808bits

Masimo Cryptographic Module

FIPS 140-3 certificate #4788 · Masimo Corporation · data as of 2026-08-28
Active. Sunset date 2026-09-03, 5 days away.
Caveat: Interim validation. When operating in the approved mode. No assurance of the minimum strength of generated SSPs

Certificate

Certificate number4788
StandardFIPS 140-3
Statusactive
Sunset date2026-09-03
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorMasimo Corporation · website
Software versions1.0

Module description

The Masimo Cryptographic Module provides FIPS-Approved symmetric encryption and decryption, digital signature functions, hashing, message authentication, key establishment, and random number generation to Masimo solutions in support of general data protection functionality and secure communications protocols, including TLS.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3595
AES-CCMA3595
AES-CFB1A3595
AES-CFB128A3595
AES-CFB8A3595
AES-CMACA3595
AES-CTRA3595
AES-ECBA3595
AES-GCMA3595
AES-GMACA3595
AES-KWA3595
AES-KWPA3595
AES-OFBA3595
AES-XTS Testing Revision 2.0A3595
Counter DRBGA3595
DSA KeyGen (FIPS186-4)A3595
DSA PQGGen (FIPS186-4)A3595
DSA PQGVer (FIPS186-4)A3595
DSA SigGen (FIPS186-4)A3595
DSA SigVer (FIPS186-4)A3595
ECDSA KeyGen (FIPS186-4)A3595
ECDSA KeyVer (FIPS186-4)A3595
ECDSA SigGen (FIPS186-4)A3595
ECDSA SigVer (FIPS186-4)A3595
HMAC-SHA-1A3595
HMAC-SHA2-224A3595
HMAC-SHA2-256A3595
HMAC-SHA2-384A3595
HMAC-SHA2-512A3595
HMAC-SHA3-224A3595
HMAC-SHA3-256A3595
HMAC-SHA3-384A3595
HMAC-SHA3-512A3595
KAS-ECC-SSC Sp800-56Ar3A3595
KAS-FFC-SSC Sp800-56Ar3A3595
PBKDFA3595
RSA KeyGen (FIPS186-4)A3595
RSA SigGen (FIPS186-4)A3595
RSA SigGen (FIPS186-4)A3595
RSA SigGen (FIPS186-4)A3595
RSA SigVer (FIPS186-4)A3595
RSA SigVer (FIPS186-4)A3595
RSA SigVer (FIPS186-4)A3595
SHA-1A3595
SHA2-224A3595
SHA2-256A3595
SHA2-384A3595
SHA2-512A3595
SHA3-224A3595
SHA3-256A3595
SHA3-384A3595
SHA3-512A3595
SHAKE-128A3595
SHAKE-256A3595
TDES-CBCA3595
TDES-CFB1A3595
TDES-CFB64A3595
TDES-CFB8A3595
TDES-CMACA3595
TDES-ECBA3595
TDES-OFBA3595
TLS v1.2 KDF RFC7627A3595
TLS v1.3 KDFA3595

Allowed algorithms

AES (Cert. A3595) (-; Key unwrapping (using any approved mode));Triple-DES (Cert. A3595) (-; Key unwrapping (using any approved mode with two-key or three-key))

Tested configurations

  • Custom Linux OS with Linux kernel 2.6.38 running on Masimo Radical-7 with ARM Cortex-A8 (ARMv7-A) without PAA
  • Custom Linux OS with Linux kernel 4.9.43 running on Masimo Root with ARM Cortex-A8 (ARMv7-A) without PAA

Validation history

DateTypeLab
2024-09-04InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-09-04

Source documents