808bits

Apple CoreCrypto Kernel Module v8.0 for ARM

FIPS 140-2 certificate #3147 · Apple Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS Mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number3147
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorApple Inc. · website
Software versions8.0

Module description

The Apple CoreCrypto Kernel Module v8.0 for ARM is a software cryptographic module running on a multi-chip standalone hardware device and provides services intended to protect data in transit and at rest.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
key establishment methodology provides between 128 and 160 bits of encryption strength
AES4906, 4907, 4908, 4909, 4910, 4911, 4912, 4913, 4916, 4917, 4918, 4919, 4920, 4921, 4922, 4923, 4924, 4925, 4926, 4927, 4928, 4929, 4932, 4935, 5039, 5040, 5041, 5125, 5126, 5127, 5128, 5129, 5130, 5185, 5186, 5187
DRBG1736, 1737, 1738, 1739, 1740, 1741, 1742, 1743, 1744, 1745, 1746, 1747, 1748, 1749, 1750, 1751, 1752, 1753, 1754, 1755, 1756, 1757, 1760, 1763, 1849, 1850, 1851, 1852, 1853, 1854, 1855, 1856, 1860, 1861, 1862, 1863, 1915, 1916, 1917, 1918, 1919, 1920, 1921, 1922, 1959, 1960, 1961, 1962
ECDSA1289, 1290, 1291, 1292, 1293, 1294, 1295, 1296, 1298, 1325, 1326, 1345
HMAC3273, 3274, 3275, 3276, 3277, 3278, 3279, 3280, 3350, 3351, 3352, 3353, 3354, 3355, 3356, 3357, 3361, 3362, 3405, 3406, 3407, 3408, 3441, 3442
KTS
PBKDFvendor affirmed
RSA2717, 2718, 2719, 2720, 2721, 2722, 2723, 2724, 2728, 2763, 2764, 2783
SHS4013, 4014, 4015, 4016, 4017, 4018, 4019, 4020, 4095, 4096, 4097, 4098, 4099, 4100, 4101, 4102, 4106, 4107, 4151, 4152, 4153, 4154, 4189, 4190
Triple-DES2589, 2590, 2595, 2596, 2597, 2598, 2599, 2600, 2602, 2628, 2629, 2637

Allowed algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • iBridgeOS (15P2064) running on Apple iMac Pro with Apple T2 (iBridge 2,1) with PAA
  • iBridgeOS (15P2064) running on Apple iMac Pro with Apple T2 (iBridge 2,1) without PAA (single-user mode)
  • iOS 11 running on iPad Air 2 with Apple A8X CPU with PAA
  • iOS 11 running on iPad Air 2 with Apple A8X CPU without PAA
  • iOS 11 running on iPad Pro with Apple A10X Fusion CPU with PAA
  • iOS 11 running on iPad Pro with Apple A10X Fusion CPU without PAA
  • iOS 11 running on iPad Pro with Apple A9X CPU with PAA
  • iOS 11 running on iPad Pro with Apple A9X CPU without PAA
  • iOS 11 running on iPhone 5S with Apple A7 CPU with PAA
  • iOS 11 running on iPhone 5S with Apple A7 CPU without PAA
  • iOS 11 running on iPhone 6 (iPhone 6 and iPhone 6 Plus) with Apple A8 CPU with PAA
  • iOS 11 running on iPhone 6 (iPhone 6 and iPhone 6 Plus) with Apple A8 CPU without PAA
  • iOS 11 running on iPhone 6S (iPhone 6S and iPhone 6S Plus) with Apple A9 CPU with PAA
  • iOS 11 running on iPhone 6S (iPhone 6S and iPhone 6S Plus) with Apple A9 CPU without PAA
  • iOS 11 running on iPhone 7 (iPhone 7 and iPhone 7 Plus) with Apple A10 Fusion CPU with PAA
  • iOS 11 running on iPhone 7 (iPhone 7 and iPhone 7 Plus) with Apple A10 Fusion CPU without PAA
  • iOS 11 running on iPhone 8 with Apple A11 Bionic CPU with PAA
  • iOS 11 running on iPhone 8 with Apple A11 Bionic CPU without PAA
  • tvOS 11 running on Apple TV 4K with Apple A10X Fusion CPU with PAA
  • tvOS 11 running on Apple TV 4K with Apple A10X Fusion CPU without PAA
  • watchOS 4 running on Apple Watch Series 1 with Apple S1P CPU with PAA
  • watchOS 4 running on Apple Watch Series 1 with Apple S1P CPU without PAA
  • watchOS 4 running on Apple Watch Series 3 with Apple S3 CPU with PAA
  • watchOS 4 running on Apple Watch Series 3 with Apple S3 CPU without PAA

Validation history

DateTypeLab
2018-03-09Initialatsec information security corporation
2018-05-17Updateatsec information security corporation
2018-07-03Updateatsec information security corporation
2021-03-11Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-03-09, 2018-05-17, 2018-07-03, 2021-03-11

Source documents