808bits

SafeZone FIPS SW Cryptographic Module

FIPS 140-3 certificate #4898 · Rambus Inc. · data as of 2026-09-03

SafeZone FIPS SW Cryptographic Module, from Rambus Inc., holds FIPS 140-3 certificate #4898 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Replaced by certificate #5423. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim Validation. When operated in approved mode

Certificate

Certificate number4898
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRambus Inc. · website
Software versionsv2.0
EntropyENT (NP)

Module description

Quoted from the NIST CMVP entry for this certificate.

SafeZone FIPS SW Cryptographic Module is a FIPS 140-3 Level 1 validated software cryptographic module from Rambus. The module provides a set of commonly used cryptographic primitives by exposing a custom API for a wide range of applications, typically running on a general-purpose operating system.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (53)

AlgorithmCAVP certificates
AES-CBCA2836
AES-CCMA2836
AES-CMACA2836
AES-CTRA2836
AES-ECBA2836
AES-GCMA2836
AES-GMACA2836
AES-KWA2836
AES-KWPA2836
AES-OFBA2836
AES-XTS Testing Revision 2.0A2836
Counter DRBGA2836
DSA KeyGen (FIPS186-4)A2836
DSA PQGGen (FIPS186-4)A2836
DSA PQGVer (FIPS186-4)A2836
DSA SigGen (FIPS186-4)A2836
DSA SigVer (FIPS186-4)A2836
ECDSA KeyGen (FIPS186-4)A2836
ECDSA SigGen (FIPS186-4)A2836
ECDSA SigVer (FIPS186-4)A2836
HMAC-SHA-1A2836
HMAC-SHA2-224A2836
HMAC-SHA2-256A2836
HMAC-SHA2-384A2836
HMAC-SHA2-512A2836
KAS-ECC CDH-ComponentA2836
KAS-ECC-SSC Sp800-56Ar3A2836
KAS-FFC-SSC Sp800-56Ar3A2836
KDA HKDF SP800-56Cr2A2836
KDA TwoStep SP800-56Cr2A2836
KDF IKEv1A2836
KDF IKEv2A2836
KDF SP800-108A2836
KDF SRTPA2836
KTS-IFCA2836
PBKDFA2836
RSA KeyGen (FIPS186-4)A2836
RSA SigGen (FIPS186-4)A2836
RSA SigVer (FIPS186-4)A2836
SHA-1A2836
SHA2-224A2836
SHA2-256A2836
SHA2-384A2836
SHA2-512A2836
SHA3-224A2836
SHA3-256A2836, A2890
SHA3-384A2836
SHA3-512A2836
SHAKE-128A2836
SHAKE-256A2836
TDES-CBCA2836
TDES-ECBA2836
TLS v1.2 KDF RFC7627A2836

Tested configurations

  • Linux Ubuntu 20.04 LTS (32-bit) running on a Raspberry Pi 2 with a Broadcom BCM2836 with PAA
  • Linux Ubuntu 20.04 LTS (32-bit) running on an AAEON UP Core UPC-CHT01-A20-0464-A11 with an Intel® Atom™ x5-Z8350 with PAA
  • Linux Ubuntu 20.04 LTS (32-bit) running on an AAEON UP Core UPC-CHT01-A20-0464-A11 with an Intel® Atom™ x5-Z8350 without PAA
  • Linux Ubuntu 20.04 LTS (64-bit) running on a Raspberry Pi 4 with a Broadcom BCM2711 with PAA
  • Linux Ubuntu 20.04 LTS (64-bit) running on a Raspberry Pi 4 with a Broadcom BCM2711 without PAA
  • Linux Ubuntu 20.04 LTS (64-bit) running on an AAEON UP Core UPC-CHT01-A20-0464-A11 with an Intel® Atom™ x5-Z8350 with PAA
  • Linux Ubuntu 20.04 LTS (64-bit) running on an AAEON UP Core UPC-CHT01-A20-0464-A11 with an Intel® Atom™ x5-Z8350 without PAA

Validation history

DateTypeLab
2024-11-22InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-11-22

Source documents