Xperia Cryptographic Module
Caveat: When operated in FIPS mode. No assurance of the minimum strength of generated keys. The module generates cryptographic keys whose strengths are modified by available entropy
Certificate
| Certificate number | 2726 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Sony Mobile Communications, Inc. · website |
| Software versions | 1.0.0 |
Module description
The Xperia Cryptographic Module provides a functionality/service, intended to protect data in transit and at rest.
Security level exceptions
- Roles, Services, and Authentication: Level 2
- Physical Security: N/A
- EMI/EMC: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms
Other algorithms
EC Diffie-Hellman (CVL Cert. #485, key agreement methodology provides between 112 and 256 bits of security strength; non-compliant less than 112 bits of encryption strength); DUAL EC DRBG; RSA (key wrapping methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RNG
Tested configurations
- Android 5.0 running on Xperia Z4 tablet with ARMv8 Cryptographic Instruction
- Android 5.0 running on Xperia Z4 tablet without ARMv8 Cryptographic Instruction (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2016-08-29 | Initial | UL Verification Services, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2016-08-29