Hitachi Storage Hybrid Firmware Encryption Module

Certificate details

Certificate ID #5013
Status active
Validation dates 29.04.2025
Sunset date 28-04-2030
Standard FIPS 140-3
Security level 1
Type Firmware-Hybrid
Embodiment Multi-Chip Embedded
Caveat No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description Hitachi Storage Hybrid Firmware Encryption Module provides data at rest encryption for Hitachi storage.
Vendor Hitachi Vantara, Ltd. https://www.hitachivantara.com/ja-jp
Lab ECSEC Laboratory Inc.
Algorithms
  • AES-ECBA5044
  • AES-KWA5023
  • AES-XTS Testing Revision 2.0A5053
  • SHA2-256A5024
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, CAST
Randomness
RBG
Block cipher modes
ECB, XTS

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5013,
  "dgst": "9e3816a4198e3722",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "#A5047",
        "SHA2-256A5024",
        "#A5041",
        "#A5048",
        "AES-XTS Testing Revision 2.0A5053",
        "#A5049",
        "#A5033",
        "#A5042",
        "AES-ECBA5044",
        "AES-KWA5023",
        "#A5046",
        "#A5051",
        "#A5031",
        "#A5050",
        "#A5028",
        "#A5027",
        "#A5043",
        "#A5053",
        "#A5029",
        "#A5039",
        "#A5024",
        "#A5023",
        "#A5025",
        "#A5030",
        "#A5052",
        "#A5026",
        "#A5032",
        "#A5036",
        "#A5037",
        "#A5034",
        "#A5040",
        "#A5035",
        "#A5038",
        "#A5044"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5023",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5025",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5026",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5027",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5028",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5029",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5030",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5031",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5033",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5034",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5035",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5036",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5037",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5038",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5039",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5040",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5041",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5042",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5043",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5044",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A5023",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5046",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5047",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5048",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5049",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5050",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5051",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5052",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5053",
            "properties": "Direction - Decrypt, Encrypt Key Length - 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A5024",
            "properties": "Message Length - Message Length: 8-65536 Increment 8",
            "reference": "FIPS 180-4"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Expand AES key to round keys.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "DEK",
            "name": "Expand AES Key",
            "outputs": "Round Key",
            "rolesSspAccess": "Cryptographic Officer - DEK: W,E - Round Key: G,R",
            "secFunImpl": "AES-ECB Core 4 AES-ECB Core 16 AES-XTS Core 512 AES-XTS Core 520"
          },
          {
            "description": "Encrypt data using XTS-AES in units of 512 byte.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to encrypt, Round Key",
            "name": "Encrypt (512B)",
            "outputs": "Encrypted data",
            "rolesSspAccess": "Cryptographic Officer - Round Key: W,E",
            "secFunImpl": "AES-XTS Core 512"
          },
          {
            "description": "Decrypt data using XTS-AES in units of 512 byte.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to decrypt, Round Key",
            "name": "Decrypt (512B)",
            "outputs": "Decrypted data",
            "rolesSspAccess": "Cryptographic Officer - Round Key: W,E",
            "secFunImpl": "AES-XTS Core 512"
          },
          {
            "description": "Encrypt data using XTS-AES in units of 520 byte.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to encrypt, Round Key",
            "name": "Encrypt (520B)",
            "outputs": "Encrypted data",
            "rolesSspAccess": "Cryptographic Officer - Round Key: W,E",
            "secFunImpl": "AES-XTS Core 520"
          },
          {
            "description": "Decrypt data using XTS-AES in units of 520 byte.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to decrypt, Round Key",
            "name": "Decrypt (520B)",
            "outputs": "Decrypted data",
            "rolesSspAccess": "Cryptographic Officer - Round Key: W,E",
            "secFunImpl": "AES-XTS Core 520"
          },
          {
            "description": "Encrypt 16 byte data using AES-ECB.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to encrypt, KEK",
            "name": "Encrypt (ECB 16B)",
            "outputs": "Encrypted data",
            "rolesSspAccess": "Cryptographic Officer - KEK: W,E",
            "secFunImpl": "AES-ECB Core"
          },
          {
            "description": "Decrypt 16 byte data using AES-ECB.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to decrypt, KEK",
            "name": "Decrypt (ECB 16B)",
            "outputs": "Decrypted data",
            "rolesSspAccess": "Cryptographic Officer - KEK: W,E",
            "secFunImpl": "AES-ECB Core"
          },
          {
            "description": "Encrypt 64 byte data using AES-ECB.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to encrypt, DEK",
            "name": "Encrypt (ECB 64B)",
            "outputs": "Encrypted data",
            "rolesSspAccess": "Cryptographic Officer - DEK: W,E",
            "secFunImpl": "AES-ECB Core 4"
          },
          {
            "description": "Decrypt 64 byte data using AES-ECB.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to decrypt, DEK",
            "name": "Decrypt (ECB 64B)",
            "outputs": "Decrypted data",
            "rolesSspAccess": "Cryptographic Officer - DEK: W,E",
            "secFunImpl": "AES-ECB Core 4"
          },
          {
            "description": "Encrypt 256 byte data using AES-ECB.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to encrypt, DEK",
            "name": "Encrypt (ECB 256B)",
            "outputs": "Encrypted data",
            "rolesSspAccess": "Cryptographic Officer - DEK: W,E",
            "secFunImpl": "AES-ECB Core 16"
          },
          {
            "description": "Decrypt 256 byte data using AES-ECB.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to decrypt, DEK",
            "name": "Decrypt (ECB 256B)",
            "outputs": "Decrypted data",
            "rolesSspAccess": "Cryptographic Officer - DEK: W,E",
            "secFunImpl": "AES-ECB Core 16"
          },
          {
            "description": "Wrap a key using a KEK.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Key, KEK",
            "name": "Wrap Key",
            "outputs": "Wrapped key",
            "rolesSspAccess": "Cryptographic Officer - KEK: W,E",
            "secFunImpl": "AES-KW Core"
          },
          {
            "description": "Unwrap a key using a KEK.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Wrapped key, KEK",
            "name": "Unwrap Key",
            "outputs": "Unwrapped key",
            "rolesSspAccess": "Cryptographic Officer - KEK: W,E",
            "secFunImpl": "AES-KW Core"
          },
          {
            "description": "Generate hash value from inputted data.",
            "indicator": "API return value: 0 (Success)",
            "inputs": "Data to hash",
            "name": "Generate Hash",
            "outputs": "Hash Value",
            "rolesSspAccess": "Cryptographic Officer",
            "secFunImpl": "Secure Hash"
          },
          {
            "description": "Startup the module.",
            "indicator": "None",
            "inputs": "None",
            "name": "Initialize",
            "outputs": "None",
            "rolesSspAccess": "Cryptographic Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Show module ID, version, and status.",
            "indicator": "None",
            "inputs": "None",
            "name": "Show Status",
            "outputs": "Module ID, module version, module status",
            "rolesSspAccess": "Cryptographic Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Enable CSPs output in plaintext.",
            "indicator": "None",
            "inputs": "None",
            "name": "Enable CSP Output",
            "outputs": "None",
            "rolesSspAccess": "Cryptographic Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Disable CSPs output in plaintext.",
            "indicator": "None",
            "inputs": "None",
            "name": "Disable CSP Output",
            "outputs": "None",
            "rolesSspAccess": "Cryptographic Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Change the module state to Error state.",
            "indicator": "None",
            "inputs": "None",
            "name": "Forcibly Stop",
            "outputs": "None",
            "rolesSspAccess": "Cryptographic Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Reset the module.",
            "indicator": "None",
            "inputs": "None",
            "name": "Reset",
            "outputs": "None",
            "rolesSspAccess": "Cryptographic Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Cycle the power of the operational environment.",
            "indicator": "None",
            "inputs": "None",
            "name": "Zeroise",
            "outputs": "None",
            "rolesSspAccess": "Cryptographic Officer - DEK: Z - Round Key: Z - KEK: Z",
            "secFunImpl": "None"
          },
          {
            "description": "Initiate the integrity test on demand by power cycle of the operational environment.",
            "indicator": "None",
            "inputs": "None",
            "name": "On- demand integrity test",
            "outputs": "None",
            "rolesSspAccess": "Cryptographic Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Initiate the self-tests on demand by power cycle of the operational environment or performing the Reset service, and performing the Initialize service.",
            "indicator": "None",
            "inputs": "None",
            "name": "On demand self test",
            "outputs": "None",
            "rolesSspAccess": "Cryptographic Officer",
            "secFunImpl": "None"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-XTS (512B)",
            "condition": "From the module startup to integrity testing",
            "details": "Encrypt",
            "indicator": "None",
            "testMethod": "KAT",
            "testProps": "Key sizes: 256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS (512B)",
            "condition": "From the module startup to integrity testing",
            "details": "Decrypt",
            "indicator": "None",
            "testMethod": "KAT",
            "testProps": "Key sizes: 256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS (520B)",
            "condition": "From the module startup to integrity testing",
            "details": "Encrypt",
            "indicator": "None",
            "testMethod": "KAT",
            "testProps": "Key sizes: 256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS (520B)",
            "condition": "From the module startup to integrity testing",
            "details": "Decrypt",
            "indicator": "None",
            "testMethod": "KAT",
            "testProps": "Key sizes: 256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-KW (A5023)",
            "condition": "From the module startup to integrity testing",
            "details": "Wrap",
            "indicator": "None",
            "testMethod": "KAT",
            "testProps": "Key sizes: 256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-KW (A5023)",
            "condition": "From the module startup to integrity testing",
            "details": "Unwrap",
            "indicator": "None",
            "testMethod": "KAT",
            "testProps": "Key sizes: 256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-256 (A5024)",
            "condition": "From the module startup to integrity testing",
            "details": "Hash",
            "indicator": "None",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "Failed the Pre- operational self-tests. Failed the Cryptographic algorithm self-tests.",
            "description": "A state when the module has encountered an error condition.",
            "indicator": "Error response to Show Status service.",
            "name": "Error",
            "recoveryMethod": "Power cycling of the operational environment."
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "Data to be read from the memory area specified in the API parameters",
            "logicalInterface": "Data Input",
            "physicalPort": "N/A"
          },
          {
            "data": "Data to be written to the memory area specified in the API parameters",
            "logicalInterface": "Data Output",
            "physicalPort": "N/A"
          },
          {
            "data": "API function calls",
            "logicalInterface": "Control Input",
            "physicalPort": "N/A"
          },
          {
            "data": "Responses of the invoked API function",
            "logicalInterface": "Status Output",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Cryptographic Officer",
            "operatorType": "CO",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "1",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "SHA2-256 (A5024)",
            "details": "Hash",
            "indicator": "None",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Memory area for the module",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API Input",
            "sfiAlgo": "",
            "source": "Memory area specified in the API parameters"
          },
          {
            "dest": "Memory area specified in the API parameters",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API Output",
            "sfiAlgo": "",
            "source": "Memory area for the module"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Power cycle of the operational environment",
            "method": "Power cycle",
            "operatorId": "Yes",
            "rationale": "All SSPs of the module are zeroised by Power cycle because all SSPs are on a volatile memory."
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "A volatile memory on the operational environment",
            "name": "Memory",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [
          {
            "features": "",
            "fwVersion": "N/A",
            "hwVersion": "Intel\u00ae Xeon\u00ae Silver 4410Y",
            "modelPartNum": "Intel\u00ae Xeon\u00ae Silver 4410Y",
            "processors": "Intel\u00ae Xeon\u00ae Silver 4410Y"
          },
          {
            "features": "",
            "fwVersion": "N/A",
            "hwVersion": "Intel\u00ae Xeon\u00ae Gold 6421N",
            "modelPartNum": "Intel\u00ae Xeon\u00ae Gold 6421N",
            "processors": "Intel\u00ae Xeon\u00ae Gold 6421N"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "",
            "integrityTest": "SHA2-256",
            "packageFileName": "Storage_Encryption_Module_20 A0-01-00-00",
            "swFwVersion": "Storage_Encryption_Module_20 A0-01-00-00"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {},
      "certification_process": {},
      "cipher_mode": {
        "ECB": {
          "ECB": 12
        },
        "XTS": {
          "XTS": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "SHA2-256": 13
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 4
        }
      },
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 3,
          "FIPS 180-4": 1,
          "FIPS 197": 1
        },
        "NIST": {
          "SP 800-38A": 21,
          "SP 800-38E": 8,
          "SP 800-38F": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 14
          },
          "CAST": {
            "CAST": 15
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256A5024",
        "AES-ECBA5044",
        "AES-KWA5023",
        "AES-XTS Testing Revision 2.0A5053"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A5047",
        "#A5041",
        "#A5048",
        "#A5049",
        "#A5033",
        "#A5042",
        "#A5046",
        "#A5051",
        "#A5031",
        "#A5050",
        "#A5028",
        "#A5027",
        "#A5043",
        "#A5053",
        "#A5029",
        "#A5039",
        "#A5024",
        "#A5023",
        "#A5025",
        "#A5030",
        "#A5052",
        "#A5026",
        "#A5032",
        "#A5036",
        "#A5037",
        "#A5034",
        "#A5040",
        "#A5035",
        "#A5038",
        "#A5044"
      ]
    },
    "policy_metadata": {
      "/Author": "",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20250428084508-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/ModDate": "D:20250428084529-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.208",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 282938,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 18
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "2e55d74540ec6b0e102fc733dc32510d8d7cc333e848e161f1994268f4f0c87c",
      "source_hash": "1eb925e6c91130205a535b48b5d896c5abfc1fb147048e5329c559c2f653eb4e",
      "txt_hash": "7a8324aff9b3073ee05ccf392f376d32d2698bcbea968793e46ce9e20ed9a61d"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/April 2025_010525_0659.pdf",
    "date_sunset": "2030-04-28",
    "description": "Hitachi Storage Hybrid Firmware Encryption Module provides data at rest encryption for Hitachi storage.",
    "embodiment": "Multi-Chip Embedded",
    "exceptions": [
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Hitachi Storage Hybrid Firmware Encryption Module",
    "module_type": "Firmware-Hybrid",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-04-29",
        "lab": "ECSEC Laboratory Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Hitachi Vantara, Ltd.",
    "vendor_url": "https://www.hitachivantara.com/ja-jp"
  }
}