IT Security techniques. Test tool requirements and test tool calibration methods for use in testing non-invasive attack mitigation techniques in cryptographic modules - Test tools and techniques

IT Security techniques. Test tool requirements and test tool calibration methods for use in testing non-invasive attack mitigation techniques in cryptographic modules - Test tools and techniques

Regular price
£232.00
Sale price
£232.00
Regular price
£116.00
Sold out
Unit price
per 

What is ISO/IEC 20085-1 Testing non-invasive attack mitigation techniques in cryptographic modules about?  

ISO/IEC 20085-1 is the first part of the ISO/IEC 20085 series of standards that provides specifications for non-invasive attack test tools and provides information about how to operate such tools. The purpose of the test tools is the collection of signals (i.e. side-channel leakage) and their analysis as a non-invasive attack on a cryptographic module implementation under test (IUT). 

Who is ISO/IEC 20085-1 Testing non-invasive attack mitigation techniques in cryptographic modules for? 

ISO/IEC 20085-1 on cryptographic modules is useful for: 

  • Software developer 
  • Quality control personnel 

Why should you use ISO/IEC 20085-1 Testing non-invasive attack mitigation techniques in cryptographic modules 

Cryptographic modules provide cryptographic services and protect critical security parameters (CSPs). Protection of CSPs can either be logical, physical, or both. However, information such as knowledge of CSPs can leak out of the cryptographic module when manipulated if the module is not designed to mitigate such leakage.  

Without mitigation, a malicious attacker can record available side-channel leakage. This leakage is a physical quantity related to the CSPs and can be analysed in a manner to extract knowledge of those parameters. Such analysis is passive, in that it simply collects the side-channel leakage utilizing measurement apparatus which is freely available. Notice that the measurement tool can be adaptively controlled. This kind of extraction and analysis is referred to as non-invasive. Techniques that allow the extraction of CSPs out of this non-invasive leakage are termed an “attack” on the module. Side-channel non-invasive test tools can be automated to collect such leakage.  ISO/IEC 20085-1 focuses on the measurement and analysis of side-channel information.