All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Ruckus FastIron ICXTM 7550/7650/7850 Series Switch/Router

Certificate#5076StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorRuckus Wireless LLC
High review priority  ·  no TCB surface named  ·  last validated 9 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date10/2/2030
CaveatWhen installed, initialized and configured as specified in Section Life-Cycle Assurance of the Security Policy
VendorRuckus Wireless LLC

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Ruckus FastIron ICXTM 7550/7650/7850 Series Switch/Router
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>bootloader<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Ruckus FastIron ICXTM 7550/7650/7850 Series Switch/Router
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>status output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>bootloader<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Ruckus Wireless LLC Ruckus FastIron ICXTM 7550/7650/7850 Series Switch/Router

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Hardware11
Table 3: Modes List and Description14
Table 4: Approved Algorithms - Crypto Library I15
Table 5: Approved Algorithms - Crypto Library II15
Table 6: Vendor-Affirmed Algorithms15
Table 7: Security Function Implementations21
Table 8: Entropy Certificates22
Table 9: Entropy Sources22
Table 10: Ports and Interfaces24
Table 11: Authentication Methods26
Table 12: Roles26
Table 13: Approved Services38
Table 14: Storage Areas40
Table 15: SSP Input-Output Methods41
Table 16: SSP Zeroization Methods41
Table 17: SSP Table 147
Table 18: SSP Table 253
Table 19: Pre-Operational Self-Tests54
Table 20: Conditional Self-Tests59
Table 21: Pre-Operational Periodic Information59
Table 22: Conditional Periodic Information61
Table 23: Error States61
Figure 1: ICX 7550-247
Figure 2: ICX 7550-24F7
Figure 3: ICX 7550-24P7
Figure 4: ICX 7550-24ZP8
Figure 5: ICX 7550-488
Figure 6: ICX 7550-48F8
Figure 7: ICX 7550-48P8
Figure 8: ICX 7550-48ZP9
Figure 9: ICX 7650-48ZP9
Figure 10: ICX 7650-48P9
Figure 11: ICX 7650-48F10
Figure 12: ICX 7850-32Q10
Figure 13: ICX 7850-48FS10
Figure 14: ICX 7850-48F10
Figure 15: ICX 7850-48C10
Figure 16: ICX-7550 Series12
Figure 17: ICX-7650 Series13
Figure 18: ICX-7850 Series13
Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication2
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This is a non-proprietary cryptographic module security policy for Ruckus FastIron ICX™ 7550/7650/7850 Series Switch/Router (hereinafter referred to as the module). The firmware version running on each module is IronWare OS 10.0.10. This security policy describes how the module meets the FIPS 140-3 Level 1 security requirements, and how to operate the module in an approved mode. This security policy may be freely distributed. FIPS 140-3 (Federal Information Processing Standards Publication 140-3 — Security Requirements for Cryptographic Modules) details the U.S. Government requirements for cryptographic modules. More information about the FIPS 140-3 standard and validation program is available on the NIST website at https://csrc.nist.gov/projects/cryptographic-modulevalidation-program.

1.2 Security Levels
2.1 Description

Purpose and Use: The module delivers the performance, flexibility, and scalability required for enterprise access deployment. Module Type: Hardware Module Embodiment: MultiChipStand Module Characteristics:

Page 7

Cryptographic Boundary: The Tested Operational Environment Physical Perimeter (TOEPP) is defined as the entire chassis unit’s physical perimeter encompassing the "top," "front," "left," "right," “rear” and "bottom" surfaces of the case as shown in the figures below and in the Physical Security section. The cryptographic boundary encompasses the entire TOEPP. This section illustrates the module hardware with the help of photographs. Figure 1: ICX 7550-24 Figure 2: ICX 7550-24F Figure 3: ICX 7550-24P

Page 8

Figure 4: ICX 7550-24ZP Figure 5: ICX 7550-48 Figure 6: ICX 7550-48F Figure 7: ICX 7550-48P

Page 9

Figure 8: ICX 7550-48ZP Figure 9: ICX 7650-48ZP Figure 10: ICX 7650-48P

Page 10

Figure 11: ICX 7650-48F Figure 12: ICX 7850-32Q Figure 13: ICX 7850-48FS Figure 14: ICX 7850-48F Figure 15: ICX 7850-48C

Page 11
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
ICX-7550-24ICX-7550-24IronWare OS 10.0.10ARM Cortex A72 (ARMv8)
ICX-7550-24PICX-7550-24PIronWare OS 10.0.10ARM Cortex A72 (ARMv8)
ICX-7550- 24ZPICX-7550- 24ZPIronWare OS 10.0.10ARM Cortex A72 (ARMv8)
ICX-7550-24FICX-7550-24FIronWare OS 10.0.10ARM Cortex A72 (ARMv8)
ICX-7550-48ICX-7550-48IronWare OS 10.0.10ARM Cortex A72 (ARMv8)
ICX-7550-48PICX-7550-48PIronWare OS 10.0.10ARM Cortex A72 (ARMv8)
ICX-7550- 48ZPICX-7550- 48ZPIronWare OS 10.0.10ARM Cortex A72 (ARMv8)
ICX-7550-48FICX-7550-48FIronWare OS 10.0.10ARM Cortex A72 (ARMv8)
ICX-7650-48PICX-7650-48PIronWare OS 10.0.10ARM Cortex A57 (ARMv8)
ICX-7650- 48ZPICX-7650- 48ZPIronWare OS 10.0.10ARM Cortex A57 (ARMv8)
ICX-7650-48FICX-7650-48FIronWare OS 10.0.10ARM Cortex A57 (ARMv8)
ICX-7850-32QICX-7850-32QIronWare OS 10.0.10ARM Cortex A57 (ARMv8)
ICX-7850- 48FSICX-7850- 48FSIronWare OS 10.0.10ARM Cortex A57 (ARMv8)
ICX-7850-48FICX-7850-48FIronWare OS 10.0.10ARM Cortex A57 (ARMv8)
ICX-7850-48CICX-7850-48CIronWare OS 10.0.10ARM Cortex A57 (ARMv8)
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 12

Figure 16: ICX-7550 Series Note: The USB Port for external file storage is functionally disabled

Page 13

Figure 17: ICX-7650 Series Note: The USB Port for external file storage is functionally disabled Figure 18: ICX-7850 Series

Page 14
Mode NameDescriptionTypeStatus Indicator
Approved Mode of OperationThe module is always in the approved mode of operation after initial operations are performed.ApprovedGlobal indicator after module initialization. Please refer to Security Policy, section Life-Cycle Assurance for more information
AlgorithmCAVP CertPropertiesReference
AES-CBCA5076-SP 800-38A
AES-CFB128A5076-SP 800-38A

Note: The USB Port for external file storage is functionally disabled Tested Module Identification

2.3 Excluded Components

Modes List and Description: Table 3: Modes List and Description By default, the module is delivered in an un-initialized state but supports an approved mode of following the steps in section " Life-Cycle Assurance" of this document by the Crypto Officer, the module can only operate in the approved mode. The module does not claim implementation of a

2.5 Algorithms

Approved Algorithms: Crypto Library I

Page 15
AlgorithmCAVP CertPropertiesReference
AES-CMACA5076-SP 800-38B
AES-CTRA5076-SP 800-38A
AES-ECBA5076-SP 800-38A
AES-GCMA5076-SP 800-38D
AES-KWA5076-SP 800-38F
AES-KWPA5076-SP 800-38F
Counter DRBGA5076-SP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A5076-FIPS 186-5
ECDSA SigGen (FIPS186-5)A5076-FIPS 186-5
ECDSA SigVer (FIPS186-5)A5076-FIPS 186-5
HMAC-SHA-1A5076-FIPS 198-1
HMAC-SHA2-256A5076-FIPS 198-1
HMAC-SHA2-384A5076-FIPS 198-1
HMAC-SHA2-512A5076-FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A5076-SP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A5076-SP 800-56A Rev. 3
KDF SNMP (CVL)A5076-SP 800-135 Rev. 1
KDF SP800-108A5076-SP 800-108 Rev. 1
KDF SSH (CVL)A5076-SP 800-135 Rev. 1
RSA KeyGen (FIPS186-5)A5076-FIPS 186-5
RSA SigGen (FIPS186-5)A5076-FIPS 186-5
RSA SigVer (FIPS186-5)A5076-FIPS 186-5
Safe Primes Key GenerationA5076-SP 800-56A Rev. 3
SHA-1A5076-FIPS 180-4
SHA2-256A5076-FIPS 180-4
SHA2-384A5076-FIPS 180-4
SHA2-512A5076-FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A5076-SP 800-135 Rev. 1
AlgorithmCAVP CertPropertiesReference
AES-ECBAES 4550-SP 800-38A
AES-GCMAES 4550-SP 800-38D
NamePropertiesImplementationReference
CKGKey Type:AsymmetricN/AThe module performs Cryptographic Key Generation (CKG) for asymmetric keys as detailed by example 1 in section 4 and section 5 of SP800-133r2

Table 4: Approved Algorithms - Crypto Library I Crypto Library II Table 5: Approved Algorithms - Crypto Library II Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms

Page 16
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC (SSHv2)CKG KAS-FullFull KAS-ECC Key Agreement used for SSHv2 serviceCaveat:Key establishment methodology provides between 128 and 256 bits of security strength IG:IG D.F Scenario 2, Path 2, Split Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVLKAS-ECC-SSC Sp800-56Ar3: (A5076) KDF SSH: (A5076) Counter DRBG: (A5076) CKG: ()
KAS-FFC (SSHv2)CKG KAS-FullFull KAS-FFC Key Agreement used for SSHv2 serviceCaveat:Key establishment methodology provides between 112 and 200 bits of security strength IG:IG D.F Scenario 2, Path 2, Split Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVLKAS-FFC-SSC Sp800-56Ar3: (A5076) Domain Parameter Generation Methods: MODP-2048, MODP-4096, MODP-8192 Safe Primes Key Generation: (A5076) Safe Prime Groups: MODP- 2048, MODP- 4096, MODP-

Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations
Page 17
NameTypeDescriptionPropertiesAlgorithms
8192 KDF SSH: (A5076) Counter DRBG: (A5076) CKG: ()
KAS-ECC (TLSv1.2)CKG KAS-FullFull KAS-ECC Key Agreement used for TLSv1.2 serviceCaveat:Key establishment methodology provides between 128 and 192 bits of security strength IG:IG D.F Scenario 2, Path 2, Split Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVLKAS-ECC-SSC Sp800-56Ar3: (A5076) Domain Parameter Generation Methods: P-256, P-384 TLS v1.2 KDF RFC7627: (A5076) Counter DRBG: (A5076) CKG: ()
KAS-FFC (TLSv1.2)CKG KAS-FullFull KAS-FFC Key Agreement used for TLSv1.2 serviceCaveat:Key establishment methodology provides 112 bits of security strength IG:IG D.F Path 2, Scenario 2, Split Key Confirmation:No Key Derivation:IG 2.4.B SP 800- 135rev1 CVLKAS-FFC-SSC Sp800-56Ar3: (A5076) Domain Parameter Generation Methods: ffdhe2048 Safe Primes Key Generation: (A5076) Safe Prime Groups: ffdhe2048 TLS v1.2 KDF RFC7627: (A5076) Counter DRBG: (A5076) CKG: ()
SSH-KTS (AES and HMAC)KTS-WrapKTS via SSHv2 service by using AES and HMACCaveat:Key establishment methodology provides between 128 and 256 bits of security strength Standard:SP 800-AES-CBC: (A5076) AES-CTR: (A5076) HMAC-SHA-1: (A5076) HMAC-SHA2- 256: (A5076)
Page 18
NameTypeDescriptionPropertiesAlgorithms
38F IG D.G:"combination" method: use any approved symmetric encryption mode together with an approved authentication method
TLS-KTS (AES and HMAC)KTS-WrapKTS via TLS v1.2 service by using AES and HMACCaveat:Key establishment methodology provides between 128 and 256 bits of security strength Standard:SP 800- 38F IG D.G:"combination" method: use any approved symmetric encryption mode together with an approved authentication methodAES-CBC: (A5076) AES-ECB: (A5076) HMAC-SHA-1: (A5076) HMAC-SHA2- 256: (A5076) HMAC-SHA2- 512: (A5076)
TLS-KTS (AES- GCM)KTS-WrapKTS via TLSv1.2 service by using AES- GCMCaveat:Key establishment methodology provides between 128 and 256 bits of security strength Standard:SP 800- 38F IG D.G:Uses a previously approved authenticated symmetric encryption modeAES-GCM: (A5076)
MACSec-KTS (AES-KW)KTS-WrapMACSec KeyWrap using AES-KW toSecurity Strength:Provides 128 or 256 bits ofAES-KW: (A5076)
Page 19
NameTypeDescriptionPropertiesAlgorithms
protect MACSec SAKencryption strength
MACSec-KTS (AES-KWP)KTS-WrapMACSec KeyWrap using AES-KWP to protect MACSec SAKSecurity Strength:Provides 128 or 256 bits of encryption strengthAES-KWP: (A5076)
SSH RSA KeyGenCKG AsymKeyPair- KeyGenRSA KeyGen for SSHv2Keysize:112 bits encryption strengthRSA KeyGen (FIPS186-5): (A5076) Counter DRBG: (A5076) CKG: ()
SSH RSA SigGenDigSig-SigGenRSA SigGen for SSHv2RSA SigGen (FIPS186-5): (A5076)
SSH RSA SigVerDigSig-SigVerRSA SigVer for SSHv2RSA SigVer (FIPS186-5): (A5076)
SSH ECDSA KeyGenCKG AsymKeyPair- KeyGenECDSA KeyGen for SSHv2Keysize:128 to 192 bits encryption strengthECDSA KeyGen (FIPS186-5): (A5076) Counter DRBG: (A5076) CKG: ()
SSH ECDSA SigGenDigSig-SigGenECDSA SigGen for SSHv2ECDSA SigGen (FIPS186-5): (A5076)
SSH ECDSA SigVerDigSig-SigVerECDSA SigVer for SSHv2ECDSA SigVer (FIPS186-5): (A5076)
TLS RSA KeyGenCKG AsymKeyPair- KeyGenRSA KeyGen for TLSv1.2Keysize:112 bits encryption strengthCounter DRBG: (A5076) RSA KeyGen (FIPS186-5): (A5076) CKG: ()
TLS RSA SigGenDigSig-SigGenRSA SigGen for TLSv1.2RSA SigGen (FIPS186-5): (A5076)
TLS RSA SigVerDigSig-SigVerRSA SigVer for TLSv1.2RSA SigVer (FIPS186-5): (A5076)
TLS ECDSA KeyGenCKG AsymKeyPair- KeyGenECDSA KeyGen for TLSv1.2Keysize:128 to 192 bits encryption strengthCounter DRBG: (A5076) ECDSA KeyGen (FIPS186-5): (A5076) CKG: ()
Page 20
NameTypeDescriptionPropertiesAlgorithms
TLS ECDSA SigGenDigSig-SigGenECDSA SigGen for TLSv1.2ECDSA SigGen (FIPS186-5): (A5076)
TLS ECDSA SigVerDigSig-SigVerECDSA SigVer for TLSv1.2ECDSA SigVer (FIPS186-5): (A5076)
Block ciphers (SSHv2)BC-UnAuthBlock ciphers for SSHv2 serviceAES-CBC: (A5076) AES-CTR: (A5076)
Block ciphers (TLSv1.2)BC-Auth BC-UnAuthBlock ciphers for TLSv1.2 serviceAES-CBC: (A5076) AES-GCM: (A5076) AES-ECB: (A5076)
Block ciphers (SNMPv3)BC-UnAuthBlock ciphers for SNMPv3 serviceAES-CFB128: (A5076) KDF SNMP: (A5076)
Block ciphers (MACSec)BC-AuthBlock ciphers for MACSec serviceAES-ECB: (AES 4550) AES-GCM: (AES 4550) KDF SP800- 108: (A5076)
MAC (SSHv2)MACMAC for SSHv2 serviceHMAC-SHA-1: (A5076) HMAC-SHA2- 256: (A5076) HMAC-SHA2- 512: (A5076) SHA-1: (A5076) SHA2-256: (A5076) SHA2-512: (A5076)
MAC (TLSv1.2)MACMessage Authentication for TLSv1.2 servicesHMAC-SHA-1: (A5076) HMAC-SHA2- 256: (A5076) HMAC-SHA2- 384: (A5076) SHA-1: (A5076) SHA2-256: (A5076) SHA2-384: (A5076)
Page 21
NameTypeDescriptionPropertiesAlgorithms
MAC (SNMPv3)MACMessage Authentication for SNMPv3 servicesHMAC-SHA-1: (A5076) HMAC-SHA2- 256: (A5076) HMAC-SHA2- 384: (A5076) HMAC-SHA2- 512: (A5076) SHA-1: (A5076) SHA2-256: (A5076) SHA2-384: (A5076) SHA2-512: (A5076) KDF SNMP: (A5076)
DRBG FunctionDRBGUsed for DRBG generationCounter DRBG: (A5076)
SNMPv3 Keying Materials DevelopmentKAS-135KDFKeying materials, used to derive SNMP session keysKDF SNMP: (A5076)
TLS Keying Materials DevelopmentKAS-135KDFKeying materials, used to derive TLS session keysTLS v1.2 KDF RFC7627: (A5076)
Firmware Load TestDigSig-SigVerSignature Verification for firmware load testRSA SigVer (FIPS186-5): (A5076)
MACSec-SAK- IntegrityMACUsed to protect the integrity of SAK during key transmissionAES-CMAC: (A5076)
MACsec Keying Materials DevelopmentKBKDFMACsec session keying materials, used to derive MACsec session keysKDF SP800- 108: (A5076)

Table 7: Security Function Implementations

2.7 Algorithm Specific Information
Page 22
Cert NumberVendor Name
E192Ruckus Wireless LLC
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Ruckus IronWare 10.0.10 Entropy SourceNon- PhysicalARM Cortex A57 (ARMv8); ARM Cortex A72 (ARMv8)8 bits4 bitsN/A
2.8 RBG and Entropy

Table 8: Entropy Certificates Table 9: Entropy Sources Ruckus FastIron™ IronWare 10.0.10 Entropy Source v1.0 is the entropy source used on each Ruckus FastIron ICX™ 7550, 7650, and 7850 Series Router with firmware IronWare OS 10.0.10 to seed the approved DRBG. The noise source of entropy is periodic sampling of the high-

Page 23

precision CPU clock within the ARM CPU. There is no conditioning component applied on the output of the clock source. Health testing is implemented on the output of the noise source. The entropy source provides a minimum entropy of 4 bits per sample with the sample size of 8 bits. The module makes repeated calls to the entropy source after which the random data is loaded into a buffer. This buffer is used by the DRBG to get entropy input. Buffer size is big enough that the overall effective entropy is more than that is required for the DRBG instantiation. Similar implementation is done for DRBG reseeding.”

2.9 Key Generation

The module generates RSA, ECDSA, EC Diffie-Hellman, and Diffie-Hellman asymmetric key pairs compliant with FIPS 186-5, using a NIST SP 800-90Ar1 CTR DRBG for random number generation. In accordance with FIPS 140-3 IG D.H, the cryptographic module performs CKG for asymmetric keys as per section 5.1 of NIST SP 800-133rev2 (vendor affirmed) by obtaining a random bit string directly from an approved DRBG. The random bit string supports the required security strength requested by the calling application (without any V, as described in Additional Comments 2 of IG D.H.).

2.10 Key Establishment

The module provides the following key/SSP establishment services in the approved mode of operation:

2.11 Industry Protocols

The module supports SSHv2, TLS v1.2, SNMPv3 and MACSec industrial protocols. No parts of the SSH, TLS and SNMP protocols, other than the KDFs, have been tested by the CAVP and CMVP. Please refer to SSPs Table for more information.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces
Page 24
Physical PortLogical Interface(s)Data That Passes
Console port, Mgmt Port, PoE+ ports, Ethernet Ports, SPF/SFP+, QSFP+, and QSFP28 portsData InputData input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and MACSec service data.
Console port, Mgmt Port, PoE+ ports, Ethernet Ports, SPF/SFP+, QSFP+, and QSFP28 portsData OutputData output from the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and MACSec service data.
Console port, Mgmt Port, PoE+ ports, Ethernet Ports, SPF/SFP+, QSFP+, and QSFP28 portsControl InputControl Data input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and MACSec service data.
Console port, Mgmt Port, PoE+ ports, Ethernet Ports, SPF/SFP+, QSFP+, and QSFP28 ports and LEDsStatus OutputStatus Information output from the module.
N/AControl OutputN/A
PowerPowerProvide the Power Supply to the module.
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Password- BasedThe minimum length is eight (8) characters (94 possible characters). The probability that a random attempt will succeed or a false acceptance will occur is 1/(94^8) which is less than 1/1,000,000. As the module supports at most ten failed attempts to authenticate in a one- minute period, the probability of successfullyPassword BasedThe probability that a random attempt will succeed or a false acceptance will occur is 1/(94^8) which is less than 1/1,000,000. Please refer to Description section in this table for more details.The probability of successfully authenticating to the module within one minute is 10/(94^8), which is less than 1/100,000. Please refer to Description section in this table for more details.

The module’s physical perimeter encompasses the case of the tested platform mentioned in

4 Roles, Services, and Authentication
4.1 Authentication Methods
Page 25
Method NameDescription authenticating to the module within one minute is 10/(94^8), which is less than 1/100,000. This calculation is based on the assumption that the typical standard American QWERTY computer keyboard has 10 Integer digits, 52 alphabetic characters, and 32 special characters providing 94 characters to choose from in total.Security MechanismStrength Each AttemptStrength per Minute
RSA- Based CertificateThe modules supports RSA public-key based authentication mechanism using a minimum of RSA 2048 bits, which provides 112 bits of security strength. The probability that a random attempt will succeed is 1/(2^112) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112), which is less than 1/100,000.RSA SigVer (FIPS186-5) (A5076)With a minimum modulus size of 2048, the probability that a random attempt will succeed is 1/(2^112) which is less than 1/1,000,000. Please refer to Description section in this table for more details.For multiple attacks during a one- minute period, to exceed a one in 100,000 probability of a successful random key guess in one minute, an attacker would have to be capable of approximately 8.65x10^31 (2^112 /60 = 8.65 x 10^31) attempts per second. Please refer to Description section in this table for more details.
ECDSA- Based CertificateThe modules support ECDSA public-key based authentication mechanism using aECDSA SigVer (FIPS186-5) (A5076)With a minimum curve of P-256, the probability that a randomFor multiple attacks during a one- minute period, to exceed a one in
Page 26
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
minimum of curve P- 256, which provides 128 bits of security strength. The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128), which is less than 1/100,000.attempt will succeed is 1/(2^128) which is less than 1/1,000,000. Please refer to Description section in this table for more details.100,000 probability of a successful random key guess in one minute, an attacker would have to be capable of approximately 5.67x10^36 (2^128 /60 = 5.67 x 10^36) attempts per second. Please refer to Description section in this table for more details.
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCOPassword-Based RSA-Based Certificate ECDSA-Based Certificate
UserRoleUserPassword-Based RSA-Based Certificate ECDSA-Based Certificate
Port Config AdminRolePort Config AdminPassword-Based RSA-Based Certificate ECDSA-Based Certificate

and the User role. The module also allows the concurrent operators.

4.2 Roles
4.3 Approved Services
Page 27
NameDescriptio nIndicatorInputsOutputsSecurity Function sSSP Access
Show StatusProvide Module's current status (return codes and/or syslog messages)Global Indicator or syslog messageCommand used to show Module's StatusModule's Operationa l StatusNoneCrypto Officer Port Config Admin User
Show VersionProvide Module's name and version informationConsole messageCommand to show versionModule's ID and versioning informationNoneCrypto Officer Port Config Admin User
Perform Self-TestsPerform Self-Tests (Pre- operational self-test and Conditional Self-Tests)Perform self-test completio n messageCommand to trigger Self-TestStatus of the self- tests resultsNoneCrypto Officer User Port Config Admin Unauthentic ated
Perform ZeroizationPerform ZeroizationSyslog messageCommand to zeroize the moduleStatus of the SSPs zeroizationNoneCrypto Officer - DRBG Entropy Input: Z - DRBG Seed: Z - DRBG Internal State V value: Z - DRBG Key: Z - User Password: Z - Crypto Officer Password: Z - Port Config Admin Password: Z - Firmware Load Test Key: Z - SSH DH
Page 28

Name

Descriptio n

Indicator

Inputs

Outputs

Security Function s

SSP Access Private Key: Z - SSH DH Public Key: Z - SSH Peer DH Public Key: Z - SSH DH Shared Secret: Z - SSH ECDH Private Key: Z - SSH ECDH Public Key: Z - SSH Peer ECDH Public Key: Z - SSH ECDH Shared Secret: Z - SSH ECDSA Private Key: Z - SSH ECDSA Public Key: Z - SSH RSA Private Key: Z - SSH RSA Public Key: Z - SSH Session Encryption Key: Z - SSH Session Authenticatio n Key: Z - TLS DH Private Key: Z

Page 29

Name

Descriptio n

Indicator

Inputs

Outputs

Security Function s

SSP Access - TLS DH Public Key: Z - TLS Peer DH Public Key: Z - TLS DH Shared Secret: Z - TLS ECDH Private Key: Z - TLS ECDH Public Key: Z - TLS Peer ECDH Public Key: Z - TLS ECDH Shared Secret: Z - TLS ECDSA Private Key: Z - TLS ECDSA Public Key: Z - TLS RSA Private Key: Z - TLS RSA Public Key: Z - TLS Master Secret: Z - TLS Session Encryption Key: Z - SNMPv3 Authenticatio n Secret: Z - SNMPv3 Encryption Key: Z - SNMPv3

Page 30
NameDescriptio nIndicatorInputsOutputsSecurity Function sSSP Access Integrity Key: Z - MACSec CAK: Z - MACSec ICK: Z - MACSec SAK: Z - MACSec KEK: Z
Crypto Officer Authenticat ionCO Role Authenticat ionN/ACO Authenticat ion RequestStatus of the CO authenticat ionNoneCrypto Officer - Crypto Officer Password: W,Z
User Authenticat ionUser Role Authenticat ionN/AUser role authenticat ion requestStatus of the User role authenticat ionNoneUser - User Password: W,Z
Port Config Admin Authenticat ionPort Config Admin Role Authenticat ionN/APort Config Admin role authenticat ion requestStatus of the Port Config Admin role authenticat ionNonePort Config Admin - Port Config Admin Password: W,Z
Port Configurati on Mangemen tPerform Port Configurati onN/ACommands to configure the port parameters of switch/rout erPort configurati on completion status informationNoneCrypto Officer Port Config Admin
Account Mangemen tAccount CreationN/ACommands to create a new user accountStatus of the new user accountsNoneCrypto Officer
Configure SSHv2 FunctionConfigure SSHv2 FunctionGlobal Indicator and SSHv2 configurati on successCommands to configure SSHv2Status of the completion of the SSHv2 configurati onSSH RSA KeyGen SSH ECDSA KeyGen DRBG FunctionCrypto Officer - SSH RSA Private Key: G,W - SSH RSA Public Key: G,W
Page 31
NameDescriptio nIndicator status messageInputsOutputsSecurity Function sSSP Access - SSH ECDSA Private Key: G,W - SSH ECDSA Public Key: G,W - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State V value: G,W,E - DRBG Key: G,W,E
Run SSHv2 FunctionExecute SSHv2 FunctionGlobal Indicator and successfu l SSHv2 log messageInitiate SSHv2 tunnel establishm entStatus of SSHv2 tunnel establishm entKAS-ECC (SSHv2) KAS-FFC (SSHv2) SSH-KTS (AES and HMAC) SSH RSA SigGen SSH RSA SigVer SSH ECDSA SigGen SSH ECDSA SigVer Block ciphers (SSHv2) MAC (SSHv2) DRBG FunctionCrypto Officer - SSH DH Private Key: G,W,E,Z - SSH DH Public Key: G,R,W,E,Z - SSH Peer DH Public Key: W,E,Z - SSH DH Shared Secret: G,W,E,Z - SSH ECDH Private Key: G,W,E,Z - SSH ECDH Public Key: G,R,W,E,Z - SSH Peer ECDH Public Key: W,E,Z - SSH ECDH Shared Secret: G,W,E,Z
Page 32

Name

Descriptio n

Indicator

Inputs

Outputs

Security Function s

SSP Access - SSH RSA Private Key: E - SSH RSA Public Key: R,E - SSH ECDSA Private Key: E - SSH ECDSA Public Key: R,E - SSH Session Encryption Key: G,W,E,Z - SSH Session Authenticatio n Key: G,W,E,Z - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State V value: G,W,E - DRBG Key: G,W,E - RADIUS Secret: W,E Port Config Admin - SSH DH Private Key: R,E - SSH DH Public Key: R,E - SSH Peer DH Public

Page 33

Name

Descriptio n

Indicator

Inputs

Outputs

Security Function s

SSP Access Key: R,E - SSH DH Shared Secret: R,E - SSH ECDH Private Key: R,E - SSH ECDH Public Key: R,E - SSH Peer ECDH Public Key: R,E - SSH ECDH Shared Secret: R,E - SSH RSA Private Key: R,E - SSH RSA Public Key: R,E - SSH ECDSA Private Key: R,E - SSH ECDSA Public Key: R,E - SSH Session Encryption Key: R,E - SSH Session Authenticatio n Key: R,E - DRBG Entropy Input: R,E - DRBG Seed: R,E - DRBG Internal State V value: R,E - DRBG Key:

Page 34

Name

Descriptio n

Indicator

Inputs

Outputs

Security Function s

SSP Access R,E - RADIUS Secret: W,E User - SSH DH Private Key: R,E - SSH DH Public Key: R,E - SSH Peer DH Public Key: R,E - SSH DH Shared Secret: R,E - SSH ECDH Private Key: R,E - SSH ECDH Public Key: R,E - SSH Peer ECDH Public Key: R,E - SSH ECDH Shared Secret: R,E - SSH RSA Private Key: R,E - SSH RSA Public Key: R,E - SSH ECDSA Private Key: R,E - SSH ECDSA Public Key: R,E - SSH Session Encryption Key: R,E - SSH Session

Page 35
NameDescriptio nIndicatorInputsOutputsSecurity Function sSSP Access Authenticatio n Key: R,E - DRBG Entropy Input: R,E - DRBG Seed: R,E - DRBG Internal State V value: R,E - DRBG Key: R,E - RADIUS Secret: W,E
Configure SSL over TLSv1.2 FunctionConfigure SSL over TLSv1.2 FunctionGlobal Indicator and TLS v1.2 configurati on success status messageCommands to configure TLSv1.2Status of the completion of TLSv1.2 configurati onTLS RSA KeyGen TLS ECDSA KeyGen DRBG FunctionCrypto Officer - TLS RSA Private Key: G,W - TLS RSA Public Key: G,W - TLS ECDSA Private Key: G,W - TLS ECDSA Public Key: G,W - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State V value: G,W,E - DRBG Key: G,W,E
Run SSL over TLSv1.2 FunctionExecute SSL over TLSv1.2 FunctionGlobal Indicator and successfu l TLS v1.2Commands to initiate TLSv1.2Status of the completion of TLSv1.2KAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2) TLS-KTSCrypto Officer - TLS DH Private Key: G,W,E,Z
Page 36
NameDescriptio nIndicatorInputsOutputsSecurity Function sSSP Access
log messageestablishm ent(AES and HMAC) TLS-KTS (AES- GCM) TLS RSA KeyGen TLS RSA SigGen TLS RSA SigVer TLS ECDSA KeyGen TLS ECDSA SigGen TLS ECDSA SigVer Block ciphers (TLSv1.2) MAC (TLSv1.2) DRBG Function TLS Keying Materials Developm ent- TLS DH Public Key: G,R,W,E,Z - TLS Peer DH Public Key: W,E,Z - TLS DH Shared Secret: G,W,E,Z - TLS ECDH Private Key: G,W,E,Z - TLS ECDH Public Key: G,R,W,E,Z - TLS Peer ECDH Public Key: W,E,Z - TLS ECDH Shared Secret: G,W,E,Z - TLS RSA Private Key: E - TLS RSA Public Key: R,E - TLS Master Secret: G,W,E,Z - TLS Session Encryption Key: G,W,E,Z - TLS Session Authenticatio n Key: G,W,E,Z - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG
Page 37
NameDescriptio nIndicatorInputsOutputsSecurity Function sSSP Access Internal State V value: G,W,E - DRBG Key: G,W,E - TLS ECDSA Private Key: E - TLS ECDSA Public Key: R,E
Configure MACSec FunctionConfigure MACSec FunctionGlobal Indicator and MACSec configurati on on success status messageCommands to configure MACSec serviceStatus of the completion of MACSec configurati onMACSec- KTS (AES-KW) MACSec- KTS (AES- KWP) Block ciphers (MACSec) MACSec- SAK- IntegrityCrypto Officer - MACSec CAK: W,E - MACSec ICK: G,W,E,Z - MACSec SAK: G,W,E,Z - MACSec KEK: G,W,E,Z
Run MACSec FunctionExecute MACSec FunctionGlobal Indicator and successfu l MACSec log messageCommands to initiate MACSec serviceStatus of the completion of MACSec establishm entMACSec- KTS (AES-KW) MACSec- KTS (AES- KWP) Block ciphers (MACSec) MACSec- SAK- Integrity MACsec Keying Materials Developm entCrypto Officer - MACSec CAK: W,E - MACSec ICK: G,W,E,Z - MACSec SAK: G,W,E,Z - MACSec KEK: G,W,E,Z
Page 38
NameDescriptio nIndicatorInputsOutputsSecurity Function sSSP Access
Configure SNMPv3 FunctionConfigure SNMPv3 FunctionGlobal Indicator and SNMPv3 configurati on success status messageCommands to configure SNMPv3 serviceStatus of the completion of SNMPv3 configurati onBlock ciphers (SNMPv3) MAC (SNMPv3)Crypto Officer - SNMPv3 Authenticatio n Secret: W,E - SNMPv3 Encryption Key: G,W,E,Z - SNMPv3 Integrity Key: G,W,E,Z
Run SNMPv3 FunctionExecute SNMPv3 FunctionGlobal Indicator and successfu l SNMPv3 log messageCommands to initiate SNMPv3 serviceStatus of the completion of SNMPv3 establishm entBlock ciphers (SNMPv3) MAC (SNMPv3) SNMPv3 Keying Materials Developm entCrypto Officer - SNMPv3 Authenticatio n Secret: W,E - SNMPv3 Encryption Key: G,W,E,Z - SNMPv3 Integrity Key: G,W,E,Z
Firmware Load TestExecute the Firmware Load TestGlobal indicator and successfu l Firmware Loading status messageCommands to load new firmware imageOutcome of the Firmware Load TestFirmware Load TestCrypto Officer - Firmware Load Test Key: E
4.4 Non-Approved Services
4.5 External Software/Firmware Loaded
Page 39

The module also supports the firmware load test by using RSA 2048 bits with SHA2-256 (RSA Cert. #A5076) for the new validated firmware to be uploaded into the module. A Firmware Load Test Key was preloaded to the module’s binary at the factory and used for firmware load test. In order to load new firmware, the Crypto Officer must authenticate to the module before loading the firmware. This ensures that unauthorized access and use of the module is not performed. The module will load the new update upon reboot. The update attempt will be rejected if the verification fails.

4.6 Additional Information

The module supports unauthenticated service. The unauthenticated User/Operators can trigger the self-test service by power-cycling the module, and is able to observe the module’s LEDs status.

5 Software/Firmware Security
5.1 Integrity Techniques

The module performs the Firmware Integrity tests by using CRC-32 during the Pre-Operational Self-Test. At Module’s initialization, the integrity of the runtime executable binary file (SPR10010dufi.bin) is verified using the following two integrity check mechanisms to ensure that the module has not been tampered:

5.2 Initiate on Demand

Integrity test is performed as part of the Pre-Operational Self-Tests. It is automatically executed at power-on. The operator can power-cycle or reboot the module to initiate the firmware integrity test on-demand. This automatically performs the integrity test of all firmware components included within the boundary of the module.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited

7 Physical Security

The module is a multi-chip standalone hardware cryptographic module. The module meets the FIPS 140-3 Level 1 security requirements as production grade components.

Page 40
Storage Area NameDescriptionPersistence Type
DRAMVolatile MemoryDynamic
FlashNon-Volatile MemoryStatic
Name Peer Public Key Input Module Public Key OutputFrom External (Outside of the Module's Boundary ) ModuleTo Module External (Outside of the Module's Boundary )Format Type Plaintext PlaintextDistributio n Type Automated AutomatedEntry Type Electroni c Electroni cSFI or Algorith m
Password/Secre t Input via SSHv2 encrypted by AES and HMACExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cSSH-KTS (AES and HMAC)
Password/Secre t Input via TLS v1.2 encrypted by AES and HMACExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cTLS-KTS (AES and HMAC)
8 Non-Invasive Security

No approved non-invasive attack mitigation test metrics are defined at this time.

9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods
Page 41
NameFromToFormat TypeDistributio n TypeEntry TypeSFI or Algorith m
Password/Secre t Input via TLS v1.2 encrypted by AES-GCMExternal (Outside of the Module's Boundary )ModuleEncrypte dAutomatedElectroni cTLS-KTS (AES- GCM)
MACSec SAK Output encrypted by MACSec KEK using AES-KWModuleExternal (Outside of the Module's Boundary )Encrypte dAutomatedElectroni cMACSec- KTS (AES-KW)
MACSec SAK Output encrypted by MACSec KEK using AES-KWPModuleExternal (Outside of the Module's Boundary )Encrypte dAutomatedElectroni cMACSec- KTS (AES- KWP)
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroization CommandCO issues zeroization servicethe zeroization command will erase all SSPs stored in the DRAM or in the Flash of the module.'fips zeroize all' Command
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
DRBG Entropy InputUsed to seed the DRBG960 - at least 256 bitsEntropy Input - CSPDRBG Function
DRBG SeedUsed in DRBG Generation384 bits - 384 bitsDRBG Seed - CSPDRBG Function

m ) ) ) Table 15: SSP Input-Output Methods

9.3 SSP Zeroization Methods

Table 16: SSP Zeroization Methods Please note that the Firmware Load Test Key is only used for Firmware Load Test Authentication and not subject to the zeroization requirement.

Page 42
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
DRBG Internal State V valueUsed in DRBG Generation128 bits - 128 bitsDRBG Internal State V value - CSPDRBG Function
DRBG KeyUsed in DRBG Generation256 bits - 256 bitsDRBG Key - CSPDRBG Function
User PasswordUser authenticati on8-60 Characte rs - 8-60 Characte rsAuthenticati on Data - CSP
Crypto Officer PasswordCrypto Officer authenticati on8-60 Characte rs - 8-60 Characte rsAuthenticati on Data - CSP
Port Config Admin PasswordPort Config Admin authenticati on8-60 Characte rs - 8-60 Characte rsAuthenticati on Data - CSP
RADIUS SecretRADIUS Server Authenticati on8-64 Characte rs - 8-64 Characte rsAuthenticati on Data - CSP
Firmware Load Test KeyUsed for Firmware Load Test2048 bits - 112 bitsPublic Key - CSPFirmware Load Test
SSH ECDH Private KeyUsed to derive the SSH ECDH Shared SecretCurves: 256, 384, 521 bits - 128 to 256 bitsPrivate Key - CSPKAS- ECC (SSHv2)KAS-ECC (SSHv2)
SSH ECDH Public KeyUsed to derive SSH ECDH Shared SecretCurves: 256, 384, 521 bits - 128-256 bitsPublic Key - PSPKAS-ECC (SSHv2)
SSH Peer ECDH Public KeyUsed to derive SSH ECDH Shared SecretCurves: 256, 384, 521 bits - 128 to 256 bitsPublic Key - PSPKAS-ECC (SSHv2)
SSH ECDH Shared SecretUsed to derive SSH SessionCurves: 256, 384, 521 bits -Shared Secret - CSPKAS-ECC (SSHv2)KAS-ECC (SSHv2)
Page 43
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
Encryption Keys, SSH Session Authenticati on Keys128 to 256 bits
SSH DH Private KeyUsed to derive the SSH DH Shared SecretMODP- 2048, MODP- 4096, MODP- 8192 - 112-200 bitsPrivate Key - CSPKAS-FFC (SSHv2)KAS-FFC (SSHv2)
SSH DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 4096, MODP- 8192 - 112-200 bitsPublic Key - PSPKAS-FFC (SSHv2)
SSH Peer DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 4096, MODP- 8192 - 112-200 bitsPublic Key - PSPKAS-FFC (SSHv2)
SSH DH Shared SecretUsed to derive SSH Session Encryption Keys, SSH Session Authenticati on KeysMODP- 2048, MODP- 4096, MODP- 8192 - 112-200 bitsShared Secret - CSPKAS-FFC (SSHv2)KAS-FFC (SSHv2)
SSH RSA Private KeyUsed for SSH session authenticati onModulus 2048 bits - 112 bitsPrivate Key - CSPSSH RSA KeyGenSSH RSA SigGen
SSH RSA Public KeyUsed for SSH sessions authenticati onModulus 2048 bits - 112 bitsPublic Key - PSPSSH RSA KeyGen
Page 44
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
SSH ECDSA Private KeyUsed for SSH session authenticati onCurve P- 256/P- 384 - 128-192 bitsPrivate Key - CSPSSH ECDSA KeyGenSSH ECDSA SigGen
SSH ECDSA Public KeyUsed for SSH sessions authenticati onCurve P- 256/P- 384 - 128-192 bitsPublic Key - PSPSSH ECDSA KeyGen
SSH Session Encryption KeyUsed for SSH Session confidentiali ty protection128-256 bits - 128-256 bitsSession Key - CSPKAS-ECC (SSHv2) KAS-FFC (SSHv2)Block ciphers (SSHv2)
SSH Session Authenticati on KeyUsed for SSH Session integrity protectionAt least 160 bits - At least 160 bitsSession Key - CSPKAS-ECC (SSHv2) KAS-FFC (SSHv2)MAC (SSHv2)
TLS ECDH Private KeyUsed to derive the TLS ECDH Shared SecretCurves: 256, 384 bits - 128 to 192 bitsPrivate Key - CSPKAS- ECC (TLSv1.2 )KAS-ECC (TLSv1.2)
TLS ECDH Public KeyUsed to derive TLS ECDH Shared SecretCurves: 256, 384 bits - 128 to 192 bitsPublic Key - PSPKAS-ECC (TLSv1.2)
TLS Peer ECDH Public KeyUsed to derive TLS ECDH Shared SecretCurves: 256, 384 bits - 128 to 192 bitsPublic Key - PSPKAS-ECC (TLSv1.2)
TLS ECDH Shared SecretUsed to derive TLS Session Encryption Keys, TLS Session Authenticati on KeysCurves: 256, 384 bits - 128 to 192 bitsShared Secret - CSPKAS-ECC (TLSv1.2)KAS-ECC (TLSv1.2)
TLS DH Private KeyUsed to derive the TLS DH Shared Secretffdhe204 8 - 112 bitsPrivate Key - CSPKAS-FFC (TLSv1.2 )KAS-FFC (TLSv1.2)
Page 45
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
TLS DH Public KeyUsed to derive TLS DH Shared Secretffdhe204 8 - 112 bitsPublic Key - PSPKAS-FFC (TLSv1.2)
TLS Peer DH Public KeyUsed to derive TLS DH Shared Secretffdhe204 8 - 112 bitsPublic Key - PSPKAS-FFC (TLSv1.2)
TLS DH Shared SecretUsed to derive TLS Session Encryption Keys, TLS Session Authenticati on Keysffdhe204 8 - 112 bitsShared Secret - CSPKAS-FFC (TLSv1.2)KAS-FFC (TLSv1.2)
TLS RSA Private KeyUsed for TLS session authenticati onModulus 2048 bits - 112 bitsPrivate Key - CSPTLS RSA KeyGenTLS RSA SigGen
TLS RSA Public KeyUsed for TLS sessions authenticati onModulus 2048 bits - 112 bitsPublic Key - PSPTLS RSA KeyGen
TLS ECDSA Private KeyUsed for TLS session authenticati onCurve P- 256/P- 384 - 128-192 bitsPrivate Key - CSPTLS ECDSA KeyGenTLS ECDSA SigGen
TLS ECDSA Public KeyUsed for TLS sessions authenticati onCurve P- 256/P- 384 - 128-192 bitsPublic Key - PSPTLS ECDSA KeyGen
TLS Master SecretUsed to protect TLS Session. Pre-master secretAt least 112 bits - At least 112 bitsMaster Secret - CSPTLS Keying Materials Developme ntKAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2)
TLS Session Encryption KeyUsed to protect TLS Session. TLS Master secret128-256 bits - 128-256 bitsSession Key - CSPKAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2) TLS Keying MaterialsBlock ciphers (TLSv1.2)
Page 46
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
Developme nt
TLS Session Authenticati on KeyUsed to protect TLS Session. TLS master secretat least 112 bits - at least 112 bitsSession Key - CSPKAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2) TLS Keying Materials Developme ntMAC (TLSv1.2)
SNMPv3 Authenticati on SecretUsed for SNMPv3 user authenticati on8-20 character s - N/AAuthenticati on Secret - CSP
SNMPv3 Encryption KeyUsed to protect SNMPv3 traffic confidentiali ty128 bits - 128 bitsEncryption Key - CSPSNMPv3 Keying Materials Developme ntBlock ciphers (SNMPv3)
SNMPv3 Integrity KeyUsed to secure SNMPv3 traffic integrityAt least 160 bits - At least 112 bitsAuthenticati on Key - CSPSNMPv3 Keying Materials Developme ntMAC (SNMPv3)
MACSec CAKUsed to derive MACSec ICK and MACSec KEK128 bits - N/AMACSec Secret - CSPMACsec Keying Materials Developme nt
MACSec ICKUsed to protect the MACSec Integrity128 bits - 128 bitsIntegrity Key - CSPMACsec Keying Materials Developme ntMACSec- SAK- Integrity AES- CMAC (A5076)
MACSec SAKUsed to protect the MACSec traffic confidentiali ty128 bits - 128 bitsEncryption Key - CSPMACSec- KTS (AES- KW) MACSec- KTS (AES- KWP) TLS Keying MaterialsBlock ciphers (MACSec)
Page 47
NameDescriptionSize - StrengthType - CategoryGenerate d ByEstablishe d ByUsed By
Developme nt MACSec- SAK- Integrity
MACSec KEKUsed to transport MACSec SAK to Peer128 bits - 128 bitsEncryption Key - CSPMACsec Keying Materials Developme ntMACSec- KTS (AES- KW) MACSec- KTS (AES- KWP)
NameInput - OutputStorageStorage Duratio nZeroizatio nRelated SSPs
DRBG Entropy InputDRAM:Plaintex tUntil RebootZeroization CommandDRBG Seed:Used With DRBG Internal State V value:Used With DRBG Key:Used With
DRBG SeedDRAM:Plaintex tUntil RebootZeroization CommandDRBG Entropy Input:Used With DRBG Internal State V value:Used With DRBG Key:Used With
DRBG Internal State V valueDRAM:Plaintex tUntil RebootZeroization CommandDRBG Entropy Input:Used With DRBG Seed:Used With DRBG Key:Used With
Page 48
NameInput - OutputStorageStorage Duratio nZeroizatio nRelated SSPs
DRBG KeyDRAM:Plaintex tUntil RebootZeroization CommandDRBG Entropy Input:Used With DRBG Seed:Used With DRBG Internal State V value:Used With
User PasswordPassword/Secre t Input via SSHv2 encrypted by AES and HMAC Password/Secre t Input via TLS v1.2 encrypted by AES and HMAC Password/Secre t Input via TLS v1.2 encrypted by AES-GCMFlash:PlaintextZeroization Command
Crypto Officer PasswordPassword/Secre t Input via SSHv2 encrypted by AES and HMAC Password/Secre t Input via TLS v1.2 encrypted by AES and HMAC Password/Secre t Input via TLS v1.2 encrypted by AES-GCMFlash:PlaintextZeroization Command
Port Config Admin PasswordPassword/Secre t Input via SSHv2 encrypted by AES and HMAC Password/Secre t Input via TLS v1.2 encryptedFlash:PlaintextZeroization Command
Page 49
Name RADIUS Secret Firmware Load Test KeyInput - Output by AES and HMAC Password/Secre t Input via TLS v1.2 encrypted by AES-GCM Password/Secre t Input via SSHv2 encrypted by AES and HMAC Password/Secre t Input via TLS v1.2 encrypted by AES and HMAC Password/Secre t Input via TLS v1.2 encrypted by AES-GCMStorage Flash:Plaintext Flash:PlaintextStorage Duratio nZeroizatio n Zeroization Command N/ARelated SSPs
SSH ECDH Private KeyDRAM:Plaintex tWhile SSH tunnel is onZeroization CommandSSH ECDH Public Key:Paired With SSH Peer ECDH Public Key:Used With
SSH ECDH Public KeyModule Public Key OutputDRAM:Plaintex tWhile SSH tunnel is onZeroization CommandSSH ECDH Private Key:Paired With
SSH Peer ECDH Public KeyPeer Public Key InputDRAM:Plaintex tWhile SSH tunnel is onZeroization CommandSSH ECDH Private Key:Used With
SSH ECDH Shared SecretDRAM:Plaintex tWhile SSH tunnel is onZeroization CommandSSH ECDH Private Key:Derived From SSH ECDH Public Key:Derived From
Page 50
NameInput - OutputStorageStorage Duratio nZeroizatio nRelated SSPs
SSH DH Private KeyDRAM:Plaintex tWhile SSH tunnel is onZeroization CommandSSH DH Public Key:Paired With SSH Peer DH Public Key:Used With
SSH DH Public KeyModule Public Key OutputDRAM:Plaintex tWhile SSH tunnel is onZeroization CommandSSH DH Private Key:Paired With
SSH Peer DH Public KeyPeer Public Key InputDRAM:Plaintex tWhile SSH tunnel is onZeroization CommandSSH DH Private Key:Used With
SSH DH Shared SecretDRAM:Plaintex tWhile SSH tunnel is onZeroization CommandSSH DH Private Key:Derived From SSH DH Public Key:Derived From
SSH RSA Private KeyFlash:PlaintextZeroization CommandSSH RSA Public Key:Paired With
SSH RSA Public KeyModule Public Key OutputFlash:PlaintextZeroization CommandSSH RSA Private Key:Paired With
SSH ECDSA Private KeyFlash:PlaintextZeroization CommandSSH ECDSA Public Key:Paired With
SSH ECDSA Public KeyModule Public Key OutputFlash:PlaintextZeroization CommandSSH ECDSA Private Key:Paired With
SSH Session Encryption KeyDRAM:Plaintex tWhile SSH tunnel is onZeroization CommandSSH Session Authentication Key:Used With
SSH Session Authenticatio n KeyDRAM:Plaintex tWhile SSHZeroization CommandSSH Session Encryption
Page 51
NameInput - OutputStorageStorage Duratio nZeroizatio nRelated SSPs
tunnel is onKey:Used With
TLS ECDH Private KeyDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS ECDH Public Key:Paired With TLS Peer ECDH Public Key:Used With
TLS ECDH Public KeyModule Public Key OutputDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS ECDH Private Key:Paired With
TLS Peer ECDH Public KeyPeer Public Key InputDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS ECDH Private Key:Used With
TLS ECDH Shared SecretDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS ECDH Private Key:Derived From TLS ECDH Public Key:Derived From
TLS DH Private KeyDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS DH Public Key:Paired With TLS Peer DH Public Key:Used With
TLS DH Public KeyModule Public Key OutputDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS DH Private Key:Paired With
TLS Peer DH Public KeyPeer Public Key InputDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS DH Private Key:Used With
TLS DH Shared SecretDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS DH Private Key:Derived From TLS DH
Page 52
Name TLS RSA Private Key TLS RSA Public Key TLS ECDSA Private Key TLS ECDSA Public KeyInput - Output Module Public Key Output Module Public Key OutputStorage Flash:Plaintext Flash:Plaintext Flash:Plaintext Flash:PlaintextStorage Duratio nZeroizatio n Zeroization Command Zeroization Command Zeroization Command Zeroization CommandRelated SSPs Public Key:Derived From TLS RSA Public Key:Paired With TLS RSA Private Key:Paired With TLS ECDSA Public Key:Paired With TLS ECDSA Private Key:Paired With
TLS Master SecretDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS ECDH Shared Secret:Derive d From
TLS Session Encryption KeyDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS Session Authentication Key:Used With
TLS Session Authenticatio n KeyDRAM:Plaintex tWhile TLS tunnel is onZeroization CommandTLS Session Encryption Key:Used With
SNMPv3 Authenticatio n SecretPassword/Secre t Input via SSHv2 encrypted by AES and HMACDRAM:Plaintex tWhile SNMPv3 tunnel is onZeroization CommandSNMPv3 Encryption Key:Derive To SNMPv3 Integrity Key:Derive To
SNMPv3 Encryption KeyDRAM:Plaintex tWhile SNMPv3 tunnel is onZeroization CommandSNMPv3 Authentication Secret:Derive d From
SNMPv3 Integrity KeyDRAM:Plaintex tWhile SNMPv3 tunnel is onZeroization CommandSNMPv3 Authentication Secret:Derive d From SNMPv3 Encryption
Page 53
NameInput - OutputStorageStorage Duratio nZeroizatio nRelated SSPs Key:Used With
MACSec CAKPassword/Secre t Input via SSHv2 encrypted by AES and HMACFlash:PlaintextUntil ZeroizedZeroization CommandMACSec ICK:Derived From MACSec SAK:Derived From MACSec KEK:Derived From
MACSec ICKDRAM:Plaintex tWhile MACSec session is onZeroization CommandMACSec KEK:Used With
MACSec SAKMACSec SAK Output encrypted by MACSec KEK using AES-KW MACSec SAK Output encrypted by MACSec KEK using AES-KWPDRAM:Plaintex tWhile MACSec session is onZeroization CommandMACSec CAK:Derived From
MACSec KEKDRAM:Plaintex tWhile MACSec session is onZeroization CommandMACSec SAK:Encrypts
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
CRC-32 (Bootloader)N/AKATSW/FW IntegrityModule is in normal stateThe module performs the Bootloader integrity test
9.5 Transitions

The module includes an implementation of SHA-1 for hashing and message authentication. This implementation will be non-Approved for all uses starting January 1, 2031. User should move to SHA2, which is available in this module.”

10 Self-Tests
10.1 Pre-Operational Self-Tests
Page 54
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails by using CRC-32 at the power up
CRC-32 (Firmware)N/AKATSW/FW IntegrityModule is in normal stateThe module performs the Firmware integrity test by using CRC-32 at the power up
Algorithm or TestTest Properti esTest Metho dTest TypeIndicat orDetailsConditio ns
AES-CBC Encrypt KAT (A5076)128 bitsKATCASTModule is in normal stateEncryptPower Up
AES-CBC Decrypt KAT (A5076)128 bitsKATCASTModule is in normal stateDecryptPower Up
AES-GCM Authenticated Encrypt KAT (A5076)128 bitsKATCASTModule is in normal stateEncryptPower Up
AES-GCM Authenticated Decrypt KAT (A5076)128 bitsKATCASTModule is in normal stateDecryptPower Up
AES-CMAC Encrypt KAT (A5076)128 bitsKATCASTModule is in normal stateEncryptPower Up
AES-CMAC Decrypt KAT (5076)128 bitsKATCASTModule is in normal stateDecryptPower Up
Counter DRBG Instantiate/Generate/Res eed KAT (A5076)AES-128KATCASTModule is in normal stateInstantiate, Generate, and Reseed KATsPower Up

Table 19: Pre-Operational Self-Tests The modules perform the self-tests, including the pre-operational self-tests and conditional selftests. The module runs all self-tests without operator intervention. In the event that a self-test fails, the module will enter an error state, output an error message and follow up with a module reboot. The module permits operators to initiate the pre-operational or conditional self-tests on demand for periodic testing of the module by rebooting the system (i.e., power-cycling).

10.2 Conditional Self-Tests
Page 55
Algorithm or TestTest Properti esTest Metho dTest TypeIndicat orDetailsConditio ns
HMAC-SHA-1 KAT (A5076)SHA-1KATCASTModule is in normal stateHMAC- SHA-1Power Up
HMAC-SHA2-256 KAT (A5076)SHA2- 256KATCASTModule is in normal stateHMAC- SHA2-256Power Up
HMAC-SHA2-384 KAT (A5076)SHA2- 384KATCASTModule is in normal stateHMAC- SHA2-384Power Up
HMAC-SHA2-512 KAT (A5076)SHA2- 512KATCASTModule is in normal stateHMAC- SHA2-512Power Up
KAS-ECC-SSC Sp800- 56Ar3 KAT (A5076)P-256 CurveKATCASTModule is in normal statePrimitive Z KATPower Up
KAS-FFC-SSC Sp800- 56Ar3 KAT (A5076)MODP- 2048KATCASTModule is in normal statePrimitive Z KATPower Up
ECDSA SigGen (FIPS186-5) KAT (A5076)Curve P- 256KATCASTModule is in normal stateN/APower Up
ECDSA SigVer (FIPS186-5) KAT (A5076)Curve P- 256KATCASTModule is in normal stateN/APower Up
RSA SigGen (FIPS186- 5) KAT (A5076)2048 bit modulus with SHA2- 256KATCASTModule is in normal stateRSA SigGen KATPower Up
RSA SigVer (FIPS186-5) KAT (A5076)2048 bit modulus with SHA2- 256KATCASTModule is in normal stateRSA SigVer KATPower Up
KDF SNMP KAT (A5076)N/AKATCASTModule is in normal stateN/APower Up
Page 56
Algorithm or TestTest Properti esTest Metho dTest TypeIndicat orDetailsConditio ns
KDF SSH KAT (A5076)N/AKATCASTModule is in normal stateN/APower Up
TLS v1.2 KDF RFC7627 KAT (A5076)N/AKATCASTModule is in normal stateN/APower Up
SHA-1 KAT (A5076)N/AKATCASTModule is in normal stateN/APower Up
SHA2-256 KAT (A5076)N/AKATCASTModule is in normal stateN/APower Up
SHA2-384 KAT (A5076)N/AKATCASTModule is in normal stateN/APower Up
SHA2-512 KAT (A5076)N/AKATCASTModule is in normal stateN/APower Up
ECDSA KeyGen (FIPS186-5) PCT (A5076)Curve P- 256PCTPCTModule is in normal stateN/APerforms all required pair-wise consisten cy tests on the newly generated keypairs before the first operation al use.
RSA KeyGen (FIPS186- 5) PCT (A5076)2048 bit ModulusPCTPCTModule is in normal stateRSAPerforms all required pair-wise consisten cy tests on the newly generated
Page 57
Algorithm or TestTest Properti esTest Metho dTest TypeIndicat orDetailsConditio ns key pairs before the first operation al use.
KAS-ECC-SSC Sp800- 56Ar3 PCT (A5076)Curve P- 256 with SHA2- 256PCTPCTModule is in normal stateN/APerforms all required pair-wise consisten cy tests on the newly generated key pairs before the first operation al use.
KAS-FFC-SSC Sp800- 56Ar3 PCT (A5076)MODP- 2048PCTPCTModule is in normal stateN/APerforms all required pair-wise consisten cy tests on the newly generated key pairs before the first operation al use.
RSA SigVer (FIPS186-5) Firmware Load Test2048 bits with SHA2- 256KATSW/F W LoadModule is in normal stateN/AWhen firmware has been uploaded to the module
KDF-SP800-108 KAT (A5076)N/AKATCASTModule is in normal stateN/APower Up
AES-GCM Authenticated Encrypt KAT (AES 4550)128 bitsKATCASTModule is in normal stateEncryptPower Up
Page 58
Algorithm or TestTest Properti esTest Metho dTest TypeIndicat orDetailsConditio ns
AES-GCM Authenticated Decrypt KAT (AES 4550)128 bitsKATCASTModule is in normal stateDecryptPower Up
Entropy 90B Start-up Repetition Count Test (RCT)Repetitio n Count TestRCTCASTModule is in normal stateDesigned to quickly detect catastrophic failures that cause the noise source to become "stuck" on a single output value for a long period of timePower Up
Entropy 90B Start-up Adaptive Proportion Test (APT)Adaptive Proportio n TestAPTCASTModule is in normal stateDesigned to detect a large loss of entropy that might occur as a result of some physical failure or environment al change affecting the noise sourcePower Up
Entropy 90B Continuous Repetition Count Test (RCT)Repetitio n Count TestRCTCASTModule is in normal stateDesigned to quickly detect catastrophic failures that cause the noise source to become "stuck" on a single output value for a longEntropy data is generated from the Entropy Source - Continuou s
Page 59
Algorithm or TestTest Properti esTest Metho dTest TypeIndicat orDetails period of timeConditio ns
Entropy 90B Continuous Adaptive Proportion Test (APT)Adaptive Proportio n TestAPTCASTModule is in normal stateDesigned to detect a large loss of entropy that might occur as a result of some physical failure or environment al change affecting the noise sourceEntropy data is generated from the Entropy Source - Continuou s
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
CRC-32 (Bootloader)KATSW/FW IntegrityRecommend 60 DaysReboot
CRC-32 (Firmware)KATSW/FW IntegrityRecommend 60 DaysReboot
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC Encrypt KAT (A5076)KATCASTRecommend 60 DaysReboot
AES-CBC Decrypt KAT (A5076)KATCASTRecommend 60 DaysReboot
AES-GCM Authenticated Encrypt KAT (A5076)KATCASTRecommend 60 DaysReboot
AES-GCM Authenticated Decrypt KAT (A5076)KATCASTRecommend 60 DaysReboot
AES-CMAC Encrypt KAT (A5076)KATCASTRecommend 60 DaysReboot
AES-CMAC Decrypt KAT (5076)KATCASTRecommend 60 DaysReboot

Table 20: Conditional Self-Tests

10.3 Periodic Self-Test Information

Table 21: Pre-Operational Periodic Information

Page 60
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Counter DRBG Instantiate/Generate/Reseed KAT (A5076)KATCASTRecommend 60 DaysReboot
HMAC-SHA-1 KAT (A5076)KATCASTRecommend 60 DaysReboot
HMAC-SHA2-256 KAT (A5076)KATCASTRecommend 60 DaysReboot
HMAC-SHA2-384 KAT (A5076)KATCASTRecommend 60 DaysReboot
HMAC-SHA2-512 KAT (A5076)KATCASTRecommend 60 DaysReboot
KAS-ECC-SSC Sp800- 56Ar3 KAT (A5076)KATCASTRecommend 60 DaysReboot
KAS-FFC-SSC Sp800- 56Ar3 KAT (A5076)KATCASTRecommend 60 DaysReboot
ECDSA SigGen (FIPS186-5) KAT (A5076)KATCASTRecommend 60 DaysReboot
ECDSA SigVer (FIPS186-5) KAT (A5076)KATCASTRecommend 60 DaysReboot
RSA SigGen (FIPS186-5) KAT (A5076)KATCASTRecommend 60 DaysReboot
RSA SigVer (FIPS186-5) KAT (A5076)KATCASTRecommend 60 DaysReboot
KDF SNMP KAT (A5076)KATCASTRecommend 60 DaysReboot
KDF SSH KAT (A5076)KATCASTRecommend 60 DaysReboot
TLS v1.2 KDF RFC7627 KAT (A5076)KATCASTRecommend 60 DaysReboot
SHA-1 KAT (A5076)KATCASTRecommend 60 DaysReboot
SHA2-256 KAT (A5076)KATCASTRecommend 60 DaysReboot
SHA2-384 KAT (A5076)KATCASTRecommend 60 DaysReboot
SHA2-512 KAT (A5076)KATCASTRecommend 60 DaysReboot
ECDSA KeyGen (FIPS186- 5) PCT (A5076)PCTPCTRecommend 60 DaysReboot
RSA KeyGen (FIPS186-5) PCT (A5076)PCTPCTRecommend 60 DaysReboot
KAS-ECC-SSC Sp800- 56Ar3 PCT (A5076)PCTPCTRecommend 60 DaysReboot
KAS-FFC-SSC Sp800- 56Ar3 PCT (A5076)PCTPCTRecommend 60 DaysReboot
RSA SigVer (FIPS186-5) Firmware Load TestKATSW/FW LoadRecommend 60 DaysReboot
Page 61
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KDF-SP800-108 KAT (A5076)KATCASTRecommend 60 DaysReboot
AES-GCM Authenticated Encrypt KAT (AES 4550)KATCASTRecommend 60 DaysReboot
AES-GCM Authenticated Decrypt KAT (AES 4550)KATCASTRecommend 60 DaysReboot
Entropy 90B Start-up Repetition Count Test (RCT)RCTCASTN/AN/A
Entropy 90B Start-up Adaptive Proportion Test (APT)APTCASTN/AN/A
Entropy 90B Continuous Repetition Count Test (RCT)RCTCASTN/AN/A
Entropy 90B Continuous Adaptive Proportion Test (APT)APTCASTN/AN/A
NameDescriptionConditionsRecovery MethodIndicator
Error StateIf self-test tests fail, the module is put into an error stateSelf-test failureReboot the moduleSystem Halt

Table 22: Conditional Periodic Information

10.4 Error States

Table 23: Error States If any of the above-mentioned self-tests fail, the module reports the cause of the error and enters an error state. In the Error State, no cryptographic services are provided, and data output is prohibited. The only method to recover from the error state is to reboot the module and reperforming the self-tests, including the pre-operational software integrity test and the conditional CASTs. The module will only enter into the operational state after successfully passing the pre-operational firmware integrity test and the conditional CASTs. The table below shows the different causes that lead to the Error State and the status indicators reported.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module meets all the Level 1 requirements for FIPS 140-3. Follow the secure operations provided below to place the module in approved mode. Operating this module without maintaining the following settings will put the module operate in a non-compliant state. The module runs firmware version IronWare OS 10.0.10. This is the only allowable firmware image for this current approved mode of operation. The Crypto Officer shall load the FIPS 140-3 validated firmware only to maintain validation. Any firmware/software loaded into this module

Page 62

that is not shown on the module certificate, is out of the scope of this validation and requires a separate FIPS 140-3 validation. The module is initiated into the approved mode of operation via the following procedures through the Command Line interface (CLI):

  1. The Crypto Officer must login by using the default login password.
  2. The Crypto Officer shall replace the default login password with a new one.
  3. Enter into the configuration mode by using ‘conf t’ command.
  4. Enable approved mode by using ‘fips enable’ command.
  5. Create accounts for Port Config Admin role and User role respectively.
  6. Configure SSH, TLS, SNMPv3 and MACSec services by using only approved algorithms listed above.
  7. Configure the module as the MACSec Peer Authenticator in the MACSec service.
  8. If using RADIUS server for roles authentication, please configure a secure TLS tunnel to secure traffic between the module and the RADIUS server. The RADIUS shared secret must be at least 8 characters long.
  9. Disable the TFTP server.
  10. Ensure that installed digital certificates are signed using approved algorithms.
  11. Save the configuration.
  12. Reload the module.
  13. Verify the approved mode by using command ‘fips show’ (This command outputs the module’s status. After the approved mode was enabled, the output would be “approved mode: Administrative status ON”).
  14. The Crypto Officer shall load the FIPS 140-3 validated firmware only to maintain validation. Once the module has completed initialization into the approved mode of operation, the module automatically enforces a password change for the Crypto Officer. Any non-approved algorithms or security functions are rejected automatically by the module and an error message is output.
11.2 Administrator Guidance

No specific Administrator guidance.

11.3 Non-Administrator Guidance

No specific Non-Administrator guidance.

11.4 End of Life

Crypto Officers should follow the procedure below for the secure destruction of their module: Note: This process will cause the module to no longer function after it has wiped all configurations and keys.

  1. Access the module via SSH with Crypto Officer
  2. Authenticate using proper credentials
  3. Execute command: “fips zeroize all” a. Confirm command
Page 63

Module will begin zeroization process and wipe all security parameters and configurations

12 Mitigation of Other Attacks