ISO/IEC 17825:2024
Information technology — Security techniques — Testing methods for the mitigation of non-invasive attack classes against cryptographic modules
Information technology — Security techniques — Testing methods for the mitigation of non-invasive attack classes against cryptographic modules
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 38
- Дата публикации:
- 19 января 2024 г.
- Издание:
- ISO/IEC IS 17825 edition 2 version 1
- ICS:
- 35.030
This document specifies the non-invasive attack mitigation test metrics for determining conformance to the requirements specified in ISO/IEC 19790:2012 for security levels 3 and 4. The test metrics are associated with the security functions addressed in ISO/IEC 19790:2012. Testing is conducted at the defined boundary of the cryptographic module and the inputs/outputs available at its defined boundary. This document is intended to be used in conjunction with ISO/IEC 24759:2017 to demonstrate conformance to ISO/IEC 19790:2012. NOTE ISO/IEC 24759:2017 specifies the test methods used by testing laboratories to assess whether the cryptographic module conforms to the requirements specified in ISO/IEC 19790:2012 and the test metrics specified in this document for each of the associated security functions addressed in ISO/IEC 19790:2012. The test approach employed in this document is an efficient “push-button” approach, i.e. the tests are technically sound, repeatable and have moderate costs.
Abstract
Overview
ISO/IEC 17825:2024 - "Information technology - Security techniques - Testing methods for the mitigation of non-invasive attack classes against cryptographic modules" - specifies test metrics and repeatable test methods to evaluate the resistance of cryptographic modules to non‑invasive attacks. Focused on security levels 3 and 4 of ISO/IEC 19790:2012, the second edition updates side‑channel and other non‑invasive test methods, and provides a pragmatic, cost‑moderate “push‑button” testing approach performed at the module’s defined boundary.
Key topics and requirements
- Non‑invasive attack classes: side‑channel analysis (timing, SPA/SEMA, DPA/DEMA), advanced side‑channel attacks on asymmetric algorithms, and other non‑intrusive leakage paths.
- Side‑channel analysis workflow: a core test flow and a structured resistance test framework that includes vendor information needs, leakage analysis steps, and test strategies.
- Test metrics and pass/fail criteria: normative pass/fail metrics are defined (see Annex A) for mapping test outcomes to the security functions in ISO/IEC 19790:2012.
- Measurement and quality: informative annexes describe requirements for measurement apparatus, quality criteria for setups, and guidance on when leakage is assessed as non‑measurable.
- Scope and limitations: testing is closed‑box (external inputs/outputs only), aimed at producing repeatable, technically sound results. The standard notes that closed‑box testing provides a “controlled” level of reasonable confidence but does not guarantee coverage of all possible attacks.
- Updated content: this edition reflects recent research trends, introduces an explanatory introduction on expected assurance levels, and improves requirement traceability.
Applications and who should use it
ISO/IEC 17825:2024 is intended for:
- Testing laboratories performing conformance testing against ISO/IEC 19790 (used together with ISO/IEC 24759:2017).
- Security evaluators and certification bodies assessing cryptographic modules at security levels 3 and 4.
- Device and firmware vendors designing modules to withstand non‑invasive attacks; the standard clarifies required vendor information to support testing.
- Security architects and engineers building threat models and deciding appropriate countermeasures against side‑channel and timing attacks. Practical applications include evaluation of hardware security modules (HSMs), secure elements, smartcards, and other cryptographic modules where physical or side‑channel leakage is a concern.
Related standards
- ISO/IEC 19790:2012 - security requirements for cryptographic modules (conformance target).
- ISO/IEC 24759:2017 - test methods used by labs to assess conformance to ISO/IEC 19790 and the test metrics in ISO/IEC 17825.
- Relevant measurement and calibration guidance referenced by the standard (see informative annexes).
Keywords: ISO/IEC 17825:2024, non‑invasive attack testing, cryptographic module testing, side‑channel analysis, DPA, SPA, timing attacks, ISO/IEC 19790, ISO/IEC 24759.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 17825:2024
Похожие стандарты
Стандарты, упомянутые в описании