Ultrastar DC HC560 TCG Enterprise HDD SED, Ultrastar DC HC570 TCG Enterprise HDD SED

Certificate #4802

Webpage information ?

Status active
Validation dates 16.09.2024 , 30.01.2025
Sunset date 15-09-2026
Standard FIPS 140-3
Security level 2
Type Hardware
Embodiment Multi-Chip Embedded
Caveat Interim validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service
Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Western Digital Ultrastar DC HC560 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC560, Cryptographic Module, cryptographic module, or CM, and the Western Digital Ultrastar DC HC570 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC570, Cryptographic Module, cryptographic module, or CM are self-encryption drives (SED) that comply in general with the specifications listed in 13.2 Trusted Computing Group Specifications and specifically with the TCG Storage Architecture Core Specification [TCG Core] with the Trusted Computing Group (TCG) Security Subsystem Class (SSC): Enterprise Specification [TCG Enterprise]. The TCG SSC Enterprise Specification defines a management interface for host application software to activate, provision, and manage encryption of user data. The specification includes data structures and their required content, and mechanisms for managing and configuring Authentication Credentials and access controls. The security architecture provides a locking mechanism by which an Authentication Credential (i.e., a password) can be set by an operator to enable control of access to user data. After an operator authenticates to the appropriate role and locks access to user data access user data is inaccessible. This implementation complies with the lock-based authentication model specified in IG 4.1.A.
Version (Hardware) WUH722020BL4205 [1, 2, 3, 4], WUH722020BL5205 [1, 2, 3, 4], WUH722222BL4205 [3, 5] , WUH722222BL5205 [3, 5]
Version (Firmware) RY07 [1], R5G4 [2], RG01 [3], VM18 [4], R7J4 [5]
Vendor Western Digital Technologies, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy ?

Symmetric Algorithms
AES, AES-256, CAST, HMAC
Asymmetric Algorithms
RSA 3072, RSA-3072
Hash functions
SHA-1, SHA-256, SHA2, PBKDF2
Schemes
MAC, Key Agreement
Randomness
DRBG, RBG
Block cipher modes
ECB, CBC, CTR, XTS

Trusted Execution Environments
PSP, SSC

Security level
Level 2, Level 1, Level 0
Side-channel analysis
malfunction, fault induction

Standards
FIPS 140-3, FIPS PUB 140-3, FIPS2, FIPS 197, FIPS 198, FIPS 186, FIPS 180, FIPS 140, FIPS PUB 197, FIPS PUB 186-5, FIPS PUB 198-1, FIPS PUB 180-4, FIPS140, NIST SP 800-140C, SP 800-140D, NIST SP 800-131A, SP 800-132, SP 800-90A, SP 800-90B, SP 800-38F, RFC 2119, ISO/IEC 24759, ISO/IEC19790, ISO/IEC 19790

File metadata

Author Michael Williamson
Creation date D:20250115140054-08'00'
Modification date D:20250115140214-08'00'
Pages 65
Creator Acrobat PDFMaker 24 for Word
Producer Adobe PDF Library 24.5.96

Heuristics ?

No heuristics are available for this certificate.

References ?

No references are available for this certificate.

Updates ?

  • 24.02.2025 The certificate data changed.
    Certificate changed

    The web extraction data was updated.

    • The exceptions property was updated.
  • 04.02.2025 The certificate data changed.
    Certificate changed

    The web extraction data was updated.

    • The validation_history property was updated, with the [[1, {'_type': 'sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry', 'date': '2025-01-30', 'validation_type': 'Update', 'lab': 'UL VERIFICATION SERVICES INC'}]] values inserted.
    • The hw_versions property was set to WUH722020BL4205 [1, 2, 3, 4], WUH722020BL5205 [1, 2, 3, 4], WUH722222BL4205 [3, 5] , WUH722222BL5205 [3, 5].
    • The fw_versions property was set to RY07 [1], R5G4 [2], RG01 [3], VM18 [4], R7J4 [5].

    The PDF extraction data was updated.

    • The keywords property was updated, with the {'symmetric_crypto': {'__update__': {'AES_competition': {'__update__': {'CAST': {'__update__': {'CAST': 19}}}}}}, 'randomness': {'__update__': {'PRNG': {'__update__': {'DRBG': 57}}}}, 'standard_id': {'__update__': {'FIPS': {'__update__': {'FIPS 140-3': 84}}}}} data.
    • The policy_metadata property was updated, with the {'pdf_file_size_bytes': 1451809, 'pdf_number_of_pages': 65, '/Author': 'Michael Williamson', '/CreationDate': "D:20250115140054-08'00'", '/ModDate': "D:20250115140214-08'00'", '/Producer': 'Adobe PDF Library 24.5.96', '/SourceModified': 'D:20250115220032'} data.

    The computed heuristics were updated.

    • The extracted_versions property was set to {'_type': 'Set', 'elements': ['2', '1', '3', '4', '5']}.

    The state was updated.

    • The policy_pdf_hash property was set to 4f5dd782cb1a419de72ddeee83e518f580ca682aa8ff488247e8d51cde579050.
    • The policy_txt_hash property was set to 2d317b8f009e5daef72e7d3748afed1bb94b01db3755ba2f343a9a6ebf1ef3ab.
  • 14.10.2024 The certificate data changed.
    Certificate changed

    The web extraction data was updated.

    • The certificate_pdf_url property was set to https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/September 2024_011024_0217.pdf.
  • 01.10.2024 The certificate was first processed.
    New certificate

    A new FIPS 140 certificate with the product name Ultrastar DC HC560 TCG Enterprise HDD SED, Ultrastar DC HC570 TCG Enterprise HDD SED was processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4802,
  "dgst": "d19828eb64fa5dea",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "PBKDFA2100",
        "AES-XTSAES 3580",
        "Counter DRBGA2098",
        "HMAC-SHA-1HMAC 2280",
        "SHA2-256SHS 2942",
        "HMAC-SHA2-256HMAC 2280",
        "AES-KWPA2098",
        "HMAC-SHA2-224HMAC 2280",
        "AES-CBCAES 3580",
        "SHA-1SHS 2942",
        "AES-ECBAES 3580",
        "RSA SigVer (FIPS186-4)A2099",
        "SHA2-224SHS 2942"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "4",
        "5",
        "3",
        "1",
        "2"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "RSA": {
          "RSA 3072": 8,
          "RSA-3072": 2
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 7
        },
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 7
        },
        "XTS": {
          "XTS": 15
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1
        },
        "MAC": {
          "MAC": 4
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1,
          "#13": 1,
          "#2": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "# A2098": 2,
          "# A2099": 1,
          "AES 256": 1,
          "AES 3580": 1,
          "AES-256": 5,
          "AES-256 256": 1,
          "AES-256 5120": 1,
          "Cert #AES": 21,
          "Cert #HMAC": 25,
          "Cert #SHS": 9,
          "HMAC 2280": 2,
          "HMAC SHA-256": 1,
          "RSA 3072": 8,
          "SHA-1": 2,
          "SHA-256": 2,
          "SHA2 - 224": 1,
          "SHA2- 256": 1,
          "SHA2-224": 1,
          "SHA2-256": 23,
          "SHS 2942": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 0": 5,
          "Level 1": 1,
          "Level 2": 5
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF2": 16
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 2
          },
          "SHA2": {
            "SHA-256": 2,
            "SHA2": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 57
        },
        "RNG": {
          "RBG": 11
        }
      },
      "side_channel_analysis": {
        "FI": {
          "fault induction": 1,
          "malfunction": 1
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140": 18,
          "FIPS 140-3": 84,
          "FIPS 180": 3,
          "FIPS 186": 3,
          "FIPS 197": 6,
          "FIPS 198": 2,
          "FIPS PUB 140-3": 2,
          "FIPS PUB 180-4": 1,
          "FIPS PUB 186-5": 1,
          "FIPS PUB 197": 1,
          "FIPS PUB 198-1": 1,
          "FIPS140": 1,
          "FIPS2": 1
        },
        "ISO": {
          "ISO/IEC 19790": 4,
          "ISO/IEC 24759": 8,
          "ISO/IEC19790": 2
        },
        "NIST": {
          "NIST SP 800-131A": 2,
          "NIST SP 800-140C": 1,
          "SP 800-132": 1,
          "SP 800-140D": 1,
          "SP 800-38F": 2,
          "SP 800-90A": 2,
          "SP 800-90B": 2
        },
        "RFC": {
          "RFC 2119": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 27,
            "AES-256": 7
          },
          "CAST": {
            "CAST": 19
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 5
        },
        "IBM": {
          "SSC": 3
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Michael Williamson",
      "/Comments": "",
      "/Company": "Microsoft",
      "/ContentTypeId": "0x01010088D736DC06BD7B46BF1F61B9E63EEB42",
      "/CreationDate": "D:20250115140054-08\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 24 for Word",
      "/Keywords": "",
      "/ModDate": "D:20250115140214-08\u002700\u0027",
      "/Producer": "Adobe PDF Library 24.5.96",
      "/SourceModified": "D:20250115220032",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 1451809,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://www.pleacher.com/mp/mlessons/algebra/entropy.html",
          "https://www.westerndigital.com/support",
          "https://csrc.nist.gov/projects/cryptographic-module-validation-program/entropy-validations/certificate/13",
          "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/entropy/E13_PublicUse.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 65
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_garbage": false,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_pdf_hash": "4f5dd782cb1a419de72ddeee83e518f580ca682aa8ff488247e8d51cde579050",
    "policy_txt_hash": "2d317b8f009e5daef72e7d3748afed1bb94b01db3755ba2f343a9a6ebf1ef3ab"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/September 2024_011024_0217.pdf",
    "date_sunset": "2026-09-15",
    "description": "The Western Digital Ultrastar DC HC560 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC560, Cryptographic Module, cryptographic module, or CM, and the Western Digital Ultrastar DC HC570 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC570, Cryptographic Module, cryptographic module, or CM are self-encryption drives (SED) that comply in general with the specifications listed in 13.2 Trusted Computing Group Specifications and specifically with the TCG Storage Architecture Core Specification [TCG Core] with the Trusted Computing Group (TCG) Security Subsystem Class (SSC): Enterprise Specification [TCG Enterprise]. The TCG SSC Enterprise Specification defines a management interface for host application software to activate, provision, and manage encryption of user data. The specification includes data structures and their required content, and mechanisms for managing and configuring Authentication Credentials and access controls. The security architecture provides a locking mechanism by which an Authentication Credential (i.e., a password) can be set by an operator to enable control of access to user data. After an operator authenticates to the appropriate role and locks access to user data access user data is inaccessible. This implementation complies with the lock-based authentication model specified in IG 4.1.A.",
    "embodiment": "Multi-Chip Embedded",
    "exceptions": [
      "Operational environment: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": "RY07 [1], R5G4 [2], RG01 [3], VM18 [4], R7J4 [5]",
    "historical_reason": null,
    "hw_versions": "WUH722020BL4205 [1, 2, 3, 4], WUH722020BL5205 [1, 2, 3, 4], WUH722222BL4205 [3, 5] , WUH722222BL5205 [3, 5]",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Ultrastar DC HC560 TCG Enterprise HDD SED, Ultrastar DC HC570 TCG Enterprise HDD SED",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-09-16",
        "lab": "UL VERIFICATION SERVICES INC",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-01-30",
        "lab": "UL VERIFICATION SERVICES INC",
        "validation_type": "Update"
      }
    ],
    "vendor": "Western Digital Technologies, Inc.",
    "vendor_url": "http://www.westerndigital.com"
  }
}