808bits

Non-Volatile Memory express (NVMe) Data Path Security Cluster (DPSC) Module

FIPS 140-3 certificate #5455 · Google, LLC · data as of 2026-08-28
Active. Sunset date 2031-07-29, 1795 days away.
Caveat: No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.

Certificate

Certificate number5455
StandardFIPS 140-3
Statusactive
Sunset date2031-07-29
Overall level1
Module typeHardware
EmbodimentSingleChip
VendorGoogle, LLC · website

Module description

The Data Path Security Cluster is a hardware IP providing XTS-AES encryption to NVMe data in transit over the network. The cryptographic module accepts from its outside and stores cryptographic keys for multiple NVMe connections. Depending on the content of received data, the module shall or shall not apply cryptographic processing to the data. The DPSC contains 4 identical XTS-AES-256 decrypt engines, 4 identical XTS-AES-256 encrypt engines, key cache arbiter and key cache SRAM which is zeroized on reset. The data interfaces exposed to the NVMe Protocol Layer (NPL) within the NVMe Protocol Initiator (NPI) are read and write DMA interfaces. XTS keys are written to the module’s SRAM via Control/Status Register (CSR) writes from the Integrated Management Complex (IMC) located outside of the module boundary. On-demand self- tests may be initiated from the NPI using an on-demand self-test trigger over a wire interface.

Security level exceptions

  • Software/Firmware security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Validation history

DateTypeLab
2026-07-30InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2026-07-30

Source documents