| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Status | Active |
| Sunset date | 3/5/2030 |
| Caveat | None |
| Vendor | Samsung Electronics Co., Ltd. |
| Algorithm | ACVP Cert |
|---|---|
| AES-ECB | A2108 |
| AES-XTS | A2108 |
| Hash DRBG | A2107 |
| RSA SigVer (FIPS186-4) | A2110 |
| SHA2-256 | A2109 |
flowchart LR
%% Deterministic review-risk graph for Samsung SATA TCG Opal SSC SEDs PM893 Series
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Show Status<br/>Status Output</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>bootloader</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for Samsung SATA TCG Opal SSC SEDs PM893 Series
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Show Status<br/>Status Output</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>bootloader</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;Samsung SATA TCG Opal SSC SEDs PM893 Series Document Version: 1.0 Hardware Version: MZ7L3480HCHQ-00AMV, MZ7L3960HCJR-00AMV Firmware Version: JXTC1M8Q
| Version | Change | ||
|---|---|---|---|
| 1.0 | Initial Version |
Revision History Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| # | Section | Page |
|---|
| Acronym | Description |
|---|---|
| CTRL | Controller |
| CPU | Central Processing Unit (ARM-based) |
| DRAM | Dynamic Random Access Memory |
| DRAM I/F | Dynamic Random Access Memory Interface |
| ECC | Error Correcting Code |
| KAT | Known Answer Test |
| LBA | Logical Block Address |
| MEK | Media Encryption Key |
| PSID | Physical Presence SID (Security Identifier) |
| NAND | NAND Flash Memory |
| NAND I/F | NAND Flash Interface |
| SATA | Serial ATA(Advanced Technology Attachment) |
| ROM | Read-Only Memory |
I. Introduction I.1. Scope referred to as a “cryptographic module” or “module”. The SSD (Solid State Drive) satisfies all applicable FIPS 140-3 Security Level 1 requirements, supporting TCG Opal SSC based SED (Self-Encrypting Drive) features. It is designed to protect unauthorized access to the user data stored in its NAND flash memories. The built-in AES hardware engines in the cryptographic module’s controller provide on-the-fly encryption and decryption of the user data without performance loss. The SED’s nature also provides instantaneous sanitization of the user data via cryptographic erase. I.2. Acronyms Table 1. Acronyms Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| ISO/IEC 24759 Section 6. [Number Below] | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic module specification | 1 |
| 3 | Cryptographic module interfaces | 1 |
| 4 | Roles, services, and authentication | 1 |
| 5 | So ft w a r e / F ir m w a re s e cu ri ty | 1 |
| 6 | Operational environment | 1 |
| 7 | Physical security | 1 |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle assurance | 1 |
| 12 | Mitigation of other attacks | N/A |
5 Software/Firmware security 1
Table 2. Security Levels Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Model | Hardware Version | Firmware Version | Distinguishing Features |
|---|---|---|---|
| PM893 | MZ7L3480HCHQ-00AMV | JXTC1M8Q | 480GB |
| MZ7L3960HCJR-00AMV | 960GB |
The firmware utilizes a single-chip controller with a SATA interface on the system side, as well as Samsung NAND flash. The following figure depicts the module’s operational environment. The firmware version included within the scope of this validation must be validated through the FIPS 140-3 CMVP. Any firmware loaded onto this module that is not shown on the module certificate, is out of the scope of this validation and requires a separate FIPS 140-3 validation. Figure
| CAVP Cert | Algorithm and Standard | Mode / Method | Description / Key Size(s) / Key Strength(s) | Use / Function |
|---|---|---|---|---|
| A2107 | Hash DRBG / SP 800-90A Rev. 1 | Hash_ DRBG (SHA2-256) | Prediction Resistance: No Supports Reseed | Deterministic Random Bit Generation |
| A2108 | AES-ECB / FIPS 197, SP 800-38A | ECB | 256-bit keys with 256-bit key strength | Prerequisite for AES-XTS (A2108) |
| A2108 | AES-XTS / FIPS 197, SP 800-38E | XTS | 256-bit keys with 256-bit key strength | Data Encryption and Decryption |
| A2109 | SHA2-256 / FIPS 180-4 | SHA2-256 | SHA2-256 | Message Digest |
| A2110 | RSA SigVer / FIPS 186-4 | PSS SigVer (SHA2- 256) | 2048 bits | Digital Signature Verification |
| Vendor Affirmed | CKG / SP 800-133 Rev. 2 (Section 4, 5.1, 6.3) | N/A | N/A | Cryptographic Key Generation using DRBG. |
| N/A | ENT (P) / SP 800-90B | N/A | N/A | Non-deterministic Random Number Generator (only used for generating seed materials for the DRBG). Provides a minimum of 256 bits of entropy for DRBG seed. |
| Algorithm | Caveat | Use / Function |
|---|---|---|
| AES-CCM / FIPS 197, SP 800-38C | No Security Claimed; Non-approved algorithm here is only used for obfuscation and removal of obfuscation the CSP. (IG 2.4.A Scenario #1) | Key obfuscation and removal of obfuscation |
| AES-XTS / FIPS 197, SP 800-38E | No security claimed; AES-XTS is only used to remove obfuscation from the firmware during ROM initialized. | Firmware obfuscation removal |
| HMAC-SHA2-256 / FIPS 198-1 (non-compliant) | Non-approved algorithm here are only used as pre-requisite algorithms for PBKDF2 which is used for storing authentication data. (IG 2.4.A Scenario #1) | Store authentication data |
| PBKDF2 / SP 800-132 | Non-approved algorithms here are only used for storing authentication data using PBKDF2 (IG 2.4.A Scenario #1) | Store authentication data |
| SHA2-256 / FIPS 180-4 (non-compliant) | Non-approved algorithm here are only used as pre-requisite algorithms for PBKDF2 which is used for storing authentication data. (IG 2.4.A Scenario #1) | Store authentication data |
2.3. Cryptographic Functionality The module does not implement any "Non-Approved Algorithms Not Allowed in the Approved Mode of Operation". Note that not all algorithms/modes that appear on the module’s CAVP certificates are utilized by the module. Table 4 lists only the algorithms/modes that are utilized by the module. #1) #1) Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Physical Port | Logical Interface Type | Data that Passes Over Port / Interface | |
|---|---|---|---|
| SATA Connector | Data Input / Output | Plaintext data; signed data; User Data Input / Output | |
| Control Input | SATA Command Input logically via an API; signals input logically or physically via one or more physical ports | ||
| Status Output | SATA Command Execution Response logically via an API; signal outputs logically or physically via one or more physical ports | ||
| JTAG | Control Input | JTAG signal input logically or physically via physical ports | |
| Status Output | Diagnostic Information outputs logically or physically via one or more physical ports |
Table
| Role | Service | Input | Output | |
|---|---|---|---|---|
| Cryptographic Officer (CO) | Show Status | ATA Command | Status | |
| Lock/Unlock an LBA Range | LBA Range | Status | ||
| Erase an LBA Range’s Data | LBA Range | Status | ||
| Update the firmware | Firmware image binary | Status | ||
| Get Random Number | TCG Command | Status | ||
| IO Command | LBA Range | Status | ||
| Sanitize | LBA Range | Status | ||
| Revert | PSID | N/A | ||
| Perform the Self-tests | N/A | Status | ||
| Authentication | N/A | Status | ||
| Maintenance1 | Diagnostics | N/A | N/A |
| Service | Description | Approved Security Functions | SSPs | Roles | Type(s) of Access | Indicator2 | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| E | W | G | Z | ||||||||||
| Show Status | Show approved version status of the module / FIPS fail mode | N/A | N/A | CO | ATA Command: Identify Controller command Result : Status Code | ||||||||
| Lock / Unlock an LBA Range | Block or allow read (decrypt) / write (encrypt) of user data. | N/A | MEK3 | O | O | O | UID: Locking_GlobalRange / Locking_RangeNNNN TCG Method: Set Result: TCG status code | ||||||
| Erase an LBA Range’s Data | Erase user data by changing the data encryption key. | Hash_ DRBG / A2107 SHA2-256 / A2109 | DRBG “V” Value | O | O | UID: K_AES_256_GlobalRange_K ey / K_AES_256_RangeNNNN_K ey | |||||||
| DRBG “C” Value | O | O | |||||||||||
| DRBG Seed | O | O |
| 4.2. | Approved Services The cryptographic module only supports the following approved services and does not support any non-approved services. The abbreviations of the type of access to keys and SSPs have the following interpretation: • G = Generate: The module generates or derives the SSP. • W = Write: The SSP is updated, imported, or written to the volatile storage specified in Table 12. • Z = Zeroise: The module zeroises the SSP. E: EXECUTE; W: WRITE; G: GENERATE; Z: ZEROISE |
| 1 | Maintenance role is an operator responsible for using the JTAG. |
| 3 | Specified type of access of Lock/Unlock an LBA Range service to MEK was limited to only RAM. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy |
| CKG ENT(P) | DRBG Entropy Input String | O | O | TCG Method: GenKey Result: TCG status code | |||
|---|---|---|---|---|---|---|---|
| MEK | O | ||||||
| Update the Firmware | Update the firmware | RSA SigVer / A2110 | Firmware Verification Key | O | Admin Command: DOWNLOAD MICROCODE Result : Status Code | ||
| Get Random Number | Provide a random number generated by the CM | Hash_ DRBG / A2107 SHA2-256 / A2109 CKG ENT(P) | DRBG “V” Value | O | O | UID: ThisSP TCG Method: Random Result: TCG status code | |
| DRBG “C” Value | O | O | |||||
| DRBG Seed | O | O | |||||
| DRBG Entropy Input String | O | O | |||||
| IO Command | Read / Write user data | AES-XTS / A2108 | MEK | O | ATA Command: Read / Write Result : Status Code | ||
| Sanitize | Erase user data by changing the data encryption key | Hash_ DRBG / A2107 SHA2-256 / A2109 CKG ENT(P) | DRBG “V” Value | O | O | Admin Command: SANITIZE DEVICE / SECURITY ERASE UNIT Result : Status Code | |
| DRBG “C” Value | O | O | |||||
| DRBG Seed | O | O | |||||
| DRBG Entropy Input String | O | O | |||||
| MEK | O | ||||||
| Revert | Erase user data in all Range by changing the data | Hash_ DRBG / A2107 SHA2-256 / A2109 CKG ENT(P) | DRBG “V” Value | O | O | UID: SPObj (Admin SP) TCG Method: Revert Result: TCG status code | |
| DRBG “C” Value | O | O | |||||
| DRBG Seed | O | O | |||||
| DRBG Entropy Input String | O | O | |||||
| MEK | O | ||||||
| Perform the Self-tests | Power cycling the module to perform self- tests | N/A | N/A | Level 0 Discovery CMD return a failure as a failure indicator | |||
| Authentication | Authenticate the module. (This is not authentication to meet the FIPS 140-3 requirements) | No Security Claimed – PBKDF2 HMAC- SHA2-256 (non- compliant) SHA2-256 (non- compliant) | N/A | N/A | |||
| Diagnostics | Perform Maintenance | N/A | N/A | Maintenance | N/A |
O O O O O O O O Table 8. Approved Services Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
5. Software/Firmware Security - The LDPC (Low-density parity-check) code is applied for integrity test to firmware components of cryptographic module. - When firmware is downloaded into the module, 1024 bytes LDPC parity data per each 8KB data size is generated and integrity test is performed by verifying it every time it is loaded to initiate. - The firmware integrity test is performed when power on reset. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
6. Operational Environment - The cryptographic module operates in a limited operational environment, consisting of the module’s firmware. This limited operational environment does not require any specific security rules, settings, configurations, or restrictions to be set. - The cryptographic module does not provide any general-purpose operating system to the operator. - Firmware download is only available for CMVP validated firmware versions. Unauthorized modification of the firmware is prevented by the pre-operational firmware integrity test and conditional firmware load test. - Since the cryptographic module is zeroized through the maintenance role procedure, it is restricted to prevent uncontrolled access to CSPs and unauthorized modifications to SSPs. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Physical Security Mechanisms | Recommended Frequency of Inspection/Test | Inspection/Test Guidance Details |
|---|---|---|
| Production grade components | N/A | N/A |
The following physical security mechanisms are implemented in a cryptographic module: The following table summarizes the actions required by the Cryptographic Officer Role to ensure that physical security is maintained: N/A N/A The cryptographic module supports the Maintenance role. To assume the Maintenance role, operators must comply with the following rule:
8. Non-Invasive Security The module does not implement any non-invasive attack mitigation techniques. Therefore, this section is not applicable. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Import / Export | Establish -ment | Storage | Zeroisatio n | Use & Related Keys |
|---|---|---|---|---|---|---|---|---|
| DRBG “C” Value / CSP | 440-bit | Hash_ DRBG / A2107 SHA2-256 / A2109 | SP 800-90A Hash_ DRBG / A2107 SHA2-256 / A2109 | N/A | N/A | Plaintext in RAM | Implicitly zeroised by Power on reset | Generates the MEK |
| DRBG “V” Value / CSP | 440-bit | Hash_ DRBG / A2107 SHA2-256 / A2109 | SP 800-90A Hash_ DRBG / A2107 SHA2-256 / A2109 | N/A | N/A | Plaintext in RAM | Implicitly zeroised by Power on reset | Generates the MEK |
| DRBG Seed / CSP | Entropy input: 512-bit Nonce 256-bit | Hash_ DRBG / A2107 SHA2-256 / A2109 | ENT (P) | N/A | N/A | Plaintext in RAM | Implicitly zeroised by Power on reset | Generates the MEK |
| DRBG Entropy Input String / CSP | 512-bit / 256-bit | Hash_ DRBG / A2107 SHA2-256 / A2109 ENT (P) | ENT (P) | N/A | N/A | Plaintext in RAM | Implicitly zeroised by Power on reset | Generates the MEK |
| MEK / CSP | 256-bit | AES-XTS / A2108 CKG | SP 800-90A Hash_ DRBG / A2107 SHA2-256 / A2109 | N/A | N/A | Plain Text in RAM | Implicitly zeroised by Power on reset / Explicitly zeroised via “Lock an LBA Range” and indicate with its indicator | Data encryption and decryption of user data |
| Plaintext in Flash | Explicitly zeroised via “Erase an LBA Range’s Data”, “Revert” and “Sanitize” services and indicate |
9. Sensitive Security Parameter Management - Temporary SSPs and SSPs stored in volatile memory are automatically zeroized upon power-on reset. - The module performs zeroization by overwriting the target SSP with random values generated by the DRBG. - The module does not import or export SSPs. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| with their indicator | |||||||
|---|---|---|---|---|---|---|---|
| Firmware Verification Key / Non- SSP | 112-bit | RSA SigVer / A2110 SHA2-256 / A2109 | Entered during manufacturing | N/A | Plaintext in Hardware SFR4 | Implicitly zeroised by Power on reset / Explicitly zeroised by after completio n of “Update the firmware” with its indicator | Firmware Load Test |
| Plaintext in ROM | N/A |
| Entropy sources | Minimum Number of bits of Entropy | Details | |
|---|---|---|---|
| ENT (P) | 0.5 entropy per bit5 | Entropy source for Hash_DRBG |
N/A Table
5 Estimated amount of entropy per the source’s output bit is 0.72595 and Samsung conservatively claims to be set at 0.5 per bit.
Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Algorithm | Type | Description |
|---|---|---|
| LDPC | Firmware integrity test | Firmware integrity test is performed by using 1024 byte error correction code (ECC) at power-on. |
| Algorithm | Type | Description |
|---|---|---|
| AES-XTS | Critical function test | Duplicate Key Test for AES-XTS described in FIPS 140-3 IG C.I (i.e. key_1 ≠ key_2) when key is generated |
| AES-XTS | Cryptographic algorithm self-test | KAT: AES-256 XTS mode encryption and decryption |
| AES-ECB | Cryptographic algorithm self-test | KAT: AES-256 ECB mode encryption and decryption |
| SHA2-256 | Cryptographic algorithm self-test | KAT: SHA2-256 hash digest |
| RSA SigVer | Cryptographic algorithm self-test | KAT: RSA-2048 with SHA2-256 signature verification is performed before firmware load test |
| RSA SigVer | Firmware load test | RSA-2048 with SHA2-256 signature verification is performed if new FW is downloaded or at every power-on-reset |
| Hash DRBG | Cryptographic algorithm self-test | KATs: HASH-DRBG(SHA2-256) |
| Hash DRBG | Cryptographic algorithm self-test | SP 800-90A Health testing on Instantiate, Generate and Reseed functions |
| ENT (P) | Cryptographic algorithm self-test | Startup and Conditional SP800-90B Heath tests: Repetition count test, Adaptive proportion test |
All cryptographic algorithm self-tests are executed during power-on. During the executing these self-tests, all data output is inhibited until the tests are completed. To execute the periodic self-test on-demand, the operator can power-cycle the module. If a cryptographic module fails a self-test, the module will enter an error state. While in this state, all data output is inhibited. Any additional requests for cryptographic services return a failure indicator. 10.1. Pre-operational Test Table 12. Pre-operational Self-tests - The module does not support Periodic Self-Testing. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| Error State | The module does not provide any crypto operation. | Any conditional known answer test failure. | Power Cycle | The firmware rejects all subsequent SATA commands by responding with 'Abort,' as specified in the SATA specification, and sets the device status to 'Device Fault.' |
| Download Mode | When the Integrity Test for the Bootloader fails. | |||
| Hang | When the Integrity Test for the Main Firmware fails. |
10.3. Error States Table 14: Error States Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
11. Life-Cycle Assurance The cryptographic module operates in the Approved mode of operation by default upon shipment from the vendor’s manufacturing site and does not support a non-approved mode of operation. Section 11.1 provides guidance on the rules for secure installation and operation. Operators must follow this guidance to ensure the cryptographic module operates in compliance with FIPS 140-3 security level 1 requirements. 11.1. Secure Installation
12. Mitigation of Other Attacks The cryptographic module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy