
Critical Security Parameters
The following are the Critical Security Parameters (CSPs) used in the module.
Table 6 CSPs/Keys Used in the module
#
Name
Algorithm/Key Size
Generation/Use
Storage
Zeroization
General Keys/CSPs
1
Key Encryption Key
(KEK)
Triple-DES
(192 bits)
Hardcoded during
manufacturing. Used to
protect keys stored in
the flash.
Stored in Flash
memory (plaintext).
Zeroized by using
command ‘write erase
all’.
2
DRBG entropy input SP 800-90a
CTR_DRBG
(512 bits)
Entropy inputs to DRBG
function used to
construct the DRBG
seed.
Stored in SDRAM
memory (plaintext)
Zeroized by rebooting
the module
3
DRBG seed
SP 800-90a
CTR_DRBG
(384-bits)
Input to the DRBG that
determines the internal
state of the DRBG.
Generated using DRBG
derivation function that
includes the entropy
input from the entropy
source.
Stored in SDRAM
memory (plaintext)
Zeroized by rebooting
the module
4
DRBG Key
SP 800-90a
CTR_DRBG
(256 bits)
This is the DRBG key
used for SP 800-90a
CTR_DRBG
Stored in SDRAM
memory (plaintext)
Zeroized by rebooting
the module
5
DRBG V
SP 800-90a
CTR_DRBG V
(128 bits)
Internal V value used as
part of SP 800-90a
CTR_DRBG
Stored in SDRAM
memory (plaintext)
Zeroized by rebooting
the module
22
|
Aruba 7XXX Series Controllers FIPS 140-2 Level 2 Security Policy