IWG 0.00% 4.0¢ iwebgate limited

I'm bored and for some reason this NIST stuff is interesting....

ANNOUNCEMENT SPONSORED BY PLUS500
ANNOUNCEMENT SPONSORED BY PLUS500
CFD TRADING PLATFORM
CFD Service. Your Capital is at risk
CFD TRADING PLATFORM CFD Service. Your Capital is at risk
ANNOUNCEMENT SPONSORED BY PLUS500
CFD TRADING PLATFORM CFD Service. Your Capital is at risk
  1. 107 Posts.
    I'm bored and for some reason this NIST stuff is interesting.   The question on this website was was from a company that built a cryptographic module for their product that used standard encryption algorithms. They asked wether it meant that they were NIST compliant because they used industry standards.  Here was the response

    "f you are using an AES library that has not undergone the FIPS validation process, then you are not FIPS compliant (or, at least, your use of AES is not).

    FIPS compliant means more than "we use algorithms that FIPS likes", it means "having passed the FIPS certification process"; that is how NIST defines it.

    Sorry, but NIST is quite strict about this; if you haven't undergone the full testing, then NIST is concerned that you haven't implemented AES correctly; there may be subtle bugs that affect the security. And, since NIST makes up the rules for what's "FIPS compliant", well, there's no point in arguing about its likelihood.

    In addition, FIPS talks more than what algorithms you use; it also talks about health tests and key zeroization and other such things; the FIPS certification process checks all that as well.

    If you need to be FIPS compliant, then your choices are:

    • Use a FIPS-certified library to perform all the FIPS-approved crypto operations

    • Go through the FIPS-certification process for your application (or, at least, the crypto pieces of your application).
    The FIPS certification process is surprisingly complicated; I'd advise you to use a FIPS-certified library
 
watchlist Created with Sketch. Add IWG (ASX) to my watchlist

Currently unlisted public company.

arrow-down-2 Created with Sketch. arrow-down-2 Created with Sketch.