ISO/IEC 17825 specifies the non-invasive attack mitigation test metrics for determining conformance to the requirements specified in ISO/IEC 19790 for Security Levels 3 and 4. The test metrics are associated with the security functions specified in ISO/IEC 19790. Testing will be conducted at the defined boundary of the cryptographic module and I/O available at its defined boundary.
The test methods used by testing laboratories to test whether the cryptographic module conforms to the requirements specified in ISO/IEC 19790 and the test metrics specified in ISO/IEC 17825 for each of the associated security functions specified in ISO/IEC 19790 are specified in ISO/IEC 24759.
ISO/IEC 17825 on Testing methods for the mitigation of non-invasive attack classes against cryptographic modules is useful for:
The non-invasive attacks use side-channels (information gained from the physical implementation of a cryptosystem) emitted by the IUT such as:
The goal of non-invasive attack testing is to assess whether a cryptographic module utilizing non-invasive attack mitigation techniques can provide resistance to attacks at the desired security level.
The test approach employed in ISO/IEC 17825 is an efficient “push-button” approach: the tests are technically sound, repeatable and have moderate costs.
ISO/IEC 17825:2016