<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ECDSA Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/tag/ecdsa/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/tag/ecdsa/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Tue, 28 Feb 2023 19:08:30 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>ECDSA Archives - Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/tag/ecdsa/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>FIPS 186-5 &#038; Its Impact on FIPS 140-3</title>
		<link>https://www.corsec.com/fips-186-5/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Tue, 28 Feb 2023 19:08:30 +0000</pubDate>
				<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CAVP]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[ECDSA]]></category>
		<category><![CDATA[EdDSA]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[FIPS 186]]></category>
		<category><![CDATA[FIPS 186-1]]></category>
		<category><![CDATA[FIPS 186-2]]></category>
		<category><![CDATA[FIPS 186-3]]></category>
		<category><![CDATA[FIPS 186-4]]></category>
		<category><![CDATA[FIPS 186-5]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[RSA]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=19709</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/fips-186-5/">FIPS 186-5 &#038; Its Impact on FIPS 140-3</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>In 1994 the National Institute of Standards and Technology (NIST) and the National Security Agency (NSA) released a collaborative standard to specify a suite of algorithms that could be used to generate a digital signature.</p>
<p>A digital signature is defined as a tool to detect unauthorized modifications to data and to authenticate the identity of the signatory. In addition, the recipient of signed data can use a digital signature as evidence in demonstrating to a third party that the signature was, in fact, generated by the claimed signatory.</p>
<p>The new NIST and NSA standard was to be built on the previously proposed NSA-designed Digital Signature Algorithm (DSA), a public-key cryptosystem. The result was the release of the Federal Information Processing Standard 186, otherwise referred to as FIPS 186. Since that time, FIPS 186 has gone through many iterations, changing the approved algorithms, and adding requirements. The following is a brief history of the versioning and changes, including the recent release in February of 2023:</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p style="padding-left: 40px;"><strong>1994: </strong>Release of FIPS 186<br />
<strong>1996</strong>: Change to FIPS 186 for precomputing<br />
<strong>1998</strong>: Release of FIPS 186-1, approves the use of RSA<br />
<strong>2000</strong>: Release of FIPS 186-2, approves the use of ECDSA and elliptical curves associated with ECDSA<br />
<strong>2009</strong>: Release of FIPS 186-3:</p>
<ul>
<li style="list-style-type: none;">
<ul>
<li>Increases the key sizes for DSA</li>
<li>Provides additional requirements for the use of RSA and ECDSA</li>
<li>Allows the use of the RSA algorithm specified in Public Key Cryptography Standard (PKCS) #1</li>
<li>Includes requirements for obtaining the assurances necessary for valid digital signatures</li>
<li>Replaces the random number generators specified in previous versions of the FIPS with a reference to NIST Special Publication (SP) 800-90 (Recommendation for Random Number Generation Using Deterministic Random Bit Generators)</li>
</ul>
</li>
</ul>
<p style="padding-left: 40px;"><strong>2013: </strong>Release of FIPS 186-4:</p>
<ul>
<li style="list-style-type: none;">
<ul>
<li>Reduces restrictions on the use of random number generators and the retention and use of prime number generation seeds</li>
<li>Aligns the specification for the use of a random salt value in the RSASSA-PSS digital signature scheme with PKCS #1.</li>
</ul>
</li>
</ul>
<p style="padding-left: 40px;"><strong>2023</strong>:  Release of FIPS 186-5 (see below for the changes)</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5><strong>What is Significant About the Latest Release?</strong></h5>
<p>NIST’s Visiting Committee on Advanced Technology (VCAT), which conducts reviews of NIST&#8217;s cryptographic standards program, recently recommended that NIST “generate a new set of elliptic curves for use with ECDSA in the form of FIPS 186”. This recommendation led NIST to change the standard to specify three techniques for the generation and verification of digital signatures that can be used for the protection of data: the Rivest-Shamir-Adleman (RSA) Algorithm, the Elliptic Curve Digital Signature Algorithm (ECDSA), and the Edwards Curve Digital Signature Algorithm (EdDSA).</p>
<p>Notably, FIPS 186-5 removes DSA as an approved digital signature algorithm “due to a lack of use by industry and based on academic analyses that observed that implementations of DSA may be vulnerable to attacks if domain parameters are not properly generated. DSA is retained only for the purposes of verifying existing signatures.”</p>
<p>To facilitate a transition to the new standard, FIPS 186-4 will remain in effect alongside FIPS 186-5 for a period of one year. During the transition period (02/03/2023 &#8211; 02/03/2024) vendors may elect to comply with FIPS 186-4 or FIPS 186-5. After the one-year transition period vendors must comply with the new FIPS 186-5 standards.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5><strong>The Correlation to FIPS 140-3 &amp; The Impact to Vendors</strong></h5>
<p>In order to achieve a FIPS 140-3 validation vendors must comply with FIPS 186 if using digital signatures in their cryptographic module(s).</p>
<p>During the one-year transition period, vendors may elect to conform to either FIPS 186-4 or FIPS 186-5 for FIPS 140-3 validations. The Cryptographic Module Validation Program (CMVP) will adopt FIPS 186-5 for Cryptographic Algorithm Validation Program (CAVP) testing and is already offering production-level testing for the new FIPS 186-5 standard. Additionally, NIST SP 800-131A and the CMVP will provide transition guidance concerning the use of DSA and the binary elliptic curves.</p>
<p>The FIPS 186-5 transition is a “soft” transition and will not result in modules conforming to FIPS 186-4 being moved to the CMVP <a href="mailto:https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search?SearchMode=Advanced&amp;CertificateStatus=Historical&amp;ValidationYear=0">Historical List</a>. However, all FIPS 140-3 submissions conforming to FIPS 186-4 must be submitted to the CMVP no later than 12 months after the publication of FIPS 186-5 (02/03/2024). Modules conforming to the FIPS 186-4 standard and submitted prior to 02/03/2024 <u>will</u> remain valid until their sunset date. Modules that modify their sunset date (resubmission of validated module for modifications or updates) and that were originally submitted with FIPS 186-4 will need to conform to FIPS 186-5 if being resubmitted after a certain date. This date has yet to be determined by CMVP.</p>
<p>The CMVP is still working to release the following: transition guidance, implementation guidance, and updates to the NIST special publication which defines CMVP approved security functions. The implementation guidance for FIPS 186-5 is planned to be sent out for a four-week review period by the end of March 2023.</p>
<p>After the transition date, no modules conforming to the FIPS 186-4 standard can be submitted. To avoid having to retest and conform to FIPS 186-5 later if modifications are made, it would be best to proceed with conforming to FIPS 186-5 from the project’s start. FIPS 186-5 testing was made available on the CAVP production server on 02/03/2023*.</p>
<p style="padding-left: 40px;"><strong>*Note:</strong> X25519 and X448 curves are not currently approved key agreement schemes, therefore no testing will be provided by CAVP at this time.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_grey wpb_content_element  wpb_content_element" ><span class="vc_sep_holder vc_sep_holder_l"><span class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span class="vc_sep_line"></span></span>
</div>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper"><strong>About Corsec Security, Inc.</strong></h5>
</div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p>For two decades Corsec<strong> </strong>has assisted companies through the IT security certification process for <span style="color: #008000;"><strong><a style="color: #008000;" href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a> / <span style="color: #008000;"><a style="color: #008000;" href="https://www.corsec.com/fips-140-3/">FIPS 140-3</a></span></strong>,</span> <span style="color: #ff6600;"><a style="color: #ff6600;" href="https://www.corsec.com/common-criteria/"><strong>Common Criteria</strong></a></span> (CC), <strong><span style="color: #872b2b;"><a style="color: #872b2b;" href="https://www.corsec.com/csfc/">CSfC</a></span></strong>, and the <a href="https://www.corsec.com/dodin-apl/"><strong>DoD’s APL</strong></a>. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations. Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.</p>
</div>
</div>

		</div>
	</div>
<div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><a href="https://ww3.corsec.com/linkedin"><img decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://www.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" /></a>     <a href="https://ww3.corsec.com/twitter"><img decoding="async" class="alignnone" title="https://ww3.corsec.com/twitter" src="https://www.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Twitter.png 128w, https://www.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" /></a>    <a href="https://ww3.corsec.com/facebook"><img decoding="async" class="alignnone" src="https://www.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://www.corsec.com/wp-content/uploads/Facebook.png 128w, https://www.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.corsec.com/company/contact-us/">Press Contact:</a></strong></h5>
<p><span style="color: #3366ff;"><a style="color: #3366ff;" href="https://www.linkedin.com/in/jake-r-nelson/">Jake Nelson</a></span><br />
Corsec Director of Marketing<br />
jnelson@corsec.com</p>

		</div>
	</div>
</div></div></div></div></div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/fips-186-5/">FIPS 186-5 &#038; Its Impact on FIPS 140-3</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
