Advanced Encryption
Type-2 Confidential non-Classified Encryption
Antenna Products utilizes the Security Builder (SB) Government Security Edition (GSE-C 2.4) provided by Certicom under an OEM licensing agreement.
This leverages Certicom’s existing FIPS 140-2 validated cryptographic toolkit, Security Builder GSE-C 2.4 which includes Security Builder FIPS Module v2.4. NIST has completed its certification of the MMR SBC (Power PC) and operating system issuing the certification numbers:
FIPS Validated Certificate No. 882
Secure Hash Standard certificate number 614
Random Number Generation certificate number 317
The algorithms supported are:
- Elliptic Curve Cryptosystem (ECC)
- Curves SECT163K1, SECT283K1, SECP256R1 and SECP384R
- Digital Signature
- Key Exchange
- Encryption
- ECIES (XOR with ECDH, ANSI 9.63 KDF and SHA-1)
- ECQV (Implicit Certificate)
- Integer Discrete Log Cryptosystem (IDLC)
- Diffie-Hellman (DH)
- Digital Signature Algorithm (DSA)
- RSA
- RAW exponentiation
- PKCS#1 version 1.5 encryption and signature
- PKCS#1 version 2.1 OAEP encryption
- Block cipher
- AES
- 128 bit, 192 bit and 256 bit key sizes
- Encryption modes ECB, CBC, OFB, CFB and CTR (counter)
- Authenticated encryption modes CCM, CCM* and GCM
- DES
- Single and triple DES
- ECB, CBC, OFB and CFB modes
- ARC2
- ECB, CBC, OFB and CFB modes
- Stream cipher
- Hash functions
- SHA-1
- SHA-2
- SHA-224, SHA-256, SHA-384 and SHA-512
- MD2, MD4 and MD5
- Message Authentication Code (MAC)
- Keyed Hashed MAC (HMAC)
- HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384, HMAC-SHA512 and HMAC-MD5
- Cipher based
- Key Derivation
- IEEE 1363-2000 KDF1 based on SHA-1
- NSI X9.42/X9.63 KDF based on SHA-1, SHA-224, SHA-256, SHA-382 and SHA-512
- Pseudo Random Number Generator (PRNG)
- ANSI X9.62 based FIPS 140-2 compliant PRNG
Of the above algorithms, only the following are FIPS 140-2 certified:
- ECDSA
- DSA
- RSA PKCS#1 Signature
- AES ECB, CBC, OFB, CFB, CTR and CCM modes
- Triple DES ECB, CBC, OFB and CFB modes
- SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512
- HMAC-SHA1, HMAC-SHA224, HMAC-SHA256, HMAC-SHA384 and HMAC-SHA512
Type-1 Top Secret Encryption
The MMR has the ability to interface with a Type-1 encryptor module that provides the highest levels of Data Protection for MobileIP Communications. This module is NSA –Certified and provides Top Secret encryption.