All modules
CMVP Validated Module · FIPS 140-3 Security Policy

TuffServ® Encryption Module (TSEM)

Certificate#4938StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorAmpex Data Systems Corporation
Medium review priority  ·  no TCB surface named  ·  last validated 18 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date1/6/2027
CaveatInterim validation. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorAmpex Data Systems Corporation

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for TuffServ® Encryption Module (TSEM)
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3 clue;
  class I2,I3 infer;
  class R2,R3 risk;
  class E2,E3 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for TuffServ® Encryption Module (TSEM)
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3 clueLow;

Security Policy, page by page

Page 1

Ampex Data Systems Corporation TuffServ® Encryption Module (TSEM) Document Version 1.11 May 29, 2024 Prepared for: Prepared by: Ampex Data Systems Corporation KeyPair Consulting Inc.

26460 Corporate Avenue, Suite 200 987 Osos Street

Hayward, CA 94545 San Luis Obispo, CA 93401 ampex.com keypair.us +1 650.367.2011 +1 805.316.5024

Page 2

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table of Contents

Page 3

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy List of Tables

Page 4

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy List of Figures

Page 5
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance3
12Mitigation of other attacksN/A
Overall Level2

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy

1.1 Overview

This document defines the Security Policy for the TuffServ® Encryption Module by Ampex, hereafter denoted the “TSEM”. The TSEM:

1.2 Security Levels
2.1 Description

Purpose and Use: The hardware TSEM is a multichip embedded embodiment in FIPS 140-3 terminology. The TSEM provides cryptographic key management services for the TuffServ® secure storage device. Module Type: Hardware Module Embodiment: MultiChipEmbed

Page 6

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Cryptographic Boundary: The Tested Operational Environment’s Physical Perimeter (TOEPP) is depicted in Figure

  1. The cryptographic boundary is the metal enclosure and the P1 connector on the back of the enclosure. The enclosure opening for the P1 connector does not expose any circuitry except for the P1 connector and associated traces or decoupling capacitors. Front of Module Back of Module with P1 Connector Top of Module (Location of Tamper Seal #1) Bottom of Module (Location of Tamper Seal #2) Figure 1: TSEM Physical Perimeter The TSEM logical functionality (outlined in red) in the context of the larger TuffServ® product is shown in Figure
  2. The two SATA controllers (SATA CTL) implement all data plane functionality, including AES XTS data encryption and decryption to and from the storage media. The SoC implements control plane functionality, such as module initialization, configuration, and provisioning. All TSEM firmware is contained within the boundary.
Page 7

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Figure 2: Block Diagram

Page 8
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
TSEM1320249-010 Rev A1.1.16NXP K81 (ARM Cortex M4)N/A - only one TSEM model exists.

Mode Name Approved Mode

Description Approved mode of operation

Type Approved

Status Indicator

AlgorithmCAVP CertPropertiesReference
AES-XTS Testing Revision 2.0A2914Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
AES-ECBA2921Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-KWA2921Direction - Decrypt, Encrypt Key Length - 256SP 800-38F
AES-ECBA3009Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

N/A for this Module. Modes List and Description: Table 3: Modes List and Description The TSEM supports only an Approved mode of operation, with no configuration necessary to operate and remain in the Approved mode. The TSEM design corresponds to the TSEM security rules specified in Section 11.4.

2.5 Algorithms

Approved Algorithms: Cipher Table 4: Approved Algorithms - Cipher

Page 9
AlgorithmCAVP CertPropertiesReference
ECDSA SigVer (FIPS186-4)A2921Curve - P-384 Hash Algorithm - SHA2-384FIPS 186-4
AlgorithmCAVP CertPropertiesReference
Hash DRBGA2921Prediction Resistance - No Mode - SHA2-256SP 800-90A Rev. 1
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2-384A2921Key Length - Key Length: 256FIPS 198-1
AlgorithmCAVP Cert PropertiesReference
KDF SP800-108A2921 K SDF Mode - Counter upported Lengths - Supported Lengths: 256SP 800-108 Rev. 1
AlgorithmCAVP CertPropertiesReference
SHA2-256A2921Message Length - Message Length: 256-2048 Increment 128FIPS 180-4
SHA2-384A2921Message Length - Message Length: 256-2048 Increment 128FIPS 180-4
NamePropertiesImplementationReference
CKG Section 4Key Type:Symmetric TSEM Cryptographic LibraryNIST, SP 800-133 Rev. 2
CKG Section 6.1Key Type:Symmetric TSEM Cryptographic LibraryNIST, SP 800-133 Rev. 2
CKG Section 6.2Key Type:Symmetric TSEM Cryptographic LibraryNIST, SP 800-133 Rev. 2

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Signature Table 5: Approved Algorithms - Signature Random Table 6: Approved Algorithms - Random Message authentication Table 7: Approved Algorithms - Message authentication Key derivation Table 8: Approved Algorithms - Key derivation Message digest Table 9: Approved Algorithms - Message digest Vendor-Affirmed Algorithms: Table 10: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this Module.

Page 10
Name Cipher CKG Section 4 CKG Section 6.1Type BC-UnAuth CKG CKGDescription AES-XTS encryption and decryption for data storage Using the Output of a Random Bit Generator Direct Generation of Symmetric KeysPropertiesAlgorithms AES-XTS Testing Revision 2.0 AES-ECB CKG Section 4 CKG Section 6.1
KTSKTS-WrapSP 800-38F. KTS (key wrappingKTS:256 bit keys providing 256 bits of encryption strengthAES-KW
and unwrapping) per IG D.GAES-ECB
Signature ECDSADigSig-SigVerSignature verificationECDSA SigVer (FIPS186-4) SHA2-384
Key derivationCKG KBKDF MACKey-based key derivationHMAC-SHA2-384
(KBKDF) for key establishment.SHA2-384 KDF SP800-108 CKG Section 4 CKG Section 6.2
RandomCKG ENT-PGenerate random valueHash DRBG SHA2-256

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this Module. Non-Approved, Not Allowed Algorithms: N/A for this Module.

2.6 Security Function Implementations

Table 11: Security Function Implementations

2.7 Algorithm Specific Information

In accordance with SP 800-38E, the XTS-AES algorithm is to be used for confidentiality on storage devices. The TSEM complies with FIPS 140-3 IG C.I by:

Page 11
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
ENT K81PhysicalK811024 bytes811 bitsN/A

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy

2.8 RBG and Entropy

Table 12: Entropy Sources The entropy source does not have an ESV certificate. In accordance with FIPS 140-3 IG 9.3.A option 1(a), the TSEM generates ENT within the module boundary using a SP 800-90B compliant ENT (P) present on the SoC component. Per SP 800-90A Rev. 1 Table 2, the SHA2-256 Hash_DRBG requires 256 bits of entropy (equivalent to security strength) within the 440-bit DRBG_Seed value. As input to the SP 800-90A Rev. 1 Hash_df, the TSEM collects 1024 bytes of data from the ENT (P) to use as entropy and nonce input. The SP 80090B compliant assessment supports at least 0.099 bits of entropy per bit of ENT (P) output; as such the DRBG seeding material contains at least 811 bits of entropy, well in excess of the requirement for generating the largest key size of 256 bits.

2.9 Key Generation

The TSEM performs symmetric key generation per FIPS 140-3 IG D.H (direct output of the DRBG):

2.10 Key Establishment

Key agreement: N/A for this Module. Key transport: The Module uses AES-KW with AES-256, which provides 256 bits of strength. This is an Approved key transport method compliant with SP 800-38F and FIPS 140-3 IG D.G.

2.11 Industry Protocols
Page 12
Physical PortLogical Interface(s)Data That Passes
P1: USB1.1 – full speed, 12 MB/s Dedicated Virtual Serial Port over USB.Data Input Data Output Control Input Status OutputProprietary control plane commands and responses to and from host (TSEM configuration and control). Does not respond as a general-purpose USB port.
P1: SATA III I/OData Input Data Output Control Input Control Output Status OutputData plane: interaction between host and drive media via controller. SATA commands/responses/status to/from host. Plaintext Data In/Out (from/to host). Ciphertext Data Out/In (to/from media).
P1: RESETN TSEM reset input, active lowControl InputLow pulse results in TSEM reset.
P1: Power and ground connectionsPowerN/A
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
PIK ProvidedReceipt of PIK by a provisioned TSEM provides role-based authentication of an operator inKDF SP800- 1081/(2^256) =(60*100,000,000)/(2^256) = 5.2E-70
the User role. The 256-bit PIK is used to derive the 256-bit TIK, which in turn is used to unwrap the TMK. Success of the TMK key unwrap authenticates the caller and unlocks the TSEM, moving it to the Operational state.8.6E-78

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 13: Ports and Interfaces The P1 connector, shown in Figure 1, is the only physical port of the TSEM. It incorporates all of the specified interfaces.

4 Roles, Services, and Authentication
4.1 Authentication Methods
Page 13
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Signature VerificationVerification of signed command (ECDSA P-384 / SHA-384). All commands that require COSignature ECDSA1/(2^192) =(60*100,000,000)/(2^192) = 9.6E-51
authentication include a corresponding authentication block (signature value) in the command. The value must be verified for the command to be executed.1.6E-58
NameTypeOperator TypeAuthentication Methods
CORoleCOSignature Verification
UserRoleUserPIK Provided
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
InitializePower-on initialization, including DRBG instantiate and Built-In Test (BIT) with CASTs and FW integrity.NoneNone (automaticCPSW (on first command)RandomUnauthenticated
invocation at power-on /- DRBG_EI: G,E,Z
reset).- DRBG_C: G,W - DRBG_V: G,W - DRBG_Seed: G,E,Z
create_keysDerive TIK from PIK. Use TIK to obtain KEK. Generate DEKs (compliant with SP800-133r2 CKG) and wrap using KEK. Return wrapped DEKs.TSEM_STATUS_OK or error codecreate_keys commandCPSW; eDEKCipher CKG Section 4 CKG Section 6.1 KTS Signature ECDSA Key derivationCO
packet, PIK, command- COA Public: E
signature.- PIK: W,E,Z - TIK: G,E,Z - TMK: G,E - KEK: G,E,Z - DRBG_C: W,E - DRBG_V: W,E - DEK: G,R,Z
create_randomObtain a random value.TSEM_STATUS_OK or error codecreate_random commandCPSW; random valueRandom CKG Section 4Unauthenticated
packet .- DRBG_EI: G,E,Z - DRBG_C: G,W

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 14: Authentication Methods

4.2 Roles

Table 15: Roles The CO and the User roles are implicitly identified by the service requested.

4.3 Approved Services
Page 14
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - DRBG_Seed: G,E,Z
destroyHalt and reset SATA controllers. Destroy CSPsTSEM_STATUS_OK or error codedestroy command packet,CPSWSignature ECDSACO
in local memory and NVM.command signature.- COA Public: E,Z - DEK: Z - TMK: Z - DRBG_C: Z - DRBG_EI: Z - DRBG_Seed: Z - DRBG_V: Z - KEK: Z - PIK: Z - TIK: Z
do_bitPerform built-in test (including FIPS 140 self-TSEM_STATUS_OK or error codedo_bit command packet,CPSW; self-test resultsNoneUnauthenticated
tests).self-test selection.
get_bit_resultsObtain status of the most recent built-in tests.TSEM_STATUS_OKget_bit_results command packet, self-test selection.CPSW; self-test resultsNoneUnauthenticated
nopCheck TSEM responsiveness withoutTSEM_STATUS_OKnop command; noCPSWNoneUnauthenticated
performing an operation.additional input.
provisionDerive TIK from PIK. Wrap TMK using TIK.TSEM_STATUS_OK or error codeprovision commandCPSWSignature ECDSA Key derivationCO
eTMK refers to the wrapped TMK.packet, PIK, TMK,- COA Public: E
command signature.- PIK: W,E,Z - TIK: G,E,Z - TMK: W,Z
put_keysDerive TIK from PIK. Use TIK to obtain KEK.TSEM_STATUS_OK or error codeput_keys commandCPSWCipher CKG Section 4 CKG Section 6.1 KTS Signature ECDSA Key derivationCO
Use KEK to unwrap DEK. Update SATApacket, PIK, command- COA Public: E
controller.signature.- PIK: W,E,Z - TIK: G,E,Z - TMK: G,E - KEK: G,E,Z - DEK: G,R,Z
SATA resetReset the SATA controllers.SATA_OKSATA reset command.CPSW.NoneUnauthenticated
statusReturn status, name, version.TSEM_STATUS_OKThis service is not authenticated per FIPS140-3_IG 4.1.A.CPSW; TSEM name, status, version infoNoneUnauthenticated

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy G,E,Z

Page 15
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
readRead decrypted data from media.SATA_OK or errorSATA read commandSATA response, data from storageCipherUser
codeinput.- DEK: E
writeWrite encrypted data to media.SATA_OK or errorSATA write commandSATA responseCipherUser
codeinput, data to storage.- DEK: E
Media controlNon-cryptographic SATA commands.SATA_OK or errorSATA media controlSATA responseNoneUnauthenticated
codecommand input.

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 16: Approved Services The TSEM supports two status mechanisms: nop returns minimal status information, status returns additional information. A return code of 0 represents a state without errors. Any other return code is the specific function error of the TSEM. The phrase “self-test selection” in do_bit and get_bit_results commands refers to an enumerated target of self-tests, which can specify the firmware integrity test, subsets of CASTs or SATA controller self-tests. “BIT” refers to built-in tests. eDEK and eTMK refer to the wrapped set of AES XTS (DEK) keys or wrapped TMK, respectively. CPSW (control plane status word): the Approved mode indicator and success or failure (enumerated) status. The Indicator column above shows all possible (success or failure) indicator values. The TSEM is a slave device and as such can return status only when it receives a command. If the TSEM fails any CAST or firmware integrity test, it will respond as described in Section 10.4. The return code TSEM_STATUS_OK confirms normal successful completion of the command in the Approved mode, similar to FIPS 140-3 IG 2.4.C example scenario 2, a global indicator for modules having Approved services only. The relationship of SSPs and security functions is detailed next, using the following notation based on the cited specifications: SP 800-38F Authenticated encryption: Ciphertext (wrapped) Key = KW-AE (Wrapping Key, Plaintext Key). SP 800-38F Authenticated decryption: Plaintext key = KW-AD (Wrapping Key, Ciphertext (wrapped) Key). SP 800-90A Rev. 1 DRBG Generate (Length): generate Length random bits. SP 800-108 Rev. 1 Key Based Key Derivation Function (KBKDF) used to derive symmetric Key Material from a Key Derivation Key. The TSEM uses the Counter mode with HMAC as PRF. Key Material = KBKDF (Key Derivation Key, Label, Context, Length)

Page 16

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy [2] TIK = KBKDF (PIK): Derive TIK from PIK. [3] TMK = KW-AD (TIK, eTMK): Use TIK to obtain KEK. [4] KEK = KBKDF (TMK). Generate DEKs and wrap using KEK. Return wrapped DEKs. (eDEK refers to the wrapped DEK.) [5] DEK = DRBG Generate. [6] Verify AES XTS non-equal. [7] eDEK = KW-AE(KEK, DEK). create_random Performs a DRBG generate. DRBG_EI is used to seed as required. Random generation updates the DRBG_State. destroy [1] Verify command (with COA Public). [2] Halt / reset SATA controllers. [3] Overwrite RAM CSPs. [4] Erase NVM CSPs. do_bit, get_bit_results, nop, status and Media control do not utilize approved security functions or access SSPs. The term “bit” refers to built-in self-test functionality. The nop command provides a mechanism to check simple status; the status command provides extended status information, including name and version correlatable to the CMVP listing (as required by ISO/IEC 19790:2012 AS04.13). The status command response (intended for use by the host device driver) is a binary structure encoded in Base64 for transfer. When translated to ASCII, the response includes the module name (“TSEM”) as well as version information for the SoC and the SATA controllers. provision [1] Verify command (COA Public). [2] TIK = KBKDF (PIK): Derive TIK from PIK. [3] eTMK = KW-AE (TIK, TMK): Wrap TMK using TIK. (eTMK refers to the wrapped TMK.) put_keys Update SATA controller. [1] Verify command (COA Public). [2] TIK = KBKDF (PIK): Derive TIK from PIK. [3] TMK = KW-AD (TIK, eTMK): Use TIK to obtain KEK. [4] KEK = KBKDF (TMK): Derive KEK from TMK. [5] DEK = KW-AD (KEK, eDEK): Use KEK to unwrap DEK. [6] Verify AES XTS key constituents are non-equal. [7] Update SATA controller DEK.

Page 17
MechanismInspection FrequencyInspection Guidance
Enclosure tamperSeals should be inspected during maintenance operations and whenThe tamper seals are within recessed seal guides. Inspect tamper
seals (qty. 2)circumstances dictate (e.g., if tampering is suspected).seals for evidence of lifted edges or excessive wear.

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy SATA reset Resets the SATA engine hardware, zeroizing the DEK SSPs in both channels. The DEK keys are erased from SATA controller registers but remain intact in the TSEM RAM. read Decrypts the data using AES-XTS; supports 2 channels of decryption with separate keys. Write Encrypts the data using AES-XTS; supports 2 channels of encryption with separate keys.

4.4 Non-Approved Services
4.5 External Software/Firmware Loaded
5 Software/Firmware Security
5.1 Integrity Techniques

The TSEM uses ECDSA P-384 SHA2-384 signature verification performed over all module firmware as the integrity technique.

5.2 Initiate on Demand

The operator can initiate the integrity test on demand by power cycling the module or by issuing the do_bit command.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Non-Modifiable

7 Physical Security
7.1 Mechanisms and Actions Required
Page 18

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 17: Mechanisms and Actions Required The hardware TSEM is a multichip embedded embodiment packaged in a metal enclosure. The metal enclosure is protected by two (2) tamper seals placed within the seal guides (milled sections on the enclosure), as shown in Error! Reference source not found.. The metal enclosure is opaque in the visible spectrum. Ampex maintains control over the tamper seals, which may only be applied or replaced in the factory setting. Figure 4: Location of Tamper Seal #1 (Top Edge) Figure 3: Location of Tamper Seals (Front) Figure 5: Location of Tamper Seal #2 (Bottom Edge)

8 Non-Invasive Security
Page 19
Storage Area NameDescriptionPersistence Type
SoC FW NVMFirmware image stored in SoC Non-volatile memory (flash)Static
SoC RAMSoC RAMDynamic
SATA CTL registerSATA CTL registerDynamic
SoC NVMSoC CFG Non-volatile memory (flash)Static
Name Ampex facilityFrom Entered in Ampex maintenance facility.To SoC FW NVMFormat Type PlaintextDistribution Type N/AEntry Type N/ASFI or Algorithm
Encrypted input parameterExternal sourceSATA CTL registerEncryptedAutomatedElectronicKTS
Encrypted output parameterSATA CTL registerExternal sourceEncryptedAutomatedElectronicKTS
Plaintext input parameterExternal sourceSoC RAMPlaintextAutomatedElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
After useOverwritten by zeros after useOverwritten with zerosModule code enforces zeroization after use
Power CycleOverwritten by zeros upon loss of powerOverwritten with zerosOperator can remove power from the modul
DestroyOverwritten by zeros by Destroy serviceOverwritten with zerosOperator calls the destroy service

Name COA Public

Description Verification of CO operator commands.

Size - Strength Size: 384 - Strength: 192

Type - Category G ECDSA P-384 - PSP

enerated By

Established By

Used By Signature ECDSA

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy

9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 19: SSP Input-Output Methods

9.3 SSP Zeroization Methods

Table 20: SSP Zeroization Methods TSEM code destroys all plaintext CSPs prior to return from any control plane command.

9.4 SSPs
Page 20

Name DEK DRBG_C DRBG_EI DRBG_Seed DRBG_V KEK PIK TIK TMK

Description AES XTS data encryption keys (DEKC1, DEKC2, DEKD1, DEKD2). DRBG state value C. DRBG Entropy Input (inclusive of nonce). DRBG Seed (required per CMVP SSP conventions). DRBG state value V. AES-256 key used to wrap DEK keys. Platform Identity Key, used to derive TIK which unwraps TMK; success authenticates host to TSEM. TSEM Identity Key: used to wrap the TMK. TSEM Master Key: AES-256 key used to derive KEK.

Size - Strength Size: 256 - Strength: 256 Size: 440 - Strength: 256 Size: 1024 - Strength: 256 Size: 440 - Strength: 256 Size: 440 - Strength: 256 Size: 256 - Strength: 256 Size: 256 - Strength: 256 Size: 256 - Strength: 256 Size: 256 - Strength: 256

Type - Category Symmetric - CSP Hash_DRBG_C - CSP Entropy input - CSP DRBG_Seed - CSP Hash_DRBG_V - CSP Symmetric - CSP Symmetric - CSP Symmetric - CSP Symmetric - CSP

Generated By CKG Section 4 CKG Section 6.1 Hash DRBG Hash DRBG Hash DRBG Key derivation Key derivation

Established By

Used By Cipher Hash DRBG Hash DRBG Hash DRBG Hash DRBG KTS Key derivation KTS Key derivation

Name COA PublicInput - Output Ampex facilityStorage SoC NVM:PlaintextStorage Duration Call lifetimeZeroization DestroyRelated SSPs
DEKEncrypted input parameterSoC RAM:PlaintextCall lifetimeAfter useKEK:Wrapped By
Encrypted output parameterSATA CTL register:PlaintextPower Cycle Destroy
DRBG_CSoC RAM:PlaintextModule uptimeAfter use Power Cycle DestroyDRBG_V:Used With DRBG_Seed:Derived From
DRBG_EISoC RAM:PlaintextModule uptimeAfter use Power Cycle DestroyDRBG_Seed:Incorporated Into
DRBG_SeedSoC RAM:PlaintextModule uptimeAfter use Power Cycle DestroyDRBG_EI:Constituent DRBG_C:Derives DRBG_V:Derives

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy 6.1 Table 21: SSP Table 1

Page 21
Name DRBG_V KEKInput - OutputStorage SoC RAM:Plaintext SoC RAM:PlaintextStorage Duration Module uptime Call lifetimeZeroization After use Power Cycle Destroy After use Power Cycle DestroyRelated SSPs DRBG_C:Used With DRBG_Seed:Generated From TMK:Derived From DEK:Wraps
PIKPlaintext input parameterSoC RAM:PlaintextCall lifetimeAfter use Power Cycle DestroyTIK:Derives
TIKSoC RAM:PlaintextCall lifetimeAfter use Power Cycle DestroyPIK:Derived From TMK:Wrapped By
TMKPlaintext input parameterSoC NVM:EncryptedCall lifetimeDestroyTIK:Wraps
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
FW IntegrityECDSA P-384 #A2921Signature verification performed over all TSEM firmware at power-up.SW/FW IntegrityTSEM_STATUS_OKVerify
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-XTS Testing Revision 2.0256-bitKATCASTTSEM_STATUS_OKEncryptPerformed on module load.
AES-XTS Testing Revision 2.0256-bitKATCASTTSEM_STATUS_OKDecryptPerformed on module load.
AES-KW256-bitKATCASTTSEM_STATUS_OKForward cipherPerformed on module load.
AES-KW256-bitKATCASTTSEM_STATUS_OKInverse cipherPerformed on module load.

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 22: SSP Table 2

10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 23: Pre-Operational Self-Tests The corresponding ECDSA signature verification CAST is performed prior to the integrity test.

10.2 Conditional Self-Tests
Page 22
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigVer (FIPS186-4)P-384 SHA2- 384KATCASTTSEM_STATUS_OKSignature verificationPerformed on module load prior to firmware integrity test.
Hash DRBGSHA2-256KATCASTTSEM_STATUS_OKInstantiate, generate, reseedPerformed on module load.
KDF SP800-108HMAC-SHA2- 384KATCASTTSEM_STATUS_OKSP800-108r1 Section 4.1 KAT for a Counter Mode KDFPerformed on module load.
SHA2-384 (A2921)SHA2-384KATCASTTSEM_STATUS_OKHashPerformed on module load.
ENT (P) Self-tests90B Self-testsCASTCASTTSEM_STATUS_OK90B Health TestsPerformed on module load, power cycle or do_bit service invocation.
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
FW IntegritySignature verification performed over all TSEM firmware at power-up.SW/FW IntegrityOn demandPower cycle or do_bit
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-XTS Testing Revision 2.0KATCASTOn demandPower cycle or do_bit
AES-XTS Testing Revision 2.0KATCASTOn demandPower cycle or do_bit
AES-KWKATCASTOn demandPower cycle or do_bit
AES-KWKATCASTOn demandPower cycle or do_bit
ECDSA SigVer (FIPS186-4)KATCASTOn demandPower cycle or do_bit
Hash DRBGKATCASTOn demandPower cycle or do_bit
KDF SP800-108KATCASTOn demandPower cycle or do_bit
SHA2-384 (A2921)KATCASTOn demandPower cycle or do_bit
ENT (P) Self-testsCASTCASTEach useContinuously running
NameDescriptionConditionsRecovery MethodIndicator
ERROR stateSelf-test failure error state If one of the KATs fails or integrity test failsPower-cycleNon-zero return status

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 24: Conditional Self-Tests All cryptographic algorithm self-tests (CASTs) must complete successfully prior to any other use of cryptography by the TSEM. Table 25: Pre-Operational Periodic Information Table 26: Conditional Periodic Information

10.4 Error States
Page 23

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy Table 27: Error States If one of the CASTs fails, the TSEM enters the ERROR state. The error state is persistent, and only Status services are available. All attempts to use the TSEM’s services result in the return of a non-zero error code in the range -40 (TSEM_ERROR_CYBER) to -47 (TSEM_ERROR_CYBER_LYCAN2).

10.5 Operator Initiation of Self-Tests

The TSEM automatically invokes all self-tests on each power-on or reset. The conditional self-tests may also be invoked on demand by the Self-Test service do_bit command; detailed results are available using the Self-Test service get_BITResults command.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The TSEM is a subsystem of the TuffServ® product and is not intended for use in other settings. The TSEM User and CO Guide documents all procedures for the following:

11.2 Administrator Guidance

The TSEM User and CO Guide is inclusive of all information required per ISO/IEC 19790:2012 Section 7.11.9.

11.3 Non-Administrator Guidance

The TSEM User and CO Guide is inclusive of all information required per ISO/IEC 19790:2012 Section 7.11.9.

11.4 Design and Rules

The TSEM enforces the following security rules:

  1. All services implemented by the module are described in the tables below. The module has no other mechanism which permits access to CSPs.
  2. Data output is inhibited during key generation, self-tests, zeroization, and the error state.
  3. Control output is inhibited whenever the module is in the error state and during self-tests.
  4. There are no restrictions on which keys or CSPs are zeroized by the zeroization service.
  5. The module does not support manual key entry.
  6. The module does not support firmware loading.
  7. The module does not output plaintext CSPs or intermediate key values.
Page 24

TuffServ® Encryption Module (TSEM) FIPS 140-3 Security Policy

  1. The module does not allow CSPs entered in the module in encrypted form to be displayed in plaintext.
  2. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the module.
  3. The module can use only algorithms that have passed self-tests.
  4. The module prohibits changing to the Crypto Officer state from any other role other than the Crypto Officer.
  5. The module does not support multiple concurrent operators, a maintenance role or a bypass capability.
11.5 End of Life

The TSEM User and CO Guide documents all procedures for decommissioning and sanitization of the TSEM.

12 Mitigation of Other Attacks