{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "b7b598d56a5096e6", "cert_id": 5204, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "WinMagic Cryptographic Module for Windows", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-03-23", "validation_type": "Initial", "lab": "Lightship Security, Inc."}], "vendor_url": "http://www.winmagic.com", "vendor": "WinMagic Corp", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/March 2026_020426_1121-signed.pdf", "module_type": "Software", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "None", "exceptions": ["Physical security: N/A", "Non-invasive security: N/A", "Mitigation of other attacks: N/A"], "embodiment": "MultiChipStand", "description": "The WinMagic Cryptographic Module for Windows 1.0 is a software library, designed to run as a multi-chip standalone embodiment on Windows platform. The module leverages cryptographic services for the WinMagic software products.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2031-03-22", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {}, "fips_security_level": {"Level": {"Level 1": 2}}, "fips_certlike": {"Certlike": {"HMAC-SHA-256": 2, "SHA2-256": 3, "SHA2-384": 2, "SHA2-512": 2, "SHA2- 256": 3, "SHA2- 384": 2, "SHA2- 512": 2, "AES 256": 1}}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 2, "AES-": 2}, "CAST": {"CAST": 15}}, "constructions": {"MAC": {"HMAC": 6, "HMAC-SHA-256": 1}}}, "asymmetric_crypto": {}, "pq_crypto": {}, "hash_function": {"PBKDF": {"PBKDF": 5}}, "crypto_scheme": {"MAC": {"MAC": 4}}, "crypto_protocol": {}, "randomness": {"PRNG": {"DRBG": 7}, "RNG": {"RNG": 2, "RBG": 2}}, "cipher_mode": {"CBC": {"CBC": 2}}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 2, "FIPS 198-1": 3, "FIPS 180-4": 3}, "NIST": {"SP 800-38A": 2, "SP 800-90A": 1, "SP 800-132": 3, "NIST SP 800-90B": 1}, "ISO": {"ISO/IEC 19790:2012": 2, "ISO/IEC 24759:2017": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 609788, "pdf_is_encrypted": false, "pdf_number_of_pages": 21, "/Author": "Dennis Momy", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/CreationDate": "D:20260318131403-04'00'", "/ModDate": "D:20260318131403-04'00'", "/Producer": "Microsoft\u00ae Word for Microsoft 365", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/entropy/E234_PublicUse.pdf\u00c2\u20ac", "https://www.winmagic.com/"]}}, "module_algorithms": {"_type": "Set", "elements": ["SHA2-512A6384", "SHA2-384A6384", "HMAC DRBGA6384", "SHA2-256A6384", "PBKDFA6384", "AES-ECBA6384", "AES-CBCA6384", "HMAC-SHA2-384A6384", "HMAC-SHA2-512A6384", "HMAC-SHA2-256A6384"]}, "policy_algorithms": {"_type": "Set", "elements": ["#A6384"]}, "is_br1_format": true, "br1_deviations": 1, "br1_tables": {"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables", "security_levels": {"section": 1, "subsection": 2, "found": true, "entries": [{"section": "1", "title": "General", "level": "1"}, {"section": "2", "title": "Cryptographic module specification", "level": "1"}, {"section": "3", "title": "Cryptographic module interfaces", "level": "1"}, {"section": "4", "title": "Roles, services, and authentication", "level": "1"}, {"section": "5", "title": "Software/Firmware security", "level": "1"}, {"section": "6", "title": "Operational environment", "level": "1"}, {"section": "7", "title": "Physical security", "level": "N/A"}, {"section": "8", "title": "Non-invasive security", "level": "N/A"}, {"section": "9", "title": "Sensitive security parameter management", "level": "1"}, {"section": "10", "title": "Self-tests", "level": "1"}, {"section": "11", "title": "Life-cycle assurance", "level": "1"}, {"section": "12", "title": "Mitigation of other attacks", "level": "N/A"}, {"section": "", "title": "Overall Level", "level": "1"}]}, "tested_module_id_hw": {"section": 2, "subsection": 2, "found": false, "entries": []}, "tested_module_id_sw_fw_hy": {"section": 2, "subsection": 2, "found": false, "entries": []}, "tested_module_id_hw_hy": {"section": 2, "subsection": 2, "found": false, "entries": []}, "tested_op_env_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"operatingSystem": "Windows 11 Enterprise", "hardwarePlatform": "HP ProBook 440 G5", "processors": "Intel\u00ae CoreTM i7- 8550U (Kaby Lake)", "paa_pai": "No", "hypervisorHostOs": "", "version": "1.0"}, {"operatingSystem": "Windows 11 Enterprise", "hardwarePlatform": "HP ProBook 440 G5", "processors": "Intel\u00ae CoreTM i7- 8550U (Kaby Lake)", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "1.0"}, {"operatingSystem": "Windows 11 Pro", "hardwarePlatform": "ThinkPad T14s Gen 6", "processors": "SnapDragon\u00ae Elite X1E-78-100 (ARMv8)", "paa_pai": "No", "hypervisorHostOs": "", "version": "1.0"}]}, "vendor_affirmed_op_env_sw_fw_hy": {"section": 2, "subsection": 2, "found": false, "entries": []}, "modes_of_operation": {"section": 2, "subsection": 4, "found": true, "entries": [{"name": "Approved Mode", "description": "Automatically entered after module initialization", "type": "Approved", "statusIndicator": "CKR_CRYPTOKI_INITIALIZED (0x0)"}]}, "approved_algorithms": {"section": 2, "subsection": 5, "found": true, "entries": [{"algorithm": "AES-CBC", "cavpCertName": "A6384", "properties": "Direction - Decrypt, Encrypt Key Length - 256", "reference": "SP 800-38A"}, {"algorithm": "AES-ECB", "cavpCertName": "A6384", "properties": "Direction - Decrypt, Encrypt Key Length - 256", "reference": "SP 800-38A"}, {"algorithm": "HMAC DRBG", "cavpCertName": "A6384", "properties": "Prediction Resistance - No Mode - SHA2-256", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "HMAC-SHA2- 256", "cavpCertName": "A6384", "properties": "Key Length - Key Length: 256", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 384", "cavpCertName": "A6384", "properties": "Key Length - Key Length: 256", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512", "cavpCertName": "A6384", "properties": "Key Length - Key Length: 256", "reference": "FIPS 198-1"}, {"algorithm": "PBKDF", "cavpCertName": "A6384", "properties": "Iteration Count - Iteration Count: 8192- 12288 Increment 1 Password Length - Password Length: 8- 128 Increment 8", "reference": "SP 800-132"}, {"algorithm": "SHA2-256", "cavpCertName": "A6384", "properties": "Message Length - Message Length: 0- 51200 Increment 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-384", "cavpCertName": "A6384", "properties": "Message Length - Message Length: 0- 65536 Increment 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-512", "cavpCertName": "A6384", "properties": "Message Length - Message Length: 0- 65536 Increment 8", "reference": "FIPS 180-4"}]}, "vendor_affirmed_algos": {"section": 2, "subsection": 5, "found": false, "entries": []}, "non_approved_allowed_algos": {"section": 2, "subsection": 5, "found": false, "entries": []}, "non_approved_allowed_NSC": {"section": 2, "subsection": 5, "found": false, "entries": []}, "non_approved_not_allowed": {"section": 2, "subsection": 5, "found": false, "entries": []}, "ports_interfaces": {"section": 3, "subsection": 1, "found": true, "entries": [{"physicalPort": "N/A", "logicalInterface": "Control Input", "data": "API entry point: stack frame including non-sensitive parameters"}, {"physicalPort": "N/A", "logicalInterface": "Data Input", "data": "API call parameters passed by reference or value for cryptographic service input"}, {"physicalPort": "N/A", "logicalInterface": "Data Output", "data": "API call parameters passed by reference for cryptographic service output"}, {"physicalPort": "N/A", "logicalInterface": "Status Output", "data": "API return value: enumerated status resulting from call execution"}]}, "authentication_methods": {"section": 4, "subsection": 1, "found": false, "entries": []}, "roles": {"section": 4, "subsection": 2, "found": true, "entries": [{"name": "Crypto Officer", "type": "Role", "operatorType": "CO", "authMethodList": "None"}]}, "approved_services": {"section": 4, "subsection": 3, "found": true, "entries": [{"name": "Random Byte Generator", "description": "Generates random bytes using the DRBG", "indicator": "Success ful completi on", "inputs": "Request ed number of bytes", "outputs": "Status return Random bytes", "secFunImpl": "Determinist ic Random Bit Generator", "rolesSspAccess": "Crypto Officer - DRBG_ENT : G,E"}, {"name": "", "description": "", "indicator": "(status = 0)", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "- DRBG_SEE D: G,E - DRBG_STA TE: G,E"}, {"name": "Key Generator", "description": "Generates a symmetric key using the DRBG", "indicator": "Success ful completi on (status = 0)", "inputs": "None", "outputs": "Status return Symmetr ic key", "secFunImpl": "Symmetric Key Generation", "rolesSspAccess": "Crypto Officer - AES_KEY: G,E"}, {"name": "Message Digest", "description": "Generates a message digest", "indicator": "Success ful completi on (status = 0)", "inputs": "Input Data", "outputs": "Status return Hash", "secFunImpl": "Secure Hash", "rolesSspAccess": "Crypto Officer"}, {"name": "Message Authenticat ion", "description": "Generates or verifies message authentication code", "indicator": "Success ful completi on (status = 0)", "inputs": "Key, input data", "outputs": "Status return MAC", "secFunImpl": "Message Authenticat ion", "rolesSspAccess": "Crypto Officer - HMAC_KEY : W,E"}, {"name": "Data Encryption / Decryption", "description": "Encrypts or decrypts data using a symmetric block cipher", "indicator": "Success ful completi on (status = 0)", "inputs": "Key, AES mode, input data", "outputs": "Status return Cipherte xt or plaintext", "secFunImpl": "Block Cipher", "rolesSspAccess": "Crypto Officer - AES_KEY: W,E"}, {"name": "Key Derivation", "description": "Derives a key from password", "indicator": "Success ful completi on (status = 0)", "inputs": "String containin g a passwor d", "outputs": "Status return derived key", "secFunImpl": "Password- Based Key Derivation", "rolesSspAccess": "Crypto Officer - PBKDF_KM: G,E"}, {"name": "Key Transport", "description": "Exports or imports a key protected by key wrapping.", "indicator": "Success ful completi on (status = 0)", "inputs": "Wrappin g key, key to wrap or unwrap", "outputs": "Status return Wrapped or unwrapp ed key", "secFunImpl": "Key Transport", "rolesSspAccess": "Crypto Officer - AES_KEY: R,W,E"}, {"name": "Self-Test", "description": "Runs the integrity test and Conditional Self-Tests on booting or on demand by", "indicator": "Success ful completi on (status = 0)", "inputs": "none", "outputs": "Status return", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "", "description": "calling \"C_SendComm and\" API", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Show Version", "description": "Provides module name and version", "indicator": "Success ful completi on (status = 0)", "inputs": "none", "outputs": "Status return String containin g the name and version", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "Zeroize", "description": "Zeroize SSP stored in volatile memory of GPC by invoking \"C_Finalize()\" API or power- cycling", "indicator": "Success ful completi on (status = 0)", "inputs": "Referenc e to a structure (s) containin g SSPs", "outputs": "Status return", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer - AES_KEY: Z - HMAC_KEY : Z - DRBG_ENT : Z - DRBG_SEE D: Z - DRBG_STA TE: Z - PBKDF_KM: Z"}, {"name": "Show Status", "description": "Show module status", "indicator": "Success ful completi on (status = 0)", "inputs": "none", "outputs": "Status return", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}]}, "non_approved_services": {"section": 4, "subsection": 4, "found": false, "entries": []}, "mechanisms_actions": {"section": 7, "subsection": 1, "found": false, "entries": []}, "storage_areas": {"section": 9, "subsection": 1, "found": false, "entries": []}, "ssp_io_methods": {"section": 9, "subsection": 2, "found": true, "entries": [{"name": "Input", "source": "Call stack", "dest": "SSPsRAM", "format": "Plaintext", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": ""}, {"name": "Output", "source": "SSPsRAM", "dest": "Call stack", "format": "Plaintext", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": ""}, {"name": "Key Entry", "source": "Call stack", "dest": "SSPsRAM", "format": "Encrypted", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": "Key Transport"}, {"name": "Key Export", "source": "SSPsRAM", "dest": "Call stack", "format": "Encrypted", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": "Key Transport"}]}, "ssp_zeroization_methods": {"section": 9, "subsection": 3, "found": true, "entries": [{"method": "Free service context", "description": "Clear and free SSPs when they are no longer needed", "rationale": "Memory occupied by SSPs is overwritten by zeroes making the SSPs irretrievable.", "operatorId": "Zeroize"}, {"method": "Module reset", "description": "De-allocate SSPsRAM used to store SSPs", "rationale": "Allocated volatile memory is overwritten with zeroes within nanoseconds when power is removed.", "operatorId": "Unload the module"}]}, "self_tests": {"section": 10, "subsection": 1, "found": true, "entries": [{"algorithmOrTest": "HMAC-SHA2- 256 (A6384)", "testProps": "Key: 256", "testMethod": "KAT", "type": "SW/FW Integrity", "indicator": "CKR_OK or CKRT_HMAC_SHA", "details": "Verifies MAC of SDUser.dll"}]}, "cond_self_tests": {"section": 10, "subsection": 2, "found": true, "entries": [{"algorithmOrTest": "HMAC DRBG (A6384)", "testProps": "HMAC- SHA2- 256", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_PRNG", "details": "Instantiate, Generate", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "AES- CBC (A6384) Encrypt", "testProps": "256 bits", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_SELF_TEST_ENC RYPT", "details": "Encrypt", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "AES- CBC (A6384) Decrypt", "testProps": "256 bits", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_SELF_TEST_DEC RYPT", "details": "Decrypt", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "SHA2- 256 (A6384)", "testProps": "-", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_HASH_SHA", "details": "Digest", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "SHA2- 384 (A6384)", "testProps": "-", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_HASH_SHA", "details": "Digest", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "SHA2- 512 (A6384)", "testProps": "-", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_HASH_SHA", "details": "Digest", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "HMAC- SHA2- 256 (A6384)", "testProps": "256 bits", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_HMAC_SHA", "details": "Message Authenticati on", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "HMAC- SHA2- 384 (A6384)", "testProps": "256 bits", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_HMAC_SHA", "details": "Message Authenticati on", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "HMAC- SHA2- 512 (A6384)", "testProps": "256 bits", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_HMAC_SHA", "details": "Message Authenticati on", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "PBKDF (A6384)", "testProps": "Salt: 224 bits Count: 9954 Key: 256 bits", "testMethod": "KAT", "type": "CAS T", "indicator": "CKR_OK or CKRT_PBKDF", "details": "Password Based Key Derivation", "condition": "Runs at power-on prior to integrity test"}, {"algorithmOrTest": "RCT", "testProps": "-", "testMethod": "-", "type": "CAS T", "indicator": "Status", "details": "Repetition Count Test", "condition": "Continuo us"}, {"algorithmOrTest": "APT", "testProps": "-", "testMethod": "-", "type": "CAS T", "indicator": "Status", "details": "Adaptive Proportion Test", "condition": "Continuo us"}]}, "error_states": {"section": 10, "subsection": 4, "found": true, "entries": [{"name": "MODULE_INITIALIZATION _FAILED", "description": "Module aborts initializati on, displays an error message and returns control to OS.", "conditions": "One of the algorith ms has failed KAT. Module has failed integrity check", "recoveryMethod": "reset module", "indicator": "Module state is set to CKR_CRYPTOKI_NOT_INIT IALIZED"}]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["SHA2-512A6384", "SHA2-384A6384", "HMAC DRBGA6384", "SHA2-256A6384", "#A6384", "PBKDFA6384", "AES-ECBA6384", "AES-CBCA6384", "HMAC-SHA2-384A6384", "HMAC-SHA2-512A6384", "HMAC-SHA2-256A6384"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "b582041fe7cd3dee14fd804a98e7f40c937d24c0114fb5c2b6673ebb20a53def", "txt_hash": "1f733f18c685e3e6b819b36ae8a0648a9c1a03a0afb6e1a181d3e0d104a99384", "json_hash": "1fe28a80ad3613a1940d5546116530e62613fb48ec07bd07d60773e56852c966"}}}