FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 1 of 87 Western Digital Technologies, Inc. Ultrastar DC HC555 TCG Enterprise HDD SED FIPS 140-3 Non-Proprietary Security Policy Document Version: 1.1 Date: April 15, 2026 Protection of Data at Rest FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 2 of 87 Table of Contents 1 General ........................................................................................................................................................................6 1.1 Overview ...................................................................................................................................................................6 1.2 Security Levels..........................................................................................................................................................6 2 Cryptographic Module Specification ......................................................................................................................6 2.1 Description................................................................................................................................................................6 2.2 Tested and Vendor Affirmed Module Version and Identification ..................................................................9 2.3 Excluded Components............................................................................................................................................9 2.4 Modes of Operation ..............................................................................................................................................11 2.5 Algorithms...............................................................................................................................................................11 2.6 Security Function Implementations....................................................................................................................13 2.7 Algorithm Specific Information...........................................................................................................................15 2.8 RBG and Entropy..................................................................................................................................................15 2.9 Key Generation ......................................................................................................................................................16 2.10 Key Establishment.................................................................................................................................................17 2.11 Industry Protocols..................................................................................................................................................17 3 Cryptographic Module Interfaces..........................................................................................................................17 3.1 Ports and Interfaces...............................................................................................................................................17 4 Roles, Services, and Authentication......................................................................................................................18 4.1 Authentication Methods .......................................................................................................................................18 4.2 Roles.........................................................................................................................................................................18 4.3 Approved Services .................................................................................................................................................19 4.4 Non-Approved Services........................................................................................................................................48 4.5 External Software/Firmware Loaded.................................................................................................................48 5 Software/Firmware Security ..................................................................................................................................48 5.1 Integrity Techniques..............................................................................................................................................48 5.2 Initiate on Demand................................................................................................................................................49 5.3 Open-Source Parameters......................................................................................................................................49 6 Operational environment........................................................................................................................................49 6.1 Operational Environment Type and Requirements.........................................................................................49 6.2 Configuration Settings and Restrictions.............................................................................................................49 7 Physical Security.......................................................................................................................................................50 7.1 Mechanisms and Actions Required.....................................................................................................................50 8 Non-invasive Security..............................................................................................................................................51 8.1 Mitigation Techniques...........................................................................................................................................51 9 Sensitive Security Parameters Management.........................................................................................................52 9.1 Storage Areas ..........................................................................................................................................................52 9.2 SSP Input and Output Methods..........................................................................................................................52 9.3 SSP Zeroization Methods.....................................................................................................................................53 9.4 SSPs..........................................................................................................................................................................54 10 Self-Tests...................................................................................................................................................................74 10.1 Pre-Operational Self-Tests....................................................................................................................................74 10.2 Conditional Self-Tests...........................................................................................................................................75 10.3 Periodic Self-Test Information ............................................................................................................................76 FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 3 of 87 10.4 Error States .............................................................................................................................................................78 10.5 Operator Initiated Self-Tests................................................................................................................................78 11 Life-Cycle Assurance...............................................................................................................................................78 11.1 Installation, Initialization and Startup Procedures............................................................................................78 11.2 Administrator Guidance........................................................................................................................................79 11.3 Non-Administrator Guidance..............................................................................................................................79 11.4 Design and Rules....................................................................................................................................................80 11.5 Maintenance Requirements ..................................................................................................................................80 11.6 End of Life..............................................................................................................................................................81 12 Mitigation of Other Attacks...................................................................................................................................81 13 References and Definitions ....................................................................................................................................81 13.1 NIST Specifications...............................................................................................................................................81 13.2 Trusted Computing Group Specifications.........................................................................................................82 13.3 SCSI Specifications ................................................................................................................................................82 13.4 Corporate References............................................................................................................................................82 13.5 Other References....................................................................................................................................................82 14 Definitions.................................................................................................................................................................82 15 Acronyms ..................................................................................................................................................................85 Tables Table 1: Security Levels......................................................................................................................................................6 Table 2: Tested Module Identification – Hardware.......................................................................................................9 Table 3 Ultrastar DC HC555 Exclusions.....................................................................................................................10 Table 4: Modes List and Description.............................................................................................................................11 Table 5: Approved Algorithms - Avago Technologies ...............................................................................................11 Table 6: Approved Algorithms -.....................................................................................................................................12 Table 7: Vendor-Affirmed Algorithms..........................................................................................................................12 Table 8: Security Function Implementations................................................................................................................15 Table 9: Entropy Certificates...........................................................................................................................................15 Table 10: Entropy Sources...............................................................................................................................................16 Table 11: Ports and Interfaces.........................................................................................................................................18 Table 12: Authentication Methods.................................................................................................................................18 Table 13: Roles...................................................................................................................................................................19 Table 14: Approved Services...........................................................................................................................................48 Table 15: Mechanisms and Actions Required...............................................................................................................50 Table 16: EFP/EFT Information...................................................................................................................................51 Table 17: Hardness Testing Temperatures....................................................................................................................51 Table 18 Mechanisms and Actions Required................................................................................................................51 Table 19: Storage Areas....................................................................................................................................................52 Table 20: SSP Input-Output Methods...........................................................................................................................52 Table 21: SSP Zeroization Methods...............................................................................................................................53 Table 22: SSP Table 1.......................................................................................................................................................62 Table 23: SSP Table 2.......................................................................................................................................................74 Table 24: Pre-Operational Self-Tests.............................................................................................................................75 FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 4 of 87 Table 25: Conditional Self-Tests.....................................................................................................................................76 Table 26: Pre-Operational Periodic Information.........................................................................................................77 Table 27: Conditional Periodic Information.................................................................................................................78 Table 28: Error States.......................................................................................................................................................78 FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 5 of 87 Figures Figure 1 - Security Subsystem Components ...................................................................................................................8 Figure 2 - Ultrastar DC HC555.........................................................................................................................................8 Figure 3 - Excluded Components, Ultrastar DC HC555 ...........................................................................................10 Figure 4 - Excluded Components, Ultrastar DC HC555 ...........................................................................................11 Figure 5 - Symmetric Key Tree.......................................................................................................................................17 Figure 6 - Asymmetric Key Tree.....................................................................................................................................49 Figure 7 - Tamper-Evident Seal for Ultrastar DC HC555 .........................................................................................51 Figure 8 - Tamper Evidence on Tamper Seal...............................................................................................................51 FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 6 of 87 1 General 1.1 Overview This document is the non-proprietary FIPS 140-3 Security Policy for the Ultrastar® DC HC555 TCG Enterprise HDD SED. It contains the security rules under which the module must operate and describes how the module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 2 module. 1.2 Security Levels The FIPS 140-3 security levels for the Module are as follows. Section Title Security Level 1 General 2 2 Cryptographic module specification 2 3 Cryptographic module interfaces 2 4 Roles, services, and authentication 2 5 Software/Firmware security 2 6 Operational environment N/A 7 Physical security 2 8 Non-invasive security N/A 9 Sensitive security parameter management 2 10 Self-tests 2 11 Life-cycle assurance 2 12 Mitigation of other attacks N/A Overall Level 2 Table 1: Security Levels 2 Cryptographic Module Specification The Western Digital Ultrastar DC HC555 TCG Enterprise HDD SED, hereafter referred to as Ultrastar DC HC555, Cryptographic Module, cryptographic module, or CM is a self-encryption drive (SED) that complies TCG Storage Architecture Core Specification [TCG Core] and Trusted Computing Group (TCG) Storage Security Subsystem Class (SSC): Enterprise Specification [TCG Enterprise]. The TCG Storage SSC: Enterprise Specification defines a management interface for host application software to activate, provision, and manage user data encryption. The specification includes data structures and their required content, and mechanisms for managing and configuring Authentication Credentials and access controls. The security architecture provides a locking mechanism by which an Authentication Credential (i.e., a password) can be set by an operator to enable control of access to user data. After an operator authenticates to the appropriate role and locks access to user data access user data is inaccessible. This implementation complies with the lock- based authentication model specified in IG 4.1.A. 2.1 Description Purpose and Use FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 7 of 87 The Cryptographic Module’s intended use is by US Federal agencies or other markets that require FIPS 140-3 validated hardware modules. The primary function of the Cryptographic Module is to provide data encryption, access control, and cryptographic erase of the data stored on the hard drive media within the CM. The operator of the Cryptographic Module interfaces with the Cryptographic Module through application software that resides within a host system. Module Type: Hardware Module Embodiment: Multi-Chip Embedded Module Characteristics: Module Characteristics* Figure 1 illustrates a logical view of the CM’s firmware components. The Security Core partition is the most secure portion of the security subsystem. It forms a security boundary that provides assurances of firmware integrity and SSP integrity within the CM. The Security Protocol and Services partition contains the TCG Storage SSC: Enterprise SCC security protocol. Components in this ring communicate to the Security Core firmware through a Security Core API. The Security Application Client firmware, typically referred to as “Base Firmware” interfaces with the Security Protocol and Services firmware, provides adapters for the security subsystem support and implements a perimeter defense of the system based on security state. Specifically, the enforcement of port and command controls for manufacturing commands, firmware download control enforcement and boot up signature checks resides within the Security Application Client firmware layer. The Cryptographic Module operates within a limited operational environment. While operational, the Cryptographic Module prohibits operator or process-initiated additions, deletions, or modification of the code working set. For firmware upgrades, the Cryptographic Module uses an authenticated download service, which complies with ISO 19790 7.4.3.4, to upgrade the mutable firmware in its entirety. The immutable security firmware stored in ROM, which is essential and integral to the operation of the module is nonmodifiable. If the download operation is successful, authorized, and verified, the Cryptographic Module will begin operating with the new code working set after successfully executed all required pre-operational self-tests that comply with ISO 19790 7.10.2. Firmware loaded into the module that is not on the FIPS 140-3 certificate is out of the scope of this validation and requires a separate FIPS 140-3 validation. The Cryptographic Module’s security design utilizes common security protections, policies, and processes. It utilizes a hardware security Access Control Module (ACM) that incorporates a hardware Root of Trust (RoT). Security firmware leverages the RoT, hardware cryptographic algorithms and accelerators to implement a secure environment that assures firmware integrity, port access and the secure storage of plaintext secrets, user data, keys, and Sensitive Security Parameters (SSP) within the Cryptographic Module. The Cryptographic Module only supports approved security functions defined in NIST SP 800-140C and SP 800-140D. The hardware Root of Trust assures, 1) The isolation of security firmware and sensitive security parameters from Security Application Client firmware or firmware installed on embedded components within the cryptographic boundary, 2) The verification of cryptographic module firmware and security objects before usage, 3) A Key Management tree that secured by a root key stored in HW RoT OTP bits, 4) Support for a HW based Symmetric Key Generation, 5) Cryptographic Algorithm Acceleration and 6) End-to-End Protect between ACM & Key Server. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 8 of 87 Figure 1 - Security Subsystem Components Cryptographic Boundary Figure 2 depicts the physical form of the module within the scope of this security policy document. The CM is a multiple-chip embedded embodiment. The hard opaque surface of the enclosure and externally attached PCBA define the cryptographic boundary. All components within this boundary satisfy FIPS 140-3 requirements. The Cryptographic Module firmware disables the SIO port pins outlined by the red box to the right of the SAS connector in Figure 2 prior to transitioning to an operational state. Tested Operational Environment’s Physical Perimeter (TOEPP) Tested Operational Environment’s Physical Perimeter (TOEPP) – The physical enclosure of the CM and externally attached PCBA define the TOEPP’s physical perimeter. TOEPP and Cryptographic Boundary - The cryptographic boundary consists of CM’s physical enclosure, the externally attached PCBA and all firmware implementations within the immutable Security Core firmware that resides within the ROM of the Western Digital SoC8 ASIC and the mutable Security Protocol and Services and Security Application Client firmware layers. The Cryptographic Module writes mutable firmware from disk media into DRAM memory on power up. Photographs Figure 2 - Ultrastar DC HC555 Security Application Client Security Protocol and Services Client Security Core Data and Control Input Data and Status Output Host System FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 9 of 87 2.2 Tested and Vendor Affirmed Module Version and Identification Tested Module Identification - Hardware The Ultrastar DC HC555 cryptographic module is tested on the following operational environment. fModel and/or Part Number Hardware Version Firmware Version Processors Features Ultrastar DC HC555 WUH722012CL4205, WUH722014CL4205, WUH722016CL4205, WUH722018CL4205, WUH722020CL4205, WUH722012CL5205, WUH722014CL5205, WUH722016CL5205, WUH722018CL5205, WUH722020CL5205 RD10 ARM Cortex M3, ARM Cortex-R7 12TB 4Kn, 14TB 4Kn, 16TB 4Kn, 18TB 4Kn, 20TB 4Kn, 12TB 512e, 14TB 512e, 16TB 512e, 18TB 512e, 20TB 512e Table 2: Tested Module Identification – Hardware Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): N/A for this module. Tested Module Identification – Hybrid Disjoint Hardware: N/A for this module. Tested Operational Environments - Software, Firmware, Hybrid: N/A for this module. Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module. 2.3 Excluded Components The Ultrastar DC HC555 components listed below and identified in Figure 3 and Figure 4 are excluded from the cryptographic boundary. Exclusion* Rationale +5V via The voltage level on the +5V power rail is dependent on the presence of voltage on the +5V_EFUSE circuit. An N-channel Power MOSFET isolates the +5V circuit from the 5V_EFUSE circuit. A MOSFET failure will cause the voltage on the +5V circuit to drop to 0V. This results in the immediate shutdown of the CM. Therefore, the +5V via satisfies the excluded components requirements in 7.2.3.1 Cryptographic boundary general requirements. +5V_EFuse via The 5V_EFUSE circuit connects to the output of an integrated dual electronic eFuse, designed to protect circuitry from overcurrent and overvoltage events, in applications that require hot swap operation and in-rush current control. If the electronic eFUSE device fails, the voltage on the FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 10 of 87 Exclusion* Rationale 5V_EFUSE circuit drops to 0V. This results in the immediate shutdown of the CM. Therefore, the 5V _EFUSE via satisfies the excluded components requirements in 7.2.3.1 Cryptographic boundary general requirements. -3V via The -3V via connects to the Negative Switching Regulator (NSR) output of the PLSI device. It supplies -3V to the preamp chip in the head assembly through an inductor. If the PLSI device fails or inductor opens the preamp voltage input drops to 0V. This disables disk media read/write functions and renders user data inaccessible. Therefore, the -3V via satisfies the excluded components requirements in 7.2.3.1 Cryptographic boundary general requirements. WRPO_C via WRPO_C via: The WRPO_C signals the pre-amp in the head assembly that user data will be written to the drive’s media. The loss of the direct connection between the WRPO output of the SoC8 ASIC to the head assembly will cause user data corruption or data loss. Therefore, the WRPO_C via satisfies the excluded components requirements in 7.2.3.1 Cryptographic boundary general requirements. Table 3 Ultrastar DC HC555 Exclusions Figure 3 - Excluded Components, Ultrastar DC HC555 GND -3V GND +5V EFuse WRPO_C +5V EFuse +5V GND GND GND FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 11 of 87 Figure 4 - Excluded Components, Ultrastar DC HC555 2.4 Modes of Operation Mode Name Description Type Status Indicator isFIPS The cryptographic module is operating as a FIPS 140-3 compliant module Approved 1. The Level 0 Discovery service returns a value of 1 from the in FIPS global indicator data field and 2. The Firmware Download Control LockOnReset field is set to PowerCycle and 3. For each configured Locking SP User, the state of each attribute listed here is set such that, a. LockOnReset = PowerCycle . b. ReadLockEnabled = True c. WriteLockEnabled = True Table 4: Modes List and Description Section 11.1 (Installation, Initialization and Startup Procedures) specifies the recommended and mandatory steps necessary for the secure installation, initialization, and start-up of the cryptographic module as a FIPS 140-3 SL2 compliant module. The Crypto Officer is responsible for assuring that the mandatory configuration requirements remain unchanged. When correctly configured the Cryptographic Module always powers up isFIPS mode. The cryptographic module does not support non-approved or non-allowed security functions. Mode Change Instructions and Status: The Modes List and Description table specifies the conditions that must be true for the Cryptographic Module to operate in isFIPS mode. Any action by the operator that negates the PowerCycle setting of the Firmware Download Control's LockOnReset field transitions the CM to a noncompliant state. Any action by the operator that negates the attribute setting, specified in the Modes List and Description table for LockOnReset, ReadLockEnabled, or WriteLockEnabled for any configured BandMaster transitions the CM to a noncompliant state. Degraded Mode Description: The Cryptographic Module does not support a degraded operational mode. 2.5 Algorithms The Cryptographic Module supports NIST SP 800-131A compliant approved algorithms listed in the Approved Algorithms table. Approved Algorithms Avago Technologies Algorithm CAVP Cert Properties Reference AES-CBC AES 3580 Direction - Decrypt, Encrypt Key Length - 256 SP 800-38A AES-ECB AES 3580 Direction - Decrypt, Encrypt Key Length - 256 SP 800-38A HMAC-SHA2-256 HMAC 2280 - FIPS 198-1 SHA2-256 SHS 2942 Message Length - Message Length: 8-51200 Increment 8 FIPS 180-4 Table 5: Approved Algorithms - Avago Technologies FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 12 of 87 Algorithm CAVP Cert Properties Reference AES-ECB A670 Direction - Decrypt, Encrypt Key Length - 256 SP 800-38A AES-XTS A670 Direction - Decrypt, Encrypt Key Length - 256 SP 800-38E Counter DRBG A1390 Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - Yes SP 800-90A Rev. 1 PBKDF A1390 Iteration Count - Iteration Count: 2-1024 Increment 1 Password Length - Password Length: 32 SP 800-132 RSA SigVer (FIPS186- 4) A1390 Signature Type - PKCS 1.5 Modulo - 2048 FIPS 186-4 Table 6: Approved Algorithms - Vendor Affirmed Algorithms The Cryptographic Module implements the FIPS Vendor Affirmed cryptographic algorithms listed in the Vendor Affirmed Algorithm table. Name Properties Implementation Reference CKG-Direct AES-CBC 256:Symmetric Key Generation N/A SP 800-133rev2 Section 4 example #1, Section 6.1 and IG D.H CKG- Combined AES-CBC 256:Symmetric Key Generation N/A SP 800-133rev2 Section 6.3 example #2, IG D.H, and IG C.I Table 7: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms The Cryptographic Module does not implement non-Approved but allowed algorithms. N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed The Cryptographic Module does not implement non-Approved but allowed algorithms with no security claimed. N/A for this module. Non-Approved, Not Allowed Algorithms The cryptographic module does not implement algorithms that are not NIST SP 800-131A compliant. N/A for this module. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 13 of 87 2.6 Security Function Implementations The Cryptographic Module implements the Security Function Implementations listed in the Security Function Implementations table. Name Type Description Properties Algorithms Authority_Digest_Generation MAC Generates an HMAC message digest of an Authentication Credential PIN Publication:[FIPS 198-1] [IG10.3.A] HMAC-SHA2- 256: (HMAC 2280) SHA2-256: (SHS 2942) Authority_Digest_Verification MAC Verifies the HMAC digest of an Authentication Credential PIN. Publication:[FIPS 198-1] [IG 10.3.A] HMAC-SHA2- 256: (HMAC 2280) SHA2-256: (SHS 2942) Decryption BC-UnAuth Block Cipher Publication:[FIPS 197] [SP 800-38A] [IG 10.3.A] AES-ECB: (AES 3580) Key Size: 256 - bits Key Strength: 256 - bits Derived_Key_Generation PBKDF Password-Based Key Derivation Publication:[SP 800-132] [FIPS 198-1] [IG 10.3.A] [IG D.N] PBKDF: (A1390) HMAC-SHA2- 256: (HMAC 2280) SHA2-256: (SHS 2942) Digest_Generation SHA Secure Hash Standard Publication:[FIPS 180-4] [IG 10.3.A] [IG C.B] SHA2-256: (SHS 2942) Digest_Verification SHA Secure Hash Standard Publications:[IG 10.3.A] [IG C.B] SHA2-256: (SHS 2942) Encryption BC-UnAuth Block Cipher Publication:[FIPS 197] [SP 800-38A] [IG 10.3.A] AES-CBC: (AES 3580) Key Size: 256 Key Strength: 256 bits Entropy ENT-ESV Entropy Source Publication:[IG 9.3.A] [IG D.J] [IG D.O] [SP800-90B] FW_Authenticity DigSig-SigVer Digital Signature Verification. Verifies the authenticity of a firmware image. Publication:[IG 10.3.A] [IG C.B] [IG C.F] RSA SigVer (FIPS186-4): (A1390) SHA2-256: (SHS 2942) FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 14 of 87 Name Type Description Properties Algorithms FW_Integrity DigSig-SigVer Digital Signature Verification. Verifies the integrity of a firmware image. Publication:[IG 10.3.A] [IG C.B] [IG C.F] RSA SigVer (FIPS186-4): (A1390) SHA2-256: (SHS 2942) Keyed_Digest_Generation MAC Message Authentication Generation Publication:[FIPS 198-1] [IG 10.3.A] HMAC-SHA2- 256: (HMAC 2280) SHA2-256: (SHS 2942) Keyed_Digest_Verification MAC Message Authentication Verification Publication:[FIPS 198-1] [IG 10.3.A] HMAC-SHA2- 256: (HMAC 2280) SHA2-256: (SHS 2942) MEK Generation CKG Cryptographic Key Generation, XOR of LRK and NSK Publication:[SP800- 133rev2] [IG D.H] CKG-Combined: () Counter DRBG: (A1390) RBG DRBG Random number generator Publication:[SP 800-90A] [IG 10.3.A] [IG D.L] [IG D.R] Counter DRBG: (A1390) RBG Seeding ENT-ESV Seeds DRBG with entropy data Publication:[SP 800-90B] [IG 9.3.A] [IG 10.3.A] [IG D.J] [IG D.K] Counter DRBG: (A1390) SecureLoader_Integrity DigSig-SigVer Digital Signature Verification. Verifies the integrity of the Secure Loader firmware image Publication:[IG C.F] [IG 10.3.A] [IG C.B] RSA SigVer (FIPS186-4): (A1390) SHA2-256: (SHS 2942) Symmetric_Key_Generation CKG Generates AES 256 symmetric cryptographic keys Publication:[SP800- 133r2] [I.G D.H] CKG-Direct: () Counter DRBG: (A1390) User_Data_Decryption BC-UnAuth Block Cipher Publication:[FIPS 197] [SP 800-38E] [IG 10.3.A] [IG C.I] AES-XTS: (A670) Key Size: 256 bits Key Strength: 256 bits AES-ECB: (A670) Key Size: 256 bits FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 15 of 87 Name Type Description Properties Algorithms Key Strength: 256 bits User_Data_Encryption BC-UnAuth Block Cipher Publication:[FIPS 197] [SP 800-38E] [IG 10.3.A] [IG C.I] AES-XTS: (A670) Key Size: 256 bits Key Strength: 256 bits AES-ECB: (A670) Key Size: 256 bits Key Strength: 256 bits Table 8: Security Function Implementations 2.7 Algorithm Specific Information AES-XTS Key Pair Generation The Cryptographic Module performs a key comparison test on each LRK.AESKey/LRK.XTS key pair and NSK.AESKey/NSK.XTS key pair to assure compliance with FIPS 140-3 IG C.I XTS-AES Key Generation Requirements every time the CM generates an LRK.AESKey/LRK.XTS keyset and a NSK.AESKey/NSK.XTS key pair, to assure compliance for all derived MEKs. The only use of any AES-XTS key pair is the encryption and decryption of data-at-rest within the cryptographic module in a storage application. PBKDF2 The password consists of a minimum of twelve (12) hexadecimal bytes values and a maximum of thirty-two (32) hexadecimal bytes values that range from 0x00 to 0xFF. The probability that a random attempt correctly guesses a twelve (12) byte password, or a false acceptance occurs is equal to 1 in 7.92E+28. The probability that a random attempt correctly guesses a thirty-two (32) byte password, or a false acceptance occurs is equal to 1 in 1.16E+7728. The default 1024 iteration count, 256-bit Salt and HMAC-SHA2-256 (Cert #HMAC 2280) algorithm conforms to SP 800-132, Option 2a. The Master key (MK) encrypts and decrypts data protection keys. The PBKDF2 derived keys, Ku, and Ka, are only used in a data storage application. 2.8 RBG and Entropy The SP 800-90A rev1-compliant Deterministic Random Bit Generator (DRBG), implemented as a CTR_DRBG mechanism, uses an AES-256 block cipher derivation function to generate encryption keys for use within the cryptographic boundary of the Cryptographic Module. Paragraphs titled Entropy Information and RBG Information summarize the characteristics of the entropy noise source that resides within the cryptographic boundary and seeds the CTR_DRBG. Cert Number Vendor Name E212 Western Digital Corporation Table 9: Entropy Certificates FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 16 of 87 Name Type Operational Environment Sample Size Entropy per Sample Conditioning Component ESV, E212 Physical 0L21911, IC SOC8, Rev 2.0 ARM Cortex M3 32 bits 3.296 None Table 10: Entropy Sources Entropy Information The hardware-based ring oscillator noise source referenced in the Entropy Sources table consist of eight (8) identical groups of four (4) independent ring oscillator circuits. Within each group, there are four (4) distinct logic inverter gate designs that consist of 19, 23, 31, and 39 gates. The oscillators are physically isolated from other active traces within the SoC8 ASIC. No configuration steps are necessary to operate the entropy source in a compliant manner. As stated in the, E212 Public Use Document, on power up the Cryptographic Module executes an entropy source initialization sequence that collects sufficient samples of raw noise data to verify the health of its entropy source prior to seeding the DRBG. If the initialization sequence returns false, the Cryptographic Module transitions to an error state that blocks the execution of all security services. RBG Information The output of the entropy source referenced in the Entropy Sources table consists of the raw data generated from thirty-two (32) free running ring oscillators. Eight identical groups of four variable length inverter chains define the implementation. Each 32-bit sample produces at least 3.296 bits of entropy. Each time the DRBG is instantiated or reseeded, the CM concatenates one hundred sixty (160) 32-bit samples to seed the DRBG. This equates to 5120 bits of entropy data and translates to at least 527.36 bits of min-entropy. This seeds the CTR_DRBG with approximately 351 bits of security strength (~351 bits of entropy input and ~176 bits of nonce). Seeding the DRBG with at least 351 bits of security strength exceeds the requirement to seed the DRBG with 256 bits of security strength. 2.9 Key Generation The cryptographic module utilizes an SP 800-90A rev1-compliant CTR_DRBG to generate symmetric cryptographic keys, which comply with sections 6.1, 6.2.3 and 6.3 of SP 800-133r2. Each symmetric keyset consists of an encryption and a signing key. Specifically, • the Root Keyset consists of a 256-bit Root Encryption Key and 256-bit Root Signing Key • the Global Active Keyset (AEK) consists of a 256-bit Global Active Encryption Key and a 256-bit Global Active Signing Key • the SED Active Keyset consists of a 256-bit SED Active Encryption Key and a 256-bit SED Active Signing Key • the SED AdminSP Active Keyset consists of a 256-bit SED AdminSP Active Encryption Key and a 256-bit SED AdminSP Active Signing Key • SED LockingSP Active Keyset consists of a 256-bit SED LockingSP Active Encryption Key and a 256-bit SED LockingSP Active Signing Key FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 17 of 87 Figure 5 - Symmetric Key Tree 2.10 Key Establishment Key Agreement Information The cryptographic module does not support a key establishment scheme. Key Transport Information The cryptographic module does not support a key transport scheme. 2.11 Industry Protocols The cryptographic module does not implement any Industry Protocol. 3 Cryptographic Module Interfaces 3.1 Ports and Interfaces As a hardware module, the Cryptographic Module uses the standard 29-pin Serial Attached SCSI (SAS) connector that conforms to the mechanical requirements of SFF 8680. The Ports and Interfaces table identifies the Cryptographic Module’s physical ports and associated FIPS defined logical interfaces. The two-wire SIO Serial Port connector consists of signal and ground. Prior to shipment, Western Digital disables the SIO port. The Cryptographic Module does not provide a maintenance access interface. The Cryptographic Module does not support a trusted channel communication link between the CM and a host system. The Cryptographic Module does not support a Control Output logical interface. Physical Port Logical Interface(s) Data That Passes SAS Connector, SIO Serial Port Connector Control Input SAS connector: Used to transmit SCSI commands from the host system to the CM. SIO Serial Port: None, disabled. SAS Connector, SIO Serial Port Connector Data Input SAS connector: Used to transmit data and firmware update images from the host system to the CM. SIO Serial Port: FD_UART_RX, disabled. SAS Connector, SIO Serial Port Connector Data Output SAS connector: Used to transmit data from the Cryptographic Module to the host system. SIO Serial Port: FD_UART_TX, disabled. SAS Connector Status Output Used to transmit status data from the CM to the host system. READY_LED Root Keyset Global Active Keyset SED Active Keyset SED Admin SP Active Keyset SED Locking SP Active Keyset FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 18 of 87 Physical Port Logical Interface(s) Data That Passes SAS Connector Power SAS Connector power pins None None Downloand Port: This logical port has two valid states, locked, and unlocked. If locked, the CM logically blocks firmware downloads. If unlocked, the CM logically allows the Cryptographic Officer to download firmware. Table 11: Ports and Interfaces 4 Roles, Services, and Authentication 4.1 Authentication Methods The Cryptographic Module implements the authentication methods listed in Authentication Methods table. Method Name Description Security Mechanism Strength Each Attempt Strength per Minute Credential PIN Authentication Authenticates a 12 to 32 bytes Authentication Credential PIN. Byte value range (ea.): 0x00 to 0xFF. Authority_Digest_Verification Lowest: 12-byte PIN: 96 bits For 12-byte PIN: Permutations: 7.92E+28 Authentication Time: 2.094965 msec Guess Probability (1 min): 3.61E-25 Table 12: Authentication Methods Note: E = log2(RL), where E = authentication strength, R = pool of unique characters and L = password length defines the security strength of an Authentication Credential PIN. See Calculating Password Entropy [PW]. 4.2 Roles The Module supports distinct User and Cryptographic Officer (CO) operator roles. The Cryptographic Module enforces role separation by requiring a role identifier and authentication credential in the form of a Personal Identification Number (PIN). The Cryptographic Module enforces role dependent service access rules. The Approved Services table maps services to Crypto Officer and User roles. The Cryptographic Module implements Access Control in layers. The top layer of the implementation consists of Access Control Lists (ACLs). ACLs are lists of Access Control Elements (ACEs). The boolean state of an ACE associated with an authority within a role determines access to a service. After authentication, an authority’s associated ACE boolean expression is set to be True. Prior to authentication, an authority’s associated ACE boolean expression is set to False. Closing a TCG session or powering off the Cryptographic Module disables all previously authenticated authorities by setting the ACE Boolean expression associated with all authenticated authorities to False. After powering up the CM and opening a new TCG session, the operator must execute the Authenticate service to enable an authority within the Crypto Officer and User roles. The module does not support a maintenance role The Cryptographic Module does not support concurrent operators. The Cryptographic Module encrypts and signs all authentication data, associated with a role, stored outside the ACM. The ACM imports the encrypted and signed authentication, verifies the signature, and decrypts the authentication data. Before validating the operator supplied authentication data, the ACM checks for try limit violations. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 19 of 87 The lock-based authentication method implemented by the Cryptographic Module remains secure because the purpose of the implementation is to protect data-at-rest and the host operating system in communication with the CM acts as the operator and is considered a trusted machine. The Cryptographic Module implements the roles listed in the Roles table. Name Type Operator Type Authentication Methods Anybody Role User None BandMaster [0-15] Role CO Credential PIN Authentication EraseMaster Role CO Credential PIN Authentication SID Role CO Credential PIN Authentication SCSI User Role User None Table 13: Roles 4.3 Approved Services The Approved Services table lists the approved services implemented by the Cryptographic Module. The SSPs modes of access shown in the table below are defined as: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The CM uses the SSP to perform a cryptographic operation. Z = Zeroise: The CM zeroises the SSP. Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access Authenticate PSID PSID character string authenticati on isFIPS mode is true PSID Success or UEC failure code Decryption Keyed_Digest_Verific ation SID - PSID: W - PSID Digest: E - Global Active Encryption Key (AEK): E - Global Active Signing Key: E Anybody - PSID: W - Global Active Encryption Key (AEK): FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 20 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access E - Global Active Signing Key: E - PSID Digest: E Authenticate TCG Authority Authenticati on Credential authenticati on isFIPS mode is true Authentication Credential PIN Success or UEC failure code Authority_Digest_Ver ification Derived_Key_Genera tion SID - SID PIN Digest: E - MSID Digest: E - MSID: W - SID PIN: W - SED AdminSP Active Signing Key: E EraseMaster - EraseMaster PIN Digest: E - BandMaster PIN Digest (16 total): E - MSID Digest: E - SED LockingSP Active Signing Key: E - Locking SP Object Table (EraseMaster and BandMaster unique): E - MSID: W - EraseMaster PIN: W - BandMaster PIN (16 FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 21 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access total): W - Admin Authority Key (Ka): G,E - Non- Admin Authority Key (Ku) (BandMaster unique): G,E - KDF Salt (EraseMaster and BandMaster unique): E BandMaster [0-15] - EraseMaster PIN Digest: E - BandMaster PIN Digest (16 total): E - MSID Digest: E - SED LockingSP Active Signing Key: E - Locking SP Object Table (EraseMaster and BandMaster unique): E - MSID: W - EraseMaster PIN: W - BandMaster PIN (16 total): W - Admin Authority FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 22 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access Key (Ka): G,E - Non- Admin Authority Key (Ku) (BandMaster unique): G,E - KDF Salt (EraseMaster and BandMaster unique): E Anybody - SID PIN: W - SID PIN Digest: E - MSID: W - MSID Digest: E - EraseMaster PIN: W - EraseMaster PIN Digest: E - BandMaster PIN (16 total): W - BandMaster PIN Digest (16 total): E - SED AdminSP Active Signing Key: E - Locking SP Object Table (EraseMaster and BandMaster unique): E - Admin Authority FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 23 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access Key (Ka): G,E - Non- Admin Authority Key (Ku) (BandMaster unique): G,E - KDF Salt (EraseMaster and BandMaster unique): E BootFlashInt egrity An RSA digital signature verifies the authenticity of a binary firmware image. isFIPS mode is true RSA 2048 PKCS1 v1.5 signed firmware image Success or UEC failure code SecureLoader_Integrit y Unauthentica ted - Storage Device Certification Authority Key (SD_CA Key): E FIPS 140 Compliance Descriptor (Show Version) This service reports the FIPS 140 revision as well as the Cryptograph ic Module’s overall security level, hardware revision, firmware revision and module name. isFIPS mode is true Security Protocol IN (0x0, 0x2, 0x2) FIPS 140 Complia nce Descript or table data or UEC failure code None SCSI User Firmware Download Digital signature verification of a binary firmware image. isFIPS mode is true RSA 2048 PKCS1 v1.5 signed firmware image Success or UEC failure code FW_Authenticity SID - OEM Firmware Key (OEM_FW Key): E - OEM_Relea se Key FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 24 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access (OEM_Relea se Key): E Firmware Download Control Enable or disable access to the Firmware Download service. isFIPS mode is true FW_DOWNLOAD _PORT bit within the AdminSP Logical Port Table. Success or UEC failure code None SID Firmware Integrity An RSA digital signature verifies the authenticity of a binary firmware image. isFIPS mode is true RSA 2048 PKCS1 v1.5 signed firmware image Success or UEC failure code FW_Integrity Unauthentica ted - OEM Firmware Key (OEM_FW Key): E - Security Core Firmware Key (SC_FW Key): E - Security Protocol Firmware Key (SP_FW Key): E - OEM Original Factory State Key (OEM_OFS Key): E - Storage Device Boot FW Key (SD_BFW Key): E - Storage Device Certification Authority Key (SD_CA Key): E - Storage Device Secure Message Key (SD_SM Key): E FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 25 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access - Product Group Key (PROD_GR OUP Key): E Generate Random TCG Random method that generates a random number from the SP 800-90A CTR_DRB G isFIPS mode is true Byte count Byte string RBG Anybody - DRBG.Key: G,E - DRBG.V: G,E Get Reads data structure; access control enforcement occurs per data structure field. isFIPS mode is true See §5.3.3.6 Basic Table Method Group - Get (Table and Object Method [TCG Core] Request ed table data. [TCG Core] Decryption Keyed_Digest_Verific ation Anybody - MSID: R Get Band Attributes Returns the data stored in the Locking SP table for an LBA Range. isFIPS mode is true Band_UID [TCG Enterprise] LBA range attribute data [TCG Enterpri se] None Anybody - SED LockingSP Active Encryption Key: E - SED LockingSP Active Signing Key: E - Locking SP Object Table (EraseMaster and BandMaster unique): E BandMaster [0-15] - SED LockingSP Active Encryption Key: E FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 26 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access - SED LockingSP Active Signing Key: E - Locking SP Object Table (EraseMaster and BandMaster unique): E Get Data Store Read a stream of bytes from unstructure d storage. isFIPS mode is true See §3.2.13.9 Read data from the DataStore table [TCG SIIS] DataSto re plaintext data or UEC failure code. None Anybody Level 0 Discovery TCG ‘Level 0 Discovery’ discloses basic configuratio n data about the Cryptograph ic Module, both current and potential [TCG Core] [Product Manual] isFIPS mode is true See §3.3.6 Level 0 Discovery, §3.3.6.2 IF-RECV Command [TCG Core] Level 0 Discove ry Respons e data [TCG Core] None Anybody Read User Data Reads ciphertext from a specified LBA range and outputs the user data as plaintext. isFIPS mode is true SCSI Operation Code, LBA, Transfer Length, Data-Out Buffer See [SBC-4] Plaintext user data or UEC failure code User_Data_Decryptio n SCSI User - MEK - Media Encryption Keyset MEK.AESE nc Key MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster unique): E FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 27 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access Reset Module Power on Reset isFIPS mode is true None Drive Ready Indicato r or UEC failure code Derived_Key_Genera tion Encryption MEK Generation RBG RBG Seeding Symmetric_Key_Gen eration Unauthentica ted - DRBG.Key: G,E - DRBG.V: G,E - ESV: G,E - SED Volatile Encryption Key: G,E - SED Volatile Signing Key: G,E - DRBG.Seed: G - MEK - Media Encryption Keyset MEK.AESE nc Key MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster unique): G - Global Active Encryption Key (AEK): E - Global Active Signing Key: E - Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 28 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access unique): E - Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique): E - Range Access Key (RAK) (BandMaster unique): E Revert The Revert method cryptographi cally zeroizes CSPs and returns the Cryptograph ic Module to its original manufacture d state. isFIPS mode is true PSID Drive Ready Indicato r or UEC failure code Derived_Key_Genera tion Encryption Keyed_Digest_Gener ation MEK Generation RBG Symmetric_Key_Gen eration Authority_Digest_Ge neration SID - SID PIN Digest: G,Z - DRBG.Key: G,E - DRBG.V: G,E - Global Active Signing Key: G,E,Z - SED Active Encryption Key: G,Z - SED Active Signing Key: G,Z - SED AdminSP Active Encryption Key: G,E,Z - SED AdminSP Active Signing Key: G,Z - Admin SP Object Table: G,Z - Locking SP FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 29 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access Object Table (EraseMaster and BandMaster unique): G,Z - SED LockingSP Active Encryption Key: G,E,Z - SED LockingSP Active Signing Key: G,E,Z - SED Volatile Encryption Key: G,E,Z - SED Volatile Signing Key: G,E,Z - PSID: W - Global Active Encryption Key (AEK): G,E,Z - MEK - Media Encryption Keyset MEK.AESE nc Key MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster unique): G,Z - Admin Authority Key (Ka): G,E,Z - Non- Admin Authority Key (Ku) FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 30 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access (BandMaster unique): G,E,Z - Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique): G,E,Z - Range Access Key (RAK) (BandMaster unique): G,E,Z - User Access Key (UAK) (BandMaster unique): G,E,Z - User Management Key (UMK): G,E,Z - Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique): G,E,Z - Root Encryption Key: G,E,Z - Root Signing Key: G,E,Z - EraseMaster PIN Digest: FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 31 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access G,Z - BandMaster PIN Digest (16 total): G,Z - KDF Salt (EraseMaster and BandMaster unique): G,E,Z - MSID: E Anybody - SID PIN Digest: G,Z - DRBG.Key: G,E - DRBG.V: G,E - Global Active Signing Key: G,E,Z - SED Active Encryption Key: G,Z - SED Active Signing Key: G,Z - SED AdminSP Active Encryption Key: G,E,Z - SED AdminSP Active Signing Key: G,E,Z - Admin SP Object Table: G,Z - Locking SP Object Table (EraseMaster FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 32 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access and BandMaster unique): G,Z - SED LockingSP Active Encryption Key: G,E,Z - SED LockingSP Active Signing Key: G,E,Z - SED Volatile Encryption Key: G,E,Z - SED Volatile Signing Key: G,E,Z - PSID: W - Global Active Encryption Key (AEK): G,E,Z - MEK - Media Encryption Keyset MEK.AESE nc Key MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster unique): G,Z - Admin Authority Key (Ka): G,E,Z - Non- Admin Authority Key (Ku) (BandMaster unique): FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 33 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access G,E,Z - Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique): G,E,Z - Range Access Key (RAK) (BandMaster unique): G,E,Z - User Access Key (UAK) (BandMaster unique): G,E,Z - User Management Key (UMK): G,E,Z - Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique): G,E,Z - Root Encryption Key: G,E,Z - Root Signing Key: G,E,Z - EraseMaster PIN Digest: G,Z - FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 34 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access BandMaster PIN Digest (16 total): G,Z - KDF Salt (EraseMaster and BandMaster unique): G,E,Z - MSID: E RevertSP The RevertSP method cryptographi cally zeroizes CSPs and returns the Cryptograph ic Module to its original manufacture d state. IsFIPS mode is true See §5.1.3 RevertSP – Base Template SP Method [TCG Enterprise] Drive Ready Indicato r or UEC failure code Derived_Key_Genera tion Encryption Keyed_Digest_Gener ation MEK Generation RBG Symmetric_Key_Gen eration Authority_Digest_Ge neration SID - SID PIN Digest: G,Z - DRBG.Key: G,E - DRBG.V: G,E - Global Active Signing Key: G,E,Z - SED Active Encryption Key: G,Z - SED Active Signing Key: G,Z - SED AdminSP Active Encryption Key: G,E,Z - SED AdminSP Active Signing Key: G,E,Z - Admin SP Object Table: G,Z - Locking SP Object Table (EraseMaster and BandMaster FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 35 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access unique): G,Z - SED LockingSP Active Encryption Key: G,E,Z - SED LockingSP Active Signing Key: G,E,Z - SED Volatile Encryption Key: G,E,Z - SED Volatile Signing Key: G,E,Z - Global Active Encryption Key (AEK): G,E,Z - MEK - Media Encryption Keyset MEK.AESE nc Key MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster unique): G,Z - Admin Authority Key (Ka): G,E,Z - Non- Admin Authority Key (Ku) (BandMaster unique): G,E,Z - Locking Range FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 36 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique): G,E,Z - Range Access Key (RAK) (BandMaster unique): G,E,Z - User Access Key (UAK) (BandMaster unique): G,E,Z - User Management Key (UMK): G,E,Z - Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique): G,E,Z - Root Encryption Key: G,E,Z - Root Signing Key: G,E,Z - EraseMaster PIN Digest: G,Z - BandMaster PIN Digest (16 total): FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 37 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access G,Z - KDF Salt (EraseMaster and BandMaster unique): G,E,Z - MSID: E Anybody - DRBG.Key: G,E - DRBG.V: G,E - Global Active Signing Key: G,E,Z - SED Active Encryption Key: G,Z - SED Active Signing Key: G,Z - SED AdminSP Active Encryption Key: G,E,Z - SED AdminSP Active Signing Key: G,E,Z - Admin SP Object Table: G,Z - Locking SP Object Table (EraseMaster and BandMaster unique): G,Z - SED LockingSP Active Encryption FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 38 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access Key: G,E,Z - SED LockingSP Active Signing Key: G,E,Z - SED Volatile Encryption Key: G,E,Z - SED Volatile Signing Key: G,E,Z - Global Active Encryption Key (AEK): G,E,Z - MEK - Media Encryption Keyset MEK.AESE nc Key MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster unique): G,Z - Admin Authority Key (Ka): G,E,Z - Non- Admin Authority Key (Ku) (BandMaster unique): G,E,Z - Locking Range Keyset (LRK) LRK.AES Key LRK.XTS FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 39 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access Key (BandMaster unique): G,E,Z - Range Access Key (RAK) (BandMaster unique): G,E,Z - User Access Key (UAK) (BandMaster unique): G,E,Z - User Management Key (UMK): G,E,Z - Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique): G,E,Z - Root Encryption Key: G,E,Z - Root Signing Key: G,E,Z - EraseMaster PIN Digest: G,Z - BandMaster PIN Digest (16 total): G,Z - KDF Salt (EraseMaster and BandMaster FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 40 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access unique): G,E,Z - MSID: E SCSI Command The SCSI command set provides an efficient peer-to-peer operation for SCSI devices. isFIPS mode is true Input parameters are defined within [SCSI Core] and [SCSI Block] Return device data as defined within [SCSI Core] and [SCSI Block] or UEC failure code. None SCSI User Self-Test The Cryptograph ic Module performs self-tests when it powers up. N/A None Drive Ready or UEC failure code Decryption Derived_Key_Genera tion Digest_Generation Digest_Verification Encryption FW_Integrity Keyed_Digest_Gener ation Keyed_Digest_Verific ation RBG Entropy Unauthentica ted - DRBG.Key: G,E - DRBG.V: G,E Set Write data structures; access control enforcement occurs per data structure field. This service can change Authenticati on Credential PINs. isFIPS mode is true Set method table data. See [TCG Core] Success or UEC failure code Authority_Digest_Ge neration Derived_Key_Genera tion Encryption Keyed_Digest_Gener ation SID - Global Active Encryption Key (AEK): E - Global Active Signing Key: E - SED AdminSP Active Encryption Key: E - SED AdminSP Active Signing Key: FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 41 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access E - SED Volatile Encryption Key: E - SED Volatile Signing Key: E - SID PIN: W - SID PIN Digest: G - SED Active Encryption Key: E - SED Active Signing Key: E - Admin SP Object Table: E Anybody EraseMaster - Global Active Encryption Key (AEK): E - Global Active Signing Key: E - SED LockingSP Active Encryption Key: E - SED LockingSP Active Signing Key: E - SED Volatile Signing Key: E FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 42 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access - SED Volatile Encryption Key: E - SED Active Encryption Key: E - SED Active Signing Key: E - Admin Authority Key (Ka): E - EraseMaster PIN: W - EraseMaster PIN Digest: G - BandMaster PIN (16 total): W - BandMaster PIN Digest (16 total): G - Non- Admin Authority Key (Ku) (BandMaster unique): G,E - KDF Salt (EraseMaster and BandMaster unique): E - Locking SP Object Table (EraseMaster and BandMaster unique): G BandMaster [0-15] FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 43 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access - Global Active Encryption Key (AEK): E - Global Active Signing Key: E - SED LockingSP Active Encryption Key: E - SED LockingSP Active Signing Key: E - SED Volatile Signing Key: E - SED Volatile Encryption Key: E - SED Active Encryption Key: E - SED Active Signing Key: E - Non- Admin Authority Key (Ku) (BandMaster unique): G,E - EraseMaster PIN: W - EraseMaster PIN Digest: G - FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 44 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access BandMaster PIN (16 total): W - BandMaster PIN Digest (16 total): G - Admin Authority Key (Ka): G - KDF Salt (EraseMaster and BandMaster unique): E - Locking SP Object Table (EraseMaster and BandMaster unique): G Set Band Attributes Set the starting location, size, and attributes of an LBA range. isFIPS mode is true LBA range configuration data. See [TCG Enterprise] Success or UEC failure code Encryption MEK Generation BandMaster [0-15] - Global Active Encryption Key (AEK): E - Global Active Signing Key: E - SED Active Encryption Key: E - SED Active Signing Key: E - SED LockingSP Active Encryption Key: E - SED LockingSP Active Signing Key: FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 45 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access E - SED Volatile Encryption Key: E - SED Volatile Signing Key: E - User Access Key (UAK) (BandMaster unique): E - Range Access Key (RAK) (BandMaster unique): E - Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique): E - Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique): E - MEK - Media Encryption Keyset MEK.AESE nc Key MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 46 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access unique): E - Locking SP Object Table (EraseMaster and BandMaster unique): G Set DataStore Write a stream of bytes to unstructure d storage. isFIPS mode is true DataStore byte table data. See [TCG Enterprise] Success or UEC failure code None Anybody BandMaster [0-15] Show Status The status inquiry command requests SCSI device (e.g., Cryptograph ic Module) status information. isFIPS mode is true [SCSI Core] and [SCSI Block] define the input parameters. Return requeste d module data or UEC failure code None SCSI User TCG Erase TCG Erase cryptographi cally zeroizes user data by regenerating and replacing a Locking Range Key associated with an LBA Range. isFIPS mode is true Band_UID See [TCG Enterprise],[TCG Ent App Notes] Success or UEC failure code Encryption MEK Generation RBG Symmetric_Key_Gen eration EraseMaster - MEK - Media Encryption Keyset MEK.AESE nc Key MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster unique): G,E,Z - DRBG.Key: E - DRBG.V: E - Range Access Key (RAK) (BandMaster unique): E - User Access Key FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 47 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access (UAK) (BandMaster unique): E - Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique): G,E,Z - User Management Key (UMK): E - Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique): E - Anybody User Access Key (UAKa): E - Global Active Encryption Key (AEK): E - Locking SP Object Table (EraseMaster and BandMaster unique): G Write User Data Transforms plaintext user data into ciphertext and writes the data to a isFIPS mode is true Operation Code, LBA, Transfer Length, Data-Out Buffer [SBC-4] Success or UEC failure code User_Data_Encryptio n SCSI User - MEK - Media Encryption Keyset MEK.AESE nc Key FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 48 of 87 Name Descriptio n Indica tor Inputs Output s Security Functions SSP Access specified LBA band. MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster unique): E Table 14: Approved Services 4.4 Non-Approved Services The Cryptographic Module does not support non-approved services. N/A for this module. 4.5 External Software/Firmware Loaded The Cryptographic Module utilizes RSA public key cryptography to verify the authenticity of firmware downloaded to the CM. The Cryptographic Module uses RSA 3072 PKCSPSS with SHA2-256 to verify the digital signature of a downloaded firmware binary image. A Hardware Security Module (HSM), which resides in a secure Western Digital facility, generates, and stores the RSA Public/Private key pairs used in the firmware signing process. The Cryptographic Module rejects a downloaded firmware binary image if the digital signature verification process fails. 5 Software/Firmware Security 5.1 Integrity Techniques The Cryptographic Module utilizes RSA public key cryptography to verify the integrity of all firmware binary images within the CM prior to execution. An operator may initiate the integrity test on demand by power cycling the CM. The firmware integrity tests ensure that prior to executing any firmware image the Cryptographic Module verifies the firmware is from an authenticated Western Digital source. Current storage devices typically implement a multi-stage loader system to boot the drive. Each loader stage is responsible for loading and verifying the next image before transferring control to the next image. This process establishes a chain of trust during the boot process. The Cryptographic Module’s Boot ROM code loads the secure loader image. The SD_CA Key signed secure loader, enables the boot process to use other keys besides the SD_CA Key for boot time signature checking (i.e., SD_BFW Key). For example, the secure loader loads the SD_BFW public key certificate and verifies the SD_CA Key signature of the certificate. The secure loader then loads the next image(s) from boot flash, verifies the signature of the next image(s) using the SD_BFW public key, and transfers control to the next image. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 49 of 87 Figure 6 - Asymmetric Key Tree 5.2 Initiate on Demand The operator initiates the integrity test on demand by power cycling the Cryptographic Module. 5.3 Open-Source Parameters The Western Digital firmware development process does not utilize open-source firmware to build executable code installed within the Cryptographic Module. 6 Operational environment 6.1 Operational Environment Type and Requirements Type of Operating Environment: Limited How Requirements are Satisfied While operational, the Cryptographic Module prohibits additions, deletions, or modification of the code working set. For firmware upgrades, the Cryptographic Module uses an authenticated download service to upgrade its mutable firmware in its entirety. The immutable security firmware stored in ROM, which is essential and integral to the operation of the module is non-modifiable. If the download operation is successful, authorized, and verified, the Cryptographic Module will begin operating with the new code working set after successfully executing all pre- operational self-tests. Firmware loaded into the cryptographic module that is not on the FIPS 140-3 certificate is out of the scope of this validation and requires a separate FIPS 140-3 validation. 6.2 Configuration Settings and Restrictions The Cryptographic Module blocks the installation of firmware images that contain a Code ID that is inconsistent with the Cryptographic Module’s SoC, hardware interface type (e.g., SAS or SATA) and security type (e.g., TCG Enabled, FIPS Enabled, etc.). SD_CA Key SD_BFW Key SD_SM Key SC_FW Key SP_FW Key PROD_Group Key OEM_FW Key OEM_Release Key OEM_OFS Key FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 50 of 87 The Crypto Officer is responsible for assuring that the LockOnReset parameter of the logical firmware download port is set to PowerCycle. The Cryptographic Module is in a noncompliant state when the LockOnReset parameter is not set to PowerCycle. The Crypto Officer is responsible for assuring the logical firmware download port remains locked unless the CO intends to execute the Firmware Download service. The CO shall lock the firmware download port after the Firmware Download service completes. Consult the Ports section of the Ultrastar DC HC555 3.5-inch Serial Attached SCSI Hard Disk Drive Specification [Product Manual] for guidance. The Crypto Officer is responsible for assuring that the BandMaster Authentication PIN Credential for all configured BandMasters does not equal the MSID value. The Crypto Officer is responsible for assuring that the LockOnReset attribute for any configured BandMaster is set to PowerCycle. The Cryptographic Module is in a noncompliant state when the state of the LockOnReset attribute of any configured BandMaster is not set to PowerCycle. The Crypto Officer is responsible for assuring that the ReadLockEnabled and WriteLockEnabled attribute for any configured BandMaster is set to True. The Cryptographic Module is in a noncompliant state when the state of the ReadLockEnabled or WriteLockEnabled attribute of any configured BandMaster is set to False. Consult the TCG Storage SSC: Enterprise Specification [TCG Enterprise] for guidance. 7 Physical Security The Cryptographic Module is a multi-chip embedded module that complies with FIPS 140-3 Level 2 security. An ambient temperature from 5° to 60°C defines the Cryptographic Module’s environmental operating range [Datasheet] 7.1 Mechanisms and Actions Required The Cryptographic Module does not make claims in the Physical Security area beyond FIPS 140-3 Level 2 security. Therefore, the CM does not employ any fault induction mitigation techniques or EFP feature to immediately zeroise all unprotected SSPs if the temperature or voltage falls outside of the cryptographic module's normal operating range. The CM initiates a thermal safety shutdown if the temperature drops below -40°C or exceeds 70°C but does not zeroize SSPs if either trip point is exceeded. • All components are production-grade materials with standard passivation techniques. • The enclosure is opaque. • Engineering design supports opacity requirements. • An attacker cannot penetrate or remove and reapply a tamper-evident security seal without evidence of tampering. In addition, it is difficult to replicate the tamper-evident security seal. Mechanism Inspection Frequency Inspection Guidance During the manufacturing process, specialized equipment applies three tamper-evident security seal to the CM’s PCBA. See below. Annually The Cryptographic Module’s owner shall inspect the Cryptographic Module for evidence of tampering. If tamper evidence is apparent, the owner should return the module to Western Digital. See below. Table 15: Mechanisms and Actions Required Temp/Voltage Type Temperature or Voltage EFP or EFT Result LowTemperature FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 51 of 87 Temp/Voltage Type Temperature or Voltage EFP or EFT Result HighTemperature LowVoltage HighVoltage Table 16: EFP/EFT Information Temperature Type Temperature LowTemperature HighTemperature Table 17: Hardness Testing Temperatures Table 18 Mechanisms and Actions Required Figure 7 - Tamper-Evident Seal for Ultrastar DC HC555 Figure 8 - Tamper Evidence on Tamper Seal 8 Non-invasive Security 8.1 Mitigation Techniques The Cryptographic Module lacks features to mitigate any non-invasive security attacks beyond the scope of the FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 52 of 87 requirements within FIPS 140-3 Security Level 2. 9 Sensitive Security Parameters Management The Cryptographic Module manages the SSPs listed in Section 0 of this document. The Cryptographic Module does not support the output of SSPs beyond the cryptographic boundary. The Cryptographic Module does not support non-approved algorithms or key lengths. 9.1 Storage Areas Calling processes implemented in firmware control Cryptographic Module access to SSPs. Zeroization services destroy or cryptographically erase SSPs. Storage Area Name Description Persistence Type DRAM General purpose system memory Dynamic IRAM Memory internal to the ACM Dynamic NOR Flash(Reserved area) SSP and boot code storage Static Disk Media (Reserved Area) SSP and operation firmware image storage Static One-time Programable (OTP) Root Key and Certificate Authority Key storage Static NAND Flash SSP storage and firmware image Static Table 19: Storage Areas 9.2 SSP Input and Output Methods The CM limits the input of SSPs to plaintext Authentication Credential PINs and RSA-3072 public keys. RSA-3072 public key insertion occurs during the manufacturing process. Instead of storing PIN values as plaintext, the CM stores an HMAC SHA-256 Digest of the PIN. A Hardware Security Module (HSM), which resides within a secure Western Digital facility, generates, and stores RSA Public/Private key pairs utilized during the manufacturing process. The CM does not support the output of intermediate values generated during key generation. The module does not support the output of SSPs beyond the cryptographic boundary of the module. Name From To Format Type Distributio n Type Entry Type SFI or Algorithm Authenticatio n Credential PIN Operato r Cryptographi c Module Plaintex t Manual Electroni c Authority_Digest_Verificatio n Table 20: SSP Input-Output Methods FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 53 of 87 9.3 SSP Zeroization Methods Zeroization of persistent SSPs complies with the cryptographic erasure requirements for SCSI Hard Disk drives within [SP 800 88], Guidelines for Media Sanitization. The Cryptographic Module zeroizes ephemeral SSPs by overwriting the SSP memory location with all zeros within the scope of the function call. Zeroization Method Description Rationale Operator Initiation Power Cycle Power cycling involves disconnecting and reconnecting the CM to its source of power. Plaintext SSPs stored in IRAM memory within the ACM are destroyed instantaneously when power is removed. The operator physically or remotely disconnects the CM from its source of power. Revert The Revert method cryptographically erases CSPs. Revert removes the owner’s Authentication Credentials and returns the Cryptographic Module to its original manufactured state. The CM preserves Global Range data if the KeepGlobalRangeKey parameter is set to True. All SSPs within the scope of this zeroization method are encrypted and signed. Therefore, the rationale specified under item e of VE09.30.01 is not applicable. The operator transmits a command to the CM as the TPer to initiate a zeroisation process. RevertSP The RevertSP method cryptographically erases CSPs. RevertSP removes the owner’s Authentication Credentials and returns the Cryptographic Module to its original manufactured state. Global Range data is preserved if the KeepGlobalRangeKey parameter is set to True. All SSPs within the scope of this zeroization method are encrypted and signed. Therefore, the rationale specified under item e of VE09.30.01 is not applicable. The operator transmits a command to the CM as the TPer to initiate a zeroisation process. Secure Manufacturing Reconfiguration Process The secure manufacturing reconfiguration processes incorporates a hardware security module (HSM) and supporting security software to inject cryptographic keys, digital certificates and assure only authentic firmware is installed on the Cryptographic Module. All SSPs within the scope of this zeroization method are encrypted and signed. Therefore, the rationale specified under item e of VE09.30.01 is not applicable. The operator transmits proprietary commands to the CM to initiate a rebuild process that zeroizes and regenerates the symmetric and asymmetric key trees TCG Erase The TCG Erase method cryptographically erases user data by regenerating the Locking Range Key (LRK) and Media Encryption Key (MEK) associated with a data range. All SSPs within the scope of this zeroization method are encrypted and signed. Therefore, the rationale specified under item e of VE09.30.01 is not applicable. The operator transmits a command to the CM as to instruct the TPer to initiate a user data erasure process. Table 21: SSP Zeroization Methods FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 54 of 87 9.4 SSPs Name Description Size - Streng th Type - Catego ry Generated By Establis hed By Used By Admin Authority Key (Ka) The Ka key encrypts and decrypts UAKs and the UMK. 256 bits - 256 bits Derived Symmet ric Key - CSP Derived_Key_Generati on Decryption Encryption Admin SP Object Table An Admin SP Object Table stores data that binds a set of methods and access controls to data associated with an AdminSP. - - CSP Anybody User Access Key (UAKa) The Anybody Authority uses UAKa to decrypt the RAK of unlocked LBA bands. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Decryption Encryption BandMaster PIN (16 total) Authenticati on Credential PIN for a Locking SP BandMaster Authority. 96 to 256 bites - 96 to 256 bits Plaintex t - CSP Authority_Digest_Gen eration Derived_Key_Generati on BandMaster PIN Digest (16 total) Authenticate s BandMaster PIN. 256 bits - 256 bits Messag e Digest - CSP Authority_Digest_Gen eration Authority_Digest_Veri fication DRBG.Key Internal state associated with the [SP 800-90A] CTR_DRBG using AES- 256 256 bits - 256 bits Entrop y - CSP RBG RBG FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 55 of 87 Name Description Size - Streng th Type - Catego ry Generated By Establis hed By Used By DRBG.Seed Internal state associated with the [SP 800-90A] CTR_DRBG using AES- 256. 5120 bits - 527.36 bits Entrop y - CSP Entropy RBG Seeding DRBG.V Internal state associated with the [SP 800-90A] CTR_DRBG using AES- 256. 128 bits - 128 bits Entrop y - CSP RBG RBG EraseMaster PIN Authenticati on Credential PIN for a Locking SP EraseMaster Authority. 96 to 256 bites - 96 to 256 bits Plaintex t - CSP Authority_Digest_Gen eration Derived_Key_Generati on EraseMaster PIN Digest Authenticate s EraseMaster PIN. 256 bits - 256 bits Messag e Digest - CSP Authority_Digest_Gen eration Authority_Digest_Veri fication ESV Entropy source input to the [SP 800-90A] CTR_DRBG 32-bit sample - 3.296 bits per 32- bit sample Entrop y - CSP Entropy Global Active Encryption Key (AEK) The Global Active Encryption Key encrypts and decrypts the SED Active Keyset, NSK and the UAKa key. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Decryption Encryption Global Active Signing Key Signs the encrypted SED Active 256 bits - Symmet ric Key - CSP Symmetric_Key_Gene ration Keyed_Digest_Generat ion FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 56 of 87 Name Description Size - Streng th Type - Catego ry Generated By Establis hed By Used By Encryption Key and SED Active Signing Key. 256 bits KDF Salt (EraseMaster and BandMaster unique) KDF Salts are integral to the PBKDF2 generation of each Ka and Ku derived authority key. 256 bits - 256 bits Symmet ric Key - PSP Symmetric_Key_Gene ration Derived_Key_Generati on Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique) LRKs in combination with the NSKs derive MEKs, which encrypt LBA bands. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration MEK Generation Locking SP Object Table (EraseMaster and BandMaster unique) Locking SP Object Tables store configuration data and CSPs that bind a set of methods and access controls to a Locking SP. - - CSP MEK - Media Encryption Keyset MEK.AESEn c Key MEK.AESD ec Key MEK.XTS Tweak Key (BandMaster unique) MEKs encrypt and decrypt LBA bands. An MEK.AESD ec key is the last entry of the key schedule for an MEK.AESE nc key. 256 bits - 256 bits Derived Symmet ric Key - CSP MEK Generation User_Data_Decryption User_Data_Encryption FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 57 of 87 Name Description Size - Streng th Type - Catego ry Generated By Establis hed By Used By MSID The MSID string is the default password for the SID, EraseMaster and BandMaster authorities. Stored during the manufacturin g process, the CM generates this thirty- two- character value by processing a CTR-DRBG generated random number through an Alphanumeri c Character Conversion algorithm. The algorithm draws from a thirty-four- element character set to generate the MSID. 256 bits - 162.8 bits Plaintex t - PSP Symmetric_Key_Gene ration Authority_Digest_Gen eration MSID Digest Authenticate s the MSID PIN 256 bits - 256 bits Messag e Digest - CSP Authority_Digest_Gen eration Authority_Digest_Veri fication Namespace Keyset (NSK) NSK.AES Key NSK.XTS NSKs in combination with the LRKs derive MEKs, which 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration MEK Generation FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 58 of 87 Name Description Size - Streng th Type - Catego ry Generated By Establis hed By Used By Key (BandMaster unique) encrypt LBA bands Non-Admin Authority Key (Ku) (BandMaster unique) Ku keys encrypt and decrypt all UAKs except UAKa. 256 bits - 256 bits Derived Symmet ric Key - CSP Derived_Key_Generati on Decryption Encryption OEM Firmware Key (OEM_FW Key) The OEM_FW Key verifies the overall download firmware image and packages. 2048- bits - 112 bits Public Key - Neither FW_Integrity OEM Original Factory State Key (OEM_OFS Key) The OEM_OFS Key verifies the OEM Original Factory Settings files. 2048- bits - 112 bits Public Key - Neither FW_Integrity OEM_Releas e Key (OEM_Relea se Key) The OEM_Relea se Key verifies the outer signature of an OEM firmware package. 2048- bits - 112 bits Public Key - Neither FW_Integrity Product Group Key (PROD_GR OUP Key) The PROD_GR OUP Key verifies OEM_FW Key certificates. 2048- bits - 112 bits Public Key - Neither FW_Integrity PSID The PSID string serves as authenticatio n data and 256 bits - 162.8 bits Plaintex t - PSP Symmetric_Key_Gene ration Authority_Digest_Gen eration FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 59 of 87 Name Description Size - Streng th Type - Catego ry Generated By Establis hed By Used By proof of physical presence for the Revert and RevertSP services. Stored during the manufacturin g process, the CM generates this thirty- two- character value by processing a CTR-DRBG generated random number through an Alphanumeri c Character Conversion algorithm. The algorithm draws from a thirty-four- element character set to generate the PSID. PSID Digest Authenticate s the PSID 256 bits - 256 bits Messag e Digest - CSP Authority_Digest_Gen eration Authority_Digest_Veri fication Range Access Key (RAK) (BandMaster unique) RAKs encrypt and decrypt LRKs. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Decryption Encryption Root Encryption Key The Root Encryption Key encrypts the Global 256 bits - Symmet ric Key - CSP Symmetric_Key_Gene ration Decryption Encryption FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 60 of 87 Name Description Size - Streng th Type - Catego ry Generated By Establis hed By Used By Active Encryption Key, Global Active Signing Key. 256 bits Root Signing Key Signs the encrypted Global Active Encryption Key, Global Active Signing Key. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Keyed_Digest_Generat ion Security Core Firmware Key (SC_FW Key) The SC_FW Key verifies Access Control Module (ACM) security core firmware. 2048 bits - 112 bits Public Key - Neither FW_Integrity Security Protocol Firmware Key (SP_FW Key) The SP_FW Key verifies ACM security protocol and services firmware. 2048- bits - 112 bits Public Key - Neither FW_Integrity SED Active Encryption Key Encrypts and decrypts the SED AdminSP Keyset and the SED LockingSP Keyset. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Encryption Decryption SED Active Signing Key Signs the encrypted SED AdminSP Keyset and the SED LockingSP Keyset. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Keyed_Digest_Generat ion FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 61 of 87 Name Description Size - Streng th Type - Catego ry Generated By Establis hed By Used By SED AdminSP Active Encryption Key Encrypts and decrypts CSPs associated with an Admin SP. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Encryption Decryption SED AdminSP Active Signing Key Signs encrypted CSPs associated with an Admin SP. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Keyed_Digest_Generat ion SED LockingSP Active Encryption Key Encrypts and decrypts CSPs associated with a Locking SP. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Encryption Decryption SED LockingSP Active Signing Key Signs encrypted CSPs associated with a Locking SP. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Keyed_Digest_Generat ion Authority_Digest_Gen eration SED Volatile Encryption Key Encrypts, and decrypts LRKs and MEKs. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Decryption Encryption SED Volatile Signing Key Signs encrypted LRKs and MEKs. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Keyed_Digest_Generat ion SID PIN Authenticati on Credential PIN for the Admin SP SID Authority. 96 to 256 bits - 96 to 256 bits Plaintex t - CSP Authority_Digest_Gen eration SID PIN Digest Authenticate s the SID PIN. 256 bits - 256 bits Messag e Digest - CSP Authority_Digest_Gen eration Authority_Digest_Veri fication FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 62 of 87 Name Description Size - Streng th Type - Catego ry Generated By Establis hed By Used By Storage Device Boot FW Key (SD_BFW Key) The SD_BFW Key is public key used to verify all boot flash images. 2048- bits - 112 bits Public Key - Neither FW_Integrity Storage Device Certification Authority Key (SD_CA Key) The SD_CA Key is the Master RSA 2048 public key used to verify the Secure Loader image. 2048- bits - 112 bits Public Key - Neither FW_Integrity Storage Device Secure Message Key (SD_SM Key) The SD_SM Key verifies secure messages used for manufacturin g, development , and failure analysis. 2048 bits - 112 bits Public Key - Neither FW_Integrity User Access Key (UAK) (BandMaster unique) Encrypts and decrypts the RAK associated with a BandMasters . 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Encryption Decryption User Management Key (UMK) Encrypts and decrypts UAKs. 256 bits - 256 bits Symmet ric Key - CSP Symmetric_Key_Gene ration Encryption Decryption Table 22: SSP Table 1 FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 63 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs Admin Authority Key (Ka) IRAM:Plaintext Ephemeral Destroyed after use. User Access Key (UAK) (BandMaster unique):Encrypts User Management Key (UMK):Encrypts User Access Key (UAK) (BandMaster unique):Decrypts User Management Key (UMK):Decrypts EraseMaster PIN:Derived From KDF Salt (EraseMaster and BandMaster unique):Derived From Admin SP Object Table IRAM:Plaintext Disk Media (Reserved Area):Encrypted Power up to power down Revert RevertSP Power Cycle SED AdminSP Active Encryption Key:Encrypted by SED AdminSP Active Signing Key:Signed by Anybody User Access Key (UAKa) Disk Media (Reserved Area):Encrypted IRAM:Plaintext Power up to power down Power Cycle Revert RevertSP Range Access Key (RAK) (BandMaster unique):Decrypts Range Access Key (RAK) (BandMaster unique):Encrypts Global Active Encryption Key (AEK):Encrypted by Global Active Encryption Key (AEK):Decrypted by BandMaster PIN (16 total) Authentication Credential PIN IRAM:Plaintext Ephemeral Destroyed after use. Power Cycle SED LockingSP Active Signing Key:Used with BandMaster PIN Digest (16 total):Used to generate KDF Salt FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 64 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs (EraseMaster and BandMaster unique):Used with Non-Admin Authority Key (Ku) (BandMaster unique):Derives BandMaster PIN Digest (16 total) Disk Media (Reserved Area):Encrypted Revert RevertSP BandMaster PIN (16 total):Generated from SED LockingSP Active Signing Key:Generated from DRBG.Key IRAM:Plaintext Power up to power down Power Cycle DRBG.Seed:Used with DRBG.V:Used with DRBG.Seed IRAM:Plaintext Power up to power down Power Cycle DRBG.V:Used with DRBG.Key:Used with DRBG.V IRAM:Plaintext Power up to power down Power Cycle DRBG.Seed:Used with DRBG.Key:Used with EraseMaster PIN Authentication Credential PIN IRAM:Plaintext Ephemeral Destroyed after use. Power Cycle EraseMaster PIN Digest:Derives KDF Salt (EraseMaster and BandMaster unique):Used with Admin Authority Key (Ka):Derives SED LockingSP Active Signing Key:Used with EraseMaster PIN Digest Disk Media (Reserved Area):Encrypted Revert RevertSP EraseMaster PIN (16 total):Derived from SED LockingSP Active Signing Key:Derived from ESV IRAM:Plaintext Power up to power down Power Cycle DRBG.Seed:Used with FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 65 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs Global Active Encryption Key (AEK) NOR Flash(Reserved area):Encrypted Secure Manufacturing Reconfiguration Process SED Active Encryption Key:Encrypts SED Active Encryption Keyy:Decrypts SED Active Signing Key:Encrypts SED Active Signing Key:Decrypts Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique):Encrypts Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique):Decrypts Root Encryption Key:Encrypted By Root Encryption Key:Decrypted By Root Signing Key:Signed By Anybody User Access Key (UAKa):Encrypts Anybody User Access Key (UAKa):Decrypts Global Active Signing Key NOR Flash(Reserved area):Encrypted Secure Manufacturing Reconfiguration Process Root Encryption Key:Encrypts SED Active Encryption Key:Signs the SED Active Signing Key:Signs the Root Signing Key:Signed by KDF Salt (EraseMaster and BandMaster unique) Disk Media (Reserved Area):Plaintext Revert RevertSP BandMaster PIN (16 total):Used with Non-Admin Authority Key (Ku) (BandMaster unique):Derives EraseMaster FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 66 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs PIN:Used with Admin Authority Key (Ka):Derives Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique) DRAM:Encrypted Disk Media (Reserved Area):Encrypted Generation to power down Power Cycle Revert RevertSP TCG Erase Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique):Used with MEK - Media Encryption Keyset MEK.AESEnc Key MEK.AESDec Key MEK.XTS Tweak Key (BandMaster unique):Generates SED Volatile Encryption Key:Encrypted by Range Access Key (RAK) (BandMaster unique):Encrypts SED Volatile Encryption Key:Decrypted by Range Access Key (RAK) (BandMaster unique):Decrypts Locking SP Object Table (EraseMaster and BandMaster unique) IRAM:Plaintext Disk Media (Reserved Area):Encrypted Power Up to Power Down Power Cycle Revert RevertSP SED LockingSP Active Encryption Key:Encrypted by SED LockingSP Active Encryption Key:Decrypted by SED LockingSP Active Signing Key:Signed by MEK - Media Encryption Keyset MEK.AESEnc Key MEK.AESDec Key MEK.XTS Tweak Key (BandMaster unique) DRAM:Encrypted Generation to power down Power Cycle Revert RevertSP TCG Erase Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique):Generated from Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique):Generated FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 67 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs from SED Volatile Encryption Key:Encrypted by SED Volatile Encryption Key:Decrypted by MSID Authentication Credential PIN IRAM:Plaintext NOR Flash(Reserved area):Plaintext Ephemeral Destroyed after use. SED Active Signing Key:Used With MSID Digest:Generates MSID Digest Disk Media (Reserved Area):Plaintext Revert RevertSP MSID:Generated from SED Active Signing Key:Generated from Namespace Keyset (NSK) NSK.AES Key NSK.XTS Key (BandMaster unique) DRAM:Encrypted Disk Media (Reserved Area):Encrypted Generation to power down. Power Cycle Revert RevertSP Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique):Used with MEK - Media Encryption Keyset MEK.AESEnc Key MEK.AESDec Key MEK.XTS Tweak Key (BandMaster unique):Generate Global Active Encryption Key (AEK):Encrypted by Global Active Encryption Key (AEK):Decrypted by Non-Admin Authority Key (Ku) (BandMaster unique) Ephemeral Destroyed after use. BandMaster PIN:Derived From KDF Salt (EraseMaster and BandMaster unique):Derived From User Access Key (UAK) (BandMaster unique):Encrypts FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 68 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs User Access Key (UAK) (BandMaster unique):Decrypts OEM Firmware Key (OEM_FW Key) NOR Flash(Reserved area):Encrypted Product Group Key (PROD_GROUP Key):Verified by OEM Original Factory State Key (OEM_OFS Key) NOR Flash(Reserved area):Encrypted Product Group Key (PROD_GROUP Key):Verified by OEM_Release Key (OEM_Release Key) NOR Flash(Reserved area):Encrypted Product Group Key (PROD_GROUP Key):Verified by Product Group Key (PROD_GROUP Key) NOR Flash(Reserved area):Encrypted Storage Device Certification Authority Key (SD_CA Key):Verified By PSID Authentication Credential PIN IRAM:Plaintext NOR Flash(Reserved area):Encrypted Generation to power down. Power Cycle SED Active Signing Key:Used With PSID Digest:Generate SED Active Encryption Key:Encrypted by SED Active Encryption Key:Decrypted by PSID Digest Disk Media (Reserved Area):Plaintext Revert RevertSP PSID:Generated from SED Active Signing Key:Generated from Range Access Key (RAK) (BandMaster unique) Disk Media (Reserved Area):Encrypted Revert RevertSP User Access Key (UAK) (BandMaster unique):Encrypted by User Access Key (UAK) (BandMaster unique):Decrypted by Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique):Encrypts FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 69 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique):Decrypts Root Encryption Key One-time Programable (OTP):Plaintext Secure Manufacturing Reconfiguration Process Global Active Encryption Key (AEK):Encrypts Global Active Signing Key:Encrypts Global Active Encryption Key (AEK):Decrypts Global Active Signing Key:Decrypts Root Signing Key One-time Programable (OTP):Plaintext Secure Manufacturing Reconfiguration Process Global Active Encryption Key (AEK):Signs Security Core Firmware Key (SC_FW Key) NOR Flash(Reserved area):Encrypted Storage Device Certification Authority Key (SD_CA Key):Verified by Security Protocol Firmware Key (SP_FW Key) NOR Flash(Reserved area):Encrypted Storage Device Certification Authority Key (SD_CA Key):Verified by SED Active Encryption Key NOR Flash(Reserved area):Encrypted Revert RevertSP SED AdminSP Active Encryption Key:Encrypts SED AdminSP Active Signing Key:Encrypts SED LockingSP Active Signing Key:Encrypts SED LockingSP Active Encryption Key:Encrypts SED AdminSP Active Encryption Key:Decrypts FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 70 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs SED AdminSP Active Signing Key:Decrypts SED LockingSP Active Signing Key:Decrypts SED LockingSP Active Encryption Key:Decrypts Global Active Encryption Key (AEK):Encrypted by Global Active Encryption Key (AEK):Decrypted by Global Active Signing Key:Signed by SED Active Signing Key NOR Flash(Reserved area):Encrypted Revert RevertSP SED AdminSP Active Encryption Key:Signs SED AdminSP Active Signing Key:Signs SED LockingSP Active Encryption Key:Signs SED LockingSP Active Signing Key:Signs Global Active Encryption Key:Encrypted by Global Active Encryption Key:Decrypted by Global Active Signing Key:Signed by MSID Digest:Generates SED AdminSP Active Encryption Key NOR Flash(Reserved area):Encrypted Revert RevertSP AdminSP Object Table:Encrypts AdminSP Object Table:Decrypts SED Active FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 71 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs Encryption Key:Encrypted by SED Active Encryption Key:Decrypted by SED Active Signing Key:Signed by SED AdminSP Active Signing Key NOR Flash(Reserved area):Encrypted Revert RevertSP AdminSP Object Table:Signs SED Active Encryption Key:Encrypted by SED Active Encryption Key:Decrypted by SED Active Signing Key:Signed by SID PIN:Used with SID PIN Digest:Generates SED LockingSP Active Encryption Key NOR Flash(Reserved area):Encrypted Revert RevertSP Locking SP Object Table (EraseMaster and BandMaster unique):Encrypts Locking SP Object Table (EraseMaster and BandMaster unique):Decrypts SED Active Encryption Key:Encrypted by SED Active Encryption Key:Decrypted by SED Active Signing Key:Signed by SED LockingSP Active Signing Key NOR Flash(Reserved area):Encrypted Revert RevertSP Locking SP Object Table (EraseMaster and BandMaster unique):Signs SED Active Encryption Key:Encrypted by SED Active Encryption Key:Decrypted by SED Active Signing Key:Signed by FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 72 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs BandMaster PIN (16 total):Used with EraseMaster PIN:Used with BandMaster PIN Digest (16 total):Generates EraseMaster PIN Digest:Generates SED Volatile Encryption Key IRAM:Plaintext Power up to power down Power Cycle Revert RevertSP Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique):Encrypts MEK - Media Encryption Keyset MEK.AESEnc Key MEK.AESDec Key MEK.XTS Tweak Key (BandMaster unique):Encrypts Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique):Decrypts MEK - Media Encryption Keyset MEK.AESEnc Key MEK.AESDec Key MEK.XTS Tweak Key (BandMaster unique):Decrypts SED Volatile Signing Key IRAM:Plaintext Power up to power down Power Cycle Revert RevertSP Locking Range Keyset (LRK) LRK.AES Key LRK.XTS Key (BandMaster unique):Signs MEK - Media Encryption Keyset MEK.AESEnc Key MEK.AESDec Key MEK.XTS Tweak Key (BandMaster unique):Signs FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 73 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs SID PIN IRAM:Plaintext Ephemeral Destroyed after use SED AdminSP Active Signing Key:Used With SID PIN Digest:Generate the SID PIN Digest Disk Media (Reserved Area):Plaintext Revert RevertSP SID PIN:Generated from SED AdminSP Active Signing Key:Generated from Storage Device Boot FW Key (SD_BFW Key) NOR Flash(Reserved area):Encrypted Storage Device Certification Authority Key (SD_CA Key):Verifies Storage Device Certification Authority Key (SD_CA Key) NOR Flash(Reserved area):Plaintext One-time Programable (OTP):Encrypted Storage Device Boot FW Key (SD_BFW Key):Verifies Storage Device Secure Message Key (SD_SM Key):Verifies Security Core Firmware Key (SC_FW Key):Verifies Security Protocol Firmware Key (SP_FW Key):Verifies Product Group Key (PROD_GROUP Key):Verifies Storage Device Secure Message Key (SD_SM Key) NOR Flash(Reserved area):Encrypted Storage Device Certification Authority Key (SD_CA Key):Verified by User Access Key (UAK) (BandMaster unique) Disk Media (Reserved Area):Encrypted Revert RevertSP Range Access Key (RAK) (BandMaster unique):Encrypts Range Access Key (RAK) (BandMaster unique):Decrypts Non-Admin FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 74 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs Authority Key (Ku) (BandMaster unique):Encrypted by User Management Key (UMK) Disk Media (Reserved Area):Encrypted Revert RevertSP User Access Key (UAK) (BandMaster unique):Encrypts User Access Key (UAK) (BandMaster unique):Decrypts Admin Authority Key (Ka):Encrypted by Table 23: SSP Table 2 10 Self-Tests The Cryptographic Module performs pre-operational self-tests automatically at powered up or in response to a self- initiated reset. The Cryptographic Module executes conditional self-tests at powered up and after installing a new firmware image. Pre-operational self-tests tests ensure that the Cryptographic Module detects a corrupt condition. Conditional self-tests ensure , that the Cryptographic Module detects malfunctioning or compromised cryptographic algorithm implementation. The Cryptographic Module inhibits all data output via the “data output” interface and the execution of loaded or modified approved security functions while executing the pre-operational self-tests. 10.1 Pre-Operational Self-Tests Cryptographic Module The Cryptographic Module performs the pre-operational self-test listed in the CM Pre-Operational Self-Tests table. Upon failure the Cryptographic Module, with exception of the ESV self-tests, transitions to a Device Unavailable error state: Algorithm or Test Test Properties Test Method Test Type Indicator Details ESV Startup APT (Cert #E212) Adaptive Proportion Test (APT) SP 800-90B Health-Test Critical Function Pass: Next test, Fail: Device Unavailable Verifies that the APT Threshold was not exceeded as specified in [SP 800 90B] ESV Startup RCT (Cert #E212) Repetition Count Test (RCT) SP 800-90B Health-Test Critical Function Pass: Next test, Fail: Device Unavailable Verifies that the RCT Threshold was not exceeded as specified in [SP 800 90B] Firmware Integrity Test RSA SigVer 2048-bit PKCS v1.5 w/SHA2- Digital Signature Verification SW/FW Integrity Pass: Boot to the firmware image, Verify Digital Signature FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 75 of 87 Algorithm or Test Test Properties Test Method Test Type Indicator Details 256 (Cert # A1390, Cert #SHS 2942) Fail: Device Unavailable Table 24: Pre-Operational Self-Tests 10.2 Conditional Self-Tests Cryptographic Module Conditional Self-Tests The Cryptographic Module performs the conditional self-tests listed in the CM Conditional Self-Tests table. Upon failure the Cryptographic Module, with exception of the ESV self-tests, transitions to a Device Degraded error state. Conditional ENT self-test failures cause the CM to transition to a Device Unavailable error state. Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions AES-CBC Encrypt (AES 3580) AES, 256-bit, CBC KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Encrypt, verify Power up AES-CBC Decrypt (AES 3580) AES, 256-bit, CBC KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Decrypt, verify Power up AES-ECB Encrypt (AES 3580) AES, 256-bit, ECB KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Encrypt, verify Power up AES-ECB Decrypt (AES 3580) AES, 256-bit, ECB KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Decrypt, verify Power up AES-ECB Encrypt (A670) AES, 256-bit, ECB, DEE KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Encrypt, verify Power up AES-ECB Decrypt (A670) AES, 256-bit, ECB, DEE KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Decrypt, verify Power up AES-XTS (A670) AES, 256-bit, XTS Non- equivalence test Critical Function Pass: Success Indicator/Next test Fail: Device Degraded verify LRK and NSK generation Counter DRBG (A1390) 5120-bit seed KAT CAST Pass: Success Indicator/Next test Fail: Device SP 800- 90ARev1 section 11.3 Power up FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 76 of 87 Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions Unavailable Error health test (Instantiate, generate and reseed) ESV APT Adaptive Proportion Test (APT) APT Health Test CAST Pass: Success Indicator/Next test Fail: Device Unavailable Verifies that the APT threshold was not exceeded as specified in [SP 800 90B] Power up and After the CTR_DRBG generates 232 keys. ESV RCT Repetition Count Test (RCT) RCT Health Test CAST Pass: Success Indicator/Next test Fail: Device Unavailable Verifies that the RCT threshold was not exceeded as specified in [SP 800 90B] Power up and After the CTR_DRBG generates 232 keys. HMAC- SHA2-256 (HMAC 2280) Message, 256-bit key, 256-bit hash digest KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Verify Power up PBKDF (A1390) 256-bit Salt Iteration Count: 1024 KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Verify Power up RSA SigVer (FIPS186-4) (A1390) 2048-bit public key, 256-bit hash digest KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Verify Power up RSA SigVer FW Load Test (FIPS186-4) (A1390) 2048-bit public key, 256-bit hash digest, OEM_Release Key Digital Signature Verification SW/FW Load Pass: Boot to new image Fail: UEC error code Verify Firmware Download SHA2-256 (SHS 2942) Message, 256-bit hash digest KAT CAST Pass: Success Indicator/Next test Fail: Device Degraded Verify Power up Table 25: Conditional Self-Tests 10.3 Periodic Self-Test Information The Cryptographic Module enforces a policy that results in the interruption of the module’s operations due to a periodic self-test. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 77 of 87 Algorithm or Test Test Method Test Type Period Periodic Method ESV Startup APT (Cert #E212) SP 800-90B Health- Test Critical Function On Demand Manually ESV Startup RCT (Cert #E212) SP 800-90B Health- Test Critical Function On Demand Manually Firmware Integrity Test Digital Signature Verification SW/FW Integrity On Demand Manually Table 26: Pre-Operational Periodic Information Algorithm or Test Test Method Test Type Period Periodic Method AES-CBC Encrypt (AES 3580) KAT CAST On Demand Manually AES-CBC Decrypt (AES 3580) KAT CAST On Demand Manually AES-ECB Encrypt (AES 3580) KAT CAST On Demand Manually AES-ECB Decrypt (AES 3580) KAT CAST On Demand Manually AES-ECB Encrypt (A670) KAT CAST On Demand Manually AES-ECB Decrypt (A670) KAT CAST On Demand Manually AES-XTS (A670) Non-equivalence test Critical Function On Demand Programmatically Counter DRBG (A1390) KAT CAST On Demand Manually ESV APT APT Health Test CAST On Demand Manualy and Programmatically ESV RCT RCT Health Test CAST On Demand Manualy and Programmatically HMAC-SHA2-256 (HMAC 2280) KAT CAST On Demand Manually PBKDF (A1390) KAT CAST On Demand Manually RSA SigVer (FIPS186-4) (A1390) KAT CAST On Demand Manually RSA SigVer FW Load Test (FIPS186- 4) (A1390) Digital Signature Verification SW/FW Load On Demand Programmatically FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 78 of 87 Algorithm or Test Test Method Test Type Period Periodic Method SHA2-256 (SHS 2942) KAT CAST On Demand Manually Table 27: Conditional Periodic Information 10.4 Error States Name Description Conditions Recovery Method Indicator Device Degraded This error indicates that one of the conditional self- tests listed in Table 20 failed. In this state, the module no longer services any I/O command. The module only responds to non-I/O status inquiry commands. Conditional test failure Power cycle UEC failure code Device Unavailable This error indicates that a boot initialization, security subsystem initialization or firmware integrity failure event occurred. See Table 19. In this state, the module no longer responds to any operator commands. Pre- operational test failure Power cycle Module is unresponsive Table 28: Error States 10.5 Operator Initiated Self-Tests The operator may initiate an on-demand periodic self-test by power cycling the CM. 11 Life-Cycle Assurance 11.1 Installation, Initialization and Startup Procedures After initialization, the CM operates and powers up in isFIPS mode. Prior to configuring the CM to comply with isFIPS mode configuration requirements, it operates in a noncompliant state. Regardless, the CM functions as a Secure Erase Drive (SED) that is compliant with the TCG Storage SSC: Enterprise Specification [TCG Enterprise]. Installation and Initialisation: The Crypto Officer is responsible for executing a Take-Ownership scenario to configure the Cryptographic Module to operationally comply with operator site requirements and assure that the Cryptographic Module is compliant with FIPS 140-3 at SL2. Informative Having the MSID Authentication Credential PIN electronically available to the operator may constitute an overall security risk to the of the Cryptographic Module. Therefore, the Crypto Officer should execute a Take-Ownership scenario the first time the Cryptographic Module is inserted into a system that replaces Authentication Credential PIN values that are set to the module unique MSID value with a value, between 12 and 32 bytes in length, which is different from the unique MSID value. This assures compliance with ISO/IEC19790, Section 7.4.4 and IG 4.4.B. Take-Ownership Scenario Example 1. Authenticate to the SID. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 79 of 87 a. If the CM authenticated to the SID with the module unique MSID value, change the SID PIN to a random value between 12 and 32 bytes in length. 2. Use the Get service to determine if the logical firmware download port is set to lock on PowerCycle. a. If the logical firmware download port’s LockOnReset attribute is not set to PowerCycle utilize the Set service to set the LockOnReset attribute to PowerCycle. 3. Authenticate to each BandMaster that is within the scope of the operator site requirements. a. If the CM authenticated to a BandMaster with the module unique MSID value, change the BandMaster PIN to a random value between 12 and 32 bytes in length. b. Utilize the Get Band Attributes service to determine the state of a BandMaster’s LockOnReset attribute. If the LockOnReset attribute is not set to PowerCycle, use the Set Band Attribute service to set the LockOnReset attribute to PowerCycle. c. Utilize the Get Band Attributes service to determine the state of a BandMaster’s ReadLockEnabled attribute. If the ReadLockEnabled attribute is set to False, use the Set Band Attribute service to set the ReadLockEnabled attribute to True. d. Utilize the Get Band Attributes service to determine the state of a BandMaster’s WriteLockEnabled attribute. If the WriteLockEnabled attribute is set to False, use the Set Band Attribute service to set the WriteLockEnabled attribute to True. 4. Authenticate to the EraseMaster. a. If the CM authenticated to the EraseMaster with the module unique MSID value, change the EraseMaster PIN to a random value between 12 and 32 bytes in length. Delivery: The Cryptographic Officer shall inspect the tamper evident seal that covers the Cryptographic Module’s PCBA for evidence of tampering. See Figure 8 for an example of tamper evidence. If tamper evidence is apparent, the CO should return the module to Western Digital. 11.2 Administrator Guidance Hard disk drives are fragile. Do not drop or jar the drive. Hold the drive only by the enclosure. HDD electronics are sensitive to static electricity. Do not remove the CM from its antistatic container until ready to install. The operator engaged in the installation process should wear a grounded antistatic wrist strap to assure the discharge of static electricity from any item or surface that my touch the CM. Hold the drive only by the metal case surrounding the drive. Avoid contacting with the SAS connector. To assure proper installation and operation, verify all cooling requirements are met prior to initiating the installation instructions within the Ultrastar DC HC555 3.5-inch Serial Attached SCSI Hard Disk Drive Specification [Product Manual]. The Ultrastar DC HC555 3.5-inch Serial Attached SCSI Hard Disk Drive Specification [Product Manual] provides additional administrator guidance. 11.3 Non-Administrator Guidance Inspect the CM for damage to the case or SAS connector. If the CM exhibits damage, return the CM to Western Digital for warranty replacement service. The Ultrastar DC HC555 3.5-inch Serial Attached SCSI Hard Disk Drive Specification [Product Manual] provides non-administrator guidance. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 80 of 87 11.4 Design and Rules On power-up, if previously configured to comply with isFIPS mode, the Cryptographic Module automatically initializes to isFIPS mode without operator intervention. After successfully completing pre-operational and conditional self-tests, the CM transitions to an Approved mode operational state. In this state, the module awaits service requests from the operator. The implemented security features protect against remote and physical attacks across the complete product cycle from manufacturing build time to returns and failure analysis. The secure firmware boot and firmware download process assure firmware image integrity and prevents compromised firmware attacks. These features prevent the counterfeiting of the CM, hacking, and unauthorized access to CM ports. The authentication scheme enforces port access restrictions that are only allowed within a secure manufacturing environment. When outside a secure manufacturing environment, the CM blocks access to process that are only allowed within a secure manufacturing environment. These security features utilize cryptographically secure messages to block unauthorized access to CM ports and imposes manufacturing command set restrictions. The CM utilizes a cryptographic encryption and HMAC signing scheme to assure the protection of all SSPs stored outside the ACM. Rules of Operation 1. The Module provides two distinct operator roles: User and Cryptographic Officer. 2. The Module provides role-based authentication. 3. On power cycle the Module clears previous authentications. 4. The Module complies with the lock-based authentication model defined in IG 4.1.A. On power cycle, the Module locks unlocked services that require authentication to unlock. 5. Accept as allowed under the lock-based authentication model, the operator does not have access to any cryptographic services prior to assuming an authorized role. 6. The Module allows the operator to initiate power-up self-tests by power cycling power or resetting the Module. 7. All self-tests do not require any operator action. 8. The Cryptographic Module inhibits data output during key generation, self-tests, zeroization, and error states. 9. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module. 10. The Module implements multiple zeroisation service that vary in scope. The SSP Zeroization Methods table defines scope of each zeroisation service. 11. The Module does not support concurrent operators. 12. The Module does not support a maintenance interface or role. 13. The Module does not support a manual SSP establishment method. 14. The Module does not have any proprietary external input/output devices used for entry/output of data. 15. The Module does not enter or output plaintext CSPs. 16. The Module does not store any unprotected plaintext CSPs. 17. The Module does not output intermediate key values. 18. The Module does not provide bypass services or ports/interfaces. 11.5 Maintenance Requirements The CM does not require periodic maintenance actions to maintain functional or secure operation. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 81 of 87 11.6 End of Life All CSPs stored within the volatile memory of the CM’s ACM RoT are inaccessible from outside the ACM RoT. The CM encrypts and signs all CSPs before storing them in volatile or non-volatile memory outside ACM RoT. Removing power instantaneously erases all CSPs stored within the CM’s volatile memory. Prior to the environmentally disposal of the CM owner should cryptographically erase the CM. For this purpose, the CM supports the TCG Opal Revert method [TCG Opal]. Revert enables the CM’s owner to cryptographically erase all CSPs and overwrite existing TCG settings to the default values that were set during manufacturing. If environmental disposal requirements require the zeroization of the Root Keyset, which consists of the Root Encryption Key and Root Signing Key, the CM owner must return the CM to Western Digital. Western Digital’s proprietary Secure Manufacturing Reconfiguration Process supports Root Keyset zeroization. 12 Mitigation of Other Attacks The Cryptographic Module lacks features to mitigate any specific attacks beyond the scope of the requirements within FIPS 140-3 SL2. 13 References and Definitions The Security Policy refers to the following specifications, references, and definitions. 13.1 NIST Specifications Abbreviation** Specification Name [FIPS 197] Advanced Encryption Standard, FIPS PUB 197, NIST, May 2023 [FIPS 186] Digital Signature Standard, FIPS PUB 186-5, NIST, July 2013 [FIPS 140] Security Requirements for Cryptographic Modules, FIPS PUB 140-3, NIST, March 2019 [FIPS 140 IG] Implementation Guidance for FIPS 140-3 and the Cryptographic Module Validation Program, September 2025 [FIPS 198] The Keyed-Hash Message Authentication Code, FIPS PUB 198-1, July 2008 [FIPS 180] Secure Hash Standard (SHS), FIPS PUB 180-4, NIST, August 2015 [SP 800 38A] Recommendation for Block Cipher Modes of Operation: Methods and Techniques, NIST, December 2001 [SP 800 38E] Recommendation for Block Cipher Modes of Operation: The XTS-AES Mode for Confidentiality on Storage Devices, NIST, January 2010 [SP 800 57] Recommendation for Key Management – Part I General (Revision 5), NIST, May 2020 [SP 800 88] Guidelines for Media Sanitization (Revision 1), NIST, December 2014 [SP 800 90A] Recommendation for Random Number Generation Using Deterministic Random Bit Generators (Revision 1), NIST, June 2015 [SP 800 90B] Recommendation for the Entropy Sources Used for Random Bit Generation, NIST, January 2018 [SP 800 131A] Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths (Revision 2), NIST, March 2019 [SP 800 132] Recommendation for Password-Based Key Derivation, NIST, December 2010 [SP 800 133] Recommendation for Cryptographic Key Generation (Revision 2), NIST, June 2020 [SP 800 140B] Cryptographic Module Validation Program (CMVP) Security Policy Requirements: CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B (Revision 1), NIST, November 2023 [SP 800 140C] CMVP Approved Security Functions: CMVP Validation Authority Updates to ISO/IEC 24759 (Revision 2), NIST, July 2023 FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 82 of 87 Abbreviation** Specification Name [SP 800 140D] CMVP Approved Sensitive Security Parameter Generation and Establishment Methods: CMVP Validation Authority Updates to ISO/IEC 24759 (Revision 2), NIST, July 2023 13.2 Trusted Computing Group Specifications Abbreviation* Specification Name [TCG Core] TCG Storage Architecture Core Specification, Version 2.01 Revision 1.00 (August 5, 2015)) [TCG Enterprise] TCG Storage Security Subsystem Class: Enterprise Specification, Version 1.01 Revision 1.00 (August 5, 2015) [TCG Ent App Notes] TCG Storage Application Note: Encrypting Storage Devices Compliant with SSC: Enterprise, Version 1.00 Revision 1.00 Final [TCG Opal] TCG Storage Security Subsystem Class: Opal Specification, Version 2.01, Final Revision 1.00 (August 5, 2015) [TCG SIIS] TCG Storage Interface Interactions Specification (SIIS), Version 1.07, (January 30, 2018) [PSID] TCG Storage Opal SSC Feature Set: PSID, Specification Version 1.00, Final Revision 1.00 (August 5, 2015) 13.3 SCSI Specifications Abbreviation* Specification Name [SCSI Core] SCSI Primary Commands (SPC-6), Revision 6, October 2021 [SCSI Block] SCSI Block Commands (SBC-4), Revision 22, 29 September 2020 [SAS] Serial Attached SCSI (SAS-3), Revision 6, November 2013 [SFSC] Security Features for SCSI Commands, Revision 2, September 2015 13.4 Corporate References Abbreviation* Specification Name [Product Manual] Ultrastar DC HC555 3.5-inch Serial Attached SCSI Hard Disk Drive Specification, Version 1.0 (May 2024), https://www.westerndigital.com/support [Datasheet] Ultrastar DC HC555 Datasheet, (September 2024), https://www.westerndigital.com/support 13.5 Other References Abbreviation* Reference Name [IETF] IETF RFC 2119, 1997, “Key words for use in RFCs to Indicate Requirement Levels.” [PW] Calculating Password Entropy: https://www.pleacher.com/mp/mlessons/algebra/entropy.html [ISO 19790] ISO/IEC 19790, Information technology - Security techniques - Security requirements for cryptographic modules, International Organization for Standardization (ISO), December 2015 14 Definitions Name* Definition Access Control Entry (ACE) Access control entries are entries in an access control list containing information describing the access rights related to a particular security identifier or user. Access Control List (ACL) Access control list refers to the permissions attached to an object that specify which users have access to that object and the operations the user can perform. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 83 of 87 Name* Definition Allowed NIST approved, i.e., recommended in a NIST Special Publication, or acceptable, i.e., no known security risk as opposed to deprecated, restricted, and legacy use. [SP 800 131A] Anybody A formal TCG term for an unauthenticated role. [TCG Core] Approved mode of operation A mode of the Cryptographic Module that employs only approved security functions. [ISO 19790] Approved [ISO 19790] approved or recommended in a NIST Special Publication. Authenticate Prove the identity of an Operator or the integrity of an object. Authentication Credential PIN An authentication credential (i.e., a password) associated with the SID, Admin SP Admin1, Locking SP Admin or Locking SP User Authority as defined in the TCG Storage Security Subsystem Class Opal, Specification [TCG Core]. Authorize Grant an authenticated Operator access to a service or an object. Ciphertext Encrypted data transformed by an Approved security function. Confidentiality A cryptographic property that blocks disclosure of sensitive information to unauthorized parties. Credential A formal TCG term for data used to authenticate an Operator. [TCG Core] Critical Security Parameter (CSP) Security-related information (e.g., secret, and private cryptographic keys, and authentication data such as credentials and PINs) whose disclosure or modification can compromise the security of a Cryptographic Module. [ISO 19790] Crypto Officer An Operator performing cryptographic initialization and management functions. [ISO 19790] Cryptographic Boundary An explicitly defined perimeter that establishes the boundary of all components (i.e. set of hardware, software, or firmware components) of the cryptographic module. [ISO 19790] Cryptographic Key A sequence of symbols that controls the operation of a cryptographic transformation. A cryptographic transformation can include but not limited to encipherment, decipherment, cryptographic check function computation, signature generation, or signature verification. Cryptographic Module The set of hardware, software, and/or firmware used to implement approved security functions contained within the cryptographic boundary. [ISO 19790] CSP Blob The term CSP Blob is used to indicate an external stored object that contains one or more CSPs. The CSP Blob is a protected unit and contains metadata such as version and UID. The contents of the CSP Blob may be visible outside the ACM. Some contents may be hidden and encrypted outside the ACM boundary. In all cases, the CSP Blob is only modifiable from within the ACM. When CSPs are stored externally to the ACM and/or accepted from outside the ACM boundary, tamper protection is implemented. Secret keys are used to AES encrypt and HMAC-SHA256 sign the entire CSP Blob before being stored outside the ACM boundary. Data at Rest User data residing on the storage device media rather than in transition. Discovery A TCG method that provides the properties of the TCG device. [TCG Enterprise] Download and Execute module (DLE) The DLE verifies the OptiNAND firmware RSA signature. Field Firmware Update (sFFU) A secure Field Firmware Update replaces the firmware within an iNAND device. Global Active Keyset (AEK) Set defined by the 256-bit Global Active Encryption Key and the 256-bit Global Active Signing Key Hardware Security Module (HSM) A hardware security module is a physical computing device that safeguards and manages digital keys, performs encryption and decryption functions for digital signatures, strong authentication, and other cryptographic functions. IF-RECV An interface command used to retrieve security protocol data from the TPer [TCG Core]. IF-SEND An interface command used to transmit security protocol data to the TPer [TCG Core]. OptiNAND® A Universal Flash Storage (UFS) embedded flash device. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 84 of 87 Name* Definition Integrity A cryptographic property that blocks the modification or deletion of sensitive in an unauthorized and undetected manner. Interface A logical entry or exit point of a Cryptographic Module that provides access to the Cryptographic Module for logical information flows. [ISO 19790] Key Derivation Function (KDF) An Approved cryptographic algorithm that derives one or more keys from a secret value and other information. Key Encrypting Key (KEK) A cryptographic key used to encrypt or decrypt other keys. Key management The activities involving the handling of cryptographic keys and other related security parameters during the entire life cycle of the Cryptographic Module. The handling of authentication data is representative of a key management activity. Key Wrap An Approved cryptographic algorithm that uses a KEK to provide Confidentiality and Integrity. LBA Range A formal term that defines a contiguous logical block range (sequential LBAs) to store encrypted User Data; bands do not overlap, and each has its own unique encryption key and other settable properties. Manufactured SID (MSID) A unique module unique value assigned to each SED during manufacturing. An externally visible MSID value is not required if the user can derive the MSID from other information printed on the drive. The MSID is readable with the TCG protocol. It is the initial and module unique value for all Authentication Credentials. [TCG Core] Method A remote procedure call to an SP that initiates an action on the SP. [TCG Core] Object An object is any row of an object table. The object type is defined by the object table in which the object occurs. The columns of the object table define the contents of each object in it. [TCG Core] Object Table Object tables provide storage for data that binds a set of methods and access controls to that data. [TCG Core] ObjectUID The Unique ID (UID) of an Object. Each object table has a column named UID. This column contains an 8-byte unique identifier for that row. [TCG Core] OFS file The CM uses an OFS file to reset the Cryptographic Module’s configuration back to its original factory setting during Revert and RevertSP operations. One Time Programable (OTP) OTP memory is a special type of write once read only non-volatile memory. Operator A consumer, either human or automation, of cryptographic services that is external to the Cryptographic Module. [ISO 19790] Personal Identification Number (PIN) A formal TCG term designating a string of octets used to authenticate an identity. [TCG Core] Plaintext Unencrypted data. Port A physical entry or exit point of a Cryptographic Module that. A port provides access to the Cryptographic Module’s physical signals. [ISO 19790] PSID (Physical Security Identifier) A SED unique value printed on the Cryptographic Module’s label used as authentication data and proof of physical presence for the Zeroise Service. Public Security Parameters (PSP) Public information, that if modified can compromise the security of the Cryptographic Module (e.g., a public key). Read Data An external request to transfer User Data from the SED. [SCSI Block] Reserved Area Internal data on the storage medium within the cryptographic boundary that is not accessible to an operator. Root Keyset A set of 256-bit keys that consist of the Root Encryption Key and Root Signing Key. SD_CA Key Storage Device Certification Authority Key (X509v3). This key serves as the Cryptographic Module’s Master RSA Public Key and is the root source of verification for all other key certificates. The SD_CA Key signs the SecureLoader. A manufacturing process injects the SD_CA Key within the CM and stores a hash of the SD_CA Key in OTP memory Secure Field Firmware Update (sFFU) OptiNAND firmware update image. FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 85 of 87 Name* Definition Security Identifier (SID) The authority that represents the TPer owner. Crypto Officer serves in this role. [TCG Core] Security Provider (SP) A TCG term used to define a collection of Tables and Methods with access control. SED Active Keyset A set of 256-bit keys that consists of the SED Active Encryption Key and the SED Active Signing Key. SED AdminSP Active Keyset A set of 256-bit keys that consists of the SED AdminSP Active Encryption Key and the SED AdminSP Active Signing Key. SED Global Active Keyset A set of 256-bit keys that consists of the Global Active Encryption Key (AEK) and the Global Active Signing Key. SED LockingSP Active Keyset A set of 256-bit keys that consists of the SED LockingSP Active Encryption Key and the SED LockingSP Active Signing Key. The keyset protects TCG protocol LockingSP CSPs. SED Volatile Keyset A set of 256-bit keys that consists of the SED Volatile Key and the SED Volatile Signing Key. Self-Encrypting Drive (SED) A storage device that provides data storage services, which automatically encrypts all user data written to the device and automatically decrypts all user data read from the device. Session A formal TCG term that envelops the lifetime of an Operator’s authentication. [TCG Core] Small Form Factor (SFF) Small form factor is a computer form factor designed to minimize the volume and footprint of a desktop computer. Storage Medium The non-volatile, persistent storage location within a SED partitioned into disjointed sets defined by a User Data area, and a Reserved Area. Table The basic data structures within a Security Provider (SP). Object tables store persistent SP state data defined in TCG Core specification. [TCG Core] TableUID The Unique ID (UID) of a Table. Each object table has a column named UID. This column contains an 8-byte unique identifier for that row. [TCG Core] TPer A Trusted Peripheral. The TPer manages trusted storage-related functions and data structures. [TCG Core] TPer Owner The SID Authority (Crypto Officer) represents TPer Owner. Triple Level Cell (TLC) Triple level cells refer to NAND flash devices that store three bits of information per cell, with eight total voltage states. User Data Data transferred from/to a SED using the Read Data and Write Data commands. [SCSI Block] User An Operator that consumes cryptographic services. [ISO 19790] Write Data An external request to transfer User Data to a SED. [SCSI Block] Zeroise Invalidate a Critical Security Parameter. [ISO 19790] 15 Acronyms Acronym* Definition AEK Active Encryption Key AEN Asynchronous Event Notification AES Advanced Encryption Standard (FIPS 197) ACE Access Control Entry ACL Access Control List CBC Cipher Block Chaining, an operational mode of AES CM Cryptographic Module CO Crypto Officer [ISO 19790] CRC Cyclic Redundancy Check FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 86 of 87 Acronym* Definition CSP Critical Security Parameter [ISO 19790] DEE Data Encryption Engine DLE OptiNAND Download and Execute firmware DRAM Dynamic Random Access Memory DRBG Deterministic Random Bit Generator EDC Error Detection Code EMI Electromagnetic Interference FID Flash Internal Data FIPS Federal Information Processing Standard FSEC Flash Security Data HDD Hard Disk Drive HSM Hardware Security Module IV Initialization Vector KAT Known Answer Test KDF Key Derivation Function KEK Key Encrypting Key LBA Logical Block Address MEK Media Encryption Key MSID Manufactured Security Identifier NAND Negative AND Flash Memory technology NIST National Institute of Standards and Technology NOR Negative OR Flash Memory technology OFS Original Factory Setting OTP One Time Programable PBKDF2 Password Base Key Derivation Function PIN Personal Identification Number POR Power on Reset PSID Physical Security Identifier PSP Public Security Parameter RID Reserved Area Internal Data SAS Serial Attached SCSI SCSI Small Computer System Interface SD_CA Storage Device Certification Authority SECD Security Data SED Self-Encrypting Drive SFF Small Form Factor sFFU Secure Field Firmware Update SID Security Identifier, The TCG authority representing the TPer Owner (Cryptographic Officer) SIO Serial Input/Output FIPS 140-3 Cryptographic Module Non-Proprietary Security Policy Page 87 of 87 Acronym* Definition SOC System-on-a-Chip SP Security Provider [TCG Core], also Security Policy [ISO 19790] SSC Subsystem Class SWG Storage Work Group TCG Trusted Computing Group TLC Triple Level Cell UEC Universal Error Code UID Unique Identifier XTS A mode of AES that utilizes "Tweakable" block ciphers