All modules
CMVP Validated Module · FIPS 140-3 Security Policy

ASTRO CDEM Motorola Advanced Crypto Engine (MACE)

Certificate#5143StandardFIPS 140-3Level3TypeHardwareEmbodimentSingle ChipStatusActiveVendorMotorola Solutions, Inc.
Medium review priority  ·  exposes firmware-update authentication, HSM/SE firmware trust anchor  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level3
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date1/22/2031
CaveatWhen installed, initialized and configured as specified in Section 11 of Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorMotorola Solutions, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for ASTRO CDEM Motorola Advanced Crypto Engine (MACE)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for ASTRO CDEM Motorola Advanced Crypto Engine (MACE)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Motorola Solutions, Inc. ASTRO CDEM Motorola Advanced Crypto Engine (MACE) Document Version: R01.00.00 Date: January 16, 2025 Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 2
Table of Contents
#SectionPage
Page 3

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware8
Table 3 – Approved Mode Drop-in Algorithms8
Table 4: Modes List and Description9
Table 5: Approved Algorithms10
Table 6: Vendor-Affirmed Algorithms10
Table 7: Non-Approved, Allowed Algorithms with No Security Claimed11
Table 8: Security Function Implementations13
Table 9: Entropy Certificates14
Table 10: Entropy Sources14
Table 11: Ports and Interfaces16
Table 12: Authentication Methods18
Table 13: Roles18
Table 14: Approved Services25
Table 15: Mechanisms and Actions Required29
Table 16: EFP/EFT Information29
Table 17: Hardness Testing Temperatures30
Table 18: Storage Areas32
Table 19: SSP Input-Output Methods32
Table 20: SSP Zeroization Methods33
Table 21: SSP Table 135
Table 22: SSP Table 237
Table 23: Pre-Operational Self-Tests38
Table 24: Conditional Self-Tests40
Table 25: Pre-Operational Periodic Information40
Table 26: Conditional Periodic Information41
Table 27: Error States42
Table 28 References45
Table 29 Acronyms and Definitions45
Figure 1 – ASTRO CDEM MACE IC (Top)6
Figure 2 – ASTRO CDEM MACE IC (Interfaces)7
Figure 3 – Cryptographic Boundary7
Page 5
SectionTitleSecurity Level
1General3
2Cryptographic module specification3
3Cryptographic module interfaces3
4Roles, services, and authentication3
5Software/Firmware security3
6Operational environmentN/A
7Physical security3
8Non-invasive securityN/A
9Sensitive security parameter management3
10Self-tests3
11Life-cycle assurance3
12Mitigation of other attacksN/A
Overall Level3

requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-

1.2 Security Levels

The FIPS 140-3 security levels for the Module are as follows from Table 1: Table 1: Security Levels Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 6

2 – Cryptographic Module Specification

This document covers the Motorola Solutions ASTRO CDEM MACE module, hereafter denoted as the Module. The Module is implemented as a single-chip cryptographic module to meet FIPS 140-3 level 3 physical security requirements as defined by FIPS 140-3. The ASTRO CDEM MACE provides key storage and generation and performs all crypto processing for the Motorola Solutions ASTRO CDEM product.

2.1 Description

Purpose and Use: The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated overall Security Level

  1. The Module is intended to be used in ASTRO CDEM unit. Module Type: Hardware Module Embodiment: SingleChip Cryptographic Boundary: The physical form of the Module is depicted in Figure 1 and Figure
  2. The Module is a single-chip embedded embodiment. The cryptographic boundary is shown in Figure
  3. Figure 1 – ASTRO CDEM MACE IC (Top) Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
Page 7
Table, extracted as text (did not parse into structured rows)
Figure 2 – ASTRO CDEM MACE IC (Interfaces) Power IRQ/FIQ Clock ASTRO CDEM MACE RAM Interface Reset     Tamper         SSI         Ethernet    RS232         KVL       Front Panel LED Indicators: Alarm, Interface Interface      Interface   Port        Interface     Interface Power, Ready, Tx Clear, Status Figure 3 – Cryptographic Boundary Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
Page 8
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
ASTRO CDEM MACE5185912Y03, 5185912Y05, 5185912T05R03.01.02 with AES-256 DIA R01.00.07Motorola Advanced Crypto Engine (MACE)N/A
Algorithm*Algorithm FW VersionBase FW VersionCert. #
AES256R01.00.07R03.01.02A5275
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

The module does not exclude any components from the cryptographic boundary.

2.4 Modes of Operation

Modes List and Description: Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 9
Mode NameDescriptionTypeStatus Indicator
approvedOperating in approved modeApprovedDisplay output

Table 4: Modes List and Description The ASTRO CDEM MACE is originally non-compliant and must be configured to operate in an approved mode of operation. The MACE must be installed, initialized and configured, including a required change of the factory-default password in order to be in an approved mode. Documented below are the additional configuration settings that are required for the MACE to be used in an Approved Mode of operation at overall Security Level

  1. The approved mode is indicated by using the “Set FIPS Mode” service. The result from this service will Encrypted only Key fill is Enabled. Module is operating in FIPS 140-3 Level 3 approved mode When the module is in the approved operating mode, the “Module Status” service can be used to verify the firmware version matches an approved version listed on NIST’s website: https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules Mode Change Instructions and Status: The module can be configured to operate in a FIPS 140-3 Approved mode of operation at overall Security Level
  2. To configure the module to operate in Approved mode, the operator must log in as the CO using the default password and:
  3. Change the default password
  4. Activate and configure the periodic self-test timer
  5. Type the command “fips enable” to configure the Module into approved mode(Level 3). Additionally, the Module supports a “drop-in algorithm” via the Program Update service. Drop-in algorithms may be added or removed from the Module independent of the base FW. In order to remain in the Approved Mode, only Approved algorithms may be loaded into the Module, in particular AES-256 (Cert. # A5275). The loading and unloading of any firmware within the validated cryptographic module invalidates the Module’s validation and zeroizes all SSPs except those entered at manufacturing. The Module is then in a non-compliant state. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
Page 10
AlgorithmCAVP CertPropertiesReference
AES-CBCA5273Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-CBCA5275Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-CFB8A5273Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5275Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-KWA5438Direction - Decrypt Key Length - 256SP 800-38F
AES-OFBA5273Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-OFBA5275Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
Counter DRBGA5437Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
RSA SigVer (FIPS186-5)A5253Modulo - 2048 Signature Type - pkcs1v1.5FIPS 186-5
SHA2-256SHS 817Message Length - Message Length: 0- 51200 Increment 8FIPS 180-4
NamePropertiesImplementationReference
CKGKey Type:SymmetricN/ASP800-133rev2 Sections 4 example 1 and IG D.H
CKG - IDKKey Type:SymmetricN/ASP800-133rev2 Sections 6.3 #2 and IG C.I
2.5 Algorithms

Approved Algorithms: The Module implements the Approved cryptographic algorithms listed in the table below. Table 5: Approved Algorithms ApprovedAlgorithmsTable From Web Cryptik ApprovedAlgorithmsTable Vendor-Affirmed Algorithms: The Module implements the FIPS Vendor Affirmed cryptographic algorithms listed. N/A Table 6: Vendor-Affirmed Algorithms Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 11
NameCaveatUse and Function
AES MACNo Security Claimed. AES MAC is used as part of OTAR but is considered obfuscation.[IG 2.4.A] P25 AES OTAR. AES MAC is applied directly to the plaintext OTAR key components and then KTS encryption is performed on the OTAR key components and decrypted within the module using AES KW Cert #5438

Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: The Module implements the FIPS Non-Approved, Allowed cryptographic Algorithms with No Security Table 7: Non-Approved, Allowed Algorithms with No Security Claimed Non-Approved, Not Allowed Algorithms: N/A for this module. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 12
NameTypeDescriptionPropertiesAlgorithms
AES A5275 EncryptionBC-UnAuthEncryptBlock CipherAES-CBC: (A5275) AES-OFB: (A5275) AES-ECB: (A5275)
AES A5275 DecryptionBC-UnAuthDecryptBlock CipherAES-CBC: (A5275) AES-OFB: (A5275) AES-ECB: (A5275)
Key GenerationCKGSymmetric Key GenerationCounter DRBG: (A5437) CKG : ()
Signature VerificationDigSig-SigVerDigital Signature VerificationRSA SigVer (FIPS186- 5): (A5253)
EntropyENT-ESVEntropy Source
KTS-UnwrapKTS-UnwrapKey Transport UnwrappingCaveat:Key establishment methodology provides 256 bits strength Standard:SP 800-38F IG D.G:Approved method in KW modeAES-KW: (A5438) AES MAC: ()
SHASHASecure Hash StandardSHA2-256: (SHS 817)
AES A5273 EncryptionBC-UnAuthEncryptBlock CipherAES-CFB8: (A5273) AES-CBC: (A5273) AES-OFB: (A5273)
AES A5273 DecryptionBC-UnAuthDecryptBlock CipherAES-CFB8: (A5273) AES-CBC: (A5273) AES-OFB: (A5273)
IDK GenerationCKGSymmetric Key GenerationCKG - IDK: ()
2.6 Security Function Implementations

The following table shows the Security Function Implementations that the module implements: Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 13
NameTypeDescriptionPropertiesAlgorithms
DRBGDRBGAES-256 CTR Deterministic RBGCounter DRBG: (A5437)

Table 8: Security Function Implementations Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 14
Cert NumberVendor Name
E132Motorola Solutions Inc
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Motorola Solutions Advanced Crypto Engine Entropy SourcePhysicalAtmel 51869121 bit0.13862N/A
2.7 Algorithm Specific Information

The module does not have any algorithm specific information.

2.8 RBG and Entropy

Table 9: Entropy Certificates The Module uses the following entropy sources: Table 10: Entropy Sources

2.9 Key Generation

For Key Generation methods, see Section 2.6 Security Function Implementations above.

2.10 Key Establishment

For Key Establishment methods, see Section 2.6 Security Function Implementations above.

2.11 Industry Protocols

The module does not implement any Industry Protocols Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 15
Physical PortLogical Interface(s)Data That Passes
Synchronous Interface (SSI)Data Input Data Output Control Input Status OutputProvides an interface to the unprotected network and entry of the Crypto Officer password in encrypted form.
Ethernet Port (EP)Data Input Data Output Control Input Status OutputThis interface routes packets between subnets. The IP stack of this interface will use the subnet information to determine how to route packets between physical network interfaces.
RS232 InterfaceData Output Control Input Status OutputProvides an interface for factory programming and execution of RS232 shell commands.
Key Variable Loader (KVL)Data Input Data Output Control Input Status OutputProvides an interface to the Key Variable Loader. The Traffic Encryption Key (TEK) is entered in encrypted form over the KVL interface.
RAMData Input Data Output Control Input Status OutputThis interface provides storage for non-security related stack information.
PowerPowerThis interface powers all circuitry.
Tamper InterfaceControl InputThe interface is used for zeroization of Traffic Encryption Keys (TEKs), KPK.
Reset InterfaceControl InputThis interface forces a reset of the module.
Alarm LED outputStatus OutputThe Alarm LED output is used to drive the external Alarm LED red to indicate a fatal error has been detected.
Power LED outputStatus OutputThe Power LED output is used to drive the external Power LED green when power is supplied to the module.

The Module’s ports and associated FIPS defined logical interface categories are listed below. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 16
Physical PortLogical Interface(s)Data That Passes
Ready LED outputStatus OutputThe Ready LED output is used to drive the external Ready LED green when the module is ready to communicate with a KVL.
TX Clear LED outputStatus OutputThe TX Clear LED output is used to drive the external TX Clear LED orange when a "Bypass Rule" is programmed.
Status LED outputStatus OutputThe Status LED output is used to drive the external Status LED green to indicate a good battery, and a Traffic Encryption Key (TEK) has been loaded. The Status LED output is used to drive the external Status LED yellow to indicate a good battery, but no Traffic Encryption Key (TEK) has been loaded. The Status LED output is used to drive the external Status LED red to indicate a low or dead battery.
IRQ/FIQControl InputExternal interrupts.
ClockControl InputClock input

Table 11: Ports and Interfaces Note: The module does not support Control Output. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 17
Metho d NameDescriptionSecurity Mechanis mStrength Each AttemptStrength per Minute
AM1Identity- based. Crypto-Officer Password: a 15-16 ASCII (printable) characters password is authenticated to gain access to Crypto- Officer services assocaited to the RS232 Interface. It should be noted that after authenticating , this password may be changed at any time.SHA2-256 (SHS 817)The password requires a minimum of 1 Upper case, 1 Lower case, 1 Numerical and 1 special character. Since the minimum password length is 15 ASCII printable characters and there are 95 ASCII printable characters, the probability of a successful random attempt is 1 in {(10)*(262)*(32)*(9511)}, The password requires a minimum of 1 Upper case, 1 Lower case, 1 Numerical and 1 special character. Since the minimum password length is 15 ASCII printable characters and there are 95 ASCII printable characters, the probability of a successful random attempt is 1 in {(10)*(262)*(32)*(95^11) }After the CO password has been incorrectly entered 10 consecutive times, the Module will erase all CSPs, reset the CO password back to the default and set an alarm, at which time the module must be power cycled to become operational again. The strength per minute is 10 in {(10)*(262)*(32)*(95^11) }
AM2Identity based. Crypto-Officer Password: a 10 hexadecimal digit long password is authenticated to gain access to CryptoSHA2-256 (SHS 817)The minimum password length is 10 hex digits. The probability of a successful random attempt is 10^16After the CO password has been incorrectly entered 15 consecutive times, the Module will erase all CSPs, and set an alarm, at which time the module must be power cycled to become operational again. The strength per minute is 15x10^16.
4 Roles, Services, and Authentication
4.1 Authentication Methods

} Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 18

Metho d Name

Description Officer services associated to the Synchronous Interface (SSI) port. It should be noted that after authenticating , this password may be changed at any time.

Security Mechanis m

Strength Each Attempt

Strength per Minute

NameTypeOperator TypeAuthentication Methods
Crypto-Officer (AM1)IdentityCOAM1
Crypto-Officer (AM2)IdentityCOAM2
4.2 Roles

The Module supports one distinct operator role, the Cryptographic Officer (CO). The authentication method and services available to the CO will depend on the physical port used. The CO may be logged into both ports at the same time. In addition, the Module supports services which do not require authentication (UA). The Roles Table below lists all operator roles supported by the Module. The Module does not support concurrent operators. Table 13: Roles

4.3 Approved Services

All approved services implemented by the Module are listed in the table below: The SSPs modes of access shown in the table below are defined as:

G = Generate: The Module generates or derives the SSP.
R = Read: The SSP is read from the Module (e.g., the SSP is output).
W = Write: The SSP is updated, imported, or written to the Module (SSP is input).
E = Execute: The Module uses the SSP in performing a cryptographic operation.

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 19
NameDescriptio nIndicat orInputsOutputsSecurity Functio nsSSP Access
Program UpdateUpdate the ASTRO CDEM MACE firmware. Firmware upgrades are authenticat ed using a digital signature. The Program Update Public Signature Key is used to validate the signature of the firmware image being loaded before it is allowed to be executed using AM2.Approv ed mode indicat or and service status outputFirmware ImageThe ASTRO CDEM MACE is upgraded to new firmware.AES A5273 Decrypti on IDK Generati onCrypto- Officer (AM2) - FW-LD- Pub: Z - BKK: Z - IDK: Z - PEK: Z - KPK: Z - KEK: Z - TEK: Z - IDK-ROM: Z - IDK-Block: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z
Generate EntropyGenerate Entropy into the ASTRO CDEM MACE using AM2.Approv ed mode indicat or and service status outputDRBG SeedThe DRBG is seeded and initialized. Success/fail ure statusEntropyCrypto- Officer (AM2) - DRBG- EI/Seed: G - DRBG- State: G - DRBG- nonce: G
OTEKLoad keys into the ASTRO CDEMApprov ed mode indicat or andEncrypted KeysDecrypted keys that were imported encryptedAES A5273 Decrypti onCrypto- Officer (AM2) - KEK: E - TEK: E
Page 20
NameDescriptio n MACE using AM2.Indicat or service status outputInputsOutputs into the ASTRO CDEM MACE. Success/fail ure status.Security Functio nsSSP Access
Change CO Password (AM1)Modify the current password used to identify and authenticat e the CO role using AM1.Approv ed mode indicat or and service status outputPasswordUpdated the CO password. Success/fail ure statusSHA AES A5273 Encrypti on AES A5273 Decrypti onCrypto- Officer (AM1) - PEK: E - KPK: G,E,Z - KEK: Z - TEK: Z - CO PWD (AM1): G,E,Z - PWD Hash: G,E,Z
Change CO Password (AM2)Modify the current password used to identify and authenticat e the CO role using AM2.Approv ed mode indicat or and service status outputPasswordUpdated the CO password. Success/fail ure status.SHA AES A5273 Encrypti on AES A5273 Decrypti onCrypto- Officer (AM2) - PEK: E - KPK: G,E,Z - KEK: Z - TEK: Z - CO PWD (AM2): G,E,Z - PWD Hash: G,E,Z
Validate CO Password (AM1)Validate the current password used to identify and authenticat e the CO role using AM1.Approv ed mode indicat or and service status output Approv ed mode indicat or and service status outputPasswordSuccessful authenticatio n will allow access to the services allowed for CO role (AM1).SHA AES A5273 Encrypti on AES A5273 Decrypti onCrypto- Officer (AM1) - PEK: E - KPK: G,E,Z - KEK: Z - TEK: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z

G,E,Z G,E,Z Z Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 21
NameDescriptio nIndicat orInputsOutputsSecurity Functio nsSSP Access
Validate CO Password (AM2)Validate the current password used to identify and authenticat e the CO role using AM2.Approv ed mode indicat or and service status outputPasswordSuccessful authenticatio n will allow access to the services allowed for CO role (AM2).SHA AES A5273 Encrypti on AES A5273 Decrypti onCrypto- Officer (AM2) - PEK: E - KPK: G,E,Z - KEK: Z - TEK: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z
Logout CO (AM1)Exits command shell interface using AM1.Approv ed mode indicat or and service status outputCommand InLogout CO/Exits command shell interfaceNoneCrypto- Officer (AM1)
Logout CO (AM2)CO LogoutApprov ed mode indicat or and service status outputReboot/Comm and InLogout CONoneCrypto- Officer (AM2)
EncryptEncrypt data using AM2.Approv ed mode indicat or and service status outputPlaintextCiphertext. Success/fail ure status.AES A5275 Encrypti onCrypto- Officer (AM2) - TEK: E - KEK: E - KPK: E - DRBG- EI/Seed: E - DRBG- State: E - DRBG- nonce: E
DecryptDecrypt data using AM2.Approv ed mode indicat or and serviceCiphertextPlaintext. Success/fail ure status.AES A5275 Decrypti onCrypto- Officer (AM2) - TEK: E - KEK: E - KPK: E

Z Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 22
NameDescriptio nIndicat or status outputInputsOutputsSecurity Functio nsSSP Access
Module StatusProvide firmware version, current FIPS status using AM1.Approv ed mode indicat or and service status outputCommand inModule HW version, version information, and FIPS status.NoneCrypto- Officer (AM1)
Self-TestsPerform module self-tests comprised of cryptograph ic algorithm tests, firmware integrity test, and critical functions test. Initiated by module reset or transition from power off state to power on state using AM1 or UA.Approv ed mode indicat or and service status outputPower on/Command InSuccess/Re set.AES A5275 Encrypti on AES A5275 Decrypti on Key Generati on Signatur e Verificati on Entropy KTS- Unwrap SHA AES A5273 Encrypti on AES A5273 Decrypti on IDK Generati on DRBGCrypto- Officer (AM1) - FW-LD- Pub: E Unauthentic ated - FW-LD- Pub: E
Module Configurat ionSet configuratio n parameters used to specifyApprov ed mode indicat or and serviceConfiguration parametersUpdated module configuratio n. Success/fail ure status.NoneCrypto- Officer (AM1) - KPK: G,E,Z - KEK: Z - TEK: Z

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 23
NameDescriptio n module behavior using AM1.Indicat or status outputInputsOutputsSecurity Functio nsSSP Access - CO PWD (AM1): W,Z - PWD Hash: W,Z - CO PWD (AM2): W,Z
Set FIPS ModeUpdate module approved mode using AM1.Approv ed mode indicat or and service status outputConfiguration parametersUpdated module approved mode/Displa y current approved modeNoneCrypto- Officer (AM1)
Configure OTEKSet configuratio n parameters used for communicat ion with the KMF for OTEK using AM1.Approv ed mode indicat or and service status outputConfiguration parametersUpdated OTEK configuratio n. Success/fail ure status.NoneCrypto- Officer (AM1)
Version QueryProvides module firmware and hardware version numbers using AM1.Approv ed mode indicat or and service status outputCommand InShow module version infoNoneCrypto- Officer (AM1)
Delete KeyMark key for deletion using AM2.Approv ed mode indicat or and service status outputCommand InKey is marked for deletion. Success/fail ure status.NoneCrypto- Officer (AM2)
Perform Key Transport ProcessPerform a key transport process for OTEK service using AM2.Approv ed mode indicat or and serviceCommand InKeys imported into the MACE. Success/fail ure status.KTS- Unwrap AES A5273 Decrypti onCrypto- Officer (AM2) - KEK: W

W,Z Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 24
NameDescriptio nIndicat or status outputInputsOutputsSecurity Functio nsSSP Access
KVL Transfer KeyImports keys to the ASTRO CDEM MACE via KVL using AM2.Approv ed mode indicat or and service status outputEncrypted KeysKeys imported into the ASTRO CDEM MACE. Success/fail ure status.KTS- UnwrapCrypto- Officer (AM2) - BKK: E - KPK: E - KEK: W - TEK: W
KVL Delete KeyZeroize selected key variables from the ATRO CDEM MACE using AM2.Approv ed mode indicat or and service status outputCommand InKeys deleted from the ASTRO CDEM MACE. Success/fail ure status.NoneCrypto- Officer (AM2) - KEK: Z - TEK: Z
KVL Check KeyObtain status information about a specific key/keyset using AM2.Approv ed mode indicat or and service status outputCommand InShow key statusNoneCrypto- Officer (AM2) - BKK: E
KVL Query Algorithm ListProvides algorithm version numbers using AM2.Approv ed mode indicat or and service status outputCommand InShow list of supported algorithmsNoneCrypto- Officer (AM2)
KVL Query VersionProvides module firmware version numbers using AM2.Approv ed mode indicat or and service status outputCommand InShow module version infoNoneCrypto- Officer (AM1)
Extract Error LogProvide the history of error events using AM1.Approv ed mode indicatCommand InError logs out. Success/Fail ure status.NoneCrypto- Officer (AM1)

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 25
NameDescriptio nIndicat or or and service status outputInputsOutputsSecurity Functio nsSSP Access
Reset Crypto ModuleReset/powe r cycle the ASTRO CDEM MACE.Approv ed mode indicat or and service status outputReset Button press/Cycle power.Reset the MACE.NoneUnauthentic ated - DRBG- EI/Seed: Z - DRBG- State: Z - DRBG- nonce: Z - BKK: Z - IDK: Z - PEK: Z - KPK: Z - KEK: Z - TEK: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z - FW-LD- Pub: Z - IDK-ROM: Z - IDK-Block: Z
Erase Crypto ModuleZeroize the KPK and all keys and CSPs in the key database and causes a new KPK to be generated. Resets the password to the factory default.Approv ed mode indicat or and service status outputErase Button pressZeroize all CSPsNoneUnauthentic ated - KPK: G,Z - KEK: Z - TEK: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z

Z Z Z Z Table 14: Approved Services Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 26
4.4 Non-Approved Services

There are no Non-Approved services available while the module is in the approved mode. N/A for this module.

4.5 External Software/Firmware Loaded

This module supports loading of external firmware via the Program Update service. Execution of the successfully loaded firmware is only effective after the next reset of the security module. Any firmware loaded into the module other than that listed in section 2.2 Tested and Vendor Affirmed Module Version and Identification, is outside the scope of this Security Policy and requires a separate FIPS 140-3 validation. The module validates the integrity of the externally loaded firmware via procedures described in section

5.1 Integrity Techniques

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 27
5 Software/Firmware Security
5.1 Integrity Techniques

The Module has a limited modifiable operational environment under the FIPS 140-3 definitions. The Module is composed of the following firmware components:

5.2 Initiate on Demand

The operator can initiate the integrity test on demand by power cycling the Module. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 28
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited The ASTRO CDEM MACE has a limited operational environment under the FIPS 140-3 definitions with a Physical Security at Level 3. Therefore, per the FIPS 140-3 Management Manual Section 7.5, partial validations and non-applicable areas in this section are not applicable. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 29
MechanismInspection FrequencyInspection Guidance
Covered with a hard-opaque epoxy coating that provides evidence of attempts to tamper with the ASTRO CDEM MACE.PeriodicallyLook for signs of tampering. Remove from service if tampering found.
Temp/Voltage TypeTemperature or VoltageEFP or EFTResult
LowTemperature-38.1°CEFPShutdown - A tamper flag is raised, a wake-up reset of the product is triggered.
HighTemperature101.4°CEFPShutdown - A tamper flag is raised, a wake-up reset of the product is triggered.
LowVoltage1.65V - VDDCORE : 1.350V - VVDBUEFPShutdown - A general reset of the chip is asserted.
HighVoltage2.04V - VDDCORE : 2.292V - VVDBUEFPShutdown- A tamper flag is raised, a wake-up reset of the product is triggered.
7 Physical Security

The ASTRO CDEM MACE is a production grade, single-chip cryptographic module with standard passivation over the modules circuitry as defined by FIPS 140-3 and is designed to meet level 3 physical security requirements. The information below is applicable to cryptographic module hardware kit numbers 5185912Y03, 5185912Y05, and 5185912T05, which have identical physical security characteristics.

7.1 Mechanisms and Actions Required

CDEM MACE's epoxy encapsulate is claimed at the temperature range of -40 to 85 degrees Celsius. No assurance of the epoxy hardness is claimed for this physical security mechanism outside of this range. The ASTRO CDEM MACE does not contain any doors, removable covers, or ventilation holes or slits. No maintenance access interface is available. No special procedures are required to maintain physical Table 15: Mechanisms and Actions Required Table 16: EFP/EFT Information Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 30
Temperature TypeTemperature
LowTemperature-40°C
HighTemperature85°C
7.3 Hardness Testing Temperature Ranges

Table 17: Hardness Testing Temperatures Notes: The module is hardness tested at the lowest and highest temperatures within the module's intended temperature range of operation. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 31
8 Non-Invasive Security

The Module does not implement any mitigation method against non-invasive attack. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 32
Storage Area NameDescriptionPersistence Type
System Memory (S1)Stored in the volatile memory (RAM).Dynamic
Flash Memory (S2)Stored in the flash in plaintext, associated by memory location (pointer).Static
Flash Memory - Encrypted (S3)Stored in the flash in encrypted, associated by memory location (pointer).Static
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Input encrypted on the IDK (I1)Application Software (outside)Flash Memory - Encrypted (S3)EncryptedManualElectronicAES A5273 Decryption
Input encrypted on the PEK(I2)Application Software (outside)Flash Memory - Encrypted (S3)EncryptedManualElectronicAES A5273 Decryption
Input encrypted on the KEK (I3)OTARFlash Memory - Encrypted (S3)EncryptedAutomatedElectronicKTS- Unwrap
Input encrypted on the BKK (I4)Application Software (outside)Flash Memory - Encrypted (S3)EncryptedManualElectronicAES A5273 Decryption
Zeroization MethodDescriptionRationaleOperator Initiation
Z1Zeroized by the "Program Update" service by overwriting with a fixed pattern of 0s. *SSPs zeroized upon loading of new firmware.Yes
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 19: SSP Input-Output Methods

9.3 SSP Zeroization Methods

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 33
Zeroization MethodDescriptionRationaleOperator Initiation
Z2Zeroized by module power cycle or hard reset by overwriting with a fixed pattern of 0s. *SSPs in volatile memory zeroized.Yes
Z3Zeroized by the "Configure Module" service by overwriting with a fixed pattern of 0s.CO zeroize module when configuring into an Approved mode.Yes
Z4Zeroized by the "Change CO Password (AM1)" service by overwriting with a fixed pattern of 0s.Old CO password zeroized as new CO password setYes
Z5Zeroized by the "Validate CO Password (AM1)" service by overwriting with a fixed pattern of 0s.CO password zeroized after too many failed login attemptsYes
Z6Zeroized by the "Change CO Password (AM2)" service by overwriting with a fixed pattern of 0s.Old Crypto Officer password zeroized as new Crypto Officer password setYes
Z7Zeroized by the "Validate CO Password (AM2)" service by overwriting with a fixed pattern of 0s.Crypto Officer password zeroized after too many failed login attemptsYes
Z8Zeroized by Tamper event. (KPK) is zeroized with a fixed pattern of 0s.Zeroizes KPKN/A

Table 20: SSP Zeroization Methods Note: For zeroization methods with an asterisk, once zeroization is complete the Module will reboot, indicating successful zeroization. The output status of all other methods of success of zeroization are implicit and any attempt to use previous keys/CSPs will trigger an error. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 34
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
DRBG- EI/SeedInternally generated by the HWRNG2770 - N/AN/A - CSPEntropyDRBG
DRBG- StateCTR_DRBG internal state: V (128 bits) and Key (AES 256)256 - 256N/A - CSPDRBGDRBG
DRBG- nonceInternally generated by the HWRNG128 - N/AN/A - CSPEntropyDRBG
BKKA 256-bit AES OFB (A5273) key used to decrypt keys loaded from KVL256 - 256Symmetric Key - CSPOtherAES A5273 Decryption
IDKA 256-bit AES CBC key used to decrypt downloaded firmware images.256 - 256Symmetric Key - CSPIDK GenerationAES A5273 Decryption
PEK256-bit AES-CFB8 key used for decrypting passwords during password validation256 - 256Symmetric Key - CSPPre-loaded at manufacturingAES A5273 Decryption
KPK256 bit AES CFB-8 key used to encrypt all TEKs and KEKs stored in the flash.256 - 256Symmetric Key - CSPKey GenerationKey Generation AES A5273 Decryption
KEK256-bit AES-KW key used for decryption of keys in key transport operation256 - 256Symmetric Key - CSPKTS-Unwrap AES A5273 Decryption
TEK256-bit AES-KW key used for enabling secure communication with target devices.256 - 256Symmetric Key - CSPKTS-Unwrap AES A5273 Decryption
CO PWD (AM1)8-32 ASCII characters CO password.N/A - N/AAuthentication - CSPAES A5273 Encryption AES A5273 Decryption
9.4 SSPs

All usage of these SSPs by the Module are described in the services detailed in Section 4.3 Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 35
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
CO PWD (AM2)8-32 ASCII characters Crypto Officer password.N/A - N/AAuthentication - CSPAES A5273 Encryption AES A5273 Decryption
PWD Hash256-bit password hash stored in the non-volatile memory.256 - 128Authentication - CSPSHASHA
FW-LD- Pub2048-bit RSA key used to validate the signature of the firmware image during FW integrity and FW Loading before it is allowed to be executed.2048 - 112Asymmetric Public Key - PSPPre-loaded at manufacturingSignature Verification
IDK- ROMA 256-bit AES CBC key used in the re-construction of IDK per SP800-133r2 (Section 6.3 #2) via XOR using IDK Block256 - 256Symmetric - CSPPre-loaded at manufacturingCKG - IDK
IDK- BlockA 256-bit AES CBC key used in the re-construction of IDK per SP800-133r2 (Section 6.3 #2) via XOR using IDK ROM256 - 256Symmetric Key - CSPGenerated with an approved RBG and pre-loaded at manufacturingCKG - IDK
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
DRBG- EI/SeedSystem Memory (S1):PlaintextWhen module is resetZ2DRBG-nonce:Used With DRBG-State:Generates
DRBG-StateSystem Memory (S1):PlaintextWhen the module is restZ2DRBG-EI/Seed:Derived From DRBG-nonce:Derived From
DRBG- nonceSystem Memory (S1):PlaintextWhen module is resetZ2DRBG-EI/Seed:Used With DRBG-State:Generates

Table 21: SSP Table 1 Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 36
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
BKKInput encrypted on the IDK (I1)System Memory (S1):Plaintext Flash Memory (S2):PlaintextWhen module is resetZ1 Z2KEK:Decrypts TEK:Decrypts
IDKSystem Memory (S1):PlaintextWhen module is resetZ2IDK-ROM:Derived From IDK-Block:Derived From PEK:Decrypts KEK:Decrypts
PEKInput encrypted on the IDK (I1)System Memory (S1):Plaintext Flash Memory (S2):PlaintextWhen module is resetZ1 Z2CO PWD (AM1):Decrypts CO PWD (AM2):Decrypts PWD Hash:Used With
KPKSystem Memory (S1):Plaintext Flash Memory (S2):PlaintextWhen module is resetZ1 Z3 Z4 Z5 Z6 Z7 Z8DRBG-State:Derived From
KEKInput encrypted on the KEK (I3) Input encrypted on the BKK (I4)System Memory (S1):Plaintext Flash Memory (S2):PlaintextWhen module is resetZ1 Z2KPK:Encrypted by TEK:Decrypts
TEKInput encrypted on the KEK (I3) Input encrypted on the BKK (I4)System Memory (S1):Plaintext Flash Memory - Encrypted (S3):EncryptedWhen module is resetZ1 Z2KPK:Encrypted by
CO PWD (AM1)Input encrypted on the PEK(I2)System Memory (S1):Plaintext Flash Memory - Encrypted (S3):EncryptedWhen module is resetZ1 Z3 Z4 Z5 Z6 Z7PEK:Encrypted by

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 37
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
CO PWD (AM2)Input encrypted on the PEK(I2)System Memory (S1):Plaintext Flash Memory - Encrypted (S3):EncryptedWhen module is resetZ1 Z3 Z4 Z5 Z6 Z7PEK:Encrypted by
PWD HashSystem Memory (S1):Plaintext Flash Memory - Encrypted (S3):EncryptedWhen module is resetZ1 Z3 Z4 Z5 Z6 Z7CO PWD (AM1):Hash of CO PWD (AM2):Hash of
FW-LD-PubSystem Memory (S1):Plaintext Flash Memory (S2):PlaintextWhen module is resetZ1IDK:Encrypted by
IDK-ROMSystem Memory (S1):Plaintext Flash Memory (S2):PlaintextWhen module is resetZ1 Z2IDK:Generates IDK-Block:Paired With
IDK-BlockSystem Memory (S1):Plaintext Flash Memory (S2):PlaintextWhen module is resetZ1 Z2IDK:Generates IDK-ROM:Paired With

Table 22: SSP Table 2 Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 38
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Firmware IntegritySHA2-256 (Cert. #817), RSA- 2048 (Cert. #A5253)KATSW/FW IntegrityE2 on failureWhen the ASTRO CDEM MACE is powered up, the digital signature is verified.
10 Self-Tests
10.1 Pre-Operational Self-Tests

The ASTRO CDEM MACE performs self-tests to ensure the proper operation. Per FIPS 140-3 these are categorized as either pre-operational selftests or conditional self-tests. Pre-operational self–tests are available on demand by power cycling the ASTRO CDEM MACE. In addition, pre-operational self–tests are periodically performed by the ASTRO CDEM MACE as configured by the operator during the module configuration as shown in section 11.1 Installation, Initialization, and Startup Procedures The ASTRO CDEM MACE will not accept any commands when a periodic self-test is required; the commands still in the I/O buffer will be processed by the ASTRO CDEM MACE after periodic self-test ends and will execute when the I/O buffer is emptied. The ASTRO CDEM MACE logs the most recent self-test errors to the internal flash; the operator (CO) can extract the error logs using Extract Error Log service. The Module performs the following pre-operational self-tests in table below Table 23: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

The Module performs the following conditional self-tests in the table below Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 39
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-Encryption (A5273)AES-256KATCASTES1 on failureEncryptionBootup/Periodic
AES-Decryption (A5273)AES-256KATCASTES1 on failureDecryptionBootup/Periodic
AES-Encryption (A5275)AES-256KATCASTES1 on failureEncryptionBootup/Periodic
AES-Decryption (A5275)AES-256KATCASTES1 on failureDecryptionBootup/Periodic
AES-KW (A5438)AES-256KATCASTES1 on failureDecryptionBootup/Periodic
Counter DRBG (A5437)AES-256 CTRKATCASTES1 on failureAES-256 CTR_DRBG instantiation, generate KATs performed before the first random data generationBootup/Periodic
SHA2-256 (SHS 817)SHA2-256KATCASTE2 on failureSHA2, -256, KAT performed before Pre-Operational FW integrity tests.Bootup
RSA SigVer (FIPS186-5) (A5253)RSA-2048 SigVerKATCASTE2 on failureRSA-2048 SigVer, performed before Pre-Operational FW integrity tests.Bootup
Entropy 90B Start-up Repetition Count Test (RCT)Repetition Count TestRCTCASTES1 on failureDesigned to quickly detect catastrophic failures that cause the noise source to become "stuck" on a single output value for a long period of timeBootup
Entropy 90B Start-up Adaptive Proportion Test (ADP)Adaptive Proportion TestADPCASTES1 on failureDesigned to detect a large loss of entropy that might occur as a result of some physical failure or environment al change affecting the noise sourceBootup
Firmware Load2048-bit RSA Signature Verification/SHA2-256KATSW/FW LoadE2 on failureA digital signature is generated over the code when it is built using SHA-256 and RSA-2048.loading a new firmware image

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 40

Algorithm or Test

Test Properties

Test Method

Test Type

Indicator

Details The digital signature is verified upon download into the ASTRO CDEM MACE.

Conditions

Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Firmware IntegrityKATSW/FW IntegrityOn DemandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-Encryption (A5273)KATCASTOn Demand/PeriodicallyManually/Programmatically
AES-Decryption (A5273)KATCASTOn Demand/PeriodicallyManually/Programmatically
AES-Encryption (A5275)KATCASTOn Demand/PeriodicallyManually/Programmatically
AES-Decryption (A5275)KATCASTOn Demand/PeriodicallyManually/Programmatically
AES-KW (A5438)KATCASTOn Demand/PeriodicallyManually/Programmatically
Counter DRBG (A5437)KATCASTOn Demand/PeriodicallyManually/Programmatically

Table 24: Conditional Self-Tests

10.3 Periodic Self-Test Information

Table 25: Pre-Operational Periodic Information Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 41
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-256 (SHS 817)KATCASTOn Demand/PeriodicallyManually/Programmatically
RSA SigVer (FIPS186- 5) (A5253)KATCASTOn Demand/PeriodicallyManually/Programmatically
Entropy 90B Start-up Repetition Count Test (RCT)RCTCASTOn DemandManually
Entropy 90B Start-up Adaptive Proportion Test (ADP)ADPCASTOn DemandManually
Firmware LoadKATSW/FW LoadOn DemandManually

Table 26: Conditional Periodic Information Conditional self–tests are periodically performed by the ASTRO CDEM MACE every X hours, where X is configured by the operator during module configuration (1 hour to 720 hours). The ASTRO CDEM MACE will not accept any commands when a periodic self-test is required; the commands still in the I/O buffer will be processed by the ASTRO CDEM MACE end the periodic self-test executed when the I/O buffer is emptied. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 42
NameDescriptionConditionsRecovery MethodIndicator
ES1The ASTRO CDEMMACE fails a KAT.The ASTRO CDEM MACE enters the critical error state. In this state, the ASTRO CDEM MACE stores the status into the internal flash memory and then halts all further operation by entering an infinite loop.Reboot/Power cycle the moduleSets the status alarm LED.
ES2The ASTRO CDEMMACE fails a firmware loading during program upgrade and/or firmware integrity pre-operational self- test.The ASTRO CDEM MACE enters the firmware signature validation failure state. In this state, the ASTRO CDEM MACE halts all further operations by entering the flash programming mode.Reboot/Power cycle the module or re-flashing a new image.Sets the status alarm LED.
10.4 Error States

Table 27: Error States Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 43
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Installation and Initialization: The Module is originally a non-compliant module and must be initialized to be in Approved mode. There is no non-Approved mode. During initialization the operator shall configure the Module from the instructions below:

  1. Upon first access, the operator will use the default passwords provided by Motorola in a separate communication.
  2. The operator will then change the default passwords based on the requirements in the Roles and Authentication table.
  3. The operator will set the periodic self-tests timer as part of the Module configuration in every X minutes, where X is a minimum value = 1 hour and maximum value = 720 hours. Note: the default minimum = 0* but must be changed to a minimum of 1.
  4. The operator will then complete Module configuration using the Module Configuration and Configure OTEK services.
  5. Finally, the operator will set the Module to the Approved mode using the Set FIPS Mode service. * periodic self-tests will not perform if minimum = 0 Delivery: The Module is used in multiple Motorola Solutions, Inc. products. Motorola uses commercially available courier systems such as UPS, FedEx, and DHL with a tracking number and requires a signature at the end from an authorized client.
11.2 Administrator Guidance

Use vendor provided product specific user guide for secure operations.

11.3 Non-Administrator Guidance
11.4 Design and Rules

Rules of Operation

  1. The Module provides one distinct operator role: Cryptographic Officer.
  2. The Module provides identity-based authentication. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
Page 44
  1. The Module clears previous authentications on power cycle.
  2. An operator does not have access to any cryptographic services prior to assuming an authorized role.
  3. The Module allows the operator to initiate power-up self-tests by power cycling power or resetting the Module.
  4. All self-tests do not require any operator action.
  5. Data output is inhibited during key generation, self-tests, zeroization, and error states.
  6. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module.
  7. There are no restrictions on which keys or SSPs are zeroized by the zeroization service.
  8. The Module does not support concurrent operators.
  9. The Module does not support a maintenance interface or role.
  10. The Module does not support manual SSP establishment method.
  11. The Module does not have any proprietary external input/output devices used for entry/output of data.
  12. The Module does not enter or output plaintext CSPs.
  13. The Module does store some CSPs in plaintext.
  14. The Module does not output intermediate key values. The Module does not provide bypass services or ports/interfaces.
11.5 Maintenance Requirements
11.6 End of Life

After the end-of-life, the operator should zeroize all SSPs using “Erase Crypto Module“ service followed by shredding the ASTRO CDEM MACE chip.

12 Mitigation of Other Attacks

The Module does not implement any mitigation method against other attacks. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 45
Abbreviation*Full Specification Name
[FIPS140-3]Security Requirements for Cryptographic Modules, March 22, 2019
[ISO19790]International Standard, ISO/IEC 19790, Information technology — Security techniques — Test requirements for cryptographic modules, Third edition, March 2017
[ISO24759]International Standard, ISO/IEC 24759, Information technology — Security techniques — Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015
[IG]Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, August 30, 2024
[133]NIST Special Publication 800-133, Recommendation for Cryptographic Key Generation, Revision 2, June 2020
[186-5]National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-5, February 2023.
[197]National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197, November 26, 2001, Updated May 9, 2023
[180]National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August, 2015
[38A]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation, Methods and Techniques, Special Publication 800-38A, December 2001
[38F]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping, Special Publication 800-38F, December 2012
[90A]National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A, Revision 1, June 2015.
[90B]National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018.
[OTAR]Project 25 – Digital Radio Over-The-Air-Rekeying (OTAR) Messages and Procedures [TIA- 102.AACA-A], September 2014

References and Definitions The following standards are referred to in this Security Policy. Table 28 References Table 29 Acronyms and Definitions Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 46
Acronym*Definition
AESAdvanced Encryption Standard
BKKBlack Keyloading Key
CAICommon Air Interface
CBCCipher Block Chaining
CDEMCAI Data Encryption Module
CFBCipher Feedback
CKGCryptographic Key Generation
CSPCritical Security Parameter
DRBGDeterministic Random Bit Generator
DRBG-ElDRBG Entropy Input
ECBElectronic Code Book
FIPSFederal Information Processing Standards
FWFirmware
FW-LD-PubFirmware Load Public Key
ICIntegrated Circuit
IDKImage Decryption Key
IVInitialization Vector
KATKnown Answer Test
KPKKey Protection Key
KEKKey Encryption Key
KVLKey Variable Loader
MACMessage Authentication Code
MACEMotorola Advanced Crypto Engine
OFBOutput Feedback
OTAROver The Air Rekeying
PEKPassword Encryption Key
PWD HashPassword Hash
RSARivest–Shamir–Adleman
SSISynchronous Serial Interface
SSPSensitive Security Parameter
TEKTraffic Encryption Key

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).

Page 47
Acronym*Definition
UAUnauthenticated Service

Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).