All modules
CMVP Validated Module · FIPS 140-3 Security Policy

KIOXIA FIPS TC58NC1132GTC Crypto Sub-Chip

Certificate#4984StandardFIPS 140-3Level2TypeHardwareEmbodimentSingle ChipStatusActiveVendorKIOXIA Corporation
Medium review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 16 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date10/31/2028
CaveatWhen installed, initialized and configured as specified in Section 11 of the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service
VendorKIOXIA Corporation

Approved Algorithms (8)

AlgorithmACVP Cert
AES-CBCC1925
AES-ECBC1925
AES-XTSC1925
Hash DRBGC2002
HMAC-SHA2-256C1925
KDF SP800-108C2001
RSA SigVer (FIPS186-4)C2009
SHA2-256C1925

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for KIOXIA FIPS TC58NC1132GTC Crypto Sub-Chip
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware load<br/>Load Firmware</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show Status</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for KIOXIA FIPS TC58NC1132GTC Crypto Sub-Chip
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware load<br/>Load Firmware</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show Status</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

KIOXIA FIPS TC58NC1132GTC Crypto Sub-Chip KIOXIA CORPORATION Rev 2.5.0

1 Oct 22, 2024
Page 2
2 Oct 22, 2024
Page 3
SectionLevel
1. General2
2. Cryptographic Module Specification2
3. Cryptographic Module Interfaces2
4. Roles, Services, and Authentication2
5. Software/Firmware Security2
6. Operational EnvironmentN/A
7. Physical Security2
8. Non-invasive SecurityN/A
9. Sensitive Security Parameter Management2
10. Self-tests2
11. Life-cycle Assurance2
12. Mitigation of Other AttacksN/A
Overall Level2

This document explains precise specification of the security rules about KIOXIA FIPS TC58NC1132GTC Crypto Sub-Chip. The Cryptographic Module (CM) meets the requirements of FIPS 140-3 Security Level 2 Overall. The Table below shows the security level detail. Table 1 ‐ Security Levels This document is non-proprietary and may be reproduced in its original entirety. Section 1.1 - Acronyms

AESAdvanced Encryption Standard
DRBGDeterministic Random Bit Generator
HMACThe Keyed-Hash Message Authentication code
KATKnown Answer Test
POSTPre-Operational Self-Test
CASTCryptographic Algorithm Self-Test
PSIDPrinted SID
SEDSelf-Encrypting Drive
SHASecure Hash Algorithm
SIDSecurity ID
TCGTrusted Computing Group 3 Oct 22, 2024
Page 4
Physical single-chipThe sub-chip cryptographic subsystem soft circuitry coreThe associated firmware
TC58NC1132GTC 0003TC58NC1132GTC CRPT module 0001SC02AS
CAVP CertAlgorithm and StandardMode/ MethodDescription/Key Size(s)/ Key Strength(s)Use/Function
#C1925AES256 (FIPS 197 / SP800-38A)CBCKey Size: 256 bits/ Key Strength: 256 bitsData Encryption/ Decryption

Section 2

4 Oct 22, 2024
Page 5
#C1925AES256 (FIPS 197 / SP800-38A, SP800-38E)XTS, ECB1Key Size: 256 bits/ Key Strength: 256 bitsData Encryption/ Decryption
#C1925SHA256 (FIPS 180-4)N/AN/AHashing messages
#C1925HMAC-SHA256 (FIPS 198-1)N/AKey Size: 256 bits/ Key Strength: 256 bitsMessage Authentication Code
#C2009RSASSA-PKCS#1-v1_5 (FIPS 186-4)N/AKey Size: 2048 bit/ Key Strength: 112 bitsSignature verification
#C2002Hash_DRBG (SP800-90A Rev.1)N/AHash based: SHA256Deterministic Random Bit Generation
#C2001KBKDF (SP800-108 Revised)CounterMACs: HMAC-SHA256/ Key Size: 256 bits/ Key Strength: 256 bitsKey derivation
#C1925KTS (IG D.G)N/ACombination of AES256 CBC Mode and HMAC-SHA256 / Key Size: 256 bits/ Key Strength: 256 bitsKey Transport Scheme
Vendor AffirmationCKG (SP800-133 Rev.2)N/AMethods described in section 4 of the SP800-133 Rev.2Cryptographic Key Generation
ENT(P)Entropy Source (SP800-90B)N/AN/AHardware RNG used to seed the approved Hash_DRBG.

Table 3 ‐ Approved Algorithm The CM does not implement any Non-Approved Algorithms Allowed in the Approved Mode of Operation. ECB mode is used as a prerequisite of XTS mode. ECB is not directly used in services of the Cryptographic Module. The CM performs a check that the XTS Key1 and XTS Key2 are different according to IG C.I. AES-XTS is only used for encryption/decryption of data stored in solid state drives equipped with this CM.

5 Oct 22, 2024
Page 6
Physical portLogical InterfaceData that passes over port/interface
Mailbox AES circuit DMAC Lock CheckerData InputMailbox input parameter. User data. Read/Write destination address information.
Mailbox AES circuit DMACData OutputMailbox output parameter. User data.
Mailbox Lock CheckerControl InputMailbox command information. Lock status confirmation request signal.
Mailbox Lock CheckerStatus OutputMailbox command result. Lock status confirmation result signal.
Power PINPower InputPower

Section 2.3

6 Oct 22, 2024
Page 7
RoleServiceInputOutput
FIPS Crypto Officer (EraseMaster)Cryptographic Erase Set PIN (for EraseMaster)Mailbox commandMailbox command result
FIPS Crypto Officer (SID)Download Port Lock/Unlock Firmware Download2 Set PIN (for SID)Mailbox commandMailbox command result
FIPS Crypto Officer (BandMaster0)Band Lock/Unlock (for GlobalRange) Set Band Position and Size (for GlobalRange) Set PIN (for BandMaster0)Mailbox commandMailbox command result
Data Read/WriteEncrypted/Decrypted dataDecrypted/Encrypted data
FIPS Crypto Officer (BandMaster1)Band Lock/Unlock (for Band1) Set Band Position and Size (for Band1) Set PIN (for BandMaster1)Mailbox commandMailbox command result
Data Read/WriteEncrypted/Decrypted dataDecrypted/Encrypted data
FIPS Crypto Officer (BandMaster64)Band Lock/Unlock (for Band64) Set Band Position and Size (for Band64) Set PIN (for BandMaster64)Mailbox commandMailbox command result
Data Read/WriteEncrypted/Decrypted dataDecrypted/Encrypted data
NoneFirmware Verification Random Number Generation Show Status ZeroisationMailbox commandMailbox command result
Check Lock StateRead/Write CommandLock state of each Band
ResetPowerN/A

Section 4 – Roles Services and Authentication The relation between Roles and Services in this CM is shown below. … … … … Table 5 ‐ Roles, Service Commands, Input and output The CM supports the configuration of roles and services. The authenticated operator is expected to configure locked bands for data storage, the associated role and the lock-based authentication data (PIN) per Table 6 (refer to section 11 for detail settings to maintain secure operation). Bands that are not configured are considered unprotected or plaintext. This configuration enables Data Read/Write service using the lock-based authentication model (IG 4.1.A). To Read/Write data from/to each band, an operator must unlock the bands with appropriate authenticated roles. Once the bands are unlocked, Read and Write access to the bands must be controlled by a trusted operator outside of the module who has been “Firmware Download” service is controlled by SID role and signature of downloaded external firmware is verified (RSASSA-PKCS#1-v1_5).

7 Oct 22, 2024
Page 8
Role NameRole TypeType of AuthenticationAuthenticationAuthentication StrengthMulti Attempt strength
EraseMasterCrypto OfficerRolePIN1 / 264 < 1 / 1,000,00030 / 264 < 1 / 100,000
SIDCrypto OfficerRolePIN1 / 264 < 1 / 1,000,00030 / 264 < 1 / 100,000
BandMaster0Crypto OfficerRolePIN1 / 264 < 1 / 1,000,00030 / 264 < 1 / 100,000
BandMaster1Crypto OfficerRolePIN1 / 264 < 1 / 1,000,00030 / 264 < 1 / 100,000
BandMaster64Crypto OfficerRolePIN1 / 264 < 1 / 1,000,00030 / 264 < 1 / 100,000

authenticated as the associated role until powered off. The module prevents Data read/write service for locked bands. If Read and Write access needs to be inhibited prior to power off, the operator who authenticates the role must set the bands to the locked state again. Section 4.1 – Roles and Authentication This section describes roles, authentication method, and strength of authentication. … … … … … … Table 6 ‐ Identification and Authentication Policy The CM performs role authentication by comparing whether the PIN entered by the user matches the information stored inside the CM. PINs are hashed with SHA-256 to store them on the CM. The PIN entered by the user is hashed and compared to the stored PIN hash. PINs can be changed by executing the Set PIN Service (see Section4.2) with appropriate roles authenticated. The CM refuses to set a PIN less than 8 bytes, and responds with an error if such a setting is attempted. Therefore, the probability that a random attempt will succeed is 1 / 264 < 1 / 1,000,000 (the CM accepts any value (0x00-0xFF) as each byte of PIN). The CM waits 2sec when authentication attempt fails, so the maximum number of authentication attempts is

30 times in 1 min. Consequently, the probability that random attempts in 1min will succeed is

8 Oct 22, 2024
Page 9
ServiceDescriptionApproved Security FunctionKeys and/or SSPsRole(s)Access rights to Keys and/or SSPs3Indicator
Band Lock/UnlockLock or unlock setting for read/ write of user data in a band.KBKDFKDK MEKsBandMaster0 … BandMaster6 4E GMailbox command result
HMAC-SHA256System MAC KeyE
Check Lock StateCheck a lock state of band that read / write user data.N/AN/ANoneN/ABand Lock state
Data Read/WriteEncryption / decryption of user data to/from unlocked band of SSD4.AES256-XTSMEKsBandMaster0 … BandMaster6 4EReadable/Writable signal from lock check module
Cryptographic EraseErase user data (in cryptographic means) by changing the key that derives the data encryption key.CKG (Hash_DRBG)DRBG Internal Value KDKEraseMasterE G, ZMailbox command result
KBKDFKDK MEKsE G, Z
HMAC-SHA256System MAC KeyE
AES256-CBCSystem Enc KeyE
KTSKDKW, R
Download Port Lock/UnlockLock / unlock firmware download.N/AN/ASIDN/AMailbox command result
Firmware VerificationDigital signature verification for firmware outside the CM.RSASSA-PKCS#1-v 1_5Public Key embedded on the CM’s codeNoneEMailbox command result
Firmware DownloadDownload a firmware image5.SHA256PubKey1SIDW, EMailbox command result
RSASSA-PKCS#1-v 1_5PubKey1E
Random Number GenerationProvide a random number generated by the CM.Hash_DRBGDRBG Internal ValueNoneEMailbox command result
CKG (Hash_DRBG)DRBG Internal Value KDKE G, Z
KBKDFKDK MEKsE G, Z

Section 4.2 – Services This section describes services which the CM provides. SSD . 1_5 Set the location and

3 The letters (G, R, W, E, Z) mean Generate, Read, Write, Execute and Zeroise respectively.

The band has to be unlocked by corresponding BandMaster beforehand. Only the CMVP validated version is to be used

9 Oct 22, 2024
Page 10
HMAC-SHA256System MAC KeyE
AES256-CBCSystem Enc KeyE
KTSKDKW, R
Set PINSet PIN (authentication data).SHA256PINsEraseMaster SID BandMaster0 … BandMaster6 46W, EMailbox command result
HMAC-SHA256System MAC KeyE
AES256-CBCSystem ENC KeyE
KTSPINsW, R
Show StatusReport status of the CM and versioning information.N/AN/ANoneN/AMailbox command result
ZeroisationErase SSPs.N/ARKeyNone7ZMailbox command result
KDKZ
MEKsZ
PINsZ
System MAC KeyZ
System Enc KeyZ
DRBG Internal ValueZ
ResetPower-OFF: Delete SSPs in RAM.N/ASystem MAC KeyNoneZN/A
System Enc KeyZ
KDKZ
MEKsZ
PINsZ
DRBG Internal ValueZ
PubKey1Z
Power-ON: Runs various self-tests to be performed at power-on ( POSTs, CASTs, Firmware Load test ) and generate / import some SSPs.RSASSA-PKCS#1-v 1_5PubKey1W, E
KBKDFRkey System MAC Key System Enc KeyE G G
Entropy SourceDRBG SeedG
Hash_DRBGDRBG Seed DRBG Internal ValueE, Z G
HMAC-SHA256System MAC KeyE
AES256-CBCSystem Enc KeyE
KTSKDK PINsW W

… 1_5 Note 1: “CKG(Hash_DRBG)” means direct use of Hash_DRBG output as a key. Note 2: “PINs” in the above table means “SID/BandMaster(s)/EraseMaster PINs”. Table 7 ‐ Approved services Each role can set a PIN for themselves only. Need to input PSID, which is public drive-unique value used for the zeroisation service.

10 Oct 22, 2024
Page 11

Section 5

11 Oct 22, 2024
Page 12
Physical Security MechanismRecommended Frequency of Inspection/TestInspection/Test Guidance Detail
Passivated opaque packageEvery month or every two monthsConfirmation that there is no visual damage

The CM is a sub-chip enclosed in a single chip that is an opaque package. Gathering information of the module’s internal construction or components is impossible without forcing the package to open. In this case, it is confirmed package damage as a tamper-evidence. Operators of the CM can ensure that the physical security is maintained to confirm the package has no obvious attack damage. If the operator discovers tamper evidence, the CM should be removed. Front Back Figure 2 - TC58NC1132GTC 0003 SoC Section 8 – Non-invasive security The CM does not apply Non-invasive security.

12 Oct 22, 2024
Page 13
Key/SSP Name/Ty peStrength (bit)Security Function and Cert NumberGenerationImport/ ExportEstablishmentStorageZeroisationUse & related keys
Critical Security Parameters (CSPs)
RKey256KBKDF (#C2001)Hash_DRBG (Method SP800-133 Rev.2 Section 4)N/AManufacturingPlaintext in OTPExplicit Zeroisation serviceDerivation of System Enc Key and System MAC Key
System Enc Key256AES-CBC (#C1925)KDF in Counter ModeN/APower-OnPlaintext in RAMExplicit Zeroisation service Implicit Power-OffData Encryption / Decryption for KTS
System MAC Key256HMAC (#C1925)KDF in Counter ModeN/APower-OnPlaintext in RAMExplicit Zeroisation service Implicit Power-OffMessage Authentication Code generation and verification for KTS
KDK256KBKDF (#C2001)Hash_DRBG (Method SP800-133 Rev.2 Section 4)Imported and Exported by KTS (see Table 3)Cryptographic Erase service, Set Band Position and Size servicePlaintext in RAM Encrypted in System Area outside the module using the Approved KTSExplicit Zeroisation service, Cryptographic Erase service, Set Band Position and Size service Implicit Power-OffDerivation of MEKs

Section 9 – Sensitive security parameter management The CM uses keys and SSPs in the following table. 4)

13 Oct 22, 2024
Page 14
MEKs256AES-XTS (#C1925)KDF in Counter ModeN/ABand Lock/Unlock service, Cryptographic Erase service, Set Band Position and Size servicePlaintext in AES registerExplicit Zeroisation service, Cryptographic Erase service, Set Band Position and Size service Implicit Power-OffData encryption / decryption
SID/BandMa ster(s)/Erase Master PINsReferred to in Section 4.1 (Table 6)SHA256 (#C1925)Electronic inputImported and Exported by KTS (see Table 3)Set PIN serviceHashed in RAM Hashed + Encrypted in System Area outside the module using the Approved KTSExplicit Zeroisation service Implicit Power-OffUser authentication
DRBG Internal ValueV: 440 bits C: 440 bitsHash_DRBG (#C2002)SP800-90A Instantiation of Hash_DRBGN/APower-OnPlaintext in RAMExplicit Zeroisation service Implicit Power-OffRandom number generation
DRBG SeedEntropy Input String and Nonce: 512 bitsHash_DRBG (#C2002)Entropy collected from Entropy Source at instantiation (Minimum entropy of 8N/APower-OnPlaintext in RAMImplicit Immediately after use8Random number generation
14 Oct 22, 2024
Page 15
bits: 6.31)
Public Security Parameters (PSPs)
PubKey1112RSA (#C2009)Electronic inputImported during FW load.Power-on FW Download servicePlaintext in RAM Hashed in OTPImplicit Power-Off (Data in RAM)Signature verification.
Entropy sourceMinimum number of bits of entropyDetails
Entropy Source9Minimum entropy of 8 bits is 6.31.Hardware RNG used to seed the approved Hash_DRBG.
FunctionSelf-Test TypeExecution ConditionAbstractFailure Behavior
AES256-CBCConditionalPower-OnEncrypt/Decrypt KATEnters Boot Error State (Indicated Error Code: 0x24)
AES256-XTSConditionalPower-OnEncrypt and Decrypt KATEnters Boot Error State.

Table 9 ‐ SSPs Table 10 ‐ Non-Deterministic Random Number Generation Specification For the Entropy Source listed in the table above, self-tests are performed each time before data is obtained (see Section 10 for details of these self-tests). When these tests detect that the Entropy Source cannot generate the sufficient amount of entropy, the CM is transient to error state. The CM can be recovered from the error state by rebooting the module, and the obtaining several trials of reboot, the CM may be sent back to factory to recover from error state. Section 10 – Self Tests The CM runs self-tests in the following table. The Entropy Source is a hardware module inside the CM boundary. The Entropy Source supplies the Hash_DRBG with 512 bits entropy input. From Table 10 this input contains about

404 bits of entropy, which is sufficient entropy to obtain 256 bits of security strength.

15 Oct 22, 2024
Page 16
(Indicated Error Code: 0x23)
SHA256ConditionalPower-OnDigest KATEnters Boot Error State. (Indicated Error Code: 0x25)
HMAC-SHA256ConditionalPower-OnDigest KATEnters Boot Error State. (Indicated Error Code: 0x26)
Hash_DRBGConditionalPower-OnDRBG KATEnters Boot Error State. (Indicated Error Code: 0x18/0x19)
RSASSA-PKCS#1-v 1_5ConditionalPower-OnSignature verification KATEnters Boot Error State. (Indicated Error Code: 0x27)
KDF in Counter ModeConditionalPower-OnKDF KATEnters Boot Error State (Indicated Error Code: 0x28)
Entropy Source (Health tests of noise source at startup.)ConditionalPower-OnVerify not deviating from the intended behavior of the noise source by Repetition Count Test and Adaptive Proportion Test specified in SP800-90B.Enters Boot Error State (Indicated Error Code: 0x2C/0x2D)
Hash_DRBGConditionalRandom number generationVerify newly generated random number not equal to previous oneEnters Error State. (Indicated Error Code: 0x1D)
Entropy SourceConditionalEntropy output requestVerify newly generated random number not equal to previous oneEnters Error State. (Indicated Error Code: 0x1E)
Entropy Source (Continuous noise source health tests during operation.)ConditionalEntropy output requestVerify not deviating from the intended behavior of the noise source by Repetition Count Test and Adaptive Proportion Test specified in SP800-90B.Enters Error State. (Indicated Error Code: 0x2C/0x2D)
Firmware load testConditional10Power-onVerify signature of loaded firmware image by RSASSA-PKCS#1-v1_5Enters Power Up Load Test Error State (Indicated Error Code: 0x13)
FW downloadVerify signature ofEnters Conditional Load Test Error

loaded into the CM can be confirmed.

16 Oct 22, 2024
Page 17
downloaded firmware image by RSASSA-PKCS#1-v1_5State. After reporting Error code, transition from error state to normal state and continue to operate with FW before download. (Indicated Error Code: 0x13)
Firmware integrity testPre-operationalPower-OnVerify ROM code integrity with 32bit CRC.Enters Boot Error State (Implicit error reporting by stopping the startup sequence)

Table 11 ‐ Self Tests As shown in the table above, self-tests are performed automatically at the CM startup and before execution certain security functions. Operator can also initiate self-test on-demand for periodic testing by using the Reset service which is automatically invoked when the module is powered-off and powered-on (rebooted). If the self-tests fail, the CM reports error status and enters to the error state. In this case, the CM must be powered-off to clear error condition. When power-on is executed again, self-tests are also executed like an on-demand operator reset. If the CM continuously enters in error state in spite of several trials of reboot, the CM may be sent back to factory to recover from error Section 11 – Life-cycle Assurance In the SSD’s manufacturing process, installation is executed as below:

  1. The Firmware described in Section 2.1 is downloaded into the CM.
  2. Initial SSPs are generated.
  3. Initial authentication information is set to the CM.
  4. System area including SSPs generated in Step2 and Step3 are encrypted and calculated message authentication code. Initial operations to setup this CM are following:
  5. Load Firmware into the CM.
  6. Load System area including SSPs into the CM.
  7. Execute Range state setting method.
  8. Execute Download port setting method. The CM switches to approved mode after the initial operation success. When the initial operation succeeds, the CM indicates success on the Status Output interface. Users can confirm
17 Oct 22, 2024
Page 18

that the CM is in approved mode by executing Show Status service and checking that the startup is successfully completed. For secure operation, the following settings must be maintained:  Data Locking Protection is Enabled  Each Band is set to be locked when power-on. Bands that are not configured are considered unprotected or plaintext. (Refer to SSD setting procedure11 ) As described in Section 2, the CM is used by being embedded in the solid state drive. Therefore, there are no maintenance requirements for the CM alone. Guidance for this module is provided to solid state drive developers who embed the CM. The usage and maintenance of solid state drives with the CM built-in are outside of the scope of this document. Section 12 – Mitigation of Other Attacks The CM does not mitigate other attacks beyond the scope of FIPS 140-3 requirements.

11 For maintaining secure condition, the SSD needs several setting at least.

Owners of the SSD that embeds the CM must use it securely according to the followings:

  1. Both ReadLockEnabled and WriteLockEnabled are set to “True” for each band (included Global Range) and it must not be modified.
  2. For each band, “Power Cycle” of LockOnReset setting is not change.
18 Oct 22, 2024