlgorithms
AsymmetricKeyGenAsymKeyPair- DomPar AsymKeyPair- KeyGen AsymKeyPair- KeyVer AsymKeyPair- PubKeyValAsymKeyPair-Used to generate asymmetric keys using the DRBG for CKG per SP 800- 133r2. Established SSPs are passed out to the calling application.Used to generateECDSA Allowed Curves:brainpoolP224r1 (strength 112 bits) brainpoolP256r1 (strength 128 bits) brainpoolP320r1 (strength 160 bits) brainpoolP384r1 (strength 192 bits) brainpoolP512r1 (strength 256 bits)ECDSA AllowedCounter DRBG:
DomParasymmetric keysCurves:brainpoolP224r1(A4593, A5173)
AsymKeyPair-using the DRBG for(strength 112 bits)Hash DRBG:
KeyGenCKG per SP 800-brainpoolP256r1(A4593, A5173)
AsymKeyPair-133r2. Established(strength 128 bits)HMAC DRBG:
KeyVerSSPs are passedbrainpoolP320r1(A4593, A5173)
AsymKeyPair-out to the calling(strength 160 bits)CKG, asymmetric
PubKeyValapplication.brainpoolP384r1keys: ()
(strength 192 bits)DSA KeyGen
brainpoolP512r1(FIPS186-4):
(strength 256 bits)(A4593, A5173) DSA PQGGen (FIPS186-4): (A4593, A5173) DSA PQGVer (FIPS186-4): (A4593, A5173) EDDSA KeyGen: (A4593, A5173) EDDSA KeyVer: (A4593, A5173) RSA KeyGen (FIPS186-4): (A4593, A5173) Safe Primes Key Generation: (A4593, A5173) Safe Primes Key Verification: (A4593, A5173) ECDSA KeyGen (FIPS186-4): (A4593, A5173)

N/A for this module. The module does not implement any non-approved, not allowed algorithms.

2.6 Security Function Implementations

Security function implementations (SFIs) are defined by the table below. The module is a software library, therefore the SFIs map directly to the module’s services. Refer also to Security Policy Section 4.3 - Approved Services for a description of the module’s services and SSP access.

Page 29
NameTypeDescriptionPropertiesAlgorithms Approved Curves: B-233, B-283, B- 409, B-571, K-233, K-283, K-409, K- 571, P-224, P-256, P-384, P-521 ECDSA KeyVer (FIPS186-4): (A4593, A5173) Approved Curves: B-163, B-233, B- 283, B-409, B-571, K-163, K-233, K- 283, K-409, K-571, P-192, P-224, P- 256, P-384, P-521
AuthSymmetric Encrypt/DecryptBC-AuthUsed to encrypt or decrypt data. SSPs are passed in by the calling application.AES-CCM: (A4593, A5173) AES-GCM: (A4593, A5173)
CKGCKGDirect output of DRBGs may be used for symmetric key generation per SP 800-133r2.Counter DRBG: (A4593, A5173) CKG: () Key Type: Symmetric and Asymmetric Hash DRBG: (A4593, A5173) HMAC DRBG: (A4593, A5173)
CKG (XTS)CKGAES-XTS key concatenationCKG: () Key Type: Symmetric
DigitalSigDigSig-SigGen DigSig-SigVerUsed to generate or verify digital signatures. SSPs are passed in by the calling application.ECDSA AllowedEDDSA SigGen:
Curves:brainpoolP224r1(A4593, A5173)
(strength 112 bits)EDDSA SigVer:
brainpoolP256r1(A4593, A5173)
(strength 128 bits)RSA SigGen
brainpoolP320r1(FIPS186-4):
(strength 160 bits)(A4593, A5173)
Page 30
NameTypeDescriptionPropertiesAlgorithms
brainpoolP384r1 (strength 192 bits) brainpoolP512r1 (strength 256 bits)brainpoolP384r1RSA SigVer
(strength 192 bits)(FIPS186-4):
brainpoolP512r1(A4593, A5173)
(strength 256 bits)ECDSA SigGen (FIPS186-4): (A4593, A5173) Approved Curves: B-233, B-283, B- 409, B-571, K-233, K-283, K-409, K- 571, P-224, P-256, P-384, P-521 ECDSA SigVer (FIPS186-4): (A4593, A5173) Approved Curves: B-163, B-233, B- 283, B-409, B-571, K-163, K-233, K- 283, K-409, K-571, P-192, P-224, P- 256, P-384, P-521
DigitalSig (Legacy)AsymKeyPair- DomPar AsymKeyPair- KeyVer DigSig-SigVerUsed to verify digital signatures. SSPs are passed in by the calling application.DSA PQGVer (FIPS186-4): (A4593, A5173) ECDSA KeyVer (FIPS186-4): (A4593, A5173) DSA SigVer (FIPS186-4): (A4593, A5173) ECDSA SigVer (FIPS186-4): (A4593, A5173) RSA SigVer (FIPS186-4): (A4593, A5173)
IntegrityTestMACIntegrity TestHMAC-SHA2-256: (A4593, A5173)
KeyAgreement (ECC)KAS-SSCUsed to perform key agreement primitives onIG:IG D.F Scenario 2, path 1 Key Confirmation:NoKAS-ECC-SSC Sp800-56Ar3: (A4593, A5173)
Page 31
NameTypeDescriptionPropertiesAlgorithms
behalf of the calling application (does not establish keys into the module). SSPs are passed in by the calling application. Established SSPs are passed out to the calling application.Key Derivation:No Caveat:Key establishment methodology provides between 112 and 256 bits of security strengthApproved Curves: B-233, B-283, B- 409, B-571, K-233, K-283, K-409, K- 571, P-224, P-256, P-384, P-521 Allowed Curves: EC Diffie-Hellman with non-NIST recommended curves
KeyAgreement (FFC)KAS-SSCUsed to perform key agreement primitives on behalf of the calling application (does not establish keys into the module). SSPs are passed in by the calling application. Established SSPs are passed out to the calling application.IG:IG D.F Scenario 2, path 1 Key Confirmation:No Key Derivation:No Caveat:Key establishment methodology provides between 112 and 200 bits of security strengthKAS-FFC-SSC Sp800-56Ar3: (A4593, A5173)
KeyAgreement (RSA)KAS-SSCUsed to perform key agreement primitives on behalf of the calling application (does not establish keys into the module). SSPs are passed in by the calling application. Established SSPs are passed out to the calling application.IG:IG D.F Scenario 1, path 1 Key Confirmation:No Key Derivation:No Caveat:Key establishment methodology provides between 112 and 200 bits of security strengthKAS-IFC-SSC: (A4593, A5173)
KeyDerivationKAS-135KDF KAS-56CKDFUsed to deriveKDA HKDF SP800-
keys using KBKDF,56Cr2: (A4593,
PBKDF, HKDF, SPA5173)
Page 32
NameTypeDescriptionPropertiesAlgorithms
KBKDF PBKDFKBKDF800-56Cr2 One- Step KDF (KDA), SP 800-56Cr2 Two- Step KDF (KDA), ANSI X9.42-2001 KDF, ANSI X9.63- 2001 KDF, SSHv2 KDF, TLS 1.2 KDF, TLS 1.3 KDF (does not establish keys into the module). SSPs are passed in by the calling application. Established SSPs are passed out to the calling application.800-56Cr2 One-KDA OneStep
PBKDFStep KDF (KDA), SPSP800-56Cr2:
800-56Cr2 Two-(A4593, A5173)
Step KDF (KDA),KDA TwoStep
ANSI X9.42-2001SP800-56Cr2:
KDF, ANSI X9.63-(A4593, A5173)
2001 KDF, SSHv2KDF ANS 9.42:
KDF, TLS 1.2 KDF,(A4593, A5173)
TLS 1.3 KDF (doesKDF ANS 9.63:
not establish keys(A4593, A5173)
into the module).KDF KMAC Sp800-
SSPs are passed in108r1: (A4593,
by the callingA5173)
application.KDF SP800-108:
Established SSPs(A4593, A5173)
are passed out toKDF SSH: (A4593,
the callingA5173)
application.PBKDF: (A4593, A5173) TLS v1.2 KDF RFC7627: (A4593, A5173) TLS v1.3 KDF: (A4593, A5173)
KeyedHashMAC XOFUsed to generate or verify data integrity. SSPs are passed in by the calling application.HMAC-SHA-1: (A4593, A5173) HMAC-SHA2-224: (A4593, A5173) HMAC-SHA2-256: (A4593, A5173) HMAC-SHA2-384: (A4593, A5173) HMAC-SHA2-512: (A4593, A5173) HMAC-SHA2- 512/224: (A4593, A5173) HMAC-SHA2- 512/256: (A4593, A5173) HMAC-SHA3-224: (A4593, A5173) HMAC-SHA3-256:
Page 33
NameTypeDescriptionPropertiesAlgorithms
(A4593, A5173) HMAC-SHA3-384: (A4593, A5173) HMAC-SHA3-512: (A4593, A5173) KMAC-128: (A4593, A5173) KMAC-256: (A4593, A5173)
KeyTransportBC-AuthDecrypt BC-AuthEncryptUsed to encrypt or decrypt a key value on behalf of the calling application (does not establish keys into the module). SSPs are passed in by the calling application. Established SSPs are passed out to the calling application.Standard:SP 800-56Br2 Key Confirmation:No Caveat:Key establishment methodology provides between 112 and 256 bits of security strength IG D.G:Approved key encapsulationKTS-IFC: (A4593, A5173)
KeyWrappingKTS-Unwrap KTS-WrapUsed to encrypt or decrypt a key value on behalf of the calling application (does not establish keys into the module). SSPs are passed in by the calling application. Established SSPs are passed out to the calling application.Standard:SP 800-38F IG D.G:Approved key wrapping Key Confirmation:No Caveat:Key establishment methodology provides between 128 and 256 bits of encryption strengthAES-KW: (A4593, A5173) AES-KWP: (A4593, A5173)
MessageDigestSHAUsed to generate a SHA-1, SHA-2, SHA- 3, or SHAKE message digest.SHA-1: (A4593, A5173) SHA2-224: (A4593, A5173) SHA2-256: (A4593, A5173) SHA2-384: (A4593,
Page 34
NameTypeDescriptionPropertiesAlgorithms A5173) SHA2-512: (A4593, A5173) SHA2-512/224: (A4593, A5173) SHA2-512/256: (A4593, A5173) SHA3-224: (A4593, A5173) SHA3-256: (A4593, A5173) SHA3-384: (A4593, A5173) SHA3-512: (A4593, A5173) SHAKE-128: (A4593, A5173) SHAKE-256: (A4593, A5173)
RNGDRBGRandom Number Generation from the DRBG. Random data or established SSPs are passed out to the calling application.Counter DRBG: (A4593, A5173) Hash DRBG: (A4593, A5173) HMAC DRBG: (A4593, A5173) CKG: () Key Type: Symmetric and Asymmetric
Symmetric Decrypt (Legacy)BC-UnAuthSymmetric decryption SSPs are passed in by the calling application.TDES-CBC: (A4593, A5173) TDES-ECB: (A4593, A5173)
Symmetric Encrypt/DecryptBC-UnAuthSymmetric encryption or decryption SSPs are passed in by the calling application.AES-CBC: (A4593, A5173) AES-CBC-CS1: (A4593, A5173) AES-CBC-CS2: (A4593, A5173) AES-CBC-CS3: (A4593, A5173)
Page 35
NameTypeDescriptionPropertiesAlgorithms
AES-CFB1: (A4593, A5173) AES-CFB8: (A4593, A5173) AES-CFB128: (A4593, A5173) AES-CTR: (A4593, A5173) AES-ECB: (A4593, A5173) AES-OFB: (A4593, A5173) AES-XTS Testing Revision 2.0: (A4593, A5173)
SymmetricDigestMACUsed to generate or verify data integrity with CMAC or GMAC. SSPs are passed in by the calling application.AES-CMAC: (A4593, A5173) AES-GMAC: (A4593, A5173)

Table 9: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES-GCM (IG C.H conformance)

The module is compatible with TLS 1.2 and supports AES-GCM IV construction in alignment with IG C.H scenario

  1. The module does not implement the TLS 1.2 protocol itself. However, the module provides the cryptographic functions required for implementing the TLS 1.2 protocol, including for AES-GCM cipher suites specified in Section 3.3.1 of SP 800-52r2. AES GCM encryption is used in the context of the TLS 1.2 protocol and the mechanism for IV generation is compliant with RFC 5288. The counter portion of the AES GCM IV is set by the module within its cryptographic boundary. The counter portion of the IV is strictly increasing. When the IV exhausts the maximum number of possible values for a given session key, encryption will fail. A handshake to establish a new encryption key is required. It is the responsibility of the user of the module (i.e., the first party to encounter this condition, either the client or the server) to trigger this handshake in accordance with RFC 5246. The module supports internal IV generation by the module’s approved DRBGs, in alignment with IG C.H scenario
  2. The IV is at least 96 bits in length per NIST SP 800-38D, Section 8.2.2.
Page 36

The module is compatible with TLS 1.3 and supports AES-GCM IV construction in alignment with IG C.H scenario 5. The module does not implement the TLS 1.3 protocol itself. However, the module provides the cryptographic functions required for implementing the TLS 1.3 protocol. AES GCM encryption is used in the context of the TLS 1.3 protocol. When used in the context of TLS 1.3, the GCM IV is constructed in accordance with RFC 8446.

2.7.2 AES-XTS

Per SP 800-38E, AES-XTS should only be used for storage applications.

2.7.3 DSA

DSA KeyGen (FIPS186-4) and DSA PQGGen (FIPS 186-4) are only implemented for use as a part of an approved SP 800-56Ar3 FFC scheme. In accordance with this, only the FIPS 186-type parameter sets FB (2048, 224) and FC (2048, 256) from SP 800-56Arev3 are supported by the module. For DSA signatures, only DSA PQGVer (FIPS186-4) and DSA SigVer (FIPS186-4) are only implemented. Refer to Security Policy Section 9.5 - Transitions for additional context.

2.7.4 Edwards Curves

Per FIPS 186-5, Edwards curves are only used for digital signatures using EdDSA. Per FIPS 186-5, only SHA-512 is supported with curve Edwards25519 and only SHAKE256 is supported with curve Edwards448.

2.7.5 PBKDF (IG D.N Conformance)

The PBKDF aligns with Option 1a in Section 5.4 of SP 800-132. Keys derived from passwords using the PBKDF may only be used in storage applications. The PBKDF function can be called using the Key Derivation service, but it does not establish keys into the module. The PBKDF function supports passwords from 8 to 128 bytes and iteration counts from 1 to 10,000. SP 800-132 Section 5.2 recommends a minimum iteration count of 1,000. Operators should select an appropriate password length and iteration count for their use case, bearing in mind that both should be as large as is feasible for the application.

2.7.6 RSA

RSA SigVer (FIPS186-4) ANSI X9.31 functionality is only implemented for legacy support. Refer to Security Policy Section 9.5 - Transitions for additional context. The module supports even RSA modulus sizes that are not testable by the CAVP in the following ranges:

Page 37

• For RSA KAS and RAS KTS per SP 800-56Br2: 2048-16384 All conformance requirements from IG C.F have been met. All implemented modulus sizes for which CAVP testing is available have been validated under CAVP certificates A4593 and A5173. The minimum number of Miller-Rabin tests used in primality testing is conformant with both FIPS 186-4 and FIPS 1865.

2.7.7 RSA KTS (IG D.G conformance)

For the RSA KTS (KTS-IFC) algorithm, the module supports the KTS-OAEP-basic scheme. As indicated in Security Policy Section 2.7.6, the module supports even RSA modulus sizes that are not testable by the CAVP. The module supports moduli 2048-16384 for RSA KTS. This is conformant to IG C.F. Refer also to Security Policy Section 2.7.10 - SP 800-140Br1 SSP Establishment for more information on the SSP establishment by the module.

2.7.8 TLS 1.2 KDF (IG D.Q conformance)

As indicated under CAVP certificates A4593 and A5173, the module supports TLS 1.2 KDF per RFC 7627, i.e. using the extended master secret.

2.7.9 Triple-DES

TDES-CBC and TDES-ECB Decryption functionality is only implemented for legacy support. Refer to Security Policy Section 9.5 - Transitions for additional context.

2.7.10 SP 800-140Br1 SSP Establishment

As a cryptographic software library, SSPs used for services are passed in by the calling application. Established SSPs are passed out to the calling application and are not stored in the module. Accordingly, the following statements are required for conformance. For additional details, see also Security Policy Section 2.10 - Key Establishment. The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS. The module does not establish SSPs using an approved key transport scheme (KTS). However, it does offer approved authenticated algorithms that can be used by an external operator/application as part of an approved KTS.

Page 38
2.8 RBG and Entropy

Entropy Certificates: N/A for this module. Entropy Sources: N/A for this module. The module does not include an entropy source. The module aligns with IG 9.3.A, scenario 2b, therefore the module’s certificate includes the caveat “No assurance of the minimum strength of generated SSPs (e.g., keys).” The module accepts input from entropy sources external to the cryptographic boundary for use as seed material for the module’s approved DRBG implementations. Entropy is supplied to the module by means of callback functions. Those functions return an error if the minimum entropy strength is not met. Entropy strength requirements are per NIST Special Publication 800-90A Rev. 1 Table 2 (Hash_DRBG, HMAC_DRBG) and Table 3 (CTR_DRBG). At a minimum, the entropy source shall provide at least 128 bits of entropy to the DRBG. All random values used by the module for approved algorithms are provided by the module’s approved DRBGs. The module includes Counter DRBG, Hash DRBG, and HMAC DRBG, all of which are approved RBGs. The output of these approved RBGs is used to generate random data, symmetric keys, and asymmetric keys, as indicated in Security Policy Section 2.5.2 - Vendor-Affirmed Algorithms.

2.9 Key Generation

Any generated SSPs are passed out to the calling application and are not stored in the module. Additional detail is provided in Security Policy Section 2.6 - Security Function Implementations and Section 4.3 - Approved Services. Random values for key generation are provided by the module’s approved DRBGs. The output of the module’s approved DRBGs may be used to generate symmetric and asymmetric keys per SP 800-133r2, as indicated in Security Policy Section 2.5.2 - Vendor-Affirmed Algorithms. The module is a software library that provides a service (called Random Number Generation) for direct output of the approved DRBG (U). This output is approved for generating keys or SSPs. Symmetric keys are generated per SP 800-133r2 Section 6.1 using the Random Number Generation service; additionally, Section 6.3 is applicable for AES-XTS keys. Asymmetric keys are generated per SP

Page 39

800-133r2 Section 5 per FIPS 186-4 and per FIPS 186-5 (for EdDSA only) using the Asymmetric Key Generation service.

2.10 Key Establishment

SSPs used for services are passed in by the calling application. Established SSPs are passed out to the calling application and are not stored in the module. Additional detail is provided in Security Policy Section 2.6 - Security Function Implementations and Section 4.3 - Approved Services. The module provides ECC and FFC shared secret computation that is conformant to SP 800-56Ar3 in alignment with IG D.F scenario 2 (path 1) via the Key Agreement (ECC/FFC) service. For ECC, the module supports the (Cofactor) Ephemeral Unified Model, C(2e, 0s, ECC CDH) Scheme described in SP 800-56Ar3 Section 6.1.2.2. For FFC, the module supports the dhEphem, C(2e, 0s, FFC DH) Scheme described in SP 800-56Ar3 Section 6.1.2.1. The module also provides ECC key agreement using the allowed curves specified in Security Policy Section 2.5.3 - Non-Approved, Allowed Algorithms in alignment with IG D.F scenario 3 via the Key Agreement (ECC/FFC) service. The appropriate public key validation assurances are implemented. For ECC, full public key validation is implemented (SP 800-56Ar3 Section 5.6.2.3.3). For FFC, both full public key validation (per SP 800-56Ar3 Section 5.6.2.3.1) and partial public key validation (per SP 800-56Ar3 Section 5.6.2.3.2) are implemented. The module provides RSA shared secret computation that is conformant to SP 800-56Br2 in alignment with IG D.F scenario 1 (path 1) via the Key Agreement (RSA) service. The module supports the KAS1 basic and KAS2 basic schemes. The module supports various key derivation functions separately via the Key Derivation service. Supported KDFs are conformant to SP 800-108r1 (KBKDF), SP 800-132 (PBKDF), SP 800-56Cr2 (HKDF, KDA OneStep KDA, TwoStep KDA), SP 800-135r1 (ANSI 9.42 KDF, ANSI 9.63 KDF, SSH KDF, TLS 1.2 KDF), and RFC 8446 (TLS 1.3 KDF). The module provides RSA key encapsulation that is conformant to SP 800-56Br2 via the Key Transport service. The module provides AES key wrapping (AES KW, AES KWP) that is conformant to SP 800-38F via the Key Wrapping service. Refer also to Security Policy Section 2.7.10 - SP 800-140Br1 SSP Establishment for more information on the SSP establishment by the module.

2.11 Industry Protocols

The module implements KDFs from SP 800-135r1 (Recommendation for Existing Application-Specific Key Derivation Functions) and the TLS 1.3 KDF. These KDFs have been validated by the CAVP and received

Page 40

CVL certificates (A4593, A5173). No parts of these protocols, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP.

Page 41
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters for data
N/AData OutputAPI output parameters for data
N/AControl InputAPI function calls
N/AStatus OutputAPI status outputs (return codes, error messages)
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

As a software cryptographic module, the module supports logical interfaces only and not physical ports. All access to the module is through the module’s API. The API provides and defines the module’s logical interfaces. The API provides functions that may be called by a host application (refer to Security Policy Section 4.3 - Approved Services). Table 10: Ports and Interfaces

3.2 Additional Information

All interfaces are logically separated by the module’s API. The data output path is inhibited during pre-operational self-tests, zeroisation, and when the module is in an error state.

Page 42
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Module Initialisat ionInitializeAPI return value from OSSL_provider_init: 1 for success, 0 for failureExternal dispatch (functio nInternal dispatch (function pointer) tableNoneCrypto OfficerCrypto
the FIPS module when it is loadedOfficer
4 Roles, Services, and Authentication
4.2 Roles

Table 11: Roles Crypto Officer is the only role supported by the module. The module does not support a User role or a Maintenance role. The Crypto Officer role is implicitly selected by calling the module’s services.

4.3 Approved Services

The following table describes the services the module provides and the access to SSPs by each service. Additional details on each service are available in the module’s user guidance documentation. SSP Access is divided into the following access types:

Page 43
NameDescripti on (calls pre- operatio nal self- tests and CASTs).IndicatorInputs pointer) tableOutputsSecurity FunctionsSSP Access
Self-TestPerforms pre- operatio nal self- tests and CASTs on demand.API return value code from SELF_TEST_post(): 1 for success, 0 for failureNoneModule State (queried via Show Status) changes to Running (FIPS_STATE_RUNN ING)NoneCrypto Officer
Integrity TestPerforms the integrity test on demand.API return value from verify_integrity(): 1 for verified, 0 for failureExpecte d HMACModule State (queried via Show Status) changes to Running (FIPS_STATE_RUNN ING)IntegrityTestCrypto Officer
Show StatusProvides status informati on by querying the "status" paramet er.Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for query operation completed successfully, 0 for failure to query the parameterNoneModule Status: Running (FIPS_STATE_RUNN ING), or Error (FIPS_STATE_ERRO R)NoneCrypto Officer
Output ID/ Version Informat ion (Show Version)Displays FIPS module version by querying the "version, " "name," and "buildinfImplied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for query operation completed successfully, 0 for failure to query the parameterNonename: 140-3 FIPS Provider version: 3.0.0-FIPS 140-3 or 3.0.1-FIPS 140-3 buildinfo: 3.0.0-FIPS 140-3 or 3.0.1-FIPS 140-3NoneCrypto Officer
Page 44
NameDescripti on o" paramet ers, with the results specified in the output column. The version aligns with the FIPS certificat e and Security Policy Section 2.2 - Tested and Vendor Affirmed Module Version and Identific ation.IndicatorInputsOutputsSecurity FunctionsSSP Access
Random Number Generati onUsed to seed/res eed a DRBG instance (includin g determin ing the security strength) or obtain randomImplied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureDesired security strength in bits, entropy inputRandom dataRNG CKGCrypto Officer - DRBG Entropy Input: W,E,Z - CTR_DR BG Seed: G,E,Z - CTR_DR
2.2 -
Page 45
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
data. Random data may be used for CKG per SP 800- 133r2. Establish ed SSPs are passed out to the calling applicati on.BG V: G,E,Z - CTR_DR BG Key: G,E,Z - Hash_D RBG Seed: G,E,Z - Hash_D RBG V: G,E,Z - Hash_D RBG C: G,E,Z - HMAC_ DRBG Seed: G,E,Z - HMAC_ DRBG V: G,E,Z - HMAC_ DRBG Key: G,E,Z - Generic Secret: G,R,Z
Symmetr ic Encrypti on/Used toImplied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 forAESCiphertext data or plaintext dataSymmetric Encrypt/Dec rypt CKG (XTS)Crypto
encryptEDK,Officer
orAES XTS- AES
decryptkey, IV,EDK:
data.cipherteW,E,Z
Page 46
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Decrypti onSSPs areoperation completed successfully, 0 for failurext data, plaintex t data- AES XTS key: W,E,Z- AES
passedXTS key:
in by the calling applicati on.W,E,Z
Authenti cated Symmetr ic Encrypti on/ Decrypti onUsed to encrypt or decrypt data or keys. SSPs are passed in by the calling applicati on. Any establish ed SSPs are passed out to the calling applicati on.Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureAES CMAC/C CM key, AES GMAC/ GCM key, cipherte xt data, plaintex t dataCiphertext data or plaintext dataAuthSymme tric Encrypt/Dec ryptCrypto Officer - AES CMAC/C CM key: W,E,Z - AES GMAC/ GCM key: W,E,Z - AES GMAC/ GCM IV: G,E,Z
Symmetr ic DigestUsed to generate or verify data integrity with CMAC or GMAC. SSPs are passed in by the calling applicati on.Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureDigest or message , AES CMAC/C CM key, AES GMAC/ GCM keyDigest or verification resultSymmetricDi gestCrypto Officer - AES CMAC/C CM key: W,E,Z - AES GMAC/ GCM key: W,E,Z - AES GMAC/
Page 47
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access GCM IV: G,E,Z
Asymme tric Key Generati onUsed to generate asymmet ric keys using the DRBG. Establish ed SSPs are passed out to the calling applicati on.Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureDesired security strength in bits, entropy input, predicti on resistan ce, paramet ers and values for FFC, ECC, RSA key generati onECDSA SGK, ECDSA SVK, RSA SGK, RSA SVK, EdDSA SGK, EdDSA SVK, DH Private, DH Public, ECDH Private, ECDH Public, RSA KAK Private, RSA KAK Public, RSA KDK Private, RSA KEK PublicAsymmetric KeyGenCrypto Officer - DRBG Entropy Input: W,E,Z - CTR_DR BG Seed: G,E,Z - CTR_DR BG V: G,E,Z - CTR_DR BG Key: G,E,Z - Hash_D RBG Seed: G,E,Z - Hash_D RBG V: G,E,Z - Hash_D RBG C: G,E,Z - HMAC_ DRBG Seed: G,E,Z - HMAC_ DRBG V:
Page 48
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
G,E,Z - HMAC_ DRBG Key: G,E,Z - ECDSA SGK: G,R,Z - ECDSA SVK: G,R,Z - RSA SGK: G,R,Z - RSA SVK: G,R,Z - EdDSA SGK: G,R,Z - EdDSA SVK: G,R,Z - DH Private: G,R,Z - DH Public: G,R,Z - EC DH Private: G,R,Z - EC DH Public: G,R,Z - RSA KAK Private: G,R,Z - RSA KAK Public:
Page 49
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
G,R,Z - RSA KDK Private: G,R,Z - RSA KEK Public: G,R,Z
Digital Signatur esUsed to generate or verify digital signatur es. SSPs are passed in by the calling applicati on.Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureDSA SVK, ECDSA SGK, ECDSA SVK, RSA SGK, RSA SVK, EdDSA SGK, EdDSA SVKDigital signature or verification resultDigitalSigCrypto Officer - ECDSA SGK: W,E,Z - ECDSA SVK: W,E,Z - RSA SGK: W,E,Z - RSA SVK: W,E,Z - EdDSA SGK: W,E,Z - EdDSA SVK: W,E,Z
Keyed HashUsed to generate or verify data integrity. SSPs are passed in by the calling applicati on.Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureHMAC key, KMAC keyKeyed hash or verification resultKeyedHashCrypto Officer - HMAC Key: W,E,Z - KMAC Key: W,E,Z
Page 50
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Message DigestUsed toImplied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureMessag e dataDigestMessageDig estMessageDigCrypto OfficerCrypto
generate a SHA-1, SHA-2, SHA-3, or SHAKE message digest.estOfficer
Key Agreeme nt (ECC/FFC )Used to perform key agreeme nt primitive s on behalf of the calling applicati on (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureDH Private, DH Public, ECDH Private, ECDH PublicDH Private, DH Public, ECDH Private, ECDH Public, KDF secretKeyAgreeme nt (ECC) KeyAgreeme nt (FFC)Crypto Officer - DH Private: R,W,E,Z - DH Public: R,W,E,Z - EC DH Private: R,W,E,Z - EC DH Public: R,W,E,Z - KDF Secret: G,R,Z
Page 51
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Key Agreeme nt (RSA)Used toImplied if EVP_default_properties_is _fips_enabled() returns true API return value: 1 for operation completed successfully, 0 for failureRSA KAK Private, RSA KAK PublicRSA KAK Private, RSA KAK Public, KDF secretKeyAgreeme nt (RSA)KeyAgreemeCrypto Officer - RSA KAK Private: R,W,E,Z - RSA KAK Public: R,W,E,Z - KDF Secret: G,R,ZCrypto
performnt (RSA)Officer
key- RSA
agreemeKAK
ntPrivate:
primitiveR,W,E,Z
s on- RSA
behalf ofKAK
thePublic:
callingR,W,E,Z
applicati- KDF
on (doesSecret:
not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati onG,R,Z
Key Derivatio nUsed to derive keys using KBKDF, PBKDF, HKDF, SP 800- 56Cr2 One-Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureKDF secret, salt, iteration count, MAC, digest, cipher, keyGeneric SecretKeyDerivatio nCrypto Officer - KDF Secret: W,E,Z - Generic Secret: G,R,Z
Page 52
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Step KDF (KDA), SP 800- 56Cr2 Two- Step KDF (KDA), ANSI X9.42- 2001 KDF, ANSI X9.63- 2001 KDF, SSHv2 KDF, TLS 1.2 KDF, TLS 1.3 KDF (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.
Page 53
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Key Transpor tUsed toImplied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureRSA KEK Public and key to be encapsu lated (Generic Secret), or RSA KDK Private and encapsu lated key (Generic Secret)Encapsulated key (Generic Secret), or unencapsulated key (Generic Secret)KeyTranspor tKeyTransporCrypto Officer - RSA KDK Private: W,E,Z - RSA KEK Public: W,E,Z - Generic Secret: R,W,ZCrypto
encrypttOfficer
or- RSA
decryptKDK
a keyPrivate:
value onW,E,Z
behalf of- RSA
theKEK
callingPublic:
applicatiW,E,Z
on (does-
notGeneric
establishSecret:
keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.R,W,Z
Key Wrappin gUsed to encrypt or decrypt a key value on behalf of the calling applicati on (doesImplied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureAES key wrappin g key, key to be wrappe d or unwrap pedWrapped key or unwrapped key (Generic Secret)KeyWrappin gCrypto Officer - AES key wrappin g key: W,E,Z - Generic
Page 54
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.(Generic Secret)Secret: R,W,Z
ZeroiseAllImplied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureMemory to be cleanse d (pointer and length)The completion of a zeroisation routine indicates that the zeroisation procedure succeeded. Zeroisation can be confirmed via EVP_RAND_verify_z eroization: 1 for success (i.e. the DRBG CSPs have been zeroised), 0 for failure.NoneCrypto
servicesOfficer
automati- DRBG
callyEntropy
overwritInput: Z
e SSPs-
stored inCTR_DR
allocatedBG
memorySeed: Z
(zeroise).-
TheCTR_DR
moduleBG V: Z
does not-
store anyCTR_DR
SSPBG Key:
persistenZ
tly-
(beyondHash_D
theRBG
lifetimeSeed: Z
of an API-
call),Hash_D
Page 55
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
exceptRBG V: Z - Hash_D RBG C: Z - HMAC_ DRBG Seed: Z - HMAC_ DRBG V: Z - HMAC_ DRBG Key: ZRBG V: Z
for DRBG-
stateHash_D
valuesRBG C: Z
(stored-
for theHMAC_
lifetimeDRBG
of theSeed: Z
DRBG-
instance)HMAC_
. StackDRBG V:
cleanupZ
is the-
responsiHMAC_
bility ofDRBG
the calling applicati on.Key: Z
UtilityMiscella neous helper function s.Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failureNoneNoneNoneCrypto Officer
Symmetr ic Decrypti on (Legacy)Used to decrypt data. SSPs are passed in by the calling applicati on.Implied if EVP_default_properties_is _fips_enabled() returns true API return value: 1 for operation completed successfully, 0 for failureTDES DK, cipherte xt dataPlaintext dataSymmetric Decrypt (Legacy)Crypto Officer - TDES DK: W,E,Z
Digital Signatur es (Legacy)Used to verify digital signatur es. SSPs are passedImplied if EVP_default_properties_is _fips_enabled() returns true API return value: 1 for operation completed successfully, 0 for failureDSA SVK, ECDSA SVK (Legacy) , RSAVerification resultDigitalSig (Legacy)Crypto Officer - DSA SVK: W,E,Z - ECDSA SVK
Page 56
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
in by the calling applicati on.SVK (Legacy)(Legacy) : W,E,Z - RSA SVK (Legacy) : W,E,Z
4.4 Non-Approved Services

N/A for this module. The module does not implement any non-approved, not allowed algorithms; therefore, it also does not provide any non-approved services.

4.5 External Software/Firmware Loaded

Not applicable for this module.

Page 57
5 Software/Firmware Security
5.1 Integrity Techniques

As specified in the executable code sets table in Security Policy Section 2.2 - Tested and Vendor Affirmed Module Version and Identification, the module implements integrity techniques for all executable code sets. The integrity technique used by the module is HMAC-SHA-256. The integrity technique has received CAVP certificates A4593 and A5173. The integrity technique is implemented by the module itself. The integrity authentication key for the integrity technique is an HMAC-SHA-256 key with a key length of

256 bits. It is integrated into the module during compilation and cannot be changed afterwards. The

module is only provided to the end user in the form of a compiled binary (refer to Security Policy Section 11.1). Note, per ISO 19790:2012 Section 7.5, this key is not considered a SSP. The installation process generates the HMAC digest for the module using this key and the module. For dynamic libraries, the HMAC digest is generated from the module file and is then stored in the module's configuration file. For static and iOS libraries, the HMAC digest is generated from the memory the module is loaded at and is then stored in the executable the module is linked into. To verify the module's integrity (for the pre-operational self-test or on demand), the module generates a new HMAC digest and compares it with the corresponding stored value. The test passes if the values match.

5.2 Initiate on Demand

The Integrity Test can be performed on demand via the “Integrity Test” service.

Page 58
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: Supported operational environments are indicated in Security Policy Section 2.2 - Tested and Vendor Affirmed Module Version and Identification. Refer also to that section for vendor affirmed operating environment porting guidance. The operating environments ensure that every application using the module operates in its own private and isolated environment (memory, I/O, etc.) and that user processes are segregated into separate process spaces. The module does not spawn any processes.

6.2 Configuration Settings and Restrictions

The module must be installed, and the correct installation confirmed, as described in Security Policy Section 11.1 - Installation, Initialization, and Startup Procedures. No specific configuration options are required for the operational environments. No security rules, settings, or restrictions to the configuration of the operational environment are needed for the module to function in an approved manner. It is advised to restrict write access to the module and its related configuration file to the administrator role in the operational environment.

Page 59
7 Physical Security

The requirements of this section are not applicable to the module. The module is a software module and does not implement any physical security mechanisms.

Page 60
8 Non-Invasive Security

The requirements of this section are not applicable to the module.

Page 61
Storage Area NameDescriptionPersistence Type
RAM / DRAMMemory that only holds data during power on of the operating environmentDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API Input via TOEPP pathOther Applications (App per IG 9.5.A)RAM / DRAMPlaintextManualElectronic
Encrypted API Input using Key Transport via TOEPP pathOther Applications (App per IG 9.5.A)RAM / DRAMEncryptedManualElectronicKeyTransport
Encrypted APIOtherRAM / DRAMEncryptedManualElectronicKeyWrapping
Input using KeyApplications
Wrapping via(App per IG
TOEPP path9.5.A)
API Output via TOEPP pathRAM / DRAMOther Applications (App per IG 9.5.A)PlaintextManualElectronic
Encrypted APIRAM / DRAMOtherEncryptedManualElectronicKeyTransport
Output using KeyApplications
Transport via(App per IG
TOEPP path9.5.A)
Encrypted API Output using Key Wrapping via TOEPP pathRAM / DRAMOther Applications (App per IG 9.5.A)EncryptedManualElectronicKeyWrapping
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods
Page 62
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroise serviceCalls OPENSSL_cleanse to zeroise the DRBG CSPsDRBG CSPs are the only SSPs storedFunction provided via APIFunction
by the module beyond the lifetime ofprovided
an API call. The Zeroise service zeroises SSPs by overwriting zeroes to the memory location occupied by the SSP and further deallocating that area.via API
Call a service that creates or uses the SSPServices include appropriate APIs (OPENSSL_free or OPENSSL_cleanse) to automatically zeroise the SSPs created or used by the services. This zeroises the context structures that contains the SSP.SSPs are zeroised by overwriting zeroes to the memory location occupied by the SSP and further deallocating that area.Function provided via API

Table 14: SSP Input-Output Methods The information in the table above aligns with IG 9.5.A. IG 9.5.A indicates that SSPs established by a software cryptographic module to or from a general purpose application that operates outside the module’s boundary but within the TOEPP are classified as Manually Distributed using Electronic Entry. The module does not support any other methods of SSP input or output. Specifically, the module does not support Automated Distribution, Wireless Distribution, or Direct Entry. The module outputs CSPs in plaintext unless a KeyTransport (RSA) or KeyWrapping (AES) Security Function Implementation (refer to Security Policy Section 2.6 - Security Function Implementations) is used to encrypt the output CSP. Table 15: SSP Zeroization Methods As indicated in Security Policy Section 4.3 - Approved Services, the completion of a zeroisation routine indicates that the zeroisation procedure succeeded. Zeroisation can be confirmed via EVP_RAND_verify_zeroization: 1 for success (i.e. the DRBG CSPs have been zeroised), 0 for failure. The following two tables define the module’s Sensitive Security Parameters (SSPs). Access to SSPs is defined under Security Policy Section 4.3 - Approved Services.

Page 63
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
Generic SecretSSPs112 - 512 bits - 112 - 256 bits112 - 512Key or other SSP - CSPKey or otherKeyDerivation CKGKeyTranspo rt KeyWrappi ngKeyTranspoKeyTransport KeyWrapping
generatedbits - 112SSP - CSPrt
from the- 256 bitsKeyWrappi
direct DRBG output (CKG) or by key derivation and directly output by the module, or generic keys that are wrapped or transported and directly output by the module. Note: when the encrypted item is not a key or other SSP, it is denoted as "data" instead of as the Generic Secret SSP.ng
AES EDKAES encrypt/ decrypt key128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPSymmetric Encrypt/Decrypt
Page 64
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES CMAC/CCM keyAES128, 192, 256 bits - 128, 192, 256 bits128, 192,Symmetric Key - CSPSymmetricAuthSymmetric Encrypt/Decrypt SymmetricDigest
CMAC/CCM256 bits -Key - CSP
key for128, 192,
encrypt/ decrypt or generate/ verify256 bits
AES GMAC/GC M keyAES GMAC/GC M key for encrypt/ decrypt or generate/ verify128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPAuthSymmetric Encrypt/Decrypt SymmetricDigest
AES GMAC/GC M IVAES GMAC/GC M IV for encrypt/ decrypt or generate/ verify96-1024 bits - 96- 1024 bitsIV - CSPRNGAuthSymmetric Encrypt/Decrypt SymmetricDigest
AES XTS keyAES XTS encrypt/ decrypt key128, 256 bits - 128, 256 bitsSymmetric Key - CSPCKG (XTS)Symmetric Encrypt/Decrypt
AES key wrapping keyAES KW, KWP key128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPKeyWrapping
TDES DK3-key Triple-DES decrypt key192 bits - 112 bitsSymmetric Key - CSPSymmetric Decrypt (Legacy)
DRBG Entropy InputEntropy Input128-1024 bits (length is dependen t on the requested securityRBG - CSPRNG AsymmetricKeyG en
Page 65
NameDescriptionSize - Strength strength, per SP 800-90A Rev. 1 Table 2 and Table 3) - 128- 256 bitsType - CategoryGenerated ByEstablished ByUsed By
CTR_DRBG SeedCTR_DRBG seed, constructed from entropy input and other inputs per SP 800-90A Rev. 1 Sections 7.2, 8.6256-896 bits - 128- 256 bitsRBG - CSPRNG AsymmetricKeyG enRNG AsymmetricKeyG en
CTR_DRBG VV, internal state128 bits - 128 bitsRBG - CSPRNGRNG
AsymmetricKeyGAsymmetricKeyG
enen
CTR_DRBG KeyKey (AES), internal state128, 192, 256 bits - 128, 192, 256 bitsRBG - CSPRNG AsymmetricKeyG enRNG AsymmetricKeyG en
Hash_DRBG SeedHash_DRBG seed, constructed from entropy input and other inputs per SP 800-90A Rev 1 Sections 7.2, 8.6224-736 bits - 128- 256 bitsRBG - CSPRNG AsymmetricKeyG enRNG AsymmetricKeyG en
Page 66
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
Hash_DRBG VV, internal state440, 888 bits - 128, 256 bitsRBG - CSPRNG AsymmetricKeyG enRNG AsymmetricKeyG en
Hash_DRBG CC, internal state440, 888RBG - CSPRNGRNG
bits - 128,AsymmetricKeyGAsymmetricKeyG
256 bitsenen
HMAC_DRB G SeedHMAC_DRB G seed, constructed from entropy input and other inputs per SP 800-90A Rev. 1 Sections 7.2, 8.6224-1408 bits - 128, 256 bitsRBG - CSPRNG AsymmetricKeyG enRNG AsymmetricKeyG en
HMAC_DRB G VV, internal state160, 256, 512 bits - 160, 256, 512 bitsRBG - CSPRNG AsymmetricKeyG enRNG AsymmetricKeyG en
HMAC_DRB G KeyKey (HMAC), internal state160, 256, 512 bits - 160, 256, 512 bitsRBG - CSPRNG AsymmetricKeyG enRNG AsymmetricKeyG en
ECDSA SGKECDSA signature generation key (P, B, K curves and brainpool)224 - 512 bits - 112 - 256 bitsSignature - CSPAsymmetricKeyG enDigitalSig
RSA SGKRSA signature generation key2048 - 16384 bits - 112 - 256 bitsSignature - CSPAsymmetricKeyG enDigitalSig
Page 67
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
EdDSA SGKEd25519 or256, 456 bits - 128, 224 bits256, 456Signature - CSPSignature -AsymmetricKeyG enDigitalSig
Ed448bits - 128,CSP
signature generation key224 bits
DH PrivateDiffie- Hellman private key agreement key (186-4- type and safe primes)For 186-4 type key generatio n: 224, 256 bits. For safe primes key generatio n: ffdhe2048 , ffdhe3072 , ffdhe4096 , ffdhe6144 , ffdhe8192 , MODP- 2048, MODP- 3072, MODP- 4096, MODP- 6144, MODP- 8192 - 112 bits 112-200 bitsKey Agreement - CSPAsymmetricKeyG enKeyAgreement (FFC)
EC DH PrivateElliptic Curve Diffie- Hellman224 - 512 bits - 112 - 256 bitsKey Agreement - CSPAsymmetricKeyG enKeyAgreement (ECC)
Page 68
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
private key
agreement
key (P, B, K
curves and
brainpool)
RSA KAK PrivateRSA private key agreement key2048 - 16384 bits - 112 - 256 bitsKey Agreement - CSPAsymmetricKeyG enKeyAgreement (RSA)
RSA KDK PrivateRSA private2048 -Key Transport - CSPAsymmetricKeyG enKeyTransport
key16384 bits
decryption- 112 -
key256 bits
HMAC KeyKeyed hash key for HMAC160, 224, 256, 384, 512 bits - 128, 192 256 bitsAuthenticati on - CSPKeyedHash
KMAC KeyKeyed hash128-1024Authenticati on - CSPKeyedHash
key forbits - 128,
KMAC256 bits
KDF SecretSecret value used by KDFs112 - 512 bits - 112 - 512 bitsKey Derivation Function - CSPKeyAgreement (ECC) KeyAgreement (FFC) KeyAgreement (RSA)KeyDerivation
DSA SVKDSA signature verification key (legacy only)DSA (L, N) = (512 L < 2048, 160 N < 224) (2048, 224) (2048, 256) (3072, 256) - 80 - 128 bitsSignature - PSPDigitalSig (Legacy)
Page 69
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
ECDSA SVKECDSA signature verification key (P, B, K curves and brainpool)224 - 512 bits - 112 - 256 bitsSignature - PSPAsymmetricKeyG enDigitalSig
RSA SVKRSA2048 -Signature - PSPAsymmetricKeyG enDigitalSig
signature16384 bits
verification- 112 -
key256 bits
EdDSA SVKEd25519 or Ed448 signature verification key256, 456 bits - 128, 224 bitsSignature - PSPAsymmetricKeyG enDigitalSig
DH PublicDiffie- Hellman public key agreement key (186-4- type and safe primes)For 186-4 type key generatio n: 2048 bits. For safe primes key generatio n: ffdhe2048 , ffdhe3072 , ffdhe4096 , ffdhe6144 , ffdhe8192 , MODP- 2048, MODP- 3072, MODP- 4096, MODP-Key Agreement - PSPAsymmetricKeyG enKeyAgreement (FFC)
Page 70
NameDescriptionSize - Strength 6144, MODP- 8192 - 112-200 bitsType - CategoryGenerated ByEstablished ByUsed By
EC DH PublicElliptic Curve Diffie- Hellman public key agreement key (P, B, K curves and brainpool)224 - 512 bits - 112 - 256 bitsKey Agreement - PSPAsymmetricKeyG enKeyAgreement (ECC)
RSA KAK PublicRSA public2048 -Key Agreement - PSPAsymmetricKeyG enKeyAgreement (RSA)
key16384 bits
agreement- 112 -
key256 bits
RSA KEK PublicRSA public key encryption key2048 - 16384 bits - 112 - 256 bitsKey Transport - PSPAsymmetricKeyG enKeyTransport
ECDSA SVK (Legacy)ECDSA signature verification key (P, B, K curves) for legacy curves163 - 192 bits - 80 bitsSignature - PSPDigitalSig (Legacy)
RSA SVK (Legacy)RSA signature verification key for legacy key lengths or legacy SHA- 11024 - 16384 bits - 80 bitsSignature - PSPDigitalSig (Legacy)
Page 71
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Generic SecretAPI Input via TOEPP path Encrypted API Input using Key Transport via TOEPP path Encrypted API Input using Key Wrapping via TOEPP path API Output via TOEPP path Encrypted API Output using Key Transport via TOEPP path Encrypted API Output using Key Wrapping via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPKDF Secret:Derived From RSA KDK Private:May be Wrapped or Unwrapped by RSA KEK Public:May be Wrapped or Unwrapped by AES key wrapping key:May be Wrapped or Unwrapped by
AES EDKAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSP
AES CMAC/CCM keyAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSP
AES GMAC/GCM keyAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration isCall a service that creates or uses the SSPAES GMAC/GCM IV:Used With
Page 72
NameInput - OutputStorageStorage Duration for the lifetime of the API call.ZeroizationRelated SSPs
AES GMAC/GCM IVRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPAES GMAC/GCM key:Used With
AES XTS keyAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSP
AES key wrapping keyAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPGeneric Secret:Wraps or Unwraps
TDES DKAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSP
DRBG Entropy InputAPI Input via TOEPP pathRAM / DRAM:PlaintextAll DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroise serviceCTR_DRBG Seed:Used With CTR_DRBG V:Used With CTR_DRBG Key:Used With Hash_DRBG Seed:Used With Hash_DRBG V:Used With Hash_DRBG C:Used With HMAC_DRBG Seed:Used With HMAC_DRBG V:Used With
Page 73
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
HMAC_DRBG
Key:Used With
CTR_DRBG SeedRAM / DRAM:PlaintextAll DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroise serviceDRBG Entropy Input:Used With CTR_DRBG V:Used With CTR_DRBG Key:Used With
CTR_DRBG VRAM / DRAM:PlaintextAll DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroise serviceDRBG Entropy Input:Used With CTR_DRBG Seed:Used With CTR_DRBG Key:Used With
CTR_DRBG KeyRAM / DRAM:PlaintextAll DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroise serviceDRBG Entropy Input:Used With CTR_DRBG Seed:Used With CTR_DRBG V:Used With
Hash_DRBG SeedRAM / DRAM:PlaintextAll DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroise serviceDRBG Entropy Input:Used With Hash_DRBG V:Used With Hash_DRBG C:Used With
Hash_DRBG VRAM / DRAM:PlaintextAll DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroise serviceDRBG Entropy Input:Used With Hash_DRBG Seed:Used With Hash_DRBG C:Used With
Hash_DRBG CRAM / DRAM:PlaintextAll DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroise serviceDRBG Entropy Input:Used With Hash_DRBG Seed:Used With Hash_DRBG V:Used With
Page 74
Name HMAC_DRBG SeedInput - OutputStorage RAM / DRAM:PlaintextStorage Duration All DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroization Zeroise serviceRelated SSPs DRBG Entropy Input:Used With HMAC_DRBG V:Used With HMAC_DRBG Key:Used With
HMAC_DRBG VRAM / DRAM:PlaintextAll DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroise serviceDRBG Entropy Input:Used With HMAC_DRBG Seed:Used With HMAC_DRBG Key:Used With
HMAC_DRBG KeyRAM / DRAM:PlaintextAll DRBG SSPs are temporarily stored. Storage duration is for the lifetime of the DRBG instance.Zeroise serviceDRBG Entropy Input:Used With HMAC_DRBG Seed:Used With HMAC_DRBG V:Used With
ECDSA SGKAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPECDSA SVK:Paired With
RSA SGKAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPRSA SVK:Paired With
EdDSA SGKAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPEdDSA SVK:Paired With
DH PrivateAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPDH Public:Paired With KDF Secret:Used to establish
Page 75
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
EC DH PrivateAPI Input via TOEPP path API Output via TOEPP pathAPI Input viaRAM / DRAM:PlaintextAll SSPs areCall a service that creates or uses the SSPEC DH Public:Paired With KDF Secret:Used to establish
TOEPP pathtemporarily stored.
API Output viaStorage duration is
TOEPP pathfor the lifetime of the API call.
RSA KAK PrivateAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPRSA KAK Public:Paired With KDF Secret:Used to establish
RSA KDK PrivateAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPRSA KEK Public:Paired With Generic Secret:Unwraps
HMAC KeyAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSP
KMAC KeyAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSP
KDF SecretAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPDH Private:Derived From DH Public:Derived From EC DH Private:Derived From EC DH Public:Derived From RSA KAK Private:Derived From RSA KAK
Page 76
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs Public:Derived From Generic Secret:Used to derive
DSA SVKAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSP
ECDSA SVKAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPECDSA SGK:Paired With
RSA SVKAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPRSA SGK:Paired With
EdDSA SVKAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPEdDSA SGK:Paired With
DH PublicAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPDH Private:Paired With KDF Secret:Used to establish
EC DH PublicAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPEC DH Private:Paired With KDF Secret:Used to establish
RSA KAK PublicAPI Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration isCall a service that createsRSA KAK Private:Paired With
Page 77
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
API Output viafor the lifetime ofor uses theKDF Secret:Used to
TOEPP paththe API call.SSPestablish
RSA KEK PublicAPI Input via TOEPP path API Output via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSPRSA KDK Private:Paired With Generic Secret:Wraps
ECDSA SVK (Legacy)API Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSP
RSA SVK (Legacy)API Input via TOEPP pathRAM / DRAM:PlaintextAll SSPs are temporarily stored. Storage duration is for the lifetime of the API call.Call a service that creates or uses the SSP
9.5 Transitions

All algorithms implemented by the module are approved for FIPS 140-3 and their approval status will not be impacted by the transitions specified below. The information below provides context for the algorithms not supported by the module due to algorithm transitions. Refer also to Security Policy Section 2.7 - Algorithm Specific Information. After December 31, 2023, Triple-DES transitioned to non-approved (refer to SP 800-131Ar2.). After December 31, 2023, the following functionality remains approved for legacy use. Because this functionality remains approved, this is the only Triple-DES functionality supported by the module. • Triple-DES decryption remains approved for legacy use After February 3, 2024, DSA and RSA X9.31 transitioned to non-approved for all new FIPS module submissions (refer to FIPS 186-4 and IG C.K). Although this validation was submitted to the CMVP before February 3, 2024, the module only implements the DSA and RSA X9.31 functionality that remains approved for submissions after this transition:

Page 78
Page 79
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2- 256 (A4593)HMAC-SHA2-HMAC-SHA-Compare toSW/FW IntegrityThe Module State (queried via ShowVerify
256 (A4593)256 (Cert.pre-computedStatus) changes to Running
A4593)HMAC(FIPS_STATE_RUNNING)
HMAC-SHA2- 256 (A5173)HMAC-SHA- 256 (Cert. A5173)Compare to pre-computed HMACSW/FW IntegrityThe Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNING)Verify
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 18: Pre-Operational Self-Tests The module only performs one pre-operational self-test, which is the software/firmware integrity test. The module does not implement any other pre-operational self-tests, including pre-operational selftests for bypass or critical functions, because the module does not implement corresponding functions. The pre-operational self-tests are executed automatically by the Module Initialization service when the module is powered on. Automatic execution of the pre-operational self-tests relies on use of the default entry point (DEP); no operator intervention is required. For the pre-operational self-tests, the module performs an HMAC-SHA-256 CAST, and then verifies the integrity of the runtime executable using a HMAC-SHA-256 digest computed at build time. If the digests match, the CAST tests are then performed. The integrity technique (HMAC-SHA-256) has received CAVP certificates A4593 and A5173. Note, please refer also to the HMAC-SHA-256 CAST, which is performed before the pre-operational

10.2 Conditional Self-Tests

The module mainly performs two types of conditional self-tests, which are Cryptographic Algorithm SelfTests (CASTs) and Pairwise Consistency Tests (PCTs). The module also performs one critical function test for AES-XTS, per IG C.I. The module does not implement any other conditional self-tests, including conditional self-tests for software/firmware loading, manual entry, or bypass, because the module does not implement corresponding functions. The CAST tests below are executed automatically by the Module Initialization service when the module is powered on. Automatic execution of the CASTs relies on use of the default entry point (DEP); no operator intervention is required.

Page 80
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
AES-GCM256-bit AESKATCASTThe Module StateAuthenticate d Encrypt (forward cipher)Initialisation
Authenticate(queried via Show
d EncryptStatus) changes to
KAT (ForwardRunning
Cipher)(FIPS_STATE_RUNNIN
(A4593)G)
AES-GCM Authenticate d Encrypt KAT (Forward Cipher) (A5173)256-bit AESKATCASTThe Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)Authenticate d Encrypt (forward cipher)Initialisation
AES-GCM Decrypt KAT (Forward Cipher) (A4593)256-bit AESKATCASTThe Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)Decrypt (forward cipher)Initialisation
AES-GCM Decrypt KAT (Forward Cipher) (A5173)256-bit AESKATCASTThe Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)Decrypt (forward cipher)Initialisation
AES-ECB Decrypt KAT (Inverse Cipher) (A4593)256-bit AESKATCASTThe Module State changes to RunningDecrypt (inverse cipher)Initialisation

The CASTs execute before the module transitions to the operational state. If the CASTs are successful, All other conditional self-tests are executed when the relevant condition occurs, as specified in the table below. d G) G)

Page 81
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
AES-ECB Decrypt KAT (Inverse Cipher) (A5173)256-bit AESKATCASTThe Module State changes to RunningDecrypt (inverse cipher)Initialisation
Counter DRBG (A4593)128-bit AES with dfKATCASTThe Module State changes to RunningInstantiate, Reseed, Generate (per IG 10.3.A, 6)Initialisation
Counter DRBG (A5173)128-bit AES with dfKATCASTThe Module State changes to RunningInstantiate, Reseed, Generate (per IG 10.3.A, 6)Initialisation
Hash DRBG (A4593)SHA-256KATCASTThe Module State changes to RunningInstantiate, Reseed, Generate (per IG 10.3.A, 6)Initialisation
Hash DRBG (A5173)SHA-256KATCASTThe Module State changes to RunningInstantiate, Reseed, Generate (per IG 10.3.A, 6)Initialisation
HMAC DRBG (A4593)HMAC-SHA-1KATCASTThe Module State changes to RunningInstantiate, Reseed, Generate (per IG 10.3.A, 6)Initialisation
HMAC DRBG (A5173)HMAC-SHA-1KATCASTThe Module State changes to RunningInstantiate, Reseed, Generate (per IG 10.3.A, 6)Initialisation
Page 82
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
KDF ANS 9.42SHA-1KATCASTThe Module StateDeriveInitialisation
(A4593)changes to Running
KDF ANS 9.42 (A5173)SHA-1KATCASTThe Module State changes to RunningDeriveInitialisation
KDF ANS 9.63SHA-256KATCASTThe Module StateDeriveInitialisation
(A4593)changes to Running
KDF ANS 9.63 (A5173)SHA-256KATCASTThe Module State changes to RunningDeriveInitialisation
KDF SSHSHA-1KATCASTThe Module StateDeriveInitialisation
(A4593)changes to Running
KDF SSH (A5173)SHA-1KATCASTThe Module State changes to RunningDeriveInitialisation
TLS v1.2 KDF RFC7627 (A4593)HMAC-SHA-256KATCASTThe Module State changes to RunningDeriveInitialisation
TLS v1.2 KDF RFC7627 (A5173)HMAC-SHA-256KATCASTThe Module State changes to RunningDeriveInitialisation
TLS v1.3 KDFSHA-256KATCASTThe Module StateDeriveInitialisation
(A4593)changes to Running
TLS v1.3 KDF (A5173)SHA-256KATCASTThe Module State changes to RunningDeriveInitialisation
DSA Verify2048, SHA-256KATCASTThe Module StateVerifyInitialisation
(A4593)changes to Running
DSA Verify (A5173)2048, SHA-256KATCASTThe Module State changes to RunningVerifyInitialisation
ECDSA Sign KAT for Prime Curves (A4593)P-224, SHA-512KATCASTThe Module State changes to RunningSignInitialisation
Page 83
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
ECDSA Sign KAT for Prime Curves (A5173)P-224, SHA-512KATCASTThe Module State changes to RunningSignInitialisation
ECDSA Sign KAT for Binary Curves (A4593)K-233, SHA-512KATCASTThe Module State changes to RunningSignInitialisation
ECDSA Sign KAT for Binary Curves (A5173)K-233, SHA-512KATCASTThe Module State changes to RunningSignInitialisation
ECDSA Sign KAT for Brainpool Curves (A4593)brainpoolP224r 1, SHA-512KATCASTThe Module State changes to RunningSignInitialisation
ECDSA Sign KAT for Brainpool Curves (A5173)brainpoolP224r 1, SHA-512KATCASTThe Module State changes to RunningSignInitialisation
ECDSA Verify KAT for Prime Curves (A4593)P-224, SHA-512KATCASTThe Module State changes to RunningVerifyInitialisation
ECDSA Verify KAT for Prime Curves (A5173)P-224, SHA-512KATCASTThe Module State changes to RunningVerifyInitialisation
ECDSA Verify KAT for Binary Curves (A4593)K-233, SHA-512KATCASTThe Module State changes to RunningVerifyInitialisation
Page 84
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
ECDSA Verify KAT for Binary Curves (A5173)K-233, SHA-512KATCASTThe Module State changes to RunningVerifyInitialisation
ECDSA Verify KAT for Brainpool Curves (A4593)brainpoolP224r 1, SHA-512KATCASTThe Module State changes to RunningVerifyInitialisation
ECDSA Verify KAT for Brainpool Curves (A5173)brainpoolP224r 1, SHA-512KATCASTThe Module State changes to RunningVerifyInitialisation
EDDSA Sign KAT for Ed25519 (A4593)Ed25519KATCASTThe Module State changes to RunningSignInitialisation
EDDSA Sign KAT for Ed25519 (A5173)Ed25519KATCASTThe Module State changes to RunningSignInitialisation
EDDSA Sign KAT for Ed448 (A4593)Ed448KATCASTThe Module State changes to RunningSignInitialisation
EDDSA Sign KAT for Ed448 (A5173)Ed448KATCASTThe Module State changes to RunningSignInitialisation
EDDSA Verify KAT for Ed25519 (A4593)Ed25519KATCASTThe Module State changes to RunningVerifyInitialisation
Page 85
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
EDDSA Verify KAT for Ed25519 (A5173)Ed25519KATCASTThe Module State changes to RunningVerifyInitialisation
EDDSA Verify KAT for Ed448 (A4593)Ed448KATCASTThe Module State changes to RunningVerifyInitialisation
EDDSA Verify KAT for Ed448 (A5173)Ed448KATCASTThe Module State changes to RunningVerifyInitialisation
HMAC-SHA2- 256 (A4593)HMAC-SHA-256KATCASTThe Module State changes to RunningVerifyInitialisation , performed before pre- operational integrity test
HMAC-SHA2- 256 (A5173)HMAC-SHA-256KATCASTThe Module State changes to RunningVerifyInitialisation , performed before pre- operational integrity test
KAS-ECC-SSC Sp800-56Ar3 (A4593)P-256KATCASTThe Module State changes to RunningVerify computation of shared secret Z in Ephemeral Unified scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3Initialisation
Page 86
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
KAS-ECC-SSC Sp800-56Ar3 (A5173)P-256KATCASTThe Module State changes to RunningVerify computation of shared secret Z in Ephemeral Unified scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3Initialisation
KAS-FFC-SSC Sp800-56Ar3 (A4593)FB (2048, 224)KATCASTThe Module State changes to RunningVerify computation of shared secret Z in dhEphem scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3Initialisation
KAS-FFC-SSC Sp800-56Ar3 (A5173)FB (2048, 224)KATCASTThe Module State changes to RunningVerify computation of shared secret Z in dhEphem scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3Initialisation
KAS-IFC-SSC (A4593)2048-bit keyKATCASTThe Module State changes to RunningRSA Primitive Computation, per Scenario 1 of IG D.F and Section 8.2.2 in SP 800-56Br2Initialisation
Page 87
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
KAS-IFC-SSC (A5173)2048-bit keyKATCASTThe Module State changes to RunningRSA Primitive Computation, per Scenario 1 of IG D.F and Section 8.2.2 in SP 800-56Br2Initialisation
KDA OneStep SP800-56Cr2 (A4593)SHA-224KATCASTThe Module State changes to RunningDeriveInitialisation
KDA OneStep SP800-56Cr2 (A5173)SHA-224KATCASTThe Module State changes to RunningDeriveInitialisation
KDA TwoStep SP800-56Cr2 (A4593)SHA-256KATCASTThe Module State changes to RunningDeriveInitialisation
KDA TwoStep SP800-56Cr2 (A5173)SHA-256KATCASTThe Module State changes to RunningDeriveInitialisation
KDF SP800- 108 (A4593)Counter Mode with HMAC- SHA-256KATCASTThe Module State changes to RunningDeriveInitialisation
KDF SP800- 108 (A5173)Counter Mode with HMAC- SHA-256KATCASTThe Module State changes to RunningDeriveInitialisation
KTS-IFC2048-bit keyKATCASTThe Module State changes to RunningEncrypt forInitialisation
Encrypt KATKTS-OAEP-
for KTS-Basic, per IG
OAEP-BasicD.G and SP
(A4593)800-56Br2
KTS-IFC Encrypt KAT for KTS- OAEP-Basic (A5173)2048-bit keyKATCASTThe Module State changes to RunningEncrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2Initialisation
Page 88
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
KTS-IFC2048-bit keyKATCASTThe Module State changes to RunningDecrypt forInitialisation
Decrypt KATKTS-OAEP-
for KTS-Basic, per IG
OAEP-BasicD.G and SP
(A4593)800-56Br2
KTS-IFC Decrypt KAT for KTS- OAEP-Basic (A5173)2048-bit keyKATCASTThe Module State changes to RunningDecrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2Initialisation
KTS-IFC2048-bit keyKATCASTThe Module State changes to RunningDecrypt forInitialisation
Decrypt KATCRT, per IG
for CRTD.G and SP
(A4593)800-56Br2
KTS-IFC Decrypt KAT for CRT (A5173)2048-bit keyKATCASTThe Module State changes to RunningDecrypt for CRT, per IG D.G and SP 800-56Br2Initialisation
PBKDF (A4593)HMAC-SHA-1KATCASTThe Module State changes to RunningDerivation of the Master Key (MK), per Section 5.3 of SP 800-132Initialisation
PBKDF (A5173)HMAC-SHA-1KATCASTThe Module State changes to RunningDerivation of the Master Key (MK), per Section 5.3 of SP 800-132Initialisation
RSA Sign KAT (A4593)2048-bit key, SHA-256, PKCS#1KATCASTThe Module State changes to RunningSignInitialisation
RSA Sign KAT (A5173)2048-bit key, SHA-256, PKCS#1KATCASTThe Module State changes to RunningSignInitialisation
Page 89
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
RSA Verify KAT (A4593)2048-bit key, SHA-256, PKCS#1KATCASTThe Module State changes to RunningVerifyInitialisation
RSA Verify KAT (A5173)2048-bit key, SHA-256, PKCS#1KATCASTThe Module State changes to RunningVerifyInitialisation
SHA3 KAT for Keccak-p Permutation (A4593)SHA3-256KATCASTThe Module State changes to RunningHashInitialisation
SHA3 KAT for Keccak-p Permutation (A5173)SHA3-256KATCASTThe Module State changes to RunningHashInitialisation
SHA-1SHA-1KATCASTThe Module StateHashInitialisation
(A4593)changes to Running
SHA-1 (A5173)SHA-1KATCASTThe Module State changes to RunningHashInitialisation
SHA2-512SHA-512KATCASTThe Module StateHashInitialisation
(A4593)changes to Running
SHA2-512 (A5173)SHA-512KATCASTThe Module State changes to RunningHashInitialisation
TDES-CBCCBC mode, 3-KATCASTThe Module StateDecryptInitialisation
(A4593)keychanges to Running
TDES-CBC (A5173)CBC mode, 3- keyKATCASTThe Module State changes to RunningDecryptInitialisation
DSA (FFC) PCT for Key Agreement (A4593)All supported parameters for KAS-FFCPCTPCTReturn value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failureSign/Verify for Key Agreement, per VE10.35.03Key Pair Generation, Key Pair Import
Page 90
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
DSA (FFC) PCT for Key Agreement (A5173)All supported parameters for KAS-FFCPCTPCTReturn value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failureSign/Verify for Key Agreement, per VE10.35.03Key Pair Generation, Key Pair Import
ECC PCT for Key Pair Generation (A4593)All supported curvesPCTPCTReturn value for the relevant API call (i.e. for key pair generation): 1 for success, 0 for failureSign/Verify for Digital Signatures, per VE10.35.02. At the time of key pair generation, the keys' intended usage is not known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.Key Pair Generation
ECC PCT for Key Pair Generation (A5173)All supported curvesPCTPCTReturn value for the relevant API call (i.e. for key pair generation): 1 for success, 0 for failureSign/Verify for Digital Signatures, per VE10.35.02. At the time of key pair generation, the keys' intended usage is notKey Pair Generation
Page 91
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetails known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.Conditions
ECC PCT for Key Pair Import (A4593)All supported curvesPCTPCTReturn value for the relevant API call (i.e. for key pair import): 1 for success, 0 for failureSign/Verify for Key Agreement, per VE10.35.03. At the time of key pair import, the keys' intended usage is not known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptableKey Pair Import
ECC PCT for Key Pair Import (A5173)All supported curvesPCTPCTReturn value for the relevant API call (i.e. for key pair import): 1 for success, 0 for failureSign/Verify for Key Agreement, per VE10.35.03.Key Pair Import
Page 92
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetails At the time of key pair import, the keys' intended usage is not known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptableConditions
EdDSA PCT (A4593)All supported curves (Ed25519, Ed448)PCTPCTReturn value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failureSign/Verify for Digital Signatures, per VE10.35.02. EdDSA keys can only be used for digital signatures.Key Pair Generation, Key Pair Import
EdDSA PCT (A5173)All supported curves (Ed25519, Ed448)PCTPCTReturn value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failureSign/Verify for Digital Signatures, per VE10.35.02. EdDSA keys can only be used for digital signatures.Key Pair Generation, Key Pair Import
Page 93
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
RSA PCT (A4593)All supported moduliPCTPCTReturn value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failureSign/Verify for Key Agreement, per VE10.35.03. At the time of key pair generation or import, the keys' intended usage is not known (key pairs may be used for key transport, digital signatures, or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.Key Pair Generation, Key Pair Import
RSA PCT (A5173)All supported moduliPCTPCTReturn value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failureSign/Verify for Key Agreement, per VE10.35.03. At the time of key pair generation or import, the keys' intended usage is not known (key pairs may be used for key transport,Key Pair Generation, Key Pair Import
Page 94
Algorithm or TestTest PropertiesTest Metho dTest TypeIndicatorDetails digital signatures, or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.Conditions
AES-XTS Key Test (A4593)All supported sizes (128-bit, 256-bit)OtherCritical Functio nReturn value for the relevant API call (i.e. for symmetric encryption/decryption with AES-XTS): 1 for success, 0 for failureTest that Key_1 Key_2, per IG C.ISymmetric Encryption/ Decryption
AES-XTS Key Test (A5173)All supported sizes (128-bit, 256-bit)OtherCritical Functio nReturn value for the relevant API call (i.e. for symmetric encryption/decryption with AES-XTS): 1 for success, 0 for failureTest that Key_1 Key_2, per IG C.ISymmetric Encryption/ Decryption
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A4593)HMAC-SHA2-256Compare to pre- computed HMACCompare to pre-SW/FW IntegrityOn demand. It is recommended to run the periodic tests at least annually.On demand. It isPre-Operational
(A4593)computed HMACrecommended toPeriodic tests are
run the periodiccalled by power
tests at leastcycling the module,
annually.calling the Integrity Test service, or calling the Self-Test service (which calls the module's

d Table 19: Conditional Self-Tests

Page 95
Algorithm or TestTest MethodTest TypePeriodPeriodic Method integrity test and all CASTs).
HMAC-SHA2-256 (A5173)Compare to pre- computed HMACSW/FW IntegrityOn demand. It is recommended to run the periodic tests at least annually.Pre-Operational Periodic tests are called by power cycling the module, calling the Integrity Test service, or calling the Self-Test service (which calls the module's integrity test and all CASTs).
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM Authenticated Encrypt KAT (Forward Cipher) (A4593)AES-GCMKATCASTOn demand. It is recommended to run the periodic tests at least annually.On demand. It isConditional Periodic
Authenticatedrecommended totests are called by
Encrypt KATrun the periodicpower cycling the
(Forward Cipher)tests at leastmodule or calling
(A4593)annually.the Self-Test service (which calls the module's integrity test and all CASTs).
AES-GCM Authenticated Encrypt KAT (Forward Cipher) (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
AES-GCM Decrypt KAT (Forward Cipher) (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the

Table 20: Pre-Operational Periodic Information

Page 96
Algorithm or TestTest MethodTest TypePeriodPeriodic Method module's integrity test and all CASTs).
AES-GCM Decrypt KAT (Forward Cipher) (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
AES-ECB Decrypt KAT (Inverse Cipher) (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
AES-ECB Decrypt KAT (Inverse Cipher) (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
Counter DRBG (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
Counter DRBG (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 97
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
module's integrity test and all CASTs).
Hash DRBG (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
Hash DRBG (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
HMAC DRBG (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
HMAC DRBG (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDF ANS 9.42 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 98
Algorithm or TestTest MethodTest TypePeriodPeriodic Method module's integrity test and all CASTs).
KDF ANS 9.42 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDF ANS 9.63 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDF ANS 9.63 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDF SSH (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDF SSH (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 99
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
module's integrity test and all CASTs).
TLS v1.2 KDF RFC7627 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
TLS v1.2 KDF RFC7627 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
TLS v1.3 KDF (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
TLS v1.3 KDF (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
DSA Verify (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 100
Algorithm or TestTest MethodTest TypePeriodPeriodic Method module's integrity test and all CASTs).
DSA Verify (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Sign KAT for Prime Curves (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Sign KAT for Prime Curves (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Sign KAT for Binary Curves (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Sign KAT for Binary Curves (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 101
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
module's integrity test and all CASTs).
ECDSA Sign KAT for Brainpool Curves (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Sign KAT for Brainpool Curves (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Verify KAT for Prime Curves (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Verify KAT for Prime Curves (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Verify KAT for Binary Curves (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 102
Algorithm or TestTest MethodTest TypePeriodPeriodic Method module's integrity test and all CASTs).
ECDSA Verify KAT for Binary Curves (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Verify KAT for Brainpool Curves (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
ECDSA Verify KAT for Brainpool Curves (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
EDDSA Sign KAT for Ed25519 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
EDDSA Sign KAT for Ed25519 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 103
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
module's integrity test and all CASTs).
EDDSA Sign KAT for Ed448 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
EDDSA Sign KAT for Ed448 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
EDDSA Verify KAT for Ed25519 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
EDDSA Verify KAT for Ed25519 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
EDDSA Verify KAT for Ed448 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 104
Algorithm or TestTest MethodTest TypePeriodPeriodic Method module's integrity test and all CASTs).
EDDSA Verify KAT for Ed448 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
HMAC-SHA2-256 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
HMAC-SHA2-256 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KAS-ECC-SSC Sp800- 56Ar3 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KAS-ECC-SSC Sp800- 56Ar3 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 105
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
module's integrity test and all CASTs).
KAS-FFC-SSC Sp800- 56Ar3 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KAS-FFC-SSC Sp800- 56Ar3 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KAS-IFC-SSC (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KAS-IFC-SSC (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDA OneStep SP800-56Cr2 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 106
Algorithm or TestTest MethodTest TypePeriodPeriodic Method module's integrity test and all CASTs).
KDA OneStep SP800-56Cr2 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDA TwoStep SP800-56Cr2 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDA TwoStep SP800-56Cr2 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDF SP800-108 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KDF SP800-108 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 107
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
module's integrity test and all CASTs).
KTS-IFC Encrypt KAT for KTS-OAEP-Basic (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KTS-IFC Encrypt KAT for KTS-OAEP-Basic (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KTS-IFC Decrypt KAT for KTS-OAEP-Basic (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KTS-IFC Decrypt KAT for KTS-OAEP-Basic (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
KTS-IFC Decrypt KAT for CRT (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 108
Algorithm or TestTest MethodTest TypePeriodPeriodic Method module's integrity test and all CASTs).
KTS-IFC Decrypt KAT for CRT (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
PBKDF (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
PBKDF (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
RSA Sign KAT (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
RSA Sign KAT (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 109
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
module's integrity test and all CASTs).
RSA Verify KAT (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
RSA Verify KAT (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
SHA3 KAT for Keccak-p Permutation (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
SHA3 KAT for Keccak-p Permutation (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
SHA-1 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 110
Algorithm or TestTest MethodTest TypePeriodPeriodic Method module's integrity test and all CASTs).
SHA-1 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
SHA2-512 (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
SHA2-512 (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
TDES-CBC (A4593)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the module's integrity test and all CASTs).
TDES-CBC (A5173)KATCASTOn demand. It is recommended to run the periodic tests at least annually.Conditional Periodic tests are called by power cycling the module or calling the Self-Test service (which calls the
Page 111
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
module's integrity test and all CASTs).
DSA (FFC) PCT for Key Agreement (A4593)PCTPCT
DSA (FFC) PCT for Key Agreement (A5173)PCTPCT
ECC PCT for Key Pair Generation (A4593)PCTPCT
ECC PCT for Key Pair Generation (A5173)PCTPCT
ECC PCT for Key Pair Import (A4593)PCTPCT
ECC PCT for Key Pair Import (A5173)PCTPCT
EdDSA PCT (A4593)PCTPCT
EdDSA PCT (A5173)PCTPCT
RSA PCT (A4593)PCTPCT
RSA PCT (A5173)PCTPCT
AES-XTS Key Test (A4593)OtherCritical Function
AES-XTS Key Test (A5173)OtherCritical Function
NameDescriptionConditionsRecovery MethodIndicator
FIPS_STATE_ERRORThe module has entered an error state. All cryptographicPre-Restart the moduleModule State (queried via Show Status)Module State (queried
operational self-test failure CASTvia Show Status)

Table 21: Conditional Periodic Information

10.4 Error States
Page 112
NameDescriptionConditionsRecovery MethodIndicator
APIs will returnself-test failureself-testchanges to Error (FIPS_STATE_ERROR)changes to Error
an error when called.failure(FIPS_STATE_ERROR)
Temporary ErrorThe module enters a temporary error state when a PCT test fails or when the AES-XTS critical function test fails. Keys that fail the tests are disabled and the module returns to the Running state.Conditional PCT test failure Conditional AES-XTS critical function test failureThe module will reject the tested key or key pair and then return automatically to the Running state (FIPS_STATE_RUNNING).The return value for the relevant API call (i.e. for key pair generation, key pair import, or symmetric encryption/ decryption with AES- XTS) returns 0 for failure

Table 22: Error States The module supports two error states, both triggered by failures of the module’s self-tests. The module must be restarted to recover from a failure of the pre-operational or CAST self-test, but it recovers

10.5 Operator Initiation of Self-Tests

Self-tests can be called on demand using the Self-Test service. This service calls the module’s integrity test and all CASTs (i.e. KATs). PCTs are not called by this service; PCTs are only called under the conditions specified in Section 10.2 - Conditional Self-Tests. The integrity test is automatically called as part of the Pre-Operational Self-Tests and can also be manually called by the Integrity Test service (or the Self-Test service).

Page 113
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is only provided to the end user in the form of a compiled binary file. Its source code is not provided. The module is provided to the end user by the vendor as a binary archive and an associated hash value. The end user should validate the integrity of the binary archive against the SHA-256 hash value provided with the binary archive. If the integrity value for the archive is correct, the archive should be extracted, and the binaries should be installed. The module is a FIPS-validated cryptographic provider for use by OpenSSL 3.x. OpenSSL 3.x should be installed per its documentation prior to module installation. The FIPS module may be installed using the following procedure:

  1. If the module is provided as a dynamic library: a. Copy the module binary and configuration files to the OpenSSL Provider Directory, e.g. [OPENSSL_INSTALL_LOCATION]/lib/ossl-modules/
  2. If the module is provided as a static library: a. Copy the module library archive and configuration file to the OpenSSL directory, e.g. [OPENSSL_INSTALL_LOCATION]/lib/ and [OPENSSL_INSTALL_LOCATION]/conf/
  3. If the module is provided as part of an XCFramework bundle: a. Integrate the module framework into an XCode application and install the application on an iOS device. b. Note, when provided as a XCFramework bundle (fips.xcframework), the OpenSSL framework (openssl.xcframework) should also be integrated into the application project. The OpenSSL framework is a general implementation of the OpenSSL 3.x API (common and crypto).
  4. To initialize and start up the module, use the OSSL_PROVIDER_load API call from OpenSSL. An example is specified below: int main(int argc, char **argv) { OSSL_PROVIDER *fips_provider; fips_provider = OSSL_PROVIDER_load(NULL, "fips"); if (fips_provider == NULL) { printf("Could not load FIPS provider\n"); return 1; } printf("Provider %s loaded \n", OSSL_PROVIDER_get0_name(fips_provider)); //Execute commands for the FIPS module if (fips_provider != NULL) OSSL_PROVIDER_unload(fips_provider);
Page 114

return 0; } The Module Initialization service is executed when the module is powered on. After the module starts up, the operator should confirm that the module outputs the Approved mode status indicator (refer to Security Policy Section 2.4 - Modes of Operation) and verify the module’s version using the “Output ID/ Version Information (Show Version)” service (refer to Security Policy Section 4.3 - Approved Services).

11.2 Administrator Guidance

Additional administrator guidance is provided separately in other operator documentation, including the User Manual.

11.3 Non-Administrator Guidance

If the module power is lost and restored, the operator shall establish a new key for use with AES-GCM encryption/decryption. Refer also to Security Policy Section 2.7.1 - AES-GCM (IG C.H conformance). Additional guidance is provided separately in other operator documentation, including the User Manual.

11.4 Design and Rules

The module is designed to meet the applicable requirements of FIPS 140-3. The module initializes when powered on, then performs the pre-operational self-tests and CASTs as specified in Security Policy Section 10 - Self-Tests. After successfully passing these self-tests, the module automatically transitions to the operational state and awaits service requests.

11.5 End of Life

The vendor documentation (User Guide) specifies the procedures for the removal of the FIPS module and secure sanitization of the device that the module was installed on.

Page 115
12 Mitigation of Other Attacks
12.1 Attack List

The module implements two types of mitigations of other attacks, which are constant-time implementations and numeric blinding. Constant-time implementations protect cryptographic implementations in the module against timing analysis. With this mitigation, variations in execution time cannot be traced back to an SSP, key, or secret data. Numeric Blinding protects RSA, DSA, and ECDSA from timing attacks, where attackers measure the time of signature operations or RSA decryption. To mitigate this attack, the module generates a random blinding factor that is provided as an input to the decryption/signature operation and is discarded once the operation has completed. With this mitigation, the execution time cannot be correlated to the RSA, DSA, or ECDSA key via a timing attack because the attacker does not know the blinding factor.

12.2 Mitigation Effectiveness

These mitigations should make the timing of the encryption, decryption, and signing operations independent of the key material or the input data. This should prevent an attacker from recovering information by measuring the timing of these operations.

12.3 Guidance and Constraints

While the module implements countermeasures to prevent timing analysis and timing attacks, other side-channel attacks may be possible. As a Level 1, software-based module, the module is limited in its ability to prevent access at the hardware level; power analysis attacks may be possible for an attacker with physical access. Users of software-based modules should be aware of these limitations and incorporate this information into their threat model.