Ultrastar DC HC560 TCG Enterprise HDD SED, Ultrastar DC HC570 TCG Enterprise HDD SED
Ultrastar DC HC560 TCG Enterprise HDD SED, Ultrastar DC HC570 TCG Enterprise HDD SED, from Western Digital Technologies, Inc., holds FIPS 140-3 certificate #4802 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: Interim validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service
Certificate
| Certificate number | 4802 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Vendor | Western Digital Technologies, Inc. · website |
| Hardware versions | WUH722020BL4205 [1, 2, 3, 4], WUH722020BL5205 [1, 2, 3, 4], WUH722222BL4205 [3, 5] , WUH722222BL5205 [3, 5] |
| Firmware versions | RY07 [1], R5G4 [2], RG01 [3], VM18 [4], R7J4 [5] |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Western Digital Ultrastar DC HC560 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC560, Cryptographic Module, cryptographic module, or CM, and the Western Digital Ultrastar DC HC570 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC570, Cryptographic Module, cryptographic module, or CM are self-encryption drives (SED) that comply in general with the specifications listed in 13.2 Trusted Computing Group Specifications and specifically with the TCG Storage Architecture Core Specification [TCG Core] with the Trusted Computing Group (TCG) Security Subsystem Class (SSC): Enterprise Specification [TCG Enterprise]. The TCG SSC Enterprise Specification defines a management interface for host application software to activate, provision, and manage encryption of user data. The specification includes data structures and their required content, and mechanisms for managing and configuring Authentication Credentials and access controls. The security architecture provides a locking mechanism by which an Authentication Credential (i.e., a password) can be set by an operator to enable control of access to user data. After an operator authenticates to the appropriate role and locks access to user data access user data is inaccessible. This implementation complies with the lock-based authentication model specified in IG 4.1.A.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms (13)
| Algorithm | CAVP certificates |
|---|---|
| AES-CBC | A2099, AES 3580 |
| AES-ECB | A2101, AES 3580 |
| AES-KWP | A2098 |
| AES-XTS | A2101, AES 3580 |
| Counter DRBG | A2098 |
| HMAC-SHA-1 | HMAC 2280 |
| HMAC-SHA2-224 | HMAC 2280 |
| HMAC-SHA2-256 | HMAC 2280 |
| PBKDF | A2100 |
| RSA SigVer (FIPS186-4) | A2098, A2099 |
| SHA-1 | SHS 2942 |
| SHA2-224 | SHS 2942 |
| SHA2-256 | A2099, SHS 2942 |
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-09-16 | Initial | UL Verification Services, Inc. |
| 2025-01-30 | Update | UL Verification Services, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2024-09-16, 2025-01-30