Record Details

Catalog Search

Search The Catalog



A comparison of the security requirements for cryptographic modules in FIPS 140-1 and FIPS 140-2 [electronic resource] / Ray Snouffer, Annabelle Lee, and Arch Oldehoeft.

Snouffer, Ray, (author). Lee, Annabelle. (Added Author). Oldehoeft, Arch. (Added Author).

Summary:

Federal agencies, industry, and the public now rely on cryptography to protect information and communications used in critical infrastructures, electronic commerce, and other application areas. Cryptographic modules are implemented in these products and systems to provide cryptographic services such as confidentiality, integrity, non-repudiation and identification and authentication. A documented methodology for conformance testing through a defined set of security requirements in FIPS 140-1 and FIPS 140-2 and other cryptographic standards is specified in the Derived Test Requirements. FIPS 140-1 is one of NIST's most successful standards and forms the very foundation of the Cryptographic Module Validation Program. FIPS 140-2 addresses lessons learned from questions and comments and reflects changes in technology. The standard was strengthened, but not changed in focus or emphasis. Also, the standard was minimally restructured to: standardize the language and terminology to add clarity and consistency; remove redundant and extraneous information to make the standard more concise; and revise or remove vague requirements. Finally, a new section was added detailing new types of attacks on cryptographic modules that currently do not have specific testing available. This differences paper summarizes the changes from FIPS 140-1 to FIPS 140-2 and documents the detailed requirements.

Electronic resources

Record details

  • Physical Description: 27 pages : digital, PDF file
  • Publisher: Gaithersburg, MD : U.S. Dept. of Commerce, Technology Administration, National Institute of Standards and Technology, [2001]

Content descriptions

General Note:
"June 2001."
Title from title screen (viewed on July 24, 2006).
Bibliography, etc. Note:
Includes bibliographical references.
System Details Note:
Mode of access: Internet from NIST web site. Address as of 7/24/06: http://csrc.nist.gov/publications/nistpubs/800-29/sp800-29.pdf; current access available via PURL.
Subject:
Data encryption (Computer science) > United States.
Public records > Access control > United States.
Computer security > Standards > United States.
United States > Politics and government > Data processing.
Available in another form: A comparison of the security requirements for cryptographic modules in FIPS 140-1 and FIPS 140-2

Accessibility Features

LDR 04196cam a2200493 i 4500
00115713573
003CARDINAL
00520250725114306.0
006m o d f
007cr an|||||||||
008060725s2001 mdu obu f000 0 eng d
019 . ‡a927737532 ‡a979938230 ‡a1311349718
035 . ‡a(OCoLC)70689015
037 . ‡agovdocs.govdocse
040 . ‡aGPO ‡beng ‡erda ‡cGPO ‡dSYB ‡dNBS ‡dLWA ‡dUOK ‡dINT ‡dCOM
043 . ‡an-us---
050 4. ‡aQC100 ‡b.U57 no.800-29 2001
074 . ‡a0247 (online)
08214. ‡a13.10:800-29
0860 . ‡aC 13.10:800-29
1001 . ‡aSnouffer, Ray, ‡eauthor
24512. ‡aA comparison of the security requirements for cryptographic modules in FIPS 140-1 and FIPS 140-2 ‡h[electronic resource] / ‡cRay Snouffer, Annabelle Lee, and Arch Oldehoeft.
264 1. ‡aGaithersburg, MD : ‡bU.S. Dept. of Commerce, Technology Administration, National Institute of Standards and Technology, ‡c[2001]
300 . ‡a27 pages : ‡bdigital, PDF file
336 . ‡atext ‡btxt ‡2rdacontent
337 . ‡acomputer ‡bc ‡2rdamedia
338 . ‡aonline resource ‡bcr ‡2rdacarrier
347 . ‡adata file ‡2rda
4901 . ‡aNIST special publication ; ‡v800-29
500 . ‡a"June 2001."
500 . ‡aTitle from title screen (viewed on July 24, 2006).
504 . ‡aIncludes bibliographical references.
5203 . ‡aFederal agencies, industry, and the public now rely on cryptography to protect information and communications used in critical infrastructures, electronic commerce, and other application areas. Cryptographic modules are implemented in these products and systems to provide cryptographic services such as confidentiality, integrity, non-repudiation and identification and authentication. A documented methodology for conformance testing through a defined set of security requirements in FIPS 140-1 and FIPS 140-2 and other cryptographic standards is specified in the Derived Test Requirements. FIPS 140-1 is one of NIST's most successful standards and forms the very foundation of the Cryptographic Module Validation Program. FIPS 140-2 addresses lessons learned from questions and comments and reflects changes in technology. The standard was strengthened, but not changed in focus or emphasis. Also, the standard was minimally restructured to: standardize the language and terminology to add clarity and consistency; remove redundant and extraneous information to make the standard more concise; and revise or remove vague requirements. Finally, a new section was added detailing new types of attacks on cryptographic modules that currently do not have specific testing available. This differences paper summarizes the changes from FIPS 140-1 to FIPS 140-2 and documents the detailed requirements.
538 . ‡aMode of access: Internet from NIST web site. Address as of 7/24/06: http://csrc.nist.gov/publications/nistpubs/800-29/sp800-29.pdf; current access available via PURL.
650 0. ‡aData encryption (Computer science) ‡zUnited States.
650 0. ‡aPublic records ‡xAccess control ‡zUnited States. ‡0(CARDINAL)307347
650 0. ‡aComputer security ‡xStandards ‡zUnited States.
651 0. ‡aUnited States ‡xPolitics and government ‡xData processing.
7001 . ‡aLee, Annabelle.
7001 . ‡aOldehoeft, Arch.
7760 . ‡aSnouffer, Ray. ‡tA comparison of the security requirements for cryptographic modules in FIPS 140-1 and FIPS 140-2 ‡hi, 27 p. ‡w(OCoLC)47522313
830 0. ‡aNIST special publication ; ‡v800-29. ‡0(CARDINAL)199093
85640. ‡uhttps://purl.fdlp.gov/GPO/LPS72074 ‡7govdoc ‡9BHM ‡9BLADEN ‡9BRASWELL ‡9BROWN ‡9BRUNSWICK ‡9BUNCOMBE ‡9BURKE ‡9CALDWELL ‡9CARTERET ‡9CASWELL ‡9CLEVELAND ‡9DAVIE ‡9DEQ_ELC ‡9DUPLIN ‡9FARMVILLE ‡9FORSYTH ‡9FRANKLIN ‡9GHL ‡9GOV_MANSION ‡9GRANVILLE ‡9HARNETT ‡9HAYWOOD ‡9HENDERSON ‡9HIGH_POINT ‡9IREDELL ‡9JOHNSTON ‡9LEE ‡9MADISON ‡9MAUNEY ‡9NANTAHALA ‡9NC_ARCHIVES ‡9NC_ART ‡9NC_DOL ‡9NC_DOT ‡9NC_LEG ‡9NC_NATSCI ‡9NC_SHS ‡9NORTHWESTERN ‡9ONSLOW ‡9PERRY ‡9PERSON ‡9POLK ‡9ROBESON ‡9ROCKINGHAM ‡9RUTHERFORD ‡9SAMPSON ‡9SANDHILL ‡9SCOTLAND ‡9STANLY ‡9TRV ‡9WARREN ‡9YANCEY ‡yClick for online content. ‡9CAMDEN ‡9CURRITUCK ‡9DARE ‡9JACKSON ‡9PASQUOTANK
901 . ‡a15713573 ‡bgovdoc-script 777684527997d3cf85f358254a9200ef2ce6d85a 99e11119071f4aef715be51e4537909177b7076d ‡c15713573 ‡tbiblio ‡selectronic