Purity Encryption Module
Caveat: No assurance of the minimum strength of generated SSPs (e.g., keys); No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Certificate
| Certificate number | 4937 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2030-01-05 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Pure Storage, Inc. · website |
| Software versions | FA-1.5 |
Module description
Purity Encryption Module is a standalone cryptographic module for the Purity Operating Environment for FlashArray (Purity//FA). Purity//FA powers Pure Storage's FlashArray family of products which provide economical all-flash storage. Purity Encryption Module enables FlashArray to support always-on, inline encryption of data with an internal key management scheme that requires no user intervention.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CTR | A4396 |
| AES-ECB | A4396 |
| AES-KW | A4396 |
| Counter DRBG | A4396 |
| HMAC-SHA2-256 | A4396 |
| SHA2-256 | A4396 |
Tested configurations
- Purity OS 6.4 running on FlashArray X20R3 with Intel Xeon Silver 4210R with PAA
- Purity OS 6.4 running on FlashArray X20R3 with Intel Xeon Silver 4210R without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2025-01-06 | Initial | Teron Labs |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2025-01-06
Known CVEs in this module family (heuristic match)
Name-based association with the module's product family, not a statement about the validated boundary. See methodology.
| CVE | CVSS | Severity |
|---|---|---|
| CVE-2023-31042 | 7.7 | HIGH |
| CVE-2023-36627 | 7.7 | HIGH |
| CVE-2023-28372 | 6.5 | MEDIUM |