Apple corecrypto Module v13.0 [Apple silicon, User, Software, SL1]

Certificate details

Certificate ID #5065
Status active
Validation dates 22.09.2025
Sunset date 21-09-2030
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Apple Cryptographic Module for Apple silicon user space environment.
Vendor Apple Inc. http://www.apple.com
Lab atsec information security corporation
Algorithms
  • AES-CBCA3486
  • AES-CCMA3487
  • AES-CFB128A3486
  • AES-CFB8A3486
  • AES-CMACA3486
  • AES-CTRA3487
  • AES-ECBA3487
  • AES-GCMA3487
  • AES-KWA3486
  • AES-OFBA3486
  • AES-XTS Testing Revision 2.0A3486
  • Counter DRBGA3487
  • ECDSA KeyGen (FIPS186-4)A3488
  • ECDSA KeyVer (FIPS186-4)A3488
  • ECDSA SigGen (FIPS186-4)A3488
  • ECDSA SigVer (FIPS186-4)A3488
  • HMAC-SHA-1A3488
  • HMAC-SHA2-224A3488
  • HMAC-SHA2-256A3489
  • HMAC-SHA2-384A3488
  • HMAC-SHA2-512/256A3488
  • HMAC-SHA2-512A3488
  • KAS-ECC-SSC Sp800-56Ar3A3486
  • KAS-FFC-SSC Sp800-56Ar3A3486
  • KDF SP800-108A3488
  • PBKDFA3488
  • RSA KeyGen (FIPS186-4)A3488
  • RSA SigGen (FIPS186-4)A3488
  • RSA SigVer (FIPS186-4)A3488
  • Safe Primes Key GenerationA3486
  • SHA-1A3488
  • SHA2-224A3488
  • SHA2-256A3489
  • SHA2-384A3488
  • SHA2-512/256A3488
  • SHA2-512A3488
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-128, AES-256, AES128, AES192, AES256, AES-, CAST5, CAST, RC2, RC4, DES, Triple-DES, TDEA, Blowfish, HMAC, HMAC-SHA-256, CMAC, CBC-MAC
Asymmetric Algorithms
ECDH, ECDSA, EdDSA, ECIES, ECC, Diffie-Hellman, DH
Hash functions
SHA1, SHA-1, SHA224, SHA256, SHA384, SHA512, SHA-224, SHA-256, SHA-384, SHA-512, SHA-3, Keccak, MD4, MD5, RIPEMD, PBKDF, PBKDF2
Schemes
MAC, Key agreement, Key Agreement
Protocols
TLS, TLS 1.2, IKE, IPsec
Randomness
DRBG, RBG
Elliptic Curves
P-384, P-521, curve P-192, P-224, P-256, P-192, Ed25519
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTS

JavaCard API constants
X25519
Trusted Execution Environments
SSC, SE

Security level
Level 1, level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5065,
  "dgst": "09c8798b150c5a2e",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "AES-KWA3486",
        "HMAC-SHA2-256A3489",
        "#A3425",
        "AES-CMACA3486",
        "HMAC-SHA-1A3488",
        "AES-OFBA3486",
        "#A3428",
        "AES-GCMA3487",
        "ECDSA KeyVer (FIPS186-4)A3488",
        "#A3427",
        "AES-CTRA3487",
        "KAS-FFC-SSC Sp800-56Ar3A3486",
        "ECDSA SigVer (FIPS186-4)A3488",
        "KAS-ECC-SSC Sp800-56Ar3A3486",
        "#A3429",
        "#A3487",
        "SHA2-224A3488",
        "#A3488",
        "Safe Primes Key GenerationA3486",
        "AES-CFB8A3486",
        "AES-XTS Testing Revision 2.0A3486",
        "SHA-1A3488",
        "Counter DRBGA3487",
        "SHA2-384A3488",
        "ECDSA SigGen (FIPS186-4)A3488",
        "HMAC-SHA2-512A3488",
        "#A3484",
        "#A3423",
        "#A3483",
        "SHA2-512A3488",
        "HMAC-SHA2-512/256A3488",
        "#A3485",
        "#A3424",
        "SHA2-256A3489",
        "#A3489",
        "RSA SigGen (FIPS186-4)A3488",
        "HMAC-SHA2-224A3488",
        "KDF SP800-108A3488",
        "#A3426",
        "RSA KeyGen (FIPS186-4)A3488",
        "#A3486",
        "PBKDFA3488",
        "RSA SigVer (FIPS186-4)A3488",
        "AES-CFB128A3486",
        "AES-CCMA3487",
        "AES-ECBA3487",
        "SHA2-512/256A3488",
        "ECDSA KeyGen (FIPS186-4)A3488",
        "AES-CBCA3486",
        "HMAC-SHA2-384A3488"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "13.0"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3423",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3425",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3483",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3485",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3427",
            "properties": "-",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3487",
            "properties": "-",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A3423",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A3483",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3427",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3487",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3423",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3427",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3483",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3487",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3427",
            "properties": "-",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3487",
            "properties": "-",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A3423",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A3483",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A3423",
            "properties": "-",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A3483",
            "properties": "-",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3424",
            "properties": "-",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3427",
            "properties": "-",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3484",
            "properties": "-",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3487",
            "properties": "-",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3429",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3489",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512/256",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512/256",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512/256",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512/256",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDF SP800-108",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SP800-108",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SP800-108",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SP800-108",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3429",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3489",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A3426",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A3428",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A3486",
            "properties": "-",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A3488",
            "properties": "-",
            "reference": "FIPS 180-4"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Execute AES- mode encrypt or decrypt operation",
            "indicator": "1",
            "inputs": "plaintext data and key / ciphertex t data and key",
            "name": "AES Encryption/Decryp tion",
            "outputs": "ciphertext data / plaintext data",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Unauthentica ted Symmetric Encryption and Decryption Authenticate d Symmetric Encryption and Decryption"
          },
          {
            "description": "Execute AES-key wrapping or unwrappi ng operation",
            "indicator": "1",
            "inputs": "AES key wrapping key, unwrapp ed key / Wrapped key, AES key",
            "name": "AES Key Wrapping / Key unwrapping",
            "outputs": "wrapped key / unwrapped key",
            "rolesSspAccess": "Crypto Officer - AES key- wrappin g key: W,E",
            "secFunImpl": "Key wrapping/ Key unwrapping"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "wrapping key",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Generate a digest for the requested algorithm",
            "indicator": "1",
            "inputs": "message",
            "name": "Secure Hash Generation",
            "outputs": "digest",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Message Digest"
          },
          {
            "description": "Generate a MAC digest using the requested SHA algorithm or AES algorithm",
            "indicator": "1",
            "inputs": "message, MAC key, MAC algorith m",
            "name": "Message Authentication Generation",
            "outputs": "MAC",
            "rolesSspAccess": "Crypto Officer - AES key: W,E - HMAC key: W,E",
            "secFunImpl": "CMAC Message Authenticatio n HMAC Message Authenticatio n"
          },
          {
            "description": "Verify a MAC digest",
            "indicator": "1",
            "inputs": "MAC, message, MAC key, MAC algorith m",
            "name": "Message Authentication Code Verification",
            "outputs": "pass/fail",
            "rolesSspAccess": "Crypto Officer - AES key: W,E - HMAC key: W,E",
            "secFunImpl": "CMAC Message Authenticatio n HMAC Message Authenticatio n"
          },
          {
            "description": "Sign a message with a specified RSA private key. Verify the signature of a message with a specified RSA",
            "indicator": "1",
            "inputs": "SigGen: private key, message, hash function; SigVer: public key, digital signature , message,",
            "name": "RSA signature generation and verification",
            "outputs": "SigGen: computed signature; SigVer: pass/fail result of digital signature verification",
            "rolesSspAccess": "Crypto Officer - RSA key pair: W,E",
            "secFunImpl": "RSA Digital Signature Generation RSA Digital Signature Verification"
          },
          {
            "description": "public key.",
            "indicator": "",
            "inputs": "hash function",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Sign a message with a specified ECDSA private key Verify the signature of a message with a specified ECDSA public key",
            "indicator": "1",
            "inputs": "SigGen: private key, message, hash function; SigVer: public key, digital signature , message, hash function",
            "name": "ECDSA signature generation and verification",
            "outputs": "SigGen: computed signature; SigVer: pass/fail result of digital signature verification",
            "rolesSspAccess": "Crypto Officer - ECDSA key pair: W,E",
            "secFunImpl": "ECDSA Digital Signature Generation ECDSA Digital Signature Verification"
          },
          {
            "description": "Generate random number",
            "indicator": "1",
            "inputs": "Length or size for requeste d numbers",
            "name": "Random Number Generation",
            "outputs": "random bit- string",
            "rolesSspAccess": "Crypto Officer - Entropy input string: E - DRBG seed, internal state V value, and key: G,R,E",
            "secFunImpl": "Random Number Generation"
          },
          {
            "description": "Derive key from password",
            "indicator": "1",
            "inputs": "Password",
            "name": "PBKDF",
            "outputs": "PBKDF derived key",
            "rolesSspAccess": "Crypto Officer - PBKDF derived key: G,R - PBKDF passwor d: E",
            "secFunImpl": "PBKDF Key Derivation"
          },
          {
            "description": "Derive key from key derivation key",
            "indicator": "1",
            "inputs": "Derivatio n key",
            "name": "KBKDF",
            "outputs": "KBKDF derived key",
            "rolesSspAccess": "Crypto Officer - KBKDF key derivati on key: W,E - KBKDF derived key: G,R,E",
            "secFunImpl": "KBKDF Key Derivation with HMAC KBKDF Key Derivation with CMAC"
          },
          {
            "description": "Generate a keypair for a requested modulus",
            "indicator": "1",
            "inputs": "Modulus size",
            "name": "RSA key pair generation",
            "outputs": "RSA key pair",
            "rolesSspAccess": "Crypto Officer - RSA key pair: G,R,E",
            "secFunImpl": "RSA Asymmetric Key Generation"
          },
          {
            "description": "Generate a keypair for a requested elliptic curve",
            "indicator": "1",
            "inputs": "Curve",
            "name": "ECDSA key pair generation",
            "outputs": "ECDSA key pair",
            "rolesSspAccess": "Crypto Officer - ECDSA key pair: G,R,E",
            "secFunImpl": "ECDSA Asymmetric Key Generation ECDSA Asymmetric Key Verification"
          },
          {
            "description": "Generate a keypair for a requested \u0027safe\u0027 domain paramete r",
            "indicator": "1",
            "inputs": "Curve",
            "name": "Safe primes key generation",
            "outputs": "Diffie_Hellm an key pair",
            "rolesSspAccess": "Crypto Officer - Diffie- Hellman key pair: G,R,E",
            "secFunImpl": "Safeprime Key Generation"
          },
          {
            "description": "Generate a shared secret",
            "indicator": "1",
            "inputs": "Received public key and possesse d private key",
            "name": "Diffie-Hellman shared secret computation",
            "outputs": "DH shared secret",
            "rolesSspAccess": "Crypto Officer - Diffie- Hellman shared",
            "secFunImpl": "FFC Shared Secret Computation"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "secret: G,R,W,E",
            "secFunImpl": ""
          },
          {
            "description": "Generate a shared secret",
            "indicator": "1",
            "inputs": "Received public key and possesse d private key",
            "name": "EC Diffie-Hellman shared secret computation",
            "outputs": "ECDH shared secret",
            "rolesSspAccess": "Crypto Officer - EC Diffie- Hellman shared secret: G,R,W,E",
            "secFunImpl": "ECC Shared Secret Computation"
          },
          {
            "description": "execute CASTs in table section 10.2",
            "indicator": "1",
            "inputs": "power",
            "name": "Self-test",
            "outputs": "pass/fail results",
            "rolesSspAccess": "Crypto Officer - HMAC key: E - AES key: E - AES key- wrappin g key: E - ECDSA key pair: E - RSA key pair: E - DRBG seed, internal state V value, and key: E - PBKDF derived key: E - KBKDF key derivati",
            "secFunImpl": "Unauthentica ted Symmetric Encryption and Decryption Authenticate d Symmetric Encryption and Decryption Random Number Generation ECDSA Asymmetric Key Generation ECDSA Asymmetric Key Verification ECDSA Digital Signature Generation ECDSA Digital Signature Verification CMAC"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "on key: E - KBKDF derived key: E - EC Diffie- Hellman shared secret: E - EC Diffie Hellman key pair: E - Diffie- Hellman shared secret: E - Diffie- Hellman key pair: E",
            "secFunImpl": "Message Authenticatio n HMAC Message Authenticatio n ECC Shared Secret Computation FFC Shared Secret Computation KBKDF Key Derivation with HMAC Key wrapping/ Key unwrapping RSA Asymmetric Key Generation RSA Digital Signature Generation RSA Digital Signature Verification Safeprime Key Generation Message Digest PBKDF Key Derivation KBKDF Key Derivation with CMAC"
          },
          {
            "description": "Return the module status",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show Status",
            "outputs": "Status output",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Return Module Base Name and Module Version Number",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show module version info",
            "outputs": "Module informatioi n",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "SSPs are zeroised when the system is powered down, when all resources of symmetri c crypto function context, all resources of hash context, all resources of Diffie- Hellman context for Diffie- Hellman and EC Diffie- Hellman,",
            "indicator": "1",
            "inputs": "N/A",
            "name": "Zeroization",
            "outputs": "N/A",
            "rolesSspAccess": "Crypto Officer - AES key: Z - AES key- wrappin g key: Z - HMAC key: Z - ECDSA key pair: Z - RSA key pair: Z - Entropy input string: Z - DRBG seed, internal state V value, and key: Z",
            "secFunImpl": "None"
          },
          {
            "description": "all resources of asymmetr ic crypto function context and all resources of key derivation function context are released",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- PBKDF derived key: Z - KBKDF key derivati on key: Z - PBKDF passwor d: Z - KBKDF key derivati on key: Z - Diffie- Hellman key pair: Z - EC Diffie Hellman key pair: Z - Diffie- Hellman shared secret: Z - EC Diffie- Hellman shared secret: Z",
            "secFunImpl": ""
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-GCM (A3424)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Authenticated decryption operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A3487)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Health test per SP800- 90ARev1 section 11.3",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES 128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Message authentication",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA-1 (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Message authentication",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-512 (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Message authentication",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-4) (A3426)",
            "condition": "RSA key pair generation.",
            "details": "Calculation and verification of a digital signature",
            "indicator": "Successful key generation",
            "testMethod": "PCT",
            "testProps": "SHA2-256 and respective keys",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-4) (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Signature Generation or Key Generation service request",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with 2048 bit key and SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Signature Verification or Key Generation service request",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with 2048 bit key and SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A3426)",
            "condition": "EC key pair generation.",
            "details": "Key generation",
            "indicator": "Successful key generation",
            "testMethod": "PCT",
            "testProps": "SHA2-256 and respective keys",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Signature Generation or Key Generation service request",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224 with SHA-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Signature Verification or Key Generation service request",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224 with SHA-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224 curve",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "MODP- 2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SP800- 108 (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "Counter mode using SHA-1, SHA-256, SHA-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1, SHA-256, SHA-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Safe Primes Key Generation (A3426)",
            "condition": "key gen",
            "details": "Section 5.6.2.1.4 of SP 800- 56Arev3",
            "indicator": "Successful key generation",
            "testMethod": "PCT",
            "testProps": "MODP- 2048",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "AES-CBC (A3423)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Encryption and decryption run separately",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A3423)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Encryption and decryption run separately",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS Testing Revision 2.0 (A3483)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Encryption",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CCM (A3424)",
            "condition": "Test runs at Power-on",
            "details": "Authenticated encryption and",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "",
            "condition": "before the integrity test",
            "details": "decryption run separately",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "AES-CMAC (A3426)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Authenticated encryption",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2- 512/256 (A3486)",
            "condition": "Test runs at Power-on before the integrity test",
            "details": "Message authentication",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2- 512/256",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "1) Pre- operational Software Integrity Test failure or 2) Conditional CAST failure 3) Conditional PCT failure",
            "description": "1) The HMAC-SHA- 256 value computed over the module did not match the pre- computed value or 2) The computed value in the invoked Conditional CAST did not match the known value or 3) The",
            "indicator": "1) Print statement \u0027FAILED: fipspost_post_integrity\u0027 to stdout or 2) Print statement \u0027FAILED:\u003cevent\u003e\u0027 to stdout (\u003cevent\u003e refers to any of the cryptographic functions listed Table - Conditional Self-Tests 3) Error code \u0027CCEC_GENERATE_KEY_CONSISTENCY\u0027 returned for ECDSA and EC Diffie- Hellman Error code \u0027CCRSA_GENERATE_KEY_CONSISTENCY\u0027 returned for RSA Error code \u0027CCDH_GENERATE_KEY_CONSISTENCY\u0027 returned for Diffie-Hellman",
            "name": "Error State",
            "recoveryMethod": "Power cycle the device which results in the module being reloaded into memory and reperforming the pre- operational software integrity test and the Conditional CASTs."
          },
          {
            "conditions": "",
            "description": "signature failed to verify successfully in the Conditional PCT. No cryptographic services are provided, and data output is prohibited",
            "indicator": "",
            "name": "",
            "recoveryMethod": ""
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Approved mode of operation is entered when the module utilizes the services that use the security functions listed in the Approved Algorithms Table and the Vendor Affirmed Algorithms Table.",
            "name": "Approved mode",
            "statusIndicator": "The dedicated API function returns a \u00271\u0027 from fips_allowed_mode() for block cipher functions and fips_allowed() for all other services to indicate the executed cryptographic algorithm was approved",
            "type": "Approved"
          },
          {
            "description": "Non-Approved mode of operation is entered when the module utilizes non- approved security functions in the Table Non-Approved Algorithms Not Allowed in the Approved Mode of Operation.",
            "name": "Non- Approved mode",
            "statusIndicator": "The dedicated API function returns a \u00270\u0027 from fips_allowed_mode() for block cipher functions and fips_allowed() for all other services to indicate the executed cryptographic algorithm was non- approved",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [
          {
            "caveat": "Allowed in Approved mode with no security claimed per IG 2.4.A Digest Size: 128-bit",
            "name": "MD5",
            "use": "Message Digest (used as part of the TLS key establishment scheme v1.0, v1.1 only)"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "ANSI X9.63 KDF",
            "use": "Hash based Key Derivation Function"
          },
          {
            "name": "Blowfish",
            "use": "Encryption / Decryption"
          },
          {
            "name": "CAST5",
            "use": "Encryption / Decryption Key Sizes: 40 to 128 bits in 8-bit increments"
          },
          {
            "name": "DES",
            "use": "Encryption / Decryption Key Size: 56-bits"
          },
          {
            "name": "Diffie-Hellman",
            "use": "Shared Secret Computation using key size \u003c 2048"
          },
          {
            "name": "ECDSA",
            "use": "Generation / Verification / SigGen / SigVer with curve P-192"
          },
          {
            "name": "ECDSA KeyGen",
            "use": "Key Pair Generation for compact point representation of points"
          },
          {
            "name": "EC Diffie-Hellman",
            "use": "Shared Secret Computation using curves \u003c P-224"
          },
          {
            "name": "EdDSA",
            "use": "Key Generation, Signature Generation, Signature Verification with Ed25519"
          },
          {
            "name": "ECDH",
            "use": "Key agreement with X25519"
          },
          {
            "name": "HKDF [SP800-56Crev2]",
            "use": "Key Derivation Function"
          },
          {
            "name": "Integrated Encryption Scheme on elliptic curves (ECIES)",
            "use": "Hybrid encryption scheme"
          },
          {
            "name": "MD2",
            "use": "Message Digest size: 128-bit"
          },
          {
            "name": "MD4",
            "use": "Message Digest size: 128-bit"
          },
          {
            "name": "MD5 (except in the TLS 1.0/1.1 context)",
            "use": "Message Digest size: 128-bit"
          },
          {
            "name": "OMAC (One-Key CBC MAC)",
            "use": "MAC generation / verification"
          },
          {
            "name": "RC2",
            "use": "Encryption / Decryption Key Sizes 8 to 1024-bits"
          },
          {
            "name": "RC4",
            "use": "Encryption / Decryption Key Sizes 8 to 4096-bits"
          },
          {
            "name": "RFC6637",
            "use": "Key Derivation Function"
          },
          {
            "name": "RIPEMD",
            "use": "Message Digest size: 160-bits"
          },
          {
            "name": "RSA KeyGen",
            "use": "ANSI X9.31 Key Pair Generation with Key Size \u003c 2048"
          },
          {
            "name": "RSA SigGen",
            "use": "PKCS#1 v1.5 and PSS; Signature Generation Key Size \u003c 2048"
          },
          {
            "name": "RSA SigVer",
            "use": "Signature Verification Key Size \u003c 1024"
          },
          {
            "name": "RSA Key Wrapping",
            "use": "OAEP, PKCS#1 v1.5 and -PSS schemes"
          },
          {
            "name": "Triple-DES [SP 800-67r2]",
            "use": "CBC, CTR, CFB64, ECB, CFB8, OFB"
          },
          {
            "name": "SHA-3",
            "use": "Message Digest"
          },
          {
            "name": "HPKE (Hybrid Public Key Encryption) [RFC9180]",
            "use": "Hybrid encryption scheme"
          },
          {
            "name": "Keccak",
            "use": "Message Digest"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "Triple-DES [SP 800- 67r2]",
            "description": "Execute Triple-DES mode encrypt or decrypt operation.",
            "name": "Triple-DES encryption / decryption",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA Key Wrapping",
            "description": "The CAST does not perform the full KTS, only the raw RSA encrypt/decrypt.",
            "name": "RSA Key Encapsulation",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA KeyGen",
            "description": "Generate a keypair with non-approved key sizes",
            "name": "RSA Key pair Generation",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA SigGen",
            "description": "Sign a message with non- approved private key",
            "name": "RSA Signature Generation",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA SigVer",
            "description": "Verify the signature of a message with a non- approved public key.",
            "name": "RSA Signature Verification",
            "role": "CO"
          },
          {
            "alg_accessed": "Diffie-Hellman",
            "description": "For key sizes \u003c 2048",
            "name": "Diffie Hellman Shared Secret Computation",
            "role": "CO"
          },
          {
            "alg_accessed": "EC Diffie-Hellman",
            "description": "For curve sizes \u003c P-224",
            "name": "EC Diffie Hellman Shared Secret Computation",
            "role": "CO"
          },
          {
            "alg_accessed": "ECDSA",
            "description": "For curve P-192",
            "name": "ECDSA key-pair generation , ECDSA key verification, ECDSA signature generation, ECDSA signature verification",
            "role": "CO"
          },
          {
            "alg_accessed": "ECDSA KeyGen",
            "description": "For compact point representation of points",
            "name": "ECDSA Key Pair Generation for compact point representation of points",
            "role": "CO"
          },
          {
            "alg_accessed": "EdDSA",
            "description": "Ed25519",
            "name": "EdDSA Key Generation, Signature Generation, Signature Verification",
            "role": "CO"
          },
          {
            "alg_accessed": "ECDH",
            "description": "X25519",
            "name": "ECDH Key Agreement",
            "role": "CO"
          },
          {
            "alg_accessed": "Integrated Encryption Scheme on elliptic curves (ECIES) HPKE (Hybrid Public Key Encryption) [RFC9180]",
            "description": "Encryption schemes that combine asymmetric and symmetric algorithms",
            "name": "Hybrid encryption scheme",
            "role": "CO"
          },
          {
            "alg_accessed": "ANSI X9.63 KDF",
            "description": "SHA-1 hash-based",
            "name": "ANSI X9.63 Key Derivation",
            "role": "CO"
          },
          {
            "alg_accessed": "HKDF [SP800- 56Crev2]",
            "description": "SHA-256 hash-based",
            "name": "SP800-56Crev2 Key Derivation (HKDF)",
            "role": "CO"
          },
          {
            "alg_accessed": "RFC6637",
            "description": "SHA hash based",
            "name": "RFC6637 Key Derivation",
            "role": "CO"
          },
          {
            "alg_accessed": "OMAC (One-Key CBC MAC)",
            "description": "One-Key CBC-MAC using 128-bit key",
            "name": "OMAC Message Authentication Code Generation and Verification",
            "role": "CO"
          },
          {
            "alg_accessed": "MD2 MD4 MD5 (except in the TLS 1.0/1.1 context) RIPEMD SHA-3 Keccak",
            "description": "Message digest generation using non-approved algorithms",
            "name": "Message digest generation",
            "role": "CO"
          },
          {
            "alg_accessed": "Blowfish CAST5 DES RC2 RC4",
            "description": "Symmetric encryption / decryption using non- approved algorithms",
            "name": "Symmetric encryption / decryption",
            "role": "CO"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "Data inputs/outputs are provided in the variables passed in the C language Application Programming Interfaces (APIs) and callable service invocations, generally through caller-supplied buffers",
            "logicalInterface": "Data Input Data Output",
            "physicalPort": "N/A"
          },
          {
            "data": "Control inputs which control the mode of the module are provided through dedicated parameters.",
            "logicalInterface": "Control Input",
            "physicalPort": "N/A"
          },
          {
            "data": "Status output is provided in return codes and through messages. Documentation for each API lists possible return codes. A complete list of all return codes returned by the C language APIs within the module is provided in the header files and the API documentation. Messages are also documented in the API documentation.",
            "logicalInterface": "Status Output",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto Officer",
            "operatorType": "CO",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A3486)",
            "details": "The HMAC-SHA2-256 value calculated at runtime is compared with the HMAC-SHA2- 256 value stored in the module, computed at compilation time.",
            "indicator": "Module successful execution",
            "testMethod": "Message Authentication",
            "testProps": "112-bit key",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Cryptographic module",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API input parameters",
            "sfiAlgo": "",
            "source": "Operating calling application (TOEPP)"
          },
          {
            "dest": "Operating calling application (TOEPP)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API output parameters",
            "sfiAlgo": "",
            "source": "Cryptographic module"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "SSPs are zeroised when the appropriate context object is destroyed",
            "method": "Context object destruction",
            "operatorId": "By calling the zeroization function cc_clear",
            "rationale": "Zeroization when structure is deallocated"
          },
          {
            "description": "SSPs are zeroised when the system is powered down",
            "method": "Power down",
            "operatorId": "Operator can initiate power down",
            "rationale": "SSPs are zeroised when the system is powered down"
          },
          {
            "description": "Intermediate keygen values are zeroized before the module returns from the key generation function.",
            "method": "Intermediate value zeroization",
            "operatorId": "N/A",
            "rationale": "Intermediate keygen values are zeroized before the module returns from the key generation function."
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "The module stores ephemeral SSPs in RAM provided by the operational environment. They are received for use or generated by the module only at the command of the calling application. The operating system protects all SSPs through the memory separation and protection mechanisms. No process other than the module itself can access the SSPs in its process\u0027 memory.",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "N/A",
            "integrityTest": "HMAC-SHA-256",
            "packageFileName": "corecrypto- 1608.60.11",
            "swFwVersion": "v13.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "iPad (5th generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A9",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad Pro 9.7-inch",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A9X",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad (7th generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A10 Fusion",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad Pro 10.5-inch",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A10X Fusion",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad mini (5th generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A12 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad Pro 11-inch (1st generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A12X Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad Pro 11-inch (2nd generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A12Z Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad (9th generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A13 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad Air (4th generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A14 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad mini (6th generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A15 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad Pro 11-inch (3rd generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple M Series M1",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPad Pro 11-inch (4th generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iPadOS 16",
            "paa_pai": "Yes",
            "processors": "Apple M Series M2",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPhone X",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A11 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPhone XS Max",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A12 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPhone 11 Pro",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A13 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPhone 12",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A14 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPhone 13 Pro Max",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A15 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "iPhone 14 Pro Max",
            "hypervisorHostOs": "NA",
            "operatingSystem": "iOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A16 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Apple Watch Series S4",
            "hypervisorHostOs": "NA",
            "operatingSystem": "watchOS 9",
            "paa_pai": "Yes",
            "processors": "Apple S Series S4",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Apple Watch Series S5",
            "hypervisorHostOs": "NA",
            "operatingSystem": "watchOS 9",
            "paa_pai": "Yes",
            "processors": "Apple S Series S5",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Apple Watch Series S6",
            "hypervisorHostOs": "NA",
            "operatingSystem": "watchOS 9",
            "paa_pai": "Yes",
            "processors": "Apple S Series S6",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Apple Watch Series S7",
            "hypervisorHostOs": "NA",
            "operatingSystem": "watchOS 9",
            "paa_pai": "Yes",
            "processors": "Apple S Series S7",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Apple Watch Series S8",
            "hypervisorHostOs": "NA",
            "operatingSystem": "watchOS 9",
            "paa_pai": "Yes",
            "processors": "Apple S Series S8",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Apple TV 4K",
            "hypervisorHostOs": "NA",
            "operatingSystem": "tvOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A10X Fusion",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Apple TV 4K (2nd generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "tvOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A12 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Apple TV 4K (3rd generation)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "tvOS 16",
            "paa_pai": "Yes",
            "processors": "Apple A Series A15 Bionic",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Apple Security Chip T2",
            "hypervisorHostOs": "NA",
            "operatingSystem": "T2OS 13",
            "paa_pai": "Yes",
            "processors": "Apple T Series T2",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "MacBook Pro (13- inch, M1, 2020)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "macOS 13 Ventura",
            "paa_pai": "Yes",
            "processors": "Apple M Series M1",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "MacBook Pro (16- inch, 2021)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "macOS 13 Ventura",
            "paa_pai": "Yes",
            "processors": "Apple M Series M1 Pro",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "MacBook Pro (16- inch, 2021)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "macOS 13 Ventura",
            "paa_pai": "Yes",
            "processors": "Apple M Series M1 Max",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "Mac Studio",
            "hypervisorHostOs": "NA",
            "operatingSystem": "macOS 13 Ventura",
            "paa_pai": "Yes",
            "processors": "Apple M Series M1 Ultra",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "MacBook Pro (13- inch, M2, 2020)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "macOS 13 Ventura",
            "paa_pai": "Yes",
            "processors": "Apple M Series M2",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "MacBook Pro (14- inch, 2023)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "macOS 13 Ventura",
            "paa_pai": "Yes",
            "processors": "Apple M Series M2 Pro",
            "version": "v13.0"
          },
          {
            "hardwarePlatform": "MacBook Pro (16- inch, 2023)",
            "hypervisorHostOs": "NA",
            "operatingSystem": "macOS 13 Ventura",
            "paa_pai": "Yes",
            "processors": "Apple M Series M2 Max",
            "version": "v13.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "RSA Key Generation:Modulus: 2048, 3072, 4096; Key strength: from 112 to 150-bits ECDSA Key Generation:P-224, P- 256, P-384, P-521; Key strength: from 112 to 256-bits Safe Prime Key Generation:Safe prime groups: MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Key strength: from 112 to 200-bits",
            "implName": "Apple corecrypto Module [Apple ARM, User, Software, SL1] (c_ltc)",
            "name": "Cryptographic Key Generation (CKG)",
            "reference": "FIPS 140-3 IG D.H. and [SP800- 133rev2] sections 4 and 5.1"
          },
          {
            "algoPropList": "RSA Key Generation:Modulus: 2048, 3072, 4096; Key strength: from 112 to 150-bits ECDSA Key Generation:P-224, P- 256, P-384, P-521; Key strength: from 112 to 256-bits Safe Prime Key Generation:MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192 Key strength: from 112 to 200-bits",
            "implName": "Apple corecrypto Module [Apple ARM, User, Software, SL1] (vng_ltc)",
            "name": "CKG",
            "reference": "FIPS 140-3 IG D.H. and [SP800- 133rev2] sections 4 and 5.1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "iPad Pro 12.9-inch",
            "operatingSystem": "iPadOS 16"
          },
          {
            "hardwarePlatform": "iPad (6th generation)",
            "operatingSystem": "iPadOS 16"
          },
          {
            "hardwarePlatform": "iPad Pro 12.9-inch (2nd generation)",
            "operatingSystem": "iPadOS 16"
          },
          {
            "hardwarePlatform": "iPad Air (3rd generation)",
            "operatingSystem": "iPadOS 16"
          },
          {
            "hardwarePlatform": "iPad (8th generation)",
            "operatingSystem": "iPadOS 16"
          },
          {
            "hardwarePlatform": "iPad Pro 12.9-inch (3rd generation)",
            "operatingSystem": "iPadOS 16"
          },
          {
            "hardwarePlatform": "iPad Pro 12.9-inch (4th generation)",
            "operatingSystem": "iPadOS 16"
          },
          {
            "hardwarePlatform": "iPad Pro 12.9-inch (5th generation)",
            "operatingSystem": "iPadOS 16"
          },
          {
            "hardwarePlatform": "iPad Pro 12.9-inch (6th generation)",
            "operatingSystem": "iPadOS 16"
          },
          {
            "hardwarePlatform": "iPhone 8",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 8 Plus",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone XS",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone XR",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 11",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 11 Pro Max",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone SE (2nd generation)",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 12 mini",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 12 Pro",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 12 Pro Max",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 13 mini",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 13",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 13 Pro",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "iPhone 14 Pro",
            "operatingSystem": "iOS 16"
          },
          {
            "hardwarePlatform": "Apple Watch SE",
            "operatingSystem": "watchOS 9"
          },
          {
            "hardwarePlatform": "Mac mini",
            "operatingSystem": "macOS 13 Ventura"
          },
          {
            "hardwarePlatform": "iMac (24-inch)",
            "operatingSystem": "macOS 13 Ventura"
          },
          {
            "hardwarePlatform": "MacBook Pro (14-inch, 2021)",
            "operatingSystem": "macOS 13 Ventura"
          },
          {
            "hardwarePlatform": "MacBook Air",
            "operatingSystem": "macOS 13 Ventura"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 5
          },
          "ECDH": {
            "ECDH": 4
          },
          "ECDSA": {
            "ECDSA": 82
          },
          "ECIES": {
            "ECIES": 2
          },
          "EdDSA": {
            "EdDSA": 3
          }
        },
        "FF": {
          "DH": {
            "DH": 1,
            "Diffie-Hellman": 17
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 4
        },
        "CCM": {
          "CCM": 2
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 2
        },
        "GCM": {
          "GCM": 8
        },
        "OFB": {
          "OFB": 2
        },
        "XTS": {
          "XTS": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 1
        },
        "IPsec": {
          "IPsec": 3
        },
        "TLS": {
          "TLS": {
            "TLS": 8,
            "TLS 1.2": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 3,
          "Key agreement": 1
        },
        "MAC": {
          "MAC": 16
        }
      },
      "device_model": {},
      "ecc_curve": {
        "Edwards": {
          "Ed25519": 2
        },
        "NIST": {
          "P-192": 2,
          "P-224": 26,
          "P-256": 8,
          "P-384": 20,
          "P-521": 12,
          "curve P-192": 2
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 2
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "# A3687": 1,
          "# C1223": 1,
          "AES key 128": 1,
          "AES-128": 1,
          "AES-256": 2,
          "AES128": 1,
          "AES192": 1,
          "AES256": 1,
          "DRBG 256": 1,
          "Diffie- Hellman, 1": 1,
          "HMAC SHA1": 1,
          "HMAC SHA224": 1,
          "HMAC SHA256": 1,
          "HMAC SHA384": 1,
          "HMAC SHA512": 1,
          "HMAC SHA512/256": 1,
          "HMAC- SHA-1": 1,
          "HMAC-256": 2,
          "HMAC-SHA- 1": 2,
          "HMAC-SHA- 256": 2,
          "HMAC-SHA-1": 14,
          "HMAC-SHA-256": 4,
          "HMAC-SHA1": 6,
          "HMAC-SHA224": 6,
          "HMAC-SHA256": 10,
          "HMAC-SHA384": 6,
          "HMAC-SHA512": 6,
          "HMAC-SHA512/256": 6,
          "PKCS#1": 10,
          "RSA 1": 1,
          "SHA-1": 12,
          "SHA-224": 3,
          "SHA-256": 6,
          "SHA-3": 3,
          "SHA-384": 1,
          "SHA-512": 3,
          "SHA1": 4,
          "SHA2- 256": 3,
          "SHA2- 384": 1,
          "SHA2- 512": 1,
          "SHA2-224": 7,
          "SHA2-256": 15,
          "SHA2-384": 7,
          "SHA2-512": 10,
          "SHA224": 4,
          "SHA256": 4,
          "SHA384": 4,
          "SHA512": 4
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2,
          "level 1": 1
        }
      },
      "hash_function": {
        "Keccak": {
          "Keccak": 2
        },
        "MD": {
          "MD4": {
            "MD4": 2
          },
          "MD5": {
            "MD5": 3
          }
        },
        "PBKDF": {
          "PBKDF": 35,
          "PBKDF2": 1
        },
        "RIPEMD": {
          "RIPEMD": 2
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 12,
            "SHA1": 4
          },
          "SHA2": {
            "SHA-224": 3,
            "SHA-256": 6,
            "SHA-384": 1,
            "SHA-512": 3,
            "SHA224": 4,
            "SHA256": 4,
            "SHA384": 4,
            "SHA512": 4
          },
          "SHA3": {
            "SHA-3": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {
        "curves": {
          "X25519": 2
        }
      },
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 36
        },
        "RNG": {
          "RBG": 3
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 15,
          "FIPS 180-4": 26,
          "FIPS 186-4": 32,
          "FIPS 197": 11,
          "FIPS 198": 6,
          "FIPS 198-1": 26,
          "FIPS PUB 140-3": 2,
          "FIPS140-3": 1,
          "FIPS180-4": 1,
          "FIPS186-4": 64,
          "FIPS197": 1,
          "FIPS198-1": 1,
          "FIPS202": 1
        },
        "ISO": {
          "ISO/IEC 19790:2012": 1
        },
        "NIST": {
          "NIST SP 800-140F": 1,
          "SP 800-108": 4,
          "SP 800-132": 5,
          "SP 800-140": 1,
          "SP 800-140A": 1,
          "SP 800-140C": 1,
          "SP 800-140D": 1,
          "SP 800-140E": 1,
          "SP 800-140F": 1,
          "SP 800-140x": 1,
          "SP 800-38": 1,
          "SP 800-38A": 44,
          "SP 800-38B": 3,
          "SP 800-38C": 7,
          "SP 800-38D": 7,
          "SP 800-38E": 7,
          "SP 800-38F": 4,
          "SP 800-56A": 6,
          "SP 800-90A": 6
        },
        "PKCS": {
          "PKCS#1": 5
        },
        "RFC": {
          "RFC 4106": 1,
          "RFC 5288": 1,
          "RFC3394": 1,
          "RFC5649": 1,
          "RFC6637": 3,
          "RFC9180": 3
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 37,
            "AES-": 1,
            "AES-128": 1,
            "AES-256": 2,
            "AES128": 1,
            "AES192": 1,
            "AES256": 1
          },
          "CAST": {
            "CAST": 24,
            "CAST5": 3
          },
          "RC": {
            "RC2": 2,
            "RC4": 1
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "Triple-DES": 4
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "CBC-MAC": 1,
            "CMAC": 13,
            "HMAC": 25,
            "HMAC-SHA-256": 2
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 2
          }
        }
      },
      "tee_name": {
        "IBM": {
          "SE": 2,
          "SSC": 3
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "AES-KWA3486",
        "HMAC-SHA2-256A3489",
        "AES-CMACA3486",
        "HMAC-SHA-1A3488",
        "AES-OFBA3486",
        "AES-GCMA3487",
        "ECDSA KeyVer (FIPS186-4)A3488",
        "AES-CTRA3487",
        "KAS-FFC-SSC Sp800-56Ar3A3486",
        "ECDSA SigVer (FIPS186-4)A3488",
        "KAS-ECC-SSC Sp800-56Ar3A3486",
        "SHA2-224A3488",
        "Safe Primes Key GenerationA3486",
        "AES-CFB8A3486",
        "AES-XTS Testing Revision 2.0A3486",
        "SHA-1A3488",
        "Counter DRBGA3487",
        "SHA2-384A3488",
        "ECDSA SigGen (FIPS186-4)A3488",
        "HMAC-SHA2-512A3488",
        "SHA2-512A3488",
        "HMAC-SHA2-512/256A3488",
        "SHA2-256A3489",
        "RSA SigGen (FIPS186-4)A3488",
        "HMAC-SHA2-224A3488",
        "KDF SP800-108A3488",
        "RSA KeyGen (FIPS186-4)A3488",
        "PBKDFA3488",
        "RSA SigVer (FIPS186-4)A3488",
        "AES-CFB128A3486",
        "AES-CCMA3487",
        "AES-ECBA3487",
        "SHA2-512/256A3488",
        "ECDSA KeyGen (FIPS186-4)A3488",
        "AES-CBCA3486",
        "HMAC-SHA2-384A3488"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A3427",
        "#A3484",
        "#A3488",
        "#A3486",
        "#A3423",
        "#A3425",
        "#A3485",
        "#A3429",
        "#A3487",
        "#A3424",
        "#A3489",
        "#A3428",
        "#A3426",
        "#A3483"
      ]
    },
    "policy_metadata": {
      "/Author": "scroux",
      "/CreationDate": "D:20250427093952-04\u002700\u0027",
      "/Creator": "PScript5.dll Version 5.2.2",
      "/ModDate": "D:20250427093952-04\u002700\u0027",
      "/Producer": "Acrobat Distiller 25.0 (Windows)",
      "/Title": "Microsoft Word - TID-11-1895-0000-FS-Apple_Inc.-250303-V3_sp140",
      "pdf_file_size_bytes": 314845,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 71
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "bc86e7d55a0cb02772ccc3bb0de2d52744900efa154903946e8fe4706afbcb52",
      "source_hash": "3d2666632e59e0631ce071085a4415cbf199d41b44edaf0eba284360cc047af5",
      "txt_hash": "bcbb167b35122c3892b5beb53c887994da364da8b061d445807dc8378a1364f2"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2025_181225_1202.pdf",
    "date_sunset": "2030-09-21",
    "description": "The Apple Cryptographic Module for Apple silicon user space environment.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Apple corecrypto Module v13.0 [Apple silicon, User, Software, SL1]",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-09-22",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Apple Inc.",
    "vendor_url": "http://www.apple.com"
  }
}