808bits

Cr50 U2F Cryptographic Library

FIPS 140-2 certificate #4652 · Google, LLC · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode. No assurance of the minimum strength of generated keys.

Certificate

Certificate number4652
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeFirmware-Hybrid
EmbodimentSingle Chip
VendorGoogle, LLC · website
Hardware versionsH1B2P
Firmware versions1.0.1

Module description

The Cr50 U2F Cryptographic Library is a firmware-hybrid module residing in the Google, LLC Google Security Chips (GSC) chip. The module is responsible for low-level cryptographic primitives on Google Security Chips (GSC) used in recent versions of Google Chromebooks, and includes functionality for key generation, signature generation, random bit generation, keyed-hashing and signature verification operations in support of U2F-related requests in the Cr50 Chrome OS.

Security level exceptions

  • Physical Security: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
CKGvendor affirmed
DRBGA2353
ECDSAA2353
ENT
HMACA2352, A2353
SHSA2352, A2353

Tested configurations

  • Google H1B2 with ARM V7-M with PAA

Validation history

DateTypeLab
2023-11-06InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-11-06

Source documents