This page was not yet optimized for use on mobile devices.
Lightware Crypto Core
Certificate details
| Certificate ID | #5208 |
|---|---|
| Status | active |
| Validation dates | 26.03.2026 |
| Sunset date | 26-08-2029 |
| Standard | FIPS 140-3 |
| Security level | 1 |
| Type | Software |
| Embodiment | MultiChipStand |
| Caveat | No assurance of the minimum strength of generated SSPs (e.g., keys) and random strings. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs |
| Exceptions |
|
| Description | Lightware Crypto Core is a standards-based cryptographic engine for embedded Linux systems. The module delivers core cryptographic functions to the embedded systems of Taurus product family's hardware devices and features robust algorithm support. Lightware Crypto Core offloads functions for secure key management, data integrity, data at rest encryption, and secure communications to a trusted implementation. |
| Vendor | Lightware Visual Engineering Plc. https://www.lightware.com |
| Lab | DEKRA Cybersecurity Certification Laboratory |
| Algorithms |
|
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, Triple-DES, TDES, HMAC, HMAC-SHA-256, KMAC, CMACAsymmetric Algorithms
ECDH, ECDSA, EdDSA, ECC, DHE, Diffie-Hellman, DH, DSAHash functions
SHA-1, SHA-512, SHA-256, SHA-224, SHA-2, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHA-3, SHA3, SHAKE256, PBKDFSchemes
MAC, Key AgreementProtocols
SSH, SSHv2, TLS 1.2, TLS v1.2, TLS v1.3, TLS 1.3Randomness
DRBG, RNG, RBGLibraries
OpenSSLElliptic Curves
P-256, P-384, P-521, P-192, P-224, B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, B-163, K-163, brainpoolP224r1, brainpoolP256r1, brainpoolP320r1, brainpoolP384r1, brainpoolP512r1, Ed25519, Ed448Block cipher modes
CBC, GCM, XTSTrusted Execution Environments
PSPSecurity level
Level 1Side-channel analysis
side-channel, timing attacks, timing attackStandards
FIPS 140-3, FIPS 140, FIPS186-4, FIPS 186-4, FIPS 186-5, FIPS 198-1, FIPS 180-4, FIPS 202, FIPS 1865, SP 800-38A, SP 800-38C, SP 800-38B, SP 800-38D, SP 800-38F, SP 800-38E, SP 800-90A, SP 800-56A, SP 800-56C, SP 800-135, SP 800-108, SP 800-185, SP 800-56B, SP 800-132, SP 800-67, SP 800-186, NIST SP 800-38D, PKCS 1, PKCS#1, RFC7627, RFC 5288, RFC 5246, RFC 8446, RFC 7627Automated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
No references are available for this certificate.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 5208,
"dgst": "b343addd7aa6b85a",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"SHA2-384A5173",
"KMAC-256A5173",
"SHA2-512/224A5173",
"#A4593",
"TDES-ECBA5173",
"HMAC-SHA3-512A5173",
"KDF SP800-108A5173",
"AES-GCMA5173",
"KDF ANS 9.42A5173",
"#A5173",
"HMAC-SHA2-512A5173",
"ECDSA SigVer (FIPS186-4)A5173",
"RSA SigGen (FIPS186-4)A5173",
"KDA HKDF SP800-56Cr2A5173",
"AES-CFB8A5173",
"AES-CFB1A5173",
"AES-CBC-CS1A5173",
"Hash DRBGA5173",
"AES-CMACA5173",
"SHA-1A5173",
"EDDSA KeyGenA5173",
"PBKDFA5173",
"KDF SSHA5173",
"SHA2-224A5173",
"SHA3-224A5173",
"ECDSA KeyVer (FIPS186-4)A5173",
"DSA PQGVer (FIPS186-4)A5173",
"HMAC-SHA2-224A5173",
"Safe Primes Key GenerationA5173",
"AES-OFBA5173",
"AES-CBC-CS2A5173",
"DSA PQGGen (FIPS186-4)A5173",
"TLS v1.2 KDF RFC7627A5173",
"AES-CCMA5173",
"Counter DRBGA5173",
"RSA KeyGen (FIPS186-4)A5173",
"TLS v1.3 KDFA5173",
"AES-CFB128A5173",
"KAS-IFC-SSCA5173",
"AES-CBC-CS3A5173",
"AES-CBCA5173",
"AES-XTS Testing Revision 2.0A5173",
"SHA2-512A5173",
"HMAC-SHA-1A5173",
"SHA3-512A5173",
"DSA SigVer (FIPS186-4)A5173",
"EDDSA KeyVerA5173",
"ECDSA KeyGen (FIPS186-4)A5173",
"AES-GMACA5173",
"SHAKE-128A5173",
"KTS-IFCA5173",
"HMAC-SHA2-512/224A5173",
"EDDSA SigGenA5173",
"HMAC-SHA2-384A5173",
"HMAC-SHA3-256A5173",
"HMAC-SHA2-512/256A5173",
"RSA SigVer (FIPS186-4)A5173",
"SHA3-384A5173",
"KMAC-128A5173",
"HMAC DRBGA5173",
"EDDSA SigVerA5173",
"SHA2-256A5173",
"SHA2-512/256A5173",
"HMAC-SHA3-224A5173",
"KDF KMAC Sp800-108r1A5173",
"SHAKE-256A5173",
"Safe Primes Key VerificationA5173",
"AES-KWA5173",
"AES-KWPA5173",
"KAS-ECC-SSC Sp800-56Ar3A5173",
"KDA TwoStep SP800-56Cr2A5173",
"KDF ANS 9.63A5173",
"TDES-CBCA5173",
"AES-CTRA5173",
"KDA OneStep SP800-56Cr2A5173",
"DSA KeyGen (FIPS186-4)A5173",
"AES-ECBA5173",
"ECDSA SigGen (FIPS186-4)A5173",
"HMAC-SHA2-256A5173",
"KAS-FFC-SSC Sp800-56Ar3A5173",
"HMAC-SHA3-384A5173",
"SHA3-256A5173"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"br1_deviations": 0,
"br1_tables": {
"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
"approved_algorithms": {
"entries": [
{
"algorithm": "AES-CBC",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS1",
"cavpCertName": "A4593",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS1",
"cavpCertName": "A5173",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS2",
"cavpCertName": "A4593",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS2",
"cavpCertName": "A5173",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS3",
"cavpCertName": "A4593",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS3",
"cavpCertName": "A5173",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CCM",
"cavpCertName": "A4593",
"properties": "Key Length - 128, 192, 256",
"reference": "SP 800-38C"
},
{
"algorithm": "AES-CCM",
"cavpCertName": "A5173",
"properties": "Key Length - 128, 192, 256",
"reference": "SP 800-38C"
},
{
"algorithm": "AES-CFB1",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CFB1",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CFB128",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CFB128",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CFB8",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CFB8",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CMAC",
"cavpCertName": "A4593",
"properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
"reference": "SP 800-38B"
},
{
"algorithm": "AES-CMAC",
"cavpCertName": "A5173",
"properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
"reference": "SP 800-38B"
},
{
"algorithm": "AES-CTR",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CTR",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-ECB",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-ECB",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-GCM",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-GCM",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-GMAC",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-GMAC",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-KW",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38F"
},
{
"algorithm": "AES-KW",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38F"
},
{
"algorithm": "AES-KWP",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38F"
},
{
"algorithm": "AES-KWP",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38F"
},
{
"algorithm": "AES-OFB",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-OFB",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-XTS Testing Revision 2.0",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
"reference": "SP 800-38E"
},
{
"algorithm": "AES-XTS Testing Revision 2.0",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
"reference": "SP 800-38E"
},
{
"algorithm": "Counter DRBG",
"cavpCertName": "A4593",
"properties": "Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "Counter DRBG",
"cavpCertName": "A5173",
"properties": "Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "DSA KeyGen (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "L - 2048 N - 224, 256",
"reference": "FIPS 186-4"
},
{
"algorithm": "DSA KeyGen (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "L - 2048 N - 224, 256",
"reference": "FIPS 186-4"
},
{
"algorithm": "DSA PQGGen (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "L - 2048 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
"reference": "FIPS 186-4"
},
{
"algorithm": "DSA PQGGen (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "L - 2048 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
"reference": "FIPS 186-4"
},
{
"algorithm": "DSA PQGVer (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "L - 1024, 2048 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256",
"reference": "FIPS 186-4"
},
{
"algorithm": "DSA PQGVer (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "L - 1024, 2048 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256",
"reference": "FIPS 186-4"
},
{
"algorithm": "DSA SigVer (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "L - 1024, 2048, 3072 N - 160, 224, 256",
"reference": "FIPS 186-4"
},
{
"algorithm": "",
"cavpCertName": "",
"properties": "Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256",
"reference": ""
},
{
"algorithm": "DSA SigVer (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA KeyGen (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA KeyGen (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA KeyVer (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K- 409, K-571, P-192, P-224, P-256, P-384, P-521",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA KeyVer (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K- 409, K-571, P-192, P-224, P-256, P-384, P-521",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigGen (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "Component - No Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigGen (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "Component - No Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigVer (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "Component - No Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K- 409, K-571, P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigVer (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "Component - No Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K- 409, K-571, P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512",
"reference": "FIPS 186-4"
},
{
"algorithm": "EDDSA KeyGen",
"cavpCertName": "A4593",
"properties": "Curve - ED-25519, ED-448",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA KeyGen",
"cavpCertName": "A5173",
"properties": "Curve - ED-25519, ED-448",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA KeyVer",
"cavpCertName": "A4593",
"properties": "Curve - ED-25519, ED-448",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA KeyVer",
"cavpCertName": "A5173",
"properties": "Curve - ED-25519, ED-448",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA SigGen",
"cavpCertName": "A4593",
"properties": "Curve - ED-25519, ED-448 PreHash - Yes",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA SigGen",
"cavpCertName": "A5173",
"properties": "Curve - ED-25519, ED-448 PreHash - Yes",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA SigVer",
"cavpCertName": "A4593",
"properties": "Curve - ED-25519, ED-448 PreHash - No Pure - Yes",
"reference": "FIPS 186-5"
},
{
"algorithm": "EDDSA SigVer",
"cavpCertName": "A5173",
"properties": "Curve - ED-25519, ED-448 PreHash - No Pure - Yes",
"reference": "FIPS 186-5"
},
{
"algorithm": "Hash DRBG",
"cavpCertName": "A4593",
"properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-256, SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "Hash DRBG",
"cavpCertName": "A5173",
"properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-256, SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC DRBG",
"cavpCertName": "A4593",
"properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-256, SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC DRBG",
"cavpCertName": "A5173",
"properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-256, SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC-SHA-1",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA-1",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 224",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 224",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 256",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 256",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 384",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 384",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512/224",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512/224",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512/256",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512/256",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 224",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 224",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 256",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 256",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 384",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 384",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 512",
"cavpCertName": "A4593",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 512",
"cavpCertName": "A5173",
"properties": "Key Length - Key Length: 8-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "KAS-ECC-SSC Sp800-56Ar3",
"cavpCertName": "A4593",
"properties": "Domain Parameter Generation Methods - B-233, B-283, B-409, B- 571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-ECC-SSC Sp800-56Ar3",
"cavpCertName": "A5173",
"properties": "Domain Parameter Generation Methods - B-233, B-283, B-409, B- 571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-FFC-SSC Sp800-56Ar3",
"cavpCertName": "A4593",
"properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-FFC-SSC Sp800-56Ar3",
"cavpCertName": "A5173",
"properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-IFC-SSC",
"cavpCertName": "A4593",
"properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1- prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme -",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "",
"cavpCertName": "",
"properties": "KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder",
"reference": ""
},
{
"algorithm": "KAS-IFC-SSC",
"cavpCertName": "A5173",
"properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1- prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KDA HKDF SP800-56Cr2",
"cavpCertName": "A4593",
"properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDA HKDF SP800-56Cr2",
"cavpCertName": "A5173",
"properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDA OneStep SP800-56Cr2",
"cavpCertName": "A4593",
"properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDA OneStep SP800-56Cr2",
"cavpCertName": "A5173",
"properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDA TwoStep SP800-56Cr2",
"cavpCertName": "A4593",
"properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDA TwoStep SP800-56Cr2",
"cavpCertName": "A5173",
"properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "",
"cavpCertName": "",
"properties": "Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
"reference": ""
},
{
"algorithm": "KDF ANS 9.42 (CVL)",
"cavpCertName": "A4593",
"properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF ANS 9.42 (CVL)",
"cavpCertName": "A5173",
"properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF ANS 9.63 (CVL)",
"cavpCertName": "A4593",
"properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Key Data Length - Key Data Length: 128, 4096",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF ANS 9.63 (CVL)",
"cavpCertName": "A5173",
"properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Key Data Length - Key Data Length: 128, 4096",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF KMAC Sp800-108r1",
"cavpCertName": "A4593",
"properties": "Derived Key Length - Derived Key Length: 112-4096 Increment 8",
"reference": "SP 800-108 Rev. 1"
},
{
"algorithm": "KDF KMAC Sp800-108r1",
"cavpCertName": "A5173",
"properties": "Derived Key Length - Derived Key Length: 112-4096 Increment 8",
"reference": "SP 800-108 Rev. 1"
},
{
"algorithm": "KDF SP800-108",
"cavpCertName": "A4593",
"properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096",
"reference": "SP 800-108 Rev. 1"
},
{
"algorithm": "KDF SP800-108",
"cavpCertName": "A5173",
"properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096",
"reference": "SP 800-108 Rev. 1"
},
{
"algorithm": "KDF SSH (CVL)",
"cavpCertName": "A4593",
"properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF SSH (CVL)",
"cavpCertName": "A5173",
"properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KMAC-128",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
"reference": "SP 800-185"
},
{
"algorithm": "KMAC-128",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
"reference": "SP 800-185"
},
{
"algorithm": "KMAC-256",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
"reference": "SP 800-185"
},
{
"algorithm": "KMAC-256",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
"reference": "SP 800-185"
},
{
"algorithm": "KTS-IFC",
"cavpCertName": "A4593",
"properties": "Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1- prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024",
"reference": "SP 800-56B Rev. 2"
},
{
"algorithm": "KTS-IFC",
"cavpCertName": "A5173",
"properties": "Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1- prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024",
"reference": "SP 800-56B Rev. 2"
},
{
"algorithm": "PBKDF",
"cavpCertName": "A4593",
"properties": "Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8",
"reference": "SP 800-132"
},
{
"algorithm": "PBKDF",
"cavpCertName": "A5173",
"properties": "Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8",
"reference": "SP 800-132"
},
{
"algorithm": "RSA KeyGen (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - Standard",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA KeyGen (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - Standard",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigGen (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigGen (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigVer (FIPS186-4)",
"cavpCertName": "A4593",
"properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigVer (FIPS186-4)",
"cavpCertName": "A5173",
"properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "Safe Primes Key Generation",
"cavpCertName": "A4593",
"properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "Safe Primes Key Generation",
"cavpCertName": "A5173",
"properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "Safe Primes Key Verification",
"cavpCertName": "A4593",
"properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "Safe Primes Key Verification",
"cavpCertName": "A5173",
"properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "SHA-1",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA-1",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-224",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-224",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-384",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-384",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512/224",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512/224",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512/256",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512/256",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA3-224",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-224",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-256",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-256",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-384",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-384",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-512",
"cavpCertName": "A4593",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-512",
"cavpCertName": "A5173",
"properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 202"
},
{
"algorithm": "SHAKE-128",
"cavpCertName": "A4593",
"properties": "Output Length - Output Length: 16-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHAKE-128",
"cavpCertName": "A5173",
"properties": "Output Length - Output Length: 16-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHAKE-256",
"cavpCertName": "A4593",
"properties": "Output Length - Output Length: 16-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHAKE-256",
"cavpCertName": "A5173",
"properties": "Output Length - Output Length: 16-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "TDES-CBC",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt",
"reference": "SP 800-67 Rev. 2"
},
{
"algorithm": "TDES-CBC",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt",
"reference": "SP 800-67 Rev. 2"
},
{
"algorithm": "TDES-ECB",
"cavpCertName": "A4593",
"properties": "Direction - Decrypt",
"reference": "SP 800-67 Rev. 2"
},
{
"algorithm": "TDES-ECB",
"cavpCertName": "A5173",
"properties": "Direction - Decrypt",
"reference": "SP 800-67 Rev. 2"
},
{
"algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
"cavpCertName": "A4593",
"properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
"cavpCertName": "A5173",
"properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "TLS v1.3 KDF (CVL)",
"cavpCertName": "A4593",
"properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "TLS v1.3 KDF (CVL)",
"cavpCertName": "A5173",
"properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
"reference": "SP 800-135 Rev. 1"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"approved_services": {
"entries": [
{
"description": "Initialize the FIPS module when it is loaded",
"indicator": "API return value from OSSL_provider_init: 1 for success, 0 for failure",
"inputs": "External dispatch (functio n",
"name": "Module Initialisat ion",
"outputs": "Internal dispatch (function pointer) table",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "(calls pre- operatio nal self- tests and CASTs).",
"indicator": "",
"inputs": "pointer) table",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": ""
},
{
"description": "Performs pre- operatio nal self- tests and CASTs on demand.",
"indicator": "API return value code from SELF_TEST_post(): 1 for success, 0 for failure",
"inputs": "None",
"name": "Self-Test",
"outputs": "Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNN ING)",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "Performs the integrity test on demand.",
"indicator": "API return value from verify_integrity(): 1 for verified, 0 for failure",
"inputs": "Expecte d HMAC",
"name": "Integrity Test",
"outputs": "Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNN ING)",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "IntegrityTest"
},
{
"description": "Provides status informati on by querying the \"status\" paramet er.",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for query operation completed successfully, 0 for failure to query the parameter",
"inputs": "None",
"name": "Show Status",
"outputs": "Module Status: Running (FIPS_STATE_RUNN ING), or Error (FIPS_STATE_ERRO R)",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "Displays FIPS module version by querying the \"version, \" \"name,\" and",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for query operation completed successfully, 0 for failure to query the parameter",
"inputs": "None",
"name": "Output ID/ Version Informat ion (Show Version)",
"outputs": "name: 140-3 FIPS Provider version: 3.0.0-FIPS 140-3 or 3.0.1-FIPS 140-3 buildinfo: 3.0.0-FIPS 140-3 or 3.0.1-FIPS 140-3",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "o\" paramet ers, with the results specified in the output column. The version aligns with the FIPS certificat e and Security Policy Section 2.2 - Tested and Vendor Affirmed Module Version and Identific",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": ""
},
{
"description": "Used to seed/res eed a DRBG instance (includin g determin ing the security strength) or obtain random",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "Desired security strength in bits, entropy input",
"name": "Random Number Generati on",
"outputs": "Random data",
"rolesSspAccess": "Crypto Officer - DRBG Entropy Input: W,E,Z - CTR_DR BG Seed: G,E,Z - CTR_DR",
"secFunImpl": "RNG CKG"
},
{
"description": "data. Random data may be used for CKG per SP 800- 133r2. Establish ed SSPs are passed out to the calling applicati on.",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "BG V: G,E,Z - CTR_DR BG Key: G,E,Z - Hash_D RBG Seed: G,E,Z - Hash_D RBG V: G,E,Z - Hash_D RBG C: G,E,Z - HMAC_ DRBG Seed: G,E,Z - HMAC_ DRBG V: G,E,Z - HMAC_ DRBG Key: G,E,Z - Generic Secret: G,R,Z",
"secFunImpl": ""
},
{
"description": "Used to encrypt or decrypt data.",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for",
"inputs": "AES EDK, AES XTS key, IV, cipherte",
"name": "Symmetr ic Encrypti on/",
"outputs": "Ciphertext data or plaintext data",
"rolesSspAccess": "Crypto Officer - AES EDK: W,E,Z",
"secFunImpl": "Symmetric Encrypt/Dec rypt CKG (XTS)"
},
{
"description": "SSPs are passed in by the calling applicati on.",
"indicator": "operation completed successfully, 0 for failure",
"inputs": "xt data, plaintex t data",
"name": "Decrypti on",
"outputs": "",
"rolesSspAccess": "- AES XTS key: W,E,Z",
"secFunImpl": ""
},
{
"description": "Used to encrypt or decrypt data or keys. SSPs are passed in by the calling applicati on. Any establish ed SSPs are passed out to the calling applicati on.",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "AES CMAC/C CM key, AES GMAC/ GCM key, cipherte xt data, plaintex t data",
"name": "Authenti cated Symmetr ic Encrypti on/ Decrypti on",
"outputs": "Ciphertext data or plaintext data",
"rolesSspAccess": "Crypto Officer - AES CMAC/C CM key: W,E,Z - AES GMAC/ GCM key: W,E,Z - AES GMAC/ GCM IV: G,E,Z",
"secFunImpl": "AuthSymme tric Encrypt/Dec rypt"
},
{
"description": "Used to generate or verify data integrity with CMAC or GMAC. SSPs are passed in by the calling applicati",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "Digest or message , AES CMAC/C CM key, AES GMAC/ GCM key",
"name": "Symmetr ic Digest",
"outputs": "Digest or verification result",
"rolesSspAccess": "Crypto Officer - AES CMAC/C CM key: W,E,Z - AES GMAC/ GCM key: W,E,Z - AES GMAC/",
"secFunImpl": "SymmetricDi gest"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "GCM IV: G,E,Z",
"secFunImpl": ""
},
{
"description": "Used to generate asymmet ric keys using the DRBG. Establish ed SSPs are passed out to the calling applicati on.",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "Desired security strength in bits, entropy input, predicti on resistan ce, paramet ers and values for FFC, ECC, RSA key generati on",
"name": "Asymme tric Key Generati on",
"outputs": "ECDSA SGK, ECDSA SVK, RSA SGK, RSA SVK, EdDSA SGK, EdDSA SVK, DH Private, DH Public, ECDH Private, ECDH Public, RSA KAK Private, RSA KAK Public, RSA KDK Private, RSA KEK Public",
"rolesSspAccess": "Crypto Officer - DRBG Entropy Input: W,E,Z - CTR_DR BG Seed: G,E,Z - CTR_DR BG V: G,E,Z - CTR_DR BG Key: G,E,Z - Hash_D RBG Seed: G,E,Z - Hash_D RBG V: G,E,Z - Hash_D RBG C: G,E,Z - HMAC_ DRBG Seed: G,E,Z - HMAC_ DRBG V:",
"secFunImpl": "Asymmetric KeyGen"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "G,E,Z - HMAC_ DRBG Key: G,E,Z - ECDSA SGK: G,R,Z - ECDSA SVK: G,R,Z - RSA SGK: G,R,Z - RSA SVK: G,R,Z - EdDSA SGK: G,R,Z - EdDSA SVK: G,R,Z - DH Private: G,R,Z - DH Public: G,R,Z - EC DH Private: G,R,Z - EC DH Public: G,R,Z - RSA KAK Private: G,R,Z - RSA KAK Public:",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "G,R,Z - RSA KDK Private: G,R,Z - RSA KEK Public: G,R,Z",
"secFunImpl": ""
},
{
"description": "Used to generate or verify digital signatur es. SSPs are passed in by the calling applicati on.",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "DSA SVK, ECDSA SGK, ECDSA SVK, RSA SGK, RSA SVK, EdDSA SGK, EdDSA SVK",
"name": "Digital Signatur es",
"outputs": "Digital signature or verification result",
"rolesSspAccess": "Crypto Officer - ECDSA SGK: W,E,Z - ECDSA SVK: W,E,Z - RSA SGK: W,E,Z - RSA SVK: W,E,Z - EdDSA SGK: W,E,Z - EdDSA SVK: W,E,Z",
"secFunImpl": "DigitalSig"
},
{
"description": "Used to generate or verify data integrity. SSPs are passed in by the calling applicati on.",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "HMAC key, KMAC key",
"name": "Keyed Hash",
"outputs": "Keyed hash or verification result",
"rolesSspAccess": "Crypto Officer - HMAC Key: W,E,Z - KMAC Key: W,E,Z",
"secFunImpl": "KeyedHash"
},
{
"description": "Used to generate a SHA-1, SHA-2, SHA-3, or SHAKE message digest.",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "Messag e data",
"name": "Message Digest",
"outputs": "Digest",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "MessageDig est"
},
{
"description": "Used to perform key agreeme nt primitive s on behalf of the calling applicati on (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "DH Private, DH Public, ECDH Private, ECDH Public",
"name": "Key Agreeme nt (ECC/FFC )",
"outputs": "DH Private, DH Public, ECDH Private, ECDH Public, KDF secret",
"rolesSspAccess": "Crypto Officer - DH Private: R,W,E,Z - DH Public: R,W,E,Z - EC DH Private: R,W,E,Z - EC DH Public: R,W,E,Z - KDF Secret: G,R,Z",
"secFunImpl": "KeyAgreeme nt (ECC) KeyAgreeme nt (FFC)"
},
{
"description": "Used to perform key agreeme nt primitive s on behalf of the calling applicati on (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "RSA KAK Private, RSA KAK Public",
"name": "Key Agreeme nt (RSA)",
"outputs": "RSA KAK Private, RSA KAK Public, KDF secret",
"rolesSspAccess": "Crypto Officer - RSA KAK Private: R,W,E,Z - RSA KAK Public: R,W,E,Z - KDF Secret: G,R,Z",
"secFunImpl": "KeyAgreeme nt (RSA)"
},
{
"description": "Used to derive keys using KBKDF, PBKDF, HKDF, SP 800- 56Cr2 One-",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "KDF secret, salt, iteration count, MAC, digest, cipher, key",
"name": "Key Derivatio n",
"outputs": "Generic Secret",
"rolesSspAccess": "Crypto Officer - KDF Secret: W,E,Z - Generic Secret: G,R,Z",
"secFunImpl": "KeyDerivatio n"
},
{
"description": "Step KDF (KDA), SP 800- 56Cr2 Two- Step KDF (KDA), ANSI X9.42- 2001 KDF, ANSI X9.63- 2001 KDF, SSHv2 KDF, TLS 1.2 KDF, TLS 1.3 KDF (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": ""
},
{
"description": "Used to encrypt or decrypt a key value on behalf of the calling applicati on (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "RSA KEK Public and key to be encapsu lated (Generic Secret), or RSA KDK Private and encapsu lated key (Generic Secret)",
"name": "Key Transpor t",
"outputs": "Encapsulated key (Generic Secret), or unencapsulated key (Generic Secret)",
"rolesSspAccess": "Crypto Officer - RSA KDK Private: W,E,Z - RSA KEK Public: W,E,Z - Generic Secret: R,W,Z",
"secFunImpl": "KeyTranspor t"
},
{
"description": "Used to encrypt or decrypt a key value on behalf of the calling applicati on (does",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "AES key wrappin g key, key to be wrappe d or unwrap ped",
"name": "Key Wrappin g",
"outputs": "Wrapped key or unwrapped key (Generic Secret)",
"rolesSspAccess": "Crypto Officer - AES key wrappin g key: W,E,Z - Generic",
"secFunImpl": "KeyWrappin g"
},
{
"description": "not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.",
"indicator": "",
"inputs": "(Generic Secret)",
"name": "",
"outputs": "",
"rolesSspAccess": "Secret: R,W,Z",
"secFunImpl": ""
},
{
"description": "All services automati cally overwrit e SSPs stored in allocated memory (zeroise). The module does not store any SSP persisten tly (beyond the lifetime of an API call),",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "Memory to be cleanse d (pointer and length)",
"name": "Zeroise",
"outputs": "The completion of a zeroisation routine indicates that the zeroisation procedure succeeded. Zeroisation can be confirmed via EVP_RAND_verify_z eroization: 1 for success (i.e. the DRBG CSPs have been zeroised), 0 for failure.",
"rolesSspAccess": "Crypto Officer - DRBG Entropy Input: Z - CTR_DR BG Seed: Z - CTR_DR BG V: Z - CTR_DR BG Key: Z - Hash_D RBG Seed: Z - Hash_D",
"secFunImpl": "None"
},
{
"description": "except for DRBG state values (stored for the lifetime of the DRBG instance) . Stack cleanup is the responsi bility of the calling applicati on.",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "RBG V: Z - Hash_D RBG C: Z - HMAC_ DRBG Seed: Z - HMAC_ DRBG V: Z - HMAC_ DRBG Key: Z",
"secFunImpl": ""
},
{
"description": "Miscella neous helper function s.",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "None",
"name": "Utility",
"outputs": "None",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "Used to decrypt data. SSPs are passed in by the calling",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "TDES DK, cipherte xt data",
"name": "Symmetr ic Decrypti on (Legacy)",
"outputs": "Plaintext data",
"rolesSspAccess": "Crypto Officer - TDES DK: W,E,Z",
"secFunImpl": "Symmetric Decrypt (Legacy)"
},
{
"description": "Used to verify digital signatur es. SSPs are passed",
"indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true API return value: 1 for operation completed successfully, 0 for failure",
"inputs": "DSA SVK, ECDSA SVK (Legacy) , RSA",
"name": "Digital Signatur es (Legacy)",
"outputs": "Verification result",
"rolesSspAccess": "Crypto Officer - DSA SVK: W,E,Z - ECDSA SVK",
"secFunImpl": "DigitalSig (Legacy)"
},
{
"description": "Descripti on",
"indicator": "Inputs",
"inputs": "Outputs",
"name": "Name",
"outputs": "Security Functions",
"rolesSspAccess": "",
"secFunImpl": "SSP Access"
},
{
"description": "in by the calling applicati on.",
"indicator": "SVK (Legacy)",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": "(Legacy) : W,E,Z - RSA SVK (Legacy) : W,E,Z"
}
],
"found": true,
"section": 4,
"subsection": 3
},
"authentication_methods": {
"entries": [],
"found": false,
"section": 4,
"subsection": 1
},
"cond_self_tests": {
"entries": [
{
"algorithmOrTest": "AES-GCM Authenticate d Encrypt KAT (Forward Cipher) (A4593)",
"condition": "Initialisation",
"details": "Authenticate d Encrypt (forward cipher)",
"indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)",
"testMethod": "KAT",
"testProps": "256-bit AES",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM Authenticate d Encrypt KAT (Forward Cipher) (A5173)",
"condition": "Initialisation",
"details": "Authenticate d Encrypt (forward cipher)",
"indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)",
"testMethod": "KAT",
"testProps": "256-bit AES",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM Decrypt KAT (Forward Cipher) (A4593)",
"condition": "Initialisation",
"details": "Decrypt (forward cipher)",
"indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)",
"testMethod": "KAT",
"testProps": "256-bit AES",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM Decrypt KAT (Forward Cipher) (A5173)",
"condition": "Initialisation",
"details": "Decrypt (forward cipher)",
"indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)",
"testMethod": "KAT",
"testProps": "256-bit AES",
"type": "CAST"
},
{
"algorithmOrTest": "AES-ECB Decrypt KAT (Inverse Cipher) (A4593)",
"condition": "Initialisation",
"details": "Decrypt (inverse cipher)",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "256-bit AES",
"type": "CAST"
},
{
"algorithmOrTest": "AES-ECB Decrypt KAT (Inverse Cipher) (A5173)",
"condition": "Initialisation",
"details": "Decrypt (inverse cipher)",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "256-bit AES",
"type": "CAST"
},
{
"algorithmOrTest": "Counter DRBG (A4593)",
"condition": "Initialisation",
"details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "128-bit AES with df",
"type": "CAST"
},
{
"algorithmOrTest": "Counter DRBG (A5173)",
"condition": "Initialisation",
"details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "128-bit AES with df",
"type": "CAST"
},
{
"algorithmOrTest": "Hash DRBG (A4593)",
"condition": "Initialisation",
"details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "Hash DRBG (A5173)",
"condition": "Initialisation",
"details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC DRBG (A4593)",
"condition": "Initialisation",
"details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "HMAC-SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC DRBG (A5173)",
"condition": "Initialisation",
"details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "HMAC-SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "KDF ANS 9.42 (A4593)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "KDF ANS 9.42 (A5173)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "KDF ANS 9.63 (A4593)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "KDF ANS 9.63 (A5173)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "KDF SSH (A4593)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "KDF SSH (A5173)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "TLS v1.2 KDF RFC7627 (A4593)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "HMAC-SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5173)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "HMAC-SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "TLS v1.3 KDF (A4593)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "TLS v1.3 KDF (A5173)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "DSA Verify (A4593)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048, SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "DSA Verify (A5173)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048, SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Sign KAT for Prime Curves (A4593)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "P-224, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Sign KAT for Prime Curves (A5173)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "P-224, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Sign KAT for Binary Curves (A4593)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "K-233, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Sign KAT for Binary Curves (A5173)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "K-233, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Sign KAT for Brainpool Curves (A4593)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "brainpoolP224r 1, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Sign KAT for Brainpool Curves (A5173)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "brainpoolP224r 1, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Verify KAT for Prime Curves (A4593)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "P-224, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Verify KAT for Prime Curves (A5173)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "P-224, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Verify KAT for Binary Curves (A4593)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "K-233, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Verify KAT for Binary Curves (A5173)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "K-233, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Verify KAT for Brainpool Curves (A4593)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "brainpoolP224r 1, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA Verify KAT for Brainpool Curves (A5173)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "brainpoolP224r 1, SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "EDDSA Sign KAT for Ed25519 (A4593)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Ed25519",
"type": "CAST"
},
{
"algorithmOrTest": "EDDSA Sign KAT for Ed25519 (A5173)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Ed25519",
"type": "CAST"
},
{
"algorithmOrTest": "EDDSA Sign KAT for Ed448 (A4593)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Ed448",
"type": "CAST"
},
{
"algorithmOrTest": "EDDSA Sign KAT for Ed448 (A5173)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Ed448",
"type": "CAST"
},
{
"algorithmOrTest": "EDDSA Verify KAT for Ed25519 (A4593)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Ed25519",
"type": "CAST"
},
{
"algorithmOrTest": "EDDSA Verify KAT for Ed25519 (A5173)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Ed25519",
"type": "CAST"
},
{
"algorithmOrTest": "EDDSA Verify KAT for Ed448 (A4593)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Ed448",
"type": "CAST"
},
{
"algorithmOrTest": "EDDSA Verify KAT for Ed448 (A5173)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Ed448",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC-SHA2- 256 (A4593)",
"condition": "Initialisation , performed before pre- operational integrity test",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "HMAC-SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC-SHA2- 256 (A5173)",
"condition": "Initialisation , performed before pre- operational integrity test",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "HMAC-SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A4593)",
"condition": "Initialisation",
"details": "Verify computation of shared secret Z in Ephemeral Unified scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "P-256",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A5173)",
"condition": "Initialisation",
"details": "Verify computation of shared secret Z in Ephemeral Unified scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "P-256",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3 (A4593)",
"condition": "Initialisation",
"details": "Verify computation of shared secret Z in dhEphem scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "FB (2048, 224)",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3 (A5173)",
"condition": "Initialisation",
"details": "Verify computation of shared secret Z in dhEphem scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "FB (2048, 224)",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-IFC-SSC (A4593)",
"condition": "Initialisation",
"details": "RSA Primitive Computation, per Scenario 1 of IG D.F and Section 8.2.2 in SP 800-56Br2",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-IFC-SSC (A5173)",
"condition": "Initialisation",
"details": "RSA Primitive Computation, per Scenario 1 of IG D.F and Section 8.2.2 in SP 800-56Br2",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "KDA OneStep SP800-56Cr2 (A4593)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-224",
"type": "CAST"
},
{
"algorithmOrTest": "KDA OneStep SP800-56Cr2 (A5173)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-224",
"type": "CAST"
},
{
"algorithmOrTest": "KDA TwoStep SP800-56Cr2 (A4593)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "KDA TwoStep SP800-56Cr2 (A5173)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "KDF SP800- 108 (A4593)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Counter Mode with HMAC- SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "KDF SP800- 108 (A5173)",
"condition": "Initialisation",
"details": "Derive",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "Counter Mode with HMAC- SHA-256",
"type": "CAST"
},
{
"algorithmOrTest": "KTS-IFC Encrypt KAT for KTS- OAEP-Basic (A4593)",
"condition": "Initialisation",
"details": "Encrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "KTS-IFC Encrypt KAT for KTS- OAEP-Basic (A5173)",
"condition": "Initialisation",
"details": "Encrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "KTS-IFC Decrypt KAT for KTS- OAEP-Basic (A4593)",
"condition": "Initialisation",
"details": "Decrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "KTS-IFC Decrypt KAT for KTS- OAEP-Basic (A5173)",
"condition": "Initialisation",
"details": "Decrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "KTS-IFC Decrypt KAT for CRT (A4593)",
"condition": "Initialisation",
"details": "Decrypt for CRT, per IG D.G and SP 800-56Br2",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "KTS-IFC Decrypt KAT for CRT (A5173)",
"condition": "Initialisation",
"details": "Decrypt for CRT, per IG D.G and SP 800-56Br2",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "PBKDF (A4593)",
"condition": "Initialisation",
"details": "Derivation of the Master Key (MK), per Section 5.3 of SP 800-132",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "HMAC-SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "PBKDF (A5173)",
"condition": "Initialisation",
"details": "Derivation of the Master Key (MK), per Section 5.3 of SP 800-132",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "HMAC-SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "RSA Sign KAT (A4593)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key, SHA-256, PKCS#1",
"type": "CAST"
},
{
"algorithmOrTest": "RSA Sign KAT (A5173)",
"condition": "Initialisation",
"details": "Sign",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key, SHA-256, PKCS#1",
"type": "CAST"
},
{
"algorithmOrTest": "RSA Verify KAT (A4593)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key, SHA-256, PKCS#1",
"type": "CAST"
},
{
"algorithmOrTest": "RSA Verify KAT (A5173)",
"condition": "Initialisation",
"details": "Verify",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "2048-bit key, SHA-256, PKCS#1",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3 KAT for Keccak-p Permutation (A4593)",
"condition": "Initialisation",
"details": "Hash",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA3-256",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3 KAT for Keccak-p Permutation (A5173)",
"condition": "Initialisation",
"details": "Hash",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA3-256",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A4593)",
"condition": "Initialisation",
"details": "Hash",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A5173)",
"condition": "Initialisation",
"details": "Hash",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-512 (A4593)",
"condition": "Initialisation",
"details": "Hash",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-512 (A5173)",
"condition": "Initialisation",
"details": "Hash",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "SHA-512",
"type": "CAST"
},
{
"algorithmOrTest": "TDES-CBC (A4593)",
"condition": "Initialisation",
"details": "Decrypt",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "CBC mode, 3- key",
"type": "CAST"
},
{
"algorithmOrTest": "TDES-CBC (A5173)",
"condition": "Initialisation",
"details": "Decrypt",
"indicator": "The Module State changes to Running",
"testMethod": "KAT",
"testProps": "CBC mode, 3- key",
"type": "CAST"
},
{
"algorithmOrTest": "DSA (FFC) PCT for Key Agreement (A4593)",
"condition": "Key Pair Generation, Key Pair Import",
"details": "Sign/Verify for Key Agreement, per VE10.35.03",
"indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported parameters for KAS-FFC",
"type": "PCT"
},
{
"algorithmOrTest": "DSA (FFC) PCT for Key Agreement (A5173)",
"condition": "Key Pair Generation, Key Pair Import",
"details": "Sign/Verify for Key Agreement, per VE10.35.03",
"indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported parameters for KAS-FFC",
"type": "PCT"
},
{
"algorithmOrTest": "ECC PCT for Key Pair Generation (A4593)",
"condition": "Key Pair Generation",
"details": "Sign/Verify for Digital Signatures, per VE10.35.02. At the time of key pair generation, the keys\u0027 intended usage is not known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.",
"indicator": "Return value for the relevant API call (i.e. for key pair generation): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported curves",
"type": "PCT"
},
{
"algorithmOrTest": "ECC PCT for Key Pair Generation (A5173)",
"condition": "Key Pair Generation",
"details": "Sign/Verify for Digital Signatures, per VE10.35.02. At the time of key pair generation, the keys\u0027 intended usage is not",
"indicator": "Return value for the relevant API call (i.e. for key pair generation): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported curves",
"type": "PCT"
},
{
"algorithmOrTest": "",
"condition": "",
"details": "known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.",
"indicator": "",
"testMethod": "",
"testProps": "",
"type": ""
},
{
"algorithmOrTest": "ECC PCT for Key Pair Import (A4593)",
"condition": "Key Pair Import",
"details": "Sign/Verify for Key Agreement, per VE10.35.03. At the time of key pair import, the keys\u0027 intended usage is not known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable",
"indicator": "Return value for the relevant API call (i.e. for key pair import): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported curves",
"type": "PCT"
},
{
"algorithmOrTest": "ECC PCT for Key Pair Import (A5173)",
"condition": "Key Pair Import",
"details": "Sign/Verify for Key Agreement, per VE10.35.03.",
"indicator": "Return value for the relevant API call (i.e. for key pair import): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported curves",
"type": "PCT"
},
{
"algorithmOrTest": "",
"condition": "",
"details": "At the time of key pair import, the keys\u0027 intended usage is not known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable",
"indicator": "",
"testMethod": "",
"testProps": "",
"type": ""
},
{
"algorithmOrTest": "EdDSA PCT (A4593)",
"condition": "Key Pair Generation, Key Pair Import",
"details": "Sign/Verify for Digital Signatures, per VE10.35.02. EdDSA keys can only be used for digital signatures.",
"indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported curves (Ed25519, Ed448)",
"type": "PCT"
},
{
"algorithmOrTest": "EdDSA PCT (A5173)",
"condition": "Key Pair Generation, Key Pair Import",
"details": "Sign/Verify for Digital Signatures, per VE10.35.02. EdDSA keys can only be used for digital signatures.",
"indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported curves (Ed25519, Ed448)",
"type": "PCT"
},
{
"algorithmOrTest": "RSA PCT (A4593)",
"condition": "Key Pair Generation, Key Pair Import",
"details": "Sign/Verify for Key Agreement, per VE10.35.03. At the time of key pair generation or import, the keys\u0027 intended usage is not known (key pairs may be used for key transport, digital signatures, or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.",
"indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported moduli",
"type": "PCT"
},
{
"algorithmOrTest": "RSA PCT (A5173)",
"condition": "Key Pair Generation, Key Pair Import",
"details": "Sign/Verify for Key Agreement, per VE10.35.03. At the time of key pair generation or import, the keys\u0027 intended usage is not known (key pairs may be used for key transport,",
"indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure",
"testMethod": "PCT",
"testProps": "All supported moduli",
"type": "PCT"
},
{
"algorithmOrTest": "",
"condition": "",
"details": "digital signatures, or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.",
"indicator": "",
"testMethod": "",
"testProps": "",
"type": ""
},
{
"algorithmOrTest": "AES-XTS Key Test (A4593)",
"condition": "Symmetric Encryption/ Decryption",
"details": "Test that Key_1 Key_2, per IG C.I",
"indicator": "Return value for the relevant API call (i.e. for symmetric encryption/decryption with AES-XTS): 1 for success, 0 for failure",
"testMethod": "Other",
"testProps": "All supported sizes (128-bit, 256-bit)",
"type": "Critical Functio n"
},
{
"algorithmOrTest": "AES-XTS Key Test (A5173)",
"condition": "Symmetric Encryption/ Decryption",
"details": "Test that Key_1 Key_2, per IG C.I",
"indicator": "Return value for the relevant API call (i.e. for symmetric encryption/decryption with AES-XTS): 1 for success, 0 for failure",
"testMethod": "Other",
"testProps": "All supported sizes (128-bit, 256-bit)",
"type": "Critical Functio n"
}
],
"found": true,
"section": 10,
"subsection": 2
},
"error_states": {
"entries": [
{
"conditions": "Pre- operational self-test failure CAST",
"description": "The module has entered an error state. All cryptographic",
"indicator": "Module State (queried via Show Status)",
"name": "FIPS_STATE_ERROR",
"recoveryMethod": "Restart the module"
},
{
"conditions": "self-test failure",
"description": "APIs will return an error when called.",
"indicator": "changes to Error (FIPS_STATE_ERROR)",
"name": "",
"recoveryMethod": ""
},
{
"conditions": "Conditional PCT test failure Conditional AES-XTS critical function test failure",
"description": "The module enters a temporary error state when a PCT test fails or when the AES-XTS critical function test fails. Keys that fail the tests are disabled and the module returns to the Running state.",
"indicator": "The return value for the relevant API call (i.e. for key pair generation, key pair import, or symmetric encryption/ decryption with AES- XTS) returns 0 for failure",
"name": "Temporary Error",
"recoveryMethod": "The module will reject the tested key or key pair and then return automatically to the Running state (FIPS_STATE_RUNNING)."
}
],
"found": true,
"section": 10,
"subsection": 4
},
"mechanisms_actions": {
"entries": [],
"found": false,
"section": 7,
"subsection": 1
},
"modes_of_operation": {
"entries": [
{
"description": "Single approved mode of operation. No non- approved mode is implemented in the module.",
"name": "Approved Mode",
"statusIndicator": "In alignment with IG 2.4.C example scenario 2, the module only provides approved services. The module provides a global indicator that services are approved. Additionally, the module provides a status code indicating the completion of each service, as indicated in Security Policy Section 4.3 - Approved Services. The successful completion of a service is an implicit indicator for the use of an approved service.",
"type": "Approved"
}
],
"found": true,
"section": 2,
"subsection": 4
},
"non_approved_allowed_NSC": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_allowed_algos": {
"entries": [
{
"algoPropList": "Curves: brainpoolP224r1 (strength 112 bits) brainpoolP256r1 (strength 128 bits) brainpoolP320r1 (strength 160 bits) brainpoolP384r1 (strength 192 bits) brainpoolP512r1 (strength 256 bits) : SSP Agreement",
"implName": "CryptoComply 140-3 FIPS Provider",
"name": "EC Diffie-Hellman with non-NIST recommended curves",
"reference": "Allowed per IG D.F, scenario 3 (per IG C.A, category 1a and SP 800-186 Appendix H.1)"
},
{
"algoPropList": "Curves: brainpoolP224r1 (strength 112 bits) brainpoolP256r1 (strength 128 bits) brainpoolP320r1 (strength 160 bits) brainpoolP384r1 (strength 192 bits) brainpoolP512r1 (strength 256 bits) : Signature Generation, Signature Verification, Key Generation, Key Verification",
"implName": "CryptoComply 140-3 FIPS Provider",
"name": "ECDSA with non- NIST recommended curves",
"reference": "Allowed per IG C.A, category 1a (per SP 800-186 Appendix H.1)"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_not_allowed": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_services": {
"entries": [],
"found": false,
"section": 4,
"subsection": 4
},
"ports_interfaces": {
"entries": [
{
"data": "API input parameters for data",
"logicalInterface": "Data Input",
"physicalPort": "N/A"
},
{
"data": "API output parameters for data",
"logicalInterface": "Data Output",
"physicalPort": "N/A"
},
{
"data": "API function calls",
"logicalInterface": "Control Input",
"physicalPort": "N/A"
},
{
"data": "API status outputs (return codes, error messages)",
"logicalInterface": "Status Output",
"physicalPort": "N/A"
}
],
"found": true,
"section": 3,
"subsection": 1
},
"roles": {
"entries": [
{
"authMethodList": "None",
"name": "Crypto Officer",
"operatorType": "CO",
"type": "Role"
}
],
"found": true,
"section": 4,
"subsection": 2
},
"security_levels": {
"entries": [
{
"level": "1",
"section": "1",
"title": "General"
},
{
"level": "1",
"section": "2",
"title": "Cryptographic module specification"
},
{
"level": "1",
"section": "3",
"title": "Cryptographic module interfaces"
},
{
"level": "1",
"section": "4",
"title": "Roles, services, and authentication"
},
{
"level": "1",
"section": "5",
"title": "Software/Firmware security"
},
{
"level": "1",
"section": "6",
"title": "Operational environment"
},
{
"level": "N/A",
"section": "7",
"title": "Physical security"
},
{
"level": "N/A",
"section": "8",
"title": "Non-invasive security"
},
{
"level": "1",
"section": "9",
"title": "Sensitive security parameter management"
},
{
"level": "1",
"section": "10",
"title": "Self-tests"
},
{
"level": "1",
"section": "11",
"title": "Life-cycle assurance"
},
{
"level": "1",
"section": "12",
"title": "Mitigation of other attacks"
},
{
"level": "1",
"section": "",
"title": "Overall Level"
}
],
"found": true,
"section": 1,
"subsection": 2
},
"self_tests": {
"entries": [
{
"algorithmOrTest": "HMAC-SHA2- 256 (A4593)",
"details": "Verify",
"indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNING)",
"testMethod": "Compare to pre-computed HMAC",
"testProps": "HMAC-SHA- 256 (Cert. A4593)",
"type": "SW/FW Integrity"
},
{
"algorithmOrTest": "HMAC-SHA2- 256 (A5173)",
"details": "Verify",
"indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNING)",
"testMethod": "Compare to pre-computed HMAC",
"testProps": "HMAC-SHA- 256 (Cert. A5173)",
"type": "SW/FW Integrity"
}
],
"found": true,
"section": 10,
"subsection": 1
},
"ssp_io_methods": {
"entries": [
{
"dest": "RAM / DRAM",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "API Input via TOEPP path",
"sfiAlgo": "",
"source": "Other Applications (App per IG 9.5.A)"
},
{
"dest": "RAM / DRAM",
"distribution": "Manual",
"entry": "Electronic",
"format": "Encrypted",
"name": "Encrypted API Input using Key Transport via TOEPP path",
"sfiAlgo": "KeyTransport",
"source": "Other Applications (App per IG 9.5.A)"
},
{
"dest": "RAM / DRAM",
"distribution": "Manual",
"entry": "Electronic",
"format": "Encrypted",
"name": "Encrypted API Input using Key Wrapping via TOEPP path",
"sfiAlgo": "KeyWrapping",
"source": "Other Applications (App per IG 9.5.A)"
},
{
"dest": "Other Applications (App per IG 9.5.A)",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "API Output via TOEPP path",
"sfiAlgo": "",
"source": "RAM / DRAM"
},
{
"dest": "Other Applications (App per IG 9.5.A)",
"distribution": "Manual",
"entry": "Electronic",
"format": "Encrypted",
"name": "Encrypted API Output using Key Transport via TOEPP path",
"sfiAlgo": "KeyTransport",
"source": "RAM / DRAM"
},
{
"dest": "Other Applications (App per IG 9.5.A)",
"distribution": "Manual",
"entry": "Electronic",
"format": "Encrypted",
"name": "Encrypted API Output using Key Wrapping via TOEPP path",
"sfiAlgo": "KeyWrapping",
"source": "RAM / DRAM"
}
],
"found": true,
"section": 9,
"subsection": 2
},
"ssp_zeroization_methods": {
"entries": [
{
"description": "Calls OPENSSL_cleanse to zeroise the DRBG CSPs",
"method": "Zeroise service",
"operatorId": "Function provided via API",
"rationale": "DRBG CSPs are the only SSPs stored by the module beyond the lifetime of an API call. The Zeroise service zeroises SSPs by overwriting zeroes to the memory location occupied by the SSP and further deallocating that area."
},
{
"description": "Services include appropriate APIs (OPENSSL_free or OPENSSL_cleanse) to automatically zeroise the SSPs created or used by the services. This zeroises the context structures that contains the SSP.",
"method": "Call a service that creates or uses the SSP",
"operatorId": "Function provided via API",
"rationale": "SSPs are zeroised by overwriting zeroes to the memory location occupied by the SSP and further deallocating that area."
}
],
"found": true,
"section": 9,
"subsection": 3
},
"storage_areas": {
"entries": [
{
"description": "Memory that only holds data during power on of the operating environment",
"name": "RAM / DRAM",
"persistance": "Dynamic"
}
],
"found": true,
"section": 9,
"subsection": 1
},
"tested_module_id_hw": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_hw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_sw_fw_hy": {
"entries": [
{
"features": "Compiled as a static library, tested on iOS and iPadOS",
"integrityTest": "HMAC-SHA-256",
"packageFileName": "fips.a",
"swFwVersion": "3.0.1-FIPS 140-3"
},
{
"features": "Compiled for Windows",
"integrityTest": "HMAC-SHA-256",
"packageFileName": "fips.dll",
"swFwVersion": "3.0.0-FIPS 140-3"
},
{
"features": "Compiled for MacOS",
"integrityTest": "HMAC-SHA-256",
"packageFileName": "fips.dylib",
"swFwVersion": "3.0.0-FIPS 140-3"
},
{
"features": "Compiled for Linux, Unix, Android",
"integrityTest": "HMAC-SHA-256",
"packageFileName": "fips.so",
"swFwVersion": "3.0.0-FIPS 140-3"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"tested_op_env_sw_fw_hy": {
"entries": [
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "AlmaLinux 9",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "AlmaLinux 9",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Google Pixel 7",
"hypervisorHostOs": "",
"operatingSystem": "Android 13",
"paa_pai": "No",
"processors": "Google Tensor G2",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Debian 11",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Debian 11",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "FreeBSD 13",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "FreeBSD 13",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "iPhone 13 Mini",
"hypervisorHostOs": "",
"operatingSystem": "iOS 16",
"paa_pai": "No",
"processors": "Apple A15 Bionic",
"version": "3.0.1-FIPS 140-3"
},
{
"hardwarePlatform": "iPad Air (2022)",
"hypervisorHostOs": "",
"operatingSystem": "iPadOS 16",
"paa_pai": "No",
"processors": "Apple M1",
"version": "3.0.1-FIPS 140-3"
},
{
"hardwarePlatform": "Mac Mini M2",
"hypervisorHostOs": "",
"operatingSystem": "macOS 13 (Ventura)",
"paa_pai": "No",
"processors": "Apple M2",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Oracle Solaris 11.4",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Oracle Solaris 11.4",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Red Hat Enterprise Linux 9",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Red Hat Enterprise Linux 9",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Rocky Linux 9",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Rocky Linux 9",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "SUSE Linux Enterprise Server 15",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "SUSE Linux Enterprise Server 15",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Ubuntu 22.04",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Ubuntu 22.04",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Windows 10",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Windows 10",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Windows 11",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Windows 11",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Windows Server 2019",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Windows Server 2019",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Windows Server 2022",
"paa_pai": "Yes",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
},
{
"hardwarePlatform": "Dell PowerEdge R830",
"hypervisorHostOs": "",
"operatingSystem": "Windows Server 2022",
"paa_pai": "No",
"processors": "Intel Xeon E5- 4667v4",
"version": "3.0.0-FIPS 140-3"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"vendor_affirmed_algos": {
"entries": [
{
"algoPropList": "Key Type:Symmetric and Asymmetric",
"implName": "N/A",
"name": "CKG",
"reference": "SP 800-133r2 and IG D.H: Per Section 4, example 1"
},
{
"algoPropList": "Key Type:Symmetric",
"implName": "N/A",
"name": "CKG (XTS)",
"reference": "SP 800-133r2 and IG D.H: Per Section 6.3, approved method 1. Applicable to AES-XTS compliant to IG C.I because Key_1 and Key_2 are concatenated prior to usage."
}
],
"found": true,
"section": 2,
"subsection": 5
},
"vendor_affirmed_op_env_sw_fw_hy": {
"entries": [
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "AlmaLinux 9"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Android 13"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Debian 11"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "FreeBSD 13"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "iOS 16"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "iPadOS 16"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "macOS 13 (Ventura)"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Oracle Solaris 11.4"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Red Hat Enterprise Linux 9"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Rocky Linux 9"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "SUSE Linux Enterprise Server 15"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Ubuntu 22.04"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Windows 10"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Windows 11"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Windows Server 2019"
},
{
"hardwarePlatform": "Any general-purpose platform that supports this OS",
"operatingSystem": "Windows Server 2022"
}
],
"found": true,
"section": 2,
"subsection": 2
}
},
"is_br1_format": true,
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 19
},
"ECDH": {
"ECDH": 6
},
"ECDSA": {
"ECDSA": 64
},
"EdDSA": {
"EdDSA": 22
}
},
"FF": {
"DH": {
"DH": 31,
"DHE": 2,
"Diffie-Hellman": 2
},
"DSA": {
"DSA": 41
}
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 2
},
"GCM": {
"GCM": 10
},
"XTS": {
"XTS": 10
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 8
}
},
"crypto_protocol": {
"SSH": {
"SSH": 7,
"SSHv2": 2
},
"TLS": {
"TLS": {
"TLS 1.2": 10,
"TLS 1.3": 9,
"TLS v1.2": 7,
"TLS v1.3": 7
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 19
},
"MAC": {
"MAC": 6
}
},
"device_model": {},
"ecc_curve": {
"Brainpool": {
"brainpoolP224r1": 2,
"brainpoolP256r1": 4,
"brainpoolP320r1": 4,
"brainpoolP384r1": 4,
"brainpoolP512r1": 4
},
"Edwards": {
"Ed25519": 16,
"Ed448": 16
},
"NIST": {
"B-163": 6,
"B-233": 15,
"B-283": 13,
"B-409": 12,
"B-571": 13,
"K-163": 6,
"K-233": 19,
"K-283": 13,
"K-409": 11,
"K-571": 12,
"P-192": 12,
"P-224": 30,
"P-256": 30,
"P-384": 30,
"P-521": 30
}
},
"eval_facility": {},
"fips_cert_id": {},
"fips_certlike": {
"Certlike": {
"- PKCS 1": 2,
"AES-128": 4,
"AES-192": 4,
"AES-256": 4,
"Diffie- Hellman 224": 1,
"HMAC 160": 1,
"HMAC 160, 224": 1,
"HMAC- SHA-256": 2,
"HMAC-SHA- 256": 4,
"HMAC-SHA-1": 12,
"HMAC-SHA-256": 28,
"PKCS 1": 6,
"PKCS#1": 8,
"SHA- 1 1024": 1,
"SHA- 3": 1,
"SHA-1": 32,
"SHA-2": 2,
"SHA-224": 2,
"SHA-256": 17,
"SHA-3": 1,
"SHA-512": 15,
"SHA2- 512": 12,
"SHA2-224": 20,
"SHA2-256": 28,
"SHA2-384": 24,
"SHA2-512": 18,
"SHA3": 4,
"SHA3- 384": 6,
"SHA3-224": 10,
"SHA3-256": 12,
"SHA3-384": 4,
"SHA3-512": 10
}
},
"fips_security_level": {
"Level": {
"Level 1": 2
}
},
"hash_function": {
"PBKDF": {
"PBKDF": 16
},
"SHA": {
"SHA1": {
"SHA-1": 32
},
"SHA2": {
"SHA-2": 2,
"SHA-224": 2,
"SHA-256": 17,
"SHA-512": 15
},
"SHA3": {
"SHA-3": 1,
"SHA3": 4,
"SHA3-224": 10,
"SHA3-256": 12,
"SHA3-384": 4,
"SHA3-512": 10
}
},
"SHAKE": {
"SHAKE256": 1
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 79
},
"RNG": {
"RBG": 23,
"RNG": 22
}
},
"side_channel_analysis": {
"SCA": {
"side-channel": 1,
"timing attack": 1,
"timing attacks": 2
}
},
"standard_id": {
"FIPS": {
"FIPS 140": 8,
"FIPS 140-3": 128,
"FIPS 180-4": 14,
"FIPS 186-4": 26,
"FIPS 186-5": 11,
"FIPS 1865": 1,
"FIPS 198-1": 22,
"FIPS 202": 12,
"FIPS186-4": 41
},
"NIST": {
"NIST SP 800-38D": 1,
"SP 800-108": 4,
"SP 800-132": 7,
"SP 800-135": 10,
"SP 800-185": 4,
"SP 800-186": 2,
"SP 800-38A": 20,
"SP 800-38B": 2,
"SP 800-38C": 2,
"SP 800-38D": 4,
"SP 800-38E": 3,
"SP 800-38F": 5,
"SP 800-56A": 10,
"SP 800-56B": 2,
"SP 800-56C": 6,
"SP 800-67": 4,
"SP 800-90A": 10
},
"PKCS": {
"PKCS 1": 4,
"PKCS#1": 4
},
"RFC": {
"RFC 5246": 1,
"RFC 5288": 1,
"RFC 7627": 1,
"RFC 8446": 2,
"RFC7627": 6
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 53,
"AES-": 1,
"AES-128": 4,
"AES-192": 4,
"AES-256": 4
},
"CAST": {
"CAST": 162
}
},
"DES": {
"3DES": {
"TDES": 4,
"Triple-DES": 6
}
},
"constructions": {
"MAC": {
"CMAC": 2,
"HMAC": 29,
"HMAC-SHA-256": 14,
"KMAC": 8
}
}
},
"tee_name": {
"AMD": {
"PSP": 10
}
},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"module_algorithms": {
"_type": "Set",
"elements": [
"SHA2-384A5173",
"KMAC-256A5173",
"SHA2-512/224A5173",
"TDES-ECBA5173",
"HMAC-SHA3-512A5173",
"KDF SP800-108A5173",
"AES-GCMA5173",
"KDF ANS 9.42A5173",
"HMAC-SHA2-512A5173",
"ECDSA SigVer (FIPS186-4)A5173",
"RSA SigGen (FIPS186-4)A5173",
"KDA HKDF SP800-56Cr2A5173",
"AES-CFB8A5173",
"AES-CFB1A5173",
"AES-CBC-CS1A5173",
"Hash DRBGA5173",
"AES-CMACA5173",
"SHA-1A5173",
"EDDSA KeyGenA5173",
"PBKDFA5173",
"KDF SSHA5173",
"SHA2-224A5173",
"SHA3-224A5173",
"ECDSA KeyVer (FIPS186-4)A5173",
"DSA PQGVer (FIPS186-4)A5173",
"HMAC-SHA2-224A5173",
"Safe Primes Key GenerationA5173",
"AES-OFBA5173",
"AES-CBC-CS2A5173",
"DSA PQGGen (FIPS186-4)A5173",
"TLS v1.2 KDF RFC7627A5173",
"AES-CCMA5173",
"Counter DRBGA5173",
"RSA KeyGen (FIPS186-4)A5173",
"TLS v1.3 KDFA5173",
"AES-CFB128A5173",
"KAS-IFC-SSCA5173",
"AES-CBC-CS3A5173",
"AES-CBCA5173",
"AES-XTS Testing Revision 2.0A5173",
"SHA2-512A5173",
"HMAC-SHA-1A5173",
"SHA3-512A5173",
"DSA SigVer (FIPS186-4)A5173",
"EDDSA KeyVerA5173",
"ECDSA KeyGen (FIPS186-4)A5173",
"AES-GMACA5173",
"SHAKE-128A5173",
"KTS-IFCA5173",
"HMAC-SHA2-512/224A5173",
"EDDSA SigGenA5173",
"HMAC-SHA2-384A5173",
"HMAC-SHA3-256A5173",
"HMAC-SHA2-512/256A5173",
"RSA SigVer (FIPS186-4)A5173",
"SHA3-384A5173",
"KMAC-128A5173",
"HMAC DRBGA5173",
"EDDSA SigVerA5173",
"SHA2-256A5173",
"SHA2-512/256A5173",
"HMAC-SHA3-224A5173",
"KDF KMAC Sp800-108r1A5173",
"SHAKE-256A5173",
"Safe Primes Key VerificationA5173",
"AES-KWA5173",
"AES-KWPA5173",
"KAS-ECC-SSC Sp800-56Ar3A5173",
"KDA TwoStep SP800-56Cr2A5173",
"KDF ANS 9.63A5173",
"TDES-CBCA5173",
"AES-CTRA5173",
"KDA OneStep SP800-56Cr2A5173",
"DSA KeyGen (FIPS186-4)A5173",
"AES-ECBA5173",
"ECDSA SigGen (FIPS186-4)A5173",
"HMAC-SHA2-256A5173",
"KAS-FFC-SSC Sp800-56Ar3A5173",
"HMAC-SHA3-384A5173",
"SHA3-256A5173"
]
},
"policy_algorithms": {
"_type": "Set",
"elements": [
"#A4593",
"#A5173"
]
},
"policy_metadata": {
"/ACVP Cert A": "A4593",
"/ACVP Cert B": "A5173",
"/ACVP Certs": "A4593, A5173",
"/Author": "SafeLogic Inc.",
"/Client": "SafeLogic Inc.",
"/Comments": "",
"/Company": "SafeLogic",
"/CreationDate": "D:20260312105101-04\u002700\u0027",
"/Creator": "Acrobat PDFMaker 25 for Word",
"/Doc Version": "1.3",
"/Keywords": "",
"/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_ActionId": "4887e0e4-7009-40a6-bc60-76c09a102a1b",
"/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_ContentBits": "0",
"/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_Enabled": "true",
"/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_Method": "Privileged",
"/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_Name": "Unrestricted",
"/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_SetDate": "2024-11-11T19:34:29Z",
"/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_SiteId": "b64da4ac-e800-4cfc-8931-e607f720a1b8",
"/ModDate": "D:20260312105810-04\u002700\u0027",
"/Producer": "Adobe PDF Library 25.1.5",
"/SW Version": "3.0.0-FIPS 140-3",
"/SW Version B": "3.0.1-FIPS 140-3",
"/SourceModified": "",
"/Subject": "CryptoComply 140-3 FIPS Provider",
"/Title": "Security Policy",
"pdf_file_size_bytes": 1537395,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://www.lightware.com/",
"https://csrc.nist.gov/projects/cryptographic-module-validation-program",
"http://www.safelogic.com/",
"mailto:[email protected]"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 116
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "110fc5c2a15162f852292666e63205cfbdcfc593471021a5bb17bdb3687b42fd",
"source_hash": "789f033fd09c91bec59ee6543531c413298c6d60123f2102130749f066081bf4",
"txt_hash": "9d052486a005d1c4245de8c5d3efb2f8f1b0f5d25cd51055489987b327344ddd"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "No assurance of the minimum strength of generated SSPs (e.g., keys) and random strings. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/March 2026_020426_1121-signed.pdf",
"date_sunset": "2029-08-26",
"description": "Lightware Crypto Core is a standards-based cryptographic engine for embedded Linux systems. The module delivers core cryptographic functions to the embedded systems of Taurus product family\u0027s hardware devices and features robust algorithm support. Lightware Crypto Core offloads functions for secure key management, data integrity, data at rest encryption, and secure communications to a trusted implementation.",
"embodiment": "MultiChipStand",
"exceptions": [
"Physical security: N/A",
"Non-invasive security: N/A"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 1,
"mentioned_certs": {},
"module_name": "Lightware Crypto Core",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-3",
"status": "active",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2026-03-26",
"lab": "DEKRA Cybersecurity Certification Laboratory",
"validation_type": "Initial"
}
],
"vendor": "Lightware Visual Engineering Plc.",
"vendor_url": "https://www.lightware.com"
}
}