808bits

Ultrastar DC HC560 TCG Enterprise HDD SED, Ultrastar DC HC570 TCG Enterprise HDD SED

FIPS 140-3 certificate #4802 · Western Digital Technologies, Inc. · data as of 2026-08-28
Historical. Replaced by certificate #5483. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service

Certificate

Certificate number4802
StandardFIPS 140-3
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorWestern Digital Technologies, Inc. · website
Hardware versionsWUH722020BL4205 [1, 2, 3, 4], WUH722020BL5205 [1, 2, 3, 4], WUH722222BL4205 [3, 5] , WUH722222BL5205 [3, 5]
Firmware versionsRY07 [1], R5G4 [2], RG01 [3], VM18 [4], R7J4 [5]

Module description

The Western Digital Ultrastar DC HC560 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC560, Cryptographic Module, cryptographic module, or CM, and the Western Digital Ultrastar DC HC570 TCG Enterprise HDD, hereafter referred to as Ultrastar DC HC570, Cryptographic Module, cryptographic module, or CM are self-encryption drives (SED) that comply in general with the specifications listed in 13.2 Trusted Computing Group Specifications and specifically with the TCG Storage Architecture Core Specification [TCG Core] with the Trusted Computing Group (TCG) Security Subsystem Class (SSC): Enterprise Specification [TCG Enterprise]. The TCG SSC Enterprise Specification defines a management interface for host application software to activate, provision, and manage encryption of user data. The specification includes data structures and their required content, and mechanisms for managing and configuring Authentication Credentials and access controls. The security architecture provides a locking mechanism by which an Authentication Credential (i.e., a password) can be set by an operator to enable control of access to user data. After an operator authenticates to the appropriate role and locks access to user data access user data is inaccessible. This implementation complies with the lock-based authentication model specified in IG 4.1.A.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2099
AES-CBCAES 3580
AES-ECBA2101
AES-ECBAES 3580
AES-KWPA2098
AES-XTSA2101
AES-XTSAES 3580
Counter DRBGA2098
HMAC-SHA-1HMAC 2280
HMAC-SHA2-224HMAC 2280
HMAC-SHA2-256HMAC 2280
PBKDFA2100
RSA SigVer (FIPS186-4)A2098
RSA SigVer (FIPS186-4)A2099
SHA-1SHS 2942
SHA2-224SHS 2942
SHA2-256A2099
SHA2-256SHS 2942

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-09-16InitialUL Verification Services, Inc.
2025-01-30UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-09-16, 2025-01-30

Source documents