Suite B Cryptographic Module

Certificate details

Certificate ID #2851
Status historical
Historical reason Moved to historical list due to dependency on certificate #2357
Validation dates 27.02.2017
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode with module Cryptographic Primitives Library (bcryptprimitives.dll and ncryptsslp.dll) in Microsoft Windows 8.1 Enterprise, Windows Server 2012 R2, Windows Storage Server 2012 R2, Surface Pro 3, Surface Pro 2, Surface Pro, Surface 2, Surface, Windows RT 8.1, Windows Phone 8.1, Windows Embedded 8.1 Industry Enterprise, StorSimple 8000 Series validated to FIPS 140-2 under Cert. #2357 operating in FIPS mode or BlackBerry OS Cryptographic Library validated to FIPS 140-2 under Cert. #1578 operating in FIPS mode
Exceptions
  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A
Description KEYW, in coordination with the United States Special Operations Command (USSOCOM), has developed a Suite B-compliant, standards based, AES/GCM-256 layer of encrypted communications between a BlackBerry Enterprise Server (BES) and a BlackBerry Mobile Set (MS) with Elliptic Curve (EC) key exchange used to negotiate symmetric keys.
Tested configurations
  • BlackBerry OS 10.3 running on Qualcomm Snapdragon 801
  • BlackBerry OS 10.3 running on Qualcomm Snapdragon S4
  • Microsoft Windows Server 2012 R2 (64-bit) running on Intel Xeon E5530 (single-user mode)
Vendor United States Special Operations Command (USSOCOM)
References

This certificate's webpage directly references 2 certificates, transitively this expands into 6 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-128, AES-192, AES-, HMAC, HMAC-SHA-224, HMAC-SHA-256, HMAC-SHA-512, HMAC-SHA-384, CMAC
Asymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-Hellman
Hash functions
SHA-1, SHA-160, SHA-224, SHA-384, SHA-256, SHA-512, PBKDF
Schemes
MAC, Key Agreement
Protocols
SSL, TLS
Randomness
DRBG, RBG
Elliptic Curves
P-192, P-224, P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR, GCM, XEX, XTS

Vendor
Qualcomm, Microsoft

Security level
Level 1, Level 2

Cross-references

Outgoing
  • 1578 - historical - BlackBerry OS Cryptographic Library
  • 2357 - historical - Cryptographic Primitives Library (bcryptprimitives.dll and ncryptsslp.dll) in Microsoft Windows 8.1 Enterprise, Windows Server 2012 R2, Windows Storage Server 2012 R2, Surface Pro 3, Surface Pro 2, Surface Pro, Surface 2, Surface, Windows RT 8.1, Windows Phone 8.1, Windows Embedded 8.1 Industry Enterprise, StorSimple 8000 Series, Azure StorSimple Virtual Array Windows Server 2012 R2
  • 523 - historical - Cryptek Common Security Module (CSM)

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

Loading...

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2851,
  "dgst": "d0541665ae524cf1",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "KAS#55",
        "KBKDF#116",
        "AES#4312",
        "SHS#2761",
        "AES#3328",
        "ECDSA#657",
        "CVL#484",
        "HMAC#2119",
        "KTS#3328"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "1578",
          "2357"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "2356",
          "2352",
          "2355",
          "1578",
          "2357",
          "2351"
        ]
      }
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": [
        "1578",
        "2357"
      ]
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "1578",
          "523",
          "2357"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "1609",
          "2356",
          "2352",
          "2355",
          "2357",
          "1494",
          "1578",
          "523",
          "2351"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "1578",
        "523",
        "2357"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 29
          },
          "ECDH": {
            "ECDH": 16
          },
          "ECDSA": {
            "ECDSA": 30
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 2
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CTR": {
          "CTR": 5
        },
        "ECB": {
          "ECB": 7
        },
        "GCM": {
          "GCM": 14
        },
        "XEX": {
          "XEX": 1
        },
        "XTS": {
          "XTS": 11
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "SSL": {
            "SSL": 1
          },
          "TLS": {
            "TLS": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 8
        },
        "MAC": {
          "MAC": 34
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-192": 10,
          "P-224": 36,
          "P-256": 36,
          "P-384": 32,
          "P-521": 36
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#116": 2,
          "#1578": 2,
          "#2119": 1,
          "#2357": 1,
          "#2761": 1,
          "#3328": 6,
          "#4312": 3,
          "#484": 1,
          "#523": 1,
          "#55": 1,
          "#657": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES-128": 5,
          "AES-192": 5,
          "Certificate AES": 1,
          "Certificate SHA": 1,
          "HMAC 2400": 2,
          "HMAC- 512": 2,
          "HMAC-512": 2,
          "HMAC-SHA- 224": 6,
          "HMAC-SHA- 384": 6,
          "HMAC-SHA-1": 20,
          "HMAC-SHA-224": 14,
          "HMAC-SHA-256": 2,
          "HMAC-SHA-384": 12,
          "HMAC-SHA-512": 2,
          "SHA 2300": 1,
          "SHA- 224": 1,
          "SHA-1": 20,
          "SHA-160": 23,
          "SHA-224": 25,
          "SHA-256": 13,
          "SHA-384": 26,
          "SHA-512": 15
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 6,
          "Level 2": 1
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 12
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 20
          },
          "SHA2": {
            "SHA-160": 23,
            "SHA-224": 25,
            "SHA-256": 13,
            "SHA-384": 26,
            "SHA-512": 15
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 34
        },
        "RNG": {
          "RBG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 65,
          "FIPS 180-4": 2,
          "FIPS 186-4": 3,
          "FIPS 197": 1,
          "FIPS 198-1": 1
        },
        "NIST": {
          "NIST SP 800-108": 2,
          "NIST SP 800-118": 1,
          "NIST SP 800-131A": 2,
          "NIST SP 800-132": 5,
          "NIST SP 800-38B": 1,
          "NIST SP 800-38D": 1,
          "NIST SP 800-56A": 3,
          "SP 800-108": 1
        },
        "RFC": {
          "RFC 5649": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 41,
            "AES-": 1,
            "AES-128": 5,
            "AES-192": 5
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 10,
            "HMAC": 38,
            "HMAC-SHA-224": 7,
            "HMAC-SHA-256": 1,
            "HMAC-SHA-384": 6,
            "HMAC-SHA-512": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Microsoft": {
          "Microsoft": 1
        },
        "Qualcomm": {
          "Qualcomm": 2
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/AAPL:Keywords": "[]",
      "/CreationDate": "D:20170209154410Z00\u002700\u0027",
      "/Creator": "Word",
      "/Keywords": "",
      "/ModDate": "D:20170209154410Z00\u002700\u0027",
      "/Producer": "Mac OS X 10.12.3 Quartz PDFContext",
      "/Title": "Microsoft Word - Suite_B_Cryptographic_Module_FIPS_140-2_Non-Proprietary_Security_Policy.docx",
      "pdf_file_size_bytes": 926157,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 44
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "e56a0009a270cf17c9ca284d21546c6682c97f9b26b5220a53436bc8334f6f7f",
      "txt_hash": "613f601e1f6076d3b74199667dd3273ce8f5553f0dbfa80e0aae9d3b5eb19528"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode with module Cryptographic Primitives Library (bcryptprimitives.dll and ncryptsslp.dll) in Microsoft Windows 8.1 Enterprise, Windows Server 2012 R2, Windows Storage Server 2012 R2, Surface Pro 3, Surface Pro 2, Surface Pro, Surface 2, Surface, Windows RT 8.1, Windows Phone 8.1, Windows Embedded 8.1 Industry Enterprise, StorSimple 8000 Series validated to FIPS 140-2 under Cert. #2357 operating in FIPS mode or BlackBerry OS Cryptographic Library validated to FIPS 140-2 under Cert. #1578 operating in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertFeb2017.pdf",
    "date_sunset": null,
    "description": "KEYW, in coordination with the United States Special Operations Command (USSOCOM), has developed a Suite B-compliant, standards based, AES/GCM-256 layer of encrypted communications between a BlackBerry Enterprise Server (BES) and a BlackBerry Mobile Set (MS) with Elliptic Curve (EC) key exchange used to negotiate symmetric keys.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: N/A",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to dependency on certificate #2357",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {
      "1578": 1,
      "2357": 1
    },
    "module_name": "Suite B Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "v3.0.0.0",
    "tested_conf": [
      "BlackBerry OS 10.3 running on Qualcomm Snapdragon 801",
      "BlackBerry OS 10.3 running on Qualcomm Snapdragon S4",
      "Microsoft Windows Server 2012 R2 (64-bit) running on Intel Xeon E5530 (single-user mode)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-02-27",
        "lab": "COACT INC CAFE LAB",
        "validation_type": "Initial"
      }
    ],
    "vendor": "United States Special Operations Command (USSOCOM)",
    "vendor_url": "http://www.socom.mil"
  }
}