
Security Target Version 1.0 9/29/2014
NIST SP800-56B
Section Reference
“should”, “should not”, or
“shall not”
Implemented? Rationale for deviation
should (first occurrence)
should (second occurrence)
should (third occurrence)
should (fourth occurrence)
should (first occurrence)
should (second occurrence)
should (third occurrence)
should (fourth occurrence)
should (fifth occurrence)
Table 6 NIST SP800-56B Conformance
Zeroization
Key Encryption
Key (KEK)
Triple-DES 168-
bit key
Hardcoded during
manufacturing
Stored in Flash.
Zeroized by using
command ‘wipe out
flash’
Encrypts
IKEv1/IKEv2 Pre-
shared key, RADIUS
server shared secret,
RSA private key,
ECDSA private key,
802.11i pre-shared key
and Passwords.
DRBG entropy
input
SP800-90a DRBG
(512 bits)
Derived using NON-
FIPS approved HW
RNG
Stored in plaintext in
volatile memory.
Zeroized on reboot.
DRBG initialization
DRBG seed SP800-90a DRBG
(384 bits)
Generated per SP800-
90A using a derivation
function
Stored in plaintext in
volatile memory.
Zeroized on reboot.
DRBG initialization
Comentários a estes Manuais