{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "e9c15acddd2bbb31", "cert_id": 5449, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Waveserver Ai Encryption Module", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-07-29", "validation_type": "Initial", "lab": "Acumen Security"}], "vendor_url": "http://www.ciena.com", "vendor": "Ciena Corporation", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf", "module_type": "Hardware", "standard": "FIPS 140-3", "status": "active", "level": 2, "caveat": "No assurance of minimum security of SSPs that are externally loaded, or of SSPs established with externally loaded SSPs", "exceptions": ["Operational environment: N/A", "Non-invasive security: N/A", "Mitigation of other attacks: N/A"], "embodiment": "MultiChipEmbed", "description": "The Waveserver Ai Encryption Module provides fully secure cryptographic functionality, including peer authentication, key derivation, datapath encryption, physical security, and identification and authentication of the module\u2019s Crypto Officer (CO). It is the physical security boundary and is composed of FPGA, processor, DDR4 (DRAM), Flash and the PCB-embedded wire connections between them, and all associated physical security mechanisms. All traffic entering and exiting the module is encrypted/decrypted at wire speed (100Gb/s, 200Gb/s, 300Gb/s and 400Gb/s depending on line modulation scheme selected) using AES-256 GCM mode.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2031-07-28", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#5": 1, "#3": 1, "#1": 1}}, "fips_security_level": {"Level": {"Level 1": 1, "Level 2": 1}}, "fips_certlike": {"Certlike": {"SHA2-256": 10, "SHA2-384": 8, "SHA2-512": 5, "SHA2- 384": 1, "SHA3- 256": 1, "SHA-256": 1, "RSA 4096": 4, "AES-256": 1, "AES- GCM 256": 3}}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-256": 1, "AES": 2, "AES-": 6}, "CAST": {"CAST": 34}}, "constructions": {"MAC": {"HMAC": 1}}}, "asymmetric_crypto": {"RSA": {"RSA 4096": 4}, "ECC": {"ECDH": {"ECDH": 6, "ECDHE": 1}, "ECDSA": {"ECDSA": 30}}, "FF": {"DH": {"DHE": 2, "DH": 14}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA2": {"SHA-256": 1}}}, "crypto_scheme": {"KA": {"Key Agreement": 5}}, "crypto_protocol": {"TLS": {"TLS": {"TLS v1.3": 8, "TLS": 10, "TLS 1.3": 36}}}, "randomness": {"PRNG": {"DRBG": 41}, "RNG": {"RNG": 4, "RBG": 2}}, "cipher_mode": {"GCM": {"GCM": 10}}, "ecc_curve": {"NIST": {"P-256": 10, "P-384": 12, "P-521": 20}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {"Generic": {"Crypto Library 2": 2}}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 8}, "IBM": {"SSC": 2}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 5, "FIPS186-5": 17, "FIPS 186-5": 5, "FIPS 198-1": 1, "FIPS 180-4": 3, "FIPS18": 2}, "NIST": {"SP 800-38A": 1, "SP 800-38D": 2, "SP 800-90A": 1, "SP 800-56A": 1, "SP 800-56C": 1, "SP 800-135": 1}, "RFC": {"RFC 8446": 2}, "X509": {"X.509": 3}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 613754, "pdf_is_encrypted": false, "pdf_number_of_pages": 37, "/Producer": "Microsoft\u00ae Word for Microsoft 365", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/CreationDate": "D:20260727075238-04'00'", "/ModDate": "D:20260727075238-04'00'", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/entropy/E199_PublicUse.pdf"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["ECDSA KeyVer (FIPS186-5)A5909", "TLS v1.3 KDFA5909", "Hash DRBGA5909", "ECDSA SigVer (FIPS186-5)A5909", "SHA2-512A5909", "ECDSA SigGen (FIPS186-5)A5909", "RSA SigVer (FIPS186-5)A5909", "SHA2-384A5909", "AES-GCMC120", "HMAC-SHA2-256A5909", "KDA TwoStep Sp800-56Cr1A5909", "KAS-ECC-SSC Sp800-56Ar3A5909", "ECDSA KeyGen (FIPS186-5)A5909", "AES-ECBC120", "SHA2-256A5909"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "c9c7813ab865824568428750e043481e55fb227f94baa2159881bd9a2cd1c52d", "txt_hash": "4582d12b5f322c9d40904979dd61b49bf9181607a79e942b2313d4f6e2c6eabc", "json_hash": null}}}