NITROXIII CNN35XX-NFBE HSM Family
Certificate
| Certificate number | 5219 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-05-29 |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | MultiChipEmbed |
| Vendor | JISA Softech Private Limited · website |
| Hardware versions | HW-1.0 (CNL3510-NFBE-G; CNL3510P-NFBE-G; CNL3530-NFBE-G; CNL3560-NFBE-G; CNL3560P-NFBE-G; CNN3510-NFBE-G; CNN3530-NFBE-G; CNN3560-NFBE-G; CNN3560P-NFBE-G); HW-2.0 (CNL3510-NFBE-2.0-G; CNL3510B-NFBE-2.0-G; CNL3510P-NFBE-2.0-G; CNL3510PB-NFBE-2.0-G; CNL3530-NFBE-2.0-G; CNL3530B-NFBE-2.0-G; CNL3560-NFBE-2.0-G; CNL3560B-NFBE-2.0-G; CNL3560P-NFBE-2.0-G; CNL3560PB-NFBE-2.0-G; CNN3505LP-NFBE-2.0-G; CNN3510-NFBE-2.0-G; CNN3510LP-NFBE-2.0-G; CNN3510LPB-NFBE-2.0-G; CNN3530-NFBE-2.0-G; CNN3560-NFBE-2.0-G; CNN3560P-NFBE-2.0-G); HW-3.0 (CNL3510-NFBE-3.0-G; CNL3510A-NFBE-3.0-G; CNL3510C-NFBE-3.0-G; CNL3510D-NFBE-3.0-G; CNL3510E-NFBE-3.0-G; CNL3510F-NFBE-3.0-G; CNL3510I-NFBE-3.0-G; CNL3510P-NFBE-3.0-G; CNL3530-NFBE-3.0-G; CNL3530A-NFBE-3.0-G; CNL3530B-NFBE-3.0-G; CNL3530C-NFBE-3.0-G; CNL3530D-NFBE-3.0-G; CNL3530E-NFBE-3.0-G; CNL3530F-NFBE-3.0-G; CNL3560-NFBE-3.0-G; CNL3560A-NFBE-3.0-G; CNL3560B-NFBE-3.0-G; CNL3560B-NFBE-3.0-G-FB; CNL3560C-NFBE-3.0-G; CNL3560D-NFBE-3.0-G; CNL3560E-NFBE-3.0-G; CNL3560F-NFBE-3.0-G; CNL3560P-NFBE-3.0-G; CNN3505LP-NFBE-3.0-G; CNN3505LPA-NFBE-3.0-G; CNN3505LPC-NFBE-3.0-G; CNN3505LPD-NFBE-3.0-G; CNN3505LPE-NFBE-3.0-G; CNN3505LPF-NFBE-3.0-G; CNN3510-NFBE-3.0-G; CNN3510A-NFBE-3.0-G; CNN3510C-NFBE-3.0-G; CNN3510D-NFBE-3.0-G; CNN3510E-NFBE-3.0-G; CNN3510F-NFBE-3.0-G; CNN3510LP-NFBE-3.0-G; CNN3510LPA-NFBE-3.0-G; CNN3510LPB-NFBE-3.0-G; CNN3510LPC-NFBE-3.0-G; CNN3510LPD-NFBE-3.0-G; CNN3510LPE-NFBE-3.0-G; CNN3510LPF-NFBE-3.0-G; CNN3530-NFBE-3.0-G; CNN3530A-NFBE-3.0-G; CNN3530C-NFBE-3.0-G; CNN3530D-NFBE-3.0-G; CNN3530E-NFBE-3.0-G; CNN3530F-NFBE-3.0-G; CNN3560-NFBE-3.0-G; CNN3560A-NFBE-3.0-G; CNN3560C-NFBE-3.0-G; CNN3560D-NFBE-3.0-G; CNN3560E-NFBE-3.0-G; CNN3560F-NFBE-3.0-G; CNN3560P-NFBE-3.0-G) |
| Firmware versions | CNN35XX-NFBE-FW-2.09-0702, CNN35XX-NFBE-SMW-2.09-0702, CNN35XX-UBOOT-4.03-03 |
| Entropy | ENT (P) |
Module description
The NITROXIII CNN35XX-NFBE HSM Family module is a high-performance purpose-built security solution for crypto acceleration. The module provides a FIPS 140-3 overall Level 3 security solution. The module is deployed inside CryptoBind HSM and CryptoBind DSS to provide crypto and TLS 1.0/1.1/1.2 acceleration in a secure manner to the system host. It is typically deployed in a CryptoBind HSM & CryptoBind DSS network appliance to provide cryptographic operations. The module’s functions are accessed over the PCIe interface via an API defined by the module inside CryptoBind HSM and CryptoBind DSS.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | C819 |
| AES-CBC | C839 |
| AES-CCM | C839 |
| AES-CMAC | A1190 |
| AES-CMAC | A1195 |
| AES-CMAC | C839 |
| AES-CTR | C839 |
| AES-ECB | C819 |
| AES-ECB | C839 |
| AES-GCM | A1203 |
| AES-GCM | C839 |
| AES-GMAC | C839 |
| AES-KW | C1263 |
| AES-KWP | C1263 |
| Counter DRBG | C821 |
| DSA KeyGen (FIPS186-4) | C823 |
| DSA PQGGen (FIPS186-4) | C823 |
| DSA PQGVer (FIPS186-4) | C823 |
| DSA SigGen (FIPS186-4) | C823 |
| DSA SigVer (FIPS186-4) | C823 |
| ECDSA KeyGen (FIPS186-4) | C825 |
| ECDSA KeyVer (FIPS186-4) | C825 |
| ECDSA SigGen (FIPS186-4) | C825 |
| ECDSA SigGen (FIPS186-4) | C825 |
| ECDSA SigGen (FIPS186-4) | C829 |
| ECDSA SigVer (FIPS186-4) | C825 |
| ECDSA SigVer (FIPS186-4) | C829 |
| Hash DRBG | C830 |
| HMAC-SHA-1 | C822 |
| HMAC-SHA-1 | C839 |
| HMAC-SHA2-224 | C822 |
| HMAC-SHA2-224 | C839 |
| HMAC-SHA2-256 | C822 |
| HMAC-SHA2-256 | C839 |
| HMAC-SHA2-384 | C822 |
| HMAC-SHA2-384 | C839 |
| HMAC-SHA2-512 | C822 |
| HMAC-SHA2-512 | C839 |
| KAS-ECC CDH-Component | C829 |
| KAS-ECC Sp800-56Ar3 | A1219 |
| KAS-ECC-SSC Sp800-56Ar3 | A1220 |
| KAS-ECC-SSC Sp800-56Ar3 | A2161 |
| KAS-IFC-SSC | A1193 |
| KDA HKDF Sp800-56Cr1 | A1192 |
| KDA OneStep Sp800-56Cr1 | A1192 |
| KDA TwoStep Sp800-56Cr1 | A1192 |
| KDF ANS 9.63 | C825 |
| KDF SP800-108 | A1191 |
| KDF SP800-108 | C826 |
| KDF SP800-108 | C839 |
| KDF TLS | C840 |
| KTS-IFC | A1194 |
| PBKDF | A1196 |
| RSA Decryption Primitive | A1200 |
| RSA Decryption Primitive | C839 |
| RSA KeyGen (FIPS186-4) | A1199 |
| RSA KeyGen (FIPS186-4) | C824 |
| RSA SigGen (FIPS186-2) | C824 |
| RSA SigGen (FIPS186-4) | A1199 |
| RSA Signature Primitive | C839 |
| RSA SigVer (FIPS186-4) | A1199 |
| RSA SigVer (FIPS186-4) | A1201 |
| RSA SigVer (FIPS186-4) | C824 |
| SHA-1 | C820 |
| SHA-1 | SHS 1780 |
| SHA2-224 | C820 |
| SHA2-224 | SHS 1780 |
| SHA2-256 | A1202 |
| SHA2-256 | C820 |
| SHA2-256 | SHS 1780 |
| SHA2-384 | C820 |
| SHA2-384 | SHS 1780 |
| SHA2-512 | C820 |
| SHA2-512 | SHS 1780 |
| SHA3-224 | A1197 |
| SHA3-256 | A1197 |
| SHA3-512 | A1197 |
| SHAKE-128 | A1197 |
| SHAKE-256 | A1197 |
| TDES-CBC | TDES 1311 |
| TDES-ECB | C1169 |
| TDES-ECB | TDES 1311 |
| TDES-KW | C1263 |
Allowed algorithms
AES (Cert. #C819, key unwrapping provides 128, 192 or 256 bits of encryption strength. Per IG D.G.; Key unwrap only N3FIPS-OpenSSL-1.1.1-AES ECB mode: Decrypt; 128, 192 and 256 bits CBC mode: Decrypt: 128, 192 and 256 bits *Legacy use only);EC Diffie-Hellman with non-NIST recommended curves (Cert. #C829, provides 112, 128, 160, 192 or 256 bits of encryption strength. Per IG C.A. ; EC-DH Secp224k1(112 bits), Secp256K1 (128 bits) • Prime order curve, generated as per FIPS 186-4 Section 6.1.1 brainpoolP224r1(112 bits), brainpoolP256r1(128 bits), brainpoolP320r1(160 bits), brainpoolP384r1(192 bits), brainpoolP512r1(256 bits) FRP256v1 (128 bits) • Prime order curve, generated as per FIPS 186-4 Section 6.1.1 (SHA-1*, SHA2-224, SHA2-256, SHA2-384, SHA2-512));ECDSA with non-NIST recommended curves (Cert. #C825, provides 112, 128, 160, 192 or 256 bits of encryption strength. Per IG C.A. ; EC Key generation, sign, verify Secp224k1(112 bits), Secp256K1 (128 bits) • Prime order curve, generated as per FIPS 186-4 Section 6.1.1 brainpoolP224r1(112 bits), brainpoolP256r1(128 bits), brainpoolP320r1(160 bits), brainpoolP384r1(192 bits), brainpoolP512r1(256 bits) FRP256v1 (128 bits) • Prime order curve, generated as per FIPS 186-4 Section 6.1.1 (SHA-1*, SHA2-224, SHA2-256, SHA2-384, SHA2-512))
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-03-31 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2026-03-31