Mediatek Cryptocore Hw V1.0, Fw V1.0 Fips 140-2 N
Total Page:16
File Type:pdf, Size:1020Kb
MEDIATEK CRYPTOCORE HW V1.0, FW V1.0 FIPS 140-2 NON-PROPRIETARY SECURITY POLICY VERSION 2.2 MEDIATEK INC. JUNE 2018 MEDIATEK INC. No. 1, Dusing 1st Rd. Hsinchu Science Park Hsinchu City 30078 Taiwan MediaTek Cryptographic Module FIPS 140-2 Security Policy Table of Contents 1. Introduction .......................................................................................................................................... 1 1.1 Purpose of the Security Policy ...................................................................................................... 1 1.2 Target Audience ............................................................................................................................ 1 1.3 Document Organization / Copyright ............................................................................................. 1 2. Cryptographic Module Specification ..................................................................................................... 1 2.1 Module Overview .......................................................................................................................... 1 2.1.1 Module Embodiment ............................................................................................................ 2 2.1.2 Module Validation Level ....................................................................................................... 3 2.1.3 Module Hardware ................................................................................................................. 3 2.1.4 Module Software .................................................................................................................. 3 2.1.5 Tested Platform ..................................................................................................................... 3 2.2 Approved Security Functions and Mode of Operation ................................................................. 4 2.2.1 Approved Security Functions ................................................................................................ 4 2.2.2 Allowed Security Functions ................................................................................................... 6 2.2.3 Non-Approved Security Functions ........................................................................................ 6 2.2.4 Approved Security Mode ...................................................................................................... 7 2.3 Cryptographic Module Boundary and Components ..................................................................... 7 2.3.1 Cryptographic Module Boundary .......................................................................................... 7 2.3.2 Software Block Diagram ........................................................................................................ 8 2.3.3 Hardware Block Diagram ...................................................................................................... 8 2.3.4 Module Component ............................................................................................................ 10 2.3.4.1 Secure Core Hardware .................................................................................................... 10 2.3.4.2 Secure Core Firmware ..................................................................................................... 11 2.3.4.3 Public Core Hardware ..................................................................................................... 13 2.3.4.4 Public Core Firmware ...................................................................................................... 14 2.3.4.5 IV Generator .................................................................................................................... 14 2.3.4.6 Persistent State Interface................................................................................................ 15 2.3.4.7 Secure Key Mechanism ................................................................................................... 15 2.4 Life Cycle State and Operational State........................................................................................ 15 © 2017 MediaTek Inc. i MediaTek Cryptographic Module FIPS 140-2 Security Policy 3. Cryptographic Module Ports and Interfaces ....................................................................................... 16 3.1 Secure Core and Public Core Hardware Interfaces ..................................................................... 16 3.2 Secure Core Firmware Interface ................................................................................................. 17 3.3 Public Core Firmware Interface .................................................................................................. 17 4. Roles, Services and Authentication ..................................................................................................... 17 4.1 Roles ............................................................................................................................................ 17 4.2 Services ....................................................................................................................................... 18 4.3 Operator Authentication............................................................................................................. 25 4.4 Mechanism and Strength of Authentication............................................................................... 25 5. Physical Security .................................................................................................................................. 26 6. Operational Environment ................................................................................................................... 26 7. Cryptographic Key Management ........................................................................................................ 26 7.1 User Keys ..................................................................................................................................... 26 7.2 Platform Keys .............................................................................................................................. 26 7.3 Key Generation ........................................................................................................................... 28 7.4 Key Establishment ....................................................................................................................... 28 7.5 Key Entry and Output .................................................................................................................. 29 7.6 Key Storage ................................................................................................................................. 29 7.7 Key Zeroization............................................................................................................................ 29 8. Electromagnetic Interference / Compatibility (EMI/EMC) ................................................................. 29 9. Self Tests ............................................................................................................................................. 30 9.1 Power-up Tests ........................................................................................................................... 30 9.1.1 Cryptography Test ............................................................................................................... 30 9.1.1.1 Tests in Public Core ......................................................................................................... 30 9.1.1.2 Tests in Secure Core ........................................................................................................ 30 9.1.2 Firmware Integrity Test ....................................................................................................... 31 9.2 Conditional Tests ......................................................................................................................... 31 10. Design Assurance ............................................................................................................................ 32 10.1 Configuration Management ........................................................................................................ 32 10.1.1 Software .............................................................................................................................. 32 10.1.2 Hardware............................................................................................................................. 32 10.2 Delivery and Operation ............................................................................................................... 32 © 2017 MediaTek Inc. ii MediaTek Cryptographic Module FIPS 140-2 Security Policy 10.3 Guidance ..................................................................................................................................... 32 10.3.1 Operator Guidance ............................................................................................................. 32 10.4 Proprietary Document ................................................................................................................ 32 11. Mitigation of Other Attacks ............................................................................................................ 33 Bibliography ...............................................................................................................................................