Broadcom is padding post-quantum security with its Emulex SecureHBA adapters now integrated into Everpure’s FlashArray storage systems, allowing enterprises to encrypt data traveling between application servers and storage over fiber channel networks.
The SecureHBA platform enables encryption across fiber channel networks using post-quantum cryptographic (PQC) algorithms, including module lattice-based key-encapsulation mechanism (ML-KEM) and module lattice-based digital signature algorithm (ML-DSA), combined with advanced encryption standard with 256-bit key in Galois/counter mode (AES-GCM-256) for transport-layer protection. The encryption is hardware-based and negotiated automatically during standard network login processes, eliminating the need for external key managers or manual configuration.
Broadcom said more than 120,000 SecureHBA units have already shipped on server platforms, and the addition of Everpure storage arrays completes the end-to-end architecture.
“Extending an enterprise’s Encrypt Everything policy from today’s data-at-rest encryption to include PQC-safe in-flight network encryption is the next obvious step for securing mission critical data,” said Jeff Hoogenboom, VP of the Emulex Connectivity Division at Broadcom.
A key focus of the announcement is performance. Traditional encryption methods, such as IPsec over Ethernet, can introduce latency and consume central processing unit (CPU) resources. By offloading encryption to dedicated hardware within the adapter, Broadcom said its approach avoids performance penalties and preserves storage services like compression and deduplication.
Third-party testing cited by the company found no measurable performance impact or CPU overhead when encryption was enabled, while also highlighting operational simplicity due to its “touchless” deployment model.
The move comes as enterprises begin to take more seriously the threat of “harvest now, decrypt later” attacks, where adversaries collect encrypted data today with the expectation that future quantum computers will be able to break it in the future.
Emulex SAN Manager update
Broadcom also introduced an update to its Emulex SAN Manager software platform (3.0) designed to help administrators manage encrypted connections and meet compliance requirements tied to emerging regulations such as the National Security Agency (NSA) Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) and European frameworks like Network and Information Security 2 (NIS2) and Digital Operational Resilience Act (DORA).
As AI workloads move into production, organizations are generating and transferring more data across systems, increasing the attack surface for interception. Looming advances in quantum computing are forcing enterprises to rethink long-term encryption strategies – even if large-scale quantum decryption capabilities are still years away.
Broadcom is positioning its solution at the intersection of those trends, aiming to provide a standards-based approach to quantum-safe networking that can scale across thousands of connections without adding operational complexity.
Support for environments such as VMware vSAN and Microsoft Azure Local are also expected.
Comments