Waveserver 5 Control Processor Module
Caveat: Interim validation. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. No operator authentication is enforced for executing security services that were unlocked by an authenticated service.
Certificate
| Certificate number | 4920 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2026-12-17 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Vendor | Ciena Corporation · website |
| Hardware versions | 186-3011-900 [revision 001 and revision 002], 186-3011-901 [revision 001 and revision 002] |
| Firmware versions | 2.3.12 |
Module description
The Ciena WaveLogic 5e Encryption Modem with AES-256-GCM, wire-speed optical layer encryption with line rates up to 800G for up to 6.4T of encrypted line capacity.
Security level exceptions
- Roles, services, and authentication: Level 3
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A3284 |
| AES-CTR | A3283 |
| AES-CTR | A3284 |
| AES-ECB | A3283 |
| AES-ECB | A3284 |
| AES-GCM | A3283 |
| AES-GCM | A3284 |
| ECDSA KeyGen (FIPS186-4) | A3284 |
| ECDSA KeyVer (FIPS186-4) | A3284 |
| ECDSA SigGen (FIPS186-4) | A3284 |
| ECDSA SigVer (FIPS186-4) | A3284 |
| Hash DRBG | A3284 |
| HMAC-SHA-1 | A3284 |
| HMAC-SHA2-256 | A3284 |
| HMAC-SHA2-384 | A3284 |
| HMAC-SHA2-512 | A3284 |
| KAS-ECC-SSC Sp800-56Ar3 | A3284 |
| KAS-FFC-SSC Sp800-56Ar3 | A3284 |
| KDF SP800-108 | A3284 |
| KDF SSH | A3284 |
| PBKDF | A3284 |
| RSA KeyGen (FIPS186-4) | A3284 |
| RSA SigGen (FIPS186-4) | A3284 |
| RSA SigVer (FIPS186-4) | A3284 |
| Safe Primes Key Generation | A3284 |
| Safe Primes Key Generation | A3284 |
| Safe Primes Key Generation | A3284 |
| Safe Primes Key Generation | A3284 |
| Safe Primes Key Generation | A3284 |
| Safe Primes Key Generation | A3284 |
| Safe Primes Key Verification | A3284 |
| Safe Primes Key Verification | A3284 |
| Safe Primes Key Verification | A3284 |
| Safe Primes Key Verification | A3284 |
| Safe Primes Key Verification | A3284 |
| Safe Primes Key Verification | A3284 |
| SHA-1 | A3284 |
| SHA2-224 | A3284 |
| SHA2-256 | A3284 |
| SHA2-384 | A3284 |
| SHA2-512 | A3284 |
| TDES-CBC | A3284 |
| TLS v1.2 KDF RFC7627 | A3284 |
| TLS v1.3 KDF | A3284 |
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-12-18 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-12-18