Thursday, September 7, 2017

Linux: /dev/random study published

Hi folks,

The updated study for the Linux /dev/random and /dev/urandom has now been 
published at BSI. Please see [1] for the general web site and [2] for the 
study.

Please note that at [1], there are additional documents for reusing the NTG.1 
conclusion of the study for Linux-based evaluations.

For the FIPS 140-2 folks: [2] should now be our entropy assessment report. In 
particular, chapter 6 provides the assessment according to SP800-90B we need. 
This study also contains in section 6.3 measurements of entropy during early 
boot time that will be necessary in the proposed update to SP800-90B.

This study will be continued for each new kernel version that comes out. The 
first kernel the study applies to is v4.9.

[1] https://www.bsi.bund.de/DE/Publikationen/Studien/LinuxRNG/index_htm.html

[2] https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Studien/LinuxRNG/LinuxRNG_EN.pdf?__blob=publicationFile&v=4

~ Stephan Mueller

1 comment:

Comments are moderated with the goal of reducing spam. This means that there may be a delay before your comment shows up.