808bits

CN Series Ethernet Encryptors

FIPS 140-2 certificate #3053 · Senetas Corporation Ltd, distributed by Gemalto NV (SafeNet) · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number3053
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorSenetas Corporation Ltd, distributed by Gemalto NV (SafeNet) · website
Hardware versionsSenetas Corp. Ltd. CN4000 Series: A4010B (DC), A4020B (DC); Senetas Corp. Ltd. CN6010 Series: A6010B (AC), A6011B (DC) and A6012B (AC/DC); Senetas Corp. Ltd. CN6140 Series: A6140B (AC), A6141B (DC) and A6142B (AC/DC); Senetas Corp. Ltd. & SafeNet Inc. CN4000 Series: A4010B (DC), A4020B (DC); Senetas Corp. Ltd. & SafeNet Inc. CN6010 Series: A6010B (AC), A6011B (DC) and A6012B (AC/DC); Senetas Corp. Ltd. & SafeNet Inc. CN6140 Series: A6140B (AC), A6141B (DC) and A6142B (AC/DC)
Firmware versions3.0.1 and 3.0.2

Module description

The CN4010, CN4020, CN6010 and CN6140 are high-speed hardware encryption platforms that secure data over twisted-pair and optical Ethernet networks. The modules support line rates from 10Mb/s to 10Gb/s. The CN4020, CN6010 and CN6140 are equipped with pluggable transceivers to support a variety of optical network interfaces. Data privacy is provided by FIPS approved AES algorithms in CFB, CTR and GCM modes. Additional transmission security is provided via TRANSEC (Traffic Flow Security) which can be used to remove patterns in network traffic and prevent traffic analysis attacks.

Security level exceptions

  • Cryptographic Module Ports and Interfaces: Level 3
  • Roles, Services, and Authentication: Level 3
  • Finite State Model: Level 3
  • Physical Security: Level 3
  • Operational Environment: Level 3
  • EMI/EMC: Level 3
  • Self-Tests: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: Level 3

Approved algorithms

AlgorithmCAVP certificate
AES4404, 4405, 4406, 4412, 4413, 4553
CVL1232
DRBG1503
ECDSA1108
HMAC3007
KAS123
RSA2480
SHS3731
Triple-DES2424

Allowed algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 150 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-10-19InitialDXC Technology
2017-12-08UpdateDXC Technology
2018-02-07UpdateDXC Technology

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-10-19, 2017-12-08, 2018-02-07

Source documents