All modules
CMVP Validated Module · FIPS 140-3 Security Policy

PE9110 E1.S and PE9010 M.2 22110D NVMe TCG Opal SSC SEDs

Certificate#4899StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorSK hynix Inc.
Medium review priority  ·  exposes firmware-update authentication  ·  last validated 20 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date11/21/2029
CaveatNone
VendorSK hynix Inc.

Approved Algorithms (12)

AlgorithmACVP Cert
AES-ECBC1278
Counter DRBGA2595
Counter DRBGC1278
HMAC-SHA2-256A2596
PBKDFA2595
RSA SigVer (FIPS186-4)A2595
RSA SigVer (FIPS186-4)A2597
SHA2-256A2596
SHA2-384A2595
SHA2-384A2597
SHA2-512A2595
SHA2-512A2597

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for PE9110 E1.S and PE9010 M.2 22110D NVMe TCG Opal SSC SEDs
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>firmware load<br/>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Show Status<br/>Status output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>library named: nss</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for PE9110 E1.S and PE9010 M.2 22110D NVMe TCG Opal SSC SEDs
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>firmware load<br/>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Show Status<br/>Status output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>library named: nss</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy PE9110 E1.S and PE9010 M.2 22110D NVMe TCG Opal SSC SEDs FIPS 140-3 Cryptographic Module Document Version: 0.8 Date: 11/11/2024 SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 2

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy Table of Contents SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 3

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy List of Tables Table 6: Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed List of Figures SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 4
Security RequirementSecurity Level
General1
Cryptographic Module Specification1
Cryptographic Module Ports and Interfaces1
Roles, Services, and Authentication1
Software/Firmware Security1
Operational Environment1
Physical Security1
Non-Invasive SecurityN/A
Sensitive Security Parameter Management1
Self-Tests1
Life-Cycle Assurance1
Mitigation of Other AttacksN/A
Overall Level1

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy This document defines the Security Policy for the SK hynix PE9110 E1.S and PE9010 M.2 22110D NVMe TCG Opal SSC SEDs cryptographic module, hereafter denoted the Module. The Module is a multiple chip embedded self-encrypting drive (SED) compliant with TCG Core, TCG Opal, TCG Single User Mode (SUM), PCIe, and NVMe specifications. The Module is also compliant with the IEEE1667 storage specification. The cryptographic module’s controller has a built-in AES-XTS HW engine which encrypts and decrypts the user data without any performance loss. The Module meets FIPS 140-3 overall security Level 1. The FIPS 140-3 security levels for the Module are as follows: SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 5
#ModelHW P/NFW VersionDistinguishing Features
1PE9110 E1.SHFS1T9GEEWX132N41089A301920GB
2PE9110 E1.SHFS3T8GEEWX132N41089A303840GB
3PE9110 E1.SHFS7T6GEEWX132N41089A307680GB
4PE9010 M.2 22110DHFS960GDJ0X132N51082A30960GB
5PE9010 M.2 22110DHFS1T9GDJ0X132N51082A301920GB
6PE9010 M.2 22110DHFS3T8GDJ0X132N51082A303840GB

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy Cryptographic Module Specification The Module is designed to be embedded in a General Purpose Computer (host). The Module does not support a maintenance access interface. The Module uses a single chip controller (Atomos) with a PCIe/NVMe and SMBus interface on the systems side and SK hynix NAND flash internally. The Module is composed of the following major components:

2.1 Operational Environment

The following Module configurations were tested: Table 2: Cryptographic Module Tested Configuration

2.2 Cryptographic Boundary

The PE9110 has an E1.S physical form factor, while the PE9010 has an M.2 22110D physical form factor as depicted in Figures 1 and 2 respectively. The cryptographic boundary is defined as the entire PCB of each form factor, as outlined with a red dotted line. Note that the PE9110 SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 6
CertAlgorithmModeDescriptionFunctions/Caveats
A2596AES [197]ECB [38A]Key Sizes: 256 Boundary: HardwareEncrypt, Decrypt Support for XTS and KW
XTS [38E]Key Sizes: 256 Boundary: HardwareEncrypt, Decrypt of user data
KW [38F]Forward Key Sizes: 256 Boundary: HardwareAuthenticated Encrypt, Authenticated Decrypt for key storage
A2272Conditioning Component Block Cipher Derivation Function SP800-90BECB [90B]Key Sizes: 128 Boundary: HardwareSP800-90B Conditioner

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy E1.S includes a metallic enclosure, while the PE9010 M.2 22110D does not. No components have been excluded from the cryptographic boundary. Figure 1: PE9110 E1.S Top and Bottom (Cryptographic Boundary in Red) Figure 2: PE9010 M.2 22110D Top and Bottom (Cryptographic Boundary in Red) The Module only supports an Approved Mode of operation and is thus continually in an Approved mode of operation. In order to confirm the module’s versioning information and that it is operating in an Approved manner, the operator may invoke the “Read FIPS Compliance” service, as specified in Section 11.1. Per IG 2.4.C, Example Scenario #2, a global indicator is used to identify the Approved mode of operation, along with the implicit indicator for the successful completion of each Approved service.

2.4 Security Functions

The Module implements the Approved Mode cryptographic functions listed in the table below. The module does not support any non-Approved cryptographic functions. Table 3: Approved Algorithms SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 7
CertAlgorithmModeDescriptionFunctions/Caveats
C1278DRBG [90Ar1]CTRPrediction Resistance: Yes, No Supports Reseed Mode: AES-256 Derivation Function Enabled: No Additional Input: 0-384 Entropy Input: 384 Nonce: 0 Personalization String Length: 0-384 Returned Bits: 512 Additional Input used: No Entropy Input used: 384 Personalization String used: No Boundary: HardwareDeterministic Random Bit Generation Security strength = 256 bits.
AES [197]ECB [38A]Key Sizes: 256 Boundary: HardwareEncrypt, Decrypt To support CTR_DRBG
A2595DRBG [90Ar1]CTRPrediction Resistance: Yes, No Supports Reseed Mode: AES-256 Derivation Function Enabled: Yes Additional Input: 0-2048 Increment 128 Entropy Input: 256-2048 Increment 128 Nonce: 128-1024 Increment 128 Personalization String Length: 0-2048 Increment 128 Returned Bits: 512Tested, but not used
N/AENT [90B]ENT (P)Hardware Non-Deterministic RNG; minimum of 512 bits per access. Boundary: HardwareProvides a minimum of 256 bits of security strength to the Approved DRBG
A2596HMAC [198-1]SHA2-256Key Sizes: 256 bits λ = 32 bytes Boundary: HardwarePublic Security Parameter (PSP) data authentication and support for PBKDF2
A2595PBKDF [132]Option 1asLen = 32 bytes salt C = 1,000 iterations HMAC-SHA2-256 Cert. #A2596 Boundary: FirmwarePassword Based Key Derivation. The keys derived from passwords are used only in storage application
A2595RSA [186-4]PSSn = 2048 – 4096, SHA2-256, 384, 512 Boundary: FirmwareSigVer - Signature Verification: Firmware Updates and Maker Authentication

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 8
CertAlgorithmModeDescriptionFunctions/Caveats
A2597RSA [186-4]PSSn = 3072 – 4096, SHA2-384, 512 Boundary: HardwareSigVer - Signature Verification: Firmware Integrity
A2595SHA2-384SHA2-512Boundary: FirmwareMessage digest
A2595SHA2-512SHA2-512Boundary: FirmwareMessage digest
A2596SHA2-256SHA2-256Boundary: HardwareMessage digest
A2597SHA2-384SHA2-384Boundary: HardwareMessage digest
A2597SHA2-512SHA2-512Boundary: HardwareMessage digest
AlgorithmCaveatUse/Function
CKG [IG D.12][133r2] Section 6.1 - The “Direct Generation” of Symmetric KeysDirect Symmetric Key generation using unmodified DRBG output
[133r2] Section 6.2.3 - Symmetric Keys Derived from PasswordsDerivation of symmetric keys from a Password. The key can only be used for storage applications.
[133r2] Section 6.3 - Symmetric Keys Produced by Combining (Multiple) Keys and Other DataDerivation of XTS keys.
AlgorithmCaveatUse/Function
N/AN/AN/A
AlgorithmCaveatUse/Function
PBKDF [132]IG 2.4.A, Example #1 – Obfuscation of internally stored dataPBKDF is used to derive an obfuscation key based on an optional password. Per TCG specifications, the password must be optional and may be of 0 length.
AES-KWIG 2.4.A, Example #1 – Obfuscation of internally stored dataUsed in conjunction with PBKDF above to obfuscate keys. All keys obfuscated with AES-KW when using a PBKDF derived key are treated as plaintext SSPs.
RSAIG 2.4.A, Example #2 – Use of an approved algorithm for a purpose that is not security relevant or is redundant to an approved cryptographic algorithmRSA verification using a 4096-bit key with SHA2-512 serves a redundant purpose to HMAC-SHA2-256 at power on; both RSA 4096 and HMAC-SHA2-256 are applied to PSPs for verifying data integrity.
NameTypeDescriptionSF PropertioesAlgorithms/CAVP Cert
N/AN/AN/AN/AN/A
Table, extracted as text (did not parse into structured rows)
SK hynix PE9110 E1.S and PE9010 M.2 22110D                                                        FIPS 140-3 Security Policy Table 4: Vendor Affirmed Approved Algorithms N/A                 N/A                                         N/A Claimed Table 7: Security Function Implementation (SFI) N/A           N/A            N/A                   N/A                      N/A SK hynix Public Material – May be reproduced only in its original entirety (without revision).
Page 9
Vendor NameCertificate Number
N/AN/A

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy Table 8: Entropy Certificates N/A N/A

2.5 Overall Security Design

Per IG C.I, the module assures Key1 and Key2 are not equal for AES-XTS operations. The module implements the following security elements:

  1. No additional interface or service is implemented by the Module which would provide access to CSPs.
  2. Data output is inhibited during self-tests, Key generation, Zeroization, error states, and firmware load verification.
  3. The module does not support manual key entry.
  4. The module does not output plaintext CSPs or intermediate key values.
  5. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the module.
  6. The Module does not support a bypass capability.
  7. Power on self-tests do not require any operator action.
  8. The Module does not support the update of the serial number and vendor ID.
  9. The Module does not support concurrent operators.
2.6 Rules of Operation

The following security rules must also be considered when operating the module:

  1. All CSPs are zeroized by the Zeroization service. Only the Maker role can call the Zeroization service.
  2. The Module shall provide five (5) distinct operator roles: Cryptographic Officer, User, Maker, PSID, and Anybody
  3. The operator shall be capable of commanding the Module to perform the power up self-tests by power cycling or resetting the Module. SK hynix Public Material – May be reproduced only in its original entirety (without revision).
Page 10
Physical PortLogical Interface TypeData that passes over port/interface
PCIe ConnectorPowerPower
Control in, Data in, Data out, Status outNVMe storage commands and payloads
Control in, Status outManagement information via SMBus commands and payloads

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy Cryptographic Module Interfaces The Module’s ports and associated FIPS defined logical interface categories are listed in Table 9. The module does not support a Control Output interface. Table 9: Ports and Interfaces The module also supports a JTAG and UART port, which are permanently disabled. The NVMe interface provides the primary interface to interact with the Module. Most services provided by the Module are accessed via the NVMe Interface including Opal configuration, reading and writing user data, retrieving FIPS capability support, and retrieving FIPS status reporting. The SMBus interface provides the ability to audit the SSD environment (temperature, Vital Product Data). SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 11
RoleAuthentication MethodAuthentication Strength
CON/AN/A
UserN/AN/A
MakerN/AN/A
PSIDN/AN/A
AnybodyN/AN/A

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy Roles, Services, and Authentication

4.1 Assumption of Roles

The module supports five distinct operator roles: Cryptographic Officer (CO), User, Maker, PSID, and Anybody. The method for assuming a role is implicit based on the services invoked. The module only asserts conformance with Level 1 requirements; PINs and passwords are optional as required by TCG standards and are defined as non-SSPs; the module makes no claim to support FIPS 140-3 authentication mechanisms. The module supports the following operator roles:

  1. Crypto Officer (CO): a. Admin SP SID - This operator is responsible for transitioning from uninitialized mode to initialized mode. b. Admin SP Admin – This operator is disabled by default but can be enabled by SID authority. When enabled, it can transition the Module back to the uninitialized state from the initialized state. c. Locking SP Admins – This operator is used to enable and disable Users, create and delete user ranges, lock or unlock the ranges and cryptographically erase the user ranges. The CO is also responsible for performing firmware updates.
  2. User: The Locking SP Users can unlock and lock the drive to allow the operator to read and write data to the drive. This user can also call the “Cryptographic Erase” service.
  3. Maker: This is an assumed role which enables the operator to execute the “Zeroise Service” command.
  4. PSID: The TCG PSID Authority has access to perform the “PSID Revert” service.
  5. Anybody: This role is assumed when the operator executes services that does not require a TCG role to be assumed. The Module does not support a maintenance role or bypass capability. The Module does not support concurrent operators. Table 10: Roles and Authentication
4.2 Services

All services implemented by the Module are listed in Table 11, while SSP usage for each service is specified in Table 12. Note: SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 12
RoleServiceInputOutput
COTake ownershipSecurity Send command parameters; Security Send command payload w/ TCG Set method for C_PIN_SID-; Security Receive command status
COActivate OPALSecurity Send command parameters; Security Send command payload w/ TCG Activate method-; Security Receive command status
CODeactivate OPALSecurity Send command parameters; Security Send command payload w/ TCG Revert method-; Security Receive command status
COAdmin Set PINSecurity Send command parameters; Security Send command payload w/ TCG Set method for ASP or LSP Admins-; Security Receive command status
CO UUser Set PINSecurity Send command parameters; Security Send command payload w/ TCG Set method for LSP Users-; Security Receive command status
COEnable/Disable User Set PINSecurity Send command parameters; Security Send command payload w/ TCG Set method for ACE Set User PIN object-; Security Receive command status
COEnable/Disable Admin SP authoritiesSecurity Send command parameters; Security Send command payload w/ TCG Set method for ASP Authority object-; Security Receive command status
COEnable/Disable Locking SP authoritiesSecurity Send command parameters; Security Send command payload w/ TCG Set method for ASP Authority object.-; Security Receive command status

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy

Page 13
RoleServiceInputOutput
COEnable/Disable SUMSecurity Send command parameters; Security Send command payload w/ TCG Reactivate method-; Security Receive command status
COLocking Range ConfigurationSecurity Send command parameters; Security Send command payload w/ TCG Reactivate method-; Security Receive command status
CO ULock/Unlock rangeSecurity Send command parameters; Security Send command payload w/ TCG Set method-; Security Receive command status
CO USet common nameSecurity Send command parameters; Send command payload w/ TCG Set method for Common Name object-; Security Receive command status
CO UData store table SetSecurity Send command parameters; Security Send command payload w/ TCG Set method for Datastore table-; Security Receive command status
CO UCrypto Erase of a rangeSecurity Send command parameters; Security Send command payload w/ TCG Erase or Genkey method-; Security Receive command status
MZeroizationZeroization VU command parameters; Zeroization VU command payload-; Zeroization VU comma status
PPSID RevertSecurity Send command parameters; Security Send command payload w/ TCG Revert method-; Security Receive command status
APower Cycle (Self-Test)-; --; -
AHot resetBit 6 (Secondary Bus Reset) of Bridge Control Register (offset 0x3E) PCI Config Space; --; -

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 14
RoleServiceInputOutput
AWarm resetBit 4 (Link Control Register Offset 0x10) in PCI Express Capability Register of PCI config space; or Offset 0x20 is the NVM Subsystem Reset register(NSSR) in the controller registers (PCIe BAR); --; “Negotiated Link width” (Bit 9:4) in the Link Status Register (Offset 0x12) of PCI config space; or Bit 4 of the NVMe Controller status register (Offset 0x1C)
AShow StatusLevel 0 Discovery parameters or NVMe Identify command parameters; -Level 0 Discovery payload or NVMe Identify; Level 0 Discovery status or NVMe Identify command status
ARead FIPS ComplianceSecurity Receive w/ Read FIPS Compliance command parameters; -Read FIPS Compliance payload; Security Receive command status
ABlock SID AuthorizationSecurity Send w/ Block SID Authorization command parameters; --; Security Send command status
ATCG AuthorizationSecurity Send command parameters; Security Send command payload w/ TCG StartSession or Authorization method-; Security Receive command status
AEnable Zeroization ServiceVendor Specific Auth Challenge command parameters; Vendor Specific Command Payload-; Vendor Specific command status
AGet Random NumberSecurity Send command parameters; Security Send command payload w/ TCG Random methodSecurity Receive command payload; Security Receive command status
ATelemetry logsTelemetry Log (Get Log Page) command parameters; -Telemetry Log (Get Log Page) command payload; Telemetry Log (Get Log Page) command status
ARead/Write User DataRead/Write command parameters; Write command payloadRead command response payload; Read/Write command status
COFirmware UpdateFirmware Update command parameters; Firmware Update command payload-; Firmware Update command status

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 15
RoleServiceInputOutput
AFormat NVM / Namespace ManagementFormat command parameters / Namespace Management command parameters; Format command / Namespace Management command payload-; Format command / Namespace Management command status
ASanitizeCrypto Sanitize command parameters; --; Crypto Sanitize command status
AConfigure DriveSet Features command parameters; --; Set Features command status

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 16
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Take ownershipChanges default password of SID to a value other than MSID.PBKDF (#A2595); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596)CO Password; AUTH_KEYs; SALT; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; TPER_SALT_KEK; TPER_KEKCOW, E, Z; G, E, Z; G, E; G, E, Z; G, E; G, E; E; E; G, EStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy

Page 17
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Activate OPALEnables Locking SP via TCG Activate method. Activate method can enable SUM.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596)CO Password; User Password; AUTH_KEYs; SALT; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; TPER_SALT_KEK; SUM_KEKsCOW, E, Z; E; G, E, Z; G, E; G, E; G, E; E; E; G, E; G, E, ZStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 18
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Deactivate OPALReverts the drive back to the Original Factory State through TCG Revert or Revert SP methods. Note: For Revert SP, 1. Global Range data is preserved if KeepGlobal parameter is TRUE. 2. TPER_SALT_KEK and PSP_HMAC_KEY are also preserved.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596); AES-XTS (#A2596)CO Password; AUTH_KEYs; SALT; MSID PIN; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; HRK; MEK_KEK; TPER_SALT_KEK; TPER_KEK; SUM_KEKs; MEKsCOE; G, E, Z; G, E; E; G, E, Z; G, E, Z; G, E, Z; G, E, Z; E; G, E, Z; G, E, Z; E, Z; E, Z; G, E, ZStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 19
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Admin Set PINUpdates Admin authority PIN.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596)CO Password; AUTH_KEYs; SALT; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; TPER_SALT_KEK; TPER_KEK; SUM_KEKsCOW, E, Z; G, E, Z; G, E; G, E, Z; G, E; G, E; E; E; E; EStatus output to the host is returned for success or error
User Set PINUpdates User authority PIN. Locking SP Admins can set PINs for any Non-SUM Users.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596)User Password; AUTH_KEYs; SALT; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; TPER_SALT_KEK; TPER_KEK; SUM_KEKsCO, UW, E, Z; G, E, Z; G, E; G, E, Z; G, E; G, E; E; E; E; EStatus output to the host is returned for success or error
Enable/Disable User Set PINDisables a non-SUM User’s ability to change its own PIN.HMAC-SHA2-256 (#A2596)PSP_HMAC_KEYCOEStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 20
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Enable/Disable Admin SP authoritiesEnables or disables an Admin SP authority.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596)CO Password; AUTH_KEYs; SALT; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; TPER_SALT_KEKCOE; G, E, Z; G, E; G, E, Z; G, E; G, E; E; EStatus output to the host is returned for success or error
Enable/Disable Locking SP authoritiesEnables or disables a Locking SP Admins and non-SUM Users.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596)CO Password; User Password; AUTH_KEYs; SALT; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; TPER_SALT_KEK; TPER_KEKCOE; E; G, E, Z; G, E; G, E, Z; G, E; G, E; E; E; EStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 21
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Enable/Disable SUMConfigures users and ranges in SUM through TCG Reactivate method.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596)CO Password; User Password; AUTH_KEYs; SALT; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; TPER_SALT_KEK; TPER_KEK; SUM_KEKsCOW, E, Z; E; G, E, Z; G, E; G, E, Z; G, E; G, E; E; E; G, E, Z; G, E, ZStatus output to the host is returned for success or error
Locking Range ConfigurationFor non-SUM ranges: Used to modify a range starting address, capacity and attributes of non-SUM ranges. For SUM Policy 1: Used to modify a SUM range starting address, capacity and attributes by Admins if allowed. For SUM Policy 0: Used to modify a SUM range starting address, capacity and attributes by SUM Users if allowed.DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596); AES-XTS (#A2596)DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; MEK_KEK; TPER_KEK; SUM_KEKs; MEKsCOG, E, Z; G, E; G, E; E; E; E; E; G, E, ZStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 22
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Lock/Unlock rangeControls read and write access to a range by either locking or unlocking the LBA range. In Non-SUM, Admins and Users (if allowed by Admins) have access. In SUM, only Users have access.HMAC-SHA2-256 (#A2596); AES-KW (#A2596); AES-XTS (#A2596)PSP_HMAC_KEY; TPER_KEK; SUM_KEKs; MEKsCO, UE; E; E; E, ZStatus output to the host is returned for success or error
Set common nameCustomizes the name of a TCG Authority. Admins and Users (if allowed by Admins) have access.HMAC-SHA2-256 (#A2596)PSP_HMAC_KEYCO, UEStatus output to the host is returned for success or error
Data store table SetWrites a stream of bytes to unstructured storage. Admins and Users (if allowed by Admins) have access.HMAC-SHA2-256 (#A2596)PSP_HMAC_KEYCO, UEStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 23
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Crypto Erase of a rangeFor Non-SUM Ranges: Erases a range by destroying its existing MEK and generating a new one. This service is performed via TCG GenKey method. By default, Admins have access. If Admins allows, Users also have access. For SUM Ranges via TCG Erase method: Erases a range by destroying its existing MEK and generating a new one. The range’s LBA range is unlocked, and the User PIN is reset to the NULL password. This service is performed via the TCG Erase method. For SUM Ranges via TCG GenKey method: Erases a range by destroying its existing MEK and generating a new one. This service is performed via the TCG GenKey method.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596); AES-XTS (#A2596)User Password; AUTH_KEYs; SALT; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; MEK_KEK; TPER_SALT_KEK; TPER_KEK; SUM_KEKs; MEKsCO, UE; G, E, Z; G, E; G, E, Z; G, E; G, E; E; E; E; E; E; G, E, ZStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 24
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
ZeroizationDestruction of plaintext keys and CSPs. This service decommissions the drive.-DRBG-EI; DRBG V; DRBG Key; HRK; PSP_HMAC_KEY; MEK_KEK; TPER_SALT_KEK; TPER_KEK; SALT; SUM_KEKs; KS_HMAC_KEY; MEKsMZ; Z; Z; Z; Z; Z; Z; Z; Z; Z; Z; ZStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 25
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
PSID RevertTCG Revert method using PSID. This service returns the Module to its original factory state. The authentication data (PSID) is printed on the label of the Module.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596)CO Password; AUTH_KEYs; SALT; MSID PIN; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; HRK; MEK_KEK; TPER_SALT_KEK; TPER_KEK; SUM_KEKs; MEKsPE; G, E, Z; G, E; E; G, E, Z; G, E; G, E; G, E, Z; E; G, E, Z; G, E, Z; Z; Z; G, ZStatus output to the host is returned for success or error

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 26
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Power Cycle (Self-Test)Powers the module off and on again. This triggers 1. Power-On Self- Tests of the Module. 2. Unblock locked-out authorities that have exhausted their Try Limit. Enable CO authority (Admins SP SID) if it is previously blocked by Block SID Authorization service.DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596); AES-XTS (#A2596); RSA-3072 SigVer (#A2597); SHA2-384 (#A2597);DRBG V; DRBG Key; PSP_HMAC_KEY; KS_HMAC_KEY; HRK; MEK_KEK TPER_SALT_KEK; MEKs; FW Public Key; Root Public KeyAG, E, Z; G, E, Z; E; E; E; E; E; E; E; EReturn code for success or error
Hot resetResets one of the ports of the Module by performing a PCIe Hot Reset.--A-
Warm resetResets the Module by performing an NVMe Subsystem Reset or PCIe Warm reset.HMAC-SHA2-256 (#A2596)PSP_HMAC_KEYAE

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 27
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Show StatusThis is a set of commands from the TCG and NVMe protocols to read Security Configuration. Specifically, this includes NVMe Security Send/Receive, Identify Controller commands, which can be used for reading Approved mode (Initialized/Uninitialized), error messages, and other status information. The Approved Mode indicator is a subset of the NVMe Security Receive command (TCG Level 0 Discovery) and the returned word of the NVMe Identify Controller command (word at offset 4092, bit 0).--A-The Approved Mode indicator is a subset of the NVMe Security Receive command (TCG Level 0 Discovery) and the returned word of the NVMe Identify Controller command (word at offset 4092, bit 0).
Read FIPS ComplianceThe Module’s FIPS 140 Compliance descriptor (hardware and firmware versions) can be retrieved in the format specified by SFSC specification using TCG IF-RECV command with Protocol Id 0 and ComID 2.--A-The indicator follows the SFSC specification using TCG IF-RECV command with Protocol Id 0 and ComID 2.

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 28
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Block SID AuthorizationDisables CO (Admin SP SID) authorization when ownership of the drive is not taken.--A-Status output to the host is returned for success or error.
TCG AuthorizationAuthorizes an operator using TCG PIN through Start session or TCG Authentication method.PBKDF (#A2585); DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596)CO Password; User Password; AUTH_KEYs; SALT; PSID PIN; DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; TPER_SALT_KEK; TPER_KEK; SUM_KEKsAW, E, Z; W, E, Z; G, E, Z; G, E; W, E; G, E, Z; G, E; G, E; E; E; G, E; EStatus output to the host is returned for success or error.
Enable Zeroization ServiceAuthorizes the Zeroization service for the Maker role.DRBG (#C1278); RSA-2048 SigVer (#A2595); SHA2-256 (#A2596)DRBG-EI; DRBG V; DRBG Key; Maker Public KeyAG, E, Z; G, E; G, E; EStatus output to the host is returned for success or error.

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 29
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Get Random NumberTCG Random method used to generate and output a random number from the DRBG.DRBG (#C1278)DRBG-EI; DRBG V; DRBG KeyAG, E, Z; G, E; G, EStatus output to the host is returned for success or error.
Telemetry logsThe Module allows the collection of debugging information through NVMe log pages. The purpose of the telemetry log data is to provide information required to debug firmware issues remotely. No sensitive information is included.--A-Status output to the host is returned for success or error.
Read/Write User DataReads/Writes user data. In uninitialized mode, this service is always successful. In initialized mode, this service is only successful if the range is unlocked for read/write access via Lock/Unlock range service.AES-XTS (#A2596)MEKsAEStatus output to the host is returned for success or error.

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 30
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
Firmware UpdateLoads a firmware image. All firmware loaded into the module is validated with RSA signature verification over the entire firmware image.AES-KW (#A2596); HMAC-SHA2-256 (#A2596); RSA-3072 SigVer (#A2595); SHA2-384 (#A2595)HRK; KS_HMAC_KEY; FW Public Key; Root Public KeyCOE; E; E; EStatus output to the host is returned for success or error.
Format NVM / Namespace ManagementWipes the data of a particular namespace by generating new MEK. This service is only successful if the range is unlocked for read/write access via Lock/Unlock range service.DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596); AES-XTS (#A2596)DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; MEK_KEK; TPER_KEK; SUM_KEKs; MEKsAG, E, Z; G, E; G, E; E; E; E; E; G, E, ZStatus output to the host is returned for success or error.

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 31
ServiceDescriptionApproved Security FunctionsSSPsRolesAccess RightsIndicator
SanitizeWipes the data of a particular namespace by generating new MEK. This service is accessible only in Uninitialized mode.DRBG (#C1278); HMAC-SHA2-256 (#A2596); AES-KW (#A2596); AES-XTS (#A2596)DRBG-EI; DRBG V; DRBG Key; PSP_HMAC_KEY; MEK_KEK; MEKsAG, E, Z; G, E; G, E; E; E; G, E, ZStatus output to the host is returned for success or error.
Configure DriveEnables or disables IEEE1667 protocol support.--A-Status output to the host is returned for success or error.

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 32

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy Software/Firmware Security The firmware components are protected by an RSA signature. The operator can initiate the integrity test on demand by power cycling or resetting the module. Operational Environment The Module has a limited operational environment under FIPS 140-3 definitions. The tested operational environments are listed in Table 2. The Module includes a firmware load service to support necessary updates. The Module will not load or execute firmware which is not signed with SK hynix 3072-bit RSA Private Key. Firmware versions validated through the FIPS 140-3 CMVP will be explicitly identified on a validation certificate. Any firmware not identified in this Security Policy does not constitute the Module defined by this Security Policy or covered by this validation. Please see the operator instructions provided in Section 11 for the initialization, uninitialization, and sanitation of the module. Physical Security Policy The Module meets commercial-grade specifications for power, temperature, reliability, and shock/vibrations. The Module uses standard passivation techniques and only asserts compliance with Level 1 physical security requirements. Non-Invasive Security The Module does not implement any mitigation method against non-invasive attack. Sensitive Security Parameter (SSP) Management CSPs and PSPs are defined in the tables below. The following legend is used to describe the generation, storage, input, output, and zeroization methods:

Page 33
SSPStrengt hSecurity Functio n/ Cert.Gene rationImport /Expor tEstabli shmen tSto rag eZeroizat ionDescription / Usage
DRBG-EI384ENT (P)G2N/AN/AS1Z1, Z2Deterministic Random Bit Generator – Entropy Input string and seed. Size: 384 bits of entropy data. Instantiates the DRBG to 256 bits of security strength.
DRBG V128DRBG Cert. #C1278G3N/AN/AS1Z1, Z2The secret value V (128 bits) in the current DRBG internal working state
DRBG Key256DRBG Cert. #C1278G3N/AN/AS1Z1, Z2The secret Key (256 bits) in the current DRBG internal working state
HRK256AES-KW Cert. #A2596G5N/AN/AS2Z2Hidden Root Key Type: AES wrapping key Purpose: Used to wrap following keys: PSP_HMAC_KEY,
Table, extracted as text (did not parse into structured rows)
SK hynix PE9110 E1.S and PE9010 M.2 22110D                                                          FIPS 140-3 Security Policy •    S4      Stored in static NAND in plaintext, associated by memory location (index) •    S5      Stored in dynamic RAM in plaintext, associated by memory location (index) •    S6      Stored in static NAND encrypted obfuscated (treated as plaintext) with AES-KW using the AUTH_KEY, associated by memory location (index) •    S7      Stored in static NAND encrypted with AES-KW using SUM_KEK, TPER_KEK, or MEK_KEK, associated by memory location (index) •    S8      Stored in static NAND encrypted with AES-KW using the TPER_SALT_KEK, associated by memory location (index) •    S9      Stored in plaintext as part of static firmware, which is RSA signed •    I1      Input in plaintext (Non-SSPs only) •    O1      Plaintext to host (Non-SSPs only) •    Z1      Zeroized by Module power cycle or hard reset •    Z2      Zeroized by the “Zeroization” service by overwriting with zeroes or ones •    Z3      Zeroize after service completion by overwriting the RAM location by zeroes
9.1 Sensitive Security Parameters

All SSPs used by the Module are described in this section. Table 13: SSPs SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 34
SSPStrengt hSecurity Functio n/ Cert.Gene rationImport /Expor tEstabli shmen tSto rag eZeroizat ionDescription / Usage
MEK_KEK,
TPER_SALT_KEK,
and KS_HMAC_KEY.
PSP_HMAC_KE Y256HMAC Cert. #A2596G5N/AN/AS3, S5Z1, Z2, Z3Public Security Parameter HMAC Key Type: 256-bit Purpose: Key is used to check the integrity of the SALT and PSID PIN
KS_HMAC_KEY256HMAC Cert. #A2596G5N/AN/AS3, S5Z1, Z2, Z3Key Storage HMAC Key Type: 256-bit Purpose: Key is used to check the integrity of the FW Public Key and Root Public Key
MEK_KEK256AES-KW Cert. #A2596G5N/AN/AS3, S5Z1, Z2, Z3Type: AES 256 Purpose: Key wraps the MEKs when in the Uninitialized state
TPER_SALT_KE K256AES-KWG5N/AN/AS3, S5Z1, Z2, Z3Type: AES 256
Cert.Purpose: Key wraps
#A2596the SALT.
TPER_KEK256AES-KWG5N/AN/AS5, S6Z1, Z2, Z3Type: AES 256
Cert.Purpose: Key wraps
#A2596the MEKs for OPAL.
SUM_KEKs256AES-KW Cert. #A2596AES-KWG5N/AN/AS5, S6Z1, Z2, Z3Type: AES 256
Cert.Purpose: It is the
#A2596key wrapping key used for MEKs for SUM.
MEKs256AES-XTS Cert. #A2596G5N/AN/AS5, S7Z1, Z2, Z3Type: AES 256 Purpose: MEK is 0 the Global Range Key. MEK keys are 1-8 used for User data encryption in XTS mode.
AUTH_KEYs (Non-SSP)N/APBKDF Cert. #A2595G4N/AN/AS1Z1, Z3Type: AES 256-bit key wrap key derived from PBKDF using the CO or User password, which may be 0 length. Purpose: Key is used for TPER_KEK (OPAL) and

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 35
SSPStrengt hSecurity Functio n/ Cert.Gene rationImport /Expor tEstabli shmen tSto rag eZeroizat ionDescription / Usage
SUM_KEK (SUM)
obfuscation.
CO Password (Non-SSP)N/APBKDF Cert. #A2595N/AI1N/AS1Z1, Z3Crypto Officer password Type: Password Purpose: May be used for authorizing the CO role
User Passwords (Non-SSP)N/APBKDF Cert. #A2595N/AI1N/AS1Z1, Z3User Password Type: Password Purpose: May be used for authorizing User roles
SALT (Non- SSP)256PBKDF Cert. #A2595G5N/AN/AS5, S8Z1, Z2, Z3256-bit non-secret salt used as input to = PBKDF. A unique salt is associated with the derivation of each AUTH_KEY.
PSID PIN (Non- SSP)N/APBKDF Cert. #A2595G1I1N/AS5Z132 byte PIN is used to access the TCG Revert service. The PSID PIN is visibly printed on a production label on the Module.
MSID PIN (Non-SSP)N/APBKDF Cert. #A2595G1I1, O1N/AS5, S9Z132 byte default PIN is used to authorize the Initialize service. It can be displayed via the Show Status/Read Security Configuration service.
FW Public Key (Non-SSP)128RSA Cert. #A2595, #A2597G1N/AN/AS4, S5N/AType: 3072 bit RSA Public Key Purpose: Key is used for RSA signature verification of the firmware image.
Maker Public Key (Non-SSP)112RSA Cert. #A2595G1N/AN/AS5, S9N/A.Type: 2048 bit RSA Public Key Purpose: Key is used to access Zeroise service.Type: 2048 bit RSA
ProtectPublic Key
ed byPurpose: Key is used
RSAto access Zeroise
Signatur e.service.
Root Public Key (Non-SSP)150RSAG1N/AN/AS4, S5N/AType: 4096 bit RSA
Cert.Public Key
#A2595,Purpose: Key is used
#A2597to validate the chain

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy e. SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 36
SSPStrengt hSecurity Functio n/ Cert.Gene rationImport /Expor tEstabli shmen tSto rag eZeroizat ionDescription / Usage
of trust for the FW
Public Key.

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 37
Entropy SourceMinimum Number of Bits of EntropyDetails
ENT (P)Min-entropy of 1 per 1-bit sampleThis ENT (P) has been evaluated according to the non-IID evaluation path of the [SP800-90B] standard.
Test TargetDescriptionFailure Behavior
Firmware IntegrityRSA 3072 and SHA2-384 verification performed over all firmware located in NAND storage on the Atomos controller.Enters INTERNAL_STATE_ERROR state. SMBus bytes offset 243, bit 7 will be 1b.
ENT (P)Performs ENT (P) startup test. Generates 32 byte noise that will force RCT and APT on 1536 bits.Enters SELF_TEST_ERROR state.
Test TargetDescriptionFailure Behavior
AES-KW Decrypt Cert.# A2596KAT: Decryption only Mode: KW Key size: 256 bitsEnters INTERNAL_STATE_ERROR state
AES-KW Cert.# A2596KATs: Both forward and inverse ciphers are tested via encryption and decryption. Modes: KW Key size: 256 bits Note: This test covers AES-ECB and AES-XTS as per IG 10.3.AEnters SELF_TEST_ERROR state.

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy Table 14: Non-Deterministic Random Number Generation Specification Self-Tests Each time the Module is powered up, tests are run to guarantee the proper functioning of the crypto algorithms. Power on self-tests are available on demand by power cycling or resetting the Module. The module zeroises all temporary values used as part of the pre-operational and conditional self-tests On power-on or reset, the Module performs self-tests as described in the tables below. All KATs must be completed successfully prior to any other use of cryptography by the Module. If one of the KATs fails during the ROM boot stage of the device, then the Module enters an internal error state. If the Module has exited ROM boot stage, the Module enters SELF_TEST_ERROR state which can be retrieved by NVMe Identify Controller command word at offset 4092, bit 0 will be 1. Power cycle is required to recover the Module from self-test failure. Table 15: Pre-Operational and Conditional Self-Tests performed at Power-On Table 16: Additional Conditional Self-Tests SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 38
Test TargetDescriptionFailure Behavior
AES- Conditioner Cert.# A2272KAT: Encryption only, exercises the SP800-90B conditioner. Modes: ECB Key size: 256 bitsEnters SELF_TEST_ERROR state.
AES XTS Key generationAn IG C.I key comparison test is performed on Key1 and Key2 for each generation.Enters SELF_TEST_ERROR state.
DRBG Cert.# C1278Performs a fixed input KAT inclusive of the SP 800- 90Ar1 instantiate, generate, and reseed health tests. Mode: CTR_DRBGEnters SELF_TEST_ERROR state.
DRBG Cert.# C1278SP800-90Ar1 Health Tests (Instantiate, Generate, Reseed)Enters SELF_TEST_ERROR state.
ENT (P)SP800-90B Health Tests (RCT and APT)Enters SELF_TEST_ERROR state.
HMAC (SoC HW) Cert.# A2596Performs HMAC generates and verify KATs using a 256-bit key and SHA2-256 Note: SHA2-256 is covered by HMAC KAT per IG 10.3.BEnters INTERNAL_STATE_ERROR state. Status output data via SMBus bytes offset 243, bit 7 will be 1b.
PBKDF2 Cert.# A2595Performs KAT using a known password and HMAC- SHA2-256 (Satisfies the HMAC KAT).Enters SELF_TEST_ERROR state.
RSA (ROM) Cert.# A2597KAT: RSA PSS verify with 3072 bit key and SHA2-384 (Cert. #A2597). Note: SHA2-384 KAT is included in this test. This test is performed prior to the Firmware Integrity Test.Enters INTERNAL_STATE_ERROR state. Status output data via SMBus bytes offset 243, bit 7 will be 1b
RSA (FW) Cert.# A2595KAT: RSA PSS verify with 2048 bit key and SHA2-512 (Cert. #A2595). Note: RSA 3072 and 4096 key sizes are covered by testing 2048 bit key. SHA2-512 KAT is included in this test.Enters SELF_TEST_ERROR state
Firmware Load TestThe Module performs a RSA 3072 signature verification on all firmware loaded into the Module.The Module returns invalid image for download commit command and the image is discarded.

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 39

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy Life-Cycle Assurance The Module design corresponds to the Module Security rules. This section documents the Cryptographic Officer instructions that are necessary to implement in order to maintain compliance with FIPS 140-3 security requirements.

11.1 Cryptographic Officer Initialization

The Module is shipped from the factory in an Approved mode of operation (uninitialized state). The keys generated during manufacturing are used to encrypt/decrypt the user data. The shipping container protecting the Module or set of Modules in transit should be verified for evidence of tampering. The CO should initialize the Module by taking the following steps:

11.1.1 Verifying the Module is in an Approved Mode of Operation

To verify that a module is in the Approved mode of operation the operator will perform the Read FIPS Compliance by issuing TCG IF-RECV command with Protocol Id 0 and ComID 2. Refer [SFSC] spec. For example, the sample of data below is returned from the module: ----------------FIPS 140 compliance descriptor-----------------------COMPLIANCE DESCRIPTOR INFORMATION LENGTH -> 528 COMPLIANCE DESCRIPTOR DESCRIPTOR TYPE -> 1 COMPLIANCE DESCRIPTOR DESCRIPTOR LENGTH -> 520 COMPLIANCE DESCRIPTOR RELATED STANDARD -> 511 COMPLIANCE DESCRIPTOR OVERALL SECURITY LEVEL -> 492 COMPLIANCE DESCRIPTOR HARDWARE VERSION -> HFS1T9GEEWX132N COMPLIANCE DESCRIPTOR VERSION ->51082A30 COMPLIANCE DESCRIPTOR MODULE NAME -> SK hynix PE9110 E1.S and PE9010 M.2 22110D NVMe TCG Opal SSC SEDs ----------------------------------------------------------------------

11.1.2 Initialize the Module
  1. Take Ownership - Set Admin SP SID.
  2. Activate Opal with Single User Mode.
  3. Set WriteLockEnabled and ReadLockEnabled column of all valid Locking ranges.
  4. Power cycle the Module.
  5. Verify the module is in initialized mode by checking the • LockingEnabled bit of the TCG Level 0 Discovery Locking Feature Descriptor is set to 1. • WriteLockEnabled and ReadLockEnabled columns of all valid Locking ranges in the Locking Table are set to True.
11.2 Un-Initialize the Module

The Deactivate OPAL may be invoked by an authorized role to affect a transition into the uninitialized state of operation. The PSID Revert may be done by the PSID role to affect a

1 “51” is an ASCII data field that indicates “FIPS 140-3” per the Security Features for SCSI Commands, Revision 2, Section 5.1.5.3

2 “49” is an ASCII data field that indicates the FIPS 140 overall security level of “1” per the Security Features for SCSI Commands, Revision 2,

Section 5.1.5.3. SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 40

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy transition into the uninitialized state of operation. This is analogous to restoring the module to the factory default state.

11.3 Sanitization

The Zeroization service may be invoked to destroy all SSPs and render the module inoperable. Mitigation of Other Attacks Policy The Module does not support the mitigation of other attacks outside the scope of FIPS 140-3. SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 41
AcronymFull Specification Name
[FIPS140-3]Security Requirements for Cryptographic Modules, March 22, 2019
[ISO19790]International Standard, ISO/IEC 19790, Information technology — Security techniques — Test requirements for cryptographic modules, Third edition, March 2017
[ISO24759]International Standard, ISO/IEC 24759, Information technology — Security techniques — Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015
[180-4]NIST, Secure Hash Standard, FIPS Publication 180-4, August 2015
[186-4]NIST, Digital Signature Standard (DSS), FIPS Publication 186-4, July 2013
[197]NIST, Advanced Encryption Standard (AES), FIPS Publication 197, November 26, 2001
[198-1]NIST, The Keyed-Hash Message Authentication Code (HMAC), FIPS Publication 198-1, July 2008
[IG]NIST, Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, last updated October 7, 2022
[NVMe]Standard spec available online https://nvmexpress.org/wp-content/uploads/NVM-Express- 1_3c-2018.05.24-Ratified.pdf Revision 1.3C May 24, 2018
[PKCS#1]PKCS #1 v2.1: RSA Cryptography Standard, RSA Laboratories, June 14, 2002
[SFSC]Information technology – Security Features for SCSI Commands (SFSC)
[38A]NIST Special Publication 800-38A, Recommendation for Block Cipher Modes of Operation, December 2001
[38E]NIST Special Publication 800-38E, Recommendation for Block Cipher Modes of Operation: The XTS-AES Mode for Confidentiality on Storage Devices, January 2010
[38F]NIST Special Publication 800-38F, Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping, December 2012
[90Ar1]National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A Revision 1, June 2015.
[90B]National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018.
[132]NIST Special Publication 800-132, Recommendation for Password-Based Key Derivation, December 2010
[133r2]NIST Special Publication 800-133 Revision 2, Recommendation for Cryptographic Key Generation, June 2020
[TCG Core]TCG Storage Architecture Core Specification, version 2.01 Revision 1.0, 5 August 2015
[TCG Opal]TCG Storage Security Subsystem Class: Opal Specification, Version 2.01 Revision 1.00, 5 August 2015
[TCG SIIS]TCG Storage Interface Interactions Specification (SIIS), Version .08, 14 August 2018

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy References and Definitions The following standards are referred to in this Security Policy Table 17: References SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 42
AcronymFull Specification Name
[TCG ADS]TCG Storage Opal SSC Feature Set: Additional Datastore Tables Specification, Version 1.00 Revision 1.00, 24 February 2012
[TCG SUM]TCG Storage Opal SSC Feature Set: Single User Mode Specification, Version 1.00 Revision 2.00, 5 August 2015
[TCG PSID]TCG Storage Opal SSC Feature Set: PSID, Version 1.00 Revision 1.00, 5 August 2015
[TCG Block SID]TCG Storage Feature Set: Block SID Authentication, Version 1.00 Final, Revision 1.00, 5 August 2015
[IEEE 1667]IEEE Std 1667-2018 – IEEE Standard for Discovery, Authentication, and Authorization in Host Attachments of Storage Devices, February 2018
AcronymDefinition
ACEAccess Control Elements
AESAdvanced Encryption Standard
APTAdaptive Proportion Test
COCryptographic Officer
CSPCritical Security Parameter, see [FIPS 140-3]
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book mode of AES Encryption/Decryption
KATKnown Answer Test
PBKDFPassword Based Key Derivation Function
LBALogical Block Address
MSIDManufactured Security Identifier
MEKMedia Encryption Key
NVMeNon-Volatile Memory express
PBKDFPassword Based Key Derivation Function
PCIePeripheral Component Interconnect Express
PSPPublic Security Parameter
PINPersonal Identification Number (or Password)
PSIDPhysical Security Identifier
RCTRepetitive Count Test
RSARivest Shamir Adleman
SHASecure Hash Algorithm
SEDSelf-Encrypting Drive
SIDSecurity Identifier
SSDSolid-state Drive
SSCSecurity Subsystem Class
TCGTrusted Computing Group
UIDUnique Identifier
VUVendor Unique

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy Table 18: Acronyms and Definitions SK hynix Public Material – May be reproduced only in its original entirety (without revision).

Page 43

XTS

XEX Tweakable Block Cipher with Cipher text Stealing

SK hynix PE9110 E1.S and PE9010 M.2 22110D FIPS 140-3 Security Policy SK hynix Public Material – May be reproduced only in its original entirety (without revision).