| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Firmware-hybrid |
| Embodiment | Multi-Chip Embedded |
| Status | Active |
| Sunset date | 4/28/2030 |
| Caveat | No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. |
| Vendor | Hitachi Vantara, Ltd. |
flowchart LR
%% Deterministic review-risk graph for Hitachi Storage Hybrid Firmware Encryption Module
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for Hitachi Storage Hybrid Firmware Encryption Module
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;Hitachi Vantara, Ltd. Hitachi Storage Hybrid Firmware Encryption Module © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
| # | Section | Page |
|---|
© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
| Item | Page |
|---|---|
| Table 1: Security Levels | 5 |
| Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) | 6 |
| Table 3: Tested Module Identification – Hybrid Disjoint Hardware | 7 |
| Table 4: Tested Operational Environments - Software, Firmware, Hybrid | 7 |
| Table 5: Modes List and Description | 7 |
| Table 6: Approved Algorithms | 8 |
| Table 7: Security Function Implementations | 10 |
| Table 8: Ports and Interfaces | 10 |
| Table 9: Roles | 11 |
| Table 10: Approved Services | 12 |
| Table 11: Storage Areas | 14 |
| Table 12: SSP Input-Output Methods | 14 |
| Table 13: SSP Zeroization Methods | 15 |
| Table 14: SSP Table 1 | 15 |
| Table 15: SSP Table 2 | 15 |
| Table 16: Pre-Operational Self-Tests | 15 |
| Table 17: Conditional Self-Tests | 16 |
| Table 18: Pre-Operational Periodic Information | 16 |
| Table 19: Conditional Periodic Information | 16 |
| Table 20: Error States | 17 |
| Figure 1: Block Diagram | 6 |
| Section | Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic module specification | 1 |
| 3 | Cryptographic module interfaces | 1 |
| 4 | Roles, services, and authentication | 1 |
| 5 | Software/Firmware security | 1 |
| 6 | Operational environment | 1 |
| 7 | Physical security | 1 |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle assurance | 1 |
| 12 | Mitigation of other attacks | N/A |
| Overall Level | 1 |
This document defines the Security Policy for the Hitachi Storage Hybrid Firmware Encryption Module, hereafter denoted as the module. The module meets FIPS 140-3 overall Level 1 requirements.
Purpose and Use: The module provides data at rest encryption for Hitachi storage system, Hitachi Virtual Storage Platform One Block. In other words, the module encrypts data onto drives and decrypts data read from drives using XTS-AES. The XTS-AES mode was approved by CMVP for protecting the confidentiality of data on storage devices. Module Type: Firmware-hybrid Module Embodiment: MultiChipEmbed Module Characteristics: Cryptographic Boundary: The cryptographic boundary for the module consists of disjoint firmware and hardware components within a same tested operational environment’s physical perimeter (TOEPP). The firmware component is defined as binary CRYPTLOAD, and the hardware component is a CPU. The hardware component implements AES-NI (PAA) and SHA Extensions (PAA). The firmware component of the module is designed to utilize AES-NI and SHA Extensions provided by the CPU. Red dashed lines in Figure 1 show the cryptographic boundary. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
Package or File Name Storage_Encryption_Module_20
Software/ Firmware Version A0-01-00-00
Features
Integrity Test SHA2-256
Tested Operational Environment’s Physical Perimeter (TOEPP): The operational environment hardware for the module is dedicated hardware for Hitachi storage system, Storage Controller Board (hereafter denoted as the board). The enclosure of the board is TOEPP. The hardware component of the module, CPU, is implemented in the board. Operating system for Hitachi storage system works on the CPU. The module works on the operating system. Figure 1: Block Diagram
Tested Module Identification
Model and/or Part Number Intel® Xeon® Silver 4410Y Intel® Xeon® Gold 6421N
Hardware Version Intel® Xeon® Silver 4410Y Intel® Xeon® Gold 6421N
Firmware Version N/A N/A
Processors Intel® Xeon® Silver 4410Y Intel® Xeon® Gold 6421N
Features
Operating System SVOS10 SVOS10
Hardware Platform Storage Controller Board Storage Controller Board
Processors Intel® Xeon® Silver 4410Y Intel® Xeon® Gold 6421N
PAA/PAI Yes Yes
Hypervisor or Host OS
Version(s) A0-01-00-00 A0-01-00-00
| Mode Name | Description | Type | Status Indicator |
|---|---|---|---|
| Approved | All services are available in this mode of operation. | Approved | A status code indicating the completion of service |
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-ECB | A5023 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5025 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5026 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5027 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5028 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5029 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
Table 3: Tested Module Identification – Hybrid Disjoint Hardware Tested Operational Environments - Software, Firmware, Hybrid: Table 4: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module.
The module has no excluded components. Modes List and Description: Table 5: Modes List and Description The module implements only the approved mode of operation. No special API calls or settings
Approved Algorithms: © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-ECB | A5030 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5031 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5032 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5033 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5034 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5035 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5036 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5037 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5038 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5039 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5040 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5041 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5042 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5043 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-ECB | A5044 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38A |
| AES-KW | A5023 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38F |
| AES-XTS Testing Revision 2.0 | A5046 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A5047 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A5048 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A5049 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A5050 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A5051 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A5052 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A5053 | Direction - Decrypt, Encrypt Key Length - 256 | SP 800-38E |
| SHA2-256 | A5024 | Message Length - Message Length: 8-65536 Increment 8 | FIPS 180-4 |
Table 6: Approved Algorithms Vendor-Affirmed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms: © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
Name Secure Hash AES-ECB Core AES-KW Core AES-ECB Core 4 AES-ECB Core 16 AES-XTS Core 512 AES-XTS Core 520
Type SHA BC-UnAuth KTS-Wrap BC-UnAuth BC-UnAuth BC-UnAuth BC-UnAuth
Description Used to generate hash value from inputted data. Used to encrypt/decrypt inputted data. The underlying block cipher of AES-KW. Used to wrap/unwrap an inputted key. Used to encrypt/decrypt inputted data. The underlying block cipher of AES-XTS. Used to encrypt/decrypt inputted data. The underlying block cipher of AES-XTS. Used to encrypt/decrypt inputted data in units of 512 byte. Used to encrypt/decrypt inputted data in units of 520 byte.
Properties
Algorithms SHA2-256: (A5024) AES-ECB: (A5023) AES-KW: (A5023) AES-ECB: (A5023) AES-ECB: (A5025, A5026, A5027, A5028) AES-ECB: (A5029, A5030, A5031, A5032, A5033, A5034, A5035, A5036, A5037, A5038, A5039, A5040, A5041, A5042, A5043, A5044) AES-XTS Testing Revision 2.0: (A5046, A5047, A5048, A5049) AES-ECB: (A5025, A5026, A5027, A5028, A5029, A5030, A5031, A5032, A5033, A5034, A5035, A5036, A5037, A5038, A5039, A5040, A5041, A5042, A5043, A5044) AES-XTS Testing Revision 2.0: (A5050, A5051, A5052, A5053) AES-ECB: (A5025, A5026, A5027, A5028, A5029,
N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.
© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
Name
Type
Description
Properties
Algorithms A5030, A5031, A5032, A5033, A5034, A5035, A5036, A5037, A5038, A5039, A5040, A5041, A5042, A5043, A5044)
| Physical Port | Logical Interface(s) | Data That Passes |
|---|---|---|
| N/A | Data Input | Data to be read from the memory area specified in the API parameters |
| N/A | Data Output | Data to be written to the memory area specified in the API parameters |
| N/A | Control Input | API function calls |
| N/A | Status Output | Responses of the invoked API function |
Table 7: Security Function Implementations
The module has a function that checks if two keys for AES XTS mode are different from each other.
N/A for this module. N/A for this module.
Table 8: Ports and Interfaces The module utilizes APIs as its interfaces and has no physical ports. Additionally, the module does not implement any control output interfaces. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
| Name | Type | Operator Type | Authentication Methods |
|---|---|---|---|
| Cryptographic Officer | Role | CO | None |
| Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Expand AES Key | Expand AES key to round keys. | API return value: 0 (Success) | DEK | Round Key | AES-ECB Core 4 AES-ECB Core 16 AES-XTS Core 512 AES-XTS Core 520 | Cryptographic Officer - DEK: W,E - Round Key: G,R |
| Encrypt (512B) | Encrypt data using XTS-AES in units of 512 byte. | API return value: 0 (Success) | Data to encrypt, Round Key | Encrypted data | AES-XTS Core 512 | Cryptographic Officer - Round Key: W,E |
| Decrypt (512B) | Decrypt data using XTS-AES in units of 512 byte. | API return value: 0 (Success) | Data to decrypt, Round Key | Decrypted data | AES-XTS Core 512 | Cryptographic Officer - Round Key: W,E |
| Encrypt (520B) | Encrypt data using XTS-AES in units of 520 byte. | API return value: 0 (Success) | Data to encrypt, Round Key | Encrypted data | AES-XTS Core 520 | Cryptographic Officer - Round Key: W,E |
| Decrypt (520B) | Decrypt data using XTS-AES in units of 520 byte. | API return value: 0 (Success) | Data to decrypt, Round Key | Decrypted data | AES-XTS Core 520 | Cryptographic Officer - Round Key: W,E |
| Encrypt (ECB 16B) | Encrypt 16 byte data using AES-ECB. | API return value: 0 (Success) | Data to encrypt, KEK | Encrypted data | AES-ECB Core | Cryptographic Officer - KEK: W,E |
| Decrypt (ECB 16B) | Decrypt 16 byte data using AES-ECB. | API return value: 0 (Success) | Data to decrypt, KEK | Decrypted data | AES-ECB Core | Cryptographic Officer - KEK: W,E |
| Encrypt (ECB 64B) | Encrypt 64 byte data using AES-ECB. | API return value: 0 (Success) | Data to encrypt, DEK | Encrypted data | AES-ECB Core 4 | Cryptographic Officer - DEK: W,E |
| Decrypt (ECB 64B) | Decrypt 64 byte data using AES-ECB. | API return value: 0 (Success) | Data to decrypt, DEK | Decrypted data | AES-ECB Core 4 | Cryptographic Officer - DEK: W,E |
N/A for this module. The module does not support authentication for roles.
Table 9: Roles Cryptographic Officer role is implicitly and always assumed.
W,E W,E W,E W,E © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
| Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Encrypt (ECB 256B) | Encrypt 256 byte data using AES-ECB. | API return value: 0 (Success) | Data to encrypt, DEK | Encrypted data | AES-ECB Core 16 | Cryptographic Officer - DEK: W,E |
| Decrypt (ECB 256B) | Decrypt 256 byte data using AES-ECB. | API return value: 0 (Success) | Data to decrypt, DEK | Decrypted data | AES-ECB Core 16 | Cryptographic Officer - DEK: W,E |
| Wrap Key | Wrap a key using a KEK. | API return value: 0 (Success) | Key, KEK | Wrapped key | AES-KW Core | Cryptographic Officer - KEK: W,E |
| Unwrap Key | Unwrap a key using a KEK. | API return value: 0 (Success) | Wrapped key, KEK | Unwrapped key | AES-KW Core | Cryptographic Officer - KEK: W,E |
| Generate Hash | Generate hash value from inputted data. | API return value: 0 (Success) | Data to hash | Hash Value | Secure Hash | Cryptographic Officer |
| Initialize | Startup the module. | None | None | None | None | Cryptographic Officer |
| Show Status | Show module ID, version, and status. | None | None | Module ID, module version, module status | None | Cryptographic Officer |
| Enable CSP Output | Enable CSPs output in plaintext. | None | None | None | None | Cryptographic Officer |
| Disable CSP Output | Disable CSPs output in plaintext. | None | None | None | None | Cryptographic Officer |
| Forcibly Stop | Change the module state to Error state. | None | None | None | None | Cryptographic Officer |
| Reset | Reset the module. | None | None | None | None | Cryptographic Officer |
| Zeroise | Cycle the power of the operational environment. | None | None | None | None | Cryptographic Officer - DEK: Z - Round Key: Z - KEK: Z |
| On- demand integrity test | Initiate the integrity test on demand by power cycle of the operational environment. | None | None | None | None | Cryptographic Officer |
| On demand self test | Initiate the self-tests on demand by power cycle of the operational environment or performing the Reset service, and performing the Initialize service. | None | None | None | None | Cryptographic Officer |
Z Table 10: Approved Services The module provides only approved services. Accordingly, API return codes that confirm the successful completion of these services serve as the indicators. All approved services implemented by the module are listed in above. Each service description also describes all usage of SSPs by the service. The access rights to keys and/or SSPs modes shown in the table are defined as: © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
External firmware can be loaded through a complete image replacement of SVOS10. The new firmware image is executed after the module transitions through a power-on reset. All SSPs are zeroised prior to execution of the new image. A complete image replacement constitutes an entirely new module. Administrators of the module can obtain ID and version of the module as described in Chapter 11.2 to verify that the new module is validated version of the module.
The integrity of CRYPTLOAD (the firmware component of the module) is tested by comparing a SHA2-256 digest value calculated at startup with the SHA2-256 digest value stored in the module that was calculated at compile.
Integrity tests are performed as part of the pre-operational self-tests. Thus, the integrity test can be initiated on demand by power cycle of the operational environment of the module.
Type of Operational Environment: Limited How Requirements are Satisfied: The module does not store SSPs in persistent storage. SSPs are temporarily stored in process memory when the module is being used. The module has control over its own SSPs. The © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
| Storage Area Name | Description | Persistence Type |
|---|---|---|
| Memory | A volatile memory on the operational environment | Dynamic |
Name API Input API Output
From Memory area specified in the API parameters Memory area for the module
To Memory area for the module Memory area specified in the API parameters
Format Type Plaintext Plaintext
Distribution Type Manual Manual
Entry Type Electronic Electronic
SFI or Algorithm
| Zeroization Method | Description | Rationale | Operator Initiation |
|---|---|---|---|
| Power cycle | Power cycle of the operational environment | All SSPs of the module are zeroised by Power cycle because all SSPs are on a volatile memory. | Yes |
operational environment is a single-process system and provides the time separation of the process memory. When the process memory is used by the module, no other process or component can concurrently access the memory. There are no security rules settings or restriction to the configuration of the operational
The module is a multi-chip embedded cryptographic module and conforms to Level 1 requirements for physical security. The cryptographic module consists of production-grade components.
N/A. The module does not implement non-invasive security techniques.
Table 11: Storage Areas The module does not store SSPs in persistent storage. SSPs are temporarily stored in process memory when the module is being used.
Table 12: SSP Input-Output Methods
© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
Name KEK DEK Round Key
Description Key encryption key Data encryption key AES round key
Size - Strength 256 bits - 256 bits 256 bits - 256 bits 1920 bits - 256 bits
Type - Category Symmetric Key - CSP Symmetric Key - CSP Round Key - CSP
Generated By
Established By
Used By AES-ECB Core AES-KW Core AES-ECB Core 4 AES-ECB Core 16 AES-XTS Core 512 AES-XTS Core 520 AES-ECB Core 4 AES-ECB Core 16 AES-XTS Core 512 AES-XTS Core 520
| Name KEK DEK | Input - Output API Input API Input | Storage Memory:Plaintext Memory:Plaintext | Storage Duration While the module is executing Encrypt (ECB 16B), Decrypt (ECB 16B), Wrap Key or Unwrap Key. While the module is executing Expand AES Key, Encrypt (ECB 64B), Decrypt (ECB 64B), Encrypt (ECB 256B) or Decrypt (ECB 256B). | Zeroization Power cycle Power cycle | Related SSPs |
|---|---|---|---|---|---|
| Round Key | API Input API Output | Memory:Plaintext | While the module is executing Expand AES Key, Encrypt (512B), Decrypt (512B), Encrypt (520B), Decrypt (520B). | Power cycle | DEK:Derived From |
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details |
|---|---|---|---|---|---|
| SHA2-256 (A5024) | SHA2-256 | KAT | SW/FW Integrity | None | Hash |
Table 13: SSP Zeroization Methods Administrators of the module can zeroise all SSPs of the module by power cycle of Hitachi storage system. Power cycle can be done in Maintenance Utility, which is Management tool of Hitachi storage system. In details, see System Administrator Guide. Table 14: SSP Table 1 Table 15: SSP Table 2
Table 16: Pre-Operational Self-Tests © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| AES-XTS (512B) | Key sizes: 256 bits | KAT | CAST | None | Encrypt | From the module startup to integrity testing |
| AES-XTS (512B) | Key sizes: 256 bits | KAT | CAST | None | Decrypt | From the module startup to integrity testing |
| AES-XTS (520B) | Key sizes: 256 bits | KAT | CAST | None | Encrypt | From the module startup to integrity testing |
| AES-XTS (520B) | Key sizes: 256 bits | KAT | CAST | None | Decrypt | From the module startup to integrity testing |
| AES-KW (A5023) | Key sizes: 256 bits | KAT | CAST | None | Wrap | From the module startup to integrity testing |
| AES-KW (A5023) | Key sizes: 256 bits | KAT | CAST | None | Unwrap | From the module startup to integrity testing |
| SHA2-256 (A5024) | SHA2-256 | KAT | CAST | None | Hash | From the module startup to integrity testing |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| SHA2-256 (A5024) | KAT | SW/FW Integrity | On Demand | Manually |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| AES-XTS (512B) | KAT | CAST | On Demand | Manually |
| AES-XTS (512B) | KAT | CAST | On Demand | Manually |
| AES-XTS (520B) | KAT | CAST | On Demand | Manually |
| AES-XTS (520B) | KAT | CAST | On Demand | Manually |
| AES-KW (A5023) | KAT | CAST | On Demand | Manually |
| AES-KW (A5023) | KAT | CAST | On Demand | Manually |
| SHA2-256 (A5024) | KAT | CAST | On Demand | Manually |
Once the “Initialize” service is called and all Cryptographic Algorithm Self-tests (CAST) are completed, the module automatically performs firmware integrity test using SHA2-256 over the CRYPTLOAD. If the firmware integrity test fails, the module enters the error state.
Table 17: Conditional Self-Tests When the “Initialize” service is called, the module starts to perform cryptographic algorithm selftests for XTS-AES mode, AES Key Wrap, AES Key Unwrap and SHA2-256. If one of the selftests fails, the module enters the error state.
Table 18: Pre-Operational Periodic Information Table 19: Conditional Periodic Information Pre-operational self-tests, and cryptographic algorithm self-tests for XTS-AES mode, AES Key and b); a) Cycle power of the operational environment or execute “Reset” service. b) Execute “Initialize” service.
© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| Error | A state when the module has encountered an error condition. | Failed the Pre- operational self-tests. Failed the Cryptographic algorithm self-tests. | Power cycling of the operational environment. | Error response to Show Status service. |
The module is integrated into SVOS10. When SVOS10 is installed by the vendor of Hitachi storage system, the module is also installed. To initialize the module, enable the encryption feature of Hitachi storage system (See Encryption License Key Users Guide Chapter 3). No other special procedure is required to securely install and initialize the module.
Administrators can verify that an ID and a version of the module is identical to the ID (Storage_Encryption_Module_20) and the version (A0-01-00-00). See REST API Reference guide Chapter 17.5 to show an ID and a version of the module. Administrators can identify the processor by checking the model of storage system. In the case where the model is VSP One B28, the processor is Intel® Xeon® Gold 6421N. For the models VSP One B23, VSP One B24 or VSP One B26, the processor is Intel® Xeon® Silver 4410Y. See REST API Reference guide to show the model of storage system. All the functions, physical ports, and logical interfaces of the module are available to the Crypto Officer. The module provides only an approved mode of operation. Therefore, no special API calls or settings are required to place the module in an approved mode of operation.
There are no requirements for non-administrator.
The module design corresponds to the module security rules. This subsection documents the security rules enforced by the module to implement the security requirements of this FIPS 140-3 Level 1 module.
N/A. The module does not provide mitigation of other attacks. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).