808bits

NITROXIII CNN35XX-NFBE HSM Family

FIPS 140-2 certificate #2850 · Cavium Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2850
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorCavium Inc. · website
Hardware versionsP/Ns CNL3560P-NFBE-G [1], CNL3560P-NFBE-2.0-G [2], CNL3560-NFBE-G [1], CNL3530-NFBE-G [1], CNL3510-NFBE-G [1], CNL3510P-NFBE-G [1], CNN3560P-NFBE-G [1], CNN3560-NFBE-G [1], CNN3560-NFBE-2.0-G [2], CNN3530-NFBE-G [1], CNN3530-NFBE-2.0-G [2], CNN3510-NFBE-G [1], CNN3510-NFBE-2.0-G [2], CNN3505LP-NFBE-2.0-G [2] and CNN3510LP-NFBE-2.0-G [2]
Firmware versionsCNN35XX-NFBE-FW-2.03 build 10 [1], CNN35XX-NFBE-FW-2.03 build 13 [1], CNN35XX-NFBE-FW-2.03 build 20 [1], CNN35XX-NFBE-FW-2.03 build 21 [1], CNN35XX-NFBE-FW-2.03 build 22 [1] and CNN35XX-NFBE-FW-2.03 build 13-HW2.0 [1, 2]

Module description

CNN35XX-NFBE HSM Family is a high performance purpose built solution for key management and crypto acceleration compliance to FIPS 140-2. The module supports flexible key store that can be partitioned up to 32 individually managed and isolated partitions. This is a SRIOV capable PCIe adapter and can be used in a virtualization environment to extend services like virtual key management, crypto and TLS offloads to VMs in dedicated I/O channels. This product is suitable for PKI vendors, SSL servers/load balancers.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES2033, 2034, 2035, 3205, 3206, 4104
CVL167, 563
DRBG680
DSA916
ECDSA589
HMAC1233, 2019
KAS53
KASvendor affirmed
KBKDF65
KTS
KTS
RSA1634, 2218
SHS1780, 2652
Triple-DES1311, 2242

Other algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength); PBE; RC4

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-02-27InitialUL Verification Services, Inc.
2017-02-28UpdateUL Verification Services, Inc.
2017-04-04UpdateUL Verification Services, Inc.
2017-08-04UpdateUL Verification Services, Inc.
2017-08-31UpdateUL Verification Services, Inc.
2017-11-09UpdateUL Verification Services, Inc.
2018-02-21UpdateUL Verification Services, Inc.
2018-03-15UpdateUL Verification Services, Inc.
2018-03-26UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-02-27, 2017-02-28, 2017-04-04, 2017-08-04, 2017-08-31, 2017-11-09, 2018-02-21, 2018-03-15, 2018-03-26

Source documents