Microsoft BoringCrypto Module
Caveat: When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Certificate
| Certificate number | 4253 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Microsoft Corporation · website |
| Software versions | 7f02881e96e51f1873afcf384d02f782b48967ca |
Module description
Software library for the Microsoft Surface 2 Duo that contains cryptographic functionality to serve BoringSSL and other user-space applications
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A2316 |
| CVL | A2316 |
| DRBG | A2316 |
| ECDSA | A2316 |
| HMAC | A2316 |
| KAS-SSC | vendor affirmed |
| KTS | |
| RSA | A2316 |
| SHS | A2316 |
| Triple-DES | A2316 |
Allowed algorithms
MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Tested configurations
- Android 11 running on Microsoft Surface Duo 2 with Qualcomm Snapdragon 888 with PAA with PAA
- Android 11 running on Microsoft Surface Duo 2 with Qualcomm Snapdragon 888 without PAA (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-06-23 | Initial | Gossamer Security Solutions |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2022-06-23