Cisco Systems 7206VXR NPE-400 manual Self-Tests, Key Zeroization, HMAC-SHA-1 KAT

Page 15

Self-Tests

Key Zeroization

All of the keys and CSPs of the module can be zeroized. Please refer to the Description column of Table 2 for information on methods to zeroize each key and CSP.

Self-Tests

To prevent secure data from being released, it is important to test the cryptographic components of a security module to insure all components are functioning correctly. The router includes an array of self-tests that are run during startup and periodically during operations. If any of the self-tests fail, the router transitions into an error state. Within the error state, all secure data transmission is halted and the router outputs status information indicating the failure.

Self-tests performed by the IOS image:

Power-up tests

Firmware integrity test

RSA signature KAT (both signature and verification)

DES KAT

TDES KAT

AES KAT

SHA-1 KAT

PRNG KAT

Power-up bypass test

Diffie-Hellman self-test

HMAC-SHA-1 KAT

Conditional tests

Conditional bypass test

Pairwise consistency test on RSA signature

Continuous random number generator tests

Self-tests performed by the VAM (cryptographic accelerator):

Power-up tests

Firmware integrity test

RSA signature KAT (both signature and verification)

DES KAT

TDES KAT

SHA-1 KAT

HMAC-SHA-1 KAT

PRNG KAT

Conditional tests

Pairwise consistency test on RSA signature

FIPS 140-2 Nonproprietary Security Policy for Cisco 7206VXR NPE-400 Router with VAM

 

OL-3959-01

15

 

 

 

Image 15
Contents Introduction Overview Fips 140-2 Submission PackageModule Interfaces Cryptographic ModuleIndication Description IO Power OKLED Label Color State Function EnableBoot ErrorRouter Physical Interface Fips 140-2 Logical Interface Roles and ServicesUser Role Crypto Officer RolePhysical Security Cryptographic Key Management Cryptographic Key ManagementCSP Name Description Storage CSP17 CSP14CSP15 CSP16CSP28 CSP25CSP26 CSP27Role and Service Access to CSPs Cryptographic Key Management HMAC-SHA-1 KAT Self-TestsKey Zeroization DES KAT Tdes KAT AES KAT SHA-1 KAT Prng KATInitial Setup System Initialization and ConfigurationSecure Operation Protocols Remote AccessObtaining Documentation IPSec Requirements and Cryptographic AlgorithmsDocumentation Feedback Obtaining Technical AssistanceOrdering Documentation Submitting a Service Request Definitions of Service Request SeverityCisco Technical Support Website Obtaining Additional Publications and Information Obtaining Additional Publications and Information OL-3959-01