| поискавой системы для электроныых деталей |
|
ST33TPHF20SPI датащи(PDF) 22 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
ST33TPHF20SPI датащи(HTML) 22 Page - STMicroelectronics |
|
22 / 47 page ![]() FIPS140-2 SECURITY POLICY Page 22 of 47 NON-PROPRIETARY DOCUMENT 2. Executing the expected policy commands sequence in case of policy authorization session (defined policy must follow recommendations listed in §1.7.3). 3. Do the comparison between reference value and computed value. If both match, command execution is authorized. More details on HMAC and policy sessions can be found in §19 of [TPM2.0 Part1 r1.16]. 2.2.2 Authorization strength As minimum value of authorization or policy values might be 160-bit random values (based on unbiased distribution of ‘0’ and ‘1’), the probability for an attacker to guess the authorization data is: 1 2160 = 6.84 ∗ 10−49 This value is then higher than the minimum of 1*10-6 required by [FIPS140-2]. The number of attempts per minute that an attacker can make is limited by the DAM (Dictionary Attack Mechanism). DAM consists in counting the number of failed authentication. When this counter reaches a pre-defined threshold, a lockout period is started. During this period, no authorized command execution is allowed and a specific error is returned in TPM response until period expires. Next table indicates the threshold values and the lockout durations: Table 16: DAM lockout durations Failed authentication counter >31 Lockout period (in seconds) 7200 This table indicates that an attacker can do a maximum (during the first minute) of 32 trials per minute before DAM being active. As a result the probability per minute that a random attempt will lead to a successful authorization matches FIPS requirements. Value is equal to: 32 ∗ 1 2160 = 2.19 ∗ 10−47 This value is then higher than the minimum of 1*10-5 required by [FIPS140-2]. NB: commands handling (reception, processing and response sending) is negligible compared to the lockout periods and not taken into account in the above computation. NB2: DAM parameters might be changed by using TPM2_DictionnaryAttackParameters command. However to operate in a FIPS approved mode, they shall not be changed in order not to decrease the authorization strength computed above. 2.2.3 Authorization protection By following recommendations to operate in FIPS mode of operation, authorization data associated to objects, NV indexes or hierarchies are never output from TPM in plaintext form and thus are protected from unauthorized disclosure. Authorization can be changed via the following services: TPM2_ObjectChangeAuth TPM2_HierarchyChangeAuth TPM2_NV_ChangeAuth As indicated in Table 18, roles that imply authentication are associated with these services meaning that authentication are protected against unauthorized modification and substitution. TPM authorization mechanism (HMAC or policy digest comparison) does not provide any information about authentication data or policy sequence. Authentication indicates pass (command executed) or fail (command not executed) and does not provide feedback that could weaken the strength of authentication. |
|
ссылки URL |
| Вашему бизинису помогли Аллдатащит? [ DONATE ] |
Что такое Аллдатащит | реклама | контакт | Конфиденциальность | Ссылка на техническое описание | обмен ссыками | поиск по производителю All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |