River Cryptographic Module
Caveat: When operated in FIPS mode with Titan Chip validated to FIPS 140-2 under Cert. #3382 operating in FIPS mode
Certificate
| Certificate number | 3383 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Vendor | Google, Inc. · website |
| Hardware versions | RiverHD and RiverQD |
| Firmware versions | River-gqfips-1.2 |
Module description
The River Cryptographic Module is a Network Interface Card (NIC) housed on a host device, which is designed to support Ethernet and IP networking. The River module contains cryptographic hardware and firmware support, which allows data packets to be encrypted and decrypted using AES-GCM-128 at "line rate", while supporting a very large number of simultaneous Security Associations.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 5656, 5659 |
| CKG | vendor affirmed |
| DRBG | 2285 |
| ECDSA | 1529 |
| KTS | |
| RSA | 3045 |
| SHA-3 | 58 |
| SHS | 4536, 4537 |
Allowed algorithms
NDRNG
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2019-03-22 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2019-03-22