All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Solidigm® P5316 SSD (ADP-R)

Certificate#4851StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorSK hynix NAND Product Solutions Corp (d/b/a Solidigm)
Medium review priority  ·  exposes firmware-update authentication  ·  last validated 7 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date10/22/2029
CaveatWhen installed, initialized and configured as specified in Section 2.4 of the Security Policy. The tamper evident seals installed as indicated in the Security Policy.
VendorSK hynix NAND Product Solutions Corp (d/b/a Solidigm)

Approved Algorithms (11)

AlgorithmACVP Cert
AES-ECBA2879
AES-ECBA2881
AES-KWA2881
AES-XTS Testing Revision 2.0A2879
HMAC DRBGA2881
HMAC-SHA2-256A2881
KDF SP800-108A2881
RSA SigVer (FIPS186-4)A2880
RSA SigVer (FIPS186-4)A2881
SHA2-256A2880
SHA2-256A2881

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Solidigm® P5316 SSD (ADP-R)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>show status<br/>Status output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Solidigm® P5316 SSD (ADP-R)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>show status<br/>Status output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Solidigm® P5316 SSD (ADP-R) Security Policy Solidigm® Corporation Solidigm® P5316 SSD (ADP-R) FIPS 140-3 Cryptographic Module Version: 1.3 Date: July 28, 2025 Prepared by: www.acumensecurity.net

Page 2

Solidigm® P5316 SSD (ADP-R) Security Policy Table of Contents

Page 3

Solidigm® P5316 SSD (ADP-R) Security Policy List of Tables Table 4 - Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security List of Figures

Page 4

Solidigm® P5316 SSD (ADP-R) Security Policy © 2025 Solidigm® Corporation. This document can be reproduced and distributed only whole and

Page 5

Solidigm® P5316 SSD (ADP-R) Security Policy About FIPS 140-3 Federal Information Processing Standards Publication 140-3 — Security Requirements for Cryptographic Modules specifies requirements for cryptographic modules to be deployed in a sensitive but unclassified environment. The National Institute of Standards and Technology (NIST) and Canadian Centre for Cyber Security (CCCS) oversees the Cryptographic Module Validation Program (CMVP). The NVLAP accredits independent testing labs to perform FIPS 140-3 testing and the CMVP validates modules meeting FIPS 140-3 compliance. Validated is the term given to a module that is documented and tested against the FIPS 140-3 criteria. More information is available on the CMVP website at: https://csrc.nist.gov/projects/cryptographic-module-validation-program About this Document This non-proprietary Cryptographic Module Security Policy for the Solidigm® P5316 Solid State Drive (SSD) (ADP-R) provides an overview of the product and a high-level description of how it meets the overall Level Security Level 2 security requirements of FIPS 140-3. The Solidigm® P5316 SSD (ADP-R) may also be referred to as the “module”, “ADP-R”, or simply the “drive” in this document. Disclaimer The contents of this document are subject to revision without notice due to continued progress in methodology, design, and manufacturing. Solidigm® shall have no liability for any error or damages of any kind resulting from the use of this document. Notices This document may be freely reproduced and distributed in its entirety without modification.

Page 6
ISO/IEC 24759 Section 6 [Number Below]FIPS 140-3 Section TitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A

Solidigm® P5316 SSD (ADP-R) Security Policy

1.1 Scope

This document describes the cryptographic module security policy for the Solidigm® P5316 SSD (ADP-R), Hardware and Firmware versions described in Table 2. It contains specification of the security rules, under which the cryptographic module operates, including the security rules derived from the requirements of the FIPS 140-3 standard.

1.2 Overview

The Solidigm® P5316 SSD (ADP-R) is a hardware module in a multi-chip embedded embodiment which provides data-at-rest protection, using AES-XTS-256 to encrypt user data prior to being written to media. Authentication and access controls in the module are provided by the Opal Storage Specification (v2.01) by the Trusted Computing Group Storage Workgroup. The module is designed to be installed in a data center environment configured as a Single Port NVMe storage device. The following table lists the level of validation for each area in FIPS 140-3: Table 1 - Security Levels The module meets the overall Security Level 2 requirements. The Module implementation is compliant with:

Page 7

Solidigm® P5316 SSD (ADP-R) Security Policy • NVMe-MI 1.0a: o https://nvmexpress.org/wpcontent/uploads/NVM_Express_Management_Interface_1_0a_2017.04.08_-_gold.pdf

Page 8

Solidigm® P5316 SSD (ADP-R) Security Policy 2. Cryptographic Module Specification The multi-chip embedded Module, pictured below in Figure 1, is intended for use by US Federal agencies and other markets that require FIPS 140-3 validated Self Encrypting Solid State Disks. Figure 1

Page 9

Solidigm® P5316 SSD (ADP-R) Security Policy Figure 3 -- E1.L Module Picture (Top Side with secured black latch) Figure 4 – E1.L Module Picture (Top Side with secured black latch with Solidigm branding) Figure 5 -- E1.L Module Picture (Bottom Side with secured black latch with Intel branding) The cryptographic boundary is defined as the external perimeter of the SSD enclosure represented in Figures 1-4. Figure 5 below shows the module block diagram where the red dotted line depicts the module’s physical perimeter.

Page 10
ModelHardware [Part Number and Version]Firmware VersionDistinguishing Features
Solidigm® P5316 SSDP/N: SSDPF2NV153TZ9 Ver: K82228-10304 with TEL P/N: M52551-0011.6.02.5-inch U.2 drive in 15.36 TB capacity, Intel or Solidigm branded
P/N: SSDPF2NV307TZ9 Ver: K82229-10304 with TEL P/N: M52551-0011.6.02.5-inch U.2 drive in 30.72 TB capacity, Intel or Solidigm branded
P/N: SSDPFWNV153TZD Ver: K78028-10305 with TEL P/N: M45818-002 and Latch P/N: AA0015502ACV1MA18E1.L 9.5 mm drive in 15.36 TB capacity, Intel or Solidigm branded
P/N: SSDPFWNV307TZDACV1MA18E1.L 9.5 mm drive in 30.72 TB capacity,

Solidigm® P5316 SSD (ADP-R) Security Policy Figure 6 – Module Block Diagram

2.1 Tested Configurations

The module was tested in two different form factors (U.2 and E1.L), each with two different capacities.

Page 11
ModelHardware [Part Number and Version]Firmware VersionDistinguishing Features
Ver: K78023-10305 with TEL P/N: M45818-002 and Latch P/N: AA0015502Intel or Solidigm branded
P/N: SSDPF2NV153TZD Ver: K82228-10304 with TEL P/N: M52551-001ACV103602.5-inch U.2 drive in 15.36 TB capacity, Intel or Solidigm branded
P/N: SSDPF2NV307TZD Ver: K82229-10304 with TEL P/N: M52551-001ACV103602.5-inch U.2 drive in 30.72 TB capacity, Intel or Solidigm branded
CAVP Cert1Algorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A2881AES [FIPS 197, SP 800-38A]ECB256 bitsEncryption and Decryption of encryption Keys
A2881AES [FIPS 197, SP 800-38F]KW256 bitsEncryption and Decryption of the Keys for key storage
A2879AES [FIPS 197, SP 800-38A, SP 800- 38E]XTS, ECB2256 bitsXTS Encryption and Decryption operations within storage applications
Vendor Affirmed IG D.HCKG [SP 800-133, rev 2]Section 4, 6.1, 6.2256 bitsDirect seed and symmetric key generation using unmodified DRBG output
A2881DRBG [SP 800-90A, rev 1]HMAC_DRBG256 bitsGenerate random bits used to create cryptographic keys
ENTENT (P) [SP 800- 90B]Physical entropy sourceEntropy Source Broadcom TRNG
A2881HMAC [FIPS 198-1]HMAC-SHA2- 256256 bitsHMAC-DRBG, KBKDF, KDF
A2881KBKDF [SP 800-108, rev 1]Counter Mode256 bitsUsed to derive symmetric encryption keys used internal to the drive

Solidigm® P5316 SSD (ADP-R) Security Policy Table 2 - Cryptographic Module Tested Configuration

2.2 Algorithms

The Module implements the Approved cryptographic functions listed in the table below. This table includes vendor-affirmed algorithms that are approved but CAVP testing is not yet available. ECB is only supported as a prerequisite for XTS and is not directly used by the module.

Page 12
CAVP Cert1Algorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A2881PBKDF [SP 800- 132]KDF with Option 1a - HMAC-based KDF using SHA2- 256 -10,0003 iteration count256 bitsUsed as part of authentication of Cryptographic Officer role Note: The keys derived from passwords are only used for storage applications
A2880RSA [FIPS 186-4 and PKCS #1 v2.1 (PKCS1.5)]sigVer PKCS1.5 with SHA2-2562048 bitsDigital Signature Verification (Firmware Integrity test)
A2881RSA [FIPS 186-4 and PKCS #1 v2.1 (PKCS1.5)]sigVer PKCS1.5 with SHA2-2562048 bitsDigital Signature Verification (Firmware Download, Maintenance authentication)
A2880SHS [FIPS 180-4]SHA2-256N/AHashing for Digital Signature Verification for the integrity test
A2881SHS [FIPS 180-4]SHA2-256N/AHashing for Digital Signature Verification, HMAC DRBG, Key Based-KDF operations
AlgorithmCaveatUse/Function
AES-CTR (non-compliant)Used for added protection of stored keys but is not required for securityUsed to wrap key data (Encrypted Key Blob) using a non-SSP. Note, this algorithm was CAVP tested but is not used in a way that claims security.

Solidigm® P5316 SSD (ADP-R) Security Policy Table 3

2.3 Cryptographic Boundary

The cryptographic boundary is defined as the external perimeter of the SSD enclosure and is composed of the following components: 1. Sentinel Rock Plus ASIC (B1 stepping) – The storage controller ASIC. This component is responsible for terminating PCIe/NVMe commands, reading or writing data to the Host platform, encrypting

Page 13

Solidigm® P5316 SSD (ADP-R) Security Policy or decrypting data from the Host platform, and storing or retrieving data to NAND non-volatile memory.

  1. DRAM – Dynamic RAM.
  2. NAND – non-volatile memory. These components comprise the non-volatile media of the storage device. These components store encrypted user data, firmware for the P5316, and other nonvolatile configuration data needed by the ASIC controller during execution.
  3. MIC – SMBus controller The Module relies on the PCIe/NVMe interface as input/output devices. Two capacitors within the module boundary are excluded from the FIPS 140-3 requirements. The exclusion of these components does not affect the security of the module.
2.4 Approved Mode of Operation

The Module ships from the manufacturing facility with either the Approved firmware identified in Table

2 or a firmware which has not been validated.

To determine if a module is using an Approved firmware version, the Compliance Descriptor will be retrieved via the Read Compliance (show status) service and the following information will be verified (Note: Byte references below are from a starting index of zero):

  1. Related Standard indicates FIPS 140-3 (3) on byte 13
  2. Overall Security Level indicates Level 2 (2) on byte 14
  3. Compliance Descriptor Hardware Version (byte 16) matches the HW P/N and Version column of a configuration in Table 2.
  4. Compliance Descriptor Version (byte 144) matches the FW Version column of a configuration in Table 2.
  5. Compliance Descriptor Module Name (byte 272) matches the Module column of a configuration in Table
  6. When the Approved firmware is installed, the module is in an uninitialized state and user authentication is not enabled. When the Approved firmware is not installed, the Cryptographic Officer will have to perform the following procedure to transition the module to an uninitialized state:
  7. Update the firmware with the Firmware Update service to the Approved firmware
  8. Reset the module
  9. Enable/Activate Opal
  10. Perform an AdminSP Revert method on the AdminSP Once in the uninitialized state, the Module must be placed into the approved mode of operation (Initialized) through the following initialization procedure:
  11. Taking ownership of Opal by setting the AdminSP SID credential to something other than MSID (default password)
  12. Activating the LockingSP
  13. Setting the WriteLockEnabled and ReadLockEnabled column within the Locking Table of all ranges containing sensitive user data via the Lock, Unlock Ranges service.
  14. Power cycle the drive or set the WriteLock and ReadLock columns to True within the Locking Table of all ranges containing sensitive user data.
Page 14

Solidigm® P5316 SSD (ADP-R) Security Policy The CO role is responsible for configuration of other CO and user roles as well as enabling locking/unlocking of any of the CO role-controlled areas (locking ranges). The User roles are responsible for enabling locking/unlocking of the assigned locking ranges as well as performing locking/unlocking of their assigned locking range. In Approved mode (Initialized), the CO Role requires authentication and unlock prior to allowing access to data, whereas the uninitialized mode does not. The module will be in a non-compliant state if not initialized. To determine if a Module is in the Approved mode of operation (Initialized), the following must be verified:

  1. The LockingEnabled bit of the TCG Level 0 Discovery Locking Feature Descriptor is set to 1
  2. Minimally, the ReadLockEnabled column of the Locking Table is set to the True state for all ranges covering sensitive user data It is possible to switch from the Initialized state to an uninitialized state by performing the AdminSP Revert service. The module shall be initialized to be in an Approved mode of operation before any User accesses the Module and calls any services different than those described in this section’s instructions.
2.5 Rules of Module Operation

The Module design corresponds to the Module security rules. This section documents the security rules enforced by the cryptographic Module to implement the security requirements of this FIPS 140-3 Level 2 Module.

  1. The Module shall provide three distinct operator roles: Cryptographic Officer, User, and Maintenance.
  2. The Module shall provide role-based authentication.
  3. The Module shall clear previous authentications on power cycle.
  4. If an operator has not been successfully authenticated, no cryptographic services are available to the operator.
  5. The operator shall be capable of commanding the Module to perform the power-up self-tests by cycling power or resetting the Module.
  6. Power-up self-tests do not require any operator action.
  7. Control Input and Data output shall be inhibited during self-tests and error states.
  8. Data output shall be logically disconnected during key generation and zeroization.
  9. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module.
  10. There are no restrictions on which keys or CSPs are zeroized by the zeroization service.
  11. The Module does not support manual key entry.
  12. The Module does have external input/output devices used for entry/output of data.
  13. The Module does not output plaintext CSPs.
  14. The Module does not output intermediate key values.
Page 15

Solidigm® P5316 SSD (ADP-R) Security Policy

  1. The Module does not support a bypass capability service.
  2. The Module does not support the update of the logical serial number or vendor ID. The following section documents the security rules imposed by the vendor.
  3. The operator is capable of commanding the Module to perform the power-up Self-Tests by cycling power or resetting the Module.
  4. The shipping container protecting the module or set of modules in transit should be verified for tamper evidence.
  5. If the Module is shipped from the factory with the Approved firmware installed and uninitialized (TCG Opal is in a manufactured inactive state), the steps in section 2.4 will have to be followed.
  6. If the module is shipped with the Approved firmware not installed, seals will need to be applied as described in Section 7 and then the module must be initialized as described in Section 2.4.
  7. The module CSPs may be zeroized by calling the Revert method on the AdminSP in the Opal interface of the cryptographic Module.
  8. Successful execution of the challenge / response protocol zeroizes the module prior to allowing a Maintenance operation.
  9. The module shall be zeroized using the service: “Module Reset” and “Zeroize/Admin SP Revert” after performing a Maintenance operation. The operator shall follow the procedure contained in “Solidigm SSD_DC_D7-D4512 _Procedure_To_Exit_Maintenance_Mode.pdf” - Version 1.0 to exit the maintenance mode.
  10. The password length must be equal or greater to 8 bytes.
  11. The Module shall be initialized by the CO before any User access to the Module and calling any services different than those described in Section 2.4
Page 16
Physical portLogical interfaceData that passes over port/interface
PCIe ConnectorData inputNVMe interface used for both normal and maintenance operations
Data outputNVMe interface used for both normal and maintenance operations
Control inputNVMe interface used for both normal and maintenance operations, SMBus management interface, VDM interface, UART interface MUX for Debug accessed only during maintenance
Status outputNVMe interface used for both normal and maintenance operations, SMBus management interface, VDM interface, UART interface MUX for Debug accessed only during maintenance
Power interfacePower interface
UARTControl inputUART interface for Debug (available with latch removal in E1.L)
Status outputUART interface for Debug (available with latch removal in E1.L)
LED (E1.L only)Status outputSignals to illuminate module LED status

Solidigm® P5316 SSD (ADP-R) Security Policy 3. Cryptographic Module Interfaces The physical ports and logical interfaces4 are identified in Table 4 below: Table 5 – Ports and Interfaces The NVMe interface provides the primary interface to interact with the module. Most services provided by the module are accessed via the NVMe Interface including Opal configuration, reading and writing user data, retrieving capability support, and retrieving status reporting. The SMBus interface provides the ability to audit the SSD environment (temperature, Vital Product Data). Control output is not supported.

Page 17
RoleServiceInputOutput
Cryptographic Officer (CO)• Take Ownership • Data Encryption/Decryption • Activate Opal • Change Admin Password • Zeroise/AdminSP Revert • Disable Authorities • Configure Locking Ranges • Format NVM/ Crypto Erase • TCG RevertSP and Keep Data • Set data store • Configure Access Control • Lock, Unlock Ranges• TCG Opal commands tunneled over NVMe Security Send / Receive administrative commands • NVMe IO commands (Read, Write, etc.)• Status information and information regarding Opal configuration state • Status and user data

Solidigm® P5316 SSD (ADP-R) Security Policy 4. Roles, Services, and Authentication

4.1 Assumption of Roles

The Module supports three (3) distinct roles: Cryptographic Officer (CO), User, and Maintenance roles. The cryptographic Module enforces the separation of CO and User roles using a credential (named password or PIN) that is provisioned for the administrator (CO) role as part of taking ownership and personalization of the Opal security subsystem. The credential is verified as part of authentication as the specific role during session startup to the Opal Security Subsystem. Access control over configuration mechanisms under control of the administrator is enforced by the Module firmware. The Maintenance role is entered via authentication of an RSA 2048-bit challenge/response protocol with 512-bit nonce and PSID verification (to prove physical presence). This role grants maintenance and recovery capabilities to the Module implementer. The PSID is a unique identifier of each device and is classified as a non-CSP. A unique PSID value is printed on each device label and stored in the module’s OTP. No security is claimed from this value but is used solely to prove physical presence. It is feasible for the Module to process concurrent operations by roles. However, the Module can only support one Opal session at a time. This implies that authentication to the Module by various roles must be serialized. Once authenticated, various roles may interact with the Module simultaneously. As an example, the CO role may perform administrative tasks while the User role is simultaneously reading and writing data to the module.

Page 18
RoleServiceInputOutput
• Module Reset (Self- Test) • Low Power State Entry • Low Power State Exit • Read Compliance (show status) • Firmware Update • Block SID • MBR Shadow
Maintenance• FW Maintenance • Maintenance FW update • Firmware Update• Authentication credentials • Commands for retrieving debug logs • Device Recovery commands • Firmware download and commit commands• A 512-bit nonce which is used as part of the Authentication protocol Authentication results • Debug log pages • Command status

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 19
RoleServiceInputOutput
User (Opal LockingSP User Authority)• Data Encryption/Decryption • Configure Locking Ranges • Format NVM/ Crypto Erase • Set data store • Configure Access Control • Lock, unlock ranges • Set common name – Locking SP if allowed by Locking SP Admin • Module Reset (Self- test) • Low Power State Entry • Low Power State Exit • Read Compliance (show status) • Firmware Update • NVMe-MI Basic Management Command • NVMe Administration• Opal commands that the user has been authorized to perform by the CO role • NVMe IO commands (Read, Write, etc.)• Status information and information regarding Opal configuration state • Status and user data
RoleAuthentication MethodAuthentication Strength
Cryptographic OfficerRole-based: 8-byte to 32-byte password (AdminSP SID) A maximum of 5 for attempts are possible before requiring a power-on reset of the storage device• The probability of guessing a password/PIN in a single attempt is 1/2^64 (= 1/2^(8*8)) which is smaller than 1/10^6 • Since each reset takes approximately 2 seconds, 5 * 30 = 150 password attempts may be executed in one minute where the overall search space is 2^64 leaving a false acceptance probability in one minute of 150/2^64
MaintenanceRole-based: RSA 2048-bit challenge/response protocol w/ 512 bit nonce and PSID• The Maintenance role challenge response authentication mechanism leverages a 2048-bit signature verification

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 20
RoleAuthentication MethodAuthentication Strength
verification (to prove physical presence)The security strength of the authentication method is greater than 112 bits Therefore, the probability of a random attempt of generating a matching signed challenge is 1/2^112 which is smaller than 1/10^6 • The module can perform up to 1,500 authentication verifications per one minute where the overall search space is 2^112 leaving a false acceptance probability in one minute of 1,500/2^112 (= 2.88E-31)
UserRole-based: 8-byte to 32-byte password (User-Password) A maximum of 5 attempts are possible before requiring a power-on reset of the storage device• The probability of guessing a password/PIN in a single attempt is 1/2^64 (= 1/2^(8*8)) • Since each reset takes approximately 2 seconds, 5 * 30 = 150 password attempts may be executed in one minute where the overall search space is 2^64 leaving a false acceptance probability in one minute of 150/2^64

Solidigm® P5316 SSD (ADP-R) Security Policy Table 7 – Roles and Authentication

4.2 Services

All services implemented by the Module in Approved mode are listed in Table 7 below. Each service description also describes all usage of CSPs by the service. The service names highlighted in bold can be called in the uninitialized state. Note:

Page 21
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Take OwnershipObtain the default credential (SID = MSID) for the Opal and configure the Opal credential to a unique value (SID != MSID)PBKDF2AdminSP SID, SaltCOWCompliance descriptor and success return code
Data Encryption/Dec ryptionProtects access to the Media Encryption Keys stored in the Module in ciphertext form The cryptographic officer or user password is used to generate an intermediate key (Pkey) which is used to unwrap a Key Ring Encryption Key which is then used to unwrap the Media Key Encryption Key which is then used to unwrap the Media Encryption KeyAES-XTSMEKCO, UECompliance descriptor and success return code
Activate OpalEnable through TCG Opal Activate commandPBKDF2, AES-KW, AES-ECB, KBKDF, HMAC, SHSUser Password, User PKey, User KREK, MKEK, Opal Admin PKey, Opal Admin KREKCOG, ECompliance descriptor and success return code

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 22
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Change Admin PasswordChange any password in AdminSPPBKDF2Opal Admin PKeyCOG, ECompliance descriptor and success return code
Zeroise/Admin SP RevertDestroy user data (TCG Revert)DRBG, ENT, HMAC, SHSAll CSPsCOZCompliance descriptor and success return code
Disable AuthoritiesDisable authorities to make them invalid and no longer able to authenticate to the drivePBKDF2Opal Admin KREKCOECompliance descriptor and success return code
Enable AuthoritiesEnable authorities to make them valid for a user to be able to authenticate to the drivePBKDF2Opal Admin KREKCOECompliance descriptor and success return code
Configure Locking RangesConfigure locking ranges in the CMPBKDF2User KREKCO, U (if enabled by CO)GCompliance descriptor and success return code
Format NVM/ Crypto EraseDestroy any data (changing key)PBKDF2, DRBG, ENT, HMAC, SHS, CKG, AES- CTRMEK, MKEK, Device Root Key (Non- SSP), Ephemeral Blob Encryption Key (Non- SSP), DRBG- EI, DRBG- Seed, DRBG- StateCO, UG, ECompliance descriptor and success return code

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 23
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
TCG RevertSP and Keep DataRevert and keep data Reset all configuration data in the locking SP but do not destroy user data in the Global RangePBKDF2, AES-KW, AES- ECB, KBKDF, HMAC, SHSMKEK, User KREKCOZ, ECompliance descriptor and success return code
Set Data StoreSet data store – write data into the Opal data store tablesPBKDF2AdminSP SID, User PasswordCO, UECompliance descriptor and success return code
Configure Access ControlChange which entity can manage/lock/unlock an encryption rangePBKDF2AdminSP SID, User PasswordCO, U (if enabled by CO)ECompliance descriptor and success return code
Lock, Unlock RangesLock, unlock ranges from access to read/writes on the data input/output interfacePBKDF2AdminSP SID, User Password, User KREK, MKEKCO, UECompliance descriptor and success return code
Set Common Name – Locking SP (if allowed by Locking SP Admin)If the Locking SP Administrator allows, change the common name to reflect different text in the Locking SPN/AN/AUN/AN/A
FW MaintenanceRetrieve FW Maintenance Logs, recover device from non-functional stateRSASSA-PKCS1-v1.5, SHSRSA Public ADU Verification KeyMRECompliance descriptor and success return code

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 24
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Maintenance FW UpdateThe module allows the firmware to be updated through a vendor unique command in the event of a firmware failure This authentication mechanism is used to verify the firmware using RSASSA-PKCS1-v1.5 signature verification with SHA2-256 and the internal RSA Public FW Verification KeyRSASSA-PKCS1-v1.5, SHSRSA Public ADU Verification Key, RSA Public Firmware Verification KeyMRECompliance descriptor and success return code
Module Reset (Self-Test)Reset the Module by power cycle, or performing NVMe Controller or NVM Subsystem reset Performs self-tests, firmware integrity checkN/AN/ACO, UN/AN/A
Low Power State EntryPlace the module into a low power stateCKG [SP 800-133, rev2] AES KW [SP800-38F]REK MEKCO, UG, EThe module stops processing commands from the host
Low Power State ExitResume the module from the low power stateAES KW [SP800-38F]REK MEKCO, UEThe module resumes processing commands from the host

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 25
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Read Compliance (show status)Query the module for configuration information by reading the TCG defined Level 0 Feature Descriptor, the NVMe defined Identify command, and the T10 Compliance Descriptor as defined in [SFSC]. This service provides the module version information.N/AN/ACO, UN/AN/A
Firmware UpdateDownload new firmware images to the module using NVMe defined Firmware Download and Commit commandsRSASSA-PKCS1-v1.5, SHSRSA Public Firmware Verification KeyCO, U, MRECompliance descriptor and success return code
NVMe-MI Basic Management CommandRetrieves drive status (status flags, SMART warnings, temperature, VID, serial number, etc.)N/AN/AUN/AN/A
NVMe AdministrationIssue administrative commands (not previously mentioned) to the module, as defined in the NVMe specification This may include Vendor Unique public commands that are in compliance with the NVMe specificationN/AN/AUN/AN/A

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 26
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Block SIDAllows host pre-OS application to lock access to the SID authority by subsequently loaded host softwarePBKDF2AdminSP SIDCOECompliance descriptor and success return code
MBR ShadowRead/write Pre-Boot Application (PBA) to a reserved area of Module non-volatile memoryPBKDF2AdminSP SIDCOECompliance descriptor and success return code

Solidigm® P5316 SSD (ADP-R) Security Policy Table 8 – Approved Services The module does not implement any non-Approved services.

Page 27

Solidigm® P5316 SSD (ADP-R) Security Policy

  1. Software/Firmware Security The Module is designated as a limited operational environment under the FIPS 140-3 definitions and operates on the Sentinel Rock Plus B1 ASIC processor. The Module includes a firmware load service to support necessary field updates. The Module will not load or execute firmware which is not signed with the Solidigm 2048-bit RSA private key. The mechanisms available to perform a firmware load are the following:
  2. Through NVMe using NVMe Firmware Download and Commit operations
  3. Through NVMe, SMBUS or UART (after removing tamper evident label for E1.L) after entering the Maintenance role New firmware versions within the scope of this FIPS 140-3 validation must be validated through the CMVP. Any other firmware loaded into this Module is out of the scope of this validation and require a separate FIPS 140-3 validation. The module’s integrity test can be run on demand by power cycling the Module or by the Module Reset service.
Page 28

Solidigm® P5316 SSD (ADP-R) Security Policy 6. Operational Environment This section is not applicable to the module.

Page 29
Physical Security MechanismRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Three (3) tamper-evident labels affixed to the module’s back face (E1.L)12 monthsInspect the tamper-evident seals for scratches, gouges, cuts, and other signs of tamper. Remove from service if tampering is found.
One (1) tamper-evident label affixed to the module’s front (U.2)12 monthsInspect the tamper-evident seal for scratches, gouges, cuts, and other signs of tamper. Remove from service if tampering is found.
Production grade cases12 monthsInspect the entire perimeter for cracks, gouges, lack of enclosure, bent clips, and other signs of tamper. Remove from service if tampering is found.

Solidigm® P5316 SSD (ADP-R) Security Policy The following physical security measures are implemented in the module, which meet the requirements for a multi-chip embedded embodiment at Security Level 2: • The Module consists of production-grade components enclosed in an aluminum alloy enclosure, which is opaque within the visible spectrum. • The U.2 enclosure contains two parts: a top and bottom part that affix together using a hinge on the back side of the Module and two (2) screws that affix the top to the bottom near the PCIe edge connector. • The E1.L enclosure contains three parts: a top and a bottom part that affix together using eight (8) screws that affix the top and bottom together as well as a latch affixed with two (2) screws. the Module top and bottom are separated, exposing the internals of the Module, that the tamper-evident seal will be broken in the process. The position of the one (1) tamper-evident seal is indicated in Figure 1 and Figure

  1. The tamper-evident seals are captured as part of the model part number that is listed in Table 2. that if the Module top and bottom are separated, exposing internals of the Module, that the tamper-evident seals will be broken in the process. The position of the three (3) tamper-evident seals are indicated in Figure 3 and Figure
  2. The tamper evident seals are captured as part of the model number that is listed in Table
  3. The Cryptographic Officer is responsible for obtaining, storing, and applying new tamper-evident labels should the module require maintenance or repair upon inspection. The Crypto Officer can order new tamper evident seals using the part number M45818-002 (E1.L form factor) or M52551-001 (U.2 form factor).
Page 30

Solidigm® P5316 SSD (ADP-R) Security Policy Figure 7 - U.2 Module Seal Application Locations - Front Figure 8 - E1.L Module (Intel Branded) Seal Application Locations – Bottom

7.1 Applying Tamper-Evident Seals

Some modules may be shipped without the required tamper- evident seals. The tamper-evident seals shall be installed for the module to operate in Approved mode of operation. To convert the module to Approved mode of operation, the following procedure must be followed to apply the provided seals to the module:

  1. Clean seal surface a. Use isopropyl alcohol of equivalent solution to remove any contaminants from the enclosure seam seal location b. Handle drive and seal with gloves
  2. Locate the Tamper Evident Label Locations a. For U.2 Module: There is just one seal to be placed on the right front of the module (see Figure 7) b. For E1.L Module There are three seals to be placed on the bottom side of the module; one seal over the upper far right screw next to the PCIe connector, one seal over the lower third screw from the PCIe connector and one seal on the lower screw on the far left attaching the black latch (see Figure 9).
  3. Use tweezers to lift seal from liner and place on the seam of the enclosure for the designated area (see Figure below for an example on the U.2 Module).
  4. Apply finger pressure to seal pressing out any air or lifted edges
Page 31

Solidigm® P5316 SSD (ADP-R) Security Policy Figure 9 - Applying Tamper-Evident Seals EFP/EFT testing of the module is not applicable as the module does not claim Security Level 3 or above. 8. Non-invasive Security This section is not applicable to the module.

Page 32
Key/SSP Name/TypeStrengthSecurity Function and Cert. NumberGenerationImport/ ExportEstablishmentStorageZeroisationUse & related keys
DRBG-EI (CSP)256DRBG [SP 800- 90A, rev1] (#A2881)ENT (P) (Whenever encryption keys are derived by the module)N/AN/AVolatile memory (plaintext)Cleared automatically after key derivation operation completes or ResetDRBG entropy input used to derive the DRBG-Seed
DRBG-State (CSP)256DRBG [SP 800- 90A, rev1] (#A2881)DRBG (Whenever encryption keys are derived by the module)N/AN/AVolatile memory (plaintext)Cleared automatically after key derivation operation completes or ResetHMAC_DRBG internal state (V and Key) derived from the DRBG-Seed
DRBG-Seed (CSP)256DRBG [SP 800- 90A, rev1] (#A2881)DRBG (Whenever encryption keys are derived by the module)N/AN/AVolatile memory (plaintext)Cleared automatically after key derivation operation completes or ResetDRBG HMAC seed derived from the DRBG_EI
Opal Admin KREK (CSP)256AES KW [SP800-38F] (#A2881)KBKDF [SP 800-108, rev1] (At TCG Opal ActivationN/AN/AASIC internal memory (plaintext), NAND (encrypted with OpalAdminSP RevertOpal Admin Key Ring Encryption Key is used to protect/encrypt the Admin Locking Range Key Ring(s)

Solidigm® P5316 SSD (ADP-R) Security Policy 9. Sensitive Security Parameter Management

Page 33
Admin Pkey)
AdminSP SID (CSP)Varies, must be of minimum length of 8 bytes enforced by the modulePBKDF2 [SP 800-132] (#A2881)External to the module (By the CO role)Import: Plaintext (electroni cally) Export: N/AN/ATemporaril y in volatile memory (plaintext)Internally zeroized once the Admin has been authenticatedAdminSP SID (Password)is used to authenticate the CO and is used to derive the Opal Admin PKey
Opal Admin PKey (CSP)256AES KW [SP800-38F] (#A2881)PBKDF2 [SP 800-132] - Derived from admin password and salt (During Authenticati on)N/AN/AASIC internal volatile memory (plaintext)Internally zeroized once the Admin has been authenticatedAdmin password Key used to encrypt / decrypt Opal Admin KREK and is derived from the AdminSP SID
MEK (CSP)256AES XTS [SP800-38E] CKG [SP 800- 133, rev2] (#A2879)CKG [SP 800- 133, rev2]N/AN/AASIC internal volatile memory (plaintext), NAND (encrypted by MKEK)From ASIC internal memory during Power Cycle, Hard Reset, Maintenance Mode From NVM at Opal Activation and Crypto Erase commands, or issuance of NVMe FormatMedia Encryption Keys are used to protect user data when stored to non-volatile memory

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 34
NVM, Crypto Erase, or Sanitize commands
MKEK (CSP)256AES KW [SP800-38F] CKG [SP 800- 133, rev2] (#A2881)CKG [SP 800- 133, retv2]N/AN/AASIC internal volatile memory (plaintext), NAND (encrypted by User KREK)From ASIC internal memory during Power Cycle, Hard Reset, Maintenance Mode From NAND at TCG Opal Activation or ReactivateMedia Key Encryption Keys are used to protect Media Encryption Keys (MEKs)
User KREK (CSP)256AES KW [SP800-38F] (#A2881)KBKDF [SP 800-108, rev1] (During Opal Activation; During User Locking Range Creation)N/AN/AASIC internal volatile memory (plaintext), NAND (encrypted with User PKey)On AdminSP RevertUser Key Ring Encryption Key is used to protect the MKEK
User Password (CSP)Varies, must be of minimum length of 8 bytes enforced by the modulePBKDF2 [SP 800-132] (#A2881)Externally (By the User role)Import: Plaintext (electroni cally) Export: N/AN/ATemporaril y in volatile memory (plaintext)Internally zeroized once the User has been authenticatedOpal User password is used to authenticate the User and is used to derive the User PKey

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 35
User PKey (CSP)256AES KW [SP800-38F] (#A2881)PBKDF2 [SP 800-132] Derived from user password and salt (During Authenticati on)N/AN/AASIC internal volatile memory (plaintext)Power Cycle, Hard Reset, Maintenance ModeUser password Key used to encrypt / decrypt User KREK
Reset Ephemeral Key (REK) (CSP)256AES KW [SP800-38F] CKG [SP 800- 133, rev2] (#A2881)CKG [SP 800- 133, rev2] At Power on of the DeviceN/AN/AASIC internal volatile memory (plaintext)Power Cycle, Hard Reset, Maintenance ModeReset Ephemeral Key enables recovery of Media Encryption Keys across Low Power transitions
RSA Public Firmware Verification Key (PSP)112RSA Key Verification [FIPS 186-4 and PKCS #1 v2.1 (PKCS1.5)] (#A2880, #A2881)ExternalN/AN/ABurned into Hardware ROM (plaintext)N/A (Protected from modification and stored with an integrity value per IG 9.7.A)2048-bit RSA public Key used to verify the RSA Signature of the Module’s main firmware(on Boot and Firmware Download / Commit)
Salt (CSP)160PBKDF2 [SP 800-132] (#A2881)DRBG [SP 800-90A, rev1] Whenever symmetric encryption keys are generated by the moduleN/AN/AASIC internal volatile memory (plaintext), NAND (encrypted)On AdminSP RevertPBKDF2 Salt, 20-byte value
RSA Public ADU112RSA Signature Verification [FIPS 186-4 andExternal (Built intoImport: Plaintext inN/ABuilt into firmware binaryN/A (Protected2048-bit RSA public Key used to verify the signature

Solidigm® P5316 SSD (ADP-R) Security Policy

Page 36

Verification Key (PSP)

PKCS #1 v2.1 (PKCS1.5)] (#A2881)

firmware binary)

firmware image

from modification)

of the request to unlock the drive for diagnostic access

Entropy sourcesMinimum number of bits of entropyDetails
SP 800-90B compliant ENT (P)0.259 bits of min entropy per bit The DRBG is seeded with 2048 bits of random data providing approximately 530 bits of entropy.Physical noise source from the Broadcom TRNG used to seed the DRBG

Solidigm® P5316 SSD (ADP-R) Security Policy Table 10

Page 37

Pre-operational Software/Firmware Integrity Test

Description

Conditional Self-Tests Test Target

Description

Solidigm® P5316 SSD (ADP-R) Security Policy Each time the Module is powered up, it tests that the cryptographic algorithms operate correctly, and that sensitive data has not been damaged. Pre-operational and conditional cryptographic algorithm tests are available on demand by power cycling the Module or by the Module Reset service. On power-up or reset, the Module performs the Self-Tests described below. All Cryptographic Algorithm Self-Tests (CASTS) must be completed successfully prior to any other use of cryptography by the Module. If one of the CASTs fails, the Module enters an error state requiring reset of the Module. The module uses RSA 2048 with SHA2-256 to satisfy the pre-operational integrity self-test requirement. RSA Integrity Test Signature verification with RSA 2048 bit key and SHA2-256 (Cert. #A2880) AES-CTR (Cert. #A2881) CASTs: Encryption in CTR mode with 256 bit key KAT, Decryption in CTR mode with 256 bit key KAT AES-KW (Cert. #A2881) CASTs: Encryption in KW mode with 256 bit key KAT, Decryption in KW mode with 256 bit key KAT AES-XTS (Cert. #A2879) CASTs: Encryption in XTS mode with 256 bit key KAT, Decryption in XTS mode with 256 bit key KAT DRBG (Cert. #A2881) CASTs: HMAC DRBG (inclusive of instantiate, generate and reseed) PBKDF (Cert. #A2881) CASTs: Key Derivation Iterations: 10,000 KBKDF (Cert. #A2881) CASTs: HMAC-SHA2-256 Key Derivation KAT RSA (Cert. #A2881) CASTs: Signature Verification with 2048 bit key and SHA2-256

Page 38

Solidigm® P5316 SSD (ADP-R) Security Policy SP 800-90B Health NIST SP 800-90B ENT Health Tests, per SP 800-90B Section 4.5 Tests Firmware Load Test Firmware signature verification based on RSA PKCS#1 v1.5 with SHA2-256 and 2048-bit key. Key Equality Check When an XTS key is generated, the module verifies that Key1!=Key2 If a self-test fails, the Module will indicate the following information:

Page 39

Solidigm® P5316 SSD (ADP-R) Security Policy 11. Life-Cycle Assurance

11.1 Secure Distribution

The module is shipped using a certified mail carrier. The shipping container protecting the module or set of modules in transit should be verified for tamper evidence. The module is shipped in a shipping container with yellow tape. The tape should be sealing the container. Additionally, the module is contained within a clamshell with seals that should be inspected for tampering. If the shipping container or clamshell appears to be tampered with, the CO should contact Solidigm.

11.2 Secure Installation Procedure

On receipt of the Module, the CO should examine the product to ensure it has not been tampered with during shipping according to the procedures outlined in the Section 7. Upon verification that the Module has not been tampered with, the user should initialize the module as described in Section 2.4.

11.3 Module Start-up and Initialization Procedure

See instructions in section 2.4 for module start-up information.

Page 40

Solidigm® P5316 SSD (ADP-R) Security Policy 12. Mitigation of Other Attacks This module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3.

Page 41

Abbreviation

Full Specification Name

Acronym

Definition

Table, extracted as text (did not parse into structured rows)
Solidigm® P5316 SSD (ADP-R) Security Policy References and Definitions The following standards are referred to in this Security Policy. [ISO/IEC 19790]       Information technology - Security techniques - Security requirements for cryptographic modules, June 25, 2014 [SP800-140C]          CMVP Approved Security Functions [SP800-131Arev2]      Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths, March 2019 [TCG-OPAL]            Storage Work Group Storage Security Subsystem Class: Opal, Version 2.01 Final, Revision 1.00 [SFSC]                Information technology – Security Features for SCSI Commands (SFSC) ASCII                 American Standard Code for Information Interchange AES                   Advanced Encryption Standard CAST                  Cryptographic Algorithm Self-Test CBC                   Cipher Block Chain mode of AES encryption/decryption CO                    Cryptographic Officer CSP                   Critical Security Parameters DRBG                  Deterministic Random Bit Generator ECB                   Electronic Code Book mode of AES encryption/decryption KBKDF                 Key Based Key Derivation Function KDF                   Key Derivation Function MSID                  Manufactured SID, Public value that is used as default password NVMe                  Non-Volatile Memory express PBKDF                 Password Based Key Derivation Function PCIe                  Peripheral Component Interconnect express POST                  Power-On Self-Test PSID                  Physical SID, a public unique value for each drive RSA                   Rivest Shamir Adleman SHA                   Secure Hash Algorithm SHS                   Secure Hash Standard
Page 42

Acronym

Definition

Solidigm® P5316 SSD (ADP-R) Security Policy

SSDSolid State Drive
SIDSecure ID
TCGTrusted Computing Group
XTSXEX Tweakable Block Cipher with Ciphertext Stealing