All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Apple corecrypto Module v13.0 [Apple silicon, Kernel, Software, SL1]

Certificate#5050StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorApple Inc.
Low review priority  ·  no TCB surface named  ·  last validated 12 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date7/29/2030
CaveatWhen operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorApple Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Apple corecrypto Module v13.0 [Apple silicon, Kernel, Software, SL1]
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Unauthenticated<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Apple corecrypto Module v13.0 [Apple silicon, Kernel, Software, SL1]
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Unauthenticated<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Apple Inc. Apple corecrypto Module v13.0 [Apple silicon, Kernel, Software, SL1] Prepared for: Apple Inc. One Apple Park Way Cupertino, CA 95014 Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com

Page 2
Table of Contents
#SectionPage
Page 3

This document may be reproduced and distributed only in its original entirely without revision.

Page 4
List of Tables
ItemPage
Table 1: Security Levels7
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)9
Table 3: Tested Operational Environments - Software, Firmware, Hybrid11
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid12
Table 5: Modes List and Description12
Table 6: Approved Algorithms - AES-CBC12
Table 7: Approved Algorithms - AES-CCM13
Table 8: Approved Algorithms - AES-CFB12813
Table 9: Approved Algorithms - AES-CFB813
Table 10: Approved Algorithms - AES-CTR13
Table 11: Approved Algorithms - AES-ECB13
Table 12: Approved Algorithms - AES-GCM14
Table 13: Approved Algorithms - AES-KW14
Table 14: Approved Algorithms - AES-OFB14
Table 15: Approved Algorithms - AES-XTS14
Table 16: Approved Algorithms - CTR_DRBG14
Table 17: Approved Algorithms - ECDSA-KEYGEN14
Table 18: Approved Algorithms - ECDSA-KEYVER14
Table 19: Approved Algorithms - ECDSA-SIGGEN15
Table 20: Approved Algorithms - ECDSA-SIGVER15
Table 21: Approved Algorithms - HMAC-SHA115
Table 22: Approved Algorithms - HMAC-SHA22415
Table 23: Approved Algorithms - HMAC-SHA25615
Table 24: Approved Algorithms - HMAC-SHA38415
Table 25: Approved Algorithms - HMAC-SHA51216
Table 26: Approved Algorithms - HMAC-SHA512/25616
Table 27: Approved Algorithms - RSA-SIGGEN16
Table 28: Approved Algorithms - RSA-SIGVER16
Table 29: Approved Algorithms - SHA116
Table 30: Approved Algorithms - SHA22416
Table 31: Approved Algorithms - SHA25617
Table 32: Approved Algorithms - SHA38417
Table 33: Approved Algorithms - SHA51217
Table 34: Approved Algorithms - SHA512/25617
Table 35: Vendor-Affirmed Algorithms17
Table 36: Non-Approved, Not Allowed Algorithms18
Table 37: Security Function Implementations21
Table 38: Entropy Certificates21
Table 39: Entropy Sources22
Table 40: Ports and Interfaces23
Table 41: Roles24
Page 5

List of Figures This document may be reproduced and distributed only in its original entirely without revision.

Page 6

Trademarks Apple’s trademarks applicable to this document are listed in https://www.apple.com/legal/intellectual-property/trademark/appletmlist.html. Other company, product, and service names may be trademarks or service marks of others. This document may be reproduced and distributed only in its original entirely without revision.

Page 7
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for Apple corecrypto Module v13.0 [Apple silicon, Kernel, Software, SL1] cryptographic module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for This document provides all tables and diagrams (when applicable) required by NIST SP 800140Br1.

1.2 Security Levels

Overall Level 1 Table 1: Security Levels This document may be reproduced and distributed only in its original entirely without revision.

Page 8
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Apple corecrypto Module v13.0 [Apple silicon, Kernel, Software, SL1] cryptographic module (hereafter referred to as “the module”) provides implementations of lowlevel cryptographic primitives to the Device OS’s kernels (iOS 16, iPadOS 16, watchOS 9, tvOS 16) Security Framework and Common Crypto. The module provides services intended to protect data in transit and at rest. The module is optimized for library use within the Device OS kernel space and does not contain any terminating assertions or exceptions. It is implemented as a Device OS dynamically loadable library. The library is loaded into the Device OS kernel and its cryptographic functions are made available to Device OS kernel services only. Any internal error detected by the module is returned to the caller with an appropriate return code. The calling Device OS kernel service must examine the return code and act accordingly. The module communicates any error status synchronously through the use of its documented return codes, thus indicating the module’s status. Caller-induced or internal errors do not reveal any sensitive material to callers. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The module cryptographic boundary is delineated by the dotted green rectangle in the Figure 1 where the Kernel Extension (KEXT) is a bundle that performs low-level tasks. KEXTs run in kernel space, which gives them elevated privileges and the ability to perform tasks that user-space apps can’t. This document may be reproduced and distributed only in its original entirely without revision.

Page 9

Tested Module Identific Package or File Name

at Version

ion – Software, Firmw Software/ Firmware

a

re, Hybrid (Executable C Features

ode Sets): Integrity Test

Tested Oper Operating Systemational Environments - Sof Hardware Platformtware, Firmware, Hybr Processorsid: PAA/PAIVersion(s)
Hypervisor
or Host
OS
iPadOS 16iPad (5th generation)Apple A Series A9YesNAv13.0
iPadOS 16 iPadOS 16iPad Pro 9.7-inch iPad (7th generation)Apple A Series A9X Apple A Series A10Yes YesNA NAv13.0 v13.0

Figure 1: Block Diagram Tested Operational Environment’s Physical Perimeter (TOEPP): The physical perimeter is represented by the most exterior black line in the block diagram Figure 1. The module executes within the kernel space of the computing platforms and operating systems listed in the Tested Operational Environments Table section 2.2.

2.2 Tested and Vendor Affirmed Module Version and Identification

xnu-10002.60.75.0.3 v13.0 N/A HMAC-SHA256 Fusion This document may be reproduced and distributed only in its original entirely without revision.

Page 10
Operating SystemHardware PlatformProcessorsPAA/PAIVersion(s)
Hypervisor
or Host
iPadOS 16iPad mini (5thApple A Series A12YesOS NAv13.0
iPadOS 16generation) iPad Pro 11-inch (1stBionic Apple A SeriesYesNAv13.0
iPadOS 16generation) iPad Pro 11-inch (2ndA12X Bionic Apple A SeriesYesNAv13.0
iPadOS 16generation) iPad (9th generation)A12Z Bionic Apple A Series A13YesNAv13.0
iPadOS 16iPad Air (4thBionic Apple A Series A14YesNAv13.0
iPadOS 16generation) iPad mini (6thBionic Apple A Series A15YesNAv13.0
iPadOS 16generation) iPad Pro 11-inch (3rdBionic Apple M Series M1YesNAv13.0
iPadOS 16generation) iPad Pro 11-inch (4thApple M Series M2YesNAv13.0
iOS 16generation) iPhone XApple A Series A11YesNAv13.0
iOS 16iPhone XS MaxBionic Apple A Series A12YesNAv13.0
iOS 16iPhone 11 ProBionic Apple A Series A13YesNAv13.0
iOS 16iPhone 12Bionic Apple A Series A14YesNAv13.0
iOS 16iPhone 13 Pro MaxBionic Apple A Series A15YesNAv13.0
iOS 16iPhone 14 Pro MaxBionic Apple A Series A16YesNAv13.0
watchOSApple Watch Series S4Bionic Apple S Series S4YesNAv13.0
9 watchOSApple Watch Series S5Apple S Series S5YesNAv13.0
9 watchOSApple Watch Series S6Apple S Series S6YesNAv13.0
9 watchOSApple Watch Series S7Apple S Series S7YesNAv13.0
9 watchOSApple Watch Series S8Apple S Series S8YesNAv13.0

This document may be reproduced and distributed only in its original entirely without revision.

Page 11
Operating SystemHardware PlatformProcessorsPAA/PAIVersion(s)
Hypervisor
or Host
iPadOS 16iPad Pro 10.5-inchApple A SeriesYesOS NAv13.0
tvOS 16Apple TV 4K (2ndA10X Fusion Apple A Series A12YesNAv13.0
tvOS 16generation) Apple TV 4K (3rdBionic Apple A Series A15YesNAv13.0

V Operating System iPadOS 16 iPadOS 16 iPadOS 16 iPadOS 16 iPadOS 16 iPadOS 16 iPadOS 16 iPadOS 16 iPadOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 iOS 16 watchOS 9 macOS 13 Ventura macOS 13 Ventura macOS 13 Ventura

endor-Affirmed O

p

e Hardware Platform iPad Pro 12.9-inch iPad (6th generation) iPad Pro 12.9-inch (2nd generation) iPad Air (3rd generation) iPad (8th generation) iPad Pro 12.9-inch (3rd generation) iPad Pro 12.9-inch (4th generation) iPad Pro 12.9-inch (5th generation) iPad Pro 12.9-inch (6th generation) iPhone 8 iPhone 8 Plus iPhone XS iPhone XR iPhone 11 iPhone 11 Pro Max iPhone SE (2nd generation) iPhone 12 mini iPhone 12 Pro iPhone 12 Pro Max iPhone 13 mini iPhone 13 iPhone 13 Pro iPhone 14 Pro Apple Watch SE Mac mini iMac (24-inch) MacBook Pro (14-inch, 2021)

rational Environments - Software, Fi

r

Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: This document may be reproduced and distributed only in its original entirely without revision.

Page 12
DescriptionTypeStatus Indicator
Mode
Name Approved modeApproved mode of operation is entered when the module utilizes the services that use the security functions listed in the Approved Algorithms Table and the VendorApprovedreturn a '1' from fips_allowed_mode() for block cipher functions and fips_allowed() for all other services to indicate the executed cryptographic algorithm was approved
Non- Approved modeAffirmed Algorithms Table. Non-Approved mode of operation is entered when the module utilizes non-approved security functions in the Table Non-Approved Algorithms Not Allowed in the ApprovedNon- Approvedreturn a '0' from fips_allowed_mode() for block cipher functions and fips_allowed() for all other services to indicate the executed cryptographic algorithm was non- approved
AES-CBC
Algorithm AES-CBCCAVP Cert A3682Properties Direction - Decrypt, EncryptReference SP 800-38A
AES-CBCA3683Key Length - 128, 192, 256 Direction - Decrypt, EncryptSP 800-38A

Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

None for this module Modes List and Description: This document may be reproduced and distributed only in its original entirely without revision.

Page 13
AES-CCM
AlgorithmCAVP CertPropertiesReference
AES-CFB128
Algorithm AES-CFB128CAVP Cert A3682Properties Direction - Decrypt, EncryptReference SP 800-38A
AES-CFB128A3683Key Length - 128, 192, 256 Direction - Decrypt, EncryptSP 800-38A
AES-CFB8
Algorithm AES-CFB8CAVP Cert A3683Properties Direction - Decrypt, EncryptReference SP 800-38A
AES-CTR
Algorithm AES-CTRCAVP Cert A3683Properties Direction - Decrypt, EncryptReference SP 800-38A
AES-CTRA3685Key Length - 128, 192, 256 Direction - Decrypt, EncryptSP 800-38A
AES-ECB
Algorithm AES-ECBCAVP Cert A3682Properties Direction - Decrypt, EncryptReference SP 800-38A
AES-ECBA3683Key Length - 128, 192, 256 Direction - Decrypt, EncryptSP 800-38A
AES-ECBA3685Key Length - 128, 192, 256 Direction - Decrypt, EncryptSP 800-38A
AES-GCM
Algorithm AES-GCMCAVP Cert A3685Properties Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1Reference SP 800-38D

Table 7: Approved Algorithms - AES-CCM Table 8: Approved Algorithms - AES-CFB128 Table 9: Approved Algorithms - AES-CFB8 Table 10: Approved Algorithms - AES-CTR Table 11: Approved Algorithms - AES-ECB This document may be reproduced and distributed only in its original entirely without revision.

Page 14
AES-KW
Algorithm AES-KWCAVP Cert A3683Properties Direction - Decrypt, EncryptReference SP 800-38F
AES-OFB
Algorithm AES-OFBCAVP Cert A3682Properties Direction - Decrypt, EncryptReference SP 800-38A
AES-OFBA3683Key Length - 128, 192, 256 Direction - Decrypt, EncryptSP 800-38A
AES-XTS
Algorithm AES-XTS Testing Revision 2.0CAVP Cert A3682Properties Direction - Decrypt, EncryptReference SP 800-38E
CTR_DRBG
Algorithm Counter DRBGCAVP Cert A3683Properties Prediction Resistance - No Mode - AES-128, AES-256Reference SP 800-90A Rev. 1
Counter DRBGA3685Derivation Function Enabled - Yes Prediction Resistance - No Mode - AES-128, AES-256SP 800-90A Rev. 1
ECDSA-KEYGEN
Algorithm ECDSA KeyGen (FIPS186-4)CAVP Cert A3686Properties Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - TestingReference FIPS 186-4
ECDSA-KEYVER
AlgorithmCAVP CertPropertiesReference

Table 12: Approved Algorithms - AES-GCM Table 13: Approved Algorithms - AES-KW Table 14: Approved Algorithms - AES-OFB Table 15: Approved Algorithms - AES-XTS CTR_DRBG Table 16: Approved Algorithms - CTR_DRBG Candidates Table 17: Approved Algorithms - ECDSA-KEYGEN Table 18: Approved Algorithms - ECDSA-KEYVER This document may be reproduced and distributed only in its original entirely without revision.

Page 15
ECDSA-SIGGEN
Algorithm ECDSA SigGen (FIPS186-4)CAVP Cert A3686Properties Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256,Reference FIPS 186-4
ECDSA-SIGVER
Algorithm ECDSA SigVer (FIPS186-4)CAVP Cert A3686Properties Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-Reference FIPS 186-4
HMAC-SHA1
Algorithm HMAC-SHA-CAVP Cert A3686Properties Key Length - Key Length: 8-262144 IncrementReference FIPS 198-1
HMAC-SHA224
Algorithm HMAC-SHA2-CAVP Cert A3686Properties Key Length - Key Length: 8-262144Reference FIPS 198-1
HMAC-SHA256
Algorithm HMAC-SHA2-CAVP Cert A3686Properties Key Length - Key Length: 8-262144Reference FIPS 198-1
256 HMAC-SHA2-A3687Increment 8 Key Length - Key Length: 8-262144FIPS 198-1
HMAC-SHA384
Algorithm HMAC-SHA2-CAVP Cert A3684Properties Key Length - Key Length: 8-262144Reference FIPS 198-1
384 HMAC-SHA2-A3686Increment 8 Key Length - Key Length: 8-262144FIPS 198-1

Table 19: Approved Algorithms - ECDSA-SIGGEN Table 20: Approved Algorithms - ECDSA-SIGVER

1 8

Table 21: Approved Algorithms - HMAC-SHA1 Table 22: Approved Algorithms - HMAC-SHA224 Table 23: Approved Algorithms - HMAC-SHA256 Table 24: Approved Algorithms - HMAC-SHA384 This document may be reproduced and distributed only in its original entirely without revision.

Page 16
HMAC-SHA512
Algorithm HMAC-SHA2-CAVP Cert A3684Properties Key Length - Key Length: 8-262144Reference FIPS 198-1
512 HMAC-SHA2-A3686Increment 8 Key Length - Key Length: 8-262144FIPS 198-1
HMAC-SHA512/256
Algorithm HMAC-SHA2-CAVP Cert A3684Properties Key Length - Key Length: 8-262144Reference FIPS 198-1
512/256 HMAC-SHA2-A3686Increment 8 Key Length - Key Length: 8-262144FIPS 198-1
RSA-SIGGEN
Algorithm RSA SigGen (FIPS186-4)CAVP Cert A3686Properties Signature Type - PKCS 1.5, PKCSPSSReference FIPS 186-4
RSA-SIGVER
Algorithm RSA SigVer (FIPS186-4)CAVP Cert A3686Properties Signature Type - PKCS 1.5, PKCSPSS FReference IPS 186-4
SHA1
Algorithm SHA-1CAVP Cert A3686Properties Message Length - Message Length: 0-32768Reference FIPS 180-4
SHA224
Algorithm SHA2-CAVP Cert A3686Properties Message Length - Message Length: 0-32768Reference FIPS 180-4

Table 25: Approved Algorithms - HMAC-SHA512 Table 26: Approved Algorithms - HMAC-SHA512/256 Modulo - 2048, 3072, 4096 Table 27: Approved Algorithms - RSA-SIGGEN Modulo - 1024, 2048, 3072, 4096 Table 28: Approved Algorithms - RSA-SIGVER SHA1 Table 29: Approved Algorithms - SHA1 SHA224

224 Increment 8

Table 30: Approved Algorithms - SHA224 This document may be reproduced and distributed only in its original entirely without revision.

Page 17
SHA256
Algorithm SHA2-CAVP Cert A3686Properties Message Length - Message Length: 0-32768Reference FIPS 180-4
256 SHA2-A3687Increment 8 Message Length - Message Length: 0-32768FIPS 180-4
SHA384
Algorithm SHA2-CAVP Cert A3684Properties Message Length - Message Length: 0-32768Reference FIPS 180-4
384 SHA2-A3686Increment 8 Message Length - Message Length: 0-32768FIPS 180-4
SHA512
Algorithm SHA2-CAVP Cert A3684Properties Message Length - Message Length: 0-32768Reference FIPS 180-4
512 SHA2-A3686Increment 8 Message Length - Message Length: 0-32768FIPS 180-4
SHA512/256
Algorithm SHA2-CAVP Cert A3684Properties Message Length - Message Length: 0-32768Reference FIPS 180-4
512/256 SHA2-A3686Increment 8 Message Length - Message Length: 0-32768FIPS 180-4
Vendor-Affirmed Algorithms:
NamePropertiesImplementationReference

SHA256 Table 31: Approved Algorithms - SHA256 SHA384 Table 32: Approved Algorithms - SHA384 SHA512 Table 33: Approved Algorithms - SHA512 SHA512/256 Table 34: Approved Algorithms - SHA512/256 The FIPS 186-4 CAVP tests in the listed ACVP certificates above are mathematically identical to the FIPS 186-5 CAVP tests. Per FIPS 140-3 C.K Additional Comments 2, the module claims compliance with FIPS 186-5 tests. Vendor-Affirmed Algorithms: CKG Key Type:Asymmetric N/A SP800-133rev2 section 4 example 1 Table 35: Vendor-Affirmed Algorithms This document may be reproduced and distributed only in its original entirely without revision.

Page 18
NameUse and Function
ANSI X9.63 KDFHash based Key Derivation Function
Blowfish CAST5Encryption / Decryption Encryption / Decryption Key Sizes: 40 to 128 bits in 8-bit increments
DES ECDSAEncryption / Decryption Key Size: 56-bits Generation / Verification / SigGen / SigVer with
ECDSA KeyGencurve P-192 Key Pair Generation for compact point
EdDSArepresentation of points Key Generation, Signature Generation, Signature Verification with Ed25519
HKDF [SP800-56Crev2] Integrated Encryption Scheme on elliptic curves (ECIES)Key Derivation Function Encryption / Decryption
MD2Message Digest size: 128-bit
MD4Message Digest size: 128-bit
OMAC (One-Key CBC MAC)MAC generation /verification
RC2Encryption / Decryption Key Sizes 8 to 1024-bits
RC4Encryption / Decryption Key Sizes 8 to 4096-bits
RIPEMD RSA SigGenMessage Digest size: 160-bits PKCS#1 v1.5 and PSS; Signature Generation Key Size < 2048
RSA SigVerSignature Verification Key Size < 1024
RSA Key WrappingOAEP, PKCS#1 v1.5 and -PSS schemes
Triple-DES [SP 800-67r2]CBC, CTR, CFB64, ECB, CFB8, OFB
MD5Message Digest size: 128-bit

Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: RFC 6637 Key Derivation SHA-256, SHA-512, AES-128, AES-256 Table 36: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

This document may be reproduced and distributed only in its original entirely without revision.

Page 19
Name Unauthenticated Symmetric Encryption and DecryptionType BC-UnAuthDescription Key Size / Key Strength: 128, 192, 256-bits (for all but XTS, which supports 128 and 256 bit keys)Properties AES [FIPS 197; SP 800- 38A]:ECB, CBC, CFB8, CFB128, OFB, CTR AES [FIPS 197; SP 800-38E]:XTSAlgorithms AES-CBC: (A3682, A3683) AES-CFB128: (A3682, A3683) AES-XTS Testing Revision 2.0: (A3682) AES-ECB: (A3682, A3683, A3685) AES-OFB: (A3682, A3683) AES-CFB8: (A3683) AES-CTR:
Authenticated Symmetric Encryption and DecryptionBC-AuthKey Size/ Key Strength: 128, 192, 256-bitsAES [FIPS 197; SP 800- 38C]:CCM AES [FIPS 197; SP 800-(A3683, A3685) AES-CCM: (A3685) AES-GCM: (A3685)
Random Number GenerationDRBGKey Length/ Key Strength: 128, 25638D]:GCM CTR_DRBG [SP800- 90ARev1]:AES- 128, AES-256 Derivation Function Enabled No PredictionCounter DRBG: (A3683, A3685)
ECDSA Asymmetric Key GenerationAsymKeyPair- KeyGen CKGCurve: P-224, P- 256, P-384, P- 521. Key Strength: from 112 to 256Resistance key generation method:Testing Candidates Supported Curves:P-224, P- 256, P-384, P-ECDSA KeyGen (FIPS186-4): (A3686) CKG: () Key Type: Asymmetric
ECDSA Public- Key ValidationAsymKeyPair- PubKeyValCurve: P-224, P- 256, P-384, P- 521. Key521 ECDSA [FIPS 186-5]:Public- Key ValidationECDSA KeyVer (FIPS186-4): (A3686)

(PKV) This document may be reproduced and distributed only in its original entirely without revision.

Page 20
NameTypeDescription Strength: fromPropertiesAlgorithms
ECDSA Digital Signature GenerationDigSig-SigGen112 to 256 Curve: P-224, P- 256, P-384, P- 521. Key Strength: fromECDSA [FIPS 186-5]:Signature GenerationECDSA SigGen (FIPS186-4): (A3686)
ECDSA Digital Signature VerificationDigSig-SigVer112 to 256 Curve: P-224, P- 256, P-384, P- 521. Key Strength: fromECDSA [FIPS 186-5]:Signature VerificationECDSA SigVer (FIPS186-4): (A3686)
HMAC Message AuthenticationMAC112 to 256 Key Length 8 - 262144 bits/ Key Strength: 112 to 256 bitsHMAC [FIPS 198] (vng_ltc):SHA-1, SHA-224, SHA- 256, SHA-384, SHA-512, SHA- 512/256 HMAC [FIPS 198] (c_ltc):SHA-384, SHA-512, SHA- 512/256 HMAC [FIPS 198] (vng_neon):SHA- 256HMAC-SHA2- 384: (A3684, A3686) HMAC-SHA2- 512: (A3684, A3686) HMAC-SHA2- 512/256: (A3684, A3686) HMAC-SHA2- 256: (A3686, A3687) HMAC-SHA-1: (A3686) HMAC-SHA2-
key wrapping / key unwrappingKTS-WrapKey Size/ Key Strength: 128,KTS (AES) [SP 800-38F]:AES-224: (A3686) AES-KW: (A3683)
RSA Digital Signature GenerationDigSig-SigGen192, 256-bits Modulus: 2048, 3072, 4096. Key Strength: from 112 to 150KW RSA [FIPS 186- 5]:Signature Generation (PKCS#1 v1.5)RSA SigGen (FIPS186-4): (A3686)
RSA Digital Signature VerificationDigSig-SigVerModulus: 1024 (legacy use per FIPS 140-3 IG C.K), 2048, 3072,and (PKCS PSS) RSA [FIPS 186- 5]:Signature Verification PKCS#1 v1.5)RSA SigVer (FIPS186-4): (A3686)

This document may be reproduced and distributed only in its original entirely without revision.

Page 21
NameTypeDescription Strength: fromPropertiesAlgorithms
Message DigestSHA80 to 150 N/ASHS [FIPS 180- 4] (vng_ltc):SHA- 1, SHA-224, SHA-256, SHA- 384, SHA-512, SHA-512/256 SHS [FIPS 180- 4] (c_ltc):SHA- 384, SHA-512, SHA-512/256 SHS [FIPS 180-4] (vng_neon):SHA-SHA2-384: (A3684, A3686) SHA2-512: (A3684, A3686) SHA2-512/256: (A3684, A3686) SHA2-224: (A3686) SHA2-256: (A3686, A3687) SHA-1: (A3686)
CertVendor
NumberName
E14apple

Table 37: Security Function Implementations

2.7 Algorithm Specific Information

AES-GCM AES-GCM IV is constructed in compliance with IG C.H scenario

  1. The GCM IV generation follows RFC 4106 and shall only be used for the IPsec protocol version
  2. When the IV in RFC 4106 exhausts the maximum number of possible values for a given security association, either party to the security association that encounters this condition triggers a rekeying with IKEv2 to establish a new encryption key for the security association. The module uses RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AESGCM encryption keys are derived. In case the module’s power is lost and then restored, the key used for the AES GCM encryption/decryption shall be re-distributed. This condition is not enforced by the module. AES-XTS AES-XTS mode is only approved for hardware storage applications. The length of the AES-XTS data unit does not exceed 220 blocks. The module checks explicitly that Key_1 ≠ Key_2 before using the keys in the XTS-Algorithm to process data with them compliant with IG C.I.
2.8 RBG and Entropy

E15 apple Table 38: Entropy Certificates This document may be reproduced and distributed only in its original entirely without revision.

Page 22
NameTypeOperational EnvironmentSample SizeConditioning Component
Entropy
per
Apple corecrypto physical entropyPhysicalSee Tested Operational256 bitSample 256 bitSHA-256 [ACVP cert. # C1223]
source Apple corecrypto non- physicalNon- PhysicalEnvironment Table See Tested Operational256 bit256 bitSHA-256 [ACVP Certs. # A3687]

Table 39: Entropy Sources Entropy sources: Two entropy sources (one non-physical entropy source and one physical entropy source) residing within the TOEPP provide the random bits. The entropy sources are located within the physical perimeter of the module (TOEPP) but outside the cryptographic boundary of the module. RBGs: The NIST [SP 800-90ARev1] approved deterministic random bit generators (DRBG) used for random number generation is a CTR_DRBG using AES-256 with derivation function and without prediction resistance. The module performs DRBG health tests according to [SP800-90ARev1 section 11.3]. The deterministic random bit generators are seeded by “read_random”. The read_random is the Kernel Space interface. RBG Output: The output of entropy sources provides 256-bits of entropy to seed and reseed SP800-90ARev1 DRBG during initialization (seed) and reseeding (reseed).

2.9 Key Generation

See vendor affirmed algorithms (CKG) in section 2.5. The module does not implement symmetric key generation.

2.10 Key Establishment
2.11 Industry Protocols

No parts of the IPSec, other than those mentioned above, have been tested by the CAVP and CMVP. This document may be reproduced and distributed only in its original entirely without revision.

Page 23
Data That Passes
PhysicalLogical
Port N/AInterface(s) Data Input DataData inputs/outputs are provided in the variables passed in the C language Kernel Interfaces (KPIs) and callable service invocations,
N/AOutput Controlgenerally through caller-supplied buffers Control inputs which control the mode of the module are provided
N/AInput Status Outputthrough dedicated parameters. Status output is provided in return codes and through messages. Documentation for each KPI lists possible return codes. A complete list of all return codes returned by the C language KPIs within the module is provided in the header files and the KPI documentation.

Table 40: Ports and Interfaces This document may be reproduced and distributed only in its original entirely without revision.

Page 24

Name

Type

Operator Type

Authentication Methods

NameInputsOutputs
DescriptioIndicatSecuritySSP
AES Encryption/Decrypt ionn Execute AES- mode encrypt or decrypt operationor 1plaintext data and key / ciphertex t data and keyciphertext data / plaintext dataFunctions Unauthenticat ed Symmetric Encryption and Decryption Authenticated Symmetric Encryption andAccess Crypto Officer - AES key: W,E
AES Key Wrapping / Key UnwrappingExecute AES-key wrapping or unwrappi ng operation1key wrapping key, unwrapp ed key / Wrapped key, AES key wrappingwrapped key / unwrappe d keyDecryption key wrapping / key unwrappingCrypto Officer - AES key- wrappin g key: W,E
4 Roles, Services, and Authentication

N/A for this module. FIPS 140-3 does not require an authentication mechanism for level 1 modules. Therefore, the module does not support an authentication mechanism for Crypto Officer. The Crypto Officer role is authorized to access all services provided by the module (see Table - Approved Services and Table - Non-Approved Services).

4.2 Roles

Crypto Officer Role CO None Table 41: Roles

4.3 Approved Services

This document may be reproduced and distributed only in its original entirely without revision.

Page 25
NameInputsOutputs
DescriptioIndicatSecuritySSP
Secure Hash Generationn Generate a digest for the requestedor 1messagedigestFunctions Message DigestAccess Crypto Officer
Message Authentication Generationalgorithm Generate a MAC digest using the requested SHA1message, MAC key, MAC algorithmMACHMAC Message Authenticatio nCrypto Officer - HMAC key: W,E
Message Authentication Code Verificationalgorithm Verify a MAC digest1MAC, message, MAC key, MACpass/failHMAC Message Authenticatio nCrypto Officer - HMAC key:
RSA signature generation and verificationSign a message with a specified RSA private key. Verify the signature of a message with a specified RSA public1algorithm SigGen: private key, message, hash function; SigVer: public key, digital signature, message, hash functionSigGen: compute d signature; SigVer: pass/fail result of digital signature verificatio nRSA Digital Signature Generation RSA Digital Signature VerificationW,E Crypto Officer - RSA key pair: W,E
ECDSA signature generation and verificationkey. Sign a message with a specified ECDSA private key Verify1SigGen: private key, message, hash function; SigVer:SigGen: compute d signature; SigVer: pass/fail result ofECDSA Digital Signature Generation ECDSA Digital Signature VerificationCrypto Officer - ECDSA key pair: W,E

This document may be reproduced and distributed only in its original entirely without revision.

Page 26
NameInputsOutputs
DescriptioIndicatSecuritySSP
n signature of a message with a specified ECDSAorkey, digital signature, message, hash functionsignature verificatio nFunctionsAccess
Random Number Generationpublic key Generate random number1length of generate d numberrandom bit-stringRandom Number GenerationCrypto Officer - Entropy input string: E - DRBG seed, internal state V value, and key:
ECDSA key pair generation and validationGenerate a keypair for a requested elliptic curve and1domain paramete rskey pairECDSA Asymmetric Key Generation ECDSA Public- Key ValidationG,R,E Crypto Officer - ECDSA key pair:
Self-testvalidity execute CASTs1powerpass/fail resultsUnauthenticat ed Symmetric Encryption and Decryption Authenticated Symmetric Encryption and Decryption Random NumberG,R,E Crypto Officer - HMAC key: E - AES key: E - AES key- wrappin g key: E - ECDSA

G,R,E This document may be reproduced and distributed only in its original entirely without revision.

Page 27
NameInputsOutputs
DescriptioIndicatSecuritySSP
norFunctions ECDSA Asymmetric Key Generation ECDSA Public- Key Validation ECDSA Digital Signature Generation ECDSA Digital Signature Verification HMAC Message Authenticatio n key wrapping / key unwrapping RSA Digital Signature Generation RSA Digital Signature Verification MessageAccess pair: E - RSA key pair: E - DRBG seed, internal state V value, and key: E
Show StatusReturn the moduleN/AN/AStatus outputDigest NoneCrypto Officer
Show module version infostatus Return Module Base Name and Module VersionN/AN/AModule informati onNoneCrypto Officer
ZeroizationNumber SSPs are zeroised1N/AN/ANoneCrypto Officer

n when the - AES This document may be reproduced and distributed only in its original entirely without revision.

Page 28
NameInputsOutputs
DescriptioIndicatSecuritySSP
n system is powered down, when all resources of symmetric crypto function context, all resources of hash context, all resources of asymmetri c crypto function context are released.orFunctionsAccess key: Z - AES key- wrappin g key: Z - HMAC key: Z - ECDSA key pair: Z - RSA key pair: Z - Entropy input string: Z - DRBG seed, internal state V value, and

Name Triple-DES encryption /

Description Execute Triple-DES mode

Algorithms Triple-DES [SP 800-

Role CO

Table 42: Approved Services The abbreviations of the access rights to SSPs have the following interpretation: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. N/A = The service does not access any SSP during its operation

4.4 Non-Approved Services

decryption encrypt or decrypt operation. 67r2] This document may be reproduced and distributed only in its original entirely without revision.

Page 29
Name RSA Key EncapsulationDescription The CAST does not perform the full KTS, only the rawAlgorithms RSA Key WrappingRole CO
RSA Signature GenerationRSA encrypt/decrypt. Sign a message with a non- approved RSA private keyRSA SigGenCO
RSA Signature Verificationsize Verify the signature of a message with a non- approved RSA public keyRSA SigVerCO
ECDSA key-pair generation, ECDSA PKV, ECDSA signature generation, ECDSA signaturesize For curve P-192ECDSACO
verification ECDSA Key Pair Generation for compact point representation ofFor compact point representation of pointsECDSA KeyGenCO
points EdDSA Key Generation, Signature Generation, SignatureEd25519EdDSACO
Verification ECIESElliptic Curve encrypt/ decryptIntegrated Encryption Scheme on elliptic curves (ECIES)CO
ANSI X9.63 Key Derivation SP800-56Crev2 Key DerivationSHA-1 hash-based SHA-256 hash-basedANSI X9.63 KDF HKDF [SP800-CO CO
(HKDF) OMAC Message AuthenticationOne-Key CBC-MAC using56Crev2] OMAC (One-KeyCO
Code Generation OMAC Message Authentication128-bit key One-Key CBC-MAC usingCBC MAC) OMAC (One-KeyCO
Code Verification Message digest generation128-bit key Message digest generation using non-approved algorithmsCBC MAC) MD2 MD4 RIPEMDCO
Symmetric encryption / decryptionSymmetric encryption / decryption using non- approved algorithmsMD5 Blowfish CAST5 DES RC2CO
RFC 6637 KDFSHA-256, SHA-512, AES-128,RC4 RFC 6637 KeyCO

This document may be reproduced and distributed only in its original entirely without revision.

Page 30

Table 43: Non-Approved Services

4.5 External Software/Firmware Loaded

N/A This document may be reproduced and distributed only in its original entirely without revision.

Page 31
5 Software/Firmware Security
5.1 Integrity Techniques

A software integrity test is performed on the runtime image of the module. The HMAC-SHA256 implemented in the module is used as the approved algorithm for the integrity test. If the test fails, the module enters an error state where no cryptographic services are provided, and data output is prohibited i.e. the module is not operational.

5.2 Initiate on Demand

The module’s integrity test can be performed on demand by power-cycling the computing platform. Integrity test on demand is performed as part of the Pre-Operational Self-Tests, automatically executed at power-on. This document may be reproduced and distributed only in its original entirely without revision.

Page 32
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable

6.2 Configuration Settings and Restrictions

The module is supplied as part of Device OS, a commercially available general-purpose operating system executing on the computing platforms specified in section 2.2. This document may be reproduced and distributed only in its original entirely without revision.

Page 33
7 Physical Security

The FIPS 140-3 physical security requirements do not apply to the Apple corecrypto Module v13.0 [Apple silicon, Kernel, Software, SL1] since it is a software module. This document may be reproduced and distributed only in its original entirely without revision.

Page 34
8 Non-Invasive Security
8.1 Mitigation Techniques

Per IG 12.A, until the requirements of NIST SP 800-140F are defined, non-invasive mechanisms fall under ISO/IEC 19790:2012 Section 7.12 Mitigation of other attacks. The requirements of this area are not applicable to the module. This document may be reproduced and distributed only in its original entirely without revision.

Page 35
DescriptionPersistence Type
Storage
Area
Name RAMThe module stores ephemeral SSPs in RAM provided by the operational environment. They are received for use or generated by the module only at the command of the calling application. The operating system protects all SSPs through the memory separation and protection mechanisms. No process other than the module itselfDynamic
NameFromToFormat
DistributionEntrySFI or
KPI input parametersOperating calling applicationCryptographic moduleType PlaintextType ManualType ElectronicAlgorithm
KPI output parameters(TOEPP) Cryptographic moduleOperating calling applicationPlaintextManualElectronic
DescriptionRationale
ZeroizationOperator
Method Context object destructionSSPs are zeroised when the appropriate context object is destroyedZeroization when structure is deallocatedInitiation By calling the zeroization function
Power downSSPs are zeroised when the system is powered downSSPs are zeroised when the system is powered downcc_clear Operator can initiate power
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 45: SSP Input-Output Methods

9.3 SSP Zeroization Methods

This document may be reproduced and distributed only in its original entirely without revision.

Page 36
DescriptionRationale
ZeroizationOperator
Method Intermediate value zeroizationIntermediate keygen values are zeroized before the module returns from theIntermediate keygen values are zeroized before the module returns from theInitiation N/A
NameDescriptionType - CategoryGenerated ByEstablishe d ByUsed By
Size -
Strengt
AES keyAES keyh 128 to 256 bits - 128 to 256 bitsSymmetric - CSPUnauthenticate d Symmetric Encryption and Decryption Authenticated Symmetric Encryption and
AES key- wrappin g keyAES KW128 to 256 bits - 128 tosymmetric - CSPDecryption key wrapping / key unwrapping
HMAC keyHMAC key256 bits 128 to 256 - 128 toMAC - CSPHMAC Message Authentication
ECDSA key pairECDSA key pair (including intermediat e keygen values)256 P-224, P-256, P-384, P-521 - 112 to 256 bitsAsymmetri c - CSPECDSA Asymmetri c Key GenerationECDSA Public- Key Validation ECDSA Digital Signature Generation ECDSA Digital Signature
RSA key pairRSA key pair2048 - 4096 - 112 toAsymmetri c - CSPVerification RSA Digital Signature Generation

Table 46: SSP Zeroization Methods Data output interfaces are inhibited while zeroisation is performed.

9.4 SSPs

h This document may be reproduced and distributed only in its original entirely without revision.

Page 37
NameDescriptionType - CategoryGenerated ByEstablishe d ByUsed By
Size -
Strengt
hSignature
Entropy inputEntropy input string256 bits - 256Entropy input stringVerification Random Number
string DRBG seed, internal state V value,DRBG input parametersbits 256 bits - 256 bits- CSP DRBG - CSPRandom Number GenerationGeneration Random Number Generation
NameStorageZeroizationRelated SSPs
Input -Storage
AES keyOutput KPI input parametersRAM:PlaintextDuration From service invocation to serviceContext object destruction
AES key- wrapping keyKPI input parametersRAM:Plaintextcompletion From service invocation to servicePower down Context object destruction
HMAC keyKPI input parametersRAM:Plaintextcompletion From service invocation to servicePower down Context object destruction
ECDSA key pairKPI input parameters KPI output parametersRAM:Plaintextcompletion From service invocation to service completionPower down Context object destruction Power down Intermediate valueDRBG seed, internal state V value, and key:Used With
RSA key pairKPI input parametersRAM:PlaintextFrom service invocation to service completionzeroization Context object destruction Power down

h Table 47: SSP Table 1 This document may be reproduced and distributed only in its original entirely without revision.

Page 38
NameStorageZeroizationRelated SSPs
Input -Storage
OutputDurationvalue
Entropy input stringRAM:PlaintextStorage duration during the usage of thezeroization Power downDRBG seed, internal state V value, and key:Used With
DRBG seed, internal state V value, andCSP Storage duration during the usage of thePower downEntropy input string:Used With

Table 48: SSP Table 2 This document may be reproduced and distributed only in its original entirely without revision.

Page 39
Test MethodIndicatorDetails
AlgorithmTestTest
or Test HMAC- SHA2-256 (A3687)Properties 112-bit keyMessage AuthenticationType SW/FW IntegrityModule successful executionThe HMAC-SHA2-256 value calculated at runtime is compared with the HMAC-SHA2- 256 value stored in the module, computed at
IndicatorDetailsConditions
AlgorithmTestTestTest
or Test AES-GCM (A3685)Properties 128-bit keyMethod KATType CASTModule becomes operationalAuthenticated decryptionTest runs at Power-on before the
Counter DRBG (A3685)AES 128-bit keyKATCASTModule becomes operationalHealth test per SP800- 90ARev1 section 11.3integrity test Test runs at Power-on before the
HMAC- SHA2-256 (A3686)SHA2-256KATCASTModule becomes operationalMessage authenticationintegrity test Test runs at Power-on before the
HMAC- SHA-1SHA-1KATCASTModule becomesMessage authenticationintegrity test Test runs at Power-on
10 Self-Tests

While the module is executing the self-tests, services are not available, and input and output are inhibited.

10.1 Pre-Operational Self-Tests

The module performs a pre-operational software integrity automatically when the module is loaded into memory (i.e., at power on) before the module transitions to the operational state. A used to perform the approved integrity technique. Prior to using HMAC-SHA-256, a Conditional Cryptographic Algorithm Self-Tests (CAST) is performed. compilation time. Table 49: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

This document may be reproduced and distributed only in its original entirely without revision.

Page 40
IndicatorDetailsConditions
AlgorithmTestTestTest
or TestPropertiesMethodTypebefore the
HMAC- SHA2-512 (A3684)SHA2-512KATCASTModule becomes operationalMessage authenticationintegrity test Test runs at Power-on before the
RSA SigGen (FIPS186-4) (A3686)PKCS#1 v1.5 with 2048 bit key and SHA2-KATCASTModule becomes operationalSignature Generation service requestintegrity test Test runs at Power-on before the integrity test
RSA SigVer (FIPS186-4) (A3686)256 PKCS#1 v1.5 with 2048 bit key and SHA2-KATCASTModule becomes operationalSignature Verification service requestTest runs at Power-on before the integrity test
ECDSA KeyGen (FIPS186-4)256 SHA2-256 and respectivePCTPCTSuccessful key generationKey generationKey pair generation.
(A3686) ECDSA SigGen (FIPS186-4)keys P-256 with SHA-256KATCASTModule becomes operationalSignature Generation or Key GenerationTest runs at Power-on before the
(A3686) ECDSA SigVer (FIPS186-4)P-224 with SHA-224KATCASTModule becomes operationalservice request Signature Verification or Key Generationintegrity test Test runs at Power-on before the
(A3686) AES-CBC (A3682)128-bit keyKATCASTModule becomes operationalservice request Encryption and decryption run separatelyintegrity test Test runs at Power-on before the
AES-ECB (A3682)128-bit keyKATCASTModule becomes operationalEncryption and decryption run separatelyintegrity test Test runs at Power-on before the
AES-XTS Testing Revision128-bit keyKATCASTModule becomes operationalEncryptionintegrity test Test runs at Power-on before the

This document may be reproduced and distributed only in its original entirely without revision.

Page 41
IndicatorDetailsConditions
AlgorithmTestTestTest
or Test AES-CCM (A3685)Properties 128-bit keyMethod KATType CASTModule becomes operationalAuthenticated encryption / decryption operations are performedTest runs at Power-on before the integrity test
HMAC- SHA2- 512/256SHA2- 512/256KATCASTModule becomes operationalseparately Message authenticationTest runs at Power-on before the
Test MethodTest TypePeriodPeriodic Method
Algorithm or
Test HMAC-SHA2- 256 (A3687)Message AuthenticationSW/FW IntegrityWhenever module isUpon every power on
Test MethodTest TypePeriodPeriodic Method
Algorithm or
Test AES-GCMKATCASTOn DemandManually
(A3685) Counter DRBGKATCASTOn DemandManually
(A3685) HMAC-SHA2-KATCASTOn DemandManually
256 (A3686) HMAC-SHA-1KATCASTOn DemandManually
(A3686) HMAC-SHA2-KATCASTOn DemandManually
512 (A3684) RSA SigGen (FIPS186-4)KATCASTOn DemandManually
(A3686) RSA SigVer (FIPS186-4)KATCASTOn DemandManually

Table 50: Conditional Self-Tests

10.3 Periodic Self-Test Information

powered on Table 51: Pre-Operational Periodic Information This document may be reproduced and distributed only in its original entirely without revision.

Page 42
Test MethodTest TypePeriodPeriodic Method
Algorithm or
Test ECDSA KeyGen (FIPS186-4)PCTPCTUpon generation of an ECDSA keyUpon generation of an ECDSA key
(A3686) ECDSA SigGen (FIPS186-4)KATCASTpair On Demandpair Manually
(A3686) ECDSA SigVer (FIPS186-4)KATCASTOn DemandManually
(A3686) AES-CBC (A3682)KATCASTOn DemandManually
AES-ECB (A3682) AES-XTS Testing Revision 2.0KAT KATCAST CASTOn Demand On DemandManually Manually
(A3682) AES-CCMKATCASTOn DemandManually
(A3685) HMAC-SHA2-KATCASTOn DemandManually
NameDescriptionConditionsIndicator
Recovery
Error State1) The HMAC- SHA-256 value computed over the module did not match the pre- computed value or 2) The computed value in the invoked Conditional1) Pre- operational Software Integrity Test failure or 2) Conditional CAST failure 3) Conditional PCT failureMethod The only method to recover from the error state is to power cycle the device which results in the module being reloaded into memory and reperforming1) Print statement "FAILED: fipspost_post_integrity" to stdout or 2) Print statement "FAILED:<event>" to stdout (<event> refers to any of the CASTs listed in Conditional Self-Tests Table. 3) Error code "CCEC_GENERATE_KEY_CONSISTENCY" returned for ECDSA error code
10.4 Error States

This document may be reproduced and distributed only in its original entirely without revision.

Page 43
NameDescriptionConditionsIndicator
Recovery
match the known value or 3) The signature failed to verify successfully in the Conditional PCT. No cryptographic services are provided, and data output isMethod operational software integrity test and the Conditional CASTs.

prohibited Table 53: Error States

10.5 Operator Initiation of Self-Tests

The module permits operators to initiate the pre-operational or conditional self-tests on demand for periodic testing of the module by rebooting the system (i.e., power-cycling). This document may be reproduced and distributed only in its original entirely without revision.

Page 44
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Startup Procedures: The module is built into Device OS defined in section 2 and delivered/ installed with the respective Device OS. There is no standalone delivery of the module as a software library. Installation Process and Authentication Mechanisms: The vendor’s internal development process guarantees that the correct version of module goes with its intended Device OS version. For additional assurance, the module is digitally signed by vendor, and it is verified during the integration into Host Device OS. This digital signature-based integrity protection during the delivery/integration process is not to be confused with the HMAC-256 based integrity check performed by the module itself as part of its pre-operational self- tests.

11.2 Administrator Guidance

The Approved mode of operation is configured in the system by default and can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table - Non-Approved Services. If the device starts up successfully, then the module has passed all self-tests and is operating in the Approved mode. The ESV Public Use Document (PUD) reference for physical entropy source is: https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validationprogram/documents/entropy/E14_PublicUse.pdf The ESV Public Use Document (PUD) reference for non-physical entropy source is: https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validationprogram/documents/entropy/E15_PublicUse.pdf Apple Platform Certifications guide [platform certifications] and Apple Platform Security guide [SEC] are provided by Apple which offers IT System Administrators with the necessary technical information to ensure FIPS 140-3 Compliance of the deployed systems. This guide walks the reader through the system’s assertion of cryptographic module integrity and the steps necessary if module integrity requires remediation.

11.3 Non-Administrator Guidance
11.4 Design and Rules

The Crypto Officer shall consider the following requirements and restrictions when using the module.

Page 45
11.6 End of Life

The module secure sanitization is accomplished through the Lost Mode, remote wipe, and remote lock sections of the provided vendor document [platform certifications]. This document may be reproduced and distributed only in its original entirely without revision.

Page 46
12 Mitigation of Other Attacks

The module does not claim mitigation of other attacks. This document may be reproduced and distributed only in its original entirely without revision.

Page 47
Table, extracted as text (did not parse into structured rows)
Appendix A.                   Glossary and Abbreviations AES                    Advanced Encryption Standard CAVP                   Cryptographic Algorithm Validation Program CAST                   Cryptographic Algorithm Self-Test CAST5                  A symmetric-key 64-bit block cipher with 128-bit key CBC                    Cipher Block Chaining CCM                    Counter with Cipher Block Chaining-Message Authentication Code CFB                    Cipher Feedback CMVP                   Cryptographic Module Validation Program CSP                    Critical Security Parameter CTR                    Counter Mode DRBG                   Deterministic Random Bit Generator ECB                    Electronic Code Book ESVP                   Entropy Source Validation Program FIPS                   Federal Information Processing Standards Publication GCM                    Galois Counter Mode HMAC                   Hash Message Authentication Code KAT                    Known Answer Test KDF                    Key Derivation Function KEXT                   Kernel Extension KW                     AES Key Wrap MAC                    Message Authentication Code KPI                    Kernel Programming Interface NIST                   National Institute of Science and Technology OFB                    Output Feedback PAA                    Processor Algorithm Acceleration PKG                    Key-Pair Generation PKV                    Public Key Validation PSS                    Probabilistic Signature Scheme PUD                    Public Use Document (ESVP) RSA                    Rivest, Shamir, Addleman SHA                    Secure Hash Algorithm SHS                    Secure Hash Standard TOEPP                  Tested Operational Environment Physical Perimeter XTS                    XEX-based Tweaked-codebook mode with cipher text Stealing This document may be reproduced and distributed only in its original entirely without revision.
Page 48
Appendix B.References
FIPS140-3FIPS PUB 140-3 - Security Requirements for Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3
SP 800-140xCMVP FIPS 140-3 Related Reference https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-standards
FIPS140-3_IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program September 2020 https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig-announcements
FIPS140-3_MMCMVP FIPS 140-3 Draft Management Manual https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation- program/documents/fips%20140-3/FIPS-140-3-CMVP%20Management%20Manual%20v2.0.pdf
SP 800-140FIPS 140-3 Derived Test Requirements (DTR) https://csrc.nist.gov/publications/detail/sp/800-140/final
SP 800-140ACMVP Documentation Requirements https://csrc.nist.gov/publications/detail/sp/800-140a/final
SP 800-140Br1CMVP Security Policy Requirements https://doi.org/10.6028/NIST.SP.800-140Br1
SP 800-140CCMVP Approved Security Functions https://csrc.nist.gov/publications/detail/sp/800-140c/final
SP 800-140DCMVP Approved Sensitive Security Parameter Generation and Establishment Methods https://csrc.nist.gov/publications/detail/sp/800-140d/final
SP 800-140ECMVP Approved Authentication Mechanisms https://csrc.nist.gov/publications/detail/sp/800-140e/final
SP 800-140FCMVP Approved Non-Invasive Attack Mitigation Test Metrics https://csrc.nist.gov/publications/detail/sp/800-140f/final
FIPS180-4Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS186-5Digital Signature Standard (DSS) F3b 2023 https://doi.org/10.6028/NIST.FIPS.186-5
FIPS197Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf This document may be reproduced and distributed only in its original entirely without revision.
Page 49
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt
RFC3394Advanced Encryption Standard (AES) Key Wrap Algorithm September 2002 http://www.ietf.org/rfc/rfc3394.txt
RFC5649Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm September 2009 http://www.ietf.org/rfc/rfc5649.txt
SP800-38ANIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP800-38CNIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
SP800-38DNIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP800-38ENIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 http://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP800-38FNIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP800-56Cr2Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://doi.org/10.6028/NIST.SP.800-56Cr2
SP800-57NIST Special Publication 800-57 Part 1 Revision 5 - Recommendation for Key Management Part 1: General May 2020 https://doi.org/10.6028/NIST.SP.800-57pt1r5
SP800-67r2NIST Special Publication 800-67 Revision 1 - Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher January 2012 (withdrawn January 2014) https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-67r2.pdf
SP800-90Ar1NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://dx.doi.org/10.6028/NIST.SP.800-90Ar1 This document may be reproduced and distributed only in its original entirely without revision.
Page 50
SP800-90BNIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://doi.org/10.6028/NIST.SP.800-90B
SP800-108r1NIST Special Publication 800-108r1 - Recommendation for Key Derivation Using Pseudorandom Functions Aug 2022 https://doi.org/10.6028/NIST.SP.800-108r1
SP800-131Ar2Transitioning the Use of Cryptographic Algorithms and Key Lengths March 2019 https://doi.org/10.6028/NIST.SP.800-131Ar2
SP800-133r2Recommendation for Cryptographic Key Generation June 2020 https://doi.org/10.6028/NIST.SP.800-133r2
SP800-135r1NIST Special Publication 800-135 Revision 1 - Recommendation for Existing Application-Specific Key Derivation Functions December 2011 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf
SECApple Platform Security https://support.apple.com/guide/security/welcome/web https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/apple-platform-security-guide.pdf