NITROXIII CNN35XX-NFBE HSM Family
Certificate
| Certificate number | 3741 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Vendor | Marvell Semiconductor, Inc. · website |
| Hardware versions | P/Ns CNL3560P-NFBE-G [1], CNL3560-NFBE-G [1], CNL3530-NFBE-G [1], CNL3510-NFBE-G [1], CNL3510P-NFBE-G [1], CNN3560P-NFBE-G [1], CNN3560-NFBE-G [1], CNN3530-NFBE-G [1], CNN3510-NFBE-G [1], CNL3560P-NFBE-2.0-G [2], CNL3560-NFBE-2.0-G [2], CNL3530-NFBE-2.0-G [2], CNL3510-NFBE-2.0-G [2], CNL3510P-NFBE-2.0-G [2], CNL3560PB-NFBE-2.0-G [2], CNL3560B-NFBE-2.0-G [2], CNL3530B-NFBE-2.0-G [2], CNL3510B-NFBE-2.0-G [2], CNL3510PB-NFBE-2.0-G [2], CNN3510LP-NFBE-2.0-G [2] and CNN3510LPB-NFBE-2.0-G [2] |
| Firmware versions | CNN35XX-NFBE-FW-2.04 build 48 [1, 2], CNN35XX-NFBE-FW-2.04 build 49 [1, 2], CNN35XX-NFBE-FW-2.04 build 50 [1, 2], CNN35XX-NFBE-FW-2.04 build 52 [1, 2], CNN35XX-NFBE-FW-2.04 build 53 [1, 2], CNN35XX-NFBE-FW-2.05 build 15 [1] and CNN35XX-NFBE-FW-2.05 build 18 [1] |
Module description
CNN35XX-NFBE HSM Family is a high performance purpose built solution for key management and crypto acceleration compliance to FIPS 140-2. The module supports flexible key store that can be partitioned up to 32 individually managed and isolated partitions. This is a SRIOV capable PCIe adapter and can be used in a virtualization environment to extend services like virtual key management, crypto and TLS offloads to VMs in dedicated I/O channels. This product is suitable for PKI vendors, SSL servers/load balancers.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 2033, 2034, 2035, 3205, 3206, 4104 |
| CKG | vendor affirmed |
| CVL | 167, 563 |
| DRBG | 680 |
| DSA | 916 |
| ECDSA | 589 |
| HMAC | 1233, 2019 |
| KAS | 53 |
| KAS | vendor affirmed |
| KBKDF | 65 |
| KTS | |
| KTS | |
| KTS | |
| KTS | |
| RSA | 1634, 2218 |
| SHS | 1780, 2652 |
| Triple-DES | 1311, 2242 |
Allowed algorithms
EC Diffie-Hellman (CVL Certs. #167 and #563, key agreement; key establishment methodology provides 128 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2020-10-30 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2020-10-30