| Standard | FIPS 140-3 |
|---|---|
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 11/13/2026 |
| Caveat | Interim Validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. The tamper evident seals installed as indicated in the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service |
| Vendor | Samsung Electronics Co., Ltd. |
flowchart LR
%% Deterministic review-risk graph for Samsung NVMe TCG Opal SSC SEDs PM1743/PM1745 Series
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Show Status<br/>Status Output<br/>unauthenticated</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for Samsung NVMe TCG Opal SSC SEDs PM1743/PM1745 Series
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Show Status<br/>Status Output<br/>unauthenticated</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;Samsung NVMe TCG Opal SSC SEDs PM1743/PM1745 Series Document Version: 1.1 H/W Version: MZWLO1T9HCJR-00AD9 [1, 4], MZWLO3T8HCLS-00AD9 [1, 4], MZWLO7T6HBLA-00AD9 [1, 4], MZWLO15THBLA-00AD9 [1, 4], MZWLO1T6HCJR-00AD9 [1, 4], MZWLO3T2HCLS-00AD9 [1, 4], MZWLO6T4HBLA-00AD9 [1, 4], MZWLO12THBLA-00AD9 [1, 4], MZWLO1T9HCJR-00AH9 [2], MZWLO3T8HCLS-00AH9 [2], MZWLO7T6HBLA-00AH9 [2], MZWLO15THBLA-00AH9 [2], MZWLO1T9HCJR-00AH8 [3], MZWLO3T8HCLS-00AH8 [3], MZWLO7T6HBLA-00AH8 [3], MZWLO15THBLA-00AH8 [3] F/W Version: OPP90D5Q [1], 3P00 [2], 3R00 [3], 3.1.0 [4]
| Version | Change |
|---|---|
| 1.0 | Initial Version |
| 1.1 | NSRL Revalidation |
Revision History Samsung Electronics Co., Ltd.
2 / 22
| # | Section | Page |
|---|
| ISO/IEC 24759 Section 6. [Number Below] | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 2 |
| 2 | Cryptographic module specification | 2 |
| 3 | Cryptographic module interfaces | 2 |
| 4 | Roles, services, and authentication | 2 |
| 5 | Software/Firmware security | 2 |
| 6 | Operational environment | N/A |
| 7 | Physical security | 2 |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 2 |
| 10 | Self-tests | 2 |
| 11 | Life-cycle assurance | 2 |
| 12 | Mitigation of other attacks | N/A |
| Acronym | Description |
|---|---|
| CPU | Central Processing Unit (ARM-based) |
| CTRL | Controller |
| DRAM I/F | Dynamic Random Access Memory Interface |
| LBA | Logical Block Address |
| MEK | Media Encryption Key |
| NAND I/F | NAND Flash Interface |
| PMIC | Power Management Integrated Circuit |
| ROM | Read Only Memory |
| NVMe | Non-Volatile Memory Host Controller Interface Specification |
| SED | Self-Encrypting Drive |
| SSC | Security Subsystem Class |
| SSP | Sensitive Security Parameter |
| TCG | Trusted Computing Group |
1.1. Scope hereinafter referred to as a “cryptographic module” or “module”. The SSD (Solid State Drive) satisfies all applicable FIPS features. It is designed to protect unauthorized access to the user data stored in its NAND Flash memories. The built-in AES hardware engines in the cryptographic module’s controller provide on-the-fly encryption and decryption of the user data without performance loss. The SED’s nature also provides instantaneous sanitization of the user data via cryptographic erase. Table
4 / 22
5 / 22
| Model | Hardware [Part Number and Version] | Firmware Version | Distinguishing Features |
|---|---|---|---|
| PM1743 | MZWLO1T9HCJR-00AH9 | 3P00 | 1.92TB |
| MZWLO3T8HCLS-00AH9 | 3.84TB | ||
| MZWLO7T6HBLA-00AH9 | 7.68TB | ||
| MZWLO15THBLA-00AH9 | 15.36TB | ||
| MZWLO1T9HCJR-00AH8 | 3R00 | 1.92TB | |
| MZWLO3T8HCLS-00AH8 | 3.84TB | ||
| MZWLO7T6HBLA-00AH8 | 7.68TB | ||
| MZWLO15THBLA-00AH8 | 15.36TB | ||
| MZWLO1T9HCJR-00AD9 | OPP90D5Q, 3.1.0 | 1.92TB | |
| MZWLO3T8HCLS-00AD9 | 3.84TB | ||
| MZWLO7T6HBLA-00AD9 | 7.68TB | ||
| MZWLO15THBLA-00AD9 | 15.36TB | ||
| PM1745 | MZWLO1T6HCJR-00AD9 | 1.6TB | |
| MZWLO3T2HCLS-00AD9 | 3.2TB | ||
| MZWLO6T4HBLA-00AD9 | 6.4TB | ||
| MZWLO12THBLA-00AD9 | 12.8TB |
Figure
6 / 22
| CAVP Cert | Algorithm and Standard | Mode/ Method | Description/ Key Size(s)/ Key Strength(s) | Use/Function |
|---|---|---|---|---|
| A4661 | AES-ECB / FIPS 197, SP 800-38A | ECB | 256-bit keys with 256-bit key strength | Prerequisite for AES-XTS (A4661) |
| A4661 | AES-XTS / FIPS 197, SP 800-38E | XTS2 | 256-bit keys with 256-bit key strength | Data Encryption / Decryption |
| A4662 | AES-ECB / FIPS 197, SP 800-38A | ECB | 256-bit keys with 256-bit key strength | Prerequisite for Counter DRBG (A4662) |
| A4662 | Counter DRBG / SP 800-90Arev1 | CTR_ DRBG3 (AES-256) | AES 256 bits with Derivation Function Enabled | All Cryptographic Key Generation for version ‘OPP90D5Q’ and ‘3.1.0’ firmware |
| A4846 | AES-ECB / FIPS 197, SP 800-38A | ECB | 256-bit keys with 256-bit key strength | Prerequisite for Counter DRBG (A4846) |
| A4846 | Counter DRBG / SP 800-90Arev1 | CTR_ DRBG4 (AES-256) | AES 256 bits with Derivation Function Enabled | All Cryptographic Key Generation for version ‘3P00’ and ‘3R00’ firmware |
| A4663 | AES-ECB / FIPS 197, SP 800-38A | ECB | 256-bit keys with 256-bit key strength | Prerequisite for AES-GCM (A4663) |
| A4663 | AES-GCM / FIPS 197, SP 800-38D | GCM5 | 256-bit keys with 256-bit key strength IV: 96 bits | Key Encryption / Decryption |
| A4663 | ECDSA SigVer / FIPS 186-4 | ECDSA SigVer | Curve P-384 with SHA2- 384 | Digital Signature Verification |
| A4663 | HMAC-SHA2-256 / FIPS 198-1 | HMAC6 | 256-bit keys HMAC- SHA2-256 with λ=256 | Message Authentication |
2.3. Cryptographic Functionality 2.3.1. Approved Algorithm1 The cryptographic module supports the following Approved algorithms for secure data storage:
1 Not all algorithms/modes that appear on the module’s CAVP certificates are utilized by the module.
2 AES-ECB is the pre-requisite for AES-XTS (#4661); AES-ECB alone is NOT supported by the cryptographic module in Approved Mode.
3 AES-ECB is the pre-requisite for Counter DRBG (#4662); AES-ECB alone is NOT supported by the cryptographic module in Approved Mode.
4 AES-ECB is the pre-requisite for Counter DRBG (#4662); AES-ECB alone is NOT supported by the cryptographic module in Approved Mode.
5 2nd technique of IG C.H for generating an IV is implemented in this module. In other words, Key and IV are generated internally using by
approved CTR-DRBG (A4662 and A4846). And AES-ECB is the pre-requisite for AES-GCM (#4663); AES-ECB alone is NOT supported by the cryptographic module in Approved Mode.
6 HMAC is the pre-requisite for PBKDF2 (#4663); HMAC alone is NOT supported by the cryptographic module in Approved Mode.
Samsung Electronics Co., Ltd.
7 / 22
| A4663 | SHA2-256 / FIPS 180-4 | SHA2-2567 | SHA2-256 | Message Digest |
|---|---|---|---|---|
| A4663 | SHA2-384 / FIPS 180-4 | SHA2-384 | SHA2-384 | Message Digest |
| A4663 | PBKDF2 / SP 800-132 | HMAC SHA2-256 Option 2a using AES-GCM encryption | 256 bits | Key Derivation8 |
| Vendor Affirmed | CKG / SP 800-133rev2 | Section 4 Section 6.1 Section 6.3 | N/A | Symmetric Cryptographic Key Generation |
| - | ENT (P) / SP800-90B | N/A | N/A | ENT (P) provides a minimum of 256 bits of entropy for DRBG seed materials in key generation. |
| Algorithm | Caveat | Use / Function |
|---|---|---|
| AES-XTS / FIPS 197, SP 800-38E | No Security Claimed; AES-XTS is used remove obfuscation from the firmware during ROM initialized. | Removal of firmware obfuscation |
| No Security Claimed; AES-XTS is used for obfuscation and removal of obfuscation the CSP. (IG 2.4.A Scenario #1) | Key obfuscation and Removal of obfuscation | |
| AES-GCM / FIPS 197, SP800-38D | No Security Claimed; AES-GCM is only used for obfuscation and removal of obfuscation the CSP. (IG 2.4.A Scenario #1) | Key obfuscation and Removal of obfuscation |
| 2.3.2. | Non-Approved Algorithm The module does not implement any Non-Approved Algorithms Not Allowed in the Approved Mode of Operation. The following algorithms are not intended to be used as a security function and are not implemented to meet any FIPS 140-3 requirements. Additionally, these algorithms are not provided through a non-approved service to an operator #1) #1) Table 5. Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed |
| 2.4. | Approved Mode of Operation The module defaults to an Approved mode of operation, and as long as the guidance outlined in section 11 is followed, the module will remain in the Approved mode. The cryptographic module indicates the approved mode through the validated version status, as shown by the 'Show Status Service' in Table 8 via the NVM Express Identify Controller command. |
| 7 | SHA2-265 is the pre-requisite for PBKDF2 (#4663); SHA2-256 alone is NOT supported by the cryptographic module in Approved Mode. |
8 The Iteration Count parameter is 281. It was set accordingly in order to meet the minimum response time required from the application while
maintaining acceptable performance. Samsung Electronics Co., Ltd.
8 / 22
| Physical port | Logical Interface | Data that passes over port/interface |
|---|---|---|
| NVMe Connector | Data Input | plaintext data; signed data; authentication data |
| Data Output | plaintext data | |
| Control Input | commands input logically via an API; signals input logically or physically via one or more physical ports | |
| Status Output | status information output logically via an API; signal outputs logically or physically via one or more physical ports; |
9 / 22
| Role | Service | Input | Output | |
|---|---|---|---|---|
| Cryptographic Officer (CO) and User | Lock/Unlock an LBA Range | LBA Range | Status | |
| Erase an LBA Range’s Data | LBA Range | Status | ||
| IO Command | LBA | Status | ||
| CO | Change the Password | CO Password | Status | |
| User | Set User Password | User Password | Status | |
| None | Update the firmware | Firmware image binary | Status | |
| Show Status | None | Status | ||
| Authentication | Authority, Authenticated data | Status | ||
| Get Random Number | None | Status | ||
| Revert | None | Status | ||
| FormatNVM | Namespace ID, LBA Format | Status | ||
| Sanitize / DeleteNS | Namespace ID | Status | ||
| Perform Self-tests | None | Status |
| Role | Authentication Method | Authentication Strength |
|---|---|---|
| CO User | Password (Min: 8 bytes, Max: 32 bytes) | Probability of 1/264 in a single random attempt Probability of 80/264 in multiple random attempts in a minute |
10 / 22
| Service | Description | Approved Security Functions | Keys and/or SSPs | Roles | Access right to Keys and/or SSPs | Indicator9 | |||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| E | W | G | Z | ||||||||
| Change the Password | Change CO password | A4663 PBKDF2 HMAC-SHA2- 256 SHA2-256 | CO Password | CO | O | O | O | UID: AdminSP_SID_C_PIN / AdminSP_Admin1_C_PIN TCG Method: Set Result: TCG status code (Success: 00h) | |||
| CPK | O | O | O | ||||||||
| KPK | O | O | O | ||||||||
| Set User Password | Set User Password | A4663 PBKDF2 HMAC-SHA2- 256 SHA2-256 | User Password | User | O | O | O | UID: LockingSP_Admin1~4_C_PIN / LockingSP_User1~9_C_PIN TCG Method: Set Result: TCG status code (Success: 00h) | |||
| CPK | O | O | O | ||||||||
| KPK | O | O | O | ||||||||
| Lock/Unlock an LBA Range10 | Block or allow read (decrypt) / write (encrypt) of user data. | A4663 AES-GCM | MEK | CO, User | O | O | UID: Locking_GlobalRange / Locking_RangeNNNN TCG Method: Set Result: TCG status code (Success: 00h) | ||||
| KEK | O | O | O | ||||||||
| KPK | O | O | |||||||||
| IO Command11 | Encrypt / Decrypt User data | A4661 AES-XTS | MEK | O | NVM Command: Write / Read Result: NVM Status Code (Success: 00h) | ||||||
| Erase an LBA Range’s Data | Erase user data by changing the data encryption key. | A4662/A4846 CTR_ DRBG (AES-256) ENT (P) | DRBG V | O | O | O | O | UID: K_AES_256_GlobalRange_Key / K_AES_256_RangeNNNN_Key TCG Method: GenKey Result: TCG status code (Success: 00h) | |||
| DRBG Key | O | O | O | O | |||||||
| DRBG Seed | O | O | O | O | |||||||
| CKG | MEK | O | O | O |
| Service | Description | Approved Security Functions | Keys and/or SSPs | Roles | Access right to Keys and/or SSPs | Indicator12 | |||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| E | W | G | Z | ||||||||
| Show Status | Show approved version status of the module / Error state | N/A | N/A | N/A | NVM Command: Identify Controller command Result: NVM Status Code (Success: 00h) | ||||||
| Authentication | Authenticate the module | A4663 PBKDF2 HMAC-SHA2- 256 SHA2-256 | CO Password | O | O | O | UID: AdminSP_SID / AdminSP_Admin1 / LockingSP_Admin1~4 / LockingSP_User1~9 TCG Method: Authenticate Result: TCG status code (Success: 00h) | ||||
| User Password | O | O | O | ||||||||
| CPK | O | O | O | ||||||||
| KPK | O |
E W G Z Table 9. Approved Services - Authenticated - The following table displays unauthenticated services. Initially, it is possible to use the services in the table without authentication. The operator can configure settings that comply with NVM and TCG specifications. E W G Z
10 This service can lock/unlock an “IO Command” Service that doesn’t require any authentication specified in the Role column.
11The “IO Command” service is unlocked in advance by using the “Lock/Unlock an LBA Range” service, which complies with IG 4.1.A Additional Comment 8. Power cycling the module re-locks this service.
12 The result of NVM or TCG command is used as an indicator. NVM status code is stated in NVM Express® Base Specification and TCG status
code is stated in TCG Storage Architecture Core Specification. Samsung Electronics Co., Ltd.
11 / 22
| Get Random Number | Provide a random number generated by the CM. | A4662/A4846 CTR_ DRBG (AES-256) ENT (P) | DRBG V DRBG Key DRBG Seed Entropy Input | O O O O | UID: ThisSP TCG Method: Random Result: TCG status code (Success: 00h) |
|---|---|---|---|---|---|
| Revert | Erase user data in all Range by changing the data | A4662/A4846 CTR_ DRBG (AES-256) ENT (P) | DRBG V | O | UID: SPObj(AdminSP) TCG Method: Revert Result: TCG status code (Success: 00h) |
| DRBG Key | O | ||||
| DRBG Seed | O | ||||
| Entropy Input | O | ||||
| A4663 PBKDF2 HMAC-SHA2- 256 SHA2-256 | CPK | O | |||
| CKG | MEK | O | |||
| KEK | O | ||||
| FormatNVM | Erase user data by changing the data encryption key. | A4662/A4846 CTR_ DRBG (AES-256) ENT (P) | DRBG V | O | Admin Command: Format NVM Result: NVM Status Code (Success: 00h) |
| DRBG Key | O | ||||
| DRBG Seed | O | ||||
| Entropy Input | O | ||||
| A4663 PBKDF2 HMAC2-SHA- 256 SHA2-256 | CPK | O | |||
| CKG | MEK | O | |||
| KEK | O | ||||
| Sanitize / DeleteNS | Erase user data by changing the data encryption key. | A4662/A4846 CTR_ DRBG (AES-256) ENT (P) | DRBG V | O | Admin Command: Sanitize / Namespace Management Result: NVM Status Code (Success: 00h) |
| DRBG Key | O | ||||
| DRBG Seed | O | ||||
| Entropy Input | O | ||||
| A4663 PBKDF2 HMAC-SHA2- 256 SHA2-256 | CPK | O | |||
| CKG | MEK | O | |||
| KEK | O | ||||
| Update the firmware13 | Update the firmware | A4663 ECDSA, A4663 SHA2-384 | Firmware Verification Key | O | Admin Command: Firmware Commit Result: NVM Status Code (Success: 00h) |
| Perform Self-tests | Power cycling the module to perform self- tests | All cryptographic algorithms listed in Table 14 and Table 15 “Self- tests”. | N/A | N/A | The module enters operational state upon successful completion; otherwise, it indicates failure via the Show Status Service. |
Table 10. Approved Services - Unauthenticated
13 This service is exempted from being authenticated by exception clause (c) of IG 4.1.A.
Samsung Electronics Co., Ltd.
12 / 22
5. Software/Firmware Security - The cryptographic module employs ECDSA P-384 with SHA2-384 for firmware integrity testing, which is performed during power-on reset. Samsung Electronics Co., Ltd.
13 / 22
6. Operational Environment - The cryptographic module operates in a limited operational environment, consisting of the module’s firmware because this module does not have any operating system but designed in a manner to allow controlled validated firmware modification by an authenticated limited operator. This limited operational setting does not require any specific security rules, settings/configurations, or restrictions to be set. - The cryptographic module does not provide any general-purpose operating system to the operator. - Unauthorized modification of the firmware is prevented by the pre-operational firmware integrity test and conditional firmware load test. Samsung Electronics Co., Ltd.
14 / 22
| Physical Security Mechanisms | Recommended Frequency of Inspection/Test | Inspection/Test Guidance Details |
|---|---|---|
| Production grade cases | As often as feasible | Inspect the entire perimeter for cracks, gouges, lack of screw(s) and other signs of tampering. Remove from service if tampering found. |
| Tamper-evident Sealing Label | Inspect the sealing label for scratches, gouges, cuts and other signs of tampering. Remove from service if tampering found. |
The following physical security mechanisms are implemented in a cryptographic module:
15 / 22
8. Non-Invasive Security - Non-invasive security is not applicable to this cryptographic module Samsung Electronics Co., Ltd.
16 / 22
| Key/SSP Name/ Type | Strength | Security Function and Cert. Number | Generation | Import /Export | Establish -ment | Storage | Zeroisation14 | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| DRBG V / CSP | 128-bit | A4662/A4846 CTR_DRBG (AES-256) | SP 800-90A CTR_DRBG (AES-256) | N/A | N/A | N/A (HW internal) | Implicitly zeroised by Power on Reset | Generate s the MEK and KEK |
| DRBG Key / CSP | 256-bit | A4662/A4846 CTR_DRBG (AES-256) | SP 800-90A CTR_DRBG (AES-256) | N/A | N/A | Implicitly zeroised by Power on Reset | Generate s the MEK and KEK | |
| DRBG Seed / CSP | Entropy input: 512 bits Nonce 256 bits | A4662/A4846 CTR_DRBG (AES-256) | ENT (P) | N/A | N/A | Implicitly zeroised by Power on Reset | Generate s the MEK and KEK | |
| Entropy Input / CSP | 512-bit / 256-bit | A4662/A4846 CTR_DRBG (AES-256) | ENT (P) | N/A | N/A | Implicitly zeroised by Power on Reset | Generate s the MEK and KEK | |
| CO Password / CSP | Min. 64- bit | A4663 PBKDF2 | N/A | Manual Distribution / Electronic Entry in plaintext | N/A | Plaintext in RAM | Implicitly zeroised by Power on Reset | Derives CPK/KPK |
| User Password / CSP | Min. 64- bit | A4663 PBKDF2 | N/A | Manual Distribution / Electronic Entry in plaintext | N/A | Plaintext in RAM | Implicitly zeroised by Power on Reset | Derives CPK/KPK |
| CPK / CSP | 256-bit | N/A | Derived via PBKDF2 | N/A | N/A | Plaintext in RAM and Flash | Explicitly zeroised via these services: Performing via Set User Password, Change the password and Revert; FormatNVM; Sanitize / DeleteNS service, and zeroisation is shown through | Derived from User and CO Password |
9. Sensitive Security Parameter Management - Temporary SSPs stored in RAM are zeroised during power on reset. - The zeroisation is performed by overwriting the target SSP with a random value generated through the DRBG. - The module does not export SSPs. - All SSPs in volatile memory, including HW SFR, are automatically zeroised instantly either after key generation/use or upon performing power-on-reset, depending on the characteristics of volatile memory. - This module does not support SSP establishment.
Samsung Electronics Co., Ltd.
17 / 22
| the indicator of that service in Table 9, 10 | ||||||||
|---|---|---|---|---|---|---|---|---|
| KPK / CSP | 256-bit | A4663 AES-GCM | Derived via PBKDF2 | N/A | N/A | Obfuscated (AES-XTS [no security claimed]) in Plaintext in RAM | Explicitly zeroised via these services: Performing via Authentication service, and zeroisation is shown through the indicator of those service in Table 9 | Derived from User and CO Password Wraps KEK |
| KEK / CSP | 256-bit | A4663 AES-GCM | CKG / SP 800- 133rev2; SP 800-90A CTR_DRBG (AES-256) | N/A | N/A | Plaintext in RAM, Cipher text (AES- GCM) and obfuscated (AES-XTS [no security claimed]) in Flash | Explicitly zeroised via these services: Performing via Revert; FormatNVM; Sanitize / DeleteNS; Lock/Unlock an LBA Range service, and zeroisation is shown through the indicator of that service in Table 9, 10 | Wraps MEK |
| MEK / CSP | 256-bit | A4661 AES-XTS | CKG / SP 800- 133rev2; SP 800-90A CTR_DRBG (AES-256) | N/A | N/A | Plaintext in RAM, Cipher text (AES- GCM) in Flash | Explicitly zeroised via these services: Performing via Revert; FormatNVM; Sanitize / DeleteNS; Lock/Unlock an LBA Range; Erase an LBA Range’s Data service, and zeroisation is shown through the indicator of that service in Table 9, 10 | IO Comman d |
| Firmware Verification Key / Non- SSP | 256-bit | A4663 ECDSA | N/A | Entered during manufacturing | N/A | HW SFR15 | Implicitly zeroised by Right after Firmware Load Test completed. | Firmwar e Load Test *Note: This is not consider ed an SSP as |
15 HW SFR (Special Function Register) is a register within a hardware cryptographic algorithm IP, which has characteristic of volatile memory.
Samsung Electronics Co., Ltd.
18 / 22
per ISO/IEC 19790:20 12 section 7.5 but is included in the list for complete ness
| Entropy sources | Minimum number of bits of entropy | Details | |
|---|---|---|---|
| ENT (P)16 | 0.5 entropy per bit | Provides 512 bits of entropy input and 256 bits of nonce to construct a seed for CTR_DRBG. The module requests 256 amount of entropy for entropy source to provide 256 security strength. |
Table
16 Estimated amount of entropy per the source’s output bit is 0.85444 and Samsung conservatively claims to be set at 0.5 per bit.
Samsung Electronics Co., Ltd.
19 / 22
| Algorithm | Type | Description |
|---|---|---|
| ECDSA | Firmware integrity test | Firmware integrity test is performed by using ECDSA with SHA2- 38417 at every power-on-reset. |
| Algorithm | Type | Description |
|---|---|---|
| DRBG | Cryptographic algorithm self-test | KATs: SP 800-90A Health testing on Instantiate, Generate and Reseed functions |
| DRBG | Cryptographic algorithm self-test | KAT: DRBG with AES-256 is performed |
| AES-XTS | Critical function test | Duplicate Key Test for AES-XTS described in FIPS 140-3 IG C.I (i.e. key_1 ≠ key_2) |
| AES-XTS | Cryptographic algorithm self-test | KAT: Encrypt is performed |
| AES-XTS | Cryptographic algorithm self-test | KAT: Decrypt is performed |
| ECDSA | Cryptographic algorithm self-test | KAT: Curve P-384 with SHA2-384 signature verification is performed |
| SHA2-256 | Cryptographic algorithm self-test | KAT: Hash digest is performed |
| SHA2-384 | Cryptographic algorithm self-test | KAT: Hash digest is performed |
| HMAC | Cryptographic algorithm self-test | KAT: HMAC with SHA2-256 is performed |
| AES-GCM | Cryptographic algorithm self-test | KAT: Encrypt is performed |
| AES-GCM | Cryptographic algorithm self-test | KAT: Decrypt is performed |
| PBKDF2 | Cryptographic algorithm self-test | KAT: Password based key derivation using HMAC with SHA2-256 is performed |
| ECDSA | Firmware load test | ECDSA signature verification is performed if new FW is downloaded or at every power-on-reset |
| ENT (P) | Cryptographic algorithm self-test | Conditional SP800-90B Heath tests: Repetition count test, Adaptive proportion test |
While executing the following self-tests, all data output is inhibited until the completion of the self-test. The operator can initiate pre-operational tests on-demand by power-cycling the module. Conditional self-tests are conducted before the initial operation of approved algorithms. If a cryptographic module fails a self-test, it will enter an error state, during which all data output is inhibited. 10.1. Pre-Operational Test Table 14. Pre-operational Self-tests Samsung Electronics Co., Ltd.
20 / 22
21 / 22
12. Mitigation of Other Attacks The cryptographic module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3. Samsung Electronics Co., Ltd.
22 / 22