September 14-16, 2022 | Westin Arlington Gateway

Open Source Transitioning Strategies to FIPS 140-3 (U30b)

Open Source Transitioning Strategies to FIPS 140-3 (U30b)

Transitioning open source cryptographic modules to FIPS 140-3 is very challenging. Vendors looking to leverage open source FIPS modules need to take several factors into consideration including: timing of updates to meet FIPS 140-3, viable stopgaps until a FIPS 140-3 validation can be achieved and whether the open source communities are committed to migrating to FIPS 140-3. There are several scenarios that vendors can leverage to help transition to the new FIPS 140-3 standard. The speaker will discuss the challenges for vendors in transitioning to FIPS 140-3 compliant modules that use open source cryptography, provide several approaches for vendors to maintain FIPS validations on products while transitioning, as well as strategies to consider for obtaining a FIPS 140-3 validation on open source cryptography. Strategic planning will be essential for vendors to minimize the gap between the FIPS 140-2 sunset dates and achieving the FIPS 140-3 validations.