Infinera Groove G30 Cryptographic Module
Infinera Groove G30 Cryptographic Module, from Infinera Corporation (Nokia), holds FIPS 140-3 certificate #5538 at overall level 1. The validation is active, with a sunset date of 2031-10-04. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section Life-Cycle Assurance of the Security Policy
Certificate
| Certificate number | 5538 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-10-04 |
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | MultiChipStand |
| Vendor | Infinera Corporation (Nokia) · website |
Module description
Quoted from the NIST CMVP entry for this certificate.
Infinera Groove G30 Cryptographic Module is an innovative stackable transport solution for cloud and data center networks that delivers 4.8 terabits of capacity throughput in a compact 1RU form factor. Infinera Groove G30 Cryptographic Module enables Wide Area Network (WAN) cloud connectivity services, including 10G, 40G, 100G, and 400G client services. Infinera Groove G30 Cryptographic Module supports programmable DWDM line interface bandwidth and performance to optimize high-capacity transmission from 100G to 600G per wavelength in metro, regional, or long-haul DCI applications. As a key solution of Infinera Open Line System (OLS), ROADM (Reconfigurable Optical Add-Drop Multiplexer) provides reconfigurable multiplexing and de-multiplexing of wavelengths that are added, dropped, or passed through from one DWDM interface to up to three other DWDM interfaces. Infinera Groove G30 Cryptographic Module provides DWDM Optical Multiplexing/De-multiplexing, optical amplification, tunable dispersion compensation, optical time domain reflectometer, optical channel monitoring, and protection with relevant Optical Cards.
Security level exceptions
- Roles, services, and authentication: Level 3
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms (35)
| Algorithm | CAVP certificates |
|---|---|
| AES-CBC | A5078, A5112 |
| AES-CTR | A5078, A5112, AES 3844 |
| AES-ECB | A5078, A5112, AES 4707 |
| AES-GCM | A5078, A5112, AES 4770, C646 |
| AES-GMAC | AES 3844 |
| AES-KW | A5112 |
| Counter DRBG | A5112 |
| ECDSA KeyGen (FIPS186-5) | A5112 |
| ECDSA SigGen (FIPS186-5) | A5112 |
| ECDSA SigVer (FIPS186-4) | A5112 |
| ECDSA SigVer (FIPS186-5) | A5112 |
| HMAC-SHA-1 | A5078, A5112 |
| HMAC-SHA2-224 | A5112 |
| HMAC-SHA2-256 | A5078, A5112 |
| HMAC-SHA2-384 | A5078, A5112 |
| HMAC-SHA2-512 | A5078, A5112 |
| KAS-ECC-SSC Sp800-56Ar3 | A5112 |
| KAS-FFC-SSC Sp800-56Ar3 | A5112 |
| KDF IKEv2 | A5112 |
| KDF SNMP | A5112 |
| KDF SSH | A5112 |
| RSA KeyGen (FIPS186-5) | A5112 |
| RSA SigGen (FIPS186-5) | A5112 |
| RSA SigVer (FIPS186-4) | A5112 |
| RSA SigVer (FIPS186-5) | A5112 |
| Safe Primes Key Generation | A5112 |
| Safe Primes Key Verification | A5112 |
| SHA-1 | A5078, A5112 |
| SHA2-224 | A5112 |
| SHA2-256 | A5078, A5112 |
| SHA2-384 | A5078, A5112 |
| SHA2-512 | A5078, A5112 |
| SHA3-256 | A5078, A5148 |
| TLS v1.2 KDF RFC7627 | A5112 |
| TLS v1.3 KDF | A5112 |
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-10-05 | Initial | Asia Pacific IT Laboratory, TUV NORD |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-10-09: first observed by this tracker, status active
- Validation dates on record: 2026-10-05