All modules
CMVP Validated Module · FIPS 140-3 Security Policy

AWS-LC Cryptographic Module (dynamic)

Certificate#5146StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorAmazon Web Services, Inc
Low review priority  ·  no TCB surface named  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date1/25/2031
CaveatWhen operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
VendorAmazon Web Services, Inc

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for AWS-LC Cryptographic Module (dynamic)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery<br/>upgrade</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for AWS-LC Cryptographic Module (dynamic)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery<br/>upgrade</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Amazon Web Services, Inc AWS-LC Cryptographic Module (dynamic) Document version: 1.2 Last update: 2026-01-20 © 2026 Amazon Web Services, Inc., atsec information security.

Page 2

Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 www.atsec.com © 2026 Amazon Web Services, Inc., atsec information security.

2 of 48

Page 3
Table of Contents
#SectionPage
Page 4

© 2026 Amazon Web Services, Inc., atsec information security.

4 of 48

Page 5
List of Tables
ItemPage
Table 1: Security Levels7
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)9
Table 3: Tested Operational Environments - Software, Firmware, Hybrid9
Table 4: Modes List and Description9
Table 5: Approved Algorithms12
Table 6: Vendor-Affirmed Algorithms12
Table 7: Non-Approved, Allowed Algorithms with No Security Claimed12
Table 8: Non-Approved, Not Allowed Algorithms13
Table 9: Security Function Implementations15
Table 10: Ports and Interfaces20
Table 11: Roles21
Table 12: Approved Services26
Table 13: Non-Approved Services27
Table 14: Storage Areas32
Table 15: SSP Input-Output Methods32
Table 16: SSP Zeroization Methods33
Table 17: SSP Table 135
Table 18: SSP Table 236
Table 19: Pre-Operational Self-Tests37
Table 20: Conditional Self-Tests41
Table 21: Pre-Operational Periodic Information42
Table 22: Conditional Periodic Information44
Table 23: Error States45
Page 6
List of Figures
ItemPage
Figure 1: Block Diagram8
Page 7
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version AWS-LC FIPS 1.29.1 of the AWSLC Cryptographic Module (dynamic). It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module.

1.2 Security Levels
1.3 Additional Information

This Security Policy describes the features and design of the module named AWS-LC Cryptographic Module (dynamic) using the terminology contained in the FIPS 140-3 specification. The FIPS 140-3 Security Requirements for Cryptographic Module specifies the security requirements that will be satisfied by a cryptographic module utilized within a security system protecting sensitive but unclassified information. The NIST/CCCS Cryptographic Module Validation Program (CMVP) validates cryptographic module to FIPS 140-3. Validated products are accepted by the Federal agencies of both the USA and Canada for the protection of sensitive or designated information. including this notice. Other documentation is proprietary to their authors. In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. © 2026 Amazon Web Services, Inc., atsec information security.

7 of 48

Page 8
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
bcm.o on NetOS 2024 on AS7772 on NXP T-Series T2080AWS-LC FIPS 1.29.1N/AHMAC-SHA2-256
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The AWS-LC Cryptographic Module (dynamic) (hereafter referred to as “the module”) provides cryptographic services to applications running in the user space of the underlying operating system through a C language Application Program Interface (API). Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The block diagram in Figure 1 shows the cryptographic boundary of the module, its interfaces with the operational environment and the flow of information between the module and operator (depicted through the arrows). The cryptographic boundary is defined as the AWS-LC Cryptographic Module (dynamic) which is a cryptographic library consisting of the bcm.o file (version AWS-LC FIPS 1.29.1). This file is dynamically linked to the userspace application during the compilation process. Tested Operational Environment’s Physical Perimeter (TOEPP): The PAA provided by the processor is located within the module’s physical perimeter and outside of the module’s cryptographic boundary. Figure 1: Block Diagram

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): © 2026 Amazon Web Services, Inc., atsec information security.

8 of 48

Page 9
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
bcm.o on NetOS 2024 on CS8274 on NXP Layerscape LX2080AWS-LC FIPS 1.29.1N/AHMAC-SHA2-256
bcm.o on NetOS 2024 v1.1 on AZ3324 on NXP Layerscape LX2080AWS-LC FIPS 1.29.1N/AHMAC-SHA2-256
bcm.o on NetOS 2024 on CS8320 on Annapurna K2X-NAWS-LC FIPS 1.29.1N/AHMAC-SHA2-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
NetOS 2024CS8274NXP Layerscape LX2080 (ARMv8)YesN/AAWS-LC FIPS 1.29.1
NetOS 2024CS8320Annapurna K2X-N (ARMv8)YesN/AAWS-LC FIPS 1.29.1
NetOS 2024 v1.1AZ3324NXP Layerscape LX2080 (ARMv8)YesN/AAWS-LC FIPS 1.29.1
NetOS 2024AS7772NXP T-Series T2080 (Power 7)NoN/AAWS-LC FIPS 1.29.1
NetOS 2024CS8274NXP Layerscape LX2080 (ARMv8)NoN/AAWS-LC FIPS 1.29.1
NetOS 2024CS8320Annapurna K2X-N (ARMv8)NoN/AAWS-LC FIPS 1.29.1
NetOS 2024 v1.1AZ3324NXP Layerscape LX2080 (ARMv8)NoN/AAWS-LC FIPS 1.29.1
Mode NameDescriptionTypeStatus Indicator
Approved ModeAutomatically entered whenever an approved service is requested.ApprovedEquivalent to the indicator of the requested service as defined in section 4.3
Non-approved ModeAutomatically entered whenever a non- approved service is requested.Non- ApprovedEquivalent to the indicator of the requested service as defined in section 4.3

Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) Tested Operational Environments - Software, Firmware, Hybrid: Table 3: Tested Operational Environments - Software, Firmware, Hybrid

2.3 Excluded Components
2.4 Modes of Operation

Modes List and Description: Table 4: Modes List and Description Mode Change Instructions and Status: When the module starts up successfully, after passing a set of cryptographic algorithms self-tests (CASTs) and the pre-operational self-test, the module is operating in the approved mode of operation by default and can only be transitioned into the non-approved mode by calling one of the non-approved services listed in the NonApproved Services table. The module will transition back to approved mode when approved service is called. Section 4 provides details on the service indicator implemented by the module. The service indicator identifies © 2026 Amazon Web Services, Inc., atsec information security.

9 of 48

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CBCA5422, A5427, A5429, A5431Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA5422, A5427, A5429, A5431Key Length - 128SP 800-38C
AES-CMACA5422, A5427, A5429, A5431Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CTRA5422, A5427, A5429, A5431Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5422, A5423, A5427, A5428, A5429, A5430, A5431, A5432, A5435Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA5423, A5428, A5430, A5432, A5435Direction - Decrypt, Encrypt IV Generation - External, Internal Key Length - 128, 256 IV Generation Mode - 8.2.1, 8.2.2SP 800-38D
AES-GMACA5423, A5428, A5430, A5432, A5435Direction - Decrypt, Encrypt IV Generation - External, Internal Key Length - 128, 256 IV Generation Mode - 8.2.1, 8.2.2SP 800-38D
AES-KWA5422, A5427, A5429, A5431Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA5422, A5427, A5429, A5431Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-XTS Testing Revision 2.0A5422, A5427, A5429, A5431Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
Counter DRBGA5422, A5427, A5429, A5431Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A5425, A5426, A5433, A5434Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A5425, A5426, A5433, A5434Curve - P-224, P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A5425, A5426, A5433, A5434Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-4)A5425, A5426, A5433, A5434Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A5425, A5426, A5433, A5434Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-5
HMAC-SHA-1A5425, A5426, A5433, A5434Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
2.5 Algorithms

Approved Algorithms: © 2026 Amazon Web Services, Inc., atsec information security.

10 of 48

Page 11
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2-224A5425, A5433, A5434Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5425, A5433, A5434Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5425, A5433, A5434Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5425, A5433, A5434Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A5425, A5433, A5434Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A5425, A5433, A5434Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A5425, A5426, A5433, A5434Domain Parameter Generation Methods - P- 224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800- 56Cr1A5425, A5426, A5433, A5434Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512SP 800-56C Rev. 2
KDF SSH (CVL)A5425, A5426, A5433, A5434Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF TLS (CVL)A5425, A5426, A5433, A5434TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
PBKDFA5425, A5426, A5433, A5434Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 14-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-5)A5425, A5426, A5433, A5434Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186-5)A5425, A5426, A5433, A5434Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-4)A5425, A5426, A5433, A5434Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-5)A5425, A5426, A5433, A5434Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A5425, A5426, A5433, A5434Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-224A5425, A5433, A5434Message Length - Message Length: 0-65536 Increment 8FIPS 180-4

© 2026 Amazon Web Services, Inc., atsec information security.

11 of 48

Page 12
AlgorithmCAVP CertPropertiesReference
SHA2-256A5425, A5433, A5434Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A5425, A5433, A5434Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A5425, A5433, A5434Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512/224A5425, A5433, A5434Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512/256A5425, A5433, A5434Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA3-224A5424Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-256A5424Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-384A5424Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-512A5424Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHAKE-128A5424Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A5424Output Length - Output Length: 16-65536 Increment 8FIPS 202
NamePropertiesImplementationReference
Cryptographic Key Generation (CKG)Key Type:Asymmetric RSA (FIPS 186-5):2048, 3072, 4096 bits with 112, 128, 150 bits of key strength. EC (FIPS 186-5):P-224, P-256, P-384, P-521 elliptic curves with 112-256 bits of key strengthN/ASP 800-133Rev2 section 4, example 1
NameCaveatUse and Function
MD5Allowed per IG 2.4.AMessage Digest used in TLS 1.0/1.1 KDF only
Non-Approved, Not Allowed Algorithms: NameUse and Function
AES with OFB or CFB1, CFB8 modesEncryption, Decryption (not CAVP tested)
AES GCM, GMAC, XTS with keys not listed in Table 5Encryption, Decryption
AES using aes_*_generic functionEncryption, Decryption (not CAVP tested)

Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms N/A for this module. © 2026 Amazon Web Services, Inc., atsec information security.

12 of 48

Page 13
Non-Approved, Not Allowed Algorithms: NameUse and Function
AES GMAC using aes_*_genericMessage Authentication Generation (not CAVP tested)
Curve secp256k1Signature Generation, Signature Verification, Shared Secret Computation
Diffie HellmanShared Secret Computation (not CAVP tested)
HMAC-MD4, HMAC-MD5, HMAC-SHA-3, HMAC-RIPEMD-160Message Authentication Generation (not CAVP tested)
MD4Message Digest
MD5 (outside of TLS)Message Digest
RSA using RSA_generate_key_exKey Generation (not complaint with FIPS186- 5)
ECDSA using EC_KEY_generate_keyKey Generation (not complaint with FIPS186- 5)
RSA using keys less than 2048 bitsSignature Generation
RSA using keys less than 1024 bitsSignature Verification
RSA without hashingSign/Verify primitive operations
RSA encryption primitive with PKCS#1 v1.5 and OAEP paddingEncryption
SHA-1, SHA-3Signature Generation (not CAVP tested)
RIPEMD-160Message Digest
TLS KDF using any SHA algorithms other than SHA2-256, SHA2-384, SHA2-512; or TLS KDF using non-extended master secretKey Derivation
RSAKey Encapsulation/Un-encapsulation (not compliant with SP 800-56BRev2)

Name Shared Secret Computation with EC Diffie-Hellman Authenticated Encryption/Decryption with AES KW, AES- KWP Encryption/Decryption with AES

Type KAS-SSC BC-Auth BC-UnAuth

Description SP800-56Arev3. KAS- ECC-SSC per IG D.F Scenario 2 path (1). SP800-38F. Authenticated encryption, Authenticated decryption SP800-38A and SP 800- 38E. Encryption and Decryption

Properties

Algorithms KAS-ECC-SSC Sp800- 56Ar3: (A5425, A5426, A5433, A5434) AES-KW: (A5422, A5427, A5429, A5431) AES-KWP: (A5422, A5427, A5429, A5431) AES-CBC: (A5422, A5427, A5429, A5431) AES-CTR: (A5422, A5427, A5429, A5431) AES-ECB: (A5422, A5423, A5427, A5428, A5429, A5430, A5431,

2.6 Security Function Implementations

© 2026 Amazon Web Services, Inc., atsec information security.

13 of 48

Page 14

Name Signature Generation with RSA Signature Generation with ECDSA Key Generation with RSA Key Generation with ECDSA Signature Verification with ECDSA Signature Verification with RSA Key Verification with ECDSA Key Derivation with TLS KDF Key Derivation with SSH KDF Key Derivation with KDA HKDF Key Derivation with PBKDF Message Digest with SHA

Type DigSig-SigGen DigSig-SigGen AsymKeyPair-KeyGen CKG AsymKeyPair-KeyGen CKG DigSig-SigVer DigSig-SigVer AsymKeyPair-KeyVer KAS-135KDF KAS-135KDF KAS-56CKDF PBKDF SHA

Description FIPS186-5. Digital signature generation FIPS186-5. Digital signature generation FIPS186-5. Key generation FIPS186-5. Key generation FIPS186-5. Digital signature verification FIPS186-5. Digital signature verification FIPS186-5. Key verification SP800-135rev1. Key derivation SP800-135rev1. Key derivation SP800-56Crev1. Key derivation SP800-132. Key derivation FIPS180-4 and FIPS202. Message digest using SHA

Properties

Algorithms A5432, A5435) AES-XTS Testing Revision 2.0: (A5422, A5427, A5429, A5431) RSA SigGen (FIPS186- 5): (A5425, A5426, A5433, A5434) ECDSA SigGen (FIPS186-5): (A5425, A5426, A5433, A5434) RSA KeyGen (FIPS186- 5): (A5425, A5426, A5433, A5434) ECDSA KeyGen (FIPS186-5): (A5425, A5426, A5433, A5434) ECDSA SigVer (FIPS186-5): (A5425, A5426, A5433, A5434) RSA SigVer (FIPS186- 5): (A5425, A5426, A5433, A5434) ECDSA KeyVer (FIPS186-5): (A5425, A5426, A5433, A5434) KDF TLS: (A5425, A5426, A5433, A5434) KDF SSH: (A5425, A5426, A5433, A5434) KDA HKDF Sp800- 56Cr1: (A5425, A5426, A5433, A5434) PBKDF: (A5425, A5426, A5433, A5434) SHA-1: (A5425, A5426, A5433, A5434) SHA2-224: (A5425, A5433, A5434) SHA2-256: (A5425, A5433, A5434) SHA2-384: (A5425, A5433, A5434) SHA2-512: (A5425, A5433, A5434) SHA2-512/224: (A5425, A5433, A5434) SHA2-512/256: (A5425, A5433, A5434)

© 2026 Amazon Web Services, Inc., atsec information security.

14 of 48

Page 15
Name Random Number Generation with DRBG Message Authentication Generation with HMAC Message Authentication Generation with AES Authenticated Encryption/Decryption with AES CCM Authenticated Encryption/Decryption with AES GCM Message Digest with SHAKEType DRBG MAC MAC BC-Auth BC-Auth XOFDescription SP800-90ARev1. Random number generation FIPS198-1. Message authentication generation SP800-38B and SP800- 38D Message authentication generation SP800-38C. Authenticated encryption, Authenticated decryption SP800-38D. Authenticated encryption, Authenticated decryption FIPS202. Message digestPropertiesAlgorithms SHA3-224: (A5424) SHA3-256: (A5424) SHA3-384: (A5424) SHA3-512: (A5424) Counter DRBG: (A5422, A5427, A5429, A5431) HMAC-SHA-1: (A5425, A5426, A5433, A5434) HMAC-SHA2-224: (A5425, A5433, A5434) HMAC-SHA2-256: (A5425, A5433, A5434) HMAC-SHA2-384: (A5425, A5433, A5434) HMAC-SHA2-512: (A5425, A5433, A5434) HMAC-SHA2-512/256: (A5425, A5433, A5434) HMAC-SHA2-512/224: (A5425, A5433, A5434) AES-CMAC: (A5422, A5427, A5429, A5431) AES-GMAC: (A5423, A5428, A5430, A5432, A5435) AES-CCM: (A5422, A5427, A5429, A5431) AES-GCM: (A5423, A5428, A5430, A5432, A5435) SHAKE-128: (A5424) SHAKE-256: (A5424)
Signature Verification with RSA (legacy)DigSig-SigVerFIPS186-4. Legacy digital signature verificationPublications:FIPS 140-3 IG C.M legacy algorithmsRSA SigVer (FIPS186- 4): (A5425, A5426, A5433, A5434)
Signature Verification with ECDSA (legacy)DigSig-SigVerFIPS186-4. Legacy digital signature verificationPublications:FIPS 140-3 IG C.M legacy algorithmsECDSA SigVer (FIPS186-4): (A5425, A5426, A5433, A5434)

Table 9: Security Function Implementations © 2026 Amazon Web Services, Inc., atsec information security.

15 of 48

Page 16
2.7 Algorithm Specific Information
2.7.1 GCM IV

The module offers three AES GCM implementations. The GCM IV generation for these implementations complies respectively with IG C.H under Scenario 1, Scenario 2, and Scenario 5. The GCM shall only be used in the context of the AES-GCM encryption executing under each scenario, and using the referenced APIs explained next. Scenario 1, TLS 1.2 For TLS 1.2, the module offers the GCM implementation via the functions EVP_aead_aes_128_gcm_tls12() and EVP_aead_aes_256_gcm_tls12(), and uses the context of Scenario 1 of IG C.H. The module is compliant with SP800-52rev2 and the mechanism for IV generation is compliant with RFC5288. The module supports acceptable AES-GCM ciphersuites from Section 3.3.1 of SP800-52rev2. The module explicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values of 2^{64-1} for a given session key. If this exhaustion condition is observed, the module returns an error indication to the calling application, which will then need to either abort the connection, or trigger a handshake to establish a new encryption key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established. Scenario 2, Random IV In this implementation, the module offers the interfaces EVP_aead_aes_128_gcm_randnonce() and EVP_aead_aes_256_gcm_randnonce() for compliance with Scenario 2 of IG C.H and SP800-38D Section 8.2.2. The module generates the IV and then performs AES GCM encryption without outputting the IV to the calling application. The 96-bit AES-GCM IV, is generated randomly internal to the module using module’s approved DRBG. Scenario 5, TLS 1.3 For TLS 1.3, the module offers the AES-GCM implementation via the functions EVP_aead_aes_128_gcm_tls13() and EVP_aead_aes_256_gcm_tls13(), and uses the context of Scenario 5 of IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the ciphersuites that explicitly select AES-GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES-GCM ciphersuites from Section 3.3.1 of SP800-52rev2. The module implements, within its boundary, an IV generation unit for TLS 1.3 that keeps control of the 64-bit counter value within the AES-GCM IV. If the exhaustion condition is observed, the module will return an error indication to the calling application, who will then need to either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection. In the event the module’s power is lost and restored, the consuming application must ensure that new AESGCM keys encryption or decryption under this scenario are established. TLS 1.3 provides session resumption, but the resumption procedure derives new AES-GCM encryption keys.

2.7.2 AES XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, © 2026 Amazon Web Services, Inc., atsec information security.

16 of 48

Page 17

such as the encryption of data in transit. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical.

2.7.3 Key Derivation using SP 800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:

2.7.4 Compliance to SP 800-56ARev3 assurances

The module offers ECDH shared secret computation services compliant to the SP 800-56ARev3 and meeting IG D.F scenario 2 path (1). To meet the required assurances listed in section 5.6 of SP 800-56ARev3, the module shall be used together with an application that implements the “TLS protocol” or “SSH protocol” and the following steps shall be performed. • The entity using the module, must use the module's "Key Pair Generation" service for generating ECDH ephemeral keys. This meets the assurances required by key pair owner defined in the section

5.6.2.1 of SP 800-56ARev3.
2.7.5 Approved Modulus Sizes for RSA Digital Signature

RSA SigGen (FIPS 186-5) has been CAVP tested with all the supported RSA modulus lengths (i.e., 2048, 3072, 4096). This is documented in the Approved Algorithms table of the Security Policy. All modulus sizes for SigVer have also been CAVP tested. There is no RSA signature with keys for which CAVP testing is not available. The minimum number of the Miller-Rabin tests used in primality testing complies with Table B.1 in FIPS 186-5. The RSA SigVer (FIPS 186-4) and (FIPS 186-5) have been CAVP tested with the modulus sizes of © 2026 Amazon Web Services, Inc., atsec information security.

17 of 48

Page 18

1024 (FIPS 186-4) and 2048, 3072, 4096 (FIPS 186-5). All modulus sizes in which testing is available have been

tested by the CAVP.

2.7.6 Legacy Algorithms

The cryptographic module implements the following cryptographic algorithms for legacy use. Algorithms designated as “Legacy” can only be used on data that was generated prior to the Legacy Date specified in FIPS 140-3 IG C.M:

2.7.7 Authenticated Encryption/Decryption

The module does not establish SSPs using an approved key transport scheme (KTS). However, it does offer approved authenticated algorithms that can be used by an external operator/application as part of an approved KTS.

2.7.8 KAS-SSC

The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS.

2.8 RBG and Entropy

The module provides an SP800-90Arev1-compliant Deterministic Random Bit Generator (DRBG) using CTR_DRBG mechanism with AES-256, with a derivation function, for generation of key components of asymmetric keys, and random number generation. The DRBG is seeded with 256-bit of entropy input provided from an external entity to the module. This corresponds to scenario 2 (b) of IG 9.3.A i.e., the DRBG that receives a LOAD command from external entropy source outside of module's cryptographic boundary. The calling application shall use an entropy source that meets the security strength required for the CTR_DRBG as shown in NIST SP 800-90Arev1, Table 3 and should return an error if minimum strength cannot be met. Per the IG 9.3.A requirement, the module includes the caveat "No assurance of the minimum strength of generated keys (e.g., keys)".

2.9 Key Generation

The key generation methods implemented by the module are specified in the Vendor-Affirmed Algorithms table. The key derivation methods implemented by the module are specified in the Security Function Implementations table. © 2026 Amazon Web Services, Inc., atsec information security.

18 of 48

Page 19
2.10 Key Establishment

The key establishment methods implemented by the module are specified in the Security Function Implementations table.

2.11 Industry Protocols

The module implements the SSH key derivation function for use in the SSH protocol (RFC 4253 and RFC 6668). GCM with internal IV generation in the approved mode is compliant with versions 1.2 and 1.3 of the TLS protocol (RFC 5288 and 8446) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the TLS 1.2 and TLS 1.3 key derivation functions for use in the TLS protocol. No parts of the SSH, TLS, other than those mentioned above, have been tested by the CAVP and CMVP. © 2026 Amazon Web Services, Inc., atsec information security.

19 of 48

Page 20
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters for data.
N/AData OutputAPI output parameters for data.
N/AControl InputAPI function calls.
N/AStatus OutputAPI return codes, error message.
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 10: Ports and Interfaces The module does not implement the Control Output interface. © 2026 Amazon Web Services, Inc., atsec information security.

20 of 48

Page 21
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
EncryptionEncryptionReturn value 1 from the function: FIPS_service_indicator_check_app roved()AES key, plaintextCiphertextEncryption/Decryp tion with AESCrypto Officer - AES Key: W,E
DecryptionDecryptionReturn value 1 from the function: FIPS_service_indicator_check_app roved()AES key, cipherte xtPlaintextEncryption/Decryp tion with AESCrypto Officer - AES Key: W,E
Authenticat ed EncryptionAuthenticated EncryptionReturn value 1 from the function: FIPS_ service_indicator_check_approved( )AES key, plaintext , IVCiphertext, MAC tagAuthenticated Encryption/Decryp tion with AES KW, AES-KWP Authenticated Encryption/Decryp tion with AES CCM Authenticated Encryption/Decryp tion with AES GCMCrypto Officer - AES Key: W,E
Authenticat ed DecryptionAuthenticated DecryptionReturn value 1 from the function: FIPS_ service_indicator_check_approved( )AES key, cipherte xt, IV, MAC tagPlaintext or failAuthenticated Encryption/Decryp tion with AES KW, AES-KWP Authenticated Encryption/Decryp tion with AES CCM Authenticated Encryption/Decryp tion with AES GCMCrypto Officer - AES Key: W,E
4 Roles, Services, and Authentication
4.2 Roles

Table 11: Roles The module does not support concurrent operators.

4.3 Approved Services

W,E W,E © 2026 Amazon Web Services, Inc., atsec information security.

21 of 48

Page 22
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Message Authenticati on GenerationMAC computationReturn value 1 from the function: FIPS_ service_indicator_check_approved( )AES key or HMAC key, messageMAC tagMessage Authentication Generation with HMAC Message Authentication Generation with AESCrypto Officer - HMAC Key: W,E - AES Key: W,E
Message DigestGenerating message digestReturn value 1 from the function: FIPS_ service_indicator_check_approved( )MessageMessage digestMessage Digest with SHA Message Digest with SHAKECrypto Officer
Random Number GenerationGenerating random numbersReturn value 1 from the function: FIPS_ service_indicator_check_approved( )Output lengthRandom bytesRandom Number Generation with DRBGCrypto Officer - Entropy Input: W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E
Key GenerationGenerating a key pairReturn value 1 from the function: FIPS_service_indicator_check_app roved()Modulus size / CurveRSA public key, RSA private key / EC public key, EC private keyKey Generation with RSA Key Generation with ECDSACrypto Officer - RSA Public Key: G,R - RSA Private Key: G,R - EC Public Key: G,R - EC Private Key: G,R - Intermediat e Key Generation Value: G,E,Z
Key VerificationVerifying the public keyReturn value 1 from the function: FIPS_ service_indicator_check_approved( )Public keySuccess/ errorKey Verification with ECDSACrypto Officer - EC Public Key: W,E
Signature GenerationGenerating signatureReturn value 1 from the function: FIPS_Message, EC privateDigital signatureSignature Generation with RSACrypto Officer - RSA

G,W,E G,W,E G,E,Z © 2026 Amazon Web Services, Inc., atsec information security.

22 of 48

Page 23
NameDescriptionIndicator service_indicator_check_approved( )Inputs key or RSA private key, hash algorith mOutputsSecurity Functions Signature Generation with ECDSASSP Access Private Key: W,E - EC Private Key: W,E
Signature VerificationVerifying signatureReturn value 1 from the function: FIPS_ service_indicator_check_approved( )Signatur e, EC public key or RSA public key, hash algorith mDigital signature verification resultSignature Verification with ECDSA Signature Verification with RSA Signature Verification with RSA (legacy) Signature Verification with ECDSA (legacy)Crypto Officer - RSA Public Key: W,E - EC Public Key: W,E
Shared Secret Computatio nCalculating the Shared SecretReturn value 1 from the function: FIPS_ service_indicator_check_approved( )EC public key, EC private keyShared SecretShared Secret Computation with EC Diffie-HellmanCrypto Officer - EC Public Key: W,E - EC Private Key: W,E - Shared Secret: G,R
Key Derivation with TLS KDFDeriving KeysReturn value 1 from the function: FIPS_ service_indicator_check_approved( )TLS Pre- Master Secret, key lengthTLS Derived Key (AES/HMA C)Key Derivation with TLS KDFCrypto Officer - TLS Pre- Master Secret: W,E - TLS Master Secret: G,E,Z - TLS Derived Key (AES/HMA C): G,R
Key Derivation with PBKDFDeriving KeysReturn value 1 from the function: FIPS_ service_indicator_check_approved( )Passwor d, salt, iteration count, key lengthPBKDF Derived KeyKey Derivation with PBKDFCrypto Officer - PBKDF Derived Key: G,R - Password: W,E

m G,E,Z C): G,R W,E © 2026 Amazon Web Services, Inc., atsec information security.

23 of 48

Page 24
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Key Derivation with KDA HKDFDeriving KeysReturn value 1 from the function: FIPS_ service_indicator_check_approved( )Shared Secret, Key LengthHKDF Derived KeyKey Derivation with KDA HKDFCrypto Officer - HKDF Derived Key: G,R - Shared Secret: W,E - TLS Master Secret: W,E,Z
ZeroizationZeroize SSP in volatile memoryN/ASSPN/ANoneCrypto Officer - AES Key: Z - HMAC Key: Z - Entropy Input: Z - DRBG Seed: Z - DRBG Internal State (V, Key): Z - RSA Public Key: Z - RSA Private Key: Z - EC Public Key: Z - EC Private Key: Z - Shared Secret: Z - TLS Pre- Master Secret: Z - TLS Master Secret: Z - TLS Derived Key (AES/HMA C): Z - HKDF Derived Key: Z

W,E,Z Z Z C): Z © 2026 Amazon Web Services, Inc., atsec information security.

24 of 48

Page 25
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - SSH Derived Key: Z - PBKDF Derived Key: Z - Password: Z - Intermediat e Key Generation Value: Z
Key Derivation with SSH KDFDeriving KeysReturn value 1 from the function: FIPS_ service_indicator_check_approved( )Shared Secret, Key LengthSSH Derived KeyKey Derivation with SSH KDFCrypto Officer - Shared Secret: W,E - SSH Derived Key: G,R
Show StatusShow status of the module stateN/AN/AModule statusNoneCrypto Officer
Show VersionShow the version of the module using awslc_version_st ringN/AN/AModule name and versionNoneCrypto Officer
On-Demand Self-testInitiate cryptographic algorithms self- tests and integrity test on- demand.N/AN/APass or failShared Secret Computation with EC Diffie-Hellman Authenticated Encryption/Decryp tion with AES KW, AES-KWP Encryption/Decryp tion with AES Signature Generation with RSA Signature Generation with ECDSA Key Generation with RSA Key Generation with ECDSA Signature Verification with ECDSA Signature Verification withCrypto Officer

Z © 2026 Amazon Web Services, Inc., atsec information security.

25 of 48

Page 26

Name

Description

Indicator

Inputs

Outputs

Security Functions RSA Key Verification with ECDSA Key Derivation with TLS KDF Key Derivation with SSH KDF Key Derivation with KDA HKDF Key Derivation with PBKDF Message Digest with SHA Random Number Generation with DRBG Message Authentication Generation with HMAC Message Authentication Generation with AES Authenticated Encryption/Decryp tion with AES CCM Authenticated Encryption/Decryp tion with AES GCM Message Digest with SHAKE

SSP Access

Table 12: Approved Services For the above table, the convention below applies when specifying the access permissions (types) that the service has for each SSP.

26 of 48

Page 27
NameDescriptionAlgorithmsRole
EncryptionEncryptionAES with OFB or CFB1, CFB8 modes AES GCM, GMAC, XTS with keys not listed in Table 5 AES using aes_*_generic function AES GMAC using aes_*_generic RSA encryption primitive with PKCS#1 v1.5 and OAEP paddingCO
DecryptionDecryptionAES with OFB or CFB1, CFB8 modes AES GCM, GMAC, XTS with keys not listed in Table 5 AES using aes_*_generic function AES GMAC using aes_*_genericCO
Message Authentication GenerationMAC computationAES using aes_*_generic function HMAC-MD4, HMAC-MD5, HMAC-SHA-3, HMAC-RIPEMD-160CO
Message DigestGenerating message digestMD4 MD5 (outside of TLS) RIPEMD-160CO
Signature GenerationGenerating signaturesRSA using keys less than 2048 bits RSA without hashing SHA-1, SHA-3CO
Signature VerificationVerifying signaturesRSA using keys less than 1024 bits RSA without hashingCO
Key GenerationGenerating key pairRSA using RSA_generate_key_ex ECDSA using EC_KEY_generate_keyCO
Shared Secret ComputationCalculating shared secretCurve secp256k1 Diffie HellmanCO
Key DerivationDeriving TLS keysTLS KDF using any SHA algorithms other than SHA2-256, SHA2-384, SHA2-512; or TLS KDF using non-extended master secretCO
Key EncapsulationEncrypting a keyRSACO
Key Un-encapsulationDecrypting a keyRSACO
4.4 Non-Approved Services

Table 13: Non-Approved Services

4.5 External Software/Firmware Loaded

Not applicable. © 2026 Amazon Web Services, Inc., atsec information security.

27 of 48

Page 28
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC value calculated at run time on the bcm.o file, with the HMAC-SHA2-256 value stored within the module that was computed at build time. The HMAC key for the integrity verification is embedded in the module.

5.2 Initiate on Demand

The module provides on-demand integrity test. The integrity test can be performed on demand by reloading the module. Additionally, the integrity test can be performed using the On-Demand Integrity Test service, which calls the BORINGSSL_integrity_test function. © 2026 Amazon Web Services, Inc., atsec information security.

28 of 48

Page 29
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module runs on a commercially available general-purpose operating system executing on the hardware specified in section

  1. The module shall be compiled and installed as stated in section
  2. The Crypto Officer shall confirm that the module is installed correctly by following steps listed in section 11.1.
6.2 Configuration Settings and Restrictions

Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2026 Amazon Web Services, Inc., atsec information security.

29 of 48

Page 30
7 Physical Security

The module is software only; therefore, this section is not applicable. © 2026 Amazon Web Services, Inc., atsec information security.

30 of 48

Page 31
8 Non-Invasive Security

The module does not implement any non-invasive security mechanisms; therefore, this section is not applicable. © 2026 Amazon Web Services, Inc., atsec information security.

31 of 48

Page 32
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPsDynamic

Name API input parameters API output parameters

From Operator calling application (TOEPP) Cryptographic module

To Cryptographic module Operator calling application (TOEPP)

Format Type Plaintext Plaintext

Distribution Type Manual Manual

Entry Type Electronic Electronic

SFI or Algorithm

Zeroization MethodDescriptionRationaleOperator Initiation
Free Cipher HandleZeroizes the SSPs contained within the cipher handleMemory occupied by SSPs is overwritten with zeros, which renders the SSP values irretrievable. The successful completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the appropriate zeroization functions: OpenSSL_cleanse, EVP_CIPHER_CTX_cleanup, EVP_AEAD_CTX_zero, HMAC_CTX_cleanup, CTR_DRBG_clear, RSA_free, EC_KEY_free
Module ResetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. The successful completion of the removal of power from the module indicates that zeroization has completed.By unloading and reloading the module.
AutomaticallyAutomatically zeroized when no longer neededMemory occupied by SSPs is overwritten with zeros, which renders the SSP values irretrievable. The successful completion of the running service indicates that zeroization has completed.N/A
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 14: Storage Areas Table 15: SSP Input-Output Methods operational environment. © 2026 Amazon Web Services, Inc., atsec information security.

32 of 48

Page 33

Name AES Key HMAC Key Entropy Input DRBG Seed DRBG Internal State (V, Key) RSA Public Key RSA Private Key EC Public Key

Description AES key used for encryption, decryption, and computing MAC tags HMAC key for Message Authentication Generation Entropy input used to seed the DRBGs DRBG seed derived from entropy input as defined in SP 800-90Ar1 Internal state of CTR_DRBG RSA public key used for RSA key generation, signature verification RSA private key used for RSA key generation, signature generation EC public key used for EC key generation, key verification,

Size - Strength 128-256 bits - 128-256 bits 112-524288 bits - 112-256 bits 256 bits - 256 bits 256 bits - 256 bits V: 128 bits, Key: 256 bits - 256 bits 1024, 2048, 3072, 4096 bits - 80-150 bits 2048, 3072, 4096 bits - 112-150 bits P-224, P-256, P-384, P-521 - 112-256 bits

Type - Category Symmetric key - CSP Authentication key - CSP Entropy - CSP DRBG seed - CSP Internal state - CSP Public key - PSP Private key - CSP Public key - PSP

Generated By Random Number Generation with DRBG Random Number Generation with DRBG Key Generation with RSA Key Generation with RSA Key Generation with ECDSA

Established By

Used By Authenticated Encryption/Decryption with AES KW, AES- KWP Encryption/Decryption with AES Message Authentication Generation with AES Authenticated Encryption/Decryption with AES CCM Authenticated Encryption/Decryption with AES GCM Message Authentication Generation with HMAC Random Number Generation with DRBG Random Number Generation with DRBG Random Number Generation with DRBG Signature Verification with RSA Signature Verification with RSA (legacy) Signature Generation with RSA Shared Secret Computation with EC Diffie-Hellman Signature Verification

Table 16: SSP Zeroization Methods All data output is inhibited during zeroization.

9.4 SSPs

© 2026 Amazon Web Services, Inc., atsec information security.

33 of 48

Page 34

Name EC Private Key Shared Secret TLS Pre- Master Secret TLS Master Secret TLS Derived Key (AES/HMAC) HKDF Derived Key SSH Derived Key PBKDF Derived Key

Description signature verification, shared secret computation EC private key used for EC key generation, key verification, signature generation, shared secret computation Shared Secret generated by KAS- ECC-SSC TLS Pre-Master secret used for deriving the TLS Master Secret TLS Master secret used for deriving the TLS Derived Key TLS Derived Key from TLS Master Secret KDA HKDF derived key SSH KDF derived key PBKDF derived key

Size - Strength P-224, P-256, P-384, P-521 - 112-256 bits P-224, P-256, P-384, P-521 - 112-256 bits P-224, P-256, P-384, P-521 - 112-256 bits 384 bits - 112-256 bits AES: 128-256 bits HMAC: 112 to 256 bits - AES: 128-256 bits HMAC: 112 to 256 bits 2048 bits - 112-256 bits 128 to 512 bits - 112 to 256 bits 128 to 4096 bits - N/A

Type - Category Private key - CSP Shared secret - CSP TLS pre-master secret - CSP TLS master secret - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP

Generated By Key Generation with ECDSA Key Derivation with TLS KDF Key Derivation with KDA HKDF Key Derivation with TLS KDF Key Derivation with KDA HKDF Key Derivation with SSH KDF Key Derivation with PBKDF

Established By Shared Secret Computation with EC Diffie- Hellman

Used By with ECDSA Key Verification with ECDSA Signature Verification with ECDSA (legacy) Shared Secret Computation with EC Diffie-Hellman Signature Generation with ECDSA Key Derivation with TLS KDF Key Derivation with SSH KDF Key Derivation with KDA HKDF Key Derivation with TLS KDF Key Derivation with KDA HKDF Key Derivation with TLS KDF Key Derivation with KDA HKDF

© 2026 Amazon Web Services, Inc., atsec information security.

34 of 48

Page 35

Name Password Intermediate Key Generation Value

Description Password for PBKDF Intermediate key generation value

Size - Strength 14-128 characters - N/A 224-4096 bits - 112-256 bits

Type - Category Password - CSP Intermediate value - CSP

Generated By Key Generation with RSA Key Generation with ECDSA

Established By

Used By Key Derivation with PBKDF Key Generation with RSA Key Generation with ECDSA

Name AES Key HMAC KeyInput - Output API input parameters API input parametersStorage RAM:Plaintext RAM:PlaintextStorage Duration From service invocation to service completion From service invocation to service completionZeroization Free Cipher Handle Module Reset Free Cipher Handle Module ResetRelated SSPs
Entropy InputAPI input parametersRAM:PlaintextFrom service invocation to service completionModule Reset AutomaticallyDRBG Seed:Generation OF
DRBG SeedRAM:PlaintextFrom service invocation to service completionModule Reset AutomaticallyEntropy Input:Derived From DRBG Internal State (V, Key):Generation Of
DRBG Internal State (V, Key)RAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetDRBG Seed:Derived From
RSA Public KeyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetRSA Private Key:Paired With Intermediate Key Generation Value:Generated From
RSA Private KeyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetRSA Public Key:Paired With Intermediate Key Generation Value:Generated From
EC Public KeyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetEC Private Key:Paired With Shared Secret:Generation Of Intermediate Key Generation Value:Generated From
EC Private KeyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetEC Public Key:Paired With Shared Secret:Generation Of Intermediate Key Generation Value:Generated From

N/A Table 17: SSP Table 1 © 2026 Amazon Web Services, Inc., atsec information security.

35 of 48

Page 36
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Shared SecretAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetEC Public Key:Derived From EC Private Key:Derived From
TLS Pre-Master SecretAPI input parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetTLS Master Secret:Derivation Of
TLS Master SecretRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetTLS Pre-Master Secret:Derived From TLS Derived Key (AES/HMAC):Derivation Of
TLS Derived Key (AES/HMAC)API output parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetTLS Master Secret:Derived From
HKDF Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetShared Secret:Derived From
SSH Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetShared Secret:Derived From
PBKDF Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetPassword:Derived From
PasswordAPI input parametersRAM:PlaintextFrom service invocation to service completionFree Cipher Handle Module ResetPBKDF Derived Key:Derivation Of
Intermediate Key Generation ValueRAM:PlaintextFrom service invocation to service completionModule Reset AutomaticallyRSA Public Key:Generation Of RSA Private Key:Generation Of EC Public Key:Generation Of EC Private Key:Generation Of
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. © 2026 Amazon Web Services, Inc., atsec information security.

36 of 48

Page 37
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-256 (A5425)SHA2- 256Message AuthenticationSW/FW IntegrityModule becomes operationalIntegrity test for bcm.o
HMAC-SHA2-256 (A5433)SHA2- 256Message AuthenticationSW/FW IntegrityModule becomes operationalIntegrity test for bcm.o
HMAC-SHA2-256 (A5434)SHA2- 256Message AuthenticationSW/FW IntegrityModule becomes operationalIntegrity test for bcm.o
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A5422)128, 192, 256 bit keys, encrypt/decryptKATCASTModule becomes operationalSymmetric operationPower up
AES-CBC (A5427)128, 192, 256 bit keys, encrypt/decryptKATCASTModule becomes operationalSymmetric operationPower up
AES-CBC (A5429)128, 192, 256 bit keys, encrypt/decryptKATCASTModule becomes operationalSymmetric operationPower up
AES-CBC (A5431)128, 192, 256 bit keys, encrypt/decryptKATCASTModule becomes operationalSymmetric operationPower up
AES-GCM (A5423)128, 192, 256 bit keys, 96-bit (internal/external IV), encrypt/decryptKATCASTModule becomes operationalSymmetric operationPower up
AES-GCM (A5428)128, 192, 256 bit keys, 96-bit (internal/external IV), encrypt/decryptKATCASTModule becomes operationalSymmetric operationPower up
AES-GCM (A5430)128, 192, 256 bit keys, 96-bit (internal/external IV), encrypt/decryptKATCASTModule becomes operationalSymmetric operationPower up
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 19: Pre-Operational Self-Tests The module performs the pre-operational self-test automatically when the module is loaded into memory; the pre-operational self-test is the software integrity test that ensures that the module is not corrupted. While the module is executing the pre-operational self-test, services are not available, and input and output are inhibited. If the pre-operational self-test fails, the module transitions to the Error state. The software integrity test is performed after a set of conditional cryptographic algorithm self-tests (CASTs). The set of CASTs includes the self-test for HMAC-SHA2-256 algorithm used in the pre-operational self-test.

10.2 Conditional Self-Tests

© 2026 Amazon Web Services, Inc., atsec information security.

37 of 48

Page 38
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A5432)128, 192, 256 bit keys, 96-bit (internal/external IV), encrypt/decryptKATCASTModule becomes operationalSymmetric operationPower up
AES-GCM (A5435)128, 192, 256 bit keys, 96-bit (internal/external IV), encrypt/decryptKATCASTModule becomes operationalSymmetric operationPower up
SHA-1 (A5425)SHA-1KATCASTModule becomes operationalMessage digestPower up
SHA-1 (A5426)SHA-1KATCASTModule becomes operationalMessage digestPower up
SHA-1 (A5433)SHA-1KATCASTModule becomes operationalMessage digestPower up
SHA-1 (A5434)SHA-1KATCASTModule becomes operationalMessage digestPower up
SHA2-256 (A5425)SHA2-256KATCASTModule becomes operationalMessage digestPower up
SHA2-256 (A5433)SHA2-256KATCASTModule becomes operationalMessage digestPower up
SHA2-256 (A5434)SHA2-256KATCASTModule becomes operationalMessage digestPower up
SHA2-512 (A5425)SHA2-512KATCASTModule becomes operationalMessage digestPower up
SHA2-512 (A5433)SHA2-512KATCASTModule becomes operationalMessage digestPower up
SHA2-512 (A5434)SHA2-512KATCASTModule becomes operationalMessage digestPower up
HMAC-SHA2- 256 (A5425)SHA2-256KATCASTModule becomes operationalMessage authenticationPower up
HMAC-SHA2- 256 (A5433)SHA2-256KATCASTModule becomes operationalMessage authenticationPower up
HMAC-SHA2- 256 (A5434)SHA2-256KATCASTModule becomes operationalMessage authenticationPower up

© 2026 Amazon Web Services, Inc., atsec information security.

38 of 48

Page 39
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Counter DRBG (A5422)256 bit keys, with PRKATCASTModule becomes operationalHealth test per section 11.3 of SP 800-90Ar1Power up
Counter DRBG (A5427)256 bit keys, with PRKATCASTModule becomes operationalHealth test per section 11.3 of SP 800-90Ar1Power up
Counter DRBG (A5429)256 bit keys, with PRKATCASTModule becomes operationalHealth test per section 11.3 of SP 800-90Ar1Power up
Counter DRBG (A5431)256 bit keys, with PRKATCASTModule becomes operationalHealth test per section 11.3 of SP 800-90Ar1Power up
ECDSA SigGen (FIPS186-5) (A5425)SHA2-256, P-256 curveKATCASTModule becomes operationalDigital signature generationSignature Generation or Key Generation service request
ECDSA SigGen (FIPS186-5) (A5426)SHA2-256, P-256 curveKATCASTModule becomes operationalDigital signature generationSignature Generation or Key Generation service request
ECDSA SigGen (FIPS186-5) (A5433)SHA2-256, P-256 curveKATCASTModule becomes operationalDigital signature generationSignature Generation or Key Generation service request
ECDSA SigGen (FIPS186-5) (A5434)SHA2-256, P-256 curveKATCASTModule becomes operationalDigital signature generationSignature Generation or Key Generation service request
ECDSA SigVer (FIPS186-5) (A5425)SHA2-256, P-256 curveKATCASTModule becomes operationalDigital signature verificationSignature verification or Key Generation service request
ECDSA SigVer (FIPS186-5) (A5426)SHA2-256, P-256 curveKATCASTModule becomes operationalDigital signature verificationSignature verification or Key Generation service request
ECDSA SigVer (FIPS186-5) (A5433)SHA2-256, P-256 curveKATCASTModule becomes operationalDigital signature verificationSignature verification or Key Generation service request
ECDSA SigVer (FIPS186-5) (A5434)SHA2-256, P-256 curveKATCASTModule becomes operationalDigital signature verificationSignature verification or Key Generation service request
RSA SigGen (FIPS186-5) (A5425)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationSignature Generation or Key Generation service request
RSA SigGen (FIPS186-5) (A5426)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationSignature Generation or Key Generation service request
RSA SigGen (FIPS186-5) (A5433)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationSignature Generation or Key Generation service request

© 2026 Amazon Web Services, Inc., atsec information security.

39 of 48

Page 40
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigGen (FIPS186-5) (A5434)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature generationSignature Generation or Key Generation service request
RSA SigVer (FIPS186-5) (A5425)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationSignature Verification or Key Generation service request
RSA SigVer (FIPS186-5) (A5426)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationSignature Verification or Key Generation service request
RSA SigVer (FIPS186-5) (A5433)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationSignature Verification or Key Generation service request
RSA SigVer (FIPS186-5) (A5434)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operationalDigital signature verificationSignature Verification or Key Generation service request
KAS-ECC-SSC Sp800-56Ar3 (A5425)P-256 curveKATCASTModule becomes operationalShared secret computationShared secret computation service request
KAS-ECC-SSC Sp800-56Ar3 (A5426)P-256 curveKATCASTModule becomes operationalShared secret computationShared secret computation service request
KAS-ECC-SSC Sp800-56Ar3 (A5433)P-256 curveKATCASTModule becomes operationalShared secret computationShared secret computation service request
KAS-ECC-SSC Sp800-56Ar3 (A5434)P-256 curveKATCASTModule becomes operationalShared secret computationShared secret computation service request
KDF TLS (A5425)SHA2-256KATCASTModule becomes operationalKey derivationPower up
KDF TLS (A5426)SHA2-256KATCASTModule becomes operationalKey derivationPower up
KDF TLS (A5433)SHA2-256KATCASTModule becomes operationalKey derivationPower up
KDF TLS (A5434)SHA2-256KATCASTModule becomes operationalKey derivationPower up
KDA HKDF Sp800-56Cr1 (A5425)SHA2-256KATCASTModule becomes operationalShared secret key derivationPower up
KDA HKDF Sp800-56Cr1 (A5426)SHA2-256KATCASTModule becomes operationalShared secret key derivationPower up

© 2026 Amazon Web Services, Inc., atsec information security.

40 of 48

Page 41
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
KDA HKDF Sp800-56Cr1 (A5433)SHA2-256KATCASTModule becomes operationalShared secret key derivationPower up
KDA HKDF Sp800-56Cr1 (A5434)SHA2-256KATCASTModule becomes operationalShared secret key derivationPower up
PBKDF (A5425)SHA2-256KATCASTModule becomes operationalPassword-based key derivationPower up
PBKDF (A5426)SHA2-256KATCASTModule becomes operationalPassword-based key derivationPower up
PBKDF (A5433)SHA2-256KATCASTModule becomes operationalPassword-based key derivationPower up
PBKDF (A5434)SHA2-256KATCASTModule becomes operationalPassword-based key derivationPower up
ECDSA KeyGen (FIPS186-5) (A5425)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A5426)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A5433)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A5434)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5425)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5426)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5433)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5434)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
SHA3-256 (A5424)SHA3-256KATCASTModule becomes operationalMessage digestPower up

Table 20: Conditional Self-Tests © 2026 Amazon Web Services, Inc., atsec information security.

41 of 48

Page 42
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A5425)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A5433)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A5434)Message AuthenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A5422)KATCASTOn DemandManually
AES-CBC (A5427)KATCASTOn DemandManually
AES-CBC (A5429)KATCASTOn DemandManually
AES-CBC (A5431)KATCASTOn DemandManually
AES-GCM (A5423)KATCASTOn DemandManually
AES-GCM (A5428)KATCASTOn DemandManually
AES-GCM (A5430)KATCASTOn DemandManually
AES-GCM (A5432)KATCASTOn DemandManually
AES-GCM (A5435)KATCASTOn DemandManually
SHA-1 (A5425)KATCASTOn DemandManually
SHA-1 (A5426)KATCASTOn DemandManually
SHA-1 (A5433)KATCASTOn DemandManually
SHA-1 (A5434)KATCASTOn DemandManually
SHA2-256 (A5425)KATCASTOn DemandManually
SHA2-256 (A5433)KATCASTOn DemandManually
SHA2-256 (A5434)KATCASTOn DemandManually
SHA2-512 (A5425)KATCASTOn DemandManually
SHA2-512 (A5433)KATCASTOn DemandManually
SHA2-512 (A5434)KATCASTOn DemandManually
HMAC-SHA2-256 (A5425)KATCASTOn DemandManually
HMAC-SHA2-256 (A5433)KATCASTOn DemandManually
HMAC-SHA2-256 (A5434)KATCASTOn DemandManually
Counter DRBG (A5422)KATCASTOn DemandManually
Counter DRBG (A5427)KATCASTOn DemandManually
Counter DRBG (A5429)KATCASTOn DemandManually
Counter DRBG (A5431)KATCASTOn DemandManually

Data output through the data output interface is inhibited during the self-tests.

10.3 Periodic Self-Test Information

Table 21: Pre-Operational Periodic Information © 2026 Amazon Web Services, Inc., atsec information security.

42 of 48

Page 43
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA SigGen (FIPS186-5) (A5425)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5426)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5433)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5434)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5425)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5426)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5433)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5434)KATCASTOn DemandManually
RSA SigGen (FIPS186- 5) (A5425)KATCASTOn DemandManually
RSA SigGen (FIPS186- 5) (A5426)KATCASTOn DemandManually
RSA SigGen (FIPS186- 5) (A5433)KATCASTOn DemandManually
RSA SigGen (FIPS186- 5) (A5434)KATCASTOn DemandManually
RSA SigVer (FIPS186- 5) (A5425)KATCASTOn DemandManually
RSA SigVer (FIPS186- 5) (A5426)KATCASTOn DemandManually
RSA SigVer (FIPS186- 5) (A5433)KATCASTOn DemandManually
RSA SigVer (FIPS186- 5) (A5434)KATCASTOn DemandManually
KAS-ECC-SSC Sp800- 56Ar3 (A5425)KATCASTOn DemandManually
KAS-ECC-SSC Sp800- 56Ar3 (A5426)KATCASTOn DemandManually
KAS-ECC-SSC Sp800- 56Ar3 (A5433)KATCASTOn DemandManually
KAS-ECC-SSC Sp800- 56Ar3 (A5434)KATCASTOn DemandManually
KDF TLS (A5425)KATCASTOn DemandManually
KDF TLS (A5426)KATCASTOn DemandManually
KDF TLS (A5433)KATCASTOn DemandManually
KDF TLS (A5434)KATCASTOn DemandManually

© 2026 Amazon Web Services, Inc., atsec information security.

43 of 48

Page 44
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KDA HKDF Sp800- 56Cr1 (A5425)KATCASTOn DemandManually
KDA HKDF Sp800- 56Cr1 (A5426)KATCASTOn DemandManually
KDA HKDF Sp800- 56Cr1 (A5433)KATCASTOn DemandManually
KDA HKDF Sp800- 56Cr1 (A5434)KATCASTOn DemandManually
PBKDF (A5425)KATCASTOn DemandManually
PBKDF (A5426)KATCASTOn DemandManually
PBKDF (A5433)KATCASTOn DemandManually
PBKDF (A5434)KATCASTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5425)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5426)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5433)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5434)PCTPCTOn DemandManually
RSA KeyGen (FIPS186- 5) (A5425)PCTPCTOn DemandManually
RSA KeyGen (FIPS186- 5) (A5426)PCTPCTOn DemandManually
RSA KeyGen (FIPS186- 5) (A5433)PCTPCTOn DemandManually
RSA KeyGen (FIPS186- 5) (A5434)PCTPCTOn DemandManually
SHA3-256 (A5424)KATCASTOn DemandManually
NameDescriptionConditionsRecovery MethodIndicator
ErrorThe library is aborted with SIGABRT signal. Module is no longer operational the data output interface is inhibitedPre- operational test failure; CAST failureModule resetPre-operational test failure: an error message is output (i.e., "FIPS integrity test failed.") on the stderr and then the module is aborted. Conditional test failure: an error message indicating which KAT failed (e.g., "* KAT failed") is output on the stderr and then the module is aborted.
PCT ErrorThe library is aborted with SIGABRT signal. Module is no longerPCT failureModule resetAn error message is output in the error queue (e.g., EC_R_PUBLIC_KEY_VALIDATION_FAILED, RSA_R_PUBLIC_KEY_VALIDATION_FAILED) and then the module

Table 22: Conditional Periodic Information

10.4 Error States

© 2026 Amazon Web Services, Inc., atsec information security.

44 of 48

Page 45

Name

Description operational the data output interface is inhibited

Conditions

Recovery Method

Indicator generates a new key, if the PCT still does not pass, eventually the module will be aborted after 5 tries.

Table 23: Error States In the error states, the output interface is inhibited. If the module fails any of the self-tests, the module enters an error state. To recover from any error state, the module must be rebooted.

10.5 Operator Initiation of Self-Tests

The software integrity tests and the CASTs for AES, SHA, SHA3, DRBG, TLS KDF, KDA HKDF, PBKDF2 can be invoked by unloading and subsequently re-initializing the module. The CASTs for ECDSA, KAS-ECC-SSC and RSA can be invoked by requesting the corresponding Key Generation, Shared Secret Computation or Digital Signature services. Additionally, all the CASTs can be invoked by calling the BORINGSSL_self_test function. The PCTs can be invoked on demand by requesting the Key Generation service. © 2026 Amazon Web Services, Inc., atsec information security.

45 of 48

Page 46
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module bcm.o is embedded into the shared library libcrypto.so which can be obtained by building the source code at the following location [1]. The set of files specified in the archive constitutes the complete set of source files of the validated module. There shall be no additions, deletions, or alterations of this set as used during module build. [1] https://github.com/aws/aws-lc/archive/refs/heads/fips-NetOS-2024-06-11.zip The downloaded zip file can be verified by issuing the “sha256sum aws-lc-fips-NetOS-2024-06-11.zip” command. The expected SHA2-256 digest value is: 952c4a23cea54e2ada37dde18d4d95228736f1d2c303a056c9bb39de55c9cd89 After the zip file is extracted, the cmake flags listed below must be used to compile the module. The compilation must be executed separately for each platform. Due to four possible combinations of OS/processor, the module count is four (i.e., there are four separate binaries generated, one for each entry listed in the Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) table). -DFIPS=1 \ -Dlibdir=${libdir} \ -Dbindir=${bindir} \ -DENABLE_EXPERIMENTAL_BIG_ENDIAN_SUPPORT=ON \ -DCMAKE_BUILD_TYPE=Release \ -GNinja \ Upon completion of the build process, the module’s status can be verified by the command below. If the value obtained is “1” then the module has been installed and configured to operate in FIPS compliant manner. ./tool/bssl isfips Lastly, the user can call the “show version” service using awslc_version_string function and the expected output is “AWS-LC FIPS 1.29.1” which is the module version. This will confirm that the module is in the operational mode. Additionally, the “AWS-LC FIPS” also acts as the module identifier and the verification of the "dynamic" part can be done using following command with an application that was used for dynamic linking. The "U" in the output confirms that the module is dynamically linked. Command: nm <application_name> | grep awslc_version_string Example Output: “ U awslc_version_string”

11.2 Administrator Guidance

The approved and non-approved modes of operation are specified in section 2.4. The approved services that include the administrative functions are specified in section 4.3. All the logical interfaces are specified in section 3.1. The procedures of installation, initialization, startup, that are specified in section 11.1, and the operational environment requirements, that are specified in section 6, must be followed.

11.3 Non-Administrator Guidance

The approved and non-approved modes of operation are specified in section 2.4. The approved and nonapproved cryptographic algorithms are specified in section 2.5. The approved security functions are specified in © 2026 Amazon Web Services, Inc., atsec information security.

46 of 48

Page 47

section 2.6. The algorithm-specific information is specified in section 2.7. The approved services are specified in section 4.3, the non-approved services are specified in section 4.4. The logical interfaces available to users are specified in section 3.1. The user is responsible for following the procedures of installation, initialization, startup that are specified in section 11.1. The configuration settings and restrictions regarding the operational environment are specified in section 6.2.

11.4 End of Life

When the module is at end of life, for the GitHub repo, the README will be modified to mark the library as deprecated. After a 6-month window, more restrictive branch permissions will be added such that only administrators can read from the FIPS branch. The module does not possess persistent storage of SSPs. The SSP value only exists in volatile memory and that value vanishes when the module is powered off. So as a first step for the secure sanitization, the module needs to be powered off. Then for actual deprecation, the module will be upgraded to newer version that is approved. This upgrade process will uninstall/remove the old/terminated module and provide a new replacement. © 2026 Amazon Web Services, Inc., atsec information security.

47 of 48

Page 48
12 Mitigation of Other Attacks
12.1 Attack List

RSA timing attacks: RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack.

12.2 Mitigation Effectiveness

The module provides the mechanism to use the blinding for RSA. When the blinding is on, the module generates a random value to form a blinding factor in the RSA key before the RSA key is used in the RSA cryptographic operations. © 2026 Amazon Web Services, Inc., atsec information security.

48 of 48