Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Self Tests Must be Repeated Periodically for FIPS Level 3 #1766

Open
nquarton opened this issue Nov 1, 2024 · 3 comments
Open

Self Tests Must be Repeated Periodically for FIPS Level 3 #1766

nquarton opened this issue Nov 1, 2024 · 3 comments
Assignees
Labels
Caliptra v2.0 Items to be considered for v2.0 Release FIPS Level 3 FIPS Related to FIPS requirements

Comments

@nquarton
Copy link
Contributor

nquarton commented Nov 1, 2024

For FIPS level 3, 7.10.3.8 requires that self tests are repeated periodically.

Note this requirement does allow deferring self tests when critical services are being performed. To reduce latency during these tests, it may make sense to allow the sequence to be interruptible between each test if a mailbox request is received.

@nquarton nquarton added FIPS Related to FIPS requirements Caliptra v2.0 Items to be considered for v2.0 Release FIPS Level 3 labels Nov 1, 2024
@nquarton
Copy link
Contributor Author

nquarton commented Jan 9, 2025

Open to consider: Is a ROM implementation needed for this? We would not expect ROM to ever be idle long enough for this to run and would prefer to not add anything non-essential in ROM.

@nquarton
Copy link
Contributor Author

After speaking with our FIPS consultant again, the suggestion was made to periodically "mark" that the KAT for a particular algorithm needs to re-run instead of actually re-running it every time. Then, the KAT can re=run when that crypto is invoked by other actions. This eliminates wasting time running KATs for crypto that is not being used between these periods.

@nquarton nquarton self-assigned this Mar 10, 2025
@jhand2
Copy link
Collaborator

jhand2 commented Mar 11, 2025

We should consider making the FIPS level configurable (either at compile-time or some runtime mechanism). A device which does not want level 3 support shouldn't have to take the runtime hit of doing this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Caliptra v2.0 Items to be considered for v2.0 Release FIPS Level 3 FIPS Related to FIPS requirements
Projects
None yet
Development

No branches or pull requests

2 participants