Astro Subscriber Motorola Advanced Crypto Engine (MACE) - Security Level 2

Certificate #4834

Webpage information ?

Status active
Validation dates 11.10.2024
Sunset date 10-10-2029
Standard FIPS 140-3
Security level 2
Type Hardware
Embodiment Single Chip
Caveat When installed, initialized and configured as specified in Section 11 of Security Policy. No assurance of the minimum strength of generated SSPs
Exceptions
  • Roles, services, and authentication: Level 3
  • Software/Firmware security: Level 3
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Self-tests: Level 3
  • Life-cycle assurance: Level 3
  • Mitigation of other attacks: N/A
  • Documentation requirements: N/A
  • Cryptographic module security policy: N/A
Description The MACE cryptographic processor is used in security modules embedded in Motorola's Astro family of radio systems products. It provides secure voice and data capabilities as well as APCO Over-The-Air-Rekeying and advanced key management.
Version (Hardware) P/Ns 5185912Y03, 5185912Y05, 5185912T05
Version (Firmware) R01.13.04 with [AES256 R01.00.00 and AES256 R01.00.01]
Vendor Motorola Solutions, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy ?

Symmetric Algorithms
AES, AES256, AES-256, E2, HMAC
Asymmetric Algorithms
RSA-2048, ECDH, ECDSA, Diffie-Hellman, DH
Schemes
MAC, Key Agreement
Randomness
DRBG
Elliptic Curves
P-384
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM

Security level
Level 2, level 2, Level 1

Standards
FIPS 140-3, FIPS 186-2, FIPS 186-4, FIPS 186-5, FIPS140-3, FIPS PUB 140-3, SP 800-90A, SP 800-56A, ISO/IEC 24759, ISO/IEC 19790

File metadata

Subject FIPS 140-2 Security Policy Template
Author Brown, Bethany
Creation date D:20241008103828-05'00'
Modification date D:20241008103828-05'00'
Pages 30
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

References

Outgoing
  • 396 - historical - nShield F3 PCI[1], nShield F3 PCI Ultrasign[2], nCipher F3 PCI for NetHSM[3], nShield F3 PCI Ultrasign 32[4], payShield PCI[5], payShield Ultra PCI[6], payShield Ultra PCI for NetHSM[7] and nShield Lite[8]
  • 2266 - historical - CHN-II
  • 817 - historical - DPHx Radio with LZA0577 or LZA0577/LZA0578 Cryptographic Module
  • 2399 - historical - Dell SonicWALL NSA Series 2600, 3600, 4600, 5600

Heuristics ?

No heuristics are available for this certificate.

References ?

Updates ?

  • 14.10.2024 The certificate was first processed.
    New certificate

    A new FIPS 140 certificate with the product name was processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4834,
  "dgst": "42e030263323a3e5",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA2-384HMAC 1796",
        "AES-ECBA2262",
        "SHA2-384SHS 2399",
        "AES-KWA2264",
        "RSA SigVer (FIPS186-2)RSA 396",
        "ECDSA KeyGen (FIPS186-4)A655",
        "RSA SigVer (FIPS186-5)A5253",
        "Counter DRBGA2265",
        "AES-CFB8A2260",
        "SHA2-256SHS 817",
        "AES-OFBA2262",
        "KAS-ECC Sp800-56Ar3A2266",
        "AES-CBCA2262",
        "AES-GCMA2262"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "01.13.04",
        "01.00.00",
        "01.00.01"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "2266",
          "2399",
          "396",
          "817"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "2266",
          "2399",
          "396",
          "817"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "2266",
        "2399",
        "396",
        "817"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 5
          },
          "ECDSA": {
            "ECDSA": 9
          }
        },
        "FF": {
          "DH": {
            "DH": 5,
            "Diffie-Hellman": 10
          }
        },
        "RSA": {
          "RSA-2048": 4
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 21
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 15
        },
        "GCM": {
          "GCM": 9
        },
        "OFB": {
          "OFB": 14
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 4
        },
        "MAC": {
          "MAC": 3
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-384": 8
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1796": 2,
          "#2": 3,
          "#2262": 2,
          "#2264": 1,
          "#2265": 3,
          "#2266": 1,
          "#2399": 1,
          "#396": 3,
          "#817": 5
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 256": 2,
          "AES Cert. #2264": 1,
          "AES [197": 8,
          "AES \u2013 GCM (Cert. #2262": 2,
          "AES-256": 22,
          "AES256": 4,
          "DRBG Cert. #2265": 3,
          "HMAC (Cert. #1796": 1,
          "HMAC 1796": 2,
          "HMAC [198": 1,
          "RSA 396": 1,
          "SHA2-256": 5,
          "SHA2-384": 5,
          "SHS 2399": 1,
          "SHS 817": 1,
          "SHS [180": 3
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 2": 8,
          "level 2": 2
        }
      },
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 18
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 11,
          "FIPS 186-2": 2,
          "FIPS 186-4": 1,
          "FIPS 186-5": 1,
          "FIPS PUB 140-3": 1,
          "FIPS140-3": 1
        },
        "ISO": {
          "ISO/IEC 19790": 2,
          "ISO/IEC 24759": 4
        },
        "NIST": {
          "SP 800-56A": 1,
          "SP 800-90A": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 71,
            "AES-256": 22,
            "AES256": 4
          },
          "E2": {
            "E2": 2
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 5
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Brown, Bethany",
      "/CreationDate": "D:20241008103828-05\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20241008103828-05\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "/Subject": "FIPS 140-2 Security Policy Template",
      "pdf_file_size_bytes": 694390,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "file:///G:/My%20Drive/SPG_FIPS/Crypto%20Module%20Documentation/MACE/APX%20MACE/R01.13.02/CMVP%20Review%20Comments/CMVP%20Comments%20round%201%20-%20Jan08-2024/15d%20-%20Astro_Subscriber_SP_Level_2_V1.1_redlined_PP_JD_AR_JD_AR.docx%23_Toc155681314",
          "https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 30
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_garbage": false,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_pdf_hash": "ef713d704eea44c1274118153a2996d054348a44e31a5a047d6f21cc2638b4d1",
    "policy_txt_hash": "04d4c446b0473a415f5a35f886711aa6dae89aeb993da16a0761dc9769cd6a0e"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When installed, initialized and configured as specified in Section 11 of Security Policy. No assurance of the minimum strength of generated SSPs",
    "certificate_pdf_url": null,
    "date_sunset": "2029-10-10",
    "description": "The MACE cryptographic processor is used in security modules embedded in Motorola\u0027s Astro family of radio systems products. It provides secure voice and data capabilities as well as APCO Over-The-Air-Rekeying and advanced key management.",
    "embodiment": "Single Chip",
    "exceptions": [
      "Roles, services, and authentication: Level 3",
      "Software/Firmware security: Level 3",
      "Operational environment: N/A",
      "Non-invasive security: N/A",
      "Self-tests: Level 3",
      "Life-cycle assurance: Level 3",
      "Mitigation of other attacks: N/A",
      "Documentation requirements: N/A",
      "Cryptographic module security policy: N/A"
    ],
    "fw_versions": "R01.13.04 with [AES256 R01.00.00 and AES256 R01.00.01]",
    "historical_reason": null,
    "hw_versions": "P/Ns 5185912Y03, 5185912Y05, 5185912T05",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Astro Subscriber Motorola Advanced Crypto Engine (MACE) - Security Level 2",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-10-11",
        "lab": "UL VERIFICATION SERVICES INC",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Motorola Solutions, Inc.",
    "vendor_url": "http://www.motorolasolutions.com"
  }
}