808bits

Samsung BoringSSL Android

FIPS 140-2 certificate #3900 · Samsung Electronic Co. Ltd. · data as of 2026-09-03

Samsung BoringSSL Android, from Samsung Electronic Co. Ltd., holds FIPS 140-2 certificate #3900 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number3900
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSamsung Electronic Co. Ltd. · website
Software versions1.5

Module description

Quoted from the NIST CMVP entry for this certificate.

Provides general purpose cryptographic services to user-space applications on the mobile platform for the protection of data.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AESA907
CVLA907
DRBGA907
ECDSAA907
HMACA907
KAS-SSCvendor affirmed
KTS
RSAA907
SHSA907
Triple-DESA907

Allowed algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Android 11 running on Galaxy A52 with Snapdragon 750 with PAA
  • Android 11 running on Galaxy A52 with Snapdragon 750 without PAA
  • Android 11 running on Galaxy A71 5G with Snapdragon 765 without PAA
  • Android 11 running on Galaxy A71 5G with Snapdragon 765 with PAA
  • Android 11 running on Galaxy Note10+ with Exynos 9825 with PAA
  • Android 11 running on Galaxy Note10+ with Exynos 9825 without PAA
  • Android 11 running on Galaxy S10+ with Exynos 9820 with PAA
  • Android 11 running on Galaxy S10+ with Exynos 9820 without PAA
  • Android 11 running on Galaxy S10+ with Snapdragon 855 with PAA
  • Android 11 running on Galaxy S10+ with Snapdragon 855 without PAA
  • Android 11 running on Galaxy S20+ 5G with Exynos 990 with PAA
  • Android 11 running on Galaxy S20+ 5G with Exynos 990 without PAA
  • Android 11 running on Galaxy S20+ 5G with Snapdragon 865 with PAA
  • Android 11 running on Galaxy S20+ 5G with Snapdragon 865 without PAA
  • Android 11 running on Galaxy S21+ with Exynos 2100 with PAA
  • Android 11 running on Galaxy S21+ with Exynos 2100 without PAA
  • Android 11 running on Galaxy S21+ with Snapdragon 888 with PAA
  • Android 11 running on Galaxy S21+ with Snapdragon 888 without PAA
  • Android 11 running on Galaxy Tab Active3 with Exynos 9810 with PAA
  • Android 11 running on Galaxy Tab Active3 with Exynos 9810 without PAA
  • Android 11 running on Galaxy Xcover Pro with Exynos 9611 with PAA
  • Android 11 running on Galaxy Xcover Pro with Exynos 9611 without PAA
  • Wear OS 3 running on Galaxy Watch 4 with Exynos 5515 with PAA
  • Wear OS 3 running on Galaxy Watch 4 with Exynos 5515 without PAA (single-user mode)

Validation history

DateTypeLab
2021-04-19InitialAcumen Security
2022-01-14UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-04-19, 2022-01-14

Source documents