All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Samsung NVMe TCG Opal SSC SEDs BM1733a Series

Certificate#4681StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorSamsung Electronics Co., Ltd.
Medium review priority  ·  no TCB surface named  ·  last validated 28 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date3/24/2029
CaveatNone
VendorSamsung Electronics Co., Ltd.

Approved Algorithms (4)

AlgorithmACVP Cert
AES-XTSC1271
Hash DRBGA1720
RSA SigVer (FIPS186-4)A940
SHA2-256C1272

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Samsung NVMe TCG Opal SSC SEDs BM1733a Series
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Show Status<br/>Status Output<br/>self-test</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Samsung NVMe TCG Opal SSC SEDs BM1733a Series
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Show Status<br/>Status Output<br/>self-test</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Samsung NVMe TCG Opal SSC SEDs BM1733a Series Document Version: 1.0 H/W Version: MZEM515THALC-00AMV F/W Version: MPOA3A5Q

Page 2
VersionChange
1.0Initial Version

Revision History Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 3
Table of Contents
#SectionPage
Page 4
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
AcronymDescription
CTRLController
CPUCentral Processing Unit (ARM-based)
DRAMDynamic Random Access Memory
DRAM I/FDynamic Random Access Memory Interface
ECCError Correcting Code
KATKnown Answer Test
LBALogical Block Address
MEKMedia Encryption Key
MSIDManufactured SID (Security Identifier)
NANDNAND Flash Memory
NAND I/FNAND Flash Interface
NVMeNon-Volatile Memory Host Controller Interface Specification
ROMRead-only Memory

1.1. Scope This document specifies the security policy for Samsung Electronics Co., Ltd. (“Samsung”) NVMe TCG Opal SSC SEDs BM1733a Series, herein after referred to as a “cryptographic module” or “module”, SSD (Solid State Drive), satisfies all applicable FIPS 140-3 Security Level 1 requirements of a hardware module, supporting TCG Opal SSC based SED (SelfEncrypting Drive) features, designed to protect unauthorized access to the user data stored in its NAND Flash memories. The built-in AES HW engines in the cryptographic module’s controller provide on-the-fly encryption and decryption of the user data without performance loss. The SED’s nature also provides instantaneous sanitization of the user data via cryptographic erase. Table

  1. Security Levels 1.2. Acronyms Table
  2. Acronyms Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 5
  1. Cryptographic module specification 2.1. Cryptographic Boundary The following photograph shows the cryptographic module’s top and bottom views. The multiple-chip standalone cryptographic module consists of hardware and firmware components specified version in the Table 3 that are all enclosed in two aluminum alloy cases, which serve as the cryptographic boundary of the module. Figure
  2. Specification of the Samsung SSD NVMe TCG Opal SSC SEDs BM1733a Series Cryptographic Boundary Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 6
ModelHardware VersionFirmware VersionDrive Capacity
BM1733aMZEM515THALC-00AMVMPOA3A5Q15.36TB

The firmware utilizes a single chip controller with an NVMe interface on the system side as well as Samsung NAND flash. The following figure depicts the module operational environment. The firmware within the scope of this validation must be validated through the FIPS 140-3 CMVP. Any other firmware loaded into this module is out of the scope of this validation and requires a separate FIPS 140-3 validation. Figure

  1. Block Diagram for Samsung SSD NVMe TCG Opal SSC SEDs BM1733a Series 2.2. Version information Table
  2. Cryptographic Module Tested Configuration Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 7
CAVP CertAlgorithm and StandardMode/ MethodDescription/ Key Size(s)/ Key Strength(s)Use/Function
C12711AES / FIPS 197, SP 800-38EXTS,256 bitsData Encryption / Decryption
A1720DRBG / SP 800-90A Rev. 1Hash_ DRBG (SHA-256)N/ADeterministic Random Bit Generation
A940RSA / FIPS 186-4PSS SigVer (SHA-256)3072 bitsDigital Signature Verification
C1272SHS / FIPS 180-4SHA-256N/AMessage Digest
Vendor AffirmedCKG / SP 800-133 rev2Section 4 and Section 6.1N/ACryptographic Key Generation (Symmetric Keys)
N/AENT (P) / SP800-90BN/AN/ANon-deterministic Random Number Generator (only used for generating seed materials for the Approved DRBG)
AlgorithmCaveatUse / Function
AES-XTS / FIPS 197, SP 800-38ENo Security Claimed; AES-XTS is only used for firmware decryption during ROM initialized.Firmware Decryption
AES-CCM / FIPS 197, SP 800-38CNo Security Claimed; Non-approved algorithms here are only used for encrypting or obfuscating the CSP.Key Encryption and Decryption
PBKDF2Key Derivation
HMAC / SHA-256 (SHS Cert.# C1272)Key Derivation
2.3.Cryptographic Functionality The cryptographic module supports the following Approved algorithms for secure data storage: Following algorithms are not intended to be used as a security function, and not used whatsoever to meet any FIPS 140-3 requirements. These algorithms are not provided through a non-approved service to an operator. Table 5. Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed
2.4.Approved Mode of Operation The module only has a single approved mode of operation and does not have a non-approved mode of operation. The cryptographic module shows the approved mode through validated version status by Show Status Service in Table 8 via NVM express Identify Controller command. The only non-approved algorithms present in the module are allowed in the approved mode of operation with no security claimed in the module.
1AES-ECB is the pre-requisite for AES-XTS; AES-ECB alone is NOT supported by the cryptographic module in the approved mode of operation. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 8
Physical portLogical interface TypeData that passes over port/interface
NVMe ConnectorData Input / Outputplaintext data; signed data;
Control Inputcommands input logically via an API; signals input logically or physically via one or more physical ports
Status Outputstatus information output logically via an API; signal outputs logically or physically via one or more physical ports;
Power InputPower input
JTAGControl Inputsignals input logically or physically via one or more physical ports
Status Outputsignal outputs logically or physically via one or more physical ports;
  1. Cryptographic module interfaces Table
  2. Ports and Interfaces Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 9
RoleServiceInputOutput
Cryptographic Officer(CO)Lock/Unlock an LBA RangeLBA Rangestatus
Erase an LBA Range’s DataLBA Rangestatus
Update the firmwareFW image binarystatus
Get Random NumberN/Astatus
IO CommandLBAstatus
FormatNVM / Sanitize / DeleteNSLBA Rangestatus
RevertPSIDN/A
Perform Self-TestsN/AN/A
Maintenance2DiagnosticsN/AN/A
ServiceDescriptionApproved Security FunctionsSSPsRolesType(s) of Access3Indicator4
EWGZ
Show Status5Show approved version status of the module / FIPS fail modeN/AN/ACONVM Command: Identify Controller command Result : Status Code
Lock/Unlock an LBA RangeBlock or allow read (decrypt) / write (encrypt) of user data.AES-XTSMEKOOOUID: Locking_GlobalRange / Locking_RangeNNNN TCG Method: Set Result: TCG status code
Erase an LBA Range’s DataErase user data by changing the data encryption key.Hash_ DRBG (SHA-256)DRBG Internal StateOOUID: K_AES_256_GlobalRange_Key / K_AES_256_RangeNNNN_Key TCG Method: GenKey Result: TCG status code
DRBG SeedOO
DRBG Entropy Input StringOO
MEKOOO
Update the firmwareUpdate the firmwareRSAFW Verification KeyOAdmin Command: Firmware Commit Result : Status Code
Get Random NumberProvide a random number generated by the CM.Hash_ DRBG (SHA-256)DRBG Internal StateOOUID: ThisSP TCG Method: Random Result: TCG status code
DRBG SeedOO
DRBG EntropyOO
  1. Roles, services, and authentication The module does not support role authentication. Roles are implicitly assumed based on the service they are invoking. Table
  2. Roles, Service Commands, Input and Output 4.2.1. Approved Services E: EXECUTE; W: WRITE; G: GENERATE; Z: ZEROISE O O
2 Maintenance role is operator that has responsible for using the JTAG

3 It means that “Write” and “Zeroise” perform in each storage of SSPs that is described in Table 10. The (R)ead column, which is specified in

NIST SP 800-140B, is not applicable to the module.

4 The result of NVMe or TCG command is used as an indicator

5 The cryptographic module shows the hardware version and firmware version through the ‘Model Number (MN)’ and ‘Firmware Revision (FR)’

of Identify Controller Data Structure. If the module enters the FIPS Fail Mode, this service indicates “ERRORMOD” in Firmware Revision (FR). Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 10
Input String
IO CommandRead/Write user dataAES-XTSMEKONVM Command: Write / Read Result : Status Code
FormatNVM / Sanitize / DeleteNSErase user data by changing the data encryption key.Hash_ DRBG (SHA-256)DRBG Internal StateOOAdmin Command: Format NVM / Sanitize / Namespace Management Result : Status Code
DRBG SeedOO
DRBG Entropy Input StringOO
MEKO
RevertErase user data in all Range by changing the dataHash_ DRBG (SHA-256)DRBG Internal StateOOUID: SPObj(AdminSP) TCG Method: Revert Result: TCG status code
Perform Self- testsPower cycling the module to perform self- testsN/AN/AON/A
DiagnosticsPerform MaintenanceN/AN/AMaint enanc eN/A

O O e Table 8. Approved Services Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 11

5. Software/Firmware security - The cryptographic module employs the 428-byte parity for firmware integrity test - The firmware integrity test is performed when power on reset. - The masked ROM embedded in this module is guaranteed for a minimum 10 years after manufactured date under effective lifetime. - If this cryptographic module is no longer deployed, secure sanitization can be fulfilled by carrying out the following NVM Express commands; FormatNVM, Sanitize Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 12

6. Operational environment - The cryptographic module operates in a limited operational environment that is consist of the module’s firmware. This operational environment does not require any specific security rules, settings/configurations or restrictions to be set. - The cryptographic module does not provide any general-purpose operating system to the operator. - Unauthorized modification of the firmware is prevented by the pre-operational firmware integrity test and conditional firmware load test. - Since the cryptographic module is zeroised through the procedure for using maintenance role, it is restricted preventing uncontrolled access to CSPs and uncontrolled modifications of SSPs. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 13
Physical Security MechanismsRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Production grade componentsN/AN/A

The following physical security mechanisms are implemented in a cryptographic module: The following table summarizes the actions required by the Cryptographic Officer Role to ensure that physical security is maintained: The Cryptographic module supports a maintenance role. The maintenance access interface is defined as the JTAG port. In compliance with maintenance role requirements, the operator shall perform the following procedures.

Page 14

8. Non-invasive security - Non-invasive security has not applicable for this cryptographic module Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 15
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablish mentStorageZeroisationUse & related keys
DRBG Internal State6256-bitA1720 Hash_ DRBG (SHA-256)SP 800-90A HASH_DRBG (SHA-256)N/AN/ARAMPower on ResetMEK
DRBG Seed256-bitA1720 Hash_ DRBG (SHA-256)ENT (P)N/AN/ARAMPower on ResetMEK
DRBG Entropy Input String256-bitA1720 Hash_ DRBG (SHA-256)ENT (P)N/AN/ARAMPower on ResetMEK
MEK256-bitC1271 AES-XTSSP 800-90A HASH_DRBG (SHA-256)N/AN/APlain Text in RAM, FlashVia “Unlock an LBA Range”, “Erase an LBA Range’s Data”, “Revert” and “FormatNVM / Sanitize / DeleteNS” serviceN/A
Firmware Verification Key128-bitsA940 RSAN/AEntered during manufact uringN/AHW SFR FlashRight after FW load test N/AFirmware Load Test
Entropy sourcesMinimum number of bits of entropyDetails
ENT (P)- 0.5 entropy per bit - Minimum of 256 bits of entropy for DRBG seed (total seed size of 512 bits).Entropy source for Hash_DRBG
  1. Sensitive security parameter management - Temporary SSPs, stored in RAM are zeroised when power on reset. - Firmware integrity temporary values are zeroised after the firmware integrity test is complete - The zeroisation is performed overwriting the target SSP with random value which is creating through the DRBG. - SSPs are not exported to outside. Table
  2. SSPs The module contains an entropy source, compliant with SP 800-90B, within the module’s cryptographic boundary. Table
  3. Non-Deterministic Random Number Generation Specification
6 The values of V and C are the “secret values” of the internal state

Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 16
AlgorithmDescription
Hash_DRBGKATs for Hash_DRBG (SHA-256) described in SP 800-90A Section 11.3.1, 11.3.2, 11.3.3, 11.3.4
AES-XTSAES256 XTS mode Encrypt and Decrypt KAT performed
SHA-256Hash Digest KAT performed (SHA-256)
RSA, 2048 modulus with SHA-256Signature verification KAT are performed (RSA 2048 PSS with SHA-256)
  1. Self-tests While executing the following self-tests, all data output is inhibited until self-test completion. To execute the pre-operational tests on-demand, the operator may power-cycle the module. If a cryptographic module fails a self-test, the module will enter an error state. While in this state, all data output is inhibited. 10.1. Pre-operational test • F/W integrity check - Firmware integrity check is performed by using 428-byte parity at power-on. 10.2. Conditional test • Cryptographic Algorithm Tests Table
  2. Self-tests • Firmware load test - Firmware load test is performed using RSA-3072 with SHA-256 when new FW is downloaded. • Health test The cryptographic module has performed the below 2 types of tests and each test includes the Repetition Count test and Adaptive Proportion test described in SP800-90B. - Start-up test is performed for Entropy Source after power on reset. - Continuous test is performed for Entropy Source while the module is operating Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 17

11. Life-cycle assurance 11.1. Secure Installation

Page 18
Other AttacksMitigation MechanismSpecific Limitations
N/AN/A

The cryptographic module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3 N/A N/A N/A Table 13. Mitigation of Other Attacks Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy