Showing posts with label FIPS 140-3 news. Show all posts
Showing posts with label FIPS 140-3 news. Show all posts

April 1, 2014

8 Important requirements for your FIPS 140-3 Survival Kit

Why 8? Because 8 is my favorite, positive, single-digit number.

(Also, some might say I am relying on my Magic 8 Ball for my FIPS 140-3 posts.)

This is the second post in my FIPS 140-3 Survival Kit series. As of this post, no formal announcement has been made on the replacement standard to FIPS 140-2.  Be sure to read the first post for proper context.

For Technology Vendors in the planning phase for future products, here are 8 important requirements that are likely to change from the current FIPS 140-2 requirements:


  1. EMI/EMC testing - there are no EMI/EMC requirements in ISO 19790. Everyone is thrilled that this requirement got cut -- especially those vendors with short-shelf-life products.
  2. EFP or EFT for Level 3 - This FIPS 140-2 Level 4 requirement has been pushed down to Level 3 in ISO 19790. (Note: Only EFP is allowed at Level 4 in ISO 19790)
  3. Cryptographic integrity tests - For Level 2 and above, either an Approved keyed MAC based integrity check (Level 2) or an Approved digital signature based integrity test (Levels 2-4) is required. FIPS 140-2 allowed a non-cryptographic error detection code as a start-up integrity check for HW/FW modules.
  4. Conditional tests for algorithms - known-answer tests (KATs) are not required for all of the Approved algorithms on power-up. A conditional test of an Approved algorithm is required prior to use of that algorithm. This will allow for faster module start-up times!
  5. Degraded operation - ISO 19790 allows for a module to transition to a degraded operation if the mechanism or function causing the failure is isolated.
  6. One role minimum - Only the Crypto Officer Role is required. Other roles may be defined as needed (User Role, Maintenance Role, ...).
  7. Multi-factor authentication - If you are designing a Level 4 module, then you will need to employ multi-factor identity based authentication for access control.
  8. Zeroisation gets stricter - At Levels 2 and 3, you can no longer overwrite an SSP (Sensitive Security Parameter) with another SSP. Temporary SSPs must be zeroised when no longer needed. At Level 4, even cryptographically protected SSPs must be zeroised. (Note: In ISO 19790, things get "zeroised" not "zeroized")
My next FIPS 140-3 Survival Kit post will take a look into SSPs.

Mark Minnoch is an Account Manager at InfoGard Laboratories.  His other favorite single-digit numbers are 0 (because zero is awesome) and -3 (that's right -- negative-three).

March 17, 2014

Build your own FIPS 140-3 survival kit

"When is FIPS 140-3 coming out?"

This is probably the question I am asked most often. It's my own fault for trying to provide my best guesses at a FIPS 140-3 schedule.

Even though my predictions have not panned out as expected, that won't deter me from attempting to be helpful.

Since the last NIST activity was to replace dates with "TBDs" on the official FIPS 140-3 schedule, my recommendation to stay ahead of the FIPS 140-3 curve is to begin building your own FIPS 140-3 Survival Kit. The first items to place in the kit are the following ISO documents:

  • ISO/IEC 19790 Security requirements for cryptographic modules
  • ISO/IEC 24759 Test requirements for cryptographic modules

ISO 19790 may be what NIST selects as the replacement standard for FIPS 140-2.  

ISO 24759 is the "DTR" (with all the ASxx.xx, VExx.xx.xx, and TExx.xx.xx statements as you know and love them).

Even though I've been through several California earthquakes, I am not able to predict when they will occur. I do know that I need to prepare for the next one. 

I am not certain that these ISO documents will be adopted by NIST, but it is a good idea to prepare. 

In earthquakes and FIPS, it's best to have a survival kit ready and not need it.

(Go to the next post in the FIPS 140-3 Survival Kit series)

Mark Minnoch is an Account Manager at InfoGard Laboratories.  During the 1989 Loma Prieta earthquake, he was in Santa Clara... under his desk.

September 25, 2012

Unofficial FIPS 140-3 schedule

Thank you, dear readers, for your interest in my "unofficial FIPS 140-3 schedule" updates.  By popular demand, I've been asked to communicate my best guesses again.

Here are the latest dates from NIST's FIPS 140-3 Pub Development page:

  • On October 1, 2012, the additional public comments period closes for specific sections of the second draft of FIPS 140-3 (comments on sections not specifically listed will not be considered).
  • During 2Q of 2013 (April/May/June), all public comments will be addressed by NIST.
  • The remaining schedule milestones do not have target dates so this is where I begin my guessing...

Here are my thoughts on the remainder of FIPS 140-3 schedule:

  • The scope of the current public comment period is focused.  My approach is to pick more aggressive dates than I have in the past as I do not anticipate any significant changes to the working draft.
  • 3Q of 2013 (July/August/September) - FIPS 140-3 presented to the Commerce Department for signature.
  • 1Q of 2014 (January/February/March) - FIPS 140-3 becomes effective.  The Derived Test Requirements have already been published by now.  Modules may be validated by Labs for FIPS 140-3 requirements.
  • 3Q of 2014 (July/August/September) - the transition period for completing FIPS 140-2 reports ends. All new validation reports submitted must be validated to FIPS 140-3 requirements.  
  • 2015 - Any products in the planning cycle that are to be released in 2015 must be designed to meet FIPS 140-3 requirements.

In other news, ISO/IEC 19790:2012 was published in August 2012.  This is an international standard that evolved from the original FIPS 140-3 draft.  The Derived Test Requirements for 19790, ISO/IEC 24759, may be published in 4Q 2013 (October/November/December).  If the FIPS 140-3 publication followed an alternate path to adopt 19790 (with allowances for US and Canadian specific security functions and other requirements), then the overall schedule may be a Quarter sooner than my estimated schedule above.  There are no official plans for FIPS 140-3 to adopt 19790.

Reference Links:
Official FIPS 140-3 Pub Development
ISO / IEC 19790:2012

 

August 31, 2012

NIST seeking comments on FIPS 140-3 draft

Here is the link to the latest FIPS 140-3 draft:   http://csrc.nist.gov/news_events/index.html#august30

Comments are requested on or before October 1, 2012.

NIST plans to address all public comments in the 2nd Quarter of 2013.  The updated FIPS 140-3 Development Status information is here:  http://csrc.nist.gov/groups/ST/FIPS140_3/


September 21, 2011

Update: Unofficial FIPS 140-3 schedule

Here are my thoughts on the current FIPS 140-3 schedule:
  • Previously, NIST had left open the possibility of another public comment period.  The schedule now indicates that another public comment period will occur in 1Q 2012.
  • Since it has been some time since the last public review, I am expecting a 60 day public review period (perhaps it will be only 30 days? -- share your thoughts in the comment section).
  • After the comments have been addressed, the Secretary of Commerce receives the FIPS 140-3 publication for signature.  Previous estimates allow for 6 months for the Secretary of Commerce to sign.  
  • My unofficial estimate for FIPS 140-3 reports to be accepted by the CMVP is now 2Q 2013 (at the earliest).
  • My unofficial estimate for the last date FIPS 140-2 reports will be accepted by the CMVP is the end of 2013 (which allows for a 6 month transition period from 140-2 to 140-3).