## FEITIAN Technologies Co., Ltd. FEITIAN ePass Token Cryptographic Module ## FIPS 140-3 Non-Proprietary Security Policy Document Version: 1.1.0 Date: January 16, 2026 ## Table of Contents | 1 - General ................................................................................................................................ | 5 | |------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------| | 1.1 Overview | .......................................................................................................................... 5 | | 1.2 Security Levels | ................................................................................................................. 5 | | 2 - Cryptographic Module Specification ..................................................................................... | 6 | | 2.1 Description | ....................................................................................................................... 6 | | 2.2 Tested and Vendor Affirmed Module Version and Identification ........................................ | 8 | | 2.3 Excluded Components ...................................................................................................... | 9 | | 2.4 Modes of Operation .......................................................................................................... | 9 | | 2.5 Algorithms | ........................................................................................................................ 9 | | 2.6 Security Function Implementations ..................................................................................12 | | | 2.7 Algorithm Specific Information .........................................................................................16 | | | 2.8 RBG and Entropy | ............................................................................................................16 | | 2.9 Key Generation................................................................................................................17 | | | 2.10 Key Establishment | .........................................................................................................17 | | 2.11 Industry Protocols | ..........................................................................................................17 | | 3 Cryptographic Module Interfaces............................................................................................18 | | | 3.1 Ports and Interfaces | ........................................................................................................18 | | 4 Roles, Services, and Authentication .......................................................................................19 | | | 4.1 Authentication Methods | ...................................................................................................19 | | 4.2 Roles | ...............................................................................................................................21 | | 4.3 Approved Services | ..........................................................................................................22 | | 4.4 Non-Approved Services | ...................................................................................................45 | | 4.5 External Software/Firmware Loaded ................................................................................45 | | | 5 Software/Firmware Security | ...................................................................................................46 | | 5.1 Integrity Techniques | ........................................................................................................46 | | 5.2 Initiate on Demand | ..........................................................................................................46 | | 6 Operational Environment........................................................................................................47 | | | 6.1 Operational Environment Type and Requirements ..........................................................47 | | | 7 Physical Security | ....................................................................................................................48 | | 7.1 Mechanisms and Actions Required..................................................................................48 | | | 7.2 EFP/EFT Information | .......................................................................................................48 | | 7.3 Hardness Testing Temperature Ranges | ..........................................................................49 | | 8 Non-Invasive Security | ............................................................................................................50 | | 8.1 Mitigation Techniques | ......................................................................................................50 | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 2 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | 9 Sensitive Security Parameters Management ..........................................................................51 | | |-----------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------| | 9.1 Storage Areas .................................................................................................................51 | | | 9.2 SSP Input-Output Methods ..............................................................................................51 | | | 9.3 SSP Zeroization Methods ................................................................................................52 | | | 9.4 SSPs ...............................................................................................................................53 | | | 9.5 Transitions | .......................................................................................................................72 | | 10 Self-Tests .............................................................................................................................73 | | | 10.1 Pre-Operational Self-Tests ............................................................................................73 | | | 10.2 Conditional Self-Tests ....................................................................................................73 | | | 10.3 Periodic Self-Test Information ........................................................................................76 | | | 10.4 Error States ...................................................................................................................79 | | | 10.5 Operator Initiation of Self-Tests .....................................................................................79 | | | 11 Life-Cycle Assurance ...........................................................................................................80 | | | 11.1 Installation, Initialization, and Startup Procedures ..........................................................80 | | | 11.2 Administrator Guidance .................................................................................................80 | | | 11.3 Non-Administrator Guidance ..........................................................................................80 | | | 11.4 Design and Rules ..........................................................................................................80 | | | 11.5 Maintenance Requirements ...........................................................................................81 | | | 11.6 End of Life .....................................................................................................................81 | | | 12 Mitigation of Other Attacks | ...................................................................................................82 | | References and Definitions | .......................................................................................................83 | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 3 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ### List of Tables | Table 1: Security Levels | ............................................................................................................. 5 | |--------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------| | Table 2: Tested Module Identification - Hardware ..................................................................... | 9 | | Table 3: Modes List and Description .......................................................................................... | 9 | | Table 4: Approved Algorithms | ...................................................................................................11 | | Table 5: Vendor-Affirmed Algorithms | ........................................................................................11 | | Table 6: Security Function Implementations ..............................................................................16 | | | Table 7: Entropy Certificates | .....................................................................................................17 | | Table 8: Entropy Sources | ..........................................................................................................17 | | Table 9: Ports and Interfaces | ....................................................................................................18 | | Table 10: Authentication Methods .............................................................................................20 | | | Table 11: Roles | .........................................................................................................................21 | | Table 12: Approved Services | ....................................................................................................45 | | Table 13: Mechanisms and Actions Required | ...........................................................................48 | | Table 14: EFP/EFT Information .................................................................................................48 | | | Table 15: Hardness Testing Temperatures | ...............................................................................49 | | Table 16: Storage Areas | ...........................................................................................................51 | | Table 17: SSP Input-Output Methods | ........................................................................................52 | | Table 18: SSP Zeroization Methods | ..........................................................................................52 | | Table 19: SSP Table 1 | ..............................................................................................................65 | | Table 20: SSP Table 2 | ..............................................................................................................71 | | Table 21: Pre-Operational Self-Tests | ........................................................................................73 | | Table 22: Conditional Self-Tests | ...............................................................................................76 | | Table 23: Pre-Operational Periodic Information .........................................................................76 | | | Table 24: Conditional Periodic Information | ................................................................................78 | | Table 25: Error States | ...............................................................................................................79 | | Table 26 References | .................................................................................................................83 | | Table 27 Acronyms and Definitions | ...........................................................................................84 | | List of Figures | | | Figure 1 - Module Boundary ...................................................................................................... | 6 | | Figure 2 - Block diagram ........................................................................................................... | 7 | | Figure 3 - Module Appearance | .................................................................................................. 8 | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 4 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 1 - General ### 1.1 Overview This document is the non-proprietary FIPS 140-3 Security Policy for the ePass token. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 1403 for an overall Security Level 3 module. ### 1.2 Security Levels The FIPS 140-3 security levels for the Module are as follows: | Section | Title | Security Level | |-----------|-----------------------------------------|------------------| | 1 | General | 3 | | 2 | Cryptographic module specification | 3 | | 3 | Cryptographic module interfaces | 3 | | 4 | Roles, services, and authentication | 3 | | 5 | Software/Firmware security | 3 | | 6 | Operational environment | N/A | | 7 | Physical security | 3 | | 8 | Non-invasive security | N/A | | 9 | Sensitive security parameter management | 3 | | 10 | Self-tests | 3 | | 11 | Life-cycle assurance | 3 | | 12 | Mitigation of other attacks | N/A | | | Overall Level | 3 | Table 1: Security Levels Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 5 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 2 - Cryptographic Module Specification This FEITIAN ePass token module, hereafter denoted as the Module. The Module supports multiple identity authentication system frameworks such as PKI/OTP/FIDO, among which PKI includes three applications: ePass2003/ePassPIV/ePassOpenPGP. The OTP functional unit complies with OATH standards. The PIV functional unit meets the specifications NIST.SP.800-73-4. The OpenPGP functional unit is an ISO Smart Card Operating Systems. ### 2.1 Description ###### Purpose and Use: The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated identity authentication product, the Module is intended to be used in E-mail encryption, system login, transaction protection, etc. Module Type : Hardware Module Embodiment : MultiChipEmbed ###### Cryptographic Boundary: The physical form of the Module is depicted in Figure 1. The Module is a multi-chip embedded embodiment. The Module is a USB token containing FEITIAN owned FTCOS, which is embedded in a HSC32K2 with PAA Integrated Circuit (IC) chip and has been developed to support FEITIAN USB token. The Module is designed to provide strong authentication and identification and to support network login, secure online transactions, digital signatures, and sensitive data protection. Figure 1 - Module Boundary Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 6 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Figure 2 - Block diagram Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 7 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Figure 3 - Module Appearance Model Description : There are two types, one without buttons and the other with buttons. In the above Figure 3, the top row (A2 models - Blue and Purple) do not come with buttons, they are only used for ePass2003 products. All other models (K9, K40, A4B, K49, K50 and K28) have a button which can be used for all functional units. ### 2.2 Tested and Vendor Affirmed Module Version and Identification The operator can correlate the module's name and versioning information with the CMVP validation record by following the instructions in the FEITIAN ePass Token Cryptographic Module Administrator Guidance, page 31, Section 5.8 Get Device Info, #7 get version info. ###### Tested Module Identification - Hardware: FEITIAN ePass Token cryptographic module is tested on the following operational environment. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 8 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Table 2: Tested Module Identification - Hardware | Model and/or Part Number | Hardware Version | Firmware Version | Processors | Features | |----------------------------|--------------------|--------------------|------------------|------------| | A2 | V1.2 | V1.3.02 | HSC32K2 with PAA | | | K9 | V1.0 | V1.3.02 | HSC32K2 with PAA | | | K40 | V1.0 | V1.3.02 | HSC32K2 with PAA | | | A4B | V1.0 | V1.3.02 | HSC32K2 with PAA | | | K49 | V1.0 | V1.3.02 | HSC32K2 with PAA | | | K50 | V1.0 | V1.3.02 | HSC32K2 with PAA | | | K28 | V1.0 | V1.3.02 | HSC32K2 with PAA | | ### 2.3 Excluded Components The module does not exclude any components. ### 2.4 Modes of Operation ###### Modes List and Description: Table 3: Modes List and Description | Mode Name | Description | Type | Status Indicator | |---------------|-------------------------------------------------------------------------------------------------|----------|--------------------| | Approved Mode | The module has only one mode of operation - the Approved mode, which is entered after power up. | Approved | LED on and blink | The module only supports Approved mode. IG 2.4.C scenario 2) is applied to the module, i.e. A static code(9000 or 00) indicating the completion of service. The successful completion of a service is an implicit indicator for the use of an approved service. ### 2.5 Algorithms ###### Approved Algorithms: The Module implements the Approved cryptographic algorithms listed the table below. | Algorithm | CAVP Cert | Properties | Reference | |-------------|-------------|-----------------------------------------------------------------|-------------| | AES-CBC | A4980 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A | | AES-CMAC | A4980 | Direction - Generation, Verification Key Length - 128, 192, 256 | SP 800-38B | FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Page 9 of 84 | Algorithm | CAVP Cert | Properties | Reference | |--------------------------|-------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------| | AES-ECB | A4980 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A | | AES-GCM | A4980 | Direction - Decrypt, Encrypt IV Generation Mode - 8.2.2 Key Length - 128, 192, 256 | SP 800-38D | | Counter DRBG | A4980 | Prediction Resistance - Yes Mode - AES-128 Derivation Function Enabled - Yes | SP 800-90A Rev. 1 | | ECDSA KeyGen (FIPS186-5) | A4980 | Curve - P-256, P-384, P-521 Secret Generation Mode - testing candidates | FIPS 186-5 | | ECDSA KeyVer (FIPS186-5) | A4980 | Curve - P-256, P-384, P-521 | FIPS 186-5 | | ECDSA SigGen (FIPS186-5) | A4980 | Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 Component - Yes | FIPS 186-5 | | ECDSA SigVer (FIPS186-5) | A4980 | Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 | FIPS 186-5 | | HMAC-SHA-1 | A4980 | Key Length - Key Length: 8-2048 Increment 8 | FIPS 198-1 | | HMAC-SHA2-256 | A4980 | Key Length - Key Length: 8-2048 Increment 8 | FIPS 198-1 | | KAS-ECC Sp800- 56Ar3 | A4980 | Domain Parameter Generation Methods - P-256 Function - Key Pair Generation Scheme - ephemeralUnified - KAS Role - Responder KDF Methods - twoStepKdf - Key Length - 256 | SP 800-56A Rev. 3 | | KDF SP800-108 | A4980 | KDF Mode - Counter Supported Lengths - Supported Lengths: 8-256 Increment 8 | SP 800-108 Rev. 1 | | RSA KeyGen (FIPS186-5) | A4980 | Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - crt | FIPS 186-5 | | RSA SigGen (FIPS186-5) | A4980 | Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5 | FIPS 186-5 | | RSA SigVer (FIPS186-5) | A4980 | Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5 | FIPS 186-5 | | SHA-1 | A4980 | Message Length - Message Length: 160, 0-65536 Increment 8 | FIPS 180-4 | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 10 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Table 4: Approved Algorithms | Algorithm | CAVP Cert | Properties | Reference | |-------------|-------------|-----------------------------------------------------------|-------------| | SHA2-256 | A4980 | Message Length - Message Length: 256, 0-65536 Increment 8 | FIPS 180-4 | | SHA2-384 | A4980 | Message Length - Message Length: 384, 0-65536 Increment 8 | FIPS 180-4 | | SHA2-512 | A4980 | Message Length - Message Length: 512, 0-65536 Increment 8 | FIPS 180-4 | ###### Vendor-Affirmed Algorithms: The Module implements the FIPS Vendor Affirmed cryptographic algorithms listed below. Table 5: Vendor-Affirmed Algorithms | Name | Properties | Implementation | Reference | |--------|------------------------------------|------------------|-----------------------------------------| | CKG1 | Key Type::Asymmetric and Symmetric | N/A | [133r2] section 4, example 1 and IG D.H | ###### Non-Approved, Allowed Algorithms: N/A for this module. ###### Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. ###### Non-Approved, Not Allowed Algorithms: N/A for this module. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 11 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ### 2.6 Security Function Implementations The SFI table shows the Security Function Implementations that the module implements: | Name | Type | Descriptio n | Properties | Algorith ms | |------------------|---------------------|----------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------| | RSA_GEN_KEY_PAIR | AsymKeyPa ir-KeyGen | Asymmetric Key-Pair Generation | Publications:Publicat ions: [FIPS 186-5], [SP800-90A], [SP800-133r1], [IG C.E] | RSA KeyGen (FIPS186 -5): (A4980) Counter DRBG: (A4980) CKG1: () Key Type:: Symmetri c | | ECC_GEN_KEY_PAIR | AsymKeyPa ir-KeyGen | Asymmetric Key-Pair Generation | Publications:[FIPS 186-5], [SP800-90A], [SP800-133r1], [IG C.A] | ECDSA KeyGen (FIPS186 -5): (A4980) Counter DRBG: (A4980) CKG1: () Key Type:: Symmetri c | | AES_KEY_GEN | CKG | Symmetric Key Generation Sections 4 and 6.1 Direct symmetric key generation using unmodified DRBG output | Publications:[SP800- 90A], [IG D.H], [FIPS 197] | AES- CBC: (A4980) Size: 128 AES- GCM: (A4980) Size: 128 AES- ECB: (A4980) Size: 128 Counter DRBG: (A4980) CKG1: () Key | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 12 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Type | Descriptio n | Properties | Algorith ms | |----------------|----------------|--------------------------------------|------------------------------------------------------|-------------------------------------------------------------------------------------------| | | | | | Type:: Symmetri c | | SESSIONKEY_GEN | KBKDF | Symmetric Key Generation using KBKDF | Publications:[SP800- 108r1], [SP800-38B], [FIPS 197] | AES- CMAC: (A4980) Size: 128 KDF SP800- 108: (A4980) Size: 128 | | RSA_SIG_GEN | DigSig- SigGen | Digital Signature Generation | Publications:[FIPS 186-5], [SP800- 133r1], [IG C.E] | RSA SigGen (FIPS186 -5): (A4980) SHA2- 256: (A4980) SHA2- 384: (A4980) SHA2- 512: (A4980) | | RSA_SIG_VER | DigSig- SigVer | Signature Verification | Publications:[FIPS 186-5], [IG C.E] | RSA SigVer (FIPS186 -5): (A4980) SHA2- 256: (A4980) SHA2- 384: (A4980) SHA2- 512: (A4980) | | ECC_SIG_GEN | DigSig- SigGen | Digital Signature Generation | Publications:[FIPS 186-5], [SP800- 133r1], [IG C.A] | ECDSA SigGen (FIPS186 -5): (A4980) SHA2- 256: (A4980) | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 13 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Type | Descriptio n | Properties | Algorith ms | |--------------------------|---------------------|----------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------| | | | | | SHA2- 384: (A4980) SHA2- 512: (A4980) | | ECC_SIG_VER | DigSig- SigVer | Signature Verification | Publications:[FIPS 186-5], [IG C.A] | ECDSA SigVer (FIPS186 -5): (A4980) SHA2- 256: (A4980) SHA2- 384: (A4980) SHA2- 512: (A4980) | | ECC_KEY_VER | AsymKeyPa ir-KeyVer | Check the validity of the public key | Publications:[FIPS 186-5], [IG C.A] | ECDSA KeyVer (FIPS186 -5): (A4980) | | DRBG_GEN | DRBG | Random Number Generation | Publications:[SP800- 90A], [IG D.L] | Counter DRBG: (A4980) | | ENT_GEN | ENT-ESV | Entropy Source | Publications:[SP800- 90B], [IG 9.3.A], [IG D.J] [IG D.O] | | | SHAREDSECRETKEY_GE N_KAS | KAS-Full | Key Agreement Shared Secret Calculation [56Ar3] Key Derivation KDA [56Cr2] | IG:D.F Scenario 2, path 2, end-to-end Caveat:Key establishment methodology provides 128 bits of security strength Key confirmation:No Key derivation:KDA (tested as part KAS certificate) | KAS- ECC Sp800- 56Ar3: (A4980) | | AES_ENC_AUTH | BC- AuthEncrypt | Block Cipher | Publications:[FIPS 197] | AES- CMAC: (A4980) Sizes: 128 AES- | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 14 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Type | Descriptio n | Properties | Algorith ms | |-----------------|----------------------|------------------------------------|------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------| | | | | | GCM: (A4980) Size: 128 | | AES_ENC | BC- UnAuthEncr ypt | Block Cipher | Publications:[FIPS 197] | AES- CBC: (A4980) AES- ECB: (A4980) | | AES_DEC_AUTH | BC- AuthDecrypt | Block Cipher | Publications:[FIPS 197] | AES- CMAC: (A4980) Size: 128 AES- GCM: (A4980) Size: 128 | | AES_DEC | BC- UnAuthDecr ypt | Block Cipher | Publications:[FIPS 197] | AES- CBC: (A4980) AES- ECB: (A4980) | | HMAC_GEN | MAC | Message Authenticati on Generation | Publications:[FIPS19 8-1] [IG C.B] | HMAC- SHA-1: (A4980) HMAC- SHA2- 256: (A4980) SHA-1: (A4980) SHA2- 256: (A4980) | | KTS_SCP03_WRAP | KTS- Unwrap | used as SCP03 | Standard:SP 800- 38F IG D.G:Approved Caveat:Key establishment methodology provides 128 bits of security strength | AES- CBC: (A4980) Sizes: 128 AES- CMAC: (A4980) Sizes: | | KTS_AESGCM_WRAP | KTS- Unwrap KTS-Wrap | SP800-38D Based on IG D.G | Standard:SP 800- 38F IG D.G:Approved | 128 AES- GCM: (A4980) | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 15 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Type | Descriptio n | Properties | Algorith ms | |---------------|----------------------|------------------------------|------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------| | | | | Caveat:Key establishment methodology provides 128 bits of security strength | Sizes: 128 | | KTS_CTAP_WRAP | KTS- Unwrap KTS-Wrap | Key Wrapping Based on IG D.G | Standard:SP 800- 38F IG D.G:Approved Caveat:Key establishment methodology provides 128 bits of security strength | AES- CBC: (A4980) Sizes: 128 HMAC- SHA2- 256: (A4980) | | SHA_CAL | SHA | Secure Hash Standard | Publications: [FIPS 180-4], [IG C.B] | SHA2- 256: (A4980) SHA2- 384: (A4980) SHA2- 512: (A4980) | Table 6: Security Function Implementations ### 2.7 Algorithm Specific Information ###### AES GCM IV Uniqueness ###### FIPS140-3 IG C.H, Option 2 The IV is generated internally at its entirety randomly. The generation uses an Approved DRBG (Cert. #A4980) that is internal to the module's boundary. The IV length shall be at least 96 bits (per SP 800-38D). KAS [56Ar3] - Per [IG] D.F Scenario 2 path (2), compliant key agreement scheme where testing is performed end-to-end for the shared secret computation and a KDF compliant with HKDF (2step KDF). The Module obtains the [FIPS140-3_IG] D.F required key agreement assurances [SP800-56Ar3] in accordance with Section 5.6.2. ### 2.8 RBG and Entropy Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 16 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). The scenario 1(a) in IG 9.3.A is applied to the module, the security strength of the DRBG seeded by the entropy source is 128-bit. According to table 4 of the ESV Public Use Document, to reach 128 bits of strength, at least 581 bits of random nonce are needed to seed the DRBG. A 640-bit nonce is used in the module, so the DRBG entropy strength is 128 bits. Table 7: Entropy Certificates | Cert Number | Vendor Name | |---------------|--------------------------------| | E134 | Feitian Technologies Co., Ltd. | The Module uses the following entropy sources: Table 8: Entropy Sources | Name | Type | Operational Environment | Sample Size | Entropy per Sample | Conditioning Component | |---------|----------|---------------------------|---------------|----------------------|--------------------------| | HSEC_ES | Physical | HSEC HSC | 1 bit | 0.3308 | N/A | ### 2.9 Key Generation For Key Generation, see Section 2.5 and Section 2.6 above. ### 2.10 Key Establishment ###### Key Agreement Information For Key Agreement, see Section 2.5 and Section 2.6 above. ###### Key Transport Information For Key Transport, see Section 2.5 and Section 2.6 above. ### 2.11 Industry Protocols The module does not support any industry protocols that would be of interest to this standard. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 17 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 3 Cryptographic Module Interfaces ### 3.1 Ports and Interfaces The Module's ports and associated FIPS defined logical interface categories are listed below. Table 9: Ports and Interfaces | Physical Port | Logical Interface(s) | Data That Passes | |---------------------|----------------------------------------------------|-------------------------------------------------------| | Power Supply 2 Pins | Power | Vcc Vdd 1.62-5.5V | | Touch Button 1 Pin | Control Input | Physical input | | LED 1 Pin | Status Output | Physical output | | USB(D+/D-) 2 Pins | Data Input Data Output Control Input Status Output | Primary physical interface (USB) for all service data | Note: The module does not support Control Output. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 18 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 4 Roles, Services, and Authentication ### 4.1 Authentication Methods | Method Name | Description | Security Mechanism | Strength Each Attempt | Strength per Minute | |-------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Authentication_PIN | A role is authenticated to the Module console with a PIN mechanism The PIN must be to changed by the CO after first authentication with default data. The Module enforced a minimum size of 8 ASCII characters. The number of incorrect attempts for PIN is 3-15, which can be set to a maximum of 15 times and a minimum of 3 times. | Memorized Secrets | PIN8-63 characters PIN, including numbers, letters, and special characters.Therefore, the probability of successful attempt is 1/95^8 | Each authentication attempt takes approximately 60 ms which allows a maximum of 15 attempts per minute. Therefore, the probability of successfully authenticating to the module within one minute through random attempts is 15/95^8 | | Authentication_ AuthKey | The identity is authenticated to the module with a challenge- response mechanism (Cert. #A4980). The entity gets challenge from the module then encrypts it resulting in cryptogram | AES-ECB (A4980) | 128-bit AES-ECB Key Challenge-Response A minimum 16 byte (128 bit) binary string has a probability that a random attempt will succeed or a false acceptance will occur of 1/2^128. | Each authentication attempt takes approximately 60 ms which allows a maximum of 15 attempts per minute. Therefore, the probability of successfully authenticating to the module | FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 19 of 84 Table 10: Authentication Methods | Method Name | Description | Security | Strength Each | Strength per Minute | |---------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------|-----------------|---------------------------------------------------------| | | using Auth key. The cryptogram is sent back and decrypted in the module using same key, then the module check if the result is matched with original challenge. The Auth key MUST be changed to specific value for each module by the CO after first authentication with default data. The Auth key is generally a random number automatically generated by HSM. The number of incorrect attempts for Auth key is 3- 15, which can be set to a maximum of 15 times and a minimum of 3 times. | Mechanism | Attempt | within one minute through random attempts is 15/2^128 . | All authentication states are all stored in RAM, so they are cleared automatically once the module is powered down. ###### Note: Authentication-PIN is an abstract noun that includes the PIN of ePass2003 unit, PIN/PUK of PIV unit, PIN of FIDO unit, AccessiCode of OTP unit, PGP User PIN(PW1)/ PGP Admin PIN(PW3) of OpenPGP unit. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 20 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Authentication-AuthKey is an abstract noun that includes the Device authenticate key of a universal service unit, the External Auth Key of an ePass2003 unit, and the PIV Authentication Key of a PIV unit. ### 4.2 Roles The Module supports four distinct operator roles, User, Admin, Cryptographic Officer (CO) and Unauth. The CO role is responsible for device authentication, resetting applications and other roles' authentication data (User PINs, etc). The Admin role is responsible for configuring SSPs and managing User identities (such as unblock a User identity in the PIV application). The User role is responsible for performing cryptographic operations to utilize the module as an authenticator. The unauthenticated role can only access some non-operational SSP services, Such as Select functional unit, get a challenge, read non-security relevant information, self-tests, etc. The Module does not support a maintenance role. The Module does not support concurrent operators. The Roles Table below lists all operator roles supported by the Module. | Name | Type | Operator Type | Authentication Methods | |--------|----------|-----------------|--------------------------------------------| | CO | Identity | Crypto Officer | Authentication_ AuthKey | | Admin | Identity | User | Authentication_PIN Authentication_ AuthKey | | User | Identity | User | Authentication_PIN | | UnAuth | Role | Unauthenticated | None | Table 11: Roles Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 21 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ### 4.3 Approved Services All approved services implemented by the Module are listed in the table below: The SSPs modes of access shown in the table below are defined as: - G = Generate: The Module generates or derives the SSP. - R = Read: The SSP is read from the Module (e.g., the SSP is output). - W = Write: The SSP is updated, imported, or written to the Module (SSP is input). - E = Execute: The Module uses the SSP in performing a cryptographic operation. - Z = Zeroize: The Module zeroizes the SSP | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |----------------------|----------------------------------------------------------------------------------------------|-----------------------|------------------------------------|--------------------------------|----------------------|---------------------------------------------------------------| | SELECT | Select functional unit | 9000 or error statu s | Comman d with AID | FCI(File Control Informatio n) | None | Unauthen ticated - KSenc: Z - KSmac: Z | | Get Device Info | Get device information content including versioning information and show status | 9000 or error statu s | Comman d without input paramete r | Device Info | None | Unauthen ticated | | Get Challenge | Request random data that will be used as a challenge within the Device Authenticat e service | 9000 or error statu s | Comman d with expected data length | random value | DRBG_GEN ENT_GEN | Unauthen ticated - DRBG V: G,Z - DRBG Seed: G - DRBG Key: G,Z | | Device Authenticat e | Request administrat or privileges | 9000 or error statu s | Kid and cipher text | N/A | AES_DEC_AUTH | CO - Device authentic ate key: E | | Update key | Change Device authenticat e key, INIT_KEYe nc and | 9000 or error statu s | cipher text | N/A | AES_DEC | CO - KSenc: E - KSmac: E - Device authentic | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 22 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |---------------------------|------------------------------------------------------------------------------------------------------------|-----------------------|-----------------------------------|-------------|----------------------|--------------------------------------------------------------------------------------------------------------------------------| | | INIT_KEY mac | | | | | ate key: W,E,Z - INIT_KEY enc: W,Z - INIT_KEY mac: W,Z | | GP Initialize Update | Create Secure Channel Session | 9000 or error statu s | Host random Card random | cipher text | SESSIONKEY_GEN | Admin - INIT_KEY enc: E - INIT_KEY mac: E - KSenc: G - KSmac: G User - INIT_KEY enc: E - INIT_KEY mac: E - KSenc: G - KSmac: G | | GP External Authenticat e | This service may also be used to both authenticat e and initiate a secure session with an external entity. | 9000 or error statu s | cipher text | N/A | SESSIONKEY_GEN | Admin - KSenc: E - KSmac: E User - KSenc: E - KSmac: E | | Terminate token | The token into terminate state. | 9000 or error statu s | Comman d without input paramete r | N/A | None | CO - DRBG- EI: Z - DRBG V: Z | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 23 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio | Indic | Inputs | Outputs | Security Functions | SSP | |--------|--------------|---------|----------|-----------|----------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | n | ator | | | | Access - DRBG Key: Z - Managing Key: Z - Device authentic ate key: Z - INIT_KEY enc: Z - INIT_KEY mac: Z - KSenc: Z - KSmac: Z - AES- GCM Key: Z - FIDO Device ECDSA Private Key: Z - FIDO Device ECDSA Public Key: Z - FIDO User ECDSA Private Key: Z - FIDO User ECDSA Public Key: Z - FIDO Agreeme nt ECC Private Key: Z - FIDO Agreeme | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 24 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio | Indic | Inputs | Outputs | Security Functions | SSP Access | |--------|--------------|---------|----------|-----------|----------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | n | ator | | | | nt ECC Public Key: Z - FIDO Agreeme nt sharedSe cret: Z - FIDO SharedSe cret AES Key: Z - FIDO SharedSe cret HMAC Key: Z - FIDO PinUvAut hToken: Z - FIDO PIN: Z - PIV Authentic ation Key: Z - PIV ECC Signature Private Key: Z - PIV ECC verificatio n Public Key: Z - PIV RSA Signature Private Key: Z - PIV RSA verificatio n Public Key: Z - PIV User PIN: Z - PIV PUK PIN: Z - 2003 Internal | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 25 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic | Inputs | Outputs | Security Functions | SSP | |--------|----------------|---------|----------|-----------|----------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | | ator | | | | Access Auth Key: Z - 2003 External Auth Key: Z - 2003 PIN: Z - 2003 PSO calculatio n key: Z - 2003 Unblock PIN: Z - 2003 RSA Private Key: Z - 2003 RSA Public Key: Z - 2003 ECDSA Private Key: Z - 2003 ECDSA Public Key: Z - OTP HMAC Seed Key: Z - OTP AccessCo de: Z - PGP Admin PIN(PW3) : Z - PGP User PIN(PW1) : Z - PGP Resetting | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 26 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |------------------------------------|------------------------------------------------------------------------------------------------------------|-----------------------|-----------------------------------|-----------------|----------------------|--------------------------------------------------------------------------------------------------------------------------------------------------| | | | | | | | Code: Z - PGP Signature Private Key: Z - PGP Verificatio n Public Key: Z - External Agreeme nt ECC Public Key: Z - DRBG Seed: Z - AES- GCM IV: Z | | Manage Security Environme nt (MSE) | Prepares the Module for the subsequent commands, Perform Security Operation. | 9000 or error statu s | Comman d without input paramete r | N/A | None | User Admin | | Hash | Performs a hash using SHA-256, SHA-384, or SHA- 512. | 9000 or error statu s | message | Hash value | SHA_CAL | Unauthen ticated | | Read Binary | Allows read access to a binary file. A binary file is a file whose content is a sequential string of bits. | 9000 or error statu s | Comman d with file info | Binary database | None | Admin User | | Update Binary | Allows write access to a binary file. | 9000 or error statu s | Binary data | N/A | None | Admin User | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 27 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------|-------------------------|-------------|----------------------|--------------------------------------------------------------------| | Read Record | Allows read access to a record. A record is a type of data storage structure as defined within ISO 7816. Records are stored in files. | 9000 or error statu s | Comman d With file info | Record data | None | Admin User | | Update Record | Allows write access to a record | 9000 or error statu s | Record data | N/A | None | Admin User | | Append Record | Allows a record to be append | 9000 or error statu s | Record data | N/A | None | Admin User | | Internal Authenticat e | Authenticat e the cryptograp hic module by an external entity NOTE: In order for this service to be utilized, the external entity must have privileged access to the referenced key. | 9000 or error statu s | Random data | cipher text | AES_ENC | Admin - 2003 Internal Auth Key: E User - 2003 Internal Auth Key: E | | External Authenticat e | Authenticat es an external entity by the | 9000 or error statu s | cipher text | N/A | AES_DEC | Admin - 2003 External Auth Key: E | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Page 28 of 84 | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |-----------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------|------------------------|-----------|----------------------|----------------------------------------------------------------------------------------| | | cryptograp hic module. NOTE: Prerequisit e to this service is the use of Get Challenge service. The key as referenced within the service call exists under the current file | | | | | User - 2003 External Auth Key: E | | Verify PIN | Provides PIN verification. | 9000 or error statu s | PIN data | N/A | KTS_SCP03_WRA P | Admin - 2003 PIN: E - KSenc: E - KSmac: E User - KSenc: E - KSmac: E - 2003 PIN: E | | Change Reference Data | Modify the PIN | 9000 or error statu s | PIN and new PIN data | N/A | KTS_SCP03_WRA P | Admin - 2003 PIN: W,E - KSenc: E - KSmac: E User - 2003 PIN: W,E - KSenc: E - KSmac: E | | Reset Retry Counter | Resets the retry counter | 9000 or error | Comman d without input | N/A | KTS_SCP03_WRA P | User - KSenc: E | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 29 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |-------------------------------|-----------------------------------|-----------------------|-----------------------------------|-----------|-------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | | statu s | paramete r | | | - KSmac: E Admin - KSenc: E - KSmac: | | Generate Asymmetri c Key Pair | Generates an Asymmetric key pair. | 9000 or error statu s | Comman d without input paramete r | N/A | RSA_GEN_KEY_P AIR ECC_GEN_KEY_P AIR | E Admin - DRBG- EI: G,E - 2003 RSA Private Key: G - 2003 RSA Public Key: G - 2003 ECDSA Private Key: G - 2003 ECDSA Public Key: G - DRBG Seed: G,E User - DRBG- EI: G,E - 2003 RSA Private Key: G - 2003 RSA Public Key: G - 2003 ECDSA Private Key: G - 2003 ECDSA Public Key: G | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 30 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |--------------------------|--------------------------------------------------------------------|-----------------------|---------------------|-------------|-------------------------------------|---------------------------------------------------------------------------------------------------------------------| | | | | | | | - DRBG Seed: G,E | | Encrypt | Performs an encrypt operation using an Approved security function. | 9000 or error statu s | Kid and plain text | cipher text | AES_ENC | Admin - 2003 PSO calculatio n key: E - Managing Key: E User - 2003 PSO calculatio n key: E - Managing | | Decrypt | Performs a decrypt operation. | 9000 or error statu s | Kid and cipher text | plain text | AES_DEC | Key: E Admin - 2003 PSO calculatio n key: E - Managing Key: E User - 2003 PSO calculatio n key: E - Managing Key: E | | Verify Digital Signature | Verifies a digital signature using RSA PKCS#1 or ECDSA | 9000 or error statu s | Signature and kid | N/A | RSA_SIG_VER ECC_SIG_VER ECC_KEY_VER | Admin - 2003 RSA Public Key: E - 2003 ECDSA Public Key: E User - 2003 RSA Public | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 31 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |---------------------------------|----------------------------------------------------------|-----------------------|-------------------------|-------------|-------------------------|--------------------------------------------------------------------------------------------------------------------------------------| | Generate Digital Signature | Generates a digital signature using RSA PKCS#1 or ECDSA. | 9000 or error statu s | message and kid | Signature | RSA_SIG_GEN ECC_SIG_GEN | Public Key: E Admin - 2003 RSA Private Key: E - 2003 ECDSA Private Key: E User - 2003 RSA Private Key: E - 2003 ECDSA Private Key: E | | Verify Cryptograp hic Checksum | Performs AES CMAC verification. | 9000 or error statu s | cipher text | N/A | AES_ENC_AUTH | Admin - 2003 PSO calculatio n key: E User - 2003 PSO calculatio n key: E | | Compute Cryptograp hic Checksum | Compute AES CMAC. | 9000 or error statu s | plain text | cipher text | AES_ENC_AUTH | Admin - 2003 PSO calculatio n key: E User - 2003 PSO calculatio n key: E | | Create File | Create a file. | 9000 or error statu s | Comman d with file info | N/A | None | Admin | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Page 32 of 84 | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |----------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------|----------------------------------|-----------|----------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Delete File | Delete a File. | 9000 or error statu s | Comman d with file info | N/A | None | Admin - 2003 Internal Auth Key: Z - 2003 External Auth Key: Z - 2003 PIN: Z - 2003 Unblock PIN: Z - 2003 RSA Private Key: Z - 2003 RSA Public Key: Z - 2003 ECDSA Private Key: Z - 2003 ECDSA | | Install Secret | This service is used to enter AES keys, and PINs. SSPs which may be entered are as follows: * Internal Auth Key * External Auth Key * Symmetric Key * PIN | 9000 or error statu s | Encrypte d Symmetri c Key or pin | N/A | KTS_SCP03_WRA P | Key: Z Admin - 2003 Internal Auth Key: W - 2003 External Auth Key: W - 2003 PSO calculatio n key: W - KSenc: E - KSmac: E - 2003 | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 33 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |-----------------|-----------------------------------------------------------------------|-----------------------|-------------------------------------------------|--------------------------------------|-------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------| | | | | | | | PIN: W - 2003 Unblock PIN: W | | Get File List | Allows the reading of the FID list of child files of the current file | 9000 or error statu s | Comman d with file | File info | None | Admin User | | Read Public Key | Allows the output of a public key. | 9000 or error statu s | Comman d with key info | RSA/ECC Public Key | None | Admin - 2003 RSA Public Key: R - 2003 ECDSA Public Key: R User - 2003 RSA Public Key: R - 2003 ECDSA Public | | Make Credential | This service is used to generate a new credential in the module | 00 or error statu s | Encrypte d Device ECDSA Private Key and message | Credentic alID and X.509 certificate | ECC_GEN_KEY_P AIR ECC_SIG_GEN AES_ENC_AUTH KTS_AESGCM_WR AP | Key: R User - DRBG- EI: G,E - DRBG V: G,E - AES- GCM Key: E - FIDO Device ECDSA Private Key: E - FIDO User ECDSA Private Key: G,R,W - FIDO | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 34 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |----------------------|---------------------------------------------------------------|-----------------------|-----------------------------------------------|-----------|-------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------| | | | | | | | Device ECDSA Public Key: R - AES- GCM IV: E - DRBG Seed: G,E - DRBG Key: G,E - FIDO User ECDSA Public Key: G,R User | | Get Attestation | This service is using Registratio n's credential to signature | 00 or error statu s | Encrypte d User ECDSA Private Key and message | Signature | ECC_SIG_GEN ECC_SIG_VER AES_DEC_AUTH KTS_AESGCM_WR AP | E - AES- GCM IV: E - DRBG Seed: G,E - DRBG Key: G,E - FIDO User ECDSA Private Key: E - FIDO User ECDSA | | Get Next Attestation | The client calls this service when the Attestationr | OK or error statu s00 | Comman d without input paramete r | Signature | ECC_SIG_GEN | Key: E User - DRBG- EI: G,E - DRBG V: G,E | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 35 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |-----------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------|-----------------------------------|-----------------|--------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | esponse contains the number of credentials member and the number of credentials | or error statu s | | | | - AES- GCM Key: E - DRBG Seed: G,E - DRBG Key: G,E | | Get Information | Device Information | 00 or error statu s | Comman d without input paramete r | Version | None | Unauthen ticated | | PIN Service | This service is used by the platform to establish the sharedSecr et key, setting a new user PIN, changing existing user PIN, and getting User PinUvAuth Token from the module | 00 or error statu s | PIN | PinUvAut hToken | ECC_GEN_KEY_P AIR AES_KEY_GEN ECC_KEY_VER SHAREDSECRETK EY_GEN_KAS AES_ENC_AUTH HMAC_GEN KTS_CTAP_WRAP | User - FIDO PIN: W,E - FIDO PinUvAut hToken: G,R,E - FIDO SharedSe cret AES Key: G,E - FIDO SharedSe cret HMAC Key: G,E - FIDO Agreeme nt sharedSe cret: G,E - FIDO Agreeme nt ECC Public Key: G,R - External Agreeme nt ECC Public Key: W,E - | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 36 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |------------------------|-------------------------|---------------------|-----------------------------------|-----------|--------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | | | | | | Managing Key: G | | FIDO Reset | Zeroization | 00 or error statu s | Comman d without input paramete r | N/A | AES_KEY_GEN DRBG_GEN | CO - FIDO User ECDSA Private Key: Z - FIDO User ECDSA Public Key: Z - FIDO Agreeme nt ECC Private Key: Z - FIDO Agreeme nt ECC Public Key: Z - FIDO Agreeme nt sharedSe cret: Z - FIDO SharedSe cret AES Key: Z - FIDO SharedSe cret HMAC Key: Z - FIDO PinUvAut hToken: Z - FIDO PIN: Z - AES- GCM Key: G | | Credential Manageme nt | Listing credentials and | 00 or error | pinUvAut hParam | N/A | AES_ENC HMAC_GEN KTS_CTAP_WRAP | User - FIDO | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 37 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |------------------------------|----------------------------------------------------------------------------------------|-----------------------|-----------------------------------|-------------|----------------------|----------------------------------------------------------------------------------| | | deleting credentials | statu s | | | | PinUvAut hToken: E | | authenticat orConfig | used to configure various authenticat or features through the use of its subcomma nds. | 00 or error statu s | pinUvAut hParam | N/A | AES_ENC HMAC_GEN | User - FIDO PinUvAut hToken: E | | PIV GET DATA | This service is used to read data object | 9000 or error statu s | Comman d without input paramete r | data object | None | User - PIV ECC verificatio n Public Key: R - PIV RSA verificatio n Public Key: R | | PIV Verify PIN | This service is used to verify the PIN. | 9000 or error statu s | PIN | N/A | KTS_SCP03_WRA P | User - KSenc: E - KSmac: E - PIV User PIN: W,E | | PIV Verify PUK | This service is used to verify the PUK. | 9000 or error statu s | PUK | N/A | KTS_SCP03_WRA P | Admin - KSenc: E - KSmac: E - PIV PUK PIN: W,E | | GeneralAut h (Symmetric Key) | This service is used to external and mutual authenticat e with PIV Symmetric Key | 9000 or error statu s | Random data and cipher text | N/A | AES_ENC_AUTH AES_ENC | User - DRBG- EI: E - PIV Authentic ation Key: E | | PIV Reset | Reset PIV card state and delete all stored | 9000 or error statu s | Comman d without input paramete r | N/A | SHA_CAL | CO - PIV User PIN: Z - PIV PUK PIN: Z | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 38 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |-----------------------------------|------------------------------------------------------------------------|-----------------------|--------------------------------|-----------|---------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | information Zeroization | | | | | - PIV Authentic ation Key: Z - PIV ECC Signature Private Key: Z - PIV ECC verificatio n Public Key: Z - PIV RSA Signature Private Key: Z - PIV RSA verificatio n Public | | Set Authenticat ion Key | This service is used to change Authenticati on key (PIV Symmetric Key) | 9000 or error statu s | Encrypte d Authentic ation Key | N/A | AES_ENC AES_DEC KTS_SCP03_WRA P | Key: Z Admin - PIV Authentic ation Key: W,E - Managing Key: E | | Change PUK | This service is used to change PUK | 9000 or error statu s | PUK | N/A | KTS_SCP03_WRA P | Admin - PIV PUK PIN: W,E - KSenc: E - KSmac: E | | Change PIN | This service is used to change PIN | 9000 or error statu s | PIN and new PIN | N/A | KTS_SCP03_WRA P | User - PIV User PIN: W,E - KSenc: E - KSmac: E | | Unblock PIN (Reset retry counter) | This service is used to reset retry counter and set | 9000 or error statu s | New PIN and PUK | N/A | KTS_SCP03_WRA P | Admin - PIV User PIN: W,E - PIV PUK PIN: W,E - KSenc: | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 39 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |---------------------------|----------------------------------------------------------------|-----------------------|--------------------------|------------------------|-------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | new user PIN with known PUK | | | | | E - KSmac: E | | Generate Asymmetri c Key | This service is used to generate an asymmetric key | 9000 or error statu s | Comman d with Key length | Asymmet ric Public key | RSA_GEN_KEY_P AIR ECC_GEN_KEY_P AIR | Admin - DRBG V: G,Z - PIV ECC Signature Private Key: G - PIV ECC verificatio n Public Key: G - PIV RSA Signature Private Key: G - PIV RSA verificatio n Public Key: G - DRBG Key: G,Z - DRBG Seed: G,E - DRBG- EI: G,E | | GeneralAut h (RSA/ECD SA) | This service is used to generate signature with asymmetric key | 9000 or error statu s | message | Signature | RSA_SIG_GEN ECC_SIG_GEN | User - PIV ECC Signature Private Key: E - PIV RSA Signature Private Key: E | | PIV Put Data | This service is used to write data (certicate, ID and etc) | 9000 or error statu s | Data object | N/A | None | Admin | | Personaliz ation OTP | Add a new entry and initialize its seed key | 9000 or error | Seed key | N/A | KTS_SCP03_WRA P | User - OTP HMAC Seed | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 40 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |--------------------|----------------------------------------------------|-----------------------|-----------------------------------|----------------------------------------|----------------------|--------------------------------------------------------------------------------------------------------------| | | | statu s | | | | Key: W - KSenc: E - KSmac: E - DRBG V: E - OTP AccessCo de: E - DRBG Key: E - DRBG Seed: G,E - DRBG- EI: G,E | | Delete OTP | Remove an entry and its seed key. | 9000 or error statu s | Comman d without input paramete r | N/A | None | User - OTP AccessCo de: E - OTP HMAC Seed Key: Z | | List | List all the names of the entries. | 9000 or error statu s | Comman d without input paramete r | Slot info | None | User | | Calculate OTP | Calculate the OTP value for an entry. | 9000 or error statu s | Comman d without input paramete r | 6-digit OTP value or 8-digit OTP value | HMAC_GEN | User - OTP HMAC Seed Key: E - OTP AccessCo de: E | | OTP Reset | Reset the applet to manufactor y default settings. | 9000 or error statu s | Comman d without input paramete r | N/A | None | CO - OTP HMAC Seed Key: Z | | Verify AccessCod e | Verify user AccessCod e | 9000 or error statu s | AccessC ode | N/A | KTS_SCP03_WRA P | User - OTP AccessCo de: E | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 41 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |--------------------------------|-------------------------------------------------------------------------------------------------------|-----------------------|-------------------------------------------|----------------------------------------|----------------------|-----------------------------------------------------------------| | Change AccessCod e | Change user AccessCod e | 9000 or error statu s | AccessC ode | N/A | KTS_SCP03_WRA P | User - OTP AccessCo de: W,E | | Emit OTP from slot | When the device is powered on and the user presses the button, the device outputs a 6-byte or 8- byte | 9000 or error statu s | press- button | 6-digit OTP value or 8-digit OTP value | HMAC_GEN | User - OTP HMAC Seed Key: E | | SELECT DATA | password Select a current DO ,a following GET DATA or PUT DATA will access this current DO | 9000 or error statu s | DO Data | N/A | None | Unauthen ticated | | VERIFY | Verify using user PGP User PIN(PW1) or administrat or PGP Admin PIN(PW3) | 9000 or error statu s | PGP User PIN(PW1 ) or PGP Admin PIN(PW3 ) | N/A | KTS_SCP03_WRA P | Admin - PGP Admin PIN(PW3) : E User - PGP User PIN(PW1) : E | | OpenPGP CHANGE REFEREN CE DATA | Change user PGP User PIN(PW1) or administrat or PGP Admin PIN(PW3) | 9000 or error statu s | Comman d with data info | N/A | KTS_SCP03_WRA P | Admin - PGP Admin PIN(PW3) : W,E User - PGP User PIN(PW1) : W,E | | OpenPGP RESET | Reset PGP User PIN(PW1) | 9000 or error | PW1 or PW3/ | N/A | KTS_SCP03_WRA P | Admin - PGP Admin | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 42 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |-----------------------------------|-----------------------------------------------------------------------------------|-----------------------|-----------------------------------|----------------|----------------------|-----------------------------------------------------------------------------------------------| | RETRY COUNTER | counter and set new PGP User PIN(PW1) using PGP Admin PIN(PW3) or Resetting Code. | statu s | Resetting Code | | | PIN(PW3) : W,E - PGP User PIN(PW1) : W User - PGP User PIN(PW1) : W - PGP Resetting Code: W,E | | GET DATA | Read protected or unprotecte d Data Object | 9000 or error statu s | Comman d without input paramete r | Data Object | None | User - PGP User PIN(PW1) : E Unauthen ticated | | PUT DATA | Write data objects except user writable data objects. | 9000 or error statu s | Data to be written | None | KTS_SCP03_WRA P | Admin - PGP Resetting Code: W - PGP Admin PIN(PW3) : E | | COMPUTE DIGITAL SIGNATU RE | Perform signature primitive with signature Private Key | 9000 or error statu s | message and kid | Signature | RSA_SIG_GEN | User - PGP Signature Private Key: E | | OpenPGP GENERAT E ASYMMET RIC KEY | Generate asymmetric key pair | 9000 or error statu s | Comman d without input paramete r | RSA public key | RSA_GEN_KEY_P AIR | Admin - DRBG V: G,E - PGP Admin PIN(PW3) : E - PGP Signature Private Key: G - PGP | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 43 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |----------------------|------------------------------------------------------------------------------------------|-----------------------|-----------------------------------|------------------|----------------------|-------------------------------------------------------------------------------------------------------------------------------------------------| | | | | | | | Verificatio n Public Key: G,R - DRBG Key: G,E - DRBG Seed: G,E - DRBG- EI: G,E | | TERMINAT E DF | This command is designed to renew a card in case of blocked passwords or other problems. | 9000 or error statu s | Comman d without input paramete r | N/A | None | Admin - PGP Admin PIN(PW3) : E | | ACTIVATE FILE | Initialize to the manufactor y default settings. Zeroization | 9000 or error statu s | Comman d without input paramete r | N/A | None | Admin - PGP Admin PIN(PW3) : Z - PGP User PIN(PW1) : Z - PGP Resetting Code: Z - PGP Signature Private Key: Z - PGP Verificatio n Public Key: Z | | Get Error log | Get self- test result | 9000 or error statu s | Comman d without input paramete r | Self-test result | None | Admin - Device authentic ate key: E | | On- Demand Self-test | Initiate on- demand self-tests | None | None | Pass or Fail | | Admin Unauthen ticated | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 44 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Table 12: Approved Services | Name | Descriptio n | Indic ator | Inputs | Outputs | Security Functions | SSP Access | |--------|--------------------------|--------------|----------|-----------|----------------------|--------------| | | by reboot or power cycle | | | | | | ### 4.4 Non-Approved Services N/A for this module. ### 4.5 External Software/Firmware Loaded NOTE: There is no External Software/Firmware Loaded. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 45 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 5 Software/Firmware Security ### 5.1 Integrity Techniques The Module is composed of the following firmware component(s): Component 1: cryptographic binary Component 2: non-modifiable operating system - binary The firmware components are protected with the error detection code CRC-16. Calculate CRC-16 on code and constant data in flash, then compare the result with expected value, which is also part of preoperational self-test. ### 5.2 Initiate on Demand The operator can initiate integrity test on demand by restarting the module. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 46 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 6 Operational Environment ### 6.1 Operational Environment Type and Requirements The Module has a non-modifiable operational environment at Level 3 under the FIPS 140-3 definitions therefore per the FIPS 140-3 Management Manual Section 7.5 Partial validations and non-applicable areas this section is not applicable. Type of Operational Environment : Non-Modifiable Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 47 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 7 Physical Security The Module is made of a completely hardened, production-grade polycarbonate or metal. The colored polycarbonate or metal enclosure obscures a clear view of the hardware components within. A hard, non-malleable metal casing surrounds the USB connector. The casing is made of hard, production-grade, black, opaque plastic. The coloring of the Module obscures any visible writing on the PCB. The visible critical components within the Module are further covered to meet FIPS 140-3 level 3 physical security requirements. The HSC32K2 with PAA microcontroller is covered with a black, opaque, tamper-resistant, epoxy encapsulated, thus completely covering all critical cryptographic components from plain view. The USB connector located outside of the casing (in the case of the USB Token-A3) of the USB token is made of a hard, black, opaque, production grade plastic and prevents access to the rest of the USB token. Any attempt at removal or penetration of the enclosure has a high probability of causing serious damage to the Module and the hardware components within the enclosure, which will reveal clear tamper evidence. Removal of the metal surrounding the USB connector will result in physical damage of the USB connector and its associated pins, rendering the entire cryptographic module useless. If the USB connector is exposed, there is no power going to the USB token. Once power is removed from the cryptographic module, all plaintext keys and unprotected SSPs in RAM are zeroized. ### 7.1 Mechanisms and Actions Required The enclosure of the module is designed with anti-dismantle. After assembly, any attempt at tampering will leave visible damage on the enclosure. So, each time a user uses the module, you should first check the outer appearance of the module to make sure the module has not been tampered since last time use. In case user detects any tamper during inspection, user must stop using the module immediately and contact manufacturer. Table 13: Mechanisms and Actions Required | Mechanism | Inspection Frequency | Inspection Guidance | |--------------------------|----------------------------|------------------------------------------| | anti-dismantle enclosure | Each time using the module | check the outer appearance of the module | ### 7.2 EFP/EFT Information Table 14: EFP/EFT Information | Temp/Voltage Type | Temperature or Voltage | EFP or EFT | Result | |---------------------|--------------------------|--------------|----------| | LowTemperature | -29.6 | EFP | shutdown | | HighTemperature | +86.6 | EFP | shutdown | | LowVoltage | 2.8V | EFP | shutdown | | HighVoltage | 5.5V | EFP | shutdown | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 48 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ### 7.3 Hardness Testing Temperature Ranges Table 15: Hardness Testing Temperatures | Temperature Type | Temperature | |--------------------|---------------| | LowTemperature | -20C° | | HighTemperature | +40C° | Notes: The module is hardness tested at the lowest and highest temperatures within the module's intended temperature range of operation. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 49 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 8 Non-Invasive Security ### 8.1 Mitigation Techniques The Module does not implement any mitigation method against non-invasive attack. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 50 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 9 Sensitive Security Parameters Management ### 9.1 Storage Areas Table 16: Storage Areas | Storage Area Name | Description | Persistence Type | |---------------------|-----------------------------------------------------|--------------------| | CHIPRAM(S1) | Session Key stored in volatile memory in plaintext. | Dynamic | | CHIPRAM(S2) | Session Key stored in volatile memory in encrypted. | Dynamic | | CHIPNVM(S3) | CSP is encrypted with AES-128 and stored in FLASH | Static | | CHIPNVM(S4) | CSP stored in flash in SHA2-256 | Static | | CHIPNVM(S5) | CSP stored in flash in plaintext | Static | | CHIPNVM(S6) | PSP stored in flash in plaintext | Static | ### 9.2 SSP Input-Output Methods | Name | From | To | Format Type | Distributi on Type | Entry Type | SFI or Algorithm | |---------------------------------------------------------|--------------------------------|--------------------------------|---------------|----------------------|--------------|--------------------| | Input encapsula ted by KTS-Wrap SCP03(IO 1) | Application Software (outside) | CHIPNVM( S3) | Encrypt ed | Automate d | Electro nic | KTS_SCP03_WR AP | | Input encapsula ted by KTS-Wrap AES-GCM (IO2) | Application Software (outside) | CHIPRAM( S2) | Encrypt ed | Automate d | Electro nic | KTS_AESGCM_W RAP | | Output encapsula ted by KTS-Wrap AES-GCM (IO3) | CHIPRAM( S2) | Application Software (outside) | Encrypt ed | Automate d | Electro nic | KTS_AESGCM_W RAP | | Input encapsula ted by KTS-Wrap AES-CBC with HMAC (IO4) | Application Software (outside) | CHIPNVM( S4) | Encrypt ed | Automate d | Electro nic | KTS_CTAP_WRA P | | Output encapsula ted by | CHIPRAM( S2) | Application Software (outside) | Encrypt ed | Automate d | Electro nic | KTS_CTAP_WRA P | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Page 51 of 84 Table 17: SSP Input-Output Methods | Name | From | To | Format Type | Distributi on Type | Entry Type | SFI or Algorithm | |----------------------------------|--------------------------------|--------------------------------|---------------|----------------------|--------------|--------------------| | KTS-Wrap AES-CBC with HMAC (IO5) | | | | | | | | Input in plaintext (IO6) | Application Software (outside) | CHIPRAM( S1) | Plaintex t | Automate d | Electro nic | | | Output in plaintext (IO7) | CHIPRAM( S1) | Application Software (outside) | Plaintex t | Automate d | Electro nic | | | Output in plaintext (IO8) | CHIPNVM( S6) | Application Software (outside) | Plaintex t | Automate d | Electro nic | | ### 9.3 SSP Zeroization Methods Table 18: SSP Zeroization Methods | Zeroization Method | Description | Rationale | Operator Initiation | |----------------------|--------------------------------------------|------------------------------------------------------------------------------------------|-----------------------| | Z1 | Zeroized by Terminate token command | All SSP are cleared, completed by explicit indication of 9000 Status | CO | | Z2 | Overwritten with all 0 after power cycle | Power on and implicit clear, completed by implicit indication of LED on. | Unauth | | Z3 | Zeroized by 2003 delete MF | Received command to actively clear SSPs, completed by explicit indication of 9000 Status | CO | | Z4 | "TERMINATE DF" followed by "ACTIVATE FILE" | Received command to actively clear SSPs, completed by explicit indication of 9000 Status | CO | | Z5 | Zeroized by FIDO Reset | Received command to actively clear SSPs, completed by explicit indication of 00 Status | CO | | Z6 | Zeroized by PIV Reset | Received command to actively clear SSPs, completed by explicit indication of 9000 Status | CO | | Z7 | Select functional unit | Received command to actively clear SSPs, completed by explicit indication of 9000 Status | Unauth | | Z8 | Zeroized by OTP Reset | Received command to actively clear SSPs, completed by explicit indication of 9000 Status | CO | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 52 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). 9.4 SSPs All usage of these SSPs by the Module are described in the services detailed in Section 4.3 | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |-----------|---------------------------------------------------------------------------------------------|-------------------|--------------------------------|----------------|------------------|-----------| | DRBG-EI | 384-bit entropy and 256-bit nonce input collected from the ESV,used to derive the DRBG seed | 640 - 128 | entropy source and nonce - CSP | ENT_GEN | | DRBG_GEN | | DRBG Seed | 640-bit DRBG Seed from DRBG-EI | 640 - 128 | entropy source and nonce - CSP | ENT_GEN | | DRBG_GEN | | DRBG V | Internal CTR_DRB G state value is used for SP800-90A CTR_DRB G (Consists of 128 bits) | 128 - 128 | state value - CSP | DRBG_GEN | | DRBG_GEN | | DRBG Key | Internal CTR_DRB G state value is used for | 128 - 128 | key value - CSP | DRBG_GEN | | DRBG_GEN | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 53 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |--------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------|-------------------|-----------------------|----------------------------|------------------|-----------------| | | SP800-90A CTR_DRB G (Consists of 128 bits) | | | | | | | Managing Key | 128-bit AES key, used to encrypt SSPs and keys | 128 - 128 | Symmetri c Key - CSP | AES_KEY_GEN | | AES_ENC AES_DEC | | Device authenticat e key | 128-bit AES key used for CO role to reach a safe state | 128 - 128 | Authentic ation - CSP | input during manufacturing | | AES_DEC | | INIT_KEYe nc | AES 128- bit key, used to derive KSenc and KSmac which is then used to encrypt/dec rypt data over a secure session between an authorized external | 128 - 128 | Symmetri c Key - CSP | input during manufacturing | | SESSIONKEY_GEN | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 54 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |--------------|-------------------------------------------------------------------------------------------------------------------------------------------|-------------------|----------------------|----------------------------|------------------|----------------| | INIT_KEY mac | entity and the Module. AES CMAC 128-bit key, used to derive a KSenc,KS mac which is then used to authenticat e an operator or data over a | 128 - 128 | Symmetri c Key - CSP | input during manufacturing | | SESSIONKEY_GEN | | KSenc | the Module. AES 128- bit key used to encrypt/dec rypt data over a secure session | 128 - 128 | session Key - CSP | SESSIONKEY_GEN | | KTS_SCP03_WRAP | | KSmac | AES CMAC 128-bit key used to authenticat | 128 - 128 | session Key - CSP | SESSIONKEY_GEN | | KTS_SCP03_WRAP | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 55 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |-------------------------------|----------------------------------------------------------------------|-------------------|-------------------------------|----------------------------|------------------|---------------------------| | | e data over a secure session | | | | | | | AES-GCM Key | 128-bit AES-GCM key used to encrypt the key handle or credentialI D | 128 - 128 | Symmetri c Key - CSP | AES_KEY_GEN | | AES_ENC_AUTH AES_DEC_AUTH | | AES-GCM IV | 96-bit AES- GCM IV used to encrypt the key handle or credentialI D | 96 - N/A | Random IV - CSP | DRBG_GEN | | AES_ENC_AUTH AES_DEC_AUTH | | FIDO Device ECDSA Private Key | 256-bit ECC private key used to generate signature for registration. | 256 - 128 | Asymmet ric Private Key - CSP | input during manufacturing | | ECC_SIG_GEN | | FIDO Device ECDSA Public Key | 256-bit ECC FIDO public key, it is returned to the server | 256 - 128 | Asymmet ric Public Key - PSP | input during manufacturing | | ECC_SIG_VER | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 56 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |--------------------------------|----------------------------------------------------------------------------------------------------------------------|-------------------|-------------------------------|------------------|------------------|--------------------------| | | via the certificate to verify the signature generated after registration | | | | | | | FIDO User ECDSA Private Key | 256-bit ECC private key used to Attestation signature | 256 - 128 | Asymmet ric Private Key - CSP | ECC_GEN_KEY_PAIR | | ECC_SIG_GEN | | FIDO User ECDSA Public Key | 256-bit ECC FIDO public key, it is transmitted to the server for verifying signature generated after authenticati on | 256 - 128 | Asymmet ric public Key - PSP | ECC_GEN_KEY_PAIR | | ECC_SIG_VER | | FIDO Agreement ECC Private Key | 256-bit ECC private key used to perform key agreement | 256 - 128 | Asymmet ric Private Key - CSP | ECC_GEN_KEY_PAIR | | SHAREDSECRETKEY _GEN_KAS | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 57 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |-------------------------------|----------------------------------------------------------------------------------------------------------------------------------|-------------------|------------------------------|--------------------------|--------------------------|-----------------------------| | FIDO Agreement ECC Public Key | with external public ECC key to get shared Secret 256-bit ECC public key used to perform key agreement, the Module returns it to | 256 - 128 | Asymmet ric public Key - PSP | ECC_GEN_KEY_PAIR | | SHAREDSECRETKEY _GEN_KAS | | FIDO Agreement sharedSecr et | et 256-bit key Used to derived FIDO SharedSec ret AES Key and FIDO SharedSec ret HMAC | 256 - 128 | Shared Secret - CSP | SHAREDSECRETKEY _GEN_KAS | | KAS-ECC Sp800-56Ar3 (A4980) | | FIDO SharedSec | 256-bit AES CBC key used | 256 - 128 | Symmetri c Key - CSP | | SHAREDSECRETKEY _GEN_KAS | SHAREDSECRETKEY _GEN_KAS | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 58 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |-----------------------------|---------------------------------------------------------------------------------|-------------------|-----------------------|----------------|--------------------------|--------------------------| | ret AES Key | for encryption calculation of pin related operations | | | | | | | FIDO SharedSec ret HMAC Key | 256-bit AES CBC key used for HMAC SHA-256 calculation of pin related operations | 256 - 128 | Symmetri c Key - CSP | | SHAREDSECRETKEY _GEN_KAS | SHAREDSECRETKEY _GEN_KAS | | FIDO PinUvAuth Token | 256-bit HMAC SHA-256 Key used to authorize operator after PIN authenticati on | 256 - 128 | Authentic ation - CSP | DRBG_GEN | | HMAC_GEN | | FIDO PIN | Authenticat e the User,4 to 63-byte PIN value | 32-248 - N/A | Authentic ation - CSP | | | KTS_CTAP_WRAP | | PIV Authenticat ion Key | 128-bit AES ECB key, used for | 128 - 128 | Authentic ation - CSP | | | AES_ENC_AUTH | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 59 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |---------------------------------|-------------------------------------------------------------------|-------------------|-------------------------------|------------------|------------------|----------------| | | authenticati on of PIV CO | | | | | | | PIV ECC Signature Private Key | 256 bit ECC private key, used for signature operations | 256 - 128 | Asymmet ric Private Key - CSP | ECC_GEN_KEY_PAIR | | ECC_SIG_GEN | | PIV ECC verification Public Key | 256-bit ECC public key, used for client verification operations | 256 - 128 | Asymmet ric public Key - PSP | ECC_GEN_KEY_PAIR | | | | PIV RSA Signature Private Key | 2048 -bit RSA private key, used for signature operations | 2048 - 112 | Asymmet ric Private Key - CSP | RSA_GEN_KEY_PAIR | | RSA_SIG_GEN | | PIV RSA verification Public Key | 2048 -bit RSA public key, used for client verification operations | 2048 - 112 | Asymmet ric public Key - PSP | RSA_GEN_KEY_PAIR | | | | PIV User PIN | 8-byte pin, used for authenticati ng the PIV user for | 64 - N/A | Authentic ation - CSP | | | KTS_SCP03_WRAP | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 60 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |------------------------|---------------------------------------------------------------------------------------|-------------------|-----------------------|----------------|------------------|----------------| | | Asymmetric services | | | | | | | PIV PUK PIN | 8-byte pin, used for unblocking the PIV admin pin | 64 - N/A | Authentic ation - CSP | | | KTS_SCP03_WRAP | | 2003 Internal Auth Key | AES 128,192,25 6-bit ,used to authenticat e the Module to an external entity | 128-256 - 128-256 | Authentic ation - CSP | | | AES_ENC | | 2003 External Auth Key | AES 128,192,25 6-bit, used to modify the security state of the currently selected DF. | 128-256 - 128-256 | Authentic ation - CSP | | | AES_DEC | | 2003 PIN | 8-16 byte secret used to modify the security state of the currently selected DF. | 64-128 - N/A | Authentic ation - CSP | | | | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 61 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |--------------------------|---------------------------------------------------------------------------------------------------------------|---------------------------|-------------------------------|------------------|------------------|-----------------| | 2003 PSO calculation key | AES 128,192,25 6-bit, Used to encryption, decryption, checksum calculation, and checksum verification in Unit | 128-256 - 128-256 | Symmetri c Key - CSP | | | AES_ENC AES_DEC | | 2003 Unblock PIN | 8-16 byte secret used to unblocking the 2003 pin the currently selected | 64-128 - N/A | Authentic ation - CSP | | | AES_ENC | | 2003 RSA Private Key | 2048,3072, 4096 bit RSA private key is used to sign data | 2048,3072 ,4096 - 112-152 | Asymmet ric Private Key - CSP | RSA_GEN_KEY_PAIR | | RSA_SIG_GEN | | 2003 RSA Public Key | 2048,3072, 4096-bit RSA public key used to verify data | 2048,3072 ,4096 - 112-152 | Asymmet ric public Key - PSP | RSA_GEN_KEY_PAIR | | RSA_SIG_VER | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 62 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |------------------------|----------------------------------------------------------------|-------------------------|-------------------------------|------------------|------------------|-------------------------| | 2003 ECDSA Private Key | 256,384,52 1bit ECDSA private key used to sign data. | 256,384,5 21 - 128- 256 | Asymmet ric Private Key - CSP | ECC_GEN_KEY_PAIR | | ECC_SIG_GEN | | 2003 ECDSA Public Key | 256,384,52 1bit ECDSA public key used to verify data. | 256,384,5 21 - 128- 256 | Asymmet ric public Key - PSP | ECC_GEN_KEY_PAIR | | ECC_SIG_VER | | OTP HMAC Seed Key | SHA- 1,HMAC SHA-256 key ,used to calculate OTP values | 128-512 - 128 | Authentic ation - CSP | | | HMAC_GEN | | OTP AccessCod e | for the User 8-byte pin, used for authenticati ng the OTP user | 64 - N/A | Authentic ation - CSP | | | HMAC_GEN KTS_SCP03_WRAP | | PGP Admin PIN(PW3) | 8 to 127- byte, used for authenticati on of the OpenPGP CO. | 64-1024 - N/A | Authentic ation - CSP | | | KTS_SCP03_WRAP | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 63 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength Type - Category | Generated By | Established By | Used By | |-----------------------------|-----------------------------------------------------------------------------------------|----------------------------------------|------------------|------------------|----------------| | PGP User PIN(PW1) | for authenticati ng the OpenPGP user for Asymmetric 64-1024 | - N/A Authentic ation - CSP | | | KTS_SCP03_WRAP | | PGP Resetting Code | 8 to 127- byte.Used for resetting the User PIN 64-1024 N/A | - Authentic ation - CSP | | | KTS_SCP03_WRAP | | PGP Signature Private Key | 4096 bit RSA private key, used for PKCS#1 v1.5 2048,3072 ,4096 112-152 | - Asymmet ric Private Key - CSP | RSA_GEN_KEY_PAIR | | RSA_SIG_GEN | | PGP Verification Public Key | 4096 bit RSA public key, used for verification specified in PKCS#1 v1.5 2048,3072 ,4096 | - 112-152 Asymmet ric public Key - PSP | RSA_GEN_KEY_PAIR | | | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 64 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Descriptio n | Size - Strength | Type - Category | Generated By | Established By | Used By | |-----------------------------------|------------------------------------------------------------------------------------------------------------|-------------------|------------------------------|----------------|------------------|--------------------------| | External Agreement ECC Public Key | 256-bit ECC Public key used to perform key agreement with FIDO Agreement ECC Private Key to get sharedSecr | 256 - 128 | Asymmet ric public Key - PSP | | | SHAREDSECRETKEY _GEN_KAS | Table 19: SSP Table 1 | Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |--------------|------------------|-----------------------|-------------------------|---------------|--------------------------------------------------------------------------------------------------------------------------------------------------------| | DRBG-EI | | CHIPRAM(S1):Plaintext | after usage is complete | Z2 | | | DRBG Seed | | CHIPRAM(S1):Plaintext | after usage is complete | Z2 | | | DRBG V | | CHIPRAM(S1):Plaintext | after usage is complete | Z2 | DRBG-EI:Derived From | | DRBG Key | | CHIPRAM(S1):Plaintext | after usage is complete | Z2 | DRBG-EI:Derived From | | Managing Key | | CHIPNVM(S5):Plaintext | | Z1 | Device authenticate key:Encrypts INIT_KEYenc:Encrypts INIT_KEYmac:Encrypts FIDO Device ECDSA Private Key:Encrypts FIDO User ECDSA Private Key:Encrypts | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 65 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |-------------------------|------------------|-----------------------|--------------------------|---------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | | | | | PIV Authentication Key:Encrypts PIV ECC Signature Private Key:Encrypts PIV RSA Signature Private Key:Encrypts 2003 Internal Auth Key:Encrypts 2003 External Auth Key:Encrypts 2003 PSO calculation key:Encrypts 2003 RSA Private Key:Encrypts 2003 ECDSA Private Key:Encrypts OTP HMAC Seed Key:Encrypts PGP Resetting Code:Encrypts PGP Signature Private Key:Encrypts | | Device authenticate key | | CHIPNVM(S3):Encrypted | | Z1 | Managing Key:Encrypted by KSenc:Derives | | INIT_KEYenc | | CHIPNVM(S3):Encrypted | | Z1 | Managing Key:Encrypted by KSenc:Derives | | INIT_KEYmac | | CHIPNVM(S3):Encrypted | | Z1 | Managing Key:Encrypted by KSmac:Derives | | KSenc | | CHIPRAM(S1):Plaintext | after usage is completed | Z7 | INIT_KEYenc:Derived From | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 66 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |--------------------------------|----------------------------------------------------------------------------------------------|-----------------------|--------------------------------|---------------|---------------------------------------------------------------------------------------------------------------| | KSmac | | CHIPRAM(S1):Plaintext | after usage is completed | Z7 | INIT_KEYmac:Derived From | | AES-GCM Key | | CHIPNVM(S5):Plaintext | | Z5 | FIDO User ECDSA Private Key:Wraps | | AES-GCM IV | | CHIPNVM(S5):Plaintext | | Z5 | FIDO User ECDSA Private Key:Wraps | | FIDO Device ECDSA Private Key | | CHIPNVM(S3):Encrypted | | Z1 | FIDO Device ECDSA Public Key:Paired With Managing Key:Encrypted by AES-GCM Key:Wrapped by | | FIDO Device ECDSA Public Key | Output in plaintext (IO8) | CHIPNVM(S6):Plaintext | | Z1 | FIDO Device ECDSA Private Key:Paired With | | FIDO User ECDSA Private Key | Input encapsulated by KTS-Wrap AES- GCM (IO2) Output encapsulated by KTS-Wrap AES- GCM (IO3) | CHIPNVM(S3):Encrypted | | Z5 | FIDO User ECDSA Public Key:Paired With Managing Key:Encrypted by AES-GCM Key:Wrapped by AES-GCM IV:Wrapped by | | FIDO User ECDSA Public Key | Output in plaintext (IO7) | CHIPNVM(S6):Plaintext | | Z5 | FIDO User ECDSA Private Key:Paired With | | FIDO Agreement ECC Private Key | | CHIPRAM(S1):Plaintext | | Z2 | FIDO Agreement ECC Public Key:Paired With FIDO Agreement sharedSecret:Derives | | FIDO Agreement ECC Public Key | Output in plaintext (IO7) | CHIPRAM(S1):Plaintext | | Z2 | FIDO Agreement ECC Private Key:Paired With | | FIDO Agreement sharedSecret | | CHIPRAM(S1):Plaintext | after their usage is completed | Z2 | FIDO Agreement ECC Private Key:Derived From External Agreement ECC Public Key:Derived From | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 67 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |---------------------------------|----------------------------------------------------------|-----------------------|--------------------------------|---------------|----------------------------------------------------------------------------| | | | | | | FIDO SharedSecret AES Key:Derives FIDO SharedSecret HMAC Key:Derives | | FIDO SharedSecret AES Key | | CHIPRAM(S1):Plaintext | | Z5 | FIDO Agreement sharedSecret:Derived From | | FIDO SharedSecret HMAC Key | | CHIPRAM(S1):Plaintext | | Z5 | FIDO Agreement sharedSecret:Derived From | | FIDO PinUvAuthToken | Output encapsulated by KTS-Wrap AES- CBC with HMAC (IO5) | CHIPRAM(S1):Plaintext | after their usage is completed | Z5 | FIDO SharedSecret AES Key:Wrapped by FIDO SharedSecret HMAC Key:Wrapped by | | FIDO PIN | Input encapsulated by KTS-Wrap AES- CBC with HMAC (IO4) | CHIPNVM(S4):Encrypted | | Z5 | | | PIV Authentication Key | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S3):Encrypted | | Z6 | Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by | | PIV ECC Signature Private Key | | CHIPNVM(S3):Encrypted | | Z6 | PIV ECC verification Public Key:Paired With Managing Key:Encrypted by | | PIV ECC verification Public Key | Output in plaintext (IO8) | CHIPNVM(S6):Plaintext | | Z6 | PIV ECC Signature Private Key:Paired With | | PIV RSA Signature Private Key | | CHIPNVM(S3):Encrypted | | Z6 | PIV RSA verification Public Key:Paired With Managing Key:Encrypted by | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 68 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |---------------------------------|-------------------------------------------|-----------------------|--------------------|---------------|-----------------------------------------------------------------| | PIV RSA verification Public Key | Output in plaintext (IO8) | CHIPNVM(S6):Plaintext | | Z6 | PIV RSA Signature Private Key:Paired With | | PIV User PIN | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S4):Encrypted | | Z6 | KSenc:Unwrapped by KSmac:Unwrapped by | | PIV PUK PIN | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S4):Encrypted | | Z6 | KSenc:Unwrapped by KSmac:Unwrapped by | | 2003 Internal Auth Key | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S3):Encrypted | | Z3 | Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by | | 2003 External Auth Key | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S3):Encrypted | | Z3 | Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by | | 2003 PIN | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S4):Encrypted | | Z3 | | | 2003 PSO calculation key | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S3):Encrypted | | Z3 | Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by | | 2003 Unblock PIN | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S4):Encrypted | | Z3 | Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by | | 2003 RSA Private Key | | CHIPNVM(S3):Encrypted | | Z3 | 2003 RSA Public Key:Paired With Managing Key:Encrypted by | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 69 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |-----------------------------------|-------------------------------------------|-----------------------|--------------------|---------------|-------------------------------------------------------------------| | 2003 RSA Public Key | Output in plaintext (IO8) | CHIPNVM(S6):Plaintext | | Z3 | 2003 RSA Private Key:Paired With | | 2003 ECDSA Private Key | | CHIPNVM(S3):Encrypted | | Z3 | Managing Key:Encrypted by 2003 ECDSA Public Key:Paired With | | 2003 ECDSA Public Key | Output in plaintext (IO8) | CHIPNVM(S6):Plaintext | | Z3 | 2003 ECDSA Private Key:Paired With | | OTP HMAC Seed Key | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S3):Encrypted | | Z1 | Managing Key:Encrypted by KSenc:Unwrapped by KSmac:Unwrapped by | | OTP AccessCode | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S4):Encrypted | | Z8 | KSenc:Unwrapped by KSmac:Unwrapped by | | PGP Admin PIN(PW3) | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S4):Encrypted | | Z4 | KSenc:Unwrapped by KSmac:Unwrapped by | | PGP User PIN(PW1) | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S4):Encrypted | | Z4 | KSenc:Unwrapped by KSmac:Unwrapped by | | PGP Resetting Code | Input encapsulated by KTS-Wrap SCP03(IO1) | CHIPNVM(S3):Encrypted | | Z4 | KSenc:Unwrapped by KSmac:Unwrapped by | | PGP Signature Private Key | | CHIPNVM(S3):Encrypted | | Z4 | Managing Key:Encrypted by PGP Verification Public Key:Paired With | | PGP Verification Public Key | Output in plaintext (IO8) | CHIPNVM(S6):Plaintext | | Z4 | PGP Signature Private Key:Paired With | | External Agreement ECC Public Key | Input in plaintext (IO6) | CHIPRAM(S1):Plaintext | | Z2 | FIDO Agreement ECC Private Key:Used With | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 70 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 71 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ### 9.5 Transitions The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 72 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 10 Self-Tests The Module performs self-tests to ensure the proper operation of the Module. Per FIPS 140-3 these are categorized as either pre-operational self-tests or conditional self-tests. ### 10.1 Pre-Operational Self-Tests The Module performs the following pre-operational self-tests in table below Table 21: Pre-Operational Self-Tests | Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | |---------------------|-------------------|---------------|-----------------|--------------|-------------------------------------------------------------------------------------------------| | FIPS_CRC16_FIT | CRC-16 | KAT | SW/FW Integrity | 9000 or 6F90 | Executed on the whole firmware stored in EEPROM before the Module transition to the idle state. | ### 10.2 Conditional Self-Tests The Module performs the following conditional self-tests in the table below | Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions | |---------------------|-------------------|---------------|-------------|------------------------------------------------|----------------|--------------| | AES Encrypt | AES-128-bit - ECB | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | AES Encryption | Bootup | | AES Decrypt | AES-128-bit - ECB | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | AES decryption | Bootup | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 73 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions | |--------------------------|-------------------------------------------------------------------------|---------------|-------------|------------------------------------------------|-------------------------------------------------------------------------------------------------------------|--------------------------| | AES-CMAC | AES-128-bit CMAC | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | Message Authentication | Bootup | | AES-GCM Encrypt | AES-128-bit GCM | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | Authenticated encryption | Bootup | | AES-GCM Decrypt | AES-128-bit GCM | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | Authenticated decryption | Bootup | | Counter DRBG | AES-128-bit- ECB | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | AES-128 CTR_DRBG instantiation, generate, and reseed KATs performed before the first random data generation | Bootup | | KAS-ECC Sp800-56Ar3 | ECDH: P-256 HKDF: Using HMAC-Two step | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | KAS-SSC Shared Secret generation with P-256 per IG D.F. | Bootup | | ECDSA KeyGen (FIPS186-5) | ECDSA Key Generation | PCT | PCT | 9000(meaning Successful) or 6F90(meaning fail) | Signature and Verification Per IG C.A | Generate ECDSA key pairs | | ECDSA SigGen (FIPS186-5) | ECDSA Signature Generation | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | ECDSA P-256 with SHA-256 Signature Generation | Bootup | | ECDSA SigVer (FIPS186-5) | ECDSA Signature Verification | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | ECDSA P-256 with SHA-256 Signature Verification | Bootup | | HMAC-SHA2-256 | using HMAC- SHA256 | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | HMAC-SHA-256 KAT | Bootup | | RSA KeyGen (FIPS186-5) | 2048-bit 3072-bit 4096-bit RSA Key Generation Pairwise Consistency Test | PCT | PCT | 9000(meaning Successful) or 6F90(meaning fail) | Signature and Verification per IG C.E. | Generate RSA key pairs | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 74 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions | |-----------------------------------------------------|-------------------------------------|---------------|-------------|------------------------------------------------|-----------------------------------------------------------|--------------------------------------| | RSA SigVer (FIPS186-5) | 2048-bit RSA Signature Verification | KAT | CAST | 9000 or 6F90 | 2048-bit RSA PKCSv1.5 with SHA-256 Signature Verification | Bootup | | RSA SigGen (FIPS186-5) | 2048-bit RSA Signature Generation | KAT | CAST | 9000 or 6F90 | 2048-bit RSA PKCSv1.5 with SHA-256 Signature Generation | Bootup | | SHA-1 | SHA-1 | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | SHA-1 | Bootup | | SHA2-256 | SHA2-256 | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | SHA2-256 | Bootup | | SHA2-384 | SHA2-384 | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | SHA2-384 | Bootup | | SHA2-512 | SHA2-512 | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | SHA2-512 | Bootup | | KDF SP800-108 | Using AES128 CMAC | KAT | CAST | 9000(meaning Successful) or 6F90(meaning fail) | AES128 CMAC KAT | Bootup | | Entropy 90B Start-up Repetition Count Test (RCT) | Repetition Count Test | RCT | CAST | Success or Failure Code | As specified in [90B] RCT startup health tests | At boot up | | Entropy 90B Start-up Adaptive Proportion Test (APT) | Adaptive Proportion Test | APT | CAST | Success or Failure Code | As specified in [90B] APT startup health tests | At boot up | | Entropy 90B Continuous Repetition Count Test (RCT) | Repetition Count Test | RCT | CAST | Success or Failure Code | As specified in [90B] RCT continuous health tests | Continuous when entropy is requested | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 75 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Table 22: Conditional Self-Tests | Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions | |-------------------------------------------------------|--------------------------|---------------|-------------|-------------------------|---------------------------------------------------|--------------------------------------| | Entropy 90B Continuous Adaptive Proportion Test (APT) | Adaptive Proportion Test | APT | CAST | Success or Failure Code | As specified in [90B] APT continuous health tests | Continuous when entropy is requested | ### 10.3 Periodic Self-Test Information | Algorithm or Test | Test Method | Test Type | Period | Periodic Method | |---------------------|---------------|-----------------|-----------------------------------------------|------------------------------------------| | FIPS_CRC16_FIT | KAT | SW/FW Integrity | every 1000 services are processed or power on | performed by the Module programmatically | Table 23: Pre-Operational Periodic Information | Algorithm or Test | Test Method | Test Type | Period | Periodic Method | |---------------------|---------------|-------------|-----------------------------------------------|-------------------| | AES Encrypt | KAT | CAST | every 1000 services are processed or power on | Automatic | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 76 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Algorithm or Test | Test Method | Test Type | Period | Periodic Method | |--------------------------|---------------|-------------|------------------------------------------------|-------------------| | AES Decrypt | KAT | CAST | every 1000 services are processed and power on | Automatic | | AES-CMAC | KAT | CAST | every 1000 services are processed or power on | Automatic | | AES-GCM Encrypt | KAT | CAST | every 1000 services are processed or power on | Automatic | | AES-GCM Decrypt | KAT | CAST | every 1000 services are processed or power on | Automatic | | Counter DRBG | KAT | CAST | every 1000 services are processed or power on | Automatic | | KAS-ECC Sp800-56Ar3 | KAT | CAST | every 1000 services are processed or power on | Automatic | | ECDSA KeyGen (FIPS186-5) | PCT | PCT | Everytime a key pair is generated | Automatic | | ECDSA SigGen (FIPS186-5) | KAT | CAST | every 1000 services are processed or power on | Automatic | | ECDSA SigVer (FIPS186-5) | KAT | CAST | every 1000 services are processed or power on | Automatic | | HMAC-SHA2-256 | KAT | CAST | every 1000 services are processed or power on | Automatic | | RSA KeyGen (FIPS186- 5) | PCT | PCT | Everytime a key pair is generated | Automatic | | RSA SigVer (FIPS186- 5) | KAT | CAST | every 1000 services are processed or power on | Automatic | | RSA SigGen (FIPS186- 5) | KAT | CAST | every 1000 services are processed or power on | Automatic | | SHA-1 | KAT | CAST | every 1000 services are processed or power on | Automatic | | SHA2-256 | KAT | CAST | every 1000 services are processed or power on | Automatic | | SHA2-384 | KAT | CAST | every 1000 services are processed or power on | Automatic | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 77 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). Table 24: Conditional Periodic Information | Algorithm or Test | Test Method | Test Type | Period | Periodic Method | |-------------------------------------------------------|---------------|-------------|------------------------------------------------|-------------------| | SHA2-512 | KAT | CAST | every 1000 services are processed or power on | Automatic | | KDF SP800-108 | KAT | CAST | every 1000 services are processed and power on | Automatic | | Entropy 90B Start-up Repetition Count Test (RCT) | RCT | CAST | On Demand | Device Reset | | Entropy 90B Start-up Adaptive Proportion Test (APT) | APT | CAST | On Demand | Device Reset | | Entropy 90B Continuous Repetition Count Test (RCT) | RCT | CAST | N/A | N/A | | Entropy 90B Continuous Adaptive Proportion Test (APT) | APT | CAST | N/A | N/A | The condition of initiating Periodic Self-Test is to execute every 1000 services. Once every 1000 services being executed, the periodic self-test function will call Pre-Operational Self-Tests and Conditional Self-Tests. Self-test failures are indicated to the user through LED status and service return status. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 78 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ### 10.4 Error States Table 25: Error States | Name | Description | Conditions | Recovery Method | Indicator | |--------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------|-------------------------------|-----------------------| | ES1 | The Module fails at CRC16 FIT, ENT RCT and APT, CTR DRBG KAT, ECDSA KAT, RSA KAT, AES ECB KAT, AES CMAC KAT, AES GCM KAT, HMAC KAT, KBKDF KAT, KAS-ECC KAT, SHS KAT, RSA Generate key pair PCT, ECC Generate key pair PCT | The Module enters Critical error state. | Reboot/Power cycle the module | 6F90 and blinking LED | ### 10.5 Operator Initiation of Self-Tests All self-tests, except for the continuous health tests, can be invoked on demand by restarting the module. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 79 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 11 Life-Cycle Assurance ### 11.1 Installation, Initialization, and Startup Procedures ###### Installation and Initialization: The following steps must be performed in order to securely install, initialize, and start up the ePass Token cryptographic module in the FIPS 140-3 Approved mode of operation. The steps for the CO to enter the module and change the default password gain authorized access to the module. The module is setup at manufacturing and delivered to the CO in approved mode. ###### Delivery: The following steps must be performed in order to securely deliver the ePass Token cryptographic module to the authorized operator: 1. Set the required keys in a secure factory environment 2. Complete packaging and user manual 3. Shipping the modules to the final customer. For each shipment, our factory will use the courier agreed with customer, such as FedEx or DHL. Our factory will inform customer in advance with the shipment info by email. When the goods arriving in customer site, the customer will first check the goods according to the shipment info they received, and sign for acceptance. 4. The final customer check the module information according to administrator manual. ### 11.2 Administrator Guidance Refer to FEITIAN ePass Token Cryptographic Module Administrator Guidance.docx, which will be provided to the issuer through secure communications. ### 11.3 Non-Administrator Guidance Refer to FEITIAN ePass Token Cryptographic Module Non-Administrator Guidance.docx, which will be provided to the issuer through secure communications. ### 11.4 Design and Rules ##### Rules of Operation 1. The Module provides two distinct operator roles: User and Cryptographic Officer. 2. The Module provides identity-based authentication. 3. The Module clears previous authentications on power cycle. 4. An operator does not have access to any cryptographic services prior to assuming an authorized role. 5. The Module allows the operator to initiate power-up self-tests by power cycling power or resetting the Module. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 80 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). 6. All self-tests do not require any operator action. 7. Data output is inhibited during key generation, self-tests, zeroization, and error states. 8. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module. ### There are no restrictions on which keys or SSPs are zeroized by the zeroization service. 10. The Module does not support concurrent operators. 11. The Module does not support a maintenance interface or role. 12. The Module does not have any proprietary external input/output devices used for entry/output of data. 13. The Module does not enter or output plaintext CSPs. 14. The Module does not store any plaintext CSPs. 15. The Module does not output intermediate key values. 16. The Module does not provide bypass services or ports/interfaces. ### 11.5 Maintenance Requirements The module does not require any maintenance requirements ### 11.6 End of Life Administrator SHALL invoke Terminate token service after authentication to switch device into the terminated state as a result, all CSPs are cleared, and all services are not available anymore. The device shall be destroyed. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 81 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## 12 Mitigation of Other Attacks The Module does not implement any mitigation method against other attacks. Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 82 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). ## References and Definitions The following standards are referred to in this Security Policy. Table 26 References | Abbreviation | Full Specification Name | |----------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | [FIPS140-3] | Security Requirements for Cryptographic Modules, March 22, 2019 | | [ISO19790] | International Standard, ISO/IEC 19790, Information technology - Security techniques - Test requirements for cryptographic modules, Third edition, March 2017 | | [ISO24759] | International Standard, ISO/IEC 24759, Information technology - Security techniques - Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015 | | [IG] | Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, October 23, 2024 | | [108r1] | NIST Special Publication 800-108, Recommendation for Key Derivation Using Pseudorandom Functions (Revised), August 2022 INCLUDES UPDATES AS OF 02-02-2024 | | [133] | NIST Special Publication 800-133, Recommendation for Cryptographic Key Generation, Revision 2, June 2020 | | [135] | National Institute of Standards and Technology, Recommendation for Existing Application- Specific Key Derivation Functions, Special Publication 800-135rev1, December 2011. | | [186] | National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-5, February 3, 2023. | | [197] | National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197, May 9, 2023 | | [198-1] | National Institute of Standards and Technology, The Keyed-Hash Message Authentication Code (HMAC), Federal Information Processing Standards Publication 198-1, July, 2008 | | [180] | National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August, 2015 | | [38A] | National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation, Methods and Techniques, Special Publication 800-38A, December 2001 | | [38B] | National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication, Special Publication 800-38B, May 2005 | | [38D] | National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC, Special Publication 800-38D, November 2007 | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 83 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision). | Abbreviation | Full Specification Name | |----------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | [56Ar3] | NIST Special Publication 800-56A Revision 3, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, April 2018 | | [56Br2] | NIST Special Publication 800-56B Revision 2, Recommendation for Pair-Wise Key Establishment Schemes Using Finite Field Cryptography, March 2019 | | [56Cr2] | NIST Special Publication 800-56C Revision 2, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, August 2020 | | [90A] | National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A, Revision 1, June 2015. | | [90B] | National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018. | Table 27 Acronyms and Definitions | Acronym* | Definition | |---------------------|----------------------------------| | APT | Adaptative Proportion Test | | KAT | Know Answer Test | | RCT | Repetition Count Test | | SSP | Sensitive Security Parameter | | PCT | Pairwise Consistency Test | | KDF | Key Derivation Function | | KTS | Key Transport Scheme | | KAS | Key Agreement Scheme | | VCC | Voltage(at the) Common Collector | | PIN | Personal Identification Number | | PGP User PIN (PW1) | user-password | | PGP Admin PIN (PW3) | admin-password | | CO | Crypto Officer | | PUK | PIN Unblocking Key | Copyright FEITIAN Technologies, Inc., 2026 Version 1.1.0 Page 84 of 84 FEITIAN Technologies Public Material - May be reproduced only in its original entirety (without revision).