808bits

Huawei USG 9520/9560/9580 Firewall

FIPS 140-2 certificate #3058 · Huawei Technologies Co., Ltd. · data as of 2026-08-28
Historical. 186-2 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with the tamper evident seals installed as indicated in the Security Policy

Certificate

Certificate number3058
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorHuawei Technologies Co., Ltd. · website
Hardware versionsBase Models: USG9520 (P/N 02350FRU Rev D.2) [1], USG9560 (P/N 02350FRW Rev D.2) [2] and USG9580 (P/N 02350FRX Rev D.2) [3]; SPU/SPC cards: SPU-X3-B (P/N 03056640) [1, 2, 3], SPU-X3-B2 (P/N 03056989) [1, 2, 3], SPU-X8X16-B (P/N 03056638) [1, 2, 3], SPC-20-O-E8KE (P/N 03056636) [1, 2, 3], SPU-X3-20-O-E8KE (P/N 03056634) [1, 2, 3], SPU-X8X16-20-O-E8KE (P/N 03056635) [1, 2, 3], SPC-APPSEC-FW (P/N 03056688) [1, 2, 3], SPUA-20-O-H (P/N 03057426) [1, 2, 3], SPUA-20-O-M (P/N 03057427) [1, 2, 3], SPCA-20-O-H&M (P/N 03057429) [1, 2, 3], SPUB-20-O-H (P/N 03057520) [1, 2, 3], SPUB-20-O-M (P/N 03057518) [1, 2, 3], SPCB-20-O-H&M (P/N 03057522) [1, 2, 3]; External Baffle: 99089JEB, Version A.2 [1, 3]; Tamper Seal 4057-113016, Version A.3 [1, 2, 3]
Firmware versionsV500R001C50

Module description

The Huawei USG Firewalls ensure secure services for large data centers, cloud computing environments, and enterprise campus networks. Integrated switching, routing, and security enable smooth upgrades, easy virtualization, and terabit-level processing capability - all with carrier-grade reliability in a compact, space-saving form factor. NP + multi-core + distributed architecture integrates security, virtualization, and comprehensive service awareness with continuous database updates to optimize protection.

Security level exceptions

  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES4450, 4451
CKGvendor affirmed
CVL1150, 1151, 1152, 1153
DRBG1441, 1442
ECDSA1084
HMAC2953, 2954
KTS
KTS
RSA2431, 2432
SHS3663, 3664
Triple-DES2392, 2393

Allowed algorithms

Diffie-Hellman (CVL Certs. #1150 and #1152, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1151 and #1153, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-11-07InitialUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-11-07

Source documents