Contact Advantech Search Shopping list
  1. 1-888-576-9668
  2. Login
Order By Part Number
NSA Commercial Solutions for Classified (CSFC) Listed and Common Criteria Certified SSDs
Press Release
Inquiries? SSD-FIPS@advantech.com | 1-408-519-1751
  • FIPS 140-2
    Validated
    FIPS 140-2 Validated
    • Advantech’s SQFlash SSD meets FIPS 140-2 Level 2 certification, verified by NIST. Its design undergoes rigorous review to meet strict security standards, reducing data leakage risks and protecting user data effectively.
  • NSA CSfC
    Listed
    FIPS 140-2 Validated
    • CSfC, part of NSA's cybersecurity strategy, uses commercial technologies to rapidly deliver secure solutions. It relies on layered configurations to adequately protect classified data across diverse applications.
  • Common Criteria Certified
    FIPS 140-2 Validated
    • Common Criteria allows users to specify security requirements (SFRs and SARs) in a Security Target (ST), drawn from Protection Profiles (PPs). Vendors can then implement security attributes, with testing labs evaluating if products meet these claims.
  • NIAP
    Tested
    FIPS 140-2 Validated
    • NIAP oversees U.S. implementation of Common Criteria, including the CCEVS validation body. It develops Protection Profiles and evaluation policies to establish clear, repeatable security requirements. In collaboration with NIST, NIAP approves labs for conducting evaluations in U.S. private sector operations.
Advantages of the Advantech and CipherDriveOne
Secure SSD Product Combination
  • Key Certifications &
    Listings

    • • NIAP Tested and Verified
    • • Common Criteria Certified
    • • NSA CSfC-listed
    • • Complies Presidential executive orders
  • Quantum Resistant
    Encryption

    • • FIPS 140-2 validated algorithms
    • • NIST AES 256-bit encryption
    • • Secure Erase
    • • Pre-boot authentication for decryption
  • Multi-factor
    Authentication

    • • Username/password
    • • Smart Cards using PIV
    • • Supports Yubico Yubikey USB tokens
    • • All NIST CAC smart card profiles supported
Common Criteria Certified Drives
  • SQF-2040-512ECM
    NVMe M.2 2280
    • • 512GB
    • • FIPS140-2 and CC certified
    • • Supports AES256 and OPAL
    • • Operational temperature 32~158°F (0~70℃ )
  • SQF-2040-1TECM
    NVMe M.2 2280
    • • 1TB
    • • FIPS140-2 and CC certified
    • • Supports AES256 and OPAL
    • • Operational temperature 32~158°F (0~70℃ )
  • SQF-2020-1TSCB
    2.5" SATA
    • • 1TB
    • • FIPS140-2 and CC certified
    • • Supports AES256 and OPAL
    • • Operational temperature 32~158°F (0~70℃ )
  • SQF-2020-2TSCB
    2.5" SATA
    • • 2TB
    • • FIPS140-2 and CC certified
    • • Supports AES256 and OPAL
    • • Operational temperature 32~158°F (0~70℃ )
Special Features of Advantech & CipherDriveOne NSA CSfC Solutions
  • Standard SSDs
    (Non FIPS 140-2 Certified)
    Advantech SQF +
    CipherDriveOne Software
  • FIPS 140-2 Algorithms
    No
    Yes
  • Common Criteria Certified
    No
    Yes
  • NSA CSfC Listing
    No
    Yes
  • Layer 2 Protective Coating
    No
    Yes
  • Pre-boot Authentication
    No
    Yes
  • User Roles
    No
    Yes
  • Multi-Factor Authentication
    No
    Yes
  • Customizable Disclaimer
    No
    Yes
  • Type 1 & 2 Chain Boot
    No
    Yes
  • Log Event Files
    No
    Yes
FAQs: Certifications and Listings
FAQs: Encryption and Security
  • 1. What is meant by a FIPS 140-2 Level 2 Validation?
    FIPS 140-2 Level 2 Validation is typical for data storage devices. Advantech SQFF840 and SQFF920 SSD have met Level 2 requirements. The FIPS 140-2 Level 2 requirements help ensure that the SSD encryption algorithms follow predefined and accepted standards. FIPS 140-2 describes role-based user authentication, boot time firmware identity attestation, and provisions for tamper-evident seals or labels. For more details, please refer to the Advantech’s SQFF series product sheet.
    Within the framework of FIPS 140-2, there are four levels, with cumulative requirements:
    Level 1: Certification of encryption engine and associated firmware
    Level 2: Tamper-evident seals to protect access; role-based authentication requirements
    Level 3: Tamper-resistant casing (tamper response may include zeroing of all critical security parameters [CSP]); identity-based authentication requirements
    Level 4: Robust tamper resistance and intrusion response; compulsory zeroing of CSPs on intrusion detection; hardened casing for unanticipated environmental conditions
  • 2. Is FIPS 140-2 required by my application?
    Previously, actual policy requirements for FIPS 140-2 validated SEDs are limited to government owned or government-controlled compute and data storage systems, mostly within the U.S. and Canada. However, many private firms in healthcare, financial services and other industries that manage sensitive or confidential data are finding it beneficial to add FIPS 140-2 validated data storage devices to their system requirements as an added and documented way to ensure compliance with federal regulations on data security and customer privacy.
  • 3. What is AES-256 Bit Encryption?
  • 4. What is Pre-boot Authentication?
    Pre-boot authentication or power-on authentication serves as an extension of the BIOS, UEFI or boot firmware and guarantees a secure, tamper-proof environment external to the operating system as a trusted authentication layer.
  • 5. What is Authorization Acquisition?
    Authorization Acquisition purpose is to gather user input and provide the Encryption Engine with a value that can be used to make the data encryption key available for encryption/decryption functions.
  • 6. What is the Encryption Engine?
    The encryption engine is located on the storage management level, with the keys usually held by the CSP. The engine encrypts data written to the storage and decrypts it when exiting the storage.
  • 7. What is the purpose of having Dual Layer Encryption?
    The purpose of Dual Layer Encryption is that it provides an extra layer of protection against cyberattacks, such as brute-force attacks. If an attacker obtains the encrypted data, they will need to break through two encryption layers instead of just one, making it more difficult and time consuming.
FAQs: Software with CipherDrive One
  • 1. What is Secure Erase?
    CipherDriveOne Secure Erase deletes the authentication (AK) and encryption keys (DEK) from the SSD following TCG OPAL 2.0 specifications. Once CipherDriveOne Secure Erase is executed, it is permanent. All data is left encrypted with AES-256-bit encryption and there is no way to recover the key or retrieve the data. AES-256 encryption is quantum-resistant.
  • 2. Does CipherDriveOne Support Smart Cards?
    Yes, CipherDriveOne supports Smart Cards as one form of authentication. This can include CAC, PIV, and Yubikey, smartcards or tokens.
  • 3. What Forms of authentication does CipherDriveOne use?
x
Contact Us

1-888-576-9668

8 am- 8 pm (EST) Mon-Fri

Contact Advantech