808bits

Microsoft Windows 8, Microsoft Windows Server 2012, Microsoft Windows RT, Microsoft Surface Windows RT, Microsoft Surface Windows 8 Pro, Microsoft Windows Phone 8, and Microsoft Windows Storage Server 2012 Cryptographic Primitives Library (BCRYPTPRIMITIVES.DLL)

FIPS 140-2 certificate #1892 · Microsoft Corporation · data as of 2026-08-28
Historical. Moved to historical list in accordance with SP800-131A Revision 1 Transition (AES/TDES key wrapping). Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with modules Microsoft Windows 8, Microsoft Windows Server 2012, Microsoft Windows RT, Microsoft Surface Windows RT, Microsoft Surface Windows 8 Pro, and Microsoft Windows Phone 8 Kernel Mode Cryptographic Primitives Library (CNG.SYS) validated to FIPS 140-2 under Cert. #1891 operating in FIPS mode, and Microsoft Windows 8, Microsoft Windows Server 2012, Microsoft Windows RT, Microsoft Surface Windows RT, Microsoft Surface Windows 8 Pro, and Microsoft Windows Phone 8 Code Integrity (CI.DLL) validated to FIPS 140-2 under Cert. #1897 operating in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy.

Certificate

Certificate number1892
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorMicrosoft Corporation · website
Software versions6.2.9200

Module description

The Cryptographic Primitives Library (BCRYPTPRIMITIVES.DLL) provides cryptographic services to Windows components and applications. It includes cryptographic algorithms in an easy-to-use cryptographic module via the Cryptography Next Generation (CNG) API. It can be dynamically linked into applications for the use of general-purpose FIPS 140-2 validated cryptography. This cryptographic module also maintains FIPS 140-2 validation compliance (according to FIPS 140-2 PUB Implementation Guidance G.5) on Microsoft Windows 8, Microsoft Windows 8 Pro, and Microsoft Windows Server 2012 Datacenter.

Security level exceptions

  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AES2197, 2216
DRBG258, 259
DSA687
ECDSA341
HMAC1345
KAS36
KBKDF3
PBKDFvendor affirmed
RSA1133, 1134
SHS1903
Triple-DES1387

Other algorithms

AES (Cert. #2197, key wrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); DES; Legacy CAPI KDF; MD2; MD4; MD5; HMAC MD5; RC2; RC4; RSA (encrypt/decrypt)

Tested configurations

  • Microsoft Windows 8 Enterprise (x64) running on a Dell PowerEdge SC430 without PAA
  • Microsoft Windows 8 Enterprise (x64) running on Intel Core i7 with PAA running on an Intel Client Desktop
  • Microsoft Windows 8 Enterprise (x86) running on a Dell Dimension C521
  • Microsoft Windows 8 Pro (x64) running on an Intel x64 Processor with PAA running on a Microsoft Surface Windows 8 Pro
  • Microsoft Windows Phone 8 (ARMv7 Thumb-2) running on a Windows Phone 8
  • Microsoft Windows RT (ARMv7 Thumb-2) running on a Microsoft Surface Windows RT
  • Microsoft Windows RT (ARMv7 Thumb-2) running on a Qualcomm Tablet
  • Microsoft Windows RT (ARMv7 Thumb-2) running on an NVIDIA Tegra 3 Tablet
  • Microsoft Windows Server 2012 (x64) running on a Dell PowerEdge SC430 without PAA
  • Microsoft Windows Server 2012 (x64) running on Intel Core i7 with PAA running on an Intel Client Desktop
  • Microsoft Windows Storage Server 2012 (x64) running on an Intel Maho Bay with PAA
  • Microsoft Windows Storage Server 2012 (x64) running on an Intel Maho Bay without PAA (single-user mode)

Validation history

DateTypeLab
2013-09-06InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2015-01-09UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-09-06, 2015-01-09

Source documents