Navigation

Get in touch
Logo
News

Marvell LiquidSecurity: cards for HSM platforms

Marvell builds hardware security modules as PCIe cards and leaves the operations to the cloud providers, HSM service providers and appliance makers that install these cards. We check with you whether LiquidSecurity fits your platform, connect the cards to your applications and support the operations.

Try product
  • FIPS 140-3 Level 3, CMVP 4703
  • PCI PTS HSM
  • PCIe Gen4 x8
  • Azure Cloud HSM
Marvell LiquidSecurity 2 as a PCIe card
Product photo: Marvell

Marvell at a glance

A LiquidSecurity card sits in the server and generates, stores and uses cryptographic keys inside a validated hardware boundary. Applications call signing and decryption through PKCS#11, JCA/JCE, CNG/KSP or OpenSSL, and the key stays on the card. Marvell runs no cloud service of its own and sells the cards to providers that build services and appliances from them.

Cryptography and hardware security modules are our core competence. We know how the LiquidSecurity cards are partitioned, how PKCS#11 connects to them and how to read the reports of the CMVP, the program that runs the FIPS validations. We run your project from the first selection to daily operations.

PCIe Gen4 x8, low profile
FIPS 140-3 Level 3, CMVP 4703
21 on LS2-A050, 32 on LS2-A100, 42 with the upgrade
HSM as a service, key vaults, payments, TLS offload

The series in detail

LiquidSecurity 2

LiquidSecurity 2 is the current generation of the cards and came to market in September 2022. Depending on the version it separates 21, 32 or 42 partitions and holds up to one million keys according to the product page.

View device illustration

Models

LiquidSecurity 2: Models
LS2-A05021 partitions, 21,250 RSA-2048 operations per second
LS2-A10032 partitions, 35,000 RSA-2048 operations per second
Performance upgrade42 partitions, 42,500 RSA-2048 operations per second
LS-SW-PQCLicense for post-quantum algorithms on the card
LS-SW-PLHLicense for applications of other vendors on the card
Form factors
PCIe card Gen4 x8, Low profile
Operation
Servers of cloud providers, Platform of an HSM service provider, Appliance of a device maker

Certifications

  • FIPS 140-3 Level 3, CMVP 4703, validated on June 6, 2024
  • Validation entry valid until June 5, 2029
  • PCI PTS HSM 4.0 per the product page, v3 on the same hardware and firmware
  • Common Criteria as a vendor statement without a certificate number
  • eIDAS as a vendor statement without a certificate number

Features

  • PKCS#11, JCA/JCE, CNG/KSP and OpenSSL interfaces
  • Role based rights, attested audit logs and remote administration
  • With the upgrade 100,000 EC P-256 and 1,000,000 AES-GCM operations per second
  • SR-IOV with one physical and 64 virtual functions
  • Licenses for post-quantum algorithms and third party applications

Vendor information

LiquidSecurity 1

LiquidSecurity 1 rests on the NITROX III crypto processor, still appears on the product page and carries a validation of its own. It separates 16, 24 or 32 partitions, one version 64, and stores 25,000 to 100,000 keys.

Marvell LiquidSecurity 1 as a PCIe card
Product photo: Marvell

Models

LiquidSecurity 1: Models
CNN35XX-NFBECard family behind the validation entry CMVP 4700
Version with 16 partitionsSmallest separation of the line
Version with 24 partitionsMedium separation of the line
Version with 32 partitionsRegular case of the line
Version with 64 partitionsSingle variant of the line
Form factors
PCIe card
Operation
Servers of cloud providers, Platform of an HSM service provider
Lifecycle
Previous generation, still listed on the product page, the successor is LiquidSecurity 2

Certifications

  • FIPS 140-3 Level 3, CMVP 4700, validated on May 30, 2024
  • Validation entry valid until May 29, 2029
  • FIPS 140-2 Level 3

Features

  • Key store from 25,000 to 100,000 keys
  • Partitions in the steps 16, 24 and 32
  • One version with 64 partitions
  • Validation entry under the name NITROXIII CNN35XX-NFBE HSM Family

Vendor information

LiquidSecurity at Microsoft Azure

Marvell sells the cards to cloud providers that build a service from them, and so far this path is documented for Microsoft Azure. Azure Key Vault and Azure Managed HSM have used LiquidSecurity 2 since August 2024, and Azure Cloud HSM since August 2025.

View device illustration

Models

LiquidSecurity at Microsoft Azure: Models
Azure Key VaultFitted with LiquidSecurity 2 since August 2024
Azure Managed HSMFitted with LiquidSecurity 2 since August 2024
Azure Cloud HSMFitted with LiquidSecurity 2 since August 2025
Form factors
Service of the cloud provider
Operation
Microsoft Azure, Platform of an HSM service provider

Certifications

  • FIPS 140-3 Level 3 of the LiquidSecurity 2 in use, CMVP 4703

Features

  • Marvell supplies the cards and runs no cloud service of its own
  • Azure Key Vault and Azure Managed HSM use the cards since August 2024
  • Azure Cloud HSM uses the cards since August 2025
  • For AWS and Google Cloud no confirmation from Marvell is available to us
  • Providers of HSM as a service build the cards into their own platforms

Vendor information

How you find the right card

Four questions decide the choice: the number of partitions, the required proof of validation, the interfaces of your applications and the operating model. We clear them in a workshop and record the result with a source for every figure.

Partitions and tenants

The LS2-A050 separates 21 partitions, the LS2-A100 separates 32 and the upgrade raises the count to 42. The product page states up to 45 partitions and the validation report up to 64 logical partitions, so we record each figure with its source.

Proof of validation

FIPS 140-3 Level 3 is documented for both generations with the numbers 4703 and 4700 and runs until 2029. Marvell names Common Criteria and eIDAS on the product page without a certificate number, so we carry both as a vendor statement.

Interfaces

Your applications speak PKCS#11, JCA/JCE, CNG/KSP or OpenSSL, and the card serves all four paths. We check up front whether your PKI, database or signing service works with the planned firmware and the planned partition.

Operating model

You buy the card inside an appliance, book a service from an HSM provider or use Azure Key Vault, Managed HSM and Cloud HSM. The entire solution runs in German data centers.

What we deliver around Marvell

We deliver the work around the card: choosing the version, cutting the partitions, connecting the applications, the key ceremony and monitoring. One team accompanies you from consulting to operations.

  • HSM consulting and integration

    We pick the version by your load, cut the partitions to your tenants, connect PKCS#11 and CNG/KSP to your applications and document the key ceremony in an audit proof form.

    HSM & Key Management

  • PQC readiness

    We record which keys and protocols rest on RSA and ECC, because quantum computers threaten both algorithms. We then plan the use of the LS-SW-PQC license that brings post-quantum algorithms onto the card.

    Post-Quantum Cryptography

  • Cloud

    We set up Azure Key Vault, Managed HSM and Cloud HSM, separate the keys by application and connect the service to your systems in your own data center.

    Cloud

Standards and evidence

Four rules decide the selection and the documentation on Marvell projects. We tell you which statement carries a validation number and which one only appears on the product page.

Requirement / Demands / OTOKO® delivers
RequirementDemandsOTOKO® delivers
FIPS 140-3Validated crypto modules with a defined physical protection levelLiquidSecurity 2 at Level 3 with CMVP 4703, LiquidSecurity 1 with CMVP 4700
PCI PTS HSMCertified hardware for PINs and card keysLiquidSecurity 2 at 4.0 per the product page, at v3 per the Marvell blog on the same hardware
Common CriteriaCertified security module with a published certificateNamed by Marvell on the product page, without a number, therefore a vendor statement
eIDASQualified signature creation device at the trust service providerNamed by Marvell, without a certificate number, we clear the fit per project

Frequently asked questions about Marvell

Related topics

You would like to learn more about

Marvell

Marvell builds hardware security modules as PCIe cards and leaves the operations to the cloud providers, HSM service providers and appliance makers that install these cards. We check with you whether LiquidSecurity fits your platform, connect the cards to your applications and support the operations.

Our clients

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.