PrismPlus Cryptographic Module

Certificate details

Certificate ID #4952
Status active
Validation dates 27.01.2025
Sunset date 26-01-2030
Standard FIPS 140-3
Security level 1
Type Hardware
Embodiment Multi-Chip Embedded
Caveat None
Exceptions
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The PrismPlus Cryptographic Module is a hardware Module intended for use by US Federal agencies or other markets that require a FIPS 140-3 validated network encryption device. The Module implemented on a PCIe Adapter is intended to be used in Fibre Channel based Storage Area Networks. The Module allows a Connection to be established between one of the multiple Host Initiator Entities (eg 256 Virtual Machine Drivers running on multiple CPU cores) on a Storage Server Appliance and one of the multiple Remote Host Target Entities (eg 1000s of Storage LUNs) on multiple Storage Device Appliances via one of the multiple Physical Ports (eg 4x 64GFC ports). The Connection facilitates transfer of data between a Host Initiator Entity on a Storage Server Appliance and Host Target Entity on a Storage Server Appliance using the FC (Fibre Channel) Protocol. The Module allows multiple (1000s) of connections between Host Initiator Entities on a Storage Server Appliance and Host Target Entities on Storage Device Appliances. The module can be used to support Data-in-Flight Encryption/Decryption between Storage Appliances in a FC-SAN environment. Encryption decisions are made on a connection basis, whereby only a subset of the connections could be enabled for Encryption. If a connection is enabled for Encryption, only a subset of the Frame Types (eg Data Frames only, not Command/Status/Control/etc. Frames) could be enabled for Encryption.
Version (Hardware) G99-00139-01
Version (Firmware) 14.2.338.0
Vendor Broadcom, Inc. http://www.broadcom.com/
Lab UL Verification Services, Inc.
Algorithms
  • AES-ECBA2693
  • AES-GCMA2695
  • RSA SigVer (FIPS186-4)A2691
  • SHA2-256A2694
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES
Asymmetric Algorithms
RSA 2048, RSA2048
Protocols
IKEv2
Randomness
DRBG
Block cipher modes
ECB, GCM

Vendor
Broadcom, Broadcom Inc

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4952,
  "dgst": "ecd8409a7716ba7f",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "#A2696",
        "#A2692",
        "#A2694",
        "RSA SigVer (FIPS186-4)A2691",
        "#A2693",
        "#A2695",
        "#A2691",
        "AES-ECBA2693",
        "AES-GCMA2695",
        "SHA2-256A2694"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "14.2.338.0"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 33,
    "br1_tables": null,
    "is_br1_format": false,
    "keywords": {
      "asymmetric_crypto": {
        "RSA": {
          "RSA 2048": 6,
          "RSA2048": 4
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "ECB": {
          "ECB": 4
        },
        "GCM": {
          "GCM": 7
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKEv2": 1
        }
      },
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES 256": 1,
          "AES [197": 2,
          "RSA 2048": 6,
          "RSA2048": 4,
          "SHA2-256": 14
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1
        }
      },
      "hash_function": {},
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 12
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 7,
          "FIPS PUB 140-3": 1,
          "FIPS140-3": 1,
          "FIPS180-4": 1,
          "FIPS186-4": 1
        },
        "ISO": {
          "ISO/IEC 19790": 2,
          "ISO/IEC 24759": 4
        },
        "NIST": {
          "SP 800-38D": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 12
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Broadcom": {
          "Broadcom": 146,
          "Broadcom Inc": 1
        }
      },
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "RSA SigVer (FIPS186-4)A2691",
        "AES-ECBA2693",
        "AES-GCMA2695",
        "SHA2-256A2694"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A2696",
        "#A2692",
        "#A2694",
        "#A2693",
        "#A2695",
        "#A2691"
      ]
    },
    "policy_metadata": {
      "/Author": "Ravi Shenoy",
      "/Category": "",
      "/Comments": "",
      "/Company": "",
      "/ContentTypeId": "0x01010066E6728D5E109246855D376F3778675F",
      "/CreationDate": "D:20250117080035-08\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 24 for Word",
      "/Keywords": "",
      "/Manager": "",
      "/ModDate": "D:20250117080043-08\u002700\u0027",
      "/Producer": "Adobe PDF Library 24.5.96",
      "/SourceModified": "D:20250117155805",
      "/Subject": "FIPS 140-2 Security Policy",
      "/Title": "",
      "/_dlc_DocIdItemGuid": "189bbc1a-71fa-4077-a078-0f3e60820f51",
      "pdf_file_size_bytes": 686657,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://www.webopedia.com/TERM/N/network.html",
          "https://en.wikipedia.org/wiki/Server_(computing)",
          "https://en.wikipedia.org/wiki/Data_center",
          "https://en.wikipedia.org/wiki/Storage_area_network",
          "https://www.webopedia.com/TERM/R/resource.html",
          "https://en.wikipedia.org/wiki/Computer_data_storage",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=35306",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=35304",
          "https://www.webopedia.com/TERM/D/device.html",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=35305",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=35302"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 29
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "686b4b35011333422cb79be33aa1a48a57a5ce61593e9415ca97a6ba085b0f05",
      "source_hash": "2b1363d17140aae7fcecdc3323a8b39204a2cd3825a65b70dae8e3ad50f68c0f",
      "txt_hash": "da2bcc2ad6a2cc2939d4e92380e897effc9c02804e1f65aa3a5e0ad05d695145"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "None",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/January 2025-signed.pdf",
    "date_sunset": "2030-01-26",
    "description": "The PrismPlus Cryptographic Module is a hardware Module intended for use by US Federal agencies or other markets that require a FIPS 140-3 validated network encryption device. The Module implemented on a PCIe Adapter is intended to be used in Fibre Channel based Storage Area Networks. The Module allows a Connection to be established between one of the multiple Host Initiator Entities (eg 256 Virtual Machine Drivers running on multiple CPU cores) on a Storage Server Appliance and one of the multiple Remote Host Target Entities (eg 1000s of Storage LUNs) on multiple Storage Device Appliances via one of the multiple Physical Ports (eg 4x 64GFC ports). The Connection facilitates transfer of data between a Host Initiator Entity on a Storage Server Appliance and Host Target Entity on a Storage Server Appliance using the FC (Fibre Channel) Protocol. The Module allows multiple (1000s) of connections between Host Initiator Entities on a Storage Server Appliance and Host Target Entities on Storage Device Appliances. The module can be used to support Data-in-Flight Encryption/Decryption between Storage Appliances in a FC-SAN environment. Encryption decisions are made on a connection basis, whereby only a subset of the connections could be enabled for Encryption. If a connection is enabled for Encryption, only a subset of the Frame Types (eg Data Frames only, not Command/Status/Control/etc. Frames) could be enabled for Encryption.",
    "embodiment": "Multi-Chip Embedded",
    "exceptions": [
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": "14.2.338.0",
    "historical_reason": null,
    "hw_versions": "G99-00139-01",
    "level": 1,
    "mentioned_certs": {},
    "module_name": "PrismPlus Cryptographic Module",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-01-27",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Broadcom, Inc.",
    "vendor_url": "http://www.broadcom.com/"
  }
}