Mocana Cryptographic Suite B Module

Certificate #4761

Webpage information

Status active
Validation dates 14.08.2024
Sunset date 13-08-2029
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat Interim validation. No assurance of the minimum strength of generated SSPs (e.g., keys). When operated in approved mode
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Mocana Cryptographic Module is the engine of Mocana's Device Security Framework - a software framework that secures all aspects of a system. The Device Security Framework helps applications and device designers reduce development costs and dramatically enhance cryptographic performance. For details see www.mocana.com.
Tested configurations
  • Buildroot Linux 2020.02.01 (32-bit) running on Honeywell Cordless Ultra with an Ingenic X2000 (without PAA)
  • Buildroot Linux 2020.02.01 (32-bit) running on Ultra Charge & Communication Base with an Ingenic X1600E (without PAA)
  • Yocto Linux 3.1 (32-bit) running on Xerox Alexandra Platform with an ARM Cortex A53 (without PAA))
  • Yocto Linux 3.1 (32-bit) running on Xerox Explorer 6.5 with an Intel Atom E3950 (with PAA)
  • Yocto Linux 3.1 (32-bit) running on Xerox Explorer 6.5 with an Intel Atom E3950 (without PAA)
  • Yocto Linux 3.1 (32-bit) running on Xerox Explorer 8.0 with an Intel Atom x6413E (with PAA)
  • Yocto Linux 3.1 (32-bit) running on Xerox Explorer 8.0 with an Intel Atom x6413E (without PAA)
Vendor DigiCert, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, AES-192, AES-256, CAST, E2, DES, Triple-DES, TDEA, TDES, HMAC, HMAC-SHA-256, HMAC-SHA-224, CMAC, CBC-MAC
Asymmetric Algorithms
ECDH, ECDSA, EdDSA, ECC, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA-512, SHA-256, SHA-224, SHA-384, SHA2, SHA-2, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHA-3, SHA3, SHAKE256, SHAKE128, MD4, MD5
Schemes
MAC, Key Exchange, Key Agreement, Key agreement
Protocols
TLS 1.2, TLS
Randomness
DRBG, RNG
Elliptic Curves
P-224, P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTS

Security level
Level 1

Standards
FIPS 140-3, FIPS 186-2, FIPS 186-4, FIPS 186-5, FIPS140-3, FIPS PUB 140-3, FIPS PUB 202, NIST SP 800-90A, SP 800-108, PKCS #1, RFC8032, RFC 5246, ISO/IEC 24759, ISO/IEC 19790, ISO/IEC 19790:2012

File metadata

Subject FIPS 140-3 Security Policy Template
Author S. Black
Creation date D:20240813082012-07'00'
Modification date D:20240813082050-07'00'
Pages 36
Creator Acrobat PDFMaker 24 for Word
Producer Adobe PDF Library 24.2.255

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4761,
  "dgst": "9625b0d86d2d7e98",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA3-256A4653",
        "EDDSA SigGenA4653",
        "RSA KeyGen (FIPS186-4)A4653",
        "HMAC-SHA-1A4653",
        "AES-CMACA4653",
        "SHAKE-128A4653",
        "HMAC-SHA2-224A4653",
        "DSA PQGGen (FIPS186-4)A4653",
        "SHA3-384A4653",
        "AES-CTRA4653",
        "AES-CCMA4653",
        "DSA SigGen (FIPS186-4)A4653",
        "KDF SP800-108A4653",
        "SHAKE-256A4653",
        "ECDSA SigVer (FIPS186-4)A4653",
        "AES-GMACA4655",
        "EDDSA SigVerA4653",
        "SHA3-512A4653",
        "KAS-FFC Sp800-56Ar3A4653",
        "EDDSA KeyGenA4653",
        "Counter DRBGA4653",
        "SHA3-256A4653",
        "AES-CFB128A4653",
        "DSA PQGVer (FIPS186-4)A4653",
        "HMAC-SHA2-512A4653",
        "SHA2-224A4653",
        "AES-CBCA4653",
        "SHA2-512A4653",
        "RSA SigVer (FIPS186-4)A4653",
        "HMAC-SHA2-384A4653",
        "HMAC-SHA3-224A4653",
        "ECDSA KeyVer (FIPS186-4)A4653",
        "AES-ECBA4653",
        "AES-GCMA4655",
        "EDDSA KeyVerA4653",
        "SHA2-384A4653",
        "KAS-ECC Sp800-56Ar3A4653",
        "RSA SigGen (FIPS186-4)A4653",
        "ECDSA KeyGen (FIPS186-4)A4653",
        "ECDSA SigGen (FIPS186-4)A4653",
        "HMAC-SHA3-512A4653",
        "HMAC-SHA3-384A4653",
        "DSA SigVer (FIPS186-4)A4653",
        "DSA KeyGen (FIPS186-4)A4653",
        "SHA-1A4653",
        "SHA2-256A4653",
        "SHA3-224A4653",
        "HMAC-SHA2-256A4653",
        "AES-XTS Testing Revision 2.0A4653",
        "AES-OFBA4653"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 21
          },
          "ECDH": {
            "ECDH": 1
          },
          "ECDSA": {
            "ECDSA": 28
          },
          "EdDSA": {
            "EdDSA": 28
          }
        },
        "FF": {
          "DH": {
            "DH": 13,
            "Diffie-Hellman": 4
          },
          "DSA": {
            "DSA": 29
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CCM": {
          "CCM": 4
        },
        "CFB": {
          "CFB": 2
        },
        "CTR": {
          "CTR": 7
        },
        "ECB": {
          "ECB": 2
        },
        "GCM": {
          "GCM": 11
        },
        "OFB": {
          "OFB": 3
        },
        "XTS": {
          "XTS": 4
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "TLS": {
            "TLS": 3,
            "TLS 1.2": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 8,
          "Key agreement": 2
        },
        "KEX": {
          "Key Exchange": 2
        },
        "MAC": {
          "MAC": 11
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 14,
          "P-256": 12,
          "P-384": 12,
          "P-521": 12
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1,
          "#3": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES [197": 9,
          "AES-128": 1,
          "AES-192": 1,
          "AES-256": 3,
          "DSA [186": 1,
          "HMAC SHA-1": 3,
          "HMAC [198": 9,
          "HMAC- SHA-1": 2,
          "HMAC-SHA- 256": 2,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-224, 256": 2,
          "HMAC-SHA-256": 12,
          "HMAC-SHA2": 2,
          "HMAC-SHA3": 2,
          "PAA 2": 1,
          "PKCS #1": 1,
          "RSA PKCS #1": 1,
          "SHA- 512": 1,
          "SHA-1": 24,
          "SHA-2": 2,
          "SHA-224": 4,
          "SHA-256": 3,
          "SHA-3": 3,
          "SHA-3 [202": 1,
          "SHA-384": 2,
          "SHA-512": 2,
          "SHA2 (224": 24,
          "SHA2 (256": 4,
          "SHA2(224": 1,
          "SHA2- 224": 1,
          "SHA2-(224": 11,
          "SHA2-224": 4,
          "SHA2-256": 3,
          "SHA2-384": 3,
          "SHA2-512": 3,
          "SHA3": 2,
          "SHA3-(224": 3,
          "SHA3-224": 9,
          "SHA3-256": 5,
          "SHA3-384": 6,
          "SHA3-512": 5,
          "SHS [180": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 6
        }
      },
      "hash_function": {
        "MD": {
          "MD4": {
            "MD4": 3
          },
          "MD5": {
            "MD5": 3
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 24
          },
          "SHA2": {
            "SHA-2": 2,
            "SHA-224": 4,
            "SHA-256": 3,
            "SHA-384": 2,
            "SHA-512": 2,
            "SHA2": 29
          },
          "SHA3": {
            "SHA-3": 4,
            "SHA3": 2,
            "SHA3-224": 9,
            "SHA3-256": 5,
            "SHA3-384": 6,
            "SHA3-512": 5
          }
        },
        "SHAKE": {
          "SHAKE128": 1,
          "SHAKE256": 1
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 26
        },
        "RNG": {
          "RNG": 3
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 8,
          "FIPS 186-2": 2,
          "FIPS 186-4": 3,
          "FIPS 186-5": 1,
          "FIPS PUB 140-3": 1,
          "FIPS PUB 202": 1,
          "FIPS140-3": 1
        },
        "ISO": {
          "ISO/IEC 19790": 2,
          "ISO/IEC 19790:2012": 2,
          "ISO/IEC 24759": 4
        },
        "NIST": {
          "NIST SP 800-90A": 1,
          "SP 800-108": 1
        },
        "PKCS": {
          "PKCS #1": 1
        },
        "RFC": {
          "RFC 5246": 1,
          "RFC8032": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 42,
            "AES-128": 1,
            "AES-192": 1,
            "AES-256": 3
          },
          "CAST": {
            "CAST": 13
          },
          "E2": {
            "E2": 8
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "TDES": 1,
            "Triple-DES": 4
          },
          "DES": {
            "DES": 3
          }
        },
        "constructions": {
          "MAC": {
            "CBC-MAC": 1,
            "CMAC": 8,
            "HMAC": 27,
            "HMAC-SHA-224": 1,
            "HMAC-SHA-256": 6
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "S.  Black",
      "/Category": "",
      "/Comments": "",
      "/Company": "Microsoft",
      "/ContentTypeId": "0x01010066E6728D5E109246855D376F3778675F",
      "/CreationDate": "D:20240813082012-07\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 24 for Word",
      "/Keywords": "",
      "/Manager": "",
      "/ModDate": "D:20240813082050-07\u002700\u0027",
      "/Producer": "Adobe PDF Library 24.2.255",
      "/SourceModified": "D:20240809001506",
      "/Subject": "FIPS 140-3 Security Policy Template",
      "/Title": "",
      "/_dlc_DocIdItemGuid": "189bbc1a-71fa-4077-a078-0f3e60820f51",
      "pdf_file_size_bytes": 776312,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=17131"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 36
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_garbage": false,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_pdf_hash": "dd954921c9011a1e0f55281baf289219f9654e4be02b59850d8487738f667e32",
    "policy_txt_hash": "9713809c9bff1c832a64f58df4da60a2500eccb7f4aeca13e128c66b96da28d4"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim validation. No assurance of the minimum strength of generated SSPs (e.g., keys). When operated in approved mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/August 2024_010924_0336.pdf",
    "date_sunset": "2029-08-13",
    "description": "The Mocana Cryptographic Module is the engine of Mocana\u0027s Device Security Framework - a software framework that secures all aspects of a system. The Device Security Framework helps applications and device designers reduce development costs and dramatically enhance cryptographic performance. For details see www.mocana.com.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Mocana Cryptographic Suite B Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": "7.0.0f_u1",
    "tested_conf": [
      "Buildroot Linux 2020.02.01 (32-bit) running on Honeywell Cordless Ultra with an Ingenic X2000 (without PAA)",
      "Buildroot Linux 2020.02.01 (32-bit) running on Ultra Charge \u0026 Communication Base with an Ingenic X1600E (without PAA)",
      "Yocto Linux 3.1 (32-bit) running on Xerox Alexandra Platform with an ARM Cortex A53 (without PAA))",
      "Yocto Linux 3.1 (32-bit) running on Xerox Explorer 6.5 with an Intel Atom E3950 (with PAA)",
      "Yocto Linux 3.1 (32-bit) running on Xerox Explorer 6.5 with an Intel Atom E3950 (without PAA)",
      "Yocto Linux 3.1 (32-bit) running on Xerox Explorer 8.0 with an Intel Atom x6413E (with PAA)",
      "Yocto Linux 3.1 (32-bit) running on Xerox Explorer 8.0 with an Intel Atom x6413E (without PAA)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-08-14",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "DigiCert, Inc.",
    "vendor_url": "http://www.digicert.com"
  }
}