
Page 34 of 51
© Copyright 2017 Oracle Corporation
This document may be freely reproduced and distributed whole and intact including this Copyright notice.
Key
Key Type
Generation / Input
Output
Storage
Zeroization
Use
TLS_PM
48 bytes random
data
Generated internally
via Approved DRBG
Output encapsulated
via CA_Cert
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Premaster secret for
TLS 1.0/1.1 session
TLS_MS
48 bytes pseudo-
random data
Generated internally
via TLS 1.0/1.1
PRF
51
Output encrypted via
DEKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Master secret for TLS
1.0/1.1 session
TLS_EMK
HMAC SHA-1 (112-
bits)
Generated internally
via TLS 1.0/1.1 PRF
Output encrypted via
DEKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Authentication key for
data leaving the module
(per TLS 1.0/1.1)
TLS_DMK
HMAC SHA-1 (112-
bits)
Generated internally
via TLS 1.0/1.1 PRF
Output encrypted via
DEKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Authentication key for
data entering the
module (per TLS
1.0/1.1)
TLS_ECK
AES CBC 256-bit
Generated internally
via TLS 1.0/1.1 PRF
Output encrypted via
DEKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Encryption key for data
leaving the module (per
TLS 1.0/1.1)
TLS_DCK
AES CBC 256-bit
Generated internally
via TLS 1.0/1.1 PRF
Output encrypted via
DEKey
Plaintext in RAM
“Reset” service;
Power cycle;
Switch Approved
Mode
Decryption key for data
entering the module
(per TLS 1.0/1.1)
SSH_HOST_PRIV
RSA 2048-bit
Private Key
ECDSA P256 Curve
Private Key
Generated internally
via Approved DRBG
Output encrypted
via DEKey
Plaintext in
EEPROM
“Reset” service;
Power cycle;
Switch Approved
Mode
SSH Authentication
51
PRF (Pseudo Random Function) is based on a hash on the TLS_PM and nonces; Utilizes SHA-1 and MD5 (Message Digest 5)