
Page 36 of 51
© Copyright 2017 Oracle Corporation
This document may be freely reproduced and distributed whole and intact including this Copyright notice.
Key
Key Type
Generation / Input
Output
Storage
Zeroization
Use
Firmware Signature
Public Key
(FSPubKey)
RSA 2048-bit public
key
Generated externally;
Hardcoded into
module
Does not exit the
module
Plaintext in
EEPROM
Not Applicable
Validate a new
firmware image loaded
onto module
Firmware Signature
Root Certificate Key
(FSRootCert)
RSA 2048-bit public
key
Generated externally;
Hardcoded into
module
Output encrypted via
DEKey
Plaintext in
EEPROM and RAM
Not Applicable
Verify the chain of
certificates provided by
the new firmware
image
DRBG Seed
Random bit value
Generated internally Output encrypted via
DEKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Generate random
values for the
CTR_DRBG
DRBG ‘V’ Value
Internal DRBG state
value (integer)
Generated internally Output encrypted via
DEKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Internal state value for
the CTR_DRBG
DRBG ‘Key’ Value Internal DRBG state
value (integer)
Generated internally Output encrypted via
DEKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Internal state value for
the CTR_DRBG
2.7.5 Encryption Disabled Cryptographic Keys and Critical Security Parameters
The cryptographic keys, key components, and other CSPs used by the module while operating in the Encryption
Disabled Approved Mode are shown in Table 10.
Table 10 – List of Cryptographic Keys, Cryptographic Key Components, and CSPs (Encryption Disabled Mode)
Key
Key Type
Generation / Input
Output
Storage
Zeroization
Use