Module Name
Non-Volatile Memory express (NVMe) Data Path Security Cluster (DPSC) Module
Caveat
No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Security Level Exceptions
- Software/Firmware security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Description
The Data Path Security Cluster is a hardware IP providing XTS-AES encryption to NVMe data in transit over the network. The cryptographic module accepts from its outside and stores cryptographic keys for multiple NVMe connections. Depending on the content of received data, the module shall or shall not apply cryptographic processing to the data. The DPSC contains 4 identical XTS-AES-256 decrypt engines, 4 identical XTS-AES-256 encrypt engines, key cache arbiter and key cache SRAM which is zeroized on reset. The data interfaces exposed to the NVMe Protocol Layer (NPL) within the NVMe Protocol Initiator (NPI) are read and write DMA interfaces. XTS keys are written to the module’s SRAM via Control/Status Register (CSR) writes from the Integrated Management Complex (IMC) located outside of the module boundary. On-demand self- tests may be initiated from the NPI using an on-demand self-test trigger over a wire interface.