Apple corecrypto Module v12 [Intel, User, Software]

Certificate details

Certificate ID #4951
Status active
Validation dates 27.01.2025
Sunset date 26-01-2027
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat Interim validation. When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Apple corecrypto User module is a software cryptographic module running on a multi-chip standalone hardware device and provides services intended to protect data in transit and at rest.
Tested configurations
  • macOS Monterey 12 running on iMac Pro with Xeon W (Sky Lake) with PAA
  • macOS Monterey 12 running on iMac Pro with Xeon W (Sky Lake) without PAA
  • macOS Monterey 12 running on iMac with an Intel i5 (Comet Lake) with PAA
  • macOS Monterey 12 running on iMac with an Intel i5 (Comet Lake) without PAA
  • macOS Monterey 12 running on iMac with an Intel i7 (Comet Lake) with PAA
  • macOS Monterey 12 running on iMac with an Intel i7 (Comet Lake) without PAA
  • macOS Monterey 12 running on Mac Pro with Xeon W (Cascade Lake) with PAA
  • macOS Monterey 12 running on Mac Pro with Xeon W (Cascade Lake) without PAA (single-user mode)
  • macOS Monterey 12 running on MacBook Air with an Intel i5 (Amber Lake) with PAA
  • macOS Monterey 12 running on MacBook Air with an Intel i5 (Amber Lake) without PAA
  • macOS Monterey 12 running on MacBook Air with an Intel i7 (Ice Lake) with PAA
  • macOS Monterey 12 running on MacBook Air with an Intel i7 (Ice Lake) without PAA
  • macOS Monterey 12 running on MacBook Pro with an Intel i7 (Coffee Lake) with PAA
  • macOS Monterey 12 running on MacBook Pro with an Intel i7 (Coffee Lake) without PAA
  • macOS Monterey 12 running on MacBook Pro with an Intel i9 (Coffee Lake) with PAA
  • macOS Monterey 12 running on MacBook Pro with an Intel i9 (Coffee Lake) without PAA
Vendor Apple, Inc. http://www.apple.com
Lab Acumen Security
Algorithms
  • AES-CBCA2820
  • AES-CCMA2822
  • AES-CFB128A2820
  • AES-CFB8A2820
  • AES-CMACA2820
  • AES-CTRA2822
  • AES-ECBA2822
  • AES-GCMA2822
  • AES-KWA2820
  • AES-OFBA2820
  • AES-XTS Testing Revision 2.0A2820
  • Counter DRBGA2822
  • ECDSA KeyGen (FIPS186-4)A2820
  • ECDSA KeyVer (FIPS186-4)A2820
  • ECDSA SigGen (FIPS186-4)A2820
  • ECDSA SigVer (FIPS186-4)A2820
  • HMAC DRBGA2820
  • HMAC-SHA-1A2823
  • HMAC-SHA2-224A2823
  • HMAC-SHA2-256A2823
  • HMAC-SHA2-384A2823
  • HMAC-SHA2-512/256A2820
  • HMAC-SHA2-512A2823
  • KAS-ECC-SSC Sp800-56Ar3A2820
  • KAS-FFC-SSC Sp800-56Ar3A2820
  • KDF SP800-108A2820
  • PBKDFA2820
  • RSA KeyGen (FIPS186-4)A2820
  • RSA SigGen (FIPS186-4)A2820
  • RSA SigVer (FIPS186-4)A2820
  • Safe Primes Key GenerationA2820
  • SHA-1A2823
  • SHA2-224A2823
  • SHA2-256A2823
  • SHA2-384A2823
  • SHA2-512/256A2820
  • SHA2-512A2823
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-128, AES-256, AES, AES-, CAST, CAST5, RC4, RC2, DES, Triple-DES, Blowfish, HMAC, CMAC
Asymmetric Algorithms
RSA 2048, ECDH, ECDSA, ECIES, ECC, Diffie-Hellman, DH
Hash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, MD4, MD5, RIPEMD, PBKDF
Schemes
MAC, Key Agreement, Key agreement
Protocols
TLS, TLS 1.2, IKE, IPsec
Randomness
DRBG
Elliptic Curves
P-224, P-256, P-521, Curve P-192, P-384, curve P-192, P-192, Ed25519
Block cipher modes
ECB, CBC, CTR, OFB, GCM, CCM, XTS

Trusted Execution Environments
SSC

Security level
Level 1, level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4951,
  "dgst": "625501d1100c1c84",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "#A2814",
        "#A2819",
        "HMAC-SHA-1A2823",
        "SHA-1A2823",
        "#A2820",
        "AES-CFB128A2820",
        "KAS-FFC-SSC Sp800-56Ar3A2820",
        "SHA2-224A2823",
        "HMAC-SHA2-256A2823",
        "#A2813",
        "#A2817",
        "#A9819",
        "Counter DRBGA2822",
        "KDF SP800-108A2820",
        "AES-GCMA2822",
        "KAS-ECC-SSC Sp800-56Ar3A2820",
        "HMAC-SHA2-512/256A2820",
        "AES-XTS Testing Revision 2.0A2820",
        "RSA KeyGen (FIPS186-4)A2820",
        "AES-CTRA2822",
        "#A2815",
        "SHA2-512A2823",
        "AES-KWA2820",
        "PBKDFA2820",
        "Safe Primes Key GenerationA2820",
        "#A2818",
        "ECDSA KeyGen (FIPS186-4)A2820",
        "HMAC-SHA2-384A2823",
        "AES-OFBA2820",
        "ECDSA SigGen (FIPS186-4)A2820",
        "HMAC-SHA2-512A2823",
        "RSA SigVer (FIPS186-4)A2820",
        "AES-ECBA2822",
        "SHA2-512/256A2820",
        "AES-CBCA2820",
        "HMAC-SHA2-224A2823",
        "HMAC DRBGA2820",
        "RSA SigGen (FIPS186-4)A2820",
        "AES-CCMA2822",
        "#A2822",
        "SHA2-256A2823",
        "SHA2-384A2823",
        "AES-CMACA2820",
        "AES-CFB8A2820",
        "ECDSA SigVer (FIPS186-4)A2820",
        "#A2816",
        "ECDSA KeyVer (FIPS186-4)A2820",
        "#A2812",
        "#A2823",
        "#A2821"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 32,
    "br1_tables": null,
    "is_br1_format": false,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 8
          },
          "ECDH": {
            "ECDH": 1
          },
          "ECDSA": {
            "ECDSA": 23
          },
          "ECIES": {
            "ECIES": 4
          }
        },
        "FF": {
          "DH": {
            "DH": 9,
            "Diffie-Hellman": 11
          }
        },
        "RSA": {
          "RSA 2048": 2
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 9
        },
        "CCM": {
          "CCM": 5
        },
        "CTR": {
          "CTR": 4
        },
        "ECB": {
          "ECB": 7
        },
        "GCM": {
          "GCM": 10
        },
        "OFB": {
          "OFB": 3
        },
        "XTS": {
          "XTS": 8
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 1
        },
        "IPsec": {
          "IPsec": 2
        },
        "TLS": {
          "TLS": {
            "TLS": 6,
            "TLS 1.2": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 6,
          "Key agreement": 2
        },
        "MAC": {
          "MAC": 7
        }
      },
      "device_model": {},
      "ecc_curve": {
        "Edwards": {
          "Ed25519": 7
        },
        "NIST": {
          "Curve P-192": 4,
          "P-192": 5,
          "P-224": 26,
          "P-256": 24,
          "P-384": 8,
          "P-521": 24,
          "curve P-192": 1
        }
      },
      "eval_facility": {
        "Acumen": {
          "Acumen Security": 1
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES CBC 128": 2,
          "AES CMAC 128": 2,
          "AES GCM 128": 2,
          "AES- 256": 1,
          "AES-128": 6,
          "AES-256": 6,
          "HMAC- SHA-1": 2,
          "HMAC-SHA- 1": 4,
          "HMAC-SHA-1": 4,
          "PKCS#1": 18,
          "RSA 2048": 2,
          "SHA- 224": 1,
          "SHA- 256": 1,
          "SHA- 384": 2,
          "SHA- 512": 2,
          "SHA-1": 25,
          "SHA-224": 9,
          "SHA-256": 12,
          "SHA-384": 8,
          "SHA-512": 8,
          "SHA-512 112": 1,
          "SHA2- 224": 7,
          "SHA2- 256": 3,
          "SHA2- 512": 1,
          "SHA2-224": 9,
          "SHA2-256": 14,
          "SHA2-284": 7,
          "SHA2-384": 6,
          "SHA2-512": 12
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2,
          "level 1": 2
        }
      },
      "hash_function": {
        "MD": {
          "MD4": {
            "MD4": 2
          },
          "MD5": {
            "MD5": 1
          }
        },
        "PBKDF": {
          "PBKDF": 16
        },
        "RIPEMD": {
          "RIPEMD": 2
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 25
          },
          "SHA2": {
            "SHA-224": 9,
            "SHA-256": 12,
            "SHA-384": 8,
            "SHA-512": 9
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 19
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 13,
          "FIPS 1403": 1,
          "FIPS 180-4": 1,
          "FIPS 186-4": 3,
          "FIPS 197": 2,
          "FIPS 198": 1,
          "FIPS PUB 140-3": 1,
          "FIPS186-4": 1
        },
        "ISO": {
          "ISO/IEC 24759": 2
        },
        "NIST": {
          "NIST SP 800-140B": 2,
          "NIST SP 800-140F": 1,
          "NIST SP 800-90B": 2,
          "SP 800-38": 10,
          "SP 800-38D": 1,
          "SP 800-38F": 1,
          "SP 800-67": 1,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS#1": 9
        },
        "RFC": {
          "RFC 3526": 1,
          "RFC 4106": 1,
          "RFC 5288": 1,
          "RFC6637": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 23,
            "AES-": 8,
            "AES-128": 6,
            "AES-256": 6
          },
          "CAST": {
            "CAST": 4,
            "CAST5": 1
          },
          "RC": {
            "RC2": 2,
            "RC4": 2
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 4
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 7,
            "HMAC": 14
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 2
          }
        }
      },
      "tee_name": {
        "IBM": {
          "SSC": 7
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA-1A2823",
        "SHA-1A2823",
        "AES-CFB128A2820",
        "KAS-FFC-SSC Sp800-56Ar3A2820",
        "SHA2-224A2823",
        "HMAC-SHA2-256A2823",
        "Counter DRBGA2822",
        "KDF SP800-108A2820",
        "AES-GCMA2822",
        "KAS-ECC-SSC Sp800-56Ar3A2820",
        "HMAC-SHA2-512/256A2820",
        "AES-XTS Testing Revision 2.0A2820",
        "RSA KeyGen (FIPS186-4)A2820",
        "AES-CTRA2822",
        "SHA2-512A2823",
        "AES-KWA2820",
        "PBKDFA2820",
        "Safe Primes Key GenerationA2820",
        "ECDSA KeyGen (FIPS186-4)A2820",
        "HMAC-SHA2-384A2823",
        "AES-OFBA2820",
        "ECDSA SigGen (FIPS186-4)A2820",
        "HMAC-SHA2-512A2823",
        "RSA SigVer (FIPS186-4)A2820",
        "AES-ECBA2822",
        "SHA2-512/256A2820",
        "AES-CBCA2820",
        "HMAC-SHA2-224A2823",
        "HMAC DRBGA2820",
        "RSA SigGen (FIPS186-4)A2820",
        "AES-CCMA2822",
        "SHA2-256A2823",
        "SHA2-384A2823",
        "AES-CMACA2820",
        "AES-CFB8A2820",
        "ECDSA SigVer (FIPS186-4)A2820",
        "ECDSA KeyVer (FIPS186-4)A2820"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A2814",
        "#A9819",
        "#A2819",
        "#A2818",
        "#A2820",
        "#A2823",
        "#A2816",
        "#A2812",
        "#A2815",
        "#A2813",
        "#A2817",
        "#A2822",
        "#A2821"
      ]
    },
    "policy_metadata": {
      "/Author": "Aniket Ingle  Intertek",
      "/ClassificationContentMarkingFooterFontProps": "#000000,7,Calibri",
      "/ClassificationContentMarkingFooterShapeIds": "2,4,5",
      "/ClassificationContentMarkingFooterText": "Juniper Business Use Only",
      "/Comments": "",
      "/Company": "",
      "/ContentTypeId": "0x0101005FC48ADBEA28F14BA352723A969D8CBC",
      "/CreationDate": "D:20250115155910+05\u002730\u0027",
      "/Creator": "Acrobat PDFMaker 24 for Word",
      "/Keywords": "",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ActionId": "10f4ee9b-e3a9-4cc7-88d2-2f42364a5831",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ContentBits": "2",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Enabled": "true",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Method": "Standard",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Name": "0633b888-ae0d-4341-a75f-06e04137d755",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SetDate": "2022-11-30T05:04:04Z",
      "/MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SiteId": "bea78b3c-4cdb-4130-854a-1d193232e5f4",
      "/ModDate": "D:20250115155938+05\u002730\u0027",
      "/Producer": "Adobe PDF Library 24.4.48",
      "/SourceModified": "D:20250115102859",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 639466,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.apple.com/legal/intellectual-",
          "https://www.acumensecurity.net/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 52
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "dc2f0350148b24e27bccff61ef96eddb13a1987e0fca102399ecac89e57cbf69",
      "source_hash": "81f7ff68eb821f5d45f0d76e97d51fe0e3ce7f8a94d2088c52b99be216b7caf0",
      "txt_hash": "eb5cce5a98b80fd583badddd9dfd2104c77813e54b01af7a4d04dec238252d99"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim validation. When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/January 2025-signed.pdf",
    "date_sunset": "2027-01-26",
    "description": "The Apple corecrypto User module is a software cryptographic module running on a multi-chip standalone hardware device and provides services intended to protect data in transit and at rest.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Apple corecrypto Module v12 [Intel, User, Software]",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": "12",
    "tested_conf": [
      "macOS Monterey 12 running on iMac Pro with Xeon W (Sky Lake) with PAA",
      "macOS Monterey 12 running on iMac Pro with Xeon W (Sky Lake) without PAA",
      "macOS Monterey 12 running on iMac with an Intel i5 (Comet Lake) with PAA",
      "macOS Monterey 12 running on iMac with an Intel i5 (Comet Lake) without PAA",
      "macOS Monterey 12 running on iMac with an Intel i7 (Comet Lake) with PAA",
      "macOS Monterey 12 running on iMac with an Intel i7 (Comet Lake) without PAA",
      "macOS Monterey 12 running on Mac Pro with Xeon W (Cascade Lake) with PAA",
      "macOS Monterey 12 running on Mac Pro with Xeon W (Cascade Lake) without PAA (single-user mode)",
      "macOS Monterey 12 running on MacBook Air with an Intel i5 (Amber Lake) with PAA",
      "macOS Monterey 12 running on MacBook Air with an Intel i5 (Amber Lake) without PAA",
      "macOS Monterey 12 running on MacBook Air with an Intel i7 (Ice Lake) with PAA",
      "macOS Monterey 12 running on MacBook Air with an Intel i7 (Ice Lake) without PAA",
      "macOS Monterey 12 running on MacBook Pro with an Intel i7 (Coffee Lake) with PAA",
      "macOS Monterey 12 running on MacBook Pro with an Intel i7 (Coffee Lake) without PAA",
      "macOS Monterey 12 running on MacBook Pro with an Intel i9 (Coffee Lake) with PAA",
      "macOS Monterey 12 running on MacBook Pro with an Intel i9 (Coffee Lake) without PAA"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-01-27",
        "lab": "Acumen Security",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Apple, Inc.",
    "vendor_url": "http://www.apple.com"
  }
}