This page was not yet optimized for use on mobile devices.
Allegro Cryptographic Engine
Certificate details
| Certificate ID | #4944 |
|---|---|
| Status | historical |
| Historical reason | Replaced by certificate #5246 |
| Validation dates | 17.01.2025 |
| Standard | FIPS 140-3 |
| Security level | 1 |
| Type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Caveat | Interim validation. No assurance of the minimum strength of generated SSPs (e.g., keys) |
| Exceptions |
|
| Description | Allegro’s suite of Embedded Device Security tool kits makes embedding standards-based security protocols into resource sensitive embedded systems and consumer electronics fast, easy and reliable. The Allegro Cryptographic Engine (ACE) is a cryptographic library module specifically engineered for embedded devices. The module provides embedded systems developers with an easily understood software interface to enable bulk encryption and decryption, message digests, digital signature creation and validation and key generation and exchange. For full details see www.allegrosoft.com/ace. |
| Vendor | Allegro Software Development Corporation http://www.allegrosoft.com |
| Lab | Acumen Security |
| Algorithms |
|
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, HMAC, CMACAsymmetric Algorithms
ECDH, ECDSA, DHHash functions
SHA-1, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHA-3, MD5, PBKDF, PBKDF2Schemes
MAC, Key AgreementProtocols
SSH, SSHv2, TLS v1.2, TLS v1.3, TLS 1.2, TLS, TLS 1.3Randomness
DRBG, RBGElliptic Curves
P-224, P-256, P-384, P-521, P-192Block cipher modes
GCM, CCM, XTSTLS cipher suites
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_DHE_RSA_WITH_AES_128_GCM_SHA256, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384, TLS_DHE_DSS_WITH_AES_128_GCM_SHA256, TLS_DHE_DSS_WITH_AES_256_GCM_SHA384Trusted Execution Environments
PSP, SSCSecurity level
Level 1Standards
FIPS 140-3, FIPS 1403, FIPS 198-1, FIPS186-4, FIPS 186-4, FIPS 180-4, FIPS 202, SP 800-38A, SP 800-38C, SP 800-38G, SP 800-38D, SP 800-38E, SP 800-38B, SP 800-38F, SP 800-90A, SP 800-56A, SP 800-56C, SP 800-135, SP 800-132, NIST SP 800-133, SP 800-52, SP 800-107, NIST SP 800-132, NIST SP 800-38F, NIST SP 800-90A, RFC7627, RFC 7627, RFC 5288, RFC 5246, RFC 8446Automated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
No references are available for this certificate.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 4944,
"dgst": "e83a33c58345ed88",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"Safe Primes Key VerificationA3332",
"KDA HKDF Sp800-56Cr1A3332",
"HMAC-SHA2-224A3332",
"AES-CFB128A3332",
"PBKDFA3332",
"AES-KWA3332",
"SHAKE-128A3332",
"AES-GCMA3332",
"AES-CMACA3332",
"AES-OFBA3332",
"RSA KeyGen (FIPS186-4)A3332",
"KAS-ECC-SSC Sp800-56Ar3A3332",
"HMAC-SHA3-224A3332",
"Safe Primes Key GenerationA3332",
"TLS v1.2 KDF RFC7627A3332",
"TLS v1.3 KDFA3332",
"Hash DRBGA3332",
"AES-KWPA3332",
"AES-ECBA3332",
"SHA-1A3332",
"HMAC-SHA3-384A3332",
"SHA3-384A3332",
"ECDSA KeyVer (FIPS186-4)A3332",
"HMAC-SHA3-512A3332",
"RSA SigGen (FIPS186-4)A3332",
"SHA2-256A3332",
"AES-GMACA3332",
"AES-CFB1A3332",
"ECDSA KeyGen (FIPS186-4)A3332",
"HMAC-SHA-1A3332",
"KAS-FFC-SSC Sp800-56Ar3A3332",
"SHA3-224A3332",
"SHA3-512A3332",
"HMAC-SHA3-256A3332",
"SHAKE-256A3332",
"AES-CTRA3332",
"HMAC-SHA2-512A3332",
"RSA SigVer (FIPS186-4)A3332",
"HMAC-SHA2-256A3332",
"AES-FF1A3332",
"AES-CFB8A3332",
"ECDSA SigVer (FIPS186-4)A3332",
"AES-XTS Testing Revision 2.0A3332",
"#A3332",
"SHA2-512A3332",
"SHA3-256A3332",
"AES-CBCA3332",
"HMAC-SHA2-384A3332",
"SHA2-224A3332",
"SHA2-384A3332",
"AES-CCMA3332",
"ECDSA SigGen (FIPS186-4)A3332",
"KDF SSHA3332"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"br1_deviations": 0,
"br1_tables": {
"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
"approved_algorithms": {
"entries": [
{
"algorithm": "AES-CBC",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CCM",
"cavpCertName": "A3332",
"properties": "Key Length - 128, 192, 256",
"reference": "SP 800-38C"
},
{
"algorithm": "AES-CFB1",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CFB128",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CFB8",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CTR",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-ECB",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-FF1",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38G"
},
{
"algorithm": "AES-GCM",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-OFB",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-XTS Testing Revision 2.0",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
"reference": "SP 800-38E"
},
{
"algorithm": "AES-CMAC",
"cavpCertName": "A3332",
"properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
"reference": "SP 800-38B"
},
{
"algorithm": "AES-GMAC",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "HMAC-SHA-1",
"cavpCertName": "A3332",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-224",
"cavpCertName": "A3332",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-256",
"cavpCertName": "A3332",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-384",
"cavpCertName": "A3332",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-512",
"cavpCertName": "A3332",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3-224",
"cavpCertName": "A3332",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3-256",
"cavpCertName": "A3332",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3-384",
"cavpCertName": "A3332",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3-512",
"cavpCertName": "A3332",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "AES-KW",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38F"
},
{
"algorithm": "AES-KWP",
"cavpCertName": "A3332",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38F"
},
{
"algorithm": "ECDSA KeyGen (FIPS186-4)",
"cavpCertName": "A3332",
"properties": "Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA KeyGen (FIPS186-4)",
"cavpCertName": "A3332",
"properties": "Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.3 Private Key Format - Standard",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA KeyVer (FIPS186-4)",
"cavpCertName": "A3332",
"properties": "Curve - P-192, P-224, P-256, P-384, P-521",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigGen (FIPS186-4)",
"cavpCertName": "A3332",
"properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigGen (FIPS186-4)",
"cavpCertName": "A3332",
"properties": "Signature Type - ANSI X9.31, PKCSPSS Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigVer (FIPS186-4)",
"cavpCertName": "A3332",
"properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigVer (FIPS186-4)",
"cavpCertName": "A3332",
"properties": "Signature Type - ANSI X9.31, PKCSPSS Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "Hash DRBG",
"cavpCertName": "A3332",
"properties": "Mode - SHA2-256, SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "KAS-ECC-SSC Sp800- 56Ar3",
"cavpCertName": "A3332",
"properties": "Domain Parameter Generation Methods - P-224, P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-FFC-SSC Sp800- 56Ar3",
"cavpCertName": "A3332",
"properties": "Domain Parameter Generation Methods - MODP- 2048, MODP-3072",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KDA HKDF Sp800- 56Cr1",
"cavpCertName": "A3332",
"properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA3-224, SHA3-256, SHA3-384, SHA3-512",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDF SSH (CVL)",
"cavpCertName": "A3332",
"properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "PBKDF",
"cavpCertName": "A3332",
"properties": "Iteration Count - Iteration Count: 1000-100000 Increment 1 Password Length - Password Length: 8-128 Increment 1",
"reference": "SP 800-132"
},
{
"algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
"cavpCertName": "A3332",
"properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "TLS v1.3 KDF (CVL)",
"cavpCertName": "A3332",
"properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - PSK-DHE",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "SHA-1",
"cavpCertName": "A3332",
"properties": "Message Length - Message Length: 0-65528 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-224",
"cavpCertName": "A3332",
"properties": "Message Length - Message Length: 0-65528 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A3332",
"properties": "Message Length - Message Length: 0-65528 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-384",
"cavpCertName": "A3332",
"properties": "Message Length - Message Length: 0-65528 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "A3332",
"properties": "Message Length - Message Length: 0-65528 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA3-224",
"cavpCertName": "A3332",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-256",
"cavpCertName": "A3332",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-384",
"cavpCertName": "A3332",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-512",
"cavpCertName": "A3332",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHAKE-128",
"cavpCertName": "A3332",
"properties": "Output Length - Output Length: 16-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "SHAKE-256",
"cavpCertName": "A3332",
"properties": "Output Length - Output Length: 16-65536 Increment 8",
"reference": "FIPS 202"
},
{
"algorithm": "Safe Primes Key Generation",
"cavpCertName": "A3332",
"properties": "Safe Prime Groups - modp-2048, modp- 3072",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "Safe Primes Key Verification",
"cavpCertName": "A3332",
"properties": "Safe Prime Groups - modp-2048, modp- 3072",
"reference": "SP 800-56A Rev. 3"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"approved_services": {
"entries": [
{
"description": "Initialize the module for use in Approved mode",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "N/A",
"name": "AcInit()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Zeroize all keys and CSPs and disable crypto services",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "N/A",
"name": "AcDeInit()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Run cryptographic self-tests on demand",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "N/A",
"name": "AcRunSelfTest()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "DRBG Message Digest Generate Digital"
},
{
"description": "Description",
"indicator": "Indicato r",
"inputs": "Inputs",
"name": "Name",
"outputs": "Outputs",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": "Functions Signature Verify Digital Signature Generate Asymmetric Keys Shared Secret Computatio n (KAS- FFC-SSC) Shared Secret Computatio n (KAS- ECC-SSC) Derive Key (HKDF) Derive Key (TLS 1.2) Derive Key (TLS 1.3) Derive Key (SSH) Derive Key (PBKDF) Message Authenticati on Symmetric Cipher Verify Asymmetric"
},
{
"description": "Return the module name and version",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "N/A",
"name": "AcAceLibraryInfo()",
"outputs": "Module Name, Major Version, Minor Version, Build Number, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Generate random data",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcGenerateRandomNumb ers()",
"outputs": "Random Number, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "DRBG"
},
{
"description": "Description",
"indicator": "Indicato",
"inputs": "Inputs",
"name": "Name",
"outputs": "Outputs",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Functions"
},
{
"description": "Create message digest from input data",
"indicator": "r Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcDigest() AcDigestInit() AcDigestUpdate() AcDigestFinal()",
"outputs": "Hash, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "Message Digest"
},
{
"description": "Duplicate a message digest",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcDigestClone()",
"outputs": "Hash, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Create a keyed message digest of input data",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcKeyedDigestInit()",
"outputs": "Digest, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - HMAC Key: R,E - AES GMAC Key: R,E - AES CMAC Key: R,E",
"secFunImpl": "Message Digest Message Authenticati on"
},
{
"description": "Create a Digital Signature",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcSign() AcSignInit() AcSignUpdate() AcSignFinal()",
"outputs": "Signature, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - RSA Private Key: R,E - ECDSA Private Key: R,E",
"secFunImpl": "Generate Digital Signature"
},
{
"description": "Create a digital signature for a previously computed message digest",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcSignDigestBuffer()",
"outputs": "Signature, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - RSA Private Key: R,E - ECDSA Private Key: R,E",
"secFunImpl": "Generate Digital Signature"
},
{
"description": "Verify a digital signature",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcVerify() AcVerifyInit() AcVerifyUpdate() AcVerifyFinal()",
"outputs": "Signature, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - RSA Public Key: R,E - ECDSA Public Key: R,E",
"secFunImpl": "Verify Digital Signature Verify Asymmetric Keys"
},
{
"description": "Verify a digital signature for a previously computed digest",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcVerifyDigestBuffer()",
"outputs": "Signature, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - RSA Public Key: R,E - ECDSA Public Key: R,E",
"secFunImpl": "Verify Digital Signature Verify Asymmetric Keys"
},
{
"description": "Encrypt or decrypt a block of data",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcEncryptInit()",
"outputs": "Plaintext, Ciphertext, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - AES Key : R,E - AES GCM Key: R,E - AES GCM IV: R,E",
"secFunImpl": "Symmetric Cipher"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- AES CCM Key: R,E - AES-XTS Testing Revision 2.0 Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E",
"secFunImpl": ""
},
{
"description": "Encrypt or decrypt a block of data",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcEncryptUpdate()",
"outputs": "Plaintext, Ciphertext, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - AES Key : R,E - AES GCM Key: R,E - AES GCM IV: R,E - AES CCM Key: R,E - AES-XTS Testing Revision 2.0 Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E",
"secFunImpl": "Symmetric Cipher"
},
{
"description": "Encrypt or decrypt a block of data",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcEncryptFinal()",
"outputs": "Plaintext, Ciphertext, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - AES Key : R,E - AES GCM Key: R,E - AES GCM IV: R,E - AES CCM Key: R,E - AES-XTS Testing Revision 2.0 Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E CO",
"secFunImpl": "Symmetric Cipher"
},
{
"description": "Generate symmetric keys",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcGenerateKey()",
"outputs": "Key, Invocation Success or Invocation Failure",
"rolesSspAccess": "- AES Key : G,W - AES GCM Key: G,W",
"secFunImpl": "Generate Symmetric Keys CKG Section 4"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- AES CMAC Key: G,W - AES-XTS Testing Revision 2.0 Key: G,W - Key Encryption Key (KEK): G,W",
"secFunImpl": "CKG Section 6.1"
},
{
"description": "Generate asymmetric key pairs",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcGenerateKeyPair()",
"outputs": "KeyPair, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - RSA Private Key: G,W - RSA Public Key: G,W - ECDSA Private Key: G,W - ECDSA Public Key: G,W - ECDH Private Components : G,W - ECDH Public Components : G,W - DH Private Components : G,W - DH Public Components",
"secFunImpl": "Generate Asymmetric Keys CKG Section 4"
},
{
"description": "Generate asymmetric key pairs using specific key parameters",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcBuildKeyPairFromPara ms()",
"outputs": "KeyPair, Invocation Success or Invocation Failure",
"rolesSspAccess": ": G,W CO - RSA Private Key: G,W - RSA Public Key: G,W - ECDSA Private Key: G,W - ECDSA Public Key: G,W - ECDH Private Components : G,W",
"secFunImpl": "Generate Asymmetric Keys Shared Secret Computatio n (KAS- FFC-SSC) Shared Secret Computatio n (KAS- ECC-SSC)"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- ECDH Public Components : G,W - DH Private Components : G,W - DH Public Components : G,W",
"secFunImpl": ""
},
{
"description": "Wrap Key",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcExportKey()",
"outputs": "Key/KeyPair, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - Key Encryption Key (KEK): R,E",
"secFunImpl": "Key Wrapping"
},
{
"description": "Unwrap Key",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcImportKey()",
"outputs": "Key/KeyPair, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - Key Encryption Key (KEK): W,E",
"secFunImpl": "Key Wrapping"
},
{
"description": "Return the key size for a selected Key",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcKeySize()",
"outputs": "Key Size, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Establish a shared secret",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcKeyExchange()",
"outputs": "Shared, Secret, Key, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - ECDH Private Components : R,E - ECDH Public Components : R,E - DH Private Components : R,E - DH Public Components",
"secFunImpl": "Shared Secret Computatio n (KAS- FFC-SSC) Shared Secret Computatio n (KAS- ECC-SSC)"
},
{
"description": "Derive a key",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcDeriveKey()",
"outputs": "Key, Invocation Success or Invocation Failure",
"rolesSspAccess": ": R,E CO - TLS Session Key: G,W - PBKDF2 DPK: G,W - AES Key : G,W - TLS RSA Premaster Secret: G,W - TLS Master",
"secFunImpl": "Derive Key (TLS 1.2) Derive Key (TLS 1.3) Derive Key (PBKDF)"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Secret: G,W - TLS Integrity Key: G,W - PBKDF2 Password: G,W - TLS Extended Master",
"secFunImpl": ""
},
{
"description": "Zeroize Keys",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcReleaseHandle()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "Secret: G,W CO - AES Key : Z - AES GCM Key: Z - AES GCM IV: Z - AES CCM Key: Z - AES-XTS Testing Revision 2.0 Key: Z - AES CMAC Key: Z - AES GMAC Key: Z - HMAC Key: Z - Key Encryption Key (KEK): Z - PBKDF2 DPK: Z - PBKDF2 Password: Z - RSA Private Key: Z - ECDSA Private Key: Z - ECDH Private Components : Z - TLS RSA Premaster Secret: Z - TLS Master",
"secFunImpl": "None"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Secret: Z - TLS Session Key: Z - TLS Integrity Key: Z - DRBG Entropy: Z - DRBG Seed: Z - DRBG \u0027C\u0027 Value: Z - DRBG \u0027V\u0027 Value : Z - RSA Public Key: Z - ECDSA Public Key: Z - ECDH Public Components : Z - TLS Extended Master",
"secFunImpl": ""
},
{
"description": "Query whether library is in the soft error state",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcAceLibraryStatus()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Message authenticatio n",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcKeyedDigest()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - HMAC Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E",
"secFunImpl": "Message Digest Message Authenticati on"
},
{
"description": "Message authenticatio n digest size",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcDigestSize()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Encrypt plaintext",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcEncrypt()",
"outputs": "Ciphertext, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - AES Key : R,E - AES GCM Key: R,E - AES GCM IV: R,E",
"secFunImpl": "Message Authenticati on Symmetric Cipher"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- AES CCM Key: R,E - AES-XTS Testing Revision 2.0 Key: R,E - AES CMAC Key: R,E - AES GMAC Key: R,E",
"secFunImpl": ""
},
{
"description": "Return size of ciphertext",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcEncryptBlockSize()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Sets/Configur es non- security relevant operational parameters",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcSetOperationParameter ()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Returns the Module\u0027s Algorithm capabilities",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcGetVendorImplementati on()",
"outputs": "Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Encrypt plaintext",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcAESFpeEncrypt( )",
"outputs": "Ciphertext, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - AES Key : R,E",
"secFunImpl": "Symmetric Cipher"
},
{
"description": "Get Data Pointer",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AsGetCryptoDataPtr()",
"outputs": "Data Pointer, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Get Error Message",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcGetAceError()",
"outputs": "Error Message, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
},
{
"description": "Gather Entropy Input",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcGatherSystemNoise()",
"outputs": "Entropy Input, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - DRBG Entropy: G,W,E - DRBG \u0027V\u0027 Value : G,W,E - DRBG \u0027C\u0027 Value: G,W,E",
"secFunImpl": "None"
},
{
"description": "Get DRBG Personalizati on Data",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcGetPersonalizationData ()",
"outputs": "Personalizati on Data, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO - DRBG Personalizati on String: R - DRBG Seed: G,W,E",
"secFunImpl": "None"
},
{
"description": "Duplicate an Encrypt Operation",
"indicator": "Successf ul Invocatio n (Pass)",
"inputs": "API call paramete rs",
"name": "AcEncryptClone()",
"outputs": "Encrypt Operation, Invocation Success or Invocation Failure",
"rolesSspAccess": "CO",
"secFunImpl": "None"
}
],
"found": true,
"section": 4,
"subsection": 3
},
"authentication_methods": {
"entries": [],
"found": false,
"section": 4,
"subsection": 1
},
"cond_self_tests": {
"entries": [
{
"algorithmOrTest": "AES-CBC (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CCM (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CCM (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CFB1 (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CFB1 (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CFB128 (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CFB128 (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CFB8 (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CFB8 (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CMAC (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CMAC (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CTR (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CTR (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-ECB (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-ECB (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-FF1 (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-OFB (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-OFB (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 192, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-XTS Testing Revision 2.0 (A3332)",
"condition": "Power-On",
"details": "Encrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "AES-XTS Testing Revision 2.0 (A3332)",
"condition": "Power-On",
"details": "Decrypt",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "128, 256 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A3332)",
"condition": "Power-On",
"details": "Sign",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "P-384 Curve",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A3332)",
"condition": "Power-On",
"details": "Verify",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "P-384 Curve",
"type": "CAST"
},
{
"algorithmOrTest": "Hash DRBG (A3332)",
"condition": "1. Power On 2. Instantiate: Any time that a new DRBG instance is created 3. Generate: When new random data is generated 4. Reseed: When the reseed counter has reached its pre- determined maximum value and the DRBG needs to be reseeded",
"details": "Hash_DRBG",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "SHA2-256, SHA2-512 (NIST SP 800- 90A, Section 11.3 Health Tests)",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA-1 (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "160 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-224 (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "224 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-256 (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "256 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-384 (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "384 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-512 (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "512 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA3-224 (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "224 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA3-256 (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "256 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA3-384 (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "384 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA3-512 (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "512 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A3332)",
"condition": "Power-On",
"details": "Primitive \"Z\"",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "P-384 Curve",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 (A3332)",
"condition": "Power-On",
"details": "Primitive \"Z\"",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "MODP-2048, MODP-3072",
"type": "CAST"
},
{
"algorithmOrTest": "KDA HKDF Sp800- 56Cr1 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "KDF SSH (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "AES-128, AES-192, AES-256, SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "PBKDF (A3332)",
"condition": "Power-On",
"details": "Keyed Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "160 bit Keyed Hash",
"type": "CAST"
},
{
"algorithmOrTest": "RSA SigGen (FIPS186-4) (A3332)",
"condition": "Power-On",
"details": "Sign",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "2048 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "RSA SigVer (FIPS186-4) (A3332)",
"condition": "Power-On",
"details": "Verify",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "2048 bit Key",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "160 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-224 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "224 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-256 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "256 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-384 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "384 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-512 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "512 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3-224 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "224 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3-256 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "256 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3-384 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "384 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3-512 (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "512 bit Hash",
"type": "CAST"
},
{
"algorithmOrTest": "TLS v1.2 KDF RFC7627",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "TLS v1.3 KDF (A3332)",
"condition": "Power-On",
"details": "Hash",
"indicator": "Pass",
"testMethod": "KAT",
"testProps": "SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "AES-XTS Testing Revision 2.0 (A3332)",
"condition": "Conditional upon first use of AES-XTS",
"details": "Check",
"indicator": "Pass",
"testMethod": "Key_1 \u2260 Key_2 (IG C.I)",
"testProps": "128, 256 bit key",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A3332)",
"condition": "Conditional upon ECDSA KeyPair Generation",
"details": "Check",
"indicator": "Pass",
"testMethod": "Public Key Assurance Test",
"testProps": "P-224, P-256, P-384, P-521",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A3332)",
"condition": "Conditional upon ECDSA KeyPair Generation",
"details": "Sign \u0026 Verify",
"indicator": "Pass",
"testMethod": "Pairwise Consistency Test",
"testProps": "P-384",
"type": "PCT"
},
{
"algorithmOrTest": "RSA KeyGen (FIPS186-4) (A3332)",
"condition": "Conditional upon RSA KeyPair Generation",
"details": "Sign \u0026 Verify",
"indicator": "Pass",
"testMethod": "Pairwise Consistency Test",
"testProps": "2048 bit key",
"type": "PCT"
}
],
"found": true,
"section": 10,
"subsection": 2
},
"error_states": {
"entries": [
{
"conditions": "Result of pre-operational self-test failure Result of CAST failure",
"description": "Non-recoverable error state",
"indicator": "Fail",
"name": "Hard Error State",
"recoveryMethod": "Reload module / Reinstall module"
},
{
"conditions": "Result of RSA pairwise consistency test failure Result of ECDSA pairwise consistency test failure Result of Key_1 \u2260 Key_2 for AES - XTS",
"description": "Recoverable error state",
"indicator": "Fail",
"name": "Soft Error State",
"recoveryMethod": "Automatic"
}
],
"found": true,
"section": 10,
"subsection": 4
},
"mechanisms_actions": {
"entries": [],
"found": false,
"section": 7,
"subsection": 1
},
"modes_of_operation": {
"entries": [
{
"description": "Mode of operation where only approved security functions and services can be utilized",
"name": "Approved Mode",
"statusIndicator": "Pass",
"type": "Approved"
}
],
"found": true,
"section": 2,
"subsection": 4
},
"non_approved_allowed_NSC": {
"entries": [
{
"caveat": "Allowed in the approved mode with no security claimed",
"name": "MD5",
"use": "Used for TLS 1.2 interoperability"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_allowed_algos": {
"entries": [
{
"algoPropList": "Key Type:Symmetric",
"implName": "N/A",
"name": "Key Unwrap",
"reference": "IG D.G"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_not_allowed": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_services": {
"entries": [],
"found": false,
"section": 4,
"subsection": 4
},
"ports_interfaces": {
"entries": [
{
"data": "Input data passed via API calls as function arguments or in memory buffers referenced by function arguments",
"logicalInterface": "Data Input",
"physicalPort": "N/A"
},
{
"data": "Data returned by API calls using function arguments and related memory buffers",
"logicalInterface": "Data Output",
"physicalPort": "N/A"
},
{
"data": "API function calls that initialize and control the operation of the module",
"logicalInterface": "Control Input",
"physicalPort": "N/A"
},
{
"data": "Values returned from API calls",
"logicalInterface": "Status Output",
"physicalPort": "N/A"
}
],
"found": true,
"section": 3,
"subsection": 1
},
"roles": {
"entries": [
{
"authMethodList": "None",
"name": "CO",
"operatorType": "Crypto Officer",
"type": "Role"
}
],
"found": true,
"section": 4,
"subsection": 2
},
"security_levels": {
"entries": [
{
"level": "1",
"section": "1",
"title": "General"
},
{
"level": "1",
"section": "2",
"title": "Cryptographic module specification"
},
{
"level": "1",
"section": "3",
"title": "Cryptographic module interfaces"
},
{
"level": "1",
"section": "4",
"title": "Roles, services, and authentication"
},
{
"level": "1",
"section": "5",
"title": "Software/Firmware security"
},
{
"level": "1",
"section": "6",
"title": "Operational environment"
},
{
"level": "N/A",
"section": "7",
"title": "Physical security"
},
{
"level": "N/A",
"section": "8",
"title": "Non-invasive security"
},
{
"level": "1",
"section": "9",
"title": "Sensitive security parameter management"
},
{
"level": "1",
"section": "10",
"title": "Self-tests"
},
{
"level": "1",
"section": "11",
"title": "Life-cycle assurance"
},
{
"level": "N/A",
"section": "12",
"title": "Mitigation of other attacks"
},
{
"level": "1",
"section": "",
"title": "Overall Level"
}
],
"found": true,
"section": 1,
"subsection": 2
},
"self_tests": {
"entries": [
{
"algorithmOrTest": "HMAC-SHA2-256 (A3332)",
"details": "Keyed hash performed on Acelib.so or AceDll.dll",
"indicator": "Pass",
"testMethod": "Software Integrity Test",
"testProps": "HMAC-SHA2- 256",
"type": "SW/FW Integrity"
}
],
"found": true,
"section": 10,
"subsection": 1
},
"ssp_io_methods": {
"entries": [
{
"dest": "Call stack (API) input parameters",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "Input",
"sfiAlgo": "",
"source": "Calling Process"
},
{
"dest": "Calling Process",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "Output",
"sfiAlgo": "",
"source": "Call stack (API) output parameters"
}
],
"found": true,
"section": 9,
"subsection": 2
},
"ssp_zeroization_methods": {
"entries": [
{
"description": "Unload module from memory",
"method": "Unload Module",
"operatorId": "Operator unloads module",
"rationale": "SSPs no longer present in memory after unload"
},
{
"description": "API zeroize instruction",
"method": "API Call",
"operatorId": "AcDeInit() AcReleaseHandle()",
"rationale": "SSPs no longer present in memory after API call"
},
{
"description": "Power removed from host GPC",
"method": "Remove Power",
"operatorId": "Operator powers off GPC",
"rationale": "SSPs no longer present in memory after GPC power loss"
}
],
"found": true,
"section": 9,
"subsection": 3
},
"storage_areas": {
"entries": [
{
"description": "Random Access Memory",
"name": "RAM",
"persistance": "Dynamic"
}
],
"found": true,
"section": 9,
"subsection": 1
},
"tested_module_id_hw": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_hw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_sw_fw_hy": {
"entries": [
{
"features": "PAA Enabled Binary",
"integrityTest": "HMAC-SHA2-256 (AceLib.dat)",
"packageFileName": "Acelib.so (Linux 5.15) (Mint 21) (PAA Enabled)",
"swFwVersion": "6.50"
},
{
"features": "PAA Enabled Binary",
"integrityTest": "HMAC-SHA2-256 (AceDll.dll.dat)",
"packageFileName": "AceDll.dll (Windows 11 Pro) (PAA Enabled)",
"swFwVersion": "6.50"
},
{
"features": "PAA Disabled Binary",
"integrityTest": "HMAC-SHA2-256 (AceLib.dat)",
"packageFileName": "Acelib.so (Linux 5.15) (Mint 21) (PAA Disabled)",
"swFwVersion": "6.50"
},
{
"features": "PAA Disabled Binary",
"integrityTest": "HMAC-SHA2-256 (AceDll.dll.dat)",
"packageFileName": "AceDll.dll (Windows 11 Pro) (PAA Disabled)",
"swFwVersion": "6.50"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"tested_op_env_sw_fw_hy": {
"entries": [
{
"hardwarePlatform": "Intel NUC",
"hypervisorHostOs": "N/A",
"operatingSystem": "Linux 5.15 (Mint 21)",
"paa_pai": "No",
"processors": "Intel\u00ae Core\u2122 i7-1260P",
"version": "6.50"
},
{
"hardwarePlatform": "Intel NUC",
"hypervisorHostOs": "N/A",
"operatingSystem": "Linux 5.15 (Mint 21)",
"paa_pai": "Yes",
"processors": "Intel\u00ae Core\u2122 i7-1260P",
"version": "6.50"
},
{
"hardwarePlatform": "Intel NUC",
"hypervisorHostOs": "N/A",
"operatingSystem": "Windows 11 Pro",
"paa_pai": "No",
"processors": "Intel\u00ae Core\u2122 i7-1260P",
"version": "6.50"
},
{
"hardwarePlatform": "Intel NUC",
"hypervisorHostOs": "N/A",
"operatingSystem": "Windows 11 Pro",
"paa_pai": "Yes",
"processors": "Intel\u00ae Core\u2122 i7-1260P",
"version": "6.50"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"vendor_affirmed_algos": {
"entries": [
{
"algoPropList": "Key Type:Symmetric",
"implName": "N/A",
"name": "CKG Section 4",
"reference": "NIST SP 800-133 Rev. 2 (Section 4)"
},
{
"algoPropList": "Key Type:Seed for Asymmetric Key",
"implName": "N/A",
"name": "CKG Section 4",
"reference": "NIST SP 800-133 Rev. 2 (Section 4)"
},
{
"algoPropList": "Key Type:Symmetric",
"implName": "N/A",
"name": "CKG Section 6.1",
"reference": "NIST SP 800-133 Rev. 2 (Section 6.1)"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"vendor_affirmed_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
}
},
"is_br1_format": true,
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECDH": {
"ECDH": 15
},
"ECDSA": {
"ECDSA": 38
}
},
"FF": {
"DH": {
"DH": 10
}
}
},
"certification_process": {},
"cipher_mode": {
"CCM": {
"CCM": 7
},
"GCM": {
"GCM": 18
},
"XTS": {
"XTS": 1
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"SSH": {
"SSH": 8,
"SSHv2": 2
},
"TLS": {
"TLS": {
"TLS": 30,
"TLS 1.2": 15,
"TLS 1.3": 10,
"TLS v1.2": 5,
"TLS v1.3": 4
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 1
},
"MAC": {
"MAC": 2
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-192": 2,
"P-224": 20,
"P-256": 10,
"P-384": 20,
"P-521": 12
}
},
"eval_facility": {},
"fips_cert_id": {},
"fips_certlike": {
"Certlike": {
"AES-128": 2,
"AES-192": 2,
"AES-256": 2,
"AES-CMAC 128": 1,
"AES-GCM 128": 1,
"AES-GCM 96": 1,
"HMAC- SHA-1": 1,
"HMAC-SHA-1": 10,
"SHA-1": 7,
"SHA-3": 2,
"SHA2- 384": 1,
"SHA2-224": 8,
"SHA2-256": 21,
"SHA2-384": 9,
"SHA2-512": 15,
"SHA3-224": 5,
"SHA3-256": 7,
"SHA3-384": 5,
"SHA3-512": 6,
"SHA3-512 160": 1
}
},
"fips_security_level": {
"Level": {
"Level 1": 4
}
},
"hash_function": {
"MD": {
"MD5": {
"MD5": 2
}
},
"PBKDF": {
"PBKDF": 13,
"PBKDF2": 16
},
"SHA": {
"SHA1": {
"SHA-1": 7
},
"SHA3": {
"SHA-3": 2,
"SHA3-224": 6,
"SHA3-256": 6,
"SHA3-384": 6,
"SHA3-512": 6
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 57
},
"RNG": {
"RBG": 2
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-3": 8,
"FIPS 1403": 1,
"FIPS 180-4": 5,
"FIPS 186-4": 8,
"FIPS 198-1": 9,
"FIPS 202": 6,
"FIPS186-4": 29
},
"NIST": {
"NIST SP 800-132": 1,
"NIST SP 800-133": 5,
"NIST SP 800-38F": 1,
"NIST SP 800-90A": 1,
"SP 800-107": 1,
"SP 800-132": 1,
"SP 800-135": 3,
"SP 800-38A": 7,
"SP 800-38B": 1,
"SP 800-38C": 1,
"SP 800-38D": 2,
"SP 800-38E": 1,
"SP 800-38F": 2,
"SP 800-38G": 1,
"SP 800-52": 1,
"SP 800-56A": 4,
"SP 800-56C": 1,
"SP 800-90A": 1
},
"RFC": {
"RFC 5246": 1,
"RFC 5288": 1,
"RFC 7627": 1,
"RFC 8446": 1,
"RFC7627": 4
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 54,
"AES-": 2,
"AES-128": 2,
"AES-192": 2,
"AES-256": 2
},
"CAST": {
"CAST": 112
}
},
"constructions": {
"MAC": {
"CMAC": 10,
"HMAC": 7
}
}
},
"tee_name": {
"AMD": {
"PSP": 4
},
"IBM": {
"SSC": 10
}
},
"tls_cipher_suite": {
"TLS": {
"TLS_DHE_DSS_WITH_AES_128_GCM_SHA256": 1,
"TLS_DHE_DSS_WITH_AES_256_GCM_SHA384": 1,
"TLS_DHE_RSA_WITH_AES_128_GCM_SHA256": 1,
"TLS_DHE_RSA_WITH_AES_256_GCM_SHA384": 1,
"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 1,
"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA384": 1,
"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1,
"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 1
}
},
"vendor": {},
"vulnerability": {}
},
"module_algorithms": {
"_type": "Set",
"elements": [
"Safe Primes Key VerificationA3332",
"KDA HKDF Sp800-56Cr1A3332",
"HMAC-SHA2-224A3332",
"AES-CFB128A3332",
"PBKDFA3332",
"AES-KWA3332",
"SHAKE-128A3332",
"AES-GCMA3332",
"AES-CMACA3332",
"AES-OFBA3332",
"RSA KeyGen (FIPS186-4)A3332",
"KAS-ECC-SSC Sp800-56Ar3A3332",
"HMAC-SHA3-224A3332",
"Safe Primes Key GenerationA3332",
"TLS v1.2 KDF RFC7627A3332",
"TLS v1.3 KDFA3332",
"Hash DRBGA3332",
"AES-KWPA3332",
"AES-ECBA3332",
"SHA-1A3332",
"HMAC-SHA3-384A3332",
"SHA3-384A3332",
"ECDSA KeyVer (FIPS186-4)A3332",
"HMAC-SHA3-512A3332",
"RSA SigGen (FIPS186-4)A3332",
"SHA2-256A3332",
"AES-GMACA3332",
"AES-CFB1A3332",
"ECDSA KeyGen (FIPS186-4)A3332",
"HMAC-SHA-1A3332",
"KAS-FFC-SSC Sp800-56Ar3A3332",
"SHA3-224A3332",
"SHA3-512A3332",
"HMAC-SHA3-256A3332",
"SHAKE-256A3332",
"AES-CTRA3332",
"HMAC-SHA2-512A3332",
"RSA SigVer (FIPS186-4)A3332",
"HMAC-SHA2-256A3332",
"AES-FF1A3332",
"AES-CFB8A3332",
"ECDSA SigVer (FIPS186-4)A3332",
"AES-XTS Testing Revision 2.0A3332",
"SHA2-512A3332",
"SHA3-256A3332",
"AES-CBCA3332",
"HMAC-SHA2-384A3332",
"SHA2-224A3332",
"SHA2-384A3332",
"AES-CCMA3332",
"ECDSA SigGen (FIPS186-4)A3332",
"KDF SSHA3332"
]
},
"policy_algorithms": {
"_type": "Set",
"elements": [
"#A3332"
]
},
"policy_metadata": {
"/Author": "Hawes, David J. (Fed)",
"/Comments": "",
"/Company": "",
"/CreationDate": "D:20241211124720-05\u002700\u0027",
"/Creator": "Acrobat PDFMaker 24 for Word",
"/Keywords": "",
"/ModDate": "D:20241211124846-05\u002700\u0027",
"/Producer": "Adobe PDF Library 24.3.144",
"/SourceModified": "",
"/Subject": "",
"/Title": "",
"pdf_file_size_bytes": 556729,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 40
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "e8f984ae30f941b5cd437924d02eeaf58cda3d4316e89b9011dc97fba281da52",
"source_hash": "e5e528a49bfd0ebe09fd2a5dd18d23e0b92342378ceabb61b5eadbfbaef6c3b5",
"txt_hash": "3f1c91dc0826f73a6a99120b009631ca66d0c3da375f2bf3e1f52c9ee346b088"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "Interim validation. No assurance of the minimum strength of generated SSPs (e.g., keys)",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/January 2025-signed.pdf",
"date_sunset": null,
"description": "Allegro\u2019s suite of Embedded Device Security tool kits makes embedding standards-based security protocols into resource sensitive embedded systems and consumer electronics fast, easy and reliable. The Allegro Cryptographic Engine (ACE) is a cryptographic library module specifically engineered for embedded devices. The module provides embedded systems developers with an easily understood software interface to enable bulk encryption and decryption, message digests, digital signature creation and validation and key generation and exchange. For full details see www.allegrosoft.com/ace.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Physical security: N/A",
"Non-invasive security: N/A",
"Mitigation of other attacks: N/A"
],
"fw_versions": null,
"historical_reason": "Replaced by certificate #5246",
"hw_versions": null,
"level": 1,
"mentioned_certs": {},
"module_name": "Allegro Cryptographic Engine",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-3",
"status": "historical",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2025-01-17",
"lab": "Acumen Security",
"validation_type": "Initial"
}
],
"vendor": "Allegro Software Development Corporation",
"vendor_url": "http://www.allegrosoft.com"
}
}