808bits

Samsung OpenSSL Cryptographic Module

FIPS 140-2 certificate #2120 · Samsung Electronics Co., Ltd. · data as of 2026-09-15

Samsung OpenSSL Cryptographic Module, from Samsung Electronics Co., Ltd., holds FIPS 140-2 certificate #2120 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2120
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorSamsung Electronics Co., Ltd. · website
Software versionsSecOpenSSL2.0.3

Module description

Quoted from the NIST CMVP entry for this certificate.

Provides general purpose cryptographic services to user-space applications on the mobile platform for the protection of data in transit.

Security level exceptions

  • Physical Security: N/A
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AES2351, 2411
CVL56, 72
DRBG299, 321
DSA735, 753
ECDSA386, 396
HMAC1458, 1496
RNG1171, 1190
RSA1212, 1245
SHS2026, 2069
Triple-DES1471, 1501

Other algorithms

RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); Blowfish; Triple-DES-CTR (non-compliant); AES-CTR (non-compliant); MD4; MD5; MDC-2; RC2; RC4; RIPEMD-160; Diffie-Hellman; md_rand.c; DRBG (Certs. #299 and #321; DUAL-EC; non-compliant)

Tested configurations

  • Android Jelly Bean 4.1 running on Samsung Galaxy Note II
  • Android Jelly Bean 4.2 running on Samsung Galaxy S4 (single-user mode)

Validation history

DateTypeLab
2014-03-28Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-03-28

Source documents