BoringCrypto
Caveat: Interim validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
Certificate
| Certificate number | 4953 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Google, LLC. · website |
| Software versions | 2023042800 |
Module description
A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A4687 |
| AES-CCM | A4687 |
| AES-CTR | A4687 |
| AES-ECB | A4687 |
| AES-GCM | A4687 |
| AES-GMAC | A4687 |
| AES-KW | A4687 |
| AES-KWP | A4687 |
| Counter DRBG | A4687 |
| ECDSA KeyGen (FIPS186-4) | A4687 |
| ECDSA KeyVer (FIPS186-4) | A4687 |
| ECDSA SigGen (FIPS186-4) | A4687 |
| ECDSA SigVer (FIPS186-4) | A4687 |
| HMAC-SHA-1 | A4687 |
| HMAC-SHA2-224 | A4687 |
| HMAC-SHA2-256 | A4687 |
| HMAC-SHA2-384 | A4687 |
| HMAC-SHA2-512 | A4687 |
| HMAC-SHA2-512/256 | A4687 |
| KAS-ECC-SSC Sp800-56Ar3 | A4687 |
| KAS-FFC-SSC Sp800-56Ar3 | A4687 |
| KDA HKDF Sp800-56Cr1 | A4687 |
| RSA KeyGen (FIPS186-4) | A4687 |
| RSA SigGen (FIPS186-4) | A4687 |
| RSA SigVer (FIPS186-4) | A4687 |
| SHA-1 | A4687 |
| SHA2-224 | A4687 |
| SHA2-256 | A4687 |
| SHA2-384 | A4687 |
| SHA2-512 | A4687 |
| SHA2-512/256 | A4687 |
| TLS v1.2 KDF RFC7627 | A4687 |
| TLS v1.3 KDF | A4687 |
Tested configurations
- Android 14 running on a Google Pixel 5a with a Qualcomm Snapdragon 765 with PAA
- Android 14 running on a Google Pixel 5a with a Qualcomm Snapdragon 765 without PAA
- Android 14 running on a Google Pixel 6 with a Google Tensor with PAA
- Android 14 running on a Google Pixel 6 with a Google Tensor without PAA
- Android 14 running on a Google Pixel 7 with a Google Tensor G2 with PAA
- Android 14 running on a Google Pixel 7 with a Google Tensor G2 without PAA
- Android 14 running on a Google Pixel 8 with a Google Tensor G3 with PAA
- Android 14 running on a Google Pixel 8 with a Google Tensor G3 without PAA
- Debian Linux 6.4.4 running on an n2d with an AMD EPYC 7B12 with PAA
- Debian Linux 6.4.4 running on an n2d with an AMD EPYC 7B12 without PAA
- Google Prodimage with Linux 5.10.0 running on a Tau t2a with an Ampere Altra with PAA
- Google Prodimage with Linux 5.10.0 running on a Tau t2a with an Ampere Altra without PAA
- Google Prodimage with Linux 5.15.110 running on an IN762 with an IN762 with PAA
- Google Prodimage with Linux 5.15.110 running on an IN762 with an IN762 without PAA
- Ubuntu 23.04 running on a Gigabyte GA-Z170X-UD5 with an Intel Core i7-6700K with PAA
- Ubuntu 23.04 running on a Gigabyte GA-Z170X-UD5 with an Intel Core i7-6700K without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2025-01-27 | Initial | DEKRA Cybersecurity Certification Laboratory |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2025-01-27