1 Jun 16, 2026 KIOXIA Corporation KIOXIA FIPS TC58NC1137GTC/TC58NC1138GTC Crypto Sub-Chip Class B1 FIPS 140-3 Non-Proprietary Security Policy Rev 1.3.0 2 Jun 16, 2026 Table of Contents 1 General ......................................................................................................................................5 1.1 Overview .............................................................................................................................5 1.2 Security Levels....................................................................................................................5 1.3 Additional Information..........................................................................................................5 2 Cryptographic Module Specification ..........................................................................................6 2.1 Description ..........................................................................................................................6 2.2 Tested and Vendor Affirmed Module Version and Identification .........................................7 2.3 Excluded Components ........................................................................................................7 2.4 Modes of Operation.............................................................................................................7 2.5 Algorithms ...........................................................................................................................8 2.6 Security Function Implementations .....................................................................................9 2.7 Algorithm Specific Information...........................................................................................10 2.8 RBG and Entropy ..............................................................................................................10 2.9 Key Generation .................................................................................................................10 2.10 Key Establishment...........................................................................................................10 2.11 Industry Protocols............................................................................................................10 3 Cryptographic Module Interfaces.............................................................................................10 3.1 Ports and Interfaces ..........................................................................................................10 4 Roles, Services, and Authentication ........................................................................................11 4.1 Authentication Methods.....................................................................................................11 4.2 Roles .................................................................................................................................11 4.3 Approved Services ............................................................................................................11 4.4 Non-Approved Services ....................................................................................................20 4.5 External Software/Firmware Loaded .................................................................................20 5 Software/Firmware Security.....................................................................................................20 5.1 Integrity Techniques..........................................................................................................20 5.2 Initiate on Demand ............................................................................................................21 6 Operational Environment .........................................................................................................21 6.1 Operational Environment Type and Requirements ...........................................................21 7 Physical Security......................................................................................................................21 7.1 Mechanisms and Actions Required...................................................................................21 8 Non-Invasive Security..............................................................................................................22 8.1 Mitigation Techniques .......................................................................................................22 9 Sensitive Security Parameters Management...........................................................................22 9.1 Storage Areas ...................................................................................................................22 3 Jun 16, 2026 9.2 SSP Input-Output Methods ...............................................................................................23 9.3 SSP Zeroization Methods..................................................................................................23 9.4 SSPs .................................................................................................................................24 10 Self-Tests...............................................................................................................................25 10.1 Pre-Operational Self-Tests..............................................................................................25 10.2 Conditional Self-Tests .....................................................................................................26 10.3 Periodic Self-Test Information .........................................................................................27 10.4 Error States .....................................................................................................................28 10.5 Operator Initiation of Self-Tests.......................................................................................29 11 Life-Cycle Assurance.............................................................................................................29 11.1 Installation, Initialization, and Startup Procedures ..........................................................29 11.2 Administrator Guidance...................................................................................................29 11.3 Non-Administrator Guidance ...........................................................................................30 11.4 Design and Rules............................................................................................................30 11.5 Maintenance Requirements ............................................................................................30 11.6 End of Life .......................................................................................................................30 12 Mitigation of Other Attacks.....................................................................................................30 12.1 Attack List........................................................................................................................30 12.2 Mitigation Effectiveness...................................................................................................30 4 Jun 16, 2026 List of Tables Table 1: Security Levels................................................................................................................5 Table 2: Tested Module Identification – Hardware .......................................................................7 Table 3: Modes List and Description.............................................................................................7 Table 4: Approved Algorithms.......................................................................................................8 Table 5: Vendor-Affirmed Algorithms............................................................................................8 Table 6: Security Function Implementations.................................................................................9 Table 7: Entropy Certificates.......................................................................................................10 Table 8: Entropy Sources ...........................................................................................................10 Table 9: Ports and Interfaces......................................................................................................11 Table 10: Roles...........................................................................................................................11 Table 11: Approved Services......................................................................................................20 Table 12: Mechanisms and Actions Required ............................................................................21 Table 13: Storage Areas.............................................................................................................23 Table 14: SSP Input-Output Methods.........................................................................................23 Table 15: SSP Zeroization Methods ...........................................................................................23 Table 16: SSP Table 1................................................................................................................24 Table 17: SSP Table 2................................................................................................................25 Table 18: Pre-Operational Self-Tests .........................................................................................26 Table 19: Conditional Self-Tests.................................................................................................27 Table 20: Pre-Operational Periodic Information..........................................................................27 Table 21: Conditional Periodic Information .................................................................................28 Table 22: Error States.................................................................................................................28 List of Figures Figure 1: Block Diagram ...............................................................................................................6 Figure 2: TC58NC1137GTC 0002 SoC ......................................................................................22 Figure 3: TC58NC1138GTC 0002 SoC ......................................................................................22 5 Jun 16, 2026 1 General 1.1 Overview This document explains precise specification of the security rules about KIOXIA FIPS TC58NC1137GTC/TC58NC1138GTC Crypto Sub-Chip Class B1. The Cryptographic Module (CM) meets the requirements of FIPS 140-3 Security Level 1 Overall. 1.2 Security Levels Section Title Security Level 1 General 1 2 Cryptographic module specification 1 3 Cryptographic module interfaces 1 4 Roles, services, and authentication 1 5 Software/Firmware security 1 6 Operational environment N/A 7 Physical security 2 8 Non-invasive security N/A 9 Sensitive security parameter management 1 10 Self-tests 1 11 Life-cycle assurance 1 12 Mitigation of other attacks 1 Overall Level 1 Table 1: Security Levels 1.3 Additional Information Acronyms AES Advanced Encryption Standard CM Cryptographic Module SSP Sensitive Security Parameter DRBG Deterministic Random Bit Generator HMAC The Keyed-Hash Message Authentication code KAT Known Answer Test RCT Repetition Count Test APT Adaptive Proportion Test POST Power on Self-Test CAST Cryptographic Algorithm Self-Test PSID Printed SID SED Self-Encrypting Drive SHA Secure Hash Algorithm SID Security ID TCG Trusted Computing Group LBA Logical Block Address 6 Jun 16, 2026 2 Cryptographic Module Specification 2.1 Description Purpose and Use: KIOXIA FIPS TC58NC1137GTC/TC58NC1138GTC Crypto Sub-Chip Class B1 (listed in Section2.2 Tested and Vendor Affirmed Module Version and Identification) is used for solid state drive data security. The CM is a single chip hardware module implemented as a sub-chip compliant with IG 2.3.B in the TC58NC1137GTC 0002 SoC and TC58NC1138GTC 0002 SoC (see Figure 2,3 in Section 7.1). The CM is embedded in TCG OPAL compliant solid state drive controllers which provides user data encryption/decryption through build-in HW engines. Module Type: Hardware Module Embodiment: Single Chip Module Characteristics: SubChip Cryptographic Boundary: The cryptographic boundary is defined as the set of TC58NC1137GTC/TC58NC1138GTC CRPT module as soft circuity core and SC82DN as associated firmware, and the physical perimeter is defined as the surface of TC58NC1137GTC 0002 SoC and TC58NC1138GTC 0002 SoC. Components of the CM is shown with gray background include processor and memories (volatile and non-volatile memory) and HW circuitry for cryptographic processing. Physical ports bordering outside the CM’s boundary and the data passing over them are also indicated (see Section 3.1 for details on physical ports and interfaces). Overview block diagram of the CM is shown below. Figure 1: Block Diagram 7 Jun 16, 2026 2.2 Tested and Vendor Affirmed Module Version and Identification Tested Module Identification – Hardware: Model and/or Part Number Hardwar e Version Firmwar e Version Processor s Features KIOXIA FIPS TC58NC1137GT C Crypto Sub- Chip Class B1 0002 SC82DN Cortex-M3 Single-Chip: TC58NC1137GTC- 0002; Soft Circuitry core: TC58NC1137GTC/TC58NC1138G TC CRPT module 0001 KIOXIA FIPS TC58NC1138GT C Crypto Sub- Chip Class B1 0002 SC82DN Cortex-M3 Single-Chip: TC58NC1138GTC- 0002; Soft Circuitry core: TC58NC1137GTC/TC58NC1138G TC CRPT module 0001 Table 2: Tested Module Identification – Hardware Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): N/A for this module. Tested Module Identification – Hybrid Disjoint Hardware: N/A for this module. Tested Operational Environments - Software, Firmware, Hybrid: N/A for this module. Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module. 2.3 Excluded Components N/A for this module. 2.4 Modes of Operation Modes List and Description: Mode Name Description Type Status Indicator Approved mode Approved mode Approved None* Table 3: Modes List and Description * The CM has one approved mode of operation and CM is always in approved mode of operation after initial operations are performed (See Section 11.1). In approved mode, the CM provides services defined in Table 11 in Section 4.3. 8 Jun 16, 2026 2.5 Algorithms Approved Algorithms: Algorithm CAVP Cert Properties Reference AES-CBC A5952 Direction - Decrypt, Encrypt Key Length - 256 SP 800-38A AES-ECB A5952 Direction - Decrypt, Encrypt Key Length - 256 SP 800-38A AES-XTS Testing Revision 2.0 A5952 Direction - Decrypt, Encrypt Key Length - 256 SP 800-38E ECDSA SigGen (FIPS186-5) A6045 Curve - P-384 Hash Algorithm - SHA2-384 FIPS 186-5 ECDSA SigVer (FIPS186-5) A6045 Curve - P-384 Hash Algorithm - SHA2-384 FIPS 186-5 Hash DRBG A6007 Prediction Resistance - No Mode - SHA2-256 SP 800-90A Rev. 1 HMAC-SHA2-256 A5952 Key Length - Key Length: 256 FIPS 198-1 KDF SP800-108 A6026 KDF Mode - Counter Supported Lengths - Supported Lengths: 512 SP 800-108 Rev. 1 RSA SigVer (FIPS186-5) A5952 Modulo - 2048, 3072 Signature Type - pkcs1v1.5 FIPS 186-5 SHA2-256 A5952 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 SHA2-384 A5952 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 Table 4: Approved Algorithms ECB mode is used as a prerequisite of XTS mode. ECB is not directly used in services of the Cryptographic Module. The CM performs a check that the XTS Key1 and XTS Key2 are different according to IG C.I. AES-XTS is only used for encryption/decryption of data stored in solid state drives equipped with this CM. Vendor-Affirmed Algorithms: Name Properties Implementation Reference CKG Key Type:Symmetric N/A SP800-133 r2, Section 4, example 1 Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: 9 Jun 16, 2026 N/A for this module. 2.6 Security Function Implementations Name Type Description Properties Algorithms KDK Generation CKG Generate KDK with random number Hash DRBG: (A6007) MEKs Generation KBKDF Derive MEKs to be used in external AES circuit based on KDK KDF SP800- 108: (A6026) HMAC Generation/Verification MAC HMAC generation and verification for arbitrary data HMAC-SHA2- 256: (A5952) Key Transport KTS-Wrap Transport data to/from external memory area HMAC-SHA2- 256: (A5952) AES-CBC: (A5952) User Data Encryption/Decryption BC-UnAuth Encryption / Decryption of user data AES-XTS Testing Revision 2.0: (A5952) AES-ECB: (A5952) FW digital signature verification DigSig-SigVer Signature verification for firmware image RSA SigVer (FIPS186-5): (A5952) SHA2-384: (A5952) Signature Generation DigSig-SigGen Signature generation for arbitrary data ECDSA SigGen (FIPS186-5): (A6045) Signature Verification DigSig-SigVer Signature verification for arbitrary data ECDSA SigVer (FIPS186-5): (A6045) Hash calculation SHA Calculate hash for the arbitrary data SHA2-256: (A5952) SHA2-384: (A5952) Random Number Generation DRBG Generate Random Number Hash DRBG: (A6007) Entropy Generation ENT-ESV Entropy Source (E188) : () Table 6: Security Function Implementations 10 Jun 16, 2026 The CM does not implement any Non-Approved Security Function Implementations in the Approved Mode of Operation. 2.7 Algorithm Specific Information There is no algorithm specific information. 2.8 RBG and Entropy Cert Number Vendor Name E188 KIOXIA Corporation Table 7: Entropy Certificates Name Type Operational Environment Sample Size Entropy per Sample Conditioning Component Entropy Source Physical TC58NC1137GTC-0002, TC58NC1138GTC-0002 1 bit 0.673 bit N/A Table 8: Entropy Sources The Entropy Source is a hardware module inside the CM boundary. The Entropy Source supplies the Hash_DRBG with 1024 bits entropy input. From Table 8 this input contains about 689 bits of entropy, which is sufficient entropy to obtain 256 bits of security strength. 2.9 Key Generation Please refer to Section 9.4. 2.10 Key Establishment N/A for this module. 2.11 Industry Protocols N/A for this module. 3 Cryptographic Module Interfaces 3.1 Ports and Interfaces Physical Port Logical Interface(s) Data That Passes Mailbox Data Input Mailbox input parameter Mailbox Data Output Mailbox output parameter Mailbox Control Input Mailbox command information 11 Jun 16, 2026 Physical Port Logical Interface(s) Data That Passes Mailbox Status Output Mailbox command result AES circuit Data Input User data AES circuit Data Output User data DMAC Data Input Mailbox input parameter DMAC Data Output Mailbox output parameter Lock Checker Data Input Read/Write destination address information Lock Checker Control Input Lock status confirmation request signal Lock Checker Status Output Lock status confirmation result signal Power PIN Power Power Table 9: Ports and Interfaces Control output is omitted in the table above because the CM does not implement this type of interface. 4 Roles, Services, and Authentication 4.1 Authentication Methods N/A for this module. 4.2 Roles Name Type Operator Type Authentication Methods AdminSP.SID Role CO None AdminSP.Admin1 Role CO None LockingSP.Admin1-4 Role CO None LockingSP.UserX (X=1, ...192) Role CO None Table 10: Roles The CM only supports Crypto Officer Role. The CM is FIPS140-3 Level 1 certification and does not comply with the authentication mechanisms specified in FIPS140-3. However, it does support the authentication function for TCG Role authentication defined by the TCG Opal specification. Each Role is explicitly assumed using the TCG Start Session Method. 4.3 Approved Services Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access Band Lock/Unloc k Lock or unlock read / write of user Mailbo x comm Mailbox comman d / input Mailbox Comman d Result MEKs Generation HMAC LockingSP.Ad min1-4 - KDK: E - MEKs: G,Z 12 Jun 16, 2026 Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access data in a band. and result paramet er Generation/Verifi cation - System MAC Key: E Band Lock/Unloc k for Band of Single User Mode Lock or unlock read / write of user data in band "X" of single user mode Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result MEKs Generation HMAC Generation/Verifi cation LockingSP.Us erX (X=1, ...192) - KDK: E - MEKs: G,Z - System MAC Key: E Check Lock State Check a lock state of band that read / write user data. N/A Lock status confirma tion request signal Lock status confirma tion result signal None Unauthenticat ed Data Read/Write Encryption / Decryption of user data to / from unlocked band of SSD. Reada ble / Writabl e signal from Lock Check er LBA, User Data of ciphertex t / plaintext (read / write) LBA, User Data of plaintext / ciphertex t (read / write) User Data Encryption/Decr yption Unauthenticat ed - MEKs: E Cryptograp hic Erase Erase user data (in cryptograp hic means) by changing the key that derives the data encryption key. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation Key Transport LockingSP.Ad min1-4 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E Cryptograp hic Erase for Band of Single User Mode Erase user data in band "X" of single user mode (in cryptograp hic means) by changing the key that Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation Key Transport LockingSP.Us erX (X=1, ...192) - KDK: G,R,W,E,Z - System MAC Key: E - System Enc Key: E - MEKs: G,Z 13 Jun 16, 2026 Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access derives the data encryption key. Cryptograp hic Erase and Initialize Band State Erase user data in band "X" of single user mode (in cryptograp hic means) by changing the key that derives the data encryption key, and initialize the band state Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation HMAC Generation/Verifi cation Key Transport LockingSP.Ad min1-4 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E LockingSP.Us erX (X=1, ...192) - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E Download Port Lock/Unloc k Lock / unlock firmware download Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result None AdminSP.SID Firmware Verification Digital signature verification for firmware outside the CM Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result FW digital signature verification Unauthenticat ed Firmware Download Download a firmware image Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result FW digital signature verification Hash calculation AdminSP.SID - PubKey1: W,E Random Number Generation Provide a random number generated by the CM. Mailbo x comm and result Mailbox comman d Mailbox Comman d Result Random Number Generation Unauthenticat ed - DRBG Internal Value: E Set Band Position and Size Set the location Mailbo x comm Mailbox comman d / input Mailbox Comman d Result KDK Generation MEKs Generation LockingSP.Ad min1-4 - KDK: 14 Jun 16, 2026 Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access and size of the band and result paramet er HMAC Generation/Verifi cation Key Transport G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E Set Band Position and Size for Band of Single User Mode Set the location and size of the band "X" of single user mode Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation HMAC Generation/Verifi cation Key Transport LockingSP.Ad min1-4 - MEKs: G,Z - KDK: G,R,W,E,Z - System MAC Key: E - System Enc Key: E LockingSP.Us erX (X=1, ...192) - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E Set PIN Set PIN (authentica tion data) Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result Key Transport Hash calculation AdminSP.SID - PINs: W,E - System MAC Key: E - System Enc Key: E AdminSP.Adm in1 - PINs: W,E - System MAC Key: E - System Enc Key: E LockingSP.Ad min1-4 - PINs: W,E - System MAC Key: E - System Enc Key: E LockingSP.Us erX (X=1, ...192) - PINs: W,E 15 Jun 16, 2026 Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access - System MAC Key: E - System Enc Key: E Set PIN for Band of Single User Mode Set PIN (authentica tion data) of authority for band X of single user mode Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result Key Transport Hash calculation LockingSP.Us erX (X=1, ...192) - PINs: W,E - System MAC Key: E - System Enc Key: E Authority Enable/Dis able Enable/Dis able the authority. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result Key Transport AdminSP.SID - System MAC Key: E - System Enc Key: E LockingSP.Ad min1-4 - System MAC Key: E - System Enc Key: E Revert Initialize the band State and disable band lock setting. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation HMAC Generation/Verifi cation Key Transport Hash calculation AdminSP.SID - PINs: R,W,E - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E AdminSP.Adm in1 - PINs: R,W,E - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E LockingSP.Ad min1-4 - PINs: R,W,E - KDK: G,R,W,E,Z - MEKs: G,Z 16 Jun 16, 2026 Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access - System MAC Key: E - System Enc Key: E Data Locking Protection Enable Enable Data protection with band lock setting. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result Key Transport Hash calculation AdminSP.SID - PINs: R,W,E - System MAC Key: E - System Enc Key: E LockingSP.Ad min1-4 - PINs: R,W,E - System MAC Key: E - System Enc Key: E Sanitize Erase all user data (in cryptograp hic means) by changing the key that derives the data encryption key. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation Key Transport AdminSP.SID - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E AdminSP.Adm in1 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E LockingSP.Ad min1-4 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E Format Namespac e Erase user data (in cryptograp hic means) on Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation Key Transport AdminSP.SID - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC 17 Jun 16, 2026 Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access Namespac e by changing the key that derives the data encryption key. Key: E - System Enc Key: E AdminSP.Adm in1 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E LockingSP.Ad min1-4 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E LockingSP.Us erX (X=1, ...192) - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E Namespac e Create/Del ete Create and delete Namespac e. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation Key Transport AdminSP.SID - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E AdminSP.Adm in1 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E LockingSP.Ad 18 Jun 16, 2026 Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access min1-4 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E LockingSP.Us erX (X=1, ...192) - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E Band Set Enable Set the location, size and lock state of the band. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation HMAC Generation/Verifi cation Key Transport LockingSP.Ad min1-4 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E Band Set Disable Initialize the location, size and lock state of the band. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result KDK Generation MEKs Generation HMAC Generation/Verifi cation Key Transport LockingSP.Ad min1-4 - KDK: G,R,W,E,Z - MEKs: G,Z - System MAC Key: E - System Enc Key: E Signature Generation Generate a signature of the data by using a private key entered from outside of the CM. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result Signature Generation Unauthenticat ed - Key Pair Private Key: W,E,Z Signature Verification Verify input signature by using a Mailbo x comm Mailbox comman d / input Mailbox Comman d Result Signature Verification Unauthenticat ed - Key Pair 19 Jun 16, 2026 Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access public key entered from outside of the CM. and result paramet er Public Key: W,E,Z Calculate Hash Digest Hash the data entered from outside of the CM Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result Hash calculation Unauthenticat ed Show Status (Show Version) Report status of the CM and versioning information . Mailbo x comm and result Mailbox comman d Mailbox Comman d Result None Unauthenticat ed Zeroization Zeroize SSPs. Mailbo x comm and result Mailbox comman d / input paramet er Mailbox Comman d Result None Unauthenticat ed - RKey: Z - KDK: Z - MEKs: Z - PINs: Z - System MAC Key: Z - System Enc Key: Z - DRBG Internal Value: Z Reset (Power- OFF) Delete SSPs in SRAM. N/A N/A N/A None Unauthenticat ed - KDK: Z - MEKs: Z - PINs: Z - System MAC Key: Z - System Enc Key: Z - DRBG Internal Value: Z - PubKey1: Z Reset (Power- ON) (Self Test) Runs various self-tests to be N/A N/A N/A MEKs Generation Key Transport FW digital Unauthenticat ed - RKey: E - KDK: W,E 20 Jun 16, 2026 Name Descriptio n Indicat or Inputs Outputs Security Functions SSP Access performed at power- on ( POSTs, CASTs, Firmware Load test ) and generate / import some SSPs. Derive MEKs if the correspond ing band has been unlocked by the appropriat e roles. signature verification Hash calculation Entropy Generation - MEKs: G,Z - PINs: W - System MAC Key: G,E - System Enc Key: G,E - DRBG Internal Value: G - DRBG Seed: G,E,Z - PubKey1: W,E Table 11: Approved Services Need to input PSID, which is public drive-unique value used for the zeroization service. 4.4 Non-Approved Services N/A for this module. 4.5 External Software/Firmware Loaded The CM performs signature verification on Firmware loaded from external memory using RSASSA-PKCS#1-v1_5 (SHA2-384, 3072-bit key).The Firmware is verified at separated memory from the current firmware, and it is loading if the firmware verification is successful. 5 Software/Firmware Security 5.1 Integrity Techniques Firmware Security of components in this CM is shown below. MaskROM Code: ・ Form of the executable code: Binary ・ Integrity verification method: 32bit CRC 21 Jun 16, 2026 Firmware image (User Code): ・ Form of the executable code: Binary ・ Integrity verification method: Approved signature verification (RSASSA-PKCS#1-v1_5) 5.2 Initiate on Demand MaskROM Code, Firmware image (User Code) ・ Initiate on demand integrity verification: Power cycling 6 Operational Environment 6.1 Operational Environment Type and Requirements Type of Operational Environment: Limited How Requirements are Satisfied: Operational Environment requirements are not applicable because the CM does not employ operating systems and operates in a limited operational environment under the FIPS 140-3 definitions. Any firmware/software loaded into this module that is not shown on the module certificate, is out of the scope of this validation and requires a success of firmware load test and a separate FIPS 140-3 validation. 7 Physical Security 7.1 Mechanisms and Actions Required Mechanism Inspection Frequency Inspection Guidance Passivated opaque package Every month or every two months Confirmation that there is no visual damage Table 12: Mechanisms and Actions Required The CM is a sub-chip enclosed in a single chip that is an opaque package. Gathering information of the module’s internal construction or components is impossible without forcing the package to open. In this case, it is confirmed package damage as a tamper-evidence. Operators of the CM can ensure that the physical security is maintained to confirm the package has no obvious attack damage. If the operator discovers tamper evidence, the CM should be removed. Front Back 22 Jun 16, 2026 Figure 2: TC58NC1137GTC 0002 SoC Front Back Figure 3: TC58NC1138GTC 0002 SoC 8 Non-Invasive Security 8.1 Mitigation Techniques The CM does not apply Non-invasive security. 9 Sensitive Security Parameters Management 9.1 Storage Areas Storage Area Name Description Persistence Type S1 OTP: One Time Programmable area Static S2 SRAM: Storage area to store FW components and SSPs as volatile information Dynamic S3 AES Circuit HW Register: Write Only Storage area to store MEKs of unlock band Dynamic S4 DRAM: Outside the cryptographic module Dynamic 23 Jun 16, 2026 Table 13: Storage Areas 9.2 SSP Input-Output Methods Name From To Format Type Distribution Type Entry Type SFI or Algorithm IE1 S2 S4 Encrypted Automated Electronic Key Transport IE2 S4 S2 Encrypted Automated Electronic Key Transport IE3 S4 S2 Plaintext Manual Electronic Table 14: SSP Input-Output Methods 9.3 SSP Zeroization Methods Zeroization Method Description Rationale Operator Initiation Z1 Overwriting S1 with All 1 S1 is overwritten, All 1 key is not allowed. Zeroization Z2-1 Overwriting S2 with All 0 S2 is overwritten, All 0 key is not allowed. Zeroization, Services that allow setting the range length to zero* Z2-2 Overwriting S3 with All 0 S3 is overwritten, All 0 key is not allowed. Zeroization, Services that allow setting the range length to zero; Services that allow locking the corresponding band** Z3-1 Overwriting S2 with random value S2 is overwritten with newly generated random value. Services that update key*** Z3-2 Overwriting S3 with random value S3 is overwritten with newly generated random value. Services that update key Z4 Overwriting immediately after use The CM overwrites SSP with All 0 immediately N/A Z5 Clear the data in volatile memory S2 and S3, S4 are cleared when Power-off Reset(Power-OFF) service Table 15: SSP Zeroization Methods * Services that allow setting the range length to zero: Set Band position and Size, Set Band Position and Size for Band of Single User Mode, Namespace Create/Delete, Band Set Enable and Band Set Disable. ** Services that allow locking the corresponding band: Band Lock/Unlock, Cryptographic Erase and initialize Band State, Revert, and Band Set Enable. *** Services that update key: The following service are applicable, Cryptographic Erase, Cryptographic Erase for Band of Single User Mode, Cryptographic Erase and Initialize Band State, Set Band Position and Size, Revert, Sanitize and Format Namespace. 24 Jun 16, 2026 9.4 SSPs Name Description Size - Streng th Type - Categor y Generat ed By Establish ed By Used By RKey Derivation of System Enc Key and System MAC Key 256 - 256 Symmet ric - CSP Hash DRBG (A6007) KDF SP800-108 (A6026) System Enc Key Data Encryption / Decryption for KTS 256 - 256 Symmet ric - CSP KDF SP800- 108 (A6026) Key Transport System MAC Key Message Authentication Code generation and verification for KTS 256 - 256 Symmet ric - CSP KDF SP800- 108 (A6026) HMAC Generation/Verific ation Key Transport KDK Derivation of MEKs 256 - 256 Symmet ric - CSP KDK Generati on Key Transport MEKs Generation MEKs Data encryption/decry ption 512 - 256 Symmet ric - CSP MEKs Generati on User Data Encryption/Decryp tion PINs User authentication PIN 256 - 128 PIN - CSP Key Transport Hash calculation Key Pair Private Key Imported Private Key for ECDSA 384 - 192 Private - CSP Signature Generation DRBG Internal Value DRBG state(V: 440 bits, C: 440 bits) 880 - 256 DRBG Internal State - CSP Hash DRBG (A6007) Random Number Generation DRBG Seed DRBG seed 1024 - 256 Seed - CSP Entropy Generati on Hash DRBG (A6007) PubKe y1 Signature verification key for RSA 3072 - 128 Public - PSP FW digital signature verification Key Pair Public Key Imported Public key for ECDSA 384 - 192 Public - PSP Signature Verification Table 16: SSP Table 1 25 Jun 16, 2026 Name Input - Output Storage Storage Duration Zeroization Related SSPs RKey S1:Plaintext Until zeroization Z1 System Enc Key:Derives System MAC Key:Derives System Enc Key S2:Plaintext Until Power-Off Z2-1 Z5 RKey:Derived From KDK:Wraps PINs:Wraps System MAC Key S2:Plaintext Until Power-Off Z2-1 Z5 RKey:Derived From KDK IE1 IE2 S2:Plaintext While the band exist, Until Power- Off Z2-1 Z2-2 Z3-1 Z5 System Enc Key:wrapped by MEKs:Derives MEKs S3:Plaintext While the band is unlocked, Until Power-Off Z2-2 Z3-2 Z5 KDK:Derived From PINs IE1 IE2 IE3 S2:Obfuscated Until Power-Off Z2-1 Z4 Z5 System Enc Key:wrapped by Key Pair Private Key IE3 S2:Plaintext While in use Z4 DRBG Internal Value S2:Plaintext Until Power-Off Z2-1 Z5 DRBG Seed S2:Plaintext While in use Z4 PubKey1 IE3 S2:Plaintext S1:Obfuscated Until Power-Off Z2-1 Z5 Key Pair Public Key IE3 S2:Plaintext While in use Z4 Table 17: SSP Table 2 PINs are stored in S2, and PubKey1 is stored in S1 as hashed value. “Obfuscated” in “Storage” column of these SSPs means hashed value. 10 Self-Tests 10.1 Pre-Operational Self-Tests Algorithm or Test Test Properties Test Method Test Type Indicator Details Firmware integrity test integrity 32 bit CRC SW/FW Integrity Implicit error reporting by stopping the startup sequence Verify MaskROM code integrity with 32bit CRC 26 Jun 16, 2026 Table 18: Pre-Operational Self-Tests Firmware load test is also run at the time of Power-up, and the integrity of the Firmware loaded into the CM can be confirmed. 10.2 Conditional Self-Tests Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions AES-CBC (A5952) Key Size: 256 bits KAT CAST 0x01 or 0x24 Encrypt, Decrypt Power-on AES-XTS Testing Revision 2.0 (A5952) Key Size: 256 bits KAT CAST 0x01 or 0x23 Encrypt, Decrypt Power-on SHA2-256 (A5952) Digest Size : 256 bits KAT CAST 0x01 or 0x25 Digest Power-on SHA2-384 (A5952) Digest Size : 384 bits KAT CAST 0x01 or 0x25 Digest Power-on HMAC-SHA2- 256 (A5952) Key Size: 256 bits KAT CAST 0x01 or 0x26 Digest Power-on Hash DRBG (A6007) Hash based: SHA2-256 KAT CAST 0x01 or 0x18/0x19 DRBG Power-on RSA SigVer (FIPS186-5) (A5952) Key Size: 2048 and 3072 bits KAT CAST 0x01 or 0x27 Signature Verification Power-on ECDSA SigGen (FIPS186-5) (A6045) Curve: P- 384 KAT CAST 0x01 or 0x36 Signature Generation Before first use ECDSA SigVer (FIPS186-5) (A6045) Curve: P- 384 KAT CAST 0x01 or 0x36 Signature Verification Before first use KDF SP800- 108 (A6026) HMAC- SHA2-256 KAT CAST 0x01 or 0x28 KDF Power-on Entropy Source (Health tests of noise source at startup) Cut off RCT: 60, APT: 744 RCT, APT CAST 0x01 or 0x2C/2D Entropy Generation Power-on Entropy Source (Continuous noise source health tests during operation) Cut off RCT: 60, APT: 744 RCT, APT CAST 0x01 or 0x2C/2D Entropy Generation Entropy output request 27 Jun 16, 2026 Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions Firmware load test at Power on hash type: SHA2-384; key length: 3072 bit sigVer SW/FW Load 0x01 or 0x13 Verify signature of loaded firmware image Power on Firmware load test at FW download hash type: SHA2-384; key length: 3072 bit sigVer SW/FW Load 0x01 or 0x13 Verify signature of downloaded firmware image FW download Table 19: Conditional Self-Tests If the Conditional Self-Tests are successful, the CM will return 0x01 as an indicator; if they fail, it will return Error Code in Table22. 10.3 Periodic Self-Test Information Algorithm or Test Test Method Test Type Period Periodic Method Firmware integrity test 32 bit CRC SW/FW Integrity On Demand Power cycling Table 20: Pre-Operational Periodic Information Algorithm or Test Test Method Test Type Period Periodic Method AES-CBC (A5952) KAT CAST On Demand Power cycling AES-XTS Testing Revision 2.0 (A5952) KAT CAST On Demand Power cycling SHA2-256 (A5952) KAT CAST On Demand Power cycling SHA2-384 (A5952) KAT CAST On Demand Power cycling HMAC-SHA2- 256 (A5952) KAT CAST On Demand Power cycling Hash DRBG (A6007) KAT CAST On Demand Power cycling RSA SigVer (FIPS186-5) (A5952) KAT CAST On Demand Power cycling ECDSA SigGen (FIPS186-5) (A6045) KAT CAST On Demand First provided service after power cycling ECDSA SigVer (FIPS186-5) (A6045) KAT CAST On Demand First provided service after power cycling 28 Jun 16, 2026 Algorithm or Test Test Method Test Type Period Periodic Method KDF SP800-108 (A6026) KAT CAST On Demand Power cycling Entropy Source (Health tests of noise source at startup) RCT, APT CAST On Demand Power cycling Entropy Source (Continuous noise source health tests during operation) RCT, APT CAST On Demand Provided service with generating entropy Firmware load test at Power on sigVer SW/FW Load On Demand Power cycling Firmware load test at FW download sigVer SW/FW Load On Demand Provided service Table 21: Conditional Periodic Information 10.4 Error States Name Description Conditions Recovery Method Indicator Boot Error State The CM has failed Pre-operational self- test and cryptographic algorithm test excluded ECDSA Pre-operational self- test and cryptographic algorithm test excluded ECDSA Failure Power-off Indicated Error Code: 0x23 0x24, 0x25, 0x26, 0x18, 0x19, 0x27, 0x28, 0x2C, 0x2D and/or no response Error State The CM has failed ECDSA algorithm test and continuous noise source health tests ECDSA algorithm test and continuous noise source health tests Failure Power-off Indicated Error Code: 0x2C, 0x 2D, 0x36 and/or no response Power Up Load Test Error State The CM has failed FW Load at power up FW Load at power up Failure Power-off Indicated Error Code: 0x13 and/or no response Conditional Load Test Error State The CM has failed FW update FW update Failure N/A Indicated Error Code: 0x13 Table 22: Error States If the self-tests fail, the CM reports error status and enters to the error state. In this case, the CM must be powered-off to clear error condition (i.e. Recovery Method). When power-on is executed again, self-tests are also executed like an on-demand operator reset. If the CM continuously enters in error state in spite of several trials of reboot, the CM may be sent back to factory to recover from error state. When the CM is in an error state except for Conditional Load 29 Jun 16, 2026 Test Error State, cryptographic functions cannot be executed by the CM. If the CM enters Conditional Load Test Error State, it reports Error code and transitions from error state to normal state, and continues to operate with FW before download. 10.5 Operator Initiation of Self-Tests Operator can also initiate self-test on-demand for periodic testing by using the Reset service which is automatically invoked when the module is powered-off and powered-on (rebooted). 11 Life-Cycle Assurance 11.1 Installation, Initialization, and Startup Procedures In the SSD’s manufacturing process, installation is executed as below: 1. The Firmware described in Section 2.2 is downloaded into the CM. 2. Initial SSPs are generated. 3. Initial authentication information is set to the CM. 4. System area including SSPs generated in Step2 and Step3 are encrypted and calculated message authentication code. Once installation is successfully completed, the CM is always in the Compliant state indicated by the bits [22:20] and bit [9] of mailbox status being set to 1 as a response for “Show Status (Show Version)” service. Initial operations to setup this CM are following:  Load Firmware into the CM.  Load system area including SSPs into the CM.  Execute range state setting method (Set the location and size of all range).  Execute download port setting method (Lock / unlock firmware download).  Execute namespace setting method (Create Namespace).  Execute service execution state setting method (Enable CM settings (location and size of all range, lock/unlock firmware download, namespace status)). The CM switches to approved mode after the initial operation success. When the initial operation succeeds, the CM indicates success on the Status Output interface. Operators can confirm that the CM is in approved mode by executing Show Status (Show Version) service and checking that the startup is successfully completed. Some additional information for SSD’s manufacturing process and initial operation to setup is described in ‘XD8 configuration guide at manufacturing’. 11.2 Administrator Guidance After the procedure written in section 11.1, the CM can be used as an approved mode. Users can confirm that the CM is in approved mode by executing Show Status (Show Version) service and checking that the startup is successfully completed. Guidance for this module is provided to solid state drive developers who embed the CM. The usage and maintenance of solid state drives with the CM built-in are outside of the scope of this document. 30 Jun 16, 2026 11.3 Non-Administrator Guidance The module implements only the Crypto Officer. There are no guidances for non-administrators. 11.4 Design and Rules N/A for this module. 11.5 Maintenance Requirements As described in Section 2, the CM is used by being embedded in the solid state drive. Therefore, there are no maintenance requirements for the CM alone. 11.6 End of Life The user needs to erase CPSs by executing Revert service for secure sanitization. 12 Mitigation of Other Attacks 12.1 Attack List The CM implements mitigation for no authorized user execution of service. 12.2 Mitigation Effectiveness The CM implements authentication function defined by the TCG Opal specification by verifying whether the PIN entered by the user matches the information stored inside the CM. PINs are hashed with SHA2-256 to store them on the CM. The PIN entered by the user is hashed and compared to the stored PIN hash.