| поискавой системы для электроныых деталей |
|
ST33TPHF20SPI датащи(PDF) 18 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
ST33TPHF20SPI датащи(HTML) 18 Page - STMicroelectronics |
|
18 / 47 page ![]() FIPS140-2 SECURITY POLICY Page 18 of 47 NON-PROPRIETARY DOCUMENT Table 13: Approved mode 2 Properties Description Definition Full approved mode of operation Configuration TPM2_SelfTest(full=YES) execution Services available All services Algorithms used All supported algorithms (cf. §1.6) CSPs used All CSPs Self-tests SHS / HMAC / AES / DRBG / KDF / TDES / RSA / ECDH / ECDSA / HW integrity / FW integrity / NDRNG 1.7.3 FIPS mode recommendations To use the TPM in a FIPS approved mode of operation (valid for mode1 and mode2), the TPM operator shall: Use an encryption session for the commands that inputs/outputs CSPs (List is indicated at §3.3.1). For commands without authorization, encryptedSalt used in TPM_StartAuthSession on encryption session creation must be different from the empty buffer. Use an approved symmetric algorithm (AES) for encryption sessions Use authorization session based on HMAC or policy (no password allowed, cf. §2.2.1). Duplicate only objects with encryptedDuplication attribute set. Not use FIPS 140-2 non-approved algorithms: o SHA-1 for RSA digital signature generation o EC Schnorr for ECC digital signature generation o ECDAA for ECC digital signature generation For the following services: o TPM2_Sign, TPM2_Certify, TPM2_CertifyCreation, TPM2_Quote, TPM2_GetSessionAuditDigest, TPM2_GetCommandAuditDigest, TPM2_GetTime, TPM2_NV_Certify, TPM2_Commit Not use TPM2_LoadExternal service to load TDES keys into the TPM. Limit number of encryptions with a same TDES key to a maximum of 228 encryptions. Use a policy including TPM2_PolicyAuthValue as a minimum in the policy sequence in case authorization is ensured by policy (authorization by policy must be at least as secure as authorization by HMAC). Use TPM2_HierarchyChangeAuth after first TPM init or after each TPM2_Clear to set the authorization value for the endorsement, platform, owner and lockout hierarchies. Use TPM2_CreatePrimary command only for RSA and ECC key with default template. If operator does not strictly follow the FIPS approved mode recommendations (ex: use of XOR instead of AES in encryption session), TPM is considered as being in a FIPS non-approved mode of operation. To use the TPM in a FIPS approved mode if it was previously used in a FIPS non-approved mode, the operator shall: Zeroize all data listed in Table 17: Keys and CSPs list that could potentially be reused as CSPs in FIPS approved mode To use the TPM in a FIPS non-approved mode if it was previously used in a FIPS approved mode, the operator shall: |
|
ссылки URL |
| Вашему бизинису помогли Аллдатащит? [ DONATE ] |
Что такое Аллдатащит | реклама | контакт | Конфиденциальность | Ссылка на техническое описание | обмен ссыками | поиск по производителю All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |