Codan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 1 of 34 Codan - DTC MESH SDR Cryptography Module FIPS 140-3 Non-Proprietary Security Policy Document Version 2.0 August 28th, 2025 Prepared by: www.lightshipsec.com Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 2 of 34 Table of Contents 1 General .................................................................................................................................... 5 1.1 Overview............................................................................................................................ 5 1.2 Security Levels..................................................................................................................... 5 2 Cryptographic Module Specification............................................................................................ 6 2.1 Description ......................................................................................................................... 6 2.2 Tested and Vendor Affirmed Module Version and Identification ............................................... 8 2.3 Excluded Components.........................................................................................................10 2.4 Modes of Operation............................................................................................................10 2.5 Algorithms.........................................................................................................................10 2.6 Security Function Implementations ......................................................................................11 2.7 Algorithm Specific Information.............................................................................................12 2.8 RBG and Entropy ................................................................................................................12 2.9 Key Generation ..................................................................................................................12 2.10 Key Establishment.............................................................................................................12 2.11 Industry Protocols.............................................................................................................12 3 Cryptographic Module Interfaces...............................................................................................13 3.1 Ports and Interfaces............................................................................................................13 4 Roles, Services, and Authentication ...........................................................................................14 4.1 Authentication Methods......................................................................................................14 4.2 Roles.................................................................................................................................15 4.3 Approved Services ..............................................................................................................15 4.4 Non-Approved Services .......................................................................................................19 4.5 External Software/Firmware Loaded.....................................................................................19 5 Software/Firmware Security .....................................................................................................20 5.1 Integrity Techniques ...........................................................................................................20 5.2 Initiate on Demand.............................................................................................................20 6 Operational Environment..........................................................................................................21 6.1 Operational Environment Type and Requirements .................................................................21 7 Physical Security ......................................................................................................................22 7.1 Mechanisms and Actions Required .......................................................................................22 8 Non-Invasive Security ...............................................................................................................23 9 Sensitive Security Parameters Management...............................................................................24 9.1 Storage Areas.....................................................................................................................24 9.2 SSP Input-Output Methods ..................................................................................................24 Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 3 of 34 9.3 SSP Zeroization Methods.....................................................................................................25 9.4 SSPs ..................................................................................................................................26 10 Self-Tests...............................................................................................................................29 10.1 Pre-Operational Self-Tests .................................................................................................29 10.2 Conditional Self-Tests........................................................................................................29 10.3 Periodic Self-Test Information ............................................................................................31 10.4 Error States......................................................................................................................32 11 Life-Cycle Assurance ...............................................................................................................33 11.1 Installation, Initialization, and Startup Procedures ................................................................33 11.2 Administrator Guidance.....................................................................................................33 11.3 Non-Administrator Guidance..............................................................................................33 11.4 End of Life........................................................................................................................33 12 Mitigation of Other Attacks.....................................................................................................34 List of Tables Table 1: Security Levels............................................................................................................. 5 Table 2: SDR Product Line......................................................................................................... 6 Table 3: Tested Module Identification – Hardware ..................................................................... 9 Table 4: Modes List and Description .........................................................................................10 Table 5: Approved Algorithms...................................................................................................11 Table 6: Non-Approved, Allowed Algorithms with No Security Claimed.....................................11 Table 7: Security Function Implementations..............................................................................12 Table 8: Ports and Interfaces ....................................................................................................13 Table 9: Authentication Methods...............................................................................................15 Table 10: Roles.........................................................................................................................15 Table 11: Approved Services ....................................................................................................18 Table 12: Mechanisms and Actions Required ...........................................................................22 Table 13: Storage Areas ...........................................................................................................24 Table 14: SSP Input-Output Methods........................................................................................25 Table 15: SSP Zeroization Methods..........................................................................................26 Table 16: SSP Table 1..............................................................................................................27 Table 17: SSP Table 2..............................................................................................................28 Table 18: Pre-Operational Self-Tests........................................................................................29 Table 19: Conditional Self-Tests ...............................................................................................30 Table 20: Pre-Operational Periodic Information.........................................................................31 Table 21: Conditional Periodic Information................................................................................31 Table 22: Error States...............................................................................................................32 List of Figures Figure 1: Block Diagram............................................................................................................. 7 Figure 2: Xilinx Zynq 7030 - 1SBG485....................................................................................... 8 Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 4 of 34 Figure 3: Xilinx Zynq 7030 - 1FBG484 ....................................................................................... 8 Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 5 of 34 1 General 1.1 Overview This document is the non-proprietary FIPS 140-3 Security Policy for the Codan DTC Communications MESH SDR Cryptographic Module version 1.0.0 [SDR 8.5.0], hereafter referred to as, “the module”. It contains the security rules under which the module must operate and describes how the module meets the requirements as specified in FIPS PUB 140-3 for an overall Security Level 2 sub-chip firmware cryptographic module. 1.2 Security Levels The table below describes the individual security areas of FIPS 140-3, as well as the Security Levels of those individual areas. Section Title Security Level 1 General 2 2 Cryptographic module specification 2 3 Cryptographic module interfaces 2 4 Roles, services, and authentication 2 5 Software/Firmware security 2 6 Operational environment 2 7 Physical security 2 8 Non-invasive security N/A 9 Sensitive security parameter management 2 10 Self-tests 2 11 Life-cycle assurance 2 12 Mitigation of other attacks N/A Overall Level 2 Table 1: Security Levels The Module has an overall security level of 2. Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 6 of 34 2 Cryptographic Module Specification 2.1 Description Purpose and Use: The MESH SDR Cryptography Module resides within the BluSDR-90-UL, SDR-C (SDR-H2), SDR-M BluSDR-6, SDR-U BluSDR-30, D1740 NETNode BluSDR-90+, IVAS and Sentry 6161 wireless MESH IP SDR (Software Defined Radio) product lines. The module provides FIPS140-3 compliant AES-128 and AES-256 encryption and decryption functions, in addition to SHA2-256 and HMAC-SHA2-256 functionalities. Module Type: Hardware Module Embodiment: Single Chip SubChip Cryptographic Boundary: The module resides within the Programmable Logic (PL) of the Xilinx Zynq 7030 Field Programmable Gate Array (FPGA). The physical boundary is defined as the silicon SBG485 and FBG484 packages of the Xilinx Zynq 7030. The cryptographic module is defined as a Sub-Chip module per FIPS 140-3 IG 2.3.B. The module is contained in a bitstream that is composed of the following parts: - Hardware AES-ECB and SHA2-256 blocks; - MicroBlaze FPGA soft-core processor containing HMAC-SHA256 and AES-CBC-CS2 cryptographic algorithm logic for the hardware AES-ECB and SHA2-256 implementations; and the functionality related to the authentication, execution of services, execution of self-tests and error handling. - The firmware component of the cryptographic module resides within the Programmable Logic (PL) of the Xilinx Zynq FPGA. The firmware contains the logic description of the BRAM register and the rest of components needed to communicate between the MicroBlaze FPGA soft-core processor the Hardware AES- ECB and SHA-256 blocks, and the BRAM register. The MicroBlaze (version 11.0 Rev. 4) is a 32-bit RISC-based softcore processor. There are 12 bitstreams associated with a different wireless radio waveform or physically different MESH SDR product line as shown in the Table below. Waveforms Products BluSDR-90- UL SDR-C (SDR-H2) SDR-M BluSDR-6 SDR-U BluSDR-30 D1740 NETNode BluSDR-90+ IVAS (US DoD Radio) Sentry Mesh 6161 Ultra-M X X X X X X Ultra-X X X X X X X Table 2: SDR Product Line Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 7 of 34 Figure 1: Block Diagram below illustrates the cryptographic boundary is entirely contained within Xilinx Zynq 7030 Programmable Logic that includes the digital logic and an associated softcore ‘MicroBlaze’ FPGA processor. The FPGA MicroBlaze executes in a non-modifiable operational environment. The following picture shows the cryptographic boundary of the module: - The entire Programmable Logic (PL) portion of the Zynq 7030 - The physical Zynq 7030 represents the physical perimeter - Non cryptographic functions such as the Dual ARM hardcore processors and other FPGA logic Figure 1: Block Diagram The Xilinx Zynq Bitstream image which contains the module is persistently stored in external Flash memory when powered off. At every power-up the bitstream image, the integrity test values, and the reference authentication keys are passed from external Flash and DDR memory to the Xilinx Zynq 7030 chip. The on-chip Zynq ARM CPU and the Processor System (PS) then instantiates the MicroBlaze softcore processor and Programmable Logic (PL) portion of the FPGA. The Zynq Processor Subsystem (PS) loads the MicroBlaze and module firmware from FLASH external memory into to the TOEPP via the AXI data bus to an address register in BRAM at power-up. Tested Operational Environment’s Physical Perimeter (TOEPP): The physical perimeter is represented by the most exterior black line in the block diagram Figure 1. A photograph of each hardware chip is shown below in Figure 2 and Figure 3. Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 8 of 34 Figure 2: Xilinx Zynq 7030 - 1SBG485 Figure 3: Xilinx Zynq 7030 - 1FBG484 The physical perimeter is represented by the silicon chip packages (SBG485 and FBG484) of the Xilinx Zynq 7030 device containing the module. The following components are located in the TOEPP but are considered outside of the module’s sub-chip cryptographic boundary: • The Dual ARM A9 processors: These processors do not execute the MicroBlaze or module firmware. They work in conjunction with the Zynq Processor Subsystem (PS) and communicate with the module via the AXI data bus to request the execution of cryptographic services. • Non-Security Relevant PL components: Components in the Zynq PL logic outside of the cryptographic boundary and do not include cryptographic functionality. These include the Media Access Controller (MAC) functions that define when the radio can transmit and receive, the Forward Error Correction (FEC) functionality, digital modulation, digital demodulation and the interface functions to the RF transceiver chip residing outside of the physical TOEPP. No components outside of the TOEPP can directly access the cryptographic module. All requests for cryptographic services must enter via the AXI data bus to an address register in BRAM. 2.2 Tested and Vendor Affirmed Module Version and Identification Tested Module Identification – Hardware: Model and/or Part Number Hardware Version Firmware Version Processors Features Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-M waveform bitstream on BluSDR-90-UL device Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-X waveform bitstream on BluSDR-90-UL device Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-X waveform bitstream on BluSDR-90-UL device Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-X waveform bitstream on SDR-C (SDR-H2) device Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 9 of 34 Model and/or Part Number Hardware Version Firmware Version Processors Features Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-M waveform bitstream on SDR-M BluSDR-6 device Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-M waveform bitstream on SDR-U BluSDR-30 Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-X waveform bitstream on SDR-U BluSDR-30 Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-M waveform bitstream on Sentry Mesh 6161 device Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-X waveform bitstream on Sentry Mesh 6161 device Xilinx Zynq XC7Z030 FPGA 1FBG484 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-X waveform bitstream on D1740 NETNode BluSDR-90+ device Xilinx Zynq XC7Z030 FPGA 1FBG484 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-X waveform bitstream on D1740 NETNode BluSDR-90+ device Xilinx Zynq XC7Z030 FPGA 1SBG485 1.0.0 [SDR 8.5.0] MicroBlaze 11.0 (Rev. 4) softcore running on XC7Z030 FPGA Running MeshUltra-X waveform bitstream on IVAS (US DoD Radio) device Table 3: Tested Module Identification – Hardware Notes: 1. Hardware version represents the physical FPGA package designation. 2. Firmware version v1.0.0 represents the version of the cryptographic module encompassing the firmware version of the code running on the MicroBlaze together with the VHDL cryptographic hardware acceleration. As shown in the orange box in Figure 2. 3. The processor column lists the MicroBlaze, which is a soft-core processor instantiated within the FPGA. 4. The features column identifies which waveform and product is in use. This determines which bitstream contains the Cryptographic Module. Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): N/A for this module. Tested Module Identification – Hybrid Disjoint Hardware: Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 10 of 34 N/A for this module. Tested Operational Environments - Software, Firmware, Hybrid: N/A for this module. Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module. 2.3 Excluded Components There are no components within the cryptographic boundary that are excluded from the FIPS 140-3 security requirements. 2.4 Modes of Operation Modes List and Description: The table below details the Modes of Operation supported by the module. Mode Name Description Type Status Indicator Approved mode Approved mode of operation where the module utilizes the services listed in the Approved Algorithms table and Non-Approved, Allowed Algorithms with No Security Claimed table Approved The module always operates in the approved mode Table 4: Modes List and Description Once the module has been loaded and setup and initialized by the CO, it always operates in approved mode of operation. Degraded Mode Description: The module does not support a degraded mode of operation. 2.5 Algorithms Approved Algorithms: The table below lists all the Approved Algorithms supported by the module. Algorithm CAVP Cert Properties Reference AES-CBC-CS2 A7334 Direction - decrypt, encrypt Key Length - 128, 256 SP 800-38A AES-ECB A7335 Direction - Decrypt, Encrypt Key Length - 128, 256 SP 800-38A AES-ECB A7336 Direction - Decrypt, Encrypt Key Length - 128, 256 SP 800-38A HMAC-SHA2- 256 A7334 Key Length - Key Length: 8-256 Increment 8 FIPS 198-1 Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 11 of 34 Algorithm CAVP Cert Properties Reference SHA2-256 A7337 Message Length - Message Length: 8-2048 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2-256 A7338 Message Length - Message Length: 8-2048 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 Table 5: Approved Algorithms Vendor-Affirmed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: The table below lists all the Non-Approved, Allowed Algorithms with No Security Claimed supported by the module. Name Caveat Use and Function EDC- 64 Error Detection Code (EDC) 64 bits in length utilized during the authentication process. When a pin is entered during the authentication process, the module calculates its associated value to compare it with the stored result. Reference: FIPS 140- 3 IG 2.4.A MESH SDR Cryptographic Module Table 6: Non-Approved, Allowed Algorithms with No Security Claimed Non-Approved, Not Allowed Algorithms: N/A for this module. 2.6 Security Function Implementations The table below lists the Security Function Implementations supported by the module. Name Type Description Properties Algorithms Data Encryption/Decryption BC-UnAuth AES Symmetric Encryption and Decryption Publication:NIST SP 800-38A AES-CBC- CS2: (A7334) Key Length: 128, 256 bits AES-ECB: (A7335, A7336) Key Length: 128, 256 bits Message Digest SHA SHA Digest Publication:FIPS 180-4 SHA2-256: (A7337) SHA2: SHA2- 256 (s = 256). Large Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 12 of 34 Name Type Description Properties Algorithms Message Sizes: 1, 2, 4, 8gigabytes SHA2-256: (A7338) SHA2: SHA2- 256 (s = 256). Large Message Sizes: 1, 2, 4, 8gigabytes Message Authentication Code MAC MAC generation and verification Publication:FIPS 198-1 HMAC-SHA2- 256: (A7334) HMAC-SHA2 [FIPS198-1: SHA2-256 (s = 256) Table 7: Security Function Implementations 2.7 Algorithm Specific Information The supported algorithms do not require specific implementation considerations. 2.8 RBG and Entropy 2.9 Key Generation The module does not implement any approved key generation methods. 2.10 Key Establishment The module does not implement any approved key establishment methods. 2.11 Industry Protocols The module does not implement any industry protocols. Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 13 of 34 3 Cryptographic Module Interfaces 3.1 Ports and Interfaces The table below details the module Ports and Interfaces. Physical Port Logical Interface(s) Data That Passes Block Random Access Memory (BRAM) Register Data Input Data Output Control Input Status Output Data input, Data output, Control input and status output via the AXI data bus to an address register in BRAM Fips-irq line Status Output Status output is provided by the module by activating the FIPS-irq line VCCPINT, VCCPAUX, VCCPLL, VCCO_DDR, VCCO_MIO, VPREF, VPIN, VCCINT, VCCBRAM, VCCAUX, VCCO, VCCAUX_IO pins Power Power GND pins Control Input Ground for power voltage reference Table 8: Ports and Interfaces All data communication between the module and the rest of components within the TOEPP occur via the AXI data bus to an address register in BRAM. The Dual ARM A9 processors and applications in the Processor Subsystem (PS) can request the execution of the cryptographic services using the available command structures via memory writes to a BRAM register via the AXI data bus. Data Output and Status Output to the Dual ARM A9 processors and applications in the Processor Subsystem (PS) within the TOEPP exit through the same interface. Status Output is also provided via a FIPS IRQ line. Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 14 of 34 4 Roles, Services, and Authentication 4.1 Authentication Methods The module supports the following authentication methods: Method Name Description Security Mechanism Strength Each Attempt Strength per Minute Role Pin The module requires entering a unique Role Pin to authenticate to the Crypto Officer and User roles. The module does not store the value of the Role Pin in memory but stores its associated 64-bit value after processing it an EDC. non-approved but allowed mechanism. During authentication the module checks the value of the role pin provided and compares it with 64- bit EDC value EDC-64 value The authentication mechanism uses a 64-bit PIN with 2⁶⁴ possible values. Since the input to the module is run through an EDC and compared exactly against a stored value. Upon a failed authentication, the module transitions into a hard error state, disallowing any further authentication attempts. Therefore, the probability of a random guess succeeding is 1/2⁶⁴ , and no retries are possible The module enforces an effective rate of zero retries per minute. The module transitions to an error state and must be re- installed and re- instantiated (first authentication process) in case of entering an invalid pin during authentication. There is no retry window and an entirely new operational session would need to be initiated. User Session Pin In addition to the Role pin, to open a session and request cryptographic services the User will be required to provide a User Session Pin. Upon each request for cryptographic services the module will verify the User provided the correct 64-bit binary value associated with the session. 64-bit binary value The authentication mechanism uses a 64-bit PIN with 2⁶⁴ possible values. The module compares the value to the Pin provided when the session was opened. If a valid User Session Pin is not supplied by a User upon request of a service, then an error code will be returned by the Cryptographic Module. The module closes the session and transitions into a hard error state, disallowing any further authentication attempts. The module enforces an effective rate of zero retries per minute. The module transitions to an error state and must be re- installed and re- instantiated (first authentication process) in case of entering an invalid pin during authentication. There is no retry window and an entirely new operational session would need to be initiated. Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 15 of 34 Table 9: Authentication Methods The module supports explicit role-based authentication for the Crypto Officer and User. The module supports multiple concurrent User sessions at the same time, however, only one Crypto Officer is supported at a time. The module implements a default authentication pin for the first authentication process during module setup and initialization. The Crypto Officer is responsible for setting a new Pin for the Crypto Officer role and creating the User role pin for the User role. Then the user role is responsible for creating session pins for each new request to create a new user session. This session pin is utilized by the module to create a session handle associated with each user session in order to separate between concurrent user operators requesting services. 4.2 Roles The table below lists the roles supported by the module. Name Type Operator Type Authentication Methods Crypto Officer Role CO Role Pin User Role User Role Pin User Session Pin Table 10: Roles 4.3 Approved Services The table below lists all Approved Services supported by the module. The abbreviations of the access rights to SSPs have the following interpretation: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. Name Descripti on Indicator Inputs Outputs Security Functions SSP Access Initialization Power-up of the module and initial configurat ion of the default authentic ation data N/A CO Role Pin None None Crypto Officer - Role Pin: W,E AES Encryption/De cryption Execute AES- ECB, AES- CBC-CS2 encrypt or decrypt operation FIPS_OK Plaintext data and key/Ciph ertext data and key Cipherte xt data/Plai ntext data Data Encryption/De cryption User - AES Key: W,E Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 16 of 34 Name Descripti on Indicator Inputs Outputs Security Functions SSP Access Module Halt Decommi ssion or return module to factory state FIPS_MB_ FAULT None None None User - AES Key: Z - MAC Key: Z - User Session Pin: Z - Role Pin: Z Crypto Officer - Role Pin: Z - Module MAC Reference Authentica tion Key: Z - Microblaz e FPGA MAC Reference Authentica tion Key: Z Message digest calculation Calculate a SHA2- 256 the message digest of a given input plaintext FIPS_OK Input plaintext Result of the messag e digest calculati on Message Digest User MAC Generation/Ve rification Generate/ Verify a HMAC- SHA2- 256 Message Authentic ation Code FIPS_OK Plaintext data and key Result of the MAC generati on or verificati on Message Authentication Code User - MAC Key: W,E Show Module and Version Information Return the module FIPS_OK None Module name None Unauthent icated Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 17 of 34 Name Descripti on Indicator Inputs Outputs Security Functions SSP Access name and version number and version Show status Return the module status N/A None Module status None Unauthent icated On-Demand Self-Test Execute the self- tests automatic ally at power-up of the module FIPS_OK None None Data Encryption/De cryption Message Digest Message Authentication Code Unauthent icated Zeroization • Zeroize all SSPs upon module reboot. • Zeroize AES and MAC SSPs and User Session Pin with close session command s • Execute the change role pin • Execute the module halt command • N/A -The module cannot output any indicator when it is rebooted. • FIPS_OK for the zeroization related to the close session commands • FIPS_OK for the zeroization related to the change role pin command • FIPS_MB_ FAULT None None None User - MAC Key: Z - AES Key: Z - User Session Pin: Z - Role Pin: Z Crypto Officer - Role Pin: Z - Module MAC Reference Authentica tion Key: Z - Microblaz e FPGA MAC Reference Authentica tion Key: Z Change role pin Set a new Crypto Officer role pin or a new FIPS_OK New Crypto Officer role pin None None Crypto Officer - Role Pin: W,Z Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 18 of 34 Name Descripti on Indicator Inputs Outputs Security Functions SSP Access User Role Pin (When a new User role pin is created the Officer role pin is zeroized) or User Role Pin Firmware loading Executed automatic ally at power-up of the module FIPS_OK Bitstrea m image of the Microblz e and firmware of module; Module MAC Referenc e authentic ation key; Microbla ze FPGA MAC Referenc e authentic ation key None Message Authentication Code Unauthent icated - Module MAC Reference Authentica tion Key: W,E - Microblaz e FPGA MAC Reference Authentica tion Key: W,E Firmware Load test Considere d as successfu l executed upon completio n of the Firmware loading test FIPS_OK Module MAC Referenc e authentic ation key; Microbla ze FPGA MAC Referenc e authentic ation key None Message Authentication Code Unauthent icated - Module MAC Reference Authentica tion Key: W,E - Microblaz e FPGA MAC Reference Authentica tion Key: W,E Table 11: Approved Services Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 19 of 34 4.4 Non-Approved Services N/A for this module. 4.5 External Software/Firmware Loaded The bitstream of the module is considered firmware as indicated in FIPS 140-3 IG 10.3.F - Additional Comment 6. The MicroBlaze FPGA and module firmware are loaded from an external source to the TOEEP automatically at every power-up of the module as indicated in FIPS 140-3 IG 10.3.F - Additional Comment 3.a. The module performs the software/firmware load test during module setup and initialisation prior to entering the operational state (FIPS_OPERATIONAL) as an exception to FIPS 140-3 IG 10.3.F - Additional Comment 9. When powered off Xilinx Zynq bitstream image containing the module is persistently stored in external Flash memory. On power-up the bitstream image the integrity test values and the reference authentication keys are passed from external Flash and DDR memory to the Xilinx Zynq 7030 chip. The on-chip Zynq ARM CPU and the ARM Processor System then instantiate the MicroBlaze softcore processor and Zynq Programmable Logic (PL) portion of the FPGA. The bitstream image, the MicroBlaze image, the pre-computed integrity test values and reference authentication keys1 are passed to the PL and the MESH SDR Cryptographic Module is loaded after module CASTs and load tests on the FPGA image and the Cryptographic Module pass. Upon verifying the authenticity of the MicroBlaze FPGA and module firmware, the CO replaces the default authentication pin with a new CO role pin. This command triggers the execution of the CASTs again. The CO authenticates using their new CO role pin and then User Session Pins are set by the CO. Only then will the module enter the operational state (FIPS_OPERATIONAL). All data output on the data output interfaces are inhibited and no cryptographic output is possible until the module transitions to operational state. 1 The Refence Authentication Keys and images are independently loaded into the FPGA Programmable Logic via separate API calls by the Zynq ARM Processor System (PS). Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 20 of 34 5 Software/Firmware Security 5.1 Integrity Techniques A HMAC-SHA2-256 Firmware Load Test has been implemented to separately verify the authenticity and integrity of the module and Microblaze firmware images. The Refence Authentication Keys and images are independently loaded into the FPGA Programmable Logic via separate API calls by the Zynq ARM Processor System. Once both images are loaded into the FPGA Programable Logic, they are authenticated and integrity checked independently by executing the HMAC-SHA2-256 Firmware Load Test over the Microblaze Firmware image first and after that over the module firmware image. In case of failure during the execution of the HMAC-SHA2-256 Firmware Load Test, the module outputs the “FIPS_MB_FAULT” error and enters in Halt state. 5.2 Initiate on Demand The HMAC-SHA2-256 Firmware Load Test executes at power on. It can be invoked on demand by power-cycling the module. Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 21 of 34 6 Operational Environment 6.1 Operational Environment Type and Requirements Type of Operational Environment: Non-Modifiable How Requirements are Satisfied: The module implements a non-modifiable operational environment since it is designed to prevent the loading of any additional firmware while the module is in operational state as it does not implement any service to perform the loading of new firmware. The MicroBlaze FPGA and module firmware are loaded from an external source to the TOEEP automatically at every power-up of the module as indicated in FIPS 140-3 IG 10.3.F - Additional Comment 3.a.” Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 22 of 34 7 Physical Security 7.1 Mechanisms and Actions Required The following physical security mechanisms are implemented in the cryptographic module: - All components are manufactured to production-grade with standard passivation; - The module is encapsulated in an opaque package within the visible spectrum; and - Strong removal-resistant and penetration resistant IC packaging techniques have been applied. The following table summarizes the actions required by the Crypto Officer Role to ensure that physical security is maintained. Mechanism Inspection Frequency Inspection Guidance Opaque covering As often as feasible Inspect perimeter and determine whether gathering of internal components are visible. If tampering is suspected, issue the halt command or power down the module immediately. Tamper evident IC packaging As often as feasible Inspect the damage such as removing epoxy overfill, separation from the PCB of the silicon die, solder ball deterioration (diameter, pitch). If tampering is suspected, the halt command or power down the module immediately. Table 12: Mechanisms and Actions Required Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 23 of 34 8 Non-Invasive Security Currently, the ISO/IEC 19790:2012 non-invasive security area is not required by FIPS 140-3 (see NIST SP 800-140F). The requirements of this area are not applicable to the module. Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 24 of 34 9 Sensitive Security Parameters Management 9.1 Storage Areas The table below lists Sensitive Security Parameters (SSPs) storage areas for the module. Section 9.4 below selects from the storage areas listed and specifies the appropriate parameter in the “Storage” column if applicable to a specific SSP. Storage Area Name Description Persistence Type BRAM The Block Random Access Memory (BRAM) register through which the information flows into and out of the module. Dynamic Microblaze RAM Microblaze Random Access Memory where SSPs are stored into the module Dynamic Table 13: Storage Areas 9.2 SSP Input-Output Methods The table below lists SSP input and output methods for the module. Section 9.4 below selects from the input and output methods listed and specifies the appropriate parameter in the “Inputs/Outputs” column if applicable to a specific SSP. Name From To Format Type Distributio n Type Entr y Type SFI or Algorithm AES Key input Zynq Processor System located into the TOEPP but outside of the cryptograph ic boundary BRAM; Microblaz e RAM Plainte xt N/A N/A Data Encryption/Decrypti on MAC Key input Zynq Processor System located into the TOEPP but outside of the cryptograph ic boundary BRAM; Microblaz e RAM Plainte xt N/A N/A Message Authentication Code User Session Pin input Zynq Processor System located into the TOEPP but outside of the cryptograph ic boundary BRAM; Microblaz e RAM Plainte xt N/A N/A Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 25 of 34 Name From To Format Type Distributio n Type Entr y Type SFI or Algorithm MAC Reference Authenticatio n Key input Zynq Processor System located into the TOEPP but outside of the cryptograph ic boundary BRAM, Microblaz e RAM Plainte xt N/A N/A Message Authentication Code Role pin input Zynq Processor System located into the TOEPP but outside of the cryptograph ic boundary BRAM, Microblaz e RAM Plainte xt N/A N/A Table 14: SSP Input-Output Methods 9.3 SSP Zeroization Methods The table below lists SSP zeroisation methods for this module. Section 9.4 below selects from the zeroisation methods listed and specifies the appropriate parameter in the “Zeroization” column if applicable to a specific SSP. Zeroization Method Description Rationale Operator Initiation Close session Zeroization of AES and MAC keys, and User Session Pin by closing sessions related to AES Encryption/Decryption and MAC generation services Upon completion of AES encryption/decryption or MAC Generation/Verification operations, the module receives a command to close the session associated with those services and their associated keys are zeroized User by sending close session commands Reboot Zeroization of all SSPs when the module is rebooted SSPs are procedurally zeroized by rebooting the module Crypto Officer or User by rebooting the module Change Role Zeroization of Role pin (When it is related to the CO) Changing from Crypto Officer to User role causes the zeroization of the Crypto Officer role Crypto Officer by executing the change role pin service to set Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 26 of 34 Zeroization Method Description Rationale Operator Initiation Module halting eroization of all SSPs including the Role pin and User Session Pins All the SSPs are zeroized when the module is halted in the case of error or by executing the module halt command Crypto Officer or User by executing the module halt command Table 15: SSP Zeroization Methods The module provides an status indicator when the zeroization is complete according to the indicated in table 12. 9.4 SSPs The following table summarizes the keys and Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module: Name Description Size - Stren gth Type - Category Genera ted By Establis hed By Used By AES Key AES Key utilized to perform encryption/decry ption operations 128, 256 - 128, 256 Symmetric key - CSP Data Encryption/Decr yption MAC Key MAC Key utilized to perform MAC generation/verifi cation operations 8, 256 - 8, 256 Symmetric key - CSP Message Authentication Code Role Pin Role pin is utilized to authenticate either the CO or user roles 64 - 64 Authentica tion - CSP EDC-64 User Session Pin MAC Reference Authentication Key input 64 - 64 Authentica tion - CSP Module MAC Reference Authentica tion Key Module MAC reference authentication key utilized to verify the integrity and authenticity of the module firmware loaded into the module at power-up 256 - 256 Symmetric key - CSP Message Authentication Code Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 27 of 34 Name Description Size - Stren gth Type - Category Genera ted By Establis hed By Used By Microblaz e FPGA MAC Reference Authentica tion Key Microblaze FPGA MAC reference authentication key utilized to verify the integrity and authenticity of the microblaze FPGA image firmware loaded into the module at power-up 256- 256 - 256- 256 Symmetric key - CSP Message Authentication Code Table 16: SSP Table 1 Name Input - Output Storage Storage Duration Zeroization Related SSPs AES Key AES Key input BRAM:Plaintext Microblaze RAM:Plaintext Until module reboot, execution of AES close session or module halting commands Close session Reboot Module halting MAC Key MAC Key input BRAM:Plaintext Microblaze RAM:Plaintext Until module reboot, execution of MAC close session or module halting commands Close session Reboot Module halting Role Pin Role pin input BRAM:Plaintext Microblaze RAM:Plaintext Until module reboot, execution of the change role pin or module halting commands Reboot Change Role Module halting User Session Pin User Session Pin input BRAM:Plaintext Microblaze RAM:Plaintext Until module reboot or TBD Reboot Close session Module halting Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 28 of 34 Name Input - Output Storage Storage Duration Zeroization Related SSPs Module MAC Reference Authentication Key MAC Reference Authentication Key input BRAM:Plaintext Microblaze RAM:Plaintext Until module reboot, execution of the MAC close session or module halting command Close session Reboot Module halting Microblaze FPGA MAC Reference Authentication Key MAC Reference Authentication Key input BRAM:Plaintext Microblaze RAM:Plaintext Until module reboot, execution of the MAC close session or module halting command Reboot Close session Module halting Table 17: SSP Table 2 Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 29 of 34 10 Self-Tests This section specifies the pre-operational and conditional self-tests performed by the module. The pre-operational and conditional self-tests ensure that the module is not corrupted and that the cryptographic algorithms work as expected. The module transitions to the operational state once the User role is authenticated after the pre- operational and conditional self-tests are passed successfully. 10.1 Pre-Operational Self-Tests The Pre-Operational Self-Tests are detailed in the table below. Algorithm or Test Test Properties Test Method Test Type Indicator Details HMAC- SHA2-256 (A7334) 256 – bit key KAT SW/FW Integrity FIPS_OK Module and Microblaze FPGA firmware images verified on every power-up by performing separate HMAC-SHA2-256 Load Tests Table 18: Pre-Operational Self-Tests 10.2 Conditional Self-Tests The Conditional Self-Tests are detailed on the table below. Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions AES-ECB 128 and 256- bit key, encrypt KAT CAST FIPS_OK Encryption During Setup and initialization and after successful first successful User role authentication AES-ECB 128 and 256- bit key, decryp KAT CAST FIPS_OK Decryption During Setup and initialization and after successful first successful User role authentication AES-CBC- CS2 128 and 256- bit key, encrypt KAT CAST FIPS_OK Encryption During Setup and initialization and after successful first successful Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 30 of 34 Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions User role authentication AES-CBC- CS2 128 and 256- bit key, decrypt KAT CAST FIPS_OK Decryption During Setup and initialization and after successful first successful User role authentication SHA2-256 256-bit hash KAT CAST FIPS_OK Hash During Setup and initialization and after first successful User role authentication HMAC- SHA2-256 (A7334) 256-bit key KAT CAST FIPS_OK MAC Generation and Verification During Setup and initialization and after first successful User role authentication EDC-64 64-bit value KAT Critical Function FIPS_OK EDC Generation and verification During Setup and initialization and after first successful User role authentication Module Firmware Load Test HMAC-SHA2- 256 with Module MAC Reference authentication key MAC Verification SW/FW Load FIPS_OK Verification of Module firmware at Load Test At module power-up after Setup and initialization Microblaze FPGA Firmware Load Test HMAC-SHA2- 256 with Microblaze FPGA MAC Reference authentication key MAC Verification SW/FW Load FIPS_OK Verification of Microblaze FPGA firmware at Load Test At module power-up after Setup and initialization Table 19: Conditional Self-Tests Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 31 of 34 On power-up the bitstream image, pre-computed integrity test values and the reference authentication keys are passed from external Flash and DDR memory to the Xilinx Zynq 7030 chip. The on-chip Zynq ARM CPU and the Processor System (PS) then instantiate the MicroBlaze softcore processor and Zynq Programmable Logic (PL) portion of the FPGA. The bitstream image, pre-computed integrity test values and reference authentication keys are passed to the FPGA’s PL. Immediately after the firmware is loaded the module’s CAST’s are executed. The firmware load tests on the MicroBlaze FPGA firmware and the module portion of the firmware immediately follow. Upon verifying the authenticity of the MicroBlaze FPGA and module firmware, the CO replaces the default authentication pin with a new CO role pin. This command triggers the execution of the CASTs a second time. The CO then authenticates using their new CO role pin and sets the User role pin. The user role authentication triggers the execution of the CASTs a third time. If the CASTs successfully complete the module enters the operational state (FIPS_OPERATIONAL). User Session Pins are set by the User role when new User sessions are requested. By design, module services are not available until the successful completion of the firmware load test and the conditional self-tests, therefore, the data output interface is inhibited during the execution of the self-tests and in case of error. 10.3 Periodic Self-Test Information Pre-operational self-tests can be run on-demand, for periodic testing, by rebooting the module. Algorithm or Test Test Method Test Type Period Periodic Method HMAC-SHA2- 256 (A7334) KAT SW/FW Integrity On Demand Reboot, reset or power cycle Table 20: Pre-Operational Periodic Information Algorithm or Test Test Method Test Type Period Periodic Method AES-ECB KAT CAST On Demand Reboot, reset or power cycle AES-ECB KAT CAST On Demand Reboot, reset or power cycle AES-CBC-CS2 KAT CAST On Demand Reboot, reset or power cycle AES-CBC-CS2 KAT CAST On Demand Reboot, reset or power cycle SHA2-256 KAT CAST On Demand Reboot, reset or power cycle HMAC-SHA2- 256 (A7334) KAT CAST On Demand Reboot, reset or power cycle EDC-64 KAT Critical Function On Demand Reboot, reset or power cycle Module Firmware Load Test MAC Verification SW/FW Load On Demand Reboot, reset or power cycle Microblaze FPGA Firmware Load Test MAC Verification SW/FW Load On Demand Reboot, reset or power cycle Table 21: Conditional Periodic Information Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 32 of 34 10.4 Error States The table below shows the different causes that lead to the Error States and the status indicators reported. Name Description Conditions Recovery Method Indicator Halt state The module is halted in case of error (1) Failure in SW/FW Load Test, second execution of Cryptographic algorithm KATs, EDC-64 KAT and CO/User authentication or normal operation. (2) First execution of Cryptographic algorithm KATs The module can only recover the normal operation after a module reset or reboot (1) Status is set to “halt”, the module is halted and the module outputs the FIPS_MB_FAULT error. (2) Status is set to “halt”, the module is halted, and the module outputs the following error codes: • FIPS_KAT_HASH64_FAIL in case of error in the EDC-64 KAT • FIPS_KAT_SHA2_FAIL in case of error in the SHA2-256 KAT • FIPS_KAT_SHA2_HMAC_FAIL in case of error in the HMAC-SHA256 KAT • FIPS_KAT_AES_FAIL in case of error in the ECB and CBC-CS2 encryption/decryption KATs Table 22: Error States The module enters this state in case of error during the execution of the pre-operational self-tests, conditional self- tests, invalid authentication attempt or in case of failure during normal operation. Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 33 of 34 11 Life-Cycle Assurance 11.1 Installation, Initialization, and Startup Procedures When the module is powered on and after loading the firmware and executing the cryptographic algorithm KATs without any operator intervention, the module requires the CO authentication using the default CO Role Pin pre- configured during the manufacturing process. Once the CO is authenticated, a new CO Role Pin is required to replace the default authentication data. The CO authenticates using the new CO role pin and then User Role Pin is set by the CO. Once the User Role is authenticated, then the module enters the operational state (FIPS_OPERATIONAL). A User can authenticate to the module using their User Role pin and request new sessions utilizing User Session Pin and verify that the module name and version match with the versioning information on the module certificate by executing the “Show Module and Version Information” service. 11.2 Administrator Guidance No additional guidance for the administrator other than the indicated in the previous paragraph is required to perform the secure initialization of the module. 11.3 Non-Administrator Guidance Once the module is initialized by the CO as indicated above, a User operator can request the Approved services supported by the module without requiring special instructions. 11.4 End of Life All SSPs and sensitive information are removed from the module when it is powered off, or when the CO or User executes the “module halt” command. This will transition the module back to its factory state. Codan DTC Communications MESH SDR Cryptographic Module FIPS 140-3 Non-Proprietary Security Policy Conan DTC Communications 2025 This document may be reproduced and distributed only in its original entirety without revision Page 34 of 34 12 Mitigation of Other Attacks The module does not offer mitigation of other attacks and therefore this section is not applicable.