808bits

Inline Crypto Engine (ICE)

FIPS 140-2 certificate #4265 · Google, LLC · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: None

Certificate

Certificate number4265
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeHardware
EmbodimentSingle Chip
VendorGoogle, LLC · website
Hardware versions1.0

Module description

The Inline Crypto Engine (ICE) module is comprised of a sub-chip cryptographic subsystem in the Google IN762 SoC. The module provides a cryptographic engine supporting cryptographic offload for IPsec and PSP protocols. The ICE module processes network infrastructure packets in both the Ingress and Egress directions. In addition to providing the cryptographic primitives for the security protocols it also provides packet integrity authentication and anti-replay protection.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA811, A812, A813
KBKDFA811
KTS

Tested configurations

  • IN762 SoC B0

Validation history

DateTypeLab
2022-07-17InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2022-07-17

Source documents