808bits

NITROXIII CNN35XX-NFBE HSM Family

FIPS 140-2 certificate #3521 · Marvell Semiconductor, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy. This validation entry is a non-security-relevant modification to Cert. #3108

Certificate

Certificate number3521
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorMarvell Semiconductor, Inc. · website
Hardware versionsCNL3560P-NFBE-G, CNL3560P-NFBE-2.0-G, CNL3560M-NFBE-2.0G, CNL3560-NFBE-G, CNL3560-NFBE-2.0-G, CNL3530-NFBE-G, CNL3530-NFBE-2.0-G, CNL3510-NFBE-G, CNL3510-NFBE-2.0-G, CNL3510P-NFBE-G, CNL3510P-NFBE-2.0-G, CNN3560P-NFBE-G, CNN3560P-NFBE-2.0-G, CNN3560-NFBE-G, CNN3560-NFBE-2.0-G, CNN3530-NFBE-G, CNN3530-NFBE-2.0-G, CNN3510-NFBE-G and CNN3510-NFBE-2.0-G
Firmware versionsCNN35XX-NFBE-FW-3.3 build 11

Module description

CNN35XX-NFBE HSM Family is a high performance purpose built solution for key management and crypto acceleration compliance to FIPS 140-2. The module supports flexible key store that can be partitioned up to 32 individually managed and isolated partitions. This is a SRIOV capable PCIe adapter and can be used in a virtualization environment to extend services like virtual key management, crypto and TLS offloads to VMs in dedicated I/O channels. This product is suitable for PKI vendors, SSL servers/load balancers.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES2033, 2034, 2035, 3205, 3206, 4104
CKGvendor affirmed
CVL167, 563
DRBG680
DSA916
ECDSA589
HMAC1233, 2019
KAS53
KASvendor affirmed
KBKDF65
KTS
KTS
RSA1634, 2218
SHS1780, 2652
Triple-DES1311, 2242

Allowed algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2019-09-08InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-09-08

Source documents