All modules
CMVP Validated Module · FIPS 140-3 Security Policy

FEITIAN ePass Token Cryptographic Module

Certificate#5151StandardFIPS 140-3Level3TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorFEITIAN Technologies Co., Ltd.
Low review priority  ·  no TCB surface named  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date1/27/2031
CaveatThe module generates SSPs (e.g., keys) whose strengths are modified by available entropy, No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorFEITIAN Technologies Co., Ltd.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for FEITIAN ePass Token Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Unauth</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for FEITIAN ePass Token Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Unauth</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

FEITIAN Technologies Co., Ltd. FEITIAN ePass Token Cryptographic Module Document Version: 1.1.0 Date: January 16, 2026

Page 2
Table of Contents
#SectionPage
Page 3

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware9
Table 3: Modes List and Description9
Table 4: Approved Algorithms11
Table 5: Vendor-Affirmed Algorithms11
Table 6: Security Function Implementations16
Table 7: Entropy Certificates17
Table 8: Entropy Sources17
Table 9: Ports and Interfaces18
Table 10: Authentication Methods20
Table 11: Roles21
Table 12: Approved Services45
Table 13: Mechanisms and Actions Required48
Table 14: EFP/EFT Information48
Table 15: Hardness Testing Temperatures49
Table 16: Storage Areas51
Table 17: SSP Input-Output Methods52
Table 18: SSP Zeroization Methods52
Table 19: SSP Table 165
Table 20: SSP Table 271
Table 21: Pre-Operational Self-Tests73
Table 22: Conditional Self-Tests76
Table 23: Pre-Operational Periodic Information76
Table 24: Conditional Periodic Information78
Table 25: Error States79
Table 26 References83
Table 27 Acronyms and Definitions84
Figure 1 – Module Boundary6
Figure 2 – Block diagram7
Figure 3 – Module Appearance8
Page 5
SectionTitleSecurity Level
1General3
2Cryptographic module specification3
3Cryptographic module interfaces3
4Roles, services, and authentication3
5Software/Firmware security3
6Operational environmentN/A
7Physical security3
8Non-invasive securityN/A
9Sensitive security parameter management3
10Self-tests3
11Life-cycle assurance3
12Mitigation of other attacksN/A
Overall Level3
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for the ePass token. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-

1.2 Security Levels

The FIPS 140-3 security levels for the Module are as follows: Table 1: Security Levels FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 6

2 – Cryptographic Module Specification

This FEITIAN ePass token module, hereafter denoted as the Module. The Module supports multiple identity authentication system frameworks such as PKI/OTP/FIDO, among which PKI includes three applications: ePass2003/ePassPIV/ePassOpenPGP. The OTP functional unit complies with OATH standards. The PIV functional unit meets the specifications NIST.SP.800-73-4. The OpenPGP functional unit is an ISO Smart Card Operating Systems.

2.1 Description

Purpose and Use: The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated identity authentication product, the Module is intended to be used in E-mail encryption, system login, transaction protection, etc. Module Type: Hardware Module Embodiment: MultiChipEmbed Cryptographic Boundary: The physical form of the Module is depicted in Figure 1. The Module is a multi-chip embedded embodiment. The Module is a USB token containing FEITIAN owned FTCOS, which is embedded in a HSC32K2 with PAA Integrated Circuit (IC) chip and has been developed to support FEITIAN USB token. The Module is designed to provide strong authentication and identification and to support network login, secure online transactions, digital signatures, and sensitive data protection. Figure 1

Page 7

Figure 2

Page 8

Figure 3

2.2 Tested and Vendor Affirmed Module Version and Identification

The operator can correlate the module’s name and versioning information with the CMVP validation record by following the instructions in the FEITIAN ePass Token Cryptographic Module Administrator Guidance, page 31, Section 5.8 Get Device Info, #7 get version info. Tested Module Identification

Page 9
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
A2V1.2V1.3.02HSC32K2 with PAA
K9V1.0V1.3.02HSC32K2 with PAA
K40V1.0V1.3.02HSC32K2 with PAA
A4BV1.0V1.3.02HSC32K2 with PAA
K49V1.0V1.3.02HSC32K2 with PAA
K50V1.0V1.3.02HSC32K2 with PAA
K28V1.0V1.3.02HSC32K2 with PAA
Mode NameDescriptionTypeStatus Indicator
Approved ModeThe module has only one mode of operation - the Approved mode, which is entered after power up.ApprovedLED on and blink
AlgorithmCAVP CertPropertiesReference
AES-CBCA4980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA4980Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B

Table 2: Tested Module Identification – Hardware

2.3 Excluded Components

The module does not exclude any components. Modes List and Description: Table 3: Modes List and Description The module only supports Approved mode. IG 2.4.C scenario 2) is applied to the module, i.e. A static code(9000 or 00) indicating the completion of service. The successful completion of a service is an implicit indicator for the use of an approved service.

2.5 Algorithms

Approved Algorithms: The Module implements the Approved cryptographic algorithms listed the table below. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 10
AlgorithmCAVP CertPropertiesReference
AES-ECBA4980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4980Direction - Decrypt, Encrypt IV Generation Mode - 8.2.2 Key Length - 128, 192, 256SP 800-38D
Counter DRBGA4980Prediction Resistance - Yes Mode - AES-128 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A4980Curve - P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4980Curve - P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A4980Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 Component - YesFIPS 186-5
ECDSA SigVer (FIPS186-5)A4980Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-5
HMAC-SHA-1A4980Key Length - Key Length: 8-2048 Increment 8FIPS 198-1
HMAC-SHA2-256A4980Key Length - Key Length: 8-2048 Increment 8FIPS 198-1
KAS-ECC Sp800- 56Ar3A4980Domain Parameter Generation Methods - P-256 Function - Key Pair Generation Scheme - ephemeralUnified - KAS Role - Responder KDF Methods - twoStepKdf - Key Length - 256SP 800-56A Rev. 3
KDF SP800-108A4980KDF Mode - Counter Supported Lengths - Supported Lengths: 8-256 Increment 8SP 800-108 Rev. 1
RSA KeyGen (FIPS186-5)A4980Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - crtFIPS 186-5
RSA SigGen (FIPS186-5)A4980Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5
RSA SigVer (FIPS186-5)A4980Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5
SHA-1A4980Message Length - Message Length: 160, 0-65536 Increment 8FIPS 180-4

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 11
AlgorithmCAVP CertPropertiesReference
SHA2-256A4980Message Length - Message Length: 256, 0-65536 Increment 8FIPS 180-4
SHA2-384A4980Message Length - Message Length: 384, 0-65536 Increment 8FIPS 180-4
SHA2-512A4980Message Length - Message Length: 512, 0-65536 Increment 8FIPS 180-4
NamePropertiesImplementationReference
CKG1Key Type::Asymmetric and SymmetricN/A[133r2] section 4, example 1 and IG D.H

Table 4: Approved Algorithms Vendor-Affirmed Algorithms: The Module implements the FIPS Vendor Affirmed cryptographic algorithms listed below. Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 12
NameTypeDescriptio nPropertiesAlgorith ms
RSA_GEN_KEY_PAIRAsymKeyPa ir-KeyGenAsymmetric Key-Pair GenerationPublications:Publicat ions: [FIPS 186-5], [SP800-90A], [SP800-133r1], [IG C.E]RSA KeyGen (FIPS186 -5): (A4980) Counter DRBG: (A4980) CKG1: () Key Type:: Symmetri c
ECC_GEN_KEY_PAIRAsymKeyPa ir-KeyGenAsymmetric Key-Pair GenerationPublications:[FIPS 186-5], [SP800-90A], [SP800-133r1], [IG C.A]ECDSA KeyGen (FIPS186 -5): (A4980) Counter DRBG: (A4980) CKG1: () Key Type:: Symmetri c
AES_KEY_GENCKGSymmetric Key Generation Sections 4 and 6.1 Direct symmetric key generation using unmodified DRBG outputPublications:[SP800- 90A], [IG D.H], [FIPS 197]AES- CBC: (A4980) Size: 128 AES- GCM: (A4980) Size: 128 AES- ECB: (A4980) Size: 128 Counter DRBG: (A4980) CKG1: () Key
2.6 Security Function Implementations

The SFI table shows the Security Function Implementations that the module implements: -5): c -5): C.A] c FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 13
NameTypeDescriptio nPropertiesAlgorith ms
Type:: Symmetri c
SESSIONKEY_GENKBKDFSymmetric Key Generation using KBKDFPublications:[SP800- 108r1], [SP800-38B], [FIPS 197]AES- CMAC: (A4980) Size: 128 KDF SP800- 108: (A4980) Size: 128
RSA_SIG_GENDigSig- SigGenDigital Signature GenerationPublications:[FIPS 186-5], [SP800- 133r1], [IG C.E]RSA SigGen (FIPS186 -5): (A4980) SHA2- 256: (A4980) SHA2- 384: (A4980) SHA2- 512: (A4980)
RSA_SIG_VERDigSig- SigVerSignature VerificationPublications:[FIPS 186-5], [IG C.E]RSA SigVer (FIPS186 -5): (A4980) SHA2- 256: (A4980) SHA2- 384: (A4980) SHA2- 512: (A4980)
ECC_SIG_GENDigSig- SigGenDigital Signature GenerationPublications:[FIPS 186-5], [SP800- 133r1], [IG C.A]ECDSA SigGen (FIPS186 -5): (A4980) SHA2- 256: (A4980)

c -5): -5): FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 14
NameTypeDescriptio nPropertiesAlgorith ms
SHA2- 384: (A4980) SHA2- 512: (A4980)
ECC_SIG_VERDigSig- SigVerSignature VerificationPublications:[FIPS 186-5], [IG C.A]ECDSA SigVer (FIPS186 -5): (A4980) SHA2- 256: (A4980) SHA2- 384: (A4980) SHA2- 512: (A4980)
ECC_KEY_VERAsymKeyPa ir-KeyVerCheck the validity of the public keyPublications:[FIPS 186-5], [IG C.A]ECDSA KeyVer (FIPS186 -5): (A4980)
DRBG_GENDRBGRandom Number GenerationPublications:[SP800- 90A], [IG D.L]Counter DRBG: (A4980)
ENT_GENENT-ESVEntropy SourcePublications:[SP800- 90B], [IG 9.3.A], [IG D.J] [IG D.O]
SHAREDSECRETKEY_GE N_KASKAS-FullKey Agreement Shared Secret Calculation [56Ar3] Key Derivation KDA [56Cr2]IG:D.F Scenario 2, path 2, end-to-end Caveat:Key establishment methodology provides 128 bits of security strength Key confirmation:No Key derivation:KDA (tested as part KAS certificate)KAS- ECC Sp800- 56Ar3: (A4980)
AES_ENC_AUTHBC- AuthEncryptBlock CipherPublications:[FIPS 197]AES- CMAC: (A4980) Sizes: 128 AES-

-5): -5): FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 15
NameTypeDescriptio nPropertiesAlgorith ms
GCM: (A4980) Size: 128
AES_ENCBC- UnAuthEncr yptBlock CipherPublications:[FIPS 197]AES- CBC: (A4980) AES- ECB: (A4980)
AES_DEC_AUTHBC- AuthDecryptBlock CipherPublications:[FIPS 197]AES- CMAC: (A4980) Size: 128 AES- GCM: (A4980) Size: 128
AES_DECBC- UnAuthDecr yptBlock CipherPublications:[FIPS 197]AES- CBC: (A4980) AES- ECB: (A4980)
HMAC_GENMACMessage Authenticati on GenerationPublications:[FIPS19 8-1] [IG C.B]HMAC- SHA-1: (A4980) HMAC- SHA2- 256: (A4980) SHA-1: (A4980) SHA2- 256: (A4980)
KTS_SCP03_WRAPKTS- Unwrapused as SCP03Standard:SP 800- 38F IG D.G:Approved Caveat:Key establishment methodology provides 128 bits of security strengthAES- CBC: (A4980) Sizes: 128 AES- CMAC: (A4980) Sizes: 128
KTS_AESGCM_WRAPKTS- Unwrap KTS-WrapSP800-38D Based on IG D.GStandard:SP 800- 38F IG D.G:ApprovedAES- GCM: (A4980)

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 16
NameTypeDescriptio nPropertiesAlgorith ms
Caveat:Key establishment methodology provides 128 bits of security strengthSizes: 128
KTS_CTAP_WRAPKTS- Unwrap KTS-WrapKey Wrapping Based on IG D.GStandard:SP 800- 38F IG D.G:Approved Caveat:Key establishment methodology provides 128 bits of security strengthAES- CBC: (A4980) Sizes: 128 HMAC- SHA2- 256: (A4980)
SHA_CALSHASecure Hash StandardPublications: [FIPS 180-4], [IG C.B]SHA2- 256: (A4980) SHA2- 384: (A4980) SHA2- 512: (A4980)

Table 6: Security Function Implementations

2.7 Algorithm Specific Information

AES GCM IV Uniqueness FIPS140-3 IG C.H, Option 2 The IV is generated internally at its entirety randomly. The generation uses an Approved DRBG (Cert. #A4980) that is internal to the module’s boundary. The IV length shall be at least 96 bits (per SP 800-38D). KAS [56Ar3] - Per [IG] D.F Scenario 2 path (2), compliant key agreement scheme where testing is performed end-to-end for the shared secret computation and a KDF compliant with HKDF (2step KDF). The Module obtains the [FIPS140-3_IG] D.F required key agreement assurances [SP800-56Ar3] in accordance with Section 5.6.2.

2.8 RBG and Entropy

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 17
Cert NumberVendor Name
E134Feitian Technologies Co., Ltd.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
HSEC_ESPhysicalHSEC HSC1 bit0.3308N/A

The scenario 1(a) in IG 9.3.A is applied to the module, the security strength of the DRBG seeded by the entropy source is 128-bit. According to table 4 of the ESV Public Use Document, to reach 128 bits of strength, at least 581 bits of random nonce are needed to seed the DRBG. A 640-bit nonce is used in the module, so the DRBG entropy strength is 128 bits. Table 7: Entropy Certificates The Module uses the following entropy sources: Table 8: Entropy Sources

2.9 Key Generation

For Key Generation, see Section 2.5 and Section 2.6 above.

2.10 Key Establishment

Key Agreement Information For Key Agreement, see Section 2.5 and Section 2.6 above. Key Transport Information For Key Transport, see Section 2.5 and Section 2.6 above.

2.11 Industry Protocols

The module does not support any industry protocols that would be of interest to this standard. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 18
Physical PortLogical Interface(s)Data That Passes
Power Supply 2 PinsPowerVcc Vdd 1.62-5.5V
Touch Button 1 PinControl InputPhysical input
LED 1 PinStatus OutputPhysical output
USB(D+/D-) 2 PinsData Input Data Output Control Input Status OutputPrimary physical interface (USB) for all service data
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

The Module’s ports and associated FIPS defined logical interface categories are listed below. Table 9: Ports and Interfaces Note: The module does not support Control Output. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 19
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Authentication_PINA role is authenticated to the Module console with a PIN mechanism The PIN must be to changed by the CO after first authentication with default data. The Module enforced a minimum size of 8 ASCII characters. The number of incorrect attempts for PIN is 3-15, which can be set to a maximum of 15 times and a minimum of 3 times.Memorized SecretsPIN8-63 characters PIN, including numbers, letters, and special characters.Therefore, the probability of successful attempt is 1/95^8Each authentication attempt takes approximately 60 ms which allows a maximum of 15 attempts per minute. Therefore, the probability of successfully authenticating to the module within one minute through random attempts is 15/95^8
Authentication_ AuthKeyThe identity is authenticated to the module with a challenge- response mechanism (Cert. #A4980). The entity gets challenge from the module then encrypts it resulting in cryptogramAES-ECB (A4980)128-bit AES-ECB Key Challenge-Response A minimum 16 byte (128 bit) binary string has a probability that a random attempt will succeed or a false acceptance will occur of 1/2^128.Each authentication attempt takes approximately 60 ms which allows a maximum of 15 attempts per minute. Therefore, the probability of successfully authenticating to the module
4 Roles, Services, and Authentication
4.1 Authentication Methods

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 20
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
using Auth key. The cryptogram is sent back and decrypted in the module using same key, then the module check if the result is matched with original challenge. The Auth key MUST be changed to specific value for each module by the CO after first authentication with default data. The Auth key is generally a random number automatically generated by HSM. The number of incorrect attempts for Auth key is 3- 15, which can be set to a maximum of 15 times and a minimum of 3 times.within one minute through random attempts is 15/2^128 .

Table 10: Authentication Methods All authentication states are all stored in RAM, so they are cleared automatically once the module is powered down. Note: Authentication-PIN is an abstract noun that includes the PIN of ePass2003 unit, PIN/PUK of PIV unit, PIN of FIDO unit, AccessiCode of OTP unit, PGP User PIN(PW1)/ PGP Admin PIN(PW3) of OpenPGP unit. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 21
NameTypeOperator TypeAuthentication Methods
COIdentityCrypto OfficerAuthentication_ AuthKey
AdminIdentityUserAuthentication_PIN Authentication_ AuthKey
UserIdentityUserAuthentication_PIN
UnAuthRoleUnauthenticatedNone

Authentication-AuthKey is an abstract noun that includes the Device authenticate key of a universal service unit, the External Auth Key of an ePass2003 unit, and the PIV Authentication Key of a PIV unit.

4.2 Roles

The Module supports four distinct operator roles, User, Admin, Cryptographic Officer (CO) and Unauth. The CO role is responsible for device authentication, resetting applications and other roles' authentication data (User PINs, etc). The Admin role is responsible for configuring SSPs and managing User identities (such as unblock a User identity in the PIV application). The User role is responsible for performing cryptographic operations to utilize the module as an authenticator. The unauthenticated role can only access some non-operational SSP services, Such as Select functional unit, get a challenge, read non-security relevant information, self-tests, etc. The Module does not support a maintenance role. The Module does not support concurrent operators. The Roles Table below lists all operator roles supported by the Module. Table 11: Roles FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 22
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
SELECTSelect functional unit9000 or error statu sComman d with AIDFCI(File Control Informatio n)NoneUnauthen ticated - KSenc: Z - KSmac: Z
Get Device InfoGet device information content including versioning information and show status9000 or error statu sComman d without input paramete rDevice InfoNoneUnauthen ticated
Get ChallengeRequest random data that will be used as a challenge within the Device Authenticat e service9000 or error statu sComman d with expected data lengthrandom valueDRBG_GEN ENT_GENUnauthen ticated - DRBG V: G,Z - DRBG Seed: G - DRBG Key: G,Z
Device Authenticat eRequest administrat or privileges9000 or error statu sKid and cipher textN/AAES_DEC_AUTHCO - Device authentic ate key: E
Update keyChange Device authenticat e key, INIT_KEYe nc and9000 or error statu scipher textN/AAES_DECCO - KSenc: E - KSmac: E - Device authentic
4.3 Approved Services

All approved services implemented by the Module are listed in the table below: The SSPs modes of access shown in the table below are defined as:

G = Generate: The Module generates or derives the SSP.
R = Read: The SSP is read from the Module (e.g., the SSP is output).
W = Write: The SSP is updated, imported, or written to the Module (SSP is input).
E = Execute: The Module uses the SSP in performing a cryptographic operation.
Z = Zeroize: The Module zeroizes the SSP s Z s r s

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 23
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
INIT_KEY macate key: W,E,Z - INIT_KEY enc: W,Z - INIT_KEY mac: W,Z
GP Initialize UpdateCreate Secure Channel Session9000 or error statu sHost random Card randomcipher textSESSIONKEY_GENAdmin - INIT_KEY enc: E - INIT_KEY mac: E - KSenc: G - KSmac: G User - INIT_KEY enc: E - INIT_KEY mac: E - KSenc: G - KSmac: G
GP External Authenticat eThis service may also be used to both authenticat e and initiate a secure session with an external entity.9000 or error statu scipher textN/ASESSIONKEY_GENAdmin - KSenc: E - KSmac: E User - KSenc: E - KSmac: E
Terminate tokenThe token into terminate state.9000 or error statu sComman d without input paramete rN/ANoneCO - DRBG- EI: Z - DRBG V: Z

G s G G E E E s r V: Z FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 24
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
- DRBG Key: Z - Managing Key: Z - Device authentic ate key: Z - INIT_KEY enc: Z - INIT_KEY mac: Z - KSenc: Z - KSmac: Z - AES- GCM Key: Z - FIDO Device ECDSA Private Key: Z - FIDO Device ECDSA Public Key: Z - FIDO User ECDSA Private Key: Z - FIDO User ECDSA Public Key: Z - FIDO Agreeme nt ECC Private Key: Z - FIDO Agreeme

Z Z Z FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 25
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
nt ECC Public Key: Z - FIDO Agreeme nt sharedSe cret: Z - FIDO SharedSe cret AES Key: Z - FIDO SharedSe cret HMAC Key: Z - FIDO PinUvAut hToken: Z - FIDO PIN: Z - PIV Authentic ation Key: Z - PIV ECC Signature Private Key: Z - PIV ECC verificatio n Public Key: Z - PIV RSA Signature Private Key: Z - PIV RSA verificatio n Public Key: Z - PIV User PIN: Z - PIV PUK PIN: Z - 2003 Internal

Z FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 26
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
Auth Key: Z - 2003 External Auth Key: Z - 2003 PIN: Z - 2003 PSO calculatio n key: Z - 2003 Unblock PIN: Z - 2003 RSA Private Key: Z - 2003 RSA Public Key: Z - 2003 ECDSA Private Key: Z - 2003 ECDSA Public Key: Z - OTP HMAC Seed Key: Z - OTP AccessCo de: Z - PGP Admin PIN(PW3) : Z - PGP User PIN(PW1) : Z - PGP Resetting

Z Z :Z :Z FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 27
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
Code: Z - PGP Signature Private Key: Z - PGP Verificatio n Public Key: Z - External Agreeme nt ECC Public Key: Z - DRBG Seed: Z - AES- GCM IV: Z
Manage Security Environme nt (MSE)Prepares the Module for the subsequent commands, Perform Security Operation.9000 or error statu sComman d without input paramete rN/ANoneUser Admin
HashPerforms a hash using SHA-256, SHA-384, or SHA- 512.9000 or error statu smessageHash valueSHA_CALUnauthen ticated
Read BinaryAllows read access to a binary file. A binary file is a file whose content is a sequential string of bits.9000 or error statu sComman d with file infoBinary databaseNoneAdmin User
Update BinaryAllows write access to a binary file.9000 or error statu sBinary dataN/ANoneAdmin User

Z s r s s s FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 28
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
Read RecordAllows read access to a record. A record is a type of data storage structure as defined within ISO 7816. Records are stored in files.9000 or error statu sComman d With file infoRecord dataNoneAdmin User
Update RecordAllows write access to a record9000 or error statu sRecord dataN/ANoneAdmin User
Append RecordAllows a record to be append9000 or error statu sRecord dataN/ANoneAdmin User
Internal Authenticat eAuthenticat e the cryptograp hic module by an external entity NOTE: In order for this service to be utilized, the external entity must have privileged access to the referenced key.9000 or error statu sRandom datacipher textAES_ENCAdmin - 2003 Internal Auth Key: E User - 2003 Internal Auth Key: E
External Authenticat eAuthenticat es an external entity by the9000 or error statu scipher textN/AAES_DECAdmin - 2003 External Auth Key: E

s s s FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 29
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
cryptograp hic module. NOTE: Prerequisit e to this service is the use of Get Challenge service. The key as referenced within the service call exists under the current fileUser - 2003 External Auth Key: E
Verify PINProvides PIN verification.9000 or error statu sPIN dataN/AKTS_SCP03_WRA PAdmin - 2003 PIN: E - KSenc: E - KSmac: E User - KSenc: E - KSmac: E - 2003 PIN: E
Change Reference DataModify the PIN9000 or error statu sPIN and new PIN dataN/AKTS_SCP03_WRA PAdmin - 2003 PIN: W,E - KSenc: E - KSmac: E User - 2003 PIN: W,E - KSenc: E - KSmac: E
Reset Retry CounterResets the retry counter9000 or errorComman d without inputN/AKTS_SCP03_WRA PUser - KSenc: E

E s E E E s E E P FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 30
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
statu sparamete r- KSmac: E Admin - KSenc: E - KSmac: E
Generate Asymmetri c Key PairGenerates an Asymmetric key pair.9000 or error statu sComman d without input paramete rN/ARSA_GEN_KEY_P AIR ECC_GEN_KEY_P AIRAdmin - DRBG- EI: G,E - 2003 RSA Private Key: G - 2003 RSA Public Key: G - 2003 ECDSA Private Key: G - 2003 ECDSA Public Key: G - DRBG Seed: G,E User - DRBG- EI: G,E - 2003 RSA Private Key: G - 2003 RSA Public Key: G - 2003 ECDSA Private Key: G - 2003 ECDSA Public Key: G

s r E E E FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 31
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
- DRBG Seed: G,E
EncryptPerforms an encrypt operation using an Approved security function.9000 or error statu sKid and plain textcipher textAES_ENCAdmin - 2003 PSO calculatio n key: E - Managing Key: E User - 2003 PSO calculatio n key: E - Managing Key: E
DecryptPerforms a decrypt operation.9000 or error statu sKid and cipher textplain textAES_DECAdmin - 2003 PSO calculatio n key: E - Managing Key: E User - 2003 PSO calculatio n key: E - Managing Key: E
Verify Digital SignatureVerifies a digital signature using RSA PKCS#1 or ECDSA9000 or error statu sSignature and kidN/ARSA_SIG_VER ECC_SIG_VER ECC_KEY_VERAdmin - 2003 RSA Public Key: E - 2003 ECDSA Public Key: E User - 2003 RSA Public

G,E s FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 32
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
Key: E - 2003 ECDSA Public Key: E
Generate Digital SignatureGenerates a digital signature using RSA PKCS#1 or ECDSA.9000 or error statu smessage and kidSignatureRSA_SIG_GEN ECC_SIG_GENAdmin - 2003 RSA Private Key: E - 2003 ECDSA Private Key: E User - 2003 RSA Private Key: E - 2003 ECDSA Private Key: E
Verify Cryptograp hic ChecksumPerforms AES CMAC verification.9000 or error statu scipher textN/AAES_ENC_AUTHAdmin - 2003 PSO calculatio n key: E User - 2003 PSO calculatio n key: E
Compute Cryptograp hic ChecksumCompute AES CMAC.9000 or error statu splain textcipher textAES_ENC_AUTHAdmin - 2003 PSO calculatio n key: E User - 2003 PSO calculatio n key: E
Create FileCreate a file.9000 or error statu sComman d with file infoN/ANoneAdmin

s s s s FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 33
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
Delete FileDelete a File.9000 or error statu sComman d with file infoN/ANoneAdmin - 2003 Internal Auth Key: Z - 2003 External Auth Key: Z - 2003 PIN: Z - 2003 Unblock PIN: Z - 2003 RSA Private Key: Z - 2003 RSA Public Key: Z - 2003 ECDSA Private Key: Z - 2003 ECDSA Public Key: Z
Install SecretThis service is used to enter AES keys, and PINs. SSPs which may be entered are as follows: * Internal Auth Key * External Auth Key * Symmetric Key * PIN9000 or error statu sEncrypte d Symmetri c Key or pinN/AKTS_SCP03_WRA PAdmin - 2003 Internal Auth Key: W - 2003 External Auth Key: W - 2003 PSO calculatio n key: W - KSenc: E - KSmac: E - 2003

Z Z s FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 34
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
PIN: W - 2003 Unblock PIN: W
Get File ListAllows the reading of the FID list of child files of the current file9000 or error statu sComman d with fileFile infoNoneAdmin User
Read Public KeyAllows the output of a public key.9000 or error statu sComman d with key infoRSA/ECC Public KeyNoneAdmin - 2003 RSA Public Key: R - 2003 ECDSA Public Key: R User - 2003 RSA Public Key: R - 2003 ECDSA Public Key: R
Make CredentialThis service is used to generate a new credential in the module00 or error statu sEncrypte d Device ECDSA Private Key and messageCredentic alID and X.509 certificateECC_GEN_KEY_P AIR ECC_SIG_GEN AES_ENC_AUTH KTS_AESGCM_WR APUser - DRBG- EI: G,E - DRBG V: G,E - AES- GCM Key: E - FIDO Device ECDSA Private Key: E - FIDO User ECDSA Private Key: G,R,W - FIDO

s s V: G,E G,R,W FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 35
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
Device ECDSA Public Key: R - AES- GCM IV: E - DRBG Seed: G,E - DRBG Key: G,E - FIDO User ECDSA Public Key: G,R
Get AttestationThis service is using Registratio n's credential to signature00 or error statu sEncrypte d User ECDSA Private Key and messageSignatureECC_SIG_GEN ECC_SIG_VER AES_DEC_AUTH KTS_AESGCM_WR APUser - DRBG- EI: G,E - DRBG V: G,E - AES- GCM Key: E - AES- GCM IV: E - DRBG Seed: G,E - DRBG Key: G,E - FIDO User ECDSA Private Key: E - FIDO User ECDSA Public Key: E
Get Next AttestationThe client calls this service when the AttestationrOK or error statu s00Comman d without input paramete rSignatureECC_SIG_GENUser - DRBG- EI: G,E - DRBG V: G,E

E G,E V: G,E E FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 36
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
esponse contains the number of credentials member and the number of credentials exceeds 1.or error statu s- AES- GCM Key: E - DRBG Seed: G,E - DRBG Key: G,E
Get InformationDevice Information00 or error statu sComman d without input paramete rVersionNoneUnauthen ticated
PIN ServiceThis service is used by the platform to establish the sharedSecr et key, setting a new user PIN, changing existing user PIN, and getting User PinUvAuth Token from the module00 or error statu sPINPinUvAut hTokenECC_GEN_KEY_P AIR AES_KEY_GEN ECC_KEY_VER SHAREDSECRETK EY_GEN_KAS AES_ENC_AUTH HMAC_GEN KTS_CTAP_WRAPUser - FIDO PIN: W,E - FIDO PinUvAut hToken: G,R,E - FIDO SharedSe cret AES Key: G,E - FIDO SharedSe cret HMAC Key: G,E - FIDO Agreeme nt sharedSe cret: G,E - FIDO Agreeme nt ECC Public Key: G,R - External Agreeme nt ECC Public Key: W,E -

s r G,R,E FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 37
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
Managing Key: G
FIDO ResetZeroization00 or error statu sComman d without input paramete rN/AAES_KEY_GEN DRBG_GENCO - FIDO User ECDSA Private Key: Z - FIDO User ECDSA Public Key: Z - FIDO Agreeme nt ECC Private Key: Z - FIDO Agreeme nt ECC Public Key: Z - FIDO Agreeme nt sharedSe cret: Z - FIDO SharedSe cret AES Key: Z - FIDO SharedSe cret HMAC Key: Z - FIDO PinUvAut hToken: Z - FIDO PIN: Z - AES- GCM Key: G
Credential Manageme ntListing credentials and00 or errorpinUvAut hParamN/AAES_ENC HMAC_GEN KTS_CTAP_WRAPUser - FIDO

s G FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 38
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
deleting credentialsstatu sPinUvAut hToken: E
authenticat orConfigused to configure various authenticat or features through the use of its subcomma nds.00 or error statu spinUvAut hParamN/AAES_ENC HMAC_GENUser - FIDO PinUvAut hToken: E
PIV GET DATAThis service is used to read data object9000 or error statu sComman d without input paramete rdata objectNoneUser - PIV ECC verificatio n Public Key: R - PIV RSA verificatio n Public Key: R
PIV Verify PINThis service is used to verify the PIN.9000 or error statu sPINN/AKTS_SCP03_WRA PUser - KSenc: E - KSmac: E - PIV User PIN: W,E
PIV Verify PUKThis service is used to verify the PUK.9000 or error statu sPUKN/AKTS_SCP03_WRA PAdmin - KSenc: E - KSmac: E - PIV PUK PIN: W,E
GeneralAut h (Symmetric Key)This service is used to external and mutual authenticat e with PIV Symmetric Key9000 or error statu sRandom data and cipher textN/AAES_ENC_AUTH AES_ENCUser - DRBG- EI: E - PIV Authentic ation Key: E
PIV ResetReset PIV card state and delete all stored9000 or error statu sComman d without input paramete rN/ASHA_CALCO - PIV User PIN: Z - PIV PUK PIN: Z

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 39
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
information Zeroization- PIV Authentic ation Key: Z - PIV ECC Signature Private Key: Z - PIV ECC verificatio n Public Key: Z - PIV RSA Signature Private Key: Z - PIV RSA verificatio n Public Key: Z
Set Authenticat ion KeyThis service is used to change Authenticati on key (PIV Symmetric Key)9000 or error statu sEncrypte d Authentic ation KeyN/AAES_ENC AES_DEC KTS_SCP03_WRA PAdmin - PIV Authentic ation Key: W,E - Managing Key: E
Change PUKThis service is used to change PUK9000 or error statu sPUKN/AKTS_SCP03_WRA PAdmin - PIV PUK PIN: W,E - KSenc: E - KSmac: E
Change PINThis service is used to change PIN9000 or error statu sPIN and new PINN/AKTS_SCP03_WRA PUser - PIV User PIN: W,E - KSenc: E - KSmac: E
Unblock PIN (Reset retry counter)This service is used to reset retry counter and set9000 or error statu sNew PIN and PUKN/AKTS_SCP03_WRA PAdmin - PIV User PIN: W,E - PIV PUK PIN: W,E - KSenc:

Z s E E s FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 40
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
new user PIN with known PUKE - KSmac: E
Generate Asymmetri c KeyThis service is used to generate an asymmetric key9000 or error statu sComman d with Key lengthAsymmet ric Public keyRSA_GEN_KEY_P AIR ECC_GEN_KEY_P AIRAdmin - DRBG V: G,Z - PIV ECC Signature Private Key: G - PIV ECC verificatio n Public Key: G - PIV RSA Signature Private Key: G - PIV RSA verificatio n Public Key: G - DRBG Key: G,Z - DRBG Seed: G,E - DRBG- EI: G,E
GeneralAut h (RSA/ECD SA)This service is used to generate signature with asymmetric key9000 or error statu smessageSignatureRSA_SIG_GEN ECC_SIG_GENUser - PIV ECC Signature Private Key: E - PIV RSA Signature Private Key: E
PIV Put DataThis service is used to write data (certicate, ID and etc)9000 or error statu sData objectN/ANoneAdmin
Personaliz ation OTPAdd a new entry and initialize its seed key9000 or errorSeed keyN/AKTS_SCP03_WRA PUser - OTP HMAC Seed

V: G,Z G,E s FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 41
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
statu sKey: W - KSenc: E - KSmac: E - DRBG V: E - OTP AccessCo de: E - DRBG Key: E - DRBG Seed: G,E - DRBG- EI: G,E
Delete OTPRemove an entry and its seed key.9000 or error statu sComman d without input paramete rN/ANoneUser - OTP AccessCo de: E - OTP HMAC Seed Key: Z
ListList all the names of the entries.9000 or error statu sComman d without input paramete rSlot infoNoneUser
Calculate OTPCalculate the OTP value for an entry.9000 or error statu sComman d without input paramete r6-digit OTP value or 8-digit OTP valueHMAC_GENUser - OTP HMAC Seed Key: E - OTP AccessCo de: E
OTP ResetReset the applet to manufactor y default settings.9000 or error statu sComman d without input paramete rN/ANoneCO - OTP HMAC Seed Key: Z
Verify AccessCod eVerify user AccessCod e9000 or error statu sAccessC odeN/AKTS_SCP03_WRA PUser - OTP AccessCo de: E

E E V: E G,E s r s r s r s FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 42
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
Change AccessCod eChange user AccessCod e9000 or error statu sAccessC odeN/AKTS_SCP03_WRA PUser - OTP AccessCo de: W,E
Emit OTP from slotWhen the device is powered on and the user presses the button, the device outputs a 6-byte or 8- byte password9000 or error statu spress- button6-digit OTP value or 8-digit OTP valueHMAC_GENUser - OTP HMAC Seed Key: E
SELECT DATASelect a current DO ,a following GET DATA or PUT DATA will access this current DO9000 or error statu sDO DataN/ANoneUnauthen ticated
VERIFYVerify using user PGP User PIN(PW1) or administrat or PGP Admin PIN(PW3)9000 or error statu sPGP User PIN(PW1 ) or PGP Admin PIN(PW3 )N/AKTS_SCP03_WRA PAdmin - PGP Admin PIN(PW3) : E User - PGP User PIN(PW1) : E
OpenPGP CHANGE REFEREN CE DATAChange user PGP User PIN(PW1) or administrat or PGP Admin PIN(PW3)9000 or error statu sComman d with data infoN/AKTS_SCP03_WRA PAdmin - PGP Admin PIN(PW3) : W,E User - PGP User PIN(PW1) : W,E
OpenPGP RESETReset PGP User PIN(PW1)9000 or errorPW1 or PW3/N/AKTS_SCP03_WRA PAdmin - PGP Admin

s s :E : W,E FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 43
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
RETRY COUNTERcounter and set new PGP User PIN(PW1) using PGP Admin PIN(PW3) or Resetting Code.statu sResetting CodePIN(PW3) : W,E - PGP User PIN(PW1) : W User - PGP User PIN(PW1) : W - PGP Resetting Code: W,E
GET DATARead protected or unprotecte d Data Object9000 or error statu sComman d without input paramete rData ObjectNoneUser - PGP User PIN(PW1) : E Unauthen ticated
PUT DATAWrite data objects except user writable data objects.9000 or error statu sData to be writtenNoneKTS_SCP03_WRA PAdmin - PGP Resetting Code: W - PGP Admin PIN(PW3) : E
COMPUTE DIGITAL SIGNATU REPerform signature primitive with signature Private Key9000 or error statu smessage and kidSignatureRSA_SIG_GENUser - PGP Signature Private Key: E
OpenPGP GENERAT E ASYMMET RIC KEYGenerate asymmetric key pair9000 or error statu sComman d without input paramete rRSA public keyRSA_GEN_KEY_P AIRAdmin - DRBG V: G,E - PGP Admin PIN(PW3) : E - PGP Signature Private Key: G - PGP

W,E s :E V: G,E FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 44
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
Verificatio n Public Key: G,R - DRBG Key: G,E - DRBG Seed: G,E - DRBG- EI: G,E
TERMINAT E DFThis command is designed to renew a card in case of blocked passwords or other problems.9000 or error statu sComman d without input paramete rN/ANoneAdmin - PGP Admin PIN(PW3) : E
ACTIVATE FILEInitialize to the manufactor y default settings. Zeroization9000 or error statu sComman d without input paramete rN/ANoneAdmin - PGP Admin PIN(PW3) : Z - PGP User PIN(PW1) : Z - PGP Resetting Code: Z - PGP Signature Private Key: Z - PGP Verificatio n Public Key: Z
Get Error logGet self- test result9000 or error statu sComman d without input paramete rSelf-test resultNoneAdmin - Device authentic ate key: E
On- Demand Self-testInitiate on- demand self-testsNoneNonePass or FailAdmin Unauthen ticated

G,E s r :E :Z s r s r FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 45
NameDescriptio nIndic atorInputsOutputsSecurity FunctionsSSP Access
by reboot or power cycle
4.4 Non-Approved Services
4.5 External Software/Firmware Loaded

NOTE: There is no External Software/Firmware Loaded. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 46
5 Software/Firmware Security
5.1 Integrity Techniques

The Module is composed of the following firmware component(s): Component 1: cryptographic binary Component 2: non-modifiable operating system - binary The firmware components are protected with the error detection code CRC-16. Calculate CRC-16 on code and constant data in flash, then compare the result with expected value, which is also part of preoperational self-test.

5.2 Initiate on Demand

The operator can initiate integrity test on demand by restarting the module. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 47
6 Operational Environment
6.1 Operational Environment Type and Requirements

The Module has a non-modifiable operational environment at Level 3 under the FIPS 140-3 definitions therefore per the FIPS 140-3 Management Manual Section 7.5 Partial validations and non-applicable areas this section is not applicable. Type of Operational Environment: Non-Modifiable FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 48
MechanismInspection FrequencyInspection Guidance
anti-dismantle enclosureEach time using the modulecheck the outer appearance of the module
Temp/Voltage TypeTemperature or VoltageEFP or EFTResult
LowTemperature-29.6EFPshutdown
HighTemperature+86.6EFPshutdown
LowVoltage2.8VEFPshutdown
HighVoltage5.5VEFPshutdown
7 Physical Security

The Module is made of a completely hardened, production-grade polycarbonate or metal. The colored polycarbonate or metal enclosure obscures a clear view of the hardware components within. A hard, non-malleable metal casing surrounds the USB connector. The casing is made of hard, production-grade, black, opaque plastic. The coloring of the Module obscures any visible writing on the PCB. The visible critical components within the Module are further covered to meet FIPS 140-3 level 3 physical security requirements. The HSC32K2 with PAA microcontroller is covered with a black, opaque, tamper-resistant, epoxy encapsulated, thus completely covering all critical cryptographic components from plain view. The USB connector located outside of the casing (in the case of the USB Token-A3) of the USB token is made of a hard, black, opaque, production grade plastic and prevents access to the rest of the USB token. Any attempt at removal or penetration of the enclosure has a high probability of causing serious damage to the Module and the hardware components within the enclosure, which will reveal clear tamper evidence. Removal of the metal surrounding the USB connector will result in physical damage of the USB connector and its associated pins, rendering the entire cryptographic module useless. If the USB connector is exposed, there is no power going to the USB token. Once power is removed from the cryptographic module, all plaintext keys and unprotected SSPs in RAM are zeroized.

7.1 Mechanisms and Actions Required

The enclosure of the module is designed with anti-dismantle. After assembly, any attempt at tampering will leave visible damage on the enclosure. So, each time a user uses the module, you should first check the outer appearance of the module to make sure the module has not been tampered since last time use. In case user detects any tamper during inspection, user must stop using the module immediately and contact manufacturer. Table 13: Mechanisms and Actions Required Table 14: EFP/EFT Information FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 49
Temperature TypeTemperature
LowTemperature-20C°
HighTemperature+40C°
7.3 Hardness Testing Temperature Ranges

Table 15: Hardness Testing Temperatures Notes: The module is hardness tested at the lowest and highest temperatures within the module's intended temperature range of operation. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 50
8 Non-Invasive Security
8.1 Mitigation Techniques

The Module does not implement any mitigation method against non-invasive attack. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 51
Storage Area NameDescriptionPersistence Type
CHIPRAM(S1)Session Key stored in volatile memory in plaintext.Dynamic
CHIPRAM(S2)Session Key stored in volatile memory in encrypted.Dynamic
CHIPNVM(S3)CSP is encrypted with AES-128 and stored in FLASHStatic
CHIPNVM(S4)CSP stored in flash in SHA2-256Static
CHIPNVM(S5)CSP stored in flash in plaintextStatic
CHIPNVM(S6)PSP stored in flash in plaintextStatic
NameFromToFormat TypeDistributi on TypeEntry TypeSFI or Algorithm
Input encapsula ted by KTS-Wrap SCP03(IO 1)Application Software (outside)CHIPNVM( S3)Encrypt edAutomate dElectro nicKTS_SCP03_WR AP
Input encapsula ted by KTS-Wrap AES-GCM (IO2)Application Software (outside)CHIPRAM( S2)Encrypt edAutomate dElectro nicKTS_AESGCM_W RAP
Output encapsula ted by KTS-Wrap AES-GCM (IO3)CHIPRAM( S2)Application Software (outside)Encrypt edAutomate dElectro nicKTS_AESGCM_W RAP
Input encapsula ted by KTS-Wrap AES-CBC with HMAC (IO4)Application Software (outside)CHIPNVM( S4)Encrypt edAutomate dElectro nicKTS_CTAP_WRA P
Output encapsula ted byCHIPRAM( S2)Application Software (outside)Encrypt edAutomate dElectro nicKTS_CTAP_WRA P
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

1) FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 52
Name KTS-Wrap AES-CBC with HMAC (IO5)FromToFormat TypeDistributi on TypeEntry TypeSFI or Algorithm
Input in plaintext (IO6)Application Software (outside)CHIPRAM( S1)Plaintex tAutomate dElectro nic
Output in plaintext (IO7)CHIPRAM( S1)Application Software (outside)Plaintex tAutomate dElectro nic
Output in plaintext (IO8)CHIPNVM( S6)Application Software (outside)Plaintex tAutomate dElectro nic
Zeroization MethodDescriptionRationaleOperator Initiation
Z1Zeroized by Terminate token commandAll SSP are cleared, completed by explicit indication of 9000 StatusCO
Z2Overwritten with all 0 after power cyclePower on and implicit clear, completed by implicit indication of LED on.Unauth
Z3Zeroized by 2003 delete MFReceived command to actively clear SSPs, completed by explicit indication of 9000 StatusCO
Z4"TERMINATE DF" followed by "ACTIVATE FILE"Received command to actively clear SSPs, completed by explicit indication of 9000 StatusCO
Z5Zeroized by FIDO ResetReceived command to actively clear SSPs, completed by explicit indication of 00 StatusCO
Z6Zeroized by PIV ResetReceived command to actively clear SSPs, completed by explicit indication of 9000 StatusCO
Z7Select functional unitReceived command to actively clear SSPs, completed by explicit indication of 9000 StatusUnauth
Z8Zeroized by OTP ResetReceived command to actively clear SSPs, completed by explicit indication of 9000 StatusCO

Table 17: SSP Input-Output Methods Table 18: SSP Zeroization Methods FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 53
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
DRBG-EI384-bit entropy and 256-bit nonce input collected from the ESV,used to derive the DRBG seed640 - 128entropy source and nonce - CSPENT_GENDRBG_GEN
DRBG Seed640-bit DRBG Seed from DRBG-EI640 - 128entropy source and nonce - CSPENT_GENDRBG_GEN
DRBG VInternal CTR_DRB G state value is used for SP800-90A CTR_DRB G (Consists of 128 bits)128 - 128state value - CSPDRBG_GENDRBG_GEN
DRBG KeyInternal CTR_DRB G state value is used for128 - 128key value - CSPDRBG_GENDRBG_GEN
9.4 SSPs

All usage of these SSPs by the Module are described in the services detailed in Section 4.3 FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 54
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
SP800-90A CTR_DRB G (Consists of 128 bits)
Managing Key128-bit AES key, used to encrypt SSPs and keys128 - 128Symmetri c Key - CSPAES_KEY_GENAES_ENC AES_DEC
Device authenticat e key128-bit AES key used for CO role to reach a safe state128 - 128Authentic ation - CSPinput during manufacturingAES_DEC
INIT_KEYe ncAES 128- bit key, used to derive KSenc and KSmac which is then used to encrypt/dec rypt data over a secure session between an authorized external128 - 128Symmetri c Key - CSPinput during manufacturingSESSIONKEY_GEN

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 55
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
entity and the Module.
INIT_KEY macAES CMAC 128-bit key, used to derive a KSenc,KS mac which is then used to authenticat e an operator or data over a secure session between an authorized external entity and the Module.128 - 128Symmetri c Key - CSPinput during manufacturingSESSIONKEY_GEN
KSencAES 128- bit key used to encrypt/dec rypt data over a secure session128 - 128session Key - CSPSESSIONKEY_GENKTS_SCP03_WRAP
KSmacAES CMAC 128-bit key used to authenticat128 - 128session Key - CSPSESSIONKEY_GENKTS_SCP03_WRAP

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 56
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
e data over a secure session
AES-GCM Key128-bit AES-GCM key used to encrypt the key handle or credentialI D128 - 128Symmetri c Key - CSPAES_KEY_GENAES_ENC_AUTH AES_DEC_AUTH
AES-GCM IV96-bit AES- GCM IV used to encrypt the key handle or credentialI D96 - N/ARandom IV - CSPDRBG_GENAES_ENC_AUTH AES_DEC_AUTH
FIDO Device ECDSA Private Key256-bit ECC private key used to generate signature for registration.256 - 128Asymmet ric Private Key - CSPinput during manufacturingECC_SIG_GEN
FIDO Device ECDSA Public Key256-bit ECC FIDO public key, it is returned to the server256 - 128Asymmet ric Public Key - PSPinput during manufacturingECC_SIG_VER

D D FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 57
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
via the certificate to verify the signature generated after registration
FIDO User ECDSA Private Key256-bit ECC private key used to Attestation signature256 - 128Asymmet ric Private Key - CSPECC_GEN_KEY_PAIRECC_SIG_GEN
FIDO User ECDSA Public Key256-bit ECC FIDO public key, it is transmitted to the server for verifying signature generated after authenticati on256 - 128Asymmet ric public Key - PSPECC_GEN_KEY_PAIRECC_SIG_VER
FIDO Agreement ECC Private Key256-bit ECC private key used to perform key agreement256 - 128Asymmet ric Private Key - CSPECC_GEN_KEY_PAIRSHAREDSECRETKEY _GEN_KAS

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 58
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
with external public ECC key to get shared Secret
FIDO Agreement ECC Public Key256-bit ECC public key used to perform key agreement, the Module returns it to external to get sharedSecr et256 - 128Asymmet ric public Key - PSPECC_GEN_KEY_PAIRSHAREDSECRETKEY _GEN_KAS
FIDO Agreement sharedSecr et256-bit key Used to derived FIDO SharedSec ret AES Key and FIDO SharedSec ret HMAC Key by HKDF256 - 128Shared Secret - CSPSHAREDSECRETKEY _GEN_KASKAS-ECC Sp800-56Ar3 (A4980)
FIDO SharedSec256-bit AES CBC key used256 - 128Symmetri c Key - CSPSHAREDSECRETKEY _GEN_KASSHAREDSECRETKEY _GEN_KAS

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 59
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
ret AES Keyfor encryption calculation of pin related operations
FIDO SharedSec ret HMAC Key256-bit AES CBC key used for HMAC SHA-256 calculation of pin related operations256 - 128Symmetri c Key - CSPSHAREDSECRETKEY _GEN_KASSHAREDSECRETKEY _GEN_KAS
FIDO PinUvAuth Token256-bit HMAC SHA-256 Key used to authorize operator after PIN authenticati on256 - 128Authentic ation - CSPDRBG_GENHMAC_GEN
FIDO PINAuthenticat e the User,4 to 63-byte PIN value32-248 - N/AAuthentic ation - CSPKTS_CTAP_WRAP
PIV Authenticat ion Key128-bit AES ECB key, used for128 - 128Authentic ation - CSPAES_ENC_AUTH

N/A FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 60
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
authenticati on of PIV CO
PIV ECC Signature Private Key256 bit ECC private key, used for signature operations256 - 128Asymmet ric Private Key - CSPECC_GEN_KEY_PAIRECC_SIG_GEN
PIV ECC verification Public Key256-bit ECC public key, used for client verification operations256 - 128Asymmet ric public Key - PSPECC_GEN_KEY_PAIR
PIV RSA Signature Private Key2048 -bit RSA private key, used for signature operations2048 - 112Asymmet ric Private Key - CSPRSA_GEN_KEY_PAIRRSA_SIG_GEN
PIV RSA verification Public Key2048 -bit RSA public key, used for client verification operations2048 - 112Asymmet ric public Key - PSPRSA_GEN_KEY_PAIR
PIV User PIN8-byte pin, used for authenticati ng the PIV user for64 - N/AAuthentic ation - CSPKTS_SCP03_WRAP

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 61
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
Asymmetric services
PIV PUK PIN8-byte pin, used for unblocking the PIV admin pin64 - N/AAuthentic ation - CSPKTS_SCP03_WRAP
2003 Internal Auth KeyAES 128,192,25 6-bit ,used to authenticat e the Module to an external entity128-256 - 128-256Authentic ation - CSPAES_ENC
2003 External Auth KeyAES 128,192,25 6-bit, used to modify the security state of the currently selected DF.128-256 - 128-256Authentic ation - CSPAES_DEC
2003 PIN8-16 byte secret used to modify the security state of the currently selected DF.64-128 - N/AAuthentic ation - CSP

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 62
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
2003 PSO calculation keyAES 128,192,25 6-bit, Used to encryption, decryption, checksum calculation, and checksum verification in Unit 2003128-256 - 128-256Symmetri c Key - CSPAES_ENC AES_DEC
2003 Unblock PIN8-16 byte secret used to unblocking the 2003 pin the currently selected DF.64-128 - N/AAuthentic ation - CSPAES_ENC
2003 RSA Private Key2048,3072, 4096 bit RSA private key is used to sign data2048,3072 ,4096 - 112-152Asymmet ric Private Key - CSPRSA_GEN_KEY_PAIRRSA_SIG_GEN
2003 RSA Public Key2048,3072, 4096-bit RSA public key used to verify data2048,3072 ,4096 - 112-152Asymmet ric public Key - PSPRSA_GEN_KEY_PAIRRSA_SIG_VER

N/A FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 63
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
2003 ECDSA Private Key256,384,52 1bit ECDSA private key used to sign data.256,384,5 21 - 128- 256Asymmet ric Private Key - CSPECC_GEN_KEY_PAIRECC_SIG_GEN
2003 ECDSA Public Key256,384,52 1bit ECDSA public key used to verify data.256,384,5 21 - 128- 256Asymmet ric public Key - PSPECC_GEN_KEY_PAIRECC_SIG_VER
OTP HMAC Seed Key16 to 64- byte HMAC SHA- 1,HMAC SHA-256 key ,used to calculate OTP values for the User128-512 - 128Authentic ation - CSPHMAC_GEN
OTP AccessCod e8-byte pin, used for authenticati ng the OTP user64 - N/AAuthentic ation - CSPHMAC_GEN KTS_SCP03_WRAP
PGP Admin PIN(PW3)8 to 127- byte, used for authenticati on of the OpenPGP CO.64-1024 - N/AAuthentic ation - CSPKTS_SCP03_WRAP

N/A FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 64
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
PGP User PIN(PW1)8 to 127- byte, used for authenticati ng the OpenPGP user for Asymmetric services.64-1024 - N/AAuthentic ation - CSPKTS_SCP03_WRAP
PGP Resetting Code8 to 127- byte.Used for resetting the User PIN64-1024 - N/AAuthentic ation - CSPKTS_SCP03_WRAP
PGP Signature Private Key2048,3072, 4096 bit RSA private key, used for PKCS#1 v1.5 signing operation2048,3072 ,4096 - 112-152Asymmet ric Private Key - CSPRSA_GEN_KEY_PAIRRSA_SIG_GEN
PGP Verification Public Key2048,3072, 4096 bit RSA public key, used for verification specified in PKCS#1 v1.52048,3072 ,4096 - 112-152Asymmet ric public Key - PSPRSA_GEN_KEY_PAIR

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 65
NameDescriptio nSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
External Agreement ECC Public Key256-bit ECC Public key used to perform key agreement with FIDO Agreement ECC Private Key to get sharedSecr et256 - 128Asymmet ric public Key - PSPSHAREDSECRETKEY _GEN_KAS
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
DRBG-EICHIPRAM(S1):Plaintextafter usage is completeZ2
DRBG SeedCHIPRAM(S1):Plaintextafter usage is completeZ2
DRBG VCHIPRAM(S1):Plaintextafter usage is completeZ2DRBG-EI:Derived From
DRBG KeyCHIPRAM(S1):Plaintextafter usage is completeZ2DRBG-EI:Derived From
Managing KeyCHIPNVM(S5):PlaintextZ1Device authenticate key:Encrypts INIT_KEYenc:Encrypts INIT_KEYmac:Encrypts FIDO Device ECDSA Private Key:Encrypts FIDO User ECDSA Private Key:Encrypts

Table 19: SSP Table 1 FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 66
Name Device authenticate key INIT_KEYenc INIT_KEYmacInput - OutputStorage CHIPNVM(S3):Encrypted CHIPNVM(S3):Encrypted CHIPNVM(S3):EncryptedStorage DurationZeroization Z1 Z1 Z1Related SSPs PIV Authentication Key:Encrypts PIV ECC Signature Private Key:Encrypts PIV RSA Signature Private Key:Encrypts 2003 Internal Auth Key:Encrypts 2003 External Auth Key:Encrypts 2003 PSO calculation key:Encrypts 2003 RSA Private Key:Encrypts 2003 ECDSA Private Key:Encrypts OTP HMAC Seed Key:Encrypts PGP Resetting Code:Encrypts PGP Signature Private Key:Encrypts Managing Key:Encrypted by KSenc:Derives Managing Key:Encrypted by KSenc:Derives Managing Key:Encrypted by KSmac:Derives
KSencCHIPRAM(S1):Plaintextafter usage is completedZ7INIT_KEYenc:Derived From

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 67
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
KSmacCHIPRAM(S1):Plaintextafter usage is completedZ7INIT_KEYmac:Derived From
AES-GCM KeyCHIPNVM(S5):PlaintextZ5FIDO User ECDSA Private Key:Wraps
AES-GCM IVCHIPNVM(S5):PlaintextZ5FIDO User ECDSA Private Key:Wraps
FIDO Device ECDSA Private KeyCHIPNVM(S3):EncryptedZ1FIDO Device ECDSA Public Key:Paired With Managing Key:Encrypted by AES-GCM Key:Wrapped by
FIDO Device ECDSA Public KeyOutput in plaintext (IO8)CHIPNVM(S6):PlaintextZ1FIDO Device ECDSA Private Key:Paired With
FIDO User ECDSA Private KeyInput encapsulated by KTS-Wrap AES- GCM (IO2) Output encapsulated by KTS-Wrap AES- GCM (IO3)CHIPNVM(S3):EncryptedZ5FIDO User ECDSA Public Key:Paired With Managing Key:Encrypted by AES-GCM Key:Wrapped by AES-GCM IV:Wrapped by
FIDO User ECDSA Public KeyOutput in plaintext (IO7)CHIPNVM(S6):PlaintextZ5FIDO User ECDSA Private Key:Paired With
FIDO Agreement ECC Private KeyCHIPRAM(S1):PlaintextZ2FIDO Agreement ECC Public Key:Paired With FIDO Agreement sharedSecret:Derives
FIDO Agreement ECC Public KeyOutput in plaintext (IO7)CHIPRAM(S1):PlaintextZ2FIDO Agreement ECC Private Key:Paired With
FIDO Agreement sharedSecretCHIPRAM(S1):Plaintextafter their usage is completedZ2FIDO Agreement ECC Private Key:Derived From External Agreement ECC Public Key:Derived From

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 68
Name FIDO SharedSecret AES Key FIDO SharedSecret HMAC KeyInput - OutputStorage CHIPRAM(S1):Plaintext CHIPRAM(S1):PlaintextStorage DurationZeroization Z5 Z5Related SSPs FIDO SharedSecret AES Key:Derives FIDO SharedSecret HMAC Key:Derives FIDO Agreement sharedSecret:Derived From FIDO Agreement sharedSecret:Derived From
FIDO PinUvAuthTokenOutput encapsulated by KTS-Wrap AES- CBC with HMAC (IO5)CHIPRAM(S1):Plaintextafter their usage is completedZ5FIDO SharedSecret AES Key:Wrapped by FIDO SharedSecret HMAC Key:Wrapped by
FIDO PINInput encapsulated by KTS-Wrap AES- CBC with HMAC (IO4)CHIPNVM(S4):EncryptedZ5
PIV Authentication KeyInput encapsulated by KTS-Wrap SCP03(IO1)CHIPNVM(S3):EncryptedZ6Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by
PIV ECC Signature Private KeyCHIPNVM(S3):EncryptedZ6PIV ECC verification Public Key:Paired With Managing Key:Encrypted by
PIV ECC verification Public KeyOutput in plaintext (IO8)CHIPNVM(S6):PlaintextZ6PIV ECC Signature Private Key:Paired With
PIV RSA Signature Private KeyCHIPNVM(S3):EncryptedZ6PIV RSA verification Public Key:Paired With Managing Key:Encrypted by

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 69

Name PIV RSA verification Public Key PIV User PIN PIV PUK PIN 2003 Internal Auth Key 2003 External Auth Key 2003 PIN 2003 PSO calculation key 2003 Unblock PIN 2003 RSA Private Key

Input - Output Output in plaintext (IO8) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1)

Storage CHIPNVM(S6):Plaintext CHIPNVM(S4):Encrypted CHIPNVM(S4):Encrypted CHIPNVM(S3):Encrypted CHIPNVM(S3):Encrypted CHIPNVM(S4):Encrypted CHIPNVM(S3):Encrypted CHIPNVM(S4):Encrypted CHIPNVM(S3):Encrypted

Storage Duration

Zeroization Z6 Z6 Z6 Z3 Z3 Z3 Z3 Z3 Z3

Related SSPs PIV RSA Signature Private Key:Paired With KSenc:Unwrapped by KSmac:Unwrapped by KSenc:Unwrapped by KSmac:Unwrapped by Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by 2003 RSA Public Key:Paired With Managing Key:Encrypted by

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 70

Name 2003 RSA Public Key 2003 ECDSA Private Key 2003 ECDSA Public Key OTP HMAC Seed Key OTP AccessCode PGP Admin PIN(PW3) PGP User PIN(PW1) PGP Resetting Code PGP Signature Private Key PGP Verification Public Key External Agreement ECC Public Key

Input - Output Output in plaintext (IO8) Output in plaintext (IO8) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1) Input encapsulated by KTS-Wrap SCP03(IO1) Output in plaintext (IO8) Input in plaintext (IO6)

Storage CHIPNVM(S6):Plaintext CHIPNVM(S3):Encrypted CHIPNVM(S6):Plaintext CHIPNVM(S3):Encrypted CHIPNVM(S4):Encrypted CHIPNVM(S4):Encrypted CHIPNVM(S4):Encrypted CHIPNVM(S3):Encrypted CHIPNVM(S3):Encrypted CHIPNVM(S6):Plaintext CHIPRAM(S1):Plaintext

Storage Duration

Zeroization Z3 Z3 Z3 Z1 Z8 Z4 Z4 Z4 Z4 Z4 Z2

Related SSPs 2003 RSA Private Key:Paired With Managing Key:Encrypted by 2003 ECDSA Public Key:Paired With 2003 ECDSA Private Key:Paired With Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by KSenc:Unwrapped by KSmac:Unwrapped by KSenc:Unwrapped by KSmac:Unwrapped by KSenc:Unwrapped by KSmac:Unwrapped by KSenc:Unwrapped by KSmac:Unwrapped by Managing Key:Encrypted by PGP Verification Public Key:Paired With PGP Signature Private Key:Paired With FIDO Agreement ECC Private Key:Used With

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 71

Name

Input - Output

Storage

Storage Duration

Zeroization

Related SSPs FIDO Agreement sharedSecret:Derives

Table 20: SSP Table 2 FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 72
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 73
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
FIPS_CRC16_FITCRC-16KATSW/FW Integrity9000 or 6F90Executed on the whole firmware stored in EEPROM before the Module transition to the idle state.
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES EncryptAES-128-bit - ECBKATCAST9000(meaning Successful) or 6F90(meaning fail)AES EncryptionBootup
AES DecryptAES-128-bit - ECBKATCAST9000(meaning Successful) or 6F90(meaning fail)AES decryptionBootup
10 Self-Tests

The Module performs self-tests to ensure the proper operation of the Module. Per FIPS 140-3 these are categorized as either pre-operational self-tests or conditional self-tests.

10.1 Pre-Operational Self-Tests

The Module performs the following pre-operational self-tests in table below Table 21: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

The Module performs the following conditional self-tests in the table below FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 74
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CMACAES-128-bit CMACKATCAST9000(meaning Successful) or 6F90(meaning fail)Message AuthenticationBootup
AES-GCM EncryptAES-128-bit GCMKATCAST9000(meaning Successful) or 6F90(meaning fail)Authenticated encryptionBootup
AES-GCM DecryptAES-128-bit GCMKATCAST9000(meaning Successful) or 6F90(meaning fail)Authenticated decryptionBootup
Counter DRBGAES-128-bit- ECBKATCAST9000(meaning Successful) or 6F90(meaning fail)AES-128 CTR_DRBG instantiation, generate, and reseed KATs performed before the first random data generationBootup
KAS-ECC Sp800-56Ar3ECDH: P-256 HKDF: Using HMAC-Two stepKATCAST9000(meaning Successful) or 6F90(meaning fail)KAS-SSC Shared Secret generation with P-256 per IG D.F.Bootup
ECDSA KeyGen (FIPS186-5)ECDSA Key GenerationPCTPCT9000(meaning Successful) or 6F90(meaning fail)Signature and Verification Per IG C.AGenerate ECDSA key pairs
ECDSA SigGen (FIPS186-5)ECDSA Signature GenerationKATCAST9000(meaning Successful) or 6F90(meaning fail)ECDSA P-256 with SHA-256 Signature GenerationBootup
ECDSA SigVer (FIPS186-5)ECDSA Signature VerificationKATCAST9000(meaning Successful) or 6F90(meaning fail)ECDSA P-256 with SHA-256 Signature VerificationBootup
HMAC-SHA2-256using HMAC- SHA256KATCAST9000(meaning Successful) or 6F90(meaning fail)HMAC-SHA-256 KATBootup
RSA KeyGen (FIPS186-5)2048-bit 3072-bit 4096-bit RSA Key Generation Pairwise Consistency TestPCTPCT9000(meaning Successful) or 6F90(meaning fail)Signature and Verification per IG C.E.Generate RSA key pairs

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 75
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigVer (FIPS186-5)2048-bit RSA Signature VerificationKATCAST9000 or 6F902048-bit RSA PKCSv1.5 with SHA-256 Signature VerificationBootup
RSA SigGen (FIPS186-5)2048-bit RSA Signature GenerationKATCAST9000 or 6F902048-bit RSA PKCSv1.5 with SHA-256 Signature GenerationBootup
SHA-1SHA-1KATCAST9000(meaning Successful) or 6F90(meaning fail)SHA-1Bootup
SHA2-256SHA2-256KATCAST9000(meaning Successful) or 6F90(meaning fail)SHA2-256Bootup
SHA2-384SHA2-384KATCAST9000(meaning Successful) or 6F90(meaning fail)SHA2-384Bootup
SHA2-512SHA2-512KATCAST9000(meaning Successful) or 6F90(meaning fail)SHA2-512Bootup
KDF SP800-108Using AES128 CMACKATCAST9000(meaning Successful) or 6F90(meaning fail)AES128 CMAC KATBootup
Entropy 90B Start-up Repetition Count Test (RCT)Repetition Count TestRCTCASTSuccess or Failure CodeAs specified in [90B] RCT startup health testsAt boot up
Entropy 90B Start-up Adaptive Proportion Test (APT)Adaptive Proportion TestAPTCASTSuccess or Failure CodeAs specified in [90B] APT startup health testsAt boot up
Entropy 90B Continuous Repetition Count Test (RCT)Repetition Count TestRCTCASTSuccess or Failure CodeAs specified in [90B] RCT continuous health testsContinuous when entropy is requested

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 76
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Entropy 90B Continuous Adaptive Proportion Test (APT)Adaptive Proportion TestAPTCASTSuccess or Failure CodeAs specified in [90B] APT continuous health testsContinuous when entropy is requested
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
FIPS_CRC16_FITKATSW/FW Integrityevery 1000 services are processed or power onperformed by the Module programmatically
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES EncryptKATCASTevery 1000 services are processed or power onAutomatic

Table 22: Conditional Self-Tests

10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 77
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES DecryptKATCASTevery 1000 services are processed and power onAutomatic
AES-CMACKATCASTevery 1000 services are processed or power onAutomatic
AES-GCM EncryptKATCASTevery 1000 services are processed or power onAutomatic
AES-GCM DecryptKATCASTevery 1000 services are processed or power onAutomatic
Counter DRBGKATCASTevery 1000 services are processed or power onAutomatic
KAS-ECC Sp800-56Ar3KATCASTevery 1000 services are processed or power onAutomatic
ECDSA KeyGen (FIPS186-5)PCTPCTEverytime a key pair is generatedAutomatic
ECDSA SigGen (FIPS186-5)KATCASTevery 1000 services are processed or power onAutomatic
ECDSA SigVer (FIPS186-5)KATCASTevery 1000 services are processed or power onAutomatic
HMAC-SHA2-256KATCASTevery 1000 services are processed or power onAutomatic
RSA KeyGen (FIPS186- 5)PCTPCTEverytime a key pair is generatedAutomatic
RSA SigVer (FIPS186- 5)KATCASTevery 1000 services are processed or power onAutomatic
RSA SigGen (FIPS186- 5)KATCASTevery 1000 services are processed or power onAutomatic
SHA-1KATCASTevery 1000 services are processed or power onAutomatic
SHA2-256KATCASTevery 1000 services are processed or power onAutomatic
SHA2-384KATCASTevery 1000 services are processed or power onAutomatic

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 78
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-512KATCASTevery 1000 services are processed or power onAutomatic
KDF SP800-108KATCASTevery 1000 services are processed and power onAutomatic
Entropy 90B Start-up Repetition Count Test (RCT)RCTCASTOn DemandDevice Reset
Entropy 90B Start-up Adaptive Proportion Test (APT)APTCASTOn DemandDevice Reset
Entropy 90B Continuous Repetition Count Test (RCT)RCTCASTN/AN/A
Entropy 90B Continuous Adaptive Proportion Test (APT)APTCASTN/AN/A

Table 24: Conditional Periodic Information The condition of initiating Periodic Self-Test is to execute every 1000 services. Once every 1000 services being executed, the periodic self-test function will call Pre-Operational Self-Tests and Conditional Self-Tests. Self-test failures are indicated to the user through LED status and service return status. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 79
NameDescriptionConditionsRecovery MethodIndicator
ES1The Module fails at CRC16 FIT, ENT RCT and APT, CTR DRBG KAT, ECDSA KAT, RSA KAT, AES ECB KAT, AES CMAC KAT, AES GCM KAT, HMAC KAT, KBKDF KAT, KAS-ECC KAT, SHS KAT, RSA Generate key pair PCT, ECC Generate key pair PCTThe Module enters Critical error state.Reboot/Power cycle the module6F90 and blinking LED
10.4 Error States
10.5 Operator Initiation of Self-Tests

All self-tests, except for the continuous health tests, can be invoked on demand by restarting the module. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 80
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Installation and Initialization: The following steps must be performed in order to securely install, initialize, and start up the ePass Token cryptographic module in the FIPS 140-3 Approved mode of operation. The steps for the CO to enter the module and change the default password gain authorized access to the module. The module is setup at manufacturing and delivered to the CO in approved mode. Delivery: The following steps must be performed in order to securely deliver the ePass Token cryptographic module to the authorized operator:

  1. Set the required keys in a secure factory environment
  2. Complete packaging and user manual
  3. Shipping the modules to the final customer. For each shipment, our factory will use the courier agreed with customer, such as FedEx or DHL. Our factory will inform customer in advance with the shipment info by email. When the goods arriving in customer site, the customer will first check the goods according to the shipment info they received, and sign for acceptance.
  4. The final customer check the module information according to administrator manual.
11.2 Administrator Guidance

Refer to FEITIAN ePass Token Cryptographic Module Administrator Guidance.docx, which will be provided to the issuer through secure communications.

11.3 Non-Administrator Guidance

Refer to FEITIAN ePass Token Cryptographic Module Non-Administrator Guidance.docx, which will be provided to the issuer through secure communications.

11.4 Design and Rules
1.The Module provides two distinct operator roles: User and Cryptographic Officer.
2.The Module provides identity-based authentication.
3.The Module clears previous authentications on power cycle.
4.An operator does not have access to any cryptographic services prior to assuming an authorized role.
5.The Module allows the operator to initiate power-up self-tests by power cycling power or resetting the Module.

FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 81
  1. All self-tests do not require any operator action.
  2. Data output is inhibited during key generation, self-tests, zeroization, and error states.
  3. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module.
  4. There are no restrictions on which keys or SSPs are zeroized by the zeroization service.
  5. The Module does not support concurrent operators.
  6. The Module does not support a maintenance interface or role.
  7. The Module does not have any proprietary external input/output devices used for entry/output of data.
  8. The Module does not enter or output plaintext CSPs.
  9. The Module does not store any plaintext CSPs.
  10. The Module does not output intermediate key values.
  11. The Module does not provide bypass services or ports/interfaces.
11.5 Maintenance Requirements

The module does not require any maintenance requirements

11.6 End of Life

Administrator SHALL invoke Terminate token service after authentication to switch device into the terminated state as a result, all CSPs are cleared, and all services are not available anymore. The device shall be destroyed. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 82
12 Mitigation of Other Attacks

The Module does not implement any mitigation method against other attacks. FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 83
Abbreviation *Full Specification Name
[FIPS140-3]Security Requirements for Cryptographic Modules, March 22, 2019
[ISO19790]International Standard, ISO/IEC 19790, Information technology — Security techniques — Test requirements for cryptographic modules, Third edition, March 2017
[ISO24759]International Standard, ISO/IEC 24759, Information technology — Security techniques — Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015
[IG]Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, October 23, 2024
[108r1]NIST Special Publication 800-108, Recommendation for Key Derivation Using Pseudorandom Functions (Revised), August 2022 INCLUDES UPDATES AS OF 02-02-2024
[133]NIST Special Publication 800-133, Recommendation for Cryptographic Key Generation, Revision 2, June 2020
[135]National Institute of Standards and Technology, Recommendation for Existing Application- Specific Key Derivation Functions, Special Publication 800-135rev1, December 2011.
[186]National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-5, February 3, 2023.
[197]National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197, May 9, 2023
[198-1]National Institute of Standards and Technology, The Keyed-Hash Message Authentication Code (HMAC), Federal Information Processing Standards Publication 198-1, July, 2008
[180]National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August, 2015
[38A]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation, Methods and Techniques, Special Publication 800-38A, December 2001
[38B]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication, Special Publication 800-38B, May 2005
[38D]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC, Special Publication 800-38D, November 2007

References and Definitions The following standards are referred to in this Security Policy. Table 26 References * FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).

Page 84
Abbreviation *Full Specification Name
[56Ar3]NIST Special Publication 800-56A Revision 3, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, April 2018
[56Br2]NIST Special Publication 800-56B Revision 2, Recommendation for Pair-Wise Key Establishment Schemes Using Finite Field Cryptography, March 2019
[56Cr2]NIST Special Publication 800-56C Revision 2, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, August 2020
[90A]National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A, Revision 1, June 2015.
[90B]National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018.
Acronym*Definition
APTAdaptative Proportion Test
KATKnow Answer Test
RCTRepetition Count Test
SSPSensitive Security Parameter
PCTPairwise Consistency Test
KDFKey Derivation Function
KTSKey Transport Scheme
KASKey Agreement Scheme
VCCVoltage(at the) Common Collector
PINPersonal Identification Number
PGP User PIN (PW1)user-password
PGP Admin PIN (PW3)admin-password
COCrypto Officer
PUKPIN Unblocking Key

* Table 27 Acronyms and Definitions FEITIAN Technologies Public Material – May be reproduced only in its original entirety (without revision).