All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Samsung SATA TCG Opal SSC SEDs PM893 Series

Certificate#4983StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorSamsung Electronics Co., Ltd.
Low review priority  ·  exposes boot-chain verification  ·  last validated 16 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date3/5/2030
CaveatNone
VendorSamsung Electronics Co., Ltd.

Approved Algorithms (5)

AlgorithmACVP Cert
AES-ECBA2108
AES-XTSA2108
Hash DRBGA2107
RSA SigVer (FIPS186-4)A2110
SHA2-256A2109

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Samsung SATA TCG Opal SSC SEDs PM893 Series
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Show Status<br/>Status Output</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>bootloader</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Samsung SATA TCG Opal SSC SEDs PM893 Series
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Show Status<br/>Status Output</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>bootloader</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Samsung SATA TCG Opal SSC SEDs PM893 Series Document Version: 1.0 Hardware Version: MZ7L3480HCHQ-00AMV, MZ7L3960HCJR-00AMV Firmware Version: JXTC1M8Q

Page 2
VersionChange
1.0Initial Version

Revision History Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 3
Table of Contents
#SectionPage
Page 4
AcronymDescription
CTRLController
CPUCentral Processing Unit (ARM-based)
DRAMDynamic Random Access Memory
DRAM I/FDynamic Random Access Memory Interface
ECCError Correcting Code
KATKnown Answer Test
LBALogical Block Address
MEKMedia Encryption Key
PSIDPhysical Presence SID (Security Identifier)
NANDNAND Flash Memory
NAND I/FNAND Flash Interface
SATASerial ATA(Advanced Technology Attachment)
ROMRead-Only Memory

I. Introduction I.1. Scope referred to as a “cryptographic module” or “module”. The SSD (Solid State Drive) satisfies all applicable FIPS 140-3 Security Level 1 requirements, supporting TCG Opal SSC based SED (Self-Encrypting Drive) features. It is designed to protect unauthorized access to the user data stored in its NAND flash memories. The built-in AES hardware engines in the cryptographic module’s controller provide on-the-fly encryption and decryption of the user data without performance loss. The SED’s nature also provides instantaneous sanitization of the user data via cryptographic erase. I.2. Acronyms Table 1. Acronyms Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 5
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5So ft w a r e / F ir m w a re s e cu ri ty1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A

5 Software/Firmware security 1

Table 2. Security Levels Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 6
  1. Cryptographic Module Specification 2.1. Cryptographic Boundary The following photographs depict the different views of the cryptographic module. This multiple-chip embedded module comprises both hardware and firmware components. The module type is hardware. The cryptographic boundary of the module is the physical perimeter of the PCB as following. Figure
  2. Specification of the PM893 2.5’’ Form Factor Cryptographic Boundary Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 7
ModelHardware VersionFirmware VersionDistinguishing Features
PM893MZ7L3480HCHQ-00AMVJXTC1M8Q480GB
MZ7L3960HCJR-00AMV960GB

The firmware utilizes a single-chip controller with a SATA interface on the system side, as well as Samsung NAND flash. The following figure depicts the module’s operational environment. The firmware version included within the scope of this validation must be validated through the FIPS 140-3 CMVP. Any firmware loaded onto this module that is not shown on the module certificate, is out of the scope of this validation and requires a separate FIPS 140-3 validation. Figure

  1. Block Diagram for Samsung SSD SATA TCG Opal SSC SEDs PM893 Series 2.2. Version Information Table
  2. Cryptographic Module Tested Configuration Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 8
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A2107Hash DRBG / SP 800-90A Rev. 1Hash_ DRBG (SHA2-256)Prediction Resistance: No Supports ReseedDeterministic Random Bit Generation
A2108AES-ECB / FIPS 197, SP 800-38AECB256-bit keys with 256-bit key strengthPrerequisite for AES-XTS (A2108)
A2108AES-XTS / FIPS 197, SP 800-38EXTS256-bit keys with 256-bit key strengthData Encryption and Decryption
A2109SHA2-256 / FIPS 180-4SHA2-256SHA2-256Message Digest
A2110RSA SigVer / FIPS 186-4PSS SigVer (SHA2- 256)2048 bitsDigital Signature Verification
Vendor AffirmedCKG / SP 800-133 Rev. 2 (Section 4, 5.1, 6.3)N/AN/ACryptographic Key Generation using DRBG.
N/AENT (P) / SP 800-90BN/AN/ANon-deterministic Random Number Generator (only used for generating seed materials for the DRBG). Provides a minimum of 256 bits of entropy for DRBG seed.
AlgorithmCaveatUse / Function
AES-CCM / FIPS 197, SP 800-38CNo Security Claimed; Non-approved algorithm here is only used for obfuscation and removal of obfuscation the CSP. (IG 2.4.A Scenario #1)Key obfuscation and removal of obfuscation
AES-XTS / FIPS 197, SP 800-38ENo security claimed; AES-XTS is only used to remove obfuscation from the firmware during ROM initialized.Firmware obfuscation removal
HMAC-SHA2-256 / FIPS 198-1 (non-compliant)Non-approved algorithm here are only used as pre-requisite algorithms for PBKDF2 which is used for storing authentication data. (IG 2.4.A Scenario #1)Store authentication data
PBKDF2 / SP 800-132Non-approved algorithms here are only used for storing authentication data using PBKDF2 (IG 2.4.A Scenario #1)Store authentication data
SHA2-256 / FIPS 180-4 (non-compliant)Non-approved algorithm here are only used as pre-requisite algorithms for PBKDF2 which is used for storing authentication data. (IG 2.4.A Scenario #1)Store authentication data

2.3. Cryptographic Functionality The module does not implement any "Non-Approved Algorithms Not Allowed in the Approved Mode of Operation". Note that not all algorithms/modes that appear on the module’s CAVP certificates are utilized by the module. Table 4 lists only the algorithms/modes that are utilized by the module. #1) #1) Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 9
Physical PortLogical Interface TypeData that Passes Over Port / Interface
SATA ConnectorData Input / OutputPlaintext data; signed data; User Data Input / Output
Control InputSATA Command Input logically via an API; signals input logically or physically via one or more physical ports
Status OutputSATA Command Execution Response logically via an API; signal outputs logically or physically via one or more physical ports
JTAGControl InputJTAG signal input logically or physically via physical ports
Status OutputDiagnostic Information outputs logically or physically via one or more physical ports

Table

  1. Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed 2.4. Approved Mode of Operation The module only supports one mode of operation: the Approved mode, in which the Approved cryptographic functions are available. The module automatically transitions to the Approved mode of operation after completing its pre-operational self-tests. The cryptographic module indicates its approved mode through the validated version status, displayed by the Show Status Service in Table 8 via the ATA Identify Controller command. In the approved mode of operation, non-approved algorithms are allowed, but with no security claims in the module.
  2. Cryptographic Module Interfaces The module doesn’t support a Control output interface. Table
  3. Ports and Interfaces Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 10
RoleServiceInputOutput
Cryptographic Officer (CO)Show StatusATA CommandStatus
Lock/Unlock an LBA RangeLBA RangeStatus
Erase an LBA Range’s DataLBA RangeStatus
Update the firmwareFirmware image binaryStatus
Get Random NumberTCG CommandStatus
IO CommandLBA RangeStatus
SanitizeLBA RangeStatus
RevertPSIDN/A
Perform the Self-testsN/AStatus
AuthenticationN/AStatus
Maintenance1DiagnosticsN/AN/A
ServiceDescriptionApproved Security FunctionsSSPsRolesType(s) of AccessIndicator2
EWGZ
Show StatusShow approved version status of the module / FIPS fail modeN/AN/ACOATA Command: Identify Controller command Result : Status Code
Lock / Unlock an LBA RangeBlock or allow read (decrypt) / write (encrypt) of user data.N/AMEK3OOOUID: Locking_GlobalRange / Locking_RangeNNNN TCG Method: Set Result: TCG status code
Erase an LBA Range’s DataErase user data by changing the data encryption key.Hash_ DRBG / A2107 SHA2-256 / A2109DRBG “V” ValueOOUID: K_AES_256_GlobalRange_K ey / K_AES_256_RangeNNNN_K ey
DRBG “C” ValueOO
DRBG SeedOO
  1. Roles, Services, and Authentication The cryptographic module does not support role-based authentication. Roles are implicitly assumed based on the service they are invoking. Table
  2. Roles, Service Commands, Input and Output
4.2.Approved Services The cryptographic module only supports the following approved services and does not support any non-approved services. The abbreviations of the type of access to keys and SSPs have the following interpretation: • G = Generate: The module generates or derives the SSP. • W = Write: The SSP is updated, imported, or written to the volatile storage specified in Table 12. • Z = Zeroise: The module zeroises the SSP. E: EXECUTE; W: WRITE; G: GENERATE; Z: ZEROISE
1Maintenance role is an operator responsible for using the JTAG.
3Specified type of access of Lock/Unlock an LBA Range service to MEK was limited to only RAM. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy
Page 11
CKG ENT(P)DRBG Entropy Input StringOOTCG Method: GenKey Result: TCG status code
MEKO
Update the FirmwareUpdate the firmwareRSA SigVer / A2110Firmware Verification KeyOAdmin Command: DOWNLOAD MICROCODE Result : Status Code
Get Random NumberProvide a random number generated by the CMHash_ DRBG / A2107 SHA2-256 / A2109 CKG ENT(P)DRBG “V” ValueOOUID: ThisSP TCG Method: Random Result: TCG status code
DRBG “C” ValueOO
DRBG SeedOO
DRBG Entropy Input StringOO
IO CommandRead / Write user dataAES-XTS / A2108MEKOATA Command: Read / Write Result : Status Code
SanitizeErase user data by changing the data encryption keyHash_ DRBG / A2107 SHA2-256 / A2109 CKG ENT(P)DRBG “V” ValueOOAdmin Command: SANITIZE DEVICE / SECURITY ERASE UNIT Result : Status Code
DRBG “C” ValueOO
DRBG SeedOO
DRBG Entropy Input StringOO
MEKO
RevertErase user data in all Range by changing the dataHash_ DRBG / A2107 SHA2-256 / A2109 CKG ENT(P)DRBG “V” ValueOOUID: SPObj (Admin SP) TCG Method: Revert Result: TCG status code
DRBG “C” ValueOO
DRBG SeedOO
DRBG Entropy Input StringOO
MEKO
Perform the Self-testsPower cycling the module to perform self- testsN/AN/ALevel 0 Discovery CMD return a failure as a failure indicator
AuthenticationAuthenticate the module. (This is not authentication to meet the FIPS 140-3 requirements)No Security Claimed – PBKDF2 HMAC- SHA2-256 (non- compliant) SHA2-256 (non- compliant)N/AN/A
DiagnosticsPerform MaintenanceN/AN/AMaintenanceN/A

O O O O O O O O Table 8. Approved Services Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 12

5. Software/Firmware Security - The LDPC (Low-density parity-check) code is applied for integrity test to firmware components of cryptographic module. - When firmware is downloaded into the module, 1024 bytes LDPC parity data per each 8KB data size is generated and integrity test is performed by verifying it every time it is loaded to initiate. - The firmware integrity test is performed when power on reset. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 13

6. Operational Environment - The cryptographic module operates in a limited operational environment, consisting of the module’s firmware. This limited operational environment does not require any specific security rules, settings, configurations, or restrictions to be set. - The cryptographic module does not provide any general-purpose operating system to the operator. - Firmware download is only available for CMVP validated firmware versions. Unauthorized modification of the firmware is prevented by the pre-operational firmware integrity test and conditional firmware load test. - Since the cryptographic module is zeroized through the maintenance role procedure, it is restricted to prevent uncontrolled access to CSPs and unauthorized modifications to SSPs. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 14
Physical Security MechanismsRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Production grade componentsN/AN/A

The following physical security mechanisms are implemented in a cryptographic module: The following table summarizes the actions required by the Cryptographic Officer Role to ensure that physical security is maintained: N/A N/A The cryptographic module supports the Maintenance role. To assume the Maintenance role, operators must comply with the following rule:

Page 15

8. Non-Invasive Security The module does not implement any non-invasive attack mitigation techniques. Therefore, this section is not applicable. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 16
Key / SSP Name / TypeStrengthSecurity Function and Cert. NumberGenerationImport / ExportEstablish -mentStorageZeroisatio nUse & Related Keys
DRBG “C” Value / CSP440-bitHash_ DRBG / A2107 SHA2-256 / A2109SP 800-90A Hash_ DRBG / A2107 SHA2-256 / A2109N/AN/APlaintext in RAMImplicitly zeroised by Power on resetGenerates the MEK
DRBG “V” Value / CSP440-bitHash_ DRBG / A2107 SHA2-256 / A2109SP 800-90A Hash_ DRBG / A2107 SHA2-256 / A2109N/AN/APlaintext in RAMImplicitly zeroised by Power on resetGenerates the MEK
DRBG Seed / CSPEntropy input: 512-bit Nonce 256-bitHash_ DRBG / A2107 SHA2-256 / A2109ENT (P)N/AN/APlaintext in RAMImplicitly zeroised by Power on resetGenerates the MEK
DRBG Entropy Input String / CSP512-bit / 256-bitHash_ DRBG / A2107 SHA2-256 / A2109 ENT (P)ENT (P)N/AN/APlaintext in RAMImplicitly zeroised by Power on resetGenerates the MEK
MEK / CSP256-bitAES-XTS / A2108 CKGSP 800-90A Hash_ DRBG / A2107 SHA2-256 / A2109N/AN/APlain Text in RAMImplicitly zeroised by Power on reset / Explicitly zeroised via “Lock an LBA Range” and indicate with its indicatorData encryption and decryption of user data
Plaintext in FlashExplicitly zeroised via “Erase an LBA Range’s Data”, “Revert” and “Sanitize” services and indicate

9. Sensitive Security Parameter Management - Temporary SSPs and SSPs stored in volatile memory are automatically zeroized upon power-on reset. - The module performs zeroization by overwriting the target SSP with random values generated by the DRBG. - The module does not import or export SSPs. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 17
with their indicator
Firmware Verification Key / Non- SSP112-bitRSA SigVer / A2110 SHA2-256 / A2109Entered during manufacturingN/APlaintext in Hardware SFR4Implicitly zeroised by Power on reset / Explicitly zeroised by after completio n of “Update the firmware” with its indicatorFirmware Load Test
Plaintext in ROMN/A
Entropy sourcesMinimum Number of bits of EntropyDetails
ENT (P)0.5 entropy per bit5Entropy source for Hash_DRBG

N/A Table

  1. SSPs - The module contains an entropy source, compliant with SP 800-90B, within the module’s cryptographic boundary. Table
  2. Non-Deterministic Random Number Generation Specification HW SFR (Special Function Register) is a register within a hardware cryptographic algorithm IP, which has characteristic of volatile memory.

5 Estimated amount of entropy per the source’s output bit is 0.72595 and Samsung conservatively claims to be set at 0.5 per bit.

Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 18
AlgorithmTypeDescription
LDPCFirmware integrity testFirmware integrity test is performed by using 1024 byte error correction code (ECC) at power-on.
AlgorithmTypeDescription
AES-XTSCritical function testDuplicate Key Test for AES-XTS described in FIPS 140-3 IG C.I (i.e. key_1 ≠ key_2) when key is generated
AES-XTSCryptographic algorithm self-testKAT: AES-256 XTS mode encryption and decryption
AES-ECBCryptographic algorithm self-testKAT: AES-256 ECB mode encryption and decryption
SHA2-256Cryptographic algorithm self-testKAT: SHA2-256 hash digest
RSA SigVerCryptographic algorithm self-testKAT: RSA-2048 with SHA2-256 signature verification is performed before firmware load test
RSA SigVerFirmware load testRSA-2048 with SHA2-256 signature verification is performed if new FW is downloaded or at every power-on-reset
Hash DRBGCryptographic algorithm self-testKATs: HASH-DRBG(SHA2-256)
Hash DRBGCryptographic algorithm self-testSP 800-90A Health testing on Instantiate, Generate and Reseed functions
ENT (P)Cryptographic algorithm self-testStartup and Conditional SP800-90B Heath tests: Repetition count test, Adaptive proportion test

All cryptographic algorithm self-tests are executed during power-on. During the executing these self-tests, all data output is inhibited until the tests are completed. To execute the periodic self-test on-demand, the operator can power-cycle the module. If a cryptographic module fails a self-test, the module will enter an error state. While in this state, all data output is inhibited. Any additional requests for cryptographic services return a failure indicator. 10.1. Pre-operational Test Table 12. Pre-operational Self-tests - The module does not support Periodic Self-Testing. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 19
NameDescriptionConditionsRecovery MethodIndicator
Error StateThe module does not provide any crypto operation.Any conditional known answer test failure.Power CycleThe firmware rejects all subsequent SATA commands by responding with 'Abort,' as specified in the SATA specification, and sets the device status to 'Device Fault.'
Download ModeWhen the Integrity Test for the Bootloader fails.
HangWhen the Integrity Test for the Main Firmware fails.

10.3. Error States Table 14: Error States Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy

Page 20

11. Life-Cycle Assurance The cryptographic module operates in the Approved mode of operation by default upon shipment from the vendor’s manufacturing site and does not support a non-approved mode of operation. Section 11.1 provides guidance on the rules for secure installation and operation. Operators must follow this guidance to ensure the cryptographic module operates in compliance with FIPS 140-3 security level 1 requirements. 11.1. Secure Installation

Page 21

12. Mitigation of Other Attacks The cryptographic module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3. Samsung Electronics Co., Ltd. SSD FIPS 140-3 Security Policy