CN Series Encryptors
CN Series Encryptors, from Senetas Corporation Ltd., distributed by Thales SA (SafeNet), holds FIPS 140-2 certificate #3905 at overall level 3. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Certificate
| Certificate number | 3905 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Senetas Corporation Ltd., distributed by Thales SA (SafeNet) · website |
| Hardware versions | Senetas Corp. Ltd. CN4000 Series: A4010B (DC) and A4020B (DC); Senetas Corp. Ltd. CN6000 Series: A6010B (AC), A6011B (DC), A6012B (AC/DC), A6140B (AC), A6141B (DC) and A6142B (AC/DC); Senetas Corp. Ltd. CN9000 Series: A9100B (AC), A9101B (DC), A9102B (AC/DC), A9120B (AC), A9121B (DC) and A9122B (AC/DC); Senetas Corp. Ltd. & SafeNet Inc. CN4000 Series: A4010B (DC) and A4020B (DC); Senetas Corp. Ltd. & SafeNet Inc. CN6000 Series: A6010B (AC), A6011B (DC), A6012B (AC/DC), A6140B (AC), A6141B (DC) and A6142B (AC/DC); Senetas Corp. Ltd. & SafeNet Inc. CN9000 Series: A9100B (AC), A9101B (DC), A9102B (AC/DC), A9120B (AC), A9121B (DC) and A9122B (AC/DC); Senetas Corp. Ltd. & Thales CN4000 Series: A4010B (DC) and A4020B (DC); Senetas Corp. Ltd. & Thales CN6000 Series: A6010B (AC), A6011B (DC), A6012B (AC/DC), A6140B (AC), A6141B (DC) and A6142B (AC/DC); Senetas Corp. Ltd. & Thales CN9000 Series: A9100B (AC), A9101B (DC), A9102B (AC/DC), A9120B (AC), A9121B (DC) and A9122B (AC/DC) |
| Firmware versions | 5.1.1 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The CN4010, CN4020, CN6010, CN6140, CN9100 and CN9120 are high-speed hardware encryption platforms that secure data over twisted-pair and optical Ethernet networks. The modules support line rates from 10Mb/s to 100Gb/s. All models except CN4010 are equipped with pluggable transceivers to support a variety of optical network interfaces. Data privacy is provided by FIPS approved AES algorithms in CFB, CTR and GCM modes. Additional transmission security is provided via TRANSEC (Traffic Flow Security) which can be used to remove patterns in network traffic and prevent traffic analysis attacks.
Approved algorithms (12)
| Algorithm | CAVP certificates |
|---|---|
| AES | C1331, C1332, C1333, C1334, C1335, C1336, C1337, C1338, C1342, C1343, C1344, C1345, C1346 |
| CKG | vendor affirmed |
| CVL | C1331 |
| DRBG | C1331 |
| ECDSA | C1331 |
| HMAC | C1331 |
| KAS | C1331 |
| KBKDF | C1331 |
| KTS | vendor affirmed |
| RSA | C2206 |
| SHS | C1331 |
| Triple-DES | C1331 |
Allowed algorithms
Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C1331, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-04-22 | Initial | Lightship Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2021-04-22