This page was not yet optimized for use on mobile devices.
Summit Linux FIPS Core Crypto Module
Certificate details
| Certificate ID | #5054 |
|---|---|
| Status | active |
| Validation dates | 18.08.2025 |
| Sunset date | 17-08-2030 |
| Standard | FIPS 140-3 |
| Security level | 1 |
| Type | Firmware |
| Embodiment | Multi-Chip Stand Alone |
| Caveat | When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs |
| Exceptions |
|
| Description | The Summit FIPS Core Crypto Module is defined as a Firmware, Multi-chip Standalone module running on Laird's wireless bridge. |
| Vendor | Ezurio https://www.ezurio.com/wireless-modules/wifi-modules-bluetooth/wb45nbt-bluetooth-and-wifi-module |
| Lab | atsec information security corporation |
| Algorithms |
|
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES, AES-128, AES-192, AES-256, AES-, CAST, TDES, HMAC, HMAC-SHA-256, KMAC, CMACAsymmetric Algorithms
ECDH, ECDSA, ECC, DHE, DH, Diffie-HellmanHash functions
SHA-1, SHA-256, SHA-512, SHA-224, SHA-3, SHA3-224, SHA3-256, SHA3-384, SHA3-512, PBKDF2, PBKDFSchemes
MAC, Key Exchange, Key AgreementProtocols
SSH, TLS, TLS v1.2, TLS v1.3, TLSv1.0, TLSv1.1, TLSv1.2, TLS 1.0, TLS 1.2, TLS 1.3, IKE, IPsecRandomness
DRBG, RNG, RBGLibraries
OpenSSLElliptic Curves
P-256, P-384, P-224, P-521, Ed448Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTSJavaCard API constants
ED25519, ED448Trusted Execution Environments
PSP, SSCSecurity level
Level 1Standards
FIPS 140-3, FIPS186-5, FIPS 186-5, FIPS 198-1, FIPS 180-4, FIPS 202, FIPS 186-4, FIPS PUB 140-3, FIPS 197, SP 800-132, SP 800-38A, SP 800-38C, SP 800-38B, SP 800-38D, SP 800-38F, SP 800-38E, SP 800-90A, SP 800-56A, SP 800-56C, SP 800-135, SP 800-108, SP 800-185, SP 800-56B, SP 800-52, SP 800-140B, SP 800-90B, PKCS#1, RFC7627, RFC 4106, RFC5288, RFC8446, RFC 3526, RFC 7919, RFC 7627, RFC 5288, RFC 8446Automated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
No references are available for this certificate.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 5054,
"dgst": "b1537e61106f66d8",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"AES-CFB128A5004",
"RSA SigGen (FIPS186-5)A5018",
"AES-CBCA5004",
"KDF SSHA5019",
"SHA3-224A5020",
"SHA2-512/224A5018",
"AES-XTS Testing Revision 2.0A5004",
"#A5010",
"HMAC-SHA-1A5018",
"HMAC-SHA2-512/256A5018",
"#A5013",
"#A5005",
"HMAC-SHA2-224A5018",
"ECDSA SigGen (FIPS186-5)A5020",
"EDDSA SigGenA5016",
"AES-CBC-CS2A5004",
"HMAC-SHA3-256A5020",
"SHA3-512A5020",
"ECDSA SigVer (FIPS186-5)A5020",
"#A5006",
"#A5015",
"EDDSA SigVerA5016",
"KDF ANS 9.63A5018",
"KMAC-256A5020",
"KAS-FFC-SSC Sp800-56Ar3A5014",
"#A5002",
"#A4713",
"Safe Primes Key GenerationA5014",
"HMAC-SHA2-256A5018",
"AES-GMACA5008",
"SHAKE-128A5020",
"KTS-IFCA5018",
"KDA OneStep SP800-56Cr2A5012",
"AES-CTRA5004",
"#A4711",
"AES-CBC-CS3A5004",
"#A5018",
"PBKDFA5020",
"KAS-IFC-SSCA5018",
"SHA2-512A5018",
"AES-GCMA5008",
"#A5007",
"KAS-ECC-SSC Sp800-56Ar3A5018",
"KDF ANS 9.42A5020",
"ECDSA KeyVer (FIPS186-5)A5018",
"SHA2-512/256A5018",
"#A4712",
"AES-CBC-CS1A5004",
"HMAC-SHA3-224A5020",
"Safe Primes Key VerificationA5014",
"AES-KWPA5004",
"KDA TwoStep SP800-56Cr2A5012",
"TLS v1.2 KDF RFC7627A5018",
"HMAC-SHA3-384A5020",
"HMAC-SHA2-512A5018",
"KDF SP800-108A5017",
"KDA HKDF Sp800-56Cr1A5013",
"TLS v1.3 KDFA5013",
"AES-CMACA5004",
"SHA3-256A5020",
"Hash DRBGA5015",
"AES-ECBA5019",
"#A4715",
"#A5011",
"AES-CFB8A5004",
"HMAC-SHA2-512/224A5018",
"#A4714",
"SHA-1A5018",
"RSA KeyGen (FIPS186-5)A5018",
"AES-CCMA5004",
"AES-KWA5004",
"#A4718",
"#A4716",
"SHA3-384A5020",
"#A5003",
"#A5012",
"#A4717",
"SHA2-256A5018",
"HMAC DRBGA5015",
"RSA SigVer (FIPS186-5)A5018",
"EDDSA KeyGenA5016",
"HMAC-SHA2-384A5018",
"SHAKE-256A5020",
"#A5019",
"#A5008",
"#A5020",
"#A5009",
"#A5014",
"#A5004",
"AES-OFBA5004",
"KMAC-128A5020",
"SHA2-224A5018",
"AES-CFB1A5004",
"#A5017",
"HMAC-SHA3-512A5020",
"SHA2-384A5018",
"#A5016",
"Counter DRBGA5015",
"KDF TLSA5018",
"KDF KMAC Sp800-108r1A5017",
"ECDSA KeyGen (FIPS186-5)A5018"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"br1_deviations": 1,
"br1_tables": {
"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
"approved_algorithms": {
"entries": [
{
"algorithm": "AES-CBC",
"cavpCertName": "A4712, A4716, A5002, A5003, A5004",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS1",
"cavpCertName": "A5002, A5003, A5004",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS2",
"cavpCertName": "A5002, A5003, A5004",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS3",
"cavpCertName": "A4714, A4718, A5002, A5003, A5004",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CCM",
"cavpCertName": "A4712, A4716, A5002, A5003, A5004",
"properties": "Key Length - 128, 192, 256",
"reference": "SP 800-38C"
},
{
"algorithm": "AES-CFB1",
"cavpCertName": "A5002, A5003, A5004",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CFB128",
"cavpCertName": "A5002, A5003, A5004",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CFB8",
"cavpCertName": "A5002, A5003, A5004",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CMAC",
"cavpCertName": "A4712, A4716, A5002, A5003, A5004",
"properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
"reference": "SP 800-38B"
},
{
"algorithm": "AES-CTR",
"cavpCertName": "A4712, A4716, A5002, A5003, A5004",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-ECB",
"cavpCertName": "A4711, A4712, A4715, A4716, A4717, A5002, A5003, A5004, A5019",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-GCM",
"cavpCertName": "A4712, A4715, A4717",
"properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-GCM",
"cavpCertName": "A5005, A5006, A5007, A5008",
"properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-GMAC",
"cavpCertName": "A4712, A5005, A5006, A5007, A5008",
"properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-KW",
"cavpCertName": "A5002, A5003, A5004",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38F"
},
{
"algorithm": "AES-KWP",
"cavpCertName": "A5002, A5003, A5004",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38F"
},
{
"algorithm": "AES-OFB",
"cavpCertName": "A5002, A5003, A5004",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-XTS Testing Revision 2.0",
"cavpCertName": "A4712, A4716, A5002, A5003, A5004",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
"reference": "SP 800-38E"
},
{
"algorithm": "Counter DRBG",
"cavpCertName": "A4711, A4712, A4715, A4717",
"properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "Counter DRBG",
"cavpCertName": "A5015",
"properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "ECDSA KeyGen (FIPS186-5)",
"cavpCertName": "A4711",
"properties": "Curve - P-256, P-384 Secret Generation Mode - testing candidates",
"reference": "FIPS 186-5"
},
{
"algorithm": "ECDSA KeyGen (FIPS186-5)",
"cavpCertName": "A5009, A5018",
"properties": "Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidates",
"reference": "FIPS 186-5"
},
{
"algorithm": "ECDSA KeyVer (FIPS186-5)",
"cavpCertName": "A5009, A5018",
"properties": "Curve - P-224, P-256, P-384, P-521",
"reference": "FIPS 186-5"
},
{
"algorithm": "ECDSA SigGen (FIPS186-5)",
"cavpCertName": "A5009, A5018",
"properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Component - No",
"reference": "FIPS 186-5"
},
{
"algorithm": "ECDSA SigGen (FIPS186-5)",
"cavpCertName": "A5011, A5020",
"properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Component - No",
"reference": "FIPS 186-5"
},
{
"algorithm": "ECDSA SigVer (FIPS186-5)",
"cavpCertName": "A5009, A5018",
"properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
"reference": "FIPS 186-5"
},
{
"algorithm": "ECDSA SigVer (FIPS186-5)",
"cavpCertName": "A5011, A5020",
"properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA KeyGen",
"cavpCertName": "A5016",
"properties": "Curve - ED-25519, ED-448",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA SigGen",
"cavpCertName": "A5016",
"properties": "Curve - ED-25519, ED-448",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA SigVer",
"cavpCertName": "A5016",
"properties": "Curve - ED-25519, ED-448",
"reference": "FIPS 186-5"
},
{
"algorithm": "Hash DRBG",
"cavpCertName": "A5015",
"properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC DRBG",
"cavpCertName": "A5015",
"properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC-SHA-1",
"cavpCertName": "A5009, A5018",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 224",
"cavpCertName": "A5009, A5018",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 256",
"cavpCertName": "A5009, A5010, A5018",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 384",
"cavpCertName": "A5009, A5018",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512",
"cavpCertName": "A5009, A5018",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512/224",
"cavpCertName": "A5009, A5018",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512/256",
"cavpCertName": "A5009, A5018",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 224",
"cavpCertName": "A5011, A5020",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 256",
"cavpCertName": "A5011, A5020",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 384",
"cavpCertName": "A5011, A5020",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 512",
"cavpCertName": "A5011, A5020",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "KAS-ECC-SSC Sp800-56Ar3",
"cavpCertName": "A4711",
"properties": "Domain Parameter Generation Methods - P- 256, P-384",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "",
"cavpCertName": "",
"properties": "Scheme - ephemeralUnified - KAS Role - initiator, responder",
"reference": ""
},
{
"algorithm": "KAS-ECC-SSC Sp800-56Ar3",
"cavpCertName": "A5009, A5018",
"properties": "Domain Parameter Generation Methods - P- 224, P-256, P-384, P-521 Scheme - ephemeralUnified -",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-FFC-SSC Sp800-56Ar3",
"cavpCertName": "A5014",
"properties": "KAS Role - initiator, responder Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP- 8192 Scheme - dhEphem - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-IFC-SSC",
"cavpCertName": "A5009, A5018",
"properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime- factor Scheme - KAS1 - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KDA HKDF Sp800-56Cr1",
"cavpCertName": "A5013",
"properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDA OneStep SP800-56Cr2",
"cavpCertName": "A5012",
"properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDA TwoStep SP800-56Cr2",
"cavpCertName": "A5012",
"properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDF ANS 9.42 (CVL)",
"cavpCertName": "A5009, A5018",
"properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 8-4096 Increment 8",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF ANS 9.42 (CVL)",
"cavpCertName": "A5011, A5020",
"properties": "KDF Type - DER Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF ANS 9.63 (CVL)",
"cavpCertName": "A5009, A5018",
"properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "Algorithm",
"cavpCertName": "CAVP Cert",
"properties": "Key Data Length - Key Data Length: 128- 4096 Increment 8",
"reference": "Reference"
},
{
"algorithm": "KDF KMAC Sp800-108r1",
"cavpCertName": "A5017",
"properties": "Derived Key Length - Derived Key Length: 112-4096 Increment 8",
"reference": "SP 800-108 Rev. 1"
},
{
"algorithm": "KDF SP800- 108",
"cavpCertName": "A5017",
"properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 112, 128, 776, 3456, 4096",
"reference": "SP 800-108 Rev. 1"
},
{
"algorithm": "KDF SSH (CVL)",
"cavpCertName": "A5019",
"properties": "Cipher - AES-128, AES-192, AES-256, TDES Hash Algorithm - SHA-1, SHA2-256, SHA2- 384, SHA2-512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF TLS (CVL)",
"cavpCertName": "A5009, A5018",
"properties": "TLS Version - v1.0/1.1",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KMAC-128",
"cavpCertName": "A5011, A5020",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Key Data Length - Key Data Length: 128- 1024 Increment 8",
"reference": "SP 800-185"
},
{
"algorithm": "KMAC-256",
"cavpCertName": "A5011, A5020",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Key Data Length - Key Data Length: 128- 1024 Increment 8",
"reference": "SP 800-185"
},
{
"algorithm": "KTS-IFC",
"cavpCertName": "A5009, A5018",
"properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime- factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 768",
"reference": "SP 800-56B Rev. 2"
},
{
"algorithm": "PBKDF",
"cavpCertName": "A5009, A5011, A5018, A5020",
"properties": "Iteration Count - Iteration Count: 1000- 10000 Increment 1 Password Length - Password Length: 14- 128 Increment 1",
"reference": "SP 800-132"
},
{
"algorithm": "RSA KeyGen (FIPS186-5)",
"cavpCertName": "A5009, A5018",
"properties": "Key Generation Mode - probableWithProbableAux Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standard",
"reference": "FIPS 186-5"
},
{
"algorithm": "RSA SigGen (FIPS186-5)",
"cavpCertName": "A5009, A5018",
"properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
"reference": "FIPS 186-5"
},
{
"algorithm": "RSA SigVer (FIPS186-5)",
"cavpCertName": "A5009, A5018",
"properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
"reference": "FIPS 186-5"
},
{
"algorithm": "Safe Primes Key Generation",
"cavpCertName": "A5014",
"properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP- 6144, MODP-8192",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "Safe Primes Key Verification",
"cavpCertName": "A5014",
"properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP- 6144, MODP-8192",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "SHA-1",
"cavpCertName": "A5009, A5018",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-224",
"cavpCertName": "A4711, A4712, A4716, A5009, A5018",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A4711, A4712, A4716, A5009, A5010, A5018",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-384",
"cavpCertName": "A4711, A4712, A4716, A5009, A5018",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "A4711, A4712, A4716, A5009, A5018",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2- 512/224",
"cavpCertName": "A5009, A5018",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2- 512/256",
"cavpCertName": "A5009, A5018",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA3-224",
"cavpCertName": "A4713, A5011, A5020",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-256",
"cavpCertName": "A4713, A5011, A5020",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-384",
"cavpCertName": "A4713, A5011, A5020",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-512",
"cavpCertName": "A4713, A5011, A5020",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHAKE-128",
"cavpCertName": "A5011, A5020",
"properties": "Output Length - Output Length: 16-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHAKE-256",
"cavpCertName": "A5011, A5020",
"properties": "Output Length - Output Length: 16-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
"cavpCertName": "A5009, A5018",
"properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "TLS v1.3 KDF (CVL)",
"cavpCertName": "A5013",
"properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
"reference": "SP 800-135 Rev. 1"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"approved_services": {
"entries": [
{
"description": "Encrypti on",
"indicator": "crypto_skcipher_setkey returns 0",
"inputs": "AES key, plaintex t",
"name": "Kernel Encryptio n",
"outputs": "cipherte xt",
"rolesSspAccess": "Crypto Officer - Kernel AES key: W,E",
"secFunImpl": "Kernel AES- ECB Kernel AES- CTR Kernel AES- CBC Kernel AES- CBC- CS3 Kernel AES- XTS"
},
{
"description": "Decrypt ion",
"indicator": "crypto_skcipher_setkey returns 0",
"inputs": "AES key, cipherte xt",
"name": "Kernel Decrypti on",
"outputs": "plaintext",
"rolesSspAccess": "Crypto Officer - Kernel AES key: W,E",
"secFunImpl": "Kernel AES- ECB Kernel AES- CTR Kernel AES- CBC Kernel AES- CBC- CS3 Kernel AES- XTS"
},
{
"description": "Encrypti on",
"indicator": "crypto_aead_setkey returns 0",
"inputs": "AES key, IV, plaintex t",
"name": "Kernel Authenti cated Encryptio n",
"outputs": "cipherte xt, MAC tag",
"rolesSspAccess": "Crypto Officer - Kernel AES key: W,E",
"secFunImpl": "Kernel AES- CCM (BC- Auth) Kernel AES- GCM (BC- Auth)"
},
{
"description": "Decrypt ion",
"indicator": "crypto_aead_setkey returns 0",
"inputs": "AES key, IV, MAC tag, cipherte xt",
"name": "Kernel Authenti cated Decrypti on",
"outputs": "plaintext or fail",
"rolesSspAccess": "Crypto Officer - Kernel AES key: W,E",
"secFunImpl": "Kernel AES- CCM (BC- Auth) Kernel AES- GCM (BC- Auth)"
},
{
"description": "Wrap a key",
"indicator": "crypto_skcipher_setkey returns 0; crypto_aead_setkey returns 0; crypto_shash_init returns 0",
"inputs": "AES key, key to be wrappe d",
"name": "Kernel key wrapping",
"outputs": "wrapped key",
"rolesSspAccess": "Crypto Officer - Kernel AES key: W,E",
"secFunImpl": "Kernel AES- CCM (KTS- Wrap) Kernel AES- GCM (KTS- Wrap) Kernel AES CBC with HMAC Kernel AES CTR with HMAC"
},
{
"description": "unwrap a key",
"indicator": "crypto_skcipher_setkey returns 0; crypto_aead_setkey returns 0; crypto_shash_init returns 0",
"inputs": "AES key, key to be unwrap ped",
"name": "Kernel key unwrappi ng",
"outputs": "unwrapp ed key",
"rolesSspAccess": "Crypto Officer - Kernel AES key: W,E",
"secFunImpl": "Kernel AES- CCM (KTS- Wrap) Kernel AES- GCM (KTS- Wrap) Kernel"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": "AES CBC with HMAC Kernel AES CTR with HMAC"
},
{
"description": "comput e a MAC tag",
"indicator": "crypto_shash_init returns 0",
"inputs": "AES key, messag e",
"name": "Kernel AES Message Authenti cation",
"outputs": "MAC tag",
"rolesSspAccess": "Crypto Officer - Kernel AES key: W,E",
"secFunImpl": "Kernel AES- CMAC Kernel AES- GMAC"
},
{
"description": "comput e a MAC tag",
"indicator": "crypto_shash_init returns 0",
"inputs": "HMAC key, messag e",
"name": "Kernel HMAC Message Authenti cation",
"outputs": "MAC tag",
"rolesSspAccess": "Crypto Officer - Kernel HMAC key: W,E",
"secFunImpl": "Kernel HMAC"
},
{
"description": "comput e a messag e digest",
"indicator": "crypto_shash_init returns 0",
"inputs": "messag e",
"name": "Kernel Message Digest",
"outputs": "digest value",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "Kernel Hashes"
},
{
"description": "comput e a shared secret",
"indicator": "crypto_kpp_compute_sh ared_secret returns 0",
"inputs": "EC public key, EC private key",
"name": "Kernel ECC Shared Secret Computa tion",
"outputs": "Shared Secret",
"rolesSspAccess": "Crypto Officer - Kernel EC public key: W,E - Kernel EC private key: W,E - Kernel shared secret: W,E",
"secFunImpl": "Kernel KAS- ECC- SSC"
},
{
"description": "generat e random bytes",
"indicator": "crypto_rng_get_bytes returns 0",
"inputs": "output length",
"name": "Kernel Random Number Generati on",
"outputs": "random data",
"rolesSspAccess": "Crypto Officer - Entropy input: W,E - Kernel DRBG seed: G,E - DRBG Internal State (V, Key): W,E - DRBG Internal state (V, C): W,E",
"secFunImpl": "Kernel Counte r DRBG"
},
{
"description": "generat e key pair",
"indicator": "crypto_kpp_set_secret and crypto_kpp_generate_pu blic_key return 0",
"inputs": "Curve",
"name": "Kernel EC Key generati on",
"outputs": "EC keys",
"rolesSspAccess": "Crypto Officer - Kernel EC public key: G,R - Kernel EC private key: G,R - Kernel Intermedi ate Key Generatio n Value: G,E,Z",
"secFunImpl": "Kernel ECDSA Key Genera tion"
},
{
"description": "comput e a mesage digest",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "messag e",
"name": "FIPS provider Message Digest",
"outputs": "digest value",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "FIPS provid er Hashes"
},
{
"description": "Encrypt plaintex t",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "AES key, plaintex t",
"name": "FIPS provider Encryptio n",
"outputs": "cipherte xt",
"rolesSspAccess": "Crypto Officer - FIPS provider AES Key: W,E",
"secFunImpl": "FIPS provid er AES- CTR FIPS provid er AES- CBC FIPS provid er AES- ECB FIPS provid er AES- CBC- CS1 FIPS provid er AES- CBC- CS2 FIPS provid er AES- CBC- CS3 FIPS provid er AES- CFB1 FIPS provid"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": "er AES- CFB8 FIPS provid er AES- CFB12 8 FIPS provid er AES- XTS FIPS provid er AES-"
},
{
"description": "Decrypt cipherte xt",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "AES key, cipherte xt",
"name": "FIPS provider Decrypti on",
"outputs": "plaintext",
"rolesSspAccess": "Crypto Officer - FIPS provider AES Key: W,E",
"secFunImpl": "OFB FIPS provid er AES- CTR FIPS provid er AES- CBC FIPS provid er AES- ECB FIPS provid er AES- CBC- CS1 FIPS provid er AES- CBC- CS2 FIPS provid er AES- CBC- CS3 FIPS provid er AES- CFB1 FIPS provid er AES- CFB8 FIPS"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": "provid er AES- CFB12 8 FIPS provid er AES- XTS FIPS provid er AES- OFB"
},
{
"description": "Encrypt plaintex t",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "AES key, IV, plaintex t",
"name": "FIPS provider Authenti cated Encryptio n",
"outputs": "cipherte xt, MAC tag",
"rolesSspAccess": "Crypto Officer - FIPS provider AES Key: W,E",
"secFunImpl": "FIPS provid er AES- CCM (BC- Auth) FIPS provid er AES- GCM (BC-"
},
{
"description": "Decrypt cipherte xt",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "AES key, IV, MAC tag, cipherte xt",
"name": "FIPS provider Authenti cated Decrypti on",
"outputs": "plaintext",
"rolesSspAccess": "Crypto Officer - FIPS provider AES Key: W,E",
"secFunImpl": "FIPS provid er AES- CCM (BC- Auth) FIPS provid er AES- GCM (BC- Auth)"
},
{
"description": "comput e a MAC tag",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "AES key, messag e",
"name": "FIPS provider AES Message Authenti cation",
"outputs": "MAC tag",
"rolesSspAccess": "Crypto Officer - FIPS provider AES Key: W,E",
"secFunImpl": "FIPS provid er AES- CMAC FIPS provid er AES- GMAC"
},
{
"description": "comput e a MAC tag",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "HMAC key, messag e",
"name": "FIPS provider HMAC Message Authenti cation",
"outputs": "MAC tag",
"rolesSspAccess": "Crypto Officer - FIPS provider HMAC key: W,E",
"secFunImpl": "FIPS provid er HMAC"
},
{
"description": "comput e a shared secret",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "DH private key, DH public key",
"name": "FIPS provider FFC Shared Secret Computa tion",
"outputs": "Shared Secret",
"rolesSspAccess": "Crypto Officer - FIPS provider DH public key: W,E - FIPS provider DH private key: W,E",
"secFunImpl": "FIPS provid er KAS- FFC- SSC"
},
{
"description": "comput e a shared secret",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "EC public key, EC private key",
"name": "FIPS provider ECC Shared Secret Computa tion",
"outputs": "Shared Secret",
"rolesSspAccess": "Crypto Officer - FIPS provider EC public key: W,E - FIPS provider EC private key: W,E - FIPS provider shared secret:",
"secFunImpl": "FIPS provid er KAS- ECC- SSC"
},
{
"description": "comput e a shared secret",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "RSA public key, RSA private key",
"name": "FIPS provider IFC Shared Secret Computa tion",
"outputs": "Shared Secret",
"rolesSspAccess": "Crypto Officer - FIPS provider RSA public key: W,E - FIPS provider RSA private key: W,E - FIPS provider shared secret: W,E",
"secFunImpl": "FIPS provid er KAS- IFC- SSC"
},
{
"description": "derive a key",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "Shared secret",
"name": "FIPS provider Key Derivatio n",
"outputs": "derived key",
"rolesSspAccess": "Crypto Officer - FIPS provider shared secret: W,E - FIPS provider derived",
"secFunImpl": "FIPS provid er ANS 9.42 Key Derivat ion (CVL) FIPS provid"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "key: G,R - FIPS provider key- derivation key: W,E - FIPS provider AES Derived Key: G,R - FIPS provider HMAC Derived Key : G,R - FIPS provider 802.11 Pre- shared key (PSK): W,E - FIPS provider 802.11 Pairwise Master Key (PMK): W,E - FIPS provider 802.11 KDF Internal State: R - FIPS provider 802.11 Temporal Keys: W,E - FIPS provider 802.11 MIC keys (KCK): W,E - FIPS provider 802.11 Key",
"secFunImpl": "er ANS 9.63 Key Derivat ion (CVL) FIPS provid er TLS 1.0 and 1.1 Key Derivat ion (CVL) FIPS provid er TLS 1.2 Key Derivat ion (CVL) FIPS provid er TLS 1.3 Key Derivat ion (CVL) FIPS provid er HKDF Key Derivat ion FIPS provid er OneSte p Key Derivat ion FIPS provid er TwoSte p Key"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Encryption Key (KEK): W,E - FIPS provider 802.11 Group Temporal Key (GTK): W,E",
"secFunImpl": "Derivat ion FIPS provid er KMAC Key Derivat ion FIPS provid er KBKDF Key Derivat ion FIPS provid er SSH Key Derivat ion"
},
{
"description": "derive a key from a passwor d",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "passwor d",
"name": "FIPS provider Password -based key derivatio n",
"outputs": "derived key",
"rolesSspAccess": "Crypto Officer - FIPS provider derived key: G,R - FIPS provider Password: W,E",
"secFunImpl": "FIPS provid er Passw ord- based Key Derivat ion"
},
{
"description": "generat e a key pair",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "DH- Group",
"name": "FIPS provider SafePrim e key generati on",
"outputs": "Module generat ed DH private key, Module generat ed DH public key",
"rolesSspAccess": "Crypto Officer - FIPS provider module generated DH public key: G,R - FIPS provider module generated DH private key: G,R - FIPS provider Intermedi ate Key Generatio",
"secFunImpl": "FIPS provid er Safe Primes Key Genera tion"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "n Value: G,E,Z",
"secFunImpl": ""
},
{
"description": "generat e a key pair",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "Curve",
"name": "FIPS provider EC Key generati on",
"outputs": "Module Generat ed EC Private Key, Module Generat ed EC Public Key",
"rolesSspAccess": "Crypto Officer - FIPS provider module generated EC public key: G,R - FIPS provider module generated EC private key: G,R - FIPS provider Intermedi ate Key Generatio n Value: G,E,Z",
"secFunImpl": "FIPS provid er ECDSA Key Genera tion FIPS provid er EDDSA Key Genera tion"
},
{
"description": "generat e a key pair",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "Modulus",
"name": "FIPS provider RSA key generati on",
"outputs": "Module Generat ed RSA Private Key, Module Generat ed RSA Public Key",
"rolesSspAccess": "Crypto Officer - FIPS provider module generated RSA private key: G,R - FIPS provider module generated RSA public key: G,R - FIPS provider Intermedi ate Key Generatio n Value: G,E,Z",
"secFunImpl": "FIPS provid er RSA Key Genera tion"
},
{
"description": "verify key pair",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "DH Private key, DH public key",
"name": "FIPS provider SafePrim e Key Verificati on",
"outputs": "Pass/fail",
"rolesSspAccess": "Crypto Officer - FIPS provider DH public key: W",
"secFunImpl": "FIPS provid er Safe Primes Key"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- FIPS provider DH private key: W",
"secFunImpl": "Verific ation"
},
{
"description": "verify key pair",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "EC public key, EC private key",
"name": "FIPS provider EC Key Verificati on",
"outputs": "Pass/fail",
"rolesSspAccess": "Crypto Officer - FIPS provider EC public key: W - FIPS provider EC private key: W",
"secFunImpl": "FIPS provid er ECDSA Key Verific ation"
},
{
"description": "wrap a key",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "AES key, key to be wrappe d",
"name": "FIPS provider Key wrapping",
"outputs": "wrapped key",
"rolesSspAccess": "Crypto Officer - FIPS provider AES Key: W,E",
"secFunImpl": "FIPS provid er AES- CCM (KTS- Wrap) FIPS provid er AES- GCM (KTS- Wrap) FIPS provid er AES KW FIPS provid er AES KWP"
},
{
"description": "unwrap a key",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "AES key, key to be unwrap ped",
"name": "FIPS provider Key unwrappi ng",
"outputs": "unwrapp ed key",
"rolesSspAccess": "Crypto Officer - FIPS provider AES Key: W,E",
"secFunImpl": "FIPS provid er AES- CCM (KTS- Wrap) FIPS provid er AES- GCM (KTS- Wrap) FIPS provid er AES KW FIPS"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": "provid er AES KWP"
},
{
"description": "verify digital signatur e",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "RSA public key, signatur e, hash algorith m",
"name": "FIPS provider RSA Signatur e Verificati on",
"outputs": "Pass/fail",
"rolesSspAccess": "Crypto Officer - FIPS provider RSA public key: W,E",
"secFunImpl": "FIPS provid er RSA Signat ure Verific ation"
},
{
"description": "verify digital signatur e",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "Messag e, EC public key, signatur e, hash algorith m (ECDSA only)",
"name": "FIPS provider EC Signatur e Verificati on",
"outputs": "Pass/fail",
"rolesSspAccess": "Crypto Officer - FIPS provider EC public key: W,E",
"secFunImpl": "FIPS provid er ECDSA Signat ure Verific ation FIPS provid er EDDSA Signat ure Verific"
},
{
"description": "generat e digital signatur e",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "Messag e, EC public key, signatur e, hash algorith m (ECDSA only)",
"name": "FIPS provider EC Signatur e Generati on",
"outputs": "signatur e",
"rolesSspAccess": "Crypto Officer - FIPS provider EC private key: W,E",
"secFunImpl": "FIPS provid er ECDSA Signat ure Genera tion FIPS provid er EDDSA Signat ure Genera tion"
},
{
"description": "generat e digital signatur e",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "Messag e,RSA public key, signatur e, hash algorith m",
"name": "FIPS provider RSA Signatur e Generati on",
"outputs": "signatur e",
"rolesSspAccess": "Crypto Officer - FIPS provider RSA private key: W,E",
"secFunImpl": "FIPS provid er RSA Signat ure Genera tion"
},
{
"description": "generat e random bytes",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "output length",
"name": "FIPS provider Random Number Generati on",
"outputs": "random bytes",
"rolesSspAccess": "Crypto Officer - Entropy input: W,E - FIPS provider DRBG seed: G,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal state (V, C): G,W,E",
"secFunImpl": "FIPS provid er Counte r DRBG FIPS provid er Hash DRBG FIPS provid er HMAC DRBG"
},
{
"description": "KTS",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "RSA public key",
"name": "FIPS provider key encapsul ation",
"outputs": "Encapsu lated key",
"rolesSspAccess": "Crypto Officer - FIPS provider RSA public key: W,E",
"secFunImpl": "FIPS provid er KTS- IFC"
},
{
"description": "KTS",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "RSA private key",
"name": "FIPS provider key un- encapsul ation",
"outputs": "Decapsu lated key",
"rolesSspAccess": "Crypto Officer - FIPS provider RSA private key: W,E",
"secFunImpl": "FIPS provid er KTS- IFC"
},
{
"description": "MAC",
"indicator": "_SUMMIT_FIPS_INDICAT OR_APPROVED",
"inputs": "KMAC key",
"name": "FIPS provider KMAC Message Authenti cation",
"outputs": "Mac tag",
"rolesSspAccess": "Crypto Officer - FIPS Provider KMAC Key: W,E",
"secFunImpl": "FIPS provid er KMAC"
},
{
"description": "Return the module name and version informa tion",
"indicator": "None",
"inputs": "N/A",
"name": "Show version",
"outputs": "module name and version",
"rolesSspAccess": "Unauthent icated",
"secFunImpl": "None"
},
{
"description": "return module status",
"indicator": "None",
"inputs": "N/A",
"name": "Show status",
"outputs": "module status",
"rolesSspAccess": "Unauthent icated",
"secFunImpl": "None"
},
{
"description": "perform CASTs and",
"indicator": "None",
"inputs": "N/A",
"name": "Self- Tests",
"outputs": "Pass/Fail",
"rolesSspAccess": "Unauthent icated",
"secFunImpl": "None"
},
{
"description": "integrit y test",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": ""
},
{
"description": "zeroize all SSPs",
"indicator": "None",
"inputs": "Any SSP",
"name": "Zeroizati on",
"outputs": "N/A",
"rolesSspAccess": "Crypto Officer - Kernel AES key: Z - FIPS provider AES Key: Z - Kernel shared secret: Z - Kernel HMAC key: Z - FIPS provider shared secret: Z - Entropy input: Z - Kernel DRBG seed: Z - DRBG Internal State (V, Key): Z - DRBG Internal state (V, C): Z - FIPS provider DH public key: Z - FIPS provider DH private key: Z - Kernel EC public key: Z - Kernel EC private key: Z - FIPS provider EC public key: Z",
"secFunImpl": "None"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- FIPS provider EC private key: Z - FIPS provider module generated DH public key: Z - FIPS provider module generated DH private key: Z - FIPS provider module generated EC public key: Z - FIPS provider module generated RSA public key: Z - FIPS provider RSA public key: Z - FIPS provider RSA private key: Z - FIPS provider module generated RSA public key: Z - FIPS provider module generated RSA private key: Z - FIPS",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "provider Intermedi ate Key Generatio n Value: Z - FIPS provider derived key: Z - FIPS provider DRBG seed: Z - Kernel Intermedi ate Key Generatio n Value: Z - FIPS provider key- derivation key: Z - FIPS provider Password: Z - FIPS provider HMAC key: Z - FIPS Provider KMAC Key: Z - FIPS provider 802.11 Pairwise Master Key (PMK): Z - FIPS provider 802.11 Group Temporal Key (GTK): Z - FIPS provider",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "802.11 KDF Internal State: Z - FIPS provider 802.11 Temporal Keys: Z - FIPS provider 802.11 MIC keys (KCK): Z - FIPS provider 802.11 Key Encryption Key (KEK): Z",
"secFunImpl": ""
}
],
"found": true,
"section": 4,
"subsection": 3
},
"authentication_methods": {
"entries": [],
"found": false,
"section": 4,
"subsection": 1
},
"cond_self_tests": {
"entries": [
{
"algorithmOrTest": "ECDSA KeyGen (FIPS186- 5) (A4711)",
"condition": "Key pair generation",
"details": "SP 800- 56Ar3 Section 5.6.2.1.4",
"indicator": "crypto_kpp_g enerate_public_k ey returns 0",
"testMethod": "PCT",
"testProps": "N/A",
"type": "PCT"
},
{
"algorithmOrTest": "SHA2-224 (A4711)",
"condition": "Module initializatio n",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184 bit messages",
"type": "CAS T"
},
{
"algorithmOrTest": "SHA2-256 (A4711)",
"condition": "Module initializatio n",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184 bit messages",
"type": "CAS T"
},
{
"algorithmOrTest": "SHA2-384 (A4711)",
"condition": "Module initializatio n",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184 bit messages",
"type": "CAS T"
},
{
"algorithmOrTest": "SHA2-512 (A4711)",
"condition": "Module initializatio n",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184 bit messages",
"type": "CAS T"
},
{
"algorithmOrTest": "SHA3-224 (A4713)",
"condition": "Module initializatio n",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184 bit messages",
"type": "CAS T"
},
{
"algorithmOrTest": "SHA3-256 (A4713)",
"condition": "Module initializatio n",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184 bit messages",
"type": "CAS T"
},
{
"algorithmOrTest": "SHA3-384 (A4713)",
"condition": "Module initializatio n",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184 bit messages",
"type": "CAS T"
},
{
"algorithmOrTest": "SHA3-512 (A4713)",
"condition": "Module initializatio n",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184 bit messages",
"type": "CAS T"
},
{
"algorithmOrTest": "AES-ECB (A4711)",
"condition": "Module initializatio n",
"details": "Encryption, Decryption (Separately)",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit keys",
"type": "CAS T"
},
{
"algorithmOrTest": "AES-CBC (A4712)",
"condition": "Module initializatio n",
"details": "Encryption, Decryption (Separately)",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit keys",
"type": "CAS T"
},
{
"algorithmOrTest": "AES-CTR (A4712)",
"condition": "Module initializatio n",
"details": "Encryption, Decryption (Separately)",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit keys",
"type": "CAS T"
},
{
"algorithmOrTest": "AES-CCM (A4712)",
"condition": "Module initializatio n",
"details": "Encryption, Decryption (Separately)",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit keys",
"type": "CAS T"
},
{
"algorithmOrTest": "AES-GCM (A4712)",
"condition": "Module initializatio n",
"details": "Message authenticatio n",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit keys",
"type": "CAS T"
},
{
"algorithmOrTest": "AES- CMAC (A4712)",
"condition": "Module initializatio n",
"details": "Message authenticatio n",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128 and 256 bit keys",
"type": "CAS T"
},
{
"algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A4711)",
"condition": "Module initializatio n",
"details": "Shared secret computation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "P-256, P- 384",
"type": "CAS T"
},
{
"algorithmOrTest": "Counter DRBG (A4711)",
"condition": "Module initializatio n",
"details": "Seed Generate",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit keys with/witho ut PR; Health test per section 11.3 of SP 800-90A",
"type": "CAS T"
},
{
"algorithmOrTest": "ECDSA KeyGen (FIPS186- 5) (A5009)",
"condition": "EC key pair generation",
"details": "Signature generation and verification",
"indicator": "Successful key generation",
"testMethod": "PCT",
"testProps": "SHA2-256",
"type": "PCT"
},
{
"algorithmOrTest": "RSA KeyGen (FIPS186- 5)",
"condition": "RSA key pair generation",
"details": "Signature generation and verification",
"indicator": "Successful key generation",
"testMethod": "PCT",
"testProps": "PKCS#1 v1.5 with SHA2-256",
"type": "PCT"
},
{
"algorithmOrTest": "Safe Primes Key",
"condition": "Safe Primes key",
"details": "Public key re- computation and",
"indicator": "Successful key generation",
"testMethod": "PCT",
"testProps": "N/A",
"type": "PCT"
},
{
"algorithmOrTest": "Generatio n (A5014)",
"condition": "pair generation",
"details": "comparison with the existing public key (per SP 800- 56Ar3 Section 5.6.2.1.4)",
"indicator": "",
"testMethod": "",
"testProps": "",
"type": ""
},
{
"algorithmOrTest": "EDDSA KeyGen (A5016)",
"condition": "EDDSA key pair generation",
"details": "Signature generation and verification",
"indicator": "Successful key generation",
"testMethod": "PCT",
"testProps": "ED25519 and ED448",
"type": "PCT"
},
{
"algorithmOrTest": "SHA-1 (A5009)",
"condition": "Module initializatio n",
"details": "Message Digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "24-bit message",
"type": "CAS T"
},
{
"algorithmOrTest": "SHA2-512 (A5009)",
"condition": "Module initializatio n",
"details": "Message Digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "24-bit message",
"type": "CAS T"
},
{
"algorithmOrTest": "SHA3-256 (A5011)",
"condition": "Module initializatio n",
"details": "Message Digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-bit message",
"type": "CAS T"
},
{
"algorithmOrTest": "AES-ECB (A5002)",
"condition": "Module initializatio n",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128-bit keys, 128- bit ciphertext",
"type": "CAS T"
},
{
"algorithmOrTest": "AES-GCM (A5005)",
"condition": "Module initializatio n",
"details": "Encryption, Decryption (Separately)",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "256-bit keys, 96- bit IVs, 128-bit plaintext, 128-bit additional data",
"type": "CAS T"
},
{
"algorithmOrTest": "KDF SP800- 108 (A5017)",
"condition": "Module initializatio n",
"details": "Key Derivation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "Counter mode, HMAC- SHA2-256, 128-bit input key",
"type": "CAS T"
},
{
"algorithmOrTest": "KDA OneStep SP800- 56Cr2 (A5012)",
"condition": "Module initializatio n",
"details": "Key Derivation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-224, 392-bit input secret",
"type": "CAS T"
},
{
"algorithmOrTest": "KDA HKDF Sp800- 56Cr1 (A5013)",
"condition": "Module initializatio n",
"details": "Key Derivation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-256, 48-bit input secret",
"type": "CAS T"
},
{
"algorithmOrTest": "KDF ANS 9.42 (A5009)",
"condition": "Module initializatio n",
"details": "Key Derivation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-1 with AES-128, KW, 160-",
"type": "CAS T"
},
{
"algorithmOrTest": "",
"condition": "",
"details": "",
"indicator": "",
"testMethod": "",
"testProps": "bit input secret",
"type": ""
},
{
"algorithmOrTest": "KDF ANS 9.63 (A5009)",
"condition": "Module initializatio n",
"details": "Key Derivation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-256, 192-bit input secret",
"type": "CAS T"
},
{
"algorithmOrTest": "KDF SSH (A5019)",
"condition": "Module initializatio n",
"details": "Key Derivation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-1, 1056-bit input secret",
"type": "CAS T"
},
{
"algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5009)",
"condition": "Module initializatio n",
"details": "Key Derivation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-256, 84-bit input secret",
"type": "CAS T"
},
{
"algorithmOrTest": "TLS v1.3 KDF (A5013)",
"condition": "Module initializatio n",
"details": "Key Derivation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "Extract and expand modes, SHA-256",
"type": "CAS T"
},
{
"algorithmOrTest": "PBKDF (A5009)",
"condition": "Module initializatio n",
"details": "Key Derivation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-256, 24- character password, 288-bit salt, Iteration count: 4096",
"type": "CAS T"
},
{
"algorithmOrTest": "Counter DRBG (A5015)",
"condition": "Module initializatio n",
"details": "Instantiate, Generate, Reseed, Generate (compliant with SP 800- 90Ar1 Section 11.3)",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "AES-128 with prediction resistance",
"type": "CAS T"
},
{
"algorithmOrTest": "HMAC DRBG (A5015)",
"condition": "Module initializatio n",
"details": "Instantiate, Generate, Reseed, Generate (compliant with SP 800- 90Ar1 Section 11.3)",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-1 with prediction resistance",
"type": "CAS T"
},
{
"algorithmOrTest": "Hash DRBG (A5015)",
"condition": "Module initializatio n",
"details": "Instantiate, Generate, Reseed, Generate (compliant with SP 800- 90Ar1 Section 11.3)",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-256 with prediction resistance",
"type": "CAS T"
},
{
"algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 (A5014)",
"condition": "Module initializatio n",
"details": "Shared Secret Computation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "ffdhe2048",
"type": "CAS T"
},
{
"algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A5009)",
"condition": "Module initializatio n",
"details": "Shared Secret Computation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "P-256",
"type": "CAS T"
},
{
"algorithmOrTest": "RSA SigGen (FIPS186- 5) (A5009)",
"condition": "Module initializatio n",
"details": "Signature Generation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "PKCS#1 v1.5 with SHA-256 and 2048- bit key",
"type": "CAS T"
},
{
"algorithmOrTest": "RSA SigVer (FIPS186- 5) (A5009)",
"condition": "Module initializatio n",
"details": "Signature Verification",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "PKCS#1 v1.5 with SHA-256 and 2048- bit key",
"type": "CAS T"
},
{
"algorithmOrTest": "ECDSA SigGen (FIPS186- 5) (A5009)",
"condition": "Module initializatio n",
"details": "Signature Generation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-256 and P-224, P-256, P- 384, and P- 521",
"type": "CAS T"
},
{
"algorithmOrTest": "ECDSA SigVer (FIPS186- 5) (A5009)",
"condition": "Module initializatio n",
"details": "Signature Verification",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-256 and P-224, P-256, P- 384, and P- 521",
"type": "CAS T"
},
{
"algorithmOrTest": "EDDSA SigGen (A5016)",
"condition": "Module initializatio n",
"details": "Signature Generation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "ED25519 and ED448",
"type": "CAS T"
},
{
"algorithmOrTest": "EDDSA SigVer (A5016)",
"condition": "Module initializatio n",
"details": "Signature Verification",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "ED25519 and ED448",
"type": "CAS T"
},
{
"algorithmOrTest": "KTS-IFC (A5018)",
"condition": "Module initializatio n",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-256, no padding",
"type": "CAS T"
}
],
"found": true,
"section": 10,
"subsection": 2
},
"error_states": {
"entries": [
{
"conditions": "Integrity test failure CAST Failure PCT Failure",
"description": "The module immediately stops functioning due to a self-test failure",
"indicator": "Module reboots",
"name": "Error State",
"recoveryMethod": "Reboot and successful completion of self- tests"
}
],
"found": true,
"section": 10,
"subsection": 4
},
"mechanisms_actions": {
"entries": [],
"found": false,
"section": 7,
"subsection": 1
},
"modes_of_operation": {
"entries": [
{
"description": "Automatically entered whenever an approved service is requested",
"name": "Approved mode",
"statusIndicator": "Equivalent to the indicator of the requested service as defined in section 4.3",
"type": "Approved"
},
{
"description": "Automatically entered whenever a non-approved service is requested",
"name": "Non- approved mode",
"statusIndicator": "",
"type": "Non- Approved"
}
],
"found": true,
"section": 2,
"subsection": 4
},
"non_approved_allowed_NSC": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_allowed_algos": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_not_allowed": {
"entries": [
{
"name": "FIPS provider PBKDF with salt length less than 128 bits",
"use": "Key derivation"
},
{
"name": "FIPS provider TLSv1.0 and TLSv1.1 KDF using EMS",
"use": "Key derivation"
},
{
"name": "FIPS provider TLSv1.2 KDF without using EMS",
"use": "Key derivation"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_services": {
"entries": [
{
"alg_accessed": "FIPS provider PBKDF with salt length less than 128 bits",
"description": "Key derivation",
"name": "FIPS provider PBKDF with salt length less than 128 bits",
"role": "CO"
},
{
"alg_accessed": "FIPS provider TLSv1.0 and TLSv1.1 KDF using EMS",
"description": "Key derivation",
"name": "FIPS provider TLSv1.0 and TLSv1.1 KDF using EMS",
"role": "CO"
},
{
"alg_accessed": "FIPS provider TLSv1.2 KDF without using EMS",
"description": "Key derivation",
"name": "FIPS provider TLSv1.2 KDF without using EMS",
"role": "CO"
}
],
"found": true,
"section": 4,
"subsection": 4
},
"ports_interfaces": {
"entries": [
{
"data": "API data input parameters, AF_ALG type sockets (kernel component)",
"logicalInterface": "Data Input",
"physicalPort": "N/A"
},
{
"data": "API output parameters, AF_ALG type sockets (kernel component)",
"logicalInterface": "Data Output",
"physicalPort": "N/A"
},
{
"data": "API function calls, API control input parameters, AF_ALG type sockets (kernel component), kernel command line (kernel component)",
"logicalInterface": "Control Input",
"physicalPort": "N/A"
},
{
"data": "API return values, error queue, AF_ALG type sockets (kernel component), kernel logs (kernel component)",
"logicalInterface": "Status Output",
"physicalPort": "N/A"
},
{
"data": "The hardware on which the module runs receives power from the circuit board on which the hardware resides.",
"logicalInterface": "Power",
"physicalPort": "N/A"
}
],
"found": true,
"section": 3,
"subsection": 1
},
"roles": {
"entries": [
{
"authMethodList": "None",
"name": "Crypto Officer",
"operatorType": "Crypto Officer",
"type": "Role"
}
],
"found": true,
"section": 4,
"subsection": 2
},
"security_levels": {
"entries": [
{
"level": "1",
"section": "1",
"title": "General"
},
{
"level": "1",
"section": "2",
"title": "Cryptographic module specification"
},
{
"level": "1",
"section": "3",
"title": "Cryptographic module interfaces"
},
{
"level": "1",
"section": "4",
"title": "Roles, services, and authentication"
},
{
"level": "1",
"section": "5",
"title": "Software/Firmware security"
},
{
"level": "1",
"section": "6",
"title": "Operational environment"
},
{
"level": "1",
"section": "7",
"title": "Physical security"
},
{
"level": "N/A",
"section": "8",
"title": "Non-invasive security"
},
{
"level": "1",
"section": "9",
"title": "Sensitive security parameter management"
},
{
"level": "1",
"section": "10",
"title": "Self-tests"
},
{
"level": "1",
"section": "11",
"title": "Life-cycle assurance"
},
{
"level": "1",
"section": "12",
"title": "Mitigation of other attacks"
},
{
"level": "1",
"section": "",
"title": "Overall Level"
}
],
"found": true,
"section": 1,
"subsection": 2
},
"self_tests": {
"entries": [
{
"algorithmOrTest": "HMAC- SHA2-256 (A5009)",
"details": "Integrity test for fips.so; Integrity test for kernel binary; Integrity test for fipsheck binary; Integrity test for fipscheck library",
"indicator": "Module becomes operational and services are available for use",
"testMethod": "Message Authentication",
"testProps": "256-bit key",
"type": "SW/FW Integrity"
}
],
"found": true,
"section": 10,
"subsection": 1
},
"ssp_io_methods": {
"entries": [
{
"dest": "Cryptographi c module",
"distribution": "Manual",
"entry": "Electroni c",
"format": "Plaintex t",
"name": "API input parameters",
"sfiAlgo": "",
"source": "Operating calling application (TOEPP)"
},
{
"dest": "Cryptographi c module",
"distribution": "Manual",
"entry": "Electroni c",
"format": "Plaintex t",
"name": "Kernel AF_ALG_typ e sockets (input)",
"sfiAlgo": "",
"source": "Operating calling application (TOEPP)"
},
{
"dest": "Operator calling application (TOEPP)",
"distribution": "Manual",
"entry": "Electroni c",
"format": "Plaintex t",
"name": "API output parameters",
"sfiAlgo": "",
"source": "Cryptographi c module"
},
{
"dest": "Operator calling application (TOEPP)",
"distribution": "Manual",
"entry": "Electroni c",
"format": "Plaintex t",
"name": "Kernel AF_ALG type sockets (output)",
"sfiAlgo": "",
"source": "Cryptographi c module"
}
],
"found": true,
"section": 9,
"subsection": 2
},
"ssp_zeroization_methods": {
"entries": [
{
"description": "Zeroizes the SSPs contained within the cipher handle",
"method": "Kernel free cipher handle",
"operatorId": "By calling the appropriate zeroization functions:- AES key: crypto_free_skcipher and crypto_free_aead; - DRBG Internal state: crypto_free_rng; - EC public",
"rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of"
},
{
"description": "",
"method": "",
"operatorId": "\u0026 private key: crypto_free_kpp and crypto_free_akcipher",
"rationale": "the zeroization routine(s) indicate that the zeroization procedure succeeded"
},
{
"description": "Zeroizes the SSPs",
"method": "FIPS provider calling the zeroization API",
"operatorId": "By calling the appropriate zeroization functions: - EVP_CIPHER_CTX_free(): clears and frees symmetric cipher context; - EVP_MAC_CTX_free(): clears and frees MAC context; - EVP_KDF_CTX_free(): clears and frees KDF context; - EVP_RAND_CTX_free(): clears and frees DRBG context; - EVP_PKEY_free(): clears and frees asymmetric key pair structures",
"rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. All data output is inhibited during zeroization. The completion of the zeroization routine(s) indicate that the zeroization procedure succeeded"
},
{
"description": "Zeroizes the SSPs",
"method": "FIPS provider Automatic",
"operatorId": "Intermediate key generation value: zeroized automatically by the module (after the requested service completed)",
"rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. All data output is inhibited during zeroization."
},
{
"description": "De-allocates the volatile memory used to store SSPs",
"method": "Remove power from the module",
"operatorId": "By removing power",
"rationale": "Volatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded."
}
],
"found": true,
"section": 9,
"subsection": 3
},
"storage_areas": {
"entries": [
{
"description": "Temporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPs.",
"name": "RAM",
"persistance": "Dynamic"
}
],
"found": true,
"section": 9,
"subsection": 1
},
"tested_module_id_hw": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_hw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_sw_fw_hy": {
"entries": [
{
"features": "N/A",
"integrityTest": "HMAC-SHA-256",
"packageFileName": "Image.Izma, fipscheck (application and library), fips.so",
"swFwVersion": "11.0"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"tested_op_env_sw_fw_hy": {
"entries": [
{
"hardwarePlatform": "Laird WB5NBT wireless bridge",
"hypervisorHostOs": "N/A",
"operatingSystem": "Summit Linux 11.0",
"paa_pai": "No",
"processors": "Microchip AT91SAM9G (ARM926EJ-S), ARMv5-based",
"version": "11.0"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"vendor_affirmed_algos": {
"entries": [
{
"algoPropList": "Curves:P-256, P-384 (128, 192 bits)",
"implName": "Summit Linux (ECDH_C)",
"name": "Kernel ECDSA Key Generation",
"reference": "FIPS 186-5, SP 800-133rev2 Section 5.1, 5.2"
},
{
"algoPropList": "Safe Primes:MODP-2048, MODP- 3072, MODP-4096, MODP-6144, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112- 200 bits of key strength",
"implName": "FIPS provider (FFC_DH)",
"name": "FIPS provider Safe Primes Key Generation",
"reference": "FIPS 186-5, SP 800-133rev2 Section 5.1, 5.2"
},
{
"algoPropList": "Curves:ED-25519, ED-448 (128, 224 bits)",
"implName": "FIPS provider (EDDSA_3_2)",
"name": "FIPS provider EDDSA Key Generation",
"reference": "FIPS 186-5, SP 800-133rev2 Section 5.1"
},
{
"algoPropList": "Keys:2048, 3072, 4096 (112, 128, 149 bits)",
"implName": "FIPS provider (SHA_ASM)",
"name": "FIPS provider RSA Key Generation",
"reference": "FIPS 186-5, SP 800-133rev2 Section 5.1, 5.2"
},
{
"algoPropList": "Curves:P-224, P-256, P-384, P- 512 (112, 128, 192, 256 bits)",
"implName": "FIPS provider (SSH_ASM)",
"name": "FIPS provider ECDSA Key Generation",
"reference": "FIPS 186-5, SP 800-133rev2 Section 5.1, 5.2"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"vendor_affirmed_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
}
},
"is_br1_format": true,
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 3
},
"ECDH": {
"ECDH": 10
},
"ECDSA": {
"ECDSA": 51
}
},
"FF": {
"DH": {
"DH": 42,
"DHE": 1,
"Diffie-Hellman": 7
}
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 11
},
"CCM": {
"CCM": 10
},
"CFB": {
"CFB": 1
},
"CTR": {
"CTR": 10
},
"ECB": {
"ECB": 5
},
"GCM": {
"GCM": 32
},
"OFB": {
"OFB": 2
},
"XTS": {
"XTS": 13
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 3
}
},
"crypto_protocol": {
"IKE": {
"IKE": 3
},
"IPsec": {
"IPsec": 4
},
"SSH": {
"SSH": 9
},
"TLS": {
"TLS": {
"TLS": 22,
"TLS 1.0": 6,
"TLS 1.2": 11,
"TLS 1.3": 13,
"TLS v1.2": 5,
"TLS v1.3": 4,
"TLSv1.0": 3,
"TLSv1.1": 3,
"TLSv1.2": 3
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 3
},
"KEX": {
"Key Exchange": 1
},
"MAC": {
"MAC": 33
}
},
"device_model": {},
"ecc_curve": {
"Edwards": {
"Ed448": 7
},
"NIST": {
"P-224": 24,
"P-256": 52,
"P-384": 52,
"P-521": 32
}
},
"eval_facility": {
"atsec": {
"atsec": 3
}
},
"fips_cert_id": {},
"fips_certlike": {
"Certlike": {
"AES-128": 7,
"AES-192": 5,
"AES-256": 5,
"DRBG 440": 1,
"HMAC-SHA-1": 2,
"HMAC-SHA-256": 2,
"PKCS#1": 8,
"SHA-1": 13,
"SHA-224": 1,
"SHA-256": 12,
"SHA-3": 6,
"SHA-512": 1,
"SHA2- 256": 2,
"SHA2- 384": 1,
"SHA2-224": 8,
"SHA2-256": 15,
"SHA2-384": 10,
"SHA2-512": 14,
"SHA3- 256": 1,
"SHA3-224": 7,
"SHA3-256": 9,
"SHA3-384": 7,
"SHA3-512": 7
}
},
"fips_security_level": {
"Level": {
"Level 1": 3
}
},
"hash_function": {
"PBKDF": {
"PBKDF": 7,
"PBKDF2": 5
},
"SHA": {
"SHA1": {
"SHA-1": 13
},
"SHA2": {
"SHA-224": 1,
"SHA-256": 12,
"SHA-512": 1
},
"SHA3": {
"SHA-3": 6,
"SHA3-224": 7,
"SHA3-256": 9,
"SHA3-384": 7,
"SHA3-512": 7
}
}
},
"ic_data_group": {},
"javacard_api_const": {
"curves": {
"ED25519": 3,
"ED448": 3
}
},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 88
},
"RNG": {
"RBG": 2,
"RNG": 1
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-3": 15,
"FIPS 180-4": 8,
"FIPS 186-4": 1,
"FIPS 186-5": 20,
"FIPS 197": 1,
"FIPS 198-1": 12,
"FIPS 202": 7,
"FIPS PUB 140-3": 1,
"FIPS186-5": 26
},
"NIST": {
"SP 800-108": 2,
"SP 800-132": 7,
"SP 800-135": 7,
"SP 800-140B": 1,
"SP 800-185": 2,
"SP 800-38A": 12,
"SP 800-38B": 2,
"SP 800-38C": 2,
"SP 800-38D": 4,
"SP 800-38E": 3,
"SP 800-38F": 3,
"SP 800-52": 1,
"SP 800-56A": 6,
"SP 800-56B": 1,
"SP 800-56C": 3,
"SP 800-90A": 5,
"SP 800-90B": 1
},
"PKCS": {
"PKCS#1": 4
},
"RFC": {
"RFC 3526": 2,
"RFC 4106": 1,
"RFC 5288": 1,
"RFC 7627": 2,
"RFC 7919": 2,
"RFC 8446": 1,
"RFC5288": 1,
"RFC7627": 3,
"RFC8446": 2
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 88,
"AES-": 74,
"AES-128": 7,
"AES-192": 5,
"AES-256": 5
},
"CAST": {
"CAST": 44
}
},
"DES": {
"3DES": {
"TDES": 1
}
},
"constructions": {
"MAC": {
"CMAC": 7,
"HMAC": 55,
"HMAC-SHA-256": 1,
"KMAC": 16
}
}
},
"tee_name": {
"AMD": {
"PSP": 7
},
"IBM": {
"SSC": 23
}
},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"module_algorithms": {
"_type": "Set",
"elements": [
"Safe Primes Key GenerationA5014",
"HMAC DRBGA5015",
"KDA TwoStep SP800-56Cr2A5012",
"AES-CFB128A5004",
"HMAC-SHA2-256A5018",
"AES-CBCA5004",
"RSA SigGen (FIPS186-5)A5018",
"KDF SSHA5019",
"TLS v1.2 KDF RFC7627A5018",
"AES-GMACA5008",
"HMAC-SHA3-384A5020",
"HMAC-SHA2-512A5018",
"RSA SigVer (FIPS186-5)A5018",
"KDF SP800-108A5017",
"EDDSA KeyGenA5016",
"SHA2-512/224A5018",
"HMAC-SHA2-384A5018",
"KDA HKDF Sp800-56Cr1A5013",
"AES-XTS Testing Revision 2.0A5004",
"SHA3-224A5020",
"SHAKE-128A5020",
"SHAKE-256A5020",
"KTS-IFCA5018",
"HMAC-SHA-1A5018",
"TLS v1.3 KDFA5013",
"HMAC-SHA2-512/256A5018",
"KDA OneStep SP800-56Cr2A5012",
"AES-CTRA5004",
"AES-CMACA5004",
"SHA3-256A5020",
"HMAC-SHA2-224A5018",
"Hash DRBGA5015",
"AES-KWPA5004",
"ECDSA SigGen (FIPS186-5)A5020",
"AES-OFBA5004",
"AES-CBC-CS2A5004",
"AES-ECBA5019",
"EDDSA SigGenA5016",
"AES-CBC-CS3A5004",
"HMAC-SHA3-256A5020",
"KMAC-128A5020",
"KMAC-256A5020",
"AES-CFB8A5004",
"HMAC-SHA2-512/224A5018",
"SHA3-512A5020",
"SHA-1A5018",
"PBKDFA5020",
"SHA2-224A5018",
"ECDSA SigVer (FIPS186-5)A5020",
"AES-CFB1A5004",
"KAS-IFC-SSCA5018",
"AES-GCMA5008",
"RSA KeyGen (FIPS186-5)A5018",
"SHA2-512A5018",
"AES-CCMA5004",
"KAS-ECC-SSC Sp800-56Ar3A5018",
"KDF ANS 9.42A5020",
"HMAC-SHA3-512A5020",
"ECDSA KeyVer (FIPS186-5)A5018",
"SHA2-512/256A5018",
"SHA2-384A5018",
"AES-KWA5004",
"EDDSA SigVerA5016",
"KDF ANS 9.63A5018",
"AES-CBC-CS1A5004",
"Counter DRBGA5015",
"KDF TLSA5018",
"KDF KMAC Sp800-108r1A5017",
"ECDSA KeyGen (FIPS186-5)A5018",
"HMAC-SHA3-224A5020",
"Safe Primes Key VerificationA5014",
"SHA3-384A5020",
"SHA2-256A5018",
"KAS-FFC-SSC Sp800-56Ar3A5014"
]
},
"policy_algorithms": {
"_type": "Set",
"elements": [
"#A5002",
"#A4713",
"#A5019",
"#A5010",
"#A5008",
"#A5020",
"#A5013",
"#A5005",
"#A5009",
"#A5014",
"#A5004",
"#A4711",
"#A4715",
"#A5011",
"#A5018",
"#A4714",
"#A5006",
"#A5015",
"#A5007",
"#A5017",
"#A5016",
"#A4712",
"#A4718",
"#A4716",
"#A5003",
"#A5012",
"#A4717"
]
},
"policy_metadata": {
"/Author": "",
"/Comments": "",
"/Company": "",
"/CreationDate": "D:20250520122750-04\u002700\u0027",
"/Creator": "Acrobat PDFMaker 25 for Word",
"/Keywords": "",
"/ModDate": "D:20250520123050-04\u002700\u0027",
"/Producer": "Adobe PDF Library 25.1.208",
"/SourceModified": "",
"/Subject": "",
"/Title": "",
"pdf_file_size_bytes": 1012824,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf",
"https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf",
"https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf",
"https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig-announcements",
"https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf",
"https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf",
"https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf",
"https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf",
"https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
"https://www.ietf.org/rfc/rfc7919.txt",
"https://www.ietf.org/rfc/rfc8446.txt",
"https://www.ietf.org/rfc/rfc3447.txt",
"https://www.ietf.org/rfc/rfc5288.txt",
"http://www.atsec.com/",
"https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf",
"https://webstore.ansi.org/standards/ascx9/ansix9422001",
"https://webstore.ansi.org/standards/ascx9/ansix9632001",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf",
"https://www.ietf.org/rfc/rfc3526.txt",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf",
"https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a-add.pdf",
"https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf",
"https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf",
"https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 90
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "76b4a83253a11515529b532285c84d424b4b2e83bb1e1dd69850adac26dc3e22",
"source_hash": "edae5d48f7d9b7d0ad51b94ff10c25f720547328d0ef263c066f5c05cb5209cb",
"txt_hash": "6d4ac22d1ab78da9aa25e3c7b6a5be8fbcde863efc67efc0860a3dab5499bd25"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2025_181225_1202.pdf",
"date_sunset": "2030-08-17",
"description": "The Summit FIPS Core Crypto Module is defined as a Firmware, Multi-chip Standalone module running on Laird\u0027s wireless bridge.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Non-invasive security: N/A"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 1,
"mentioned_certs": {},
"module_name": "Summit Linux FIPS Core Crypto Module",
"module_type": "Firmware",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-3",
"status": "active",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2025-08-18",
"lab": "atsec information security corporation",
"validation_type": "Initial"
}
],
"vendor": "Ezurio",
"vendor_url": "https://www.ezurio.com/wireless-modules/wifi-modules-bluetooth/wb45nbt-bluetooth-and-wifi-module"
}
}