All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Samsung NVMe TCG Opal SSC SEDs PM9A3 Series

Certificate#4864StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorSamsung Electronics Co., Ltd.
Medium review priority  ·  no TCB surface named  ·  last validated 20 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date11/3/2029
CaveatNone
VendorSamsung Electronics Co., Ltd.

Approved Algorithms (5)

AlgorithmACVP Cert
AES-ECBA1157
AES-XTSA1157
Hash DRBGA1153
RSA SigVer (FIPS186-4)A1155
SHA2-256A1158

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Samsung NVMe TCG Opal SSC SEDs PM9A3 Series
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Show Status<br/>Status Output</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Samsung NVMe TCG Opal SSC SEDs PM9A3 Series
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Show Status<br/>Status Output</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Samsung NVMe TCG Opal SSC SEDs PM9A3 Series Document Version: 1.0 H/W Version: MZ1L2960HCJR-00AMV[1], MZ1L21T9HCLS-00AMV[1], MZ1L23T8HBLA-00AMV[1], MZCL21T9HCJR-00AMV[2], MZCL23T8HCLS-00AMV[2], MZCL27T6HBLA-00AMV[2] and MZEL215THBLA-00AMV[3] F/W Version: GDC76M4Q[1], GDC79M4Q[1], GDC62M4Q[2], GDC63M4Q[2], GDDB3M2Q[3], GDDB4M2Q[3]

Page 2
VersionChange
1.0Initial Version

Revision History Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 3
Table of Contents
#SectionPage
Page 4
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
AcronymDescription
CTRLController
CPUCentral Processing Unit (ARM-based)
DRAMDynamic Random Access Memory
DRAM I/FDynamic Random Access Memory Interface
ECCError Correction Code
EDCError Detection Code
KATKnown-answer Test
LBALogical Block Address
MEKMedia Encryption Key
PSIDPhysical Presence SID (Security Identifier)
NANDNAND Flash Memory
NAND I/FNAND Flash Interface
NVMeNon-Volatile Memory Host Controller Interface Specification
ROMRead-Only Memory

1.1. Scope This document outlines the security policy for Samsung Electronics Co., Ltd. Samsung NVMe TCG Opal SSC SEDs PM9A3 Series, herein after referred to as the “cryptographic module” or “module”, SSD (Solid State Drive). This module satisfies all applicable FIPS 140-3 Security Level 1 hardware cryptographic module requirements. It supports TCG Opal SSC based SED (Self-Encrypting Drive) features that is designed to protect unauthorized access to the user data stored in its NAND Flash memories. The cryptographic module’s controller has built-in AES hardware engines that provide on-the-fly encryption and decryption of the user data without performance loss. The SED design also allows for instant data sanitization via cryptographic erase. Table

  1. Security Levels 1.2. Acronyms Table
  2. Acronyms Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 5
  1. Cryptographic Module Specification 2.1. Hardware and Physical Cryptographic Boundary This firmware version, within the scope of this validation, must undergo validation through the FIPS 140-3 CMVP. Any other firmware loaded into this module is beyond the scope of this validation and requires a separate FIPS 140-3 validation. Below are photographs showing the cryptographic module views of each form factor. The multiple-chip embedded cryptographic module includes both hardware and firmware components. The cryptographic boundary of the M.2 module is defined as the physical perimeter of the PCB. Figure
  2. Specification of the PM9A3 M.2 Form Factor Cryptographic Boundary The E1.S and E1.L cryptographic modules are each enclosed in two aluminum alloy cases. These cases define the modules’ cryptographic boundary. Figure
  3. Specification of the PM9A3 E1.S Form Factor Cryptographic Boundary Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 6

Figure 3. Specification of the PM9A3 E1.L Form Factor Cryptographic Boundary Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 7
ModelHardware VersionFirmware VersionDistinguishing Features
PM9A3MZ1L2960HCJR-00AMVGDC76M4Q GDC79M4Q960GB
MZ1L21T9HCLS-00AMV1.92TB
MZ1L23T8HBLA-00AMV3.84TB
MZCL21T9HCJR-00AMVGDC62M4Q GDC63M4Q1.92TB
MZCL23T8HCLS-00AMV3.84TB
MZCL27T6HBLA-00AMV7.68TB
MZEL215THBLA-00AMVGDDB3M2Q GDDB4M2Q15.36TB

2.2. Module Cryptographic Boundary The PM9A3 series utilizes a single-chip controller with an NVMe interface for system side communication and integrates Samsung NAND flash memory for internal storage. The following figure depicts the module’s operational environment. Figure

  1. Block Diagram for Samsung NVMe TCG Opal SSC SEDs PM9A3 Series 2.3. Version information Table
  2. Cryptographic Module Tested Configuration Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 8
CAVP CertAlgorithm and StandardMode/ MethodDescription/ Key Size(s)/ Key Strength(s)Use/Function
A1157AES / FIPS 197, SP 800-38AECB256 bitsPrerequisite for AES-XTS (A1157)
A1157AES / FIPS 197, SP 800-38EXTS1256 bitsData Encryption / Decryption
A1153DRBG / SP 800-90A Rev. 1Hash_ DRBG (SHA-256)N/ADeterministic Random Bit Generation
A1155RSA / FIPS 186-4SigVer3072 bitsDigital Signature Verification
A1158SHS / FIPS 180-4SHA-256N/AMessage Digest
Vendor AffirmedCKG / SP 800-133 Rev. 2Section 4 and Section 6.1N/ACryptographic Key Generation (Symmetric keys which are direct unmodified outputs from the DRBG)
N/AENT (P) / SP 800-90BN/AN/ANon-deterministic Random Number Generator (only used for generating seed materials for the DRBG). Provides a minimum of 256 bits of entropy for DRBG seed.
AlgorithmCaveatUse / Function
AES-XTS / FIPS 197, SP 800-38ENo Security Claimed; AES-XTS is only used for firmware decryption during ROM initialized.Firmware Decryption
AES-CCM / FIPS 197, SP 800-38CNo Security Claimed; Non-approved algorithms here are only used for encrypting or obfuscating the CSP.Key Encryption and Decryption
PBKDF2Key Derivation
HMAC / SHA-256Key Derivation

2.4. Cryptographic Functionality The module does not implement any "Non-Approved Algorithms Not Allowed in the Approved Mode of Operation". The cryptographic module supports the following Approved algorithms for secure data storage: Note that not all algorithms/modes that appear on the module’s CAVP certificates are utilized by the module. Table 4 lists only the algorithms/modes that are utilized by the module. The following algorithms are not intended to be used as security functions, and not used whatsoever to meet any FIPS 140-3 requirements. These algorithms are not provided through a non-approved services to an operator. AES-ECB is the pre-requisite for AES-XTS; AES-ECB alone is NOT supported by the cryptographic module in approved mode. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 9
Physical portLogical interfaceData that passes over port/interface
NVMe ConnectorData Input / OutputPlaintext data; signed data;
Control InputCommands input logically via an API; signals input logically or physically via one or more physical ports
Status OutputStatus information output logically via an API; signal outputs logically or physically via one or more physical ports
JTAGControl InputSignals input logically or physically via one or more physical ports
Status OutputSignal outputs logically or physically via one or more physical ports

The module always defaults to an Approved mode of operation. To ensure it remains in this mode, operators must strictly follow the guidance outlined in section

  1. The user can verify the module's Approved status using the “Show Status” Service in Table 7 via the NVM Express Identify Controller command.
  2. Cryptographic Module Interfaces The module doesn’t support a Control output interface. Table
  3. Ports and Interfaces Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 10
RoleServiceInputOutput
Cryptographic Officer (CO)Show StatusN/AStatus
Lock/Unlock an LBA RangeLBA RangeStatus
Erase an LBA Range’s DataLBA RangeStatus
Update the firmwareFW image binaryStatus
Get Random NumberN/AStatus
IO CommandLBAStatus
FormatNVM / Sanitize / DeleteNSLBA RangeStatus
RevertPSIDN/A
Maintenance2DiagnosticsN/AN/A
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and SSPsIndicator3
EWGZ
Show StatusShow approved version status of the module / FIPS fail modeN/AN/ACryptographic Officer (CO)NVM Command: Identify Controller command Result : Status Code
Lock/Unlock an LBA RangeBlock or allow read (decrypt) / write (encrypt) of user data.N/AMEK4OOUID: Locking_GlobalRange / Locking_RangeNNNN TCG Method: Set Result: TCG status code
Erase an LBA Range’s DataErase user data by changing the data encryption key.Hash_ DRBG (SHA-256) CKG ENT (P)DRBG Internal State V valueOOUID: K_AES_256_GlobalRange _Key / K_AES_256_RangeNNNN _Key TCG Method: GenKey Result: TCG status code
DRBG Internal State C valueOO
DRBG SeedOO
DRBG Entropy Input StringOO
MEKOOO
RevertErase user data in all Range byHash_ DRBG (SHA-256)DRBG Internal State V valueOOUID: SPObj(AdminSP) TCG Method: Revert

4. Roles, Services, and Authentication The module does not support role authentication. Roles are implicitly assumed based on the service they are invoking. 4.2. Approved Services The cryptographic module does not offer bypass capabilities. E: EXECUTE; W: WRITE; G: GENERATE; Z: ZEROISE E W G Z

2 Maintenance role is operator that is responsible for using the JTAG

3 The result of NVMe or TCG command is used as an indicator

Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 11
changing the data encryption key, initialize range settings, and reset PINs for TCG.CKG ENT (P)DRBG Internal State C value DRBG Seed DRBG Entropy Input StringO O OO O OResult: TCG status code
MEKO
Update the firmwareUpdate the firmwareRSAFW Verification KeyOAdmin Command: Firmware Commit Result : Status Code
Get Random NumberProvide a random number generated by the CM.Hash_ DRBG (SHA-256) CKG ENT (P)DRBG Internal State V valueOOUID: ThisSP TCG Method: Random Result: TCG status code
DRBG Internal State C valueOO
DRBG SeedOO
DRBG Entropy Input StringOO
IO CommandRead/Write user dataAES-XTSMEKONVM Command: Write / Read Result : Status Code
FormatNVM / Sanitize / DeleteNSErase user data by changing the data encryption key.Hash_ DRBG (SHA-256) CKG ENT (P)DRBG Internal State V valueOOAdmin Command: Format NVM / Sanitize / Namespace Management Result : Status Code
DRBG Internal State C valueOO
DRBG SeedOO
DRBG Entropy Input StringOO
MEKO
DiagnosticsPerform MaintenanceN/AN/AMaintenanceN/A

O O Table 8. Approved Services Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 12

5. Software/Firmware Security - The cryptographic module employs a 428-byte error detection code for firmware integrity testing, which is performed during power-on reset. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 13

6. Operational Environment - The cryptographic module operates in a limited operational environment, consisting of the module’s firmware. This limited operational setting does not require any specific security rules, settings/configurations, or restrictions to be set. - The cryptographic module does not provide any general-purpose operating system to the operator. - Firmware download is only available for CMVP validated firmware versions. Unauthorized modification of the firmware is prevented by the pre-operational firmware integrity test and conditional firmware load test. - Since the cryptographic module is zeroised through the procedure for using maintenance role, it is restricted preventing uncontrolled access to CSPs and uncontrolled modifications of SSPs. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 14
Physical Security MechanismsRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Production grade componentsN/AN/A

The following physical security mechanisms are implemented in the cryptographic module: The following table summarizes the actions required by the Cryptographic Officer Role to ensure that physical security is maintained: N/A N/A The cryptographic module supports the Maintenance role. To assume the Maintenance role, operators must comply with the following rule:

Page 15

8. Non-Invasive Security - The module does not implement any non-invasive attack mitigation techniques. Therefore, this section is not applicable. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 16
Key / SSP Name / TypeStrengthSecurity Function and Cert. NumberGenerationEstablishmentImport / ExportStorageZeroisationUse & related keys
DRBG Internal State V value440-bitHash_ DRBG (SHA- 256) / A1153SP 800-90A HASH_DRBG (SHA-256)N/AN/APlaintext in RAMImplicitly zeroised by Power on resetMEK
DRBG Internal State C value440-bitHash_ DRBG (SHA- 256) / A1153SP 800-90A HASH_DRBG (SHA-256)N/AN/APlaintext in RAMImplicitly zeroised by Power on resetMEK
DRBG SeedN/AHash_ DRBG (SHA- 256) / A1153ENT (P)N/AN/APlaintext in RAMImplicitly zeroised by Power on resetMEK
DRBG Entropy Input StringN/AHash_ DRBG (SHA- 256) / A1153ENT (P)N/AN/APlaintext in RAMImplicitly zeroised by Power on resetMEK
MEK256-bitAES-XTS / A1157SP 800-90A HASH_DRBG (SHA-256)N/AN/APlaintext in RAMImplicitly zeroised by Power on reset / Explicitly zeroised via “Unlock an LBA Range” service and indicate with its indicatorData encryption and decryption of user data
Plaintext in FlashExplicitly zeroised via “Erase an LBA Range’s Data”, “Revert” and “FormatNV M / Sanitize /

9. Sensitive Security Parameter Management - Temporary SSPs and SSPs stored in volatile memory are automatically zeroized upon power-on reset. - The module performs zeroization by overwriting the target SSP with random values generated by the DRBG. - The module does not import or export SSPs. M/ Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 17
DeleteNS” services and indicate with their indicators
Firmware Verificati on Key5128-bitRSA / A1155Generated during the manufacturing process, is included as part of the FW.N/APlaintext in HW SFR6Implicitly zeroised by Power on reset and after completion of “Update the firmware” serviceFirmware Load Test
Entropy sourcesMinimum number of bits of entropyDetails
ENT (P)0.5 entropy per bit7Entropy source for Hash_DRBG

Table

  1. SSPs - The module contains an entropy source, compliant with SP 800-90B, within the module’s cryptographic boundary. Table
  2. Non-Deterministic Random Number Generation Specification
5 This is not considered an SSP.

6 HW SFR (Special Function Register) is a register within a hardware cryptographic algorithm IP, which has characteristic of volatile memory.

7 Estimated amount of entropy per the source’s output bit is 0.841621 and Samsung conservatively claims to be set at 0.5 per bit.

Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 18
AlgorithmTypeDescription
EDCFirmware integrity testFirmware integrity test is performed by using 428 byte error correction code (ECC) at power-on.
AlgorithmTypeDescription
AESCritical function testDuplicate Key Test for AES-XTS described in FIPS 140-3 IG C.I (i.e. key_1 ≠ key_2) when key is generated
AESCryptographic algorithm self-testKAT: AES-256 XTS mode encryption and decryption
AESCryptographic algorithm self-testKAT: AES-256 ECB mode encryption and decryption
SHSCryptographic algorithm self-testKAT: SHA-256 hash digest
RSACryptographic algorithm self-testKAT: RSA-3072 verification is performed before firmware load test
RSAFirmware load testRSA-3072 with SHA-256 signature verification is performed if new FW is downloaded.
DRBGCryptographic algorithm self-testKATs: HASH-DRBG(SHA2-256), SP 800-90A Health testing on Instantiate, Generate and Reseed functions
ENT (P)Cryptographic algorithm self-testStartup and Conditional SP800-90B Heath tests: Repetition count test, Adaptive proportion test

All cryptographic algorithm self-tests are executed during power-on. While executing the following self-tests, all data output is inhibited until the self-test completes. To execute the pre-operational tests on-demand, the operator may power-cycle the module. Cryptographic algorithm self-tests are performed prior to the approved algorithms’ first use. If a cryptographic module fails a self-test, the module will enter an error state. While in this state, all data output is inhibited. 10.1. Pre-Operational Test Table 12. Pre-operational Self-tests The cryptographic module enters the error state upon failure of Self-tests. All commands from the Host (General Purpose Computer (GPC) outside the cryptographic boundary) are rejected in the error state and the cryptographic module returns an FIPS Fail Mode (SC=0x6, SCT=0x0) defined in NVMe specification via the status output. Cryptographic services and data output are explicitly inhibited when in the error state. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 19

11. Life-Cycle Assurance The cryptographic module operates in the Approved mode of operation by default once shipped from the vendor’s manufacturing site and does not support a non-approved mode of operation. The following guidance in section 11.1 describes the rules for secure installation and operation which the operator shall follow to operate the cryptographic module in a FIPS 140-3 security level 1 compliant manner. 11.1. Secure Installation

Page 20

12. Mitigation of Other Attacks The cryptographic module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy