| Standard | FIPS 140-3 |
|---|---|
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Status | Active |
| Sunset date | 1/6/2027 |
| Caveat | Interim validation. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs |
| Vendor | Ampex Data Systems Corporation |
flowchart LR
%% Deterministic review-risk graph for TuffServ® Encryption Module (TSEM)
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>Recovery</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3 clue;
class I2,I3 infer;
class R2,R3 risk;
class E2,E3 evidence;flowchart LR
%% Deterministic clue tier for TuffServ® Encryption Module (TSEM)
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>Recovery</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3 clueLow;Ampex Data Systems Corporation TuffServ® Encryption Module (TSEM) Document Version 1.11 May 29, 2024 Prepared for: Prepared by: Ampex Data Systems Corporation KeyPair Consulting Inc.
Hayward, CA 94545 San Luis Obispo, CA 93401 ampex.com keypair.us +1 650.367.2011 +1 805.316.5024
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table of Contents
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy List of Tables
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy List of Figures
| Section | Title | Security Level |
|---|---|---|
| 1 | General | 2 |
| 2 | Cryptographic module specification | 2 |
| 3 | Cryptographic module interfaces | 2 |
| 4 | Roles, services, and authentication | 2 |
| 5 | Software/Firmware security | 2 |
| 6 | Operational environment | N/A |
| 7 | Physical security | 2 |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 2 |
| 10 | Self-tests | 2 |
| 11 | Life-cycle assurance | 3 |
| 12 | Mitigation of other attacks | N/A |
| Overall Level | 2 |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy
This document defines the Security Policy for the TuffServ® Encryption Module by Ampex, hereafter denoted the “TSEM”. The TSEM:
Purpose and Use: The hardware TSEM is a multichip embedded embodiment in FIPS 140-3 terminology. The TSEM provides cryptographic key management services for the TuffServ® secure storage device. Module Type: Hardware Module Embodiment: MultiChipEmbed
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Cryptographic Boundary: The Tested Operational Environment’s Physical Perimeter (TOEPP) is depicted in Figure
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Figure 2: Block Diagram
| Model and/or Part Number | Hardware Version | Firmware Version | Processors | Features |
|---|---|---|---|---|
| TSEM | 1320249-010 Rev A | 1.1.16 | NXP K81 (ARM Cortex M4) | N/A - only one TSEM model exists. |
Mode Name Approved Mode
Description Approved mode of operation
Type Approved
Status Indicator
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-XTS Testing Revision 2.0 | A2914 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38E |
| AES-ECB | A2921 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-KW | A2921 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38F |
| AES-ECB | A3009 | Direction - Decrypt, Encrypt Key Length - 128, 256 | SP 800-38A |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy
Tested Module Identification
N/A for this Module. Modes List and Description: Table 3: Modes List and Description The TSEM supports only an Approved mode of operation, with no configuration necessary to operate and remain in the Approved mode. The TSEM design corresponds to the TSEM security rules specified in Section 11.4.
Approved Algorithms: Cipher Table 4: Approved Algorithms - Cipher
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| ECDSA SigVer (FIPS186-4) | A2921 | Curve - P-384 Hash Algorithm - SHA2-384 | FIPS 186-4 |
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| Hash DRBG | A2921 | Prediction Resistance - No Mode - SHA2-256 | SP 800-90A Rev. 1 |
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| HMAC-SHA2-384 | A2921 | Key Length - Key Length: 256 | FIPS 198-1 |
| Algorithm | CAVP Cert P | roperties | Reference |
|---|---|---|---|
| KDF SP800-108 | A2921 K S | DF Mode - Counter upported Lengths - Supported Lengths: 256 | SP 800-108 Rev. 1 |
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| SHA2-256 | A2921 | Message Length - Message Length: 256-2048 Increment 128 | FIPS 180-4 |
| SHA2-384 | A2921 | Message Length - Message Length: 256-2048 Increment 128 | FIPS 180-4 |
| Name | Properties | Implementation | Reference |
|---|---|---|---|
| CKG Section 4 | Key Type:Symmetri | c TSEM Cryptographic Library | NIST, SP 800-133 Rev. 2 |
| CKG Section 6.1 | Key Type:Symmetri | c TSEM Cryptographic Library | NIST, SP 800-133 Rev. 2 |
| CKG Section 6.2 | Key Type:Symmetri | c TSEM Cryptographic Library | NIST, SP 800-133 Rev. 2 |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Signature Table 5: Approved Algorithms - Signature Random Table 6: Approved Algorithms - Random Message authentication Table 7: Approved Algorithms - Message authentication Key derivation Table 8: Approved Algorithms - Key derivation Message digest Table 9: Approved Algorithms - Message digest Vendor-Affirmed Algorithms: Table 10: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this Module.
| Name Cipher CKG Section 4 CKG Section 6.1 | Type BC-UnAuth CKG CKG | Description AES-XTS encryption and decryption for data storage Using the Output of a Random Bit Generator Direct Generation of Symmetric Keys | Properties | Algorithms AES-XTS Testing Revision 2.0 AES-ECB CKG Section 4 CKG Section 6.1 |
|---|---|---|---|---|
| KTS | KTS-Wrap | SP 800-38F. KTS (key wrapping | KTS:256 bit keys providing 256 bits of encryption strength | AES-KW |
| and unwrapping) per IG D.G | AES-ECB | |||
| Signature ECDSA | DigSig-SigVer | Signature verification | ECDSA SigVer (FIPS186-4) SHA2-384 | |
| Key derivation | CKG KBKDF MAC | Key-based key derivation | HMAC-SHA2-384 | |
| (KBKDF) for key establishment. | SHA2-384 KDF SP800-108 CKG Section 4 CKG Section 6.2 | |||
| Random | CKG ENT-P | Generate random value | Hash DRBG SHA2-256 |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this Module. Non-Approved, Not Allowed Algorithms: N/A for this Module.
Table 11: Security Function Implementations
In accordance with SP 800-38E, the XTS-AES algorithm is to be used for confidentiality on storage devices. The TSEM complies with FIPS 140-3 IG C.I by:
| Name | Type | Operational Environment | Sample Size | Entropy per Sample | Conditioning Component |
|---|---|---|---|---|---|
| ENT K81 | Physical | K81 | 1024 bytes | 811 bits | N/A |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy
Table 12: Entropy Sources The entropy source does not have an ESV certificate. In accordance with FIPS 140-3 IG 9.3.A option 1(a), the TSEM generates ENT within the module boundary using a SP 800-90B compliant ENT (P) present on the SoC component. Per SP 800-90A Rev. 1 Table 2, the SHA2-256 Hash_DRBG requires 256 bits of entropy (equivalent to security strength) within the 440-bit DRBG_Seed value. As input to the SP 800-90A Rev. 1 Hash_df, the TSEM collects 1024 bytes of data from the ENT (P) to use as entropy and nonce input. The SP 80090B compliant assessment supports at least 0.099 bits of entropy per bit of ENT (P) output; as such the DRBG seeding material contains at least 811 bits of entropy, well in excess of the requirement for generating the largest key size of 256 bits.
The TSEM performs symmetric key generation per FIPS 140-3 IG D.H (direct output of the DRBG):
Key agreement: N/A for this Module. Key transport: The Module uses AES-KW with AES-256, which provides 256 bits of strength. This is an Approved key transport method compliant with SP 800-38F and FIPS 140-3 IG D.G.
| Physical Port | Logical Interface(s) | Data That Passes |
|---|---|---|
| P1: USB1.1 – full speed, 12 MB/s Dedicated Virtual Serial Port over USB. | Data Input Data Output Control Input Status Output | Proprietary control plane commands and responses to and from host (TSEM configuration and control). Does not respond as a general-purpose USB port. |
| P1: SATA III I/O | Data Input Data Output Control Input Control Output Status Output | Data plane: interaction between host and drive media via controller. SATA commands/responses/status to/from host. Plaintext Data In/Out (from/to host). Ciphertext Data Out/In (to/from media). |
| P1: RESETN TSEM reset input, active low | Control Input | Low pulse results in TSEM reset. |
| P1: Power and ground connections | Power | N/A |
| Method Name | Description | Security Mechanism | Strength Each Attempt | Strength per Minute |
|---|---|---|---|---|
| PIK Provided | Receipt of PIK by a provisioned TSEM provides role-based authentication of an operator in | KDF SP800- 108 | 1/(2^256) = | (60*100,000,000)/(2^256) = 5.2E-70 |
| the User role. The 256-bit PIK is used to derive the 256-bit TIK, which in turn is used to unwrap the TMK. Success of the TMK key unwrap authenticates the caller and unlocks the TSEM, moving it to the Operational state. | 8.6E-78 |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy
Table 13: Ports and Interfaces The P1 connector, shown in Figure 1, is the only physical port of the TSEM. It incorporates all of the specified interfaces.
| Method Name | Description | Security Mechanism | Strength Each Attempt | Strength per Minute |
|---|---|---|---|---|
| Signature Verification | Verification of signed command (ECDSA P-384 / SHA-384). All commands that require CO | Signature ECDSA | 1/(2^192) = | (60*100,000,000)/(2^192) = 9.6E-51 |
| authentication include a corresponding authentication block (signature value) in the command. The value must be verified for the command to be executed. | 1.6E-58 |
| Name | Type | Operator Type | Authentication Methods |
|---|---|---|---|
| CO | Role | CO | Signature Verification |
| User | Role | User | PIK Provided |
| Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Initialize | Power-on initialization, including DRBG instantiate and Built-In Test (BIT) with CASTs and FW integrity. | None | None (automatic | CPSW (on first command) | Random | Unauthenticated |
| invocation at power-on / | - DRBG_EI: G,E,Z | |||||
| reset). | - DRBG_C: G,W - DRBG_V: G,W - DRBG_Seed: G,E,Z | |||||
| create_keys | Derive TIK from PIK. Use TIK to obtain KEK. Generate DEKs (compliant with SP800-133r2 CKG) and wrap using KEK. Return wrapped DEKs. | TSEM_STATUS_OK or error code | create_keys command | CPSW; eDEK | Cipher CKG Section 4 CKG Section 6.1 KTS Signature ECDSA Key derivation | CO |
| packet, PIK, command | - COA Public: E | |||||
| signature. | - PIK: W,E,Z - TIK: G,E,Z - TMK: G,E - KEK: G,E,Z - DRBG_C: W,E - DRBG_V: W,E - DEK: G,R,Z | |||||
| create_random | Obtain a random value. | TSEM_STATUS_OK or error code | create_random command | CPSW; random value | Random CKG Section 4 | Unauthenticated |
| packet . | - DRBG_EI: G,E,Z - DRBG_C: G,W |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 14: Authentication Methods
Table 15: Roles The CO and the User roles are implicitly identified by the service requested.
| Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access - DRBG_Seed: G,E,Z |
|---|---|---|---|---|---|---|
| destroy | Halt and reset SATA controllers. Destroy CSPs | TSEM_STATUS_OK or error code | destroy command packet, | CPSW | Signature ECDSA | CO |
| in local memory and NVM. | command signature. | - COA Public: E,Z - DEK: Z - TMK: Z - DRBG_C: Z - DRBG_EI: Z - DRBG_Seed: Z - DRBG_V: Z - KEK: Z - PIK: Z - TIK: Z | ||||
| do_bit | Perform built-in test (including FIPS 140 self- | TSEM_STATUS_OK or error code | do_bit command packet, | CPSW; self-test results | None | Unauthenticated |
| tests). | self-test selection. | |||||
| get_bit_results | Obtain status of the most recent built-in tests. | TSEM_STATUS_OK | get_bit_results command packet, self-test selection. | CPSW; self-test results | None | Unauthenticated |
| nop | Check TSEM responsiveness without | TSEM_STATUS_OK | nop command; no | CPSW | None | Unauthenticated |
| performing an operation. | additional input. | |||||
| provision | Derive TIK from PIK. Wrap TMK using TIK. | TSEM_STATUS_OK or error code | provision command | CPSW | Signature ECDSA Key derivation | CO |
| eTMK refers to the wrapped TMK. | packet, PIK, TMK, | - COA Public: E | ||||
| command signature. | - PIK: W,E,Z - TIK: G,E,Z - TMK: W,Z | |||||
| put_keys | Derive TIK from PIK. Use TIK to obtain KEK. | TSEM_STATUS_OK or error code | put_keys command | CPSW | Cipher CKG Section 4 CKG Section 6.1 KTS Signature ECDSA Key derivation | CO |
| Use KEK to unwrap DEK. Update SATA | packet, PIK, command | - COA Public: E | ||||
| controller. | signature. | - PIK: W,E,Z - TIK: G,E,Z - TMK: G,E - KEK: G,E,Z - DEK: G,R,Z | ||||
| SATA reset | Reset the SATA controllers. | SATA_OK | SATA reset command. | CPSW. | None | Unauthenticated |
| status | Return status, name, version. | TSEM_STATUS_OK | This service is not authenticated per FIPS140-3_IG 4.1.A. | CPSW; TSEM name, status, version info | None | Unauthenticated |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy G,E,Z
| Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| read | Read decrypted data from media. | SATA_OK or error | SATA read command | SATA response, data from storage | Cipher | User |
| code | input. | - DEK: E | ||||
| write | Write encrypted data to media. | SATA_OK or error | SATA write command | SATA response | Cipher | User |
| code | input, data to storage. | - DEK: E | ||||
| Media control | Non-cryptographic SATA commands. | SATA_OK or error | SATA media control | SATA response | None | Unauthenticated |
| code | command input. |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 16: Approved Services The TSEM supports two status mechanisms: nop returns minimal status information, status returns additional information. A return code of 0 represents a state without errors. Any other return code is the specific function error of the TSEM. The phrase “self-test selection” in do_bit and get_bit_results commands refers to an enumerated target of self-tests, which can specify the firmware integrity test, subsets of CASTs or SATA controller self-tests. “BIT” refers to built-in tests. eDEK and eTMK refer to the wrapped set of AES XTS (DEK) keys or wrapped TMK, respectively. CPSW (control plane status word): the Approved mode indicator and success or failure (enumerated) status. The Indicator column above shows all possible (success or failure) indicator values. The TSEM is a slave device and as such can return status only when it receives a command. If the TSEM fails any CAST or firmware integrity test, it will respond as described in Section 10.4. The return code TSEM_STATUS_OK confirms normal successful completion of the command in the Approved mode, similar to FIPS 140-3 IG 2.4.C example scenario 2, a global indicator for modules having Approved services only. The relationship of SSPs and security functions is detailed next, using the following notation based on the cited specifications: SP 800-38F Authenticated encryption: Ciphertext (wrapped) Key = KW-AE (Wrapping Key, Plaintext Key). SP 800-38F Authenticated decryption: Plaintext key = KW-AD (Wrapping Key, Ciphertext (wrapped) Key). SP 800-90A Rev. 1 DRBG Generate (Length): generate Length random bits. SP 800-108 Rev. 1 Key Based Key Derivation Function (KBKDF) used to derive symmetric Key Material from a Key Derivation Key. The TSEM uses the Counter mode with HMAC as PRF. Key Material = KBKDF (Key Derivation Key, Label, Context, Length)
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy [2] TIK = KBKDF (PIK): Derive TIK from PIK. [3] TMK = KW-AD (TIK, eTMK): Use TIK to obtain KEK. [4] KEK = KBKDF (TMK). Generate DEKs and wrap using KEK. Return wrapped DEKs. (eDEK refers to the wrapped DEK.) [5] DEK = DRBG Generate. [6] Verify AES XTS non-equal. [7] eDEK = KW-AE(KEK, DEK). create_random Performs a DRBG generate. DRBG_EI is used to seed as required. Random generation updates the DRBG_State. destroy [1] Verify command (with COA Public). [2] Halt / reset SATA controllers. [3] Overwrite RAM CSPs. [4] Erase NVM CSPs. do_bit, get_bit_results, nop, status and Media control do not utilize approved security functions or access SSPs. The term “bit” refers to built-in self-test functionality. The nop command provides a mechanism to check simple status; the status command provides extended status information, including name and version correlatable to the CMVP listing (as required by ISO/IEC 19790:2012 AS04.13). The status command response (intended for use by the host device driver) is a binary structure encoded in Base64 for transfer. When translated to ASCII, the response includes the module name (“TSEM”) as well as version information for the SoC and the SATA controllers. provision [1] Verify command (COA Public). [2] TIK = KBKDF (PIK): Derive TIK from PIK. [3] eTMK = KW-AE (TIK, TMK): Wrap TMK using TIK. (eTMK refers to the wrapped TMK.) put_keys Update SATA controller. [1] Verify command (COA Public). [2] TIK = KBKDF (PIK): Derive TIK from PIK. [3] TMK = KW-AD (TIK, eTMK): Use TIK to obtain KEK. [4] KEK = KBKDF (TMK): Derive KEK from TMK. [5] DEK = KW-AD (KEK, eDEK): Use KEK to unwrap DEK. [6] Verify AES XTS key constituents are non-equal. [7] Update SATA controller DEK.
| Mechanism | Inspection Frequency | Inspection Guidance |
|---|---|---|
| Enclosure tamper | Seals should be inspected during maintenance operations and when | The tamper seals are within recessed seal guides. Inspect tamper |
| seals (qty. 2) | circumstances dictate (e.g., if tampering is suspected). | seals for evidence of lifted edges or excessive wear. |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy SATA reset Resets the SATA engine hardware, zeroizing the DEK SSPs in both channels. The DEK keys are erased from SATA controller registers but remain intact in the TSEM RAM. read Decrypts the data using AES-XTS; supports 2 channels of decryption with separate keys. Write Encrypts the data using AES-XTS; supports 2 channels of encryption with separate keys.
The TSEM uses ECDSA P-384 SHA2-384 signature verification performed over all module firmware as the integrity technique.
The operator can initiate the integrity test on demand by power cycling the module or by issuing the do_bit command.
Type of Operational Environment: Non-Modifiable
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 17: Mechanisms and Actions Required The hardware TSEM is a multichip embedded embodiment packaged in a metal enclosure. The metal enclosure is protected by two (2) tamper seals placed within the seal guides (milled sections on the enclosure), as shown in Error! Reference source not found.. The metal enclosure is opaque in the visible spectrum. Ampex maintains control over the tamper seals, which may only be applied or replaced in the factory setting. Figure 4: Location of Tamper Seal #1 (Top Edge) Figure 3: Location of Tamper Seals (Front) Figure 5: Location of Tamper Seal #2 (Bottom Edge)
| Storage Area Name | Description | Persistence Type |
|---|---|---|
| SoC FW NVM | Firmware image stored in SoC Non-volatile memory (flash) | Static |
| SoC RAM | SoC RAM | Dynamic |
| SATA CTL register | SATA CTL register | Dynamic |
| SoC NVM | SoC CFG Non-volatile memory (flash) | Static |
| Name Ampex facility | From Entered in Ampex maintenance facility. | To SoC FW NVM | Format Type Plaintext | Distribution Type N/A | Entry Type N/A | SFI or Algorithm |
|---|---|---|---|---|---|---|
| Encrypted input parameter | External source | SATA CTL register | Encrypted | Automated | Electronic | KTS |
| Encrypted output parameter | SATA CTL register | External source | Encrypted | Automated | Electronic | KTS |
| Plaintext input parameter | External source | SoC RAM | Plaintext | Automated | Electronic |
| Zeroization Method | Description | Rationale | Operator Initiation |
|---|---|---|---|
| After use | Overwritten by zeros after use | Overwritten with zeros | Module code enforces zeroization after use |
| Power Cycle | Overwritten by zeros upon loss of power | Overwritten with zeros | Operator can remove power from the modul |
| Destroy | Overwritten by zeros by Destroy service | Overwritten with zeros | Operator calls the destroy service |
Name COA Public
Description Verification of CO operator commands.
Size - Strength Size: 384 - Strength: 192
Type - Category G ECDSA P-384 - PSP
enerated By
Established By
Used By Signature ECDSA
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy
Table 19: SSP Input-Output Methods
Table 20: SSP Zeroization Methods TSEM code destroys all plaintext CSPs prior to return from any control plane command.
Name DEK DRBG_C DRBG_EI DRBG_Seed DRBG_V KEK PIK TIK TMK
Description AES XTS data encryption keys (DEKC1, DEKC2, DEKD1, DEKD2). DRBG state value C. DRBG Entropy Input (inclusive of nonce). DRBG Seed (required per CMVP SSP conventions). DRBG state value V. AES-256 key used to wrap DEK keys. Platform Identity Key, used to derive TIK which unwraps TMK; success authenticates host to TSEM. TSEM Identity Key: used to wrap the TMK. TSEM Master Key: AES-256 key used to derive KEK.
Size - Strength Size: 256 - Strength: 256 Size: 440 - Strength: 256 Size: 1024 - Strength: 256 Size: 440 - Strength: 256 Size: 440 - Strength: 256 Size: 256 - Strength: 256 Size: 256 - Strength: 256 Size: 256 - Strength: 256 Size: 256 - Strength: 256
Type - Category Symmetric - CSP Hash_DRBG_C - CSP Entropy input - CSP DRBG_Seed - CSP Hash_DRBG_V - CSP Symmetric - CSP Symmetric - CSP Symmetric - CSP Symmetric - CSP
Generated By CKG Section 4 CKG Section 6.1 Hash DRBG Hash DRBG Hash DRBG Key derivation Key derivation
Established By
Used By Cipher Hash DRBG Hash DRBG Hash DRBG Hash DRBG KTS Key derivation KTS Key derivation
| Name COA Public | Input - Output Ampex facility | Storage SoC NVM:Plaintext | Storage Duration Call lifetime | Zeroization Destroy | Related SSPs |
|---|---|---|---|---|---|
| DEK | Encrypted input parameter | SoC RAM:Plaintext | Call lifetime | After use | KEK:Wrapped By |
| Encrypted output parameter | SATA CTL register:Plaintext | Power Cycle Destroy | |||
| DRBG_C | SoC RAM:Plaintext | Module uptime | After use Power Cycle Destroy | DRBG_V:Used With DRBG_Seed:Derived From | |
| DRBG_EI | SoC RAM:Plaintext | Module uptime | After use Power Cycle Destroy | DRBG_Seed:Incorporated Into | |
| DRBG_Seed | SoC RAM:Plaintext | Module uptime | After use Power Cycle Destroy | DRBG_EI:Constituent DRBG_C:Derives DRBG_V:Derives |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy 6.1 Table 21: SSP Table 1
| Name DRBG_V KEK | Input - Output | Storage SoC RAM:Plaintext SoC RAM:Plaintext | Storage Duration Module uptime Call lifetime | Zeroization After use Power Cycle Destroy After use Power Cycle Destroy | Related SSPs DRBG_C:Used With DRBG_Seed:Generated From TMK:Derived From DEK:Wraps |
|---|---|---|---|---|---|
| PIK | Plaintext input parameter | SoC RAM:Plaintext | Call lifetime | After use Power Cycle Destroy | TIK:Derives |
| TIK | SoC RAM:Plaintext | Call lifetime | After use Power Cycle Destroy | PIK:Derived From TMK:Wrapped By | |
| TMK | Plaintext input parameter | SoC NVM:Encrypted | Call lifetime | Destroy | TIK:Wraps |
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details |
|---|---|---|---|---|---|
| FW Integrity | ECDSA P-384 #A2921 | Signature verification performed over all TSEM firmware at power-up. | SW/FW Integrity | TSEM_STATUS_OK | Verify |
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| AES-XTS Testing Revision 2.0 | 256-bit | KAT | CAST | TSEM_STATUS_OK | Encrypt | Performed on module load. |
| AES-XTS Testing Revision 2.0 | 256-bit | KAT | CAST | TSEM_STATUS_OK | Decrypt | Performed on module load. |
| AES-KW | 256-bit | KAT | CAST | TSEM_STATUS_OK | Forward cipher | Performed on module load. |
| AES-KW | 256-bit | KAT | CAST | TSEM_STATUS_OK | Inverse cipher | Performed on module load. |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 22: SSP Table 2
Table 23: Pre-Operational Self-Tests The corresponding ECDSA signature verification CAST is performed prior to the integrity test.
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| ECDSA SigVer (FIPS186-4) | P-384 SHA2- 384 | KAT | CAST | TSEM_STATUS_OK | Signature verification | Performed on module load prior to firmware integrity test. |
| Hash DRBG | SHA2-256 | KAT | CAST | TSEM_STATUS_OK | Instantiate, generate, reseed | Performed on module load. |
| KDF SP800-108 | HMAC-SHA2- 384 | KAT | CAST | TSEM_STATUS_OK | SP800-108r1 Section 4.1 KAT for a Counter Mode KDF | Performed on module load. |
| SHA2-384 (A2921) | SHA2-384 | KAT | CAST | TSEM_STATUS_OK | Hash | Performed on module load. |
| ENT (P) Self-tests | 90B Self-tests | CAST | CAST | TSEM_STATUS_OK | 90B Health Tests | Performed on module load, power cycle or do_bit service invocation. |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| FW Integrity | Signature verification performed over all TSEM firmware at power-up. | SW/FW Integrity | On demand | Power cycle or do_bit |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| AES-XTS Testing Revision 2.0 | KAT | CAST | On demand | Power cycle or do_bit |
| AES-XTS Testing Revision 2.0 | KAT | CAST | On demand | Power cycle or do_bit |
| AES-KW | KAT | CAST | On demand | Power cycle or do_bit |
| AES-KW | KAT | CAST | On demand | Power cycle or do_bit |
| ECDSA SigVer (FIPS186-4) | KAT | CAST | On demand | Power cycle or do_bit |
| Hash DRBG | KAT | CAST | On demand | Power cycle or do_bit |
| KDF SP800-108 | KAT | CAST | On demand | Power cycle or do_bit |
| SHA2-384 (A2921) | KAT | CAST | On demand | Power cycle or do_bit |
| ENT (P) Self-tests | CAST | CAST | Each use | Continuously running |
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| ERROR state | Self-test failure error stat | e If one of the KATs fails or integrity test fails | Power-cycle | Non-zero return status |
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 24: Conditional Self-Tests All cryptographic algorithm self-tests (CASTs) must complete successfully prior to any other use of cryptography by the TSEM. Table 25: Pre-Operational Periodic Information Table 26: Conditional Periodic Information
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 27: Error States If one of the CASTs fails, the TSEM enters the ERROR state. The error state is persistent, and only Status services are available. All attempts to use the TSEM’s services result in the return of a non-zero error code in the range -40 (TSEM_ERROR_CYBER) to -47 (TSEM_ERROR_CYBER_LYCAN2).
The TSEM automatically invokes all self-tests on each power-on or reset. The conditional self-tests may also be invoked on demand by the Self-Test service do_bit command; detailed results are available using the Self-Test service get_BITResults command.
The TSEM is a subsystem of the TuffServ® product and is not intended for use in other settings. The TSEM User and CO Guide documents all procedures for the following:
The TSEM User and CO Guide is inclusive of all information required per ISO/IEC 19790:2012 Section 7.11.9.
The TSEM User and CO Guide is inclusive of all information required per ISO/IEC 19790:2012 Section 7.11.9.
The TSEM enforces the following security rules:
TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy
The TSEM User and CO Guide documents all procedures for decommissioning and sanitization of the TSEM.