Wave Relay® User Space Crypto Module

Certificate details

Certificate ID #5079
Status active
Validation dates 08.10.2025
Sunset date 07-10-2030
Standard FIPS 140-3
Security level 2
Type Software
Embodiment Single Chip
Caveat When operated in approved mode, No assurance of the minimum strength of generated SSPs (e.g., keys)
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description Persistent Systems LLC Wave Relay® User Space Crypto Module is a Software cryptographic module embedded in the Wave Relay® System that provides FIPS Validated cryptographic algorithms which are used by user space system services & protocols (e.g., TLS, IPsec, etc.).
Vendor Persistent Systems, LLC http://www.persistentsystems.com/
Lab UL Verification Services, Inc.
Algorithms
  • AES-CBC-CS1A5177
  • AES-CBC-CS2A5177
  • AES-CBC-CS3A5177
  • AES-CBCA5177
  • AES-CCMA5177
  • AES-CFB128A5177
  • AES-CFB1A5177
  • AES-CFB8A5177
  • AES-CMACA5177
  • AES-CTRA5177
  • AES-ECBA5177
  • AES-GCMA5177
  • AES-GMACA5177
  • AES-KWA5177
  • AES-KWPA5177
  • AES-OFBA5177
  • AES-XTS Testing Revision 2.0A5177
  • Counter DRBGA5177
  • ECDSA KeyGen (FIPS186-4)A5177
  • ECDSA KeyVer (FIPS186-4)A5177
  • ECDSA SigGen (FIPS186-4)A5177
  • ECDSA SigVer (FIPS186-4)A5177
  • Hash DRBGA5177
  • HMAC DRBGA5177
  • HMAC-SHA-1A5177
  • HMAC-SHA2-224A5177
  • HMAC-SHA2-256A5177
  • HMAC-SHA2-384A5177
  • HMAC-SHA2-512/224A5177
  • HMAC-SHA2-512/256A5177
  • HMAC-SHA2-512A5177
  • HMAC-SHA3-224A5177
  • HMAC-SHA3-256A5177
  • HMAC-SHA3-384A5177
  • HMAC-SHA3-512A5177
  • KAS-ECC CDH-Component SP800-56Ar3A5177
  • KAS-ECC-SSC Sp800-56Ar3A5177
  • KAS-FFC-SSC Sp800-56Ar3A5177
  • KAS-IFC-SSCA5177
  • KDA HKDF SP800-56Cr2A5177
  • KDA OneStep SP800-56Cr2A5177
  • KDA TwoStep SP800-56Cr2A5177
  • KDF ANS 9.42A5177
  • KDF ANS 9.63A5177
  • KDF IKEv2A5177
  • KDF SP800-108A5177
  • KDF SSHA5177
  • KMAC-128A5177
  • KMAC-256A5177
  • KTS-IFCA5177
  • PBKDFA5177
  • RSA KeyGen (FIPS186-4)A5177
  • RSA SigGen (FIPS186-4)A5177
  • RSA Signature PrimitiveA5177
  • RSA SigVer (FIPS186-4)A5177
  • Safe Primes Key GenerationA5177
  • Safe Primes Key VerificationA5177
  • SHA-1A5177
  • SHA2-224A5177
  • SHA2-256A5177
  • SHA2-384A5177
  • SHA2-512/224A5177
  • SHA2-512/256A5177
  • SHA2-512A5177
  • SHA3-224A5177
  • SHA3-256A5177
  • SHA3-384A5177
  • SHA3-512A5177
  • SHAKE-128A5177
  • SHAKE-256A5177
  • TLS v1.2 KDF RFC7627A5177
  • TLS v1.3 KDFA5177
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, HMAC, KMAC, CMAC
Asymmetric Algorithms
ECDSA, ECC, Diffie-Hellman, DHE
Hash functions
SHA-1, SHA1, SHA3-224, SHA3-256, SHA3-512, SHA3-384, PBKDF, PBKDF2
Schemes
MAC, Key Agreement
Protocols
SSH, TLS, TLS v1.2, TLS v1.3, IKEv2, IPsec
Randomness
DRBG, RBG
Elliptic Curves
P-224, P-256, P-384, P-521, P-192, B-233, B-283, B-409, B-571, K-233, K-409, K-571, B-163, K-283, K-163
Block cipher modes
CTR, GCM, XTS

Trusted Execution Environments
PSP, SSC

Security level
Level 2

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5079,
  "dgst": "c567607d29893662",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "KDF SSHA5177",
        "HMAC-SHA2-512A5177",
        "AES-XTS Testing Revision 2.0A5177",
        "HMAC-SHA3-224A5177",
        "ECDSA SigVer (FIPS186-4)A5177",
        "RSA SigVer (FIPS186-4)A5177",
        "SHAKE-256A5177",
        "KDA OneStep SP800-56Cr2A5177",
        "Safe Primes Key VerificationA5177",
        "KDF ANS 9.42A5177",
        "AES-CBC-CS3A5177",
        "KAS-FFC-SSC Sp800-56Ar3A5177",
        "SHA-1A5177",
        "KAS-ECC-SSC Sp800-56Ar3A5177",
        "SHA2-384A5177",
        "SHA2-512A5177",
        "KDF ANS 9.63A5177",
        "AES-GCMA5177",
        "HMAC DRBGA5177",
        "AES-OFBA5177",
        "AES-KWPA5177",
        "Safe Primes Key GenerationA5177",
        "SHA3-384A5177",
        "HMAC-SHA2-384A5177",
        "AES-CBC-CS2A5177",
        "KDA TwoStep SP800-56Cr2A5177",
        "SHA2-512/256A5177",
        "HMAC-SHA3-384A5177",
        "HMAC-SHA3-512A5177",
        "HMAC-SHA2-224A5177",
        "AES-CBC-CS1A5177",
        "KDA HKDF SP800-56Cr2A5177",
        "#A5177",
        "AES-CFB128A5177",
        "AES-GMACA5177",
        "ECDSA KeyGen (FIPS186-4)A5177",
        "AES-ECBA5177",
        "SHA3-224A5177",
        "KDF SP800-108A5177",
        "SHAKE-128A5177",
        "KMAC-256A5177",
        "AES-CBCA5177",
        "Hash DRBGA5177",
        "AES-CFB1A5177",
        "AES-CTRA5177",
        "SHA2-256A5177",
        "HMAC-SHA2-512/256A5177",
        "KDF IKEv2A5177",
        "SHA2-512/224A5177",
        "RSA KeyGen (FIPS186-4)A5177",
        "PBKDFA5177",
        "SHA3-512A5177",
        "AES-CCMA5177",
        "KAS-ECC CDH-Component SP800-56Ar3A5177",
        "ECDSA KeyVer (FIPS186-4)A5177",
        "SHA2-224A5177",
        "RSA Signature PrimitiveA5177",
        "TLS v1.3 KDFA5177",
        "KTS-IFCA5177",
        "RSA SigGen (FIPS186-4)A5177",
        "ECDSA SigGen (FIPS186-4)A5177",
        "HMAC-SHA2-512/224A5177",
        "AES-CFB8A5177",
        "HMAC-SHA-1A5177",
        "HMAC-SHA3-256A5177",
        "SHA3-256A5177",
        "HMAC-SHA2-256A5177",
        "KAS-IFC-SSCA5177",
        "TLS v1.2 KDF RFC7627A5177",
        "Counter DRBGA5177",
        "KMAC-128A5177",
        "AES-KWA5177",
        "AES-CMACA5177"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS1",
            "cavpCertName": "A5177",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS2",
            "cavpCertName": "A5177",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS3",
            "cavpCertName": "A5177",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A5177",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB1",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A5177",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5177",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A5177",
            "properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A5177",
            "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K- 283, K-409, K-571, P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A5177",
            "properties": "Curve - B-163, B-233, B-283, B-409, B-571, K- 163, K-233, K-283, K-409, K-571, P-192, P- 224, P-256, P-384, P-521",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A5177",
            "properties": "Component - No, Yes Curve - B-233, B-283, B-409, B-571, K-233, K- 283, K-409, K-571, P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A5177",
            "properties": "Component - No, Yes Curve - B-163, B-233, B-283, B-409, B-571, K- 163, K-233, K-283, K-409, K-571, P-192, P- 224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "A5177",
            "properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A5177",
            "properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/224",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/256",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-224",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-256",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-384",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-512",
            "cavpCertName": "A5177",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC CDH- Component SP800-56Ar3 (CVL)",
            "cavpCertName": "A5177",
            "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K- 283, K-409, K-571, P-224, P-256, P-384, P-521",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A5177",
            "properties": "Domain Parameter Generation Methods - B- 233, B-283, B-409, B-571, K-233, K-283, K- 409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A5177",
            "properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-IFC-SSC",
            "cavpCertName": "A5177",
            "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF SP800-56Cr2",
            "cavpCertName": "A5177",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA OneStep SP800-56Cr2",
            "cavpCertName": "A5177",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA TwoStep SP800-56Cr2",
            "cavpCertName": "A5177",
            "properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A5177",
            "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A5177",
            "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Key Data Length - Key Data Length: 128, 4096",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF IKEv2 (CVL)",
            "cavpCertName": "A5177",
            "properties": "Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 224, 8192 Derived Keying Material Length - Derived Keying Material Length: 160, 16384 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SP800-108",
            "cavpCertName": "A5177",
            "properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8-4096 Increment 8",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A5177",
            "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KMAC-128",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "KMAC-256",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "KTS-IFC",
            "cavpCertName": "A5177",
            "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024",
            "reference": "SP 800-56B Rev. 2"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A5177",
            "properties": "Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A5177",
            "properties": "Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - Standard",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A5177",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA Signature Primitive (CVL)",
            "cavpCertName": "A5177",
            "properties": "Private Key Format - crt",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A5177",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A5177",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A5177",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 160, 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 224, 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 256, 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 384, 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 512, 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/224",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 224, 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 256, 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A5177",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-128",
            "cavpCertName": "A5177",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-256",
            "cavpCertName": "A5177",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A5177",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A5177",
            "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
            "reference": "SP 800-135 Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Perform module initializa tion, pre- operatio nal, and conditio nal cryptogr aphic algorith m self- tests.",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "Power",
            "name": "Module Self- Test",
            "outputs": "Status",
            "rolesSspAccess": "Cryptogr aphic Officer - Software Integrity Key: E - CO Authenti cation Key: E",
            "secFunImpl": "None"
          },
          {
            "description": "Shows module\u0027s status",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "None",
            "name": "Show Status",
            "outputs": "Status",
            "rolesSspAccess": "Cryptogr aphic Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Shows module\u0027s versioni ng informat ion",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "None",
            "name": "Show Version",
            "outputs": "Module Base Name + Module Version Number",
            "rolesSspAccess": "Cryptogr aphic Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Encrypti on and decrypti on of data.",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "AES Key, Plaint ext or Cipher text",
            "name": "Symmetric Encryption/D ecryption",
            "outputs": "Plaintext or Cipherte xt",
            "rolesSspAccess": "Cryptogr aphic Officer - AES Key: W,E,Z",
            "secFunImpl": "BCU BCA"
          },
          {
            "description": "Compute a Message Authenti cation Code",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "Messa ge, HMA C, AES, or KMA C Key",
            "name": "Keyed MAC",
            "outputs": "Message Authenti cation Code",
            "rolesSspAccess": "Cryptogr aphic Officer - AES Key: W,E,Z - MAC Key: W,E,Z",
            "secFunImpl": "MAC"
          },
          {
            "description": "Compute a Message Digest",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "Messa ge",
            "name": "Hash",
            "outputs": "Hash Value",
            "rolesSspAccess": "Cryptogr aphic Officer",
            "secFunImpl": "SHS"
          },
          {
            "description": "Generate random values",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "DRB G Selecti on",
            "name": "Random Bit Generation",
            "outputs": "Random Values",
            "rolesSspAccess": "Cryptogr aphic Officer - DRBG- V: W,E,Z - DRBG- C: W,E,Z - DRBG- Key: W,E,Z - DRBG- EI: G,W,E,Z",
            "secFunImpl": "RAN D"
          },
          {
            "description": "Signatur e Generati on",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR()=1",
            "inputs": "Privat e Key, Messa ge",
            "name": "Signature Generation",
            "outputs": "Digital Signatur e",
            "rolesSspAccess": "Cryptogr aphic Officer - RSA Private Key: W,E,Z - ECDSA Private Key:",
            "secFunImpl": "SigGe n"
          },
          {
            "description": "Signatur e Verificat ion",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "Public Key, Signat ure",
            "name": "Signature Verification",
            "outputs": "Status",
            "rolesSspAccess": "Cryptogr aphic Officer - RSA Public Key: W,E,Z - ECDSA Public Key: W,E,Z",
            "secFunImpl": "SigVe r"
          },
          {
            "description": "Generate asymmet ric keys",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "Key Attrib utes,",
            "name": "Key Generation",
            "outputs": "Private Key,",
            "rolesSspAccess": "Cryptogr aphic Officer",
            "secFunImpl": "AKP- KG AKP-"
          },
          {
            "description": "(i.e., RSA, EC)",
            "indicator": "",
            "inputs": "Key Size",
            "name": "",
            "outputs": "Public Key",
            "rolesSspAccess": "- DRBG- V: E,Z - RSA Private Key: G,R,Z - RSA Public Key: G,R,Z - ECDSA Private Key: G,R,Z - ECDSA Public Key: G,R,Z - KAS Private Key: G,R,Z - KAS Public Key: G,R,Z - DRBG- C: E,Z - DRBG-",
            "secFunImpl": "DP RAN D KAS- KG Sym- KG"
          },
          {
            "description": "Asymme tric Key Verificat ion",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "Public Key",
            "name": "Key Verification",
            "outputs": "Validity",
            "rolesSspAccess": "Key: E,Z Cryptogr aphic Officer - ECDSA Public Key: W,E,Z - KAS Public",
            "secFunImpl": "AKP- KV AKV- PKV"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Key: W,E,Z",
            "secFunImpl": ""
          },
          {
            "description": "Derive keys using SP800- 56Cr2, SP800- 135, SP800- 108, or SP800- 132 key derivatio n methods",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "Key Materi al, Passp hrase",
            "name": "Key Derivation",
            "outputs": "Key Material",
            "rolesSspAccess": "Cryptogr aphic Officer - AES Key: W,E,Z - MAC Key: W,E,Z - Key Material: G,R,W,E ,Z - Passphra se:",
            "secFunImpl": "KDF KDA KBK DF PBK DF"
          },
          {
            "description": "Key agreeme nt using KAS- ECC, KAS- FFC, or KAS- IFC",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "RSA or KAS Public and Privat e Keys",
            "name": "Shared Secret Calculation",
            "outputs": "Key Material",
            "rolesSspAccess": "W,E,Z Cryptogr aphic Officer - Key Material: G,R,Z - RSA Private Key: W,E,Z - RSA Public Key: W,E,Z - KAS Private Key: W,E,Z - KAS Public Key: W,E,Z",
            "secFunImpl": "SSC"
          },
          {
            "description": "Key transport using AES- KW or KTS- IFC",
            "indicator": "OSSL_FIPS_PARAM_I NDICATOR",
            "inputs": "AES Key, RSA Key",
            "name": "Key Transport",
            "outputs": "Wrapped or Encapsul ated Key",
            "rolesSspAccess": "Cryptogr aphic Officer - AES Key: W,E,Z - RSA Public Key: W,E,Z - RSA Private Key: W,E,Z",
            "secFunImpl": "BCA AKP- E AKP- D"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [
          {
            "description": "Signature Verification",
            "mechanism": "SigVer",
            "name": "Role Based Authentication",
            "perMinute": "Each authentication attempt takes approximately 0.3 seconds, which results in a maximum of 200 authentication attempts per minute. The probably of a brute force attack being successful within a given minute is 200/(2^128).",
            "strength": "RSA 3072-bit has a security strength of 128 bits. The probability of successfully guessing the private key is 1/(2^128)."
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-GCM Encrypt",
            "condition": "Power-On",
            "details": "Encrypt",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "Key size: 256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM Decrypt",
            "condition": "Power-On",
            "details": "Decrypt",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "Key size: 256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5177)",
            "condition": "Power-On",
            "details": "Decrypt",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "Key size: 128 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A5177)",
            "condition": "Power-On",
            "details": "instantiation, generate, and reseed",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "Key size: 128",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Hash DRBG (A5177)",
            "condition": "Power-On",
            "details": "instantiation, generate, and reseed",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A5177)",
            "condition": "Power-On",
            "details": "instantiation, generate, and reseed",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5177)",
            "condition": "Power-On",
            "details": "Generate/Verify",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KMAC-256 (A5177)",
            "condition": "Power-On",
            "details": "Generate/Verify",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "KMAC-256 with 384-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-4) (A5177)",
            "condition": "Power-On",
            "details": "Signature Generation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "PKCS#1, SHA2- 256 with 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A5177)",
            "condition": "Power-On",
            "details": "Signature Verification",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "PKCS#1, SHA2- 256 with 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-4) (A5177)",
            "condition": "Upon key generation",
            "details": "Encrypt/Decrypt",
            "indicator": "OSSL_PROV_PARAM_STATUS = 1 (ok) OSSL_PROV_PARAM_STATUS = 0 (error)",
            "testMethod": "PCT",
            "testProps": "Key Generation",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "SHA-1 (A5177)",
            "condition": "Power-On",
            "details": "Generate/Verify",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A5177)",
            "condition": "Power-On",
            "details": "Generate/Verify",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A5177)",
            "condition": "Power-On",
            "details": "Generate/Verify",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA3-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A5177)",
            "condition": "Power-On",
            "details": "Signature Generation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "P-224, B-233 with SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A5177)",
            "condition": "Power-On",
            "details": "Signature Verification",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "P-224, B-233 with SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A5177)",
            "condition": "Power-On",
            "details": "Shared Secret Calculation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 (A5177)",
            "condition": "Power-On",
            "details": "Shared Secret Calculation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "ffdhe2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Safe Primes Key Generation (A5177)",
            "condition": "Upon key generation",
            "details": "SP800-56Ar3 PCT",
            "indicator": "OSSL_PROV_PARAM_STATUS = 1 (ok) OSSL_PROV_PARAM_STATUS = 0 (error)",
            "testMethod": "PCT",
            "testProps": "Key Generation",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A5177)",
            "condition": "Upon key generation",
            "details": "Sign/Verify",
            "indicator": "OSSL_PROV_PARAM_STATUS = 1 (ok) OSSL_PROV_PARAM_STATUS = 0 (error)",
            "testMethod": "PCT",
            "testProps": "Key Generation",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 384-bit secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.3 KDF (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 256-bit Key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "HMAC SHA2- 256 with 24 character passphrase",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS-IFC (A5177)",
            "condition": "Power-On",
            "details": "Encrypt/Decrypt",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "2048-bit Key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA-1 with 1056- bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SP800- 108 (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "HMAC SHA2- 256, Counter Mode, 128-bit. CMAC AES-128, Counter Mode, 128-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF IKEv2 (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA-1, 192-bit secret, 160-bit skeyseed",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 192- bit secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "SHA-1, 160-bit secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA HKDF SP800-56Cr2 (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "HMAC SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA OneStep SP800-56Cr2 (A5177)",
            "condition": "Power-On",
            "details": "Key Derivation",
            "indicator": "SELF_TEST_post success SELF_TEST_post failure",
            "testMethod": "KAT",
            "testProps": "HMAC SHA2- 224 with 448-bit secret",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "The Module enters the error state",
            "description": "The module fails pre-operational self-tests, conditional self- tests, or authentication.",
            "indicator": "OSSL_PROV_PARAM_STATUS = 0",
            "name": "ES1",
            "recoveryMethod": "Power cycle the module"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "The module supports Approved services in the Approved mode of operation. Non-Approved services are not supported in this mode.",
            "name": "Approved",
            "statusIndicator": "FIPS Indicator:",
            "type": "Approved"
          },
          {
            "description": "The module is capable of non-approved services in the non-approved mode of operation only.",
            "name": "Non- Approved",
            "statusIndicator": "FIPS Indicator: not-approved",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "AES (GCM) - Ext IV",
            "use": "GCM with Externally Generated IVs"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "AES (GCM) -",
            "description": "GCM using externally",
            "name": "Authenticated Symmetric",
            "role": "CO"
          },
          {
            "alg_accessed": "Ext IV",
            "description": "generated IVs",
            "name": "Encryption/Decryption",
            "role": ""
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "o API input arguments that are used to initialize and control the operation of the module o API Commands invoking cryptographic services",
            "logicalInterface": "Control Input",
            "physicalPort": "N/A"
          },
          {
            "data": "o API input arguments that provide input data for processing o Data to be encrypted, decrypted, verified, signed, or hashed o Keys to be used in cryptographic services o Random seed material for Module\u0027s DRBG o Keying Material to be used as input to key establishment services",
            "logicalInterface": "Data Input",
            "physicalPort": "N/A"
          },
          {
            "data": "o API output arguments that return generated or processed data back to the caller o Data that has been encrypted, decrypted, signed, or verified o Hashes o Random Values generated by the module\u0027s DRBG o o Keys Established using module\u0027s key establishment methods",
            "logicalInterface": "Data Output",
            "physicalPort": "N/A"
          },
          {
            "data": "o API call return values o Status information regarding the module",
            "logicalInterface": "Status Output",
            "physicalPort": "N/A"
          },
          {
            "data": "N/A",
            "logicalInterface": "Power",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "Role Based Authentication",
            "name": "Cryptographic Officer",
            "operatorType": "CO",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "2",
            "section": "1",
            "title": "General"
          },
          {
            "level": "2",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "2",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "2",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "2",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "2",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "2",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "2",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "2",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "2",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "Software Integrity Test",
            "details": "HMAC-SHA2-256 Verify",
            "indicator": "verify_integrity_success or verify_integrity failure",
            "testMethod": "KAT",
            "testProps": "HMAC SHA2- 256",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "System Memory (S1)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Input in plaintext (IO1)",
            "sfiAlgo": "",
            "source": "Application Software (outside)"
          },
          {
            "dest": "Application Software (outside)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Output in plaintext (IO2)",
            "sfiAlgo": "",
            "source": "System Memory (S1)"
          },
          {
            "dest": "System Memory (S1)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Input encapsulated (IO3)",
            "sfiAlgo": "AKP-D",
            "source": "Application Software (outside)"
          },
          {
            "dest": "Application Software (outside)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Output encapsulated (IO4)",
            "sfiAlgo": "AKP-E",
            "source": "System Memory (S1)"
          },
          {
            "dest": "System Memory (S1)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Input wrapped (IO5)",
            "sfiAlgo": "BCA",
            "source": "Application Software (outside)"
          },
          {
            "dest": "Application Software (outside)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "Output wrapped (IO6)",
            "sfiAlgo": "BCA",
            "source": "System Memory (S1)"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Zeroisation upon use",
            "method": "Z1",
            "operatorId": "Automatic upon use",
            "rationale": "Active overwriting of SSP values with 0s immediately after SSP is no longer needed"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Stored in plaintext in volatile memory (RAM).",
            "name": "System Memory (S1)",
            "persistance": "Dynamic"
          },
          {
            "description": "Stored in plaintext as part of the module binary itself.",
            "name": "Binary (S2)",
            "persistance": "Static"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "",
            "integrityTest": "HMAC-SHA2-256",
            "packageFileName": "Wave Relay User Space Crypto Module",
            "swFwVersion": "1.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "MPU (5th Generation)",
            "hypervisorHostOs": "",
            "operatingSystem": "Wave Relay\u00ae OS 2.2",
            "paa_pai": "Yes",
            "processors": "MCIMX6Q6AVT10AE, MCIMX6Q6AVT10AD",
            "version": "1.0"
          },
          {
            "hardwarePlatform": "Embedded Module",
            "hypervisorHostOs": "",
            "operatingSystem": "Wave Relay\u00ae OS 2.2",
            "paa_pai": "Yes",
            "processors": "MCIMX6Q7CZK08AE, MSCMMX6QZCK08AB",
            "version": "1.0"
          },
          {
            "hardwarePlatform": "Embedded Module lite",
            "hypervisorHostOs": "",
            "operatingSystem": "Wave Relay\u00ae OS 2.2",
            "paa_pai": "Yes",
            "processors": "MCIMX6Q7CZK08AE, MSCMMX6QZCK08AB",
            "version": "1.0"
          },
          {
            "hardwarePlatform": "GVR5",
            "hypervisorHostOs": "",
            "operatingSystem": "Wave Relay\u00ae OS 2.2",
            "paa_pai": "Yes",
            "processors": "MCIMX6Q7CZK08AE",
            "version": "1.0"
          },
          {
            "hardwarePlatform": "Integrated Antenna Series",
            "hypervisorHostOs": "",
            "operatingSystem": "Wave Relay\u00ae OS 2.2",
            "paa_pai": "Yes",
            "processors": "MCIMX6Q7CZK08AE",
            "version": "1.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "Key Type:Symmetric and Asymmetric",
            "implName": "N/A",
            "name": "CKG - Symmetric and Asymmetric",
            "reference": "SP800-133rev2, Section 4, Example 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 3
          },
          "ECDSA": {
            "ECDSA": 25
          }
        },
        "FF": {
          "DH": {
            "DHE": 2,
            "Diffie-Hellman": 2
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CTR": {
          "CTR": 1
        },
        "GCM": {
          "GCM": 5
        },
        "XTS": {
          "XTS": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKEv2": 3
        },
        "IPsec": {
          "IPsec": 1
        },
        "SSH": {
          "SSH": 3
        },
        "TLS": {
          "TLS": {
            "TLS": 1,
            "TLS v1.2": 4,
            "TLS v1.3": 4
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1
        },
        "MAC": {
          "MAC": 18
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "B-163": 11,
          "B-233": 29,
          "B-283": 20,
          "B-409": 27,
          "B-571": 25,
          "K-163": 9,
          "K-233": 24,
          "K-283": 25,
          "K-409": 20,
          "K-571": 23,
          "P-192": 10,
          "P-224": 42,
          "P-256": 56,
          "P-384": 44,
          "P-521": 46
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 2,
          "AES- 128, 192": 1,
          "AES- 256": 3,
          "AES-128": 6,
          "AES-192": 5,
          "AES-256": 2,
          "HMAC-SHA-1": 8,
          "PKCS 1": 6,
          "PKCS#1": 4,
          "SHA-1": 47,
          "SHA1": 1,
          "SHA2- 224": 6,
          "SHA2- 256": 15,
          "SHA2- 384": 1,
          "SHA2- 512": 8,
          "SHA2-224": 50,
          "SHA2-256": 63,
          "SHA2-384": 58,
          "SHA2-512": 56,
          "SHA2-512 20": 1,
          "SHA2-512 31": 1,
          "SHA3- 384": 2,
          "SHA3-224": 5,
          "SHA3-256": 8,
          "SHA3-384": 3,
          "SHA3-512": 5
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 2
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 7,
          "PBKDF2": 2
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 47,
            "SHA1": 1
          },
          "SHA3": {
            "SHA3-224": 5,
            "SHA3-256": 8,
            "SHA3-384": 3,
            "SHA3-512": 5
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 23
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 8,
          "FIPS 180-4": 7,
          "FIPS 186-4": 9,
          "FIPS 198-1": 11,
          "FIPS 202": 7,
          "FIPS PUB 140-3": 1,
          "FIPS140-3": 2,
          "FIPS186-4": 23
        },
        "NIST": {
          "SP 800-108": 1,
          "SP 800-132": 1,
          "SP 800-135": 6,
          "SP 800-185": 2,
          "SP 800-38A": 10,
          "SP 800-38B": 1,
          "SP 800-38C": 1,
          "SP 800-38D": 3,
          "SP 800-38E": 1,
          "SP 800-38F": 2,
          "SP 800-56A": 6,
          "SP 800-56B": 1,
          "SP 800-56C": 3,
          "SP 800-90A": 3
        },
        "PKCS": {
          "PKCS 1": 4,
          "PKCS#1": 2
        },
        "RFC": {
          "RFC7627": 3
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 13,
            "AES-": 5,
            "AES-128": 6,
            "AES-192": 5,
            "AES-256": 2
          },
          "CAST": {
            "CAST": 56
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 17,
            "KMAC": 1
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 4
        },
        "IBM": {
          "SSC": 11
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "KDF SSHA5177",
        "HMAC-SHA2-512A5177",
        "AES-XTS Testing Revision 2.0A5177",
        "HMAC-SHA3-224A5177",
        "ECDSA SigVer (FIPS186-4)A5177",
        "RSA SigVer (FIPS186-4)A5177",
        "SHAKE-256A5177",
        "KDA OneStep SP800-56Cr2A5177",
        "Safe Primes Key VerificationA5177",
        "KDF ANS 9.42A5177",
        "AES-CBC-CS3A5177",
        "KAS-FFC-SSC Sp800-56Ar3A5177",
        "SHA-1A5177",
        "KAS-ECC-SSC Sp800-56Ar3A5177",
        "SHA2-384A5177",
        "KDF ANS 9.63A5177",
        "AES-GCMA5177",
        "HMAC DRBGA5177",
        "Safe Primes Key GenerationA5177",
        "AES-OFBA5177",
        "AES-KWPA5177",
        "HMAC-SHA2-384A5177",
        "SHA2-512A5177",
        "SHA3-384A5177",
        "AES-CBC-CS2A5177",
        "KDA TwoStep SP800-56Cr2A5177",
        "SHA2-512/256A5177",
        "HMAC-SHA3-384A5177",
        "HMAC-SHA3-512A5177",
        "HMAC-SHA2-224A5177",
        "AES-CBC-CS1A5177",
        "KDA HKDF SP800-56Cr2A5177",
        "AES-CFB128A5177",
        "AES-GMACA5177",
        "ECDSA KeyGen (FIPS186-4)A5177",
        "AES-ECBA5177",
        "SHA3-224A5177",
        "KDF SP800-108A5177",
        "KMAC-256A5177",
        "AES-CBCA5177",
        "SHAKE-128A5177",
        "Hash DRBGA5177",
        "AES-CFB1A5177",
        "AES-CTRA5177",
        "SHA2-256A5177",
        "HMAC-SHA2-512/256A5177",
        "KDF IKEv2A5177",
        "SHA2-512/224A5177",
        "RSA KeyGen (FIPS186-4)A5177",
        "PBKDFA5177",
        "SHA3-512A5177",
        "AES-CCMA5177",
        "KAS-ECC CDH-Component SP800-56Ar3A5177",
        "ECDSA KeyVer (FIPS186-4)A5177",
        "SHA2-224A5177",
        "KTS-IFCA5177",
        "RSA Signature PrimitiveA5177",
        "TLS v1.3 KDFA5177",
        "RSA SigGen (FIPS186-4)A5177",
        "ECDSA SigGen (FIPS186-4)A5177",
        "HMAC-SHA2-512/224A5177",
        "AES-CFB8A5177",
        "HMAC-SHA-1A5177",
        "HMAC-SHA2-256A5177",
        "HMAC-SHA3-256A5177",
        "SHA3-256A5177",
        "KAS-IFC-SSCA5177",
        "TLS v1.2 KDF RFC7627A5177",
        "Counter DRBGA5177",
        "KMAC-128A5177",
        "AES-KWA5177",
        "AES-CMACA5177"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A5177"
      ]
    },
    "policy_metadata": {
      "/Author": "Hawes, David J. (Fed)",
      "/Comments": "",
      "/Company": "",
      "/ContentTypeId": "0x010100DDAED41F50E7E1489940D8989E1CB412",
      "/CreationDate": "D:20251008094437-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/MediaServiceImageTags": "",
      "/ModDate": "D:20251008094605-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.51",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "",
      "/_dlc_DocIdItemGuid": "d99cb545-c615-4aff-9c49-97c1576b5f50",
      "pdf_file_size_bytes": 719136,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=37787"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 70
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "ad6a96c74685e253ff98da66b4a713b2c59fb903dcc7f5f0998af518d2da91c2",
      "source_hash": "5e164cc8eb54c333c7e020540624ae9056cb67b21e83a6fe5187969e27051c32",
      "txt_hash": "d6297669a75e66c04531f91dcab747cb7f42fa9f453d7006b5e14d0a7fa9ad2c"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode, No assurance of the minimum strength of generated SSPs (e.g., keys)",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2025_181225_1202.pdf",
    "date_sunset": "2030-10-07",
    "description": "Persistent Systems LLC Wave Relay\u00ae User Space Crypto Module is a Software cryptographic module embedded in the Wave Relay\u00ae System that provides FIPS Validated cryptographic algorithms which are used by user space system services \u0026 protocols (e.g., TLS, IPsec, etc.).",
    "embodiment": "Single Chip",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Wave Relay\u00ae User Space Crypto Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-10-08",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Persistent Systems, LLC",
    "vendor_url": "http://www.persistentsystems.com/"
  }
}