Challenges and Experiences on Our First ISO/IEC 19790 Cryptographic Module Test Project (C30b)
In the Cryptographic Module Tests ecosystem dominated by the FIPS 140-2 standard, the ISO/IEC 19790 standard has not received enough attention and additional resources have not been developed for test details. That’s why we didn’t work on the standard that we got license for in 2016 in the first years. However, we are about to receive applications for three more products as we finish the tests of the first HSM product. Since new experiences were gained for the certificate authority, laboratory and developer, the testing process of the first product was kept long for the structure to settle, and it was tried to fill the gaps correctly and adequately rather than going to the conclusion. In the talk, it is aimed to convey the experiences gained in the process both for those who want to learn the ISO/IEC 19790 standard and those who want to establish a test process related to these standards.