| Standard | FIPS 140-3 |
|---|---|
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 5/20/2029 |
| Caveat | None |
| Vendor | Samsung Electronics Co., Ltd. |
| Algorithm | ACVP Cert |
|---|---|
| AES-XTS | C1271 |
| Hash DRBG | A1720 |
| RSA SigVer (FIPS186-4) | A940 |
| SHA2-256 | C1272 |
flowchart LR
%% Deterministic review-risk graph for Samsung NVMe TCG Opal SSC SEDs BM1733a Series
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load<br/>Recovery</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Show Status<br/>Status Output<br/>unauthenticated</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for Samsung NVMe TCG Opal SSC SEDs BM1733a Series
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load<br/>Recovery</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Show Status<br/>Status Output<br/>unauthenticated</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;Samsung NVMe TCG Opal SSC SEDs BM1733a Series Document Version: 1.3 H/W Version: MZWM515THALC-00AC9, MZWM515THALC-00AG6 F/W Version: MPO92E5Q, MPO93E5Q, NA50, MPO94E5Q, MPO96E5Q
| Version | Change |
|---|---|
| 1.0 | Initial Version |
| 1.1 | Updated for MPO93E5Q and NA50 |
| 1.2 | Updated for MPO94E5Q |
| 1.3 | Updated for MPO96E5Q |
Revision History Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| # | Section | Page |
|---|
| ISO/IEC 24759 Section 6. [Number Below] | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 2 |
| 2 | Cryptographic module specification | 2 |
| 3 | Cryptographic module interfaces | 2 |
| 4 | Roles, services, and authentication | 2 |
| 5 | Software/Firmware security | 2 |
| 6 | Operational environment | N/A |
| 7 | Physical security | 2 |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 2 |
| 10 | Self-tests | 2 |
| 11 | Life-cycle assurance | 2 |
| 12 | Mitigation of other attacks | N/A |
| Acronym | Description |
|---|---|
| CTRL | Controller |
| CPU | Central Processing Unit (ARM-based) |
| DRAM | Dynamic Random Access Memory |
| DRAM I/F | Dynamic Random Access Memory Interface |
| ECC | Error Correcting Code |
| KAT | Known Answer Test |
| LBA | Logical Block Address |
| LDPC | Low Density Parity Check |
| MEK | Media Encryption Key |
| MSID | Manufactured SID(Security Identifier) |
| NAND | NAND Flash Memory |
| NAND I/F | NAND Flash Interface |
| NVMe | Non-Volatile Memory Host Controller Interface Specification |
| ROM | Read-only Memory |
| SFR | Special Function Register |
1.1. Scope This document specifies the security policy for Samsung Electronics Co., Ltd. (“Samsung”) NVMe TCG Opal SSC SEDs BM1733a Series, herein after referred to as a “cryptographic module” or “module”, SSD (Solid State Drive), satisfies all applicable FIPS 140-3 Security Level 2 requirements of a hardware module, supporting TCG Opal SSC based SED (SelfEncrypting Drive) features, designed to protect unauthorized access to the user data stored in its NAND Flash memories. The built-in AES HW engines in the cryptographic module’s controller provide on-the-fly encryption and decryption of the user data without performance loss. The SED’s nature also provides instantaneous sanitization of the user data via cryptographic erase. Table
| Model | Hardware Version | Firmware Version | Drive Capacity | |
|---|---|---|---|---|
| BM1733a | MZWM515THALC-00AC9 | MPO92E5Q MPO93E5Q MPO94E5Q MPO96E5Q | 15.36TB | |
| MZWM515THALC-00AG6 | NA50 | 15.3TB |
The firmware utilizes a single chip controller with an NVMe interface on the system side as well as Samsung NAND flash. The following figure depicts the module operational environment. The firmware within the scope of this validation must be validated through the FIPS 140-3 CMVP. Any other firmware loaded into this module is out of the scope of this validation and requires a separate FIPS 140-3 validation. Any firmware loaded into this module that is not shown on the module certificate, is out of the scope of this validation and requires a separate FIPS 140-3 validation Figure
| CAVP Cert | Algorithm and Standard | Mode/ Method | Description/ Key Size(s)/ Key Strength(s) | Use/Function |
|---|---|---|---|---|
| C12711 | AES / FIPS 197, SP 800-38E | XTS | 256 bits | Data Encryption / Decryption (only used for storage) |
| A1720 | DRBG / SP 800-90A Rev. 1 | Hash_DRBG (SHA-256) | N/A | Deterministic Random Bit Generation |
| A940 | RSA / FIPS 186-4 | PSS SigVer (SHA- 256) | 3072 bits | Digital Signature Verification |
| C1272 | SHS / FIPS 180-4 | SHA-256 | N/A | Message Digest |
| Vendor Affirmed | CKG / SP 800-133 rev2 | Section 4 and Section 6.1 | N/A | Cryptographic Key Generation (Symmetric Keys) |
| N/A | ENT (P) / SP800-90B | N/A | N/A | Non-deterministic Random Number Generator (only used for generating seed materials for the Approved DRBG) ENT (P) provides a minimum of 256 bits of entropy for DRBG seed |
| Algorithm | Caveat | Use / Function | |
|---|---|---|---|
| AES-XTS / FIPS 197, SP 800-38E | No Security Claimed; AES-XTS is only used for firmware removal of obfuscation during ROM initialized. (IG 2.4.A Scenario #2) | Firmware Removal of obfuscation | |
| AES-CCM / FIPS 197, SP 800-38C | No Security Claimed; Non-approved algorithms here are only used for obfuscation and removal of obfuscation the CSP. (IG 2.4.A Scenario #1) | Key obfuscation and Removal of obfuscation | |
| PBKDF2 | Non-SSP Derivation | ||
| HMAC / SHA-256 (SHS Cert.# C1272) | Non-SSP Derivation |
2.3. Cryptographic Functionality Following algorithms are not intended to be used as a security function, and not used whatsoever to meet any FIPS 140-
3 requirements. These algorithms are not provided through a non-approved service to an operator.
The module only has a single approved mode of operation and does not have a non-approved mode of operation. The cryptographic module shows the approved mode through validated version status by Show Status Service in Table 9 via NVM express Identify Controller command.
1 AES-ECB is the pre-requisite for AES-XTS; AES-ECB alone is NOT supported by the cryptographic module in Approved Mode.
Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Physical Port | Logical Interface Type | Data that Passes Over Port/Interface |
|---|---|---|
| NVMe Connector | Data Input | plaintext data; signed data; authentication data |
| Data Output | plaintext data; | |
| Control Input | commands input logically via an API (e.g. for the software and firmware components of the cryptographic module); signals input logically or physically via one or more physical ports (e.g. for the hardware components of the cryptographic module); | |
| Status Output | status information output logically via an API; signal outputs logically or physically via one or more physical ports; | |
| Power | Power input |
Table 6. Ports and Interfaces Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Role | Service | Input | Output |
|---|---|---|---|
| Cryptographic Officer(CO) and User | Lock/Unlock an LBA Range | LBA Range | Status |
| Erase an LBA Range’s Data | LBA Range | Status | |
| CO | Change the Password. | CO Password | Status |
| User | Set User Password | User Password | Status |
| Service | Description | Approved Security | SSPs | Role | Type(s) of Access2 | Indicator3 | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Functions | E | W | G | Z | |||||||||
| Change the Password. | Change CO password | SHA-256 | CO Password | CO | O | O | O | UID: AdminSP_SID_C_PIN / AdminSP_Admin1_C_PIN TCG Method: Set Result: TCG status code | |||||
| Hashed CO Authentication Data | O | O | O | ||||||||||
| Set User Password | Set User Password | SHA-256 | User Password | User | O | O | O | UID: LockingSP_Admin1~4_C_PIN / LockingSP_User1~9_C_PIN TCG Method: Set Result: TCG status code | |||||
| Hashed User Authentication Data | O | O | O | ||||||||||
| Lock/Unlock an LBA Range4 | Block or allow read (decrypt) / write (encrypt) of user data | N/A | MEK | CO, User | O | O | UID: Locking_GlobalRange / Locking_RangeNNNN TCG Method: Set Result: TCG status code | ||||||
| Erase an LBA Range’s Data | Erase user data by changing the data encryption key | Hash_ DRBG (SHA-256) | DRBG Internal State | O | O | O | O | UID: K_AES_256_GlobalRange_Key / K_AES_256_RangeNNNN_Key TCG Method: GenKey Result: TCG status code | |||||
| MEK | O | O | O |
2 It means that “Write” and “Zeroise” perform in each storage of SSPs that is described in Table 13. The (R)ead column, which is specified in
NIST SP 800-140B, is not applicable to the module.
4 The CO can grant Users the authority to utilize this service via updating the “Locking SP ACE Table”, in accordance with the TCG specification
(included in the Lock/Unlock an LBA Range service). Initially, only the CO can perform this service. This module provides an indicator which shows when Self-Initiated Cryptographic Output Capability is activated or inactivated. The operator can check whether the target range is locked or unlocked through the ‘getLockingTable’ query per the TCG specification. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Service | Description | Approved Security | SSPs | Role | Type(s) of Access | Indicator5 | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Functions | E | W | G | Z | ||||||||||
| Show Status6 | Show approved version status of the module / FIPS fail mode | N/A | N/A | N/A | NVM Command: Identify Controller command Result : Status Code | |||||||||
| Authentication | Authenticate to the module | SHA-256 | CO Password | O | O | UID: AdminSP_SID / AdminSP_Admin1 / LockingSP_Admin1~4 / LockingSP_User1~9 TCG Method: Authenticate Result: TCG status code | ||||||||
| User Password | O | O | ||||||||||||
| Get Random Number | Provide a random number generated by the CM | Hash_ DRBG (SHA-256) | DRBG Internal State | O | O | UID: ThisSP TCG Method: Random Result: TCG status code | ||||||||
| IO Command7 | Read/Write user data. | AES-XTS | MEK | O | NVM Command: Write / Read Result : Status Code | |||||||||
| Revert | Erase user data in all Range by changing the data encryption key and clearing the authentication data | Hash_ DRBG (SHA-256) | DRBG Internal State | O | O | UID: SPObj(AdminSP) TCG Method: Revert Result: TCG status code | ||||||||
| MEK | O | O | O | |||||||||||
| Hashed CO Authentication Data | O | |||||||||||||
| Hashed User Authentication Data | O | |||||||||||||
| FormatNVM / Sanitize / DeleteNS | Erase user data by changing the data encryption key | Hash_ DRBG (SHA-256) | DRBG Internal State | O | O | O | O | Admin Command: Format NVM / Sanitize / Namespace Management Result : Status Code | ||||||
| MEK | O | O | O | |||||||||||
| Update the firmware8 | Update the firmware | RSA | Firmware Verification Key | O | O | Admin Command: Firmware Commit Result : Status Code | ||||||||
| Perform Self-tests | Power cycling the module to perform self-tests | N/A | N/A | N/A |
- Following table shows unauthenticated services. It is initially possible to use the services in following table without O O Table 9. Unauthenticated Services
5 The module only supports approved services in an approved manner. The module uses implicit indicators through the result of the NVMe or
6 The cryptographic module shows the hardware version and firmware version through the ‘Model Number (MN)’ and ‘Firmware Revision (FR)’
7 The I/O command itself is the approved service where Self-Initiated Cryptographic Output Capability occurs, while the unlock request (via
Lock/Unlock an LBA range” service) is the authorized enablement of this capability.
8 This service is exempted from being authenticated by exception clause (c) of IG 4.1.A.
Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Role | Authentication Method | Authentication Strength | |||
|---|---|---|---|---|---|
| CO User | Password (Min: 8 bytes, Max: 32 bytes) | Probability of 1/264 in a single random attempt Probability of 80/264 in multiple random attempts in a minute |
This module provides the role-based authentication. The authentication mechanism allows a minimum 8-byte length or longer (up to 32-byte) password, where each byte can be any of 0x00 to 0xFF, for every Cryptographic Officer and User role supported by the module, which means a single random attempt can succeed with the probability of 1/264 or lower. Each Password authentication attempt takes at least 750ms. It means, the number of attempts possible in a minute period is maximum 80 attempts (60000ms/750ms). Table 10. Roles and Authentication Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
5. Software/Firmware security - The cryptographic module employs the 428-byte parity for firmware integrity test - The firmware integrity test is performed when power on reset. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
6. Operational environment - The cryptographic module operates in a limited operational environment that is consist of the module’s firmware. This operational environment does not require any specific security rules, settings, configurations or restrictions to be set. - The cryptographic module does not provide any general-purpose operating system to the operator. - Unauthorized modification of the firmware is prevented by the pre-operational firmware integrity test and conditional firmware load test. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Physical Security Mechanisms | Recommended Frequency of Inspection/Test | Inspection/Test Guidance Details |
|---|---|---|
| Production grade cases | As often as feasible | Inspect the entire perimeter for cracks, gouges, lack of screw(s) and other signs of tampering. Remove from service if tampering found. |
| Tamper-evident Sealing Labels | Inspect the sealing labels for scratches, gouges, cuts and other signs of tampering. Remove from service if tampering found. |
The following physical security mechanisms are implemented in a cryptographic module:
8. Non-invasive security - Non-invasive security has not applicable for this cryptographic module Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Key/SSP Name/ Type | Strength | Security Function and Cert. Number | Generation | Import /Export | Estab lishm ent | Storage | Zeroisation | Use & Related Keys |
|---|---|---|---|---|---|---|---|---|
| DRBG Internal State9 | 256-bit | A1720 Hash_ DRBG (SHA-256) | SP 800-90A HASH_DRBG (SHA-256) | N/A | N/A | Plaintext in RAM | Power on Reset | MEK |
| DRBG Seed | 256-bit | A1720 Hash_ DRBG (SHA-256) | ENT (P) | N/A | N/A | Plaintext in RAM | Power on Reset | MEK |
| DRBG Entropy Input String | 256-bit | A1720 Hash_ DRBG (SHA-256) | ENT (P) | N/A | N/A | Plaintext in RAM | Power on Reset | MEK |
| CO Password | Min. 64- bit | N/A | N/A | Manual Distribution/Ele ctronic Entry | N/A | Plaintext in RAM | Via “Authentication” service | N/A |
| User Password | Min. 64- bit | N/A | N/A | Manual Distribution/Ele ctronic Entry | N/A | Plaintext in RAM | Via “Authentication” service | N/A |
| Hashed CO Authenticatio n Data | 128-bit | C1272 SHA-256 | Hashed from Password as per SHA-256 | N/A | N/A | Plaintext in Flash | Via “Change the Password” and Revert” service | N/A |
| Hashed User Authenticatio n Data | 128-bit | C1272 SHA-256 | Hashed from Password as per SHA-256 | N/A | N/A | Plaintext in Flash | Via “Set User Password” and Revert” service | N/A |
| MEK | 256-bit | C1271 AES-XTS | SP 800-90A HASH_DRBG (SHA-256) | N/A | N/A | Plaintext in RAM and Flash | Via “Unlock an LBA Range”, “Erase an LBA Range’s Data”, “Revert” and “FormatNVM / Sanitize / DeleteNS” service | N/A |
| Firmware Verification Key | 128-bit | A940 RSA | N/A | Entered during manufacturing | N/A | Plaintext in Hardware SFR | Right after FW load test | Firmwar e load test |
| Plaintext in Flash | N/A |
| Entropy Sources | Minimum Number of Bits of Entropy | Details |
|---|---|---|
| ENT (P) | - 0.5 entropy per bit - Minimum of 256 bits of entropy for DRBG seed (total seed size of 512 bits). | Entropy source for Hash_DRBG |
| Algorithm | Type | Description |
|---|---|---|
| DRBG | Cryptographic algorithm self-test | KATs for Hash_DRBG (SHA-256) described in SP 800-90A Section 11.3.1, 11.3.2, 11.3.3, 11.3.4 KAT performed with 512-bit entropy input |
| AES-XTS | Cryptographic algorithm self-test | Encrypt and Decrypt KAT performed with 512-bit key size |
| SHA | Cryptographic algorithm self-test | Hash Digest KAT performed with 256-bit message size |
| RSA | Cryptographic algorithm self-test | Verify KAT performed with 3072 Modulus (3072-bit key size) and SHA-256. |
| RSA | Firmware load test | Perform using RSA-3072 with SHA-256 when new firmware is downloaded. |
| ENT (P) | Cryptographic algorithm self-test | Perform the below 2 types of tests and each test includes the Repetition Count test and Adaptive Proportion test described in SP800-90B. • Start-up test is performed for Entropy Source after power on reset. • Continuous test is performed for Entropy Source while the module is operating |
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| Error state in Boot | The module does not provide any crypto operation. | Integrity test or SP 800-90B start-up failure during boot | Power cycle | Hang state. No action |
| Error State | Any other self-test failure | If the module enters the FIPS Fail Mode, Show Status service indicates “ERRORMOD” in Firmware Revision (FR). |
While executing the following self-tests, all data output is inhibited until self-test completion. To execute the premodule will enter an error state. While in this state, all data output is inhibited. 10.1. Pre-operational Test – Firmware integrity check is performed by using 428-byte parity at power-on. 10.2. Conditional Test Table
11. Life-cycle assurance The following specifies the security rules under which the cryptographic module shall operate in accordance with FIPS 140-3:
| Other Attacks | Mitigation Mechanism | Specific Limitations |
|---|---|---|
| N/A | N/A |
The cryptographic module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3 N/A N/A N/A Table 16. Mitigation of Other Attacks Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy