All modules
CMVP Validated Module · FIPS 140-3 Security Policy

VaultIP RT-130

Certificate#5100StandardFIPS 140-3Level2TypeHardwareEmbodimentSingle ChipStatusActiveVendorRambus Inc.
Medium review priority  ·  exposes debug/recovery interface, HSM/SE firmware trust anchor  ·  last validated 7 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date12/1/2030
CaveatWhen operated in approved mode.
VendorRambus Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for VaultIP RT-130
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>No authentication</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for VaultIP RT-130
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>No authentication</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Rambus Inc. VaultIP RT-130 Prepared by: Prepared for: atsec information security corporation Rambus Inc.

4516 Seton Center Parkway, Suite 250 4453 North First Street, Suite 100

Austin, TX 78759 San Jose, CA 95134 www.atsec.com www.rambus.com

Page 2
Table of Contents
#SectionPage
Page 3

©2024 Rambus Inc. / atsec information security.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware9
Table 3: Modes List and Description9
Table 4: Approved Algorithms13
Table 5: Vendor-Affirmed Algorithms13
Table 6: Non-Approved, Allowed Algorithms13
Table 7: Non-Approved, Allowed Algorithms with No Security Claimed14
Table 8: Non-Approved, Not Allowed Algorithms15
Table 9: Security Function Implementations19
Table 10: Entropy Certificates20
Table 11: Entropy Sources20
Table 12: Ports and Interfaces22
Table 13: Authentication Methods23
Table 14: Roles23
Table 15: Approved Services36
Table 16: Non-Approved Services38
Table 17: Mechanisms and Actions Required42
Table 18: Storage Areas44
Table 19: SSP Input-Output Methods45
Table 20: SSP Zeroization Methods45
Table 21: SSP Table 150
Table 22: SSP Table 255
Table 23: Pre-Operational Self-Tests56
Table 24: Conditional Self-Tests59
Table 25: Pre-Operational Periodic Information60
Table 26: Conditional Periodic Information61
Table 27: Error States62
Figure 1 - Xilinx Zynq XC7Z045 FPGA7
Figure 2: Block Diagram8
Page 5
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level2
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for the Rambus VaultIP RT-

130 cryptographic module (hereafter referred to as “the module” or RT-130 or only VaultIP).

It contains a specification of the rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for a Security Level 2 module.

1.2 Security Levels
1.3 Additional Information

VaultIP is a Silicon IP Security Module which includes a complete set of high-level and lowlevel cryptographic functions. It offers key management and crypto functions needed for platform and application security such as Content Protection and Mobile Payment, and can be used stand-alone or as a 'Root of Trust' to support a Trusted Execution Environment-based platform. VaultIP completely shields all key and security sensitive data from all CPUs, interfaces and memory. Security sensitive materials are stored as assets that never leave VaultIP in unencrypted and/or non-authenticated form. Additionally, VaultIP offers hardware security features that are needed when operating in a Trusted Execution Environment (TEE). These features include One-Time-Programmable memory (OTP) access and management, Random Number Generation / entropy source, timers, (short) monotonic/non-volatile counters and import and export of keys and other assets. ©2024 Rambus Inc. / atsec information security.

Page 6

The module provides a slave and a master interface. The slave interface is used to receive commands from one or more host CPUs. The master interface is used for autonomous data reads and writes from and to an external memory, flash or interface. VaultIP supports many Approved or Allowed cryptographic algorithms. ©2024 Rambus Inc. / atsec information security.

Page 7
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The primary application of VaultIP is in mobile communications and consumer electronics appliances, where authentication, encrypted content processing using standard protocols, and protection of keys and other sensitive assets are required. VaultIP is best suited for mobile phones, tablets, wireless handsets, PDA-like devices and set top boxes that have the resources and connectivity to download, store and play back digital media content. These small, battery-powered devices require a low power IP solution with these features available in VaultIP. VaultIP is primarily aimed to be integrated in the design of Application-Specific Integrated Circuits (ASIC). However, it can also be synthesized in a Field-Programmable Gate Array (FPGA). Module Type: Hardware Module Embodiment: SingleChip Module Characteristics [O]: SubChip Cryptographic Boundary: The block diagram in Figure 2 shows the cryptographic module boundary represented with the red line box and the physical boundary shown as the most external thick black line. The orange and grey boxes represent the VaultIP components that comprise the IP core. The VaultIP firmware is stored in Program ROM and Program RAM. Figure 2 shows the details of interfaces that cross the security boundary. Tested Operational Environment’s Physical Perimeter (TOEPP): For the purpose of this Cryptographic Module Validation, VaultIP is synthesized on the Xilinx Zynq XC7Z045 FPGA chip, which belongs to the Zynq-7000 All Programmable SoC series. The Xilinx ZC706 evaluation board for the XC7Z045 SoC provides the hardware environment for developing and evaluating the hardware design of VaultIP. Photograph and Block Diagram The module physical boundary is defined by the Xilinx Zynq XC7Z045 FPGA perimeter. The FPGA is a rectangular enclosure measuring approximately 31 mm x 31 mm x 3 mm. Figure 1 - Xilinx Zynq XC7Z045 FPGA The block diagram of the sub-chip module is shown below. ©2024 Rambus Inc. / atsec information security.

Page 8

Figure 2: Block Diagram ©2024 Rambus Inc. / atsec information security.

Page 9
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
Xilinx Zynq XC7Z045 FPGA4.3.14.6.3ARM Cortex-A9
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service
Non- approved modeAutomatically entered whenever a non-approved service is requestedNon- ApprovedEquivalent to the indicator of the requested service
AlgorithmCAVP CertPropertiesReference
AES-CBCA5264Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: Table 3: Modes List and Description Once the module is powered on and the self-tests are successful, the module becomes The mode of operation is assumed based on the service invoked i.e., the module switches back and forth between approved and non-approved modes based on the service called. By when non-approved services are requested (Section 4.4). The module switches back to approved mode of operation when an approved service in Section 4.3 is called. The module implements the approved service indicator as described in Section 4.3.

2.5 Algorithms

Approved Algorithms: ©2024 Rambus Inc. / atsec information security.

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CCMA5264Key Length - 128, 192, 256SP 800-38C
AES-CMACA5264Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA5264Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5264Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA5264Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GMACA5264Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-KWPA5264Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-XTS Testing Revision 2.0A5264Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA5264Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A5264Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - extra bitsFIPS 186-5
ECDSA KeyVer (FIPS186-4)A5264Curve - P-192FIPS 186-4
ECDSA KeyVer (FIPS186-5)A5264Curve - P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A5264Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A5264Component - No Curve - P-192, P-224, P-256, P-384, P- 521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-5)A5263Curve - P-256 Hash Algorithm - SHA2-256FIPS 186-5
ECDSA SigVer (FIPS186-5)A5264Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-5

©2024 Rambus Inc. / atsec information security.

Page 11
AlgorithmCAVP CertPropertiesReference
HMAC-SHA-1A5264Key Length - Key Length: 112-512 Increment 8FIPS 198-1
HMAC-SHA2-224A5264Key Length - Key Length: 112-512 Increment 8FIPS 198-1
HMAC-SHA2-256A5264Key Length - Key Length: 128-512 Increment 8FIPS 198-1
HMAC-SHA2-384A5264Key Length - Key Length: 192-1024 Increment 8FIPS 198-1
HMAC-SHA2-512A5264Key Length - Key Length: 256-1024 Increment 8FIPS 198-1
HMAC-SHA3-224A5264Key Length - Key Length: 112-1152 Increment 8FIPS 198-1
HMAC-SHA3-256A5264Key Length - Key Length: 128-1088 Increment 8FIPS 198-1
HMAC-SHA3-384A5264Key Length - Key Length: 192-832 Increment 8FIPS 198-1
HMAC-SHA3-512A5264Key Length - Key Length: 256-576 Increment 8FIPS 198-1
KAS-ECC Sp800- 56Ar3A5264Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Function - Key Pair Generation Scheme - fullUnified - KAS Role - Initiator, Responder KDF Methods - oneStepKdf - Key Length - 512 ephemeralUnified - KAS Role - Initiator, Responder KDF Methods - oneStepKdf - Key Length - 512 onePassUnified - KAS Role - Initiator, Responder KDF Methods - oneStepKdf - Key Length - 512 onePassDh - KAS Role - Initiator, Responder KDF Methods - oneStepKdf - Key Length - 512 staticUnified - KAS Role - Initiator, Responder KDF Methods -SP 800-56A Rev. 3

©2024 Rambus Inc. / atsec information security.

Page 12
AlgorithmCAVP CertProperties oneStepKdf - Key Length - 512Reference
KDF SP800-108A5264KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 112-1152 Increment 8SP 800-108 Rev. 1
KTS-IFCA5264Modulo - 2048, 3072 Key Generation Methods - rsakpg1-basic Scheme - KTS-OAEP-basic - KAS Role - responder Key Transport Method - Key Length - 1024SP 800-56B Rev. 2
RSA SigGen (FIPS186-5)A5264Modulo - 2048, 3072 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-2)A5264Signature Type - PKCS 1.5, PKCSPSS Modulo - 1536FIPS 186-4
RSA SigVer (FIPS186-4)A5264Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-5)A5264Modulo - 2048, 3072 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A5264Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-224A5264Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-256A5255Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-256A5263Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-256A5264Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-384A5264Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA2-512A5264Message Length - Message Length: 0- 65536 Increment 8FIPS 180-4
SHA3-224A5264Message Length - Message Length: 0- 65536 Increment 8FIPS 202
SHA3-256A5264Message Length - Message Length: 0- 65536 Increment 8FIPS 202
SHA3-384A5264Message Length - Message Length: 0- 65536 Increment 8FIPS 202

©2024 Rambus Inc. / atsec information security.

Page 13
AlgorithmCAVP CertPropertiesReference
SHA3-512A5264Message Length - Message Length: 0- 65536 Increment 8FIPS 202
NamePropertiesImplementationReference
CKG (symmetric)Key Type:SymmetricN/ASP 800-133r2, Section 4, example 1
CKG (asymmetric)Key Type:AsymmetricN/ASP 800-133r2, Section 4, example 1
NamePropertiesImplementationReference
ECDSA key pair generationCurves:brainpoolP224r1, brainpoolP256r1, brainpoolP384r1, brainpoolP512r1 (112, 128, 192, 256 bits of security)Rambus Root of Trust RT-130 (RAM)FIPS 140-3 IG C.A; RFC 5639
ECDSA signature generationCurves:brainpoolP224r1, brainpoolP256r1, brainpoolP384r1, brainpoolP512r1 (112, 128, 192, 256 bits of security)Rambus Root of Trust RT-130 (RAM)FIPS 140-3 IG C.A; RFC 5639
ECDSA signature verificationCurves:brainpoolP192r1, brainpoolP224r1, brainpoolP256r1, brainpoolP384r1, brainpoolP512r1 (96, 112, 128, 192, 256 bits of security)Rambus Root of Trust RT-130 (RAM)FIPS 140-3 IG C.A; RFC 5639
KAS-ECCCurves:brainpoolP224r1, brainpoolP256r1, brainpoolP384r1, brainpoolP512r1 (112, 128, 192, 256 bits of security)Rambus Root of Trust RT-130 (RAM)FIPS 140-3 IG C.A; RFC 5639
NameCaveatUse and Function
Image de- obfuscationFirmware images obfuscated using a non- approved AES key are considered plaintext and unprotected (IG 2.4.A)De-obfuscation of the RAM firmware image

Table 4: Approved Algorithms Vendor-Affirmed Algorithms: Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: Table 6: Non-Approved, Allowed Algorithms Non-Approved, Allowed Algorithms with No Security Claimed: ©2024 Rambus Inc. / atsec information security.

Page 14
NameCaveatUse and Function
AES SIVSSPs obfuscated using this algorithm are considered plaintext and unprotected (IG 2.4.A)De-obfuscation of Asset Key Blobs or OTP Key Blobs
NameUse and Function
AES CTR using external IVEncryption
AES ICMEncryption, Decryption
AES GCM using external IVAuthenticated encryption
AES GCM using IV generated with non- approved entropy source configurationAuthenticated encryption
SHA-1 standaloneMessage digest
AES CBC-MACMAC
AES GMAC using IV generated with non- approved entropy source configurationMAC
HMAC with key sizes less than 112 bitsMAC
Non-approved entropy source configurationRandom number generation
TwoStep KDFKey derivation
CKG with key sizes less than 112 bitsSymmetric key generation
CKG with non-approved entropy source configurationSymmetric key generation
ECDSA key pair generation with non-approved entropy source configurationKey pair generation
ECDSA with P-192Key pair generation, Signature generation
ECDSA with SHA-1Signature generation
ECDSA with non-approved entropy source configurationSignature generation
ECDSA (pre-hashed message)Signature generation, Signature verification
RSA with modulus size not 2048 or 3072 bitsSignature generation
RSA with modulus size not 1024, 1536, 2048, or 3072 bitsSignature verification
RSA with SHA-1Signature generation
RSA-PSS with non-approved entropy source configurationSignature generation

Table 7: Non-Approved, Allowed Algorithms with No Security Claimed ©2024 Rambus Inc. / atsec information security.

Page 15
NameUse and Function
RSA-PSS with invalid salt lengthSignature generation, Signature verification
Diffie-HellmanKey pair generation, Key pair verification, Shared secret computation
EC Diffie-HellmanShared secret computation
Ed25519Key pair generation, Signature generation, Signature verification
X25519Key pair generation, Shared secret computation
RSA-OAEPKey encapsulation
RSA-PKCS#1v1.5Key encapsulation, Key un-encapsulation
ECIESKey encapsulation, Key un-encapsulation
NameTypeDescriptionPropertiesAlgorithms
Signature verification (ROM)DigSig-SigVerVerify a digital signature (ROM)ECDSA SigVer (FIPS186-5): (A5263) SHA2-256: (A5263)
EncryptionBC-UnAuthEncrypt a plaintextAES-CBC: (A5264) AES-CTR: (A5264) AES-ECB: (A5264) AES-XTS Testing Revision 2.0: (A5264)
DecryptionBC-UnAuthDecrypt a ciphertextAES-CBC: (A5264) AES-CTR: (A5264) AES-ECB: (A5264) AES-XTS Testing Revision 2.0: (A5264)
Authenticated encryptionBC-AuthEncrypt a plaintextAES-CCM: (A5264) AES-GCM: (A5264)

Table 8: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

©2024 Rambus Inc. / atsec information security.

Page 16
NameTypeDescriptionPropertiesAlgorithms
Authenticated decryptionBC-AuthDecrypt a plaintextAES-CCM: (A5264) AES-GCM: (A5264)
Message digestSHACompute a message digestSHA2-224: (A5264) SHA2-256: (A5264) SHA2-384: (A5264) SHA2-512: (A5264) SHA3-224: (A5264) SHA3-256: (A5264) SHA3-384: (A5264) SHA3-512: (A5264)
MACMACCompute a MAC tagAES-CMAC: (A5264) AES-GMAC: (A5264) SHA-1: (A5264) HMAC-SHA-1: (A5264) HMAC-SHA2- 224: (A5264) HMAC-SHA2- 256: (A5264) HMAC-SHA2- 384: (A5264) HMAC-SHA2- 512: (A5264) HMAC-SHA3- 224: (A5264) HMAC-SHA3- 256: (A5264) HMAC-SHA3- 384: (A5264) HMAC-SHA3- 512: (A5264)
Random number generationDRBGGenerate random bytesSHA2-256: (A5255) Counter DRBG: (A5264)
Key wrapping (KTS)KTS-WrapWrap a keyKey size:128, 192, 256 bits Standard:SPAES-KWP: (A5264)

©2024 Rambus Inc. / atsec information security.

Page 17
NameTypeDescriptionPropertiesAlgorithms
800-38F IG D.G:approved Key confirmation:no Caveat:Key establishment methodology provides between 128 and 256 bits of security strength
Key unwrapping (KTS)KTS-UnwrapUnwrap a wrapped keyKey size:128, 192, 256 bits Standard:SP 800-56Brev2 IG D.G:approved Key confirmation:no Caveat:Key establishment methodology provides between 128 and 256 bits of security strengthAES-KWP: (A5264)
Key derivationKBKDFDerive a key from a key derivation keyKDF SP800-108: (A5264)
Symmetric key generationCKGGenerate a symmetric keyStandard:SP 800-133r2, Section 4, example 1CKG (symmetric): () Counter DRBG: (A5264)
Key pair generationAsymKeyPair- KeyGenGenerate an EC key pairECDSA KeyGen (FIPS186-5): (A5264)
Key pair verificationAsymKeyPair- KeyVerVerify an EC key pairECDSA KeyVer (FIPS186-4): (A5264) ECDSA KeyVer (FIPS186-5): (A5264)
Signature generationDigSig-SigGenGenerate a digital signatureECDSA SigGen (FIPS186-5): (A5264) RSA SigGen

©2024 Rambus Inc. / atsec information security.

Page 18
NameTypeDescriptionPropertiesAlgorithms
(FIPS186-5): (A5264)
Signature verificationDigSig-SigVerVerify a digital signatureSHA-1: (A5264) ECDSA SigVer (FIPS186-4): (A5264) ECDSA SigVer (FIPS186-5): (A5264) RSA SigVer (FIPS186-2): (A5264) RSA SigVer (FIPS186-4): (A5264) RSA SigVer (FIPS186-5): (A5264)
KASKAS-FullEstablish a shared key among two partiesCurve:P-224, P- 256, P-384, P- 521 Security strength:112, 128, 192, 256 bits IG:IG D.F Scenario 2, path (2), end-to-end Key confirmation:no Key derivation:KDA (tested as part KAS certificate) Caveat:Key establishment methodology provides between 112 and 256 bits of security strengthKAS-ECC Sp800- 56Ar3: (A5264)
KTS- DecapsulationKTS-DecapUn-encapsulate an encapsulated keyModulus size:2048, 3072 bits RSA key generation method:N/A Standard:SP 800-56Brev2 IGKTS-IFC: (A5264)

©2024 Rambus Inc. / atsec information security.

Page 19
NameTypeDescriptionPropertiesAlgorithms
D.G:approved Key confirmation:no Caveat:Key establishment methodology provides between 112 and 128 bits of security strength

Table 9: Security Function Implementations

2.7 Algorithm Specific Information

AES-GCM IV (IG C.H): VaultIP is compliant with scenario 2 of FIPS 140-3 IG C.H in [FIPS1403_IG]. The internal IV is generated in the encryption operation using the RBG-based construction method as defined in section 8.2.2 of [SP800-38D]. VaultIP generates an IV with a length of 96 bits, initialized with random data obtained from the SP800-90Ar1 DRBG implemented in the module. AES-XTS (IG C.I): The AES algorithm in XTS mode can be only used for the cryptographic protection of data on storage devices, as specified in [SP800-38E]. VaultIP implements a check to ensure that the two AES keys used in XTS-AES algorithm are not identical, meeting the requirement of FIPS 140-3 IG C.I in [FIPS140-3_IG]. SP800-56Ar3 assurances (IG D.F): To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the keys for KAS-ECC must be generated using the approved key generation services specified in Section 2.9. The module performs full public key validation on the generated public keys. Additionally, the module performs full public key validation on the received public keys. If the module is used to perform key agreement with the “One-Pass Diffie-Hellman”, “Static Unified Model”, or “One-Pass Unified Model” schemes, a trusted third party is used to obtain the assurance of private key possession for the static peer public key. RSA modulus size (IG C.F): In compliance with FIPS 186-5, the RSA Signature Generation uses module sizes greater or equal to 2048 bits. The 1536 bits RSA is used in approved mode for FIPS 186-2 signature verification, the 1024-bit modulus is used in approved mode for FIPS 186-4 signature verification and the modulus size for FIPS 186-5 signature verification are

2048 and 3072 bits. All supported modulus sizes have been CAVP tested.

SP800-56Br2 assurances (IG D.G): The entity using the IUT must obtain required assurances listed in section 6.4 of SP 800-56Br2 as follows: • The entity requesting the RSA key unwrapping (un-encapsulation) service from the module, shall only use an RSA private key that was generated by an active FIPS validated module that implements FIPS 186-5 compliant RSA key generation service and performs the key pair validity and the pairwise consistency as stated in section

6.4.1.1 of the SP 800-56Br2. Additionally, the entity shall renew these assurances

over time by using any method described in section 6.4.1.5 of the SP 800-56Br2. Legacy use (IG C.M): Per SP800-131r2, the SHA-1 with FIPS 186-4 RSA and ECDSA Digital Signature Verification is used in approved mode (for legacy use), the FIPS 186-4 ECDSA Signature Verification with P-192 is used in approved mode (for legacy use), RSA Digital Signature Verification is used in approved mode (for legacy use) with 1024-bit or 1536-bit modulus. ©2024 Rambus Inc. / atsec information security.

Page 20
CertVendor
NumberName
E167Rambus Inc.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
EIP130 TRNG Entropy SourcePhysicalXilinx Zynq XC7Z045 FPGA256 bitsFull EntropySHA2-256 (A5255)
2.8 RBG and Entropy

Table 10: Entropy Certificates Table 11: Entropy Sources The module provides an SP800-90Ar1-compliant Deterministic Random Bit Generator (DRBG) using CTR_DRBG mechanism with AES-256 for generation of key components of asymmetric keys, and random number generation. The DRBG does not employ a derivation function. The DRBG is seeded and reseeded with 384 bits of entropy input (corresponding to 384 bits of entropy) provided from the entropy source inside the module. This corresponds to scenario 1 of IG 9.3.A. The module complies with the Public Use Document (URL provided in section 11.2) for ESV certificate E167 by reading entropy data from the SHA2-256 conditioning function, which corresponds to the conditioned GetEntropy() function. Outputs of multiple GetEntropy() calls are concatenated to receive the entropy input length greater than 256 bits. The output is truncated to get the entropy input string which is not a multiple of 256. The 384 bits of entropy source output is obtained by calling the GetEntropy() twice, with each call providing 256 bits of output. The second call output is truncated to 128 bits and concatenated to the 256-bit output from the first call. The operational environment on the ESV certificate is identical to the Xilinx Zynq XC7Z045 FPGA, in which the sub-chip components are contained. There are no maintenance requirements for the entropy source.

2.9 Key Generation

VaultIP provides services for generating symmetric and asymmetric keys compliant with [SP800-133r2] section 4 example 1 (vendor affirmed). VaultIP implements symmetric key generation for AES and HMAC keys (”Asset Load (random)” service), using random data obtained from a Deterministic Random Bit Generator (DRBG) compliant with [SP800-90Ar1]. VaultIP implements asymmetric key generation for ECDSA and EC Diffie-Hellman key pairs ("Key pair generation" service) with the following methods:

5.2 i.e. key generation method specified in [SP800-56Ar3] section 5.6.1.2.1 used by

approved key-establishment schemes which maps to [FIPS186-5]. ©2024 Rambus Inc. / atsec information security.

Page 21

Intermediate key generation values are not output from the cryptographic module during or after processing the service. VaultIP implements a key-based key derivation function (KBKDF) in Counter or Feedback modes ("Asset Load (derive)" service) using HMAC-SHA-256 or AES-CMAC [SP800-108r1upd1].

2.10 Key Establishment

Vault IP also provides EC Diffie-Hellman key agreement compliant with [SP800-56Ar3] and using SHA-256 as a one-step key derivation function compliant with section 4.1 of [SP80056Cr2] according to scenario 2 path (2) of IG D.F. The key agreement scheme provides between 112 and 256 bits of security strength. VaultIP provides SSP transport to the dynamic assets entered in encrypted form:

2.11 Industry Protocols

The module does not implement any industry protocol. ©2024 Rambus Inc. / atsec information security.

Page 22
Physical PortLogical Interface(s)Data That Passes
TCM slaveData Input Data Output Control Input Status OutputService requests, service input data, service output data, service result codes
DMA-TCM masterData Input Data OutputBulk service input and output data
Coprocessor interfaceData OutputAsset (SSP) data
MODULE_STATUS registerStatus OutputModule status
soft_reset pinControl InputSoft reset
abort_req pinControl InputSoft reset
reset_n pinControl InputHard reset
clk pinControl InputClock signal
fatal_error pinStatus OutputFatal error
power pinPowerPower
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12: Ports and Interfaces The slave and master interfaces connect the VaultIP RT-130 to the AXI bus system. The slave interface is used to receive commands from one or more host CPUs and send the appropriate response. The master interface is used for autonomous data reads and writes from and to an external memory, flash or interface. ©2024 Rambus Inc. / atsec information security.

Page 23
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Login service32-bit PIN value must be provided via the Login serviceModule compares 32- bit PIN value provided by operator with Login PIN provisioned during module installation32 bits (guess probability = 1/2^32, approx. 10^- 9.63)22.74 bits (guess probability = 614/2^32, approx. 10^-6.84) at 614 attempts per minute
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCOLogin service
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access
System BootContinue initialization of the module by loadingFW accepted bit is set in the MODULE_STFirmware signature, de- obfuscatioN/ASignature verificatio n (ROM)Unauthenti cated
4 Roles, Services, and Authentication

Table 13: Authentication Methods The Crypto Officer role is initialized via the “Provision Random HUK” service, which accepts the 32-bit Login PIN and instructs the module to generate the Hardware Unique Key (HUK) and install the 32-bit Login PIN. The Login PIN is stored in One Time Programmable (OTP) memory and is protected against disclosure, modification, and substitution like any CSP. It cannot be altered except by zeroization of the whole OTP memory. After power-up, the module will require the authentication of the Crypto Officer role before allowing execution of most services (exceptions listed in the table below). Authentication is installation. If the comparison succeeds, then the Login service succeeds and the module is unlocked. Otherwise, the module enters the firmware error state and must be hard reset to allow a new authentication attempt. The Crypto Officer role is always authenticated, both in approved mode and non-approved modes of operation. No authentication data can be output by any of the available services.

4.2 Roles

Table 14: Roles No support is provided for multiple concurrent operators.

4.3 Approved Services

s ©2024 Rambus Inc. / atsec information security.

Page 24
NameDescription the RAM firmware imageIndicator ATUS registerInputs n key, ECDSA public key, de- obfuscatio n IVOutput sSecurity Function sSSP Access
Encryptio nEncrypt a plaintextFAsvc bit is set in the service outputPlaintext, IV (if applicable ), asset store reference to keyCiphert extEncryptio nCrypto Officer - Static AES key: E - Dynamic AES key: E
Decryptio nDecrypt a ciphertextFAsvc bit is set in the service outputCiphertext , IV (if applicable ), asset store reference to keyPlaintex tDecryptio nCrypto Officer - Static AES key: E - Dynamic AES key: E
Authentic ated Encryptio nEncrypt a plaintextFAsvc bit is set in the service outputPlaintext, IV, asset store reference to keyCiphert ext, MAC tagAuthentic ated encryptio nCrypto Officer - Static AES key: E - Dynamic AES key: E
Authentic ated Decryptio nDecrypt a ciphertextFAsvc bit is set in the service outputCiphertext , IV, MAC tag, asset store reference to keyPlaintex t or failAuthentic ated decryptio nCrypto Officer - Static AES key: E - Dynamic AES key: E
HashCompute a message digestFAsvc bit is set in the service outputMessageDigest valueMessage digestCrypto Officer
MAC Tag Generatio nGenerate a MAC tagFAsvc bit is set in the service outputMessage, asset store reference to keyMAC tagMACCrypto Officer - Static AES key: E - Dynamic AES key: E - Static HMAC key: E - Dynamic

s E ©2024 Rambus Inc. / atsec information security.

Page 25
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access HMAC key: E
MAC Tag Verificatio nVerify a MAC tag for a messageFAsvc bit is set in the service outputMessage, MAC tag, asset store reference to keyPass/failMACCrypto Officer - Static AES key: E - Dynamic AES key: E - Static HMAC key: E - Dynamic HMAC key: E
RNG Configura tion (reseed)Reseed the DRBGFAsvc bit is set in the service outputN/AN/ARandom number generatio nCrypto Officer - Entropy input: G,E,Z - DRBG seed: G,E,Z - Internal state (V, Key): G,E,Z
RNG Get Random NumberGenerate random bytes using the DRBG or entropy sourceFAsvc bit is set in the service outputOutput sizeRando m bytesRandom number generatio nCrypto Officer - Internal state (V, Key): E
RNG Post- Processin g Verificatio nVerify the conditioning component and DRBG self-tests using known inputsN/AKnown noise input or DRBG state valuesTest random bitsNoneCrypto Officer
RNG Hardware Self-Test Verificatio nVerify the entropy source health tests using known inputsN/AHealth test paramete rs, known noise inputResultNoneCrypto Officer
Symmetri c WrapWrap key material using AES KWPFAsvc bit is set in the service outputKey wrapping key or asset storeWrappe d key materia lKey wrapping (KTS)Crypto Officer - Static AES key: E - Dynamic

s E E E ©2024 Rambus Inc. / atsec information security.

Page 26
NameDescriptionIndicatorInputs reference to key wrapping key, key material to be wrappedOutput sSecurity Function sSSP Access AES key: E - AES key wrapping key: W,E
Symmetri c UnwrapUnwrap key material using AES KWPFAsvc bit is set in the service outputKey wrapping key, wrapped key materialUnwrap ped key materia lKey unwrappi ng (KTS)Crypto Officer - AES key wrapping key: W,E
Asset CreateAllocate space for an asset in the Dynamic Asset StoreN/AAsset sizeAsset store referen ce to SSPNoneCrypto Officer
Static Asset SearchSearch for an asset in the Static Asset StoreN/AAsset numberAsset store referen ce to SSPNoneUnauthenti cated
Asset Load (derive)Derive a key from a key derivation key and store the result in the Dynamic Asset StoreFAsvc bit is set in the service outputAsset store reference to key derivation key, asset store reference to derived keyN/AKey derivationCrypto Officer - HUK: E - Dynamic AES key: G - Dynamic HMAC key: G - Static key derivation key: E - Dynamic key derivation key: G,E
Asset Load (import)De-obfuscate obfuscated key material using AES-SIV and store the result in the Dynamic Asset Store (AES key,N/AObfuscate d key material, asset store reference to keyN/ANoneCrypto Officer - Dynamic AES key: W - Dynamic HMAC key: W - Dynamic key

s ©2024 Rambus Inc. / atsec information security.

Page 27
NameDescription HMAC key, key derivation key, EC public/private key, or RSA public/private key)IndicatorInputsOutput sSecurity Function sSSP Access derivation key: W - Dynamic EC public key: W - Dynamic EC private key: W - Dynamic RSA public key: W - Dynamic RSA private key: W
Asset Load (random)Generate symmetric key material using the DRBG, store the result in the Dynamic Asset Store, and optionally output the obfuscated resultFAsvc bit is set in the service outputKey size, asset store reference to key materialObfusca ted key materia l (option al)Symmetri c key generatio nCrypto Officer - Internal state (V, Key): E - Dynamic AES key: G,R - Dynamic HMAC key: G,R - Dynamic key derivation key: G,R
Asset Load (plaintext )Store plaintext key material in the Dynamic Asset Store and optionally output the obfuscated resultN/APlaintext key material, asset store reference to keyObfusca ted key materia l (option al)NoneCrypto Officer - Dynamic AES key: R,W - Dynamic HMAC key: R,W - Dynamic key derivation key: R,W - Dynamic EC public key: R,W - Dynamic EC private key: R,W - Dynamic RSA public

s ©2024 Rambus Inc. / atsec information security.

Page 28
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access key: R,W - Dynamic RSA private key: R,W
Asset Load (unwrap)Unwrap wrapped key material using AES KWP and store the result in the Dynamic Asset StoreFAsvc bit is set in the service outputWrapped key material, asset store reference to keyN/AKey unwrappi ng (KTS)Crypto Officer - Dynamic AES key: W - Dynamic HMAC key: W - Dynamic key derivation key: W - Dynamic EC public key: W - Dynamic EC private key: W - Dynamic RSA public key: W - Dynamic RSA private key: W
Asset DeleteDelete an asset from the Dynamic Asset StoreN/AAsset store reference to SSPN/ANoneCrypto Officer - Dynamic AES key: Z - Dynamic HMAC key: Z - Dynamic key derivation key: Z - Dynamic EC public key: Z - Dynamic EC private key: Z - Dynamic RSA public key: Z - Dynamic

s Z ©2024 Rambus Inc. / atsec information security.

Page 29
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access RSA private key: Z
Asset ExportExport an asset via the coprocessor interfaceN/AAsset store reference to SSP, coprocess or selectionAsset dataNoneCrypto Officer - Dynamic AES key: R - Dynamic HMAC key: R - Dynamic key derivation key: R - Dynamic EC public key: R - Dynamic EC private key: R - Dynamic RSA public key: R - Dynamic RSA private key: R
Public Data ReadRead a Public Data assetN/AAsset store referencePublic Data assetNoneUnauthenti cated
Monotoni c Counter ReadRead a Monotonic Counter assetN/AAsset store referenceMonoto nic Counter valueNoneUnauthenti cated
Monotoni c Counter IncrementIncrement a Monotonic Counter assetN/AAsset store referenceN/ANoneCrypto Officer
OTP Data WriteDe-obfuscate obfuscated key material using AES-SIV and store the result in the Static Asset Store (HUK, AES key, HMAC key, key derivationN/AObfuscate d key material, asset store reference to keyN/ANoneCrypto Officer - HUK: W - Static AES key: W - Static HMAC key: W - Static key derivation key: W - Static EC

s ©2024 Rambus Inc. / atsec information security.

Page 30
NameDescription key, EC public/private key, or RSA public/private key)IndicatorInputsOutput sSecurity Function sSSP Access public key: W - Static EC private key: W - Static RSA public key: W - Static RSA private key: W
Provision Random HUKGenerate a random HUK using the DRBG and store the result (together with the provided Login PIN) in the Static Asset StoreHUK has FIPSApprove d bit setLogin PIN, HUK sizeAES-SIV obfusca ted HUKSymmetri c key generatio nCrypto Officer - Internal state (V, Key): E - Login PIN: W - HUK: G,R
Secure TimerStart, stop, or read a timerN/AAsset store referenceTimer valueNoneCrypto Officer
Dynamic Asset Store ResetZeroize the Dynamic Asset StoreN/AN/AN/ANoneCrypto Officer - Dynamic AES key: Z - Dynamic HMAC key: Z - Dynamic key derivation key: Z - Dynamic EC public key: Z - Dynamic EC private key: Z - Dynamic RSA public key: Z - Dynamic

s W W Z ©2024 Rambus Inc. / atsec information security.

Page 31
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access RSA private key: Z
Show statusReturn information about the module stateN/AN/AModule statusNoneUnauthenti cated
Show versionReturn information about the module hardware and firmwareN/AN/AModule versionNoneUnauthenti cated
Self-TestPerform all CASTsFAsvc bit is set in the service outputN/AN/ANoneCrypto Officer
ResetReset the module to its initial stateN/AN/AN/ANoneCrypto Officer
LoginAuthenticate as the Crypto OfficerN/ALogin PINN/ANoneUnauthenti cated - Login PIN: E
Authentic ated Unlock StartStep 1 in the two-step protocol to enable Secure Debug for peripheralsFAsvc bit is set in the service outputAsset store reference to authentic ation keyNonceRandom number generatio nCrypto Officer - Internal state (V, Key): E
Authentic ated Unlock VerifyStep 2 in the two-step protocol to enable Secure Debug for peripheralsFAsvc bit is set in the service outputNonce, signatureN/ASignature verificatio nCrypto Officer - Static EC public key: E - Dynamic EC public key: E
Set Secure DebugActivate a Secure Debug port for a peripheralN/APort numberN/ANoneCrypto Officer

s E ©2024 Rambus Inc. / atsec information security.

Page 32
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access
Key pair generatio nGenerate a key pairFAsvc bit is set in the service outputCurve or modulus size, asset store reference s to key pairN/AKey pair generatio nCrypto Officer - Internal state (V, Key): E - Static EC public key: G - Dynamic EC public key: G - Static EC private key: G - Dynamic EC private key: G - Static RSA public key: G - Dynamic RSA public key: G - Static RSA private key: G - Dynamic RSA private key: G - Intermediat e key generation value: G,E,Z
Key pair verificatio nVerify a key pairFAsvc bit is set in the service outputAsset store reference s to key pairPass/failKey pair verificatio nCrypto Officer - Static EC public key: G - Dynamic EC public key: G - Static EC private key: G - Dynamic EC private key: G

s G G G G G,E,Z G ©2024 Rambus Inc. / atsec information security.

Page 33
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access - NIST SP 800- 56Arev3 domain parameters : E
Signature generatio nGenerate a signature for a messageFAsvc bit is set in the service outputMessage, asset store reference to private keySignatu reSignature generatio nCrypto Officer - Static EC private key: E - Dynamic EC private key: E - Static RSA private key: E - Dynamic RSA private key: E
Signature verificatio nVerify a signature for a messageFAsvc bit is set in the service outputMessage, signature, asset store reference to public keyPass/failSignature verificatio nCrypto Officer - Static EC public key: E - Dynamic EC public key: E - Static RSA public key: E - Dynamic RSA public key: E
KASEstablish a shared key among two partiesFAsvc bit is set in the service outputAsset store reference( s) to owner private key(s), asset store reference( s) to peer public key(s), asset storeN/AKASCrypto Officer - Static AES key: G - Dynamic AES key: G - Static HMAC key: G - Dynamic HMAC key: G - Static key derivation key: G

s :E E E ©2024 Rambus Inc. / atsec information security.

Page 34
NameDescriptionIndicatorInputs reference to shared keyOutput sSecurity Function sSSP Access - Dynamic key derivation key: G - Static EC public key: E - Dynamic EC public key: E - Static EC private key: E - Dynamic EC private key: E - Shared secret: G,E,Z - NIST SP 800- 56Arev3 domain parameters : E
Key un- encapsula tionUn- encapsulate key material using KTS-IFCFAsvc bit is set in the service outputEncapsula ted key material, asset store reference to owner private key, asset store reference to un- encapsula ted keyN/AKTS- Decapsul ationCrypto Officer - Dynamic AES key: W - Dynamic HMAC key: W - Dynamic key derivation key: W - Dynamic EC public key: W - Dynamic EC private key: W - Dynamic RSA public key: W - Static RSA public key: E - Dynamic

s E E G,E,Z :E E ©2024 Rambus Inc. / atsec information security.

Page 35
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access RSA private key: W,E
Register ReadRead from a specified addressN/AAddressRead dataNoneUnauthenti cated
Register WriteWrite to a specified addressN/AAddress, write dataN/ANoneCrypto Officer
Clock SwitchActivate/deac tivate clocksN/AClock configurat ionN/ANoneCrypto Officer
Zeroize Output MailboxZeroize the output mailboxN/AN/AN/ANoneCrypto Officer
Select OTP ZeroizeStep 1 in the OTP zeroization processN/AN/AN/ANoneCrypto Officer
Zeroize OTPStep 2 in the OTP zeroization processN/AN/AN/ANoneCrypto Officer - Login PIN: Z - HUK: Z - Static AES key: Z - Static HMAC key: Z - Static key derivation key: Z - Static EC public key: Z - Static EC private key: Z - Static RSA public key: Z - Static RSA private key: Z - NIST SP 800- 56Arev3 domain

s Z Z Z Z Z ©2024 Rambus Inc. / atsec information security.

Page 36
NameDescriptionIndicatorInputsOutput sSecurity Function sSSP Access parameters : Z
Sleep ModeMove the module to the Sleep ModeN/AN/AN/ANoneCrypto Officer
Resume From SleepRestore the module to the operational stateN/AN/AN/ANoneUnauthenti cated
Firmware CheckVerify a firmware image using ECDSA signature verificationFAsvc bit is set in the service outputFirmware image, firmware signature verificatio n keyPass/failSignature verificatio nCrypto Officer - Firmware signature verification key: W,E
Update RollbackI DUpdate the RollbackIDN/ANew RollbackI DN/ANoneCrypto Officer
Hard resetForcefully reset the module using a hardware pinN/AN/AN/ANoneUnauthenti cated

s :Z D D Table 15: Approved Services The following convention is used to specify access rights to SSPs:

4.4 Non-Approved Services

©2024 Rambus Inc. / atsec information security.

Page 37
NameDescriptionAlgorithmsRole
EncryptionEncrypt a plaintextAES CTR using external IV AES ICMCrypto Officer
DecryptionDecrypt a ciphertextAES CTR using external IV AES ICMCrypto Officer
Authenticated EncryptionEncrypt a plaintextAES GCM using external IV AES GCM using IV generated with non- approved entropy source configurationCrypto Officer
HashCompute a message digestSHA-1 standaloneCrypto Officer
MAC Tag GenerationGenerate a MAC tagAES CBC-MAC AES GMAC using IV generated with non- approved entropy source configuration HMAC with key sizes less than 112 bitsCrypto Officer
MAC Tag VerificationVerify a MAC tag for a messageAES CBC-MAC HMAC with key sizes less than 112 bitsCrypto Officer
RNG Configuration (reconfiguration)Use non-approved entropy source configurationNon-approved entropy source configurationCrypto Officer
RNG Get Random NumberGenerate random bytes using a non-approved entropy source configurationNon-approved entropy source configurationCrypto Officer
Asset Load (derive)Derive a key from a key derivation key and store the result in the Dynamic Asset StoreTwoStep KDFCrypto Officer
Asset Load (random)Generate symmetric key material using the DRBG, store the result in the Dynamic Asset Store, and optionally output the obfuscated resultCKG with key sizes less than 112 bits CKG with non-approved entropy source configurationCrypto Officer
Authenticated Unlock StartStep 1 in the two-step protocol to enable Secure Debug for peripheralsNon-approved entropy source configurationCrypto Officer
Key pair generationGenerate a key pairECDSA key pair generation with non- approved entropy source configuration ECDSA with P-192Crypto Officer

©2024 Rambus Inc. / atsec information security.

Page 38
NameDescriptionAlgorithmsRole
Diffie-Hellman Ed25519 X25519
Key pair verificationVerify a key pairDiffie-HellmanCrypto Officer
Signature generationGenerate a signature for a messageECDSA with P-192 ECDSA with SHA-1 ECDSA with non- approved entropy source configuration ECDSA (pre-hashed message) RSA with modulus size not 2048 or 3072 bits RSA with SHA-1 RSA-PSS with non- approved entropy source configuration RSA-PSS with invalid salt length Ed25519Crypto Officer
Signature verificationVerify a signature for a messageECDSA (pre-hashed message) RSA with modulus size not 1024, 1536, 2048, or 3072 bits RSA-PSS with invalid salt length Ed25519Crypto Officer
Key agreementEstablish a shared key among two partiesDiffie-Hellman X25519Crypto Officer
Shared secret computationEstablish a shared secret among two partiesDiffie-Hellman EC Diffie-Hellman X25519Crypto Officer
Key encapsulationEncapsulate key materialRSA-OAEP RSA-PKCS#1v1.5 ECIESCrypto Officer
Key un- encapsulationUn-encapsulate key materialRSA-PKCS#1v1.5 ECIESCrypto Officer

Table 16: Non-Approved Services

4.5 External Software/Firmware Loaded

Upon startup, the ROM firmware component loads the RAM firmware from external storage into the sub-chip cryptographic subsystem. The integrity of the RAM firmware is determined by verifying an ECDSA P-256 with SHA2-256 signature stored in the firmware that was computed at build time. If the signature verification fails, the firmware load test fails. The ©2024 Rambus Inc. / atsec information security.

Page 39

public key used to verify this signature is provided with the RAM firmware, the private key associated with this public key is controlled by the vendor. The hash of the public key is compared with a hash value stored in ROM to ensure the authenticity of the provided public key. All data output is inhibited during the execution of the firmware load test and the firmware loading process. ©2024 Rambus Inc. / atsec information security.

Page 40
5 Software/Firmware Security
5.1 Integrity Techniques

The module employs a CRC24 as integrity technique to integrity verify the ROM code during startup.

5.2 Initiate on Demand

Integrity tests are performed when the module is powered on. The integrity test can be performed on demand by powering off and powering on the module. ©2024 Rambus Inc. / atsec information security.

Page 41
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Non-Modifiable How Requirements are Satisfied: N/A ©2024 Rambus Inc. / atsec information security.

Page 42
MechanismInspection FrequencyInspection Guidance
Tamper-evident coating covering the FPGA components: integrated heat spreader, substrate with solder ball grid array, silicon chip with TMIN/AN/A
7 Physical Security
7.1 Mechanisms and Actions Required

Table 17: Mechanisms and Actions Required The integrated heat spreader (IHS) serves as a protective shell for the processing silicon chip. Interface material (TMI) are production-grade components. They provide opacity in the visible spectrum. ©2024 Rambus Inc. / atsec information security.

Page 43
8 Non-Invasive Security

The module does not implement any non-invasive security mechanisms. ©2024 Rambus Inc. / atsec information security.

Page 44
Storage Area NameDescriptionPersistence Type
Static Asset StoreSSPs are stored in One Time Programmable (OTP) memoryStatic
Dynamic Asset StoreSSPs are maintained in Data RAMDynamic
NameFromToFormat TypeDistributio n TypeEntry TypeSFI or Algorithm
OTP coprocesso r exportStatic Asset StoreCoprocesso r interfacePlaintextManualElectroni c
OTP obfuscated importOperator calling applicatio n (TOEPP)Static Asset StorePlaintextManualElectroni c
OTP obfuscated exportStatic Asset StoreOperator calling application (TOEPP)PlaintextManualElectroni c
RAM coprocesso r exportDynamic Asset StoreCoprocesso r interfacePlaintextManualElectroni c
RAM plaintext importOperator calling applicatio n (TOEPP)Dynamic Asset StorePlaintextManualElectroni c
RAM obfuscated importOperator calling applicatio n (TOEPP)Dynamic Asset StorePlaintextManualElectroni c
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 18: Storage Areas The Static Asset Store and Dynamic Asset Store maintain internal separation of the SSPs (including CSPs) in approved and non-approved modes of operation. Each asset internally maintains a "Fips Approved" bit which indicates if the asset can be used in an approved service or not. SSPs that are not stored in an Asset Store are only transiently used for a specific service. They are by definition exclusive between approved and non-approved services.

9.2 SSP Input-Output Methods

©2024 Rambus Inc. / atsec information security.

Page 45
NameFromToFormat TypeDistributio n TypeEntry TypeSFI or Algorithm
RAM obfuscated exportDynamic Asset StoreOperator calling application (TOEPP)PlaintextManualElectroni c
RAM encrypted importOperator calling applicatio n (TOEPP)Dynamic Asset StoreEncrypte dManualElectroni cKey unwrappin g (KTS)
RAM encrypted exportDynamic Asset StoreOperator calling application (TOEPP)Encrypte dManualElectroni cKey wrapping (KTS)
Zeroization MethodDescriptionRationaleOperator Initiation
Asset Delete serviceZeroize and delete an SSP from the Dynamic Asset StoreMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievableBy invoking the Asset Delete service
Zeroize OTP serviceZeroize all OTP memory, including all SSPs contained in the Static Asset StoreOTP memory is overwritten by ones, which renders the SSP values for all SSPs in the Static Asset Store irretrievableBy invoking the Select OTP Zeroize and Zeroize OTP services
Dynamic Asset Store Reset serviceZeroize all SSPs contained in the Dynamic Asset StoreDynamic Asset Store memory is overwritten by zeroes, which renders the SSP values for all SSPs in the Dynamic Asset Store irretrievableBy invoking the Dynamic Asset Store Reset service
AutomaticSSP is automatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievableN/A
Module resetDe-allocates the volatile memory used to store SSPs in the Dynamic Asset StoreVolatile memory used by the module is overwritten within nanoseconds when the module is resetVia the soft_reset, abort_req, or reset_n pins, or by invoking the Reset service

Table 19: SSP Input-Output Methods Table 20: SSP Zeroization Methods ©2024 Rambus Inc. / atsec information security.

Page 46
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
Login PINPIN value used to authentic ate the Crypto Officer32 bits - 32 bitsAuthenticat ion data - CSP
HUKHardware Unique Key used to derive trusted keys128, 256 bits - 128, 256 bitsRoot key - CSPSymmetr ic key generati onKey derivation
Static AES keyAES key used for encryptio n, decryptio n, and computin g MAC tagsXTS: 256, 512 bits; other modes: 128, 192, 256 bits - XTS: 128, 256 bits; other modes: 128, 192, 256 bitsSymmetric key - CSPSymmetr ic key generati on Key derivatio nKey unwrappin g (KTS) KAS KTS- Decapsulat ionEncryption Decryption Authentica ted encryption Authentica ted decryption MAC Key wrapping (KTS)
Dynamic AES keyAES key used for encryptio n, decryptio n, and computin g MAC tagsXTS: 256, 512 bits; other modes: 128, 192, 256 bits - XTS: 128, 256 bits; other modes: 128, 192, 256 bitsSymmetric key - CSPSymmetr ic key generati on Key derivatio nKey unwrappin g (KTS) KAS KTS- Decapsulat ionEncryption Decryption Authentica ted encryption Authentica ted decryption MAC
AES key wrapping keyAES key used for wrapping128, 192, 256 bits -Symmetric key - CSPKey wrapping (KTS)Key wrapping (KTS)

SSP zeroization when overwriting RAM or OTP memory is performed without delay. Additionally, control is not returned to the operator until the zeroization is completed, preventing any potential compromise of the zeroized SSP. All data output is inhibited during zeroization. The Asset Delete, Zeroize OTP, and Dynamic Asset Store Reset services provide an explicit indicator when the service (i.e., zeroization) completes: Result output parameter. Automatic SSP zeroization is indicated to the operator by successful completion of the relevant service.

9.4 SSPs

©2024 Rambus Inc. / atsec information security.

Page 47
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
and unwrappi ng128, 192, 256 bitsKey unwrappin g (KTS)Key unwrappin g (KTS)
Static HMAC keyHMAC key used for computin g MAC tags112-1152 bits - 112- 256 bitsSymmetric key - CSPSymmetr ic key generati on Key derivatio nKey unwrappin g (KTS) KAS KTS- Decapsulat ionMAC
Dynamic HMAC keyHMAC key used for computin g MAC tags112-1152 bits - 112- 256 bitsSymmetric key - CSPSymmetr ic key generati on Key derivatio nKey unwrappin g (KTS) KAS KTS- Decapsulat ionMAC
Entropy inputEntropy input used to seed the DRBG384 bits - 384 bitsEntropy input - CSPRandom number generati onRandom number generation
DRBG seedDRBG seed derived from the entropy input384 bits - 384 bitsSeed - CSPRandom number generati onRandom number generation
Internal state (V, Key)Internal state of CTR_DRB G instance384 bits - 256 bitsInternal state - CSPRandom number generati onRandom number generation
Static key derivation keySymmetri c key used to derive symmetri c keys112-1152 bits - 112- 256 bitsSymmetric key - CSPSymmetr ic key generati on Key derivatio nKey unwrappin g (KTS) KTS- Decapsulat ionKey derivation
Dynamic key derivation keySymmetri c key used to derive symmetri c keys112-1152 bits - 112- 256 bitsSymmetric key - CSPSymmetr ic key generati on Key derivatio nKey unwrappin g (KTS) KTS- Decapsulat ionKey derivation

n n ©2024 Rambus Inc. / atsec information security.

Page 48
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
Static EC public keyPublic key used for ECDSA and KAS- ECCP-192, P-224, P-256, P-384, P-521, brainpoolP19 2r1, brainpoolP22 4r1, brainpoolP25 6r1, brainpoolP38 4r1, brainpoolP51 2r1 - 96-256 bitsPublic key - PSPKey pair generati onKTS- Decapsulat ionKey pair verification Signature verification KAS
Dynamic EC public keyPublic key used for ECDSA and KAS- ECCP-192, P-224, P-256, P-384, P-521, brainpoolP19 2r1, brainpoolP22 4r1, brainpoolP25 6r1, brainpoolP38 4r1, brainpoolP51 2r1 - 96-256 bitsPublic key - PSPKey pair generati onKTS- Decapsulat ionKey pair verification Signature verification KAS
Static EC private keyPrivate key used for ECDSA and KAS- ECCP-224, P-256, P-384, P-521, brainpoolP22 4r1, brainpoolP25 6r1, brainpoolP38 4r1, brainpoolP51 2r1 - 112- 256 bitsPrivate key - CSPKey pair generati onKTS- Decapsulat ionKey pair verification Signature generation KAS
Dynamic EC private keyPrivate key used for ECDSA and KAS- ECCP-224, P-256, P-384, P-521, brainpoolP22 4r1, brainpoolP25 6r1, brainpoolP38 4r1, brainpoolP51Private key - CSPKey pair generati onKTS- Decapsulat ionKey pair verification Signature generation KAS

©2024 Rambus Inc. / atsec information security.

Page 49
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
2r1 - 112- 256 bits
Static RSA public keyPublic key used for RSA1024, 1536, 2048, 3072 bits - 80-132 bitsPublic key - PSPKTS- Decapsulat ionSignature verification
Dynamic RSA public keyPublic key used for RSA1024, 1536, 2048, 3072 bits - 80-132 bitsPublic key - PSPKTS- Decapsulat ionSignature verification
Static RSA private keyPrivate key used for RSA2048, 3072 bits - 110- 132 bitsPrivate key - CSPKTS- Decapsulat ionSignature generation KTS- Decapsulat ion
Dynamic RSA private keyPrivate key used for RSA2048, 3072 bits - 110- 132 bitsPrivate key - CSPKTS- Decapsulat ionSignature generation KTS- Decapsulat ion
Firmware signature verificatio n keyPublic key used for firmware signature verificatio nP-256 - 128 bitsPublic key - PSPSignature verification
Shared secretShared secret establishe d as part of KAS- ECC224-512 bits - 112-256 bitsShared secret - CSPKASKAS
Intermedi ate key generatio n valueTemporar y value generate d during key pair generatio n services224-4096 bits - 112- 256 bitsIntermediat e value - CSP
NIST SP 800- 56Arev3 domain paramete rsDomain paramete rs used as part of KAS-ECCP-192, P-224, P-256, P-384, P-521, brainpoolP19 2r1, brainpoolP22 4r1, brainpoolP25Domain parameter - PSPKAS

n ©2024 Rambus Inc. / atsec information security.

Page 50
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablish ed ByUsed By
6r1, brainpoolP38 4r1, brainpoolP51 2r1 - 96-256 bits
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
Login PINOTP obfuscated importStatic Asset Store:Obfuscate dFor the lifetime of the moduleZeroize OTP service
HUKOTP obfuscated import OTP obfuscated exportStatic Asset Store:Obfuscate dFor the lifetime of the moduleZeroize OTP service
Static AES keyOTP coprocesso r export OTP obfuscated importStatic Asset Store:Obfuscate dUntil explicitly zeroizedZeroize OTP serviceHUK:Derived From Static key derivation key:Derived From Dynamic key derivation key:Derived From Shared secret:Derive d From
Dynamic AES keyRAM coprocesso r export RAM plaintext import RAM obfuscated import RAM obfuscated export RAM encrypted import RAMDynamic Asset Store:Obfuscate dUntil explicitly zeroized or module resetAsset Delete service Module reset Dynamic Asset Store Reset serviceHUK:Derived From Static key derivation key:Derived From Dynamic key derivation key:Derived From Shared secret:Derive d From

Table 21: SSP Table 1 ©2024 Rambus Inc. / atsec information security.

Page 51
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
encrypted export
AES key wrapping keyRAM plaintext importFor the duration of the serviceAutomatic
Static HMAC keyOTP coprocesso r export OTP obfuscated importStatic Asset Store:Obfuscate dUntil explicitly zeroizedZeroize OTP serviceHUK:Derived From Static key derivation key:Derived From Dynamic key derivation key:Derived From Shared secret:Derive d From
Dynamic HMAC keyRAM coprocesso r export RAM plaintext import RAM obfuscated import RAM obfuscated export RAM encrypted import RAM encrypted exportDynamic Asset Store:Obfuscate dUntil explicitly zeroized or module resetAsset Delete service Dynamic Asset Store Reset service Module resetHUK:Derived From Static key derivation key:Derived From Dynamic key derivation key:Derived From Shared secret:Derive d From
Entropy inputFrom generation until DRBG seed is createdAutomatic
DRBG seedWhile the DRBG is being instantiatedAutomaticEntropy input:Derived From
Internal state (V, Key)From DRBG instantiatio n untilAutomatic Module resetDRBG seed:Derived From

©2024 Rambus Inc. / atsec information security.

Page 52
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
DRBG termination
Static key derivation keyOTP coprocesso r export OTP obfuscated importStatic Asset Store:Obfuscate dUntil explicitly zeroizedZeroize OTP serviceHUK:Derived From Shared secret:Derive d From
Dynamic key derivation keyRAM coprocesso r export RAM plaintext import RAM obfuscated import RAM obfuscated export RAM encrypted import RAM encrypted exportDynamic Asset Store:Obfuscate dUntil explicitly zeroized or module resetAsset Delete service Dynamic Asset Store Reset service Module resetHUK:Derived From Shared secret:Derive d From
Static EC public keyOTP coprocesso r export OTP obfuscated importStatic Asset Store:Obfuscate dUntil explicitly zeroizedZeroize OTP serviceStatic EC private key:Paired With
Dynamic EC public keyRAM coprocesso r export RAM plaintext import RAM obfuscated import RAM obfuscated export RAM encrypted import RAMDynamic Asset Store:Obfuscate dUntil explicitly zeroized or module resetAsset Delete service Dynamic Asset Store Reset service Module resetDynamic EC private key:Paired With

©2024 Rambus Inc. / atsec information security.

Page 53
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
encrypted export
Static EC private keyOTP coprocesso r export OTP obfuscated importStatic Asset Store:Obfuscate dUntil explicitly zeroizedZeroize OTP serviceStatic EC public key:Paired With
Dynamic EC private keyRAM coprocesso r export RAM plaintext import RAM obfuscated import RAM obfuscated export RAM encrypted import RAM encrypted exportDynamic Asset Store:Obfuscate dUntil explicitly zeroized or module resetAsset Delete service Dynamic Asset Store Reset service Module resetDynamic EC public key:Paired With
Static RSA public keyOTP coprocesso r export OTP obfuscated importStatic Asset Store:Obfuscate dUntil explicitly zeroizedZeroize OTP serviceStatic RSA private key:Paired With
Dynamic RSA public keyRAM coprocesso r export RAM plaintext import RAM obfuscated import RAM obfuscated export RAM encrypted import RAMDynamic Asset Store:Obfuscate dUntil explicitly zeroized or module resetAsset Delete service Dynamic Asset Store Reset service Module resetDynamic RSA private key:Paired With

©2024 Rambus Inc. / atsec information security.

Page 54
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
encrypted export
Static RSA private keyOTP coprocesso r export OTP obfuscated importStatic Asset Store:Obfuscate dUntil explicitly zeroizedZeroize OTP serviceStatic RSA public key:Paired With
Dynamic RSA private keyRAM coprocesso r export RAM plaintext import RAM obfuscated import RAM obfuscated export RAM encrypted import RAM encrypted exportDynamic Asset Store:Obfuscate dUntil explicitly zeroized or module resetAsset Delete service Dynamic Asset Store Reset service Module resetDynamic RSA public key:Paired With
Firmware signature verification keyRAM plaintext importFor the duration of the serviceAutomatic
Shared secretFor the duration of the serviceAutomatic
Intermediat e key generation valueFor the duration of the serviceAutomatic
NIST SP 800- 56Arev3 domain parametersDynamic Asset Store:Obfuscate d Static Asset Store:Obfuscate dUntil explicitly zeroized or module resetAsset Delete service Zeroize OTP service Dynamic Asset Store Reset service Module resetStatic EC public key:Used With Static EC private key:Used With Dynamic EC public key:Used

©2024 Rambus Inc. / atsec information security.

Page 55
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
With Dynamic EC private key:Used With
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2030. ©2024 Rambus Inc. / atsec information security.

Page 56
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
CRC24N/AError Detection CodeSW/FW IntegrityCRC24 ok bit is set in the MODULE_STATUS registerCRC24 check is performed on the entire ROM firmware image
Algorith m or TestTest Propertie sTest MethodTest TypeIndicatorDetailsCondition s
ECDSA SigVer (FIPS186- 5) (A5263) KATP-256 with SHA2-256KATCASTROM firmware is ready to accept RAM firmware imageKAT signature verificationROM firmware integrity test passed
SHA2-256 (A5263)320-bit messageKATCASTROM firmware is ready to accept RAM firmware imageKAT message digestROM firmware integrity test passed
ECDSA SigVer (FIPS186-P-256 with SHA2-256Signature verificatio nSW/F W LoadFW accepted bit is set in the MODULE_STATU S registerSignature verification is performed on theRAM firmware image is loaded
10 Self-Tests

While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module does not process service requests from the operator until the tests are completed.

10.1 Pre-Operational Self-Tests

Table 23: Pre-Operational Self-Tests automatically when the module is initialized. If this test fails, the module transitions to the Hardware Error state.

10.2 Conditional Self-Tests

As part of the initialization, the ROM firmware component performs the SHA2-256 and ECDSA and performs the firmware load test on the RAM firmware. Only if these tests succeed, will the RAM firmware be executed. Finally, the RAM firmware automatically performs the rest of the CASTs listed in the table below, before transitioning to the operational state. If any of the tests state. ©2024 Rambus Inc. / atsec information security.

Page 57
Algorith m or TestTest Propertie sTest MethodTest TypeIndicatorDetailsCondition s
5) (A5263)entire RAM firmware image
AES-CBC (A5264)128-bit keyKATCASTSelftestActive field in System Information output is set to 0KAT encryption and decryptionRAM firmware load test passed
AES-CCM (A5264)192-bit key, 88-bit nonceKATCASTSelftestActive field in System Information output is set to 0KAT encryption and decryptionRAM firmware load test passed
AES-XTS Testing Revision 2.0 (A5264)256-bit keyKATCASTSelftestActive field in System Information output is set to 0KAT encryption and decryptionRAM firmware load test passed
AES-GCM (A5264)256-bit key, 128- bit IVKATCASTSelftestActive field in System Information output is set to 0KAT encryption and decryptionRAM firmware load test passed
AES- CMAC (A5264)256-bit keyKATCASTSelftestActive field in System Information output is set to 0KAT MAC tag generationRAM firmware load test passed
Counter DRBG (A5264)AES-256KATCASTSelftestActive field in System Information output is set to 0KAT instantiate, reseed, generate, generate (compliant to SP 800- 90A Section 11.3)RAM firmware load test passed
SHA-1 (A5264)256-bit messageKATCASTSelftestActive field in System Information output is set to 0KAT message digestRAM firmware load test passed

©2024 Rambus Inc. / atsec information security.

Page 58
Algorith m or TestTest Propertie sTest MethodTest TypeIndicatorDetailsCondition s
SHA2-224 (A5264)320-bit messageKATCASTSelftestActive field in System Information output is set to 0KAT message digestRAM firmware load test passed
HMAC- SHA2-256 (A5264)256-bit keyKATCASTSelftestActive field in System Information output is set to 0KAT MAC tag generationRAM firmware load test passed
KDF SP800- 108 (A5264)HMAC SHA2-256 in feedback modeKATCASTSelftestActive field in System Information output is set to 0KAT key- based key derivationRAM firmware load test passed
SHA2-512 (A5264)640-bit messageKATCASTSelftestActive field in System Information output is set to 0KAT message digestRAM firmware load test passed
SHA3-512 (A5264)320-bit messageKATCASTSelftestActive field in System Information output is set to 0KAT message digestRAM firmware load test passed
KDA (A5264)OneStep KDA with SHA2-256KATCASTSelftestActive field in System Information output is set to 0KAT key derivation from shared secretRAM firmware load test passed
ECDSA SigGen (FIPS186- 5) (A5264)P-224 with SHA2-224KATCASTSelftestActive field in System Information output is set to 0KAT signature generationRAM firmware load test passed
ECDSA SigVer (FIPS186- 5) (A5264)P-224 with SHA2-224KATCASTSelftestActive field in System Information output is set to 0KAT signature verificationRAM firmware load test passed
KAS-ECC Sp800- 56Ar3 (A5264)KAS-ECC- SSC with P-224KATCASTSelftestActive field in System Information output is set to 0KAT shared secret computatio nRAM firmware load test passed

©2024 Rambus Inc. / atsec information security.

Page 59
Algorith m or TestTest Propertie sTest MethodTest TypeIndicatorDetailsCondition s
RSA SigGen (FIPS186- 5) (A5264)2048-bit modulus with PKCS#1 v1.5 padding and SHA2- 256KATCASTSelftestActive field in System Information output is set to 0KAT signature generationRAM firmware load test passed
RSA SigVer (FIPS186- 5) (A5264)2048-bit modulus with PKCS#1 v1.5 padding and SHA2- 256KATCASTSelftestActive field in System Information output is set to 0KAT signature verificationRAM firmware load test passed
ECDSA KeyGen (FIPS186- 5) (A5264)SHA-224, SHA-256, SHA-384, SHA-512PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186- 5) (A5264) Sp800- 56Ar3N/APCTPCTSuccessful key pair generationSP 800- 56Ar3 Section 5.6.2.1.4Key pair generation
Entropy Source RCT-STCutoff: 31 samplesStartup health testCASTEntropy source produces entropyRepetition Count TestEntropy source startup
Entropy Source APT-STCutoff: 325 samplesStartup health testCASTEntropy source produces entropyAdaptive Proportion TestEntropy source startup
Entropy Source RCT-CCutoff: 31 samplesContinuou s health testCASTEntropy source produces entropyRepetition Count TestDRBG seeding
Entropy Source APT-CCutoff: 325 samplesContinuou s health testCASTEntropy source produces entropyAdaptive Proportion TestDRBG seeding

5) 5.6.2.1.4 Table 24: Conditional Self-Tests

10.3 Periodic Self-Test Information

©2024 Rambus Inc. / atsec information security.

Page 60
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
CRC24Error Detection CodeSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA SigVer (FIPS186-5) (A5263) KATKATCASTOn demandManually
SHA2-256 (A5263)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A5263)Signature verificationSW/FW LoadOn demandManually
AES-CBC (A5264)KATCASTOn demandManually
AES-CCM (A5264)KATCASTOn demandManually
AES-XTS Testing Revision 2.0 (A5264)KATCASTOn demandManually
AES-GCM (A5264)KATCASTOn demandManually
AES-CMAC (A5264)KATCASTOn demandManually
Counter DRBG (A5264)KATCASTOn demandManually
SHA-1 (A5264)KATCASTOn demandManually
SHA2-224 (A5264)KATCASTOn demandManually
HMAC-SHA2- 256 (A5264)KATCASTOn demandManually
KDF SP800-108 (A5264)KATCASTOn demandManually
SHA2-512 (A5264)KATCASTOn demandManually
SHA3-512 (A5264)KATCASTOn demandManually
KDA (A5264)KATCASTOn demandManually

Table 25: Pre-Operational Periodic Information ©2024 Rambus Inc. / atsec information security.

Page 61
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA SigGen (FIPS186-5) (A5264)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A5264)KATCASTOn demandManually
KAS-ECC Sp800- 56Ar3 (A5264)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A5264)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5264)KATCASTOn demandManually
ECDSA KeyGen (FIPS186-5) (A5264)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A5264) Sp800- 56Ar3PCTPCTOn demandManually
Entropy Source RCT-STStartup health testCASTOn demandManually
Entropy Source APT-STStartup health testCASTOn demandManually
Entropy Source RCT-CContinuous health testCASTOn demandManually
Entropy Source APT-CContinuous health testCASTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
Hardware errorHardware failed to verify the integrity of the ROM firmwareROM firmware integrity test failurePower offCRC24 error bit is set in the MODULE_STATUS register
Firmware errorROM or RAM firmwareUnsuccessful login RAM firmwareHard reset (reset_n pin) or power offFatal error bit is set or FW accepted bit is not set in the

Table 26: Conditional Periodic Information

10.4 Error States

©2024 Rambus Inc. / atsec information security.

Page 62

Name

Description encountered an error

Conditions load test failure CAST failure PCT failure DMA error

Recovery Method

Indicator MODULE_STATUS register

Table 27: Error States In the Hardware Error state, no firmware input or output is possible at all, only the hardware registers such as the MODULE_STATUS register. In the Firmware Error state, only the Show status, Show version and Hard Reset services are available. Cryptographic functions and data output are inhibited.

10.5 Operator Initiation of Self-Tests

To perform the on-demand self-tests that includes the pre-operational self-tests and CASTs, the Crypto Officer shall power-off and power-on or perform a hard reset of the module. ©2024 Rambus Inc. / atsec information security.

Page 63
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

VaultIP synthesized in the Xillinx Zynq XC7Z045 FPGA is a single chip hardware module. The chip is delivered from the vendor via a trusted delivery courier. Upon reception of VaultIP, the customer should verify that the package does not have any irregular tears or openings. The chip comes preloaded with the following code packages:

11.2 Administrator Guidance

The Public Use Document related to the ESV certificate is posted here: https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validationprogram/documents/entropy/E167_PublicUse.pdf The module is configured as a FIPS140-3 module at factory for the Xilinx Zynq XC7Z045 FPGA tested implementation. In this FPGA configuration the Crypto Officer should execute the “Show version" service and verify the following outputs:

11.3 Non-Administrator Guidance
11.4 Design and Rules
Table, extracted as text (did not parse into structured rows)
The Crypto Officer shall consider the following requirements and restrictions when using the module. •   AES GCM IV see Section 2.7 •   AES XTS see Section 2.7 •   SP800-56Ar3 assurances see Section 2.7 •   RSA modulus size see Section 2.7 •   SP800-56Br2 assurances see Section 2.7 •   Legacy use see Section 2.7
11.5 End of Life

Secure sanitization of the module consists of performing the Zeroize OTP service then powering off the module. This will zeroize all SSPs in non-volatile and volatile memory. ©2024 Rambus Inc. / atsec information security.

Page 64
12 Mitigation of Other Attacks

The module does not implement security mechanisms to mitigate other attacks. ©2024 Rambus Inc. / atsec information security.

Page 65
Table, extracted as text (did not parse into structured rows)
Appendix A.               Glossary and Abbreviations AES                 Advanced Encryption Standard ASIC                Application-Specific Integrated Circuit CAST                Cryptographic Algorithm Self-Test CAVP                Cryptographic Algorithm Validation Program CBC                 Cipher Block Chaining CBC-MAC             Cipher Block Chaining Message Authentication Code CCM                 Counter with Cipher Block Chaining Message Authentication Code CKG                 Cryptographic Key Generation CMAC                Cipher-based Message Authentication Code CMVP                Cryptographic Module Validation Program CPU                 Central Processing Unit CRC                 Cyclic Redundancy Check CTR                 Counter Mode DMA                 Direct Memory Access DRBG                Deterministic Random Bit Generator ECB                 Electronic Code Book ECC                 Elliptic Curve Cryptography ECDSA               Elliptic Curve Digital Signature Algorithm ECIES               Elliptic Curve Integrated Encryption Scheme ESV                 Entropy Source Validation FIPS                Federal Information Processing Standards Publication FPGA                Field Programmable Gate Array GCM                 Galois Counter Mode GMAC                Galois Message Authentication Code HMAC                Keyed-Hash Message Authentication Code HUK                 Hardware Unique Key ICM                 Integer Counter Mode IFC                 Integer Factorization Cryptography IV                  Initialization Vector KAS                 Key Agreement Scheme KAT                 Known Answer Test KDF                 Key Derivation Function KTS                 Key Transport Scheme KWP                 AES Key Wrap with Padding MAC                 Message Authentication Code NIST                National Institute of Science and Technology OAEP                Optimal Asymmetric Encryption Padding OTP                 One-Time Programmable PCT                 Pair-wise Consistency Test PDA                 Personal Digital Assistant PIN                 Personal Identification Number PSS                 Probabilistic Signature Scheme RAM                 Random-Access Memory ROM                 Read-Only Memory RSA                 Rivest, Shamir, Adleman SHA                 Secure Hash Algorithm SIV                 Synthetic Initialization Vector SoC                 System on Chip SSP                 Sensitive Security Parameter TCM                 Tightly-Coupled Memory TEE                 Trusted Execution Environment XTS                 XEX-based Tweaked-codebook mode with cipher text Stealing ©2024 Rambus Inc. / atsec information security.
Page 66

Appendix B. References FIPS140-3 FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS140-3_IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validationprogram/fips-140-3-ig-announcements FIPS180-4 Secure Hash Standard (SHS) August 2015 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf FIPS186-2 Digital Signature Standard (DSS) Jan 2000 https://csrc.nist.gov/files/pubs/fips/186-2/final/docs/fips186-2.pdf FIPS186-4 Digital Signature Standard (DSS) July 2013 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf FIPS186-5 Digital Signature Standard (DSS) February 2023 https://doi.org/10.6028/NIST.FIPS.186-5 FIPS197 Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf FIPS198-1 The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf FIPS202 SHA-3 Standard: Permutation-Based Hash and ExtendableOutput Functions August 2015 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf PKCS#1 Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt RFC 5639 Elliptic Curve Cryptography (ECC) Brainpool Standard Curves and Curve Generation March 2010 https://doi.org/10.17487/RFC5639 SP800-38A NIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf ©2024 Rambus Inc. / atsec information security.

Page 67

SP800-38B NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf SP800-38C NIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038c.pdf SP800-38D NIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf SP800-38E NIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 http://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf SP800-38F NIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf SP800-56Ar3 NIST Special Publication 800-56A Revision 3 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.80056Ar3.pdf SP800-56Br2 Recommendation for Pair-Wise Key Establishment Schemes Using Integer Factorization Cryptography March 2019 https://doi.org/10.6028/NIST.SP.800-56Br2 SP800-56Cr2 Recommendation for Key Derivation through Extraction-thenExpansion August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.80056Cr2.pdf SP800-90Ar1 NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.80090Ar1.pdf SP800-90B NIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://doi.org/10.6028/NIST.SP.800-90B ©2024 Rambus Inc. / atsec information security.

Page 68

SP800-108r1- NIST Special Publication 800-108 - Recommendation for Key upd1 Derivation Using Pseudorandom Functions (Revised) August 2022 https://doi.org/10.6028/NIST.SP.800-108r1-upd1 SP800-133r2 NIST Special Publication 800-133 Revision 2 - Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800133r2.pdf SP800-140Br1 NIST Special Publication 800-140Br1 - CMVP Security Policy Requirements November 2023 https://doi.org/10.6028/NIST.SP.800-140Br1 ©2024 Rambus Inc. / atsec information security.