All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Micron 7400 SSD Controller Sub Chip Security Subsystem

Certificate#4701StandardFIPS 140-3Level2TypeHardwareEmbodimentSingle ChipStatusActiveVendorMicron Technology, Inc.
High review priority  ·  exposes boot-chain verification, HSM/SE firmware trust anchor  ·  last validated 25 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date6/3/2029
CaveatNo assurance of the minimum strength of generated SSPs
VendorMicron Technology, Inc.

Approved Algorithms (12)

AlgorithmACVP Cert
AES-ECBA2522
AES-ECBA2523
AES-KWA2520
AES-XTS Testing Revision 2.0A2522
AES-XTS Testing Revision 2.0A2523
Hash DRBGA2520
HMAC-SHA2-256A2521
KDF SP800-108A2521
KTS-IFCA2520
PBKDFA2520
RSA SigVer (FIPS186-4)A2521
SHA2-256A2522

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Micron 7400 SSD Controller Sub Chip Security Subsystem
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load<br/>Update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>bootloader<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Micron 7400 SSD Controller Sub Chip Security Subsystem
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load<br/>Update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>bootloader<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Micron Technology Micron Technology Micron 7400 SSD Controller Sub Chip Security Subsystem Non-Proprietary FIPS 140-3 Security Policy Document Version: 1.3 Date: April 11th, 2024 Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 2

Micron Technology Table of Contents Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 3

Micron Technology List of Tables Table 4

Page 4
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General2
2Cryptographic Module Specification2
3Cryptographic Module Interfaces2
4Roles, Services and, Authentication2
5Software/Firmware Security2
6Operational EnvironmentN/A
7Physical Security2
8Non-Invasive SecurityN/A
9Sensitive Security Parameter Management2
10Self-Tests2
11Life-Cycle Assurance2
12Mitigation of Other AttacksN/A

Micron Technology Controller Security Subsystem module, hereafter denoted as the Module. The Module is a Single Chip Hardware sub-chip cryptographic subsystem, as defined in FIPS 140-3 Implementation Guidance 2.3.B. The FIPS 140-3 security levels for the Module are as follows: Table 1

Page 5
ModelHardware [Part Number and version]Firmware versionDistinguishing Features
Micron 7400 SSD Controller Security SubsystemSCCS v1.0Runtime SCSS v2.3 Bootloader v1.0 Function ROM v2.0 Boot ROM v1.0Tested Configuration: 7400 SSD Controller v20190703
2 Cryptographic Module Specification

The Module is a Single Chip Hardware Sub-Chip cryptographic module operating on a single chip embodiment. The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated cryptographic controllers. The Module is embedded in the ASIC 7400 Controller package (see Figure 1 below). Figure 1 – Micron 7400 ASIC

2.1 Operational Environment

The cryptographic module is tested on the following operational environment. Table 2 – Cryptographic Module Tested Configuration Module operational environment information is provided from the Module from the get status service and is returned from the controller as TCG Level 0 discovery content.

2.2 Cryptographic Boundary

The physical form of the Module is depicted above in Figure 1. The cryptographic boundary of the Module is defined by the Security Subsystem and includes all cryptographic algorithm implementations. The physical embodiment is the Micron 7400 Controller ASIC and includes its package. The cryptographic boundary is depicted by the red outline line in Figure 2 below. The Module is a Single Chip Hardware Sub-Chip cryptographic module operating on a single chip embodiment. Table 2 above specifies the firmware components of the module. Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 6

Micron Technology M7400 SSD M7400 Controller NAND NAND NAND NAND NAND NAND NAND NAND NVMe Security Subsystem NAND NAND NAND NAND Figure 2 – Module

2.3 Modes of Operation

The Module only supports an Approved mode and cannot be configured to operate otherwise. To verify that the Module is in the Approved mode of operation, the operator may invoke the “Get Status” service, which will indicate the Approved mode of operation, as well as the version information for the Module. The following states are defined for the module.

Page 7
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A2520AES [197]AES-KW [38F]Key Sizes: 256Authenticated Encrypt, Authenticated Decrypt (Uses Auxiliary ECB)
A2522AES [197]AES-ECB [38A]Key Sizes: 256Encrypt, Decrypt (Auxiliary)
AES-XTS1 Testing Revision 2.0 [38E]Key Sizes: 256Encrypt, Decrypt (Auxiliary)
A2523AES [197]AES-ECB [38A]Key Sizes: 256Encrypt, Decrypt (Datapath)
AES-XTS1 Testing Revision 2.0 [38E]Key Sizes: 256Encrypt, Decrypt (Datapath)
VACKG [IG D.H][133] Sections 4 and 6.1 Direct symmetric key generation using unmodified DRBG output [133] Section 6.2.2 Symmetric Keys Derived from a Pre-existing Key [133] Section 6.2.3 Derivation of symmetric keys from a password [133] Section 6.3 Symmetric Keys Produced by Combining Multiple Keys and Other DataKey Generation
A2520HASH DRBG [90A]HASH DRBGSHA2-256Deterministic Random Bit Generation Security Strength = 256
A2521HMAC- SHA2-256 [198]S HA2-256Key Size: 256 MAC = 256Key derivation. Data Authentication
A2521KDF [108]Counter Mode KDF SP800-108HMAC-SHA2-256 Supported Lengths: 256 Fixed Data Order: Before Fixed DataKey Based Key Derivation

Micron Technology Note: By default, the drive is issued with a single namespace encompassing the whole capacity of the drive. Once the drive is TCG activated this default namespace’s attributes are managed by the TCG “Global Range”.

2.4 Security Functions

The Module implements the cryptographic functions listed in table 3 below. The numbers and letters within square brackets reference standards which are defined in the References and Definitions section of this Security Policy. Table 3

Page 8
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s) Counter Length: 8 Custom Key in Length: 0Use / Function
A2520KTS [38F]AES-KWKey Sizes: 256CSP Wrapping/Unwrapping
A2520KTS-IFC [56Br2]KTS-OAEP-basicn = 20482 SHA2-256 n = 30722 SHA2-256Key transport methodology provides between 112 and 128 bits of encryption strength; Encapsulation Only.
A2520PBKDF [132]Option 1asLen = 256 C = 300 HMAC-SHA2-256Password Based Key Derivation. Keys derived from passwords may only be used in storage applications. Password length is 32 bytes and only five attempts are permitted before a reset is required. The PBKDF iteration count (C) is chosen to be as high as can be tolerated without impacting system boot up performance.
A2521RSA SigVer [186]PKCS1_v1.5n = 2048 SHA2-256 n = 3072 SHA2-256 Public Exponent Mode: Fixed Fixed Public Exponent: 010001Signature verification
A2522SHA2-256 [180]SHA2-256-Message Digest Generation

Micron Technology The module does not implement any “Non-Approved Algorithms Allowed in the Approved Mode of Operation” or “Non-Approved Algorithms Not Allowed in the Approved Mode of Operation” per SP800140B. Only “Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed” are supported per Table 4 below. Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 9
AlgorithmCaveatUse / Function
RBGNo security claimed per IG 2.4.A.Generates a 64-byte personalization string for the DRBG. Per [90A], the personalization is entirely optional, is not required to contain any entropy, and may be provided by a non- Approved RBG.
NameTypeDescriptionSF PropertiesAlgorithms/CAVP Cert
KTSKTSAES-KW – AES Cert. #A2520Key establishment methodology provides 256 bits of encryption strengthAES-KW/Cert. #A2520
KTS-IFCKTSKTS-IFC - RSA Cert. #A2520Key transport methodology provides between 112 and 128 bits of encryption strengthKTS-IFC/Cert. #A2520

Micron Technology Table 4 – Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed The following table shows the Security Function Implementations that the module implements: Table 5 - Security Function Implementation

2.6 Overall Security Design
  1. The Module provides one distinct operator role: Controller, which acts as the Cryptographic Officer
  2. The Module provides role-based authentication.
  3. The Module clears previous authentications on reset.
  4. An operator does not have access to any cryptographic services prior to assuming an authorized role.
  5. The Module allows the operator to initiate power-up self-tests by power cycling power or resetting the Module.
  6. Power up self-tests do not require any operator action.
  7. Data outputs are inhibited during firmware loading, self-tests, zeroization, and error states.
  8. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise
  9. There are no restrictions on which keys or SSPs are zeroized by the zeroization service, except for the KManifestPUB_ROM.
  10. The Module does not support concurrent operators.
  11. The Module does not support a maintenance interface or role.
  12. The Module does not support manual SSP establishment method.
  13. The Module does not have any proprietary external input/output devices used for entry/output of data.
  14. The Module does not output plaintext CSPs or intermediate key values. Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).
Page 10

Micron Technology

  1. The Module does not provide bypass services.
  2. The Module zeroizes temporary values generated and used during self-tests.
2.7 Rules of Operation

The Module is embedded within the Micron 7400 controller of the SSD. The Module shall be operated according to Section 11. Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 11
Physical PortLogical InterfaceData that passes over port/interface
AESE (encryption engine)Control in | Data in | Data out | Status outUser data
AESD (decryption engine)Control in | Data in | Data out | Status outUser data
Mbox (Mailbox)Control in | Status outService info input
Controller output (response to Mbox)Data outService info output
External Interrupt (JTAG, AHB bypass and inter-CPU interrupts)DisabledDisabled
Reset/InterruptControl inNone
BMG-128 (S-DMA Interface)Data in | Data outService info data (command/response)
PowerPower inNone
JTAG / AHB-32 bypassDisabledDisabled
LDPC DecoderData InFirmware Images
UARTStatus outStatus Data
3 Cryptographic Module Interfaces

The Module’s ports and associated FIPS defined logical interface categories are listed in Table 5 above. Table 6

Page 12
RoleServiceInputOutput
AnySelf-TestN/AN/A
ControllerSUP AuthenticatePasswordResponse
ControllerSUP GenerateNoneEncrypted blob
ControllerTCG AuthenticateWrapped RdsKey or SumRdsKey, PasswordResponse
ControllerClear TCG AuthenticationsNoneResponse
ControllerRandomSize/LocationRandom Value
ControllerNVMe Allocate and associate KeyNamespace InformationResponse
ControllerNVMe Deallocate and disassociate KeyNamespace informationResponse
ControllerNVMe Update KeyNamespace informationResponse
ControllerPublic HMAC GenerationTarget inputHMAC
ControllerLoad Range and KeyRange and key (index) InformationResponse
ControllerAWORNoneEncrypted block
ControllerTCG Allocate and associate KeyRange InformationResponse
ControllerTCG Deallocate and disassociate KeyRange InformationResponse
ControllerTCG Update KeyRange InformationResponse
ControllerTCG Set PINPasswordResponse
ControllerTCG Revert, Activate, ReactivateCommand informationResponse
ControllerTCG HMAC GenerationTarget HMACHMAC
ControllerManifest LoadManifestVerification status
ControllerCSP LoadCSP BlockVerification status
ControllerWrite/ReadRead/Write LocationRead information Status
ControllerGet StatusNoneStatus
ControllerFirmware Signature CheckFirmware blockVerification status
4 Roles, Services and Authentication
4.1 Assumption of Roles and Related Services

The Module supports one distinct operator role, Controller (Cryptographic Officer). Table 6 lists the operator role supported by the Module and their related services. In addition to the services listed in Table 6, the Module also supports a Self-Test service, which is invoked by power cycling the Module. The Module does not support a maintenance role or bypass capability. The Module does not support concurrent operators. Table 7

Page 13
RoleServiceInputOutput
ControllerFactory AuthSignatureVerification status
Controller*Device DeprovisionDeprovision IDStatus
Controller*Generate KeyDerivationKeyModeStatus
Controller*ZeroizeNoneStatus
RoleAuthentication MethodAuthentication Strength
ControllerSignature VerificationRSA 2048/3072 has a key strength of 112/128 bits. The probability of a successful verification from a single random attempt is at least 1/2112 which is < 1/1,000,000. This effectively eliminates the possibility of determining the private key through exhaustive methods. Using a conservative estimate of 1ms per verification attempt, the maximum number of attempts which can be made in 1 minute is 60,000. This results in a probability of at least 60,000/2112 that multiple attempts in a given minute of time is successful, which is less than 1/100,000.

Micron Technology *Requires additional authorization The role-based authentication methods are defined in Table 8 below. Table 8 – Roles and Authentication

4.3 Services

All services implemented by the Module are listed in the Table 9 below. The services provided by the Module are defined in terms of the services being exposed at the Module (logical) boundary. Each service description also describes the operator roles involved along with the interface command associated with the service. The SSPs modes of access shown in Table 9 are defined as:

Page 14
Keys and/or SSPsRolesAccessIndicator
Approved Securityrights to
ServiceDescriptionFunctionsKeys and/or SSPs
Self-TestRun KAT tests on all cryptographic algorithms.AllNAAny This service is unauthenticat ed.N/ACCS
SUP AuthenticateUnwrap SUP blob using PBKDF derived key.PBKDF, AES-KWPassword; PasswordWrapKeyControllerW, E G, ECCS
SUP GenerateKTS-IFC wrap an internally generated random.DRBG, CKG KTS-IFC, AES-KW, PBKDFDrbgState; KDeviceWrappingPub; PasswordWrapKey; SUP SeedControllerW, E; E; G, E, Z; G, E, ZCCS
TCG AuthenticateUnwrap TCG SSP using PBKDF derived key.PBKDF, AES-KW, CKGPassword; SumRDSKey; RdsKey; PasswordWrapKey; AuthenticatedUseHmacKey; EphemeralSumRdskWrapKeyControllerE; W; W; G, E, Z; E; ECCS
Clear TCG AuthenticationsRemove status of all past authentication and their privilegesNANAControllerN/ACCS
RandomReturns a 256-bit random numberDRBGDrbgStateControllerE, WCCS
NVMe Allocate and associate KeyGenerate a key, wrap key and associate key with an entity.DRBG, AES-KW, CKGDrbgState; WrapKey; RdsKey; SumRdsKey; NamespaceDEK; AuthenticatedUseHmacKey; EphemeralSumRdskWrapKeyControllerE, W; E; G, E, R; G, E, R; G, R; E; ECCS
NVMe Deallocate and disassociate KeyZeroize key and disassociate key from an entity.AES-KWNamespaceDEK; WrapKey; AuthenticatedUseHmacKeyControllerZ; E; ECCS
NVMe Update KeyErase user data in a namespace by changing the encryption keyDRBG, AES-KW, CKGDrbgState; WrapKey; RdsKey; SumRdsKey NamespaceDEK; LockingObjectDEK; AuthenticatedUseHmacKey; EphemeralSumRdskWrapKeyControllerE; E; E; W, E; Z, G, R; Z, G, R; E; ECCS
Public HMAC GenerationGenerate an HMAC over the prescribed content.HMAC SHA2-256RootPublicMacKey; PspHmacKeyControllerE; ECCS

Micron Technology Table 9

Page 15
Keys and/or SSPsRolesAccessIndicator
Approved Securityrights to
ServiceDescriptionFunctionsKeys and/or SSPs
Load Range and KeyLoad DEK into DPE for indicated rangeAES-KWTweakKey; LockingObjectDEK; NamespaceDEK; RdsKey; SumRdsKey; WrapKey; EphemeralSumRdskWrapKeyControllerW; W; W; E; W, E; E; E;CCS
AWORSave, restore security operational context.KDF, AES-KW, HMAC, CKGAworWrapKey; AworHmacKey; DrbgState; WrapKey; AuthenticatedUseHmacKey; PspHmacKey; TweakKey; RdsKey; SumRdsKey; RootHmacKey; RootKeyWrapKey; RootPublicMacKey; EphemeralSumRdskWrapKeyControllerE; E; W, R; W, R; W, R; W, R; W, R; W, R; W, R; W, R; W, R; W, R; W, RCCS
TCG Allocate and associate KeyGenerate a key, wrap key and associate key with an entity.DRBG, AES-KW, CKGDrbgState; WrapKey; RdsKey; SumRdsKey; LockingObjectDEK; EphemeralSumRdskWrapKey ; AuthenticatedUseHmacKeyControllerE; E; G, E, R; G, E, R; G, R; E; ECCS
TCG Deallocate and disassociate KeyZeroize key and disassociate key from an entity.NAWrapKey; LockingObjectDEK AuthenticatedUseHmacKeyControllerE; Z, R; E;CCS
TCG Update KeyErase user data in a namespace by changing the encryption key.DRBG, AES-KW, CKGDrbgState; WrapKey; RDSKey; SumRDSKey; LockingObjectDEK; EphemeralSumRdskWrapKey ; AuthenticatedUseHmacKeyControllerE; E; E; E, W; Z, G, R; E; ECCS

Micron Technology ; E ; E Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 16
Keys and/or SSPsRolesAccessIndicator
Approved Securityrights to
ServiceDescriptionFunctionsKeys and/or SSPs
TCG Set PINSet PIN which is used in generating a key to wrap a TCG credential.PBKDF, DRBG, AES-KW, CKG, HMACPassword; DrbgState; WrapKey; PasswordWrapKey; RDSKey; SumRDSKey; EphemeralSumRdskWrapKey ; AuthenticatedUseHmacKeyControllerW, E, Z; E; E; G, E, Z; G, W; G, W; E; ECCS
TCG Revert, Activate, ReactivateRevert to FOB, Revert to FOB with TCG Activated.AES-KW, HMAC, DRBG, CKGRootHmacKey; DrbgState; WrapKey; RdsKey; SumRdsKey; NameSpaceDEK; LockingObjectDEK; AuthenticatedUseHmacKeyControllerE; E; E; Z; Z; Z, G; Z, G; ECCS
TCG HMAC GenerationGenerate an HMAC over the prescribed TCG content.HMACAuthenticatedUseHmacKey; DrbgState; RootKeyWrapKey; TweakKey; WrapKey; Password; PassordWrapKeyControllerE; R; E; R; E, R; G, E; G, ECCS
Manifest LoadRSA Verify trusted list of PKs.RSA VerifyK ManifestPub_ROMControllerECCS
CSP LoadRestore persistent SSPs.AES-KW HMACRootHmacKey; RootKeyWrapKey; DrbgState; WrapKey; AuthenticatedUseHmacKey; TweakKey; PspHmacKeyControllerE; E; W; W; W; W; WCCS
Write/ReadEncryption / Decryption of user data to / from a user data range.DPE-AES-XTSNamespaceDEK; LockingObjectDEK; TweakKeyControllerE; E; ECCS
Get StatusGet information about the operational state of the drive. This service provides the requisite data for the Show module’s versioning information requirement.NANAControllerNACCS
Firmware Signature CheckVerify firmware image signature before persisting.RSA VerifyK FWCBootloaderVerify; K FWModuleVerify;ControllerE; E; ECCS

Micron Technology ; E E KFWModuleVerify; E; E KFWControllerVerify Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 17
Keys and/or SSPsRolesAccessIndicator
Approved Securityrights to
ServiceDescriptionFunctionsKeys and/or SSPs
Factory AuthAuthentication for factory- restricted services.RSA Verify, DRBGK AuthPub; K VSAuthPubControllerE; E; E, WCSS
Device DeprovisionDeprovision the device, zeroize all SSPs.NAAll CSPsControllerZCCS
Generate KeyDerivationKeyGenerate a new KeyDerivationKey.DRBG, CKGDrbgState; KeyDerivationKey; Entropy Input; RootHmacKey; RootKeyWrapKey; RootPublicMacKey; AworHmacKey; AworWrapKey; WrapKey; AuthenticatedUseHmacKey; PspHmacKey; TweakKeyControllerG, E; G, E; W, E; G, E; G, E; G; G; G; G, E; G, E; G; GCCS
ZeroizeDestroys all keys. Must be performed under the direct control of the operator.Factory zeroization processAll CSPsControllerZCCS
5 Software/Firmware Security

The Module is composed of the following firmware components:

Page 18
6 Operational Environment

The Module has a limited operational environment under the FIPS 140-3 definitions. The tested operational environment is listed in Table 2. The Module includes a firmware verification and load service to support necessary updates. Firmware versions validated through the FIPS 140-3 CMVP will be explicitly identified on a validation certificate. Any firmware not identified in this Security Policy does not constitute the Module defined by this Security Policy or covered by this validation. Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 19
Physical Security MechanismRecommended Frequency of Inspection/TestInspection/Test Guidance Details
IC packagingOn initial receipt of the device and periodically afterwardsInspect for evidence of prying or removal of the chip packaging. See Examples below. If tampering is suspected, then the device containing the IC should be removed from service and the site administrator should be contacted.

Micron Technology The Module is a Single Chip Hardware sub-chip cryptographic subsystem, and the embodiment is a single chip. The chip is encapsulated in a standard IC package. The IC packaging itself provides the necessary opacity and tamper evidence required for Level 2 conformance. Table 10

8 Non-Invasive Security

The Module does not implement any mitigation method against non-invasive attack. Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 20
Key/SSP/Name/T ypeStrengthSecurity Function and Cert. NumberGene- rationImport /ExportEstablish mentStorageZeroiza- tionUse & Related keys
AuthenticatedUse HmacKey256HMACG2E3 / O2 byN/AS1Z1, Z2Integrity
#A2521RootKeyWrapKeyverification of
or AworWrapKeyTCG table data
AworWrapKey256KTSG3 fromN/AN/AS1Z1, Z2Key encryption
#A2520KeyDerivat ionKey
AworHmacKey256HMACG3 fromN/AN/AS1Z1, Z2Integrity
#A2521KeyDerivatverification of
ionKeyTCG context data
DrbgState256HASHG2E3 / O2 byN/AS1Z1, Z2HASH_DRBG
DRBGRootKeyWrapKeyinternal state (V
#A2520or AworWrapKeyand C are each 55 bytes)
9 Sensitive Security Parameter (SSP) Management

The SSPs access methods are described in below. The SSPs management methods as shown in Table 11 below are defined as:

9.1 Sensitive Security Parameters (SSP)

All CSPs and PSPs used by the Module are described in this section. All usage of these SSPs by the Module is described in the services detailed in Section 4.3. The numbers and letters within square brackets reference standards which are defined in the References and Definitions section of this Security Policy. Table 11

Page 21
Key/SSP/Name/T ypeStrengthSecurity Function and Cert. NumberGene- rationImport /ExportEstablish mentStorageZeroiza- tionUse & Related keys
EphemeralSumRd skWrapKey256KTSG2E3 / O2 byN/AS1Z1, Z2Key wrap of
#A2520AworWrapKeySumRdsKey
Entropy Input256HASHG1E1N/AS1Z1128 bytes of
DRBGEntropy and 64
#A2520bytes of Nonce
KeyDerivationKey256KDFG2N/AN/AS2Z2Master key used
#A2521to derive other keys
LockingObjectDEK256AESG2E3 / O2 by RdsKey,N/AS1, S3Z1, Z2Data encryption
#A2523SumRdsKey or WrapKey
NamespaceDEK256AESG2E3 / O2 by RdsKey,N/AS1, S3Z1, Z2Data encryption
#A2523SumRdsKey or WrapKey
Password256PBKDFN/AE1N/AS1Z1Used with
#A2520PBKDF2 to derive the PasswordWrapKe y, Password is 32 bytes in length
PasswordWrapKe y256KTSG4N/AN/AS1Z1Key wrap of
#A2520RdsKey or SumRdsKey
PspHmacKey256HMACG2E3 / O2 byN/AS1Z1, Z2Integrity
#A2521RootKeyWrapKeyverification of
or AworWrapKeypublic TCG content
RdsKey256KTSG2E3 / O2 byN/AS1Z1, Z2Key wrap of
#A2520PasswordWrapKeyLockingObjectDE
or AworWrapKeyK and NameSpaceDEK
RootHmacKey256HMACG3 fromE3 / O2 byN/AS1Z1, Z2Integrity checking
#A2521KeyDerivat ionKeyAworWrapKey
RootKeyWrapKey256KTSG3 fromE3 / O2 byN/AS1Z1, Z2Key wrapping
#A2520KeyDerivat ionKeyAworWrapKey
RootPublicMacKe y256HMACG3 fromE3 / O2 byN/AS1Z1, Z2Integrity
#A2521KeyDerivatAworWrapKeyverification of
ionKeyexternal TCG content
SumRdsKey256KTSG2E3 / O2 byN/AS1Z1, Z2Key wrap of
#A2520AworWrapKey,LockingObjectDE
EphemeralSumRdsK and
kWrapKey, or by PasswordWrapKeyNameSpaceDEK

Micron Technology Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 22
Key/SSP/Name/T ypeStrengthSecurity Function and Cert. NumberGene- rationImport /ExportEstablish mentStorageZeroiza- tionUse & Related keys
SUP Seed256PBKDFG2O3 byN/AS1Z1Random value
#A2520K DeviceWrappingPubused in password creation
TweakKey256AESG2E3 / O2 byN/AS1, S3Z1, Z2Data encryption
#A2523RootKeyWrapKey or AworWrapKey
WrapKey256KTSG2E3 / O2 byN/AS1Z1, Z2Key wrap of
#A2520RootKeyWrapKeyLockingObjectDE
or AworWrapKeyK and NameSpaceDEK
K AuthPub112RSAN/AE2 / O1N/AS1Z1RSA 2048/3072
128SigVerPublic Key for
(FIPS186-Factory-restricted
4)services signature
#A2521verification
112KTS-IFCN/AE2 / O1N/AS1Z1RSA 2048/3072
128#A2520Public Key for SUP Generate
K FWCBootloaderVerify (Not an SSP)112RSAN/AE2N/AS1Z1RSA 2048/3072
128SigVerPublic Key for
(FIPS186-Bootloader
4)firmware
#A2521signature verification
K FWControllerVerify112RSAN/AE2N/AS1Z1RSA 2048/3072
128SigVerPublic Key for
(FIPS186-Controller
4)signature
#A2521verification
K FWModuleVerify (Not an SSP)112RSAN/AE2N/AS1Z1RSA 2048/3072
128SigVerPublic Key for
(FIPS186-runtime firmware
4)signature
#A2521verification
K ManifestPub_ROM112RSAN/AN/A. Pre-installed.N/AS4N/A.RSA 2048/3072
128SigVerUsedPublic Key for
(FIPS186-solely formanifest
4)self-testssignature
#A2521and can be revokedverification
112 128RSA SigVer (FIPS186- 4) #A2521N/AE2 / O1N/AS1Z1RSA 2048/3072 Public Key for Factory-restricted signature verification

Micron Technology Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 23
Error stateDescriptionIndicator
ES1The Function ROM fails a KATTriggered by cryptographic KAT failure. The Module enters the ES1 error state and outputs A Cryptographic Self-Test Failure status in response to any service request
ES2The Module fails the firmware load test or the Firmware Integrity testThe Module enters the ES2 error state and outputs a verification failure status in response to the firmware load test or the firmware integrity test
ES3The Module fails conditional KAT self-test.The Module enters the ES3 error state and will output a self-test failure status to any service requestThe Module enters the ES3 error state and will output a
Non-operational state. No services beside status services are allowedself-test failure status to any service request
Security FunctionMethodDescriptionError state
Bootloader FirmwareRSA SHA2-256 Signature VerificationRSA SHA2-256An RSA 2048 or 3072-bit Signature Verification isES2
(Bootloader V1.0)Signature Verificationexecuted on the whole Bootloader copied into
integrity testthe Module
SEE FirmwareRSA SHA2-256 Signature VerificationAn RSA 2048 or 3072-bit Signature Verification isES2
(Runtime SCSS V2.3)executed on the whole Bootloader copied into
integrity testthe Module
9.2 DRBG Randomness Source

The DRBG Randomness source (i.e., entropy) is loaded at manufacturing. Per IG 9.3.A, Example 2A, there is no assurance of the minimum strength of generated SSPs. The DRBG mechanism is SHA2-256, which has a security strength of 256-bits (per SP800-57, Part 1, Revision 5). The HASH DRBG is seeded with 128 bytes of entropy and 64 bytes of nonce material during manufacturing and is assumed to initialize the HASH DRBG to the full 256-bits security strength.

10 Self-Tests

The Module performs self-tests to ensure the proper operation of the Module. Per FIPS 140-3 these are categorized as either pre-operational self-tests or conditional self-tests. Pre-operational and conditional self-tests are available on demand by resetting or power cycling the The self-tests error states and status indicator are described in Table 12 below: Table 12

Page 24
Security FunctionMethodDescriptionError state
ROM HMACHMAC_HMAC SHA2-256 KAT. This test occurs before the Pre-ES1
SHA2-256Operational firmware integrity test.
ROM RSASHS/RSA2048 RSA PKCS#1_v1.5 Verification KAT with SHA2-256 KAT, which satisfies the self-test requirements for KTS-IFC per IG D.G; the Module only supports the public key operations for RSA Signature Verification and KTS-IFC Encapsulation. This test occurs before the Pre-Operational firmware integrity test.ES1
AES – KW (KeyKAT(Auxiliary) AES-256 KW encryption KAT – Inclusive of AES ECBES3
Wrap)testing with 256-bit key per IG 10.3.B.
AES – KW (KeyKAT(Auxiliary) AES-256 KW decryption KAT – Inclusive of AES ECBES3
Unwrap)testing with 256-bit key per IG 10.3.B.
AES XTS – AUX andComparative256-bit AES-XTS encryption Comparative Answer Test with theES3
DPE EncryptionAES-AUX and DPE AES-XTS implementations.
AES XTS – AUX andComparative256-bit AES-XTS decryption Comparative Answer Test with theES3
DPE DecryptionAES-AUX and DPE AES-XTS implementations.
DRBGKATHASH_DRBG (SHA2-256) instantiation, generate, and reseed KATs performed before the first random data generation.ES3
PBKDFKATOption 1a using HMAC SHA2-256. Password size is 32 Bytes. Key generated is 256 bits.ES3
KBKDFKATKnown answer test. Inclusive of HMAC-SHA2-256 KAT. Key size requested is 256 bits.ES3
BootLoader Firmware Load testRSAA 2048 or 3072-bit RSA Signature Verification is executed on the bootloader copied into the Module.A 2048 or 3072-bit RSA Signature Verification is executed on theES2
PKCS#1_v1.5 SHA2-256bootloader copied into the Module.
SEE Firmware Load testRSA PKCS#1_v1.5 SHA2-256A 2048 or 3072-bit RSA Signature Verification is executed on the SEE firmware copied into the Module.ES2

Micron Technology Table 14 – Conditional Self-Tests DPE self-tests are initiated when functionality is requested. All other self-tests are initiated automatically when the module boots. The self-tests cannot be interrupted and will run to completion.

11 Life-Cycle Assurance

This section documents the operational behavior of the device.

11.1 Security Initialization

The device is shipped from the factory in the Approved mode of operation and no further initialization is required to operate in the Approved mode. Going further, it is not possible to configure the module in such a way that it would operate in a non-compliant state or non-Approved mode. On receipt of the Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).

Page 25
AbbreviationFull Specification Name
[FIPS140-3]Security Requirements for Cryptographic Modules, March 22, 2019
[ISO19790]International Standard, ISO/IEC 19790, Information technology — Security techniques — Test requirements for cryptographic modules, Third edition, March 2017
[ISO24759]International Standard, ISO/IEC 24759, Information technology — Security techniques — Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015
[IG]Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, May 16, 2022
[108]NIST Special Publication 800-108, Recommendation for Key Derivation Using Pseudorandom Functions (Revised), October 2009
[131A]Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths, Revision 2, March 2019
[132]NIST Special Publication 800-132, Recommendation for Password-Based Key Derivation, Part 1: Storage Applications, December 2010
[133]NIST Special Publication 800-133, Recommendation for Cryptographic Key Generation, Revision 2, June 2020
[186]National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-4, July 2013.
[197]National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197, November 26, 2001
[198]National Institute of Standards and Technology, The Keyed-Hash Message Authentication Code (HMAC), Federal Information Processing Standards Publication 198-1, July, 2008
[180]National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August, 2015
[38A]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation, Methods and Techniques, Special Publication 800-38A, December 2001

Micron Technology Module, examine the product to ensure it has not been tampered with during shipping according to the procedures outlined in Section 7.

12 Mitigation of Other Attacks

The Module does not implement any mitigation method against other attacks.

13 References and Definitions

The following standards are referred to in this Security Policy. Table 15

Page 26
AbbreviationFull Specification Name
[38B]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication, Special Publication 800-38B, May 2005
[38E]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: The XTS-AES Mode for Confidentiality on Storage Devices, Special Publication 800- 38E, January 2010
[38F]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping, Special Publication 800-38F, December 2012
[56Br2]NIST Special Publication 800-56B Revision 2, Recommendation for Pair-Wise Key Establishment Schemes Using Finite Field Cryptography, March 2019
[90A]National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A, Revision 1, June 2015.
[90B]National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018.
[ACS-3]ACS-3 Reporting Security Compliance December 1,2009
[TCG-SSC- Opal]TCG Storage Security Subsystem Class: Opal, Specification
[TCG-SACS]TCG Storage Architecture Core Specification
[TCG-SIIS]TCG Storage Interface Interactions Specification
AcronymDefinition
KATKnown Answer Test
SSPSensitive Security Parameter
AKAuthentication key
DEKData Encryption Key
LBALogical Block Address
MSIDManufacturing SID. Public value used as part of the default PIN
PSIDPhysical SID, a public unique value for each drive
SEDSelf-Encrypting Drive
SIDSecurity ID, PIN for Drive Owner CO Role - TCG OPAL
TCGTrusted Computing Group

Micron Technology Table 16– Acronyms and Definitions Micron Technology, Inc. Public Material – May be reproduced only in its original entirety (without revision).