All modules
CMVP Validated Module · FIPS 140-3 Security Policy

WTM 4000 module

Certificate#5107StandardFIPS 140-3Level1TypeSoftwareEmbodimentMultiChipStandStatusActiveVendorAviat Networks
Low review priority  ·  no TCB surface named  ·  last validated 7 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMultiChipStand
StatusActive
Sunset date7/10/2029
CaveatNo assurance of the minimum strength of generated SSPs (e.g., keys)
VendorAviat Networks

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for WTM 4000 module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Show Status<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>library named: wolfssl</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C3,C5,C6 clue;
  class I3,I5,I6 infer;
  class R3,R5,R6 risk;
  class E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for WTM 4000 module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Show Status<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>library named: wolfssl</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Aviat Networks WTM 4000 module Document Version 1.0

23 May 2025

AVIAT NETWORKS 200C Parker Drive, Suite 100A Austin, TX 78728 aviatnetworks.com +1 (512) 265-3680 © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 4
List of Tables
ItemPage
Table 1: This Document History4
Table 2: Security Levels5
Table 3: Legend of Terms and references that appear in this document6
Table 4: Source Files7
Table 5: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)8
Table 6: Tested Operational Environments - Software, Firmware, Hybrid8
Table 7: Modes List and Description9
Table 8: Approved Algorithms12
Table 9: Vendor-Affirmed Algorithms13
Table 10: Security Function Implementations20
Table 11: Ports and Interfaces21
Table 12: Roles22
Table 13: Approved Services25
Table 14: Storage Areas27
Table 15: SSP Input-Output Methods27
Table 16: SSP Zeroization Methods28
Table 17: SSP Table 133
Table 18: SSP Table 233
Table 19: Pre-Operational Self-Tests34
Table 20: Conditional Self-Tests39
Table 21: Pre-Operational Periodic Information39
Table 22: Conditional Periodic Information40
Table 23: Periodic Method Descriptions40
Table 24: Error States42
Figure 1: Module Block Diagram7
Figure 2: Code Sample A44
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
Term/RefDescription
[140-3]FIPS 140-3, Security Requirements for Cryptographic Modules
[OE]The “Operating Environment”
[186-4]FIPS 186-4, Digital Signature Standard (DSS)
[90Arev1]NIST SP 800-90A Rev. 1, Recommendation for Random Number Generation Using Deterministic Random Bit Generators
[56Arev3]NIST SP 800-56A Rev. 3, Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography
[56Crev2]NIST SP 800-56C Rev. 2, Recommendation for Key- Derivation Methods in Key-Establishment Schemes
[135rev1]NIST SP 800-135 Rev. 1, Recommendation for Existing Application-Specific Key Derivation Functions
1.1 Overview

This document defines the Security Policy for AVIAT NETWORKS WTM 4000 module, hereafter levels as described in section 1.2 below.

1.2 Security Levels
1.3 Additional Information

In accordance with AS02.05, [ISO19790] §7.7 Physical Security is optional and does not apply © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 6
Term/RefDescription
[140Drev2]NIST SP 800-140D revision 2, CMVP Approved Sensitive Parameter Generation and Establishment Methods: CMVP Validation Authority Updates to ISO/IEC 24759
[UG]AVIAT NETWORKS FIPS 140-3 User Guide (sometimes referred to as the “Cryptographic Officer Guidance Manual” in documentation not produced by this vendor)
[COGM]Cryptographic Officer Guidance Manual (Another term for [UG] recognized by some in the Industry. Same meaning as [UG]
[140-3 IG]FIPS 140-3, Implementation Guidance
[131Arev2]NIST SP 800-131A Rev. 2, Transitioning the Use of Cryptographic Algorithms and Key Lengths
[56Brev2]NIST SP 800-56B Rev. 2, Recommendation for Pair-Wise Key-Establishment Using Integer Factorization Cryptography

Table 3: Legend of Terms and references that appear in this document

2 – Cryptographic Module Specification

TOEPP: The platform(s) used for testing are documented in Table 6: Tested Operational Environments - Software, Firmware, Hybrid. If the onboard CPU of a tested platform supported a known PAA [FIPS 140-3 IG 2.3.C] and was desirable for FIPS use, then in accordance with [FIPS 140-3 IG2.3.C] that platform was tested both with and without PAA unless an identical or similar platform had already been tested. When an identical or similar platform was already tested, the new platform was tested only with PAA. This is reflected by the column PAA/PAI in table 6 as marked with a Yes or No entry. The Intel and AMD AESNI (AES New Instructions) are known PAA(s). The Module is a cryptography software library. The Module is a Multi-Chip Stand Alone embodiment. The Module is intended for use by U.S. and Canadian Federal agencies in addition to any other markets that require FIPS 140-3 validated cryptographic functionality. The Module was originally designed with embedded and IoT in mind. As a side effect of this design, it also scales exceptionally well on larger desktop and server systems allowing more connections per box than similar competing solutions. The Module version under validation is Software Version v5.2.1. Module Type: Software Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without

Page 7
Source File NameDescription
aes.cAES algorithm
aes_asm.sAES assembler optimizations (Linux)
aes_asm.asmAES assembler optimizations (Windows 10)
cmac.cCMAC algorithm
dh.cDiffie-Hellman
ecc.cElliptic curve cryptography
fips.cPre-operational entry point and API wrappers
fips_test.cPower on self-tests
hmac.cHMAC algorithm
kdf.cTLS v1.2, v1.3 and SSH v2 KDFs
random.cDRBG algorithm
rsa.cRSA algorithm
sha.cSHA algorithm
sha256.cSHA-256 algorithm
sha256_asm.sSHA-256 assembler optimizations (Linux)
sha512_asm.sSHA-512 assembler optimizations (Linux)
sha3.cSHA-3 algorithm
sha512.cSHA-512 algorithm
wolfcrypt_first.cFirst function and Read Only address marking start of cryptographic boundary
wolfcrypt_last.cLast function and Read Only address marking end of cryptographic boundary

Figure 1 depicts the Module operational environment, with the software module cryptographic boundary highlighted in red inclusive of all Module entry points (API calls). The Module is defined as a Software module per AS02.03. No components are excluded from [140-3] requirements. The pre-operational approved integrity test is performed over all components of the cryptographic boundary. Updates to the Module are provided as a complete replacement in accordance with AS04.27 – AS04.35. Figure 1: Module Block Diagram of cryptographic boundary Table 4: Source Files The source code files listed in Table “Source Files” result in the corresponding object files that comprise the WTM 4000 module boundary on each supported operating environment; the extensions of the object file can differ across environments.

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 8
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
wolfssl-5.6.3- commercial-fips- linuxv5.2.1.7zv5.2.1FIPS 140-3 module and SSL/TLS libraryHMAC-SHA256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Linux 5.4WTM 4100Broadcom BCM56260B0IFSBG - Saber2Nov5.2.1
Mode NameDescriptionTypeStatus Indicator
Approved mode of operationThe Module supports an Approved mode of operation. In this mode all services are available.ApprovedFIPS_MODE_NORMAL (1)
Degraded mode of operationThe Module implements a Degraded Mode of operation: when a CAST fails, that CAST is marked as failed and the module will inhibit use of algorithms governed by that CASTApprovedFIPS_MODE_DEGRADED (2)

Table 5: Tested Module Identification

2.3 Excluded Components

N/A the module does not support excluded components. Modes List and Description: © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 9

Table 7: Modes List and Description Mode Change Instructions and Status: Each time the module is power cycled or reloaded all CAST status are initialized to FIPS_CAST_STATE_INIT. Each algorithm invocation includes a check of the algorithms CAST status; if the CAST status is FIPS_CAST_STATE_INIT the module will automatically run the CAST and that algorithms CAST status will be updated to either FIPS_CAST_STATE_SUCCESS (if it passes) or FIPS_CAST_STATE_FAILURE (if it fails). See degraded mode for when a CAST status fails. To check the modules overall status at any time the cryptographic officer may use the Show Status service by calling wolfCrypt_GetMode_fips() this will return either: FIPS_MODE_INIT (0) - Module is currently running its’ pre-operational self-test in another thread (multi-threaded) FIPS_MODE_NORMAL (1) - Module in normal mode of operation without errors FIPS_MODE_DEGRADED (2) - Module in degraded mode of operation with some errors FIPS_MODE_FAILED (3) - Module failed the integrity check and is not usable To check the CAST state of any algorithm the cryptographic officer may use the Show Status Service by calling wc_GetCastStatus_fips(<algorithm type>) where algorithm type can be any of the following:

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CBCA4308Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4308Key Length - 128, 192, 256SP 800-38C
AES-CMACA4308Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA4308Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4308Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4308Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GMACA4308Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-OFBA4308Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
DSA KeyGen (FIPS186-4)A4308L - 2048 N - 256FIPS 186-4
ECDSA KeyGen (FIPS186-4)A4308Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Extra BitsFIPS 186-4
ECDSA KeyVer (FIPS186-4)A4308Curve - P-192, P-224, P-256, P-384, P-521FIPS 186-4

Degraded Mode Description: The Module implements a degraded mode of operation: when a CAST fails, the module enters an error state. The algorithm CAST status is set to FIPS_CAST_STATE_FAILED and the module runs all CASTS prior to the first operational use of any algorithm, regardless of the CAST having passed previously. Before exiting the error state, the module status (reported in the Show Status service) is set to FIPS_MODE_DEGRADED. Upon exiting the error state, the module enters the degraded mode of operation. This sequence of events is in accordance with AS02.26. The algorithm that failed its’ CAST initially triggering the error state will no longer be available for use in degraded mode of operation and any algorithms that depend on that algorithm will also be unavailable for use. See Table 16: Conditional Self-Tests in section 10.2, column Conditions to see if a CAST failure will affect use of another algorithm. To recover from degraded mode of operation CO shall power cycle or reload the module (equivalent to a power cycle).

2.5 Algorithms

Approved Algorithms: © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 11
AlgorithmCAVP CertPropertiesReference
ECDSA SigGen (FIPS186-4)A4308Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA3-224, SHA3-256, SHA3- 384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4308Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
Hash DRBGA4308Prediction Resistance - No Mode - SHA2-256SP 800-90A Rev. 1
HMAC-SHA-1A4308Key Length - Key Length: 112-1024 Increment 8FIPS 198-1
HMAC-SHA2- 224A4308Key Length - Key Length: 112-1024 Increment 8FIPS 198-1
HMAC-SHA2- 256A4308Key Length - Key Length: 112-1024 Increment 8FIPS 198-1
HMAC-SHA2- 384A4308Key Length - Key Length: 112-1024 Increment 8FIPS 198-1
HMAC-SHA2- 512A4308Key Length - Key Length: 112-1024 Increment 8FIPS 198-1
HMAC-SHA3- 224A4308Key Length - Key Length: 112-1024 Increment 8FIPS 198-1
HMAC-SHA3- 256A4308Key Length - Key Length: 112-1024 Increment 8FIPS 198-1
HMAC-SHA3- 384A4308Key Length - Key Length: 112-1024 Increment 8FIPS 198-1
HMAC-SHA3- 512A4308Key Length - Key Length: 112-1024 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4308Domain Parameter Generation Methods - P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A4308Domain Parameter Generation Methods - ffdhe2048 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF SSH (CVL)A4308Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF TLS (CVL)A4308TLS Version - v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512SP 800-135 Rev. 1

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 12
AlgorithmCAVP CertPropertiesReference
RSA KeyGen (FIPS186-4)A4308Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4308Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4308Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
SHA-1A4308Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-224A4308Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A4308Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A4308Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A4308Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA3-224A4308Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-256A4308Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-384A4308Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-512A4308Message Length - Message Length: 0-65536 Increment 8FIPS 202
TLS v1.2 KDF RFC7627 (CVL)A4308Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A4308HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHESP 800-135 Rev. 1
NamePropertiesImplementationReference
CKG- 1Asymmetric:RSA Asymmetric:ECDSALinux 4.4 (Ubuntu 16.04 LTS) with an Intel Core i5-5300U CPU @2.30GHz x 4 with PAA; Linux 4.4 (Ubuntu 16.04SP800-133r2 5.1 "Key Pairs for Digital Signature Schemes"

Table 8: Approved Algorithms NOTE: Only the algorithms specified in this section are supported by the module in approved mode of operation. No operational use of an algorithm may be performed until the corresponding CAST has passed. Vendor-Affirmed Algorithms: © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 13
NamePropertiesImplementationReference
LTS) with an Intel Core i5-5300U CPU @2.30GHz x 4 without PAA
CKG- 2Asymmetric:ECC Asymmetric:FFCLinux 4.4 (Ubuntu 16.04 LTS) with an Intel Core i5-5300U CPU @2.30GHz x 4 with PAA; Linux 4.4 (Ubuntu 16.04 LTS) with an Intel Core i5-5300U CPU @2.30GHz x 4 without PAASP800-133r2 5.2 "Key Pairs for Key Establishment"
CKG- 3Symmetric:AES Symmetric:HMACLinux 4.4 (Ubuntu 16.04 LTS) with an Intel Core i5-5300U CPU @2.30GHz x 4 with PAA; Linux 4.4 (Ubuntu 16.04 LTS) with an Intel Core i5-5300U CPU @2.30GHz x 4 without PAASP800-133r2 6.2 "Derivation of Symmetric Keys"
NameTypeDescriptionPropertiesAlgorithms
DRBGDRBGDeterministic Random Byte GeneratorSHA2-256: (A4308) A4308: Hash DRBG: (A4308) A4308:
Message AuthenticationMACHash-Based Message Authentication Codes, Generation and VerificationHMAC-SHA-1: (A4308) A4308: HMAC-SHA2- 224: (A4308) A4308: HMAC-SHA2-

Table 9: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. The Module does not implement non-approved algorithms. The services listed in this Security Policy include all cryptographic and non-cryptographic functionality. NOTE: For TLS 1.2 KDF Extended master-secret shall be used in approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 14
NameTypeDescriptionPropertiesAlgorithms
256: (A4308) A4308: HMAC-SHA2- 384: (A4308) A4308: HMAC-SHA2- 512: (A4308) A4308: HMAC-SHA3- 224: (A4308) A4308: HMAC-SHA3- 256: (A4308) A4308: HMAC-SHA3- 384: (A4308) A4308: HMAC-SHA3- 512: (A4308) A4308:
Secure HashSHASecure Hash FunctionSHA-1: (A4308) A4308: SHA2-224: (A4308) A4308: SHA2-256: (A4308) A4308: SHA2-384: (A4308) A4308: SHA2-512: (A4308) A4308: SHA3-224: (A4308) A4308: SHA3-256: (A4308) A4308: SHA3-384: (A4308) A4308: SHA3-512: (A4308) A4308:
TLS 1.3 Key AgreementKAS-56CKDFKDF: Extract then Expand (56C)TLS v1.3 KDF: (A4308) A4308:

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 15
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA2- 256: (A4308) A4308: HMAC-SHA2- 384: (A4308) A4308: HMAC-SHA2- 512: (A4308) A4308:
Primitive Key AgreementKAS-KeyGenDH: Key agreement primitivesKAS-FFC-SSC Sp800-56Ar3: (A4308) A4308:
KDF Derived Key AgreementKAS-135KDFKDF: Derive keying material from a shared secret (135);KDF SSH: (A4308) A4308: KDF TLS: (A4308) A4308: TLS v1.2 KDF RFC7627: (A4308) A4308: SHA-1: (A4308) A4308: SHA2-256: (A4308) A4308: SHA2-384: (A4308) A4308: SHA2-512: (A4308) A4308:
KAS SSC Derived Key AgreementKAS-SSCDerived keying material from a shared secretKAS-ECC-SSC Sp800-56Ar3: (A4308) A4308: KAS-FFC-SSC Sp800-56Ar3: (A4308) A4308:
133r2 5.1 Asymmetric Key GenerationCKGSP800-133r2 5.1 "Key Pairs for Digital Signature Schemes"RSA KeyGen (FIPS186-4): (A4308) A4308: ECDSA KeyGen (FIPS186-4): (A4308)

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 16
NameTypeDescriptionPropertiesAlgorithms
A4308: Hash DRBG: (A4308) A4308: CKG-1: ()
133r2 5.2 Asymmetric Key GenerationCKGSP800-133r2 5.2 "Key Pairs for Key Establishment"KAS-ECC-SSC Sp800-56Ar3: (A4308) A4308: KAS-FFC-SSC Sp800-56Ar3: (A4308) A4308: Hash DRBG: (A4308) A4308: CKG-2: ()
Symmetric Key GenerationCKGSP800-133r2 6.2 "Derivation of Symmetric Keys"AES-CBC: (A4308) A4308: AES-CCM: (A4308) A4308: AES-CMAC: (A4308) A4308: AES-CTR: (A4308) A4308: AES-ECB: (A4308) A4308: AES-GCM: (A4308) A4308: AES-GMAC: (A4308) A4308: AES-OFB: (A4308) A4308: HMAC-SHA-1: (A4308) A4308: HMAC-SHA2- 224: (A4308) A4308: HMAC-SHA2- 256: (A4308)

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 17
NameTypeDescriptionPropertiesAlgorithms
A4308: HMAC-SHA2- 384: (A4308) A4308: HMAC-SHA2- 512: (A4308) A4308: HMAC-SHA3- 224: (A4308) A4308: HMAC-SHA3- 256: (A4308) A4308: HMAC-SHA3- 384: (A4308) A4308: HMAC-SHA3- 512: (A4308) A4308: Hash DRBG: (A4308) A4308: CKG-3: ()
RSA Asymmetric Key-Pair GenerationAsymKeyPair- KeyGenGenerate an RSA Asymmetric Key PairRSA KeyGen (FIPS186-4): (A4308) A4308: Hash DRBG: (A4308) A4308:
DSA Asymmetric Key-Pair GenerationAsymKeyPair- KeyGen AsymKeyPair- PubKeyVal AsymKeyPair- DomParGenerate a DSA Asymmetric Key Pair, Validate a Public DSA Key and KAS-FFC- SSC Domain Parameter Generation (SP800-56Ar3)KAS-FFC-SSC Sp800-56Ar3: (A4308) A4308: DSA KeyGen (FIPS186-4): (A4308) A4308: Hash DRBG: (A4308) A4308:
ECC Asymmetric Key-Pair GenerationAsymKeyPair- KeyVer AsymKeyPair- KeyGen AsymKeyPair- DomParGenerate an ECC Asymmetric Key Pair, ECC KeyVer and KAS-ECC-SSC Domain ParameterKAS-ECC-SSC Sp800-56Ar3: (A4308) A4308: ECDSA KeyGen (FIPS186-4): (A4308) A4308:

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 18
NameTypeDescriptionPropertiesAlgorithms
Generation (SP800-56Ar3)Hash DRBG: (A4308) A4308:
Digital Signature GenerationDigSig-SigGenDigital Signature GenerationRSA SigGen (FIPS186-4): (A4308) A4308: ECDSA SigGen (FIPS186-4): (A4308) A4308: SHA2-224: (A4308) A4308: SHA2-256: (A4308) A4308: SHA2-384: (A4308) A4308: SHA2-512: (A4308) A4308: SHA3-224: (A4308) A4308: SHA3-256: (A4308) A4308: SHA3-384: (A4308) A4308: SHA3-512: (A4308) A4308: Hash DRBG: (A4308) A4308:
Digital Signature VerificationDigSig-SigVerDigital Signature VerificationDigSig- SigVer:1024 (verification only) DigSig- SigVer:SHA-1 (verification only) DigSig- SigVer:P-192 (Signature andRSA SigVer (FIPS186-4): (A4308) A4308: ECDSA SigVer (FIPS186-4): (A4308) A4308: ECDSA KeyVer (FIPS186-4): (A4308)

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 19
NameTypeDescriptionPropertiesAlgorithms
Key Verification only)A4308: SHA-1: (A4308) A4308: SHA2-224: (A4308) A4308: SHA2-256: (A4308) A4308: SHA2-384: (A4308) A4308: SHA2-512: (A4308) A4308: SHA3-224: (A4308) A4308: SHA3-256: (A4308) A4308: SHA3-384: (A4308) A4308: SHA3-512: (A4308) A4308:
Auth Block CipherBC-AuthAuthenticated Block CiphersAES-GMAC: (A4308) A4308: AES-GCM: (A4308) A4308: AES-CMAC: (A4308) A4308: AES-CCM: (A4308) A4308:
UnAuth Block CipherBC-UnAuthUnauthenticated Block CiphersAES-CBC: (A4308) A4308: AES-ECB: (A4308) A4308: AES-OFB: (A4308) A4308: AES-CTR:

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 20
NameTypeDescriptionPropertiesAlgorithms
(A4308) A4308:

Table 10: Security Function Implementations

2.7 Algorithm Specific Information

The conditions for using the Module in the Approved mode of operation are:

  1. The Module is a cryptographic library and it is intended to be used with a calling application. The calling application is responsible for the usage of the primitives in the correct sequence including the IVs and sessions.
  2. The keys used by the Module for cryptographic purposes are determined by the calling application. The calling application is required to provide keys in accordance with [140Drev2].
  3. With the Module installed and configured in accordance with [UG] instructions, only the algorithms listed in the table in Section 2.5 are available. The module is in the Approved mode if the following conditions for algorithm use are met. NOTE: All conditions and restrictions below are met when the executable binary is built in accordance with the UG instructions. Applications that would be at risk of violating any restriction in this section will fail to build and link successfully against the compliant module binary executable. a. Adherence to [140-3 IG] C.H Key/IV Pair Uniqueness Requirements from SP 800-38D. The Module supports both internal IV generation (for use with the [56Arev3] compliant KAS API entry points) and external IV generation (for TLS KAS usage). For internal IV generation, the Module complies with C.H 2, users MUST specify an IV length of GCM_NONCE_MID_SZ or greater for internal IV generation otherwise specifying any length less than 96-bits is rejected by the module. For internal IV generation, C.H requires the calling application to use the modules internal approved DRBG to generate the random IV For external IV generation, the Module complies with C.H 1 (a), tested per option (ii) under C.H TLS protocol IV generation. The module performs a check for nonce_explicit rollover, returning an error if that condition is encountered. b. ECDSA and RSA signature generation must be used with a SHA-2 or SHA-3 hash function. c. RSA signature generation and encryption primitives must use RSA keys with k = 2048,
3072 or 4096 bits or greater.

d. The calling process shall adhere to all current [131Arev2] algorithm usage restrictions.

  1. Manual key entry is not supported.
  2. Data output is inhibited during self-tests, zeroization, and error states.
  3. RSA Decrypt Primitive (RSADP) with k=2048-bit is the only CAVP testable aspect of [56Brev2]. The module implements the RSA primitive operations only, there are no claims of key transport. The module implements ‘RSA Encrypt Primitive’ (RSAEP) and RSADP. The vendor affirms conformance to [56Brev2] for RSAEP and RSADP with other key sizes since no CAVP test is available for key sizes other than 2048-bit.
2.8 RBG and Entropy

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 21
Physical PortLogical Interface(s)Data That Passes
N/A: Internal (call stack)Control InputAPI entry point: stack frame including non-sensitive parameters
N/A: Internal (call stack)Control OutputAPI call parameters passed by reference for structures allocated by wolfCrypt
N/A: Internal (call stack)Data InputAPI call parameters passed by reference or value for cryptographic service input
N/A: Internal (call stack)Data OutputAPI call parameters passed by reference for cryptographic service output
N/A: Internal (call stack)Status OutputAPI return value: enumerated status resulting from call execution

N/A for this module. N/A for this module.

2.9 Key Generation
2.10 Key Establishment
2.11 Industry Protocols

The Module conforms to [140-3 IG] D.C References to the Support of Industry Protocols: while the module provides [56A] conformant schemes and API entry points oriented to TLS and SSH usage, the Module does not contain the full implementation of TLS or SSH. The following statements are required per IG D.C case #2: No parts of the TLS protocol other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP. No parts of the SSH protocol other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP.

2.12 Additional Information

The Module design corresponds to the Module security rules. Security rules enforced by the Module are described in the appropriate context of this document.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 22
NameTypeOperator TypeAuthentication Methods
CORoleCO
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Digital SignatureGenerate or verify digital signatures.Successf ul completi on of the service (status code >= 0)Sign: Key Struct (DS_SGK); message; Verify: signature value; flags; sizes.Sign: Status return; Signature value. Verify: Status return;Digital Signature Generation Digital Signature VerificationCO - DS_SGK: W,E,Z - DS_SVK: W,E,Z
Generate Key PairGenerate asymmetric key pairs.Successf ul completi on of the service (status code >= 0)FFC, ECC: curve identifier; RSA: modulous size;Status return; Key structure (GKP_Privat e)ECC Asymmetric Key-Pair Generation DSA Asymmetric Key-Pair Generation RSA Asymmetric Key-Pair Generation 133r2 5.2CO - GKP_Privat e: G,R,Z - GKP_Publi c: G,R,Z

Table 7 defines the Module’s [140-3] logical interfaces; the Module does not interact with physical ports.

4 Roles, Services, and Authentication
4.2 Roles

Table 12: Roles The Module supports the Cryptographic Officer (CO) operator role, and does not support multiple concurrent operators, a maintenance role or bypass capability. The cryptographic module does not provide an authentication or identification method of its own. The CO role is implicitly identified by the service requested.

4.3 Approved Services

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 23
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Asymmetric Key Generation 133r2 5.1 Asymmetric Key Generation
Key Agreeme ntDH key agreement primitives.Successf ul completi on of the service (status code >= 0)Key structures (KAS_Priva te and KAS_Publi c); flags;Status return; KAS_SSC;Primitive Key AgreementCO - KAS_Privat e: W,E,Z - KAS_Public : W,E,Z - KAS_SSC: G,R,Z
Key Derivatio nDerive keying material from a shared secretSuccessf ul completi on of the service (status code >= 0)KAS_SSC; flags;Status return; KD_DKM;TLS 1.3 Key Agreement KDF Derived Key Agreement KAS SSC Derived Key AgreementCO - KAS_SSC: R,E,Z
Keyed HashGenerate or verify message integritySuccessf ul completi on of the service (status code >= 0)KH_KeyStatus return; Tag value;Message Authenticati on Auth Block CipherCO - KH_Key: W,E
Message DigestGenerate a message digestSuccessf ul completi on of the service (status code >= 0)Message; flags;Status return; Hash value;Secure HashCO
RandomGenerate random bits using the DRBGSuccessf ul completi on of the service (statusDRBG structure (Internal State containing secret(s) CStatus return; Random Value;DRBGCO - Seed: W,E,Z - Internal State: G,E - Secret C: G,E
  1. G,R,Z 0)
  2. G,E © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).
Page 24
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
code >= 0)and V); Seed- Secret V: G,E - Entropy Input String: W,E,Z
Self-testPerform the designated self-test.Successf ul completi on of the service (status code >= 0)FlagsStatus returnMessage Authenticati onCO - MOD_INT: G,Z - coreKey: E
Show StatusProvide Module statusSuccessf ul completi on of the service (status code >= 0)NoneStatus returnCO
Symmetri c cipherEncrypt or Decrypt data, including AEAD modes (CCM, GCM)Successf ul completi on of the service (status code >= 0)SC_EDK; flags;Status return. Plaintext or ciphertext data;Auth Block Cipher UnAuth Block Cipher Symmetric Key GenerationCO - SC_EDK: E,W
ZeroiseFreeRng_fi ps destroys RNG CSPs. All functions zeroise CSPs using function ForceZero (overwriting with zeros) within the function scope after use. Caller stack cleanup is the duty ofSuccessf ul completi on of the service (status code >= 0)DRBG struct (RBG State) or other structures containing SSPsStatus returnCO - DS_SGK: Z - GKP_Privat e: Z - KAS_Privat e: Z - KAS_SSC: Z - KD_DKM: Z - KH_Key: Z - Seed: Z - Internal

W,E,Z 0) 0) © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 25
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
the application. Restarting the general- purpose computer clears all CSPs in RAM.State: Z - Secret C: Z - Secret V: Z - SC_EDK: Z - Entropy Input String: Z
Show VersionProvide Module VersionSuccessf ul completi on of the service (status code >= 0)NonePlaintext containing the module versionCO
  1. Table 13: Approved Services All services implemented by the Module are listed in Table
  2. The calling application may use the Show status service (wolfCrypt_GetStatus_fips call) to determine the status of the Module. A return code of FIPS_MODE_NORMAL means the Module is in a state without errors; Please see Section 2.4 for more information. In addition, as per [140-3 IG] 2.4.C the module supports an implicit indicator via the successful completion of a service, module does not support nonapproved services. See the AVIAT NETWORKS FIPS 140-3 User Guide [UG] for additional information on the cryptographic services listed in this section. Note that the caller provides the KAS_Private and KAS_Public keys for shared secret computation; the caller’s exchange and assurance of PSPs with the remote participant is For services Generate Key Pair, Key Agreement and Key Derivation consistent with [140-3 IG] 9.5.A, available only if the private_key_read_enable property is set to TRUE
4.4 Non-Approved Services
5 Software/Firmware Security
5.1 Integrity Techniques

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 26

The Module uses HMAC-SHA2-256 with a 256-bit key (HMAC Cert. #A4308) as the approved integrity technique. Before the integrity technique is executed the module performs an HMACSHA2-256 KAT.

5.2 Initiate on Demand

The operator can initiate the integrity test on demand by reloading the Module or by calling the API wolfCrypt_IntegrityTest_fips() at any time after power on. (See Section 10.5 “Operator Initiation of Self-Tests” later in this document for details of proper use of this API in an application).

5.3 Open-Source Parameters

While the module is not “open source” since it is only shipped under a commercial license, open source practice of source code delivery with a commercial license is standard for the module. As such the module (while not required to do so) will abide by ISO/IEC 19790:2012 B.2.5. Please see details in the AVIAT NETWORKS FIPS 140-3 User Guide [UG] for the [OE] listed on the FIPS certificate. Details will include information about compiler, compiler configuration settings and methods to compile the source code into an executable form in a FIPS validated manner. See also section 11.1 Installation, Initialization, and Startup Procedures later in this document.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable

6.2 Configuration Settings and Restrictions

Any setting that affects the module directly while compiling the executable binary shall not be used. If unsure contact AVIAT NETWORKS by sending email to “TACAM at aviatnet dot com”. An AVIAT engineer will review the setting for impact on the FIPS validated sources and determine if the setting is allowed or disallowed for an approved mode of operation. NOTE: The User Guide [UG] will contain an exact list of allowed settings. CO should refer to the [UG] first before contacting AVIAT support.

6.3 Additional Information

The operational environment for the Module is modifiable. Table 6 lists the operational environments on which the Module was tested. Specification of the security rules, settings or restrictions to the configuration of the operational environment are covered in the [UG]. The configure script provided with the package detects the environment and sets the required flags. © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 27
Storage Area NameDescriptionPersistence Type
S1RAM (Memory)Dynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
IE1EXT: Call stack (API) input parametersINTPlaintextAutomatedElectronic
IE2INT: Call stack (API) output parametersEXTPlaintextAutomatedElectronic
IE3EXT: Loaded from external entropy sourceINTPlaintextAutomatedElectronic

There are no specific restrictions to the configuration of the operational environment unless stated in the [UG].

7 Physical Security
7.1 Mechanisms and Actions Required
7.5 EFP/EFT Information
7.6 Hardness Testing Temperature Ranges
8 Non-Invasive Security

The Module does not implement non-invasive security mechanisms.

9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 15: SSP Input-Output Methods

9.3 SSP Zeroization Methods

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 28
Zeroization MethodDescriptionRationaleOperator Initiation
Z1cleared immediately after useModule does not store SSPs persistentlyZeroise
Z2Per ISO/IEC 19790:2012 section 7.9.7, parameters used solely for self-test purposes in 7.10 need not meet zeroisation requirementsFIPS 140-3 IG 9.7.B
NameDescriptionSize - Strengt hType - CategoryGenerated ByEstablishe d ByUsed By
DS_SGKDigital Signature: Signature Generation using Private KeyRSA: 2048, 3072, 4096; ECDSA: 224, 256, 384, 521; - RSA: 112, 128; ECDSA: 112, 128, 192, 256;Private - CSPRSA SigGen (FIPS18 6-4) ECDSA SigGen (FIPS18 6-4)
DS_SVKDigital Signature Verification using Public KeyRSA: 1024*, 2048, 3072, 4096; ECDSA: 192*, 224, 256, 384, 521; - RSA:Public - PSPRSA SigVer (FIPS18 6-4) ECDSA SigVer (FIPS18 6-4)

Table 16: SSP Zeroization Methods The module supports an implicit Zeroisation indicator. The implicit indicator is a successful completion of the service call. h © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 29
NameDescriptionSize - Strengt hType - CategoryGenerated ByEstablishe d ByUsed By
80*, 112, 128; ECDSA: 80*, 112, 128, 192, 256;
GKP_Privat eGenerated Key Pair (Private)RSA: 2048, 3072, 4096; ECDSA: 224, 256, 384, 521; - RSA: 112, 128; ECDSA: 112, 128, 192, 256;Private - CSPRSA Asymmetric Key-Pair Generation ECC Asymmetric Key-Pair GenerationRSA KeyGen (FIPS18 6-4) ECDSA KeyGen (FIPS18 6-4)
GKP_Publi cGenerated Key Pair (Public)RSA: 2048, 3072, 4096; ECDSA: 224, 256, 384, 521; - RSA: 112, 128; ECDSA: 112, 128, 192, 256;Public - PSPRSA Asymmetric Key-Pair Generation ECC Asymmetric Key-Pair GenerationRSA KeyGen (FIPS18 6-4) ECDSA KeyGen (FIPS18 6-4)
KAS_Privat eKey pair component provided by the localFFC: 2048; ECC: 224,Private - CSPECC Asymmetric Key-Pair GenerationKAS- FFC- SSC Sp800-

h © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 30
NameDescriptionSize - Strengt hType - CategoryGenerated ByEstablishe d ByUsed By
participant, used for Diffie- Hellman shared secret generation.256, 384, 521; - FFC: 112; ECC: 112, 128, 192, 256;DSA Asymmetric Key-Pair Generation Primitive Key Agreement56Ar3 KAS- ECC- SSC Sp800- 56Ar3
KAS_Publi cKey pair component provided by the local participant, used for Diffie- Hellman shared secret generation.FFC: 2048; ECC: 224, 256, 384, 521; - FFC: 112; ECC: 112, 128, 192, 256;Public - PSPECC Asymmetric Key-Pair Generation DSA Asymmetric Key-Pair Generation Primitive Key AgreementKAS- ECC- SSC Sp800- 56Ar3 KAS- FFC- SSC Sp800- 56Ar3
KAS_SSCShared secret calculation; z output value is expected to be used by a KDFFFC: 2048; ECC: 224, 256, 384, 521; - FFC: 112; ECC: 112, 128, 192, 256;Shared Secret - CSPECC Asymmetri c Key-Pair Generation DSA Asymmetri c Key-Pair Generation KAS SSC Derived Key AgreementKAS- FFC- SSC Sp800- 56Ar3 KAS- ECC- SSC Sp800- 56Ar3 KDF TLS KDF SSH
KD_DKMKey Derivation derived keying materialTLS KDF v1.2 RFC 7627: 1024; TLS KDF v1.3:Derived Key Material - CSPTLS 1.3 Key Agreement KDF Derived Key AgreementTLS v1.2 KDF RFC762 7 TLS v1.3 KDF KDF SSH

h © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 31
NameDescriptionSize - Strengt hType - CategoryGenerated ByEstablishe d ByUsed By
256, 384; KDF SSH: 256, 384, 512 - 256-bit
KH_KeyKeyed Hash keyCMAC: 128, 192, 256; GMAC: 128, 192, 256; HMAC: 160, 256, 512; - CMAC: 128, 192, 256; GMAC: 128, 192, 256; HMAC: 128, 256;Symmetric Key - CSPAES- CMAC AES- GMAC HMAC- SHA3- 512 HMAC- SHA3- 384 HMAC- SHA3- 256 HMAC- SHA3- 224 HMAC- SHA2- 512 HMAC- SHA2- 384 HMAC- SHA2- 256 HMAC- SHA2- 224 HMAC- SHA-1
Entropy Input StringEntropy input bit string loaded from the external entropy source256-bit - 256-bitEntropy - CSPHash DRBG
SeedDRBG Seed_materi384-bit - 256-bitEntropy - CSPDRBGHash DRBG

h © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 32
NameDescription al consisting of entropy input string (256-bit) concatenate d with the nonce (128- bit)Size - Strengt hType - CategoryGenerated ByEstablishe d ByUsed By
Secret CHash DRBG Internal State Secret C440-bits - 256-bitEntropy - CSPDRBGHash DRBG
Secret VHash DRBG Internal State Secret V440-bits - 256-bitEntropy - CSPDRBGHash DRBG
Internal StateHash DRBG Internal State (SHA- 256) with secret values V and C. V is 440- bits, C is 440-bits.880-bit - 256-bitEntropy - CSPDRBGHash DRBG
SC_EDKAES key used for symmetric encryption (including AES authenticate d encryption). Modes: CBC, CCM, CTR, ECB, GCM, OFB128, 192 or 256 bits - 128, 192 or 256 bitsSymmetric Key - CSPAES- CBC AES- CCM AES- CTR AES- ECB AES- GCM AES- OFB
MOD_INTModule Integrity Value Computed at Run Time32- bytes - 256-bitMessage Authenticati on - CSPMessage Authenticati onHMAC- SHA2- 256
coreKeyHMAC key for in-core integrity32- bytes - 256-bitMessage Authenticati on - CSPHMAC- SHA2- 256

h C V © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 33

Name

Description check self- test

Size - Strengt h

Type - Category

Generated By

Establishe d By

Used By

NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
DS_SGKIE1S1:PlaintextWhile in useZ1
DS_SVKIE1S1:PlaintextWhile in useZ1
GKP_PrivateIE2S1:PlaintextWhile in useZ1GKP_Public:Paired With
GKP_PublicIE2S1:PlaintextWhile in useZ1GKP_Private:Paired With
KAS_PrivateIE1S1:PlaintextWhile in useZ1
KAS_PublicIE2S1:PlaintextWhile in useZ1
KAS_SSCS1:PlaintextWhile in useZ1KAS_Public:Derived From KAS_Private:Derived From
KD_DKMS1:PlaintextWhile in useZ1
KH_KeyIE1S1:PlaintextWhile in useZ1
Entropy Input StringIE3S1:PlaintextWhile in useZ1
SeedS1:PlaintextWhile in useZ1
Secret CS1:PlaintextWhile in useZ1Seed:Derived From
Secret VS1:PlaintextWhile in useZ1Seed:Derived From
Internal StateS1:PlaintextWhile in useZ1
SC_EDKIE1S1:PlaintextWhile in useZ1
MOD_INTS1:PlaintextWhile in useZ1
coreKeyS1:PlaintextWhile in useZ2

h Table 17: SSP Table 1 Table 18: SSP Table 2 © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 34
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-256hash type: SHA256, key length: 32-bytes. Please note this is the module integrity testKATSW/FW IntegrityFIPS_MODE_NORMAL or FIPS_MODE_FAILEDMAC
Algorit hm or TestTest PropertiesTest Meth odTest Typ eIndicatorDetailsConditio ns
AES- CBCkey length: 32-bytesKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREEncryptBefore first use of algorithm( s) AES- ECB, AES- CBC, AES- CTR, AES- OFB, AES- GCM, AES-

* Per SP800-131Ar2 Section 3, Table 2, key sizes (1024-bit for RSA and 192-bit for ECC) are available for legacy use verification requirements when inter-oping with legacy systems. These key sizes shall not be used for signing operations.

10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 19: Pre-Operational Self-Tests Each time the Module is powered on or loaded (equivalent to a power on) the integrity of the module is tested per ISO/IEC 19790:2012 Section 7.10.2.2. The very first step of the preoperational self-test (POST) is to force every Conditional Algorithm Self-Test to be in the FIPS_CAST_STATE_INIT mode meaning the CAST for a given algorithm has not run since power on and the CAST must run and pass prior to operational use of the algorithm. The integrity test uses HMAC-SHA2-256 to ensure the modules integrity therefore per AS 10.20 HMAC CAST is triggered prior to the integrity check. The HMAC CAST uses a known answer test per ISO/IEC 19790-2012 Section 7.10.3.2. The POST executes outside user control as the module is powering on or being loaded.

10.2 Conditional Self-Tests

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 35
Algorit hm or TestTest PropertiesTest Meth odTest Typ eIndicatorDetailsConditio ns GMAC, AES- CCM or AES- CMAC
AES- CBCkey length: 32-bytesKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREDecryptBefore first use of algorithm( s) AES- ECB, AES- CBC, AES- CTR, AES- OFB, AES- GCM, AES- GMAC, AES- CCM or AES- CMAC
AES- GCMkey length: 32-bytesKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREDecryptBefore first use of algorithm( s) AES- GCM or AES- GMAC
AES- GCMkey length: 32-bytesKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREEncryptBefore first use of algorithm( s) AES- GCM or AES- GMAC
HMAC- SHA1hash type: SHA1; key length: 20- bytesKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREMACBefore first use of algorithm( s) SHA1

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 36
Algorit hm or TestTest PropertiesTest Meth odTest Typ eIndicatorDetailsConditio ns or HMAC- SHA1
HMAC- SHA2- 256hash type: SHA256; key length: 20-bytesKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREMACBefore first use of algorithm( s) SHA224, SHA256, HMAC- SHA224 or HMAC- SHA256
HMAC- SHA2- 512hash type: SHA2-512, key length: 20-bytesKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREMACBefore first use of algorithm( s) SHA384, SHA512, HMAC- SHA384 or HMAC- SHA512
HMAC- SHA3- 256hash type: SHA3-256, key length: 64-bytesKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREMACBefore first use of algorithm( s) SHA3- 224, SHA3- 256, SHA3- 384 or SHA3- 512, HMAC- SHA3- 224, HMAC- SHA3- 256, HMAC- SHA3- 384 or HMAC-

s) s) © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 37
Algorit hm or TestTest PropertiesTest Meth odTest Typ eIndicatorDetailsConditio ns SHA3- 512
RSA- PKCSv 1.5hash type: SHA256; key length: 2048-bitsKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LURESignBefore first use of algorithm( s) RSA (PKCSv1. 5) or RSA (PSS)
RSA- PKCSv 1.5hash type: SHA256, key length: 2048-bitsKATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREVerifyBefore first use of algorithm( s) RSA (PKCSv1. 5) or RSA (PSS)
ECC Diffie- HellmanhashType: SHA2-256; curve: P-256KATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREComputatio n Shared Secret ZBefore first use of algorithm( s) ECC for shared secret generatio n
FFC Diffie- HellmanhashType: SHA2-256; keySize: 2048-bit;KATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREComputatio n Shared Secret ZBefore first use of algorithm( s) FFC for shared secret generatio n
ECDSAcurve: P256; hashType: SHA2-256KATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LURESignBefore first use of algorithm( s) ECDSA
ECDSAcurve: P256; hashType: SHA2-256KATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREVerifyBefore first use of algorithm( s) ECDSA

n n © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 38
Algorit hm or TestTest PropertiesTest Meth odTest Typ eIndicatorDetailsConditio ns
TLSv1. 2 KDFHMAC- SHA2-256KATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREDerive Keying MaterialBefore first use of TLSv1.2 KDF
TLSv1. 3 KDFHMAC- SHA2-256KATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREDerive Keying MaterialBefore first use of TLSv1.3 KDF
KDF SSHhashType: SHA2-256KATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREDerive Keying MaterialBefore first use of KDF SSH
RSA- PCTkey size: 2048,3072,4 096PCTPCTService is successful or an error code RSA_KEY_PAIR_ESign/VerifyInvoked automatic ally during generate key pair service
ECC- PCTcurve size: 224, 256, 384, 521PCTPCTService is successful or an error code ECC_PCT_ESign/VerifyInvoked automatic ally during generate key pair service
DH- PCTkey size: 2048, 3072, 4096PCTPCTService is successful or an error code MP_CMP_EModulus Exponentia tionInvoked automatic ally during generate key pair service
DRBGDRBG mode: SHA2-256KATCAS TFIPS_CAST_STATE_SU CCESS or FIPS_CAST_STATE_FAI LUREHealth-Test with sub- elements: Instantiate, Generate, ReseedBefore first use of algorithm( s) DBRG or Immediat ely upon registerin g an external entropy source

© 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 39

Algorit hm or Test

Test Properties

Test Meth od

Test Typ e

Indicator

Details

Conditio ns with the module

Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 256KATSW/FW IntegrityP2Automatic or Manually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBCKATCASTP1Manually
AES-CBCKATCASTP1Manually
AES-GCMKATCASTP1Manually
AES-GCMKATCASTP1Manually
HMAC-SHA1KATCASTP1Manually
HMAC-SHA2- 256KATCASTP2Automatic or Manually
HMAC-SHA2- 512KATCASTP1Manually
HMAC-SHA3- 256KATCASTP1Manually
RSA-PKCSv1.5KATCASTP1Manually
RSA-PKCSv1.5KATCASTP1Manually
ECC Diffie- HellmanKATCASTP1Manually
FFC Diffie- HellmanKATCASTP1Manually
ECDSAKATCASTP1Manually
ECDSAKATCASTP1Manually
TLSv1.2 KDFKATCASTP1Manually
TLSv1.3 KDFKATCASTP1Manually

Table 20: Conditional Self-Tests Once the module is powered on and has passed the POST, calls to any cryptographic algorithm will trigger the CAST on first operational use of the algorithm. The POST and CASTS are available on demand after power on and can be executed by the cryptographic officer (CO) at any time. The CO may optionally invoke any CAST ahead of algorithm use at a more convenient time rather than letting it run automatically on first use. Regardless of the CAST running manually or automatically, once it has passed the CO may manually re-run any CAST at any time in a periodic fashion, a CAST will no longer run automatically after it has passed the first time.

10.3 Periodic Self-Test Information

Table 21: Pre-Operational Periodic Information © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 40
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KDF SSHKATCASTP1Manually
RSA-PCTPCTPCTP3Automatic
ECC-PCTPCTPCTP3Automatic
DH-PCTPCTPCTP3Automatic
DRBGKATCASTP4Automatic or Manually
NameDescription
P1Periodic method 1: Automatically by the module when algorithm is first invoked. CO may opt to invoke prior to first algorithm use to avoid delay at time of first operational use of an algorithm or at a later time manually.
P2Periodic method 2: Automatically by the module during power on. CO may opt to invoke manually thereafter.
P3Periodic method 3: Automatically during key generation service
P4Automatically by the module upon first operational use of the DRBG algorithm. When an external entropy source is registered with the module by application level entropy callback function it is considered the first operational use of the DRBG. Does a periodic reseed every 1 million invocations, during the reseed the DRBG health test will be automatically executed.
NameDescriptionConditi onsRecov ery Metho dIndicator
FIPS_MODE_FAILEDModule has failed its software integrity checkHMAC- SHA2- 256 CAST Failure Module Integrity Check FailurePower CyclefipsModeId set to FIPS_MODE_FAILED (3)
FIPS_CAST_STATE_F AILUREOne or more algorithm(s) are no longer usable and the module mode isAES- CBC AES- GCMPower CycleOne or more algorithms CAST status values set to

Table 22: Conditional Periodic Information Table 23: Periodic Method Descriptions

10.4 Error States

d © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 41
NameDescription set to FIPS_MODE_DEG RADED (2)Conditi ons HMAC- SHA1 HMAC- SHA2- 256 HMAC- SHA2- 512 HMAC- SHA3- 256 RSA- PKCSv1 .5 DRBG ECC Diffie- Hellman FFC Diffie- Hellman ECDSA TLSv1.2 KDF TLSv1.3 KDF KDF SSHRecov ery Metho dIndicator FIPS_CAST_STATE_F AILURE (3)
FIPS_MODE_DEGRA DEDOne or more of the CASTS have failed anytime following a successful power on and integrity check. Upon entering this mode the module will automatically run all CASTS prior to the operational use of any cryptographic algorithm.Any CAST FailurePower CyclefipsModeId set to FIPS_MODE_DEGRA DED (2)
RSA_KEY_PAIR_ERSA Pairwise Consistency Test FailureRSA- PCTManual self- test service call orRSA_KEY_PAIR_E (- 262)

d .5 © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).

Page 42
NameDescriptionConditi onsRecov ery Metho dIndicator
power cycle
ECC_PCT_EECC Pairwise Consistency Test FailureECC- PCTManual self- test service call or power cycleECC_PCT_E (-286)
MP_CMP_EDH Pairwise Consistency Test FailureDH-PCTManual self- test service call or power cycleMP_CMP_E (-120)
10.5 Operator Initiation of Self-Tests

For calling applications the following is required:

  1. Include the library configuration header wolfssl/options.h (or user_settings.h via wolfssl/wolfcrypt/settings.h) first.
  2. After including the library configuration header, include wolfssl/wolfcrypt/fips_test.h then use the API specified below to execute a given self-test. CO may initiate all CAST self-tests in one-shot. The API wc_RunAllCast_fips() is provided as a public API to applications using the module that have included the headers above in proper order. CO may initiate CAST self-tests individually using the API wc_RunCast_fips(algorithm type) with any of the below “algorithm type” inputs: • FIPS_CAST_AES_CBC • FIPS_CAST_AES_GCM • FIPS_CAST_HMAC_SHA1 • FIPS_CAST_HMAC_SHA2_256 • FIPS_CAST_HMAC_SHA2_512 • FIPS_CAST_HMAC_SHA3_256 • FIPS_CAST_DRBG • FIPS_CAST_RSA_SIGN_PKCS1v15 • FIPS_CAST_ECC_CDH • FIPS_CAST_ECC_PRIMITIVE_Z • FIPS_CAST_DH_PRIMITIVE_Z © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).
Page 43

• FIPS_CAST_ECDSA • FIPS_CAST_KDF_TLS12 • FIPS_CAST_KDF_TLS13 • FIPS_CAST_KDF_SSH CO may re-run the POST at any time after power on using the public API wolfCrypt_IntegrityTest_fips(). This function always returns a value of zero regardless if the integrity check passed or failed so the CO shall then check the status of the module using the API wolfCrypt_GetStatus_fips(). The return value of the GetStatus API shall then be checked against the status indicators below: • FIPS_MODE_INIT status indicator value is

  1. This indicator means then integrity test has not completed and is likely running in another thread (multi-threaded) • FIPS_MODE_NORMAL status indicator value is
  2. This indicator means the integrity test passed and the module is in a state without errors • FIPS_MODE_FAILED status indicator value is
  3. This indicator means the integrity test failed and the module is unusable. The CO shall power cycle or reloaded (equivalent to power cycle) to restore the module.
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The CO shall use the provided AVIAT NETWORKS FIPS 140-3 User Guide hereafter referred to as [UG]. A common name for this document is also the Cryptographic Officer Guidance Manual [COGM]. [UG] and [COGM] are one and the same for this module and include all administrative guidance. The [UG] will have a section specific to each Operational Environment [OE] that appears on the modules FIPS certificate and/or in Table 6: Tested Operational Environments - Software, Firmware, Hybrid. The instructions provided in the [UG] shall be followed or the module will never have been properly initialized and built and therefore noncompliant. To create the compliant module, as per this Security Policy, the configuration steps shall be followed.

Page 44

static void myFipsCb(int ok, int err, const char* hash)

printf("in my Fips callback, ok = %d, err = %d\n", ok, err);

printf("message = %s\n", wc_GetErrorString(err));

printf("hash = %s\n", hash);

if (err == IN_CORE_FIPS_E) {

printf("In core integrity hash check failure,"

"copy above hash\n");

printf("into verifyCore[] in fips_test.c and rebuild\n");

code into an executable format” even though the module is not claiming “open source”. The following initialization instructions apply to all use-cases for the module generically by a consuming application. [OE] specific details will be covered in the [UG].

Page 45
11.2 Administrator Guidance

The CO shall use the provided AVIAT NETWORKS FIPS 140-3 User Guide [UG].

11.3 Non-Administrator Guidance

The Module supports the Cryptographic Officer (CO) operator role and does not support nonadministrators or non-administrative roles.

11.7 Additional Information

Please defer to AVIAT NETWORKS FIPS 140-3 User Guide [UG].

12 Mitigation of Other Attacks

The module does not claim mitigation of other attacks. © 2025 AVIAT NETWORKS AVIAT NETWORKS Public Material – May be reproduced only in its original entirety (without revision).