All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Samsung NVMe TCG Opal SSC SEDs BM1733a Series

Certificate#4698StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorSamsung Electronics Co., Ltd.
Low review priority  ·  no TCB surface named  ·  last validated 2 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date5/20/2029
CaveatNone
VendorSamsung Electronics Co., Ltd.

Approved Algorithms (4)

AlgorithmACVP Cert
AES-XTSC1271
Hash DRBGA1720
RSA SigVer (FIPS186-4)A940
SHA2-256C1272

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Samsung NVMe TCG Opal SSC SEDs BM1733a Series
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Show Status<br/>Status Output<br/>unauthenticated</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Samsung NVMe TCG Opal SSC SEDs BM1733a Series
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Show Status<br/>Status Output<br/>unauthenticated</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Samsung NVMe TCG Opal SSC SEDs BM1733a Series Document Version: 1.3 H/W Version: MZWM515THALC-00AC9, MZWM515THALC-00AG6 F/W Version: MPO92E5Q, MPO93E5Q, NA50, MPO94E5Q, MPO96E5Q

Page 2
VersionChange
1.0Initial Version
1.1Updated for MPO93E5Q and NA50
1.2Updated for MPO94E5Q
1.3Updated for MPO96E5Q

Revision History Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 3
Table of Contents
#SectionPage
Page 4
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
AcronymDescription
CTRLController
CPUCentral Processing Unit (ARM-based)
DRAMDynamic Random Access Memory
DRAM I/FDynamic Random Access Memory Interface
ECCError Correcting Code
KATKnown Answer Test
LBALogical Block Address
LDPCLow Density Parity Check
MEKMedia Encryption Key
MSIDManufactured SID(Security Identifier)
NANDNAND Flash Memory
NAND I/FNAND Flash Interface
NVMeNon-Volatile Memory Host Controller Interface Specification
ROMRead-only Memory
SFRSpecial Function Register

1.1. Scope This document specifies the security policy for Samsung Electronics Co., Ltd. (“Samsung”) NVMe TCG Opal SSC SEDs BM1733a Series, herein after referred to as a “cryptographic module” or “module”, SSD (Solid State Drive), satisfies all applicable FIPS 140-3 Security Level 2 requirements of a hardware module, supporting TCG Opal SSC based SED (SelfEncrypting Drive) features, designed to protect unauthorized access to the user data stored in its NAND Flash memories. The built-in AES HW engines in the cryptographic module’s controller provide on-the-fly encryption and decryption of the user data without performance loss. The SED’s nature also provides instantaneous sanitization of the user data via cryptographic erase. Table

  1. Security Levels 1.2. Acronyms Table
  2. Acronyms Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 5
  1. Cryptographic module specification 2.1. Cryptographic Boundary The following photographs show the cryptographic module’s top and bottom views. The multiple-chip standalone cryptographic module consists of hardware and firmware components that are all enclosed in two aluminum alloy cases, which serve as the cryptographic boundary of the module. Figure
  2. Specification of the Samsung SSD NVMe TCG Opal SSC SEDs BM1733a Series Cryptographic Boundary Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 6
ModelHardware VersionFirmware VersionDrive Capacity
BM1733aMZWM515THALC-00AC9MPO92E5Q MPO93E5Q MPO94E5Q MPO96E5Q15.36TB
MZWM515THALC-00AG6NA5015.3TB

The firmware utilizes a single chip controller with an NVMe interface on the system side as well as Samsung NAND flash. The following figure depicts the module operational environment. The firmware within the scope of this validation must be validated through the FIPS 140-3 CMVP. Any other firmware loaded into this module is out of the scope of this validation and requires a separate FIPS 140-3 validation. Any firmware loaded into this module that is not shown on the module certificate, is out of the scope of this validation and requires a separate FIPS 140-3 validation Figure

  1. Block Diagram for Samsung SSD NVMe TCG Opal SSC SEDs BM1733a Series 2.2. Version information Table
  2. Cryptographic Module Tested Configuration Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 7
CAVP CertAlgorithm and StandardMode/ MethodDescription/ Key Size(s)/ Key Strength(s)Use/Function
C12711AES / FIPS 197, SP 800-38EXTS256 bitsData Encryption / Decryption (only used for storage)
A1720DRBG / SP 800-90A Rev. 1Hash_DRBG (SHA-256)N/ADeterministic Random Bit Generation
A940RSA / FIPS 186-4PSS SigVer (SHA- 256)3072 bitsDigital Signature Verification
C1272SHS / FIPS 180-4SHA-256N/AMessage Digest
Vendor AffirmedCKG / SP 800-133 rev2Section 4 and Section 6.1N/ACryptographic Key Generation (Symmetric Keys)
N/AENT (P) / SP800-90BN/AN/ANon-deterministic Random Number Generator (only used for generating seed materials for the Approved DRBG) ENT (P) provides a minimum of 256 bits of entropy for DRBG seed
AlgorithmCaveatUse / Function
AES-XTS / FIPS 197, SP 800-38ENo Security Claimed; AES-XTS is only used for firmware removal of obfuscation during ROM initialized. (IG 2.4.A Scenario #2)Firmware Removal of obfuscation
AES-CCM / FIPS 197, SP 800-38CNo Security Claimed; Non-approved algorithms here are only used for obfuscation and removal of obfuscation the CSP. (IG 2.4.A Scenario #1)Key obfuscation and Removal of obfuscation
PBKDF2Non-SSP Derivation
HMAC / SHA-256 (SHS Cert.# C1272)Non-SSP Derivation

2.3. Cryptographic Functionality Following algorithms are not intended to be used as a security function, and not used whatsoever to meet any FIPS 140-

3 requirements. These algorithms are not provided through a non-approved service to an operator.

The module only has a single approved mode of operation and does not have a non-approved mode of operation. The cryptographic module shows the approved mode through validated version status by Show Status Service in Table 9 via NVM express Identify Controller command.

1 AES-ECB is the pre-requisite for AES-XTS; AES-ECB alone is NOT supported by the cryptographic module in Approved Mode.

Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 8
Physical PortLogical Interface TypeData that Passes Over Port/Interface
NVMe ConnectorData Inputplaintext data; signed data; authentication data
Data Outputplaintext data;
Control Inputcommands input logically via an API (e.g. for the software and firmware components of the cryptographic module); signals input logically or physically via one or more physical ports (e.g. for the hardware components of the cryptographic module);
Status Outputstatus information output logically via an API; signal outputs logically or physically via one or more physical ports;
PowerPower input

Table 6. Ports and Interfaces Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 9
RoleServiceInputOutput
Cryptographic Officer(CO) and UserLock/Unlock an LBA RangeLBA RangeStatus
Erase an LBA Range’s DataLBA RangeStatus
COChange the Password.CO PasswordStatus
UserSet User PasswordUser PasswordStatus
ServiceDescriptionApproved SecuritySSPsRoleType(s) of Access2Indicator3
FunctionsEWGZ
Change the Password.Change CO passwordSHA-256CO PasswordCOOOOUID: AdminSP_SID_C_PIN / AdminSP_Admin1_C_PIN TCG Method: Set Result: TCG status code
Hashed CO Authentication DataOOO
Set User PasswordSet User PasswordSHA-256User PasswordUserOOOUID: LockingSP_Admin1~4_C_PIN / LockingSP_User1~9_C_PIN TCG Method: Set Result: TCG status code
Hashed User Authentication DataOOO
Lock/Unlock an LBA Range4Block or allow read (decrypt) / write (encrypt) of user dataN/AMEKCO, UserOOUID: Locking_GlobalRange / Locking_RangeNNNN TCG Method: Set Result: TCG status code
Erase an LBA Range’s DataErase user data by changing the data encryption keyHash_ DRBG (SHA-256)DRBG Internal StateOOOOUID: K_AES_256_GlobalRange_Key / K_AES_256_RangeNNNN_Key TCG Method: GenKey Result: TCG status code
MEKOOO
  1. Roles, services, and authentication The following table defines the roles, and associated services supported by the each role: Table
  2. Roles, Service Commands, Input and Output E: EXECUTE; W: WRITE; G: GENERATE; Z: ZEROISE Table
  3. Authenticated Services

2 It means that “Write” and “Zeroise” perform in each storage of SSPs that is described in Table 13. The (R)ead column, which is specified in

NIST SP 800-140B, is not applicable to the module.

3 The result of NVMe or TCG command is used as an indicator.

4 The CO can grant Users the authority to utilize this service via updating the “Locking SP ACE Table”, in accordance with the TCG specification

(included in the Lock/Unlock an LBA Range service). Initially, only the CO can perform this service. This module provides an indicator which shows when Self-Initiated Cryptographic Output Capability is activated or inactivated. The operator can check whether the target range is locked or unlocked through the ‘getLockingTable’ query per the TCG specification. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 10
ServiceDescriptionApproved SecuritySSPsRoleType(s) of AccessIndicator5
FunctionsEWGZ
Show Status6Show approved version status of the module / FIPS fail modeN/AN/AN/ANVM Command: Identify Controller command Result : Status Code
AuthenticationAuthenticate to the moduleSHA-256CO PasswordOOUID: AdminSP_SID / AdminSP_Admin1 / LockingSP_Admin1~4 / LockingSP_User1~9 TCG Method: Authenticate Result: TCG status code
User PasswordOO
Get Random NumberProvide a random number generated by the CMHash_ DRBG (SHA-256)DRBG Internal StateOOUID: ThisSP TCG Method: Random Result: TCG status code
IO Command7Read/Write user data.AES-XTSMEKONVM Command: Write / Read Result : Status Code
RevertErase user data in all Range by changing the data encryption key and clearing the authentication dataHash_ DRBG (SHA-256)DRBG Internal StateOOUID: SPObj(AdminSP) TCG Method: Revert Result: TCG status code
MEKOOO
Hashed CO Authentication DataO
Hashed User Authentication DataO
FormatNVM / Sanitize / DeleteNSErase user data by changing the data encryption keyHash_ DRBG (SHA-256)DRBG Internal StateOOOOAdmin Command: Format NVM / Sanitize / Namespace Management Result : Status Code
MEKOOO
Update the firmware8Update the firmwareRSAFirmware Verification KeyOOAdmin Command: Firmware Commit Result : Status Code
Perform Self-testsPower cycling the module to perform self-testsN/AN/AN/A

- Following table shows unauthenticated services. It is initially possible to use the services in following table without O O Table 9. Unauthenticated Services

5 The module only supports approved services in an approved manner. The module uses implicit indicators through the result of the NVMe or

6 The cryptographic module shows the hardware version and firmware version through the ‘Model Number (MN)’ and ‘Firmware Revision (FR)’

7 The I/O command itself is the approved service where Self-Initiated Cryptographic Output Capability occurs, while the unlock request (via

Lock/Unlock an LBA range” service) is the authorized enablement of this capability.

8 This service is exempted from being authenticated by exception clause (c) of IG 4.1.A.

Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 11
RoleAuthentication MethodAuthentication Strength
CO UserPassword (Min: 8 bytes, Max: 32 bytes)Probability of 1/264 in a single random attempt Probability of 80/264 in multiple random attempts in a minute

This module provides the role-based authentication. The authentication mechanism allows a minimum 8-byte length or longer (up to 32-byte) password, where each byte can be any of 0x00 to 0xFF, for every Cryptographic Officer and User role supported by the module, which means a single random attempt can succeed with the probability of 1/264 or lower. Each Password authentication attempt takes at least 750ms. It means, the number of attempts possible in a minute period is maximum 80 attempts (60000ms/750ms). Table 10. Roles and Authentication Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 12

5. Software/Firmware security - The cryptographic module employs the 428-byte parity for firmware integrity test - The firmware integrity test is performed when power on reset. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 13

6. Operational environment - The cryptographic module operates in a limited operational environment that is consist of the module’s firmware. This operational environment does not require any specific security rules, settings, configurations or restrictions to be set. - The cryptographic module does not provide any general-purpose operating system to the operator. - Unauthorized modification of the firmware is prevented by the pre-operational firmware integrity test and conditional firmware load test. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 14
Physical Security MechanismsRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Production grade casesAs often as feasibleInspect the entire perimeter for cracks, gouges, lack of screw(s) and other signs of tampering. Remove from service if tampering found.
Tamper-evident Sealing LabelsInspect the sealing labels for scratches, gouges, cuts and other signs of tampering. Remove from service if tampering found.

The following physical security mechanisms are implemented in a cryptographic module:

Page 15

8. Non-invasive security - Non-invasive security has not applicable for this cryptographic module Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 16
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstab lishm entStorageZeroisationUse & Related Keys
DRBG Internal State9256-bitA1720 Hash_ DRBG (SHA-256)SP 800-90A HASH_DRBG (SHA-256)N/AN/APlaintext in RAMPower on ResetMEK
DRBG Seed256-bitA1720 Hash_ DRBG (SHA-256)ENT (P)N/AN/APlaintext in RAMPower on ResetMEK
DRBG Entropy Input String256-bitA1720 Hash_ DRBG (SHA-256)ENT (P)N/AN/APlaintext in RAMPower on ResetMEK
CO PasswordMin. 64- bitN/AN/AManual Distribution/Ele ctronic EntryN/APlaintext in RAMVia “Authentication” serviceN/A
User PasswordMin. 64- bitN/AN/AManual Distribution/Ele ctronic EntryN/APlaintext in RAMVia “Authentication” serviceN/A
Hashed CO Authenticatio n Data128-bitC1272 SHA-256Hashed from Password as per SHA-256N/AN/APlaintext in FlashVia “Change the Password” and Revert” serviceN/A
Hashed User Authenticatio n Data128-bitC1272 SHA-256Hashed from Password as per SHA-256N/AN/APlaintext in FlashVia “Set User Password” and Revert” serviceN/A
MEK256-bitC1271 AES-XTSSP 800-90A HASH_DRBG (SHA-256)N/AN/APlaintext in RAM and FlashVia “Unlock an LBA Range”, “Erase an LBA Range’s Data”, “Revert” and “FormatNVM / Sanitize / DeleteNS” serviceN/A
Firmware Verification Key128-bitA940 RSAN/AEntered during manufacturingN/APlaintext in Hardware SFRRight after FW load testFirmwar e load test
Plaintext in FlashN/A
Entropy SourcesMinimum Number of Bits of EntropyDetails
ENT (P)- 0.5 entropy per bit - Minimum of 256 bits of entropy for DRBG seed (total seed size of 512 bits).Entropy source for Hash_DRBG
  1. Sensitive security parameter management - Temporary SSPs are zeroised when power on reset. - Firmware integrity temporary values are zeroised after the firmware integrity test is complete. - The zeroisation is performed before overwriting to the target SSP with random value which is generated from the DRBG. - SSP’s are not exported outside the module. State 9 RAM N/A Table
  2. SSPs The module contains an entropy source, compliant with SP 800-90B, within the module’s cryptographic boundary. Table
  3. Non-Deterministic Random Number Generation Specification The values of V and C are the “secret values” of the internal state Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 17
AlgorithmTypeDescription
DRBGCryptographic algorithm self-testKATs for Hash_DRBG (SHA-256) described in SP 800-90A Section 11.3.1, 11.3.2, 11.3.3, 11.3.4 KAT performed with 512-bit entropy input
AES-XTSCryptographic algorithm self-testEncrypt and Decrypt KAT performed with 512-bit key size
SHACryptographic algorithm self-testHash Digest KAT performed with 256-bit message size
RSACryptographic algorithm self-testVerify KAT performed with 3072 Modulus (3072-bit key size) and SHA-256.
RSAFirmware load testPerform using RSA-3072 with SHA-256 when new firmware is downloaded.
ENT (P)Cryptographic algorithm self-testPerform the below 2 types of tests and each test includes the Repetition Count test and Adaptive Proportion test described in SP800-90B. • Start-up test is performed for Entropy Source after power on reset. • Continuous test is performed for Entropy Source while the module is operating
NameDescriptionConditionsRecovery MethodIndicator
Error state in BootThe module does not provide any crypto operation.Integrity test or SP 800-90B start-up failure during bootPower cycleHang state. No action
Error StateAny other self-test failureIf the module enters the FIPS Fail Mode, Show Status service indicates “ERRORMOD” in Firmware Revision (FR).

While executing the following self-tests, all data output is inhibited until self-test completion. To execute the premodule will enter an error state. While in this state, all data output is inhibited. 10.1. Pre-operational Test – Firmware integrity check is performed by using 428-byte parity at power-on. 10.2. Conditional Test Table

  1. Self-tests 10.3. Error States Table
  2. Error States Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 18

11. Life-cycle assurance The following specifies the security rules under which the cryptographic module shall operate in accordance with FIPS 140-3:

Page 19
Other AttacksMitigation MechanismSpecific Limitations
N/AN/A

The cryptographic module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3 N/A N/A N/A Table 16. Mitigation of Other Attacks Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy