Ideem ZSM Cryptographic Module

Certificate details

Certificate ID #4982
Status active
Validation dates 03.03.2025 , 19.05.2025
Sunset date 02-03-2030
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat No assurance of the minimum strength of generated SSPs (e.g., keys)
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
Description Ideem ZSM Cryptographic Module randomly splits keys across servers so that they are never in any single place to be stolen. The advanced protocols used in Ideem ZSM ensure that even if servers are breached and completely controlled by an attacker, the secrets and credentials cannot be stolen. The result is that digital assets remain safe, even if all else fails and attackers get inside the network. Ideem ZSM is able to protect all types of standard cryptographic keys for all purposes, including encryption/decryption, digital signing, and authentication. Ideem’s technology for securing keys using two-party computation (TPC) is fully transparent to the calling application.
Vendor Ideem, Inc. https://www.useideem.com
Lab Teron Labs
Algorithms
  • AES-CBCA5056
  • AES-CCMA5056
  • AES-CFB128A5056
  • AES-CFB1A5056
  • AES-CFB8A5056
  • AES-CMACA5056
  • AES-CTRA5056
  • AES-ECBA5056
  • AES-GCMA5056
  • AES-GMACA5056
  • AES-KWA5056
  • AES-KWPA5056
  • AES-OFBA5056
  • AES-XTS Testing Revision 2.0A5056
  • Counter DRBGA5056
  • ECDSA KeyGen (FIPS186-4)A5055
  • ECDSA KeyGen (FIPS186-5)A5056
  • ECDSA KeyVer (FIPS186-5)A5056
  • ECDSA SigGen (FIPS186-4)A5055
  • ECDSA SigGen (FIPS186-5)A5056
  • ECDSA SigVer (FIPS186-5)A5056
  • HMAC-SHA-1A5056
  • HMAC-SHA2-224A5056
  • HMAC-SHA2-256A5056
  • HMAC-SHA2-384A5056
  • HMAC-SHA2-512/224A5056
  • HMAC-SHA2-512/256A5056
  • HMAC-SHA2-512A5056
  • HMAC-SHA3-224A5056
  • HMAC-SHA3-256A5056
  • HMAC-SHA3-384A5056
  • HMAC-SHA3-512A5056
  • KAS-ECC-SSC Sp800-56Ar3A5056
  • KDA HKDF SP800-56Cr2A5056
  • KDF TLSA5056
  • PBKDFA5056
  • RSA KeyGen (FIPS186-5)A5056
  • RSA SigGen (FIPS186-5)A5056
  • RSA SigVer (FIPS186-5)A5056
  • SHA-1A5056
  • SHA2-224A5056
  • SHA2-256A5056
  • SHA2-384A5056
  • SHA2-512/224A5056
  • SHA2-512/256A5056
  • SHA2-512A5056
  • SHA3-224A5056
  • SHA3-256A5056
  • SHA3-384A5056
  • SHA3-512A5056
  • SHAKE-128A5056
  • SHAKE-256A5056
  • TLS v1.2 KDF RFC7627A5056
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-128, AES-192, AES-256, AES-, CAST, DES, HMAC, CMAC
Asymmetric Algorithms
ECDH, ECDSA, ECC, DH, Diffie-Hellman
Hash functions
SHA-1, SHA3-224, SHA3-384, SHA3-512, SHA3-256, SHA3, PBKDF, PBKDF2
Schemes
MAC, Key Agreement, Key agreement
Protocols
TLS, TLS v1.2
Randomness
DRBG, RBG
Elliptic Curves
P-256, P-224, P-384, P-521
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTS

Trusted Execution Environments
PSP

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4982,
  "dgst": "59e1e59850940550",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA3-384A5056",
        "RSA KeyGen (FIPS186-5)A5056",
        "SHAKE-128A5056",
        "AES-GMACA5056",
        "AES-CFB1A5056",
        "KDF TLSA5056",
        "RSA SigVer (FIPS186-5)A5056",
        "SHA2-224A5056",
        "AES-XTS Testing Revision 2.0A5056",
        "AES-CTRA5056",
        "SHAKE-256A5056",
        "HMAC-SHA2-512/224A5056",
        "ECDSA KeyVer (FIPS186-5)A5056",
        "Counter DRBGA5056",
        "HMAC-SHA-1A5056",
        "KDA HKDF SP800-56Cr2A5056",
        "AES-CMACA5056",
        "AES-CFB128A5056",
        "HMAC-SHA2-256A5056",
        "KAS-ECC-SSC Sp800-56Ar3A5056",
        "HMAC-SHA2-512A5056",
        "ECDSA SigGen (FIPS186-5)A5056",
        "PBKDFA5056",
        "HMAC-SHA3-256A5056",
        "ECDSA SigVer (FIPS186-5)A5056",
        "TLS v1.2 KDF RFC7627A5056",
        "SHA-1A5056",
        "SHA3-224A5056",
        "AES-OFBA5056",
        "SHA2-384A5056",
        "#A5056",
        "HMAC-SHA2-512/256A5056",
        "ECDSA SigGen (FIPS186-4)A5055",
        "HMAC-SHA3-512A5056",
        "SHA3-256A5056",
        "HMAC-SHA2-224A5056",
        "#A5055",
        "HMAC-SHA2-384A5056",
        "AES-ECBA5056",
        "AES-CBCA5056",
        "SHA3-384A5056",
        "ECDSA KeyGen (FIPS186-4)A5055",
        "SHA2-512/224A5056",
        "SHA2-512A5056",
        "SHA3-512A5056",
        "SHA2-256A5056",
        "AES-CCMA5056",
        "SHA2-512/256A5056",
        "ECDSA KeyGen (FIPS186-5)A5056",
        "AES-CFB8A5056",
        "AES-KWA5056",
        "RSA SigGen (FIPS186-5)A5056",
        "AES-GCMA5056",
        "HMAC-SHA3-224A5056",
        "AES-KWPA5056"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 1,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A5056",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB1",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A5056",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A5055",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5055",
            "properties": "Direction - Encrypt Key Length - 128",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5056",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A5056",
            "properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A5055",
            "properties": "Curve - P-256 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-5)",
            "cavpCertName": "A5056",
            "properties": "Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidates",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-5)",
            "cavpCertName": "A5056",
            "properties": "Curve - P-224, P-256, P-384, P-521",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A5055",
            "properties": "Curve - P-256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA3-224, SHA3- 256, SHA3-384, SHA3-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-5)",
            "cavpCertName": "A5056",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-5)",
            "cavpCertName": "A5056",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/224",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/256",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-224",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-256",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-384",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-512",
            "cavpCertName": "A5056",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A5056",
            "properties": "Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF SP800- 56Cr2",
            "cavpCertName": "A5056",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-3968 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDF TLS (CVL)",
            "cavpCertName": "A5056",
            "properties": "TLS Version - v1.2 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A5056",
            "properties": "Iteration Count - Iteration Count: 10-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-5)",
            "cavpCertName": "A5055",
            "properties": "Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standard",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-5)",
            "cavpCertName": "A5056",
            "properties": "Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standard",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-5)",
            "cavpCertName": "A5055",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-5)",
            "cavpCertName": "A5056",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-5)",
            "cavpCertName": "A5056",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/224",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A5056",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-128",
            "cavpCertName": "A5056",
            "properties": "Output Length - Output Length: 16-1024 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-256",
            "cavpCertName": "A5056",
            "properties": "Output Length - Output Length: 16-1024 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A5056",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Return FIPS mode status",
            "indicator": "N/A",
            "inputs": "API call parameters",
            "name": "Show status",
            "outputs": "Current operational status",
            "rolesSspAccess": "Unauthenticated",
            "secFunImpl": "None"
          },
          {
            "description": "Perform pre- operational self-tests",
            "indicator": "API return value",
            "inputs": "API call parameters",
            "name": "Perform self-tests on- demand",
            "outputs": "Status",
            "rolesSspAccess": "Unauthenticated",
            "secFunImpl": "None"
          },
          {
            "description": "Zeroize and de- allocate memory containing sensitive data",
            "indicator": "N/A",
            "inputs": "API call parameters",
            "name": "Zeroize",
            "outputs": "None",
            "rolesSspAccess": "",
            "secFunImpl": "None"
          },
          {
            "description": "Return module versioning information",
            "indicator": "N/A",
            "inputs": "API call parameters",
            "name": "Show versioning information",
            "outputs": "Module name, version",
            "rolesSspAccess": "Unauthenticated",
            "secFunImpl": "None"
          },
          {
            "description": "Encrypt plaintext data",
            "indicator": "API return value",
            "inputs": "API call parameters, key, plaintext",
            "name": "Perform Multi-party symmetric encryption",
            "outputs": "Status, ciphertext",
            "rolesSspAccess": "User - MPC AES Key: W,E",
            "secFunImpl": "AES for Multi-party Symmetric Encryption/Decryption"
          },
          {
            "description": "Decrypt ciphertext data",
            "indicator": "API return value",
            "inputs": "API call parameters, key, ciphertext",
            "name": "Perform Multi-party symmetric decryption",
            "outputs": "Status, plaintext",
            "rolesSspAccess": "User - MPC AES Key: W,E",
            "secFunImpl": "AES for Multi-party Symmetric Encryption/Decryption"
          },
          {
            "description": "Generate a public/private key pair",
            "indicator": "API return value",
            "inputs": "API call parameters",
            "name": "Generate Multi-party asymmetric key pair",
            "outputs": "Status, key pair",
            "rolesSspAccess": "User - MPC ECDSA Public key: G,R - MPC ECDSA Private key: G,R - MPC RSA public key: G,R - MPC RSA private key: G,R",
            "secFunImpl": "ECDSA for Multi-party Asymmetric Key Pair Generation RSA for Multi-party Asymmetric Key Pair Generation"
          },
          {
            "description": "Generate a digital signature",
            "indicator": "API return value",
            "inputs": "API call parameters, key, message",
            "name": "Generate Multi-party digital signature",
            "outputs": "Status, signature",
            "rolesSspAccess": "User - MPC ECDSA Private key: W,E - MPC RSA public key: W,E",
            "secFunImpl": "ECDSA for Multi-party Digital Signature Generation RSA for Multi-party Digital Signature Generation"
          },
          {
            "description": "Encrypt plaintext data",
            "indicator": "API return value",
            "inputs": "API call parameters, key, plaintext",
            "name": "Perform symmetric encryption",
            "outputs": "Status, ciphertext",
            "rolesSspAccess": "User - AES key: W,E - AES XTS key: W,E",
            "secFunImpl": "AES for Symmetric Encryption/Decryption AES-XTS for Symmetric Encryption/Decryption"
          },
          {
            "description": "Decrypt ciphertext data",
            "indicator": "API return value",
            "inputs": "API call parameters, key, ciphertext",
            "name": "Perform symmetric decryption",
            "outputs": "Status, plaintext",
            "rolesSspAccess": "User - AES key: W,E - AES XTS key: W,E",
            "secFunImpl": "AES for Symmetric Encryption/Decryption AES-XTS for Symmetric Encryption/Decryption"
          },
          {
            "description": "Generate symmetric digest",
            "indicator": "API return value",
            "inputs": "API call parameters, key, plaintext",
            "name": "Generate symmetric digest",
            "outputs": "Status, digest",
            "rolesSspAccess": "User - AES CMAC key: W,E - AES GMAC key: W,E",
            "secFunImpl": "AES-CMAC for Message Authentication AES-GMAC for Message Authentication"
          },
          {
            "description": "Verify symmetric digest",
            "indicator": "API return value",
            "inputs": "API call parameters, key, digest",
            "name": "Verify symmetric digest",
            "outputs": "Status",
            "rolesSspAccess": "User - AES CMAC key: W,E - AES GMAC key: W,E",
            "secFunImpl": "AES-CMAC for Message Authentication AES-GMAC for Message Authentication"
          },
          {
            "description": "Encrypt plaintext",
            "indicator": "API return value",
            "inputs": "API call parameters, key, plaintext",
            "name": "Perform authenticated symmetric encryption",
            "outputs": "Status, ciphertext",
            "rolesSspAccess": "User - AES CCM key: W,E - AES GCM key: W,E - AES GCM IV: G,R,E",
            "secFunImpl": "AES-CCM for Authenticated Symmetric Encryption/Decryption AES-GCM for Authenticated Symmetric Encryption/Decryption"
          },
          {
            "description": "Decrypt ciphertext",
            "indicator": "API return value",
            "inputs": "API call parameters, key, ciphertext",
            "name": "Perform authenticated symmetric decryption",
            "outputs": "Status, plaintext",
            "rolesSspAccess": "User - AES CCM key: W,E - AES GCM key: W,E - AES GCM IV: W,E",
            "secFunImpl": "AES-CCM for Authenticated Symmetric Encryption/Decryption AES-GCM for Authenticated Symmetric Encryption/Decryption"
          },
          {
            "description": "Generate random bits using DRBG",
            "indicator": "API return value",
            "inputs": "API call parameters",
            "name": "Generate random number",
            "outputs": "Status, random bits",
            "rolesSspAccess": "User - DRBG entropy input: W,E - DRBG seed: G,E - DRBG \u0027V\u0027 value: G,E - DRBG \u0027Key\u0027 value: G,E",
            "secFunImpl": "DRBG"
          },
          {
            "description": "Compute a message authentication code",
            "indicator": "API return value",
            "inputs": "API call parameters, key, message",
            "name": "Perform keyed hash operation",
            "outputs": "Status, MAC",
            "rolesSspAccess": "User - HMAC key: W,E",
            "secFunImpl": "HMAC for Message Authentication"
          },
          {
            "description": "Compute a message digest",
            "indicator": "API return value",
            "inputs": "API call parameters",
            "name": "Perform hash operation",
            "outputs": "Status, hash",
            "rolesSspAccess": "User",
            "secFunImpl": "SHA for Message Digest SHA3 for Message Digest SHAKE for Extendable Output Function"
          },
          {
            "description": "Generate a public/private key pair",
            "indicator": "API return value",
            "inputs": "API call parameters",
            "name": "Generate asymmetric key pair",
            "outputs": "Status, key pair",
            "rolesSspAccess": "User - ECDSA public key: G,R - ECDSA private key: G,R - RSA public key: G,R - RSA private key: G,R - ECDH public component: G,R - ECDH private component: G,R",
            "secFunImpl": "ECDSA for Key Generation RSA for Key Generation"
          },
          {
            "description": "Verify an ECDSA public key",
            "indicator": "API return value",
            "inputs": "API call parameters, key",
            "name": "Verify ECDSA public key",
            "outputs": "Status",
            "rolesSspAccess": "User - ECDSA public key: W",
            "secFunImpl": "ECDSA for Key Verification"
          },
          {
            "description": "Generate a digital signature",
            "indicator": "API return value",
            "inputs": "API call parameters, key, message",
            "name": "Generate digital signature",
            "outputs": "Status, signature",
            "rolesSspAccess": "User - ECDSA private key: W,E - RSA private key: W,E",
            "secFunImpl": "ECDSA for Digital Signature Generation RSA for Signature Generation"
          },
          {
            "description": "Verify a digital signature",
            "indicator": "API return value",
            "inputs": "API call parameters, key, signature, message",
            "name": "Verify digital signature",
            "outputs": "Status",
            "rolesSspAccess": "User - ECDSA public key: W,E - RSA public key: W,E",
            "secFunImpl": "ECDSA for Digital Signature Verification RSA for Signature Verification"
          },
          {
            "description": "Perform key wrap",
            "indicator": "API return value",
            "inputs": "API call parameters, encryption key, key",
            "name": "Perform key wrap",
            "outputs": "Status, encrypted key",
            "rolesSspAccess": "User - AES key: W,E - AES CCM key: W,E - AES CMAC key: W,E - AES GMAC key: W,E - AES GCM key: W,E - AES GCM IV: G,R,E",
            "secFunImpl": "AES for Key Wrapping/Unwrapping"
          },
          {
            "description": "Perform key unwrap",
            "indicator": "API return value",
            "inputs": "API call parameters, decryption key, key",
            "name": "Perform key unwrap",
            "outputs": "Status, decrypted key",
            "rolesSspAccess": "User - AES key: W,E - AES CCM key: W,E - AES CMAC key: W,E - AES GMAC key: W,E - AES GCM key: W,E - AES GCM IV: W,E",
            "secFunImpl": "AES for Key Wrapping/Unwrapping"
          },
          {
            "description": "Compute ECDH shared secret suitable for use as input to a TLS KDF",
            "indicator": "API return value",
            "inputs": "API call parameters",
            "name": "Compute shared secret",
            "outputs": "Status, shared secret",
            "rolesSspAccess": "User - ECDH public component: W,E - ECDH private component: W,E",
            "secFunImpl": "ECDH Shared Secret Computation"
          },
          {
            "description": "Utilize TLS protocol",
            "indicator": "API return value",
            "inputs": "API call parameters, TLS certs and keys, raw application data, TLS session data",
            "name": "TLS v1.2 network protocol",
            "outputs": "Status, TLS keys, TLS session data, decrypted application data",
            "rolesSspAccess": "User - ECDH public component: W,E - ECDH private component: W,E - TLS extended pre-master secret: W,E - TLS master secret: W,E - TLS Authentication Key (HMAC key): W,E - TLS Session Key: W,E - TLS Server Authentication",
            "secFunImpl": "TLS v1.2 Key Agreement TLS v1.2 Authentication TLS v1.2 Data Encryption/Decryption"
          },
          {
            "description": "Derive TLS session and integrity keys",
            "indicator": "API return value",
            "inputs": "API call parameters, TLS extended pre-master secret",
            "name": "Derive keys via TLS v1.2 KDF",
            "outputs": "Status, TLS keys",
            "rolesSspAccess": "User - TLS extended pre-master secret: W,E - TLS master secret: G,E - TLS Session Key: G,E",
            "secFunImpl": "TLS v1.2 Key Derivation"
          },
          {
            "description": "Certificate management services",
            "indicator": "API return value",
            "inputs": "API call parameters, AES key, private keys, public keys, certificates, certificate data.",
            "name": "Certificate Management/Handling",
            "outputs": "Status",
            "rolesSspAccess": "User - AES key: W,E - AES XTS key: W,E - ECDSA public key: R,W,E - ECDSA private key: R,W,E - RSA public key: R,W,E - RSA private key: R,W,E",
            "secFunImpl": "AES for Symmetric Encryption/Decryption ECDSA for Digital Signature Generation ECDSA for Digital Signature Verification RSA for Signature Generation RSA for Signature Verification SHA for Message Digest SHA3 for Message Digest"
          },
          {
            "description": "Establish symmetric key using ECDH key agreement",
            "indicator": "API return value",
            "inputs": "API call parameters",
            "name": "Perform key agreement functions",
            "outputs": "Status, symmetric key",
            "rolesSspAccess": "User - ECDH public component: W,E - ECDH private component: W,E - AES key: G,R - AES GCM key: G,R - AES GCM IV: G,R - HMAC key: G,R",
            "secFunImpl": "TLS v1.2 Key Agreement"
          },
          {
            "description": "Derive key from HKDF",
            "indicator": "API return value",
            "inputs": "API call parameters, input key material",
            "name": "Derive key via HKDF",
            "outputs": "Status, key",
            "rolesSspAccess": "User - HKDF Derived key: G,R",
            "secFunImpl": "HKDF for Key Derivation"
          },
          {
            "description": "Derive key from PBKDF2",
            "indicator": "API return value",
            "inputs": "API call parameters, password",
            "name": "Derive key via PBKDF2",
            "outputs": "Status, key",
            "rolesSspAccess": "User - Password: W,E - PBKDF Derived key: G,R",
            "secFunImpl": "PBKDF for Key Derivation"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-ECB (A5055)",
            "condition": "Triggered upon first usage of MPC services.",
            "details": "Encrypt",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "128-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A5055)",
            "condition": "Triggered upon first usage of MPC services.",
            "details": "Sign",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "P-256; SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5055)",
            "condition": "Triggered upon first usage of MPC services.",
            "details": "Sign",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "2048-bit; SHA2-224; PKCS#1.5 scheme",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Encrypt",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "128-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Decrypt",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "128-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CCM (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Encrypt",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "192-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CCM (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Decrypt",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "192-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Encrypt",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "128-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Decrypt",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "128-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS Testing Revision 2.0 (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Encrypt",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "128-bit, 256-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS Testing Revision 2.0 (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Decrypt",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "128-bit, 256-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CMAC (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Generate",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "CBC mode; 128-bit, 192- bit, 256-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Instantiate, Reseed, Generate",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "AES, 256-bit, with derivation function",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Sign",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "P-224; SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Verify",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "P-224; SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Sign",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "2048-bit; SHA2-256; PKCS#1.5 scheme",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Verify",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "2048-bit; SHA2-256; PKCS#1.5 scheme",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA-1 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hashed message authentication",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 224 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hashed message authentication",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hashed message authentication",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 384 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hashed message authentication",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "SHA2-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 512 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hashed message authentication",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hash",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-224 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hash",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-256 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hash",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-384 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hash",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hash",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A5056)",
            "condition": "Upon power-up and before the pre- operational software integrity tests.",
            "details": "Hash",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Shared Secret \"Z\" Computation",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "P-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA HKDF SP800-56Cr2 (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Derive",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Derive",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5056)",
            "condition": "After successful completion of software integrity tests.",
            "details": "Derive",
            "indicator": "A boolean value indicating success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A5055)",
            "condition": "Executed upon key pair generation before returning key pair.",
            "details": "Sign/Verify",
            "indicator": "An integer value indicating success (1) or failure (0) of the self- test procedure call.",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A5055)",
            "condition": "Executed upon key pair generation before returning key pair.",
            "details": "Sign/Verify",
            "indicator": "An integer value indicating success (1) or failure (0) of the self- test procedure call.",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A5056)",
            "condition": "Executed upon key pair generation before returning key pair.",
            "details": "Sign/Verify",
            "indicator": "An integer value indicating success (1) or failure (0) of the self- test procedure call.",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A5056)",
            "condition": "Executed upon key pair generation before returning key pair.",
            "details": "Sign/Verify",
            "indicator": "An integer value indicating success (1) or failure (0) of the self- test procedure call.",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDH",
            "condition": "Executed upon key pair generation before returning key pair.",
            "details": "Sign/Verify",
            "indicator": "An integer value indicating success (1) or failure (0) of the self- test procedure call.",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "AES-XTS Testing Revision 2.0 (A5056)",
            "condition": "Executed upon initialization of AES- XTS cipher with key data.",
            "details": "Duplicate key test",
            "indicator": "An integer value indicating success (1) or failure (0) of the self- test procedure call.",
            "testMethod": "Duplicate Key Test",
            "testProps": "-",
            "type": "Critical Function"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "If the module fails pre-operational integrity tests, the SHA/HMAC pre- operational KATs (SHA, HMAC), or the conditional CASTs (DRBG, AES-ECB, AES- CCM, AES-GCM, AES-XTS, AES-CMAC, ECDSA Sign/Verify, RSA Sign/Verify, KAS- ECC Shared Secret \u0027Z\u0027 Computation, HKDF, PBKDF, TLS v1.2 KDF).",
            "description": "The module immediately terminates the calling application\u0027s API call. Subsequent requests made by the calling application for cryptographic services will return failure indicator, disabling all access to cryptographic functions, SSPs, and data output services.",
            "indicator": "Returned error code and sets an internal flag. Further requests will return this failure indicator.",
            "name": "Critical Error",
            "recoveryMethod": "The module must be re-instantiated by the calling application. If errors persist, the CO should contact Ideem, Inc. for assistance."
          },
          {
            "conditions": "If the module fails ECDSA/RSA/ECDH PCTs or the AES-XTS duplicate key test.",
            "description": "The module enters this state upon the failure of a PCT or self-test. The module transitions back to normal operation where the service requiring the self-test can be re-run or a new service can be performed.",
            "indicator": "Returns error code",
            "name": "Soft Error",
            "recoveryMethod": "Module records the error and resumes normal operation"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Mode allows the use of cryptographic operations",
            "name": "Approved",
            "statusIndicator": "",
            "type": "Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "Logical interface is defined as API input arguments that provide input data for processing. This includes data to be encrypted, decrypted, signed, verified, and hashed, keys to be used in cryptographic services, random seed material for the DRBG of the module, keying material used as input to key establishment services, and intermediate data required for services.",
            "logicalInterface": "Data Input",
            "physicalPort": "Physical data input port(s) of the tested platforms"
          },
          {
            "data": "Logical interface is defined as API output arguments that return generated or processed data back to the caller. This includes data that has been encrypted/decrypted/verified, digital signatures, hashes, random values generated by the DRBG of the module, keys established using key establishment methods of the module, and key components/intermediate data/traffic (client and server data and messages).",
            "logicalInterface": "Data Output",
            "physicalPort": "Physical data output port(s) of the tested platforms"
          },
          {
            "data": "Logical interface is defined as API input arguments that are used to initialize and control the operation of the module. This includes API commands invoking cryptographic services, modes, key sizes, etc. used with cryptographic services.",
            "logicalInterface": "Control Input",
            "physicalPort": "Physical control input port(s) of the tested platforms"
          },
          {
            "data": "Logical interface is defined as API call return values. This includes status information regarding the module or invoked service/operation.",
            "logicalInterface": "Status Output",
            "physicalPort": "Physical status output port(s) of the tested platforms"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto Officer",
            "operatorType": "CO",
            "type": "Role"
          },
          {
            "authMethodList": "None",
            "name": "User",
            "operatorType": "User",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "1",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A5056)",
            "details": "Software integrity test for libcrypto",
            "indicator": "A boolean value is returned indicating the success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "Software Integrity",
            "testProps": "SHA2-256",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A5056)",
            "details": "Software integrity test for libssl",
            "indicator": "A boolean value is returned indicating the success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "Software Integrity",
            "testProps": "SHA2-256",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A5056)",
            "details": "Software integrity test for libsecurikey",
            "indicator": "A boolean value is returned indicating the success (true) or failure (false) of the self-test procedure call.",
            "testMethod": "Software Integrity",
            "testProps": "SHA2-256",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "RAM",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Plaintext import via API parameter",
            "sfiAlgo": "",
            "source": "External"
          },
          {
            "dest": "External",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Plaintext export via API parameter",
            "sfiAlgo": "",
            "source": "RAM"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "The OpenSSL_cleanse() function zeroizes SSPs. OpenSSL_cleanse() may only be called directly by the calling application for some SSPs. However, other SSPs will be zeroized by an indirect call to OpenSSL_cleanse() via object destruction APIs.",
            "method": "Zeroize service",
            "operatorId": "The operator calls the OpenSSL_cleanse(). The successful completion of the procedural zeroization suffices as the implicit indicator that zeroization has completed.",
            "rationale": "The OpenSSL_cleanse() service zeroizes SSPs, which makes them irretrievable."
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "SSPs stored in RAM",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "",
            "integrityTest": "Yes",
            "packageFileName": "RedHat: libcrypto.so, libsecurikey.so, libssl.so, libcrypto.hmac, libsecurikey.hmac, libssl.hmac",
            "swFwVersion": "1.0"
          },
          {
            "features": "",
            "integrityTest": "Yes",
            "packageFileName": "Android: libcrypto.so, libsecurikey.so, libssl.so, libcrypto.hmac, libsecurikey.hmac, libssl.hmac",
            "swFwVersion": "1.0"
          },
          {
            "features": "",
            "integrityTest": "Yes",
            "packageFileName": "iOS: libcrypto.dylib, libsecurikey.dylib, libssl.dylib, libcrypto.hmac, libsecurikey.hmac, libssl.hmac",
            "swFwVersion": "1.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "Dell T5610",
            "hypervisorHostOs": "",
            "operatingSystem": "RedHat 9.2",
            "paa_pai": "Yes",
            "processors": "Intel Xeon CPU E5-2609 v2",
            "version": "1.0"
          },
          {
            "hardwarePlatform": "Dell T5610",
            "hypervisorHostOs": "",
            "operatingSystem": "RedHat 9.2",
            "paa_pai": "No",
            "processors": "Intel Xeon CPU E5-2609 v2",
            "version": "1.0"
          },
          {
            "hardwarePlatform": "iPhone 14",
            "hypervisorHostOs": "",
            "operatingSystem": "iOS 16.5",
            "paa_pai": "Yes",
            "processors": "Apple A15 Bionic (ARMv8)",
            "version": "1.0"
          },
          {
            "hardwarePlatform": "iPhone 14",
            "hypervisorHostOs": "",
            "operatingSystem": "iOS 16.5",
            "paa_pai": "No",
            "processors": "Apple A15 Bionic (ARMv8)",
            "version": "1.0"
          },
          {
            "hardwarePlatform": "Pixel 6",
            "hypervisorHostOs": "",
            "operatingSystem": "Android 13",
            "paa_pai": "Yes",
            "processors": "Octa-core (2x2.80 GHz Cortex-X1 \u0026 2x2.25 GHz Cortex-A76 \u0026 4x1.80 GHz Cortex-A55)",
            "version": "1.0"
          },
          {
            "hardwarePlatform": "Pixel 6",
            "hypervisorHostOs": "",
            "operatingSystem": "Android 13",
            "paa_pai": "No",
            "processors": "Octa-core (2x2.80 GHz Cortex-X1 \u0026 2x2.25 GHz Cortex-A76 \u0026 4x1.80 GHz Cortex-A55)",
            "version": "1.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "Any x86-based platform",
            "operatingSystem": "RedHat 7 and above"
          },
          {
            "hardwarePlatform": "Any x86-based platform",
            "operatingSystem": "CentOS 7 and above"
          },
          {
            "hardwarePlatform": "Any x86-based platform",
            "operatingSystem": "Ubuntu 16 and above"
          },
          {
            "hardwarePlatform": "iPhone 8 and newer",
            "operatingSystem": "iOS 12 and above"
          },
          {
            "hardwarePlatform": "Pixel 4a and newer",
            "operatingSystem": "Android 11 and above"
          },
          {
            "hardwarePlatform": "Any x86-based platform and iPhone 8 and newer (mixed configuration)",
            "operatingSystem": "RedHat 7 and above and iOS 12 and above"
          },
          {
            "hardwarePlatform": "Any x86-based platform and iPhone 8 and newer (mixed configuration)",
            "operatingSystem": "CentOS 7 and above and iOS 12 and above"
          },
          {
            "hardwarePlatform": "Any x86-based platform and iPhone 8 and newer (mixed configuration)",
            "operatingSystem": "Ubuntu 16 and above and iOS 12 and above"
          },
          {
            "hardwarePlatform": "Any x86-based platform and Pixel 4a and newer (mixed configuration)",
            "operatingSystem": "RedHat 7 and above and Android 11 and above"
          },
          {
            "hardwarePlatform": "Any x86-based platform and Pixel 4a and newer (mixed configuration)",
            "operatingSystem": "CentOS 7 and above and Android 11 and above"
          },
          {
            "hardwarePlatform": "Any x86-based platform and Pixel 4a and newer (mixed configuration)",
            "operatingSystem": "Ubuntu 16 and above and Android 11 and above"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 2
          },
          "ECDH": {
            "ECDH": 25
          },
          "ECDSA": {
            "ECDSA": 80
          }
        },
        "FF": {
          "DH": {
            "DH": 1,
            "Diffie-Hellman": 2
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 3
        },
        "CCM": {
          "CCM": 7
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 2
        },
        "GCM": {
          "GCM": 26
        },
        "OFB": {
          "OFB": 1
        },
        "XTS": {
          "XTS": 7
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "TLS": {
            "TLS": 39,
            "TLS v1.2": 36
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 9,
          "Key agreement": 1
        },
        "MAC": {
          "MAC": 5
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 16,
          "P-256": 16,
          "P-384": 10,
          "P-521": 10
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES GCM 96": 1,
          "AES-128": 1,
          "AES-192": 1,
          "AES-256": 1,
          "DRBG 128": 1,
          "HMAC-SHA-1": 12,
          "PKCS#1": 6,
          "SHA-1": 11,
          "SHA2- 256": 4,
          "SHA2-224": 12,
          "SHA2-256": 27,
          "SHA2-384": 13,
          "SHA2-512": 17,
          "SHA2-512 2": 1,
          "SHA3": 3,
          "SHA3- 256": 1,
          "SHA3-224": 9,
          "SHA3-256": 5,
          "SHA3-384": 9,
          "SHA3-512": 3
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 15,
          "PBKDF2": 3
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 11
          },
          "SHA3": {
            "SHA3": 3,
            "SHA3-224": 10,
            "SHA3-256": 4,
            "SHA3-384": 10,
            "SHA3-512": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 40
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 66,
          "FIPS 180-4": 7,
          "FIPS 186-4": 3,
          "FIPS 186-5": 13,
          "FIPS 198-1": 11,
          "FIPS 202": 6,
          "FIPS PUB 140-3": 1,
          "FIPS PUB 186-4": 1,
          "FIPS186-4": 6,
          "FIPS186-5": 32
        },
        "ISO": {
          "ISO/IEC 19790": 8
        },
        "NIST": {
          "NIST SP 800-132": 1,
          "NIST SP 800-38D": 1,
          "NIST SP 800-38E": 1,
          "SP 800-132": 2,
          "SP 800-133": 1,
          "SP 800-135": 2,
          "SP 800-38A": 9,
          "SP 800-38B": 1,
          "SP 800-38C": 1,
          "SP 800-38D": 3,
          "SP 800-38E": 1,
          "SP 800-38F": 2,
          "SP 800-56A": 1,
          "SP 800-56C": 1,
          "SP 800-90A": 2
        },
        "PKCS": {
          "PKCS#1": 3
        },
        "RFC": {
          "RFC 5246": 1,
          "RFC 5288": 1,
          "RFC7627": 5
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 81,
            "AES-": 2,
            "AES-128": 1,
            "AES-192": 1,
            "AES-256": 1
          },
          "CAST": {
            "CAST": 64
          }
        },
        "DES": {
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 6,
            "HMAC": 22
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 6
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA3-384A5056",
        "RSA KeyGen (FIPS186-5)A5056",
        "SHAKE-128A5056",
        "AES-GMACA5056",
        "AES-CFB1A5056",
        "KDF TLSA5056",
        "RSA SigVer (FIPS186-5)A5056",
        "SHA2-224A5056",
        "AES-XTS Testing Revision 2.0A5056",
        "AES-CTRA5056",
        "SHAKE-256A5056",
        "HMAC-SHA2-512/224A5056",
        "ECDSA KeyVer (FIPS186-5)A5056",
        "Counter DRBGA5056",
        "HMAC-SHA-1A5056",
        "KDA HKDF SP800-56Cr2A5056",
        "AES-CMACA5056",
        "AES-CFB128A5056",
        "HMAC-SHA2-256A5056",
        "KAS-ECC-SSC Sp800-56Ar3A5056",
        "HMAC-SHA2-512A5056",
        "ECDSA SigGen (FIPS186-5)A5056",
        "PBKDFA5056",
        "HMAC-SHA3-256A5056",
        "ECDSA SigVer (FIPS186-5)A5056",
        "TLS v1.2 KDF RFC7627A5056",
        "SHA-1A5056",
        "SHA3-224A5056",
        "AES-OFBA5056",
        "SHA2-384A5056",
        "HMAC-SHA2-512/256A5056",
        "ECDSA SigGen (FIPS186-4)A5055",
        "HMAC-SHA3-512A5056",
        "SHA3-256A5056",
        "HMAC-SHA2-224A5056",
        "HMAC-SHA2-384A5056",
        "AES-ECBA5056",
        "AES-CBCA5056",
        "SHA3-384A5056",
        "ECDSA KeyGen (FIPS186-4)A5055",
        "SHA2-512/224A5056",
        "SHA2-512A5056",
        "SHA3-512A5056",
        "SHA2-256A5056",
        "AES-CCMA5056",
        "SHA2-512/256A5056",
        "ECDSA KeyGen (FIPS186-5)A5056",
        "AES-CFB8A5056",
        "AES-KWA5056",
        "RSA SigGen (FIPS186-5)A5056",
        "AES-GCMA5056",
        "HMAC-SHA3-224A5056",
        "AES-KWPA5056"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A5056",
        "#A5055"
      ]
    },
    "policy_metadata": {
      "/Author": "Corsec Security, Inc.",
      "/Comments": "",
      "/Company": "Corsec Security, Inc.",
      "/ContentTypeId": "0x0101008CEA64F1FB1D5A4F93ABC4EA3F4AF0B8",
      "/CreationDate": "D:20250514084314-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/MediaServiceImageTags": "",
      "/ModDate": "D:20250514084527-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.208",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "FIPS 140-3 Non-Proprietary Security Policy",
      "/_Algorithm Implementation 1": "Ideem ZSM Multi-party Cryptographic Library",
      "/_Algorithm Implementation 2": "Ideem ZSM Single-party Cryptographic Library",
      "/_Copyright": "2024",
      "/_Document Date": "February 19, 2025",
      "/_Document Version": "1.0",
      "/_FIPS Security Level": "1",
      "/_Module Embodiment": "MultiChipStand",
      "/_Module Name (long)": "Ideem ZSM Cryptographic Module",
      "/_Module Name (short)": "Ideem Cryptographic Module",
      "/_Module Type": "software",
      "/_Module Version Number": "1.0",
      "/_Vendor Name (long)": "Ideem, Inc.",
      "/_Vendor Name (short)": "Ideem",
      "pdf_file_size_bytes": 831258,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://www.useideem.com/",
          "https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Validated-Modules/Search",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=17572",
          "http://csrc.nist.gov/groups/STM/cmvp",
          "http://www.corsec.com/",
          "mailto:[email protected]",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=17571"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 58
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "c4a0a8844482888643d14062dcf7625229abd8f076929fe190300806e36045d0",
      "source_hash": "63bf017deded73e7d519344c9c577f5336dcacfef69748eff20f3a24abcbe4ea",
      "txt_hash": "a57a8a59610ae83f14c334bb90afe65c27eba41a0902a19cce09709d3411e084"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "No assurance of the minimum strength of generated SSPs (e.g., keys)",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/March 2025_010425_0326.pdf",
    "date_sunset": "2030-03-02",
    "description": "Ideem ZSM Cryptographic Module randomly splits keys across servers so that they are never in any single place to be stolen. The advanced protocols used in Ideem ZSM ensure that even if servers are breached and completely controlled by an attacker, the secrets and credentials cannot be stolen. The result is that digital assets remain safe, even if all else fails and attackers get inside the network. Ideem ZSM is able to protect all types of standard cryptographic keys for all purposes, including encryption/decryption, digital signing, and authentication. Ideem\u2019s technology for securing keys using two-party computation (TPC) is fully transparent to the calling application.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Ideem ZSM Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-03-03",
        "lab": "Teron Labs",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-05-19",
        "lab": "Teron Labs",
        "validation_type": "Update"
      }
    ],
    "vendor": "Ideem, Inc.",
    "vendor_url": "https://www.useideem.com"
  }
}