All modules
CMVP Validated Module · FIPS 140-3 Security Policy

SafeCase Security Module

Certificate#5052StandardFIPS 140-3Level2TypeFirmware-hybridEmbodimentSingle ChipStatusActiveVendorPrivoro LLC
Low review priority  ·  no TCB surface named  ·  last validated 11 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeFirmware-hybrid
EmbodimentSingle Chip
StatusActive
Sunset date8/11/2030
CaveatNo assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorPrivoro LLC

Approved Algorithms (15)

AlgorithmACVP Cert
AES-CCMA2494
AES-ECBA2494
ECDSA KeyGen (FIPS186-4)A2494
ECDSA SigGen (FIPS186-4)A2494
ECDSA SigVer (FIPS186-4)A2494
Hash DRBGA2494
HMAC-SHA2-384A2494
KAS-ECC-SSC Sp800-56Ar3A2494
KDA OneStep Sp800-56Cr1A2494
RSA KeyGen (FIPS186-4)A2494
RSA SigGen (FIPS186-4)A2494
RSA Signature PrimitiveA2494
RSA SigVer (FIPS186-4)A2494
SHA2-256A2494
SHA2-384A2494

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for SafeCase Security Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>Show status<br/>self-test</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for SafeCase Security Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>Show status<br/>self-test</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

SafeCase Security Module Document Version D18 July 01, 2025 Prepared for: Prepared by: Privoro LLC KeyPair Consulting Inc.

3100 W. Ray Road, Suite 201 987 Osos Street

Chandler, AZ 85226 San Luis Obispo, CA 93401 privoro.com keypair.us +1 844.774.8676 +1 805.316.5024 Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 2

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy Table of Contents List of Tables List of Figures Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 3
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General2
2Cryptographic Module Specification2
3Cryptographic Module Interfaces2
4Roles, Services, and Authentication2
5Software / Firmware Security2
6Operational EnvironmentN/A
7Physical Security3
8Non-Invasive SecurityN/A
9Sensitive Security Parameters Management2
10Self-tests2
11Life-cycle Assurance2
12Mitigation of Other AttacksN/A
#Operating SystemHardware PlatformProcessorPAA/Acceleration
1Free-RTOSNXP MK81FN256VDC15NXP Kinetis K81FN256xxx15PAA is enabled for the K811
Privoro LLCSafeCase Security Module FIPS 140-3 Security Policy
is a firmware-hybrid module with a single-chip embodiment, updated only by a complete image replacement by Privoro in the SafeCase environment;
does not implement mitigations of attacks outside the [FIPS140-3] specification.

The Module is validated to FIPS 140-3 overall Level 2 requirements with security levels as follows: Table 1: Security Levels The Module is a firmware-hybrid Module as defined by [I19790], operated on a single-chip. The Module provides cryptographic services for use in SafeCase mobile device management systems. The tested Operational Environments are specified in Table 2 below. Table 2: Tested Operational Environments Memory-Mapped Cryptographic Acceleration Unit (MMCAU) within the NXP MK81FN256VDC15 single-chip which is the physical perimeter (TOEPP) of the module. The UID information returned by pcrypt_status contains name (“SCSM”), hardware version (0x81001BD9) for the MMCAU disjoint hardware component and firmware version (“1.0.1”), consistent with the Module’s CMVP listing information and tabularized below: Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 4
#Firmware ComponentFirmware VersionHardware ComponentHardware VersionModule Identifier
1libpcrypt.a1.0.1Hardware accelerator (MMCAU) within the NXP MK81FN256VDC15 i.e. K81 chip0x81001BD9SCSM

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy Table 3: Tested Module Versioning Information/Identification Please Note: The disjoint firmware component of the module is the libpcrypt.a statically linked library (version 1.0.1) and is identified by the identifier returned by the module, i.e. the ‘SCSM’ string as detailed in the table above.

2.1 Cryptographic Boundary

The physical form of the Module is depicted below. The physical perimeter (i.e. the Tested Operational Environment’s Physical Perimeter (TOEPP)) consists of the surfaces, edges and solder connections of the NXP MK81FN256VDC15 integrated circuit shown in Figure 1. Top Bottom Figure 1: Module Physical Perimeter The module is a hybrid module with the disjoint firmware component, libpcrypt.a (executing on the ARM CPU core) and the disjoint hardware component (MMCAU) forming the cryptographic boundary as depicted in the Figure 2 (outlined in red). The libpcrypt.a uses AES hardware cryptographic accleration from the MMCAU. Both the disjoint components Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 5

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy Figure 2: Module Block Diagram

2.2 Modes of Operation, Security Rules and Guidance

The Module supports only an Approved mode of operation by default, and enforces the following security rules:

  1. No additional interface or service is implemented by the Module which would provide access to SSPs.
  2. Data output is inhibited during key generation, self-tests, zeroisation, and error states.
  3. There are no restrictions on which keys or SSPs are zeroised by the zeroisation service.
  4. The Module does not support manual key entry.
  5. The Module does not output plaintext CSPs or intermediate key values.
  6. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module. The Module design corresponds to the Module security rules. No specific installation requirements apply and the initialization process of the Module is as detailed in Section 11 of this document.
2.3 Degraded Operation

The Module does not support a degraded mode of operation.

2.4 Approved and Allowed Cryptographic Functionality

The Module implements the Approved cryptographic functions listed in Table 4. Equivalent strength in bits is given for each key or algorithm type (as some algorithms do not use or produce keys). The term s is used throughout to indicate security strength, following the notation used in the majority of the sources (refer to the notes below Table 4). This table is referenced by Table 13 (SSPs). All references to the algorithm standards cited throughout this document can be found in the References section. Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 6
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A2494AES-ECBAES-ECBAES-256 (s = 256)Encryption (used only as a pre-
[FIPS197], [SP800-38A]requisite for AES-CCM)
A2494AES-CCM [SP800-38C]AES-CCMAES-256 (s = 256)Authenticated encryption
Vendor AffirmedCKGDirect256-bitCitation of [SP800-133r2]
[SP800-133r2]The module supports the followingcompliance required per [FIPS140-
sections per NIST [SP800-133r2]: 4, 5.1, 5.2, 5.3, 5.4, 6.1, 6.2.1, 6.4 and 6.5.3_IG] D.H Scenario 2
A2494ECDSA KeyGen [FIPS186-4]Secret Generation Mode: Extra BitsP-384 (s ~= 192) See Note 2Key generation
A2494ECDSA SigGenSigGen (tested with SHA2-384)P-384 (s ~= 192)Signature generation
[FIPS186-4]See Note 2
A2494ECDSA SigVer [FIPS186-4]SigVer (tested with SHA2-384)P-384 (s ~= 192) See Note 2Signature verification
A2494ENTENT (P)1024-bit seed;DRBG seeding
[SP800-90B]1024-bit nonce
A2494Hash DRBG [SP800-90Ar1]No prediction resistanceSHA2-256 (s = 256)Random bit generation
A2494HMAC-SHA2-384 [FIPS198-1]Generate HMAC-SHA2-384 MACSHA2-384 (s = 384)HMAC generation and verification
A2494KAS [SP800-56Ar3]Schemes: Ephemeral Unified Roles: Initiator, Responder KAS-ECC-SSC curves: P-384 KDA One-Step KDFKAS-ECC per IG D.F Scenario 2 path (2) option 2 P-384 curve providing 192 bits of encryption strengthKey agreement with key derivation using [SP800-56Cr1] KDA
A2494KAS-ECC-SSCScheme: ephemeralUnifiedP-384 (s ~= 192)Shared secret generation
[SP800-56Ar3]KAS Role: initiator, responder IG D.F Scenario 2 path 2 with an approved KDF per [SP800-56Ar3]See Note 2 and Note 3
A2494KDA OneStep [SP800-56Cr1]One-Step KDF Auxiliary function method: SHA2-384SHA2-384 (112 ≤ s ≤ 384) See Note 6Derivation of keying material from a KAS shared secret
A2494RSA KeyGenKey generation mode: B.3.3k=2048 (s ~= 112)Key generation
[FIPS186-4]Primality tests per Table C.3See Note 5
A2494RSA SigGen [FIPS186-4]Signature type: PKCS 1.5 tested with k=2048 and SHA2-256k=2048 (s ~= 112) See Note 4 and Note 5Signature generation
A2494RSA SignaturePrivate Key format: standardk=2048 (s ~= 112)Signature primitive operation
Primitive [FIPS186-4]Public Exponent Mode: fixedSee Note 4 and Note 5
A2494RSA SigVer [FIPS186-4]Signature type: PKCS 1.5 tested with k=2048 and SHA2-256k=2048 (s ~= 112) See Note 4 and Note 5Signature verification
A2494SHA2-256SHA2-256SHA2-256 (s = 256)Secure hash generation
[FIPS180-4]See Note 1

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy 6.5. Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 7
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A2494SHA2-384 [FIPS180-4]SHA2-384SHA2-384 (s = 384) See Note 1Secure hash generation

Algorithm RSADP

Caveat No security claimed

Use/Function Decryption of derived keying material, [FIPS 140-3_IG] 2.4.A Scenario 1

Physical portLogical Interface Control InputData that passes over port/interface API entry point: stack frame including non-sensitive parameters
N/A: InternalData InputAPI call parameters passed by reference or value for cryptographic service input
(call stack)Status OutputAPI return value: enumerated status resulting from call execution
Data OutputAPI call parameters passed by reference for cryptographic service output

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy Note 1: Preimage resistance strength applies to hash algorithms used in DRBG, KDFs. Described also in [SP800-57P1r5] Table

  1. Note 2: Elliptic curve strengths are annotated as approximate (i.e., s ~=) since [SP800-186] Table 1 provides approximate security strengths. Note 3: Approved elliptic curves for ECC key agreement are given in [SP800-56Ar3] Table
  2. Note 4: In Digital Signature applications, security strength is primarily associated with the asymmetric key pair specification. The hash function used must have equivalent strength equal to or greater than the security strength of the associated key pair. Note 5: Estimated security strengths of common RSA moduli are given in [SP800-56Br2] Table
  3. IFC key types approved for Digital Signature Generation and Verification are given also in [SP800-57P1r5] Table
  4. Equivalent strengths are annotated as approximate (i.e., s ~=) since [SP800-56Br2] Table 4 provides approximate security strengths. Note 6: Security strengths for KDA One Step are given in [SP800-56Cr1] Table 1 (hash). Reference sources for the strengths provided in Table 4 are as follows: • AES (AES-256): [SP800-57P1r5] Table 2. • ECC (P-384): [SP800-186] Table 1. • IFC (k=2048): [SP800-56Br2] Table 4. • SHA2 (SHA2-256, SHA2-384): [SP800-107r1] Table
  5. Table 5: Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed Please see the note below Table 9 pertaining to usage of RSADP. The module does not implement the following: • Non-Approved Algorithms Allowed in the Approved Mode of Operation • Non-Approved Algorithms Not Allowed in the Approved Mode of Operation
3 Cryptographic Module Interfaces

The Module’s logical interfaces are described in Table 6; the Module’s physical ports are outside the cryptographic boundary. Table 6: Ports and Interfaces The Control Output interface is not applicable, as the module does not control other components. Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 8
RoleServiceInputOutput
COpcrypt_aesccm_decryptSC_EDK; ciphertext messagePlaintext message; status
COpcrypt_aesccm_encryptSC_EDK; plaintext messageCiphertext message; status
N/Apcrypt_aes_free (Perform zeroisation)AES struct (includes SC_EDK)Status (AES struct zeroised, freed)
COpcrypt_aesccm_initSC_EDKInitialized AES struct; status
COpcrypt_ecc_export_privateECC struct inclusive of ECC_PrivateECC_Private; status
COpcrypt_ecc_export_publicECC struct inclusive of ECC_PublicECC_Public; status
COpcrypt_ecc_import_privateECC_PrivateInitialized ECC struct; status
COpcrypt_ecc_import_publicECC_PublicInitialized ECC struct; status
COpcrypt_ecc_init_keyECC_Private; ECC_PublicInitialized ECC struct; status
N/Apcrypt_ecc_free (Perform zeroisation)ECC struct (includes ECC_Private, ECC Public, ECC_SGK, ECC SVK)Status
COpcrypt_ecc_gen_keyECC key parametersInitialized ECC struct; status
COpcrypt_ecc_signECC_SGK; plaintext messageSignature; status
COpcrypt_ecc_verify_hashECC_SVK; plaintext message; signatureStatus
COpcrypt_hmac_initHMAC_MHK, uninitialized HMAC structInitialized HMAC struct, status
COpcrypt_hmac_updateHMAC struct, messageStatus
COpcrypt_hmac_finalizeHMAC struct, output buffer pointerOutput buffer containing HMAC tag
N/Apcrypt_hmac_free (Perform zeroisation)HMAC struct (includes HMAC_HMK)Status
COpcrypt_initPassword; memory management parametersStatus
COpcrypt_key_exchangeKAS_U_Private; KAS_V_Public; KAS_SSKAS_DKM; status
COpcrypt_rng_generate_blockRBG_StateRandom bit string; RBG_State; status
COpcrypt_rng_initRBG_EI; RBG_State; parameters; flagsDRBG struct; status
COpcrypt_rsa_export_privateRSA struct inclusive of RSA_PrivateRSA_Private; status
COpcrypt_rsa_export_publicRSA struct inclusive RSA_PublicRSA_Public; status
COpcrypt_rsa_import_privateRSA_PrivateInitialized RSA struct; status
N/Apcrypt_rsa_free (Perform zeroisation)RSA struct (includes RSA_Private, RSA Public, RSA_SGK, RSA_SVK)Status
COpcrypt_rsa_gen_keyRSA parametersInitialized RSA struct; status
COpcrypt_rsa_initRSA_Private; RSA_PublicInitialized RSA struct; status
COpcrypt_rsa_signRSA_SGK; plaintext messageSignature; status
COpcrypt_rsa_verifyRSA_SVK; plaintext message; signatureStatus
COpcrypt_sha256_hashPlaintext messageMessage digest; status
COpcrypt_sha384_hashPlaintext messageMessage digest; status
COpcrypt_selftest (Perform self-tests)NoneStatus
N/Apcrypt_status (Show statusValid pointer to UID structure (optional)Status: READY or ERROR
and Show module’sUID: name, version; hardware
versioning information)version
COpcrypt_tamper_detectedNoneStatus

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy

4 Roles, Services and Authentication

The Module supports only the Cryptographic Officer (CO) role. It does not support multiple concurrent operators, a maintenance role or bypass capability. Operator authentication is described in Table 8. Table 7: Roles, Service Commands, Input and Output Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 9
RoleServiceInputOutput
COpcrypt_uninit (Perform zeroisation)NoneStatus
N/Apcrypt_update_timeTime valueNone
RoleAuthentication Method Authentication Strength
COAuthentication of a 256-bit memorized secret, in accordance with [SP800-140E] and [SP800-63B]; 2 authentication attempts require at least 50 µs 9256 = 1.16E+77 .65E+71 in 1 minute
RolesAccess rights to Keys and/or SSPsIndicator
Approved SecurityKeys and/or
ServiceDescription
FunctionsSSPs
pcrypt_aesccm_decryptAuthenticated decryptAES-CCM #A2494 AES-ECB #A2494SC_EDKCOWEZSW
pcrypt_aesccm_encryptAuthenticated encryptAES-CCM #A2494 AES-ECB #A2494SC_EDKCOWEZSW
pcrypt_aesccm_initInitialize AES CCM structN/ASC_EDKCOWRZSW
pcrypt_ecc_export_private, pcrypt_ecc_export_public, pcrypt_ecc_import_private, pcrypt_ecc_import_publicExtract ECC key (from struct) Initialize ECC structN/AECC_Private ECC_PublicCOWRZ WRZSW
pcrypt_ecc_init_keyInitialize an ECC key structN/AECC_Private ECC_PublicCOWRZ WRZSW
pcrypt_ecc_gen_keyGenerate ECC key pairECDSA KeyGen #A2494 CKGECC_Private ECC_PublicCOGRZ GRZSW
pcrypt_ecc_signGenerate ECDSA signatureECDSA SigGen #A2494ECC_SGKCOEWZSW
pcrypt_ecc_verify_hashVerify ECDSA signatureECDSA SigVer #A2494ECC_SVKCOEWZSW
pcrypt_hmac_initInitialize HMACHMAC-SHA2-384 #A2494HMAC_HMKCOWESW
pcrypt_hmac_updateUpdate HMACHMAC-SHA2-384 #A2494HMAC_HMKCOESW
pcrypt_hmac_finalizeGenerate HMAC tagHMAC-SHA2-384 #A2494HMAC_HMKCOEZSW
pcrypt_initInitialize the Module; executes FW integrity test and all CASTsSHA2-256 #A2494, SHA2-384 #A2494PW_Entry PW_RefCOESW
pcrypt_key_exchangeKey agreement andKAS-ECC-SSC #A2494,KAS_U_PrivateCOEWZ EWZ GEZ GRZSW
subsequent derivation ofKDA OneStep #A2494KAS_V_Public
keying material from aKAS_SS
shared secretKAS_DKM
pcrypt_rng_generate_blockGenerate random bitsHash DRBG #A2494RBG_StateCOWERSW

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy The pcrypt_status service does not require authentication and provides information to address both AS04.13 (Show module’s versioning information) and AS04.14 (output current status). The Module is similar to [FIPS140-3_IG] 2.4.C Scenario 2, where pcrypt_status provides a global dynamic indication of Module status and operation in the approved mode, augmented by a status value returned on each API call. The module supports role-based authentication. Table 9 describes all Approved services and service access to SSPs. The following annotations indicate the type of access G = Generate: The Module generates or derives the SSP. E = Execute: The Module uses the SSP in performing a R = Read: The SSP is read from the Module (e.g., the SSP is output). cryptographic operation. W = Write: The SSP is updated, imported, or written to the Module. Z = Zeroise: The Module zeroises the SSP. Table 9: Approved Services Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 10
RolesAccessIndicator
Approved SecurityKeys and/orrights to
ServiceDescription
FunctionsSSPs RBG_SeedKeys and/or SSPs
pcrypt_rng_initInstantiate DRBGHash DRBG #A2494RBG_EICOEZSW
RBG_StateEG
pcrypt_rsa_export_private, pcrypt_rsa_export_public, pcrypt_rsa_import_privateExtract RSA key (from struct) Initialize RSA structN/ARSA_Private RSA_PublicCOWRZSW
pcrypt_rsa_gen_keyGenerate RSA key pairRSA KeyGen #A2494RSA_PrivateCOGRZSW
CKGRSA_Public
pcrypt_rsa_initInitialize RSA structN/ARSA_Private RSA_PublicCOWRZSW
pcrypt_rsa_signRSA sign a hashed messageRSA SigGen #A2494 RSA Signature Primitive #A2494RSA_SGKCOWEZSW
pcrypt_rsa_verifyVerify RSA signatureRSA SigVer #A2494RSA_SVKCOWEZSW
pcrypt_sha256_hashGenerate a message digestSHA2-256 #A2494N/ACON/ASW
pcrypt_sha384_hashGenerate a message digestSHA2-384 #A2494N/ACON/ASW
pcrypt_selftest (PerformOn-demand invocation ofN/AN/ACON/ASW
self-tests)self-tests
pcrypt_status (Show status and Show module’s versioning information)Provide Module statusN/AN/AN/AN/ASW
pcrypt_tamper_detectedTamper detectionN/AN/ACON/ASW
pcrypt_uninit pcrypt_aes_free pcrypt_ecc_free pcrypt_hmac_free pcrypt_rsa_free (Perform zeroisation)Zeroise the DRBG and release struct memory, zeroising SSPsN/ARBG_EI RBG_State RBG_Seed SC_EDK ECC_Private ECC_Public ECC_SGK ECC_SVK HMAC_HMK RSA_Private RSA_Public RSA_SGK RSA_SVK KAS_DKM KAS_U_ Private KAS_V_Public KAS_SSN/AZSW
pcrypt_update_timeUpdate module timeN/AN/AN/AN/ASW

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy SW refers to the enumerated status return value, encoded in two bytes. The least significant byte gives status as one of the following: PCRYPT_STATUS_READY: Module operation successful/normal PCRYPT_STATUS_NOINIT: Module not initialized (Default startup state) PCRYPT_STATUS_STFAIL: Module self-test failure PCRYPT_STATUS_BADARG: Module passed invalid argument Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 11
Physical Security MechanismRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Single-chip packagingThe Module is intended to be mounted in additional packaging; physical inspection of the chip is not practical after packagingN/A
Temperature or voltage measurementSpecify EFP or EFTSpecify if this condition results in a shutdown or zeroisation
Low Temperature-40 CEFPShutdown (inoperable state)
High Temperature+105 CEFPShutdown (inoperable state)
Low Voltage1.54 VEFPShutdown (inoperable state)
High Voltage3.72 VEFPShutdown (inoperable state)
Hardness tested temperature measurement
Low Temperature-40 C

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy PCRYPT_STATUS_DISABLED: Module is disabled (tamper detected) PCRYPT_STATUS_ERROR: Module internal error The most significant byte indicates the use of a non-Approved algorithm; at the time of validation, this only applies to RSA Decrypt (RSADP). PCRYPT_STATUS_FIPS_NOALLOW: set to 1 if the service does not use an approved algorithm. Usage of RSADP is deemed non-Approved but allowed and conforms to [FIPS 140_3_IG] 2.4.A example scenario 1. All functions zeroise SSPs within the function scope after use. Call stack cleanup is the responsibility of the application. The Module-provided methods to deallocate memory perform active zeroisation (overwriting with zeros) prior to deallocation. Zeroisation of PW_Ref requires destruction of the firmware image via the SafeCase product Crypto Reset function (Table 13 “Z2”). As allowed by [SP800-140DTR] VE09.38.03, this mechanism is provided as a service of the SafeCase product. The indicator of zeroisation is a status word (SW) returned by the module as specified above.

5 Software/Firmware Security

The executable form of the disjoint firmware component of the Module is a firmware library statically linked in the SafeCase firmware. During initialization (without operator intervention and prior to operation), it performs an ECDSA P-

384 with SHA2-384 signature verification over all files in the Module boundary. The operator can initiate the integrity test

on demand by either power cycling the Module or by invoking the pcrypt_init service. The module does not support loading of firmware from an external source.

6 Operational Environment

The Module executes in a limited operational environment as defined by [I19790]. The module does not support loading firmware from an external source. The Module is a single-chip embodiment as shown in Figure 1 with a tamper evident hard coating applied to it. The singleNo actions are required by the operator(s) to ensure that the physical security is maintained. Table 10: Physical Security Inspection Guidelines Table 11: EFP/EFT Table 12: Hardness testing temperature ranges Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 12

High Temperature

+105 C

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy

8 Non-Invasive Security

[SP800-140F] currently does not define applicable metrics. The Module does not implement non-invasive security measures. Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 13
Strength2n o it a r e n e Gt r o p x E / t r o p m It n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Z
Key/SSPSecurity FunctionUse & related keys
Name/Typeand Cert. Number
ECC_Private192ECDSA KeyGenG2IE1--S1Z1Private component of ECC key pair generated on
CSP#A2494MDcaller request (key pair purpose is unspecified);
CKG/EErelated to ECC_Public
ECC_Public PSP192ECDSA KeyGen #A2494 CKGG2IE1 MD /EE--S1Z1Public component of ECC key pair generated on caller request (key pair purpose is unspecified); related to ECC_Private
ECC_SGK192ECDSA SigGen--IE1--S1Z1Private key for ECC signature generation; related to
CSP#A2494MD /EEECC_SVK
ECC_SVK PSP192ECDSA SigVer #A2494--IE1 MD /EE--S1Z1Public key for ECC signature verification; related to ECC_SGK
HMAC_HMK384HMAC-SHA2-384--IE1--S1Z1Key to generate and verify and HMAC
CSP#A2494MD /EE
KAS_DKM CSP112 ≤ s ≤ 384KDA OneStep #A2494--IE1 MD /EEE2S1Z1Key Derivation derived keying material3
KAS_U_Private192KAS-ECC-SSC--IE1--S1Z1Private key pair component provided by the local
CSP#A2494MDparticipant, used for Diffie-Hellman shared secret
/EEgeneration; related to KAS_V_Public
KAS_V_Public PSP192KAS-ECC-SSC #A2494--IE1 MD /EE--S1Z1Public key pair component provided by the local participant, used for Diffie-Hellman shared secret generation; related to KAS_U_Private
KAS_SS192KAS-ECC-SSC----E1 E2S1Z1Shared secret calculation; z output value is
CSP#A2494expected to be used by a KDF
PW_Entry CSP256N/A--IE1 MD /EE--S1Z1Authentication input
PW_Ref256SHA2-256,--IE2--S2Z2Authentication reference (hashed)
CSPSHA2-384
RBG_EI CSPSee Table 14ENT (P)G3----S1Z1Entropy input and nonce

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy

9 Sensitive Security Parameters Management

Table 13 summarizes the SSPs implemented by the Module. Table 13: SSPs Generation Import/Export Establishment Zeroisation Storage Strength is provided in bits. Please refer to Table 4 and the notes below it for the strength provenance (traceability to applicable standards and special publications). The separation into specific keys is done outside the scope of the module but must be conformant to [SP800-56Cr1]. Privoro Public Material – may be reproduced only in its original entirety (without revision)

Page 14
Strength2n o it a r e n e Gt r o p x E / t r o p m It n e m h s ilb a t s Ee g a r o t Sn o it a s io r e Z
Key/SSPSecurity FunctionUse & related keys
Name/Typeand Cert. Number
RBG_Seed440 bitsENT (P), CounterG3----S1Z1DRBG seed derived from the entropy input
CSPDRBG
RBG_State CSP256Hash DRBG #A2494----E3S1Z1Hash DRBG (SHA2-256) state: V (440 bits) and C (440 bits)
RSA_Private112RSA KeyGenG1IE1--S1Z1Private component of RSA key pair generated on
CSP#A2494MDcaller request (key pair purpose is unspecified);
CKG/EErelated to RSA_Public
RSA_Public PSP112RSA KeyGen #A2494 CKGG1IE1 MD /EE--S1Z1Public component of RSA key pair generated on caller request (key pair purpose is unspecified); related to RSA_Private
RSA_SGK112RSA SigGen--IE1--S1Z1Private key for RSA signature generation; related
CSP#A2494MDto RSA_SVK
RSA Signature Primitive #A2494/EE
RSA_SVK PSP112RSA SigVer #A2494--IE1 MD /EE--S1Z1Public key for RSA signature verification; related to RSA_SGK
SC_EDK256AES-CCM #A2494--IE1--S1Z1AES key used for symmetric encryption (including
CSPAES-ECB #A2494MD /EEAES authenticated encryption)
Entropy sourcesMinimum number of bits of entropyDetails
K814 ENT (P)[SP800-90Ar1] min_length: 256 bits [SP800-90Ar1] seedlen: 440 bits[FIPS140-3_IG] 9.3.A: The Module generates entropy within the Module’s physical perimeter: option 1(b) using a [SP800-90B] compliant ENT present on the SoC component Per [SP800-90Ar1] Table 2, the SHA2-256 Hash DRBG requires 256 bits of entropy (equivalent to security strength) within the 440-bit DRBG_Seed value As input to the [SP800-90Ar1] Hash_df, the Module collects 1024 bits of data from the ENT to use as entropy and nonce input. The [SP800-90B] compliant assessment supports at least
Table, extracted as text (did not parse into structured rows)
Privoro LLC                                                                                                                  SafeCase Security Module FIPS 140-3 Security Policy Generation   Import/Export   Establishment             Zeroisation Storage Legend Generation                                       Establishment                                                                         Storage G1: [FIPS186-4] RSA keypair generation           E1: [SP800-56Ar3] §5.7.1.2 ECC CDH                                                    S1: RAM G2: [FIPS186-4] ECDSA keypair generation         E2: [SP800-56Cr1] KDA OneStep Generate; Reseed                                                                      Z1: Cleared after use, module initiated Import/Export                                                                                                                          Z2: Cleared by Crypto Reset, operator IE1: Call stack (API) parameters                                                                                                       initiated IE2: Entered in manufacturing Table 14: Non-Deterministic Random Number Generation Specification K81= NXP MK81FN256VDC15 Privoro Public Material – may be reproduced only in its original entirety (without revision)
Page 15

Entropy sources

Minimum number of bits of entropy

Details 0.99 bits of entropy per bit of ENT output; as such the DRBG seeding material contains at least 1013 bits of entropy, well in excess of the requirement

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy

10 Self-tests

Each time the Module is powered on, it tests that the cryptographic algorithms still operate correctly, and that sensitive data has not been damaged. CASTs are available on demand and can be tested periodically using the pcrypt_selftest command. The integrity test can be run on demand by either power cycling the Module or by invoking the pcrypt_init service. The disjoint firmware component of the module, i.e., the libpcrypt.a, performs an ECDSA P-384 with SHA2-384 signature verification over all files in the Module boundary during module initialization i.e. on every boot. On power-on or reset, the Module performs the self-tests described below. All cryptographic algorithm self-tests (CASTs) must complete successfully prior to any other use of cryptography by the Module. The ECDSA CASTs are performed prior to the firmware integrity test. All CASTs are implemented as known answer tests. If one of the CASTs or the firmware integrity test fails, the Module enters the STFAIL error state. The error state is persistent, and no services are available. All attempts to use the Module’s services result in the return of a non-zero error code, PCRYPT_STATUS_STFAIL. A power-cycle or reset of the Module is required to recover from an error state, causing it to retry all self-tests. Pre-Operational Self-Tests

Page 16

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy

11 Life-cycle Assurance

The Privoro SafeCase Security Module FIPS 140-3 Guidance [GD] describes all procedures for secure installation, initialization, configuration, provisioning, decommissioning and sanitization of the Module. The Module is a component of the SafeCase product, integrated in the Privoro manufacturing setting and thus no further installation procedures are required of the Crypto Officer. The initialization process for the module involves loading the module and successfully authenticating to it as the Crypto Officer using the pcrypt_init service. There are no maintenance requirements for the Module.

12 Mitigation of Other Attacks

The Module does not implement mitigations of other attacks outside the scope of [FIPS140-3]. References

Page 17

Privoro LLC SafeCase Security Module FIPS 140-3 Security Policy

Page 18
Table, extracted as text (did not parse into structured rows)
Privoro LLC                                                                        SafeCase Security Module FIPS 140-3 Security Policy •    ECC: Elliptic Curve Cryptography •    ECDSA: Elliptic Curve Digital Signature Algorithm, see [FIPS186-4] •    FIPS: Federal Information Processing Standard •    HMAC: Keyed-Hash Message Authentication Code, see [FIPS198-1] •    IG: Implementation Guidance, see [FIPS140-3_IG] •    KAS: Key Agreement Scheme •    KDF: Key Derivation Function •    MAC: Message Authentication Code •    NIST: National Institute of Standards and Technology •    OE: Operating Environment •    PCT: Pairwise Consistency Test •    PSP: Public Security Parameter •    RSADP: RSA Decryption Primitive •    SHA/SHS: Secure Hash Algorithm/Standard, see [FIPS180-4] •    SP: NIST Special Publication •    SSC: Shared Secret Calculation •    SSP: Sensitive Security Parameter Privoro Public Material – may be reproduced only in its original entirety (without revision)