| Standard | FIPS 140-3 |
|---|---|
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Status | Active |
| Sunset date | 9/2/2029 |
| Caveat | When installed, initialized and configured as specified in Section 11 of the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service |
| Vendor | KIOXIA Corporation |
| Algorithm | ACVP Cert |
|---|---|
| AES-CBC | C1925 |
| AES-XTS | C1925 |
| Hash DRBG | C2002 |
| HMAC-SHA2-256 | C1925 |
| KDF SP800-108 | C2001 |
| RSA SigVer (FIPS186-4) | C2009 |
| SHA2-256 | C1925 |
flowchart LR
%% Deterministic review-risk graph for KIOXIA TCG OPAL SSC Crypto Sub-Chip TC58NC1132GTC
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load<br/>update</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show Status</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for KIOXIA TCG OPAL SSC Crypto Sub-Chip TC58NC1132GTC
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load<br/>update</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show Status</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;KIOXIA TCG OPAL SSC Crypto Sub-Chip TC58NC1132GTC KIOXIA CORPORATION Rev 2.0.0
| Section | Level |
|---|---|
| 1. General | 2 |
| 2. Cryptographic Module Specification | 2 |
| 3. Cryptographic Module Interfaces | 2 |
| 4. Roles, Services, and Authentication | 2 |
| 5. Software/Firmware Security | 2 |
| 6. Operational Environment | N/A |
| 7. Physical Security | 2 |
| 8. Non-invasive Security | N/A |
| 9. Sensitive Security Parameter Management | 2 |
| 10. Self-tests | 2 |
| 11. Life-cycle Assurance | 2 |
| 12. Mitigation of Other Attacks | N/A |
| Overall Level | 2 |
This document explains precise specification of the security rules about KIOXIA TCG OPAL SSC Crypto Sub-Chip TC58NC1132GTC. The Cryptographic Module (CM) meets the requirements of FIPS 140-3 Security Level 2 Overall. The Table below shows the security level detail. Table 1 ‐ Security Levels This document is non-proprietary and may be reproduced in its original entirety. Section 1.1 - Acronyms
| AES | Advanced Encryption Standard |
| DRBG | Deterministic Random Bit Generator |
| HMAC | The Keyed-Hash Message Authentication code |
| KAT | Known Answer Test |
| POST | Power on Self-Test |
| CAST | Cryptographic Algorithm Self-Test |
| PSID | Printed SID |
| SED | Self-Encrypting Drive |
| SHA | Secure Hash Algorithm |
| SID | Security ID |
| TCG | Trusted Computing Group 3 Jun 26, 2024 |
| Physical single-chip | The sub-chip cryptographic subsystem soft circuitry core | The associated firmware | ||
|---|---|---|---|---|
| TC58NC1132GTC 0003 | TC58NC1132GTC CRPT module 0001 | SC02AN |
| CAVP Cert | Algorithm and Standard | Mode/ Method | Description/Key Size(s)/ Key Strength(s) | Use/Function | |
|---|---|---|---|---|---|
| #C1925 | AES256 (FIPS 197 / SP800-38A) | CBC | Key Size: 256 bits/ Key Strength: 256 bits | Data and Key Encryption/ Decryption |
Section 2
| #C1925 | AES256 (FIPS 197 / SP800-38E) | XTS1 | Key Size: 256 bits/ Key Strength: 256 bits | Data Encryption/ Decryption |
|---|---|---|---|---|
| #C1925 | SHA256 (FIPS 180-4) | N/A | N/A | Hashing messages |
| #C1925 | HMAC-SHA256 (FIPS 198-1) | N/A | Key Size: 256 bits/ Key Strength: 256 bits | Message Authentication Code |
| #C2009 | RSASSA-PKCS#1-v1_5 (FIPS 186-4) | N/A | Key Size: 2048 bits/ Key Strength: 112 bits | Signature verification |
| #C2002 | Hash_DRBG (SP800-90A Rev.1) | N/A | Hash based: SHA256 | Deterministic Random Bit Generation |
| #C2001 | KBKDF (SP800-108 Revised) | Counter | MACs: HMAC-SHA256/ Key Size: 256 bits/ Key Strength 256 bits | Key derivation |
| #C1925 | KTS (IG D.G) | N/A | Combination of AES256 CBC Mode and HMAC-SHA256 / Key Size: 256 bits/ Key Strength: 256 bits | Key Transport Scheme |
| Vendor Affirmation | CKG (SP800-133 Rev.2) | N/A | Methods described in section 4 of the SP800-133 Rev.2 | Cryptographic Key Generation |
| ENT(P) | Entropy Source (SP800-90B) | N/A | N/A | Hardware RNG used to seed the approved Hash_DRBG. |
Table 3 ‐ Approved Algorithm The CM does not implement any Non-Approved Algorithms Allowed in the Approved Mode of Operation. ECB mode is used as a prerequisite of XTS mode. ECB is not directly used in services of the Cryptographic Module. The CM performs a check that the XTS Key1 and XTS Key2 are different
| Physical port | Logical Interface | Data that passes over port/interface |
|---|---|---|
| Mailbox AES circuit DMAC Lock Checker | Data Input | Mailbox input parameter. User data. Read/Write destination address information. |
| Mailbox AES circuit DMAC | Data Output | Mailbox output parameter. User data. |
| Mailbox Lock Checker | Control Input | Mailbox command information. Lock status confirmation request signal. |
| Mailbox Lock Checker | Status Output | Mailbox command result. Lock status confirmation result signal. |
| Power PIN | Power Input | Power |
Section 2.3
| Role | Service | Input | Output |
|---|---|---|---|
| FIPS Crypto Officer (AdminSP.SID) | Download Port Lock/Unlock Firmware Download2 Set PIN (for AdminSP.SID and AdminSP.Admin1) Authority Enable/Disable Revert Data Locking protection Enable Sanitize Format Namespace Namespace Create/Delete | Mailbox command | Mailbox command result |
| FIPS Crypto Officer (AdminSP.Admin1) | Set PIN (for AdminSP.Admin1) Revert Sanitize Format Namespace Namespace Create/Delete | Mailbox command | Mailbox command result |
| FIPS Crypto Officer (LockingSP.Admin1-4) | Band Lock/Unlock Cryptographic Erase Cryptographic Erase and Initialize Band State Set Band position and Size, Set Band position and Size for Band of Single User Mode Set PIN(for LockingSP.Admin1-4 and LockingSP.User1-192) Authority Enable/Disable Revert Data Locking protection Enable Sanitize Format Namespace Namespace Create/Delete Band Set Enable Band Set Disable | Mailbox command | Mailbox command result |
| Data Read/Write | Encrypted/Decrypted data | Decrypted/Encrypted data | |
| FIPS Crypto Officer (LockingSP.User1) | Band Lock/Unlock for Band of Single User Mode (for GlobalRange) Cryptographic Erase for Band of Single User Mode (for GlobalRange) | Mailbox command | Mailbox command result |
Section 4 – Roles Services and Authentication The relation between Roles and Services in this CM is shown below. external firmware is verified (RSASSA-PKCS#1-v1_5).
| Cryptographic Erase and Initialize Band State (for GlobalRange) | |||
|---|---|---|---|
| Set Band position and Size for Band of Single user Mode (for GlobalRange | |||
| Set PIN (for LockingSP.User1), Set PIN for Band of Single User Mode (for LockingSP.Use1) | |||
| Format Namespace | |||
| Namespace Create/Delete | |||
| Data Read/Write | Encrypted/Decrypted data | Decrypted/Encrypted data | |
| FIPS Crypto Officer (LockingSP.User2) | Band Lock/Unlock for Band of Single User Mode (for Band1) Cryptographic Erase for Band of Single User Mode (for Band1) Cryptographic Erase and Initialize Band State (for Band1) Set Band position and Size for Band of Single user Mode (for Band1) Set PIN (for LockingSP.User2), Set PIN for Band of Single User Mode (for LockingSP.User2) Format Namespace | Mailbox command | Mailbox command result |
| Data Read/Write | Encrypted/Decrypted data | Decrypted/Encrypted data | |
| … | … | … | … |
| FIPS Crypto Officer (LockingSP.User192) | Band Lock/Unlock for Band of Single User Mode (for Band191) Cryptographic Erase for Band of Single User Mode (for Band191) Cryptographic Erase and Initialize Band State (for Band191) Set Band position and Size for Band of Single user Mode (for Band191) Set PIN (for LockingSP.User192), Set PIN for Band of Single User Mode (for LockingSP.User192) Format Namespace | Mailbox command | Mailbox command result |
| Data Read/Write | Encrypted/Decrypted data | Decrypted/Encrypted data | |
| None | Firmware Verification Random Number Generation Show Status Zeroisation | Mailbox command | Mailbox command result |
| Check Lock State | Read/Write Command | Lock state of each Band | |
| Reset | Power | N/A |
… … … … Table 5 ‐ Roles, Service Commands, Input and output
| Role Name | Role Type | Type of Authentication | Authentication | Authentication Strength | Multi Attempt strength |
|---|---|---|---|---|---|
| AdminSP.SID | Crypto Officer | Role | PIN | 1 / 264 < 1 / 1,000,000 | 30 / 264 < 1 / 100,000 |
| AdminSP.Admin1 | Crypto Officer | Role | PIN | 1 / 264 < 1 / 1,000,000 | 30 / 264 < 1 / 100,000 |
| LockingSP.Admin1-4 | Crypto Officer | Role | PIN | 1 / 264 < 1 / 1,000,000 | 30 / 264 < 1 / 100,000 |
| LockingSP.User1 | Crypto Officer | Role | PIN | 1 / 264 < 1 / 1,000,000 | 30 / 264 < 1 / 100,000 |
| LockingSP.User2 | Crypto Officer | Role | PIN | 1 / 264 < 1 / 1,000,000 | 30 / 264 < 1 / 100,000 |
| … | … | … | … | … | … |
| LockingSP.User192 | Crypto Officer | Role | PIN | 1 / 264 < 1 / 1,000,000 | 30 / 264 < 1 / 100,000 |
The CM supports the configuration of roles and services. The authenticated operator is expected to configure locked bands for data storage, the associated role and the lock-based authentication data (PIN) per Table 6 (refer to section 11 for detail settings to maintain secure operation). Bands that are not configured are considered unprotected or plaintext. This configuration enables Data Read/Write service using the lock-based authentication model (IG 4.1.A). To Read/Write data from/to each band, an operator must unlock the bands with appropriate authenticated roles. Once the bands are unlocked, Read and Write access to the bands must be controlled by a trusted operator outside of the module who has been authenticated as the associated role until powered off. The module prevents Data read/write service for locked bands. If Read and Write access needs to be inhibited prior to power off, the operator who authenticates the role must set the bands to the locked state again. Section 4.1 – Roles and Authentication This section describes roles, authentication method, and strength of authentication. … … … … … … Table 6 ‐ Identification and Authentication Policy The CM performs role authentication by comparing whether the PIN entered by the user matches the information stored inside the CM. PINs are hashed with SHA-256 to store them on the CM. The PIN entered by the user is hashed and compared to the stored PIN hash. PINs can be changed by executing the Set PIN Service (see Section4.2) with appropriate roles authenticated. The CM refuses to set a PIN less than 8 bytes, and responds with an error if such a setting is attempted. Therefore the probability that a random attempt will succeed is 1 / 264 <
1 / 1,000,000 (the CM accepts any value (0x00-0xFF) as each byte of PIN). The CM waits 2sec
when authentication attempt fails, so the maximum number of authentication attempts is 30
| Service | Description | Approved Security Function | Keys and/or SSPs | Role(s) | Access rights to Keys and/or SSPs3 | Indicator | |
|---|---|---|---|---|---|---|---|
| Band Lock/Unlock | Lock or unlock read / write of user data in a band. | KBKDF HMAC-SHA256 | KDK MEKs System MAC Key | LockingSP.Admin 1-4 | E G E | Mailbox command result | |
| Band Lock/Unlock for Band of Single User Mode | Lock or unlock read / write of user data in band”X” of single user mode. | LockingSP.User”X +1” | |||||
| Check Lock State | Check a lock state of band that read / write user data. | N/A | N/A | None | N/A | Band Lock state | |
| Data Read/Write | Encryption / decryption of user data to/from unlocked band of SSD 4. | AES256-XTS | MEKs | LockingSP.Admin 1-4 LockingSP.User1- 192 | E | Readable/Writab le signal from lock check module | |
| Cryptographic Erase | Erase user data (in cryptographic means) by changing the key that derives the data encryption key. | CKG (Hash_DRBG) KBKDF HMAC-SHA256 AES256-CBC KTS | DRBG Internal Value KDK KDK MEKs System MAC Key System Enc Key KDK | LockingSP.Admin 1-4 | E G, Z E G, Z E E W, R | Mailbox command result | |
| Cryptographic Erase for Band of Single User Mode | Erase user data in band”X” of single user mode (in cryptographic means) by changing the key that derives the data encryption key. | LockingSP.user”X +1” |
times in 1 min. Consequently the probability that random attempts in 1min will succeed is 30 /
The Roles of AdminSP.Admin1, LockingSP.Admin2-4 and LockingSP.User1-192 are set initial authentication data to null (means data of length 0). These role’s authentication data are need to be replaced upon the first-time authentication. Otherwise, the operator who assumes these role cannot execute services except Set PIN and services that does not need authorized roles. Section 4.2 – Services This section describes services which the CM provides.
3 The letters (G, R, W, E, Z) mean Generate, Read, Write, Execute and Zeroise respectively.
| Cryptographic Erase and Initialize Band State | Erase user data in band”X” of single user mode (in cryptographic means) by changing the key that derives the data encryption key, and initialize the band state. | DRBG Internal Value KDK KDK MEKs System MAC Key System Enc Key KDK | LockingSP.Admin 1-4 LockingSP.user”X +1” | |||
|---|---|---|---|---|---|---|
| Download Port Lock/Unlock | Lock / unlock firmware download. | N/A | N/A | AdminSP.SID | N/A | Mailbox command result |
| Firmware Verification | Digital signature verification for firmware outside the CM. | RSASSA-PKCS#1- v1_5 | Public Key embedded on the CM’s code | None | E | Mailbox command result |
| Firmware Download | Download a firmware image5. | SHA256 RSASSA-PKCS#1- v1_5 | PubKey1 PubKey1 | AdminSP.SID | W, E E | Mailbox command result |
| Random Number Generation | Provide a random number generated by the CM. | Hash_DRBG | DRBG Internal Value | None | E | Mailbox command result |
| Set Band Position and Size | Set the location and size of the band. | CKG (Hash_DRBG) KBKDF HMAC-SHA256 AES256-CBC KTS | DRBG Internal Value KDK KDK MEKs System MAC Key System Enc Key KDK | LockingSP.Admin 1-4 | E G, Z E G, Z E E W, R | Mailbox command result |
| Set Band Position and Size for Band of Single User Mode | Set the location and size of the band”X” of single user mode. | LockingSP.Admin 1-4 LockingSP.User”X +1” | ||||
| Set PIN | Set PIN (authentication data). | SHA256 HMAC-SHA256 AES256-CBC KTS | PINs System MAC Key System Enc Key PINs | AdminSP.SID, AdminSP.Admin1 , LockingSP.Admin 1-4, LockingSP.User1- 192 | W, E E E W, R | Mailbox command result |
| Set PIN for Band of Single User Mode | Set PIN (authentication data) of authority for band”X” of single use mode | LockingSP.User1- 192 | ||||
| Authority Enable/Disable | Enable/Disable the authority. | HMAC-SHA256 AES256-CBC | System MAC Key System Enc Key | AdminSP.SID LockingSP.Admin 1-4 | E E | Mailbox command result |
+1” , 1-4 Only the CMVP validated version is to be used
| Data Locking Protection Enable | Enable Data protection with band lock setting. | SHA256 HMAC-SHA256 AES256-CBC KTS | PINs System MAC Key System Enc Key PINs | AdminSP.SID LockingSP.Admin 1-4 | W, E E E W, R | Mailbox command result |
|---|---|---|---|---|---|---|
| Sanitize | Erase all user data (in cryptographic means) by changing the key that derives the data encryption key. | CKG (Hash_DRBG) KBKDF HMAC-SHA256 AES256-CBC KTS | DRBG Internal Value KDK KDK MEKs System MAC Key System Enc Key KDK | AdminSP.SID, AdminSP.Admin1 , LockingSP.Admin 1-4 | E G, Z E G, Z E E W, R | Mailbox command result |
| Format Namespace | Erase user data (in cryptographic means) on Namespace by changing the key that derives the data encryption key. | CKG (Hash_DRBG) KBKDF HMAC-SHA256 AES256-CBC KTS | DRBG Internal Value KDK KDK MEKs System MAC Key System Enc Key KDK | AdminSP.SID, AdminSP.Admin1 , LockingSP.Admin 1-4, LockingSP.User1- 192 | E G, Z E G, Z E E W, R | Mailbox command result |
| Namespace Create/Delete | Create and delete Namespace. | CKG (Hash_DRBG) KBKDF HMAC-SHA256 AES256-CBC KTS | DRBG Internal Value KDK KDK MEKs System MAC Key System Enc Key KDK | AdminSP.SID, AdminSP.Admin1 , LockingSP.Admin 1-4, LockingSP.User1 | E G, Z E G, Z E E W, R | Mailbox command result |
| Band Set Enable | Set the location, size and lock state of the band. | CKG (Hash_DRBG) KBKDF HMAC-SHA256 AES256-CBC KTS | DRBG Internal Value KDK KDK MEKs System MAC Key System Enc Key KDK | LockinSP.Admin1 -4 | E G, Z E G, Z E E W, R | Mailbox command result |
| Band Set Disable | Initialize the location, size and lock state of the band. | CKG (Hash_DRBG) KBKDF HMAC-SHA256 AES256-CBC KTS | DRBG Internal Value KDK KDK MEKs System MAC Key System Enc Key KDK | LockingSP.Admin 1-4 | E G, Z E G, Z E E W, R | Mailbox command result |
| Show Status | Report status of the CM and versioning information. | N/A | N/A | None | N/A | Mailbox command result |
| N/A | None6 |
Zeroisation Erase SSPs. N/A RKey None6 Z Mailbox
6 Need to input PSID, which is public drive-unique value used for the zeroisation service.
Reset
Power-OFF: Delete SSPs in RAM. Power-ON: Runs various self-tests to be performed at power-on ( POSTs, CASTs, Firmware Load test ) and generate / import some SSPs.
N/A
System MAC Key System Enc Key KDK MEKs PINs DRBG Internal Value PubKey1
Z Z Z Z Z Z Z
N/A
KDK Z command result v1_5 N/A power-on ( POSTs, Entropy Source DRBG Seed G KTS KDK W Note 1: “CKG(Hash_DRBG)” means direct use of Hash_DRBG output as a key. Table 7 ‐ Approved services Section 5 – Software/Firmware Security Firmware Security of components in this CM is shown below. ROM Code: ・ Form of the executable code: ELF format ・ Integrity verification method: 32bit CRC ・ Method for integrity test on demand: Power cycling Firmware image (User Code): ・ Form of the executable code: ELF format ・ Integrity verification method: Approved signature verification (RSASSA-PKCS#1-v1_5, see table 3) ・ Method for integrity test on demand: Power cycling
| Physical Security Mechanism | Recommended Frequency of Inspection/Test | Inspection/Test Guidance Detail | |
|---|---|---|---|
| Passivated opaque package | Every month or every two months | Confirmation that there is no visual damage |
Section 6
| Key/SSP Name/Ty pe | Strength (bit) | Security Function and Cert Number | Generation | Import/ Export | Establishment | Storage | Zeroisation | Use & related keys | |
|---|---|---|---|---|---|---|---|---|---|
| Critical Security Parameters (CSPs) | |||||||||
| RKey | 256 | KBKDF (#C2001) | Hash_DRBG (Method SP800-133 Rev.2 Section 4) | N/A | Manufacturing | Plaintext in OTP | Explicit Zeroisation service | Derivation of System Enc Key and System MAC Key | |
| System Enc Key | 256 | AES-CBC (#C1925) | KDF in Counter Mode | N/A | Power-On | Plaintext in RAM | Explicit Zeroisation service Implicit Power-Off | Data and Key Encryption / Decryption for KTS | |
| System MAC Key | 256 | HMAC (#C1925) | KDF in Counter Mode | N/A | Power-On | Plaintext in RAM | Explicit Zeroisation service Implicit Power-Off | Message Authentication Code generation and verification for KTS | |
| KDK | 256 | KBKDF (#C2001) | Hash_DRBG (Method SP800-133 Rev.2 Section 4) | Imported and Exported by KTS (see Table 3) | Key update services7 | Plaintext in RAM Encrypted in System Area outside the module | Explicit Zeroisation service, Key update services Implicit Power-Off | Derivation of MEKs |
Section 9 – Sensitive security parameter management The CM uses keys and SSPs in the following table. 4)
7 The following service are applicable, Cryptographic Erase, Cryptographic Erase for Band of
Single User Mode, Cryptographic Erase and Initialize Band State, Set Band Position and Size, Set Band Position and Size for Band of Single User Mode, Revert, Sanitize, Format Namespace, Namespace Create/Delete and Band Set Enable.
| using the Approved KTS | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| MEKs | 256 | AES-XTS (#C1925) | KDF in Counter Mode | N/A | Band Lock/Unlock service, Key update services | Plaintext in AES register | Explicit Zeroisation service, Key update services Implicit Power-Off | Data Encryption / Decryption | |
| PINs | Referred to in Section 4.1 (Table 6) | SHA256 (#C1925) | Electric input | Imported and Exported by KTS (see Table 3) | Set PIN service | Hashed in RAM Hashed + Encrypted in System Area outside the module using the Approved KTS | Explicit Zeroisation service Implicit Power-Off | User authentication | |
| DRBG Internal Value | V: 440 bits C: 440 bits | Hash_DRBG (#C2002) | SP800-90A Instantiation of Hash_DRBG | N/A | Power-On | Plaintext in RAM | Explicit Zeroisation service Implicit Power-Off | Random number generation | |
| DRBG Seed | Public Security Parameters (PSPs) | Entropy Input String and Nonce: 512 bits | Hash_DRBG (#C2002) | Entropy collected from Entropy Source at instantiation (Minimum entropy of 8 bits: 6.31) | N/A | Power-On | Plaintext in RAM | Implicit Immediately after use8 | Random number generation |
PubKey1
RSA (#C2009)
Electric input
Imported during FW load.
Power-on FW Download service
Plaintext in RAM Hashed in OTP
Implicit Power-Off (Data in RAM)
Signature verification.
| Entropy source | Minimum number of bits of entropy | Details | |
|---|---|---|---|
| Entropy Source9 | Minimum entropy of 8 bits is 6.31. | Hardware RNG used to seed the approved Hash_DRBG. |
| Function | Self-Test Type | Execution Condition | Abstract | Failure Behavior |
|---|---|---|---|---|
| AES256-CBC | Conditional | Power-On | Encrypt and Decrypt KAT | Enters Boot Error State. (Indicated Error Code: 0x24) |
| AES256-XTS | Conditional | Power-On | Encrypt and Decrypt KAT | Enters Boot Error State. (Indicated Error Code: 0x23) |
| SHA256 | Conditional | Power-On | Digest KAT | Enters Boot Error State. (Indicated Error Code: 0x25) |
Table 9 ‐ SSPs Table 10 ‐ Non-Deterministic Random Number Generation Specification For the Entropy Source listed in the table above, self-tests are performed each time before data is obtained (see Section 10 for details of these self-tests). When these tests detect that the Entropy Source cannot generate the sufficient amount of entropy, the CM is transient to error state. The CM can be recovered from the error state by rebooting the module, and the obtaining several trials of reboot, the CM may be sent back to factory to recover from error state. Section 10 – Self Tests The CM runs self-tests in the following table. The Entropy Source is a hardware module inside the CM boundary. The Entropy Source supplies the Hash_DRBG with 512 bits entropy input. From Table 10 this input contains about
404 bits of entropy, which is sufficient entropy to obtain 256 bits of security strength.
| HMAC-SHA256 | Conditional | Power-On | Digest KAT | Enters Boot Error State. (Indicated Error Code: 0x26) |
|---|---|---|---|---|
| Hash_DRBG | Conditional | Power-On | DRBG KAT | Enters Boot Error State. (Indicated Error Code: 0x18/0x19) |
| RSASSA-PKCS#1-v1_5 | Conditional | Power-On | Signature verification KAT | Enters Boot Error State. (Indicated Error Code: 0x27) |
| KDF in Counter Mode | Conditional | Power-On | KDF KAT | Enters Boot Error State (Indicated Error Code: 0x28) |
| Entropy Source (Health tests of noise source at startup.) | Conditional | Power-On | Verify not deviating from the intended behavior of the noise source by Repetition Count Test and Adaptive Proportion Test specified in SP800-90B. | Enters Boot Error State (Indicated Error Code: 0x2C/0x2D) |
| Hash_DRBG | Conditional | Random number generation | Verify newly generated random number not equal to previous one | Enters Error State. (Indicated Error Code: 0x1D) |
| Entropy Source | Conditional | Entropy output request | Verify newly generated random number not equal to previous one | Enters Error State. (Indicated Error Code: 0x1E) |
| Entropy Source (Continuous noise source health tests during operation.) | Conditional | Entropy output request | Verify not deviating from the intended behavior of the noise source by Repetition Count Test and Adaptive Proportion Test specified in SP800-90B. | Enters Error State. (Indicated Error Code: 0x2C/0x2D) |
| Firmware load test | Conditional10 | Power-on | Verify signature of loaded firmware image by RSASSA-PKCS#1-v1_5 | Enters Power Up Load Test Error State (Indicated Error Code: 0x13) |
| FW download | Verify signature of downloaded firmware image by RSASSA-PKCS#1-v1_5 | Enters Conditional Load Test Error State. After reporting Error code, transition from error state to normal state and continue to operate with FW before download. |
loaded into the CM can be confirmed.
| (Indicated Error Code: 0x13) | ||||
|---|---|---|---|---|
| Firmware integrity test | Pre-operational | Power-On | Verify ROM code integrity with 32bit CRC. | Enters Boot Error State (Implicit error reporting by stopping the startup sequence) |
Table 11 ‐ Self Tests As shown in the table above, self-tests are performed automatically at the CM startup and before execution certain security functions. Operator can also initiate self-test on-demand for periodic testing by using the Reset service which is automatically invoked when the module is powered-off and powered-on (rebooted). If the self-tests fail, the CM reports error status and enters to the error state. In this case, the CM must be powered-off to clear error condition. When power-on is executed again, self-tests are also executed like an on-demand operator reset. If the CM continuously enters in error state in spite of several trials of reboot, the CM may be sent back to factory to recover from error Section 11 – Life-cycle Assurance In the SSD’s manufacturing process, installation is executed as below:
For secure operation, the following settings must be maintained: Data Locking Protection is Enabled Each Band is set to be locked when power-on. Bands that are not configured are considered unprotected or plaintext. (Refer to SSD setting procedure11 ) As described in Section 2, the CM is used by being embedded in the solid state drive. Therefore, there are no maintenance requirements for the CM alone. Guidance for this module is provided to solid state drive developers who embed the CM. The usage and maintenance of solid state drives with the CM built-in are outside of the scope of this document. Section 12 – Mitigation of Other Attacks The CM does not mitigate other attacks beyond the scope of FIPS 140-3 requirements.
11 For maintaining secure condition, the SSD needs several setting at least.
Owners of the SSD that embeds the CM must use it securely according to the followings: