You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<rationale>Mitigates the threat by ensuring secret and private key data is disposed of immediately after use to prevent unauthorized disclosure of keys.</rationale>
<rationale>Mitigates the threat by ensuring secret and private key data is disposed of immediately after use to prevent unauthorized disclosure of keys.</rationale>
<rationale>Mitigates the threat by ensuring secret and private key data is disposed of immediately after use to prevent unauthorized disclosure of keys.</rationale>
<h:p><h:b>FCS_CKM.6.2: </h:b>The TSF shall destroy cryptographic keys and keying material specified by FCS_CKM.6.1 in accordance with a specified cryptographic
<h:li>For plaintext keys in volatile storage, the destruction shall be executed by a [<h:b>selection: </h:b>
1142
-
<h:ul>
1143
-
<h:li>Single overwrite consisting of [<h:b>selection: </h:b>
1144
-
<h:ul>
1145
-
<h:li>a pseudo-random pattern using the TSF's RBG</h:li>
1146
-
<h:li>zeroes</h:li>
1147
-
<h:li>ones</h:li>
1148
-
<h:li>a new value of the key</h:li>
1149
-
<h:li>[<h:b>assignment: </h:b>a static or dynamic value that does not contain any CSP]</h:li>
1150
-
</h:ul>]</h:li>
1151
-
<h:li>Destruction of reference to the key directly followed by a request for garbage collection</h:li>
1152
-
</h:ul>]</h:li>
1153
-
<h:li>For plaintext keys in non-volatile storage, the destruction shall be executed by the invocation of an interface provided by the
1154
-
TSF that [<h:b>selection: </h:b>
1155
-
<h:ul>
1156
-
<h:li>Logically addresses the storage location of the key and performs a [<h:b>selection: </h:b>single, [<h:b>assignment: </h:b> number of passes]-pass] overwrite
1157
-
consisting of [<h:b>selection: </h:b>
1158
-
<h:ul>
1159
-
<h:li>a pseudo-random pattern using the TSF's RBG</h:li>
1160
-
<h:li>zeroes</h:li>
1161
-
<h:li>ones</h:li>
1162
-
<h:li>a new value of the key</h:li>
1163
-
<h:li>[<h:b>assignment: </h:b>a static or dynamic value that does not contain any CSP]</h:li>
1164
-
</h:ul>
1165
-
]</h:li>
1166
-
<h:li>Instructs a part of the TSF to destroy the abstraction that represents the key</h:li>
1167
-
</h:ul>]
1168
-
</h:li>
1169
-
</h:ul></h:i>] that meets the following: [<h:i>no standard</h:i>].
1170
-
</h:p>
1171
-
<h:p><h:b>Application Note: </h:b>This SFR is refined from its definition in the Base-PP through the inclusion of security critical parameters and clarifies when destruction
1172
-
is required; a STIP device includes persistent keys, including the embedded CA’s signing private key that should not be destroyed until they are no longer needed. Security
1173
-
critical parameters includes security related information (e.g., secret and private cryptographic keys, authentication data such as passwords and PINs) appearing in plaintext
1174
-
or otherwise unprotected form and whose disclosure or modification can compromise the security of a CA or the security of the information protected by the CA.</h:p></description>
1175
-
<!-- NDcPP is not in XML so no change can be modeled -->
1176
-
<no-change/>
1128
+
1177
1129
1178
-
</base-sfr-spec>
1179
1130
<base-sfr-spec cc-id="fcs_tlsc_ext.1" id="nd-mod-fcs-tlsc-ext-1" title="TLS Client Protocol without Mutual Authentication">
1180
1131
<consistency-rationale>Other than defining an additional selection-based trigger, there is no modification to this SFR.</consistency-rationale>
1181
1132
<description>This PP-Module does not modify this SFR as it is defined in the <h:a
@@ -1543,7 +1494,7 @@ expected to enforce.<h:p/>
1543
1494
<selectable>192 bits</selectable>
1544
1495
<selectable>256 bits</selectable>
1545
1496
</selectables> that meet the
1546
-
following: [<h:i>AES as specified in ISO 18033-3, CCM and CCM-8 as specified in NIST
1497
+
following: [<h:i>AES as specified in ISO 18033-3, AES as specified in FIPS PUB 197 CCM and CCM-8 as specified in NIST
1547
1498
SP 800-38C and <selectables>
1548
1499
<selectable>TDES as specified in NIST SP 800-67 Rev 2 and CBC mode
1549
1500
as specified in NIST SP 800-38A addendum</selectable>
0 commit comments