BlackBerry Linux Kernel Cryptographic Module

Certificate #2728

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 29.08.2016
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and installed, initialized and configured as specified in the Security Policy Appendix C
Exceptions
  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A
Description The BlackBerry Linux Kernel Cryptographic Module is a software-only external Linux Kernel module that provides general-purpose cryptographic services to the remainder of the kernel. The BlackBerry Linux Kernel Cryptographic Module expands the secure capabilities and features BlackBerry is known for, to devices running operating systems other than the BlackBerry OS.
Tested configurations
  • Android 5.1 64-bit running on a Qualcomm Snapdragon MSM8992 development device (single-user mode)
  • CentOS 7 64-bit running on a Kontron NSN2U IP Network Server with AES-NI
  • CentOS 7 64-bit running on a Kontron NSN2U IP Network Server without AES-NI
Vendor BlackBerry Limited
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, DES, Triple-DES, TDES, HMAC, HMAC-SHA-224, HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512, CBC-MAC, CMAC
Asymmetric Algorithms
DSA
Hash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
Schemes
MAC
Randomness
DRBG, RNG
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, LRW, XTS

Security level
Level 1, level 1

Standards
FIPS 140-2, FIPS 197, FIPS 180-4, FIPS 198-1, FIPS PUB 140-2, NIST SP 800-67, NIST SP 800-90A, NIST SP 800-90, SP 800-90

File metadata

Title FIPS 140-2 Security Policy
Subject Module name
Keywords FIPS, 140-2, Security Policy, validation, certification
Author Randy Eyamie
Creation date D:20160630160240-04'00'
Modification date D:20160630160240-04'00'
Pages 29
Creator Microsoft® Word 2016
Producer Microsoft® Word 2016

References

Outgoing
  • 1383 - historical - JUNOS-FIPS 9.3 OS Cryptographic Module

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2728,
  "dgst": "ff3637d30b19ff65",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "Triple-DES#1953",
        "DRBG#850",
        "SHS#2859",
        "AES#3464",
        "HMAC#2209"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "1383"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "1383"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "1383"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "FF": {
          "DSA": {
            "DSA": 1
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CCM": {
          "CCM": 5
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 8
        },
        "ECB": {
          "ECB": 7
        },
        "GCM": {
          "GCM": 3
        },
        "LRW": {
          "LRW": 3
        },
        "OFB": {
          "OFB": 1
        },
        "XTS": {
          "XTS": 4
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1383": 1,
          "#1953": 1,
          "#2209": 5,
          "#2859": 5,
          "#3464": 2,
          "#850": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "#1953 AES": 1,
          "#3464 AES": 2,
          "HMAC- SHA-384": 1,
          "HMAC-SHA-1": 8,
          "HMAC-SHA-224": 6,
          "HMAC-SHA-256": 4,
          "HMAC-SHA-384": 4,
          "HMAC-SHA-512": 6,
          "HMAC-SHA256": 2,
          "SHA- 384": 1,
          "SHA-1": 3,
          "SHA-224": 3,
          "SHA-256": 3,
          "SHA-384": 3,
          "SHA-512": 3
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3,
          "level 1": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 3
          },
          "SHA2": {
            "SHA-224": 3,
            "SHA-256": 3,
            "SHA-384": 3,
            "SHA-512": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 14
        },
        "RNG": {
          "RNG": 5
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 10,
          "FIPS 180-4": 5,
          "FIPS 197": 1,
          "FIPS 198-1": 5,
          "FIPS PUB 140-2": 7
        },
        "NIST": {
          "NIST SP 800-67": 1,
          "NIST SP 800-90": 1,
          "NIST SP 800-90A": 2,
          "SP 800-90": 4
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 11
          }
        },
        "DES": {
          "3DES": {
            "TDES": 2,
            "Triple-DES": 4
          },
          "DES": {
            "DES": 3
          }
        },
        "constructions": {
          "MAC": {
            "CBC-MAC": 1,
            "CMAC": 1,
            "HMAC": 6,
            "HMAC-SHA-224": 3,
            "HMAC-SHA-256": 2,
            "HMAC-SHA-384": 2,
            "HMAC-SHA-512": 3
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Randy Eyamie",
      "/CreationDate": "D:20160630160240-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word 2016",
      "/Keywords": "FIPS, 140-2, Security Policy, validation, certification",
      "/ModDate": "D:20160630160240-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word 2016",
      "/Subject": "Module name",
      "/Title": "FIPS 140-2 Security Policy",
      "pdf_file_size_bytes": 625688,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://ca.blackberry.com/",
          "http://www.blackberry.com/",
          "mailto:[email protected]"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 29
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "3c7a92bc94669691a0e77521256e2b3c189fb72ae8bf403ebb33ec805125c52b",
    "policy_txt_hash": "b5fa6f909d8a453b174732bb52a6e3818758a87f717293ea21b38b3db692ad66"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and installed, initialized and configured as specified in the Security Policy Appendix C",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertAug2016.pdf",
    "date_sunset": null,
    "description": "The BlackBerry Linux Kernel Cryptographic Module is a software-only external Linux Kernel module that provides general-purpose cryptographic services to the remainder of the kernel. The BlackBerry Linux Kernel Cryptographic Module expands the secure capabilities and features BlackBerry is known for, to devices running operating systems other than the BlackBerry OS.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: N/A",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "BlackBerry Linux Kernel Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "1.0",
    "tested_conf": [
      "Android 5.1 64-bit running on a Qualcomm Snapdragon MSM8992 development device (single-user mode)",
      "CentOS 7 64-bit running on a Kontron NSN2U IP Network Server with AES-NI",
      "CentOS 7 64-bit running on a Kontron NSN2U IP Network Server without AES-NI"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2016-08-29",
        "lab": "CGI Information Systems \u0026 Management Consultants Inc",
        "validation_type": "Initial"
      }
    ],
    "vendor": "BlackBerry Limited",
    "vendor_url": "http://www.blackberry.com"
  }
}