808bits

Samsung BoringSSL Cryptographic Module

FIPS 140-2 certificate #2746 · Samsung Electronics Co., Ltd. · data as of 2026-09-15

Samsung BoringSSL Cryptographic Module, from Samsung Electronics Co., Ltd., holds FIPS 140-2 certificate #2746 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number2746
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSamsung Electronics Co., Ltd.
Software versions1.0

Module description

Quoted from the NIST CMVP entry for this certificate.

Provides general purpose cryptographic services to user-space applications on the mobile platform for the protection of data.

Security level exceptions

  • Physical Security: N/A
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (9)

AlgorithmCAVP certificates
AES3917
CVL777, 784, 802
DRBG1132
DSA1071
ECDSA857
HMAC2545
KTS
RSA2000
SHS3227

Other algorithms

Diffie-Hellman (CVL Cert. #802, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #777, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 128 bits of encryption strength); RSA (non-compliant); Triple-DES (non-compliant)

Tested configurations

  • Android 6.0.1 with processor EXYNOS5433 running on Samsung Galaxy Note 4, Android 6.0.1 with processor EXYNOS3475 running on Samsung Galaxy J3
  • Android 6.0.1 with processor EXYNOS7420 running on Samsung Galaxy S6 Edge
  • Android 6.0.1 with processor EXYNOS7420 running on Samsung Galaxy S6 Edge
  • Android 6.0.1 with processor EXYNOS8890 running on Samsung Galaxy S7 Edge
  • Android 6.0.1 with processor EXYNOS8890 running on Samsung Galaxy S7 Edge
  • Android 6.0.1 with processor Qualcomm APQ8084 running on Samsung Galaxy Note 4
  • Android 6.0.1 with processor Qualcomm APQ8084 running on Samsung Galaxy Note 4
  • Android 6.0.1 with processor Qualcomm MSM8916 running on Samsung Galaxy J3 (single-user mode)
  • Android 6.0.1 with processor Qualcomm MSM8996 running on Samsung Galaxy S7 Edge
  • Android 6.0.1 with processor Qualcomm MSM8996 running on Samsung Galaxy S7 Edge

Validation history

DateTypeLab
2016-09-16InitialGossamer Security Solutions
2016-09-29UpdateGossamer Security Solutions

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-09-16, 2016-09-29

Source documents