Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #4837

Details

Module Name
i.MX8 DXL SECO HSM
Standard
FIPS 140-3
Status
Active
Sunset Date
10/14/2029
Overall Level
3
Caveat
When utilizing a Trusted Channel as specified in the Security Policy.
Security Level Exceptions
  • Operational environment: N/A
  • Documentation requirements: N/A
  • Cryptographic module security policy: N/A
Module Type
Hardware
Embodiment
Single Chip
Description
The i.MX8 DXL SECO HSM hardware is a sub-chip subsystem of a single-chip embodiment that provides cryptographic engine and secure storage functions, intended for use in automotive or IoT applications.
Tested Configuration(s)
  • [SOC_iMX8DualXL_28FDSOI_1.75 (P/Ns MIMX8SL3AVNFZAB, PIMX8SL3AVNFZAB, MIMX8DL3AVNFZAB, PIMX8DL3AVNFZAB)]
Approved Algorithms
AES-CBC
AES-CCM
AES-CMAC
AES-ECB
AES-GCM
AES-GCM
ECDSA KeyGen (FIPS186-4)
ECDSA SigGen (FIPS186-4)
ECDSA SigVer (FIPS186-4)
Hash DRBG
HMAC-SHA2-224
HMAC-SHA2-256
HMAC-SHA2-384
HMAC-SHA2-512
KAS-ECC-SSC Sp800-56Ar3
KDA OneStep Sp800-56Cr1
KDF SP800-108
KDF TLS
RSA SigVer (FIPS186-4)
SHA2-224
SHA2-256
SHA2-256
SHA2-384
SHA2-512
TLS v1.2 KDF RFC7627
Allowed Algorithms
ECDSA with non-NIST recommended curves (Provides 128 or 192 bits of encryption strength); Per IG C.A; Use of Brainpool curves, allowed for use per [FIPS 140-3 IG] C.A: - BrainpoolP256R1 (128-bit security strength) - BrainpoolP384R1 (192-bit security strength));EC Diffie-Hellman with non-NIST recommended curves (Provides 128 or 192 bits of encryption strength); Per IGs D.F and C.A; Use of Brainpool curves in KAS, allowed for use per [FIPS 140-3 IG] C.A and [FIPS 140-3 IG] D.F Scenario 3: - BrainpoolP256R1 (available for both KEK and TLS use cases; 128-bit security strength) - BrainpoolP384R1 (available only for TLS use case; 192-bit security strength))
Entropy
ENT (P)
Hardware Versions
P/N: version tag DA_SSL_iMX8DXL_SCU_SUBSYS_LN28FDSOI_1.56
Firmware Versions
SECO ROM mem_I.MX8_s28roml_w24576x032m32B2_1Tlms_m0_1.7; SECO FW 5.9.0

Vendor

NXP Semiconductors, Inc.
Troplowitzstrasse 20
Hamburg D-22529
Germany

Tim 't Hart
tim.t.hart@nxp.com
Phone: 31639186402
David Herrgesell
david.herrgesell@nxp.com
Phone: 4331242998963

Related Files

Validation History

Date Type Lab
10/15/2024 Initial ACUMEN SECURITY, LLC