Module Name
MS1201 Security Sub-system
Historical Reason
SP 800-56Arev3 transition
Caveat
When operated in FIPS mode
Security Level Exceptions
- Physical Security: Level 3
- Mitigation of Other Attacks: N/A
Description
MS1201 Security Sub-system is a Silicon IP Security Module with a secure asset store protecting all valuable assets on your device. It is a stand-alone Root of Trust that offers key management and crypto functions needed for platform and application security. MS1201 Security Sub-system offers all security services to manage your device securely through its lifecycle. These include Secure Debug, Secure Provisioning, HUK and Identity protection and secure authentication services.
Tested Configuration(s)
- MS1201 Security Sub-system
FIPS Algorithms
AES |
Cert. #C1900 |
CKG |
vendor affirmed |
CVL |
Cert. #C1900 |
DRBG |
Cert. #C1900 |
ECDSA |
Cert. #C1900 |
HMAC |
Cert. #C1900 |
KBKDF |
Cert. #C1900 |
KDA |
vendor affirmed |
KTS |
AES Cert. #C1900; key establishment methodology provides between 128 and 256 bits of encryption strength |
KTS |
AES Cert. #C1900 and AES Cert. #C1900; key establishment methodology provides 256 bits of encryption strength |
RSA |
Cert. #C1900 |
SHS |
Cert. #C1900 |
Allowed Algorithms
EC Diffie-Hellman (CVL Cert. #C1900 with SP 800-56C, vendor affirmed, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); NDRNG