March 17, 2014

Build your own FIPS 140-3 survival kit

"When is FIPS 140-3 coming out?"

This is probably the question I am asked most often. It's my own fault for trying to provide my best guesses at a FIPS 140-3 schedule.

Even though my predictions have not panned out as expected, that won't deter me from attempting to be helpful.

Since the last NIST activity was to replace dates with "TBDs" on the official FIPS 140-3 schedule, my recommendation to stay ahead of the FIPS 140-3 curve is to begin building your own FIPS 140-3 Survival Kit. The first items to place in the kit are the following ISO documents:

  • ISO/IEC 19790 Security requirements for cryptographic modules
  • ISO/IEC 24759 Test requirements for cryptographic modules

ISO 19790 may be what NIST selects as the replacement standard for FIPS 140-2.  

ISO 24759 is the "DTR" (with all the ASxx.xx, VExx.xx.xx, and TExx.xx.xx statements as you know and love them).

Even though I've been through several California earthquakes, I am not able to predict when they will occur. I do know that I need to prepare for the next one. 

I am not certain that these ISO documents will be adopted by NIST, but it is a good idea to prepare. 

In earthquakes and FIPS, it's best to have a survival kit ready and not need it.

(Go to the next post in the FIPS 140-3 Survival Kit series)

Mark Minnoch is an Account Manager at InfoGard Laboratories.  During the 1989 Loma Prieta earthquake, he was in Santa Clara... under his desk.

March 14, 2014

FIPS and sharks

The CMVP recently emerged from "Shark Week" with all limbs attached. In fact, the results of "Shark Week" are even better than fresh fish tacos with guacamole at the beach!

The CMVP probably has a different interpretation of "Shark Week" than I do, but I don't want to interrupt any of the Reviewers to ask them for a definition (they've been busy).

At the beginning of 2014, the CMVP was faced with an enormous backlog of FIPS 140-2 reports to review -- more than 150 reports were waiting for Reviewers to complete their initial pass. When I saw this report backlog, I feared that we might start seeing CMVP review times of 1 year or more. "Shark Week" was CMVP's strategy to attack the report queue.

No mercy.
No phone calls.
No meetings.

They became sharks. Reports were their prey.

How did they do?

Much better than the seals swimming in open waters. The March 10, 2014 Modules in Process report shows only 70 reports are in the "Review Pending" or "In Review" columns --  that's more than a 50% reduction in review backlog.

There's still work to do -- the report also shows 112 reports in the "Coordination" column. The "Coordination" phase indicates that the CMVP has completed their initial review and clarifying questions have been sent to the testing laboratory. This is the highest I've seen the Coordination value. The Vendor, Laboratory, and CMVP Reviewers all share responsibility in moving the report out of the "Coordination" phase so the certificate process can begin.

Will we see 3-4 month review times again this year? It could happen (and I would have never believed it in January).

Next week is InfoGard's "Shark Week."  We have some report comments to attack!

Mark Minnoch is an Account Manager at InfoGard Laboratories.  He was chased to shore once while surfing after seeing a shark fin that actually belonged to a dolphin.

January 10, 2014

January 7, 2014

Second highest number of FIPS 140-2 certificates issued in 2013

The CMVP recovered nicely at the end of 2013 -- working down 8+ month queue times to 5.5 months -- to have the second highest year of validating FIPS 140-2 cryptographic modules. With 208 new FIPS certificates issued in 2013, only 2010 tops that number with 229.

Here are the totals by Laboratory for 2013.


Congratulations (again!) to the FIPS Team at InfoGard Laboratories.  That's 5 years in a row of producing the most FIPS 140-2 certificates (2009-2013).

November 15, 2013

CMVP queue time is currently 5.5 months for FIPS 140-2 reports

InfoGard's current estimate for the CMVP queue time is 5.5 months (this is the time between report submission -- "Review Pending" -- to the time the Lab receives comments from the CMVP -- "Coordination").  

As of November 15, 2013, the CMVP has provided comments on all InfoGard reports submitted through May 2013 (the oldest InfoGard report that has not received CMVP comments was submitted June 10, 2013).

The CMVP focus on the report queue since returning from the US government shutdown in October has been phenomenal.  Right after the NIST side of the CMVP returned to work last month, I expected the queue to hold steady at 8 months.

Please contribute your comments to this post or contact me directly.

Contact info:
Mark Minnoch
InfoGard Laboratories
805-783-0810

October 18, 2013

No perfect storm for the FIPS 140-2 report queue?

After reviewing the CMVP's Modules in Process list pre- and post-government shutdown, the expected "welcome back to work" flood of reports did not materialize.  In the simplest of explanations, the CMVP queue only increased by 3 reports during the furlough.

Let me explain my thinking.  The following picture shows the Modules in Process totals updated 10/17/2013 (after NIST returned to work):

The "Review Pending" column shows 73 FIPS 140-2 reports have been submitted to the CMVP but Reviewers have not yet been assigned.  As you might have guessed, this is a large number of reports waiting to be reviewed, but this number was 69 before the shutdown.  The CMVP is responsible for moving reports to the next phase of "In Review."

The "In Review" column indicates that 12 reports have been assigned to Reviewers.  This is actually a decrease from 19 shown on the 9/30/2013 report.  7 or more reports moved into the coordination phase once NIST returned.  The CMVP is responsible for moving reports to the"Coordination" phase.

The 86 reports in the "Coordination" phase means that the CMVP has completed their initial review and clarifying questions have been sent to the testing laboratory.  This is a very high number of reports for the CMVP to manage and it has a direct impact on the queue time.  This compares to 80 at the end of September and we would expect to see this number increase with the decrease in the "In Review" phase.  The Vendor, Laboratory, and CMVP Reviewers all share responsibility in moving the report to the "Finalization" phase.


The "Finalization" phase still has 11 reports pre- and post-shutdown.


In comparing the pre- and post-shutdown grand totals for all reports, there is only a +3 gain.


"What does it all mean?"  (side note: a former co-worker used this question instead of a "hello" greeting every time someone passed him in the hall)


Here are my thoughts (and please share yours in the comment section):


  1. We may have dodged a bullet.  Perhaps I will be asking for forgiveness for my earlier prediction that review times would certainly increase. (Let's hope that I do get to apologize!)
  2. CSEC, the Canadian side of the CMVP, may have rocked though some reports while NIST was shutdown.
I will continue to monitor the report queue, but for now I estimate the CMVP queue review time is 8 months.



October 11, 2013

Shut the backdoor

If you have a FIPS 140-2 cryptographic module that implements the Dual EC DRBG from SP800-90A, then you may be fielding questions from your customers after they read articles like this one from the IEEE Spectrum:  Can You Trust NIST?

Please contact me if InfoGard performed your FIPS 140-2 validation.  I would be happy to help determine if your Dual EC DRBG function can be disabled in a new version of your crypto module without going through a lengthy revalidation effort.

Mark Minnoch
mminnoch@infogard.com 
805-783-0810