All modules
CMVP Validated Module · FIPS 140-3 Security Policy

IPC Cryptographic Module

Certificate#5106StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorST Engineering Urban Solutions Ltd.
Low review priority  ·  no TCB surface named  ·  last validated 4 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date12/10/2030
CaveatWhen operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys). No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorST Engineering Urban Solutions Ltd.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for IPC Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C3,C5,C6 clue;
  class I3,I5,I6 infer;
  class R3,R5,R6 risk;
  class E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for IPC Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

ST Engineering Urban Solutions Ltd. IPC Cryptographic Module This document may be freely reproduced and distributed in its entirety without modification.

Page 2
Table of Contents
#SectionPage
Page 3

This document may be freely reproduced and distributed in its entirety without modification.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)8
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Modes List and Description8
Table 5: Approved Algorithms11
Table 6: Vendor-Affirmed Algorithms11
Table 7: Non-Approved, Allowed Algorithms12
Table 8: Non-Approved, Not Allowed Algorithms13
Table 9: Security Function Implementations24
Table 10: Ports and Interfaces28
Table 11: Roles29
Table 12: Approved Services48
Table 13: Non-Approved Services50
Table 14: Storage Areas52
Table 15: SSP Input-Output Methods52
Table 16: SSP Zeroization Methods53
Table 17: SSP Table 162
Table 18: SSP Table 265
Table 19: Pre-Operational Self-Tests67
Table 20: Conditional Self-Tests70
Table 21: Pre-Operational Periodic Information70
Table 22: Conditional Periodic Information72
Table 23: Error States73
Figure 1: Block Diagram7
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance3
12Mitigation of other attacks1
Overall Level1

Validated is the term given to a module that is documented and tested against the FIPS 140-3 criteria. More information is available on the CMVP website at: https://csrc.nist.gov/projects/cryptographic-module-validation-program. About this Document (hereafter referred to as “the Module”) from ST Engineering Urban Solutions Ltd. It contains specifications of the security rules under which the Module operates, including the security rules derived from the requirements of the FIPS 140-3 standard. This document may be freely reproduced and distributed whole and intact including this The following table lists the level of validation for each area in FIPS 140-3:

1.2 Security Levels
1.3 Additional Information

The Section 7.7 Physical Security and Section 7.8 Non-Invasive Security from ISO 19790 do not apply to the module.

1 Internet Protocol Controller

This document may be freely reproduced and distributed in its entirety without modification.

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The module is intended to execute within the IPC device and provide cryptographic services. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary is as depicted in Figure 1. No components are excluded from the cryptographic boundary. The module supports an Approved mode and a non-Approved mode of operation. The module does not support a degraded mode. Tested Operational Environment’s Physical Perimeter (TOEPP): The block diagram of the Module is depicted in Figure 1 (blue outlined). The Tested Operational Environment’s Physical Perimeter (TOEPP) is the underlying host platform i.e. IPC device on which it runs. The operating environment of the module is modifiable since the platform does support modifications to it. This document may be freely reproduced and distributed in its entirety without modification.

Page 7
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): This document may be freely reproduced and distributed in its entirety without modification.

Page 8
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
IPCV9FIPS.1.0N/ARSA mod 2048 SHA2-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Windows 10 Enterprise LTSC Version 1809IPCIntel Core i5- 8500T CPU @ 2.1GhzNoN/AV9FIPS.1.0
Mode NameDescriptionTypeStatus Indicator
Approved modeThe module is initialized into the Approved mode of operation by defaultApproved"FIPS operation in progress" printed in bootlogs
non- Approved modeThe module transitions implicitly to the non- Approved mode upon usage of any Non- Approved Algorithms Not Allowed in the Approved ModeNon- ApprovedNone

Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) Tested Operational Environments - Software, Firmware, Hybrid: Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: No environments have been vendor affirmed.

2.3 Excluded Components

No components have been excluded. Modes List and Description: Table 4: Modes List and Description

  1. The module does not support manual SSP entry.
  2. The module inhibits data output during self-test execution, zeroisation, SSP generation and upon entry into the error state. This document may be freely reproduced and distributed in its entirety without modification.
Page 9
AlgorithmCAVP CertPropertiesReference
AES-CBCA5153-SP 800-38A
AES-CBC-CS1A5153-SP 800-38A
AES-CBC-CS2A5153-SP 800-38A
AES-CBC-CS3A5153-SP 800-38A
AES-CCMA5153-SP 800-38C
AES-CFB1A5153-SP 800-38A
AES-CFB128A5153-SP 800-38A
AES-CFB8A5153-SP 800-38A
AES-CMACA5153-SP 800-38B
AES-CTRA5153-SP 800-38A
AES-ECBA5153-SP 800-38A
AES-GCMA5153-SP 800-38D
AES-GMACA5153-SP 800-38D
AES-KWA5153-SP 800-38F
AES-KWPA5153-SP 800-38F
AES-OFBA5153-SP 800-38A
AES-XTS Testing Revision 2.0A5153-SP 800-38E
Counter DRBGA5153-SP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A5153-FIPS 186-5
ECDSA KeyVer (FIPS186-5)A5153-FIPS 186-5
ECDSA SigGen (FIPS186-5)A5153-FIPS 186-5
ECDSA SigVer (FIPS186-5)A5153-FIPS 186-5
  1. In the event of a self-test failure, all calls made to the module to request services from it are rejected by the module. The Module is shipped with the Approved mode pre-enabled as noted in Section
  2. No further configuration is required. Mode Change Instructions and Status: The module is in the Approved mode of operation provided the Approved algorithms and NonApproved Algorithms Allowed in the Approved Mode are used. Usage of the non-Approved Algorithms Not Allowed in the Approved Mode causes the module to transition to the nonApproved mode. Degraded Mode Description: A degraded mode of operation is not supported by the module.
2.5 Algorithms

Approved Algorithms: This document may be freely reproduced and distributed in its entirety without modification.

Page 10
AlgorithmCAVP CertPropertiesReference
Hash DRBGA5153-SP 800-90A Rev. 1
HMAC DRBGA5153-SP 800-90A Rev. 1
HMAC-SHA-1A5153-FIPS 198-1
HMAC-SHA2-224A5153-FIPS 198-1
HMAC-SHA2-256A5153-FIPS 198-1
HMAC-SHA2-384A5153-FIPS 198-1
HMAC-SHA2-512A5153-FIPS 198-1
HMAC-SHA2-512/224A5153-FIPS 198-1
HMAC-SHA2-512/256A5153-FIPS 198-1
HMAC-SHA3-224A5153-FIPS 198-1
HMAC-SHA3-256A5153-FIPS 198-1
HMAC-SHA3-384A5153-FIPS 198-1
HMAC-SHA3-512A5153-FIPS 198-1
KAS-ECC CDH-Component SP800-56Ar3 (CVL)A5153-SP 800-56A Rev. 3
KAS-ECC-SSC Sp800-56Ar3A5153-SP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A5153-SP 800-56A Rev. 3
KAS-IFC-SSCA5153-SP 800-56A Rev. 3
KDA HKDF SP800-56Cr2A5153-SP 800-56C Rev. 2
KDA OneStep SP800-56Cr2A5153-SP 800-56C Rev. 2
KDA TwoStep SP800-56Cr2A5153-SP 800-56C Rev. 2
KDF ANS 9.42 (CVL)A5153-SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A5153-SP 800-135 Rev. 1
KDF KMAC Sp800-108r1A5153-SP 800-108 Rev. 1
KDF SP800-108A5153-SP 800-108 Rev. 1
KDF SSH (CVL)A5153-SP 800-135 Rev. 1
KMAC-128A5153-SP 800-185
KMAC-256A5153-SP 800-185
KTS-IFCA5153-SP 800-56B Rev. 2
PBKDFA5153-SP 800-132
RSA KeyGen (FIPS186-5)A5153-FIPS 186-5
RSA SigGen (FIPS186-5)A5153-FIPS 186-5
RSA Signature Primitive (CVL)A5153-FIPS 186-4

This document may be freely reproduced and distributed in its entirety without modification.

Page 11
AlgorithmCAVP CertPropertiesReference
RSA SigVer (FIPS186-4)A5153-FIPS 186-4
RSA SigVer (FIPS186-5)A5153-FIPS 186-5
Safe Primes Key GenerationA5153-SP 800-56A Rev. 3
Safe Primes Key VerificationA5153-SP 800-56A Rev. 3
SHA-1A5153-FIPS 180-4
SHA2-224A5153-FIPS 180-4
SHA2-256A5153-FIPS 180-4
SHA2-384A5153-FIPS 180-4
SHA2-512A5153-FIPS 180-4
SHA2-512/224A5153-FIPS 180-4
SHA2-512/256A5153-FIPS 180-4
SHA3-224A5153-FIPS 202
SHA3-256A5153-FIPS 202
SHA3-384A5153-FIPS 202
SHA3-512A5153-FIPS 202
SHAKE-128A5153-FIPS 202
SHAKE-256A5153-FIPS 202
TLS v1.2 KDF RFC7627 (CVL)A5153-SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A5153-SP 800-135 Rev. 1
NamePropertiesImplementationReference
CKG (6.3)Key Type:SymmetricN/ANIST SP 800-133rev2, Section 6.3: Symmetric Keys Produced by Combining Multiple Keys and Other Data
CKG (4)Key Type:Symmetric and AsymmetricN/ANIST SP800-133r2 Section 4: Using the Output of a Random Bit Generator; Section 5.1: Key Pairs for Digital Signature Schemes; Section 5.2: Key Pairs for Key Establishment; Section 6.1: Direct Generation of Symmetric Keys; Section 6.2: Derivation of Symmetric keys

Table 5: Approved Algorithms Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: This document may be freely reproduced and distributed in its entirety without modification.

Page 12
NamePropertiesImplementationReference
AESCert. A5153:key unwrapping per IG D.GIPCSymmetric key unwrapping per IG D.G Additional Comment 5
FIPS 186-4 RSA SigVer X9.31Cert. A5153:signature verificationIPCIG C.K
NameUse and Function
X448SSP Agreement
X25519SSP Agreement
FIPS 186-5 ECDSA SigVer ComponentCurve(s): P-192, P-224, P-256, P-384, P-521, B-163, B-233, B-283, B- 409, B-571, K-163, K-233, K-283, K-409, K-571, Function(s): SigVer
HMAC GenerateKey length(s): < 112 bits for MAC generation
HMAC DRBG/Hash DRBGPRF(s): SHA3 (all sizes)
ED448PRF: SHAKE256, Function(s): SigGen, SigVer
ED25519PRF: SHA2-512, Function(s): SigGen, SigVer
TDESMode(s): CBC and ECB, Function(s): Encrypt, Decrypt
FIPS 186-4 DSAKey size (strength): L = 1024, N = 160 (s < 112); L = 2048, N = 224 (s = 112); L = 2048, N = 256 (s = 112); L = 3072, N = 256 (s = 128); Function(s): KeyGen, SigGen, SigVer, PQGVer and PQGGen (SHA-1, SHA2 and SHA3 all sizes); SigVer and PQGVer disapproved per IG C.M 3.e
FIPS 186-2 RSA SignatureModulus: > 1024 bits, Function(s): SigGen, SigVer (per IG C.M 3.e. for SigVer)
FIPS 186-2 RSA Generate KeyModulus: >= 2048 bits, Function(s): KeyGen
KDA HKDF SP800- 56Cr1Key length(s): < 112 bits
KDA OneStep SP800-56Cr1PRF(s): SHAKE128 and SHAKE256
KDF ANS 9.42PRF(s): SHA-1, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, KECCAK- KMAC128 and KECCAK-KMAC256
KDF ANS 9.63PRF(s): SHA-1, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, KECCAK- KMAC128 and KECCAK-KMAC256

Table 7: Non-Approved, Allowed Algorithms Non-Approved, Allowed Algorithms with No Security Claimed: The module does not support any Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed. Non-Approved, Not Allowed Algorithms: C.M 3.e This document may be freely reproduced and distributed in its entirety without modification.

Page 13
NameUse and Function
RSA PKCS1.5 (for KTS)Usage of RSA PKCS1.5 Encapsulation/decapsulation in the context of SSP Transport (KTS)
RSA Signature PrimitiveRSASP with modulus 3072, 4096 (since RSASP 2.0 is untested per CAVP Cert. #A5153)
FIPS 186-4 RSA KeyGen X9.31, FIPS 186-4 RSA SigGen X9.31RSA KeyGen, SigGen per X9.31 per IG C.K
SHA-1 for SigVerUsage of SHA-1 in the context of signature verification (per IG C.M 3.e)
NameTypeDescriptionPropertiesAlgorithms
AES Encrypt/DecryptBC-Auth BC-UnAuthEncryption and decryption using AES modesKey Length:128, 192 and 256 bits Key Length (XTS):128 and 256 bitsAES-CBC: (A5153) AES-CBC-CS1: (A5153) AES-CBC-CS2: (A5153) AES-CBC-CS3: (A5153) AES-CCM: (A5153) AES-CFB1: (A5153) AES-CFB128: (A5153) AES-CFB8: (A5153) AES-CMAC: (A5153) AES-CTR: (A5153) AES-ECB: (A5153) AES-GCM: (A5153) AES-GMAC: (A5153) AES-OFB: (A5153) AES-XTS Testing

3.e) Table 8: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

This document may be freely reproduced and distributed in its entirety without modification.

Page 14
NameTypeDescriptionPropertiesAlgorithms
Revision 2.0: (A5153)
AES Key WrappingKTS-WrapKey WrappingKey Length:128, 192 and 256 bitsAES-KW: (A5153) AES-KWP: (A5153)
SHSSHAHashingSHA-1: (A5153) SHA2-224: (A5153) SHA2-256: (A5153) SHA2-384: (A5153) SHA2-512: (A5153) SHA2-512/224: (A5153) SHA2-512/256: (A5153) SHA3-224: (A5153) SHA3-256: (A5153) SHA3-384: (A5153) SHA3-512: (A5153) SHAKE-128: (A5153) SHAKE-256: (A5153)
MACBC-Auth MACMessage Authentication CodeHMAC-SHA-1: (A5153) HMAC-SHA2- 224: (A5153) HMAC-SHA2- 256: (A5153) HMAC-SHA2- 384: (A5153) HMAC-SHA2- 512: (A5153) HMAC-SHA2- 512/224: (A5153) HMAC-SHA2- 512/256: (A5153)

This document may be freely reproduced and distributed in its entirety without modification.

Page 15
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA3- 224: (A5153) HMAC-SHA3- 256: (A5153) HMAC-SHA3- 384: (A5153) HMAC-SHA3- 512: (A5153) AES-CMAC: (A5153) AES-GMAC: (A5153) KMAC-128: (A5153) KMAC-256: (A5153)
RSA SigGen/SigVerDigSig-SigGen DigSig-SigVerRSA SigGen and SigVerMode: PKCS 1.5 (SigGen):Modulus: 2048, 3072, 4096; Hash: SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256 Mode: PKCSPSS (SigGen):Modulus: 2048, 3072, 4096; Hash: SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256 Mode: ANSI X9.31 (SigVer only):Modulus: 1024, 2048, 3072, 4096; Hash: SHA2-256, SHA2- 384, SHA2-512 Mode: PKCS 1.5 (SigVer):Modulus: 1024, 2048, 3072, 4096; Hash: SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256 Mode: PKCSPSSRSA SigGen (FIPS186-5): (A5153) RSA SigVer (FIPS186-5): (A5153) RSA SigVer (FIPS186-4): (A5153)

This document may be freely reproduced and distributed in its entirety without modification.

Page 16
NameTypeDescriptionPropertiesAlgorithms
(SigVer):Modulus: 1024, 2048, 3072, 4096; Hash: SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256
ECDSA SigGen/SigVerDigSig-SigGen DigSig-SigVerECDSA SigGen and SigVerSigGen:P-224, P- 256, P-384, P- 521, B-233, B- 283, B-409, B- 571, K-233, K- 283, K-409, K- 571; SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512 SigVer :P-192, P- 224, P-256, P- 384, P-521, B- 163, B-233, B- 283, B-409, B- 571, K-163, K- 233, K-283, K- 409, K-571; SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512ECDSA SigGen (FIPS186-5): (A5153) ECDSA SigVer (FIPS186-5): (A5153)
RSASPDigSig-SigGenRSA signature primitiveRSA Signature Primitive: (A5153)
Generate KeyAsymKeyPair- KeyGen AsymKeyPair- KeyVer CKGKeypair generationECDSA KeyGen (FIPS186-5): (A5153) ECDSA KeyVer (FIPS186-5): (A5153) RSA KeyGen

This document may be freely reproduced and distributed in its entirety without modification.

Page 17
NameTypeDescriptionPropertiesAlgorithms
(FIPS186-5): (A5153) Safe Primes Key Generation: (A5153) Safe Primes Key Verification: (A5153) CKG (4): () Key Type: Symmetric and Asymmetric
Random Bit GenerationDRBGRandom Number Generation - Hash_DRBG, CTR_DRBG and HMAC_DRBGHash DRBG: (A5153) HMAC DRBG: (A5153) Counter DRBG: (A5153)
DeriveCKG KAS-135KDF KAS-56CKDF KBKDF PBKDFDerive Keying MaterialKDA HKDF SP800-56Cr2: (A5153) KDA OneStep SP800-56Cr2: (A5153) KDA TwoStep SP800-56Cr2: (A5153) KDF ANS 9.42: (A5153) KDF ANS 9.63: (A5153) KDF KMAC Sp800-108r1: (A5153) KDF SP800- 108: (A5153) KDF SSH: (A5153) PBKDF: (A5153) TLS v1.2 KDF RFC7627: (A5153) TLS v1.3 KDF: (A5153) CKG (4): ()

This document may be freely reproduced and distributed in its entirety without modification.

Page 18
NameTypeDescriptionPropertiesAlgorithms
Key Type: Symmetric and Asymmetric
KAS-1KAS-SSCScheme: EphemeralUnified, KAS Role: Initiator, ResponderIG : IG D.F Scenario 2, path (1) Key confirmation:no Key derivation:no Caveat:Key establishment methodology provides between 112 and 256 bits of security strengthKAS-ECC-SSC Sp800-56Ar3: (A5153)
KAS-2KAS-SSCScheme: dhEphem. KAS Role: Initiator, ResponderIG : IG D.F Scenario 2, path (1) Key confirmation:no Key derivation:no Caveat: Key establishment methodology provides between 112 and 200 bits of security strengthKAS-FFC-SSC Sp800-56Ar3: (A5153)
KAS-3KAS-SSCScheme: KAS1, KAS2. KAS Role: Initiator, ResponderIG:IG D.F Scenario 1, path (1) Key confirmation :no Key derivation:no Caveat :Key establishment methodology provides between 112 and 200 bits of security strengthKAS-IFC-SSC: (A5153)
KTS-1KTS-WrapKey Transport in compliance with [SP800- 38F] when approved using an AuthenticatedStandard :SP 800- 38F IG D.G:approved method from IG D.G Caveat :KeyAES-CCM: (A5153) AES-GCM: (A5153) AES-KW: (A5153)

This document may be freely reproduced and distributed in its entirety without modification.

Page 19
NameTypeDescriptionPropertiesAlgorithms
AES mode (AES CCM; AES GCM; AES KW, KWP)establishment methodology provides between 128 and 256 bits of security strengthAES-KWP: (A5153)
KTS-2KTS-WrapKey Transport in compliance with [SP800- 38F] when approved AES (any mode) and approved HMAC are used in combinationStandard:SP 800- 38F IG D.G:approved method from IG D.G Caveat :Key establishment methodology provides between 128 and 256 bits of security strengthAES-CBC: (A5153) AES-CBC-CS1: (A5153) AES-CBC-CS2: (A5153) AES-CBC-CS3: (A5153) AES-CCM: (A5153) AES-CFB1: (A5153) AES-CFB128: (A5153) AES-CFB8: (A5153) AES-CMAC: (A5153) AES-CTR: (A5153) AES-ECB: (A5153) AES-GCM: (A5153) AES-GMAC: (A5153) AES-KW: (A5153) AES-KWP: (A5153) AES-OFB: (A5153) AES-XTS Testing Revision 2.0: (A5153) HMAC-SHA-1: (A5153) HMAC-SHA2- 224: (A5153) HMAC-SHA2- 256: (A5153)

This document may be freely reproduced and distributed in its entirety without modification.

Page 20
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA2- 384: (A5153) HMAC-SHA2- 512: (A5153) HMAC-SHA2- 512/224: (A5153) HMAC-SHA2- 512/256: (A5153) HMAC-SHA3- 224: (A5153) HMAC-SHA3- 256: (A5153) HMAC-SHA3- 384: (A5153) HMAC-SHA3- 512: (A5153)
KTS-3KTS-WrapKey Transport in compliance with [SP800- 38F] when approved AES (any mode) and approved CMAC/GMAC are used in combinationStandard:SP 800- 38F IG D.G:approved method from IG D.G Caveat:Key establishment methodology provides between 128 and 256 bits of security strengthAES-CBC: (A5153) AES-CBC-CS1: (A5153) AES-CBC-CS2: (A5153) AES-CBC-CS3: (A5153) AES-CCM: (A5153) AES-CFB1: (A5153) AES-CFB128: (A5153) AES-CFB8: (A5153) AES-CMAC: (A5153) AES-CTR: (A5153) AES-ECB: (A5153) AES-GCM: (A5153) AES-GMAC: (A5153) AES-KW: (A5153) AES-KWP: (A5153)

This document may be freely reproduced and distributed in its entirety without modification.

Page 21
NameTypeDescriptionPropertiesAlgorithms
AES-OFB: (A5153) AES-XTS Testing Revision 2.0: (A5153)
KTS-4KTS-EncapKey Transport; Scheme: KTS- OAEP-basic (no key confirmation): RSA-OAEP, RSADP, RSAEP, Key Encapsulation, Key Unencapsulation Key Generation Methods: rsakpg1-basic, rsakpg1-crt, rsakpg1-prime- factor, rsakpg2- basic, rsakpg2-crt, rsakpg2- prime- factorStandard:SP 800- 56Brev2 IG D.G:approved method per IG D.G Key confirmation:no Caveat :Key establishment methodology provides between 112 and 176 bits of security strengthKTS-IFC: (A5153)
KAS ECC ComponentKAS-SSCKAS-ECC-SSC primitive (ECC CDH)KAS-ECC CDH- Component SP800-56Ar3: (A5153)
Self-testsBC-Auth BC-UnAuth DigSig-SigGen DigSig-SigVer DRBG KAS-135KDF KAS-56CKDF KAS-SSC KBKDF MAC PBKDF SHA XOFAll self-tests executed by the module at bootAES-ECB: (A5153) AES-GCM: (A5153) Hash DRBG: (A5153) Counter DRBG: (A5153) HMAC DRBG: (A5153) ECDSA SigGen (FIPS186-5): (A5153) ECDSA SigVer (FIPS186-5): (A5153) RSA SigGen

This document may be freely reproduced and distributed in its entirety without modification.

Page 22
NameTypeDescriptionPropertiesAlgorithms
(FIPS186-5): (A5153) RSA SigVer (FIPS186-5): (A5153) HMAC-SHA2- 256: (A5153) SHA-1: (A5153) SHA3-256: (A5153) KDF ANS 9.42: (A5153) KDF ANS 9.63: (A5153) KAS-ECC-SSC Sp800-56Ar3: (A5153) KAS-FFC-SSC Sp800-56Ar3: (A5153) KAS-IFC-SSC: (A5153) KDA OneStep SP800-56Cr2: (A5153) KDA TwoStep SP800-56Cr2: (A5153) KDA HKDF SP800-56Cr2: (A5153) KDF SSH: (A5153) PBKDF: (A5153) KDF SP800- 108: (A5153) SHA2-512: (A5153) TLS v1.2 KDF RFC7627: (A5153) TLS v1.3 KDF: (A5153)
TLS all algorithmsAsymKeyPair- KeyGen AsymKeyPair-All algorithms supported by the module for theAES-GCM: (A5153) SHA2-384:

This document may be freely reproduced and distributed in its entirety without modification.

Page 23
NameTypeDescriptionPropertiesAlgorithms
KeyVer BC-Auth CKG DigSig-SigGen DigSig-SigVer DRBG KAS-135KDF KTS-Wrap SHATLS 1.2 protocol/service(A5153) RSA SigGen (FIPS186-5): (A5153) RSA SigVer (FIPS186-5): (A5153) ECDSA KeyGen (FIPS186-5): (A5153) Hash DRBG: (A5153) TLS v1.2 KDF RFC7627: (A5153) ECDSA SigGen (FIPS186-5): (A5153) ECDSA SigVer (FIPS186-5): (A5153) CKG (4): () Key Type: Symmetric and Asymmetric
Software Integrity TestDigSig-SigVerRSA mod 2048 bits SHA2-256 signature VerificationRSA SigVer (FIPS186-5): (A5153)
KTS-5KTS-WrapKey wrapping in the context of the TLS 1.2 IETF protocol using an AES GCM 256-bit keyStandard:SP 800- 38F IG D.G: approved method from IG D.G Caveat:Key establishment methodology provides 256 bits of security strengthAES-GCM: (A5153)
KAS-4KAS-FullKey agreement in the context of the TLS 1.2 IETF protocol; KAS- ECC-SSC P-384IG : IG D.F Scenario 2 path (2) Key confirmation:no Key derivation:IGKAS-ECC-SSC Sp800-56Ar3: (A5153) TLS v1.2 KDF RFC7627: (A5153)

This document may be freely reproduced and distributed in its entirety without modification.

Page 24
NameTypeDescriptionPropertiesAlgorithms
used with KDF TLS 1.22.4.B SP 800- 135rev1 CVL Caveat :Key establishment methodology provides 192 bits of security strength
Symmetric Key GenerationCKGGeneration of symmetric keysCKG (4): () CKG (6.3): ()

Table 9: Security Function Implementations

2.7 Algorithm Specific Information

a. AES-GCM Usage The AES GCM IV computation must comply with IG C.H and NIST SP 800-38D Scenario 1(a), tested per option (ii) under C.H TLS 1.2 protocol IV generation per RFC7627, Scenario 1(d) SSHv2 per RFC4252, RFC4253 and RFC5647 and Scenario 5 TLS 1.3 per RFC8446. The Module does not implement the TLS 1.3 and SSH protocols itself, however, it provides the cryptographic functions required for implementing these protocols. The module does implement the TLS 1.2 protocol. AES GCM encryption is used in the context of the SSH and TLS protocol versions 1.2 and 1.3 and the IV computed shall only be used within the protocols. The module provides the primitives to support the AES GCM cipher suites per NIST SP800-52r1 Section 3.3.1. The module’s implementation of AES-GCM is used together with an application that runs outside the module’s cryptographic boundary in case of TLS 1.3 and SSH protocols. The application negotiates the protocol session’s keys and the 32-bit nonce value of the IV. When the IV exhausts the maximum number of possible values for a given session key (2^64 - 1), this results in failure in encryption and a handshake to establish a new encryption key will be required. It is the responsibility of the user of the module, i.e., the first party, client or server, to encounter this condition, to trigger this handshake in accordance with the TLS/SSH protocol. The Module also supports internal IV generation using the module’s approved DRBG. The IV is at least 96 bits in length per NIST SP800-38D Section 8.2.2. Per IG C.H Scenario 2 and NIST SP800-38D, the approved DRBG generates outputs such that the (key, IV) pair collision probability is less than 2^-32. For all cases of IV generation, in the event that the module power is lost and restored the user must ensure that the AES GCM encryption/decryption keys are redistributed/re-established in accordance with IG C.H Scenario 3. The module does not support persistent storage of SSPs. This document may be freely reproduced and distributed in its entirety without modification.

Page 25

The Module also supports importing of GCM IVs when an IV is not generated within the Module. In the approved mode, an IV must not be imported for encryption from outside the cryptographic boundary of the Module as this will result in a non-conformance. This is in accordance with IG 2.4.A: “If the module operator (e.g., calling application) can do things outside of the module’s control/visibility that can take an otherwise approved algorithm and use it in a non-approved way (e.g., use PBKDF and/or AES XTS outside of storage applications), the corresponding module service may still be considered approved (and if so, shall have an approved indicator per AS02.24) and the Security Policy shall clarify how to use the service in an approved manner (per ISO 19790 B.2.2 on Overall security design and the rules of operation).” b. AES-XTS Usage Usage In accordance with NIST SP800-38E, the XTS-AES algorithm shall only be used for confidentiality on storage devices. The Module complies with IG C.I by explicitly checking that Key_1 ≠ Key_2 before using the keys in the XTS-AES algorithm to process data with them. The module implements CKG per NIST SP 800-133r2 Section 6.3. c. Legacy Usage The module supports the following implementations for legacy use/support per NIST SP 800-131Ar2: • FIPS 186-4/5 RSA (modulus 1024 bits), ECDSA (B-163, K-163 and P-192, curves) digital signature verification providing less than 112 bits of security strength. Legacy usage only. These legacy algorithms can only be used on data that was generated prior to the Legacy Date specified in IG C.M. d. Component Validation List (CVL) In accordance with IG 2.4.B, all tested components have been marked with the “CVL” notation in Table 5 and all vendor affirmed algorithms have been listed in Table 6. Also, per IG 2.4.B, the RSASP i.e. RSA SigGen (CVL) shall only be used within the context of a FIPS 186-5 signature generation. e. PBKDF Usage The module is compliant with IG D.N and NIST SP 800-132 Section 5.4 Option 1a. The iteration count values used range from 1 to 10000 per NIST SP 800-132 Section 5.2 whereby the iteration count shall be selected as large as possible, as long as the time required to generate the key using the entered password is acceptable for the users. The derived key must possess a minimum security strength of 112 bits. The module implements CKG per NIST SP 800-133r2 Section 6.2.2. In accordance with NIST SP 800-132 requirements, usage of the derived keys shall be restricted to storage applications alone. The module supports a minimum 1-character long password. The ASCII system comprises of 94 printable characters (letters, digits, punctuation, and symbols). For a 1character password/passphrase chosen from 94 printable ASCII characters, the total combinations are: 94^1. Thus, the probability of guessing the correct password/passphrase on a random attempt is: 1/94^1 ~ 0.01063. This document may be freely reproduced and distributed in its entirety without modification.

Page 26

The module being a software module does not restrict the usage of a password/string used as the password and input to the PBKDF. The onus is on the calling application to provide a password of an appropriate length based on the intended security strength (and size) of the key to be derived. In accordance with NIST SP 800-132, passwords shorter than 10 characters are usually considered to be weak. There are many other properties that may render a password weak. For example, it is not advisable to use sequences of numbers or sequences of letters as passwords. Easily accessed personal information, such as the user’s name, phone number, and date of birth, should not be used directly as a password. Passphrases frequently consist solely of letters, but they make up for their lack of entropy by being much longer than passwords, typically 20 to 30 characters. Passphrases shorter than 20 characters are usually considered weak. f. FIPS 202 Usage Per IG C.C Resolution 2.a., each SHA-3 and SHAKE function has been tested and validated the module’s operational environment. g. RSA Usage

2.8 RBG and Entropy

The Module complies with IG 9.3.A Scenario 2. b. and relies on the use of a NIST SP800-90B compliant entropy source outside the cryptographic boundary. The onus is on the calling This document may be freely reproduced and distributed in its entirety without modification.

Page 27

application to ensure the use of an NIST SP800-90B compliant entropy source and of sufficient entropy for the required security strength. The minimum number of bits of entropy, depending on the target security strength of generated SSPs is 128, 192 or 256 bits. If the Counter DRBG implementation without the derivation function enabled is used, ensure full entropy from the entropy source is provided. The following caveat applies to the module: No assurance of the minimum strength of generated SSPs (e.g., keys).

2.9 Key Generation

The module contains NIST SP 800-90Ar1 DRBGs and supports the NIST SP 800-133r2 (CKG) sections 4, 5.1, 5.2, 6.1, 6.2 and 6.3.

2.10 Key Establishment

The module supports key agreement and key transport in the context of the TLS protocol. Apart from this, it also provides cryptographic primitives in support of key agreement and key transport where the onus is on the calling application to ensure that the primitives are used in the correct sequence. The module does not establish SSPs using an approved key transport scheme (KTS). However, it does offer approved authenticated algorithms that can be used by an external operator/application as part of an approved KTS (KTS-1, KTS-2, KTS-3 and KTS-4). In addition to the TLS case, the following applies to the module for SSP agreement: The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS (KAS-1, KAS-2 and KAS-3). Per IG D.F: The module supports Key Agreement Schemes per NIST SP800-56Ar3 and IG D.F Scenario 2 (path 1) and NIST SP800-56Br2 and IG D.F Scenario 1 (path 1). The KAS-1, KAS-2, KAS-3 in the SFI Table 10 have been documented accordingly. The Approved Algorithm list includes the tested components (KAS-ECC-SSC, KAS-FFC-SSC and KAS-IFC-SSC) as individual entries. The Module obtains the IG D.F required key agreement assurances: NIST SP800-56Ar3 in accordance with Section 5.6.2. NIST SP800-56Br2 in accordance with Section 6.4. The module also supports key agreement in the context of the IETF TLS 1.2 protocol in accordance with IG D.F Scenario 2 (path 2) and the KAS-4 entry corresponds to the same. Per IG D.G: The module supports the Key Transport per NIST SP 800-56Br2 (RSA-OAEP) denoted by KTS-

4 in the SFI Table 10. This notation is in accordance with the IG D.G Additional Comment 4:

“The FIPS 140-3 annotation details for the approved or allowed key transport schemes (KTS) can be found on SP 800-140B: CMVP Security Policy Requirements (see MIS Guidance “KTS”).”. This document may be freely reproduced and distributed in its entirety without modification.

Page 28
Physical PortLogical Interface(s)Data That Passes
N/AControl InputAPI input
N/AData InputAPI parameters passed by calling applications for use in services
N/AStatus OutputAPI return code/status
N/AData OutputAPI parameters returned to calling applications as a result of service execution

The module also supports the following untested approved moduli for KTS-4: 6144 < nlen <=16384, where nlen denotes the modulus. The RSA modulus sizes and key generation method have been documented in the table as well. The module can also optionally be used in the context of IEFT protocols and provide key transport using any approved AES mode(s) and an approved MAC. The corresponding entries KTS-1, KTS-2 and KTS-3 in the SFI Table 10 have been documented accordingly. All KTS entries have been documented in accordance with Additional Comment 4 in the IG. Finally, KTS-5 corresponds to the key transport (wrapping) supported by the module in the context of the IETF TLS 1.2 protocol supported by it. Per IG D.A and IG D.B: The strengths of the established key have been documented in accordance with IG D.A Additional Comment 4. and per the Resolution in IG D.B.

2.11 Industry Protocols

The module supports cryptographic primitives used in the context of SSH, TLS 1.2 and TLS 1.3. It also supports the TLS 1.2 protocol itself. The module does not support the SSH and TLS 1.3 protocols and thus the following in accordance with Resolution #3 applies to the module: No parts of the SSH and TLS 1.3 protocols, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 10: Ports and Interfaces The module does not support control output and thus the Control Output interface is inapplicable.

4 Roles, Services, and Authentication

This document may be freely reproduced and distributed in its entirety without modification.

Page 29
NameTypeOperator TypeAuthentication Methods
Crypto Officer (CO)RoleCrypto OfficerNone
NameDescriptionIndicat orInputsOutputsSecurity Function sSSP Acces s
Module initializationModule boot and initialization process1Ctx passed into the functionReturn code 1 for success; 0 for failureRandom Bit Generati on Software Integrity TestCrypto Officer (CO) - Entrop y Input: G,W,E ,Z - State: G - Softw are Integri ty Key - RSA: E
Show Status/Show VersionShow status; show version (version for fips.dll)1Ctx passed into the function fips_get_ paramsStatus and versioning informationNoneCrypto Officer (CO)

The Module does not support authentication.

4.2 Roles

Table 11: Roles The module supports the Crypto Officer (CO) role alone, assumed implicitly by the calling application. The module does not support a maintenance role, a bypass role or any unauthorized operators.

4.3 Approved Services

s s G,W,E ,Z G E This document may be freely reproduced and distributed in its entirety without modification.

Page 30
NameDescriptionIndicat orInputsOutputsSecurity Function sSSP Acces s
Perform Self- TestsExecution of all self-tests1RebootReturn code 1 for success; 0 for failureSelf-tests Software Integrity TestCrypto Officer (CO)
Key Transport (Perform approved security functions)Key encapsulation and unencapsulati on[KTS- IFC: RSA, 4, (2048, 3072, 4096, 6144, 8192)]Encapsul ation: SSP Transport Private Key; Decapsul atation: SSP Transport Public KeyKey Transport Shared SecretKTS-4Crypto Officer (CO) - SSP Trans port Privat e Key: E - SSP Trans port Public key: E - Key Trans port Share d Secret : R
Encrypt/Decr ypt and Key Wrapping (Perform approved security functions)Encrypt or decrypt data and key wrap[AES- ECB: AES- 128- ECB, AES- 192- ECB, AES- 256- ECB]; [AES- CBC: AES- 128- CBC, AES- 192- CBC, AES- 256-Symmetri c Key and MAC Key (for wrapping)Plaintext/ciphert ext/wrapped keyAES Encrypt/ Decrypt AES Key Wrapping KTS-1 KTS-2 KTS-3 Symmetri c Key Generati onCrypto Officer (CO) - Symm etric Key: E - MAC Key: E

s s d :R This document may be freely reproduced and distributed in its entirety without modification.

Page 31

Name

Description

Indicat or CBC]; [AES- CBC- CS: AES- 128- CBC- CTS, AES- 192- CBC- CTS, AES- 256- CBC- CTS]; [AES- OFB: AES- 128- OFB, AES- 192- OFB, AES- 256- OFB]; [AES- CFB1: AES- 128- CFB1, AES- 192- CFB1, AES- 256- CFB1]; [AES- CFB8: AES- 128- CFB8, AES- 192- CFB8,

Inputs

Outputs

Security Function s

SSP Acces s

s s This document may be freely reproduced and distributed in its entirety without modification.

Page 32

Name

Description

Indicat or AES- 256- CFB8]; [AES- CFB12 8: AES- 128- CFB, AES- 192- CFB, AES- 256- CFB]; [AES- CTR: AES- 128- CTR, AES- 192- CTR, AES- 256- CTR]; [AES- CCM: AES- 128- CCM, AES- 192- CCM, AES- 256- CCM]; [AES- GCM: AES- 128- GCM, AES- 192- GCM, AES- 256-

Inputs

Outputs

Security Function s

SSP Acces s

s s This document may be freely reproduced and distributed in its entirety without modification.

Page 33
NameDescriptionIndicat or GCM]; [AES- XTS: AES- 128- XTS, AES- 256- XTS]; [AES- KW, KWP: AES- 128- WRAP, AES- 256- WRAP]InputsOutputsSecurity Function sSSP Acces s
SSP Derivation (Perform approved security functions)Derivation of keying material (DKM)PBKDF : PBKDF 2, (SHA- 1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/22 4, SHA2- 512/25 6, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512)];KAS Shared SecretDKMDeriveCrypto Officer (CO) - KAS Share d Secret : W,E - DKM: G,R - Key Trans port Share d Secret : W,E

s s 6, This document may be freely reproduced and distributed in its entirety without modification.

Page 34

Name

Description

Indicat or [TLS1- PRF, (SHA2- 256, SHA2- 384, SHA2- 512)]; [TLS13 -KDF, (SHA2- 256, SHA2- 384)]; [X963- KDF, (SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512)]; [X942K DF- ASNI, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/22 4, SHA2- 512/25 6, SHA3- 224, SHA3- 256,

Inputs

Outputs

Security Function s

SSP Acces s

s s 4, 6, This document may be freely reproduced and distributed in its entirety without modification.

Page 35

Name

Description

Indicat or SHA3- 384, SHA3- 512)]; [NIST SP 800- 108r1 KDF KMAC: KBKDF , (KMAC -128, KMAC- 256)]; [NIST SP 800- 108r1 KDF: KBKDF , MAC: CMAC, Cipher: AES- 128- CBC, AES- 192- CBC, AES- 256- CBC, MAC: HMAC- SHA1, HMAC- SHA2- 224, HMAC- SHA2- 256, HMAC- SHA2- 384,

Inputs

Outputs

Security Function s

SSP Acces s

s s , This document may be freely reproduced and distributed in its entirety without modification.

Page 36

Name

Description

Indicat or HMAC- SHA2- 256, HMAC- SHA2- 384, HMAC- SHA2- 512, HMAC- SHA2- 512/22 4, HMAC- SHA2- 512/25 6, HMAC- SHA3- 224, HMAC- SHA3- 256, HMAC- SHA3- 384, HMAC- SHA3- 512]; [KDF SSH: SSHKD F, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512)]; [OneSt ep KDF: SSKDF

Inputs

Outputs

Security Function s

SSP Acces s

s s 4, 6, F, This document may be freely reproduced and distributed in its entirety without modification.

Page 37

Name

Description

Indicat or , (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/22 4, SHA2- 512/25 6, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512, HMAC- SHA1, HMAC- SHA2- 224, HMAC- SHA2- 256, HMAC- SHA2- 384, HMAC- SHA2- 512, HMAC- SHA2- 512/22 4, HMAC- SHA2- 512/25 6,

Inputs

Outputs

Security Function s

SSP Acces s

s s , 4, 6, 4, 6, This document may be freely reproduced and distributed in its entirety without modification.

Page 38

Name

Description

Indicat or SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512, KMAC- 128, KMAC- 256)]; [TwoSt ep KDF: HKDF, MAC: HMAC, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/22 4, SHA2- 512/25 6, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512]; [HKDF: HKDF, MAC: HMAC, (SHA1,

Inputs

Outputs

Security Function s

SSP Acces s

s s 4, 6, This document may be freely reproduced and distributed in its entirety without modification.

Page 39
NameDescriptionIndicat or SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/22 4, SHA2- 512/25 6, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512]InputsOutputsSecurity Function sSSP Acces s
Key Agreement (Perform approved security functions)Shared secret computation[KAS- FFC- SSC: DHX]; [KAS- ECC- SSC: EC]SSP Agreeme nt Private FFC/ECC Key, SSP Agreeme nt Public FFC/ECC KeyKAS Shared SecretKAS-1 KAS-2 KAS-3 KAS ECC Compon entCrypto Officer (CO) - SSP Agree ment Privat e FFC/E CC Key: E - SSP Agree ment Public FFC/E CC Key: E - KAS Share d Secret : G

s s 4, 6, d :G This document may be freely reproduced and distributed in its entirety without modification.

Page 40
NameDescriptionIndicat orInputsOutputsSecurity Function sSSP Acces s
Key Pair Generation (Perform approved security functions)ECC/DH/RSA/ SafePrime key pair generation[SafePr imes: DHX]; [RSA KeyGe n: RSA, (2048, 3072, 4096)]; [ECDS A KeyGe n: EC]ECDSA: curve id. RSA: modulusKey pair returned to callerGenerate KeyCrypto Officer (CO) - Privat e Key: G - Public Key: G
MAC Generation/V erification (Perform approved security functions)Keyed hash generation/veri fication[HMAC : HMAC- SHA1, HMAC- SHA2- 224, HMAC- SHA2- 256, HMAC- SHA2- 384, HMAC- SHA2- 512, HMAC- SHA2- 512/22 4, HMAC- SHA2- 512/25 6, HMAC- SHA3- 224, HMAC- SHA3- 256, HMAC- SHA3- 384,MAC KeyMAC valueMAC Symmetri c Key Generati onCrypto Officer (CO) - MAC Key: E

s s A G 4, 6, This document may be freely reproduced and distributed in its entirety without modification.

Page 41
NameDescriptionIndicat or HMAC- SHA3- 512]; [CMAC ]; [KMAC: KMAC- 128, KMAC- 256]; [GMAC : AES- 128- GCM, AES- 192- GCM, AES- 256- GCM]InputsOutputsSecurity Function sSSP Acces s
Hash generation (Perform approved security functions)Hashing[SHA- 1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/22 4, SHA2- 512/25 6, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512, SHAKE -128,Message to be hashedHash valueSHSCrypto Officer (CO)

s s ]; 4, 6, This document may be freely reproduced and distributed in its entirety without modification.

Page 42
NameDescriptionIndicat or SHAKE -256]InputsOutputsSecurity Function sSSP Acces s
Random Bit Generation (Perform approved security functions)Random bit generation using the DRBG[Hash DRBG: HASH- DRBG, (SHA1, SHA2- 256, SHA2- 512)]; [HMAC - DRBG, (SHA1, SHA2- 256, SHA2- 512)]; [CTR- DRBG, (AES- 128- CTR, AES- 192- CTR, AES- 256- CTR)]DRBG State; DRBG Entropy InputRandom bitsRandom Bit Generati onCrypto Officer (CO) - Entrop y Input: E - Seed: E - State: E
Digital Signature Generation/V erification (Perform approved security functions)RSA/ECDSA signature generation and verification[RSA SigGen : RSA, (2048, 3072, 4096), (SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/22Sign: SigGen Key; Verify: SigVer KeySignature value for SigGen, 1 or 0 respectively for success or failure in case of SigVerRSA SigGen/S igVer ECDSA SigGen/S igVer RSASPCrypto Officer (CO) - SigGe n Key: E - SigVe r Key: E

s s - E This document may be freely reproduced and distributed in its entirety without modification.

Page 43

Name

Description

Indicat or 4, SHA2- 512/25 6)]; [RSA SigVer: RSA, (1024, 2048, 3072, 4096), (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/22 4, SHA2- 512/25 6)]; [RSA Signatu re Primitiv e: RSA, 2048, hash algorith m: (null)]; [ECDS A SigGen : EC, (SHA2- 224, SHA2- 256, SHA2- 384,

Inputs

Outputs

Security Function s

SSP Acces s

s s 4, 6)]; 4, 6)]; m: A This document may be freely reproduced and distributed in its entirety without modification.

Page 44
NameDescriptionIndicat or SHA2- 512, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512)]; [ECDS A SigVer: EC, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/22 4, SHA2- 512/25 6)]; [ECDS A SigGen Compo nent]: EC, hash: (null)]InputsOutputsSecurity Function sSSP Acces s
Perform zeroisation* Zeroisation in the context of function calls * Restarting the host platform * TLS 1.2 Session Termination *1Location of SSPReturn code 1NoneCrypto Officer (CO) - SigGe n Key: Z - SigVe

s s A 4, 6)]; A This document may be freely reproduced and distributed in its entirety without modification.

Page 45
NameDescriptionIndicat orInputsOutputsSecurity Function sSSP Acces s
Module uninstantiationr Key: Z - Privat e Key: Z - Public Key: Z - SSP Agree ment Privat e FFC/E CC Key: Z - SSP Agree ment Public FFC/E CC Key: Z - KAS Share d Secret : Z - DKM: Z - MAC Key: Z - SSP Trans port Privat e Key: Z - SSP Trans port Public key: Z - Key

s s Z e d :Z Z Z This document may be freely reproduced and distributed in its entirety without modification.

Page 46
NameDescriptionIndicat orInputsOutputsSecurity Function sSSP Acces s
Trans port Share d Secret : Z - Entrop y Input: Z - Seed: Z - State: Z - Symm etric Key: Z - TLS Maste r Secret : Z - TLS Sessi on Key: Z - KAS Public Key: Z - KAS Privat e Key: Z - ECDS A Public Key: Z - ECDS A Privat

s s d :Z y Z Z Z r :Z Z A A This document may be freely reproduced and distributed in its entirety without modification.

Page 47
NameDescriptionIndicat orInputsOutputsSecurity Function sSSP Acces s
e Key: Z - RSA Public Key: Z - RSA Privat e Key: Z - TLS Pre- Maste r Secret : Z - KAS Peer Public Key: Z - Softw are Integri ty Key - RSA: Z
HTTPS communicati ons with backend (Perform approved security functions)TLS v1.2 protocol usedSucces sful comple tion of the service, i.e. succes sful TLS 1.2 session negotia tionTLS Peer Public Key (KAS Peer Public Key)Packets transferred over TLS 1.2TLS all algorithm s KTS-5 KAS-4Crypto Officer (CO) - TLS Maste r Secret : G,E,Z - TLS Pre- Maste r Secret : G,E,Z - TLS Sessi on Key:

s s Z Z r :Z Z : G,E,Z This document may be freely reproduced and distributed in its entirety without modification.

Page 48
NameDescriptionIndicat orInputsOutputsSecurity Function sSSP Acces s
G,E,Z - KAS Privat e Key: G,E,Z - KAS Public Key: G,R,E ,Z - ECDS A Public Key: G,R,E ,Z - ECDS A Privat e Key: G,E,Z - RSA Public Key: G,R,E ,Z - RSA Privat e Key: G,E,Z - KAS Peer Public Key: W,E,Z

s s G,E,Z G,E,Z G,R,E ,Z A G,R,E ,Z A G,E,Z G,R,E ,Z G,E,Z W,E,Z Table 12: Approved Services The following indicate the type of access: G = Generate: The service generates or derives the CSP/Public Key. W = Write/Input: The service inputs the CSP/Public Key. E = Execute: The Module executes using the CSP/Public Key. This document may be freely reproduced and distributed in its entirety without modification.

Page 49
NameDescriptionAlgorithmsRole
SSP AgreementKAS-SSCX448 X25519Crypto Officer (CO)
FIPS 186-5 ECDSA SigVer ComponentSignature verificationFIPS 186-5 ECDSA SigVer ComponentCrypto Officer (CO)
HMAC GenerateMAC generation with key length < 112 bitsHMAC GenerateCrypto Officer (CO)
HMAC DRBG/Hash DRBGPRF(s): SHA3 (all sizes)HMAC DRBG/Hash DRBGCrypto Officer (CO)
TDES Encrypt/DecryptEncryption and decryptionTDESCrypto Officer (CO)
Digital Signature Generation/VerificationSignature generation and verificationED448 ED25519 FIPS 186-4 DSA FIPS 186-2 RSA SignatureCrypto Officer (CO)
FIPS 186-2 RSA Key GenerationRSA public/private key pair generation per FIPS 186-2FIPS 186-2 RSA Generate KeyCrypto Officer (CO)
DeriveKey derivationKDA HKDF SP800- 56Cr1 KDA OneStep SP800-56Cr1 KDF ANS 9.42 KDF ANS 9.63Crypto Officer (CO)

R = Read/Output: The service outputs the CSP/Public Key. CSP are always protected with the approved KTS. Z = Zeroise: The Module zeroizes the CSP/Public Key after usage. A zeroised CSP is not retrievable or reusable. The module provides service indicators in accordance with the FIPS 140-3 IG 2.4.C example 3. All CSPs are zeroised when they are no longer needed: - Temporary CSPs are zeroised within the relevant function calls per service. - The DRBG state is zeroised on Module instantiation - The temporary underlying hash value generated as part of the RSA Signature Verification in the context of the integrity test performed, is zeroised prior to exiting the integrity test function. - TLS 1.2 SSPs are zeroised upon TLS 1.2 session termination.

4.4 Non-Approved Services

This document may be freely reproduced and distributed in its entirety without modification.

Page 50
NameDescriptionAlgorithmsRole
SSP TransportSSP transport using RSA PKCS1.5 paddingRSA PKCS1.5 (for KTS)Crypto Officer (CO)
RSA Signature PrimitiveSignature primitive function/signature generation with modulus 3072 and 4096RSA Signature PrimitiveCrypto Officer (CO)
FIPS 186-4 RSA X9.31 Key Generation and Signature GenerationKey generation and signature generation per ANS X9.31FIPS 186-4 RSA KeyGen X9.31, FIPS 186-4 RSA SigGen X9.31Crypto Officer (CO)
SHA-1 for Signature VerificationFIPS 186-4/5 RSA/ECDSA Signature Verification using SHA-1 (in accordance with IG C.M 3.e)SHA-1 for SigVerCrypto Officer (CO)

Table 13: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not support loading software from an external source.

4.6 Bypass Actions and Status

The module does not support bypass.

4.7 Cryptographic Output Actions and Status

The module supports self-initiated cryptographic output over the TLS 1.2 IETF protocol. Two internal actions are performed, i.e. software flags are checked within the module prior to allowing output over TLS 1.2. The TLS 1.2 i.e. self-initiated cryptographic output capability is inherently active per the module’s design. The Crypto Officer must only power on the underlying platform, i.e., IPC device. Successful negotiation of the TLS 1.2 session indicates that the selfinitiated cryptographic output capability is active.

5 Software/Firmware Security
5.1 Integrity Techniques

The Module uses RSA 2048 SHA2-256 as the approved integrity technique. The pre-calculated value of the approved digital signature is included within the module. The integrity test covers the entirety of the module software. If the value calculated at boot for the approved digital signature does not match the pre-calculated, stored value, the test fails. This document may be freely reproduced and distributed in its entirety without modification.

Page 51

The RSA 2048 SHA2-256 CAST is performed prior to the software integrity test in accordance with the IG 10.2.A. The Module is provided in the executable form (.exe). The software integrity RSA mod 2048 public key used for signature verification is considered non-SSP and stored within the module.

5.2 Initiate on Demand

An operator of the module can perform the integrity test on demand by reloading the module. If the integrity test fails, module enters an error state. The module does not support loading any additional software from an external source.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module is a Level 1 multi-chip standalone software module with a modifiable operational environment.

6.2 Configuration Settings and Restrictions

There are no restrictions on the operational environment of the module.

7 Physical Security

The Module is a software module thus the requirements per this section do not apply.

8 Non-Invasive Security

The Module is a software module thus the requirements per this section do not apply.

9 Sensitive Security Parameters Management
9.1 Storage Areas

This document may be freely reproduced and distributed in its entirety without modification.

Page 52
Storage Area NameDescriptionPersistence Type
RAMTemporary, plaintext storageDynamic
Stored in the module binaryPersistent, plaintext storageStatic

Name API input API output Stored at manufactur e - 1 Input during TLS 1.2 negotiation Output during TLS 1.2 negotiation

From Calling application Module Manufacture r TLS 1.2 peer/external endpoint RAM

To Module Calling application Stored in the module binary RAM TLS 1.2 peer/externa l endpoint

Format Type Plaintex t Plaintex t Plaintex t Plaintex t Plaintex t

Distributio n Type Manual Manual N/A Automated Automated

Entry Type Electroni c Electroni c N/A Electroni c Electroni c

SFI or Algorith m

Zeroization MethodDescriptionRationaleOperator Initiation
Zeroisation in the context of function callsTemporary CSPs are zeroised within the relevant function calls per serviceAutomatic zeroisation per module's design in the context of each function calledModule initiated
Restarting the host platformSSPs are stored temporarily in RAMRAM is cleansed via reboot of the underlying host; no copies of SSPs are maintained/stored within the module itselfOperator initiated
TLS 1.2 Session TerminationSSPs zeroised upon TLS 1.2 session terminationTLS 1.2 SSPs are stored ephemerally until session terminationModule initiated
9.2 SSP Input-Output Methods

m Table 15: SSP Input-Output Methods The module is compliant with IG 9.5.A MD/EE (CM Software to/from App via TOEPP Path) and with AD/EE in the context of the TLS 1.2 protocol.

9.3 SSP Zeroization Methods

This document may be freely reproduced and distributed in its entirety without modification.

Page 53
Zeroization MethodDescriptionRationaleOperator Initiation
Module uninstantiationDRBG state zeroisationUn-instantiation of the module zeroises the DRBG stateOperator initiated
NameDescriptionSize - StrengthType - Catego ryGenerat ed ByEstablish ed ByUsed By
SigGen KeyPrivate key for signature generationRSA: 2048, 3072 and 4096 bits ECDSA: B-233, K- 233, P- 224; B- 283, K- 283, P- 256; B- 409, K- 409, P- 384; B- 571, K- 571, P- 521 - RSA: 112, 128 or 152 ECDSA: 112, 128, 192, 521Private key - CSPRSA SigGen/Sig Ver ECDSA SigGen/Sig Ver RSASP
SigVer KeyPublic key for signature verificationRSA: 1024, 2048, 3072 and 4096 bits ECDSA: ECDSA: B-233, K- 233, P- 224; B- 283, K- 283, P- 256; B-Public key - PSPRSA SigGen/Sig Ver ECDSA SigGen/Sig Ver

Table 16: SSP Zeroization Methods

9.4 SSPs

This document may be freely reproduced and distributed in its entirety without modification.

Page 54
NameDescriptionSize - Strength 409, K- 409, P- 384; B- 571, K- 571, P- 521 - RSA: 80, 112, 128 or 152 ECDSA: 112, 128, 192, 256Type - Catego ryGenerat ed ByEstablish ed ByUsed By
Private KeyPrivate key requested by calling application (purpose unknown)RSA: 2048, 3072, 4096 bits ECDSA: ECDSA: B-233, K- 233, P- 224; B- 283, K- 283, P- 256; B- 409, K- 409, P- 384; B- 571, K- 571, P- 521 - RSA: 112, 128 or 152 ECDSA: 112, 128, 192, 256Private key - CSPGenerat e Key Random Bit Generati on
Public KeyPublic key requested by calling application (purpose unknown)RSA: 2048, 3072, 4096 bits ECDSA: ECDSA: B-233, K- 233, P- 224; B- 283, K-Public key - PSPGenerat e Key Random Bit Generati on

This document may be freely reproduced and distributed in its entirety without modification.

Page 55
NameDescriptionSize - Strength 283, P- 256; B- 409, K- 409, P- 384; B- 571, K- 571, P- 521 - RSA: 112, 128 or 152 ECDSA: 112, 128, 192, 256Type - Catego ryGenerat ed ByEstablish ed ByUsed By
SSP Agreem ent Private FFC/EC C KeyPrivate key provided by the entity using the module for Diffie- Hellman shared secret generationFFC: FB, FC, MODP20 48, ffdhe204 8, MODP30 72, ffdhe307 2, MODP40 96, ffdhe409 6, MODP61 44, ffdhe614 4, MODP81 92, ffdhe 8192 ECC: B- 233, K- 233, P- 224, B- 283, K- 283, P- 256, B- 409, K- 409, P- 384, B- 571, K-Private key - CSPGenerat e Key Random Bit Generati onKAS-1 KAS-2 KAS-3

2, 6, 4, This document may be freely reproduced and distributed in its entirety without modification.

Page 56
NameDescriptionSize - Strength 571, P- 521, IFC: k=2048, 3072, 4096, 6144, 8192 bits - FFC: between 112 and 200 ECC: 112, 128, 192, 256 IFC [SP800- 56Br2]: 112, 128Type - Catego ryGenerat ed ByEstablish ed ByUsed By
SSP Agreem ent Public FFC/EC C KeyPublic key provided by the entity using the module for Diffie- Hellman shared secret generationFFC: FB, FC, MODP20 48, ffdhe204 8, MODP30 72, ffdhe307 2, MODP40 96, ffdhe409 6, MODP61 44, ffdhe614 4, MODP81 92, ffdhe 8192 ECC: B- 233, K- 233, P- 224, B- 283, K- 283, P- 256, B- 409, K-Public key - PSPGenerat e Key Random Bit Generati onKAS-1 KAS-2 KAS-3

2, 6, 4, This document may be freely reproduced and distributed in its entirety without modification.

Page 57
NameDescriptionSize - Strength 409, P- 384, B- 571, K- 571, P- 521, IFC: k=2048, 3072, 4096, 6144, 8192 bits - FFC: between 112 and 200 ECC: 112, 128, 192, 256 IFC [SP800- 56Br2]: 112, 128Type - Catego ryGenerat ed ByEstablish ed ByUsed By
KAS Shared SecretShared secret computation (z)FFC: FB, FC, MODP20 48, ffdhe204 8, MODP30 72, ffdhe307 2, MODP40 96, ffdhe409 6, MODP61 44, ffdhe614 4, MODP81 92, ffdhe 8192 ECC: B- 233, K- 233, P- 224, B- 283, K-Shared secret - CSPKAS-1 KAS-2 KAS-3

8, 2, 6, 4, This document may be freely reproduced and distributed in its entirety without modification.

Page 58
NameDescriptionSize - Strength 283, P- 256, B- 409, K- 409, P- 384, B- 571, K- 571, P- 521, IFC: k=2048, 3072, 4096, 6144, 8192 bits - FFC: between 112 and 200 ECC: 112, 128, 192, 256 IFC: 112, 128Type - Catego ryGenerat ed ByEstablish ed ByUsed By
DKMKey Derivation derived keying materialHMAC PRF: 160, 224, 256, 384, 512 - HMAC PRF: 160, 224, 256, 384, 512Derived Keying Material - CSPDerive
MAC KeyKeyed Hash keyCMAC: 128, 192, 256 GMAC: 128, 192, 256 HMAC: 160, 256, 512. KMAC: 128, 256 - CMAC: 128, 192, 256 GMAC:Symmet ric key - CSPRandom Bit Generati on Symmet ric Key Generati onMAC KTS-2

This document may be freely reproduced and distributed in its entirety without modification.

Page 59
NameDescriptionSize - Strength 128, 192, 256 HMAC: 160, 256, 512. KMAC: 128, 256Type - Catego ryGenerat ed ByEstablish ed ByUsed By
SSP Transpo rt Private KeyPrivate key (KDK) used for [SP800- 56Br2] RSA key transport2048, 3072, 4096 and 6144 bits - 112, 128, 152, 176Private key - CSPKTS-4
SSP Transpo rt Public keyPublic key (KEK) used for [SP800- 56Br2] RSA key transport2048, 3072, 4096 and 6144 bits - 112, 128, 152, 176Public key - PSPKTS-4
Key Transpo rt Shared SecretThe RSA key transport shared secret2048, 3072, 4096 and 6144 bits - 112, 128, 152, 176Shared secret - CSPKTS-4
Entropy InputEntropy input from an external source used for DRBG seeding128 - 256 bits - 128 - 256 bitsEntropy input - CSPRandom Bit Generation
SeedSeed generated from the entropy input for the DRBG128 - 256 bits - 128 - 256 bitsDRBG seed - CSPRandom Bit Generation
StateDRBG stateHash DRBG: 160, 224, 256, 384, 512 HMAC DRBG: 160, 224, 256, 384, 512. CTR DRBG:DRBG state - CSPRandom Bit Generati onRandom Bit Generation

This document may be freely reproduced and distributed in its entirety without modification.

Page 60
NameDescriptionSize - Strength 128, 192, 256 - Hash DRBG: 160, 224, 256, 384, 512 HMAC DRBG: 160, 224, 256, 384, 512. CTR DRBG: 128, 192, 256Type - Catego ryGenerat ed ByEstablish ed ByUsed By
Symmet ric KeyAES Encryption/Decryptio n/Key Wrapping KeyAES: 128, 192, 256 AES CCM: 128, 192, 256 AES GCM: 128, 192, 256 AES XTS: 128, 256. - AES: 128, 192, 256 AES CCM: 128, 192, 256 AES GCM: 128, 192, 256 AES XTS: 128, 256Symmet ric key - CSPRandom Bit Generati on Symmet ric Key Generati onAES Encrypt/Dec rypt AES Key Wrapping KTS-1 KTS-2 KTS-3
TLS Master SecretTLS 1.2 Master Secret derived from the pre-master secret384 bits - 192 bitsShared secret - CSPDeriveTLS v1.2 KDF RFC7627 (A5153)
TLS Session KeyAES key used to encrypt the TLS session256 bits - 256 bitsSymmet ric key - PSPDeriveKAS-4KTS-5

This document may be freely reproduced and distributed in its entirety without modification.

Page 61
NameDescriptionSize - StrengthType - Catego ryGenerat ed ByEstablish ed ByUsed By
KAS Public KeyEC Diffie-Hellman i.e. KAS-ECC-SSC public key used in EC Diffie-Hellman Key Exchange for TLS 1.2P-384 - 192 bitsPublic key - PSPGenerat e Key Random Bit Generati onKAS-ECC- SSC Sp800- 56Ar3 (A5153)
KAS Private KeyEC Diffie-Hellman i.e. KAS-ECC-SSC private key used in EC Diffie-Hellman Key Exchange for TLS 1.2P-384 - 192 bitsPrivate key - CSPGenerat e Key Random Bit Generati onKAS-ECC- SSC Sp800- 56Ar3 (A5153)
ECDSA Public KeyECDSA public key used for TLS 1.2 authenticationP-384 - 192 bitsPublic key - PSPGenerat e Key Random Bit Generati onECDSA SigVer (FIPS186-5) (A5153)
ECDSA Private KeyECDSA private key used for TLS 1.2 authenticationP-384 - 192 bitsPrivate key - CSPGenerat e Key Random Bit Generati onECDSA SigGen (FIPS186-5) (A5153)
RSA Public KeyRSA public key used for TLS 1.2 authenticationRSA SigVer mod 2048 - 112 bitsPublic key - PSPGenerat e Key Random Bit Generati onRSA SigVer (FIPS186-5) (A5153)
RSA Private KeyRSA private key used for TLS 1.2 authenticationRSA SigGen mod 2048 - 112 bitsPrivate key - CSPGenerat e Key Random Bit Generati onRSA SigGen (FIPS186-5) (A5153)
TLS Pre- Master SecretTLS 1.2 pre-master secret computed (KAS-ECC-SSC)384 bits - 192 bitsShared secret - CSPKAS-4TLS v1.2 KDF RFC7627 (A5153)
KAS Peer Public KeyEC Diffie-Hellman i.e. KAS-ECC-SSC public key used in EC Diffie-Hellman Key Exchange forP-384 - 192 bitsPublic key - PSPKAS-4

This document may be freely reproduced and distributed in its entirety without modification.

Page 62
NameDescription TLS 1.2 (TLS 1.2 peer key)Size - StrengthType - Catego ryGenerat ed ByEstablish ed ByUsed By
Softwar e Integrity Key - RSARSA key used to perform the Software Integrity Test2048 bits - 112 bitsPublic key - NeitherRSA SigVer (FIPS186 -5) (A5153)Software Integrity Test
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
SigGen KeyAPI inputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nSigVer Key:Paired With
SigVer KeyAPI inputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nSigGen Key:Paired With
Private KeyAPI outputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nPublic Key:Paired With
Public KeyAPI outputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nPrivate Key:Paired With

Table 17: SSP Table 1 n n n n This document may be freely reproduced and distributed in its entirety without modification.

Page 63
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
SSP Agreemen t Private FFC/ECC KeyAPI inputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nSSP Agreement Public FFC/ECC Key:Paired With
SSP Agreemen t Public FFC/ECC KeyAPI inputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nSSP Agreement Private FFC/ECC Key:Paired With
KAS Shared SecretAPI outputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nSSP Agreement Private FFC/ECC Key:Establishe d using SSP Agreement Public FFC/ECC Key:Establishe d using
DKMAPI outputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio n
MAC KeyAPI inputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio n
SSP TransportAPI inputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function callsSSP Transport Public

n n n n This document may be freely reproduced and distributed in its entirety without modification.

Page 64
Name Private KeyInput - OutputStorageStorage DurationZeroization Restarting the host platform Module uninstantiatio nRelated SSPs key:Paired With
SSP Transport Public keyAPI inputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nSSP Transport Private Key:Paired With
Key Transport Shared SecretAPI input API outputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio n
Entropy InputAPI inputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nSeed:Used to derive
SeedRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform Module uninstantiatio nEntropy Input:Derived From
StateRAM:Encrypte dUntil power- cycling of the underlying host platformRestarting the host platform Module uninstantiatio nSeed:Derived From
Symmetric KeyAPI input API outputRAM:Encrypte dzeroised once no longer neededZeroisation in the context of function calls Restarting the host platform

n n n n n n This document may be freely reproduced and distributed in its entirety without modification.

Page 65
NameInput - OutputStorageStorage DurationZeroization Module uninstantiatio nRelated SSPs
TLS Master SecretRAM:Plaintextzeroised once no longer neededZeroisation in the context of function callsTLS Pre- Master Secret:Derived From
TLS Session KeyRAM:Plaintextzeroised once no longer neededTLS 1.2 Session TerminationTLS Master Secret:Derived From
KAS Public KeyOutput during TLS 1.2 negotiationRAM:Plaintextzeroised once no longer neededTLS 1.2 Session TerminationKAS Private Key:Paired With
KAS Private KeyRAM:Plaintextzeroised once no longer neededTLS 1.2 Session TerminationKAS Public Key:Paired With
ECDSA Public KeyOutput during TLS 1.2 negotiationRAM:Plaintextzeroised once no longer neededTLS 1.2 Session Termination
ECDSA Private KeyRAM:Plaintextzeroised once no longer neededTLS 1.2 Session Termination
RSA Public KeyOutput during TLS 1.2 negotiationRAM:Plaintextzeroised once no longer neededTLS 1.2 Session Termination
RSA Private KeyRAM:Plaintextzeroised once no longer neededTLS 1.2 Session Termination
TLS Pre- Master SecretRAM:Plaintextzeroised once no longer neededZeroisation in the context of function callsTLS Master Secret:Used to derive
KAS Peer Public KeyInput during TLS 1.2 negotiationRAM:Plaintextzeroised once no longer neededTLS 1.2 Session TerminationKAS Public Key:Used With
Software Integrity Key - RSAStored at manufactur e - 1Stored in the module binary:Plaintex tUntil module uninstantiatio n is performedModule uninstantiatio n
9.5 Transitions

This document may be freely reproduced and distributed in its entirety without modification.

Page 66

Conformance to FIPS 186-5 is mandatory as of February 4, 2024. The module claims conformance to FIPS 186-4 as allowed per the FIPS 140-3 IG C.K Additional Comment #2. Per the NIST SP 800-133Ar2/3 and the programmatic transitions defined by the CMVP, the following algorithm transitions apply to the module, and the algorithms have been designated allowed/non-approved accordingly in Section 2.5: a. SHA-1 for SigVer (per IG C.M 3.e) and SHA-1 used for SigGen is a non-approved, not allowed algorithm. Usage of SHA-1 for all other SigVer is allowed for legacy use only until 2030. Thereafter, all usage of SHA-1 will be considered a non-approved, not allowed algorithm. b. FIPS 186-2 RSA KeyGen and SigGen modes are non-approved, not allowed algorithms. c. RSA-based key transport schemes that only use PKCS#1-v1.5 padding are nonapproved, not allowed algorithms. d. FIPS 186-4 DSA Key Gen, Sig Gen, or PQG Gen; FIPS 186-4 X9.31 RSA Key Gen, RSA Sig Gen are non-approved, not allowed algorithms. e. Usage of FIPS 186-4 RSA SigVer X9.31 is allowed only for legacy use. f. Triple-DES decryption is allowed for legacy use only. g. Triple-DES encryption is non-approved, not allowed algorithm. h. Key agreement schemes that are not compliant with any version of SP 800-56A (X448, X25519) are non-approved, not allowed algorithms. i. Until January 1, 2031, the following algorithms will be considered deprecated: a. SHA-1, SHA-224 hash functions b. Hash_DRBG and HMAC_DRBG using SHA-1, SHA-224 hash functions c. Hash function and HMAC using SHA-1, SHA-224 hash functions d. Use of a security strength less than 128-bits but greater than 112 bits for HMAC Generation j. As of January 1, 2031, the following algorithms will be considered deprecated/disallowed (i.e. non-approved, not allowed)/legacy use: a. SHA-1, SHA2-224 hash functions (disallowed) b. Use of the 112-bit security strength for classical digital signature and keyestablishment mechanisms (deprecated) c. Use of the 112-bit security strength for block ciphers (disallowed) d. Use of a security strength less than 128-bits but greater than 112 bits for ECDA KeyGen and RSA KeyGen (PKCS #1 v1.5 & PSS) (deprecated) e. Hash_DRBG and HMAC_DRBG using SHA-1, SHA-224 hash functions (disallowed) f. Hash function and HMAC using SHA-1, SHA-224 hash functions (legacy use) g. Use of a security strength less than 128-bits but greater than 112 bits for HMAC Generation (disallowed) h. Use of a security strength less than 128-bits but greater than 112 bits for HMAC Verification (legacy use)

10 Self-Tests
10.1 Pre-Operational Self-Tests

This document may be freely reproduced and distributed in its entirety without modification.

Page 67
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
RSA SigVer (FIPS186-5) (A5153)Modulus: 2048 bits; Hash: SHA2-256KATSW/FW IntegrityVerified OKVerify
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A5153)Key Length: 128 bitsKATCAST1DecryptOn reloading the module
AES-GCM (A5153) - Encrypt - 256 bitsKey Length: 256 bitsKATCAST1EncryptOn reloading the module
AES-GCM (A5153) - Decrypt - 256 bitsKey Length: 256 bitsKATCAST1DecryptOn reloading the module
Counter DRBG (A5153)AES CTR (128 bits) with derivation functionKATCAST1Generate, Reseed, Instantiate functionsOn reloading the module
ECDSA SigGen (FIPS186- 5) (A5153) - P-224Curve: P- 224; Hash: SHA2-512KATCAST1SignOn reloading the module
ECDSA SigVer (FIPS186- 5) (A5153) - P-224Curve: P- 224; Hash: SHA2-512KATCAST1VerifyOn reloading the module
Hash DRBG (A5153)PRF: SHA2-256KATCAST1Generate, Reseed, Instantiate functionsOn reloading the module
HMAC DRBG (A5153)PRF: HMAC- SHA-1KATCAST1Generate, Reseed, Instantiate functionsOn reloading the module

Table 19: Pre-Operational Self-Tests The pre-operational self-tests can be run on demand by reloading the module.

10.2 Conditional Self-Tests

This document may be freely reproduced and distributed in its entirety without modification.

Page 68
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-256 (A5153)PRF: SHA2-256KATCAST1HMAC tag GenerationOn reloading the module
KAS- ECC-SSC Sp800- 56Ar3 (A5153)Scheme: Ephemeral Unified, Curve: P- 256KATCAST1Key Agreement - Shared Secret ComputationOn reloading the module
KAS-FFC- SSC Sp800- 56Ar3 (A5153)Scheme: dhEphem; Modulus: L = 2048 bits, N = 256 bitKATCAST1Key Agreement - Shared Secret ComputationOn reloading the module
KAS-IFC- SSC (A5153)Schemes: Basic, CRT, Modulus: L = 2048 bitsKATCAST1Key Agreement - Shared Secret ComputationOn reloading the module
KDF SP800- 108 (A5153)Mode: Counter, PRF: HMAC- SHA2-256KATCAST1Counter Mode (HMAC- SHA2-256).On reloading the module
KDA OneStep SP800- 56Cr2 (A5153)Auxiliary Function, H = SHA2- 224KATCAST1Key DerivationOn reloading the module
KDA TwoStep SP800- 56Cr2 (A5153)Auxiliary Function, H = HMAC- SHA2-256KATCAST1Key DerivationOn reloading the module
KTS-IFC (A5153) - BasicSchemes: Basic Modulus: L = 2048 bitsKATCAST1EncryptOn reloading the module
KTS-IFC (A5153) - CRTSchemes: Basic, CRT, Modulus: L = 2048 bitsKATCAST1DecryptOn reloading the module
PBKDF (A5153)Derivation of the Master Key (MK),KATCAST1Key DerivationOn reloading the module

This document may be freely reproduced and distributed in its entirety without modification.

Page 69
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
PRF: SHA2-256
RSA SigGen (FIPS186- 5) (A5153)Scheme: PKCS#1, Modulus: L = 2048, Hash: SHA2-256KATCAST1SignOn reloading the module
RSA SigVer (FIPS186- 5) (A5153)Scheme: PKCS#1, Modulus: L = 2048, Hash: SHA2-256KATCAST1VerifyOn reloading the module
SHA-1 (A5153)SHA-1KATCAST1HashOn reloading the module
SHA2-512 (A5153)SHA2-512KATCAST1HashOn reloading the module
SHA3-256 (A5153)SHA3-256KATCAST1HashOn reloading the module
KDF ANS 9.42 (A5153)PRFs: AES KW (128 bits), SHA-1KATCAST1Key DerivationOn reloading the module
KDF ANS 9.63 (A5153)PRF: SHA2-256KATCAST1Key DerivationOn reloading the module
KDF SSH (A5153)PRF: SHA- 1KATCAST1Key DerivationOn reloading the module
TLS v1.2 KDF RFC7627 (A5153)PRF: SHA2-256KATCAST1Key DerivationOn reloading the module
TLS v1.3 KDF (A5153)PRF: SHA2-256KATCAST1Key DerivationOn reloading the module
RSA KeyGen (FIPS186- 5) (A5153)Performed on key generationPCTPCT1Key GenerationOn generating keys for Key Transport (KTS IFC)/Key Agreement (KAS IFC)/Signature Generation/Signature Verification
ECDSA KeyGen (FIPS186- 5) (A5153)Performed on key generationPCTPCT1Key GenerationOn generating keys for Key Agreement (KAS ECC)/Signature

This document may be freely reproduced and distributed in its entirety without modification.

Page 70
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions Generation/Signature Verification
ECDSA SigGen (FIPS186- 5) (A5153) - K-233Curve: K- 233; Hash: SHA2-512KATCAST1SignOn reloading the module
ECDSA SigVer (FIPS186- 5) (A5153) - K-233Curve: K- 233; Hash: SHA2-512KATCAST1VerifyOn reloading the module
KAS-FFC- SSC Sp800- 56Ar3 (A5153) - PCTPerformed post key generationPCTPCT1Key GenerationOn generating keys for Key Agreement (KAS FFC)
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigVer (FIPS186-5) (A5153)KATSW/FW IntegrityOn DemandManually by reloading the module
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A5153)KATCASTOn DemandManually by reloading the module
AES-GCM (A5153) - Encrypt - 256 bitsKATCASTOn DemandManually by reloading the module
AES-GCM (A5153) - Decrypt - 256 bitsKATCASTOn DemandManually by reloading the module

Table 20: Conditional Self-Tests The conditional cryptographic algorithm self-tests can be run on demand by reloading the

10.3 Periodic Self-Test Information

Table 21: Pre-Operational Periodic Information This document may be freely reproduced and distributed in its entirety without modification.

Page 71
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Counter DRBG (A5153)KATCASTOn DemandManually by reloading the module
ECDSA SigGen (FIPS186-5) (A5153) - P-224KATCASTOn DemandManually by reloading the module
ECDSA SigVer (FIPS186-5) (A5153) - P-224KATCASTOn DemandManually by reloading the module
Hash DRBG (A5153)KATCASTOn DemandManually by reloading the module
HMAC DRBG (A5153)KATCASTOn DemandManually by reloading the module
HMAC-SHA2- 256 (A5153)KATCASTOn DemandManually by reloading the module
KAS-ECC-SSC Sp800-56Ar3 (A5153)KATCASTOn DemandManually by reloading the module
KAS-FFC-SSC Sp800-56Ar3 (A5153)KATCASTOn DemandManually by reloading the module
KAS-IFC-SSC (A5153)KATCASTOn DemandManually by reloading the module
KDF SP800-108 (A5153)KATCASTOn DemandManually by reloading the module
KDA OneStep SP800-56Cr2 (A5153)KATCASTOn DemandManually by reloading the module
KDA TwoStep SP800-56Cr2 (A5153)KATCASTOn DemandManually by reloading the module
KTS-IFC (A5153) - BasicKATCASTOn DemandManually by reloading the module
KTS-IFC (A5153) - CRTKATCASTOn DemandManually by reloading the module
PBKDF (A5153)KATCASTOn DemandManually by reloading the module

This document may be freely reproduced and distributed in its entirety without modification.

Page 72
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigGen (FIPS186-5) (A5153)KATCASTOn DemandManually by reloading the module
RSA SigVer (FIPS186-5) (A5153)KATCASTOn DemandManually by reloading the module
SHA-1 (A5153)KATCASTOn DemandManually by reloading the module
SHA2-512 (A5153)KATCASTOn DemandManually by reloading the module
SHA3-256 (A5153)KATCASTOn DemandManually by reloading the module
KDF ANS 9.42 (A5153)KATCASTOn DemandManually by reloading the module
KDF ANS 9.63 (A5153)KATCASTOn DemandManually by reloading the module
KDF SSH (A5153)KATCASTOn DemandManually by reloading the module
TLS v1.2 KDF RFC7627 (A5153)KATCASTOn DemandManually by reloading the module
TLS v1.3 KDF (A5153)KATCASTOn DemandManually by reloading the module
RSA KeyGen (FIPS186-5) (A5153)PCTPCTOn DemandOn generation of keys
ECDSA KeyGen (FIPS186-5) (A5153)PCTPCTOn DemandOn generation of keys
ECDSA SigGen (FIPS186-5) (A5153) - K-233KATCASTOn DemandManually by reloading the module
ECDSA SigVer (FIPS186-5) (A5153) - K-233KATCASTOn DemandManually by reloading the module
KAS-FFC-SSC Sp800-56Ar3 (A5153) - PCTPCTPCTOn DemandOn generation of keys

Table 22: Conditional Periodic Information This document may be freely reproduced and distributed in its entirety without modification.

Page 73
Nam eDescriptionConditionsRecover y MethodIndicator
Hard errorA failure in the pre- operational integrity test/one of the cryptographi c algorithm self-tests will cause the module to return an error and enter the Hard error stateIf the pre- operational software integrity test fails If one of the cryptographi c algorithm's self-test (a CAST, specifically, a Known Answer Test (KAT)) were to failReloadin g of the modulePROV_R_FIPS_MODULE_IN_ERROR_ST ATE and the string "signature not match"
10.4 Error States

e y Table 23: Error States On instantiation, the Module performs the self-tests described in Table 22 and all CASTs. All KATs must complete successfully prior to any other use of cryptography by the Module. If one of

10.5 Operator Initiation of Self-Tests

The module can be reloaded on demand for running the Cryptographic Algorithm Self-tests

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is shipped pre-installed in the Approved mode of operation with the IPC device. The operator must power on the appliance upon delivery to cause it to automatically execute the pre-operational integrity tests and CASTs on all algorithms. Once the self-tests have completed successfully, the module is ready for use. The operator can verify the software version (V9FIPS.1.0) returned via an API call to the module and the module identifier (the string “IPC” printed in the boot logs). This document may be freely reproduced and distributed in its entirety without modification.

Page 74
11.2 Administrator Guidance

No additional guidance applies for the operation of the module apart from that specified in Section 2 and other subsections under this section.

11.3 Non-Administrator Guidance

No additional guidance applies for the operation of the module apart from that specified in Section 2 and other subsections under this section.

11.4 Design and Rules

Azure is used as the Configuration Management System. The module’s software is implemented using high-level language and designed to avoid use of code, parameters or symbols that are not necessary for the module’s functionality and execution.

11.5 Maintenance Requirements

No maintenance requirements apply. The module’s software is protected from tampering as it is delivered securely within the IPC device.

11.6 End of Life

The module can be uninstalled to end-of-life the module. The module can be securely sanitized by zeroising it.

12 Mitigation of Other Attacks
12.1 Attack List

The Module implements mitigations for some types of attacks using constant implementation and blinding. This document may be freely reproduced and distributed in its entirety without modification.