This page was not yet optimized for use on mobile devices.
NITROX XL 1600-NFBE HSM Family
Certificate details
| Certificate ID | #2259 |
|---|---|
| Status | historical |
| Historical reason | 186-2 transition |
| Validation dates | 26.09.2014 , 11.01.2017 , 29.03.2018 |
| Standard | FIPS 140-2 |
| Security level | 3 |
| Type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Caveat | When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy |
| Exceptions |
|
| Description | The FN1620-NFBE2-G HSM adapter delivers the world's fastest FIPS 140-2 Level 3 Hardware Security Module (HSM) with PCIe Gen 2.0 via an SFF-8639 connector. The adapter offers up to 30,000 RSA operations per second and 5 Gbps of bulk crypto performance and is certified to the stringent US Government security standards. This FIPS family delivers an unmatched solution to the increasing performance, cryptographic and time to market requirements of the financial, government and healthcare vertical markets. |
| Version (Hardware) | P/N FN1620-NFBE2-G |
| Version (Firmware) | CN16XX-NFBE-FW-2.1-110020 |
| Vendor | Cavium Networks |
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES, AES256, AES-256, AES-128, RC4, Triple-DES, HMAC, HMAC-SHA-512, HMAC-SHA-256Asymmetric Algorithms
RSA 1024, ECDSA, ECC, DH, DSAHash functions
SHA-1, SHA1, SHA512, SHA256, SHA384, SHA-256, SHA-2, MD5Schemes
MAC, Key agreementProtocols
SSH, TLS 1.0, TLSRandomness
DRBG, RNGElliptic Curves
P-521, P-224, P-256, P-384, P-192, K-233, K-283, K-409, K-571, B-233, B-409, B-571, K-163, B-163, P-512, B-283Block cipher modes
ECB, CBC, CTRSecurity level
Level 3Certification process
out of scope, Upgrade Allows the CO to upgrade the firmware after the firmware load test. New firmware is out of scope of this validation; as the module’s validation to FIPS 140-2 is no longer valid once any, Downgrade Allows the CO to downgrade the firmware after the firmware load test. New firmware is out of scope of this validation; as the module’s validation to FIPS 140-2 is no longer valid once any, Upgrade Allows the default CO to upgrade the firmware after the firmware load test. New firmware is out of scope of this validation; as the module’s validation to FIPS 140-2 is no longer valid once any, Allows the default CO to downgrade the firmware after the firmware load test. New firmware is out of scope of this validation; as the module’s validation to FIPS 140-2 is no longer valid once anyAutomated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
No references are available for this certificate.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 2259,
"dgst": "2f5b70c621fdcb0d",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"AES#1266",
"HMAC#443",
"ECDSA#188",
"HMAC#1677",
"RSA#607",
"KAS#5",
"SHS#801",
"RSA#742",
"DSA#474",
"SHS#1166",
"SHS#1379",
"Triple-DES#898",
"AES#1265",
"CVL#166",
"HMAC#736",
"DRBG#32",
"ECDSA#150",
"KTS#5314"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"2.1"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 23
},
"ECDSA": {
"ECDSA": 20
}
},
"FF": {
"DH": {
"DH": 5
},
"DSA": {
"DSA": 12
}
},
"RSA": {
"RSA 1024": 2
}
},
"certification_process": {
"OutOfScope": {
"Allows the default CO to downgrade the firmware after the firmware load test. New firmware is out of scope of this validation; as the module\u2019s validation to FIPS 140-2 is no longer valid once any": 1,
"Downgrade Allows the CO to downgrade the firmware after the firmware load test. New firmware is out of scope of this validation; as the module\u2019s validation to FIPS 140-2 is no longer valid once any": 1,
"Upgrade Allows the CO to upgrade the firmware after the firmware load test. New firmware is out of scope of this validation; as the module\u2019s validation to FIPS 140-2 is no longer valid once any": 1,
"Upgrade Allows the default CO to upgrade the firmware after the firmware load test. New firmware is out of scope of this validation; as the module\u2019s validation to FIPS 140-2 is no longer valid once any": 1,
"out of scope": 4
}
},
"cipher_mode": {
"CBC": {
"CBC": 2
},
"CTR": {
"CTR": 4
},
"ECB": {
"ECB": 2
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"SSH": {
"SSH": 1
},
"TLS": {
"TLS": {
"TLS": 6,
"TLS 1.0": 10
}
}
},
"crypto_scheme": {
"KA": {
"Key agreement": 2
},
"MAC": {
"MAC": 13
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"B-163": 1,
"B-233": 2,
"B-283": 1,
"B-409": 2,
"B-571": 2,
"K-163": 1,
"K-233": 2,
"K-283": 2,
"K-409": 2,
"K-571": 2,
"P-192": 2,
"P-224": 4,
"P-256": 4,
"P-384": 2,
"P-512": 2,
"P-521": 6
}
},
"eval_facility": {},
"fips_cert_id": {
"Cert": {
"#1166": 1,
"#1265": 1,
"#1266": 1,
"#1379": 1,
"#150": 1,
"#1677": 1,
"#188": 1,
"#443": 1,
"#607": 1,
"#736": 1,
"#742": 1,
"#801": 1
}
},
"fips_certlike": {
"Certlike": {
"AES 128, 192": 1,
"AES-128, 192": 2,
"AES-256": 4,
"AES256": 1,
"Certificate RSA": 1,
"DRBG 1266": 1,
"HMAC SHA512": 1,
"HMAC-SHA-1": 2,
"HMAC-SHA-256": 2,
"HMAC-SHA-512": 2,
"PKCS#1": 1,
"RSA 1024": 2,
"RSA 7": 1,
"RSA PKCS#1": 1,
"SHA 160": 1,
"SHA 512": 1,
"SHA-1": 6,
"SHA-2": 1,
"SHA-256": 1,
"SHA1": 2,
"SHA256": 1,
"SHA384": 1,
"SHA512": 2,
"SHS KAT 160": 2,
"SHS KAT 256": 1
}
},
"fips_security_level": {
"Level": {
"Level 3": 6
}
},
"hash_function": {
"MD": {
"MD5": {
"MD5": 1
}
},
"SHA": {
"SHA1": {
"SHA-1": 6,
"SHA1": 2
},
"SHA2": {
"SHA-2": 1,
"SHA-256": 1,
"SHA256": 1,
"SHA384": 1,
"SHA512": 2
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 9
},
"RNG": {
"RNG": 4
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-2": 11,
"FIPS PUB 140-2": 2
},
"NIST": {
"NIST SP 800-131A": 3,
"SP 800-131A": 3,
"SP 800-56A": 5,
"SP 800-56B": 4
},
"PKCS": {
"PKCS#1": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 18,
"AES-128": 2,
"AES-256": 4,
"AES256": 1
},
"RC": {
"RC4": 2
}
},
"DES": {
"3DES": {
"Triple-DES": 10
}
},
"constructions": {
"MAC": {
"HMAC": 4,
"HMAC-SHA-256": 1,
"HMAC-SHA-512": 1
}
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"policy_metadata": {
"/Author": "cgoodman",
"/Company": "",
"/CreationDate": "D:20180327173152-07\u002700\u0027",
"/Creator": "Acrobat PDFMaker 17 for Word",
"/ModDate": "D:20180327173158-07\u002700\u0027",
"/Producer": "Adobe PDF Library 15.0",
"/SourceModified": "D:20180328003138",
"/Title": "A. Scope of Document",
"pdf_file_size_bytes": 491774,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 29
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "2095e494e4c727b52be7aca8afb32bd750a8be7a1b3815a786ab5df5179f5645",
"txt_hash": "321744b60569881fedb2840ba590a1f023d56d40df28eefe4fbb1d080e62dbf7"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertList0045.pdf",
"date_sunset": null,
"description": "The FN1620-NFBE2-G HSM adapter delivers the world\u0027s fastest FIPS 140-2 Level 3 Hardware Security Module (HSM) with PCIe Gen 2.0 via an SFF-8639 connector. The adapter offers up to 30,000 RSA operations per second and 5 Gbps of bulk crypto performance and is certified to the stringent US Government security standards. This FIPS family delivers an unmatched solution to the increasing performance, cryptographic and time to market requirements of the financial, government and healthcare vertical markets.",
"embodiment": "Multi-Chip Embedded",
"exceptions": [
"Mitigation of Other Attacks: N/A"
],
"fw_versions": "CN16XX-NFBE-FW-2.1-110020",
"historical_reason": "186-2 transition",
"hw_versions": "P/N FN1620-NFBE2-G",
"level": 3,
"mentioned_certs": {},
"module_name": "NITROX XL 1600-NFBE HSM Family",
"module_type": "Hardware",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "historical",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2014-09-26",
"lab": "UL Verification Services, Inc.",
"validation_type": "Initial"
},
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2017-01-11",
"lab": "UL Verification Services, Inc.",
"validation_type": "Update"
},
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2018-03-29",
"lab": "UL Verification Services, Inc.",
"validation_type": "Update"
}
],
"vendor": "Cavium Networks",
"vendor_url": "http://www.cavium.com"
}
}