All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Infinera G42

Certificate#5064StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorNokia Corporation
Low review priority  ·  exposes firmware-update authentication  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date9/21/2030
CaveatWhen installed, initialized and configured as specified in Section Secure Operation in Section 11 of the Security Policy
VendorNokia Corporation

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Infinera G42
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load<br/>upgrade<br/>Update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>kernel<br/>bootloader<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Infinera G42
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load<br/>upgrade<br/>Update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>kernel<br/>bootloader<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Nokia Corporation Infinera G42 © 2021-2025 Nokia Corporation

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware7
Table 3: Modes List and Description8
Table 4: Approved Algorithms13
Table 5: Vendor-Affirmed Algorithms13
Table 6: Security Function Implementations19
Table 7: Entropy Certificates20
Table 8: Entropy Sources21
Table 9: Ports and Interfaces22
Table 10: Authentication Methods25
Table 11: Roles26
Table 12: Approved Services92
Table 13: Mechanisms and Actions Required94
Table 14: Storage Areas94
Table 15: SSP Input-Output Methods95
Table 16: SSP Zeroization Methods96
Table 17: SSP Table 1106
Table 18: SSP Table 2122
Table 19: Pre-Operational Self-Tests125
Table 20: Conditional Self-Tests132
Table 21: Pre-Operational Periodic Information134
Table 22: Conditional Periodic Information138
Table 23: Error States139
Figure 1: Infinera G42 Module Front View6
Figure 2: Infinera G42 IOP Card6
Figure 3: Infinera G42 XMM4 Card6
Figure 4: Infinera G42 CHM6 Card6
Figure 5: Infinera G42 Module Back View7
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication3
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
2.1 Description

Purpose and Use: The Infinera G42 is a next-generation compact modular transport network elements deployed as part of a point-to-point, point-to-multipoint network for terrestrial and/or subsea applications. The G42 chassis provides multi-service client access (e.g. Ethernet, Optical Transport Network (OTN), etc.) to the Dense Wavelength Division Multiplexing (DWDM) transport bandwidth. The module is operated in a limited operational environment. Module Type: Hardware Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: The module is a multiple-chip standalone hardware cryptographic module. The cryptographic boundary is defined as the entire chassis unit’s physical perimeter encompassing the "top," "front," "left," "right," “rear” and "bottom" surfaces of the case and shown in the figures below and in the Physical Security section. These modules are described in more detail further below in this section. © 2021-2025 Nokia Corporation

Page 6

Figure 1: Infinera G42 Module Front View Figure 2: Infinera G42 IOP Card Figure 3: Infinera G42 XMM4 Card Figure 4: Infinera G42 CHM6 Card © 2021-2025 Nokia Corporation

Page 7
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
G42Chassis G42, Controller Card XMM4, GX-IOP, Line Card [CHM6- C8, CHM6S-C14, CHM6S-C15 or CHM6-L8], and Filler Plate (GX-BLANK)R6.2.2 or R6.2.3Intel Atom C3558, EFR32MG21B010F1024IM32, Zynq UltraScale+ and NXP LS1012

Figure 5: Infinera G42 Module Back View

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 8
Mode NameDescriptionTypeStatus Indicator
Approved ModeThe module is only operated in Approved mode of operation after initial operations are performedApprovedApproved mode message is displayed via the module's status output interface
AlgorithmCAVP CertPropertiesReference
AES-CBCA4956Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4956Key Length - 128, 192, 256SP 800-38C
AES-CCMA4958Key Length - 128, 192, 256SP 800-38C
AES-CMACA4958Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA4956Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
2.3 Excluded Components

N/A for this module. Modes List and Description: Table 3: Modes List and Description By default, the module is delivered with a non-compliant state but supports an Approved mode following the steps in section "Secure Operation" of this document by the Crypto Officer, the module can only operate in the Approved mode. The module does not claim implementation of The tables in section 2.5 below list all Approved security functions of the module, including specific key size(s) (in bits unless noted otherwise) employed for Approved services, and implemented modes of operation. There are some algorithm modes that were tested but not implemented by the module. Only the algorithms, modes, and key sizes that are implemented by the module are shown in these tables

2.5 Algorithms

Approved Algorithms: © 2021-2025 Nokia Corporation

Page 9
AlgorithmCAVP CertPropertiesReference
AES-CTRA4958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBC482Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-GCMA4956Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-GCMA4958Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA4959Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMC501Direction - Decrypt, Encrypt IV Generation - External Key Length - 256SP 800-38D
Counter DRBGA4958Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA4959Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A4958Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A4959Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA SigGen (FIPS186-4)A4958Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigGen (FIPS186-4)A4959Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A3366Component - No Curve - P-192, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4948Component - No Curve - P-521 Hash Algorithm - SHA2-512FIPS 186-4
Page 10
AlgorithmCAVP CertPropertiesReference
ECDSA SigVer (FIPS186-4)A4949Component - No Curve - P-521 Hash Algorithm - SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4952Component - No Curve - P-521 Hash Algorithm - SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4953Component - No Curve - P-521 Hash Algorithm - SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4955Component - No Curve - P-521 Hash Algorithm - SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4956Component - No Curve - P-521 Hash Algorithm - SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4958Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A4959Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A4960Component - No Curve - P-521 Hash Algorithm - SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4961Component - No Curve - P-521 Hash Algorithm - SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4962Component - No Curve - P-521 Hash Algorithm - SHA2-512FIPS 186-4
HMAC-SHA-1A4956Key Length - Key Length: 128-512 Increment 128FIPS 198-1
HMAC-SHA-1A4958Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A4956Key Length - Key Length: 128-512 Increment 128FIPS 198-1
HMAC-SHA2- 256A4957Key Length - Key Length: 64-2048 Increment 8FIPS 198-1
HMAC-SHA2- 256A4958Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A4959Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A4956Key Length - Key Length: 384-1024 Increment 320FIPS 198-1
HMAC-SHA2- 384A4958Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
Page 11
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 512A4956Key Length - Key Length: 512-1024 Increment 256FIPS 198-1
HMAC-SHA2- 512A4958Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A4959Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4958Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-ECC-SSC Sp800-56Ar3A4959Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A4958Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP- 4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF IKEv2 (CVL)A4958Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 384-2048 Increment 1664 Derived Keying Material Length - Derived Keying Material Length: 1056, 2432 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF IKEv2 (CVL)A4959Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 384-2048 Increment 1664 Derived Keying Material Length - Derived Keying Material Length: 1056, 2432 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF SNMP (CVL)A4958Password Length - Password Length: 64, 96SP 800-135 Rev. 1
KDF SSH (CVL)A4958Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
PBKDFA4958Iteration Count - Iteration Count: 10-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8SP 800-132
RSA KeyGen (FIPS186-4)A4958Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096FIPS 186-4
Page 12
AlgorithmCAVP CertProperties Primality Tests - Table C.2 Private Key Format - StandardReference
RSA KeyGen (FIPS186-4)A4959Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4958Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigGen (FIPS186-4)A4959Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4958Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4959Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
Safe Primes Key GenerationA4958Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192SP 800-56A Rev. 3
SHA-1A4956Message Length - Message Length: 8-51200 Increment 8FIPS 180-4
SHA-1A4958Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-256A3366Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A4956Message Length - Message Length: 8-51200 Increment 8FIPS 180-4
SHA2-256A4957Message Length - Message Length: 8-51200 Increment 8FIPS 180-4
SHA2-256A4958Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-256A4959Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-384A4956Message Length - Message Length: 8-51200 Increment 8FIPS 180-4
SHA2-384A4958Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-512A4948Message Length - Message Length: 8-51200 Increment 8FIPS 180-4
SHA2-512A4949Message Length - Message Length: 8-51200 Increment 8FIPS 180-4
SHA2-512A4952Message Length - Message Length: 1536-4096 Increment 8FIPS 180-4
SHA2-512A4953Message Length - Message Length: 1536-4096 Increment 8FIPS 180-4
SHA2-512A4954Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-512A4955Message Length - Message Length: 8-51200 Increment 8FIPS 180-4
Page 13
AlgorithmCAVP CertPropertiesReference
SHA2-512A4956Message Length - Message Length: 8-51200 Increment 8FIPS 180-4
SHA2-512A4958Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-512A4959Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-512A4960Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-512A4961Message Length - Message Length: 1536-65536 Increment 8FIPS 180-4
SHA2-512A4962Message Length - Message Length: 8-51200 Increment 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4958Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A4958HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHESP 800-135 Rev. 1
NamePropertiesImplementationReference
CKGKey Type:AsymmetricN/ASP 800-133r2 Section 4, Method 1

Table 4: Approved Algorithms Vendor-Affirmed Algorithms: Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations
Page 14
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2)CKG KAS-KeyGenKAS ECC KeyGen in SSH, TLS and Control Plane IKEv2 servicesCounter DRBG CKG
KAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)CKG KAS-KeyGenKAS FFC KeyGen in SSH, TLS and Control Plane IKEv2 servicesCounter DRBG Safe Primes Key Generation CKG
KAS-ECC- KeyGen (Data Plane IKEv2)CKG KAS-KeyGenKAS ECC KeyGen in Data Plane Encryption serviceCounter DRBG CKG
KAS-ECC (SSHv2)KAS-FullKAS-ECC for SSHv2 serviceBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthKAS-ECC-SSC Sp800-56Ar3 KDF SSH
KAS-FFC (SSHv2)KAS-FullKAS-FFC for SSHv2 serviceBit-strength Caveat:Provides between 112 and 200 bits of encryption strengthKAS-FFC-SSC Sp800-56Ar3 Domain Parameter Generation Method : MODP- 2048, MODP- 4096, and MODP-8192 KDF SSH
KAS-ECC (TLSv1.2/v1.3)KAS-FullKAS-ECC for TLSv1.2/v1.3 serviceBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthKAS-ECC-SSC Sp800-56Ar3 TLS v1.2 KDF RFC7627 TLS v1.3 KDF
KAS-FFC (TLSv1.2/v1.3)KAS-FullKAS-FFC for TLSv1.2/v1.3 serviceBit-strength Caveat:Provides 112 bits of encryption strengthKAS-FFC-SSC Sp800-56Ar3 Domain Parameter Generation Method: ffdhe2048 TLS v1.2 KDF RFC7627 TLS v1.3 KDF
Page 15
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC (Control Plane IKEv2)KAS-FullKAS-ECC for Control Plane IKEv2 serviceBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthKAS-ECC-SSC Sp800-56Ar3 KDF IKEv2
KAS-FFC (Control Plane IKEv2)KAS-FullKAS-FFC for Control Plane IKEv2 serviceBit-strength Caveat:Provides between 112 and 200 bits of encryption strengthKAS-FFC-SSC Sp800-56Ar3 Domain Parameter Generation Method: MODP- 2048, MODP- 3072, MODP- 4096, MODP- 6144 and MODP-8192 KDF IKEv2
KAS-ECC (Data Plane IKEv2)KAS-FullKAS-ECC for Data Plane IKEv2 serviceBit-strength Caveat:Provides 256 bits of encryption strengthKAS-ECC-SSC Sp800-56Ar3 Curve: P-521 KDF IKEv2
ECDSA KeyGen (SSH, TLS and Control Plane IKEv2)AsymKeyPair- KeyGen CKGRSA Keypair generation for SSH, TLS and Control Plane IKEv2 servicesECDSA KeyGen (FIPS186-4) Counter DRBG CKG
ECDSA SigGen (SSH, TLS and Control Plane IKEv2)DigSig-SigGenECDSA SigGen for SSH, TLS and Control Plane IKEv2 servicesECDSA SigGen (FIPS186-4)
ECDSA SigVer (SSH, TLS and Control Plane IKEv2)DigSig-SigVerECDSA SigVer for SSH, TLS and Control Plane IKEv2 servicesECDSA SigVer (FIPS186-4)
RSA KeyGen (SSH, TLS and Control Plane IKEv2)AsymKeyPair- KeyGen CKGRSA Keypair generation for SSH, TLS and Control Plane IKEv2 servicesRSA KeyGen (FIPS186-4) Counter DRBG CKG
RSA SigGen (SSH, TLS and Control Plane IKEv2)DigSig-SigGenRSA SigGen for SSH, TLS and Control Plane IKEv2 servicesRSA SigGen (FIPS186-4)
RSA SigVer (SSH, TLS andDigSig-SigVerRSA SigVer for SSH, TLS andRSA SigVer (FIPS186-4)
Page 16
NameTypeDescriptionPropertiesAlgorithms
Control Plane IKEv2)Control Plane IKEv2 services
ECDSA KeyGen (Data Plane IKEv2)AsymKeyPair- KeyGen CKGECDSA Keypair generation for Data Plane IKEv2 servicesCounter DRBG ECDSA KeyGen (FIPS186-4) CKG
ECDSA SigGen (Data Plane IKEv2)DigSig-SigGenECDSA SigGen for Data Plane IKEv2 serviceECDSA SigGen (FIPS186-4)
ECDSA SigVer (Data Plane IKEv2)DigSig-SigVerECDSA SigVer for Data Plane IKEv2 serviceECDSA SigVer (FIPS186-4)
RSA KeyGen (Data Plane IKEv2)AsymKeyPair- KeyGen CKGRSA Keypair generation for Data Plane IKEv2 servicesRSA KeyGen (FIPS186-4) Counter DRBG CKG
RSA SigGen (Data Plane IKEv2)DigSig-SigGenRSA SigGen for Data Plane IKEv2 serviceRSA SigGen (FIPS186-4)
RSA SigVer (Data Plane IKEv2)DigSig-SigVerRSA SigVer for Data Plane IKEv2 serviceRSA SigVer (FIPS186-4)
TLS Keying Materials DevelopmentKAS-135KDFKeying materials, used to derive TLS session keysTLS v1.2 KDF RFC7627 TLS v1.3 KDF
IPsec/IKEv2 Keying Materials DevelopmentKAS-135KDFKeying materials, used to derive IPSec/IKE session keysKDF IKEv2
SNMPv3 Keying Materials DevelopmentKAS-135KDFKeying materials, used to derive SNMP session keysKDF SNMP
Block Ciphers (SNMPv3)BC-UnAuth MACBlock Ciphers used for SNMPv3 serviceAES-ECB HMAC-SHA-1 KDF SNMP SHA-1
Block Ciphers (SSHv2)BC-Auth BC-UnAuth MACBlock Cipher for SSHv2 serivceAES-CBC AES-CTR HMAC-SHA-1 HMAC-SHA2- 256 HMAC-SHA2- 512 SHA-1 SHA2-256
Page 17
NameTypeDescriptionPropertiesAlgorithms
SHA2-512 AES-GCM
Block Ciphers (TLSv1.2/v1.3)BC-Auth BC-UnAuth MACBlock Cipher used for TLSv1.2/v1.3 serviceAES-CBC AES-GCM HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 SHA2-256 SHA2-384 SHA2-512
Block Ciphers (Control Plane IKEv2)BC-Auth BC-UnAuth MACBlock Ciphers for Control Plane IKEv2 serviceAES-CBC AES-CCM AES-GCM AES-CBC AES-CCM AES-GCM AES-CTR AES-CTR HMAC-SHA-1 HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 HMAC-SHA-1 HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 SHA-1 SHA2-256 SHA2-384 SHA2-512 SHA-1 SHA2-256 SHA2-384 SHA2-512
Block Cipher (Data Plane IKEv2)BC-AuthBlock Cipher for Data Plane IKEv2 serviceAES-GCM AES-GCM AES-CBC HMAC-SHA2- 256 HMAC-SHA2-
Page 18
NameTypeDescriptionPropertiesAlgorithms
512 SHA2-256 SHA2-512 AES-ECB
SSH KTS (AES and HMAC)KTS-WrapKTS via SSHv2 service by using AES and HMACBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-CBC AES-CTR HMAC-SHA-1 HMAC-SHA2- 256 HMAC-SHA2- 512 SHA-1 SHA2-256 SHA2-512
SSH KTS (GCM)KTS-WrapKTS via SSHv2 service by using AES-GCMBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-GCM
TLS KTS (AES and HMAC)KTS-WrapKTS via TLSv1.2/v1.3 service by using AES and HMACBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-CBC HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 SHA2-256 SHA2-384 SHA2-512
TLS KTS (GCM)KTS-WrapKTS via TLSv1.2/v1.3 service by using GCMBit-strength Caveat:Provides between 128 and 256 bits of encryption strengthAES-GCM
OSPFv2 AuthenticationMACOSPFv2 authenticationHMAC-SHA2- 256 SHA2-256
LUKS Database ProtectionMACDatabase integrity protection using HMAC-SHA2- 512SHA2-512 HMAC-SHA2- 512 PBKDF
Firmware Load TestDigSig-SigVerECDSA SigVer for firmware load testECDSA SigVer (FIPS186-4) Curve: P-521
Page 19
NameTypeDescriptionPropertiesAlgorithms
NTP AuthenticationMACNTP authenticationSHA-1 SHA2-256 AES-CMAC
DRBG FunctionDRBGUsed for DRBG generationCounter DRBG Counter DRBG
Firmware Integrity TestDigSig-SigVerUsed for firmware integrity testECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) SHA2-512 ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) SHA2-256 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512

Table 6: Security Function Implementations

2.7 Algorithm Specific Information

• The IV for AES-GCM is constructed in compliance with IG C.H scenario 1a (TLSv1.2). For TLS 1.2, the module offers the AES-GCM implementation and uses the context of Scenario 1a of IG C.H. The module is compliant with SP 800-52r2 section 3.3.1 and the mechanism for IV generation is compliant with RFC5288. The module’s implementation © 2021-2025 Nokia Corporation

Page 20
Cert NumberVendor Name
E156Silicon Laboratories

of AES-GCM is compliant to IG C.H option i) where module implements TLS protocol. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established.

2.8 RBG and Entropy

Table 7: Entropy Certificates © 2021-2025 Nokia Corporation

Page 21
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
EFR32MG21B010F1024IM32PhysicalB with SE Firmware Version 1.2.13128 bitsFull entropyA3366 (AES- CBC-MAC)

Table 8: Entropy Sources The module implements two approved CTR_DRBGs based on SP800-90Arev1, with Algo Certs. #A4958 and #A4959. Each DRBG is used internally by the module (e.g. to generate symmetric keys, seeds for asymmetric key pairs, and random numbers for security functions). The DRBG is seeded by the entropy source described in the table above. The CTR_DRBG (AES-128/192/256) enables Derivation Function capability. The DRBG is instantiated with a 384-bits long entropy input (corresponding to 384 bits of entropy) and provides at least 256 bits security strength for the following cryptographic keys generation. The entropy source implementation generates an output that is considered to have full entropy. More information can be found in the public use document for ESV cert #E156.

2.9 Key Generation

The module generates RSA, ECDSA, EC Diffie-Hellman, and Diffie-Hellman asymmetric key pairs compliant with FIPS 186-4, using a NIST SP 800-90Arev1 CTR DRBG for random number generation. In accordance with FIPS 140-3 IG D.H, the cryptographic module performs CKG for asymmetric keys as per section 5 of NIST SP 800-133rev2 (vendor affirmed) by obtaining a random bit string directly from an approved DRBG. The random bit string supports the required security strength requested by the calling application (without any V, as described in Additional Comments 2 of IG D.H.).

2.10 Key Establishment

The module provides the following key/SSP establishment services in the approved mode of operation:

7919 (TLS) and RFC 3526 (IKE).

- SSH (RFC 4419): © 2021-2025 Nokia Corporation

Page 22
Physical PortLogical Interface(s)Data That Passes
Ethernet Ports and Optical Ports on CHM6 Card; DCN, CRAFT, CONSOLE, AUX 1 & AUX 2 Ports on XMM4 CardData InputPlaintext/Ciphertext Data input to the module for all approved services defined in the approved services table
Ethernet Ports and Optical Ports on CHM6 Card; DCN, CRAFT, CONSOLE, AUX 1 & AUX 2 Ports on XMM4 CardData OutputPlaintext/Ciphertext Data output from the module for all approved services defined in the approved services table
DCN, CRAFT, CONSOLE, AUX 1 & AUX 2 Ports on XMM4 Card; Lamp Test on IOP CardControl InputControl information input into the module for all the services defined in the approved services table
DCN, CRAFT, CONSOLE, AUX 1 & AUX 2 Ports on XMM4 Card, and LEDsStatus OutputStatus Information output from the module for all the services defined in the approved services table
Power InterfacePowerPower supply

MODP-2048 (ID =

  1. MODP-4096 (ID =
  2. MODP-8192 (ID = 18) - TLS (RFC 7919): ffdhe2048 (ID = 256) - IKE (RFC 3526): MODP-2048 (ID =
  3. MODP-3072 (ID =
  4. MODP-4096 (ID =
  5. MODP-6144 (ID =
  6. MODP-8192 (ID = 18) • KAS-ECC Shared Secret Computation: o The module provides SP800-56Arev3 compliant key establishment according to FIPS 140-3 IG D.F scenario 2 path (2) with KAS-ECC shared secret computation. The shared secret computation provides between 128 and 256 bits of encryption strength.
2.11 Industry Protocols

The module supports SSHv2, TLS v1.2, TLSv1.3, SNMPv3 and IKEv2 industrial protocols. No parts of SSH, TLS, SNMP and IKEv2 protocols, other than the KDFs, have been tested by the CAVP and CMVP. Please refer to SSPs Table for more information.

3 Cryptographic Module Interfaces
Page 23
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Password- based AuthenticationThe minimum length is eight (8) characters (94 possible characters). The probability that a random attempt will succeed or a false acceptance will occur is 1/(94^8) which is less than 1/1,000,000. As the module supports at most ten failed attempts to authenticate in a one- minute period, the probability of successfully authenticating to the module within one minute is 10/(94^8), which is less than 1/100,000. This calculation is based on the assumption that the typical standard American QWERTY computer keyboard has 10 Integer digits, 52 alphabetic characters, and 32 special characters providing 94 characters to choose from in total.Password BasedThe probability that a random attempt will succeed or a false acceptance will occur is 1/(94^8). Please refer to Description section in this table for more detailsThe probability of successfully authenticating to the module within one minute is 10/(94^8). Please refer to Description section in this table for more details

The module’s physical perimeter encompasses the case of the tested platform mentioned in Table 2. The module provides physical ports which are mapped to logical interfaces provided by the module (data input, data output, control input, control output and status output) as above. The module’s data output interface will be disabled when performing pre-operational self-tests, loading new firmware, zeroizing keys, or when in an error state.

4 Roles, Services, and Authentication
4.1 Authentication Methods
Page 24
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
RSA-based AuthenticationThe modules support RSA public-key based authentication mechanism using a minimum of RSA 2048 bits, which provides 112 bits of security strength. The probability that a random attempt will succeed is 1/(2^112) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one-minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112), which is less than 1/100,000.RSA SigVer (FIPS186-4) (A4958)The probability that a random attempt will succeed is 1/(2^112). Please refer to Description section in this table for more detailsthe probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112). Please refer to Description section in this table for more details
ECDSA- based AuthenticationThe modules support ECDSA public-key based authentication mechanism using a minimum of curve P- 256, which provides 128 bits of security strength. The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 newECDSA SigVer (FIPS186-4) (A4958)The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. Please refer to Description section in this table for more detailsthe probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128). Please refer to Description section in this table for more details
Page 25

Method Name

Description sessions per second to authenticate in a one-minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128), which is less than 1/100,000.

Security Mechanism

Strength Each Attempt

Strength per Minute

Table 10: Authentication Methods The module supports identity-based authentication mechanism. The module supports the multiple Crypto Officer roles and User roles. Each role is authenticated by the module upon initial access to the module, as detailed below. Crypto Officer Roles:

Page 26
NameTypeOperator TypeAuthentication Methods
Security Admin (SA)IdentityCrypto OfficerPassword-based Authentication RSA-based Authentication ECDSA-based Authentication
Network Admin (NA)IdentityCrypto OfficerPassword-based Authentication RSA-based Authentication ECDSA-based Authentication
Encryption Admin (EA)IdentityCrypto OfficerPassword-based Authentication RSA-based Authentication ECDSA-based Authentication
Network Engineer (NE)IdentityUserPassword-based Authentication RSA-based Authentication ECDSA-based Authentication
Monitoring Access (MA)IdentityUserPassword-based Authentication RSA-based Authentication ECDSA-based Authentication
Provisioning (PR)IdentityUserPassword-based Authentication RSA-based Authentication ECDSA-based Authentication
Turn-up and Test (TT)IdentityUserPassword-based Authentication RSA-based Authentication ECDSA-based Authentication

The module also allows the concurrent operators.

4.2 Roles
4.3 Approved Services
Page 27
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Show VersionShow module's ID and versioning informationN/ACommand used to show module's versionModule's ID and versioning informatio nNoneSecurity Admin (SA) Network Admin (NA) Encryption Admin (EA) Network Engineer (NE) Monitoring Access (MA) Provisionin g (PR) Turn-up and Test (TT)
Show StatusShow module's operational statusN/ACommand used to show Module's StatusModule's operation al statusNoneSecurity Admin (SA) Network Admin (NA) Encryption Admin (EA) Network Engineer (NE) Monitoring Access (MA) Provisionin g (PR) Turn-up and Test (TT)
User Account Manageme ntUser account manageme ntN/ACommand to manage the User accountStatus of User accountNoneSecurity Admin (SA) - Operator Password: G,R,W,Z - SSH RSA Public Key: G,R,W,Z - SSH ECDSA Public Key: G,R,W,Z
Page 28
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Certificates Manageme ntN/ACommand s used to manage the certificatesStatus of the completio n of network configurati on statusNoneSecurity Admin (SA) - SSH ECDSA Private Key: G,R,W,E,Z - SSH ECDSA Public Key: G,R,W,E,Z - SSH RSA Private Key: G,R,W,E,Z - SSH RSA Public Key: G,R,W,E,Z - TLS ECDSA Private Key: G,R,W,E,Z - TLS ECDSA Public Key: G,R,W,E,Z - TLS RSA Private Key: G,R,W,E,Z - TLS RSA Public Key: G,R,W,E,Z - IPSec/IKE ECDSA Private Key: G,R,W,E,Z - IPSec/IKE ECDSA Public Key: G,R,W,E,Z - IPSec/IKE RSA Private Key: G,R,W,E,Z - IPSec/IKE
Page 29
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
RSA Public Key: G,R,W,E,Z - Data Plane Encryption ECDSA Private Key: G,R,W,E,Z - Data Plane Encryption ECDSA Public Key: G,R,W,E,Z - Data Plane Encryption RSA Private Key: G,R,W,E,Z - Data Plane Encryption RSA Public Key: G,R,W,E,Z
Setup Network (non- security relevant)Commands to configure the non- security relevant networkN/ACommand s to configure the networkStatus of the completio n of network configurati on statusNoneNetwork Admin (NA) Provisionin g (PR) Turn-up and Test (TT)
Enable/disa ble approved modeEnable/disa ble approved modeN/ACommand used to enable or disable approved modeModule's approved mode statusNoneSecurity Admin (SA)
Configure Network Access Control ListConfigure network access control listN/ACommand s used to configure network access control listNetwork access control list configurati on statusNoneSecurity Admin (SA)
Page 30
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Configure Performanc e Monitoring ServiceConfigure Performanc e Monitoring ServiceN/ACommand s used to configure performan ce monitoring serviceperforman ce monitoring service configurati on statusNoneNetwork Admin (NA) Turn-up and Test (TT)
Configure EquipmentProvision equipmentN/ACommand s used to configue equipmentEquipmen t configurati on statusNoneNetwork Admin (NA) Network Engineer (NE)
Configure Facilities (physical or logical Interfaces)Configure Facilities (physical or logical interfaces)N/ACommand s to configure the module's physical or logical interfacesModule's physical or logical interfaces configruait on statusNoneNetwork Admin (NA) Provisionin g (PR) Turn-up and Test (TT)
Perform Self-TestPerform self-testsN/ACommand to trigger self-testsSelf-tests completio n statusFirmware Integrity TestSecurity Admin (SA) Network Admin (NA) Encryption Admin (EA) Network Engineer (NE) Monitoring Access (MA) Provisionin g (PR) Turn-up and Test (TT)
Firmware UpdatePerform firmware updateFirmware update service completio n statusCommand to trigger firmware updateFirmware update statusFirmware Load TestNetwork Admin (NA) - Firmware Load Test Key: R,E
Perform ZeroizationZeroize all SSPs in the moduleN/ACommand to zeroize the moduleSSPs zeroizatio n statusNoneSecurity Admin (SA) - DRBG Entropy Input: Z - DRBG
Page 31
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Seed: Z - DRBG Internal State V value: Z - DRBG Key: Z - Operator Password: Z - LUKS DB Password: Z - LUKS DB Salt : Z - LUKS DB Integrity Key : Z - SSH DH Private Key: Z - SSH DH Public Key: Z - SSH Peer DH Public Key: Z - SSH DH Shared Secret: Z - SSH ECDH Private Key: Z - SSH ECDH Public Key: Z - SSH Peer ECDH Public Key: Z - SSH ECDH Shared Secret: Z - SSH ECDSA Private
Page 32
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key: Z - SSH ECDSA Public Key: Z - SSH RSA Private Key: Z - SSH RSA Public Key: Z - SSH Encryption Key: Z - SSH Integrity Key: Z - TLS DH Private Key: Z - TLS DH Public Key: Z - TLS Peer DH Public Key: Z - TLS DH Shared Secret: Z - TLS ECDH Private Key: Z - TLS ECDH Public Key: Z - TLS Peer ECDH Public Key: Z - TLS ECDH Shared Secret: Z - TLS ECDSA Private Key: Z
Page 33
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- TLS ECDSA Public Key: Z - TLS RSA Private Key: Z - TLS RSA Public Key: Z - TLS Master Secret: Z - TLS Encryption Key: Z - TLS Integrity Key: Z - IPSec/IKE DH Private Key: Z - IPSec/IKE DH Public Key: Z - IPSec/IKE Peer DH Public Key: Z - IPSec/IKE DH Shared Secret: Z - IPSec/IKE ECDH Private Key: Z - IPSec/IKE ECDH Public Key: Z - IPSec/IKE Peer ECDH Public Key: Z - IPSec/IKE ECDH Shared Secret: Z
Page 34
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- IPSec/IKE ECDSA Private Key: Z - IPSec/IKE ECDSA Public Key: Z - IPSec/IKE RSA Private Key: Z - IPSec/IKE RSA Public Key: Z - IPSec/IKE Pre-shared Secret: Z - IPSec/IKE SKEYSEE D: Z - IPSec/IKE Encryption Key: Z - IPSec/IKE Integrity Key: Z - SNMPv3 Encryption Key: Z - SNMPv3 Integrity Key: Z - Data Plane Encryption Pre-shared Secret: Z - Data Plane Encryption ECDH Private Key: Z - Data Plane Encryption ECDH Public Key:
Page 35
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Z - Data Plane Encryption Peer ECDH Public Key: Z - Data Plane Encryption ECDH Shared Secret: Z - Data Plane Encryption ECDSA Private Key: Z - Data Plane Encryption ECDSA Public Key: Z - Data Plane Encryption RSA Private Key: Z - Data Plane Encryption RSA Public Key: Z - Data Plane Encryption IKE-SA Session Key: Z - Data Plane Encryption Child-SA Session Key: Z
Page 36
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- SNMPv3 Authenticat ion Secret: Z
Configure SSHv2 serviceGlobal approved mode indicator and SSHv2 service configurati on statusCommman ds used to configure SSHv2 serviceSSHv2 service configurati on statusKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-ECC (SSHv2) KAS-FFC (SSHv2) ECDSA KeyGen (SSH, TLS and Control Plane IKEv2) ECDSA SigGen (SSH, TLS and Control Plane IKEv2) ECDSA SigVer (SSH, TLS and Control Plane IKEv2) RSA KeyGen (SSH, TLS and Control Plane IKEv2) RSA SigGen (SSH, TLS and Control PlaneSecurity Admin (SA) - SSH DH Private Key: W,Z - SSH DH Public Key: W,Z - SSH Peer DH Public Key: W,Z - SSH DH Shared Secret: W,Z - SSH ECDH Private Key: W,Z - SSH ECDH Public Key: W,Z - SSH Peer ECDH Public Key: W,Z - SSH ECDH Shared Secret: W,Z - SSH ECDSA Private Key: W,Z - SSH ECDSA Public Key: W,Z - SSH RSA Private Key: W,Z - SSH RSA Public Key:
Page 37
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
IKEv2) RSA SigVer (SSH, TLS and Control Plane IKEv2) Block Ciphers (SSHv2) SSH KTS (AES and HMAC) SSH KTS (GCM) DRBG FunctionW,Z - SSH Encryption Key: W,Z - SSH Integrity Key: W,Z - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V value: W,Z - DRBG Key: W,Z
Configure TLS (v1.2/v1.3) ServiceConfigure TLS (v1.2/v1.3) serviceGlobal approved mode indicator and OSPF service configurati on statusCommman ds used to configure TLS (v1.2/v1.3) serviceTLS (v1.2/v1.3 ) service configurati on statusKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-ECC (TLSv1.2/v 1.3) KAS-FFC (TLSv1.2/v 1.3) ECDSA KeyGen (SSH, TLS and Control Plane IKEv2) ECDSA SigGen (SSH, TLS and Control Plane IKEv2) ECDSASecurity Admin (SA) - TLS DH Private Key: W,Z - TLS DH Public Key: W,Z - TLS Peer DH Public Key: W,Z - TLS DH Shared Secret: W,Z - TLS ECDH Private Key: W,Z - TLS ECDH Public Key: W,Z - TLS Peer ECDH Public Key: W,Z - TLS ECDH Shared Secret:
Page 38
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
SigVer (SSH, TLS and Control Plane IKEv2) RSA KeyGen (SSH, TLS and Control Plane IKEv2) RSA SigGen (SSH, TLS and Control Plane IKEv2) RSA SigVer (SSH, TLS and Control Plane IKEv2) Block Ciphers (TLSv1.2/v 1.3) TLS KTS (AES and HMAC) TLS KTS (GCM) DRBG Function TLS Keying Materials Developme ntW,Z - TLS ECDSA Private Key: W,Z - TLS ECDSA Public Key: W,Z - TLS RSA Private Key: W,Z - TLS RSA Public Key: W,Z - TLS Master Secret: W,Z - TLS Encryption Key: W,Z - TLS Integrity Key: W,Z - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V value: W,Z - DRBG Key: W,Z
Configure SNMP serviceGlobal approved mode indicator and SNMP service configurati on statusCommman ds used to configure SNMP serviceSNMP service configurati on statusBlock Ciphers (SNMPv3) SNMPv3 Keying Materials Developme ntSecurity Admin (SA) - SNMPv3 Authenticat ion Secret: W,Z - SNMPv3 Encryption Key: W,Z - SNMPv3 Integrity Key: W,Z
Page 39
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Configure Control Plane IPSec/IKEv 2 ServiceGlobal approved mode indicator and Control Plane IPSec/IKE v2 service configurati on statusCommman ds used to configure Control Plane IPSec/IKE v2 serviceControl Plane IPSec/IKE v2 service configurati on statusKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-ECC (Control Plane IKEv2) KAS-FFC (Control Plane IKEv2) ECDSA KeyGen (SSH, TLS and Control Plane IKEv2) ECDSA SigGen (SSH, TLS and Control Plane IKEv2) ECDSA SigVer (SSH, TLS and Control Plane IKEv2) RSA KeyGen (SSH, TLS and Control Plane IKEv2) RSA SigGen (SSH, TLS and Control PlaneSecurity Admin (SA) - IPSec/IKE DH Private Key: W,Z - IPSec/IKE DH Public Key: W,Z - IPSec/IKE Peer DH Public Key: W,Z - IPSec/IKE DH Shared Secret: W,Z - IPSec/IKE ECDH Private Key: W,Z - IPSec/IKE ECDH Public Key: W,Z - IPSec/IKE Peer ECDH Public Key: W,Z - IPSec/IKE ECDH Shared Secret: W,Z - IPSec/IKE ECDSA Private Key: W,Z - IPSec/IKE ECDSA Public Key: W,Z - IPSec/IKE RSA Private Key: W,Z - IPSec/IKE RSA Public Key: W,Z
Page 40
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
IKEv2) RSA SigVer (SSH, TLS and Control Plane IKEv2) Block Ciphers (Control Plane IKEv2) DRBG Function IPsec/IKEv 2 Keying Materials Developme nt- IPSec/IKE Pre-shared Secret: W,Z - IPSec/IKE SKEYSEE D: W,Z - IPSec/IKE Encryption Key: W,Z - IPSec/IKE Integrity Key: W,Z - DRBG Entropy Input: W,Z - DRBG Seed: W,Z - DRBG Internal State V value: W,Z - DRBG Key: W,Z
Configure Data Plane Encryption ServiceGlobal approved mode indicator and Data Plane Encryptio n service configurati on statusCommman ds used to configure Data Plane Encryption serviceData Plane Encryptio n service configurati on statusKAS-ECC- KeyGen (Data Plane IKEv2) KAS-ECC (Data Plane IKEv2) ECDSA KeyGen (Data Plane IKEv2) ECDSA SigGen (Data Plane IKEv2) ECDSA SigVer (Data Plane IKEv2) RSA KeyGen (Data Plane IKEv2) RSA SigGenEncryption Admin (EA) - Data Plane Encryption ECDH Private Key: W,Z - Data Plane Encryption ECDH Public Key: W,Z - Data Plane Encryption Peer ECDH Public Key: W,Z - Data Plane Encryption ECDH
Page 41
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
(Data Plane IKEv2) RSA SigVer (Data Plane IKEv2) Block Cipher (Data Plane IKEv2) DRBG FunctionShared Secret: W,Z - Data Plane Encryption ECDSA Private Key: W,Z - Data Plane Encryption ECDSA Public Key: W,Z - Data Plane Encryption RSA Private Key: W,Z - Data Plane Encryption RSA Public Key: W,Z - Data Plane Encryption Pre-shared Secret: W,Z - Data Plane Encryption IKE-SA Session Key: W,Z - Data Plane Encryption Child-SA Session Key: W,Z - DRBG Entropy Input: W,Z - DRBG Seed: W,Z
Page 42
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- DRBG Internal State V value: W,Z - DRBG Key: W,Z
Configure OSPF ServiceConfigure OSPF ServiceGlobal approved mode indicator and OSPF service configurati on status logCommand s used to configure OSPF serviceOSPF configurati on statusOSPFv2 Authenticati onSecurity Admin (SA) - OSPFv2 Authenticat ion Key : W,Z Network Admin (NA) - OSPFv2 Authenticat ion Key : W,Z
Configure LUKS Database Protection ServiceConfigure LUKS Database protection serviceGlobal approved mode indicator and LUKS Database service configurati on statusCommand s to configure LUKS database serviceStatus of completio n of LUKS database service configurati onLUKS Database ProtectionSecurity Admin (SA) - LUKS DB Password: G,W,Z
Run SSHv2 serviceRun SSHv2 serviceGlobal approved mode indicator and SSHv2 service running statusInitiate SSHv2 service establishm ent requestSSHv2 service running statusKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-ECC (SSHv2) KAS-FFC (SSHv2) ECDSA KeyGen (SSH, TLS and Control PlaneSecurity Admin (SA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - SSH DH Private Key: G,W,E,Z
Page 43
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
IKEv2) ECDSA SigGen (SSH, TLS and Control Plane IKEv2) ECDSA SigVer (SSH, TLS and Control Plane IKEv2) RSA KeyGen (SSH, TLS and Control Plane IKEv2) RSA SigGen (SSH, TLS and Control Plane IKEv2) RSA SigVer (SSH, TLS and Control Plane IKEv2) Block Ciphers (SSHv2) SSH KTS (AES and HMAC) SSH KTS (GCM) DRBG Function- SSH DH Public Key: G,W,E,Z - SSH Peer DH Public Key: G,W,E,Z - SSH DH Shared Secret: G,W,E,Z - SSH ECDH Private Key: G,W,E,Z - SSH ECDH Public Key: G,W,E,Z - SSH Peer ECDH Public Key: G,W,E,Z - SSH ECDH Shared Secret: G,W,E,Z - SSH ECDSA Private Key: G,W,E,Z - SSH ECDSA Public Key: G,W,E,Z - SSH RSA Private Key: G,W,E,Z - SSH RSA Public Key: G,W,E,Z - SSH Encryption Key: G,W,E,Z
Page 44
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- SSH Integrity Key: G,W,E,Z Network Admin (NA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - SSH DH Private Key: G,W,E,Z - SSH DH Public Key: G,W,E,Z - SSH Peer DH Public Key: G,W,E,Z - SSH DH Shared Secret: G,W,E,Z - SSH ECDH Private Key: G,W,E,Z - SSH ECDH Public Key: G,W,E,Z - SSH Peer ECDH Public Key: G,W,E,Z
Page 45
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- SSH ECDH Shared Secret: G,W,E,Z - SSH ECDSA Private Key: G,W,E,Z - SSH ECDSA Public Key: G,W,E,Z - SSH RSA Private Key: G,W,E,Z - SSH RSA Public Key: G,W,E,Z - SSH Encryption Key: G,W,E,Z - SSH Integrity Key: G,W,E,Z Encryption Admin (EA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - SSH DH Private Key:
Page 46
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
G,W,E,Z - SSH DH Public Key: G,W,E,Z - SSH Peer DH Public Key: G,W,E,Z - SSH DH Shared Secret: G,W,E,Z - SSH ECDH Private Key: G,W,E,Z - SSH ECDH Public Key: G,W,E,Z - SSH Peer ECDH Public Key: G,W,E,Z - SSH ECDH Shared Secret: G,W,E,Z - SSH ECDSA Private Key: G,W,E,Z - SSH ECDSA Public Key: G,W,E,Z - SSH RSA Private Key: G,W,E,Z - SSH RSA Public Key: G,W,E,Z - SSH Encryption Key:
Page 47
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
G,W,E,Z - SSH Integrity Key: G,W,E,Z Network Engineer (NE) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - SSH DH Private Key: G,W,E,Z - SSH DH Public Key: G,W,E,Z - SSH Peer DH Public Key: G,W,E,Z - SSH DH Shared Secret: G,W,E,Z - SSH ECDH Private Key: G,W,E,Z - SSH ECDH Public Key: G,W,E,Z - SSH Peer ECDH
Page 48
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Public Key: G,W,E,Z - SSH ECDH Shared Secret: G,W,E,Z - SSH ECDSA Private Key: G,W,E,Z - SSH ECDSA Public Key: G,W,E,Z - SSH RSA Private Key: G,W,E,Z - SSH RSA Public Key: G,W,E,Z - SSH Encryption Key: G,W,E,Z - SSH Integrity Key: G,W,E,Z Monitoring Access (MA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z
Page 49
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- SSH DH Private Key: G,W,E,Z - SSH DH Public Key: G,W,E,Z - SSH Peer DH Public Key: G,W,E,Z - SSH DH Shared Secret: G,W,E,Z - SSH ECDH Private Key: G,W,E,Z - SSH ECDH Public Key: G,W,E,Z - SSH Peer ECDH Public Key: G,W,E,Z - SSH ECDH Shared Secret: G,W,E,Z - SSH ECDSA Private Key: G,W,E,Z - SSH ECDSA Public Key: G,W,E,Z - SSH RSA Private Key: G,W,E,Z - SSH RSA Public Key: G,W,E,Z
Page 50
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- SSH Encryption Key: G,W,E,Z - SSH Integrity Key: G,W,E,Z Provisionin g (PR) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - SSH DH Private Key: G,W,E,Z - SSH DH Public Key: G,W,E,Z - SSH Peer DH Public Key: G,W,E,Z - SSH DH Shared Secret: G,W,E,Z - SSH ECDH Private Key: G,W,E,Z - SSH ECDH Public Key: G,W,E,Z
Page 51
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- SSH Peer ECDH Public Key: G,W,E,Z - SSH ECDH Shared Secret: G,W,E,Z - SSH ECDSA Private Key: G,W,E,Z - SSH ECDSA Public Key: G,W,E,Z - SSH RSA Private Key: G,W,E,Z - SSH RSA Public Key: G,W,E,Z - SSH Encryption Key: G,W,E,Z - SSH Integrity Key: G,W,E,Z Turn-up and Test (TT) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG
Page 52
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key: G,W,E,Z - SSH DH Private Key: G,W,E,Z - SSH DH Public Key: G,W,E,Z - SSH Peer DH Public Key: G,W,E,Z - SSH DH Shared Secret: G,W,E,Z - SSH ECDH Private Key: G,W,E,Z - SSH ECDH Public Key: G,W,E,Z - SSH Peer ECDH Public Key: G,W,E,Z - SSH ECDH Shared Secret: G,W,E,Z - SSH ECDSA Private Key: G,W,E,Z - SSH ECDSA Public Key: G,W,E,Z - SSH RSA Private Key: G,W,E,Z - SSH RSA
Page 53
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Public Key: G,W,E,Z - SSH Encryption Key: G,W,E,Z - SSH Integrity Key: G,W,E,Z
Run TLS (v1.2/v1.3) ServiceGlobal approved mode indicator and TLS (v1.2/v1.3 ) service running statusInitiate TLS (v1.2/v1.3) service establishm ent requestTLS (v1.2/v1.3 ) service running statusKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-ECC (TLSv1.2/v 1.3) KAS-FFC (TLSv1.2/v 1.3) ECDSA KeyGen (SSH, TLS and Control Plane IKEv2) ECDSA SigGen (SSH, TLS and Control Plane IKEv2) ECDSA SigVer (SSH, TLS and Control Plane IKEv2) RSA KeyGen (SSH, TLSSecurity Admin (SA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - TLS DH Private Key: G,W,E,Z - TLS DH Public Key: G,W,E,Z - TLS Peer DH Public Key: G,W,E,Z - TLS DH Shared Secret: G,W,E,Z - TLS ECDH Private Key: G,W,E,Z - TLS ECDH
Page 54
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
and Control Plane IKEv2) RSA SigGen (SSH, TLS and Control Plane IKEv2) RSA SigVer (SSH, TLS and Control Plane IKEv2) Block Ciphers (TLSv1.2/v 1.3) TLS KTS (AES and HMAC) TLS KTS (GCM) DRBG Function TLS Keying Materials Developme ntPublic Key: G,W,E,Z - TLS Peer ECDH Public Key: G,W,E,Z - TLS ECDH Shared Secret: G,W,E,Z - TLS ECDSA Private Key: G,W,E,Z - TLS ECDSA Public Key: G,W,E,Z - TLS RSA Private Key: G,W,E,Z - TLS RSA Public Key: G,W,E,Z - TLS Master Secret: G,W,E,Z - TLS Encryption Key: G,W,E,Z - TLS Integrity Key: G,W,E,Z Network Admin (NA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG
Page 55
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - TLS DH Private Key: G,W,E,Z - TLS DH Public Key: G,W,E,Z - TLS Peer DH Public Key: G,W,E,Z - TLS DH Shared Secret: G,W,E,Z - TLS ECDH Private Key: G,W,E,Z - TLS ECDH Public Key: G,W,E,Z - TLS Peer ECDH Public Key: G,W,E,Z - TLS ECDH Shared Secret: G,W,E,Z - TLS ECDSA Private Key: G,W,E,Z - TLS ECDSA Public Key: G,W,E,Z
Page 56
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- TLS RSA Private Key: G,W,E,Z - TLS RSA Public Key: G,W,E,Z - TLS Master Secret: G,W,E,Z - TLS Encryption Key: G,W,E,Z - TLS Integrity Key: G,W,E,Z Encryption Admin (EA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - TLS DH Private Key: G,W,E,Z - TLS DH Public Key: G,W,E,Z - TLS Peer DH Public Key: G,W,E,Z - TLS DH Shared
Page 57
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Secret: G,W,E,Z - TLS ECDH Private Key: G,W,E,Z - TLS ECDH Public Key: G,W,E,Z - TLS Peer ECDH Public Key: G,W,E,Z - TLS ECDH Shared Secret: G,W,E,Z - TLS ECDSA Private Key: G,W,E,Z - TLS ECDSA Public Key: G,W,E,Z - TLS RSA Private Key: G,W,E,Z - TLS RSA Public Key: G,W,E,Z - TLS Master Secret: G,W,E,Z - TLS Encryption Key: G,W,E,Z - TLS Integrity Key: G,W,E,Z Network
Page 58
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Engineer (NE) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - TLS DH Private Key: G,W,E,Z - TLS DH Public Key: G,W,E,Z - TLS Peer DH Public Key: G,W,E,Z - TLS DH Shared Secret: G,W,E,Z - TLS ECDH Private Key: G,W,E,Z - TLS ECDH Public Key: G,W,E,Z - TLS Peer ECDH Public Key: G,W,E,Z - TLS ECDH Shared Secret:
Page 59
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
G,W,E,Z - TLS ECDSA Private Key: G,W,E,Z - TLS ECDSA Public Key: G,W,E,Z - TLS RSA Private Key: G,W,E,Z - TLS RSA Public Key: G,W,E,Z - TLS Master Secret: G,W,E,Z - TLS Encryption Key: G,W,E,Z - TLS Integrity Key: G,W,E,Z Monitoring Access (MA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - TLS DH Private
Page 60
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key: G,W,E,Z - TLS DH Public Key: G,W,E,Z - TLS Peer DH Public Key: G,W,E,Z - TLS DH Shared Secret: G,W,E,Z - TLS ECDH Private Key: G,W,E,Z - TLS ECDH Public Key: G,W,E,Z - TLS Peer ECDH Public Key: G,W,E,Z - TLS ECDH Shared Secret: G,W,E,Z - TLS ECDSA Private Key: G,W,E,Z - TLS ECDSA Public Key: G,W,E,Z - TLS RSA Private Key: G,W,E,Z - TLS RSA Public Key: G,W,E,Z - TLS Master
Page 61
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Secret: G,W,E,Z - TLS Encryption Key: G,W,E,Z - TLS Integrity Key: G,W,E,Z Provisionin g (PR) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - TLS DH Private Key: G,W,E,Z - TLS DH Public Key: G,W,E,Z - TLS Peer DH Public Key: G,W,E,Z - TLS DH Shared Secret: G,W,E,Z - TLS ECDH Private Key: G,W,E,Z - TLS ECDH
Page 62
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Public Key: G,W,E,Z - TLS Peer ECDH Public Key: G,W,E,Z - TLS ECDH Shared Secret: G,W,E,Z - TLS ECDSA Private Key: G,W,E,Z - TLS ECDSA Public Key: G,W,E,Z - TLS RSA Private Key: G,W,E,Z - TLS RSA Public Key: G,W,E,Z - TLS Master Secret: G,W,E,Z - TLS Encryption Key: G,W,E,Z - TLS Integrity Key: G,W,E,Z Turn-up and Test (TT) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z
Page 63
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - TLS DH Private Key: G,W,E,Z - TLS DH Public Key: G,W,E,Z - TLS Peer DH Public Key: G,W,E,Z - TLS DH Shared Secret: G,W,E,Z - TLS ECDH Private Key: G,W,E,Z - TLS ECDH Public Key: G,W,E,Z - TLS Peer ECDH Public Key: G,W,E,Z - TLS ECDH Shared Secret: G,W,E,Z - TLS ECDSA Private Key: G,W,E,Z - TLS ECDSA Public Key:
Page 64
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
G,W,E,Z - TLS RSA Private Key: G,W,E,Z - TLS RSA Public Key: G,W,E,Z - TLS Master Secret: G,W,E,Z - TLS Encryption Key: G,W,E,Z - TLS Integrity Key: G,W,E,Z
Run Control Plane IPsec/IKEv 2 ServiceGlobal approved mode indicator and Run IPsec/IKE v2 service completio n status logCommand to run Run Control Plane IPsec/IKEv 2 serviceControl Plane IPsec/IKE v2 service running statusKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2) KAS-ECC (Control Plane IKEv2) KAS-FFC (Control Plane IKEv2) ECDSA KeyGen (SSH, TLS and Control Plane IKEv2) ECDSA SigGen (SSH, TLSSecurity Admin (SA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - IPSec/IKE DH Private Key: G,W,E,Z - IPSec/IKE DH Public Key: G,W,E,Z - IPSec/IKE Peer DH Public Key: G,W,E,Z
Page 65
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
and Control Plane IKEv2) ECDSA SigVer (SSH, TLS and Control Plane IKEv2) RSA KeyGen (SSH, TLS and Control Plane IKEv2) RSA SigGen (SSH, TLS and Control Plane IKEv2) RSA SigVer (SSH, TLS and Control Plane IKEv2) Block Ciphers (Control Plane IKEv2) DRBG Function IPsec/IKEv 2 Keying Materials Developme nt- IPSec/IKE DH Shared Secret: G,W,E,Z - IPSec/IKE ECDH Private Key: G,W,E,Z - IPSec/IKE ECDH Public Key: G,W,E,Z - IPSec/IKE Peer ECDH Public Key: G,W,E,Z - IPSec/IKE ECDH Shared Secret: G,W,E,Z - IPSec/IKE ECDSA Private Key: G,W,E,Z - IPSec/IKE ECDSA Public Key: G,W,E,Z - IPSec/IKE RSA Private Key: G,W,E,Z - IPSec/IKE RSA Public Key: G,W,E,Z - IPSec/IKE Pre-shared Secret: G,W,E,Z - IPSec/IKE SKEYSEE D: G,W,E,Z - IPSec/IKE
Page 66
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Encryption Key: G,W,E,Z - IPSec/IKE Integrity Key: G,W,E,Z Network Admin (NA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - IPSec/IKE DH Private Key: G,W,E,Z - IPSec/IKE DH Public Key: G,W,E,Z - IPSec/IKE Peer DH Public Key: G,W,E,Z - IPSec/IKE DH Shared Secret: G,W,E,Z - IPSec/IKE ECDH Private Key: G,W,E,Z - IPSec/IKE ECDH Public Key: G,W,E,Z
Page 67
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- IPSec/IKE Peer ECDH Public Key: G,W,E,Z - IPSec/IKE ECDH Shared Secret: G,W,E,Z - IPSec/IKE ECDSA Private Key: G,W,E,Z - IPSec/IKE ECDSA Public Key: G,W,E,Z - IPSec/IKE RSA Private Key: G,W,E,Z - IPSec/IKE RSA Public Key: G,W,E,Z - IPSec/IKE Pre-shared Secret: G,W,E,Z - IPSec/IKE SKEYSEE D: G,W,E,Z - IPSec/IKE Encryption Key: G,W,E,Z - IPSec/IKE Integrity Key: G,W,E,Z Encryption Admin (EA) - DRBG Entropy Input: G,W,E,Z
Page 68
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - IPSec/IKE DH Private Key: G,W,E,Z - IPSec/IKE DH Public Key: G,W,E,Z - IPSec/IKE Peer DH Public Key: G,W,E,Z - IPSec/IKE DH Shared Secret: G,W,E,Z - IPSec/IKE ECDH Private Key: G,W,E,Z - IPSec/IKE ECDH Public Key: G,W,E,Z - IPSec/IKE Peer ECDH Public Key: G,W,E,Z - IPSec/IKE ECDH Shared Secret: G,W,E,Z - IPSec/IKE ECDSA Private
Page 69
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key: G,W,E,Z - IPSec/IKE ECDSA Public Key: G,W,E,Z - IPSec/IKE RSA Private Key: G,W,E,Z - IPSec/IKE RSA Public Key: G,W,E,Z - IPSec/IKE Pre-shared Secret: G,W,E,Z - IPSec/IKE SKEYSEE D: G,W,E,Z - IPSec/IKE Encryption Key: G,W,E,Z - IPSec/IKE Integrity Key: G,W,E,Z Network Engineer (NE) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - IPSec/IKE
Page 70
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
DH Private Key: G,W,E,Z - IPSec/IKE DH Public Key: G,W,E,Z - IPSec/IKE Peer DH Public Key: G,W,E,Z - IPSec/IKE DH Shared Secret: G,W,E,Z - IPSec/IKE ECDH Private Key: G,W,E,Z - IPSec/IKE ECDH Public Key: G,W,E,Z - IPSec/IKE Peer ECDH Public Key: G,W,E,Z - IPSec/IKE ECDH Shared Secret: G,W,E,Z - IPSec/IKE ECDSA Private Key: G,W,E,Z - IPSec/IKE ECDSA Public Key: G,W,E,Z - IPSec/IKE RSA Private Key: G,W,E,Z - IPSec/IKE
Page 71
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
RSA Public Key: G,W,E,Z - IPSec/IKE Pre-shared Secret: G,W,E,Z - IPSec/IKE SKEYSEE D: G,W,E,Z - IPSec/IKE Encryption Key: G,W,E,Z - IPSec/IKE Integrity Key: G,W,E,Z Provisionin g (PR) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - IPSec/IKE DH Private Key: G,W,E,Z - IPSec/IKE DH Public Key: G,W,E,Z - IPSec/IKE Peer DH Public Key: G,W,E,Z - IPSec/IKE DH Shared
Page 72
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Secret: G,W,E,Z - IPSec/IKE ECDH Private Key: G,W,E,Z - IPSec/IKE ECDH Public Key: G,W,E,Z - IPSec/IKE Peer ECDH Public Key: G,W,E,Z - IPSec/IKE ECDH Shared Secret: G,W,E,Z - IPSec/IKE ECDSA Private Key: G,W,E,Z - IPSec/IKE ECDSA Public Key: G,W,E,Z - IPSec/IKE RSA Private Key: G,W,E,Z - IPSec/IKE RSA Public Key: G,W,E,Z - IPSec/IKE Pre-shared Secret: G,W,E,Z - IPSec/IKE SKEYSEE D: G,W,E,Z - IPSec/IKE Encryption Key:
Page 73
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
G,W,E,Z - IPSec/IKE Integrity Key: G,W,E,Z Turn-up and Test (TT) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - IPSec/IKE DH Private Key: G,W,E,Z - IPSec/IKE DH Public Key: G,W,E,Z - IPSec/IKE Peer DH Public Key: G,W,E,Z - IPSec/IKE DH Shared Secret: G,W,E,Z - IPSec/IKE ECDH Private Key: G,W,E,Z - IPSec/IKE ECDH Public Key: G,W,E,Z - IPSec/IKE
Page 74
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Peer ECDH Public Key: G,W,E,Z - IPSec/IKE ECDH Shared Secret: G,W,E,Z - IPSec/IKE ECDSA Private Key: G,W,E,Z - IPSec/IKE ECDSA Public Key: G,W,E,Z - IPSec/IKE RSA Private Key: G,W,E,Z - IPSec/IKE RSA Public Key: G,W,E,Z - IPSec/IKE Pre-shared Secret: G,W,E,Z - IPSec/IKE SKEYSEE D: G,W,E,Z - IPSec/IKE Encryption Key: G,W,E,Z - IPSec/IKE Integrity Key: G,W,E,Z Monitoring Access (MA) - DRBG Entropy Input: G,W,E,Z
Page 75
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - IPSec/IKE DH Private Key: G,W,E,Z - IPSec/IKE DH Public Key: G,W,E,Z - IPSec/IKE Peer DH Public Key: G,W,E,Z - IPSec/IKE DH Shared Secret: G,W,E,Z - IPSec/IKE ECDH Private Key: G,W,E,Z - IPSec/IKE ECDH Public Key: G,W,E,Z - IPSec/IKE Peer ECDH Public Key: G,W,E,Z - IPSec/IKE ECDH Shared Secret: G,W,E,Z - IPSec/IKE ECDSA Private
Page 76
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key: G,W,E,Z - IPSec/IKE ECDSA Public Key: G,W,E,Z - IPSec/IKE RSA Private Key: G,W,E,Z - IPSec/IKE RSA Public Key: G,W,E,Z - IPSec/IKE Pre-shared Secret: G,W,E,Z - IPSec/IKE SKEYSEE D: G,W,E,Z - IPSec/IKE Encryption Key: G,W,E,Z - IPSec/IKE Integrity Key: G,W,E,Z
Run SNMP ServiceGlobal approved mode indicator and SNMP service running statusInitiate SNMP service establishm ent requestSNMP service running statusBlock Ciphers (SNMPv3) SNMPv3 Keying Materials Developme ntSecurity Admin (SA) - SNMPv3 Authenticat ion Secret: G,W,E,Z - SNMPv3 Encryption Key: G,W,E,Z - SNMPv3 Integrity Key: G,W,E,Z Network Admin (NA) - SNMPv3 Authenticat ion Secret:
Page 77
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
G,W,E,Z - SNMPv3 Encryption Key: G,W,E,Z - SNMPv3 Integrity Key: G,W,E,Z Encryption Admin (EA) - SNMPv3 Authenticat ion Secret: G,W,E,Z - SNMPv3 Encryption Key: G,W,E,Z - SNMPv3 Integrity Key: G,W,E,Z Network Engineer (NE) - SNMPv3 Authenticat ion Secret: G,W,E,Z - SNMPv3 Encryption Key: G,W,E,Z - SNMPv3 Integrity Key: G,W,E,Z Monitoring Access (MA) - SNMPv3 Authenticat ion Secret: G,W,E,Z - SNMPv3 Encryption Key: G,W,E,Z
Page 78
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- SNMPv3 Integrity Key: G,W,E,Z Provisionin g (PR) - SNMPv3 Authenticat ion Secret: G,W,E,Z - SNMPv3 Encryption Key: G,W,E,Z - SNMPv3 Integrity Key: G,W,E,Z Turn-up and Test (TT) - SNMPv3 Authenticat ion Secret: G,W,E,Z - SNMPv3 Encryption Key: G,W,E,Z - SNMPv3 Integrity Key: G,W,E,Z
Run Data Plane Encrypiton ServiceGlobal approved mode indicator and Data Plane Encryptio n service completio n status logCommand to run OSPF serviceData Plane Encryptio n service running statusKAS-ECC- KeyGen (Data Plane IKEv2) KAS-ECC (Data Plane IKEv2) ECDSA KeyGen (Data Plane IKEv2) ECDSA SigGen (Data Plane IKEv2) ECDSASecurity Admin (SA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key:
Page 79
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
SigVer (Data Plane IKEv2) RSA KeyGen (Data Plane IKEv2) RSA SigGen (Data Plane IKEv2) RSA SigVer (Data Plane IKEv2) Block Cipher (Data Plane IKEv2) DRBG FunctionG,W,E,Z - Data Plane Encryption ECDH Private Key: G,W,E,Z - Data Plane Encryption ECDH Public Key: G,W,E,Z - Data Plane Encryption Peer ECDH Public Key: G,W,E,Z - Data Plane Encryption ECDH Shared Secret: G,W,E,Z - Data Plane Encryption ECDSA Private Key: G,W,E,Z - Data Plane Encryption ECDSA Public Key: G,W,E,Z - Data Plane Encryption RSA Private Key: G,W,E,Z - Data
Page 80
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Plane Encryption RSA Public Key: G,W,E,Z - Data Plane Encryption Pre-shared Secret: G,W,E,Z - Data Plane Encryption IKE-SA Session Key: G,W,E,Z - Data Plane Encryption Child-SA Session Key: G,W,E,Z Network Admin (NA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - Data Plane Encryption ECDH Private Key: G,W,E,Z
Page 81
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- Data Plane Encryption ECDH Public Key: G,W,E,Z - Data Plane Encryption Peer ECDH Public Key: G,W,E,Z - Data Plane Encryption ECDH Shared Secret: G,W,E,Z - Data Plane Encryption ECDSA Private Key: G,W,E,Z - Data Plane Encryption ECDSA Public Key: G,W,E,Z - Data Plane Encryption RSA Private Key: G,W,E,Z - Data Plane Encryption RSA Public Key: G,W,E,Z - Data Plane Encryption
Page 82
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Pre-shared Secret: G,W,E,Z - Data Plane Encryption IKE-SA Session Key: G,W,E,Z - Data Plane Encryption Child-SA Session Key: G,W,E,Z Encryption Admin (EA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - Data Plane Encryption ECDH Private Key: G,W,E,Z - Data Plane Encryption ECDH Public Key: G,W,E,Z - Data Plane
Page 83
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Encryption Peer ECDH Public Key: G,W,E,Z - Data Plane Encryption ECDH Shared Secret: G,W,E,Z - Data Plane Encryption ECDSA Private Key: G,W,E,Z - Data Plane Encryption ECDSA Public Key: G,W,E,Z - Data Plane Encryption RSA Private Key: G,W,E,Z - Data Plane Encryption RSA Public Key: G,W,E,Z - Data Plane Encryption Pre-shared Secret: G,W,E,Z - Data Plane Encryption IKE-SA Session
Page 84
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key: G,W,E,Z - Data Plane Encryption Child-SA Session Key: G,W,E,Z Network Engineer (NE) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - Data Plane Encryption ECDH Private Key: G,W,E,Z - Data Plane Encryption ECDH Public Key: G,W,E,Z - Data Plane Encryption Peer ECDH Public Key: G,W,E,Z - Data Plane
Page 85
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Encryption ECDH Shared Secret: G,W,E,Z - Data Plane Encryption ECDSA Private Key: G,W,E,Z - Data Plane Encryption ECDSA Public Key: G,W,E,Z - Data Plane Encryption RSA Private Key: G,W,E,Z - Data Plane Encryption RSA Public Key: G,W,E,Z - Data Plane Encryption Pre-shared Secret: G,W,E,Z - Data Plane Encryption IKE-SA Session Key: G,W,E,Z - Data Plane Encryption Child-SA Session
Page 86
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key: G,W,E,Z Monitoring Access (MA) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - Data Plane Encryption ECDH Private Key: G,W,E,Z - Data Plane Encryption ECDH Public Key: G,W,E,Z - Data Plane Encryption Peer ECDH Public Key: G,W,E,Z - Data Plane Encryption ECDH Shared Secret: G,W,E,Z - Data Plane
Page 87
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Encryption ECDSA Private Key: G,W,E,Z - Data Plane Encryption ECDSA Public Key: G,W,E,Z - Data Plane Encryption RSA Private Key: G,W,E,Z - Data Plane Encryption RSA Public Key: G,W,E,Z - Data Plane Encryption Pre-shared Secret: G,W,E,Z - Data Plane Encryption IKE-SA Session Key: G,W,E,Z - Data Plane Encryption Child-SA Session Key: G,W,E,Z Provisionin g (PR) - DRBG Entropy Input:
Page 88
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V value: G,W,E,Z - DRBG Key: G,W,E,Z - Data Plane Encryption ECDH Private Key: G,W,E,Z - Data Plane Encryption ECDH Public Key: G,W,E,Z - Data Plane Encryption Peer ECDH Public Key: G,W,E,Z - Data Plane Encryption ECDH Shared Secret: G,W,E,Z - Data Plane Encryption ECDSA Private Key: G,W,E,Z - Data Plane Encryption
Page 89
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
ECDSA Public Key: G,W,E,Z - Data Plane Encryption RSA Private Key: G,W,E,Z - Data Plane Encryption RSA Public Key: G,W,E,Z - Data Plane Encryption Pre-shared Secret: G,W,E,Z - Data Plane Encryption IKE-SA Session Key: G,W,E,Z - Data Plane Encryption Child-SA Session Key: G,W,E,Z Turn-up and Test (TT) - DRBG Entropy Input: G,W,E,Z - DRBG Seed: G,W,E,Z - DRBG Internal State V
Page 90
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
value: G,W,E,Z - DRBG Key: G,W,E,Z - Data Plane Encryption ECDH Private Key: G,W,E,Z - Data Plane Encryption ECDH Public Key: G,W,E,Z - Data Plane Encryption Peer ECDH Public Key: G,W,E,Z - Data Plane Encryption ECDH Shared Secret: G,W,E,Z - Data Plane Encryption ECDSA Private Key: G,W,E,Z - Data Plane Encryption ECDSA Public Key: G,W,E,Z - Data Plane Encryption RSA
Page 91
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Private Key: G,W,E,Z - Data Plane Encryption RSA Public Key: G,W,E,Z - Data Plane Encryption Pre-shared Secret: G,W,E,Z - Data Plane Encryption IKE-SA Session Key: G,W,E,Z - Data Plane Encryption Child-SA Session Key: G,W,E,Z
Run OSPF ServiceGlobal approved mode indicator and OSPF service completio n status logCommand to run OSPF FunctionOSPF running statusOSPFv2 Authenticati onSecurity Admin (SA) - OSPFv2 Authenticat ion Key : W,E Network Admin (NA) - OSPFv2 Authenticat ion Key : W,E Encryption Admin (EA) - OSPFv2 Authenticat ion Key : W,E Network Engineer
Page 92
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
(NE) - OSPFv2 Authenticat ion Key : W,E Monitoring Access (MA) - OSPFv2 Authenticat ion Key : W,E Provisionin g (PR) - OSPFv2 Authenticat ion Key : W,E Turn-up and Test (TT) - OSPFv2 Authenticat ion Key : W,E
Configure NTP Authenticati onConfigure NTP Authenticati on Scheme and KeyGlobal approved mode indicator and NTP service configurati on statusCommand s to configure NTP serviceStatus of the completio n of NTP configurati onNTP Authenticati onSecurity Admin (SA) - NTP Authenticat ion Key : G,W,Z
Run LUKS Database Protection ServiceRun LUKS database protection serviceGlobal approved mode indicator and LUKS service completio n status logCommand to run LUKS protection serviceLUKS running statusLUKS Database ProtectionSecurity Admin (SA) - LUKS DB Password: W,E,Z - LUKS DB Salt : W,E,Z
4.4 Non-Approved Services
Page 93
4.5 External Software/Firmware Loaded

The module supports the firmware load test by using ECDSA with Curve P-521 and SHA2-512 (ECDSA Cert. #A4956) for the new validated firmware to be uploaded into the module. A Firmware Load Test Key was preloaded to the module’s binary at the factory and used for firmware load test. In order to load new firmware, the Crypto Officer must authenticate to the module before loading the firmware. This ensures that unauthorized access and use of the module is not performed. The module will load the new update upon reboot. The update attempt will be rejected if the verification fails. Any firmware loaded into this module that is not shown on the module certificate, is out of the scope of this validation and requires a separate FIPS 140-3 validation.

4.6 Bypass Actions and Status
4.7 Cryptographic Output Actions and Status

The module implements Self-initiated cryptographic output capability without external operator request. The Crypto Officer shall configure self-initiated cryptographic output capability. Prior to executing the self-initiated cryptographic output capability, the module conducts two independent internal actions to activate the capability to prevent the inadvertent output due to a single error.

4.8 Additional Information

The module supports unauthenticated service. The unauthenticated User/Operators can trigger the self-test service by power-cycling the module, and is able to observe the module’s LEDs status.

5 Software/Firmware Security
5.1 Integrity Techniques

The module is provided in the form of binary executable code. To ensure firmware security, the module is protected by conducting multiple layers firmware integrity tests. Please refer to section 10.1 Pre-Operational Self-Tests of this Security Policy document for more details. If the firmware integrity test fails, the module would enter to an Error state with all crypto functionality inhibited.

5.2 Initiate on Demand
Page 94
MechanismInspection FrequencyInspection Guidance
Production grade componentsN/AN/A
Storage Area NameDescriptionPersistence Type
DRAMVolatile memoryDynamic
FlashNon-Volatile memoryStatic

Integrity test is performed as part of the Pre-Operational Self-Tests. It is automatically executed at power-on. The operator can power-cycle or reboot the module to initiate the firmware integrity test on-demand.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited Module is operated in a limited operational environment. New firmware versions within the scope of this validation must be validated through the FIPS 140-3 CMVP. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation.

7 Physical Security

The module meets the FIPS 140-3 Level 1 security requirements as production grade equipment.

7.1 Mechanisms and Actions Required

Table 13: Mechanisms and Actions Required

8 Non-Invasive Security
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 14: Storage Areas © 2021-2025 Nokia Corporation

Page 95
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Module Public Key OutputModuleExternal (Outside the Module’s Boundary)PlaintextAutomatedElectronic
Peer Public Key InputExternal (Outside the Module’s Boundary)ModulePlaintextAutomatedElectronic
SSPs Input/Output protected by TLS KTS (GCM)External (Outside the Module’s Boundary)ModuleEncryptedAutomatedElectronicTLS KTS (GCM)
SSPs Input/Output protected by TLS KTS (AES and HMAC)External (Outside the Module’s Boundary)ModuleEncryptedAutomatedElectronicTLS KTS (AES and HMAC)
SSPs Input/Output protected by SSH KTS (GCM)External (Outside the Module’s Boundary)ModuleEncryptedAutomatedElectronicSSH KTS (GCM)
SSPs Input/Output protected by SSH KTS (AES and HMAC)External (Outside the Module’s Boundary)ModuleEncryptedAutomatedElectronicSSH KTS (AES and HMAC)
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroization commandCO issues zeroization service: "fips zeroize" to zeroize all SSPsThe zeroization command will erase all SSPs stored in the RAM and in the Flash of the module.Module Reboot
Session terminationZeroization upon session terminationSession termination will automatically zeroize all session based temporary SSPsTerminate session
9.2 SSP Input-Output Methods

Table 15: SSP Input-Output Methods

9.3 SSP Zeroization Methods
Page 96
Zeroization MethodDescriptionRationaleOperator Initiation
RebootZeroization upon rebooting the moduleReboot to zeroize all temporary SSPs stored in Module's DRAMReboot
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
DRBG Entropy InputUsed to seed the DRBG384 bits - At least 256 bitsEntropy Inputs - CSPDRBG Function
DRBG SeedUsed for DRBG generation256 bits - 256 bitsDRBG Seed - CSPDRBG Function
DRBG Internal State V valueUsed for DRBG generation256 bits - 256 bitsDRBG Internal State V value - CSPDRBG Function
DRBG KeyUsed for DRBG generation256 bits - 256 bitsDRBG Key - CSPDRBG Function
Operator PasswordUsed for operator authenticati on8-30 characte rs - N/AAuthenticati on Data - CSP
LUKS DB PasswordUsed for LUKS DB Integrity Key derivation512 bits - 512 bitsHMAC key - CSPDRBG FunctionLUKS Database Protection
LUKS DB SaltUsed for LUKS DB Integrity Key derivation256 bits - 256 bitsSalt - CSPDRBG FunctionLUKS Database Protection
LUKS DB Integrity KeyUsed for LUKS Database integrity protection512 bits - 512 bitsAuthenticati on - CSPPBKDF (A4958)LUKS Database Protection
Firmware Load Test KeyUsed for firmware load testP-521 - 256 bitsPublic Key - PSPFirmware Load Test

Table 16: SSP Zeroization Methods Please note that the Firmware Load Test Key is only used for Firmware Load Test Authentication and not subject to the zeroization requirement. h © 2021-2025 Nokia Corporation

Page 97
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
SSH DH Private KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 4096, and MODP- 8192 - 112-200 bitsPrivate Key - CSPKAS- FFC- KeyGen (SSH, TLS and Control Plane IKEv2)KAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)
SSH DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 4096, and MODP- 8192 - 112-200 bitsPublic Key - PSPKAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)
SSH Peer DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 4096, and MODP- 8192 - N/APublic Key - PSPKAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)
SSH DH Shared SecretUsed to derive SSH Encryption Key and SSH Integrity KeyMODP- 2048, MODP- 4096, and MODP- 8192 - 112-200 bitsShared Secret - CSPKAS-FFC (SSHv2)KAS-FFC (SSHv2)
SSH ECDH Private KeyUsed to derive SSH ECDH Shared SecretP-256, P-384, P-521 - 128-256 bitsPrivate Key - CSPKAS- ECC- KeyGen (SSH, TLS and Control Plane IKEv2)KAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2)
SSH ECDH Public KeyUsed to derive SSH ECDHP-256, P-384, P-521 -Public Key - PSPKAS-ECC- KeyGen (SSH, TLS and Control
Page 98
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
Shared Secret128-256 bitsPlane IKEv2)
SSH Peer ECDH Public KeyUsed to derive SSH ECDH Shared SecretP-256, P-384, P-521 - N/APublic Key - PSPKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2)
SSH ECDH Shared SecretUsed to derive SSH Encryption Key and SSH Integrity KeyP-256, P-384, P-521 - 128-256 bitsShared Secret - CSPKAS-ECC (SSHv2)KAS-ECC (SSHv2)
SSH ECDSA Private KeyUsed for SSH authenticati onP-256, P-384 and P- 521 - 128-256 bitsPrivate Key - CSPECDSA KeyGen (SSH, TLS and Control Plane IKEv2)ECDSA SigGen (SSH, TLS and Control Plane IKEv2)
SSH ECDSA Public KeyUsed for SSH authetnicati onP-256, P-384 and P- 521 - 128-256 bitsPublic Key - PSPECDSA KeyGen (SSH, TLS and Control Plane IKEv2)ECDSA SigVer (SSH, TLS and Control Plane IKEv2)
SSH RSA Private KeyUsed for SSH authetnicati on2048, 3072 and 4096 bits - 112 -152 bitsPrivate Key - CSPRSA KeyGen (SSH, TLS and Control Plane IKEv2)RSA SigGen (SSH, TLS and Control Plane IKEv2)
SSH RSA Public KeyUsed for SSH authetnicati on2048, 3072 and 4096 bits - 112 -152 bitsPublic Key - PSPRSA KeyGen (SSH, TLS and Control Plane IKEv2)RSA SigVer (SSH, TLS and Control Plane IKEv2)
SSH Encryption KeyUsed for SSH traffic protection128-256 bits - 128-256 bitsSymmetric Key - CSPKAS-ECC (SSHv2) KAS-FFC (SSHv2)Block Ciphers (SSHv2)
Page 99
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
SSH Integrity KeyUsed for SSH traffic integrity protectionat least 112 bits - at least 112 bitsAuthenticati on Key - CSPKAS-ECC (SSHv2) KAS-FFC (SSHv2)Block Ciphers (SSHv2)
TLS DH Private KeyUsed to drive TLS DH Shared Secretffdhe204 8 - 112 bitsPrivate Key - CSPKAS- FFC- KeyGen (SSH, TLS and Control Plane IKEv2)KAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)
TLS DH Public KeyUsed to drive TLS DH Shared Secretffdhe204 8 - 112 bitsPublic Key - PSPKAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)
TLS Peer DH Public KeyUsed to derive TLS DH Shared Secretffdhe204 8 - 112 bitsPublic Key - PSPKAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)
TLS DH Shared SecretUsed to derive TLS encryption Key and TLS Integrity Keyffdhe204 8 - 112 bitsShared Secret - CSPKAS-FFC (TLSv1.2/v1 .3)KAS-FFC (TLSv1.2/v1 .3)
TLS ECDH Private KeyUsed to drive TLS ECDH Shared SecretP-256, P-384 and P- 521 - 128-256 bitsPrivate Key - CSPKAS- ECC- KeyGen (SSH, TLS and Control Plane IKEv2)KAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2)
TLS ECDH Public KeyUsed to drive TLS ECDH Shared SecretP-256, P-384 and P- 521 - 128-256 bitsPublic Key - PSPKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2)
Page 100
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
TLS Peer ECDH Public KeyUsed to derive TLS ECDH Shared SecretP-256, P-384 and P- 521 - N/APublic Key - PSPKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2)
TLS ECDH Shared SecretUsed to derive TLS Encryption Key and TLS Integrity KeyP-256, P-384 and P- 521 - 128-256 bitsShared Secret - CSPKAS-ECC (TLSv1.2/v1 .3)KAS-ECC (TLSv1.2/v1 .3)
TLS ECDSA Private KeyUsed for TLS authenticati onP-256, P-384 and P- 521 - 128-256 bitsPrivate Key - CSPECDSA KeyGen (SSH, TLS and Control Plane IKEv2)ECDSA SigGen (SSH, TLS and Control Plane IKEv2)
TLS ECDSA Public KeyUsed for TLS authenticati onP-256, P-384 and P- 521 - 128-256 bitsPublic Key - PSPECDSA KeyGen (SSH, TLS and Control Plane IKEv2)ECDSA SigVer (SSH, TLS and Control Plane IKEv2)
TLS RSA Private KeyUsed for TLS authenticati on2048 bits - 112 bitsPrivate Key - CSPRSA KeyGen (SSH, TLS and Control Plane IKEv2)RSA SigGen (SSH, TLS and Control Plane IKEv2)
TLS RSA Public KeyUsed for TLS peer authenticati on2048 bits - 112 bitsPublic Key - PSPRSA KeyGen (SSH, TLS and Control Plane IKEv2)RSA SigVer (SSH, TLS and Control Plane IKEv2)
TLS Master SecretUsed to derive TLS Encryption Key and TLS Integrity Key384 bits - 384 bitsTLS Master Secret - CSPTLS Keying Materials Developme ntTLS Keying Materials Developme nt
Page 101
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
TLS Encryption KeyUsed to protect TLS traffic confidentiali ty.128-256 bits - 128-256 bitsEncryption Key - CSPKAS-ECC (TLSv1.2/v1 .3) KAS-FFC (TLSv1.2/v1 .3)Block Ciphers (TLSv1.2/v1 .3)
TLS Integrity KeyUsed to protect traffic confidentiali ty.at least 112 bits - at least 112 bitsAuthenticati on Key - CSPKAS-ECC (TLSv1.2/v1 .3) KAS-FFC (TLSv1.2/v1 .3)Block Ciphers (TLSv1.2/v1 .3)
IPSec/IKE DH Private KeyUsed for IPsec/IKE DH Shared Secret derivationMODP- 2048, MODP- 3072, MODP- 4096, MODP- 6144 and MODP- 8192 - 112-200 bitsPrivate Key - CSPKAS- FFC- KeyGen (SSH, TLS and Control Plane IKEv2)KAS-FFC- SSC Sp800- 56Ar3 (A4958)
IPSec/IKE DH Public KeyUsed for IPsec/IKE DH Shared Secret derivationMODP- 2048, MODP- 3072, MODP- 4096, MODP- 6144 and MODP- 8192 - 112-200 bitsPublic Key - PSPKAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)
IPSec/IKE Peer DH Public KeyUsed for IPsec/IKE DH Shared Secret derivationMODP- 2048, MODP- 3072, MODP- 4096, MODP- 6144 andPublic Key - PSPKAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)
Page 102
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
MODP- 8192 - N/A
IPSec/IKE DH Shared SecretUsed for IPSec/IKE Encryption Key and IPSec/IKE Integrity key derivationMODP- 2048, MODP- 3072, MODP- 4096, MODP- 6144 and MODP- 8192 - 112-200 bitsShared Secret - CSPKAS-FFC- KeyGen (SSH, TLS and Control Plane IKEv2)KAS-FFC (Control Plane IKEv2)
IPSec/IKE ECDH Private KeyUsed for IPSec/IKE ECDH Shared Secret derivationP-256, P-384 and P- 521 - 128-256 bitsPrivate Key - CSPKAS- ECC- KeyGen (SSH, TLS and Control Plane IKEv2)KAS-ECC (Control Plane IKEv2)
IPSec/IKE ECDH Public KeyUsed for IPSec/IKE ECDH Shared Secret derivationP-256, P-384 and P- 521 - 128-256 bitsPublic Key - PSPKAS-ECC- KeyGen (SSH, TLS and Control Plane IKEv2)
IPSec/IKE Peer ECDH Public KeyUsed for IPSec/IKE ECDH Shared Secret derivationP-256, P-384 and P- 521 - 128-256 bitsPublic Key - PSPKAS-ECC (Control Plane IKEv2)
IPSec/IKE ECDH Shared SecretUsed for IPSec/IKE Encryption Key and IPSec/IKE Integrity Key derivationP-256, P-384 and P- 521 - 128-256 bitsShared Secret - CSPKAS-ECC (Control Plane IKEv2)KAS-ECC (Control Plane IKEv2)
IPSec/IKE ECDSA Private KeyUsed for IPSec/IKE peerP-256, P-384 and P-Private Key - CSPECDSA SigGen (SSH,ECDSA SigGen (SSH, TLS
Page 103
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
authenticati on521 - 128-256 bitsTLS and Control Plane IKEv2)and Control Plane IKEv2)
IPSec/IKE ECDSA Public KeyUsed for IPSec/IKE peer authenticati onP-256, P-384 and P- 521 - 128-256 bitsPublic Key - PSPECDSA KeyGen (SSH, TLS and Control Plane IKEv2)ECDSA SigVer (SSH, TLS and Control Plane IKEv2)
IPSec/IKE RSA Private KeyUsed for IPSec/IKE peer authenticati on2048, 3072 and 4096 bits - 112-152 bitsPrivate Key - CSPRSA KeyGen (SSH, TLS and Control Plane IKEv2)RSA SigGen (SSH, TLS and Control Plane IKEv2)
IPSec/IKE RSA Public KeyUsed for IPSec/IKE peer authenticati on2048, 3072 and 4096 bits - 112-152 bitsPublic Key - PSPRSA KeyGen (SSH, TLS and Control Plane IKEv2)RSA SigVer (SSH, TLS and Control Plane IKEv2)
IPSec/IKE Pre-shared SecretUsed for IPSec/IKE peer authenticati on256 bits - N/AShared Secret - CSPIPsec/IKEv2 Keying Materials Developme nt
IPSec/IKE SKEYSEEDKeying material used to derive the IPSec/IKE Encryption Key and IPSec/IKE Integrity Key160 bits - N/AKeying Material - CSPIPsec/IKEv2 Keying Materials Developme nt
IPSec/IKE Encryption KeyUsed for IPSec/IKE traffic confidentiali ty protection128-256 bits - 128-256 bitsEncryption Key - CSPIPsec/IKEv2 Keying Materials Developme ntBlock Ciphers (Control Plane IKEv2)
Page 104
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
IPSec/IKE Integrity KeyUsed for IPSec/IKE traffic integrity protectionAt least 112 bits - At least 112 bitsAuthenticati on Key - CSPBlock Ciphers (Control Plane IKEv2)Block Ciphers (Control Plane IKEv2)
SNMPv3 Authenticati on SecretUsed to SNMPv3 authenticati on64 characte rs - N/AAuthenticati on Secret - CSPSNMPv3 Keying Materials Developme nt
SNMPv3 Encryption KeyUsed to secure SNMPv3 traffic confidentiali ty128-256 bits - 128-256 bitsSymmetric Key - CSPSNMPv3 Keying Materials Developme ntBlock Ciphers (SNMPv3)
SNMPv3 Integrity KeyUsed to secure SNMPv3 traffic integrityAt least 112 bits - At least 112 bitsAuthenticati on Key - CSPSNMPv3 Keying Materials Developme ntBlock Ciphers (SNMPv3)
Data Plane Encryption ECDH Private KeyUsed to derive Data Plane Encryption ECDH Shared SecretP-521 - 256 bitsPrivate Key - CSPKAS- ECC- KeyGen (Data Plane IKEv2)KAS-ECC (Data Plane IKEv2)
Data Plane Encryption ECDH Public KeyUsed to derive Data Plane Encryption ECDH Shared SecretP-521 - 256 bitsPublic Key - PSPKAS-ECC- KeyGen (Data Plane IKEv2)
Data Plane Encryption ECDH Shared SecretUsed to derive Data Plane Encryption IKE-SA Session Key and Data Plane Encryption Child-SA Session KeyP-521 - 256 bitsShared Secret - CSPKAS-ECC (Data Plane IKEv2)KAS-ECC (Data Plane IKEv2)
Page 105
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
Data Plane Encryption Peer ECDH Public KeyUsed to derive Data Plane Encryption ECDH Shared SecretP-521 - 256 bitsPublic Key - PSPKAS-ECC (Data Plane IKEv2)
Data Plane Encryption ECDSA Private KeyUsed for Data Plane Encryption authenticati onP-256, P-384 and P- 521 - 128-256 bitsPrivate Key - CSPECDSA KeyGen (Data Plane IKEv2)ECDSA SigGen (Data Plane IKEv2)
Data Plane Encryption ECDSA Public KeyUsed for Data Plane Encryption authenticati onP-256, P-384 and P- 521 - 128-256 bitsPublic Key - PSPECDSA KeyGen (Data Plane IKEv2)ECDSA SigVer (Data Plane IKEv2)
Data Plane Encryption RSA Private KeyUsed for Data Plane Encryption authenticati on2048, 3072 and 4096 bits - 112- 152 bitsPrivate Key - CSPRSA KeyGen (Data Plane IKEv2)RSA SigGen (Data Plane IKEv2)
Data Plane Encryption RSA Public KeyUsed for Data Plane Encryption authenticati on2048, 3072 and 4096 bits - 112- 152 bitsPublic Key - PSPRSA KeyGen (Data Plane IKEv2)RSA SigVer (Data Plane IKEv2)
Data Plane Encryption Pre-shared SecretUsed for Data Plane Encryption service authenticati onCurves: P-256, P-384, P-521 - 128-256 bitsShared Secret - CSPKAS-ECC (Data Plane IKEv2)
Data Plane Encryption IKE-SA Session KeyUsed to secure Data Plane Encryption traffic confidentiali ty256 bits - 256 bitsAuthenticat ed Symmetric Key - CSPKAS-ECC (Data Plane IKEv2)Block Cipher (Data Plane IKEv2)
Page 106
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
Data Plane Encryption Child-SA Session KeyUsed to secure Data Plane Encryption Child-SA traffic confidentiali ty256 bits - 256 bitsAuthenticat ed Symmetric Key - CSPKAS-ECC (Data Plane IKEv2)Block Cipher (Data Plane IKEv2)
NTP Authenticati on KeyUsed for NTP authenticati on8-40 characte rs - N/AAuthenticati on - CSPNTP Authenticati on
OSPFv2 Authenticati on KeyUsed for OSPFv2 authenticati on8-25 characte rs - N/AAuthenticati on - CSPOSPFv2 Authenticati on
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
DRBG Entropy InputDRAM:PlaintextUntil RebootZeroizatio n command Session terminatio n RebootDRBG Seed:Used With DRBG Internal State V value:Used With DRBG Key:Used With
DRBG SeedDRAM:PlaintextUntil RebootZeroizatio n command Session terminatio n RebootDRBG Entropy Input:Used With DRBG Internal State V value:Used With DRBG Key:Used With
DRBG Internal State V valueDRAM:PlaintextUntil RebootZeroizatio n command Session terminatio n RebootDRBG Entropy Input:Used With DRBG Seed:Used With DRBG Key:Used With
DRBG KeyDRAM:PlaintextUntil RebootZeroizatio n command Session terminatioDRBG Entropy Input:Used With DRBG Seed:Used With DRBG Internal

h Table 17: SSP Table 1 © 2021-2025 Nokia Corporation

Page 107
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
n RebootState V value:Used With
Operator PasswordSSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)Flash:Obfuscat edUntil zeroizedZeroizatio n command
LUKS DB PasswordFlash:PlaintextUntil zeroizedZeroizatio n commandLUKS DB Salt :Used With
LUKS DB SaltFlash:PlaintextUntil zeroizedZeroizatio n commandLUKS DB Password:Used With
LUKS DB Integrity KeyFlash:PlaintextUntil zeroizedZeroizatio n commandLUKS DB Password:Derived From LUKS DB Salt :Derived From
Firmware Load Test KeyFlash:PlaintextN/A. This PSP is only used for Firmware Load Test,N/A
Page 108
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
which is not subject to the zeroization requirement s.
SSH DH Private KeyDRAM:Plaintextwhile SSH session is onZeroizatio n command Session terminatio n RebootSSH DH Public Key:Paired With
SSH DH Public KeyModule Public Key OutputDRAM:Plaintextwhile SSH session is onZeroizatio n command Session terminatio n RebootSSH DH Private Key:Paired With
SSH Peer DH Public KeyPeer Public Key InputDRAM:Plaintextwhile SSH session is onZeroizatio n command Session terminatio n RebootSSH DH Private Key:Used With
SSH DH Shared SecretDRAM:Plaintextwhile SSH session is onZeroizatio n command Session terminatio n RebootSSH Encryption Key:Derived To SSH Integrity Key:Derived To SSH DH Private Key:Derived From SSH Peer DH Public Key:Derived From
SSH ECDH Private KeyDRAM:Plaintextwhile SSH session is onZeroizatio n command Session terminatio n RebootSSH ECDH Public Key:Paired With
SSH ECDH Public KeyModule Public Key OutputDRAM:Plaintextwhile SSH session is onZeroizatio n command Session terminatioSSH ECDH Private Key:Paired With
Page 109
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
n Reboot
SSH Peer ECDH Public KeyPeer Public Key InputDRAM:Plaintextwhile SSH session is onZeroizatio n command Session terminatio n RebootSSH ECDH Private Key:Used With
SSH ECDH Shared SecretDRAM:Plaintextwhile SSH session is onZeroizatio n command Session terminatio n RebootSSH ECDH Private Key:Derived From SSH Peer ECDH Public Key:Derived From SSH Encryption Key:Derive To SSH Integrity Key:Derive To
SSH ECDSA Private KeyFlash:PlaintextUntil zeroizedZeroizatio n commandSSH ECDSA Public Key:Paired With
SSH ECDSA Public KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protectedFlash:PlaintextUntil zeroizedZeroizatio n commandSSH ECDSA Private Key:Paired With
Page 110
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
by SSH KTS (AES and HMAC)
SSH RSA Private KeyFlash:PlaintextUntil zeroizedZeroizatio n commandSSH RSA Public Key:Paired With
SSH RSA Public KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)Flash:PlaintextUntil zeroizedZeroizatio n commandSSH RSA Private Key:Paired With
SSH Encryption KeyDRAM:Plaintextwhile SSH session is onZeroizatio n command Session terminatio n RebootSSH Integrity Key:Used With
SSH Integrity KeyDRAM:Plaintextwhile SSH session is onZeroizatio n command SessionSSH Encryption Key:Used With
Page 111
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
terminatio n Reboot
TLS DH Private KeyDRAM:Plaintextwhile TLS session is onZeroizatio n command Session terminatio n RebootTLS DH Public Key:Paired With
TLS DH Public KeyModule Public Key OutputDRAM:Plaintextwhile TLS tunnel is onZeroizatio n command Session terminatio n RebootTLS DH Private Key:Paired With
TLS Peer DH Public KeyPeer Public Key InputDRAM:Plaintextwhile TLS tunnel is onZeroizatio n command Session terminatio n RebootTLS DH Private Key:Used With TLS DH Shared Secret:Derived To
TLS DH Shared SecretDRAM:Plaintextwhile TLS tunnel is onZeroizatio n command Session terminatio n RebootTLS DH Private Key:Derived From TLS Peer DH Public Key:Derived From
TLS ECDH Private KeyDRAM:Plaintextwhile TLS tunnel is onZeroizatio n command Session terminatio n RebootTLS ECDH Public Key:Paired With
TLS ECDH Public KeyModule Public Key OutputDRAM:Plaintextwhile TLS tunnel is onZeroizatio n command Session terminatio n RebootTLS ECDH Private Key:Paired With
TLS Peer ECDH Public KeyPeer Public Key InputDRAM:Plaintextwhile TLS tunnel is onZeroizatio n commandTLS ECDH Private Key:Used With
Page 112
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
Session terminatio n Reboot
TLS ECDH Shared SecretDRAM:Plaintextwhile TLS tunnel is onZeroizatio n command Session terminatio n RebootTLS ECDH Private Key:Derived From TLS Peer ECDH Public Key:Derived From
TLS ECDSA Private KeyFlash:PlaintextUntil zeroizedZeroizatio n commandTLS ECDSA Public Key:Paired With
TLS ECDSA Public KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)Flash:PlaintextUntil zeroizedZeroizatio n commandTLS ECDSA Private Key:Paired With
TLS RSA Private KeyFlash:PlaintextUntil zeroizedZeroizatio n commandTLS RSA Public Key:Paired With
Page 113
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
TLS RSA Public KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)Flash:PlaintextUntil zeroizedZeroizatio n commandTLS RSA Private Key:Paired With
TLS Master SecretDRAM:Plaintextwhile TLS session is onZeroizatio n command Session terminatio n RebootTLS DH Shared Secret:Derived From
TLS Encryption KeyDRAM:Plaintextwhile TLS session is onZeroizatio n command Session terminatio n RebootTLS Integrity Key:Used With
TLS Integrity KeyDRAM:Plaintextwhile TLS session is onZeroizatio n command SessionTLS Encryption Key:Used With
Page 114
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
terminatio n Reboot
IPSec/IKE DH Private KeyDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootIPSec/IKE DH Public Key:Paired With
IPSec/IKE DH Public KeyModule Public Key OutputDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootIPSec/IKE DH Private Key:Paired With
IPSec/IKE Peer DH Public KeyPeer Public Key InputDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootIPSec/IKE DH Private Key:Used With
IPSec/IKE DH Shared SecretDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootIPSec/IKE SKEYSEED:Deriv e TO
IPSec/IKE ECDH Private KeyDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootIPSec/IKE ECDH Public Key:Paired With
IPSec/IKE ECDH Public KeyModule Public Key OutputDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootIPSec/IKE ECDH Private Key:Paired With
IPSec/IKE Peer ECDH Public KeyPeer Public Key InputDRAM:Plaintextwhile Control PanelZeroizatio n commandIPSec/IKE ECDH Private Key:Used With
Page 115
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
IPSec/IKE session is onSession terminatio n Reboot
IPSec/IKE ECDH Shared SecretDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootIPSec/IKE SKEYSEED:Deriv e To
IPSec/IKE ECDSA Private KeyFlash:PlaintextUntil zeroizedZeroizatio n commandIPSec/IKE ECDSA Public Key:Paired With
IPSec/IKE ECDSA Public KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)Flash:PlaintextUntil zeroizedZeroizatio n commandIPSec/IKE ECDSA Private Key:Paired With
IPSec/IKE RSA Private KeyFlash:PlaintextUntil zeroizedZeroizatio n commandIPSec/IKE RSA Public Key:Paired With
Page 116
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
IPSec/IKE RSA Public KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)Flash:PlaintextUntil zeroizedZeroizatio n commandIPSec/IKE RSA Private Key:Paired With
IPSec/IKE Pre-shared SecretSSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protectedFlash:PlaintextUntil zeroizedZeroizatio n commandIPSec/IKE SKEYSEED:Deriv ed To
Page 117
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)
IPSec/IKE SKEYSEEDDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootTLS ECDH Shared Secret:Derived From IPSec/IKE DH Shared Secret:Derived From
IPSec/IKE Encryption KeyDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootIPSec/IKE SKEYSEED:Deriv ed From
IPSec/IKE Integrity KeyDRAM:Plaintextwhile Control Panel IPSec/IKE session is onZeroizatio n command Session terminatio n RebootIPSec/IKE SKEYSEED:Deriv ed From
SNMPv3 Authenticati on SecretSSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC)Flash:PlaintextUntil zeroizedZeroizatio n command
Page 118
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)
SNMPv3 Encryption KeyDRAM:Plaintextwhile SNMPv3 session is onZeroizatio n command Session terminatio n RebootSNMPv3 Authentication Secret:Derived From SNMPv3 Integrity Key:Used With
SNMPv3 Integrity KeyDRAM:Plaintextwhile SNMPv3 session is onZeroizatio n command Session terminatio n RebootSNMPv3 Authentication Secret:Derived From SNMPv3 Encryption Key:Used With
Data Plane Encryption ECDH Private KeyDRAM:Plaintextwhile Data Plane Encryption session is onZeroizatio n command Session terminatio n RebootData Plane Encryption ECDH Public Key:Paired With
Data Plane Encryption ECDH Public KeyModule Public Key OutputDRAM:Plaintextwhile Data Plane Encryption session is onZeroizatio n command Session terminatio n RebootIPSec/IKE ECDH Private Key:Paired With
Data Plane Encryption ECDH Shared SecretDRAM:Plaintextwhile Data Plane Encryption session is onZeroizatio n command Session terminatioData Plane Encryption ECDH Private Key:Derived From Data Plane
Page 119
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
n RebootEncryption Peer ECDH Public Key:Derived From Data Plane Encryption IKE-SA Session Key:Derived To Data Plane Encryption Child- SA Session Key :Derived To
Data Plane Encryption Peer ECDH Public KeyPeer Public Key InputDRAM:Plaintextwhile Data Plane Encryption session is onZeroizatio n command Session terminatio n RebootData Plane Encryption ECDH Private Key:Used With
Data Plane Encryption ECDSA Private KeyFlash:PlaintextUntil zeroizedZeroizatio n commandData Plane Encryption ECDSA Private Key:Paired With
Data Plane Encryption ECDSA Public KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protectedFlash:PlaintextUntil zeroizedZeroizatio n commandData Plane Encryption ECDSA Private Key:Paired With
Page 120
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
by SSH KTS (AES and HMAC)
Data Plane Encryption RSA Private KeyFlash:PlaintextUntil zeroizedZeroizatio n commandData Plane Encryption RSA Public Key:Paired With
Data Plane Encryption RSA Public KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)Flash:PlaintextUntil zeroizedZeroizatio n commandData Plane Encryption RSA Private Key:Paired With
Data Plane Encryption Pre-shared SecretSSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp utFlash:Obfuscat edUntil zeroizedZeroizatio n commandIPSec/IKE SKEYSEED:Used With IPSec/IKE Encryption Key:Derived to IPSec/IKE Authentication Key:Derived to
Page 121
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)
Data Plane Encryption IKE-SA Session KeyDRAM:Plaintextwhile Data Plane Encryption session is onZeroizatio n command Session terminatio n RebootData Plane Encryption ECDH Shared Secret:Derived From
Data Plane Encryption Child-SA Session KeyDRAM:Plaintextwhile Data Plane Encryption session is onZeroizatio n command Session terminatio n RebootData Plane Encryption ECDH Shared Secret:Derived From
NTP Authenticati on KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES andFlash:PlaintextUntil zeroizedZeroizatio n command
Page 122
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)
OSPFv2 Authenticati on KeySSPs Input/Outp ut protected by TLS KTS (GCM) SSPs Input/Outp ut protected by TLS KTS (AES and HMAC) SSPs Input/Outp ut protected by SSH KTS (GCM) SSPs Input/Outp ut protected by SSH KTS (AES and HMAC)Flash:PlaintextUntil ZeroizedZeroizatio n command

Table 18: SSP Table 2 © 2021-2025 Nokia Corporation

Page 123
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Gecko Firmware Bootloader Integrity TestECDSA SigVer P-256 with SHA2-256KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A3366
Gecko Firmware Application Integrity TestECDSA SigVer P-256 with SHA2-256KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A3366
CHM6_Zynq Firmware Bootloader Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4955
DCO_NXP Firmware Bootloader Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4955
DCO_Zynq Firmware Bootloader Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4955
XMM4_Intel Firmware Bootloader Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4955
9.5 Transitions
10 Self-Tests
10.1 Pre-Operational Self-Tests
Page 124
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
CHM6_Zynq Firmware Kernel Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4952
CHM6_Zynq Firmware init script Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4948
CHM6_Zynq Firmware Application Manifest file Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4948
CHM6_Zynq Firmware Application Integrity TestSHA2-512KATSW/FW IntegrityModule is in normal stateSHA2-512 from SHA Cert. #A4954
DCO_NXP Firmware Kernel Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA from ECDSA Cert. #A4953
DCO_NXP Firmware init script IntegrityECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4949
DCO_NXP Firmware Application Manifest file Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4949
DCO_NXP Firmware Application Integrity TestSHA2-512KATSW/FW IntegrityModule is in normal stateSHA2-512 from SHA Cert. #A4954
DCO_Zynq Firmware Kernel Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4961
DCO_Zynq Firmware Application Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4960
XMM4_Intel Firmware Kernel Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4962
XMM4_Intel Firmware init script Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA from ECDSA Cert. #A4956
XMM4 Intel Firmware Application Manifest file Integrity TestECDSA SigVer P-521 with SHA2-512KATSW/FW IntegrityModule is in normal stateECDSA SigVer from ECDSA Cert. #A4956
Page 125
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
XMM4 Intel Firmware Application Integrity TestSHA2-512KATSW/FW IntegrityModule is in normal stateSHA2-512 from SHA Cert. #A4958
Algorithm or TestTest Properti esTest MethodTest TypeIndicat orDetailsConditio ns
SHA2-256 KAT (A3366)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A3366)Curve: P-256Known Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-512 KAT (A4955)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A4955)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-512 KAT (A4960)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A4960)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up

Table 19: Pre-Operational Self-Tests The module performs the following self-tests, including the pre-operational self-tests and Conditional self-tests. Prior to the module providing any data output via the data output interface, the module performs and passes the pre-operational self-tests. Following the successful pre-operational self-tests, the module executes the Conditional Cryptographic Algorithm Self-tests (CASTs). If anyone of the self-tests fails, the module transitions into an error state and outputs the error message via the module’s status output interface. While the module is in the error state, all data through the data output interface and all cryptographic operations are disabled. The error state can only be cleared by reloading the module. All self-tests must be completed successfully before the module transitions to the operational state.

10.2 Conditional Self-Tests
Page 126
Algorithm or TestTest Properti esTest MethodTest TypeIndicat orDetailsConditio ns
SHA2-512 KAT (A4961)SHA2- 512Known Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A4961)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-512 KAT (A4948)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A4948)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-512 KAT (A4952)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A4952)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-512 KAT (A4949)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A4949)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-512 KAT (A4953)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A4953)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-512 KAT (A4954)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
AES-CBC Encrypt KAT (A4959)128 bitsKnown AnswerCASTModule is inEncryption KATPower up
Page 127
Algorithm or TestTest Properti esTest Method Test (KAT)Test TypeIndicat or normal stateDetailsConditio ns
AES-CBC Decrypt KAT (A4959)128 bitsKnown Answer Test (KAT)CASTModule is in normal stateDecryption KATPower up
AES-GCM Authenticated Encrypt KAT (A4959)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Encryption KATPower up
AES-GCM Authenticated Decrypt KAT (A4959)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Decryption KATPower up
Counter DRBG Generate/Reseed/Insta ntiate KAT (A4959)N/AKnown Answer Test (KAT)CASTModule is in normal stateGenerate KAT, Reseed KAT, and Instantiate KATPower up
KDF IKEv2 KAT (A4959)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
KAS-ECC-SSC Sp800- 56Ar3 KAT (A4959)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up
RSA SigGen (FIPS186- 4) KAT (A4959)Modulus: 2048 bitsKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
RSA SigVer (FIPS186- 4) KAT (A4959)Modulus: 2048 bitsKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-512 KAT (A4959)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC-SHA2-512 KAT (A4959)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A4962)Curve: P-521Known AnswerCASTModule is inN/APower up
Page 128
Algorithm or TestTest Properti esTest Method Test (KAT)Test TypeIndicat or normal stateDetailsConditio ns
SHA2-512 KAT (A4962)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
AES-CBC Encrypt KAT (A4956)128, 192 and 256 bitsKnown Answer Test (KAT)CASTModule is in normal stateEncryption KATPower up
AES-CBC Decrypt KAT (A4956)128, 192 and 256 bitsKnown Answer Test (KAT)CASTModule is in normal stateDecryption KATPower up
AES-CCM Authenticated Encrypt KAT (A4956)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Encryption KATPower up
AES-CCM Authenticated Decrypt KAT (A4956)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Decryption KATPower up
AES-GCM Authenticated Encrypt KAT (A4956)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Encryption KATPower up
AES-GCM Authenticated Decrypt KAT (A4956)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Decryption KATPower up
HMAC-SHA-1 KAT (A4956)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC-SHA2-256 KAT (A4956)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC-SHA2-384 KAT (A4956)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC-SHA2-512 KAT (A4956)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
Page 129
Algorithm or TestTest Properti esTest MethodTest TypeIndicat orDetailsConditio ns
ECDSA SigVer (FIPS186-4) KAT (A4956)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-256 KAT (A4957)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC-SHA2-256 KAT (A4957)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
AES-ECB Encrypt KAT (A4958)128 bitsKnown Answer Test (KAT)CASTModule is in normal stateEncryption KATPower up
AES-ECB Decrypt KAT (A4958)128 bitsKnown Answer Test (KAT)CASTModule is in normal stateDecryption KATPower up
AES-GCM Authenticated Encrypt KAT (A4958)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Encryption KATPower up
AES-GCM Authenticated Decrypt KAT (A4958)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Decryption KATPower up
Counter DRBG Generate/Reseed/Insta ntiate KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateGenerate KAT, Reseed KAT, and Instantiate KATPower up
ECDSA SigGen (FIPS186-4) KAT (A4958)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up
ECDSA SigVer (FIPS186-4) KAT (A4958)Curve: P-521Known Answer Test (KAT)CASTModule is in normal stateN/APower up
HMAC-SHA2-256 KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
Page 130
Algorithm or TestTest Properti esTest MethodTest TypeIndicat orDetailsConditio ns
KDF SSH KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
KDF IKEv2 KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
KDF SNMP KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
TLS v1.2 KDF RFC7627 KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
TLS v1.3 KDF KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
KAS-ECC-SSC KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateKAS-ECC- SSC Primitive ZPower up
KAS-FFC-SSC KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateKAS-FFC- SSC Primitive ZPower up
PBKDF KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
RSA SigGen KAT (A4958)Modulus: 2048 bitsKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
RSA SigVer KAT (A4958)Modulus: 2048 bitsKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA-1 KAT (A4958)N/AKnown Answer Test (KAT)CASTModule is in normal stateN/APower up
SHA2-512 KAT (A4958)N/AKnown AnswerCASTModule is inN/APower up
Page 131
Algorithm or TestTest Properti esTest Method Test (KAT)Test TypeIndicat or normal stateDetailsConditio ns
AES-GCM Authenticated Encrypt KAT (C501)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Encryption KATPower up
AES-GCM Authenticated Decrypt KAT (C501)256 bitsKnown Answer Test (KAT)CASTModule is in normal stateAuthenticat ed Decryption KATPower up
Entropy Source Start-up Health Test (RCT)N/ARCTCASTModule is in normal stateN/APower up
Entropy Source Start-up Health Test (APT)N/AAPTCASTModule is in normal stateN/APower up
Entropy Source Continuous Health Test (RCT)N/ARCTCASTModule is in normal stateN/APower up
Entropy Source Continuous Health Test (APT)N/AAPTCASTModule is in normal stateN/APower up
ECDSA KeyGen (FIPS186-4) PCT (A4958)Curve: P-256Pair-Wise Consisten cy Test (PCT)PCTModule is in normal stateN/AECDSA Keypair generatio n
RSA KeyGen (FIPS186- 4) PCT (A4958)Modulus: 2048 bitsPair-Wise Consisten cy Test (PCT)PCTModule is in normal stateN/ARSA Keypair generatio n
KAS-ECC-SSC (FIPS186-4) PCT (A4958)Curve: P-256Pair-Wise Consisten cy Test (PCT)PCTModule is in normal stateN/AKAS- ECC Keypair generatio n
KAS-FFC-SSC (FIPS186-4) PCT (A4958)MODP- 2048Pair-Wise Consisten cy Test (PCT)PCTModule is in normal stateN/AKAS-FFC Keypair generatio n
KAS-ECC-SSC Sp800- 56Ar3 PCT (A4959)Curve: P-256Pair-Wise Consisten cy Test (PCT)PCTModule is in normal stateN/AECDSA Keypair generatio n
Page 132
Algorithm or TestTest Properti esTest MethodTest TypeIndicat orDetailsConditio ns
ECDSA KeyGen (FIPS186-4) PCT (A4959)Curve: P-256Pair-Wise Consisten cy Test (PCT)PCTModule is in normal stateN/AECDSA Keypair generatio n
Firmware Load TestCurve: P-521ECDSA SigVerSW/F W LoadModule is in normal stateN/AFirmware Load Test
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Gecko Firmware Bootloader Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
Gecko Firmware Application Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
CHM6_Zynq Firmware Bootloader Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
DCO_NXP Firmware Bootloader Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
DCO_Zynq Firmware Bootloader Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
XMM4_Intel Firmware Bootloader Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
CHM6_Zynq Firmware Kernel Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
CHM6_Zynq Firmware initKATSW/FW IntegrityOn-demandModule Reboot

Table 20: Conditional Self-Tests The module performs on-demand self-tests initiated by the operator, by powering off and powering the module back on. The full suite of self-tests is then executed. The same procedure may be employed by the operator to perform periodic self-tests.

10.3 Periodic Self-Test Information
Page 133
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
script Integrity Test
CHM6_Zynq Firmware Application Manifest file Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
CHM6_Zynq Firmware Application Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
DCO_NXP Firmware Kernel Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
DCO_NXP Firmware init script IntegrityKATSW/FW IntegrityOn-demandModule Reboot
DCO_NXP Firmware Application Manifest file Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
DCO_NXP Firmware Application Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
DCO_Zynq Firmware Kernel Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
DCO_Zynq Firmware Application Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
XMM4_Intel Firmware Kernel Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
XMM4_Intel Firmware init script Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
XMM4 Intel Firmware Application Manifest file Integrity TestKATSW/FW IntegrityOn-demandModule Reboot
XMM4 Intel FirmwareKATSW/FW IntegrityOn-demandModule Reboot
Page 134
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Application Integrity Test
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-256 KAT (A3366)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A3366)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4955)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A4955)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4960)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A4960)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4961)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A4961)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4948)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A4948)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4952)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A4952)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4949)Known Answer Test (KAT)CASTOn-demandModule Reboot

Table 21: Pre-Operational Periodic Information © 2021-2025 Nokia Corporation

Page 135
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA SigVer (FIPS186-4) KAT (A4949)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4953)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A4953)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4954)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-CBC Encrypt KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-CBC Decrypt KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-GCM Authenticated Encrypt KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-GCM Authenticated Decrypt KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
Counter DRBG Generate/Reseed/Instantiate KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
KDF IKEv2 KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
KAS-ECC-SSC Sp800- 56Ar3 KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
RSA SigGen (FIPS186-4) KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
RSA SigVer (FIPS186-4) KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
HMAC-SHA2-512 KAT (A4959)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A4962)Known Answer Test (KAT)CASTOn-demandModule Reboot
Page 136
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-512 KAT (A4962)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-CBC Encrypt KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-CBC Decrypt KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-CCM Authenticated Encrypt KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-CCM Authenticated Decrypt KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-GCM Authenticated Encrypt KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-GCM Authenticated Decrypt KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
HMAC-SHA-1 KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
HMAC-SHA2-256 KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
HMAC-SHA2-384 KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
HMAC-SHA2-512 KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A4956)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-256 KAT (A4957)Known Answer Test (KAT)CASTOn-demandModule Reboot
HMAC-SHA2-256 KAT (A4957)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-ECB Encrypt KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-ECB Decrypt KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
Page 137
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM Authenticated Encrypt KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-GCM Authenticated Decrypt KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
Counter DRBG Generate/Reseed/Instantiate KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigGen (FIPS186-4) KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
ECDSA SigVer (FIPS186-4) KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
HMAC-SHA2-256 KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
KDF SSH KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
KDF IKEv2 KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
KDF SNMP KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
TLS v1.2 KDF RFC7627 KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
TLS v1.3 KDF KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
KAS-ECC-SSC KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
KAS-FFC-SSC KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
PBKDF KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
RSA SigGen KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
RSA SigVer KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
Page 138
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
SHA2-512 KAT (A4958)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-GCM Authenticated Encrypt KAT (C501)Known Answer Test (KAT)CASTOn-demandModule Reboot
AES-GCM Authenticated Decrypt KAT (C501)Known Answer Test (KAT)CASTOn-demandModule Reboot
Entropy Source Start-up Health Test (RCT)RCTCASTOn-demandModule Reboot
Entropy Source Start-up Health Test (APT)APTCASTOn-demandModule Reboot
Entropy Source Continuous Health Test (RCT)RCTCASTOn-demandModule Reboot
Entropy Source Continuous Health Test (APT)APTCASTOn-demandModule Reboot
ECDSA KeyGen (FIPS186- 4) PCT (A4958)Pair-Wise Consistency Test (PCT)PCTOn-demandModule Reboot
RSA KeyGen (FIPS186-4) PCT (A4958)Pair-Wise Consistency Test (PCT)PCTOn-demandModule Reboot
KAS-ECC-SSC (FIPS186-4) PCT (A4958)Pair-Wise Consistency Test (PCT)PCTOn-demandModule Reboot
KAS-FFC-SSC (FIPS186-4) PCT (A4958)Pair-Wise Consistency Test (PCT)PCTOn-demandModule Reboot
KAS-ECC-SSC Sp800- 56Ar3 PCT (A4959)Pair-Wise Consistency Test (PCT)PCTOn-demandModule Reboot
ECDSA KeyGen (FIPS186- 4) PCT (A4959)Pair-Wise Consistency Test (PCT)PCTOn-demandModule Reboot
Firmware Load TestECDSA SigVerSW/FW LoadOn-demandModule Reboot

Table 22: Conditional Periodic Information

10.4 Operator Initiation of Self-Tests

On demand and periodic self-tests are performed by powering off the module and powering it on again. This service performs the same cryptographic algorithm tests executed during pre-operational self-tests and CASTs. During the execution of the periodic and on-demand © 2021-2025 Nokia Corporation

Page 139
NameDescriptionConditionsRecovery MethodIndicator
Error StateIf self-test tests fail, the module is put into an error stateSelf-tests failureReboot the moduleSystem Halt

self-tests, crypto services are not available and no data output or input is possible.

10.5 Error States

Table 23: Error States If any of the above-mentioned self-tests fail, the module reports the error and enters the Error state. In the Error State, no cryptographic services are provided, and data output is prohibited. The only method to recover from the error state is to reboot the module and perform the selftests, including the pre-operational firmware integrity test and the conditional CASTs. The module will only enter into the operational state after successfully passing the pre-operational firmware integrity test and the conditional CASTs.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module meets all the Level 1 requirements for FIPS 140-3. Follow the secure operations provided below to place the module in approved mode. Operating this module without maintaining the following settings would put module operated in a non-compliance state. Secure Operation The Security Admin (SA) must configure and enforce the following initialization steps. Step

  1. Strictly follow up the steps in section Physical Security to place the Opacity Shield and Tamper Evident Labels on the module. Step
  2. Ensure that the firmware version R6.2.2 or R6.2.3 is running on the module. To verify the firmware version, the Security Admin (SA) shall use the following command. >show sw-management software-load-active swload-version swload-label software-load-active swload-version 'R6.2.2' or >show sw-management software-load-active swload-version swload-label software-load-active swload-version 'R6.2.3' Step
  3. Enable approved mode. © 2021-2025 Nokia Corporation
Page 140

Execute the following steps to enable approved mode on the module: • To enable approved mode via CLI: Execute the following command from the CLI interface: ‘fips mode-enable’ A confirmation message is displayed. Enter y to proceed with the operation. This operation will cold reboot the system, delete the entire system configuration, including networking details, and may leave the system unreachable until the reboot is complete. • To enable approved mode via WebGUI: Navigate to Security > FIPS tab. Click ‘FIPS Control’. A pop-up window is displayed. Select mode-enable against Action field and click Submit. A success message is displayed Step

  1. Create the User account and privileges for other roles defined in the Security Policy. Step
  2. Ensuring that any of the deleted/deprecated algorithms by NIST SP800-140Crev2 and/or NIST SP800-131Arev2 are disabled as applicable in the FIPS 140-3 validated firmware.
11.2 Administrator Guidance

No specific Administrator guidance.

11.3 Non-Administrator Guidance

No specific Non-Administrator guidance.

12 Mitigation of Other Attacks

N/A for this module. © 2021-2025 Nokia Corporation