ISO/IEC 20085-2:2020
IT Security techniques — Test tool requirements and test tool calibration methods for use in testing non-invasive attack mitigation techniques in cryptographic modules — Part 2: Test calibration methods and apparatus
IT Security techniques — Test tool requirements and test tool calibration methods for use in testing non-invasive attack mitigation techniques in cryptographic modules — Part 2: Test calibration methods and apparatus
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 17
- Дата публикации:
- 5 марта 2020 г.
- Издание:
- ISO/IEC IS 20085 edition 1 version 1
- ICS:
- 35.030
This document specifies the test calibration methods and apparatus used when calibrating test tools for cryptographic modules under ISO/IEC 19790 and ISO/IEC 24759 against the test metrics defined in ISO/IEC 17825 for mitigation of non-invasive attack classes.
Abstract
Overview
ISO/IEC 20085-2:2020 - "IT Security techniques - Test tool requirements and test tool calibration methods ... Part 2: Test calibration methods and apparatus" specifies how to calibrate non‑invasive attack test tools used on cryptographic modules. The standard defines calibration methods and the required apparatus (including a reference artefact) so that different measurement and analysis tools produce comparable, reproducible results against the pass/fail test metrics in ISO/IEC 17825. Key goals are traceability, repeatability and reliable determination of whether side‑channel leakage endangers critical security parameters.
Key topics and requirements
- Scope and purpose
- Calibration of test tools used for side‑channel (power, electromagnetic, timing) evaluation of cryptographic modules against ISO/IEC 17825 metrics.
- Test tool components
- Separation of measurement tool (probe, A/D converter, trigger, capture rate) and analysis tool (data processing, alignment, filtering, attack algorithms). Calibration covers both.
- Calibration principles
- Methods to set threshold values so that pass/fail boundaries are reproducible across tools.
- Use of a defined artefact (signal source representative of a leaking device) to establish a clear threshold between pass and fail.
- Calibration procedure elements
- Point of measurement, parameter adjustment, accuracy and traceability of measurement tools, and metrics tied to number of traces (security strength).
- Calibration metrics and artefacts
- Security strength defined in terms of number of traces required to detect leakage per ISO/IEC 17825.
- Informative annexes provide example artefacts and implementations (e.g., HSM emulation on FPGA, microcontroller, signal generator) and guidance on countermeasures tuning.
Applications
- Calibrating side‑channel measurement setups in testing labs to ensure consistent vulnerability assessments.
- Verifying equivalence between different non‑invasive attack tools and test benches.
- Supporting conformity and certification testing of cryptographic modules (e.g., FIPS/ISO/IEC conformity frameworks).
- Establishing reproducible thresholds for pass/fail decisions in product evaluation, R&D and independent testing.
Who should use this standard
- Security testing laboratories and certification bodies performing side‑channel evaluations.
- Cryptographic module vendors and embedded system designers validating non‑invasive attack mitigations.
- Hardware security engineers, penetration testers and QA teams responsible for measurement tool setup and traceability.
- Tool manufacturers (oscilloscopes, probes, signal generators) aiming for interoperability with standardized test suites.
Related standards
- ISO/IEC 17825 - Testing methods for mitigation of non-invasive attack classes (metrics referenced)
- ISO/IEC 19790 - Security requirements for cryptographic modules (IUT context)
- ISO/IEC 20085-1 - Part 1: Test tools and techniques (tool requirements and test concepts)
Keywords: ISO/IEC 20085-2:2020, test calibration methods, artefact, cryptographic modules, non-invasive attack mitigation, side‑channel analysis, measurement tool, analysis tool, ISO/IEC 17825.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 20085-2:2020
Похожие стандарты
Стандарты, упомянутые в описании