HID/Mercury FIPS Provider for OpenSSL 3

Certificate details

Certificate ID #4923
Status active
Validation dates 18.12.2024 , 20.08.2025
Sunset date 10-07-2029
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat No assurance of the minimum strength of generated SSPs (e.g., keys).
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Life-cycle assurance: Level 3
Description The HID/Mercury FIPS Provider for OpenSSL 3 is a secure cryptographic module that enhances the cryptographic capabilities of HID and Mercury intelligent controllers, complying with the FIPS 140-3 standard. It integrates seamlessly with OpenSSL 3 to offer advanced encryption, decryption, hashing, and key management functions, ensuring high performance and robust security. Designed to meet stringent industry requirements, this provider ensures that all cryptographic operations are executed securely and efficiently, making it ideal for applications demanding the highest level of security assurance.
Vendor [email protected] /cdn-cgi/l/email-protection
Lab DEKRA Cybersecurity Certification Laboratory, Acumen Security
Algorithms
  • AES-CBC-CS1A4481
  • AES-CBC-CS2A4481
  • AES-CBC-CS3A4481
  • AES-CBCA4481
  • AES-CCMA4481
  • AES-CFB128A4481
  • AES-CFB1A4481
  • AES-CFB8A4481
  • AES-CMACA4481
  • AES-CTRA4481
  • AES-ECBA4481
  • AES-GCMA4481
  • AES-GMACA4481
  • AES-KWA4481
  • AES-KWPA4481
  • AES-OFBA4481
  • AES-XTS Testing Revision 2.0A4481
  • Counter DRBGA4481
  • DSA KeyGen (FIPS186-4)A4481
  • DSA PQGGen (FIPS186-4)A4481
  • DSA PQGVer (FIPS186-4)A4481
  • DSA SigGen (FIPS186-4)A4481
  • DSA SigVer (FIPS186-4)A4481
  • ECDSA KeyGen (FIPS186-4)A4481
  • ECDSA KeyVer (FIPS186-4)A4481
  • ECDSA SigGen (FIPS186-4)A4481
  • ECDSA SigVer (FIPS186-4)A4481
  • EDDSA KeyGenA4481
  • EDDSA KeyVerA4481
  • EDDSA SigGenA4481
  • EDDSA SigVerA4481
  • Hash DRBGA4481
  • HMAC DRBGA4481
  • HMAC-SHA-1A4481
  • HMAC-SHA2-224A4481
  • HMAC-SHA2-256A4481
  • HMAC-SHA2-384A4481
  • HMAC-SHA2-512/224A4481
  • HMAC-SHA2-512/256A4481
  • HMAC-SHA2-512A4481
  • HMAC-SHA3-224A4481
  • HMAC-SHA3-256A4481
  • HMAC-SHA3-384A4481
  • HMAC-SHA3-512A4481
  • KAS-ECC CDH-Component SP800-56Ar3A4481
  • KAS-ECC-SSC Sp800-56Ar3A4481
  • KAS-FFC-SSC Sp800-56Ar3A4481
  • KAS-IFC-SSCA4481
  • KDA HKDF SP800-56Cr2A4481
  • KDA OneStep SP800-56Cr2A4481
  • KDA TwoStep SP800-56Cr2A4481
  • KDF ANS 9.42A4481
  • KDF ANS 9.63A4481
  • KDF SP800-108A4481
  • KDF SSHA4481
  • KMAC-128A4481
  • KMAC-256A4481
  • KTS-IFCA4481
  • PBKDFA4481
  • RSA KeyGen (FIPS186-4)A4481
  • RSA SigGen (FIPS186-4)A4481
  • RSA SigGen (FIPS186-5)A4481
  • RSA Signature PrimitiveA4481
  • RSA SigVer (FIPS186-4)A4481
  • RSA SigVer (FIPS186-5)A4481
  • Safe Primes Key GenerationA4481
  • Safe Primes Key VerificationA4481
  • SHA-1A4481
  • SHA2-224A4481
  • SHA2-256A4481
  • SHA2-384A4481
  • SHA2-512/224A4481
  • SHA2-512/256A4481
  • SHA2-512A4481
  • SHA3-224A4481
  • SHA3-256A4481
  • SHA3-384A4481
  • SHA3-512A4481
  • SHAKE-128A4481
  • SHAKE-256A4481
  • TLS v1.2 KDF RFC7627A4481
  • TLS v1.3 KDFA4481
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-128, AES-192, AES-256, AES, CAST, HMAC, KMAC, CMAC
Asymmetric Algorithms
ECDSA, EdDSA, ECC, DHE, DSA
Hash functions
SHA-1, SHA2, SHA3-224, SHA3-384, SHA3-512, SHA3-256, SHA-3, SHA3, SHAKE128, SHAKE256, PBKDF
Schemes
MAC, Key agreement, Key Agreement, AEAD
Protocols
SSH, SSHv2, TLS v1.2, TLS v1.3, TLS 1.3, TLS, TLS 1.2
Randomness
DRBG, RBG
Libraries
OpenSSL
Elliptic Curves
P-224, P-256, P-384, P-521, P-192, B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, B-163, K-163
Block cipher modes
CTR, GCM, CCM

JavaCard API constants
ED25519, ED448
Trusted Execution Environments
PSP, SSC
Vendor
STMicroelectronics

Security level
Level 1
Side-channel analysis
timing attacks

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4923,
  "dgst": "66132b1c601d1f2c",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-512/224A4481",
        "AES-CFB1A4481",
        "ECDSA SigVer (FIPS186-4)A4481",
        "RSA SigVer (FIPS186-4)A4481",
        "SHA3-256A4481",
        "Hash DRBGA4481",
        "AES-CBCA4481",
        "SHA2-256A4481",
        "HMAC-SHA2-512A4481",
        "SHA3-512A4481",
        "DSA KeyGen (FIPS186-4)A4481",
        "PBKDFA4481",
        "ECDSA KeyGen (FIPS186-4)A4481",
        "KDF SP800-108A4481",
        "RSA SigGen (FIPS186-5)A4481",
        "HMAC-SHA3-256A4481",
        "KTS-IFCA4481",
        "SHA2-512/256A4481",
        "EDDSA SigGenA4481",
        "AES-CBC-CS2A4481",
        "TLS v1.3 KDFA4481",
        "Safe Primes Key GenerationA4481",
        "KDF ANS 9.63A4481",
        "AES-CBC-CS3A4481",
        "DSA PQGGen (FIPS186-4)A4481",
        "KAS-ECC CDH-Component SP800-56Ar3A4481",
        "KDF SSHA4481",
        "ECDSA KeyVer (FIPS186-4)A4481",
        "SHA2-224A4481",
        "AES-CFB8A4481",
        "AES-CFB128A4481",
        "KDA HKDF SP800-56Cr2A4481",
        "AES-CMACA4481",
        "KAS-IFC-SSCA4481",
        "DSA SigVer (FIPS186-4)A4481",
        "AES-GMACA4481",
        "HMAC-SHA2-256A4481",
        "SHA3-384A4481",
        "AES-CTRA4481",
        "AES-XTS Testing Revision 2.0A4481",
        "RSA SigGen (FIPS186-4)A4481",
        "HMAC-SHA2-512/224A4481",
        "SHA3-224A4481",
        "Counter DRBGA4481",
        "HMAC-SHA2-512/256A4481",
        "AES-ECBA4481",
        "HMAC-SHA3-224A4481",
        "SHAKE-128A4481",
        "DSA SigGen (FIPS186-4)A4481",
        "SHAKE-256A4481",
        "AES-GCMA4481",
        "KMAC-128A4481",
        "ECDSA SigGen (FIPS186-4)A4481",
        "AES-CCMA4481",
        "HMAC-SHA2-384A4481",
        "HMAC-SHA3-384A4481",
        "AES-OFBA4481",
        "AES-KWA4481",
        "EDDSA KeyVerA4481",
        "HMAC-SHA-1A4481",
        "KDA OneStep SP800-56Cr2A4481",
        "AES-KWPA4481",
        "#A4481",
        "DSA PQGVer (FIPS186-4)A4481",
        "AES-CBC-CS1A4481",
        "EDDSA KeyGenA4481",
        "RSA KeyGen (FIPS186-4)A4481",
        "KAS-ECC-SSC Sp800-56Ar3A4481",
        "SHA2-512A4481",
        "RSA Signature PrimitiveA4481",
        "SHA2-384A4481",
        "KAS-FFC-SSC Sp800-56Ar3A4481",
        "KDF ANS 9.42A4481",
        "KDA TwoStep SP800-56Cr2A4481",
        "TLS v1.2 KDF RFC7627A4481",
        "SHA-1A4481",
        "RSA SigVer (FIPS186-5)A4481",
        "Safe Primes Key VerificationA4481",
        "HMAC-SHA3-512A4481",
        "EDDSA SigVerA4481",
        "KMAC-256A4481",
        "HMAC-SHA2-224A4481",
        "HMAC DRBGA4481"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS1",
            "cavpCertName": "A4481",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-512 Increment 8",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS2",
            "cavpCertName": "A4481",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-512 Increment 8",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS3",
            "cavpCertName": "A4481",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 136-512 Increment 8",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A4481",
            "properties": "Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56-104 Increment 8 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0-524288 Increment 8",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB1",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - Yes",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96-1024 Increment 8 Payload Length - Payload Length: 8-65536 Increment 8 AAD Length - AAD Length: 0-65536 Increment 8",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Cipher - Cipher, Inverse Key Length - 128, 192, 256 Payload Length - Payload Length: 128-524288 Increment 128",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Cipher - Cipher, Inverse Key Length - 128, 192, 256 Payload Length - Payload Length: 8-524288 Increment 8",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload - Yes",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "KAS-ECC CDH-Component SP800-56Ar3 (CVL)",
            "cavpCertName": "A4481",
            "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A4481",
            "properties": "Domain Parameter Generation Methods - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A4481",
            "properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, modp-2048, modp-3072, modp-4096, modp-6144, modp-8192 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-IFC-SSC",
            "cavpCertName": "A4481",
            "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder Fixed Public Exponent - 010001",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF SP800- 56Cr2",
            "cavpCertName": "A4481",
            "properties": "Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation Derived Key Length - 2048",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA OneStep SP800-56Cr2",
            "cavpCertName": "A4481",
            "properties": "HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512 Perform Multiple Expansion Tests - No Uses Hybrid Shared Secret - No Auxiliary Function Methods - Auxiliary Function Name - SHA2-512 MAC Salting Methods - default, random",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA TwoStep SP800-56Cr2",
            "cavpCertName": "A4481",
            "properties": "Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 MAC Salting Methods - default, random Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation KDF Mode - feedback MAC Modes - HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, HMAC-SHA2- 512/224, HMAC-SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512 Fixed Data Order - after fixed data Counter Lengths - 8 The KDF supports an empty IV - Yes The KDF requires an empty IV - Yes Supported Lengths - Supported Lengths: 2048 Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 Perform Multiple Expansion Tests - No",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A4481",
            "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512 Other Info Length - Other Info Length: 0-4096 Increment 8 zz Length - zz Length: 8-4096 Increment 8 Key Data Length - Key Data Length: 8-4096 Increment 8 Supplemental Information Length - Supplemental Information Length: 0-120 Increment 8 OID - AES-128-KW, AES-192-KW, AES-256-KW",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A4481",
            "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Field Size - 224, 571 Shared Info Length - Shared Info Length: 0, 1024 Key Data Length - Key Data Length: 128, 4096",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SP800-108",
            "cavpCertName": "A4481",
            "properties": "KDF Mode - Counter, Feedback MAC Mode - CMAC-AES128, CMAC-AES192, CMAC-AES256, HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC- SHA2-384, HMAC-SHA2-512 Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096 Fixed Data Order - Before Fixed Data Counter Length - 32 Supports Empty IV - No, Yes Custom Key In Length - 0 Requires Empty IV - Yes",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A4481",
            "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A4481",
            "properties": "Iteration Count - Iteration Count: 1-10000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Password Length - Password Length: 8-128 Increment 8 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 112-4096 Increment 8",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A4481",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 Key Block Length - Key Block Length: 1024",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A4481",
            "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "DSA KeyGen (FIPS186- 4)",
            "cavpCertName": "A4481",
            "properties": "L - 2048, 3072 N - 224, 256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA PQGGen (FIPS186- 4)",
            "cavpCertName": "A4481",
            "properties": "P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA PQGVer (FIPS186- 4)",
            "cavpCertName": "A4481",
            "properties": "P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A4481",
            "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A4481",
            "properties": "Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P- 521",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "EDDSA KeyGen",
            "cavpCertName": "A4481",
            "properties": "Curve - ED-25519, ED-448",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "EDDSA KeyVer",
            "cavpCertName": "A4481",
            "properties": "Curve - ED-25519, ED-448",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A4481",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, modp-2048, modp-3072, modp-4096, modp-6144, modp-8192",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A4481",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, modp-2048, modp-3072, modp-4096, modp-6144, modp-8192",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186- 4)",
            "cavpCertName": "A4481",
            "properties": "Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - Yes Public Exponent Mode - Random Private Key Format - Standard",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "KTS-IFC",
            "cavpCertName": "A4481",
            "properties": "Function - keyPairGen, partialVal IUT ID - CAFEFACE Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime- factor Fixed Public Exponent - 010001 Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Hash Algorithms - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Supports Null Associated Data - Yes Associated Data Encoding - concatenation Key Length - 1024",
            "reference": "SP 800-56B Rev. 2"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A4481",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "MAC Length - MAC Length: 128 Message Length - Message Length: 0-524288 Increment 8",
            "reference": ""
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96 AAD Length - AAD Length: 0-65536 Increment 8",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-160 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512/224",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512/256",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-224",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-256",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-384",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-512",
            "cavpCertName": "A4481",
            "properties": "MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 112-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KMAC-128",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8 Hex Customization - No Supports eXtendable-Output Functions - No, Yes",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "KMAC-256",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "Key Data Length - Key Data Length: 128-1024 Increment 8 Hex Customization - No Supports eXtendable-Output Functions - No, Yes",
            "reference": ""
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/224",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-128",
            "cavpCertName": "A4481",
            "properties": "Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-256",
            "cavpCertName": "A4481",
            "properties": "Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A4481",
            "properties": "Prediction Resistance - Yes Supports Reseed - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes Additional Input - Additional Input: 0-256 Increment 256, Additional Input: 256, Additional Input: 320, Additional Input: 384 Entropy Input - Entropy Input: 128-256 Increment 128, Entropy Input: 256, Entropy Input: 256-512 Increment 128, Entropy Input: 320, Entropy Input: 384 Nonce - Nonce: 0, Nonce: 128 Personalization String Length - Personalization String Length: 0-256 Increment 256, Personalization String Length: 256, Personalization String Length: 320, Personalization String Length: 384 Returned Bits - 256",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "A4481",
            "properties": "Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Entropy Input - Entropy Input: 128-256 Increment 64, Entropy Input: 192-256 Increment 64, Entropy Input: 256-320 Increment 64 Nonce - Nonce: 128-160 Increment 32, Nonce: 96-128 Increment 32 Personalization String Length - Personalization String Length: 0-256 Increment 128 Additional Input - Additional Input: 0-256 Increment 128",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A4481",
            "properties": "Returned Bits - 160, 224, 256, 384, 512 Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Entropy Input - Entropy Input: 160-256 Increment 32, Entropy Input: 192-256 Increment 64, Entropy Input: 256-512 Increment 64, Entropy Input: 384-512 Increment 64, Entropy Input: 512-1024 Increment 64 Nonce - Nonce: 128, Nonce: 64, Nonce: 96 Personalization String Length - Personalization String Length: 0-192 Increment 64, Personalization String Length: 0-256 Increment 128 Additional Input - Additional Input: 0-256 Increment 128, Additional Input: 192 Returned Bits - 160, 224, 256, 384, 512",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A4481",
            "properties": "Component - No, Yes Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A4481",
            "properties": "Component - No Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P- 384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA SigGen (FIPS186-4)",
            "cavpCertName": "A4481",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA SigVer (FIPS186-4)",
            "cavpCertName": "A4481",
            "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "EDDSA SigGen",
            "cavpCertName": "A4481",
            "properties": "Curve - ED-25519, ED-448 PreHash - Yes",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "EDDSA SigVer",
            "cavpCertName": "A4481",
            "properties": "Curve - ED-25519, ED-448 PreHash - No Pure - Yes",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A4481",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-5)",
            "cavpCertName": "A4481",
            "properties": "Hash Pair - Hash Algorithm - SHA2-224 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss Mask Function - MGF1",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA Signature Primitive (CVL)",
            "cavpCertName": "A4481",
            "properties": "Private Key Format - crt Public Exponent Mode - fixed Fixed Public Exponent - 010001",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A4481",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA-1 Public Exponent Mode - Random",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-5)",
            "cavpCertName": "A4481",
            "properties": "Hash Pair - Hash Algorithm - SHA-1 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss Mask Function - MGF1 Public Exponent Mode - random",
            "reference": "FIPS 186-5"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Encrypt or decrypt data, including AEAD modes (CCM, GCM).",
            "indicator": "FIPS_OK",
            "inputs": "Encryption or decryption key; plaintext or ciphertext data; flags.",
            "name": "Cipher",
            "outputs": "Status return. Plaintext or ciphertext data.",
            "rolesSspAccess": "CO - SC_EDK_AES: W,E - SC_EDK_XTS: W,E",
            "secFunImpl": "Cipher (Unauth) Cipher (Auth)"
          },
          {
            "description": "Reports information on the requested capabilities.",
            "indicator": "FIPS_OK",
            "inputs": "Provider context, capability, callback pointer and arguments.",
            "name": "Get capabilities",
            "outputs": "Description of capabilities.",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Module initialization, including instantiation of the opaque (managed within the module) Counter DRBG instance.",
            "indicator": "FIPS_OK",
            "inputs": "Core handle, dispatch in and out, provider context.",
            "name": "Initialize",
            "outputs": "Initialization status (1 = pass, 0 = fail).",
            "rolesSspAccess": "CO - DRBG_EI: W,E,Z - DRBG_Seed: G,E,Z - DRBG_Key: G,W,E - DRBG_V: G,W,E",
            "secFunImpl": "Random MAC HMAC"
          },
          {
            "description": "Perform key agreement primitives on behalf of the calling process (does not establish keys into the module).",
            "indicator": "FIPS_OK",
            "inputs": "Key structs (key agreement keys); flags.",
            "name": "Key agreement",
            "outputs": "Status return; key agreement shared secret.",
            "rolesSspAccess": "CO - KAS_Private_ECC: W,E - KAS_Public_ECC: W,E - KAS_Private_FFC: W,E - KAS_Public_FFC: W,E - KAS_Private_IFC: W,E - KAS_Public_IFC: W,E - KAS_SS_ECC: G,R - KAS_SS_FFC: G,R - KAS_SS_IFC: G,R",
            "secFunImpl": "CKG Section 5 Key agreement"
          },
          {
            "description": "Derive keying material from a shared secret.",
            "indicator": "FIPS_OK",
            "inputs": "Key agreement shared secret; flags.",
            "name": "Key derivation",
            "outputs": "Status return; derived keying material.",
            "rolesSspAccess": "CO - KD_DKM_KDF: G,R - KD_PW_PBKDF: W,E - KD_DKM_PBKDF: G,R - KD_SK: W,E",
            "secFunImpl": "Key derivation CKG Section 6.2"
          },
          {
            "description": "Generate asymmetric key pairs.",
            "indicator": "FIPS_OK",
            "inputs": "ECDSA, EdDSA: curve identifier. DSA, RSA: domain parameter targets.",
            "name": "Key management",
            "outputs": "Status return; general digital signature private and public keys.",
            "rolesSspAccess": "CO - DRBG_C: G,W,E - DRBG_Key: W,G,E - DRBG_V: W,G,E - GKP_Private_ECC: G,R - GKP_Public_ECC: G,R",
            "secFunImpl": "Key management ECC Key management Edwards Key management FFC"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- GKP_Private_Edwards: G,R - GKP_Public_Edwards: G,R - GKP_Private_FFC: G,R - GKP_Public_FFC: G,R - GKP_Private_IFC: G,R - GKP_Public_IFC: G,R",
            "secFunImpl": "Key management IFC CKG Section 4"
          },
          {
            "description": "Encapsulate or decapsulate key material on behalf of the calling process.",
            "indicator": "FIPS_OK",
            "inputs": "Key encapsulation/decapsulation key or Key wrap/unwrap key.",
            "name": "Key transport",
            "outputs": "Status return; key transport shared secret.",
            "rolesSspAccess": "CO - KTS_KDK_IFC: W,E - KTS_KEK_IFC: W,E - KTS_SS_IFC: G,R",
            "secFunImpl": "CKG Section 5 Key transport KTS (Cipher w/ CMAC, GMAC, HMAC, KMAC) KTS (AES KW, KWP)"
          },
          {
            "description": "Generate or verify data integrity.",
            "indicator": "FIPS_OK",
            "inputs": "Keyed hash key.",
            "name": "Message authentication",
            "outputs": "Status return; MAC output value.",
            "rolesSspAccess": "CO - KH_Key_AES-CMAC: W,E - KH_Key_AES-GMAC: W,E - KH_Key_HMAC: W,E - KH_Key_KMAC: W,E",
            "secFunImpl": "MAC AES (CMAC, GMAC) MAC HMAC MAC KMAC (XOF)"
          },
          {
            "description": "Generate a message digest.",
            "indicator": "FIPS_OK",
            "inputs": "Message; flags.",
            "name": "Message digest",
            "outputs": "Status return; Hash output value.",
            "rolesSspAccess": "",
            "secFunImpl": "Message Digest Message Digest (XOF SHAKE)"
          },
          {
            "description": "Report available crypto operations.",
            "indicator": "FIPS_OK",
            "inputs": "Provider context, operation ID.",
            "name": "Query",
            "outputs": "Array of available operations.",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Generate random bits using the DRBG.",
            "indicator": "FIPS_OK",
            "inputs": "DRBG struct (RBG State); DRBG_Seed.",
            "name": "Random",
            "outputs": "Status return; Random value.",
            "rolesSspAccess": "CO - DRBG_C: W,E - DRBG_EI: W,E,Z - DRBG_Seed: G,E,Z - DRBG_Key: W,E - DRBG_V: W,E",
            "secFunImpl": "Random CKG Section 4"
          },
          {
            "description": "Perform the self-test sequence.",
            "indicator": "FIPS_OK",
            "inputs": "Provider context.",
            "name": "Self-test",
            "outputs": "Status (1 = pass, 0 = fail).",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Return module name and versioning information.",
            "indicator": "FIPS_OK",
            "inputs": "Provider context, parameter types (array).",
            "name": "Show module name and versioning information",
            "outputs": "Parameter types (array) with: Name, Version.",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "OpenSSL core metadata (Gettable parameters; Get parameters).",
            "indicator": "FIPS_OK",
            "inputs": "Provider context, parameter types (array).",
            "name": "Show status",
            "outputs": "Parameter types with: BuildInfo, Status, SecurityChecks; Status return.",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Generate or verify digital signatures. (SSPs are passed in by the calling process.)",
            "indicator": "FIPS_OK",
            "inputs": "Sign: signing key; message. Verify: signature value; flags; sizes.",
            "name": "Signature",
            "outputs": "Status return; Signature value.",
            "rolesSspAccess": "CO - DS_SGK_ECC: W,E - DS_SVK_ECC: W,E - DS_SGK_Edwards: W,E - DS_SVK_Edwards: W,E - DS_SGK_FFC: W,E - DS_SVK_FFC: W,E - DS_SGK_IFC: W,E - DS_SVK_IFC: W,E",
            "secFunImpl": "CKG Section 5 Signature DSA Signature ECDSA Signature EDDSA Signature RSA"
          },
          {
            "description": "Uninstantiate the module; zeroizes internal CTR DRBG state (DRBG_Key, DRBG_V).",
            "indicator": "FIPS_OK",
            "inputs": "Provider context.",
            "name": "Teardown",
            "outputs": "None.",
            "rolesSspAccess": "CO - DRBG_Key: Z - DRBG_V: Z",
            "secFunImpl": ""
          },
          {
            "description": "Zeroization of allocated key structures using openssl_cleanse.",
            "indicator": "FIPS_OK",
            "inputs": "Memory pointer.",
            "name": "Zeroize",
            "outputs": "Void.",
            "rolesSspAccess": "CO - DRBG_C: Z - DRBG_EI: Z - DRBG_Key: Z - DRBG_Seed: Z - DRBG_V: Z - DS_SGK_ECC: Z - DS_SGK_Edwards: Z - DS_SGK_FFC: Z - DS_SGK_IFC: Z - DS_SVK_ECC: Z - DS_SVK_Edwards: Z - DS_SVK_FFC: Z - DS_SVK_IFC: Z - GKP_Private_ECC: Z -",
            "secFunImpl": ""
          },
          {
            "description": "Description",
            "indicator": "Indicator Inputs",
            "inputs": "Outputs",
            "name": "Name",
            "outputs": "Security Functions",
            "rolesSspAccess": "",
            "secFunImpl": "SSP Access"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": "GKP_Private_Edwards: Z - GKP_Private_FFC: Z - GKP_Private_IFC: Z - GKP_Public_ECC: Z - GKP_Public_Edwards: Z - GKP_Public_FFC: Z - GKP_Public_IFC: Z - KAS_Private_ECC: Z - KAS_Private_FFC: Z - GKP_Private_ECC: Z - KAS_Private_IFC: Z - KAS_Public_ECC: Z - KAS_Public_FFC: Z - KAS_Public_IFC: Z - KAS_SS_ECC: Z - KD_DKM_KDF: Z - KD_DKM_PBKDF: Z - KD_SK: Z - KH_Key_AES-CMAC: Z - KH_Key_AES-GMAC: Z - KH_Key_HMAC: Z - KH_Key_KMAC: Z - KTS_KDK_IFC: Z - KTS_KEK_IFC: Z - KTS_SS_IFC: Z - KAS_SS_ECC: Z - SC_EDK_AES: Z - SC_EDK_XTS: Z"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [],
        "found": false,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "If one of the KATs fails or integrity test fails",
            "description": "The self-test failure error state",
            "indicator": "PROV_R_FIPS_MODULE_IN_ERROR_STATE",
            "name": "Self-test failure",
            "recoveryMethod": "Reload the Module into memory"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Approved mode of operation",
            "name": "Nominal",
            "statusIndicator": "",
            "type": "Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "API input: stack frame including non-sensitive parameters.",
            "logicalInterface": "Control Input Data Input",
            "physicalPort": "N/A (API - input)"
          },
          {
            "data": "API output: output parameters and return value resulting from call execution.",
            "logicalInterface": "Data Output Status Output",
            "physicalPort": "N/A (API - output)"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "",
            "name": "CO",
            "operatorType": "CO",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "3",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "1",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [],
        "found": false,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Call stack (API) input parameters",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "I",
            "sfiAlgo": "",
            "source": "Calling process"
          },
          {
            "dest": "Calling process",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "O",
            "sfiAlgo": "",
            "source": "Call stack (API) output parameters"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "C (Cleanse): Caller invocation of openssl_cleanse.",
            "method": "C",
            "operatorId": "Caller invocation of openssl_cleanse",
            "rationale": "Overwrites with zeros"
          },
          {
            "description": "T (Teardown): Module unload - invokes cleanse internally.",
            "method": "T",
            "operatorId": "Occurs when module is unloaded",
            "rationale": "Overwrites with zeros"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "R: Random access memory",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "N/A",
            "integrityTest": "HMAC-SHA2-256 #A4481 over the complete module file image",
            "packageFileName": "fips.so",
            "swFwVersion": "3.0.10 with KP_1.2"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "LP4502",
            "hypervisorHostOs": "",
            "operatingSystem": "HID Intelligent Controller OS 2.0",
            "paa_pai": "No",
            "processors": "Atmel SAMA5 (ARMv7)",
            "version": "3.0.10 with KP_1.2"
          },
          {
            "hardwarePlatform": "MP4502",
            "hypervisorHostOs": "",
            "operatingSystem": "HID Intelligent Controller OS 2.0",
            "paa_pai": "No",
            "processors": "STMicroelectronics STM32MP133CAF3 (ARMv7)",
            "version": "3.0.10 with KP_1.2"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "CKG Section 4",
            "reference": "NIST, SP 800-133 Rev. 2"
          },
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "CKG Section 5",
            "reference": "NIST, SP 800-133 Rev. 2"
          },
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "CKG Section 6.2",
            "reference": "NIST, SP 800-133 Rev. 2"
          },
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "Hash DRBG with SHA3-256, SHA3-512",
            "reference": "NIST, SP 800-90A Rev. 1"
          },
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "HMAC DRBG with SHA3-256, SHA3-512",
            "reference": "NIST, SP 800-90A Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "MP1502 with STMicroelectronics STM32MP133CAF3 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          },
          {
            "hardwarePlatform": "MP2500 with STMicroelectronics STM32MP133CAF3 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          },
          {
            "hardwarePlatform": "MP1501 with STMicroelectronics STM32MP133CAF3 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          },
          {
            "hardwarePlatform": "X1100C with STMicroelectronics STM32MP133CAF3 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          },
          {
            "hardwarePlatform": "LP1502 with Atmel SAMA5 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          },
          {
            "hardwarePlatform": "LP2500 with Atmel SAMA5 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          },
          {
            "hardwarePlatform": "LP1501 with Atmel SAMA5 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          },
          {
            "hardwarePlatform": "X1100 with Atmel SAMA5 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          },
          {
            "hardwarePlatform": "PW7K1IC with Atmel SAMA5 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          },
          {
            "hardwarePlatform": "PRO4200IC with Atmel SAMA5 (ARMv7)",
            "operatingSystem": "HID Intelligent Controller OS 2.x"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 8
          },
          "ECDSA": {
            "ECDSA": 23
          },
          "EdDSA": {
            "EdDSA": 4
          }
        },
        "FF": {
          "DH": {
            "DHE": 1
          },
          "DSA": {
            "DSA": 23
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CCM": {
          "CCM": 1
        },
        "CTR": {
          "CTR": 3
        },
        "GCM": {
          "GCM": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 56
        }
      },
      "crypto_protocol": {
        "SSH": {
          "SSH": 3,
          "SSHv2": 2
        },
        "TLS": {
          "TLS": {
            "TLS": 3,
            "TLS 1.2": 1,
            "TLS 1.3": 1,
            "TLS v1.2": 4,
            "TLS v1.3": 5
          }
        }
      },
      "crypto_scheme": {
        "AEAD": {
          "AEAD": 1
        },
        "KA": {
          "Key Agreement": 1,
          "Key agreement": 17
        },
        "MAC": {
          "MAC": 36
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "B-163": 4,
          "B-233": 14,
          "B-283": 14,
          "B-409": 14,
          "B-571": 14,
          "K-163": 4,
          "K-233": 14,
          "K-283": 14,
          "K-409": 14,
          "K-571": 14,
          "P-192": 8,
          "P-224": 32,
          "P-256": 30,
          "P-384": 26,
          "P-521": 26
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES-128": 7,
          "AES-192": 6,
          "AES-256": 6,
          "HMAC-SHA-1": 6,
          "PKCS 1": 4,
          "SHA-1": 16,
          "SHA-3": 3,
          "SHA2": 1,
          "SHA2- 256": 2,
          "SHA2-224": 18,
          "SHA2-256": 25,
          "SHA2-384": 21,
          "SHA2-512": 24,
          "SHA3": 1,
          "SHA3- 256": 2,
          "SHA3-224": 5,
          "SHA3-256": 8,
          "SHA3-384": 5,
          "SHA3-512": 8
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 9
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 16
          },
          "SHA2": {
            "SHA2": 1
          },
          "SHA3": {
            "SHA-3": 3,
            "SHA3": 1,
            "SHA3-224": 5,
            "SHA3-256": 8,
            "SHA3-384": 5,
            "SHA3-512": 8
          }
        },
        "SHAKE": {
          "SHAKE128": 1,
          "SHAKE256": 1
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {
        "curves": {
          "ED25519": 4,
          "ED448": 4
        }
      },
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 34
        },
        "RNG": {
          "RBG": 3
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "timing attacks": 2
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 66,
          "FIPS 180-4": 7,
          "FIPS 186-4": 13,
          "FIPS 186-5": 6,
          "FIPS 198-1": 11,
          "FIPS 202": 6,
          "FIPS186-4": 38,
          "FIPS186-5": 4
        },
        "ISO": {
          "ISO/IEC 19790:2012": 3
        },
        "NIST": {
          "SP 800-107": 1,
          "SP 800-108": 2,
          "SP 800-132": 7,
          "SP 800-133": 7,
          "SP 800-135": 9,
          "SP 800-140D": 1,
          "SP 800-185": 3,
          "SP 800-186": 3,
          "SP 800-38A": 10,
          "SP 800-38B": 1,
          "SP 800-38C": 1,
          "SP 800-38D": 4,
          "SP 800-38E": 2,
          "SP 800-38F": 3,
          "SP 800-52": 1,
          "SP 800-56A": 12,
          "SP 800-56B": 8,
          "SP 800-56C": 7,
          "SP 800-57": 5,
          "SP 800-90A": 5,
          "SP 800-90B": 2
        },
        "PKCS": {
          "PKCS 1": 2
        },
        "RFC": {
          "RFC 5288": 1,
          "RFC 5647": 1,
          "RFC 8446": 1,
          "RFC7627": 3,
          "RFC8446": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 10,
            "AES-128": 7,
            "AES-192": 6,
            "AES-256": 6
          },
          "CAST": {
            "CAST": 73
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 6,
            "HMAC": 20,
            "KMAC": 7
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 12
        },
        "IBM": {
          "SSC": 1
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "STMicroelectronics": {
          "STMicroelectronics": 5
        }
      },
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-512/224A4481",
        "AES-CFB1A4481",
        "ECDSA SigVer (FIPS186-4)A4481",
        "RSA SigVer (FIPS186-4)A4481",
        "SHA3-256A4481",
        "Hash DRBGA4481",
        "AES-CBCA4481",
        "SHA2-256A4481",
        "HMAC-SHA2-512A4481",
        "SHA3-512A4481",
        "DSA KeyGen (FIPS186-4)A4481",
        "PBKDFA4481",
        "ECDSA KeyGen (FIPS186-4)A4481",
        "KDF SP800-108A4481",
        "RSA SigGen (FIPS186-5)A4481",
        "HMAC-SHA3-256A4481",
        "KTS-IFCA4481",
        "SHA2-512/256A4481",
        "AES-CBC-CS2A4481",
        "EDDSA SigGenA4481",
        "TLS v1.3 KDFA4481",
        "Safe Primes Key GenerationA4481",
        "KDF ANS 9.63A4481",
        "AES-CBC-CS3A4481",
        "DSA PQGGen (FIPS186-4)A4481",
        "KAS-ECC CDH-Component SP800-56Ar3A4481",
        "KDF SSHA4481",
        "ECDSA KeyVer (FIPS186-4)A4481",
        "SHA2-224A4481",
        "AES-CFB8A4481",
        "AES-CFB128A4481",
        "KDA HKDF SP800-56Cr2A4481",
        "AES-CMACA4481",
        "KAS-IFC-SSCA4481",
        "DSA SigVer (FIPS186-4)A4481",
        "AES-GMACA4481",
        "HMAC-SHA2-256A4481",
        "SHA3-384A4481",
        "AES-CTRA4481",
        "AES-XTS Testing Revision 2.0A4481",
        "RSA SigGen (FIPS186-4)A4481",
        "HMAC-SHA2-512/224A4481",
        "SHA3-224A4481",
        "Counter DRBGA4481",
        "HMAC-SHA2-512/256A4481",
        "AES-ECBA4481",
        "HMAC-SHA3-224A4481",
        "SHAKE-128A4481",
        "DSA SigGen (FIPS186-4)A4481",
        "SHAKE-256A4481",
        "AES-GCMA4481",
        "KMAC-128A4481",
        "ECDSA SigGen (FIPS186-4)A4481",
        "AES-CCMA4481",
        "HMAC-SHA2-384A4481",
        "HMAC-SHA3-384A4481",
        "AES-OFBA4481",
        "AES-KWA4481",
        "EDDSA KeyVerA4481",
        "HMAC-SHA-1A4481",
        "KDA OneStep SP800-56Cr2A4481",
        "AES-KWPA4481",
        "DSA PQGVer (FIPS186-4)A4481",
        "AES-CBC-CS1A4481",
        "EDDSA KeyGenA4481",
        "RSA KeyGen (FIPS186-4)A4481",
        "KAS-ECC-SSC Sp800-56Ar3A4481",
        "SHA2-512A4481",
        "RSA Signature PrimitiveA4481",
        "SHA2-384A4481",
        "KAS-FFC-SSC Sp800-56Ar3A4481",
        "KDF ANS 9.42A4481",
        "KDA TwoStep SP800-56Cr2A4481",
        "TLS v1.2 KDF RFC7627A4481",
        "SHA-1A4481",
        "RSA SigVer (FIPS186-5)A4481",
        "Safe Primes Key VerificationA4481",
        "HMAC-SHA3-512A4481",
        "EDDSA SigVerA4481",
        "KMAC-256A4481",
        "HMAC-SHA2-224A4481",
        "HMAC DRBGA4481"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A4481"
      ]
    },
    "policy_metadata": {
      "/Author": "Hawes, David J. (Fed)",
      "/Comments": "",
      "/Company": "",
      "/ComplianceAssetId": "",
      "/ContentTypeId": "0x010100DCA90304BC368747933546DC38C49DF0",
      "/CreationDate": "D:20250820085946-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/MediaServiceImageTags": "",
      "/ModDate": "D:20250820090109-04\u002700\u0027",
      "/Order": "1084700.000000",
      "/Producer": "Adobe PDF Library 25.1.51",
      "/SourceModified": "",
      "/Subject": "",
      "/TemplateUrl": "",
      "/Title": "",
      "/TriggerFlowInfo": "",
      "/_ExtendedDescription": "",
      "/xd_ProgID": "",
      "/xd_Signature": "0",
      "pdf_file_size_bytes": 790536,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://keypair.us/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 45
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "319021f24e9777e39c2334d70689e474696c2cc4ba12d1ec3b1d7fe29a56f794",
      "source_hash": "20c49e1df616925b2418eb1d0a29a9f3d6678b3a11fe1ffb4bf8ac212241e4cb",
      "txt_hash": "feae4162c5a146ff59dc91e0a91bb6b13b2c32389d1dc3ac9d9fb7c659c6597c"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "No assurance of the minimum strength of generated SSPs (e.g., keys).",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/December 2024_060125_0402.pdf",
    "date_sunset": "2029-07-10",
    "description": "The HID/Mercury FIPS Provider for OpenSSL 3 is a secure cryptographic module that enhances the cryptographic capabilities of HID and Mercury intelligent controllers, complying with the FIPS 140-3 standard. It integrates seamlessly with OpenSSL 3 to offer advanced encryption, decryption, hashing, and key management functions, ensuring high performance and robust security. Designed to meet stringent industry requirements, this provider ensures that all cryptographic operations are executed securely and efficiently, making it ideal for applications demanding the highest level of security assurance.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Life-cycle assurance: Level 3"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "HID/Mercury FIPS Provider for OpenSSL 3",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-12-18",
        "lab": "DEKRA Cybersecurity Certification Laboratory",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-08-20",
        "lab": "Acumen Security",
        "validation_type": "Update"
      }
    ],
    "vendor": "[email\u00a0protected]",
    "vendor_url": "/cdn-cgi/l/email-protection"
  }
}