<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Entropy Testing Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://sitdev.corsec.com/tag/entropy-testing/feed/" rel="self" type="application/rss+xml" />
	<link>https://sitdev.corsec.com/tag/entropy-testing/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-2, Common Criteria, and listing on the DoDIN APL / UC APL.</description>
	<lastBuildDate>Wed, 02 Mar 2022 15:59:12 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>

<image>
	<url>https://sitdev.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>Entropy Testing Archives - Corsec Security, Inc.®</title>
	<link>https://sitdev.corsec.com/tag/entropy-testing/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Fed Roundup: February 2022</title>
		<link>https://sitdev.corsec.com/fed-feb22/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 02 Mar 2022 15:59:12 +0000</pubDate>
				<category><![CDATA[Algorithm Testing]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[FIPS 140-3]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[CAVP]]></category>
		<category><![CDATA[CCRA]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[CMVP]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DISA]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[Entropy Testing]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[NIAP]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<category><![CDATA[STIG]]></category>
		<guid isPermaLink="false">https://sitdev.corsec.com/?p=19242</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.disa.mil/newsandevents">DISA News</a></strong></h5>
<h5 style="padding-left: 30px;">Announcements:</h5>
<ul>
<li><a href="https://www.disa.mil/en/NewsandEvents/2022/MajGenYeeRetirement">Army Maj. Gen. Garrett Yee is retiring</a></li>
<li><a href="https://www.disa.mil/en/NewsandEvents/2022/TechNetCyberApril2022">2022 AFCEA TechNet Cyber Symposium iis set for April</a></li>
</ul>
<h5 style="padding-left: 30px;"><span style="color: #000000;"><a style="color: #000000;" href="https://public.cyber.mil/stigs/">STIG Updates:</a></span></h5>
<ul>
<li><a href="https://public.cyber.mil/announcement/disa-releases-ubuntu-v20-04-scap-security-technical-implementation-guide-benchmark/">Automated benchmark for the Ubuntu v20.04 SCAP STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-draft-oracle-linux-8-stig-scap-benchmark-for-review/">Draft Oracle Linux 8 STIG SCAP benchmark</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-updated-dod-annex-for-mdfpp-v3-2/">DoD Annex for Mobile Device Fundamental Protection Profile (MDFPP) V3.2</a></li>
<li><a href="https://public.cyber.mil/announcement/group-policy-objects-gpos-have-been-updated-for-january-2022/">Group Policy Objects (GPOs) have been updated for January 2022</a></li>
<li><a href="https://public.cyber.mil/announcement/stig-update-disa-releases-the-samsung-android-12-with-knox-3-x-security-technical-implementation-guide/">Samsung Android 12 with Knox 3.x STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/stig-update-disa-releases-the-apple-macos-12-security-technical-implementation-guide/">Apple macOS 12 STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-releases-the-vmware-vsphere-6-7-v1r2-security-technical-implementation-guide/">VMware vSphere 6.7, Version 1 Release 2 STIG</a></li>
<li><a href="https://public.cyber.mil/announcement/disa-has-released-updates-to-the-srg-stig-library-compilations-9/">Updates to the SRG/STIG Library Compilations</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://csrc.nist.gov/News">NIST News</a></strong></h5>
<h5 style="padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>None</li>
</ul>
<h5 style="padding-left: 30px;">Special Publications:</h5>
<ul>
<li><a href="https://csrc.nist.gov/News/2021/draft-pd-manufacturing-sector-cybersecurity">Draft project description, &#8220;Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/second-draft-nistir-8270-available-for-comment">2nd Draft NISTIR 8270, &#8220;Introduction to Cybersecurity for Commercial Satellite Operations&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/rfi-evaluating-and-improving-nist-cyber-resources">NIST has released an RFI to assist in improving cybersecurity resources such as the CSF and CSCRM</a></li>
<li><a href="https://csrc.nist.gov/News/2022/draft-nist-sp-800-219-available-for-comment">Draft SP 800-219, &#8220;Automated Secure Configuration Guidance from the macOS Security Compliance Project (mSCP)&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/second-drafts-of-nist-sp-800-140cd-rev-1-available">2nd Draft NIST SP 800-140C/D Rev. 1</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nistir-8286b-prioritizing-cybersecurity-risk-erm">NISTIR 8286B, &#8220;Prioritizing Cybersecurity Risk for Enterprise Risk Management&#8221;</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nist-publishes-sp-800-218-ssdf-v11">SP 800-218 has updated the Secure Software Development Framework (SSDF) to v1.1</a></li>
<li><a href="https://csrc.nist.gov/News/2022/nccoe-releases-sp-1800-32">SP 1800-32, &#8220;Securing Distributed Energy Resources: An Example of Industrial Internet of Things Cybersecurity&#8221;</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://www.niap-ccevs.org/Announcements/Announcements.cfm">NIAP News</a></strong></h5>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Updates &amp; Announcements:</h5>
<ul>
<li>None</li>
</ul>
<h5 class="wpb_wrapper" style="text-align: left; padding-left: 30px;">Protection Profile Posting:</h5>
<ul>
<li><a href="https://www.niap-ccevs.org/MMO/PP/PP_GPCP_v1.0.pdf.">Protection Profile for General Purpose Computing Platforms (GPCP), Version 1.0.</a></li>
</ul>
</div>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "></div>
<div class="wpb_text_column wpb_content_element ">
<div class="wpb_wrapper">
<p style="text-align: center;">###</p>
</div>
</div>

		</div>
	</div>
<div class="vc_separator wpb_content_element vc_separator_align_center vc_sep_width_100 vc_sep_pos_align_center vc_separator_no_text vc_sep_color_black" ><span class="vc_sep_holder vc_sep_holder_l"><span  class="vc_sep_line"></span></span><span class="vc_sep_holder vc_sep_holder_r"><span  class="vc_sep_line"></span></span>
</div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/company/contact-us/">Connect With Us:</a></strong></h5>
<p>Stay up to date with Corsec as we bring you all the most recent updates to the standards, certifications, and requirements – <a href="https://ww3.corsec.com/subscribe"><span style="color: #0000ff;">Subscribe</span></a></p>
</div>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element ">
<h5 class="wpb_wrapper" style="text-align: left;"><strong style="color: #000000;"><a style="color: #000000;" href="https://sitdev.corsec.com/contact-us/">Press Contact:</a></strong></h5>
<p><strong>Jake Nelson</strong><br />
Dir of Marketing<br />
Jnelson@corsec.com</p>
</div>

		</div>
	</div>
</div></div></div></div>
	<div class="wpb_text_column wpb_content_element " >
		<div class="wpb_wrapper">
			<div class="wpb_text_column wpb_content_element "><a href="https://www.linkedin.com/company/corsec-security"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/LinkedIn.png 128w, https://sitdev.corsec.com/wp-content/uploads/LinkedIn-150x150.png 150w" alt="LinkedIn" width="35" height="35" />     </a><a href="https://twitter.com/CorsecSecurity"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Twitter.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Twitter.png 128w, https://sitdev.corsec.com/wp-content/uploads/Twitter-150x150.png 150w" alt="Twitter" width="35" height="35" />     </a><a href="https://www.facebook.com/Corsec-158518584300710/"><img decoding="async" src="https://sitdev.corsec.com/wp-content/uploads/Facebook.png" sizes="(max-width: 40px) 100vw, 40px" srcset="https://sitdev.corsec.com/wp-content/uploads/Facebook.png 128w, https://sitdev.corsec.com/wp-content/uploads/Facebook-150x150.png 150w" alt="Facebook" width="35" height="35" /></a></div>

		</div>
	</div>
</div></div></div></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Entropy Testing: Tips for Meeting Requirements</title>
		<link>https://sitdev.corsec.com/entropy-testing/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 16 Jan 2014 21:17:41 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Entropy]]></category>
		<category><![CDATA[Entropy Testing]]></category>
		<guid isPermaLink="false">http://corsec.com/?p=6425</guid>

					<description><![CDATA[In the second post of our two-part series, we continue our discussion with panelists from Computer Sciences Corporation: Lachlan Turner, Jason Cunningham, and Maureen Barry. Continuing where we left off with last week’s post, we’ll dive deeper into entropy and answer some of the many questions now arising...]]></description>
										<content:encoded><![CDATA[<p>In the second post of our two-part series, we continue our discussion with panelists from Computer Sciences Corporation: Lachlan Turner, Jason Cunningham, and Maureen Barry. Continuing where we left off with <a href="http://corsec.com/entropy-testing-for-fips-and-common-criteria-what-you-need-to-know/" target="_blank" rel="noopener noreferrer">last week’s post</a>, we’ll dive deeper into entropy and answer some of the many questions now arising about new requirements, entropy testing and tools and how all of this might affect your upcoming FIPS or Common Criteria evaluations.</p>
<h4><strong>What do vendors have to do to meet the entropy testing requirements?</strong></h4>
<p>Vendors must prove to the testing laboratories that their entropy source conforms to the requirements in NIST’s <a href="http://csrc.nist.gov/publications/drafts/800-90/draft-sp800-90b.pdf" target="_blank" rel="noopener noreferrer">Special Publication 800-90B</a>. In general terms, this requires:</p>
<ul>
<li>Identification and specifications of the entropy source</li>
<li>Identification of whether the entropy is independent and identically distributed (IID) or non-IID</li>
<li>Justification as to the randomness of the entropy</li>
<li>Subjecting a sampling of the entropy to statistical testing</li>
<li>Proof that adequate health tests are implemented</li>
</ul>
<p>If vendors are using third-party modules for their products, it’s best to choose those where access to information about sources of entropy is available. If a module has already been chosen, start a discussion with the third-party provider on how to best approach the entropy testing process. The key is that in the design process, vendors should look for solutions where they can get entropy that is as random as possible.</p>
<p>While nothing is guaranteed at this stage, our experience has shown that when accurately demonstrated, NIST generally accepts the justification of sufficient entropy stemming from the character device /dev/random, available in the Linux-based pseudo-random number generator (PRNG). The counterpart in that Linux-based PRNG, /dev/urandom, however, is not currently allowed by NIST due to its non-blocking characteristic.</p>
<h4><strong>Is there a way for product vendors to perform entropy testing on their sources before they enter into evaluation?</strong></h4>
<p>Unfortunately, there is really no way to know if a vendor will pass entropy testing at this stage. The most that can be done is to present arguments to a certification body, but because this is such a new area, there is no way to know for certain that an argument will stand up and something will pass.</p>
<p>There are test tools available that are helpful, and running a sample entropy output through one of these test tools can certainly give an indication of the sufficiency of the entropy source. A vendor can independently perform its own entropy testing against the NIST publication SP 800-90B—this is the gold standard right now. (The applicable concepts required to gauge whether the entropy source is sufficient are all outlined in that publication.) Vendors may, however, need some consulting help from a Cryptographic Security Testing laboratory for that. Engaging with a consultant early on may also help identify any red flags that could hold up the process (for example, the use of dev/urandom).</p>
<h4><strong>What tools can be used for entropy testing specifically?</strong></h4>
<p>No officially sanctioned tool exists for entropy testing. As it stands, the Cryptographic Security Testing laboratories are responsible for measuring entropy samples using their own methods and tools. Several third parties have created their own tools for entropy testing. Some tools are available in the public domain, and incorporate some or all of the NIST SP 800-90B requirements.</p>
<p>For instance, the Python testing tool is available upon request from CAVP to labs and vendors for entropy testing. It is a fairly primitive program, but can be useful and at some point there will be a GUI interface for it.</p>
<p>At this point in time, the Common Criteria schemes do not rely on the entropy testing tools, and including output in the Entropy Assessment Report is entirely optional.  Our experience indicates that CSEC (Canada) and NIAP (U.S.) are more interested in an explanation that the input to the entropy source (i.e. noise source) contains sufficient entropy itself to justify the encryption strength of the resulting keys that the TOE will generate. Any use of the tools would have to focus on the noise source data, which is problematic. Measuring the output of the entropy source, after post-processing of the entropy has occurred, does not appear to be acceptable.</p>
<h4><strong>How do you deal with third-party entropy sources if the vendor does not have access to all internal technical details?</strong></h4>
<h4>It’s possible that a vendor may not have the source code or design information regarding the entropy source. Typically, if the entropy source is a True Random Number Generator (TRNG) such as one might find on certain processors, there may be sufficient specifications from the manufacturer detailing the product, such that the requirements of NIST SP 800-90B could be addressed.</h4>
<h4><strong>Are vendors required to use a hardware noise source for entropy generation to be FIPS 140-2 validated or CC validated against a NIAP PP?</strong></h4>
<p>The use of a hardware noise source isn’t a requirement, but it is highly recommended. The entropy source identified by the vendor will be tested per the requirements of NIST SP 800-90 (as well as any supplemental FIPS or CC programmatic guidance), and an entropy testing verdict will be rendered.</p>
<p>Entropy that is found to fail the mathematical testing outlined in NIST SP 800-90, or entropy sources that contain inadequate health testing, will be considered insufficient by the laboratory.</p>
<p>While not required, there are some benefits to using hardware noise sources. There are commonly available hardware-based entropy sources that are built in to some CPUs (for example, Intel’s Ivy Bridge processors). These hardware-based solutions have been found to produce quality entropy very quickly, so are ideal for use in systems where the entropy pool can become quickly depleted.</p>
<h4><strong>How long is the process of evaluating entropy adding to evaluations?</strong></h4>
<p>For FIPS, the CMVP requires a report containing justifications, so it can add about a week of lab time onto the process — this includes all the components involved: source code review and writing the entropy justification. On the vendor end, there is then additional time. Because this is fairly new guidance, we can’t always estimate what CMVP will require. Labs are providing the information we believe we’re being asked for, but we’ll have a better feel for what is truly required in the future.</p>
<p>For Common Criteria in the U.S., there has been a starting gate implemented requiring that the entropy source be evaluated and approved prior to a vendor actually starting a CC evaluation. Turnaround times will likely improve, however the impact here is potentially quite large – for now one should assume a two-month to three-month delay waiting for entropy review. Because it’s so new, we’ve only just had our first submission approved in Canada, which fortunately occurs in parallel with the rest of the evaluation and therefore has less of an impact.</p>
<h4><strong>Panel members from Computer Sciences Corporation (CSC) are:</strong></h4>
<p>Lachlan Turner is the Technical Director of <a href="http://www.csc.com/" target="_blank" rel="noopener noreferrer">CSC’s</a> Security Testing and Certification Labs with over 10 years of experience in cyber security specializing in Common Criteria. Lachlan served as a member of the Common Criteria Interpretations Management Board (CCIMB) and has held roles as certifier, evaluator and consultant across multiple schemes – Australia/New Zealand, Canada, USA, Malaysia and Italy. Lachlan provides technical leadership to CSC’s four accredited CC labs and is passionate about helping vendors through the evaluation process to achieve their business goals and gain maximum value from their security assurance investments.</p>
<p>Jason Cunningham leads the FIPS 140-2 program at <a href="http://www.csc.com/" target="_blank" rel="noopener noreferrer">CSC</a> and has over 10 years of experience in IT security. Throughout his career, Jason has been involved in numerous security related projects covering a wide range of technologies.</p>
<p>Maureen Barry is the Deputy Director for <a href="http://www.csc.com/" target="_blank" rel="noopener noreferrer">CSC’s</a> Security Testing and Certification Labs (STCL) and primarily manages the Canadian laboratory.  She is also a Global Product Manager responsible for developing, managing, and executing the Cybersecurity Offering program for STCL across four countries: Canada, USA, Australia and Germany.  She has almost 10 years of experience in Common Criteria in addition to over 10 years of experience in IT.</p>
<p>Corsec Lead Engineer Darryl Johnson was also a member of the panel discussing entropy testing and contributed to the writing of this post.</p>
<p>For help with your FIPS 140-2 or Common Criteria evaluation, or if you have questions about entropy testing and how it might affect your next evaluation, <a href="http://sitdev.corsec.com/contact-us/" target="_blank" rel="noopener noreferrer">contact us</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Content Delivery Network via cdn.corsec.com

Served from: sitdev.corsec.com @ 2026-05-30 21:44:08 by W3 Total Cache
-->