The Evolution of Security Requirements for Cryptographic Modules:the Status Quo,Dilemma and Future Trends
Jiye Liu · Journal of Chengdu University of Information Technology · 2011
The publication series of FIPS 140 standards,formulated by National Institute of Standards and Technology(NIST) and issued by Federal Government of the United States,aim to specify the techniques and procedures related to the secure design,implementation,operation and disposal of a cryptographic module.FIPS 140-1 and FIPS 140-2 were issued in 1994 and 2001,respectively.According to the established policy that standards are reviewed every five years,the review of FIPS 140-2(and also the drafting of FIPS 140-3) was initiated in January, 2005.However,the final FIPS 140-3 is still not disclosed so far,even after two draft versions of FIPS 140-3 have been proclaimed and then more than 2,000 comments and feedbacks were gathered worldwide.This very fact is well worth pondering.In view of this,we discuss the evolution of FIPS 140 standards within the latest twenty years,investigate the possible reasons behind structural and technological changes,and forecast some future trends in this survey and position paper.