whats-new-app-protection-profile

What’s New In App PP v1.4

Marina Ibrishimova Common Criteria

The Protection Profile for Application Software (APP PP) v1.4 has recently been published. Here are some key points from our initial review.

  • PP-Modules. Vendors are now allowed to specify additional protection profiles (PPs) and PP-Modules in a PP-Configuration with APP PP v1.4. Previously, only PP-Module for VPN Clients was allowed to be claimed with this PP.
  • SSH. Functional package for Secure Shell (SSH) v1.0 was added to APP PP v1.4. The Extended Package for Secure Shell (SSH) v1.0, which is about to sunset on November 13th, 2021, is superseded by the Functional Package for Secure Shell (SSH).
  • MEC. An optional selection to include FDP_PRT_EXT.1 from the PP-module for file encryption was added to FMT_MEC_EXT.1.
  • X509. Clarifications on when FIA_X509_EXT.1/2 need to be claimed.
Read More

Understanding the IUT and MIP Lists and Their Wait Times

Gillian Bedrosian FIPS 140-2, FIPS 140-3

The most common question we receive from clients on the FIPS Validation process is: “after my validation report has been sent to the Cryptographic Module Validation Program (“CMVP”), how long will it take to complete the Validation?”. This post outlines the various stages for a module to be validated in the CMVP’s review process, as well as the average duration of each stage.

Read More

Beyond the testing: FIPS 140-3 documentation inputs

Grace Grundy and Jason Cunningham Entropy, FIPS 140-2, FIPS 140-3

First time vendors to the FIPS 140 validation process are often not aware of the scope of supporting documentation and evidence required. These documentation inputs are integral to the lab being able to perform and finalize the full validation process.

The set of documents described below provide the testers with in an in-depth description, with evidence, of how a cryptographic implementation complies with the FIPS 140 standard and the most current Implementation Guidance (IG) from the CMVP.  The core documents are the first thing the Lab will evaluate and ultimately forms the basis of the report that the CMVP assesses in consideration of awarding the validation. As an independent third-party, laboratories are not permitted to author original design documentation for cryptographic modules under test.  As such, it’s important for vendors to plan their FIPS strategy in advance to determine if they should “build or buy” the documentation / consulting support that will be required.  Generating adequately detailed documentation and design information can be time-consuming and onerous depending on your experience and the complexity of the module being validated.  This effort should not be underestimated and needs to be factored into the overall cost and effort of undertaking a FIPS 140 validation.  

Read More

Product Development. What’s Assurance Got To Do With It?

Garrett Nickel Common Criteria

Observations from a CC newcomer

If you’re new to Common Criteria (CC), you might be feeling a little overwhelmed and find yourself wondering if the effort in performing the certification is really worth it. As a newcomer to the industry myself, I can relate. However, as I learn more about the process, I can also tell you that it can be a worthwhile investment for an organization on many levels.

At first glance, you might think that CC is just another framework or standard that requires yet another “audit”. While it is an international standard (ISO/IEC 15408), the real difference vs many other frameworks lies within the core of what Common Criteria is all about. Product Assurance.

Read More

FIPS 140-3 Is Here!

Jason Lawlor and James Ramage FIPS 140-3

The countdown is on. As of September 22, 2021, FIPS 140-2 will be sunset and only FIPS 140-3 validations can be submitted to the Cryptographic Module Validation Program (CMVP). In this latest post, we cover the key differences in the versions and where to find additional information.

Read More

Ottawa’s Fastest Growing Companies 2021

Jason Lawlor Lightship News

Lightship Security has been named as one of Ottawa’s Fastest Growing Companies for 2021.

Every year, the Ottawa Business Journal (OBJ) recognizes 10 regional companies for their substantial, sustainable, and profitable growth. 

Fueled by continued innovation, reinvestment, and a good dose of grit – we have bootstrapped our way to substantial growth over a three-year period to earn a spot on the 2021 list.  This is the second year in a row (the awards were postponed in 2020 due to Covid) that Lightship has made the top 10.

Mitigating risk for our clients through our modernized approach to 3rd party product security certifications has resulted in 5 straight years of more than 100% growth.

Read More

NIST 800-90B Input Data Considerations

Greg McLearn Certifications, Common Criteria, Entropy, FIPS 140-2, Tools

For the past few years, the Common Criteria program has been mandating entropy analysis for almost all protection profile based evaluations.  Since November 2020, NIST 800-90B has also become a mandatory requirement under the FIPS 140-2 and the forthcoming FIPS 140-3 program, meaning there is evaluation of entropy sources in both major North American security standards.  Over the past few years, NIST has been fine-tuning an entropy analysis process to help quantify entropy sources as per the 800-90B standard.  Their work can be found on the NIST public github page.  In addition, new development on a web-based submission process has begun called the “Entropy Source Validation” program (ESV).  This process will accept data from a registered entity and process the entropy source data via the NIST 800-90B entropy analysis tool.

This article focuses on an important, but sometimes overlooked, aspect of the entropy source validation process: ensuring the data is in a format appropriate to be read by the entropy assessment tool.

Read More

Great Place to Work

Jason Lawlor Lightship News

Lightship Security has been certified as a Great Place to Work®!

This certification process is based on a thorough, independent analysis conducted by the Great Place to Work Institute® Canada.  The certification is a result of direct feedback from employees, provided as part of an extensive and anonymous survey about their workplace experience.

Read More

Funding for NIST CAVP Vendor Software Platform

Jason Lawlor ACVP, FIPS 140-2, FIPS 140-3

As part of our continued push to modernize the product security certification industry, Lightship Security is pleased to announce that it is receiving advisory services and conditional research and development funding from the National Research Council of Canada Industrial Research Assistance Program (NRC IRAP) supporting a project to develop and launch our innovative client facing cryptographic algorithm testing portal.

Read More

NIST 800-90B Concepts

James Ramage Entropy, FIPS 140-2, FIPS 140-3

The claimed entropy source for a FIPS 140 validated module now requires compliance to NIST SP800-90B. This means that any cryptographic module going through FIPS 140-2 or FIPS 140-3 validation needs to adhere to NIST implementation guidance 7.18 – Entropy Estimation and Compliance with SP 800-90B. This post will introduce relevant requirements and cover basic concepts of entropy source validation for a FIPS 140 module.

Read More