Cloud Key Management

ISO/IEC TR 24485:2022 Information security, cybersecurity and privacy protection - Security techniques - Security properties and best practices for test and evaluation of white box cryptography

  • 1.  ISO/IEC TR 24485:2022 Information security, cybersecurity and privacy protection - Security techniques - Security properties and best practices for test and evaluation of white box cryptography

    Posted Nov 10, 2022 01:22:00 AM
    Hi All,

    ISO/IEC just published ISO/IEC TR 24485:2022 Information security, cybersecurity, and privacy protection - Security techniques - Security properties and best practices for test and evaluation of white-box cryptography

    This document introduces security properties and provides best practices on the test and evaluation of white-box cryptography (WBC). WBC is a cryptographic algorithm specialized for a key or secret, but where the said key cannot be extracted.

    The WBC implementation can consist of plain source code for the cryptographic algorithm and/or of a device implementing the algorithm. In both cases, security functions are implemented to deter an attacker from uncovering the key or secret.

    Security properties consist of the secrecy of security parameters concealed within the implementation of white-box cryptography. Best practices for the test and evaluation include mathematical and practical analyses, static and dynamic analyses, and non-invasive and invasive analyses.

    This document is related to ISO/IEC 19790 which specifies security requirements for cryptographic modules. In those modules, critical security parameters (CSPs) and public security parameters (PSPs) are the assets to protect. WBC is one solution to conceal CSPs inside of the implementation.

    This standard can be previewed here: https://www.iso.org/obp/ui/#iso:std:iso-iec:tr:24485:ed-1:v1:en
     
    This standard can be purchased here: https://www.iso.org/standard/78890.html



    ------------------------------
    Michael Roza CPA, CISA, CIA, MBA, Exec MBA
    ------------------------------