Samsung BoringCrypto Android 15

Known vulnerabilities detected

Our automated heuristics have identified vulnerabilities that may be associated with this certificate. See the CVEs section for details.

Certificate details

Certificate ID #5530
Status active
Validation dates 23.09.2026
Sunset date 17-04-2031
Standard FIPS 140-3
Security level 1
Type Software
Embodiment MultiChipStand
Caveat When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys). No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.
Vendor Samsung Electronics Co., Ltd. http://www.samsung.com
Lab Gossamer Security Solutions
Algorithms
  • AES-CBCA6134
  • AES-CCMA6134
  • AES-CTRA6134
  • AES-ECBA6134
  • AES-GCMA6134
  • AES-GMACA6134
  • AES-KWA6134
  • AES-KWPA6134
  • Counter DRBGA6134
  • ECDSA KeyGen (FIPS186-5)A6134
  • ECDSA KeyVer (FIPS186-5)A6134
  • ECDSA SigGen (FIPS186-5)A6134
  • ECDSA SigVer (FIPS186-5)A6134
  • HMAC-SHA-1A6134
  • HMAC-SHA2-224A6134
  • HMAC-SHA2-256A6134
  • HMAC-SHA2-384A6134
  • HMAC-SHA2-512/256A6134
  • HMAC-SHA2-512A6134
  • KAS-ECC-SSC Sp800-56Ar3A6134
  • KAS-FFC-SSC Sp800-56Ar3A6134
  • KDA HKDF Sp800-56Cr1A6134
  • RSA KeyGen (FIPS186-5)A6134
  • RSA SigGen (FIPS186-5)A6134
  • RSA SigVer (FIPS186-5)A6134
  • SHA-1A6134
  • SHA2-224A6134
  • SHA2-256A6134
  • SHA2-384A6134
  • SHA2-512/256A6134
  • SHA2-512A6134
  • TLS v1.2 KDF RFC7627A6134
  • TLS v1.3 KDFA6134
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-256, AES, AES-, CAST, DES, Triple-DES, HMAC, HMAC-SHA-256
Asymmetric Algorithms
ECDSA, DHE, DH
Hash functions
SHA-1, SHA-256, MD4, MD5
Schemes
MAC, Key Agreement
Protocols
TLS v1.2, TLS v1.3, TLS, TLS 1.2, TLS 1.3
Randomness
DRBG, RBG
Libraries
BoringSSL
Elliptic Curves
P-224, P-256, P-384, P-521
Block cipher modes
CBC, GCM, SIV

Trusted Execution Environments
PSP, SSC
Vendor
Samsung

Security level
Level 1, level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

CPE matches

CVE matches

ID Links Severity CVSS Score Published on
Base score
CVE-2025-20903
C N
HIGH 7.3 06.03.2025
CVE-2025-20908
C N
MEDIUM 6.5 06.03.2025
CVE-2025-20936
C N
HIGH 7.8 08.04.2025
CVE-2025-20937
C N
MEDIUM 6.7 07.05.2025
CVE-2025-20941
C N
LOW 3.3 08.04.2025
CVE-2025-20942
C N
MEDIUM 4.4 08.04.2025
CVE-2025-20943
C N
MEDIUM 4.4 08.04.2025
CVE-2025-20944
C N
HIGH 7.1 08.04.2025
CVE-2025-20947
C N
MEDIUM 5.5 08.04.2025
CVE-2025-20948
C N
HIGH 7.1 08.04.2025
CVE-2025-20952
C N
MEDIUM 5.5 09.04.2025
CVE-2025-20953
C N
MEDIUM 4.4 07.05.2025
CVE-2025-20954
C N
MEDIUM 5.5 07.05.2025
CVE-2025-20955
C N
MEDIUM 5.5 07.05.2025
CVE-2025-20957
C N
HIGH 7.8 07.05.2025
CVE-2025-20958
C N
MEDIUM 4.4 07.05.2025
CVE-2025-20959
C N
MEDIUM 5.5 07.05.2025
CVE-2025-20960
C N
LOW 3.3 07.05.2025
CVE-2025-20961
C N
MEDIUM 5.5 07.05.2025
CVE-2025-20962
C N
MEDIUM 4.0 07.05.2025
CVE-2025-20963
C N
HIGH 7.8 07.05.2025
CVE-2025-20964
C N
HIGH 7.8 07.05.2025
CVE-2025-20981
C N
MEDIUM 6.2 04.06.2025
CVE-2025-20982
C N
MEDIUM 6.7 08.07.2025
CVE-2025-20983
C N
MEDIUM 6.7 08.07.2025
CVE-2025-20985
C N
LOW 3.3 04.06.2025
CVE-2025-20987
C N
MEDIUM 6.7 04.06.2025
CVE-2025-20988
C N
HIGH 7.1 04.06.2025
CVE-2025-20989
C N
MEDIUM 5.2 04.06.2025
CVE-2025-20990
C N
LOW 3.3 06.08.2025
CVE-2025-20991
C N
MEDIUM 5.1 04.06.2025
CVE-2025-20992
C N
HIGH 7.7 04.06.2025
CVE-2025-20993
C N
MEDIUM 6.8 04.06.2025
CVE-2025-20999
C N
LOW 2.1 08.07.2025
CVE-2025-21000
C N
LOW 3.3 08.07.2025
CVE-2025-21001
C N
MEDIUM 5.5 08.07.2025
CVE-2025-21002
C N
MEDIUM 5.5 08.07.2025
CVE-2025-21003
C N
MEDIUM 5.5 08.07.2025
CVE-2025-21010
C N
MEDIUM 6.0 06.08.2025
CVE-2025-21014
C N
MEDIUM 5.5 06.08.2025
CVE-2025-21015
C N
HIGH 7.1 06.08.2025
CVE-2025-21025
C N
MEDIUM 4.4 03.09.2025
CVE-2025-21026
C N
LOW 3.3 03.09.2025
CVE-2025-21027
C N
MEDIUM 4.4 03.09.2025
CVE-2025-21028
C N
MEDIUM 5.5 03.09.2025
CVE-2025-21029
C N
LOW 3.3 03.09.2025
CVE-2025-21031
C N
MEDIUM 6.8 03.09.2025
CVE-2025-21032
C N
MEDIUM 6.8 03.09.2025
CVE-2025-21033
C N
MEDIUM 5.5 03.09.2025
CVE-2025-21034
C N
HIGH 7.8 03.09.2025
CVE-2025-21041
C N
MEDIUM 5.5 03.09.2025
CVE-2025-21042
C N
CRITICAL 9.8 12.09.2025
CVE-2025-21043
C N
CRITICAL 9.8 12.09.2025
CVE-2025-21044
C N
MEDIUM 4.4 10.10.2025
CVE-2025-21046
C N
LOW 2.4 10.10.2025
CVE-2025-21047
C N
MEDIUM 6.8 10.10.2025
CVE-2025-21048
C N
HIGH 7.8 10.10.2025
CVE-2025-21049
C N
MEDIUM 5.5 10.10.2025
CVE-2025-21050
C N
MEDIUM 5.5 10.10.2025
CVE-2025-21051
C N
HIGH 7.8 10.10.2025
CVE-2025-21052
C N
HIGH 7.8 10.10.2025
CVE-2025-21053
C N
HIGH 7.8 10.10.2025
CVE-2025-21054
C N
MEDIUM 5.5 10.10.2025
CVE-2025-21055
C N
HIGH 7.5 10.10.2025
CVE-2025-21071
C N
MEDIUM 4.4 05.11.2025
CVE-2025-21072
C N
MEDIUM 4.4 02.12.2025
CVE-2025-21073
C N
MEDIUM 4.1 05.11.2025
CVE-2025-21074
C N
HIGH 7.5 05.11.2025
CVE-2025-21075
C N
HIGH 7.5 05.11.2025
CVE-2025-21080
C N
HIGH 7.1 02.12.2025
CVE-2025-58475
C N
MEDIUM 4.4 02.12.2025
CVE-2025-58476
C N
MEDIUM 4.6 02.12.2025
CVE-2025-58477
C N
MEDIUM 6.5 02.12.2025
CVE-2025-58478
C N
HIGH 7.5 02.12.2025
CVE-2025-58479
C N
HIGH 7.5 02.12.2025
CVE-2025-58480
C N
HIGH 7.5 02.12.2025
CVE-2026-20968
C N
MEDIUM 6.7 09.01.2026
CVE-2026-20969
C N
MEDIUM 5.5 09.01.2026
CVE-2026-20970
C N
HIGH 7.8 09.01.2026
CVE-2026-20971
C N
HIGH 7.8 09.01.2026
CVE-2026-20972
C N
LOW 3.3 09.01.2026
CVE-2026-20973
C N
CRITICAL 9.1 09.01.2026
CVE-2026-20974
C N
MEDIUM 4.6 09.01.2026
CVE-2026-20977
C N
MEDIUM 5.5 04.02.2026
CVE-2026-20978
C N
MEDIUM 6.1 04.02.2026
CVE-2026-20979
C N
HIGH 7.8 04.02.2026
CVE-2026-20980
C N
MEDIUM 6.8 04.02.2026
CVE-2026-20981
C N
MEDIUM 6.6 04.02.2026
CVE-2026-20982
C N
MEDIUM 6.0 04.02.2026
CVE-2026-20983
C N
HIGH 7.8 04.02.2026
CVE-2026-20990
C N
HIGH 8.1 16.03.2026
CVE-2026-20991
C N
MEDIUM 4.4 16.03.2026
CVE-2026-20992
C N
LOW 3.3 16.03.2026
CVE-2026-21003
C N
MEDIUM 6.8 13.04.2026
CVE-2026-21006
C N
LOW 2.4 13.04.2026
CVE-2026-21007
C N
MEDIUM 6.8 13.04.2026
CVE-2026-21008
C N
MEDIUM 6.5 13.04.2026
CVE-2026-21009
C N
MEDIUM 6.8 13.04.2026
CVE-2026-21010
C N
HIGH 7.8 13.04.2026
CVE-2026-21011
C N
MEDIUM 6.8 13.04.2026
CVE-2026-21012
C N
LOW 3.3 13.04.2026
CVE-2026-21015
C N
MEDIUM 5.5 13.05.2026
CVE-2026-21016
C N
MEDIUM 5.5 13.05.2026
CVE-2026-21017
C N
MEDIUM 5.5 05.06.2026
CVE-2026-21018
C N
MEDIUM 6.7 13.05.2026
CVE-2026-21020
C N
HIGH 7.8 13.05.2026
CVE-2026-21022
C N
MEDIUM 5.5 13.05.2026
CVE-2026-21023
C N
MEDIUM 5.5 29.04.2026
CVE-2026-21025
C N
MEDIUM 5.5 05.06.2026
CVE-2026-21027
C N
LOW 3.3 05.06.2026
CVE-2026-21029
C N
HIGH 7.8 05.06.2026
CVE-2026-21030
C N
HIGH 7.8 05.06.2026
CVE-2026-21031
C N
HIGH 7.8 05.06.2026
CVE-2026-21058
C N
HIGH 7.1 10.08.2026
CVE-2026-21060
C N
MEDIUM 4.6 10.08.2026
CVE-2026-21061
C N
MEDIUM 6.5 10.08.2026
CVE-2026-21062
C N
LOW 3.3 10.08.2026
CVE-2026-21063
C N
MEDIUM 6.1 10.08.2026
CVE-2026-21064
C N
MEDIUM 5.5 10.08.2026
CVE-2026-21065
C N
HIGH 7.8 10.08.2026
CVE-2026-21066
C N
HIGH 7.8 10.08.2026
CVE-2026-21067
C N
HIGH 7.8 10.08.2026
CVE-2026-21068
C N
HIGH 7.8 10.08.2026
CVE-2026-21069
C N
HIGH 7.8 10.08.2026
CVE-2026-21070
C N
MEDIUM 4.6 10.08.2026
CVE-2026-21071
C N
HIGH 7.8 10.08.2026
CVE-2026-21072
C N
HIGH 7.8 10.08.2026
CVE-2026-21073
C N
MEDIUM 6.1 10.08.2026
CVE-2026-21085
C N
MEDIUM 6.7 09.09.2026
CVE-2026-21087
C N
HIGH 7.8 09.09.2026
CVE-2026-21088
C N
HIGH 7.8 09.09.2026
CVE-2026-21089
C N
HIGH 7.8 09.09.2026
CVE-2026-21090
C N
HIGH 7.8 09.09.2026
CVE-2026-21091
C N
HIGH 7.8 09.09.2026
CVE-2026-21092
C N
MEDIUM 5.3 09.09.2026
CVE-2026-21093
C N
MEDIUM 6.7 09.09.2026
CVE-2026-21094
C N
HIGH 8.8 09.09.2026
CVE-2026-21095
C N
CRITICAL 9.8 09.09.2026
CVE-2026-21096
C N
CRITICAL 9.8 09.09.2026
CVE-2026-21097
C N
MEDIUM 6.7 09.09.2026
CVE-2026-21099
C N
MEDIUM 5.5 09.09.2026
CVE-2026-21100
C N
HIGH 7.1 09.09.2026
CVE-2026-21101
C N
MEDIUM 6.7 09.09.2026
CVE-2026-21102
C N
MEDIUM 6.7 09.09.2026
CVE-2026-21103
C N
MEDIUM 6.1 09.09.2026
CVE-2026-21104
C N
MEDIUM 6.7 09.09.2026
CVE-2026-21112
C N
MEDIUM 5.5 09.09.2026
Showing 5 out of 147.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5530,
  "dgst": "2d92cc08f22524db",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256A6134",
        "ECDSA SigVer (FIPS186-5)A6134",
        "SHA-1A6134",
        "ECDSA SigGen (FIPS186-5)A6134",
        "AES-GCMA6134",
        "HMAC-SHA-1A6134",
        "HMAC-SHA2-512/256A6134",
        "AES-CTRA6134",
        "SHA2-512A6134",
        "KAS-ECC-SSC Sp800-56Ar3A6134",
        "RSA SigVer (FIPS186-5)A6134",
        "RSA SigGen (FIPS186-5)A6134",
        "KAS-FFC-SSC Sp800-56Ar3A6134",
        "Counter DRBGA6134",
        "TLS v1.3 KDFA6134",
        "ECDSA KeyGen (FIPS186-5)A6134",
        "AES-CCMA6134",
        "AES-CBCA6134",
        "AES-KWPA6134",
        "HMAC-SHA2-512A6134",
        "ECDSA KeyVer (FIPS186-5)A6134",
        "SHA2-512/256A6134",
        "AES-KWA6134",
        "#A6134",
        "HMAC-SHA2-256A6134",
        "HMAC-SHA2-384A6134",
        "TLS v1.2 KDF RFC7627A6134",
        "AES-GMACA6134",
        "KDA HKDF Sp800-56Cr1A6134",
        "SHA2-384A6134",
        "HMAC-SHA2-224A6134",
        "RSA KeyGen (FIPS186-5)A6134",
        "AES-ECBA6134",
        "SHA2-224A6134"
      ]
    },
    "cpe_matches": {
      "_type": "Set",
      "elements": [
        "cpe:2.3:o:samsung:android:15.0:smr-mar-2026-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-jun-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-aug-2026-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:-:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-sep-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-jan-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-feb-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-dec-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-nov-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-jul-2026-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-apr-2026-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-jun-2026-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-apr-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-may-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-jan-2026-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-jul-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-oct-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-feb-2026-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-may-2026-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-mar-2025-r1:*:*:*:*:*:*",
        "cpe:2.3:o:samsung:android:15.0:smr-aug-2025-r1:*:*:*:*:*:*"
      ]
    },
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "15"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": {
      "_type": "Set",
      "elements": [
        "CVE-2025-20999",
        "CVE-2026-21070",
        "CVE-2026-21015",
        "CVE-2025-20948",
        "CVE-2025-20954",
        "CVE-2026-21067",
        "CVE-2026-20977",
        "CVE-2025-21026",
        "CVE-2025-58480",
        "CVE-2025-21049",
        "CVE-2026-21031",
        "CVE-2025-58478",
        "CVE-2025-21053",
        "CVE-2026-21112",
        "CVE-2026-21103",
        "CVE-2025-20944",
        "CVE-2025-21003",
        "CVE-2026-20983",
        "CVE-2025-20987",
        "CVE-2025-20943",
        "CVE-2025-20937",
        "CVE-2026-20971",
        "CVE-2026-21025",
        "CVE-2026-21064",
        "CVE-2025-21044",
        "CVE-2025-21027",
        "CVE-2026-21087",
        "CVE-2026-21023",
        "CVE-2025-20942",
        "CVE-2026-21091",
        "CVE-2026-21090",
        "CVE-2026-21068",
        "CVE-2026-20981",
        "CVE-2026-20968",
        "CVE-2025-20981",
        "CVE-2026-21093",
        "CVE-2025-21028",
        "CVE-2025-20959",
        "CVE-2025-21054",
        "CVE-2026-20972",
        "CVE-2025-21043",
        "CVE-2026-21027",
        "CVE-2026-21100",
        "CVE-2026-21066",
        "CVE-2025-21029",
        "CVE-2026-20973",
        "CVE-2026-20990",
        "CVE-2026-21009",
        "CVE-2025-20958",
        "CVE-2025-20960",
        "CVE-2025-21051",
        "CVE-2025-21042",
        "CVE-2026-21085",
        "CVE-2026-21007",
        "CVE-2025-20963",
        "CVE-2026-21094",
        "CVE-2026-21071",
        "CVE-2026-21016",
        "CVE-2026-21101",
        "CVE-2026-21060",
        "CVE-2025-21001",
        "CVE-2025-58477",
        "CVE-2025-20988",
        "CVE-2026-21010",
        "CVE-2025-20961",
        "CVE-2025-20955",
        "CVE-2026-20970",
        "CVE-2026-21022",
        "CVE-2026-21102",
        "CVE-2025-58475",
        "CVE-2025-20983",
        "CVE-2025-20908",
        "CVE-2026-20978",
        "CVE-2025-20985",
        "CVE-2025-21025",
        "CVE-2025-58479",
        "CVE-2025-21071",
        "CVE-2026-21011",
        "CVE-2025-58476",
        "CVE-2025-20991",
        "CVE-2025-20962",
        "CVE-2026-21099",
        "CVE-2025-21041",
        "CVE-2026-21008",
        "CVE-2025-21031",
        "CVE-2026-20974",
        "CVE-2025-20992",
        "CVE-2026-21065",
        "CVE-2026-20991",
        "CVE-2026-21061",
        "CVE-2025-21032",
        "CVE-2026-21003",
        "CVE-2025-21073",
        "CVE-2026-21063",
        "CVE-2026-21097",
        "CVE-2025-21046",
        "CVE-2026-21095",
        "CVE-2026-20992",
        "CVE-2025-20941",
        "CVE-2026-21058",
        "CVE-2026-21104",
        "CVE-2025-21034",
        "CVE-2025-20936",
        "CVE-2025-20982",
        "CVE-2025-20952",
        "CVE-2026-21088",
        "CVE-2025-20993",
        "CVE-2026-21020",
        "CVE-2025-21050",
        "CVE-2026-21092",
        "CVE-2025-20989",
        "CVE-2026-21069",
        "CVE-2025-21080",
        "CVE-2025-20953",
        "CVE-2025-21015",
        "CVE-2026-21096",
        "CVE-2026-21030",
        "CVE-2026-21017",
        "CVE-2026-20980",
        "CVE-2025-21048",
        "CVE-2026-21006",
        "CVE-2026-20979",
        "CVE-2026-20982",
        "CVE-2025-21052",
        "CVE-2026-21089",
        "CVE-2025-20964",
        "CVE-2026-21062",
        "CVE-2025-21072",
        "CVE-2025-21002",
        "CVE-2025-20947",
        "CVE-2025-21033",
        "CVE-2025-20957",
        "CVE-2026-21072",
        "CVE-2025-20990",
        "CVE-2025-21000",
        "CVE-2025-21010",
        "CVE-2026-21018",
        "CVE-2025-21075",
        "CVE-2026-21073",
        "CVE-2025-21055",
        "CVE-2026-20969",
        "CVE-2026-21012",
        "CVE-2026-21029",
        "CVE-2025-21014",
        "CVE-2025-20903",
        "CVE-2025-21074",
        "CVE-2025-21047"
      ]
    },
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A6134",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A6134",
            "properties": "Key Length - 128 Tag Length - 32, 64",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "IV Length - IV Length: 104 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0-524288 Increment 8",
            "reference": ""
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A6134",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - Yes Incremental Counter - Yes Counter Tests Performed - Yes",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A6134",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A6134",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96 Payload Length - Payload Length: 0-65536 Increment 8 AAD Length - AAD Length: 0-65536 Increment 8",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A6134",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96 AAD Length - AAD Length: 0-65536 Increment 8",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A6134",
            "properties": "Direction - Decrypt, Encrypt Cipher - Cipher Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 64",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A6134",
            "properties": "Direction - Decrypt, Encrypt Cipher - Cipher Key Length - 128, 192, 256 Payload Length - Payload Length: 8-4096 Increment 8",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A6134",
            "properties": "Prediction Resistance - No Supports Reseed - Yes Mode - AES-256 Derivation Function Enabled - No Additional Input - Additional Input: 0-384 Increment 16",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "Entropy Input - Entropy Input: 384 Nonce - Nonce: 0 Personalization String Length - Personalization String Length: 0-384 Increment 16 Returned Bits - 2048",
            "reference": ""
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-5)",
            "cavpCertName": "A6134",
            "properties": "Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidates",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-5)",
            "cavpCertName": "A6134",
            "properties": "Curve - P-224, P-256, P-384, P-521",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-5)",
            "cavpCertName": "A6134",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-5)",
            "cavpCertName": "A6134",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A6134",
            "properties": "MAC - MAC: 32-160 Increment 8 Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A6134",
            "properties": "MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A6134",
            "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A6134",
            "properties": "MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A6134",
            "properties": "MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/256",
            "cavpCertName": "A6134",
            "properties": "MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A6134",
            "properties": "Domain Parameter Generation Methods - P- 224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder staticUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A6134",
            "properties": "Domain Parameter Generation Methods - FB, FC Scheme - dhEphem - KAS Role - initiator",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF Sp800-56Cr1",
            "cavpCertName": "A6134",
            "properties": "Fixed Info Pattern - uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-65336 Increment 8 HMAC Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/256",
            "reference": ""
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-5)",
            "cavpCertName": "A6134",
            "properties": "Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Fixed Public Exponent - 010001 Info Generated By Server - Yes Private Key Format - standard Public Exponent Mode - fixed",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-5)",
            "cavpCertName": "A6134",
            "properties": "Hash Pair - Hash Algorithm - SHA2-224 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss Mask Function - mgf1",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-5)",
            "cavpCertName": "A6134",
            "properties": "Hash Pair - Hash Algorithm - SHA2-224 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss Mask Function - mgf1 Fixed Public Exponent - 010001 Public Exponent Mode - fixed",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A6134",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A6134",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A6134",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A6134",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A6134",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A6134",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A6134",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 Key Block Length - Key Block Length: 1024",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A6134",
            "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
            "reference": "SP 800-135 Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Module Initializatio n",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Module Initializati on",
            "outputs": "Return Code",
            "rolesSspAccess": "Crypto Officer (CO)",
            "secFunImpl": "None"
          },
          {
            "description": "Symmetric encryption of calling application data",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "Plaintext, AAD, IV, encryptio n key",
            "name": "Symmetr ic Encryptio n",
            "outputs": "Return code, ciphertext, tag",
            "rolesSspAccess": "Crypto Officer (CO) - AES Key: W,E - AES- GCM Key: W,E",
            "secFunImpl": "Authenticat ed Encryption Encryption"
          },
          {
            "description": "Symmetric decryption of calling application data",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "Cipherte xt, AAD, IV, tag, decryptio n key",
            "name": "Symmetr ic Decrypti on",
            "outputs": "Return code, plaintext",
            "rolesSspAccess": "Crypto Officer (CO) - AES Key: W,E - AES-",
            "secFunImpl": "Authenticat ed Decryption Decryption"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "GCM Key: W,E",
            "secFunImpl": ""
          },
          {
            "description": "Symmetric message authenticat ion of calling application data",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "Message , key",
            "name": "Keyed Hashing",
            "outputs": "Return code, Message Authenticat ion Code",
            "rolesSspAccess": "Crypto Officer (CO) - HMAC Key: W,E - AES- GCM Key: W,E",
            "secFunImpl": "Message Authenticat ion"
          },
          {
            "description": "Hashing of calling application data",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "Message",
            "name": "Hashing",
            "outputs": "Return code, hash",
            "rolesSspAccess": "Crypto Officer (CO)",
            "secFunImpl": "Hashing"
          },
          {
            "description": "Generation of random bits for calling application",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs",
            "name": "Random Bit Generati on",
            "outputs": "Return code, random bits",
            "rolesSspAccess": "Crypto Officer (CO) - CTR_DR BG Entropy Input: W,E - CTR_DR BG Seed: G,E - CTR_DR BG V: G,E - CTR_DR BG Key: G,E",
            "secFunImpl": "Random Bit Generation"
          },
          {
            "description": "Digital signature of calling application data",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "Message , signing key",
            "name": "Signatur e Generati on",
            "outputs": "Return code, signature",
            "rolesSspAccess": "Crypto Officer (CO) - ECDSA Signing Key: W,E - RSA Signature Generatio n Key: W,E - CTR_DR",
            "secFunImpl": "Signature Generation"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "BG V: E - CTR_DR BG Key: E",
            "secFunImpl": ""
          },
          {
            "description": "Digital signature verification of calling application data",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "Signatur e, verificatio n key",
            "name": "Signatur e Verificati on",
            "outputs": "Return code",
            "rolesSspAccess": "Crypto Officer (CO) - ECDSA Verificatio n Key: W,E - RSA Signature Verificatio n Key: W,E",
            "secFunImpl": "Signature Verification"
          },
          {
            "description": "Symmetric key wrapping of calling application key",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs, unwrapp ed key, wrapping key",
            "name": "Key Wrap Service",
            "outputs": "Return code, wrapped key",
            "rolesSspAccess": "Crypto Officer (CO) - AES Wrapping Key: W,E - Unwrapp ed Key: W - Wrapped Key: G,R",
            "secFunImpl": "AES- KeyWrap"
          },
          {
            "description": "Symmetric key unwrappin g of calling application key",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs, wrapped key",
            "name": "Key Unwrap Service",
            "outputs": "Return code, unwrapped key",
            "rolesSspAccess": "Crypto Officer (CO) - AES Wrapping Key: W,E - Wrapped Key: W - Unwrapp ed Key: G,R",
            "secFunImpl": "AES- KeyWrap"
          },
          {
            "description": "API call parameter s",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "Return code, shared secret",
            "name": "Key Agreeme nt Service",
            "outputs": "Return code, shared secret",
            "rolesSspAccess": "Crypto Officer (CO) - EC DH Private",
            "secFunImpl": "KAS-ECC- SSC KAS-FFC- SSC"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Key: G,E - EC DH Public Key: G,R - Other Party EC DH Public Key: W,E - DH Private Key: G,E - Other Party DH Public Key: W,E - KAS Shared Secret: G,R - DH Public Key: W,E Crypto",
            "secFunImpl": ""
          },
          {
            "description": "Hash based key derivation for calling application",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs, shared secret",
            "name": "Key Derivatio n KDA",
            "outputs": "Return code, derived keying material",
            "rolesSspAccess": "Officer (CO) - KDA Shared Secret: W,E - Derived Keying Material: G,R",
            "secFunImpl": "Key Derivation Hash Based"
          },
          {
            "description": "TLS Key derivation for calling application",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs, TLS KDF input",
            "name": "TLS Key Derivatio n",
            "outputs": "Return code, TLS Keying Material",
            "rolesSspAccess": "Crypto Officer (CO) - TLS KDF input: W,E - TLS Keying Material: G,R",
            "secFunImpl": "Key Derivation TLS 1.2 Key Derivation TLS 1.3"
          },
          {
            "description": "Asymmetri c key generation",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs",
            "name": "Key Generati on",
            "outputs": "Return code, key pair",
            "rolesSspAccess": "Crypto Officer (CO)",
            "secFunImpl": "Signature Key Generation"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- ECDSA Signing Key: G,R - ECDSA Verificatio n Key: G,R - RSA Signature Generatio n Key: G,R - RSA Signature Verificatio n Key: G,R - CTR_DR BG V: E - CTR_DR BG Key: E",
            "secFunImpl": ""
          },
          {
            "description": "Asymmetri c key pair validation",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs, key pair",
            "name": "Key Verificati on",
            "outputs": "Return code",
            "rolesSspAccess": "Crypto Officer (CO) - ECDSA Signing Key: W,E - ECDSA Verificatio n Key: W,E",
            "secFunImpl": "Signature Key Validation"
          },
          {
            "description": "On- Demand Self-Test",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "N/A",
            "name": "On- Demand Self-Test",
            "outputs": "Return Code",
            "rolesSspAccess": "Crypto Officer (CO)",
            "secFunImpl": "Authenticat ed Decryption Authenticat ed Encryption Decryption Encryption Hashing KAS-ECC- SSC KAS-FFC- SSC Key Derivation"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": "Hash Based Key Derivation TLS 1.2 Key Derivation TLS 1.3 AES- KeyWrap Message Authenticat ion Random Bit Generation Signature Generation Signature Verification"
          },
          {
            "description": "Zeroisation",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "N/A",
            "name": "Zeroisati on",
            "outputs": "N/A",
            "rolesSspAccess": "Crypto Officer (CO) - AES Key: Z - AES- GCM Key: Z - AES Wrapping Key: Z - Wrapped Key: Z - Unwrapp ed Key: Z - ECDSA Signing Key: Z - ECDSA Verificatio n Key: Z - EC DH Private Key: Z - EC DH Public Key: Z",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- Other Party EC DH Public Key: Z - DH Private Key: Z - DH Public Key: Z - Other Party DH Public Key: Z - KAS Shared Secret: Z - KDA Shared Secret: Z - HMAC Key: Z - RSA Signature Generatio n Key: Z - RSA Signature Verificatio n Key: Z - TLS KDF input: Z - TLS Keying Material: Z - CTR_DR BG Entropy Input: Z - CTR_DR BG Seed: Z - CTR_DR",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "BG V: Z - CTR_DR BG Key: Z - Derived Keying Material: Z",
            "secFunImpl": ""
          },
          {
            "description": "Show Status",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs",
            "name": "Show Status",
            "outputs": "Return code, status",
            "rolesSspAccess": "Crypto Officer (CO)",
            "secFunImpl": "None"
          },
          {
            "description": "Show module name",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs",
            "name": "Show Name",
            "outputs": "Return code, string of module name",
            "rolesSspAccess": "Crypto Officer (CO)",
            "secFunImpl": "None"
          },
          {
            "description": "Show module version",
            "indicator": "fips_service_indi cator set to 1",
            "inputs": "API call paramete rs",
            "name": "Show Version",
            "outputs": "Return code, string of module version",
            "rolesSspAccess": "Crypto Officer (CO)",
            "secFunImpl": "None"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES- CBC Encrypt KAT",
            "condition": "module power-up",
            "details": "Encrypt",
            "indicator": "None on success. \"AES- CBC-encrypt KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "128",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES- CBC Decrypt KAT",
            "condition": "module power-up",
            "details": "Decrypt",
            "indicator": "None on success. \"AES- CBC-decrypt KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "128",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES- GCM Encrypt KAT",
            "condition": "module power-up",
            "details": "Encrypt",
            "indicator": "None on success. \"AES- GCM-encrypt KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "128",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES- GCM",
            "condition": "module power-up",
            "details": "Decrypt",
            "indicator": "None on success. \"AES- GCM-decrypt KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "128",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "Decrypt KAT",
            "condition": "",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "Counter DRBG KAT",
            "condition": "module power-up",
            "details": "Instantiat e, Reseed, Generate",
            "indicator": "None on success. \"CTR- DRBG failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "initialize, reseed, generate tests, per SP 800- 90Arev1 Section 11.3",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "ECDSA SigGen KAT",
            "condition": "On first use",
            "details": "Sign",
            "indicator": "None on success. \"ECDSA-sign KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "ECDSA SigVer KAT",
            "condition": "On first use",
            "details": "Verify",
            "indicator": "None on success. \"ECDSA-verify KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "HMAC- SHA2- 256 KAT",
            "condition": "module power-up",
            "details": "MAC",
            "indicator": "None on success. \"HMAC-SHA-256 KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "128",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KAS- ECC- SSC Sp800- 56Ar3 KAT",
            "condition": "On first use",
            "details": "SSC",
            "indicator": "None on success. \"Z- computation KAT failed.\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KAS- FFC- SSC Sp800- 56Ar3 KAT",
            "condition": "On first use",
            "details": "SSC",
            "indicator": "None on success. \"FFDH failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "2048",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDA HKDF Sp800- 56Cr1 KAT",
            "condition": "module power-up",
            "details": "KDF",
            "indicator": "None on success. \"HKDF failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "HMAC SHA-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "RSA SigGen KAT",
            "condition": "On first use",
            "details": "Sign",
            "indicator": "None on success. \"RSA- sign KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "2048",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "RSA SigVer KAT",
            "condition": "On first use",
            "details": "Verify",
            "indicator": "None on success. \"RSA- verify KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "2048",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "SHA-1 KAT",
            "condition": "module power-up",
            "details": "Hash",
            "indicator": "None on success. \"SHA- 1 KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "n/a",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "SHA2- 256 KAT",
            "condition": "module power-up",
            "details": "Hash",
            "indicator": "None on success. \"SHA- 256 KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "n/a",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "SHA2- 512 KAT",
            "condition": "module power-up",
            "details": "Hash",
            "indicator": "None on success. \"SHA- 512 KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "n/a",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC762 7 KAT",
            "condition": "module power-up",
            "details": "KDF",
            "indicator": "None on success. \"TLS12-KDF KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "SHA-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TLS v1.3 KDF KAT",
            "condition": "module power-up",
            "details": "KDF",
            "indicator": "None on success. \"TLS13-KDF KAT failed\" on stderr on failure.",
            "testMethod": "KAT",
            "testProps": "SHA-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen PCT",
            "condition": "Keypair generated",
            "details": "Sign/Veri fy PCT",
            "indicator": "None on success. \"EC_KEY_generate_key_ fips failed\" on stderr on failure.",
            "testMethod": "Sign/Veri fy PCT",
            "testProps": "Generate d key- pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen PCT",
            "condition": "Keypair generated",
            "details": "Sign/Veri fy PCT",
            "indicator": "None on success. \"RSA_generate_key_fips failed\" on stderr on failure.",
            "testMethod": "Sign/Veri fy PCT",
            "testProps": "Generate d key- pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "KAS- ECC- SSC Sp800- 56Ar3 PCT",
            "condition": "Keypair generated",
            "details": "SP 800- 56Arev3 validity tests",
            "indicator": "None on success. Module aborted on failure.",
            "testMethod": "SP 800- 56Arev3 validity tests",
            "testProps": "Generate d key- pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "KAS- FFC- SSC Sp800- 56Ar3 PCT",
            "condition": "Keypair generated",
            "details": "SP 800- 56Arev3 validity tests",
            "indicator": "None on success. Module aborted on failure.",
            "testMethod": "SP 800- 56Arev3 validity tests",
            "testProps": "Generate d key- pair",
            "type": "PCT"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "Failure of any FIPS self-test",
            "description": "The module\u0027s error state",
            "indicator": "SIGABRT signal as module aborts. Prior to that most self-tests output an informational message on stderr (see Pre-Operational Self-Tests and Conditional Self-Tests tables for each test\u0027s failure message).",
            "name": "Error state",
            "recoveryMethod": "Restart the module"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "When all self-tests pass and only Approved algorithms are invoked",
            "name": "Approved",
            "statusIndicator": "Per service indication",
            "type": "Approved"
          },
          {
            "description": "When a non-Approved algorithm is invoked",
            "name": "Non- Approved",
            "statusIndicator": "Per service indication",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "MD5, MD4",
            "use": "Non-Approved Hashing"
          },
          {
            "name": "POLYVAL",
            "use": "Non-Approved authenticated encryption"
          },
          {
            "name": "DES, Triple-DES (non-compliant)",
            "use": "Non-Approved encryption/decryption"
          },
          {
            "name": "AES (non-compliant)",
            "use": "Non-Approved encryption/decryption"
          },
          {
            "name": "DH (non-compliant)",
            "use": "Non-Approved key agreement"
          },
          {
            "name": "RSA PKCS #1 v1.5 key wrapping (non-compliant)",
            "use": "Non-Approved key wrapping"
          },
          {
            "name": "TLS 1.0/1.1 KDF (non-compliant)",
            "use": "Non-Approved TLS key derivation"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "TLS 1.0/1.1 KDF (non-compliant)",
            "description": "Perform hashing operations when used with the TLS protocol version 1.0 and 1.1",
            "name": "TLS 1.0/1.1 KDF",
            "role": "Crypto Officer (CO)"
          },
          {
            "alg_accessed": "MD5, MD4",
            "description": "Perform hashing operations",
            "name": "Hashing",
            "role": "Crypto Officer (CO)"
          },
          {
            "alg_accessed": "POLYVAL",
            "description": "Used as part of AES-GCM- SIV",
            "name": "Hashing for GCM-SIV",
            "role": "Crypto Officer (CO)"
          },
          {
            "alg_accessed": "DES, Triple-DES (non-compliant) AES (non-compliant)",
            "description": "Perform symmetric encryption and/or decryption operations",
            "name": "Symmetric encryption/decryption",
            "role": "Crypto Officer (CO)"
          },
          {
            "alg_accessed": "RSA PKCS #1 v1.5 key wrapping (non- compliant)",
            "description": "Perform RSA PKCS #1 v1.5 key transport",
            "name": "Key Transport",
            "role": "Crypto Officer (CO)"
          },
          {
            "alg_accessed": "DH (non-compliant)",
            "description": "Perform non-compliant DH key agreement",
            "name": "Key Agreement",
            "role": "Crypto Officer (CO)"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "API input parameters",
            "logicalInterface": "Data Input",
            "physicalPort": "n/a"
          },
          {
            "data": "API output parameters and return values",
            "logicalInterface": "Data Output",
            "physicalPort": "n/a"
          },
          {
            "data": "API input parameters",
            "logicalInterface": "Control Input",
            "physicalPort": "n/a"
          },
          {
            "data": "API return values",
            "logicalInterface": "Status Output",
            "physicalPort": "n/a"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto Officer (CO)",
            "operatorType": "Crypto Officer",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A6134)",
            "details": "Single HMAC over entire module",
            "indicator": "None on success. \"FIPS integrity test failed.\" on stderr on failure.",
            "testMethod": "Integrity",
            "testProps": "Hardcoded 512 bit key",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "RAM",
            "distribution": "N/A",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "PT Input",
            "sfiAlgo": "",
            "source": "Calling Application"
          },
          {
            "dest": "Calling Application",
            "distribution": "N/A",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "PT Output",
            "sfiAlgo": "",
            "source": "RAM"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Turn off or power cycle the host computer to clear all RAM contents",
            "method": "Power Cycle Host",
            "operatorId": "Procedural - turn off or power cycle host",
            "rationale": "All module SSPs are held ephemerally in RAM, so turning off or power cycling the computer will cause them to be irretrievably lost."
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Ephemeral storage in RAM",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "",
            "integrityTest": "Yes",
            "packageFileName": "bcm.o",
            "swFwVersion": "20240805"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "Google Pixel 8",
            "hypervisorHostOs": "",
            "operatingSystem": "Android 15",
            "paa_pai": "Yes",
            "processors": "Google Tensor G3 64-bit",
            "version": "20240805"
          },
          {
            "hardwarePlatform": "Google Pixel 8",
            "hypervisorHostOs": "",
            "operatingSystem": "Android 15",
            "paa_pai": "No",
            "processors": "Google Tensor G3 64-bit",
            "version": "20240805"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "Key Type:Asymmetric",
            "implName": "BoringCrypto",
            "name": "CKG",
            "reference": "Section 4, example 1: U is directly output without XORing V"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 31
          }
        },
        "FF": {
          "DH": {
            "DH": 45,
            "DHE": 1
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "GCM": {
          "GCM": 6
        },
        "SIV": {
          "SIV": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "BoringSSL": {
          "BoringSSL": 1
        }
      },
      "crypto_protocol": {
        "TLS": {
          "TLS": {
            "TLS": 33,
            "TLS 1.2": 5,
            "TLS 1.3": 6,
            "TLS v1.2": 7,
            "TLS v1.3": 7
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1
        },
        "MAC": {
          "MAC": 8
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 12,
          "P-256": 22,
          "P-384": 10,
          "P-521": 10
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 3
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES- CBC Decrypt KAT 128": 1,
          "AES- CBC Encrypt KAT 128": 1,
          "AES- GCM 128": 1,
          "AES- GCM Encrypt KAT 128": 1,
          "AES-256": 1,
          "HMAC SHA-256": 1,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-256": 4,
          "PKCS #1": 3,
          "RSA PKCS #1": 3,
          "SHA- 1": 1,
          "SHA- 256": 1,
          "SHA- 512": 1,
          "SHA-1": 4,
          "SHA-256": 3,
          "SHA2- 256": 2,
          "SHA2- 512": 1,
          "SHA2-224": 6,
          "SHA2-256": 7,
          "SHA2-384": 7,
          "SHA2-512": 6,
          "SHA2224": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2,
          "level 1": 1
        }
      },
      "hash_function": {
        "MD": {
          "MD4": {
            "MD4": 2
          },
          "MD5": {
            "MD5": 2
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 4
          },
          "SHA2": {
            "SHA-256": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 15
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 9,
          "FIPS 180-4": 7,
          "FIPS 186-5": 8,
          "FIPS 198-1": 6,
          "FIPS186-5": 14
        },
        "NIST": {
          "NIST SP 800-38D": 1,
          "SP 800-135": 2,
          "SP 800-38A": 3,
          "SP 800-38C": 1,
          "SP 800-38D": 2,
          "SP 800-38F": 2,
          "SP 800-56A": 2,
          "SP 800-56C": 1,
          "SP 800-90A": 1,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS #1": 3
        },
        "RFC": {
          "RFC 5246": 1,
          "RFC 5288": 1,
          "RFC 7627": 1,
          "RFC 8446": 3,
          "RFC762": 1,
          "RFC7627": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 20,
            "AES-": 16,
            "AES-256": 1
          },
          "CAST": {
            "CAST": 20
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 2
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 9,
            "HMAC-SHA-256": 2
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 6
        },
        "IBM": {
          "SSC": 22
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "Samsung": {
          "Samsung": 4
        }
      },
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256A6134",
        "ECDSA SigVer (FIPS186-5)A6134",
        "SHA-1A6134",
        "ECDSA SigGen (FIPS186-5)A6134",
        "AES-GCMA6134",
        "HMAC-SHA-1A6134",
        "HMAC-SHA2-512/256A6134",
        "AES-CTRA6134",
        "SHA2-512A6134",
        "KAS-ECC-SSC Sp800-56Ar3A6134",
        "RSA SigVer (FIPS186-5)A6134",
        "RSA SigGen (FIPS186-5)A6134",
        "KAS-FFC-SSC Sp800-56Ar3A6134",
        "Counter DRBGA6134",
        "TLS v1.3 KDFA6134",
        "ECDSA KeyGen (FIPS186-5)A6134",
        "AES-CCMA6134",
        "AES-CBCA6134",
        "AES-KWPA6134",
        "HMAC-SHA2-512A6134",
        "ECDSA KeyVer (FIPS186-5)A6134",
        "SHA2-512/256A6134",
        "AES-KWA6134",
        "HMAC-SHA2-256A6134",
        "HMAC-SHA2-384A6134",
        "TLS v1.2 KDF RFC7627A6134",
        "AES-GMACA6134",
        "KDA HKDF Sp800-56Cr1A6134",
        "SHA2-384A6134",
        "HMAC-SHA2-224A6134",
        "RSA KeyGen (FIPS186-5)A6134",
        "AES-ECBA6134",
        "SHA2-224A6134"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A6134"
      ]
    },
    "policy_metadata": {
      "/Author": "jjing",
      "/CreationDate": "D:20260922120454-04\u002700\u0027",
      "/Creator": "PScript5.dll Version 5.2.2",
      "/ModDate": "D:20260922120454-04\u002700\u0027",
      "/Producer": "Acrobat Distiller 26.0 (Windows)",
      "/Title": "Microsoft Word - TID-28-e0e1-RBND-IS-2609171322_140sp.docx",
      "pdf_file_size_bytes": 391790,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 39
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "6e3c3a3323b1793df9c6528ef8c077995efed4b718d86ad798c1e8f6b0063dd5",
      "source_hash": "854525b5574c47d9ec78d570756a878eb689d33d52abba75e1752aca7939183e",
      "txt_hash": "74933100f1b9576122ea79c7868245b82081cdef4b44d9cc6fc0d49d8c412c3a"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys). No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": null,
    "date_sunset": "2031-04-17",
    "description": "A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.",
    "embodiment": "MultiChipStand",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Samsung BoringCrypto Android 15",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-09-23",
        "lab": "Gossamer Security Solutions",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Samsung Electronics Co., Ltd.",
    "vendor_url": "http://www.samsung.com"
  }
}