I hope this message finds you well. I am evaluating the LX2160A Reference Design Board (RDB) for a secure networking application and would appreciate clarification on some aspects related to its cryptographic capabilities.
Specifically, I would like to know:
Cryptographic Boundary: Does the cryptographic engine within the LX2160A SoC have a defined cryptographic boundary in line with security certification frameworks (e.g., FIPS 140-2)?
Code and Memory Isolation:
Is the cryptographic code logically isolated from other software components?
Is there any form of physical separation between the crypto code and the rest of the system?
Does the SoC reserve dedicated memory for cryptographic operations?
Sandbagging Support: Does the platform support any kind of sandbagging—i.e., deliberate buffering, obfuscation, or timing equalization to mitigate side-channel attacks?
FIPS 140-2 Level 3: Is it possible to achieve FIPS 140-2 Level 3 compliance using the LX2160A platform, either directly or through integration with external secure elements?
Documentation: Are there any white papers, application notes, or security architecture documents available that detail the cryptographic and isolation mechanisms implemented in the LX2160A or the RDB?
Hey. While the answer satisfied my query, i need a clarification. Are the cryptographic algorithms implemented within the chip or is it just a blank accelerator where i have to implement the algorithms myself by writing a crypto code. I'll clarify by mentioning that i wish to implement DES, 3DES, AES-128, AES-256, RSA(748, 1024, 2048 bit), ECDSA (256/384 bit). MD5, SHA, SHA-256, SHA-384, SHA-512. Are these already available in the chip or a code has to be written for its implementation in software?
We have FSLNISTCAVP.pdf, but as far as I know, we don't have an update.
We have been telling customers to check the individual crypto suites that they need. Because the LX2160 uses the same engine as the LS processors.
If you have a particular algorithm that you are interested in, I can check with our internal team about it.
But as this is related to the SEC, please create a case
https://support.nxp.com/s/?language=en_US
And confirm you have a NDA in place.
Thanks