808bits

i.MX8 DXL SECO HSM

FIPS 140-3 certificate #4837 · NXP Semiconductors, Inc. · data as of 2026-08-28
Active. Sunset date 2029-10-14, 1142 days away.
Caveat: When utilizing a Trusted Channel as specified in the Security Policy.

Certificate

Certificate number4837
StandardFIPS 140-3
Statusactive
Sunset date2029-10-14
Overall level3
Module typeHardware
EmbodimentSingle Chip
VendorNXP Semiconductors, Inc. · website
Hardware versionsP/N: version tag DA_SSL_iMX8DXL_SCU_SUBSYS_LN28FDSOI_1.56
Firmware versionsSECO ROM mem_I.MX8_s28roml_w24576x032m32B2_1Tlms_m0_1.7; SECO FW 5.9.0
EntropyENT (P)

Module description

The i.MX8 DXL SECO HSM hardware is a sub-chip subsystem of a single-chip embodiment that provides cryptographic engine and secure storage functions, intended for use in automotive or IoT applications.

Security level exceptions

  • Operational environment: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2953
AES-CCMA2962
AES-CMACA2954
AES-ECBA2953
AES-GCMA2964
AES-GCMA2964
ECDSA KeyGen (FIPS186-4)A2963
ECDSA SigGen (FIPS186-4)A2963
ECDSA SigVer (FIPS186-4)A2963
Hash DRBGA2955
HMAC-SHA2-224A2961
HMAC-SHA2-256A2961
HMAC-SHA2-384A2961
HMAC-SHA2-512A2961
KAS-ECC-SSC Sp800-56Ar3A2972
KDA OneStep Sp800-56Cr1A2965
KDF SP800-108A2966
KDF TLSA2973
RSA SigVer (FIPS186-4)A2967
SHA2-224A2956
SHA2-256A2955
SHA2-256A2956
SHA2-384A2956
SHA2-512A2956
TLS v1.2 KDF RFC7627A2973

Allowed algorithms

ECDSA with non-NIST recommended curves (Provides 128 or 192 bits of encryption strength); Per IG C.A; Use of Brainpool curves, allowed for use per [FIPS 140-3 IG] C.A: - BrainpoolP256R1 (128-bit security strength) - BrainpoolP384R1 (192-bit security strength));EC Diffie-Hellman with non-NIST recommended curves (Provides 128 or 192 bits of encryption strength); Per IGs D.F and C.A; Use of Brainpool curves in KAS, allowed for use per [FIPS 140-3 IG] C.A and [FIPS 140-3 IG] D.F Scenario 3: - BrainpoolP256R1 (available for both KEK and TLS use cases; 128-bit security strength) - BrainpoolP384R1 (available only for TLS use case; 192-bit security strength))

Tested configurations

  • [SOC_iMX8DualXL_28FDSOI_1.75 (P/Ns MIMX8SL3AVNFZAB, PIMX8SL3AVNFZAB, MIMX8DL3AVNFZAB, PIMX8DL3AVNFZAB)]

Validation history

DateTypeLab
2024-10-15InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-10-15

Source documents