Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #4253

Details

Module Name
Microsoft BoringCrypto Module
Standard
FIPS 140-2
Status
Active
Sunset Date
12/1/2025
Overall Level
1
Caveat
When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Security Level Exceptions
  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A
Module Type
Software
Embodiment
Multi-Chip Stand Alone
Description
Software library for the Microsoft Surface 2 Duo that contains cryptographic functionality to serve BoringSSL and other user-space applications
Tested Configuration(s)
  • Android 11 running on Microsoft Surface Duo 2 with Qualcomm Snapdragon 888 with PAA with PAA
  • Android 11 running on Microsoft Surface Duo 2 with Qualcomm Snapdragon 888 without PAA (single-user mode)
Approved Algorithms
AES Certs. #A2316
CVL Cert. #A2316
DRBG Cert. #A2316
ECDSA Cert. #A2316
HMAC Cert. #A2316
KAS-SSC vendor affirmed
KTS AES Cert. #A2316; key establishment methodology provides between 128 and 256 bits of encryption strength
RSA Cert. #A2316
SHS Cert. #A2316
Triple-DES Cert. #A2316
Allowed Algorithms
MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Software Versions
7f02881e96e51f1873afcf384d02f782b48967ca

Vendor

Microsoft Corporation
1 Microsoft Way
Redmond, WA 98052
USA

Karan Dhillon
karand@microsoft.com
Phone: +1 (857) 4536177

Validation History

Date Type Lab
6/23/2022 Initial GOSSAMER SECURITY SOLUTIONS INC