808bits

CN9000 Series Encryptors

FIPS 140-2 certificate #3051 · Senetas Corporation Ltd, distributed by Gemalto NV (SafeNet) · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number3051
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorSenetas Corporation Ltd, distributed by Gemalto NV (SafeNet) · website
Hardware versionsSenetas Corp. Ltd. CN9000 Series: A9100B (AC), A9101B (DC), A9102B (AC/DC); Senetas Corp. Ltd. CN9000 Series: A9120B (AC), A9121B (DC), A9122B (AC/DC); Senetas Corp. Ltd. & SafeNet Inc. CN9000 Series: A9100B (AC), A9101B (DC), A9102B (AC/DC); Senetas Corp. Ltd. & SafeNet Inc. CN9000 Series: A9120B (AC), A9121B (DC), A9122B (AC/DC)
Firmware versions3.0.1 and 3.0.2

Module description

The CN9000 Series are high-speed hardware encryption platforms that secure data over optical Ethernet networks. The models included are the CN9100 and CN9120 100G Ethernet Encryptors, operating at line rates of 100Gb/s with pluggable transceivers to support a variety of optical network interfaces. Data privacy is provided by FIPS approved AES CTR algorithms.

Security level exceptions

  • Cryptographic Module Ports and Interfaces: Level 3
  • Roles, Services, and Authentication: Level 3
  • Finite State Model: Level 3
  • Physical Security: Level 3
  • Operational Environment: Level 3
  • EMI/EMC: Level 3
  • Self-Tests: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES4113, 4556, 4557
CVL1238
DRBG1506
ECDSA1111
HMAC3010
KAS126
RSA2483
SHS3734
Triple-DES2427

Allowed algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 150 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-10-18InitialDXC Technology
2017-12-07UpdateDXC Technology
2018-02-07UpdateDXC Technology

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-10-18, 2017-12-07, 2018-02-07

Source documents