密码模块安全测评标准的演进:现状、困境与趋势  被引量:1

The Evolution of Security Requirements for Cryptographic Modules:the Status Quo,Dilemma and Future Trends

在线阅读下载全文

作  者:周永彬[1] 李建堂[1] 刘继业[1] 

机构地区:[1]中国科学院软件研究所信息安全国家重点实验室,北京100190

出  处:《成都信息工程学院学报》2011年第2期109-122,共14页Journal of Chengdu University of Information Technology

基  金:国家自然科学基金资助项目(61073178);北京市自然科学基金资助项目(4112064)

摘  要:联邦信息处理规范FIPS 140系美国国家标准技术研究所(NIST)制定并由美国联邦政府颁布的密码模块安全要求。FIPS 140-1与FIPS 140-2先后于1994年和2001年颁布执行。按照NIST每5年启动1次标准审查的既定方针,FIPS 140-2的审查暨FIPS 140-3的制定工作于2005年1月启动。但是,在先后公布FIPS 140-3草案与修订草案并面向全球征集到2000余条修订意见后,时至今日,FIPS 140-3标准仍未颁布,这一事实引人深思。通过对近20年来FIPS 140系列标准演变的分析,结合密码分析与应用技术的发展,探讨FIPS 140系列标准随着密码模块技术发展产生的结构性与技术性改进以及当前陷于困境的可能原因,展望可能的发展趋势。The publication series of FIPS 140 standards,formulated by National Institute of Standards and Technology(NIST) and issued by Federal Government of the United States,aim to specify the techniques and procedures related to the secure design,implementation,operation and disposal of a cryptographic module.FIPS 140-1 and FIPS 140-2 were issued in 1994 and 2001,respectively.According to the established policy that standards are reviewed every five years,the review of FIPS 140-2(and also the drafting of FIPS 140-3) was initiated in January, 2005.However,the final FIPS 140-3 is still not disclosed so far,even after two draft versions of FIPS 140-3 have been proclaimed and then more than 2,000 comments and feedbacks were gathered worldwide.This very fact is well worth pondering.In view of this,we discuss the evolution of FIPS 140 standards within the latest twenty years,investigate the possible reasons behind structural and technological changes,and forecast some future trends in this survey and position paper.

关 键 词:密码模块 标准 安全要求 安全等级 

分 类 号:P4[天文地球—大气科学及气象学]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象