Endpoint Security Module

Certificate #3445

Webpage information

Status historical
Historical reason SP 800-56Arev3 transition
Validation dates 29.04.2019 , 04.06.2019
Standard FIPS 140-2
Security level 3
Type Hardware
Embodiment Single Chip
Caveat None
Exceptions
  • Mitigation of Other Attacks: N/A
Description Silver Spring Networks Endpoint Security Module provides acceleration and off-load of standard cryptographic algorithms and secure network protocols, key storage and generation, bootloader and firmware verification, and encrypted data storage. It is included in the SoC designed for SSN's Gen5 endpoint and infrastructure products.
Version (Hardware) 130-0117-01.ESM
Version (Firmware) ROM version 82136 with Applet version 1.0.0
Vendor Silver Spring Networks, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-256, HMAC, HMAC-SHA-256, HMAC-SHA-512, HMAC-SHA-384
Asymmetric Algorithms
RSA 2048, ECDH, ECDSA, ECC, DH, DSA
Hash functions
SHA1, SHA-1, SHA-512, SHA-256, SHA224, SHA256, SHA384, SHA512, SHA-224, SHA-384
Schemes
Key Agreement
Protocols
TLSv1.2, TLS, IKEv1, IKEv2
Randomness
TRNG, DRBG
Elliptic Curves
P-256, P-384
Block cipher modes
ECB, CBC, OFB

Security level
level 3, Level 3

Standards
FIPS 140-2, FIPS 197, FIPS 186-4, FIPS 198-1, FIPS186-4, FIPS 180-4, FIPS140-2, FIPS197, FIPS198-1, SP 800-38A, SP 800-38F, SP 800-56A, SP 800-90A, SP 800-135, SP 800-108, SP 800-133, PKCS#1

File metadata

Title Microsoft Word - TID-15-0886 arnie-.docx
Author dspann
Creation date D:20190422153541
Modification date D:20190422153541
Pages 43
Creator PScript5.dll Version 5.2.2
Producer GPL Ghostscript 8.15

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3445,
  "dgst": "8a835b9bf9c1f897",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC#3402",
        "CVL#1709",
        "CVL#1711",
        "DRBG#1906",
        "CVL#1710",
        "AES#5101",
        "KBKDF#178",
        "AES#5238",
        "DSA#1359",
        "ECDSA#1362",
        "SHS#4148",
        "KTS#5238",
        "KAS#164",
        "RSA#2800"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "1.0.0"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 7
          },
          "ECDH": {
            "ECDH": 1
          },
          "ECDSA": {
            "ECDSA": 23
          }
        },
        "FF": {
          "DH": {
            "DH": 8
          },
          "DSA": {
            "DSA": 1
          }
        },
        "RSA": {
          "RSA 2048": 2
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 3
        },
        "ECB": {
          "ECB": 1
        },
        "OFB": {
          "OFB": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKEv1": 5,
          "IKEv2": 5
        },
        "TLS": {
          "TLS": {
            "TLS": 6,
            "TLSv1.2": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 26,
          "P-384": 12
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1906": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 256": 1,
          "AES-256": 1,
          "DRBG (Cert. #1906": 1,
          "DRBG4": 1,
          "HMAC- SHA-256": 1,
          "HMAC- SHA-512 112": 1,
          "HMAC- SHA256": 2,
          "HMAC-SHA- 224": 2,
          "HMAC-SHA- 384": 2,
          "HMAC-SHA-1": 8,
          "HMAC-SHA-256": 26,
          "HMAC-SHA-384": 2,
          "HMAC-SHA-512": 22,
          "PKCS#1": 2,
          "RSA 2048": 2,
          "SHA 256": 1,
          "SHA- 256": 2,
          "SHA-1": 2,
          "SHA-224": 1,
          "SHA-256": 7,
          "SHA-384": 1,
          "SHA-512": 2,
          "SHA-512 112": 1,
          "SHA1;128": 1,
          "SHA224": 1,
          "SHA256": 5,
          "SHA384": 1,
          "SHA512": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 3": 1,
          "level 3": 2
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 2,
            "SHA1": 1
          },
          "SHA2": {
            "SHA-224": 1,
            "SHA-256": 7,
            "SHA-384": 1,
            "SHA-512": 3,
            "SHA224": 1,
            "SHA256": 5,
            "SHA384": 1,
            "SHA512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 37
        },
        "TRNG": {
          "TRNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 16,
          "FIPS 180-4": 1,
          "FIPS 186-4": 4,
          "FIPS 197": 2,
          "FIPS 198-1": 2,
          "FIPS140-2": 2,
          "FIPS186-4": 2,
          "FIPS197": 1,
          "FIPS198-1": 1
        },
        "NIST": {
          "SP 800-108": 8,
          "SP 800-133": 7,
          "SP 800-135": 17,
          "SP 800-38A": 1,
          "SP 800-38F": 19,
          "SP 800-56A": 11,
          "SP 800-90A": 11
        },
        "PKCS": {
          "PKCS#1": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 41,
            "AES-256": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 26,
            "HMAC-SHA-256": 13,
            "HMAC-SHA-384": 1,
            "HMAC-SHA-512": 11
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "dspann",
      "/CreationDate": "D:20190422153541",
      "/Creator": "PScript5.dll Version 5.2.2",
      "/ModDate": "D:20190422153541",
      "/Producer": "GPL Ghostscript 8.15",
      "/Title": "Microsoft Word - TID-15-0886 arnie-.docx",
      "pdf_file_size_bytes": 997165,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 43
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "2e73f139220474804848764f1acbc7f20745418fa6b0c36c679821139102203f",
      "txt_hash": "b4f6f2c1c80f4215d23f25cc7bbac6f18580ba4309a0e363e288020698786ac3"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "None",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/AprilConsolidated.pdf",
    "date_sunset": null,
    "description": "Silver Spring Networks Endpoint Security Module provides acceleration and off-load of standard cryptographic algorithms and secure network protocols, key storage and generation, bootloader and firmware verification, and encrypted data storage. It is included in the SoC designed for SSN\u0027s Gen5 endpoint and infrastructure products.",
    "embodiment": "Single Chip",
    "exceptions": [
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "ROM version 82136 with Applet version 1.0.0",
    "historical_reason": "SP 800-56Arev3 transition",
    "hw_versions": "130-0117-01.ESM",
    "level": 3,
    "mentioned_certs": {},
    "module_name": "Endpoint Security Module",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-04-29",
        "lab": "AEGISOLVE, Inc.",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-06-04",
        "lab": "AEGISOLVE, Inc.",
        "validation_type": "Update"
      }
    ],
    "vendor": "Silver Spring Networks, Inc.",
    "vendor_url": "http://www.ssni.com"
  }
}