All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Hitachi Embedded Storage Manager Kernel Crypto API Cryptographic Module

Certificate#5086StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip EmbeddedStatusActiveVendorHitachi Vantara, Ltd.
Medium review priority  ·  exposes kernel crypto consumer  ·  Linux kernel upstream has published 3932 CVEs since this module's initial validation  ·  last validated 9 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Embedded
StatusActive
Sunset date10/22/2030
CaveatWhen operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorHitachi Vantara, Ltd.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Hitachi Embedded Storage Manager Kernel Crypto API Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Hitachi Embedded Storage Manager Kernel Crypto API Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

Hitachi Vantara, Ltd. Hitachi Embedded Storage Manager Kernel Crypto API Cryptographic Module Version 1.0 © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 2
Table of Contents
#SectionPage
Page 3

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)7
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Modes List and Description8
Table 5: Approved Algorithms9
Table 6: Non-Approved, Not Allowed Algorithms10
Table 7: Security Function Implementations22
Table 8: Ports and Interfaces23
Table 9: Roles23
Table 10: Approved Services27
Table 11: Non-Approved Services27
Table 12: Storage Areas28
Table 13: SSP Input-Output Methods29
Table 14: SSP Zeroization Methods29
Table 15: SSP Table 131
Table 16: SSP Table 231
Table 17: Pre-Operational Self-Tests31
Table 18: Conditional Self-Tests43
Table 19: Pre-Operational Periodic Information43
Table 20: Conditional Periodic Information48
Table 21: Error States48
Figure 1: Block Diagram7
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document defines the Security Policy for the Hitachi Embedded Storage Manager Kernel Crypto API Cryptographic Module, hereafter denoted as the module. The module meets FIPS 140-3 overall Level 1 requirements.

1.2 Security Levels
2.1 Description

Purpose and Use: The module provides general purpose cryptographic services for the Hitachi Embedded Storage Manager. The module works in kernel space and provides cryptographic services to other kernel functions through C language interfaces and to user space applications through the AF_ALG socket. Module Embodiment: MultiChipEmbed Cryptographic Boundary: The cryptographic boundary for the module consists of the static kernel binary, the cryptographic kernel object files, the self-test program, the integrity test program, the Conditional Cryptographic Algorithm Self-Tests (CAST) result check program, the version printout program, and its integrity hash files. The components are enumerated below. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 6
Static kernel binary: /boot/Image-5.10.212-cip45
Cryptographic kernel object files: /lib/modules/5.10.212-cip45/kernel/crypto/*.ko /lib/modules/5.10.212-cip45/kernel/arch/arm64/crypto/*.ko
Self-test program: /usr/local/sbin/pltf-kernel-fips.sh
Integrity test utility: /usr/local/sbin/sha256sum-fips
Integrity test hash file: /usr/local/sbin/fips-checksums.txt
Conditional Cryptographic Algorithm Self-Tests (CAST) result check program: /usr/local/sbin/checkcrypto
Version printout program: /usr/local/sbin/showversion-fips

The green solid line in Figure 1 shows the delimitation of the module’s cryptographic boundary. The module is designed to be able to utilize Processor Algorithm Acceleration(PAA) functions, Arm Neon instructions and ARMv8 Crypto Extensions, from the processor and assembly code for AES and SHA operations to accelerate the cryptographic calculations of the module. Tested Operational Environment’s Physical Perimeter (TOEPP) The tested operational environment hardware for the module is dedicated hardware for the Hitachi Storage System, Storage Management Controller. The enclosure of the Storage Management Controller is TOEPP. The Storage Management Controller implements a processor, Layerscape® 1046A. An operating system, EMLinux®, works on the processor. The module and the Embedded Storage Manager (ESM) applications work within the operating system. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
Embedded Storage Manager Kernel Crypto API Cryptographic Module1.1N/ASHA2-256
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 8
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
EMLinux 2.9Storage Management ControllerLayerscape® 1046AYesN/A1.1
EMLinux 2.9Storage Management ControllerLayerscape® 1046ANoN/A1.1
Mode NameDescriptionTypeStatus Indicator
ApprovedOnly approved or allowed security functions with sufficient security strength can be used.ApprovedThe indicator of the service as defined in Section 4.3.
Non- approvedOnly non-approved security functions can be used.Non- ApprovedThe indicator of the return value of the indicator function.
AlgorithmCAVP CertPropertiesReference
AES-CBCA5827, A5828, A5829, A5830, A5831, A5834Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800- 38A

Tested Operational Environments - Software, Firmware, Hybrid: Table 3: Tested Operational Environments - Software, Firmware, Hybrid The Layerscape® 1046A processor integrates quad 64-bit Arm® Cortex®-A72 cores. Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module.

2.3 Excluded Components

The module has no excluded components.

2.4 Modes of Operation

Modes List and Description: Table 4: Modes List and Description When the operating system starts, the module automatically enters the approved mode of operation. No special API calls or settings are required to place the module in the approved Once the module is operational, if the use of the non-approved service is started, the module implicitly enters the non-approved mode. When the use of the non-approved service is ended, the module implicitly and immediately enters the approved mode.

2.5 Algorithms

Approved Algorithms: © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 9
AlgorithmCAVP CertPropertiesReference
AES-CBC-CS3A5827, A5828, A5829, A5830, A5831, A5833Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800- 38A
AES-CMACA5827, A5828, A5829, A5830, A5831, A5833Direction - Generation, Verification Key Length - 128, 192, 256SP 800- 38B
AES-CTRA5827, A5828, A5829, A5830, A5831, A5834Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800- 38A
AES-ECBA5827, A5828, A5829, A5830, A5831, A5834Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800- 38A
AES-KWA5827, A5828, A5830, A5831Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800- 38F
AES-XTS Testing Revision 2.0A5827, A5828, A5829, A5830, A5831, A5834Direction - Decrypt, Encrypt Key Length - 128, 256SP 800- 38E
HMAC-SHA-1A5830, A5831Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5828, A5830, A5831, A5833Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5828, A5831Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5828, A5831Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-256A5831Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-384A5831Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-512A5831Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
SHA-1A5830, A5831Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A5828, A5830, A5831, A5832, A5833Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A5828, A5831Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A5828, A5831Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA3-256A5831Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-384A5831Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-512A5831Message Length - Message Length: 0-65536 Increment 8FIPS 202

Table 5: Approved Algorithms Vendor-Affirmed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms: © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 10
NameUse and Function
RSA-sigGen (pkcs1pad(rsa- generic,sha256/sha384/sha512))Used for RSA signature generation.
RSA-sigVer (pkcs1pad(rsa- generic,sha256/sha384/sha512))Used for RSA signature verification.
RSA-signaturePrimitive (rsa-generic)Used for RSA signature primitive operation.
RSA-decryptionPrimitive (rsa-generic)Used for RSA decrypt primitive operation.
NameTypeDescriptionPropertiesAlgorithms
sha1-genericSHAUsed to generate SHA1 hash value using generic C implementation.SHA-1: (A5831)
sha1-ceSHAUsed to generate SHA1 hash value using ARMv8 Crypto Extensions (CE).SHA-1: (A5830)
sha256-genericSHAUsed to generate SHA2- 256 hash value using generic C implementation.SHA2-256: (A5831)
sha256-ceSHAUsed to generate SHA2- 256 hash value using ARMv8 Crypto Extensions (CE).SHA2-256: (A5830)
sha256-arm64SHAUsed to generate SHA2- 256 hash value using assembler.SHA2-256: (A5828)
sha256-arm64- neonSHAUsed to generate SHA2-SHA2-256: (A5833)

N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: Table 6: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 11
NameTypeDescriptionPropertiesAlgorithms
256 hash value using Arm NEON instructions.
Integrity Check UtilitySHAUsed to generate SHA2- 256 hash value for integrity check of the module.SHA2-256: (A5832)
sha384-genericSHAUsed to generate SHA2- 384 hash value using generic C implementation.SHA2-384: (A5831)
sha384-arm64SHAUsed to generate SHA2- 384 hash value using assembler.SHA2-384: (A5828)
sha512-genericSHAUsed to generate SHA2- 512 hash value using generic C implementation.SHA2-512: (A5831)
sha512-arm64SHAUsed to generate SHA2- 512 hash value using assembler.SHA2-512: (A5828)
sha3-256- genericSHAUsed to generate SHA3- 256 hash value using generic C implementation.SHA3-256: (A5831)
sha3-384- genericSHAUsed to generate SHA3- 384 hash value using generic C implementation.SHA3-384: (A5831)
sha3-512- genericSHAUsed to generate SHA3- 512 hash value using generic C implementation.SHA3-512: (A5831)
hmac(sha1- generic)MACUsed to generate MAC based on SHA1 function usingHMAC-SHA-1: (A5831)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 12
NameTypeDescriptionPropertiesAlgorithms
generic C implementation.
hmac(sha1-ce)MACUsed to generate MAC based on SHA1 function using ARMv8 Crypto Extensions (CE).HMAC-SHA-1: (A5830)
hmac(sha256- generic)MACUsed to generate MAC based on SHA2- 256 function using generic C implementation.HMAC-SHA2- 256: (A5831)
hmac(sha256- ce)MACUsed to generate MAC based on SHA2- 256 function using ARMv8 Crypto Extensions (CE).HMAC-SHA2- 256: (A5830)
hmac(sha256- arm64)MACUsed to generate MAC based on SHA2- 256 function using assembler.HMAC-SHA2- 256: (A5828)
hmac(sha256- arm64-neon)MACUsed to generate MAC based on SHA2- 256 function using NEON instructions.HMAC-SHA2- 256: (A5833)
hmac(sha384- generic)MACUsed to generate MAC based on SHA2- 384 function using generic C implementation.HMAC-SHA2- 384: (A5831)
hmac(sha384- arm64)MACUsed to generate MAC based on SHA2- 384 function using assembler.HMAC-SHA2- 384: (A5828)
hmac(sha512- generic)MACUsed to generate MAC based on SHA2- 512 functionHMAC-SHA2- 512: (A5831)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 13
NameTypeDescriptionPropertiesAlgorithms
using generic C implementation.
hmac(sha512- arm64)MACUsed to generate MAC based on SHA2- 512 function using assembler.HMAC-SHA2- 512: (A5828)
hmac(sha3-256- generic)MACUsed to generate MAC based on SHA3- 256 function using generic C implementation.HMAC-SHA3- 256: (A5831)
hmac(sha3-384- generic)MACUsed to generate MAC based on SHA3- 384 function using generic C implementation.HMAC-SHA3- 384: (A5831)
hmac(sha3-512- generic)MACUsed to generate MAC based on SHA3- 512 function using generic C implementation.HMAC-SHA3- 512: (A5831)
ecb(aes-generic)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-ECB composed of AES using generic C implementation and ECB mode using generic C implementation.AES-ECB: (A5831)
ecb(aes-ce)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-ECB composed of AES using ARMv8 Crypto Extensions (CE) and ECB mode using generic C implementation.AES-ECB: (A5830)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 14
NameTypeDescriptionPropertiesAlgorithms
ecb-aes-ceBC-UnAuthUsed to encrypt/decrypt inputted data with AES-ECB composed of AES using ARMv8 Crypto Extensions (CE) and ECB mode using assembler.AES-ECB: (A5829)
ecb(aes-arm64)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-ECB composed of AES using assembler and ECB mode using assembler.AES-ECB: (A5828)
ecb(aes-fixed- time)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-ECB composed of Fixed time AES using generic C implementation and ECB mode using generic C implementation.AES-ECB: (A5827)
ecb-aes-neonbsBC-UnAuthUsed to encrypt/decrypt inputted data with AES-ECB composed of Bit sliced AES using Arm Neon instructions and ECB mode using assembler.AES-ECB: (A5834)
ctr(aes-generic)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CTR composed of AES using generic C implementationAES-CTR: (A5831)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 15
NameTypeDescriptionPropertiesAlgorithms
and CTR mode using generic C implementation.
ctr(aes-ce)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CTR composed of AES using ARMv8 Crypto Extensions (CE) and CTR mode using generic C implementation.AES-CTR: (A5830)
ctr-aes-ceBC-UnAuthUsed to encrypt/decrypt inputted data with AES-CTR composed of AES using ARMv8 Crypto Extensions (CE) and CTR mode using assembler.AES-CTR: (A5829)
ctr(aes-arm64)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CTR composed of AES using assembler and CTR mode using assembler.AES-CTR: (A5828)
ctr(aes-fixed- time)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CTR composed of Fixed time AES using generic C implementation and CTR mode using generic C implementation.AES-CTR: (A5827)
ctr-aes-neonbsBC-UnAuthUsed to encrypt/decrypt inputted data with AES-CTRAES-CTR: (A5834)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 16
NameTypeDescriptionPropertiesAlgorithms
composed of Bit sliced AES using Arm Neon instructions and CTR mode using assembler.
cbc(aes-generic)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC composed of AES using generic C implementation and CBC mode using generic C implementation.AES-CBC: (A5831)
cbc(aes-ce)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC composed of AES using ARMv8 Crypto Extensions (CE) and CBC mode using generic C implementation.AES-CBC: (A5830)
cbc-aes-ceBC-UnAuthUsed to encrypt/decrypt inputted data with AES-CTR composed of AES using ARMv8 Crypto Extensions (CE) and CTR mode using assembler.AES-CBC: (A5829)
cbc(aes-arm64)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC composed of AES using assembler and CBC mode using assembler.AES-CBC: (A5828)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 17
NameTypeDescriptionPropertiesAlgorithms
cbc(aes-fixed- time)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC composed of Fixed time AES using generic C implementation and CBC mode using generic C implementation.AES-CBC: (A5827)
cbc-aes-neonbsBC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC composed of Bit sliced AES using Arm Neon instructions and CBC mode using assembler.AES-CBC: (A5834)
cts(cbc(aes- generic))BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC- CS3 composed of AES using generic C implementation and CBC-CS3 mode using generic C implementation.AES-CBC-CS3: (A5831)
cts(cbc(aes-ce))BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC- CS3 composed of AES using ARMv8 Crypto Extensions (CE) and CBC-CS3 mode using generic C implementation.AES-CBC-CS3: (A5830)
cts-cbc-aes-ceBC-UnAuthUsed to encrypt/decrypt inputted dataAES-CBC-CS3: (A5829)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 18
NameTypeDescriptionPropertiesAlgorithms
with AES-CBC- CS3 composed of AES using ARMv8 Crypto Extensions (CE) and CBC-CS3 mode using assembler.
cts(cbc(aes- arm64))BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC- CS3 composed of AES using assembler and CBC-CS3 mode using assembler.AES-CBC-CS3: (A5828)
cts(cbc(aes- fixed-time))BC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC- CS3 composed of Fixed time AES using generic C implementation and CBC-CS3 mode using generic C implementation.AES-CBC-CS3: (A5827)
cts-cbc-aes- neonBC-UnAuthUsed to encrypt/decrypt inputted data with AES-CBC- CS3 composed of AES using Arm Neon instructions and CBC-CS3 mode using assembler.AES-CBC-CS3: (A5833)
cmac(aes- generic)MACUsed to generate MAC based on AES encryption using generic C implementation and CMACAES-CMAC: (A5831)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 19
NameTypeDescriptionPropertiesAlgorithms
mode using generic C implementation.
cmac(aes-ce)MACUsed to generate MAC based on AES encryption using ARMv8 Crypto Extensions (CE) and CMAC mode using generic C implementation.AES-CMAC: (A5830)
cmac-aes-ceMACUsed to generate MAC based on AES encryption using ARMv8 Crypto Extensions (CE) and CMAC mode using assembler.AES-CMAC: (A5829)
cmac(aes- arm64)MACUsed to generate MAC based on AES encryption using assembler and CMAC mode using assembler.AES-CMAC: (A5828)
cmac(aes-fixed- time)MACUsed to generate MAC based on Fixed time AES encryption using generic C implementation and CMAC mode using generic C implementation.AES-CMAC: (A5827)
cmac-aes-neonMACUsed to generate MAC based on AES encryption using Arm Neon instructions and CMAC modeAES-CMAC: (A5833)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 20
NameTypeDescriptionPropertiesAlgorithms
using assembler.
xts(aes-generic)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-XTS composed of AES using generic C implementation and XTS mode using generic C implementation.AES-XTS Testing Revision 2.0: (A5831)
xts(aes-ce)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-XTS composed of AES using ARMv8 Crypto Extensions (CE) and XTS mode using generic C implementation.AES-XTS Testing Revision 2.0: (A5830)
xts-aes-ceBC-UnAuthUsed to encrypt/decrypt inputted data with AES-XTS composed of AES using ARMv8 Crypto Extensions (CE) and XTS mode using assembler.AES-XTS Testing Revision 2.0: (A5829)
xts(aes-arm64)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-XTS composed of AES using assembler and XTS mode using assembler.AES-XTS Testing Revision 2.0: (A5828)
xts(aes-fixed- time)BC-UnAuthUsed to encrypt/decrypt inputted data with AES-XTS composed ofAES-XTS Testing Revision 2.0: (A5827)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 21
NameTypeDescriptionPropertiesAlgorithms
Fixed time AES using generic C implementation and XTS mode using generic C implementation.
xts-aes-neonbsBC-UnAuthUsed to encrypt/decrypt inputted data with AES-XTS composed of Bit sliced AES using Arm Neon instructions and XTS mode using assembler.AES-XTS Testing Revision 2.0: (A5834)
kw(aes-generic)BC-AuthUsed to wrap/unwrap inputted key with AES-KW composed of AES using generic C implementation and KW mode using generic C implementation.AES-KW: (A5831)
kw(aes-ce)BC-AuthUsed to wrap/unwrap inputted key with AES-KW composed of AES using ARMv8 Crypto Extensions (CE) and KW mode using generic C implementation.AES-KW: (A5830)
kw(aes-arm64)BC-AuthUsed to wrap/unwrap inputted key with AES-KW composed of AES using assembler and KW mode using assembler.AES-KW: (A5828)
kw(aes-fixed- time)BC-AuthUsed to wrap/unwrapAES-KW: (A5827)

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 22
NameTypeDescriptionPropertiesAlgorithms
inputted key with AES-KW composed of Fixed time AES using generic C implementation and KW mode using generic C implementation.

Table 7: Security Function Implementations

2.7 Algorithm Specific Information

AES XTS: As specified in SP800-38E, the AES algorithm in XTS mode (AES-XTS) was designed for the cryptographic protection of data on storage devices that use fixed length data units. Thus, it can only be used for the disk encryption functionality offered by dm-crypt (i.e., the hard disk encryption scheme). For dm-crypt, the length of a single data unit encrypted with the AES XTS is at most 65,536 bytes (64KiB of data), which does not exceed 220 AES blocks (16MiB of data). To meet the requirement stated in FIPS140-3 IG C.I, the module has a function that checks if two keys for the AES-XTS are different from each other. SHA-1: The use of SHA-1 is only approved for integrity checks and is not approved if used as part of digital signature generation.

2.8 RBG and Entropy

N/A for this module. N/A for this module.

2.9 Key Generation
2.10 Key Establishment
2.11 Industry Protocols

N/A for this module. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 23
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters from kernel system calls, AF_ALG type socket.
N/AData OutputAPI output parameters from kernel system calls, AF_ALG type socket.
N/AControl InputAPI function calls, API input parameters for control from kernel system calls, AF_ALG type socket, command line input.
N/AStatus OutputAPI return codes, AF_ALG type socket, kernel logs, user logs, command line output.
NameTypeOperator TypeAuthentication Methods
Cryptographic OfficerRoleCONone
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access
AES encryption and decryptionAES encryption and decryption.Approve d if the following condition s are met. Conditio n 1: the return value ofAES keys, Data to encrypt or decryptEncrypted data or decrypted dataecb(aes- generic) ecb(aes-ce) ecb-aes-ce ecb(aes- arm64) ecb(aes- fixed-time) ecb-aes- neonbsCryptographi c Officer - AES Key: W,E
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 8: Ports and Interfaces

4 Roles, Services, and Authentication

N/A for this module. The module does not support authentication for roles.

4.2 Roles

Table 9: Roles Cryptographic Officer role is implicitly and always assumed.

4.3 Approved Services

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 24
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access
indicator function is 1. Conditio n 2: the return value of key input is 0.ctr(aes- generic) ctr(aes-ce) ctr-aes-ce ctr(aes- arm64) ctr(aes-fixed- time) ctr-aes- neonbs cbc(aes- generic) cbc(aes-ce) cbc-aes-ce cbc(aes- arm64) cbc(aes- fixed-time) cbc-aes- neonbs cts(cbc(aes- generic)) cts(cbc(aes- ce)) cts-cbc-aes- ce cts(cbc(aes- arm64)) cts(cbc(aes- fixed-time)) cts-cbc-aes- neon xts(aes- generic) xts(aes-ce) xts-aes-ce xts(aes- arm64) xts(aes- fixed-time) xts-aes- neonbs
Key wrapping and unwrappingKey wrapping and unwrapping using AES.Approve d if the following condition s are met. ConditioAES key, Key as data to key wrap orWrapped key or unwrappe d keykw(aes- generic) kw(aes-ce) kw(aes- arm64) kw(aes- fixed-time)Cryptographi c Officer - AES Key: W,E

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 25
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access
n 1: the return value of indicator function is 1. Conditio n 2: the return value of key input is 0.key unwrap
Message digestMessage digest generation.Approve d if the return value of indicator function is 1.Data for digestDigest valuesha1-generic sha1-ce sha256- generic sha256-ce sha256- arm64 sha256- arm64-neon sha384- generic sha384- arm64 sha512- generic sha512- arm64 sha3-256- generic sha3-384- generic sha3-512- genericCryptographi c Officer
Message authenticatio n code (HMAC)Message authenticatio n code generation based on a hash function.Approve d if the return value of indicator function is 1.HMAC Key, messag eMAChmac(sha1- generic) hmac(sha1- ce) hmac(sha25 6-generic) hmac(sha25 6-ce) hmac(sha25 6-arm64) hmac(sha25 6-arm64- neon) hmac(sha38Cryptographi c Officer - HMAC Key: W,E

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 26
NameDescriptionIndicato rInputsOutputsSecurity FunctionsSSP Access
4-generic) hmac(sha38 4-arm64) hmac(sha51 2-generic) hmac(sha51 2-arm64) hmac(sha3- 256-generic) hmac(sha3- 384-generic) hmac(sha3- 512-generic)
Message authenticatio n code (CMAC)Message authenticatio n code generation based on a cipher function.Approve d if the return value of indicator function is 1.AES Key, messag eMACcmac(aes- generic) cmac(aes- ce) cmac-aes-ce cmac(aes- arm64) cmac(aes- fixed-time) cmac-aes- neonCryptographi c Officer - AES Key: W,E
Error detectionCompute an EDC (crc32, crc32c, xxhash64)NoneDataEDCNoneCryptographi c Officer
Memory copyMemory copy operationNoneDataOutputNoneCryptographi c Officer
Show Module Information (show version)Show module ID and version.NoneNoneModule ID, module version.NoneCryptographi c Officer
Show StatusShow module status.NoneNoneModule statusNoneCryptographi c Officer
ZeroiseZeroise SSPs.NoneNoneNoneNoneCryptographi c Officer - AES Key: Z - HMAC Key: Z
On-demand self testPerform IntegrityNoneNoneNoneIntegrity Check UtilityCryptographi c Officer

Z © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 27

Name

Description check and CASTs.

Indicato r

Inputs

Outputs

Security Functions

SSP Access

NameDescriptionAlgorithmsRole
RSA signature generationSignature generation based on the PKCS#1.RSA-sigGen (pkcs1pad(rsa- generic,sha256/sha384/sha512))Cryptographic Officer
RSA signature verificationSignature verification based on the PKCS#1.RSA-sigVer (pkcs1pad(rsa- generic,sha256/sha384/sha512))Cryptographic Officer
RSA signature primitive operationSignature primitive operation based on the RSA algorithm.RSA-signaturePrimitive (rsa-generic)Cryptographic Officer
RSA decrypt primitive operationDecrypt primitive operation based on the RSA algorithm.RSA-decryptionPrimitive (rsa- generic)Cryptographic Officer

Table 10: Approved Services All approved services implemented by the module are listed above. Each service description also describes all usage of SSPs by the service. The access rights to keys and/or SSPs modes shown in the table are defined as:

4.4 Non-Approved Services

Table 11: Non-Approved Services

4.5 External Software/Firmware Loaded
5 Software/Firmware Security
5.1 Integrity Techniques

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 28
Storage Area NameDescriptionPersistence Type
MemoryA volatile memory on the operational environmentDynamic

The integrity of the static kernel binary, the cryptographic kernel object files, the self-test program, the integrity test program, the Conditional Cryptographic Algorithm Self-Tests (CAST) result check program and the version printout program are tested by comparing the SHA2-256 digest values calculated at startup with the SHA2-256 digest values calculated and stored in the module during module development.

5.2 Initiate on Demand

The integrity tests are performed as part of the pre-operational self-tests. Thus, the integrity tests can be initiated on demand by power cycle or reboot of the operational environment of the module.

6.2 Configuration Settings and Restrictions

The ptrace system call, the debugger gdb and strace shall not be used. In addition, other tracing mechanisms offered by the Linux environment, such as ftrace or systemtap shall not be used.

7 Physical Security

N/A. Since the module consists only of software, this section is not applicable.

8 Non-Invasive Security

N/A. The module does not implement non-invasive security techniques.

9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 12: Storage Areas The module does not store SSPs in persistent storage. The SSPs are temporarily stored in process memory when the module is being used.

9.2 SSP Input-Output Methods

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 29
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API InputMemoryMemoryPlaintextManualElectronic
AF_ALG_type sockets (input)MemoryMemoryPlaintextManualElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Power cyclePower cycle of the operational environmentAll SSPs of the module are zeroised by Power cycle because all SSPs are on a volatile memory.Yes
RebootReboot of the operational environmentAll SSPs of the module are zeroised by Reboot because all SSPs are on a volatile memory.Yes
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES KeyAES key used for encryption, decryption, and generating MAC.128, 192, 256 bits; XTS 128, 256 bits - 128, 192, 256 bits; XTS 128, 256 bitsSymmetric Key - CSPecb(aes- generic) ecb(aes-ce) ecb-aes-ce ecb(aes- arm64) ecb(aes-fixed- time) ecb-aes- neonbs ctr(aes- generic) ctr(aes-ce) ctr-aes-ce ctr(aes- arm64) ctr(aes-fixed- time) ctr-aes- neonbs cbc(aes- generic) cbc(aes-ce) cbc-aes-ce

Table 13: SSP Input-Output Methods

9.3 SSP Zeroization Methods

Table 14: SSP Zeroization Methods the Hitachi Embedded Storage Manager. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 30
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By cbc(aes- arm64) cbc(aes-fixed- time) cbc-aes- neonbs cts(cbc(aes- generic)) cts(cbc(aes- ce)) cts-cbc-aes-ce cts(cbc(aes- arm64)) cts(cbc(aes- fixed-time)) cts-cbc-aes- neon cmac(aes- generic) cmac(aes-ce) cmac-aes-ce cmac(aes- arm64) cmac(aes- fixed-time) cmac-aes- neon xts(aes- generic) xts(aes-ce) xts-aes-ce xts(aes- arm64) xts(aes-fixed- time) xts-aes- neonbs kw(aes- generic) kw(aes-ce) kw(aes- arm64) kw(aes-fixed- time)
HMAC KeyHMAC key used for generating MAC112 - 65,535 bits - 112 - 256 bitsSymmetric Key - CSPhmac(sha1- generic) hmac(sha1- ce) hmac(sha256-

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 31

Name

Description

Size - Strength

Type - Category

Generated By

Established By

Used By generic) hmac(sha256- ce) hmac(sha256- arm64) hmac(sha256- arm64-neon) hmac(sha384- generic) hmac(sha384- arm64) hmac(sha512- generic) hmac(sha512- arm64) hmac(sha3- 256-generic) hmac(sha3- 384-generic) hmac(sha3- 512-generic)

Name AES Key HMAC Key

Input - Output API Input AF_ALG_type sockets (input) API Input AF_ALG_type sockets (input)

Storage Memory:Plaintext Memory:Plaintext

Storage Duration During the execution of the service. During the execution of the service.

Zeroization Power cycle Reboot Power cycle Reboot

Related SSPs

Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
SHA2-256 (A5832)SHA2-256KATSW/FW Integrityuser.err logMessage Digest

Table 15: SSP Table 1 Table 16: SSP Table 2

9.5 Transitions

The SHA-1 algorithm, as implemented by the module, will be non-approved for all purposes after December 31, 2030.

10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 17: Pre-Operational Self-Tests If the pre-operational self-test fails, the module enters the error state. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 32
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A5827)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CBC (A5827)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CTR (A5827)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-XTS (A5827)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CBC- CS3 (A5827)- EncryptKey size: 128 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-KW (A5827)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot
AES-CMAC (A5827)- GenerationKey size: 128, 256 bitsKATCASTKernel logGenerationFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-ECB (A5828)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first-
10.2 Conditional Self-Tests

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 33
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions time use of this algorithm after OS boot.
AES-CBC (A5828)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CTR (A5828)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-XTS (A5828)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CBC- CS3 (A5828)- EncryptKey size: 128 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-KW (A5828)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot
AES-ECB (A5827)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CBC (A5827)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CTR (A5827)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first-

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 34
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions time use of this algorithm after OS boot.
AES-XTS (A5827)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CBC- CS3 (A5827)- DecryptKey size: 128 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-KW (A5827)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot
AES-CMAC (A5827)- VerificationKey size: 128, 256 bitsKATCASTKernel logVerificationFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-ECB (A5828)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CBC (A5828)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CTR (A5828)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-XTS (A5828)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first-

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 35
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions time use of this algorithm after OS boot.
AES-CBC- CS3 (A5828)- DecryptKey size: 128 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-KW (A5828)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot
SHA2-256 (A5828)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
SHA2-384 (A5828)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
SHA2-512 (A5828)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
AES-CMAC (A5828)- GenerationKey size: 128, 256 bitsKATCASTKernel logGenerationFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CMAC (A5828)- VerificationKey size: 128, 256 bitsKATCASTKernel logVerificationFrom the operation of the module to the first- time use of this algorithm after OS boot.
HMAC- SHA2-256 (A5828)Key size: 32, 256, 296, 640 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
HMAC- SHA2-384 (A5828)Key size: 32, 160, 1048 bitsKATCASTKernel logMACFrom the operation of the module to the first-

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 36
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions time use of this algorithm after OS boot.
HMAC- SHA2-512 (A5828)Key size: 32, 160, 1048 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-ECB (A5830)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CBC (A5830)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CTR (A5830)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-XTS (A5830)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CBC- CS3 (A5830)- EncryptKey size: 128 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-KW (A5830)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot
AES-ECB (A5830)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first-

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 37
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions time use of this algorithm after OS boot.
AES-CBC (A5830)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CTR (A5830)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-XTS (A5830)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-CBC- CS3 (A5830)- DecryptKey size: 128 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-KW (A5830)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot
SHA-1 (A5830)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
SHA2-256 (A5830)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
AES-CMAC (A5830)- GenerationKey size: 128, 256 bitsKATCASTKernel logGenerationFrom the operation of the module to the first- time use of this algorithm after OS boot.

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 38
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CMAC (A5830)- VerificationKey size: 128, 256 bitsKATCASTKernel logVerificationFrom the operation of the module to the first- time use of this algorithm after OS boot.
HMAC-SHA- 1 (A5830)Key size: 32, 160, 200, 640 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
HMAC- SHA2-256 (A5830)Key size: 32, 256, 296, 640 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-ECB (A5829)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-CBC (A5829)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-CTR (A5829)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-XTS (A5829)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-CBC- CS3 (A5829)- EncryptKey size: 128 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-ECB (A5829)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-CBC (A5829)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 39
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CTR (A5829)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-XTS (A5829)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-CBC- CS3 (A5829)- DecryptKey size: 128 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-CMAC (A5829)- GenerationKey size: 128, 256 bitsKATCASTKernel logGenerationFrom the module startup to the operation of the module.
AES-CMAC (A5829)- VerificationKey size: 128, 256 bitsKATCASTKernel logVerificationFrom the module startup to the operation of the module.
AES-ECB (A5831)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-CBC (A5831)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-CTR (A5831)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-XTS (A5831)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-CBC- CS3 (A5831)- EncryptKey size: 128 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-KW (A5831)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the operation of the module to the first- time use of this algorithm after OS boot

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 40
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A5831)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-CBC (A5831)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-CTR (A5831)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-XTS (A5831)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-CBC- CS3 (A5831)- DecryptKey size: 128 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-KW (A5831)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the operation of the module to the first- time use of this algorithm after OS boot
SHA-1 (A5831)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
SHA2-256 (A5831)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
SHA2-384 (A5831)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
SHA2-512 (A5831)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
SHA3-256 (A5831)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
SHA3-384 (A5831)N/AKATCASTKernel logHashFrom the module startup to the

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 41
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions operation of the module.
SHA3-512 (A5831)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
AES-CMAC (A5831)- GenerationKey size: 128, 256 bitsKATCASTKernel logGenerationFrom the module startup to the operation of the module.
AES-CMAC (A5831)- VerificationKey size: 128, 256 bitsKATCASTKernel logVerificationFrom the module startup to the operation of the module.
HMAC-SHA- 1 (A5831)Key size: 32, 160, 200, 640 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
HMAC- SHA2-256 (A5831)Key size: 32, 256, 296, 640 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
HMAC- SHA2-384 (A5831)Key size: 32, 160, 1048 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
HMAC- SHA2-512 (A5831)Key size: 32, 160, 1048 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
HMAC- SHA3-256 (A5831)Key size: 32, 160, 1048 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
HMAC- SHA3-384 (A5831)Key size: 32, 160, 1048 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 42
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions algorithm after OS boot.
HMAC- SHA3-512 (A5831)Key size: 32, 160, 1048 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
SHA2-256 (A5832)N/AKATCASTuser.err logHashFrom the module startup to the integrity testing.
AES-CBC- CS3 (A5833)- EncryptKey size: 128 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-CBC- CS3 (A5833)- DecryptKey size: 128 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
SHA2-256 (A5833)N/AKATCASTKernel logHashFrom the module startup to the operation of the module.
AES-CMAC (A5833)- GenerationKey size: 128, 256 bitsKATCASTKernel logGenerationFrom the module startup to the operation of the module.
AES-CMAC (A5833))- VerificationKey size: 128, 256 bitsKATCASTKernel logVerificationFrom the module startup to the operation of the module.
HMAC- SHA2-256 (A5833)Key size: 32, 256, 296, 640 bitsKATCASTKernel logMACFrom the operation of the module to the first- time use of this algorithm after OS boot.
AES-ECB (A5834)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-CBC (A5834)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-CTR (A5834)- EncryptKey size: 128, 192, 256 bitsKATCASTKernel logEncryptFrom the module startup to the

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 43
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions operation of the module.
AES-XTS (A5834)- EncryptKey size: 128, 256 bitsKATCASTKernel logEncryptFrom the module startup to the operation of the module.
AES-ECB (A5834)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-CBC (A5834)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-CTR (A5834)- DecryptKey size: 128, 192, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
AES-XTS (A5834)- DecryptKey size: 128, 256 bitsKATCASTKernel logDecryptFrom the module startup to the operation of the module.
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-256 (A5832)KATSW/FW IntegrityOn DemandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A5827)-EncryptKATCASTOn DemandManually
AES-CBC (A5827)-EncryptKATCASTOn DemandManually
AES-CTR (A5827)-EncryptKATCASTOn DemandManually
AES-XTS (A5827)-EncryptKATCASTOn DemandManually

Table 18: Conditional Self-Tests When the operational environment is powered on and the module is loaded, the module starts to perform each cryptographic algorithm self-test for the algorithm which “Conditions” item in the "From the module startup to the integrity testing". If one of the self-tests fails, the module enters the error state.

10.3 Periodic Self-Test Information

Table 19: Pre-Operational Periodic Information © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 44
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC-CS3 (A5827)-EncryptKATCASTOn DemandManually
AES-KW (A5827)-EncryptKATCASTOn DemandManually
AES-CMAC (A5827)- GenerationKATCASTOn DemandManually
AES-ECB (A5828)-EncryptKATCASTOn DemandManually
AES-CBC (A5828)-EncryptKATCASTOn DemandManually
AES-CTR (A5828)-EncryptKATCASTOn DemandManually
AES-XTS (A5828)-EncryptKATCASTOn DemandManually
AES-CBC-CS3 (A5828)-EncryptKATCASTOn DemandManually
AES-KW (A5828)-EncryptKATCASTOn DemandManually
AES-ECB (A5827)-DecryptKATCASTOn DemandManually
AES-CBC (A5827)-DecryptKATCASTOn DemandManually
AES-CTR (A5827)-DecryptKATCASTOn DemandManually
AES-XTS (A5827)-DecryptKATCASTOn DemandManually
AES-CBC-CS3 (A5827)-DecryptKATCASTOn DemandManually
AES-KW (A5827)-DecryptKATCASTOn DemandManually
AES-CMAC (A5827)- VerificationKATCASTOn DemandManually
AES-ECB (A5828)-DecryptKATCASTOn DemandManually
AES-CBC (A5828)-DecryptKATCASTOn DemandManually
AES-CTR (A5828)-DecryptKATCASTOn DemandManually
AES-XTS (A5828)-DecryptKATCASTOn DemandManually
AES-CBC-CS3 (A5828)-DecryptKATCASTOn DemandManually
AES-KW (A5828)-DecryptKATCASTOn DemandManually
SHA2-256 (A5828)KATCASTOn DemandManually

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 45
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-384 (A5828)KATCASTOn DemandManually
SHA2-512 (A5828)KATCASTOn DemandManually
AES-CMAC (A5828)- GenerationKATCASTOn DemandManually
AES-CMAC (A5828)- VerificationKATCASTOn DemandManually
HMAC-SHA2- 256 (A5828)KATCASTOn DemandManually
HMAC-SHA2- 384 (A5828)KATCASTOn DemandManually
HMAC-SHA2- 512 (A5828)KATCASTOn DemandManually
AES-ECB (A5830)-EncryptKATCASTOn DemandManually
AES-CBC (A5830)-EncryptKATCASTOn DemandManually
AES-CTR (A5830)-EncryptKATCASTOn DemandManually
AES-XTS (A5830)-EncryptKATCASTOn DemandManually
AES-CBC-CS3 (A5830)-EncryptKATCASTOn DemandManually
AES-KW (A5830)-EncryptKATCASTOn DemandManually
AES-ECB (A5830)-DecryptKATCASTOn DemandManually
AES-CBC (A5830)-DecryptKATCASTOn DemandManually
AES-CTR (A5830)-DecryptKATCASTOn DemandManually
AES-XTS (A5830)-DecryptKATCASTOn DemandManually
AES-CBC-CS3 (A5830)-DecryptKATCASTOn DemandManually
AES-KW (A5830)-DecryptKATCASTOn DemandManually
SHA-1 (A5830)KATCASTOn DemandManually
SHA2-256 (A5830)KATCASTOn DemandManually
AES-CMAC (A5830)- GenerationKATCASTOn DemandManually

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 46
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CMAC (A5830)- VerificationKATCASTOn DemandManually
HMAC-SHA-1 (A5830)KATCASTOn DemandManually
HMAC-SHA2- 256 (A5830)KATCASTOn DemandManually
AES-ECB (A5829)-EncryptKATCASTOn DemandManually
AES-CBC (A5829)-EncryptKATCASTOn DemandManually
AES-CTR (A5829)-EncryptKATCASTOn DemandManually
AES-XTS (A5829)-EncryptKATCASTOn DemandManually
AES-CBC-CS3 (A5829)-EncryptKATCASTOn DemandManually
AES-ECB (A5829)-DecryptKATCASTOn DemandManually
AES-CBC (A5829)-DecryptKATCASTOn DemandManually
AES-CTR (A5829)-DecryptKATCASTOn DemandManually
AES-XTS (A5829)-DecryptKATCASTOn DemandManually
AES-CBC-CS3 (A5829)-DecryptKATCASTOn DemandManually
AES-CMAC (A5829)- GenerationKATCASTOn DemandManually
AES-CMAC (A5829)- VerificationKATCASTOn DemandManually
AES-ECB (A5831)-EncryptKATCASTOn DemandManually
AES-CBC (A5831)-EncryptKATCASTOn DemandManually
AES-CTR (A5831)-EncryptKATCASTOn DemandManually
AES-XTS (A5831)-EncryptKATCASTOn DemandManually
AES-CBC-CS3 (A5831)-EncryptKATCASTOn DemandManually
AES-KW (A5831)-EncryptKATCASTOn DemandManually
AES-ECB (A5831)-DecryptKATCASTOn DemandManually

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 47
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A5831)-DecryptKATCASTOn DemandManually
AES-CTR (A5831)-DecryptKATCASTOn DemandManually
AES-XTS (A5831)-DecryptKATCASTOn DemandManually
AES-CBC-CS3 (A5831)-DecryptKATCASTOn DemandManually
AES-KW (A5831)-DecryptKATCASTOn DemandManually
SHA-1 (A5831)KATCASTOn DemandManually
SHA2-256 (A5831)KATCASTOn DemandManually
SHA2-384 (A5831)KATCASTOn DemandManually
SHA2-512 (A5831)KATCASTOn DemandManually
SHA3-256 (A5831)KATCASTOn DemandManually
SHA3-384 (A5831)KATCASTOn DemandManually
SHA3-512 (A5831)KATCASTOn DemandManually
AES-CMAC (A5831)- GenerationKATCASTOn DemandManually
AES-CMAC (A5831)- VerificationKATCASTOn DemandManually
HMAC-SHA-1 (A5831)KATCASTOn DemandManually
HMAC-SHA2- 256 (A5831)KATCASTOn DemandManually
HMAC-SHA2- 384 (A5831)KATCASTOn DemandManually
HMAC-SHA2- 512 (A5831)KATCASTOn DemandManually
HMAC-SHA3- 256 (A5831)KATCASTOn DemandManually
HMAC-SHA3- 384 (A5831)KATCASTOn DemandManually
HMAC-SHA3- 512 (A5831)KATCASTOn DemandManually
SHA2-256 (A5832)KATCASTOn DemandManually
AES-CBC-CS3 (A5833)-EncryptKATCASTOn DemandManually

© Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 48
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC-CS3 (A5833)-DecryptKATCASTOn DemandManually
SHA2-256 (A5833)KATCASTOn DemandManually
AES-CMAC (A5833)- GenerationKATCASTOn DemandManually
AES-CMAC (A5833))- VerificationKATCASTOn DemandManually
HMAC-SHA2- 256 (A5833)KATCASTOn DemandManually
AES-ECB (A5834)-EncryptKATCASTOn DemandManually
AES-CBC (A5834)-EncryptKATCASTOn DemandManually
AES-CTR (A5834)-EncryptKATCASTOn DemandManually
AES-XTS (A5834)-EncryptKATCASTOn DemandManually
AES-ECB (A5834)-DecryptKATCASTOn DemandManually
AES-CBC (A5834)-DecryptKATCASTOn DemandManually
AES-CTR (A5834)-DecryptKATCASTOn DemandManually
AES-XTS (A5834)-DecryptKATCASTOn DemandManually
NameDescriptionConditionsRecovery MethodIndicator
ErrorA state when the module has encountered an error condition.Condition 1: Failed the pre-operational self- tests or the conditional self-test for SHA2-256 (A5832). Condition 2: Failed the conditional self-tests except for that of SHA2- 256 (A5832).Power cycling or rebooting of the operational environment.Condition 1: user.err log; Condition 2: kernel log

Table 20: Conditional Periodic Information The pre-operational self-tests, and all cryptographic algorithm self-tests listed in Conditional

10.4 Error States

Table 21: Error States © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).

Page 49

After the OS boots, the user.err log and the kernel log (kern.log) are moved to /pstorage1/pltf/snapshot-log/<id>/var/log/ directory. <id> is a number from 0 to 4. <id> is incremented by the OS boot and wrapped back to 0 when that max value is reached. The latest <id> corresponds to that of the filename of the “latest-number-<id>” file in /pstorage1/pltf/snapshot-log/ directory.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is integrated into Embedded Storage Manager. When Embedded Storage Manager is installed by the vendor of Hitachi storage system, the module is also installed. No other special procedure is required to securely install and initialize the module.

11.2 Administrator Guidance

Administrators can verify that an ID and a version of the module is identical to the ID (Embedded Storage Manager Kernel Crypto API) and the version (1.1). To show an ID and a version of the module, run “showversion-fips” command in Command Console of ESM. All the functions, physical ports, and logical interfaces of the module are available to the Crypto Officer.

11.3 Non-Administrator Guidance

There are no requirements for non-administrator.

11.4 Design and Rules

The module design corresponds to the module security rules. This subsection documents the security rules enforced by the module to implement the security requirements of this FIPS 140-3 Level 1 module.

  1. The module shall provide a Cryptographic Officer role.
  2. The operator shall be capable of commanding the module to perform the pre-operational selftests and the cryptographic algorithm self-tests which are configured to be executed during the module initialization process by cycling power or reboot of the operational environment.
  3. Pre-operational self-tests do not require any operator action.
  4. Data output shall be inhibited during self-tests, zeroisation, and error states.
  5. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the module.
  6. The module does not support degraded operation.
  7. The module does not support concurrent operators.
  8. The module does not support a maintenance interface or role.
  9. The module does not support manual key entry. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).
Page 50

10. The module does not have any external input/output devices used for entry/output of data.

12 Mitigation of Other Attacks

N/A. The module does not provide mitigation of other attacks. © Hitachi Vantara, Ltd. 2024 This document may be reproduced and distributed only in its original entirety (without revision).