Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #5455

Details

Module Name
Non-Volatile Memory express (NVMe) Data Path Security Cluster (DPSC) Module
Standard
FIPS 140-3
Status
Active
Sunset Date
7/29/2031
Overall Level
1
Caveat
No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Security Level Exceptions
  • Software/Firmware security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Module Type
Hardware
Embodiment
SingleChip
Description
The Data Path Security Cluster is a hardware IP providing XTS-AES encryption to NVMe data in transit over the network. The cryptographic module accepts from its outside and stores cryptographic keys for multiple NVMe connections. Depending on the content of received data, the module shall or shall not apply cryptographic processing to the data. The DPSC contains 4 identical XTS-AES-256 decrypt engines, 4 identical XTS-AES-256 encrypt engines, key cache arbiter and key cache SRAM which is zeroized on reset. The data interfaces exposed to the NVMe Protocol Layer (NPL) within the NVMe Protocol Initiator (NPI) are read and write DMA interfaces. XTS keys are written to the module’s SRAM via Control/Status Register (CSR) writes from the Integrated Management Complex (IMC) located outside of the module boundary. On-demand self- tests may be initiated from the NPI using an on-demand self-test trigger over a wire interface.

Vendor

Google, LLC
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA

FIPS Crypto Officer
[email protected]
Phone: 650-253-0000

Validation History

Date Type Lab
7/30/2026 Initial Acumen Security