March 26, 2012

InfoGard featured in local newspaper

InfoGard Laboratories was featured in San Luis Obispo's local newspaper.  The Tribune published the article on Saturday, March 24.  A short version of the article may be read here:

http://www.sanluisobispo.com/2012/03/23/2002514/infogard-laboratories.html

March 6, 2012

FIPS 180-4 published

NIST published FIPS 180-4 Secure Hash Standard (SHS).

The updates from FIPS 180-3 are listed in Appendix C of the new FIPS 180-4 publication.  In short, the changes are:
  1. FIPS 180-4 relaxes the padding restriction described in FIPS 180-3
  2. SHA-512/224 and SHA-512/256 were added to the standard

January 20, 2012

FIPS 140-2 Consolidated Validation Certificates

Q:  How long does it take for a recently validated cryptographic module to appear on a FIPS 140-2 Consolidated Validation Certificate?

A:  At the end of each month, the CMVP generates a list of cryptographic modules that were issued new FIPS 140-2 certificates.  The Consolidated Validation Certificate is signed by a NIST representative in the United States and then routed to Canada for signature by a CSEC representative.  The signature and posting process takes about two weeks. 

For example, modules that received a certificate number in the month of January will appear on the FIPS 140-2 Consolidated Validation Certificate that gets posted mid-February.

January 10, 2012

January 5, 2012

FIPS 140-2 Annex D updated

On December 20, 2011, Annex D was updated with the following change:

Key Establishment Techniques
Added: Recommendation for Key Derivation through Extraction-then-Expansion,
Special Publication 800-56C

FIPS certificate totals for 2011 down 19%

The number of FIPS 140-2 certificates issued in 2011 was down 19% compared to 2010.  A total of 185 certificates were issued in 2011 (229 were issued in 2010).  Here are the totals by Lab for 2011:





December 12, 2011

Power-on self-test guidance


The CMVP intends to release new FIPS 140-2 Implementation Guidance clarifying the power-on self-test required for cryptographic algorithms whose outputs do not vary for a given set of inputs (e.g. RSA).

A Known Answer Test (KAT) will be required in the future for cryptographic modules that perform RSA sign and verify when the outputs of those operations are deterministic.

The Implementation Guidance will include a transition date.  After that transition date, new FIPS 140-2 validation submissions must implement a Known Answer Test (for a deterministic mode of RSA) as a power-on self-test.  A Pairwise Consistency Test will no longer be acceptable as a power-on self-test (for a deterministic mode of RSA).

The release date of the Implementation Guidance and the transition date are not yet available.