{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "d554f1a19f5ac3d3", "cert_id": 5179, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Verkada Cryptographic Module", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-03-10", "validation_type": "Initial", "lab": "DEKRA Cybersecurity Certification Laboratory"}, {"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-07-31", "validation_type": "Update", "lab": "DEKRA Cybersecurity Certification Laboratory"}, {"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-08-05", "validation_type": "Update", "lab": "DEKRA Cybersecurity Certification Laboratory"}], "vendor_url": "https://verkada.com", "vendor": "Verkada, Inc.", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/March 2026_020426_1121-signed.pdf", "module_type": "Software", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "No assurance of the minimum strength of generated SSPs (e.g., keys) and random strings. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs", "exceptions": ["Physical security: N/A", "Non-invasive security: N/A"], "embodiment": "MultiChipStand", "description": "The Verkada Cryptographic Module is a software toolkit which provides various cryptographic functions to support the Verkada Command Platform.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2029-08-26", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {}, "fips_security_level": {"Level": {"Level 1": 2}}, "fips_certlike": {"Certlike": {"HMAC-SHA-256": 28, "HMAC-SHA-1": 16, "HMAC- SHA-1": 2, "HMAC 160": 1, "HMAC-SHA- 256": 4, "HMAC- SHA-256": 2, "HMAC 160, 224": 1, "SHA2-224": 26, "SHA2-256": 32, "SHA2-384": 28, "SHA2-512": 36, "SHA-1": 40, "SHA3-224": 14, "SHA3-256": 16, "SHA3-384": 14, "SHA3-512": 6, "SHA3- 512": 8, "SHA-2": 2, "SHA- 3": 1, "SHA-512": 15, "SHA-3": 1, "SHA- 1 1024": 1, "SHA-256": 17, "SHA-224": 2, "SHA3": 4, "- PKCS 1": 2, "PKCS 1": 6, "PKCS#1": 8, "AES-128": 4, "AES-192": 4, "AES-256": 4}}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-128": 4, "AES-192": 4, "AES-256": 4, "AES": 53, "AES-": 1}, "CAST": {"CAST": 162}}, "DES": {"3DES": {"Triple-DES": 6, "TDES": 4}}, "constructions": {"MAC": {"HMAC": 31, "HMAC-SHA-256": 14, "KMAC": 8, "CMAC": 2}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 6}, "ECDSA": {"ECDSA": 64}, "EdDSA": {"EdDSA": 22}, "ECC": {"ECC": 19}}, "FF": {"DH": {"DHE": 2, "Diffie-Hellman": 2, "DH": 31}, "DSA": {"DSA": 41}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 40}, "SHA2": {"SHA-512": 15, "SHA-256": 17, "SHA-224": 2, "SHA-2": 2}, "SHA3": {"SHA3-224": 14, "SHA3-256": 16, "SHA3-384": 14, "SHA3-512": 6, "SHA-3": 1, "SHA3": 4}}, "SHAKE": {"SHAKE256": 1}, "PBKDF": {"PBKDF": 16}}, "crypto_scheme": {"MAC": {"MAC": 48}, "KA": {"Key Agreement": 19}}, "crypto_protocol": {"SSH": {"SSH": 7, "SSHv2": 2}, "TLS": {"TLS": {"TLS 1.2": 10, "TLS v1.2": 7, "TLS v1.3": 7, "TLS 1.3": 9}}}, "randomness": {"PRNG": {"DRBG": 79}, "RNG": {"RNG": 22, "RBG": 23}}, "cipher_mode": {"CBC": {"CBC": 2}, "GCM": {"GCM": 10}, "XTS": {"XTS": 10}}, "ecc_curve": {"NIST": {"P-224": 38, "P-256": 30, "P-384": 30, "P-521": 30, "P-192": 12, "B-233": 15, "B-283": 13, "B-409": 12, "B-571": 15, "K-233": 19, "K-283": 13, "K-409": 15, "K-571": 12, "B-163": 6, "K-163": 6}, "Brainpool": {"brainpoolP224r1": 2, "brainpoolP256r1": 4, "brainpoolP320r1": 4, "brainpoolP384r1": 4, "brainpoolP512r1": 4}, "Edwards": {"Ed25519": 16, "Ed448": 16}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {"OpenSSL": {"OpenSSL": 8}}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"side-channel": 1, "timing attacks": 2, "timing attack": 1}}, "device_model": {}, "tee_name": {"AMD": {"PSP": 10}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 134, "FIPS 140": 8, "FIPS186-4": 41, "FIPS 186-4": 26, "FIPS 186-5": 11, "FIPS 198-1": 22, "FIPS 180-4": 14, "FIPS 202": 12, "FIPS 1865": 1}, "NIST": {"SP 800-38A": 20, "SP 800-38C": 2, "SP 800-38B": 2, "SP 800-38F": 5, "SP 800-38E": 3, "SP 800-90A": 10, "SP 800-56A": 10, "SP 800-56C": 6, "SP 800-135": 10, "SP 800-108": 4, "SP 800-185": 4, "SP 800-56B": 2, "SP 800-132": 7, "SP 800-67": 4, "SP 800-186": 2, "NIST SP 800-38D": 1}, "PKCS": {"PKCS 1": 4, "PKCS#1": 4}, "RFC": {"RFC7627": 6, "RFC 5288": 1, "RFC 5246": 1, "RFC 8446": 2, "RFC 7627": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 1847861, "pdf_is_encrypted": false, "pdf_number_of_pages": 122, "/Author": "Jing, Janet R. (Fed)", "/CreationDate": "D:20260805145444-04'00'", "/ModDate": "D:20260805145444-04'00'", "/Producer": "Microsoft: Print To PDF", "/Title": "Microsoft Word - TID-38-SV15-VAOE-IS-2608051654_140sp.docx", "pdf_hyperlinks": {"_type": "Set", "elements": []}}, "module_algorithms": {"_type": "Set", "elements": ["SHA2-384A5173", "KMAC-256A5173", "SHA2-512/224A5173", "TDES-ECBA5173", "HMAC-SHA3-512A5173", "KDF SP800-108A5173", "AES-GCMA5173", "KDF ANS 9.42A5173", "HMAC-SHA2-512A5173", "ECDSA SigVer (FIPS186-4)A5173", "RSA SigGen (FIPS186-4)A5173", "KDA HKDF SP800-56Cr2A5173", "AES-CFB8A5173", "AES-CFB1A5173", "AES-CBC-CS1A5173", "Hash DRBGA5173", "AES-CMACA5173", "SHA-1A5173", "EDDSA KeyGenA5173", "PBKDFA5173", "KDF SSHA5173", "SHA2-224A5173", "SHA3-224A5173", "ECDSA KeyVer (FIPS186-4)A5173", "DSA PQGVer (FIPS186-4)A5173", "HMAC-SHA2-224A5173", "Safe Primes Key GenerationA5173", "AES-OFBA5173", "AES-CBC-CS2A5173", "DSA PQGGen (FIPS186-4)A5173", "TLS v1.2 KDF RFC7627A5173", "AES-CCMA5173", "Counter DRBGA5173", "RSA KeyGen (FIPS186-4)A5173", "TLS v1.3 KDFA5173", "AES-CFB128A5173", "KAS-IFC-SSCA5173", "AES-CBC-CS3A5173", "AES-CBCA5173", "AES-XTS Testing Revision 2.0A5173", "SHA2-512A5173", "HMAC-SHA-1A5173", "SHA3-512A5173", "DSA SigVer (FIPS186-4)A5173", "EDDSA KeyVerA5173", "ECDSA KeyGen (FIPS186-4)A5173", "AES-GMACA5173", "SHAKE-128A5173", "KTS-IFCA5173", "HMAC-SHA2-512/224A5173", "EDDSA SigGenA5173", "HMAC-SHA2-384A5173", "HMAC-SHA3-256A5173", "HMAC-SHA2-512/256A5173", "RSA SigVer (FIPS186-4)A5173", "SHA3-384A5173", "KMAC-128A5173", "HMAC DRBGA5173", "EDDSA SigVerA5173", "SHA2-256A5173", "SHA2-512/256A5173", "HMAC-SHA3-224A5173", "KDF KMAC Sp800-108r1A5173", "SHAKE-256A5173", "Safe Primes Key VerificationA5173", "AES-KWA5173", "AES-KWPA5173", "KAS-ECC-SSC Sp800-56Ar3A5173", "KDA TwoStep SP800-56Cr2A5173", "KDF ANS 9.63A5173", "TDES-CBCA5173", "AES-CTRA5173", "KDA OneStep SP800-56Cr2A5173", "DSA KeyGen (FIPS186-4)A5173", "AES-ECBA5173", "ECDSA SigGen (FIPS186-4)A5173", "HMAC-SHA2-256A5173", "KAS-FFC-SSC Sp800-56Ar3A5173", "HMAC-SHA3-384A5173", "SHA3-256A5173"]}, "policy_algorithms": {"_type": "Set", "elements": ["#A4593", "#A5173"]}, "is_br1_format": true, "br1_deviations": 0, "br1_tables": {"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables", "security_levels": {"section": 1, "subsection": 2, "found": true, "entries": [{"section": "1", "title": "General", "level": "1"}, {"section": "2", "title": "Cryptographic module specification", "level": "1"}, {"section": "3", "title": "Cryptographic module interfaces", "level": "1"}, {"section": "4", "title": "Roles, services, and authentication", "level": "1"}, {"section": "5", "title": "Software/Firmware security", "level": "1"}, {"section": "6", "title": "Operational environment", "level": "1"}, {"section": "7", "title": "Physical security", "level": "N/A"}, {"section": "8", "title": "Non-invasive security", "level": "N/A"}, {"section": "9", "title": "Sensitive security parameter management", "level": "1"}, {"section": "10", "title": "Self-tests", "level": "1"}, {"section": "11", "title": "Life-cycle assurance", "level": "1"}, {"section": "12", "title": "Mitigation of other attacks", "level": "1"}, {"section": "", "title": "Overall Level", "level": "1"}]}, "tested_module_id_hw": {"section": 2, "subsection": 2, "found": false, "entries": []}, "tested_module_id_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"packageFileName": "fips.a", "swFwVersion": "3.0.1-FIPS 140-3", "features": "Compiled as a static library, tested on iOS and iPadOS", "integrityTest": "HMAC-SHA-256"}, {"packageFileName": "fips.dll", "swFwVersion": "3.0.0-FIPS 140-3", "features": "Compiled for Windows", "integrityTest": "HMAC-SHA-256"}, {"packageFileName": "fips.dylib", "swFwVersion": "3.0.0-FIPS 140-3", "features": "Compiled for MacOS", "integrityTest": "HMAC-SHA-256"}, {"packageFileName": "fips.so", "swFwVersion": "3.0.0-FIPS 140-3", "features": "Compiled for Linux, Unix, Android", "integrityTest": "HMAC-SHA-256"}]}, "tested_module_id_hw_hy": {"section": 2, "subsection": 2, "found": false, "entries": []}, "tested_op_env_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"operatingSystem": "AlmaLinux 9", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "AlmaLinux 9", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Android 13", "hardwarePlatform": "Google Pixel 7", "processors": "Google Tensor G2", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Debian 11", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Debian 11", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "FreeBSD 13", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "FreeBSD 13", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "iOS 16", "hardwarePlatform": "iPhone 13 Mini", "processors": "Apple A15 Bionic", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.1-FIPS 140-3"}, {"operatingSystem": "iPadOS 16", "hardwarePlatform": "iPad Air (2022)", "processors": "Apple M1", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.1-FIPS 140-3"}, {"operatingSystem": "macOS 13 (Ventura)", "hardwarePlatform": "Mac Mini M2", "processors": "Apple M2", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Oracle Solaris 11.4", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Oracle Solaris 11.4", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Red Hat Enterprise Linux 9", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Red Hat Enterprise Linux 9", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Rocky Linux 9", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Rocky Linux 9", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "SUSE Linux Enterprise Server 15", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "SUSE Linux Enterprise Server 15", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Ubuntu 22.04", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Ubuntu 22.04", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Windows 10", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Windows 10", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Windows 11", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Windows 11", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Windows Server 2019", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Windows Server 2019", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Windows Server 2022", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}, {"operatingSystem": "Windows Server 2022", "hardwarePlatform": "Dell PowerEdge R830", "processors": "Intel Xeon E5- 4667v4", "paa_pai": "No", "hypervisorHostOs": "", "version": "3.0.0-FIPS 140-3"}]}, "vendor_affirmed_op_env_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"operatingSystem": "AlmaLinux 9", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Android 13", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Debian 11", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "FreeBSD 13", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "iOS 16", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "iPadOS 16", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "macOS 13 (Ventura)", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Oracle Solaris 11.4", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Red Hat Enterprise Linux 9", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Rocky Linux 9", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "SUSE Linux Enterprise Server 15", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Ubuntu 22.04", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Windows 10", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Windows 11", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Windows Server 2019", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Windows Server 2022", "hardwarePlatform": "Any general-purpose platform that supports this OS"}, {"operatingSystem": "Verkada Linux v1.x", "hardwarePlatform": "Verkada FIPS Devices"}, {"operatingSystem": "GNU/Linux with Poky Distribution", "hardwarePlatform": "AArch64 architecture"}, {"operatingSystem": "GNU/Linux with Poky Distribution", "hardwarePlatform": "x86_64 architecture"}]}, "modes_of_operation": {"section": 2, "subsection": 4, "found": true, "entries": [{"name": "Approved Mode", "description": "Single approved mode of operation. No non- approved mode is implemented in the module.", "type": "Approved", "statusIndicator": "In alignment with IG 2.4.C example scenario 2, the module only provides approved services. The module provides a global indicator that services are approved. Additionally, the module provides a status code indicating the completion of each service, as indicated in Security Policy Section 4.3 - Approved Services. The successful completion of a service is an implicit indicator for the use of an approved service."}]}, "approved_algorithms": {"section": 2, "subsection": 5, "found": true, "entries": [{"algorithm": "AES-CBC", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS1", "cavpCertName": "A4593", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-65536 Increment 8", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS1", "cavpCertName": "A5173", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-65536 Increment 8", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS2", "cavpCertName": "A4593", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-65536 Increment 8", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS2", "cavpCertName": "A5173", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-65536 Increment 8", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS3", "cavpCertName": "A4593", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-65536 Increment 8", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS3", "cavpCertName": "A5173", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-65536 Increment 8", "reference": "SP 800-38A"}, {"algorithm": "AES-CCM", "cavpCertName": "A4593", "properties": "Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56-104 Increment 8 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0-524288 Increment 8", "reference": "SP 800-38C"}, {"algorithm": "AES-CCM", "cavpCertName": "A5173", "properties": "Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56-104 Increment 8 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0-524288 Increment 8", "reference": "SP 800-38C"}, {"algorithm": "AES-CFB1", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CFB1", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CFB128", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CFB128", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CFB8", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CFB8", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CMAC", "cavpCertName": "A4593", "properties": "Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 0-524288 Increment 8", "reference": "SP 800-38B"}, {"algorithm": "AES-CMAC", "cavpCertName": "A5173", "properties": "Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 0-524288 Increment 8", "reference": "SP 800-38B"}, {"algorithm": "AES-CTR", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - Yes", "reference": "SP 800-38A"}, {"algorithm": "AES-CTR", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - Yes", "reference": "SP 800-38A"}, {"algorithm": "AES-ECB", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-ECB", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-GCM", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2", "reference": "SP 800- 38D"}, {"algorithm": "", "cavpCertName": "", "properties": "Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96-1024 Increment 8 Payload Length - Payload Length: 0-65536 Increment 8 AAD Length - AAD Length: 0-65536 Increment 8", "reference": ""}, {"algorithm": "AES-GCM", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96-1024 Increment 8 Payload Length - Payload Length: 0-65536 Increment 8 AAD Length - AAD Length: 0-65536 Increment 8", "reference": "SP 800- 38D"}, {"algorithm": "AES-GMAC", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96-1024 Increment 8 AAD Length - AAD Length: 0-65536 Increment 8", "reference": "SP 800- 38D"}, {"algorithm": "AES-GMAC", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96-1024 Increment 8 AAD Length - AAD Length: 0-65536 Increment 8", "reference": "SP 800- 38D"}, {"algorithm": "AES-KW", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Cipher - Cipher, Inverse Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128", "reference": "SP 800-38F"}, {"algorithm": "AES-KW", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Cipher - Cipher, Inverse Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128", "reference": "SP 800-38F"}, {"algorithm": "AES-KWP", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Cipher - Cipher, Inverse", "reference": "SP 800-38F"}, {"algorithm": "", "cavpCertName": "", "properties": "Key Length - 128, 192, 256 Payload Length - Payload Length: 8-4096 Increment 8", "reference": ""}, {"algorithm": "AES-KWP", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Cipher - Cipher, Inverse Key Length - 128, 192, 256 Payload Length - Payload Length: 8-4096 Increment 8", "reference": "SP 800-38F"}, {"algorithm": "AES-OFB", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-OFB", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-XTS Testing Revision 2.0", "cavpCertName": "A4593", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - Yes", "reference": "SP 800-38E"}, {"algorithm": "AES-XTS Testing Revision 2.0", "cavpCertName": "A5173", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - Yes", "reference": "SP 800-38E"}, {"algorithm": "Counter DRBG", "cavpCertName": "A4593", "properties": "Prediction Resistance - Yes Supports Reseed - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0-256 Increment 256 Entropy Input - Entropy Input: 128-256 Increment 128, Entropy Input: 256-512 Increment 128 Nonce - Nonce: 128 Personalization String Length - Personalization String Length: 0-256 Increment 256 Returned Bits - 256", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "Counter DRBG", "cavpCertName": "A5173", "properties": "Prediction Resistance - Yes Supports Reseed - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0-256 Increment 256 Entropy Input - Entropy Input: 128-256 Increment 128, Entropy Input: 256-512 Increment 128", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "", "cavpCertName": "", "properties": "Nonce - Nonce: 128 Personalization String Length - Personalization String Length: 0-256 Increment 256 Returned Bits - 256", "reference": ""}, {"algorithm": "DSA KeyGen (FIPS186-4)", "cavpCertName": "A4593", "properties": "L - 2048 N - 224, 256", "reference": "FIPS 186-4"}, {"algorithm": "DSA KeyGen (FIPS186-4)", "cavpCertName": "A5173", "properties": "L - 2048 N - 224, 256", "reference": "FIPS 186-4"}, {"algorithm": "DSA PQGGen (FIPS186-4)", "cavpCertName": "A4593", "properties": "P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 2048 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "DSA PQGGen (FIPS186-4)", "cavpCertName": "A5173", "properties": "P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 2048 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "DSA PQGVer (FIPS186-4)", "cavpCertName": "A4593", "properties": "P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 1024, 2048 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "DSA PQGVer (FIPS186-4)", "cavpCertName": "A5173", "properties": "P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 1024, 2048 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "DSA SigVer (FIPS186-4)", "cavpCertName": "A4593", "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "DSA SigVer (FIPS186-4)", "cavpCertName": "A5173", "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA KeyGen (FIPS186-4)", "cavpCertName": "A4593", "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA KeyGen (FIPS186-4)", "cavpCertName": "A5173", "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA KeyVer (FIPS186-4)", "cavpCertName": "A4593", "properties": "Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA KeyVer (FIPS186-4)", "cavpCertName": "A5173", "properties": "Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA SigGen (FIPS186-4)", "cavpCertName": "A4593", "properties": "Component - No Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA SigGen (FIPS186-4)", "cavpCertName": "A5173", "properties": "Component - No Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA SigVer (FIPS186-4)", "cavpCertName": "A4593", "properties": "Component - No Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA SigVer (FIPS186-4)", "cavpCertName": "A5173", "properties": "Component - No Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512,", "reference": "FIPS 186-4"}, {"algorithm": "", "cavpCertName": "", "properties": "SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512", "reference": ""}, {"algorithm": "EDDSA KeyGen", "cavpCertName": "A4593", "properties": "Curve - ED-25519, ED-448", "reference": "FIPS 186-5"}, {"algorithm": "EDDSA KeyGen", "cavpCertName": "A5173", "properties": "Curve - ED-25519, ED-448", "reference": "FIPS 186-5"}, {"algorithm": "EDDSA KeyVer", "cavpCertName": "A4593", "properties": "Curve - ED-25519, ED-448", "reference": "FIPS 186-5"}, {"algorithm": "EDDSA KeyVer", "cavpCertName": "A5173", "properties": "Curve - ED-25519, ED-448", "reference": "FIPS 186-5"}, {"algorithm": "EDDSA SigGen", "cavpCertName": "A4593", "properties": "Curve - ED-25519, ED-448 PreHash - Yes", "reference": "FIPS 186-5"}, {"algorithm": "EDDSA SigGen", "cavpCertName": "A5173", "properties": "Curve - ED-25519, ED-448 PreHash - Yes", "reference": "FIPS 186-5"}, {"algorithm": "EDDSA SigVer", "cavpCertName": "A4593", "properties": "Curve - ED-25519, ED-448 PreHash - No Pure - Yes", "reference": "FIPS 186-5"}, {"algorithm": "EDDSA SigVer", "cavpCertName": "A5173", "properties": "Curve - ED-25519, ED-448 PreHash - No Pure - Yes", "reference": "FIPS 186-5"}, {"algorithm": "Hash DRBG", "cavpCertName": "A4593", "properties": "Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 128-256 Increment 64, Entropy Input: 256-320 Increment 64 Nonce - Nonce: 128-160 Increment 32, Nonce: 96-128 Increment 32 Personalization String Length - Personalization String Length: 0-256 Increment 128 Additional Input - Additional Input: 0-256 Increment 128", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "Hash DRBG", "cavpCertName": "A5173", "properties": "Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 128-256 Increment 64, Entropy Input: 256-320 Increment 64", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "", "cavpCertName": "", "properties": "Nonce - Nonce: 128-160 Increment 32, Nonce: 96-128 Increment 32 Personalization String Length - Personalization String Length: 0-256 Increment 128 Additional Input - Additional Input: 0-256 Increment 128 Returned Bits - 160, 256, 512", "reference": ""}, {"algorithm": "HMAC DRBG", "cavpCertName": "A4593", "properties": "Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160-256 Increment 32, Entropy Input: 256-512 Increment 64, Entropy Input: 512-1024 Increment 64 Nonce - Nonce: 128, Nonce: 64 Personalization String Length - Personalization String Length: 0-256 Increment 128 Additional Input - Additional Input: 0-256 Increment 128 Returned Bits - 160, 256, 512", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "HMAC DRBG", "cavpCertName": "A5173", "properties": "Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160-256 Increment 32, Entropy Input: 256-512 Increment 64, Entropy Input: 512-1024 Increment 64 Nonce - Nonce: 128, Nonce: 64 Personalization String Length - Personalization String Length: 0-256 Increment 128 Additional Input - Additional Input: 0-256 Increment 128 Returned Bits - 160, 256, 512", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "HMAC-SHA-1", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-160 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA-1", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-160 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 224", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 224", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 256", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 256", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 384", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 384", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512/224", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512/224", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512/256", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512/256", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 224", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 224", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 256", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 256", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 384", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 384", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 512", "cavpCertName": "A4593", "properties": "MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 512", "cavpCertName": "A5173", "properties": "MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "KAS-ECC-SSC Sp800-56Ar3", "cavpCertName": "A4593", "properties": "Domain Parameter Generation Methods - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KAS-ECC-SSC Sp800-56Ar3", "cavpCertName": "A5173", "properties": "Domain Parameter Generation Methods - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KAS-FFC-SSC Sp800-56Ar3", "cavpCertName": "A4593", "properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KAS-FFC-SSC Sp800-56Ar3", "cavpCertName": "A5173", "properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KAS-IFC-SSC", "cavpCertName": "A4593", "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime- factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder Fixed Public Exponent - 010001", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KAS-IFC-SSC", "cavpCertName": "A5173", "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime- factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "", "cavpCertName": "", "properties": "Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder Fixed Public Exponent - 010001", "reference": ""}, {"algorithm": "KDA HKDF SP800-56Cr2", "cavpCertName": "A4593", "properties": "Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 Perform Multiple Expansion Tests - No Uses Hybrid Shared Secret - No", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDA HKDF SP800-56Cr2", "cavpCertName": "A5173", "properties": "Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 Perform Multiple Expansion Tests - No Uses Hybrid Shared Secret - No", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDA OneStep SP800-56Cr2", "cavpCertName": "A4593", "properties": "Auxiliary Function Methods - Auxiliary Function Name - SHA-1 MAC Salting Methods - default, random Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDA OneStep SP800-56Cr2", "cavpCertName": "A5173", "properties": "Auxiliary Function Methods - Auxiliary Function Name - SHA-1 MAC Salting Methods - default, random Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDA TwoStep SP800-56Cr2", "cavpCertName": "A4593", "properties": "MAC Salting Methods - default, random Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation KDF Mode - feedback MAC Modes - HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, HMAC-SHA2-512/224, HMAC- SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512 Fixed Data Order - after fixed data Counter Lengths - 8 The KDF supports an empty IV - Yes The KDF requires an empty IV - Yes Supported Lengths - Supported Lengths: 2048 Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 Perform Multiple Expansion Tests - No", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDA TwoStep SP800-56Cr2", "cavpCertName": "A5173", "properties": "MAC Salting Methods - default, random Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation KDF Mode - feedback MAC Modes - HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, HMAC-SHA2-512/224, HMAC- SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512 Fixed Data Order - after fixed data Counter Lengths - 8 The KDF supports an empty IV - Yes The KDF requires an empty IV - Yes Supported Lengths - Supported Lengths: 2048 Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 Perform Multiple Expansion Tests - No Uses Hybrid Shared Secret - No", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDF ANS 9.42 (CVL)", "cavpCertName": "A4593", "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 Other Info Length - Other Info Length: 0-4096 Increment 8 zz Length - zz Length: 8-4096 Increment 8 Key Data Length - Key Data Length: 8-4096 Increment 8", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "", "cavpCertName": "", "properties": "Supplemental Information Length - Supplemental Information Length: 0-120 Increment 8 OID - AES-128-KW, AES-192-KW, AES-256-KW", "reference": ""}, {"algorithm": "KDF ANS 9.42 (CVL)", "cavpCertName": "A5173", "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 Other Info Length - Other Info Length: 0-4096 Increment 8 zz Length - zz Length: 8-4096 Increment 8 Key Data Length - Key Data Length: 8-4096 Increment 8 Supplemental Information Length - Supplemental Information Length: 0-120 Increment 8 OID - AES-128-KW, AES-192-KW, AES-256-KW", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "KDF ANS 9.63 (CVL)", "cavpCertName": "A4593", "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Field Size - 224, 571 Shared Info Length - Shared Info Length: 0, 1024 Key Data Length - Key Data Length: 128, 4096", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "KDF ANS 9.63 (CVL)", "cavpCertName": "A5173", "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Field Size - 224, 571 Shared Info Length - Shared Info Length: 0, 1024 Key Data Length - Key Data Length: 128, 4096", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "KDF KMAC Sp800-108r1", "cavpCertName": "A4593", "properties": "Key Derivation Key Length - Key Derivation Key Length: 112-4096 Increment 8 Context Length - Context Length: 8-4096 Increment 8 Label Length - Label Length: 8-4096 Increment 8 Derived Key Length - Derived Key Length: 112-4096 Increment 8 MAC Modes - KMAC-128, KMAC-256", "reference": "SP 800-108 Rev. 1"}, {"algorithm": "KDF KMAC Sp800-108r1", "cavpCertName": "A5173", "properties": "Key Derivation Key Length - Key Derivation Key Length: 112-4096 Increment 8 Context Length - Context Length: 8-4096 Increment 8 Label Length - Label Length: 8-4096 Increment 8 Derived Key Length - Derived Key Length: 112-4096 Increment 8 MAC Modes - KMAC-128, KMAC-256", "reference": "SP 800-108 Rev. 1"}, {"algorithm": "KDF SP800- 108", "cavpCertName": "A4593", "properties": "KDF Mode - Counter, Feedback MAC Mode - CMAC-AES128, CMAC-AES192, CMAC-AES256, HMAC- SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC- SHA2-512, HMAC-SHA2-512/224, HMAC-SHA2-512/256, HMAC-SHA3- 224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512", "reference": "SP 800-108 Rev. 1"}, {"algorithm": "", "cavpCertName": "", "properties": "Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096 Fixed Data Order - Before Fixed Data Counter Length - 32 Supports Empty IV - No Custom Key In Length - 0", "reference": ""}, {"algorithm": "KDF SP800- 108", "cavpCertName": "A5173", "properties": "KDF Mode - Counter, Feedback MAC Mode - CMAC-AES128, CMAC-AES192, CMAC-AES256, HMAC- SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC- SHA2-512, HMAC-SHA2-512/224, HMAC-SHA2-512/256, HMAC-SHA3- 224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512 Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096 Fixed Data Order - Before Fixed Data Counter Length - 32 Supports Empty IV - No Custom Key In Length - 0", "reference": "SP 800-108 Rev. 1"}, {"algorithm": "KDF SSH (CVL)", "cavpCertName": "A4593", "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "KDF SSH (CVL)", "cavpCertName": "A5173", "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "KMAC-128", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8 Hex Customization - No Supports eXtendable-Output Functions - No, Yes", "reference": "SP 800-185"}, {"algorithm": "KMAC-128", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8 Hex Customization - No Supports eXtendable-Output Functions - No, Yes", "reference": "SP 800-185"}, {"algorithm": "KMAC-256", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8 Hex Customization - No Supports eXtendable-Output Functions - No, Yes", "reference": "SP 800-185"}, {"algorithm": "KMAC-256", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8", "reference": "SP 800-185"}, {"algorithm": "", "cavpCertName": "", "properties": "Hex Customization - No Supports eXtendable-Output Functions - No, Yes", "reference": ""}, {"algorithm": "KTS-IFC", "cavpCertName": "A4593", "properties": "IUT ID - CAFECAFE Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime- factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Fixed Public Exponent - 010001 Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Hash Algorithms - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Supports Null Associated Data - Yes Associated Data Pattern - Associated Data Encoding - concatenation", "reference": "SP 800-56B Rev. 2"}, {"algorithm": "KTS-IFC", "cavpCertName": "A5173", "properties": "IUT ID - CAFECAFE Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime- factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Fixed Public Exponent - 010001 Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Hash Algorithms - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Supports Null Associated Data - Yes Associated Data Pattern - Associated Data Encoding - concatenation Key Length - 1024", "reference": "SP 800-56B Rev. 2"}, {"algorithm": "PBKDF", "cavpCertName": "A4593", "properties": "Iteration Count - Iteration Count: 1-10000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 Password Length - Password Length: 8-128 Increment 8 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 112-4096 Increment 8", "reference": "SP 800-132"}, {"algorithm": "PBKDF", "cavpCertName": "A5173", "properties": "Iteration Count - Iteration Count: 1-10000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 Password Length - Password Length: 8-128 Increment 8 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 112-4096 Increment 8", "reference": "SP 800-132"}, {"algorithm": "RSA KeyGen (FIPS186-4)", "cavpCertName": "A4593", "properties": "Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - Yes Public Exponent Mode - Random Private Key Format - Standard", "reference": "FIPS 186-4"}, {"algorithm": "RSA KeyGen (FIPS186-4)", "cavpCertName": "A5173", "properties": "Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - Yes Public Exponent Mode - Random Private Key Format - Standard", "reference": "FIPS 186-4"}, {"algorithm": "RSA SigGen (FIPS186-4)", "cavpCertName": "A4593", "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224", "reference": "FIPS 186-4"}, {"algorithm": "RSA SigGen (FIPS186-4)", "cavpCertName": "A5173", "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224", "reference": "FIPS 186-4"}, {"algorithm": "RSA SigVer (FIPS186-4)", "cavpCertName": "A4593", "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA-1 Public Exponent Mode - Random", "reference": "FIPS 186-4"}, {"algorithm": "RSA SigVer (FIPS186-4)", "cavpCertName": "A5173", "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA-1 Public Exponent Mode - Random", "reference": "FIPS 186-4"}, {"algorithm": "Safe Primes Key Generation", "cavpCertName": "A4593", "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "Safe Primes Key Generation", "cavpCertName": "A5173", "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "Safe Primes Key Verification", "cavpCertName": "A4593", "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "Safe Primes Key Verification", "cavpCertName": "A5173", "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "SHA-1", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA-1", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-224", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-224", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-256", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-256", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-384", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-384", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-512", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-512", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2- 512/224", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2- 512/224", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2- 512/256", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2- 512/256", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA3-224", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 202"}, {"algorithm": "SHA3-224", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 202"}, {"algorithm": "SHA3-256", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 202"}, {"algorithm": "SHA3-256", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 202"}, {"algorithm": "SHA3-384", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 202"}, {"algorithm": "SHA3-384", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 202"}, {"algorithm": "SHA3-512", "cavpCertName": "A4593", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 202"}, {"algorithm": "SHA3-512", "cavpCertName": "A5173", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 202"}, {"algorithm": "SHAKE-128", "cavpCertName": "A4593", "properties": "Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8", "reference": "FIPS 202"}, {"algorithm": "SHAKE-128", "cavpCertName": "A5173", "properties": "Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8", "reference": "FIPS 202"}, {"algorithm": "SHAKE-256", "cavpCertName": "A4593", "properties": "Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8", "reference": "FIPS 202"}, {"algorithm": "SHAKE-256", "cavpCertName": "A5173", "properties": "Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8", "reference": "FIPS 202"}, {"algorithm": "TDES-CBC", "cavpCertName": "A4593", "properties": "Direction - Decrypt Keying Option - 1", "reference": "SP 800-67 Rev. 2"}, {"algorithm": "TDES-CBC", "cavpCertName": "A5173", "properties": "Direction - Decrypt Keying Option - 1", "reference": "SP 800-67 Rev. 2"}, {"algorithm": "TDES-ECB", "cavpCertName": "A4593", "properties": "Direction - Decrypt Keying Option - 1", "reference": "SP 800-67 Rev. 2"}, {"algorithm": "TDES-ECB", "cavpCertName": "A5173", "properties": "Direction - Decrypt Keying Option - 1", "reference": "SP 800-67 Rev. 2"}, {"algorithm": "TLS v1.2 KDF RFC7627 (CVL)", "cavpCertName": "A4593", "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 Key Block Length - Key Block Length: 1024", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "TLS v1.2 KDF RFC7627 (CVL)", "cavpCertName": "A5173", "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 Key Block Length - Key Block Length: 1024", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "TLS v1.3 KDF (CVL)", "cavpCertName": "A4593", "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "TLS v1.3 KDF (CVL)", "cavpCertName": "A5173", "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE", "reference": "SP 800-135 Rev. 1"}]}, "vendor_affirmed_algos": {"section": 2, "subsection": 5, "found": true, "entries": [{"name": "CKG", "algoPropList": "Key Type:Symmetric and Asymmetric", "implName": "N/A", "reference": "SP 800-133r2 and IG D.H: Per Section 4, example 1"}, {"name": "CKG (XTS)", "algoPropList": "Key Type:Symmetric", "implName": "N/A", "reference": "SP 800-133r2 and IG D.H: Per Section 6.3, approved method 1. Applicable to AES-XTS compliant to IG C.I because Key_1 and Key_2 are concatenated prior to usage."}]}, "non_approved_allowed_algos": {"section": 2, "subsection": 5, "found": true, "entries": [{"name": "EC Diffie-Hellman with non-NIST recommended curves", "algoPropList": "Curves: brainpoolP224r1 (strength 112 bits) brainpoolP256r1 (strength 128 bits) brainpoolP320r1 (strength 160 bits) brainpoolP384r1 (strength 192 bits) brainpoolP512r1 (strength 256 bits) : SSP Agreement", "implName": "CryptoComply 140-3 FIPS Provider", "reference": "Allowed per IG D.F, scenario 3 (per IG C.A, category 1a and SP 800-186 Appendix H.1)"}, {"name": "ECDSA with non- NIST recommended curves", "algoPropList": "Curves: brainpoolP224r1 (strength 112 bits) brainpoolP256r1 (strength 128 bits) brainpoolP320r1 (strength 160 bits) brainpoolP384r1 (strength 192 bits) brainpoolP512r1 (strength 256 bits) : Signature Generation, Signature Verification, Key Generation, Key Verification", "implName": "CryptoComply 140-3 FIPS Provider", "reference": "Allowed per IG C.A, category 1a (per SP 800-186 Appendix H.1)"}]}, "non_approved_allowed_NSC": {"section": 2, "subsection": 5, "found": false, "entries": []}, "non_approved_not_allowed": {"section": 2, "subsection": 5, "found": false, "entries": []}, "ports_interfaces": {"section": 3, "subsection": 1, "found": true, "entries": [{"physicalPort": "N/A", "logicalInterface": "Data Input", "data": "API input parameters for data"}, {"physicalPort": "N/A", "logicalInterface": "Data Output", "data": "API output parameters for data"}, {"physicalPort": "N/A", "logicalInterface": "Control Input", "data": "API function calls"}, {"physicalPort": "N/A", "logicalInterface": "Status Output", "data": "API status outputs (return codes, error messages)"}]}, "authentication_methods": {"section": 4, "subsection": 1, "found": false, "entries": []}, "roles": {"section": 4, "subsection": 2, "found": true, "entries": [{"name": "Crypto Officer", "type": "Role", "operatorType": "CO", "authMethodList": "None"}]}, "approved_services": {"section": 4, "subsection": 3, "found": true, "entries": [{"name": "Module Initialisat ion", "description": "Initialize the FIPS module when it is loaded", "indicator": "API return value from OSSL_provider_init: 1 for success, 0 for failure", "inputs": "External dispatch (functio n", "outputs": "Internal dispatch (function pointer) table", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "", "description": "(calls pre- operatio nal self- tests and CASTs).", "indicator": "", "inputs": "pointer) table", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Self-Test", "description": "Performs pre- operatio nal self- tests and CASTs on demand.", "indicator": "API return value code from SELF_TEST_post(): 1 for success, 0 for failure", "inputs": "None", "outputs": "Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNN ING)", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "Integrity Test", "description": "Performs the integrity test on demand.", "indicator": "API return value from verify_integrity(): 1 for verified, 0 for failure", "inputs": "Expecte d HMAC", "outputs": "Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNN ING)", "secFunImpl": "IntegrityTest", "rolesSspAccess": "Crypto Officer"}, {"name": "Show Status", "description": "Provides status informati on by querying the \"status\" paramet er.", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for query operation completed successfully, 0 for failure to query the parameter", "inputs": "None", "outputs": "Module Status: Running (FIPS_STATE_RUNN ING), or Error (FIPS_STATE_ERRO R)", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "Output ID/ Version Informat ion (Show Version)", "description": "Displays FIPS module version by querying the \"version, \" \"name,\" and", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for query operation completed successfully, 0 for failure to query the parameter", "inputs": "None", "outputs": "name: 140-3 FIPS Provider version: 3.0.0-FIPS 140-3 or 3.0.1-FIPS 140-3 buildinfo: 3.0.0-FIPS 140-3 or 3.0.1-FIPS 140-3", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "", "description": "o\" paramet ers, with the results specified in the output column. The version aligns with the FIPS certificat e and Security Policy Section 2.2 - Tested and Vendor Affirmed Module Version and Identific", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Random Number Generati on", "description": "Used to seed/res eed a DRBG instance (includin g determin ing the security strength) or obtain random", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "Desired security strength in bits, entropy input", "outputs": "Random data", "secFunImpl": "RNG CKG", "rolesSspAccess": "Crypto Officer - DRBG Entropy Input: W,E,Z - CTR_DR BG Seed: G,E,Z - CTR_DR"}, {"name": "", "description": "data. Random data may be used for CKG per SP 800- 133r2. Establish ed SSPs are passed out to the calling applicati on.", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "BG V: G,E,Z - CTR_DR BG Key: G,E,Z - Hash_D RBG Seed: G,E,Z - Hash_D RBG V: G,E,Z - Hash_D RBG C: G,E,Z - HMAC_ DRBG Seed: G,E,Z - HMAC_ DRBG V: G,E,Z - HMAC_ DRBG Key: G,E,Z - Generic Secret: G,R,Z"}, {"name": "Symmetr ic Encrypti on/", "description": "Used to encrypt or decrypt data.", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for", "inputs": "AES EDK, AES XTS key, IV, cipherte", "outputs": "Ciphertext data or plaintext data", "secFunImpl": "Symmetric Encrypt/Dec rypt CKG (XTS)", "rolesSspAccess": "Crypto Officer - AES EDK: W,E,Z"}, {"name": "Decrypti on", "description": "SSPs are passed in by the calling applicati on.", "indicator": "operation completed successfully, 0 for failure", "inputs": "xt data, plaintex t data", "outputs": "", "secFunImpl": "", "rolesSspAccess": "- AES XTS key: W,E,Z"}, {"name": "Authenti cated Symmetr ic Encrypti on/ Decrypti on", "description": "Used to encrypt or decrypt data or keys. SSPs are passed in by the calling applicati on. Any establish ed SSPs are passed out to the calling applicati on.", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "AES CMAC/C CM key, AES GMAC/ GCM key, cipherte xt data, plaintex t data", "outputs": "Ciphertext data or plaintext data", "secFunImpl": "AuthSymme tric Encrypt/Dec rypt", "rolesSspAccess": "Crypto Officer - AES CMAC/C CM key: W,E,Z - AES GMAC/ GCM key: W,E,Z - AES GMAC/ GCM IV: G,E,Z"}, {"name": "Symmetr ic Digest", "description": "Used to generate or verify data integrity with CMAC or GMAC. SSPs are passed in by the calling applicati", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "Digest or message , AES CMAC/C CM key, AES GMAC/ GCM key", "outputs": "Digest or verification result", "secFunImpl": "SymmetricDi gest", "rolesSspAccess": "Crypto Officer - AES CMAC/C CM key: W,E,Z - AES GMAC/ GCM key: W,E,Z - AES GMAC/"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "GCM IV: G,E,Z"}, {"name": "Asymme tric Key Generati on", "description": "Used to generate asymmet ric keys using the DRBG. Establish ed SSPs are passed out to the calling applicati on.", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "Desired security strength in bits, entropy input, predicti on resistan ce, paramet ers and values for FFC, ECC, RSA key generati on", "outputs": "ECDSA SGK, ECDSA SVK, RSA SGK, RSA SVK, EdDSA SGK, EdDSA SVK, DH Private, DH Public, ECDH Private, ECDH Public, RSA KAK Private, RSA KAK Public, RSA KDK Private, RSA KEK Public", "secFunImpl": "Asymmetric KeyGen", "rolesSspAccess": "Crypto Officer - DRBG Entropy Input: W,E,Z - CTR_DR BG Seed: G,E,Z - CTR_DR BG V: G,E,Z - CTR_DR BG Key: G,E,Z - Hash_D RBG Seed: G,E,Z - Hash_D RBG V: G,E,Z - Hash_D RBG C: G,E,Z - HMAC_ DRBG Seed: G,E,Z - HMAC_ DRBG V:"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "G,E,Z - HMAC_ DRBG Key: G,E,Z - ECDSA SGK: G,R,Z - ECDSA SVK: G,R,Z - RSA SGK: G,R,Z - RSA SVK: G,R,Z - EdDSA SGK: G,R,Z - EdDSA SVK: G,R,Z - DH Private: G,R,Z - DH Public: G,R,Z - EC DH Private: G,R,Z - EC DH Public: G,R,Z - RSA KAK Private: G,R,Z - RSA KAK Public:"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "G,R,Z - RSA KDK Private: G,R,Z - RSA KEK Public: G,R,Z"}, {"name": "Digital Signatur es", "description": "Used to generate or verify digital signatur es. SSPs are passed in by the calling applicati on.", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "DSA SVK, ECDSA SGK, ECDSA SVK, RSA SGK, RSA SVK, EdDSA SGK, EdDSA SVK", "outputs": "Digital signature or verification result", "secFunImpl": "DigitalSig", "rolesSspAccess": "Crypto Officer - ECDSA SGK: W,E,Z - ECDSA SVK: W,E,Z - RSA SGK: W,E,Z - RSA SVK: W,E,Z - EdDSA SGK: W,E,Z - EdDSA SVK: W,E,Z"}, {"name": "Keyed Hash", "description": "Used to generate or verify data integrity. SSPs are passed in by the calling applicati on.", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "HMAC key, KMAC key", "outputs": "Keyed hash or verification result", "secFunImpl": "KeyedHash", "rolesSspAccess": "Crypto Officer - HMAC Key: W,E,Z - KMAC Key: W,E,Z"}, {"name": "Message Digest", "description": "Used to generate a SHA-1, SHA-2, SHA-3, or SHAKE message digest.", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "Messag e data", "outputs": "Digest", "secFunImpl": "MessageDig est", "rolesSspAccess": "Crypto Officer"}, {"name": "Key Agreeme nt (ECC/FFC )", "description": "Used to perform key agreeme nt primitive s on behalf of the calling applicati on (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "DH Private, DH Public, ECDH Private, ECDH Public", "outputs": "DH Private, DH Public, ECDH Private, ECDH Public, KDF secret", "secFunImpl": "KeyAgreeme nt (ECC) KeyAgreeme nt (FFC)", "rolesSspAccess": "Crypto Officer - DH Private: R,W,E,Z - DH Public: R,W,E,Z - EC DH Private: R,W,E,Z - EC DH Public: R,W,E,Z - KDF Secret: G,R,Z"}, {"name": "Key Agreeme nt (RSA)", "description": "Used to perform key agreeme nt primitive s on behalf of the calling applicati on (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true API return value: 1 for operation completed successfully, 0 for failure", "inputs": "RSA KAK Private, RSA KAK Public", "outputs": "RSA KAK Private, RSA KAK Public, KDF secret", "secFunImpl": "KeyAgreeme nt (RSA)", "rolesSspAccess": "Crypto Officer - RSA KAK Private: R,W,E,Z - RSA KAK Public: R,W,E,Z - KDF Secret: G,R,Z"}, {"name": "Key Derivatio n", "description": "Used to derive keys using KBKDF, PBKDF, HKDF, SP 800- 56Cr2 One-", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "KDF secret, salt, iteration count, MAC, digest, cipher, key", "outputs": "Generic Secret", "secFunImpl": "KeyDerivatio n", "rolesSspAccess": "Crypto Officer - KDF Secret: W,E,Z - Generic Secret: G,R,Z"}, {"name": "", "description": "Step KDF (KDA), SP 800- 56Cr2 Two- Step KDF (KDA), ANSI X9.42- 2001 KDF, ANSI X9.63- 2001 KDF, SSHv2 KDF, TLS 1.2 KDF, TLS 1.3 KDF (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Key Transpor t", "description": "Used to encrypt or decrypt a key value on behalf of the calling applicati on (does not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "RSA KEK Public and key to be encapsu lated (Generic Secret), or RSA KDK Private and encapsu lated key (Generic Secret)", "outputs": "Encapsulated key (Generic Secret), or unencapsulated key (Generic Secret)", "secFunImpl": "KeyTranspor t", "rolesSspAccess": "Crypto Officer - RSA KDK Private: W,E,Z - RSA KEK Public: W,E,Z - Generic Secret: R,W,Z"}, {"name": "Key Wrappin g", "description": "Used to encrypt or decrypt a key value on behalf of the calling applicati on (does", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "AES key wrappin g key, key to be wrappe d or unwrap ped", "outputs": "Wrapped key or unwrapped key (Generic Secret)", "secFunImpl": "KeyWrappin g", "rolesSspAccess": "Crypto Officer - AES key wrappin g key: W,E,Z - Generic"}, {"name": "", "description": "not establish keys into the module). SSPs are passed in by the calling applicati on. Establish ed SSPs are passed out to the calling applicati on.", "indicator": "", "inputs": "(Generic Secret)", "outputs": "", "secFunImpl": "", "rolesSspAccess": "Secret: R,W,Z"}, {"name": "Zeroise", "description": "All services automati cally overwrit e SSPs stored in allocated memory (zeroise). The module does not store any SSP persisten tly (beyond the lifetime of an API call),", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "Memory to be cleanse d (pointer and length)", "outputs": "The completion of a zeroisation routine indicates that the zeroisation procedure succeeded. Zeroisation can be confirmed via EVP_RAND_verify_z eroization: 1 for success (i.e. the DRBG CSPs have been zeroised), 0 for failure.", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer - DRBG Entropy Input: Z - CTR_DR BG Seed: Z - CTR_DR BG V: Z - CTR_DR BG Key: Z - Hash_D RBG Seed: Z - Hash_D"}, {"name": "", "description": "except for DRBG state values (stored for the lifetime of the DRBG instance) . Stack cleanup is the responsi bility of the calling applicati on.", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "RBG V: Z - Hash_D RBG C: Z - HMAC_ DRBG Seed: Z - HMAC_ DRBG V: Z - HMAC_ DRBG Key: Z"}, {"name": "Utility", "description": "Miscella neous helper function s.", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true. API return value: 1 for operation completed successfully, 0 for failure", "inputs": "None", "outputs": "None", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "Symmetr ic Decrypti on (Legacy)", "description": "Used to decrypt data. SSPs are passed in by the calling", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true API return value: 1 for operation completed successfully, 0 for failure", "inputs": "TDES DK, cipherte xt data", "outputs": "Plaintext data", "secFunImpl": "Symmetric Decrypt (Legacy)", "rolesSspAccess": "Crypto Officer - TDES DK: W,E,Z"}, {"name": "Digital Signatur es (Legacy)", "description": "Used to verify digital signatur es. SSPs are passed", "indicator": "Implied if EVP_default_properties_is _fips_enabled() returns true API return value: 1 for operation completed successfully, 0 for failure", "inputs": "DSA SVK, ECDSA SVK (Legacy) , RSA", "outputs": "Verification result", "secFunImpl": "DigitalSig (Legacy)", "rolesSspAccess": "Crypto Officer - DSA SVK: W,E,Z - ECDSA SVK"}, {"name": "Name", "description": "Descripti on", "indicator": "Inputs", "inputs": "Outputs", "outputs": "Security Functions", "secFunImpl": "SSP Access", "rolesSspAccess": ""}, {"name": "", "description": "in by the calling applicati on.", "indicator": "SVK (Legacy)", "inputs": "", "outputs": "", "secFunImpl": "(Legacy) : W,E,Z - RSA SVK (Legacy) : W,E,Z", "rolesSspAccess": ""}]}, "non_approved_services": {"section": 4, "subsection": 4, "found": false, "entries": []}, "mechanisms_actions": {"section": 7, "subsection": 1, "found": false, "entries": []}, "storage_areas": {"section": 9, "subsection": 1, "found": true, "entries": [{"name": "RAM / DRAM", "description": "Memory that only holds data during power on of the operating environment", "persistance": "Dynamic"}]}, "ssp_io_methods": {"section": 9, "subsection": 2, "found": true, "entries": [{"name": "API Input via TOEPP path", "source": "Other Applications (App per IG 9.5.A)", "dest": "RAM / DRAM", "format": "Plaintext", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": ""}, {"name": "Encrypted API Input using Key Transport via TOEPP path", "source": "Other Applications (App per IG 9.5.A)", "dest": "RAM / DRAM", "format": "Encrypted", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": "KeyTransport"}, {"name": "Encrypted API Input using Key Wrapping via TOEPP path", "source": "Other Applications (App per IG 9.5.A)", "dest": "RAM / DRAM", "format": "Encrypted", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": "KeyWrapping"}, {"name": "API Output via TOEPP path", "source": "RAM / DRAM", "dest": "Other Applications (App per IG 9.5.A)", "format": "Plaintext", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": ""}, {"name": "Encrypted API Output using Key Transport via TOEPP path", "source": "RAM / DRAM", "dest": "Other Applications (App per IG 9.5.A)", "format": "Encrypted", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": "KeyTransport"}, {"name": "Encrypted API Output using Key Wrapping via TOEPP path", "source": "RAM / DRAM", "dest": "Other Applications (App per IG 9.5.A)", "format": "Encrypted", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": "KeyWrapping"}]}, "ssp_zeroization_methods": {"section": 9, "subsection": 3, "found": true, "entries": [{"method": "Zeroise service", "description": "Calls OPENSSL_cleanse to zeroise the DRBG CSPs", "rationale": "DRBG CSPs are the only SSPs stored by the module beyond the lifetime of an API call. The Zeroise service zeroises SSPs by overwriting zeroes to the memory location occupied by the SSP and further deallocating that area.", "operatorId": "Function provided via API"}, {"method": "Call a service that creates or uses the SSP", "description": "Services include appropriate APIs (OPENSSL_free or OPENSSL_cleanse) to automatically zeroise the SSPs created or used by the services. This zeroises the context structures that contains the SSP.", "rationale": "SSPs are zeroised by overwriting zeroes to the memory location occupied by the SSP and further deallocating that area.", "operatorId": "Function provided via API"}]}, "self_tests": {"section": 10, "subsection": 1, "found": true, "entries": [{"algorithmOrTest": "HMAC-SHA2- 256 (A4593)", "testProps": "HMAC-SHA- 256 (Cert. A4593)", "testMethod": "Compare to pre-computed HMAC", "type": "SW/FW Integrity", "indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNING)", "details": "Verify"}, {"algorithmOrTest": "HMAC-SHA2- 256 (A5173)", "testProps": "HMAC-SHA- 256 (Cert. A5173)", "testMethod": "Compare to pre-computed HMAC", "type": "SW/FW Integrity", "indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNING)", "details": "Verify"}]}, "cond_self_tests": {"section": 10, "subsection": 2, "found": true, "entries": [{"algorithmOrTest": "AES-GCM Authenticate d Encrypt KAT (Forward Cipher) (A4593)", "testProps": "256-bit AES", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)", "details": "Authenticate d Encrypt (forward cipher)", "condition": "Initialisation"}, {"algorithmOrTest": "AES-GCM Authenticate d Encrypt KAT (Forward Cipher) (A5173)", "testProps": "256-bit AES", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)", "details": "Authenticate d Encrypt (forward cipher)", "condition": "Initialisation"}, {"algorithmOrTest": "AES-GCM Decrypt KAT (Forward Cipher) (A4593)", "testProps": "256-bit AES", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)", "details": "Decrypt (forward cipher)", "condition": "Initialisation"}, {"algorithmOrTest": "AES-GCM Decrypt KAT (Forward Cipher) (A5173)", "testProps": "256-bit AES", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State (queried via Show Status) changes to Running (FIPS_STATE_RUNNIN G)", "details": "Decrypt (forward cipher)", "condition": "Initialisation"}, {"algorithmOrTest": "AES-ECB Decrypt KAT (Inverse Cipher) (A4593)", "testProps": "256-bit AES", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Decrypt (inverse cipher)", "condition": "Initialisation"}, {"algorithmOrTest": "AES-ECB Decrypt KAT (Inverse Cipher) (A5173)", "testProps": "256-bit AES", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Decrypt (inverse cipher)", "condition": "Initialisation"}, {"algorithmOrTest": "Counter DRBG (A4593)", "testProps": "128-bit AES with df", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)", "condition": "Initialisation"}, {"algorithmOrTest": "Counter DRBG (A5173)", "testProps": "128-bit AES with df", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)", "condition": "Initialisation"}, {"algorithmOrTest": "Hash DRBG (A4593)", "testProps": "SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)", "condition": "Initialisation"}, {"algorithmOrTest": "Hash DRBG (A5173)", "testProps": "SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)", "condition": "Initialisation"}, {"algorithmOrTest": "HMAC DRBG (A4593)", "testProps": "HMAC-SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)", "condition": "Initialisation"}, {"algorithmOrTest": "HMAC DRBG (A5173)", "testProps": "HMAC-SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Instantiate, Reseed, Generate (per IG 10.3.A, 6)", "condition": "Initialisation"}, {"algorithmOrTest": "KDF ANS 9.42 (A4593)", "testProps": "SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDF ANS 9.42 (A5173)", "testProps": "SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDF ANS 9.63 (A4593)", "testProps": "SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDF ANS 9.63 (A5173)", "testProps": "SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDF SSH (A4593)", "testProps": "SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDF SSH (A5173)", "testProps": "SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "TLS v1.2 KDF RFC7627 (A4593)", "testProps": "HMAC-SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5173)", "testProps": "HMAC-SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "TLS v1.3 KDF (A4593)", "testProps": "SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "TLS v1.3 KDF (A5173)", "testProps": "SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "DSA Verify (A4593)", "testProps": "2048, SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "DSA Verify (A5173)", "testProps": "2048, SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Sign KAT for Prime Curves (A4593)", "testProps": "P-224, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Sign KAT for Prime Curves (A5173)", "testProps": "P-224, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Sign KAT for Binary Curves (A4593)", "testProps": "K-233, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Sign KAT for Binary Curves (A5173)", "testProps": "K-233, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Sign KAT for Brainpool Curves (A4593)", "testProps": "brainpoolP224r 1, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Sign KAT for Brainpool Curves (A5173)", "testProps": "brainpoolP224r 1, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Verify KAT for Prime Curves (A4593)", "testProps": "P-224, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Verify KAT for Prime Curves (A5173)", "testProps": "P-224, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Verify KAT for Binary Curves (A4593)", "testProps": "K-233, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Verify KAT for Binary Curves (A5173)", "testProps": "K-233, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Verify KAT for Brainpool Curves (A4593)", "testProps": "brainpoolP224r 1, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "ECDSA Verify KAT for Brainpool Curves (A5173)", "testProps": "brainpoolP224r 1, SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "EDDSA Sign KAT for Ed25519 (A4593)", "testProps": "Ed25519", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "EDDSA Sign KAT for Ed25519 (A5173)", "testProps": "Ed25519", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "EDDSA Sign KAT for Ed448 (A4593)", "testProps": "Ed448", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "EDDSA Sign KAT for Ed448 (A5173)", "testProps": "Ed448", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "EDDSA Verify KAT for Ed25519 (A4593)", "testProps": "Ed25519", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "EDDSA Verify KAT for Ed25519 (A5173)", "testProps": "Ed25519", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "EDDSA Verify KAT for Ed448 (A4593)", "testProps": "Ed448", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "EDDSA Verify KAT for Ed448 (A5173)", "testProps": "Ed448", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "HMAC-SHA2- 256 (A4593)", "testProps": "HMAC-SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation , performed before pre- operational integrity test"}, {"algorithmOrTest": "HMAC-SHA2- 256 (A5173)", "testProps": "HMAC-SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation , performed before pre- operational integrity test"}, {"algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A4593)", "testProps": "P-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify computation of shared secret Z in Ephemeral Unified scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3", "condition": "Initialisation"}, {"algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A5173)", "testProps": "P-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify computation of shared secret Z in Ephemeral Unified scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3", "condition": "Initialisation"}, {"algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3 (A4593)", "testProps": "FB (2048, 224)", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify computation of shared secret Z in dhEphem scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3", "condition": "Initialisation"}, {"algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3 (A5173)", "testProps": "FB (2048, 224)", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify computation of shared secret Z in dhEphem scheme, per Scenario 2 of IG D.F and Section 6 of SP 800-56Ar3", "condition": "Initialisation"}, {"algorithmOrTest": "KAS-IFC-SSC (A4593)", "testProps": "2048-bit key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "RSA Primitive Computation, per Scenario 1 of IG D.F and Section 8.2.2 in SP 800-56Br2", "condition": "Initialisation"}, {"algorithmOrTest": "KAS-IFC-SSC (A5173)", "testProps": "2048-bit key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "RSA Primitive Computation, per Scenario 1 of IG D.F and Section 8.2.2 in SP 800-56Br2", "condition": "Initialisation"}, {"algorithmOrTest": "KDA OneStep SP800-56Cr2 (A4593)", "testProps": "SHA-224", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDA OneStep SP800-56Cr2 (A5173)", "testProps": "SHA-224", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDA TwoStep SP800-56Cr2 (A4593)", "testProps": "SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDA TwoStep SP800-56Cr2 (A5173)", "testProps": "SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDF SP800- 108 (A4593)", "testProps": "Counter Mode with HMAC- SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KDF SP800- 108 (A5173)", "testProps": "Counter Mode with HMAC- SHA-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derive", "condition": "Initialisation"}, {"algorithmOrTest": "KTS-IFC Encrypt KAT for KTS- OAEP-Basic (A4593)", "testProps": "2048-bit key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Encrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2", "condition": "Initialisation"}, {"algorithmOrTest": "KTS-IFC Encrypt KAT for KTS- OAEP-Basic (A5173)", "testProps": "2048-bit key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Encrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2", "condition": "Initialisation"}, {"algorithmOrTest": "KTS-IFC Decrypt KAT for KTS- OAEP-Basic (A4593)", "testProps": "2048-bit key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Decrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2", "condition": "Initialisation"}, {"algorithmOrTest": "KTS-IFC Decrypt KAT for KTS- OAEP-Basic (A5173)", "testProps": "2048-bit key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Decrypt for KTS-OAEP- Basic, per IG D.G and SP 800-56Br2", "condition": "Initialisation"}, {"algorithmOrTest": "KTS-IFC Decrypt KAT for CRT (A4593)", "testProps": "2048-bit key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Decrypt for CRT, per IG D.G and SP 800-56Br2", "condition": "Initialisation"}, {"algorithmOrTest": "KTS-IFC Decrypt KAT for CRT (A5173)", "testProps": "2048-bit key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Decrypt for CRT, per IG D.G and SP 800-56Br2", "condition": "Initialisation"}, {"algorithmOrTest": "PBKDF (A4593)", "testProps": "HMAC-SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derivation of the Master Key (MK), per Section 5.3 of SP 800-132", "condition": "Initialisation"}, {"algorithmOrTest": "PBKDF (A5173)", "testProps": "HMAC-SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Derivation of the Master Key (MK), per Section 5.3 of SP 800-132", "condition": "Initialisation"}, {"algorithmOrTest": "RSA Sign KAT (A4593)", "testProps": "2048-bit key, SHA-256, PKCS#1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "RSA Sign KAT (A5173)", "testProps": "2048-bit key, SHA-256, PKCS#1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Sign", "condition": "Initialisation"}, {"algorithmOrTest": "RSA Verify KAT (A4593)", "testProps": "2048-bit key, SHA-256, PKCS#1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "RSA Verify KAT (A5173)", "testProps": "2048-bit key, SHA-256, PKCS#1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Verify", "condition": "Initialisation"}, {"algorithmOrTest": "SHA3 KAT for Keccak-p Permutation (A4593)", "testProps": "SHA3-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Hash", "condition": "Initialisation"}, {"algorithmOrTest": "SHA3 KAT for Keccak-p Permutation (A5173)", "testProps": "SHA3-256", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Hash", "condition": "Initialisation"}, {"algorithmOrTest": "SHA-1 (A4593)", "testProps": "SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Hash", "condition": "Initialisation"}, {"algorithmOrTest": "SHA-1 (A5173)", "testProps": "SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Hash", "condition": "Initialisation"}, {"algorithmOrTest": "SHA2-512 (A4593)", "testProps": "SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Hash", "condition": "Initialisation"}, {"algorithmOrTest": "SHA2-512 (A5173)", "testProps": "SHA-512", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Hash", "condition": "Initialisation"}, {"algorithmOrTest": "TDES-CBC (A4593)", "testProps": "CBC mode, 3- key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Decrypt", "condition": "Initialisation"}, {"algorithmOrTest": "TDES-CBC (A5173)", "testProps": "CBC mode, 3- key", "testMethod": "KAT", "type": "CAST", "indicator": "The Module State changes to Running", "details": "Decrypt", "condition": "Initialisation"}, {"algorithmOrTest": "DSA (FFC) PCT for Key Agreement (A4593)", "testProps": "All supported parameters for KAS-FFC", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure", "details": "Sign/Verify for Key Agreement, per VE10.35.03", "condition": "Key Pair Generation, Key Pair Import"}, {"algorithmOrTest": "DSA (FFC) PCT for Key Agreement (A5173)", "testProps": "All supported parameters for KAS-FFC", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure", "details": "Sign/Verify for Key Agreement, per VE10.35.03", "condition": "Key Pair Generation, Key Pair Import"}, {"algorithmOrTest": "ECC PCT for Key Pair Generation (A4593)", "testProps": "All supported curves", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair generation): 1 for success, 0 for failure", "details": "Sign/Verify for Digital Signatures, per VE10.35.02. At the time of key pair generation, the keys' intended usage is not known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.", "condition": "Key Pair Generation"}, {"algorithmOrTest": "ECC PCT for Key Pair Generation (A5173)", "testProps": "All supported curves", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair generation): 1 for success, 0 for failure", "details": "Sign/Verify for Digital Signatures, per VE10.35.02. At the time of key pair generation, the keys' intended usage is not", "condition": "Key Pair Generation"}, {"algorithmOrTest": "", "testProps": "", "testMethod": "", "type": "", "indicator": "", "details": "known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.", "condition": ""}, {"algorithmOrTest": "ECC PCT for Key Pair Import (A4593)", "testProps": "All supported curves", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair import): 1 for success, 0 for failure", "details": "Sign/Verify for Key Agreement, per VE10.35.03. At the time of key pair import, the keys' intended usage is not known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable", "condition": "Key Pair Import"}, {"algorithmOrTest": "ECC PCT for Key Pair Import (A5173)", "testProps": "All supported curves", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair import): 1 for success, 0 for failure", "details": "Sign/Verify for Key Agreement, per VE10.35.03.", "condition": "Key Pair Import"}, {"algorithmOrTest": "", "testProps": "", "testMethod": "", "type": "", "indicator": "", "details": "At the time of key pair import, the keys' intended usage is not known (key pairs may be used for digital signatures or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable", "condition": ""}, {"algorithmOrTest": "EdDSA PCT (A4593)", "testProps": "All supported curves (Ed25519, Ed448)", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure", "details": "Sign/Verify for Digital Signatures, per VE10.35.02. EdDSA keys can only be used for digital signatures.", "condition": "Key Pair Generation, Key Pair Import"}, {"algorithmOrTest": "EdDSA PCT (A5173)", "testProps": "All supported curves (Ed25519, Ed448)", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure", "details": "Sign/Verify for Digital Signatures, per VE10.35.02. EdDSA keys can only be used for digital signatures.", "condition": "Key Pair Generation, Key Pair Import"}, {"algorithmOrTest": "RSA PCT (A4593)", "testProps": "All supported moduli", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure", "details": "Sign/Verify for Key Agreement, per VE10.35.03. At the time of key pair generation or import, the keys' intended usage is not known (key pairs may be used for key transport, digital signatures, or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.", "condition": "Key Pair Generation, Key Pair Import"}, {"algorithmOrTest": "RSA PCT (A5173)", "testProps": "All supported moduli", "testMethod": "PCT", "type": "PCT", "indicator": "Return value for the relevant API call (i.e. for key pair generation or key pair import): 1 for success, 0 for failure", "details": "Sign/Verify for Key Agreement, per VE10.35.03. At the time of key pair generation or import, the keys' intended usage is not known (key pairs may be used for key transport,", "condition": "Key Pair Generation, Key Pair Import"}, {"algorithmOrTest": "", "testProps": "", "testMethod": "", "type": "", "indicator": "", "details": "digital signatures, or key agreement); per IG 10.3.A comment 1, any of the AS10.35 PCTs is acceptable.", "condition": ""}, {"algorithmOrTest": "AES-XTS Key Test (A4593)", "testProps": "All supported sizes (128-bit, 256-bit)", "testMethod": "Other", "type": "Critical Functio n", "indicator": "Return value for the relevant API call (i.e. for symmetric encryption/decryption with AES-XTS): 1 for success, 0 for failure", "details": "Test that Key_1 Key_2, per IG C.I", "condition": "Symmetric Encryption/ Decryption"}, {"algorithmOrTest": "AES-XTS Key Test (A5173)", "testProps": "All supported sizes (128-bit, 256-bit)", "testMethod": "Other", "type": "Critical Functio n", "indicator": "Return value for the relevant API call (i.e. for symmetric encryption/decryption with AES-XTS): 1 for success, 0 for failure", "details": "Test that Key_1 Key_2, per IG C.I", "condition": "Symmetric Encryption/ Decryption"}]}, "error_states": {"section": 10, "subsection": 4, "found": true, "entries": [{"name": "FIPS_STATE_ERROR", "description": "The module has entered an error state. All cryptographic", "conditions": "Pre- operational self-test failure CAST", "recoveryMethod": "Restart the module", "indicator": "Module State (queried via Show Status)"}, {"name": "", "description": "APIs will return an error when called.", "conditions": "self-test failure", "recoveryMethod": "", "indicator": "changes to Error (FIPS_STATE_ERROR)"}, {"name": "Temporary Error", "description": "The module enters a temporary error state when a PCT test fails or when the AES-XTS critical function test fails. Keys that fail the tests are disabled and the module returns to the Running state.", "conditions": "Conditional PCT test failure Conditional AES-XTS critical function test failure", "recoveryMethod": "The module will reject the tested key or key pair and then return automatically to the Running state (FIPS_STATE_RUNNING).", "indicator": "The return value for the relevant API call (i.e. for key pair generation, key pair import, or symmetric encryption/ decryption with AES- XTS) returns 0 for failure"}]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["SHA2-384A5173", "KMAC-256A5173", "SHA2-512/224A5173", "#A4593", "TDES-ECBA5173", "HMAC-SHA3-512A5173", "KDF SP800-108A5173", "AES-GCMA5173", "KDF ANS 9.42A5173", "#A5173", "HMAC-SHA2-512A5173", "ECDSA SigVer (FIPS186-4)A5173", "RSA SigGen (FIPS186-4)A5173", "KDA HKDF SP800-56Cr2A5173", "AES-CFB8A5173", "AES-CFB1A5173", "AES-CBC-CS1A5173", "Hash DRBGA5173", "AES-CMACA5173", "SHA-1A5173", "EDDSA KeyGenA5173", "PBKDFA5173", "KDF SSHA5173", "SHA2-224A5173", "SHA3-224A5173", "ECDSA KeyVer (FIPS186-4)A5173", "DSA PQGVer (FIPS186-4)A5173", "HMAC-SHA2-224A5173", "Safe Primes Key GenerationA5173", "AES-OFBA5173", "AES-CBC-CS2A5173", "DSA PQGGen (FIPS186-4)A5173", "TLS v1.2 KDF RFC7627A5173", "AES-CCMA5173", "Counter DRBGA5173", "RSA KeyGen (FIPS186-4)A5173", "TLS v1.3 KDFA5173", "AES-CFB128A5173", "KAS-IFC-SSCA5173", "AES-CBC-CS3A5173", "AES-CBCA5173", "AES-XTS Testing Revision 2.0A5173", "SHA2-512A5173", "HMAC-SHA-1A5173", "SHA3-512A5173", "DSA SigVer (FIPS186-4)A5173", "EDDSA KeyVerA5173", "ECDSA KeyGen (FIPS186-4)A5173", "AES-GMACA5173", "SHAKE-128A5173", "KTS-IFCA5173", "HMAC-SHA2-512/224A5173", "EDDSA SigGenA5173", "HMAC-SHA2-384A5173", "HMAC-SHA3-256A5173", "HMAC-SHA2-512/256A5173", "RSA SigVer (FIPS186-4)A5173", "SHA3-384A5173", "KMAC-128A5173", "HMAC DRBGA5173", "EDDSA SigVerA5173", "SHA2-256A5173", "SHA2-512/256A5173", "HMAC-SHA3-224A5173", "KDF KMAC Sp800-108r1A5173", "SHAKE-256A5173", "Safe Primes Key VerificationA5173", "AES-KWA5173", "AES-KWPA5173", "KAS-ECC-SSC Sp800-56Ar3A5173", "KDA TwoStep SP800-56Cr2A5173", "KDF ANS 9.63A5173", "TDES-CBCA5173", "AES-CTRA5173", "KDA OneStep SP800-56Cr2A5173", "DSA KeyGen (FIPS186-4)A5173", "AES-ECBA5173", "ECDSA SigGen (FIPS186-4)A5173", "HMAC-SHA2-256A5173", "KAS-FFC-SSC Sp800-56Ar3A5173", "HMAC-SHA3-384A5173", "SHA3-256A5173"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "4458a6a97caab8091f44913d83f2999febf790ab5bd3aa1f691507f145bac1c3", "txt_hash": "c1e43314f3d7aacdf7ac940b5c9217968c1ca0c1a2da925609d40b2f084afeb9", "json_hash": "6ed4f15efe636ebf7a9839b367570e0c4baf5c852d98d31b6e4c9b35d2298ce6"}}}