Cryptographic Testing

Entropy Source Assessment

Consult our experts. We are happy to support you.

What atsec offers:

atsec US offers entropy source assessment specified by the SP800-90 series of documents through its accredited Cryptographic Security Testing (CST) laboratory (NVLAP Lab Code #200658-0). The assessment consists of two parts and will lead to an ESV certificate listing on the NIST website:

  • Analysis of the design and operation of the noise source, as well as other aspects of the noise source (conditioning components, health tests, IID assumptions, etc.), that need to be documented and reviewed.
  • Cryptographic modules that implement an entropy source need to be compliant with Special Publication 800-90B “Recommendation for the Entropy Sources Used for Random Bit Generation”. This involves the statistical testing of raw entropy data (one million samples) collected from a continuous run of the noise source, as well as raw entropy data (another million samples) collected by concatenating 1,000 samples after a restart of the noise source with a total of 1,000 restarts.

Why our services are important to you:

The CMVP requires that all FIPS 140-3 module validation submissions include documented conformance to SP 800-90B when it is applicable. SP 800-90B, along with corresponding FIPS 140-3 IGs D.J, D.K, and D.O, outline the requirements for an entropy source to be included in a FIPS-approved cryptographic module.

Downloads:

Further information for your certification journey.

Entropy source implementations tested by atsec’s laboratory:

Vendor / ImplementationCertificate / Date
SAP SE
Kernel CPU Time Jitter RNG Entropy Source
E359
2026-09-09
Qualcomm Technologies, Inc.
Entropy Source of the Qualcomm® Pseudo Random Number Generator (Snapdragon® 7 Gen 4, Qualcomm Dragonwing™ Q-7790, Snapdragon® 8s Gen 4)
E358
2026-09-09
HP Inc.
HP Kernel CPU Time Jitter RNG Entropy Source
E357
2026-09-08
IBM Corporation
IBM Capri ASIC Entropy Source with EP11 CLIC
E355
2026-08-28
Ctrl IQ, Inc.
CIQ Linux Kernel CPU Time Jitter RNG Entropy Source
E354
2026-08-26
Google LLC
Google CPA2601 Entropy Source
E353
2026-08-21
Google LLC
Google Tensor 6th Gen security core Entropy Source
E352
2026-08-19
Qualcomm Technologies, Inc.
Entropy Source of the Qualcomm® Random Number Generator
E351
2026-08-19
Samsung Electronics Co., Ltd
Samsung Exynos TRNG
E350
2026-08-18
Samsung Electronics Co.,Ltd.
Samsung Evan TRNG
E332
2026-05-26

Still have questions?

Can’t find what you’re looking for? Let’s talk!

FIPS 140-3 Testing

FIPS 140-3 specifies requirements related to securely designing and implementing cryptographic modules, and compliance is increasingly mandatory worldwide.

Cryptographic Algorithm Testing

Testing that cryptographic algorithms are implemented correctly is a prerequisite for FIPS 140-3 cryptographic module testing and NIAP Common Criteria evaluations.

Common Criteria Evaluation

The Common Criteria (CC), also known as ISO 15408, is an internationally recognized standard used to specify and assess the security of IT products.

The Information Security Provider

Read Our Latest Blog Articles

Learn the latest and greatest about information security. You’ll find insights and analyses of recent developments in technology and policy on our blog.