Module Name
Zebra BoringSSL Cryptographic Module
Caveat
When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Security Level Exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.
Tested Configuration(s)
- Android 10 running on TC57 with Qualcomm SDM660 with PAA
- Android 10 running on TC57 with Qualcomm SDM660 without PAA
- Android 11 running on ET40 with Qualcomm SM6375 with PAA
- Android 11 running on ET40 with Qualcomm SM6375 without PAA
- Android 11 running on TC57 with Qualcomm SDM660 with PAA
- Android 11 running on TC57 with Qualcomm SDM660 without PAA
- Android 13 running on ET40 with Qualcomm SM6375 with PAA
- Android 13 running on ET40 with Qualcomm SM6375 without PAA (single-user mode)
- Android 13 running on TC57 with Qualcomm SDM660 with PAA
- Android 13 running on TC57 with Qualcomm SDM660 without PAA
- Android 13 running on TC58 with Qualcomm QCM6490 with PAA
- Android 13 running on TC58 with Qualcomm QCM6490 without PAA
Approved Algorithms
key establishment methodology provides between 128 and 256 bits of encryption strength |
|
AES |
Certs. #C1748 and #A1395 |
CKG |
vendor affirmed |
CVL |
Certs. #C1748 and #A1395 |
DRBG |
Certs. #C1748 and #A1395 |
ECDSA |
Certs. #C1748 and #A1395 |
HMAC |
Certs. #C1748 and #A1395 |
KAS-SSC |
vendor affirmed |
KTS |
AES Certs. #C1748 and #A1395 |
RSA |
Certs. #C1748 and #A1395 |
SHS |
Certs. #C1748 and #A1395 |
Triple-DES |
Certs. #C1748 and #A1395 |
Allowed Algorithms
MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)