Seagate Secure® Self-Encrypting Drive
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No operator authentication is enforced for executing security services that were unlocked by an authenticated service
Certificate
| Certificate number | 4930 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-12-19 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Vendor | Seagate Technology, LLC · website |
| Hardware versions | ST18000NM007J[1][6], ST16000NM007J[1][6][11][15][22][24], ST14000NM007J[1][6], ST12000NM007J[1][6][11][22][23], ST10000NM016G[1][6], ST10000NM022B[2][5], ST10000NM011B[2][18], ST8000NM022B[2][4][5][7][8][13][14][15][20], ST8000NM011B[2][18][19], ST6000NM024B[2][5][7][8], ST6000NM013B[2][18], ST4000NM013B[2][9][10][12][16][21], ST4000NM029B[2][4][5], ST4000NM017B[2][18][19], ST10000NM021B[3][25], ST8000NM021B[3][17][25], ST6000NM023B[3][25], ST4000NM012B[3][17][26], ST4000NM028B[3][25], ST18000NM002D[27], ST20000NM005D[27][28] |
| Firmware versions | EP7U[1], EF34[2], SZFP[3], 3P01[4], EF04[5], EF07[6], FCE7[7], FCL7[8], FKE8[9], FKL8[10], FQD4[11], FRB5[12], FRD6[13], GCN6[14], HPD5[15], HPD6[16], HPG4[17], KF04[18], L708[19], LT0E[20], NF04[21], P705[22], PJ07[23], PSFG[24], SF04[25], TF04[26], FSE1[27], FSK1[28] |
| Entropy | ENT (P) |
Module description
The Seagate Secure® Self-Encrypting Drive is embodied in Seagate Enterprise Exos™ Enterprise SED model devices. These products meet the performance requirements of the most demanding Enterprise applications. The Cryptographic Module (CM) provides a wide range of cryptographic services including: • HW based data encryption (AES-XTS) • Instantaneous user data disposal with cryptographic erase • Independently controlled and protected user data LBA bands • Authenticated FW download. The services are provided through industry-standard TCG Enterprise SSC SATA and SCSI protocols.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A1095 |
| AES-CMAC | A1081 |
| AES-CMAC | A3515 |
| AES-GCM | A1080 |
| AES-KW | A1094 |
| AES-XTS | A1090 |
| Counter DRBG | A1082 |
| HMAC-SHA2-256 | A1083 |
| HMAC-SHA2-256 | A1091 |
| KAS-FFC-SSC Sp800-56Ar3 | A1084 |
| KDF TLS | A1089 |
| PBKDF | A1085 |
| RSA SigVer (FIPS186-4) | A1093 |
| Safe Primes Key Generation | A1087 |
| SHA2-256 | A1088 |
| SHA2-256 | A1092 |
| SHA2-384 | A1088 |
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-12-20 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
| 2025-10-21 | Update | Leidos Accredited Testing & Evaluation (AT&E) Lab |
| 2026-07-24 | Update | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-12-20