What is ISO/IEC 17825 - Testing methods for the mitigation of non-invasive attack classes against cryptographic modules about?
ISO/IEC 17825 specifies the non-invasive attack mitigation test metrics for determining conformance to the requirements specified in ISO/IEC 19790 for Security Levels 3 and 4. The test metrics are associated with the security functions specified in ISO/IEC 19790. Testing will be conducted at the defined boundary of the cryptographic module and I/O available at its defined boundary.
The test methods used by testing laboratories to test whether the cryptographic module conforms to the requirements specified in ISO/IEC 19790 and the test metrics specified in ISO/IEC 17825 for each of the associated security functions specified in ISO/IEC 19790 are specified in ISO/IEC 24759.
Who is ISO/IEC 17825 - Testing methods for the mitigation of non-invasive attack classes against cryptographic modules for?
ISO/IEC 17825 on Testing methods for the mitigation of non-invasive attack classes against cryptographic modules is useful for:
- Testing laboratories
- Information technology industry
- Organizations dealing with cryptographic modules
- Risk mitigation departments
Why should you use ISO/IEC 17825 - Testing methods for the mitigation of non-invasive attack classes against cryptographic modules?
The non-invasive attacks use side-channels (information gained from the physical implementation of a cryptosystem) emitted by the IUT such as:
- Its power consumption
- Its electromagnetic emissions
- Its computation time
The goal of non-invasive attack testing is to assess whether a cryptographic module utilizing non-invasive attack mitigation techniques can provide resistance to attacks at the desired security level.
The test approach employed in ISO/IEC 17825 is an efficient “push-button” approach: the tests are technically sound, repeatable and have moderate costs.