All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Nuvoton Cryptographic Library 3.0

Certificate#5098StandardFIPS 140-3Level1TypeHardwareEmbodimentSingle ChipStatusActiveVendorNuvoton Technology Corporation
Low review priority  ·  no TCB surface named  ·  last validated 8 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date11/29/2030
CaveatNo assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorNuvoton Technology Corporation

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Nuvoton Cryptographic Library 3.0
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Firmware Load<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Nuvoton Cryptographic Library 3.0
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Firmware Load<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Nuvoton Technology Corporation Nuvoton Cryptographic Library 3.0 Document Version 1.2 Last update: 2025-11-19 Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com © 2025 Nuvoton Technology Corporation / atsec information security.

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 Nuvoton Technology Corporation / atsec information security.

3 of 47

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware7
Table 3: Modes List and Description7
Table 4: Approved Algorithms11
Table 5: Vendor-Affirmed Algorithms11
Table 6: Security Function Implementations14
Table 7: Entropy Certificates15
Table 8: Entropy Sources15
Table 9: Ports and Interfaces16
Table 10: Roles17
Table 11: Approved Services22
Table 12: Mechanisms and Actions Required25
Table 13: Storage Areas27
Table 14: SSP Input-Output Methods27
Table 15: SSP Zeroization Methods28
Table 16: SSP Table 130
Table 17: SSP Table 233
Table 18: Conditional Self-Tests37
Table 19: Conditional Periodic Information41
Table 20: Error States41
Figure 1: Block Diagram6
Figure 2: Nuvoton NPCD324HA0DX (SIO)7
Figure 3: Nuvoton NPCX499HA0BX (EC)7
Figure 4: Nuvoton NPCX499HA1BX (EC)7
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware securityN/A
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for Hardware version 3.0.7 / 3.0.8 of the Nuvoton Cryptographic Library 3.0. It has a one-to-one mapping to the [SP 800-140Br1] starting with section B.2.1 named “General” that maps to section 1 in this document and ending with section B.2.12 named “Mitigation of other attacks” that maps to section 12 in this document. This document also contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for a Security Level 1 module.

1.2 Security Levels

Table 1 describes the individual security areas of FIPS 140-3, as well as the Security Levels of those individual areas: Table 1: Security Levels © 2025 Nuvoton Technology Corporation / atsec information security.

5 of 47

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Nuvoton Cryptographic Library 3.0 cryptographic module (hereafter referred to as “the module”) is a Hardware Single Chip cryptographic module. More specifically, the module is considered a sub-chip cryptographic subsystem as defined in IG 2.3.B. Module Type: Hardware Module Embodiment: SingleChip Module Characteristics: SubChip Cryptographic Boundary: The block diagram below shows the cryptographic boundary of the module (shown by the blue dotted outline), and its interfaces with the operational environment. Figure 1: Block Diagram Tested Operational Environment’s Physical Perimeter (TOEPP): The red outline in Figure 1 above indicates the Tested Operational Environment’s Physical Perimeter (TOEPP). © 2025 Nuvoton Technology Corporation / atsec information security.

6 of 47

Page 7
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
Nuvoton NPCX499HA0BX3.0.7N/AN/ANotebook Embedded Controller (EC)
Nuvoton NPCD324HA0DX3.0.8N/AN/ADesktop Super I/O (SIO)
Nuvoton NPCX499HA1BX3.0.8N/AN/ANotebook Embedded Controller (EC)
Mode NameDescriptionTypeStatus Indicator
Approved ModeOnly approved algorithms are usedApprovedNCL_STATUS_OK
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: The module supports approved services in the approved mode of operation. There are no non-approved services supported by the module. Table 3: Modes List and Description The table below lists all security functions of the module, including specific key strengths employed for approved services, and implemented modes of operation. © 2025 Nuvoton Technology Corporation / atsec information security.

7 of 47

Page 8
AlgorithmCAVP CertPropertiesReference
AES-CBCA4659Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5276Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4659Key Length - 128, 192, 256SP 800-38C
AES-CCMA5276Key Length - 128, 192, 256SP 800-38C
AES-CFB128A4659Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A5276Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA4659Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CMACA5276Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA4659Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5276Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4659Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5276Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4659Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5276Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GMACA4659Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256SP 800-38D

© 2025 Nuvoton Technology Corporation / atsec information security.

8 of 47

Page 9
AlgorithmCAVP CertPropertiesReference
AES-GMACA5276Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-OFBA4659Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-OFBA5276Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
ECDSA KeyGen (FIPS186-5)A4659Curve - P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyGen (FIPS186-5)A5276Curve - P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4659Curve - P-256, P-384, P-521FIPS 186-5
ECDSA KeyVer (FIPS186-5)A5276Curve - P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4659Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 Component - No, YesFIPS 186-5
ECDSA SigGen (FIPS186-5)A5276Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 Component - No, YesFIPS 186-5
ECDSA SigVer (FIPS186-5)A4659Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-5
ECDSA SigVer (FIPS186-5)A5276Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-5
Hash DRBGA4659Prediction Resistance - No, Yes Mode - SHA2-512SP 800-90A Rev. 1
Hash DRBGA5276Prediction Resistance - No, Yes Mode - SHA2-512SP 800-90A Rev. 1
HMAC-SHA2- 256A4659Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A5276Key Length - Key Length: 8-524288 Increment 8FIPS 198-1

© 2025 Nuvoton Technology Corporation / atsec information security.

9 of 47

Page 10
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 384A4659Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A5276Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A4659Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A5276Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4659Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-ECC-SSC Sp800-56Ar3A5276Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF SP800-108A4659KDF Mode - Counter, Double Pipeline Iteration, Feedback Supported Lengths - Supported Lengths: 8-4096 Increment 8SP 800-108 Rev. 1
KDF SP800-108A5276KDF Mode - Counter, Double Pipeline Iteration, Feedback Supported Lengths - Supported Lengths: 8-4096 Increment 8SP 800-108 Rev. 1
KTS-IFCA4659Modulo - 2048, 3072 Key Generation Methods - rsakpg1-basic, rsakpg2-basic Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024SP 800-56B Rev. 2
KTS-IFCA5276Modulo - 2048, 3072 Key Generation Methods - rsakpg1-basic, rsakpg2-basic Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024SP 800-56B Rev. 2
LMS SigVerA4659LMS Modes - LMS_SHA256_M32_H10, LMS_SHA256_M32_H15, LMS_SHA256_M32_H20, LMS_SHA256_M32_H25, LMS_SHA256_M32_H5SP 800-208

© 2025 Nuvoton Technology Corporation / atsec information security.

10 of 47

Page 11
AlgorithmCAVP CertPropertiesReference
LMS SigVerA5276LMS Modes - LMS_SHA256_M32_H10, LMS_SHA256_M32_H15, LMS_SHA256_M32_H20, LMS_SHA256_M32_H25, LMS_SHA256_M32_H5SP 800-208
RSA SigGen (FIPS186-5)A4659Modulo - 2048, 3072 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigGen (FIPS186-5)A5276Modulo - 2048, 3072 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-5)A4659Modulo - 2048, 3072 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-5)A5276Modulo - 2048, 3072 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA2-256A4659Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A5276Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A4659Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A5276Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A4659Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A5276Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
NamePropertiesImplementationReference
HSS SigVerKey Size:256 bitsNuvoton Cryptographic Library 3.0 (NCL)The LMS operations used by the HSS implementation were CAVP tested in accordance with IG C.O with Certs A4659 and A5276
CKG (ECDSA/ECDH)Type:AsymmetricN/ACKG for asymmetric keys as per SP 800-133Rev2 section 4 example 1 with no post processing on the U value

Table 4: Approved Algorithms Vendor-Affirmed Algorithms Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. © 2025 Nuvoton Technology Corporation / atsec information security.

11 of 47

Page 12
NameTypeDescriptionPropertiesAlgorithms
AES-CBCBC-UnAuthAES Encryption and AES DecryptionKey Size:128, 192, 256 bits Key Strength:128, 192, 256 bitsAES-CBC: (A4659, A5276)
AES-CCMBC-AuthAuthenticated AES Encryption and AES DecryptionKey Size:128, 192, 256 bits Key Strength:128, 192, 256 bitsAES-CCM: (A4659, A5276)
AES-CFB128BC-UnAuthAES Encryption and AES DecryptionKey Size:128, 192, 256 bits Key Strength:128, 192, 256 bitsAES-CFB128: (A4659, A5276)
AES-CMACMACCMAC Message Authentication Code Generation and CMAC Message Authentication Code VerificationKey Size:128, 192, 256 bitsAES-CMAC: (A4659, A5276)
AES-CTRBC-UnAuthAES Encryption and AES DecryptionKey Size:128, 192, 256 bits Key Strength:128, 192, 256 bitsAES-CTR: (A4659, A5276)
AES-ECBBC-UnAuthAES Encryption and AES DecryptionKey Size:128, 192, 256 bits Key Strength:128, 192, 256 bitsAES-ECB: (A4659, A5276)
AES-GCMBC-AuthAuthenticated AES Encryption and AES DecryptionKey Size:128, 192, 256 bits Key Strength:128, 192, 256 bitsAES-GCM: (A4659, A5276)
AES-GMACMACGMAC Message Authentication Code Generation and GMAC Message Authentication Code VerificationKey Size:128, 192, 256 bits Key Strength:128, 192, 256 bitsAES-GMAC: (A4659, A5276)

Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations

© 2025 Nuvoton Technology Corporation / atsec information security.

12 of 47

Page 13
NameTypeDescriptionPropertiesAlgorithms
AES-OFBBC-UnAuthAES Encryption and AES DecryptionKey Size:128, 192, 256 bits Key Strength:128, 192, 256 bitsAES-OFB: (A4659, A5276)
HMACMACHMAC Message Authentication Code GenerationKey Size:256, 384, 512 bits Key Strength:256, 384, 512 bitsHMAC-SHA2- 256: (A4659, A5276) HMAC-SHA2- 384: (A4659, A5276) HMAC-SHA2- 512: (A4659, A5276)
RSA SigGenDigSig-SigGenRSA Signature GenerationSignature Types:PKCS#1 v1.5, RSA-PSS Message Digest:SHA2-256, SHA2- 384, SHA2-512 Modulus Size:2048, 3072RSA SigGen (FIPS186-5): (A4659, A5276)
RSA SigVerDigSig-SigVerRSA Signature VerificationSignature Types:PKCS#1 v1.5, RSA-PSS Message Digest:SHA2-256, SHA2- 384, SHA2-512 Modulus Size:2048, 3072RSA SigVer (FIPS186-5): (A4659, A5276)
RSA encapsulationAsymKeyPair- EncapRSA encapsulation of arbitrary dataScheme:OAEP-basic Modulus Size:2048, 3072 Standard:SP800-56Brev2KTS-IFC: (A4659, A5276)
RSA decapsulationAsymKeyPair- DecapRSA decapsulation of arbitrary dataScheme:OAEP-basic Modulus Size:2048, 3072 Standard:SP800-56Brev2KTS-IFC: (A4659, A5276)
ECDSA KeyGenAsymKeyPair- KeyGen CKGECDSA Key GenerationGeneration Method:B.4.2 Testing Candidates Curves:P-256, P-384, P-521ECDSA KeyGen (FIPS186-5): (A4659, A5276) CKG (ECDSA/ECDH): ()
ECDSA KeyVerAsymKeyPair- KeyVerECDSA Key VerificationCurves:P-256, P-384, P-521ECDSA KeyVer (FIPS186-5): (A4659, A5276)
ECDSA SigGenDigSig-SigGenECDSA Signature GenerationMessage Digest:SHA2-256, SHA2- 384, SHA2-512 Curves:P-256, P-384, P-521ECDSA SigGen (FIPS186-5): (A4659, A5276)

() © 2025 Nuvoton Technology Corporation / atsec information security.

13 of 47

Page 14
NameTypeDescriptionPropertiesAlgorithms
ECDSA SigVerDigSig-SigVerECDSA Signature VerificationMessage Digest:SHA2-256, SHA2- 384, SHA2-512 Curves:P-256, P-384, P-521ECDSA SigVer (FIPS186-5): (A4659, A5276)
ECDSA SigGen ComponentDigSig-SigGenECDSA Signature Generation ComponentCurves:P-256, P-384, P-521ECDSA SigGen (FIPS186-5): (A4659, A5276)
SHSSHAMessage Digest GenerationSHA2-256: (A4659, A5276) SHA2-384: (A4659, A5276) SHA2-512: (A4659, A5276)
KAS-ECC-SSCKAS-SSCEC Diffie-Hellman Shared Secret ComputationScheme:ephemeralUnified Curves:P-256, P-384, P-521KAS-ECC-SSC Sp800-56Ar3: (A4659, A5276)
Hash_DRBGDRBGRandom Number GenerationMode:SHA2-512Hash DRBG: (A4659, A5276)
HSS SigVerDigSig-SigVerHSS Signature VerificationKey Size:256 bits LMS Modes (CAVP):LMS_SHA256_M32_H10, LMS_SHA256_M32_H15, LMS_SHA256_M32_H20, LMS_SHA256_M32_H25, LMS_SHA256_M32_H5 LMOTS Modes (CAVP):LMOTS_SHA256_N32_W1, LMOTS_SHA256_N32_W2, LMOTS_SHA256_N32_W4, LMOTS_SHA256_N32_W8LMS SigVer: (A4659, A5276)
KBKDFKBKDFKey Derivation FunctionKDF Modes:Counter, Feedback, Double pipeline iteration MAC Modes:HMAC-SHA2- 256, HMAC-SHA2-384, HMAC-SHA2- 512 Key Sizes:256, 384, 512 bitsKDF SP800-108: (A4659, A5276)

Table 6: Security Function Implementations

2.7 Algorithm Specific Information

The module’s AES-GCM implementation conforms to IG C.H scenario 2. The module uses the approved Hash_DRBG to generate the IV with a length of 96-bits. The entropy source producing the DRBG seed is located inside the module’s cryptographic boundary. Steps to comply with the SP800-56Brev2 assurances can be found in section 11.3 Non-Administrator Guidance. © 2025 Nuvoton Technology Corporation / atsec information security.

14 of 47

Page 15
CertVendor
NumberName
E161Nuvoton
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Nuvoton NTCES03PhysicalNPCX499HA0BX, NPCX499HA1BX, NPCD324HA0DX512 bitsThe entropy pool is filled with random bits provided by an SP800-90B compliant entropy source whose noise source is from Ring Oscillators in hardware. SHA2-512 is used as the conditioning component with CAVP certs# A4659 and A5276.

The module does not establish SSPs using an approved key transport scheme (KTS). However, it does offer approved authenticated algorithms that can be used by an external operator/application as part of an approved KTS. The module employs a Hash_DRBG using a SHA-512 PRF. Per section 10.1.1.1 of [SP800-90A], the internal state of the Hash_DRBG is the V, C, and reseed counter. The module makes use of the GetEntropy() interface of the entropy source to make two independent calls that output 512-bit each of full entropy from the SP 800-90B entropy source then concatenating them together to form 1024-bits of entropy input for the DRBG. The Hash_DRBG can generate random numbers with up to 256-bits of security strength. The DRBG internal state is not accessible by non-DRBG functions. All random values used by approved security functions, SSP generation, or SSP establishment method are provided by the Hash_DRBG. Table 7: Entropy Certificates Table 8: Entropy Sources

2.9 Key Generation

The module generates Keys and SSPs in accordance with FIPS 140-3 IG D.H. The cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys as per [SP800-133rev2] (vendor affirmed), compliant with [FIPS186-5] and using DRBG compliant with [SP800-90Arev1]. A seed (i.e., the random value) used in asymmetric key generation is obtained from [SP800-90Arev1] DRBG as described in Section 4 example 1 of [SP800-133rev2], where V is a string of binary zeroes, meaning B = U (i.e., the output of an approved RBG). The key generation service for ECDSA, as well as the [SP 800-90Arev1] DRBG have been ACVT tested with algorithm certificates found in Table 3. The module provides key derivation service using SP800-108 KBKDF.

2.10 Key Establishment

The module implements KAS-ECC-SSC EC Diffie-Hellman Shared Secret Computation compliant to [SP800-56Arev3] and IG D.F Scenario (2) path (1). • The shared secret computation provides between 128 and 256 bits of encryption strength. © 2025 Nuvoton Technology Corporation / atsec information security.

15 of 47

Page 16
Physical PortLogical Interface(s)Data That Passes
I/O PortsData InputData inputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers.
I/O PortsData OutputData outputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers.
I/O PortsControl InputControl inputs which control the operation of the module are provided through dedicated parameters.
I/O PortsStatus OutputStatus output is provided in return codes and through messages. Documentation for each API lists possible return codes. A complete list of all return codes returned by the C language APIs within the module is provided in the header files and the API documentation. Messages are documented also in the API documentation.
Power PortPowerPower interface is provided internally by TEOPP in which the cryptographic module is embedded.

Table 9: Ports and Interfaces © 2025 Nuvoton Technology Corporation / atsec information security.

16 of 47

Page 17
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
UserRoleUserNone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
AES EncryptionData EncryptionNCL STATUS OKAES key, plain textcipher textAES-CBC AES-CCM AES-CFB128 AES-CTRUser - AES key: W,E
4 Roles, Services, and Authentication

FIPS 140-3 does not require authentication mechanism for level 1 modules. Therefore, the module does not implement an authentication mechanism. N/A for this module.

4.2 Roles

The module supports two authorized roles: A Crypto Officer Role and a User Role. No support is provided for a Maintenance operator. The module does not implement a bypass mode nor concurrent operators. Table 10: Roles When a device is delivered, the Crypto Officer is responsible for initializing the module i.e., configure the device by properly setting up key registers for storage of keys/CSPs. The Crypto Officer is implicitly assumed. The User can perform services from Table 11 only after the Crypto Officer takes possession by initializing the module, thus creating data to be protected is generated. The Users of the module are software applications that implicitly assume the User Role when requesting any cryptographic services provided by the module.

4.3 Approved Services

The module only implements Approved security functions in an Approved mode. The Table 5 below lists services available. The module provides an approved service indicator by receiving a return code of “NCL_STATUS_OK to indicate that the service executed an approved security function. NOTE: The module does not implement any non-Approved Algorithms in the Approved Mode of Operation (neither with nor without security claim). The module does not implement any non-approved security functions. The abbreviations of the access rights to keys and SSPs have the following interpretation: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. © 2025 Nuvoton Technology Corporation / atsec information security.

17 of 47

Page 18
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
AES-ECB AES-GCM AES-OFB
AES DecryptionAES DecryptionNCL STATUS OKAES key, cipher textplain textAES-CBC AES-CCM AES-CFB128 AES-CTR AES-ECB AES-GCM AES-OFBUser - AES key: W,E
CMAC Message Authentication Code GenerationMessage Authentication Code GenerationNCL STATUS OKAES key, messageMACAES-CMACUser - AES key: W,E
CMAC Message Authentication Code VerificationMessage Authentication Code VerificationNCL STATUS OKMAC, Message"VALID" or "INVALID"AES-CMACUser - AES key: W,E
GMAC Message Authentication Code GenerationMessage Authentication Code GenerationNCL STATUS OKAES key, AADauthentication tagAES-GMACUser - AES key: W,E
GMAC Message Authentication Code VerificationMessage Authentication Code VerificationNCL STATUS OKAES key, AAD, IV, tag"PASS" or "FAIL"AES-GMACUser - AES key: W,E
HMAC Message Authentication Code GenerationMessage Authentication Code GenerationNCL STATUS OKHMAC key, messageMACHMACUser - HMAC Key: W,E
Message Digest GenerationSHS Message Digest GenerationNCL STATUS OKmessagedigest (hash value)SHSUser
RSA EncapsulationRSA EncapsulationNCL STATUS OKRSA public key, data toencapsulated dataRSA encapsulationUser - RSA

© 2025 Nuvoton Technology Corporation / atsec information security.

18 of 47

Page 19
NameDescription using KTS- OAEP-basicIndicatorInputs be encapsulatedOutputsSecurity FunctionsSSP Access Encapsulation Key: W,E
RSA DecapsulationRSA Decapsulation using KTS- OAEP-basicNCL STATUS OKRSA private key, encapsulated datadecapsulated dataRSA decapsulationUser - RSA Decapsulation Key: W,E
RSA Digital Signature GenerationDigital Signature GenerationNCL STATUS OKRSA public key, message, hash algorithmsignatureRSA SigGen Hash_DRBGUser - RSA Sig private key: W,E
RSA Digital Signature VerificationDigital Signature VerificationNCL STATUS OKRSA public key, signature, message, hash algorithmTrue or FalseRSA SigVerUser - RSA Sig public key: W,E
ECDSA Digital Signature GenerationDigital Signature GenerationNCL STATUS OKECDSA private key, message, hash algorithmsignatureECDSA SigGen Hash_DRBGUser - ECDSA private key: W,E - DRBG internal state (i.e., Hash_DRBG V and C values): W
ECDSA Digital Signature Generation ComponentDigital Signature Generation ComponentNCL STATUS OKECDSA private key, message, message digestsignatureECDSA SigGen Component Hash_DRBGUser - ECDSA private key: W,E - DRBG internal state (i.e., Hash_DRBG V and C values): W
ECDSA Digital Signature VerificationDigital Signature VerificationNCL STATUS OKECDSA public key, signature, message, hash algorithmTrue or FalseECDSA SigVerUser - ECDSA public key: W,E

(i.e., W (i.e., W © 2025 Nuvoton Technology Corporation / atsec information security.

19 of 47

Page 20
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
ECDSA Key GenerationAsymmetric Key Pair GenerationNCL STATUS OKCurve sizegenerated private and public key pairECDSA KeyGen Hash_DRBGUser - ECDSA private key: G,R - ECDSA public key: G,R - ECDH private key: G,R - ECDH public key: G,R - DRBG internal state (i.e., Hash_DRBG V and C values): W - ECDSA intermediate key generation values: G,Z - ECDH intermediate key generation values: G,Z
ECDSA Key VerificationAsymmetric Public Key VerificationNCL STATUS OKPublic KeyTrue or FalseECDSA KeyVerUser - ECDSA public key: W,E - ECDH public key: W,E
EC Diffie- Hellman Shared Secret ComputationShared Secret Computation using Elliptic Curve CryptographyNCL STATUS OKreceived public key, possessed private keyshared secretKAS-ECC- SSCUser - ECDH public key: W,E - ECDH private key: W,E - ECC Shared Secret: G,R
Random Number GenerationDeterministic Random Number GenerationNCL STATUS OKSeedrandom numbersHash_DRBGUser - Entropy Input String: G,E - DRBG Seed: G,E - DRBG internal state (i.e., Hash_DRBG V

G,R (i.e., W W,E G,E (i.e., © 2025 Nuvoton Technology Corporation / atsec information security.

20 of 47

Page 21
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access and C values): W,E
Show Module Version InfoOutputs Module Name + Version NumberN/ANoneModule Name + Module Version NumberNoneUser
SSP ZeroisationSeries of APIs that can be invoked by the operator to zeroize crypto function context and release memory space; See the list of APIs mentioned in section 9.3 and 11.4N/Ahandle of crypto function contextzeroized and released memory spaceNoneUser - AES key: Z - RSA Encapsulation Key: Z - RSA Decapsulation Key: Z - RSA Sig private key: Z - RSA Sig public key: Z - ECDSA private key: Z - ECDSA public key: Z - HMAC Key: Z - ECDH private key: Z - ECDH public key: Z - ECC Shared Secret: Z - Entropy Input String: Z - DRBG Seed: Z - DRBG internal state (i.e., Hash_DRBG V and C values): Z - HSS public key: Z - Derived key: Z - Key Derivation Key: Z

W,E Z (i.e., Z Z Z © 2025 Nuvoton Technology Corporation / atsec information security.

21 of 47

Page 22
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Show-StatusOutputs Operational/ Error status of the moduleN/ANoneOperational/Error statusNoneUser
Self-testExecutes on- demand self-test and outputs Pass/Fail statusNCL STATUS OKNonePass/Fail statusAES-CBC AES-CCM HMAC RSA SigGen RSA SigVer RSA encapsulation RSA decapsulation ECDSA SigGen ECDSA SigVer SHS KAS-ECC- SSC Hash_DRBG HSS SigVer KBKDFUser
HSS Signature VerificationDigital Signature VerificationNCL STATUS OKHSS Public Key, Digital Signature, messageTrue or FalseHSS SigVerUser - HSS public key: W,E
Key derivationPerform key derivationNCL STATUS OKKey Derivation KeyDerived keyKBKDFUser - Derived key: G,R - Key Derivation Key: W,E

W,E Table 11: Approved Services © 2025 Nuvoton Technology Corporation / atsec information security.

22 of 47

Page 23
5 Software/Firmware Security
5.1 Integrity Techniques

The memory technology is non reconfigurable memory as defined in IG 5.A, which will not have any change or degradation of data for a minimum of 10 years after manufactured date. As such, it is considered a hardware only module with a non-modifiable operational environment. The requirements of this area are not applicable to the module. © 2025 Nuvoton Technology Corporation / atsec information security.

23 of 47

Page 24
6 Operational Environment
6.1 Operational Environment Type and Requirements

The Nuvoton Cryptographic Library 3.0 operates in a non-modifiable operational environment. The module is programmed by the manufacturer during the silicon manufacturing (rather than by the user). It maintains its own memory region which can only be accessed by the module. There is no additional application present within the operating environment. The module does not spawn any cryptographic processes. Type of Operational Environment: Limited © 2025 Nuvoton Technology Corporation / atsec information security.

24 of 47

Page 25
MechanismInspection FrequencyInspection Guidance
Hard tamper-evident coatingDetermined by the operatorObserve the coating surrounding the chip for any signs of damage
7 Physical Security
7.1 Mechanisms and Actions Required

The Nuvoton Cryptographic Library 3.0 cryptographic module is a Hardware cryptographic module in a single chip embodiment. More specifically, the module is considered a sub-chip cryptographic subsystem. The module consists of production-grade components that include standard passivation techniques (e.g., a conformal coating applied over the module’s circuitry to protect against environmental or other physical damage). The module does not implement a maintenance role and has no maintenance access interface. Table 12: Mechanisms and Actions Required © 2025 Nuvoton Technology Corporation / atsec information security.

25 of 47

Page 26
8 Non-Invasive Security

Currently, the non-invasive security is not required by FIPS 140-3 (see NIST SP 800-140F). The requirements of this area are not applicable to the module. © 2025 Nuvoton Technology Corporation / atsec information security.

26 of 47

Page 27
Storage Area NameDescriptionPersistence Type
RAMStored in volatile memoryDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API inputWithin the TOEPPRAMPlaintextAutomatedElectronic
API outputRAMWithin the TOEPPPlaintextAutomatedElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Module ResetPower cycles the moduleAll SSPs in memory are overwritten by zerosInitiated by operator
Automatic zeroizationAutomatic zeroization when when no longer neededOverwrites the targeted SSP's contents in memory with zeros using memset/memset_s for any contents in RAM and REG_WRITE for any contents in hardware registersAutomatically by the module
9 Sensitive Security Parameters Management
9.1 Storage Areas

The module does not provide persistent storage for keys/SSPs. Keys/SSPs are stored in memory only and are received for use by the module only at the request of the User firmware. Table 13: Storage Areas Keys/SSPs entered or output the module are electronically entered in plaintext form from the invoking User firmware running on the same device. No Keys/SSPs are entered into or output from the module from outside of the TOEPP. According to IG 2.3.B, transferring SSPs including the entropy input between a sub-chip cryptographic subsystem and an intervening functional subsystem for Security Levels 1 and 2 on the same single chip is considered as not having Sensitive Security Parameter Establishment crossing the HMI of the sub-chip module per IG 9.5.A. Entropy input remains within the module's sub-chip boundary. Table 14: SSP Input-Output Methods Keys and SSPs are explicitly zeroized automatically prior to the structure associated with the cipher being deallocated or implicitly when the device is powered down thereby rendering the data irretrievable. Input and output interfaces are inhibited while zeroization is being performed. For Keys and SSPs explicitly zeroized automatically the successful completion of a requested service suffices as the implicit indicator that zeroisation has completed. Keys and SSPs may be zeroized explicitly by calling the respective NCL_<alg>_Clear API listed in the table below which immediately zeroizes all sensitive data. © 2025 Nuvoton Technology Corporation / atsec information security.

27 of 47

Page 28
Zeroization MethodDescriptionRationaleOperator Initiation
NCL_SHA_ClearClears existing SHA, HMAC, KBKDF contextsOverwrites the targeted SSP's contents in memory with zeros using memset/memset_s for any contents in RAM and REG_WRITE for any contents in hardware registersInitiated by operator
NCL_DRBG_ClearClears existing DRBG contextsOverwrites the targeted SSP's contents in memory with zeros using memset/memset_s for any contents in RAM and REG_WRITE for any contents in hardware registersInitiated by operator
NCL_AES_ClearClears existing AES contextsOverwrites the targeted SSP's contents in memory with zeros using memset/memset_s for any contents in RAM and REG_WRITE for any contents in hardware registersInitiated by operator
NCL_RSA_ClearClears existing RSA contextsOverwrites the targeted SSP's contents in memory with zeros using memset/memset_s for any contents in RAM and REG_WRITE for any contents in hardware registersInitiated by operator
NCL_ECC_ClearClears existing ECDSA and ECDH contextsOverwrites the targeted SSP's contents in memory with zeros using memset/memset_s for any contents in RAM and REG_WRITE for any contents in hardware registersInitiated by operator
NCL_HSS_ClearClears existing HSS contextsOverwrites the targeted SSP's contents in memory with zeros using memset/memset_s for any contents in RAM and REG_WRITE for any contents in hardware registersInitiated by operator
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES keyAES Symmetric key used in Data Encryption, Data Decryption and Message Authentication Code Generation and verification128, 192, 256 bits - 128, 192, 256 bitsSymmetric - CSPAES-CBC AES-CCM AES-CFB128 AES-CMAC AES-CTR AES-ECB AES-GCM AES-GMAC

Table 15: SSP Zeroization Methods

9.4 SSPs

The following summarizes the keys and Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module. Modification of PSPs by unauthorized operators is prohibited. © 2025 Nuvoton Technology Corporation / atsec information security.

28 of 47

Page 29
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
RSA Encapsulation KeyRSA OAEP private key2048, 3072 bits - 112, 128 bitsAsymmetric - CSPRSA encapsulation
RSA Decapsulation KeyRSA OAEP public key2048, 3072 bits - 112, 128 bitsAsymmetric - PSPRSA decapsulation
RSA Sig private keySignature Generation2048, 3072 bits - 112, 128 bitsAsymmetric - CSPRSA SigGen
RSA Sig public keySignature Verification2048, 3072 bits - 112, 128 bitsAsymmetric - PSPRSA SigVer
ECDSA private keySignature GenerationP-256, P- 384, P-521 curves - 112 to 256 bitsAsymmetric - CSPECDSA KeyGen Hash_DRBGECDSA SigGen
ECDSA intermediate key generation valuesIntermediate values for ECDSA Signature GenerationP-256, P- 384, P-521 curves - 112 to 256 bitsAsymmetric - CSPECDSA KeyGen Hash_DRBGECDSA SigGen
ECDSA public keyKey Verification, Signature VerificationP-256, P- 384, P-521 curves - 112 to 256 bitsAsymmetric - PSPECDSA KeyGen Hash_DRBGECDSA KeyVer ECDSA SigVer
HMAC KeyHashed Message Authentication Code Generation112 bits or greater - 112 bits or greaterSymmetric - CSPHMAC
ECDH private keyECDH Shared Secret ComputationP-256, P- 384, P-521 curves - 112 to 256- bitsAsymmetric - CSPECDSA KeyGen Hash_DRBGKAS-ECC- SSC
ECDH intermediate keyIntermediate values for ECDH Shared Secret ComputationP-256, P- 384, P-521 curves -Asymmetric - CSPECDSA KeyGen Hash_DRBG

© 2025 Nuvoton Technology Corporation / atsec information security.

29 of 47

Page 30
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
generation values112 to 256- bits
ECDH public keyECDH Shared Secret ComputationP-256, P- 384, P-521 curves - 112 to 256- bitsAsymmetric - PSPECDSA KeyGen Hash_DRBGECDSA KeyVer KAS-ECC- SSC
ECC Shared SecretECDH Shared Secret ComputationP-256, P- 384, P-521 curves - 112 to 256- bitsAsymmetric shared secret - CSPKAS-ECC- SSC
Entropy Input StringSeed DRBG256-bits - 256-bitsDRBG - CSPHash_DRBG
DRBG SeedMaintaining DRBG internal state256-bits - 256-bitsDRBG - CSPHash_DRBG
DRBG internal state (i.e., Hash_DRBG V and C values)Maintaining DRBG internal state256-bits - 256-bitsDRBG - CSPHash_DRBG
HSS public keyUsed by HSS signature verification256-bits - 256-bitsAsymmetric key - PSPHSS SigVer
Derived keyKey derived by KBKDF256, 384, 512 bits - 256, 384, 512 bitsSymmetric - CSPKBKDF
Key Derivation KeyKey used by KBKDF256, 384, 512 bits - 256, 384, 512 bitsSymmetric - CSPKBKDF
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyAPI inputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_AES_Clear

Table 16: SSP Table 1 © 2025 Nuvoton Technology Corporation / atsec information security.

30 of 47

Page 31
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
RSA Encapsulation KeyAPI inputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_RSA_ClearRSA Decapsulation Key:Paired With
RSA Decapsulation KeyAPI inputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_RSA_ClearRSA Encapsulation Key:Paired With
RSA Sig private keyAPI inputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_RSA_ClearRSA Sig public key:Paired With
RSA Sig public keyAPI inputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_RSA_ClearRSA Sig private key:Paired With
ECDSA private keyAPI input API outputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_ECC_ClearDRBG internal state (i.e., Hash_DRBG V and C values):Derived From ECDSA public key:Paired With ECDSA intermediate key generation values:Paired With
ECDSA intermediate key generation valuesRAM:PlaintextUntil no longer neededAutomatic zeroizationDRBG internal state (i.e., Hash_DRBG V and C values):Derived From ECDSA private key:Paired With ECDSA public key:Paired With
ECDSA public keyAPI input API outputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_ECC_ClearDRBG internal state (i.e., Hash_DRBG V and C values):Derived From ECDSA private key:Paired With ECDSA intermediate key generation values:Paired With
HMAC KeyAPI inputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic

© 2025 Nuvoton Technology Corporation / atsec information security.

31 of 47

Page 32
NameInput - OutputStorageStorage DurationZeroization zeroization NCL_SHA_ClearRelated SSPs
ECDH private keyAPI input API outputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_ECC_ClearDRBG internal state (i.e., Hash_DRBG V and C values):Derived From ECDH public key:Paired With ECDH intermediate key generation values:Paired With
ECDH intermediate key generation valuesRAM:PlaintextUntil no longer neededAutomatic zeroizationDRBG internal state (i.e., Hash_DRBG V and C values):Derived From ECDH private key:Paired With ECDH public key:Paired With
ECDH public keyAPI input API outputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_ECC_ClearDRBG internal state (i.e., Hash_DRBG V and C values):Derived From ECDH private key:Paired With ECDH intermediate key generation values:Paired With
ECC Shared SecretAPI outputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_ECC_ClearECDH private key:Established From ECDH public key:Established From
Entropy Input StringRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_DRBG_ClearDRBG Seed:Derives
DRBG SeedRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_DRBG_ClearEntropy Input String:Derived From DRBG internal state (i.e., Hash_DRBG V and C values):Derives
DRBG internal state (i.e., Hash_DRBG V and C values)RAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_DRBG_ClearDRBG Seed:Derived From

© 2025 Nuvoton Technology Corporation / atsec information security.

32 of 47

Page 33
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
HSS public keyAPI inputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_HSS_Clear
Derived keyAPI outputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_SHA_ClearKey Derivation Key:Derived From
Key Derivation KeyAPI inputRAM:PlaintextUntil deallocated or on module resetModule Reset Automatic zeroization NCL_SHA_ClearDerived key:Derives

Table 17: SSP Table 2 © 2025 Nuvoton Technology Corporation / atsec information security.

33 of 47

Page 34
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC-SHA2- 512 (A4659)HMAC-SHA2-512 MAC Generation KATKATCASTNCL STATUS OKMAC GenerationPerformed when the module is powered on
HMAC-SHA2- 512 (A5276)HMAC-SHA2-512 MAC Generation KATKATCASTNCL STATUS OKMAC GenerationPerformed when the module is powered on
SHA2-256 (A4659)SHA2-256 Message Digest KATKATCASTNCL STATUS OKMessage DigestPerformed when the module is powered on
SHA2-256 (A5276)SHA2-256 Message Digest KATKATCASTNCL STATUS OKMessage DigestPerformed when the module is powered on
AES-CCM (A4659)AES-CCM Encryption KAT using 128-bit keyKATCASTNCL STATUS OKAES EncryptionPrior to the first operational use of the algorithm
AES-CCM (A5276)AES-CCM Encryption KAT using 128-bit keyKATCASTNCL STATUS OKAES EncryptionPrior to the first operational use of the algorithm
10 Self-Tests
10.1 Pre-Operational Self-Tests

The module is solely implemented in hardware (i.e., only contains executable code that is stored in non- reconfigurable memory). As such, the module does not perform any pre-operational software/firmware integrity test, but instead performs Self-tests ensure that the module is not corrupted and that the cryptographic algorithms work as expected. While the module is executing the above self-tests, no services are available and input and output are inhibited. The module will boot only after successfully passing the SHA2-256, HMAC- SHA2-512 and KBKDF-HMAC-SHA2-256 CASTs. If an error is detected in any self-test, the module will enter the Error State. N/A for this module. The module does not implement a pre-operational bypass test nor pre-operational critical functions test.

10.2 Conditional Self-Tests

algorithm. The table below describe the conditional tests supported by the module. © 2025 Nuvoton Technology Corporation / atsec information security.

34 of 47

Page 35
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A4659)AES-CBC Decryption KAT using 128-bit keyKATCASTNCL STATUS OKAES DecryptionPrior to the first operational use of the algorithm
AES-CBC (A5276)AES-CBC Decryption KAT using 128-bit keyKATCASTNCL STATUS OKAES DecryptionPrior to the first operational use of the algorithm
KTS-IFC (A4659)KTS-OAEP-basic Encryption/Decryption KAT with 2048 -bit key and SHA2-256KATCASTNCL STATUS OKKTS-OAEP-basic Encryption and DecryptionPrior to the first operational use of the algorithm
KTS-IFC (A5276)KTS-OAEP-basic Encryption/Decryption KAT with 2048 -bit key and SHA2-256KATCASTNCL STATUS OKKTS-OAEP-basic Encryption and DecryptionPrior to the first operational use of the algorithm
RSA SigGen (FIPS186-5) (A4659)RSA Signature Generation KAT with 2048-bit key and SHA2-256KATCASTNCL STATUS OKRSA Signature GenerationPrior to the first operational use of the algorithm
RSA SigGen (FIPS186-5) (A5276)RSA Signature Generation KAT with 2048-bit key and SHA2-256KATCASTNCL STATUS OKRSA Signature GenerationPrior to the first operational use of the algorithm
RSA SigVer (FIPS186-5) (A4659)RSA Signature Verification KAT with 2048-bit key and SHA2-256KATCASTNCL STATUS OKRSA Signature VerificationPrior to the first operational use of the algorithm
RSA SigVer (FIPS186-5) (A5276)RSA Signature Verification KAT with 2048-bit key and SHA2-256KATCASTNCL STATUS OKRSA Signature VerificationPrior to the first operational use of the algorithm
ECDSA SigGen (FIPS186-5) (A4659)ECDSA Signature Generation KAT with P-256 curve and SHA2-256KATCASTNCL STATUS OKECDSA Signature GenerationPrior to the first operational use of the algorithm
ECDSA SigGen (FIPS186-5) (A5276)ECDSA Signature Generation KAT with P-256 curve and SHA2-256KATCASTNCL STATUS OKECDSA Signature GenerationPrior to the first operational use of the algorithm
ECDSA SigVer (FIPS186-5) (A4659)ECDSA Signature Verification KAT with P-256 curve and SHA2-256KATCASTNCL STATUS OKECDSA Signature VerificationPrior to the first operational use of the algorithm

© 2025 Nuvoton Technology Corporation / atsec information security.

35 of 47

Page 36
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigVer (FIPS186-5) (A5276)ECDSA Signature Verification KAT with P-256 curve and SHA2-256KATCASTNCL STATUS OKECDSA Signature VerificationPrior to the first operational use of the algorithm
KAS-ECC-SSC Sp800-56Ar3 (A4659)ECDH shared secret computation KAT with P- 256 curveKATCASTNCL STATUS OKECDH shared secret computationPrior to the first operational use of the algorithm
KAS-ECC-SSC Sp800-56Ar3 (A5276)ECDH shared secret computation KAT with P- 256 curveKATCASTNCL STATUS OKECDH shared secret computationPrior to the first operational use of the algorithm
Hash DRBG (A4659)Hash_DRBG random number generation KAT using predefined seed.KATCASTNCL STATUS OKSP 800-90Ar1 section 11.3 (instantiate, reseed, generate) health testPrior to the first operational use of the algorithm
Hash DRBG (A5276)Hash_DRBG random number generation KAT using predefined seed.KATCASTNCL STATUS OKSP 800-90Ar1 section 11.3 (instantiate, reseed, generate) health testPrior to the first operational use of the algorithm
KDF SP800-108 (A4659)Counter mode using HMAC- SHA2-256 using 160-bit keyKATCASTNCL STATUS OKKBKDFPerformed when the module is powered on
KDF SP800-108 (A5276)Counter mode using HMAC- SHA2-256 using 160-bit keyKATCASTNCL STATUS OKKBKDFPerformed when the module is powered on
ECDSA KeyGen (FIPS186-5) (A4659)Pairwise consistency testPCTPCTNCL STATUS OKPairwise consistency testPerformed upon generation of a new ECDSA key pair
ECDSA KeyGen (FIPS186-5) (A5276)Pairwise consistency testPCTPCTNCL STATUS OKPairwise consistency testPerformed upon generation of a new ECDSA key pair
HSS SigVerHSS KAT SHA2-256KATCASTNCL STATUS OKHSS Digital Signature VerificationPrior to the first operational use of the algorithm

© 2025 Nuvoton Technology Corporation / atsec information security.

36 of 47

Page 37
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ESV - Repetition Count Test (Startup)Startup test with 1024 samples; Cutoff value = 35RCTCASTNCL STATUS OKEntropy Health TestPerformed before seeding the DRBG
ESV - Repetition Count Test (Continuous)Cutoff value = 35RCTCASTNCL STATUS OKEntropy Health TestPerformed before seeding the DRBG
ESV - Adaptive Proportional Test (Startup)Startup test with 1024 samples; Cutoff value = 748APTCASTNCL STATUS OKEntropy Health TestPerformed before seeding the DRBG
ESV - Adaptive Proportional Test (Continuous)Cutoff value = 748APTCASTNCL STATUS OKEntropy Health TestPerformed before seeding the DRBG
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-512 (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
HMAC-SHA2-512 (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
SHA2-256 (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the

Table 18: Conditional Self-Tests The module does not implement a Software/Firmware Load Test, Manual Entry Test, Conditional Bypass Test nor Conditional Critical Functions Test.

10.3 Periodic Self-Test Information

During runtime, operators can initiate the conditional self-tests on demand by calling NCL_MISC_SelfTest and passing The module’s entropy source is powered on only momentarily to seed the module’s SP800-90B DRBG. The module performs entropy source health tests defined in Section 4 of SP800-90B on the generated output prior to seeding the SP800-90B DRBG. After completing its execution, the entropy source powers down. N/A for this module. © 2025 Nuvoton Technology Corporation / atsec information security.

37 of 47

Page 38
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
algorithm as an argument
SHA2-256 (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
AES-CCM (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
AES-CCM (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
AES-CBC (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
AES-CBC (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
KTS-IFC (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
KTS-IFC (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
RSA SigGen (FIPS186-5) (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument

© 2025 Nuvoton Technology Corporation / atsec information security.

38 of 47

Page 39
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigGen (FIPS186-5) (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
RSA SigVer (FIPS186-5) (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
RSA SigVer (FIPS186-5) (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
ECDSA SigGen (FIPS186-5) (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
ECDSA SigGen (FIPS186-5) (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
ECDSA SigVer (FIPS186-5) (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
ECDSA SigVer (FIPS186-5) (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
KAS-ECC-SSC Sp800-56Ar3 (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument

© 2025 Nuvoton Technology Corporation / atsec information security.

39 of 47

Page 40
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-ECC-SSC Sp800-56Ar3 (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
Hash DRBG (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
Hash DRBG (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
KDF SP800-108 (A4659)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
KDF SP800-108 (A5276)KATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
ECDSA KeyGen (FIPS186-5) (A4659)PCTPCTN/AN/A
ECDSA KeyGen (FIPS186-5) (A5276)PCTPCTN/AN/A
HSS SigVerKATCASTOn demandBy calling NCL_MISC_SelfTest and passing the algorithm as an argument
ESV - Repetition Count Test (Startup)RCTCASTOn demandPowering the chip off and on
ESV - Repetition Count Test (Continuous)RCTCASTOn demandPowering the chip off and on

© 2025 Nuvoton Technology Corporation / atsec information security.

40 of 47

Page 41
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ESV - Adaptive Proportional Test (Startup)APTCASTOn demandPowering the chip off and on
ESV - Adaptive Proportional Test (Continuous)APTCASTOn demandPowering the chip off and on
NameDescriptionConditionsRecovery MethodIndicator
Error StateWhen in this error state, no cryptographic services are provided, control and data output is prohibited.Failure in conditional self- test (conditional CAST or conditional PCT) Failure of the ENT health testThe only method to clear this error state is to power cycle the device and then successfully pass the conditional self-tests.Failure in conditional self-test: NCL_STATUS_FAIL; Failure of the ENT health test: ENTROPY_SRC_ERROR

Table 19: Conditional Periodic Information

10.4 Error States

For any of the conditional self-tests, the module enters an error state upon failing the self-test. A failure in the conditional Table 20: Error States © 2025 Nuvoton Technology Corporation / atsec information security.

41 of 47

Page 42
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is delivered as part of the Nuvoton NPCX499HA0BX (EC), Nuvoton NPCD324HA0DX (SIO) and Nuvoton NPCX499HA1BX (EC) platforms (listed in Table 2). During manufacturing

11.2 Administrator Guidance

The module is configured to be operational by default. If the device starts up successfully and has successfully passed the SHA2-256, HMAC- SHA2-512 and KBKDF-HMAC-SHA2-256 CASTs, it is operating correctly and can begin servicing User requests.

11.3 Non-Administrator Guidance

The module does not establish any SSPs for itself. Instead, the module provides this functionality as a service for other components within the TOEPP. The entity using the IUT must obtain required assurances listed in section 6.4 of SP 80056BRev2 by performing the following steps: 1. The entity requesting the RSA key unwrapping (un-encapsulation) service from the module, shall only use an RSA private key that was generated by an active FIPS validated module that implements FIPS 186-5 compliant RSA key generation service and performs the key pair validity and the pairwise consistency as stated in section

6.4.1.1 of the SP 800-56BRev2. Additionally, the entity shall renew these assurances over time by using any

method described in section 6.4.1.5 of the SP 800-56BRev2.

  1. For use of an RSA key wrapping (encapsulation) service in the context of key transport per IG D.G, the entity using the module, shall verify the validity of the peer's public key using any method specified in section 6.4.2.1 of the SP 800-56BRev2.
  2. The entity using the module, shall confirm the peer's possession of private key by using any method specified in section 6.4.2.3 of the SP 800-56BRev2. To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the operator must use module’s approved key pair generation service to generate ephemeral EC Diffie-Hellman key pair, or the key pair must be obtained from another FIPS-validated module. As part of this service, the module will internally perform the full public key validation of the generated public key. The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 800-56Ar3.
11.4 End of Life

Once the module reaches its end-of-life stage (End of Life (EOL) date for the Nuvoton device is 10 years from manufacturing date) or sanitation is initiated by the module’s Operator, it is the Operator’s responsibility to clear all existing SSPs from the module. This can be achieved by either performing a full device reset, or by explicitly invoking the following sequence of APIs to clear the data from all modules:

42 of 47

Page 43
12 Mitigation of Other Attacks

The module does not implement security mechanisms to mitigate other attacks. © 2025 Nuvoton Technology Corporation / atsec information security.

43 of 47

Page 44
Table, extracted as text (did not parse into structured rows)
Glossary and Abbreviations AES               Advanced Encryption Standard ACVP              Algorithm Certification Validation Program CBC               Cipher Block Chaining CAST              Cryptographic Algorithm Self-Test CCM               Counter with Cipher Block Chaining-Message Authentication Code CFB               Cipher Feedback CMAC              Cipher-based Message Authentication Code CMVP              Cryptographic Module Validation Program CSP               Critical Security Parameter CTR               Counter Mode DRBG              Deterministic Random Bit Generator ECB               Electronic Code Book ECC               Elliptic Curve Cryptography EOL               End Of Life FIPS              Federal Information Processing Standards Publication GCM               Galois Counter Mode HMAC              Hash Message Authentication Code HSS               Hierarchical Signature System KAS               Key Agreement Scheme KAT               Known Answer Test LMS               Leighton-Micali Signature MAC               Message Authentication Code NIST              National Institute of Science and Technology OFB               Output Feedback PSS               Probabilistic Signature Scheme RSA               Rivest, Shamir, Addleman SHA               Secure Hash Algorithm SHS               Secure Hash Standard SSC               Shared Secret Computation TOEPP             Tested Operational Environment’s Physical Perimeter © 2025 Nuvoton Technology Corporation / atsec information security.

44 of 47

Page 45
FIPS140-3FIPS PUB 140-3 - Security Requirements for Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3
FIPS140-3_IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program September 2024 https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validation- program/documents/fips 140-3/FIPS 140-3 IG.pdf
FIPS180-4Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS186-5Digital Signature Standard (DSS) February 2023 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
FIPS197Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt
RFC3394Advanced Encryption Standard (AES) Key Wrap Algorithm September 2002 http://www.ietf.org/rfc/rfc3394.txt
RFC5649Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm September 2009 http://www.ietf.org/rfc/rfc5649.txt
SP800-38ANIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP800-38BNIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf © 2025 Nuvoton Technology Corporation / atsec information security. 45 of 47
Page 46
SP800-38CNIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
SP800-38DNIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP800-38FNIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP800-56Arev3NIST Special Publication 800-56A Revision 3 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf
SP800-56Brev2Recommendation for Pair-Wise Key Establishment Schemes Using Integer Factorization Cryptography March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Br2.pdf
SP800-90Ar1NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP800-90BNIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP800-208NIST Special Publication 800-208 - Recommendation for Stateful Hash-Based Signature Schemes October 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-208.pdf
SP800-108rev1NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions February 2024 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1-upd1.pdf
SP800-133rev2NIST Special Publication 800-133 - Recommendation for Cryptographic Key Generation December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf © 2025 Nuvoton Technology Corporation / atsec information security. 46 of 47
Page 47

SP800-140Br1 NIST Special Publication 800-140Br1 - CMVP Security Policy Requirements November 2023 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140Br1.pdf © 2025 Nuvoton Technology Corporation / atsec information security.

47 of 47