Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Technical issue in the TSS Assurance Activities for SFR FCS_CKM.1/SKG in HCD SD v1.0 #18

Open
ansukert opened this issue Oct 16, 2023 · 2 comments
Assignees
Labels
Priority +1 Priority 1 Issue SD Issue with the SD technical technical issue

Comments

@ansukert
Copy link
Contributor

An issue from Masatoshi Kawashima, Information Technology Security Center

HCD SD Version 1.0
Section 2.2.1. FCS_CKM.1/SKG Cryptographic key generation (Symmetric Keys)” of HCD SD, Section 2.2.1.1 TSS”
As last selection of FCS_CKM.1.1/SKG, one can select Section 6.1 or 6.3 of NIST SP 800-133 Rev.2. Section 6.1 of SP 800-133 describes symmetric keys that are directly generated from the output of an RBG, and Section 6.3 describes symmetric keys produced by combining keys and other data.

On the other hand, Section 2.2.1.1 of HCD SD says that the evaluator shall verify how the TOE obtains a symmetric key through direct generation from a random bit generator. This requirement is considered to be inadequate when SP 800-133 Rev.2 Section 6.3 is selected.

Proposed Resolution (if any):
The word “direct” should be deleted from Section 2.2.1.1 of HCD SD.

@ansukert ansukert added technical technical issue SD Issue with the SD labels Oct 16, 2023
@ansukert ansukert added the Priority +1 Priority 1 Issue label Oct 16, 2023
@ansukert ansukert removed their assignment Oct 16, 2023
@gcolunga
Copy link

gcolunga commented Jan 5, 2024

I have implemented the following fix:
2.2.1.1. TSS
The evaluator shall review the TSS to determine that it describes how the functionality described by FCS_RBG_EXT.1 is invoked and how the TOE obtains a symmetric key through direct generation from a random bit generator as specified in FCS_RBG_EXT.1 or by combining one or more keys and other data.

The fix is marked by the text in bold above.

The fix is available here:
HCD-iTC/HCD-iTC-Template@38fb9da

@gcolunga
Copy link

gcolunga commented Feb 9, 2024

This issue is addressed by the following TD:

  • HCD0006

The TD above is located at the following location:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Priority +1 Priority 1 Issue SD Issue with the SD technical technical issue
Projects
Status: Completed
Development

No branches or pull requests

2 participants