Pattern Based FIPS 140-2 Cryptographic Module Validation

No ratings

Presented at ICMC 2013 by

A significant subset of modules validated for compliance to the FIPS 140-2 standard conform to a pattern of module type, services, keys and other common information. The concept is conceptually similar to re-validations of module variations by the same vendor, a process known to be more efficient and less time consuming for the CMVP, the vendor and lab. A process is described to streamline FIPS 140-2 validations for modules that conform to a well-established pattern. The proposed process includes a laboratory or laboratory group proposal for a baseline pattern to CMVP; review of a Security Policy template; submission of baseline Security Policy and report; submission of reports and associated documentation following an accepted baseline, including a summary of differences from the baseline. Issues of pattern maintenance and pattern variation management are presented. A proposed process change model to incorporate pattern based validation into CMVP methods is presented. The status of pilot report submissions following this model is presented, along with a summary of issues encountered by pilot projects. An analysis of the process outcome at the time of publication time is presented along with recommendations for the FIPS 140-2 validation community (end users, CMVP, vendors and laboratories.)