Inline Crypto Engine (ICE)
Inline Crypto Engine (ICE), from Google, LLC, holds FIPS 140-2 certificate #4425 at overall level 1. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: None
Certificate
| Certificate number | 4425 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Vendor | Google, LLC · website |
| Hardware versions | 1.0 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Inline Crypto Engine (ICE) module is comprised of a sub-chip cryptographic subsystem in the Google IN762 SoC. The module provides a cryptographic engine supporting cryptographic offload for IPsec and PSP protocols. The ICE module processes network infrastructure packets in both the Ingress and Egress directions. In addition to providing the cryptographic primitives for the security protocols it also provides packet integrity authentication and anti-replay protection.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms (3)
Tested configurations
- IN762 SoC B1
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-01-26 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2023-01-26