Masimo Cryptographic Module
Caveat: Interim validation. When operating in the approved mode. No assurance of the minimum strength of generated SSPs
Certificate
| Certificate number | 4788 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2026-09-03 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Masimo Corporation · website |
| Software versions | 1.0 |
Module description
The Masimo Cryptographic Module provides FIPS-Approved symmetric encryption and decryption, digital signature functions, hashing, message authentication, key establishment, and random number generation to Masimo solutions in support of general data protection functionality and secure communications protocols, including TLS.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A3595 |
| AES-CCM | A3595 |
| AES-CFB1 | A3595 |
| AES-CFB128 | A3595 |
| AES-CFB8 | A3595 |
| AES-CMAC | A3595 |
| AES-CTR | A3595 |
| AES-ECB | A3595 |
| AES-GCM | A3595 |
| AES-GMAC | A3595 |
| AES-KW | A3595 |
| AES-KWP | A3595 |
| AES-OFB | A3595 |
| AES-XTS Testing Revision 2.0 | A3595 |
| Counter DRBG | A3595 |
| DSA KeyGen (FIPS186-4) | A3595 |
| DSA PQGGen (FIPS186-4) | A3595 |
| DSA PQGVer (FIPS186-4) | A3595 |
| DSA SigGen (FIPS186-4) | A3595 |
| DSA SigVer (FIPS186-4) | A3595 |
| ECDSA KeyGen (FIPS186-4) | A3595 |
| ECDSA KeyVer (FIPS186-4) | A3595 |
| ECDSA SigGen (FIPS186-4) | A3595 |
| ECDSA SigVer (FIPS186-4) | A3595 |
| HMAC-SHA-1 | A3595 |
| HMAC-SHA2-224 | A3595 |
| HMAC-SHA2-256 | A3595 |
| HMAC-SHA2-384 | A3595 |
| HMAC-SHA2-512 | A3595 |
| HMAC-SHA3-224 | A3595 |
| HMAC-SHA3-256 | A3595 |
| HMAC-SHA3-384 | A3595 |
| HMAC-SHA3-512 | A3595 |
| KAS-ECC-SSC Sp800-56Ar3 | A3595 |
| KAS-FFC-SSC Sp800-56Ar3 | A3595 |
| PBKDF | A3595 |
| RSA KeyGen (FIPS186-4) | A3595 |
| RSA SigGen (FIPS186-4) | A3595 |
| RSA SigGen (FIPS186-4) | A3595 |
| RSA SigGen (FIPS186-4) | A3595 |
| RSA SigVer (FIPS186-4) | A3595 |
| RSA SigVer (FIPS186-4) | A3595 |
| RSA SigVer (FIPS186-4) | A3595 |
| SHA-1 | A3595 |
| SHA2-224 | A3595 |
| SHA2-256 | A3595 |
| SHA2-384 | A3595 |
| SHA2-512 | A3595 |
| SHA3-224 | A3595 |
| SHA3-256 | A3595 |
| SHA3-384 | A3595 |
| SHA3-512 | A3595 |
| SHAKE-128 | A3595 |
| SHAKE-256 | A3595 |
| TDES-CBC | A3595 |
| TDES-CFB1 | A3595 |
| TDES-CFB64 | A3595 |
| TDES-CFB8 | A3595 |
| TDES-CMAC | A3595 |
| TDES-ECB | A3595 |
| TDES-OFB | A3595 |
| TLS v1.2 KDF RFC7627 | A3595 |
| TLS v1.3 KDF | A3595 |
Allowed algorithms
AES (Cert. A3595) (-; Key unwrapping (using any approved mode));Triple-DES (Cert. A3595) (-; Key unwrapping (using any approved mode with two-key or three-key))
Tested configurations
- Custom Linux OS with Linux kernel 2.6.38 running on Masimo Radical-7 with ARM Cortex-A8 (ARMv7-A) without PAA
- Custom Linux OS with Linux kernel 4.9.43 running on Masimo Root with ARM Cortex-A8 (ARMv7-A) without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-09-04 | Initial | Lightship Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-09-04