All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Toshiba Secure TCG Opal SSC Self-Encrypting Drive Series MG09SCP18TA and MG09SCP16TA

Certificate#4813StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorToshiba Electronic Devices & Storage Corporation
High review priority  ·  no TCB surface named  ·  last validated 22 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date9/23/2029
CaveatNone
VendorToshiba Electronic Devices & Storage Corporation

Approved Algorithms (9)

AlgorithmACVP Cert
AES-CBCA1638
AES-ECBA1638
AES-XTS Testing Revision 2.0A1638
Hash DRBGA1645
HMAC-SHA2-256A1638
RSA SigVer (FIPS186-4)A1637
SHA2-256A1637
SHA2-256A1638
SHA2-256A1645

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Toshiba Secure TCG Opal SSC Self-Encrypting Drive Series MG09SCP18TA and MG09SCP16TA
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>firmware load<br/>recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status output<br/>Show status</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Toshiba Secure TCG Opal SSC Self-Encrypting Drive Series MG09SCP18TA and MG09SCP16TA
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>firmware load<br/>recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status output<br/>Show status</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Toshiba Secure TCG Opal SSC Self-Encrypting Drive Series MG09SCP18TA and MG09SCP16TA Prepared by: Rev 2.4.0

1 Sep. 13, 2024
Page 2
2 Sep. 13, 2024
Page 3
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security2
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1

The Toshiba Secure TCG Opal SSC Self-Encrypting Drive Series (MG09SCP18TA and MG09SCP16TA) is used for hard disk drive data security. The security levels for this Cryptographic Module (CM) are as follows: Table 1: Security Levels This document is non-proprietary and may be reproduced in its original entirety.

1.1 Acronyms
AESAdvanced Encryption Standard
CSPCritical Security Parameter
DRBGDeterministic Random Bit Generator
EBGEntropy Bit Generator
FWFirmware
HMACKeyed-Hashing for Message Authentication code
KATKnown Answer Test
LBALogical Block Address
PCAPrinted Circuit Assembly
POSTPower on Self-Test (pre-operational self-tests and conditional algorithm self-tests)
SoCSystem on Chip
SSCSecurity Subsystem Class
SEDSelf-Encrypting Drive
SHASecure Hash Algorithm
SIDSecurity ID

TCG SWG Trusted Computing Group Storage Work Group TOEPP Tested Operational Environment’s Physical Perimeter

3 Sep. 13, 2024
Page 4
ModelHardware [Part Number and Version]Firmware VersionDistinguishing Features
MG09SCP18TAA0PC82SAS interface, 18TB
MG09SCP16TAA0PC82SAS interface, 16TB
CAVP CertsAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key StrengthUse/Function
A1637RSA, FIPS PUB 186-4RSASSA- PKCS#1-v1_5Modulus: 3072bits, Key Strength: 128bitsDigital signature verification
A1637SHS, FIPS PUB 180-4SHA2-256 (BYTE-only)-Message digest for RSA
A1638AES, FIPS PUB 197-CBCKey Size: 256bits, Key Strength: 256bitsData encryption / decryption

2. Cryptographic Module Specification This CM provides various cryptographic services using approved algorithms. Services include hardware-based data encryption, cryptographic erase, independently protected user data LBA ranges, and FW Download. The CM always encrypts the user data, protects CSPs from unauthorized access, and provides secure sanitization methods by supporting TCG Opal SSC features. The operational rules described in this document adheres to TCG Opal. This CM is a multiple-chip-embedded hardware cryptographic module. The cryptographic boundary of the CM is the entire HDD. The physical interface for power-supply and for communication is one SAS connector. The CM is connected with host system by this SAS connector. The logical interface is the SAS, TCG SWG and Opal SSC. The CM has the non-volatile storage area for not only user data but also the keys, CSPs, and FW. The latter storage area is called the “system area”, which is not logically accessible / addressable by the host application. The CM has one approved mode of operation and CM is always in approved mode of operation. The CM provides only approved services defined in 4.2. Non-approved security functions are not implemented.

2.1 Product Version

The Toshiba Secure TCG Opal SSC SED has been validated in the following versions: The tested platform is Toshiba Cryptographic Hardware 88i1215-B1. The CM does not employ any operating system. Table 2: Cryptographic Module Tested Configuration

2.2 All Security Functions

The CM does not implement any non-approved algorithms allowed in the approved mode of operation. It does not implement any non-approved algorithms allowed in the approved mode of operation with no security claimed. It does not implement any non-approved algorithms not allowed in the approved mode of operation.

4 Sep. 13, 2024
Page 5
upd1, SP800- 38A
A1638AES, FIPS PUB 197- upd1, SP800- 38EXTSKey Size (Key_1): 256bits, Key Size (Key_2): 256bits, Key Strength: 256bitsData encryption / decryption
A1638HMAC, FIPS PUB 198-1SHA2-256Key Size: 256bits, Key Strength: 256bits, KS < BSMessage authentication for data integrity verification of system area
A1638SHS, FIPS PUB 180-4SHA2-256 (BYTE-only)-Message digest for HMAC
A1645Hash-DRBG, SP800-90A rev1SHA2-256Prediction Resistance: FalseDeterministic random bit generation
A1645SHS, FIPS PUB 180-4SHA2-256 (BYTE-only)-Message digest for DRBG
ENT (P)SP800-90B--Seed generation for Hash- DRBG
Vendor AffirmedCKG, SP800- 133rev2-An output of the hash- DRBG is directly used. (Section 4 of SP800- 133rev2)Key generation
Table, extracted as text (did not parse into structured rows)
CAVP Certs         Algorithm and    Mode/Method       Description / Key Size(s) /   Use/Function There are algorithms, modes, and keys that have been CAVP tested but not used by the module. Only the algorithms, modes/methods, and key lengths/curves/moduli shown in this table are used by the module. Table 3: Approved Algorithms Figure 1: MG09SCP16TA                    Figure 2: MG09SCP18TA             Figure 3: PCA side
5 Sep. 13, 2024
Page 6
Physical portLogical interfaceData that passes over port / interface
SAS connectorData input interfaceUser data, FW data
SAS connectorData output interfaceUser data
SAS connectorControl input interfaceSAS control input data (ex. command frame, data frame)
N/AControl output interfaceN/A
SAS connectorStatus output interfaceSAS status output data (ex. response frame, data frame)
SAS connectorPower interfaceN/A

Figure 4: Side of the device Figure 5: SAS port Figure 6: Side of the device Figure 7 shows the CM's block diagram. In this diagram, the cryptographic boundary of the CM, defined by the enclosure of the MG09SCP18TA and the MG09SCP16TA, is indicated by a dashed line. It includes the SAS connector, the SoC, the buffer DRAM, the flash ROM and the magnetic storage medium. Figure 7: Block Diagram 3. Cryptographic Module Interfaces The CM does not implement any control output interface. All data, status, control, and power interfaces above use a single SAS connector that contains multiple pins for power supply, data transmission, and signal exchange. Table 4: Ports and Interfaces

6 Sep. 13, 2024
Page 7
Role1ServiceInputOutput
LockingSP.Ad min1 … LockingSP.Ad min4Enable / Disable LockingSP Admin/User Range Lock/Unlock Set range position and size TCG Reactivate TCG Cryptographic Erase (Erase) TCG Cryptographic Erase (GenKey) Zeroization (without RKey)Security Protocol Out commandCommand response
LockingSP.Us er1 … LockingSP.Us er9Range Lock/Unlock Set range position and size TCG Cryptographic Erase (Erase) TCG Cryptographic Erase (GenKey)2Security Protocol Out commandCommand response
AdminSP.SIDTCG activateSecurity Protocol Out commandCommand response
Firmware DownloadSecurity Protocol Out command and Write Buffer command with FW
NoneReset (run POSTs)Power on reset commandCommand response
Data read / writeRead/Write commands with User dataCommand response, User data
Random number generationSecurity Protocol Out commandCommand response, Random number
Show statusRequest Sense commandCommand response, Status
Zeroization (with RKey) (using PSID)Security Protocol Out commandCommand response
Cryptographic SanitizationSanitize command
Show versioning informationInquiry commandCommand response, Versioning
  1. Roles, Services, and Authentication This section describes roles and services the CM supports. The CM supports 14 Crypto Officer roles listed in Table
  2. The roles listed in Table 5 are all Crypto Officer roles. The CM does not implement any Non-Approved Services.
4.1 Roles

1 TCG Authority (LockingSP.Admin1-4, AdminSP.Admin1, LockingSP.User1-9 or AdminSP.SID)

can be assumed by using TCG Start Session method.

2 Available only when the CM uses TCG Single User Mode functionality.

The CM is always in 140-3 approved mode of operation regardless of this functionality.

7 Sep. 13, 2024
Page 8
information
Non-security relevant HDD serviceSCSI commandCommand response
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRole(s)Access rights to Keys and/or SSPsIndicator
Data read/write (decrypt/encry pt)Encryption / decryption of unlocked user data to/from range Method: SCSI READ, WRITE commandsAES256-XTSMEK(s)NoneECommand response

Role1 Service Input Output Table 5: Roles, Service Commands, Input and Output

4.2 Services

The CM supports the TCG Single User Mode functionality defined in the Single User Mode feature set of TCG Opal. A single role (LockingSP.Userx) is assigned to manage the associated range (range X) during the TCG single user mode. The LockingSP.Reactivate or LockingSP.Activate method enables this mode. Authorized roles of some services differ when the CM is in single user mode. About such services, the Role(s) column in Table 6 is divided into two rows. The upper row shows authorized roles in non-single user mode (normal mode), while the lower row shows authorized roles against range X in single user mode. The CM provides the following services to operators per Section 7.4.3.1 of ISO/IEC 19790_2012_2015:  Show module's versioning information: Show versioning information service  Show status: Show Status service  Perform self-test: Reset (run POSTs) service  Perform zeroization: Zeroization (with RKey) service, Zeroization (without RKey) services  Perform approved security functions: Services indicated with Approved Security Functions in Table 6 The modes of access to SSPs shown in Table 6 are defined as: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP.

8 Sep. 13, 2024
Page 9
Enable /Disable LockingSP Admin/UserEnable/Disable LockingSP Admin/User (except for- Single-User-Data-Range User) Authority Method: SECURITY PROTOCOL OUT command (TCG Set Method)HMAC SHA2- 256(A1638)N/ALockingSP.A dminxN/ACommand response
Random Number generationProvide a random number generated by the CM Method: SECURITY PROTOCOL OUT command (TCG Random)Hash_DRBG SHA2- 256(A1645)DRBG C Vector DRBG V VectorNoneE ECommand response
Range Lock/UnlockBlock or allow read (decrypt) / write (encrypt) of user data in a range. Locking also requires read/write locking to be enabled Method: -SECURITY PROTOCOL OUT command (TCG Set Method)HMAC SHA2- 256(A1638)RKey MEK(s)LockingSP.A dminx/Locki ngSP.Userx (LockingSP is active) LocknigSP. UserxE ECommand response
Set range position and sizeSet the location and size of the LBA range Method: SECURITY PROTOCOL OUT command (TCG Set Method)Hash_DRBG SHA2- 256(A1645) AES256-CBC HMAC SHA2- 256(A1638) ENT (P) CKGMEK(s) RKeyLockingSP.A dminx LockingSP.A dminx or LockingSP. UserxG ECommand response
Reset (run POSTs)Perform self-tests and delete CSPs in SRAM Method: Power on reset commandRSASSA- PKCS#1-v1_5 SHA2- 256(A1637)DRBG C Vector DRBG V Vector Seed RKeyNoneG, Z G, Z G, E, Z ECommand response
TCG reactivateSwitch from/to TCG Opal single user mode Method: SECURITY PROTOCOL OUT command (TCG Reactivate)HMAC SHA2- 256(A1638)N/ALockingSP.A dminxN/ACommand response
Show StatusReport status of the CM Method: REQUEST SENSE commandN/AN/ANoneN/ACommand response
Table, extracted as text (did not parse into structured rows)
Service        Description                        Approved      Keys     Role(s)       Access    Indicator Functions     SSPs                   to Keys SSPs
9 Sep. 13, 2024
Page 10
TCG ActivateActivate LockingSP Method: SECURITY PROTOCOL OUT command (AdminSP.activate)Hash_DRBG SHA2- 256(A1645) AES256-CBC HMAC SHA2- 256(A1638)MEK(s) (except for Global Range) RKeyAdminSP.SI DG ECommand response
TCG Cryptographic Erase (Erase)Erase user data (in cryptographic means) in an LBA range by changing the data encryption key. This method is available only in single user mode. Method: SECURITY PROTOCOL OUT command (TCG Erase)Hash_DRBG SHA2- 256(A1645) AES256-CBC HMAC SHA2- 256(A1638) ENT (P) CKGMEK(s) RKeyN/A LocknigSP. Userx LockingSP.A dminxG, Z ECommand response
TCG Cryptographic Erase (GenKey)Erase user data (in cryptographic means) in an LBA range by changing the data encryption key. Method: SECURITY PROTOCOL OUT command (TCG GenKey)Hash_DRBG SHA2- 256(A1645) AES256-CBC HMAC SHA2- 256(A1638) ENT (P) CKGMEK(s) RKeyLockingSP.A dminx LockingSP. UserxG, Z ECommand response
Zeroization (with RKey)Initialize the CM by zeroizing RKey, MEKs, and range configuration. Method: SECURITY PROTOCOL OUT command ( - AdminSPObj.Revert3 )Hash_DRBG SHA2- 256(A1645) AES256-CBC HMAC SHA2- 256(A1638) ENT (P) CKGMEK(s) RKeyNone (using PSID4)G, Z G, E, ZCommand response
Zeroization (without RKey)Initialize the CM by zeroizing MEKs, and range configuration. Method: SECURITY PROTOCOL OUT command ( - LockingSP.RevertSP3 - LockingSPObj.Revert3 )Hash_DRBG SHA2- 256(A1645) AES256-CBC HMAC SHA2- 256(A1638) ENT (P) CKGMEK(s) RKeyLockingSP.A dminxG, Z ECommand response
Table, extracted as text (did not parse into structured rows)
Service         Description                      Approved     Keys      Role(s)       Access    Indicator Security     and/or                  rights Functions    SSPs                    to Keys and/or SSPs 3AdminSPObj.Revert, LockingSP.RevertSP, LockingSPObj.Revert are methods of TCG Opal SSC. 4PSID (Printed SID) is public drive-unique value which is used for the TCG Revert AdminSP method. PSID is printed on the HDD’s product label.
10 Sep. 13, 2024
Page 11
Firmware DownloadEnable / Disable firmware download and load a part of a firmware image. If the firmware load test passes, the CM will run with the new code. Method: SECURITY PROTOCOL OUT command (TCG Set Method), WRITE BUFFER commandRSASSA- PKCS#1-v1_5 SHA2- 256(A1637) HMAC SHA2- 256(A1638)PubKeyAdminSP.SI DECommand response
Cryptographic SanitizationErase user data by changing the data encryption key. This service is available only when all ranges are unlocked. Method: SANITIZE CRYPTOGRAPHIC ERASE commandHash_DRBG SHA2- 256(A1645) AES256-CBC HMAC SHA2- 256(A1638) ENT (P) CKGMEK(s) RKeyNoneG, Z ECommand response
Show versioning informationOutput the model name, HW version and FW version of the CM. Method: INQUIRY Standard Inquiry data command with Byte 32-35 (FW version), VPD Page C2, Byte 4-5 (HW version)N/AN/ANoneN/ACommand response
Non-security relevant HDD serviceProvide a HDD general service Method: SCSI commandsN/AN/ANoneN/ACommand response

Service Description Approved Keys Role(s) Access Indicator Security and/or rights Functions SSPs to Keys and/or SSPs Table 6: Approved Services FW integrity check is performed at power on. Signature verification using RSASSA-PKCS#1-v1_5 of the FW codes (in the flash ROM and in the disk media) and EDC verification of the FW code in the Mask ROM are done. The operator can initiate the on-demand FW integrity check by power cycling. All firmware components are in executable form, which cannot be dynamically modified. 6. Operational Environment The CM is a hardware module and operates in a non-modifiable operational environment, that is its firmware cannot be modified and no code can be added or deleted. SSPs are controlled by the CM itself, and uncontrolled access to CSPs and uncontrolled modifications of SSPs are prevented. Although firmware can be updated by “Firmware Download” service, whole FW codes (in the flash ROM and in the disk media) are replaced by this service, and the module becomes another module

11 Sep. 13, 2024
Page 12
Security
Key/SSP/Name/Import/
Strengthfunction andGenerationEstablishmentStorageZeroizationUse & related keys
Typecert. numberexport
MEKs/ CSP/ Symmetric256AES- XTS(A1638)By Hash- DRBG (A1645) CKG, SP800- 133rev2 Compliant with IG C.I (Key_1 ≠ Key_2)NoAfter “Zeroization (with RKey /without RKey)”, “TCG Cryptographic Erase (Erase/ GenKey)”, “Cryptographic Sanitization”, “TCG Activate”, and “Set range position and size” services. In the factoryEncrypte d by RKey / in System area /StaticBy “Zeroization (with RKey /without RKey)”, “TCG Cryptograph ic Erase (Erase / GenKey)”, and “Cryptograp hic Sanitization” services (explicitly)User data encryption and decryption (only for storage purpose) Encrypted and decrypted by RKey
By “Range Lock/Unlock” service. By “Reset” service (when the associated range is unlocked)Plain/ in SRAM (SoC register) /Dynami cBy power-off (implicitly)
RKey/ CSP/ Symmetric256AES- CBC(A1638)By Hash- DRBG (A1645) CKG, SP800- 133rev2NoAfter “Zeroization (with RKey)” service. In the factoryObfuscat ed (plain in 140-3 means) / in System area /StaticBy “Zeroization (with RKey)” service (explicitly)Encryption and decryption of MEKs

which requires new 140-3 certification.

  1. Physical Security The CM has the following physical security: ⚫ Production-grade components with standard passivation ⚫ Exterior of the drive is opaque The operator is required to periodically inspect the enclosure condition of the CM.
  2. Non-Invasive Security The CM does not employ non-invasive mitigation techniques referenced in NIST SP800-140F.
  3. Sensitive Security Parameters Management The CM uses SSPs in the following tables: c
12 Sep. 13, 2024
Page 13
Key/SSP/Name/Import/
Strengthfunction andGenerationEstablishmentStorageZeroizationUse & related keys
Typecert. numberexport
By “Zeroization (with RKey /without RKey)”, “TCG Cryptographic Erase (Erase/ GenKey)”, “Cryptographic Sanitization”, “TCG Activate”, “Set range position and size”, and “Range Lock/Unlock” services. By “Reset” service (when the range is unlocked)Plain/ in SRAM /Dynami cAfter use (implicitly)
Seed/ CSP/ DRBG seed5N/A6Hash- DRBG(A1645), Entropy sourceBy Entropy sourceNoAt instantiation (SP800-90Arev1)Plain/ in SRAM /Dynami cBy power-off (implicitly)Instantiation of Hash_DRBG
DRBG C Vector /CSP /internal stateN/A6Hash- DRBG(A1645)By DRBGNoAt instantiation (SP800-90Arev1)Plain/ in SRAM /Dynami cBy power-off (implicitly)Random number generation
DRBG V Vector / CSP/ internal stateN/A6Hash- DRBG(A1645)By DRBGNoAt instantiation (SP800-90Arev1)Plain/ in SRAM /Dynami cBy power-off (implicitly)Random number generation
PubKey/ PSP/ PublicModulus: 3072 Key Strength :128RSASSA- PKCS#1- v1_5(A1637)Manufacturi ngNoIn the factoryPlain / Embedde d in FW in system area /StaticBy "Firmware Download” service (explicitly)Signature verification
By “Firmware Download” servicePlain/ in SRAM /Dynami cBy power-off (implicitly)

Security c c c c c Table 8: SSPs Note that there is no security-relevant audit feature and audit data.

5 Entropy input string and nonce.
13 Sep. 13, 2024
Page 14

Entropy source

0.6 / 1

Physical noise source used to seed the approved Hash- DRBG. The overall amount of generated entropy is 48 bytes. This entropy source meets NIST SP800-90B requirements.

FunctionSelf-test typeDescriptionOperator initiationFailure behavior
Firmware integrity checkPre-operational software/firmware integrity testEDC (32bits) verification of the firmware in the Mask ROMPower-cycleBoot error state The CM is not accessible via SAS interface
Signature verification of the firmware in the flash ROM by RSASSA-PKCS#1- v1_5 with a 3072-bit Modulus using “PubKey2”Boot error state The CM is not accessible via SAS interface
Signature verification of the firmware in the disk media by RSASSA-PKCS#1- v1_5 with a 3072-bit Modulus using “PubKey2”Boot error state Status: CHECK CONDITION(02h), Sense Data: 04 4C 9F
AES CBCConditional cryptographic algorithm testEncrypt KAT with a 256-bit key Decrypt KAT with a 256-bit keyPower-cycleBoot error state Status: CHECK CONDITION(02h), Sense Data: 04 44 92
AES XTSConditional cryptographic algorithm testEncrypt KAT with a 256-bit key Decrypt KAT with a 256-bit keyPower-cycle
SHA2- 256(A1637)Conditional cryptographic algorithm testDigest KATPower-cycle
SHA2- 256(A1638)Conditional cryptographic algorithm testDigest KATPower-cycle
SHA2- 256(A1645)Conditional cryptographicDigest KATPower-cycle

Entropy sources Minimum number of bits of Details Table 9: Non-Deterministic Random Number Generation Specification If the source may deteriorate to the point when the generation of the sufficient amount of entropy can no longer be guaranteed, health test detects the source deterioration, enter an error state, and halts the CM. When the CM continuously enters in error state in spite of several trials of reboot, the CM shall be sent back to factory to recover from error state. 10. Self-Tests The CM runs self-tests in the following table.

14 Sep. 13, 2024
Page 15
Hash DRBGConditional cryptographic algorithm testDRBG KAT for instantiate and generate functionsPower-cycle
HMACConditional cryptographic algorithm testDigest KATPower-cycle
RSASSA- PKCS#1-v1_5Conditional cryptographic algorithm testSignature verification KAT with a 3072-bit ModulusPower-cycle
Entropy sourceConditional cryptographic algorithm testSP800-90B Start-up health test (repetition count test, adaptive proportion test)Power-cycleBoot error state Status: CHECK CONDITION(02h), Sense Data: 04 40 91
SP800-90B Continuous health test (repetition count test, adaptive proportion test)Power-cycleError state (conditional test) Status: CHECK CONDITION(02h), Sense Data: 04 44 92
Firmware load testConditional software/firmware load testSignature verification of firmware image by RSASSA-PKCS#1- v1_5 with a 3072-bit ModulusN/AError state (FW Load Test) Status: CHECK CONDITION(02h), Sense Data: 0B 74 08 The CM discards the new firmware image, then enters the Idle state

The public verification key “PubKey2” used in firmware integrity check resides within the MaskROM code and is not a SSP. SHA2-256(A1637) is embedded in RSASSA-PKCS#1-v1_5, while SHA2-256(A1638) is used in HMAC, and SHA2-256(A1645) is employed in Hash DRBG. The CM does not implement reseed function of Hash DRBG. Table 10: Self-Tests If the CM fails the self-test, it enters one of three error states: Error State (Conditional Test), Error and for other self-tests, it transitions to Boot Error State. Status indicator for each error state is CM is currently in Boot Error State). When in the error state, the CM does not perform any cryptographic operations or output data. A power cycle is required to clear the error state. When the CM continuously enters the error state despite several reboot attempts, the CM should be returned to the factory for recovery from the error The CM does not support any degraded operation.

15 Sep. 13, 2024
Page 16

11. Life-Cycle Assurance The following are the secure initialization procedure for the CM. The CM is always in approved mode of operation in a deployed environment. In addition to this, the following procedure of initial settings will allow further secure operation during power cycling. Please refer to TCG Opal specification (TCG Storage Security Subsystem Class: Opal Version 2.01 Revision 1.00) for the details. (1) Activate LockingSP by “TCG Activate” service. (2) Set LockOnReset in Download port to “Power Cycle”. (3) Set ReadLockEnabled and WriteLockEnabled to 1(true) and LockOnReset to “Power Cycle”. (4) Do a power-on-reset. The longest service life of the CM under suitable conditions and treatment is 5 years. By the end of this period the operator is required to follow the CM’s end of life procedures below. (1) Initialize internal sensitive data in the host system. (2) Initialize parameters and user information in the CM by “Zeroization (with RKey)” service. For additional details, refer to the guidance documents provided with the CM:

3.5 type SAS Hard Disk Drives Product Specification
3.5 type SAS Hard Disk Drives Interface Specification
3.5 type Hard Disk Drives SED Specification
Toshiba SED HDD FIPS140-2/3 Use case Rev.6.0

12. Mitigation of Other Attacks The CM does not mitigate other attacks beyond the scope of 140-3 requirements.

16 Sep. 13, 2024