| Standard | FIPS 140-3 |
|---|---|
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Status | Active |
| Sunset date | 1/22/2031 |
| Caveat | When installed, initialized and configured as specified in Section 11 of Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs |
| Vendor | Motorola Solutions, Inc. |
flowchart LR
%% Deterministic review-risk graph for ASTRO CDEM Motorola Advanced Crypto Engine (MACE)
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for ASTRO CDEM Motorola Advanced Crypto Engine (MACE)
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;Motorola Solutions, Inc. ASTRO CDEM Motorola Advanced Crypto Engine (MACE) Document Version: R01.00.00 Date: January 16, 2025 Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| # | Section | Page |
|---|
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Item | Page |
|---|---|
| Table 1: Security Levels | 5 |
| Table 2: Tested Module Identification – Hardware | 8 |
| Table 3 – Approved Mode Drop-in Algorithms | 8 |
| Table 4: Modes List and Description | 9 |
| Table 5: Approved Algorithms | 10 |
| Table 6: Vendor-Affirmed Algorithms | 10 |
| Table 7: Non-Approved, Allowed Algorithms with No Security Claimed | 11 |
| Table 8: Security Function Implementations | 13 |
| Table 9: Entropy Certificates | 14 |
| Table 10: Entropy Sources | 14 |
| Table 11: Ports and Interfaces | 16 |
| Table 12: Authentication Methods | 18 |
| Table 13: Roles | 18 |
| Table 14: Approved Services | 25 |
| Table 15: Mechanisms and Actions Required | 29 |
| Table 16: EFP/EFT Information | 29 |
| Table 17: Hardness Testing Temperatures | 30 |
| Table 18: Storage Areas | 32 |
| Table 19: SSP Input-Output Methods | 32 |
| Table 20: SSP Zeroization Methods | 33 |
| Table 21: SSP Table 1 | 35 |
| Table 22: SSP Table 2 | 37 |
| Table 23: Pre-Operational Self-Tests | 38 |
| Table 24: Conditional Self-Tests | 40 |
| Table 25: Pre-Operational Periodic Information | 40 |
| Table 26: Conditional Periodic Information | 41 |
| Table 27: Error States | 42 |
| Table 28 References | 45 |
| Table 29 Acronyms and Definitions | 45 |
| Figure 1 – ASTRO CDEM MACE IC (Top) | 6 |
| Figure 2 – ASTRO CDEM MACE IC (Interfaces) | 7 |
| Figure 3 – Cryptographic Boundary | 7 |
| Section | Title | Security Level |
|---|---|---|
| 1 | General | 3 |
| 2 | Cryptographic module specification | 3 |
| 3 | Cryptographic module interfaces | 3 |
| 4 | Roles, services, and authentication | 3 |
| 5 | Software/Firmware security | 3 |
| 6 | Operational environment | N/A |
| 7 | Physical security | 3 |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 3 |
| 10 | Self-tests | 3 |
| 11 | Life-cycle assurance | 3 |
| 12 | Mitigation of other attacks | N/A |
| Overall Level | 3 |
requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-
The FIPS 140-3 security levels for the Module are as follows from Table 1: Table 1: Security Levels Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
2 – Cryptographic Module Specification
This document covers the Motorola Solutions ASTRO CDEM MACE module, hereafter denoted as the Module. The Module is implemented as a single-chip cryptographic module to meet FIPS 140-3 level 3 physical security requirements as defined by FIPS 140-3. The ASTRO CDEM MACE provides key storage and generation and performs all crypto processing for the Motorola Solutions ASTRO CDEM product.
Purpose and Use: The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated overall Security Level
Figure 2 – ASTRO CDEM MACE IC (Interfaces) Power IRQ/FIQ Clock ASTRO CDEM MACE RAM Interface Reset Tamper SSI Ethernet RS232 KVL Front Panel LED Indicators: Alarm, Interface Interface Interface Port Interface Interface Power, Ready, Tx Clear, Status Figure 3 – Cryptographic Boundary Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Model and/or Part Number | Hardware Version | Firmware Version | Processors | Features | |
|---|---|---|---|---|---|
| ASTRO CDEM MACE | 5185912Y03, 5185912Y05, 5185912T05 | R03.01.02 with AES-256 DIA R01.00.07 | Motorola Advanced Crypto Engine (MACE) | N/A |
| Algorithm* | Algorithm FW Version | Base FW Version | Cert. # | ||||
|---|---|---|---|---|---|---|---|
| AES256 | R01.00.07 | R03.01.02 | A5275 |
Tested Module Identification
The module does not exclude any components from the cryptographic boundary.
Modes List and Description: Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Mode Name | Description | Type | Status Indicator | ||
|---|---|---|---|---|---|
| approved | Operating in approved mode | Approved | Display output |
Table 4: Modes List and Description The ASTRO CDEM MACE is originally non-compliant and must be configured to operate in an approved mode of operation. The MACE must be installed, initialized and configured, including a required change of the factory-default password in order to be in an approved mode. Documented below are the additional configuration settings that are required for the MACE to be used in an Approved Mode of operation at overall Security Level
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-CBC | A5273 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-CBC | A5275 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-CFB8 | A5273 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5275 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-KW | A5438 | Direction - Decrypt Key Length - 256 | SP 800-38F |
| AES-OFB | A5273 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-OFB | A5275 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| Counter DRBG | A5437 | Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - Yes | SP 800-90A Rev. 1 |
| RSA SigVer (FIPS186-5) | A5253 | Modulo - 2048 Signature Type - pkcs1v1.5 | FIPS 186-5 |
| SHA2-256 | SHS 817 | Message Length - Message Length: 0- 51200 Increment 8 | FIPS 180-4 |
| Name | Properties | Implementation | Reference |
|---|---|---|---|
| CKG | Key Type:Symmetric | N/A | SP800-133rev2 Sections 4 example 1 and IG D.H |
| CKG - IDK | Key Type:Symmetric | N/A | SP800-133rev2 Sections 6.3 #2 and IG C.I |
Approved Algorithms: The Module implements the Approved cryptographic algorithms listed in the table below. Table 5: Approved Algorithms ApprovedAlgorithmsTable From Web Cryptik ApprovedAlgorithmsTable Vendor-Affirmed Algorithms: The Module implements the FIPS Vendor Affirmed cryptographic algorithms listed. N/A Table 6: Vendor-Affirmed Algorithms Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Caveat | Use and Function | |||
|---|---|---|---|---|---|
| AES MAC | No Security Claimed. AES MAC is used as part of OTAR but is considered obfuscation. | [IG 2.4.A] P25 AES OTAR. AES MAC is applied directly to the plaintext OTAR key components and then KTS encryption is performed on the OTAR key components and decrypted within the module using AES KW Cert #5438 |
Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: The Module implements the FIPS Non-Approved, Allowed cryptographic Algorithms with No Security Table 7: Non-Approved, Allowed Algorithms with No Security Claimed Non-Approved, Not Allowed Algorithms: N/A for this module. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Type | Description | Properties | Algorithms | |
|---|---|---|---|---|---|
| AES A5275 Encryption | BC-UnAuthEncrypt | Block Cipher | AES-CBC: (A5275) AES-OFB: (A5275) AES-ECB: (A5275) | ||
| AES A5275 Decryption | BC-UnAuthDecrypt | Block Cipher | AES-CBC: (A5275) AES-OFB: (A5275) AES-ECB: (A5275) | ||
| Key Generation | CKG | Symmetric Key Generation | Counter DRBG: (A5437) CKG : () | ||
| Signature Verification | DigSig-SigVer | Digital Signature Verification | RSA SigVer (FIPS186- 5): (A5253) | ||
| Entropy | ENT-ESV | Entropy Source | |||
| KTS-Unwrap | KTS-Unwrap | Key Transport Unwrapping | Caveat:Key establishment methodology provides 256 bits strength Standard:SP 800-38F IG D.G:Approved method in KW mode | AES-KW: (A5438) AES MAC: () | |
| SHA | SHA | Secure Hash Standard | SHA2-256: (SHS 817) | ||
| AES A5273 Encryption | BC-UnAuthEncrypt | Block Cipher | AES-CFB8: (A5273) AES-CBC: (A5273) AES-OFB: (A5273) | ||
| AES A5273 Decryption | BC-UnAuthDecrypt | Block Cipher | AES-CFB8: (A5273) AES-CBC: (A5273) AES-OFB: (A5273) | ||
| IDK Generation | CKG | Symmetric Key Generation | CKG - IDK: () |
The following table shows the Security Function Implementations that the module implements: Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Type | Description | Properties | Algorithms | ||||
|---|---|---|---|---|---|---|---|---|
| DRBG | DRBG | AES-256 CTR Deterministic RBG | Counter DRBG: (A5437) |
Table 8: Security Function Implementations Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Cert Number | Vendor Name | |
|---|---|---|
| E132 | Motorola Solutions Inc |
| Name | Type | Operational Environment | Sample Size | Entropy per Sample | Conditioning Component | |
|---|---|---|---|---|---|---|
| Motorola Solutions Advanced Crypto Engine Entropy Source | Physical | Atmel 5186912 | 1 bit | 0.13862 | N/A |
The module does not have any algorithm specific information.
Table 9: Entropy Certificates The Module uses the following entropy sources: Table 10: Entropy Sources
For Key Generation methods, see Section 2.6 Security Function Implementations above.
For Key Establishment methods, see Section 2.6 Security Function Implementations above.
The module does not implement any Industry Protocols Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Physical Port | Logical Interface(s) | Data That Passes |
|---|---|---|
| Synchronous Interface (SSI) | Data Input Data Output Control Input Status Output | Provides an interface to the unprotected network and entry of the Crypto Officer password in encrypted form. |
| Ethernet Port (EP) | Data Input Data Output Control Input Status Output | This interface routes packets between subnets. The IP stack of this interface will use the subnet information to determine how to route packets between physical network interfaces. |
| RS232 Interface | Data Output Control Input Status Output | Provides an interface for factory programming and execution of RS232 shell commands. |
| Key Variable Loader (KVL) | Data Input Data Output Control Input Status Output | Provides an interface to the Key Variable Loader. The Traffic Encryption Key (TEK) is entered in encrypted form over the KVL interface. |
| RAM | Data Input Data Output Control Input Status Output | This interface provides storage for non-security related stack information. |
| Power | Power | This interface powers all circuitry. |
| Tamper Interface | Control Input | The interface is used for zeroization of Traffic Encryption Keys (TEKs), KPK. |
| Reset Interface | Control Input | This interface forces a reset of the module. |
| Alarm LED output | Status Output | The Alarm LED output is used to drive the external Alarm LED red to indicate a fatal error has been detected. |
| Power LED output | Status Output | The Power LED output is used to drive the external Power LED green when power is supplied to the module. |
The Module’s ports and associated FIPS defined logical interface categories are listed below. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Physical Port | Logical Interface(s) | Data That Passes |
|---|---|---|
| Ready LED output | Status Output | The Ready LED output is used to drive the external Ready LED green when the module is ready to communicate with a KVL. |
| TX Clear LED output | Status Output | The TX Clear LED output is used to drive the external TX Clear LED orange when a "Bypass Rule" is programmed. |
| Status LED output | Status Output | The Status LED output is used to drive the external Status LED green to indicate a good battery, and a Traffic Encryption Key (TEK) has been loaded. The Status LED output is used to drive the external Status LED yellow to indicate a good battery, but no Traffic Encryption Key (TEK) has been loaded. The Status LED output is used to drive the external Status LED red to indicate a low or dead battery. |
| IRQ/FIQ | Control Input | External interrupts. |
| Clock | Control Input | Clock input |
Table 11: Ports and Interfaces Note: The module does not support Control Output. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Metho d Name | Description | Security Mechanis m | Strength Each Attempt | Strength per Minute |
|---|---|---|---|---|
| AM1 | Identity- based. Crypto-Officer Password: a 15-16 ASCII (printable) characters password is authenticated to gain access to Crypto- Officer services assocaited to the RS232 Interface. It should be noted that after authenticating , this password may be changed at any time. | SHA2-256 (SHS 817) | The password requires a minimum of 1 Upper case, 1 Lower case, 1 Numerical and 1 special character. Since the minimum password length is 15 ASCII printable characters and there are 95 ASCII printable characters, the probability of a successful random attempt is 1 in {(10)*(262)*(32)*(9511)}, The password requires a minimum of 1 Upper case, 1 Lower case, 1 Numerical and 1 special character. Since the minimum password length is 15 ASCII printable characters and there are 95 ASCII printable characters, the probability of a successful random attempt is 1 in {(10)*(262)*(32)*(95^11) } | After the CO password has been incorrectly entered 10 consecutive times, the Module will erase all CSPs, reset the CO password back to the default and set an alarm, at which time the module must be power cycled to become operational again. The strength per minute is 10 in {(10)*(262)*(32)*(95^11) } |
| AM2 | Identity based. Crypto-Officer Password: a 10 hexadecimal digit long password is authenticated to gain access to Crypto | SHA2-256 (SHS 817) | The minimum password length is 10 hex digits. The probability of a successful random attempt is 10^16 | After the CO password has been incorrectly entered 15 consecutive times, the Module will erase all CSPs, and set an alarm, at which time the module must be power cycled to become operational again. The strength per minute is 15x10^16. |
} Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
Metho d Name
Description Officer services associated to the Synchronous Interface (SSI) port. It should be noted that after authenticating , this password may be changed at any time.
Security Mechanis m
Strength Each Attempt
Strength per Minute
| Name | Type | Operator Type | Authentication Methods |
|---|---|---|---|
| Crypto-Officer (AM1) | Identity | CO | AM1 |
| Crypto-Officer (AM2) | Identity | CO | AM2 |
The Module supports one distinct operator role, the Cryptographic Officer (CO). The authentication method and services available to the CO will depend on the physical port used. The CO may be logged into both ports at the same time. In addition, the Module supports services which do not require authentication (UA). The Roles Table below lists all operator roles supported by the Module. The Module does not support concurrent operators. Table 13: Roles
All approved services implemented by the Module are listed in the table below: The SSPs modes of access shown in the table below are defined as:
| • | G = Generate: The Module generates or derives the SSP. |
| • | R = Read: The SSP is read from the Module (e.g., the SSP is output). |
| • | W = Write: The SSP is updated, imported, or written to the Module (SSP is input). |
| • | E = Execute: The Module uses the SSP in performing a cryptographic operation. |
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Descriptio n | Indicat or | Inputs | Outputs | Security Functio ns | SSP Access |
|---|---|---|---|---|---|---|
| Program Update | Update the ASTRO CDEM MACE firmware. Firmware upgrades are authenticat ed using a digital signature. The Program Update Public Signature Key is used to validate the signature of the firmware image being loaded before it is allowed to be executed using AM2. | Approv ed mode indicat or and service status output | Firmware Image | The ASTRO CDEM MACE is upgraded to new firmware. | AES A5273 Decrypti on IDK Generati on | Crypto- Officer (AM2) - FW-LD- Pub: Z - BKK: Z - IDK: Z - PEK: Z - KPK: Z - KEK: Z - TEK: Z - IDK-ROM: Z - IDK-Block: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z |
| Generate Entropy | Generate Entropy into the ASTRO CDEM MACE using AM2. | Approv ed mode indicat or and service status output | DRBG Seed | The DRBG is seeded and initialized. Success/fail ure status | Entropy | Crypto- Officer (AM2) - DRBG- EI/Seed: G - DRBG- State: G - DRBG- nonce: G |
| OTEK | Load keys into the ASTRO CDEM | Approv ed mode indicat or and | Encrypted Keys | Decrypted keys that were imported encrypted | AES A5273 Decrypti on | Crypto- Officer (AM2) - KEK: E - TEK: E |
| Name | Descriptio n MACE using AM2. | Indicat or service status output | Inputs | Outputs into the ASTRO CDEM MACE. Success/fail ure status. | Security Functio ns | SSP Access |
|---|---|---|---|---|---|---|
| Change CO Password (AM1) | Modify the current password used to identify and authenticat e the CO role using AM1. | Approv ed mode indicat or and service status output | Password | Updated the CO password. Success/fail ure status | SHA AES A5273 Encrypti on AES A5273 Decrypti on | Crypto- Officer (AM1) - PEK: E - KPK: G,E,Z - KEK: Z - TEK: Z - CO PWD (AM1): G,E,Z - PWD Hash: G,E,Z |
| Change CO Password (AM2) | Modify the current password used to identify and authenticat e the CO role using AM2. | Approv ed mode indicat or and service status output | Password | Updated the CO password. Success/fail ure status. | SHA AES A5273 Encrypti on AES A5273 Decrypti on | Crypto- Officer (AM2) - PEK: E - KPK: G,E,Z - KEK: Z - TEK: Z - CO PWD (AM2): G,E,Z - PWD Hash: G,E,Z |
| Validate CO Password (AM1) | Validate the current password used to identify and authenticat e the CO role using AM1. | Approv ed mode indicat or and service status output Approv ed mode indicat or and service status output | Password | Successful authenticatio n will allow access to the services allowed for CO role (AM1). | SHA AES A5273 Encrypti on AES A5273 Decrypti on | Crypto- Officer (AM1) - PEK: E - KPK: G,E,Z - KEK: Z - TEK: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z |
G,E,Z G,E,Z Z Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Descriptio n | Indicat or | Inputs | Outputs | Security Functio ns | SSP Access |
|---|---|---|---|---|---|---|
| Validate CO Password (AM2) | Validate the current password used to identify and authenticat e the CO role using AM2. | Approv ed mode indicat or and service status output | Password | Successful authenticatio n will allow access to the services allowed for CO role (AM2). | SHA AES A5273 Encrypti on AES A5273 Decrypti on | Crypto- Officer (AM2) - PEK: E - KPK: G,E,Z - KEK: Z - TEK: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z |
| Logout CO (AM1) | Exits command shell interface using AM1. | Approv ed mode indicat or and service status output | Command In | Logout CO/Exits command shell interface | None | Crypto- Officer (AM1) |
| Logout CO (AM2) | CO Logout | Approv ed mode indicat or and service status output | Reboot/Comm and In | Logout CO | None | Crypto- Officer (AM2) |
| Encrypt | Encrypt data using AM2. | Approv ed mode indicat or and service status output | Plaintext | Ciphertext. Success/fail ure status. | AES A5275 Encrypti on | Crypto- Officer (AM2) - TEK: E - KEK: E - KPK: E - DRBG- EI/Seed: E - DRBG- State: E - DRBG- nonce: E |
| Decrypt | Decrypt data using AM2. | Approv ed mode indicat or and service | Ciphertext | Plaintext. Success/fail ure status. | AES A5275 Decrypti on | Crypto- Officer (AM2) - TEK: E - KEK: E - KPK: E |
Z Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Descriptio n | Indicat or status output | Inputs | Outputs | Security Functio ns | SSP Access |
|---|---|---|---|---|---|---|
| Module Status | Provide firmware version, current FIPS status using AM1. | Approv ed mode indicat or and service status output | Command in | Module HW version, version information, and FIPS status. | None | Crypto- Officer (AM1) |
| Self-Tests | Perform module self-tests comprised of cryptograph ic algorithm tests, firmware integrity test, and critical functions test. Initiated by module reset or transition from power off state to power on state using AM1 or UA. | Approv ed mode indicat or and service status output | Power on/Command In | Success/Re set. | AES A5275 Encrypti on AES A5275 Decrypti on Key Generati on Signatur e Verificati on Entropy KTS- Unwrap SHA AES A5273 Encrypti on AES A5273 Decrypti on IDK Generati on DRBG | Crypto- Officer (AM1) - FW-LD- Pub: E Unauthentic ated - FW-LD- Pub: E |
| Module Configurat ion | Set configuratio n parameters used to specify | Approv ed mode indicat or and service | Configuration parameters | Updated module configuratio n. Success/fail ure status. | None | Crypto- Officer (AM1) - KPK: G,E,Z - KEK: Z - TEK: Z |
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Descriptio n module behavior using AM1. | Indicat or status output | Inputs | Outputs | Security Functio ns | SSP Access - CO PWD (AM1): W,Z - PWD Hash: W,Z - CO PWD (AM2): W,Z |
|---|---|---|---|---|---|---|
| Set FIPS Mode | Update module approved mode using AM1. | Approv ed mode indicat or and service status output | Configuration parameters | Updated module approved mode/Displa y current approved mode | None | Crypto- Officer (AM1) |
| Configure OTEK | Set configuratio n parameters used for communicat ion with the KMF for OTEK using AM1. | Approv ed mode indicat or and service status output | Configuration parameters | Updated OTEK configuratio n. Success/fail ure status. | None | Crypto- Officer (AM1) |
| Version Query | Provides module firmware and hardware version numbers using AM1. | Approv ed mode indicat or and service status output | Command In | Show module version info | None | Crypto- Officer (AM1) |
| Delete Key | Mark key for deletion using AM2. | Approv ed mode indicat or and service status output | Command In | Key is marked for deletion. Success/fail ure status. | None | Crypto- Officer (AM2) |
| Perform Key Transport Process | Perform a key transport process for OTEK service using AM2. | Approv ed mode indicat or and service | Command In | Keys imported into the MACE. Success/fail ure status. | KTS- Unwrap AES A5273 Decrypti on | Crypto- Officer (AM2) - KEK: W |
W,Z Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Descriptio n | Indicat or status output | Inputs | Outputs | Security Functio ns | SSP Access |
|---|---|---|---|---|---|---|
| KVL Transfer Key | Imports keys to the ASTRO CDEM MACE via KVL using AM2. | Approv ed mode indicat or and service status output | Encrypted Keys | Keys imported into the ASTRO CDEM MACE. Success/fail ure status. | KTS- Unwrap | Crypto- Officer (AM2) - BKK: E - KPK: E - KEK: W - TEK: W |
| KVL Delete Key | Zeroize selected key variables from the ATRO CDEM MACE using AM2. | Approv ed mode indicat or and service status output | Command In | Keys deleted from the ASTRO CDEM MACE. Success/fail ure status. | None | Crypto- Officer (AM2) - KEK: Z - TEK: Z |
| KVL Check Key | Obtain status information about a specific key/keyset using AM2. | Approv ed mode indicat or and service status output | Command In | Show key status | None | Crypto- Officer (AM2) - BKK: E |
| KVL Query Algorithm List | Provides algorithm version numbers using AM2. | Approv ed mode indicat or and service status output | Command In | Show list of supported algorithms | None | Crypto- Officer (AM2) |
| KVL Query Version | Provides module firmware version numbers using AM2. | Approv ed mode indicat or and service status output | Command In | Show module version info | None | Crypto- Officer (AM1) |
| Extract Error Log | Provide the history of error events using AM1. | Approv ed mode indicat | Command In | Error logs out. Success/Fail ure status. | None | Crypto- Officer (AM1) |
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Descriptio n | Indicat or or and service status output | Inputs | Outputs | Security Functio ns | SSP Access |
|---|---|---|---|---|---|---|
| Reset Crypto Module | Reset/powe r cycle the ASTRO CDEM MACE. | Approv ed mode indicat or and service status output | Reset Button press/Cycle power. | Reset the MACE. | None | Unauthentic ated - DRBG- EI/Seed: Z - DRBG- State: Z - DRBG- nonce: Z - BKK: Z - IDK: Z - PEK: Z - KPK: Z - KEK: Z - TEK: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z - FW-LD- Pub: Z - IDK-ROM: Z - IDK-Block: Z |
| Erase Crypto Module | Zeroize the KPK and all keys and CSPs in the key database and causes a new KPK to be generated. Resets the password to the factory default. | Approv ed mode indicat or and service status output | Erase Button press | Zeroize all CSPs | None | Unauthentic ated - KPK: G,Z - KEK: Z - TEK: Z - CO PWD (AM1): Z - CO PWD (AM2): Z - PWD Hash: Z |
Z Z Z Z Table 14: Approved Services Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
There are no Non-Approved services available while the module is in the approved mode. N/A for this module.
This module supports loading of external firmware via the Program Update service. Execution of the successfully loaded firmware is only effective after the next reset of the security module. Any firmware loaded into the module other than that listed in section 2.2 Tested and Vendor Affirmed Module Version and Identification, is outside the scope of this Security Policy and requires a separate FIPS 140-3 validation. The module validates the integrity of the externally loaded firmware via procedures described in section
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
The Module has a limited modifiable operational environment under the FIPS 140-3 definitions. The Module is composed of the following firmware components:
The operator can initiate the integrity test on demand by power cycling the Module. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
Type of Operational Environment: Limited The ASTRO CDEM MACE has a limited operational environment under the FIPS 140-3 definitions with a Physical Security at Level 3. Therefore, per the FIPS 140-3 Management Manual Section 7.5, partial validations and non-applicable areas in this section are not applicable. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Mechanism | Inspection Frequency | Inspection Guidance | |
|---|---|---|---|
| Covered with a hard-opaque epoxy coating that provides evidence of attempts to tamper with the ASTRO CDEM MACE. | Periodically | Look for signs of tampering. Remove from service if tampering found. |
| Temp/Voltage Type | Temperature or Voltage | EFP or EFT | Result |
|---|---|---|---|
| LowTemperature | -38.1°C | EFP | Shutdown - A tamper flag is raised, a wake-up reset of the product is triggered. |
| HighTemperature | 101.4°C | EFP | Shutdown - A tamper flag is raised, a wake-up reset of the product is triggered. |
| LowVoltage | 1.65V - VDDCORE : 1.350V - VVDBU | EFP | Shutdown - A general reset of the chip is asserted. |
| HighVoltage | 2.04V - VDDCORE : 2.292V - VVDBU | EFP | Shutdown- A tamper flag is raised, a wake-up reset of the product is triggered. |
The ASTRO CDEM MACE is a production grade, single-chip cryptographic module with standard passivation over the modules circuitry as defined by FIPS 140-3 and is designed to meet level 3 physical security requirements. The information below is applicable to cryptographic module hardware kit numbers 5185912Y03, 5185912Y05, and 5185912T05, which have identical physical security characteristics.
CDEM MACE's epoxy encapsulate is claimed at the temperature range of -40 to 85 degrees Celsius. No assurance of the epoxy hardness is claimed for this physical security mechanism outside of this range. The ASTRO CDEM MACE does not contain any doors, removable covers, or ventilation holes or slits. No maintenance access interface is available. No special procedures are required to maintain physical Table 15: Mechanisms and Actions Required Table 16: EFP/EFT Information Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Temperature Type | Temperature |
|---|---|
| LowTemperature | -40°C |
| HighTemperature | 85°C |
Table 17: Hardness Testing Temperatures Notes: The module is hardness tested at the lowest and highest temperatures within the module's intended temperature range of operation. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
The Module does not implement any mitigation method against non-invasive attack. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Storage Area Name | Description | Persistence Type |
|---|---|---|
| System Memory (S1) | Stored in the volatile memory (RAM). | Dynamic |
| Flash Memory (S2) | Stored in the flash in plaintext, associated by memory location (pointer). | Static |
| Flash Memory - Encrypted (S3) | Stored in the flash in encrypted, associated by memory location (pointer). | Static |
| Name | From | To | Format Type | Distribution Type | Entry Type | SFI or Algorithm |
|---|---|---|---|---|---|---|
| Input encrypted on the IDK (I1) | Application Software (outside) | Flash Memory - Encrypted (S3) | Encrypted | Manual | Electronic | AES A5273 Decryption |
| Input encrypted on the PEK(I2) | Application Software (outside) | Flash Memory - Encrypted (S3) | Encrypted | Manual | Electronic | AES A5273 Decryption |
| Input encrypted on the KEK (I3) | OTAR | Flash Memory - Encrypted (S3) | Encrypted | Automated | Electronic | KTS- Unwrap |
| Input encrypted on the BKK (I4) | Application Software (outside) | Flash Memory - Encrypted (S3) | Encrypted | Manual | Electronic | AES A5273 Decryption |
| Zeroization Method | Description | Rationale | Operator Initiation | ||
|---|---|---|---|---|---|
| Z1 | Zeroized by the "Program Update" service by overwriting with a fixed pattern of 0s. * | SSPs zeroized upon loading of new firmware. | Yes |
Table 19: SSP Input-Output Methods
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Zeroization Method | Description | Rationale | Operator Initiation |
|---|---|---|---|
| Z2 | Zeroized by module power cycle or hard reset by overwriting with a fixed pattern of 0s. * | SSPs in volatile memory zeroized. | Yes |
| Z3 | Zeroized by the "Configure Module" service by overwriting with a fixed pattern of 0s. | CO zeroize module when configuring into an Approved mode. | Yes |
| Z4 | Zeroized by the "Change CO Password (AM1)" service by overwriting with a fixed pattern of 0s. | Old CO password zeroized as new CO password set | Yes |
| Z5 | Zeroized by the "Validate CO Password (AM1)" service by overwriting with a fixed pattern of 0s. | CO password zeroized after too many failed login attempts | Yes |
| Z6 | Zeroized by the "Change CO Password (AM2)" service by overwriting with a fixed pattern of 0s. | Old Crypto Officer password zeroized as new Crypto Officer password set | Yes |
| Z7 | Zeroized by the "Validate CO Password (AM2)" service by overwriting with a fixed pattern of 0s. | Crypto Officer password zeroized after too many failed login attempts | Yes |
| Z8 | Zeroized by Tamper event. (KPK) is zeroized with a fixed pattern of 0s. | Zeroizes KPK | N/A |
Table 20: SSP Zeroization Methods Note: For zeroization methods with an asterisk, once zeroization is complete the Module will reboot, indicating successful zeroization. The output status of all other methods of success of zeroization are implicit and any attempt to use previous keys/CSPs will trigger an error. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By |
|---|---|---|---|---|---|---|
| DRBG- EI/Seed | Internally generated by the HWRNG | 2770 - N/A | N/A - CSP | Entropy | DRBG | |
| DRBG- State | CTR_DRBG internal state: V (128 bits) and Key (AES 256) | 256 - 256 | N/A - CSP | DRBG | DRBG | |
| DRBG- nonce | Internally generated by the HWRNG | 128 - N/A | N/A - CSP | Entropy | DRBG | |
| BKK | A 256-bit AES OFB (A5273) key used to decrypt keys loaded from KVL | 256 - 256 | Symmetric Key - CSP | Other | AES A5273 Decryption | |
| IDK | A 256-bit AES CBC key used to decrypt downloaded firmware images. | 256 - 256 | Symmetric Key - CSP | IDK Generation | AES A5273 Decryption | |
| PEK | 256-bit AES-CFB8 key used for decrypting passwords during password validation | 256 - 256 | Symmetric Key - CSP | Pre-loaded at manufacturing | AES A5273 Decryption | |
| KPK | 256 bit AES CFB-8 key used to encrypt all TEKs and KEKs stored in the flash. | 256 - 256 | Symmetric Key - CSP | Key Generation | Key Generation AES A5273 Decryption | |
| KEK | 256-bit AES-KW key used for decryption of keys in key transport operation | 256 - 256 | Symmetric Key - CSP | KTS-Unwrap AES A5273 Decryption | ||
| TEK | 256-bit AES-KW key used for enabling secure communication with target devices. | 256 - 256 | Symmetric Key - CSP | KTS-Unwrap AES A5273 Decryption | ||
| CO PWD (AM1) | 8-32 ASCII characters CO password. | N/A - N/A | Authentication - CSP | AES A5273 Encryption AES A5273 Decryption |
All usage of these SSPs by the Module are described in the services detailed in Section 4.3 Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By |
|---|---|---|---|---|---|---|
| CO PWD (AM2) | 8-32 ASCII characters Crypto Officer password. | N/A - N/A | Authentication - CSP | AES A5273 Encryption AES A5273 Decryption | ||
| PWD Hash | 256-bit password hash stored in the non-volatile memory. | 256 - 128 | Authentication - CSP | SHA | SHA | |
| FW-LD- Pub | 2048-bit RSA key used to validate the signature of the firmware image during FW integrity and FW Loading before it is allowed to be executed. | 2048 - 112 | Asymmetric Public Key - PSP | Pre-loaded at manufacturing | Signature Verification | |
| IDK- ROM | A 256-bit AES CBC key used in the re-construction of IDK per SP800-133r2 (Section 6.3 #2) via XOR using IDK Block | 256 - 256 | Symmetric - CSP | Pre-loaded at manufacturing | CKG - IDK | |
| IDK- Block | A 256-bit AES CBC key used in the re-construction of IDK per SP800-133r2 (Section 6.3 #2) via XOR using IDK ROM | 256 - 256 | Symmetric Key - CSP | Generated with an approved RBG and pre-loaded at manufacturing | CKG - IDK |
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs |
|---|---|---|---|---|---|
| DRBG- EI/Seed | System Memory (S1):Plaintext | When module is reset | Z2 | DRBG-nonce:Used With DRBG-State:Generates | |
| DRBG-State | System Memory (S1):Plaintext | When the module is rest | Z2 | DRBG-EI/Seed:Derived From DRBG-nonce:Derived From | |
| DRBG- nonce | System Memory (S1):Plaintext | When module is reset | Z2 | DRBG-EI/Seed:Used With DRBG-State:Generates |
Table 21: SSP Table 1 Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs |
|---|---|---|---|---|---|
| BKK | Input encrypted on the IDK (I1) | System Memory (S1):Plaintext Flash Memory (S2):Plaintext | When module is reset | Z1 Z2 | KEK:Decrypts TEK:Decrypts |
| IDK | System Memory (S1):Plaintext | When module is reset | Z2 | IDK-ROM:Derived From IDK-Block:Derived From PEK:Decrypts KEK:Decrypts | |
| PEK | Input encrypted on the IDK (I1) | System Memory (S1):Plaintext Flash Memory (S2):Plaintext | When module is reset | Z1 Z2 | CO PWD (AM1):Decrypts CO PWD (AM2):Decrypts PWD Hash:Used With |
| KPK | System Memory (S1):Plaintext Flash Memory (S2):Plaintext | When module is reset | Z1 Z3 Z4 Z5 Z6 Z7 Z8 | DRBG-State:Derived From | |
| KEK | Input encrypted on the KEK (I3) Input encrypted on the BKK (I4) | System Memory (S1):Plaintext Flash Memory (S2):Plaintext | When module is reset | Z1 Z2 | KPK:Encrypted by TEK:Decrypts |
| TEK | Input encrypted on the KEK (I3) Input encrypted on the BKK (I4) | System Memory (S1):Plaintext Flash Memory - Encrypted (S3):Encrypted | When module is reset | Z1 Z2 | KPK:Encrypted by |
| CO PWD (AM1) | Input encrypted on the PEK(I2) | System Memory (S1):Plaintext Flash Memory - Encrypted (S3):Encrypted | When module is reset | Z1 Z3 Z4 Z5 Z6 Z7 | PEK:Encrypted by |
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs |
|---|---|---|---|---|---|
| CO PWD (AM2) | Input encrypted on the PEK(I2) | System Memory (S1):Plaintext Flash Memory - Encrypted (S3):Encrypted | When module is reset | Z1 Z3 Z4 Z5 Z6 Z7 | PEK:Encrypted by |
| PWD Hash | System Memory (S1):Plaintext Flash Memory - Encrypted (S3):Encrypted | When module is reset | Z1 Z3 Z4 Z5 Z6 Z7 | CO PWD (AM1):Hash of CO PWD (AM2):Hash of | |
| FW-LD-Pub | System Memory (S1):Plaintext Flash Memory (S2):Plaintext | When module is reset | Z1 | IDK:Encrypted by | |
| IDK-ROM | System Memory (S1):Plaintext Flash Memory (S2):Plaintext | When module is reset | Z1 Z2 | IDK:Generates IDK-Block:Paired With | |
| IDK-Block | System Memory (S1):Plaintext Flash Memory (S2):Plaintext | When module is reset | Z1 Z2 | IDK:Generates IDK-ROM:Paired With |
Table 22: SSP Table 2 Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | ||
|---|---|---|---|---|---|---|---|
| Firmware Integrity | SHA2-256 (Cert. #817), RSA- 2048 (Cert. #A5253) | KAT | SW/FW Integrity | E2 on failure | When the ASTRO CDEM MACE is powered up, the digital signature is verified. |
The ASTRO CDEM MACE performs self-tests to ensure the proper operation. Per FIPS 140-3 these are categorized as either pre-operational selftests or conditional self-tests. Pre-operational self–tests are available on demand by power cycling the ASTRO CDEM MACE. In addition, pre-operational self–tests are periodically performed by the ASTRO CDEM MACE as configured by the operator during the module configuration as shown in section 11.1 Installation, Initialization, and Startup Procedures The ASTRO CDEM MACE will not accept any commands when a periodic self-test is required; the commands still in the I/O buffer will be processed by the ASTRO CDEM MACE after periodic self-test ends and will execute when the I/O buffer is emptied. The ASTRO CDEM MACE logs the most recent self-test errors to the internal flash; the operator (CO) can extract the error logs using Extract Error Log service. The Module performs the following pre-operational self-tests in table below Table 23: Pre-Operational Self-Tests
The Module performs the following conditional self-tests in the table below Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| AES-Encryption (A5273) | AES-256 | KAT | CAST | ES1 on failure | Encryption | Bootup/Periodic |
| AES-Decryption (A5273) | AES-256 | KAT | CAST | ES1 on failure | Decryption | Bootup/Periodic |
| AES-Encryption (A5275) | AES-256 | KAT | CAST | ES1 on failure | Encryption | Bootup/Periodic |
| AES-Decryption (A5275) | AES-256 | KAT | CAST | ES1 on failure | Decryption | Bootup/Periodic |
| AES-KW (A5438) | AES-256 | KAT | CAST | ES1 on failure | Decryption | Bootup/Periodic |
| Counter DRBG (A5437) | AES-256 CTR | KAT | CAST | ES1 on failure | AES-256 CTR_DRBG instantiation, generate KATs performed before the first random data generation | Bootup/Periodic |
| SHA2-256 (SHS 817) | SHA2-256 | KAT | CAST | E2 on failure | SHA2, -256, KAT performed before Pre-Operational FW integrity tests. | Bootup |
| RSA SigVer (FIPS186-5) (A5253) | RSA-2048 SigVer | KAT | CAST | E2 on failure | RSA-2048 SigVer, performed before Pre-Operational FW integrity tests. | Bootup |
| Entropy 90B Start-up Repetition Count Test (RCT) | Repetition Count Test | RCT | CAST | ES1 on failure | Designed to quickly detect catastrophic failures that cause the noise source to become "stuck" on a single output value for a long period of time | Bootup |
| Entropy 90B Start-up Adaptive Proportion Test (ADP) | Adaptive Proportion Test | ADP | CAST | ES1 on failure | Designed to detect a large loss of entropy that might occur as a result of some physical failure or environment al change affecting the noise source | Bootup |
| Firmware Load | 2048-bit RSA Signature Verification/SHA2-256 | KAT | SW/FW Load | E2 on failure | A digital signature is generated over the code when it is built using SHA-256 and RSA-2048. | loading a new firmware image |
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
Algorithm or Test
Test Properties
Test Method
Test Type
Indicator
Details The digital signature is verified upon download into the ASTRO CDEM MACE.
Conditions
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method | |||||
|---|---|---|---|---|---|---|---|---|---|
| Firmware Integrity | KAT | SW/FW Integrity | On Demand | Manually |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| AES-Encryption (A5273) | KAT | CAST | On Demand/Periodically | Manually/Programmatically |
| AES-Decryption (A5273) | KAT | CAST | On Demand/Periodically | Manually/Programmatically |
| AES-Encryption (A5275) | KAT | CAST | On Demand/Periodically | Manually/Programmatically |
| AES-Decryption (A5275) | KAT | CAST | On Demand/Periodically | Manually/Programmatically |
| AES-KW (A5438) | KAT | CAST | On Demand/Periodically | Manually/Programmatically |
| Counter DRBG (A5437) | KAT | CAST | On Demand/Periodically | Manually/Programmatically |
Table 24: Conditional Self-Tests
Table 25: Pre-Operational Periodic Information Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| SHA2-256 (SHS 817) | KAT | CAST | On Demand/Periodically | Manually/Programmatically |
| RSA SigVer (FIPS186- 5) (A5253) | KAT | CAST | On Demand/Periodically | Manually/Programmatically |
| Entropy 90B Start-up Repetition Count Test (RCT) | RCT | CAST | On Demand | Manually |
| Entropy 90B Start-up Adaptive Proportion Test (ADP) | ADP | CAST | On Demand | Manually |
| Firmware Load | KAT | SW/FW Load | On Demand | Manually |
Table 26: Conditional Periodic Information Conditional self–tests are periodically performed by the ASTRO CDEM MACE every X hours, where X is configured by the operator during module configuration (1 hour to 720 hours). The ASTRO CDEM MACE will not accept any commands when a periodic self-test is required; the commands still in the I/O buffer will be processed by the ASTRO CDEM MACE end the periodic self-test executed when the I/O buffer is emptied. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| ES1 | The ASTRO CDEMMACE fails a KAT. | The ASTRO CDEM MACE enters the critical error state. In this state, the ASTRO CDEM MACE stores the status into the internal flash memory and then halts all further operation by entering an infinite loop. | Reboot/Power cycle the module | Sets the status alarm LED. |
| ES2 | The ASTRO CDEMMACE fails a firmware loading during program upgrade and/or firmware integrity pre-operational self- test. | The ASTRO CDEM MACE enters the firmware signature validation failure state. In this state, the ASTRO CDEM MACE halts all further operations by entering the flash programming mode. | Reboot/Power cycle the module or re-flashing a new image. | Sets the status alarm LED. |
Table 27: Error States Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
Installation and Initialization: The Module is originally a non-compliant module and must be initialized to be in Approved mode. There is no non-Approved mode. During initialization the operator shall configure the Module from the instructions below:
Use vendor provided product specific user guide for secure operations.
Rules of Operation
After the end-of-life, the operator should zeroize all SSPs using “Erase Crypto Module“ service followed by shredding the ASTRO CDEM MACE chip.
The Module does not implement any mitigation method against other attacks. Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Abbreviation* | Full Specification Name |
|---|---|
| [FIPS140-3] | Security Requirements for Cryptographic Modules, March 22, 2019 |
| [ISO19790] | International Standard, ISO/IEC 19790, Information technology — Security techniques — Test requirements for cryptographic modules, Third edition, March 2017 |
| [ISO24759] | International Standard, ISO/IEC 24759, Information technology — Security techniques — Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015 |
| [IG] | Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, August 30, 2024 |
| [133] | NIST Special Publication 800-133, Recommendation for Cryptographic Key Generation, Revision 2, June 2020 |
| [186-5] | National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-5, February 2023. |
| [197] | National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197, November 26, 2001, Updated May 9, 2023 |
| [180] | National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August, 2015 |
| [38A] | National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation, Methods and Techniques, Special Publication 800-38A, December 2001 |
| [38F] | National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping, Special Publication 800-38F, December 2012 |
| [90A] | National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A, Revision 1, June 2015. |
| [90B] | National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018. |
| [OTAR] | Project 25 – Digital Radio Over-The-Air-Rekeying (OTAR) Messages and Procedures [TIA- 102.AACA-A], September 2014 |
References and Definitions The following standards are referred to in this Security Policy. Table 28 References Table 29 Acronyms and Definitions Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Acronym* | Definition |
|---|---|
| AES | Advanced Encryption Standard |
| BKK | Black Keyloading Key |
| CAI | Common Air Interface |
| CBC | Cipher Block Chaining |
| CDEM | CAI Data Encryption Module |
| CFB | Cipher Feedback |
| CKG | Cryptographic Key Generation |
| CSP | Critical Security Parameter |
| DRBG | Deterministic Random Bit Generator |
| DRBG-El | DRBG Entropy Input |
| ECB | Electronic Code Book |
| FIPS | Federal Information Processing Standards |
| FW | Firmware |
| FW-LD-Pub | Firmware Load Public Key |
| IC | Integrated Circuit |
| IDK | Image Decryption Key |
| IV | Initialization Vector |
| KAT | Known Answer Test |
| KPK | Key Protection Key |
| KEK | Key Encryption Key |
| KVL | Key Variable Loader |
| MAC | Message Authentication Code |
| MACE | Motorola Advanced Crypto Engine |
| OFB | Output Feedback |
| OTAR | Over The Air Rekeying |
| PEK | Password Encryption Key |
| PWD Hash | Password Hash |
| RSA | Rivest–Shamir–Adleman |
| SSI | Synchronous Serial Interface |
| SSP | Sensitive Security Parameter |
| TEK | Traffic Encryption Key |
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).
| Acronym* | Definition | ||
|---|---|---|---|
| UA | Unauthenticated Service |
Motorola Solutions Public Material – May be reproduced only in its original entirety (without revision).