Ultrastar DC HC560 TCG Enterprise HDD SED, Ultrastar DC HC570 TCG Enterprise HDD SED

Certificate #4802

Webpage information ?

Status active
Validation dates 16.09.2024
Sunset date 15-09-2026
Standard FIPS 140-3
Security level 2
Type Hardware
Embodiment Multi-Chip Embedded
Caveat Interim validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service
Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
  • Documentation requirements: N/A
  • Cryptographic module security policy: N/A
Description The Western Digital Ultrastar DC HC560 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC560, Cryptographic Module, cryptographic module, or CM, and the Western Digital Ultrastar DC HC570 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC570, Cryptographic Module, cryptographic module, or CM are self-encryption drives (SED) that comply in general with the specifications listed in 13.2 Trusted Computing Group Specifications and specifically with the TCG Storage Architecture Core Specification [TCG Core] with the Trusted Computing Group (TCG) Security Subsystem Class (SSC): Enterprise Specification [TCG Enterprise]. The TCG SSC Enterprise Specification defines a management interface for host application software to activate, provision, and manage encryption of user data. The specification includes data structures and their required content, and mechanisms for managing and configuring Authentication Credentials and access controls. The security architecture provides a locking mechanism by which an Authentication Credential (i.e., a password) can be set by an operator to enable control of access to user data. After an operator authenticates to the appropriate role and locks access to user data access user data is inaccessible. This implementation complies with the lock-based authentication model specified in IG 4.1.A.
Version (Hardware) 0F38603, 0F38653, 0F48003, 0F48053
Version (Firmware) RY07, R5G4, RG01, VM18, R7J4
Vendor Western Digital Technologies, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy ?

Symmetric Algorithms
AES, AES-256, CAST, HMAC
Asymmetric Algorithms
RSA 3072, RSA-3072
Hash functions
SHA-1, SHA-256, SHA2, PBKDF2
Schemes
MAC, Key Agreement
Randomness
DRBG, RBG
Block cipher modes
ECB, CBC, CTR, XTS

Trusted Execution Environments
PSP, SSC

Security level
Level 2, Level 1, Level 0
Side-channel analysis
malfunction, fault induction

Standards
FIPS 140-3, FIPS PUB 140-3, FIPS2, FIPS 197, FIPS 198, FIPS 186, FIPS 180, FIPS 140, FIPS PUB 197, FIPS PUB 186-5, FIPS PUB 198-1, FIPS PUB 180-4, FIPS140, NIST SP 800-140C, SP 800-140D, NIST SP 800-131A, SP 800-132, SP 800-90A, SP 800-90B, SP 800-38F, RFC 2119, ISO/IEC 24759, ISO/IEC19790, ISO/IEC 19790

File metadata

Author [email protected]
Creation date D:20240712084740-07'00'
Modification date D:20240712085140-07'00'
Pages 71
Creator Acrobat PDFMaker 24 for Word
Producer Adobe PDF Library 24.2.159

Heuristics ?

No heuristics are available for this certificate.

References ?

No references are available for this certificate.

Updates ?

  • 14.10.2024 The certificate data changed.
    Certificate changed

    The web extraction data was updated.

    • The certificate_pdf_url property was set to https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/September 2024_011024_0217.pdf.
  • 01.10.2024 The certificate was first processed.
    New certificate

    A new FIPS 140 certificate with the product name was processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4802,
  "dgst": "d19828eb64fa5dea",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "AES-ECBAES 3580",
        "HMAC-SHA-1HMAC 2280",
        "HMAC-SHA2-224HMAC 2280",
        "RSA SigVer (FIPS186-4)A2099",
        "SHA-1SHS 2942",
        "Counter DRBGA2098",
        "AES-XTSAES 3580",
        "AES-CBCAES 3580",
        "SHA2-224SHS 2942",
        "PBKDFA2100",
        "SHA2-256SHS 2942",
        "HMAC-SHA2-256HMAC 2280",
        "AES-KWPA2098"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "RSA": {
          "RSA 3072": 8,
          "RSA-3072": 2
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 7
        },
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 7
        },
        "XTS": {
          "XTS": 15
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1
        },
        "MAC": {
          "MAC": 4
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1,
          "#13": 1,
          "#2": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "# A2098": 2,
          "# A2099": 1,
          "AES 256": 1,
          "AES 3580": 1,
          "AES-256": 5,
          "AES-256 256": 1,
          "AES-256 5120": 1,
          "Cert #AES": 21,
          "Cert #HMAC": 25,
          "Cert #SHS": 9,
          "HMAC 2280": 2,
          "HMAC SHA-256": 1,
          "RSA 3072": 8,
          "SHA-1": 2,
          "SHA-256": 2,
          "SHA2 - 224": 1,
          "SHA2- 256": 1,
          "SHA2-224": 1,
          "SHA2-256": 23,
          "SHS 2942": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 0": 5,
          "Level 1": 1,
          "Level 2": 5
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF2": 16
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 2
          },
          "SHA2": {
            "SHA-256": 2,
            "SHA2": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 74
        },
        "RNG": {
          "RBG": 11
        }
      },
      "side_channel_analysis": {
        "FI": {
          "fault induction": 1,
          "malfunction": 1
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140": 18,
          "FIPS 140-3": 90,
          "FIPS 180": 3,
          "FIPS 186": 3,
          "FIPS 197": 6,
          "FIPS 198": 2,
          "FIPS PUB 140-3": 2,
          "FIPS PUB 180-4": 1,
          "FIPS PUB 186-5": 1,
          "FIPS PUB 197": 1,
          "FIPS PUB 198-1": 1,
          "FIPS140": 1,
          "FIPS2": 1
        },
        "ISO": {
          "ISO/IEC 19790": 4,
          "ISO/IEC 24759": 8,
          "ISO/IEC19790": 2
        },
        "NIST": {
          "NIST SP 800-131A": 2,
          "NIST SP 800-140C": 1,
          "SP 800-132": 1,
          "SP 800-140D": 1,
          "SP 800-38F": 2,
          "SP 800-90A": 2,
          "SP 800-90B": 2
        },
        "RFC": {
          "RFC 2119": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 27,
            "AES-256": 7
          },
          "CAST": {
            "CAST": 17
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 5
        },
        "IBM": {
          "SSC": 3
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "[email protected]",
      "/Comments": "",
      "/Company": "Microsoft",
      "/ContentTypeId": "0x01010088D736DC06BD7B46BF1F61B9E63EEB42",
      "/CreationDate": "D:20240712084740-07\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 24 for Word",
      "/Keywords": "",
      "/ModDate": "D:20240712085140-07\u002700\u0027",
      "/Producer": "Adobe PDF Library 24.2.159",
      "/SourceModified": "D:20240712154701",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 1450541,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://www.pleacher.com/mp/mlessons/algebra/entropy.html",
          "https://csrc.nist.gov/projects/cryptographic-module-validation-program/entropy-validations/certificate/13",
          "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/entropy/E13_PublicUse.pdf",
          "https://www.westerndigital.com/support"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 71
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_garbage": false,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_pdf_hash": "9964d708afe623c2907ed0636337b468f017a27dff0608e3fe39bb5edb3dad9f",
    "policy_txt_hash": "e2b3ef3dd7b3fc7952bb863efb194e7c049c2a8bfb57089ee959d2561f5a567f"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/September 2024_011024_0217.pdf",
    "date_sunset": "2026-09-15",
    "description": "The Western Digital Ultrastar DC HC560 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC560, Cryptographic Module, cryptographic module, or CM, and the Western Digital Ultrastar DC HC570 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC570, Cryptographic Module, cryptographic module, or CM are self-encryption drives (SED) that comply in general with the specifications listed in 13.2 Trusted Computing Group Specifications and specifically with the TCG Storage Architecture Core Specification [TCG Core] with the Trusted Computing Group (TCG) Security Subsystem Class (SSC): Enterprise Specification [TCG Enterprise]. The TCG SSC Enterprise Specification defines a management interface for host application software to activate, provision, and manage encryption of user data. The specification includes data structures and their required content, and mechanisms for managing and configuring Authentication Credentials and access controls. The security architecture provides a locking mechanism by which an Authentication Credential (i.e., a password) can be set by an operator to enable control of access to user data. After an operator authenticates to the appropriate role and locks access to user data access user data is inaccessible. This implementation complies with the lock-based authentication model specified in IG 4.1.A.",
    "embodiment": "Multi-Chip Embedded",
    "exceptions": [
      "Operational environment: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A",
      "Documentation requirements: N/A",
      "Cryptographic module security policy: N/A"
    ],
    "fw_versions": "RY07, R5G4, RG01, VM18, R7J4",
    "historical_reason": null,
    "hw_versions": "0F38603, 0F38653, 0F48003, 0F48053",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Ultrastar DC HC560 TCG Enterprise HDD SED, Ultrastar DC HC570 TCG Enterprise HDD SED",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-09-16",
        "lab": "UL VERIFICATION SERVICES INC",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Western Digital Technologies, Inc.",
    "vendor_url": "http://www.westerndigital.com"
  }
}