All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Hitachi Storage Hybrid Firmware Encryption Module

Certificate#5013StandardFIPS 140-3Level1TypeFirmware-hybridEmbodimentMulti-Chip EmbeddedStatusActiveVendorHitachi Vantara, Ltd.
Medium review priority  ·  no TCB surface named  ·  last validated 15 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeFirmware-hybrid
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date4/28/2030
CaveatNo assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorHitachi Vantara, Ltd.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Hitachi Storage Hybrid Firmware Encryption Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Hitachi Storage Hybrid Firmware Encryption Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Hitachi Vantara, Ltd. Hitachi Storage Hybrid Firmware Encryption Module © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 2
Table of Contents
#SectionPage
Page 3

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)6
Table 3: Tested Module Identification – Hybrid Disjoint Hardware7
Table 4: Tested Operational Environments - Software, Firmware, Hybrid7
Table 5: Modes List and Description7
Table 6: Approved Algorithms8
Table 7: Security Function Implementations10
Table 8: Ports and Interfaces10
Table 9: Roles11
Table 10: Approved Services12
Table 11: Storage Areas14
Table 12: SSP Input-Output Methods14
Table 13: SSP Zeroization Methods15
Table 14: SSP Table 115
Table 15: SSP Table 215
Table 16: Pre-Operational Self-Tests15
Table 17: Conditional Self-Tests16
Table 18: Pre-Operational Periodic Information16
Table 19: Conditional Periodic Information16
Table 20: Error States17
Figure 1: Block Diagram6
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document defines the Security Policy for the Hitachi Storage Hybrid Firmware Encryption Module, hereafter denoted as the module. The module meets FIPS 140-3 overall Level 1 requirements.

1.2 Security Levels
2.1 Description

Purpose and Use: The module provides data at rest encryption for Hitachi storage system, Hitachi Virtual Storage Platform One Block. In other words, the module encrypts data onto drives and decrypts data read from drives using XTS-AES. The XTS-AES mode was approved by CMVP for protecting the confidentiality of data on storage devices. Module Type: Firmware-hybrid Module Embodiment: MultiChipEmbed Module Characteristics: Cryptographic Boundary: The cryptographic boundary for the module consists of disjoint firmware and hardware components within a same tested operational environment’s physical perimeter (TOEPP). The firmware component is defined as binary CRYPTLOAD, and the hardware component is a CPU. The hardware component implements AES-NI (PAA) and SHA Extensions (PAA). The firmware component of the module is designed to utilize AES-NI and SHA Extensions provided by the CPU. Red dashed lines in Figure 1 show the cryptographic boundary. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 6

Package or File Name Storage_Encryption_Module_20

Software/ Firmware Version A0-01-00-00

Features

Integrity Test SHA2-256

Tested Operational Environment’s Physical Perimeter (TOEPP): The operational environment hardware for the module is dedicated hardware for Hitachi storage system, Storage Controller Board (hereafter denoted as the board). The enclosure of the board is TOEPP. The hardware component of the module, CPU, is implemented in the board. Operating system for Hitachi storage system works on the CPU. The module works on the operating system. Figure 1: Block Diagram

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 7

Model and/or Part Number Intel® Xeon® Silver 4410Y Intel® Xeon® Gold 6421N

Hardware Version Intel® Xeon® Silver 4410Y Intel® Xeon® Gold 6421N

Firmware Version N/A N/A

Processors Intel® Xeon® Silver 4410Y Intel® Xeon® Gold 6421N

Features

Operating System SVOS10 SVOS10

Hardware Platform Storage Controller Board Storage Controller Board

Processors Intel® Xeon® Silver 4410Y Intel® Xeon® Gold 6421N

PAA/PAI Yes Yes

Hypervisor or Host OS

Version(s) A0-01-00-00 A0-01-00-00

Mode NameDescriptionTypeStatus Indicator
ApprovedAll services are available in this mode of operation.ApprovedA status code indicating the completion of service
AlgorithmCAVP CertPropertiesReference
AES-ECBA5023Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5025Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5026Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5027Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5028Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5029Direction - Decrypt, Encrypt Key Length - 256SP 800-38A

Table 3: Tested Module Identification – Hybrid Disjoint Hardware Tested Operational Environments - Software, Firmware, Hybrid: Table 4: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module.

2.3 Excluded Components

The module has no excluded components. Modes List and Description: Table 5: Modes List and Description The module implements only the approved mode of operation. No special API calls or settings

2.5 Algorithms

Approved Algorithms: © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 8
AlgorithmCAVP CertPropertiesReference
AES-ECBA5030Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5031Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5032Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5033Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5034Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5035Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5036Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5037Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5038Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5039Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5040Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5041Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5042Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5043Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-ECBA5044Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
AES-KWA5023Direction - Decrypt, Encrypt Key Length - 256SP 800-38F
AES-XTS Testing Revision 2.0A5046Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
AES-XTS Testing Revision 2.0A5047Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
AES-XTS Testing Revision 2.0A5048Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
AES-XTS Testing Revision 2.0A5049Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
AES-XTS Testing Revision 2.0A5050Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
AES-XTS Testing Revision 2.0A5051Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
AES-XTS Testing Revision 2.0A5052Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
AES-XTS Testing Revision 2.0A5053Direction - Decrypt, Encrypt Key Length - 256SP 800-38E
SHA2-256A5024Message Length - Message Length: 8-65536 Increment 8FIPS 180-4

Table 6: Approved Algorithms Vendor-Affirmed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms: © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 9

Name Secure Hash AES-ECB Core AES-KW Core AES-ECB Core 4 AES-ECB Core 16 AES-XTS Core 512 AES-XTS Core 520

Type SHA BC-UnAuth KTS-Wrap BC-UnAuth BC-UnAuth BC-UnAuth BC-UnAuth

Description Used to generate hash value from inputted data. Used to encrypt/decrypt inputted data. The underlying block cipher of AES-KW. Used to wrap/unwrap an inputted key. Used to encrypt/decrypt inputted data. The underlying block cipher of AES-XTS. Used to encrypt/decrypt inputted data. The underlying block cipher of AES-XTS. Used to encrypt/decrypt inputted data in units of 512 byte. Used to encrypt/decrypt inputted data in units of 520 byte.

Properties

Algorithms SHA2-256: (A5024) AES-ECB: (A5023) AES-KW: (A5023) AES-ECB: (A5023) AES-ECB: (A5025, A5026, A5027, A5028) AES-ECB: (A5029, A5030, A5031, A5032, A5033, A5034, A5035, A5036, A5037, A5038, A5039, A5040, A5041, A5042, A5043, A5044) AES-XTS Testing Revision 2.0: (A5046, A5047, A5048, A5049) AES-ECB: (A5025, A5026, A5027, A5028, A5029, A5030, A5031, A5032, A5033, A5034, A5035, A5036, A5037, A5038, A5039, A5040, A5041, A5042, A5043, A5044) AES-XTS Testing Revision 2.0: (A5050, A5051, A5052, A5053) AES-ECB: (A5025, A5026, A5027, A5028, A5029,

N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 10

Name

Type

Description

Properties

Algorithms A5030, A5031, A5032, A5033, A5034, A5035, A5036, A5037, A5038, A5039, A5040, A5041, A5042, A5043, A5044)

Physical PortLogical Interface(s)Data That Passes
N/AData InputData to be read from the memory area specified in the API parameters
N/AData OutputData to be written to the memory area specified in the API parameters
N/AControl InputAPI function calls
N/AStatus OutputResponses of the invoked API function

Table 7: Security Function Implementations

2.7 Algorithm Specific Information

The module has a function that checks if two keys for AES XTS mode are different from each other.

2.8 RBG and Entropy

N/A for this module. N/A for this module.

2.9 Key Generation
2.10 Key Establishment
2.11 Industry Protocols
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 8: Ports and Interfaces The module utilizes APIs as its interfaces and has no physical ports. Additionally, the module does not implement any control output interfaces. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 11
NameTypeOperator TypeAuthentication Methods
Cryptographic OfficerRoleCONone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Expand AES KeyExpand AES key to round keys.API return value: 0 (Success)DEKRound KeyAES-ECB Core 4 AES-ECB Core 16 AES-XTS Core 512 AES-XTS Core 520Cryptographic Officer - DEK: W,E - Round Key: G,R
Encrypt (512B)Encrypt data using XTS-AES in units of 512 byte.API return value: 0 (Success)Data to encrypt, Round KeyEncrypted dataAES-XTS Core 512Cryptographic Officer - Round Key: W,E
Decrypt (512B)Decrypt data using XTS-AES in units of 512 byte.API return value: 0 (Success)Data to decrypt, Round KeyDecrypted dataAES-XTS Core 512Cryptographic Officer - Round Key: W,E
Encrypt (520B)Encrypt data using XTS-AES in units of 520 byte.API return value: 0 (Success)Data to encrypt, Round KeyEncrypted dataAES-XTS Core 520Cryptographic Officer - Round Key: W,E
Decrypt (520B)Decrypt data using XTS-AES in units of 520 byte.API return value: 0 (Success)Data to decrypt, Round KeyDecrypted dataAES-XTS Core 520Cryptographic Officer - Round Key: W,E
Encrypt (ECB 16B)Encrypt 16 byte data using AES-ECB.API return value: 0 (Success)Data to encrypt, KEKEncrypted dataAES-ECB CoreCryptographic Officer - KEK: W,E
Decrypt (ECB 16B)Decrypt 16 byte data using AES-ECB.API return value: 0 (Success)Data to decrypt, KEKDecrypted dataAES-ECB CoreCryptographic Officer - KEK: W,E
Encrypt (ECB 64B)Encrypt 64 byte data using AES-ECB.API return value: 0 (Success)Data to encrypt, DEKEncrypted dataAES-ECB Core 4Cryptographic Officer - DEK: W,E
Decrypt (ECB 64B)Decrypt 64 byte data using AES-ECB.API return value: 0 (Success)Data to decrypt, DEKDecrypted dataAES-ECB Core 4Cryptographic Officer - DEK: W,E
4 Roles, Services, and Authentication

N/A for this module. The module does not support authentication for roles.

4.2 Roles

Table 9: Roles Cryptographic Officer role is implicitly and always assumed.

4.3 Approved Services

W,E W,E W,E W,E © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 12
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Encrypt (ECB 256B)Encrypt 256 byte data using AES-ECB.API return value: 0 (Success)Data to encrypt, DEKEncrypted dataAES-ECB Core 16Cryptographic Officer - DEK: W,E
Decrypt (ECB 256B)Decrypt 256 byte data using AES-ECB.API return value: 0 (Success)Data to decrypt, DEKDecrypted dataAES-ECB Core 16Cryptographic Officer - DEK: W,E
Wrap KeyWrap a key using a KEK.API return value: 0 (Success)Key, KEKWrapped keyAES-KW CoreCryptographic Officer - KEK: W,E
Unwrap KeyUnwrap a key using a KEK.API return value: 0 (Success)Wrapped key, KEKUnwrapped keyAES-KW CoreCryptographic Officer - KEK: W,E
Generate HashGenerate hash value from inputted data.API return value: 0 (Success)Data to hashHash ValueSecure HashCryptographic Officer
InitializeStartup the module.NoneNoneNoneNoneCryptographic Officer
Show StatusShow module ID, version, and status.NoneNoneModule ID, module version, module statusNoneCryptographic Officer
Enable CSP OutputEnable CSPs output in plaintext.NoneNoneNoneNoneCryptographic Officer
Disable CSP OutputDisable CSPs output in plaintext.NoneNoneNoneNoneCryptographic Officer
Forcibly StopChange the module state to Error state.NoneNoneNoneNoneCryptographic Officer
ResetReset the module.NoneNoneNoneNoneCryptographic Officer
ZeroiseCycle the power of the operational environment.NoneNoneNoneNoneCryptographic Officer - DEK: Z - Round Key: Z - KEK: Z
On- demand integrity testInitiate the integrity test on demand by power cycle of the operational environment.NoneNoneNoneNoneCryptographic Officer
On demand self testInitiate the self-tests on demand by power cycle of the operational environment or performing the Reset service, and performing the Initialize service.NoneNoneNoneNoneCryptographic Officer

Z Table 10: Approved Services The module provides only approved services. Accordingly, API return codes that confirm the successful completion of these services serve as the indicators. All approved services implemented by the module are listed in above. Each service description also describes all usage of SSPs by the service. The access rights to keys and/or SSPs modes shown in the table are defined as: © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 13
4.4 Non-Approved Services
4.5 External Software/Firmware Loaded

External firmware can be loaded through a complete image replacement of SVOS10. The new firmware image is executed after the module transitions through a power-on reset. All SSPs are zeroised prior to execution of the new image. A complete image replacement constitutes an entirely new module. Administrators of the module can obtain ID and version of the module as described in Chapter 11.2 to verify that the new module is validated version of the module.

5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of CRYPTLOAD (the firmware component of the module) is tested by comparing a SHA2-256 digest value calculated at startup with the SHA2-256 digest value stored in the module that was calculated at compile.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests. Thus, the integrity test can be initiated on demand by power cycle of the operational environment of the module.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited How Requirements are Satisfied: The module does not store SSPs in persistent storage. SSPs are temporarily stored in process memory when the module is being used. The module has control over its own SSPs. The © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 14
Storage Area NameDescriptionPersistence Type
MemoryA volatile memory on the operational environmentDynamic

Name API Input API Output

From Memory area specified in the API parameters Memory area for the module

To Memory area for the module Memory area specified in the API parameters

Format Type Plaintext Plaintext

Distribution Type Manual Manual

Entry Type Electronic Electronic

SFI or Algorithm

Zeroization MethodDescriptionRationaleOperator Initiation
Power cyclePower cycle of the operational environmentAll SSPs of the module are zeroised by Power cycle because all SSPs are on a volatile memory.Yes

operational environment is a single-process system and provides the time separation of the process memory. When the process memory is used by the module, no other process or component can concurrently access the memory. There are no security rules settings or restriction to the configuration of the operational

7 Physical Security
7.1 Mechanisms and Actions Required

The module is a multi-chip embedded cryptographic module and conforms to Level 1 requirements for physical security. The cryptographic module consists of production-grade components.

8 Non-Invasive Security

N/A. The module does not implement non-invasive security techniques.

9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 11: Storage Areas The module does not store SSPs in persistent storage. SSPs are temporarily stored in process memory when the module is being used.

9.2 SSP Input-Output Methods

Table 12: SSP Input-Output Methods

9.3 SSP Zeroization Methods

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 15

Name KEK DEK Round Key

Description Key encryption key Data encryption key AES round key

Size - Strength 256 bits - 256 bits 256 bits - 256 bits 1920 bits - 256 bits

Type - Category Symmetric Key - CSP Symmetric Key - CSP Round Key - CSP

Generated By

Established By

Used By AES-ECB Core AES-KW Core AES-ECB Core 4 AES-ECB Core 16 AES-XTS Core 512 AES-XTS Core 520 AES-ECB Core 4 AES-ECB Core 16 AES-XTS Core 512 AES-XTS Core 520

Name KEK DEKInput - Output API Input API InputStorage Memory:Plaintext Memory:PlaintextStorage Duration While the module is executing Encrypt (ECB 16B), Decrypt (ECB 16B), Wrap Key or Unwrap Key. While the module is executing Expand AES Key, Encrypt (ECB 64B), Decrypt (ECB 64B), Encrypt (ECB 256B) or Decrypt (ECB 256B).Zeroization Power cycle Power cycleRelated SSPs
Round KeyAPI Input API OutputMemory:PlaintextWhile the module is executing Expand AES Key, Encrypt (512B), Decrypt (512B), Encrypt (520B), Decrypt (520B).Power cycleDEK:Derived From
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
SHA2-256 (A5024)SHA2-256KATSW/FW IntegrityNoneHash

Table 13: SSP Zeroization Methods Administrators of the module can zeroise all SSPs of the module by power cycle of Hitachi storage system. Power cycle can be done in Maintenance Utility, which is Management tool of Hitachi storage system. In details, see System Administrator Guide. Table 14: SSP Table 1 Table 15: SSP Table 2

10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 16: Pre-Operational Self-Tests © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 16
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-XTS (512B)Key sizes: 256 bitsKATCASTNoneEncryptFrom the module startup to integrity testing
AES-XTS (512B)Key sizes: 256 bitsKATCASTNoneDecryptFrom the module startup to integrity testing
AES-XTS (520B)Key sizes: 256 bitsKATCASTNoneEncryptFrom the module startup to integrity testing
AES-XTS (520B)Key sizes: 256 bitsKATCASTNoneDecryptFrom the module startup to integrity testing
AES-KW (A5023)Key sizes: 256 bitsKATCASTNoneWrapFrom the module startup to integrity testing
AES-KW (A5023)Key sizes: 256 bitsKATCASTNoneUnwrapFrom the module startup to integrity testing
SHA2-256 (A5024)SHA2-256KATCASTNoneHashFrom the module startup to integrity testing
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-256 (A5024)KATSW/FW IntegrityOn DemandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-XTS (512B)KATCASTOn DemandManually
AES-XTS (512B)KATCASTOn DemandManually
AES-XTS (520B)KATCASTOn DemandManually
AES-XTS (520B)KATCASTOn DemandManually
AES-KW (A5023)KATCASTOn DemandManually
AES-KW (A5023)KATCASTOn DemandManually
SHA2-256 (A5024)KATCASTOn DemandManually

Once the “Initialize” service is called and all Cryptographic Algorithm Self-tests (CAST) are completed, the module automatically performs firmware integrity test using SHA2-256 over the CRYPTLOAD. If the firmware integrity test fails, the module enters the error state.

10.2 Conditional Self-Tests

Table 17: Conditional Self-Tests When the “Initialize” service is called, the module starts to perform cryptographic algorithm selftests for XTS-AES mode, AES Key Wrap, AES Key Unwrap and SHA2-256. If one of the selftests fails, the module enters the error state.

10.3 Periodic Self-Test Information

Table 18: Pre-Operational Periodic Information Table 19: Conditional Periodic Information Pre-operational self-tests, and cryptographic algorithm self-tests for XTS-AES mode, AES Key and b); a) Cycle power of the operational environment or execute “Reset” service. b) Execute “Initialize” service.

10.4 Error States

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 17
NameDescriptionConditionsRecovery MethodIndicator
ErrorA state when the module has encountered an error condition.Failed the Pre- operational self-tests. Failed the Cryptographic algorithm self-tests.Power cycling of the operational environment.Error response to Show Status service.
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is integrated into SVOS10. When SVOS10 is installed by the vendor of Hitachi storage system, the module is also installed. To initialize the module, enable the encryption feature of Hitachi storage system (See Encryption License Key Users Guide Chapter 3). No other special procedure is required to securely install and initialize the module.

11.2 Administrator Guidance

Administrators can verify that an ID and a version of the module is identical to the ID (Storage_Encryption_Module_20) and the version (A0-01-00-00). See REST API Reference guide Chapter 17.5 to show an ID and a version of the module. Administrators can identify the processor by checking the model of storage system. In the case where the model is VSP One B28, the processor is Intel® Xeon® Gold 6421N. For the models VSP One B23, VSP One B24 or VSP One B26, the processor is Intel® Xeon® Silver 4410Y. See REST API Reference guide to show the model of storage system. All the functions, physical ports, and logical interfaces of the module are available to the Crypto Officer. The module provides only an approved mode of operation. Therefore, no special API calls or settings are required to place the module in an approved mode of operation.

11.3 Non-Administrator Guidance

There are no requirements for non-administrator.

11.4 Design and Rules

The module design corresponds to the module security rules. This subsection documents the security rules enforced by the module to implement the security requirements of this FIPS 140-3 Level 1 module.

  1. The module shall provide a Cryptographic Officer role.
  2. The operator shall be capable of commanding the module to perform the pre-operational self3. Pre-operational self-tests do not require any operator action.
  3. Data output shall be inhibited during self-tests, zeroization, and error states.
  4. Status information does not contain CSPs or sensitive data that if misused could lead to a © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
Page 18
  1. The module does not support degraded operation.
  2. The module does not support concurrent operators.
  3. The module does not support a maintenance interface or role.
  4. The module does not support manual key entry.
  5. The module does not have any external input/output devices used for entry/output of data.
  6. Two independent internal actions shall be required in order to output any plaintext CSP.
12 Mitigation of Other Attacks

N/A. The module does not provide mitigation of other attacks. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).