| Standard | FIPS 140-3 |
|---|---|
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 6/23/2030 |
| Caveat | None |
| Vendor | DataLocker, Inc. |
| Algorithm | ACVP Cert |
|---|---|
| AES-CBC | A3268 |
| AES-ECB | A3268 |
| AES-KW | A3268 |
| AES-XTS Testing Revision 2.0 | A3268 |
| ECDSA KeyGen (FIPS186-5) | A3268 |
| ECDSA KeyVer (FIPS186-4) | A3268 |
| HMAC DRBG | A3268 |
| HMAC-SHA2-256 | A3268 |
| KAS-ECC-SSC Sp800-56Ar3 | A3268 |
| KDA TwoStep SP800-56Cr2 | A3268 |
| PBKDF | A3268 |
| RSA SigVer (FIPS186-4) | A3268 |
| SHA2-256 | A3268 |
flowchart LR
%% Deterministic review-risk graph for Sentry 5 Encrypted USB Flash Drive
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>Self-test</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for Sentry 5 Encrypted USB Flash Drive
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>Self-test</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;DataLocker, Inc. Sentry 5 Encrypted USB Flash Drive Document Version 1.0 This document may be freely reproduced and distributed, but only in its entirety and without modification.
| # | Section | Page |
|---|
This document may be freely reproduced and distributed, but only in its entirety and without modification.
This document may be freely reproduced and distributed, but only in its entirety and without modification.
TABLE OF TABLES This document may be freely reproduced and distributed, but only in its entirety and without modification.
| ISO/IEC 24759 | FIPS140-3SectionTitle | Security Level |
|---|---|---|
| 1 | General | 3 |
| 2 | CryptographicModuleSpecification | 3 |
| 3 | CryptographicModuleInterfaces | 3 |
| 4 | Roles,Services,andAuthentication | 3 |
| 5 | Software/FirmwareSecurity | 3 |
| 6 | OperationalEnvironment | N/A |
| 7 | PhysicalSecurity | 3 |
| 8 | Non-InvasiveSecurity | N/A |
| 9 | SensitiveSecurityParameterManagement | 3 |
| 10 | Self-Tests | 3 |
| 11 | Life-CycleAssurance | 3 |
| 12 | MitigationofOtherAttacks | N/A |
| OverallLevel: | 3 |
The DataLocker, Inc. (DataLocker) Sentry 5 Encrypted USB Flash Drive is a hardware cryptographic module designed to meet the overall requirements of FIPS 140-3 Security Level 3.
Table 1 – Security Levels ISO/IEC FIPS 140-3 Section Title Security 2 Cryptographic Module Specification 3 3 Cryptographic Module Interfaces 3 4 Roles, Services, and Authentication 3 6 Operational Environment N/A 7 Physical Security 3 9 Sensitive Security Parameter Management 3 11 Life-Cycle Assurance 3 12 Mitigation of Other Attacks N/A
Overall Level: 3 2. CRYPTOGRAPHIC MODULE SPECIFICATION
The DataLocker Sentry 5 Encrypted USB Flash Drive (refer to Figure 1) is a hardware cryptographic module designed for organizations that require a secure way to store and transfer portable data. The stored data is secured by hardware-based 256-bit AES on-the-fly encryption to guard sensitive information in case the drive is lost or stolen. Its strong, durable, metal casing provides robust physical protection. Its strong password rules and lock-down control protect against brute force attacks. Such advanced security features make the Sentry 5 Encrypted USB Flash Drive ideal for corporations and service organizations that require employees to transport large digital files consisting of confidential documents. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Model/Part Number(s) | HardwareVersion(s) | Firmware Version(s) | Processor(s) | Non-SecurityRelevant DistinguishingFeatures | |
|---|---|---|---|---|---|
| Sentry5 EncryptedUSB FlashDrive | Sentry5 EncryptedUSB | S5-008-FE-M | 3.06 | PS2251-15USBAES Micro-Controller | 8GBofuserdatastorage |
| FlashDrive | S5-016-FE-M | 16GBofuserdatastorage | |||
| S5-032-FE-M | 32GBofuserdatastorage | ||||
| S5-064-FE-M | 64GBofuserdatastorage |
The module is a multi-chip standalone cryptographic module whose outer enclosure defines the cryptographic boundary and Tested Operational Environment’s Physical Perimeter (TOEPP) (refer to Figure 1). Figure 1 – Cryptographic Boundary
2.2 T ESTED AND V ENDOR A FFIRMED M ODULE V ERSION AND I DENTIFICATION
The Sentry 5 Encrypted USB Flash Drive is a FIPS 140-3 Security Level 3 (refer to Table 1) multi-chip standalone cryptographic module (module) available in the following configurations: x = 008, 016, 032, 064, 128, 256, or 512 (denotes module’s memory capacity in GB)
The module’s operating environment is defined as the non-modifiable, PS2251-15 USB AES MicroController. The FIPS 140-3 Security Level 3 validated versioning information is shown in Table 2. The hardware versions differ by memory capacity e.g., 16GB, 32GB, etc. Table 2 – Tested Module Identification - Hardware Number(s) Version(s) Distinguishing Features Sentry 5 S5-008-FE-M 3.06 PS2251-15 USB AES 8GB of user data storage Encrypted USB Micro-Controller S5-016-FE-M 16GB of user data storage Flash Drive S5-032-FE-M 32GB of user data storage S5-064-FE-M 64GB of user data storage This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Model/Part Number(s) | HardwareVersion(s) | Firmware Version(s) | Processor(s) | Non-SecurityRelevant DistinguishingFeatures | |
|---|---|---|---|---|---|
| S5-128-FE-M | 128GBofuserdatastorage | ||||
| S5-256-FE-M | 256GBofuserdatastorage | ||||
| S5-512-FE-M | 512GBofuserdatastorage |
Number(s) Version(s) Distinguishing Features S5-128-FE-M 128GB of user data storage S5-256-FE-M 256GB of user data storage S5-512-FE-M 512GB of user data storage
The module does not exclude any components from the requirements of FIPS 140-3.
The module supports a single approved mode of operation that is entered by powering-on the module. There are no non-approved modes, degraded modes or non-approved services available to the module. The module’s firmware provides an indicator (i.e., “FIPS ACTIVE”) showing the approved configuration which can be queried. This global indicator will be used along with the successful return codes of each service to indicate the module has provided an approved security service. If the module reports “FIPS DEFAULT”, the module is awaiting a new password (CO Password) to be set. The module is always running in an approved mode when module reports either “FIPS DEFAULT” or “FIPS ACTIVE”. The approved mode cannot be exited. The module does not support a non-approved or degraded mode of operation. In case of critical error, the module will remain in an error state, until reset. While in its error state, the LED will blink rapidly until it is reset. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| CAVP Cert(s) | Algorithm | Standards | Modes/Methods | Description/KeySizes, Curves,orModuli/Key Strengths | Use/Function | |
|---|---|---|---|---|---|---|
| A3268 | AES-CBC | FIPS197 NISTSP800-38A | CBC | KeyLength:256-bit Strength:256bits | KeyLength:256-bit | PrerequisiteforKW |
| Strength:256bits | Data Encryption/Decryption | |||||
| A3268 | AES-ECB | FIPS197 NISTSP800-38A | ECB | KeyLength:256-bit Strength:256bits | PrerequisiteforKW Data Encryption/Decryption | |
| A3268 | AES-KW | FIPS197 | KW | KeyLength:256-bit | DEK_COandDEK_U | |
| NISTSP800-38F | Strength:256bits | Encryption/Decryption | ||||
| A3268 | AES-XTS1 | FIPS197 NISTSP800-38E | XTS | KeyLength:256-bit Strength:256bits | Mass-StorageData Encryption/Decryption | |
| A3268 | ECDSA | FIPS186-5 | KeyGeneration | Curve:P-256 | KeyGenerationofKAS | |
| KeyGen | Strength:128bits | keys | ||||
| A3268 | ECDSA KeyVer | FIPS186-4 | KeyVerification | Curve:P-256 Strength:128bits | KeyVerificationofKAS keys | |
| A3268 | HMAC-SHA2- | FIPS198-1 | SHA2-256 | KeyLength:256-bit | PrerequisiteforKDA MessageAuthentication | |
| 256 | Strength:256bits | |||||
| A3268 | HMACDRBG | NISTSP800-90A | HMAC-SHA2-256 | Securitystrength: 256bits | DeterministicRandom BitGeneration | |
| A3268 | KAS-ECC-SSC | NISTSP800-56Ar3 | ECCCDH | Curve:P-256 | KeyAgreementShared Secretcalculation | |
| C(2e,0s) | Strength:128bits | |||||
| A3268 | KDA | NISTSP800-56Cr2 | Two-StepKDF (HMAC-SHA2-256) | DerivedKeyLength:256 bits SharedSecretLength:256 bits | Keyderivationaspartof KAS | |
| A3268 | PBKDF2 | NISTSP800-132 (option2A) | HMAC-SHA2-256 | Passwordlength:8to136 bytes(refertoSection4.1) SaltLength:256-bit | DerivingKEK_CO, KEK_U,KEK_R | |
| A3268 | RSASigVer (PKCS1v1.5) | FIPS186-4 | DigitalSignature Verification | Modulo:2048 Strength:128bits | DigitalSignature Verification |
The module supports the following approved cryptographic algorithms. Table 3 – Approved Algorithms A3268 AES-CBC FIPS 197 CBC Key Length: 256-bit Prerequisite for KW A3268 AES-ECB FIPS 197 ECB Key Length: 256-bit Prerequisite for KW A3268 HMAC-SHA2- FIPS 198-1 SHA2-256 Key Length: 256-bit Prerequisite for KDA A3268 HMAC DRBG NIST SP 800-90A HMAC-SHA2-256 Security strength: Deterministic Random A3268 KAS-ECC-SSC NIST SP 800-56Ar3 ECC CDH Curve: P-256 Key Agreement Shared C(2e, 0s) Strength: 128 bits Secret calculation A3268 KDA NIST SP 800-56Cr2 Two-Step KDF Derived Key Length: 256 Key derivation as part of Shared Secret Length: 256 A3268 PBKDF 2 NIST SP 800-132 HMAC-SHA2-256 Password length: 8 to 136 Deriving KEK_CO, (option 2A) bytes (refer to Section 4.1) KEK_U, KEK_R Salt Length: 256-bit A3268 RSA SigVer FIPS 186-4 Digital Signature Modulo: 2048 Digital Signature (PKCS1 v1.5) Verification Strength: 128 bits Verification
1 AES XTS was designed for the cryptographic protection of data on storage devices per NIST SP 800-38E. It
was not designed for other purposes, such as the encryption of data in transit.
2 The module implements PBKDF in conformance with NIST SP 800132 and FIPS IG D.N. Specifically, the
module implements Option 2a from Section 5.4 to generate the Key Encryption Key (KEK) responsible for protecting the Data Encryption Key using AES KW (Cert. #3268). The module implements an iteration counter equal to 1024 bits which is greater than the minimum recommendation documented within NIST SP 800-132 - Section 5.2. This is also justified by the maximum limit enforced on password retry attempts (Max = 10). This document may be freely reproduced and distributed, but only in its entirety and without modification.
| CAVP Cert(s) | Algorithm | Standards | Modes/Methods | Description/KeySizes, Curves,orModuli/Key Strengths | Use/Function | |
|---|---|---|---|---|---|---|
| A3268 | SHA2-256 | FIPS180-4 | SHA2-256 | Strength:128bits | PrerequisiteforHMAC MessageDigest |
| AlgorithmName | AlgorithmProperties | Implementation | Reference | |
|---|---|---|---|---|
| CKG | KeyType:Symmetric | CryptoLibraryFWv2.00 | NISTSP800-133r2Sections4 5.1and6.1 |
| AlgorithmName | AlgorithmProperties | Implementation | Reference |
|---|---|---|---|
| N/A | N/A | N/A | N/A |
| Algorithm | Caveat | Use/Function |
|---|---|---|
| N/A | N/A | N/A |
| Algorithm | Use/Function |
|---|---|
| N/A | N/A |
A3268 SHA2-256 FIPS 180-4 SHA2-256 Strength: 128 bits Prerequisite for HMAC Message Digest
The module supports the following vendor affirmed algorithms. Table 4 - Vendor Affirmed Algorithms CKG Key Type: Symmetric Crypto Library FW v2.00 NIST SP 800-133r2 Sections 4
The module does not support non-approved algorithms. Table 5 – Non-Approved, Allowed Algorithms N/A N/A N/A N/A
2.5.4 N ON -A PPROVED , A LLOWED A LGORITHMS WITH N O S ECURITY C LAIMED
The module does not support non-approved algorithms. Table 6 – Non-Approved, Allowed Algorithms with No Security Claimed N/A N/A N/A
The module does not support non-approved algorithms. Table 7 – Non-Approved, Not Allowed Algorithms N/A N/A This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Name | Type | Description | SFProperties | Algorithms/CAVPCert | ||
|---|---|---|---|---|---|---|
| KAS | KAS-Full | NISTSP800-56Arev3 perIGD.FScenario2 path(2) | NISTSP800-56Arev3 | Standards:NISTSP | KAS-ECC-SSC:(A3268) | |
| perIGD.FScenario2 | 800-56Arev3,NIST | KDA:(A3268) | ||||
| path(2) | SP800-56Crev2, | |||||
| FIPS186-4 | ECDSAKeyVer:(A3268) | |||||
| KTS | KTS-Unwrap | Keyunwrappingper | Standards:FIPS197, FIPS198-1,NISTSP 800-38A | Standards:FIPS197, | AES-CBC:(A3268) | |
| NISTSP800-38FPer | FIPS198-1,NISTSP | |||||
| IGD.G.Usedforthe entryoftheoperator’s password. | 800-38A | HMAC-SHA2-256:(A3268) |
| EntropySources | MinimumNumberof BitsofEntropy | Details | |
|---|---|---|---|
| KingstonTechnologyCompany,Inc. CryptoLibraryFWv2.00 ESVValidation#E55 | TheESVsourceoutputs 1024bitswitha minimumof256bitsof entropy | TheESVsourceoutputs | Basedontheheuristic |
| 1024bitswitha | lowerboundentropy | ||
| minimumof256bitsof | estimate,theentropy | ||
| entropy | sourcehasarateof1-bit pernibbleor25%.This meanstheentropyinput requiredfortheDRBGis 1024*0.25=256bits. |
Table 8 - Security Function Implementations (SFI) Name Type Description SF Properties Algorithms / CAVP Cert per IG D.F Scenario 2 800-56Arev3, NIST FIPS 186-4 ECDSA KeyVer: (A3268) KTS KTS-Unwrap Key unwrapping per Standards: FIPS 197, AES-CBC: (A3268) NIST SP 800-38F Per FIPS 198-1, NIST SP entry of the operator’s
The module utilizes only approved algorithms (refer to Table 3) that are tested and validated under the Cryptographic Module Validation Program (CAVP).
The module includes an internal entropy source for the generation of the DRBG seed. Please refer to the Entropy Source Validation (ESV) certificate #E55. Table 9 - Non-Deterministic Random Number Generation Specification Minimum Number of Bits of Entropy Kingston Technology Company, Inc. The ESV source outputs Based on the heuristic Crypto Library FW v2.00 1024 bits with a lower bound entropy minimum of 256 bits of estimate, the entropy ESV Validation #E55 entropy source has a rate of 1-bit per nibble or 25%. This means the entropy input required for the DRBG is
The module generates cryptographic keys using a NIST SP 800-90A conforming DRBG (Cert. #A3268) for the encryption and protection of user data.
The module supports a NIST SP 800-56Ar3 conforming key agreement scheme for the establishment of AES 256 and HMAC-SHA2-256 keys to secure communication to / from the module. In addition, the module supports KTS using AES CBC with HMAC-SHA2-256 in conformance with NIST SP 800-38F and IG D.G. This document may be freely reproduced and distributed, but only in its entirety and without modification.
The module relies upon the standard USB protocol for communication with general purpose computer (GPC) systems. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| PhysicalPort | LogicalInterface | DatathatPassesoverPort/Interface |
|---|---|---|
| USBPort(Rx/Tx) | DataInput | TheUSB3.0portconnectsthemoduletothehostcomputer.Itisused toreceiveuserdataaswellasAPIcallsissuedbythehostviatheUSB protocol.TheinputisreceivedbythemoduleontheRxline. |
| DataOutput | TheUSB3.0portconnectsthemoduletothehostcomputer.Itisused tosenduserdataaswellasreturncodesuponcompletionofAPIcalls issuedbythehostviatheUSBprotocol.Theinputisreceivedbythe moduleontheTxline. | |
| ControlInput | TheUSB3.0portconnectsthemoduletothehostcomputer.Itisused toreceivecommandsaswellasAPIcallsissuedbythehostviatheUSB protocol.TheinputisreceivedbythemoduleontheRxline. | |
| StatusOutput | Errorcodesandotherstatusesaretransmittedfromthemoduletothe hostcomputer. | |
| LED | StatusOutput | ErrorcodesandotherstatusesaretransmittedbytheLED: − Activedatatransferwithhostcomputer:LEDblinksat3Hz − Errorstate:LEDblinksrapidlyat16Hz − Pre-operationalSelf-teststatusoutput:LEDblinksat3Hzifallself- testscompleted,LEDblinksat16Hziffailed − ContinuousSelf-teststatusoutput:LEDblinksat16Hziffailed − PeriodicSelf-teststatusoutput:LEDblinksat16Hziffailed |
| USBPort(VCC) | Power | TheUSBVBUS(+5VDC)powersthemodule. |
The module incorporates both physical and logical interfaces as described within Table 10. Table 10 - Ports and Interfaces Physical Port Logical Interface Data that Passes over Port/Interface USB Port (Rx / Tx) Data Input The USB 3.0 port connects the module to the host computer. It is used to receive user data as well as API calls issued by the host via the USB protocol. The input is received by the module on the Rx line. Data Output The USB 3.0 port connects the module to the host computer. It is used to send user data as well as return codes upon completion of API calls issued by the host via the USB protocol. The input is received by the module on the Tx line. Control Input The USB 3.0 port connects the module to the host computer. It is used to receive commands as well as API calls issued by the host via the USB protocol. The input is received by the module on the Rx line. Status Output Error codes and other statuses are transmitted from the module to the host computer. LED Status Output Error codes and other statuses are transmitted by the LED: − Active data transfer with host computer: LED blinks at 3Hz − Error state: LED blinks rapidly at 16Hz − Pre-operational Self-test status output: LED blinks at 3Hz if all selftests completed, LED blinks at 16Hz if failed − Continuous Self-test status output: LED blinks at 16Hz if failed − Periodic Self-test status output: LED blinks at 16Hz if failed USB Port (VCC) Power The USB VBUS (+5VDC) powers the module.
The module does not support a Trusted Channel. 4. ROLES, SERVICES, AND AUTHENTICATION
The module supports identity-based authentication in the form of a User ID and Password (Memorized Secret) in conformance with NIST SP 800-140E and SP 800-63B (refer to Section 5.1.1).
Per NIST SP 800-63B – Section 5.1.1, passwords must be a minimum of 8 bytes (enforced by the module). The password must contain three of the following four-character types: lowercase letters, uppercase letters, numeric characters and/or special characters. This greatly increases the passwords entropy. Assuming a mix of lowercase letters, uppercase letters, numeric characters, the This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Name | Description | Mechanism | StrengthEachAttempt | StrengthPerMinute | |||
|---|---|---|---|---|---|---|---|
| ID/Password | COandUserrole | ID&Password combination usedwithina challenge/resp onse mechanism | ID&Password | Theupperboundforthe probabilityofhavingthe passwordguessedat randomis: 1/(10*26*26*955) ~=1/245<1/1,000,000 | Theupperboundforthe | Theprobabilityofthe consecutivefailed authenticationattemptsinone minuteperiodis approximately10/245< 1/100,000 | Theprobabilityofthe |
| authentication | combination | probabilityofhavingthe | consecutivefailed | ||||
| method. | usedwithina | passwordguessedat | authenticationattemptsinone | ||||
| Thepasswordisat | challenge/resp | randomis: | minuteperiodis | ||||
| onse | approximately10/245< | ||||||
| least8bytesin | 1/(10*26*26*955) | ||||||
| mechanism | 1/100,000 | ||||||
| lengthand includesthe numbers,the uppercaseletters, thelowercase letters,andthe specialcharacters. | ~=1/245<1/1,000,000 |
| Role | Service | Input | Output | |
|---|---|---|---|---|
| CryptoOfficer(CO) | ChangeCOPassword | CurrentCOPasswordand newCOPassword | CurrentCOPasswordand | StatusOut(success,session |
| newCOPassword | invalid,wrongpassword)LED blinksat16Hziffatalerror | |||
| ClosePartition(Logout) | N/A | StatusOut(success,session invalid,partitionhasbeen closed)LEDblinksat16Hzif fatalerror | ||
| Decrypt | Diskaccessing | Readpartitiondata | ||
| Encrypt | Diskaccessing | Writepartitiondata | ||
| Initialize | COPassword | StatusOut(success, | ||
| andthedrive’spartition | configurationinvalid)LED | |||
| configuration | blinksat16Hziffatalerror | |||
| OpenPartition(Login) | COID&Password,andthe selectedpartition | StatusOut(success,session invalid,partitionhasbeen opened,wrongpassword)LED blinksat16Hziffatalerror,the partitionisopenedifsuccess | ||
| SetupUserPassword | CurrentCOPasswordand newUserPassword | StatusOut(success,session invalid,wrongpassword)LED blinksat16Hziffatalerror |
password can consist of the following set: uppercase letters, lowercase letters, numbers, and special characters, yielding 95 choices per character. The probability of a successful random attempt is 1/ (10 * 26 * 26 * 955) ~= 1/245, which is less than 1/1,000,000. The module only allows for ten (10) unsuccessful authentication attempts. Therefore, the probability of success with multiple attempts in a one-minute period is 10/245, which is less than 1/100,000. Table 11 – Authentication Methods Name Description Mechanism Strength Each Attempt Strength Per Minute ID/Password CO and User role ID & Password The upper bound for the The probability of the authentication combination probability of having the consecutive failed method. used within a password guessed at authentication attempts in one challenge/resp random is: minute period is The password is at least 8 bytes in 1 / (10 * 26 * 26 * 955) length and ~= 1/245 < 1/1,000,000 includes the uppercase letters, the lowercase special characters.
Table 12 lists the roles supported by the module with the respective services supported by that Table 12 – Roles, Service Commands, Input and Output Crypto Officer (CO) Change CO Password Current CO Password and Status Out (success, session blinks at 16Hz if fatal error Close Partition (Logout) N/A Status Out (success, session invalid, partition has been closed) LED blinks at 16Hz if fatal error Decrypt Disk accessing Read partition data Encrypt Disk accessing Write partition data and the drive’s partition configuration invalid) LED configuration blinks at 16Hz if fatal error Open Partition (Login) CO ID & Password, and the Status Out (success, session selected partition invalid, partition has been blinks at 16Hz if fatal error, the partition is opened if success Setup User Password Current CO Password and Status Out (success, session new User Password invalid, wrong password) LED blinks at 16Hz if fatal error This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Role | Service | Input | Output | |
|---|---|---|---|---|
| SetupRecovery Password | CurrentCOPasswordand newRecoveryPassword | StatusOut(success,session invalid,wrongpassword)LED blinksat16Hziffatalerror | ||
| User | ChangeUserPassword | CurrentUserPassword andnewUserPassword | StatusOut(success,session invalid,wrongpassword)LED blinksat16Hziffatalerror | |
| ClosePartition(Logout) | N/A | StatusOut(success,session invalid,partitionhasbeen closed)LEDblinksat16Hzif fatalerror | ||
| Decrypt | Diskaccessing | Readpartitiondata | ||
| Encrypt | Diskaccessing | Writepartitiondata | ||
| OpenPartition(Login) | UserID&Password,and theselectedpartition | StatusOut(success,session invalid,partitionhasbeen opened,wrongpassword)LED blinksat16Hziffatalerror,the partitionisopenedifsuccess | ||
| SetupUserPassword (UsingRecovery Password) | RecoveryPasswordand newUserPassword | StatusOut(success,session invalid,wrongpassword, recoverypasswordnotcreated) LEDblinksat16Hziffatalerror | ||
| Unauthenticated | CDUpdate | APIcallwithCDImage, Signature | StatusOut(success,session invalid,signatureverification failed) | |
| PerformSelf-Tests | Power-onthemodule | LEDblinksat3Hzifalltests complete LEDblinksat16Hziffailed | ||
| ResetDrive | N/A | StatusOut(success,session invalid)Internallyzeroizeall CSPsexceptthesessionkeys andgenerateDEK_COand configuretothesinglepartition. LEDblinksat16Hziffatalerror | ||
| ShowModuleVersion | N/A | ReturnsmoduleIDandversion information,inadditiontothe approvedmodeindicatortoAPI call. | ||
| ShowErrorStatus | N/A | ReturnstheerrorlogtoAPIcall | ||
| ShowStatus | N/A | Replytheservicestatus,thedisk status,orthesession establishmentstatustoAPIcall | ||
| Zeroization | N/A | StatusOut(success)Internally zeroizeallCSPs.LEDblinksat 16Hziffatalerror |
Setup Recovery Current CO Password and Status Out (success, session Password new Recovery Password invalid, wrong password) LED blinks at 16Hz if fatal error blinks at 16Hz if fatal error Close Partition (Logout) N/A Status Out (success, session invalid, partition has been closed) LED blinks at 16Hz if fatal error Decrypt Disk accessing Read partition data Encrypt Disk accessing Write partition data the selected partition invalid, partition has been blinks at 16Hz if fatal error, the partition is opened if success (Using Recovery new User Password invalid, wrong password, Password) recovery password not created) LED blinks at 16Hz if fatal error Unauthenticated CD Update API call with CD Image, Status Out (success, session Perform Self-Tests Power-on the module LED blinks at 3Hz if all tests LED blinks at 16Hz if failed Reset Drive N/A Status Out (success, session invalid) Internally zeroize all CSPs except the session keys and generate DEK_CO and configure to the single partition. LED blinks at 16Hz if fatal error Show Module Version N/A Returns module ID and version information, in addition to the approved mode indicator to API Show Error Status N/A Returns the error log to API call Show Status N/A Reply the service status, the disk establishment status to API call zeroize all CSPs. LED blinks at 16Hz if fatal error The operator must perform that following initialization procedures to access the module for the first time.
| Role | Authentication Method | AuthenticationStrength | |||
|---|---|---|---|---|---|
| StrengthEachAttempt | StrengthPerMinute | ||||
| CryptoOfficer(CO) | ID&Password | Theupperboundforthe probabilityofhavingthe passwordguessedatrandomis: 1/(10*26*26*955)~=1/245 <1/1,000,000 | Theupperboundforthe | Theprobabilityofthe consecutivefailedauthentication attemptsinoneminuteperiodis approximately10/245< 1/100,000 | Theprobabilityofthe |
| combinationused | probabilityofhavingthe | consecutivefailedauthentication | |||
| withina | passwordguessedatrandomis: | attemptsinoneminuteperiodis | |||
| challenge/response | 1/(10*26*26*955)~=1/245 | approximately10/245< | |||
| mechanism.The passwordmustbeat least8characters longandmust containatleastone integer,onelower- caseletter,andone upper-caseletter. | <1/1,000,000 | 1/100,000 | |||
| User | ID&Password combinationused withina challenge/response mechanism.The passwordmustbeat least8characters longandmust containatleastone integer,onelower- caseletter,andone upper-caseletter. | Theupperboundforthe probabilityofhavingthe passwordguessedatrandomis: 1/(10*26*26*955)~=1/245 <1/1,000,000 | Theprobabilityofthe consecutivefailedauthentication attemptsinoneminuteperiodis approximately10/245< 1/100,000 |
Table 13 – Roles and Authentication Strength Each Attempt Strength Per Minute Crypto Officer (CO) ID & Password The upper bound for the The probability of the combination used probability of having the consecutive failed authentication within a password guessed at random is: attempts in one minute period is password must be at least 8 characters long and must contain at least one integer, one lowercase letter, and one upper-case letter. User ID & Password The upper bound for the The probability of the combination used probability of having the consecutive failed authentication within a password guessed at random is: attempts in one minute period is password must be at least 8 characters long and must contain at least one integer, one lowercase letter, and one upper-case letter. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| rotacidnI | :IPAehtaivsutatsnruteR | sseccus:0000x0 | dilavninoisses:2004x0 | :IPAehtaivsutatsnruteR | sseccus:0000x0 | dilavninoisses:2004x0 | erutangis:6004x0 | deliafnoitacifirev | :IPAehtaivsutatsnruteR | sseccus:0000x0 | noitarugifnoc:2018x0 | dilavni | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ro/dnasyeKotsthgiRsseccA | sPSS | Z,E,G:)Z(terceSderahS | E,G:yeKnoisseSSEA | E,G:yeKnoisseSCAM | Z,G:yeKetavirPHDCEeciveD | Z,R,G:yeKcilbuPHDCEeciveD | Z,W:yeKcilbuPHDCEtsoH | E,G:etatSlanretnIGBRD | E:yeKcilbuPetadpUDC | Z,E,G:OC_KEK | Z,E:drowssaPOC | G,Z:hsaHdrowssaPOC | E,G:etatSlanretnIGBRD | ||||||||||
| seloR | resUdnaOC | detacitnehtuanU | OC | ||||||||||||||||||||
| sPSS&syeK | ,yeKnoisseSSEA | yeKnoisseSCAM | cilbuPetadpUDC | yeK | ,OC_KEK | ,drowssaPOC | hsaHdrowssaPOC | etatSlanretnIGBRD | |||||||||||||||
| ytiruceSdevorppA | snoitcnuF | ADK&CSS-CCE-SAK | )5.1v1SCKP(ASR | erutangiS | noitacifireV | -2AHS,FDKBP,GBRD | 652 | ||||||||||||||||
| noitpircseD | eruceS | noitacinummoC | noisseS | DCetadpU/daoL | MOR-DCehtotegamI | noititrap | OCwenetaerC | drowssap | |||||||||||||||
| ecivreS | resU/OCllA( | )secivreS | etadpUDC | OCegnahC | drowssaP |
SSP access rights are defined as follows: • G = Generate: The module generates or derives the SSP. • R = Read: The SSP is read from the module (e.g., the SSP is output). • W = Write: The SSP is updated, imported, or written to the module. • E = Execute: The module uses the SSP in performing a cryptographic operation. • Z = Zeroize: The module zeroizes the SSP. Table 14 – Approved Services Service Description Approved Security Keys & SSPs Roles Access Rights to Keys and / or Indicator Functions SSPs (All CO/User Secure KAS-ECC-SSC & KDA AES Session Key, CO and User Shared Secret (Z): G, E, Z Return status via the API: Services) Communication MAC Session Key AES Session Key: G, E MAC Session Key: G, E 0x0000: success Session Device ECDH Private Key: G, Z 0x4002: session invalid Device ECDH Public Key: G, R, Z Host ECDH Public Key: W, Z DRBG Internal State: G, E CD Update Load/Update CD RSA (PKCS1 v1.5) CD Update Public Unauthenticated CD Update Public Key: E Return status via the API: Image to the CD-ROM Signature Key 0x0000: success partition Verification 0x4002: session invalid 0x4006: signature verification failed Change CO Create new CO DRBG, PBKDF, SHA2- KEK_CO, CO KEK_CO: G, E, Z Return status via the API: Password password 256 CO Password, CO Password: E, Z 0x0000: success CO Password Hash CO Password Hash: Z, G 0x8102: configuration DRBG Internal State DRBG Internal State: G, E invalid This document may be freely reproduced and distributed, but only in its entirety and without modification.
| rotacidnI | :IPAehtaivsutatsnruteR | sseccus:0000x0 | noitarugifnoc:2018x0 | dilavni | :IPAehtaivsutatsnruteR | sseccus:0000x0 | dilavninoisses:2061x0 | neebsahnoititrap:4061x0 | desolc | :IPAehtaivsutatsnruteR | sseccus:0000x0 | :IPAehtaivsutatsnruteR | sseccus:0000x0 | :IPAehtaivsutatsnruteR | sseccus:0000x0 | noitarugifnoc:2018x0 | dilavni | :IPAehtaivsutatsnruteR | sseccus:0000x0 | dilavninoisses:2041x0 | neebsahnoititrap:4041x0 | denepo | drowssapgnorw:6041x0 | gnihsalFDEL | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ro/dnasyeKotsthgiRsseccA | sPSS | Z,E,G:U_KEK | Z,E:drowssaPresU | G,Z:hsaHdrowssaPresU | E,G:etatSlanretnIGBRD | Z:OC_KED | Z:yeKnoisseSSEA | Z:yeKnoisseSCAM | Z:U_KED | Z:yeKnoisseSSEA | Z:yeKnoisseSCAM | E:OC_KED | E:U_KED | E:OC_KED | E:U_KED | G,Z:OC_KED | Z,E,G:OC_KEK | Z,E,W:drowssaPOC | G:hsaHdrowssaPOC | E,G:tupnIyportnE | E,G:ecnoNGBRD | E,G:etatSlanretnIGBRD | Z,E,W:drowssaPOC | Z,E,G:OC_KEK | E:OC_KED | Z,E,W:drowssaPresU | Z,E,G:U_KEK | E:U_KED | E,G:etatSlanretnIGBRD | ||||||||||||
| seloR | resU | OC | resU | OC | resU | OC | resU | OC | OC | resU | detacitnehtuanU | ||||||||||||||||||||||||||||||
| sPSS&syeK | U_KEK | ,drowssaPresU | ,hsaHdrowssaPresU | etatSlanretnIGBRD | U_KEDroOC_KED | U_KEDroOC_KED | U_KEDroOC_KED | ,OC_KED | ,OC_KEK | ,drowssaPOC | ,hsaHdrowssaPOC | ,tupnIyportnE | ,ecnoNGBRD | etatSlanretnIGBRD | drowssaPOC | OC_KED&OC_KEK | ro | ,drowssaPresU | U_KED&U_KEK | A/N | |||||||||||||||||||||
| ytiruceSdevorppA | snoitcnuF | -2AHS,FDKBP,GBRD | 652 | A/N | STX-SEA | STX-SEA | -2AHS,FDKBP,GBRD | WK-SEA,652 | ,652-2AHS,FDKBP | WK-SEA | A/N | ||||||||||||||||||||||||||||||
| noitpircseD | resUwenetaerC | drowssaP | evirdskcoL.tuogoL | atadnoititrapdaeR | atadnoititrapetirW | drowssapOCetaerC | KEDetarenegdna | rehtiesetacitnehtuA | ehtotresUroOCeht | eludom | -erPmrofreP | dnalanoitarepO | stseT-fleSlanoitidnoC | ||||||||||||||||||||||||||||
| ecivreS | resUegnahC | drowssaP | noititraPesolC | )tuogoL( | tpyrceD | tpyrcnE | ezilaitinI | noititraPnepO | )nigoL( | -fleSmrofreP | stseT |
Service Description Approved Security Keys & SSPs Roles Access Rights to Keys and / or Indicator Functions SSPs Change User Create new User DRBG, PBKDF, SHA2- KEK_U User KEK_U: G, E, Z Return status via the API: Password Password 256 User Password, User Password: E, Z 0x0000: success User Password Hash, User Password Hash: Z, G 0x8102: configuration DRBG Internal State DRBG Internal State: G, E invalid Close Partition Logout. Locks drive N/A DEK_CO or DEK_U CO DEK_CO: Z Return status via the API: (Logout) AES Session Key: Z 0x0000: success MAC Session Key: Z 0x1602: session invalid User DEK_U: Z 0x1604: partition has been closed AES Session Key: Z MAC Session Key: Z Decrypt Read partition data AES-XTS DEK_CO or DEK_U CO DEK_CO: E Return status via the API: User DEK_U: E 0x0000: success Encrypt Write partition data AES-XTS DEK_CO or DEK_U CO DEK_CO: E Return status via the API: User DEK_U: E 0x0000: success Initialize Create CO password DRBG, PBKDF, SHA2- DEK_CO, CO DEK_CO: Z, G Return status via the API: and generate DEK 256, AES-KW KEK_CO, KEK_CO: G, E, Z 0x0000: success CO Password, CO Password: W, E, Z 0x8102: configuration CO Password Hash, CO Password Hash: G Entropy Input, Entropy Input: G, E invalid DRBG Nonce, DRBG Nonce: G, E DRBG Internal State DRBG Internal State: G, E Open Partition Authenticates either PBKDF, SHA2-256, CO Password CO CO Password: W, E, Z Return status via the API: (Login) the CO or User to the AES-KW KEK_CO & DEK_CO KEK_CO: G, E, Z 0x0000: success module DEK_CO: E or 0x1402: session invalid User User Password: W, E, Z 0x1404: partition has been User Password, KEK_U: G, E, Z opened KEK_U & DEK_U DEK_U: E 0x1406: wrong password Perform Self- Perform Pre- N/A N/A Unauthenticated DRBG Internal State: G, E LED Flashing Tests Operational and Conditional Self-Tests This document may be freely reproduced and distributed, but only in its entirety and without modification.
| rotacidnI | :IPAehtaivsutatsnruteR | sseccus:0000x0 | dilavninoisses:1018x0 | :IPAehtaivsutatsnruteR | sseccus:0000x0 | noitarugifnoc:2018x0 | dilavni | :IPAehtaivsutatsnruteR | sseccus:0000x0 | noitarugifnoc:2018x0 | dilavni | :IPAehtaivsutatsnruteR | sseccus:0000x0 | noitarugifnoc:2018x0 | dilavni | :IPAehtaivsutatsnruteR | sseccus:0000x0 | :IPAehtaivsutatsnruteR | sseccus:0000x0 | :IPAehtaivsutatsnruteR | sseccus:0000x0 | ||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ro/dnasyeKotsthgiRsseccA | sPSS | Z:OC_KED | Z:U_KED | Z:hsaHdrowssaPOC | Z:hsaHdrowssaPresU | Z:hsaHdrowssaPyrevoceR | Z:etatSlanretnIGBRD | Z,G:U_KED | Z,E,G:U_KEK | Z,E,W:drowssaPresU | G:hsaHdrowssaPresU | E,G:etatSlanretnIGBRD | Z,E,G:U_KEK | Z,E,G:R_KEK | Z,E:drowssaPyrevoceR | Z:hsaHdrowssaPyrevoceR | Z,E,W:drowssaPresU | G:hsaHdrowssaPresU | E,G:etatSlanretnIGBRD | Z,E,G:R_KEK | Z,E,W:drowssaPyrevoceR | G:hsaHdrowssaPyrevoceR | E,G:etatSlanretnIGBRD | A/N | A/N | A/N | |||||||||||||||
| seloR | detacitnehtuanU | OC | resU | OC | detacitnehtuanU | detacitnehtuanU | detacitnehtuanU | ||||||||||||||||||||||||||||||||||
| sPSS&syeK | ,U_KED,OC_KED | ,hsaHdrowssaPOC | ,hsaHdrowssaPresU | drowssaPyrevoceR | lanretnIGBRD,hsaH | etatS | ,U_KEK,U_KED | resU,drowssaPresU | ,hsaHdrowssaP | etatSlanretnIGBRD | U_KEK,R_KEK | ,drowssaPyrevoceR | drowssaPyrevoceR | ,hsaH | ,drowssaPresU | ,hsaHdrowssaPresU | etatSlanretnIGBRD | ,R_KEK | ,drowssaPyrevoceR | drowssaPyrevoceR | ,hsaH | etatSlanretnIGBRD | A/N | A/N | A/N | ||||||||||||||||
| ytiruceSdevorppA | snoitcnuF | A/N | -2AHS,FDKBP,GBRD | 652 | -2AHS,FDKBP,GBRD | 652 | -2AHS,FDKBP,GBRD | 652 | A/N | A/N | A/N | ||||||||||||||||||||||||||||||
| noitpircseD | derotsselifllaesarE | dnaeludomehtno | sPSCllaseziorez | resUwenetaerC | drowssap | resUwenetaerC | drowssaP | yrevoceRetaerC | drowssap | dnaDIeludomteG | noisrev | tsomehtsnruteR | sliatedrorretnecer | s’eludomehtteG | sutats | ||||||||||||||||||||||||||
| ecivreS | evirDteseR | resUputeS | drowssaP | resUputeS | drowssaP | yrevoceRgnisU( | )drowssaP | yrevoceRputeS | drowssaP | eludoMwohS | noisreV | rorrEwohS | sutatS | sutatSwohS |
Service Description Approved Security Keys & SSPs Roles Access Rights to Keys and / or Indicator Functions SSPs Reset Drive Erase all files stored N/A DEK_CO, DEK_U, Unauthenticated DEK_CO: Z Return status via the API: on the module and CO Password Hash, DEK_U: Z 0x0000: success zeroizes all CSPs User Password Hash, CO Password Hash: Z 0x8101: session invalid Recovery Password User Password Hash: Z Hash, DRBG Internal Recovery Password Hash: Z State DRBG Internal State: Z Setup User Create new User DRBG, PBKDF, SHA2- DEK_U, KEK_U, CO DEK_U: G, Z Return status via the API: Password password 256 User Password, User KEK_U: G, E, Z 0x0000: success Password Hash, User Password: W, E, Z 0x8102: configuration DRBG Internal State User Password Hash: G invalid DRBG Internal State: G, E Setup User Create new User DRBG, PBKDF, SHA2- KEK_R, KEK_U User KEK_U: G, E, Z Return status via the API: Password Password 256 Recovery Password, KEK_R: G, E, Z 0x0000: success (Using Recovery Recovery Password Recovery Password: E, Z 0x8102: configuration Password) Hash, Recovery Password Hash: Z invalid User Password, User Password: W, E, Z User Password Hash, User Password Hash: G DRBG Internal State DRBG Internal State: G, E Setup Recovery Create Recovery DRBG, PBKDF, SHA2- KEK_R, CO KEK_R: G, E, Z Return status via the API: Password password 256 Recovery Password, Recovery Password: W, E, Z 0x0000: success Recovery Password Recovery Password Hash: G 0x8102: configuration Hash, DRBG Internal State: G, E invalid DRBG Internal State Show Module Get module ID and N/A N/A Unauthenticated N/A Return status via the API: Version version 0x0000: success Show Error Returns the most N/A N/A Unauthenticated N/A Return status via the API: Status recent error details 0x0000: success Show Status Get the module’s N/A N/A Unauthenticated N/A Return status via the API: status 0x0000: success This document may be freely reproduced and distributed, but only in its entirety and without modification.
| rotacidnI | :IPAehtaivsutatsnruteR | sseccus:0000x0 | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| ro/dnasyeKotsthgiRsseccA | sPSS | Z:OC_KED | Z:U_KED | Z:hsaHdrowssaPOC | Z:hsaHdrowssaPresU | Z:hsaHdrowssaPyrevoceR | Z:etatSlanretnIGBRD | Z:yeKnoisseSSEA | Z:yeKnoisseSCAM | |
| seloR | detacitnehtuanU | |||||||||
| sPSS&syeK | A/N | |||||||||
| ytiruceSdevorppA | snoitcnuF | A/N | ||||||||
| noitpircseD | dnasyekllaezioreZ | sPSC | ||||||||
| ecivreS | noitazioreZ |
Service Description Approved Security Keys & SSPs Roles Access Rights to Keys and / or Indicator Functions SSPs Zeroization Zeroize all keys and N/A N/A Unauthenticated DEK_CO: Z Return status via the API: CSPs DEK_U: Z 0x0000: success CO Password Hash: Z User Password Hash: Z Recovery Password Hash: Z DRBG Internal State: Z AES Session Key: Z MAC Session Key: Z This document may be freely reproduced and distributed, but only in its entirety and without modification.
The module does not support any non-approved services.
The module’s firmware is non-modifiable. It does not have the ability to support the external software / firmware loading.
The module supports the following authenticated roles: • Crypto Officer (CO) • User It enforces the separation of roles using identity-based authentication. The operator must perform that following initialization procedures to access the module for the first time.
The module incorporates an RSA 2048 PKCS1 v1.5 (Cert. #A3268) digital signature mechanism over its firmware. The digital signature provides integrity as well as authentication. All commands sent to and from the cryptographic module are protected with HMAC-SHA2-256.
The module loads the firmware image from non-volatile memory to on-chip RAM when powering on the module where it then performs the firmware integrity test using the module’s RSA-2048 ‘Firmware Integrity Public Key’. If the test fails, the module enters an error state, the data output interface is inhibited, and the module’s LED (status output) blinks at 16Hz. The firmware integrity test is a part of Pre-Operational Self-Tests. It is automatically executed at power-on or during the Periodic Self-Tests. It can also be invoked by power-cycling the module. 6. OPERATIONAL ENVIRONMENT
The operational environment is classified as non-modifiable. 7. PHYSICAL SECURITY The module is a multiple-chip standalone module and conforms to FIPS 140-3 Security Level 3 physical security requirements. The module is housed within a strong, non-removable, tamperevident enclosure. The enclosure is opaque within the visible spectrum. In addition, all components are protected with a hard epoxy coating that protects each component from being viewed or probed. Attempts at removing the epoxy will render the module inoperable.
The operator of the module should inspect the outer casing of the module each time prior to connecting the module to a computer. If tamper evidence is observed on the outer casing, the module should not be used. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| PhysicalSecurity Mechanism | RecommendedFrequencyof Inspection/Test | Inspection/TestGuidanceDetails | ||
|---|---|---|---|---|
| TamperEvidence | Eachtimethemoduleisused | Uponeachuseofthemoduletheoperatorshould examinethemoduleforevidenceoftamper. |
| LowTemperature | HighTemperature | |
|---|---|---|
| NormalOperation | 0°C | 60°C |
| Storage | -20°C | 85°C |
| Distribution | -20°C | 85°C |
| Environment | Temperature/Voltage Measurement | EFP/EFT | Shutdown,Zeroization,UndefinedFailure,Known ErrorSateorContinuestoOperateNormally3 |
|---|---|---|---|
| LowTemperature | -100°C | EFT | ContinuestoOperateNormally |
| HighTemperature | +122°C | EFT | UndefinedFailure |
| LowVoltage | 3.2V | EFT | Shutdown |
| HighVoltage | 10.1V | EFT | UndefinedFailure |
| HardnessTestedTemperatureMeasurement | |
|---|---|
| LowTemperature | -20°C |
| HighTemperature | 85°C |
Table 15 - Physical Security Inspection Guidelines Physical Security Recommended Frequency of Inspection/Test Guidance Details Upon each use of the module the operator should Tamper Evidence Each time the module is used examine the module for evidence of tamper. The module supports the operation, storage and distribution temperatures listed in Table 16. Table 16 – Normal Operation, Storage and Distribution Temperature Ranges Low Temperature High Temperature Normal Operation 0°C 60°C The module does not incorporate any environmental protection mechanisms (EFP). The module satisfies environmental failure testing (EFT) requirements. Table 17 – EFP/EFT Measurement Error Sate or Continues to Operate Normally 3 Low Temperature -100°C EFT Continues to Operate Normally High Temperature +122°C EFT Undefined Failure High Voltage 10.1V EFT Undefined Failure
The module supports and has been tested at the operation, storage and distribution temperatures listed in Table 16. The module’s epoxy and outer enclosure hardness are assured within these ranges. Table 18 – Hardness Testing Temperature Ranges Hardness Tested Temperature Measurement
3 For EFP, states can be Shutdown or Zeroise; for EFT, states can be Shutdown, Zeroization, Undefined Failure, Known Error Sate
or Continues to Operate Normally. This document may be freely reproduced and distributed, but only in its entirety and without modification.
The module is designed to encrypt and store arbitrary data with XTS-AES within eMMC memory components. The module physically and logically protects static keys and CSPs. Please refer to Table 19 for additional information.
The module inputs CSPs encrypted with AES CBC and authenticated with HMAC-SHA2-256. The module does not output CSPs. PSPs are output in order to authenticate the module to the connected GPC. Please refer to Table 19 for additional information.
During normal operation, the module explicitly erases copies of CSPs in volatile memory (e.g., RAM) by overwriting with zeros after their use. For CSPs stored in non-volatile memory the module initiates its erase operation to zeroize. The following methods are used to zeroize the module’s CSPs during normal operation. − ‘Zeroization’ and ‘Reset Drive’ service: This service overwrites all CSPs with zeroes and returns the module to its factory default state. − After ten failed CO authentication attempts the respective CO and User DEKs are erased. − After ten failed User authentication attempts the respective User DEK is erased. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| sPSSdetaler&esU noitazioreZ | /noitpyrcnEataD noitpyrceD | /noitpyrcnEataD noitpyrceD ro’noitazioreZ‘ fonoitazioreZ esolC‘gnirud gnitcennocsid ’evirDteseR‘ U_KEKeht ’noititraP roecivres .evirdeht .secivres | tpyrceD/tpyrcnE OC_KED | tpyrceD/tpyrcnE U_KED nettirwrevO yletaidemmi sorezhtiw esuretfa | tpyrceD/tpyrcnE U_KED | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| fonoitazioreZ | OC_KEKeht | esolC‘gnirud | ’noititraP | roecivres | gnitcennocsid | .evirdeht | ro’noitazioreZ‘ | ’evirDteseR‘ | .secivres | nettirwrevO | sorezhtiw | yletaidemmi | esuretfa | nettirwrevO | sorezhtiw | yletaidemmi | esuretfa | ||||
| egarotS | OC_KEKhtiw detpyrcnE -CMMe | U_KEKhtiw detpyrcnE -CMMe | )txetnialP( MAR | )txetnialP( MAR | )txetnialP( MAR | ||||||||||||||||
| tnemhsilbatsE | A/N | A/N | morfdevireD reciffOotpyrC drowssaP | drowssaPresU morfdevireD | morfdevireD yrevoceR drowssaP | ||||||||||||||||
| A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | |||||||||||||||||
| /tropmI | tropxE | A/N:yrtnE | A/N:tuptuO | ||||||||||||||||||
| noitareneG | -008PSaiv( )GBRDA09 detareneG | -008PSaiv( )GBRDA09 detareneG | A/N | A/N | A/N | ||||||||||||||||
| )8623A#.treC( STX-SEA | )8623A#.treC( STX-SEA | )8623A#.treC( WK-SEA | )8623A#.treC( WK-SEA | )8623A#.treC( WK-SEA | |||||||||||||||||
| noitcnuFytiruceS | rebmuN.treC& | STX-SEA | )8623A#.treC( | ||||||||||||||||||
| htgnertS | stib652 | stib652 | stib652 | stib652 | stib652 | ||||||||||||||||
| emaNPSC/yeK | )OC-yeKnoitpyrcnEataD( OC_KED | )resU-yeKnoitpyrcnEataD( U_KED | )OC-yeKnoitpyrcnEyeK( OC_KEK | )resU-yeKnoitpyrcnEyeK( U_KEK | )KEKyrevoceR( R_KEK |
/noitpyrcnEataD
noitpyrceD
tpyrceD/tpyrcnE
OC_KED
tpyrceD/tpyrcnE
U_KED
-CMMe
detpyrcnE
OC_KEKhtiw
MAR
)txetnialP(
MAR
)txetnialP(
morfdevireD
reciffOotpyrC
drowssaP
morfdevireD
yrevoceR
drowssaP
A/N:yrtnE
A/N:tuptuO
A/N:yrtnE
A/N:tuptuO
detareneG
-008PSaiv(
)GBRDA09
WK-SEA
)8623A#.treC(
WK-SEA
)8623A#.treC(
OC_KED
)OC-yeKnoitpyrcnEataD(
OC_KEK
)OC-yeKnoitpyrcnEyeK(
R_KEK
)KEKyrevoceR(
The module incorporates SSPs as defined with Table 19. Table 19 – SSPs Key/CSP Name Strength Security Function Generation Import / Establishment Storage Zeroization Use & related SSPs & Cert. Number Export DEK_CO 256 bits AES-XTS Generated Entry: N/A N/A eMMC - Zeroization of Data Encryption / (Data Encryption Key - CO) (Cert. #A3268) (via SP 800- Output: N/A Encrypted the KEK_CO Decryption 90A DRBG) with KEK_CO during ‘Close Partition’ service or disconnecting the drive. ‘Zeroization’ or ‘Reset Drive’ services. DEK_U 256 bits AES-XTS Generated Entry: N/A N/A eMMC - Zeroization of Data Encryption / (Data Encryption Key - User) (Cert. #A3268) (via SP 800- Output: N/A Encrypted the KEK_U Decryption 90A DRBG) with KEK_U during ‘Close Partition’ service or disconnecting the drive. ‘Zeroization’ or ‘Reset Drive’ services. KEK_CO 256 bits AES-KW N/A Entry: N/A Derived from RAM Overwritten Encrypt / Decrypt (Key Encryption Key - CO) (Cert. #A3268) Output: N/A Crypto Officer (Plaintext) with zeros DEK_CO Password immediately after use KEK_U 256 bits AES-KW N/A Entry: N/A Derived from RAM Overwritten Encrypt / Decrypt (Key Encryption Key - User) (Cert. #A3268) Output: N/A User Password (Plaintext) with zeros DEK_U immediately after use KEK_R 256 bits AES-KW N/A Entry: N/A Derived from RAM Overwritten Encrypt / Decrypt (Recovery KEK) (Cert. #A3268) Output: N/A Recovery (Plaintext) with zeros DEK_U Password immediately after use This document may be freely reproduced and distributed, but only in its entirety and without modification.
| sPSSdetaler&esU noitazioreZ | ehtetarenegotdesU OC_KEK nettirwrevO yletaidemmi sorezhtiw esuretfa | ehtetarenegotdesU U_KEK nettirwrevO yletaidemmi sorezhtiw esuretfa | ehtetarenegotresU R_KEK nettirwrevO yletaidemmi sorezhtiw esuretfa | noitacitnehtuA rofdesU | noitacitnehtuA rofdesU ro’noitazioreZ‘ ’eciveDteseR‘ ecivres | noitacitnehtuA rofdesU ro’noitazioreZ‘ ’eciveDteseR‘ ecivres | tupniyportnesadesU A09-008PSehtot GBRD nettirwrevO yletaidemmi sorezhtiw esuretfa | ottupniecnonsadesU GBRDA09-008PSeht nettirwrevO yletaidemmi sorezhtiw esuretfa | GBRDA09-008PSeht foetatslanretniehT ro’noitazioreZ‘ ’eciveDteseR‘ ecivres | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ro’noitazioreZ‘ | ’eciveDteseR‘ | ecivres | |||||||||||||||||||
| egarotS | )txetnialP( MAR | )txetnialP( MAR | )txetnialP( MAR | htiwdehsaH 652-2AHS CMMe | htiwdehsaH 652-2AHS CMMe | htiwdehsaH 652-2AHS CMMe | )txetnialP( MAR | )txetnialp( MAR | )txetnialp( MAR | ||||||||||||
| tnemhsilbatsE | A/N | A/N | A/N | A/N | A/N | A/N | A/N | A/N | A/N | ||||||||||||
| tsohaivyrtne A/N:tuptuO SEA:yrtnE detpyrcnE noitacilppa | tsohaivyrtne A/N:tuptuO SEA:yrtnE detpyrcnE noitacilppa | tsohaivyrtne A/N:tuptuO SEA:yrtnE detpyrcnE noitacilppa | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | |||||||||||||
| /tropmI | tropxE | ||||||||||||||||||||
| noitareneG | ybdetaerC otpyrC reciffO | ybdetaerC resU | ybdetaerC otpyrC reciffO | detareneG resUmorf drowssaP | yllanretnI PSmorf B09-008 yportnE ecruoS | A09-008PS yllanretnI GBRD morf | |||||||||||||||
| detareneG | OCmorf | drowssaP | detareneG | morf | yrevoceR | drowssaP | yllanretnI | PSmorf | B09-008 | yportnE | ecruoS | ||||||||||
| )8623A#.treC( FDKBP | )8623A#.treC( FDKBP | )8623A#.treC( FDKBP | )8623A#.treC( 652-2AHS | )8623A#.treC( 652-2AHS | )8623A#.treC( 652-2AHS | ecruoSyportnE )55E#.treC( | )8623A#.treC( GBRDCAMH | )8623A#.treC( GBRDCAMH | |||||||||||||
| noitcnuFytiruceS | rebmuN.treC& | ||||||||||||||||||||
| htgnertS | 631~8 otrefer( noitceS setyb )1.4 | 631~8 otrefer( noitceS setyb )1.4 | stib-821 | stib-821 | stib-821 | sihtgnerts stib4201 ytiruceS( )stib652 | sihtgnerts stib215 ytiruceS( )stib821 | A/N | |||||||||||||
| 631~8 | setyb | otrefer( | noitceS | )1.4 | |||||||||||||||||
| emaNPSC/yeK | drowssaPreciffOotpyrC | drowssaPresU | drowssaPyrevoceR | hsaHdrowssaPreciffOotpyrC | hsaHdrowssaPresU | hsaHdrowssaPyrevoceR | tupnIyportnE | ecnoNGBRD | etatSlanretnIGBRD )yeKdnaV( |
ehtetarenegotdesU
U_KEK
rofdesU
noitacitnehtuA
rofdesU
noitacitnehtuA
ottupniecnonsadesU
GBRDA09-008PSeht
nettirwrevO
sorezhtiw
yletaidemmi
esuretfa
ro’noitazioreZ‘
’eciveDteseR‘
ecivres
nettirwrevO
sorezhtiw
yletaidemmi
esuretfa
MAR
)txetnialP(
CMMe
htiwdehsaH
652-2AHS
CMMe
htiwdehsaH
652-2AHS
MAR
)txetnialp(
SEA:yrtnE
detpyrcnE
tsohaivyrtne
noitacilppa
A/N:tuptuO
A/N:yrtnE
A/N:tuptuO
A/N:yrtnE
A/N:tuptuO
A/N:yrtnE
A/N:tuptuO
ybdetaerC
resU
FDKBP
)8623A#.treC(
652-2AHS
)8623A#.treC(
652-2AHS
)8623A#.treC(
GBRDCAMH
)8623A#.treC(
stib215
ytiruceS(
sihtgnerts
)stib821
Key/CSP Name Strength Security Function Generation Import / Establishment Storage Zeroization Use & related SSPs & Cert. Number Export Crypto Officer Password 8 ~ 136 PBKDF Created by Entry: AES N/A RAM Overwritten Used to generate the bytes (Cert. #A3268) Crypto Encrypted (Plaintext) with zeros KEK_CO (refer to Officer entry via host immediately Section application after use 4.1) Output: N/A User Password 8 ~ 136 PBKDF Created by Entry: AES N/A RAM Overwritten Used to generate the bytes (Cert. #A3268) User Encrypted (Plaintext) with zeros KEK_U (refer to entry via host immediately Section application after use 4.1) Output: N/A Recovery Password 8 ~ 136 PBKDF Created by Entry: AES N/A RAM Overwritten User to generate the bytes (Cert. #A3268) Crypto Encrypted (Plaintext) with zeros KEK_R (refer to Officer entry via host immediately Section application after use 4.1) Output: N/A Crypto Officer Password Hash 128-bits SHA2-256 Generated Entry: N/A N/A eMMC ‘Zeroization’ or Used for (Cert. #A3268) from CO Output: N/A Hashed with ‘Reset Device’ Authentication Password SHA2-256 service User Password Hash 128-bits SHA2-256 Generated Entry: N/A N/A eMMC ‘Zeroization’ or Used for (Cert. #A3268) from User Output: N/A Hashed with ‘Reset Device’ Authentication Password SHA2-256 service Recovery Password Hash 128-bits SHA2-256 Generated Entry: N/A N/A eMMC ‘Zeroization’ or Used for (Cert. #A3268) from Output: N/A Hashed with ‘Reset Device’ Authentication Recovery SHA2-256 service Password Entropy Input 1024 bits Entropy Source Internally Entry: N/A N/A RAM Overwritten Used as entropy input (Security (Cert. #E55) from SP Output: N/A (Plaintext) with zeros to the SP 800-90A strength is 800-90B immediately DRBG 256 bits) Entropy after use Source DRBG Nonce 512 bits HMAC DRBG Internally Entry: N/A N/A RAM Overwritten Used as nonce input to (Security (Cert. #A3268) from SP Output: N/A (plaintext) with zeros the SP 800-90A DRBG strength is 800-90B immediately 128 bits) Entropy after use Source DRBG Internal State N/A HMAC DRBG Internally Entry: N/A N/A RAM ‘Zeroization’ or The internal state of (V and Key) (Cert. #A3268) from Output: N/A (plaintext) ‘Reset Device’ the SP 800-90A DRBG SP 800-90A service DRBG This document may be freely reproduced and distributed, but only in its entirety and without modification.
| sPSSdetaler&esU | lairetaMyeKnoisseS ehteviredotdesU | atadtpyrcneotsevres eruceSehtgnirud yeKnoisseSSEA .noisseS | etacitnehtuaotsevres eruceSehtgnirudatad yeKnoisseSCAM .noisseS | MORDCehtsetadilaV .noititrap | PSrepCSS-CCE-SAK( eludomehtybdesU tnemeergayekrof )3rA65-008 | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| eludomehtybdesU | tnemeergayekrof | repCSS-CCE-SAK( | )3rA65-008PS | eludomehtybdesU | tnemeergayekrof | PSrepCSS-CCE-SAK( | )3rA65-008 | |||||||||||||||
| noitazioreZ | nettirwrevO yletaidemmi sorezhtiw esuretfa | nettirwrevO sorezhtiw yletaidemmi erucesretfa detanimret ’noitazioreZ‘ sinoisses ecivres | detcetorp–A/N 4652-2AHShtiw | nettirwrevO yletaidemmi sorezhtiw desuretfa | ||||||||||||||||||
| nettirwrevO | sorezhtiw | yletaidemmi | esuretfa | nettirwrevO | sorezhtiw | yletaidemmi | erucesretfa | sinoisses | detanimret | ’noitazioreZ‘ | ecivres | nettirwrevO | sorezhtiw | yletaidemmi | desuretfa | |||||||
| egarotS | )txetnialp( MAR | )txetnialp( MAR | )txetnialp( MAR | )txetnialp( MAR | CMMe | )txetnialp( MAR | )txetnialp( MAR | |||||||||||||||
| tnemhsilbatsE | A/N | -CCE-SAKmorf terceSderahS )s0,e2(CCSS HDCCCE | ehtybdevireD petS-owTADK noitavireDyeK noitcnuF | ehtybdevireD yeKpetS-owT ADKaivKDK noitavireD noitcnuF | A/N | A/N | A/N | |||||||||||||||
| A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:tuptuO A/N:yrtnE | A/N:yrtnE txetnialP :tuptuO | A/N:tuptuO txetnialP :yrtnE | |||||||||||||||||
| /tropmI | tropxE | A/N:yrtnE | A/N:tuptuO | :yrtnE | gnirutcafunaM | A/N:tuptuO | ||||||||||||||||
| noitareneG | A/N | A/N | A/N | A/N | detareneG yllanretni GBRD morf | A/N | ||||||||||||||||
| yllanretnI | morf | A09-008PS | GBRD | |||||||||||||||||||
| neGyeKASDCE )8623A#.treC( | )8623A#.treC( ADK | )8623A#.treC( CBC-SEA | 652-2AHS-CAMH )8623A#.treC( | )8623A#.treC( 8402ASR | )8623A#.treC( CSS-CCE-SAK | )8623A#.treC( CSS-CCE-SAK | ||||||||||||||||
| noitcnuFytiruceS | rebmuN.treC& | neGyeKASDCE | )8623A#.treC( | |||||||||||||||||||
| htgnertS | sihtgnerts stib652 ytiruceS( )stib821 | sihtgnerts stib652 ytiruceS( )stib821 | sihtgnerts stib652 ytiruceS( )stib821 | 8402ASR )stib211( | 652(652-P )stib | 652(652-P )stib | ||||||||||||||||
| stib652 | ytiruceS( | sihtgnerts | )stib652 | |||||||||||||||||||
| emaNPSC/yeK | HDCEeciveD yeKetavirP | )Z(terceSderahS | yeKnoisseSSEA | yeKnoisseSCAM | yeKcilbuPetadpUDC | yeKcilbuPHDCEeciveD | yeKcilbuPHDCEtsoH |
yeKnoisseSSEA
atadtpyrcneotsevres
eruceSehtgnirud
.noisseS
MORDCehtsetadilaV
.noititrap
detcetorp–A/N
4652-2AHShtiw
MAR
)txetnialp(
MAR
)txetnialp(
MAR
)txetnialp(
ehtybdevireD
petS-owTADK
noitavireDyeK
noitcnuF
A/N:yrtnE
A/N:tuptuO
:yrtnE
txetnialP
A/N:tuptuO
CBC-SEA
)8623A#.treC(
8402ASR
)8623A#.treC(
CSS-CCE-SAK
)8623A#.treC(
stib652
ytiruceS(
sihtgnerts
)stib821
8402ASR
)stib211(
652(652-P
)stib
HDCEeciveD
yeKetavirP
Key/CSP Name Strength Security Function Generation Import / Establishment Storage Zeroization Use & related SSPs & Cert. Number Export Device ECDH 256 bits ECDSA Key Gen Internally Entry: N/A N/A RAM Overwritten Used by the module Private Key (Security (Cert. #A3268) from Output: N/A (plaintext) with zeros for key agreement strength is SP 800-90A immediately (KAS-ECC-SSC per 256 bits) DRBG after use SP 800-56Ar3) Shared Secret (Z) 256 bits KDA N/A Entry: N/A Shared Secret RAM Overwritten Used to derive the (Security (Cert. #A3268) Output: N/A from KAS-ECC- (plaintext) with zeros Session Key Material strength is SSC C(2e, 0s) immediately 128 bits) ECC CDH after use AES Session Key 256 bits AES-CBC N/A Entry: N/A Derived by the RAM Overwritten AES Session Key (Security (Cert. #A3268) Output: N/A KDA Two-Step (plaintext) with zeros serves to encrypt data strength is Key Derivation immediately during the Secure 128 bits) Function after secure Session. session is terminated ‘Zeroization’ service MAC Session Key 256 bits HMAC-SHA2-256 N/A Entry: N/A Derived by the RAM Overwritten MAC Session Key (Security (Cert. #A3268) Output: N/A KDK via KDA (plaintext) with zeros serves to authenticate strength is Two-Step Key immediately data during the Secure 128 bits) Derivation after secure Session. Function session is terminated ‘Zeroization’ service CD Update Public Key RSA 2048 RSA 2048 N/A Entry: N/A eMMC N/A – protected Validates the CD ROM (112 bits) (Cert. #A3268) Manufacturing with SHA2-256 4 partition. Output: N/A Device ECDH Public Key P-256 (256 KAS-ECC-SSC Generated Entry: N/A N/A RAM Overwritten Used by the module bits) (Cert. #A3268) internally Output: (plaintext) with zeros for key agreement from Plaintext immediately (KAS-ECC-SSC per SP DRBG after used 800-56Ar3) Host ECDH Public Key P-256 (256 KAS-ECC-SSC N/A Entry: N/A RAM Overwritten Used by the module bits) (Cert. #A3268) Plaintext (plaintext) with zeros for key agreement Output: N/A immediately (KAS-ECC-SSC per SP after used 800-56Ar3)
4 Per IG 9.6.A
This document may be freely reproduced and distributed, but only in its entirety and without modification.
| AlgorithmorTest | TestProperties | TestMethod | Type | Indicator | Details | ||||
|---|---|---|---|---|---|---|---|---|---|
| Firmware IntegrityTest | Firmware | RSA2048PKCS1v1.5Digital SignatureVerification | RSA2048PKCS1v1.5Digital | RSA2048Digital SignatureVerification | RSA2048Digital | SW/FW Integrity | SW/FW | Success:LED | Performedduring modulepower-on, on-demand,andona periodicbasis |
| IntegrityTest | SignatureVerification | SignatureVerification | Integrity | blinksat3Hz Error:LED blinksat16Hz |
| Algorithm orTest | Test Properties | TestMethod | Type | Indicator | Details | Conditionsfor Performing Test |
|---|---|---|---|---|---|---|
| AESCBC | 256-bit | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | EncryptKAT DecryptKAT | Power-on& Periodically (11mins) |
| AESECB | 256-bit | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | EncryptKAT DecryptKAT | Power-on& Periodically (11mins) |
| AESKW | 256-bit | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | KeyWrapKAT KeyUnwrapKAT | Power-on& Periodically (11mins) |
| AESXTS | 256-bit | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | EncryptKAT DecryptKAT | Power-on& Periodically (11mins) |
| AES-XTSKey Gen (Ref:IGC.I) | XTSKey Validity | -- | -- | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | Key1≠Key2 | Generationof DEK_COor DEK_U |
The module performs pre-operational self-tests and conditional self-tests (refer to Section 10.2). Both self-tests ensure that the module is not corrupted, and the cryptographic algorithms work as expected. During self-tests, data output (via the data output interface) is inhibited. The module services are not available until the self-tests have completed successfully. Table 20 – Pre-Operational Self-Tests Firmware RSA 2048 PKCS1 v1.5 Digital RSA 2048 Digital SW / FW Success: LED Performed during Integrity Test Signature Verification Signature Verification Integrity blinks at 3Hz module power-on, blinks at 16Hz periodic basis For the above error case, the device can be powered cycle to reinitiate the power-up self-tests. Please note: An RSA signature verification known-answer test (KAT) is performed prior to the
Table 21 – Conditional Self-Tests at 3Hz Decrypt KAT Periodically Error: LED blinks at (11 mins) at 3Hz Decrypt KAT Periodically Error: LED blinks at (11 mins) at 3Hz Key Unwrap KAT Periodically Error: LED blinks at (11 mins) at 3Hz Decrypt KAT Periodically Error: LED blinks at (11 mins) AES-XTS Key XTS Key -- -- Success: LED blinks Key1≠ Key2 Generation of Gen Validity at 3Hz DEK_CO or (Ref: IG C.I) Error: LED blinks at DEK_U This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Algorithm orTest | Test Properties | TestMethod | Type | Indicator | Details | Conditionsfor Performing Test |
|---|---|---|---|---|---|---|
| DRBG | Instantiate, Generateand Reseed5 | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | InstantiateKAT GenerateKAT | Power-on& Periodically (11mins) |
| ECCCDHP- 256 | ECCCDHP- 256keypair pairwise consistency test. | PCT | PCT | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | Performed immediatelyafterkey generationduring keyagreement | ECCCDH keypair generation duringkey agreement when‘Open Partition’ serviceis called. |
| ECCCDHP- 256 | ECCCDHP- 256Public Key Validation | PKV | PKV | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | FullPublicKey Validationofhost publickey | Partofkey agreement when‘Open Partition’ serviceis called. |
| Entropy Source | N/A | APT/RCT | APT | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | AdaptiveProportion Test | Continuous |
| HMAC- SHA2-256 | 256-bit | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | HMACKAT | Power-on& Periodically (11mins) |
| KAS-ECC- SSC | Private | KAT | CAST | Success:LEDblinks | Comparesoutput withexpectedresult | Power-on& Periodically (11mins) |
| Key:256-bit | at3Hz | |||||
| PublicKey: | Error:LEDblinksat | |||||
| 256-bit | 16Hz | |||||
| KDA | SharedSecret: 256-bit | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | Comparesoutput withexpectedresult | Power-on& Periodically (11mins) |
| PBKDF | Salt256-bit, Password:8- bytes | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | Comparesoutput withexpectedresult | Power-on& Periodically (11mins) |
| SHA2-256 | N/A | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | SHA2-256KAT | Power-on& Periodically (11mins) |
| RSA-2048 | RSA2048& SHA2-256 | KAT | CAST | Success:LEDblinks at3Hz Error:LEDblinksat 16Hz | SignatureVerification KAT | Power-on& Periodically (11mins) |
Generate and at 3Hz Generate KAT Periodically Reseed 5 Error: LED blinks at (11 mins) ECC CDH P- ECC CDH P- PCT PCT Success: LED blinks Performed ECC CDH 256 256 keypair at 3Hz immediately after key keypair pairwise Error: LED blinks at generation during generation service is ECC CDH P- ECC CDH P- PKV PKV Success: LED blinks Full Public Key Part of key 256 256 Public at 3Hz Validation of host agreement Key Error: LED blinks at public key when ‘Open service is Entropy N/A APT/RCT APT Success: LED blinks Adaptive Proportion Continuous Source at 3Hz Test Error: LED blinks at Error: LED blinks at (11 mins) SSC Key:256-bit at 3Hz with expected result Periodically Public Key: Error: LED blinks at (11 mins) KDA Shared Secret: KAT CAST Success: LED blinks Compares output Power-on & 256-bit at 3Hz with expected result Periodically Error: LED blinks at (11 mins) Password: 8- at 3Hz with expected result Periodically bytes Error: LED blinks at (11 mins) at 3Hz Periodically Error: LED blinks at (11 mins) Error: LED blinks at (11 mins)
The module performs all self-tests automatically (with no operator intervention) every 11 minutes after being powered-on.
This document may be freely reproduced and distributed, but only in its entirety and without modification.
| StateName | Description | Conditions | RecoveryMode | Indicator | |
|---|---|---|---|---|---|
| HardError | HardErrorState | Transitionstothisstate | Power-Cycle | LEDBlinkPattern, | |
| forallself-testerrors | ErrorCode. | ||||
| SoftError | SoftErrorState | Transitionstothisstate | Automatic | LEDBlinkPattern, ErrorCode. | LEDBlinkPattern, |
| forallnon-critical errors | ErrorCode. |
The module supports the following error states: Table 22 – Error States State Name Description Conditions Recovery Mode Indicator Hard Error Hard Error State Transitions to this state Power-Cycle LED Blink Pattern, for all self-test errors Error Code. Soft Error Soft Error State Transitions to this state Automatic LED Blink Pattern, for all non-critical Error Code. The module transitions into an error state when an error condition is encountered and provides an unambiguous error status indicator (i.e., blinking LED and error code). All data output is inhibited while the module is in the error state.
The operator can initiate the self-tests at any time by power-cycling the module or via the ‘Perform Self-Tests’ command. 11. LIFE-CYCLE ASSURANCE
The User must configure and enforce the following initialization procedures:
Upon receipt of the module an operator must follow the initialization procedure outlined in Section 11.1. This establishes the operator as the Cryptographic Officer (CO) with a valid ID and password. The module is designed to securely store authorized user’s data files using physical and logical security methods. A user may transfer files to the device via a compatible PC or similar device. Over the life of the device an operator may: − Initialize the device as a single operator (CO only). − Initialize the device for multiple operators (CO and User). − Transfer files to the device for secure storage. − Reset the device effectively erasing all data and security parameters. Services available to the CO role are listed in Table 12.
The cryptographic officer must establish access for additional operators. Additional operators will be assigned to the User role. An operator under the User role shall authenticate and transfer files to the device via a compatible PC or similar device. Services available to the User role are listed in Table 12.
In the approved mode of operation, the module shall adhere to the following rules:
Upon the need to decommission the module, the CO should perform a ‘Reset Drive’ operation to securely overwrite all security parameters which makes all stored data unrecoverable. The module can then be repurposed or physically scrapped. 12. MITIGATION OF OTHER ATTACKS This module is not designed to mitigate other attacks beyond the scope of FIPS 140-3 requirements. This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Reference Number | ReferenceTitle | Publishing Entity | Publication Date |
|---|---|---|---|
| 1 | ISO/IEC19790–Securityrequirementsforcryptographic modules | ISO/IEC | 2015 |
| 2 | ISO/IEC24759–Testrequirementsforcryptographicmodules | ISO | 2015 |
| 3 | FIPS140-3–Securityrequirementsforcryptographic equipment | NIST | 2019 |
| 4 | SP800-140–FIPS140-3DerivedTestRequirements(DTR) | NIST | 2020 |
| 5 | SP800-140A–CMVPDocumentationRequirements | NIST | 2020 |
| 6 | SP800-140B–CMVPSecurityPolicyRequirements | NIST | 2022 |
| 7 | SP800-140C–CMVPApprovedSecurityFunctions | NIST | 2023 |
| 8 | SP800-140D–CMVPApprovedSensitiveSecurityParameter GenerationandEstablishmentMethods | NIST | 2023 |
| 9 | SP800-140E–CMVPApprovedAuthenticationMechanisms | NIST | 2020 |
| 10 | SP800-140F–CMVPApprovedNon-InvasiveAttackMitigation TestMetrics | NIST | 2020 |
13. APPENDIX A: REFERENCES Table 23 – References
1 ISO/IEC 19790 – Security requirements for cryptographic ISO/IEC 2015 2 ISO/IEC 24759 – Test requirements for cryptographic modules ISO 2015 3 FIPS 140-3 – Security requirements for cryptographic NIST 2019 4 SP 800-140 – FIPS 140-3 Derived Test Requirements (DTR) NIST 2020 5 SP 800-140A – CMVP Documentation Requirements NIST 2020 6 SP 800-140B – CMVP Security Policy Requirements NIST 2022 7 SP 800-140C – CMVP Approved Security Functions NIST 2023 8 SP 800-140D – CMVP Approved Sensitive Security Parameter NIST 2023
Generation and Establishment Methods
9 SP 800-140E – CMVP Approved Authentication Mechanisms NIST 2020 10 SP 800-140F – CMVP Approved Non-Invasive Attack Mitigation NIST 2020
Test Metrics This document may be freely reproduced and distributed, but only in its entirety and without modification.
| Term | Definition |
|---|---|
| ANSI | AmericanNationalStandardsInstitute |
| CMVP | CryptographicModuleValidationProgram |
| CSEC | CommunicationsSecurityEstablishmentofCanada |
| CSP | CriticalSecurityParameter |
| DRBG | DeterministicRandomBitGenerator |
| DTR | DerivedTestRequirements |
| ECB | ElectronicCodebook |
| FIPS | FederalInformationProcessingStandards |
| GPC | GeneralPurposeComputer |
| GUI | GraphicalUserInterface |
| HMAC | HashedMessageAuthenticationCode |
| KAT | KnownAnswerTest |
| NIST | NationalInstituteofStandardsandTechnology |
| NVRAM | Non-VolatileRandomAccessMemory |
| PBKDF | Password-BasedKeyDerivationFunction |
| RNG | RandomNumberGenerator |
| RSA | RivestShamirAdelman |
| SHA | SecureHashAlgorithm |
| USB | UniversalSerialBus |
| 14. | APPENDIX B: ABBREVIATIONS AND DEFINITIONS Table 24 – Abbreviations and Definitions |
| ANSI | American National Standards Institute |
| CMVP | Cryptographic Module Validation Program |
| CSEC | Communications Security Establishment of Canada |
| CSP | Critical Security Parameter |
| DRBG | Deterministic Random Bit Generator |
| DTR | Derived Test Requirements |
| ECB | Electronic Codebook |
| FIPS | Federal Information Processing Standards |
| GPC | General Purpose Computer |
| GUI | Graphical User Interface |
| HMAC | Hashed Message Authentication Code |
| KAT | Known Answer Test |
| NIST | National Institute of Standards and Technology |
| NVRAM | Non-Volatile Random Access Memory |
| PBKDF | Password-Based Key Derivation Function |
| RNG | Random Number Generator |
| RSA | Rivest Shamir Adelman |
| SHA | Secure Hash Algorithm |
| USB | Universal Serial Bus This document may be freely reproduced and distributed, but only in its entirety and without modification. |