| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Status | Active |
| Sunset date | 11/3/2029 |
| Caveat | None |
| Vendor | Samsung Electronics Co., Ltd. |
| Algorithm | ACVP Cert |
|---|---|
| AES-ECB | A1157 |
| AES-XTS | A1157 |
| Hash DRBG | A1153 |
| RSA SigVer (FIPS186-4) | A1155 |
| SHA2-256 | A1158 |
flowchart LR
%% Deterministic review-risk graph for Samsung NVMe TCG Opal SSC SEDs PM9A3 Series
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Show Status<br/>Status Output</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for Samsung NVMe TCG Opal SSC SEDs PM9A3 Series
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Show Status<br/>Status Output</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;Samsung NVMe TCG Opal SSC SEDs PM9A3 Series Document Version: 1.0 H/W Version: MZ1L2960HCJR-00AMV[1], MZ1L21T9HCLS-00AMV[1], MZ1L23T8HBLA-00AMV[1], MZCL21T9HCJR-00AMV[2], MZCL23T8HCLS-00AMV[2], MZCL27T6HBLA-00AMV[2] and MZEL215THBLA-00AMV[3] F/W Version: GDC76M4Q[1], GDC79M4Q[1], GDC62M4Q[2], GDC63M4Q[2], GDDB3M2Q[3], GDDB4M2Q[3]
| Version | Change | ||
|---|---|---|---|
| 1.0 | Initial Version |
Revision History Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| # | Section | Page |
|---|
| ISO/IEC 24759 Section 6. [Number Below] | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic module specification | 1 |
| 3 | Cryptographic module interfaces | 1 |
| 4 | Roles, services, and authentication | 1 |
| 5 | Software/Firmware security | 1 |
| 6 | Operational environment | 1 |
| 7 | Physical security | 1 |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle assurance | 1 |
| 12 | Mitigation of other attacks | N/A |
| Acronym | Description |
|---|---|
| CTRL | Controller |
| CPU | Central Processing Unit (ARM-based) |
| DRAM | Dynamic Random Access Memory |
| DRAM I/F | Dynamic Random Access Memory Interface |
| ECC | Error Correction Code |
| EDC | Error Detection Code |
| KAT | Known-answer Test |
| LBA | Logical Block Address |
| MEK | Media Encryption Key |
| PSID | Physical Presence SID (Security Identifier) |
| NAND | NAND Flash Memory |
| NAND I/F | NAND Flash Interface |
| NVMe | Non-Volatile Memory Host Controller Interface Specification |
| ROM | Read-Only Memory |
1.1. Scope This document outlines the security policy for Samsung Electronics Co., Ltd. Samsung NVMe TCG Opal SSC SEDs PM9A3 Series, herein after referred to as the “cryptographic module” or “module”, SSD (Solid State Drive). This module satisfies all applicable FIPS 140-3 Security Level 1 hardware cryptographic module requirements. It supports TCG Opal SSC based SED (Self-Encrypting Drive) features that is designed to protect unauthorized access to the user data stored in its NAND Flash memories. The cryptographic module’s controller has built-in AES hardware engines that provide on-the-fly encryption and decryption of the user data without performance loss. The SED design also allows for instant data sanitization via cryptographic erase. Table
Figure 3. Specification of the PM9A3 E1.L Form Factor Cryptographic Boundary Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Model | Hardware Version | Firmware Version | Distinguishing Features |
|---|---|---|---|
| PM9A3 | MZ1L2960HCJR-00AMV | GDC76M4Q GDC79M4Q | 960GB |
| MZ1L21T9HCLS-00AMV | 1.92TB | ||
| MZ1L23T8HBLA-00AMV | 3.84TB | ||
| MZCL21T9HCJR-00AMV | GDC62M4Q GDC63M4Q | 1.92TB | |
| MZCL23T8HCLS-00AMV | 3.84TB | ||
| MZCL27T6HBLA-00AMV | 7.68TB | ||
| MZEL215THBLA-00AMV | GDDB3M2Q GDDB4M2Q | 15.36TB |
2.2. Module Cryptographic Boundary The PM9A3 series utilizes a single-chip controller with an NVMe interface for system side communication and integrates Samsung NAND flash memory for internal storage. The following figure depicts the module’s operational environment. Figure
| CAVP Cert | Algorithm and Standard | Mode/ Method | Description/ Key Size(s)/ Key Strength(s) | Use/Function |
|---|---|---|---|---|
| A1157 | AES / FIPS 197, SP 800-38A | ECB | 256 bits | Prerequisite for AES-XTS (A1157) |
| A1157 | AES / FIPS 197, SP 800-38E | XTS1 | 256 bits | Data Encryption / Decryption |
| A1153 | DRBG / SP 800-90A Rev. 1 | Hash_ DRBG (SHA-256) | N/A | Deterministic Random Bit Generation |
| A1155 | RSA / FIPS 186-4 | SigVer | 3072 bits | Digital Signature Verification |
| A1158 | SHS / FIPS 180-4 | SHA-256 | N/A | Message Digest |
| Vendor Affirmed | CKG / SP 800-133 Rev. 2 | Section 4 and Section 6.1 | N/A | Cryptographic Key Generation (Symmetric keys which are direct unmodified outputs from the DRBG) |
| N/A | ENT (P) / SP 800-90B | N/A | N/A | Non-deterministic Random Number Generator (only used for generating seed materials for the DRBG). Provides a minimum of 256 bits of entropy for DRBG seed. |
| Algorithm | Caveat | Use / Function | |
|---|---|---|---|
| AES-XTS / FIPS 197, SP 800-38E | No Security Claimed; AES-XTS is only used for firmware decryption during ROM initialized. | Firmware Decryption | |
| AES-CCM / FIPS 197, SP 800-38C | No Security Claimed; Non-approved algorithms here are only used for encrypting or obfuscating the CSP. | Key Encryption and Decryption | |
| PBKDF2 | Key Derivation | ||
| HMAC / SHA-256 | Key Derivation |
2.4. Cryptographic Functionality The module does not implement any "Non-Approved Algorithms Not Allowed in the Approved Mode of Operation". The cryptographic module supports the following Approved algorithms for secure data storage: Note that not all algorithms/modes that appear on the module’s CAVP certificates are utilized by the module. Table 4 lists only the algorithms/modes that are utilized by the module. The following algorithms are not intended to be used as security functions, and not used whatsoever to meet any FIPS 140-3 requirements. These algorithms are not provided through a non-approved services to an operator. AES-ECB is the pre-requisite for AES-XTS; AES-ECB alone is NOT supported by the cryptographic module in approved mode. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Physical port | Logical interface | Data that passes over port/interface |
|---|---|---|
| NVMe Connector | Data Input / Output | Plaintext data; signed data; |
| Control Input | Commands input logically via an API; signals input logically or physically via one or more physical ports | |
| Status Output | Status information output logically via an API; signal outputs logically or physically via one or more physical ports | |
| JTAG | Control Input | Signals input logically or physically via one or more physical ports |
| Status Output | Signal outputs logically or physically via one or more physical ports |
The module always defaults to an Approved mode of operation. To ensure it remains in this mode, operators must strictly follow the guidance outlined in section
| Role | Service | Input | Output | |
|---|---|---|---|---|
| Cryptographic Officer (CO) | Show Status | N/A | Status | |
| Lock/Unlock an LBA Range | LBA Range | Status | ||
| Erase an LBA Range’s Data | LBA Range | Status | ||
| Update the firmware | FW image binary | Status | ||
| Get Random Number | N/A | Status | ||
| IO Command | LBA | Status | ||
| FormatNVM / Sanitize / DeleteNS | LBA Range | Status | ||
| Revert | PSID | N/A | ||
| Maintenance2 | Diagnostics | N/A | N/A |
| Service | Description | Approved Security Functions | Keys and/or SSPs | Roles | Access rights to Keys and SSPs | Indicator3 | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| E | W | G | Z | |||||||||
| Show Status | Show approved version status of the module / FIPS fail mode | N/A | N/A | Cryptographic Officer (CO) | NVM Command: Identify Controller command Result : Status Code | |||||||
| Lock/Unlock an LBA Range | Block or allow read (decrypt) / write (encrypt) of user data. | N/A | MEK4 | O | O | UID: Locking_GlobalRange / Locking_RangeNNNN TCG Method: Set Result: TCG status code | ||||||
| Erase an LBA Range’s Data | Erase user data by changing the data encryption key. | Hash_ DRBG (SHA-256) CKG ENT (P) | DRBG Internal State V value | O | O | UID: K_AES_256_GlobalRange _Key / K_AES_256_RangeNNNN _Key TCG Method: GenKey Result: TCG status code | ||||||
| DRBG Internal State C value | O | O | ||||||||||
| DRBG Seed | O | O | ||||||||||
| DRBG Entropy Input String | O | O | ||||||||||
| MEK | O | O | O | |||||||||
| Revert | Erase user data in all Range by | Hash_ DRBG (SHA-256) | DRBG Internal State V value | O | O | UID: SPObj(AdminSP) TCG Method: Revert |
4. Roles, Services, and Authentication The module does not support role authentication. Roles are implicitly assumed based on the service they are invoking. 4.2. Approved Services The cryptographic module does not offer bypass capabilities. E: EXECUTE; W: WRITE; G: GENERATE; Z: ZEROISE E W G Z
2 Maintenance role is operator that is responsible for using the JTAG
Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| changing the data encryption key, initialize range settings, and reset PINs for TCG. | CKG ENT (P) | DRBG Internal State C value DRBG Seed DRBG Entropy Input String | O O O | O O O | Result: TCG status code | ||
|---|---|---|---|---|---|---|---|
| MEK | O | ||||||
| Update the firmware | Update the firmware | RSA | FW Verification Key | O | Admin Command: Firmware Commit Result : Status Code | ||
| Get Random Number | Provide a random number generated by the CM. | Hash_ DRBG (SHA-256) CKG ENT (P) | DRBG Internal State V value | O | O | UID: ThisSP TCG Method: Random Result: TCG status code | |
| DRBG Internal State C value | O | O | |||||
| DRBG Seed | O | O | |||||
| DRBG Entropy Input String | O | O | |||||
| IO Command | Read/Write user data | AES-XTS | MEK | O | NVM Command: Write / Read Result : Status Code | ||
| FormatNVM / Sanitize / DeleteNS | Erase user data by changing the data encryption key. | Hash_ DRBG (SHA-256) CKG ENT (P) | DRBG Internal State V value | O | O | Admin Command: Format NVM / Sanitize / Namespace Management Result : Status Code | |
| DRBG Internal State C value | O | O | |||||
| DRBG Seed | O | O | |||||
| DRBG Entropy Input String | O | O | |||||
| MEK | O | ||||||
| Diagnostics | Perform Maintenance | N/A | N/A | Maintenance | N/A |
O O Table 8. Approved Services Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
5. Software/Firmware Security - The cryptographic module employs a 428-byte error detection code for firmware integrity testing, which is performed during power-on reset. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
6. Operational Environment - The cryptographic module operates in a limited operational environment, consisting of the module’s firmware. This limited operational setting does not require any specific security rules, settings/configurations, or restrictions to be set. - The cryptographic module does not provide any general-purpose operating system to the operator. - Firmware download is only available for CMVP validated firmware versions. Unauthorized modification of the firmware is prevented by the pre-operational firmware integrity test and conditional firmware load test. - Since the cryptographic module is zeroised through the procedure for using maintenance role, it is restricted preventing uncontrolled access to CSPs and uncontrolled modifications of SSPs. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Physical Security Mechanisms | Recommended Frequency of Inspection/Test | Inspection/Test Guidance Details |
|---|---|---|
| Production grade components | N/A | N/A |
The following physical security mechanisms are implemented in the cryptographic module: The following table summarizes the actions required by the Cryptographic Officer Role to ensure that physical security is maintained: N/A N/A The cryptographic module supports the Maintenance role. To assume the Maintenance role, operators must comply with the following rule:
8. Non-Invasive Security - The module does not implement any non-invasive attack mitigation techniques. Therefore, this section is not applicable. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Establishment | Import / Export | Storage | Zeroisation | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| DRBG Internal State V value | 440-bit | Hash_ DRBG (SHA- 256) / A1153 | SP 800-90A HASH_DRBG (SHA-256) | N/A | N/A | Plaintext in RAM | Implicitly zeroised by Power on reset | MEK |
| DRBG Internal State C value | 440-bit | Hash_ DRBG (SHA- 256) / A1153 | SP 800-90A HASH_DRBG (SHA-256) | N/A | N/A | Plaintext in RAM | Implicitly zeroised by Power on reset | MEK |
| DRBG Seed | N/A | Hash_ DRBG (SHA- 256) / A1153 | ENT (P) | N/A | N/A | Plaintext in RAM | Implicitly zeroised by Power on reset | MEK |
| DRBG Entropy Input String | N/A | Hash_ DRBG (SHA- 256) / A1153 | ENT (P) | N/A | N/A | Plaintext in RAM | Implicitly zeroised by Power on reset | MEK |
| MEK | 256-bit | AES-XTS / A1157 | SP 800-90A HASH_DRBG (SHA-256) | N/A | N/A | Plaintext in RAM | Implicitly zeroised by Power on reset / Explicitly zeroised via “Unlock an LBA Range” service and indicate with its indicator | Data encryption and decryption of user data |
| Plaintext in Flash | Explicitly zeroised via “Erase an LBA Range’s Data”, “Revert” and “FormatNV M / Sanitize / |
9. Sensitive Security Parameter Management - Temporary SSPs and SSPs stored in volatile memory are automatically zeroized upon power-on reset. - The module performs zeroization by overwriting the target SSP with random values generated by the DRBG. - The module does not import or export SSPs. M/ Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| DeleteNS” services and indicate with their indicators | |||||||
|---|---|---|---|---|---|---|---|
| Firmware Verificati on Key5 | 128-bit | RSA / A1155 | Generated during the manufacturing process, is included as part of the FW. | N/A | Plaintext in HW SFR6 | Implicitly zeroised by Power on reset and after completion of “Update the firmware” service | Firmware Load Test |
| Entropy sources | Minimum number of bits of entropy | Details | |
|---|---|---|---|
| ENT (P) | 0.5 entropy per bit7 | Entropy source for Hash_DRBG |
Table
6 HW SFR (Special Function Register) is a register within a hardware cryptographic algorithm IP, which has characteristic of volatile memory.
7 Estimated amount of entropy per the source’s output bit is 0.841621 and Samsung conservatively claims to be set at 0.5 per bit.
Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Algorithm | Type | Description |
|---|---|---|
| EDC | Firmware integrity test | Firmware integrity test is performed by using 428 byte error correction code (ECC) at power-on. |
| Algorithm | Type | Description |
|---|---|---|
| AES | Critical function test | Duplicate Key Test for AES-XTS described in FIPS 140-3 IG C.I (i.e. key_1 ≠ key_2) when key is generated |
| AES | Cryptographic algorithm self-test | KAT: AES-256 XTS mode encryption and decryption |
| AES | Cryptographic algorithm self-test | KAT: AES-256 ECB mode encryption and decryption |
| SHS | Cryptographic algorithm self-test | KAT: SHA-256 hash digest |
| RSA | Cryptographic algorithm self-test | KAT: RSA-3072 verification is performed before firmware load test |
| RSA | Firmware load test | RSA-3072 with SHA-256 signature verification is performed if new FW is downloaded. |
| DRBG | Cryptographic algorithm self-test | KATs: HASH-DRBG(SHA2-256), SP 800-90A Health testing on Instantiate, Generate and Reseed functions |
| ENT (P) | Cryptographic algorithm self-test | Startup and Conditional SP800-90B Heath tests: Repetition count test, Adaptive proportion test |
All cryptographic algorithm self-tests are executed during power-on. While executing the following self-tests, all data output is inhibited until the self-test completes. To execute the pre-operational tests on-demand, the operator may power-cycle the module. Cryptographic algorithm self-tests are performed prior to the approved algorithms’ first use. If a cryptographic module fails a self-test, the module will enter an error state. While in this state, all data output is inhibited. 10.1. Pre-Operational Test Table 12. Pre-operational Self-tests The cryptographic module enters the error state upon failure of Self-tests. All commands from the Host (General Purpose Computer (GPC) outside the cryptographic boundary) are rejected in the error state and the cryptographic module returns an FIPS Fail Mode (SC=0x6, SCT=0x0) defined in NVMe specification via the status output. Cryptographic services and data output are explicitly inhibited when in the error state. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
11. Life-Cycle Assurance The cryptographic module operates in the Approved mode of operation by default once shipped from the vendor’s manufacturing site and does not support a non-approved mode of operation. The following guidance in section 11.1 describes the rules for secure installation and operation which the operator shall follow to operate the cryptographic module in a FIPS 140-3 security level 1 compliant manner. 11.1. Secure Installation
12. Mitigation of Other Attacks The cryptographic module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy