All modules
CMVP Validated Module · FIPS 140-3 Security Policy

AMD ASP Cryptographic CoProcessor ("Turin")

Certificate#5085StandardFIPS 140-3Level1TypeHardwareEmbodimentSingle ChipStatusActiveVendorAdvanced Micro Devices (AMD)
Medium review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 9 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date10/21/2030
CaveatWhen operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorAdvanced Micro Devices (AMD)

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for AMD ASP Cryptographic CoProcessor ("Turin")
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for AMD ASP Cryptographic CoProcessor ("Turin")
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Advanced Micro Devices (AMD) AMD ASP Cryptographic CoProcessor ("Turin") Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 Document version: 1.1 www.atsec.com Last update: 2025-10-08

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 Advanced Micro Devices (AMD), atsec information security.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware8
Table 3: Modes List and Description8
Table 4: Approved Algorithms10
Table 5: Vendor-Affirmed Algorithms10
Table 6: Non-Approved, Allowed Algorithms with No Security Claimed10
Table 7: Non-Approved, Not Allowed Algorithms11
Table 8: Security Function Implementations13
Table 9: Entropy Certificates14
Table 10: Entropy Sources14
Table 11: Ports and Interfaces16
Table 12: Roles17
Table 13: Approved Services25
Table 14: Non-Approved Services27
Table 15: Mechanisms and Actions Required30
Table 16: Storage Areas32
Table 17: SSP Input-Output Methods32
Table 18: SSP Zeroization Methods33
Table 19: SSP Table 135
Table 20: SSP Table 237
Table 21: Pre-Operational Self-Tests38
Table 22: Conditional Self-Tests41
Table 23: Pre-Operational Periodic Information41
Table 24: Conditional Periodic Information42
Table 25: Error States43
Figure 1: AMD EPYC 9B45 SoC7
Figure 2: Block Diagram7
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security3
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for the AMD ASP Cryptographic CoProcessor ("Turin") cryptographic module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) intact and including this notice.

1.2 Security Levels

Table 1: Security Levels © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The AMD ASP Cryptographic CoProcessor ("Turin") cryptographic module (hereafter referred to as “the module”) is defined as a sub-chip hardware module in a single chip embodiment, with hardware and firmware components implementing general purpose cryptographic algorithms. Module Type: Hardware Module Embodiment: SingleChip Module Characteristics: SubChip Cryptographic Boundary: The module consists primarily of the ARM Cortex-A5, Random Bit Generation hardware, Security Infrastructure Block, Cryptographic CoProcessor, and OTP fuses. These hardware components are sub-components of the “IOD” (EPYC EIOD2.0), which itself is a smaller die in the larger single chip embodiment, the EPYC SoC. OTP fuses are used to persistently store FIPS support enablement and versioning information, security state information, and Entropy Source configuration values (sample rate, sample count, RCT and APT cutoffs). In addition, there is a ROM firmware component (“libROM”) permanently stored inside the EPYC SoC, and an overlay firmware component (“overlay firmware”) permanently stored inside SPI flash storage, outside the EPYC SoC, which is loaded into the IOD SRAM on startup. The block diagram in Figure 2 shows the design of the module when the module is operational and the firmware components are loaded into the SRAM. In this diagram, the physical boundary of the module, defined by the perimeter of the EPYC SoC (i.e., the enclosure of the SoC), is indicated by a dashed purple line. The cryptographic boundary is represented by the components painted in orange blocks. Solid orange lines indicate the flow of data within the cryptographic module (i.e., internal paths). Dashed green lines are used to denote the logical interfaces defined in Section 3. Components in white are only included in the diagram for informational purposes. They are not included in the cryptographic boundary (and therefore not part of the module’s validation). Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP is the EPYC SoC (shown in Figure 1), a rectangular enclosure measuring approximately 72 mm x 75.4 mm x 5.30 mm. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 7

Figure 1: AMD EPYC 9B45 SoC Figure 2: Block Diagram © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 8
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
AMD EPYC 9B45 containing EPYC EIOD2.0C1-1-3D0A003D0306ARM Cortex- A5N/A
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service (FipsIndicatorStatus is set to 2)
Non- approved modeAutomatically entered whenever a non-approved service is requestedNon- ApprovedEquivalent to the indicator of the requested service (FipsIndicatorStatus is not set to 2)
AlgorithmCAVP CertPropertiesReference
AES-CBCA5794Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA5794Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA5794Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5794Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
2.2 Tested and Vendor Affirmed Module Version and

Identification Tested Module Identification

2.3 Excluded Components

There are no components excluded from the requirements of the FIPS 140-3 standard.

2.4 Modes of Operation

Modes List and Description: Table 3: Modes List and Description After passing all pre-operational self-tests and conditional self-tests executed on startup, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. In the operational state, the module accepts service requests from calling applications through its logical interfaces. The operator can verify that the module is operational by requesting the RL_ARCL_GetState service and comparing the returned ArclState value with 4. The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. The status indicator of the mode of

2.5 Algorithms

Approved Algorithms: © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 9
AlgorithmCAVP CertPropertiesReference
AES-ECBA5795Direction - Encrypt Key Length - 256SP 800-38A
Conditioning Component AES-CBC- MAC SP800-90BA5337Key Length - 256SP 800-90B
Counter DRBGA5795Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A5794Curve - P-384 Secret Generation Mode - extra bitsFIPS 186-5
ECDSA SigGen (FIPS186-5)A5794Curve - P-384 Hash Algorithm - SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A5794Component - No Curve - P-384 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A5794Curve - P-384 Hash Algorithm - SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-5
HMAC-SHA-1A5794Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5794Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5794Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5794Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5794Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A5794Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A5794Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A5794Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A5794Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KDF SP800-108A5794KDF Mode - Counter Supported Lengths - Supported Lengths: 112-4096 Increment 8SP 800-108 Rev. 1
RSA KeyGen (FIPS186- 5)A5794Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5

© 2025 Advanced Micro Devices (AMD), atsec information security.

Page 10
AlgorithmCAVP CertPropertiesReference
RSA SigGen (FIPS186- 5)A5794Modulo - 2048, 3072, 4096 Signature Type - pssFIPS 186-5
RSA SigVer (FIPS186-2)A5794Signature Type - PKCSPSS Modulo - 1536FIPS 186-4
RSA SigVer (FIPS186-4)A5794Signature Type - PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-5)A5794Modulo - 2048, 3072, 4096 Signature Type - pssFIPS 186-5
SHA-1A5794Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-224A5794Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-256A5794Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-384A5794Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-512A5794Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA3-224A5794Message Length - Message Length: 0- 65536 Increment 8FIPS 202
SHA3-256A5794Message Length - Message Length: 0- 65536 Increment 8FIPS 202
SHA3-384A5794Message Length - Message Length: 0- 65536 Increment 8FIPS 202
SHA3-512A5794Message Length - Message Length: 0- 65536 Increment 8FIPS 202
SHAKE-128A5794Output Length - Output Length: 1344FIPS 202
SHAKE-256A5794Output Length - Output Length: 1088FIPS 202
NamePropertiesImplementationReference
CKG (asymmetric)Key Type:AsymmetricN/ASP 800-133r2, Section 4, example 1
NameCaveatUse and Function
RTL key de- obfuscationWhen used to de-obfuscate data using the weak RTL keyDe- obfuscation

Table 4: Approved Algorithms Vendor-Affirmed Algorithms: Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: Table 6: Non-Approved, Allowed Algorithms with No Security Claimed Non-Approved, Not Allowed Algorithms: © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 11
NameUse and Function
HMAC with key lengths less than 112 bitsMessage authentication
Deterministic ECDSA key pair generationKey pair generation
Deterministic RSA key pair generationKey pair generation
ECDSA (pre-hashed message)Signature generation, Signature verification
ECDSA with SHA-1Signature generation
RSA with 1024 or 1536 bits modulusKey pair generation, Signature generation
RSA (pre-hashed message)Signature generation, Signature verification
RSA with SHA-1Signature generation
SHA-384 with non- standard initial hash valuePCR-based memory measurement
CCP_HAL algorithmMessage digest (SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA3-224, SHA3-256, SHA3-384, SHA3-512), XOF (SHAKE128, SHAKE256), encryption, decryption (AES ECB, CBC, OFB, CFB, CTR, GCTR, IAPM, XTS), message authentication (AES CMAC)
SIB_HAL algorithmRandom number generation
NameTypeDescriptionPropertiesAlgorithms
EncryptionBC-UnAuthEncrypt a plaintextAES-CBC: (A5794) AES-CTR: (A5794) AES-ECB: (A5794)
DecryptionBC-UnAuthDecrypt a ciphertextAES-CBC: (A5794) AES-CTR: (A5794) AES-ECB: (A5794)
Message digestSHACompute a message digestSHA-1: (A5794) SHA2-224: (A5794) SHA2-256: (A5794) SHA2-384: (A5794) SHA2-512:

Table 7: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© 2025 Advanced Micro Devices (AMD), atsec information security.

Page 12
NameTypeDescriptionPropertiesAlgorithms
(A5794) SHA3-224: (A5794) SHA3-256: (A5794) SHA3-384: (A5794) SHA3-512: (A5794)
XOFXOFCompute an extendable output message digestSHAKE-128: (A5794) SHAKE-256: (A5794)
MACMACCompute a MAC tagAES-CMAC: (A5794) HMAC-SHA-1: (A5794) HMAC-SHA2- 224: (A5794) HMAC-SHA2- 256: (A5794) HMAC-SHA2- 384: (A5794) HMAC-SHA2- 512: (A5794) HMAC-SHA3- 224: (A5794) HMAC-SHA3- 256: (A5794) HMAC-SHA3- 384: (A5794) HMAC-SHA3- 512: (A5794)
Random number generationDRBGGenerate random bytesConditioning Component AES-CBC-MAC SP800-90B: (A5337) AES-ECB: (A5795) Counter DRBG: (A5795)
Key derivationKBKDFDerive a key from a key derivation keyKDF SP800-108: (A5794)
Key pair generationAsymKeyPair- KeyGen CKGGenerate a key pairECDSA KeyGen (FIPS186-5): (A5794) RSA KeyGen (FIPS186-5): (A5794)

© 2025 Advanced Micro Devices (AMD), atsec information security.

Page 13
NameTypeDescriptionPropertiesAlgorithms
CKG (asymmetric): ()
Signature generationDigSig-SigGenGenerate a digital signatureECDSA SigGen (FIPS186-5): (A5794) RSA SigGen (FIPS186-5): (A5794)
Signature verificationDigSig-SigVerVerify a digital signatureECDSA SigVer (FIPS186-5): (A5794) RSA SigVer (FIPS186-5): (A5794)
Signature verification (Legacy)DigSig-SigVerVerify a digital signaturePublications:FIPS 140-3 IG C.M legacy algorithms RSA Key:1024 or 1536 bit modulus; 2048, 3072, 4096 bit modulus with SHA-1 ECDSA Key:P- 384 with SHA-1RSA SigVer (FIPS186-4): (A5794) RSA SigVer (FIPS186-2): (A5794) ECDSA SigVer (FIPS186-4): (A5794)

Table 8: Security Function Implementations

2.7 Algorithm Specific Information

Digital signature generation using SHA-1 is non-approved and not allowed in approved services. For RSA key pair generation, signature generation, and signature verification, the module supports modulus sizes 2048, 3072, and 4096 bits. Additionally, the module supports a modulus size of 1024 and 1536 bits for RSA signature verification. All supported modulus sizes have been CAVP tested. Legacy use and FIPS 186-5: In compliance with FIPS 140-3 IG C.K, the digital signature algorithm implementations have been CAVP tested against FIPS 186-5 where possible. FIPS 186-2 CAVP testing was performed for RSA signature verification with a 1536-bit modulus. FIPS 186-4 CAVP testing was performed for digital signature verification using SHA-1 and RSA only. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 14
Cert NumberVendor Name
E173Advanced Micro Devices (AMD)
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
AMD TRNG Entropy SourcePhysicalEPYC EIOD2.0128AES-CBC-MAC (A5337)
2.8 RBG and Entropy

Table 9: Entropy Certificates Table 10: Entropy Sources The module provides an SP800-90Ar1-compliant Deterministic Random Bit Generator (DRBG) using CTR_DRBG mechanism with AES-256 for generation of key components of asymmetric keys, and random number generation. The module complies with the Public Use Document for ESV certificate E173 by reading entropy data from the 2048-bit FIFO, which corresponds to the GetEntropy() function. This function outputs 128 bits of entropy. The module constructs the 384-bit entropy input for the DRBG by requesting GetEntropy() three times and concatenating the result. The DRBG does not employ a derivation function, does not support a personalization string, and does not support additional input. Consequently, the 384-bit entropy input is used directly as the DRBG seed, for both seeding and reseeding. The operational environment on the ESV certificate is identical to the IOD in the EPYC SoC, in which the sub-chip components are contained. Thus, the module is compliant with scenario 1 of IG 9.3.A. There are no maintenance requirements for the entropy source.

2.9 Key Generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800-133r2. When random values are required, they are obtained from the SP 800 90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2. The following methods are implemented:

256 PRF and a 32-bit counter. This implementation can be used to derive secret keys when

provided with a pre-existing key-derivation key. The resulting SSPs can be stored by the module in the Key Storage Block (if specified by the operator) or output as an API output parameter. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 15
2.10 Key Establishment

The module does not implement any automated key establishment methods.

2.11 Industry Protocols

The module does not implement any industry protocol. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 16
Physical PortLogical Interface(s)Data That Passes
SRAMData InputAPI input parameters for data.
SRAMData OutputAPI output parameters for data.
SRAMControl InputAPI function calls, API input parameters for control.
SRAMStatus OutputAPI return codes, status values.
Power portPowerPower port or pin on the SoC.
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces The logical interfaces are logically separated from each other by the API design. The module does not implement a control output interface. The power interface is physically separated from any other interface. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 17
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescript ionIndicatorInputsOutputsSecu rity Func tionsSSP Acces s
RL_ARCL_ShaGenerate a (extenda ble output) message digestFipsIndica torStatus is set to 2Message, output length (XOF)Message digestMess age digest XOFCrypto Officer
RL_ARCL_AesPerform an AES operation (encrypt/ decrypt)FipsIndica torStatus is set to 2Plaintext/ci phertext, AES key, IV (if applicable)Plaintext/c iphertextEncry ption Decry ptionCrypto Officer - AES key: W,E
RL_ARCL_MacGenerate a MAC tagFipsIndica torStatus is set to 2Message, AES/HMAC keyMAC tagMACCrypto Officer - AES key: W,E - HMAC key: W,E
RL_ARCL_EcdsaGener ateKeyPairGenerate an ECDSA key pairFipsIndica torStatus is set to 2CurveECDSA key pairKey pair gener ationCrypto Officer - ECDSA private key: G,R - ECDSA public
4 Roles, Services, and Authentication

The module does not implement any authentication methods.

4.2 Roles

Table 12: Roles No support is provided for multiple concurrent operators.

4.3 Approved Services

W,E W,E G,R © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 18
NameDescript ionIndicatorInputsOutputsSecu rity Func tionsSSP Acces s key: G,R - Interm ediate key genera tion value: G,E,Z
RL_ARCL_RsaGenerat eKeyPairGenerate an RSA key pairFipsIndica torStatus is set to 2Modulus sizeRSA key pairKey pair gener ationCrypto Officer - RSA private key: G,R - ECDSA public key: G,R - Interm ediate key genera tion value: G,E,Z
RL_ARCL_SignSign a messageFipsIndica torStatus is set to 2Message, hash algorithm, private keySignatureSigna ture gener ationCrypto Officer - ECDSA private key: W,E - RSA private key: W,E
RL_ARCL_VerifyVerify a message signatureFipsIndica torStatus is set to 2Message, hash algorithm, signature, public keyPass/failSigna ture verific ation Signa ture verific ationCrypto Officer - ECDSA public key: W,E - RSA public

G,R G,E,Z G,R G,R G,E,Z W,E W,E © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 19
NameDescript ionIndicatorInputsOutputsSecu rity Func tionsSSP Acces s
(Lega cy)key: W,E
RL_ARCL_X509CertCr eateCreate and sign an X.509 certificat eFipsIndica torStatus is set to 2X.509 informatio n, hash algorithm, private keySigned X.509 certificateSigna ture gener ationCrypto Officer - ECDSA private key: W,E
RL_ARCL_DeriveKeyU singPRFDerive a key using SP 800- 108r1 KDFFipsIndica torStatus is set to 2Key- derivation- key, derived key lengthDerived keyKey deriv ationCrypto Officer - Key- derivat ion key: W,E - Derive d key: G,R
RL_ARCL_GenerateRa ndomGenerate random bytesFipsIndica torStatus is set to 2Output lengthRandom bytesRand om numb er gener ationCrypto Officer - Entrop y input: G,E,Z - DRBG seed: G,E,Z - Intern al state (V, Key): W,E
RL_ARCL_FwImageLo adValidateWithKeyVerify the signature of a firmware image using a provided keyFipsIndica torStatus is set to 2Firmware image, public keyPass/failSigna ture verific ation Signa ture verific ation (Lega cy)Crypto Officer - RSA public key: W,E

W,E W,E G,R G,E,Z G,E,Z (V, W,E © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 20
NameDescript ionIndicatorInputsOutputsSecu rity Func tionsSSP Acces s
RL_ARCL_FwImageLo adValidateVerify the signature of a firmware image using an embedde d keyFipsIndica torStatus is set to 2Firmware imagePass/failSigna ture verific ation Signa ture verific ation (Lega cy)Crypto Officer - RSA public key: W,E
RL_ARCL_KeyDbInstal lVerify the signature of a key database image using an embedde d keyFipsIndica torStatus is set to 2Key database imagePass/failSigna ture verific ation Signa ture verific ation (Lega cy)Crypto Officer - RSA public key: W,E
RL_ARCL_KeyImageV alidateVerify the signature of a key image using an embedde d keyFipsIndica torStatus is set to 2Key imagePass/failSigna ture verific ation Signa ture verific ation (Lega cy)Crypto Officer - RSA public key: W,E
RL_ARCL_SelfTestPerform on- demand self-testsFipsIndica torStatus is set to 2NonePass/failNoneCrypto Officer
RL_ARCL_RtlDeobfusc ateDe- obfuscat e some data using the RTL keyFipsIndica torStatus is set to 2Obfuscate d input dataDe- obfuscate d output dataNoneCrypto Officer
RL_ARCL_ReconfigUpdate the ASP register base addressNoneRegister base addressNoneNoneCrypto Officer
RL_ARCL_GetState (Show Status / Show Version)Show the module status,NoneNoneModule status, version,NoneCrypto Officer

© 2025 Advanced Micro Devices (AMD), atsec information security.

Page 21
NameDescript ion version, and service indicatorIndicatorInputsOutputs service indicatorSecu rity Func tionsSSP Acces s
RL_ARCL_ScrapZeroize the KSB and prepare the module for end- of-lifeNoneNoneNoneCrypto Officer - AES key: Z - HMAC key: Z - Key- derivat ion key: Z - Derive d key: Z - ECDSA private key: Z - ECDSA public key: Z - RSA private key: Z - RSA public key: Z
RL_ARCL_ShutdownZeroize the KSB and shut down the moduleNoneNoneNoneCrypto Officer - AES key: Z - HMAC key: Z - Key- derivat ion key: Z - Derive d key: Z -

Z Z © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 22
NameDescript ionIndicatorInputsOutputsSecu rity Func tionsSSP Acces s ECDSA private key: Z - ECDSA public key: Z - RSA private key: Z - RSA public key: Z
RL_ARCL_KeyDbRetir eDisable the installed key database imageNoneNoneNoneNoneCrypto Officer
RL_ARCL_ReinitHwReinitializ e CCP hardwareNoneNoneNoneNoneCrypto Officer
RL_ARCL_GetShaInfoGet SHA IV, message block size, and output hash lengthNoneSHA typeIV, message block size, output hash lengthNoneCrypto Officer
RL_ARCL_ModExpPerform a modular exponent iationNoneBase, exponent, modulusResultNoneCrypto Officer
RL_ARCL_RtlDisableK eyUsageDisable usage of the RTL keyNoneNoneNoneNoneCrypto Officer
RL_ARCL_AddAddress MapRegister a new device address mapNoneDevice address mapNoneNoneCrypto Officer
RL_ARCL_GetRuntime ProfileGet the runtime profile addressNoneNoneRuntime profile addressNoneCrypto Officer

© 2025 Advanced Micro Devices (AMD), atsec information security.

Page 23
NameDescript ionIndicatorInputsOutputsSecu rity Func tionsSSP Acces s
RL_ARCL_GetReadOnl yRegionsGet list of read-only regionsNoneNoneList of read-only regionsNoneCrypto Officer
RL_ARCL_CcpDmaCopy data from a source to a destinati on using the CCPNoneSRAM address or KSB slot handleSRAM address or KSB slot handleNoneCrypto Officer
RL_ARCL_KsbAllocAllocate a slot in the KSBNoneLength, allocation typeKSB slot handleNoneCrypto Officer
RL_ARCL_KsbChange UsageChange attribute s for a KSB slotNoneKSB slot, attributesNoneNoneCrypto Officer
RL_ARCL_KsbGetAttri butesRetrieve attribute s for a KSB slotNoneKSB slotAttributesNoneCrypto Officer
RL_ARCL_KsbClearSet the first 64 bytes of a KSB slot to zeroNoneKSB slotNoneNoneCrypto Officer
RL_ARCL_KsbLockLock a KSB slotNoneKSB slotNoneNoneCrypto Officer
RL_ARCL_KsbFreeFree and zeroize a previousl y allocated KSB slotNoneKSB slotNoneNoneCrypto Officer - AES key: Z - HMAC key: Z - Key- derivat ion key: Z - Derive d key: Z - ECDSA private

a Z © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 24
NameDescript ionIndicatorInputsOutputsSecu rity Func tionsSSP Acces s key: Z - ECDSA public key: Z - RSA private key: Z - RSA public key: Z
RL_ARCL_ZlibDecomp ressDecompr ess zlib dataNoneCompresse d dataUncompre ssed dataNoneCrypto Officer
RL_ARCL_ClearInterru ptClear CCP interrupt for the flagsNoneFlagsNoneNoneCrypto Officer
RL_ARCL_GetInterrupt StateCheck if CCP interrupt is signaled for the flagsNoneFlagsInterrupt stateNoneCrypto Officer
RL_ARCL_EnableInterr uptEnable CCP interrupt for the flagsNoneFlagsNoneNoneCrypto Officer
RL_ARCL_GetKeyUsag eHistoryCheck key usage so far in bootNoneNoneKey usage countersNoneCrypto Officer
RL_ARCL_RngReinitReinitializ e the Entropy Source and DRBGNoneNoneNoneRand om numb er gener ationCrypto Officer - Entrop y input: G,E,Z - DRBG seed: G,E,Z -

G,E,Z G,E,Z © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 25
NameDescript ionIndicatorInputsOutputsSecu rity Func tionsSSP Acces s Intern al state (V, Key): G
RL_ARCL_RngReseedReseed the DRBGNoneNoneNoneRand om numb er gener ationCrypto Officer - Entrop y input: G,E,Z - DRBG seed: G,E,Z - Intern al state (V, Key): W,E
RL_ARCL_DeInitVcqDisable and clear the virtual queue VCQ0NoneNoneNoneNoneCrypto Officer
RL_ARCL_QueryRootK eyCheck whether the provided key reference is one of the root keysNoneKey referenceTrue/falseNoneCrypto Officer

(V, G G,E,Z G,E,Z (V, W,E Table 13: Approved Services For the above table, the convention below applies when specifying the access permissions (types) that the service has for each SSP.

Page 26
NameDescriptionAlgorithmsRole
RL_ARCL_MacGenerate a MAC tagHMAC with key lengths less than 112 bitsCrypto Officer
RL_ARCL_EcdsaGenerateKeyPairGenerate an ECDSA key pairDeterministic ECDSA key pair generationCrypto Officer
RL_ARCL_RsaGenerateKeyPairGenerate an RSA key pairDeterministic RSA key pair generation RSA with 1024 or 1536 bits modulusCrypto Officer
RL_ARCL_SignSign a messageECDSA with SHA-1 RSA with 1024 or 1536 bits modulus RSA with SHA-1Crypto Officer
RL_ARCL_X509CertCreateCreate and sign an X.509 certificateECDSA with SHA-1Crypto Officer
RL_ARCL_EcdsaSignDigestSign a pre-hashed messageECDSA (pre-hashed message)Crypto Officer
RL_ARCL_RsaPssSignDigestSign a pre-hashed messageRSA (pre-hashed message)Crypto Officer
RL_ARCL_EcdsaVerifySignatureVerify a pre-hashed message signatureECDSA (pre-hashed message)Crypto Officer
RL_ARCL_RsaPssVerifySignatureVerify a pre-hashed message signatureRSA (pre-hashed message)Crypto Officer

• Zeroize (Z): The module zeroizes the SSP. • N/A: The module does not access any SSP or key during its operation. The module provides three different API layers, each with distinct services:

  1. The ARCL layer, which provides high-level cryptographic (both approved and nonapproved) and non-cryptographic functionality.
  2. The CCP HAL layer, which provides non-approved, low-level cryptographic functionality.
  3. The SIB HAL layer, which provides non-approved, low-level functionality to interact with the Key Storage Block, Entropy Source, DRBG, and Security State. The ARCL API layer provides the RL_ARCL_GetState function which returns the ArclState, ArclVersion, and FipsIndicatorStatus values: • The ArclState value serves as the module’s status indicator and is used to indicate the error states. • The ArclVersion value contains the module’s versioning information. The FipsIndicatorStatus value serves as the approved service indicator. If this value is set to 2, the previously requested ARCL service was approved. If this value is set to any other value, the service was non-approved. The CCP HAL and SIB HAL layers only provide non-approved services.
4.4 Non-Approved Services

© 2025 Advanced Micro Devices (AMD), atsec information security.

Page 27
NameDescriptionAlgorithmsRole
RL_ARCL_MeasureMemoryPerPcrPCR-based memory measurementSHA-384 with non- standard initial hash valueCrypto Officer
CCP_HAL APIAny API in the CCP_HAL API layerCCP_HAL algorithmCrypto Officer
SIB_HAL APIAny API in the SIB_HAL API layerSIB_HAL algorithmCrypto Officer

Table 14: Non-Approved Services

4.5 External Software/Firmware Loaded

Upon startup, the libROM firmware component loads the overlay firmware from external storage (SPI flash) into the sub-chip cryptographic subsystem. The integrity of the overlay firmware is determined by verifying an RSA-PSS 4096 with SHA-384 signature stored in the firmware that was computed at build time. If the signature verification fails, the firmware load test fails. The public key used to verify this signature is stored inside the libROM firmware component of the module, the private key associated with this public key is controlled by the vendor. All data output is inhibited during the execution of the firmware load test and the firmware loading process. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 28
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the libROM component of the module is verified by comparing a SHA-384 digest value calculated at runtime with the SHA-384 digest value stored in the module that was computed at build time. The integrity of the overlay firmware component of the module is discussed in Section 4.5.

5.2 Initiate on Demand

The module provides the RL_ARCL_SelfTest service to perform self-tests on demand. Among those self-tests is the integrity test, as part of the pre-operational self-tests. More details on the API are provided by the vendor in its developer’s manual. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 29
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited How Requirements are Satisfied: Any SSPs contained within the module are protected by the hardware and firmware restrictions implemented by the Key Storage Block. Only the module has access to these SSPs, and access is only possible through the defined interfaces.

6.2 Configuration Settings and Restrictions

No configuration of the operational environment is required for the module to operate in an approved mode. Therefore, there are no rules, settings, or restrictions to the configuration of the operational environment. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 30
MechanismInspection FrequencyInspection Guidance
Opaque sealing coatNo actions are required to maintain the physical security of the moduleNo actions are required to maintain the physical security of the module
7.1 Mechanisms and Actions Required

Table 15: Mechanisms and Actions Required © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 31
8 Non-Invasive Security

The module does not implement any non-invasive security mechanisms. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 32
Storage Area NameDescriptionPersistence Type
Hardware registersHardware registers store the SSPs used by the hardware DRBGDynamic
Key Storage Block (KSB)Hardware block used to securely store SSPs while the module is operationalDynamic
SRAMTemporary storage for SSPs used by the module as part of service executionDynamic

Name API input parameter s API output parameter s

From Operator calling application (TOEPP) Cryptographi c module

To Cryptographi c module Operator calling application (TOEPP)

Format Type Plaintex t Plaintex t

Distributio n Type Manual Manual

Entry Type Electroni c Electroni c

SFI or Algorith m

Zeroization MethodDescriptionRationaleOperator Initiation
RL_ARCL_KsbFreeZeroize a single KSB slotMemory occupied by the SSP is overwritten with zeroes, which renders the SSP value irretrievable. Completion of the function indicates that the zeroization procedure succeeded.By calling the RL_ARCL_KsbFree function
RL_ARCL_ShutdownZeroize all data stored in the KSBMemory occupied by the SSPs is overwritten with zeroes, which renders theBy calling the RL_ARCL_Shutdown function
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 16: Storage Areas approved and non-approved modes of operation using a “virtual queue” mechanism: virtual queue 0 is exclusively used for approved services, whereas virtual queue 1 is always used for non- approved services. The module does not perform persistent storage of SSPs; SSPs in use by the module exist in volatile memory only. m Table 17: SSP Input-Output Methods © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 33
Zeroization MethodDescriptionRationale SSP values irretrievable. Completion of the function indicates that the zeroization procedure succeeded.Operator Initiation
RL_ARCL_ScrapZeroize all data stored in the KSBMemory occupied by the SSPs is overwritten with zeroes, which renders the SSP values irretrievable. Completion of the function indicates that the zeroization procedure succeeded.By calling the RL_ARCL_Scrap function
Remove power from the SoCDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removedBy removing power
AutomaticAutomatically zeroized by the module when no longer neededEvery service overwrites its temporary memory upon completion, which renders any SSP values used by the service irretrievable. Completion of the service indicates that the zeroization procedure succeeded.N/A
NameDescriptio nSize - Strengt hType - CategoryGenerate d ByEstablishe d ByUsed By
AES keySymmetric key used for AES operations128, 192, 256 bits - 128, 192, 256 bitsSymmetric - CSPEncryptio n Decryptio n MAC
HMAC keySymmetric key used for HMAC operations112-256 bits - 112-256 bitsSymmetric - CSPMAC
Key- derivation keySymmetric key used to derive other112-256 bits - 112-256 bitsSymmetric - CSPKey derivation

Table 18: SSP Zeroization Methods All data output is inhibited during zeroization. h © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 34
NameDescriptio n symmetric keysSize - Strengt hType - CategoryGenerate d ByEstablishe d ByUsed By
Derived keySymmetric key derived from a key- derivation key112-256 bits - 112-256 bitsSymmetric - CSPKey derivation
Entropy inputEntropy input used to seed the DRBG384 bits - 384 bitsEntropy input - CSPRandom number generationRandom number generatio n
DRBG seedDRBG seed derived from entropy input384 bits - 256 bitsDRBG seed - CSPRandom number generationRandom number generatio n
Internal state (V, Key)Internal state of the CTR_DRBG instance384 bits - 256 bitsInternal state - CSPRandom number generationRandom number generatio n
ECDSA private keyPrivate key used for ECDSAP-384 - 192 bitsPrivate key - CSPKey pair generationSignature generatio n
ECDSA public keyPublic key used for ECDSAP-384 - 192 bitsPublic key - PSPKey pair generationSignature verificatio n Signature verificatio n (Legacy)
RSA private keyPrivate key used for RSA2048, 3072, 4096 bits - 112, 128, 150 bitsPrivate key - CSPKey pair generationSignature generatio n
RSA public keyPublic key used for RSA1024, 1536, 2048, 3072, 4096 bits - 80, 96, 112, 128, 150 bitsPublic key - PSPKey pair generationSignature verificatio n Signature verificatio n (Legacy)

h n © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 35
NameDescriptio nSize - Strengt hType - CategoryGenerate d ByEstablishe d ByUsed By
Intermediat e key generation valueTemporary value generated during key pair generation services384- 4096 bits - 112-256 bitsIntermediat e value - CSPKey pair generation
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyAPI input paramete rsKey Storage Block (KSB):Plaintext SRAM:PlaintextKSB: until explicitly removed or the module ends its operation; SRAM: for the duration of the serviceRL_ARCL_KsbFree RL_ARCL_Shutdo wn RL_ARCL_Scrap Remove power from the SoC Automatic
HMAC keyAPI input paramete rsKey Storage Block (KSB):Plaintext SRAM:PlaintextKSB: until explicitly removed or the module ends its operation; SRAM: for the duration of the serviceRL_ARCL_KsbFree RL_ARCL_Shutdo wn RL_ARCL_Scrap Remove power from the SoC Automatic
Key- derivation keyAPI input paramete rsKey Storage Block (KSB):Plaintext SRAM:PlaintextKSB: until explicitly removed or the module ends its operation; SRAM: for the duration of the serviceRL_ARCL_KsbFree RL_ARCL_Shutdo wn RL_ARCL_Scrap Remove power from the SoC Automatic
Derived keyAPI output paramete rsKey Storage Block (KSB):Plaintext SRAM:PlaintextKSB: until explicitly removed or the moduleRL_ARCL_KsbFree RL_ARCL_Shutdo wn RL_ARCL_Scrap Remove powerKey- derivation key:Derived From

h Table 19: SSP Table 1 © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 36
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
ends its operation; SRAM: for the duration of the servicefrom the SoC Automatic
Entropy inputHardware registers:Plainte xtFrom generation until DRBG seed is createdRemove power from the SoC
DRBG seedHardware registers:Plainte xtWhile the DRBG is instantiate dRemove power from the SoCEntropy input:Derive d From
Internal state (V, Key)Hardware registers:Plainte xtFrom DRBG instantiatio n until DRBG terminatio nRemove power from the SoCDRBG seed:Derive d From
ECDSA private keyAPI input paramete rs API output paramete rsKey Storage Block (KSB):Plaintext SRAM:PlaintextKSB: until explicitly removed or the module ends its operation; SRAM: for the duration of the serviceRL_ARCL_KsbFree RL_ARCL_Shutdo wn RL_ARCL_Scrap Remove power from the SoC AutomaticECDSA public key:Paired With
ECDSA public keyAPI input paramete rs API output paramete rsSRAM:PlaintextFor the duration of the serviceRemove power from the SoC AutomaticECDSA private key:Paired With
RSA private keyAPI input paramete rs API output paramete rsKey Storage Block (KSB):Plaintext SRAM:PlaintextKSB: until explicitly removed or the module ends its operation; SRAM: for the duration of the serviceRL_ARCL_KsbFree RL_ARCL_Shutdo wn RL_ARCL_Scrap Remove power from the SoC AutomaticRSA public key:Paired With

d n © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 37
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
RSA public keyAPI input paramete rs API output paramete rsKey Storage Block (KSB):Plaintext SRAM:PlaintextKSB: until explicitly removed or the module ends its operation; SRAM: for the duration of the serviceRL_ARCL_KsbFree RL_ARCL_Shutdo wn RL_ARCL_Scrap Remove power from the SoC AutomaticRSA private key:Paired With
Intermediat e key generation valueSRAM:PlaintextFor the duration of the serviceRemove power from the SoC Automatic
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2030. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 38
Algorith m or TestTest Propertie sTest Metho dTest TypeIndicatorDetails
SHA2-384 (A5794)N/AMessag e digestSW/FW Integrit yRomIntegrityState is set to ARCL_SELFTEST_STATE_PASSE DIntegrity test on the libROM firmware componen t at power up
Algorit hm or TestTest Properti esTest MethodTest TypeIndicatorDetailsConditio ns
RSA SigVer (FIPS186 -5) (A5794)4096-bit key, SHA-384Signatur e verificati onSW/F W LoadFwIntegrityState is set to ARCL_SELFTEST_STATE_P ASSEDFirmware load test on the overlay firmware compone ntPower up
SHA-1 (A5794)0-bit messageKATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDKAT message digestPrior to first approved use of SHA-1
SHA2- 256 (A5794)0-bit messageKATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDMessage digestPrior to first approved use of SHA-224 or SHA- 256
10 Self-Tests

While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module does not return control to the calling application until the tests are completed.

10.1 Pre-Operational Self-Tests

s d Table 21: Pre-Operational Self-Tests automatically when the module is initialized. If this test fails, the module transitions to the hard error state.

10.2 Conditional Self-Tests

As part of the initialization, the libROM firmware component loads the overlay firmware component and performs the firmware load test on the overlay firmware. Only if this test succeeds, will the module move to the operational state. Similar to the pre-operational integrity test, if the firmware load test fails, the module transitions to the hard error state. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 39
Algorit hm or TestTest Properti esTest MethodTest TypeIndicatorDetailsConditio ns
SHA2- 512 (A5794)0-bit messageKATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDMessage digestPrior to libROM firmware integrity test
SHA3- 512 (A5794)0-bit messageKATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDMessage digestPrior to first approved use of SHA-3 or SHAKE
AES-ECB (A5794) encrypti on128-bit keyKATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDEncryptio nPrior to first approved use of AES ECB, CBC, or CTR
AES-ECB (A5794) decrypti on128-bit keyKATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDDecryptio nPrior to first approved use of AES ECB, CBC, or CTR
AES- CMAC (A5794)128-bit keyKATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDMAC tag generatio nPrior to first approved use of AES CMAC
HMAC- SHA2- 384 (A5794)384-bit key, SHA-384KATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDMAC tag generatio nPrior to first approved use of HMAC
KDF SP800- 108 (A5794)256-bit key- derivatio n key, 128-bit derived keyKATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDKey- based key derivatio nPrior to first approved use of KBKDF
Entropy Source start-up RCTCutoff: 5 samplesRCTCASTEntropy Source is operationalSP 800- 90B start-up health test ran overInitializati on of the Entropy Source

© 2025 Advanced Micro Devices (AMD), atsec information security.

Page 40
Algorit hm or TestTest Properti esTest MethodTest TypeIndicatorDetails 4096 samplesConditio ns
Entropy Source start-up APTCutoff: 16 samplesAPTCASTEntropy Source is operationalSP 800- 90B start-up health test ran over 4096 samplesInitializati on of the Entropy Source
Entropy Source continuo us RCTCutoff: 5 samplesRCTCASTEntropy Source produces entropySP 800- 90B continuo us health testDRBG seeding
Entropy Source continuo us APTCutoff: 16APTCASTEntropy Source produces entropySP 800- 90B continuo us health testDRBG seeding
Counter DRBG (A5795)AES-256KATCASTTrngState is set to ARCL_SELFTEST_STATE_P ASSEDSP 800- 90Ar1 (instantia te, reseed, generate ) health testPrior to first approved use of the CTR_DRB G
ECDSA SigGen (FIPS186 -5) (A5794)P-384 with SHA-384KATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDSignature generatio nPrior to first approved use of ECDSA signature generatio n
ECDSA SigVer (FIPS186 -5) (A5794)P-384 with SHA-384KATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDSignature verificati onPrior to first approved use of ECDSA signature verificati on
RSA SigGen (FIPS186 -5) (A5794)2048-bit key with SHA-384KATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDSignature generatio nPrior to first approved use of RSA-PSS

n © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 41
Algorit hm or TestTest Properti esTest MethodTest TypeIndicatorDetailsConditio ns signature generatio n
RSA SigVer (FIPS186 -5) (A5794)2048-bit key with SHA-384KATCASTKatState is set to ARCL_SELFTEST_STATE_P ASSEDSignature verificati onPrior to overlay firmware load test
ECDSA KeyGen (FIPS186 -5) (A5794)SHA-384PCTPCTEcdsaPctState is set to ARCL_SELFTEST_STATE_P ASSEDSignature generatio n & verificati onECDSA key pair generatio n
RSA KeyGen (FIPS186 -5) (A5794)SHA-384PCTPCTRsaPctState is set to ARCL_SELFTEST_STATE_P ASSEDSignature generatio n & verificati onRSA key pair generatio n
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-384 (A5794)Message digestSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigVer (FIPS186-5) (A5794)Signature verificationSW/FW LoadOn demandManually
SHA-1 (A5794)KATCASTOn demandManually
SHA2-256 (A5794)KATCASTOn demandManually
SHA2-512 (A5794)KATCASTOn demandManually
SHA3-512 (A5794)KATCASTOn demandManually
AES-ECB (A5794) encryptionKATCASTOn demandManually

n Table 22: Conditional Self-Tests Upon generation of an ECDSA or RSA key pair, the module will perform a pair-wise consistency test (PCT) as shown in the table above, which provides some assurance that the generated

10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 42
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A5794) decryptionKATCASTOn demandManually
AES-CMAC (A5794)KATCASTOn demandManually
HMAC-SHA2- 384 (A5794)KATCASTOn demandManually
KDF SP800-108 (A5794)KATCASTOn demandManually
Entropy Source start-up RCTRCTCASTOn demandManually
Entropy Source start-up APTAPTCASTOn demandManually
Entropy Source continuous RCTRCTCASTEvery sampleManually
Entropy Source continuous APTAPTCASTEvery sampleManually
Counter DRBG (A5795)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A5794)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A5794)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A5794)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5794)KATCASTOn demandManually
ECDSA KeyGen (FIPS186-5) (A5794)PCTPCTOn demandManually
RSA KeyGen (FIPS186-5) (A5794)PCTPCTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
Soft ErrorThe module only responds to status, zeroization, and self- test service requestsCryptographic algorithm self-test error or Pair-wise consistency test errorInvoke RL_ARCL_SelfTest serviceArclState = 8

Table 24: Conditional Periodic Information

10.4 Error States

© 2025 Advanced Micro Devices (AMD), atsec information security.

Page 43
NameDescriptionConditionsRecovery MethodIndicator
Hard ErrorThe module does not respond to any service requests and must be resetFW integrity test error or FW load test errorPower off the moduleArclState = 16

Table 25: Error States In the Soft Error state, the module outputs the error type through the status indicator and status output interface. Moreover, the data input and data output interfaces are inhibited, and the module only accepts control input. In the Hard Error state, no input or output is possible at all.

10.5 Operator Initiation of Self-Tests

The operator can request on-demand self-tests by invoking the RL_ARCL_SelfTest service. This service executes all self-tests listed above. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 44
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

To detect any potential tampering during delivery of the module, the user can verify the Thermoform or JEDEC tray is securely strapped and vacuum sealed in the moisture barrier bag. Additionally, the SoC itself provides tamper evidence as specified in Section 7. Upon delivery, no further installation or configuration is required for the hardware to operate as the validated module in conformance with the rules in this Security Policy document. The module implicitly transitions between the approved mode and the non-approved mode when appropriate.

11.2 Administrator Guidance

All the functions, ports and logical interfaces described in this document are available to the Crypto Officer. The module implicitly transitions between the approved mode and the nonapproved mode contingent on the service that is invoked. Therefore, there are no special procedures to administer the approved or non-approved modes.

11.3 Non-Administrator Guidance

The module implements only the Crypto Officer. There are no requirements for nonadministrator operators.

11.4 Design and Rules
11.5 Maintenance Requirements
11.6 End of Life

The process for performing “End of Life” occurs at the chronological point of 10 years starting from manufacturing date of the module. The module does not possess persistent storage of SSPs. The SSP value only exists in volatile memory and that value vanishes when the module is powered off. The procedure for secure sanitization of the module at the end of life is simply to power it off, which is the action of zeroization of the SSPs. As a result of this sanitization via power-off, the SSP is removed from the module, so that the module may either be distributed to other operators or disposed. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 45
12 Mitigation of Other Attacks

The module does not implement security mechanisms to mitigate other attacks. © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 46
Table, extracted as text (did not parse into structured rows)
A Glossary and Abbreviations AES                   Advanced Encryption Standard API                   Application Programming Interface ARCL                  AMD Root of Trust Crypto Library ASP                   AMD Secure Processor CAST                  Cryptographic Algorithm Self-Test CAVP                  Cryptographic Algorithm Validation Program CBC                   Cipher Block Chaining CBC-MAC               Cipher Block Chaining Message Authentication Code CCP                   Cryptographic Co-Processor CFB                   Cipher Feedback CMAC                  Cipher-based Message Authentication Code CMVP                  Cryptographic Module Validation Program CSP                   Critical Security Parameter CTR                   Counter DRBG                  Deterministic Random Bit Generator ECB                   Electronic Code Book ECDSA                 Elliptic Curve Digital Signature Algorithm FIPS                  Federal Information Processing Standards GCTR                  Galois Counter HAL                   Hardware Abstraction Layer HMAC                  Keyed-Hash Message Authentication Code IAPM                  Integrity-Aware Parallelizable Mode IV                    Initialization Vector JEDEC                 Joint Electron Device Engineering Council KAT                   Known Answer Test KSB                   Key Storage Block MAC                   Message Authentication Code NIST                  National Institute of Science and Technology OFB                   Output Feedback OTP                   One-Time Programmable PCT                   Pair-wise Consistency Test PKI                   Public Key Infrastructure PSP                   Public Security Parameter PSS                   Probabilistic Signature Scheme ROM                   Read-Only Memory RSA                   Rivest Shamir Adleman RTL                   Register-Transfer Level SHA                   Secure Hash Algorithm SHAKE                 Secure Hash Algorithm with Keccak SIB                   Security Infrastructure Block SoC                   System on Chip SRAM                  Static Random-Access Memory SSP                   Sensitive Security Parameter TRNG                  True Random Number Generator XOF                   Extendable Output Function XTS                   XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 Advanced Micro Devices (AMD), atsec information security.
Page 47

B References FIPS 140-3 FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS 140-3 IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/CSRC/media/Projects/cryptographic-modulevalidation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf FIPS 180-4 Secure Hash Standard (SHS) August 2015 https://doi.org/10.6028/NIST.FIPS.180-4 FIPS 186-2 Digital Signature Standard (DSS) January 2000 https://csrc.nist.gov/files/pubs/fips/186-2/final/docs/fips186-2.pdf FIPS 186-4 Digital Signature Standard (DSS) July 2013 https://doi.org/10.6028/NIST.FIPS.186-4 FIPS 186-5 Digital Signature Standard (DSS) February 2023 https://doi.org/10.6028/NIST.FIPS.186-5 FIPS 197 Advanced Encryption Standard (AES) November 2001; Updated May 2023 https://doi.org/10.6028/NIST.FIPS.197-upd1 FIPS 198-1 The Keyed-Hash Message Authentication Code (HMAC) July 2008 https://doi.org/10.6028/NIST.FIPS.198-1 FIPS 202 SHA-3 Standard: Permutation-Based Hash and ExtendableOutput Functions August 2015 https://doi.org/10.6028/NIST.FIPS.202 SP 800-38A Recommendation for Block Cipher Modes of Operation: Methods and Techniques December 2001 https://doi.org/10.6028/NIST.SP.800-38A SP 800-38B Recommendation for Block Cipher Modes of Operation: the CMAC Mode for Authentication May 2005; Updated October 2016 https://doi.org/10.6028/NIST.SP.800-38B SP 800-38D Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://doi.org/10.6028/NIST.SP.800-38D SP 800-38E Recommendation for Block Cipher Modes of Operation: the XTS-AES Mode for Confidentiality on Storage Devices January 2010 https://doi.org/10.6028/NIST.SP.800-38E SP 800-90Ar1 Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://doi.org/10.6028/NIST.SP.800-90Ar1 SP 800-90B Recommendation for the Entropy Sources Used for Random Bit Generation © 2025 Advanced Micro Devices (AMD), atsec information security.

Page 48

January 2018 https://doi.org/10.6028/NIST.SP.800-90B SP 800-108r1 Recommendation for Key Derivation Using Pseudorandom Functions August 2022; Updated February 2024 https://doi.org/10.6028/NIST.SP.800-108r1-upd1 SP 800-131Ar2 Transitioning the Use of Cryptographic Algorithms and Key Lengths March 2019 https://doi.org/10.6028/NIST.SP.800-131Ar2 SP 800-133r2 Recommendation for Cryptographic Key Generation June 2020 https://doi.org/10.6028/NIST.SP.800-133r2 SP 800-140Br1 Cryptographic Module Validation Program (CMVP) Security Policy Requirements: CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B November 2023 https://doi.org/10.6028/NIST.SP.800-140Br1 © 2025 Advanced Micro Devices (AMD), atsec information security.