{"id":4915,"date":"2021-10-18T14:00:19","date_gmt":"2021-10-18T06:00:19","guid":{"rendered":"https:\/\/www.progreso.com.sg\/newsite\/?post_type=all_news&#038;p=4915"},"modified":"2021-10-18T14:00:20","modified_gmt":"2021-10-18T06:00:20","slug":"hsm-fips-2","status":"publish","type":"all_news","link":"https:\/\/www.progreso.com.sg\/newsite\/all_news\/hsm-fips-2\/","title":{"rendered":"Introduction to hardware security modules (HSM): \u201cFIPS 140-2 tested and certified\u201d"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"4915\" class=\"elementor elementor-4915\" data-elementor-settings=\"[]\">\n\t\t\t<div class=\"elementor-inner\">\n\t\t\t\t<div class=\"elementor-section-wrap\">\n\t\t\t\t\t\t\t<section class=\"elementor-element elementor-element-70b5204 elementor-section-boxed elementor-section-height-default elementor-section-height-default elementor-section elementor-top-section\" data-id=\"70b5204\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t<div class=\"elementor-row\">\n\t\t\t\t<div class=\"elementor-element elementor-element-0002e48 elementor-column elementor-col-100 elementor-top-column\" data-id=\"0002e48\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-column-wrap  elementor-element-populated\">\n\t\t\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t<div class=\"elementor-element elementor-element-11d8acc elementor-widget elementor-widget-text-editor\" data-id=\"11d8acc\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><h2>What is FIPS 140-2?<\/h2><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-43e014c elementor-widget elementor-widget-text-editor\" data-id=\"43e014c\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">The requirements specified in the Federal Information Processing Standard (FIPS) PUB 140- 2 outline a total of 11 areas of design and implementation of products in applied cryptography. These areas include:<\/span><br \/><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">\u2022 cryptographic module specification<\/span><br \/><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">\u2022 roles, services, and authentication<\/span><br \/><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">\u2022 ports and interfaces<\/span><br \/><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">\u2022 operational environment<\/span><br \/><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">\u2022 physical security<\/span><br \/><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">\u2022 EMI \/ EMC<\/span><br \/><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">\u2022 key management<\/span><br \/><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">\u2022 design assurance<\/span><br \/><span style=\"font-family: Lato, sans-serif; font-size: 16px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400;\">To boot, every certified cryptographic module is categorized into 4 levels of security:<\/span><\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-41000ef elementor-widget elementor-widget-image\" data-id=\"41000ef\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image\">\n\t\t\t\t\t\t\t\t\t\t<img width=\"768\" height=\"640\" src=\"https:\/\/www.progreso.com.sg\/newsite\/wp-content\/uploads\/2021\/10\/FIPS-140-2-levels-explained.png.jpeg\" class=\"attachment-medium_large size-medium_large\" alt=\"\" loading=\"lazy\" srcset=\"https:\/\/www.progreso.com.sg\/newsite\/wp-content\/uploads\/2021\/10\/FIPS-140-2-levels-explained.png.jpeg 768w, https:\/\/www.progreso.com.sg\/newsite\/wp-content\/uploads\/2021\/10\/FIPS-140-2-levels-explained.png-300x250.jpeg 300w, https:\/\/www.progreso.com.sg\/newsite\/wp-content\/uploads\/2021\/10\/FIPS-140-2-levels-explained.png-600x500.jpeg 600w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-948f318 elementor-widget elementor-widget-text-editor\" data-id=\"948f318\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p>Based on security requirements in the above areas, FIPS 140-2 defines 4 levels of security:<br \/>\u2022 Level 1 \u2013 The lowest security that can be applied to a cryptographic module. The sole basis of its security is the fact that it uses a cryptographic function.<br \/>\u2022 Level 2 \u2013 These modules have temper evidence as an additional security feature. This cryptographic device will allow authorized operators to open the seals and access the keys, but only after successfully authenticating.<br \/>\u2022 Level 3 \u2013 This level of security is measured by tamper detection and response, enhanced protection of private key pairs, and identity-based authentication.<br \/>\u2022 Level 4 \u2013 This is the highest level of security. To be certified a level 4 device, the module must be tamper resistant and provide environmental (voltage or temperature) failure protection.<\/p><p><span style=\"font-size: 16px; background-color: transparent;\">An example of a level 4 certified HSM is Utimaco\u2019s Hardware security modules. Every Utimaco HSMs has been laboratory-tested and certified against FIPS 140-2 standards to help you comply with the standards you need to meet.<\/span><\/p><p><strong>Reasons to use a FIPS-certified HSM<\/strong><br \/>\u2022 To bar unauthorized users from accessing sensitive information<br \/>\u2022 To protect from any unauthorized activity in private systems<br \/>\u2022 To prevent changes from being made without your knowledge or permission<br \/>\u2022 To detect errors immediately, before sensitive information has been damaged or compromised<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f8f86cc elementor-widget elementor-widget-text-editor\" data-id=\"f8f86cc\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><h2>Why is FIPS Compliance important?<\/h2><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-02187a4 elementor-widget elementor-widget-text-editor\" data-id=\"02187a4\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p>The FIPS 140-2 standard is applicable to all Federal departments and agencies operate or are operated for them under contract and use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems (including voice systems). Additionally, FIPS compliance is required in any regulated industry that collects, stores, transfers, shares or disseminates sensitive information. This includes products in regulated industries such as Banking, Health-care institutions, and National Defense. If you want to sell into these industries and cryptography is a central component of your product, you\u2019ll need to prove FIPS compliance. To certify a cryptographic module such as an HSM, Private vendors must first undergo a series of FIPS testing by an independent, accredited Cryptographic and Security Testing (CST) laboratory, such as the National Voluntary Lab Accreditation Program. First, the CST laboratory uses the Derived Test Requirements (DTR) and Implementation Guidance (IG) to test cryptographic modules. Then they must validate the test results before issuing a certificate.\u00a0<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d4765b1 elementor-widget elementor-widget-text-editor\" data-id=\"d4765b1\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><h2>What are the requirements of FIPS 140-2?<\/h2><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8b64975 elementor-widget elementor-widget-text-editor\" data-id=\"8b64975\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><p>An FIPS 140-2 compliant cryptographic module must satisfy the following:<\/p><ul><li>Cryptographic Module Ports &amp; Interfaces<\/li><li>Roles, Services, &amp; Authentication<\/li><li>Finite State Model<\/li><li>Physical Security<ul><li>General<\/li><li>Single Chip Crypto Modules<\/li><li>Multi Chip Crypto Modules<\/li><li>Multi Chip Standalone Crypto Modules<\/li><li>Environmental Failure Protection\/Testing<\/li><li>Operational Environment<ul><li>Operating System Requirements<\/li><li>Crypto Key Management<\/li><li>Random Number Generators (RNGs)<\/li><li>Key Generation<\/li><li>Key Establishment<\/li><li>Key Entry &amp; Output<\/li><li>Key Storage<\/li><li>Key Zeroization<\/li><li>EMI\/EMC Compatibility<\/li><li>Self-Tests<\/li><li>Design Assurance<\/li><li>Configuration Management<\/li><li>Mitigation of other Attacks<\/li><\/ul><\/li><\/ul><\/li><\/ul><p>The NIST specifies certain crypto algorithms as FIPS 140-2 compliant, and also identifies which algorithms can be used for symmetric, asymmetric, message authentication, and hashing cryptographic functions. The following is a list of approved cryptographic algorithms:<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-14bd54a elementor-widget elementor-widget-text-editor\" data-id=\"14bd54a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><table class=\"MsoNormalTable aligncenter\" style=\"background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial;\" border=\"0\" cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><b><span style=\"font-size: 11.5pt; font-family: Roboto;\">Symmetric<\/span><\/b><b><\/b><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><b><span style=\"font-size: 11.5pt; font-family: Roboto;\">Asymmetric<\/span><\/b><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><b><span style=\"font-size: 11.5pt; font-family: Roboto;\">Message<br \/>Authentication<\/span><\/b><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><b><span style=\"font-size: 11.5pt; font-family: Roboto;\">Hashing<\/span><\/b><b><\/b><\/p><\/td><\/tr><tr><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">AES<\/span><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">DSS<\/span><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">TDES<\/span><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">SHA1<\/span><\/p><\/td><\/tr><tr><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">TDES<\/span><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">SHS<\/span><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">AES<\/span><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">SHA-256<\/span><\/p><\/td><\/tr><tr><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">EES<\/span><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">RNG<\/span><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">HMAC<\/span><\/p><\/td><td style=\"padding: .75pt .75pt .75pt .75pt;\"><p class=\"MsoNormal\" style=\"margin-bottom: 0cm; line-height: normal;\"><span style=\"font-size: 11.5pt; font-family: Roboto;\">SHA-512<\/span><\/p><\/td><\/tr><\/tbody><\/table><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4e97787 elementor-widget elementor-widget-text-editor\" data-id=\"4e97787\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-text-editor elementor-clearfix\"><ul><li>AES= Advanced Encryption Standard<\/li><li>TDES= Triple Data Encryption Standard<\/li><li>EES= Escrowed Encryption Standard<\/li><li>DSS= Digital Signature Standard<\/li><li>SHS= Secure Hash Standard<\/li><li>RNG= Random Number Generators<\/li><li>HMAC= Hash Message Authentication Code<\/li><\/ul><p>The FIPS 140-2 standard is applicable to all Federal departments and any regulated industry that collects, stores, transfers, shares or disseminates sensitive information. More importantly, a cryptographic device with high security is necessary to maintain the privacy and integrity of the sensitive information protected by the module. Now that you have a general idea on the importance of FIPS 140-2 and how to comply, take some time to reflect on what you\u2019ve learned and written down any ideas that come to mind. Then when you\u2019re ready, let\u2019s continue on to Part 2 of the Comprehensive Guide to Hardware Security Modules.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>What is FIPS 140-2? The requirements specified in the Federal Information Processing Standard (FIPS) PUB 140- 2 outline a total of 11 areas of design and implementation of products in applied cryptography. These areas include:\u2022 cryptographic module specification\u2022 roles, services, and authentication\u2022 ports and interfaces\u2022 operational environment\u2022 physical security\u2022 EMI \/ EMC\u2022 key management\u2022 design [&hellip;]<\/p>\n","protected":false},"featured_media":0,"template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news\/4915"}],"collection":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news"}],"about":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/types\/all_news"}],"version-history":[{"count":6,"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news\/4915\/revisions"}],"predecessor-version":[{"id":4923,"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/all_news\/4915\/revisions\/4923"}],"wp:attachment":[{"href":"https:\/\/www.progreso.com.sg\/newsite\/wp-json\/wp\/v2\/media?parent=4915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}