All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Wave Relay® User Space Crypto Module

Certificate#5079StandardFIPS 140-3Level2TypeSoftwareEmbodimentSingle ChipStatusActiveVendorPersistent Systems, LLC
Low review priority  ·  no TCB surface named  ·  last validated 9 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeSoftware
EmbodimentSingle Chip
StatusActive
Sunset date10/7/2030
CaveatWhen operated in approved mode, No assurance of the minimum strength of generated SSPs (e.g., keys)
VendorPersistent Systems, LLC

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Wave Relay® User Space Crypto Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Wave Relay® User Space Crypto Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Persistent Systems, LLC Wave Relay® User Space Crypto Module Document Version: 1.2 Date: September 29, 2025

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)7
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Modes List and Description9
Table 5: Approved Algorithms14
Table 6: Vendor-Affirmed Algorithms15
Table 7: Non-Approved, Not Allowed Algorithms15
Table 8: Security Function Implementations40
Table 9: Ports and Interfaces43
Table 10: Authentication Methods44
Table 11: Roles44
Table 12: Approved Services49
Table 13: Non-Approved Services49
Table 14: Storage Areas52
Table 15: SSP Input-Output Methods53
Table 16: SSP Zeroization Methods53
Table 17: SSP Table 156
Table 18: SSP Table 259
Table 19: Pre-Operational Self-Tests61
Table 20: Conditional Self-Tests65
Table 21: Pre-Operational Periodic Information65
Table 22: Conditional Periodic Information66
Table 23: Error States67
Table 24 – References70
Table 25 – Acronyms and Definitions70
Figure 1 Logical Cryptographic Boundary and Physical Perimeter6
Page 5
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environment2
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level2

Table 1: Security Levels FIPS validated connectivity drives mission success. This Persistent Systems LLC Wave Relay® User Space Crypto Module, hereafter denoted as the “module”, is a Software cryptographic module embedded in the Wave Relay® System that provides FIPS validated cryptographic algorithms which are used by user space system services & protocols (e.g., TLS, IPsec, etc.) The Wave Relay® System is a peer-to-peer wireless MANET networking solution in which there is no master node. If any device fails, the rest of the devices continue to communicate using any remaining connectivity. By eliminating master nodes, gateways, access points, and central coordinators from the design, Wave Relay® delivers high levels of fault tolerance regardless of which nodes might fail.

2.1 Description

Purpose and Use: The module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated cryptography. The module is intended to be used in various products within the vendor’s portfolio of solutions. Built to create powerful, secure networks anywhere, the module is used to unite all critical data sources in real time giving you and your team the confidence to make difficult decisions in the heat of the moment. Module Embodiment: SingleChip

Page 6

Module Characteristics: Cryptographic Boundary: The TOEPP of the module is depicted in Figure 1. The Module is a single-chip embodiment. The cryptographic boundary is outlined in red and is defined as a dynamic software library (fips.so). The following block diagram details the module’s boundaries: Figure 1 Logical Cryptographic Boundary and Physical Perimeter

2.2 Tested and Vendor Affirmed Module Version and Identification

N/A for this module. Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): The cryptographic module is tested on the following operational environments:

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
Wave Relay User Space Crypto Module1.0HMAC-SHA2-256

Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)

Page 8
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Wave Relay® OS 2.2MPU (5th Generation)MCIMX6Q6AVT10AE, MCIMX6Q6AVT10ADYes1.0
Wave Relay® OS 2.2Embedded ModuleMCIMX6Q7CZK08AE, MSCMMX6QZCK08ABYes1.0
Wave Relay® OS 2.2Embedded Module liteMCIMX6Q7CZK08AE, MSCMMX6QZCK08ABYes1.0
Wave Relay® OS 2.2GVR5MCIMX6Q7CZK08AEYes1.0
Wave Relay® OS 2.2Integrated Antenna SeriesMCIMX6Q7CZK08AEYes1.0

Tested Operational Environments - Software, Firmware, Hybrid: Wave Relay® User Space Crypto Module cryptographic module is tested on the following operational environments. Table 3: Tested Operational Environments - Software, Firmware, Hybrid N/A for this module.

2.3 Excluded Components

No components were excluded from the cryptographic boundary.

2.4 Modes of Operation

Modes List and Description: The Module supports an Approved mode and Non-Approved mode of operation. The module does not support a degraded mode. The Module’s status output will include a “FIPS Indicator” line. If this line explicitly states “not-approved”, then the Module is in the Non-Approved state; otherwise, the line will be blank, indicating the Approved state.

Page 9
Mode NameDescriptionTypeStatus Indicator
ApprovedThe module supports Approved services in the Approved mode of operation. Non-Approved services are not supported in this mode.ApprovedFIPS Indicator:
Non- ApprovedThe module is capable of non-approved services in the non-approved mode of operation only.Non- ApprovedFIPS Indicator: not-approved
AlgorithmCAVP CertPropertiesReference
AES-CBCA5177Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A5177Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A5177Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A5177Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA5177Key Length - 128, 192, 256SP 800-38C
AES-CFB1A5177Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A5177Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A5177Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

Table 4: Modes List and Description Mode Change Instructions and Status : The module provides a service level indicator. All Approved services will indicate they are Approved services, and all non-Approved services will indicate they are non-Approved. No additional configuration or initialization is required.

2.5 Algorithms

Approved Algorithms: The Module implements cryptographic algorithms in the following providers: • Wave Relay® User Space Crypto Module version 1.0 (Cert. #A5177) Validation certificates for each Approved security function are listed in the table below.

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CMACA5177Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA5177Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5177Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA5177Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GMACA5177Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-KWA5177Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA5177Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA5177Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A5177Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA5177Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A5177Curve - B-233, B-283, B-409, B-571, K-233, K- 283, K-409, K-571, P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A5177Curve - B-163, B-233, B-283, B-409, B-571, K- 163, K-233, K-283, K-409, K-571, P-192, P- 224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A5177Component - No, Yes Curve - B-233, B-283, B-409, B-571, K-233, K- 283, K-409, K-571, P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A5177Component - No, Yes Curve - B-163, B-233, B-283, B-409, B-571, K- 163, K-233, K-283, K-409, K-571, P-192, P- 224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
Page 11
AlgorithmCAVP CertPropertiesReference
Hash DRBGA5177Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5177Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC-SHA-1A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A5177Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
KAS-ECC CDH- Component SP800-56Ar3 (CVL)A5177Curve - B-233, B-283, B-409, B-571, K-233, K- 283, K-409, K-571, P-224, P-256, P-384, P-521SP 800-56A Rev. 3
KAS-ECC-SSC Sp800-56Ar3A5177Domain Parameter Generation Methods - B- 233, B-283, B-409, B-571, K-233, K-283, K- 409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A5177Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
Page 12
AlgorithmCAVP CertPropertiesReference
KAS-IFC-SSCA5177Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF SP800-56Cr2A5177Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512SP 800-56C Rev. 2
KDA OneStep SP800-56Cr2A5177Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDA TwoStep SP800-56Cr2A5177MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDF ANS 9.42 (CVL)A5177KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A5177Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Key Data Length - Key Data Length: 128, 4096SP 800-135 Rev. 1
KDF IKEv2 (CVL)A5177Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 224, 8192 Derived Keying Material Length - Derived Keying Material Length: 160, 16384 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF SP800-108A5177KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8-4096 Increment 8SP 800-108 Rev. 1
Page 13
AlgorithmCAVP CertPropertiesReference
KDF SSH (CVL)A5177Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KMAC-128A5177Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KMAC-256A5177Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KTS-IFCA5177Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024SP 800-56B Rev. 2
PBKDFA5177Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8SP 800-132
RSA KeyGen (FIPS186-4)A5177Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A5177Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA Signature Primitive (CVL)A5177Private Key Format - crtFIPS 186-4
RSA SigVer (FIPS186-4)A5177Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
Safe Primes Key GenerationA5177Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
Safe Primes Key VerificationA5177Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
SHA-1A5177Message Length - Message Length: 160, 0- 65536 Increment 8FIPS 180-4
Page 14
AlgorithmCAVP CertPropertiesReference
SHA2-224A5177Message Length - Message Length: 224, 0- 65536 Increment 8FIPS 180-4
SHA2-256A5177Message Length - Message Length: 256, 0- 65536 Increment 8FIPS 180-4
SHA2-384A5177Message Length - Message Length: 384, 0- 65536 Increment 8FIPS 180-4
SHA2-512A5177Message Length - Message Length: 512, 0- 65536 Increment 8FIPS 180-4
SHA2-512/224A5177Message Length - Message Length: 224, 0- 65536 Increment 8FIPS 180-4
SHA2-512/256A5177Message Length - Message Length: 256, 0- 65536 Increment 8FIPS 180-4
SHA3-224A5177Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-256A5177Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-384A5177Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-512A5177Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHAKE-128A5177Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A5177Output Length - Output Length: 16-65536 Increment 8FIPS 202
TLS v1.2 KDF RFC7627 (CVL)A5177Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A5177HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHESP 800-135 Rev. 1

Table 5: Approved Algorithms ApprovedAlgorithmsTable From Web Cryptik ApprovedAlgorithmsTable Vendor-Affirmed Algorithms: The Module supports SP800-133rev2, CKG, as the sole vendor affirmed cryptographic

Page 15
NamePropertiesImplementationReference
CKG - Symmetric and AsymmetricKey Type:Symmetric and AsymmetricN/ASP800-133rev2, Section 4, Example 1
NameUse and Function
AES (GCM) - Ext IVGCM with Externally Generated IVs

Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: The module does not support any Non-Approved but Allowed Algorithms in the Approved Mode of Operation. N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: The module does not implement any Non-Approved, Algorithms Allowed with No Security Claimed in the Approved Mode of Operation. N/A for this module. Non-Approved, Not Allowed Algorithms: The Module implements the Non-Approved, Not Allowed cryptographic algorithms listed in the table below. Table 7: Non-Approved, Not Allowed Algorithms

Page 16
NameTypeDescriptionPropertiesAlgorithms
BCUBC-UnAuthSymmetric Data Encryption/DecryptionPublication:FIPS 197AES-CBC: (A5177) Key Length: 128, 192, 256 AES-CBC-CS1: (A5177) Key Length: 128, 192, 256 AES-CBC-CS2: (A5177) Key Length: 128, 192, 256 AES-CBC-CS3: (A5177) Key Length: 128, 192, 256 AES-CFB128: (A5177) Key Length: 128, 192, 256 AES-CFB8: (A5177) Key Length: 128, 192, 256 AES-CTR: (A5177) Key Length: 128, 192, 256 AES-ECB: (A5177) Key Length: 128, 192, 256 AES-XTS Testing Revision 2.0: (A5177) Key Length: 128, 256 AES-OFB: (A5177) Key Length: 128, 192, 256 AES-CFB1: (A5177) Key Length: 128, 192, 256
BCABC-AuthAuthenticated Symmetric Encryption/DecryptionPublications:FIPS197, SP800-38C, SP800- 38D, SP800-38FAES-CCM: (A5177) Key Length: 128, 192, 256 AES-GCM: (A5177) Key Length: 128, 192, 256
2.6 Security Function Implementations

The table below shows the Security Function Implementations that the module implements:

Page 17
NameTypeDescriptionPropertiesAlgorithms
AES-KW: (A5177) Key Length: 128, 192, 256 AES-KWP: (A5177) Key Length: 128, 192, 256
SigVerDigSig-SigVerSignature VerificationPublication:186-4ECDSA SigVer (FIPS186-4): (A5177) Capabilities: Capabilities: Curve: P- 192 Hash Algorithm: SHA-1 Capabilities: Curve: P-224 Hash Algorithm: SHA-1 Capabilities: Curve: P-256 Hash Algorithm: SHA-1 Capabilities: Curve: P-384 Hash Algorithm: SHA-1 Capabilities: Curve: P-521 Hash Algorithm: SHA-1 Capabilities: Curve: K-163 Hash Algorithm: SHA-1 Capabilities: Curve: K-233 Hash Algorithm: SHA-1 Capabilities: Curve: K-283 Hash Algorithm: SHA-1 Capabilities: Curve: K-409 Hash Algorithm: SHA-1 Capabilities: Curve: K-571 Hash Algorithm: SHA-1 Capabilities: Curve: B-163 Hash Algorithm: SHA-1 Capabilities: Curve: B-233 Hash Algorithm: SHA-1 Capabilities: Curve: B-283 Hash Algorithm: SHA-1 Capabilities: Curve: B-409 Hash Algorithm: SHA-1 Capabilities: Curve: B-571 Hash Algorithm: SHA-1 Capabilities: Curve: P-192
Page 18
NameTypeDescriptionPropertiesAlgorithms
Hash Algorithm: SHA2-224 Capabilities: Curve: P-224 Hash Algorithm: SHA2-224 Capabilities: Curve: P-256 Hash Algorithm: SHA2-224 Capabilities: Curve: P- 384 Hash Algorithm: SHA2-224 Capabilities: Curve: P-521 Hash Algorithm: SHA2-224 Capabilities: Curve: K-163 Hash Algorithm: SHA2-224 Capabilities: Curve: K- 233 Hash Algorithm: SHA2-224 Capabilities: Curve: K-283 Hash Algorithm: SHA2-224 Capabilities: Curve: K-409 Hash Algorithm: SHA2-224 Capabilities: Curve: K- 571 Hash Algorithm: SHA2-224 Capabilities: Curve: B-163 Hash Algorithm: SHA2-224 Capabilities: Curve: B-233 Hash Algorithm: SHA2-224 Capabilities: Curve: B- 283 Hash Algorithm: SHA2-224 Capabilities: Curve: B-409 Hash Algorithm: SHA2-224 Capabilities: Curve: B-571 Hash Algorithm: SHA2-224 Capabilities: Curve: P- 192 Hash Algorithm: SHA2-256 Capabilities: Curve: P-224 Hash Algorithm: SHA2-256 Capabilities: Curve: P-256 Hash Algorithm: SHA2-256 Capabilities: Curve: P- 384 Hash Algorithm: SHA2-256 Capabilities: Curve: P-521 Hash
Page 19
NameTypeDescriptionPropertiesAlgorithms
Algorithm: SHA2-256 Capabilities: Curve: K-163 Hash Algorithm: SHA2-256 Capabilities: Curve: K- 233 Hash Algorithm: SHA2-256 Capabilities: Curve: K-283 Hash Algorithm: SHA2-256 Capabilities: Curve: K-409 Hash Algorithm: SHA2-256 Capabilities: Curve: K- 571 Hash Algorithm: SHA2-256 Capabilities: Curve: B-163 Hash Algorithm: SHA2-256 Capabilities: Curve: B-233 Hash Algorithm: SHA2-256 Capabilities: Curve: B- 283 Hash Algorithm: SHA2-256 Capabilities: Curve: B-409 Hash Algorithm: SHA2-256 Capabilities: Curve: B-571 Hash Algorithm: SHA2-256 Capabilities: Curve: P- 192 Hash Algorithm: SHA2-384 Capabilities: Curve: P-224 Hash Algorithm: SHA2-384 Capabilities: Curve: P-256 Hash Algorithm: SHA2-384 Capabilities: Curve: P- 384 Hash Algorithm: SHA2-384 Capabilities: Curve: P-521 Hash Algorithm: SHA2-384 Capabilities: Curve: K-163 Hash Algorithm: SHA2-384 Capabilities: Curve: K- 233 Hash Algorithm: SHA2-384 Capabilities: Curve: K-283 Hash Algorithm: SHA2-384 Capabilities: Curve: K-409 Hash Algorithm:
Page 20
NameTypeDescriptionPropertiesAlgorithms
SHA2-384 Capabilities: Curve: K- 571 Hash Algorithm: SHA2-384 Capabilities: Curve: B-163 Hash Algorithm: SHA2-384 Capabilities: Curve: B-233 Hash Algorithm: SHA2-384 Capabilities: Curve: B- 283 Hash Algorithm: SHA2-384 Capabilities: Curve: B-409 Hash Algorithm: SHA2-384 Capabilities: Curve: B-571 Hash Algorithm: SHA2-384 Capabilities: Curve: P- 192 Hash Algorithm: SHA2-512 Capabilities: Curve: P-224 Hash Algorithm: SHA2-512 Capabilities: Curve: P-256 Hash Algorithm: SHA2-512 Capabilities: Curve: P- 384 Hash Algorithm: SHA2-512 Capabilities: Curve: P-521 Hash Algorithm: SHA2-512 Capabilities: Curve: K-163 Hash Algorithm: SHA2-512 Capabilities: Curve: K- 233 Hash Algorithm: SHA2-512 Capabilities: Curve: K-283 Hash Algorithm: SHA2-512 Capabilities: Curve: K-409 Hash Algorithm: SHA2-512 Capabilities: Curve: K- 571 Hash Algorithm: SHA2-512 Capabilities: Curve: B-163 Hash Algorithm: SHA2-512 Capabilities: Curve: B-233 Hash Algorithm: SHA2-512 Capabilities: Curve: B- 283 Hash Algorithm: SHA2-512
Page 21
NameTypeDescriptionPropertiesAlgorithms
Capabilities: Curve: B-409 Hash Algorithm: SHA2-512 Capabilities: Curve: B-571 Hash Algorithm: SHA2-512 Capabilities: Curve: P- 192 Hash Algorithm: SHA2- 512/224 Capabilities: Curve: P-224 Hash Algorithm: SHA2-512/224 Capabilities: Curve: P-256 Hash Algorithm: SHA2-512/224 Capabilities: Curve: P-384 Hash Algorithm: SHA2-512/224 Capabilities: Curve: P-521 Hash Algorithm: SHA2-512/224 Capabilities: Curve: K-163 Hash Algorithm: SHA2-512/224 Capabilities: Curve: K-233 Hash Algorithm: SHA2-512/224 Capabilities: Curve: K-283 Hash Algorithm: SHA2-512/224 Capabilities: Curve: K-409 Hash Algorithm: SHA2-512/224 Capabilities: Curve: K-571 Hash Algorithm: SHA2-512/224 Capabilities: Curve: B-163 Hash Algorithm: SHA2-512/224 Capabilities: Curve: B-233 Hash Algorithm: SHA2-512/224 Capabilities: Curve: B-283 Hash Algorithm: SHA2-512/224 Capabilities: Curve: B-409 Hash Algorithm: SHA2-512/224 Capabilities: Curve: B-571 Hash
Page 22
NameTypeDescriptionPropertiesAlgorithms
Algorithm: SHA2-512/224 Capabilities: Curve: P-192 Hash Algorithm: SHA2-512/256 Capabilities: Curve: P-224 Hash Algorithm: SHA2-512/256 Capabilities: Curve: P-256 Hash Algorithm: SHA2-512/256 Capabilities: Curve: P-384 Hash Algorithm: SHA2-512/256 Capabilities: Curve: P-521 Hash Algorithm: SHA2-512/256 Capabilities: Curve: K-163 Hash Algorithm: SHA2-512/256 Capabilities: Curve: K-233 Hash Algorithm: SHA2-512/256 Capabilities: Curve: K-283 Hash Algorithm: SHA2-512/256 Capabilities: Curve: K-409 Hash Algorithm: SHA2-512/256 Capabilities: Curve: K-571 Hash Algorithm: SHA2-512/256 Capabilities: Curve: B-163 Hash Algorithm: SHA2-512/256 Capabilities: Curve: B-233 Hash Algorithm: SHA2-512/256 Capabilities: Curve: B-283 Hash Algorithm: SHA2-512/256 Capabilities: Curve: B-409 Hash Algorithm: SHA2-512/256 Capabilities: Curve: B-571 Hash Algorithm: SHA2-512/256 RSA SigVer (FIPS186-4): (A5177)
Page 23
NameTypeDescriptionPropertiesAlgorithms
Capabilities: Signature Type: PKCS 1.5 Properties: Modulo: 1024 Hash Pair: Hash Algorithm: SHA-1 Hash Pair: Hash Algorithm: SHA2-224 Hash Pair: Hash Algorithm: SHA2- 256 Hash Pair: Hash Algorithm: SHA2-384 Hash Pair: Hash Algorithm: SHA2-512 Hash Pair: Hash Algorithm: SHA2-512/224 Hash Pair: Hash Algorithm: SHA2- 512/256 Properties: Modulo: 2048 Hash Pair: Hash Algorithm: SHA-1 Hash Pair: Hash Algorithm: SHA2- 224 Hash Pair: Hash Algorithm: SHA2-256 Hash Pair: Hash Algorithm: SHA2-384 Hash Pair: Hash Algorithm: SHA2-512 Hash Pair: Hash Algorithm: SHA2- 512/224 Hash Pair: Hash Algorithm: SHA2-512/256 Properties: Modulo: 3072 Hash Pair: Hash Algorithm: SHA-1 Hash Pair: Hash Algorithm: SHA2-224 Hash Pair: Hash Algorithm: SHA2-256 Hash Pair: Hash Algorithm: SHA2-384 Hash Pair: Hash Algorithm: SHA2-512 Hash Pair: Hash Algorithm: SHA2- 512/224 Hash Pair: Hash Algorithm: SHA2-512/256 Properties: Modulo: 4096 Hash Pair: Hash Algorithm: SHA-1 Hash Pair: Hash Algorithm: SHA2-224 Hash Pair: Hash
Page 24
NameTypeDescriptionPropertiesAlgorithms
Algorithm: SHA2-256 Hash Pair: Hash Algorithm: SHA2-384 Hash Pair: Hash Algorithm: SHA2-512 Hash Pair: Hash Algorithm: SHA2- 512/224 Hash Pair: Hash Algorithm: SHA2-512/256 Capabilities: Signature Type: PKCSPSS Properties: Modulo: 1024 Hash Pair: Hash Algorithm: SHA-1 Salt Length: 20 Hash Pair: Hash Algorithm: SHA2-224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-256 Salt Length: 32 Hash Pair: Hash Algorithm: SHA2-384 Salt Length: 48 Hash Pair: Hash Algorithm: SHA2-512 Salt Length: 62 Hash Pair: Hash Algorithm: SHA2-512/224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2- 512/256 Salt Length: 32 Properties: Modulo: 2048 Hash Pair: Hash Algorithm: SHA-1 Salt Length: 20 Hash Pair: Hash Algorithm: SHA2- 224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-256 Salt Length: 32 Hash Pair: Hash Algorithm: SHA2-384 Salt Length: 48 Hash Pair: Hash Algorithm: SHA2-512 Salt Length: 64 Hash Pair: Hash Algorithm: SHA2-512/224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-512/256 Salt
Page 25
NameTypeDescriptionPropertiesAlgorithms
Length: 32 Properties: Modulo: 3072 Hash Pair: Hash Algorithm: SHA-1 Salt Length: 20 Hash Pair: Hash Algorithm: SHA2-224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-256 Salt Length: 32 Hash Pair: Hash Algorithm: SHA2-384 Salt Length: 48 Hash Pair: Hash Algorithm: SHA2-512 Salt Length: 64 Hash Pair: Hash Algorithm: SHA2-512/224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-512/256 Salt Length: 32 Properties: Modulo: 4096 Hash Pair: Hash Algorithm: SHA-1 Salt Length: 20 Hash Pair: Hash Algorithm: SHA2-224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-256 Salt Length: 32 Hash Pair: Hash Algorithm: SHA2-384 Salt Length: 48 Hash Pair: Hash Algorithm: SHA2-512 Salt Length: 64 Hash Pair: Hash Algorithm: SHA2-512/224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-512/256 Salt Length: 32 Public Exponent Mode: Random
AKP-KGAsymKeyPair- KeyGenAsymmetric Key Pair GenerationPublication:SP800- 56Br2, FIPS 186-4ECDSA KeyGen (FIPS186-4): (A5177) Curves:: B-233, B-283, B-409, B- 571, K-233, K-283, K-409, K-571,
Page 26
NameTypeDescriptionPropertiesAlgorithms
P-224, P-256, P-384, P-521 RSA KeyGen (FIPS186-4): (A5177) Modulo: 2048, 3072, 4096 KTS-IFC: (A5177) Modulo: 2048, 3072, 4096, 6144, 8192 CKG - Symmetric and Asymmetric: () Safe Primes Key Generation: (A5177)
AKP-DPAsymKeyPair- DomParDomain Parameter GenerationPublications:SP800- 56Ar3KAS-ECC-SSC Sp800-56Ar3: (A5177) Methods: B-233, B-283, B-409, B- 571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 KAS-FFC-SSC Sp800-56Ar3: (A5177) Methods: FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192
AKP-KVAsymKeyPair- KeyVerECDSA Key VerificationPublication:FIPS186- 4ECDSA KeyVer (FIPS186-4): (A5177) Curve: B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K- 409, K-571, P-192, P-224, P-256, P- 384, P-521 Safe Primes Key Verification: (A5177)
Page 27
NameTypeDescriptionPropertiesAlgorithms
AKV-PKVAsymKeyPair- PubKeyValPublic Key ValidationPublication:FIPS 186- 4KTS-IFC: (A5177) Modulo: 2048, 3072, 4096, 6144, 8192
SigGenDigSig-SigGenSignature Generation and Signature PrimitivePublication:FIPS 186- 4ECDSA SigGen (FIPS186-4): (A5177) Capabilities: Capabilities: Curve: P- 224 Hash Algorithm: SHA2-224 Capabilities: Curve: P-256 Hash Algorithm: SHA2-224 Capabilities: Curve: P-384 Hash Algorithm: SHA2-224 Capabilities: Curve: P- 521 Hash Algorithm: SHA2-224 Capabilities: Curve: K-233 Hash Algorithm: SHA2-224 Capabilities: Curve: K-283 Hash Algorithm: SHA2-224 Capabilities: Curve: K- 409 Hash Algorithm: SHA2-224 Capabilities: Curve: K-571 Hash Algorithm: SHA2-224 Capabilities: Curve: B-233 Hash Algorithm: SHA2-224 Capabilities: Curve: B- 283 Hash Algorithm: SHA2-224 Capabilities: Curve: B-409 Hash Algorithm: SHA2-224 Capabilities: Curve: B-571 Hash Algorithm: SHA2-224 Capabilities: Curve: P- 224 Hash Algorithm: SHA2-256 Capabilities: Curve: P-256 Hash Algorithm: SHA2-256 Capabilities: Curve: P-384 Hash Algorithm: SHA2-256 Capabilities: Curve: P- 521 Hash Algorithm: SHA2-256
Page 28
NameTypeDescriptionPropertiesAlgorithms
Capabilities: Curve: K-233 Hash Algorithm: SHA2-256 Capabilities: Curve: K-283 Hash Algorithm: SHA2-256 Capabilities: Curve: K- 409 Hash Algorithm: SHA2-256 Capabilities: Curve: K-571 Hash Algorithm: SHA2-256 Capabilities: Curve: B-233 Hash Algorithm: SHA2-256 Capabilities: Curve: B- 283 Hash Algorithm: SHA2-256 Capabilities: Curve: B-409 Hash Algorithm: SHA2-256 Capabilities: Curve: B-571 Hash Algorithm: SHA2-256 Capabilities: Curve: P- 224 Hash Algorithm: SHA2-384 Capabilities: Curve: P-256 Hash Algorithm: SHA2-384 Capabilities: Curve: P-384 Hash Algorithm: SHA2-384 Capabilities: Curve: P- 521 Hash Algorithm: SHA2-384 Capabilities: Curve: K-233 Hash Algorithm: SHA2-384 Capabilities: Curve: K-283 Hash Algorithm: SHA2-384 Capabilities: Curve: K- 409 Hash Algorithm: SHA2-384 Capabilities: Curve: K-571 Hash Algorithm: SHA2-384 Capabilities: Curve: B-233 Hash Algorithm: SHA2-384 Capabilities: Curve: B- 283 Hash Algorithm: SHA2-384 Capabilities: Curve: B-409 Hash Algorithm: SHA2-384 Capabilities:
Page 29
NameTypeDescriptionPropertiesAlgorithms
Curve: B-571 Hash Algorithm: SHA2-384 Capabilities: Curve: P- 224 Hash Algorithm: SHA2-512 Capabilities: Curve: P-256 Hash Algorithm: SHA2-512 Capabilities: Curve: P-384 Hash Algorithm: SHA2-512 Capabilities: Curve: P- 521 Hash Algorithm: SHA2-512 Capabilities: Curve: K-233 Hash Algorithm: SHA2-512 Capabilities: Curve: K-283 Hash Algorithm: SHA2-512 Capabilities: Curve: K- 409 Hash Algorithm: SHA2-512 Capabilities: Curve: K-571 Hash Algorithm: SHA2-512 Capabilities: Curve: B-233 Hash Algorithm: SHA2-512 Capabilities: Curve: B- 283 Hash Algorithm: SHA2-512 Capabilities: Curve: B-409 Hash Algorithm: SHA2-512 Capabilities: Curve: B-571 Hash Algorithm: SHA2-512 Capabilities: Curve: P- 224 Hash Algorithm: SHA2- 512/224 Capabilities: Curve: P-256 Hash Algorithm: SHA2-512/224 Capabilities: Curve: P-384 Hash Algorithm: SHA2-512/224 Capabilities: Curve: P-521 Hash Algorithm: SHA2-512/224 Capabilities: Curve: K-233 Hash Algorithm: SHA2-512/224 Capabilities: Curve: K-283 Hash
Page 30
NameTypeDescriptionPropertiesAlgorithms
Algorithm: SHA2-512/224 Capabilities: Curve: K-409 Hash Algorithm: SHA2-512/224 Capabilities: Curve: K-571 Hash Algorithm: SHA2-512/224 Capabilities: Curve: B-233 Hash Algorithm: SHA2-512/224 Capabilities: Curve: B-283 Hash Algorithm: SHA2-512/224 Capabilities: Curve: B-409 Hash Algorithm: SHA2-512/224 Capabilities: Curve: B-571 Hash Algorithm: SHA2-512/224 Capabilities: Curve: P-224 Hash Algorithm: SHA2-512/256 Capabilities: Curve: P-256 Hash Algorithm: SHA2-512/256 Capabilities: Curve: P-384 Hash Algorithm: SHA2-512/256 Capabilities: Curve: P-521 Hash Algorithm: SHA2-512/256 Capabilities: Curve: K-233 Hash Algorithm: SHA2-512/256 Capabilities: Curve: K-283 Hash Algorithm: SHA2-512/256 Capabilities: Curve: K-409 Hash Algorithm: SHA2-512/256 Capabilities: Curve: K-571 Hash Algorithm: SHA2-512/256 Capabilities: Curve: B-233 Hash Algorithm: SHA2-512/256 Capabilities: Curve: B-283 Hash
Page 31
NameTypeDescriptionPropertiesAlgorithms
Algorithm: SHA2-512/256 Capabilities: Curve: B-409 Hash Algorithm: SHA2-512/256 Capabilities: Curve: B-571 Hash Algorithm: SHA2-512/256 RSA SigGen (FIPS186-4): (A5177) Capabilities: Signature Type: PKCS 1.5 Properties: Modulo: 2048 Hash Pair: Hash Algorithm: SHA2-224 Hash Pair: Hash Algorithm: SHA2- 256 Hash Pair: Hash Algorithm: SHA2-384 Hash Pair: Hash Algorithm: SHA2-512 Properties: Modulo: 3072 Hash Pair: Hash Algorithm: SHA2-224 Hash Pair: Hash Algorithm: SHA2-256 Hash Pair: Hash Algorithm: SHA2-384 Hash Pair: Hash Algorithm: SHA2- 512 Properties: Modulo: 4096 Hash Pair: Hash Algorithm: SHA2-224 Hash Pair: Hash Algorithm: SHA2- 256 Hash Pair: Hash Algorithm: SHA2-384 Hash Pair: Hash Algorithm: SHA2-512 Capabilities: Signature Type: PKCSPSS Properties: Modulo: 2048 Hash Pair: Hash Algorithm: SHA2-224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-256 Salt Length: 32 Hash Pair: Hash Algorithm: SHA2-384 Salt Length: 48 Hash Pair: Hash Algorithm: SHA2-512
Page 32
NameTypeDescriptionPropertiesAlgorithms
Salt Length: 64 Hash Pair: Hash Algorithm: SHA2-512/224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-512/256 Salt Length: 32 Properties: Modulo: 3072 Hash Pair: Hash Algorithm: SHA2-224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-256 Salt Length: 32 Hash Pair: Hash Algorithm: SHA2-384 Salt Length: 48 Hash Pair: Hash Algorithm: SHA2-512 Salt Length: 64 Hash Pair: Hash Algorithm: SHA2- 512/224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-512/256 Salt Length: 32 Properties: Modulo: 4096 Hash Pair: Hash Algorithm: SHA2-224 Salt Length: 24 Hash Pair: Hash Algorithm: SHA2-256 Salt Length: 32 Hash Pair: Hash Algorithm: SHA2-384 Salt Length: 48 Hash Pair: Hash Algorithm: SHA2-512 Salt Length: 64 RSA Signature Primitive: (A5177) Private Key Format: crt
RANDDRBGRandom Number GenreationPublication:SP800- 90AHash DRBG: (A5177) Mode: SHA-1, SHA2-256, SHA2- 512 Counter DRBG: (A5177) Mode: AES-128, AES-192, AES- 256 HMAC DRBG: (A5177)
Page 33
NameTypeDescriptionPropertiesAlgorithms
Mode: SHA-1, SHA2-256, SHA2- 512
Sym-KGCKGCryptographic Key GenerationCounter DRBG: (A5177) Mode: AES-128, AES-192, AES- 256 Hash DRBG: (A5177) Mode=: SHA-1, SHA2-256, SHA2- 512 HMAC DRBG: (A5177) Mode: SHA-1, SHA2-256, SHA2- 512 CKG - Symmetric and Asymmetric: ()
KDFKAS-135KDFApplication-Specific Key DerivationPublication:SP800- 135KDF ANS 9.42: (A5177) KDF Type: DER Hash Algorithm: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 KDF ANS 9.63: (A5177) Hash Algorithm: SHA2-224, SHA2-256, SHA2-384, SHA2-512 KDF IKEv2: (A5177) Capabilities: Initiator Nonce Length: 128, 2048 Responder Nonce Length: 128, 2048 Diffie-Hellman Shared Secret Length: 224, 8192 Derived Keying Material Length: 160, 16384 Derived Keying Material Child Length: 160, 16384 Hash Algorithm: SHA-1, SHA2-224,
Page 34
NameTypeDescriptionPropertiesAlgorithms
SHA2-256, SHA2-384, SHA2-512 KDF SSH: (A5177) Cipher: AES-128, AES-192, AES- 256 Hash: SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512 TLS v1.2 KDF RFC7627: (A5177) Hash Algorithm: SHA2-256, SHA2- 384, SHA2-512 TLS v1.3 KDF: (A5177) HMAC Algorithm: SHA2-256, SHA2-384 KDF Running Modes: DHE, PSK, PSK-DHE
KDAKAS-56CKDFKey Derivation Methods in Key Establishment SchemesPublication:SP800- 56Cr2KDA HKDF SP800-56Cr2: (A5177) HMAC Algorithm: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 KDA OneStep SP800-56Cr2: (A5177) Auxiliary Function Name: SHA2- 512, HMAC-SHA2-224, KMAC- 128 KDA TwoStep SP800-56Cr2: (A5177) Capabilities: Fixed Info Pattern: algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding: concatenation KDF Mode: feedback MAC Modes: HMAC-SHA-1, HMAC-SHA2-224,
Page 35
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA2-256, HMAC-SHA2- 384, HMAC-SHA2-512, HMAC- SHA2-512/224, HMAC-SHA2- 512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3- 384, HMAC-SHA3-512 Fixed Data Order: after fixed data Counter Lengths: 8 The KDF supports an empty IV The KDF requires an empty IV Supported Lengths: 2048
KAS-KGKAS-KeyGenKAS Key Generation MethodsPublication:SP800- 56Ar3KAS-ECC-SSC Sp800-56Ar3: (A5177) Domain Parameter Generation Methods: B-233, B-283, B-409, B- 571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 KAS-FFC-SSC Sp800-56Ar3: (A5177) Domain Parameter Generation Methods: FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192 KAS-IFC-SSC: (A5177) Key Generation Methods: rsakpg1- basic, rsakpg1-crt, rsakpg1-prime- factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor
SSCKAS-SSCKey Agreement Shared Secret CalculationIG:IG D.F Scenario 2, path (1)KAS-FFC-SSC Sp800-56Ar3: (A5177) Domain Parameter Generation
Page 36
NameTypeDescriptionPropertiesAlgorithms
Methods: FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192 KAS-ECC-SSC Sp800-56Ar3: (A5177) Curve: Curve: B-233, B-283, B-409, B-571, K-233, K-283, K-409, K- 571, P-224, P-256, P-384, P-521 KAS-IFC-SSC: (A5177) Modulo: 2048, 3072, 4096, 6144, 8192 KAS-ECC CDH-Component SP800-56Ar3: (A5177) Curve: B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521
KBKDFKBKDFKey Based Key DerivationPublication:SP800- 108KDF SP800-108: (A5177) Capabilities: KDF Mode: Counter MAC Mode: CMAC-AES128, CMAC-AES192, CMAC-AES256, HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2- 384, HMAC-SHA2-512 Supported Lengths: 8-4096 Increment 8 Fixed Data Order: Before Fixed Data Counter Length: 32 Custom Key In Length: 0; KDF Mode: Feedback MAC Mode: CMAC-AES128, CMAC-AES192, CMAC-AES256, HMAC-SHA-1, HMAC-SHA2-224,
Page 37
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA2-256, HMAC-SHA2- 384, HMAC-SHA2-512 Supported Lengths: 8-4096 Increment 8 Fixed Data Order: Before Fixed Data Counter Length: 32 Supports Empty IV Requires Empty IV Custom Key In Length: 0
AKP-EAsymKeyPair- EncapAsymmetric Key Pair EncapsulationStandard:SP800- 56Br2 IG D.G.:Approved Key Confirmation:No Caveat:Key establishment methodology provides between 112 and 200 bits of security strengthKTS-IFC: (A5177) Modulo: 2048, 3072, 4096, 6144, 8192
AKP-DAsymKeyPair- DecapAsymmetric Key Pair DecapsulationStandard:SP800- 56Br2 IG D.G.:Approved Key Confirmation:No Caveat:Key establishment methodology provides between 112 and 200 bits of security strengthKTS-IFC: (A5177) Modulo: 2048, 3072, 4096, 6144, 8192
MACMACMessage AuthenticationPublication:FIPS 198, SP800-38B, SP800- 38D, SP800-185AES-CMAC: (A5177) Key Length: 128, 192, 256 AES-GMAC: (A5177) Key Length: 128, 192, 256 HMAC-SHA-1: (A5177)
Page 38
NameTypeDescriptionPropertiesAlgorithms
Key Length: 8-524288 Increment 8 HMAC-SHA2-224: (A5177) Key Length: 8-524288 Increment 8 HMAC-SHA2-256: (A5177) Key Length: 8-524288 Increment 8 HMAC-SHA2-384: (A5177) Key Length: 8-524288 Increment 8 HMAC-SHA2-512: (A5177) Key Length: 8-524288 Increment 8 HMAC-SHA2-512/224: (A5177) Key Length: 8-524288 Increment 8 HMAC-SHA2-512/256: (A5177) Key Length: 8-524288 Increment 8 HMAC-SHA3-224: (A5177) Key Length: 8-524288 Increment 8 HMAC-SHA3-256: (A5177) Key Length: 8-524288 Increment 8 HMAC-SHA3-384: (A5177) Key Length: 8-524288 Increment 8 KMAC-256: (A5177) Key Length: 128-1024 Increment 8 KMAC-128: (A5177) Key Length: 128-1024 Increment 8 HMAC-SHA3-512: (A5177) Key Length: 8-524288 Increment 8
PBKDFPBKDFPassword Based Key DerivationPublication:SP800- 132PBKDF: (A5177) HMAC Algorithm: SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256
SHSSHAMessage DigestPublications:FIPS 180-4, FIPS 202SHA-1: (A5177) Message Length: 0-65536 Increment 8, 160
Page 39
NameTypeDescriptionPropertiesAlgorithms
SHA2-224: (A5177) Message Length: 0-65536 Increment 8, 224 SHA2-256: (A5177) Message Length: 0-65536 Increment 8, 256 SHA2-384: (A5177) Message Length: 0-65536 Increment 8, 384 SHA2-512: (A5177) Message Length: 0-65536 Increment 8, 512 SHA2-512/224: (A5177) Message Length: 0-65536 Increment 8, 224 SHA2-512/256: (A5177) Message Length: 0-65536 Increment 8, 256 SHA3-224: (A5177) Message Length: 0-65536 Increment 8 SHA3-256: (A5177) Message Length: 0-65536 Increment 8 SHA3-384: (A5177) Message Length: 0-65536 Increment 8 SHA3-512: (A5177) Message Length: 0-65536 Increment 8 SHAKE-128: (A5177) Output Length: 16-65536 Increment
Page 40
NameTypeDescriptionPropertiesAlgorithms
8 SHAKE-256: (A5177) Output Length: 16-65536 Increment 8

Table 8: Security Function Implementations

Page 41
2.7 Algorithm Specific Information

Below are the documentation requirements for specific algorithms and conditions, as mandated by Implementation Guidance. FIPS140-3 IG C.H, Option 2: AES GCM IV Uniqueness The IV is generated internally at its entirety randomly. The generation uses an Approved DRBG (Cert. #A5177) that is internal to the module’s boundary. The IV length is fixed at 96 bits (per SP 800-38D). FIPS140-3 IG C.I: XTS-AES Requirements The XTS algorithm implementation includes a check prior to use to ensure Key_1 ≠ Key_2. FIPS 140-3 IG D.N: PBKDF Requirements The module conforms to IG D.N, Option 1a. The password length is 8 – 128 bytes. The password may be selected from a set of 94 characters. So the total combinations for an 8-character password are 94^8. Thus, the probability of guessing the correct password on a random attempt is 1/94^8. The iteration count is 1 - 10,000, as determined by the operator. Keys derived from passwords per SP800-132 may only be used in storage applications. SHA-1 Usage Per SP800-131Ar2, the use of SHA-1 is disallowed for digital signature generation, but is permitted for digital signature verification (legacy use) and all non-digital signature applications. KAS and KTS The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS. The module does not establish SSPs using an approved key transport scheme (KTS). However, it does offer approved authenticated algorithms that can be used by an external operator/application as part of an approved KTS.

2.8 RBG and Entropy
Page 42

The Module uses an entropy source from within the TOEPP, but outside of the cryptographic boundary. The module exercises no control over the source of entropy per IG 9.3.A, Scenario 2B. The size of the entropy provided to the DRBG varies depending on the DRBG mechanism (i.e., HASH, CTR, HMAC) and desired security strength. No assurance of the minimum strength of generated SSPs (e.g., keys). N/A for this module.

2.9 Key Generation

The module generates both symmetric and asymmetric cryptographic keys using the internal DRBG (CAVP Cert. #A5177). The module implements key generation methods according to SP 800-133r2 Section 4, Example 1, without the use of V. The key generation methods are specified in the Vendor Affirmed Algorithms table and the Security Function Implementations table. Additionally, the module implements key derivation methods according to Section 6.2 of SP 800-133r2. The key derivation methods are specified in the Security Function Implementations table.

2.10 Key Establishment

The module does not establish SSPs using an approved key agreement scheme (KAS) or key transport scheme (KTS). However, it does offer some or all of the underlying KAS cryptographic functionality and approved authenticated algorithms that can be used by an external operator/application as part of an approved KAS or KTS. The module supports KAS-ECC-SSC, KAS-FFC-SSC, KAS-IFC-SSC, AES-KW, AES-KWP, and KTS-IFC. KAS-IFC SSC [56Br2] - Per [IG] D.F Scenario 1 path (1), compliant the derivation of a shared secret Z in one of the schemes in Sections 8.2 and 8.3 of SP 800-56Brev2. KAS-SSC [56Ar3] - Per [IG] D.F Scenario 2 path (2), compliant with the derivation of a shared secret Z in one or more of the key agreement schemes in Section 6 of SP 800-56Arev3. Testing is split into (i) testing the computation of the shared secret and (ii) testing the key derivation function used in deriving the keying material comply to IG 2.4.B. KAS-SSC as a service: The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS.

2.11 Industry Protocols
Page 43
Physical PortLogical Interface(s)Data That Passes
N/AControl Inputo API input arguments that are used to initialize and control the operation of the module o API Commands invoking cryptographic services
N/AData Inputo API input arguments that provide input data for processing o Data to be encrypted, decrypted, verified, signed, or hashed o Keys to be used in cryptographic services o Random seed material for Module's DRBG o Keying Material to be used as input to key establishment services
N/AData Outputo API output arguments that return generated or processed data back to the caller o Data that has been encrypted, decrypted, signed, or verified o Hashes o Random Values generated by the module's DRBG o o Keys Established using module's key establishment methods
N/AStatus Outputo API call return values o Status information regarding the module
N/APowerN/A

The module does not implement any Industry Protocols. The module is a cryptographic toolkit that may be used in support for Industry Protocols but does not itself implement the protocol.

3.1 Ports and Interfaces

The Module’s ports and associated FIPS defined logical interface categories are listed below. Table 9: Ports and Interfaces Note: The module does not support Control Output.

4 Roles, Services, and Authentication
Page 44
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Role Based AuthenticationSignature VerificationSigVerRSA 3072-bit has a security strength of 128 bits. The probability of successfully guessing the private key is 1/(2^128).Each authentication attempt takes approximately 0.3 seconds, which results in a maximum of 200 authentication attempts per minute. The probably of a brute force attack being successful within a given minute is 200/(2^128).
NameTypeOperator TypeAuthentication Methods
Cryptographic OfficerRoleCORole Based Authentication
4.2 Roles

The Module supports one distinct operator role, Crypto Officer (CO). One authentication is allowed per Module reset. The Module does not support concurrent operators. The Cryptographic Officer’s authentication public key is protected by the physical and logical design of the module; it is stored as part of the module binary itself. The Roles Table below lists all operator roles supported by the Module. Table 11: Roles

4.3 Approved Services

All approved services implemented by the Module are listed in the table below: The SSPs modes of access shown in the table below are defined as:

G = Generate: The Module generates or derives the SSP.
R = Read: The SSP is read from the Module (e.g., the SSP is output).
W = Write: The SSP is updated, imported, or written to the Module (SSP is input).
E = Execute: The Module uses the SSP in performing a cryptographic operation.
Z = Zeroize: The Module zeroizes the SSP
Page 45
NameDescript ionIndicatorInput sOutputsSecur ity Funct ionsSSP Access
Module Self- TestPerform module initializa tion, pre- operatio nal, and conditio nal cryptogr aphic algorith m self- tests.OSSL_FIPS_PARAM_I NDICATORPowerStatusNoneCryptogr aphic Officer - Software Integrity Key: E - CO Authenti cation Key: E
Show StatusShows module's statusOSSL_FIPS_PARAM_I NDICATORNoneStatusNoneCryptogr aphic Officer
Show VersionShows module's versioni ng informat ionOSSL_FIPS_PARAM_I NDICATORNoneModule Base Name + Module Version NumberNoneCryptogr aphic Officer
Symmetric Encryption/D ecryptionEncrypti on and decrypti on of data.OSSL_FIPS_PARAM_I NDICATORAES Key, Plaint ext or Cipher textPlaintext or Cipherte xtBCU BCACryptogr aphic Officer - AES Key: W,E,Z
Keyed MACCompute a Message Authenti cation CodeOSSL_FIPS_PARAM_I NDICATORMessa ge, HMA C, AES, or KMA C KeyMessage Authenti cation CodeMACCryptogr aphic Officer - AES Key: W,E,Z - MAC Key: W,E,Z
HashCompute a Message DigestOSSL_FIPS_PARAM_I NDICATORMessa geHash ValueSHSCryptogr aphic Officer
Page 46
NameDescript ionIndicatorInput sOutputsSecur ity Funct ionsSSP Access
Random Bit GenerationGenerate random valuesOSSL_FIPS_PARAM_I NDICATORDRB G Selecti onRandom ValuesRAN DCryptogr aphic Officer - DRBG- V: W,E,Z - DRBG- C: W,E,Z - DRBG- Key: W,E,Z - DRBG- EI: G,W,E,Z
Signature GenerationSignatur e Generati onOSSL_FIPS_PARAM_I NDICATOR()=1Privat e Key, Messa geDigital Signatur eSigGe nCryptogr aphic Officer - RSA Private Key: W,E,Z - ECDSA Private Key: W,E,Z
Signature VerificationSignatur e Verificat ionOSSL_FIPS_PARAM_I NDICATORPublic Key, Signat ureStatusSigVe rCryptogr aphic Officer - RSA Public Key: W,E,Z - ECDSA Public Key: W,E,Z
Key GenerationGenerate asymmet ric keysOSSL_FIPS_PARAM_I NDICATORKey Attrib utes,Private Key,AKP- KG AKP-Cryptogr aphic Officer
Page 47
NameDescript ionIndicatorInput sOutputsSecur ity Funct ionsSSP Access
(i.e., RSA, EC)Key SizePublic KeyDP RAN D KAS- KG Sym- KG- DRBG- V: E,Z - RSA Private Key: G,R,Z - RSA Public Key: G,R,Z - ECDSA Private Key: G,R,Z - ECDSA Public Key: G,R,Z - KAS Private Key: G,R,Z - KAS Public Key: G,R,Z - DRBG- C: E,Z - DRBG- Key: E,Z
Key VerificationAsymme tric Key Verificat ionOSSL_FIPS_PARAM_I NDICATORPublic KeyValidityAKP- KV AKV- PKVCryptogr aphic Officer - ECDSA Public Key: W,E,Z - KAS Public
Page 48
NameDescript ionIndicatorInput sOutputsSecur ity Funct ionsSSP Access Key: W,E,Z
Key DerivationDerive keys using SP800- 56Cr2, SP800- 135, SP800- 108, or SP800- 132 key derivatio n methodsOSSL_FIPS_PARAM_I NDICATORKey Materi al, Passp hraseKey MaterialKDF KDA KBK DF PBK DFCryptogr aphic Officer - AES Key: W,E,Z - MAC Key: W,E,Z - Key Material: G,R,W,E ,Z - Passphra se: W,E,Z
Shared Secret CalculationKey agreeme nt using KAS- ECC, KAS- FFC, or KAS- IFCOSSL_FIPS_PARAM_I NDICATORRSA or KAS Public and Privat e KeysKey MaterialSSCCryptogr aphic Officer - Key Material: G,R,Z - RSA Private Key: W,E,Z - RSA Public Key: W,E,Z - KAS Private Key: W,E,Z - KAS Public Key: W,E,Z
Page 49
NameDescript ionIndicatorInput sOutputsSecur ity Funct ionsSSP Access
Key TransportKey transport using AES- KW or KTS- IFCOSSL_FIPS_PARAM_I NDICATORAES Key, RSA KeyWrapped or Encapsul ated KeyBCA AKP- E AKP- DCryptogr aphic Officer - AES Key: W,E,Z - RSA Public Key: W,E,Z - RSA Private Key: W,E,Z
NameDescriptionAlgorithmsRole
Authenticated Symmetric Encryption/DecryptionGCM using externally generated IVsAES (GCM) - Ext IVCO
4.4 Non-Approved Services

All approved services implemented by the Module are listed in the table below: Table 13: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not support an External Software/Firmware Load capability.

5 Software/Firmware Security
5.1 Integrity Techniques

The Module is composed of the following component(s):

Page 50

The software component is protected with the authentication technique, HMAC-SHA2-256, as described in Table 16.

5.2 Initiate on Demand

The operator can initiate the integrity test on demand by power cycling the hardware.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable The Module has a modifiable operational environment under the FIPS 140-3 definitions. The tested operational environments are listed in Section 2.1. The Operating Environment is modifiable and allows the operator to load and execute software. How Requirements are Satisfied : The module supports a modifiable operational environment. The operator may load and execute software that was not included in the original evaluation as the underlying Wave Relay OS 2.2 operational environment is modifiable. Each instance of a cryptographic module controls its own SSPs and are not owned or controlled by external processes/operators. This requirement is not enforced by administrative documentation and procedures but by the cryptographic module itself. The operational environment provides the capability to separate individual application processes from each other in order to prevent uncontrolled access to CSPs and uncontrolled modification of SSPs.

6.2 Configuration Settings and Restrictions

All cryptographic software, SPPs and control/status information is under the control of an operating system that implements mandatory access control. The Operating system protects against unauthorized execution, unauthorized modification, and unauthorized reading of SSPs and status data. Processes that are spawned by the cryptographic module are owned by the module and are not owned by external processes/operators. The Operating System provides an audit mechanism with the date and time of each audited event.

Page 52
Storage Area NameDescriptionPersistence Type
System Memory (S1)Stored in plaintext in volatile memory (RAM).Dynamic
Binary (S2)Stored in plaintext as part of the module binary itself.Static
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Input in plaintext (IO1)Application Software (outside)System Memory (S1)PlaintextManualElectronic
Output in plaintext (IO2)System Memory (S1)Application Software (outside)PlaintextManualElectronic
Input encapsulated (IO3)Application Software (outside)System Memory (S1)EncryptedManualElectronicAKP-D
Output encapsulated (IO4)System Memory (S1)Application Software (outside)EncryptedManualElectronicAKP-E
Input wrapped (IO5)Application Software (outside)System Memory (S1)EncryptedManualElectronicBCA
7 Physical Security

The module is software and as such, physical security requirements do not apply. N/A for this module.

8 Non-Invasive Security

The Module does not implement any mitigation method against non-invasive attack.

9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods
Page 53
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Output wrapped (IO6)System Memory (S1)Application Software (outside)EncryptedManualElectronicBCA
Zeroization MethodDescriptionRationaleOperator Initiation
Z1Zeroisation upon useActive overwriting of SSP values with 0s immediately after SSP is no longer neededAutomatic upon use

Table 15: SSP Input-Output Methods Table 16: SSP Zeroization Methods

Page 54
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
DRBG-EIEntropy Input384 - 768 - 128 to 256 bitsENT - CSPRAND
DRBG-VDRBG internal state value (V for all DRBGs)440 - 888 (Hash_DRBG); 128 (CTR_DRBG); 160- 512 (HMAC_DRBG) - 128 to 256DRBG - CSPRANDAKP- KG RAND Sym- KG KAS- KG
DRBG-CDRBG internal state value (C for HASH_DRBG)440 - 888 (Hash_DRBG); 128 (CTR_DRBG); 160- 512 (HMAC_DRBG) - 128 to 256DRBG - CSPRANDAKP- KG RAND Sym- KG KAS- KG
DRBG-KeyDRBG internal state value (Key for HMAC_DRBG and CTR_DRBG)128 to 256 bits (CTR_DRBG); 160-512 (HMAC_DRBG) - 128 to 256DRBG - CSPRANDAKP- KG RAND Sym- KG KAS- KG
AES KeyUsed for encryption/decryption operations. May also be used for MAC (AES-128, 192, 256 - 128, 192, 256Symmetric - CSPBCU BCA KBKDF MAC
9.4 SSPs

All usage of these SSPs by the Module are described in the services detailed in Section 4.3.

Page 55
NameDescription CMAC, AES-GMAC) or KBKDF.Size - StrengthType - CategoryGenerated ByEstablished ByUsed By
MAC KeyUsed for Message Authentication (HMAC or KMAC)HMAC: 8 to 524288 (Increment 8) (Legacy less than 112) KMAC: 128- 1024 (increment 8) - 128 to 512MAC - CSPKDF KDA KBKDF MAC PBKDF
RSA Private KeySignature Generation, KTS-IFC, KAS-IFC2048, 3072, 4096, 6144 (KAS-IFC and KTS-IFC only), 8192 (KAS-IFC and KTS-IFC only) - 112-150Asymmetric - CSPAKP-KGSigGen SSC AKP-D
RSA Public KeyUsed for signature verification, KTS-IFC, KAS-IFC1024 (Legacy), 2048, 3072, 4096, 6144 (KAS-IFC and KTS-IFC only), 8192 (KAS-IFC and KTS-IFC only) - 112-150 (Legacy >112)Asymmetric - PSPAKP-KGSigVer SSC AKP-E
CO Authentication KeyUsed for authenticating the CO3072 - 128Asymmetric - PSPAt manufacturingSigVer
Software Integrity KeyUsed for Module Integrity256 - 256MAC - NeitherAt manufacturingMAC
ECDSA Private KeyUsed for signature generationB-233, B-283, B-409, B- 571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 - 112-256Asymmetric - CSPAKP-KGSigGen
ECDSA Public KeyUsed for signature verificationB-163, B-233, B-283, B- 409, B-571, K-163, K-233, K-283, K-409, K-571, P- 192, P-224, P-256, P-384,Asymmetric - PSPAKP-KGSigVer
Page 56
NameDescriptionSize - Strength P-521 - 112-256 (Legacy >112)Type - CategoryGenerated ByEstablished ByUsed By
KAS Private KeyUsed for key agreement (FFC and ECC)ECC: B-233, B-283, B-409, B-571, K-233, K-283, K- 409, K-571, P-224, P-256, P-384, P-521; FFC: ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 - 112-256Asymmetric - CSPKAS-KGSSC
KAS Public KeyUsed for key agreement (FFC and ECC)ECC: B-233, B-283, B-409, B-571, K-233, K-283, K- 409, K-571, P-224, P-256, P-384, P-521; FFC: ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 - 112-256Asymmetric - PSPKAS-KGSSC
PassphrasePassphrase to be used with PBKDF264-1024 - N/APBKDF2 - CSPPBKDF
Key MaterialMay be intended for or the result of SSC, KDA, KDF, or KTSVaries - 128 to 256Key Material - CSPSSC
Page 57
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
DRBG-EIInput in plaintext (IO1)System Memory (S1):PlaintextUntil use completesZ1DRBG-V:Used to derive DRBG-C:Used to derive DRBG-Key:Used to derive
DRBG-VSystem Memory (S1):PlaintextUntil use completesZ1DRBG-EI:Derived From DRBG-C:Used With DRBG-Key:Used With
DRBG-CSystem Memory (S1):PlaintextUntil use completesZ1DRBG-EI:Derived From DRBG-V:Used With
DRBG-KeySystem Memory (S1):PlaintextUntil use completesZ1DRBG-EI:Derived From DRBG-V:Used With
AES KeyInput in plaintext (IO1) Output in plaintext (IO2)System Memory (S1):PlaintextUntil use completesZ1
MAC KeyInput in plaintext (IO1) Output in plaintext (IO2)System Memory (S1):PlaintextUntil use completesZ1
RSA Private KeyInput in plaintext (IO1) Output in plaintext (IO2)System Memory (S1):PlaintextUntil use completesZ1RSA Public Key:Paired With
RSA Public KeyInput in plaintext (IO1) Output in plaintext (IO2)System Memory (S1):PlaintextUntil use completesZ1RSA Private Key:Paired With
CO Authentication KeyBinary (S2):Plaintext System Memory (S1):PlaintextUntil use completesZ1Software Integrity Key:Protected by
Page 58
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Software Integrity KeyBinary (S2):Plaintext System Memory (S1):PlaintextUntil use completesZ1
ECDSA Private KeyInput in plaintext (IO1) Output in plaintext (IO2)System Memory (S1):PlaintextUntil use completesZ1
ECDSA Public KeyInput in plaintext (IO1) Output in plaintext (IO2)System Memory (S1):PlaintextUntil use completesZ1ECDSA Private Key:Paired With
KAS Private KeyInput in plaintext (IO1) Output in plaintext (IO2)System Memory (S1):PlaintextUntil use completesZ1KAS Public Key:Paired With DRBG-State:Generated with Key Material:Establishes
KAS Public KeyInput in plaintext (IO1) Output in plaintext (IO2)System Memory (S1):PlaintextUntil use completesZ1KAS Private Key:Paired With DRBG-State:Generated with Key Material:Establishes
PassphraseInput in plaintext (IO1)System Memory (S1):PlaintextUntil use completesZ1Key Material:Derives
Key MaterialInput in plaintext (IO1) Output in plaintext (IO2) Input encapsulated (IO3) Output encapsulated (IO4) Input wrapped (IO5)System Memory (S1):PlaintextUntil use completesZ1Passphrase:Derived From RSA Private Key:Derived From RSA Public Key:Derived From KAS Private Key:Derived From KAS Public Key:Derived From
Page 59

Name

Input - Output Output wrapped (IO6)

Storage

Storage Duration

Zeroization

Related SSPs AES Key:Derived From MAC Key:Derived From

Page 61
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Software Integrity TestHMAC SHA2- 256KATSW/FW Integrityverify_integrity_success or verify_integrity failureHMAC-SHA2-256 Verify
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM EncryptKey size: 256 bitsKATCASTSELF_TEST_post success SELF_TEST_post failureEncryptPower-On
10 Self-Tests
10.1 Pre-Operational Self-Tests

The Module performs self-tests to ensure the proper operation of the Module. Per FIPS 140-3 these are categorized as either pre-operational self-tests or conditional self-tests. Pre-operational self–tests are available on demand by power cycling the Module. The operator may invoke periodic self-tests by power cycling the module. It is recommended that periodic self-testing be performed weekly. Please note that HMAC-SHA2-256 is self-tested prior to execution of the Software Integrity Test. The Module performs the following pre-operational self-tests in table below. Table 19: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

The Module performs the following conditional self-tests in the table below.

Page 62
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM DecryptKey size: 256 bitsKATCASTSELF_TEST_post success SELF_TEST_post failureDecryptPower-On
AES-ECB (A5177)Key size: 128 bitsKATCASTSELF_TEST_post success SELF_TEST_post failureDecryptPower-On
Counter DRBG (A5177)Key size: 128KATCASTSELF_TEST_post success SELF_TEST_post failureinstantiation, generate, and reseedPower-On
Hash DRBG (A5177)SHA2-256KATCASTSELF_TEST_post success SELF_TEST_post failureinstantiation, generate, and reseedPower-On
HMAC DRBG (A5177)SHA1KATCASTSELF_TEST_post success SELF_TEST_post failureinstantiation, generate, and reseedPower-On
HMAC- SHA2-256 (A5177)SHA2-256 with 256-bit keyKATCASTSELF_TEST_post success SELF_TEST_post failureGenerate/VerifyPower-On
KMAC-256 (A5177)KMAC-256 with 384-bit keyKATCASTSELF_TEST_post success SELF_TEST_post failureGenerate/VerifyPower-On
RSA SigGen (FIPS186-4) (A5177)PKCS#1, SHA2- 256 with 2048-bit keyKATCASTSELF_TEST_post success SELF_TEST_post failureSignature GenerationPower-On
RSA SigVer (FIPS186-4) (A5177)PKCS#1, SHA2- 256 with 2048-bit keyKATCASTSELF_TEST_post success SELF_TEST_post failureSignature VerificationPower-On
RSA KeyGen (FIPS186-4) (A5177)Key GenerationPCTPCTOSSL_PROV_PARAM_STATUS = 1 (ok) OSSL_PROV_PARAM_STATUS = 0 (error)Encrypt/DecryptUpon key generation
SHA-1 (A5177)SHA-1KATCASTSELF_TEST_post success SELF_TEST_post failureGenerate/VerifyPower-On
SHA2-512 (A5177)SHA2-512KATCASTSELF_TEST_post success SELF_TEST_post failureGenerate/VerifyPower-On
Page 63
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA3-256 (A5177)SHA3-256KATCASTSELF_TEST_post success SELF_TEST_post failureGenerate/VerifyPower-On
ECDSA SigGen (FIPS186-4) (A5177)P-224, B-233 with SHA2-256KATCASTSELF_TEST_post success SELF_TEST_post failureSignature GenerationPower-On
ECDSA SigVer (FIPS186-4) (A5177)P-224, B-233 with SHA2-256KATCASTSELF_TEST_post success SELF_TEST_post failureSignature VerificationPower-On
KAS-ECC- SSC Sp800- 56Ar3 (A5177)P-256KATCASTSELF_TEST_post success SELF_TEST_post failureShared Secret CalculationPower-On
KAS-FFC- SSC Sp800- 56Ar3 (A5177)ffdhe2048KATCASTSELF_TEST_post success SELF_TEST_post failureShared Secret CalculationPower-On
Safe Primes Key Generation (A5177)Key GenerationPCTPCTOSSL_PROV_PARAM_STATUS = 1 (ok) OSSL_PROV_PARAM_STATUS = 0 (error)SP800-56Ar3 PCTUpon key generation
ECDSA KeyGen (FIPS186-4) (A5177)Key GenerationPCTPCTOSSL_PROV_PARAM_STATUS = 1 (ok) OSSL_PROV_PARAM_STATUS = 0 (error)Sign/VerifyUpon key generation
TLS v1.2 KDF RFC7627 (A5177)SHA2-256 with 384-bit secretKATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
Page 64
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
TLS v1.3 KDF (A5177)SHA2-256 with 256-bit KeyKATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
PBKDF (A5177)HMAC SHA2- 256 with 24 character passphraseKATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
KTS-IFC (A5177)2048-bit KeyKATCASTSELF_TEST_post success SELF_TEST_post failureEncrypt/DecryptPower-On
KDF SSH (A5177)SHA-1 with 1056- bitsKATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
KDF SP800- 108 (A5177)HMAC SHA2- 256, Counter Mode, 128-bit. CMAC AES-128, Counter Mode, 128-bitKATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
KDF IKEv2 (A5177)SHA-1, 192-bit secret, 160-bit skeyseedKATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
KDF ANS 9.63 (A5177)SHA2-256, 192- bit secretKATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
KDF ANS 9.42 (A5177)SHA-1, 160-bit secretKATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
KDA HKDF SP800-56Cr2 (A5177)HMAC SHA2- 256KATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
KDA OneStep SP800-56Cr2 (A5177)HMAC SHA2- 224 with 448-bit secretKATCASTSELF_TEST_post success SELF_TEST_post failureKey DerivationPower-On
Page 65
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Software Integrity TestKATSW/FW IntegrityOn DemandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM EncryptKATCASTOn DemandManually
AES-GCM DecryptKATCASTOn DemandManually
AES-ECB (A5177)KATCASTOn DemandManually
Counter DRBG (A5177)KATCASTOn DemandManually
Hash DRBG (A5177)KATCASTOn DemandManually
HMAC DRBG (A5177)KATCASTOn DemandManually
HMAC-SHA2-256 (A5177)KATCASTOn DemandManually
KMAC-256 (A5177)KATCASTOn DemandManually
RSA SigGen (FIPS186- 4) (A5177)KATCASTOn DemandManually
RSA SigVer (FIPS186- 4) (A5177)KATCASTOn DemandManually
RSA KeyGen (FIPS186-4) (A5177)PCTPCTOn DemandManually
SHA-1 (A5177)KATCASTOn DemandManually
SHA2-512 (A5177)KATCASTOn DemandManually

Table 20: Conditional Self-Tests

10.3 Periodic Self-Test Information

Table 21: Pre-Operational Periodic Information

Page 66
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA3-256 (A5177)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A5177)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A5177)KATCASTOn DemandManually
KAS-ECC-SSC Sp800- 56Ar3 (A5177)KATCASTOn DemandManually
KAS-FFC-SSC Sp800- 56Ar3 (A5177)KATCASTOn DemandManually
Safe Primes Key Generation (A5177)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A5177)PCTPCTOn DemandManually
TLS v1.2 KDF RFC7627 (A5177)KATCASTOn DemandManually
TLS v1.3 KDF (A5177)KATCASTOn DemandManually
PBKDF (A5177)KATCASTOn DemandManually
KTS-IFC (A5177)KATCASTOn DemandManually
KDF SSH (A5177)KATCASTOn DemandManually
KDF SP800-108 (A5177)KATCASTOn DemandManually
KDF IKEv2 (A5177)KATCASTOn DemandManually
KDF ANS 9.63 (A5177)KATCASTOn DemandManually
KDF ANS 9.42 (A5177)KATCASTOn DemandManually
KDA HKDF SP800- 56Cr2 (A5177)KATCASTOn DemandManually
KDA OneStep SP800- 56Cr2 (A5177)KATCASTOn DemandManually

Table 22: Conditional Periodic Information The operator may invoke periodic self-tests by power cycling the module. It is recommended that periodic self-testing be performed weekly.

Page 67
NameDescriptionConditionsRecovery MethodIndicator
ES1The module fails pre-operational self-tests, conditional self- tests, or authentication.The Module enters the error statePower cycle the moduleOSSL_PROV_PARAM_STATUS = 0
10.4 Error States
10.5 Operator Initiation of Self-Tests

Self-tests may be initiated on demand by power cycling the module.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

No end user action is required to startup the module in an approved mode for operation. The module is built into the Wave Relay® OS and delivered in Persistent Systems’ Wave Relay® Solutions. There is no standalone delivery of the module as a software hybrid module. Persistent Systems’ internal development process guarantees that the correct version of the module is installed within its intended device OS version. Installation and Initialization: The module is pre-installed within the Persistent Systems Solutions, which include the MPU5, Embedded Module, Embedded Module lite, GVR5, or Integrated Antenna Series. No further initialization of the module is required. Upon powering on the hardware platform, the module will automatically perform pre-operational and conditional self-tests in accordance with FIPS 140-3 requirements. Delivery: The module is pre-installed within the Persistent Systems product offerings. The Persistent Systems products are distributed using a trusted courier and packaging must be inspected upon delivery.

11.2 Administrator Guidance
Page 68

There are no specific management activities required of the Crypto Officer Role to ensure that the module runs securely. However, if any irregular activity is noticed or the module is consistently reporting errors, then Persistent Systems Support should be contacted.

11.3 Non-Administrator Guidance

There are no specific management activities required of the Crypto Officer Role to ensure that the module runs securely. However, if any irregular activity is noticed or the module is consistently reporting errors, then Persistent Systems Support should be contacted.

11.4 Design and Rules

Rules of Operation

  1. The Module provides one distinct operator roles: Cryptographic Officer.
  2. The Module provides identity-based authentication.
  3. The Module clears previous authentications on power cycle.
  4. An operator does not have access to any cryptographic services prior to assuming an authorized role.
  5. The Module allows the operator to initiate power-up self-tests by power cycling the Module.
  6. All self-tests do not require any operator action.
  7. Data output is inhibited during self-tests, zeroization, and error states.
  8. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module.
  9. There are no restrictions on which keys or SSPs are zeroized after use.
  10. The Module does not support concurrent operators.
  11. The Module does not support a maintenance interface or role.
  12. The Module does not support manual SSP establishment method.
  13. The Module does not have any proprietary external input/output devices used for entry/output of data.
  14. The Module does not store any plaintext CSPs.
  15. The Module does not output intermediate key values.
  16. The Module does not provide bypass services for ports/interfaces.
11.6 End of Life

The module must be zeroized and returned to the manufacturer.

12 Mitigation of Other Attacks

The Module does not implement any mitigation method against other attacks.

Page 70

References and Definitions The following standards are referred to in this Security Policy. Table 24