808bits

PrismPlus Cryptographic Module

FIPS 140-3 certificate #4952 · Broadcom, Inc. · data as of 2026-08-28
Active. Sunset date 2030-01-26, 1246 days away.
Caveat: None

Certificate

Certificate number4952
StandardFIPS 140-3
Statusactive
Sunset date2030-01-26
Overall level1
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorBroadcom, Inc. · website
Hardware versionsG99-00139-01
Firmware versions14.2.338.0
EntropyENT (P)

Module description

The PrismPlus Cryptographic Module is a hardware Module intended for use by US Federal agencies or other markets that require a FIPS 140-3 validated network encryption device. The Module implemented on a PCIe Adapter is intended to be used in Fibre Channel based Storage Area Networks. The Module allows a Connection to be established between one of the multiple Host Initiator Entities (eg 256 Virtual Machine Drivers running on multiple CPU cores) on a Storage Server Appliance and one of the multiple Remote Host Target Entities (eg 1000s of Storage LUNs) on multiple Storage Device Appliances via one of the multiple Physical Ports (eg 4x 64GFC ports). The Connection facilitates transfer of data between a Host Initiator Entity on a Storage Server Appliance and Host Target Entity on a Storage Server Appliance using the FC (Fibre Channel) Protocol. The Module allows multiple (1000s) of connections between Host Initiator Entities on a Storage Server Appliance and Host Target Entities on Storage Device Appliances. The module can be used to support Data-in-Flight Encryption/Decryption between Storage Appliances in a FC-SAN environment. Encryption decisions are made on a connection basis, whereby only a subset of the connections could be enabled for Encryption. If a connection is enabled for Encryption, only a subset of the Frame Types (eg Data Frames only, not Command/Status/Control/etc. Frames) could be enabled for Encryption.

Security level exceptions

  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-ECBA2693
AES-GCMA2695
RSA SigVer (FIPS186-4)A2691
SHA2-256A2694

Tested configurations

  • N/A

Validation history

DateTypeLab
2025-01-27InitialUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2025-01-27

Source documents