All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Samsung TCG Opal SSC Cryptographic Sub-Chip

Certificate#4965StandardFIPS 140-3Level2TypeHardwareEmbodimentSingle ChipStatusActiveVendorSamsung Electronics Co., Ltd.
Medium review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 17 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date2/12/2030
CaveatWhen operated in approved mode
VendorSamsung Electronics Co., Ltd.

Approved Algorithms (11)

AlgorithmACVP Cert
AES-ECBA4135
AES-ECBA4252
AES-GCMA4252
Counter DRBGA4135
ECDSA KeyGen (FIPS186-4)A4252
ECDSA SigVer (FIPS186-4)A4252
HMAC-SHA2-256A4252
KAS-ECC-SSC Sp800-56Ar3A4252
KDF SP800-108A4252
SHA2-256A4252
SHA2-384A4252

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Samsung TCG Opal SSC Cryptographic Sub-Chip
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Rollback</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>Show Status<br/>self-test</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3 clue;
  class I2,I3 infer;
  class R2,R3 risk;
  class E2,E3 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Samsung TCG Opal SSC Cryptographic Sub-Chip
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Rollback</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>Show Status<br/>self-test</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3 clueLow;

Security Policy, page by page

Page 1

Samsung TCG Opal SSC Cryptographic Sub-Chip Document Version: 1.2 Last update: 2025-01-28 Prepared for: Samsung Electronics Co., Ltd. 1-1, Samsungjeonja-ro Hwaseong-si, Gyeonggi-do Korea, 18448 www.samsung.com Prepared by: atsec information security corporation

4516 Seton Center Pkwy Suite 250

Austin, TX 78759 www.atsec.com

Page 2
Table of Contents
#SectionPage
Page 3

©2025 Samsung Electronics Co., Ltd., and atsec information security.

3 of 32

Page 4

©2025 Samsung Electronics Co., Ltd., and atsec information security.

4 of 32

Page 5
ISO/IEC 24759 Section 6 [Subsection Num. Below]FIPS 140-3 Section TitleSecurity Level
1General2
2Cryptographic Module Specification2
3Cryptographic Module Interfaces2
4Roles, Services, and Authentication2
5Software/Firmware Security2
6Operational EnvironmentN/A
7Physical Security2
8Non-invasive SecurityN/A
9Sensitive Security Parameter Management2
10Self-tests2
11Life-cycle Assurance2
12Mitigation of Other AttacksN/A
Overall2
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy of the Samsung TCG Opal SSC Cryptographic Sub-Chip cryptographic module (hereafter referred to as “the module”). This Security Policy contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 2 module. This Non-Proprietary Security Policy may be reproduced and distributed, but only whole, intact, and must include this notice. Other documentation is proprietary to their authors. Table 1 describes the individual security areas of FIPS 140-3, as well as the security levels of the module with respect to each of those individual areas.

1.2 Security Levels

Table 1: Security Levels ©2025 Samsung Electronics Co., Ltd., and atsec information security.

5 of 32

Page 6
2.1 Description

Purpose and Use: The Samsung TCG Opal SSC Cryptographic Sub-Chip (referred to as “the module” in the rest of this document) is a hardware cryptographic module which provides FIPS 140-

3 certified security functionality to Samsung’s TCG Opal SEDs.

Module Type: Hardware Module Embodiment: Single Chip Module Characteristics: The sub-chip hardware is contained within the Samsung S4LV006A01 SSD controller found within a Samsung TCG Opal SEDs. Cryptographic Boundary: The cryptographic boundary of the module consists of following components: - S-Core, - A dedicated OTP on the SoC for the S-Core - A set of fuses on the SoC which are dedicated to the S-Core - Sub-Chip’s main firmware and bootloader. Figure 1: Block Diagram ©2025 Samsung Electronics Co., Ltd., and atsec information security.

6 of 32

Page 7
Model and/or Part NumberHardware VersionFirmware VersionProcessor
S4LV006A01S01SS0100ARM SC000
NameDescriptionTypeStatus Indicator
Approved ModeAutomatically entered whenever an approved service is requestedFIPSEquivalent to the indicator of the requested service
Non-approved ModeAutomatically entered whenever a non-approved service is requestednonFIPSEquivalent to the indicator of the requested service
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification – Hardware: Software Version(s): The module does not contain a software component. Table 2: Hardware Operating Environments Note: S4LV006A01 refers to the SoC on which the sub-chip cryptographic module runs on.

2.3 Excluded Components

The vendor does not claim any excluded components within the module’s boundary.

2.4 Modes of Operation

Modes List and Description: Table 3: Modes List and Description Mode change instructions and status indicators: After passing all pre-operational self-tests and cryptographic algorithm self-tests executed on startThe module automatically switches between the approved and non-approved modes depending on to the indicator of the service that was requested. For each service the module provides a response message that includes the service indicator for the requested service. Output “1” suggests that the ©2025 Samsung Electronics Co., Ltd., and atsec information security.

7 of 32

Page 8
Key Size/
Cert1Algorithm and StandardMode/MethodStrengthUse/Function
A4252AES [FIPS 197, SP 800-38A]ECB256 bits / 256 bitsEncryption
A4252AES [FIPS 197, SP 800-38D]GCM (internal IV) Section 8.2.2 of SP 800- 38D256 bits / 256 bitsAuthenticated Encryption/Decryption
A4252ECDSA key generation [FIPS 186-4]Appendix B.4.2 Testing CandidatesP-384 / 192 bitskey generation
A4252ECDSA signature verification [FIPS 186-4]Using SHA2-384P-384 / 192 bitssignature verification
A4252HMAC [FIPS 198-1]SHA2-256112-512 bits / 112- 256 bitsMessage Authentication Code
A4252KAS-ECC-SSC [SP 800-56Arev3]staticUnifiedP-384 / 192 bitsShared secret computation
A4252KDA [SP 800-56Crev2]One step no counter256 bits / 256 bitsKey derivation
A4252KDF [SP 800-108]Counter using HMAC- SHA2-256256 bitsKey derivation
A4252SHS [FIPS 180-4]SHA2-256, SHA2-384N/AHashing
A4135AES [FIPS 197, SP 800-38A]ECB256 bits / 256 bitsEncryption
A4135CTR_DRBG [SP 800-90A]AES-256 with derivation function256 bits / 256 bitsRandom number generation
NameUse and Function
AES-XTSUsed for Decrypt Firmware to decrypt FW provided by H-Core Used for Verify Decrypt Firmware together with ECDSA signature verification to decrypt and verify signature of FW provided by H-Core
RSA EncryptUsed for Get Dump Key to encrypt the AES-XTS dump key
2.5 Algorithms

Approved Algorithms: Table 4: Approved Algorithms Vendor Affirmed Algorithms: The module implements Cryptographic Key Generation (CKG), as a vendor affirmed algorithm Non-approved, Allowed Algorithms: The module does not implement any non-approved algorithms that could be used in an approved Non-Approved, Allowed Algorithms with No Security Claimed: The module does not implement any non-approved algorithms that could be used in an approved Non-Approved, Not-Allowed Algorithms:

1 The CAVP certs also list ECB decryption and ECDSA signature generation algorithm which is not used by the module.

©2025 Samsung Electronics Co., Ltd., and atsec information security.

8 of 32

Page 9

ECDSA verification with AES XTS decryption

Used for Verify Decrypt Firmware together with AES-XTS decryption to verify a signature of and encrypted FW provided by H-Core

Table 5: Non-Approved, Not Allowed Algorithms ©2025 Samsung Electronics Co., Ltd., and atsec information security.

9 of 32

Page 10
NameTypeDescriptionPropertiesAlgorithms/CAVP Cert
ECDH Key agreementKASSP 800-56Arev3. KAS-ECC per IG D.F Scenario 2 path (2)P-384 curve providing 192 bits of security strengthKAS-ECC-SSC / A4252 KDA / A4252
AES GCMKTSSP 800-38D and SP 800-38F. KTS (key wrapping and unwrapping) per IG D.G256-bit key providing 256 bits of security strengthAES GCM / A4252
NameTypeOperational EnvironmentSample SizeEntropy Per SampleConditioning Component
Samsung TRNG (Cert. E81)PhysicalSee Table 21 Bit0.5 BitsNone
NameTypeProperties
ECDSA key pair generationCKGEC Curve: P-384; Security strength: 192 bits Method: FIPS 186-4 Appendix B.4.2 Testing Candidates Compliant to SP 800-133r2, Section 5.2
Symmetric key generationCKGSymmetric key generated using SP 800-90ARev1 DRBG Compliant to SP 800-133r2, Section 4
NameTypeProperties
ECDH Key agreementKAS-ECC-SSC with SP 800- 56Crev2Curves: P-384; Security strength: 192 bits KDF: One Step KDF with no counter Compliant with SP 800-56Ar3 and IG D.F Scenario 2 (2)
2.6 Security Function Implementations

Table 5A: Security Function Implementation

2.7 Algorithm Specific Information

The ECDSA algorithm as implemented by the module conforms to FIPS 186-4, which has been superseded by FIPS 186-5 on February 3, 2024. For the current module context, FIPS 186-4 can still be used in the approved mode. See IG C.K for details. Entropy Information: RNG Information: The module implements SP 800-90ARev1 CTR_DRBG that with AES-256 as the block cipher and has a derivation function. The CTR_DRBG is provided with a 256-bit nonce and 512-bits of entropy input from the entropy source, which provides 256-bit of entropy.

2.10 Key Establishment

©2025 Samsung Electronics Co., Ltd., and atsec information security.

10 of 32

Page 11

AES Key Transport

GCM

AES GCM using 256 bit Key Compliant with IG D.G and SP 800-38F

2.11 Industry Protocols

The module does not implement any industry protocols. ©2025 Samsung Electronics Co., Ltd., and atsec information security.

11 of 32

Page 12
Physical PortLogical InterfaceData That Passes
Mailbox/DMAData InputInput Parameters
DMAData OutputOutput parameters
MailboxControl InputCommand Input
MailboxStatus OutputStatus information
Power PortPower InputN/A
3.1 Ports and Interfaces

Table 9: Ports and Interfaces This module does not have a Control Output interface. ©2025 Samsung Electronics Co., Ltd., and atsec information security.

12 of 32

Page 13
Method NameDescriptionSecurity MechanismStrength Per AttemptStrength Per Minute
Key- Based KDFOperator keys that are necessary to access authenticated commands, are access controlled using 256-bit Credential Protection Key (CPK) which is derived from SP 800-108 KDF using Authority ID, Password and KDK_CPK i.e. key derivation key for CPK. Only the operator with valid Authority ID and Password (minimum of 8 bytes) can lead to derivation of valid CPK which will allow the operator to access the authenticated commands. The module does not support concurrent operators and it does not maintain any authentication results across power cycle.The module waits for 750ms after a failed attempt.Probability of success: 1/264Probability of success: 80/264
NameTypeAuthentication Methods
SysIDCOKey-Based KDF
AdminSP.SIDCOKey-Based KDF
AdminSP.Admin1COKey-Based KDF
LockingSP.Admin1~4COKey-Based KDF
LockingSP.User1~9UserKey-Based KDF

4. Roles, Services, and Authentication Table 10: Authentication Methods

4.2 Roles

Table 11: Roles ©2025 Samsung Electronics Co., Ltd., and atsec information security.

13 of 32

Page 14
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsRoleSSP Access
Show StatusProvide the module versioning information and current status of the module1NoneModule versioning informationNoneN/ANone
Create NamespaceCreate Namespace1NoneSuccess/ FailureAES-GCM, ECDH Key Agreement, CTR_DRBG, SHA, HMACSysIDEWGZ: [CK, PK, SK]; EWZ: [KEK, KPK]; E: [SMK, KMK, REK]
Delete NamespaceDelete Namespace1Namespace SelectionSuccess/ FailureAES-GCM, CTR_DRBG, HMACSysIDEWGZ: [MEK]; EWZ: [KEK, KPK]; E: [SMK, KMK, REK]
Format NVMCryptograph ically erase a specific Namespace' s MEK1NoneSuccess/ FailureAES-GCM, CTR_DRBG, HMACSysIDEWGZ: [MEK]; EWZ: [KEK, KPK]; E: [SMK, KMK, REK]
Permanent Write ProtectionEnable NVMe write protection1NoneSuccess/ FailureAES-GCM, HMACSysIDEWZ: [KPK, KEK]; E: [SMK, KMK, REK]
SanitizeErase all MEKs and generate new MEK to support NVMe Sanitize1NoneSuccess/ FailureAES-GCM, CTR_DRBG, HMACSysIDEWGZ: [MEK]; EWZ: [KEK, KPK]; E: [SMK, KMK, REK]
Crypto EraseErase all MEKs and generate new MEK to support NVMe CryptoErase1NoneSuccess/ FailureAES-GCM, CTR_DRBG, HMACSysIDEWGZ: [MEK]; EWZ: [KEK, KPK]; E: [SMK, KMK, REK]
ActivateMake AdminSP to transition to the Manufacture d2 state1PINSuccess/ FailureAES-GCM, CTR_DRBG, HMAC, ECDH Key Agreement, KBKDF, SHAAdminSP.SI DEWGZ: [KPK, MEK, CPK, KDK_CPK, KDK_KPK]; EWZ: [PIN]; WGZ: [SK, PK]; E: [REK, SMK, KMK]
4.3 Approved Services

©2025 Samsung Electronics Co., Ltd., and atsec information security.

14 of 32

Page 15
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsRoleSSP Access
ReactivateSupport TCG SUM method that change to "Single User Mode" from TCG Opal feature set spec.1PINSuccess/ FailureAES-GCM, CTR_DRBG, HMAC, ECDH Key Agreement, KBKDF, SHAAdminSP.SI D AdminSP.Ad min1EWGZ: [KPK, MEK, CPK, KDK_CPK, KDK_KPK]; EWZ: [PIN]; WGZ: [SK, PK]; E: [REK, SMK, KMK]
AssignSupport TCG CNL method to couple LockingObje ct from NSGlobal Range1Target Namespace, Target Locking ObjectSuccess/ FailureAES-GCM, ECDH Key Agreement, CTR_DRBG, SHA, HMACLockingSP.A dmin1~4 LockingSP.U ser1~9EWGZ: [MEK, CK, PK, SK]; EGZ: [KEK, KPK]; E: [REK, SMK, KMK]
DeassignSupport TCG CNL method to decouple LockingObje ct from NSGlobal Range1Target Namespace, Target Locking ObjectSuccess/ FailureAES-GCM, ECDH Key Agreement, CTR_DRBG, SHA, HMACLockingSP.A dmin1~4 LockingSP.U ser1~9EWGZ: [MEK, CK, PK, SK]; EGZ: [KEK, KPK]; E: [REK, SMK, KMK]
EraseSupport TCG SUM method to crypto erase. EraseGlobal crypto erase MEK which assign to Global Range1Target NamespaceSuccess/ FailureAES-GCM, CTR_DRBG, HMAC, ECDH Key Agreement, KBKDF, SHALockingSP.A dmin1~4 LockingSP.U ser1~9EWGZ: [MEK, CPK, KDK_CPK, KDK_CPK, PK, SK]; EWZ: [KPK]; EZ: [PIN]; E: [REK, SMK, KMK]
GenkeySupport TCG method to crypto erase. GenkeyNon Global crypto erase MEK which assign to Global Range1Target NamespaceSuccess/ FailureAES-GCM, CTR_DRBG, HMACLockingSP.A dmin1~4 LockingSP.U ser1~9EWGZ: [MEK]; EWZ: [KEK, KPK]; E: [REK, SMK, KMK]
GrantSupport TCG method that grants a User’s authority to another authority1Target AuthoritySuccess/ FailureAES-GCM, ECDH Key Agreement, CTR_DRBG, SHA, HMACLockingSP.A dmin1~4 LockingSP.U ser1~9EWGZ: [CK, PK, SK]; EWZ: [KEK, KPK]; E: [REK, SMK, KMK]
RandomProvides random number1NoneDRBG OutputCTR_DRBGN/ADRBG Output

©2025 Samsung Electronics Co., Ltd., and atsec information security.

15 of 32

Page 16
NameDescriptio n from the moduleIndicatorInputsOutputsSecurity FunctionsRoleSSP Access
RevertSupport TCG method to make a TCG state to Manufacture d2 inactivate state with password1PINSuccess/ FailureAES-GCM, CTR_DRBG, HMAC, KBKDF, SHAAdminSP.SI D AdminSP.Ad min1EWGZ: [KEK, KPK, MEK, CPK, KDK_CPK, KDK_KPK]; WGZ: [SK, PK]; EZ: [PIN]; E: [REK, SMK, KMK]
RevertWithP SIDSupport TCG method to make a TCG state to Manufacture d2 inactivate state with PSID1PINSuccess/ FailureAES-GCM, CTR_DRBG, HMAC, KBKDF, SHASysIDEWGZ: [KEK, KPK, MEK, CPK, KDK_CPK, KDK_KPK]; WGZ: [SK, PK]; EZ: [PIN]; E: [REK, SMK, KMK]
RevertSPClear state of TCG Service Provider(SP) i.e. it causes the SP to revert to its factory2 state.1PIN, Target SPSuccess/Fail ureAES-GCM, CTR_DRBG, KBKDF, SHALockingSP.A dmin1~4EWGZ: [KPK, MEK, CPK, KDK_CPK, KDK_KPK]; WGZ: [SK, PK]; EWZ: [PIN, KEK]; E: [REK, SMK, KMK]
SetC_PINSet PIN1PIN, New PINSuccess/ FailureCTR_DRBG, AES-GCM, ECDH Key Agreement, KBKDF, SHA, HMACAll rolesEWGZ: [KPK, MEK, CPK, KDK_CPK, KDK_KPK]; WGZ: [SK, PK]; EWZ: [PIN, KEK]; E: [REK, SMK, KMK]
SetRangeSet Range for using TCG1Target RangeSuccess/ FailureAES-GCM, HMACLockingSP.A dmin1~4 LockingSP.U ser1~9EWZ: [KPK, KEK, MEK]; E: [REK, SMK, KMK]
Load the KPK for authority and decrypt1Authority Index, PINSuccess/ FailureCTR_DRBG, AES-GCM, ECDH Key Agreement,All rolesEWGZ: [KPK, MEK, CPK, KDK_CPK,

2 Manufactured or Factory state refers to TCG Opal SSC’s policy state, not a FIPS 140-3 module state.

3* “authenticate” and “deauthenticate” services are not functions used to comply with FIPS authentication requirements but instead used as part of the TCG Opal SSC specification’s commands. ©2025 Samsung Electronics Co., Ltd., and atsec information security.

16 of 32

Page 17
NameDescriptio n related encryption keys.IndicatorInputsOutputsSecurity Functions KBKDF, SHA, HMACRoleSSP Access KDK_KPK]; WGZ: [SK, PK]; EWZ: [PIN, KEK]; E: [REK, SMK, KMK]
Deauthentic ate3*Zeroise the KPK for authority and zeroise related encryption keys.1NoneSuccess/ FailureN/AAll rolesZ: [KPK]
TperResetReset the lock state information1NoneSuccess/ FailureAES-GCM, HMACSysIDEWZ: [KPK, KEK, MEK]; E: [REK, SMK, KMK]
VerifyFWVerify Firmware1NoneSuccess/ FailureECDSA, SHA-384SysIDEWZ: [FW Verification Key]
Prevent FW Rollback4Update the Anti- Rollback index1NoneSuccess/ FailureNoneSysIDNone
Revoke FW verification key4Revoke the ECDSA FW verification key of Firmware integrity by updating the key index pointer stored in OTP1NoneSuccess/ FailureNoneSysIDNone
SHA DigestProvide to generate the SHA digest1Input DataHashSHA-256N/ANone
Revoke Root Encryption KeyRevoke REK and Generate new REK1NoneSuccess/ FailureCTR_DRBGSysIDWZ: [REK]
OTP ZeroisationZeroises root key in OTPNoneNoneSuccess/ FailureNoneSysIDZ: [Root Key]

4 These services are only indicated for use within the firmware update process. If any of these services are called

during operation of the module outside of a firmware update process, the module will fail to verify the firmware during boot, resulting in halting during boot and becoming unavailable for use. Also note that use of any firmware version other than the one specific in Table 2 is not part of validated module. ©2025 Samsung Electronics Co., Ltd., and atsec information security.

17 of 32

Page 18
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsRoleSSP Access
On demand self-testModule reset by setting the SFR SW_RST12NoneNoneModule resetNoneAll rolesZ: All SSPs in volatile memory
NameDescriptionInputOutputIndicatorAlgorithm AccessedRole
Decrypt FirmwareDecrypt FW provided by H- CoreFirmware locationDecrypted firmware0AES-XTS in S- CoreN/A (Unauthenticat ed)
Verify Decrypt FirmwareVerify and Decrypt Firmware5 provided by H- CoreFirmware locationDecrypted firmware if verification is successful else error.0ECDSA, SHA- 384, AES-XTSN/A (Unauthenticat ed)
Get Dump KeyModule generates AES XTS dump key using DRBG and then exports it after encrypting with RSAN/ADump key with RSA0CTR_DRBG, RSA encryptN/A (Unauthenticat ed)
Clear Dump KeyRemoves dump key stored in the moduleN/ASuccess/ error0NoneN/A (Unauthenticat ed)
Dump EncryptionEncrypts the dump data provided by H- Core using dump keyDump data locationEncrypted dump data0AES-XTS in S- CoreN/A (Unauthenticat ed)
4.4 Non-Approved Services

Table 13: Non-Approved Services

4.5 External Software and Firmware Loaded

The module loads its firmware component from outside of the sub-chip boundary during module start up. The module uses firmware load test described in Section 5.1 to ensure the firmware’s validity.

5 Note: the firmware does not pertain to the module.

©2025 Samsung Electronics Co., Ltd., and atsec information security.

18 of 32

Page 19
5.1 Integrity Techniques

The module’s firmware component (i.e., main firmware and bootloader) is in executable form and is verified with ECDSA signature verification using P-384 ECDSA curve and SHA-384 by the ROM code. The corresponding firmware verification key (i.e., ECDSA public key) used for verification is stored in the ROM and its key index is stored in the OTP memory within the subchip. During the module startup time the firmware component is loaded from outside of the module’s sub-chip boundary. The firmware provides the “key index” of the public key stored in the OTP. The module reads this key index and its corresponding public key, which is then used to perform signature verification, i.e., the firmware load test required per IG 2.3.B. Only when the signature verification is successful the firmware component is loaded, and the module proceeds to boot. If the signature verification fails, the module enters Power on Error state. The module does not provide any data output until the firmware load test is successful.

5.2 Initiate on Demand

The integrity tests can be invoked on demand by module reset. ©2025 Samsung Electronics Co., Ltd., and atsec information security.

19 of 32

Page 20
6.1 Operational Environment Type and Requirements

The module has a non-modifiable operational environment; therefore, this section is not applicable. ©2025 Samsung Electronics Co., Ltd., and atsec information security.

20 of 32

Page 21
MechanismInspection FrequencyInspection Guidance
Tamper evident coatingN/AN/A

7. Physical Security The module is hosted in a single chip that forms the physical perimeter of the module. The SoC is enclosed within production grade components. At the time of manufacturing, the module is embedded into its host SoC (shown in Figure 2), preventing visibility into the module’s internal circuitry. In addition, the layer process which embeds the module into the SoC prevents tampering of the module’s physical components without leaving tamper evidence. The module is intended to be deployed within a storage device which itself is made from production grade, commercially available components. The storage device’s enclosure surrounds the module’s SoC.

7.1 Mechanisms and Actions Required

Table 14: Mechanisms and Actions Required ©2025 Samsung Electronics Co., Ltd., and atsec information security.

21 of 32

Page 22

8. Non-Invasive Security This module does not implement a non-invasive security technique. ©2025 Samsung Electronics Co., Ltd., and atsec information security.

22 of 32

Page 23
Storage Area NameDescriptionPersistence Type
RegistersThe module has internal registers that may store SSPs for use by the module.Dynamic
S-Core Dedicated OTP (OTP)Stores Root KeysStatic
S-Core ROM (SROM)Stores Firmware Verification KeyStatic
S-Core RAM (SRAM)S-Core exclusive RAMDynamic
NameFromToFormat TypeDistribution TypeEntry Type
MailboxH-CoreModulePlaintextN/A per IG 2.3.B as transfer is only between the sub-chip module and the components residing on the same SoCElectronic
DMANANDModuleEncryptedAutomatedElectronic
ZeroisationDescription
MethodRationaleOperator Initiation
Module resetLoss of volatile SSP data stores upon power down.N/APowering off the module
Mailbox ZeroisationWriting zeroes over the SSP that is used within a service.N/APerformed automatically by the module as part of each service that receives an SSP as input
OTP ZeroisationZeroising Root key stored in OTP.N/ACall to OTP Zeroisation service
NameDescriptio nSize - StrengthType -Generated ByUsed By
CategoEstablish
ryed By
DRBG Internal StateInternal state of DRBGN/ACSPCTR_DRBGN/ACTR_DRBG
DRBG SeedDerived from entropy input per SP 800- 90ARev1256 bits/ 256 bitsCSPCTR_DRBGN/ACTR_DRBG

9. Sensitive Security Parameter Management

9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 16: SSP Input-Output All data output via data output interface is inhibited until completion of zeroization. Table 17: SSP Zeroisation Methods ©2025 Samsung Electronics Co., Ltd., and atsec information security.

23 of 32

Page 24
Size - StrengthType - Catego ry
DescriptioGeneratedEstablish
NamenByed ByUsed By
Entropy InputOutput from Entropy source512 bits/ 256 bitsCSPENT (P)N/ACTR_DRBG
PasswordOperator provided password64-256- bits / 64 bits - 256 bitsCSPN/AN/AAll authenticated services listed in Table 12
CPKCredential Protection Key256-bit / 256-bitsCSPDerived using SP 800-108 KBKDFEncrypted Import and export (AES GCM) to NANDAll authenticated services listed in Table 12
CKCommon Key i.e., ECDH shared secretP-384 / 192 bitsCSPSP 800- 56Arev3 Shared secret computationN/AGrant
KDK_KPKKey Derivation Key for the KPK256-bits / 256-bitsCSPCTR_DRBGEncrypted Import and export (AES GCM) to NANDAll authenticated services listed in Table 12
KDK_CPKKey Derivation Key for the CPK256-bits / 256-bitsCSPCTR_DRBGEncrypted Import and export (AES GCM) to NANDAll authenticated services listed in Table 12
KPKKey Protection Key256-bits / 256-bitsCSPKBKDFN/AAll authenticated services listed in Table 12
SKECDSA private KeyP-384 / 192 bitsCSPFIPS 186-4 EC key generationEncrypted Import and export (AES GCM) to NANDGrant
PKECDSA Public KeyP-384 / 192 bitsPSPFIPS 186-4 EC key generationEncrypted Import and export (AES GCM) to NANDGrant
GRKGrant Key (AES GCM Key)256-bits / 256-bitsCSPN/ASP 800- 56ARev3 ECDH key agreementGrant
KEKKey Encryption Key (AES GCM Key)256-bits / 256-bitsCSPCTR_DRBGEncrypted Import and export (AES GCM) to NANDCreateNamespace, DeleteNamespace, FormatNVM, PermanentWriteProtect ion, Sanitze, CryptoErase, Assign, Deassign, Genkey,

©2025 Samsung Electronics Co., Ltd., and atsec information security.

24 of 32

Page 25
NameSize - StrengthType -Generated ByUsed By
DescriptioCategoEstablish
nryed ByGrant, Revert, RevertWithPSID, RevertSP, Authenticate
MEKMedia Encryption Key (AES GCM Key)256-bits / 256-bitsCSPCTR_DRBGEncrypted Import and export (AES GCM) to NANDDeleteNamespace, FormatNVM, Sanitize, CryptoErase, Activate, Reactivate, Assign, Deassign, Erase, Genkey, Revert, RevertWithPSID, RevertSP, SetRange, Authenticate, TperReset
REKRoot Encryption Key (AES GCM Key)256-bits / 256-bitsCSPDerived from Root key using KBKDFN/AAll authenticated services listed in Table 12
Root KeyStored in the OTP during manufacturi ng (key derivation key)256-bits / 256-bitsCSPN/A, loaded at manufacturi ngN/AAll authenticated services listed in Table 12
SMKService metadata Mac Key (HMAC key)256-bits / 256-bitsCSPDerived from Root key using KBKDFN/AModule Startup
KMKSecret Key metadata Mac Key (HMAC key)256-bits / 256-bitsCSPDerived from Root key using KBKDFN/AAll authenticated services listed in Table 12
NameInput -StorageZeroisation Type
OutputStorge DurationRelated SSPs
DRBG Internal StateN/AHW registersUntil Module resetModule resetDRBG seed, entropy input, MEK, KEK, SK, KDK_CPK, KDK_KPK
DRBG SeedN/AHW registersDRBG internal state, entropy input, MEK, KEK, SK, KDK_CPK, KDK_KPK
Entropy InputN/AHW registersUntil Module resetModule resetDRBG seed, DRBG internal state

Table 18: SSP Information First ©2025 Samsung Electronics Co., Ltd., and atsec information security.

25 of 32

Page 26
NameInput -StorageZeroisation TypeRelated SSPs
OutputStorge Duration
PasswordMailboxSRAMFor the duration of the serviceOverwriteCPK, KPK
CPKDMASRAMMailbox ZeroisationKDK_CPK, Password
CKN/ASRAMOverwriteGRK
KDK_KPKDMASRAMMailbox ZeroisationKPK, Password
KDK_CPKSRAMCPK, Password
KPKN/ASRAMKDK_KPK, Password
SKDMASRAMGRK
PKSRAMGRK
GRKN/ASRAMSK, PK, CK
KEKDMASRAMFor the duration of the serviceMailbox ZeroisationMEK SK, PK, CK, GRK
MEKDMASRAMKEK
REKN/ASRAMRoot Key, KMK, SMK
Root KeyN/AOTPUntil OTP zeroisationOTP zeroisationREK
SMKDMASRAMUntil Module resetMailbox ZeroisationREK
KMKDMASRAMREK

Table 19: SSP Information Second ©2025 Samsung Electronics Co., Ltd., and atsec information security.

26 of 32

Page 27
Implementa tionTest PropertiesTest MethodTest TypeIndicator
FirmwareP-384 with SHA2-384Signature VerificationFirmware IntegrityModule is operational
AlgorithmImplementatio nTestTest Typ eIndic.
PropertieTest
sMethodDetailsConditions
ECDSAFirmwareP-384 with SHA2-384KATCAS TModule is operationa lBefore firmware integrity checkModule Startup
AES-GCM6AES-256KATCAS TEncrypt/ Decrypt
SHA2-256N/AKATCAS THashing
SHA2-384N/AKATCAS THashing
HMACSHA2-256KATCAS TMessage authenticatio n
CTR_DRBGHardwareAES-256KATCAS TRandom number generation7
KBKDFFirmwareHMAC SHA2-256KATCAS TKey Derivation
ECDH SSCP-384KATCAS TShared secret computation
One step KDF (KDA)SHA-256KATCAS TKey Derivation
ENT (P)HardwareSP 800- 90B Startup Tests1024 samplesRCT & APTEntropy source is operationa lEntropy source start- up testBoot Up
SP 800- 90BContinuousl yRCT & APTEntropy sourceContinuousl y
10.1 Pre-Operational Self-Tests

Bootloader Table 20: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

6 Even though the module implements AES ECB mode, it is not available as a standalone service and therefore does not

include any self-test. ECB encryption is only used internally by module’s AES GCM and DRBG algorithm which have their own self-test.

7 Including instantiate, generate, and reseed function per section 11.3 of SP 800-90A DRBG.

©2025 Samsung Electronics Co., Ltd., and atsec information security.

27 of 32

Page 28
Implementatio nTest PropertieTest MethodTest TypIndic.
AlgorithmseDetailsConditions
Continuou s Testscontinuous test
ECDSAFirmwareSHA2-256PCTCAS TKey generatio n successfulPer SP 800- 56ARev3 section 5.6.2.1.4 bKey Generation
NameDescriptionConditionsRecovery MethodIndicator
Power ON Error State iThe module is not operational. All data output is nhibited.pre-operational test or CAST failurePower cycle or Internal Reset Signalthe module is not started, and no services are available.
Operational Error state iThe module does not provide any crypto operation. All data output is nhibited. Only status output is allowed.PCT or runtime health test failurePower cycle or Internal Reset SignalFIPS_FAIL message in Show Status Service

Table 21: Conditional Self-Tests

10.3 Periodic Self-Tests
10.4 Error States

inhibited. available. inhibited. Only Table 22: Error States ©2025 Samsung Electronics Co., Ltd., and atsec information security.

28 of 32

Page 29
11.1 Installation, Initialization and Startup Procedures

The vendor uses trusted delivery courier to dispatch the SoC that hosts the module. The Crypto officer should verify the package and the received SoC to verify that there is no tamper evidence present.

11.2 Administrator Guidance

The Crypto officer shall power up the module and call the “Show Status” service to verify the following output is provided. This confirms that the SoC is running a FIPS validated module that has booted successfully passing the pre-operational self-tests. - Tested Configuration: S4LV006A01 - Hardware Version: S01 - Firmware Version: SS0100

11.3 Non-Administrator Guidance

The module generates GCM IV internally in compliance with scenario 2 of IG C.H. The IV length is 96 bits, and the IV value is obtained from the SP 800-90ARev1 approved DRBG implemented by the module. ©2025 Samsung Electronics Co., Ltd., and atsec information security.

29 of 32

Page 30

12. Mitigation of Other Attacks The module does not provide additional mitigations against other types of attacks. ©2025 Samsung Electronics Co., Ltd., and atsec information security.

30 of 32

Page 31
Table, extracted as text (did not parse into structured rows)
13. Abbreviations AES              Advanced Encryption Standard CAVP             Cryptographic Algorithm Validation Program CMVP             Cryptographic Module Validation Program CK               Common Key CPK              Credential Protection Key CSP              Critical Security Parameter CTR              Counter Mode DRBG             Deterministic Random Bit Generator DTRNG            Deterministic True Random Number Generator ECB              Electronic Code Book ENT              NIST SP 800-90B Compliant Entropy Source FIPS             Federal Information Processing Standards GCM              Galois Counter Mode GRK              Grant Key HMAC             Hash Message Authentication Code KAT              Known Answer Test KDF              Key Derivation Function KDK_CPK          Key Derivation Key for CPK KDK_KPK          Key Derivation Key for KPK KMK              Secret Key metadata Mac Key KPK              Key Protection Key NVM              Non-Volatile Memory OTP              One Time Programmable PK               Public Key PKE              Public Key Encryption PSP              Public Security Parameter ROM              Read Only Memory RSA              Rivest, Shamir, Addleman SED              Self-Encrypting Device SHA              Secure Hash Algorithm SHS              Secure Hash Standard SID              Security ID ©2025 Samsung Electronics Co., Ltd., and atsec information security.

31 of 32

Page 32
Table, extracted as text (did not parse into structured rows)
SK               Secret key SoC              System on Chip SSC              Security Subsystem Class SSP              Sensitive Security Parameter TCG              Trusted Computing Group XTS              XEX-based Tweaked-codebook mode with ciphertext stealing ©2025 Samsung Electronics Co., Ltd., and atsec information security.

32 of 32