BoringCrypto

Certificate #4953

Webpage information ?

Status active
Validation dates 27.01.2025
Sunset date 26-01-2027
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat Interim validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
  • Documentation requirements: N/A
  • Cryptographic module security policy: N/A
Description A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.
Tested configurations
  • Android 14 running on a Google Pixel 5a with a Qualcomm Snapdragon 765 with PAA
  • Android 14 running on a Google Pixel 5a with a Qualcomm Snapdragon 765 without PAA
  • Android 14 running on a Google Pixel 6 with a Google Tensor with PAA
  • Android 14 running on a Google Pixel 6 with a Google Tensor without PAA
  • Android 14 running on a Google Pixel 7 with a Google Tensor G2 with PAA
  • Android 14 running on a Google Pixel 7 with a Google Tensor G2 without PAA
  • Android 14 running on a Google Pixel 8 with a Google Tensor G3 with PAA
  • Android 14 running on a Google Pixel 8 with a Google Tensor G3 without PAA
  • Debian Linux 6.4.4 running on an n2d with an AMD EPYC 7B12 with PAA
  • Debian Linux 6.4.4 running on an n2d with an AMD EPYC 7B12 without PAA
  • Google Prodimage with Linux 5.10.0 running on a Tau t2a with an Ampere Altra with PAA
  • Google Prodimage with Linux 5.10.0 running on a Tau t2a with an Ampere Altra without PAA
  • Google Prodimage with Linux 5.15.110 running on an IN762 with an IN762 with PAA
  • Google Prodimage with Linux 5.15.110 running on an IN762 with an IN762 without PAA
  • Ubuntu 23.04 running on a Gigabyte GA-Z170X-UD5 with an Intel Core i7-6700K with PAA
  • Ubuntu 23.04 running on a Gigabyte GA-Z170X-UD5 with an Intel Core i7-6700K without PAA
Vendor Google, LLC.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy ?

Symmetric Algorithms
AES, AES-256, AES-, CAST, DES, Triple-DES, TDEA, HMAC, HMAC-SHA-224, HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512
Asymmetric Algorithms
ECDSA, ECC, DHE, DH, Diffie-Hellman
Hash functions
SHA-1, SHA-224, SHA-256, SHA-512, MD4, MD5
Schemes
MAC, Key Agreement
Protocols
SSL, TLS v1.2, TLS, TLS v1.3, TLS 1.3
Randomness
DRBG
Libraries
BoringSSL
Elliptic Curves
P-224, P-256, P-521, P-384
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM

Vendor
Qualcomm

Security level
Level 1

Standards
FIPS 140-3, FIPS 140, FIPS 197, FIPS 186-4, FIPS 198-1, FIPS 180-4, FIPS PUB 140-3, SP 800-38A, SP 800-38D, SP 800-38C, SP 800-38F, SP 800-140B, SP 800-135, SP 800-90B, NIST SP 800-38D, NIST SP 800-131A, PKCS 1, PKCS #1, RFC7627, RFC6727, RFC 8446, RFC 5288, RFC 5246

File metadata

Author Brian Wood
Creation date D:20250110120238-05'00'
Modification date D:20250110120238-05'00'
Pages 36
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

Heuristics ?

No heuristics are available for this certificate.

References ?

No references are available for this certificate.

Updates ?

  • 27.01.2025 The certificate was first processed.
    New certificate

    A new FIPS 140 certificate with the product name BoringCrypto was processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4953,
  "dgst": "f0b48f80d7276757",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "Counter DRBGA4687",
        "HMAC-SHA2-512/256A4687",
        "ECDSA KeyVer (FIPS186-4)A4687",
        "AES-GCMA4687",
        "AES-CBCA4687",
        "ECDSA SigGen (FIPS186-4)A4687",
        "AES-GMACA4687",
        "SHA2-384A4687",
        "SHA-1A4687",
        "AES-CCMA4687",
        "KAS-FFC-SSC Sp800-56Ar3A4687",
        "HMAC-SHA2-224A4687",
        "HMAC-SHA2-512A4687",
        "RSA SigGen (FIPS186-4)A4687",
        "AES-ECBA4687",
        "HMAC-SHA2-256A4687",
        "SHA2-224A4687",
        "HMAC-SHA2-384A4687",
        "ECDSA KeyGen (FIPS186-4)A4687",
        "HMAC-SHA-1A4687",
        "SHA2-512/256A4687",
        "SHA2-512A4687",
        "AES-KWA4687",
        "AES-KWPA4687",
        "ECDSA SigVer (FIPS186-4)A4687",
        "RSA SigVer (FIPS186-4)A4687",
        "RSA KeyGen (FIPS186-4)A4687",
        "KDA HKDF Sp800-56Cr1A4687",
        "KAS-ECC-SSC Sp800-56Ar3A4687",
        "TLS v1.3 KDFA4687",
        "SHA2-256A4687",
        "AES-CTRA4687",
        "TLS v1.2 KDF RFC7627A4687"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDSA": {
            "ECDSA": 21
          }
        },
        "FF": {
          "DH": {
            "DH": 39,
            "DHE": 1,
            "Diffie-Hellman": 1
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 7
        },
        "CCM": {
          "CCM": 3
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 4
        },
        "ECB": {
          "ECB": 4
        },
        "GCM": {
          "GCM": 5
        },
        "OFB": {
          "OFB": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "BoringSSL": {
          "BoringSSL": 1
        }
      },
      "crypto_protocol": {
        "TLS": {
          "SSL": {
            "SSL": 1
          },
          "TLS": {
            "TLS": 37,
            "TLS 1.3": 1,
            "TLS v1.2": 7,
            "TLS v1.3": 7
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 5
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 8,
          "P-256": 14,
          "P-384": 4,
          "P-521": 4
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 2
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES-256": 1,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-224": 2,
          "HMAC-SHA-256": 6,
          "HMAC-SHA-384": 2,
          "HMAC-SHA-512": 2,
          "PAA 2": 1,
          "PAA 3": 1,
          "PAA 4": 1,
          "PAA 5": 1,
          "PAA 6": 1,
          "PAA 7": 1,
          "PAA 8": 1,
          "PKCS #1": 2,
          "PKCS 1": 2,
          "RSA PKCS #1": 2,
          "SHA- 384": 1,
          "SHA-1": 3,
          "SHA-224": 1,
          "SHA-256": 2,
          "SHA-512": 1,
          "SHA2- 384": 2,
          "SHA2-224": 1,
          "SHA2-256": 3,
          "SHA2-384": 1,
          "SHA2-512": 3
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3
        }
      },
      "hash_function": {
        "MD": {
          "MD4": {
            "MD4": 4
          },
          "MD5": {
            "MD5": 5
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 3
          },
          "SHA2": {
            "SHA-224": 1,
            "SHA-256": 2,
            "SHA-512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 13
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140": 4,
          "FIPS 140-3": 13,
          "FIPS 180-4": 2,
          "FIPS 186-4": 7,
          "FIPS 197": 6,
          "FIPS 198-1": 2,
          "FIPS PUB 140-3": 1
        },
        "NIST": {
          "NIST SP 800-131A": 1,
          "NIST SP 800-38D": 1,
          "SP 800-135": 4,
          "SP 800-140B": 2,
          "SP 800-38A": 2,
          "SP 800-38C": 1,
          "SP 800-38D": 3,
          "SP 800-38F": 3,
          "SP 800-90B": 2
        },
        "PKCS": {
          "PKCS #1": 2,
          "PKCS 1": 1
        },
        "RFC": {
          "RFC 5246": 1,
          "RFC 5288": 1,
          "RFC 8446": 1,
          "RFC6727": 2,
          "RFC7627": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 25,
            "AES-": 1,
            "AES-256": 1
          },
          "CAST": {
            "CAST": 3
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "Triple-DES": 5
          },
          "DES": {
            "DES": 3
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 12,
            "HMAC-SHA-224": 1,
            "HMAC-SHA-256": 3,
            "HMAC-SHA-384": 1,
            "HMAC-SHA-512": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Qualcomm": {
          "Qualcomm": 1
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Brian Wood",
      "/CreationDate": "D:20250110120238-05\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20250110120238-05\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 590047,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://github.com/ninja-build/ninja/releases",
          "https://golang.org/dl/",
          "https://boringssl.googlesource.com/boringssl.git/+/refs/heads/fips-20230428/crypto/fipsmodule/FIPS.md",
          "https://ci.android.com/",
          "https://commondatastorage.googleapis.com/chromium-boringssl-fips/boringssl-a430310d6563c0734ddafca7731570dfb683dc19.tar.xz",
          "https://ci.android.com/builds/submitted/10050109/aosp_cf_arm64_phone-userdebug/latest",
          "https://cmake.org/download/",
          "https://csrc.nist.gov/projects/cryptographic-module-validation-program",
          "http://releases.llvm.org/download.html",
          "https://boringssl.googlesource.com/boringssl"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 36
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_garbage": false,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_pdf_hash": "00c171a0e940aba9e76429004a28ce8755a987728f09dee2486412684ce03e34",
    "policy_txt_hash": "eddab7b6edea6189368f8c1c74215f4b8d45eba235cb49d98b897f7611cf96ec"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)",
    "certificate_pdf_url": null,
    "date_sunset": "2027-01-26",
    "description": "A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A",
      "Documentation requirements: N/A",
      "Cryptographic module security policy: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "BoringCrypto",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": "2023042800",
    "tested_conf": [
      "Android 14 running on a Google Pixel 5a with a Qualcomm Snapdragon 765 with PAA",
      "Android 14 running on a Google Pixel 5a with a Qualcomm Snapdragon 765 without PAA",
      "Android 14 running on a Google Pixel 6 with a Google Tensor with PAA",
      "Android 14 running on a Google Pixel 6 with a Google Tensor without PAA",
      "Android 14 running on a Google Pixel 7 with a Google Tensor G2 with PAA",
      "Android 14 running on a Google Pixel 7 with a Google Tensor G2 without PAA",
      "Android 14 running on a Google Pixel 8 with a Google Tensor G3 with PAA",
      "Android 14 running on a Google Pixel 8 with a Google Tensor G3 without PAA",
      "Debian Linux 6.4.4 running on an n2d with an AMD EPYC 7B12 with PAA",
      "Debian Linux 6.4.4 running on an n2d with an AMD EPYC 7B12 without PAA",
      "Google Prodimage with Linux 5.10.0 running on a Tau t2a with an Ampere Altra with PAA",
      "Google Prodimage with Linux 5.10.0 running on a Tau t2a with an Ampere Altra without PAA",
      "Google Prodimage with Linux 5.15.110 running on an IN762 with an IN762 with PAA",
      "Google Prodimage with Linux 5.15.110 running on an IN762 with an IN762 without PAA",
      "Ubuntu 23.04 running on a Gigabyte GA-Z170X-UD5 with an Intel Core i7-6700K\t with PAA",
      "Ubuntu 23.04 running on a Gigabyte GA-Z170X-UD5 with an Intel Core i7-6700K\t without PAA"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-01-27",
        "lab": "DEKRA Certification, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Google, LLC.",
    "vendor_url": "http://www.google.com"
  }
}