Cr50 U2F Cryptographic Library

Certificate #4652

Webpage information

Status active
Validation dates 06.11.2023
Sunset date 21-09-2026
Standard FIPS 140-2
Security level 1
Type Firmware-Hybrid
Embodiment Single Chip
Caveat When operated in FIPS mode. No assurance of the minimum strength of generated keys.
Exceptions
  • Physical Security: Level 3
  • Mitigation of Other Attacks: N/A
Description The Cr50 U2F Cryptographic Library is a firmware-hybrid module residing in the Google, LLC Google Security Chips (GSC) chip. The module is responsible for low-level cryptographic primitives on Google Security Chips (GSC) used in recent versions of Google Chromebooks, and includes functionality for key generation, signature generation, random bit generation, keyed-hashing and signature verification operations in support of U2F-related requests in the Cr50 Chrome OS.
Version (Hardware) H1B2P
Version (Firmware) 1.0.1
Tested configurations
  • Google H1B2 with ARM V7-M with PAA
Vendor Google, LLC
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, HMAC, HMAC-SHA-256
Asymmetric Algorithms
ECDSA, ECC, DH, Diffie-Hellman
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512
Schemes
MAC, Key Agreement
Randomness
TRNG, DRBG
Elliptic Curves
P-256
Block cipher modes
ECB, CBC, CFB, GCM

Security level
Level 1, Level 5, Level 3

Standards
FIPS 140-2, FIPS 140, FIPS 186-4, FIPS 198-1, FIPS 180-4, NIST SP 800-90B, SP 800-90A, SP 800-90B, SP 800-90

File metadata

Author klasoski
Creation date D:20230919113147-04'00'
Modification date D:20230919113613-04'00'
Pages 15
Creator Acrobat PDFMaker 23 for Word
Producer Adobe PDF Library 23.6.96

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4652,
  "dgst": "13b9f23e5ea0d47a",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC#A2353",
        "DRBG#A2353",
        "ECDSA#A2353",
        "SHS#A2353",
        "SHS#A2352",
        "HMAC#A2352"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "1.0.1"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDSA": {
            "ECDSA": 14
          }
        },
        "FF": {
          "DH": {
            "DH": 3,
            "Diffie-Hellman": 1
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "CFB": {
          "CFB": 1
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 16
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "HMAC SHA-256": 2,
          "HMAC-SHA-256": 8,
          "SHA-1": 1,
          "SHA-256": 8,
          "SHA-384": 1,
          "SHA-512": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2,
          "Level 3": 1,
          "Level 5": 2
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 1
          },
          "SHA2": {
            "SHA-256": 8,
            "SHA-384": 1,
            "SHA-512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 7
        },
        "TRNG": {
          "TRNG": 3
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140": 1,
          "FIPS 140-2": 12,
          "FIPS 180-4": 2,
          "FIPS 186-4": 1,
          "FIPS 198-1": 2
        },
        "NIST": {
          "NIST SP 800-90B": 1,
          "SP 800-90": 1,
          "SP 800-90A": 2,
          "SP 800-90B": 3
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 4
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8,
            "HMAC-SHA-256": 4
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "klasoski",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20230919113147-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 23 for Word",
      "/Keywords": "",
      "/ModDate": "D:20230919113613-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 23.6.96",
      "/SourceModified": "D:20230919152849",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 519240,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14854",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14853",
          "http://csrc.nist.gov/groups/STM/cmvp/index.html",
          "https://www.w3.org/TR/webauthn-1/#sctn-authenticator-model"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 15
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "9d1cf38d12a1e39d3be61ee6faa259c112e154b86e03fd34fd6b3d5689fd39fa",
    "policy_txt_hash": "8d949dbfc33e110ad216b76e71dd45281ff7b18aa45dc3fd6545a36f679bd859"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode. No assurance of the minimum strength of generated keys.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2023_111223_0648_signed.pdf",
    "date_sunset": "2026-09-21",
    "description": "The Cr50 U2F Cryptographic Library is a firmware-hybrid module residing in the Google, LLC Google Security Chips (GSC) chip. The module is responsible for low-level cryptographic primitives on Google Security Chips (GSC) used in recent versions of Google Chromebooks, and includes functionality for key generation, signature generation, random bit generation, keyed-hashing and signature verification operations in support of U2F-related requests in the Cr50 Chrome OS.",
    "embodiment": "Single Chip",
    "exceptions": [
      "Physical Security: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "1.0.1",
    "historical_reason": null,
    "hw_versions": "H1B2P",
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Cr50 U2F Cryptographic Library",
    "module_type": "Firmware-Hybrid",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": null,
    "tested_conf": [
      "Google H1B2 with ARM V7-M with PAA"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2023-11-06",
        "lab": "Acumen Security",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Google, LLC",
    "vendor_url": "http://www.google.com"
  }
}