IEC 19790 Security Requirements for Cryptographic Modules

    IEC 19790 Introduction

    The modern cybersecurity systems are based on cryptographic modules. They safeguard monetary dealings, individual information, state communications, industrial control systems, and secure networks. Cryptographic modules may weaken or fail to provide appropriate protection to the whole security system. IEC 19790 gives standard security requirements that include physical security, logical security, key management, roles and services, and operational environments. The standard allows for a standardized assessment and certification of cryptographic modules in order to be able to withstand specified security levels and avoid unauthorized access or manipulation.

    Read more

    Get Certified IEC 19790 for Trusted Cryptographic Security

    Both certification to IEC 19790 and certification to IEC 9554 prove that a cryptographic module satisfies internationally recognized security requirements. Certified modules offer the regulators, customers, and integrators of the system an assurance that cryptographic controls are working in a secure and reliable manner. Compliance promotes government approvals, validation of the financial system, and safe product deployment in international markets.

    IEC 19790 Security Requirement Areas

    Module SpecificationDefinition of cryptographic module boundaries and components
    Roles and ServicesIdentification of authorized roles and permitted services
    Operational EnvironmentSecure configuration and execution environment
    Cryptographic Key ManagementGeneration, storage, distribution, and destruction of keys
    Self-TestsPower-up and conditional integrity tests
    Design AssuranceDocumentation, configuration management, and testing controls
    Mitigation of AttacksProtection against side-channel and other advanced attacks

    Scope of IEC 19790

    • Covers both hardware, software, and firmware, and hybrid cryptography modules. Establishes the level of security in various risk conditions. 
    • Endorses testing and approval in certified laboratories. 
    • Covers business, government, and industrial uses. 
    • Provides stability in the worldwide security assessments. 
    • Ensures adherence to regulatory cybersecurity systems.

    IEC 19790 Equipment and Sample Preparation

    Specimen DetailCryptographic hardware modules, software libraries, firmware components, or integrated systems
    Specimen DimensionPhysical dimensions applicable for hardware modules; software modules defined by logical boundaries
    Specimen PreparationConfigure the module according to the documented operational mode; provide technical documentation and security policy for evaluation

    Applications of IEC 19790

    • Assessment of secure cryptographic hardware devices. 
    • Secure software encryption library validation. 
    • Defence system and governmental approvals. 
    • Security systems of financial transactions. 
    • Secured information centres and clouds.
    • Protective communication and authentication. 
    • Embedded system and IoT security certification.

    IEC 19790 Common Challenges and Troubleshooting

    Testing to IEC 19790 requires reviewing module design documentation and reviewing source code or hardware architecture, functional testing, cryptographic algorithms testing, and physical and logical protection testing. The input of data as a test result, vulnerability analysis, self-test logs, and documentation inspection is provided. Labs ensure the module works in specific security parameters and is of the specified level of assurance.

    Read more

    IEC 19790 Technique, Process, and Data Collection

    Evaluation under IEC 19790 entails reviewing module design documentation, inspecting source code or hardware structure, performing functional testing, verifying cryptographic algorithms, and assessing bodily and environmental protections. Data collection includes test results, vulnerability checks, self-check facts, and documentation opinions. Laboratories verify that the module operates within defined security parameters and meets required assurance levels.

    IEC 19790 Analysis Results and Interpretation

    The results of IEC 19790 testing establish the compliance of the cryptographic module with the security requirements and the security levels as defined. The compliance guarantees that the module is effectively using the cryptographic algorithms, guards keys, and has anti-tampering and self-assessments as required. Non-compliance implies the bodily, software program, or operational manipulation weaknesses that must be remedied before deployment.

    Read more

    IEC 19790 Problem & Solution

    Problem: Cryptographic modules can be designed in a manner that allows insecure systems.

    Solution: EC 19790 defines strict security standards and test criteria to make cryptographic modules reliable and tamper-resistant in offering secure protection.

    FAQ

    Where can I get the iec 19790 tested?
    You can share your iec 19790 testing requirements with MaTestLab. MaTestLab has a vast network of material testing laboratories, spread across the USA and Canada. We support your all material testing needs ranging from specific iec 19790 test to various testing techniques.
    Please contact us for a detailed quote for your iec 19790 testing needs. Cost incurred to carry out different iec 19790 testing methodology depends on the type of raw material; number of samples, coupons, or specimens; test conditions, turn around time etc. Costs of some ASTM testing methods start from $100 and the final value depends upon the factors listed above. Please contact us for the best and latest prices.
    The required number of samples or specimens should comply with the procedure given in the iec 19790 standard. However, the MaTestLab operations team can assist you for your special requirements once you share your testing details with us.
    MaTestLab has a vast testing laboratory network, hence we bring you the best testing facilities in a cost-effective way. We offer considerable discounts (15-20%) to our returning customers based on test volume and frequency.
    The turnaround time for iec 19790 test methodology depends upon the test procedure mentioned in the standard test document. However, we at MaTestLab understand your research requirements and hence try to get your test completed within the least possible time.
    Davis Scott
    About Author
    Davis Scott
    Davis Scott is an Electrical and Electronics Engineer specializing in multidisciplinary validation, quality assurance, and comprehensive electro-mechanical testing.
    Testimonials
    Real results
    Engineers trust us with what matters most
    Start Your Testing
    Project Today
    Define your requirements and get access to
    specialized laboratories ready to deliver results
    Partners with us
    Clients
    Vendors
    Process for testing
    • STEP 01

      You share your testing requirements

    • STEP 02

      You share your sample(s)

    • STEP 03

      We deliver your test reports

    Get your testing done

    Let us known your testing requirements and we will be right back with a solution.

      Let us root for each other. Collaborate to grow, expand, and accelerate our businesses.

      Partner with us

        Contact Us

        Discover more from MaTestLab

        Subscribe now to keep reading and get access to the full archive.

        Continue reading