Marvell LS2 HSM Family
Caveat: When installed, initialized and configured as specified in Section 11.1 of the Security Policy. When operated in approved mode
Certificate
| Certificate number | 5502 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-08-24 |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | MultiChipEmbed |
| Vendor | Marvell Semiconductor, Inc. · website |
Module description
The LS2 HSM module is a multi-chip PCIe adapter with firmware. It consists of multiple firmware components, including an operating system, applications exposing services and interfaces related to secure key management, crypto operations, and policy management of the module.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A1948 |
| AES-CBC | A7544 |
| AES-CCM | A7544 |
| AES-CMAC | A1948 |
| AES-CMAC | A7544 |
| AES-CTR | A1948 |
| AES-CTR | A7544 |
| AES-ECB | A1948 |
| AES-ECB | A7544 |
| AES-GCM | A1948 |
| AES-GCM | A7544 |
| AES-GMAC | A1948 |
| AES-GMAC | A7544 |
| AES-KW | A1948 |
| AES-KWP | A1948 |
| Counter DRBG | A1948 |
| ECDSA KeyGen (FIPS186-4) | A1948 |
| ECDSA KeyGen (FIPS186-5) | A7545 |
| ECDSA KeyVer (FIPS186-4) | A1948 |
| ECDSA SigGen (FIPS186-4) | A1948 |
| ECDSA SigGen (FIPS186-5) | A7544 |
| ECDSA SigVer (FIPS186-4) | A1948 |
| ECDSA SigVer (FIPS186-5) | A7544 |
| Hash DRBG | A7544 |
| HMAC-SHA-1 | A1948 |
| HMAC-SHA-1 | A7544 |
| HMAC-SHA2-224 | A1948 |
| HMAC-SHA2-224 | A7544 |
| HMAC-SHA2-256 | A1948 |
| HMAC-SHA2-256 | A7544 |
| HMAC-SHA2-384 | A1948 |
| HMAC-SHA2-384 | A7544 |
| HMAC-SHA2-512 | A1948 |
| HMAC-SHA2-512 | A7544 |
| HMAC-SHA3-224 | A1948 |
| HMAC-SHA3-224 | A7544 |
| HMAC-SHA3-256 | A1948 |
| HMAC-SHA3-256 | A7544 |
| HMAC-SHA3-384 | A1948 |
| HMAC-SHA3-384 | A7544 |
| HMAC-SHA3-512 | A1948 |
| HMAC-SHA3-512 | A7544 |
| KAS-ECC Sp800-56Ar3 | A1948 |
| KAS-ECC-SSC Sp800-56Ar3 | A1948 |
| KAS-ECC-SSC Sp800-56Ar3 | A7544 |
| KAS-IFC-SSC | A1948 |
| KDA HKDF Sp800-56Cr1 | A1948 |
| KDA OneStep Sp800-56Cr1 | A1948 |
| KDA TwoStep Sp800-56Cr1 | A1948 |
| KDF ANS 9.63 | A1948 |
| KDF SP800-108 | A1948 |
| KDF SP800-108 | A7544 |
| KTS-IFC | A1948 |
| KTS-IFC | A7545 |
| RSA Decryption Primitive | A1948 |
| RSA Decryption Primitive Sp800-56Br2 | A7544 |
| RSA KeyGen (FIPS186-5) | A1948 |
| RSA KeyGen (FIPS186-5) | A7545 |
| RSA SigGen (FIPS186-5) | A1948 |
| RSA Signature Primitive | A1948 |
| RSA Signature Primitive | A7544 |
| RSA SigVer (FIPS186-4) | A1946 |
| RSA SigVer (FIPS186-5) | A1948 |
| RSA SigVer (FIPS186-5) | A7545 |
| SHA-1 | A1948 |
| SHA-1 | A7544 |
| SHA2-224 | A1948 |
| SHA2-224 | A7544 |
| SHA2-256 | A1946 |
| SHA2-256 | A1948 |
| SHA2-256 | A7544 |
| SHA2-384 | A1948 |
| SHA2-384 | A7544 |
| SHA2-512 | A1948 |
| SHA2-512 | A7544 |
| SHA3-224 | A1948 |
| SHA3-224 | A7544 |
| SHA3-256 | A1948 |
| SHA3-256 | A7544 |
| SHA3-384 | A1948 |
| SHA3-384 | A7544 |
| SHA3-512 | A1948 |
| SHA3-512 | A7544 |
| TDES-CBC | A1948 |
| TDES-CBC | A7544 |
| TDES-ECB | A7544 |
| TDES-KW | A1948 |
| TLS v1.2 KDF RFC7627 | A1948 |
| TLS v1.2 KDF RFC7627 | A7544 |
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-08-25 | Initial | Teron Labs |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-28: first observed by this tracker, status active
- Validation dates on record: 2026-08-25