All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Samsung TCG Opal SSC Cryptographic Sub-Chip Deneb

Certificate#5047StandardFIPS 140-3Level2TypeHardwareEmbodimentSingle ChipStatusActiveVendorSamsung Electronics Co., Ltd.
Medium review priority  ·  exposes boot-chain verification, HSM/SE firmware trust anchor  ·  last validated 12 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date7/24/2030
CaveatWhen operated in approved mode
VendorSamsung Electronics Co., Ltd.

Approved Algorithms (10)

AlgorithmACVP Cert
AES-ECBA4352
AES-GCMA4353
Counter DRBGA4352
ECDSA KeyGen (FIPS186-4)A4351
ECDSA SigVer (FIPS186-4)A4351
HMAC-SHA2-256A4351
KAS-ECC-SSC Sp800-56Ar3A4351
KDF SP800-108A4351
SHA2-256A4351
SHA2-384A4351

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Samsung TCG Opal SSC Cryptographic Sub-Chip Deneb
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>Show status<br/>self-test</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>bootloader<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Samsung TCG Opal SSC Cryptographic Sub-Chip Deneb
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>Show status<br/>self-test</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>bootloader<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Samsung TCG Opal SSC Cryptographic Sub-Chip Deneb Document Date: July 18, 2025 Document Version: 1.0

Page 2
VersionChange
1.0Initial Version
Page 3
Table of Contents
#SectionPage
Page 4
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
AcronymDescription
CPKCredential Protection Key
DRBGDeterministic Random Bit Generator
ECDHElliptic Curve Diffie-Hellman
ECDH CKCommon Key, shared secret for key agreement
ECDH PKPublic key for key agreement
ECDH SKSecret key for key agreement
GRKGrant Key derived from shared secret
HMIHardware Module Interface the Mailbox and DMA are physical ports of the sub-chip
KAS-ECC-SSCKey Agreement Scheme (Shared Secret Computation)
KATKnown Answer Test
KEKKey Encryption Key
KPKKey Protection Key
LBALogical Block Address
MEKMedia Encryption Key
NANDNAND Flash Memory
NVMeNon-Volatile Memory Host Controller Interface Specification
SEDSelf-Encrypting Drive
SSCSecurity Subsystem Class
SSPSensitive Security Parameter
TCGTrusted Computing Group
  1. Introduction 1.1. Scope This document describes the security policy for Samsung TCG Opal SSC Cryptographic Sub-Chip Deneb, herein after referred to as a “cryptographic module” or “module” in compliance with IG 2.3.B, satisfies all applicable FIPS 140-3 Security Level 2 requirements. This module is dedicated to be embedded Samsung SED to support cryptographic algorithms and robust key management design. The module is integrated in a SoC and used as FIPS 140-3 validated Sub-Chip subsystem module to provide approved security functions subject to various SSD products’ configuration. Table
  2. Security Levels 1.2. Acronyms Table
  3. Acronyms
Page 5
  1. Cryptographic module specification 2.1. Cryptographic boundary The following photographs show explicitly defined perimeter of the cryptographic module’s physical boundary. A single IC chip package serves as the single-chip physical boundary of the module. Set of hard circuitry cores of Sub-Chip cryptographic subsystem are contained in this physical boundary. Figure
  2. External view of the Samsung TCG Opal SSC Cryptographic Sub-Chip The Sub-Chip cryptographic subsystem boundary (i.e. HMI) is essentially composed of dedicated isolated security processor and cryptographic hardware subsystems. The associated firmware that loaded into the HMI provides the required approved mode of operation. • Module type: Hardware • Module embodiment: Single Chip • Module Characteristics: The sub-chip is contained within the Samsung S4LY011A01 SoC implemented within a TCG Opal SED. Figure
  3. HMI of the Samsung TCG Opal SSC Cryptographic Sub-Chip
Page 6
Tested ConfigurationHardware VersionFirmware Version
S4LY011A011S02SS0200
CAVP CertAlgorithm and StandardMode/ MethodDescription/ Key Size(s)/ Key Strength(s)Use/Function
A4353AES / FIPS 197, SP 800- 38DGCM256 bitsKey Encryption / Decryption
A4353KTSAES-GCM256 bitsKey Transport as per SP 800-38F
A4352DRBG / SP 800-90Arev1CTR_ DRBG (AES-256)N/AAll Cryptographic Key Generation
A4351SHS / FIPS 180-4SHA-256N/AMessage Digest
SHS / FIPS 180-4SHA-384N/AMessage Digest
KBKDF / SP 800- 108rev1HMAC-SHA-256256 bitsKey Derivation
HMAC / FIPS 198-1SHA-256256 bitsMessage Authentication
ECDSA / FIPS 186-4Curve P-384 with SHA- 384P-384 / 192 bitsKey Generation and Digital Signature Verification
KAS-ECC-SSC / SP 800- 56Ar3staticUnifiedP-384 / 192 bits2Shared secret computation
KDA / SP 800-56C Rev2OnestepNoCounterKdf with SHA2-256256 bitsKey Derivation for GRK from ECDH CK
Vendor AffirmedCKG / SP 800-133r2Section 5.2 and 6.1N/AAs per SP 800-133rev2 Section 5.2 and 6.1, key generation is performed for "Key Pairs for Key Establishment" and "Direct Generation: of Symmetric Keys" which are Approved key generation methods. The list of CSPs generated by the module: KDK_CPK, KDK_KPK, MEK, KEK, ECDH SK, Root Key
E83ENT (P) / SP800-90BN/AN/AENT (P) provides a minimum of 256 bits of entropy for approved DRBG seed construction in key generation.

2.2. Version information 2.3. Cryptographic functionality The cryptographic module supports the following Approved algorithms for secure data storage: Table 4. Approved Algorithms NOTE: There are algorithms, modes, and keys that have been CAVP tested but not used by the module. Only the algorithms, modes/methods, and key lengths/curves/moduli shown in this table are used by the module.

1 The “S4LY011A01” version number is NOT the cryptographic boundary of the module, it references the SoC on which it operates on.

Page 7
#NameTypeDescriptionSF PropertiesAlgorithms
1Key TransportKTSSP 800-38D and SP 800-38F. KTS (key wrapping and unwrapping) per IG D.G.256-bit keys providing 256 bits of encryption strengthAES GCM Cert. #A4353
2Key AgreementKASSP 800-56Arev3. KASECC per IG D.F Scenario 2 path (2).Key establishment methodology provides 192 bits of encryption strengthKAS-ECC-SSC / SP 800- 56Ar3 Cert. #A4351 KDA / SP 800-56C Rev2 Cert. #A4351 Cert. SHS / FIPS 180-4 #A4351
AlgorithmUse / Function
AES-XTS / FIPS 197, SP 800-38EEncryption for Dump data
RSA / SP 800-56BEncryption for dump encryption Key
HKDF/ SP 800-56C Rev2Key Derivation
AlgorithmCaveatUse / Function
AES-XTS / FIPS 197, SP 800-38ENo Security Claimed; AES-XTS is only used for proprietary firmware decryption during ROM initialization; as per FIPS 140-3 IG 2.4.A this cryptographic operation is applied for good measure.Firmware Decryption

Table

  1. Security Function Implementations 2.3.2. Non-Approved Algorithm Table
  2. Non-Approved Algorithms Not Allowed in the Approved Mode of Operation Following algorithm is not intended to be used as a security function in this module, and not used whatsoever to meet any FIPS 140-3 requirements. The algorithm below is not provided through executable approved service to an operator. Table
  3. Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed
Page 8

2.4. Approved mode of operation The cryptographic module supports an approved and non-approved mode of operation. The module defaults to the approved mode of operation as long as the guidance outlined in Section 11 is followed, and operator can verify that the module enters the default approved mode by confirming that the version is consistent with the version information described in this Security Policy. The module will transition between the approved and non-approved modes depending on the services requested by the operator. The operator can check whether the module is in the approved mode or the nonapproved mode via status response from each service. The module zeroises SSPs when completing a service as described in Table 10, however it is recommended for the Crypto Officer (CO) via procedural guidance set forth in this Security Policy to also perform a power reset to zeroise all SSPs of the module when switching between modes of operation.

Page 9
Physical portLogical interface TypeData that passes over port/interface
MailboxData InputSignature Data
DMAFirmware Data Signature Data Key Data
DMAData OutputPlaintext data that has been decrypted by the cryptographic module
MailboxControl InputCommands input logically via an API;
Status OutputStatus information
Power planesPower InputPower input

Table 8. Ports and Interfaces

Page 10
RoleAuthorityServiceInputOutput
Crypto Officer (CO)SysIDCreateNamespaceAuthority Index, Password, Authority ListStatus
DeleteNamespaceAuthority Index, Password, Authority ListStatus
WriteProtectionAuthority Index, Password, Authority ListStatus
SanitizeAuthority Index, PasswordStatus
CryptoEraseAuthority Index, PasswordStatus
FormatNVMAuthority Index, PasswordStatus
RevertWithPSIDAuthority Index, PasswordStatus
TPER ResetAuthority Index, PasswordStatus
Revoke Root Encryption KeyAuthority Index, PasswordStatus
AdminSP.SID AdminSP.Admin1 LockingSP.Admin1~4RevertAuthority Index, PasswordStatus
ActivateAuthority Index, PasswordStatus
ReactivateAuthority Index, PasswordStatus
AssignAuthority Index, Password, Authority ListStatus
DeassignAuthority Index, Password, Authority ListStatus
Set CPINAuthority Index, PasswordStatus
GenKeyAuthority Index, PasswordStatus
EraseAuthority Index, PasswordStatus
GrantAuthority Index, Password, Authority ListStatus
SetRangeAuthority Index, Password, Authority ListStatus
UserLockingSP.User1~33ReactivateAuthority Index, PasswordStatus
AssignAuthority Index, Password, Authority ListStatus
DeassignAuthority Index, Password, Authority ListStatus
Set CPINAuthority Index, PasswordStatus
GenKeyAuthority Index, PasswordStatus
EraseAuthority Index, PasswordStatus
GrantAuthority Index, Password, Authority ListStatus
SetRangeAuthority Index, Password, Authority ListStatus
Firmware Loader (FL)BootloaderVerifyFWSignature Data, Firmware DataStatus
  1. Roles, services, and authentication The following table defines the roles, authority, associated services, and inputs/outputs supported by the cryptographic module: Table
  2. Roles, Service Commands, Input and Output
Page 11
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPs3Indicator
EWGZ
Show StatusShow status of the module and show module’s versioning information---Return value MESSAGE_RESPONSE. bApprovedMode: 1 // 1: Approved Mode, 0: Non-Approved Mode
Perform self-testsPerform all pre- operational and conditional self-tests by power-cycling the module---
Get Random NumberProvide a random number generated by the CMCTR_ DRBG (AES-256)DRBG Internal State, DRBG Seed-OOO
Authentication4Load the KPK for authority and decrypt related encryption keysCTR_DRBG, AES- GCM, KAS-ECC- SSC, KBKDF, SHA, HMACDRBG Internal State, DRBG Seed-OOO
Unauthentication 5Zeroise the KPK for authority and zeroise related encryption keys-KPK-O
Hash OperationHash operationSHA--
VerifyFWVerify firmware signatureECDSAFW Verification KeyFLO
RevertWithPSIDNVMe Command, Erase user data in all Range by changing the dataCTR_DRBG, AES- GCM, KBKDF, SHA, HMACPINCOOO
DRBG Internal State, DRBG SeedOOO
KEK, KPK, MEK, CPK, KDK_CPK, KDK_KPKOOOO
ECDH SK, ECDH PKOOO
REK, SMK, KMKO
TPER ResetAbort all TCG Communications and Reset TCG protocolKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, HMACKPK, KEK,OOO
Table, extracted as text (did not parse into structured rows)
4.2.1. Approved Services The following table shows all approved services which is implemented by the cryptographic module. E: EXECUTE; W: WRITE; G: GENERATE; Z: ZEROISE E     W      G    Z O            O    O O     O    O O

3 It means that “Write” and “Zeroise” perform in each storage of SSPs that is described in table10.

4 This does not mean to use to comply with Section 7.4.4 of ISO/IEC 19790, but is a service used to support the part of TCG authenticate

5 This does not mean to use to comply with Section 7.4.4 of ISO/IEC 19790, but is a service used to support the part of TCG deauthenticate

Page 12
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPs3Indicator
MEKEWGZ
REK, SMK, KMKO
CreateNamespaceAllocate key to the specified NamespaceKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, KAS- ECC-SSC, CTR_DRBG, SHA, HMACKEK, KPKOOO
DRBG Internal State, DRBG SeedOOO
ECDH CK, ECDH PK, ECDH SKOOOO
REK, SMK, KMKO
DeleteNamespaceDelete key for the specified NamespaceKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, CTR_DRBG, HMACKEK, KPKOOO
DRBG Internal State, DRBG SeedOOO
MEKOOOO
REK, SMK, KMKO
WriteProtectionRemove key from TCG boundary on the specified NamespaceKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, HMACKPK, KEKOOO
REK, SMK, KMKO
SanitizeCryptographically erase user data (Delete key)KBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, CTR_DRBG, HMACKEK, KPKOOO
DRBG Internal State, DRBG SeedOOO
MEKOOOO
REK, SMK, KMKO
CryptoEraseCryptographically erase user data (Delete key)KBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, CTR_DRBG, HMACKEK, KPKOOO
DRBG Internal State, DRBGOOO
Page 13
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPs3Indicator
SeedEWGZ
MEKOOOO
REK, SMK, KMKO
FormatNVMDelete the Key corresponding to the specified NamespaceKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, CTR_DRBG, HMACKEK, KPKOOO
DRBG Internal State, DRBG SeedOOO
MEKOOOO
REK, SMK, KMKO
ActivateReady to TCG Locking operationKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
CTR_DRBG, AES- GCM, KAS-ECC- SSC, KBKDF, SHA, HMACPIN, KEKOOO
DRBG Internal State, DRBG SeedOOO
KPK, MEK, CPK, KDK_KPKOOOO
ECDH SK, ECDH PKOOO
REK, SMK, KMKO
RevertReset CPINs of all authorities and range informationKBKDFKDK_CPK, KDK_KPKOOO
CPKOOO
PINOO
CTR_DRBG, AES- GCM, KBKDF, SHA, HMACDRBG Internal State, DRBG SeedOOO
KEK, KPK, MEK, CPK, KDK_KPKOOOO
ECDH SK, ECDH PKOOO
REK, SMK, KMKO
Revoke Root Encryption KeyRevoke and zeroise REKKBKDFPINCOOO
KDK_CPK, KDK_KPKOOO
CPKOOO
CTR_DRBG, KBKDFREK, SMK, KMKOOO
DRBG Internal State, DRBGOOO
Page 14
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPs3Indicator
SeedEWGZ
Root KeyOO
ReactivateRevert and ActivateKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
CTR_DRBG, AES- GCM, KAS-ECC- SSC, KBKDF, SHA, HMACKEKCO, USEROOO
DRBG Internal State, DRBG SeedOOO
KPK, MEK, CPK, KDK_KPKOOOO
ECDH SK, ECDH PKOOO
REK, SMK, KMKO
Set CPINSet TCG authority’s passwordKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
CTR_DRBG, AES- GCM, KAS-ECC- SSC, KBKDF, SHA, HMACKEKOOO
DRBG Internal State, DRBG SeedOOO
KPK, MEK, CPK, KDK_KPKOOOO
ECDH SK, ECDH PKOOO
REK, SMK, KMKO
AssignAssign locking object to the specified NamespaceKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, CTR_DRBG, KAS- ECC-SSC, SHA, HMACKEK, KPKOOO
DRBG Internal State, DRBG SeedOOO
MEK, ECDH CK, ECDH PK, ECDH SKOOOO
REK, SMK, KMKO
DeassignDeassign locking object to the specified NamespaceKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, CTR_DRBG, KAS- ECC-SSC, SHA, HMACKEK, KPKOOO
DRBG Internal State, DRBGOOO
Page 15
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPs3Indicator
SeedEWGZ
MEK, ECDH CK, ECDH PK, ECDH SKOOOO
REK, SMK, KMKO
GrantGrant Key to the specified AuthorityKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, KAS- ECC-SSC, CTR_DRBG, SHA, HMAC, KDAKEK, KPKOOO
DRBG Internal State, DRBG SeedOOO
ECDH CK, ECDH PK, ECDH SK, GRKOOOO
REK, SMK, KMKO
GenKeyGenerate key materialsKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, CTR_DRBG, HMACKEK, KPKOOO
DRBG Internal State, DRBG SeedOOO
MEKOOOO
REK, SMK, KMKO
EraseCryptographically erase user data within a specific LBA RangeKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
CTR_DRBG, AES- GCM. KAS-ECC- SSC, KBKDF, SHA, HMACPINOO
DRBG Internal State, DRBG SeedOOO
KEK, KPKOOO
MEK, CPK, KDK_KPK, ECDH PK, ECDH SKOOOO
REK, SMK, KMKO
SetRangeLock or Unlock the specified RangeKBKDFPINOO
KDK_CPK, KDK_KPKOOO
CPKOOO
AES-GCM, HMACKPK, KEK, MEKOOO
REK, SMK,O
Page 16
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPs3Indicator
KMKEWGZ
ServiceDescriptionAlgorithms AccessedRoleIndicator
GetDumpKeyReturn Dump KeyCTR_ DRBG (AES-256)N/AReturn value MESSAGE_RESPONSE.bAppr ovedMode: 0 // 1: Approved Mode, 0: Non- Approved Mode
DumpEncryptionEncrypt Dump DataRSA (Non-approved algorithm)
FWDecryptionDecrypt encrypted Firmware binaryAES-XTS (Non-approved algorithm)
FWVerifyNDecryptionVerify and Decrypt encrypted Firmware binaryAES-XTS (Non-approved algorithm)
GetCSROutput the public key and signature for certificationSHA ECDSA Sig Gen
VerifyCertVerity the chain of certificationSHA AES-GCM
KeyExchangeECDH agreementSHA CTR_ DRBG (AES-256) ECDSA SigGen, KeyGen ECDH HKDF(HMAC) (Non-approved algorithm)
GetDigestOutput the hashed certification chainSHA
ChallengeGenerate the signature with transcriptSHA CTR_ DRBG (AES-256) ECDSA SigGen
FinishOutput the signature, mac and enc for checking the common secretSHA HMAC
GetMeasurementsOutput the hashed and signed with firmware and configurationCTR_ DRBG (AES-256) ECDSA SigGen
KeyUpdateUpdate the common secretHKDF(HMAC) (Non-approved algorithm)
RoleAuthentication MethodAuthentication Strength
COPassword (Min: 8 bytes, Max: 44 bytes)Probability of 1/264 in a single random attempt. Probability of 80/264 in a multiple random attempts in a one-minute.
UserPassword (Min: 8 bytes, Max: 44 bytes)Probability of 1/264 in a single random attempt. Probability of 80/264 in a multiple random attempts in a one-minute.

E W G Z Table

  1. Approved Services The services in this non-Approved mode of operation are non-security relevant, and do not expose/utilize any critical security parameters. The operator can distinguish these via response value; ApprovedMode return
  2. N/A Table
  3. Non-Approved Services The module supports role-based authentication that requires authentication to assume for the authorization of each role.
Page 17

FL

ECDSA signature verification

Probability of 1/2192 in a single random attempt. Probability of 1250/2192 in multiple random attempts in a one-minute.

Table 12. Roles and Authentication Table 9 shows each authentication method and strength for a single and multiple attempts. The CO role requires password-based authentication, where each byte can be any of 0x00 to 0xFF. Each password authentication failure holds the cryptographic module for 750ms. This restricts the maximum attempts for a one-minute to less than 80 attempts (60,000ms/750ms). The User role requires password-based authentication, where each byte can be any of 0x00 to 0xFF. Each password authentication failure holds the cryptographic module for 750ms. This restricts the maximum attempts for a one-minute to less than 80 attempts (60,000ms/750ms). The FL role is limited to authenticate functions that verifies 2 steps of ECDSA P-384 with SHA-384 digital signature of firmware to complete a login. The firmware signed6 by Samsung is authenticated by verifying the ECDSA signature which has 192 security strength in every power-on. Each signature verification attempt takes at least 48ms. This can be enforced with up to

6 The signing key is securely stored in HSM which is under Samsung internal development management.

Page 18

5. Software/Firmware security - The module applies digital signature verification using ECDSA-384 with SHA-384 for firmware integrity test. - The firmware integrity test is performed every power on reset.

Page 19

6. Operational environment - The cryptographic module operates in limited operational environment that consists of the module’s firmware. This operational environment does not require any specific security rules, settings/configurations or restrictions to be set. - The cryptographic module does not provide any general-purpose operating system to the operator. - Firmware loading is allowed only for CMVP validated firmware versions. Unauthorized modification of the firmware is prevented by the pre-operational firmware integrity test and conditional firmware load test.

Page 20
Physical Security MechanismsRecommended Frequency of Inspection/TestInspection/Test Guidance Details
Opaque coveringAs often as feasibleInspect the entire perimeter whether gathering of internal components are visible. Stop the service if tampering is found.
Tamper evident IC packagingInspect the damage such as removing epoxy overfill, separation from the PCB of the silicon die, solder ball deterioration (diameter, pitch) No functioning normally if tampering is found. Stop the service.

The following physical security mechanisms are implemented in a cryptographic module itself:

Page 21

8. Non-invasive security - Non-invasive security is not applicable for this cryptographic module

Page 22
Key/SSP Name/ TypeSize / StrengthSecurity Function and Cert. NumberGeneration or EstablishmentImport /ExportStorage7Zeroisation8Use & related keys
DRBG Internal State9256 bits / 256 bitsA4352 CTR_DRBG (AES-256)SP 800- 90Arev1 CTR_DRBG (AES-256)N/AHW internal10RevertWithPSID TPER Reset CreateNamespace DeleteNamespace WriteProtection Sanitize CryptoErase FormatNVM Activate Revert Revoke Root Encryption Key Reactivate Set CPIN Assign Deassign Grant GenKey Erase SetRangeMEK, KEK, ECDH SK, KDK_CPK, KDK_KPK, Root Key
DRBG SeedEntropy input: 512 bits Nonce: 256 bits / 256 bitsA4352 CTR_DRBG (AES-256)ENT (P)N/A
PIN118-44 bytesA4351 SHA-256Electronic inputN/ASRAMRevertWithPSID TPER Reset CreateNamespace DeleteNamespace WriteProtection Sanitize CryptoErase FormatNVM Activate Revert Revoke Root Encryption Key Reactivate Set CPIN Assign Deassign Grant GenKeyCPK KPK
  1. Sensitive security parameter management - Temporary SSPs are zeroised when power on reset. - Firmware integrity temporary values are zeroised after the firmware integrity test is complete. - The zeroisation is performed before overwriting the target SSP with random value which is generated from the DRBG - The AES-GCM IV is generated by the module and complies with FIPS 140-3 IG C.H technique
  2. The IV is 96 bits in length, and its generated by the SP 800-90Arev1 DRBG internal to the module’s boundary.

7 Because there is no non-volatile storage in this module without OTP, basically, automatic zeroisation runs instantly either when temporary SSP

as well as SSPs are no longer needed after key generation/use, or every power-on-reset depending on characteristics of volatile memory.

8List only methods by running the approved service in 10 of the operator.
9The values of V and Key are the critical values of the internal state.
10Approved DRBG SSPs reside only inside the hardware DRBG IP and there is no way for operator to access and handle.
11The PIN is also known as a Password in the context of this document. The terms are interchangeable.
Page 23
Key/SSP Name/ TypeSize / StrengthSecurity Function and Cert. NumberGeneration or EstablishmentImport /ExportStorage7Zeroisation8 Erase SetRangeUse & related keys
CPK256 bits / 256 bitsA4351 KBKDFSP 800- 108rev1 KBKDFImport / Export (Encrypt ed)SRAMRevertWithPSID TPER Reset CreateNamespace DeleteNamespace WriteProtection Sanitize CryptoErase FormatNVM Activate Revert Revoke Root Encryption Key Reactivate Set CPIN Assign Deassign Grant GenKey Erase SetRangePassword
KDK_CPK256 bits / 256 bitsA4351 KBKDFSP 800- 90Arev1 CTR_DRBG (AES-256)Import / Export (Encrypt ed)SRAMCPK
KPK256 bits / 256 bitsA4353 AES-GCMSP 800- 108rev1 KBKDFN/ASRAMUnauthentication RevertWithPSID TPER Reset CreateNamespace DeleteNamespace WriteProtection Sanitize CryptoErase FormatNVM Activate Revert Reactivate Set CPIN Assign Deassign Grant GenKey Erase SetRangeKEK
KDK_KPK256 bits / 256 bitsA4351 KBKDFSP 800- 90Arev1 CTR_DRBG (AES-256)Import / Export (Encrypt ed)SRAMRevertWithPSID TPER Reset CreateNamespace DeleteNamespace WriteProtection Sanitize CryptoErase FormatNVM Activate Revert Revoke Root Encryption Key Reactivate Set CPIN AssignKPK
Page 24
Key/SSP Name/ TypeSize / StrengthSecurity Function and Cert. NumberGeneration or EstablishmentImport /ExportStorage7Zeroisation8 Deassign Grant GenKey Erase SetRangeUse & related keys
ECDH SKP-384 / 192-bitA4351 KAS- ECC-SSCSP 800- 90Arev1 CTR_DRBG (AES-256)Import / Export (Encrypt ed)SRAMRevertWithPSID CreateNamespace Activate Revert Reactivate Set CPIN Assign Deassign Grant EraseGRK
ECDH PKP-384 / 192-bitA4351 KAS- ECC-SSCSP 800-56Ar3 KAS-ECC-SSCImport / Export (Encrypt ed)SRAMGRK
ECDH CKP-384 / 192-bitA4351 KAS-ECC-SSCSP 800-56Ar3 KAS-ECC-SSCN/ASRAMCreateNamespace Assign Deassign GrantGRK
GRK256-bit / 256-bitA4353 AES-GCMSP 800-56Cr2 KDAN/ASRAMGrantECDH CK
KEK256 bits / 256 bitsA4353 AES-GCMSP 800- 90Arev1 CTR_DRBG (AES-256)Import / Export (Encrypt ed)SRAMRevertWithPSID TPER Reset CreateNamespace DeleteNamespace WriteProtection Sanitize CryptoErase FormatNVM Activate Revert Reactivate Set CPIN Assign Deassign Grant GenKey Erase SetRangeMEK
MEK12256 bits / 256 bitsN/ASP 800- 90Arev1 CTR_DRBG (AES-256)Import (Encrypt ed)/ Export (Plaintext 13 & Encrypte d)SRAMRevertWithPSID TPER Reset DeleteNamespace Sanitize CryptoErase FormatNVM Activate Revert ReactivateKEK

12 Please note this is a SSP generated by the module to be used by the consuming application (outside of the boundary)

13 FIPS 140-3 IG 2.3.B states Transferring SSPs between a sub-chip cryptographic subsystem and an intervening functional subsystem for

Security Level 2 on the same single chip is considered as not having Sensitive Security Parameter Establishment crossing the HMI of the sub-chip module per IG 9.5.A.

Page 25
Key/SSP Name/ TypeSize / StrengthSecurity Function and Cert. NumberGeneration or EstablishmentImport /ExportStorage7Zeroisation8 Set CPIN Assign Deassign GenKey Erase SetRangeUse & related keys
SMK256 bits / 256 bitsA4351 HMACSP 800- 108rev1 KBKDFN/ASRAMRevertWithPSID TPER Reset CreateNamespace DeleteNamespace WriteProtection Sanitize CryptoErase FormatNVM Activate Revert Revoke Root Encryption Key Reactivate Set CPIN Assign Deassign Grant GenKey Erase SetRangeRoot Key
KMK256 bits / 256 bitsA4351 HMACSP 800- 108rev1 KBKDFN/ASRAMRoot Key
REK256 bits / 256 bitsA4353 AES-GCMSP 800- 108rev1 KBKDFN/ASRAMRoot Key
Root Key256 bits / 256 bitsA4351 KBKDFSP 800- 90Arev1 CTR_DRBG (AES-256)N/AOTPRevoke Root Encryption KeyREK
Firmware Verificatio n Key14P-384 / 192-bitA4351 ECDSAManufacturingN/AROMPhysically protected PSP stored in the ROMN/A
Entropy sourcesMinimum number of bits of entropyDetails
Cert #E83 ENT (P)- 0.5 entropy per bit15 - Minimum of 256 bits of entropy for DRBG seed (Total seed length of 512 bits)Provides entropy input and nonce to construct a seed for CTR_DRBG

Table

  1. SSPs The cryptographic module contains an entropy source compliant with SP800-90B. Table
  2. Non-Deterministic Random Number Generation Specification

14 The Firmware Verification key is not an SSP per ISO/IEC 19790 Section 7.5.

15 Estimated amount of entropy per the source’s output bit is 0.767252 and Samsung conservatively claims to be set at 0.5 per bit.

Page 26
AlgorithmTypeDescriptionConditions
ECDSAFirmware integrity testCurve P-384 with SHA-384 signature verifications for firmware integrityModule initialization
Algorith mTypeDescriptionConditions
ECDSACryptographic algorithm self- testKAT: Curve P-384 with SHA-384 signature verificationModule initialization
AESCryptographic algorithm self- testKAT: AES-256 GCM mode encryption and decryptionModule initialization
HMACCryptographic algorithm self- testKAT: HMAC with SHA-256Module initialization
SHSCryptographic algorithm self- testKAT: SHA-256 hash digestModule initialization
SHSCryptographic algorithm self- testKAT: SHA-384 hash digestModule initialization
KBKDFCryptographic algorithm self- testKAT: Key based key derivation using HMAC with SHA-256Module initialization
KAS-ECC- SSCCryptographic algorithm self- testKAT: ECDH P-384 Shared secret computationModule initialization
KDACryptographic algorithm self- testKAT: OneStepNoCounter KDF with SHA2- 256Module initialization
KAS-ECC- SSCPair-wise consistency testThe module executes a PCT every time a key is generated. Module computes dG and compares to public key Q.Key generation
  1. Self-tests While executing the following self-tests, all data output is inhibited until the self-test is completed. To execute the preoperational tests on-demand, the operator may run the power-cycle of the module. If the self-test fails, the module enters an error state. The module has two error states. The "Rom Mode" error state is entered when the module fails the pre-operational self-test (Firmware integrity test) or the conditional self-test (Firmware load test). The error indicator output by the module is "eSROMReturn_VerifyFail". The "FIPS Fail Mode" error state is entered when the module fails any other conditional self-test (Cryptographic algorithm self-test or Pair-wise consistency test). The error indicator output is "0x4C494146". All data output is inhibited during the self-test and error states. 10.1. Pre-operational test Table
  2. List of pre-operational self-tests 10.2. Conditional test m
Page 27
ECDSAFirmware load testECDSA signature verification is performed if new FW is downloaded or at every power-on-resetFirmware load test
DRBGCryptographic algorithm self- testKATs: SP 800-90Arev1 Health testing on Instantiate, Generate and Reseed functionsModule initialization
ENT (P)Cryptographic algorithm self- testStart up and Conditional SP800-90B Heath tests: Repetition count test, Adaptive proportion testModule initialization and Continuously

Table 17. List of Conditional self-tests

Page 28

11. Life-cycle assurance The followings describe the security rules for secure initialization and operation which the cryptographic module and Crypto Officer shall be enforced under FIPS 140-3 security level 2 compliant manner: 11.1. Secure Initialization [Step 1] Execute the firmware loading into the module [Step 2] Execute Init and Open method [Step 3] Replace the default password via Set_CPIN service if first-time authentication. - Identify the status indicator via Show Status service in the Table 7. - Identify that response information matches the versioning information in Table 3. 11.2. Operational description of module

Page 29
Other AttacksMitigation MechanismSpecific Limitations
N/AN/A

The cryptographic module has not been designed to mitigate any specific attacks beyond the scope of FIPS 140-3 N/A N/A N/A Table 18. Mitigation of Other Attacks