What is PD CEN/TS 419221-3 - CSP key generation about?
The protection profile defines the security requirements for cryptographic modules used by trust service providers supporting electronic signing and sealing operations and authentication services. It includes optional support for protected backup of keys.
PD CEN/TS 419221 series is on protection profiles for TSP cryptographic modules. PD CEN/TS 419221-3 specifies a protection profile for the cryptographic module for certification service provider (CSP) key generation services.
PD CEN/TS 419221-3 contains the security problem definition, including the set of target of evaluation (TOE) assets to protect, the expected threats to those assets, the organizational security policies in place and the assumptions made on the TOE.
PD CEN/TS 419221-3 contains the security objectives for the TOE and the TOE operational environment, which address the threats, organizational security policies and assumptions considered. This section also includes a rationale of correspondence between the security objectives and the threats, organizational security policies and assumptions.
Who is PD CEN/TS 419221-3 - CSP key generation for?
PD CEN/TS 419221-3 on CSP key generation is useful for:
- Entities that use authentication for their business
- Software engineers/IT firms
- Trust services providers
- Certification service providers
- Certification authorities
Why should you use PD CEN/TS 419221-3 - CSP key generation?
The Cryptographic Module, which is the TOE, is used for the creation of subscriber private keys, and loading them into secure signature creation devices as part of a subscriber device provision service. Such keys are referred to in this protection profile as subscriber signature creation data. A cryptographic module for CSP key generation services is needed particularly to import such key into the secure signature creation devices.
This Protection Profile in PD CEN/TS 419221-3 defines the security requirements of a Cryptographic Module used by CSP as part of its trustworthy system to provide key generation services.
PD CEN/TS 419221-3 provides you with the security functional requirements and security assurance requirements that need to be satisfied by the TOE and developer. PD CEN/TS 419221-3 provides you with the rationale to explicitly demonstrate that the set of security functional requirements is complete with respect to the objectives.