X5 Postal Security Device (PSD)

Certificate details

Certificate ID #4933
Status active
Validation dates 24.12.2024
Sunset date 23-12-2029
Standard FIPS 140-3
Security level 3
Type Hardware
Embodiment Single Chip
Caveat Interim Validation; When operated in approved mode; No assurance of the minimum strength of generated SSPs (e.g., keys).
Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The X5 Postal Security Device (PSD) is a single-chip cryptographic module designed by Pitney Bowes, Inc. (PB) to conform with FIPS 140-3 Security Level 3 requirements. The device includes the Maxim Integrated MAX32590 DeepCover Secure Microcontroller hardware component. The PSD Application and DAL are compiled into a single firmware. The X5 Postal Security Device (PSD) provides cryptographic services to a host device (i.e., Digital Postage Meter), to support postage evidence in the form of an indicium. A PSD provides protection that includes ensuring the secrecy of sensitive security parameters (SSPs) such as cryptographic keys and providing data integrity protection for funds relevant data items (FRDIs) such as accounting data. SSPs and FRDIs reside inside the strong physical protections of the X5 Postal Security Device (PSD).
Version (Hardware) Maxim Integrated MAX32590 DeepCover Secure Microcontroller - Revision B4
Version (Firmware) PSD Application: 22.01.000D & 22.01.000F Device Abstraction Layer (DAL): 02.01.000F & 02.01.00013
Vendor Pitney Bowes, Inc. http://www.pitneybowes.com
Lab Penumbra Security, Inc.
Algorithms
  • AES-CBCA2435
  • AES-ECBA2435
  • AES-KWA2435
  • ECDSA KeyGen (FIPS186-4)A2437
  • ECDSA SigGen (FIPS186-4)A2437
  • ECDSA SigVer (FIPS186-4)A2437
  • Hash DRBGA2436
  • HMAC-SHA2-256A2438
  • KAS-ECC-SSC Sp800-56Ar3A2439
  • KDA OneStep Sp800-56Cr1A2439
  • RSA SigVer (FIPS186-4)A2440
  • SHA2-224A2441
  • SHA2-256A2441
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-, CAST, DES, Triple-DES, HMAC, HMAC-SHA-256
Asymmetric Algorithms
RSA 2048, ECDH, ECDSA, ECC, DH, DSA
Hash functions
SHA-256
Schemes
MAC
Randomness
DRBG, RBG
Elliptic Curves
P-224, P-256

Trusted Execution Environments
PSP, SSC

Security level
Level 3

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4933,
  "dgst": "26da1548ae1645e0",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "#A2440",
        "KAS-ECC-SSC Sp800-56Ar3A2439",
        "SHA2-224A2441",
        "Hash DRBGA2436",
        "SHA2-256A2441",
        "#A2439",
        "#A2438",
        "RSA SigVer (FIPS186-4)A2440",
        "AES-ECBA2435",
        "ECDSA KeyGen (FIPS186-4)A2437",
        "AES-KWA2435",
        "ECDSA SigGen (FIPS186-4)A2437",
        "KDA OneStep Sp800-56Cr1A2439",
        "#A2436",
        "#A2435",
        "#A2437",
        "#A2441",
        "HMAC-SHA2-256A2438",
        "AES-CBCA2435",
        "ECDSA SigVer (FIPS186-4)A2437"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "22.01.000",
        "02.01.000",
        "02.01.00013"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 3,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "Cert. #A2435",
            "properties": "Direction: Encrypt, Decrypt Key Length : 256 2",
            "reference": "FIPS 197, NIST SP 800- 38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "Cert. #A2435",
            "properties": "Direction: Encrypt, Decrypt Key Length : 256 3",
            "reference": "FIPS 197, NIST SP 800- 38A"
          },
          {
            "algorithm": "AES KW",
            "cavpCertName": "Cert. #A2435",
            "properties": "Direction: Wrap, Unwrap Key Length : 256 4",
            "reference": "NIST SP 800-38F"
          },
          {
            "algorithm": "ECDSA Key Generation",
            "cavpCertName": "Cert. #A2437",
            "properties": "Curves: P-224, P-256 SHA Size: 224, 256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA Signature Generation",
            "cavpCertName": "Cert. #A2437",
            "properties": "Curves: P-224, P-256 SHA Size: 224, 256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA Signature Verification",
            "cavpCertName": "Cert. #A2437",
            "properties": "Curves: P-224, P-256 SHA Size: 224, 256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "Cert. #A2436",
            "properties": "Function: Hash_DRBG",
            "reference": "NIST SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "Cert. #A2438",
            "properties": "Function: Generate Message Authentication Codes SHA Size: 256",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC NIST SP 800-56Ar3",
            "cavpCertName": "Cert. #A2439",
            "properties": "Scheme: Ephemeral Unified Model C (2e, 0s, ECC CDH) Curve: P-256",
            "reference": "NIST SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDA OneStep NIST SP 800-56Cr1",
            "cavpCertName": "Cert. #A2439",
            "properties": "Function: One-Step KDF (Session Key) SHA Size: 256",
            "reference": "NIST SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KTS",
            "cavpCertName": "Cert. #A2435",
            "properties": "Function: Wrap, Unwrap Key Length: 256",
            "reference": "NIST SP 800-38F"
          },
          {
            "algorithm": "KTS",
            "cavpCertName": "Cert. #A2435 Cert. #A2438",
            "properties": "AES Function: Encrypt, Decrypt HMAC Function: Generate HMAC Key Length: 256 SHA Size: 256",
            "reference": "NIST SP 800-38F; FIPS 197; FIPS 198-1"
          },
          {
            "algorithm": "RSA Signature Verification",
            "cavpCertName": "Cert. #A2440 5",
            "properties": "Function: Signature Verification (PKCS PSS) Key Length: 2048 SHA Size: 256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "Cert. #A2441",
            "properties": "SHA Size: 224",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "Cert. #A2441",
            "properties": "SHA Size: 256",
            "reference": "FIPS 180-4"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Instructs the PSD to generate its Unique ECDSA P-256 Operation Key pair or the Unique ECDSA P-256 Debit Key pair.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00BD + Signed Key Record with the parameters for use in the generation of the private and public key values.",
            "name": "Generate PSD Key",
            "outputs": "PSD Certificate Request block after the key has been generated or an error condition has been detected",
            "rolesSspAccess": "Cryptographic Officer - Operation Private/Public Keys: G - Or Debit Private/Public Keys: G - DRBG Working State: E, G - Vendor Key: E - KEK: E - KAK: E",
            "secFunImpl": "ECDSA P-256/P- 224 KeyGen, Hash-DRBG, AES 256, HMAC-SHA- 256, CKG"
          },
          {
            "description": "Instructs the PSD to generate an AES 256-bit and a HMAC 256-bit session key via NIST SP 800-56A and NIST SP 800-56C.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00C3 + Signed Key Block with an ECDH key for generating the shared secret key.",
            "name": "Generate Session Key",
            "outputs": "Status bits, Session Key",
            "rolesSspAccess": "Cryptographic Officer - DRBG Working State: E, G - Shared Secret: G, E - ECC-CDH PSD KAS Private Key: G, E - Operation Private Key: E, Session - Authentication Key: G, E - Or Session Privacy Key: G, E - KEK: E, KAK: E - Certificate Key: E, ECC-CDH - Infrastructure KAS Public Key: E - ECC-CDH PSD KAS Public Key: G, E, R",
            "secFunImpl": "Hash-DRBG, NIST SP 800-56A KAS- SSC, NIST SP 800- 56C KDA, ECDSA P-256 SigVer, AES KW 256, HMAC- SHA-256 Or AES 256, CKG"
          },
          {
            "description": "Instructs the PSD to load the (ECDSA P-256) Certificate Key.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block: 0x203F00BA + Certificate Key",
            "name": "Load Certificate Key",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - KAK: E, Vendor Key: E - Certificate Key: W",
            "secFunImpl": "HMAC-SHA-256, ECDSA P-256 SigVer"
          },
          {
            "description": "Loads the Certificate Revocation List and the CRL version.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block: 0x203F00B8 + CRL",
            "name": "Load CRL",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - Download Key: E",
            "secFunImpl": "ECDSA P-256 SigVer"
          },
          {
            "description": "Instructs the PSD to load the (ECDSA P-256) Download Key Certificate.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00BB + Download Key",
            "name": "Load Download Key",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - KAK: E - Certificate Key: E - Download Key: W",
            "secFunImpl": "HMAC-SHA-256 ECDSA P-256 SigVer"
          },
          {
            "description": "The Crypto Officer instructs the PSD to load a signed key record containing an encrypted symmetric or private key.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00AD + Encrypted Secret Key",
            "name": "Load Encrypted Key",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - Debit Secret Key: W - Session Privacy Key: E - KEK: E - KAK: E - Certificate Key: E",
            "secFunImpl": "HMAC-SHA-256 AES KW 256 AES 256 ECDSA P-256 SigVer"
          },
          {
            "description": "Acknowledge that the generated PSD Key has been successfully registered and that the PSD can activate that key.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block: 0x203F00AE + Affirmation from server with Key Acknowledgement",
            "name": "Load Key Acknowledgement",
            "outputs": "N/A",
            "rolesSspAccess": "Cryptographic Officer - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 SigVer"
          },
          {
            "description": "Causes the PSD to transition to the PSD Operational lifecycle state.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B5 + parameter value",
            "name": "Load Parameters: Transition to Operational State",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Transitions the PSD from its Manufacturing lifecycle state to Base lifecycle state.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B5 + parameter value",
            "name": "Load Parameters: Transition to Base State",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Places the PSD in the Disabled lifecycle state. In the Disabled lifecycle state, further financial functions are prohibited.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B5 + parameter value",
            "name": "Load Parameters: Disable PSD",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Transition the PSD from Disabled lifecycle state to Operational lifecycle state.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B5 + parameter value",
            "name": "Load Parameters: Enable PSD",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Causes PSD to zeroize all plaintext cryptographic keys and CSPs, and then invalidates the PSD Application.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B5 + parameter value",
            "name": "Load Parameters: Reinitialize PSD",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Update utility that allows start of firmware download.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B5 + parameter value",
            "name": "Load Parameters: Software Update",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - SWAK: E - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Triggers event to have the PSD prepare for a multi-message transaction that must be completed successfully as a unit (atomic transaction).",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B5 + parameter value",
            "name": "Load Parameters: Transaction Start (Commit, Rollback)",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Causes PSD to zeroize all plaintext cryptographic keys and CSPs.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "None",
            "name": "Wipe PSD",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - KEK: Z - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Instructs the PSD to load the (ECDSA-P256) Vendor Key Certificate.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00BC + Vendor Key",
            "name": "Load Vendor Key",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - KAK: E - Manufacturing Key: E - Vendor Key: W",
            "secFunImpl": "HMAC-SHA-256, ECDSA P-256 SigVer"
          },
          {
            "description": "Instructs the PSD to process the Horizon Audit Response Block returned from the Pitney Bowes infrastructure.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B2 + Audit Response Block",
            "name": "Process Audit Response",
            "outputs": "Status Bits",
            "rolesSspAccess": "Cryptographic Officer - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Instructs the PSD to perform a postage value download operation.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B9",
            "name": "Process Postage Value Download",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "Cryptographic Officer - Certificate Key: E",
            "secFunImpl": "ECDSA P-256 Sig Ver"
          },
          {
            "description": "Instructs the PSD to complete the withdraw process.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B0",
            "name": "Process Withdraw Response",
            "outputs": "Status Bits",
            "rolesSspAccess": "Cryptographic Officer - Debit Private Key: E - Certificate Key: E",
            "secFunImpl": "ECDSA P-256/P- 224 Sig Ver"
          },
          {
            "description": "Instructs the PSD to prepare a signed Audit Request Block.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0007 - initiates an Audit Request",
            "name": "Audit Request",
            "outputs": "Audit block",
            "rolesSspAccess": "User - DRBG Working State: E, G - KEK:E - Operation Key: E",
            "secFunImpl": "Hash-DRBG, AES- 256, ECDSA P-256 SigGen"
          },
          {
            "description": "Instructs the PSD to clear the Upload Interval Timer.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block: 0x204E0032 - clears the upload interval",
            "name": "Clear Upload Interval",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "User - None",
            "secFunImpl": "None"
          },
          {
            "description": "Instructs the PSD to create a debit certificate in the format defined by the Flex Debit Certificate Template.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0029 + Postal data for signing",
            "name": "Create Debit Certificate",
            "outputs": "Status bits, Signed data block",
            "rolesSspAccess": "User - DRBG Working State: E, G - KEK: E - Debit Secret Key: E, or Debit Private Key: E or Mail Piece Key: E",
            "secFunImpl": "DRBG, AES 256, ECDSA P-256/P- 224 SigGen or HMAC-SHA-256"
          },
          {
            "description": "Instructs the PSD to create a Postage Value Download Request Block.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0033 - initiates an PVD Request",
            "name": "Create PVD Request",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "User - DRBG Working State: E, G - KEK: E - Operation Key: E",
            "secFunImpl": "Hash-DRBG, AES 256, ECDSA P-256 SigGen"
          },
          {
            "description": "Performs post-debit housekeeping and prepare for the next Debit operation by precomputing the \u0027r\u0027 signature parameter if necessary",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0008 + data to perform a debit transaction",
            "name": "Finalize Debit",
            "outputs": "Status Bits",
            "rolesSspAccess": "User - None",
            "secFunImpl": "None"
          },
          {
            "description": "Logs the permit and the data capture recovery information.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E002B",
            "name": "Log Permit",
            "outputs": "Status Bits and Register Values",
            "rolesSspAccess": "User - None",
            "secFunImpl": "None"
          },
          {
            "description": "Authenticates the User with the PSD. If the authentication is successful, the PSD allows debit operations.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E002F + Login data",
            "name": "Login Request",
            "outputs": "Status Bits with login success or failure",
            "rolesSspAccess": "User - KEK: E - Password: E",
            "secFunImpl": "AES 256"
          },
          {
            "description": "Pre- computes the \u0027r\u0027 signature component for the PSD Key signature (ECDSA). This message is used for countries whose debit certificate is signed by an ECDSA key.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0009",
            "name": "Precompute r for Debit",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "User - DRBG Working State: E, G - KEK: E",
            "secFunImpl": "Hash-DRBG, AES- 256"
          },
          {
            "description": "Loads a flex debit template into the PSD. The flex debit template defines the indicia content for debit operations.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B4 + debit template data",
            "name": "Process Flex Debit Block",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "User - Download Key: E",
            "secFunImpl": "ECDSA P-256 SigVer"
          },
          {
            "description": "Generates a signature on the included hash.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0030 + Data to be hashed",
            "name": "Sign Transaction Data",
            "outputs": "Digital Signature",
            "rolesSspAccess": "User - DRBG Working State: E, G - KEK: E - Operation Key: E",
            "secFunImpl": "Hash-DRBG, AES 256, ECDSA P-256 SigGen"
          },
          {
            "description": "Validates the included hash.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x203F00B3 + data and hash to be verified",
            "name": "Verify Hash Block",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "User - Download Key: E",
            "secFunImpl": "ECDSA P-256 SigVer"
          },
          {
            "description": "Verifies the hash of the transaction data for a mail piece.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0031 + Data to be verified",
            "name": "Verify Mail Piece Data",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "User - MailPiece Key: E",
            "secFunImpl": "HMAC-SHA-256"
          },
          {
            "description": "Instructs the PSD to initiate a Withdrawal operation.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E000A",
            "name": "Withdraw Request",
            "outputs": "Status bits (Success or Error ID)",
            "rolesSspAccess": "User - Operation Key: E",
            "secFunImpl": "ECDSA P-256 SigGen"
          },
          {
            "description": "Returns an 8-byte nonce (random number) from the DRBG.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0003",
            "name": "Get Challenge",
            "outputs": "Nonce (8 bytes from DRBG)",
            "rolesSspAccess": "Unauthenticated - DRBG Working State: E, G - KEK: E",
            "secFunImpl": "Hash-DRBG, AES- 256"
          },
          {
            "description": "Returns the drift and GMT offset values.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0020",
            "name": "Get Clock Offsets",
            "outputs": "Status bits, + value of offsets",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Returns the loaded flex debit template.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E002E",
            "name": "Get Flex Debit Template",
            "outputs": "Status bits + Debit Template",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Returns the real time clock value with only the drift correction applied.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E001C",
            "name": "Get GMT Time",
            "outputs": "Time YYYYMMDDhhmmss",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Returns a list of all active keys stored in the PSD.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0004",
            "name": "Get Key List",
            "outputs": "Key List",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Returns the real time clock with drift and GMT offsets applied.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E001E",
            "name": "Get Local Time",
            "outputs": "Time YYYYMMDDhhmmss",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Returns device versions and unique device serial number.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E002D",
            "name": "Get ML Attributes",
            "outputs": "DAL Layer versions",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Returns parameter values stored in the PSD. The Host can request individual parameter IDs or all the Parameters in the PSD.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0005",
            "name": "Get Parameters",
            "outputs": "Status bits + parameter information",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Returns PSD attribute data, including firmware and hardware versions.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0021",
            "name": "Get PSD Attributes",
            "outputs": "PSD versioning information",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Returns PSD status information that includes the module\u0027s mode of operation indicator.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0022",
            "name": "Get PSD Status",
            "outputs": "Status of the PSD",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Retrieves the versions of the hardware, software and cryptographic libraries.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0037",
            "name": "Get PSD Versions",
            "outputs": "PSD Versioning information (includes HW ID and FW versions)",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Retrieves the Withdraw Certificate created at the successful completion of the Withdraw process.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0034",
            "name": "Get Withdraw Certificate",
            "outputs": "Signed withdrawal certificate",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "The User sends this message to request that the PSD perform a diagnostic test.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0026",
            "name": "Perform Diagnostic Test",
            "outputs": "Status bits (Success or Error ID",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "The User sends this command to request the PSD perform its diagnostic processing.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0024",
            "name": "Perform Full Diagnostics",
            "outputs": "Status bits (Success or Error ID",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Returns Log Data stored in the PSD.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0028",
            "name": "Read Log File",
            "outputs": "Log data",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Restarts the PSD application. The PSD will run its power up tests.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0006",
            "name": "Reboot PSD",
            "outputs": "N/A",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Sets the real time clock in the PSD. The real time clock can only be set when the PSD is in manufacturing state.",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E0002 + clock data YYYYMMDDhhmmss",
            "name": "Set Clock",
            "outputs": "Status bits (Success or Error ID",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          },
          {
            "description": "Sets the GMT offset in the PSD. The GMT offset is a combination of time zone offset and daylight savings time offset (if applicable).",
            "indicator": "Approved Service ID, Success or Error ID",
            "inputs": "Command Block:0x204E001D + 4-byte offset",
            "name": "Set GMT Offset",
            "outputs": "Time with offset",
            "rolesSspAccess": "Unauthenticated - None",
            "secFunImpl": "None"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [
          {
            "description": "Identity-based. Allows the Cryptographic Officer to authenticate themselves. Sets up a remote session with CO.",
            "mechanism": "ECDSA P-256 SigVer (FIPS 186-4) (A2437)",
            "name": "Cryptographic Officer (CO)",
            "perMinute": "The module can execute at most 17.85 ECDSA verifications per second. Therefore, the probability of a successful random attempt in a one- minute period is 1 in 3.2 x 10^35 for ECDSA, which is far less than 1 in 100,000.",
            "strength": "128 bits"
          },
          {
            "description": "Identity-based. Allows the User to authenticate to the module.",
            "mechanism": "Challenge response mechanism.",
            "name": "User",
            "perMinute": "The module can execute at most 40 password authentication attempts per minute. Therefore, the probability of a successful random attempt in a one- minute period is 1 in 8.5 x 10^36, which is far less than 1 in 100,000.",
            "strength": "128 bits"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-ECB (Cert. #A2435)",
            "condition": "Power-up, Periodically \u0026 on-demand",
            "details": "Encrypt and Decrypt KATs",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "KAT",
            "testProps": "256-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-KW (Cert. #A2435)",
            "condition": "Power-up, Periodically \u0026 on-demand",
            "details": "Encrypt and Decrypt KATs",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "KAT",
            "testProps": "256-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA (Cert. #A2437)",
            "condition": "Power-up, Periodically \u0026 on-demand",
            "details": "Signature Generation and Verification KATs",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Hash DRBG (Cert. #A2436)",
            "condition": "Power-up, Periodically \u0026 on-demand",
            "details": "Instantiate and Generate KAT",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC (Cert. #A2438)",
            "condition": "Power-up, Periodically \u0026 on-demand",
            "details": "HMAC-SHA-256 KAT",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "KAT",
            "testProps": "256-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC SP800-56Ar3 (Cert. #A2439)",
            "condition": "Power-up, Periodically \u0026 on-demand",
            "details": "KAS-ECC Shared Secret Computation KAT per IG D. F",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA OneStep SP800-56Cr1 (Cert. #A2439)",
            "condition": "Power-up, Periodically \u0026 on-demand",
            "details": "KDA KAT",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "KAT",
            "testProps": "256-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA (Cert. #A2440)",
            "condition": "Power-up, Periodically \u0026 on-demand",
            "details": "Signature Verification KAT",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "KAT",
            "testProps": "2048-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Firmware Load Test",
            "condition": "During Firmware Updates",
            "details": "Firmware load test occurs during \u0027Load Parameters Software Update \u0027 service",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "Digital Signature Verification",
            "testProps": "ECDSA P- 256",
            "type": "SW/FW Load"
          },
          {
            "algorithmOrTest": "Public Key Validation",
            "condition": "During key agreement",
            "details": "Occurs during KAS upon receipt of the connected host application public key",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "N/A",
            "testProps": "P-256",
            "type": "Critical Function"
          },
          {
            "algorithmOrTest": "ECC Pairwise Consistency Test",
            "condition": "During key agreement",
            "details": "Pairwise consistency test",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "PCT",
            "testProps": "P-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA Key Generation",
            "condition": "After key pair generation",
            "details": "Pairwise consistency test",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "PCT",
            "testProps": "P-256",
            "type": "PCT"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [],
        "found": false,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [
          {
            "inspectFreq": "During installation, re-installation, decommissioning, and servicing.",
            "inspectGuidance": "Inspect device for obvious damage or other evidence of tamper.",
            "mechanism": "Tamper Evidence"
          },
          {
            "inspectFreq": "Every 30 days",
            "inspectGuidance": "The module HW status flag is submitted every 30 days to the PB servers to check for tamper.",
            "mechanism": "Tamper Detection"
          }
        ],
        "found": true,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Only Approved services are supported",
            "name": "Approved Mode",
            "statusIndicator": "Approved Mode Status Flag returns \u00270\u0027.",
            "type": "Approved"
          },
          {
            "description": "Non-Approved Configuration",
            "name": "Non-Approved Mode",
            "statusIndicator": "Approved Mode Status Flag returns \u00271\u0027.",
            "type": "Non-Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "Reset Input, RTC, Commands.",
            "logicalInterface": "Control Input",
            "physicalPort": "G13, J5, J13, K5, K13"
          },
          {
            "data": "Serial UART and USB interfaces for inputting postal relevant data items, configuration or sensitive security parameters (SSPs).",
            "logicalInterface": "Control Input Data Input",
            "physicalPort": "B7, F13, F14, R10, R11, R12, R13, T10, T11, T12, T13, U10, U11, U12, U13, V10, V11, V12, V13"
          },
          {
            "data": "Serial UART and USB interfaces for outputting postal relevant data items, sensitive security parameters (SSPs), error codes and module status.",
            "logicalInterface": "Data Output, Status Output",
            "physicalPort": "A7, F13, F14, P4, P6, P7, P8, P9, P10, P11, P13, P14, P15, P16, P17, P18, R10, R11, R12, R13, R14, R15, R16, R17, R18, T10, T11, T12, T13, T15, T16, T17, T18, U10, U11, U12, U13, U16, U17, U18, V10, V11, V12, V13, V16, V17, V18"
          },
          {
            "data": "USB Detect, Reset Output, module status.",
            "logicalInterface": "Status Output",
            "physicalPort": "G5, H13, M4, N14, N17, N18"
          },
          {
            "data": "Power input.",
            "logicalInterface": "Power",
            "physicalPort": "C3, D3, F6, F7, F8, F9, F10, F11, F12, G6, G12, H5, H6, H12, J6, J12, K6, K12, L6, L12, M6, M12, N6, N7, N8, N9, N10, N11, N12"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "Digital Signature (ECDSA P-256, authenticated with Vendor, Download or Certificate Keys)",
            "name": "Cryptographic Officer (CO)",
            "operatorType": "Cryptographic Officer",
            "type": "Identity"
          },
          {
            "authMethodList": "Uniquely Assigned ID in conjunction with 128-bit password",
            "name": "User",
            "operatorType": "User",
            "type": "Identity"
          },
          {
            "authMethodList": "None",
            "name": "Unauthenticated",
            "operatorType": "Unauthenticated",
            "type": "N/A"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "3",
            "section": "1",
            "title": "General"
          },
          {
            "level": "3",
            "section": "2",
            "title": "Cryptographic Module Specification"
          },
          {
            "level": "3",
            "section": "3",
            "title": "Cryptographic Module Interfaces"
          },
          {
            "level": "3",
            "section": "4",
            "title": "Roles, Services, and Authentication"
          },
          {
            "level": "3",
            "section": "5",
            "title": "Software/Firmware Security"
          },
          {
            "level": "N/A",
            "section": "6",
            "title": "Operational Environment"
          },
          {
            "level": "3",
            "section": "7",
            "title": "Physical Security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-Invasive Security"
          },
          {
            "level": "3",
            "section": "9",
            "title": "Sensitive Security Parameter Management"
          },
          {
            "level": "3",
            "section": "10",
            "title": "Self-Tests"
          },
          {
            "level": "3",
            "section": "11",
            "title": "Life-Cycle Assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of Other Attacks"
          },
          {
            "level": "3",
            "section": "Overall Level",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "Firmware Integrity of Bootloader",
            "details": "RSA 2048 Digital Signature Verification",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "RSA Signature Verification",
            "testProps": "RSA 2048 (Cert. #A2440)",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "Firmware Integrity of Firmware",
            "details": "ECDSA P-256 Digital Signature Verification",
            "indicator": "Success: No Error Code; Failure: Error Code",
            "testMethod": "ECDSA Signature Verification",
            "testProps": "ECDSA P-256 (Cert. #A2437)",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "NVRAM",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Input (Encrypted)",
            "sfiAlgo": "Key Transport",
            "source": "Outside the Module"
          },
          {
            "dest": "Outside the Module",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Output (Encrypted)",
            "sfiAlgo": "Key Transport",
            "source": "NVRAM"
          },
          {
            "dest": "SRAM",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Input (Plaintext)",
            "sfiAlgo": "KAS (dhEphem C(2e, 0s, FFC DH))",
            "source": "Outside the Module"
          },
          {
            "dest": "Outside the Module",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Output (Plaintext)",
            "sfiAlgo": "KAS (dhEphem C(2e, 0s, FFC DH))",
            "source": "SRAM"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Service",
            "method": "Reinitialize PSD",
            "operatorId": "Host device calls the service",
            "rationale": "Forces a zeroization of the KEK (Key Encryption Key) and NVRAM memory components. N.B. This process is irreversible."
          },
          {
            "description": "Service",
            "method": "Wipe PSD",
            "operatorId": "Host device calls the service",
            "rationale": "Forces a zeroization of the KEK (Key Encryption Key) and NVRAM memory components. N.B. This process is irreversible."
          },
          {
            "description": "Automatic",
            "method": "End of session",
            "operatorId": "N/A",
            "rationale": "Firmware programmed zeroization of ephemeral SSPs used in secure session"
          },
          {
            "description": "Physical",
            "method": "Removal of Battery/Tamper",
            "operatorId": "Removal of battery power or a tamper event",
            "rationale": "Forces a zeroization of the KEK (Key Encryption Key) and removal of power from battery-backed memory."
          },
          {
            "description": "Automatic",
            "method": "Automatically",
            "operatorId": "N/A",
            "rationale": "Immediately after use."
          },
          {
            "description": "Description",
            "method": "Name",
            "operatorId": "Type - Category",
            "rationale": "Size - Strength"
          },
          {
            "description": "Protect all keys stored internally or in NVM",
            "method": "KEK (Key Encryption Key)",
            "operatorId": "Symmetric Key - CSP",
            "rationale": "256-bit"
          },
          {
            "description": "Backup KEK",
            "method": "KEK\u0027 (Backup Key Encryption Key)",
            "operatorId": "Symmetric Key - CSP",
            "rationale": "256-bit"
          },
          {
            "description": "Authenticate keys externally stored in NVM",
            "method": "KAK (Key Authentication Key)",
            "operatorId": "Symmetric Key - CSP",
            "rationale": "256-bit"
          },
          {
            "description": "Digitally sign debit records (indicia data)",
            "method": "Debit Private Key",
            "operatorId": "Asymmetric Private Key - CSP",
            "rationale": "112-bit or 128-bit"
          },
          {
            "description": "Digitally authenticate debit records (indicia data)",
            "method": "Debit Secret Key",
            "operatorId": "Symmetric Key - CSP",
            "rationale": "256-bit"
          },
          {
            "description": "Authenticate to the communicating infrastructure",
            "method": "Operation Private Key",
            "operatorId": "Asymmetric Private Key - CSP",
            "rationale": "128-bit"
          },
          {
            "description": "Used to authenticate messages sent between the Host and the PSD",
            "method": "Session Authentication Key",
            "operatorId": "Symmetric Key - CSP",
            "rationale": "256-bit"
          },
          {
            "description": "Encrypt data or wrap keys transported to infrastructure",
            "method": "Session Privacy Key",
            "operatorId": "Symmetric Key - CSP",
            "rationale": "256-bit"
          },
          {
            "description": "Ephemeral ECC-CDH private key used in KAS",
            "method": "ECC-CDH PSD KAS Key",
            "operatorId": "Asymmetric Private Key - CSP",
            "rationale": "256-bit"
          },
          {
            "description": "Used to derive session keys",
            "method": "Shared Secret",
            "operatorId": "Shared Secret - CSP",
            "rationale": "256 bits"
          },
          {
            "description": "Instantiate the DRBG",
            "method": "Entropy Input",
            "operatorId": "Entropy - CSP",
            "rationale": "512 bits"
          },
          {
            "description": "Seeding the DRBG",
            "method": "DRBG Seed",
            "operatorId": "Entropy - CSP",
            "rationale": "1024 bits"
          },
          {
            "description": "Internal working state of the DRBG",
            "method": "DRBG Working State",
            "operatorId": "N/A - CSP",
            "rationale": "N/A"
          },
          {
            "description": "Authenticate stored mail piece data",
            "method": "Mail Piece Key",
            "operatorId": "Symmetric Key - CSP",
            "rationale": "256-bit"
          },
          {
            "description": "Authenticate User Role",
            "method": "Password",
            "operatorId": "N/A - CSP",
            "rationale": "128-bit"
          },
          {
            "description": "Used to verify loaded application code",
            "method": "SWAK (Software Authentication Key)",
            "operatorId": "Asymmetric Public Key - PSP",
            "rationale": "128-bit"
          },
          {
            "description": "Validates Vendor Certificate",
            "method": "Manufacturing Key",
            "operatorId": "Asymmetric Public Key - PSP",
            "rationale": "128-bit"
          },
          {
            "description": "Authenticates CO role",
            "method": "Vendor Key",
            "operatorId": "Asymmetric Public Key - PSP",
            "rationale": "128-bit"
          },
          {
            "description": "Authenticates CO role. Validates Authority Data, including other public keys",
            "method": "Certificate Key",
            "operatorId": "Asymmetric Public Key - PSP",
            "rationale": "128-bit"
          },
          {
            "description": "Authenticates CO role",
            "method": "Download Key",
            "operatorId": "Asymmetric Public Key - PSP",
            "rationale": "128-bit"
          },
          {
            "description": "ECDH public counterpart received as part of tKAS",
            "method": "ECC-CDH Infrastructure KAS Public Key",
            "operatorId": "Asymmetric Public Key - PSP",
            "rationale": "128-bit"
          },
          {
            "description": "ECDH public key transmitted as part of KAS",
            "method": "ECC-CDH PSD KAS Public Key",
            "operatorId": "Asymmetric Public Key - PSP",
            "rationale": "128-bit"
          },
          {
            "description": "Output to the CO. Used to allow the CO to authenticate the debit records",
            "method": "Debit Public Key",
            "operatorId": "N/A - PSP",
            "rationale": "112-bit or 128-bit"
          },
          {
            "description": "Output to the CO. Used to allow the CO to authenticate the PSD",
            "method": "Operation Public Key",
            "operatorId": "Asymmetric Public Key - PSP",
            "rationale": "128-bit"
          },
          {
            "description": "Input - Output",
            "method": "Name",
            "operatorId": "Storage Duration",
            "rationale": "Storage"
          },
          {
            "description": "N/A",
            "method": "KEK (Key Encryption Key)",
            "operatorId": "N/A",
            "rationale": "NVRAM: Plaintext"
          },
          {
            "description": "N/A",
            "method": "KEK\u0027 (Backup Key Encryption Key)",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "N/A",
            "method": "KAK (Key Authentication Key)",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "N/A",
            "method": "Debit Private Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "Input (Encrypted)",
            "method": "Debit Secret Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "N/A",
            "method": "Operation Private Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "N/A",
            "method": "Session Authentication Key",
            "operatorId": "For the life of the Secure Session",
            "rationale": "SRAM: Plaintext"
          },
          {
            "description": "N/A",
            "method": "Session Privacy Key",
            "operatorId": "For the life of the Secure Session",
            "rationale": "SRAM: Plaintext"
          },
          {
            "description": "N/A",
            "method": "ECC-CDH PSD KAS Key",
            "operatorId": "Until Use",
            "rationale": "SRAM: Plaintext"
          },
          {
            "description": "N/A",
            "method": "Shared Secret (Z)",
            "operatorId": "Until Use",
            "rationale": "SRAM: Plaintext"
          },
          {
            "description": "N/A",
            "method": "Entropy Input",
            "operatorId": "Until Use",
            "rationale": "SRAM: Plaintext"
          },
          {
            "description": "N/A",
            "method": "DRBG Seed",
            "operatorId": "Until Use",
            "rationale": "SRAM: Plaintext"
          },
          {
            "description": "N/A",
            "method": "DRBG Working State",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "N/A",
            "method": "Mail Piece Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "N/A",
            "method": "Password",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "N/A",
            "method": "SWAK (Software Authentication Key)",
            "operatorId": "N/A",
            "rationale": "Plaintext"
          },
          {
            "description": "N/A",
            "method": "Manufacturing Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "Input (Encrypted)",
            "method": "Vendor Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "Input (Encrypted)",
            "method": "Certificate Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "Input (Encrypted)",
            "method": "Download Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "Input (Plaintext)",
            "method": "ECC-CDH Infrastructure KAS Public Key",
            "operatorId": "Until Use",
            "rationale": "SRAM: Plaintext"
          },
          {
            "description": "Output (Plaintext)",
            "method": "ECC-CDH PSD KAS Public Key",
            "operatorId": "Until Use",
            "rationale": "SRAM: Plaintext"
          },
          {
            "description": "Output (Encrypted)",
            "method": "Debit Public Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          },
          {
            "description": "Output (Encrypted)",
            "method": "Operation Public Key",
            "operatorId": "N/A",
            "rationale": "NVRAM: Encrypted"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "On-chip memory that is zeroized on tamper detection.",
            "name": "Battery Backed RAM Register (BBREG)",
            "persistance": "Static"
          },
          {
            "description": "On-chip memory that is zeroized on tamper detection.",
            "name": "NVRAM",
            "persistance": "Static"
          },
          {
            "description": "Volatile memory",
            "name": "SRAM",
            "persistance": "Dynamic"
          },
          {
            "description": "Persistent long-term storage",
            "name": "FLASH",
            "persistance": "Static"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [
          {
            "features": "ARM926EJ-S \u2122 Processor Core with 16KB Data Cache and 32KB Instruction Cache",
            "fwVersion": "PSD Application: 22.01.000D \u0026 22.01.000F Device Abstraction Layer (DAL): 02.01.000F \u0026 02.01.0013",
            "hwVersion": "Maxim Integrated MAX32590 DeepCover Secure Microcontroller - Revision B4",
            "modelPartNum": "X5 Postal Security Device (PSD)",
            "processors": "Maxim Integrated MAX32590 DeepCover Secure Microcontroller"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "Key Type: Asymmetric",
            "implName": "N/A",
            "name": "CKG - Asymmetric",
            "reference": "NIST SP 800-133r2 Section 4 and Section 5.1 - The unmodified output of the DRBG is used for generation of asymmetric keys."
          },
          {
            "algoPropList": "Key Type: Symmetric",
            "implName": "N/A",
            "name": "CKG - Symmetric",
            "reference": "NIST SP 800-133r2 Section 4 and Section 6.1 - The unmodified output of the DRBG is used for generation of symmetric keys."
          },
          {
            "algoPropList": "Key Type: Asymmetric",
            "implName": "N/A",
            "name": "CKG - Establishment",
            "reference": "NIST SP 800-133r2 Section 4 and Section 5.2 - The unmodified output of the DRBG is used for key pair generation for key establishment."
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 4
          },
          "ECDH": {
            "ECDH": 3
          },
          "ECDSA": {
            "ECDSA": 69
          }
        },
        "FF": {
          "DH": {
            "DH": 5
          },
          "DSA": {
            "DSA": 2
          }
        },
        "RSA": {
          "RSA 2048": 4
        }
      },
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "MAC": {
          "MAC": 3
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 12,
          "P-256": 88
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#2": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 256": 7,
          "AES- 256": 3,
          "DRBG 1024": 1,
          "DRBG 512": 1,
          "HMAC- SHA-256": 1,
          "HMAC-SHA- 256": 2,
          "HMAC-SHA-256": 16,
          "RSA 2048": 4,
          "SHA-256": 1,
          "SHA2- 256": 1,
          "SHA2-224": 5,
          "SHA2-256": 6
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 3": 5
        }
      },
      "hash_function": {
        "SHA": {
          "SHA2": {
            "SHA-256": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 56
        },
        "RNG": {
          "RBG": 3
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 8,
          "FIPS 1403": 1,
          "FIPS 180-4": 2,
          "FIPS 186-4": 9,
          "FIPS 186-5": 1,
          "FIPS 197": 3,
          "FIPS 198-1": 2,
          "FIPS186-4": 4
        },
        "ISO": {
          "ISO/IEC 19790": 2
        },
        "NIST": {
          "NIST SP 800-38F": 6,
          "NIST SP 800-56A": 4,
          "NIST SP 800-56C": 2,
          "NIST SP 800-90A": 3
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 12,
            "AES-": 3
          },
          "CAST": {
            "CAST": 16
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 2
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 7,
            "HMAC-SHA-256": 8
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 9
        },
        "IBM": {
          "SSC": 1
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "AES-KWA2435",
        "SHA2-224A2441",
        "ECDSA SigGen (FIPS186-4)A2437",
        "Hash DRBGA2436",
        "RSA SigVer (FIPS186-4)A2440",
        "AES-ECBA2435",
        "ECDSA KeyGen (FIPS186-4)A2437",
        "SHA2-256A2441",
        "HMAC-SHA2-256A2438",
        "KDA OneStep Sp800-56Cr1A2439",
        "KAS-ECC-SSC Sp800-56Ar3A2439",
        "AES-CBCA2435",
        "ECDSA SigVer (FIPS186-4)A2437"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A2438",
        "#A2436",
        "#A2435",
        "#A2437",
        "#A2441",
        "#A2440",
        "#A2439"
      ]
    },
    "policy_metadata": {
      "/Author": "Hawes, David J. (Fed)",
      "/CreationDate": "D:20241217074233-08\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20241217074233-08\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 789518,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 36
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "8732e8086cffc0a3e4843e63c3a77722db4e2b6b8ecef6cf0366475f35071b03",
      "source_hash": "3d3c5d28a36155b32e4475cdc05d3ecc96c83bea2798a5f60ff967514a225c35",
      "txt_hash": "51cc1f41c3e0c39661972259b977b9429fde1c626d6beaa4edf35cead42dca08"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim Validation; When operated in approved mode; No assurance of the minimum strength of generated SSPs (e.g., keys).",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/December 2024_060125_0402.pdf",
    "date_sunset": "2029-12-23",
    "description": "The X5 Postal Security Device (PSD) is a single-chip cryptographic module designed by Pitney Bowes, Inc. (PB) to conform with FIPS 140-3 Security Level 3 requirements. The device includes the Maxim Integrated MAX32590 DeepCover Secure Microcontroller hardware component. The PSD Application and DAL are compiled into a single firmware. The X5 Postal Security Device (PSD) provides cryptographic services to a host device (i.e., Digital Postage Meter), to support postage evidence in the form of an indicium. A PSD provides protection that includes ensuring the secrecy of sensitive security parameters (SSPs) such as cryptographic keys and providing data integrity protection for funds relevant data items (FRDIs) such as accounting data. SSPs and FRDIs reside inside the strong physical protections of the X5 Postal Security Device (PSD).",
    "embodiment": "Single Chip",
    "exceptions": [
      "Operational environment: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": "PSD Application: 22.01.000D \u0026 22.01.000F Device Abstraction Layer (DAL): 02.01.000F \u0026 02.01.00013",
    "historical_reason": null,
    "hw_versions": "Maxim Integrated MAX32590 DeepCover Secure Microcontroller - Revision B4",
    "level": 3,
    "mentioned_certs": {},
    "module_name": "X5 Postal Security Device (PSD)",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-12-24",
        "lab": "Penumbra Security, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Pitney Bowes, Inc.",
    "vendor_url": "http://www.pitneybowes.com"
  }
}