All modules
CMVP Validated Module · FIPS 140-3 Security Policy

IBM COS Linux Kernel Cryptographic API Cryptographic Module

Certificate#5094StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorIBM Corporation
Medium review priority  ·  exposes kernel crypto consumer  ·  Linux kernel upstream has published 3932 CVEs since this module's initial validation  ·  last validated 8 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date11/13/2030
CaveatWhen operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorIBM Corporation

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for IBM COS Linux Kernel Cryptographic API Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for IBM COS Linux Kernel Cryptographic API Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

IBM Corporation IBM COS Linux Kernel Cryptographic API Cryptographic Module Document Version 1.1 Last update: 2025-11-10 Prepared by: Prepared for: atsec information security corporation IBM Corporation

4516 Seton Center Parkway, Suite 250 71 S Wacker Dr, 6th Floor

Austin, TX 78759 Chicago, IL 60606 www.atsec.com www.ibm.com © 2025 IBM / atsec information security.

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 IBM / atsec information security.

3 of 71

Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid9
Table 5: Modes List and Description9
Table 6: Approved Algorithms12
Table 7: Vendor-Affirmed Algorithms12
Table 8: Non-Approved, Not Allowed Algorithms12
Table 9: Security Function Implementations17
Table 10: Entropy Certificates18
Table 11: Entropy Sources19
Table 12: Ports and Interfaces21
Table 13: Roles22
Table 14: Approved Services30
Table 15: Non-Approved Services30
Table 16: Storage Areas35
Table 17: SSP Input-Output Methods35
Table 18: SSP Zeroization Methods36
Table 19: SSP Table 139
Table 20: SSP Table 241
Table 21: Pre-Operational Self-Tests42
Table 22: Conditional Self-Tests57
Table 23: Pre-Operational Periodic Information57
Table 24: Conditional Periodic Information64
Table 25: Error States64
Page 5
List of Figures
ItemPage
Figure 1: Block Diagram7
Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 3 of the IBM COS Linux Kernel Cryptographic API Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for intact and including this notice. Other documentation is proprietary to their authors.

1.2 Security Levels
1.3 Additional Information

In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. © 2025 IBM / atsec information security.

6 of 71

Page 7
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The IBM COS Linux Kernel Cryptographic API Cryptographic Module (hereafter referred to as “the module”) provides a C language application program interface (API) for use by other (kernel space and user space) processes that require cryptographic functionality. The module operates on a general-purpose computer as part of the Linux kernel. Its cryptographic functionality can be accessed using the Linux Kernel Crypto API. Module Type: Software Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: The cryptographic boundary of the module is defined as the kernel binary and the kernel crypto object files, the libkcapi library, and the kcapi-hasher binary, which is used to verify the integrity of the software components. In addition, the cryptographic boundary contains the .hmac files which store the expected integrity values for each of the software components. The cryptographic boundary is indicated by the small bold border in Figure

  1. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. It includes software in kernel and user space, as well as the PAA in the CPU. The TOEPP is indicated by the large thin border in Figure
  2. Figure 1: Block Diagram © 2025 IBM / atsec information security.

7 of 71

Page 8
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
/boot/vmlinuz-6.1.0-32-amd64; *.ko files in /usr/lib/modules/6.1.0-32- amd64/kernel/crypto/; *.ko files in /usr/lib/modules/6.1.0-32- amd64/kernel/arch/x86/crypto/; /usr/lib/x86_64-linux- gnu/libkcapi.so.1.5.0; /usr/bin/kcapi-hasherKernel: 3; libkcapi: 1.5.0-1 amd64N/AHMAC SHA-512 (vmlinuz, libkcapi.so.1.5.0, kcapi-hasher); RSA signature verification (*.ko files)
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
ClevOS 3.19Lenovo SR650v3Intel Sapphire Rapids Xeon 8474CYesN/AKernel: 3 libkcapi: 1.5.0-1 amd64
ClevOS 3.19Lenovo SR650v3Intel Sapphire Rapids Xeon 8474CNoN/AKernel: 3 libkcapi: 1.5.0-1 amd64
Operating SystemHardware Platform
ClevOS 3.19PIO-628U-TR4T+-ST031 (Intel Xeon E5-2620 *)
ClevOS 3.19PIO-648R-E1CR36L+-ST031 (Intel Xeon E5-2620 *)
ClevOS 3.19IBM A10 Series (Intel Xeon 6126)
ClevOS 3.19IBM A10 Series (Intel Xeon 6226)
ClevOS 3.19IBM M10 Series (Intel Xeon 4110)
ClevOS 3.19IBM M10 Series (Intel Xeon 4210R)
ClevOS 3.19IBM C10 Series (Intel Xeon 4110)
2.2 Tested and Vendor Affirmed Module Version

and Identification Tested Module Identification

8 of 71

Page 9
Operating SystemHardware Platform
ClevOS 3.19IBM C10 Series (Intel Xeon 4210R)
ClevOS 3.19IBM 4616-A2D Series (Intel Xeon 4416+)
ClevOS 3.19IBM 4616-M2D Series (Intel Xeon 4416+)
ClevOS 3.19IBM 4616-C2D Series (Intel Xeon 4416+)
ClevOS 3.19IBM 4616-S3D Series (Intel Xeon Gold 6438N)
ClevOS 3.19IBM 4616-S4D/S6D Series (Intel Xeon 4416+)
ClevOS 3.19IBM 4616-A1D Series (Intel Xeon 4314)
ClevOS 3.19IBM 4616-M1D Series (Intel Xeon 4314)
ClevOS 3.19IBM 4616-C1D Series (Intel Xeon 4314)
ClevOS 3.19IBM 4616-S2D Series (Intel Xeon 4314)
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedMapped to approved service indicator in Section 4.3 for all approved algorithms except GCM: respective approved service function returns indicator 0. For GCM: crypto_aead_get_flags(tfm) has the CRYPTO_TFM_FIPS_COMPLIANCE flag set
Non- approved modeAutomatically entered whenever a non-approved service is requestedNon- ApprovedNo service indicator required for non-approved services per IG 2.4.C

Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components
2.4 Modes of Operation

Modes List and Description: Table 5: Modes List and Description Mode Change Instructions and Status: After passing all pre-operational self-tests and cryptographic algorithm self-tests executed on start-up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. that was requested. Not applicable. © 2025 IBM / atsec information security.

9 of 71

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CBCA6801, A6806, A6809, A6812Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A6801, A6806, A6809, A6812Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA6801, A6806, A6812Key Length - 128, 192, 256SP 800-38C
AES-CFB128A6801, A6806, A6812Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA6801, A6806, A6812Direction - Generation Key Length - 128, 192, 256SP 800-38B
AES-CTRA6801, A6806, A6809, A6812Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA6801, A6804, A6805, A6806, A6807, A6808, A6809, A6810, A6811, A6812, A6813, A6814Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA6801, A6805, A6806, A6808, A6809, A6811, A6812, A6814Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-GCMA6804, A6807, A6810, A6813Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA6801, A6806, A6812Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-KWA6801, A6806, A6812Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA6801, A6806, A6812Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A6801, A6806, A6809, A6812Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA6801, A6804, A6805, A6806, A6807, A6808, A6809, A6810, A6811, A6812, A6813, A6814Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A6801Curve - P-256, P-384 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA SigVer (FIPS186-4)A6802Component - No Curve - P-256, P-384 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A6802Curve - P-256, P-384 Hash Algorithm - SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA3- 256, SHA3-384, SHA3-512FIPS 186-5
Hash DRBGA6801, A6815, A6816, A6817Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2- 384, SHA2-512SP 800-90A Rev. 1
2.5 Algorithms

Approved Algorithms: © 2025 IBM / atsec information security.

10 of 71

Page 11
AlgorithmCAVP CertPropertiesReference
HMAC DRBGA6801, A6815, A6816, A6817Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2- 384, SHA2-512SP 800-90A Rev. 1
HMAC-SHA-1A6801, A6815, A6816, A6817, A6818Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A6801, A6815, A6816, A6817, A6818Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A6801, A6815, A6816, A6817, A6818Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A6801, A6815, A6816, A6817Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A6801, A6815, A6816, A6817Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3- 224A6801Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3- 256A6801Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3- 384A6801Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3- 512A6801Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A6801Domain Parameter Generation Methods - P-256, P-384 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A6801Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA OneStep SP800-56Cr2A6803Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8SP 800-56C Rev. 2
KDF SP800- 108A6803KDF Mode - Counter Supported Lengths - Supported Lengths: 112-4096 Increment 8SP 800-108 Rev. 1
RSA SigVer (FIPS186-4)A6801Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-5)A6801Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5
Safe Primes Key GenerationA6801Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192SP 800-56A Rev. 3
SHA-1A6801, A6815, A6816, A6817, A6818Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A6801, A6815, A6816, A6817, A6818Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4

© 2025 IBM / atsec information security.

11 of 71

Page 12
AlgorithmCAVP CertPropertiesReference
SHA2-256A6801, A6815, A6816, A6817, A6818Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A6801, A6815, A6816, A6817Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A6801, A6815, A6816, A6817Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA3-224A6801Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-256A6801Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-384A6801Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-512A6801Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
NamePropertiesImplementationReference
CKG (asymmetric)Key Type:AsymmetricN/ASP800-133r2, section 4 example 1 (without XOR)
NameUse and Function
AES-GCM with external IVEncryption with external IV (not compliant to FIPS 140-3 IG C.H)
KBKDF (libkcapi)Key derivation with implementation not tested by CAVP
HKDF (libkcapi)Key derivation with implementation not tested by CAVP
PBKDF2 (libkcapi)Password-based key derivation with implementation not tested by CAVP
RSAEncryption primitive; Decryption primitive (not compliant to SP 800-56Br2)
RSA with PKCS#1 v1.5 paddingSignature generation (pre-hashed message); Signature verification (pre- hashed message); Key encapsulation (not compliant to SP 800-56Br2); Key un-encapsulation (not compliant to SP 800-56Br2)

Table 6: Approved Algorithms Vendor-Affirmed Algorithms: Table 7: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: Table 8: Non-Approved, Not Allowed Algorithms © 2025 IBM / atsec information security.

12 of 71

Page 13
Name Encryption and Decryption with AESType BC-UnAuthDescription SP800-38A. Encryption, DecryptionPropertiesAlgorithms AES-CBC: (A6801, A6806, A6809, A6812) AES-ECB: (A6801, A6804, A6805, A6806, A6807, A6808, A6809, A6810, A6811, A6812, A6813, A6814) AES-CFB128: (A6801, A6806, A6812) AES-XTS Testing Revision 2.0: (A6801, A6806, A6809, A6812) AES-CBC-CS3: (A6801, A6806, A6809, A6812) AES-OFB: (A6801, A6806, A6812)
Authenticated Encryption and Authenticated Decryption with AES-KWBC-AuthSP800-38F. Authenticated encryption, Authenticated decryptionAuthenticated Encryption and Authenticated Decryption with AES-KW Security Strength:128-256 bitsAES-KW: (A6801, A6806, A6812)
Random Number Generation with HMAC DRBG, Hash DRBG or Counter DRBGDRBGSP800-90Ar1. Random number generationHash DRBG: (A6801, A6815, A6816, A6817) HMAC DRBG: (A6801, A6815, A6816, A6817) Counter DRBG: (A6801, A6804, A6805, A6806, A6807, A6808, A6809, A6810, A6811, A6812, A6813, A6814)
Message Authentication Code Generation with AES or HMACMACSP800-38B, SP800-38D, FIPS 198-1. Message authenticationHMAC-SHA-1: (A6801, A6815, A6816, A6817, A6818) HMAC-SHA2-224: (A6801, A6815, A6816, A6817, A6818) HMAC-SHA2-256:
2.6 Security Function Implementations

© 2025 IBM / atsec information security.

13 of 71

Page 14
Name Message Authentication Code Verification with AES-GMACType MACDescription SP800-38D, FIPS 198-1. Message authenticationPropertiesAlgorithms (A6801, A6815, A6816, A6817, A6818) HMAC-SHA2-384: (A6801, A6815, A6816, A6817) HMAC-SHA2-512: (A6801, A6815, A6816, A6817) AES-CMAC: (A6801, A6806, A6812) AES-GMAC: (A6801, A6806, A6812) HMAC-SHA3-224: (A6801) HMAC-SHA3-256: (A6801) HMAC-SHA3-384: (A6801) HMAC-SHA3-512: (A6801) AES-GMAC: (A6801, A6806, A6812)
Shared Secret Computation with KAS-FFC-SSC or KAS-ECC-SSCKAS-SSCSP 800-56Ar3. KAS-ECC-SSC and KAS-FFC-SSC per IG D.F Scenario 2 (1)KAS-FFC-SSC Security Strength:112-200 bits KAS-ECC-SSC Security Strength:128, 192 bitsKAS-ECC-SSC Sp800-56Ar3: (A6801) KAS-FFC-SSC Sp800-56Ar3: (A6801)
Message Digest with SHASHAFIPS180-4, FIPS202. Message digestSHA-1: (A6801, A6815, A6816, A6817, A6818) SHA2-224: (A6801, A6815, A6816, A6817, A6818) SHA2-256: (A6801, A6815, A6816, A6817, A6818) SHA2-384: (A6801, A6815, A6816, A6817) SHA2-512: (A6801, A6815, A6816, A6817) SHA3-224: (A6801)

© 2025 IBM / atsec information security.

14 of 71

Page 15
Name Key Pair Generation with ECDSA or Safe PrimesType AsymKeyPair- KeyGen CKG KAS-KeyGenDescription FIPS186-5, SP800-56Ar3. ECDSA Key pair generation according to FIPS186-5, Appendix A.2.2 per IG D.H and SP800-133r2, section 4 (without XOR) 5.1, 5.2; Safe Primes Key Generation according to SP800-56Ar3, Section 5.6.1.1.4 per IG D.H and SP800-133r2, section 4 (without XOR), 5.2PropertiesAlgorithms SHA3-256: (A6801) SHA3-384: (A6801) SHA3-512: (A6801) Safe Primes Key Generation: (A6801) ECDSA KeyGen (FIPS186-5): (A6801) CKG (asymmetric): ()
Authenticated Encryption and Authenticated Decryption with AES-CCMBC-AuthSP800-38C. Authenticated encryption, Authenticated decryptionAuthenticated Encryption and Authenticated Decryption with AES-CCM Security Strength:128-256 bitsAES-CCM: (A6801, A6806, A6812)
Authenticated Encryption and Authenticated Decryption with AES-GCMBC-AuthSP800-38D. Authenticated encryption, Authenticated decryptionAuthenticated Encryption and Authenticated Decryption with AES-GCM Security Strength:128-256 bitsAES-GCM: (A6801, A6804, A6805, A6806, A6807, A6808, A6809, A6810, A6811, A6812, A6813, A6814)
Authenticated Encryption and Authenticated Decryption with AES-CBC or AES- CTR with HMACBC-AuthSP800-38A, FIPS 198-1. Authenticated encryption, Authenticated decryptionAES-CBC: (A6801, A6806, A6809, A6812) AES-CTR: (A6801, A6806, A6809, A6812) HMAC-SHA-1: (A6801, A6815, A6816, A6817, A6818) HMAC-SHA2-256: (A6801, A6815, A6816, A6817,

© 2025 IBM / atsec information security.

15 of 71

Page 16

Name Signature Verification with RSA Legacy Signature Verification with RSA Signature Verification with ECDSA

Type DigSig-SigVer DigSig-SigVer DigSig-SigVer

Description Signature verification Signature verification Signature verification

Properties

Algorithms A6818) HMAC-SHA2-384: (A6801, A6815, A6816, A6817) HMAC-SHA2-512: (A6801, A6815, A6816, A6817) RSA SigVer (FIPS186-5): (A6801) SHA2-224: (A6801, A6815, A6816, A6817, A6818) SHA2-256: (A6801, A6815, A6816, A6818) SHA2-384: (A6801, A6815, A6816, A6817) SHA2-512: (A6801, A6815, A6816, A6817) SHA-1: (A6801, A6815, A6816, A6817, A6818) RSA SigVer (FIPS186-4): (A6801) SHA2-224: (A6801, A6815, A6816, A6817, A6818) SHA2-256: (A6801, A6815, A6816, A6817, A6818) SHA2-384: (A6801, A6815, A6816, A6817) SHA2-512: (A6801, A6815, A6816, A6817) SHA3-256: (A6801) SHA3-384: (A6801) SHA3-512: (A6801) ECDSA SigVer (FIPS186-5): (A6802)

© 2025 IBM / atsec information security.

16 of 71

Page 17

Name Legacy Signature Verification with ECDSA Key Derivation with KBKDF Key Derivation with KDA OneStep

Type DigSig-SigVer KBKDF KAS-56CKDF

Description Signature verification SP 800-108r1. Key derivation SP 800-56cr2. Key agreement scheme

Properties

Algorithms SHA-1: (A6801, A6815, A6816, A6817, A6818) ECDSA SigVer (FIPS186-4): (A6802) KDF SP800-108: (A6803) KDA OneStep SP800-56Cr2: (A6803)

Table 9: Security Function Implementations

2.7 Algorithm Specific Information

Algorithms designated as “Legacy” can only be used on data that was generated prior to the Legacy Date specified in FIPS 140-3 IG C.M.

2.7.1 AES GCM IV

For IPsec, the module offers the AES GCM implementation and uses the context of Scenario

1 (b) of FIPS 140-3 IG C.H. The mechanism for IV generation is compliant with RFC 4106. IVs

generated using this mechanism may only be used in the context of AES GCM encryption within the IPsec protocol. The module does not implement IPsec. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. This application must use RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AES GCM encryption keys are derived. The design of the IPsec protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the crypto_aead_encrypt API function with an AES GCM handle. When this is the case, the API will not set an approved service indicator, as described in the Approved Services table.

2.7.2 AES XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit. © 2025 IBM / atsec information security.

17 of 71

Page 18
Cert NumberVendor Name
E260IBM Corporation

To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical. As the module does not implement symmetric key generation, this check is performed when the keys are input by the operator. Key_1 and Key_2 shall be generated and/or established independently according to the rules for component symmetric keys from NIST SP 800-133r2, Section 6.3.

2.7.3 Diffie-Hellman and EC Diffie-Hellman

The module offers DH and ECDH shared secret computation services compliant to the SP 800-56Ar3 and meeting IG D.F scenario 2 path (1). To meet the required assurances listed in Section 5.6 of SP 800-56Ar3, the module shall be used together with an application that implements the IPSec protocol and the following steps shall be performed:

  1. The entity using the module, must use the module's "Key pair generation" service: the set_secret and generate_public_key API functions, to generate DH/ECDH ephemeral key pairs. This meets the assurances required by key pair owner defined in the section 5.6.2.1 of SP 800-56Ar3.
  2. As part of the module's shared secret computation service, the module internally performs the public key validation on the peer's public key passed in as input to the API function. This meets the public key validity assurance required by section
5.6.2.2.2 of SP 800-56Ar3.

3. The module does not support static keys, therefore the "assurance of peer's possession of private key" is not applicable.

2.7.5 SHA-1

Digital signature generation using SHA-1 is non-approved and not allowed in approved services.

2.7.6 SHA-3

The module implements HMAC with SHA3-224, SHA3-256, SHA3-384, SHA3-512. The CAVP certificates have been obtained for the HMAC algorithm as well as for all the SHA3 implementations. The CAVP certificates are listed in the Approved Algorithms table.

2.7.7 RSA

The module implements FIPS 186-4 RSA SigVer and FIPS 186-5 RSA SigVer. All RSA modulus lengths (i.e., 2048, 3072, 4096 bits) have been CAVP tested. The CAVP certificates are listed in the Approved Algorithms table.

2.8 RBG and Entropy

Table 10: Entropy Certificates © 2025 IBM / atsec information security.

18 of 71

Page 19
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
IBM Corporation Kernel CPU Time Jitter Entropy source Version 3.4.0Non- PhysicalClevOS 3.19 on Intel® Xeon® 8474C256 bits256 bitsSHA3-256 (A6801)

Table 11: Entropy Sources The module implements three different Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1: Counter DRBG, Hash DRBG, and HMAC DRBG. Each of these DRBG implementations can be instantiated by the operator of the module, using the parameters listed specified in the Security Function Implementations table. When instantiated, these DRBGs can be used to generate random numbers for external usage. Additionally, the module employs a specific HMAC-SHA-512 DRBG implementation for internal purposes (e.g. to generate asymmetric key pairs). The module complies with the Public Use Document for ESV certificate E260 by reading entropy data from the jent_kcapi_random() function, which corresponds to the GetEntropy() conceptual interface. This function outputs 256 bits of full entropy. The HMAC-SHA-512 DRBG is instantiated with a 384-bit entropy input and reseeded with a 256-bits long entropy input. Outputs of multiple GetEntropy() calls are concatenated to receive the entropy input length greater than 256 bits. The output is truncated to get the entropy input string which is not a multiple of 256. The operational environment on the ESV certificate is identical to the operating system described in this document, and the entropy source is implemented inside the cryptographic boundary. Thus, the module is compliant with scenario 1 of IG 9.3.A. There are no maintenance requirements for the entropy source.

2.9 Key Generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800-133r2. When random values are required, they are directly obtained as output from the SP 800-90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2 (without XOR, as described in Additional Comment 2 of IG D.H). The following methods are implemented:

19 of 71

Page 20
2.10 Key Establishment

The module implements shared secret computation methods as listed in the Security Function Implementations table.

2.11 Industry Protocols

AES-GCM with internal IV generation in the approved mode is compliant with RFC 4106 and shall only be used in conjunction with the IPsec protocol. The module implements shared secret computation for DH and ECDH following SP 80056Arev3 No other parts of the TLS or IPSec protocols, other than those mentioned above, have been tested by the CAVP and CMVP. © 2025 IBM / atsec information security.

20 of 71

Page 21
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI data input parameters, AF_ALG type sockets
N/AData OutputAPI output parameters, AF_ALG type sockets
N/AControl InputAPI function calls, API control input parameters, AF_ALG type sockets, kernel command line
N/AStatus OutputAPI return values, AF_ALG type sockets, kernel logs
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. The module does not implement a control output interface. © 2025 IBM / atsec information security.

21 of 71

Page 22
NameTypeOperator TypeAuthentication Methods
CORoleCONone
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Message DigestCompute a message digestcrypto_shash_init returns 0Messag eDigest ValueMessage Digest with SHACO
EncryptionEncrypt a plaintextcrypto_skcipher_setkey returns 0AES Key, plaintex tCipherte xtEncryption and Decryption with AESCO - AES Key: W,E
DecryptionDecrypt a ciphertextcrypto_skcipher_setkey returns 0AES Key, cipherte xtPlaintextEncryption and Decryption with AESCO - AES Key: W,E
Authentica ted EncryptionEncrypt a plaintextFor all except AES GCM: crypto_aead_setkey returns 0; For AES GCM: crypto_aead_get_flags(tfm) has the CRYPTO_TFM_FIPS_COMPLI ANCE flag setAES Key, IV, plaintex tCipherte xt, MAC tagAuthentica ted Encryption and Authentica ted Decryption with AES- CCM Authentica ted Encryption and Authentica ted Decryption with AES- GCM AuthenticaCO - AES Key: W,E
4 Roles, Services, and Authentication
4.2 Roles

Table 13: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators.

4.3 Approved Services

© 2025 IBM / atsec information security.

22 of 71

Page 23
NameDescripti onIndicatorInputsOutputsSecurity Functions ted Encryption and Authentica ted Decryption with AES- CBC or AES-CTR with HMAC Authentica ted Encryption and Authentica ted Decryption with AES- KWSSP Access
Authentica ted DecryptionDecrypt a ciphertextFor all except AES GCM: crypto_aead_setkey returns 0; For AES GCM: crypto_aead_get_flags(tfm) has the CRYPTO_TFM_FIPS_COMPLI ANCE flag setAES key, IV, MAC tag, cipherte xtPlaintext or failureAuthentica ted Encryption and Authentica ted Decryption with AES- CCM Authentica ted Encryption and Authentica ted Decryption with AES- GCM Authentica ted Encryption and Authentica ted Decryption with AES- CBC or AES-CTR with HMAC Authentica ted Encryption and AuthenticaCO - AES Key: W,E

© 2025 IBM / atsec information security.

23 of 71

Page 24
NameDescripti onIndicatorInputsOutputsSecurity Functions ted Decryption with AES- KWSSP Access
Message Authentica tion Code GenerationCompute a MAC tagcrypto_shash_init returns 0AES key or HMAC key, messag eMAC tagMessage Authentica tion Code Generation with AES or HMACCO - AES Key: W,E - HMAC Key: W,E
Message Authentica tion Code Verificatio nVerify a MAC tagcrypto_shash_init returns 0AES key, MAC tag, messag ePass/failMessage Authentica tion Code Verificatio n with AES-GMACCO - AES Key: W,E
Random Number GenerationGenerate random bytescrypto_rng_get_bytes returns 0Output lengthRandom bytesRandom Number Generation with HMAC DRBG, Hash DRBG or Counter DRBGCO - Entropy Input (IG D.L): W,E,Z - CTR_DRB G Seed (IG D.L): G,E - Hash_DR BG Seed (IG D.L): G,E - HMAC_DR BG Seed (IG D.L): G,E - CTR_DRB G Internal State (V, Key) (IG D.L): G,W,E - Hash_DR BG Internal State (V, C) (IG D.L): G,W,E - HMAC_DR

G,E G,E G,E D.L): G,W,E D.L): G,W,E © 2025 IBM / atsec information security.

24 of 71

Page 25
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access BG Internal State (V, Key) (IG D.L): G,W,E
Shared Secret Computati onCompute a shared secretcrypto_kpp_compute_share d_secret returns 0DH private key, DH public key or EC private key, EC public keyShared secretShared Secret Computati on with KAS-FFC- SSC or KAS-ECC- SSCCO - DH Public Key: W,E - DH Private Key: W,E - EC Public Key: W,E - EC Private Key: W,E - Shared Secret: G,R
Key Pair GenerationGenerate a key paircrypto_kpp_set_secret and crypto_kpp_generate_publi c_key return 0Safe Primes: Group; ECDSA: CurveSafe Primes: DH private key, DH public key; ECDSA: EC private key, EC public keyKey Pair Generation with ECDSA or Safe PrimesCO - Intermedi ate Key Generatio n Value: G,E,Z - DH Public Key: G,R - DH Private Key: G,R - EC Public Key: G,R - EC Private Key: G,R
Signature Verificatio nVerify a signaturecrypto_akcipher_init returns 0Signatu re, ECDSA public key, RSA public keyDigital signature verificati on resultSignature Verificatio n with RSA Signature Verificatio n with ECDSA Legacy Signature Verificatio n with RSA LegacyCO - RSA Public Key: W,E - EC Public Key: W,E

D.L): G,W,E G,R © 2025 IBM / atsec information security.

25 of 71

Page 26
NameDescripti onIndicatorInputsOutputsSecurity Functions Signature Verificatio n with ECDSASSP Access
KBKDF Key DerivationDerive a key from a key- derivation keycrypto_kdf108_ctr_generat e returns 0Key- Derivati on KeyKBKDF Derived KeyKey Derivation with KBKDFCO - Key- Derivatio n Key: W,E - KBKDF Derived Key: G,R
OneStep KDA Key DerivationDerive a key from a shared secretcrypto_kdf108_ctr_generat e returns 0Shared SecretKDA OneStep Derived KeyKey Derivation with KDA OneStepCO - Shared Secret: W,E - KDA OneStep Derived Key: G,R
Error Detection CodeCompute an EDC (crc32, crct10dif, crc64- rocksoft)NoneMessag eEDCNoneCO
Compressi onCompress data (deflate, deflate- iaa, lz4, lz4hc, lzo, zstd)NoneDataCompres sed dataNoneCO
Generic System CallUse the kernel to perform various non- cryptogra phic operationsNoneIdentifie r, various argume ntsVarious return valuesNoneCO
Show VersionReturn the module name and version informatio nNoneN/AModule name and versionNoneCO
Show StatusReturn the module statusNoneN/AModule statusNoneCO
Self-TestPerform the CASTs andNoneN/APass/failEncryption and DecryptionCO

n © 2025 IBM / atsec information security.

26 of 71

Page 27

Name

Descripti on integrity tests

Indicator

Inputs

Outputs

Security Functions with AES Random Number Generation with HMAC DRBG, Hash DRBG or Counter DRBG Message Authentica tion Code Generation with AES or HMAC Message Authentica tion Code Verificatio n with AES-GMAC Shared Secret Computati on with KAS-FFC- SSC or KAS-ECC- SSC Message Digest with SHA Key Pair Generation with ECDSA or Safe Primes Authentica ted Encryption and Authentica ted Decryption with AES- CCM Authentica ted Encryption and Authentica

SSP Access

© 2025 IBM / atsec information security.

27 of 71

Page 28
NameDescripti onIndicatorInputsOutputsSecurity Functions ted Decryption with AES- GCM Authentica ted Encryption and Authentica ted Decryption with AES- CBC or AES-CTR with HMAC Authentica ted Encryption and Authentica ted Decryption with AES- KW Signature Verificatio n with RSA Signature Verificatio n with ECDSASSP Access
ZeroizationZeroize all SSPsNoneAny SSPN/ANoneCO - AES Key: Z - HMAC Key: Z - Shared Secret: Z - Entropy Input (IG D.L): Z - CTR_DRB G Seed (IG D.L): Z - Hash_DR BG Seed (IG D.L): Z - HMAC_DR

D.L): Z Z Z © 2025 IBM / atsec information security.

28 of 71

Page 29

Name

Descripti on

Indicator

Inputs

Outputs

Security Functions

SSP Access BG Seed (IG D.L): Z - CTR_DRB G Internal State (V, Key) (IG D.L): Z - Hash_DR BG Internal State (V, C) (IG D.L): Z - HMAC_DR BG Internal State (V, Key) (IG D.L): Z - DH Public Key: Z - DH Private Key: Z - EC Public Key: Z - EC Private Key: Z - Intermedi ate Key Generatio n Value: Z - RSA Public Key: Z - Key- Derivatio n Key: Z - KBKDF Derived Key: Z - KDA OneStep

Z D.L): Z D.L): Z D.L): Z Z © 2025 IBM / atsec information security.

29 of 71

Page 30

Name

Descripti on

Indicator

Inputs

Outputs

Security Functions

SSP Access Derived Key: Z

NameDescriptionAlgorithmsRole
AES-GCM with external IVEncryptionAES-GCM with external IVCO
KBKDF (libkcapi)Key derivationKBKDF (libkcapi)CO
HKDF (libkcapi)Key derivationHKDF (libkcapi)CO
PBKDF2 (libkcapi)Password-based key derivationPBKDF2 (libkcapi)CO
RSAEncryption primitive; Decryption primitiveRSACO
RSA with PKCS#1 v1.5 paddingSignature generation (pre-hashed message); Signature verification (pre-hashed message); Key encapsulation; Key un-encapsulationRSA with PKCS#1 v1.5 paddingCO

Table 14: Approved Services The following convention is used to specify access rights to SSPs:

4.4 Non-Approved Services

Table 15: Non-Approved Services

4.5 External Software/Firmware Loaded

Not applicable. © 2025 IBM / atsec information security.

30 of 71

Page 31
5 Software/Firmware Security
5.1 Integrity Techniques

The kcapi-hasher binary utilizes the module’s HMAC and SHA-512 implementations and verifies it’s integrity test and the libkcapi library integrity followed by the integrity test on the static kernel binary i.e. vmlinuz. The HMAC key used for this integrity test is stored in libkcapi. The kernel object (.ko) files are verified using RSA signature verification with PKCS#1 v1.5 padding, SHA-512, and a 4096-bit key stored in the kernel.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity tests can be invoked on demand by unloading and subsequently re-initializing the module, which will perform (among others) the software integrity tests. © 2025 IBM / atsec information security.

31 of 71

Page 32
6 Operational Environment
6.1 Operational Environment Type and

Requirements Type of Operational Environment: Modifiable How Requirements are Satisfied: the module executes as part of a general-purpose operating system (ClevOS 3.19), which allows modification, loading, and execution of software that is not part of the validated module. The approved cryptographic algorithms of the module are part of the Linux kernel, which operates in Linux kernel space. This ensures that any SSPs contained within the module are protected by the process isolation and memory separation mechanisms provided by the Linux kernel, and only the module has control over these SSPs. The user space libkcapi and kcapi-hasher components, though not processing any SSPs, are similarly protected by the operating environment.

6.2 Configuration Settings and Restrictions

The module shall be installed as specified in Section 11.1. Instrumentation tools like the ptrace system call, gdb and strace, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2025 IBM / atsec information security.

32 of 71

Page 33
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. © 2025 IBM / atsec information security.

33 of 71

Page 34
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2025 IBM / atsec information security.

34 of 71

Page 35
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service executionDynamic

Name API input parameters; AF_ALG_type sockets (input) API output parameters; AF_ALG type sockets (output)

From Operator calling application (TOEPP) Cryptographic module

To Cryptographic module Operator calling application (TOEPP)

Format Type Plaintext Plaintext

Distribution Type Manual Manual

Entry Type Electronic Electronic

SFI or Algorithm

Zeroization MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the cipher handleMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievableBy calling the appropriate zeroization functions: AES key: crypto_free_skcipher and crypto_free_aead; HMAC key: crypto_free_shash and crypto_free_ahash; Internal state: crypto_free_rng; DH public & private key: crypto_free_kpp; EC public & private key: crypto_free_kpp; Key- Derivation Key: memzero_explicit; KBKDF Derived Key: memzero_explicit; KDA OneStep Derived Key: memzero_explicit
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, whichN/A
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 16: Storage Areas The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in destroyed when released by the appropriate zeroization function calls. Table 17: SSP Input-Output Methods © 2025 IBM / atsec information security.

35 of 71

Page 36
Zeroization MethodDescriptionRationale renders the SSP values irretrievable.Operator Initiation
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed.By removing power

Name AES Key HMAC Key Shared Secret

Description AES key used for Encryption; Decryption; Authenticated encryption; Authenticated decryption; Message authenticatio n; HMAC key used for Message authenticatio n code (MAC); Shared secret established during Shared Secret Computation

Size - Strength XTS: 128, 256 bits; ECB, CBC, CTR, CFB128, CBC- CS3, KW, OFB, CCM, GCM, CMAC, GMAC: 128, 192, 256 bits - XTS: 128, 256 bits; ECB, CBC, CTR, CFB128, CBC- CS3, KW, OFB, CCM, GCM, CMAC, GMAC: 128, 192, 256 bits 112-524288 bits - 112-256 bits KAS-FFC- SSC:ffdhe204 8, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192; KAS-ECC-SSC: P-256, P-384 bits - KAS-

Type - Category Symmetric key - CSP Symmetric key - CSP Shared secret - CSP

Generate d By

Establishe d By Shared Secret Computatio n with KAS- FFC-SSC or KAS-ECC- SSC

Used By Encryption and Decryption with AES Message Authenticatio n Code Generation with AES or HMAC Message Authenticatio n Code Verification with AES- GMAC Message Authenticatio n Code Generation with AES or HMAC Key Derivation with KDA OneStep

Table 18: SSP Zeroization Methods All data output is inhibited during zeroization. © 2025 IBM / atsec information security.

36 of 71

Page 37

Name Entropy Input (IG D.L) CTR_DRBG Seed (IG D.L) Hash_DRBG Seed (IG D.L) HMAC_DRB G Seed (IG D.L) CTR_DRBG Internal State (V, Key) (IG D.L)

Description Entropy input used to seed the DRBGs DRBG seed derived from Entropy Input DRBG seed derived from Entropy Input DRBG seed derived from Entropy Input Internal state of Counter DRBG instance

Size - Strength FFC-SSC: 112- 200 bits; KAS- ECC-SSC: 128, 192 bits 128-384 bits - 128-384 bits 256, 320, 384 bits - 128, 192, 256 bits 440, 888 bits - 128, 256 bits 440, 888 bits - 128, 256 bits 256, 320, 384 bits - 128, 192, 256 bits

Type - Category Entropy input - CSP Seed - CSP Seed - CSP Seed - CSP Internal state - CSP

Generate d By Random Number Generatio n with HMAC DRBG, Hash DRBG or Counter DRBG Random Number Generatio n with HMAC DRBG, Hash DRBG or Counter DRBG Random Number Generatio n with HMAC DRBG, Hash DRBG or Counter DRBG Random Number Generatio n with HMAC DRBG, Hash DRBG or Counter DRBG

Establishe d By

Used By Random Number Generation with HMAC DRBG, Hash DRBG or Counter DRBG Random Number Generation with HMAC DRBG, Hash DRBG or Counter DRBG Random Number Generation with HMAC DRBG, Hash DRBG or Counter DRBG Random Number Generation with HMAC DRBG, Hash DRBG or Counter DRBG Random Number Generation with HMAC DRBG, Hash DRBG or Counter DRBG

© 2025 IBM / atsec information security.

37 of 71

Page 38

Name Hash_DRBG Internal State (V, C) (IG D.L) HMAC_DRB G Internal State (V, Key) (IG D.L) DH Public Key DH Private Key EC Public Key EC Private Key Intermediat e Key Generation Value

Description Internal state of Hash DRBG instance Internal state of HMAC DRBG instance Public key used for KAS- FFC-SSC DH private key used for KAS-FFC-SSC Public key used for KAS- ECC-SSC EC private key used for KAS-ECC-SSC Intermediate value generated during Key Pair Generation

Size - Strength 880, 1776 bits - 128, 256 bits 320, 512, 1024 bits - 128, 256 bits ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 - 112-200 bits ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 - 112-200 bits P-256, P-384 - 128, 192 bits P-521, P-384 - 128, 192 bits 192-8192 bits - 112-256 bits

Type - Category Internal state - CSP Internal state - CSP Public key - PSP Private key - CSP Public key - PSP Private key - CSP Intermediat e value - CSP

Generate d By Random Number Generatio n with HMAC DRBG, Hash DRBG or Counter DRBG Random Number Generatio n with HMAC DRBG, Hash DRBG or Counter DRBG Key Pair Generatio n with ECDSA or Safe Primes Key Pair Generatio n with ECDSA or Safe Primes Key Pair Generatio n with ECDSA or Safe Primes Key Pair Generatio n with ECDSA or Safe Primes Key Pair Generatio n with ECDSA or Safe Primes

Establishe d By

Used By Random Number Generation with HMAC DRBG, Hash DRBG or Counter DRBG Random Number Generation with HMAC DRBG, Hash DRBG or Counter DRBG Shared Secret Computation with KAS- FFC-SSC or KAS-ECC-SSC Shared Secret Computation with KAS- FFC-SSC or KAS-ECC-SSC Shared Secret Computation with KAS- FFC-SSC or KAS-ECC-SSC Signature Verification with ECDSA Shared Secret Computation with KAS- FFC-SSC or KAS-ECC-SSC Key Pair Generation with ECDSA or Safe Primes

© 2025 IBM / atsec information security.

38 of 71

Page 39

Name RSA Public Key Key- Derivation Key KBKDF Derived Key KDA OneStep Derived Key

Description RSA Public key used for Signature Verification with RSA Used for key derivation Generated by key-based key derivation Generated by OneStep KDA key derivation

Size - Strength 2048-4096 bits - 112-150 bits 112-4096 bits - 112-256 bits 112-4096 bits - 112-256 bits 2048 bits - 112 bits

Type - Category Public key - PSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP

Generate d By Key Derivation with KBKDF Key Derivation with KDA OneStep

Establishe d By

Used By Signature Verification with RSA Key Derivation with KBKDF

Name AES Key HMAC KeyInput - Output API input parameters; AF_ALG_type sockets (input) API input parameters; AF_ALG_type sockets (input)Storage RAM:Plaintext RAM:PlaintextStorage Duration From service invocation to service completion From service invocation to service completionZeroization Free cipher handle Remove power from the module Free cipher handle Remove power from the moduleRelated SSPs
Shared SecretAPI output parameters; AF_ALG type sockets (output)RAM:PlaintextFrom service invocation to service completionFree cipher handle Remove power from the moduleDH Public Key:Derived From DH Private Key:Derived From EC Public Key:Derived From EC Private Key:Derived From
Entropy Input (IG D.L)RAM:PlaintextFrom service invocation to service completionAutomatic Remove power from the moduleCTR_DRBG Seed (IG D.L):Derives Hash_DRBG Seed (IG D.L):Derives HMAC_DRBG Seed (IG D.L):Derives
CTR_DRBG Seed (IG D.L)RAM:PlaintextFrom service invocation to service completionAutomatic Remove power from the moduleEntropy Input (IG D.L):Derived From CTR_DRBG Internal State (V, Key) (IG D.L):Derives
Hash_DRBG Seed (IG D.L)RAM:PlaintextFrom service invocation toAutomatic RemoveEntropy Input (IG D.L):Derived From Hash_DRBG

Table 19: SSP Table 1 © 2025 IBM / atsec information security.

39 of 71

Page 40
Name HMAC_DRBG Seed (IG D.L) CTR_DRBG Internal State (V, Key) (IG D.L) Hash_DRBG Internal State (V, C) (IG D.L) HMAC_DRBG Internal State (V, Key) (IG D.L)Input - OutputStorage RAM:Plaintext RAM:Plaintext RAM:Plaintext RAM:PlaintextStorage Duration service completion From service invocation to service completion From service invocation to service completion From service invocation to service completion From service invocation to service completionZeroization power from the module Automatic Remove power from the module Free cipher handle Remove power from the module Free cipher handle Remove power from the module Free cipher handle Remove power from the moduleRelated SSPs Internal State (V, C) (IG D.L):Derives Entropy Input (IG D.L):Derived From HMAC_DRBG Internal State (V, Key) (IG D.L):Derives CTR_DRBG Seed (IG D.L):Derived From Hash_DRBG Seed (IG D.L):Derived From HMAC_DRBG Seed (IG D.L):Derived From
DH Public KeyAPI input parameters; AF_ALG_type sockets (input) API output parameters; AF_ALG type sockets (output)RAM:PlaintextFrom service invocation to service completionFree cipher handle Remove power from the moduleDH Private Key:Paired With Shared Secret:Derives Intermediate Key Generation Value:Generated From
DH Private KeyAPI input parameters; AF_ALG_type sockets (input) API output parameters; AF_ALG type sockets (output)RAM:PlaintextFrom service invocation to service completionFree cipher handle Remove power from the moduleDH Public Key:Paired With Shared Secret:Derives Intermediate Key Generation Value:Generated From
EC Public KeyAPI input parameters; AF_ALG_type sockets (input) API output parameters; AF_ALG type sockets (output)RAM:PlaintextFrom service invocation to service completionFree cipher handle Remove power from the moduleEC Private Key:Paired With Shared Secret:Derives Intermediate Key Generation Value:Generated From
EC Private KeyAPI input parameters; AF_ALG_typeRAM:PlaintextFrom service invocation toFree cipher handle RemoveEC Public Key:Paired With Shared

© 2025 IBM / atsec information security.

40 of 71

Page 41
Name Intermediate Key Generation Value RSA Public KeyInput - Output sockets (input) API output parameters; AF_ALG type sockets (output) API input parameters; AF_ALG_type sockets (input)Storage RAM:Plaintext RAM:PlaintextStorage Duration service completion From service invocation to service completion From service invocation to service completionZeroization power from the module Automatic AutomaticRelated SSPs Secret:Derives Intermediate Key Generation Value:Generated From DH Public Key:Generates DH Private Key:Generates EC Public Key:Generates EC Private Key:Generates
Key- Derivation KeyAPI input parameters; AF_ALG_type sockets (input)RAM:PlaintextFrom service invocation to service completionFree cipher handle Remove power from the moduleKBKDF Derived Key:Derives
KBKDF Derived KeyAPI output parameters; AF_ALG type sockets (output)RAM:PlaintextFrom service invocation to service completionFree cipher handle Remove power from the moduleKey-Derivation Key:Derived From
KDA OneStep Derived KeyAPI output parameters; AF_ALG type sockets (output)RAM:PlaintextFrom service invocation to service completionFree cipher handle Remove power from the moduleShared Secret:Derived From
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. © 2025 IBM / atsec information security.

41 of 71

Page 42
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2- 512 (A6817) - kernel128-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useUsed for kernel binary
HMAC-SHA2- 512 (A6817) - libkcapi128-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useUsed for libkcapi shared library
HMAC-SHA2- 512 (A6817) - kcapi-hasher128-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useUsed for kcapi- hasher binary
RSA SigVer (FIPS186-5) (A6801)4096-bit key with SHA-512Signature VerificationSW/FW IntegrityModule becomes operational and services are available for useUsed for kernel object files
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A6801) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6804) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6805) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6806) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 21: Pre-Operational Self-Tests The pre-operational software integrity tests are performed automatically when the module is powered on, before the module transitions into the operational state. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module transitions to the operational state only after the pre-operational self-tests are passed successfully.

10.2 Conditional Self-Tests

© 2025 IBM / atsec information security.

42 of 71

Page 43
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A6807) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6808) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6809) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6810) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6811) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6812) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6813) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6814) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CBC (A6801) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CBC (A6806) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CBC (A6809) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CBC (A6812) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CBC-CS3 (A6801) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

43 of 71

Page 44
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC-CS3 (A6806) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CBC-CS3 (A6809) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CBC-CS3 (A6812) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CTR (A6801) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CTR (A6806) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CTR (A6809) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CTR (A6812) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CCM (A6801) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CCM (A6806) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-CCM (A6812) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6801) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6804) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6805) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

44 of 71

Page 45
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A6806) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6807) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6808) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6809) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6810) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6811) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6812) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6813) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-GCM (A6814) - Encrypt128-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-XTS Testing Revision 2.0 (A6801) - Encrypt128-bit and 256-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-XTS Testing Revision 2.0 (A6806) - Encrypt128-bit and 256-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-XTS Testing Revision 2.0 (A6809) - Encrypt128-bit and 256-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

45 of 71

Page 46
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-XTS Testing Revision 2.0 (A6812) - Encrypt128-bit and 256-bit keyKATCASTModule becomes operationalEncryptionTest runs at power-on before the integrity test
AES-ECB (A6801) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6804) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6805) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6806) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6807) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6808) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6809) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6810) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6811) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6812) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6813) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-ECB (A6814) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on

© 2025 IBM / atsec information security.

46 of 71

Page 47
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions before the integrity test
AES-CBC (A6801) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CBC (A6806) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CBC (A6809) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CBC (A6812) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CBC-CS3 (A6801) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CBC-CS3 (A6806) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CBC-CS3 (A6809) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CBC-CS3 (A6812) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CTR (A6801) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CTR (A6806) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CTR (A6809) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CTR (A6812) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

47 of 71

Page 48
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CCM (A6801) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CCM (A6806) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CCM (A6812) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6801) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6804) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6805) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6806) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6807) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6808) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6809) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6810) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6811) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6812) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

48 of 71

Page 49
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A6813) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-GCM (A6814) - Decrypt128-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-XTS Testing Revision 2.0 (A6801) - Decrypt128-bit and 256-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-XTS Testing Revision 2.0 (A6806) - Decrypt128-bit and 256-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-XTS Testing Revision 2.0 (A6809) - Decrypt128-bit and 256-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-XTS Testing Revision 2.0 (A6812) - Decrypt128-bit and 256-bit keyKATCASTModule becomes operationalDecryptionTest runs at power-on before the integrity test
AES-CMAC (A6801)128-bit and 256-bit keyKATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
AES-CMAC (A6806)128-bit and 256-bit keyKATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
AES-CMAC (A6812)128-bit and 256-bit keyKATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
SHA-1 (A6801)SHA-1KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A6815)SHA-1KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A6816)SHA-1KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

49 of 71

Page 50
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A6817)SHA-1KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A6818)SHA-1KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-224 (A6801)SHA2-224KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-224 (A6815)SHA2-224KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-224 (A6816)SHA2-224KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-224 (A6817)SHA2-224KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-224 (A6818)SHA2-224KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-256 (A6801)SHA2-256KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-256 (A6815)SHA2-256KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-256 (A6816)SHA2-256KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-256 (A6817)SHA2-256KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-256 (A6818)SHA2-256KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-384 (A6801)SHA2-384KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

50 of 71

Page 51
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA2-384 (A6815)SHA2-384KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-384 (A6816)SHA2-384KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-384 (A6817)SHA2-384KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A6801)SHA2-512KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A6815)SHA2-512KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A6816)SHA2-512KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A6817)SHA2-512KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA3-224 (A6801)SHA3-224KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA3-256 (A6801)SHA3-256KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA3-384 (A6801)SHA3-384KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA3-512 (A6801)SHA3-512KATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
HMAC-SHA-1 (A6801)SHA-1KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA-1 (A6815)SHA-1KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

51 of 71

Page 52
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC-SHA-1 (A6816)SHA-1KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA-1 (A6817)SHA-1KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA-1 (A6818)SHA-1KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 224 (A6801)SHA2-224KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 224 (A6815)SHA2-224KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 224 (A6816)SHA2-224KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 224 (A6817)SHA2-224KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 224 (A6818)SHA2-224KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A6801)SHA2-256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A6815)SHA2-256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A6816)SHA2-256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A6817)SHA2-256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A6818)SHA2-256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

52 of 71

Page 53
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC-SHA2- 384 (A6801)SHA2-384KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 384 (A6815)SHA2-384KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 384 (A6816)SHA2-384KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 384 (A6817)SHA2-384KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 512 (A6801)SHA2-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 512 (A6815)SHA2-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 512 (A6816)SHA2-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 512 (A6817)SHA2-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA3- 224 (A6801)SHA3-224KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA3- 256 (A6801)SHA3-256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA3- 384 (A6801)SHA3-384KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA3- 512 (A6801)SHA3-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
Counter DRBG (A6801)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed,Test runs at power-on before the integrity test

© 2025 IBM / atsec information security.

53 of 71

Page 54
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails generate) health testConditions
Counter DRBG (A6804)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Counter DRBG (A6805)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Counter DRBG (A6806)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Counter DRBG (A6807)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Counter DRBG (A6808)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Counter DRBG (A6809)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Counter DRBG (A6810)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Counter DRBG (A6811)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Counter DRBG (A6812)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Counter DRBG (A6813)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

54 of 71

Page 55
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Counter DRBG (A6814)128, 192, 256 bit keys, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Hash DRBG (A6801)SHA2-256 With/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Hash DRBG (A6815)SHA2-256 With/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Hash DRBG (A6816)SHA2-256 With/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
Hash DRBG (A6817)SHA2-256 With/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
HMAC DRBG (A6801)HMAC-SHA2- 256, HMAC- SHA2-512, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
HMAC DRBG (A6815)HMAC-SHA2- 256, HMAC- SHA2-512, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
HMAC DRBG (A6816)HMAC-SHA2- 256, HMAC- SHA2-512, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
HMAC DRBG (A6817)HMAC-SHA2- 256, HMAC- SHA2-512, with/without PRKATCASTModule becomes operationalSP 800-90Ar1 (instantiate, reseed, generate) health testTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A6801)P-256, P-384 curvesKATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-FFC-SSC Sp800-56Ar3 (A6801)ffdhe2048KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test

© 2025 IBM / atsec information security.

55 of 71

Page 56
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigVer (FIPS186-4) (A6801)PKCS#1 v1.5 with 2048 bit key and SHA2- 256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A6801)PKCS#1 v1.5 with 2048 bit key and SHA2- 256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A6802)SHA2-256, P- 256 curveKATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A6802)SHA2-256, P- 256 curveKATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
KDF SP800- 108 (A6803)Counter mode; HMAC-SHA-256; 256-bit input keyKATCASTModule becomes operationalKey based key derivationTest runs at power-on before the integrity test
Safe Primes Key Generation (A6801)ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, Section 5.6.1.1.4 Testing CandidatesPCTPCTSuccessful key pair generationSP 800- 56ARev3, 5.6.2.1.4Key pair generation
ECDSA KeyGen (FIPS186-5) (A6801)SHA2-256, P- 256, P-384 curves, Appendix A.2.2 Rejection SamplingPCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
KDA OneStep SP800-56Cr2 (A6803)SHA2-256KATCASTModule becomes operationalShared secret key derivationTest runs at power-on before the integrity test
Entropy Source Initialization RCT1024 samplesRCTCASTModule becomes operational and services are available for useEntropy source startup testEntropy source initialization
Entropy Source Initialization APT1024 samplesAPTCASTModule becomes operational and services are available for useEntropy source startup testEntropy source initialization
5.6.1.1.4 © 2025 IBM / atsec information security.

56 of 71

Page 57
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Entropy Source Operational RCTIntermittent Cutoff: 31 samples, Permanent Cutoff: 61 samplesRCTCASTEntropy source is operationalEntropy source continuous testContinuously
Entropy Source Operational APT512 samples, Intermittent Cutoff: 325 samples, Permanent Cutoff: 355 samplesAPTCASTEntropy source is operationalEntropy source continuous testContinuously
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-512 (A6817) - kernelMessage AuthenticationSW/FW IntegrityOn DemandManually
HMAC-SHA2-512 (A6817) - libkcapiMessage AuthenticationSW/FW IntegrityOn DemandManually
HMAC-SHA2-512 (A6817) - kcapi- hasherMessage AuthenticationSW/FW IntegrityOn DemandManually
RSA SigVer (FIPS186-5) (A6801)Signature VerificationSW/FW IntegrityOn DemandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A6801) - EncryptKATCASTOn DemandManually
AES-ECB (A6804) - EncryptKATCASTOn DemandManually
AES-ECB (A6805) - EncryptKATCASTOn DemandManually
AES-ECB (A6806) - EncryptKATCASTOn DemandManually
AES-ECB (A6807) - EncryptKATCASTOn DemandManually
AES-ECB (A6808) - EncryptKATCASTOn DemandManually
AES-ECB (A6809) - EncryptKATCASTOn DemandManually
AES-ECB (A6810) - EncryptKATCASTOn DemandManually

Table 22: Conditional Self-Tests

10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information © 2025 IBM / atsec information security.

57 of 71

Page 58
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A6811) - EncryptKATCASTOn DemandManually
AES-ECB (A6812) - EncryptKATCASTOn DemandManually
AES-ECB (A6813) - EncryptKATCASTOn DemandManually
AES-ECB (A6814) - EncryptKATCASTOn DemandManually
AES-CBC (A6801) - EncryptKATCASTOn DemandManually
AES-CBC (A6806) - EncryptKATCASTOn DemandManually
AES-CBC (A6809) - EncryptKATCASTOn DemandManually
AES-CBC (A6812) - EncryptKATCASTOn DemandManually
AES-CBC-CS3 (A6801) - EncryptKATCASTOn DemandManually
AES-CBC-CS3 (A6806) - EncryptKATCASTOn DemandManually
AES-CBC-CS3 (A6809) - EncryptKATCASTOn DemandManually
AES-CBC-CS3 (A6812) - EncryptKATCASTOn DemandManually
AES-CTR (A6801) - EncryptKATCASTOn DemandManually
AES-CTR (A6806) - EncryptKATCASTOn DemandManually
AES-CTR (A6809) - EncryptKATCASTOn DemandManually
AES-CTR (A6812) - EncryptKATCASTOn DemandManually
AES-CCM (A6801) - EncryptKATCASTOn DemandManually
AES-CCM (A6806) - EncryptKATCASTOn DemandManually
AES-CCM (A6812) - EncryptKATCASTOn DemandManually
AES-GCM (A6801) - EncryptKATCASTOn DemandManually
AES-GCM (A6804) - EncryptKATCASTOn DemandManually
AES-GCM (A6805) - EncryptKATCASTOn DemandManually
AES-GCM (A6806) - EncryptKATCASTOn DemandManually
AES-GCM (A6807) - EncryptKATCASTOn DemandManually
AES-GCM (A6808) - EncryptKATCASTOn DemandManually
AES-GCM (A6809) - EncryptKATCASTOn DemandManually

© 2025 IBM / atsec information security.

58 of 71

Page 59
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A6810) - EncryptKATCASTOn DemandManually
AES-GCM (A6811) - EncryptKATCASTOn DemandManually
AES-GCM (A6812) - EncryptKATCASTOn DemandManually
AES-GCM (A6813) - EncryptKATCASTOn DemandManually
AES-GCM (A6814) - EncryptKATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A6801) - EncryptKATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A6806) - EncryptKATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A6809) - EncryptKATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A6812) - EncryptKATCASTOn DemandManually
AES-ECB (A6801) - DecryptKATCASTOn DemandManually
AES-ECB (A6804) - DecryptKATCASTOn DemandManually
AES-ECB (A6805) - DecryptKATCASTOn DemandManually
AES-ECB (A6806) - DecryptKATCASTOn DemandManually
AES-ECB (A6807) - DecryptKATCASTOn DemandManually
AES-ECB (A6808) - DecryptKATCASTOn DemandManually
AES-ECB (A6809) - DecryptKATCASTOn DemandManually
AES-ECB (A6810) - DecryptKATCASTOn DemandManually
AES-ECB (A6811) - DecryptKATCASTOn DemandManually
AES-ECB (A6812) - DecryptKATCASTOn DemandManually
AES-ECB (A6813) - DecryptKATCASTOn DemandManually
AES-ECB (A6814) - DecryptKATCASTOn DemandManually
AES-CBC (A6801) - DecryptKATCASTOn DemandManually
AES-CBC (A6806) - DecryptKATCASTOn DemandManually
AES-CBC (A6809) - DecryptKATCASTOn DemandManually

© 2025 IBM / atsec information security.

59 of 71

Page 60
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A6812) - DecryptKATCASTOn DemandManually
AES-CBC-CS3 (A6801) - DecryptKATCASTOn DemandManually
AES-CBC-CS3 (A6806) - DecryptKATCASTOn DemandManually
AES-CBC-CS3 (A6809) - DecryptKATCASTOn DemandManually
AES-CBC-CS3 (A6812) - DecryptKATCASTOn DemandManually
AES-CTR (A6801) - DecryptKATCASTOn DemandManually
AES-CTR (A6806) - DecryptKATCASTOn DemandManually
AES-CTR (A6809) - DecryptKATCASTOn DemandManually
AES-CTR (A6812) - DecryptKATCASTOn DemandManually
AES-CCM (A6801) - DecryptKATCASTOn DemandManually
AES-CCM (A6806) - DecryptKATCASTOn DemandManually
AES-CCM (A6812) - DecryptKATCASTOn DemandManually
AES-GCM (A6801) - DecryptKATCASTOn DemandManually
AES-GCM (A6804) - DecryptKATCASTOn DemandManually
AES-GCM (A6805) - DecryptKATCASTOn DemandManually
AES-GCM (A6806) - DecryptKATCASTOn DemandManually
AES-GCM (A6807) - DecryptKATCASTOn DemandManually
AES-GCM (A6808) - DecryptKATCASTOn DemandManually
AES-GCM (A6809) - DecryptKATCASTOn DemandManually
AES-GCM (A6810) - DecryptKATCASTOn DemandManually
AES-GCM (A6811) - DecryptKATCASTOn DemandManually
AES-GCM (A6812) - DecryptKATCASTOn DemandManually
AES-GCM (A6813) - DecryptKATCASTOn DemandManually
AES-GCM (A6814) - DecryptKATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A6801) - DecryptKATCASTOn DemandManually

© 2025 IBM / atsec information security.

60 of 71

Page 61
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-XTS Testing Revision 2.0 (A6806) - DecryptKATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A6809) - DecryptKATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A6812) - DecryptKATCASTOn DemandManually
AES-CMAC (A6801)KATCASTOn DemandManually
AES-CMAC (A6806)KATCASTOn DemandManually
AES-CMAC (A6812)KATCASTOn DemandManually
SHA-1 (A6801)KATCASTOn DemandManually
SHA-1 (A6815)KATCASTOn DemandManually
SHA-1 (A6816)KATCASTOn DemandManually
SHA-1 (A6817)KATCASTOn DemandManually
SHA-1 (A6818)KATCASTOn DemandManually
SHA2-224 (A6801)KATCASTOn DemandManually
SHA2-224 (A6815)KATCASTOn DemandManually
SHA2-224 (A6816)KATCASTOn DemandManually
SHA2-224 (A6817)KATCASTOn DemandManually
SHA2-224 (A6818)KATCASTOn DemandManually
SHA2-256 (A6801)KATCASTOn DemandManually
SHA2-256 (A6815)KATCASTOn DemandManually
SHA2-256 (A6816)KATCASTOn DemandManually
SHA2-256 (A6817)KATCASTOn DemandManually
SHA2-256 (A6818)KATCASTOn DemandManually
SHA2-384 (A6801)KATCASTOn DemandManually
SHA2-384 (A6815)KATCASTOn DemandManually
SHA2-384 (A6816)KATCASTOn DemandManually
SHA2-384 (A6817)KATCASTOn DemandManually
SHA2-512 (A6801)KATCASTOn DemandManually
SHA2-512 (A6815)KATCASTOn DemandManually

© 2025 IBM / atsec information security.

61 of 71

Page 62
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-512 (A6816)KATCASTOn DemandManually
SHA2-512 (A6817)KATCASTOn DemandManually
SHA3-224 (A6801)KATCASTOn DemandManually
SHA3-256 (A6801)KATCASTOn DemandManually
SHA3-384 (A6801)KATCASTOn DemandManually
SHA3-512 (A6801)KATCASTOn DemandManually
HMAC-SHA-1 (A6801)KATCASTOn DemandManually
HMAC-SHA-1 (A6815)KATCASTOn DemandManually
HMAC-SHA-1 (A6816)KATCASTOn DemandManually
HMAC-SHA-1 (A6817)KATCASTOn DemandManually
HMAC-SHA-1 (A6818)KATCASTOn DemandManually
HMAC-SHA2-224 (A6801)KATCASTOn DemandManually
HMAC-SHA2-224 (A6815)KATCASTOn DemandManually
HMAC-SHA2-224 (A6816)KATCASTOn DemandManually
HMAC-SHA2-224 (A6817)KATCASTOn DemandManually
HMAC-SHA2-224 (A6818)KATCASTOn DemandManually
HMAC-SHA2-256 (A6801)KATCASTOn DemandManually
HMAC-SHA2-256 (A6815)KATCASTOn DemandManually
HMAC-SHA2-256 (A6816)KATCASTOn DemandManually
HMAC-SHA2-256 (A6817)KATCASTOn DemandManually
HMAC-SHA2-256 (A6818)KATCASTOn DemandManually
HMAC-SHA2-384 (A6801)KATCASTOn DemandManually
HMAC-SHA2-384 (A6815)KATCASTOn DemandManually
HMAC-SHA2-384 (A6816)KATCASTOn DemandManually
HMAC-SHA2-384 (A6817)KATCASTOn DemandManually
HMAC-SHA2-512 (A6801)KATCASTOn DemandManually

© 2025 IBM / atsec information security.

62 of 71

Page 63
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-512 (A6815)KATCASTOn DemandManually
HMAC-SHA2-512 (A6816)KATCASTOn DemandManually
HMAC-SHA2-512 (A6817)KATCASTOn DemandManually
HMAC-SHA3-224 (A6801)KATCASTOn DemandManually
HMAC-SHA3-256 (A6801)KATCASTOn DemandManually
HMAC-SHA3-384 (A6801)KATCASTOn DemandManually
HMAC-SHA3-512 (A6801)KATCASTOn DemandManually
Counter DRBG (A6801)KATCASTOn DemandManually
Counter DRBG (A6804)KATCASTOn DemandManually
Counter DRBG (A6805)KATCASTOn DemandManually
Counter DRBG (A6806)KATCASTOn DemandManually
Counter DRBG (A6807)KATCASTOn DemandManually
Counter DRBG (A6808)KATCASTOn DemandManually
Counter DRBG (A6809)KATCASTOn DemandManually
Counter DRBG (A6810)KATCASTOn DemandManually
Counter DRBG (A6811)KATCASTOn DemandManually
Counter DRBG (A6812)KATCASTOn DemandManually
Counter DRBG (A6813)KATCASTOn DemandManually
Counter DRBG (A6814)KATCASTOn DemandManually
Hash DRBG (A6801)KATCASTOn DemandManually
Hash DRBG (A6815)KATCASTOn DemandManually
Hash DRBG (A6816)KATCASTOn DemandManually
Hash DRBG (A6817)KATCASTOn DemandManually
HMAC DRBG (A6801)KATCASTOn DemandManually
HMAC DRBG (A6815)KATCASTOn DemandManually
HMAC DRBG (A6816)KATCASTOn DemandManually

© 2025 IBM / atsec information security.

63 of 71

Page 64
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC DRBG (A6817)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A6801)KATCASTOn DemandManually
KAS-FFC-SSC Sp800-56Ar3 (A6801)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A6801)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A6801)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A6802)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A6802)KATCASTOn DemandManually
KDF SP800-108 (A6803)KATCASTOn DemandManually
Safe Primes Key Generation (A6801)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A6801)PCTPCTOn DemandManually
KDA OneStep SP800-56Cr2 (A6803)KATCASTOn DemandManually
Entropy Source Initialization RCTRCTCASTOn DemandManually
Entropy Source Initialization APTAPTCASTOn DemandManually
Entropy Source Operational RCTRCTCASTOn DemandManually
Entropy Source Operational APTAPTCASTOn DemandManually
NameDescriptionConditionsRecovery MethodIndicator
Error StateThe Linux kernel immediately stops executingAny self-test failureRestart of the moduleKernel Panic

Table 24: Conditional Periodic Information

10.4 Error States

Table 25: Error States In the Error State, the output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). © 2025 IBM / atsec information security.

64 of 71

Page 65
10.5 Operator Initiation of Self-Tests

The software integrity tests, cryptographic algorithm self-tests, and entropy source start-up tests can be invoked on demand by unloading and subsequently re-initializing the module. The pair-wise consistency tests can be invoked on demand by requesting the key pair generation service. © 2025 IBM / atsec information security.

65 of 71

Page 66
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup

Procedures On the ClevOS 3.19 operational environment, the module is distributed within the clevos3.19.2.F1606-44_fips-accesser-usbiso.iso image. There are no specific steps for installing the module, the module is installed as part of operating system.

11.2 Administrator Guidance

The Approved and non-Approved modes of operation are specified in section 2.4. The administrative functions are specified in the Approved Services table. All the physical ports and logical interfaces are specified in section 3.1. The Crypto Officer must execute the Show version service using following commands: $ cat /proc/sys/crypto/fips_name The Crypto Officer must ensure that the proper name is listed in the output as follows: IBM COS Linux Kernel Cryptographic API Then, the Crypto Officer must execute: $ cat /proc/sys/crypto/fips_version This command must output the following version for kernel components: 3.0 Then, the Crypto Officer must execute: $ apt list --installed | grep libkcapi This command must output the following version for libkcapi and kcapi-hasher components: 1.5.0-1 amd64 On the ClevOS 3.19 operational environments, versions of the installed packages can be verified using the following command: $ dpkg-query -W linux-image-6.1.0-32-amd64 libkcapi1 kcapi-tools © 2025 IBM / atsec information security.

66 of 71

Page 67
11.3 Non-Administrator Guidance

The approved and non-approved security functions available to users are listed in section 2, the physical ports, and logical interfaces available to users are specified in section 3.1. The Approved and non-Approved modes of operation are specified in section 2.4. The algorithmspecific information is listed in section 2.7.

11.4 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. If desired, the linux-image-6.1.0-32-amd64, libkcapi1, and kcapi-tools deb packages can be uninstalled from the ClevOS 3.19 system. © 2025 IBM / atsec information security.

67 of 71

Page 68
12 Mitigation of Other Attacks

The module does not offer mitigation of other attacks and therefore this section is not applicable. © 2025 IBM / atsec information security.

68 of 71

Page 69
Table, extracted as text (did not parse into structured rows)
Appendix A. Glossary and Abbreviations AES                Advanced Encryption Standard API                Application Programming Interface CAST               Cryptographic Algorithm Self-Test CAVP               Cryptographic Algorithm Validation Program CBC                Cipher Block Chaining CCM                Counter with Cipher Block Chaining-Message Authentication Code CFB                Cipher Feedback CKG                Cryptographic Key Generation CMAC               Cipher-based Message Authentication Code CMVP               Cryptographic Module Validation Program CSP                Critical Security Parameter CTR                Counter CTS                Ciphertext Stealing DRBG               Deterministic Random Bit Generator ECB                Electronic Code Book ECC                Elliptic Curve Cryptography ECDH               Elliptic Curve Diffie-Hellman ECDSA              Elliptic Curve Digital Signature Algorithm FFC                Finite Field Cryptography FIPS               Federal Information Processing Standards GCM                Galois Counter Mode GMAC               Galois Counter Mode Message Authentication Code HKDF               HMAC-based Key Derivation Function HMAC               Keyed-Hash Message Authentication Code IPsec              Internet Protocol Security KAS                Key Agreement Scheme KAT                Known Answer Test KBKDF              Key-based Key Derivation Function KW                 Key Wrap MAC                Message Authentication Code NIST               National Institute of Science and Technology OFB                Output Feedback PAA                Processor Algorithm Acceleration PAI                Processor Algorithm Implementation PCT                Pair-wise Consistency Test PBKDF2             Password-based Key Derivation Function v2 PKCS               Public-Key Cryptography Standards RSA                Rivest, Shamir, Addleman SHA                Secure Hash Algorithm SSC                Shared Secret Computation SSP                Sensitive Security Parameter XTS                XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 IBM / atsec information security.

69 of 71

Page 70

Appendix B. References FIPS 140-3 FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf FIPS 140-3 IG Implementation Guidance for FIPS PUB 140-3 and the (Last Update: Cryptographic Module Validation Program April 18, 2025) https://csrc.nist.gov/Projects/cryptographic-module-validationprogram/fips-140-3-ig-announcements FIPS 180-4 Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf FIPS 186-4 Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf FIPS 186-5 Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf FIPS 197 Advanced Encryption Standard May 9, 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.197-upd1.pdf FIPS 198-1 The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf FIPS 202 SHA-3 Standard: Permutation-Based Hash and ExtendableOutput Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf PKCS#1 Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt RFC 3526 More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt RFC 4106 The Use of Galois/Counter Mode (GCM) in IPsec Encapsulating Security Payload (ESP) June 2005 https://datatracker.ietf.org/doc/html/rfc4106 RFC 7296 Internet Key Exchange Protocol Version 2 (IKEv2) October 2014 https://datatracker.ietf.org/doc/html/rfc7296 SP 800-38A Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf © 2025 IBM / atsec information security.

70 of 71

Page 71

SP 800-38A Recommendation for Block Cipher Modes of Operation: Three Addendum Variants of Ciphertext Stealing for CBC Mode October 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038a-add.pdf SP 800-38B Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38B.pdf SP 800-38C Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038c.pdf SP 800-38D Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf SP 800-38E Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf SP 800-38F Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf SP 800-56Ar3 Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.80056Ar3.pdf SP 800-90Ar1 Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.80090Ar1.pdf SP 800-90B Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf SP 800-133r2 Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800133r2.pdf SP 800-140Br1 CMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800140Br1.pdf © 2025 IBM / atsec information security.

71 of 71