All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Apple corecrypto Module v14.1 [Apple silicon, Kernel, Software, SL1]

Certificate#5101StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorApple Inc.
Low review priority  ·  no TCB surface named  ·  last validated 7 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date12/1/2030
CaveatWhen operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorApple Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Apple corecrypto Module v14.1 [Apple silicon, Kernel, Software, SL1]
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery<br/>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Apple corecrypto Module v14.1 [Apple silicon, Kernel, Software, SL1]
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery<br/>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Apple Inc. Apple corecrypto Module v14.1 [Apple silicon, Kernel, Software, SL1] Prepared for: Apple Inc. One Apple Park Way Cupertino, CA 95014 Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com

Page 2
Table of Contents
#SectionPage
Page 3

This document may be reproduced and distributed only in its original entirely without revision.

Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)8
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Modes List and Description9
Table 5: Approved Algorithms10
Table 6: Vendor-Affirmed Algorithms10
Table 7: Non-Approved, Not Allowed Algorithms11
Table 8: Security Function Implementations13
Table 9: Entropy Certificates14
Table 10: Entropy Sources14
Table 11: Ports and Interfaces16
Table 12: Roles17
Table 13: Approved Services20
Table 14: Non-Approved Services20
Table 15: Storage Areas26
Table 16: SSP Input-Output Methods26
Table 17: SSP Zeroization Methods26
Table 18: SSP Table 127
Table 19: SSP Table 228
Table 20: Pre-Operational Self-Tests29
Table 21: Conditional Self-Tests30
Table 22: Pre-Operational Periodic Information30
Table 23: Conditional Periodic Information31
Table 24: Error States32
Figure 1: Block Diagram8
Page 5

Trademarks Apple’s trademarks applicable to this document are listed in https://www.apple.com/legal/intellectual-property/trademark/appletmlist.html. Other company, product, and service names may be trademarks or service marks of others. This document may be reproduced and distributed only in its original entirely without revision.

Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for Apple corecrypto Module v14.1 [Apple silicon, Kernel, Software, SL1] cryptographic module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for This document provides all tables and diagrams (when applicable) required by NIST SP 800140Br1.

1.2 Security Levels

Table 1: Security Levels This document may be reproduced and distributed only in its original entirely without revision.

Page 7
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Apple corecrypto Module v14.1 [Apple silicon, Kernel, Software, SL1] cryptographic module (hereafter referred to as “the module”) provides implementations of lowlevel cryptographic primitives to the visionOS’s kernels Security Framework and Common Crypto. The module provides services intended to protect data in transit and at rest. The module is optimized for library use within the visionOS kernel space and does not contain any terminating assertions or exceptions. It is implemented as a visionOS dynamically loadable library. The library is loaded into the visionOS kernel and its cryptographic functions are made available to visionOS kernel services only. Any internal error detected by the module is returned to the caller with an appropriate return code. The calling visionOS kernel service must examine the return code and act accordingly. The module communicates any error status synchronously through the use of its documented return codes, thus indicating the module’s status. Caller-induced or internal errors do not reveal any sensitive material to callers. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The module cryptographic boundary is delineated by the dotted green rectangle in the Figure 1 where the Kernel Extension (KEXT) is a bundle that performs low-level tasks. KEXTs run in kernel space, which gives them elevated privileges and the ability to perform tasks that user-space apps can’t. Tested Operational Environment’s Physical Perimeter (TOEPP): The physical perimeter is represented by the most exterior black line in the block diagram Figure 1. The module executes within the kernel space of the computing platforms and operating systems listed in the Tested Operational Environments Table section 2.2. This document may be reproduced and distributed only in its original entirely without revision.

Page 8
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
corecrypto-1638.100.6214.1N/AHMAC-SHA256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
visionOS 1Apple Vision ProApple M Series (ARMv8.6-A) M2YesNA14.1
visionOS 1Apple Vision ProApple M Series (ARMv8.6-A) M2NoNA14.1
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 9
Mode NameDescriptionTypeStatus Indicator
Approved modeApproved mode of operation is entered when the module utilizes the services that use the security functions listed in the Approved Algorithms Table and the Vendor Affirmed Algorithms Table.Approvedreturn a '1' from fips_allowed_mode() for block cipher functions and fips_allowed() for all other services to indicate the executed cryptographic algorithm was approved
Non- Approved modeNon-Approved mode of operation is entered when the module utilizes non- approved security functions in the Table Non-Approved Algorithms Not Allowed in the Approved Mode of Operation.Non- Approvedreturn any non-zero value from fips_allowed_mode() for block cipher functions and fips_allowed() for all other services to indicate the executed cryptographic algorithm was non- approved
AlgorithmCAVP CertPropertiesReference
AES-CBCA5413-SP 800-38A
AES-CBCA5414-SP 800-38A
AES-CCMA5416-SP 800-38C
AES-CFB128A5413-SP 800-38A
AES-CFB128A5414-SP 800-38A
AES-CFB8A5414-SP 800-38A
AES-CTRA5414-SP 800-38A

Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid:

2.3 Excluded Components

None for this module. Modes List and Description: Operation is assumed automatically without any specific configuration. If the device starts up successfully then the module has passed all self-tests and is operating in the Approved mode. This document may be reproduced and distributed only in its original entirely without revision.

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CTRA5416-SP 800-38A
AES-ECBA5413-SP 800-38A
AES-ECBA5414-SP 800-38A
AES-ECBA5416-SP 800-38A
AES-GCMA5416-SP 800-38D
AES-KWA5414-SP 800-38F
AES-OFBA5413-SP 800-38A
AES-OFBA5414-SP 800-38A
AES-XTS Testing Revision 2.0A5413-SP 800-38E
Counter DRBGA5414-SP 800-90A Rev. 1
Counter DRBGA5416-SP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A5369-FIPS 186-4
ECDSA KeyVer (FIPS186-4)A5369-FIPS 186-4
ECDSA SigGen (FIPS186-4)A5369-FIPS 186-4
ECDSA SigVer (FIPS186-4)A5369-FIPS 186-4
HMAC-SHA-1A5369-FIPS 198-1
HMAC-SHA2-224A5369-FIPS 198-1
HMAC-SHA2-256A5369-FIPS 198-1
HMAC-SHA2-256A5417-FIPS 198-1
HMAC-SHA2-384A5369-FIPS 198-1
HMAC-SHA2-384A5415-FIPS 198-1
HMAC-SHA2-512A5369-FIPS 198-1
HMAC-SHA2-512A5415-FIPS 198-1
HMAC-SHA2-512/256A5369-FIPS 198-1
HMAC-SHA2-512/256A5415-FIPS 198-1
RSA SigGen (FIPS186-4)A5369-FIPS 186-4
RSA SigVer (FIPS186-4)A5369-FIPS 186-4
SHA-1A5369-FIPS 180-4
SHA2-224A5369-FIPS 180-4
SHA2-256A5369-FIPS 180-4
SHA2-256A5417-FIPS 180-4
SHA2-384A5369-FIPS 180-4
SHA2-384A5415-FIPS 180-4
SHA2-512A5369-FIPS 180-4
SHA2-512A5415-FIPS 180-4
SHA2-512/256A5369-FIPS 180-4
SHA2-512/256A5415-FIPS 180-4
NamePropertiesImplementationReference
Asymmetric (CKG)N/ASP 800-133Rev2 section 4 example 1

Table 5: Approved Algorithms The FIPS 186-4 CAVP tests in the listed ACVP certificates above are mathematically identical to the FIPS 186-5 CAVP tests. Per FIPS 140-3 C.K Additional Comments 2, the module claims compliance with FIPS 186-5 tests. Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: This document may be reproduced and distributed only in its original entirely without revision.

Page 11
NameUse and Function
ANSI X9.63 KDFHash based Key Derivation Function
BlowfishEncryption / Decryption
CAST5Encryption / Decryption
DESEncryption / Decryption
ECDSAPKG: Curve P-192; PKV: Curve P-192; Signature Generation: Curve P- 192; Signature Verification: Curve P-192
ECDSA KeyGenKey Pair Generation for compact point representation of points
EdDSAKey Generation, Signature Generation, Signature Verification with Ed25519
HKDF [SP800-56Crev2]Key Derivation Function
Integrated Encryption Scheme on elliptic curves (ECIES)Encryption / Decryption
MD2Message Digest
MD4Message Digest
OMAC (One-Key CBC MAC)MAC generation /verification
RC2Encryption / Decryption
RC4Encryption / Decryption
RIPEMDMessage Digest
RSA SigGenPKCS#1 v1.5 and PSS; Signature Generation using key sizes less than 2048-bits
RSA SigVerSignature Verification using key sizes less than1024
RSA Key WrappingOAEP, PKCS#1 v1.5 and -PSS schemes
Triple-DES [SP 800-67r2]Encryption / Decryption
MD5Message Digest
RFC 6637 Key DerivationKey Derivation Function
NameTypeDescriptionPropertiesAlgorithms
Symmetric Encryption and DecryptionBC-UnAuth BC-AuthSymmetric Encryption and DecryptionAES-CBC:Key Length: 128, 192, 256 AES-CCM:Key Length: 128, 192, 256 AES-CFB128:Key Length: 128, 192, 256 AES-CFB8:Key Length: 128, 192, 256 AES-CTR:Key Length: 128, 192,AES-CBC: (A5413, A5414) AES-CCM: (A5416) AES-CFB128: (A5413, A5414) AES-CFB8: (A5414) AES-CTR: (A5414, A5416) AES-ECB: (A5413, A5414, A5416) AES-GCM: (A5416) AES-OFB: (A5413, A5414) AES-XTS Testing

N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: Table 7: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

This document may be reproduced and distributed only in its original entirely without revision.

Page 12
NameTypeDescriptionPropertiesAlgorithms
256 AES-ECB:Key Length: 128, 192, 256 AES-GCM:Key Length: 128, 192, 256 AES-OFB:Key Length: 128, 192, 256 AES-XTS:Key Length: 128, 256Revision 2.0: (A5413)
Key Wrapping and UnwrappingKTS-Wrap BC-AuthKey Wrapping and UnwrappingAES-KW:Key Length: 128, 192, 256AES-KW: (A5414)
Random Number GenerationDRBGRandom Number GenerationCounter DRBG:AES-128, AES-256; Derivation Function Enabled; No Prediction Resistance; Key size: 128, 256 bitsCounter DRBG: (A5414, A5416)
Keyed HashMACKeyed HashHMAC-SHA-1:Key Size: 128 - 262144 bits; Key Strength: 128 bits HMAC-SHA2- 224:Key Size: 224 - 262144 bits; Key Strength: 224 bits HMAC-SHA2- 256:Key Size: 256 - 262144 bits; Key Strength: 256 bits HMAC-SHA2- 384:Key Size: 384 - 262144 bits; Key Strength: 384 bits HMAC-SHA2- 512:Key Size: 512 - 262144 bits; Key Strength: 512 bits HMAC-SHA2- 512/256:Key Size: 512 - 262144 bits; Key Strength: 256 bitsHMAC-SHA2-256: (A5417, A5369) HMAC-SHA2-384: (A5415, A5369) HMAC-SHA2-512: (A5415, A5369) HMAC-SHA2- 512/256: (A5415, A5369) HMAC-SHA-1: (A5369) HMAC-SHA2-224: (A5369)
Asymmetric Key GenerationAsymKeyPair- KeyGen CKGAsymmetric Key GenerationECDSA KeyGen (FIPS186-4):Key Size(Curve): P-224, P-256, P-384, P- 521; Key Strength: from 112 to 256 bitsECDSA KeyGen (FIPS186-4): (A5369) Asymmetric (CKG): ()
Asymmetric Key ValidationAsymKeyPair- KeyVerAsymmetric Key ValidationECDSA KeyVer (FIPS186-4):Key Size(Curve): P-224, P-256, P-384, P- 521; Key Strength: from 112 to 256 bitsECDSA KeyVer (FIPS186-4): (A5369)

This document may be reproduced and distributed only in its original entirely without revision.

Page 13
NameTypeDescriptionPropertiesAlgorithms
Digital Signature GenerationDigSig-SigGenDigital Signature GenerationECDSA SigGen (FIPS186-4):Key Size(Curve): P-224, P-256, P-384, P- 521; Key Strength: from 112 to 256 bits RSA SigGen (FIPS186-4):Key Size: 2048, 3072, 4096 bits; Key Strength: from 112 to 150 bitsECDSA SigGen (FIPS186-4): (A5369) RSA SigGen (FIPS186-4): (A5369)
Digital Signature VerificationDigSig-SigVerDigital Signature VerificationECDSA SigVer (FIPS186-4):Key Size(Curve): P-224, P-256, P-384, P- 521; Key Strength: from 112 to 256 bits RSA SigVer (FIPS186-4):Key Size: 1024, 2048, 3072, 4096 bits; Key Strength: from 80 to 150 bitsECDSA SigVer (FIPS186-4): (A5369) RSA SigVer (FIPS186-4): (A5369)
Digital Signature Verification (Legacy)DigSig-SigVerDigital Signature Verification using SHA1ECDSA SigVer (FIPS186-4):Key Size(Curve): P-224, P-256, P-384, P- 521; Key Strength: from 112 to 256 bits RSA SigVer (FIPS186-4):Key Size: 1024, 2048, 3072, 4096 bits; Key Strength: from 80 to 150 bitsECDSA SigVer (FIPS186-4): (A5369) RSA SigVer (FIPS186-4): (A5369)
Message DigestSHAMessage DigestSHA-1:N/A SHA2-224:N/A SHA2-256:N/A SHA2-384:N/A SHA2-512:N/A SHA2-512/256:N/ASHA2-384: (A5415, A5369) SHA2-512: (A5415, A5369) SHA2-512/256: (A5415, A5369) SHA2-256: (A5417, A5369) SHA-1: (A5369) SHA2-224: (A5369)

Table 8: Security Function Implementations

2.7 Algorithm Specific Information

AES-GCM AES-GCM IV is constructed in compliance with IG C.H scenario 1 (IPsec-v3). This document may be reproduced and distributed only in its original entirely without revision.

Page 14
CertVendor
NumberName
E113apple
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Apple corecrypto physical entropy sourcePhysicalSee Tested Operational Environment Table in section 2.2256 bitSHA-256 [ACVP cert. #C1223]

The GCM IV generation follows RFC 4106 and shall only be used for the IPsec protocol version 3. When the IV in RFC 4106 exhausts the maximum number of possible values for a given security association, either party to the security association that encounters this condition triggers a rekeying with IKEv2 to establish a new encryption key for the security association. The module uses RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AESGCM encryption keys are derived. In compliance with IG C.H section 3, if the module’s power is lost and then restored, the key used for the AES GCM encryption/decryption shall be re-distributed. This condition is not enforced by the module. AES-XTS AES-XTS mode is only approved for hardware storage applications. The length of the AES-XTS data unit does not exceed 220 blocks. The module checks explicitly that Key_1 ≠ Key_2 before using the keys in the XTS-Algorithm to process data with them compliant with IG C.I. Digital signature generation using SHA-1 is non-approved and not allowed in approved services. Digital signature verification using SHA-1 is considered approved (“Legacy”). HMAC using SHA-1 is approved. The SHA-1 algorithm, as implemented by the module, will be non-approved for all purposes except signature verification, starting January 1, 2031. Note: Algorithms designated as “Legacy” can only be used on data that was generated prior to the Legacy Date specified in FIPS 140-3 IG C.M.

2.8 RBG and Entropy

Table 10: Entropy Sources This document may be reproduced and distributed only in its original entirely without revision.

Page 15

Entropy source(s): The random bits used to seed and reseed the module’s approved DRBG comes from a physical entropy source residing within the TOEPP. The entropy source includes a vetted conditioning component in the form of a SHA-256. The min-entropy rate at the output of the entropy source (h_out for the output of the conditioning component per Section 3.1.5 of SP 800-90B) is 256 bits per 256-bit output. The entropy source follows IG 9.3.A scenario 1.(b) i.e., the module is a software module and the entropy sources reside outside of the cryptographic boundary but inside the module’s TOEPP. DRBG(s): The module implements an SP 800-90ARev1 approved deterministic random bit generator (DRBG) in the form of a CTR_DRBG using AES-256 with derivation function and without prediction resistance. The module performs DRBG health tests according to SP800-90ARev1 section 11.3. DRBG Output: The output of CTR_DRBG provides up to 256-bits of security strength.

2.9 Key Generation

The module implements asymmetric key generation compliant to SP800-133r2 Section 4 examples 1 and is listed as a vendor affirmed algorithm per FIPS 140_3 IG D.H. The seed material used to generate the asymmetric key pairs is provided directly output from the module’s CTR_DRBG. The module does not implement symmetric key generation.

2.10 Key Establishment

The module does not implement key establishment.

2.11 Industry Protocols

No parts of the IPSec, other than those mentioned above, have been tested by the CAVP and CMVP. This document may be reproduced and distributed only in its original entirely without revision.

Page 16
Physical PortLogical Interface(s)Data That Passes
N/AData Input Data OutputData inputs/outputs are provided in the variables passed in the C language Kernel Interfaces (KPIs) and callable service invocations, generally through caller-supplied buffers
N/AControl InputControl inputs which control the mode of the module are provided through dedicated parameters.
N/AStatus OutputStatus output is provided in return codes and through messages. Documentation for each KPI lists possible return codes. A complete list of all return codes returned by the C language KPIs within the module is provided in the header files and the KPI documentation. Messages are also documented in the KPI documentation.

Table 11: Ports and Interfaces This document may be reproduced and distributed only in its original entirely without revision.

Page 17
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCrypto OfficerNone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
AES Encryption/DecryptionExecute AES- mode encrypt or decrypt operation0plaintext data and key / ciphertext data and keyciphertext data / plaintext dataSymmetric Encryption and DecryptionCrypto Officer - AES key: W,E
AES Key Wrapping / Key UnwrappingExecute AES- key wrapping or unwrapping operation0key wrapping key, unwrapped key / Wrapped key, AES key wrapping keywrapped key / unwrapped keyKey Wrapping and UnwrappingCrypto Officer - AES key- wrapping key: W,E
Secure Hash GenerationGenerate a digest for the requested algorithm0messagedigestMessage DigestCrypto Officer
4 Roles, Services, and Authentication

N/A for this module. FIPS 140-3 does not require an authentication mechanism for level 1 modules. Therefore, the module does not support an authentication mechanism for Crypto Officer. The Crypto Officer role is authorized to access all services provided by the module (see Table - Approved Services and Table - Non-Approved Services).

4.2 Roles
4.3 Approved Services

The abbreviations of the access rights to SSPs have the following interpretation: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. N/A = The service does not access any SSP during its operation This document may be reproduced and distributed only in its original entirely without revision.

Page 18
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Message Authentication GenerationGenerate a MAC digest using the requested SHA algorithm0message, MAC key, MAC algorithmMACKeyed HashCrypto Officer - HMAC key: W,E
Message Authentication Code VerificationVerify a MAC digest0MAC, message, MAC key, MAC algorithmpass/failKeyed HashCrypto Officer - HMAC key: W,E
RSA signature generation and verificationSign a message with a specified RSA private key. Verify the signature of a message with a specified RSA public key.0SigGen: private key, message, hash function; SigVer: public key, digital signature, message, hash functionSigGen: computed signature; SigVer: pass/fail result of digital signature verificationDigital Signature Generation Digital Signature Verification Digital Signature Verification (Legacy)Crypto Officer - RSA key pair: W,E
ECDSA signature generation and verificationSign a message with a specified ECDSA private key Verify the signature of a message with a specified ECDSA public key0SigGen: private key, message, hash function; SigVer: public key, digital signature, message, hash functionSigGen: computed signature; SigVer: pass/fail result of digital signature verificationDigital Signature Generation Digital Signature Verification Digital Signature Verification (Legacy)Crypto Officer - ECDSA key pair: W,E
Random Number GenerationGenerate random number0length of generated numberrandom bit- stringRandom Number GenerationCrypto Officer - Entropy input string: E - DRBG seed, internal state V value, and key: G,W,E
ECDSA key pair generation and validationGenerate a keypair for a requested elliptic curve and validity0curve sizekey pairAsymmetric Key Generation Asymmetric Key ValidationCrypto Officer - DRBG seed, internal state V value, and key: W,E - ECDSA key pair: G,R

G,W,E W,E G,R This document may be reproduced and distributed only in its original entirely without revision.

Page 19
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Self-testexecute CASTs0powerpass/fail resultsSymmetric Encryption and Decryption Key Wrapping and Unwrapping Random Number Generation Keyed Hash Asymmetric Key Generation Asymmetric Key Validation Digital Signature Generation Digital Signature Verification Digital Signature Verification (Legacy) Message DigestCrypto Officer
Show StatusReturn the module statusN/AN/AStatus outputNoneCrypto Officer
Show version/module infoReturn Module Base Name and Module Version NumberN/AN/AModule informationNoneCrypto Officer
ZeroizationSSPs are zeroised when the system is powered down, when all resources of symmetric crypto function context, all resources of hash context, all resources of asymmetric crypto function context are released.0N/AN/ANoneCrypto Officer - AES key: Z - AES key- wrapping key: Z - HMAC key: Z - ECDSA key pair: Z - RSA key pair: Z - Entropy input string: Z - DRBG seed, internal state V

This document may be reproduced and distributed only in its original entirely without revision.

Page 20
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
value, and key: Z
NameDescriptionAlgorithmsRole
Triple-DES encryption / decryptionExecute Triple-DES mode encrypt or decrypt operation.Triple-DES [SP 800-67r2]CO
RSA Key EncapsulationThe CAST does not perform the full KTS, only the raw RSA encrypt/decrypt.RSA Key WrappingCO
RSA Signature GenerationSign a message with a non- approved RSA private key sizeRSA SigGenCO
RSA Signature VerificationVerify the signature of a message with a non-approved RSA public key sizeRSA SigVerCO
ECDSA key-pair generation, ECDSA signature generation, ECDSA signature verificationFor curve P-192ECDSACO
ECDSA Key Pair Generation for compact point representation of pointsFor compact point representation of pointsECDSA KeyGenCO
EdDSA Key Generation, Signature Generation, Signature VerificationEd25519EdDSACO
ECIESElliptic Curve encrypt/ decryptIntegrated Encryption Scheme on elliptic curves (ECIES)CO
ANSI X9.63 Key DerivationSHA-1 hash-basedANSI X9.63 KDFCO
SP800-56Crev2 Key Derivation (HKDF)SHA-256 hash-basedHKDF [SP800-56Crev2]CO
OMAC Message Authentication Code GenerationOne-Key CBC-MAC using 128-bit keyOMAC (One-Key CBC MAC)CO
OMAC Message Authentication Code VerificationOne-Key CBC-MAC using 128-bit keyOMAC (One-Key CBC MAC)CO
Message digest generationMessage digest generation using non-approved algorithmsMD2 MD4 RIPEMD MD5CO
Symmetric encryption / decryptionSymmetric encryption / decryption using non-approved algorithmsBlowfish CAST5 DES RC2 RC4CO
RFC 6637 KDFSHA-256, SHA-512, AES-128, AES-256RFC 6637 Key DerivationCO

Z Table 13: Approved Services Table 14: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not support the loading of external software/firmware. This document may be reproduced and distributed only in its original entirely without revision.

Page 21

This document may be reproduced and distributed only in its original entirely without revision.

Page 22
5 Software/Firmware Security
5.1 Integrity Techniques

A software integrity test is performed on the runtime image of the module. The HMAC-SHA256 implemented in the module is used as the approved algorithm for the integrity test. If the test fails, the module enters an error state where no cryptographic services are provided, and data output is prohibited i.e. the module is not operational.

5.2 Initiate on Demand

The module’s integrity test can be performed on demand by power-cycling the computing platform. Integrity test on demand is performed as part of the Pre-Operational Self-Tests, automatically executed at power-on. This document may be reproduced and distributed only in its original entirely without revision.

Page 23
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable

6.2 Configuration Settings and Restrictions

The module is supplied as part of visionOS, a commercially available general-purpose operating system executing on the computing platforms specified in section 2.2. This document may be reproduced and distributed only in its original entirely without revision.

Page 24
7 Physical Security

The FIPS 140-3 physical security requirements do not apply to the Apple corecrypto Module v14.1 [Apple silicon, Kernel, Software, SL1] since it is a software module. This document may be reproduced and distributed only in its original entirely without revision.

Page 25
8 Non-Invasive Security

Per IG 12.A, until the requirements of NIST SP 800-140F are defined, non-invasive mechanisms fall under ISO/IEC 19790:2012 Section 7.12 Mitigation of other attacks. The requirements of this area are not applicable to the module. This document may be reproduced and distributed only in its original entirely without revision.

Page 26
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPsDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
KPI input parametersOperator calling application (TOEPP)Cryptographic modulePlaintextManualElectronic
KPI output parametersCryptographic moduleOperator calling application (TOEPP)PlaintextManualElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Wipe and Free memory block allocatedZeroizes the SSPs contained within the cipher handle.Memory occupied by SSPs is overwritten with zeroes and then it is released, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the cipher related zeroization API
Module ResetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed.By unloading and reloading the module
Intermediate value zeroizationIntermediate keygen values are zeroized before the module returns from the key generation function.Intermediate keygen values are zeroized before the module returns from the key generation function.N/A
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES keyAES key128 to 256 bits - 128 to 256 bitsSymmetric - CSPSymmetric Encryption and Decryption
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas Table 16: SSP Input-Output Methods Table 17: SSP Zeroization Methods This document may be reproduced and distributed only in its original entirely without revision.

Page 27
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES key- wrapping keyAES KW128 to 256 bits - 128 to 256 bitssymmetric - CSPKey Wrapping and Unwrapping
HMAC keyHMAC key128 to 256 - 128 to 256MAC - CSPKeyed Hash
ECDSA key pairECDSA key pair (including intermediate keygen values)P-224, P- 256, P-384, P-521 - 112 to 256 bitsAsymmetric - CSPAsymmetric Key GenerationAsymmetric Key Validation Digital Signature Generation Digital Signature Verification Digital Signature Verification (Legacy)
RSA key pairRSA key pair (including intermediate keygen values)2048 - 4096 - 112 to 150 bitsAsymmetric - CSPDigital Signature Generation Digital Signature Verification Digital Signature Verification (Legacy)
Entropy input stringEntropy input string256 bits - 256 bitsEntropy input string - CSPRandom Number Generation
DRBG seed, internal state V value, and keyDRBG input parameters256 bits - 256 bitsDRBG - CSPRandom Number GenerationRandom Number Generation
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyKPI input parametersRAM:PlaintextFrom service invocation to service completionWipe and Free memory block allocated Module Reset
AES key- wrapping keyKPI input parametersRAM:PlaintextFrom service invocation to service completionWipe and Free memory block allocated Module Reset
HMAC keyKPI input parametersRAM:PlaintextFrom service invocation to service completionWipe and Free memory block allocated Module Reset
ECDSA key pairKPI input parameters KPI output parametersRAM:PlaintextFrom service invocation to service completionWipe and Free memory block allocated Module Reset IntermediateDRBG seed, internal state V value, and key:Used With

Table 18: SSP Table 1 This document may be reproduced and distributed only in its original entirely without revision.

Page 28
NameInput - OutputStorageStorage DurationZeroization value zeroizationRelated SSPs
RSA key pairKPI input parametersRAM:PlaintextFrom service invocation to service completionWipe and Free memory block allocated Module Reset Intermediate value zeroizationDRBG seed, internal state V value, and key (IG D.L compliant):Derived From
Entropy input stringRAM:PlaintextStorage duration during the usage of the CSPModule ResetDRBG seed, internal state V value, and key:Used With
DRBG seed, internal state V value, and keyStorage duration during the usage of the CSPModule ResetEntropy input string:Used With

Table 19: SSP Table 2 This document may be reproduced and distributed only in its original entirely without revision.

Page 29
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-256 (A3687)112-bit keyMessage AuthenticationSW/FW IntegrityModule successful executionThe HMAC-SHA2-256 value calculated at runtime is compared with the HMAC-SHA2-256 value stored in the module, computed at compilation time.
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A5416)128-bit key, encryptKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
Counter DRBG (A5414)128-bit keyKATCASTModule becomes operationalCompliant with SP 800-90Ar1Test runs at power-on before the integrity test
Counter DRBG (A5416)128-bit keyKATCASTModule becomes operationalCompliant with SP 800-90Ar1Test runs at power-on before the integrity test
HMAC-SHA2- 256 (A5417)SHA2-256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A5369)SHA2-256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA-1 (A5369)SHA-1KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 512 (A5415)SHA2-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 512 (A5369)SHA2-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
10 Self-Tests

While the module is executing the self-tests, services are not available, and input and output are inhibited.

10.1 Pre-Operational Self-Tests

The module performs a pre-operational software integrity automatically when the module is loaded into memory (i.e., at power on) before the module transitions to the operational state. A used to perform the approved integrity technique. Prior to using HMAC-SHA-256, a Conditional Cryptographic Algorithm Self-Tests (CAST) is performed. Table 20: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

This document may be reproduced and distributed only in its original entirely without revision.

Page 30
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigGen (FIPS186-4) (A5369)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-4) (A5369)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA KeyGen (FIPS186-4) (A5369)PCT with SHA2- 256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA SigGen (FIPS186-4) (A5369)P-224 with SHA- 224KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A5369)P-224 with SHA- 224KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
AES-CBC (A5413)128-bit key encryptKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-CBC (A5414)128-bit key encryptKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5413)128-bit key decryptKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5414)128-bit key decryptKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5416)128-bit key decryptKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-XTS Testing Revision 2.0 (A5413)128-bit key decryptKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
HMAC-SHA2- 512/256 (A5415)SHA2-512/256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 512/256 (A5369)SHA2-512/256KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A3687)Message AuthenticationSW/FW IntegrityWhenever module is powered onUpon every power on
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A5416)KATCASTOn DemandManually

Table 21: Conditional Self-Tests

10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information This document may be reproduced and distributed only in its original entirely without revision.

Page 31
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Counter DRBG (A5414)KATCASTOn DemandManually
Counter DRBG (A5416)KATCASTOn DemandManually
HMAC-SHA2-256 (A5417)KATCASTOn DemandManually
HMAC-SHA2-256 (A5369)KATCASTOn DemandManually
HMAC-SHA-1 (A5369)KATCASTOn DemandManually
HMAC-SHA2-512 (A5415)KATCASTOn DemandManually
HMAC-SHA2-512 (A5369)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A5369)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A5369)KATCASTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A5369)PCTPCTOn DemandManually
ECDSA SigGen (FIPS186-4) (A5369)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A5369)KATCASTOn DemandManually
AES-CBC (A5413)KATCASTOn DemandManually
AES-CBC (A5414)KATCASTOn DemandManually
AES-ECB (A5413)KATCASTOn DemandManually
AES-ECB (A5414)KATCASTOn DemandManually
AES-ECB (A5416)KATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A5413)KATCASTOn DemandManually
HMAC-SHA2- 512/256 (A5415)KATCASTOn DemandManually
HMAC-SHA2- 512/256 (A5369)KATCASTOn DemandManually
NameDescriptionConditionsRecovery MethodIndicator
Error State1) The HMAC- SHA-256 value computed over the module did not match the pre- computed value or 2) The computed value in the1) Pre- operational Software Integrity Test failure or 2) Conditional CAST failure 3)Power cycle the device which results in the module being reloaded into memory and reperforming1) Error message "FAILED: fipspost_post_integrity" send to caller or 2) Error message "FAILED:<event>" sent to caller (<event> refers to any of the cryptographic functions listed Table -Conditional Self-Tests 3) Error code "CCEC_GENERATE_KEY_CONSISTENCY" returned for ECDSA and EC Diffie-Hellman
10.4 Error States

This document may be reproduced and distributed only in its original entirely without revision.

Page 32
NameDescriptionConditionsRecovery MethodIndicator
invoked Conditional CAST did not match the known value or 3) The signature failed to generate/verify successfully in the Conditional PCT. No cryptographic services are provided, and data output is prohibitedConditional PCT failurethe pre- operational software integrity test and the Conditional CASTs.
10.5 Operator Initiation of Self-Tests

The module permits operators to initiate the pre-operational or conditional self-tests on demand for periodic testing of the module by rebooting the system (i.e., power-cycling). This document may be reproduced and distributed only in its original entirely without revision.

Page 33
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Startup Procedures: The module is built into visionOS defined in section 2 and delivered/ installed with the respective visionOS. There is no standalone delivery of the module as a software library. Installation Process and Authentication Mechanisms: The vendor’s internal development process guarantees that the correct version of module goes with its intended visionOS version. For additional assurance, the module is digitally signed by vendor, and it is verified during the integration into Host visionOS. This digital signature-based integrity protection during the delivery/integration process is not to be confused with the HMAC-256 based integrity check performed by the module itself as part of its pre-operational self- tests.

11.2 Administrator Guidance

The Approved mode of operation is configured in the system by default and can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table - Non-Approved Services. If the device starts up successfully, then the module has passed all self-tests and is operating in the Approved mode. Apple Platform Certifications guide and Apple Platform Security guide are provided by Apple which offers IT System Administrators with the necessary technical information to ensure FIPS 140-3 Compliance of the deployed systems. This guide walks the reader through the system’s assertion of cryptographic module integrity and the steps necessary if module integrity requires remediation.

11.3 Non-Administrator Guidance

No non-administrator guidance.

11.4 Design and Rules

The Crypto Officer shall consider the following requirements and restrictions when using the module.

Page 34
11.5 End of Life

The module secure sanitization is accomplished by first powering the module down, which will zeroize all SSPs within volatile memory. Following the power-down, an uninstall by way of system wipe or system update will zeroize the corecrypto-1638.100.62 binary file listed in Table 2. This document may be reproduced and distributed only in its original entirely without revision.

Page 35
12 Mitigation of Other Attacks

The module does not claim mitigation of other attacks. This document may be reproduced and distributed only in its original entirely without revision.