Classification: External © Quadient Technologies France This document is non-proprietary. It may be reproduced or transmitted only in its entirety without revision. Quadient Postal Security Device (PSD) Security Policy Valid from: 15-10-2020 Version No.: V 9.0 Classification: External Document name: Quadient PSD Security Policy Page 1/21 Contents 1 Introduction............................................................................................................................................2 2 Cryptographic Module Specification......................................................................................................2 3 Sensitive Security Parameters Management .........................................................................................7 4 Ports and Interfaces ............................................................................................................................ 11 5 Roles, Services and Authentication..................................................................................................... 12 6 Operational Environment.................................................................................................................... 15 7 Physical Security.................................................................................................................................. 16 8 Self-Tests ............................................................................................................................................. 17 9 Design Assurance................................................................................................................................. 18 10 Mitigation of Other Attacks.............................................................................................................. 18 11 Glossary ............................................................................................................................................ 19 12 Revision History................................................................................................................................ 20 Figures Figure 1 – Quadient Postal Security Device....................................................................................................2 Figure 2 – Quadient PSD Configuration..........................................................................................................3 Figure 3 – FIPS 140-2 Security Level...............................................................................................................3 Figure 4 – FIPS Approved Algorithms .............................................................................................................5 Figure 5 – FIPS Allowed Security Functions....................................................................................................6 Figure 6 – Non-Approved Security Functions.................................................................................................6 Figure 7 – Critical Security Parameters ..........................................................................................................7 Figure 8 – TLS v1.2 Handshake Protocol Critical Security Parameters...........................................................8 Figure 9 – TLS v1.2 Record Protocol Critical Security Parameters .................................................................8 Figure 10 – Public Security Parameters..........................................................................................................9 Figure 11 – Interfaces.................................................................................................................................. 11 Figure 12 – Approved Roles, Services, Operators ....................................................................................... 14 Figure 13 – Non-Approved Roles, Services, Operators ............................................................................... 15 Classification: External Document name: Quadient PSD Security Policy Page 2/21 1 Introduction This document forms a Cryptographic Module Security Policy for the Quadient Technologies France (former Neopost Technologies S.A.) Postal Security Device (PSD) under the terms of the FIPS 140-2 validation. This document contains a statement of the security rules under which the Quadient Technologies France (Quadient) PSD operates. 2 Cryptographic Module Specification 2.1 Quadient PSD Overview The Quadient Postal Security Device is a cryptographic module embedded within the postal franking machines. The Quadient PSD performs all franking machine’s cryptographic and postal security functions and protects the Critical Security Parameters (CSPs) and Postal Relevant Data from unauthorized access. The Quadient PSD (Figure 1) is a multi-chip embedded cryptographic module enclosed within a hard, opaque, plastic enclosure encapsulating the epoxy potted module which is wrapped in a tamper detection envelope with a tamper response mechanism. This enclosure constitutes the cryptographic module’s physical boundary. The Quadient PSD was designed to securely operate when voltage supplied to the module is between +5V and +17V and the environmental temperature is between -30°C and 84°C. Figure 1 – Quadient Postal Security Device Classification: External Document name: Quadient PSD Security Policy Page 3/21 2.2 Quadient PSD Configuration Quadient PSD (Cryptographic Module) Description Hardware P/N A0014227-B and A0014227-C Firmware P/N A0134483A Firmware Versions a30.08 NIST Approved Security Functions ECDSA (Cert. #517) A0038110A AES-CMAC (Cert. #A760) A0038111B SHS (Cert. #A730) A0038112B AES-CBC (Cert. #A728) A0038113B KDF (CVL) (Cert. #A761) A0038114B RSA (Cert. #A765) A0038115B DRBG (Cert. #1835) A0038116B HMAC (Cert. #A729) A0038118B DSA (Cert. #A767) A0136247A Figure 2 – Quadient PSD Configuration 2.3 FIPS Security Level Compliance The Quadient PSD is designed to meet the overall requirements applicable for Level 3 of FIPS 140-2. Security Requirements Level Cryptographic Module Specification 3 Cryptographic Module Ports and Interfaces 3 Roles, Services and Authentication 3 Finite State Model 3 Physical Security 3 + EFP/EFT Operational Environment N/A Cryptographic Key Management 3 EMI/EMC 3 Self-Tests 3 Design Assurance 3 Mitigation of Other Attacks 3 Figure 3 – FIPS 140-2 Security Level Classification: External Document name: Quadient PSD Security Policy Page 4/21 2.4 Security Industry Protocols The cryptographic module implements the TLS v1.2 protocol and uses only one cipher suite (TLS-DHE- RSA-WITH-AES-128-CBC-SHA256). The TLS protocol is composed of TLS Handshake protocol (used for mutual authentication and TLS pre-master secret establishment) and TLS Record protocol (used for application data confidentiality and integrity). No parts of this protocol, other than the KDF, have been tested by the CAVP and CMVP. 2.5 Modes of Operation The module supports both Approved and non-Approved modes of operation. When initialized (in manufacturing) for countries that utilize only Approved security functions, the module is said to be in an Approved mode of operation. The module returns an explicit indicator showing whether the module is in an Approved mode or non-Approved mode via the Get Status command (Read Status Data). This command returns either a 1 or 0 for Approved mode or non-Approved mode respectively. In order to change modes of operation the module must be initialized for a specific country (this occurs in manufacturing). Therefore, it is impossible to share CSPs between modes of operation. 2.5.1 Approved Security Functions The Quadient PSD supports the following FIPS Approved security functions in Approved Mode of Operation: CAVP Cert. Algorithm Standard Modes/Methods Key Length, Curves or Moduli Usage A728 AES CBC FIPS 197 CBC 128 Encryption/Decryption of:  CSPs for storage within the module  Data encryption/decryption using TLS v1.2 A760 AES CMAC FIPS 197 SP 800-38B AES 128 Indicia Authentication Vendor affirmed CKG SP 800- 133r2 The unmodified output of the DRBG is used for symmetric key and asymmetric seed generation A761 KDF (CVL) SP 800-135 SHA-256 TLS 1.2 KDF function 1835 CTR-DRBG SP 800-90A AES 128 Key generation Classification: External Document name: Quadient PSD Security Policy Page 5/21 CAVP Cert. Algorithm Standard Modes/Methods Key Length, Curves or Moduli Usage A767 DSA FIPS 186-4 KeyGen (2048, 224) Used for KAS-SSC 517 ECDSA FIPS 186-4 SHA-256 P-224 Key Generation, Digital Signature Generation, and Digital Signature Verification (all for Indicia Authentication) A729 HMAC-SHA-1, HMAC-SHA-256 FIPS 198-1 (Key Sizes Ranges Tested: KS