i.MX8 DXL V2X
Certificate
| Certificate number | 4839 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-10-15 |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Vendor | NXP Semiconductors, Inc. · website |
| Hardware versions | P/N: SECO Block: DA_SSL_iMX8DXL_SCU_SUBSYS_LN28FDSOI_1.56; V2X Block: DA_SSL_iMX8DXL_DB_SUBSYS_CMOS28FDSOI_1.77 |
| Firmware versions | SECO ROM: mem_I.MX8_s28roml_w24576x032m32B2_1Tlms_m0_1.7; V2XP ROM: mem_I.MX8_s28roml_w32768x032m32B2_1Tlm_cm0_rom_1.18; V2XS ROM: mem_I.MX8_s28roml_w45056x032m32B4_1Tlm_empty_1.10; SECO FW 5.9.0; V2X FW 1.2.1 |
| Entropy | ENT (P) |
Module description
N/A
Security level exceptions
- Operational environment: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A2953 |
| AES-CBC | A2957 |
| AES-CCM | A2962 |
| AES-CCM | A2968 |
| AES-CMAC | A2954 |
| AES-CMAC | A2958 |
| AES-ECB | A2953 |
| AES-ECB | A2957 |
| AES-GCM | A2964 |
| AES-GCM | A2964 |
| AES-GCM | A2975 |
| AES-GCM | A2975 |
| Counter DRBG | A2969 |
| Counter DRBG | A2970 |
| ECDSA KeyGen (FIPS186-4) | A2963 |
| ECDSA KeyGen (FIPS186-4) | A2974 |
| ECDSA SigGen (FIPS186-4) | A2963 |
| ECDSA SigGen (FIPS186-4) | A2974 |
| ECDSA SigVer (FIPS186-4) | A2963 |
| ECDSA SigVer (FIPS186-4) | A2974 |
| Hash DRBG | A2955 |
| HMAC-SHA2-224 | A2961 |
| HMAC-SHA2-256 | A2961 |
| HMAC-SHA2-384 | A2961 |
| HMAC-SHA2-512 | A2961 |
| KAS-ECC-SSC Sp800-56Ar3 | A2972 |
| KAS-ECC-SSC Sp800-56Ar3 | A2977 |
| KDA OneStep Sp800-56Cr1 | A2965 |
| KDA OneStep Sp800-56Cr1 | A2976 |
| KDF SP800-108 | A2966 |
| KDF TLS | A2973 |
| KDF TLS | A2973 |
| RSA SigVer (FIPS186-4) | A2967 |
| SHA2-224 | A2956 |
| SHA2-224 | A2959 |
| SHA2-224 | A2960 |
| SHA2-256 | A2955 |
| SHA2-256 | A2956 |
| SHA2-256 | A2959 |
| SHA2-256 | A2960 |
| SHA2-384 | A2956 |
| SHA2-384 | A2959 |
| SHA2-384 | A2960 |
| SHA2-512 | A2956 |
| SHA2-512 | A2959 |
| SHA2-512 | A2960 |
| TLS v1.2 KDF RFC7627 | A2973 |
Allowed algorithms
ECDSA with non-NIST recommended curves (Provides 128 or 192 bits of encryption strength); Per IG C.A; Use of Brainpool curves, allowed for use per [FIPS 140-3 IG] C.A: - BrainpoolP256R1 (128-bit security strength) - BrainpoolP384R1 (192-bit security strength));EC Diffie-Hellman with non-NIST recommended curves (Provides 128 or 192 bits of encryption strength); Per IGs D.F and C.A; Use of Brainpool curves in KAS, allowed for use per [FIPS 140-3 IG] C.A and [FIPS 140-3 IG] D.F Scenario 3: - BrainpoolP256R1 (available for both KEK and TLS use cases; 128-bit security strength) - BrainpoolP384R1 (available only for TLS use case; 192-bit security strength))
Tested configurations
- [SOC_iMX8DualXL_28FDSOI_1.75 (P/Ns MIMX8SL2AVNFZAB, PIMX8SL2AVNFZAB, MIMX8DL2AVNFZAB, PIMX8DL2AVNFZAB)]
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-10-16 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-10-16