Module Name
Knuckle Cryptographic Module
Caveat
No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Security Level Exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Description
The Knuckle Cryptographic Module is defined as a sub-chip cryptographic subsystem within a single-chip physical embodiment. The module is the primary component of a PCIe-based NVMe controller which provides AES-XTS encryption of data-at-rest and key management functionality per Trusted Computing Group (TCG) Opal specifications. The NVMe controller also includes a Google Titan chip for providing a Root of Trust (RoT) and boot security. The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated storage devices. The Module is intended to be used in a storage system.